﻿2026-07-11T01:39:53.9681698Z ##[group]Run ./traceable-reqs lint || true
2026-07-11T01:39:53.9681841Z [36;1m./traceable-reqs lint || true[0m
2026-07-11T01:39:53.9694123Z shell: /usr/bin/bash -e {0}
2026-07-11T01:39:53.9694219Z ##[endgroup]
2026-07-11T01:39:54.0071635Z Requirement quality findings (586); 480 requirements queued for agent review:
2026-07-11T01:39:54.0072719Z   [must] requirement_quality REQ-ADAPTER-ADD-SURFACE-ERRORS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0073420Z   [must] requirement_quality REQ-ADAPTER-ADD-SURFACE-ERRORS criterion=length — title is 77 words; want 3..=25
2026-07-11T01:39:54.0074235Z   [must] requirement_quality REQ-ADAPTER-FLOOR-ENFORCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0074841Z   [must] requirement_quality REQ-ADAPTER-FLOOR-ENFORCE criterion=length — title is 368 words; want 3..=25
2026-07-11T01:39:54.0075629Z   [must] requirement_quality REQ-ADAPTER-GH-TRANSPORT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0076308Z   [must] requirement_quality REQ-ADAPTER-GH-TRANSPORT criterion=length — title is 62 words; want 3..=25
2026-07-11T01:39:54.0077093Z   [must] requirement_quality REQ-ADAPTER-LIVE-UPDATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0078023Z   [must] requirement_quality REQ-ADAPTER-LIVE-UPDATE criterion=length — title is 168 words; want 3..=25
2026-07-11T01:39:54.0078689Z   [must] requirement_quality REQ-ADAPTER-MULTIPLATFORM-SPT criterion=length — title is 123 words; want 3..=25
2026-07-11T01:39:54.0079465Z   [must] requirement_quality REQ-ADAPTER-PROOF-DIR-OVERRIDE criterion=length — title is 76 words; want 3..=25
2026-07-11T01:39:54.0080375Z   [must] requirement_quality REQ-ADAPTER-TEMPLATE-KEY-VALIDATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0081063Z   [must] requirement_quality REQ-ADAPTER-TEMPLATE-KEY-VALIDATION criterion=length — title is 110 words; want 3..=25
2026-07-11T01:39:54.0081933Z   [must] requirement_quality REQ-ADAPTER-TRANSLATE-PROOF criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0082567Z   [must] requirement_quality REQ-ADAPTER-TRANSLATE-PROOF criterion=length — title is 182 words; want 3..=25
2026-07-11T01:39:54.0083492Z   [must] requirement_quality REQ-ADAPTER-UNRESOLVED-HINT-FORM criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0084033Z   [must] requirement_quality REQ-ADAPTER-UNRESOLVED-HINT-FORM criterion=length — title is 116 words; want 3..=25
2026-07-11T01:39:54.0084596Z   [must] requirement_quality REQ-ADAPTER-UPDATE-INPLACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0085011Z   [must] requirement_quality REQ-ADAPTER-UPDATE-INPLACE criterion=length — title is 82 words; want 3..=25
2026-07-11T01:39:54.0085382Z   [must] requirement_quality REQ-ADAPTER-UPDATE-MESSAGE criterion=length — title is 64 words; want 3..=25
2026-07-11T01:39:54.0085687Z   [must] requirement_quality REQ-ADAPTER-UPDATE-POST criterion=length — title is 124 words; want 3..=25
2026-07-11T01:39:54.0086092Z   [must] requirement_quality REQ-ADAPTER-VERSION-CMD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0086403Z   [must] requirement_quality REQ-ADAPTER-VERSION-CMD criterion=length — title is 59 words; want 3..=25
2026-07-11T01:39:54.0086759Z   [must] requirement_quality REQ-API-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0087119Z   [must] requirement_quality REQ-API-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0087376Z   [must] requirement_quality REQ-API-4 criterion=length — title is 67 words; want 3..=25
2026-07-11T01:39:54.0087672Z   [must] requirement_quality REQ-API-ENDPOINT-INFO criterion=length — title is 138 words; want 3..=25
2026-07-11T01:39:54.0088287Z   [must] requirement_quality REQ-BIND-HONEST-SELF-STAMP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0088612Z   [must] requirement_quality REQ-BIND-HONEST-SELF-STAMP criterion=length — title is 182 words; want 3..=25
2026-07-11T01:39:54.0089203Z   [must] requirement_quality REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0089585Z   [must] requirement_quality REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD criterion=length — title is 134 words; want 3..=25
2026-07-11T01:39:54.0090039Z   [must] requirement_quality REQ-BOUNDARY-ROTATION-CREDENTIAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0090382Z   [must] requirement_quality REQ-BOUNDARY-ROTATION-CREDENTIAL criterion=length — title is 53 words; want 3..=25
2026-07-11T01:39:54.0091245Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONN-DEADLOCK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0091595Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONN-DEADLOCK criterion=length — title is 477 words; want 3..=25
2026-07-11T01:39:54.0092032Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONTROL-STEAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0092483Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONTROL-STEAL criterion=length — title is 498 words; want 3..=25
2026-07-11T01:39:54.0092938Z   [must] requirement_quality REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0093290Z   [must] requirement_quality REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE criterion=length — title is 282 words; want 3..=25
2026-07-11T01:39:54.0093742Z   [must] requirement_quality REQ-BROKER-ATTACH-JOURNAL-RESILIENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0094091Z   [must] requirement_quality REQ-BROKER-ATTACH-JOURNAL-RESILIENT criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0094495Z   [must] requirement_quality REQ-BROKER-SCREEN-GRID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0094802Z   [must] requirement_quality REQ-BROKER-SCREEN-GRID criterion=length — title is 126 words; want 3..=25
2026-07-11T01:39:54.0095227Z   [must] requirement_quality REQ-CARRIER-CLAIM-EXCLUSIVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0095670Z   [must] requirement_quality REQ-CARRIER-CLAIM-EXCLUSIVE criterion=length — title is 218 words; want 3..=25
2026-07-11T01:39:54.0096110Z   [must] requirement_quality REQ-CLI-1 criterion=length — title is 97 words; want 3..=25
2026-07-11T01:39:54.0096486Z   [must] requirement_quality REQ-CLI-2 criterion=length — title is 37 words; want 3..=25
2026-07-11T01:39:54.0096857Z   [must] requirement_quality REQ-CLI-3 criterion=length — title is 37 words; want 3..=25
2026-07-11T01:39:54.0097266Z   [must] requirement_quality REQ-CLI-4 criterion=length — title is 89 words; want 3..=25
2026-07-11T01:39:54.0097621Z   [must] requirement_quality REQ-CLI-BROKEN-PIPE-TOLERANT criterion=length — title is 78 words; want 3..=25
2026-07-11T01:39:54.0098014Z   [must] requirement_quality REQ-CLI-HELP-MARKDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0098309Z   [must] requirement_quality REQ-CLI-HELP-MARKDOWN criterion=length — title is 156 words; want 3..=25
2026-07-11T01:39:54.0098556Z   [must] requirement_quality REQ-CLI-JSON criterion=length — title is 95 words; want 3..=25
2026-07-11T01:39:54.0099010Z   [must] requirement_quality REQ-CLI-OUTPUT-MARKDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0099828Z   [must] requirement_quality REQ-CLI-OUTPUT-MARKDOWN criterion=length — title is 199 words; want 3..=25
2026-07-11T01:39:54.0100333Z   [must] requirement_quality REQ-CLI-WIN-VT-ENABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0100704Z   [must] requirement_quality REQ-CLI-WIN-VT-ENABLE criterion=length — title is 110 words; want 3..=25
2026-07-11T01:39:54.0101234Z   [must] requirement_quality REQ-CONN-POISON-DIAL-SCOPE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0101620Z   [must] requirement_quality REQ-CONN-POISON-DIAL-SCOPE criterion=length — title is 245 words; want 3..=25
2026-07-11T01:39:54.0101939Z   [must] requirement_quality REQ-CONSENT-1 criterion=length — title is 41 words; want 3..=25
2026-07-11T01:39:54.0102244Z   [must] requirement_quality REQ-CONSENT-2 criterion=length — title is 37 words; want 3..=25
2026-07-11T01:39:54.0102550Z   [must] requirement_quality REQ-CONSENT-3 criterion=length — title is 82 words; want 3..=25
2026-07-11T01:39:54.0103072Z   [must] requirement_quality REQ-CONTROLLER-LIVENESS-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0103464Z   [must] requirement_quality REQ-CONTROLLER-LIVENESS-REAP criterion=length — title is 370 words; want 3..=25
2026-07-11T01:39:54.0104002Z   [must] requirement_quality REQ-CONV-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0104302Z   [must] requirement_quality REQ-CONV-1 criterion=length — title is 73 words; want 3..=25
2026-07-11T01:39:54.0104599Z   [must] requirement_quality REQ-CONV-2 criterion=length — title is 47 words; want 3..=25
2026-07-11T01:39:54.0104960Z   [must] requirement_quality REQ-CRC-SWAP-OLD-DISPLACE criterion=length — title is 125 words; want 3..=25
2026-07-11T01:39:54.0105401Z   [must] requirement_quality REQ-DAEMON-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0105716Z   [must] requirement_quality REQ-DAEMON-5 criterion=length — title is 64 words; want 3..=25
2026-07-11T01:39:54.0106107Z   [must] requirement_quality REQ-DAEMON-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0106365Z   [must] requirement_quality REQ-DAEMON-6 criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0106727Z   [must] requirement_quality REQ-DAEMON-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0106975Z   [must] requirement_quality REQ-DAEMON-7 criterion=length — title is 62 words; want 3..=25
2026-07-11T01:39:54.0107227Z   [must] requirement_quality REQ-DAEMON-8 criterion=length — title is 44 words; want 3..=25
2026-07-11T01:39:54.0107576Z   [must] requirement_quality REQ-DAEMON-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0107845Z   [must] requirement_quality REQ-DAEMON-9 criterion=length — title is 114 words; want 3..=25
2026-07-11T01:39:54.0108153Z   [must] requirement_quality REQ-DAEMON-SERVICE-INSTALL criterion=length — title is 88 words; want 3..=25
2026-07-11T01:39:54.0108569Z   [must] requirement_quality REQ-DAEMON-STATUS-JSON-TRUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0108884Z   [must] requirement_quality REQ-DAEMON-STATUS-JSON-TRUTH criterion=length — title is 73 words; want 3..=25
2026-07-11T01:39:54.0109265Z   [must] requirement_quality REQ-DAEMON-STDERR-PERSIST criterion=length — title is 55 words; want 3..=25
2026-07-11T01:39:54.0109589Z   [must] requirement_quality REQ-DAEMON-STOP-LIVE-SESSION-WARN criterion=length — title is 28 words; want 3..=25
2026-07-11T01:39:54.0109970Z   [must] requirement_quality REQ-DIGEST-CURSOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0110252Z   [must] requirement_quality REQ-DIGEST-CURSOR criterion=length — title is 181 words; want 3..=25
2026-07-11T01:39:54.0110792Z   [must] requirement_quality REQ-DIGEST-FETCHER-STRATEGY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0111106Z   [must] requirement_quality REQ-DIGEST-FETCHER-STRATEGY criterion=length — title is 167 words; want 3..=25
2026-07-11T01:39:54.0111550Z   [must] requirement_quality REQ-DIGEST-GENERATION-SUPERSEDE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0111869Z   [must] requirement_quality REQ-DIGEST-GENERATION-SUPERSEDE criterion=length — title is 353 words; want 3..=25
2026-07-11T01:39:54.0112256Z   [must] requirement_quality REQ-DIGEST-PROFILE-ENV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0112556Z   [must] requirement_quality REQ-DIGEST-PROFILE-ENV criterion=length — title is 96 words; want 3..=25
2026-07-11T01:39:54.0112842Z   [must] requirement_quality REQ-DOC-DELIVERY-VOCAB criterion=length — title is 52 words; want 3..=25
2026-07-11T01:39:54.0113161Z   [must] requirement_quality REQ-DOC-ECHO-COMMUNE-CONTRACT criterion=length — title is 60 words; want 3..=25
2026-07-11T01:39:54.0113481Z   [must] requirement_quality REQ-DOC-ENDPOINT-DROP-RESOLUTION criterion=length — title is 57 words; want 3..=25
2026-07-11T01:39:54.0113981Z   [must] requirement_quality REQ-DOCS-NO-INTERNAL-CODES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0114286Z   [must] requirement_quality REQ-DOCS-NO-INTERNAL-CODES criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0114581Z   [must] requirement_quality REQ-ECHO-DROP-DIR-RESOLVE criterion=length — title is 127 words; want 3..=25
2026-07-11T01:39:54.0114988Z   [must] requirement_quality REQ-EFFECTIVE-INSTANCE-STATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0115293Z   [must] requirement_quality REQ-EFFECTIVE-INSTANCE-STATE criterion=length — title is 160 words; want 3..=25
2026-07-11T01:39:54.0115668Z   [must] requirement_quality REQ-ELEVATE-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0115932Z   [must] requirement_quality REQ-ELEVATE-1 criterion=length — title is 121 words; want 3..=25
2026-07-11T01:39:54.0116223Z   [must] requirement_quality REQ-ENDPOINT-AUTOSTART criterion=length — title is 249 words; want 3..=25
2026-07-11T01:39:54.0116558Z   [must] requirement_quality REQ-ENDPOINT-LIST-MERGE-LOCAL criterion=length — title is 95 words; want 3..=25
2026-07-11T01:39:54.0116877Z   [must] requirement_quality REQ-ENDPOINT-LIST-NODE-GROUPED criterion=length — title is 213 words; want 3..=25
2026-07-11T01:39:54.0117192Z   [must] requirement_quality REQ-ENDPOINT-LIST-NODE-IDENT criterion=length — title is 57 words; want 3..=25
2026-07-11T01:39:54.0117588Z   [must] requirement_quality REQ-ENDPOINT-LIST-PALETTE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0117898Z   [must] requirement_quality REQ-ENDPOINT-LIST-PALETTE criterion=length — title is 106 words; want 3..=25
2026-07-11T01:39:54.0118208Z   [must] requirement_quality REQ-ENDPOINT-LIST-PROJECT-COL criterion=length — title is 79 words; want 3..=25
2026-07-11T01:39:54.0118540Z   [must] requirement_quality REQ-ENDPOINT-LIST-RENDER-POLISH criterion=length — title is 122 words; want 3..=25
2026-07-11T01:39:54.0118857Z   [must] requirement_quality REQ-ENDPOINT-LIST-REST-FILTER criterion=length — title is 110 words; want 3..=25
2026-07-11T01:39:54.0119309Z   [must] requirement_quality REQ-ENDPOINT-PURGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0119587Z   [must] requirement_quality REQ-ENDPOINT-PURGE criterion=length — title is 220 words; want 3..=25
2026-07-11T01:39:54.0119882Z   [must] requirement_quality REQ-ENDPOINT-STOP-OFFLINE criterion=length — title is 58 words; want 3..=25
2026-07-11T01:39:54.0120398Z   [must] requirement_quality REQ-ENDPOINT-UNBOUND-ATTACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0120766Z   [must] requirement_quality REQ-ENDPOINT-UNBOUND-ATTACH criterion=length — title is 122 words; want 3..=25
2026-07-11T01:39:54.0121101Z   [must] requirement_quality REQ-EP-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0121352Z   [must] requirement_quality REQ-EP-6 criterion=length — title is 58 words; want 3..=25
2026-07-11T01:39:54.0121585Z   [must] requirement_quality REQ-EP-7 criterion=length — title is 68 words; want 3..=25
2026-07-11T01:39:54.0121824Z   [must] requirement_quality REQ-EP-8 criterion=length — title is 114 words; want 3..=25
2026-07-11T01:39:54.0122163Z   [must] requirement_quality REQ-EP-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0122391Z   [must] requirement_quality REQ-EP-9 criterion=length — title is 76 words; want 3..=25
2026-07-11T01:39:54.0122806Z   [must] requirement_quality REQ-GOSSIP-ADAPTER-PROJECTS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0123106Z   [must] requirement_quality REQ-GOSSIP-ADAPTER-PROJECTS criterion=length — title is 82 words; want 3..=25
2026-07-11T01:39:54.0123604Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-ANY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0123897Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-ANY criterion=length — title is 92 words; want 3..=25
2026-07-11T01:39:54.0124231Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-CROSS-NODE criterion=length — title is 108 words; want 3..=25
2026-07-11T01:39:54.0124670Z   [must] requirement_quality REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0125018Z   [must] requirement_quality REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP criterion=length — title is 199 words; want 3..=25
2026-07-11T01:39:54.0125376Z   [must] requirement_quality REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER criterion=length — title is 114 words; want 3..=25
2026-07-11T01:39:54.0125694Z   [must] requirement_quality REQ-HAZARD-ATOMIC-TMP-COLLISION criterion=length — title is 29 words; want 3..=25
2026-07-11T01:39:54.0126090Z   [must] requirement_quality REQ-HAZARD-ATTACH-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0126383Z   [must] requirement_quality REQ-HAZARD-ATTACH-WEDGE criterion=length — title is 244 words; want 3..=25
2026-07-11T01:39:54.0126769Z   [must] requirement_quality REQ-HAZARD-BIND-CWD-UNSET criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0127069Z   [must] requirement_quality REQ-HAZARD-BIND-CWD-UNSET criterion=length — title is 130 words; want 3..=25
2026-07-11T01:39:54.0127485Z   [must] requirement_quality REQ-HAZARD-BIND-REST-STATE-CARRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0127809Z   [must] requirement_quality REQ-HAZARD-BIND-REST-STATE-CARRY criterion=length — title is 115 words; want 3..=25
2026-07-11T01:39:54.0128242Z   [must] requirement_quality REQ-HAZARD-BOUNDARY-READY-STRAND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0128576Z   [must] requirement_quality REQ-HAZARD-BOUNDARY-READY-STRAND criterion=length — title is 175 words; want 3..=25
2026-07-11T01:39:54.0129052Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESPAWN-PATH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0129369Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESPAWN-PATH criterion=length — title is 119 words; want 3..=25
2026-07-11T01:39:54.0129842Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0130328Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE criterion=length — title is 125 words; want 3..=25
2026-07-11T01:39:54.0130756Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0131099Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP criterion=length — title is 199 words; want 3..=25
2026-07-11T01:39:54.0131528Z   [must] requirement_quality REQ-HAZARD-BROKER-FLOOR-LOCK-POISON criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0131873Z   [must] requirement_quality REQ-HAZARD-BROKER-FLOOR-LOCK-POISON criterion=length — title is 333 words; want 3..=25
2026-07-11T01:39:54.0132303Z   [must] requirement_quality REQ-HAZARD-BROKER-PROCESS-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0132656Z   [must] requirement_quality REQ-HAZARD-BROKER-PROCESS-ISOLATION criterion=length — title is 114 words; want 3..=25
2026-07-11T01:39:54.0133075Z   [must] requirement_quality REQ-HAZARD-BROKER-QUIC-DEADLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0133520Z   [must] requirement_quality REQ-HAZARD-BROKER-QUIC-DEADLINE criterion=length — title is 162 words; want 3..=25
2026-07-11T01:39:54.0133948Z   [must] requirement_quality REQ-HAZARD-BROKER-SEED-WIRE-SKEW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0134263Z   [must] requirement_quality REQ-HAZARD-BROKER-SEED-WIRE-SKEW criterion=length — title is 193 words; want 3..=25
2026-07-11T01:39:54.0134710Z   [must] requirement_quality REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0135072Z   [must] requirement_quality REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE criterion=length — title is 192 words; want 3..=25
2026-07-11T01:39:54.0135387Z   [must] requirement_quality REQ-HAZARD-CEREMONY-CLOCK-STEP criterion=length — title is 139 words; want 3..=25
2026-07-11T01:39:54.0135721Z   [must] requirement_quality REQ-HAZARD-COMMUNE-INGEST-BLACKHOLE criterion=length — title is 263 words; want 3..=25
2026-07-11T01:39:54.0136051Z   [must] requirement_quality REQ-HAZARD-CONFLICT-BOTH-PRESERVED criterion=length — title is 29 words; want 3..=25
2026-07-11T01:39:54.0136484Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-CONVERGENCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0136825Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-CONVERGENCE criterion=length — title is 193 words; want 3..=25
2026-07-11T01:39:54.0137243Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-LIFETIME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0137586Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-LIFETIME criterion=length — title is 100 words; want 3..=25
2026-07-11T01:39:54.0138003Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-GAP-RESUME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0138346Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-GAP-RESUME criterion=length — title is 297 words; want 3..=25
2026-07-11T01:39:54.0138817Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0139247Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND criterion=length — title is 134 words; want 3..=25
2026-07-11T01:39:54.0139688Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-RETAKE-FLOOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0140201Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-RETAKE-FLOOR criterion=length — title is 184 words; want 3..=25
2026-07-11T01:39:54.0140636Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-WRITER-REORDER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0140979Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-WRITER-REORDER criterion=length — title is 643 words; want 3..=25
2026-07-11T01:39:54.0141426Z   [must] requirement_quality REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0141785Z   [must] requirement_quality REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE criterion=length — title is 275 words; want 3..=25
2026-07-11T01:39:54.0142111Z   [must] requirement_quality REQ-HAZARD-DAEMON-SCHED-NONBLOCKING criterion=length — title is 32 words; want 3..=25
2026-07-11T01:39:54.0142530Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-BARRIER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0142855Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-BARRIER criterion=length — title is 80 words; want 3..=25
2026-07-11T01:39:54.0143264Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0143678Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-REAP criterion=length — title is 90 words; want 3..=25
2026-07-11T01:39:54.0144066Z   [must] requirement_quality REQ-HAZARD-DEAD-REC-PID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0144366Z   [must] requirement_quality REQ-HAZARD-DEAD-REC-PID criterion=length — title is 175 words; want 3..=25
2026-07-11T01:39:54.0144762Z   [must] requirement_quality REQ-HAZARD-DEFERRED-MANIFEST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0145085Z   [must] requirement_quality REQ-HAZARD-DEFERRED-MANIFEST criterion=length — title is 112 words; want 3..=25
2026-07-11T01:39:54.0145495Z   [must] requirement_quality REQ-HAZARD-DELIVERY-STARVATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0145795Z   [must] requirement_quality REQ-HAZARD-DELIVERY-STARVATION criterion=length — title is 99 words; want 3..=25
2026-07-11T01:39:54.0146247Z   [must] requirement_quality REQ-HAZARD-DETACHED-DAEMON-STDIO criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0146567Z   [must] requirement_quality REQ-HAZARD-DETACHED-DAEMON-STDIO criterion=length — title is 255 words; want 3..=25
2026-07-11T01:39:54.0146901Z   [must] requirement_quality REQ-HAZARD-DETACHED-PIPE-INHERIT criterion=length — title is 52 words; want 3..=25
2026-07-11T01:39:54.0147348Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0147699Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT criterion=length — title is 232 words; want 3..=25
2026-07-11T01:39:54.0148108Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-SELFHEAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0148423Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-SELFHEAL criterion=length — title is 77 words; want 3..=25
2026-07-11T01:39:54.0148853Z   [must] requirement_quality REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0149263Z   [must] requirement_quality REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE criterion=length — title is 440 words; want 3..=25
2026-07-11T01:39:54.0149711Z   [must] requirement_quality REQ-HAZARD-ELEVATED-DAEMON-SPAWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0150143Z   [must] requirement_quality REQ-HAZARD-ELEVATED-DAEMON-SPAWN criterion=length — title is 58 words; want 3..=25
2026-07-11T01:39:54.0150580Z   [must] requirement_quality REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0150924Z   [must] requirement_quality REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT criterion=length — title is 228 words; want 3..=25
2026-07-11T01:39:54.0151396Z   [must] requirement_quality REQ-HAZARD-ENV-SUBST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0151686Z   [must] requirement_quality REQ-HAZARD-ENV-SUBST criterion=length — title is 168 words; want 3..=25
2026-07-11T01:39:54.0152111Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-CR-LINESAFE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0152441Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-CR-LINESAFE criterion=length — title is 73 words; want 3..=25
2026-07-11T01:39:54.0152866Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-PARSER-SAFE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0153148Z   [must] requirement_quality REQ-HAZARD-EPOCH-RESET criterion=length — title is 60 words; want 3..=25
2026-07-11T01:39:54.0153538Z   [must] requirement_quality REQ-HAZARD-GEN-START-NOW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0153890Z   [must] requirement_quality REQ-HAZARD-HOSTED-LIVENESS-RECONCILE criterion=length — title is 175 words; want 3..=25
2026-07-11T01:39:54.0154311Z   [must] requirement_quality REQ-HAZARD-IDLE-SILENT-NONDELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0154640Z   [must] requirement_quality REQ-HAZARD-IDLE-SILENT-NONDELIVERY criterion=length — title is 436 words; want 3..=25
2026-07-11T01:39:54.0155055Z   [must] requirement_quality REQ-HAZARD-INJECT-CONTROL-COEXIST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0155388Z   [must] requirement_quality REQ-HAZARD-INJECT-CONTROL-COEXIST criterion=length — title is 340 words; want 3..=25
2026-07-11T01:39:54.0155801Z   [must] requirement_quality REQ-HAZARD-INJECT-SETTLE-REARM criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0156116Z   [must] requirement_quality REQ-HAZARD-INJECT-SETTLE-REARM criterion=length — title is 184 words; want 3..=25
2026-07-11T01:39:54.0156531Z   [must] requirement_quality REQ-HAZARD-INJECT-WORKER-POISON criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0156846Z   [must] requirement_quality REQ-HAZARD-INJECT-WORKER-POISON criterion=length — title is 136 words; want 3..=25
2026-07-11T01:39:54.0157276Z   [must] requirement_quality REQ-HAZARD-INPUT-ACK-BACKPRESSURE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0157609Z   [must] requirement_quality REQ-HAZARD-INPUT-ACK-BACKPRESSURE criterion=length — title is 343 words; want 3..=25
2026-07-11T01:39:54.0157912Z   [must] requirement_quality REQ-HAZARD-INSTANT-UNDERFLOW criterion=length — title is 30 words; want 3..=25
2026-07-11T01:39:54.0158302Z   [must] requirement_quality REQ-HAZARD-LISTEN-ORPHAN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0158598Z   [must] requirement_quality REQ-HAZARD-LISTEN-ORPHAN criterion=length — title is 93 words; want 3..=25
2026-07-11T01:39:54.0159036Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-LIVENESS-GATE criterion=length — title is 122 words; want 3..=25
2026-07-11T01:39:54.0159437Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0159752Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-RACE criterion=length — title is 158 words; want 3..=25
2026-07-11T01:39:54.0160396Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-NONRESIDENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0160708Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-NONRESIDENT criterion=length — title is 171 words; want 3..=25
2026-07-11T01:39:54.0161112Z   [must] requirement_quality REQ-HAZARD-PAIR-RATE-LIMIT criterion=length — title is 37 words; want 3..=25
2026-07-11T01:39:54.0161422Z   [must] requirement_quality REQ-HAZARD-PAIR-SEED-ROTATION criterion=length — title is 33 words; want 3..=25
2026-07-11T01:39:54.0161832Z   [must] requirement_quality REQ-HAZARD-PAIR-TRANSCRIPT-BIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0162251Z   [must] requirement_quality REQ-HAZARD-PSYCHE-OUTBOUND-PROXY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0162575Z   [must] requirement_quality REQ-HAZARD-PSYCHE-OUTBOUND-PROXY criterion=length — title is 27 words; want 3..=25
2026-07-11T01:39:54.0163024Z   [must] requirement_quality REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0163370Z   [must] requirement_quality REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION criterion=length — title is 130 words; want 3..=25
2026-07-11T01:39:54.0163797Z   [must] requirement_quality REQ-HAZARD-PTY-INPUT-WRITER-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0164112Z   [must] requirement_quality REQ-HAZARD-PTY-INPUT-WRITER-WEDGE criterion=length — title is 287 words; want 3..=25
2026-07-11T01:39:54.0164513Z   [must] requirement_quality REQ-HAZARD-PUMP-IPC-DEADLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0164823Z   [must] requirement_quality REQ-HAZARD-PUMP-IPC-DEADLINE criterion=length — title is 38 words; want 3..=25
2026-07-11T01:39:54.0165229Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-FAILFAST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0165544Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-FAILFAST criterion=length — title is 163 words; want 3..=25
2026-07-11T01:39:54.0165976Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-ONLINE-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0166291Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-ONLINE-RACE criterion=length — title is 184 words; want 3..=25
2026-07-11T01:39:54.0166657Z   [must] requirement_quality REQ-HAZARD-RC-EOF criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0166925Z   [must] requirement_quality REQ-HAZARD-RC-EOF criterion=length — title is 208 words; want 3..=25
2026-07-11T01:39:54.0167339Z   [must] requirement_quality REQ-HAZARD-RC-INPUT-KEY-ENCODING criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0167663Z   [must] requirement_quality REQ-HAZARD-RC-INPUT-KEY-ENCODING criterion=length — title is 222 words; want 3..=25
2026-07-11T01:39:54.0168075Z   [must] requirement_quality REQ-HAZARD-REGISTRY-GHOST-ROWS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0168401Z   [must] requirement_quality REQ-HAZARD-REGISTRY-GHOST-ROWS criterion=length — title is 152 words; want 3..=25
2026-07-11T01:39:54.0168718Z   [must] requirement_quality REQ-HAZARD-ROLLBACK-STATE-COMPAT criterion=length — title is 72 words; want 3..=25
2026-07-11T01:39:54.0169168Z   [must] requirement_quality REQ-HAZARD-ROSTER-GHOST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0169458Z   [must] requirement_quality REQ-HAZARD-ROSTER-GHOST criterion=length — title is 116 words; want 3..=25
2026-07-11T01:39:54.0169915Z   [must] requirement_quality REQ-HAZARD-SEEDMAP-CONNECT-UNBOUNDED criterion=length — title is 171 words; want 3..=25
2026-07-11T01:39:54.0170298Z   [must] requirement_quality REQ-HAZARD-SELF-ELEVATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0170583Z   [must] requirement_quality REQ-HAZARD-SELF-ELEVATE criterion=length — title is 101 words; want 3..=25
2026-07-11T01:39:54.0171102Z   [must] requirement_quality REQ-HAZARD-SESSION-PIN-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0171410Z   [must] requirement_quality REQ-HAZARD-SESSION-PIN-WEDGE criterion=length — title is 320 words; want 3..=25
2026-07-11T01:39:54.0171905Z   [must] requirement_quality REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0172311Z   [must] requirement_quality REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK criterion=length — title is 461 words; want 3..=25
2026-07-11T01:39:54.0172663Z   [must] requirement_quality REQ-HAZARD-SPOOL-SENTINEL-CREATE-FAIL criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0173107Z   [must] requirement_quality REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0173470Z   [must] requirement_quality REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0173874Z   [must] requirement_quality REQ-HAZARD-STORE-INIT-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0174172Z   [must] requirement_quality REQ-HAZARD-STORE-INIT-RACE criterion=length — title is 149 words; want 3..=25
2026-07-11T01:39:54.0174472Z   [must] requirement_quality REQ-HAZARD-SUDO-SECURE-PATH criterion=length — title is 43 words; want 3..=25
2026-07-11T01:39:54.0174883Z   [must] requirement_quality REQ-HAZARD-TEMPLATE-ARGV-FILL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0175192Z   [must] requirement_quality REQ-HAZARD-TEMPLATE-ARGV-FILL criterion=length — title is 166 words; want 3..=25
2026-07-11T01:39:54.0175512Z   [must] requirement_quality REQ-HAZARD-THRASH-GUARD-BLIND criterion=length — title is 62 words; want 3..=25
2026-07-11T01:39:54.0175974Z   [must] requirement_quality REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0176347Z   [must] requirement_quality REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH criterion=length — title is 91 words; want 3..=25
2026-07-11T01:39:54.0176755Z   [must] requirement_quality REQ-HAZARD-UNHOST-PSYCHE-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0177065Z   [must] requirement_quality REQ-HAZARD-UNHOST-PSYCHE-REAP criterion=length — title is 161 words; want 3..=25
2026-07-11T01:39:54.0177485Z   [must] requirement_quality REQ-HAZARD-VIEWER-CLOSE-DETACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0177799Z   [must] requirement_quality REQ-HAZARD-VIEWER-CLOSE-DETACH criterion=length — title is 437 words; want 3..=25
2026-07-11T01:39:54.0178204Z   [must] requirement_quality REQ-HAZARD-VIEWER-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0178510Z   [must] requirement_quality REQ-HAZARD-VIEWER-ISOLATION criterion=length — title is 118 words; want 3..=25
2026-07-11T01:39:54.0178923Z   [must] requirement_quality REQ-HAZARD-VIEWER-RING-ROLL-SNAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0179312Z   [must] requirement_quality REQ-HAZARD-VIEWER-RING-ROLL-SNAP criterion=length — title is 167 words; want 3..=25
2026-07-11T01:39:54.0179812Z   [must] requirement_quality REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0180347Z   [must] requirement_quality REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE criterion=length — title is 235 words; want 3..=25
2026-07-11T01:39:54.0180647Z   [must] requirement_quality REQ-HAZARD-WAN-ORIGIN-AUTH criterion=length — title is 37 words; want 3..=25
2026-07-11T01:39:54.0181168Z   [must] requirement_quality REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0181497Z   [must] requirement_quality REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE criterion=length — title is 96 words; want 3..=25
2026-07-11T01:39:54.0181805Z   [must] requirement_quality REQ-HAZARD-WMI-DAEMON-WINDOW criterion=length — title is 101 words; want 3..=25
2026-07-11T01:39:54.0182069Z   [must] requirement_quality REQ-HOST-RUN-1 criterion=length — title is 88 words; want 3..=25
2026-07-11T01:39:54.0182327Z   [must] requirement_quality REQ-HOST-RUN-2 criterion=length — title is 97 words; want 3..=25
2026-07-11T01:39:54.0182723Z   [must] requirement_quality REQ-IDLE-PARKED-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0183023Z   [must] requirement_quality REQ-IDLE-PARKED-DELIVERY criterion=length — title is 116 words; want 3..=25
2026-07-11T01:39:54.0183343Z   [must] requirement_quality REQ-INJECT-MULTILINE-INTEGRITY criterion=length — title is 118 words; want 3..=25
2026-07-11T01:39:54.0183600Z   [must] requirement_quality REQ-INST-15 criterion=length — title is 32 words; want 3..=25
2026-07-11T01:39:54.0183953Z   [must] requirement_quality REQ-INSTALL-10 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0184210Z   [must] requirement_quality REQ-INSTALL-10 criterion=length — title is 58 words; want 3..=25
2026-07-11T01:39:54.0184471Z   [must] requirement_quality REQ-INSTALL-11 criterion=length — title is 78 words; want 3..=25
2026-07-11T01:39:54.0184732Z   [must] requirement_quality REQ-INSTALL-12 criterion=length — title is 116 words; want 3..=25
2026-07-11T01:39:54.0185095Z   [must] requirement_quality REQ-INSTALL-13 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0185352Z   [must] requirement_quality REQ-INSTALL-13 criterion=length — title is 131 words; want 3..=25
2026-07-11T01:39:54.0185603Z   [must] requirement_quality REQ-INSTALL-2 criterion=length — title is 2 word(s); want 3..=25
2026-07-11T01:39:54.0185957Z   [must] requirement_quality REQ-INSTALL-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0186210Z   [must] requirement_quality REQ-INSTALL-6 criterion=length — title is 56 words; want 3..=25
2026-07-11T01:39:54.0186567Z   [must] requirement_quality REQ-INSTALL-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0186820Z   [must] requirement_quality REQ-INSTALL-7 criterion=length — title is 50 words; want 3..=25
2026-07-11T01:39:54.0187078Z   [must] requirement_quality REQ-INSTALL-8 criterion=length — title is 55 words; want 3..=25
2026-07-11T01:39:54.0187421Z   [must] requirement_quality REQ-INSTALL-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0187688Z   [must] requirement_quality REQ-INSTALL-9 criterion=length — title is 62 words; want 3..=25
2026-07-11T01:39:54.0188093Z   [must] requirement_quality REQ-JOIN-DEFERRED-ELEVATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0188398Z   [must] requirement_quality REQ-JOIN-DEFERRED-ELEVATION criterion=length — title is 156 words; want 3..=25
2026-07-11T01:39:54.0188788Z   [must] requirement_quality REQ-JOIN-DIAGNOSTICS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0189233Z   [must] requirement_quality REQ-JOIN-DIAGNOSTICS criterion=length — title is 137 words; want 3..=25
2026-07-11T01:39:54.0189512Z   [must] requirement_quality REQ-JOIN-TWO-PHASE criterion=length — title is 161 words; want 3..=25
2026-07-11T01:39:54.0189892Z   [must] requirement_quality REQ-JOIN-VERBOSE-CLOCK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0190283Z   [must] requirement_quality REQ-JOIN-VERBOSE-CLOCK criterion=length — title is 108 words; want 3..=25
2026-07-11T01:39:54.0190631Z   [must] requirement_quality REQ-KICK-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0190874Z   [must] requirement_quality REQ-KICK-1 criterion=length — title is 133 words; want 3..=25
2026-07-11T01:39:54.0191284Z   [must] requirement_quality REQ-LIST-JSON-LIVENESS-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0191593Z   [must] requirement_quality REQ-LIST-JSON-LIVENESS-PARITY criterion=length — title is 240 words; want 3..=25
2026-07-11T01:39:54.0192028Z   [must] requirement_quality REQ-LISTEN-SEED-CONSUME-AFTER-BIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0192365Z   [must] requirement_quality REQ-LISTEN-SEED-CONSUME-AFTER-BIND criterion=length — title is 167 words; want 3..=25
2026-07-11T01:39:54.0192783Z   [must] requirement_quality REQ-LISTEN-SESSION-ID-FALLBACK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0193102Z   [must] requirement_quality REQ-LISTEN-SESSION-ID-FALLBACK criterion=length — title is 185 words; want 3..=25
2026-07-11T01:39:54.0193521Z   [must] requirement_quality REQ-LIVE-AGENT-NO-INJECT-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0193846Z   [must] requirement_quality REQ-LIVE-AGENT-NO-INJECT-DELIVERY criterion=length — title is 275 words; want 3..=25
2026-07-11T01:39:54.0194290Z   [must] requirement_quality REQ-LIVEHOST-RECONCILE-TRIAL-SILENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0194615Z   [must] requirement_quality REQ-LIVEHOST-RECONCILE-TRIAL-SILENT criterion=length — title is 214 words; want 3..=25
2026-07-11T01:39:54.0194975Z   [must] requirement_quality REQ-MANIFEST-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0195244Z   [must] requirement_quality REQ-MANIFEST-3 criterion=length — title is 26 words; want 3..=25
2026-07-11T01:39:54.0195506Z   [must] requirement_quality REQ-MANIFEST-4 criterion=length — title is 31 words; want 3..=25
2026-07-11T01:39:54.0195759Z   [must] requirement_quality REQ-MANIFEST-5 criterion=length — title is 132 words; want 3..=25
2026-07-11T01:39:54.0196017Z   [must] requirement_quality REQ-MANIFEST-6 criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0196280Z   [must] requirement_quality REQ-MANIFEST-7 criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0196537Z   [must] requirement_quality REQ-MANIFEST-8 criterion=length — title is 77 words; want 3..=25
2026-07-11T01:39:54.0196924Z   [must] requirement_quality REQ-MANIFEST-NODE-KEY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0197225Z   [must] requirement_quality REQ-MANIFEST-NODE-KEY criterion=length — title is 187 words; want 3..=25
2026-07-11T01:39:54.0197605Z   [must] requirement_quality REQ-MANIFEST-SUBST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0197885Z   [must] requirement_quality REQ-MANIFEST-SUBST criterion=length — title is 121 words; want 3..=25
2026-07-11T01:39:54.0198128Z   [must] requirement_quality REQ-MESH-1 criterion=length — title is 86 words; want 3..=25
2026-07-11T01:39:54.0198477Z   [must] requirement_quality REQ-MESH-2 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0198830Z   [must] requirement_quality REQ-MESH-2 criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0199263Z   [must] requirement_quality REQ-MESH-3 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0199502Z   [must] requirement_quality REQ-MESH-3 criterion=length — title is 86 words; want 3..=25
2026-07-11T01:39:54.0199948Z   [must] requirement_quality REQ-MESH-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0200205Z   [must] requirement_quality REQ-MESH-4 criterion=length — title is 99 words; want 3..=25
2026-07-11T01:39:54.0200552Z   [must] requirement_quality REQ-MESH-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0200796Z   [must] requirement_quality REQ-MESH-5 criterion=length — title is 72 words; want 3..=25
2026-07-11T01:39:54.0201134Z   [must] requirement_quality REQ-MESH-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0201382Z   [must] requirement_quality REQ-MESH-6 criterion=length — title is 56 words; want 3..=25
2026-07-11T01:39:54.0201735Z   [must] requirement_quality REQ-MIGRATE-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0201983Z   [must] requirement_quality REQ-MSG-4 criterion=length — title is 31 words; want 3..=25
2026-07-11T01:39:54.0202225Z   [must] requirement_quality REQ-MSG-5 criterion=length — title is 38 words; want 3..=25
2026-07-11T01:39:54.0202458Z   [must] requirement_quality REQ-MSG-6 criterion=length — title is 65 words; want 3..=25
2026-07-11T01:39:54.0202835Z   [must] requirement_quality REQ-MSG-CLI-ORIGIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0203109Z   [must] requirement_quality REQ-MSG-CLI-ORIGIN criterion=length — title is 107 words; want 3..=25
2026-07-11T01:39:54.0203504Z   [must] requirement_quality REQ-MSG-DELIVERY-AXES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0203795Z   [must] requirement_quality REQ-MSG-DELIVERY-AXES criterion=length — title is 291 words; want 3..=25
2026-07-11T01:39:54.0204157Z   [must] requirement_quality REQ-MSG-ENVELOPE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0204434Z   [must] requirement_quality REQ-MSG-ENVELOPE criterion=length — title is 153 words; want 3..=25
2026-07-11T01:39:54.0204825Z   [must] requirement_quality REQ-MSG-IDLE-EDGE-DRAIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0205126Z   [must] requirement_quality REQ-MSG-IDLE-EDGE-DRAIN criterion=length — title is 121 words; want 3..=25
2026-07-11T01:39:54.0205535Z   [must] requirement_quality REQ-MSG-IDLE-TRANSLATION-BINARY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0205871Z   [must] requirement_quality REQ-MSG-IDLE-TRANSLATION-BINARY criterion=length — title is 269 words; want 3..=25
2026-07-11T01:39:54.0206282Z   [must] requirement_quality REQ-MSG-SELF-DETECT-ANCESTRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0206587Z   [must] requirement_quality REQ-MSG-SELF-DETECT-ANCESTRY criterion=length — title is 153 words; want 3..=25
2026-07-11T01:39:54.0206982Z   [must] requirement_quality REQ-NET-FAMILY-GATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0207278Z   [must] requirement_quality REQ-NET-FAMILY-GATE criterion=length — title is 118 words; want 3..=25
2026-07-11T01:39:54.0207674Z   [must] requirement_quality REQ-OPID-MINTER-NAMESPACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0207979Z   [must] requirement_quality REQ-OPID-MINTER-NAMESPACE criterion=length — title is 337 words; want 3..=25
2026-07-11T01:39:54.0208536Z   [must] requirement_quality REQ-OPID-TRACING-RETRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0208827Z   [must] requirement_quality REQ-OPID-TRACING-RETRY criterion=length — title is 222 words; want 3..=25
2026-07-11T01:39:54.0209346Z   [must] requirement_quality REQ-PAIR-8 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0209594Z   [must] requirement_quality REQ-PAIR-8 criterion=length — title is 67 words; want 3..=25
2026-07-11T01:39:54.0209981Z   [must] requirement_quality REQ-PAIR-NTP-LOUD-FAIL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0210262Z   [must] requirement_quality REQ-PAIR-NTP-LOUD-FAIL criterion=length — title is 104 words; want 3..=25
2026-07-11T01:39:54.0210652Z   [must] requirement_quality REQ-PAIR-NTP-MULTIHOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0210945Z   [must] requirement_quality REQ-PAIR-NTP-MULTIHOME criterion=length — title is 131 words; want 3..=25
2026-07-11T01:39:54.0211346Z   [must] requirement_quality REQ-PEER-PUMP-CHURN-STALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0211642Z   [must] requirement_quality REQ-PEER-PUMP-CHURN-STALL criterion=length — title is 97 words; want 3..=25
2026-07-11T01:39:54.0212004Z   [must] requirement_quality REQ-PICKER-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0212257Z   [must] requirement_quality REQ-PICKER-1 criterion=length — title is 156 words; want 3..=25
2026-07-11T01:39:54.0212504Z   [must] requirement_quality REQ-PICKER-2 criterion=length — title is 77 words; want 3..=25
2026-07-11T01:39:54.0212762Z   [must] requirement_quality REQ-PICKER-3 criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0213109Z   [must] requirement_quality REQ-PICKER-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0213357Z   [must] requirement_quality REQ-PICKER-4 criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0213707Z   [must] requirement_quality REQ-PICKER-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0213966Z   [must] requirement_quality REQ-PICKER-5 criterion=length — title is 147 words; want 3..=25
2026-07-11T01:39:54.0214384Z   [must] requirement_quality REQ-PICKER-ADAPTER-DESCRIPTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0214698Z   [must] requirement_quality REQ-PICKER-ADAPTER-DESCRIPTION criterion=length — title is 64 words; want 3..=25
2026-07-11T01:39:54.0215075Z   [must] requirement_quality REQ-PICKER-BACK-NAV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0215468Z   [must] requirement_quality REQ-PICKER-BACK-NAV criterion=length — title is 140 words; want 3..=25
2026-07-11T01:39:54.0215891Z   [must] requirement_quality REQ-PICKER-CHANGE-ADAPTER-FLOW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0216208Z   [must] requirement_quality REQ-PICKER-CHANGE-ADAPTER-FLOW criterion=length — title is 117 words; want 3..=25
2026-07-11T01:39:54.0216612Z   [must] requirement_quality REQ-PICKER-CHOOSE-DEDUP-ALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0216922Z   [must] requirement_quality REQ-PICKER-CHOOSE-DEDUP-ALL criterion=length — title is 72 words; want 3..=25
2026-07-11T01:39:54.0217251Z   [must] requirement_quality REQ-PICKER-CONTROL-LINE-STATUS-GATE criterion=length — title is 71 words; want 3..=25
2026-07-11T01:39:54.0217647Z   [must] requirement_quality REQ-PICKER-CONTROLLED-LOCAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0217967Z   [must] requirement_quality REQ-PICKER-CONTROLLED-LOCAL criterion=length — title is 95 words; want 3..=25
2026-07-11T01:39:54.0218272Z   [must] requirement_quality REQ-PICKER-CURRENT-DIR-LABEL criterion=length — title is 114 words; want 3..=25
2026-07-11T01:39:54.0218664Z   [must] requirement_quality REQ-PICKER-FORK-LABEL-CWD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0219101Z   [must] requirement_quality REQ-PICKER-FORK-LABEL-CWD criterion=length — title is 58 words; want 3..=25
2026-07-11T01:39:54.0219401Z   [must] requirement_quality REQ-PICKER-HISTORY-FRESH criterion=length — title is 51 words; want 3..=25
2026-07-11T01:39:54.0219735Z   [must] requirement_quality REQ-PICKER-HISTORY-FRESH criterion=tbd-todo — title contains placeholder marker 'TBD'
2026-07-11T01:39:54.0220059Z   [must] requirement_quality REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE criterion=length — title is 89 words; want 3..=25
2026-07-11T01:39:54.0220359Z   [must] requirement_quality REQ-PICKER-NODE-GROUPING criterion=length — title is 73 words; want 3..=25
2026-07-11T01:39:54.0220655Z   [must] requirement_quality REQ-PICKER-OFFLINE-NO-VIEW criterion=length — title is 46 words; want 3..=25
2026-07-11T01:39:54.0220951Z   [must] requirement_quality REQ-PICKER-ONLINE-ACTION criterion=length — title is 74 words; want 3..=25
2026-07-11T01:39:54.0221283Z   [must] requirement_quality REQ-PICKER-ONLINE-ACTION criterion=tbd-todo — title contains placeholder marker 'TBD'
2026-07-11T01:39:54.0221611Z   [must] requirement_quality REQ-PICKER-PROJECT-DISPLAY-NAME criterion=length — title is 103 words; want 3..=25
2026-07-11T01:39:54.0221935Z   [must] requirement_quality REQ-PICKER-PROJECT-HISTORY-TRUTH criterion=length — title is 128 words; want 3..=25
2026-07-11T01:39:54.0222320Z   [must] requirement_quality REQ-PICKER-PURGE-SHORTCUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0222635Z   [must] requirement_quality REQ-PICKER-PURGE-SHORTCUT criterion=length — title is 180 words; want 3..=25
2026-07-11T01:39:54.0223012Z   [must] requirement_quality REQ-PICKER-REMOTE-WAKE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0223303Z   [must] requirement_quality REQ-PICKER-REMOTE-WAKE criterion=length — title is 296 words; want 3..=25
2026-07-11T01:39:54.0223728Z   [must] requirement_quality REQ-PICKER-RESUME-CONTEXT-PANEL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0224040Z   [must] requirement_quality REQ-PICKER-RESUME-CONTEXT-PANEL criterion=length — title is 53 words; want 3..=25
2026-07-11T01:39:54.0224469Z   [must] requirement_quality REQ-PICKER-SHORTCUT-LABEL-FILENAME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0224798Z   [must] requirement_quality REQ-PICKER-SHORTCUT-LABEL-FILENAME criterion=length — title is 75 words; want 3..=25
2026-07-11T01:39:54.0225226Z   [must] requirement_quality REQ-PICKER-START-PROJECT-CHOICE criterion=length — title is 87 words; want 3..=25
2026-07-11T01:39:54.0225588Z   [must] requirement_quality REQ-PICKER-UX-V013 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0235189Z   [must] requirement_quality REQ-PICKER-UX-V013 criterion=length — title is 86 words; want 3..=25
2026-07-11T01:39:54.0235557Z   [must] requirement_quality REQ-PICKER-WINDOW-TITLE criterion=length — title is 68 words; want 3..=25
2026-07-11T01:39:54.0235944Z   [must] requirement_quality REQ-PLATFORM-MUSL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0236235Z   [must] requirement_quality REQ-PLATFORM-MUSL criterion=length — title is 106 words; want 3..=25
2026-07-11T01:39:54.0236626Z   [must] requirement_quality REQ-PLATFORM-REGISTRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0236931Z   [must] requirement_quality REQ-PLATFORM-REGISTRY criterion=length — title is 126 words; want 3..=25
2026-07-11T01:39:54.0237286Z   [must] requirement_quality REQ-PRES-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0237537Z   [must] requirement_quality REQ-PRES-1 criterion=length — title is 48 words; want 3..=25
2026-07-11T01:39:54.0238123Z   [must] requirement_quality REQ-PRESENCE-CONTROL-REAP-ON-EXIT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0238463Z   [must] requirement_quality REQ-PRESENCE-CONTROL-REAP-ON-EXIT criterion=length — title is 139 words; want 3..=25
2026-07-11T01:39:54.0238777Z   [must] requirement_quality REQ-PRESENCE-LIVENESS-TRUTH criterion=length — title is 215 words; want 3..=25
2026-07-11T01:39:54.0239292Z   [must] requirement_quality REQ-PSYCHE-CONTEXT-FILE-INDIRECTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0239645Z   [must] requirement_quality REQ-PSYCHE-CONTEXT-FILE-INDIRECTION criterion=length — title is 206 words; want 3..=25
2026-07-11T01:39:54.0240150Z   [must] requirement_quality REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0240497Z   [must] requirement_quality REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN criterion=length — title is 90 words; want 3..=25
2026-07-11T01:39:54.0240911Z   [must] requirement_quality REQ-PSYCHE-EPHEMERAL-DRIVER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0241212Z   [must] requirement_quality REQ-PSYCHE-EPHEMERAL-DRIVER criterion=length — title is 146 words; want 3..=25
2026-07-11T01:39:54.0241642Z   [must] requirement_quality REQ-PSYCHE-LEGACY-RESIDENT-SWEEP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0241966Z   [must] requirement_quality REQ-PSYCHE-LEGACY-RESIDENT-SWEEP criterion=length — title is 282 words; want 3..=25
2026-07-11T01:39:54.0242380Z   [must] requirement_quality REQ-PSYCHE-NESTED-RESOLUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0242702Z   [must] requirement_quality REQ-PSYCHE-NESTED-RESOLUTION criterion=length — title is 147 words; want 3..=25
2026-07-11T01:39:54.0243022Z   [must] requirement_quality REQ-PSYCHE-ROLE-OPTIONAL-SKIP criterion=length — title is 59 words; want 3..=25
2026-07-11T01:39:54.0243403Z   [must] requirement_quality REQ-PSYCHE-SID-CUSTODY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0243708Z   [must] requirement_quality REQ-PSYCHE-SID-CUSTODY criterion=length — title is 134 words; want 3..=25
2026-07-11T01:39:54.0244122Z   [must] requirement_quality REQ-PSYCHE-SPAWN-ENV-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0244587Z   [must] requirement_quality REQ-PSYCHE-SPAWN-ENV-PARITY criterion=length — title is 167 words; want 3..=25
2026-07-11T01:39:54.0245014Z   [must] requirement_quality REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0245345Z   [must] requirement_quality REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS criterion=length — title is 59 words; want 3..=25
2026-07-11T01:39:54.0245749Z   [must] requirement_quality REQ-PUBLIC-ERROR-SURFACES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0246050Z   [must] requirement_quality REQ-PUBLIC-ERROR-SURFACES criterion=length — title is 217 words; want 3..=25
2026-07-11T01:39:54.0246437Z   [must] requirement_quality REQ-PUMP-DIAL-FASTFAIL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0246717Z   [must] requirement_quality REQ-PUMP-DIAL-FASTFAIL criterion=length — title is 324 words; want 3..=25
2026-07-11T01:39:54.0247125Z   [must] requirement_quality REQ-PUMP-PEER-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0247410Z   [must] requirement_quality REQ-PUMP-PEER-ISOLATION criterion=length — title is 199 words; want 3..=25
2026-07-11T01:39:54.0247646Z   [must] requirement_quality REQ-RC-1 criterion=length — title is 94 words; want 3..=25
2026-07-11T01:39:54.0248151Z   [must] requirement_quality REQ-RC-CROSS-NODE-ATTACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0248475Z   [must] requirement_quality REQ-RC-CROSS-NODE-ATTACH criterion=length — title is 95 words; want 3..=25
2026-07-11T01:39:54.0248836Z   [must] requirement_quality REQ-RC-IDENTITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0249204Z   [must] requirement_quality REQ-RC-IDENTITY criterion=length — title is 122 words; want 3..=25
2026-07-11T01:39:54.0249609Z   [must] requirement_quality REQ-RC-IDMARKER-DISABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0249899Z   [must] requirement_quality REQ-RC-IDMARKER-DISABLE criterion=length — title is 73 words; want 3..=25
2026-07-11T01:39:54.0250277Z   [must] requirement_quality REQ-RC-KEY-VT-TRANSLATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0250580Z   [must] requirement_quality REQ-RC-KEY-VT-TRANSLATE criterion=length — title is 249 words; want 3..=25
2026-07-11T01:39:54.0250948Z   [must] requirement_quality REQ-RC-MOUSE-FORWARD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0251238Z   [must] requirement_quality REQ-RC-MOUSE-FORWARD criterion=length — title is 218 words; want 3..=25
2026-07-11T01:39:54.0251597Z   [must] requirement_quality REQ-RC-RECONNECT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0251877Z   [must] requirement_quality REQ-RC-RECONNECT criterion=length — title is 244 words; want 3..=25
2026-07-11T01:39:54.0252270Z   [must] requirement_quality REQ-RC-RECONNECT-TRUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0252551Z   [must] requirement_quality REQ-RC-RECONNECT-TRUTH criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0252935Z   [must] requirement_quality REQ-RC-WIN-PASTE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0253200Z   [must] requirement_quality REQ-RC-WIN-PASTE criterion=length — title is 226 words; want 3..=25
2026-07-11T01:39:54.0253582Z   [must] requirement_quality REQ-RC-WIN-VT-OUTPUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0253859Z   [must] requirement_quality REQ-RC-WIN-VT-OUTPUT criterion=length — title is 150 words; want 3..=25
2026-07-11T01:39:54.0254391Z   [must] requirement_quality REQ-RCVIEW-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0254649Z   [must] requirement_quality REQ-RCVIEW-1 criterion=length — title is 197 words; want 3..=25
2026-07-11T01:39:54.0255031Z   [must] requirement_quality REQ-READY-AGENT-RESUME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0255346Z   [must] requirement_quality REQ-READY-AGENT-RESUME criterion=length — title is 165 words; want 3..=25
2026-07-11T01:39:54.0255654Z   [must] requirement_quality REQ-RELAY-NO-BUSY-DELIVER criterion=length — title is 159 words; want 3..=25
2026-07-11T01:39:54.0255943Z   [must] requirement_quality REQ-RELEASE-MUSL-ARTIFACT criterion=length — title is 114 words; want 3..=25
2026-07-11T01:39:54.0256328Z   [must] requirement_quality REQ-REST-VERB-ROUTING criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0256615Z   [must] requirement_quality REQ-REST-VERB-ROUTING criterion=length — title is 326 words; want 3..=25
2026-07-11T01:39:54.0257050Z   [must] requirement_quality REQ-RESUME-ADAPTER-FOLLOWS-SESSION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0257384Z   [must] requirement_quality REQ-RESUME-ADAPTER-FOLLOWS-SESSION criterion=length — title is 275 words; want 3..=25
2026-07-11T01:39:54.0257879Z   [must] requirement_quality REQ-RESUME-CONTEXT-PULL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0258179Z   [must] requirement_quality REQ-RESUME-CONTEXT-PULL criterion=length — title is 460 words; want 3..=25
2026-07-11T01:39:54.0258491Z   [must] requirement_quality REQ-RESUME-HARNESS-SESSION-ID criterion=length — title is 128 words; want 3..=25
2026-07-11T01:39:54.0258801Z   [must] requirement_quality REQ-RESUME-REAP-PRIOR-HARNESS criterion=length — title is 54 words; want 3..=25
2026-07-11T01:39:54.0259191Z   [must] requirement_quality REQ-RESUME-ROW-PER-PROJECT criterion=length — title is 59 words; want 3..=25
2026-07-11T01:39:54.0259482Z   [must] requirement_quality REQ-RUN-EMPTY-CREATE criterion=length — title is 63 words; want 3..=25
2026-07-11T01:39:54.0259883Z   [must] requirement_quality REQ-RUN-ID-REUSES-ADAPTER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0260183Z   [must] requirement_quality REQ-RUN-ID-REUSES-ADAPTER criterion=length — title is 174 words; want 3..=25
2026-07-11T01:39:54.0260576Z   [must] requirement_quality REQ-RUN-MULTISUBNET-HOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0260876Z   [must] requirement_quality REQ-RUN-MULTISUBNET-HOME criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0261266Z   [must] requirement_quality REQ-RUN-NO-DUP-SESSION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0261556Z   [must] requirement_quality REQ-RUN-NO-DUP-SESSION criterion=length — title is 137 words; want 3..=25
2026-07-11T01:39:54.0261923Z   [must] requirement_quality REQ-RUN-PICKER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0262190Z   [must] requirement_quality REQ-RUN-PICKER criterion=length — title is 203 words; want 3..=25
2026-07-11T01:39:54.0262572Z   [must] requirement_quality REQ-RUN-PICKER-HOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0262854Z   [must] requirement_quality REQ-RUN-PICKER-HOME criterion=length — title is 156 words; want 3..=25
2026-07-11T01:39:54.0263211Z   [must] requirement_quality REQ-RUN-SHORTCUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0263486Z   [must] requirement_quality REQ-RUN-SHORTCUT criterion=length — title is 226 words; want 3..=25
2026-07-11T01:39:54.0263751Z   [must] requirement_quality REQ-SEAM-SPAWN criterion=length — title is 2 word(s); want 3..=25
2026-07-11T01:39:54.0264265Z   [must] requirement_quality REQ-SELF-DETECT-PARENT-PID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0264575Z   [must] requirement_quality REQ-SELF-DETECT-PARENT-PID criterion=length — title is 224 words; want 3..=25
2026-07-11T01:39:54.0264985Z   [must] requirement_quality REQ-SELF-ID-TRUST-INJECTED-ENV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0265305Z   [must] requirement_quality REQ-SELF-ID-TRUST-INJECTED-ENV criterion=length — title is 232 words; want 3..=25
2026-07-11T01:39:54.0265687Z   [must] requirement_quality REQ-SEND-REPLYTO-REMOVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0265978Z   [must] requirement_quality REQ-SEND-REPLYTO-REMOVE criterion=length — title is 60 words; want 3..=25
2026-07-11T01:39:54.0266362Z   [must] requirement_quality REQ-SEND-SPT-HOSTED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0266646Z   [must] requirement_quality REQ-SEND-SPT-HOSTED criterion=length — title is 169 words; want 3..=25
2026-07-11T01:39:54.0267028Z   [must] requirement_quality REQ-SEND-STAMP-AGENT-ID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0267428Z   [must] requirement_quality REQ-SEND-STAMP-AGENT-ID criterion=length — title is 189 words; want 3..=25
2026-07-11T01:39:54.0267838Z   [must] requirement_quality REQ-SEND-WINDOW-DRAIN-HONOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0268148Z   [must] requirement_quality REQ-SEND-WINDOW-DRAIN-HONOR criterion=length — title is 278 words; want 3..=25
2026-07-11T01:39:54.0268554Z   [must] requirement_quality REQ-SESSION-ADAPTER-RECORDED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0268886Z   [must] requirement_quality REQ-SESSION-ADAPTER-RECORDED criterion=length — title is 205 words; want 3..=25
2026-07-11T01:39:54.0269361Z   [must] requirement_quality REQ-SESSION-RESUME-TEMPLATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0269671Z   [must] requirement_quality REQ-SESSION-RESUME-TEMPLATE criterion=length — title is 287 words; want 3..=25
2026-07-11T01:39:54.0270124Z   [must] requirement_quality REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0270467Z   [must] requirement_quality REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0270724Z   [must] requirement_quality REQ-SHELL-1 criterion=length — title is 36 words; want 3..=25
2026-07-11T01:39:54.0270962Z   [must] requirement_quality REQ-SHELL-2 criterion=length — title is 49 words; want 3..=25
2026-07-11T01:39:54.0271220Z   [must] requirement_quality REQ-SHELL-3 criterion=length — title is 80 words; want 3..=25
2026-07-11T01:39:54.0271568Z   [must] requirement_quality REQ-SHELL-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0271826Z   [must] requirement_quality REQ-SHELL-4 criterion=length — title is 84 words; want 3..=25
2026-07-11T01:39:54.0272078Z   [must] requirement_quality REQ-SHELL-5 criterion=length — title is 49 words; want 3..=25
2026-07-11T01:39:54.0272516Z   [must] requirement_quality REQ-SOFT-END-PRESERVES-LIVE-LISTENER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0272859Z   [must] requirement_quality REQ-SOFT-END-PRESERVES-LIVE-LISTENER criterion=length — title is 246 words; want 3..=25
2026-07-11T01:39:54.0273283Z   [must] requirement_quality REQ-SPAWN-COLLISION-GUARD-LIVE-DUP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0273719Z   [must] requirement_quality REQ-SPAWN-COLLISION-GUARD-LIVE-DUP criterion=length — title is 123 words; want 3..=25
2026-07-11T01:39:54.0274022Z   [must] requirement_quality REQ-SPOOL-TAKE-AUDIT criterion=length — title is 50 words; want 3..=25
2026-07-11T01:39:54.0274363Z   [must] requirement_quality REQ-START-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0274625Z   [must] requirement_quality REQ-START-5 criterion=length — title is 129 words; want 3..=25
2026-07-11T01:39:54.0274877Z   [must] requirement_quality REQ-STORE-1 criterion=length — title is 34 words; want 3..=25
2026-07-11T01:39:54.0275192Z   [must] requirement_quality REQ-STORE-CONTEXT-BRANCH-FILL criterion=length — title is 73 words; want 3..=25
2026-07-11T01:39:54.0275455Z   [must] requirement_quality REQ-SUBNET-5 criterion=length — title is 52 words; want 3..=25
2026-07-11T01:39:54.0275803Z   [must] requirement_quality REQ-SUBNET-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0276064Z   [must] requirement_quality REQ-SUBNET-6 criterion=length — title is 38 words; want 3..=25
2026-07-11T01:39:54.0276408Z   [must] requirement_quality REQ-SUBNET-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0276657Z   [must] requirement_quality REQ-SUBNET-7 criterion=length — title is 75 words; want 3..=25
2026-07-11T01:39:54.0277002Z   [must] requirement_quality REQ-SUBNET-8 criterion=length — title is 53 words; want 3..=25
2026-07-11T01:39:54.0277307Z   [must] requirement_quality REQ-SUBNET-COUNT-ROUTABLE criterion=length — title is 78 words; want 3..=25
2026-07-11T01:39:54.0277706Z   [must] requirement_quality REQ-SUBNET-DISPLAY-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0278003Z   [must] requirement_quality REQ-SUBNET-DISPLAY-PARITY criterion=length — title is 166 words; want 3..=25
2026-07-11T01:39:54.0278360Z   [must] requirement_quality REQ-TERM-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0278603Z   [must] requirement_quality REQ-TERM-5 criterion=length — title is 71 words; want 3..=25
2026-07-11T01:39:54.0279110Z   [must] requirement_quality REQ-TERM-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0279408Z   [must] requirement_quality REQ-TERM-6 criterion=length — title is 53 words; want 3..=25
2026-07-11T01:39:54.0279763Z   [must] requirement_quality REQ-TERM-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0280010Z   [must] requirement_quality REQ-TERM-7 criterion=length — title is 55 words; want 3..=25
2026-07-11T01:39:54.0280446Z   [must] requirement_quality REQ-TRANSLATE-BINARY-LIVENESS-DECAY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0280793Z   [must] requirement_quality REQ-TRANSLATE-BINARY-LIVENESS-DECAY criterion=length — title is 94 words; want 3..=25
2026-07-11T01:39:54.0281185Z   [must] requirement_quality REQ-TRANSLATE-COMMAND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0281480Z   [must] requirement_quality REQ-TRANSLATE-COMMAND criterion=length — title is 137 words; want 3..=25
2026-07-11T01:39:54.0281923Z   [must] requirement_quality REQ-TRANSLATE-COMMIT-MISS-TOLERANCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0282256Z   [must] requirement_quality REQ-TRANSLATE-COMMIT-MISS-TOLERANCE criterion=length — title is 131 words; want 3..=25
2026-07-11T01:39:54.0282599Z   [must] requirement_quality REQ-UPD-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0282843Z   [must] requirement_quality REQ-UPD-6 criterion=length — title is 32 words; want 3..=25
2026-07-11T01:39:54.0283181Z   [must] requirement_quality REQ-UPD-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0283529Z   [must] requirement_quality REQ-UPD-7 criterion=length — title is 88 words; want 3..=25
2026-07-11T01:39:54.0283902Z   [must] requirement_quality REQ-UPD-8 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0284326Z   [must] requirement_quality REQ-UPD-8 criterion=length — title is 115 words; want 3..=25
2026-07-11T01:39:54.0284596Z   [must] requirement_quality REQ-UPD-9 criterion=length — title is 110 words; want 3..=25
2026-07-11T01:39:54.0285028Z   [must] requirement_quality REQ-UPDATE-APPLY-ALREADY-APPLIED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0285367Z   [must] requirement_quality REQ-UPDATE-APPLY-ALREADY-APPLIED criterion=length — title is 120 words; want 3..=25
2026-07-11T01:39:54.0285786Z   [must] requirement_quality REQ-UPDATE-APPLY-RESTART-NOTICE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0286164Z   [must] requirement_quality REQ-UPDATE-APPLY-RESTART-NOTICE criterion=length — title is 81 words; want 3..=25
2026-07-11T01:39:54.0286488Z   [must] requirement_quality REQ-UPDATE-FETCH-APPLY-FLAG criterion=length — title is 123 words; want 3..=25
2026-07-11T01:39:54.0286902Z   [must] requirement_quality REQ-UPDATE-FETCH-CURRENT-UX criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0287203Z   [must] requirement_quality REQ-UPDATE-FETCH-CURRENT-UX criterion=length — title is 134 words; want 3..=25
2026-07-11T01:39:54.0287618Z   [must] requirement_quality REQ-UPDATE-FINISH-COMMUNE-FLUSH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0287942Z   [must] requirement_quality REQ-UPDATE-FINISH-COMMUNE-FLUSH criterion=length — title is 215 words; want 3..=25
2026-07-11T01:39:54.0288271Z   [must] requirement_quality REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL criterion=length — title is 74 words; want 3..=25
2026-07-11T01:39:54.0288687Z   [must] requirement_quality REQ-UPDATE-ONE-SHOT-FINISH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0289079Z   [must] requirement_quality REQ-UPDATE-ONE-SHOT-FINISH criterion=length — title is 94 words; want 3..=25
2026-07-11T01:39:54.0289482Z   [must] requirement_quality REQ-UPDATE-PROMOTE-DRAINED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0289788Z   [must] requirement_quality REQ-UPDATE-PROMOTE-DRAINED criterion=length — title is 167 words; want 3..=25
2026-07-11T01:39:54.0290209Z   [must] requirement_quality REQ-UPDATE-RUNNING-IMAGE-SURFACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0290538Z   [must] requirement_quality REQ-UPDATE-RUNNING-IMAGE-SURFACE criterion=length — title is 166 words; want 3..=25
2026-07-11T01:39:54.0290944Z   [must] requirement_quality REQ-UPDATE-TRIAL-DRAIN-DRIVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0291259Z   [must] requirement_quality REQ-UPDATE-TRIAL-DRAIN-DRIVE criterion=length — title is 464 words; want 3..=25
2026-07-11T01:39:54.0291669Z   [must] requirement_quality REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0291993Z   [must] requirement_quality REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT criterion=length — title is 227 words; want 3..=25
2026-07-11T01:39:54.0292275Z   [must] requirement_quality REQ-WAKE-RESUME-LEG criterion=length — title is 274 words; want 3..=25
2026-07-11T01:39:54.0292532Z   [must] requirement_quality REQ-WAKE-WAIT criterion=length — title is 89 words; want 3..=25
2026-07-11T01:39:54.0292922Z   [must] requirement_quality REQ-WAN-SEND-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0293318Z   [must] requirement_quality REQ-WAN-SEND-DELIVERY criterion=length — title is 117 words; want 3..=25
2026-07-11T01:39:54.0293632Z   [must] requirement_quality REQ-WAN-SPT-HOSTED-DELIVERY criterion=length — title is 156 words; want 3..=25
2026-07-11T01:39:54.0293871Z   [must] requirement_quality REQ-WHOAMI-1 criterion=length — title is 76 words; want 3..=25
2026-07-11T01:39:54.0294385Z   [must] requirement_quality REQ-WORKER-LIST-VISIBILITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0294690Z   [must] requirement_quality REQ-WORKER-LIST-VISIBILITY criterion=length — title is 82 words; want 3..=25
2026-07-11T01:39:54.0295075Z   [must] requirement_quality REQ-WORKER-MINTED-NAME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0295363Z   [must] requirement_quality REQ-WORKER-MINTED-NAME criterion=length — title is 67 words; want 3..=25
2026-07-11T01:39:54.0295668Z   [must] requirement_quality REQ-WORKER-PICKER-EXCLUDED criterion=length — title is 61 words; want 3..=25
2026-07-11T01:39:54.0296031Z   [must] requirement_quality REQ-WORKER-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0296303Z   [must] requirement_quality REQ-WORKER-REAP criterion=length — title is 116 words; want 3..=25
2026-07-11T01:39:54.0296719Z   [must] requirement_quality REQ-WORKER-SID-SYMMETRIC-AUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-11T01:39:54.0297034Z   [must] requirement_quality REQ-WORKER-SID-SYMMETRIC-AUTH criterion=length — title is 125 words; want 3..=25
2026-07-11T01:39:54.0297344Z   [must] requirement_quality REQ-XTASK-SPT-BIN-TARGET-DIR criterion=length — title is 98 words; want 3..=25
2026-07-11T01:39:54.0297373Z 
2026-07-11T01:39:54.0297481Z # Requirement quality review
2026-07-11T01:39:54.0297509Z 
2026-07-11T01:39:54.0297706Z You are reviewing 480 requirement(s) from `traceable-reqs.toml` against a quality
2026-07-11T01:39:54.0297904Z rubric. Deterministic checks (length, contains-and, tbd-todo, duplicate-titles,
2026-07-11T01:39:54.0298090Z trailing-etc) have already run and surfaced as `requirement_quality` findings on
2026-07-11T01:39:54.0298231Z this command's output. Your task is the rubric items below.
2026-07-11T01:39:54.0298269Z 
2026-07-11T01:39:54.0298355Z ## Rubric
2026-07-11T01:39:54.0298385Z 
2026-07-11T01:39:54.0298632Z - **singular** — describes one capability; no smuggled "and"/"or" across distinct actions.
2026-07-11T01:39:54.0298860Z - **verifiable** — states an observable behavior a test or reviewer could confirm.
2026-07-11T01:39:54.0299165Z - **atomic** — cannot be split into two requirements without losing meaning.
2026-07-11T01:39:54.0299314Z - **active-voice** — clear subject and active verb.
2026-07-11T01:39:54.0299343Z 
2026-07-11T01:39:54.0299571Z If a criterion is borderline or doesn't apply, abstain — only emit findings for
2026-07-11T01:39:54.0299667Z clear concerns.
2026-07-11T01:39:54.0299696Z 
2026-07-11T01:39:54.0299786Z ## Requirements
2026-07-11T01:39:54.0299809Z 
2026-07-11T01:39:54.0299891Z ### REQ-ARCH-1
2026-07-11T01:39:54.0300015Z - Title: Many small acyclically-layered crates
2026-07-11T01:39:54.0300110Z - Required stages: impl
2026-07-11T01:39:54.0300133Z 
2026-07-11T01:39:54.0300221Z ### REQ-ARCH-2
2026-07-11T01:39:54.0300372Z - Title: Public SDK surface is spt-proto, spt-runtime, spt-msg
2026-07-11T01:39:54.0300462Z - Required stages: impl
2026-07-11T01:39:54.0300490Z 
2026-07-11T01:39:54.0300576Z ### REQ-ARCH-3
2026-07-11T01:39:54.0300755Z - Title: Wire-protocol version independent of crate semver, N-1 compat window
2026-07-11T01:39:54.0300865Z - Required stages: impl, unit
2026-07-11T01:39:54.0300888Z 
2026-07-11T01:39:54.0300975Z ### REQ-ARCH-4
2026-07-11T01:39:54.0301127Z - Title: Copy-verbatim the commodity layer from the sister project
2026-07-11T01:39:54.0301223Z - Required stages: impl, unit
2026-07-11T01:39:54.0302938Z 
2026-07-11T01:39:54.0303049Z ### REQ-DAEMON-1
2026-07-11T01:39:54.0303220Z - Title: One per-machine spt-daemon owning all per-machine state
2026-07-11T01:39:54.0303319Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0303343Z 
2026-07-11T01:39:54.0303433Z ### REQ-DAEMON-2
2026-07-11T01:39:54.0303563Z - Title: Broker/brain split for seamless self-update
2026-07-11T01:39:54.0303744Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0303768Z 
2026-07-11T01:39:54.0303858Z ### REQ-DAEMON-3
2026-07-11T01:39:54.0304005Z - Title: Any api invocation auto-starts the daemon if absent
2026-07-11T01:39:54.0304107Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0304130Z 
2026-07-11T01:39:54.0304216Z ### REQ-DAEMON-4
2026-07-11T01:39:54.0304334Z - Title: Honor every KNOWN-HAZARDS invariant
2026-07-11T01:39:54.0304431Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0304455Z 
2026-07-11T01:39:54.0304540Z ### REQ-STORE-1
2026-07-11T01:39:54.0305356Z - Title: spt-store::BranchStore (git branch as versioned KV; commit=checkpoint/tip=resume, atomic multi-key, merge-native sync) is the substrate for coarse/durable/audited state (context, registry snapshot+distribution, daemon checkpoint); hot paths (B5 fsync journal) + indexed queries (SQLite spool) excluded (ADR-0011)
2026-07-11T01:39:54.0305488Z - Required stages: impl, unit
2026-07-11T01:39:54.0305522Z 
2026-07-11T01:39:54.0305612Z ### REQ-MANIFEST-1
2026-07-11T01:39:54.0305782Z - Title: Per-adapter manifest with adapter_name and min_spt_core_version
2026-07-11T01:39:54.0305886Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0305914Z 
2026-07-11T01:39:54.0306000Z ### REQ-MANIFEST-2
2026-07-11T01:39:54.0306487Z - Title: Adapter profiles — sparse leaf-replace overlays (shipped + local), composite <adapter>:<profile> addressing, shadow-refusal, tighten-only consent floors
2026-07-11T01:39:54.0306581Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0306615Z 
2026-07-11T01:39:54.0306702Z ### REQ-MANIFEST-3
2026-07-11T01:39:54.0307308Z - Title: Adapter strings — [strings] KV tree, dot-path get-string resolving through the profile leaf-replace overlay, set-string editing a local profile's [strings] only; data-only (nothing executes a string)
2026-07-11T01:39:54.0307407Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0307431Z 
2026-07-11T01:39:54.0307521Z ### REQ-MANIFEST-4
2026-07-11T01:39:54.0308185Z - Title: Keyword hints — [[hints]] {keywords (literal/regex), text}; spt api hint --session emits at most one matched hint per message, once per session (seen-set), declaration-order first match; profiles overlay [[hints]] by leaf-replace
2026-07-11T01:39:54.0308285Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0308314Z 
2026-07-11T01:39:54.0308408Z ### REQ-MANIFEST-5
2026-07-11T01:39:54.0311273Z - Title: File-backed adapter [strings] (M12-W3-T3.1): a [strings] dot-path value MAY be an inline-table FILE POINTER `key = { file = "rel/path" }` resolved to the file's contents at get-string time, keeping large bodies (skill-instructions, hint text) out of the manifest. A value-position table with a `file` key IS the pointer form (reserved — cannot double as data). Per-adapter aux storage `adapters/<adapter>/strings/`; pointers resolve relative to it with CONTAINMENT (reject `..`/absolute escaping the dir). UPDATE-SAFETY: a LOCAL profile's file-pointers resolve relative to the user-owned local-profile dir (NOT adapter-shipped strings/, which adapter updates overwrite), or the local profile inlines. Validate-at-register (fail-fast on a bad/escaping/missing pointer) + LAZY read at get-string (live file edits reflect, no re-register) + skip-diagnostics on missing-at-read (no hard-crash, mirrors [digest]). Rides the same leaf-replace profile overlay as the rest of [strings].
2026-07-11T01:39:54.0311468Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0311502Z 
2026-07-11T01:39:54.0311615Z ### REQ-MANIFEST-6
2026-07-11T01:39:54.0313619Z - Title: Cross-adapter fallback target addressing (M12-W3-T3.2): a cross-adapter fallback target is addressed as `<adapter>:<profile>` (not just a bare adapter_name), resolved through the one composite-addressing resolver (registry::resolve_option) at every adapter-option read site so a fallback may select a shipped/local profile (e.g. a `ccs` profile). CONTEXT.md §cross-adapter-fallback reconciled ("ccs is a profile; cross-adapter fallback may target <adapter>:<profile>"). Contract-only this milestone: the node-wide fallback SETTING + its rate-limit invocation are deferred to the consuming milestone (the runtime path does not exist yet); this REQ guarantees the ADDRESSING resolves.
2026-07-11T01:39:54.0313960Z - Required stages: doc, unit
2026-07-11T01:39:54.0313989Z 
2026-07-11T01:39:54.0314075Z ### REQ-MANIFEST-7
2026-07-11T01:39:54.0316971Z - Title: Adapter-declared shortcut basename (M12-W2 follow-on): an optional `[adapter] shortcut_basename` manifest field names the basename the `spt endpoint run` picker bakes into the generated `<basename>-<id>` launcher shortcut (REQ-RUN-SHORTCUT). Absent ⇒ the harness-agnostic default `spt` (→ `spt-<id>`); an adapter sets it to brand its shortcuts (claude-spt → `cc` → `cc-<id>`), so the Claude-Code-ness lives in the PUBLISHED adapter manifest, never hardcoded in spt-core. The picker reads it from the RESOLVED manifest of the selected adapter (registry::resolve_option), falling back to `spt` when absent/empty/unresolvable. Additive + N-1-safe (serde-default Option, omitted from serialization when absent; old manifests parse clean); manifest.schema.json regenerated from the derive (ADR-0001, CI drift-gated). Documented in docs/MANIFEST.md `[adapter]` section + the claude-spt worked example — the adapter-author contract perri builds spt-claude-code against.
2026-07-11T01:39:54.0317099Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0317127Z 
2026-07-11T01:39:54.0317215Z ### REQ-MANIFEST-8
2026-07-11T01:39:54.0319442Z - Title: [adapter] host_binaries declares the harness executable basenames a kind="harness" adapter hosts agents inside (e.g. host_binaries = ["claude"]); bind-time pid→exe-basename match (case-insensitive, .exe-stripped) over the seed's parent_pid selects the candidate adapter set; zero matches → a friendly error naming the binary + the --adapter escape hatch. Additive + N-1-safe: optional Vec<String>, #[serde(default, skip_serializing_if = "Vec::is_empty")] (omitted-serialized like shortcut_basename, old manifests parse clean); manifest.schema.json regenerated from the derive (ADR-0001, CI drift-gated). The match-key for ADR-0021 adapter-agnostic bind-time resolution. (v0.9.0)
2026-07-11T01:39:54.0319571Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0319599Z 
2026-07-11T01:39:54.0319689Z ### REQ-SEAM-SPAWN
2026-07-11T01:39:54.0319781Z - Title: spawn-session seam
2026-07-11T01:39:54.0319876Z - Required stages: impl, unit
2026-07-11T01:39:54.0319905Z 
2026-07-11T01:39:54.0319994Z ### REQ-SEAM-POSTSPAWN
2026-07-11T01:39:54.0320129Z - Title: post-spawn / api bind seam with boot nonce
2026-07-11T01:39:54.0320229Z - Required stages: impl, unit
2026-07-11T01:39:54.0320267Z 
2026-07-11T01:39:54.0320353Z ### REQ-SEAM-PSYCHE
2026-07-11T01:39:54.0320487Z - Title: spawn-psyche seam (fresh + resume templates)
2026-07-11T01:39:54.0320582Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0320610Z 
2026-07-11T01:39:54.0320706Z ### REQ-SEAM-HISTORY
2026-07-11T01:39:54.0320867Z - Title: History subsystem (fetcher / locate-normalize / native store)
2026-07-11T01:39:54.0320968Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0320997Z 
2026-07-11T01:39:54.0321093Z ### REQ-SEAM-ACTIVITY
2026-07-11T01:39:54.0321254Z - Title: Activity/idle reported via api sentinels, not PTY quiescence
2026-07-11T01:39:54.0321351Z - Required stages: impl, unit
2026-07-11T01:39:54.0321374Z 
2026-07-11T01:39:54.0321460Z ### REQ-SEAM-INJECT
2026-07-11T01:39:54.0321620Z - Title: inject-input methods configurable per activity-state
2026-07-11T01:39:54.0321715Z - Required stages: impl, unit
2026-07-11T01:39:54.0321739Z 
2026-07-11T01:39:54.0321828Z ### REQ-SEAM-RESUME
2026-07-11T01:39:54.0322162Z - Title: resume-session seam (fresh-with-preload / continue-existing)
2026-07-11T01:39:54.0322251Z - Required stages: 
2026-07-11T01:39:54.0322280Z 
2026-07-11T01:39:54.0322377Z ### REQ-SEAM-CAPABILITY
2026-07-11T01:39:54.0322505Z - Title: Hostable endpoint-types capability declaration
2026-07-11T01:39:54.0322600Z - Required stages: impl, unit
2026-07-11T01:39:54.0322677Z 
2026-07-11T01:39:54.0322767Z ### REQ-SEAM-UPDATE
2026-07-11T01:39:54.0322915Z - Title: Adapter-update avenue (file-pull / delegated command)
2026-07-11T01:39:54.0323001Z - Required stages: impl, unit
2026-07-11T01:39:54.0323030Z 
2026-07-11T01:39:54.0323120Z ### REQ-API-1
2026-07-11T01:39:54.0323273Z - Title: api prefix and adapter_name on every machinery invocation
2026-07-11T01:39:54.0323373Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0323396Z 
2026-07-11T01:39:54.0323487Z ### REQ-API-2
2026-07-11T01:39:54.0323669Z - Title: The api subcommand surface (bind/listen/poll/state/worker/boundary/...)
2026-07-11T01:39:54.0323773Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0323802Z 
2026-07-11T01:39:54.0323883Z ### REQ-API-3
2026-07-11T01:39:54.0324012Z - Title: commune/signoff are file-drops, not commands
2026-07-11T01:39:54.0324102Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0324130Z 
2026-07-11T01:39:54.0324218Z ### REQ-API-4
2026-07-11T01:39:54.0325675Z - Title: api resolves the adapter manifest (+ profile + install dir) from `--adapter name:profile` via the registry when `--manifest` is omitted; `--manifest` becomes an optional OVERRIDE (unregistered / local-dev manifests). Removes the require-both-flags redundancy — a registered adapter's live bringup / digest / capability needs only `--adapter` — and yields the precise install dir (the record's source_dir) rather than the --manifest parent, closing the copy-mode psyche-binary edge (v0.8.0)
2026-07-11T01:39:54.0325775Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0325798Z 
2026-07-11T01:39:54.0325890Z ### REQ-START-1
2026-07-11T01:39:54.0326070Z - Title: Adapters never resolve SPT_HOME; binary on PATH; api bridging only
2026-07-11T01:39:54.0326171Z - Required stages: impl, unit
2026-07-11T01:39:54.0326200Z 
2026-07-11T01:39:54.0326284Z ### REQ-START-2
2026-07-11T01:39:54.0326409Z - Title: Harness-hosted startup: api seed then listen
2026-07-11T01:39:54.0326506Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0326534Z 
2026-07-11T01:39:54.0326618Z ### REQ-START-3
2026-07-11T01:39:54.0326770Z - Title: spt-hosted startup: spawn-session then api bind (no file)
2026-07-11T01:39:54.0326861Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0326889Z 
2026-07-11T01:39:54.0326978Z ### REQ-START-4
2026-07-11T01:39:54.0327102Z - Title: Adapter-injected env aliases (SPT/OWL/LIVE)
2026-07-11T01:39:54.0327188Z - Required stages: impl, unit
2026-07-11T01:39:54.0327217Z 
2026-07-11T01:39:54.0327302Z ### REQ-START-5
2026-07-11T01:39:54.0330150Z - Title: Adapter-agnostic harness-hosted seed + bind-time adapter/profile resolution (ADR-0021): `api seed` carries only parent_pid + session_id (+ optional cwd), no --adapter — a pure "a harness session exists at this pid" record; --adapter becomes an OPTIONAL override across the whole api group (an explicit name[:profile] for adapter dev, never required). Omitted, listen/poll resolve the owning adapter/profile AT BIND as a pure read against the live registry — never a seed-time snapshot that can drift: seed parent_pid → exe basename → host_binaries candidate set (REQ-MANIFEST-8) → active-profile pointer (REQ-INSTALL-12) primary, else greatest-registered_at_ms candidate base profile (name-asc tie) → friendly zero-match error. Covers BOTH LiveAgent (listen) and ReadyAgent (poll) bringup. Restores legacy parity: `$LIVE start <id>` → `$SPT listen <id>` with no mandatory --adapter, one generic SessionStart hook per harness binary. (v0.9.0)
2026-07-11T01:39:54.0330278Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0330307Z 
2026-07-11T01:39:54.0330394Z ### REQ-EP-1
2026-07-11T01:39:54.0330622Z - Title: Day-one endpoint types; open type system
2026-07-11T01:39:54.0330775Z - Required stages: impl, unit
2026-07-11T01:39:54.0330799Z 
2026-07-11T01:39:54.0330879Z ### REQ-EP-2
2026-07-11T01:39:54.0331028Z - Title: Agent endpoints vs Shells distinction in the type model
2026-07-11T01:39:54.0331123Z - Required stages: impl, unit
2026-07-11T01:39:54.0331203Z 
2026-07-11T01:39:54.0331281Z ### REQ-EP-3
2026-07-11T01:39:54.0331451Z - Title: Messaging payloads carry typed operation commands + file blobs
2026-07-11T01:39:54.0331537Z - Required stages: impl, unit
2026-07-11T01:39:54.0331567Z 
2026-07-11T01:39:54.0331648Z ### REQ-EP-4
2026-07-11T01:39:54.0331780Z - Title: PresenceChannel broker endpoint (seam day-one)
2026-07-11T01:39:54.0331872Z - Required stages: impl, unit
2026-07-11T01:39:54.0331901Z 
2026-07-11T01:39:54.0331977Z ### REQ-EP-5
2026-07-11T01:39:54.0332593Z - Title: Concrete shell instantiation model: spawn-mints-instance (vs relink/online), registered-on-node permission + broadcast-is-discovery, per-shell require_approval gate, max_instances_per_owner + over_cap, instance aliasing, discovery scope
2026-07-11T01:39:54.0332703Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0332726Z 
2026-07-11T01:39:54.0332807Z ### REQ-EP-6
2026-07-11T01:39:54.0334177Z - Title: Gateway type acceptance: a Gateway-typed perch binds (api bind --type, open type system — un-hardcode the live_agent default), advertises/addressable like any endpoint, owns shells (owner validation not agent-family-gated), subscribes to digests, and is the user-msg identity gate's user-backed origin (REQ-MSG-5); in-tree mock-gateway fixture (R-DOCS-2 pattern, no downstream adapter code). Cross-node WAN Gateway-origin (registry endpoint_type trust) tracked by REQ-MSG-6
2026-07-11T01:39:54.0334276Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0334304Z 
2026-07-11T01:39:54.0334390Z ### REQ-EP-7
2026-07-11T01:39:54.0336025Z - Title: Durable live-role.md: a per-agent broad-purpose statement in tracked/agents/<id>/ beside live-context.md (replicates with the mind on the same a-<id> branch); renders FIRST at start-transition context injection (role -> live-context -> project-context); SOLE writer `spt endpoint role --overwrite <file>` — mechanical no-automated-writer guarantee (echo-commune ingest / signoff / Psyche reconcile structurally exclude it). The user-backed-origin hard gate on the writer is a deferred later tightening (rides the user-msg identity plumbing)
2026-07-11T01:39:54.0336140Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0336173Z 
2026-07-11T01:39:54.0336259Z ### REQ-EP-8
2026-07-11T01:39:54.0339126Z - Title: AlwaysOnEndpoint: a resident, addressable, mindless endpoint whose adapter binary the daemon supervises continuously — register-triggered by an adapter-option's `[always-on]` manifest section, one supervised binary per `<adapter>[:profile]`, running independent of agent liveness. It self-manages its `#`-addressed channel endpoints via the existing `api bind` (one connection fronts many). The SECOND class of spt-core-boot-launched third-party binary (after the shell wake-watcher); supervision reuses the wake-watcher scaffolding (backoff / give-up latch / one-per-instance lock / orphan-kill / brain-side reconcile) MINUS the offline-only flip — always online, never resting (no dormant/suspended states). Two-way: agents message it; it may call `endpoint wake <id>`, target-side authorized (REQ-INST-3/6 wake resolution + access whitelist + shell_wake_spawn_anywhere — no caller-ownership gate). First consumer downstream: spt-discord.
2026-07-11T01:39:54.0341821Z - Required stages: 
2026-07-11T01:39:54.0341954Z 
2026-07-11T01:39:54.0342045Z ### REQ-EP-9
2026-07-11T01:39:54.0343686Z - Title: `#` always-on address sigil: a reserved LEADING sigil marking an AlwaysOnEndpoint, extending the REQ-INST-10 grammar to `[subnet:]#id[@node]`. Mandatory + bijective — `#name` ⟺ always-on endpoint, bare `name` ⟺ agent endpoint — so the router resolves endpoint class from the address alone, before any registry lookup. Sits ABOVE REQ-HAZARD-ID-CHARSET: the address parser strips the single leading `#` before id validation, so the bare/stored id stays charset-clean and a mid-id `#` remains rejected (the charset contract is unchanged).
2026-07-11T01:39:54.0345270Z - Required stages: 
2026-07-11T01:39:54.0345395Z 
2026-07-11T01:39:54.0345480Z ### REQ-INST-1
2026-07-11T01:39:54.0345707Z - Title: endpoint ID vs instance split (adapter-agnostic ID)
2026-07-11T01:39:54.0346032Z - Required stages: 
2026-07-11T01:39:54.0346152Z 
2026-07-11T01:39:54.0346236Z ### REQ-INST-2
2026-07-11T01:39:54.0346423Z - Title: Per-node files, synced Psyche mind
2026-07-11T01:39:54.0346662Z - Required stages: impl, unit
2026-07-11T01:39:54.0346810Z 
2026-07-11T01:39:54.0346899Z ### REQ-INST-3
2026-07-11T01:39:54.0347119Z - Title: Dormant (warm) / suspended (cold) resting states
2026-07-11T01:39:54.0347396Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0347549Z 
2026-07-11T01:39:54.0347640Z ### REQ-INST-4
2026-07-11T01:39:54.0347875Z - Title: active to dormant/suspended fires a transition echo commune
2026-07-11T01:39:54.0348192Z - Required stages: impl, unit
2026-07-11T01:39:54.0348332Z 
2026-07-11T01:39:54.0348417Z ### REQ-INST-5
2026-07-11T01:39:54.0348651Z - Title: Two-tier context sync (live to all, project to same-project)
2026-07-11T01:39:54.0349028Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0349186Z 
2026-07-11T01:39:54.0349267Z ### REQ-INST-6
2026-07-11T01:39:54.0349515Z - Title: Deferred messages not delivered to dormant/suspended instances
2026-07-11T01:39:54.0349834Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0349976Z 
2026-07-11T01:39:54.0350067Z ### REQ-INST-7
2026-07-11T01:39:54.0350272Z - Title: Subnet registry + bare-id resolution policy
2026-07-11T01:39:54.0350526Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0350672Z 
2026-07-11T01:39:54.0350757Z ### REQ-INST-8
2026-07-11T01:39:54.0350970Z - Title: Remote-control mode distinct from local operation
2026-07-11T01:39:54.0351238Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0351398Z 
2026-07-11T01:39:54.0351481Z ### REQ-INST-9
2026-07-11T01:39:54.0351728Z - Title: Multi-subnet membership (same-user N subnets; cross-user seam)
2026-07-11T01:39:54.0352028Z - Required stages: impl, unit
2026-07-11T01:39:54.0352167Z 
2026-07-11T01:39:54.0352252Z ### REQ-INST-10
2026-07-11T01:39:54.0352529Z - Title: Qualified addressing [subnet:]id[@node] + ambiguity forces qualification
2026-07-11T01:39:54.0352862Z - Required stages: impl, unit
2026-07-11T01:39:54.0353002Z 
2026-07-11T01:39:54.0353088Z ### REQ-INST-11
2026-07-11T01:39:54.0353367Z - Title: spt rename <id> rippled to all instances (collision-checked, 6.5-reconciled)
2026-07-11T01:39:54.0353704Z - Required stages: impl, unit
2026-07-11T01:39:54.0353842Z 
2026-07-11T01:39:54.0353931Z ### REQ-INST-12
2026-07-11T01:39:54.0354275Z - Title: Endpoint visibility per-(endpoint,subnet): excluded semantics, OR-of-defaults + override, gates sync
2026-07-11T01:39:54.0354682Z - Required stages: impl, unit
2026-07-11T01:39:54.0354829Z 
2026-07-11T01:39:54.0354914Z ### REQ-INST-13
2026-07-11T01:39:54.0355158Z - Title: Subnet-exclusive sync + per-endpoint subnet-membership list
2026-07-11T01:39:54.0355453Z - Required stages: impl, unit
2026-07-11T01:39:54.0355593Z 
2026-07-11T01:39:54.0355669Z ### REQ-INST-14
2026-07-11T01:39:54.0356092Z - Title: Resource advertisement (subnet resource registry): free-text blurb, both-authored, registry projection, visibility/whitelist-gated
2026-07-11T01:39:54.0356626Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0356777Z 
2026-07-11T01:39:54.0356864Z ### REQ-INST-15
2026-07-11T01:39:54.0357608Z - Title: Immutable home subnet (assigned at creation: auto-if-one/ask-if-many) + spt fork (cross-subnet clone to a new identity, copy-then-diverge, not re-home); adapter chosen at creation from registered hostable adapters, changed only via launch/resume-under-new (ADR-0010)
2026-07-11T01:39:54.0358408Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0358565Z 
2026-07-11T01:39:54.0358757Z ### REQ-REACH-1
2026-07-11T01:39:54.0359116Z - Title: Off-node remote-drive detection + file transfer
2026-07-11T01:39:54.0359401Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0359550Z 
2026-07-11T01:39:54.0359640Z ### REQ-REACH-2
2026-07-11T01:39:54.0359860Z - Title: Remote command execution (deferred, consent-gated)
2026-07-11T01:39:54.0360142Z - Required stages: 
2026-07-11T01:39:54.0360317Z 
2026-07-11T01:39:54.0360409Z ### REQ-MSG-1
2026-07-11T01:39:54.0360894Z - Title: Local message delivery: TCP-first to a registered address, spool fallback when offline; id->address via registry (stale-clean first); reply routing (__REPLY_TO__)
2026-07-11T01:39:54.0361441Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0361592Z 
2026-07-11T01:39:54.0361682Z ### REQ-MSG-2
2026-07-11T01:39:54.0362002Z - Title: spt binary CLI surface: send/ring/ready(+--once)/list/stop/whoami, stable arg shapes + exit codes
2026-07-11T01:39:54.0362380Z - Required stages: impl, unit
2026-07-11T01:39:54.0362526Z 
2026-07-11T01:39:54.0362608Z ### REQ-MSG-3
2026-07-11T01:39:54.0363033Z - Title: Ready-agent lifecycle: register perch (info.json + listener + registry address) on ready, drain spooled backlog on startup, clean teardown
2026-07-11T01:39:54.0363514Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0363663Z 
2026-07-11T01:39:54.0363746Z ### REQ-MSG-4
2026-07-11T01:39:54.0364598Z - Title: Listener stream stdout emits EVENT envelope lines (sister-format, ADR-0001): parse the __REPLY_TO__ frame, pass pre-formed typed envelopes through verbatim (no double-wrap), compose <EVENT type="msg" from=…> otherwise, chunk oversized lines into EVENT-PART
2026-07-11T01:39:54.0365360Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0365504Z 
2026-07-11T01:39:54.0365603Z ### REQ-MSG-ENVELOPE
2026-07-11T01:39:54.0369327Z - Title: The <EVENT type="msg" from=…>body</EVENT> envelope (spt-proto::event, the ADR-0001 grammar) is the SOLE canonical arriving-message format at EVERY harness arriving-message surface on an AGENT perch — api listen AND api poll/worker-poll, byte-identical (reverses REQ-MSG-4's 'hook drains keep the raw frame by contract'). SCOPE CARVE-OUT: the shell-command relay (api poll <shell-id> --link, cmd_poll_shell) is a distinct internal transport carrying RAW MAC'd stamped frames the shell child consumes verbatim — NOT an arriving-message surface, deliberately EXEMPT from <EVENT> composition (notify_shell_e2e guards this boundary). __REPLY_TO__ — mis-elevated during the clean-room port to a fake ADR-0001 'stable wire format' (spt-msg/wire.rs, lib.rs) — is REMOVED entirely (spool format_row, the spt-msg TCP frame, emit parse_frame); (from, body) carried structurally, <EVENT> composed once at the delivery boundary. No legacy sister-interop (spt-core never required it). Reply-correlation rebinds onto the structural from / <EVENT from=…> attribute (ADR-0009 access-gate + ADR-0012 Psyche/spt-live reply-target). Self-delimiting by construction → finding F-002 (non-self-delimiting multi-message poll) dissolves. ADR-0020.
2026-07-11T01:39:54.0372625Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0372790Z 
2026-07-11T01:39:54.0372873Z ### REQ-MSG-5
2026-07-11T01:39:54.0373621Z - Title: user-msg envelope kind + daemon identity gate: a Gateway endpoint / the local user's CLI author user-msg (the user's authority); agent-family senders re-stamped to plain msg; identity-gated never payload-trusted (KH 7.3/7.5); wire-additive (N-1 receivers tolerate the new type)
2026-07-11T01:39:54.0374425Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0374573Z 
2026-07-11T01:39:54.0374661Z ### REQ-MSG-6
2026-07-11T01:39:54.0376292Z - Title: cross-node Gateway user-msg honored via advertised endpoint_type: a user-msg from a Gateway-typed origin survives the receive_wan funnel as user-msg (vs the fail-closed re-stamp), keyed on the QUIC-handshake-proven origin node (never wire `from`). Trust boundary = subnet membership (operator-ratified 2026-06-13); no defense against an in-subnet member forging the type. Instance.endpoint_type is an additive serde-default field extending REQ-INST-7's data model. Absent/unknown type → re-stamp (N-1 rollout grace)
2026-07-11T01:39:54.0377888Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0378037Z 
2026-07-11T01:39:54.0378123Z ### REQ-NODE-IDENTITY
2026-07-11T01:39:54.0378423Z - Title: Ed25519 identity primitive: keypair, detached sign/verify, stable pubkey<->hex
2026-07-11T01:39:54.0378814Z - Required stages: impl, unit
2026-07-11T01:39:54.0379043Z 
2026-07-11T01:39:54.0379123Z ### REQ-NET-1
2026-07-11T01:39:54.0379358Z - Title: WAN messaging first-class, behind default-on net feature flag
2026-07-11T01:39:54.0379651Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0379793Z 
2026-07-11T01:39:54.0379878Z ### REQ-NET-2
2026-07-11T01:39:54.0380112Z - Title: n0 relay default + self-host knob + plain-language disclosure
2026-07-11T01:39:54.0380403Z - Required stages: impl
2026-07-11T01:39:54.0380531Z 
2026-07-11T01:39:54.0380609Z ### REQ-NET-3
2026-07-11T01:39:54.0380846Z - Title: Cross-node Psyche sync over P2P replaces gh-repo-sync
2026-07-11T01:39:54.0381127Z - Required stages: impl, unit
2026-07-11T01:39:54.0381271Z 
2026-07-11T01:39:54.0381357Z ### REQ-PAIR-1
2026-07-11T01:39:54.0381539Z - Title: TOTP-seeded SPAKE2 pairing
2026-07-11T01:39:54.0381757Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0381901Z 
2026-07-11T01:39:54.0381990Z ### REQ-PAIR-2
2026-07-11T01:39:54.0382192Z - Title: Local trust store with TOFU + warn-on-change
2026-07-11T01:39:54.0382452Z - Required stages: 
2026-07-11T01:39:54.0382571Z 
2026-07-11T01:39:54.0382660Z ### REQ-PAIR-3
2026-07-11T01:39:54.0382866Z - Title: Fetch current pairing code from any paired node
2026-07-11T01:39:54.0383132Z - Required stages: impl, unit
2026-07-11T01:39:54.0383275Z 
2026-07-11T01:39:54.0383355Z ### REQ-PAIR-4
2026-07-11T01:39:54.0383533Z - Title: Subnet naming on first pairing
2026-07-11T01:39:54.0383762Z - Required stages: impl, unit
2026-07-11T01:39:54.0383909Z 
2026-07-11T01:39:54.0383990Z ### REQ-PAIR-5
2026-07-11T01:39:54.0384348Z - Title: Multi-subnet pairing: subnet-name discovery input, create-new-names-up-front, rendezvous-token hashing
2026-07-11T01:39:54.0384769Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0384909Z 
2026-07-11T01:39:54.0384999Z ### REQ-PAIR-6
2026-07-11T01:39:54.0385311Z - Title: Elevation-gated per-subnet code fetch (UAC/root or elevated agent; else authenticator app)
2026-07-11T01:39:54.0385684Z - Required stages: impl, unit
2026-07-11T01:39:54.0385819Z 
2026-07-11T01:39:54.0385903Z ### REQ-PAIR-7
2026-07-11T01:39:54.0386128Z - Title: Subnet icon (inline image metadata, GUI-only consumer)
2026-07-11T01:39:54.0386400Z - Required stages: 
2026-07-11T01:39:54.0386523Z 
2026-07-11T01:39:54.0386604Z ### REQ-SUBNET-1
2026-07-11T01:39:54.0386982Z - Title: spt subnet noun namespace: status view (bare + status [NAME] [--nodes]), create (QR/otpauth), show-code; spt pair deleted
2026-07-11T01:39:54.0387414Z - Required stages: impl, unit
2026-07-11T01:39:54.0387554Z 
2026-07-11T01:39:54.0387645Z ### REQ-SUBNET-2
2026-07-11T01:39:54.0387944Z - Title: Guided join e2e: spt subnet join CLI initiator + always-on daemon pairing responder
2026-07-11T01:39:54.0388297Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0388444Z 
2026-07-11T01:39:54.0388530Z ### REQ-SUBNET-3
2026-07-11T01:39:54.0388859Z - Title: Node labels: hostname-default, gossiped, addressable in @node qualifiers (refuse-on-ambiguity)
2026-07-11T01:39:54.0389331Z - Required stages: impl, unit
2026-07-11T01:39:54.0389469Z 
2026-07-11T01:39:54.0389556Z ### REQ-SUBNET-4
2026-07-11T01:39:54.0389899Z - Title: Subnet membership mutations elevation-gated (create = seed reveal; join = trust-boundary enrollment)
2026-07-11T01:39:54.0390301Z - Required stages: impl, unit
2026-07-11T01:39:54.0390443Z 
2026-07-11T01:39:54.0390524Z ### REQ-DOCS-6
2026-07-11T01:39:54.0390902Z - Title: spt how-to <topic>: in-binary task-oriented agent instructions (anti-drift; quickstart prompts point agents at it)
2026-07-11T01:39:54.0391340Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0391659Z 
2026-07-11T01:39:54.0391736Z ### REQ-SEC-1
2026-07-11T01:39:54.0392179Z - Title: Per-endpoint access whitelist: origin-node gate, stateful-firewall (reply/outbound exempt), node-now/user-later, outer gate before grants
2026-07-11T01:39:54.0392671Z - Required stages: impl, unit
2026-07-11T01:39:54.0392804Z 
2026-07-11T01:39:54.0392941Z ### REQ-NOTIF-1
2026-07-11T01:39:54.0393353Z - Title: Notification primitive: per-subnet replicated spool, seen/dismissed, resurface-at-boundary, subsumes update+consent prompts
2026-07-11T01:39:54.0393821Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0393978Z 
2026-07-11T01:39:54.0394055Z ### REQ-NOTIF-2
2026-07-11T01:39:54.0394379Z - Title: spt notify (agent-issued subnet notif) + notif_command manifest seam (harness + shell adapters)
2026-07-11T01:39:54.0394760Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0394927Z 
2026-07-11T01:39:54.0395009Z ### REQ-UPD-1
2026-07-11T01:39:54.0395198Z - Title: Peer-propagated update over P2P
2026-07-11T01:39:54.0395446Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0395598Z 
2026-07-11T01:39:54.0395684Z ### REQ-UPD-2
2026-07-11T01:39:54.0395891Z - Title: All binaries signature-verified before handoff
2026-07-11T01:39:54.0396148Z - Required stages: impl, unit
2026-07-11T01:39:54.0396288Z 
2026-07-11T01:39:54.0396379Z ### REQ-UPD-3
2026-07-11T01:39:54.0396617Z - Title: No endpoint process terminates/suspends during self-update
2026-07-11T01:39:54.0396913Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0397060Z 
2026-07-11T01:39:54.0397150Z ### REQ-UPD-4
2026-07-11T01:39:54.0397393Z - Title: Update gated on user confirmation by default; opt-in full-auto
2026-07-11T01:39:54.0397689Z - Required stages: impl, unit
2026-07-11T01:39:54.0397838Z 
2026-07-11T01:39:54.0397919Z ### REQ-UPD-5
2026-07-11T01:39:54.0398119Z - Title: spt-core ripple-updates registered adapters
2026-07-11T01:39:54.0398375Z - Required stages: impl, unit
2026-07-11T01:39:54.0398523Z 
2026-07-11T01:39:54.0398605Z ### REQ-UPD-6
2026-07-11T01:39:54.0399548Z - Title: Platform-targeted update sets and debug rollout: signed multi-platform update metadata, recipient platform selection, channel-scoped monotonic counters, debug-channel opt-in via release-key overlay, local staging plus pull-based peer propagation, and maintainer-only convergence tooling (ADR-0016)
2026-07-11T01:39:54.0400460Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0400619Z 
2026-07-11T01:39:54.0400705Z ### REQ-UPD-7
2026-07-11T01:39:54.0402748Z - Title: Origin-source update bootstrap (`spt update fetch`): pull the latest signed release directly from the GitHub release origin (`SaberMage/spt-releases`) — the per-platform artifact + its `<asset>.release.json` SignedRelease metadata — and stage it through the EXISTING verify→stage pipeline (the same `plan_verified` gate: two-key signature + channel + monotonic rollback floor + SHA-256), after which the normal consent-notif / `spt update apply` flow is unchanged. Closes the peer-only-discovery gap (REQ-UPD-1): a first-in-fleet / isolated node can update with no peer to pull from. The signed-release anchor keeps the GitHub transport untrusted-but-verified.
2026-07-11T01:39:54.0404499Z - Required stages: impl, unit
2026-07-11T01:39:54.0404643Z 
2026-07-11T01:39:54.0404734Z ### REQ-UPD-8
2026-07-11T01:39:54.0407210Z - Title: Platform-safe `spt update fetch` + apply platform-guard (v0.3.1 cross-OS brick fix): `spt update fetch` stages the signed multi-platform `SignedUpdateSet` (`update-set.json` + every platform artifact it names), never a platform-blind single `SignedRelease`, so local apply selects `current_platform()` and P2P re-serve lets each peer select ITS own platform. Defense-in-depth: `apply_staged` REFUSES a staged single-release artifact unless it is platform-stamped for THIS node (an unstamped pre-v0.3.2 single, or a single stamped for another OS, fail-safe refuses — the guard that alone prevents the v0.3.1 brick where a Linux ELF was applied as `spt.exe`). UX: a friendly post-apply message (`Updated spt-core to vX.Y.Z.` + changelog URL) driven by an additive `product_version` metadata field, with a release-counter fallback when absent.
2026-07-11T01:39:54.0413239Z - Required stages: impl, unit
2026-07-11T01:39:54.0413404Z 
2026-07-11T01:39:54.0413496Z ### REQ-UPD-9
2026-07-11T01:39:54.0416129Z - Title: `gh_release` adapter [update] avenue (optional signing): an adapter declares `[update] avenue = "gh_release", repo = "user/repo"` (+ optional `asset`, default `adapter.spt`; + optional Ed25519 `signing_key`); spt-core's ripple compares the repo's LATEST GitHub release version against the installed adapter version and, when newer, auto-updates by fetching the release `.spt` archive (the REQ-INSTALL-9 `--release` fetch primitive) → verifies the `.spt` against `signing_key` if declared, else HTTPS+GitHub first-acquisition trust → re-extracts + re-registers the adapter root. Lets a harness adapter ship updates from its own GitHub releases with NO signing tooling or plugin coupling (removes the perri file_pull/delegated avenue blockers). Acquisition-trust mirrors `--release` + the installer first-fetch; does not alter spt-core self-update (REQ-UPD-1..8).
2026-07-11T01:39:54.0418466Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0418619Z 
2026-07-11T01:39:54.0418710Z ### REQ-TERM-1
2026-07-11T01:39:54.0419058Z - Title: Process-supervisor terminal wrapper hosting broker PTYs
2026-07-11T01:39:54.0419359Z - Required stages: impl, unit
2026-07-11T01:39:54.0419504Z 
2026-07-11T01:39:54.0419585Z ### REQ-TERM-2
2026-07-11T01:39:54.0419828Z - Title: session-surface abstraction; send-keys + send-line injection
2026-07-11T01:39:54.0420138Z - Required stages: impl, unit
2026-07-11T01:39:54.0420278Z 
2026-07-11T01:39:54.0420363Z ### REQ-TERM-3
2026-07-11T01:39:54.0420564Z - Title: Byte-stream remote terminal streaming for v1
2026-07-11T01:39:54.0420820Z - Required stages: impl, unit
2026-07-11T01:39:54.0420960Z 
2026-07-11T01:39:54.0421050Z ### REQ-TERM-4
2026-07-11T01:39:54.0421580Z - Title: Live activity buffer (session digest): projection of normalized session logs, snapshot-pull (spt endpoint digest) + structured-delta-stream contract + api digest-entry push
2026-07-11T01:39:54.0422162Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0422310Z 
2026-07-11T01:39:54.0422400Z ### REQ-TERM-5
2026-07-11T01:39:54.0423911Z - Title: Adapter-declared digest extractor seam: a `[digest]` manifest section declaring an imperative extractor (native harness log -> the {role,text,tool,ts} contract; defaults to the [history] source files with an own-source escape hatch), `api digest-entry` push fallback, register-time validation of the section, adapter-declared presentation defaults (window depth, arg-truncation, sprint-collapse) that any consumer may override, and a `spt adapter digest-proof` author tool plus runtime skip-diagnostics (no silent drop). Reverses M9's no-manifest-seam stance; no declarative DSL.
2026-07-11T01:39:54.0425487Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0425673Z 
2026-07-11T01:39:54.0425787Z ### REQ-TERM-6
2026-07-11T01:39:54.0426893Z - Title: Thread-spanning digest across session boundaries: a per-endpoint session ledger (`<perch>/sessions.log`) appended at first bind and by `api boundary` on `/clear`|`/compact` session rotation, the digest enumerating the last K sessions so its rolling window bridges a boundary, and a distinctive in-timeline boundary marker (DigestEntry::Boundary). The digest follows the live-agent thread, not a single session.
2026-07-11T01:39:54.0428082Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0428230Z 
2026-07-11T01:39:54.0428316Z ### REQ-TERM-7
2026-07-11T01:39:54.0429566Z - Title: Two-origin digest merge: spt-owned context-injection entries (psyche_download | echo_mirror | owl_message) appended by spt to the endpoint `digest.log`, timestamp-interleaved with the adapter's extracted activity records into one ordered timeline, via a distinct context-injection record category. Data model only this milestone; GUI collapse/expand and the echo-reads-digest delta loop are deferred to the surfaces that consume them.
2026-07-11T01:39:54.0430994Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0431152Z 
2026-07-11T01:39:54.0431242Z ### REQ-FRONT-1
2026-07-11T01:39:54.0431477Z - Title: Day-one launcher/manager frontend (list/launch/attach/init)
2026-07-11T01:39:54.0431763Z - Required stages: 
2026-07-11T01:39:54.0431928Z 
2026-07-11T01:39:54.0432025Z ### REQ-HOST-RUN-1
2026-07-11T01:39:54.0434434Z - Title: spt-hosted harness bringup: `spt endpoint run` spawns an adapter's `[session.self]` command template into a broker-held PTY (the spawn-session seam, brain.rs spawn_session_pid — same broker path shellhost.rs launch_shell_brokered_in uses for shells, now for kind="harness" self-role), registers the perch under the given endpoint id, returns the id. Reverses today's harness-hosted-only launch (external launcher → `api bind`). Non-interactive flag set (--adapter <a[:profile]> --id <id> --create --resume <session> --attach|--start|--view) covers every terminal action of the W2 interactive picker so shortcuts (cc-<id>) bake fully non-interactive launches; composite adapter:profile resolves via registry::resolve_option leaf-replace overlay.
2026-07-11T01:39:54.0436418Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0436572Z 
2026-07-11T01:39:54.0436657Z ### REQ-RC-1
2026-07-11T01:39:54.0438732Z - Title: `spt rc <id>` — user CLI attaching a local terminal to a broker-held PTY, reusing the cross-node attach machinery (attach.rs request_attach → send_attach_input pump, spt-net AttachRecord codec); local attach is the degenerate single-node case of the cross-node path (rides REQ-TERM-3 byte-stream streaming). Read-only `--view` (watch, no stdin forwarded). Clean detach that does NOT terminate the broker-held session (KNOWN-HAZARDS: PTY ownership stays with the broker; no termination on detach). Explicit detach keybind that cannot collide with harness passthrough input (legacy capsule used a ctrl-b prefix); documented. ConPTY DSR auto-answer in the attach reader (hazard 5.5).
2026-07-11T01:39:54.0440667Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0440816Z 
2026-07-11T01:39:54.0440906Z ### REQ-HOST-RUN-2
2026-07-11T01:39:54.0442662Z - Title: Project-scoped working directory for spt-hosted bringup: `spt endpoint run` lands the broker-spawned harness PTY in the user's PROJECT cwd, not the daemon's, via an additive `SpawnReq.cwd` field carried through the broker PTY spawn (portable-pty CommandBuilder cwd). N-1-safe wire change (additive, defaulted). Required because the consumer (Claude Code) is project-scoped: broker-inherited cwd = the daemon's cwd = the wrong `.claude`, wrong session history, wrong digest source; `cc <id>` at a project root MUST land the harness in that project. W1 ships broker-inherited cwd as a bringup-proof shortcut only; this REQ must land before the M12 gate (doyle, 2026-06-14).
2026-07-11T01:39:54.0444469Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0444613Z 
2026-07-11T01:39:54.0444713Z ### REQ-RUN-PICKER
2026-07-11T01:39:54.0449474Z - Title: Interactive `spt endpoint run` picker (ratatui TUI): bare `spt endpoint run` (no --adapter/--id) enters an in-process picker (flags-present = the REQ-HOST-RUN-1 non-interactive path, untouched). Layer 1 picks kind (Create new | Pick existing). Create-new: choose a registered kind="harness" adapter with its shipped+local profiles tree-nested (registry::registered / manifest.profiles / local_profile_names) → enter a charset-validated id → start. Pick-existing: category select (left/right) over [<cwd-project> | Local node | Subnet], endpoints grouped + alphabetically sorted per category, a status square per endpoint (online green ■ / offline gray ▢ — the blue "attached" tri-state + Kick are DEFERRED to a broker attach-presence slice, M12-W2-RULING Q1), type-to-filter (`/`, nucleo-matcher), a pinned keybind legend, and a right-half two-pane description (harness adapter:profile · best-effort project history newest→oldest from the contextstore p-<project> branches, empty-if-none · `spt endpoint description`). Confirm layer offers status-dependent options — Attach/Start/View (rc pump / cmd_endpoint_run) · Instantiate-locally (remote) · Change-harness-adapter (offline) · Fork (cmd_fork) · Resume-from-history (offline+LOCAL only; enumerate spt_store::sessions::last_k, titles `<project> @ <ts> (…id5)`, feed session_id → cmd_endpoint_run --resume). A single action enum is the source of truth so a future tap-mode (phone PTY) layers on without re-coupling to keybinds. EVERY terminal action routes through cmd_endpoint_run / existing CLI fns — no second bringup path.
2026-07-11T01:39:54.0453842Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0453995Z 
2026-07-11T01:39:54.0454070Z ### REQ-RUN-SHORTCUT
2026-07-11T01:39:54.0458675Z - Title: `<basename>-<id>` launcher shortcut generation (picker `s` keybind, M12-W2-T2.4): from any pre-start options set the picker writes/updates a `<basename>-<id>` launcher at the project root baking the current selection's non-interactive `spt endpoint run` flags (terminal actions only: adapter[:profile] + id + (create|resume) + (start|attach|view); Kick/Instantiate/Change-adapter/Fork are interactive-only, not bakeable). BASENAME IS A PARAMETER (operator rev. 2026-06-14): harness-agnostic spt-core defaults to `spt` (→ `spt-<id>`); an adapter/flow OVERRIDES it (spt-claude-code → `cc`), so spt-core NEVER bakes `cc` (a harness name) into itself. The basename must be a DISTINCT token, never bare `spt` (a `spt.cmd` would shadow the real `spt.exe` only under cmd.exe cwd-first search, silently no-op in PowerShell/Unix, and self-recurse). The script is the CURRENT OS's native form — `.cmd` on Windows (NOT `.ps1`: default PATHEXT excludes `.ps1` so a bare/ext-less name never resolves one; `.cmd` is PATHEXT-resolvable), POSIX `sh` (+chmod +x) on Unix (a single portable form can't be both). The generated header documents the invocation reality (cmd.exe bare `<name>` in the project dir / PowerShell `.\<name>` / Unix `./<name>`; a truly-bare basename on PATH = a PATH-installed launcher, `/spt:setup`'s job). Overwrite is SENTINEL-guarded: the generator writes + checks a generated-by header marker — it overwrites its own prior output freely, but REFUSES + warns if a same-named file lacks the sentinel (never clobber a user file). Requires the additive `--create` flag on `Run{}` (the default-fresh made explicit; N-1-safe).
2026-07-11T01:39:54.0462909Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0463056Z 
2026-07-11T01:39:54.0463153Z ### REQ-RUN-PICKER-HOME
2026-07-11T01:39:54.0466655Z - Title: Home-subnet selection LAYER in the `spt endpoint run` ratatui Create-new picker (v0.14.1; the deferred half of REQ-RUN-MULTISUBNET-HOME's interactive path — ADR-0026 §3 'the interactive picker lists subnets MRU-ordered'). On a MULTI-SUBNET node the Create-new flow gains a `CreateHome` screen (CreateAdapter → CreateId → CreateHome → Confirm) that lists the node's MEMBER subnets MRU-ordered (reusing recent_home::mru_preference + order_by_mru), default cursor = MRU head; the chosen subnet rides Outcome::Run{subnet} into cmd_endpoint_run's --subnet, so decide_run_home resolves Home directly and the post-TUI `Ok to proceed? Y/n` confirm NEVER fires for the picker path. Single-subnet / local-only nodes SKIP the layer (assign_home auto-homes; CreateId → Confirm unchanged). The CLI / flagged `endpoint run` path KEEPS the decide_run_home Y/n confirm + the non-interactive MULTI_SUBNET_HOME refuse (operator: the confirm stays useful for CLI-only bringup, just not in the TUI). Esc backs CreateHome → CreateId; Enter selects → Confirm. Pure front-end invariant preserved: the layer only collects --subnet, routes through the one bringup core.
2026-07-11T01:39:54.0469802Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0469952Z 
2026-07-11T01:39:54.0470045Z ### REQ-ELEVATE-1
2026-07-11T01:39:54.0473178Z - Title: Cross-platform self-elevating re-launch for privilege-gated commands: a pure decision seam `decide_elevation_path(os, elevation, interactive_tty, has_display, has_pkexec, has_term_emulator) -> ElevatePath{AlreadyElevated, InlineSudo, UacWindow, Pkexec, TerminalEmulator, PrintHint}` selecting how to re-acquire privilege, and the per-OS impure launchers it dispatches — Windows UAC console (ShellExecuteW `runas` on the abs-exe + verbatim argv; the elevated child does the work, prints 'You can close this window', and pauses for a keypress; the original prints 'Elevated terminal launched…' and exits 0; NEVER pipes the child's stdout back across the privilege boundary), Linux desktop pkexec (preferred, native polkit GUI auth) else x-terminal-emulator -e sudo (fallback list x-terminal-emulator→gnome-terminal→konsole→xterm), the existing interactive-TTY inline sudo, and the headless/no-path floor that prints the absolute-path command. Reused by every gated command (not subnet-specific). Generalizes should_auto_elevate.
2026-07-11T01:39:54.0476270Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0476436Z 
2026-07-11T01:39:54.0476527Z ### REQ-WHOAMI-1
2026-07-11T01:39:54.0478197Z - Title: `spt whoami` is a thin ALIAS for `spt endpoint list` (full output: the SELF pin + the subnet roster) — the standalone bare-id command is dropped (the `id=$(spt whoami)` capture was never a real pattern: env vars don't persist between agent tool calls). The one new render: the `endpoint list` SELF pin carries the Self endpoint's authored `endpoint description` (info::read_info(...).resources) when present, inline after the liveness state. whoami stays a top-level hot-path verb (parse unchanged, REQ-MSG-9).
2026-07-11T01:39:54.0479642Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0479795Z 
2026-07-11T01:39:54.0479880Z ### REQ-RCVIEW-1
2026-07-11T01:39:54.0484259Z - Title: Remote-attach controller/viewer model (CONTEXT.md:317): a session's broker OutputLog serves ONE interactive controller (input + EXCLUSIVE PTY resize; its viewport sets the size, sent on attach + every window change via crossterm Event::Resize) plus ANY NUMBER of read-only `--view` attachers (output-only, no input, no resize; client-side letterbox — center+pad when larger, clip+1-line indicator when smaller; only the local ctrl-b d detach chord). Attach intent is three-valued (`Viewer | Control | Take`, wire-default Control): Control to a FREE endpoint becomes controller, Control to a CONTROLLED endpoint is REFUSED with guidance (`--view`/`--take`) — never auto-viewer, never silent-displace. Wire adds (additive, N-1 skip-unknown): `Request.intent`, `Resize{rows,cols}` (controller-only), `Size{rows,cols}` (→viewer), `Displaced{by}` (→displaced controller). The brain-resume cursor (delivered_through, ADR-0018) tracks the CONTROLLER ONLY; viewers replay from their own from_seq and never move it. Dormancy keys on the controller ONLY: controller attach wakes / controller detach goes dormant (even with viewers present); viewer attach/detach is wake-neutral and may watch a dormant endpoint as-is. v1: viewing is gated identically to driving — a viewer runs the same access_check(Unsolicited) as a controller (watching reveals full session contents = a real disclosure); a lighter distinct watch-gate is deferred to cross-subnet/finer-consent (CONTEXT.md:317 'driving ≠ watching' = the future seam).
2026-07-11T01:39:54.0488232Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0488399Z 
2026-07-11T01:39:54.0488481Z ### REQ-KICK-1
2026-07-11T01:39:54.0491072Z - Title: Explicit, loud controller displacement: `spt rc kick <target>` / `--take` (Take intent) kicks the incumbent controller and becomes controller; the displaced controller receives a LOUD `Displaced{by}` notice and is FULLY DETACHED (not demoted to a viewer). A default attach to a controlled endpoint is NEVER a silent displace (it is the Control busy-refusal). An old (N-1) rc omits intent → Control, so it can drive a free endpoint but CANNOT `--take` — it can never silently steal, and gets a clean busy-refusal instead. Taking control rides the same access_check(endpoint, origin, Unsolicited) as a normal control attach (if you may drive, you may take — no elevated kick policy). The picker surfaces 'Kick <node> and attach' (Take) only on a controlled (blue ■) endpoint, via the existing attach dispatch (single-bringup-path: intent is a parameter).
2026-07-11T01:39:54.0493435Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0493602Z 
2026-07-11T01:39:54.0493688Z ### REQ-PICKER-1
2026-07-11T01:39:54.0497250Z - Title: The picker renders a FOUR-state endpoint status (extending the W2 online/offline duality): the list-item square AND a color-coded STATUS line at the top of the pick-existing right-side details both show — gray OFFLINE; green ONLINE (online + PTY-controllable spt-hosted, not controlled); amber 'ONLINE - HARNESS ONLY' (online but NOT broker-PTY-controllable = harness-hosted, no broker PTY seat — today mis-shows green); blue 'ONLINE + CONTROLLED' (online + driven_by.is_some()). Derived on EndpointRow from {offline | controllable | driven_by} with precedence offline→gray, else driven_by→blue, else !controllable→amber, else green (driven_by outranks harness-only; mutually exclusive in practice — a harness-only endpoint has no broker PTY to control). The controllable discriminator is a NEW InfoJson.controllable: Option<bool> (serde-default, N-1-safe), stamped at the establish seam — cmd_listen (harness-hosted relay, no broker PTY) → Some(false); cmd_bind live_agent (spt-hosted broker PTY) → Some(true); absent → not-controllable (amber) default (harness-hosted is the common mis-reported case; one bind self-corrects). Store-projection-only (no live daemon query — doyle ruling). (v0.10.0)
2026-07-11T01:39:54.0500676Z - Required stages: impl, unit
2026-07-11T01:39:54.0500829Z 
2026-07-11T01:39:54.0500920Z ### REQ-PICKER-2
2026-07-11T01:39:54.0502824Z - Title: The picker's project-history loader reads the git-backed context store, not the bare working tree: data.rs project_history_for enumerates an endpoint's projects via the BranchStore branch set (the context store keeps per-project context in git branches — contextstore::project_branch(project_id), checked out to projects/<project>/<id>/ only on-demand) instead of raw std::fs::read_dir over the empty working tree (which returned empty for ALL rows incl wall-a — the operator bug). Ordered newest→oldest by branch commit recency; degrades to empty (informational pane), never fails. (v0.10.0)
2026-07-11T01:39:54.0504449Z - Required stages: impl, unit
2026-07-11T01:39:54.0504591Z 
2026-07-11T01:39:54.0504681Z ### REQ-PICKER-3
2026-07-11T01:39:54.0507181Z - Title: A self-owned subnet row reconciles its status to the LIVE roster: a Subnet-category row whose endpoint_id overlaps a local (is_local) roster id is self-owned (this node hosts it), so its status square is OVERRIDDEN with the live roster status — the WAN registry snapshot (wansend::load_snapshots) is a periodically-advertised, independently-stale projection, while the local roster (p.alive) is ground truth for an endpoint this node hosts. One status square per endpoint (CONTEXT.md:348-350 — nothing licenses opposite squares for one endpoint across its Local vs Subnet listings). A reconcile pass in data.rs after the local_rows + subnet_rows gather; BOTH category listings are preserved (Local + Subnet are legitimately distinct views — you are in your own subnet), only the STATUS is unified. (v0.10.0)
2026-07-11T01:39:54.0509386Z - Required stages: impl, unit
2026-07-11T01:39:54.0509524Z 
2026-07-11T01:39:54.0509616Z ### REQ-PICKER-4
2026-07-11T01:39:54.0511542Z - Title: The picker's Subnet category renders the canonical node LABEL, not bare key-hex: a subnet row's node renders as 'LABEL (keyprefix…)' (e.g. 'HFENDULEAM (bcead52b…)') per CONTEXT.md:650 + Instance.node_label, NOT the raw node key-hex (SPT_DEV:14efb80cb… — a picker-only regression because resource_projection→ResourceRow drops node_label, so data.rs subnet_rows uses the raw row.node). Thread node_label into the picker subnet path (ResourceRow gains node_label, or subnet_rows looks it up via the registry's node_labels) and REUSE the one canonical render (format!("{l} ({}…)", key_prefix) — cli.rs / wansend.rs), never a re-implementation. (v0.10.0)
2026-07-11T01:39:54.0513517Z - Required stages: impl, unit
2026-07-11T01:39:54.0513665Z 
2026-07-11T01:39:54.0513751Z ### REQ-PICKER-5
2026-07-11T01:39:54.0516795Z - Title: `spt endpoint list` (bare/subnet view) renders an ALIGNED table with canonical node labels: cmd_endpoint_list prints subnet rows with `\t` TAB separators (cli.rs:~1651-1662) so variable-width endpoint_ids snap fields to different tab-stops → a RAGGED status column (operator screenshot: X/help statuses misaligned vs rt-*/sptc-*/wall-a); and it calls the node renderer with no label → bare key-hex for every row (SAME ResourceRow-drops-node_label root as REQ-PICKER-4). FIX: max-width per-column padding (mirror render_node_rows' pad, pad by char count not byte len — '…' is multibyte) replacing the tabs, and render the node via the shared node_label_display now that ResourceRow carries node_label (REQ-PICKER-4). Extract a pure row-formatter seam so the alignment+label is unit-testable. ALSO: the bare list is the SUBNET view (a just-run LOCAL perch is invisible cross-subnet until the next advertise tick), so emit a `--local` hint line so a freshly-run endpoint isn't perceived as lost. (v0.10.0; operator-flagged + doyle dispatch 2026-06-17)
2026-07-11T01:39:54.0519753Z - Required stages: impl, unit
2026-07-11T01:39:54.0519904Z 
2026-07-11T01:39:54.0519998Z ### REQ-SEND-SPT-HOSTED
2026-07-11T01:39:54.0523639Z - Title: An inbound `spt send` is DELIVERED to an spt-hosted endpoint (brought up via `spt endpoint run` → `api bind`, broker holds its PTY, NO `api listen` relay). Today cmd_bind→establish_perch (api/startup.rs ~441) writes info.json + ready marker + controllable=Some(true) but registers NO message-listener / NO address, so deliver.rs resolve_address→None→spool (deliver.rs:132-140) and the message NEVER reaches the live PTY — the endpoint reads 'online' (ready marker) yet `spt send` silently SPOOLS ('online but not deliverable' lie). Per CONTEXT:187-188 the daemon owns the PTY and delivers, manifest-configurable per activity-state (direct PTY injection / relay / HTTP). FIX: route an inbound send for an spt-hosted target through the daemon → broker InputReq → session.write_input PTY-inject (broker.rs dispatch_input/write_input ~988-1022), the same path the brain uses; the live-delivery handshake must report Sent (not Queued) and stop the spool-only fallback for a broker-hosted, PTY-resident endpoint. Detection is local: controllable==Some(true) + spt-hosted state + resolve_address==None. = the spt-core HALF of the wall-b finding (perri owns the adapter half: bind-hook fired-zero-perch + the missing endpoint-run int test). (post-v0.10.0)
2026-07-11T01:39:54.0526956Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0527109Z 
2026-07-11T01:39:54.0527209Z ### REQ-HAZARD-RC-EOF
2026-07-11T01:39:54.0531192Z - Title: A severed broker stream during a live rc session surfaces GRACEFULLY, never as a raw io error that crashes the PTY. The rc read-loop (rc.rs:352-362) continues only on WouldBlock/TimedOut; ANY other read_event_until error — including UnexpectedEof 'failed to fill whole buffer' — returns Err → RC_FAIL → the PTY 'crashes' from the user's view. Confirmed trigger: a deliberate `spt daemon stop` (broker bounce) severs an active rc (perri stopped the daemon to release owlery watch handles). Same severed-broker-stream EOF class as the v0.9.1 seed fix (seed_fail_message) and the listener-death case — spt-core must classify a broker-gone EOF and (a) surface a CLEAR actionable message ('daemon stopped/restarted — re-run / reconnect'), never the raw buffer error, and ideally (b) AUTO-REATTACH to the same session on the fresh broker (the broker is the daemon-lifetime anchor; it returns on the next `spt api` call). FOLD two side-observations: (1) `spt daemon stop` SILENTLY drops active rc/live sessions — warn ('N active session(s) will drop') or graceful-detach on stop; (2) the daemon holds owlery WATCH HANDLES on perch dirs so a torn-down perch dir stays 'Device busy' until a full daemon stop releases them (perri's rt-* cleanup) — a torn-down perch's handle should release without a daemon stop. doyle Finding C, root-caused. (post-v0.10.0)
2026-07-11T01:39:54.0534843Z - Required stages: impl, unit
2026-07-11T01:39:54.0534990Z 
2026-07-11T01:39:54.0535096Z ### REQ-HAZARD-DEFERRED-MANIFEST
2026-07-11T01:39:54.0537487Z - Title: A pointer-mode (delegated / GhReleaseManaged) adapter whose binary/manifest is not yet extracted is reported with a CLEAR diagnostic, never silently dropped. Today such an adapter reads its manifest LIVE from source_dir (registry.rs manifest_dir ~146/149); a deferred / un-extracted install makes load_manifest fail → registered() (~410, filter_map(.ok())) SILENTLY DROPS the row → downstream ADAPTER_UNRESOLVED + a cryptic os-error-2 on `spt adapter use`. FIX: surface a clear diagnostic at the resolver + at `adapter use` (name the adapter + the deferred/missing-manifest cause + the fix), not a silent filter-drop and not a bare os-error-2; consider an eager manifest copy at register time so host_binaries survive before the binary download completes. doyle Finding A. (post-v0.10.0)
2026-07-11T01:39:54.0539687Z - Required stages: impl, unit
2026-07-11T01:39:54.0539834Z 
2026-07-11T01:39:54.0539927Z ### REQ-HAZARD-ENV-SUBST
2026-07-11T01:39:54.0543387Z - Title: `spt endpoint run` HONORS manifest [env.<VAR>] direction=inject values (with {key} substitution) on the spt-hosted spawn. Today only the [session.self] command ARGV is {id}-substituted; the [env] inject value is NEITHER substituted NOR applied — manifest.schema.json promises EnvVar.value = 'Value to inject (with substitution)' but prepare_harness_spawn fills only argv and SpawnReq carries no env, so a [env.SPT_ENDPOINT_ID].value='{id}' arrives EMPTY. A FLAGLESS harness (bare `claude`, no argv slot for {id}) then routes the id via [env] → empty → SessionStart sees empty $SPT_ENDPOINT_ID → seeds-by-PPID instead of binding → ZERO perch → NO_PERCH (the actual wall-b bind blocker; perri hard-repro'd). SILENT failure (empty inject, no error). FIX (doyle ruled a): fill every [env] inject value from the SAME {key} catalog as argv/role (mirror F-009 TEMPLATE fill, whole-string fill_template for an env value), thread it through SpawnReq.env → the broker sets it on the spawned PTY child. Correctness fix — schema already promises it, NO manifest change, NO new binary. PAIRS with REQ-SEND-SPT-HOSTED to make endpoint run fully work. doyle F-013. (post-v0.10.0)
2026-07-11T01:39:54.0546455Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0546607Z 
2026-07-11T01:39:54.0546708Z ### REQ-HAZARD-ROSTER-GHOST
2026-07-11T01:39:54.0549280Z - Title: A LOCAL subnet roster entry whose backing perch is erased does NOT keep advertising Active (no phantom perch-less endpoint). `api session-end <id> --erase` removes the perch (owlery dir gone) but the subnet roster (identity/registry/<subnet>.json) keeps the endpoint's instance row ACTIVE with no backing perch; `endpoint stop` says 'address unregistered' yet the line persists; no CLI verb forgets a roster entry, and a hand-edit is re-added by the single-writer daemon advertiser. FIX: daemon-side self-heal — the advertiser DROPS/forgets a LOCAL roster entry whose backing perch no longer exists (stops advertising it Active), and/or a `forget`/evict verb; verify whether the epoch lease eventually evicts it (slow-self-heal) vs a real leak and scope accordingly. doyle secondary finding (perri). (post-v0.10.0)
2026-07-11T01:39:54.0551433Z - Required stages: impl, unit
2026-07-11T01:39:54.0551575Z 
2026-07-11T01:39:54.0551669Z ### REQ-WAN-SPT-HOSTED-DELIVERY
2026-07-11T01:39:54.0555281Z - Title: A WAN-ARRIVED `spt send` is DELIVERED to an spt-hosted endpoint (broker holds its PTY, NO api-listen relay), not spooled-forever. Today receive_wan (spt-daemon/wan.rs:271-276) tries deliver_tcp (the harness-hosted relay leg) then falls to spool — it has NO spt-hosted broker-inject leg, which exists ONLY in local cmd_send (REQ-SEND-SPT-HOSTED, Brain::inject_endpoint → KIND_ENDPOINT_INPUT → broker dispatch_endpoint_input → translation-binary idle-inject). So a WAN arrival to an idle spt-hosted perch with a live translation binary ALWAYS sleeps in spool until an adapter hook polls (F-023: perch verifiably idle 7min, binary healthy, zero injection). FIX: factor cmd_send's spt-hosted delivery leg into a SHARED fn; receive_wan calls it after the replay-check (wan_seen_at) + restamp (restamp_wan_user_msg), BEFORE the spool fallback. Claim discipline UNCHANGED: inject delivered=true → wan_mark_seen_at then return the existing 'delivered' wire token (no wire change); delivered=false → the existing spool-with-claim transaction. v0.14.3 LAW: the shared leg is translation-binary-ONLY, NO raw-PTY fallback — a no-binary arrival SPOOLS LOUD, never writes the PTY. (F-023, BUILD-F023-WANIDLE)
2026-07-11T01:39:54.0558765Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0559093Z 
2026-07-11T01:39:54.0559183Z ### REQ-MSG-IDLE-EDGE-DRAIN
2026-07-11T01:39:54.0561628Z - Title: On an endpoint's ACTIVE→IDLE transition the daemon DRAINS its pending spool (deferred AND non-deferred) through the same shared spt-hosted inject leg — closing the SECOND F-023 gap: no idle-edge drain exists anywhere, so an spt-hosted endpoint (which has no api-listen relay to wake it) strands BOTH message classes ('ACTIVE → spool deferred for hook-poll' and 'IDLE+no-binary → non-deferred for a relay that does not exist'). FIX: on the state ACTIVE→IDLE edge, offer the pending spool through the shared inject leg; REUSE the hook-poll drain's take/ack machinery so a concurrent `api poll` cannot double-deliver — ONE drain path, TWO triggers (hook-poll + idle-edge). v0.14.3 LAW holds on BOTH triggers: translation-binary-ONLY, a no-binary idle drain SPOOLS LOUD, never writes the PTY. (F-023, BUILD-F023-WANIDLE)
2026-07-11T01:39:54.0563789Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0563942Z 
2026-07-11T01:39:54.0564037Z ### REQ-HAZARD-DELIVERY-STARVATION
2026-07-11T01:39:54.0566185Z - Title: A message that has REACHED a node's spool (WAN-arrived or locally spooled-while-active) is NEVER dependent on an adapter HOOK-POLL cadence for its eventual delivery to an spt-hosted (relay-less) endpoint — the daemon itself drives delivery on the events it owns (WAN ingress + the ACTIVE→IDLE edge). Hazard class: delivery starvation. Without this, cross-node and post-active messages to an spt-hosted perch strand indefinitely whenever the adapter's hooks are quiet (idle session, no user turns), presenting as 'sent but never lands' with a healthy binary and an idle perch (F-023). Guarded by REQ-WAN-SPT-HOSTED-DELIVERY (WAN ingress leg) + REQ-MSG-IDLE-EDGE-DRAIN (idle-edge drain). (F-023)
2026-07-11T01:39:54.0568062Z - Required stages: doc, int
2026-07-11T01:39:54.0568195Z 
2026-07-11T01:39:54.0568290Z ### REQ-MSG-CLI-ORIGIN
2026-07-11T01:39:54.0570242Z - Title: A bare non-perch CLI `spt send` (no owning perch to name as origin) stamps from = `cli@<node-label>` at compose time (bare `cli` when no node label is known — never a dangling `cli@`), and WAN ingress renders an EMPTY from as the origin node DISPLAY (`node_label_display(origin_node, None)` = the QUIC-proven origin node's key-prefix; never blank) — a delivered message NEVER shows a blank sender. Scoped to `spt send`: a from-less send is LEGAL (stamped, never refused), while `spt ring` keeps its NO_SELF refusal (a ring needs a routable self for the reply leg; `cli@<node>` is a display origin, not a perch address). (F-024C item 3, doyle ruled)
2026-07-11T01:39:54.0571931Z - Required stages: impl, unit
2026-07-11T01:39:54.0572082Z 
2026-07-11T01:39:54.0572188Z ### REQ-HAZARD-SESSION-PIN-WEDGE
2026-07-11T01:39:54.0578780Z - Title: A perch PINNED to a DEAD session-id self-heals instead of wedging forever. authenticate() (spt/src/api/auth.rs:78) gates api poll/state/boundary on proof-sid == info.json.session_id; if ONE boundary rotation is lost (transient env corruption kills the /clear-era hook), the perch stays pinned to the dead sid and EVERY id-scoped hook call refuses — INCLUDING boundary itself (it presents the new sid), a permanent strand (ready:false, stale .idle, drain no-ops, WAN spool sleeps forever; AUTH_REFUSED is stderr-only = invisible inside a hook). FIX: authenticate() gains a DEAD-OWNER fallback — when the sid MISMATCHES AND the perch's recorded pid is dead (proc::is_process_alive==false), ACCEPT the caller's sid and RE-PIN (rotate session_id + log SESSION_REPIN loud). Same trust model as establish_perch's conflict gate (api/startup.rs:207-210), which already allows rebind exactly when owner_alive==false (an orphaned perch accepts a new LOCAL owner). A LIVE-owner mismatch STILL refuses (squat protection UNCHANGED). ADDITIVE to token auth — the existing token-auth recovery path is UNTOUCHED; the new branch fires only on (no token) AND (sid mismatch) AND (owner dead). COVERAGE SPLIT (explicit, perri clean-room 2026-07-02 — the wedge latches on /clear even in a CLEAN env, so the corruption domino was sufficient but NOT necessary): the dead-owner re-pin rescues CRASHED/DEAD sessions ONLY; a LIVE-pid rotation (/clear, /compact — same process, new sid) is CORRECTLY refused without the departed session's prior-sid proof and MUST NOT be widened to live owners. The live-rotation contract is adapter-side: the adapter PERSISTS the prior sid across rotation and PRESENTS it as boundary proof (perri's state-file pattern = the reference); a silent boundary skip on an unresolvable id, or a boundary call with NO auth proof, strands the perch (perri's court). Core rescues only the dead-owner orphan; live-rotation proof is the harness-contract's job (see the harness-contract boundary section, which cross-refs this hazard). PARKED (not this wave, logged): pid-ancestry self-proving rotation (core walks the caller's real ancestry vs info.json.pid) — needs an ADR + Windows parent-spoof caveats. (F-024C, F024C-AUTHWEDGE-ADDENDUM + F024D-DOCSCOPE)
2026-07-11T01:39:54.0584753Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0584904Z 
2026-07-11T01:39:54.0585000Z ### REQ-HAZARD-STORE-INIT-RACE
2026-07-11T01:39:54.0588086Z - Title: Concurrent first-touch of ONE fresh BranchStore must ALL succeed, never a hard error. BranchStore::open_or_init (spt-store/src/branchstore.rs:47) is a TOCTOU: it gates on HEAD.exists() then runs a NON-ATOMIC init (`git init --bare` + `git config core.autocrlf false` + best-effort worktree.useRelativePaths). Two processes that both observe !HEAD.exists() on one fresh store race the `git config` step, which takes git's per-repo config.lock — the loser fails with 'could not lock config file …/config: File exists', an io::Error that strands the caller (the G3-gate pump.rs:442 flake, doyle-ledgered). FIX: make init race-tolerant — `git init --bare` is idempotent, and `git config` is idempotent (same bytes), so tolerate a concurrent winner (open-after-lose: if init errors but HEAD now exists, proceed as opened) and retry a transient config.lock collision a bounded number of times so the required core.autocrlf=false is guaranteed set. N concurrent open_or_init on ONE fresh dir must ALL return Ok. (F-025 wave, doyle Item 2)
2026-07-11T01:39:54.0590934Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0591100Z 
2026-07-11T01:39:54.0591210Z ### REQ-HAZARD-SPOOL-SENTINEL-CREATE-FAIL
2026-07-11T01:39:54.0593150Z - Title: A persistent failure to (re)create the spool has-messages sentinel is SURFACED, never silently swallowed. touch_has_messages (spt-store/src/spool.rs:147) does `let _ = File::create(...)` — a live field defect on ENLYZEAM left a stale .has-messages (2026-06-29) beside a fresh spool.db insert (06:59:17Z) in ONE directory, i.e. the create silently failed while rows accumulated (suspected read-only-attrib / share-lock). FIX: on File::create failure emit a LOUD-ONCE-per-perch stderr diagnostic naming the concrete io::Error (self-identifying regardless of kind); do NOT make it fatal (spool writes still proceed). (F-024C item 2, doyle)
2026-07-11T01:39:54.0594858Z - Required stages: impl, unit
2026-07-11T01:39:54.0595003Z 
2026-07-11T01:39:54.0595102Z ### REQ-MANIFEST-NODE-KEY
2026-07-11T01:39:54.0599447Z - Title: A new session-scoped manifest fill key `{node}` resolves to THIS node's advertised label — available wherever the session-scoped keys ({id}/{session_id}/{session_name}) populate: BOTH topologies' spawn-prep catalogs (harnesshost.rs:111-118 self-spawn guaranteed-fill + lifecycle.rs:280 base lifecycle keys, at minimum [session.self] and [session.resume]) AND lazy [strings] eligibility (ADR-0029 family). VALUE (design-true per CONTEXT §node label / REQ-SUBNET-3): the node's ADVERTISED LABEL — the same value node_label_display renders — read from the label store (NodeLabel, registry.rs:118/220, OS-hostname default re-checked at daemon startup), NOT the pubkey and NOT a fresh gethostname at fill time when the store already holds the refreshed label; fall back to the OS hostname only if no label is known. perri's concrete use: templating `--remote-control {id}--{node}` in the claude-spt launch/resume commands. CAVEAT (documented in the manifest.md key-table row AND here): SINGLE-TOKEN fills only — tokenize-then-fill (REQ post-F-009) cannot produce a space-carrying argv element, so composite display names like `<id> @ <node>` remain adapter-shim territory (claude-spt v0.10.3's launch shim stays the reference for those); {node} COMPLEMENTS the shim for tokenizable args, it does not replace it. Origin: perri fill-catalog-gap finding 2026-07-02, operator-promoted into BUILD-F023-WANIDLE (additive, independent of the delivery legs). (NODEKEY-FOLD)
2026-07-11T01:39:54.0603491Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0603645Z 
2026-07-11T01:39:54.0603753Z ### REQ-HAZARD-HOSTED-LIVENESS-RECONCILE
2026-07-11T01:39:54.0607828Z - Title: B2 KEYSTONE: a daemon-hosted (spt-hosted) endpoint's info.json status is RECONCILED to real liveness, not left latched online. The broker exit-waiter (broker.rs:889-910) reaps its in-mem session table + emits ExitEvent but NEVER touches info.json; lifecycle::mark_offline only fires on Psyche teardown — so a dead/exited harness (operator closed the tab) stays status=online forever (is_perch_alive returns ONLINE for daemon-hosted, liveness.rs:80-93). FIX (doyle ruled PULL-PRIMARY — the live-status analog of REQ-HAZARD-ROSTER-GHOST): the livehost reconcile loop (reconcile_once livehost.rs:226-313) queries the broker's live session set (KIND_SESSIONS) each tick and, for any status=online live_agent perch PAST the boot grace whose endpoint has NO live broker session, marks it offline (lifecycle::mark_offline → status=offline → is_perch_alive=false). GATED on spt-hosted (controllable==Some(true)) so a HARNESS-HOSTED relay live agent (api listen, legitimately online with no broker session) is NEVER mis-marked. Crash-robust + self-healing on the next tick (clear-on-event is not crash-robust alone). PUSH (brain ExitEvent→mark_offline) is an OPTIONAL fast-path only if the daemon brain is reliably subscribed to all hosted sessions; correctness rides the pull. Broker stays stateless (ADR-0004 §B — brain owns the info.json write). (v0.12.0)
2026-07-11T01:39:54.0611504Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0611667Z 
2026-07-11T01:39:54.0611779Z ### REQ-HAZARD-RC-ATTACH-FAILFAST
2026-07-11T01:39:54.0615063Z - Title: B1: `spt rc <id>` to a DEAD or non-streaming session fails fast with a clear message, never an INFINITE blank screen. Today rc.rs run_attach (209-231) + pump spawns PUMP_IPC_READER and blocks: the poll times out each slice but the stream never produces output, so the operator sees a permanent blank (operator: fresh wall-f attached, closed tab, then `spt rc wall-f` HUNG — the broker still resolved a session for it). FIX: (a) once B2 lands, gate attach on is_online/status — an offline endpoint yields a clean 'endpoint offline, start it' not an attach; (b) fail-fast — if the attach-open ack / first output does not arrive within a bound, surface a clear message, never an infinite blank; (c) the broker EOFs the attach stream when the session's child is dead, so rc's existing PumpEnd::BrokerGone graceful path (REQ-HAZARD-RC-EOF) catches it. PIN the exact sub-mechanism with a repro test FIRST (dead-session-lingers-in-broker vs reaped-but-rc-waits vs alive-resting-no-wake — the wall-f Windows tab-close: child alive-silent vs dead-not-reaped). (v0.12.0)
2026-07-11T01:39:54.0618051Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0618197Z 
2026-07-11T01:39:54.0618298Z ### REQ-ENDPOINT-STOP-OFFLINE
2026-07-11T01:39:54.0619742Z - Title: H3: `spt endpoint stop <id>` marks the endpoint OFFLINE (alive=false), not merely de-readied. cmd_stop (cli.rs:2994-3010) removes the ready marker + unregisters the address but does NOT set status offline, so a stopped daemon-hosted endpoint still reports alive=true (status=online latch). FIX: add set_status(perch, STATUS_OFFLINE) to cmd_stop — folds with B2 (same setter). Unit: stop → is_perch_alive=false / alive=false. (v0.12.0)
2026-07-11T01:39:54.0621044Z - Required stages: impl, unit
2026-07-11T01:39:54.0621191Z 
2026-07-11T01:39:54.0621292Z ### REQ-HAZARD-DAEMON-STOP-BARRIER
2026-07-11T01:39:54.0623095Z - Title: B3: `spt daemon stop` then an immediate `spt daemon start` does NOT race — stop fully completes before it returns. Today request_stop (seedmap.rs:240-255) returns on the KIND_STOPPING ack (sent seedmap.rs:174-176) BEFORE the seed socket unbinds, so a following is_running ping (daemon.rs:375) wins the exit window and start reports ALREADY_RUNNING (operator: daemon stop → STOPPED then start → ALREADY_RUNNING). FIX: unbind/stop-gate the seed socket BEFORE acking KIND_STOPPING, OR request_stop waits for a ping-to-fail before returning. Unit: stop then immediate is_running()==false. (v0.12.0)
2026-07-11T01:39:54.0624669Z - Required stages: impl, unit
2026-07-11T01:39:54.0624808Z 
2026-07-11T01:39:54.0624922Z ### REQ-HAZARD-SEEDMAP-CONNECT-UNBOUNDED
2026-07-11T01:39:54.0628377Z - Title: SEED (doyle-filed, 2026-07-05, from the REQ-HAZARD-DAEMON-STOP-BARRIER B2 fix): the PRODUCTION seedmap connect callers (put / take / is_running) inherit the SAME interprocess WaitNamedPipeW-forever hazard the stop path just bounded — a Windows named-pipe connect to a name that EXISTS but has NO accepting instance parks in NMPWAIT_WAIT_FOREVER, so a slow / half-dead seed daemon could wedge a live `api seed` / `api listen` / `daemon start`. UPDATE (2026-07-05, doyle reversed the stop-path scope-guard): request_stop's OWN initial connect became load-bearing (a stop-guard re-dialing an already-dying name parked forever, resurrecting the convoy) → it is now bounded via connect_bounded under REQ-HAZARD-DAEMON-STOP-BARRIER (every dial on the STOP path is bounded). REMAINING deferred here = the put / take / is_running production clients. FIX (deferred, needs its own ruling): a shared bounded seed-control connect for those — but a 2s-style cap on a legitimately slow daemon-start connect is a real behavior change (a slow-but-fine start could become a spurious failure), so the timeout + degrade semantics need design first. NOT built — activate when scoped.
2026-07-11T01:39:54.0631594Z - Required stages: 
2026-07-11T01:39:54.0631713Z 
2026-07-11T01:39:54.0631819Z ### REQ-HAZARD-DAEMON-STOP-REAP
2026-07-11T01:39:54.0633684Z - Title: Breap: `spt daemon stop` REAPS the spt-hosted children it spawned — no orphaned psyche/harness processes. Today a stop leaves ~8 orphaned claude-spt-psyche.exe + spt.exe: Psyches are spawned DETACHED (runtime.rs:342-356, the Child is dropped — 'Detached' ~349) and the livehost stop flag Arc<AtomicBool> is NEVER raised (brainproc.rs:227-230 holds it 'for symmetry'). FIX: on stop, raise the livehost stop flag AND kill the spawned psyche/spt-hosted children — via a Windows job object / Unix process-group so the children die with the daemon (not detached-immortal). Folds with B3 (both the stop path). (v0.12.0)
2026-07-11T01:39:54.0635320Z - Required stages: impl, unit
2026-07-11T01:39:54.0635448Z 
2026-07-11T01:39:54.0635573Z ### REQ-HAZARD-LIVEHOST-BOOT-LIVENESS-GATE
2026-07-11T01:39:54.0638058Z - Title: B5: `spt daemon start` does NOT revive phantom Psyches for dead-but-online-latched perches. Today reconcile_once (livehost.rs:285) spawns a Psyche per status=online live_agent perch at boot WITHOUT verifying the harness child / {id}-psyche is actually alive — so a Cold start after an unclean stop revives N psyches for N dead-but-latched perches (3 psyches for 3 dead perches). FIX: gate the boot psyche-spawn on real child-liveness — a perch with NO live broker session (the B2 reconcile signal) is marked OFFLINE at boot instead of hosted, so a dead-harness perch is never revived. Shares the B2 reconcile loop (this is its boot-gate arm); composes with B2's honest latch. Also closes wall-a's psyche_host_error gap (residency-confirm does not run at boot tick-1, livehost.rs:395-441 / 257-263). (v0.12.0)
2026-07-11T01:39:54.0640524Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0640677Z 
2026-07-11T01:39:54.0640802Z ### REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE
2026-07-11T01:39:54.0643446Z - Title: B4 (deepest): a bare brain restart (broker survives) REHYDRATES the live-agent lifecycle so post-restart endpoints are hosted + attachable. Today resume_sessions (brainproc.rs:186, brain.rs:797-809) re-subscribes to the broker's PTY sessions but ALL BrainLifecycle instances (lifecycle.rs:58-130; the ephemeral brain.rs:254-275) are LOST on restart → a post-restart live endpoint gets no livehost → its Psyche is never (re)hosted and new spawns die / can't attach until a FULL daemon reset (operator: perri's brain kill+restart wedged everything until a full daemon kill). FIX: on brain startup, rebuild a BrainLifecycle per resumed live-capable session — load the manifest from the adapter registry → instantiate → start the pulse — the rehydrate the resume no-op cannot do. Composes with B2 (the reconcile re-hosts from the honest on-disk status after rehydrate). (v0.12.0)
2026-07-11T01:39:54.0645741Z - Required stages: 
2026-07-11T01:39:54.0645885Z 
2026-07-11T01:39:54.0645994Z ### REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP
2026-07-11T01:39:54.0649845Z - Title: A bare brain restart leaves EXACTLY ONE `{id}-psyche` process per endpoint — no duplicate. On an abrupt brain death stop_host never runs (the LiveSet + owned child handles die with the brain) and Breap's job/group only reaps at DAEMON stop, so the PRIOR brain's Psyche stays ALIVE; the respawned brain's reconcile re-hosts a SECOND Psyche and overwrites the `{id}-psyche` perch pid, leaving the old one untracked + alive = a duplicate that lingers until daemon-stop (the operator's 'brain kill+restart wedged everything'). FIX: at brain start, BEFORE the first reconcile re-hosts, reap any pre-existing `{id}-psyche` orphan — ID-SPECIFICALLY (recycle-safe on the shared box, where sibling agents share the `claude` basename): scoped-kill the recorded pid ONLY IF it is alive AND its exe basename == the adapter's psyche program (normalize_basename) AND its COMMAND LINE contains the full psyche id `<id>-psyche` (baked via {id}); a sibling never carries THIS id, and any unreadable signal FAILS SAFE (decline to reap — a missed dup is bounded by Breap, a wrong-kill is catastrophic). CAVEAT: the cmdline carries `<id>-psyche` only when the adapter's psyche_init.command uses {id} (the norm); a non-{id} adapter safely MISSES the reap (today's behavior, Breap bounds it) — never a wrong-kill. (v0.12.0)
2026-07-11T01:39:54.0653315Z - Required stages: 
2026-07-11T01:39:54.0653434Z 
2026-07-11T01:39:54.0653535Z ### REQ-HAZARD-UNHOST-PSYCHE-REAP
2026-07-11T01:39:54.0656784Z - Title: On un-host, the detached `{id}-psyche` HARNESS PROCESS is reaped — not just its in-brain pulse-driver thread. Today stop_host (livehost.rs:203) trips the HostedLife stop flag + JOINS the driver thread, but the Psyche is a detached harness process (spawn_psyche → ManifestRuntime detached spawn, runtime.rs:341-356; its pid is untracked in HostedLife though stamped on the `{id}-psyche` perch, where residency-confirm already reads it). So endpoint-stop / mid-life agent-death / a B2/B5 offline-then-unhost leaves the psyche process ORPHANED, alive until the next daemon-stop (where Breap's job/group reaps the whole brain subtree). The Psyche STAYS a harness process by design (CONTEXT.md 97/203/251 — headless harness session, its own perch) — the fix does NOT move it in-brain; it SCOPED-kills the `{id}-psyche` pid on un-host (never machine-wide — shared box). Track the pid in HostedLife at host_one (cleanest) or read the `{id}-psyche` perch pid at stop_host. Composes with H3 (endpoint stop → offline → reconcile un-host → reap) and B2/B5 (the offline arms that trigger un-host). (v0.12.0)
2026-07-11T01:39:54.0659986Z - Required stages: 
2026-07-11T01:39:54.0660100Z 
2026-07-11T01:39:54.0660195Z ### REQ-ENDPOINT-PURGE
2026-07-11T01:39:54.0664855Z - Title: `spt endpoint purge <id>` fully removes an endpoint AND every record keyed on it — the formal teardown devs/CI need for clean test setup/reset. NOT consent-gated (a local dev/test op — no peer consent). OFFLINE-ONLY: refuses while the endpoint is online / daemon-hosted (deleting records out from under a live host risks the daemon re-creating or re-hosting mid-purge); `--force` STOPS it first (endpoint stop → wait for the daemon reconcile to un-host + reap the Psyche) THEN purges. Confirms interactively unless `--yes` (the CI path). Refuses purging the CALLER's OWN running id. All LOCAL — purge reaches only THIS node's records; a remote endpoint's records can't be touched, and its subnet-registry rows decay via the epoch-lease eviction (REQ-HAZARD-REGISTRY-DECAY). Removes: (1) the perch dir TREE recursively — owlery/<id>/ incl every nested {id}-psyche / {id}-w* / shells child (info.json, ready marker, sessions.log ledger, spool.db, inbox, .idle/.more-done sentinels, auth token); (2) the registry address (registry::unregister_address); (3) the context store — ContextStore::remove_endpoint(id): the a-<id> branch+worktree + the <id>/ rows from every p-<project> branch (the same fn `fork --delete-source` already uses); (4) node-local trust rows keyed on the id — access.json + visibility.json. Reuse-heavy: it is `fork --delete-source` generalized (recursive perch remove + unregister + remove_endpoint) + the trust-record cleanup; `endpoint rename` already enumerates the same record set + uses the same offline-only gate. (v0.12.0)
2026-07-11T01:39:54.0668847Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0669070Z 
2026-07-11T01:39:54.0669176Z ### REQ-READY-AGENT-RESUME
2026-07-11T01:39:54.0672663Z - Title: An offline ReadyAgent shows in `spt endpoint run`'s picker Resume-from-history and resumes correctly — closing the gap that today only LiveAgents do. ROOT: a harness-hosted ready bind (ReadyAgent::start_homed, ready.rs) writes info.json DIRECTLY and never appends the session ledger (unlike the shared establish_perch:250 live path), so a ready agent — though it has a session_id — produces ZERO ledger rows → the picker's offline+local Resume-from-history (which gates on ledger rows) never offers it. FIX (1): ledger the ready bind (ReadyAgent::start_homed → sessions::append Boot, mirroring establish_perch). FIX (2): `spt endpoint run --resume <session>` honors the adapter MANIFEST's endpoint TYPE — a ReadyAgent manifest (no [session.psyche_init]) resumes as a ready endpoint (poll listener, NO psyche-host); a LiveAgent (with psyche_init) as live. NO new bringup mode + NO picker changes (operator 2026-06-18): `spt endpoint run` is the spt-hosted ENDPOINT bringup for BOTH types, the type IS the adapter-manifest's concern (psyche-host already keys on psyche_init presence) — so (2) likely already holds; VERIFY at code, build only the residual. (v0.12.0)
2026-07-11T01:39:54.0675891Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0676054Z 
2026-07-11T01:39:54.0676153Z ### REQ-PICKER-ADAPTER-DESCRIPTION
2026-07-11T01:39:54.0677613Z - Title: The Create-new adapter-CHOICE screen of `spt endpoint run`'s picker shows a right-hand Description panel (like the Pick-existing endpoint picker's two-pane) surfacing per-adapter detail: install date, last-updated, adapter TYPE / the endpoint types it hosts, and the adapter description — so the user can see WHAT each adapter is before choosing it (today the selector lists bare names). DEFERRED fast-follow to v0.12.0 (operator 2026-06-18). (post-v0.12.0)
2026-07-11T01:39:54.0678931Z - Required stages: 
2026-07-11T01:39:54.0679136Z 
2026-07-11T01:39:54.0679240Z ### REQ-HAZARD-VIEWER-ISOLATION
2026-07-11T01:39:54.0681464Z - Title: A slow / dead / hostile VIEWER must NEVER stall the controller, the PTY child, or the session drain thread. The broker drain fans output to the controller on the authoritative blocking bounded path (advances delivered_through) but to each viewer via a bounded per-viewer channel with a dedicated writer thread; the drain `try_send`s under the log lock and a viewer whose bounded queue OVERFLOWS (can't keep up) is EVICTED (queue dropped, writer thread ends, removed from the viewers map) — the drain thread NEVER touches a viewer socket, so no viewer write can backpressure or block it. A soft viewer cap bounds the thread count. Viewer eviction never perturbs the controller stream, the delivered_through cursor, or the child.
2026-07-11T01:39:54.0683441Z - Required stages: unit, int
2026-07-11T01:39:54.0683584Z 
2026-07-11T01:39:54.0683680Z ### REQ-INSTALL-1
2026-07-11T01:39:54.0683952Z - Title: Two install paths; signed one-line script; OS-service registration
2026-07-11T01:39:54.0684276Z - Required stages: doc, impl, int
2026-07-11T01:39:54.0684428Z 
2026-07-11T01:39:54.0684514Z ### REQ-INSTALL-2
2026-07-11T01:39:54.0684729Z - Title: Marketplace-repackaging-friendly install
2026-07-11T01:39:54.0684986Z - Required stages: doc
2026-07-11T01:39:54.0685114Z 
2026-07-11T01:39:54.0685202Z ### REQ-INSTALL-3
2026-07-11T01:39:54.0685415Z - Title: Idempotent + interactive-optional first run
2026-07-11T01:39:54.0685677Z - Required stages: impl, int
2026-07-11T01:39:54.0685814Z 
2026-07-11T01:39:54.0685895Z ### REQ-INSTALL-4
2026-07-11T01:39:54.0686562Z - Title: Adapter registration lifecycle: spt adapter add (--github, manifest-first, install-is-first-update) + soft-deregister remove + optional manifest uninstall template; node-local registered-adapter set self-update ripples over
2026-07-11T01:39:54.0687286Z - Required stages: impl, unit
2026-07-11T01:39:54.0687434Z 
2026-07-11T01:39:54.0687520Z ### REQ-MIGRATE-1
2026-07-11T01:39:54.0687759Z - Title: Auto-detect and migrate a legacy claude_skill_owl install
2026-07-11T01:39:54.0688044Z - Required stages: 
2026-07-11T01:39:54.0688164Z 
2026-07-11T01:39:54.0688253Z ### REQ-INFRA-1
2026-07-11T01:39:54.0688498Z - Title: GitHub issue tracking for v1; tangled.org as migration target
2026-07-11T01:39:54.0688796Z - Required stages: 
2026-07-11T01:39:54.0688908Z 
2026-07-11T01:39:54.0689075Z ### REQ-INSTALL-5
2026-07-11T01:39:54.0689604Z - Title: Non-interactive install path: the canonical one-liner doubles as every adapter's pack-in on-demand install (no second mechanism); sha256-verified fetch; user-PATH registration
2026-07-11T01:39:54.0690186Z - Required stages: impl, int
2026-07-11T01:39:54.0690330Z 
2026-07-11T01:39:54.0690415Z ### REQ-INSTALL-9
2026-07-11T01:39:54.0691705Z - Title: Adapter add from a GitHub release archive: `spt adapter add --release <user/repo> [--tag <tag>] [--asset <name>]` fetches a `.spt` tar asset over HTTPS+GitHub trust, extracts it to the durable adapters/_github home, and registers the root — ships built binaries source-free and versioned (the distribution path for an adapter whose dev repo is a monorepo subdir, where --github root-only clone does not fit)
2026-07-11T01:39:54.0692972Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0693120Z 
2026-07-11T01:39:54.0693221Z ### REQ-INSTALL-10
2026-07-11T01:39:54.0694550Z - Title: Windows at-logon autostart runs the daemon in the background with no persistent window: the scheduled task launches `spt daemon start` (which spawn_detaches a console-less DETACHED_PROCESS daemon and exits) rather than the foreground `spt daemon run` — Task Scheduler's interactive ONLOGON launch of a long-lived console process otherwise leaves a visible console window for the daemon's whole lifetime (v0.7.4)
2026-07-11T01:39:54.0695737Z - Required stages: impl, unit
2026-07-11T01:39:54.0695885Z 
2026-07-11T01:39:54.0695970Z ### REQ-INSTALL-11
2026-07-11T01:39:54.0697808Z - Title: Adapter command templates resolve their program against the adapter's install dir BEFORE PATH: a `.spt`-shipped binary (dropped to adapters/_github/<safe>/ by --release/--github acquisition, or kept in the source_dir under copy-mode where only manifest+strings/ are copied to adapters/<name>) runs without any PATH placement — a bare-name template token (e.g. `claude-spt-digest ...`) is rewritten to <install_dir>/<program>(.exe on Windows) when that file exists, else left bare for the PATH fallback. Makes a `.spt` self-contained (closes the --release bundled-binary gap perri confirmed) (v0.7.4)
2026-07-11T01:39:54.0699630Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0699778Z 
2026-07-11T01:39:54.0699873Z ### REQ-INSTALL-12
2026-07-11T01:39:54.0702508Z - Title: Durable active-profile pointer for bind-time profile selection (ADR-0021): adapters/active-profiles.toml at the registry ROOT (sibling to the per-adapter <name>/ dirs, so adapter add/update/remove — which only rewrite a <name>/ subdir — can never clobber it), a flat host_binary → "adapter[:profile]" map. Read at bind as the PRIMARY profile selector; unset → the registered_at_ms fallback (REQ-START-5). Written ONLY by `spt adapter use <adapter>[:profile]` (resolves the adapter's host_binaries → sets each binary→adapter[:profile]); `spt adapter use --clear <adapter|binary>` drops. NEVER auto-written by install/update/adapter add (that is precisely what would let an update silently flip the active profile). A stale pointer (uninstalled adapter / deleted profile) self-heals: ignored, fall back, warn once. Pruned on adapter remove. Atomic write (spt_store atomic). (v0.9.0)
2026-07-11T01:39:54.0704820Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0704985Z 
2026-07-11T01:39:54.0705077Z ### REQ-INSTALL-13
2026-07-11T01:39:54.0707940Z - Title: Adapter add is non-destructive & idempotent-safe (F-018): `spt adapter add --github|--release` REFUSES when the target `_github/<safe>` home already backs an ACTIVE registered record — emitting an actionable code (ADAPTER_ADD_ALREADY_REGISTERED) that routes to `spt adapter update <name>` (refresh in place) or `spt adapter remove <name>` then re-add (replace) — instead of clobbering the live install (the perri footgun: `add --github` over a `--release` pointer git-cloned a source tree over the extracted built binaries → registered pointer dangled → cryptic `os error 2`). And when it DOES (re)populate the home it STAGES-THEN-SWAPS (clone/extract to a sibling staging dir, swap into place only on success) so a failed fetch/clone never strands the previously-extracted manifest+binaries as a dangling pointer (the os-2 / DeferredManifest class). Mirrors the safe stage-then-swap `adapter update` already uses (REQ-UPD-9, apply_release_crc_swap). (v0.14.1)
2026-07-11T01:39:54.0710516Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0710677Z 
2026-07-11T01:39:54.0710763Z ### REQ-REL-1
2026-07-11T01:39:54.0711193Z - Title: spt-releases publish-target repo: README public face, licensing split, Pages docs at the permanent lapse-proof canonical URL (ADR-0014)
2026-07-11T01:39:54.0711784Z - Required stages: doc, impl
2026-07-11T01:39:54.0711921Z 
2026-07-11T01:39:54.0712012Z ### REQ-REL-2
2026-07-11T01:39:54.0712530Z - Title: Release asset set consumable by the self-updater: platform binaries, SHA256SUMS, SignedRelease metadata, manifest schema, mock-adapter zip; tag-triggered cross-repo pipeline
2026-07-11T01:39:54.0713116Z - Required stages: impl, int
2026-07-11T01:39:54.0713257Z 
2026-07-11T01:39:54.0713339Z ### REQ-REL-3
2026-07-11T01:39:54.0713811Z - Title: Two-key release-signing trust anchor: primary + offline never-used recovery, both pubkeys embedded in the binary's trusted set, manual local signing (ADR-0015)
2026-07-11T01:39:54.0714370Z - Required stages: impl, unit
2026-07-11T01:39:54.0714507Z 
2026-07-11T01:39:54.0714593Z ### REQ-DOCS-1
2026-07-11T01:39:54.0714855Z - Title: Dual-audience docs (human + AI dev-agent), markdown once / two depths
2026-07-11T01:39:54.0715164Z - Required stages: doc, impl
2026-07-11T01:39:54.0715370Z 
2026-07-11T01:39:54.0715455Z ### REQ-DOCS-2
2026-07-11T01:39:54.0715675Z - Title: Sub-10-minute runnable killer quickstart per audience
2026-07-11T01:39:54.0715957Z - Required stages: doc, int
2026-07-11T01:39:54.0716085Z 
2026-07-11T01:39:54.0716175Z ### REQ-DOCS-3
2026-07-11T01:39:54.0716423Z - Title: Diátaxis structure; one canonical way to do X
2026-07-11T01:39:54.0716733Z - Required stages: doc
2026-07-11T01:39:54.0716853Z 
2026-07-11T01:39:54.0716939Z ### REQ-DOCS-4
2026-07-11T01:39:54.0717182Z - Title: Agent-consumable layer (llms.txt, manifest schema, MCP, CLI help)
2026-07-11T01:39:54.0717490Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0717641Z 
2026-07-11T01:39:54.0717717Z ### REQ-DOCS-5
2026-07-11T01:39:54.0717970Z - Title: Anti-drift: rustdoc/schema/exports/CLI-help generated + CI-checked
2026-07-11T01:39:54.0718280Z - Required stages: impl, int
2026-07-11T01:39:54.0718412Z 
2026-07-11T01:39:54.0718514Z ### REQ-HAZARD-GRACE-BEFORE-SIGNOFF
2026-07-11T01:39:54.0718815Z - Title: Grace-period wait completes before composing INIT_SIGNOFF (1.1)
2026-07-11T01:39:54.0719195Z - Required stages: impl, unit
2026-07-11T01:39:54.0719352Z 
2026-07-11T01:39:54.0719463Z ### REQ-HAZARD-INFO-JSON-TORN-READ
2026-07-11T01:39:54.0719720Z - Title: State-file reads tolerate concurrent writes (1.2)
2026-07-11T01:39:54.0719987Z - Required stages: impl, unit
2026-07-11T01:39:54.0720126Z 
2026-07-11T01:39:54.0720224Z ### REQ-HAZARD-STALE-INDEX-LOCK
2026-07-11T01:39:54.0720467Z - Title: Sweep stale lockfiles on daemon boot (1.3)
2026-07-11T01:39:54.0720717Z - Required stages: impl, unit
2026-07-11T01:39:54.0720861Z 
2026-07-11T01:39:54.0720960Z ### REQ-HAZARD-DEFERRED-DRAIN
2026-07-11T01:39:54.0721237Z - Title: Deferred spool rows excluded from the event-stream drain (1.4)
2026-07-11T01:39:54.0721538Z - Required stages: impl, unit
2026-07-11T01:39:54.0721666Z 
2026-07-11T01:39:54.0721767Z ### REQ-HAZARD-WORKER-PATH
2026-07-11T01:39:54.0722029Z - Title: Single source of truth for Worker/Psyche perch location (1.5)
2026-07-11T01:39:54.0722340Z - Required stages: impl, unit
2026-07-11T01:39:54.0722472Z 
2026-07-11T01:39:54.0722577Z ### REQ-HAZARD-PARENT-PID-PREFER
2026-07-11T01:39:54.0722872Z - Title: Prefer stable parent PID / broker handle over ephemeral PID (2.1)
2026-07-11T01:39:54.0723155Z - Required stages: 
2026-07-11T01:39:54.0723317Z 
2026-07-11T01:39:54.0723419Z ### REQ-HAZARD-STDIN-SESSION-ID
2026-07-11T01:39:54.0723652Z - Title: Stdin session_id precedence over env (2.2)
2026-07-11T01:39:54.0723899Z - Required stages: 
2026-07-11T01:39:54.0724009Z 
2026-07-11T01:39:54.0724109Z ### REQ-HAZARD-HANDOFF-ARGV-COMPAT
2026-07-11T01:39:54.0724376Z - Title: Broker/brain IPC + handoff argv version-tolerant (2.3)
2026-07-11T01:39:54.0724681Z - Required stages: impl, unit
2026-07-11T01:39:54.0724815Z 
2026-07-11T01:39:54.0724911Z ### REQ-HAZARD-GEN-START-NOW
2026-07-11T01:39:54.0725149Z - Title: gen_start = now() on cold-start and handoff (2.4)
2026-07-11T01:39:54.0725406Z - Required stages: impl, int
2026-07-11T01:39:54.0725649Z 
2026-07-11T01:39:54.0725753Z ### REQ-HAZARD-EPHEMERAL-CLEANUP
2026-07-11T01:39:54.0726015Z - Title: Ephemeral perch cleanup on every ring exit path (3.1)
2026-07-11T01:39:54.0726288Z - Required stages: impl, unit
2026-07-11T01:39:54.0726420Z 
2026-07-11T01:39:54.0726527Z ### REQ-HAZARD-STALE-SIGNOFF-SENTINEL
2026-07-11T01:39:54.0726798Z - Title: Stale signoff sentinel does not kill a fresh start (3.2)
2026-07-11T01:39:54.0727069Z - Required stages: impl, unit
2026-07-11T01:39:54.0727203Z 
2026-07-11T01:39:54.0727303Z ### REQ-HAZARD-ECHO-BEFORE-SIGNOFF
2026-07-11T01:39:54.0727588Z - Title: Echo-commune fires before INIT_SIGNOFF on orphan teardown (3.3)
2026-07-11T01:39:54.0727893Z - Required stages: impl, unit
2026-07-11T01:39:54.0728031Z 
2026-07-11T01:39:54.0728132Z ### REQ-HAZARD-ENVELOPE-DECODE-ORDER
2026-07-11T01:39:54.0728391Z - Title: Envelope decode order, ampersand decoded last (4.1)
2026-07-11T01:39:54.0728653Z - Required stages: impl, unit
2026-07-11T01:39:54.0728850Z 
2026-07-11T01:39:54.0729060Z ### REQ-HAZARD-ENVELOPE-CR-LINESAFE
2026-07-11T01:39:54.0730888Z - Title: Envelope CR-linesafety (4.1): the line-framed EVENT codec must neutralize raw carriage returns — `event_body_escape` folds CRLF/lone-CR to the codec's representable linebreak (`\n`→`<br>`) BEFORE framing, so a body carrying `\r` (Windows `echo`/CRLF text crossing nodes) cannot survive into the single-line envelope and trigger a receiver terminal CR→col0 overwrite that corrupts the frame. Robustness on unrepresentable input, NOT a wire-format change (decoder untouched, amp-last invariant held). Belt-and-suspenders: `spt send`/`ring` also trim stdin (parity with `notify`).
2026-07-11T01:39:54.0732517Z - Required stages: impl, unit
2026-07-11T01:39:54.0732661Z 
2026-07-11T01:39:54.0732765Z ### REQ-HAZARD-ENVELOPE-PARSER-SAFE
2026-07-11T01:39:54.0733041Z - Title: Two-slice envelope parser is panic-free and tolerant (4.2)
2026-07-11T01:39:54.0733337Z - Required stages: impl, unit
2026-07-11T01:39:54.0733479Z 
2026-07-11T01:39:54.0733589Z ### REQ-HAZARD-EVENTPART-REASSEMBLY
2026-07-11T01:39:54.0733902Z - Title: EVENT-PART split/reassembly is byte-exact; orphan parts dropped silently
2026-07-11T01:39:54.0734227Z - Required stages: impl, unit
2026-07-11T01:39:54.0734354Z 
2026-07-11T01:39:54.0734449Z ### REQ-HAZARD-ID-CHARSET
2026-07-11T01:39:54.0734769Z - Title: Addressable-id charset reserves :/@ delimiters; validated at every creation seam (4.6)
2026-07-11T01:39:54.0735142Z - Required stages: impl, unit
2026-07-11T01:39:54.0735289Z 
2026-07-11T01:39:54.0735389Z ### REQ-HAZARD-REGISTRY-STALE-CLEAN
2026-07-11T01:39:54.0735675Z - Title: Stale registry entries degrade to fallback, never hard-fail (4.3)
2026-07-11T01:39:54.0735980Z - Required stages: impl, unit
2026-07-11T01:39:54.0736120Z 
2026-07-11T01:39:54.0736228Z ### REQ-HAZARD-REGISTRY-CONCURRENT
2026-07-11T01:39:54.0736575Z - Title: Concurrent SQLite openers (registry/spool) must not fail with 'database is locked' (4.7)
2026-07-11T01:39:54.0736947Z - Required stages: impl, unit
2026-07-11T01:39:54.0737101Z 
2026-07-11T01:39:54.0737210Z ### REQ-HAZARD-REGISTRY-DIR-CREATE
2026-07-11T01:39:54.0737678Z - Title: SQLite store opens create their parent dir themselves — a fresh-home registry op must not SQLITE_CANTOPEN (4.9)
2026-07-11T01:39:54.0738097Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0738254Z 
2026-07-11T01:39:54.0738351Z ### REQ-HAZARD-REGISTRY-EPOCH-LEASE
2026-07-11T01:39:54.0738880Z - Title: Registry merge ordered by per-node monotonic epoch, never wall-clock — a stale Active can't clobber a newer Offline (4.8, red-team #8)
2026-07-11T01:39:54.0739447Z - Required stages: impl, unit
2026-07-11T01:39:54.0739595Z 
2026-07-11T01:39:54.0739700Z ### REQ-HAZARD-DEFERRED-SURVIVE-DRAIN
2026-07-11T01:39:54.0739959Z - Title: Deferred rows survive poll drain (4.4)
2026-07-11T01:39:54.0740210Z - Required stages: impl, unit
2026-07-11T01:39:54.0740397Z 
2026-07-11T01:39:54.0740501Z ### REQ-HAZARD-INBOX-NO-DOUBLE
2026-07-11T01:39:54.0740840Z - Title: No double-delivery via legacy inbox (4.5)
2026-07-11T01:39:54.0741092Z - Required stages: impl, unit
2026-07-11T01:39:54.0741227Z 
2026-07-11T01:39:54.0741330Z ### REQ-HAZARD-WINDOWS-PID-RECYCLE
2026-07-11T01:39:54.0741592Z - Title: Windows PID-recycling false positives guarded (5.1)
2026-07-11T01:39:54.0741857Z - Required stages: impl, unit
2026-07-11T01:39:54.0741995Z 
2026-07-11T01:39:54.0742090Z ### REQ-HAZARD-EBUSY-RENAME
2026-07-11T01:39:54.0742343Z - Title: tmp-write + atomic-rename + retry on Windows EBUSY (5.2)
2026-07-11T01:39:54.0742620Z - Required stages: impl, unit
2026-07-11T01:39:54.0742758Z 
2026-07-11T01:39:54.0742863Z ### REQ-HAZARD-PERCH-RECORD-POWER-LOSS
2026-07-11T01:39:54.0743488Z - Title: Authoritative/identity records fsync data before the rename (5.13): a hard reset must not resurrect a full-length NUL-filled record — SCOPED, not a blanket fsync
2026-07-11T01:39:54.0744020Z - Required stages: impl, unit
2026-07-11T01:39:54.0744154Z 
2026-07-11T01:39:54.0744257Z ### REQ-HAZARD-ATOMIC-TMP-COLLISION
2026-07-11T01:39:54.0744863Z - Title: Concurrent atomic writers to the same target must not share a tmp name (5.15): a fixed tmp sibling makes one writer's rename consume the other's staged file (os-error-2 loser)
2026-07-11T01:39:54.0745416Z - Required stages: impl, unit
2026-07-11T01:39:54.0745558Z 
2026-07-11T01:39:54.0745658Z ### REQ-HAZARD-INFO-RMW-LOST-UPDATE
2026-07-11T01:39:54.0746207Z - Title: Concurrent info.json writers must serialize under the per-perch lock (5.16): an unlocked whole-record write racing a locked RMW is a silent lost update
2026-07-11T01:39:54.0746713Z - Required stages: impl, unit
2026-07-11T01:39:54.0746859Z 
2026-07-11T01:39:54.0746964Z ### REQ-HAZARD-CORRUPT-PERCH-COHERENCE
2026-07-11T01:39:54.0747479Z - Title: Corrupt (present-but-unparseable) info.json is NOT absent: liveness/status readers agree a destroyed record is neither alive nor Active (counter-39 #2)
2026-07-11T01:39:54.0748004Z - Required stages: impl, unit
2026-07-11T01:39:54.0748155Z 
2026-07-11T01:39:54.0748314Z ### REQ-HAZARD-SUBPROCESS-TIMEOUT
2026-07-11T01:39:54.0748562Z - Title: Every harness/git subprocess has a timeout (5.3)
2026-07-11T01:39:54.0748824Z - Required stages: impl, unit
2026-07-11T01:39:54.0749359Z 
2026-07-11T01:39:54.0749574Z ### REQ-HAZARD-UNC-PATH-STRIP
2026-07-11T01:39:54.0750035Z - Title: Strip Windows UNC prefix on serialized paths (5.4)
2026-07-11T01:39:54.0753752Z - Required stages: impl, unit
2026-07-11T01:39:54.0753914Z 
2026-07-11T01:39:54.0754025Z ### REQ-HAZARD-SINGLE-PATH-SOURCE
2026-07-11T01:39:54.0754335Z - Title: Single path/registry source of truth; no layout ambiguity (6.1)
2026-07-11T01:39:54.0754642Z - Required stages: impl, unit
2026-07-11T01:39:54.0754784Z 
2026-07-11T01:39:54.0754887Z ### REQ-HAZARD-SOFT-CLEANUP
2026-07-11T01:39:54.0755169Z - Title: Soft-cleanup preserves state, removes only the ready marker (6.2)
2026-07-11T01:39:54.0755479Z - Required stages: impl, unit
2026-07-11T01:39:54.0755624Z 
2026-07-11T01:39:54.0755723Z ### REQ-HAZARD-CASCADE-WIPE-GUARD
2026-07-11T01:39:54.0756019Z - Title: No hard-delete of a parent hosting non-empty children (6.3)
2026-07-11T01:39:54.0756305Z - Required stages: impl, unit
2026-07-11T01:39:54.0756447Z 
2026-07-11T01:39:54.0756553Z ### REQ-HAZARD-DROP-FILE-SINGLE-WRITER
2026-07-11T01:39:54.0756849Z - Title: Drop files are daemon-owned single-writer (6.4)
2026-07-11T01:39:54.0757115Z - Required stages: impl, unit
2026-07-11T01:39:54.0757249Z 
2026-07-11T01:39:54.0757357Z ### REQ-HAZARD-DIRECT-WRITE-PRECEDENCE
2026-07-11T01:39:54.0757686Z - Title: Direct-write precedence marker (with node id) guards stale overwrite (6.5)
2026-07-11T01:39:54.0758025Z - Required stages: impl, unit
2026-07-11T01:39:54.0758159Z 
2026-07-11T01:39:54.0758268Z ### REQ-HAZARD-CONFLICT-BOTH-PRESERVED
2026-07-11T01:39:54.0758917Z - Title: A surfaced concurrent context pair is durably preserved (both versions, tracked artifacts) until a strictly dominating write clears it; no reconcile failure path discards an unmerged version (6.6, ADR-0013)
2026-07-11T01:39:54.0759836Z - Required stages: impl, unit
2026-07-11T01:39:54.0759976Z 
2026-07-11T01:39:54.0760082Z ### REQ-HAZARD-DETACHED-PIPE-INHERIT
2026-07-11T01:39:54.0761321Z - Title: Windows detached long-lived children must not inherit a captured caller's pipe: every detach-spawn of an immortal child (daemon, shell binary) runs bInheritHandles=FALSE, or a caller capturing output anywhere up the process chain hangs forever on a pipe that never EOFs — std-handle flag stripping is NOT sufficient (grandparent strays still flow) (5.6)
2026-07-11T01:39:54.0762423Z - Required stages: impl, unit
2026-07-11T01:39:54.0762560Z 
2026-07-11T01:39:54.0762660Z ### REQ-HAZARD-CONPTY-DSR
2026-07-11T01:39:54.0762958Z - Title: ConPTY reader must auto-answer DSR (ESC[6n) or all child output stalls (5.5)
2026-07-11T01:39:54.0763292Z - Required stages: impl, unit
2026-07-11T01:39:54.0763440Z 
2026-07-11T01:39:54.0763544Z ### REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE
2026-07-11T01:39:54.0765452Z - Title: Native-PTY spawn must resolve a bare program name with PATHEXT precedence and run a non-PE target through its interpreter: portable-pty's own `which` takes the FIRST PATH match — an extensionless shebang shim (e.g. a node CLI `ccs` shipped beside `ccs.cmd`) — and CreateProcessW then rejects the non-PE file with os error 193 ('not a valid Win32 application'); spt-term resolves the program itself (PATHEXT order prefers .EXE over .CMD; .cmd/.bat → cmd.exe /d /c, .ps1 → powershell -NoProfile -File) so a bare harness/shell [session.self] command actually launches on Windows. Unix is a passthrough (execve honours the shebang).
2026-07-11T01:39:54.0767246Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0767404Z 
2026-07-11T01:39:54.0767509Z ### REQ-HAZARD-CHILD-CONSOLE-FLASH
2026-07-11T01:39:54.0768026Z - Title: Console-subsystem children of the console-less daemon spawn with CREATE_NO_WINDOW, or each spawn flashes a visible blank window on the user's desktop (5.8)
2026-07-11T01:39:54.0768561Z - Required stages: impl, unit
2026-07-11T01:39:54.0768714Z 
2026-07-11T01:39:54.0768814Z ### REQ-HAZARD-INSTANT-UNDERFLOW
2026-07-11T01:39:54.0769553Z - Title: Scheduling never subtracts a Duration from Instant::now() (underflow-panics on a host booted more recently than the offset); 'due now / never run' is Option<Instant>=None gated on forward duration_since only (5.9)
2026-07-11T01:39:54.0770195Z - Required stages: impl, unit
2026-07-11T01:39:54.0770367Z 
2026-07-11T01:39:54.0770466Z ### REQ-HAZARD-PUMP-IPC-DEADLINE
2026-07-11T01:39:54.0771362Z - Title: The single-threaded peer pump's brain-IPC reads are deadline-bounded (PUMP_PEER_IO_TIMEOUT, total-wait per call); a TimedOut read POISONS the client and escalates to a SUPERVISED RESTART, never a per-peer retry — a black-holed peer must never wedge the whole pump
2026-07-11T01:39:54.0772157Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0772307Z 
2026-07-11T01:39:54.0772410Z ### REQ-HAZARD-BROKER-QUIC-DEADLINE
2026-07-11T01:39:54.0775498Z - Title: The broker bounds every brain-waiting QUIC op (dial / open_stream / send_stream) so a black-holed or dead peer fails PROMPTLY with an ORDINARY error the broker REPLIES, never an unbounded await. The bound (< the brain's 30s PUMP_PEER_IO_TIMEOUT so the BROKER fires first) surfaces to the pump as a normal broker error reply → peer_outcome's non-TimedOut arm → drop conn + redial next tick, the round CONTINUES and the heartbeat keeps advancing — it must NEVER manifest as the brain's own read-deadline (the A-half poison → supervised-restart path REQ-HAZARD-PUMP-IPC-DEADLINE guards). Exactly-once is preserved: a timed-out journaled op fails INSIDE its apply_once closure so no phantom conn_id/stream_id is recorded and a fresh tick re-dials cleanly. The happy path is unchanged (a live peer completes with zero added latency; the bound only bites a non-responsive peer). This is the ROOT-cause cure for the 2.2h hfenduleam pump wedge — a dead roster peer whose QUIC path the broker awaited unbounded — recurring on hfenduleam 2026-06-16.
2026-07-11T01:39:54.0775739Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0775772Z 
2026-07-11T01:39:54.0775876Z ### REQ-HAZARD-BROKER-SEED-WIRE-SKEW
2026-07-11T01:39:54.0779488Z - Title: A daemon-state wire-format change (e.g. the v0.9.0 adapter-agnostic Seed) does NOT take effect until a DELIBERATE full broker restart: the broker serves the seed-control channel and is RESIDENT across a brain-only self-update (ADR-0004 no-terminate-during-update forbids auto-killing it), so a NEW-version CLI talking to a still-resident OLD broker fails the seed handshake — the old broker cannot deserialize the new Seed (its formerly-required `adapter` field is gone) and drops the conn without an ack, which surfaces to the CLI as a raw UnexpectedEof 'failed to fill whole buffer'. spt-core must (a) surface an ACTIONABLE diagnostic on that seed-ack EOF (name the stale-broker cause + the `spt daemon stop` fix — the broker restarts on the next api call), never the cryptic io error; and (b) document the operational rule (a deliberate broker restart is required on any daemon-state wire change — NOT automatic) + the FORWARD discipline (daemon-state/Seed schema changes stay additive + serde-default so a resident OLD broker tolerates a NEW CLI across a brain-only update; note this would NOT have rescued 0.9.0 itself, since the old broker's `adapter` was a required field). perri PREP-4 FINDING 1 (v0.9.0 CLI vs stale 0.8.x broker).
2026-07-11T01:39:54.0779708Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0779736Z 
2026-07-11T01:39:54.0779845Z ### REQ-HAZARD-SUDO-SECURE-PATH
2026-07-11T01:39:54.0780657Z - Title: Elevation guidance on Unix names the binary's ABSOLUTE path under sudo (a user-local install ~/.local/bin · ~/.cargo/bin is not on sudo's secure_path, so bare `sudo spt` dies 'command not found'); gated commands auto-elevate on an interactive TTY, else print the runnable hint (5.10)
2026-07-11T01:39:54.0780760Z - Required stages: impl, unit
2026-07-11T01:39:54.0780784Z 
2026-07-11T01:39:54.0780884Z ### REQ-HAZARD-SELF-ELEVATE
2026-07-11T01:39:54.0783004Z - Title: Self-elevation (REQ-ELEVATE-1) re-runs the EXACT original invocation with the binary's ABSOLUTE exe path — never widening privilege scope, never adding/altering args, never via a PATH-resolved bare name, never via a shell-interpolated command string (argv-array only, no `sh -c`); the elevated child drops state back to the user (composes with the 5.7 de-elevation) and NEVER re-elevates (loop-safe: decide_elevation_path returns AlreadyElevated whenever the process is already Elevated, on every OS). The user's UAC/polkit/sudo prompt is the only consent gate — we never bypass it; the print-hint floor prints the absolute-path command too. The unprivileged parent never depends on (pipes/captures) the privileged child's stdout.
2026-07-11T01:39:54.0783125Z - Required stages: unit
2026-07-11T01:39:54.0783153Z 
2026-07-11T01:39:54.0783256Z ### REQ-HAZARD-LOCAL-API-AUTH
2026-07-11T01:39:54.0783449Z - Title: Every local `api` mutation authenticated to an endpoint/session (codex #13)
2026-07-11T01:39:54.0783553Z - Required stages: impl, unit
2026-07-11T01:39:54.0783581Z 
2026-07-11T01:39:54.0783684Z ### REQ-BOUNDARY-ROTATION-CREDENTIAL
2026-07-11T01:39:54.0785013Z - Title: api boundary's rotation credential is designed, documented, and eventually anchor-proven (ADR-0032): the proof is the DEPARTED session's (prior sid / token) — --to-session-id is payload, never proof; the published surface documents the adapter prior-sid persistence pattern + loud-refusal requirement; the design-true end-state additionally accepts an OS-verified parent_pid-anchor ancestry proof making adapter sid-state optional
2026-07-11T01:39:54.0785114Z - Required stages: doc
2026-07-11T01:39:54.0785142Z 
2026-07-11T01:39:54.0785241Z ### REQ-HAZARD-RESTART-IDEMPOTENT
2026-07-11T01:39:54.0785480Z - Title: Idempotent/exactly-once delivery across brain restart at every broker boundary (codex #14)
2026-07-11T01:39:54.0785575Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0785604Z 
2026-07-11T01:39:54.0785809Z ### REQ-HAZARD-UPDATE-ROLLBACK
2026-07-11T01:39:54.0786044Z - Title: Self-update rejects version rollback; metadata expiry + adapter content signing (codex #5)
2026-07-11T01:39:54.0786142Z - Required stages: impl, unit
2026-07-11T01:39:54.0786171Z 
2026-07-11T01:39:54.0786274Z ### REQ-HAZARD-DAEMON-HOSTED-LIVENESS
2026-07-11T01:39:54.0786669Z - Title: Daemon-hosted perches (Psyche, spt-hosted Self) derive liveness from the daemon endpoint table + info.json status, never is_process_alive(info.pid) (2.5)
2026-07-11T01:39:54.0786770Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0786798Z 
2026-07-11T01:39:54.0786902Z ### REQ-HAZARD-BROKER-PROCESS-ISOLATION
2026-07-11T01:39:54.0789543Z - Title: Broker and brain are separate processes: the broker runs as its own long-lived per-machine process that survives every brain restart, so a routine (brain-only) self-update restarts the brain onto the swapped binary while every hosted endpoint (PTY child, live QUIC conn, listening socket) stays untouched at the PROCESS level. The in-process-thread broker (daemon.rs:165-170) is a regression that silently unrealizes REQ-UPD-3 — apply degrades to an in-process Brain::handoff no-op and new code does not run until an unrelated restart (KNOWN-HAZARDS 6.7). Evidence must prove process-level survival (SPIKE-01/03 productionized as int: PTY child + live QUIC survive a brain-PROCESS restart onto a swapped binary), re-pointing the regression-masked in-process int tags currently on REQ-DAEMON-2 / REQ-UPD-3 (ADR-0018).
2026-07-11T01:39:54.0789762Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0789790Z 
2026-07-11T01:39:54.0789892Z ### REQ-HAZARD-ROLLBACK-STATE-COMPAT
2026-07-11T01:39:54.0791525Z - Title: A brain must not irreversibly migrate durable state before update ready-promotion: the readiness-gated auto-rollback (ADR-0018 Q7) spawns the N-1 binary against durable state the new brain may have written, so every pre-ready write must stay N-1-readable (schema migrations gated behind ready-promotion, or written N-1-tolerant/additive). Else the first in-place schema migration silently bricks rollback (KNOWN-HAZARDS 6.8). Free now — a 2026-06-09 audit confirmed zero state-migration code exists; unmintable retroactively once a migration ships.
2026-07-11T01:39:54.0791638Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0791666Z 
2026-07-11T01:39:54.0791766Z ### REQ-HAZARD-BRAIN-RESPAWN-PATH
2026-07-11T01:39:54.0794103Z - Title: The broker respawns the brain onto the APPLIED bytes, not the renamed old binary: the candidate-binary default is the canonical exe path captured ONCE at broker start, never a per-spawn std::env::current_exe() — on Linux current_exe (readlink /proc/self/exe) is inode-tracking and follows the `apply` rename (spt -> spt.old-N), so a resident broker would respawn the brain onto OLD bytes while recording `applied` (Windows GetModuleFileName is path-at-start, so Windows was green; ADR-0018 Q3 silently assumed path-string semantics). Backstop: promotion gates on bytes — a trial promotes only if brain.ready exe_hash == the staged artifact hash for this platform, else auto-rollback + loud notif (readiness != new-bytes was the false-success that recorded applied:8 over a v0.4.0 brain on kitsubito, 2026-06-11). KNOWN-HAZARDS 6.11.
2026-07-11T01:39:54.0794216Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0794244Z 
2026-07-11T01:39:54.0794341Z ### REQ-HAZARD-PSYCHE-OUTBOUND-PROXY
2026-07-11T01:39:54.0795120Z - Title: Psyche outbound captured + sanitized: the live-Psyche turn driver captures stdout (never Stdio::null), and the daemon strips/re-stamps Psyche-supplied from=/target and constrains routing (reply→__REPLY_TO__ sender, notify→own user/subnet) (7.3)
2026-07-11T01:39:54.0795219Z - Required stages: impl, unit
2026-07-11T01:39:54.0795244Z 
2026-07-11T01:39:54.0795350Z ### REQ-HAZARD-DAEMON-SCHED-NONBLOCKING
2026-07-11T01:39:54.0795955Z - Title: Per-agent pulse/psyche/echo-commune scheduling must not serialize across agents: each agent's bounded LLM call (echo-commune summarizer, Psyche turn) runs off the shared scheduler so one slow/hung call cannot stall another agent's tick (7.4)
2026-07-11T01:39:54.0796149Z - Required stages: impl, unit
2026-07-11T01:39:54.0796178Z 
2026-07-11T01:39:54.0796284Z ### REQ-HAZARD-PAIR-TRANSCRIPT-BIND
2026-07-11T01:39:54.0796902Z - Title: Pairing transcript binds roles, both node pubkeys, subnet ID, seed epoch, TOTP time-step, and confirmation MACs — or unknown-key-share/reflection/wrong-subnet/replay pairing remain possible (ADR-0005 #12)
2026-07-11T01:39:54.0797011Z - Required stages: impl, unit
2026-07-11T01:39:54.0797039Z 
2026-07-11T01:39:54.0797143Z ### REQ-HAZARD-PAIR-SEED-ROTATION
2026-07-11T01:39:54.0797625Z - Title: Removing a node rotates the subnet seed (epoch bump) so an old node/old seed cannot rejoin; trust-store delete alone is NOT revocation because the seed is replicated to every trusted node (ADR-0005 #10)
2026-07-11T01:39:54.0797719Z - Required stages: impl, unit
2026-07-11T01:39:54.0797748Z 
2026-07-11T01:39:54.0797844Z ### REQ-HAZARD-PAIR-RATE-LIMIT
2026-07-11T01:39:54.0798711Z - Title: Subnet-global pairing rate limit: one active ceremony per subnet, shared attempt counter, exponential backoff — a public pre-trust relay + multiple seed-holders otherwise enables distributed SPAKE2 guessing (and ±1 TOTP window triples the valid-password space) (ADR-0005 #11)
2026-07-11T01:39:54.0798813Z - Required stages: impl, unit
2026-07-11T01:39:54.0798884Z 
2026-07-11T01:39:54.0799055Z ### REQ-HAZARD-WAN-ORIGIN-AUTH
2026-07-11T01:39:54.0799832Z - Title: WAN-inbound origin is transport truth, never payload: the access gate's subject (ADR-0009 origin-node whitelist) is the QUIC handshake-proven remote node id from the broker's conn/stream table — a forged origin/node field inside record bytes is inert (7.5)
2026-07-11T01:39:54.0799931Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0799960Z 
2026-07-11T01:39:54.0800045Z ### REQ-CONSENT-1
2026-07-11T01:39:54.0800885Z - Title: Consent grant store: capability x subject-agent x target-node rows, enforced at the target node, subnet-settable (replicates as security material near the trust store), revocable; gated-capability ids (remote-exec, instantiate-anywhere) reserved-but-refusing; v1 consumers are the shell spawn gates (CONTEXT Consent & security gates)
2026-07-11T01:39:54.0800989Z - Required stages: impl, unit
2026-07-11T01:39:54.0801019Z 
2026-07-11T01:39:54.0801110Z ### REQ-CONSENT-2
2026-07-11T01:39:54.0801867Z - Title: Interactive consent escalation: an ungated high-risk action routes a consent prompt to the user's most-recently-active session; allow-once / allow-always (writes a grant) / deny; pre-consent flags (can_shutdown, shell_wake_spawn_anywhere) author grants via manifest/settings (CONTEXT Consent & security gates)
2026-07-11T01:39:54.0801966Z - Required stages: impl, unit
2026-07-11T01:39:54.0801990Z 
2026-07-11T01:39:54.0802080Z ### REQ-PRES-1
2026-07-11T01:39:54.0803390Z - Title: Presence resolution: the presence datum (last_active_node, last_active_endpoint, ts) gossiped subnet-wide via the agent-interaction heartbeat (rides registry distribution, visibility-gated) + one first-class most-recently-active resolution API consumed by notif first-fire, update-consent delivery, consent escalation, and shell wake resolution (M5 scope decision 1: resolution only — the PresenceChannel endpoint stays deferred)
2026-07-11T01:39:54.0803504Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0803532Z 
2026-07-11T01:39:54.0803625Z ### REQ-SHELL-1
2026-07-11T01:39:54.0804439Z - Title: Shell hosting machinery: shell perch under the owner (type/owner/adapter_name/status/alias), broker-launched binary + api bind local-link handshake, the three channels (command durable, text+file durable + progress-queryable, sensory REST-only never spooled + dropped-unless-owner-live), owner exclusivity (CONTEXT Shell model)
2026-07-11T01:39:54.0804540Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0804564Z 
2026-07-11T01:39:54.0804649Z ### REQ-SHELL-2
2026-07-11T01:39:54.0806066Z - Title: Shell sleep/wake: link-break always closes the binary (pre-close instruction + termination timeout), ephemeral teardown vs persistent offline/relink, wake_command wake-watcher (offline-only, exit-opcode supervision, exponential backoff + give-up), state-keyed wake resolution (dormant/suspended/active-elsewhere; no-reachable refuses — spawn-anywhere branch deferred), spt shutdown owner cascade + api owner-shutdown gated by can_shutdown (CONTEXT Shell sleep/wake)
2026-07-11T01:39:54.0806304Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0806329Z 
2026-07-11T01:39:54.0806429Z ### REQ-HAZARD-ELEVATED-DAEMON-SPAWN
2026-07-11T01:39:54.0807698Z - Title: The daemon always runs unelevated in the invoking user's universe, regardless of which command spawns it: an elevated spawner de-elevates (Windows: UAC linked token via CreateProcessWithTokenW; Linux: drop to SUDO_UID/SUDO_GID + the invoker's HOME) — an elevated daemon's pipes deny unelevated clients (every later spt reads not-running→spawn→bind Access-denied) and a sudo'd daemon roots the user's state universe (5.7)
2026-07-11T01:39:54.0807861Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0807890Z 
2026-07-11T01:39:54.0807989Z ### REQ-HAZARD-REGISTRY-GHOST-ROWS
2026-07-11T01:39:54.0811069Z - Title: Registry rows must decay (no immortal rows) via TWO triggers: (a) NODE-SILENCE — evict rows whose author node has not been heard (admitted inbound feed) within the eviction window, so a vanished node's rows stop poisoning bare-id resolution with phantom AcrossNodes ambiguity; AND (b) per-row OFFLINE-TTL — evict rows that have been non-routable (Offline) beyond the per-row grace even while the author node is alive, because purge/erase leaves an immortal Offline row otherwise (ghost-heal re-advertises Offline ONCE with a fresh epoch, and whole-node eviction never fires for a still-alive author) so Offline ghost rows accumulate unbounded on a remote viewer under purge/erase churn (#2-secondary). Both keyed on RECEIVER-observed state (heard-map recency / a sticky receiver-observed offline_since, NOT the gossip epoch — an epoch-keyed clock would be reset by ghost-heal's fresh-epoch re-advertise); own rows never decay; a revived/re-flapped row re-inserts (or clears its offline_since) from its durable epoch within one pump cadence (4.10)
2026-07-11T01:39:54.0811240Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0811264Z 
2026-07-11T01:39:54.0811351Z ### REQ-CLI-1
2026-07-11T01:39:54.0813697Z - Title: spt endpoint noun namespace: absorbs fork/suspend/wake/shutdown/rename/stop/digest + access (ported 1:1: allow|revoke|open|list, decision 21) + description (ex-resources blurb; bare=show, set=author); merged endpoint list [--local|--subnet <name>] grouped by subnet with SELF pinned, --detail adding the ex-resources yellow-pages blurb projection; bare spt endpoint = the list (M8 decisions 1-2, 25). SUPERSEDED (F-025 item 3): the LISTING SHAPE now lives in REQ-ENDPOINT-LIST-NODE-GROUPED (node-grouped over unique instances, not grouped-by-subnet) + REQ-ENDPOINT-LIST-REST-FILTER (suspended-hidden + --show-all); the `--local` flag was dropped by REQ-ENDPOINT-LIST-MERGE-LOCAL (the list ALWAYS merges local). This REQ owns only the endpoint noun NAMESPACE + parse surface — not the render shape.
2026-07-11T01:39:54.0813807Z - Required stages: impl, unit
2026-07-11T01:39:54.0813836Z 
2026-07-11T01:39:54.0813921Z ### REQ-CLI-2
2026-07-11T01:39:54.0814570Z - Title: spt daemon noun: run|stop|status (hidden daemon verb becomes daemon run; agent-endpoint shutdown keeps its name under endpoint); daemon status renders the pump heartbeat (last-tick recency) so a half-dead daemon is never rendered implied-healthy (M8 decisions 5, 23)
2026-07-11T01:39:54.0814670Z - Required stages: impl, unit
2026-07-11T01:39:54.0814698Z 
2026-07-11T01:39:54.0814780Z ### REQ-CLI-3
2026-07-11T01:39:54.0815451Z - Title: Agent hot path stays flat across the M8 reorg: send/ring/ready/whoami/how-to unchanged; notify moves to subnet notify while notif stays top-level; breaking renames land clean with no deprecation shims (zero external CLI consumers pre-spt-claude-code) (M8 decisions 3-4, 9)
2026-07-11T01:39:54.0815649Z - Required stages: impl, unit
2026-07-11T01:39:54.0815672Z 
2026-07-11T01:39:54.0815768Z ### REQ-CLI-4
2026-07-11T01:39:54.0817786Z - Title: User-facing CLI output is human-readable: DIRECT-USER commands (e.g. adapter update/list/use) render friendly prose instead of raw CODE:RESULT markers — "claude-spt is up to date (0.2.0)." not "ADAPTER_UPDATE_UPTODATE:claude-spt: installed 0.2.0, latest 0.2.0". Strictly bounded to the direct-user surface: the adapter-PARSED bringup tokens (SEEDED/BOUND/READY/NO_SEED on seed/listen, which adapters grep) stay machine-parseable — humanization is additive (a human line beside the marker, or a --porcelain/--quiet split), never a silent rename of a dual-contract marker. The user-facing bringup composition belongs to the adapter (perri); this REQ owns only the direct-user CLI surface. (v0.9.0)
2026-07-11T01:39:54.0817879Z - Required stages: 
2026-07-11T01:39:54.0817903Z 
2026-07-11T01:39:54.0817998Z ### REQ-SUBNET-5
2026-07-11T01:39:54.0819174Z - Title: Per-subnet serve-state: spt subnet detach <NAME> [--save] / attach <NAME> [--save] — daemon keeps running, stops/starts advertising + connecting for that subnet (peer pump + responder selective); --save persists the startup default in daemon config; the all-attached banner gains per-subnet states (M8 decision 6, --save renamed from --auto per decision 25 session)
2026-07-11T01:39:54.0819356Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0819394Z 
2026-07-11T01:39:54.0819493Z ### REQ-SUBNET-6
2026-07-11T01:39:54.0820133Z - Title: Trust lifecycle verbs, elevation-gated: spt subnet leave <NAME> (membership exit) and spt subnet prune <node> (removes a dead identity's trust + registry rows, killing its dead dials; trust mutation = security surface, REQ-PAIR-6 gate machinery) (M8 decisions 6-7)
2026-07-11T01:39:54.0820229Z - Required stages: impl, unit
2026-07-11T01:39:54.0820253Z 
2026-07-11T01:39:54.0820343Z ### REQ-SUBNET-7
2026-07-11T01:39:54.0821901Z - Title: Per-machine re-pair trust overwrite: registry rows carry a hashed stable machine identifier (OS machine id /etc/machine-id|MachineGuid, domain-separated SHA-256 before gossip, spt-minted persisted UUID fallback; additive serde-default field — old rows parse clean); a COMPLETED pairing ceremony presenting the same node label AND machine id as an existing trusted row evicts the superseded identity's trust + registry rows on the seed-holder and replicates the eviction; a gossiped claim alone never evicts trust (M8 decisions 13, 22)
2026-07-11T01:39:54.0822011Z - Required stages: impl, unit
2026-07-11T01:39:54.0822034Z 
2026-07-11T01:39:54.0822120Z ### REQ-SUBNET-8
2026-07-11T01:39:54.0823149Z - Title: Status render honesty: zero-subnet text is daemon-aware ('No subnets registered — this node is standalone.' + daemon-running-dependent blurb, never implying messaging works while the daemon is down); hint footer prints on bare spt subnet only (status drops it); a stalled pump is surfaced in subnet status, never rendered implied-healthy (M8 decisions 11-12, 23)
2026-07-11T01:39:54.0823238Z - Required stages: impl, unit
2026-07-11T01:39:54.0823261Z 
2026-07-11T01:39:54.0823347Z ### REQ-INSTALL-6
2026-07-11T01:39:54.0824454Z - Title: Linux elevation install leg: install.sh symlinks the binary into a sudo-reachable path (/usr/local/bin; graceful print-the-one-liner when unelevated) so sudo spt resolves; first sudo spt detects elevation and prompts ONCE for the default user account — thereafter any elevated daemon launch runs daemon + state under that account, never root (KH 5.7 interplay verified) (M8 decision 8)
2026-07-11T01:39:54.0824554Z - Required stages: impl, unit
2026-07-11T01:39:54.0824581Z 
2026-07-11T01:39:54.0824662Z ### REQ-INSTALL-7
2026-07-11T01:39:54.0825704Z - Title: Windows inbound reachability: the elevated install leg registers the inbound-UDP firewall rule (New-NetFirewallRule); the daemon self-detects blocked inbound and renders it as the no-connection state in subnet status + the coming-online banner (covers user-scope installs that skip the elevated leg — never a silent NO_SEED_HOLDER dead-end) (M8 root cause 3)
2026-07-11T01:39:54.0825897Z - Required stages: impl
2026-07-11T01:39:54.0825920Z 
2026-07-11T01:39:54.0826011Z ### REQ-INSTALL-8
2026-07-11T01:39:54.0827015Z - Title: OS-service registration (REQ-INSTALL-1's deferred third leg): Linux systemd USER service + loginctl enable-linger (linger rides the elevated install leg; daemon starts at boot pre-login, user universe per KH 5.7, systemctl --user managed); Windows scheduled task at-logon (interactive session, no stored credentials); a node is reachable after reboot without any manual spt invocation (M8 decision 17)
2026-07-11T01:39:54.0827115Z - Required stages: impl
2026-07-11T01:39:54.0827157Z 
2026-07-11T01:39:54.0827263Z ### REQ-CONV-1
2026-07-11T01:39:54.0828602Z - Title: Peer address seeding, both cold starts: durable peer-addrs.json (identity dir) maps peer pubkey → last-known dialable address; the pump's resolver consults it FIRST with id-only discovery fallback on miss or dial failure (a stale addr never strands a peer); written by the pairing ceremony (both sides, from the live connection) and by the pump on successful connect; post-join first sync and post-restart resync converge in seconds, not ~1 min (M8 decisions 14, 20)
2026-07-11T01:39:54.0828761Z - Required stages: impl, unit
2026-07-11T01:39:54.0828823Z 
2026-07-11T01:39:54.0828914Z ### REQ-CONV-2
2026-07-11T01:39:54.0830030Z - Title: Event-driven advertisement: endpoint online/offline transitions (ready-listener start/stop, rest-state transition, perch death) trigger an immediate advertise_local + peer push as a WAKE of the existing pump loop (no second advertisement path — epoch lease + visibility gates ride unchanged); the cadence stays the steady-state floor (M8 decision 15)
2026-07-11T01:39:54.0830130Z - Required stages: impl, unit
2026-07-11T01:39:54.0830159Z 
2026-07-11T01:39:54.0830245Z ### REQ-PAIR-8
2026-07-11T01:39:54.0831440Z - Title: NTP TOTP offset: the pairing ceremony queries NTP at ceremony time (both sides) and applies the derived offset to the TOTP calculation in-process only; system-clock fallback when NTP is unreachable (offline LAN pairing unaffected — NTP failure never blocks a pairing that succeeds today); never sets the OS clock; no background sync loop (M8 decision 18; field trigger: enlyzeam clock >1 min off exceeds the ±1 window)
2026-07-11T01:39:54.0831556Z - Required stages: impl, unit
2026-07-11T01:39:54.0831579Z 
2026-07-11T01:39:54.0831659Z ### REQ-DAEMON-5
2026-07-11T01:39:54.0832870Z - Title: Pump liveness: the peer pump writes a last-tick heartbeat consumed by daemon status / subnet status (decision 23 render legs in REQ-CLI-2/REQ-SUBNET-8); the daemon supervises the pump task — a panic is caught, logged loudly, and the pump restarts with capped backoff (≤5 min), so a 5.9-class death self-heals visibly instead of silently halving the daemon (M8 decision 23; field motivation: hfenduleam 2026-06-07 half-death)
2026-07-11T01:39:54.0832970Z - Required stages: impl, unit
2026-07-11T01:39:54.0833000Z 
2026-07-11T01:39:54.0833081Z ### REQ-DAEMON-6
2026-07-11T01:39:54.0834956Z - Title: Service-aware `daemon start`/`stop`: when an OS service manager has a registered spt-daemon for this user, `spt daemon start` and `spt daemon stop` drive THAT service (so stop doesn't IPC-kill a unit that auto-restart-fights for the broker socket — the kitsubito 2026-06-08 loop). `start` graduates from a `run` alias to a first-class background verb (ensure-up, idempotent, non-blocking); stop routes managed→manager, manual→IPC. Linux=systemd user unit (`systemctl --user start|stop|is-active spt-daemon`, detected by unit-file presence); Windows=no controllable manager (the logon task is boot-only), so start=detached spawn / stop=IPC.
2026-07-11T01:39:54.0835061Z - Required stages: impl, unit
2026-07-11T01:39:54.0835090Z 
2026-07-11T01:39:54.0835174Z ### REQ-DAEMON-7
2026-07-11T01:39:54.0836471Z - Title: `daemon run` is foreground-consistent on every platform: the invoking process IS the daemon, blocks until signalled, never auto-detaches or respawns into an invisible background task. The detached/de-elevated background behavior lives ONLY in `start`. Windows: an ELEVATED `daemon run` refuses with guidance (use `start`, or an unelevated shell) instead of respawning detached/de-elevated and vanishing (KH 5.7 preserved — it still never serves elevated).
2026-07-11T01:39:54.0836679Z - Required stages: impl, unit
2026-07-11T01:39:54.0836707Z 
2026-07-11T01:39:54.0836788Z ### REQ-DAEMON-8
2026-07-11T01:39:54.0837689Z - Title: Internal auto-start prefers the service: `ensure_running` (any spt command's implicit daemon start, REQ-DAEMON-3) routes through the service-aware start path — when a manager has a registered service it starts THAT, never a competing manual `spawn_detached` daemon that would fight the service for the socket.
2026-07-11T01:39:54.0837780Z - Required stages: impl, unit
2026-07-11T01:39:54.0837809Z 
2026-07-11T01:39:54.0837895Z ### REQ-DAEMON-9
2026-07-11T01:39:54.0840275Z - Title: Net-bind boot-race resilience: a daemon that comes up net-less (NetHost::start failed — e.g. the systemd unit autostarted before the network/DNS stack was ready, `Failed to create an address lookup service`) must SELF-HEAL — retry the net bring-up in the background with capped backoff and, on success, attach net to the broker + spawn the dispatcher/peer-pump (which today are gated on `net_up` at boot and so never start, leaving the node silently unreachable until a manual restart — kitsubito 2026-06-08). Status surfaces the net-less state honestly (a net-less broker renders as 'no connection', not only a pump-STALLED line with a bogus pre-boot heartbeat age). The installer's autostart unit waits for the network (`Wants=/After=network-online.target`) as belt-and-suspenders.
2026-07-11T01:39:54.0840485Z - Required stages: impl, unit
2026-07-11T01:39:54.0840514Z 
2026-07-11T01:39:54.0840618Z ### REQ-HAZARD-LIVEHOST-BOOT-RACE
2026-07-11T01:39:54.0844088Z - Title: The brain's daemon-hosted Psyche lifecycle surfaces a host-FAILURE on the live perch (harness-diagnosable) and runs net-INDEPENDENTLY. When reconcile_once→host_one→spawn_psyche fails for a state=live_agent+status=online endpoint (e.g. the adapter's psyche binary absent from its install dir, REQ-INSTALL-11), the failure MUST be written to the perch info.json as a CURRENT-STATE field (reason + ts + attempt count; overwritten each 5s retry, CLEARED on successful host) and surfaced by `spt endpoint list`/status — never left as an eprintln on the brain's invisible stderr where a harness reading only perch state is blind. status=online stays authoritative (agent reachable; only the Psyche is missing — brain-restart rehydrate legitimately has online-without-Psyche windows), so this is a SEPARATE psyche-host-health field, never a status de-stamp. Net-independence is a locked-in invariant: spawn_live_host (brainproc.rs:230) reaches the reconcile and hosts the Psyche on a net-less/unpaired/peer-pump-STALLED node, proven by a REAL detached-daemon E2E (real broker→brain-child, real api seed+listen, real install-dir psyche binary). spt-core SURFACES the failure; the adapter owns fixing its packaging.
2026-07-11T01:39:54.0844216Z - Required stages: impl, unit
2026-07-11T01:39:54.0844245Z 
2026-07-11T01:39:54.0844345Z ### REQ-HAZARD-TEMPLATE-ARGV-FILL
2026-07-11T01:39:54.0848011Z - Title: Command-template substitution fills argv ELEMENTS, not a re-tokenized string: spt-core currently `fill_template`s {key} values INTO the command STRING and THEN `tokenize`s the filled string (runtime.rs:94/122), so a multi-word {key} value whitespace-SPLITS into multiple argv tokens unless the adapter hand-quotes the placeholder, and a value containing a `"` (or `;`) injects/breaks tokenization (shell-injection-adjacent). A filled value MUST become exactly ONE argv element regardless of spaces/quotes in the value. Fix: tokenize the TEMPLATE into argv FIRST, then `fill_template` EACH token, so a `{key}` slot resolves to a single element and the value never participates in tokenization (no whitespace-split, no quote/semicolon injection); preserve the missing-key / empty-command errors and `{{`/`}}` non-interpretation. perri's F-009 (v0.8.1 dogfood, argv-capture-confirmed): a multi-word `{psyche_prompt}` = "PSYCHE REVIVAL time: epoch-ms:… incoming event: (none)" arrived as argv[6..12] (7 stray tokens), the harness runner strict-parsed `--prompt` against the 2nd word, exited 2 within ~1s → phantom hosted perch. Applies to EVERY [session.<role>] template (psyche_init, extractor, notif, …); digest survives today only because its fills ({session_id}/{source}) are single-token.
2026-07-11T01:39:54.0848231Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0848259Z 
2026-07-11T01:39:54.0848359Z ### REQ-HAZARD-LIVEHOST-NONRESIDENT
2026-07-11T01:39:54.0851604Z - Title: A daemon-hosted Psyche that spawns then EXITS IMMEDIATELY is a host failure, surfaced like a spawn failure (closes the v0.8.1 residual masking): the REQ-HAZARD-LIVEHOST-BOOT-RACE signal stamps `psyche_host_error` only when `spawn_psyche` returns Err, NOT when the detached spawn() returns Ok but the child dies within moments (e.g. a bad-argv child exiting 2 — the F-009 case). That leaves the residual 'online + no Psyche + no cause' gap: the nested `{id}-psyche` info.json is written status=online with a real-but-DEAD pid and the PARENT perch carries NO psyche_host_error (perri's F-010: tasklist showed 0 host procs across the window while info.json read online). The host MUST confirm RESIDENCY — a hosted child not alive (or whose `{id}-psyche` perch never re-registers / has a dead pid) within N seconds of spawn is treated as a host failure: stamp the parent perch `psyche_host_error{reason:"host not resident within <n>s (psyche perch missing/dead pid)"}` (and do not leave a phantom online nested perch). Closes the last masking gap the v0.8.1 fix left open. perri's F-010 (v0.8.1 dogfood). Sibling of REQ-HAZARD-LIVEHOST-BOOT-RACE.
2026-07-11T01:39:54.0851808Z - Required stages: 
2026-07-11T01:39:54.0851837Z 
2026-07-11T01:39:54.0851948Z ### REQ-HAZARD-EPOCH-RESET
2026-07-11T01:39:54.0853205Z - Title: Advertisement-epoch reset strands a node: peers' higher last-seen epoch drops the reset node's fresh advertisements as Stale until the counter outruns history. Common case (full reinstall/re-pair) is mitigated by REQ-SUBNET-7's ceremony eviction (peer-side epoch memory dies with the deleted row — acceptance-verified); the residual narrow slice (epoch file lost, identity kept) is documented, guard deferred to a field hit (4.11)
2026-07-11T01:39:54.0853305Z - Required stages: 
2026-07-11T01:39:54.0853333Z 
2026-07-11T01:39:54.0853423Z ### REQ-MESH-1
2026-07-11T01:39:54.0855422Z - Title: Membership proof (seed-proof): symmetric current-epoch seed-knowledge replaces is_trusted at EVERY inbound gate (registry apply, WAN receive, sync, notif, connection accept). MK = HKDF(seed, domain ‖ subnet_id ‖ seed_epoch); mutual channel-bound challenge-response at connect (transcript binds both handshake-proven node pubkeys, both nonces, subnet_id, seed_epoch, role); verified once per connection, cached on the broker ConnEntry, kept warm via QUIC keep-alive so re-proof is restart/partition/rotation-only. Exact-epoch match (re-seed is the sole N-1 exception). SECURITY INVARIANTS: channel-bound (no cross-connection replay), mutual, accepts a member it never paired (the mesh property).
2026-07-11T01:39:54.0855533Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0855561Z 
2026-07-11T01:39:54.0855651Z ### REQ-MESH-2
2026-07-11T01:39:54.0858176Z - Title: Member roster: node-level union-merge grow-set (per member: pubkey, label, machine_id, last-known address, last-seen — NOT the seed), the discovery directory the mesh dials by. Seeded IN FULL at pairing (seed-holder hands joiner the whole current roster, incl. offline members — folds in deferred pairing-time hostname capture + post-join address seeding); each node authors its own entry stamped with its lease_epoch, merged strictly-greater-wins (the node_label lease); exchanged only over seed-proof'd member connections; forgery-inert (a fake entry names a pubkey that still can't seed-proof). Removal needs a TOMBSTONE — a per-pubkey revoked marker that propagates, dominates the entry, gates admission (seed-proof ∧ ¬tombstoned), and prevents reinsert; cleared by a completed re-pair of that pubkey. Persists through silence (offline member keeps its entry).
2026-07-11T01:39:54.0858386Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0858414Z 
2026-07-11T01:39:54.0858504Z ### REQ-MESH-3
2026-07-11T01:39:54.0860272Z - Title: Mesh row fan-out: registry rows stay OWN-AUTHORED; the only change is the push target widens from directly-paired peers to ALL roster members (a wider DIRECT fan-out, never a third-party relay). Every row/message still arrives from its author over a handshake → KNOWN-HAZARDS 7.5 (origin = handshake node) and 4.10 (eviction lease: any future update comes from that node itself, alive) PRESERVED VERBATIM. Closes the staggered A→B→C repro: C (roster-seeded with A at pairing) initiates to A, seed-proof admits C unpaired, A learns C, both push directly.
2026-07-11T01:39:54.0860447Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0860475Z 
2026-07-11T01:39:54.0860561Z ### REQ-MESH-4
2026-07-11T01:39:54.0862731Z - Title: Revoke + timeboxed seed rotation + re-seed grace: `spt subnet revoke <node>...` (list, elevation-gated, revoke-only) writes roster tombstones immediately, then schedules ONE seed rotation (re-mint seed, bump seed_epoch, push new seed CONFIDENTIALLY over member-auth'd TLS connections — never in roster/registry gossip — force-drop revokees) at the close of a coalescing window (default 1h); further revokes in the window join the same rotation (one epoch bump). `--force-rotate-seed` rotates immediately (compromised-node path). RE-SEED GRACE: a node proving the immediately-prior epoch (N-1) AND still on the roster gets a re-seed-only restricted connection (auto-heals a benign offliner); revoked/off-roster denied; ≥2 stale → re-pair.
2026-07-11T01:39:54.0862888Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0862930Z 
2026-07-11T01:39:54.0863020Z ### REQ-MESH-5
2026-07-11T01:39:54.0864399Z - Title: Hard cutover from pairwise trust: delete peers.json + the is_trusted authorization path (no migration — expendable test fleet, re-pairs fresh under the new model, user decision 2026-06-08). Warn-on-change DEMOTED from a gate to an awareness notice anchored on machine_id (not label): 'machine M, last seen as K1, now presents K2' — fires the same event as the REQ-SUBNET-7 re-pair overwrite. The TrustStore/peers.json code and its call sites are removed, not left dead.
2026-07-11T01:39:54.0864508Z - Required stages: impl, unit
2026-07-11T01:39:54.0864532Z 
2026-07-11T01:39:54.0864618Z ### REQ-MESH-6
2026-07-11T01:39:54.0865822Z - Title: Concurrent liveness probes: `spt subnet status --nodes` fans out its offline/serve-probes (REQ-SUBNET-5) CONCURRENTLY — total wall-time bounded by the single-probe ceiling (~3s), never k×ceiling. The mesh makes a node see ALL members (many possibly offline), so a serial probe loop would be offline_count×3s. (Planning verifies the current REQ-SUBNET-5 probe loop's behavior and fixes it if serial.)
2026-07-11T01:39:54.0865935Z - Required stages: impl, unit
2026-07-11T01:39:54.0865959Z 
2026-07-11T01:39:54.0866045Z ### REQ-SHELL-3
2026-07-11T01:39:54.0867828Z - Title: Drive channel (owner->shell, REST-only, never-spooled, latest-wins): the owner->shell mirror of sensory for continuous real-time control (scroll/crank/stick/avatar) — a [shell.drive] manifest vocab + EVENT_TYPE_DRIVE frame, delivered to the ONLINE binary only via a single live slot (a new frame supersedes an undelivered one — no spool, no queue, no replay on relink), dropped-with-diagnostic if the shell is offline; cross-node rides the ephemeral link (REST class), never the durable shell spool. Commands = discrete+durable; drive = continuous+ephemeral (CONTEXT:260, minted 2026-06-11 Gateway grill).
2026-07-11T01:39:54.0867935Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0868066Z 
2026-07-11T01:39:54.0868151Z ### REQ-SHELL-4
2026-07-11T01:39:54.0869961Z - Title: Shell tunnel (reliable-ordered opaque byte stream): an owner<->shell link may hold a long-lived, reliable-ordered, link-bound QUIC stream pair carrying opaque wire protocol traffic the channel taxonomy must NOT reinterpret (first consumer usbip URB) — manifest opt-in, not enveloped, not MAC-framed, not spooled; the link lifecycle governs it (a link-break closes the tunnel). Reliable-ordered ⇒ congestion surfaces as lag never loss ⇒ acceptable only on-LAN: the on-LAN posture is documented and the tunnel is NOT proven cross-WAN (CONTEXT:262, minted 2026-06-11 Gateway grill; doyle gate C2).
2026-07-11T01:39:54.0870075Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0870099Z 
2026-07-11T01:39:54.0870186Z ### REQ-CONSENT-3
2026-07-11T01:39:54.0872012Z - Title: Per-capability approval gates (class-keyed): the require_approval enum may ride INDIVIDUAL [shell.capabilities] entries — gating the dangerous ACT, not just the spawn — with an optional class_key scoping the grant qualifier finer than the capability id ((owner endpoint x device class x node); a remembered HID-class attach grant never authorizes a storage-class attach). Reuses the grant store + interactive escalation + tighten-only floor (REQ-CONSENT-1/2 plumbing). Spawn gates govern EXISTENCE; capability gates govern ACTS — an explicitly distinct invariant (CONTEXT:283, ratified 2026-06-11 Gateway grill).
2026-07-11T01:39:54.0872222Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0872251Z 
2026-07-11T01:39:54.0872337Z ### REQ-SHELL-5
2026-07-11T01:39:54.0873538Z - Title: Shell ownership is owner-type-agnostic: any non-Shell endpoint type may own/spawn/drive/command/link a shell (Gateway the named first) — control-exclusivity keys on the owner endpoint_id, NEVER on the owner's endpoint type. No ownership path (mint, launch, owner-from-link, cmd, drive, tunnel, sleep/wake, owner-shutdown) inspects the owner's type (CONTEXT:264, ratified 2026-06-11 Gateway grill).
2026-07-11T01:39:54.0873657Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0873685Z 
2026-07-11T01:39:54.0873782Z ### REQ-HAZARD-VIEWER-CLOSE-DETACH
2026-07-11T01:39:54.0883470Z - Title: A VIEW is independent from the endpoint: closing the tab/window where `spt endpoint run` was invoked must detach ONLY the `spt rc` attach pump — the daemon-hosted harness keeps running and stays re-attachable via `spt rc <id>`. ROOT (Windows, v0.12.0 real-harness defect): the daemon never breaks away from the launching terminal's Job Object. Windows Terminal / VS Code place the launched shell AND every descendant into a Job Object with JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE; closing the tab drops the terminal's last job handle → the OS terminates every process still in that job. A child escapes only with CREATE_BREAKAWAY_FROM_JOB — used NOWHERE in the tree. Both daemon spawn paths (daemon.rs:707 detached_no_inherit = DETACHED_PROCESS|CREATE_NEW_PROCESS_GROUP|CREATE_NO_WINDOW; deelevate.rs:519 elevated = CREATE_NEW_CONSOLE|...) drop the CONSOLE but NOT job membership, so the daemon's freshly broker-spawned ConPTY harness subtree is reaped on tab-close. The ConPTY/pseudoconsole isolation itself is CORRECT (portable-pty builds the pseudoconsole in the daemon; no console signal / handle leak) — the leaking lifetime binding is the Job Object, not the console. FIX: add CREATE_BREAKAWAY_FROM_JOB to both daemon spawn paths AND pin each broker-spawned harness into a DAEMON-OWNED Job Object (mirror reap.rs/Breap) as backstop (survives even where a terminal sets SILENT_BREAKAWAY_OK=false). Unix: the daemon's own session detachment (new session, no controlling terminal) already keeps a closing terminal's SIGHUP off its children — verify, add a guard test, no code expected. FIX UPDATE (v0.12.1 L1.5, doyle re-scope operator-approved 2026-06-18): job-neutral daemon launch is now PRIMARY, breakaway DEMOTED to a fallback rung. ROOT reframed — the daemon INHERITS the terminal's Job because spawn_detached runs FROM the terminal-child CLI (DETACHED_PROCESS detaches the console, not the job); breakaway tried to claw back out but a job CAN deny it (the L1 finding). FIX: launch the cold-started daemon via a job-NEUTRAL creator so it is WmiPrvSE/Task-Scheduler-owned, OUTSIDE any terminal job from birth (why Task-Scheduler-autostarted daemons never had this bug). Launcher ladder (first-success-wins, daemon.rs spawn_detached → BOTH cold-start AND `spt daemon start`): (1) WMI Win32_Process.Create via ABSOLUTE powershell -EncodedCommand (KH 5.12 abs path; base64-UTF16LE dodges all quoting; success requires BOTH ReturnValue==0 AND a parsed ProcessId, else fall-through — never a silent launched), forwarding SPT_* env via a `cmd /c set … & start /b` wrapper because a WMI/scheduler child does NOT inherit transient shell env (verified — SPT_HOME would be lost, wrong universe); (2) schtasks one-shot (same env wrapper; best-effort fallback); (3) CREATE_BREAKAWAY_FROM_JOB (the L1 code, reordered below); (4) in-job last resort (logs DETACH_IN_JOB + tab-close caveat). detached_no_inherit (breakaway-then-in-job) is UNCHANGED for its other caller shellhost::launch_shell (a daemon-spawned shell is already job-neutral once the daemon is). The elevated deelevate path keeps its L1 breakaway for now (elevated-case WMI-reparent = FOLLOW-UP). (v0.12.1)
2026-07-11T01:39:54.0883789Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0883890Z 
2026-07-11T01:39:54.0883991Z ### REQ-HAZARD-ATTACH-WEDGE
2026-07-11T01:39:54.0889234Z - Title: A legitimately dead PTY child (real crash/kill) + an undrained operator pump must NOT wedge the broker for all other clients. ROOT (v0.12.0 real-harness defect): loopback attach output is a blocking write_all into a bounded 64KB tokio duplex (nethost.rs:1040,1090); when the operator's rc pump stops draining (tab closed) the buffer fills and write_all blocks forever (the 'loopback never hangs' assumption at nethost.rs:1103 is false), parking a worker in the 2-worker net runtime (nethost.rs:640); a couple of these saturate BOTH workers → every new attach / `endpoint run` stalls right after 'PUMP_IPC_READER: spawned' → 30s FIRST_EVENT_GRACE → 'no output / dead or wedged'; `daemon stop` cannot join the stuck workers. DISTINCT from the removed B1 path-(c) mutex deadlock. DISPOSITION = PROVE-DON'T-CHANGE (doyle GATE-PASS @e883f45, 2026-06-18): this ROOT is the SUPERSEDED v0.12.0 hypothesis — the post-L0 code ALREADY prevents the wedge, so NO fail-fast / worker-count code was added. serve_attach forwards fire-and-forget (net_stream_send op_id=None) and the broker-side send_stream is already BROKER-QUIC-DEADLINE-bounded (bounded_block_on, 10s); the loopback duplex is drained broker-INTERNALLY by the operator row's own read pump (RecvHalf::Loopback, retentive_cap==0 → evict-not-park) so a dead rc (a dropped IPC subscriber) never backs peer_w up; bounded_block_on parks the BROKER DISPATCH thread, not a net worker → no worker-pool exhaustion (full mechanism in the required_stages comment). Folds the status=online sub-check: a dead spt-hosted endpoint is marked OFFLINE within one reconcile tick on abrupt child death (broker exit-waiter reaps the session → B2 sees it absent) — PROVEN, no change. (v0.12.1)
2026-07-11T01:39:54.0889357Z - Required stages: int
2026-07-11T01:39:54.0889382Z 
2026-07-11T01:39:54.0889489Z ### REQ-PICKER-HISTORY-FRESH
2026-07-11T01:39:54.0890595Z - Title: The `spt endpoint run` picker shows project history for FRESH endpoints (operator-raised v0.12.0 real-harness finding). Symptom: a fresh endpoint shows no project history in the picker. ROOT TBD — investigate the project-history loader (v0.10.0 PICKER-2, picker/data.rs) before fixing: distinguish a real loader bug from 'fresh = no history yet' semantics. (v0.12.1)
2026-07-11T01:39:54.0890700Z - Required stages: impl, unit
2026-07-11T01:39:54.0890729Z 
2026-07-11T01:39:54.0890824Z ### REQ-PICKER-ONLINE-ACTION
2026-07-11T01:39:54.0892367Z - Title: The `spt endpoint run` picker shows the correct action for an ALREADY-ONLINE endpoint — Attach, NOT 'Start now' (operator-raised v0.12.0 real-harness finding). Symptom: the picker offers 'Start now' for endpoints that are already online. ROOT TBD — investigate the status→action mapping (v0.10.0 PICKER-1 four-state status, picker/model.rs): is it reading live/online state correctly, or rendering stale/wedged broker state (i.e. partly a symptom of the broker wedge / status=online latch)? Fix so online → Attach. (v0.12.1)
2026-07-11T01:39:54.0892576Z - Required stages: impl, unit
2026-07-11T01:39:54.0892600Z 
2026-07-11T01:39:54.0892710Z ### REQ-ENDPOINT-LIST-MERGE-LOCAL
2026-07-11T01:39:54.0894455Z - Title: `spt endpoint list` always merges this node's LOCAL (unadvertised) perches into the view; the `--local` flag is REMOVED (operator decision 2026-06-17). Rationale: `spt whoami` is a thin alias of `endpoint list` — a just-online agent running `whoami` must see its OWN perch, or it gets an omitted-self view ('chaos'). FIX: drop the `--local` flag + its `--detail` conflict test + the v0.10.0 REQ-PICKER-5 hint line (cli.rs:1678) + cmd_list_local; the bare list merges local perches into the subnet view; fix the whoami alias path accordingly. Run `cargo run -p xtask -- gen` (docs-drift, DEFAULT target). (v0.12.1)
2026-07-11T01:39:54.0894625Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.0894653Z 
2026-07-11T01:39:54.0894767Z ### REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT
2026-07-11T01:39:54.0900049Z - Title: A clean `spt rc` attach to a LIVE spt-hosted (`endpoint run`) harness must DELIVER the harness's PTY output. KEYSTONE — the operator's central 'attach shows no output' symptom, reproduced on the real dummy-harness fixture (v0.12.1 Wave 1) with NO death and NO wedge: bringup succeeds (online, harness pid alive + heartbeating, psyche hosted), the attach CONNECTS (PUMP_IPC_READER spawned, no RC_FAIL, holds the full window) — but receives EXACTLY 0 bytes over 10s of the harness's flushed [session.self] stdout. DISTINCT from REQ-HAZARD-VIEWER-CLOSE-DETACH (death) and REQ-HAZARD-ATTACH-WEDGE (dead-child backpressure): here the harness is ALIVE and the attach is a clean first subscribe. This BLOCKS the 'view is independent' invariant — re-attach is meaningless if a live endpoint-run harness shows nothing. KNOWN-GOOD (rules out 'no drain'): attach.rs `local_attach_via_loopback_conn_rides_the_same_pump` + `broker_spawns_the_pty_child_in_the_requested_cwd` prove the broker DOES drain+fan a `spawn_session` PTY child to a loopback attach over the SAME transport rc uses. Both spawn_session and endpoint-run's spawn_session_pid send KIND_SPAWN → the same dispatch_spawn (broker.rs:706/835) which starts the per-session drain+OutputLog — so the gap is NARROWER than 'no drain', endpoint-run-specific. Root candidates: (a) spawn_session_pid's SpawnReq stdio/env/cwd differs so the dummy's stdout isn't the captured ConPTY; (b) the harness stdout WRITE BLOCKS because the ConPTY buffer fills (drain not reading THIS pty) — explains alive-but-0-bytes; (c) ConPTY reader-park (KH 7.6) on this path; (d) `spt rc` resolve_session/subscribe for an endpoint-run session subscribes to the wrong/empty log. (v0.12.1)
2026-07-11T01:39:54.0900259Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0900288Z 
2026-07-11T01:39:54.0900383Z ### REQ-CLI-HELP-MARKDOWN
2026-07-11T01:39:54.0903331Z - Title: `spt --help` (and every subcommand --help) renders the inline Markdown authored in the clap doc-comments as terminal styling, never as literal markers: `**bold**` → ANSI bold, `` `code` `` → ANSI cyan, `[text](url)` → `text`. The markers are STRIPPED either way — a raw `**` or backtick must NEVER reach the user (the operator-reported v0.12.0 defect: help text reads `**ctrl-b**` and stray backticks verbatim). Color/bold escapes are emitted ONLY when the help is going to a real terminal AND color is not suppressed (NO_COLOR unset · CLICOLOR != 0 · CLICOLOR_FORCE forces on); a pipe / redirect / CI / NO_COLOR falls back to strip-only (clean plaintext, zero escapes) so machine-readable help is byte-identical regardless of marker syntax. Pure transform over the clap-rendered help string at the single run()/bare_invocation chokepoint; preserves pre-existing ANSI (CSI sequences passed through untouched), never spans markers across a newline, leaves unmatched/empty markers literal, and does not alter the help layout. (v0.12.1)
2026-07-11T01:39:54.0903551Z - Required stages: impl, unit
2026-07-11T01:39:54.0903579Z 
2026-07-11T01:39:54.0903693Z ### REQ-HAZARD-WMI-DAEMON-WINDOW
2026-07-11T01:39:54.0906119Z - Title: `spt daemon start` launches the daemon with NO visible console window. REGRESSION (v0.12.1 L1.5): the WMI job-neutral launch (spawn_daemon_via_wmi) set CREATE_NO_WINDOW on the launching powershell but NOT on the Win32_Process.Create call — Win32_Process.Create does not inherit it, so the spawned cmd.exe env-forwarding wrapper popped a console window on every cold-start (violating REQ-INSTALL-10's v0.7.4 no-persistent-window invariant; the old detached_no_inherit path set DETACHED_PROCESS|CREATE_NO_WINDOW). FIX: pass a Win32_ProcessStartup with CreateFlags=DETACHED_PROCESS (0x8 — no console so no window; CREATE_NO_WINDOW 0x08000000 is NOT a valid Win32_ProcessStartup flag → ReturnValue 21 invalid-param, which is why the naive port fails) + ShowWindow=SW_HIDE(0) belt, via the ProcessStartupInformation argument. (v0.12.2)
2026-07-11T01:39:54.0906286Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0906315Z 
2026-07-11T01:39:54.0906411Z ### REQ-CLI-OUTPUT-MARKDOWN
2026-07-11T01:39:54.0911253Z - Title: Human-prose COMMAND OUTPUT (not just `--help`) renders the inline Markdown authored in its source strings as terminal styling, never literal markers: `` `code` `` → ANSI cyan, `**bold**` → ANSI bold, `[text](url)` → `text`, markers STRIPPED either way. REQ-CLI-HELP-MARKDOWN only hooked the clap `--help` chokepoint, so command output still printed raw Markdown (audit: `spt how-to` topic text showed `# headers`/backticks, `spt subnet`/`subnet status` hint footers showed stray backticks, the daemon-status `not running` line, the `ENDPOINT_RUN_STARTED` attach hint, and the daemon's `SUBNET_DETACHED` startup line — 13 prose surfaces). The same line-bounded pure `helpfmt::render` is applied at each emit site, color-gated by the OUTPUT STREAM's own tty (`stdout_color` for print/println, the new `stderr_color` for eprintln). HARNESS-SAFETY (binding): color is tty-gated, so an adapter (piped / non-tty / NO_COLOR) gets STRIP mode = zero ANSI + markers removed; every dual-contract MACHINE token on a rendered line (`ENDPOINT_RUN_STARTED:`, `NO_SUCH_TOPIC:`, `SUBNET_DETACHED:`) carries NO Markdown markers, so it survives strip byte-intact — the adapter parse is never perturbed. Pure-machine output (the `<EVENT …>` envelope, bringup parse-tokens SEEDED/BOUND/READY/NO_SEED, `--json`, QR) is NEVER routed through the renderer. The one spt-daemon source string (`SUBNET_DETACHED`, the bin-local renderer is unreachable from the daemon crate) is authored marker-free instead. (v0.12.2)
2026-07-11T01:39:54.0911395Z - Required stages: impl, unit
2026-07-11T01:39:54.0911429Z 
2026-07-11T01:39:54.0911563Z ### REQ-HAZARD-INJECT-CONTROL-COEXIST
2026-07-11T01:39:54.0918856Z - Title: SPINE INVARIANT (v0.13.0 keystone): the broker must accept INJECTED keystrokes into an spt-hosted PTY (the v0.11.0 raw direct-inject today; the ADR-0022 translation-binary choreography tomorrow) WHILE a live `spt rc` controller is attached to the SAME PTY, without (a) the operator losing control, (b) the endpoint latching ONLINE+CONTROLLED, or (c) the broker wedging. The injection inlet is PERMANENT — spt-claude-code requires keystroke injection — so this is root-caused + fixed at the PTY-injection layer, IN STEP with the ADR-0022 delivery redesign that formalizes the inlet. REOPENS the wedge facet of REQ-HAZARD-ATTACH-WEDGE: the v0.12.1 prove-don't-change covered only DEAD-CHILD backpressure, NOT the injection trigger (operator's signal — one injected keystroke succeeds, the next wedges → the single-threaded broker parks on a blocking PTY/loopback write after injection-induced harness output). REPRO-FIRST on the real dummy-harness fixture (NO theory): instrument to nail the exact blocking call before any fix. Fix candidates: non-blocking/fail-fast PTY write, split input/output, bounded-evicting. Mechanism shared with W2 — spt-core owns EVERY PTY write and applies an injected sequence ATOMICALLY (controller input buffered during the sequence, flushed after) so a stash/restore can't be clobbered. CONFIRMED ROOT (doyle /diagnose 2026-06-19, code-grounded): Broker::append (broker.rs:205-227) fans each live output chunk to the CONTROLLER on a SYNCHRONOUS BLOCKING write_frame held inline in the session's drain thread (the 'authoritative, advances delivered_through' path, D4-1), while VIEWERS use a dedicated writer thread + bounded evicting sync_channel (add_viewer:273 / viewer_writer) that can never stall the drain. So a slow/backed-up controller socket — or the full 64KB loopback duplex (the ATTACH-WEDGE buffer) — BLOCKS the drain thread → output stalls → keystroke echoes stall (PERCEIVED input lag) → unrecoverable wedge when the consumer never drains. TRIGGERS ON NORMAL INTERACTIVE rc USE under heavy harness output (TUI redraw), NOT only message injection — same root, wider repro. FIX DIRECTION: move controller delivery off the drain thread onto a dedicated writer (the viewer_writer pattern) BUT preserve the authoritative cursor — block the WRITER thread (not the drain), bound the wedge (deadline → detach/mark-gone, never park forever), never silently evict the operator's authoritative view. (v0.13.0)
2026-07-11T01:39:54.0919317Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0919346Z 
2026-07-11T01:39:54.0919505Z ### REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE
2026-07-11T01:39:54.0924690Z - Title: A SLOW controller must not starve a concurrent `rc --view` VIEWER. W1 (REQ-HAZARD-INJECT-CONTROL-COEXIST) moved the controller SOCKET WRITE off the drain thread onto controller_writer, but left the bounded HANDOFF (ControllerJob::deliver) as an INLINE try_send SLEEP-POLL on the drain (broker.rs:1450-1457 → deliver:669-685, up to CONTROLLER_WRITE_DEADLINE=5s). So when a controller drains slower than the PTY floods, its CONTROLLER_CHANNEL_DEPTH(4096) channel fills, deliver() polls inline, and the DRAIN THREAD is throttled to the controller's read rate → OutputLog::append's viewer fan-out (try_send) stops running → a concurrent VIEWER receives only the initial replay then nothing (root 'b4', warm forkpty: a_journaled c1=0/EVICT=0/got_output=FALSE; steady-state-near-full = no recovery; forkpty-only, floods harder than Windows ConPTY). The viewer-not-starved-by-a-busy-session property is legitimate (rc --view of a noisy session must show LIVE output). FIX: the controller becomes a SINGLE NON-BLOCKING try_send (like a viewer), done IN append() under the log lock; deliver()'s sleep-poll DELETED; the drain NEVER sleeps. ControllerSink gains a stateful last_ok deadline → a TRULY-stalled controller (continuous-Full past CONTROLLER_WRITE_DEADLINE) is evicted (bounded-wedge preserved); a slow-but-alive controller DROPS frames + falls behind the ring (resume-from-floor, the existing reconnect case). B2 GAPLESS-HANDOFF PRESERVED via a CONTIGUOUS delivered_through: controller_writer advances the cursor ONLY when the written seq == cursor (next expected); a gap from a drop FREEZES the cursor at last-contiguous so a re-attaching brain's resume_seq never skips a dropped chunk (a high-watermark advance past the gap would be a not-exactly-once resume = B2 violation, doyle's gate). (v0.13.0)
2026-07-11T01:39:54.0924837Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0924861Z 
2026-07-11T01:39:54.0924966Z ### REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT
2026-07-11T01:39:54.0930155Z - Title: A `rc --view` VIEWER that overflows its broker subscription queue and is EVICTED (OutputLog::append try_send Full → viewers.remove, REQ-HAZARD-VIEWER-ISOLATION session-protection) must SKIP TO LIVE, not die silently. ROOT (v0.13.0, b4 JIT item 2 = p0_paste + post-b4 a_journaled-Linux, ONE root): serve_attach forwards each frame (read_event→b64decode→re-encode AttachRecord→net_stream_send) SLOWER than the drain fans out under flood → its VIEWER_CHANNEL_DEPTH(256) channel overflows → the drain evicts (viewers.remove drops the ViewerSink → drops tx → viewer_writer's rx.recv() Err → the writer returns WRITING NOTHING) → serve_attach's brain.read_event() just STOPS getting Output (no EOF, no error) → serve_attach blocks forever → the operator receives nothing (attach_received_output=FALSE). Eviction-of-a-hopelessly-behind-viewer is CORRECT session-protection (keep it); SILENT+PERMANENT eviction is the bug. VIEWER-only → B2-SAFE (a viewer never advances delivered_through / is not authoritative / exposes no resume cursor). FIX (doyle-gated, skip-to-live = tail -f reconnect): (1) explicit broker→viewer EVICTION SIGNAL (KIND_VIEWER_EVICTED, written in the viewer_writer thread OFF the log lock, DISTINCT from session-exit EOF so serve must NOT tear down on it); (2) serve_attach re-subscribes from the CURRENT ring floor (skip-to-live, replays nothing, sees the next live burst) — resetting the cold serve-brain's next_seq so the post-eviction forward-jump replay is accepted (the legacy reject-gap path, brain.rs:618-626, would otherwise FATAL the forward jump); (3) HARD constraint NO evict→resubscribe busy-loop: serve_attach rate-limits re-subscribes (RESUBSCRIBE_INTERVAL) so under max-flood the operator sees intermittent LIVE bursts, never a CPU spin. (v0.13.0)
2026-07-11T01:39:54.0930493Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0930521Z 
2026-07-11T01:39:54.0930632Z ### REQ-HAZARD-VIEWER-RING-ROLL-SNAP
2026-07-11T01:39:54.0934706Z - Title: A read-only rc --view VIEWER whose serving brain falls behind the live ring under a hard flood and receives a FORWARD Output seq gap (the ring rolled frames out between reads, BEFORE any channel-overflow eviction → NO KIND_VIEWER_EVICTED marker) must SNAP TO LIVE (accept-and-advance via dedup-below + snap-above), NOT fatal with output gap (brain.rs:624/628 legacy reject-gap). ROOT (v0.13.0 forkpty, post-b4+skip-to-live): serve_attach subscribes a viewer via brain.attach_as(Viewer) leaving session_cursors EMPTY → the viewer serve-brain uses the LEGACY reject-gap → a PRE-eviction ring-roll forward-gap FATALS read_event → serve_attach returns → forwarding stops → attach_received_pty_output=FALSE (a_journaled / p0_paste / attach.rs:1071 wedged_viewer, Linux forkpty; Windows ConPTY floods slower → MASKED false-green). DISTINCT from REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT (the POST-eviction re-subscribe-from-floor): this is PRE-eviction gap-tolerance while STILL subscribed. VIEWER-only → B2-SAFE (a viewer never advances delivered_through / is not authoritative); the CONTROLLER keeps strict reject-gap (exactly-once resume). FIX: arm snap-above at initial viewer attach (attach_as_viewer_snap = attach_as(Viewer) + session_cursors.insert(session_id, from_seq)); the two viewer-survival mechanisms COMPOSE — this tolerates pre-eviction ring-roll gaps, REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT recovers post-eviction. (v0.13.0)
2026-07-11T01:39:54.0934826Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0934854Z 
2026-07-11T01:39:54.0934959Z ### REQ-HAZARD-CONTROLLER-GAP-RESUME
2026-07-11T01:39:54.0941353Z - Title: A serving CONTROLLER whose serve-brain hits a b4 drop-don't-block FORWARD output gap must RESUME-FROM-FLOOR (re-subscribe from delivered_through and re-fetch the dropped frames from the ring), NOT snap-above and NOT fatal. ROOT (v0.13.0 forkpty re-run, post-keystone): b4 made the controller a non-blocking try_send that DROPS frames when its bounded channel fills (a controller that falls behind its OWN echo under a hard flood), so the next read is a forward gap the strict reject-gap (brain.rs:624/628, B2 exactly-once) FATALS — wedged_viewer_does_not_stall_controller (attach.rs:1048) drove ctrl.read_event() raw and fataled on `output gap got 6134 want 4643`. Pre-b4 the inline sleep-poll BLOCKED the drain to the controller's rate (no drops, no gaps); this is a b4 SIDE-EFFECT, not a new class. A controller CANNOT snap (it is authoritative — advances delivered_through; skipping rolled frames = not-exactly-once = B2 violation), so REQ-HAZARD-VIEWER-RING-ROLL-SNAP does NOT apply. B2 INVARIANT (doyle, broker.rs:327-330): the ring trim is delivered_through-BLIND (`while ring.len() > cap_chunks { pop_front() }`), so re-fetch is exactly-once IFF tail - delivered_through <= cap_chunks (4096) — NOT guaranteed in general, but the common case (burst < ring; wedged_viewer ~1492 < 4096) holds. FIX: serve_attach catches the output-gap on the controller path (does not ?-propagate) and re-subscribes from Brain::controller_resume_floor (= delivered_through = the gap's `want`; NO mid-stream KIND_SESSIONS round-trip — sessions() loops on read_event and would re-fatal on the same gap + discard Output); the broker replays the dropped frames. The IRRECOVERABLE edge (floor unchanged across two resumes = ring rolled past delivered_through = frames gone) surfaces a MARKED truncation to the operator (never silent-skip = B2 lie, never spin) and ends cleanly — full graceful handling deferred to REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND. Do NOT make the ring trim delivered_through-aware (that risks an unbounded ring under a stuck controller; the 5s eviction + 4096 ring is the practical bound). (v0.13.0)
2026-07-11T01:39:54.0941630Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0941658Z 
2026-07-11T01:39:54.0941788Z ### REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND
2026-07-11T01:39:54.0944596Z - Title: DEFERRED EDGE of REQ-HAZARD-CONTROLLER-GAP-RESUME: when a serving controller falls behind the live ring FURTHER than the ring holds (tail - delivered_through > cap_chunks, the ring trim being delivered_through-blind, broker.rs:327-330), the dropped frames have rolled OUT of the ring and an exactly-once re-fetch is IMPOSSIBLE. v0.13.0 DETECTS this (resume floor unchanged across two consecutive resumes) and surfaces a MARKED truncation notice to the operator then ends the attach cleanly — it never silent-skips (a B2 lie) and never spins. FULL graceful handling (a clearly-marked snap-with-data-loss that keeps the operator on the live tail, or a structured truncation record the rc renders distinctly, plus the controller-too-slow + ring-too-small backpressure/sizing policy) is DEFERRED — staging it needs a netsplit / deep-behind harness (the in-process loopback rig keeps up; wedged_viewer's gap is recoverable at ~1492 < 4096). (v0.13.0+)
2026-07-11T01:39:54.0944715Z - Required stages: 
2026-07-11T01:39:54.0944749Z 
2026-07-11T01:39:54.0944852Z ### REQ-MSG-IDLE-TRANSLATION-BINARY
2026-07-11T01:39:54.0950827Z - Title: spt-hosted idle message delivery via an adapter TRANSLATION BINARY (ADR-0022). New opt-in manifest section `[message-idle-translation-binary]` = a TABLE carrying a `path` scalar (doyle OPT-B ruling: modeled as a table, not a bare top-level scalar, so a preceding section cannot silently absorb it + N+1 extensible; spt-core does NOT deny_unknown_fields, so a future key degrades gracefully); spt-core LIFECYCLE-manages it (spawn when the endpoint comes up, terminate when it goes down). The binary is a PURE stdin→stdout filter; spt-core owns EVERY PTY write. stdin (JSON-lines): `{type:"init",endpoint_id,node}` first · `{type:"event",envelope:"<EVENT…>"}` per inbound message (ADR-0020 envelope) · `{type:"input"}` content-free ping on each operator keystroke (binary tracks user-idle for its own idle-gated buffering; PTY input content NOT duplicated). stdout (JSON-lines): keystroke-commands `{key:…}`/`{delay_ms:…}`/`{text:…}` (extensible). spt-core applies the emitted sequence to the broker PTY ATOMICALLY (the W1 coordination — REQ-HAZARD-INJECT-CONTROL-COEXIST). The daemon poll feed is the ONE idle substrate for both topologies (Q1=A): harness-hosted consumer = the Monitor child, spt-hosted consumer = this binary; spt-core PREFERS a perch's poll listener if one exists (so spt-hosted can run a listener AND keep `spt rc`). Idle-only; busy/mid-turn = adapter hook-injection. Closes the current grounding gap: `api bind` registers no listener port → a listener-less spt-hosted perch SPOOLS inbound (only spooling+adapter-poll works today) → this delivers real inbound into the PTY. AMENDED v0.14.3 (ADR-0022 amendment, raw-inject removal): idle delivery is translation-binary-ONLY — the v0.11.0 raw `{text:payload}{key:enter}` inject is NO LONGER a delivery path; with no working binary (absent/spawn-failed/faulted/worker-gone) the inbound SPOOLS (delivered=false, poll-fed, LOUD), never a raw PTY pseudo-write (which did not submit on a modern TUI — the silent degrade that masked F-019). See REQ-HAZARD-IDLE-SILENT-NONDELIVERY. (v0.13.0, amended v0.14.3)
2026-07-11T01:39:54.0951128Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0951156Z 
2026-07-11T01:39:54.0951284Z ### REQ-HAZARD-IDLE-SILENT-NONDELIVERY
2026-07-11T01:39:54.0960915Z - Title: An idle delivery to a session whose translation binary is in a FAILED STATE — absent (none declared), spawn-failed, FAULTED, or its inject-worker channel gone — must SPOOL (delivered=false), never raw-inject a pseudo-delivery reported as delivered. The GUARANTEE is the STEADY STATE (the failed-binary state), not every in-flight message (see the fault-transient carve-out below). ROOT (F-019 post-mortem, ADR-0022 amendment): the v0.11.0 path raw-injected `payload+\r` into the PTY whenever no working translation binary handled an inbound message (none declared, spawn-failed, FAULTED, or its inject-worker channel gone) AND acked `delivered=true` — but a bare `payload+\r` does NOT submit on a modern TUI (Claude Code), so the message was TYPED but never sent: a silent pseudo-delivery reported as success. That silent degrade-to-raw-inject is exactly what MASKED F-019 through a multi-hour black-box hunt. FIX (operator-ruled, doyle-scoped): idle delivery is translation-binary-ONLY — `dispatch_endpoint_input` with no working binary replies `endpoint_injected_envelope(ep, delivered=false)` (the caller `try_broker_inject`→`cmd_send` then falls through to `deliver::send` = SPOOL, poll-fed, never lost) and writes NOTHING to the PTY, LOUDLY (eprintln names the absent/faulted/worker-gone cause). A failed binary becomes a VISIBLE no-delivery (spooled + honest QUEUED report), never a confident-but-false 'Sent'. The raw-inject fallback (`input.enqueue`) is REMOVED from the no-binary, worker-dropped, AND post-fault paths. OUT OF SCOPE (doyle ruling, follow-up note only): broker-side auto-redrive of already-spooled inbound the instant a live-update binary spawns (ordering/exactly-once hazards; the poll substrate + subsequent sends cover re-delivery). NOT COVERED — the FAULT-TRANSIENT (the STATE-vs-transient precision): a delivery landing in the worker's commit window — BEFORE `event_rx` is dropped / `faulted` is set — can be optimistically enqueue-acked (`delivered=true` the instant `event_tx.send` succeeds) then DROPPED when the worker faults+returns. That is a SEPARATE, PRE-EXISTING hazard: raw-inject removal did not touch it (the old code dropped that queued event too) — v0.14.3 is a strict improvement that makes nothing worse. It is tracked for v0.15.0 under REQ-MSG-DELIVERY-AXES (the spool-centric delivery redesign: ack-on-SPOOL replaces ack-on-enqueue, which closes the optimistic-ack drop naturally). v0.14.3 guarantees only the steady FAILED state → spool (faulted is MONOTONIC — set once, never respawns — so it converges deterministically; the g2 gate asserts the steady state via bounded-retry-until-spool, not a single-shot ack). EPHEMERAL CARVE-OUT (v0.15.0 W3, ADR-0028): `--ephemeral` is the SOLE sender-opted-in exception — an ephemeral message MAY drop silently if it cannot deliver in its accepted window (at window-open with no live carrier, or at TTL). Every NON-ephemeral path still spools + reports `delivered=false` (the guarantee is unchanged for the default durable path). v0.15.0 realizes the ephemeral drop for the spt-hosted-binary no-carrier-at-window leg + TTL; the harness-relay no-live-listener leg is a documented partial (CONTEXT.md §persistence). KNOWN-HAZARDS class (rule 4). (v0.14.3; ephemeral carve-out v0.15.0)
2026-07-11T01:39:54.0961120Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0961243Z 
2026-07-11T01:39:54.0961348Z ### REQ-MSG-DELIVERY-AXES
2026-07-11T01:39:54.0967721Z - Title: Activity-gated inbound delivery + per-message send control as THREE ORTHOGONAL AXES plus opaque metadata (ADR-0028; grilled w/ operator 2026-06-23). SUBSTRATE (the legacy-SPT parity gap, scaffolded-but-unwired today: `delivery::is_idle` + `resolve_inject_methods` exist but the result is discarded `let _methods`, and `broker::dispatch_endpoint_input` injects unconditionally — its comment calls activity-gating 'a deferred follow wave'): an inbound message has an ACTIVE window (endpoint active → spool for the receiver's hook-poll, non-disruptive) and an IDLE window (idle/idle-transition → deliver immediately: translation binary spt-hosted → relay-poll either topology → spool, in fallback order). AXES (each composes; each defaults to its unrestricted value): (1) DELIVERY WINDOW — default (both, first-to-fire) | `--idle-only` (idle window; immediate if already idle) | `--active-only` (active window only, never wakes; the RENAMED `--deferred` — `deferred=1` spool column + `api poll --include-deferred` keep their names). (2) CHANNEL RESTRICTION — unrestricted | `--prefer-native` (translation binary if running else fall back) | `--force-native` (binary ONLY, no fallback/no spool-to-other-method). Native flags do NOT respect the binary's idle-gating: the WINDOW says when, the native flag says through-what (so `--force-native --active-only` = binary injects during the active window, mid-turn-safe via the existing InjectFloor). (3) PERSISTENCE — durable (default; spool until delivered or TTL) | `--ephemeral` (drop if undeliverable in the accepted window — at window-open with no live carrier, or at TTL, whichever first). METADATA (orthogonal): `--json-payload '<json>'` → a single attr-escaped `json="…"` envelope attr ALONGSIDE (not replacing) the body, pure verbatim passthrough across spool/TCP/WAN/EVENT-PART, parsed only by the receiving adapter; collision-proof by construction (structured data lives INSIDE the one `json` value, can never forge `from`/`type`); available to ANY sender (confers no spt-core authority). HAZARD: `--ephemeral` is the ONLY path permitted to drop silently — the sender-opted-in carve-out to REQ-HAZARD-IDLE-SILENT-NONDELIVERY (that hazard gains a '…unless --ephemeral' clause in v0.15.0). (v0.15.0)
2026-07-11T01:39:54.0967955Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0967988Z 
2026-07-11T01:39:54.0968090Z ### REQ-RESUME-CONTEXT-PULL
2026-07-11T01:39:54.0979224Z - Title: Adapter-callable resume-context pull verb + not-yet-synthesized commune/signoff drop append (legacy-SPT parity, operator-directed 2026-06-24). GAP: spt-core exposes NO verb for a harness adapter's SessionStart hook to pull an agent's resume context — `resume::download_psyche_context` (spt-live/src/resume.rs:88, composes <live-role>+<live-context>+<project-context> from the durable two-tier store) is INTERNAL with ZERO spt callers and no ApiCmd verb (api/mod.rs ApiCmd enum has none); resume.rs:9 documents the intended 'adapter pulls it in its SessionStart hook' path but it was NEVER wired. Result: a harness adapter cannot inject the agent's durable mind on resume at all (claude-spt today runs only `api boundary` session-rotation + an identity brief — the agent resumes WITHOUT its mind). TIER-1 SCOPE (operator-approved; Tier-2 = drift-stamp/<current>/drift-directive + <memformat> + Pulse-Log DEFERRED to a separate parity item, NOT v0.15.0 — the legacy download_payload [claude_skill_owl context.rs:344] is richer but memformat is roadmap-deferred + drift-stamp is an orthogonal cross-machine-drift feature). TWO PARTS: (1) EXPOSE `spt api psyche-download <id> [--session-id <sid>]` -> stdout = the composed brief, project_id resolved from the endpoint's bound cwd (info::read_info -> cwd -> project derive; NO --project arg), auth-gated like sibling id-scoped verbs (the `gated(&id,&auth,…)` pattern); empty store -> NO-CONTEXT on stderr (mirror legacy). The adapter SessionStart hook runs it + injects stdout as additionalContext. (2) APPEND any commune/signoff drop NOT YET SYNTHESIZED into the durable tiers as a distinct <pending-commune>/<pending-signoff> slice AFTER the durable slices. GATING (operator ruling): append while NOT-YET-SYNTHESIZED, NOT merely 'while the raw file is on disk' — in today's synchronous ingest (ingest_drops route_two_slice writes durable THEN deletes the file, lifecycle.rs:466 @ DEFAULT_PULSE_PERIOD 5s) the two coincide (a watched-dir drop IS pre-synthesis), so the v1 realization reads the manifest-declared session.commune_dir/signoff_dir (manifest.rs:208/210) for a present <id>-commune.md/<id>-signoff.md (COMMUNE_SUFFIX/SIGNOFF_SUFFIX, ingest.rs); the CONTRACT keys on synthesis-state so it stays correct when async Psyche synthesis lands (a consumed-but-not-yet-committed drop stays appended via a pending-synthesis staging set — forward hook). The agent-checkpoint trigger sentinel CHECKPOINT_SENTINEL=`!!checkpoint!!` (a FIXED spt-core constant — operator-specified, CONTEXT.md §fixed-constants, NOT adapter-configurable) is stripped at BOTH drop-body points via one shared `strip_checkpoint_markers` (remove every token, keep inter-marker text, collapse trivial whitespace): the PRE-synthesis pending-append (resume::append_pending) AND the POST-synthesis durable ingest (ingest::route_slices — the single choke covering route_two_slice + signoff.write_resume_commune; strip-then-empty-filter so a marker-only slice routes nowhere) — else the marker would persist PERMANENTLY in live-context.md once a checkpoint drop synthesizes + re-trigger once the adapter's checkpoint detection is live. PRESENTATION-ONLY: the append NEVER writes the durable store (spt-core remains sole store-writer, REQ-HAZARD-DROP-FILE-SINGLE-WRITER; mirror legacy's read-only/process_file_drop-sole-deleter discipline). SELF-CLEARING: once synthesis commits the <pending-*> slice vanishes — no duplication. CORE-OWNED (not adapter): an adapter-side raw-file read RACES spt-core's ingest-delete (TOCTOU, ingest.rs:161 removes the drop on pulse-consume); the fold MUST live in the single composer all resume pulls flow through. New public CLI verb -> docs-drift gate (xtask gen + reference.md no-internal-codes, cli-command-docs-drift). (v0.15.0 parity wave W5)
2026-07-11T01:39:54.0979655Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0979692Z 
2026-07-11T01:39:54.0979796Z ### REQ-ADAPTER-TRANSLATE-PROOF
2026-07-11T01:39:54.0983975Z - Title: `spt adapter translate-proof <adapter> --event <envelope> [--session <id>]` — the author-time EMIT-half proof tool for `[message-idle-translation-binary]` (ADR-0022), symmetric to `spt adapter digest-proof` (REQ-TERM-5). It spawns and feeds the adapter's declared translation binary EXACTLY as the daemon does at idle-delivery — running the REAL `spt_daemon::translation` driver VERBATIM (no protocol reimplementation): `TranslationChild::spawn` the binary, send the `{type:"init",endpoint_id,node}` line then the `{type:"event",envelope}` line, and read back the emitted `{key}`/`{text}`/`{delay_ms}`/`{commit}` keystroke-command stream — then prints it author-readable (each Key with its `key_to_bytes` rendering, Text quoted, Delay in ms, Commit marker) with counts. It fills the SAME `{id}`→option and `{session_id}`→(--session, else a placeholder) keys into the `--event` envelope the daemon fills at runtime, so an envelope that proofs here feeds faithfully live. EMIT-half ONLY: it proves the binary's spawn+feed+emit contract; it does NOT exercise the daemon's atomic PTY apply / controller-buffering (that stays covered by the W2 inject_control_wedge int gate) — `--help` says so. Exit codes mirror digest-proof: 0 ok, 1 on spawn-fail / zero commands / no-commit-or-output / unparseable, 2 when the adapter declares no `[message-idle-translation-binary]` section. The `TranslationChild` Drop does the bounded no-zombie reap. (v0.13.x)
2026-07-11T01:39:54.0984081Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.0984110Z 
2026-07-11T01:39:54.0984213Z ### REQ-HAZARD-BIND-CWD-UNSET
2026-07-11T01:39:54.0986794Z - Title: A bound endpoint's `info.cwd` is SET at bind so a freshly-created perch appears under its own project tab. ROOT (found, v0.13.0): `info.cwd` is NEVER set on bind — `cmd_bind` (spt-hosted) and `bind_from_seed` (harness-hosted) never thread cwd into `establish_perch`/`rec.cwd`. FIX: `cmd_bind` reads its own `current_dir` (the broker spawned it in `project_cwd`); `bind_from_seed` passes `seed.cwd` (already captured at seed time, currently DISCARDED). DISTINCT from REQ-PICKER-HISTORY-FRESH (v0.12.1) — that unioned cwd-origin into picker MEMBERSHIP but tested merge_origin_project with a PROVIDED origin; it never asserted `info.cwd` is actually set on bind, so a real `endpoint run` perch still had an empty cwd and the union had nothing to union. This is the v0.12.1 P1 'appears under its own project right away' claim that was REFUTED in the changelog — delivered for real here. (v0.13.0)
2026-07-11T01:39:54.0987013Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0987041Z 
2026-07-11T01:39:54.0987140Z ### REQ-PICKER-UX-V013
2026-07-11T01:39:54.0988718Z - Title: `spt endpoint run` picker UX (v0.13.0 operator dogfooding): (1) SKIP the first screen — open directly on 'Pick existing'; `n` jumps to 'Create new'. (2) AUTO-ATTACH after both Start-new AND Resume-from-history (both currently don't attach and show no stdout); add an `h` shortcut to run headless (no attach). (3) 'controlled by' shows the node NAME (node_label_display), not the raw hex. (4) Clean up Start-new output — drop the Rust `pid=Some(142748)` leak and the 'harness binds its perch on startup' internals; user-friendly, not a process log. (v0.13.0)
2026-07-11T01:39:54.0988813Z - Required stages: 
2026-07-11T01:39:54.0988842Z 
2026-07-11T01:39:54.0988933Z ### REQ-HAZARD-DRIVEN-BY-SELFHEAL
2026-07-11T01:39:54.0990709Z - Title: An spt-hosted endpoint's ONLINE+CONTROLLED state (`driven_by`) must CLEAR even when the detach IPC is lost — do NOT rely on the detach signal (same lesson as REQ-HAZARD-HOSTED-LIVENESS-RECONCILE B2): the reconcile loop clears `driven_by` when the endpoint has no live controller/session. Today a wedged or lost pump never delivers the detach, so the endpoint stays latched CONTROLLED forever. Composes with W1 (the wedge no longer blocks the detach) and rides the same pull-primary reconcile substrate as B2. (v0.13.0)
2026-07-11T01:39:54.0990830Z - Required stages: impl, unit, int
2026-07-11T01:39:54.0990859Z 
2026-07-11T01:39:54.0990973Z ### REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT
2026-07-11T01:39:54.0995653Z - Title: An spt-hosted endpoint driven by a REMOTE controller whose remote is gone but whose broker connection stays OPEN (a wedged/lost pump that never delivers the detach) AND whose session is IDLE (no output) stays latched ONLINE+CONTROLLED forever: the W1 drain-evict only fires on OUTPUT (CONTROLLER_WRITE_DEADLINE on a backed-up write), a clean disconnect self-heals via detach_if→clear_controller, but an idle session with a half-open/wedged controller connection produces neither signal. PROVED repro-first on a real broker (v0.13.0 W5, inject_control_wedge.rs w5_a2): controller_by STAYS Some(origin) and driven_by STAYS Some after the remote is abandoned without a clean EOF on an idle session — so the brain reconcile CANNOT detect it from KIND_SESSIONS controller_by (the broker still reports it controlled). FIX DIRECTION (doyle ruling 2026-06-19, broker-side single-writer — the broker owns driven_by/clear_controller): wire the EXISTING D4c NetPresence connection-disconnect event → clear_controller for any session whose controller identity == the dead origin (become_controller already stores Some(origin); presence events already exist — modest wiring, NOT a new probe). The liveness ORACLE is QUIC's own keepalive/idle-timeout: a presence-disconnect IS a real QUIC conn close, already tolerant of transient blips within the keepalive window, so NO heavy partition ADR is needed UNLESS the QUIC timeout proves too slow for the UX (then mint an ADR for a faster controller-heartbeat + its false-evict bound). Composes with W1 (output path) + W5 Gap B (no-session) — this is the third, idle-remote, leg. (v0.13.0 follow-up)
2026-07-11T01:39:54.0995871Z - Required stages: 
2026-07-11T01:39:54.0995901Z 
2026-07-11T01:39:54.0996006Z ### REQ-HAZARD-RC-INPUT-KEY-ENCODING
2026-07-11T01:39:54.1000584Z - Title: An `spt rc` session forwards the Backspace key as the VT DEL byte (0x7f), so the hosted TUI (Claude Code) deletes ONE character — never a whole word. SYMPTOM (operator dogfooding): Backspace in an rc session always behaves like ctrl+Backspace — deletes the entire last word. ROOT (doyle /diagnose, code-grounded, byte PENDING HITL confirm): rc is a RAW VERBATIM byte pump — spawn_stdin_reader (rc.rs:152) reads std::io::stdin() bytes under crossterm raw mode and forwards them unchanged (parse_stdin_chunk only intercepts the ctrl-b detach prefix); there is NO key-event encoding and NO 0x08↔0x7f normalization ANYWHERE in the tree (grep: zero SetConsoleMode / ENABLE_VIRTUAL_TERMINAL_INPUT). On Windows, crossterm enable_raw_mode does NOT set ENABLE_VIRTUAL_TERMINAL_INPUT, so the LEGACY console delivers ^H (0x08, ctrl+h) for Backspace instead of VT DEL (0x7f); Claude Code maps ^H → backward-kill-word → the observed whole-word delete. CONFIRM-FIRST (build the loop): an env-gated hexdump in spawn_stdin_reader (SPT_RC_DEBUG_KEYS) prints the forwarded byte; operator presses Backspace + ctrl+Backspace in a real rc session. FIX CANDIDATES: (a) enable ENABLE_VIRTUAL_TERMINAL_INPUT on the rc stdin console on Windows so the console emits proper VT (Backspace→0x7f, arrows/Home/End as CSI) — cleanest, fixes the whole key map not just Backspace; (b) narrow normalize bare 0x08→0x7f in the rc input path (riskier — a real ctrl+h is also 0x08). Prefer (a) unless it regresses other keys. Add a KNOWN-HAZARDS.md entry on landing. (v0.13.0)
2026-07-11T01:39:54.1000813Z - Required stages: impl, unit
2026-07-11T01:39:54.1000841Z 
2026-07-11T01:39:54.1000945Z ### REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE
2026-07-11T01:39:54.1009886Z - Title: The effect journal serializes EVERY PTY effect under one mutex held ACROSS two fsyncs AND the blocking PTY write — so interactive input stutters and ultimately wedges the daemon hard. ROOT (doyle /diagnose, code-grounded + MEASURED on the operator's real Windows box, 2026-06-19): EffectJournal::apply_once (effect.rs:168-188) takes `inner.lock()` and holds it across `write_line(PENDING)` → `effect()` → `write_line(DONE)`, where write_line (effect.rs:235-239) does flush()+sync_all() (a full FlushFileBuffers) — so each effect pays TWO fsyncs under a GLOBAL lock, and the closure `effect()` (the actual PTY write, broker.rs:1257 EffectKind::PtyWrite via attach.rs:197 send_effect) runs while the lock is held. Two operator-visible facets, ONE root: (A) STUTTER/LAG — every keystroke is a PtyWrite effect = 2× sync_all serialized; measured fsync on %LOCALAPPDATA%\spt-core = median 6.5ms, spikes to 198ms (C: was recently at 100%), so ~13ms+ per keystroke best case, hundreds under contention → 'many but not all keypresses take 100s of ms, choppy, worsens with volume'. (B) HARD PERMANENT WEDGE — when a PtyWrite `effect()` blocks (ConPTY input buffer full / harness not draining stdin), the journal lock is held INDEFINITELY → the single-threaded inbound-stream dispatch (dispatch.rs serve_attach, which both applies input effects AND opens attaches) can never progress → EVERY subsequent attach (`spt rc --view`/`--take`) fails with 'attach request: brain IPC read deadline elapsed' (confirmed: two retries deadline identically; broker control-plane KIND queries still answer — different thread). This REFUTES the W2-deferred ruling that park-(b)/(c) is 'Windows-benign because ConPTY absorbs 4MiB' — on the real box the input path wedges regardless. DISTINCT from W1 (REQ-HAZARD-INJECT-CONTROL-COEXIST = the OUTPUT drain, correctly fixed @8b5583e; output uses broker.rs:1106 append, NOT the fsync journal). This is the INPUT/effect-journal path W1 never touched, and it is THE wedge the operator hits with --take/--view. FIX DIRECTION (candidates, repro-first — extend inject_control_wedge.rs to a REAL backed-up-PTY-consumer + a real rc-client attach assertion, the gap W1's gate missed): (1) do NOT hold the journal lock across effect() — reserve the key + fsync PENDING under lock, RELEASE, run effect(), re-acquire to fsync DONE + mark applied (preserve crash-idempotency via the per-key reservation, not a global hold); (2) bound/fail-fast the PtyWrite itself (the W2-deferred park bound — write_input must never block indefinitely, DSR-answer must not hold the writer mutex across a blocking write); (3) drop per-keystroke fsync on the interactive path — PtyWrite effects are EPHEMERAL (a keystroke lost on a broker crash is retyped; PTY state is not reconstructed from keystroke replay), so in-memory applied-set dedup suffices (the broker survives the brain — that IS the dedup anchor), with async/batched fsync or no-fsync for EffectKind::PtyWrite while durable kinds (NetSend/NetDial/Registry/Spool) keep their fsync. Combine (1)+(3) at minimum. Add a KNOWN-HAZARDS.md entry on landing. (v0.13.0)
2026-07-11T01:39:54.1010239Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1010267Z 
2026-07-11T01:39:54.1010368Z ### REQ-HAZARD-RC-ATTACH-ONLINE-RACE
2026-07-11T01:39:54.1013839Z - Title: `spt endpoint run` in an ATTACH/VIEW terminal action attaches BEFORE the freshly-spawned endpoint is online, so the attach races (or outright loses to) the harness bind. ROOT (doyle /diagnose, code-grounded): cmd_endpoint_run (cli.rs) does launch_harness_brokered_in -> (if start: return) -> run_attach with NO await-online between them. launch_harness_brokered_in returns once the harness PROCESS is spawned, but the broker-PTY bind (info status -> STATUS_ONLINE + the live session) lands ASYNC. Both picker attach paths route here with start=false (RunMode::Attach -> cmd_endpoint_run start=false,view=false): Start-now catches the endpoint mid-bringup -> run_attach attempts + loses the handshake race; Resume-from-history catches it still fully OFFLINE -> run_attach's status-gate (REQ-HAZARD-RC-ATTACH-FAILFAST) short-circuits 'offline - nothing to attach' and NEVER attempts. SAME root, two faces (the W4 attach-by-default surfaced both; an online endpoint is unaffected - the picker returns Outcome::Attach, not Run). FIX: in cmd_endpoint_run, when the terminal action is attach/view (NOT start), AWAIT the endpoint online between launch_harness_brokered_in success and run_attach - poll spt_store::info read_info().status to STATUS_ONLINE with a bounded harness-boot deadline (~25s) at a tight interval; on online -> run_attach; on timeout -> ENDPOINT_RUN_ONLINE_TIMEOUT err (do NOT attach a dead bringup). (v0.13.0)
2026-07-11T01:39:54.1013944Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1013973Z 
2026-07-11T01:39:54.1014091Z ### REQ-RC-KEY-VT-TRANSLATE
2026-07-11T01:39:54.1019726Z - Title: On Windows, `spt rc` translates CONSOLE KEY EVENTS to standard xterm VT so ALL keys reach the hosted harness — arrows/Home/End/PgUp/PgDn/Insert/Delete/F-keys, every modifier combo, Backspace/Ctrl+Backspace — not just the byte-emitting ones. ROOT (operator HITL, doyle /diagnose): `spt rc` reads raw STDIN BYTES (spawn_stdin_reader, std::io::stdin().read); on the Windows LEGACY console (no ENABLE_VIRTUAL_TERMINAL_INPUT) the special keys produce console KEY_EVENTs, NOT stdin bytes, so the byte-pump sees nothing → those keys are DEAD. Enabling ENABLE_VIRTUAL_TERMINAL_INPUT was rejected (W7 dc07c39): on Windows Terminal it yields harness-specific win32-input-mode + broke ctrl-b detach. FIX (agnostic, full fidelity): on Windows, replace the stdin byte-read with a crossterm EVENT source (crossterm 0.28 already a dep; the picker already reads events) and translate each KeyEvent → STANDARD xterm VT bytes via a PURE translate_key_event(KeyEvent)->Vec<u8> (copy a known-correct xterm table verbatim, ADR-0001 spirit), forwarded through the SAME rc pump — the harness receives ordinary xterm VT (harness-AGNOSTIC, no win32-input-mode). Press-only (drop Repeat/Release). Detach stays the ctrl-b+'d' PREFIX, event-sourced (doyle Option B): Ctrl+B arms; armed+plain-'d'⇒Detach; armed+Ctrl+B⇒emit literal 0x02; armed+other⇒0x02 then translate(other). Non-tty stdin (piped/tests) → FALL BACK to the byte-read path (keeps e2e byte-injection working). UNIX UNCHANGED (its raw-mode byte stream already delivers proper VT; cfg-split, zero Unix regression). SUPERSEDES the W7 normalize_key_byte swap on Windows — the translator emits 0x7f for Backspace and 0x08 for Ctrl+Backspace natively (REQ-HAZARD-RC-INPUT-KEY-ENCODING folded in). NO int (a live interactive console can't be driven in CI — HITL, REQ-RUN-PICKER/RC-1 precedent); the exhaustive non-vacuous translate_key_event mapping unit + the event-detach unit ARE the surface. (v0.13.0)
2026-07-11T01:39:54.1020040Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1020069Z 
2026-07-11T01:39:54.1020179Z ### REQ-HAZARD-PTY-INPUT-WRITER-WEDGE
2026-07-11T01:39:54.1026221Z - Title: Pasting into an `spt rc` session WEDGES the broker — after a paste the operator can no longer type AND can no longer attach to NEW or EXISTING sessions (`brain IPC read deadline`). ROOT (doyle /diagnose, code-grounded): the operator-keystroke path rc -> net-stream Input -> serve_attach (attach.rs:197 brain.send_effect) -> KIND_INPUT -> broker dispatch loop (broker.rs:1091) -> dispatch_input (broker.rs:1459) -> session.write_input(&bytes) runs SYNCHRONOUSLY on the broker request-handling thread. W1b (REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE) released the journal lock across the effect (fix 1) + made PtyWrite ephemeral/no-fsync (fix 3) but EXPLICITLY DEFERRED fix (2) — bound/fail-fast the PtyWrite itself. A single keystroke never fills the ConPTY input buffer; a PASTE BURST does -> write_input blocks -> the dispatch thread cannot service the next frame (a re-attach subscribe, a become_controller restore-write, an inject-floor flush) -> wedge. Not a bug-2 regression (the byte path funnels to the same write_input; paste just reliably fills the buffer). FIX (doyle design, V0.13.0-P0-PTY-INPUT-WRITER-DESIGN.md, CONTEXT L33 broker-owns-PTY/minimal + L435 SessionSurface + single-writer pattern): one dedicated per-session INPUT-WRITER THREAD = the SOLE caller of the blocking write_input, fed by a BOUNDED FIFO channel; every caller (dispatch_input, serve_attach->send_effect, inject-floor flush) ENQUEUES + returns immediately, never blocks. A blocked/slow harness blocks ONLY its own writer thread, never the broker dispatch. Backpressure (operator ruling): queue full => DROP excess input + stamp the session INPUT_BACKPRESSURE (visible health signal); the daemon NEVER wedges; a merely-slow harness self-heals as the writer drains. Exactly-once preserved (PtyWrite ephemeral: apply_once effect = the non-blocking enqueue => Applied; ack now means accepted+ordered, benign — rc does not gate on landing); order preserved (single FIFO + single writer); inject-floor (W2 Layer C) choreography moves to the lone writer. Completes the W1b-deferred fix (2), cross-platform (cfg(unix) forkpty park folds in). (v0.13.0)
2026-07-11T01:39:54.1026355Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1026384Z 
2026-07-11T01:39:54.1026487Z ### REQ-SESSION-RESUME-TEMPLATE
2026-07-11T01:39:54.1033194Z - Title: Resuming an endpoint session that HAS conversation history brings up a BLANK session. ROOT (doyle, code-grounded + CONTEXT — case-3 spt-core MISSING feature, NOT a perri docs-miss): CONTEXT L127-129 already defines the resume-session seam ('continue-existing: resume an existing harness session under the adapter — its NATIVE resume'), and the manifest already has the resume-variant pattern (Session has BOTH psyche_init AND psyche_resume, manifest.rs:217-219) — but the agent's own session has ONLY self_ (`[session.self]`, no resume sibling). cmd_endpoint_run (cli.rs:1304) re-passes the session_id through `[session.self]` on resume (resume.unwrap_or_else(mint_session_id)), so the adapter's FRESH command (e.g. `claude --session-id ..`) runs again instead of the harness NATIVE resume (`claude -r ..`) -> CC starts a fresh transcript -> blank. spt-core forwards session_id + cwd faithfully; it just has no way to express the native-resume invocation. SECOND GAP: CC resolves a transcript by session_id + cwd, but the session ledger records only {ts, session_id, trigger} (no cwd), so picker Resume-from-history (cross-project rows) can't restore the right cwd. FIX (doyle design, V0.13.0-P2-SESSION-RESUME-DESIGN.md, mirrors psyche_init->psyche_resume exactly): (A) add a `[session.resume]` role (resume: Option<SessionRole> on Session + roles()/is_empty()); cmd_endpoint_run selects it when --resume is set AND it's declared (fill {id}/{session_id}=resumed id/{session_name} + the resume cwd), else FALL BACK to `[session.self]` (full back-compat). (B) record cwd PER ledger row (operator ruling): {ts, session_id, trigger, cwd} additive serde-default; resume cwd = resumed row cwd -> else perch info.cwd -> else current_dir (back-compat for old rows + single-project endpoints); picker threads the selected row's cwd through Outcome::Run -> cmd_endpoint_run. (C) public docs (MANIFEST + harness-contract) teach `[session.resume]` so perri builds the adapter side BLIND. Adapter follow-on (perri, AFTER spt-core ships+docs): declare `[session.resume] command = claude -r {session_id} --remote-control {id} --dangerously-skip-permissions` from the resume cwd. Completes REQ-READY-AGENT-RESUME / REQ-RUN-PICKER resume-from-history. (v0.13.0)
2026-07-11T01:39:54.1033499Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1033527Z 
2026-07-11T01:39:54.1033627Z ### REQ-RC-WIN-PASTE
2026-07-11T01:39:54.1038233Z - Title: In an `spt rc` session neither ctrl+V nor right-click pastes (CC explicitly supports ctrl+V). ROOT (doyle /diagnose): RawGuard does only enable_raw_mode (no bracketed paste / no mouse capture / no clipboard interception); the Windows console delivers a paste as synthetic per-char KEY EVENTs (no crossterm Event::Paste), and ctrl+V translates to bare ^V forwarded to CC — but CC runs DAEMON-SIDE with NO access to the operator's LOCAL clipboard, so remote paste is fundamentally CLIENT-ORIGINATED. A multi-line paste-as-keys also becomes a \r submit-storm. FIX (doyle design, V0.13.0-P1-RC-PASTE-DESIGN.md, cfg(windows), folds into the bug-2 event path): on a paste gesture rc reads the LOCAL clipboard + forwards a BRACKETED PASTE (ESC[200~ + content + ESC[201~); CC has bracketed-paste mode on (its TUI sets ESC[?2004h) so it treats it as a paste — content intact, no submit-storm, harness-AGNOSTIC. ctrl+V: intercept Char('v')+CONTROL in the event loop -> read_clipboard -> bracketed paste. Right-click: RawGuard also EnableMouseCapture (disables console QuickEdit + enables ENABLE_MOUSE_INPUT so right-click surfaces as Event::Mouse on legacy cmd/powershell) -> right-button -> read_clipboard -> bracketed paste; DROP all other mouse (CC has no mouse features, operator-confirmed, so capture costs nothing). read_clipboard = clipboard-win crate (cfg(windows), minimal); empty/failed = clean no-op. Content forwarded VERBATIM (literal pasted text, no per-char translation). Unix UNCHANGED (its terminal pastes natively through the byte pump). DEPENDS ON P0 (a paste chunk must not wedge the broker). (v0.13.0)
2026-07-11T01:39:54.1038370Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1038393Z 
2026-07-11T01:39:54.1038500Z ### REQ-HAZARD-INPUT-ACK-BACKPRESSURE
2026-07-11T01:39:54.1045691Z - Title: A FLOOD of operator input on one brain↔broker connection deadlocks the broker PERMANENTLY (entire broker — no new/existing attach; the controller stays latched because the per-conn handler can't process the detach). ROOT (doyle /diagnose, code-grounded + HITL capture, the v0.13.0 P1 ctrl+V re-open): `serve_attach` processes a whole `NetStreamData` batch of N operator `Input` records in its inner `for rec in decoder.push()` loop, calling `brain.send_effect(op_id, &bytes)` N times WITHOUT returning to `read_event()` — so the brain writes N `KIND_INPUT` frames back-to-back and drains nothing. The broker's single-threaded per-conn handler answers EACH with `send_frame(applied_envelope)` on the SAME conn (B5 exactly-once ack, KNOWN-HAZARDS 7.2). With the brain not reading, the broker→brain return direction fills (~10 frames = the IPC pipe buffer) → `send_frame` BLOCKS → the handler stops reading → the brain's writes block too → mutual full-duplex DEADLOCK. Capture pinned it: 11 input frames, write_input 11/11 (P0 holds — the PTY write is fine), ack send START=11 / END=10 (frame #11's applied-ack never returns). Same class as the v0.12.1 L0 two-conn split. Windows Terminal's ctrl+V paste accelerator was the trigger (injects the clipboard as a char-by-char key flood) but the deadlock is generic to ANY input flood, NOT ctrl+V-specific and NOT a P0 (PTY-write) or W1 (output-drain) regression. The applied-ack is load-bearing ONLY for `shellchan` (one-at-a-time spool delivery WAITS on `BrokerEvent::Applied`); `serve_attach` DISCARDS it (the operator/rc path is fire-and-forward, op_id for dedup only, never gates on the ack). FIX (doyle-approved): CONDITIONAL ACK — `InputReq` gains `ack: bool` (serde default = true, N-1-safe: an older brain's input still acks = today's behavior). `serve_attach`'s operator path calls `send_effect_no_ack` (ack=false) → `dispatch_input` writes NO applied frame → the per-conn handler never writes back while servicing the flood → it always drains → no deadlock (cures ANY input flood). `shellchan` keeps `send_effect` (ack=true) and its `Applied`-wait. Exactly-once PRESERVED: the broker still dedups by (session, op_id) at the applied-set regardless of the ack. N-1 caveat: an OLD resident broker (self-update window) ignores `ack=false` → still acks → the deadlock persists until a broker restart (inherent KNOWN-HAZARDS 7.9 broker-resident-wire-change class). (v0.13.0)
2026-07-11T01:39:54.1046202Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1046230Z 
2026-07-11T01:39:54.1046325Z ### REQ-RC-MOUSE-FORWARD
2026-07-11T01:39:54.1050801Z - Title: On Windows, `spt rc` must FORWARD scroll-wheel events to the harness when the harness has mouse reporting on. ROOT (operator HITL): P1's RawGuard EnableMouseCapture (added for right-click paste, REQ-RC-WIN-PASTE) makes Windows Terminal forward ALL mouse — including the scroll wheel — to rc instead of scrolling its own buffer, but the rc mouse handler dropped everything except right-button-down → scroll DIED (and WT's native scrollback is stolen by the capture). Operator ruling: keep mouse capture + right-click bracketed paste AND forward scroll to the harness. FIX (doyle design, cfg(windows), folds into the rc mouse handler): TRACK the harness's mouse-reporting mode by scanning its OUTPUT stream for the DECSET set/reset — ESC[?1000h/1002h/1003h (mouse on) + ESC[?1006h (SGR ext) and their ...l (off) — into a shared MouseMode{enabled,sgr} (pump writes from output, stdin reader reads); the scan survives a sequence SPLIT across output chunks (a bounded carry buffer). The mouse handler: right-button-DOWN -> bracketed clipboard paste (unchanged, REQ-RC-WIN-PASTE); ScrollUp/Down -> translate to an xterm SGR mouse report (ESC[<64;col+1;row+1M up / ESC[<65;..M down, 0-based crossterm -> 1-based xterm) and forward ONLY when enabled && sgr (else DROP — a legacy X10 report the harness may not parse is garbage); Moved/drag/left/middle -> DROP (scroll is the operator's need; click-forward risks garbage, no click-to-position). Unix UNCHANGED (no capture; the terminal scrolls natively). (v0.13.0)
2026-07-11T01:39:54.1050934Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1050963Z 
2026-07-11T01:39:54.1051077Z ### REQ-HAZARD-CONTROLLER-WRITER-REORDER
2026-07-11T01:39:54.1064903Z - Title: Two `controller_writer` threads must never race ONE brain↔broker connection's socket. ROOT (doyle, instrumented RACEDIAG repro on kitsubito): on a brain-restart re-serve the handoff brain registers as controller on the SAME session TWICE over the SAME `Brain::conn` socket — (1) `Brain::handoff` eagerly `subscribe(prior.session_id, prior.next_seq=1)` → `become_controller(from_seq=1)`, initial=[1], spawns writer-A (writes seq 1); (2) `serve_attach` re-handles the replayed `Request{from_seq:0}` → `attach_as(sid,0)` → `become_controller(from_seq=0)`, initial=[0,1], spawns writer-B (writes 0 then 1). `become_controller` (broker.rs) drops the prior `ControllerSink` (its `tx`) but does NOT stop the prior writer thread — writer-A keeps flushing its owned `initial` batch, and both writers hold clones of the same `SharedSend` (`Arc<Mutex<socket>>`) with NO inter-thread ordering. When writer-A's seq 1 wins the socket before writer-B's seq 0, the strict legacy consumer (brain.rs read_event reject-gap path) sees `output gap: got seq 1 want 0` → the test `attach_survives_target_brain_restart_exactly_once` panics at `.expect("re-serve")` OR HANGS in `render_until` (serve thread died on the gap → MARKER_TWO never reaches the wire). `prior.next_seq` is life1's CONSUMPTION cursor, NOT life2's connection state — life2's socket has been sent NOTHING, so a `from_seq=0` full replay on a connection that already streamed seq 1 is contradictory. Snap-above tolerance ALONE can't fix it (it would dedup-drop the late seq 0 → byte loss → the exactly-once byte-identity assert fails). PRE-EXISTING, surfaced by the v0.13.0 green-both-runners release gate; P1b is INNOCENT (its diff touches only input-ack machinery, proven mechanically + the test passes post-P1b in isolation). Sibling flaky cluster: `inject_control_wedge::g2`, `broker::spawn_env_reaches_child`. INVARIANT: on a single brain↔broker connection the controller output-frame stream is monotonic non-decreasing in seq (modulo dedup re-sends); exactly ONE `controller_writer` is ever live per connection; a SUPERSEDED writer writes NO further frames; a re-serve never replays a seq below what the connection already received. FIX (doyle design, corrected at the gate 2026-06-20): fix #1 as designed ('drop handoff's eager subscribe so serve_attach's attach_as is the sole registration') was REVERTED — handoff's `subscribe(prior.next_seq)` IS the standalone-resume mechanism (the brain-only update engine `apply_brain_only` + the `handoff`/`idempotent`/`daemon_e2e` int tests replay output through it with NO `serve_attach`; dropping it hung every resume-via-handoff test). The shipped fix is three parts: (1) CORRECTNESS — `Brain::handoff` seeds `session_cursors` at `prior.next_seq` so the consumer runs the production dedup-below+snap-above path, never the strict reject-gap legacy trap; this is COMPLETE (not merely tolerant) because every `controller_writer` emits an ASCENDING seq stream and the surviving writer (serve_attach's attach_as(sid,0)) offers the complete `[0,end]` range, so a snap-above merge of ascending writers delivers `[K,end]` with no skip/dup (first sighting of any seq>M is preceded by M on that writer). (2) INVARIANT — `controller_writer`'s INITIAL-BATCH replay is epoch-gated: `controller_epoch` is a shared `Arc<AtomicU64>`, the writer re-reads it UNDER `send.lock()` (atomically with `write_frame`) and returns the instant it is superseded — no check-then-block-then-write window, no superseded replay (W1-safe: never blocks the drain under `Mutex<OutputLog>`). The LIVE loop is NOT gated (new output only flows to the current controller; a superseded writer must still deliver its terminal `Displaced` kick — gating it suppressed the loud-take notice; it ends on `tx`-drop). (3) EXPLICIT-RESUME / OPERATOR-STREAM BOUNDARY (the LOAD-BEARING fix — kitsubito RACEDIAG ~33% repro the keystones missed) — `Brain::subscribe_with` (shared by attach/attach_as) resets the resume-mode dedup cursor to `from_seq`. The handoff eager subscribe makes serve_attach's brain receive the replay's seq K BEFORE the operator Request is processed (`attached`=false); that frame is dropped by the if-attached forward gate but the snap-above cursor already advanced past K, and `attach_as(sid,0)`'s re-subscribe used to leave the cursor advanced → the broker's re-send of seq K arrives below it, deduped, never forwarded → operator viewport forward-gap (silent content loss in the real rc consumer). Resetting to from_seq on the attach_as re-subscribe re-delivers from 0 (operator dedups the overlap) so seq K reaches the viewport. The epoch gate (2) is sound (RACEDIAG: zero socket interleaving above K); cold-start brains (empty map — production dispatch serve) keep the legacy next_seq path, so production is unaffected. (v0.13.0)
2026-07-11T01:39:54.1065409Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1065438Z 
2026-07-11T01:39:54.1065546Z ### REQ-HAZARD-CONTROLLER-RETAKE-FLOOR
2026-07-11T01:39:54.1069802Z - Title: `become_controller` should STRUCTURALLY refuse a controller re-take whose `from_seq` falls below the connection's already-delivered contiguous floor — making the P1c reorder invariant un-reintroducible by a future caller, not just removed at the one caller. ROOT/SCOPE (doyle proposed, P1c gate dialogue): P1c fixes REQ-HAZARD-CONTROLLER-WRITER-REORDER three ways (handoff single-take + epoch-gate-under-lock + session_cursors seed), removing the one decreasing-floor double-take and bounding any other to already-committed-only. A self-enforcing broker guard would refuse the bad SHAPE outright. BLOCKER: the obvious predicate (`from_seq >= delivered_through`) is UNSAFE because `delivered_through` is SESSION-WIDE (the `Arc<AtomicU64>` on `OutputLog`, shared by all controllers/viewers, advanced monotonic-MAX; `resume_seq` reads it) — a normal fresh-operator `from_seq=0` attach to a producing session legitimately sits below it (full ring replay + consumer dedup-below/snap-above), and monotonic-MAX can't distinguish the hazard (a `seq1`-without-`seq0` write reads as `2`). The structurally-correct guard needs a NEW per-connection contiguous-sent cursor (the true highest-contiguous seq this socket has received) that does not exist today; the guard then refuses a re-take below THAT. Bigger than P1c; no live gap (P1c fully fixes the actual bug). Mint/refine stages when the per-connection cursor is built. (v0.13.0 follow-up, post-ship)
2026-07-11T01:39:54.1069965Z - Required stages: 
2026-07-11T01:39:54.1069994Z 
2026-07-11T01:39:54.1070097Z ### REQ-ADAPTER-MULTIPLATFORM-SPT
2026-07-11T01:39:54.1072669Z - Title: A `.spt` adapter archive may pack multiple platforms in one signed asset: shared `manifest.toml` + `strings/` at the root, role binaries under per-Rust-target-triple subdirectories (ADR-0016 triple vocabulary, e.g. `x86_64-pc-windows-msvc/`); install/update extracts the shared root plus ONLY `current_platform()`'s triple subdir, flattened into `install_dir` so flat `<install_dir>/<program>` resolution (REQ-INSTALL-11) is unchanged. Name stays `adapter.spt` (plain-tar or gzip, `--asset` optional default); one whole-archive Ed25519 signature over the fat archive (REQ-UPD-9 single-artifact verify). A legacy flat archive (no triple subdirs) extracts as today (free back-compat); a multi-platform archive sets `min_spt_core_version >= 0.13.2` (forward-compat gate, readable before extract); a multi-platform archive missing the recipient's triple -> typed `NoArtifactForPlatform`, never a silent no-op. Large adapters may still split per-platform (single-triple archives via `--asset`, or ADR-0016 update-set machinery). (ADR-0024, v0.13.2)
2026-07-11T01:39:54.1072785Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1072818Z 
2026-07-11T01:39:54.1072918Z ### REQ-ADAPTER-LIVE-UPDATE
2026-07-11T01:39:54.1075659Z - Title: An adapter update is live and daemon-coordinated (the adapter analog of brain self-update, ADR-0004): for an endpoint with a running RESIDENT adapter binary (today the `[message-idle-translation-binary]`), the CLI keeps fetch+verify and hands the APPLY to the daemon over IPC, which per affected endpoint (1) STOPS the resident binary -> releases the OS file lock (fixes the Windows 'Access denied (os error 5)' overwrite failure), (2) swaps on disk ONLY files whose CRC differs from the staged archive (unchanged files + their still-running binaries untouched), (3) RE-CLONES the new on-disk manifest into the running `BrainLifecycle` (the in-memory manifest is cached at bringup and otherwise goes stale -> binaries+manifest back on the same page), (4) RESTARTS the resident binary from the new files. An endpoint NOT running -> CLI swaps directly (no lock, no cache). Only the resident class is cycled; ephemeral adapter binaries (Psyche loop, `[digest]` extractor, `[session.*]` runners, hooks) self-heal on next spawn and are excluded. The daemon keeps a per-endpoint registry of resident adapter children. (ADR-0025, v0.13.2)
2026-07-11T01:39:54.1075912Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1075940Z 
2026-07-11T01:39:54.1076091Z ### REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP
2026-07-11T01:39:54.1080783Z - Title: A DELEGATED live adapter apply MUST NEVER report success without performing the swap, and the live-update seam MUST use ONE parent-aware adapter matcher across all its comparators. TWO defects made the field repro (BUILD-F015B-APPLYMATCH: `--adapter cc:ccs` live update silently no-ops): (D1, matcher skew) the broker's dispatch_adapter_apply filtered sessions by EXACT `s.adapter == req.adapter`, but a `--adapter <adapter>:<profile>` endpoint stores the COMPOSITE `cc:ccs` while the apply carries the PARENT record name `cc` — so every :profile endpoint fell out to affected=[]; select_endpoints_running_adapter had the same `adp == adapter` skew, while the CLI live-gate (adapter_has_live_endpoint) already parent-matched — divergent rules on ONE seam. (D2, silent success) the affected.is_empty() branch replied KIND_APPLIED and RETURNED WITHOUT SWAPPING; once the CLI delegates the apply there is no CLI-side fallback swap, so success-without-swap = the update never lands (re-register re-reads the OLD manifest, version-of-truth honestly says old). FIX: (1) ONE shared spt_runtime::profile::adapter_parent_matches(session_adapter, parent) used by the live-gate + broker apply-filter + select_endpoints_running_adapter (no exact `==` against a record name at any live-update seam); (2) the daemon owns the whole apply once delegated — the CRC swap runs UNCONDITIONALLY (terminate/restart loops no-op when nothing is resident), KIND_APPLIED reported ONLY after a real swap. (F015B, ADR-0025 amendment)
2026-07-11T01:39:54.1080906Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1080939Z 
2026-07-11T01:39:54.1081060Z ### REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP
2026-07-11T01:39:54.1083907Z - Title: Endpoint-stop and brain-death reconcile MUST reap a brain-less perch's orphan detached Psyche via the cmdline-scoped guard (`psyche_orphan_should_reap`) — the handle-reap (`LiveSet::stop_host`, REQ-HAZARD-UNHOST-PSYCHE-REAP) CANNOT, because the owning brain is gone (its `psyche_child` handle died with it), and the brain-start scoped-reap (REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP) never fires for a perch being STOPPED rather than re-hosted. So the live-host calls the scoped reap after `stop_host` at the reconcile stop-side AND in `confirm_residency_or_unhost`. Preserves fail-safe-decline (pid-alive AND exe-basename==psyche-program AND cmdline contains `<id>-psyche`; any unreadable signal DECLINES — a missed dup is bounded, a wrong-kill is catastrophic). This is the orphan-leak half of the perri F-010xF-015 field bug (the unsupervised install-dir Psyche that locked an update); the other half is the psyche own-copy (ADR-0025 amendment). (v0.13.2 W3 (a))
2026-07-11T01:39:54.1084012Z - Required stages: 
2026-07-11T01:39:54.1084040Z 
2026-07-11T01:39:54.1084140Z ### REQ-ADAPTER-UPDATE-MESSAGE
2026-07-11T01:39:54.1085609Z - Title: An adapter manifest may declare `[update].message` — a plain (multi-line) human notice surfaced to stdout, markdown-rendered (the v0.13.0 helpfmt prose path), ONLY when `spt adapter update` actually APPLIES an update (version changed), not on a no-op. Read from the newly-installed manifest; avenue-agnostic (gh_release/delegated/file_pull). No `{key}` substitution. Use: an adapter telling the operator a post-update action, e.g. spt-claude-code's "run `/reload-plugins` in any ongoing sessions". (v0.13.2)
2026-07-11T01:39:54.1085741Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1085765Z 
2026-07-11T01:39:54.1085857Z ### REQ-ADAPTER-GH-TRANSPORT
2026-07-11T01:39:54.1087128Z - Title: The `gh_release` avenue (and `spt adapter add --release`) gain a fetch `transport`: `https` (current reqwest direct, public), `gh` (shell the pre-authorized `gh` CLI — the private-repo path; `gh` honors OAuth and `GH_TOKEN`, so spt custodies no token), or `auto` (default: prefer `gh` when installed+authed, else HTTPS). `--gh`/`--https` force it on `add`. Additive over the existing fetch path; verify->extract->register downstream is unchanged. (v0.13.2)
2026-07-11T01:39:54.1087498Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1087527Z 
2026-07-11T01:39:54.1087626Z ### REQ-ADAPTER-PROOF-DIR-OVERRIDE
2026-07-11T01:39:54.1089053Z - Title: The author-time proof commands (`spt adapter digest-proof`, `spt adapter translate-proof`) gain a `--dir <path>` / `--manifest <file>` override so an author proofs a DEV binary against an on-disk manifest+install dir WITHOUT staging a full extracted GhReleaseManaged install (mirrors digest-proof's `--sample` pointing straight at a file). Fixes perri F-011: a bare-file-added gh_release adapter currently can't be resolved by the *-proof commands ('manifest is not present yet at <dir>'); un-stales the bare-file digest-proof int. (perri F-011, v0.13.x DX)
2026-07-11T01:39:54.1089166Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1089194Z 
2026-07-11T01:39:54.1089295Z ### REQ-ADAPTER-VERSION-CMD
2026-07-11T01:39:54.1090804Z - Title: `spt adapter version <name>` prints a registered adapter's declared version — the EXISTING mandatory `[adapter].version` manifest field (manifest.rs already requires it; NOT a `[strings].version`, NOT `get-string`, no second version source). A new `AdapterCmd::Version{option}` resolves the option's merged view via `registry::resolve_option` like the sibling adapter subcommands and prints `manifest.adapter.version`; an unresolvable option errors (exit 1) the same way. (v0.13.2 W6)
2026-07-11T01:39:54.1090908Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1090932Z 
2026-07-11T01:39:54.1091028Z ### REQ-DOCS-NO-INTERNAL-CODES
2026-07-11T01:39:54.1092576Z - Title: Public CLI --help (the clap `///` doc-comments) and the generated `docs-site/src/cli/reference.md` MUST NOT contain internal tracker/decision codes — `REQ-*`, `F-###`, `M#-W#`, `ADR-####`. They are meaningless to an end user reading --help and ship to GH-Pages. A CI-gated scan (the `xtask check` docs gate) fails on any such token in the GENERATED reference.md (which by construction contains only clap help, so rustdoc `///` on fns/structs is OUT of scope and keeps its REQ/ADR cross-refs). Substance is kept; codes are rewritten to plain language. (v0.13.2 W6)
2026-07-11T01:39:54.1092689Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1092717Z 
2026-07-11T01:39:54.1092812Z ### REQ-RUN-MULTISUBNET-HOME
2026-07-11T01:39:54.1095463Z - Title: `spt endpoint run` resolves the home subnet at the skeleton-create step and pre-creates the skeleton perch carrying it, so the harness `bind` inherits home via establish_perch's immutable prior-branch (no hook change, no env injection). Resolution: sole-subnet auto; multi-subnet + no --subnet + NON-interactive terminal -> refuse early with MRU-ordered --subnet guidance (never the silent 25s online-timeout); multi-subnet + no --subnet + INTERACTIVE -> print proposed config (id/project/adapter[:profile]/home=MRU-default) + 'Ok to proceed? Y/n', n -> --subnet guidance; --subnet overrides + validates membership. MRU = ordered move-to-front LISTs at two levels (per-project + always-updated node-global fallback). Home stays IMMUTABLE (ADR-0010). Fixes the LATENT multi-subnet bringup gap (perri, not a regression — HOME_REFUSED established >=0.11.0; exposed by the node crossing 1->2 subnets). (ADR-0026)
2026-07-11T01:39:54.1095578Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1095601Z 
2026-07-11T01:39:54.1095700Z ### REQ-ENDPOINT-UNBOUND-ATTACH
2026-07-11T01:39:54.1098111Z - Title: An spt-hosted endpoint is ATTACHABLE between spawn and bind: gate the attach on the broker SESSION being attachable (session+PTY+OutputLog exist at spawn, before bind), not on perch STATUS_ONLINE (bind). cmd_endpoint_run + `spt rc <id>` attach to a live broker session regardless of perch status (headless bringups too; lets an operator clear a bind-gating prompt) -- replaces await_endpoint_online; preserves REQ-HAZARD-RC-ATTACH-ONLINE-RACE's 'no attach before a session' intent at the earlier session-exists point; source = the broker sessions map (ADR-0025 W3a); local-only. New on-disk status STATUS_UNBOUND (spawn->unbound, bind->online, death->offline); lifecycle reuses the existing exit-waiter/reconcile (session death->offline); unbound is attachable but NOT message-addressable (messaging stays online/bound-gated). EpDisplay gains Unbound = HOLLOW (+ hollow-controlled variant) -- amber=HarnessOnly is taken + means not-controllable (the opposite of attachable). (ADR-0027)
2026-07-11T01:39:54.1098397Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1098421Z 
2026-07-11T01:39:54.1098506Z ### REQ-MANIFEST-SUBST
2026-07-11T01:39:54.1101197Z - Title: Manifest substitution primitives for resolve-not-execute (ADR-0029, supersedes a rejected `spt api run-hook`): (1) two adapter-static substitution keys `{adapter_dir}` (the registry record's precise source_dir — install dir, survives updates, the dir bare-program resolution uses) and `{adapter_name}`, available wherever command/string substitution runs; (2) lazy substitution INSIDE `[strings]` values at `get-string` read time, scoped to those adapter-static keys ONLY (session-scoped {id}/{session_id}/… are NOT available — get-string carries no session; a get-string --session-id is a deferred larger change). Invariant preserved: spt-core never executes a string — it substitutes and returns; the adapter's own wrapper executes the result (e.g. a CC hook dispatcher get-strings its packed binary once per session into an env var, then runs it per-hook, so hook logic rides `spt adapter update`). (v0.16.0)
2026-07-11T01:39:54.1101311Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1101336Z 
2026-07-11T01:39:54.1101435Z ### REQ-ADAPTER-UPDATE-POST
2026-07-11T01:39:54.1104369Z - Title: Composite adapter update — an avenue-agnostic `[update.post]` sub-table `{ command, self_verifies }` run AFTER the primary avenue (gh_release/file_pull/delegated) resolves, in the same `spt adapter update` (ADR-0029). Runs UNCONDITIONALLY (even on an adapter version no-op — the post-step's own idempotent check decides). PUBLISHED stdin JSON seam: one line `{adapter_applied, adapter_name, profile_name, version, previous_version, adapter_dir}` (additive keys; post-step ignores unknown). stdout decides the notice: custom text SUPERSEDES [update].message; a reserved sentinel fires the static [update].message; empty = no notice. exit code orthogonal (0 ok / nonzero failed). Precedence: dynamic-stdout > sentinel/manifest-message > nothing. NO [update.post] declared ⇒ today's adapter_applied→[update].message unchanged; post-step FAILS ⇒ loud warning + fall back to adapter_applied→message. FAILURE-ISOLATED: a committed gh_release pull is never rolled back if the post-step fails (independent channels). (v0.16.0)
2026-07-11T01:39:54.1104503Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1104531Z 
2026-07-11T01:39:54.1104626Z ### REQ-TRANSLATE-COMMAND
2026-07-11T01:39:54.1107907Z - Title: `[message-idle-translation-binary]` accepts a `command` (opaque; args + ADAPTER-STATIC {adapter_dir}/{adapter_name} substitution ONLY — ratified v0.16.0 W1, NOT session {key}: the translation binary is a persistent process serving all sessions on the endpoint (session/event ctx arrives per-message via the stdin Init/Event protocol, never the spawn argv) and the live-update respawn site has no session ctx (a {id}-bearing command would MissingKey→spool); program token resolved against install_dir like [digest].extractor/[session.psyche_init]) in addition to the bare `path`. `path` is DEPRECATED — keeps parsing (manifest forward/back-compat) but emits a registration warning steering to command. Exactly one of {path, command} (both-set refused at registration; neither = no translation binary). The spawn lifecycle + stdin/stdout JSON-lines protocol (Init/Event/Input → key/text/delay_ms/commit) are UNCHANGED — command alters only how the executable+args are located/launched (read_translation_path → read_translation_command). Unblocks folding `claude-spt translate` into the one consolidated binary (downstream ADR-0006). (v0.16.0)
2026-07-11T01:39:54.1108186Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1108268Z 
2026-07-11T01:39:54.1108366Z ### REQ-SEND-REPLYTO-REMOVE
2026-07-11T01:39:54.1109752Z - Title: Remove `--reply-to` from `spt send` — a target-fallback + REPLIED-label nicety that confuses agents, with no wire effect (ADR-0020 already made messages structural (from,body), no __REPLY_TO__). Hard-remove (no deprecation shim): the clap flag, the is_reply/REPLIED label branch (always SENT/QUEUED), the `send` how-to --reply-to example, and the reply-to mention in REQ-DOCS-6's send topic. Reply-correlation stays on the structural `from` attribute. (v0.16.0)
2026-07-11T01:39:54.1109859Z - Required stages: impl, unit
2026-07-11T01:39:54.1109892Z 
2026-07-11T01:39:54.1109986Z ### REQ-DIGEST-CURSOR
2026-07-11T01:39:54.1113520Z - Title: `spt endpoint digest` gains incremental turn-end consumption (extends REQ-TERM-4/5): `--last <N>` = the last N TURNS (the digest's natural unit; --last 1 = the latest turn = turn-end output); a per-entry STABLE SOURCE-DERIVED `seq` in the --json output (deterministic from the entry's append position in the source — transcript record index across the session ledger / digest.log index — so a live re-projection yields the same seq for the same committed entry; NOT a window-position index that renumbers on slide); `--after <seq>` = entries newer than seq still in the window (full window + signal if seq predates it, mirroring the version-slide full-refresh). An in-flight (still-growing) entry is flagged `partial: true` with NO stable seq until finalized (consumer reprocesses partial, skips <= seq). Also emit per-entry `ts` where present (seq is the authoritative dedup+cursor key). The digest's agent text is sufficient fidelity (no raw-source mode). BINDING doc-guidance: an adapter's [digest] extractor / api digest-entry MUST classify delivered user-facing messages as turn-opening `input` (equiv to direct PTY user-input), else messaging-driven sessions collapse into a few giant turns and --last/seq lose granularity. (v0.16.0)
2026-07-11T01:39:54.1113638Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1113673Z 
2026-07-11T01:39:54.1113759Z ### REQ-CLI-JSON
2026-07-11T01:39:54.1115763Z - Title: A global `--json` flag (clap global=true) honored by the READ/STATUS command set: endpoint list/whoami, daemon status, subnet status/show-code, endpoint description/role, adapter list/version, notif list, grant list, access list, shell list, how-to (endpoint digest already has it). Action commands do not honor it. A shared print_json() helper + a coverage TEST asserting every command in the set emits valid JSON (guards against the missing-shared-formatter drift). Output uses explicit per-command output DTOs with committed field names — internal structs are NOT serialized verbatim (their fields would become a public contract; JSON is a consumed wire-parity surface). (v0.16.0)
2026-07-11T01:39:54.1115873Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1115908Z 
2026-07-11T01:39:54.1115994Z ### REQ-RUN-EMPTY-CREATE
2026-07-11T01:39:54.1117247Z - Title: `spt endpoint run` / bare `spt` routes a TOTALLY-EMPTY scope straight to the endpoint-creation flow: when gather_endpoints() is empty (nothing attachable, local OR subnet) PickerModel::new opens on Screen::CreateAdapter instead of PickExisting (today it always opens PickExisting + renders a blank list). A node WITH subnet endpoints but no local ones still has things to pick → stays on the picker. Extends REQ-RUN-PICKER. (v0.16.0)
2026-07-11T01:39:54.1117351Z - Required stages: impl, unit
2026-07-11T01:39:54.1117379Z 
2026-07-11T01:39:54.1117474Z ### REQ-RC-IDENTITY
2026-07-11T01:39:54.1119799Z - Title: `spt rc` overlays a persistent endpoint-identity marker so the operator always groks which endpoint they control: a reserved TOP status row via a DECSTBM scroll-region (shrink the PTY's reported rows by 1, own the row), right-aligned `SUBNET : ENDPOINT_ID @ NODE`, CYAN text. Re-assert the margin + repaint on alt-screen enter / DECSTBM reset / resize (output-scanning, like the existing mouse_scanner). NO window title (the harness, e.g. CC, owns it for busyness — OSC dropped). Resolve subnet/node/id once at attach (perch/registry read) and thread into the pump; subnet = the endpoint's home/primary ("local" if none). The literal floating rounded-rectangle corner box is DEFERRED to the future web-based GUI (not a grid-model rc — that lift is better spent on the GUI). (v0.16.0)
2026-07-11T01:39:54.1120090Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1120114Z 
2026-07-11T01:39:54.1120209Z ### REQ-JOIN-TWO-PHASE
2026-07-11T01:39:54.1123634Z - Title: `spt subnet join` is two-phase (meet-before-code) so the entered code is FRESH at the ceremony regardless of discovery time (ADR-0030). The meet selector is the PUBLIC `(subnet-name, TOTP-epoch)` (rendezvous_token = SHA256(domain ‖ name ‖ totp_step)); the secret TOTP-code is the SPAKE2 password ONLY, never a discovery input — so the code is collected AFTER a member is found. Extend the brain.pair_join event stream (brain.rs:1009): CLI PairMeetReq{subnet} → daemon meets (name, current-epoch) resolving the seed-holder's REAL stable pairing address → MetMember event → CLI prompts the code (cli.rs cmd_subnet_join :6236) → PairCodeSubmit{code} → daemon dials the held real-address on SPT_PAIR_ALPN + SPAKE2 → PairJoined/PairFail. Daemon holds the real-address between phases, bounded by a 5-MINUTE wait-for-code timeout; a wrong-code retry re-runs the CEREMONY ONLY against the held address (no re-search). The non-interactive `--code` path stays one-shot (no prompt; relies on REQ-NET-FAMILY-GATE fast discovery, fails loudly per REQ-JOIN-DIAGNOSTICS on staleness). Security unchanged — the meet is pre-trust/unauthenticated (SPT_PAIR_MEET_ALPN); auth stays in SPAKE2. (next milestone)
2026-07-11T01:39:54.1123775Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1123805Z 
2026-07-11T01:39:54.1123891Z ### REQ-NET-FAMILY-GATE
2026-07-11T01:39:54.1126267Z - Title: spt-core binds only IP families that are actually REACHABLE (ADR-0030), so a half-broken family (e.g. IPv6 whose AAAA resolves but whose path is dead) never silently consumes connection/discovery time. At NetEndpoint::bind (endpoint.rs), probe each family's reachability ONCE and bind only the working ones: dual-stack when both healthy; IPv4-only when IPv6 is dead; IPv6-only when IPv4 is dead (drop the DEAD family — NOT a fixed prefer-IPv4; IPv6-only networks must keep working). Re-evaluated on daemon restart (once-at-bind, no live re-eval in v1). Explicit overrides SPT_DISABLE_IPV6 / SPT_DISABLE_IPV4 force a family off (escape hatch + determinism + testing, mirroring SPT_NTP_SERVER); a forced-off family is never bound regardless of the probe. Reusable beyond join — every spt connection benefits. (next milestone)
2026-07-11T01:39:54.1126376Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1126405Z 
2026-07-11T01:39:54.1126492Z ### REQ-JOIN-DIAGNOSTICS
2026-07-11T01:39:54.1129320Z - Title: `spt subnet join` never fails SILENTLY (ADR-0030; the field incident showed no output at all). (a) LIVE progress during the meet (replace the one-shot "Searching…" cli.rs:6268 with periodic elapsed/deadline) so silence ≠ hang; (b) DETAILED failure on meet-exhaustion — rendezvous candidates + families attempted (IPv4/IPv6) + relay-vs-direct + the last concrete error — surfaced BEFORE any code prompt (a dead subnet must not make the user fetch a code); connect_seed_holder (pairhost.rs:437) and dial_via_rendezvous (meet.rs:281) currently swallow per-attempt errors — thread the last error up with attempt context; (c) PROPAGATE the terminal event — brain.rs:1024 `_ => continue` must deliver a daemon NoSeedHolder/PairFail to the CLI as a printed error (this is WHY the user saw nothing); (d) `--verbose`/`SPT_LOG` discovery TRACE (per-probe derived id, discovery path mDNS/n0-DNS/relay, per-family timeouts), opt-in — no such knob exists today. (next milestone)
2026-07-11T01:39:54.1129599Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1129628Z 
2026-07-11T01:39:54.1129724Z ### REQ-PRESENCE-LIVENESS-TRUTH
2026-07-11T01:39:54.1134476Z - Title: A node's gossiped per-endpoint registry Status reflects real liveness, so a remote viewer never paints a DEAD endpoint as ONLINE. ROOT (confirmed + gated vs CONTEXT.md): registryhost.rs:397-405 advertises a NOT-alive perch as Status::Dormant (the `else` of is_perch_alive), re-stamped every gossip round (never ages to Offline). Design intent GATED vs resting.rs + CONTEXT.md: active/dormant is the MULTI-INSTANCE routing differentiator (active = the bare-id routing target; dormant = a WARM non-target sibling — 'driving ling@laptop makes ling@desktop dormant', resting.rs:97; transitions active→dormant on AttentionShift/Detach). suspended = COLD (session closed, resumable-on-wake) while its NODE is UP. offline = NODE DOWN — NEVER self-gossiped (RestState has no Offline; a live node only ever gossips active/dormant/suspended), remote-inferred via epoch-lease eviction. So labeling a NOT-running perch Dormant is the DEFECT (dormant requires warm/running). PRIMARY FIX (registryhost `else`, not-bound-alive): live-but-UNBOUND (has a live broker session; is_perch_alive is bound-gated) → Active/Dormant (still warm); else (cold, no live session, but its node is up because this very daemon is gossiping) → SUSPENDED — NOT Dormant, NOT Offline (the node is UP; Offline is never self-gossiped). This alone removes the false-ONLINE. dormant keeps gossiping (routing/MRA needs it) but RENDERS as its online flavor (no distinct glyph; the dormant→suspended auto-suspend timer disambiguates recency). The DISPLAY of these states (incl Suspended=gray-filled) is REQ-SUBNET-DISPLAY-PARITY. Design: docs/design/subnet-presence-display.md §A. (next milestone)
2026-07-11T01:39:54.1134641Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1134678Z 
2026-07-11T01:39:54.1134778Z ### REQ-SUBNET-DISPLAY-PARITY
2026-07-11T01:39:54.1138938Z - Title: The `spt endpoint run` picker renders endpoint state IDENTICALLY for local and remote (subnet) rows — bound/unbound, controlled (+driver node), and harness-only are all visible across the subnet, not local-only. Today data.rs:293-294 reduces a remote row to plain green-filled/gray-hollow because those facts aren't propagated. (1) GOSSIP additive per-Instance fields: bound/unbound, controlled + driver-node, harness_only (Offline is never gossiped — node-down is remote-inferred). (2) Derive the full EpDisplay for subnet rows from the gossiped fields, same path as local (remove the remote-reduction). (3) PALETTE rework (fill = ACTIONABLE: filled=can act now (rc-control if online, WAKE if suspended-on-live-node) / hollow=cannot (no control seat / node gone)): green-filled=online+bound+free; blue-filled=online+controlled (desc shows `controlled by <node>`); RED-filled=online+UNBOUND (controlled-or-not; controlled-ness shown via available options not glyph) — replaces green-hollow Unbound + absorbs the dropped UnboundControlled; AMBER-HOLLOW=online+harness-only (no broker seat → can't rc) — was amber-FILLED; GRAY-FILLED=Suspended (cold, node up — wakeable) NEW; gray-hollow=Offline (node down) now REMOTE-ONLY. EpDisplay: drop UnboundControlled, Unbound→red-filled, HarnessOnly→amber-hollow, add Suspended(gray-filled). Picker maps Active|Dormant→online flavor, Suspended→gray-filled, Offline→gray-hollow. (next milestone)
2026-07-11T01:39:54.1139143Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1139171Z 
2026-07-11T01:39:54.1139268Z ### REQ-UPDATE-FETCH-CURRENT-UX
2026-07-11T01:39:54.1142125Z - Title: `spt update fetch` reports an already-staged / already-applied latest as an ACTIONABLE human outcome (exit 0), not a Debug-formatted error. ROOT: cmd_update_fetch (cli.rs) sets the rollback floor = staged_version, so when the published candidate == the already-staged version, verify_update_set_metadata returns Err(RejectReason::Rollback{current,candidate}) — printed as {reason:?} (Debug) at exit 1, reading as a FAILURE when the update is merely already downloaded and just needs `spt update apply` (this bit the operator: fetch kept 'failing', apply was the missing step). FIX: a PURE classifier (reason, applied, staged) -> {AlreadyStaged (latest downloaded, not yet installed) / AlreadyApplied (up to date) / GenuineError}; already-staged + already-applied print a friendly message and exit 0; genuine rejects use RejectReason's Display (release.rs, not Debug) + exit 1 — applied at ALL THREE fetch reject sites (metadata + artifact-verify + plan-verify). (v0.18.0)
2026-07-11T01:39:54.1142425Z - Required stages: impl, unit
2026-07-11T01:39:54.1142450Z 
2026-07-11T01:39:54.1142545Z ### REQ-UPDATE-FETCH-APPLY-FLAG
2026-07-11T01:39:54.1145140Z - Title: `spt update fetch --apply` is the one-shot get-to-latest: fetch, then INSTALL the staged update REGARDLESS of whether the fetch itself staged anything new — so the brittle `fetch && apply` chain (which broke when fetch no-oped / exited nonzero on an already-staged latest, skipping the chained apply) is unnecessary. Composes with REQ-UPDATE-FETCH-CURRENT-UX: the end state is 'installed latest', reached idempotently from new-staged -> apply / already-staged (applied<candidate) -> STILL apply / already-applied -> noop+exit0 / genuine error (bad signature, no artifact for platform, true downgrade, network) -> do NOT apply, propagate the error + nonzero. Reuses the existing cmd_update_apply core (its own verify + two-phase + auto-rollback own correctness; no duplicated swap/respawn). Additive clap flag (plain doc-comment, no internal codes); reference.md regenerated. (v0.18.0)
2026-07-11T01:39:54.1145253Z - Required stages: impl, unit
2026-07-11T01:39:54.1145281Z 
2026-07-11T01:39:54.1145382Z ### REQ-UPDATE-RUNNING-IMAGE-SURFACE
2026-07-11T01:39:54.1148578Z - Title: `spt` surfaces the RUNNING broker image version beside the on-disk version so an updated-looking node reveals broker-side dormancy. ROOT (F-025): `spt update apply` restarts the BRAIN only (ADR-0018 D3-3) — the BROKER process survives and keeps running its pre-apply compiled image, so every broker-side surface of a freshly-applied release (the F015B live-apply matcher, dispatch inject legs, etc.) is silently dormant until a full daemon bounce, with nothing in the CLI revealing the split. FIX: the running broker SELF-REPORTS its compiled image version over IPC (a new request KIND answered by the live broker process from its own compiled build constant) — HARD CONSTRAINT: the version comes FROM the running broker process, NEVER inferred from disk bytes, install manifest, or file timestamps, since the disk is exactly the half that is already ahead; a version-surface command (`spt version` and/or `spt daemon status`) prints the running-broker version beside the on-disk/product version and flags a mismatch. Keeps read-side truth independent of write-side claims (the field lesson from F015B). (F-025)
2026-07-11T01:39:54.1148703Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1148731Z 
2026-07-11T01:39:54.1148835Z ### REQ-UPDATE-APPLY-RESTART-NOTICE
2026-07-11T01:39:54.1150854Z - Title: `spt update apply` prints a LOUD restart-required notice whenever the surviving broker will keep running the pre-apply image (which, until broker-restart choreography exists, is ALWAYS on a successful apply). Public wording, no internal CODE:RESULT markers (composes with REQ-ADAPTER-UPDATE-MESSAGE / the update-apply-confident-message rule) — name the user-visible CONSEQUENCE ('daemon-coordinated features run the previous version until the daemon restarts'), not the broker/brain internals. Composes with REQ-UPDATE-RUNNING-IMAGE-SURFACE (the notice tells the user what the version-surface will then show, and how to clear it). (F-025)
2026-07-11T01:39:54.1150959Z - Required stages: impl, unit
2026-07-11T01:39:54.1150982Z 
2026-07-11T01:39:54.1151092Z ### REQ-UPDATE-APPLY-ALREADY-APPLIED
2026-07-11T01:39:54.1153380Z - Title: `spt update apply` classifies an already-staged / already-applied state as a friendly exit-0 no-op instead of dying at the binary-aside rename with 'Access is denied (os error 5)'. ROOT (F-025): a second apply on an already-applied staged version reaches the two-phase binary-aside rename and fails os-error-5, reading as a hard failure when the machine is simply up to date. FIX: apply gains the same pure classifier `fetch` got in v0.18.0 (REQ-UPDATE-FETCH-CURRENT-UX) — already-applied → clear message + exit 0, and the flow MUST short-circuit BEFORE the binary-aside rename in that state; mirror the classifier at ALL apply reject/entry sites the way the fetch fix covered its three. Genuine errors (bad signature, wrong platform, true downgrade, network) still propagate nonzero. (F-025)
2026-07-11T01:39:54.1153659Z - Required stages: impl, unit
2026-07-11T01:39:54.1153687Z 
2026-07-11T01:39:54.1153798Z ### REQ-BROKER-ATTACH-JOURNAL-RESILIENT
2026-07-11T01:39:54.1156459Z - Title: A poisoned EffectJournal mutex or a sick NetHost runtime must NOT permanently brick all future attaches. Bug #16 (URGENT): a live spt-hosted endpoint (eel-a) attach fails with 'brain IPC read deadline elapsed' after a self-update brain-respawn — the broker survives the respawn and one journaled op (dispatch_net_stream_open journal.apply_once + loopback open_stream runtime.block_on nethost.rs:1060) enters a bad state, so every journaled attach silently kills its per-conn reply thread while non-journaled ops keep working. Fix: recover PoisonError via into_inner (effect.rs apply_once, replace the .expect panics) so one panic cannot brick all attaches; bound the loopback open_stream block_on (nethost.rs:1060) like the QUIC bounded_block_on so a sick runtime fails fast with an error frame not an opaque 10s deadline. Reinforces REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #16.
2026-07-11T01:39:54.1156574Z - Required stages: impl, unit
2026-07-11T01:39:54.1156598Z 
2026-07-11T01:39:54.1156693Z ### REQ-WAN-SEND-DELIVERY
2026-07-11T01:39:54.1158872Z - Title: Bug #9/#10: cross-node spt send reports SENT(WAN) but does not deliver, even on stable-IP pairs. Real root: spt send resolves the dial with id-only addr_for_node_hex (endpoint.rs:538) which forces a fresh iroh discovery round-trip every send, while the gossip pump uses cached direct addresses (dial_seeded/PeerAddrStore) so gossip stays green but send rides a marginal discovery path that cannot carry the fire-and-forget payload; the handshake completes so SENT(WAN) prints falsely. Fix: (1) route the WAN dial through the pump seeded-direct-address resolution (PeerAddrStore first, id-only fallback); (2) receiver writes its WanOutcome back so the sender confirms delivery under the QUIC deadline and only reports SENT on confirmed delivery, honest failure otherwise. Access-gate/perch/spool all verified correct (ruled out). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #9-10.
2026-07-11T01:39:54.1159066Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1159095Z 
2026-07-11T01:39:54.1159196Z ### REQ-RC-CROSS-NODE-ATTACH
2026-07-11T01:39:54.1161177Z - Title: Bug #4: spt rc to a remote endpoint fails with 'no live session' though endpoint list shows it Active — rc.rs:1063 resolves only the LOCAL broker session table and always dials loopback, never consulting the registry or dialing the owning node (the cross-node attach transport exists in the broker; only the client leg is missing). Fix: on a local resolve miss, resolve the owning node from the registry (reuse resolve_across_visible), net_dial that node, and run a remote session-resolve + serve_attach round-trip (mirror the wansend resolve-dial-round-trip pattern). Shares the resolve-owning-node primitive with REQ-WAN-SEND-DELIVERY. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #4.
2026-07-11T01:39:54.1161294Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1161318Z 
2026-07-11T01:39:54.1161414Z ### REQ-RC-WIN-VT-OUTPUT
2026-07-11T01:39:54.1164805Z - Title: Bug #12: `spt rc` to an endpoint renders ANSI escapes LITERALLY (raw ←[K / color codes) on a Win10 conhost console, garbling the viewport — while `endpoint run --attach` in the SAME env renders fine and Win11 Windows Terminal is unaffected. Root (code-grounded, doyle): rc.rs RawGuard::enable calls only crossterm enable_raw_mode (INPUT raw mode) and NEVER enables ENABLE_VIRTUAL_TERMINAL_PROCESSING on the OUTPUT handle; Win10 conhost defaults VT-output OFF so escapes print literally, whereas the picker/alt-screen setup on the endpoint-run path enters crossterm's VT-enabling console setup first (leaving VT-output on) — so it is the rc-attach CLIENT PATH specifically, and --attach-works-same-env confirms (not refutes) the VT-out theory. Fix: in the rc attach path (RawGuard), on cfg(windows) + interactive console (mirror the windows_mouse_wanted guard so piped stdin/stdout keeps clean bytes for the e2e byte tests), SetConsoleMode STD_OUTPUT_HANDLE |= ENABLE_VIRTUAL_TERMINAL_PROCESSING|ENABLE_PROCESSED_OUTPUT, capture the prior mode, restore on Drop. cfg(windows)-only, client-side, independent of #4/#6. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #12.
2026-07-11T01:39:54.1165120Z - Required stages: impl, unit
2026-07-11T01:39:54.1165148Z 
2026-07-11T01:39:54.1165240Z ### REQ-GOSSIP-CONTROLLED-ANY
2026-07-11T01:39:54.1167230Z - Title: Bug #3: a locally-controlled endpoint gossips controller_node = None so remote viewers show it free to control. Root: driven_by is stamped Some(node) only for a REMOTE WAN attach (attach.rs:337); a local controller is by=None by design (broker.rs:1750, KH 7.15 — a local-only controller must not latch driven_by). Fix: broker stamps a SEPARATE any-controller datum (true/Some(host) for a local OR remote controller) alongside stamp_driven_by, and advertise_local gossips Instance controller_node from it, leaving the remote-only driven_by untouched (do not trip REQ-HAZARD-DRIVEN-BY-SELFHEAL). node-refresh is NOT the fix (data is absent at source). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #3.
2026-07-11T01:39:54.1167329Z - Required stages: impl, unit
2026-07-11T01:39:54.1167362Z 
2026-07-11T01:39:54.1167459Z ### REQ-SUBNET-COUNT-ROUTABLE
2026-07-11T01:39:54.1169278Z - Title: Bug #2: a remote node endpoint count drifts (0/2, 1/3) because node_status_rows (cli.rs:5314) increments the per-node total unconditionally, counting non-routable Offline ghost rows; purge is not a registry eviction (it gossips a one-shot Offline row that is immortal on remote viewers — eviction is per whole-node only). Fix: routable-only denominator (total += status.routable()) keeping a separate raw count for the all-Offline liveness branch; plus per-row Offline-TTL eviction so purged endpoints stop accumulating on remote snapshots. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #2.
2026-07-11T01:39:54.1169379Z - Required stages: impl, unit
2026-07-11T01:39:54.1169407Z 
2026-07-11T01:39:54.1169503Z ### REQ-BROKER-SCREEN-GRID
2026-07-11T01:39:54.1171999Z - Title: Bugs #6 + #12 + #7/#8-artifacts: the broker is a raw-byte pump with no screen model — OutputLog replays the raw ring from seq 0 into a fresh terminal on attach, so an alt-screen TUI (Claude Code) corrupts scrollback (#6) and rc-to-a-pre-running-endpoint garbles (#12 — rc and endpoint run --attach are the SAME client fn, so it is replay content not a client-VT bug). Fix: a server-side VT/grid/screen model (tmux/mosh-style) that maintains authoritative screen + alt/main + cursor and synthesizes a CLEAN current-screen repaint on attach instead of replaying mid-stream ring bytes. Also eliminates residual-cell artifacts on animate/scroll/resize (#7/#8). Operator NON-NEGOTIABLE: accurate PTY representation with zero artifacts. (win32 vterm in the report means this server-side emulator, not ConPTY which is already the backend.) See docs/NEXT-MILESTONE-BUG-TRIAGE.md #6/#12.
2026-07-11T01:39:54.1172117Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1172145Z 
2026-07-11T01:39:54.1172236Z ### REQ-RC-IDMARKER-DISABLE
2026-07-11T01:39:54.1173620Z - Title: Bugs #14 + #7/#8 (marker half): feature-flag the top-right StatusRow endpoint-id marker OFF (rc.rs:198-307). It is a one-shot absolutely-positioned paint that scrolls off-screen and is not re-stickied (#14), and its DECSC/clear/SGR injection splices into the harness in-flight drawing causing residual artifacts (#7/#8). Ship disabled next release (operator: save the concept for a future web SPT GUI); revisit as a proper per-frame sticky overlay only once REQ-BROKER-SCREEN-GRID provides the screen model. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #14.
2026-07-11T01:39:54.1173925Z - Required stages: impl, unit
2026-07-11T01:39:54.1173953Z 
2026-07-11T01:39:54.1174048Z ### REQ-ENDPOINT-LIST-PALETTE
2026-07-11T01:39:54.1176576Z - Title: Bugs #11 + #15 (display): spt endpoint list renders status as plain text while the picker turns the same ResourceRow into the W5 colored EpDisplay palette. Fix: extract one shared ResourceRow-to-EpDisplay builder + make the picker display enums/helpers public, and have endpoint list render the same colored status squares (via helpfmt stdout_color, not ratatui Span). This also fixes #15 — a lone warm detached instance renders as its online flavor (Dormant maps to online) instead of leaking the bare word Dormant through the text-only list (no resting.rs/CONTEXT model change; operator ruling display-only). Couples REQ-PICKER-NODE-GROUPING (both edit subnet_rows — sequence the shared-builder extraction first). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #11/#15.
2026-07-11T01:39:54.1176692Z - Required stages: impl, unit
2026-07-11T01:39:54.1176730Z 
2026-07-11T01:39:54.1176858Z ### REQ-PICKER-NODE-GROUPING
2026-07-11T01:39:54.1178218Z - Title: Bug #13: the endpoint run Subnet tab shows a machine once PER shared subnet (subnet_rows data.rs:253 iterates per-subnet, groups by subnet:node, no cross-subnet dedup). Fix: dedup by (node, endpoint_id) across the subnet loop, collect the set of shared subnet names per endpoint, emit one group per MACHINE (group = node_display) with its shared subnets listed beneath the machine name; reconcile per-endpoint status across subnets (most-alive). Couples REQ-ENDPOINT-LIST-PALETTE (both edit subnet_rows). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #13.
2026-07-11T01:39:54.1178319Z - Required stages: impl, int
2026-07-11T01:39:54.1178353Z 
2026-07-11T01:39:54.1178452Z ### REQ-ENDPOINT-LIST-NODE-GROUPED
2026-07-11T01:39:54.1182786Z - Title: spt endpoint list is node-grouped over unique INSTANCES, not subnet-grouped over duplicated rows: one row per (id,node) instance — subnet duplication collapsed (ADR-0006 §1: subnet is never an identity axis), freshest-epoch wins a cross-subnet status disagreement (the resolve_among twin rule) — grouped under 'This node: <label>' (cyan; local roster is the status truth, advertised-status vocabulary, corrupt = suspended + corrupt annotation) then remote nodes alphabetical (node name orange 38;5;208, the legacy $LIVE orange), each node carrying a light-gray 'Shared subnets:' line (subnets among our memberships where that node gossips any visible row; per-instance subnet detail stays in --json/--detail), instance rows [id, endpoint_type, glyph, status] (endpoint_type threaded from Instance.endpoint_type through ResourceRow — additive, pre-field rows render '-'), per-node 'Total:' lines with NO grand total (the stderr ENDPOINTS:<n> line is REMOVED — it counted subnet rows, so the same instance in N subnets counted N times), SELF pin kept first with a '(self @ <node>)' marker (REQ-WHOAMI-1 alias; self also appears as a This-node row so the node total stays honest), remote nodes with zero visible instances skipped, --subnet narrows the union to that subnet's view, --json DTO structure UNCHANGED (committed surface; gains only an additive endpoint_type field). Grill-with-docs ruling 2026-07-02 (operator + doyle); sibling of REQ-PICKER-NODE-GROUPING (the picker half of the same dedup law).
2026-07-11T01:39:54.1182906Z - Required stages: impl, unit
2026-07-11T01:39:54.1182935Z 
2026-07-11T01:39:54.1183029Z ### REQ-ENDPOINT-LIST-REST-FILTER
2026-07-11T01:39:54.1185431Z - Title: spt endpoint list hides SUSPENDED instances by default; a new --show-all flag reveals them. Status-first row ordering with fixed precedence ONLINE > CONTROLLED > UNBOUND > SUSPENDED (when shown) > corrupt last, alphabetical by id within each band. Two invariants: (1) CORRUPT rows ALWAYS render regardless of filters — corrupt is a record condition demanding operator action (purge/re-mint), not resting clutter; hiding it would re-create counter-39 bug #3 (cross-ref REQ-HAZARD-CORRUPT-PERCH-COHERENCE, CONTEXT.md instance-state _Also avoid_); (2) the per-node Total line DISCLOSES the filter — 'Total: N (+M suspended hidden)' — so nothing silently vanishes. Registry-Offline rows stay excluded by projection law (resource_projection skips unroutable; unchanged). Grill-with-docs ruling 2026-07-02 (operator + doyle).
2026-07-11T01:39:54.1185736Z - Required stages: impl, unit
2026-07-11T01:39:54.1185764Z 
2026-07-11T01:39:54.1185868Z ### REQ-ADAPTER-UPDATE-INPLACE
2026-07-11T01:39:54.1187286Z - Title: Bug #18: spt adapter update fails at re-register with os error 2 because it derives the install dir from the update repo NAME (_github/<safe>) instead of updating in place at the adapter record source_dir; when the adapter repo is intentionally renamed across releases (spt-claude-code to claude-spt, supported), the derived dir is fresh/empty and re-register reads a missing manifest. Fix: adapter update installs and re-registers in place at the registered source_dir and tolerates a changed update repo/URL across a rename. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #18.
2026-07-11T01:39:54.1187395Z - Required stages: impl, unit
2026-07-11T01:39:54.1187422Z 
2026-07-11T01:39:54.1187517Z ### REQ-DIGEST-PROFILE-ENV
2026-07-11T01:39:54.1190225Z - Title: Bug #17: spt endpoint digest returns NO_DIGEST for a ccs-profile endpoint (claude-spt:ccs) though [digest] is wired and the transcript exists — under .ccs (CLAUDE_CONFIG_DIR relocation) not .claude. The on-demand digest runs the extractor in the daemon context WITHOUT the endpoint profile transcript-location env, so the env-aware resolver cannot find the relocated transcript. Fix: propagate/persist the endpoint profile transcript-location env (e.g. the ccs CLAUDE_CONFIG_DIR) to the on-demand digest extractor so a profile-relocated transcript resolves; confirm the exact extractor verdict via spt adapter digest-proof. Ownership spt-core (digest env/profile propagation), possibly with a claude-spt extractor-resolver assist. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #17.
2026-07-11T01:39:54.1190417Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1190446Z 
2026-07-11T01:39:54.1190542Z ### REQ-DIGEST-FETCHER-STRATEGY
2026-07-11T01:39:54.1194219Z - Title: Bug #17 (W6b, closes eel-a end-to-end): [digest] gains a `fetcher` strategy mirroring [history]'s locate/normalize split (CONTEXT §history: [digest] mirrors history's two strategies — locate ownership). ROOT: the pre-W6b [digest] had only the locate_normalize analog (spt-core resolves ONE `source` template + pre-reads the file), which CANNOT express a PARTITIONED transcript layout — CC's projects/<munge(cwd)>/<session_id>.jsonl or a date-globbed rollout tree — the exact case CONTEXT already assigns to the adapter. spt-core (correctly) provides NO {project}/slug key (harness-specific cwd munging = the charter violation FIX-A was rejected for). Fix: strategy = fetcher makes the ADAPTER's extractor locate + read + emit normalized records; spt-core runs it bounded (no locate, no pre-read, no stdin) and consumes stdout, feeding only the harness-NEUTRAL inputs it owns — {session_id}, the perch-bound {cwd} (info.json.cwd), and the captured [env] direction=read vars (W6/REQ-DIGEST-PROFILE-ENV) — so the extractor globs the unique {session_id} under {read-var-root}/projects/ with no slug. Keeps locate_normalize (default, back-compat) for a trivial single-file harness. Distinct capability from REQ-DIGEST-PROFILE-ENV (which supplies the root env). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #17.
2026-07-11T01:39:54.1194335Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1194363Z 
2026-07-11T01:39:54.1194463Z ### REQ-ADAPTER-ADD-SURFACE-ERRORS
2026-07-11T01:39:54.1196033Z - Title: Bug #1: adapter add runs the install-as-first-update via conduct (cli.rs:6963) which on a non-zero exit prints only the exit code and DISCARDS the subprocess stdout/stderr, so the real error is invisible (the failure itself does propagate). Fix: include out.stderr/stdout in the ADAPTER_INSTALL_FAIL message (mirror run_update_post_step). Operator ruling: ALSO run the [update.post] composite step at install-time (today it runs only on explicit adapter update), so an install both surfaces detail and completes the delegated post-step. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #1.
2026-07-11T01:39:54.1196185Z - Required stages: impl, unit
2026-07-11T01:39:54.1196214Z 
2026-07-11T01:39:54.1196315Z ### REQ-ENDPOINT-LIST-NODE-IDENT
2026-07-11T01:39:54.1197645Z - Title: Bug #5: spt endpoint list local section header is the hardcoded literal LOCAL (this node) (render_local_section cli.rs:4359). Change to 'This node: <node-id>' using the existing node-ident idiom (os_hostname + nodeid public-key prefix, cli.rs:5531 — factor a node_ident_display helper); compute in the impure print_local_section, pass into the pure renderer. Update the two test assertions (cli.rs:10711/10716). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #5.
2026-07-11T01:39:54.1197754Z - Required stages: impl, unit
2026-07-11T01:39:54.1197778Z 
2026-07-11T01:39:54.1197889Z ### REQ-HAZARD-CONTROL-STAMP-LIFETIME
2026-07-11T01:39:54.1200475Z - Title: #2: a control/viewer stamp never outlives its session — every teardown path clears what attach stamped. The broker exit-waiter (broker.rs ~:1844) sends the exit frame + sessions.remove(&id) but does NOT clear the perch's controller/viewer stamps; clear_controller()->stamp_driven_by() (clears driven_by+controlled) runs ONLY on controller-detach/evict/displace. /exit kills the CHILD not the controller conn, so the OutputLog drops with controlled:true, viewer_count, (and driven_by for a remote controller) latched in info.json forever — and hfenduleam keeps gossiping controller_node=self cross-node. Fix: on session reap, clear the perch's controller/viewer stamps (set_driven_by(None)+set_controlled(false)+set_viewer_count(0) via the known endpoint id) — broker stays the single writer. KNOWN-HAZARDS invariant. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #2.
2026-07-11T01:39:54.1200593Z - Required stages: doc, impl, int
2026-07-11T01:39:54.1200621Z 
2026-07-11T01:39:54.1200727Z ### REQ-PICKER-CONTROLLED-LOCAL
2026-07-11T01:39:54.1203161Z - Title: #3 local half: a LOCALLY-controlled endpoint renders CONTROLLED in its own node's picker. display_status() (crates/spt/src/picker/model.rs:415) derives Controlled ONLY from driven_by.is_some(), but driven_by is REMOTE-only by design (KH 7.15) — a locally-controlled endpoint has driven_by=None + controlled=true, and local_rows (data.rs:220) never threads controlled into EndpointRow, so a locally-RC'd endpoint shows plain ONLINE in its own picker (remote rows are fine — gossip stamps controller_node=self, REQ-GOSSIP-CONTROLLED-ANY; the asymmetry is the bug). Fix: EndpointRow gains controlled:bool (local: rec.controlled; remote: controller_node.is_some()); display_status -> Controlled when driven_by.is_some()||controlled; desc pane says 'controlled locally' when the driver is unnamed. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #3.
2026-07-11T01:39:54.1203370Z - Required stages: impl, unit
2026-07-11T01:39:54.1203393Z 
2026-07-11T01:39:54.1203511Z ### REQ-PICKER-PROJECT-HISTORY-TRUTH
2026-07-11T01:39:54.1206123Z - Title: #1: picker project history is derived from sessions.log cwds (newest->oldest, deduped by project_id_for_dir) UNION context-store branches, EXCLUDING owlery-internal paths (any cwd under spt_home()/owlery) everywhere a project is displayed or inferred. Fixes three stacked defects (crates/spt/src/picker/data.rs): (1a) project_history_for (data.rs:372) reads ONLY context-store p-* branches, which are empty on this box -> history []; (1b) the fallback origin project (data.rs:207) is derived from info.json.cwd = latest-boot-cwd (rewritten every rebind), not origin; (1c) psyche-host sessions bind owlery-internal cwds that pollute history. Full DIRS stay available in the model (feature #5 needs them). PROJECT REPRESENTATION RULING (operator 2026-07-03): project IDs ONLY, EVERYWHERE incl local display; on ID collision disambiguate minimally via a PURE disambiguate_project_ids(entries)->display-names fn (append one-level-up parent folder and/or root drive letter, e.g. 'spt-core (projects)' vs 'spt-core (D:)'). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #1.
2026-07-11T01:39:54.1206321Z - Required stages: impl, unit
2026-07-11T01:39:54.1206350Z 
2026-07-11T01:39:54.1206450Z ### REQ-STORE-CONTEXT-BRANCH-FILL
2026-07-11T01:39:54.1207937Z - Title: #1 SI-1 (RCA, operator-promoted 2026-07-03): the context store (tracked/.seed.git) holds ZERO p-* branches on a box with months of live-agent use, while kitsubito/enlyzeam stores carry them. Context commits never land -> picker history has no store source (REQ-PICKER-PROJECT-HISTORY-TRUTH's fallback ships regardless, but the store must ALSO fill). RCA the contextstore write->branch-commit path with evidence (commune-ingest/context-commit regression vs store re-init), contrast the healthy stores, land whatever fix the RCA names. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #1 SI-1.
2026-07-11T01:39:54.1208043Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1208067Z 
2026-07-11T01:39:54.1208172Z ### REQ-GOSSIP-ADAPTER-PROJECTS
2026-07-11T01:39:54.1210590Z - Title: #4: remote endpoint details (harness + project history) are gossiped, not faked. Today from_resource_row (crates/spt/src/picker/model.rs:340) hardcodes project_history=Vec::new() for every remote row and passes adapter_profile=row.resources (the blurb masquerading as the harness), and Instance/ResourceRow (crates/spt-net/src/net/registry.rs:457) carry no adapter field and no project list. Fix: additive gossip fields N-1-safe exactly like endpoint_type — Instance.adapter (composite <adapter>[:profile]) + Instance.recent_projects (bounded, newest-first, project IDs only) -> thread to ResourceRow -> from_resource_row stops faking. Pre-field remote rows render '-'. Project IDs only + REQ-PICKER-PROJECT-HISTORY-TRUTH's disambiguation. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #4.
2026-07-11T01:39:54.1210696Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1210725Z 
2026-07-11T01:39:54.1210824Z ### REQ-ENDPOINT-LIST-PROJECT-COL
2026-07-11T01:39:54.1212678Z - Title: #8: spt endpoint list gains a second column <project>/ (the endpoint's LATEST project) -> 4 columns total: id / <project>/ / type / status. Local rows: head of REQ-PICKER-PROJECT-HISTORY-TRUTH (sessions.log-derived, owlery-excluded). Remote rows: head of REQ-GOSSIP-ADAPTER-PROJECTS recent_projects. Project IDs only + #4 disambiguation; '-' when unknown (pre-field remote rows). Extends the v0.21.0 node-grouped renderer (format_instance_rows — additive column, alignment char-width-safe). --json: additive project field on the row DTO (skip-if-none, N-1 safe). Depends on #1 + #4. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #8.
2026-07-11T01:39:54.1212898Z - Required stages: impl, unit
2026-07-11T01:39:54.1212927Z 
2026-07-11T01:39:54.1213016Z ### REQ-API-ENDPOINT-INFO
2026-07-11T01:39:54.1216212Z - Title: #7: spt api endpoint-info [<id>] (JSON) lets an endpoint learn its ATTACHED (controlling) node — claude-spt surfaces local + attached node names on UserPromptSubmit so the agent knows whether getting a file to the user needs extra steps (user RC'd in from another machine). spt api * is the harness-contract agent-facing surface (JSON-first, rides perch identity/auth so the bare no-<id> form self-resolves like whoami). Payload (committed DTO, additive-forever): { id, endpoint_type, adapter, local_node:{label,key}, attached_node:{label,key}|null, controlled:bool, project:<current project id>, cwd, subnets:[...] } — attached_node from controller stamps (driven_by remote / self-node when controlled with no remote driver), null when uncontrolled. HARD dependency on #2 + #3 (stamps must be honest first). Adapter-side consumable -> perri release-ping on publish. Naming: chose 'spt api endpoint-info' over alt 'spt endpoint get-info' — api is the agent surface (doc rationale). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #7.
2026-07-11T01:39:54.1216404Z - Required stages: impl, unit
2026-07-11T01:39:54.1216433Z 
2026-07-11T01:39:54.1216532Z ### REQ-PICKER-START-PROJECT-CHOICE
2026-07-11T01:39:54.1218332Z - Title: #5: after 'Start now' in the endpoint picker, swap the bottom Options panel to a 'Choose project' list: (1) the endpoint's most recent project dir, (2) 'Here: <dir>' — the spt endpoint run cwd (only if different), (3) all other project-history dirs newest->oldest. Fire the step ONLY when (A) the run cwd mismatches a singular history entry, or (B) history has >1 entry; otherwise start immediately (today's behavior). Depends on REQ-PICKER-PROJECT-HISTORY-TRUTH (needs full DIRS from sessions.log, owlery-internal exclusion applies). Start-now is local-only (no gossip). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #5.
2026-07-11T01:39:54.1218469Z - Required stages: impl, unit
2026-07-11T01:39:54.1218497Z 
2026-07-11T01:39:54.1218593Z ### REQ-PICKER-RESUME-CONTEXT-PANEL
2026-07-11T01:39:54.1219782Z - Title: #6: the 'Resume from history' view keeps the endpoint's 'Confirm selection' top panel and swaps ONLY the bottom panel to 'Resume from a prior session' — the user stays contextually informed about what they're picking (today the resume view replaces the whole screen). crates/spt/src/picker/view.rs (resume screen) + model screen state. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #6.
2026-07-11T01:39:54.1219882Z - Required stages: impl, unit
2026-07-11T01:39:54.1219910Z 
2026-07-11T01:39:54.1220012Z ### REQ-MSG-SELF-DETECT-ANCESTRY
2026-07-11T01:39:54.1223238Z - Title: #9 (F026, operator field bug): a perch-owned `spt send` from an endpoint's OWN session must self-identify, not mis-stamp `cli@<node>` (whose replies bounce NO_PERCH). ROOT: roster::detect_self_id (roster.rs) was ENV-ONLY — OWL_SESSION_ID matched to info.session_id, else SPT_AGENT_ID — but an agent-session Bash child often carries NEITHER (the env export is spawn-path-dependent), so a perch-owned sender was classified bare-CLI and REQ-MSG-CLI-ORIGIN stamped it cli@<node> (the stamp works as designed on a wrong premise; that REQ's evidence stays intact). FIX: detect_self_id gains leg (c) PID-ANCESTRY fallback AFTER the env legs — walk THIS process's ancestry, match a live non-corrupt roster perch's recorded harness pid (info.json.pid Numeric, alive-gated via is_process_alive, corrupt/BUSY skipped), first match = self. from-LABEL / routing default ONLY, NOT authentication — authenticate() is untouched (pid-ancestry-for-AUTH stays parked per F-024 with its Windows pid-spoof caveats; a display/routing stamp has no such bar). Best-effort: a broken ancestry walk degrades to None → cli-stamp, never errors the send.
2026-07-11T01:39:54.1223448Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1223477Z 
2026-07-11T01:39:54.1223629Z ### REQ-CLI-BROKEN-PIPE-TOLERANT
2026-07-11T01:39:54.1225352Z - Title: #10 (F026 micro): `spt <anything> | <pager/Select-First-N>` must not PANIC when stdout closes early. A closed downstream reader mid-print panics with 'failed printing to stdout: The pipe is being closed. (os error 232)' (live repro: `spt daemon status | Select -First N`). Fix: tolerate BrokenPipe process-wide — a write to a closed stdout exits 0 (SIGPIPE-equivalent: a consumer that stops reading is a normal end, not a crash), without leaking a Rust panic + backtrace to the user.
2026-07-11T01:39:54.1225452Z - Required stages: impl, unit
2026-07-11T01:39:54.1225481Z 
2026-07-11T01:39:54.1225580Z ### REQ-XTASK-SPT-BIN-TARGET-DIR
2026-07-11T01:39:54.1227770Z - Title: #13 (F026 micro, tooling): xtask `spt_bin()` (crates/xtask/src/main.rs) BUILDS `spt` via cargo (which honors CARGO_TARGET_DIR) but returns a HARDCODED `<root>/target/debug/spt` path — so under a redirected target dir (CI / isolated-gate rigs that set CARGO_TARGET_DIR to a throwaway) the binary lands in `$CARGO_TARGET_DIR/debug` while xtask looks in `<root>/target/debug` -> NotFound -> `xtask check` (docs-drift gate) spuriously fails. Workaround was running `xtask check` with CARGO_TARGET_DIR unset. FIX: a pure `target_debug_dir(root, CARGO_TARGET_DIR)` seam mirroring cargo's resolution — absolute override as-is, relative resolved against `root` (the dir cargo is invoked in), default `<root>/target` — join `debug`; `spt_bin` returns from it. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md.
2026-07-11T01:39:54.1227971Z - Required stages: impl, unit
2026-07-11T01:39:54.1228000Z 
2026-07-11T01:39:54.1228109Z ### REQ-HAZARD-CONTROL-STAMP-CONVERGENCE
2026-07-11T01:39:54.1232418Z - Title: Control/viewer stamps must CONVERGE to broker session-table truth for every session-backed endpoint, not merely edge-trigger — the UPWARD companion to the DOWNWARD edge-clear REQ-HAZARD-CONTROL-STAMP-LIFETIME (7.27); same 'stamps == broker truth' family. ROOT (F-026 stamp-gap, hall-b/ball-b): a picker-created endpoint's broker spawn become_controller->stamp_driven_by->set_controlled(true) fires BEFORE the adapter binds its perch (a fresh endpoint has no perch until claude boots + binds), so mutate_info returns NotFound and the edge stamp is SWALLOWED (let _); the adapter's bind then writes InfoJson::new with controlled:false DEFAULT and no later edge re-stamps -> the endpoint reads uncontrolled FOREVER while driven (the #3 display fix is correct but datum-starved on this creation path). FIX: the broker (SINGLE WRITER) re-asserts each live session's control/viewer stamps to session-table truth, DIVERGENCE-GATED (read info; compare driven_by/controlled/viewer_count; write ONLY on diff — no per-poll fsync storm), on the KIND_SESSIONS handler (piggyback: the daemon reconcile + picker poll it, so a fresh perch converges within one reconcile-poll window after bind = the BOUNDED window, no new timer). Event-on-input rejected (an idle controlled session like hall-b never converges). Writes run OFF the log lock (snapshot truth under the lock, converge off it) per the lock-across-effect discipline (KH 7.12/5.16).
2026-07-11T01:39:54.1232554Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1232582Z 
2026-07-11T01:39:54.1232682Z ### REQ-PICKER-PROJECT-DISPLAY-NAME
2026-07-11T01:39:54.1235074Z - Title: A1 (F028, operator #1/#4/#6-display): `github-com-*` 'ghost' project entries are NOT phantoms — project_id_for_dir (spt-store/src/project.rs:64) derives ids from the git remote slug BY DESIGN (REQ-STORE-1 cross-machine sync): `github.com/SaberMage/spt-core` -> `github-com-sabermage-spt-core`. The ref is truthful; the BUG is presentation — the raw slug renders as the DISPLAY NAME everywhere (confirm-panel history view.rs:415-419, choose-project labels model.rs:314-337, resume-row titles, endpoint-list project column via latest_project_ref data.rs:417), which no operator recognizes as 'spt-core'. FIX: keep the slug as the KEY, render a friendly display name — the repo tail (spt-core) reusing the disambiguate_project_ids (model.rs:346) suffix mechanism for collisions. One shared display-name seam across all four surfaces. See triage A1.
2026-07-11T01:39:54.1235282Z - Required stages: impl, unit
2026-07-11T01:39:54.1235306Z 
2026-07-11T01:39:54.1235417Z ### REQ-PICKER-CONTROL-LINE-STATUS-GATE
2026-07-11T01:39:54.1236741Z - Title: A2 (F028, operator #2): the picker confirm-panel 'controlled locally' line renders for OFFLINE endpoints. view.rs:425-436 builds control_line from ep.controlled with NO status gate; an offline endpoint with a stale controlled stamp shows 'controlled locally' (operator screenshot: hall-a offline + controlled locally). RENDER HALF (this REQ): control_line MUST be empty when status != Online. The upstream STICKY-stamp half (stamp survives client SIGKILL >=5min) is B3/REQ-PRESENCE-CONTROL-REAP-ON-EXIT. FIX: gate the render. See triage A2(a).
2026-07-11T01:39:54.1236861Z - Required stages: impl, unit
2026-07-11T01:39:54.1236885Z 
2026-07-11T01:39:54.1236994Z ### REQ-PICKER-OFFLINE-NO-VIEW
2026-07-11T01:39:54.1237950Z - Title: A3 (F028, operator #3): 'View now (read-only)' is offered for OFFLINE endpoints. model.rs:1030 offline branch of confirm_options is vec![Start, View] — View is meaningless with no live PTY. FIX: offline set = [Start] (+ the existing Resume/ChangeAdapter/Instantiate/Fork/Shortcut tail). Update the view.rs options tests. See triage A3.
2026-07-11T01:39:54.1238106Z - Required stages: impl, unit
2026-07-11T01:39:54.1238183Z 
2026-07-11T01:39:54.1238279Z ### REQ-PICKER-CHOOSE-DEDUP-ALL
2026-07-11T01:39:54.1239738Z - Title: A4 (F028, operator #5): choose-project duplicate rows. model.rs:314-337 build_project_choices dedups the `Here: <run_cwd>` row only against the HEAD ref's dir (line 324) — an OLDER history ref with the SAME dir still renders, giving `Here: C:\...\projects` + `projects` as two rows for one project (operator screenshot). FIX: dedupe `Here` against ALL history dirs, and skip rest-rows whose dir == run_cwd when Here is present. Extend the model.rs:1847 choose-project test. See triage A4.
2026-07-11T01:39:54.1239848Z - Required stages: impl, unit
2026-07-11T01:39:54.1239890Z 
2026-07-11T01:39:54.1239985Z ### REQ-RESUME-ROW-PER-PROJECT
2026-07-11T01:39:54.1241141Z - Title: A5 (F028, operator #6): resume-from-history labels EVERY session with the endpoint's newest project. data.rs:480-496 resume_rows_for clones project_history.first() onto every ResumeRow (line 481/488), so all sessions read as the head project (the ghost). The per-row e.cwd is already carried for launch-into-dir. FIX: derive per-row project_id_for_dir(e.cwd) (owlery-excluded -> fall back to trigger token), rendered through A1's display-name path. See triage A5.
2026-07-11T01:39:54.1241240Z - Required stages: impl, unit
2026-07-11T01:39:54.1241269Z 
2026-07-11T01:39:54.1241360Z ### REQ-RUN-NO-DUP-SESSION
2026-07-11T01:39:54.1243842Z - Title: B1 (F028, hall-b diagnosis, verified 0.22.0): `endpoint run --id X --create` on an endpoint with a LIVE session mints a silent DUPLICATE session — and attach output can CROSS sessions (second create for diag-hallc minted a new session while the old ran; the new run's attach viewport rendered the OLD session's screen — claude resume-picker UI of pid 84512 while new claude 356020 had no -r). ROOT CLASS of the 0.21.0 attach-stall (zero events in FIRST_EVENT_GRACE rc.rs:1402 = attach bound to dead/wrong same-id slot); also the triplicate `launch --id ball-b` on ENLYZEAM. FIX: (i) run-on-live-session must REFUSE or REATTACH, never silently duplicate; (ii) RCA the attach/output routing that let frames cross same-id sessions (broker session-slot keying, dispatch_adapter vs serve_attach resolution). Int: two sessions one endpoint id -> each attach sees only its own frames. See triage B1.
2026-07-11T01:39:54.1243977Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1244006Z 
2026-07-11T01:39:54.1244101Z ### REQ-RESUME-HARNESS-SESSION-ID
2026-07-11T01:39:54.1246563Z - Title: B2 (F028, hall-b diagnosis, verified 0.22.0): respawn/`--resume` feeds the SPT session id to `claude -r`. After the 02:05 daemon bounce respawn built `claude.exe -r 70b5bfa40901b7d4` — an spt session id in claude's OWN session-id namespace -> claude hangs forever at a 'No sessions match' resume-picker while the endpoint reads online. Hits after EVERY daemon bounce + every picker Resume. The HARNESS session id (claude UUID, stamped in sessions.log/info.json by the hooks) is what {session_id} must mean in the adapter's [session.resume] command; the spt sid must not leak. FIX: substitute the HARNESS session id in the resume template (spt-core substitution-key semantics + LIKELY claude-spt manifest coordination — FLAG perri BEFORE touching the manifest, adapter-boundary rule). Int: resume template receives the ledger UUID, not the spt sid. See triage B2.
2026-07-11T01:39:54.1246782Z - Required stages: impl, unit
2026-07-11T01:39:54.1246806Z 
2026-07-11T01:39:54.1246911Z ### REQ-PRESENCE-CONTROL-REAP-ON-EXIT
2026-07-11T01:39:54.1249692Z - Title: B3 (F028, hall-b diagnosis + deferred #11 seed; BROADENED perri F-b CONFIRMED): dead-pid ONLINE decay window + sticky CONTROLLED stamp. Repro: /exit -> all endpoint processes dead -> `endpoint list` stays ■ ONLINE for a decay window before OFFLINE. Sticky CONTROLLED: perri confirmed controlled=true + attached_node SET while alive=false/OFFLINE, persisting >20min AND ACROSS A DAEMON RESTART (hall-b) — worse than the SIGKILL>=5min original (CAVEAT still: may reflect claude's --remote-control channel not the PTY attach — DISAMBIGUATE first). This is the deferred #11; RCA belongs to this wave. FIX: reap must clear presence AND control stamps promptly across FOUR paths — (i) clean exit, (ii) serve conn-drop, (iii) session-died-without-exit (crash/bounce), (iv) a BOOT-TIME sweep so a restarted daemon does NOT resurrect control stamps for endpoints it can see are dead. Int tests per edge. Closes A2(b). See triage B3 (broadened).
2026-07-11T01:39:54.1249925Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1249949Z 
2026-07-11T01:39:54.1250056Z ### REQ-RESUME-REAP-PRIOR-HARNESS
2026-07-11T01:39:54.1251030Z - Title: B4 (F028, hall-b diagnosis, verified 0.22.0): `--resume` respawns a SECOND harness onto the SAME session without reaping the first. Observed live: resume of b4421cf9 spawned pid 34432 while gen1 (250376) kept running — two claude.exe stacks, one session id. FIX: resume must reap/refuse when the session already has a live harness. See triage B4.
2026-07-11T01:39:54.1251138Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1251176Z 
2026-07-11T01:39:54.1251267Z ### REQ-CRC-SWAP-OLD-DISPLACE
2026-07-11T01:39:54.1253893Z - Title: C1 (F028, infra; memory crc-swap-old-litter-brick, RCA'd ENLYZEAM + confirmed systemic): crc_swap `.old`-litter bricks every subsequent adapter update. apply_crc_swap Phase-3 `let _ = remove_file(.old)` (spt-daemon/src/crc_swap.rs:129-133) silently fails whenever ANY pre-update process still image-maps the old binary (NORMAL on a live box — endpoint launch children survive updates). The NEXT update's first commit-op rename(exe->exe.old) = MoveFileExW(REPLACE_EXISTING) must delete the mapped .old -> win32 err 5 -> whole apply fails + rolls back FOREVER, context-free. FIX: (i) DISPLACE not replace — when <target>.old exists, rename it aside to a unique suffix (rename succeeds on mapped files; spt's own updater already does spt.exe.old-<counter>); GC stale .old.* opportunistically. (ii) Wrap swap io errors with op + path (`rename claude-spt.exe -> claude-spt.exe.old: …`). Unit seam exists (crc_swap tests). See triage C1.
2026-07-11T01:39:54.1254003Z - Required stages: impl, unit
2026-07-11T01:39:54.1254074Z 
2026-07-11T01:39:54.1254184Z ### REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION
2026-07-11T01:39:54.1256770Z - Title: C2 (F028, infra; ROOT-CAUSED + severity-upgraded doyle RCA 2026-07-03): cross-endpoint perch contamination — a foreign psyche's SessionStart hook REBINDS a victim perch's IDENTITY, not merely its ledger. Evidence: hall-a's info.json.session_id IS f015b-probe-psyche's session (359d7bd7) + hall-a's ledger holds the foreign psyche session; same class as hall-b's dead-pid stamp (141556). This REQ = the OBSERVABLE (foreign session_id in a perch's ledger/info.json + resume offering foreign sessions) and its belt-braces: (iii) filter owlery-cwd rows OUT of resume_rows; (iv) one-time repair for already-contaminated perches (hall-a on HFENDULEAM) or self-heal on next legitimate session-start. The ROOT (identity pinned at spawn + honest bind + nested self-resolve) is REQ-BIND-HONEST-SELF-STAMP — C2 is UPSTREAM of B3 (presence/CONTROLLED read the very stamps this corrupts). See triage C2.
2026-07-11T01:39:54.1256979Z - Required stages: impl, unit
2026-07-11T01:39:54.1257003Z 
2026-07-11T01:39:54.1257104Z ### REQ-BIND-HONEST-SELF-STAMP
2026-07-11T01:39:54.1261216Z - Title: C2-ROOT (F028, doyle RCA 2026-07-03): the identity-attribution ROOT behind REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION — three composing defects let a psyche-hosted SessionStart hook stamp a FOREIGN perch: (1) roster::detect_self_id leg (a) scans the owlery ONE level (roster.rs:107 read_dir(owlery)) so a NESTED psyche perch owlery/<parent>/nested/<id>-psyche can never self-resolve; (2) [session.psyche_init] (claude-spt manifest ~L347) spawns the psyche with NO env_remove + no pinned child identity, so whatever OWL_SESSION_ID/SPT_AGENT_ID reaches the child resolves to a foreign top-level perch; (3) the hook then writes info.json (session_id/pid rebind) + sessions.log on the mis-resolved victim. FIX (spt-core half): (i) identity PINNED at spawn — ManifestRuntime role spawns inject the child's OWN SPT_AGENT_ID=<child perch id> + OWL_SESSION_ID=<child session>, AND detect_self_id enumerates NESTED perches (fix the one-level owlery scan); (ii) BIND HONESTY — a session-start stamp may only write a perch whose resolved id AFFIRMATIVELY matches; never a fallback pick; refuse + loud-skip when unresolved (kin REQ-MSG-CLI-ORIGIN honest-default + #9 ancestry). ADAPTER half = PERRI touchpoint (psyche_init env scrubbing / relies on runtime pinning; hook loses silent fallback-perch behavior) — FLAG doyle BEFORE any manifest move (adapter glue-model rule). See triage C2 fix (i)+(ii).
2026-07-11T01:39:54.1261443Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1261466Z 
2026-07-11T01:39:54.1261572Z ### REQ-PEER-PUMP-CHURN-STALL
2026-07-11T01:39:54.1263778Z - Title: B5 (F028, perri F-a; DEFECT daemon, OBSERVED-ONCE, HIGH): the peer pump STALLS under rapid rc attach/EOF-detach/--take churn. Fresh 0.22.0 daemon ~10min after restart, during rapid rc cycling: `peer pump: STALLED (last tick 122s)`; while stalled `spt rc --view` -> `RC_FAIL: attach request: brain IPC read deadline elapsed` (repeatable) and controlled-clear stopped propagating. Daemon restart recovered + endpoints auto-revived. Prior class: REQ-HAZARD-PUMP-IPC-DEADLINE (reader-thread+channel carrier), REQ-broker-QUIC-deadline (bounded_block_on) — something in the rc-churn path can still wedge the pump tick. perri holds exact timestamps + a repro candidate (rapid attach/detach/take against one endpoint) — REQUEST before RCA. See triage B5.
2026-07-11T01:39:54.1263872Z - Required stages: 
2026-07-11T01:39:54.1263900Z 
2026-07-11T01:39:54.1264016Z ### REQ-TRANSLATE-BINARY-LIVENESS-DECAY
2026-07-11T01:39:54.1266318Z - Title: SUPERSEDED by REQ-TRANSLATE-COMMIT-MISS-TOLERANCE (F029 C-1). B6 (F028, perri F-e) was ROOT-PINNED as the commit-deadline-miss fault: at a checkpoint clear boundary the clear-only inject's {commit} was never observed within INJECT_COMMIT_DEADLINE, so the inject worker FAULTED + TERMINATED a HEALTHY translate binary and (by ADR-0022) never respawned → every subsequent force-native reported delivered=false ('no live translation binary'). NOT a dormancy/liveness-registration decay (that hypothesis is dead) — deterministic at every checkpoint-armed boundary. The fix (miss != fault + N=3 strike budget + bounded respawn + perch-visible fault stamp) lives under REQ-TRANSLATE-COMMIT-MISS-TOLERANCE + REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH. See triage addendum C-1.
2026-07-11T01:39:54.1266413Z - Required stages: 
2026-07-11T01:39:54.1266446Z 
2026-07-11T01:39:54.1266555Z ### REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN
2026-07-11T01:39:54.1268303Z - Title: C3 (F028, perri F-h): psyche wrapper crash-loop has no backoff, and `endpoint shutdown` misses a wedged wrapper. A probe psyche crash-looped ~3 boots/sec for ~30min (CC died instantly on the untrusted owlery cwd; ledger hit ordinal 5358) — SILENTLY; and `spt endpoint shutdown` did NOT tear the looping wrapper down (docs say shutdown tears the Psyche with the perch; manual kill was required). FIX: (i) bounded backoff + loud give-up on a psyche boot loop (the psyche_host_error surface already exists), (ii) shutdown must cover a wedged/looping wrapper. See triage C3.
2026-07-11T01:39:54.1268398Z - Required stages: 
2026-07-11T01:39:54.1268427Z 
2026-07-11T01:39:54.1268536Z ### REQ-DOC-ENDPOINT-DROP-RESOLUTION
2026-07-11T01:39:54.1269777Z - Title: D1 (F028, perri F-c; docs/truth): SI-1's resolution rule — a RELATIVE watched drop dir resolves against the ENDPOINT's cwd, never the daemon's (KH 7.28, shipped v0.22.0) — is documented NOWHERE public. Add it to harness-contract/manifest.md + the manifest schema field descriptions so an adapter author knows a relative commune_dir/signoff_dir is endpoint-resolved. docs-drift gate applies. See triage D1.
2026-07-11T01:39:54.1269926Z - Required stages: 
2026-07-11T01:39:54.1269954Z 
2026-07-11T01:39:54.1270053Z ### REQ-DAEMON-STATUS-JSON-TRUTH
2026-07-11T01:39:54.1271552Z - Title: D2 (F028, perri F-d): `daemon status --json` truth drift. managed_by/managed_active read null in JSON while the HUMAN view says 'managed-by: manual — at-logon task registered' (the two surfaces disagree); and pump staleness (the STALLED diagnosis, B5) is NOT computable from JSON — only a raw pump_heartbeat_ms is emitted, no derived staleness/stalled field. FIX: JSON managed_by/active match the human render, and add a derived pump-staleness/stalled field so B5's condition is machine-observable. See triage D2.
2026-07-11T01:39:54.1271699Z - Required stages: 
2026-07-11T01:39:54.1271723Z 
2026-07-11T01:39:54.1271834Z ### REQ-ENDPOINT-LIST-RENDER-POLISH
2026-07-11T01:39:54.1274080Z - Title: A6 (F028, operator, 4 asks): `spt endpoint list` render polish. (a) the 'Shared subnets' line is NOT dim — LIGHT_GRAY = "37" (cli.rs:3019) is standard-palette WHITE, indistinguishable from row text; use SGR 90 (bright-black/gray) for the dim intent. (b) the `Total:` line takes the same dim color. (c) move the status glyph ADJACENT to the endpoint name (operator: 'right behind the endpoint name'), mirroring the picker's glyph-beside-name presentation (today the glyph sits at the end next to the status word). (d) color the status WORD like the picker TUI (green ONLINE / gray OFFLINE / blue when driven, matching picker glyph semantics). All in render_node_grouped/render_instance_row (cli.rs ~3000s); pure render with an injected color decision — unit-testable off a tty. See triage A6.
2026-07-11T01:39:54.1274194Z - Required stages: impl, unit
2026-07-11T01:39:54.1274218Z 
2026-07-11T01:39:54.1274314Z ### REQ-CLI-WIN-VT-ENABLE
2026-07-11T01:39:54.1276372Z - Title: A7 (F028, operator, Win10 conhost): ANSI emitted without VT enable → garbled console. Evidence (raw PowerShell 7, Win10 conhost): literal `←[36m` in `endpoint list` + `--help`. ROOT: ENABLE_VIRTUAL_TERMINAL_PROCESSING is enabled ONLY on the rc attach path (rc.rs:746, REQ-RC-WIN-VT-OUTPUT) — plain CLI stdout never enables it, and the color decision doesn't fall back when the console can't render VT. FIX: lift the rc.rs VT-enable into a SHARED startup helper for every colored-output path; if SetConsoleMode fails (or stdout isn't a console), STRIP colors (the ansi_wrap/helpfmt color=false path already exists — plumb the decision, not new rendering). Windows Terminal masks this (VT always on) — TEST on raw conhost. See triage A7.
2026-07-11T01:39:54.1276540Z - Required stages: impl, unit
2026-07-11T01:39:54.1276574Z 
2026-07-11T01:39:54.1276730Z ### REQ-GOSSIP-CONTROLLED-CROSS-NODE
2026-07-11T01:39:54.1279235Z - Title: B7 (F028, operator, cross-node): a remote endpoint's CONTROLLED state is not rendered. Evidence: ball-b ONLINE + CONTROLLED on ENLYZEAM (local view), but HFENDULEAM renders remote ball-b as plain ONLINE (both 0.22.0). The F-026 #4 gossiped any-controller datum (REQ-GOSSIP-ADAPTER-PROJECTS controlled bool) either isn't SENT for the locally-controlled case, isn't APPLIED on the receiving row, or DECAYS. Local leg confirmed fine (sibling hall-b renders blue-glyph correctly); the gap is the REMOTE leg. perri's validation had this ENV-BLOCKED — two live nodes now available to RCA. FIX: RCA sender-side (is controlled gossiped when locally-controlled?) / receiver-render (does from_resource_row surface it?) / decay, then lock with a cross-node int. See triage B7.
2026-07-11T01:39:54.1279479Z - Required stages: 
2026-07-11T01:39:54.1279507Z 
2026-07-11T01:39:54.1279611Z ### REQ-HAZARD-INJECT-WORKER-POISON
2026-07-11T01:39:54.1282337Z - Title: The per-session inject-worker floor Mutex is SHARED by the inject worker (open/flush) and the controller-input path (dispatch_input Layer C buffer_if_held); a panic under the lock on EITHER poisons it, and a bare .lock().unwrap() at the next site then panics too — a panic in the inject WORKER kills its thread WITHOUT reaping the translation child, orphaning a live binary while event_tx.send fails, so force-native reports 'worker-gone' delivered=false FOREVER (the F-e generic-miss shape). HARDENING, NOT the F-e incident root (perri's matrix exonerated poison under thrash/dormancy/churn): (i) poison-tolerant floor lock (unwrap_or_else into_inner) at all 3 sites so one panic can't cascade the session's delivery dead; (ii) a panic-resilient inject worker (catch_unwind -> fault+terminate the child on a worker panic) so a dead worker never orphans a live binary + strands delivery. Poison-tolerance class of REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE / bug #16.
2026-07-11T01:39:54.1282577Z - Required stages: impl, unit
2026-07-11T01:39:54.1282605Z 
2026-07-11T01:39:54.1282758Z ### REQ-HAZARD-DETACHED-DAEMON-STDIO
2026-07-11T01:39:54.1287902Z - Title: A daemon DETACHED-IN-FACT (no interactive console, or an inherited stderr PIPE nobody drains) that never nulled its std handles will BLOCK on stdio writes when the pipe fills, and/or pop a visible conhost window (REQ-HAZARD-WMI-DAEMON-WINDOW is a covered surface of this hazard). detach_console nulls the 3 handles only under the --detached flag; a rung that omits it (the bare line-82 elevated->deelevated respawn; a STALE installer at-logon task registered as bare `daemon run`, confirmed live field-drift on ENLYZEAM) is exposed. FIX: (load-bearing) inside `daemon run`, null the 3 std handles when stderr GetFileType==FILE_TYPE_PIPE — a pipe is the ONLY std sink that BLOCKS the daemon when it fills; catches every rung whose inherited stderr is an undrained pipe, independent of whether each caller passed --detached, while a FILE (2>run.log AND every int-test Stdio::from(file) brain-log capture), a CONSOLE (scrolls), and a NULL/absent handle (DETACHED_PROCESS rungs, already discard) all SURVIVE. DELIBERATELY NOT gated on GetConsoleWindow==NULL: a CREATE_NO_WINDOW daemon has no console window yet a drained FILE stderr — nulling it would blank the capture for ZERO safety gain (a file never blocks) and mass-red the int-test brain-log assertions. (belt) pass --detached on the bare line-82 respawn; (drift nag) parse the schtasks /Query action argv and LOUDLY nag when the at-logon task is the stale bare `daemon run` form (manual/installer re-registers; the daemon must NOT self-elevate to rewrite it). Defense-in-depth — no current spt Windows spawn path was proven to yield a BLOCKING inherited pipe (all rungs null-discard or scrolling-conhost), so this is hardening, not a confirmed incident root.
2026-07-11T01:39:54.1288145Z - Required stages: impl, unit
2026-07-11T01:39:54.1288174Z 
2026-07-11T01:39:54.1288302Z ### REQ-PICKER-CURRENT-DIR-LABEL
2026-07-11T01:39:54.1294747Z - Title: A-2/A-3 (F029, operator, semantic pair): the Choose-project rows must self-identify the CURRENT DIR. build_project_choices (picker/model.rs:322-352). A-2: when the run cwd IS already a history dir the `Here:` row is (correctly) suppressed by the dedup (REQ-PICKER-CHOOSE-DEDUP-ALL), but the matching history row rendered bare `r.display` with no cwd affordance — mark it `<display> (CURRENT DIR)`. A-3: the not-in-history current-dir row changes from `Here: <run_cwd>` to `CURRENT DIR --> <project>`, deriving the display the SAME way the history refs do (folder tail; honest fallback to the raw path when underivable). `cwd` payload unchanged. Grep-tests rule: 3 `starts_with("Here: ")` asserts (model.rs) + a `Here: /here` render assert (view.rs) are behavior assertions on the OLD label. See triage A-2/A-3.
2026-07-11T01:39:54.1295052Z - Required stages: impl, unit
2026-07-11T01:39:54.1295086Z 
2026-07-11T01:39:54.1295196Z ### REQ-PICKER-FORK-LABEL-CWD
2026-07-11T01:39:54.1296163Z - Title: B-3 (F029, operator): the confirm-panel `Fork endpoint` option label is static and says nothing about WHERE the fork lands. A fork runs in the picker's launch cwd (run_cwd); the label must state that dir honestly: `Fork endpoint here --> <current dir>`. Anchor picker/view.rs confirm_option_label (was `fn(opt)->&'static str`). Make the label model-aware for the dir-relative options. See triage B-3.
2026-07-11T01:39:54.1296343Z - Required stages: impl, unit
2026-07-11T01:39:54.1296371Z 
2026-07-11T01:39:54.1296487Z ### REQ-PICKER-SHORTCUT-LABEL-FILENAME
2026-07-11T01:39:54.1298244Z - Title: B-4 (F029, operator): the confirm-panel shortcut option label is a static `New/Update spt-<id> shortcut (s)` placeholder — it should name the REAL file it writes: `Set shortcut here --> <current dir>/<shortcut-name>` where <shortcut-name> is the EXACT on-disk filename (incl. extension). The name must be produced by the SAME function that names the file in shortcut creation (picker/shortcut.rs shortcut_filename over the manifest-resolved basename) so label and writer can NEVER drift. Anchor picker/view.rs confirm_option_label. See triage B-4.
2026-07-11T01:39:54.1298416Z - Required stages: impl, unit
2026-07-11T01:39:54.1298444Z 
2026-07-11T01:39:54.1298576Z ### REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER
2026-07-11T01:39:54.1301288Z - Title: A-4 (F029, operator regression): the picker/confirm views drop an endpoint's adapter `:profile` (showed `claude-spt` where `claude-spt:ccs` was created). ROOT: stamp_creation_fields (spt-store/home.rs) gave the incoming BIND-TIME adapter value UNCONDITIONAL precedence (`rec.adapter = adapter.map(...).or_else(prior)`), but a hook bind resolves the adapter ADAPTER-AGNOSTICALLY (ADR-0021: a binary basename → the BARE parent, profile unknowable), so the first hook bind rewrote the richer `claude-spt:ccs` → `claude-spt`. (F-028's establish_perch self-heal widened how often this re-stamps; the precedence is the root.) FIX: profile-preserving precedence — when the incoming adapter is exactly the PARENT of the prior's `parent:profile` composite, KEEP the prior; replace only on a genuinely different adapter (or a different explicit profile). Paid-for field bug → hazard. See triage A-4.
2026-07-11T01:39:54.1301396Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1301438Z 
2026-07-11T01:39:54.1301544Z ### REQ-PICKER-WINDOW-TITLE
2026-07-11T01:39:54.1303007Z - Title: B-5 (F029, operator): `spt endpoint run`'s interactive picker window/tab is untitled — hard to find among many terminals. Set the window/tab title to `SPT Endpoint Picker`. Anchor picker/mod.rs:88 setup_terminal (crossterm SetTitle in the execute! chain). Set-only is acceptable (crossterm can't cheaply read the prior title to restore). Applies ONLY to the interactive picker path — non-interactive/headless `endpoint run` (REQ-HOST-RUN-1) must NOT retitle the operator's terminal. See triage B-5.
2026-07-11T01:39:54.1303108Z - Required stages: impl
2026-07-11T01:39:54.1303138Z 
2026-07-11T01:39:54.1303246Z ### REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE
2026-07-11T01:39:54.1304779Z - Title: B-1 (F029, operator): the `h` (headless start) / `s` (shortcut) keybinds fire from broad picker contexts (mod.rs handle_confirm_key / ChooseProject / Resume) regardless of whether the highlighted row would LAUNCH the endpoint. Restrict both to launch-capable highlights: (a) `Start now` in the immediate-start case (should_offer_project_choice == false), (b) a Choose-project row, (c) a Resume-from-history row. The footer hint line must render `h`/`s` ONLY when actually live (hint truth = availability truth). FIX: gate the key handlers on (screen, highlighted-option), unit the gate as a pure matrix. See triage B-1.
2026-07-11T01:39:54.1304992Z - Required stages: impl, unit
2026-07-11T01:39:54.1305016Z 
2026-07-11T01:39:54.1305122Z ### REQ-PICKER-CHANGE-ADAPTER-FLOW
2026-07-11T01:39:54.1307518Z - Title: B-2 (F029, operator; LARGEST item): `ConfirmOption::ChangeAdapter` wrongly routes into the CREATE flow (Screen::CreateAdapter → CreateId → CreateHome → START, reenter_create(true)) — it re-prompts id + home and then STARTS the endpoint. Required: prompt ONLY the harness-adapter pick, apply the change to the perch record (update info.json.adapter via the existing write seam; an `<adapter>:<profile>` pick stamps the full option, composing with A-4), then RETURN to the endpoint's Confirm menu — NO id prompt, NO home prompt, NO start. FIX: a return-to-Confirm mode on the adapter-pick screen (flag or dedicated Screen::ChangeAdapterPick) skipping CreateId/CreateHome + the launch outcome. Unit the flow-state transitions + the record write. Shared-seam: touches picker flow state — run the full picker cluster. See triage B-2.
2026-07-11T01:39:54.1307724Z - Required stages: impl, unit
2026-07-11T01:39:54.1307752Z 
2026-07-11T01:39:54.1307862Z ### REQ-TRANSLATE-COMMIT-MISS-TOLERANCE
2026-07-11T01:39:54.1310887Z - Title: C-1 (F029, B6 ROOT — rescope of REQ-TRANSLATE-BINARY-LIVENESS-DECAY, now PINNED): at a checkpoint clear boundary the clear-only inject drives `/clear`; its `{commit}` is never observed within INJECT_COMMIT_DEADLINE (5s, broker.rs:158) so the inject worker FAULTS + TERMINATES a HEALTHY translate binary (broker.rs respool_and_fault + return) and by ADR-0022 design NEVER respawns → every subsequent force-native reports delivered=false ('no live translation binary', cli.rs:5046) = B6's exact field signature; the v0.12.0 checkpoint post-clear WAKE dies with the terminated binary + the fire-and-forget FIRE in the dead window. NOT a race — deterministic at every checkpoint-armed boundary (perri captured-stderr proof: TRANSLATION_FAULT on the F-019 unread daemon-stderr channel). FIX (REVISED, supersedes terminate-then-respawn): miss != fault — preserve the binary; the watchdog's job is ANTI-STALL (release the operator floor), not execution-verification. See addendum C-1 + ADR-0022 amendment.
2026-07-11T01:39:54.1311015Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1311039Z 
2026-07-11T01:39:54.1311174Z ### REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH
2026-07-11T01:39:54.1313053Z - Title: C-1 hazard (F029; paid-for: B6 + three-version checkpoint-wake breakage): a REAL translation fault (binary death — stdin write fail / stdout disconnect — or strike-budget exhaustion) must get a BOUNDED eager respawn (C3(b) give-up budget) instead of permanent death, and must stamp a PERCH-VISIBLE fault surface (mutate_info field, cleared on healthy respawn/commit) — TRANSLATION_FAULT is daemon-stderr-only today (the F-019 unread-channel trap; same honesty rule as F-027 ENDPOINT_SPAWN_FAIL). A real fault legitimately loses in-memory state (the wake is NOT carried across a real fault, unlike a mere commit-miss). See addendum C-1 (3)-(4).
2026-07-11T01:39:54.1313181Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1313205Z 
2026-07-11T01:39:54.1313319Z ### REQ-HAZARD-BOUNDARY-READY-STRAND
2026-07-11T01:39:54.1316783Z - Title: C-2 (F029, SEAM-2 pinned — B6's SECOND HALF, the live-wake blocker; perri wakep9 vs wakep4 gate-state dump + doyle code trace): at a /clear, CC fires SessionEnd(reason=clear) for the DEPARTING session BEFORE SessionStart; the departing sid STILL matches the perch pin at that instant, so the adapter's [hooks.SessionEnd] → `api session-end` AUTHENTICATES and the soft handler REMOVES the ready marker (+ unregister_address, reporting.rs cmd_session_end:206-207). The subsequent `api boundary` rotates the sid but NOTHING re-writes ready → is_online false → try_spt_hosted_inject Nones on the CLI gate BEFORE any broker RPC → every post-clear force-native (incl. the checkpoint FIRE) reports the generic UNDELIVERED, persistent by construction (no path re-stamps ready outside a real bind). The single differing gate field at every UNDELIVERED instant is ready-absent (info online/controllable/rotated-sid all healthy, translate alive). Paid-for hazard. FIX: cmd_boundary re-stamps the ready marker (+ status online, idempotent) ATOMICALLY with the sid rotation — a boundary PROVES a live successor session on the same harness process; a REAL end has no subsequent boundary so genuine teardown is untouched. See triage addendum C-2.
2026-07-11T01:39:54.1317002Z - Required stages: impl, int
2026-07-11T01:39:54.1317030Z 
2026-07-11T01:39:54.1317129Z ### REQ-PSYCHE-EPHEMERAL-DRIVER
2026-07-11T01:39:54.1320403Z - Title: W1 (F030, design §3): each psyche-relevant event runs exactly ONE bounded per-event turn through the existing driver stack (psyche_turn_and_relay for outbound-intent events / resume_psyche for session-custody transitions / run_psyche_turn for pure merges) — no resident psyche process exists between events. host_one (livehost.rs:518) STOPS spawning spawn_psyche_owned; the pulse loop stays as the daemon-side scheduler (thread + stop-flag + drop-dir watch correct) but a fire now invokes one bounded turn, daemon-driving every substitution key from daemon-known context (child never self-resolves home/subnet/perch — direction-(a) multi-subnet churn impossible by construction). Turn failures consume a bounded failure budget (C3(b) shape): N consecutive failures → psyche_host_error stamp + cooldown, reset on success; no respawn storm (nothing resident to respawn). Red-first: fire an event on a hosted live endpoint → assert one turn ran (SIDE-EFFECT PROOF FILE — transcript-jsonl asserts are structurally blind, 2026-07-04 rig lesson) and no {id}-psyche process survives the turn.
2026-07-11T01:39:54.1320621Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1320650Z 
2026-07-11T01:39:54.1320732Z ### REQ-PSYCHE-SID-CUSTODY
2026-07-11T01:39:54.1323589Z - Title: W2 (F030, design §3): the psyche mints and keeps its OWN session id, stored in the nested {id}-psyche perch record — {session_id} in psyche role templates becomes the psyche's sid, never the parent's (today's fill at livehost.rs:518 is the PARENT's — the custody bug). Parent boundary (/clear, /compact) does NOT rotate the psyche sid (the psyche's conversational thread survives parent resets — its job). resume_psyche validates the custody key before spawn (resume.rs:183). Reseed path: psyche session lost/invalid → ResumeMode::FreshWithPreload (download_psyche_context composes role/live/project into {psyche_context}, resume.rs:100) + LOUD PSYCHE_RESEED:{id} marker (custody-loss loop visible; W1 budget bounds it). If the parent sid is still needed by a template it gets its OWN explicit key {parent_session_id} — never aliased. Red-first: parent `api boundary clear` → nested perch sid UNCHANGED (today it is the parent's — guard-revert reproduces).
2026-07-11T01:39:54.1323722Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1323746Z 
2026-07-11T01:39:54.1323846Z ### REQ-PSYCHE-NESTED-RESOLUTION
2026-07-11T01:39:54.1326704Z - Title: W4 (F030, design §3; F-017 sibling, general not psyche-only): nested {parent}/{nested} ids resolve under the PARENT's home — subnet-less resolution for nested perches (the home-ASSIGNMENT seam, not perch-path which is already subnet-less) — so child-side verbs acting on nested perches need no --subnet the child cannot know. ROOT: home::assign_home returns Ambiguous on a multi-subnet node w/o --subnet; a nested id must instead derive home from its parent perch. Additionally expose a SINGLE {subnet} base_keys fill WHEN KNOWN (own_subnet = home-subnet label, 'local' when unhomed; absent → LOUD missing-key fail, the {node} precedent). NO {home} key (doyle W4 Q1: the endpoint home subnet is ONE concept per CONTEXT.md:640, and 'home:' is already the subnet-name qualifier position CONTEXT.md:652 — a {home} template key invites meaning-drift). Red-first = evidence #3's exact repro: 2-subnet home, nested-id verb, must succeed (was: `spt ready <id> --once` → exit 1 READY_FAIL … pass --subnet).
2026-07-11T01:39:54.1326923Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1326952Z 
2026-07-11T01:39:54.1327066Z ### REQ-PSYCHE-CONTEXT-FILE-INDIRECTION
2026-07-11T01:39:54.1331292Z - Title: W4 (F030; doyle Q2 ruling + perri file-always freeze, 2026-07-04): the composed psyche mind ({psyche_context}) rides the SHIM argv today — a real ~20KB doyle psyche-download exceeds the win32 CreateProcess lpCommandLine ~32k cap → the shim spawn BRICKS. FIX (file-always, replaces {psyche_context} outright — no size-branch, no argv cliff, one path): core writes the mind to a file in the psyche's NESTED perch dir BEFORE each turn spawn and fills a single {psyche_context_file} = that PATH (argv-cap-immune). The soft fresh/continue discriminator moves from KEY-presence to FILE-CONTENT: FreshWithPreload writes the composed mind NON-EMPTY (the <fresh-psyche/> never-empty guarantee carries to the file content); ContinueExisting writes it TRULY 0-BYTE (perri BINDING PIN 1 — NO sentinel/placeholder EVER, else her non-empty=fresh discriminator misfires a spurious --session-id adopt). Core owns the file lifecycle: write-before-spawn each turn, overwrite in place, persists between turns in the nested perch (debuggability); never deleted per turn. perri shim delta: --psyche-context-file <path> arg, read-file prefix, TRIM-based emptiness (her tolerance, NOT core's license — core writes exactly 0 bytes on continue, PIN 2), read-failure = generic fail NEVER 95, never writes/deletes the file. Red-first: a ~40KB mind → the old {psyche_context}-on-argv path BRICKS the win32 shim spawn; the file path succeeds (shim reads the full mind from file).
2026-07-11T01:39:54.1331515Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1331554Z 
2026-07-11T01:39:54.1331664Z ### REQ-PSYCHE-LEGACY-RESIDENT-SWEEP
2026-07-11T01:39:54.1337250Z - Title: W5 (F030; doyle+perri 2026-07-04): a dirty daemon upgrade from <=v0.24.0 strands a RESIDENT psyche wrapper the OLD daemon spawned — and F-030 W4's nested-`ready` resolution fix CONVERTED that wrapper's accidental self-reap into a permanent HANG. The pre-W3 wrapper's only spt IPC is `spt ready <parent>-psyche --once` (BLOCKING, no internal timeout); pre-W4 that hit READY_FAIL on a multi-subnet home → the wrapper exit-4'd (accidental reap). Post-W4 the nested id resolves cleanly → the wrapper REGISTERS then BLOCKS FOREVER on its first post-upgrade poll: no exit, no psyche_host_error, no CPU (KH 2.6 invisible-loop class, one level up). Post-W3 core has no residency machinery to reap it. FIX: a ONE-SHOT legacy-resident sweep at BRAIN START (never per-reconcile/periodic — burying residency-era machinery, not resurrecting it). GUARD = adapter-AGNOSTIC (glue-model): resurrect the retired reap_orphan_psyches LOGIC — for each self-perch live-agent id derive `<id>-psyche` and kill iff (a) exe basename == the adapter's MANIFEST-declared psyche program (normalize_basename, never a hardcoded adapter name) AND (b) cmdline contains the id marker `<id>-psyche` AND (c) pid alive; any unreadable signal → DECLINE + loud log (fail-safe-decline, positive-match-only; infra never-kill inside the sweep). FRATRICIDE is closed by TIMING (perri-confirmed from the owning side): the ephemeral shim is daemon-spawned per-event, bounded, exits at turn end — at brain start BEFORE the first reconcile/pulse no current shim is resident, so any `<id>-psyche` psyche-program process alive then is unambiguously stranded-legacy. RESIDUE (doyle PIN 3): the hung wrapper REGISTERED a `<parent>-psyche` ready perch before blocking; killing the pid alone leaves a phantom ready-record with a dead pid (the REMOTE-TRUTH presence-lie class) — the sweep MUST also clear that stale registration or prove the existing stale-perch cleanup reaps it. No field window pre-W6 (nothing releases). (F-030 W5)
2026-07-11T01:39:54.1337526Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1337560Z 
2026-07-11T01:39:54.1337680Z ### REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION
2026-07-11T01:39:54.1340562Z - Title: W3 (F030 hazard; paid-for: hall-bf churn ordinal 6491+ + adapter v0.13.2 bad-ship brick 2026-07-04): a psyche failure of ANY shape must NOT remove or alter the parent endpoint's ready/hosted state, and hosting must NOT churn-respawn. The v0.13.2 shim-exit tripped the residency machinery (confirm_residency_or_unhost) which tore down the endpoint's hosted state — ready marker removed, never re-stamped, every force-native gated leg=cli-gate-not-hosted PERMANENTLY (field brick). FIX: residency machinery retires with the resident child; the teardown that touches parent hosted state is DELETED — psyche trouble stamps psyche fields only. REQ-HAZARD-LIVEHOST-NONRESIDENT's spirit transfers to the W1 failure budget (its entry gets a SUPERSEDED pointer here, LIVENESS-DECAY→SUPERSEDED pattern from C-1). Conformance int = the hall-bf shape: multi-subnet home, live endpoint, failing psyche → parent stays deliverable, no rehost churn, error stamped (the wave's heart).
2026-07-11T01:39:54.1340769Z - Required stages: doc, impl, int
2026-07-11T01:39:54.1340798Z 
2026-07-11T01:39:54.1340908Z ### REQ-HAZARD-THRASH-GUARD-BLIND
2026-07-11T01:39:54.1342114Z - Title: W3 (F030 hazard; paid-for: evidence #6, hall-bf ~12/min re-host NEVER tripped the C3(b) thrash guard — boot records were not ledger boundaries to the guard): the failure budget must count REAL attempts (ledger-derived: boot/turn records via the psyche perch ledger), not whatever it counted that let 12/min churn run invisibly. Red-first synthetic loop: a 12/min synthetic failure loop MUST trip the budget.
2026-07-11T01:39:54.1342243Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1342271Z 
2026-07-11T01:39:54.1342423Z ### REQ-EFFECTIVE-INSTANCE-STATE
2026-07-11T01:39:54.1346365Z - Title: A-1 (REMOTE-TRUTH triage §A + ADR-0033 §Decision): the effective instance state of a perch is DERIVED through ONE shared function — liveness discriminates warm/cold, stored rest intent refines within warm, absent intent NEVER defaults active. ROOT (certain): resting::apply_event derived its `from` off the stored rest_state field ALONE (resting.rs:225, `unwrap_or(RestState::Active)`) — a cold perch (offline) with no intent answered `from=Active`, so a Wake event found it 'already in target state' and returned Ok(None) = the field NO_EDGE-on-a-definitely-suspended-endpoint bug (the banked F-028 rest_state-void seed). advertised_status (registryhost.rs:821) ALREADY derived correctly (is_perch_alive→intent-refined / is_perch_unbound→Dormant / cold→Suspended) — the two readers disagreed. FIX (Q1 shared derivation, hazard-class): a pure `effective_rest_state(alive, unbound, intent) -> RestState` mirroring advertised_status, consumed by BOTH advertised_status (mapped RestState→Status, behavior identical) AND apply_event's `from` (real is_perch_alive/is_perch_unbound reads); void + cold ⇒ Suspended. Bonus: kills the spurious active→suspend echo a cold+void perch used to fire (on_rest_edge on a dead driver). Red-first: perch status=offline + no rest_state → daemon_rest_event(Wake) yields from=Suspended→to=Active EdgeReport, not Ok(None).
2026-07-11T01:39:54.1346494Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1346527Z 
2026-07-11T01:39:54.1346627Z ### REQ-OPID-MINTER-NAMESPACE
2026-07-11T01:39:54.1353386Z - Title: A-4a (REMOTE-TRUTH triage §A + ADR-0034 Decision 1 + Amendments 1 & 2): the broker effect journal's dedup key gains a minter dimension so ops minted by independent counters can never collide. ROOT (high, ground-truthed vs HEAD): the journaled-op producers key into ONE journal namespace (NET_EFFECT_SESSION|shell_sid, op) at broker.rs (EffectKey=(u64,u64)); a CLI wake op colliding with an already-journaled daemon op reproduces the typed 'already applied … retry with a fresh op_id' with NO broker restart (field-hit: spt endpoint wake id@node WOKE_FAIL). Same latent class: nethost dial_ops/stream_ops HashMap<u64,u64> ('Shares the one net op-id namespace') would re-clobber even after the journal separates them; AND shellchan::deliver_stdin_pending journals (shell_sid, row_id) so an rc operator's ops on the same shell_sid collide with spool row ids (dropped keystroke OR dropped spool row). Amendment 2 corrected the minter set: the REAL journal minters are {cli, pump, rc, shell} + legacy — psyche/epoch are the EpochSource notif/lease counter domain, NEVER submit to apply_once, DROPPED from the journal enum (a tag with no stamp site = doc'd-but-dead knob). FIX (Decision 1 + Amdt 2): ONE canonical Minter enum {Legacy, Cli, Pump, Rc, Shell, Wake} — Legacy reserved for pre-upgrade lines + untagged wire, monotonically shrinks; enum is the single source for the TEXTUAL journal-line token (self-describing during recovery). EffectKey becomes (effect-class, minter, op); recover() DUAL-PARSES (old shorter line → minter=Legacy, new longer line → parsed tag) so old journals need no migration and old-shape keys can never equal new-shape (migration-free). A MintedOp{minter, seq} newtype REPLACES bare op_id:u64 through the brain/daemon THREADING paths so forgot-to-stamp is UNCOMPILABLE (row_id stays the shell seq — never re-minted, the durable spool exactly-once identity). Wire keeps an additive optional minter field (serde default absent ⇒ Legacy materialized at broker decode; serde_json no deny_unknown_fields ⇒ NO wire version bump); the newtype is NOT forced into wire structs. nethost op-maps re-key by (minter, op). Red-first: mint an rc op == a journaled shell/pump/daemon op int on the same session → pre-fix the second dedups/clobbers (WOKE_FAIL class); post-fix both are distinct keys, both Applied.
2026-07-11T01:39:54.1353701Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1353724Z 
2026-07-11T01:39:54.1353832Z ### REQ-OPID-TRACING-RETRY
2026-07-11T01:39:54.1358074Z - Title: A-4b (REMOTE-TRUTH triage §A + ADR-0034 Decision 2): the tracing-only op families auto-retry ONCE with a fresh op on the typed no-longer-held error, so a broker-restart-dropped conn/stream self-heals instead of surfacing core lingo to the user. ROOT: net/rest.rs declares rest op-ids 'tracing/correlation only … redelivery needs reporting, not dedup', yet the journal enforced exactly-once on them — a rest/attach op whose conn the broker no longer holds (post-restart) returned the typed 'already applied … no longer held … retry with a fresh op_id' (broker.rs:2796 net-dial / 3047 stream-open) straight to the user (WOKE_FAIL / rc attach fail). FIX (Decision 2, scoped): the rest family (request_rest) + rc attach stream-open (request_attach_endpoint) — and ONLY those — catch the typed no-longer-held error INTERNALLY and re-issue ONCE with a FRESH op minted from the SAME minter (A-4a MintedOp; same producer, new seq). sync/update pull families (request_sync/request_update, durable open_op) are NOT wrapped — their exactly-once dedup is load-bearing (negative control). The typed op error becomes internal-only; if the retry ALSO fails, the user-facing line names the observable situation + next action in operator language, ZERO journal/op/brain lingo (F-1 public-error rule applies early — this string is user-facing). Red-first: mint a colliding op → assert the retry succeeds + the user sees NOTHING; NEGATIVE CONTROL — a durable family's no-longer-held stays a hard error, no silent retry.
2026-07-11T01:39:54.1358214Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1358242Z 
2026-07-11T01:39:54.1358332Z ### REQ-REST-VERB-ROUTING
2026-07-11T01:39:54.1365147Z - Title: A-3 (REMOTE-TRUTH triage §A + Q3 operator-law): a BARE-id rest verb (spt wake/suspend <id>) routes across the subnet like send's fallback instead of failing local-only. ROOT (certain): cmd_rest (cli.rs:3296) gates the remote arm on id.contains('@'|':'); a bare id falls to the local-only arm (cli.rs:3340) → daemon_rest_event → info::read_info miss (resting.rs:248) → 'WOKE_FAIL:{id}: info.json absent or unreadable — not a hosted perch'. cmd_send (cli.rs:5142) DOES fall back on a local miss; cmd_rest's remote arm (cli.rs:3307, wan_rest) already handles every WanRestOutcome — it is simply never reached on a bare-id local miss. Contradicts CONTEXT:286 'a wake must route'. Q3 SUBSTRATE GAP: resolve_across_visible (registry.rs:971) filters only by Status::routable() and its Ambiguity payload is node-hexes-only — it CANNOT express the Q3 status rule; per-candidate (node,status) comes from SubnetRegistry::instances(id). FIX: a NEW pure select_rest_target helper (status-aware, isolated from resolve_across_visible which cmd_send keeps) applying GOAL-SATISFACTION semantics (ADR/triage addendum @188d269, NOT naive verb symmetry — the mixed case breaks symmetry): wake is an ∃-goal (satisfied when ANY instance Active), suspend is a ∀-goal (satisfied when ALL instances Suspended); one helper parameterized by the verb's satisfaction predicate — 0 candidates→NotFound; goal already satisfied→NoOp naming the satisfying node(s); exactly 1 ACTIONABLE (not-at-target) instance→Act(node); >1 actionable→Ambiguous(copy-paste id@node list). Edge rulings: wake with >1 Active = NoOp naming ALL active nodes (NOT Ambiguous — nothing actionable); suspend mixed (X suspended + Y active, NOT ∀-satisfied) = Act(Y) if exactly one active / Ambiguous if several active. Candidate status is ADVERTISED/gossiped (post-A-1 shared-derivation, may be STALE) so a NoOp verdict is ADVISORY and the qualified id@node path is the operator override (noted in the helper doc-comment). cmd_rest's bare-id local miss loads snapshots → instances(id) → select_rest_target → dispatches (Act→wan_rest to the node / NoOp naming node(s) / Ambiguous render_refusal copy-paste id@node list / NotFound NO_ENDPOINT), all F-1 public language from day one. Qualified id@node path unchanged; shutdown leg-2 stays LOCAL_ONLY. Red-first: a bare id present ONLY in a remote registry snapshot routes to that node instead of WOKE_FAIL.
2026-07-11T01:39:54.1365462Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1365500Z 
2026-07-11T01:39:54.1365606Z ### REQ-SESSION-ADAPTER-RECORDED
2026-07-11T01:39:54.1370255Z - Title: D-2 (REMOTE-TRUTH triage §D-2 + operator Q5 @c248afc): the session ledger records the adapter[:profile] a session ran under, so a later resume can restore the harness the session actually used (not merely the endpoint's CURRENT stamp). ROOT: SessionEntry (spt-store/sessions.rs:58) carries ts/session_id/trigger/cwd/ordinal but NOT the adapter — a resume-from-history row cannot know which harness authored the transcript, so a resume under a since-changed endpoint adapter (B-2 ChangeAdapter, or a fork) launches the wrong harness. FIX: an ADDITIVE `adapter: Option<String>` on SessionEntry, exact cwd/ordinal serde pattern (#[serde(default, skip_serializing_if="Option::is_none")]) — a pre-migration row missing the key deserializes None; None omits the key on serialize (byte-identical to old rows); an unknown key on an old reader is ignored (serde default) — back-compat BOTH directions. Stamped at every PRODUCTION session-boundary append. CENSUS (doyle-confirmed @94f0205, corrects the triage-era 5-site drift to the real 3): startup.rs:317 (live bind boot row, rec.adapter in scope), reporting.rs:94 (boundary rotation row UNDER the mutate_info lock, capture adapter_for_ledger=rec.adapter beside cwd_for_ledger), ready.rs:119 in crates/spt-msg (ready-agent boot row, rec.adapter in scope). NOT digest.rs:601 (cfg(test) fixture) and NOT a livehost psyche-ledger append (none exists — the live /clear|/compact boundary shells `api boundary` → reporting.rs:94, the SAME append). None-stamp is a benign degrade (resume falls back to the endpoint's current adapter).
2026-07-11T01:39:54.1370380Z - Required stages: impl, unit
2026-07-11T01:39:54.1370408Z 
2026-07-11T01:39:54.1370512Z ### REQ-RESUME-ADAPTER-FOLLOWS-SESSION
2026-07-11T01:39:54.1376404Z - Title: D-2 (REMOTE-TRUTH triage §D-2 + operator Q5 @c248afc): a resume-from-history restores the RECORDED session adapter (REQ-SESSION-ADAPTER-RECORDED) — the resumed harness is the one the session ran under, re-stamped onto the endpoint PRE-SPAWN, and an unregistered recorded adapter refuses LOUDLY before launching anything. ROOT: the picker's resume_outcome (model.rs:1285) bakes adapter=ep.adapter_profile from the selected ENDPOINT, ignoring the ledger row — so a resume always uses the endpoint's CURRENT adapter even when the session ran under a different one; and the endpoint's info.adapter is never re-stamped to the row's on the resume path (cli.rs:1962 skeleton writer early-returns for an existing perch — adapter immutable, carried by bind's stamp_creation_fields). FIX (doyle fork ruling): ResumeRow (model.rs:199) gains adapter: Option<String> threaded from SessionEntry.adapter in picker/data.rs; the row title (model.rs:228) renders [{adapter}] when Some ({head} [{adapter}] - {time} (…{id5})); resume_outcome bakes the ROW's adapter with an endpoint fallback (row.adapter.unwrap_or(ep.adapter_profile)) — None → the endpoint's current stamp (benign degrade). The pre-spawn RE-STAMP + refusal ride the picker resume dispatch (mod.rs:360 Run arm, resume.is_some()) reusing the hazard-guarded mutate_info seam (write_adapter_change/mod.rs:336), NEVER the bind path: order = read current info.adapter → if the baked adapter DIFFERS (a real replace; a None-row bakes the endpoint's own → equals current → NO write) → registered-check via resolve_option (Err(NotRegistered) → loud F-1 refusal naming the adapter + `spt adapter add`, NO stamp, NO spawn) → write_adapter_change re-stamp → spawn. ONE adapter write path (the mutate_info seam); REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER's bind/hook path (stamp_creation_fields, home.rs) UNTOUCHED — both its guard tests stay green as the gate condition. Red-first: a resume row adapter="claude-spt" over an endpoint stamped "claude-spt:ccs" → the baked Outcome.adapter == "claude-spt" (the deliberate replace) and the pre-spawn stamp writes it.
2026-07-11T01:39:54.1376719Z - Required stages: impl, unit
2026-07-11T01:39:54.1376753Z 
2026-07-11T01:39:54.1376847Z ### REQ-WAKE-RESUME-LEG
2026-07-11T01:39:54.1382383Z - Title: A-2 (REMOTE-TRUTH triage §A-2 + ADR-0033): the daemon reconcile gains a WAKE-RESUME LEG — an endpoint whose rest INTENT is Active but whose harness session is COLD (status != online) is resumed by the daemon via the adapter's [session.resume] template using the LAST LEDGER session id, so a bare `spt wake <id>` on a suspended live agent actually brings it back (today: reconcile_once start-arm hosts ONLY status==online (livehost.rs:199), so a woken-but-unbound endpoint is skipped forever — neither status reaches online nor does reconcile re-host). This is the ADR-0033 LIFT: the thin `spt wake` edge writes rest intent, the DAEMON does the work. Mirrors shellwake::resolve_wake (read rest state, live-pid double-launch guard, launch, NEVER flip status — the harness self-binds → online). The leg reads the recorded adapter (D-2, REQ-SESSION-ADAPTER-RECORDED); an UNREGISTERED recorded adapter is the Q5 daemon-variant refuse: do NOT spawn, record a LOUD host_error report (F-1 naming the adapter + `spt adapter add`), never silent, never fallback-spawn on a different adapter. BINDS: (1) status=online is set ONLY by a real bind — the resume leg NEVER stamps it (CONTEXT liveness truth; the A-1 effective-state derivation depends on this staying honest). (2) host_error is a REPORT of the most recent host-level failure, NEVER a liveness input — neither liveness nor advertised_status reads it (host_error + online still derives Active); cleared on a successful host/bind; the existing silent `continue` on a deregistered online adapter (livehost.rs:205) folds into the same field. (3) the resume-pid guard marker is CUSTODY-ONLY (F-030 nested-record discipline) — never a liveness input. cold-with-no-ledger-row degrades benign (loud-logged skip, no crash, today's behavior). Single-node; C-2 picker Wake-now unblocks after. --wait is a SEPARATE rider (REQ-WAKE-WAIT).
2026-07-11T01:39:54.1382509Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1382655Z 
2026-07-11T01:39:54.1382749Z ### REQ-WAKE-WAIT
2026-07-11T01:39:54.1384521Z - Title: A-2 rider (REMOTE-TRUTH triage §A-2): `spt endpoint wake --wait` blocks on the REAL bind (status reaches online) after the daemon wake-resume lift (REQ-WAKE-RESUME-LEG), instead of the DEFAULT accepted-not-bound print (thin edge writes intent, daemon lifts async — ADR-0033). Reuses the F-027 bind-await machinery if/when it lands, else a bounded poll on status==online with a plain-language timeout (no core lingo, F-1). Default wake is UNCHANGED (accepted-not-bound truth). Separate chunk from the core leg (doyle A-2 ruling: C-2 needs the core leg, not --wait); F-027 bind-await stays design-only until this activates.
2026-07-11T01:39:54.1384621Z - Required stages: 
2026-07-11T01:39:54.1384650Z 
2026-07-11T01:39:54.1384747Z ### REQ-PICKER-REMOTE-WAKE
2026-07-11T01:39:54.1391141Z - Title: C-2 (REMOTE-TRUTH triage §C-2 #4 + addendum @3442ce5): a REMOTE suspended picker row offers `Wake now` — waking the endpoint THROUGH its owning node's rest edge (the A-2 daemon resume leg) — instead of a bare `Start now` that silently cold-starts a COLLIDING LOCAL instance of a remote id (node-anchored identity violation, ADR-0003/0023). ROOT (certain): confirm_options collapsed Suspended into the offline action set = [Start,…]; on a REMOTE row `Start` bakes Outcome::Run with NO node → picker dispatch → cmd_endpoint_run creates a fresh LOCAL perch of the remote id (model.rs confirm_terminal / mod.rs dispatch). Remote rows are only Online/Suspended, so remote+offline == remote-suspended. FIX: confirm_options splits the offline arm on is_local — remote → vec![Wake] (a new ConfirmOption::Wake), local → vec![Start] UNCHANGED; confirm_terminal(Wake) → a new Outcome::Wake{id,node} carrying the RAW node hex; dispatch routes crate::cli::cmd_endpoint_wake_remote(id,node) → cmd_rest(id@node, RestEvent::Wake) = the EXISTING WAN rest arm (dispatch_wan_rest → wan_rest), and A-2's resume leg revives the session async (the full loop the operator wanted). `Instantiate locally` stays the separate deliberate-copy verb. ADDENDUM correction (a): EndpointRow.node is the LOSSY DISPLAY string (node_label_display = 'LABEL (prefix…)'), which node_qualifier_matches (full-hex-prefix|exact-label) CANNOT match — a dead Wake; so a NEW EndpointRow.node_key: String carries the raw ResourceRow.node hex (empty for local rows — Wake is remote-only) threaded through from_resource_row + the 4 literal ctors. CO-GATE (b, addendum): ChangeAdapter (was `offline`-gated) is gated `offline && is_local` — write_adapter_change → resolve_perch_path(Infer) → mutate_info rewrites a LOCAL perch record, so offering it on a remote suspended row is the SAME colliding-local-write-for-a-remote-id class (the Start twin); a remote node's adapter is not ours to rewrite from here. Red-first: a remote suspended row → confirm_options has Wake NOT Start NOT ChangeAdapter, and confirm_terminal(Wake) → Outcome::Wake{node==raw hex} (never a local Outcome::Run); a LOCAL offline row is UNCHANGED (Start + ChangeAdapter).
2026-07-11T01:39:54.1391399Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1391422Z 
2026-07-11T01:39:54.1391533Z ### REQ-HAZARD-BROKER-FLOOR-LOCK-POISON
2026-07-11T01:39:54.1399075Z - Title: B-1 (REMOTE-TRUTH triage §B-1, PIVOTED @e5eb99a): NO bare `.lock().unwrap()` on a broker-resident lock reachable from serve/dispatch — a brain-only self-update keeps the broker + all its Mutexes ALIVE (REQ-UPD-3), so a single panic under one poisons it PERMANENTLY: the next `.lock().unwrap()` panics, kills its per-conn reply thread, and EVERY subsequent attach silently deadlines ('brain IPC read deadline elapsed') while non-locked ops keep working. TRIAGE-DRIFT (sweep-dispatch-site-counts discipline): the triage named 3 sites (broker.rs:1163 flush_inject_floor / :1297 inject-worker-open / :2142 buffer_if_held) as the surviving class, but ALL 3 are the INJECT FLOOR and were ALREADY poison-proofed by REQ-HAZARD-INJECT-WORKER-POISON (lock_floor, shipped post-triage — the FLOOR HALF is SUBSUMED, this seed redirects). The SURVIVING class (matching the triage's own symptom description) is the ATTACH-PATH lock set: self.sessions Mutex<HashMap> ×18 + its sessions_exit alias ×1, the per-session OutputLog RING ×11 (log/h.log/log_drain/log_exit), pair_holds ×4 — 34 production bare .lock().unwrap() (cfg(test) excluded). FIX (doyle B-1 ruling): recover ALL THREE via ONE shared `recover<T>(&Mutex<T>) -> MutexGuard<T>` helper (into_inner idiom, same as lock_floor / the effect journal bug #16 — safe for the short coherent-on-recovery map ops of sessions/pair_holds), plus `recover_log(&Mutex<OutputLog>)` for the ring which adds a COHERENCE CLAMP on the poison-recovery path: a panic mid-append can leave the ring torn (over-cap, a last seq not below next_seq, non-monotonic front/back) and serving those bytes risks garbage, so OutputLog::clamp_or_reset cheap-checks the invariants and RESETS the ring empty (next_seq preserved — cursors never rewind) + loud-logs on violation. Rationale: fail-fast on the log reintroduces the very wedge B-1 kills (poisoned log = every subscriber attach panics forever); blind recover serves torn bytes; clamp-or-reset costs only scrollback that self-heals on the next PTY output + repaint (lost scrollback << permanent wedge, torn-serve eliminated not tolerated). Sessions/pair_holds recover bare (short map ops, coherent-on-recovery). CLASS invariant (KNOWN-HAZARDS 7.33): any new broker-resident lock uses recover/recover_log or a documented fail-fast justification. Red-first: a scripted panic-under-sessions-lock → recover hands back a usable guard, the next attach still opens; a TORN-RING variant → recover_log clamps/resets so the subscriber gets sane bytes.
2026-07-11T01:39:54.1399394Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1399423Z 
2026-07-11T01:39:54.1399519Z ### REQ-CONTROLLER-LIVENESS-REAP
2026-07-11T01:39:54.1407407Z - Title: B-2 (REMOTE-TRUTH triage §B-2, REDUCED @bdc1242): a stale ONLINE+CONTROLLED stamp on a live-session perch self-heals — the info.json driven_by/controlled RECORD is made to match the broker's SINK-TABLE TRUTH. ROOT (persisted-stale-stamp class, doyle Q1): the livehost control reap gates on !has_session (reconcile_hosted_liveness), and a brain-only update KEEPS the session (REQ-UPD-3), so a controller stamp that went stale WHILE the session lived was never re-derived from broker truth. NOT a transport bug: (a) a persisted conn is the REQ-UPD-3 feature; (b) an idle-severed conn eventually EOFs via QUIC keepalive → handle_conn detach (path 1) — and the reason paths 1-3 previously failed to clean up was the B-1 broker floor-lock POISON WEDGE (cleanup panicked under the poisoned lock), now fixed. REDUCTION (doyle, my ground-truth): the prescription was 80% pre-built — converge_perch_stamps (broker.rs, REQ-HAZARD-CONTROL-STAMP-CONVERGENCE) ALREADY converges info.json driven_by/controlled to the broker's controller_by/has_controller on EVERY KIND_SESSIONS poll, and the livehost reconcile already TRIGGERS that poll per tick (query_live_session_endpoints). So NO new IPC query, NO new livehost arm, NO 5th detach path — the ONLY gap is that a controller whose WRITER THREAD died (severed conn: the writer failed a socket write, or a detach dropped by the prior B-1 wedge) still reports controller_by=Some/has_controller=true, so converge keeps the stale stamp. FIX: a broker-side lazy-reap in the KIND_SESSIONS snapshot closure — OutputLog::reap_dead_controller() drops a controller whose _writer.is_finished() BEFORE controller_by/has_controller are read, so the reply + the off-lock converge both see the honest (cleared) state and the stamp clears. LOCK-SAFE: the reap drops the sink in-memory ONLY (no stamp_driven_by → no info.json I/O under the log lock, the KH 7.12/5.16 lock-across-effect discipline); the OFF-lock converge_perch_stamps writes the honest stamp. KH 7.15 held by construction: the reap only ever CLEARS, never latches driven_by; a LIVE (idle, parked-on-rx.recv) controller is is_finished()==false so it is NEVER false-reaped. RESIDUAL (doyle Q2 accepted): a TRULY IDLE severed controller (writer parked on recv, no output, conn not yet EOF'd) stays is_finished()==false and converges only on output-resume / conn-EOF — that harder active-probe case is the RESERVED REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT (SessionInfo.controller_by doc), deliberately NOT built here so the reserved seed keeps its scope. Red-first: a dead-writer sink → reap clears it (controller_by honest None → converge clears the stamp); a live-writer sink → UNTOUCHED (no-false-reap control).
2026-07-11T01:39:54.1407631Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1407655Z 
2026-07-11T01:39:54.1407756Z ### REQ-ADAPTER-FLOOR-ENFORCE
2026-07-11T01:39:54.1415563Z - Title: F-5 (REMOTE-TRUTH triage §F-5 + doyle rulings 2026-07-05): BOTH adapter acquisition verbs (spt adapter add + spt adapter update) REFUSE when the installed spt-core is BELOW the adapter's declared [adapter].min_spt_core_version floor — with an F-1 operator refusal naming the installed core, the floor, and the next action (update spt-core first). ROOT: the floor was PARSED + required (manifest.rs) but never compared to the running core — dead enforcement; and the [update].version_check knob that gated it was DOC'D-BUT-DEAD (never read by any production path — a contract lie). RULINGS: RETIRE version_check (drop the manifest field + schema + docs + the cfg(test) literals; a pre-existing manifest still setting it deserializes fine — serde ignores the unknown key, no deny_unknown_fields, so retiring is back-compatible); SEMVER-compare NOT string-compare (the 0.9.0 < 0.25.0 lexical trap); enforce on BOTH verbs; nothing installs / registry untouched on refuse (binds both verbs, no residuals). FIX: (1) a pure spt-runtime version_meets_floor(core, floor) -> bool (numeric per-component: split '.', u64, missing→0, non-numeric→0, first-diff decides, equal-when-zero-padded ⇒ satisfied) — mirrors the CLI version_is_newer parse (same numeric model, different question: freshness=strictly-newer vs floor=at-least). (2) ADD: the gate lives INSIDE registry::register (the choke point) via a register_with_core(core_version) seam register() delegates to with env!(CARGO_PKG_VERSION) — the floor check runs right after the manifest parse, BEFORE any registry write, returning the typed RegistryError::CoreFloor{adapter,core,floor} (Display = the ONE F-1 refusal both verbs surface); nothing recorded on refuse. (3) UPDATE: a PRE-SWAP peek (staged_floor_ok) extracts the staged .spt to a THROWAWAY temp, parses its manifest floor, and refuses BEFORE apply_release_crc_swap mutates the live pointer-mode home — so a refusal (or an unverifiable floor: FAIL-CLOSED) leaves the live install BYTE-UNTOUCHED; register@8932 stays as the defense-in-depth backstop for every other entry path. doyle bind: the register-only gate would let the crc-swap replace the live files with a floor-violating version while the record refuses (record and reality disagree — the exact contract-lie shape this milestone kills), so the pre-swap peek is the only correct answer. Red-first: perri negative repro on ADD (fresh home + synthetic low core + high-floor manifest → CoreFloor refuse, registry untouched) + the UPDATE pre-swap refuse (live home byte-untouched) + a floor-met positive control (0.25.0-on-0.25.0 installs); + version_meets_floor table incl. the 0.9<0.25 trap.
2026-07-11T01:39:54.1415807Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1415835Z 
2026-07-11T01:39:54.1415935Z ### REQ-RUN-ID-REUSES-ADAPTER
2026-07-11T01:39:54.1419921Z - Title: D-1 (REMOTE-TRUTH triage §D-1): `spt endpoint run --id <id>` with NO --adapter, when <id> names an EXISTING perch, REUSES that perch's recorded info.adapter and runs NON-INTERACTIVELY — instead of always falling to the picker as a create-new prefill (an existing endpoint retyping its own adapter, or being sent to a create-new flow, is the operator wart). ROOT (certain, no design tension): the cli `match (adapter,id)` special-cased only (Some,Some)→cmd_endpoint_run; the catch-all routed EVERY lone --id to crate::picker::run as a create-new prefill, never considering an existing endpoint (cli.rs ~1290). FIX: a PURE resolve_run_target(adapter, id, recorded) over the 4 (adapter?,id?) quadrants — (Some,Some)→Direct{a,id}; (None,Some(id))→ recorded adapter present (info.adapter = adapter-chosen-at-creation, spt-store info.rs:167) → Direct{recorded,id}, absent/no-perch → Picker{None,Some(id)} (today's create-new prefill UNCHANGED); (Some,None)/(None,None)→Picker unchanged. The perch lookup (read_info(resolve_perch_path(id,Infer)).adapter) is INJECTED as a closure so the router is pure + testable without a perch on disk; resume threads into BOTH Direct paths. Red-first: (None,Some(id),recorded=Some) → Direct (pre-fix this routed to Picker create-new). int (live run --id on an existing perch reuses its recorded adapter non-interactively) deferred to the rig.
2026-07-11T01:39:54.1420171Z - Required stages: impl, unit
2026-07-11T01:39:54.1420199Z 
2026-07-11T01:39:54.1420310Z ### REQ-PICKER-PURGE-SHORTCUT
2026-07-11T01:39:54.1423842Z - Title: C-3 (REMOTE-TRUTH triage §C-3 #8): the pick-existing list gains an `x` purge shortcut — on an OFFLINE LOCAL highlight, `x` opens a small in-TUI confirm screen (Screen::ConfirmPurge, the B-2 ChangeAdapterPick shape) and Enter purges via the ONE existing purge core `cmd_endpoint_purge(id, yes=true, force=false)` — NEVER the core's stdin [y/N] (it fights the picker's raw mode; the confirm screen IS the confirm). The shortcut INHERITS both purge gates (offline-only + node-local, cli.rs cmd_endpoint_purge / CONTEXT:189): gated-off presses stay on the list and FLASH WHY (online → offline-only, remote → local-only). force=false is deliberate — the model gate is advisory; the core's own offline check is the authority, and a race to online between gate and purge must REFUSE, never stop-then-purge. After a successful purge the picker STAYS (inline outcome, like Shortcut/ChangeAdapter): the row leaves the in-memory list (remove_endpoint, cursor re-clamped) + flash PURGED:{id}. Hint truth (B-1/F029 discipline): the pick legend renders `x purge` ONLY when purge_key_live() — the same predicate the handler gates on. Red-first: purge outcome reachable ONLY from an offline LOCAL highlight (online/remote → no screen change + why-flash).
2026-07-11T01:39:54.1424037Z - Required stages: impl, unit
2026-07-11T01:39:54.1424062Z 
2026-07-11T01:39:54.1424162Z ### REQ-PICKER-BACK-NAV
2026-07-11T01:39:54.1426757Z - Title: C-4 (REMOTE-TRUTH triage §C-4 #9): Backspace is a back() ALIAS across the picker — one keypress backs out one screen along the SAME reverse map Esc walks (model back(), complete for all screens incl. the C-3 ConfirmPurge), and from the kind layer it cancels the picker (Esc parity) — EXCEPT the two text-edit contexts, where Backspace stays CHAR-DELETE: CreateId entry (id_backspace) and the pick-list filter mode (filter_backspace). DELIBERATE: no empty-buffer fallthrough to back() in the text contexts — mixing delete and nav on one key invites miskeys mid-typing; Esc already backs out (the triage's optional extra, declined). Pure key routing in handle_key (picker/mod.rs) ahead of the per-screen arms; zero model change (the reverse map pre-existed). Red-first: Backspace on Confirm → PickExisting (pre-fix: dead key); on CreateId with a buffer → buffer shortens, screen unchanged; empty buffer → STILL no nav.
2026-07-11T01:39:54.1426866Z - Required stages: impl, unit
2026-07-11T01:39:54.1426895Z 
2026-07-11T01:39:54.1426996Z ### REQ-RC-RECONNECT
2026-07-11T01:39:54.1432577Z - Title: B-3 (REMOTE-TRUTH triage §B-3, the operator-asked UX): the rc attach viewport RECONNECTS on a severed transport instead of print-and-exit. Pre-fix rc was one-shot (resolve→dial→attach→pump→parting line); FAULT-MATRIX row 9 over-promised. FIX: the establish sequence (daemon ensure → broker conn → session resolve local-first/cross-node → dial → attach-open w/ A-4b tracing retry → subscribe) is factored into establish_attach and run_attach_inner wraps establish+pump in a loop. RECONNECTABLE class = severed transport ONLY: PumpEnd::BrokerGone (broker-conn EOF class, broker bounce) + the NEW PumpEnd::Severed (serve-side stream EOF AFTER rendered output = remote conn drop — pre-fix MISLABELED as 'detached — still running'; a nothing-rendered EOF stays the honest NoLiveSession refuse). FINAL ends (Exited/Detached/Displaced/Stalled/NoLiveSession) never re-drive — re-attaching a deliberately-ended session is wrong. On sever: full-screen centered 'Reconnecting to {target}…' banner (pure byte-emit like StatusRow; target = owning-node label or 'local daemon'; Q4 UX rule — operator language, internal sever detail never paints), then re-drive establish_attach every RECONNECT_PAUSE (1s) inside RECONNECT_WINDOW (30s, generous for a daemon bounce); a Detach keypress mid-window aborts honestly to [detached]; window expiry → PumpEnd::ReconnectGaveUp with a plain-language give-up line naming the cause, the window, and the retry action (never op/read-err lingo). Per re-establish: fresh OpMinter (ADR-0034 rc tracing per viewport), fresh initial resize (PTY matches the CURRENT terminal), pump-local render cursor resets so the re-serve ring replay REPAINTS the screen the banner cleared. FAULT-MATRIX row 9 made TRUE (F-3), not edited down. Red-first: serve-EOF-after-render → Severed (vs the pre-fix false Detached); only BrokerGone/Severed classify Reconnect.
2026-07-11T01:39:54.1432896Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1432925Z 
2026-07-11T01:39:54.1433031Z ### REQ-SELF-DETECT-PARENT-PID
2026-07-11T01:39:54.1437523Z - Title: E-1 (REMOTE-TRUTH triage §E-1 #7): self-detect leg (c) — the pid-ancestry fallback — ALSO candidates on `rec.parent_pid` (the harness pid, CONTEXT's 'stable session-binding anchor', stamped at bind), not `rec.pid` alone. ROOT: for an spt-hosted endpoint (broker PTY, headless) `rec.pid` is the ephemeral bind-CLI pid, ALREADY DEAD by send time (the F-026 #11 dead-pid class, field-sighted on hall-bf) — never in any sender's ancestry and alive-gated out — so an spt-hosted sender could NEVER resolve self via leg (c): its messages were from-stamped `cli@NODE` (operator #7) and replies bounced NO_PERCH. FIX: detect_self_by_ancestry pushes a second candidate (id, parent_pid) when `rec.parent_pid` is Some + alive; the pure nearest-first matcher (match_self_by_ancestry) is unchanged. LABEL-ONLY, exactly like the rest of leg (c): from-label/routing default, NEVER authentication — authenticate() untouched, the pid-ancestry-for-auth question stays parked (KH 7.3/7.5 separation holds; a wrong label self-corrects, a wrong grant does not). Env legs (a)/(b) stay first. Red-first int (the triage-specified missing test): rec.pid = dead sibling + rec.parent_pid = genuine live ancestor → self resolves (pre-fix None); ancestry-gate control: live-but-non-ancestor parent_pid must NOT resolve. Rider (same cluster, activated separately once doyle rules the fix shape): F-026 #11 dead-pid itself — rec.pid should hold something that stays true, or liveness readers stop trusting it. Cross-node from-stamp proof (spt-hosted B-side sender arrives at A as `<id>@node`, not `cli@node`) rides the [twohost] rig wave rung.
2026-07-11T01:39:54.1437641Z - Required stages: impl, int
2026-07-11T01:39:54.1437670Z 
2026-07-11T01:39:54.1437774Z ### REQ-HAZARD-DEAD-REC-PID
2026-07-11T01:39:54.1441329Z - Title: E-1 rider (F-026 #11 dead-pid class, doyle-ruled SCOPED 2026-07-05 — KNOWN-HAZARDS 7.34): a dead `rec.pid` on an spt-hosted perch is EXPECTED, not staleness — the recorded pid is the ephemeral bind-CLI pid, which dies immediately after bind (the broker holds the PTY; no resident harness process at that pid). NO reader may alive-gate on `rec.pid` alone: spt-hosted LIVENESS comes from the daemon-managed status field (KH 2.5 — status present ⇒ authoritative, never a per-pid probe); IDENTITY comes from session/ancestry resolution where `rec.parent_pid` (the harness pid, the stable session-binding anchor) is the ancestry candidate (REQ-SELF-DETECT-PARENT-PID). Re-stamping rec.pid with the harness pid (shape (a)) is OVERRULED: ADR-0021 demoted pid to a bind-time seed hint (re-anchoring truth there reverses the design); every pre-existing record keeps the old CLI pid so readers need the scoped discipline anyway (migration hole); blast radius (every rec.pid consumer + KH 2.5 external-perch probe semantics) buys nothing the reader-side fix doesn't. CLASS rule: any newly sighted rec.pid-alive-gating reader gets the same scoped fix and EXTENDS this requirement's evidence — no new REQ per reader.
2026-07-11T01:39:54.1441649Z - Required stages: doc, int
2026-07-11T01:39:54.1441678Z 
2026-07-11T01:39:54.1441788Z ### REQ-SOFT-END-PRESERVES-LIVE-LISTENER
2026-07-11T01:39:54.1447052Z - Title: F-2 (REMOTE-TRUTH triage §F-2, field-repro'd hall-bf 2026-07-04): a /clear must not sever a SURVIVING poll listener's relay address — post-clear owl-path send hit NO_PERCH while ready was present and the inject path healthy. ROOT (source-certain): the relay registry row (id→addr + owning pid, registered by the LISTENER process itself at PollListener::bind, listener.rs:109) is DELETED by the adapter's soft `api session-end` (reporting.rs:231) fired for the DEPARTING session at /clear; but the poll listener SURVIVES /clear (a session-independent process, still bound on its port), so the deletion destroys a TRUE row. The C-2 boundary re-stamp (REQ-HAZARD-BOUNDARY-READY-STRAND) restores ready + status online but CANNOT re-register — only the listener process knows its socket addr — so every subsequent send lookup misses → NO_PERCH forever (until a listener restart re-binds). FIX: the SOFT arm of cmd_session_end unregisters CONDITIONALLY through the single liveness resolver (liveness::is_registry_entry_alive — the KH 2.5-aware resolver clean_stale_entries routes through): a row whose owner is still ALIVE is PRESERVED (the row is LISTENER-scoped truth, not session-scoped; the listener outliving /clear is the designed shape), a dead/offline row is removed (today's cleanup kept). The ERASE arm stays unconditional (a hard wipe orphans any listener; its row dies with the endpoint). Every legitimate teardown keeps its OWN unregister untouched: PollListener close/close_busy/Drop (listener.rs) and the stop verbs (cli.rs:5574/:10924). Defense-in-depth unchanged: a wrongly-preserved dead row still self-heals at delivery (deliver.rs failed-dial sweep, REQ-HAZARD-REGISTRY-STALE-CLEAN). Red-first: soft session-end with a live registered owner → row survives and lookup still resolves (pre-fix: deleted → NO_PERCH).
2026-07-11T01:39:54.1447191Z - Required stages: impl, unit
2026-07-11T01:39:54.1447220Z 
2026-07-11T01:39:54.1447319Z ### REQ-PUBLIC-ERROR-SURFACES
2026-07-11T01:39:54.1451753Z - Title: F-1 (REMOTE-TRUTH triage §F-1, Q4 UX rule, operator-ruled): CLI stderr a non-developer can hit names the OBSERVABLE SITUATION + the NEXT ACTION — never journal/op/brain/store lingo. The sweep's named offenders: (1) `RC_FAIL:{id}: … brain IPC read deadline elapsed` — the brain transport error surfaced RAW through rc's residual Err arm (rc.rs run_attach_inner); operators read 'brain IPC' where the situation is 'the daemon didn't answer in time'. (2) `WOKE_FAIL:{id}: info.json absent or unreadable — not a hosted perch` (resting.rs apply_event miss) — store-file lingo in the one rest-verb line a stale remote row still surfaces cross-node (the qualified-arm D6 case; the A-3 bare-id local path already routes instead). The miss stays SINGLE-SOURCED from NOT_A_HOSTED_PERCH_MARKER (in-process discriminant, resting.rs — reword is compat-safe per its own doc; the drift-pin unit keeps builder+matcher fused). (3) translation_fault never human-rendered (F-030 post-release seed): a broker-stamped input-translation fault (e.g. 'inject worker panicked') was invisible in `endpoint list`/`whoami` while keystrokes silently degraded — rendered now as a SELF-pin annotation exactly like the psyche_host_error pattern (REQ-HAZARD-LIVEHOST-BOOT-RACE), human line + additive skip-if-none JSON field. Kin to banked patterns: public --help no internal codes; 'Updated' not 'trial'. The A-4b retry terminal + B-3 give-up line + A-3 routing strings shipped F-1-clean already — this REQ sweeps the stragglers and is the home for future sightings (extend, don't multiply).
2026-07-11T01:39:54.1452019Z - Required stages: impl, unit
2026-07-11T01:39:54.1452049Z 
2026-07-11T01:39:54.1452147Z ### REQ-WORKER-SID-SYMMETRIC-AUTH
2026-07-11T01:39:54.1454721Z - Title: W-2 (WORKER-TRUTH triage, operator-ruled 2026-07-06): worker verbs go sid-symmetric with every sibling id-scoped verb — worker-start mints NO token and worker-stop takes NONE (token custody is undue adapter burden, ruling via perri). Registration STORES the sid it authenticated (the parent's sid at start; today cmd_worker_start hardcodes session_id="" — worker.rs:44 — so a sid-authed stop compares against empty and refuses 100%). Stop accepts the parent's CURRENT sid OR the stored registration sid (a /clear between start and stop rotates the parent's sid; either rotation endpoint is honest custody — the REQ-PSYCHE-SID-CUSTODY rotation reasoning). Under the ruling the field adapter's existing emission (worker-stop <id> --session-id <parent sid>) becomes contract-correct as-is. Publish the frozen verb shape to the docs-site with the landing wave (perri blind-builds from published docs).
2026-07-11T01:39:54.1454884Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1454917Z 
2026-07-11T01:39:54.1455012Z ### REQ-WORKER-REAP
2026-07-11T01:39:54.1457670Z - Title: W-3 (WORKER-TRUTH triage): worker records must not persist indefinitely past their useful life — 6 dead-pid workers leaked OFFLINE on flynn (kill-paths where SubagentStop never fires: parent killed, abort, timeout). The stored rec.pid is the ephemeral worker-start hook process (dead by design — the REQ-HAZARD-DEAD-REC-PID class; NEVER an alive-gate signal). Honest reap signals: (a) parent-session lifecycle — reap the parent's soft-stopped + orphaned workers at parent session-end/boundary and on parent-death detection (a worker cannot outlive its parent's live session); (b) a generous TTL floor since `created` as belt-and-braces. Soft-stop preservation semantics (REQ-HAZARD-SOFT-CLEANUP: results drain before reap) stay honored — reap after drain-or-expiry, never mid-flight hard-delete (cascade-wipe guard rationale stands). Sister shape: claude_skill_owl doctor D-21 orphan-worker GC.
2026-07-11T01:39:54.1457789Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1457818Z 
2026-07-11T01:39:54.1457917Z ### REQ-WORKER-LIST-VISIBILITY
2026-07-11T01:39:54.1459831Z - Title: V-1 (WORKER-TRUTH triage, operator rider): worker perches leave the DEFAULT `spt endpoint list` view — they are process-local machinery, not subnet citizens; leaked-or-live worker rows rendering as permanent OFFLINE endpoints is the operator-visible symptom root. A dedicated flag (--workers) reveals them (one command + flag per the --all/--detail precedent, NOT a separate list-working command — sister divergence deliberate). Applies to the human render, --json (additive default-absent filter), and the registry/projection legs; verify-and-stop any worker gossip into the subnet registry as peer endpoints.
2026-07-11T01:39:54.1459936Z - Required stages: impl, int
2026-07-11T01:39:54.1459974Z 
2026-07-11T01:39:54.1460070Z ### REQ-WORKER-PICKER-EXCLUDED
2026-07-11T01:39:54.1461286Z - Title: V-2 (WORKER-TRUTH triage, operator rider): non-drivable endpoint classes never render as `spt endpoint run` picker rows — a worker perch cannot be driven, instantiated, or controlled; offering it is a lie the picker then fails on. Filter endpoint_type worker (and the psyche class if it ever surfaces — same non-drivable family) at every picker source leg, extend-not-multiply for future non-drivable classes.
2026-07-11T01:39:54.1461390Z - Required stages: impl, unit
2026-07-11T01:39:54.1461419Z 
2026-07-11T01:39:54.1461515Z ### REQ-WORKER-MINTED-NAME
2026-07-11T01:39:54.1463017Z - Title: N-1 (WORKER-TRUTH triage, operator rider): worker perch identity is CORE-MINTED and parent-derived — `{parent}-w{N}` with a per-parent counter at registration (sister shape: claude_skill_owl hook_subagent_start.rs) — never the adapter-presented agent id (CC Task ids render as random-named rows). worker-start mints + echoes the id (WORKER_STARTED:{parent}-w{N}); the adapter's agent_id/agent_type ride the record as correlation METADATA, not identity. Verb-shape contract change — freeze with W-2 in ONE coordination with perri.
2026-07-11T01:39:54.1463290Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1463318Z 
2026-07-11T01:39:54.1463423Z ### REQ-ADAPTER-TEMPLATE-KEY-VALIDATION
2026-07-11T01:39:54.1465629Z - Title: P-1 core half (WORKER-TRUTH triage): `adapter add`/`adapter update` validate every declared role template — command, cwd, and [env] inject values — against the substitution-key catalog (spt-runtime BASE_KEYS + role-specific overrides) and REFUSE registration naming the offending key + role (fail-fast family of the [strings] pointer validation). Field driver: flynn's psyche died on the RETIRED {psyche_dir} key (adapter psyche_resume carried the old psyche_init cwd shape) — a permanent template config fault must die loudly at registration, not at the Nth per-event psyche turn via the 3-strike budget. The catalog stays the single source (runtime.rs FILL_KEYS — 'a catalog key must have a real fill'); validation reads it, never a second list.
2026-07-11T01:39:54.1465750Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1465778Z 
2026-07-11T01:39:54.1465877Z ### REQ-PSYCHE-SPAWN-ENV-PARITY
2026-07-11T01:39:54.1469275Z - Title: P-2 (WORKER-TRUTH triage addendum, perri-filed field finding 2026-07-06): the per-event psyche_resume spawn threads the perch record's CAPTURED read_env stamps into the spawn ENVIRONMENT — the F-027 Half-B env-parity contract (BINDING, design-frozen: read_env captured at creation + stamped on the record + threaded IDENTICALLY to every session spawn; the spawn never reads its own process env for a stamped var) extended to the psyche role the design predates. Field driver: flynn (claude-spt:ccs) — the ccs wrapper relocates the account root via CLAUDE_CONFIG_DIR at PARENT launch and the perch record correctly captured it, but the daemon spawns psyche_resume with bare env → default ~/.claude root → headless 'Not logged in' exit-1 → strike loop; psyche + parent land in DIFFERENT account roots (auth AND root-scoped continuity both break). Core stays harness-agnostic (threads whatever [env] direction=read captured — knows nothing of CLAUDE_CONFIG_DIR). Scope note: this is the URGENT psyche leg of F-027 Half B; the full pre_spawn seam + endpoint-session env threading stays design-parked (F-027-ENDPOINT-SPAWN-FAIL-DESIGN.md) unless operator pulls it forward.
2026-07-11T01:39:54.1469450Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1469479Z 
2026-07-11T01:39:54.1469571Z ### REQ-PAIR-NTP-MULTIHOME
2026-07-11T01:39:54.1472151Z - Title: W1/D1 (JOIN-TRUTH): the ceremony NTP query reaches a server on EITHER IP family — `query_unix_secs` (ntp.rs) must iterate every address `to_socket_addrs()` resolves (not just the first) and bind a socket of the matching family per candidate (IPv4 addr → bind 0.0.0.0:0; IPv6 addr → bind [::]:0), first successful answer wins. ROOT (proven 3/3-FAIL via our exact code on enlyzeam): today `UdpSocket::bind(("0.0.0.0",0))` is v4-only and `send_to(&packet, server)` sends ONLY to the FIRST resolved addr — time.google.com resolves 4×AAAA before any A on a v6-first dual-stack box → the primary server is PERMANENTLY unreachable via our code (w32tm reaches it over v6), silently halving NTP redundancy (pool.ntp.org v4 carried everything; a DNS rotation making BOTH v6-first would zero it). Fix keeps the lazy-cache/TTL/fallback contract of REQ-PAIR-8 unchanged — only the socket/resolve leg changes.
2026-07-11T01:39:54.1472294Z - Required stages: impl, unit
2026-07-11T01:39:54.1472322Z 
2026-07-11T01:39:54.1472409Z ### REQ-PAIR-NTP-LOUD-FAIL
2026-07-11T01:39:54.1474513Z - Title: W1/D2 (JOIN-TRUTH): total NTP failure (no server on any family answered) is LOUD, not silent — a node running the ceremony on its raw skewed system clock must be visible. ROOT: current_offset_secs (ntp.rs) does `query_offset_secs().unwrap_or(0)` and eprintln's ONLY on a nonzero success, so an all-servers-unreachable refresh is indistinguishable from 'clock agrees'. Fix: log the TRANSITION into all-servers-failed once per refresh (suggested `NTP_TOTP_UNCORRECTED: all NTP servers unreachable — ceremony clock = raw system clock`) and the recovery transition back to corrected; the OFFSET_TTL already bounds refresh cadence so no per-call spam. Fallback behavior (offset 0 → system clock) is UNCHANGED — this adds observability only.
2026-07-11T01:39:54.1474803Z - Required stages: impl, unit
2026-07-11T01:39:54.1474832Z 
2026-07-11T01:39:54.1474937Z ### REQ-HAZARD-CEREMONY-CLOCK-STEP
2026-07-11T01:39:54.1477626Z - Title: W1/D3 (JOIN-TRUTH, KNOWN-HAZARDS): the cached ceremony offset goes stale-WRONG when the OS clock STEPS under a live daemon — an offset measured against the OLD clock keeps applying for up to the 15-min TTL. Field-proven timeline (enlyzeam): refresh cadence 15:08/15:23/15:38/15:53; operator `w32tm /resync` stepped the clock −210s at 15:45:46; every `subnet join` returned NO_SEED_HOLDER until a daemon bounce forced a fresh query. Fix: the cache snapshot stores an (Instant, SystemTime) PAIR; on read, if |wall-elapsed − mono-elapsed| > ~2s the clock stepped ⇒ force an immediate refresh (offset recomputed against the new clock). PLUS: `meet_seed_holder` (pairhost.rs), on search-deadline exhaustion, forces ONE fresh NTP refresh + one final sweep before returning NO_SEED_HOLDER — so a stepped-clock join self-heals without a bounce. Clock reads must be seam-injectable for the hazard unit (inject the (mono,wall) pair — do NOT sleep 15 min).
2026-07-11T01:39:54.1477743Z - Required stages: impl, unit
2026-07-11T01:39:54.1477772Z 
2026-07-11T01:39:54.1477867Z ### REQ-JOIN-VERBOSE-CLOCK
2026-07-11T01:39:54.1479977Z - Title: W2/D4 (JOIN-TRUTH): the JOINER side is no longer blind to its own ceremony clock — `spt subnet join --verbose` prints the joiner's derived TOTP step, the applied offset seconds, and the NTP correction state (corrected / uncorrected) per meet sweep; the same triple folds into `meet_failure_detail` so the NO_SEED_HOLDER verbose block carries it. ROOT: diagnosing enlyzeam required shipping a compiled probe over ssh because the member logs PAIR_MEET_UP step=N but the joiner surfaces nothing about its OWN step/offset — the exact asymmetry that hid D1-D3. Extends REQ-JOIN-DIAGNOSTICS's --verbose without a new knob. CLI help changes → xtask docs gen, no internal REQ codes in clap /// (docs-token gate).
2026-07-11T01:39:54.1480088Z - Required stages: impl, unit
2026-07-11T01:39:54.1480117Z 
2026-07-11T01:39:54.1480215Z ### REQ-JOIN-DEFERRED-ELEVATION
2026-07-11T01:39:54.1483263Z - Title: W2 (JOIN-TRUTH, operator UX ruling verbatim): 'if --code was not supplied, don't spawn the elevated subnet-join window until a target machine is discovered → just in time for the code prompt.' When --code is ABSENT and the process is UNELEVATED, run the name prompt + ALREADY_MEMBER check + ensure_daemon + the MEET phase (brain.pair_meet) UNELEVATED; only on MetMember spawn the elevated window via the EXISTING try_auto_elevate machinery (the elevated re-run re-executes the join flow — its second meet is cheap, the member is proven present). A FAILED search must NEVER show a UAC/sudo/pkexec prompt. The --code path is UNCHANGED (gate-first, one-shot). The unelevated phase performs ZERO trust mutation — meet is pre-trust per REQ-JOIN-TWO-PHASE/ADR-0030. RULED OUT (doyle): cross-elevation hold-session adoption (passing the daemon-held pair session_id into the elevated process) — a new security seam we don't need; the elevated re-run re-meets instead. The elevation gate MOVES from command-entry to the enrollment boundary; discovery is read-only pre-trust.
2026-07-11T01:39:54.1483381Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1483409Z 
2026-07-11T01:39:54.1483508Z ### REQ-ECHO-DROP-DIR-RESOLVE
2026-07-11T01:39:54.1486202Z - Title: W1 (LIFECYCLE-TRUTH): fire_echo resolves the manifest commune_dir through the SAME resolver its siblings use before any write. ROOT (pinned): fire_echo (spt-daemon lifecycle.rs:790) passes the RAW manifest commune_dir into run_echo_commune -> echo.rs:115-117 create_dir_all+join; a relative `.claude` under the WMI-launched daemon's System32 cwd = os error 5 deterministic (two live psyches stamped FAILED on it). Siblings already resolve correctly (ingest ~:583, psyche_drop_file :1072 via resolve_endpoint_drop_dir(raw, cwd)). FIX: fire_echo routes through resolve_endpoint_drop_dir; relative-with-no-cwd = SKIP LOUD (stderr), never a raw relative write — kills the latent-worse variant where a writable daemon cwd writes the drop to a WRONG dir silently (echo communes lost, no error). Hardening riders (same touch, no separate REQ): bounded EACCES retry on the drop write; echo claude spawn gets explicit cwd = endpoint cwd (perri ask).
2026-07-11T01:39:54.1486503Z - Required stages: impl, unit
2026-07-11T01:39:54.1486526Z 
2026-07-11T01:39:54.1486641Z ### REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS
2026-07-11T01:39:54.1487899Z - Title: W1 (LIFECYCLE-TRUTH): EVERY successful psyche operation clears psyche_host_error — not just the pulse-loop leg. ROOT (three field confirmations, perri): the stamp clears only via note_turn_outcome's Ok leg (lifecycle.rs:1101); a SUCCESSFUL psyche op via checkpoint/wake bypasses it -> stale FAILED stamp sits over a healthy psyche. FIX: event turn, checkpoint/wake synthesis, and signoff echo all clear the stamp on success.
2026-07-11T01:39:54.1488008Z - Required stages: impl, unit
2026-07-11T01:39:54.1488038Z 
2026-07-11T01:39:54.1488148Z ### REQ-PSYCHE-ROLE-OPTIONAL-SKIP
2026-07-11T01:39:54.1489249Z - Title: W1 (LIFECYCLE-TRUTH): a manifest with NO [session.echo_commune] role SKIPS commune-sync (debug-level note, no strike) instead of hard-failing the turn. ROOT (perri filing, recovered): missing role -> commune-sync hard-fails -> 3-strike stamps the host ('manifest declares no [session.echo_commune] role') while the published contract presents the role as an optional template. FIX: missing OPTIONAL role = skip, not a turn failure.
2026-07-11T01:39:54.1489350Z - Required stages: impl, unit
2026-07-11T01:39:54.1489384Z 
2026-07-11T01:39:54.1489508Z ### REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE
2026-07-11T01:39:54.1493443Z - Title: W2 (LIFECYCLE-TRUTH, KNOWN-HAZARDS, flagship — the update wedge): PTY viewer fan-out and control mutations must not depend synchronously on a live draining brain. ROOT rig-CONFIRMED (NtSuspendProcess on the brain, no update involved): brain-subscriber session-output writes ride UNDER the per-session log lock (broker.rs:19-20); failed writes are handled (cursor freeze + detach :3486) but BLOCKED writes are not. Suspended brain => within seconds attached rc output freezes; detach does NOT release the control stamp (release routes through the brain); reattach REFUSED (controlled-by); rc --take hangs; daemon status stays healthy. Field: every brain cycle (incl. every update apply) has a freeze window; a stalled/slow-draining new brain = permanent wedge until bounce; brain.ready != subscribers drained. FIX SHAPE (todlando proposes, doyle RULES BEFORE IMPL): subscriber writes move OFF the log lock (bounded/nonblocking, stall => detach-subscriber like viewer eviction — broker already buffers + replays on re-attach, so a detached-stalled brain self-heals by rewind); control stamp release/take completes against the BROKER without brain round-trip (or bounded with loud timeout). doc = KNOWN-HAZARDS entry. Int (tonight's rig, encoded): suspend brain child mid-session -> attached viewer ticks CONTINUE + rc --take completes; resume -> no output lost (cursor replay).
2026-07-11T01:39:54.1493568Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1493601Z 
2026-07-11T01:39:54.1493709Z ### REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL
2026-07-11T01:39:54.1495356Z - Title: W3 (LIFECYCLE-TRUTH): daemon restart no longer massacres hosted endpoints — daemon start RE-RUNS previously-online spt-hosted endpoints. ROOT rig-proven: daemon stop+start (the apply notice's OWN instruction) kills every hosted endpoint; they stay OFFLINE after start (no resurrection) though records exist (info.json status + adapter + cwd). SCOPE RULING (doyle): re-run-on-start, marked start-reason=daemon-restart; agents' minds ride psyche re-host as today. Int: endpoint online -> daemon stop -> start -> endpoint back ONLINE, same id, harness respawned.
2026-07-11T01:39:54.1495599Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1495623Z 
2026-07-11T01:39:54.1495772Z ### REQ-UPDATE-ONE-SHOT-FINISH
2026-07-11T01:39:54.1497363Z - Title: W3 (LIFECYCLE-TRUTH): update apply works daemonless and one command finishes the cycle. ROOT (operator wart): update fetch/apply run ensure_daemon_announced (cli.rs:4386) -> on a stopped box they BOOT THE OLD broker pre-swap, guaranteeing the mixed old-broker/new-brain pair + a manual bounce. FIX: apply works daemonless (swap + record, next start runs new bytes); `update apply --finish` (name subject to docs-token gate) completes the cycle: swap -> brain cycle -> broker restart onto new bytes (rides REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL so the restart is not a massacre). CLI change -> xtask docs gen, no internal codes in clap ///.
2026-07-11T01:39:54.1497468Z - Required stages: impl, unit
2026-07-11T01:39:54.1497496Z 
2026-07-11T01:39:54.1497605Z ### REQ-DAEMON-STOP-LIVE-SESSION-WARN
2026-07-11T01:39:54.1498078Z - Title: W3 (LIFECYCLE-TRUTH, promoted old follow-wave seed): `daemon stop` with live hosted sessions warns + requires --force (or names the sessions it will kill) instead of silently killing them.
2026-07-11T01:39:54.1498173Z - Required stages: impl, unit
2026-07-11T01:39:54.1498197Z 
2026-07-11T01:39:54.1498293Z ### REQ-RC-RECONNECT-TRUTH
2026-07-11T01:39:54.1499973Z - Title: W3 (LIFECYCLE-TRUTH): rc reconnect never auto-starts a daemon and never hangs forever. ROOTS rig-proven (the operator's long-standing 'stop 2-4 times' bug): (a) an rc client's reconnect loop AUTO-LAUNCHES a daemon via WMI (rig: DAEMON_LAUNCH_VIA_WMI from the rc) — resurrection fights the operator's stops; (b) rc freezes at 'Reconnecting to local daemon…' forever when its session died with the broker. FIX: rc NEVER auto-starts a daemon (reconnect only to an already-up broker; loud 'session lost — daemon down' exit otherwise), bounded reconnect with visible countdown.
2026-07-11T01:39:54.1500092Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1500120Z 
2026-07-11T01:39:54.1500215Z ### REQ-DAEMON-STDERR-PERSIST
2026-07-11T01:39:54.1501426Z - Title: W3 (LIFECYCLE-TRUTH, observability): broker + brain stderr tee to a rotating size-capped file under SPT_HOME (e.g. 2x5MB), stamped per generation. ROOT: detached daemon nulls stdio -> the 2026-07-06/07 incident window left ZERO logs (both RCAs ran blind; rigs had to recreate everything). KNOWN-HAZARDS note: never inherit handles (REQ-HAZARD-DETACHED-DAEMON-STDIO) — open the file in-process, don't pipe.
2026-07-11T01:39:54.1501537Z - Required stages: impl, unit
2026-07-11T01:39:54.1501561Z 
2026-07-11T01:39:54.1501674Z ### REQ-UPDATE-PROMOTE-DRAINED
2026-07-11T01:39:54.1505025Z - Title: W3 (LIFECYCLE-TRUTH, mechanic-d MOVED FROM W2 per doyle gate verdict @e5ae7a9 — binding): the update-apply brain-generation promotion completes only when the OLD generation's broker subscriber connection is CLOSED or stall-EVICTED — never while blocked writes still pend on it. ROOT: `brain.ready` != subscribers drained; W2's stall-evict (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE) only BOUNDS the false-promote window to BRAIN_WRITE_DEADLINE (15s), it does NOT close it — a new brain can signal ready inside that window while the old gen's conn is still wedged, so the apply 'promotes' onto a still-frozen control plane (the 22:47 incident-night false-promote). FIX: the promotion gate (ADR-0018 brain-trial, brainproc.rs) adds an explicit DRAINED precondition — promote only on ready AND old-gen-subscriber-drained (conn closed OR stall-evicted); the drained signal reads broker truth (the W2 stall-evict tally / the old conn's liveness), no brain round-trip. The residual W2 left open, now closed. Int = a FALSE-PROMOTE rig that exercises the promotion path itself: an old-gen subscriber conn held wedged past ready must NOT promote until it drains (RED-first: ready-alone promotes).
2026-07-11T01:39:54.1505315Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1505344Z 
2026-07-11T01:39:54.1505444Z ### REQ-UPDATE-TRIAL-DRAIN-DRIVE
2026-07-11T01:39:54.1516301Z - Title: UPDATE-WEDGE (counter-54, doyle-ruled 2026-07-09 — regression of the v0.29.0 seamless brain-swap): a brain generation DRIVES the broker's controller-liveness reap (a KIND_SESSIONS poll) each heartbeat throughout its boot/trial loop, so a hard-KILLED prior generation's black-holed LOCAL controller conn (by:None) is stall-evicted within the trial window and can never permanently strand the promotion DRAINED gate. ROOT (2026-07-09 field freeze, `spt update fetch --apply` v0.30.0->v0.30.2 froze all 7 live PTYs ~30s then rolled back): the promote gate (run_trial, brainproc.rs:657-661) needs BOTH `ready_generation==gen` AND `old_gen_drained()`; `old_gen_drained()` = `!any_local_controller_wedged()` (brainproc.rs:534) is a PURE READ of `write_blocked_since` (broker.rs:2703) — it never DRIVES the evict. The evict (`stall_evict_controller`, broker.rs:1039, same 15s `brain_write_deadline` the wedge-read uses) only runs via `reap_dead_controller` (broker.rs:967, severed->drop ELSE stall-evict) inside the KIND_SESSIONS snapshot closure (broker.rs:2879). During the isolated brain-trial window NOTHING polls KIND_SESSIONS: the old brain was hard-killed (`child.kill()`, brainproc.rs:851) so its local controller conn black-holes (live PTYs keep writing to a dead Windows named pipe -> writer BLOCKS, never EOFs) -> `write_blocked_since=Some` -> wedged=true for the full 30s -> gate false -> `WindowElapsedAlive` -> kill+rollback. The candidate DID reach ready (write_ready, brainproc.rs:211, runs before the loop; the v53 log's NET_FAMILY_GATE/PAIR_MEET_UP prove the loop was entered) — so `BRAIN_TRIAL_TIMEOUT: candidate alive but never ready` is the MISLEADING ready-stamped-but-never-DRAINED case, NOT a resume_sessions hang. SECOND LEG (recovery): post-rollback the gen-2 brain's KIND_SESSIONS poll finally reaps -> `BRAIN_SUBSCRIBER_STALL_EVICT:1` fires >15s late -> a session stayed black-holed through recovery -> continued freeze. ONE root, BOTH legs. FIX (BRAIN-SIDE, self-applying — doyle ruled brain-side to AVOID a broker-side coordinated-restart flag): the boot/trial heartbeat loop (brainproc.rs run_brain, currently only `net_status` at :244) also issues `Brain::sessions()` (KIND_SESSIONS, brain.rs:1397 — already exists) every heartbeat, driving the LIVE older broker's ALREADY-SHIPPED reap (>=v0.29.0 LIFECYCLE-TRUTH; the field-stuck broker is v0.30.0 so it HAS it). The old-gen wedged conn is stall-evicted ~15s < the 30s window -> `old_gen_drained()` flips true -> PROMOTE; the same poll on the rollback/recovery brain reaps promptly -> no >15s black-hole -> kills the STALL_EVICT recovery leg. Drive it on the FIRST heartbeat (no one-tick wait) and on BOTH the trial candidate AND the recovery brain (one loop covers both). SELF-APPLIES because it drives the current broker's existing reap verb — v54's brain fixes the v0.30.0->v54 update with NO coordinated broker restart. Forward-compat: brokers <v0.29.0 have neither the DRAINED gate nor the reap, so older-broker updates never hit this path — no regression. Composes with REQ-UPDATE-PROMOTE-DRAINED (the gate this un-strands) + REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict it drives) + REQ-CONTROLLER-LIVENESS-REAP (the reap verb). Int = the brain-swap-under-live-sessions rig: (1) with a hard-killed prior gen holding a wedged by:None controller past 15s, the new brain PROMOTES within the window AND sessions stay served across the cycle (RED-first: without the drive, WindowElapsedAlive->rollback); (2) a deliberately-failing trial auto-rolls-back AND the restored brain re-drives EVERY session with NO BRAIN_SUBSCRIBER_STALL_EVICT.
2026-07-11T01:39:54.1516548Z - Required stages: doc, impl, int
2026-07-11T01:39:54.1516577Z 
2026-07-11T01:39:54.1516686Z ### REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE
2026-07-11T01:39:54.1523037Z - Title: SEED (DEFERRED, doyle 2026-07-09 — post-counter-54 root-hardening for UPDATE-WEDGE; mint now, impl a FUTURE milestone): on a PLANNED brain-restart (`BRAIN_UPDATE_RESTART`, the seamless update-apply brain-cycle), the outgoing brain's LOCAL (by:None) controller conns are GRACEFULLY CLEAN-CLOSED as the brain is cycled, instead of hard-killed and left to black-hole. ROOT (field-pinned 2026-07-09, daemon.stderr.log L24277-24303): the update-restart path hard-kills the outgoing brain (`child.kill()`, brainproc.rs:851); its live-agent controller conns then block on dead pipes (never EOF) → the broker reads them WEDGED (broker.rs:2695-2700) → the new candidate's promotion DRAINED gate (`any_local_controller_wedged`, broker.rs:2704) stays true until the W2 stall-evict matures (~15s). REQ-UPDATE-TRIAL-DRAIN-DRIVE (counter-54) makes the candidate DRIVE that reap so it promotes within the 30s window — but at a ~15s wedge-maturity hitch (frozen PTYs during the swap). A CLEAN close makes the conn 'simply absent → drained=false AT ONCE → fast promote' (broker.rs:2699-2700), ELIMINATING the hitch = truly seamless (honors the paradigm the field freeze broke). SUPERSEDES the earlier livehost-reattach framing of 'Fix Y': livehost is SPAWN-FRESH (fresh session uuid/pid per boot, nothing to re-attach — wrong site, and it never ran in the trial window); the correct site is the brain-cycle / update-restart path (a bounded graceful-drain of the outgoing brain BEFORE the kill). Non-trivial: hard-kill → bounded graceful drain; a drain that hangs must NOT wedge the swap (timeout then kill anyway, never block the update). Composes with REQ-UPDATE-TRIAL-DRAIN-DRIVE (defense-in-depth reap-drive REMAINS for any conn that still black-holes — a peer/relay conn, a drain-timeout kill) + REQ-UPDATE-PROMOTE-DRAINED (the gate) + REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict). Int: a planned update-restart under a live-agent controller conn → the new candidate promotes WITHOUT waiting the ~15s wedge-maturity (drained reads false immediately, no STALL_EVICT), RED-first vs the current hard-kill-then-reap-drive ~15s hitch.
2026-07-11T01:39:54.1523220Z - Required stages: 
2026-07-11T01:39:54.1523244Z 
2026-07-11T01:39:54.1523355Z ### REQ-LIVEHOST-RECONCILE-TRIAL-SILENT
2026-07-11T01:39:54.1528233Z - Title: SEED (DEFERRED investigation, doyle 2026-07-09 — UPDATE-WEDGE follow-up): determine WHY the trial/rollback brain's livehost reconcile loop did NOT drive the broker controller-reap (nor re-host the live agents) during the ~30s field update-trial window, when livehost polls `query_live_session_endpoints()` → `brain.sessions()` (KIND_SESSIONS) UNCONDITIONALLY every `LIVE_RECONCILE_INTERVAL_MS`=5000ms (livehost.rs:1026). CONTEXT (surfaced building the counter-54 rig): livehost's 5s KIND_SESSIONS poll drives the SAME broker `reap_dead_controller` sweep the fix drives — so it would otherwise reap the 15s-matured wedge by ~T20 < the 30s trial and SELF-HEAL. It didn't (field froze 30s → rollback), so the field trial-brain livehost was silent/delayed (PIN Q2: no `DAEMON_RESTART_RESUME` under gen-1/gen-2; the 30s kill landed before/around livehost's first reconcile tick). The counter-54 fix (REQ-UPDATE-TRIAL-DRAIN-DRIVE) puts a RELIABLE 500ms reap-driver in run_brain's CORE heartbeat loop, making the wedge-reap INDEPENDENT of livehost — so this does NOT block counter-54. But the livehost silence is a latent anomaly with a SECOND consequence: live-agent HARNESS re-hosting was also delayed ~30s (a separate freeze contributor). Investigate: does `spawn_live_host`'s reconcile thread start promptly on a trial-brain boot, or is its first tick delayed past the trial window? Does its brain conn / `query_live_session_endpoints` block against the swap/wedge state? Register concrete REQ(s) once the mechanism is pinned. RELATED: [[REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE]] (if the outgoing brain's black-holed conns perturb the new brain's livehost conn setup).
2026-07-11T01:39:54.1528360Z - Required stages: 
2026-07-11T01:39:54.1528390Z 
2026-07-11T01:39:54.1528728Z ### REQ-BRAIN-RESUME-NO-CONTROL-STEAL
2026-07-11T01:39:54.1540056Z - Title: UPDATE-WEDGE round 2 (v0.30.4, doyle-ruled 2026-07-09 — field incident on the counter-54 fetch--apply): a brain-respawn must NEVER steal, then stall-evict, the controller of a broker PTY session the daemon brain does not DRIVE. ROOT (field-pinned + SME, docs/UPDATE-WEDGE-2-RCA.md + docs/UPDATE-WEDGE-2-SME-todlando.md): `resume_sessions` (brain.rs:985) re-attaches EVERY session `KIND_SESSIONS` returns via `subscribe` = `subscribe_with(AttachIntent::Control, by:None)` (brain.rs:1450-1455). The docstring's 'a None identity never displaces (falls back to viewer)' is a MYTH for FREE / SAME-LOCAL-IDENTITY slots: `resolve_subscribe` (broker.rs:1134-1153) stall-evicts FIRST, then `become_controller` if the slot is now free OR the incumbent is also local (None==None) — viewer-fallback fires ONLY when a DIFFERENT REMOTE controls. So on a box with N spt-hosted broker PTYs, a brain-respawn STEALS the by:None controller of every free/local-controlled session (incl. the operator's LOCAL `spt rc`), which the daemon brain never drains (it hosts no PTY sessions — brainproc.rs:184) → 15s later `stall_evict_controller` (broker.rs:1039) releases driven_by → the session is UNCONTROLLABLE (Failure A). It also head-of-line-blocks the shared brain↔broker conn on the N-session controller-replay burst → every journaled `spt rc` retake deadlines ('brain IPC read deadline', the REQ-BROKER-ATTACH-JOURNAL-RESILIENT / #16 shared-conn symptom) → global rc failure on ALL N (Failure B). Field 2026-07-09 (operator-confirmed): fetch--apply 0.30.2→0.30.3 PROMOTED CLEANLY (the counter-54 fix worked) but under 7 spt-hosted PTYs (ALL with LOCAL by:None controllers) the resume SILENTLY STOLE all 7 (become_controller same-local re-take, NO Displaced notice → orphaned, output froze immediately, no rc-detach splash) + blocked every rc retake. The 5-vs-2 stall-evict split is ACTIVE-vs-IDLE, not remote-vs-local: 5 producing output → stolen writer blocked >15s → stall-evict; 2 idle → writer parked → no evict, but still silently stolen+frozen. The counter-54 promotion fix did NOT cause this — pre-existing resume-steal latent bug, hidden until N broker PTYs were present at a respawn; the single-black-holed-session A'-rig never exercised N-live-controllers-under-replay. FIX (brain-side): `resume_sessions` re-attaches as **Viewer** (`AttachIntent::Viewer`), NOT Control — a viewer never touches driven_by and is never stall-evicted (broker.rs:1063+ bounded try_send + private eviction), so steal-then-drop vanishes and the operator keeps/regains control; and it relieves shared-conn pressure (a slow viewer is DROPPED, never a 15s controller block) so rc retake gets through. Control ONLY for sessions the daemon brain genuinely DRIVES (empty set today → all become Viewer; forward-correct for the live-agent-adapter future). SECONDARY (escalation, ONLY if the gate shows residual B): stagger the resume re-attach + bound the viewer replay so the respawn burst can't saturate the conn. Int = the multi-broker-PTY-session RESPAWN rig (the coverage the A'-rig lacked): N real broker-spawned sessions with controllers producing output → real brain respawn/promote → assert (1) EVERY session keeps its controller across the swap (no stall-evict of a session the brain doesn't drive), (2) `spt rc` attaches/retakes IMMEDIATELY post-promote (no shared-conn saturation), (3) promotion still succeeds. RED-first: the current Control re-attach steals+evicts + deadlines rc. Composes with REQ-UPDATE-TRIAL-DRAIN-DRIVE (the orthogonal counter-54 promote fix), REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict it stops mis-firing on non-driven sessions), REQ-BROKER-ATTACH-JOURNAL-RESILIENT (the #16 shared-conn resilience). Distinct from REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE (that = the OLD brain's outgoing black-hole; this = the NEW brain's resume-steal).
2026-07-11T01:39:54.1540296Z - Required stages: doc, impl, int
2026-07-11T01:39:54.1540324Z 
2026-07-11T01:39:54.1540437Z ### REQ-BRAIN-RESUME-NO-CONN-DEADLOCK
2026-07-11T01:39:54.1551674Z - Title: UPDATE-WEDGE round 3 (v0.30.5, doyle-ruled Option A 2026-07-09 — the v0.30.4 field-verify re-wedge, root code-PROVEN + dead-peer-INDEPENDENT): the daemon brain must NOT subscribe broker PTY sessions onto its own request/reply IPC conn — it has no consumer for that output and the subscription DEADLOCKS the conn. ROOT (todlando code-read, docs/UPDATE-WEDGE-2-ROUND3-CODEREAD.md; the net-runtime AND the counter-54 reap-drive were both FALSIFIED first — docs/UPDATE-WEDGE-2-ROUND3-RIG-VERDICT.md): a conn's send half is a single `SharedSend = Arc<Mutex<SendHalf>>` (broker.rs:78). Subscriber writer threads (`viewer_writer` broker.rs:1333/1342, `controller_writer` :1451) hold `send.lock()` ACROSS a BLOCKING `write_frame`; the dispatch reply path (`send_frame` :4221 → KIND_SESSIONS_REPLY / KIND_NET_STATUS_REPLY) needs the SAME lock. `resume_sessions` (brain.rs:1031→1054) subscribes every session as a Viewer onto the brain's MAIN conn — which is ALSO the brain's request/reply channel. The daemon brain hosts no PTY sessions (brainproc.rs:184) so run_brain never drains that output; it reads the conn only during the 500ms-heartbeat net_status()/sessions() calls (drain-and-DISCARD, `_ => continue`). When an actively-streaming session backs the conn up, a subscriber writer BLOCKS in write_frame holding send.lock() → the dispatch thread can't send the heartbeat reply → net_status()/sessions() never return → the heartbeat loop stalls → the brain never drains → the writer stays blocked = SELF-DEADLOCK on the brain conn's send mutex → every subscriber writer on it wedges → BRAIN_SUBSCRIBER_STALL_EVICT (controller writer blocked >15s). BOTH severities, one mechanism: RESPAWN (resume subscribes N + the replay burst floods the conn before the loop drains) AND STEADY-STATE (an active streamer's output between heartbeats fills the socket buffer). Counter-54 (REQ-UPDATE-TRIAL-DRAIN-DRIVE) added a 2nd per-heartbeat reply round-trip (sessions()) through the contended mutex — WIDENED the window (regression-window-exact), did not create it. The round-2 Viewer fix (REQ-BRAIN-RESUME-NO-CONTROL-STEAL) removed the STEAL but kept the brain a SUBSCRIBER — viewer_writer has the same send.lock()-across-write pattern AND viewers have no stall-evict valve — so v0.30.4 field-verify wedged again. FIX (Option A, brain-side, SEAMLESS): resume_sessions does NOT subscribe (drop the subscribe_with call; §3 verification guard confirmed NO brain consumer — digest/relay/net-consumer/shellwake/presence — reads the resumed subs). The brain conn then carries only request/reply → no subscriber backpressure → no deadlock. Keep the session_cursors seed only if harmless. Rides the brain-swap ⇒ seamless (no daemon.rs:368 broker restart). Option B (a dedicated Split-reader drain of the brain conn, brain.rs:230 — the pump's carrier) is the FORWARD path for when genuinely daemon-DRIVEN sessions land (the live-agent adapter) — deferred, noted, not built. Option C (the broker-side durable CLASS fix) = REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK, deferred. Int = the confirmer rig (brain+broker+PTY, brain_decouple template): N sessions actively producing output, brain resume-subscribed onto its req/reply conn; RED-first = heartbeat stalls + an active-streaming controller stall-evicted >15s WITHOUT any dead peer present (proves dead-peer-independence); assert BOTH severities (respawn interleave + steady-state output backup); Option A turns both green. Composes with REQ-BRAIN-RESUME-NO-CONTROL-STEAL (the round-2 Viewer fix this supersedes as the wedge cure), REQ-UPDATE-TRIAL-DRAIN-DRIVE (the counter-54 reap-drive that widened the window), REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict it stops triggering).
2026-07-11T01:39:54.1551915Z - Required stages: doc, impl, int
2026-07-11T01:39:54.1551943Z 
2026-07-11T01:39:54.1552033Z ### REQ-DIGEST-GENERATION-SUPERSEDE
2026-07-11T01:39:54.1559328Z - Title: W3 (LIFECYCLE-TRUTH, digest projection truth — flynn filing spt-mobile d0aa3f4): a one-shot `endpoint digest --json` snapshot must return each logical activity row ONCE across a checkpoint/resume, not once per seq-generation. ROOT (spt-core-side, not a consumer bug): the K-session span (digest.rs activity_spanned, SPAN_SESSIONS=5) runs the [digest] extractor per session file and tags each row seq=(ledger_ordinal<<32)|localseq (REQ-DIGEST-CURSOR). A checkpoint/resume (self-/clear + Psyche rebuild) makes the harness REPLAY the prior generation's transcript into the NEW session file, so the ancestor's rows appear in BOTH the ancestor file AND the resume file at the SAME localseq — the span UNIONS them, one logical row surfacing under two full seqs (gen23,local208) + (gen25,local208), identical text/ts/localseq. Consumers dedup by exact seq (the documented authoritative key) so nothing collapses -> duplicate rows in every snapshot / `--after` view (`--follow from:0` is CLEAN — it reads current-generation only; the SPAN is the sole culprit). The trigger cannot disambiguate: `api boundary clear` records SessionTrigger::Clear for BOTH a fresh /clear (disjoint) and a carry-forward checkpoint (reporting.rs:94) — so a structural skip-ancestor needs new boundary metadata + adapter cooperation, deferred. FIX (doyle ruling — flynn Option 1 Supersede, projection-local, source-independent): within the span, collapse cross-generation replay dupes — an Activity record from an OLDER ordinal is dropped when an identical logical record (role, ts, text, tool) exists under a NEWER ordinal; keep the NEWEST-ordinal occurrence so the surviving seq is the live generation (snapshot + follow agree on seq). Cross-generation ONLY (never dedup within one ordinal — a session cannot replay itself; identical within-gen rows are real). Supersede runs on the raw span items BEFORE the window fold (project_timeline) so window_turns counts real turns, not phantoms; and a boundary divider adjacent to a now-fully-superseded ancestor is not left orphaned. Context entries (REQ-TERM-7, single digest.log) are not per-session-spanned -> untouched. Int = a two-session span rig where session B's extracted lines are a superset replay of A (same ts/text at same localseq) + B's own new tail: RED-first (pre-fix shows every A row twice); post-fix each logical row appears ONCE under B's generation, B's tail intact, the /clear boundary marker preserved when A retains rows.
2026-07-11T01:39:54.1559666Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1559699Z 
2026-07-11T01:39:54.1559796Z ### REQ-UPDATE-FINISH-COMMUNE-FLUSH
2026-07-11T01:39:54.1564645Z - Title: DEFERRED (post-LIFECYCLE-TRUTH, operator-ruled 2026-07-07 — mint now, impl a FUTURE milestone): make the update swap LOSSLESS for live hosted endpoints by flushing a final echo-commune per endpoint BEFORE the brain-subtree reap. ROOT (operator-surfaced probing --finish): `update apply --finish` = daemonless swap -> daemon RESTART; the graceful `daemon stop` path (daemon.rs:316-325) raises brain_stop then reaper.reap() KILLS the brain subtree (brain + shellwake watchers + detached Psyches) as one unit — there is NO per-endpoint final commune before the kill. ENDPOINT-SURVIVAL (REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL) then RESPAWNS each orphaned online spt-hosted endpoint, but from its LAST commune (whatever the ongoing per-event echo-commune cadence last saved), NOT an as-of-swap checkpoint — so mid-turn / uncommuned work is lost across the bounce. Today's mitigation is operator discipline: commune-before-swap. FIX (future): the stop/finish path, before reap, drives each LIVE hosted endpoint's final echo-commune (fire_echo final context save) so the respawn resumes from a swap-fresh checkpoint. Composes with ENDPOINT-SURVIVAL (commune -> reap -> respawn) and the W1 echo pipeline (REQ-ECHO-DROP-DIR-RESOLVE / REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS). Bounded + loud per endpoint (a commune that hangs must not wedge the stop — timeout then reap anyway, never block the swap). Int: a live hosted endpoint with uncommuned state -> --finish -> respawned endpoint's digest/psyche reflects the pre-swap state (RED-first: without the flush the respawn shows only the last-cadence commune).
2026-07-11T01:39:54.1564888Z - Required stages: 
2026-07-11T01:39:54.1564917Z 
2026-07-11T01:39:54.1565054Z ### REQ-SELF-ID-TRUST-INJECTED-ENV
2026-07-11T01:39:54.1570577Z - Title: DEFERRED to a followup vX.X.n sprint (post-LIFECYCLE-TRUTH, operator-ruled 2026-07-07): self-identity resolution must trust the harness-injected authoritative id and detect a stomped perch instead of silently mis-attributing. ROOT (doyle /diagnose 2026-07-07, field: agent sends stamped `cli@HFENDULEAM` / mis-attributed): `resolve_from` (cli.rs:5480) stamps `cli@<node>` when `detect_self_id` (roster.rs:103) returns None; detect_self_id resolves self ONLY by reverse-lookup — matching `$OWL_SESSION_ID` against a perch's info.json.session_id (then SPT_AGENT_ID, then parent_pid) — and IGNORES `SPT_ENDPOINT_ID`, the authoritative self-id the adapter injects (present in-env as SPT_ENDPOINT_ID=<id>). When a perch record is STOMPED (a cross-id info.json overwrite — the REQ-SPAWN-COLLISION-GUARD-LIVE-DUP damage class; field case: doyle's live session_id written into the deployah perch), the reverse-lookup mis-resolves (doyle session -> `deployah`) or fails (real deployah -> None -> `cli@node`), and the CLI silently believes the stomped store. FIX: detect_self_id PREFERS `SPT_ENDPOINT_ID` when set+non-empty (the harness-authoritative id, immune to a stompable perch), AND cross-checks it against the reverse-resolved perch id — a mismatch logs LOUD (a stomped/duplicated perch becomes a self-diagnosing signal, not a silent wrong identity). Bare-CLI (no SPT_ENDPOINT_ID) keeps the reverse-lookup then the `cli@node` fallback. Also reconcile the adapter/core self-id env contract (SPT_ENDPOINT_ID vs SPT_AGENT_ID vs OWL_SESSION_ID — which is canonical). NOTE: W4 REQ-SPAWN-COLLISION-GUARD-LIVE-DUP prevents FUTURE stomps but does not heal existing corruption nor add this resolution-robustness; recovery of a live stomp today is a manual `api boundary clear <id> --to-session-id <sid> --session-id <current>` re-bind (doyle recovered the doyle/deployah cross-wire this way 2026-07-07).
2026-07-11T01:39:54.1570760Z - Required stages: 
2026-07-11T01:39:54.1570788Z 
2026-07-11T01:39:54.1570897Z ### REQ-SPAWN-COLLISION-GUARD-LIVE-DUP
2026-07-11T01:39:54.1573207Z - Title: W4 (LIFECYCLE-TRUTH): single-flight wake per endpoint — the WAKE/RESUME respawn seam must not launch twice for one wake. ROOT (perri parentage + recovered filing): one wake processed TWICE within 1s — broker (306368) spawned two identical `launch --cli ccs --id flynn --resume <sid>` 1s apart, both survived; check-then-spawn TOCTOU in the spawn-side guard. DAMAGE: duplicate-perch writers STOMP info.json (the duplicate's compact re-stamped an OLD sid over a fresh /clear rotation -> injects routed to the contended record and lost). FIX: single-flight wake per endpoint (claim on the perch record or broker-side in-flight set keyed by id; second wake within the window = no-op ack), and the spawn path re-checks liveness UNDER the claim. Int: two concurrent wake requests -> exactly one launch tree.
2026-07-11T01:39:54.1573327Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1573355Z 
2026-07-11T01:39:54.1573449Z ### REQ-HAZARD-LISTEN-ORPHAN
2026-07-11T01:39:54.1575628Z - Title: W4 (LIFECYCLE-TRUTH, KNOWN-HAZARDS): `api listen --parent-pid N` watches parent liveness and exits loud on parent death. ROOT (mobile-gw RCA): --parent-pid is auth-anchor ONLY — no liveness watch; host death orphans the listener forever -> perch held alive (false ONLINE), EVENTs stream to a dead stdout, dead-owner rebind BLOCKED (recorded pid = the live orphan). FIX: listener watches --parent-pid liveness (Windows: job object or poll; Unix: PDEATHSIG or poll) and exits loud on parent death. flynn's job-object guard (spt-mobile side) stays regardless; filed SPT-CORE-NEEDS §5. Unit: parent-death -> listener exits within one poll window.
2026-07-11T01:39:54.1575794Z - Required stages: impl, unit
2026-07-11T01:39:54.1575823Z 
2026-07-11T01:39:54.1575921Z ### REQ-INJECT-MULTILINE-INTEGRITY
2026-07-11T01:39:54.1578606Z - Title: W5 (LIFECYCLE-TRUTH): the idle-inject TYPED delivery leg delivers multi-line bodies byte-complete. ROOT (4 field instances + spool diff): the typed leg eats HEAD bytes nondeterministically — spool rows complete (1669B) vs ~322B received suffix; mid-turn poll envelopes always intact; a 1854B body later rode the same leg intact => timing race (terminal-readiness / enter-coalescing settle class), NOT a size cap. FIX DIRECTION (todlando proposes on the broker/translate typed-inject seam): settle-before-head, bracketed-paste where the harness supports it, or chunked write with echo-verify. STAKES: live-SENT injects leave NO spool copy — truncation there is unrecoverable. Int: repeated large multi-line injects into a real PTY session arrive byte-complete (loop N times — the race is timing-dependent, single-shot green is not proof).
2026-07-11T01:39:54.1578803Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1578831Z 
2026-07-11T01:39:54.1578931Z ### REQ-HAZARD-INJECT-SETTLE-REARM
2026-07-11T01:39:54.1582945Z - Title: post-0.29.0 (KNOWN-HAZARDS 7.37): the Layer-1 settle-gate must RE-ARM before every delivery on an OBSERVABLE (echoing/interactive) PTY — a mid-session reader reattach re-creates the head-swallow window. ROOT (field-confirmed on 0.29.0, doyle diagnosis + perri screenshot): the shipped W5-A settle-gate (REQ-INJECT-MULTILINE-INTEGRITY) gated Layer 1 behind a worker-local ONE-SHOT (`settled_once`) on the false premise that the head-swallow race is STARTUP-only (reader not attached after spawn). A mid-session `/clear` re-enters the harness's raw-mode input reader, re-creating the pre-settle window — but the one-shot already fired at spawn, so `settle_before_inject` is SKIPPED and the head is eaten again (a checkpoint-wake payload injected right after `/clear` lost its head, mid-path `spt/Cargo.toml)`); echo-verify (Layer 2) is default-OFF for that session, so it is silent + unrecoverable. FIX (doyle ruling): re-settle before EVERY delivery on an observable PTY; latch-skip the steady-state settle ONLY where the probe is UNOBSERVABLE (non-echoing ConPTY — no reader-reattach race to guard, and each settle burns the full deadline). The settle's own bool return (observed vs timed-out) discriminates the class; a re-drive (attempt>1) ALWAYS settles. `settled_once: bool` one-shot → `probe_unobservable: bool` latch driven by the first-attempt settle outcome.
2026-07-11T01:39:54.1583069Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1583098Z 
2026-07-11T01:39:54.1583199Z ### REQ-IDLE-PARKED-DELIVERY
2026-07-11T01:39:54.1585555Z - Title: W5 (LIFECYCLE-TRUTH): a message QUEUED to an ALREADY-idle spt-hosted endpoint is delivered without an operator poke. ROOT (live during the milestone dispatch 2026-07-07): the idle-edge drain (F-023 leg 2) fires only on the ACTIVE->IDLE transition; no new edge ever comes for a parked session, and the send-time inject didn't carry it — both doyle->todlando dispatches sat delivered=0 in the spool while the endpoint showed ONLINE. FIX: send-time inject fires for an already-idle spt-hosted target (activity sense says idle => inject now, not spool), and/or a bounded spool sweep re-offers pending rows to idle endpoints (piggyback the pulse tick, no new loop). Int: send to a session idle for N minutes -> delivered without any operator poke.
2026-07-11T01:39:54.1585703Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1585732Z 
2026-07-11T01:39:54.1585822Z ### REQ-SPOOL-TAKE-AUDIT
2026-07-11T01:39:54.1586691Z - Title: W5 (LIFECYCLE-TRUTH, RCA cost: proving WHO took delivered=1 rows burned an hour): the spool records the taker per row — leg enum (relay-backlog / hook-poll / idle-inject / psyche) + sid/pid + taken_at ms — surfaced by a --json debug read. Additive column, no schema break (delivered rows already retained).
2026-07-11T01:39:54.1586797Z - Required stages: impl, unit
2026-07-11T01:39:54.1586824Z 
2026-07-11T01:39:54.1586924Z ### REQ-DOC-ECHO-COMMUNE-CONTRACT
2026-07-11T01:39:54.1588318Z - Title: W6 (LIFECYCLE-TRUTH, docs — this gap cost a full outage night, priority slot): publish the [session.echo_commune] I/O contract on the docs-site: key catalog core fills; core does NOT stdin-feed [history] (field-proven); self-locate guidance incl. CLAUDE_CONFIG_DIR / read_env; drop-file protocol (single-writer, ingest-deletes, resolver semantics from W1); stdout ingestion expectations. Public docs use VERSION numbers, never wave codes; docs-publish drift gate applies.
2026-07-11T01:39:54.1588633Z - Required stages: doc
2026-07-11T01:39:54.1588661Z 
2026-07-11T01:39:54.1588759Z ### REQ-DOC-DELIVERY-VOCAB
2026-07-11T01:39:54.1589883Z - Title: W6 (LIFECYCLE-TRUTH, docs — remaining flynn/perri gaps folded): publish the full send-outcome vocabulary (SENT / SENT(WAN) / QUEUED window semantics / DEFERRED / NO_PERCH), digest --json row schema, api poll auth + MAC-stamp prefix, remaining --json shapes checklist (seed #3). Public docs use VERSION numbers, never wave codes; docs-publish drift gate applies.
2026-07-11T01:39:54.1589983Z - Required stages: doc
2026-07-11T01:39:54.1590016Z 
2026-07-11T01:39:54.1590111Z ### REQ-PLATFORM-REGISTRY
2026-07-11T01:39:54.1593290Z - Title: MUSL-TIER W1 (target-triple centralization, behaviour-NEUTRAL refactor): ONE authoritative platform registry from which current_platform(), KNOWN_TARGET_TRIPLES, the applyhost cross-platform 'other' logic, and the asset-name<->triple map all derive. ROOT: the target triple x86_64-unknown-linux-gnu + the implicit 'exactly 2 platforms' assumption are hardcoded across ~6 sites (release.rs current_platform cfg + KNOWN_TARGET_TRIPLES, applyhost.rs:740-743 win/linux binary if/else, xtask asset map, release.yml), so adding any platform (musl, future arm64) is a scattered edit. FIX: a data-driven registry (candidate: SUPPORTED_PLATFORMS const table of {triple, asset_name}) + generalize applyhost 'other' to 'every registered platform except current_platform()'. gnu+windows behaviour BYTE-IDENTICAL — the existing release/update/apply/propagate suites stay green (that is the gate). DESIGN FORK (doyle rules pre-dispatch): enum vs const-table; applyhost N-platform generalization; current_platform stays cfg->triple but output must be a registry member, loud 'unknown' fallback kept.
2026-07-11T01:39:54.1593406Z - Required stages: impl, unit
2026-07-11T01:39:54.1593434Z 
2026-07-11T01:39:54.1593529Z ### REQ-PLATFORM-MUSL
2026-07-11T01:39:54.1596067Z - Title: MUSL-TIER W2 (register the musl platform, self-IDENTIFY): add x86_64-unknown-linux-musl to the W1 registry — a current_platform() cfg arm (target_arch=x86_64, target_os=linux, target_env=musl -> the musl triple, NO more 'unknown' fallback), asset name spt-x86_64-linux-musl, triple-map entry. PROVEN (doyle /diagnose 2026-07-08, backlog #14): the current tree builds+runs static musl with ZERO source changes (rustls not openssl; aws-lc-sys+bundled-sqlite clean under musl-gcc; openpty; DNS/HTTPS works statically) — so W2 is registry DATA + cfg + asset map, NO dependency changes. Gate: a musl-built spt self-reports x86_64-unknown-linux-musl (not 'unknown'); registry-membership unit (the cfg arm is cross-target, unit the registry not the arm); build the musl target in-gate (kitsubito toolchain) and assert current_platform.
2026-07-11T01:39:54.1596181Z - Required stages: impl, unit
2026-07-11T01:39:54.1596211Z 
2026-07-11T01:39:54.1596306Z ### REQ-RELEASE-MUSL-ARTIFACT
2026-07-11T01:39:54.1598816Z - Title: MUSL-TIER W3 (CI build + signed release + update-set publish + self-update E2E): release.yml gains a musl matrix entry (build on kitsubito; install musl-tools+cmake+target in-job, CC_x86_64_unknown_linux_musl=musl-gcc); the assemble job includes spt-x86_64-linux-musl in SHA256SUMS + the release upload; release-publish (xtask) signs the musl artifact; the update-set carries its artifact entry. This closes the field gap: a musl binary today fetches fine but ends UPDATE_FETCH_REJECTED:NoArtifactForPlatform('unknown'). Gate (release-pipeline touch -> real E2E): cut a draft/test release with the musl artifact; a static musl binary on a sub-2.39-glibc box runs spt update fetch -> gets the musl artifact (no NoArtifactForPlatform), verifies SHA256+signature over the musl bytes, applies, self-updates. musl is ADDITIVE — gnu stays the default Linux artifact.
2026-07-11T01:39:54.1599179Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1599207Z 
2026-07-11T01:39:54.1599305Z ### REQ-PUMP-DIAL-FASTFAIL
2026-07-11T01:39:54.1606303Z - Title: PUMP-TRUTH W1 (RE-SCOPED post round-2 empirical lock — the DIAL is EXONERATED, healthy ~100ms): a pump worker-leg PEER-REPLY read to a connect-then-silent / half-alive peer must drop THAT peer as an ORDINARY per-peer failure (peer_outcome's non-TimedOut arm -> PUMP_PEER_FAIL -> drop conn + redial, round CONTINUES, heartbeat advances), NEVER burn the brain's 30s PUMP_PEER_IO_TIMEOUT carrier deadline into a whole-round TimedOut POISON -> supervise_pump doubling-backoff restart. ROOT (deployah leg-instrumented capture, enlyzeam, 3 identical rounds): DIAL_EXIT 96ms ok, LEG i=3 update ms=30025 err[TimedOut] = the wedge. request_update (propagate.rs:373-375) opens the update stream + sends UpdRecord::Query (all bounded, all land), then BLOCKS read_event_until(deadline=call_deadline()=30s) on the peer's Offer/UpToDate reply; a peer that accepts the stream but never answers burns the full 30s -> TimedOut -> peer_outcome (pump/mod.rs:601) POISON -> whole-round abort + restart (= the field PEER_PUMP_FAIL: brain IPC read deadline, always-zero PUMP_PEER_FAIL). request_sync (sync.rs:374-376) is the LATENT TWIN (SKIPS the reply-read only when the want-set is empty; bites the moment it is non-empty against a silent peer). FIX (both legs): (a) reclassify the reply-read no-progress timeout OUT of TimedOut to a non-poison kind (Brain::read_peer_reply_until) so peer_outcome drops ONLY that peer -- poison RESERVED strictly for a genuine broker-IPC-CARRIER desync (the carrier ops net_open_stream/subscribe/send keep raw TimedOut); the abandoned peer stream is safe (exactly-once seq cursor stays contiguous, a late reply matches no live stream id). (b) budget-decouple the reply-read below 30s (Brain::reply_read_deadline = now + min(io_timeout, 10s)) so a silent peer drops promptly even in the still-sequential pre-W2 pump and can never race the carrier deadline. Files: propagate.rs (request_update) + sync.rs (request_sync) + brain.rs (reply_read_deadline + read_peer_reply_until) + pump/mod.rs (peer_outcome poison reserved for carrier-desync). Gate: a connect-then-silent peer at fan#0 -> the update leg drops it ordinarily within the reply-read budget, round continues + heartbeat advances, NO PEER_PUMP_RESTART; happy path (live peer) unchanged; + the sync-non-empty-want-set latent case. Kin REQ-PUMP-PEER-ISOLATION (W2 concurrency, VALIDATED by this root) + REQ-HAZARD-PUMP-IPC-DEADLINE (the poison it must stop mis-firing on a peer).
2026-07-11T01:39:54.1606514Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1606542Z 
2026-07-11T01:39:54.1606655Z ### REQ-PUMP-PEER-ISOLATION
2026-07-11T01:39:54.1609999Z - Title: PUMP-TRUTH W2 (architectural, operator ruling 2026-07-08): one peer must NOT block or poison all others -- peer discovery is async / per-peer-independent. Two coupled defects in run_peer_pump: (1) SEQUENTIAL fan-out (for peer in fan_targets dials one-at-a-time, each up to the bound -> peer N+1 waits behind peer N); (2) WHOLE-ROUND POISON (peer_outcome(...)? -- one TimedOut aborts the ENTIRE round via ? -> supervise_pump doubling-backoff restart, resetting ALL conns). FIX: per-peer concurrency + fault isolation -- the pump issues non-blocking dial requests; the broker (already async tokio+iroh) returns connection/presence results as async events (the D4c presence seam), no serial per-peer block; a peer TimedOut drops + reschedules ONLY that peer, NEVER aborts the round or restarts the pump. Supervised-restart is RESERVED for a dead BROKER conn, not a dead peer (the single-thread+bounded-read A-half REQ-HAZARD-PUMP-IPC-DEADLINE was defensive -- it stopped the infinite wedge but coupled every peer's fate; this decouples). Gate: a mixed roster (1 live + N offline peers) -- the live peer connects AND this node advertises presence in the SAME round the offline peers fail; heartbeat advances every round; no PEER_PUMP_RESTART from a dead peer. Depends on W1 (a fast-failing dial is the precondition for clean per-peer scheduling).
2026-07-11T01:39:54.1610306Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1610335Z 
2026-07-11T01:39:54.1610446Z ### REQ-HAZARD-COMMUNE-INGEST-BLACKHOLE
2026-07-11T01:39:54.1616411Z - Title: F-032 (perri field finding 2026-07-08, LEGACY-SPT-PARITY-GAP, data-loss): commune/signoff ingest MUST NOT delete a drop until its content is DURABLY COMMITTED to every APPLICABLE tier — a slice that cannot be committed this ingest must leave the drop in place for a later ingest (retry when the precondition resolves) OR durably preserve the un-committed slice, NEVER delete-then-lose. ROOT (doyle triage, code-grounded): ingest_drops (spt-live/src/ingest.rs:200) unconditionally `remove_file(&drop_path)?` AFTER route_slices (ingest.rs:121), but route_slices GATES the project tier on `!project_id.is_empty()` (ingest.rs:156) — when the endpoint's cwd is unresolved/owlery-internal at ingest time the project_id is empty, so the `<project-context>` slice is PARSED but never write_context'd/commit_project'd, yet the source drop is still deleted → the project-context content is permanently lost (black-hole). perri's repro: a two-sliced echo-commune (<live-context> role+release recipe + <project-context> v0.17.4 status + Items 3-5 map) INGESTED (file deleted) yet never surfaced at her next SessionStart resume-pull; adapter exonerated (file-write + slicing tags correct); fixture at (system temp)/F-032-commune-2026-07-08T222721Z.md (5595B, sha256 9bc27e18cf385958; perri wrote it verbatim from session log 0841835d.jsonl). Legacy spt held commit-first-then-delete parity; the modern two-slice ingest broke it. FIX distinguishes: a write SUPPRESSED-by-precedence (incoming older than durable → already-superseded → safe to delete) from a slice NOT-committed-because-un-committable-now (empty project_id / write error → must NOT delete; retry or preserve). Gate: an ingest with a non-empty <project-context> slice but an EMPTY project_id must NOT delete the drop (or must durably preserve the project slice) — the content survives to the next resolvable ingest / SessionStart; the live-tier commit path stays unchanged; a genuinely superseded (precedence-suppressed) drop still deletes. KNOWN-HAZARDS entry on landing (REQ-HAZARD-* = conformance-checklist, needs a test).
2026-07-11T01:39:54.1616544Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1616572Z 
2026-07-11T01:39:54.1616677Z ### REQ-LIVE-AGENT-NO-INJECT-DELIVERY
2026-07-11T01:39:54.1622968Z - Title: F-033 RE-SCOPED (doyle re-ruling 2026-07-10 after the #82 gate falsified the original premise — the hosting-mode class split is BINDING context): 'state:live_agent has a self-delivery reader' CONFLATED two hosting modes. (A) HARNESS-hosted live agents (api listen path) DO deliver via adapter channels only — and are ALREADY structurally excluded from inject: bind_from_seed stamps controllable=Some(false), no broker PTY exists. (B) SPT-HOSTED/CONTROLLED live agents' inject leg IS their delivery reader (broker PTY + translation binary — doyle's own endpoint is field proof: ENDPOINT_INJECT + IDLE_PARKED_DRAIN alongside hook-poll); the original blanket state:live_agent exclusion broke REQ-MSG-IDLE-EDGE-DRAIN + the v0.14.3 LAW on both CI platforms and was REVERTED (predicate stays controllable-gated). perri's adapter-channels-only model (F-dupmsg-adapter-confirm.md) holds for class (A) only — do not re-seed the conflation. The F-033 DUPLICATE mechanism (hook-poll + idle-inject both delivering one row, operator spool row 156) is closed structurally by REQ-CARRIER-CLAIM-EXCLUSIVE's atomic cross-carrier take. REMAINING LEGS OF THIS REQ: (a) unit — a harness-hosted live agent (controllable Some(false)/None, no broker PTY) can never route through try_spt_hosted_inject (evidence may TAG the existing is_spt_hosted_no_relay non-controllable case rather than duplicate it); (b) VERIFICATION (report-before-fix, DELIVERED to doyle 2026-07-10): the no-translation-binary raw payload+CR path is PROVABLY DEAD (broker dispatch_endpoint_input: no-binary -> loud spool, never a PTY write — v0.14.3 holds); the operator's typed-unsubmitted garbage is PINNED to the Layer-2 echo-verify RE-DRIVE (broker.rs inject worker) force-enabled host-wide by ambient SPT_INJECT_VERIFY_ECHO in the daemon's inherited dev-shell env (default-OFF declared capability turned on globally — the F-036 env-inheritance class): a false verify-miss RETYPES the whole sequence into the input field. Proposed fix shape (awaiting doyle stage ruling): fold SPT_INJECT_VERIFY_ECHO/SPT_INJECT_FORCE_ECHO_MISS into the W1 daemon-startup env scrub; adapter-declared capability becomes the only production on-switch.
2026-07-11T01:39:54.1623283Z - Required stages: 
2026-07-11T01:39:54.1623359Z 
2026-07-11T01:39:54.1623464Z ### REQ-ADAPTER-UNRESOLVED-HINT-FORM
2026-07-11T01:39:54.1625694Z - Title: F-034 leg a (perri/hertz field finding 2026-07-09): the ADAPTER_UNRESOLVED refusal hint must print a WORKING command form. It currently says 'pass --adapter <name[:profile]>', but --adapter is a `spt api` GROUP flag, NOT a `listen` flag — following the hint literally (`spt api listen <id> --adapter <name>`) produces clap `error: unexpected argument '--adapter'` (exit 2). Fix: the hint prints the group-level form, e.g. `spt api --adapter <name> <cmd> …` (a hint the operator can copy-paste and have work). Gate: the ADAPTER_UNRESOLVED message text carries a clap-VALID invocation (group-level --adapter placement) — a unit asserting the hint string parses under the api clap grammar, or at minimum places --adapter before the subcommand. Pure UX/hint-correctness fix, no behavior change.
2026-07-11T01:39:54.1625808Z - Required stages: impl, unit
2026-07-11T01:39:54.1625836Z 
2026-07-11T01:39:54.1625944Z ### REQ-LISTEN-SEED-CONSUME-AFTER-BIND
2026-07-11T01:39:54.1629342Z - Title: F-034 leg b (perri/hertz field finding 2026-07-09, hertz's HEADLINE): `api listen` must NOT consume the consume-once ephemeral seed on a PRE-BIND refusal — validate (adapter resolvable, home/subnet) and BIND first, THEN consume the seed. ROOT: today `api listen` burns the consume-once seed BEFORE it validates home/subnet, so on a multi-subnet node HOME_REFUSED (needs --subnet) fires AFTER the seed is already gone → the corrected retry (adding --subnet) on the SAME pid hits NO_SEED, a dead end (plausibly ADAPTER_UNRESOLVED burns it the same way). A refusal that never bound must leave the seed intact for the corrected retry. Same EFFECT-BEFORE-IRREVERSIBLE-CONSUME ordering class as F-032 (commune commit-before-delete) — the irreversible consume must follow the successful effect, never precede a refusal. Gate: a pre-bind refusal (HOME_REFUSED on a multi-subnet node without --subnet; ADAPTER_UNRESOLVED) leaves the seed CONSUMABLE — the corrected retry on the same pid binds (no NO_SEED); a SUCCESSFUL bind still consumes the seed exactly once (no double-bind). Files: the api-listen bind path (seed consume ordering). Kin F-032 [[spt-core-findings-backlog]].
2026-07-11T01:39:54.1629580Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1629604Z 
2026-07-11T01:39:54.1629713Z ### REQ-LISTEN-SESSION-ID-FALLBACK
2026-07-11T01:39:54.1633286Z - Title: F-034 leg c (perri/hertz field finding 2026-07-09): a session that goes live LATE (hours after SessionStart, or after a daemon restart) must still be able to bind — the ephemeral SessionStart seed ('consumed within seconds') is GONE by then and nothing re-fires it until the NEXT SessionStart, so even `api listen --parent-pid <correct claude pid>` hits NO_SEED. Design assumption 're-fired on the next SessionStart if needed' does not hold for long-lived sessions. FIX (perri-recommended, cleanest): `api listen --session-id <sid>` fallback that binds from the session-id when the pid has no live seed — removes the ephemeral-seed dependency entirely (the adapter already knows the sid; the skill passes it, and can then DROP its manual re-seed step). Alternative (option 1, less clean): re-fire the seed on daemon restart. Gate: a session with NO live seed (expired / post-daemon-restart) binds via `listen --session-id <sid>` (no NO_SEED); the sid-bind carries the same identity/auth the seed-bind would (session_id custody — kin REQ-PSYCHE-SID-CUSTODY / the sid-symmetric-auth pattern). Files: api-listen bind path (sid-fallback seam), clap --session-id flag (plain doc-comment). hertz/perri live-verify; if it lands the adapter skill drops the re-seed step.
2026-07-11T01:39:54.1633524Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1633553Z 
2026-07-11T01:39:54.1633659Z ### REQ-LIST-JSON-LIVENESS-PARITY
2026-07-11T01:39:54.1639763Z - Title: GATEWAY-LIVENESS (flynn field bug 2026-07-09, RCA reader-divergence root): `spt endpoint list` (human) and `endpoint list --json` MUST report an IDENTICAL status for a locally-hosted endpoint — especially a pid-alive, status-ABSENT gateway (no psyche_init). ROOT (todlando RCA STEP-1, doyle-verified): the --json builder (crates/spt/src/cli.rs cmd_endpoint_list) emits each subnet row's status straight from resource_projection (spt-net registry.rs:566, passes instance.status through verbatim :592 — the persisted WAN snapshot, a lagged gossip that can carry a stale/crash-time Suspended) and NEVER applies the self-owned reconcile the human/picker path applies (reconcile_self_owned, crates/spt/src/picker/data.rs:160 via gather_endpoints :112). So a pid-alive self-owned gateway reads Suspended on --json but ONLINE on human (roster::enumerate spt/src/roster.rs:38 -> is_perch_alive pid-fallback spt-store/liveness.rs:136); the adapter suspend-poll (parse_endpoint_status over endpoint list --json --show-all) reads the divergent --json status -> self-suspends a pid-alive gateway. Candidates REFUTED: resource_projection does NOT re-derive liveness (copies instance.status, only skips !routable :582); render is a faithful {:?}. advertised_status (registryhost.rs:822) DOES compute Active via pid-fallback (live advertise fine) — the bug is the READER showing the un-reconciled snapshot. FIX (doyle-ruled): apply the self-owned reconcile in the cli --json builder (SAME spt/picker consumer layer as gather_endpoints, NOT lifted into resource_projection which inverts the dep spt-net->perch), reading LOCAL perch truth (is_perch_alive/unbound -> Active/Offline, mirroring the picker's local_rows). Do NOT force status=online (DEFECT B latent — seed-#5 orphan-listener false-ONLINE risk). Gate: a pid-alive locally-hosted gateway (status-absent, no psyche_init) reads the SAME non-Suspended status on human AND --json. Field-verify flynn (mobile-gw). Kin REQ-PICKER-3 + REQ-PRESENCE-LIVENESS-TRUTH + seed-#5 orphan-listener false-ONLINE.
2026-07-11T01:39:54.1639897Z - Required stages: impl, int
2026-07-11T01:39:54.1639926Z 
2026-07-11T01:39:54.1640034Z ### REQ-HAZARD-BIND-REST-STATE-CARRY
2026-07-11T01:39:54.1642883Z - Title: GATEWAY-LIVENESS DEFECT A (flynn field bug 2026-07-09, confirmed independent): a re-bind MUST preserve the daemon-owned resting intent (rest_state, D9-2/REQ-INST-3) — the same carry-forward discipline establish_perch already applies to cwd/controllable/adapter/read_env. ROOT: establish_perch's record build (crates/spt/src/api/startup.rs, the build closure) constructs a fresh InfoJson via InfoJson::new (defaults rest_state None) and carries cwd/controllable/read_env forward from prior but NOT rest_state -> a re-bind WIPES the wake intent (flynn tick11 rest_state:active vanish). FIX: carry prior.rest_state (and its paired dormant_since_ms anchor, present iff dormant) forward on re-bind, like the sibling fields. Gate: a re-bind over a prior record with rest_state set preserves it (unit — the build closure carries rest_state + dormant_since_ms). KNOWN-HAZARDS entry on landing. Kin REQ-HAZARD-BIND-CWD-UNSET / REQ-PICKER-1 + REQ-INST-3.
2026-07-11T01:39:54.1643093Z - Required stages: impl, unit
2026-07-11T01:39:54.1643121Z 
2026-07-11T01:39:54.1643221Z ### REQ-SEND-WINDOW-DRAIN-HONOR
2026-07-11T01:39:54.1648149Z - Title: F-035 (field finding 2026-07-09): active_only = POLL-ONLY for a relay-bearing live agent -- it must NEVER be RELAY-delivered (its contract is 'active hook window only, never wakes' per spool.rs WINDOW_ACTIVE_ONLY doc + cli.rs:85; `spt send --active-only` / the hidden `--deferred` alias and `send_deferred` shell-context mint it). FIELD SYMPTOM: lia (a full live agent -- relay-for-idle, poll-for-busy) surfaced an --active-only msg on her IDLE RELAY. RCA JOURNEY: v1 RCA (docs/F-035-RCA.md) analyzed the WRONG class (spt-hosted-relay-LESS, the idle-edge inject leg) and proposed a COLLAPSE that would have broken the shipped F-023 anti-starvation gate (docs/F-035-CONFLICT.md); operator reclassified to a relay-bearing live agent; the relay-class re-RCA (docs/F-035-RELAY-RCA.md) traced EVERY active_only->relay carrier and found them ALL ALREADY GUARDED on main@2c05dc9 -- so spt-core has NO code bug. doyle FINAL RULING: the real leak is the ADAPTER's busy->idle poll->idle-representation handoff (spt-claude-code -- a legitimate `api poll` on going idle drains active_only, then the adapter renders it into the idle/relay surface), OUTSIDE spt-core; perri's lane. spt-core DELIVERABLE = a REGRESSION GUARD (tests only, NO behavior change) locking the 3 load-bearing guards that keep active_only off a relay: (1) send_windowed:217 -- an active_only send SKIPS deliver_tcp (never rides a live relay's TCP channel), spools poll-only; (2) cli.rs:5762 -- a cross-node active_only send stays LOCAL-ONLY (the WanMessage wire record has no window field, so shipping it would strip the class and relay-deliver at the far node); (3) relay.rs drain_backlog -> drain_non_deferred (deferred=0) -- the relay backlog NEVER forwards an active_only (deferred=1) row. Guard suite: unit (send_windowed active_only-skips-tcp-to-live-relay + relay_backlog-never-drains-active_only) + int (cross-node active_only stays local-only, never WAN, while a default send to the same remote target DOES take the WAN leg). Kin REQ-MSG-DELIVERY-AXES + REQ-MSG-IDLE-EDGE-DRAIN + REQ-INST-6.
2026-07-11T01:39:54.1648487Z - Required stages: unit, int
2026-07-11T01:39:54.1648515Z 
2026-07-11T01:39:54.1648696Z ### REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK
2026-07-11T01:39:54.1658874Z - Title: UPDATE-WEDGE round-4 (hertz RCA, root reproduced + source-pinned on Windows 2026-07-09): EVERY write on a physical broker connection rides ONE bounded + cancelable + poison-on-failure framed-write primitive — no writer may hold the connection's serialized send gate across an UNBOUNDED OS write. ROOT: controller_writer held the SharedSend = Arc<Mutex<SendHalf>> guard ACROSS a blocking write_frame; on Windows interprocess 2.4.2 routes the send to WriteFileEx + SleepEx(INFINITE, alertable) with NO supported write timeout (set_timeout → Unsupported), so an `rc --take` controller consumer that stops reading blocks the write INDEFINITELY (~127.95 s in the field capture, released only when a brain restart tore the conns down). Logical stall_evict_controller (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE) removes the controller ROLE but neither cancels the in-flight pipe write, closes the physical connection, nor invokes CancelIoEx — the detached writer keeps its SharedSend clone + live stack-owned mutex guard. Load-gated: needs a real seq>0 frame + a non-draining consumer (seq-0 boot conns + a quiescent update are clean — why v0.30.5's controlled apply passed); CTRL_WRITE_LOCKED wait_us=0 on all four capture writers exonerates the mutex convoy — the block is INSIDE the OS write, after lock acquisition. Existing deadlines can't bound it: CONTROLLER_WRITE_DEADLINE is output-driven channel-full handling (a writer blocked on its first owned frame never fills the channel); BRAIN_WRITE_DEADLINE is an age PREDICATE sampled opportunistically, not an I/O timer. FIX (accepted shape, doyle GO + 3 confirms): broker-owned Arc conn object (conn.rs BrokerConn) replacing raw Arc<Mutex<SendHalf>> — serialized write gate (bounded gate-wait) + send half (never leaves the object, so a bypass cannot compile) + idempotent poisoned state + per-in-flight op identity + platform abort seam, with an INDEPENDENT per-conn watchdog firing OUT OF BAND at an ABSOLUTE deadline stamped at write entry covering BOTH gate-wait and OS write completion (brain_write_deadline() — the existing SPT_BRAIN_WRITE_DEADLINE_MS knob; the abort NEVER relies on the write returning or on opportunistic stall-evict sampling). On deadline/partial/cancel/unknown completion: (1) poison the whole physical conn, (2) abort read+write (cfg(windows) CancelIoEx then DisconnectNamedPipe; cfg(unix) UnixStream::shutdown(Both)) so handle_conn reaches existing EOF cleanup, (3) wait for the canceled op to report completion before releasing its buffer (interprocess write_exsync returns only after the completion APC — release = write return), (4) NEVER reuse the conn (a timed-out length-prefixed frame may be partially written), (5) join/finish the retired writer before reporting physical cleanup. Controller (replay + live), viewer, dispatch-reply (send_frame/send_error + inline dispatch_* replies), and nethost stream-log/presence writes ALL route through the primitive — leaving ANY raw unbounded write behind the gate preserves the failure class (grep-proven: no surviving raw send.lock()+write_frame on a physical conn path). NO new output queue (the bounded queue + isolated writer exist; the block is BELOW them); NO PIPE_NOWAIT (recorded mid-frame corruption risk). Broker-side only, no wire change, mixed-version peers wire-compatible; Unix keeps existing semantics under the same poison/retire invariant.
2026-07-11T01:39:54.1659324Z - Required stages: doc, impl, int
2026-07-11T01:39:54.1659353Z 
2026-07-11T01:39:54.1659471Z ### REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE
2026-07-11T01:39:54.1665167Z - Title: MSG-IDENTITY W1 / F-036 leg a (perri field RCA 2026-07-09/10, psyche seat-theft — doyle ACCEPTED primary fix): the daemon MUST sanitize inherited per-session identity env (SPT_ENDPOINT_ID / OWL_SESSION_ID / SPT_AGENT_ID) at startup AND before EVERY role spawn — these are per-session identity and are NEVER correct inherited state for a daemon or its role children. ROOT: a daemon restarted from inside an agent session (routine during core dev / `spt update apply`) carries the session's SPT_ENDPOINT_ID and passes it verbatim to every [session.psyche_resume] spawn; core only strips each role's DECLARED env_remove list (runtime.rs:728), so ONE adapter env_remove miss infects the whole node — every psyche claude turn fires SessionStart, the adapter hook sees the endpoint id, takes the bind path, and ROTATES the victim's perch to the psyche's own sid with a valid prior-sid proof, every pulse (field: lia/deployah/doyle psyches ALL briefed as <sptc-active-perch id=doyle>; 37 peer msgs drained into lia's psyche transcript; victim deliveries eaten, communes dark, sends downgraded from:cli@node). Adapter half FIXED v0.18.8 (env_remove += SPT_ENDPOINT_ID + shim scrub + SPT_PSYCHE_TURN hook-bail) — this REQ is the CORE-LAYER defense so no adapter miss can ever leak identity again. FOLD (F-036 leg b docs-fix, doyle-owned): broaden the recursion_guard_env schema description (manifest.rs:314 + crates/spt-runtime/manifest.schema.json:306) — core honors it on ANY role declaring the field (runtime.rs:740, keyed on the FIELD not the role name); drop the 'summarizer children' wording (perri adopted on both psyche roles v0.18.8, proven live). Gate: a daemon started with SPT_ENDPOINT_ID/OWL_SESSION_ID/SPT_AGENT_ID in its env spawns role children WITHOUT those vars (unit: role-spawn env assembly scrubs the identity set regardless of the role's declared env_remove); KNOWN-HAZARDS entry on landing. Kin psyche-custody/session-pin cluster, [[spt-core-findings-backlog]] F-036.
2026-07-11T01:39:54.1665412Z - Required stages: doc, impl, unit
2026-07-11T01:39:54.1665435Z 
2026-07-11T01:39:54.1665548Z ### REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD
2026-07-11T01:39:54.1668091Z - Title: MSG-IDENTITY W1 / F-036 leg c (perri field RCA, doyle ACCEPTED defense-in-depth): a bind whose --set-session-id equals a NESTED psyche perch's own custody sid is definitionally wrong and MUST be refused — core owns psyche-custody.json and can see the collision at bind time. ROOT CONTEXT: with the F-036 env leak, each stolen bind carried a psyche sid as the new pin; the identity-env sanitize (leg a) removes the known vector, this guard makes the CLASS unreachable (any future vector that tries to rotate a real endpoint's perch onto a psyche's custody sid is refused loud). Gate: a bind attempt whose target sid appears in psyche-custody.json as a psyche's OWN sid is REFUSED with a distinct loud token (unit: custody-sid collision refuses; a normal non-custody sid bind is unaffected). Kin REQ-PSYCHE-SID-CUSTODY, session-pin cluster, [[spt-core-findings-backlog]] F-036.
2026-07-11T01:39:54.1668272Z - Required stages: impl, unit
2026-07-11T01:39:54.1668300Z 
2026-07-11T01:39:54.1668396Z ### REQ-CARRIER-CLAIM-EXCLUSIVE
2026-07-11T01:39:54.1672979Z - Title: MSG-IDENTITY W4 / F-033 + operator self-send probe 2026-07-09 (dup-delivery cluster, RCA-FIRST): a spooled message row is delivered by EXACTLY ONE carrier — the first carrier to take a row (hook-poll drain, relay idle-inject, relay-backlog, psyche) atomically CLAIMS it so no other carrier can re-deliver the same row. FIELD EVIDENCE (authoritative, operator-observed): a default-window doyle-to-doyle send while doyle was BUSY delivered on BOTH the busy POLL path AND the idle RELAY path; spool row 156: window='default', delivered=1, taken_leg='idle-inject' — the relay claimed a row a poll also surfaced (REQ-SPOOL-TAKE-AUDIT instrument, already shipped, is the RCA tool: taken_leg/taken_sid/taken_at per row). PRIOR: F-033 (perri 2026-07-08) — the psyche-download filing arrived as TWO copies, dup-delivery live-confirmed. RCA-FIRST (report-before-fix): pin whether the poll drains before/after the relay's delivered=1 mark; whether the busy-to-idle edge re-offers a row a poll already took; whether take-marking is atomic per carrier or check-then-mark racy. DISTINCT from F-035 (that = active_only window honor, spt-core exonerated; THIS = a default msg on both carriers — F-035's lock never asserted a default msg can't ride both). Gate: int — a default send to a BUSY live agent that polls mid-turn AND transitions idle delivers EXACTLY ONCE (spool-audit shows one taken_leg, recipient sees one copy); unit — concurrent take attempts on one row yield one winner. Kin REQ-SPOOL-TAKE-AUDIT, REQ-RELAY-NO-BUSY-DELIVER, REQ-IDLE-PARKED-DELIVERY, [[spt-core-findings-backlog]].
2026-07-11T01:39:54.1673114Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1673142Z 
2026-07-11T01:39:54.1673245Z ### REQ-RELAY-NO-BUSY-DELIVER
2026-07-11T01:39:54.1676493Z - Title: MSG-IDENTITY W4 (operator self-send probe 2026-07-09, companion leg): the relay/idle-inject carrier MUST NOT fire for an ACTIVE endpoint — the daemon already guards send-time (daemon.stderr.log: 'ENDPOINT_INJECT: endpoint ACTIVE -> spool (deferred hint), not injected') yet the field row ended taken_leg='idle-inject' for a message sent while the endpoint was ACTIVE, so the guard is bypassed somewhere on the busy-to-idle EDGE (the parked-drain idle-injects rows that arrived during busy without re-checking whether a poll is concurrently draining them — the edge itself is when BOTH carriers are plausibly live). RCA-FIRST with REQ-CARRIER-CLAIM-EXCLUSIVE (same rig, same instrument); if the exclusive claim alone closes the double-delivery this leg may reduce to an ordering assertion — rule at RCA lock, don't build blind. Gate: unit — the idle-edge drain re-verifies activity (or defers to the claim) before idle-injecting; a row taken by a poll is never idle-injected. Kin REQ-IDLE-PARKED-DELIVERY (the drain this guards), REQ-MSG-IDLE-EDGE-DRAIN, F-023 anti-starvation gate (do NOT break the already-idle delivery class).
2026-07-11T01:39:54.1676732Z - Required stages: unit
2026-07-11T01:39:54.1676765Z 
2026-07-11T01:39:54.1676861Z ### REQ-SEND-STAMP-AGENT-ID
2026-07-11T01:39:54.1680562Z - Title: MSG-IDENTITY W4 / endpoint-identity (operator-flagged 2026-07-09 + live-confirmed on flynn's F-038 ask arriving 'cli@HFENDULEAM'): a live agent's own CLI `spt send <target>` MUST stamp from_id with the AGENT id (e.g. 'doyle'), not the node fallback 'cli@<node>' — today the agent-id stamp rides ONLY the adapter/perch shortform path, so any agent shelling out `spt send` (the DOCUMENTED reach-another-agent form) presents to recipients as an anonymous node CLI: replies mis-route (recipients answer cli@node — no perch — instead of the sender), and the F-036 victim-effect ('sends downgraded to from:cli@node') is indistinguishable from normal CLI traffic. FIX: send-time self-resolve — when the calling process/session maps to a bound live perch on this node (the session-pin/seed machinery already resolves this for bind), stamp that endpoint id as from_id; a genuinely perchless CLI keeps 'cli@<node>'. Gate: unit — a send from a session bound to a live perch stamps the endpoint id; a perchless shell keeps the node stamp; int — recipient's EVENT from= carries the agent id for a shelled-out send from a live session. Kin F-036 victim effects, EVENT envelope (ADR-0020), [[owl-send-not-legacy-spt-send]] (adapter-path stamp works today — this closes the CLI-path gap).
2026-07-11T01:39:54.1680792Z - Required stages: impl, unit, int
2026-07-11T01:39:54.1680821Z 
2026-07-11T01:39:54.1680920Z ### REQ-ENDPOINT-AUTOSTART
2026-07-11T01:39:54.1685991Z - Title: MSG-IDENTITY W5 / F-038 (flynn operator-directed ask 2026-07-10, SPT-CORE-NEEDS #7 + deployah field-confirm same day: mobile-gw alive=false after the v0.30.6 full daemon restart = this feature's absence, live): an endpoint can be marked a STARTUP DEFAULT so the daemon brings it back up at daemon start — Gateway-class endpoints are infra (the phone treats mobile-gw as always-there; box reboot / daemon cold start currently leaves it down until hands-on). SHAPE RULED (doyle, dispatch): (a) `spt endpoint run --save` persists the run (id + adapter/profile + args) as a startup default REPLAYED at daemon start, symmetric with the shipped `subnet attach/detach --save` precedent — smallest orthogonal cut, explicit operator intent, no interaction with effective_rest_state/F-035 reader-parity semantics (shape (c) restore-what-was-up REJECTED for now: principled but couples to the rest_state neighborhood that just churned; revisit if --save proves insufficient in the field). A saved endpoint that fails to come up logs loud + does not block daemon start or other replays. flynn docs sweep confirmed missing-feature not docs-gap (rest/wake manual-only; no endpoint analog of subnet --save; no manifest field; no api surface). Gate: int — daemon restart brings a --save'd endpoint back up (fresh daemon, saved default, endpoint reaches its steady state without hands-on); doc — public docs page for the verb (VERSION-scoped); unit — persistence round-trip + replay skip-on-missing-adapter loud. Kin subnet --save (the symmetry precedent), REQ-LIST-JSON-LIVENESS-PARITY + REQ-HAZARD-BIND-REST-STATE-CARRY (the F-035 neighborhood shape (c) would have coupled to), [[spt-core-findings-backlog]] F-038. Interim on flynn's box (logon scheduled task) dissolves when this lands.
2026-07-11T01:39:54.1686231Z - Required stages: doc, impl, unit, int
2026-07-11T01:39:54.1686259Z 
2026-07-11T01:39:54.1686354Z ### REQ-DAEMON-SERVICE-INSTALL
2026-07-11T01:39:54.1688424Z - Title: F-038 RIDER (flynn nice-to-have, QUEUED not activated): a documented OS-service registration recipe or `spt daemon install-service` verb so the daemon itself survives box reboot (flynn's box runs managed_by:null = daemon-at-boot unprovisioned; kitsubito's hand-rolled systemd --user unit = prior art). NOT in MSG-IDENTITY scope — REQ-ENDPOINT-AUTOSTART covers the daemon-start-to-endpoint leg; the boot-to-daemon leg stays interim (logon scheduled task / systemd unit). Activate at an infra-provisioning milestone; shape (recipe doc vs verb) ruled then. Kin [[daemon-service-detection-gotcha]] (global-OS-state detection blind on dev box — a verb must not regress that), [[kitsubito-linux-rig]].
2026-07-11T01:39:54.1688541Z - Required stages: 
2026-07-11T01:39:54.1688570Z 
2026-07-11T01:39:54.1688670Z ### REQ-CONN-POISON-DIAL-SCOPE
2026-07-11T01:39:54.1694191Z - Title: MSG-IDENTITY W6 / F-039 (deployah field-acceptance follow-up 2026-07-10, RCA-FIRST — mint per the v0.30.6 PASS handoff): ambient CONN_WRITE_POISONED log-churn correlates 1:1 with PUMP_PEER_FAIL submit-dials to OFFLINE peers (enlyzeam/kitsubito/gravity) with NO wedge and NO freeze — pre-existed the blackhole rig = log-noise/mislabel, not a defect in the r4 fix. CODE CONTEXT: conn.rs poison_and_cancel emits the loud CONN_WRITE_POISONED line for a write that 'exceeded its bound (OR FAILED)' (conn.rs:181) — the fast-FAIL branch (broken pipe / conn refused on an already-dead counterpart) shares the log tag with the TIMEOUT branch that is the field-acceptance wedge observable, so routine conn teardown under offline-peer dial churn reads like poison events. RCA-FIRST: pin the exact write site that fails per PUMP_PEER_FAIL cycle (BrokerConn is broker-side — which broker conn write rides each pump dial failure? status/event fan-out to a departed subscriber? brain-side notification?) BEFORE changing anything — the correlation mechanism is unpinned. FIX SHAPE (post-RCA, doyle rules at lock): reserve the loud CONN_WRITE_POISONED token for the DEADLINE-EXCEEDED class (the wedge observable blackhole-controller.ps1 watches); a plain write-FAIL on an already-dead conn retires quietly (debug-level or a distinct low-noise token). MUST NOT weaken the r4 invariant: every failure path still poisons + retires the conn (REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK behavior unchanged — only the log LOUDNESS is scoped). Gate: unit — deadline-exceeded emits the loud token, fast-fail does not (both still poison); field — offline-peer churn no longer floods daemon.stderr.log with CONN_WRITE_POISONED. Kin REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK (the invariant this must preserve), REQ-PUMP-PEER-ISOLATION (the offline-peer dial neighborhood), [[v0306-published]].
2026-07-11T01:39:54.1694460Z - Required stages: 
2026-07-11T01:39:54.1694499Z 
2026-07-11T01:39:54.1694603Z ## How to report back
2026-07-11T01:39:54.1694631Z 
2026-07-11T01:39:54.1694782Z For every (requirement, failing criterion) pair, emit one finding:
2026-07-11T01:39:54.1694812Z 
2026-07-11T01:39:54.1694888Z     {
2026-07-11T01:39:54.1694978Z       "code": "requirement_quality",
2026-07-11T01:39:54.1695064Z       "requirementId": "REQ-...",
2026-07-11T01:39:54.1695240Z       "criterion": "singular" | "verifiable" | "atomic" | "active-voice",
2026-07-11T01:39:54.1695335Z       "message": "<short reason>",
2026-07-11T01:39:54.1695456Z       "suggestedRevision": "<optional rewrite>"
2026-07-11T01:39:54.1695532Z     }
2026-07-11T01:39:54.1695565Z 
2026-07-11T01:39:54.1695731Z Wrap your response as { "findings": [ ... ] } listing only your concerns; the
2026-07-11T01:39:54.1695875Z deterministic findings above don't need to be repeated.
