﻿2026-07-17T03:24:37.9223703Z ##[group]Run ./traceable-reqs lint || true
2026-07-17T03:24:37.9224032Z [36;1m./traceable-reqs lint || true[0m
2026-07-17T03:24:37.9237535Z shell: /usr/bin/bash -e {0}
2026-07-17T03:24:37.9237803Z ##[endgroup]
2026-07-17T03:24:37.9643428Z Requirement quality findings (641); 510 requirements queued for agent review:
2026-07-17T03:24:37.9644719Z   [must] requirement_quality REQ-ADAPTER-ADD-SURFACE-ERRORS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9645539Z   [must] requirement_quality REQ-ADAPTER-ADD-SURFACE-ERRORS criterion=length — title is 77 words; want 3..=25
2026-07-17T03:24:37.9646462Z   [must] requirement_quality REQ-ADAPTER-FLOOR-ENFORCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9647221Z   [must] requirement_quality REQ-ADAPTER-FLOOR-ENFORCE criterion=length — title is 368 words; want 3..=25
2026-07-17T03:24:37.9648209Z   [must] requirement_quality REQ-ADAPTER-GH-TRANSPORT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9649163Z   [must] requirement_quality REQ-ADAPTER-GH-TRANSPORT criterion=length — title is 62 words; want 3..=25
2026-07-17T03:24:37.9650108Z   [must] requirement_quality REQ-ADAPTER-LIVE-UPDATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9650850Z   [must] requirement_quality REQ-ADAPTER-LIVE-UPDATE criterion=length — title is 168 words; want 3..=25
2026-07-17T03:24:37.9651653Z   [must] requirement_quality REQ-ADAPTER-MULTIPLATFORM-SPT criterion=length — title is 123 words; want 3..=25
2026-07-17T03:24:37.9652473Z   [must] requirement_quality REQ-ADAPTER-PROOF-DIR-OVERRIDE criterion=length — title is 76 words; want 3..=25
2026-07-17T03:24:37.9653494Z   [must] requirement_quality REQ-ADAPTER-TEMPLATE-KEY-VALIDATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9654359Z   [must] requirement_quality REQ-ADAPTER-TEMPLATE-KEY-VALIDATION criterion=length — title is 110 words; want 3..=25
2026-07-17T03:24:37.9655579Z   [must] requirement_quality REQ-ADAPTER-TRANSLATE-PROOF criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9656477Z   [must] requirement_quality REQ-ADAPTER-TRANSLATE-PROOF criterion=length — title is 182 words; want 3..=25
2026-07-17T03:24:37.9657537Z   [must] requirement_quality REQ-ADAPTER-UNRESOLVED-HINT-FORM criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9658253Z   [must] requirement_quality REQ-ADAPTER-UNRESOLVED-HINT-FORM criterion=length — title is 116 words; want 3..=25
2026-07-17T03:24:37.9658919Z   [must] requirement_quality REQ-ADAPTER-UPDATE-INPLACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9659603Z   [must] requirement_quality REQ-ADAPTER-UPDATE-INPLACE criterion=length — title is 82 words; want 3..=25
2026-07-17T03:24:37.9660189Z   [must] requirement_quality REQ-ADAPTER-UPDATE-MESSAGE criterion=length — title is 64 words; want 3..=25
2026-07-17T03:24:37.9660729Z   [must] requirement_quality REQ-ADAPTER-UPDATE-POST criterion=length — title is 124 words; want 3..=25
2026-07-17T03:24:37.9661382Z   [must] requirement_quality REQ-ADAPTER-VERSION-CMD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9661905Z   [must] requirement_quality REQ-ADAPTER-VERSION-CMD criterion=length — title is 59 words; want 3..=25
2026-07-17T03:24:37.9662513Z   [must] requirement_quality REQ-API-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9663095Z   [must] requirement_quality REQ-API-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9663587Z   [must] requirement_quality REQ-API-4 criterion=length — title is 67 words; want 3..=25
2026-07-17T03:24:37.9664102Z   [must] requirement_quality REQ-API-ENDPOINT-INFO criterion=length — title is 138 words; want 3..=25
2026-07-17T03:24:37.9665027Z   [must] requirement_quality REQ-BIND-HONEST-SELF-STAMP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9665600Z   [must] requirement_quality REQ-BIND-HONEST-SELF-STAMP criterion=length — title is 182 words; want 3..=25
2026-07-17T03:24:37.9666296Z   [must] requirement_quality REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9666877Z   [must] requirement_quality REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD criterion=length — title is 134 words; want 3..=25
2026-07-17T03:24:37.9667558Z   [must] requirement_quality REQ-BOUNDARY-ROTATION-CREDENTIAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9668122Z   [must] requirement_quality REQ-BOUNDARY-ROTATION-CREDENTIAL criterion=length — title is 53 words; want 3..=25
2026-07-17T03:24:37.9668823Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONN-DEADLOCK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9669575Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONN-DEADLOCK criterion=length — title is 477 words; want 3..=25
2026-07-17T03:24:37.9670269Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONTROL-STEAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9671060Z   [must] requirement_quality REQ-BRAIN-RESUME-NO-CONTROL-STEAL criterion=length — title is 498 words; want 3..=25
2026-07-17T03:24:37.9671942Z   [must] requirement_quality REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9672551Z   [must] requirement_quality REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE criterion=length — title is 282 words; want 3..=25
2026-07-17T03:24:37.9673246Z   [must] requirement_quality REQ-BROKER-ATTACH-JOURNAL-RESILIENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9673946Z   [must] requirement_quality REQ-BROKER-ATTACH-JOURNAL-RESILIENT criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9674662Z   [must] requirement_quality REQ-BROKER-SCREEN-GRID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9675178Z   [must] requirement_quality REQ-BROKER-SCREEN-GRID criterion=length — title is 126 words; want 3..=25
2026-07-17T03:24:37.9675836Z   [must] requirement_quality REQ-CARRIER-CLAIM-EXCLUSIVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9676380Z   [must] requirement_quality REQ-CARRIER-CLAIM-EXCLUSIVE criterion=length — title is 218 words; want 3..=25
2026-07-17T03:24:37.9677000Z   [must] requirement_quality REQ-CI-DOCS-ONLY-THIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9677539Z   [must] requirement_quality REQ-CI-DOCS-ONLY-THIN criterion=length — title is 123 words; want 3..=25
2026-07-17T03:24:37.9678005Z   [must] requirement_quality REQ-CLI-1 criterion=length — title is 97 words; want 3..=25
2026-07-17T03:24:37.9678466Z   [must] requirement_quality REQ-CLI-2 criterion=length — title is 37 words; want 3..=25
2026-07-17T03:24:37.9678916Z   [must] requirement_quality REQ-CLI-3 criterion=length — title is 37 words; want 3..=25
2026-07-17T03:24:37.9679508Z   [must] requirement_quality REQ-CLI-4 criterion=length — title is 89 words; want 3..=25
2026-07-17T03:24:37.9680049Z   [must] requirement_quality REQ-CLI-BROKEN-PIPE-TOLERANT criterion=length — title is 78 words; want 3..=25
2026-07-17T03:24:37.9680685Z   [must] requirement_quality REQ-CLI-HELP-MARKDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9681201Z   [must] requirement_quality REQ-CLI-HELP-MARKDOWN criterion=length — title is 156 words; want 3..=25
2026-07-17T03:24:37.9681835Z   [must] requirement_quality REQ-CLI-JSON criterion=length — title is 95 words; want 3..=25
2026-07-17T03:24:37.9682493Z   [must] requirement_quality REQ-CLI-OUTPUT-MARKDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9683026Z   [must] requirement_quality REQ-CLI-OUTPUT-MARKDOWN criterion=length — title is 199 words; want 3..=25
2026-07-17T03:24:37.9683648Z   [must] requirement_quality REQ-CLI-WIN-VT-ENABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9684163Z   [must] requirement_quality REQ-CLI-WIN-VT-ENABLE criterion=length — title is 110 words; want 3..=25
2026-07-17T03:24:37.9684854Z   [must] requirement_quality REQ-CONN-BLACKHOLE-LIFECYCLE-HARNESS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9685431Z   [must] requirement_quality REQ-CONN-BLACKHOLE-LIFECYCLE-HARNESS criterion=length — title is 147 words; want 3..=25
2026-07-17T03:24:37.9686114Z   [must] requirement_quality REQ-CONN-POISON-ATTRIBUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9686659Z   [must] requirement_quality REQ-CONN-POISON-ATTRIBUTION criterion=length — title is 227 words; want 3..=25
2026-07-17T03:24:37.9687316Z   [must] requirement_quality REQ-CONN-POISON-DIAL-SCOPE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9687862Z   [must] requirement_quality REQ-CONN-POISON-DIAL-SCOPE criterion=length — title is 245 words; want 3..=25
2026-07-17T03:24:37.9688331Z   [must] requirement_quality REQ-CONSENT-1 criterion=length — title is 41 words; want 3..=25
2026-07-17T03:24:37.9688813Z   [must] requirement_quality REQ-CONSENT-2 criterion=length — title is 37 words; want 3..=25
2026-07-17T03:24:37.9689400Z   [must] requirement_quality REQ-CONSENT-3 criterion=length — title is 82 words; want 3..=25
2026-07-17T03:24:37.9690082Z   [must] requirement_quality REQ-CONTROLLER-LIVENESS-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9690709Z   [must] requirement_quality REQ-CONTROLLER-LIVENESS-REAP criterion=length — title is 370 words; want 3..=25
2026-07-17T03:24:37.9691356Z   [must] requirement_quality REQ-CONV-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9691818Z   [must] requirement_quality REQ-CONV-1 criterion=length — title is 73 words; want 3..=25
2026-07-17T03:24:37.9692281Z   [must] requirement_quality REQ-CONV-2 criterion=length — title is 47 words; want 3..=25
2026-07-17T03:24:37.9692810Z   [must] requirement_quality REQ-CRC-SWAP-OLD-DISPLACE criterion=length — title is 125 words; want 3..=25
2026-07-17T03:24:37.9693401Z   [must] requirement_quality REQ-DAEMON-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9693869Z   [must] requirement_quality REQ-DAEMON-5 criterion=length — title is 64 words; want 3..=25
2026-07-17T03:24:37.9694475Z   [must] requirement_quality REQ-DAEMON-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9694958Z   [must] requirement_quality REQ-DAEMON-6 criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9695535Z   [must] requirement_quality REQ-DAEMON-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9696000Z   [must] requirement_quality REQ-DAEMON-7 criterion=length — title is 62 words; want 3..=25
2026-07-17T03:24:37.9696456Z   [must] requirement_quality REQ-DAEMON-8 criterion=length — title is 44 words; want 3..=25
2026-07-17T03:24:37.9697047Z   [must] requirement_quality REQ-DAEMON-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9697586Z   [must] requirement_quality REQ-DAEMON-9 criterion=length — title is 114 words; want 3..=25
2026-07-17T03:24:37.9698330Z   [must] requirement_quality REQ-DAEMON-REFRESH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9698844Z   [must] requirement_quality REQ-DAEMON-REFRESH criterion=length — title is 147 words; want 3..=25
2026-07-17T03:24:37.9699520Z   [must] requirement_quality REQ-DAEMON-SERVICE-INSTALL criterion=length — title is 88 words; want 3..=25
2026-07-17T03:24:37.9700183Z   [must] requirement_quality REQ-DAEMON-STATUS-JSON-TRUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9700723Z   [must] requirement_quality REQ-DAEMON-STATUS-JSON-TRUTH criterion=length — title is 73 words; want 3..=25
2026-07-17T03:24:37.9701260Z   [must] requirement_quality REQ-DAEMON-STDERR-PERSIST criterion=length — title is 55 words; want 3..=25
2026-07-17T03:24:37.9701811Z   [must] requirement_quality REQ-DAEMON-STOP-LIVE-SESSION-WARN criterion=length — title is 28 words; want 3..=25
2026-07-17T03:24:37.9702445Z   [must] requirement_quality REQ-DIGEST-CURSOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9702941Z   [must] requirement_quality REQ-DIGEST-CURSOR criterion=length — title is 181 words; want 3..=25
2026-07-17T03:24:37.9703675Z   [must] requirement_quality REQ-DIGEST-FETCHER-STRATEGY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9704217Z   [must] requirement_quality REQ-DIGEST-FETCHER-STRATEGY criterion=length — title is 167 words; want 3..=25
2026-07-17T03:24:37.9704884Z   [must] requirement_quality REQ-DIGEST-GENERATION-SUPERSEDE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9705437Z   [must] requirement_quality REQ-DIGEST-GENERATION-SUPERSEDE criterion=length — title is 353 words; want 3..=25
2026-07-17T03:24:37.9706057Z   [must] requirement_quality REQ-DIGEST-PROFILE-ENV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9706660Z   [must] requirement_quality REQ-DIGEST-PROFILE-ENV criterion=length — title is 96 words; want 3..=25
2026-07-17T03:24:37.9707292Z   [must] requirement_quality REQ-DISPATCH-CLAIM-RETRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9707831Z   [must] requirement_quality REQ-DISPATCH-CLAIM-RETRY criterion=length — title is 117 words; want 3..=25
2026-07-17T03:24:37.9708475Z   [must] requirement_quality REQ-DISPATCH-FALLBACK-CIRCUIT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9709123Z   [must] requirement_quality REQ-DISPATCH-FALLBACK-CIRCUIT criterion=length — title is 160 words; want 3..=25
2026-07-17T03:24:37.9709676Z   [must] requirement_quality REQ-DISPATCH-HYGIENE-TELEMETRY criterion=length — title is 126 words; want 3..=25
2026-07-17T03:24:37.9710185Z   [must] requirement_quality REQ-DOC-DELIVERY-VOCAB criterion=length — title is 52 words; want 3..=25
2026-07-17T03:24:37.9710752Z   [must] requirement_quality REQ-DOC-ECHO-COMMUNE-CONTRACT criterion=length — title is 60 words; want 3..=25
2026-07-17T03:24:37.9711315Z   [must] requirement_quality REQ-DOC-ENDPOINT-DROP-RESOLUTION criterion=length — title is 57 words; want 3..=25
2026-07-17T03:24:37.9711839Z   [must] requirement_quality REQ-DOCS-LOCAL-SERVER criterion=length — title is 181 words; want 3..=25
2026-07-17T03:24:37.9712476Z   [must] requirement_quality REQ-DOCS-NO-INTERNAL-CODES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9713010Z   [must] requirement_quality REQ-DOCS-NO-INTERNAL-CODES criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9713529Z   [must] requirement_quality REQ-DOCS-RELEASE-ASSET criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9714089Z   [must] requirement_quality REQ-ECHO-DROP-DIR-RESOLVE criterion=length — title is 127 words; want 3..=25
2026-07-17T03:24:37.9714919Z   [must] requirement_quality REQ-EFFECTIVE-INSTANCE-STATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9715487Z   [must] requirement_quality REQ-EFFECTIVE-INSTANCE-STATE criterion=length — title is 160 words; want 3..=25
2026-07-17T03:24:37.9716106Z   [must] requirement_quality REQ-ELEVATE-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9716583Z   [must] requirement_quality REQ-ELEVATE-1 criterion=length — title is 121 words; want 3..=25
2026-07-17T03:24:37.9717107Z   [must] requirement_quality REQ-ENDPOINT-AUTOSTART criterion=length — title is 249 words; want 3..=25
2026-07-17T03:24:37.9717648Z   [must] requirement_quality REQ-ENDPOINT-LIST-MERGE-LOCAL criterion=length — title is 95 words; want 3..=25
2026-07-17T03:24:37.9718926Z   [must] requirement_quality REQ-ENDPOINT-LIST-NODE-GROUPED criterion=length — title is 213 words; want 3..=25
2026-07-17T03:24:37.9719589Z   [must] requirement_quality REQ-ENDPOINT-LIST-NODE-IDENT criterion=length — title is 57 words; want 3..=25
2026-07-17T03:24:37.9720284Z   [must] requirement_quality REQ-ENDPOINT-LIST-PALETTE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9720903Z   [must] requirement_quality REQ-ENDPOINT-LIST-PALETTE criterion=length — title is 106 words; want 3..=25
2026-07-17T03:24:37.9721453Z   [must] requirement_quality REQ-ENDPOINT-LIST-PROJECT-COL criterion=length — title is 79 words; want 3..=25
2026-07-17T03:24:37.9722043Z   [must] requirement_quality REQ-ENDPOINT-LIST-RENDER-POLISH criterion=length — title is 122 words; want 3..=25
2026-07-17T03:24:37.9734574Z   [must] requirement_quality REQ-ENDPOINT-LIST-REST-FILTER criterion=length — title is 110 words; want 3..=25
2026-07-17T03:24:37.9735341Z   [must] requirement_quality REQ-ENDPOINT-PURGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9735870Z   [must] requirement_quality REQ-ENDPOINT-PURGE criterion=length — title is 220 words; want 3..=25
2026-07-17T03:24:37.9736578Z   [must] requirement_quality REQ-ENDPOINT-STOP-OFFLINE criterion=length — title is 58 words; want 3..=25
2026-07-17T03:24:37.9737269Z   [must] requirement_quality REQ-ENDPOINT-UNBOUND-ATTACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9737814Z   [must] requirement_quality REQ-ENDPOINT-UNBOUND-ATTACH criterion=length — title is 122 words; want 3..=25
2026-07-17T03:24:37.9738520Z   [must] requirement_quality REQ-EP-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9739102Z   [must] requirement_quality REQ-EP-6 criterion=length — title is 58 words; want 3..=25
2026-07-17T03:24:37.9739569Z   [must] requirement_quality REQ-EP-7 criterion=length — title is 68 words; want 3..=25
2026-07-17T03:24:37.9740023Z   [must] requirement_quality REQ-EP-8 criterion=length — title is 114 words; want 3..=25
2026-07-17T03:24:37.9740629Z   [must] requirement_quality REQ-EP-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9741089Z   [must] requirement_quality REQ-EP-9 criterion=length — title is 76 words; want 3..=25
2026-07-17T03:24:37.9741766Z   [must] requirement_quality REQ-GOSSIP-ADAPTER-PROJECTS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9742315Z   [must] requirement_quality REQ-GOSSIP-ADAPTER-PROJECTS criterion=length — title is 82 words; want 3..=25
2026-07-17T03:24:37.9742959Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-ANY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9743496Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-ANY criterion=length — title is 92 words; want 3..=25
2026-07-17T03:24:37.9744046Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-CROSS-NODE criterion=length — title is 108 words; want 3..=25
2026-07-17T03:24:37.9744905Z   [must] requirement_quality REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9745507Z   [must] requirement_quality REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP criterion=length — title is 199 words; want 3..=25
2026-07-17T03:24:37.9746132Z   [must] requirement_quality REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER criterion=length — title is 114 words; want 3..=25
2026-07-17T03:24:37.9746685Z   [must] requirement_quality REQ-HAZARD-ATOMIC-TMP-COLLISION criterion=length — title is 29 words; want 3..=25
2026-07-17T03:24:37.9747334Z   [must] requirement_quality REQ-HAZARD-ATTACH-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9747858Z   [must] requirement_quality REQ-HAZARD-ATTACH-WEDGE criterion=length — title is 244 words; want 3..=25
2026-07-17T03:24:37.9748497Z   [must] requirement_quality REQ-HAZARD-BIND-CWD-UNSET criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9749203Z   [must] requirement_quality REQ-HAZARD-BIND-CWD-UNSET criterion=length — title is 130 words; want 3..=25
2026-07-17T03:24:37.9749881Z   [must] requirement_quality REQ-HAZARD-BIND-REST-STATE-CARRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9750525Z   [must] requirement_quality REQ-HAZARD-BIND-REST-STATE-CARRY criterion=length — title is 115 words; want 3..=25
2026-07-17T03:24:37.9751203Z   [must] requirement_quality REQ-HAZARD-BOUNDARY-READY-STRAND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9751758Z   [must] requirement_quality REQ-HAZARD-BOUNDARY-READY-STRAND criterion=length — title is 175 words; want 3..=25
2026-07-17T03:24:37.9752416Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESPAWN-PATH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9753003Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESPAWN-PATH criterion=length — title is 119 words; want 3..=25
2026-07-17T03:24:37.9753805Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9754426Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE criterion=length — title is 125 words; want 3..=25
2026-07-17T03:24:37.9755118Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9755681Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP criterion=length — title is 199 words; want 3..=25
2026-07-17T03:24:37.9756372Z   [must] requirement_quality REQ-HAZARD-BROKER-FLOOR-LOCK-POISON criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9756937Z   [must] requirement_quality REQ-HAZARD-BROKER-FLOOR-LOCK-POISON criterion=length — title is 333 words; want 3..=25
2026-07-17T03:24:37.9757666Z   [must] requirement_quality REQ-HAZARD-BROKER-PROCESS-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9758247Z   [must] requirement_quality REQ-HAZARD-BROKER-PROCESS-ISOLATION criterion=length — title is 114 words; want 3..=25
2026-07-17T03:24:37.9758905Z   [must] requirement_quality REQ-HAZARD-BROKER-QUIC-DEADLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9759581Z   [must] requirement_quality REQ-HAZARD-BROKER-QUIC-DEADLINE criterion=length — title is 162 words; want 3..=25
2026-07-17T03:24:37.9760241Z   [must] requirement_quality REQ-HAZARD-BROKER-SEED-WIRE-SKEW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9760795Z   [must] requirement_quality REQ-HAZARD-BROKER-SEED-WIRE-SKEW criterion=length — title is 193 words; want 3..=25
2026-07-17T03:24:37.9761642Z   [must] requirement_quality REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9762252Z   [must] requirement_quality REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE criterion=length — title is 192 words; want 3..=25
2026-07-17T03:24:37.9762815Z   [must] requirement_quality REQ-HAZARD-CEREMONY-CLOCK-STEP criterion=length — title is 139 words; want 3..=25
2026-07-17T03:24:37.9763374Z   [must] requirement_quality REQ-HAZARD-COMMUNE-INGEST-BLACKHOLE criterion=length — title is 263 words; want 3..=25
2026-07-17T03:24:37.9763930Z   [must] requirement_quality REQ-HAZARD-CONFLICT-BOTH-PRESERVED criterion=length — title is 29 words; want 3..=25
2026-07-17T03:24:37.9764611Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-CONVERGENCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9765185Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-CONVERGENCE criterion=length — title is 193 words; want 3..=25
2026-07-17T03:24:37.9765907Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-LIFETIME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9766541Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-LIFETIME criterion=length — title is 100 words; want 3..=25
2026-07-17T03:24:37.9767233Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-GAP-RESUME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9767786Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-GAP-RESUME criterion=length — title is 297 words; want 3..=25
2026-07-17T03:24:37.9768502Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9769212Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND criterion=length — title is 134 words; want 3..=25
2026-07-17T03:24:37.9769931Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-RETAKE-FLOOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9770595Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-RETAKE-FLOOR criterion=length — title is 184 words; want 3..=25
2026-07-17T03:24:37.9771292Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-WRITER-REORDER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9771860Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-WRITER-REORDER criterion=length — title is 643 words; want 3..=25
2026-07-17T03:24:37.9772566Z   [must] requirement_quality REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9773150Z   [must] requirement_quality REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE criterion=length — title is 275 words; want 3..=25
2026-07-17T03:24:37.9773714Z   [must] requirement_quality REQ-HAZARD-DAEMON-SCHED-NONBLOCKING criterion=length — title is 32 words; want 3..=25
2026-07-17T03:24:37.9774443Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-BARRIER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9774996Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-BARRIER criterion=length — title is 80 words; want 3..=25
2026-07-17T03:24:37.9775647Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9776177Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-REAP criterion=length — title is 90 words; want 3..=25
2026-07-17T03:24:37.9776811Z   [must] requirement_quality REQ-HAZARD-DEAD-REC-PID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9777334Z   [must] requirement_quality REQ-HAZARD-DEAD-REC-PID criterion=length — title is 175 words; want 3..=25
2026-07-17T03:24:37.9778120Z   [must] requirement_quality REQ-HAZARD-DEFERRED-MANIFEST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9778675Z   [must] requirement_quality REQ-HAZARD-DEFERRED-MANIFEST criterion=length — title is 112 words; want 3..=25
2026-07-17T03:24:37.9779486Z   [must] requirement_quality REQ-HAZARD-DELIVERY-STARVATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9780040Z   [must] requirement_quality REQ-HAZARD-DELIVERY-STARVATION criterion=length — title is 99 words; want 3..=25
2026-07-17T03:24:37.9780710Z   [must] requirement_quality REQ-HAZARD-DETACHED-DAEMON-STDIO criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9781261Z   [must] requirement_quality REQ-HAZARD-DETACHED-DAEMON-STDIO criterion=length — title is 255 words; want 3..=25
2026-07-17T03:24:37.9781814Z   [must] requirement_quality REQ-HAZARD-DETACHED-PIPE-INHERIT criterion=length — title is 52 words; want 3..=25
2026-07-17T03:24:37.9782564Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9783236Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT criterion=length — title is 232 words; want 3..=25
2026-07-17T03:24:37.9783884Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-SELFHEAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9784426Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-SELFHEAL criterion=length — title is 77 words; want 3..=25
2026-07-17T03:24:37.9785100Z   [must] requirement_quality REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9785674Z   [must] requirement_quality REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE criterion=length — title is 440 words; want 3..=25
2026-07-17T03:24:37.9786378Z   [must] requirement_quality REQ-HAZARD-ELEVATED-DAEMON-SPAWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9786998Z   [must] requirement_quality REQ-HAZARD-ELEVATED-DAEMON-SPAWN criterion=length — title is 58 words; want 3..=25
2026-07-17T03:24:37.9787695Z   [must] requirement_quality REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9788272Z   [must] requirement_quality REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT criterion=length — title is 228 words; want 3..=25
2026-07-17T03:24:37.9788891Z   [must] requirement_quality REQ-HAZARD-ENV-SUBST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9789535Z   [must] requirement_quality REQ-HAZARD-ENV-SUBST criterion=length — title is 168 words; want 3..=25
2026-07-17T03:24:37.9790199Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-CR-LINESAFE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9790799Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-CR-LINESAFE criterion=length — title is 73 words; want 3..=25
2026-07-17T03:24:37.9791478Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-PARSER-SAFE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9791984Z   [must] requirement_quality REQ-HAZARD-EPOCH-RESET criterion=length — title is 60 words; want 3..=25
2026-07-17T03:24:37.9792622Z   [must] requirement_quality REQ-HAZARD-GEN-START-NOW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9793195Z   [must] requirement_quality REQ-HAZARD-HOSTED-LIVENESS-RECONCILE criterion=length — title is 175 words; want 3..=25
2026-07-17T03:24:37.9793867Z   [must] requirement_quality REQ-HAZARD-IDLE-SILENT-NONDELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9794572Z   [must] requirement_quality REQ-HAZARD-IDLE-SILENT-NONDELIVERY criterion=length — title is 436 words; want 3..=25
2026-07-17T03:24:37.9795257Z   [must] requirement_quality REQ-HAZARD-INJECT-CONTROL-COEXIST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9795830Z   [must] requirement_quality REQ-HAZARD-INJECT-CONTROL-COEXIST criterion=length — title is 340 words; want 3..=25
2026-07-17T03:24:37.9796485Z   [must] requirement_quality REQ-HAZARD-INJECT-SETTLE-REARM criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9797034Z   [must] requirement_quality REQ-HAZARD-INJECT-SETTLE-REARM criterion=length — title is 184 words; want 3..=25
2026-07-17T03:24:37.9797772Z   [must] requirement_quality REQ-HAZARD-INJECT-WORKER-POISON criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9798331Z   [must] requirement_quality REQ-HAZARD-INJECT-WORKER-POISON criterion=length — title is 136 words; want 3..=25
2026-07-17T03:24:37.9799174Z   [must] requirement_quality REQ-HAZARD-INPUT-ACK-BACKPRESSURE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9799834Z   [must] requirement_quality REQ-HAZARD-INPUT-ACK-BACKPRESSURE criterion=length — title is 343 words; want 3..=25
2026-07-17T03:24:37.9800382Z   [must] requirement_quality REQ-HAZARD-INSTANT-UNDERFLOW criterion=length — title is 30 words; want 3..=25
2026-07-17T03:24:37.9801016Z   [must] requirement_quality REQ-HAZARD-LISTEN-ORPHAN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9801532Z   [must] requirement_quality REQ-HAZARD-LISTEN-ORPHAN criterion=length — title is 93 words; want 3..=25
2026-07-17T03:24:37.9802110Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-LIVENESS-GATE criterion=length — title is 122 words; want 3..=25
2026-07-17T03:24:37.9802768Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9803407Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-RACE criterion=length — title is 158 words; want 3..=25
2026-07-17T03:24:37.9804089Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-NONRESIDENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9804646Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-NONRESIDENT criterion=length — title is 171 words; want 3..=25
2026-07-17T03:24:37.9805294Z   [must] requirement_quality REQ-HAZARD-MESH-BOOTSTRAP-TRAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9805842Z   [must] requirement_quality REQ-HAZARD-MESH-BOOTSTRAP-TRAP criterion=length — title is 154 words; want 3..=25
2026-07-17T03:24:37.9806371Z   [must] requirement_quality REQ-HAZARD-PAIR-RATE-LIMIT criterion=length — title is 37 words; want 3..=25
2026-07-17T03:24:37.9806938Z   [must] requirement_quality REQ-HAZARD-PAIR-SEED-ROTATION criterion=length — title is 33 words; want 3..=25
2026-07-17T03:24:37.9807613Z   [must] requirement_quality REQ-HAZARD-PAIR-TRANSCRIPT-BIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9808285Z   [must] requirement_quality REQ-HAZARD-PSYCHE-OUTBOUND-PROXY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9808834Z   [must] requirement_quality REQ-HAZARD-PSYCHE-OUTBOUND-PROXY criterion=length — title is 27 words; want 3..=25
2026-07-17T03:24:37.9809638Z   [must] requirement_quality REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9810232Z   [must] requirement_quality REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION criterion=length — title is 130 words; want 3..=25
2026-07-17T03:24:37.9810899Z   [must] requirement_quality REQ-HAZARD-PTY-INPUT-WRITER-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9811596Z   [must] requirement_quality REQ-HAZARD-PTY-INPUT-WRITER-WEDGE criterion=length — title is 287 words; want 3..=25
2026-07-17T03:24:37.9812257Z   [must] requirement_quality REQ-HAZARD-PUMP-IPC-DEADLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9812794Z   [must] requirement_quality REQ-HAZARD-PUMP-IPC-DEADLINE criterion=length — title is 38 words; want 3..=25
2026-07-17T03:24:37.9813442Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-FAILFAST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9813981Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-FAILFAST criterion=length — title is 163 words; want 3..=25
2026-07-17T03:24:37.9814635Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-ONLINE-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9815234Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-ONLINE-RACE criterion=length — title is 184 words; want 3..=25
2026-07-17T03:24:37.9815846Z   [must] requirement_quality REQ-HAZARD-RC-EOF criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9816397Z   [must] requirement_quality REQ-HAZARD-RC-EOF criterion=length — title is 208 words; want 3..=25
2026-07-17T03:24:37.9817061Z   [must] requirement_quality REQ-HAZARD-RC-INPUT-KEY-ENCODING criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9817606Z   [must] requirement_quality REQ-HAZARD-RC-INPUT-KEY-ENCODING criterion=length — title is 222 words; want 3..=25
2026-07-17T03:24:37.9818282Z   [must] requirement_quality REQ-HAZARD-REDISPATCH-CONTROL-STEAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9818845Z   [must] requirement_quality REQ-HAZARD-REDISPATCH-CONTROL-STEAL criterion=length — title is 139 words; want 3..=25
2026-07-17T03:24:37.9819723Z   [must] requirement_quality REQ-HAZARD-REDISPATCH-STALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9820318Z   [must] requirement_quality REQ-HAZARD-REDISPATCH-STALL criterion=length — title is 152 words; want 3..=25
2026-07-17T03:24:37.9820993Z   [must] requirement_quality REQ-HAZARD-REGISTRY-GHOST-ROWS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9821545Z   [must] requirement_quality REQ-HAZARD-REGISTRY-GHOST-ROWS criterion=length — title is 152 words; want 3..=25
2026-07-17T03:24:37.9822103Z   [must] requirement_quality REQ-HAZARD-ROLLBACK-STATE-COMPAT criterion=length — title is 72 words; want 3..=25
2026-07-17T03:24:37.9822732Z   [must] requirement_quality REQ-HAZARD-ROSTER-GHOST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9823245Z   [must] requirement_quality REQ-HAZARD-ROSTER-GHOST criterion=length — title is 116 words; want 3..=25
2026-07-17T03:24:37.9823865Z   [must] requirement_quality REQ-HAZARD-SEEDMAP-CONNECT-UNBOUNDED criterion=length — title is 171 words; want 3..=25
2026-07-17T03:24:37.9824509Z   [must] requirement_quality REQ-HAZARD-SELF-ELEVATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9825028Z   [must] requirement_quality REQ-HAZARD-SELF-ELEVATE criterion=length — title is 101 words; want 3..=25
2026-07-17T03:24:37.9825661Z   [must] requirement_quality REQ-HAZARD-SESSION-PIN-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9826191Z   [must] requirement_quality REQ-HAZARD-SESSION-PIN-WEDGE criterion=length — title is 320 words; want 3..=25
2026-07-17T03:24:37.9826967Z   [must] requirement_quality REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9827731Z   [must] requirement_quality REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK criterion=length — title is 461 words; want 3..=25
2026-07-17T03:24:37.9828328Z   [must] requirement_quality REQ-HAZARD-SPOOL-SENTINEL-CREATE-FAIL criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9829171Z   [must] requirement_quality REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9829772Z   [must] requirement_quality REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9830411Z   [must] requirement_quality REQ-HAZARD-STORE-INIT-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9830935Z   [must] requirement_quality REQ-HAZARD-STORE-INIT-RACE criterion=length — title is 149 words; want 3..=25
2026-07-17T03:24:37.9831467Z   [must] requirement_quality REQ-HAZARD-SUDO-SECURE-PATH criterion=length — title is 43 words; want 3..=25
2026-07-17T03:24:37.9832164Z   [must] requirement_quality REQ-HAZARD-TEMPLATE-ARGV-FILL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9832803Z   [must] requirement_quality REQ-HAZARD-TEMPLATE-ARGV-FILL criterion=length — title is 166 words; want 3..=25
2026-07-17T03:24:37.9833340Z   [must] requirement_quality REQ-HAZARD-THRASH-GUARD-BLIND criterion=length — title is 62 words; want 3..=25
2026-07-17T03:24:37.9834047Z   [must] requirement_quality REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9834629Z   [must] requirement_quality REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH criterion=length — title is 91 words; want 3..=25
2026-07-17T03:24:37.9835292Z   [must] requirement_quality REQ-HAZARD-UNHOST-PSYCHE-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9835864Z   [must] requirement_quality REQ-HAZARD-UNHOST-PSYCHE-REAP criterion=length — title is 161 words; want 3..=25
2026-07-17T03:24:37.9836588Z   [must] requirement_quality REQ-HAZARD-VIEWER-CLOSE-DETACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9837145Z   [must] requirement_quality REQ-HAZARD-VIEWER-CLOSE-DETACH criterion=length — title is 437 words; want 3..=25
2026-07-17T03:24:37.9837785Z   [must] requirement_quality REQ-HAZARD-VIEWER-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9838310Z   [must] requirement_quality REQ-HAZARD-VIEWER-ISOLATION criterion=length — title is 118 words; want 3..=25
2026-07-17T03:24:37.9839078Z   [must] requirement_quality REQ-HAZARD-VIEWER-RING-ROLL-SNAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9839651Z   [must] requirement_quality REQ-HAZARD-VIEWER-RING-ROLL-SNAP criterion=length — title is 167 words; want 3..=25
2026-07-17T03:24:37.9840457Z   [must] requirement_quality REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9841126Z   [must] requirement_quality REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE criterion=length — title is 235 words; want 3..=25
2026-07-17T03:24:37.9841654Z   [must] requirement_quality REQ-HAZARD-WAN-ORIGIN-AUTH criterion=length — title is 37 words; want 3..=25
2026-07-17T03:24:37.9842331Z   [must] requirement_quality REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9842895Z   [must] requirement_quality REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE criterion=length — title is 96 words; want 3..=25
2026-07-17T03:24:37.9843430Z   [must] requirement_quality REQ-HAZARD-WMI-DAEMON-WINDOW criterion=length — title is 101 words; want 3..=25
2026-07-17T03:24:37.9844033Z   [must] requirement_quality REQ-HOST-RUN-1 criterion=length — title is 88 words; want 3..=25
2026-07-17T03:24:37.9844517Z   [must] requirement_quality REQ-HOST-RUN-2 criterion=length — title is 97 words; want 3..=25
2026-07-17T03:24:37.9845165Z   [must] requirement_quality REQ-IDLE-PARKED-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9845691Z   [must] requirement_quality REQ-IDLE-PARKED-DELIVERY criterion=length — title is 116 words; want 3..=25
2026-07-17T03:24:37.9846235Z   [must] requirement_quality REQ-INJECT-MULTILINE-INTEGRITY criterion=length — title is 118 words; want 3..=25
2026-07-17T03:24:37.9846696Z   [must] requirement_quality REQ-INST-15 criterion=length — title is 32 words; want 3..=25
2026-07-17T03:24:37.9847172Z   [must] requirement_quality REQ-INSTALL-1 criterion=length — title is 62 words; want 3..=25
2026-07-17T03:24:37.9847763Z   [must] requirement_quality REQ-INSTALL-10 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9848278Z   [must] requirement_quality REQ-INSTALL-10 criterion=length — title is 58 words; want 3..=25
2026-07-17T03:24:37.9848750Z   [must] requirement_quality REQ-INSTALL-11 criterion=length — title is 78 words; want 3..=25
2026-07-17T03:24:37.9849448Z   [must] requirement_quality REQ-INSTALL-12 criterion=length — title is 116 words; want 3..=25
2026-07-17T03:24:37.9850054Z   [must] requirement_quality REQ-INSTALL-13 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9850526Z   [must] requirement_quality REQ-INSTALL-13 criterion=length — title is 131 words; want 3..=25
2026-07-17T03:24:37.9850998Z   [must] requirement_quality REQ-INSTALL-2 criterion=length — title is 2 word(s); want 3..=25
2026-07-17T03:24:37.9851465Z   [must] requirement_quality REQ-INSTALL-5 criterion=length — title is 62 words; want 3..=25
2026-07-17T03:24:37.9852050Z   [must] requirement_quality REQ-INSTALL-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9852625Z   [must] requirement_quality REQ-INSTALL-6 criterion=length — title is 56 words; want 3..=25
2026-07-17T03:24:37.9853206Z   [must] requirement_quality REQ-INSTALL-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9853693Z   [must] requirement_quality REQ-INSTALL-7 criterion=length — title is 50 words; want 3..=25
2026-07-17T03:24:37.9854155Z   [must] requirement_quality REQ-INSTALL-8 criterion=length — title is 55 words; want 3..=25
2026-07-17T03:24:37.9854744Z   [must] requirement_quality REQ-INSTALL-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9855207Z   [must] requirement_quality REQ-INSTALL-9 criterion=length — title is 62 words; want 3..=25
2026-07-17T03:24:37.9855851Z   [must] requirement_quality REQ-INSTALL-BOOTSTRAP-VERB criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9856412Z   [must] requirement_quality REQ-INSTALL-BOOTSTRAP-VERB criterion=length — title is 177 words; want 3..=25
2026-07-17T03:24:37.9857081Z   [must] requirement_quality REQ-JOIN-DEFERRED-ELEVATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9857622Z   [must] requirement_quality REQ-JOIN-DEFERRED-ELEVATION criterion=length — title is 156 words; want 3..=25
2026-07-17T03:24:37.9858234Z   [must] requirement_quality REQ-JOIN-DIAGNOSTICS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9858744Z   [must] requirement_quality REQ-JOIN-DIAGNOSTICS criterion=length — title is 137 words; want 3..=25
2026-07-17T03:24:37.9859369Z   [must] requirement_quality REQ-JOIN-TWO-PHASE criterion=length — title is 161 words; want 3..=25
2026-07-17T03:24:37.9859999Z   [must] requirement_quality REQ-JOIN-VERBOSE-CLOCK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9860653Z   [must] requirement_quality REQ-JOIN-VERBOSE-CLOCK criterion=length — title is 108 words; want 3..=25
2026-07-17T03:24:37.9861253Z   [must] requirement_quality REQ-KICK-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9861724Z   [must] requirement_quality REQ-KICK-1 criterion=length — title is 133 words; want 3..=25
2026-07-17T03:24:37.9862382Z   [must] requirement_quality REQ-LIST-JSON-LIVENESS-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9862923Z   [must] requirement_quality REQ-LIST-JSON-LIVENESS-PARITY criterion=length — title is 240 words; want 3..=25
2026-07-17T03:24:37.9863600Z   [must] requirement_quality REQ-LISTEN-SEED-CONSUME-AFTER-BIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9864164Z   [must] requirement_quality REQ-LISTEN-SEED-CONSUME-AFTER-BIND criterion=length — title is 167 words; want 3..=25
2026-07-17T03:24:37.9864959Z   [must] requirement_quality REQ-LISTEN-SESSION-ID-FALLBACK criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9865571Z   [must] requirement_quality REQ-LISTEN-SESSION-ID-FALLBACK criterion=length — title is 185 words; want 3..=25
2026-07-17T03:24:37.9866243Z   [must] requirement_quality REQ-LIVE-AGENT-NO-INJECT-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9866801Z   [must] requirement_quality REQ-LIVE-AGENT-NO-INJECT-DELIVERY criterion=length — title is 312 words; want 3..=25
2026-07-17T03:24:37.9867478Z   [must] requirement_quality REQ-LIVEHOST-RECONCILE-TRIAL-SILENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9868040Z   [must] requirement_quality REQ-LIVEHOST-RECONCILE-TRIAL-SILENT criterion=length — title is 214 words; want 3..=25
2026-07-17T03:24:37.9868660Z   [must] requirement_quality REQ-MANIFEST-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9869261Z   [must] requirement_quality REQ-MANIFEST-3 criterion=length — title is 26 words; want 3..=25
2026-07-17T03:24:37.9869746Z   [must] requirement_quality REQ-MANIFEST-4 criterion=length — title is 31 words; want 3..=25
2026-07-17T03:24:37.9870213Z   [must] requirement_quality REQ-MANIFEST-5 criterion=length — title is 132 words; want 3..=25
2026-07-17T03:24:37.9870684Z   [must] requirement_quality REQ-MANIFEST-6 criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9871150Z   [must] requirement_quality REQ-MANIFEST-7 criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9871617Z   [must] requirement_quality REQ-MANIFEST-8 criterion=length — title is 77 words; want 3..=25
2026-07-17T03:24:37.9872238Z   [must] requirement_quality REQ-MANIFEST-NODE-KEY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9872772Z   [must] requirement_quality REQ-MANIFEST-NODE-KEY criterion=length — title is 187 words; want 3..=25
2026-07-17T03:24:37.9873397Z   [must] requirement_quality REQ-MANIFEST-SUBST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9873908Z   [must] requirement_quality REQ-MANIFEST-SUBST criterion=length — title is 121 words; want 3..=25
2026-07-17T03:24:37.9874356Z   [must] requirement_quality REQ-MESH-1 criterion=length — title is 86 words; want 3..=25
2026-07-17T03:24:37.9874937Z   [must] requirement_quality REQ-MESH-2 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9875420Z   [must] requirement_quality REQ-MESH-2 criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9875992Z   [must] requirement_quality REQ-MESH-3 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9876446Z   [must] requirement_quality REQ-MESH-3 criterion=length — title is 86 words; want 3..=25
2026-07-17T03:24:37.9877180Z   [must] requirement_quality REQ-MESH-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9877648Z   [must] requirement_quality REQ-MESH-4 criterion=length — title is 99 words; want 3..=25
2026-07-17T03:24:37.9878225Z   [must] requirement_quality REQ-MESH-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9878677Z   [must] requirement_quality REQ-MESH-5 criterion=length — title is 72 words; want 3..=25
2026-07-17T03:24:37.9879368Z   [must] requirement_quality REQ-MESH-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9879826Z   [must] requirement_quality REQ-MESH-6 criterion=length — title is 56 words; want 3..=25
2026-07-17T03:24:37.9880417Z   [must] requirement_quality REQ-MIGRATE-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9880901Z   [must] requirement_quality REQ-MSG-4 criterion=length — title is 31 words; want 3..=25
2026-07-17T03:24:37.9881429Z   [must] requirement_quality REQ-MSG-5 criterion=length — title is 38 words; want 3..=25
2026-07-17T03:24:37.9881934Z   [must] requirement_quality REQ-MSG-6 criterion=length — title is 65 words; want 3..=25
2026-07-17T03:24:37.9882555Z   [must] requirement_quality REQ-MSG-CLI-ORIGIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9883051Z   [must] requirement_quality REQ-MSG-CLI-ORIGIN criterion=length — title is 107 words; want 3..=25
2026-07-17T03:24:37.9883679Z   [must] requirement_quality REQ-MSG-DELIVERY-AXES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9884195Z   [must] requirement_quality REQ-MSG-DELIVERY-AXES criterion=length — title is 291 words; want 3..=25
2026-07-17T03:24:37.9884793Z   [must] requirement_quality REQ-MSG-ENVELOPE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9885336Z   [must] requirement_quality REQ-MSG-ENVELOPE criterion=length — title is 153 words; want 3..=25
2026-07-17T03:24:37.9885976Z   [must] requirement_quality REQ-MSG-IDLE-EDGE-DRAIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9886495Z   [must] requirement_quality REQ-MSG-IDLE-EDGE-DRAIN criterion=length — title is 121 words; want 3..=25
2026-07-17T03:24:37.9887158Z   [must] requirement_quality REQ-MSG-IDLE-TRANSLATION-BINARY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9887711Z   [must] requirement_quality REQ-MSG-IDLE-TRANSLATION-BINARY criterion=length — title is 269 words; want 3..=25
2026-07-17T03:24:37.9888360Z   [must] requirement_quality REQ-MSG-SELF-DETECT-ANCESTRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9889180Z   [must] requirement_quality REQ-MSG-SELF-DETECT-ANCESTRY criterion=length — title is 153 words; want 3..=25
2026-07-17T03:24:37.9889823Z   [must] requirement_quality REQ-NET-FAMILY-GATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9890332Z   [must] requirement_quality REQ-NET-FAMILY-GATE criterion=length — title is 118 words; want 3..=25
2026-07-17T03:24:37.9890967Z   [must] requirement_quality REQ-OPID-MINTER-NAMESPACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9891498Z   [must] requirement_quality REQ-OPID-MINTER-NAMESPACE criterion=length — title is 337 words; want 3..=25
2026-07-17T03:24:37.9892128Z   [must] requirement_quality REQ-OPID-TRACING-RETRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9892644Z   [must] requirement_quality REQ-OPID-TRACING-RETRY criterion=length — title is 222 words; want 3..=25
2026-07-17T03:24:37.9893248Z   [must] requirement_quality REQ-PAIR-8 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9893724Z   [must] requirement_quality REQ-PAIR-8 criterion=length — title is 67 words; want 3..=25
2026-07-17T03:24:37.9894380Z   [must] requirement_quality REQ-PAIR-NTP-LOUD-FAIL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9894890Z   [must] requirement_quality REQ-PAIR-NTP-LOUD-FAIL criterion=length — title is 104 words; want 3..=25
2026-07-17T03:24:37.9895529Z   [must] requirement_quality REQ-PAIR-NTP-MULTIHOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9896043Z   [must] requirement_quality REQ-PAIR-NTP-MULTIHOME criterion=length — title is 131 words; want 3..=25
2026-07-17T03:24:37.9896672Z   [must] requirement_quality REQ-PEER-PUMP-CHURN-STALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9897229Z   [must] requirement_quality REQ-PEER-PUMP-CHURN-STALL criterion=length — title is 97 words; want 3..=25
2026-07-17T03:24:37.9897975Z   [must] requirement_quality REQ-PEER-ROUTE-CHAIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9898554Z   [must] requirement_quality REQ-PEER-ROUTE-CHAIN criterion=length — title is 177 words; want 3..=25
2026-07-17T03:24:37.9899302Z   [must] requirement_quality REQ-PEERADDR-INVARIANT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9899825Z   [must] requirement_quality REQ-PEERADDR-INVARIANT criterion=length — title is 138 words; want 3..=25
2026-07-17T03:24:37.9900417Z   [must] requirement_quality REQ-PICKER-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9900888Z   [must] requirement_quality REQ-PICKER-1 criterion=length — title is 156 words; want 3..=25
2026-07-17T03:24:37.9901356Z   [must] requirement_quality REQ-PICKER-2 criterion=length — title is 77 words; want 3..=25
2026-07-17T03:24:37.9901860Z   [must] requirement_quality REQ-PICKER-3 criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9902468Z   [must] requirement_quality REQ-PICKER-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9902931Z   [must] requirement_quality REQ-PICKER-4 criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9903518Z   [must] requirement_quality REQ-PICKER-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9903984Z   [must] requirement_quality REQ-PICKER-5 criterion=length — title is 147 words; want 3..=25
2026-07-17T03:24:37.9904647Z   [must] requirement_quality REQ-PICKER-ADAPTER-DESCRIPTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9905193Z   [must] requirement_quality REQ-PICKER-ADAPTER-DESCRIPTION criterion=length — title is 64 words; want 3..=25
2026-07-17T03:24:37.9905950Z   [must] requirement_quality REQ-PICKER-BACK-NAV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9906461Z   [must] requirement_quality REQ-PICKER-BACK-NAV criterion=length — title is 140 words; want 3..=25
2026-07-17T03:24:37.9907115Z   [must] requirement_quality REQ-PICKER-CHANGE-ADAPTER-FLOW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9907669Z   [must] requirement_quality REQ-PICKER-CHANGE-ADAPTER-FLOW criterion=length — title is 117 words; want 3..=25
2026-07-17T03:24:37.9908313Z   [must] requirement_quality REQ-PICKER-CHOOSE-DEDUP-ALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9908846Z   [must] requirement_quality REQ-PICKER-CHOOSE-DEDUP-ALL criterion=length — title is 72 words; want 3..=25
2026-07-17T03:24:37.9909533Z   [must] requirement_quality REQ-PICKER-CONTROL-LINE-STATUS-GATE criterion=length — title is 71 words; want 3..=25
2026-07-17T03:24:37.9910233Z   [must] requirement_quality REQ-PICKER-CONTROLLED-LOCAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9910785Z   [must] requirement_quality REQ-PICKER-CONTROLLED-LOCAL criterion=length — title is 95 words; want 3..=25
2026-07-17T03:24:37.9911320Z   [must] requirement_quality REQ-PICKER-CURRENT-DIR-LABEL criterion=length — title is 114 words; want 3..=25
2026-07-17T03:24:37.9911958Z   [must] requirement_quality REQ-PICKER-FORK-LABEL-CWD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9912482Z   [must] requirement_quality REQ-PICKER-FORK-LABEL-CWD criterion=length — title is 58 words; want 3..=25
2026-07-17T03:24:37.9913004Z   [must] requirement_quality REQ-PICKER-HISTORY-FRESH criterion=length — title is 51 words; want 3..=25
2026-07-17T03:24:37.9913553Z   [must] requirement_quality REQ-PICKER-HISTORY-FRESH criterion=tbd-todo — title contains placeholder marker 'TBD'
2026-07-17T03:24:37.9914225Z   [must] requirement_quality REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE criterion=length — title is 89 words; want 3..=25
2026-07-17T03:24:37.9914802Z   [must] requirement_quality REQ-PICKER-NODE-GROUPING criterion=length — title is 73 words; want 3..=25
2026-07-17T03:24:37.9915354Z   [must] requirement_quality REQ-PICKER-OFFLINE-NO-VIEW criterion=length — title is 46 words; want 3..=25
2026-07-17T03:24:37.9915886Z   [must] requirement_quality REQ-PICKER-ONLINE-ACTION criterion=length — title is 74 words; want 3..=25
2026-07-17T03:24:37.9916449Z   [must] requirement_quality REQ-PICKER-ONLINE-ACTION criterion=tbd-todo — title contains placeholder marker 'TBD'
2026-07-17T03:24:37.9917007Z   [must] requirement_quality REQ-PICKER-PROJECT-DISPLAY-NAME criterion=length — title is 103 words; want 3..=25
2026-07-17T03:24:37.9917560Z   [must] requirement_quality REQ-PICKER-PROJECT-HISTORY-TRUTH criterion=length — title is 128 words; want 3..=25
2026-07-17T03:24:37.9918229Z   [must] requirement_quality REQ-PICKER-PURGE-SHORTCUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9918772Z   [must] requirement_quality REQ-PICKER-PURGE-SHORTCUT criterion=length — title is 180 words; want 3..=25
2026-07-17T03:24:37.9919541Z   [must] requirement_quality REQ-PICKER-REMOTE-WAKE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9920059Z   [must] requirement_quality REQ-PICKER-REMOTE-WAKE criterion=length — title is 296 words; want 3..=25
2026-07-17T03:24:37.9920726Z   [must] requirement_quality REQ-PICKER-RESUME-CONTEXT-PANEL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9921280Z   [must] requirement_quality REQ-PICKER-RESUME-CONTEXT-PANEL criterion=length — title is 53 words; want 3..=25
2026-07-17T03:24:37.9921951Z   [must] requirement_quality REQ-PICKER-SHORTCUT-LABEL-FILENAME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9922658Z   [must] requirement_quality REQ-PICKER-SHORTCUT-LABEL-FILENAME criterion=length — title is 75 words; want 3..=25
2026-07-17T03:24:37.9923216Z   [must] requirement_quality REQ-PICKER-START-PROJECT-CHOICE criterion=length — title is 87 words; want 3..=25
2026-07-17T03:24:37.9923827Z   [must] requirement_quality REQ-PICKER-UX-V013 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9924309Z   [must] requirement_quality REQ-PICKER-UX-V013 criterion=length — title is 86 words; want 3..=25
2026-07-17T03:24:37.9924833Z   [must] requirement_quality REQ-PICKER-WINDOW-TITLE criterion=length — title is 68 words; want 3..=25
2026-07-17T03:24:37.9925433Z   [must] requirement_quality REQ-PLATFORM-MUSL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9925933Z   [must] requirement_quality REQ-PLATFORM-MUSL criterion=length — title is 106 words; want 3..=25
2026-07-17T03:24:37.9926599Z   [must] requirement_quality REQ-PLATFORM-REGISTRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9927176Z   [must] requirement_quality REQ-PLATFORM-REGISTRY criterion=length — title is 126 words; want 3..=25
2026-07-17T03:24:37.9927767Z   [must] requirement_quality REQ-PRES-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9928225Z   [must] requirement_quality REQ-PRES-1 criterion=length — title is 48 words; want 3..=25
2026-07-17T03:24:37.9928914Z   [must] requirement_quality REQ-PRESENCE-CONTROL-REAP-ON-EXIT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9929590Z   [must] requirement_quality REQ-PRESENCE-CONTROL-REAP-ON-EXIT criterion=length — title is 139 words; want 3..=25
2026-07-17T03:24:37.9930129Z   [must] requirement_quality REQ-PRESENCE-LIVENESS-TRUTH criterion=length — title is 215 words; want 3..=25
2026-07-17T03:24:37.9930778Z   [must] requirement_quality REQ-PROJECT-INDEX-INVALIDATION criterion=length — title is 124 words; want 3..=25
2026-07-17T03:24:37.9931449Z   [must] requirement_quality REQ-PROJECT-INDEX-READER-CUTOVER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9932021Z   [must] requirement_quality REQ-PROJECT-INDEX-READER-CUTOVER criterion=length — title is 143 words; want 3..=25
2026-07-17T03:24:37.9932530Z   [must] requirement_quality REQ-PROJECT-INDEX-STORE criterion=length — title is 90 words; want 3..=25
2026-07-17T03:24:37.9933056Z   [must] requirement_quality REQ-PROJECT-INDEX-WRITER criterion=length — title is 151 words; want 3..=25
2026-07-17T03:24:37.9933739Z   [must] requirement_quality REQ-PSYCHE-CONTEXT-FILE-INDIRECTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9934311Z   [must] requirement_quality REQ-PSYCHE-CONTEXT-FILE-INDIRECTION criterion=length — title is 206 words; want 3..=25
2026-07-17T03:24:37.9935027Z   [must] requirement_quality REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9935664Z   [must] requirement_quality REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN criterion=length — title is 90 words; want 3..=25
2026-07-17T03:24:37.9936308Z   [must] requirement_quality REQ-PSYCHE-EPHEMERAL-DRIVER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9936845Z   [must] requirement_quality REQ-PSYCHE-EPHEMERAL-DRIVER criterion=length — title is 146 words; want 3..=25
2026-07-17T03:24:37.9937507Z   [must] requirement_quality REQ-PSYCHE-LEGACY-RESIDENT-SWEEP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9938061Z   [must] requirement_quality REQ-PSYCHE-LEGACY-RESIDENT-SWEEP criterion=length — title is 282 words; want 3..=25
2026-07-17T03:24:37.9938837Z   [must] requirement_quality REQ-PSYCHE-NESTED-RESOLUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9939516Z   [must] requirement_quality REQ-PSYCHE-NESTED-RESOLUTION criterion=length — title is 147 words; want 3..=25
2026-07-17T03:24:37.9940064Z   [must] requirement_quality REQ-PSYCHE-ROLE-OPTIONAL-SKIP criterion=length — title is 59 words; want 3..=25
2026-07-17T03:24:37.9940689Z   [must] requirement_quality REQ-PSYCHE-SID-CUSTODY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9941199Z   [must] requirement_quality REQ-PSYCHE-SID-CUSTODY criterion=length — title is 134 words; want 3..=25
2026-07-17T03:24:37.9941841Z   [must] requirement_quality REQ-PSYCHE-SPAWN-ENV-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9942381Z   [must] requirement_quality REQ-PSYCHE-SPAWN-ENV-PARITY criterion=length — title is 167 words; want 3..=25
2026-07-17T03:24:37.9943096Z   [must] requirement_quality REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9943735Z   [must] requirement_quality REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS criterion=length — title is 59 words; want 3..=25
2026-07-17T03:24:37.9944380Z   [must] requirement_quality REQ-PUBLIC-ERROR-SURFACES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9944900Z   [must] requirement_quality REQ-PUBLIC-ERROR-SURFACES criterion=length — title is 217 words; want 3..=25
2026-07-17T03:24:37.9945534Z   [must] requirement_quality REQ-PUMP-DIAL-FASTFAIL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9946069Z   [must] requirement_quality REQ-PUMP-DIAL-FASTFAIL criterion=length — title is 324 words; want 3..=25
2026-07-17T03:24:37.9946708Z   [must] requirement_quality REQ-PUMP-PEER-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9947323Z   [must] requirement_quality REQ-PUMP-PEER-ISOLATION criterion=length — title is 199 words; want 3..=25
2026-07-17T03:24:37.9947967Z   [must] requirement_quality REQ-PUMP-STAGE-TRUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9948482Z   [must] requirement_quality REQ-PUMP-STAGE-TRUTH criterion=length — title is 168 words; want 3..=25
2026-07-17T03:24:37.9948931Z   [must] requirement_quality REQ-RC-1 criterion=length — title is 94 words; want 3..=25
2026-07-17T03:24:37.9949673Z   [must] requirement_quality REQ-RC-CROSS-NODE-ATTACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9950185Z   [must] requirement_quality REQ-RC-CROSS-NODE-ATTACH criterion=length — title is 95 words; want 3..=25
2026-07-17T03:24:37.9950786Z   [must] requirement_quality REQ-RC-IDENTITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9951311Z   [must] requirement_quality REQ-RC-IDENTITY criterion=length — title is 122 words; want 3..=25
2026-07-17T03:24:37.9951945Z   [must] requirement_quality REQ-RC-IDMARKER-DISABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9952473Z   [must] requirement_quality REQ-RC-IDMARKER-DISABLE criterion=length — title is 73 words; want 3..=25
2026-07-17T03:24:37.9953108Z   [must] requirement_quality REQ-RC-KEY-VT-TRANSLATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9953627Z   [must] requirement_quality REQ-RC-KEY-VT-TRANSLATE criterion=length — title is 249 words; want 3..=25
2026-07-17T03:24:37.9954237Z   [must] requirement_quality REQ-RC-MOUSE-FORWARD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9954756Z   [must] requirement_quality REQ-RC-MOUSE-FORWARD criterion=length — title is 218 words; want 3..=25
2026-07-17T03:24:37.9955512Z   [must] requirement_quality REQ-RC-RECONNECT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9956009Z   [must] requirement_quality REQ-RC-RECONNECT criterion=length — title is 244 words; want 3..=25
2026-07-17T03:24:37.9956634Z   [must] requirement_quality REQ-RC-RECONNECT-TRUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9957143Z   [must] requirement_quality REQ-RC-RECONNECT-TRUTH criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9957741Z   [must] requirement_quality REQ-RC-WIN-PASTE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9958227Z   [must] requirement_quality REQ-RC-WIN-PASTE criterion=length — title is 226 words; want 3..=25
2026-07-17T03:24:37.9958851Z   [must] requirement_quality REQ-RC-WIN-VT-OUTPUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9959511Z   [must] requirement_quality REQ-RC-WIN-VT-OUTPUT criterion=length — title is 150 words; want 3..=25
2026-07-17T03:24:37.9960099Z   [must] requirement_quality REQ-RCVIEW-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9960636Z   [must] requirement_quality REQ-RCVIEW-1 criterion=length — title is 197 words; want 3..=25
2026-07-17T03:24:37.9961266Z   [must] requirement_quality REQ-READY-AGENT-RESUME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9961777Z   [must] requirement_quality REQ-READY-AGENT-RESUME criterion=length — title is 165 words; want 3..=25
2026-07-17T03:24:37.9962334Z   [must] requirement_quality REQ-REDISPATCH-FINISHED-RETIRE criterion=length — title is 125 words; want 3..=25
2026-07-17T03:24:37.9962905Z   [must] requirement_quality REQ-REL-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9963449Z   [must] requirement_quality REQ-REL-1 criterion=length — title is 61 words; want 3..=25
2026-07-17T03:24:37.9963978Z   [must] requirement_quality REQ-RELAY-NO-BUSY-DELIVER criterion=length — title is 159 words; want 3..=25
2026-07-17T03:24:37.9964521Z   [must] requirement_quality REQ-RELEASE-CHANNEL-PRIVATE criterion=length — title is 97 words; want 3..=25
2026-07-17T03:24:37.9965041Z   [must] requirement_quality REQ-RELEASE-MUSL-ARTIFACT criterion=length — title is 114 words; want 3..=25
2026-07-17T03:24:37.9965668Z   [must] requirement_quality REQ-REST-VERB-ROUTING criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9966181Z   [must] requirement_quality REQ-REST-VERB-ROUTING criterion=length — title is 326 words; want 3..=25
2026-07-17T03:24:37.9966854Z   [must] requirement_quality REQ-RESUME-ADAPTER-FOLLOWS-SESSION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9967450Z   [must] requirement_quality REQ-RESUME-ADAPTER-FOLLOWS-SESSION criterion=length — title is 275 words; want 3..=25
2026-07-17T03:24:37.9968126Z   [must] requirement_quality REQ-RESUME-CONTEXT-PULL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9968654Z   [must] requirement_quality REQ-RESUME-CONTEXT-PULL criterion=length — title is 460 words; want 3..=25
2026-07-17T03:24:37.9969330Z   [must] requirement_quality REQ-RESUME-HARNESS-SESSION-ID criterion=length — title is 128 words; want 3..=25
2026-07-17T03:24:37.9969874Z   [must] requirement_quality REQ-RESUME-REAP-PRIOR-HARNESS criterion=length — title is 54 words; want 3..=25
2026-07-17T03:24:37.9970400Z   [must] requirement_quality REQ-RESUME-ROW-PER-PROJECT criterion=length — title is 59 words; want 3..=25
2026-07-17T03:24:37.9970896Z   [must] requirement_quality REQ-RUN-EMPTY-CREATE criterion=length — title is 63 words; want 3..=25
2026-07-17T03:24:37.9971664Z   [must] requirement_quality REQ-RUN-ID-REUSES-ADAPTER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9972202Z   [must] requirement_quality REQ-RUN-ID-REUSES-ADAPTER criterion=length — title is 174 words; want 3..=25
2026-07-17T03:24:37.9972855Z   [must] requirement_quality REQ-RUN-MULTISUBNET-HOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9973381Z   [must] requirement_quality REQ-RUN-MULTISUBNET-HOME criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9974009Z   [must] requirement_quality REQ-RUN-NO-DUP-SESSION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9974524Z   [must] requirement_quality REQ-RUN-NO-DUP-SESSION criterion=length — title is 137 words; want 3..=25
2026-07-17T03:24:37.9975105Z   [must] requirement_quality REQ-RUN-PICKER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9975611Z   [must] requirement_quality REQ-RUN-PICKER criterion=length — title is 203 words; want 3..=25
2026-07-17T03:24:37.9976237Z   [must] requirement_quality REQ-RUN-PICKER-HOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9976805Z   [must] requirement_quality REQ-RUN-PICKER-HOME criterion=length — title is 156 words; want 3..=25
2026-07-17T03:24:37.9977405Z   [must] requirement_quality REQ-RUN-SHORTCUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9977900Z   [must] requirement_quality REQ-RUN-SHORTCUT criterion=length — title is 226 words; want 3..=25
2026-07-17T03:24:37.9978374Z   [must] requirement_quality REQ-SEAM-SPAWN criterion=length — title is 2 word(s); want 3..=25
2026-07-17T03:24:37.9979147Z   [must] requirement_quality REQ-SELF-DETECT-PARENT-PID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9979715Z   [must] requirement_quality REQ-SELF-DETECT-PARENT-PID criterion=length — title is 224 words; want 3..=25
2026-07-17T03:24:37.9980477Z   [must] requirement_quality REQ-SELF-ID-TRUST-INJECTED-ENV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9981045Z   [must] requirement_quality REQ-SELF-ID-TRUST-INJECTED-ENV criterion=length — title is 232 words; want 3..=25
2026-07-17T03:24:37.9981676Z   [must] requirement_quality REQ-SEND-REPLYTO-REMOVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9982190Z   [must] requirement_quality REQ-SEND-REPLYTO-REMOVE criterion=length — title is 60 words; want 3..=25
2026-07-17T03:24:37.9982800Z   [must] requirement_quality REQ-SEND-SPT-HOSTED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9983306Z   [must] requirement_quality REQ-SEND-SPT-HOSTED criterion=length — title is 169 words; want 3..=25
2026-07-17T03:24:37.9983955Z   [must] requirement_quality REQ-SEND-STAMP-AGENT-ID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9984488Z   [must] requirement_quality REQ-SEND-STAMP-AGENT-ID criterion=length — title is 189 words; want 3..=25
2026-07-17T03:24:37.9985146Z   [must] requirement_quality REQ-SEND-WINDOW-DRAIN-HONOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9985679Z   [must] requirement_quality REQ-SEND-WINDOW-DRAIN-HONOR criterion=length — title is 278 words; want 3..=25
2026-07-17T03:24:37.9986227Z   [must] requirement_quality REQ-SERVE-OWNERSHIP-GENERATION criterion=length — title is 131 words; want 3..=25
2026-07-17T03:24:37.9987136Z   [must] requirement_quality REQ-SESSION-ADAPTER-RECORDED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9987941Z   [must] requirement_quality REQ-SESSION-ADAPTER-RECORDED criterion=length — title is 205 words; want 3..=25
2026-07-17T03:24:37.9989180Z   [must] requirement_quality REQ-SESSION-RESUME-TEMPLATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9989844Z   [must] requirement_quality REQ-SESSION-RESUME-TEMPLATE criterion=length — title is 287 words; want 3..=25
2026-07-17T03:24:37.9990566Z   [must] requirement_quality REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9991157Z   [must] requirement_quality REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:37.9991624Z   [must] requirement_quality REQ-SHELL-1 criterion=length — title is 36 words; want 3..=25
2026-07-17T03:24:37.9992087Z   [must] requirement_quality REQ-SHELL-2 criterion=length — title is 49 words; want 3..=25
2026-07-17T03:24:37.9992561Z   [must] requirement_quality REQ-SHELL-3 criterion=length — title is 80 words; want 3..=25
2026-07-17T03:24:37.9993175Z   [must] requirement_quality REQ-SHELL-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9993652Z   [must] requirement_quality REQ-SHELL-4 criterion=length — title is 84 words; want 3..=25
2026-07-17T03:24:37.9994195Z   [must] requirement_quality REQ-SHELL-5 criterion=length — title is 49 words; want 3..=25
2026-07-17T03:24:37.9994900Z   [must] requirement_quality REQ-SOFT-END-PRESERVES-LIVE-LISTENER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9995477Z   [must] requirement_quality REQ-SOFT-END-PRESERVES-LIVE-LISTENER criterion=length — title is 246 words; want 3..=25
2026-07-17T03:24:37.9996159Z   [must] requirement_quality REQ-SPAWN-COLLISION-GUARD-LIVE-DUP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9996727Z   [must] requirement_quality REQ-SPAWN-COLLISION-GUARD-LIVE-DUP criterion=length — title is 123 words; want 3..=25
2026-07-17T03:24:37.9997247Z   [must] requirement_quality REQ-SPOOL-TAKE-AUDIT criterion=length — title is 50 words; want 3..=25
2026-07-17T03:24:37.9997973Z   [must] requirement_quality REQ-START-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:37.9998467Z   [must] requirement_quality REQ-START-5 criterion=length — title is 129 words; want 3..=25
2026-07-17T03:24:37.9998927Z   [must] requirement_quality REQ-STORE-1 criterion=length — title is 34 words; want 3..=25
2026-07-17T03:24:37.9999613Z   [must] requirement_quality REQ-STORE-CONTEXT-BRANCH-FILL criterion=length — title is 73 words; want 3..=25
2026-07-17T03:24:38.0000253Z   [must] requirement_quality REQ-STREAM-OPENER-DURABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0000782Z   [must] requirement_quality REQ-STREAM-OPENER-DURABLE criterion=length — title is 155 words; want 3..=25
2026-07-17T03:24:38.0001470Z   [must] requirement_quality REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0002070Z   [must] requirement_quality REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE criterion=length — title is 192 words; want 3..=25
2026-07-17T03:24:38.0002552Z   [must] requirement_quality REQ-SUBNET-5 criterion=length — title is 52 words; want 3..=25
2026-07-17T03:24:38.0003139Z   [must] requirement_quality REQ-SUBNET-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0003596Z   [must] requirement_quality REQ-SUBNET-6 criterion=length — title is 38 words; want 3..=25
2026-07-17T03:24:38.0004183Z   [must] requirement_quality REQ-SUBNET-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0004647Z   [must] requirement_quality REQ-SUBNET-7 criterion=length — title is 75 words; want 3..=25
2026-07-17T03:24:38.0005107Z   [must] requirement_quality REQ-SUBNET-8 criterion=length — title is 53 words; want 3..=25
2026-07-17T03:24:38.0005779Z   [must] requirement_quality REQ-SUBNET-COUNT-ROUTABLE criterion=length — title is 78 words; want 3..=25
2026-07-17T03:24:38.0006428Z   [must] requirement_quality REQ-SUBNET-DISPLAY-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0006968Z   [must] requirement_quality REQ-SUBNET-DISPLAY-PARITY criterion=length — title is 166 words; want 3..=25
2026-07-17T03:24:38.0007547Z   [must] requirement_quality REQ-TERM-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0008013Z   [must] requirement_quality REQ-TERM-5 criterion=length — title is 71 words; want 3..=25
2026-07-17T03:24:38.0008585Z   [must] requirement_quality REQ-TERM-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0009129Z   [must] requirement_quality REQ-TERM-6 criterion=length — title is 53 words; want 3..=25
2026-07-17T03:24:38.0009730Z   [must] requirement_quality REQ-TERM-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0010201Z   [must] requirement_quality REQ-TERM-7 criterion=length — title is 55 words; want 3..=25
2026-07-17T03:24:38.0010946Z   [must] requirement_quality REQ-TRANSLATE-BINARY-LIVENESS-DECAY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0011519Z   [must] requirement_quality REQ-TRANSLATE-BINARY-LIVENESS-DECAY criterion=length — title is 94 words; want 3..=25
2026-07-17T03:24:38.0012138Z   [must] requirement_quality REQ-TRANSLATE-COMMAND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0012655Z   [must] requirement_quality REQ-TRANSLATE-COMMAND criterion=length — title is 137 words; want 3..=25
2026-07-17T03:24:38.0013337Z   [must] requirement_quality REQ-TRANSLATE-COMMIT-MISS-TOLERANCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0014009Z   [must] requirement_quality REQ-TRANSLATE-COMMIT-MISS-TOLERANCE criterion=length — title is 131 words; want 3..=25
2026-07-17T03:24:38.0014592Z   [must] requirement_quality REQ-UPD-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0015053Z   [must] requirement_quality REQ-UPD-6 criterion=length — title is 32 words; want 3..=25
2026-07-17T03:24:38.0015630Z   [must] requirement_quality REQ-UPD-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0016077Z   [must] requirement_quality REQ-UPD-7 criterion=length — title is 88 words; want 3..=25
2026-07-17T03:24:38.0016650Z   [must] requirement_quality REQ-UPD-8 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0017103Z   [must] requirement_quality REQ-UPD-8 criterion=length — title is 115 words; want 3..=25
2026-07-17T03:24:38.0017584Z   [must] requirement_quality REQ-UPD-9 criterion=length — title is 110 words; want 3..=25
2026-07-17T03:24:38.0018117Z   [must] requirement_quality REQ-UPDATE-ADAPTERS-VERB criterion=length — title is 113 words; want 3..=25
2026-07-17T03:24:38.0018802Z   [must] requirement_quality REQ-UPDATE-APPLY-ALREADY-APPLIED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0019455Z   [must] requirement_quality REQ-UPDATE-APPLY-ALREADY-APPLIED criterion=length — title is 120 words; want 3..=25
2026-07-17T03:24:38.0020123Z   [must] requirement_quality REQ-UPDATE-APPLY-RESTART-NOTICE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0020677Z   [must] requirement_quality REQ-UPDATE-APPLY-RESTART-NOTICE criterion=length — title is 81 words; want 3..=25
2026-07-17T03:24:38.0021321Z   [must] requirement_quality REQ-UPDATE-DEFAULT-COMPOSITE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0021998Z   [must] requirement_quality REQ-UPDATE-DEFAULT-COMPOSITE criterion=length — title is 135 words; want 3..=25
2026-07-17T03:24:38.0022547Z   [must] requirement_quality REQ-UPDATE-FETCH-APPLY-FLAG criterion=length — title is 123 words; want 3..=25
2026-07-17T03:24:38.0023205Z   [must] requirement_quality REQ-UPDATE-FETCH-CURRENT-UX criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0023739Z   [must] requirement_quality REQ-UPDATE-FETCH-CURRENT-UX criterion=length — title is 134 words; want 3..=25
2026-07-17T03:24:38.0024392Z   [must] requirement_quality REQ-UPDATE-FINISH-COMMUNE-FLUSH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0024956Z   [must] requirement_quality REQ-UPDATE-FINISH-COMMUNE-FLUSH criterion=length — title is 215 words; want 3..=25
2026-07-17T03:24:38.0025542Z   [must] requirement_quality REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL criterion=length — title is 74 words; want 3..=25
2026-07-17T03:24:38.0026199Z   [must] requirement_quality REQ-UPDATE-GH-TRANSPORT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0026724Z   [must] requirement_quality REQ-UPDATE-GH-TRANSPORT criterion=length — title is 169 words; want 3..=25
2026-07-17T03:24:38.0027439Z   [must] requirement_quality REQ-UPDATE-ONE-SHOT-FINISH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0027964Z   [must] requirement_quality REQ-UPDATE-ONE-SHOT-FINISH criterion=length — title is 94 words; want 3..=25
2026-07-17T03:24:38.0028606Z   [must] requirement_quality REQ-UPDATE-PROMOTE-DRAINED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0029213Z   [must] requirement_quality REQ-UPDATE-PROMOTE-DRAINED criterion=length — title is 167 words; want 3..=25
2026-07-17T03:24:38.0029867Z   [must] requirement_quality REQ-UPDATE-RESTART-SAFE-SWAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0030501Z   [must] requirement_quality REQ-UPDATE-RESTART-SAFE-SWAP criterion=length — title is 158 words; want 3..=25
2026-07-17T03:24:38.0031179Z   [must] requirement_quality REQ-UPDATE-RUNNING-IMAGE-SURFACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0031737Z   [must] requirement_quality REQ-UPDATE-RUNNING-IMAGE-SURFACE criterion=length — title is 166 words; want 3..=25
2026-07-17T03:24:38.0032390Z   [must] requirement_quality REQ-UPDATE-TRIAL-DRAIN-DRIVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0032925Z   [must] requirement_quality REQ-UPDATE-TRIAL-DRAIN-DRIVE criterion=length — title is 464 words; want 3..=25
2026-07-17T03:24:38.0033592Z   [must] requirement_quality REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0034173Z   [must] requirement_quality REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT criterion=length — title is 227 words; want 3..=25
2026-07-17T03:24:38.0034700Z   [must] requirement_quality REQ-WAKE-RESUME-LEG criterion=length — title is 274 words; want 3..=25
2026-07-17T03:24:38.0035192Z   [must] requirement_quality REQ-WAKE-WAIT criterion=length — title is 89 words; want 3..=25
2026-07-17T03:24:38.0035821Z   [must] requirement_quality REQ-WAN-SEND-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0036337Z   [must] requirement_quality REQ-WAN-SEND-DELIVERY criterion=length — title is 117 words; want 3..=25
2026-07-17T03:24:38.0036873Z   [must] requirement_quality REQ-WAN-SPT-HOSTED-DELIVERY criterion=length — title is 156 words; want 3..=25
2026-07-17T03:24:38.0037464Z   [must] requirement_quality REQ-WHOAMI-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0037938Z   [must] requirement_quality REQ-WHOAMI-1 criterion=length — title is 101 words; want 3..=25
2026-07-17T03:24:38.0038738Z   [must] requirement_quality REQ-WHOAMI-IDENTITY-ONLY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0039364Z   [must] requirement_quality REQ-WHOAMI-IDENTITY-ONLY criterion=length — title is 125 words; want 3..=25
2026-07-17T03:24:38.0040012Z   [must] requirement_quality REQ-WORKER-LIST-VISIBILITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0040537Z   [must] requirement_quality REQ-WORKER-LIST-VISIBILITY criterion=length — title is 82 words; want 3..=25
2026-07-17T03:24:38.0041172Z   [must] requirement_quality REQ-WORKER-MINTED-NAME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0041681Z   [must] requirement_quality REQ-WORKER-MINTED-NAME criterion=length — title is 67 words; want 3..=25
2026-07-17T03:24:38.0042222Z   [must] requirement_quality REQ-WORKER-PICKER-EXCLUDED criterion=length — title is 61 words; want 3..=25
2026-07-17T03:24:38.0042856Z   [must] requirement_quality REQ-WORKER-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0043409Z   [must] requirement_quality REQ-WORKER-REAP criterion=length — title is 116 words; want 3..=25
2026-07-17T03:24:38.0044053Z   [must] requirement_quality REQ-WORKER-SID-SYMMETRIC-AUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-17T03:24:38.0044599Z   [must] requirement_quality REQ-WORKER-SID-SYMMETRIC-AUTH criterion=length — title is 125 words; want 3..=25
2026-07-17T03:24:38.0045151Z   [must] requirement_quality REQ-XTASK-SPT-BIN-TARGET-DIR criterion=length — title is 98 words; want 3..=25
2026-07-17T03:24:38.0045193Z 
2026-07-17T03:24:38.0045475Z # Requirement quality review
2026-07-17T03:24:38.0045508Z 
2026-07-17T03:24:38.0045910Z You are reviewing 510 requirement(s) from `traceable-reqs.toml` against a quality
2026-07-17T03:24:38.0046339Z rubric. Deterministic checks (length, contains-and, tbd-todo, duplicate-titles,
2026-07-17T03:24:38.0046800Z trailing-etc) have already run and surfaced as `requirement_quality` findings on
2026-07-17T03:24:38.0047145Z this command's output. Your task is the rubric items below.
2026-07-17T03:24:38.0047179Z 
2026-07-17T03:24:38.0047429Z ## Rubric
2026-07-17T03:24:38.0047466Z 
2026-07-17T03:24:38.0047920Z - **singular** — describes one capability; no smuggled "and"/"or" across distinct actions.
2026-07-17T03:24:38.0048353Z - **verifiable** — states an observable behavior a test or reviewer could confirm.
2026-07-17T03:24:38.0048764Z - **atomic** — cannot be split into two requirements without losing meaning.
2026-07-17T03:24:38.0049189Z - **active-voice** — clear subject and active verb.
2026-07-17T03:24:38.0049217Z 
2026-07-17T03:24:38.0049674Z If a criterion is borderline or doesn't apply, abstain — only emit findings for
2026-07-17T03:24:38.0049934Z clear concerns.
2026-07-17T03:24:38.0049982Z 
2026-07-17T03:24:38.0050234Z ## Requirements
2026-07-17T03:24:38.0050277Z 
2026-07-17T03:24:38.0050530Z ### REQ-ARCH-1
2026-07-17T03:24:38.0050830Z - Title: Many small acyclically-layered crates
2026-07-17T03:24:38.0051107Z - Required stages: impl
2026-07-17T03:24:38.0051140Z 
2026-07-17T03:24:38.0051399Z ### REQ-ARCH-2
2026-07-17T03:24:38.0051737Z - Title: Public SDK surface is spt-proto, spt-runtime, spt-msg
2026-07-17T03:24:38.0052009Z - Required stages: impl
2026-07-17T03:24:38.0052043Z 
2026-07-17T03:24:38.0052286Z ### REQ-ARCH-3
2026-07-17T03:24:38.0052679Z - Title: Wire-protocol version independent of crate semver, N-1 compat window
2026-07-17T03:24:38.0052948Z - Required stages: impl, unit
2026-07-17T03:24:38.0052982Z 
2026-07-17T03:24:38.0053234Z ### REQ-ARCH-4
2026-07-17T03:24:38.0053588Z - Title: Copy-verbatim the commodity layer from the sister project
2026-07-17T03:24:38.0053859Z - Required stages: impl, unit
2026-07-17T03:24:38.0053893Z 
2026-07-17T03:24:38.0054252Z ### REQ-DAEMON-1
2026-07-17T03:24:38.0054595Z - Title: One per-machine spt-daemon owning all per-machine state
2026-07-17T03:24:38.0054876Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0054914Z 
2026-07-17T03:24:38.0055179Z ### REQ-DAEMON-2
2026-07-17T03:24:38.0055496Z - Title: Broker/brain split for seamless self-update
2026-07-17T03:24:38.0055767Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0055801Z 
2026-07-17T03:24:38.0056045Z ### REQ-DAEMON-3
2026-07-17T03:24:38.0056373Z - Title: Any api invocation auto-starts the daemon if absent
2026-07-17T03:24:38.0056660Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0056693Z 
2026-07-17T03:24:38.0056941Z ### REQ-DAEMON-4
2026-07-17T03:24:38.0057237Z - Title: Honor every KNOWN-HAZARDS invariant
2026-07-17T03:24:38.0057514Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0057547Z 
2026-07-17T03:24:38.0057800Z ### REQ-STORE-1
2026-07-17T03:24:38.0059110Z - Title: spt-store::BranchStore (git branch as versioned KV; commit=checkpoint/tip=resume, atomic multi-key, merge-native sync) is the substrate for coarse/durable/audited state (context, registry snapshot+distribution, daemon checkpoint); hot paths (B5 fsync journal) + indexed queries (SQLite spool) excluded (ADR-0011)
2026-07-17T03:24:38.0059463Z - Required stages: impl, unit
2026-07-17T03:24:38.0059495Z 
2026-07-17T03:24:38.0059759Z ### REQ-MANIFEST-1
2026-07-17T03:24:38.0060125Z - Title: Per-adapter manifest with adapter_name and min_spt_core_version
2026-07-17T03:24:38.0060410Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0060442Z 
2026-07-17T03:24:38.0060695Z ### REQ-MANIFEST-2
2026-07-17T03:24:38.0061410Z - Title: Adapter profiles — sparse leaf-replace overlays (shipped + local), composite <adapter>:<profile> addressing, shadow-refusal, tighten-only consent floors
2026-07-17T03:24:38.0061691Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0061724Z 
2026-07-17T03:24:38.0061983Z ### REQ-MANIFEST-3
2026-07-17T03:24:38.0062836Z - Title: Adapter strings — [strings] KV tree, dot-path get-string resolving through the profile leaf-replace overlay, set-string editing a local profile's [strings] only; data-only (nothing executes a string)
2026-07-17T03:24:38.0063201Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0063249Z 
2026-07-17T03:24:38.0063509Z ### REQ-MANIFEST-4
2026-07-17T03:24:38.0064448Z - Title: Keyword hints — [[hints]] {keywords (literal/regex), text}; spt api hint --session emits at most one matched hint per message, once per session (seen-set), declaration-order first match; profiles overlay [[hints]] by leaf-replace
2026-07-17T03:24:38.0064734Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0064773Z 
2026-07-17T03:24:38.0065025Z ### REQ-MANIFEST-5
2026-07-17T03:24:38.0068563Z - Title: File-backed adapter [strings] (M12-W3-T3.1): a [strings] dot-path value MAY be an inline-table FILE POINTER `key = { file = "rel/path" }` resolved to the file's contents at get-string time, keeping large bodies (skill-instructions, hint text) out of the manifest. A value-position table with a `file` key IS the pointer form (reserved — cannot double as data). Per-adapter aux storage `adapters/<adapter>/strings/`; pointers resolve relative to it with CONTAINMENT (reject `..`/absolute escaping the dir). UPDATE-SAFETY: a LOCAL profile's file-pointers resolve relative to the user-owned local-profile dir (NOT adapter-shipped strings/, which adapter updates overwrite), or the local profile inlines. Validate-at-register (fail-fast on a bad/escaping/missing pointer) + LAZY read at get-string (live file edits reflect, no re-register) + skip-diagnostics on missing-at-read (no hard-crash, mirrors [digest]). Rides the same leaf-replace profile overlay as the rest of [strings].
2026-07-17T03:24:38.0068912Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0069032Z 
2026-07-17T03:24:38.0069285Z ### REQ-MANIFEST-6
2026-07-17T03:24:38.0071932Z - Title: Cross-adapter fallback target addressing (M12-W3-T3.2): a cross-adapter fallback target is addressed as `<adapter>:<profile>` (not just a bare adapter_name), resolved through the one composite-addressing resolver (registry::resolve_option) at every adapter-option read site so a fallback may select a shipped/local profile (e.g. a `ccs` profile). CONTEXT.md §cross-adapter-fallback reconciled ("ccs is a profile; cross-adapter fallback may target <adapter>:<profile>"). Contract-only this milestone: the node-wide fallback SETTING + its rate-limit invocation are deferred to the consuming milestone (the runtime path does not exist yet); this REQ guarantees the ADDRESSING resolves.
2026-07-17T03:24:38.0072365Z - Required stages: doc, unit
2026-07-17T03:24:38.0072398Z 
2026-07-17T03:24:38.0072652Z ### REQ-MANIFEST-7
2026-07-17T03:24:38.0076275Z - Title: Adapter-declared shortcut basename (M12-W2 follow-on): an optional `[adapter] shortcut_basename` manifest field names the basename the `spt endpoint run` picker bakes into the generated `<basename>-<id>` launcher shortcut (REQ-RUN-SHORTCUT). Absent ⇒ the harness-agnostic default `spt` (→ `spt-<id>`); an adapter sets it to brand its shortcuts (claude-spt → `cc` → `cc-<id>`), so the Claude-Code-ness lives in the PUBLISHED adapter manifest, never hardcoded in spt-core. The picker reads it from the RESOLVED manifest of the selected adapter (registry::resolve_option), falling back to `spt` when absent/empty/unresolvable. Additive + N-1-safe (serde-default Option, omitted from serialization when absent; old manifests parse clean); manifest.schema.json regenerated from the derive (ADR-0001, CI drift-gated). Documented in docs/MANIFEST.md `[adapter]` section + the claude-spt worked example — the adapter-author contract perri builds spt-claude-code against.
2026-07-17T03:24:38.0076693Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0076727Z 
2026-07-17T03:24:38.0076985Z ### REQ-MANIFEST-8
2026-07-17T03:24:38.0079700Z - Title: [adapter] host_binaries declares the harness executable basenames a kind="harness" adapter hosts agents inside (e.g. host_binaries = ["claude"]); bind-time pid→exe-basename match (case-insensitive, .exe-stripped) over the seed's parent_pid selects the candidate adapter set; zero matches → a friendly error naming the binary + the --adapter escape hatch. Additive + N-1-safe: optional Vec<String>, #[serde(default, skip_serializing_if = "Vec::is_empty")] (omitted-serialized like shortcut_basename, old manifests parse clean); manifest.schema.json regenerated from the derive (ADR-0001, CI drift-gated). The match-key for ADR-0021 adapter-agnostic bind-time resolution. (v0.9.0)
2026-07-17T03:24:38.0080116Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0080149Z 
2026-07-17T03:24:38.0080401Z ### REQ-SEAM-SPAWN
2026-07-17T03:24:38.0080678Z - Title: spawn-session seam
2026-07-17T03:24:38.0080954Z - Required stages: impl, unit
2026-07-17T03:24:38.0080988Z 
2026-07-17T03:24:38.0081260Z ### REQ-SEAM-POSTSPAWN
2026-07-17T03:24:38.0081572Z - Title: post-spawn / api bind seam with boot nonce
2026-07-17T03:24:38.0081844Z - Required stages: impl, unit
2026-07-17T03:24:38.0081878Z 
2026-07-17T03:24:38.0082154Z ### REQ-SEAM-PSYCHE
2026-07-17T03:24:38.0082487Z - Title: spawn-psyche seam (fresh + resume templates)
2026-07-17T03:24:38.0082764Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0082792Z 
2026-07-17T03:24:38.0083055Z ### REQ-SEAM-HISTORY
2026-07-17T03:24:38.0083418Z - Title: History subsystem (fetcher / locate-normalize / native store)
2026-07-17T03:24:38.0083694Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0083727Z 
2026-07-17T03:24:38.0083985Z ### REQ-SEAM-ACTIVITY
2026-07-17T03:24:38.0084364Z - Title: Activity/idle reported via api sentinels, not PTY quiescence
2026-07-17T03:24:38.0084634Z - Required stages: impl, unit
2026-07-17T03:24:38.0084677Z 
2026-07-17T03:24:38.0084924Z ### REQ-SEAM-INJECT
2026-07-17T03:24:38.0085269Z - Title: inject-input methods configurable per activity-state
2026-07-17T03:24:38.0085545Z - Required stages: impl, unit
2026-07-17T03:24:38.0085578Z 
2026-07-17T03:24:38.0085840Z ### REQ-SEAM-RESUME
2026-07-17T03:24:38.0086208Z - Title: resume-session seam (fresh-with-preload / continue-existing)
2026-07-17T03:24:38.0086581Z - Required stages: 
2026-07-17T03:24:38.0086614Z 
2026-07-17T03:24:38.0086874Z ### REQ-SEAM-CAPABILITY
2026-07-17T03:24:38.0087205Z - Title: Hostable endpoint-types capability declaration
2026-07-17T03:24:38.0087477Z - Required stages: impl, unit
2026-07-17T03:24:38.0087511Z 
2026-07-17T03:24:38.0087772Z ### REQ-SEAM-UPDATE
2026-07-17T03:24:38.0088106Z - Title: Adapter-update avenue (file-pull / delegated command)
2026-07-17T03:24:38.0088378Z - Required stages: impl, unit
2026-07-17T03:24:38.0088412Z 
2026-07-17T03:24:38.0088660Z ### REQ-API-1
2026-07-17T03:24:38.0089128Z - Title: api prefix and adapter_name on every machinery invocation
2026-07-17T03:24:38.0089410Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0089443Z 
2026-07-17T03:24:38.0089697Z ### REQ-API-2
2026-07-17T03:24:38.0090089Z - Title: The api subcommand surface (bind/listen/poll/state/worker/boundary/...)
2026-07-17T03:24:38.0090376Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0090415Z 
2026-07-17T03:24:38.0090666Z ### REQ-API-3
2026-07-17T03:24:38.0090975Z - Title: commune/signoff are file-drops, not commands
2026-07-17T03:24:38.0091257Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0091344Z 
2026-07-17T03:24:38.0091596Z ### REQ-API-4
2026-07-17T03:24:38.0093509Z - Title: api resolves the adapter manifest (+ profile + install dir) from `--adapter name:profile` via the registry when `--manifest` is omitted; `--manifest` becomes an optional OVERRIDE (unregistered / local-dev manifests). Removes the require-both-flags redundancy — a registered adapter's live bringup / digest / capability needs only `--adapter` — and yields the precise install dir (the record's source_dir) rather than the --manifest parent, closing the copy-mode psyche-binary edge (v0.8.0)
2026-07-17T03:24:38.0093800Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0093833Z 
2026-07-17T03:24:38.0094086Z ### REQ-START-1
2026-07-17T03:24:38.0094463Z - Title: Adapters never resolve SPT_HOME; binary on PATH; api bridging only
2026-07-17T03:24:38.0094819Z - Required stages: impl, unit
2026-07-17T03:24:38.0094858Z 
2026-07-17T03:24:38.0095117Z ### REQ-START-2
2026-07-17T03:24:38.0095427Z - Title: Harness-hosted startup: api seed then listen
2026-07-17T03:24:38.0095718Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0095751Z 
2026-07-17T03:24:38.0096000Z ### REQ-START-3
2026-07-17T03:24:38.0096358Z - Title: spt-hosted startup: spawn-session then api bind (no file)
2026-07-17T03:24:38.0096628Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0096668Z 
2026-07-17T03:24:38.0096916Z ### REQ-START-4
2026-07-17T03:24:38.0097221Z - Title: Adapter-injected env aliases (SPT/OWL/LIVE)
2026-07-17T03:24:38.0097496Z - Required stages: impl, unit
2026-07-17T03:24:38.0097576Z 
2026-07-17T03:24:38.0097819Z ### REQ-START-5
2026-07-17T03:24:38.0101341Z - Title: Adapter-agnostic harness-hosted seed + bind-time adapter/profile resolution (ADR-0021): `api seed` carries only parent_pid + session_id (+ optional cwd), no --adapter — a pure "a harness session exists at this pid" record; --adapter becomes an OPTIONAL override across the whole api group (an explicit name[:profile] for adapter dev, never required). Omitted, listen/poll resolve the owning adapter/profile AT BIND as a pure read against the live registry — never a seed-time snapshot that can drift: seed parent_pid → exe basename → host_binaries candidate set (REQ-MANIFEST-8) → active-profile pointer (REQ-INSTALL-12) primary, else greatest-registered_at_ms candidate base profile (name-asc tie) → friendly zero-match error. Covers BOTH LiveAgent (listen) and ReadyAgent (poll) bringup. Restores legacy parity: `$LIVE start <id>` → `$SPT listen <id>` with no mandatory --adapter, one generic SessionStart hook per harness binary. (v0.9.0)
2026-07-17T03:24:38.0101775Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0101813Z 
2026-07-17T03:24:38.0102060Z ### REQ-EP-1
2026-07-17T03:24:38.0102365Z - Title: Day-one endpoint types; open type system
2026-07-17T03:24:38.0102768Z - Required stages: impl, unit
2026-07-17T03:24:38.0102815Z 
2026-07-17T03:24:38.0103068Z ### REQ-EP-2
2026-07-17T03:24:38.0103411Z - Title: Agent endpoints vs Shells distinction in the type model
2026-07-17T03:24:38.0103697Z - Required stages: impl, unit
2026-07-17T03:24:38.0103731Z 
2026-07-17T03:24:38.0103984Z ### REQ-EP-3
2026-07-17T03:24:38.0104356Z - Title: Messaging payloads carry typed operation commands + file blobs
2026-07-17T03:24:38.0104627Z - Required stages: impl, unit
2026-07-17T03:24:38.0104656Z 
2026-07-17T03:24:38.0104890Z ### REQ-EP-4
2026-07-17T03:24:38.0105219Z - Title: PresenceChannel broker endpoint (seam day-one)
2026-07-17T03:24:38.0105480Z - Required stages: impl, unit
2026-07-17T03:24:38.0105517Z 
2026-07-17T03:24:38.0105797Z ### REQ-EP-5
2026-07-17T03:24:38.0106728Z - Title: Concrete shell instantiation model: spawn-mints-instance (vs relink/online), registered-on-node permission + broadcast-is-discovery, per-shell require_approval gate, max_instances_per_owner + over_cap, instance aliasing, discovery scope
2026-07-17T03:24:38.0107028Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0107066Z 
2026-07-17T03:24:38.0107309Z ### REQ-EP-6
2026-07-17T03:24:38.0109246Z - Title: Gateway type acceptance: a Gateway-typed perch binds (api bind --type, open type system — un-hardcode the live_agent default), advertises/addressable like any endpoint, owns shells (owner validation not agent-family-gated), subscribes to digests, and is the user-msg identity gate's user-backed origin (REQ-MSG-5); in-tree mock-gateway fixture (R-DOCS-2 pattern, no downstream adapter code). Cross-node WAN Gateway-origin (registry endpoint_type trust) tracked by REQ-MSG-6
2026-07-17T03:24:38.0109537Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0109575Z 
2026-07-17T03:24:38.0113467Z ### REQ-EP-7
2026-07-17T03:24:38.0115665Z - Title: Durable live-role.md: a per-agent broad-purpose statement in tracked/agents/<id>/ beside live-context.md (replicates with the mind on the same a-<id> branch); renders FIRST at start-transition context injection (role -> live-context -> project-context); SOLE writer `spt endpoint role --overwrite <file>` — mechanical no-automated-writer guarantee (echo-commune ingest / signoff / Psyche reconcile structurally exclude it). The user-backed-origin hard gate on the writer is a deferred later tightening (rides the user-msg identity plumbing)
2026-07-17T03:24:38.0116105Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0116138Z 
2026-07-17T03:24:38.0116401Z ### REQ-EP-8
2026-07-17T03:24:38.0119973Z - Title: AlwaysOnEndpoint: a resident, addressable, mindless endpoint whose adapter binary the daemon supervises continuously — register-triggered by an adapter-option's `[always-on]` manifest section, one supervised binary per `<adapter>[:profile]`, running independent of agent liveness. It self-manages its `#`-addressed channel endpoints via the existing `api bind` (one connection fronts many). The SECOND class of spt-core-boot-launched third-party binary (after the shell wake-watcher); supervision reuses the wake-watcher scaffolding (backoff / give-up latch / one-per-instance lock / orphan-kill / brain-side reconcile) MINUS the offline-only flip — always online, never resting (no dormant/suspended states). Two-way: agents message it; it may call `endpoint wake <id>`, target-side authorized (REQ-INST-3/6 wake resolution + access whitelist + shell_wake_spawn_anywhere — no caller-ownership gate). First consumer downstream: spt-discord.
2026-07-17T03:24:38.0120307Z - Required stages: 
2026-07-17T03:24:38.0120345Z 
2026-07-17T03:24:38.0120598Z ### REQ-EP-9
2026-07-17T03:24:38.0122594Z - Title: `#` always-on address sigil: a reserved LEADING sigil marking an AlwaysOnEndpoint, extending the REQ-INST-10 grammar to `[subnet:]#id[@node]`. Mandatory + bijective — `#name` ⟺ always-on endpoint, bare `name` ⟺ agent endpoint — so the router resolves endpoint class from the address alone, before any registry lookup. Sits ABOVE REQ-HAZARD-ID-CHARSET: the address parser strips the single leading `#` before id validation, so the bare/stored id stays charset-clean and a mid-id `#` remains rejected (the charset contract is unchanged).
2026-07-17T03:24:38.0123005Z - Required stages: 
2026-07-17T03:24:38.0123048Z 
2026-07-17T03:24:38.0123310Z ### REQ-INST-1
2026-07-17T03:24:38.0123647Z - Title: endpoint ID vs instance split (adapter-agnostic ID)
2026-07-17T03:24:38.0123907Z - Required stages: 
2026-07-17T03:24:38.0123945Z 
2026-07-17T03:24:38.0124188Z ### REQ-INST-2
2026-07-17T03:24:38.0124484Z - Title: Per-node files, synced Psyche mind
2026-07-17T03:24:38.0124756Z - Required stages: impl, unit
2026-07-17T03:24:38.0124790Z 
2026-07-17T03:24:38.0125047Z ### REQ-INST-3
2026-07-17T03:24:38.0125371Z - Title: Dormant (warm) / suspended (cold) resting states
2026-07-17T03:24:38.0125654Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0125686Z 
2026-07-17T03:24:38.0125940Z ### REQ-INST-4
2026-07-17T03:24:38.0126298Z - Title: active to dormant/suspended fires a transition echo commune
2026-07-17T03:24:38.0126581Z - Required stages: impl, unit
2026-07-17T03:24:38.0126619Z 
2026-07-17T03:24:38.0126865Z ### REQ-INST-5
2026-07-17T03:24:38.0127233Z - Title: Two-tier context sync (live to all, project to same-project)
2026-07-17T03:24:38.0127567Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0127599Z 
2026-07-17T03:24:38.0127858Z ### REQ-INST-6
2026-07-17T03:24:38.0128224Z - Title: Deferred messages not delivered to dormant/suspended instances
2026-07-17T03:24:38.0128507Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0128539Z 
2026-07-17T03:24:38.0128788Z ### REQ-INST-7
2026-07-17T03:24:38.0129190Z - Title: Subnet registry + bare-id resolution policy
2026-07-17T03:24:38.0129466Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0129499Z 
2026-07-17T03:24:38.0129751Z ### REQ-INST-8
2026-07-17T03:24:38.0130081Z - Title: Remote-control mode distinct from local operation
2026-07-17T03:24:38.0130367Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0130410Z 
2026-07-17T03:24:38.0130662Z ### REQ-INST-9
2026-07-17T03:24:38.0131087Z - Title: Multi-subnet membership (same-user N subnets; cross-user seam)
2026-07-17T03:24:38.0131364Z - Required stages: impl, unit
2026-07-17T03:24:38.0131416Z 
2026-07-17T03:24:38.0131698Z ### REQ-INST-10
2026-07-17T03:24:38.0132102Z - Title: Qualified addressing [subnet:]id[@node] + ambiguity forces qualification
2026-07-17T03:24:38.0132374Z - Required stages: impl, unit
2026-07-17T03:24:38.0132412Z 
2026-07-17T03:24:38.0132659Z ### REQ-INST-11
2026-07-17T03:24:38.0133055Z - Title: spt rename <id> rippled to all instances (collision-checked, 6.5-reconciled)
2026-07-17T03:24:38.0133332Z - Required stages: impl, unit
2026-07-17T03:24:38.0133370Z 
2026-07-17T03:24:38.0133614Z ### REQ-INST-12
2026-07-17T03:24:38.0134102Z - Title: Endpoint visibility per-(endpoint,subnet): excluded semantics, OR-of-defaults + override, gates sync
2026-07-17T03:24:38.0134373Z - Required stages: impl, unit
2026-07-17T03:24:38.0134429Z 
2026-07-17T03:24:38.0134697Z ### REQ-INST-13
2026-07-17T03:24:38.0135054Z - Title: Subnet-exclusive sync + per-endpoint subnet-membership list
2026-07-17T03:24:38.0135326Z - Required stages: impl, unit
2026-07-17T03:24:38.0135355Z 
2026-07-17T03:24:38.0135607Z ### REQ-INST-14
2026-07-17T03:24:38.0136185Z - Title: Resource advertisement (subnet resource registry): free-text blurb, both-authored, registry projection, visibility/whitelist-gated
2026-07-17T03:24:38.0136467Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0136500Z 
2026-07-17T03:24:38.0136742Z ### REQ-INST-15
2026-07-17T03:24:38.0137745Z - Title: Immutable home subnet (assigned at creation: auto-if-one/ask-if-many) + spt fork (cross-subnet clone to a new identity, copy-then-diverge, not re-home); adapter chosen at creation from registered hostable adapters, changed only via launch/resume-under-new (ADR-0010)
2026-07-17T03:24:38.0138030Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0138065Z 
2026-07-17T03:24:38.0138316Z ### REQ-REACH-1
2026-07-17T03:24:38.0138771Z - Title: Off-node remote-drive detection + file transfer
2026-07-17T03:24:38.0139137Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0139170Z 
2026-07-17T03:24:38.0139419Z ### REQ-REACH-2
2026-07-17T03:24:38.0139755Z - Title: Remote command execution (deferred, consent-gated)
2026-07-17T03:24:38.0140016Z - Required stages: 
2026-07-17T03:24:38.0140054Z 
2026-07-17T03:24:38.0140297Z ### REQ-MSG-1
2026-07-17T03:24:38.0140975Z - Title: Local message delivery: TCP-first to a registered address, spool fallback when offline; id->address via registry (stale-clean first); reply routing (__REPLY_TO__)
2026-07-17T03:24:38.0141256Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0141290Z 
2026-07-17T03:24:38.0141546Z ### REQ-MSG-2
2026-07-17T03:24:38.0142018Z - Title: spt binary CLI surface: send/ring/ready(+--once)/list/stop/whoami, stable arg shapes + exit codes
2026-07-17T03:24:38.0142296Z - Required stages: impl, unit
2026-07-17T03:24:38.0142329Z 
2026-07-17T03:24:38.0142576Z ### REQ-MSG-3
2026-07-17T03:24:38.0143181Z - Title: Ready-agent lifecycle: register perch (info.json + listener + registry address) on ready, drain spooled backlog on startup, clean teardown
2026-07-17T03:24:38.0143462Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0143553Z 
2026-07-17T03:24:38.0143810Z ### REQ-MSG-4
2026-07-17T03:24:38.0144952Z - Title: Listener stream stdout emits EVENT envelope lines (sister-format, ADR-0001): parse the __REPLY_TO__ frame, pass pre-formed typed envelopes through verbatim (no double-wrap), compose <EVENT type="msg" from=…> otherwise, chunk oversized lines into EVENT-PART
2026-07-17T03:24:38.0145234Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0145271Z 
2026-07-17T03:24:38.0145529Z ### REQ-MSG-ENVELOPE
2026-07-17T03:24:38.0149989Z - Title: The <EVENT type="msg" from=…>body</EVENT> envelope (spt-proto::event, the ADR-0001 grammar) is the SOLE canonical arriving-message format at EVERY harness arriving-message surface on an AGENT perch — api listen AND api poll/worker-poll, byte-identical (reverses REQ-MSG-4's 'hook drains keep the raw frame by contract'). SCOPE CARVE-OUT: the shell-command relay (api poll <shell-id> --link, cmd_poll_shell) is a distinct internal transport carrying RAW MAC'd stamped frames the shell child consumes verbatim — NOT an arriving-message surface, deliberately EXEMPT from <EVENT> composition (notify_shell_e2e guards this boundary). __REPLY_TO__ — mis-elevated during the clean-room port to a fake ADR-0001 'stable wire format' (spt-msg/wire.rs, lib.rs) — is REMOVED entirely (spool format_row, the spt-msg TCP frame, emit parse_frame); (from, body) carried structurally, <EVENT> composed once at the delivery boundary. No legacy sister-interop (spt-core never required it). Reply-correlation rebinds onto the structural from / <EVENT from=…> attribute (ADR-0009 access-gate + ADR-0012 Psyche/spt-live reply-target). Self-delimiting by construction → finding F-002 (non-self-delimiting multi-message poll) dissolves. ADR-0020.
2026-07-17T03:24:38.0150428Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0150476Z 
2026-07-17T03:24:38.0150733Z ### REQ-MSG-5
2026-07-17T03:24:38.0151744Z - Title: user-msg envelope kind + daemon identity gate: a Gateway endpoint / the local user's CLI author user-msg (the user's authority); agent-family senders re-stamped to plain msg; identity-gated never payload-trusted (KH 7.3/7.5); wire-additive (N-1 receivers tolerate the new type)
2026-07-17T03:24:38.0152049Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0152083Z 
2026-07-17T03:24:38.0152321Z ### REQ-MSG-6
2026-07-17T03:24:38.0154308Z - Title: cross-node Gateway user-msg honored via advertised endpoint_type: a user-msg from a Gateway-typed origin survives the receive_wan funnel as user-msg (vs the fail-closed re-stamp), keyed on the QUIC-handshake-proven origin node (never wire `from`). Trust boundary = subnet membership (operator-ratified 2026-06-13); no defense against an in-subnet member forging the type. Instance.endpoint_type is an additive serde-default field extending REQ-INST-7's data model. Absent/unknown type → re-stamp (N-1 rollout grace)
2026-07-17T03:24:38.0154710Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0154744Z 
2026-07-17T03:24:38.0155005Z ### REQ-NODE-IDENTITY
2026-07-17T03:24:38.0155423Z - Title: Ed25519 identity primitive: keypair, detached sign/verify, stable pubkey<->hex
2026-07-17T03:24:38.0155693Z - Required stages: impl, unit
2026-07-17T03:24:38.0155726Z 
2026-07-17T03:24:38.0155978Z ### REQ-NET-1
2026-07-17T03:24:38.0156337Z - Title: WAN messaging first-class, behind default-on net feature flag
2026-07-17T03:24:38.0156623Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0156657Z 
2026-07-17T03:24:38.0156904Z ### REQ-NET-2
2026-07-17T03:24:38.0157267Z - Title: n0 relay default + self-host knob + plain-language disclosure
2026-07-17T03:24:38.0157533Z - Required stages: impl
2026-07-17T03:24:38.0157558Z 
2026-07-17T03:24:38.0157805Z ### REQ-NET-3
2026-07-17T03:24:38.0158147Z - Title: Cross-node Psyche sync over P2P replaces gh-repo-sync
2026-07-17T03:24:38.0158440Z - Required stages: impl, unit
2026-07-17T03:24:38.0158488Z 
2026-07-17T03:24:38.0158741Z ### REQ-PAIR-1
2026-07-17T03:24:38.0159103Z - Title: TOTP-seeded SPAKE2 pairing
2026-07-17T03:24:38.0159441Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0159475Z 
2026-07-17T03:24:38.0159728Z ### REQ-PAIR-2
2026-07-17T03:24:38.0160052Z - Title: Local trust store with TOFU + warn-on-change
2026-07-17T03:24:38.0160309Z - Required stages: 
2026-07-17T03:24:38.0160348Z 
2026-07-17T03:24:38.0160596Z ### REQ-PAIR-3
2026-07-17T03:24:38.0160918Z - Title: Fetch current pairing code from any paired node
2026-07-17T03:24:38.0161194Z - Required stages: impl, unit
2026-07-17T03:24:38.0161228Z 
2026-07-17T03:24:38.0161476Z ### REQ-PAIR-4
2026-07-17T03:24:38.0161756Z - Title: Subnet naming on first pairing
2026-07-17T03:24:38.0162023Z - Required stages: impl, unit
2026-07-17T03:24:38.0162057Z 
2026-07-17T03:24:38.0162309Z ### REQ-PAIR-5
2026-07-17T03:24:38.0162810Z - Title: Multi-subnet pairing: subnet-name discovery input, create-new-names-up-front, rendezvous-token hashing
2026-07-17T03:24:38.0163148Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0163181Z 
2026-07-17T03:24:38.0163431Z ### REQ-PAIR-6
2026-07-17T03:24:38.0163881Z - Title: Elevation-gated per-subnet code fetch (UAC/root or elevated agent; else authenticator app)
2026-07-17T03:24:38.0164158Z - Required stages: impl, unit
2026-07-17T03:24:38.0164191Z 
2026-07-17T03:24:38.0164435Z ### REQ-PAIR-7
2026-07-17T03:24:38.0164778Z - Title: Subnet icon (inline image metadata, GUI-only consumer)
2026-07-17T03:24:38.0165022Z - Required stages: 
2026-07-17T03:24:38.0165045Z 
2026-07-17T03:24:38.0165289Z ### REQ-SUBNET-1
2026-07-17T03:24:38.0165812Z - Title: spt subnet noun namespace: status view (bare + status [NAME] [--nodes]), create (QR/otpauth), show-code; spt pair deleted
2026-07-17T03:24:38.0166081Z - Required stages: impl, unit
2026-07-17T03:24:38.0166115Z 
2026-07-17T03:24:38.0166363Z ### REQ-SUBNET-2
2026-07-17T03:24:38.0166791Z - Title: Guided join e2e: spt subnet join CLI initiator + always-on daemon pairing responder
2026-07-17T03:24:38.0167068Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0167106Z 
2026-07-17T03:24:38.0167354Z ### REQ-SUBNET-3
2026-07-17T03:24:38.0167822Z - Title: Node labels: hostname-default, gossiped, addressable in @node qualifiers (refuse-on-ambiguity)
2026-07-17T03:24:38.0168093Z - Required stages: impl, unit
2026-07-17T03:24:38.0168127Z 
2026-07-17T03:24:38.0168370Z ### REQ-SUBNET-4
2026-07-17T03:24:38.0168855Z - Title: Subnet membership mutations elevation-gated (create = seed reveal; join = trust-boundary enrollment)
2026-07-17T03:24:38.0169211Z - Required stages: impl, unit
2026-07-17T03:24:38.0169249Z 
2026-07-17T03:24:38.0169478Z ### REQ-DOCS-6
2026-07-17T03:24:38.0169996Z - Title: spt how-to <topic>: in-binary task-oriented agent instructions (anti-drift; quickstart prompts point agents at it)
2026-07-17T03:24:38.0170269Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0170404Z 
2026-07-17T03:24:38.0170655Z ### REQ-SEC-1
2026-07-17T03:24:38.0171269Z - Title: Per-endpoint access whitelist: origin-node gate, stateful-firewall (reply/outbound exempt), node-now/user-later, outer gate before grants
2026-07-17T03:24:38.0171548Z - Required stages: impl, unit
2026-07-17T03:24:38.0171581Z 
2026-07-17T03:24:38.0171830Z ### REQ-NOTIF-1
2026-07-17T03:24:38.0172403Z - Title: Notification primitive: per-subnet replicated spool, seen/dismissed, resurface-at-boundary, subsumes update+consent prompts
2026-07-17T03:24:38.0172679Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0172717Z 
2026-07-17T03:24:38.0172965Z ### REQ-NOTIF-2
2026-07-17T03:24:38.0173431Z - Title: spt notify (agent-issued subnet notif) + notif_command manifest seam (harness + shell adapters)
2026-07-17T03:24:38.0173704Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0173741Z 
2026-07-17T03:24:38.0173986Z ### REQ-UPD-1
2026-07-17T03:24:38.0174265Z - Title: Peer-propagated update over P2P
2026-07-17T03:24:38.0174552Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0174590Z 
2026-07-17T03:24:38.0174832Z ### REQ-UPD-2
2026-07-17T03:24:38.0175147Z - Title: All binaries signature-verified before handoff
2026-07-17T03:24:38.0175476Z - Required stages: impl, unit
2026-07-17T03:24:38.0175511Z 
2026-07-17T03:24:38.0175762Z ### REQ-UPD-3
2026-07-17T03:24:38.0176115Z - Title: No endpoint process terminates/suspends during self-update
2026-07-17T03:24:38.0176395Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0176428Z 
2026-07-17T03:24:38.0176670Z ### REQ-UPD-4
2026-07-17T03:24:38.0177037Z - Title: Update gated on user confirmation by default; opt-in full-auto
2026-07-17T03:24:38.0177308Z - Required stages: impl, unit
2026-07-17T03:24:38.0177342Z 
2026-07-17T03:24:38.0177586Z ### REQ-UPD-5
2026-07-17T03:24:38.0177905Z - Title: spt-core ripple-updates registered adapters
2026-07-17T03:24:38.0178176Z - Required stages: impl, unit
2026-07-17T03:24:38.0178210Z 
2026-07-17T03:24:38.0178459Z ### REQ-UPD-6
2026-07-17T03:24:38.0179685Z - Title: Platform-targeted update sets and debug rollout: signed multi-platform update metadata, recipient platform selection, channel-scoped monotonic counters, debug-channel opt-in via release-key overlay, local staging plus pull-based peer propagation, and maintainer-only convergence tooling (ADR-0016)
2026-07-17T03:24:38.0180034Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0180067Z 
2026-07-17T03:24:38.0180320Z ### REQ-UPD-7
2026-07-17T03:24:38.0182828Z - Title: Origin-source update bootstrap (`spt update fetch`): pull the latest signed release directly from the GitHub release origin (`SaberMage/spt-releases`) — the per-platform artifact + its `<asset>.release.json` SignedRelease metadata — and stage it through the EXISTING verify→stage pipeline (the same `plan_verified` gate: two-key signature + channel + monotonic rollback floor + SHA-256), after which the normal consent-notif / `spt update apply` flow is unchanged. Closes the peer-only-discovery gap (REQ-UPD-1): a first-in-fleet / isolated node can update with no peer to pull from. The signed-release anchor keeps the GitHub transport untrusted-but-verified.
2026-07-17T03:24:38.0183143Z - Required stages: impl, unit
2026-07-17T03:24:38.0183187Z 
2026-07-17T03:24:38.0183434Z ### REQ-UPD-8
2026-07-17T03:24:38.0186537Z - Title: Platform-safe `spt update fetch` + apply platform-guard (v0.3.1 cross-OS brick fix): `spt update fetch` stages the signed multi-platform `SignedUpdateSet` (`update-set.json` + every platform artifact it names), never a platform-blind single `SignedRelease`, so local apply selects `current_platform()` and P2P re-serve lets each peer select ITS own platform. Defense-in-depth: `apply_staged` REFUSES a staged single-release artifact unless it is platform-stamped for THIS node (an unstamped pre-v0.3.2 single, or a single stamped for another OS, fail-safe refuses — the guard that alone prevents the v0.3.1 brick where a Linux ELF was applied as `spt.exe`). UX: a friendly post-apply message (`Updated spt-core to vX.Y.Z.` + changelog URL) driven by an additive `product_version` metadata field, with a release-counter fallback when absent.
2026-07-17T03:24:38.0186932Z - Required stages: impl, unit
2026-07-17T03:24:38.0186970Z 
2026-07-17T03:24:38.0187225Z ### REQ-UPD-9
2026-07-17T03:24:38.0190526Z - Title: `gh_release` adapter [update] avenue (optional signing): an adapter declares `[update] avenue = "gh_release", repo = "user/repo"` (+ optional `asset`, default `adapter.spt`; + optional Ed25519 `signing_key`); spt-core's ripple compares the repo's LATEST GitHub release version against the installed adapter version and, when newer, auto-updates by fetching the release `.spt` archive (the REQ-INSTALL-9 `--release` fetch primitive) → verifies the `.spt` against `signing_key` if declared, else HTTPS+GitHub first-acquisition trust → re-extracts + re-registers the adapter root. Lets a harness adapter ship updates from its own GitHub releases with NO signing tooling or plugin coupling (removes the perri file_pull/delegated avenue blockers). Acquisition-trust mirrors `--release` + the installer first-fetch; does not alter spt-core self-update (REQ-UPD-1..8).
2026-07-17T03:24:38.0190904Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0190994Z 
2026-07-17T03:24:38.0191247Z ### REQ-TERM-1
2026-07-17T03:24:38.0191609Z - Title: Process-supervisor terminal wrapper hosting broker PTYs
2026-07-17T03:24:38.0191872Z - Required stages: impl, unit
2026-07-17T03:24:38.0191896Z 
2026-07-17T03:24:38.0192139Z ### REQ-TERM-2
2026-07-17T03:24:38.0192504Z - Title: session-surface abstraction; send-keys + send-line injection
2026-07-17T03:24:38.0192778Z - Required stages: impl, unit
2026-07-17T03:24:38.0192812Z 
2026-07-17T03:24:38.0193064Z ### REQ-TERM-3
2026-07-17T03:24:38.0193379Z - Title: Byte-stream remote terminal streaming for v1
2026-07-17T03:24:38.0193651Z - Required stages: impl, unit
2026-07-17T03:24:38.0193679Z 
2026-07-17T03:24:38.0193933Z ### REQ-TERM-4
2026-07-17T03:24:38.0194647Z - Title: Live activity buffer (session digest): projection of normalized session logs, snapshot-pull (spt endpoint digest) + structured-delta-stream contract + api digest-entry push
2026-07-17T03:24:38.0194939Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0194962Z 
2026-07-17T03:24:38.0195214Z ### REQ-TERM-5
2026-07-17T03:24:38.0197260Z - Title: Adapter-declared digest extractor seam: a `[digest]` manifest section declaring an imperative extractor (native harness log -> the {role,text,tool,ts} contract; defaults to the [history] source files with an own-source escape hatch), `api digest-entry` push fallback, register-time validation of the section, adapter-declared presentation defaults (window depth, arg-truncation, sprint-collapse) that any consumer may override, and a `spt adapter digest-proof` author tool plus runtime skip-diagnostics (no silent drop). Reverses M9's no-manifest-seam stance; no declarative DSL.
2026-07-17T03:24:38.0197607Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0197645Z 
2026-07-17T03:24:38.0197895Z ### REQ-TERM-6
2026-07-17T03:24:38.0199449Z - Title: Thread-spanning digest across session boundaries: a per-endpoint session ledger (`<perch>/sessions.log`) appended at first bind and by `api boundary` on `/clear`|`/compact` session rotation, the digest enumerating the last K sessions so its rolling window bridges a boundary, and a distinctive in-timeline boundary marker (DigestEntry::Boundary). The digest follows the live-agent thread, not a single session.
2026-07-17T03:24:38.0199740Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0199774Z 
2026-07-17T03:24:38.0200017Z ### REQ-TERM-7
2026-07-17T03:24:38.0201559Z - Title: Two-origin digest merge: spt-owned context-injection entries (psyche_download | echo_mirror | owl_message) appended by spt to the endpoint `digest.log`, timestamp-interleaved with the adapter's extracted activity records into one ordered timeline, via a distinct context-injection record category. Data model only this milestone; GUI collapse/expand and the echo-reads-digest delta loop are deferred to the surfaces that consume them.
2026-07-17T03:24:38.0201964Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0202007Z 
2026-07-17T03:24:38.0202250Z ### REQ-FRONT-1
2026-07-17T03:24:38.0202598Z - Title: Day-one launcher/manager frontend (list/launch/attach/init)
2026-07-17T03:24:38.0202850Z - Required stages: 
2026-07-17T03:24:38.0202888Z 
2026-07-17T03:24:38.0203144Z ### REQ-HOST-RUN-1
2026-07-17T03:24:38.0206113Z - Title: spt-hosted harness bringup: `spt endpoint run` spawns an adapter's `[session.self]` command template into a broker-held PTY (the spawn-session seam, brain.rs spawn_session_pid — same broker path shellhost.rs launch_shell_brokered_in uses for shells, now for kind="harness" self-role), registers the perch under the given endpoint id, returns the id. Reverses today's harness-hosted-only launch (external launcher → `api bind`). Non-interactive flag set (--adapter <a[:profile]> --id <id> --create --resume <session> --attach|--start|--view) covers every terminal action of the W2 interactive picker so shortcuts (cc-<id>) bake fully non-interactive launches; composite adapter:profile resolves via registry::resolve_option leaf-replace overlay.
2026-07-17T03:24:38.0206493Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0206581Z 
2026-07-17T03:24:38.0206833Z ### REQ-RC-1
2026-07-17T03:24:38.0209429Z - Title: `spt rc <id>` — user CLI attaching a local terminal to a broker-held PTY, reusing the cross-node attach machinery (attach.rs request_attach → send_attach_input pump, spt-net AttachRecord codec); local attach is the degenerate single-node case of the cross-node path (rides REQ-TERM-3 byte-stream streaming). Read-only `--view` (watch, no stdin forwarded). Clean detach that does NOT terminate the broker-held session (KNOWN-HAZARDS: PTY ownership stays with the broker; no termination on detach). Explicit detach keybind that cannot collide with harness passthrough input (legacy capsule used a ctrl-b prefix); documented. ConPTY DSR auto-answer in the attach reader (hazard 5.5).
2026-07-17T03:24:38.0209748Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0209791Z 
2026-07-17T03:24:38.0210043Z ### REQ-HOST-RUN-2
2026-07-17T03:24:38.0212305Z - Title: Project-scoped working directory for spt-hosted bringup: `spt endpoint run` lands the broker-spawned harness PTY in the user's PROJECT cwd, not the daemon's, via an additive `SpawnReq.cwd` field carried through the broker PTY spawn (portable-pty CommandBuilder cwd). N-1-safe wire change (additive, defaulted). Required because the consumer (Claude Code) is project-scoped: broker-inherited cwd = the daemon's cwd = the wrong `.claude`, wrong session history, wrong digest source; `cc <id>` at a project root MUST land the harness in that project. W1 ships broker-inherited cwd as a bringup-proof shortcut only; this REQ must land before the M12 gate (doyle, 2026-06-14).
2026-07-17T03:24:38.0212605Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0212639Z 
2026-07-17T03:24:38.0212891Z ### REQ-RUN-PICKER
2026-07-17T03:24:38.0218522Z - Title: Interactive `spt endpoint run` picker (ratatui TUI): bare `spt endpoint run` (no --adapter/--id) enters an in-process picker (flags-present = the REQ-HOST-RUN-1 non-interactive path, untouched). Layer 1 picks kind (Create new | Pick existing). Create-new: choose a registered kind="harness" adapter with its shipped+local profiles tree-nested (registry::registered / manifest.profiles / local_profile_names) → enter a charset-validated id → start. Pick-existing: category select (left/right) over [<cwd-project> | Local node | Subnet], endpoints grouped + alphabetically sorted per category, a status square per endpoint (online green ■ / offline gray ▢ — the blue "attached" tri-state + Kick are DEFERRED to a broker attach-presence slice, M12-W2-RULING Q1), type-to-filter (`/`, nucleo-matcher), a pinned keybind legend, and a right-half two-pane description (harness adapter:profile · best-effort project history newest→oldest from the contextstore p-<project> branches, empty-if-none · `spt endpoint description`). Confirm layer offers status-dependent options — Attach/Start/View (rc pump / cmd_endpoint_run) · Instantiate-locally (remote) · Change-harness-adapter (offline) · Fork (cmd_fork) · Resume-from-history (offline+LOCAL only; enumerate spt_store::sessions::last_k, titles `<project> @ <ts> (…id5)`, feed session_id → cmd_endpoint_run --resume). A single action enum is the source of truth so a future tap-mode (phone PTY) layers on without re-coupling to keybinds. EVERY terminal action routes through cmd_endpoint_run / existing CLI fns — no second bringup path.
2026-07-17T03:24:38.0219097Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0219131Z 
2026-07-17T03:24:38.0219392Z ### REQ-RUN-SHORTCUT
2026-07-17T03:24:38.0225175Z - Title: `<basename>-<id>` launcher shortcut generation (picker `s` keybind, M12-W2-T2.4): from any pre-start options set the picker writes/updates a `<basename>-<id>` launcher at the project root baking the current selection's non-interactive `spt endpoint run` flags (terminal actions only: adapter[:profile] + id + (create|resume) + (start|attach|view); Kick/Instantiate/Change-adapter/Fork are interactive-only, not bakeable). BASENAME IS A PARAMETER (operator rev. 2026-06-14): harness-agnostic spt-core defaults to `spt` (→ `spt-<id>`); an adapter/flow OVERRIDES it (spt-claude-code → `cc`), so spt-core NEVER bakes `cc` (a harness name) into itself. The basename must be a DISTINCT token, never bare `spt` (a `spt.cmd` would shadow the real `spt.exe` only under cmd.exe cwd-first search, silently no-op in PowerShell/Unix, and self-recurse). The script is the CURRENT OS's native form — `.cmd` on Windows (NOT `.ps1`: default PATHEXT excludes `.ps1` so a bare/ext-less name never resolves one; `.cmd` is PATHEXT-resolvable), POSIX `sh` (+chmod +x) on Unix (a single portable form can't be both). The generated header documents the invocation reality (cmd.exe bare `<name>` in the project dir / PowerShell `.\<name>` / Unix `./<name>`; a truly-bare basename on PATH = a PATH-installed launcher, `/spt:setup`'s job). Overwrite is SENTINEL-guarded: the generator writes + checks a generated-by header marker — it overwrites its own prior output freely, but REFUSES + warns if a same-named file lacks the sentinel (never clobber a user file). Requires the additive `--create` flag on `Run{}` (the default-fresh made explicit; N-1-safe).
2026-07-17T03:24:38.0225814Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0225851Z 
2026-07-17T03:24:38.0226232Z ### REQ-RUN-PICKER-HOME
2026-07-17T03:24:38.0230495Z - Title: Home-subnet selection LAYER in the `spt endpoint run` ratatui Create-new picker (v0.14.1; the deferred half of REQ-RUN-MULTISUBNET-HOME's interactive path — ADR-0026 §3 'the interactive picker lists subnets MRU-ordered'). On a MULTI-SUBNET node the Create-new flow gains a `CreateHome` screen (CreateAdapter → CreateId → CreateHome → Confirm) that lists the node's MEMBER subnets MRU-ordered (reusing recent_home::mru_preference + order_by_mru), default cursor = MRU head; the chosen subnet rides Outcome::Run{subnet} into cmd_endpoint_run's --subnet, so decide_run_home resolves Home directly and the post-TUI `Ok to proceed? Y/n` confirm NEVER fires for the picker path. Single-subnet / local-only nodes SKIP the layer (assign_home auto-homes; CreateId → Confirm unchanged). The CLI / flagged `endpoint run` path KEEPS the decide_run_home Y/n confirm + the non-interactive MULTI_SUBNET_HOME refuse (operator: the confirm stays useful for CLI-only bringup, just not in the TUI). Esc backs CreateHome → CreateId; Enter selects → Confirm. Pure front-end invariant preserved: the layer only collects --subnet, routes through the one bringup core.
2026-07-17T03:24:38.0230849Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0230883Z 
2026-07-17T03:24:38.0231129Z ### REQ-ELEVATE-1
2026-07-17T03:24:38.0234914Z - Title: Cross-platform self-elevating re-launch for privilege-gated commands: a pure decision seam `decide_elevation_path(os, elevation, interactive_tty, has_display, has_pkexec, has_term_emulator) -> ElevatePath{AlreadyElevated, InlineSudo, UacWindow, Pkexec, TerminalEmulator, PrintHint}` selecting how to re-acquire privilege, and the per-OS impure launchers it dispatches — Windows UAC console (ShellExecuteW `runas` on the abs-exe + verbatim argv; the elevated child does the work, prints 'You can close this window', and pauses for a keypress; the original prints 'Elevated terminal launched…' and exits 0; NEVER pipes the child's stdout back across the privilege boundary), Linux desktop pkexec (preferred, native polkit GUI auth) else x-terminal-emulator -e sudo (fallback list x-terminal-emulator→gnome-terminal→konsole→xterm), the existing interactive-TTY inline sudo, and the headless/no-path floor that prints the absolute-path command. Reused by every gated command (not subnet-specific). Generalizes should_auto_elevate.
2026-07-17T03:24:38.0235562Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0235591Z 
2026-07-17T03:24:38.0235839Z ### REQ-WHOAMI-1
2026-07-17T03:24:38.0238666Z - Title: The `endpoint list` SELF pin carries the Self endpoint's authored `endpoint description` (info::read_info(...).resources) when present, inline after the liveness state; whoami stays a top-level hot-path verb (parse unchanged, REQ-MSG-9) and renders the same description-carrying SELF pin. HISTORY: originally minted whoami as a thin ALIAS of `spt endpoint list` — that alias premise is SUPERSEDED by REQ-WHOAMI-IDENTITY-ONLY (PROJECT-INDEX W1, 2026-07-15): the alias inherited the list's O(perches x branches) git fanout onto hook paths (the 2026-07-15 message-delivery incident), so whoami is now identity-only over the shared render_self_pin. The pin render + parse evidence here stands; the full-roster surface lives solely on `endpoint list`.
2026-07-17T03:24:38.0239215Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0239254Z 
2026-07-17T03:24:38.0239520Z ### REQ-RCVIEW-1
2026-07-17T03:24:38.0244853Z - Title: Remote-attach controller/viewer model (CONTEXT.md:317): a session's broker OutputLog serves ONE interactive controller (input + EXCLUSIVE PTY resize; its viewport sets the size, sent on attach + every window change via crossterm Event::Resize) plus ANY NUMBER of read-only `--view` attachers (output-only, no input, no resize; client-side letterbox — center+pad when larger, clip+1-line indicator when smaller; only the local ctrl-b d detach chord). Attach intent is three-valued (`Viewer | Control | Take`, wire-default Control): Control to a FREE endpoint becomes controller, Control to a CONTROLLED endpoint is REFUSED with guidance (`--view`/`--take`) — never auto-viewer, never silent-displace. Wire adds (additive, N-1 skip-unknown): `Request.intent`, `Resize{rows,cols}` (controller-only), `Size{rows,cols}` (→viewer), `Displaced{by}` (→displaced controller). The brain-resume cursor (delivered_through, ADR-0018) tracks the CONTROLLER ONLY; viewers replay from their own from_seq and never move it. Dormancy keys on the controller ONLY: controller attach wakes / controller detach goes dormant (even with viewers present); viewer attach/detach is wake-neutral and may watch a dormant endpoint as-is. v1: viewing is gated identically to driving — a viewer runs the same access_check(Unsolicited) as a controller (watching reveals full session contents = a real disclosure); a lighter distinct watch-gate is deferred to cross-subnet/finer-consent (CONTEXT.md:317 'driving ≠ watching' = the future seam).
2026-07-17T03:24:38.0245242Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0245276Z 
2026-07-17T03:24:38.0245526Z ### REQ-KICK-1
2026-07-17T03:24:38.0248592Z - Title: Explicit, loud controller displacement: `spt rc kick <target>` / `--take` (Take intent) kicks the incumbent controller and becomes controller; the displaced controller receives a LOUD `Displaced{by}` notice and is FULLY DETACHED (not demoted to a viewer). A default attach to a controlled endpoint is NEVER a silent displace (it is the Control busy-refusal). An old (N-1) rc omits intent → Control, so it can drive a free endpoint but CANNOT `--take` — it can never silently steal, and gets a clean busy-refusal instead. Taking control rides the same access_check(endpoint, origin, Unsolicited) as a normal control attach (if you may drive, you may take — no elevated kick policy). The picker surfaces 'Kick <node> and attach' (Take) only on a controlled (blue ■) endpoint, via the existing attach dispatch (single-bringup-path: intent is a parameter).
2026-07-17T03:24:38.0249112Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0249146Z 
2026-07-17T03:24:38.0249393Z ### REQ-PICKER-1
2026-07-17T03:24:38.0253635Z - Title: The picker renders a FOUR-state endpoint status (extending the W2 online/offline duality): the list-item square AND a color-coded STATUS line at the top of the pick-existing right-side details both show — gray OFFLINE; green ONLINE (online + PTY-controllable spt-hosted, not controlled); amber 'ONLINE - HARNESS ONLY' (online but NOT broker-PTY-controllable = harness-hosted, no broker PTY seat — today mis-shows green); blue 'ONLINE + CONTROLLED' (online + driven_by.is_some()). Derived on EndpointRow from {offline | controllable | driven_by} with precedence offline→gray, else driven_by→blue, else !controllable→amber, else green (driven_by outranks harness-only; mutually exclusive in practice — a harness-only endpoint has no broker PTY to control). The controllable discriminator is a NEW InfoJson.controllable: Option<bool> (serde-default, N-1-safe), stamped at the establish seam — cmd_listen (harness-hosted relay, no broker PTY) → Some(false); cmd_bind live_agent (spt-hosted broker PTY) → Some(true); absent → not-controllable (amber) default (harness-hosted is the common mis-reported case; one bind self-corrects). Store-projection-only (no live daemon query — doyle ruling). (v0.10.0)
2026-07-17T03:24:38.0254101Z - Required stages: impl, unit
2026-07-17T03:24:38.0254135Z 
2026-07-17T03:24:38.0254393Z ### REQ-PICKER-2
2026-07-17T03:24:38.0256664Z - Title: The picker's project-history loader reads the git-backed context store, not the bare working tree: data.rs project_history_for enumerates an endpoint's projects via the BranchStore branch set (the context store keeps per-project context in git branches — contextstore::project_branch(project_id), checked out to projects/<project>/<id>/ only on-demand) instead of raw std::fs::read_dir over the empty working tree (which returned empty for ALL rows incl wall-a — the operator bug). Ordered newest→oldest by branch commit recency; degrades to empty (informational pane), never fails. (v0.10.0)
2026-07-17T03:24:38.0257002Z - Required stages: impl, unit
2026-07-17T03:24:38.0257035Z 
2026-07-17T03:24:38.0257284Z ### REQ-PICKER-3
2026-07-17T03:24:38.0260392Z - Title: A self-owned subnet row reconciles its status to the LIVE roster: a Subnet-category row whose endpoint_id overlaps a local (is_local) roster id is self-owned (this node hosts it), so its status square is OVERRIDDEN with the live roster status — the WAN registry snapshot (wansend::load_snapshots) is a periodically-advertised, independently-stale projection, while the local roster (p.alive) is ground truth for an endpoint this node hosts. One status square per endpoint (CONTEXT.md:348-350 — nothing licenses opposite squares for one endpoint across its Local vs Subnet listings). A reconcile pass in data.rs after the local_rows + subnet_rows gather; BOTH category listings are preserved (Local + Subnet are legitimately distinct views — you are in your own subnet), only the STATUS is unified. (v0.10.0)
2026-07-17T03:24:38.0260726Z - Required stages: impl, unit
2026-07-17T03:24:38.0260763Z 
2026-07-17T03:24:38.0261010Z ### REQ-PICKER-4
2026-07-17T03:24:38.0263373Z - Title: The picker's Subnet category renders the canonical node LABEL, not bare key-hex: a subnet row's node renders as 'LABEL (keyprefix…)' (e.g. 'HFENDULEAM (bcead52b…)') per CONTEXT.md:650 + Instance.node_label, NOT the raw node key-hex (SPT_DEV:14efb80cb… — a picker-only regression because resource_projection→ResourceRow drops node_label, so data.rs subnet_rows uses the raw row.node). Thread node_label into the picker subnet path (ResourceRow gains node_label, or subnet_rows looks it up via the registry's node_labels) and REUSE the one canonical render (format!("{l} ({}…)", key_prefix) — cli.rs / wansend.rs), never a re-implementation. (v0.10.0)
2026-07-17T03:24:38.0263811Z - Required stages: impl, unit
2026-07-17T03:24:38.0263839Z 
2026-07-17T03:24:38.0264089Z ### REQ-PICKER-5
2026-07-17T03:24:38.0267744Z - Title: `spt endpoint list` (bare/subnet view) renders an ALIGNED table with canonical node labels: cmd_endpoint_list prints subnet rows with `\t` TAB separators (cli.rs:~1651-1662) so variable-width endpoint_ids snap fields to different tab-stops → a RAGGED status column (operator screenshot: X/help statuses misaligned vs rt-*/sptc-*/wall-a); and it calls the node renderer with no label → bare key-hex for every row (SAME ResourceRow-drops-node_label root as REQ-PICKER-4). FIX: max-width per-column padding (mirror render_node_rows' pad, pad by char count not byte len — '…' is multibyte) replacing the tabs, and render the node via the shared node_label_display now that ResourceRow carries node_label (REQ-PICKER-4). Extract a pure row-formatter seam so the alignment+label is unit-testable. ALSO: the bare list is the SUBNET view (a just-run LOCAL perch is invisible cross-subnet until the next advertise tick), so emit a `--local` hint line so a freshly-run endpoint isn't perceived as lost. (v0.10.0; operator-flagged + doyle dispatch 2026-06-17)
2026-07-17T03:24:38.0268206Z - Required stages: impl, unit
2026-07-17T03:24:38.0268239Z 
2026-07-17T03:24:38.0268497Z ### REQ-SEND-SPT-HOSTED
2026-07-17T03:24:38.0272942Z - Title: An inbound `spt send` is DELIVERED to an spt-hosted endpoint (brought up via `spt endpoint run` → `api bind`, broker holds its PTY, NO `api listen` relay). Today cmd_bind→establish_perch (api/startup.rs ~441) writes info.json + ready marker + controllable=Some(true) but registers NO message-listener / NO address, so deliver.rs resolve_address→None→spool (deliver.rs:132-140) and the message NEVER reaches the live PTY — the endpoint reads 'online' (ready marker) yet `spt send` silently SPOOLS ('online but not deliverable' lie). Per CONTEXT:187-188 the daemon owns the PTY and delivers, manifest-configurable per activity-state (direct PTY injection / relay / HTTP). FIX: route an inbound send for an spt-hosted target through the daemon → broker InputReq → session.write_input PTY-inject (broker.rs dispatch_input/write_input ~988-1022), the same path the brain uses; the live-delivery handshake must report Sent (not Queued) and stop the spool-only fallback for a broker-hosted, PTY-resident endpoint. Detection is local: controllable==Some(true) + spt-hosted state + resolve_address==None. = the spt-core HALF of the wall-b finding (perri owns the adapter half: bind-hook fired-zero-perch + the missing endpoint-run int test). (post-v0.10.0)
2026-07-17T03:24:38.0273290Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0273323Z 
2026-07-17T03:24:38.0273585Z ### REQ-HAZARD-RC-EOF
2026-07-17T03:24:38.0278175Z - Title: A severed broker stream during a live rc session surfaces GRACEFULLY, never as a raw io error that crashes the PTY. The rc read-loop (rc.rs:352-362) continues only on WouldBlock/TimedOut; ANY other read_event_until error — including UnexpectedEof 'failed to fill whole buffer' — returns Err → RC_FAIL → the PTY 'crashes' from the user's view. Confirmed trigger: a deliberate `spt daemon stop` (broker bounce) severs an active rc (perri stopped the daemon to release owlery watch handles). Same severed-broker-stream EOF class as the v0.9.1 seed fix (seed_fail_message) and the listener-death case — spt-core must classify a broker-gone EOF and (a) surface a CLEAR actionable message ('daemon stopped/restarted — re-run / reconnect'), never the raw buffer error, and ideally (b) AUTO-REATTACH to the same session on the fresh broker (the broker is the daemon-lifetime anchor; it returns on the next `spt api` call). FOLD two side-observations: (1) `spt daemon stop` SILENTLY drops active rc/live sessions — warn ('N active session(s) will drop') or graceful-detach on stop; (2) the daemon holds owlery WATCH HANDLES on perch dirs so a torn-down perch dir stays 'Device busy' until a full daemon stop releases them (perri's rt-* cleanup) — a torn-down perch's handle should release without a daemon stop. doyle Finding C, root-caused. (post-v0.10.0)
2026-07-17T03:24:38.0278652Z - Required stages: impl, unit
2026-07-17T03:24:38.0278676Z 
2026-07-17T03:24:38.0279038Z ### REQ-HAZARD-DEFERRED-MANIFEST
2026-07-17T03:24:38.0281893Z - Title: A pointer-mode (delegated / GhReleaseManaged) adapter whose binary/manifest is not yet extracted is reported with a CLEAR diagnostic, never silently dropped. Today such an adapter reads its manifest LIVE from source_dir (registry.rs manifest_dir ~146/149); a deferred / un-extracted install makes load_manifest fail → registered() (~410, filter_map(.ok())) SILENTLY DROPS the row → downstream ADAPTER_UNRESOLVED + a cryptic os-error-2 on `spt adapter use`. FIX: surface a clear diagnostic at the resolver + at `adapter use` (name the adapter + the deferred/missing-manifest cause + the fix), not a silent filter-drop and not a bare os-error-2; consider an eager manifest copy at register time so host_binaries survive before the binary download completes. doyle Finding A. (post-v0.10.0)
2026-07-17T03:24:38.0282338Z - Required stages: impl, unit
2026-07-17T03:24:38.0282371Z 
2026-07-17T03:24:38.0282638Z ### REQ-HAZARD-ENV-SUBST
2026-07-17T03:24:38.0286697Z - Title: `spt endpoint run` HONORS manifest [env.<VAR>] direction=inject values (with {key} substitution) on the spt-hosted spawn. Today only the [session.self] command ARGV is {id}-substituted; the [env] inject value is NEITHER substituted NOR applied — manifest.schema.json promises EnvVar.value = 'Value to inject (with substitution)' but prepare_harness_spawn fills only argv and SpawnReq carries no env, so a [env.SPT_ENDPOINT_ID].value='{id}' arrives EMPTY. A FLAGLESS harness (bare `claude`, no argv slot for {id}) then routes the id via [env] → empty → SessionStart sees empty $SPT_ENDPOINT_ID → seeds-by-PPID instead of binding → ZERO perch → NO_PERCH (the actual wall-b bind blocker; perri hard-repro'd). SILENT failure (empty inject, no error). FIX (doyle ruled a): fill every [env] inject value from the SAME {key} catalog as argv/role (mirror F-009 TEMPLATE fill, whole-string fill_template for an env value), thread it through SpawnReq.env → the broker sets it on the spawned PTY child. Correctness fix — schema already promises it, NO manifest change, NO new binary. PAIRS with REQ-SEND-SPT-HOSTED to make endpoint run fully work. doyle F-013. (post-v0.10.0)
2026-07-17T03:24:38.0287036Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0287070Z 
2026-07-17T03:24:38.0287350Z ### REQ-HAZARD-ROSTER-GHOST
2026-07-17T03:24:38.0290437Z - Title: A LOCAL subnet roster entry whose backing perch is erased does NOT keep advertising Active (no phantom perch-less endpoint). `api session-end <id> --erase` removes the perch (owlery dir gone) but the subnet roster (identity/registry/<subnet>.json) keeps the endpoint's instance row ACTIVE with no backing perch; `endpoint stop` says 'address unregistered' yet the line persists; no CLI verb forgets a roster entry, and a hand-edit is re-added by the single-writer daemon advertiser. FIX: daemon-side self-heal — the advertiser DROPS/forgets a LOCAL roster entry whose backing perch no longer exists (stops advertising it Active), and/or a `forget`/evict verb; verify whether the epoch lease eventually evicts it (slow-self-heal) vs a real leak and scope accordingly. doyle secondary finding (perri). (post-v0.10.0)
2026-07-17T03:24:38.0290885Z - Required stages: impl, unit
2026-07-17T03:24:38.0290913Z 
2026-07-17T03:24:38.0291190Z ### REQ-WAN-SPT-HOSTED-DELIVERY
2026-07-17T03:24:38.0295535Z - Title: A WAN-ARRIVED `spt send` is DELIVERED to an spt-hosted endpoint (broker holds its PTY, NO api-listen relay), not spooled-forever. Today receive_wan (spt-daemon/wan.rs:271-276) tries deliver_tcp (the harness-hosted relay leg) then falls to spool — it has NO spt-hosted broker-inject leg, which exists ONLY in local cmd_send (REQ-SEND-SPT-HOSTED, Brain::inject_endpoint → KIND_ENDPOINT_INPUT → broker dispatch_endpoint_input → translation-binary idle-inject). So a WAN arrival to an idle spt-hosted perch with a live translation binary ALWAYS sleeps in spool until an adapter hook polls (F-023: perch verifiably idle 7min, binary healthy, zero injection). FIX: factor cmd_send's spt-hosted delivery leg into a SHARED fn; receive_wan calls it after the replay-check (wan_seen_at) + restamp (restamp_wan_user_msg), BEFORE the spool fallback. Claim discipline UNCHANGED: inject delivered=true → wan_mark_seen_at then return the existing 'delivered' wire token (no wire change); delivered=false → the existing spool-with-claim transaction. v0.14.3 LAW: the shared leg is translation-binary-ONLY, NO raw-PTY fallback — a no-binary arrival SPOOLS LOUD, never writes the PTY. (F-023, BUILD-F023-WANIDLE)
2026-07-17T03:24:38.0295890Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0295942Z 
2026-07-17T03:24:38.0296219Z ### REQ-MSG-IDLE-EDGE-DRAIN
2026-07-17T03:24:38.0299349Z - Title: On an endpoint's ACTIVE→IDLE transition the daemon DRAINS its pending spool (deferred AND non-deferred) through the same shared spt-hosted inject leg — closing the SECOND F-023 gap: no idle-edge drain exists anywhere, so an spt-hosted endpoint (which has no api-listen relay to wake it) strands BOTH message classes ('ACTIVE → spool deferred for hook-poll' and 'IDLE+no-binary → non-deferred for a relay that does not exist'). FIX: on the state ACTIVE→IDLE edge, offer the pending spool through the shared inject leg; REUSE the hook-poll drain's take/ack machinery so a concurrent `api poll` cannot double-deliver — ONE drain path, TWO triggers (hook-poll + idle-edge). v0.14.3 LAW holds on BOTH triggers: translation-binary-ONLY, a no-binary idle drain SPOOLS LOUD, never writes the PTY. (F-023, BUILD-F023-WANIDLE)
2026-07-17T03:24:38.0299726Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0299763Z 
2026-07-17T03:24:38.0300069Z ### REQ-HAZARD-DELIVERY-STARVATION
2026-07-17T03:24:38.0302624Z - Title: A message that has REACHED a node's spool (WAN-arrived or locally spooled-while-active) is NEVER dependent on an adapter HOOK-POLL cadence for its eventual delivery to an spt-hosted (relay-less) endpoint — the daemon itself drives delivery on the events it owns (WAN ingress + the ACTIVE→IDLE edge). Hazard class: delivery starvation. Without this, cross-node and post-active messages to an spt-hosted perch strand indefinitely whenever the adapter's hooks are quiet (idle session, no user turns), presenting as 'sent but never lands' with a healthy binary and an idle perch (F-023). Guarded by REQ-WAN-SPT-HOSTED-DELIVERY (WAN ingress leg) + REQ-MSG-IDLE-EDGE-DRAIN (idle-edge drain). (F-023)
2026-07-17T03:24:38.0302929Z - Required stages: doc, int
2026-07-17T03:24:38.0302962Z 
2026-07-17T03:24:38.0303223Z ### REQ-MSG-CLI-ORIGIN
2026-07-17T03:24:38.0305528Z - Title: A bare non-perch CLI `spt send` (no owning perch to name as origin) stamps from = `cli@<node-label>` at compose time (bare `cli` when no node label is known — never a dangling `cli@`), and WAN ingress renders an EMPTY from as the origin node DISPLAY (`node_label_display(origin_node, None)` = the QUIC-proven origin node's key-prefix; never blank) — a delivered message NEVER shows a blank sender. Scoped to `spt send`: a from-less send is LEGAL (stamped, never refused), while `spt ring` keeps its NO_SELF refusal (a ring needs a routable self for the reply leg; `cli@<node>` is a display origin, not a perch address). (F-024C item 3, doyle ruled)
2026-07-17T03:24:38.0305947Z - Required stages: impl, unit
2026-07-17T03:24:38.0305984Z 
2026-07-17T03:24:38.0306264Z ### REQ-HAZARD-SESSION-PIN-WEDGE
2026-07-17T03:24:38.0314267Z - Title: A perch PINNED to a DEAD session-id self-heals instead of wedging forever. authenticate() (spt/src/api/auth.rs:78) gates api poll/state/boundary on proof-sid == info.json.session_id; if ONE boundary rotation is lost (transient env corruption kills the /clear-era hook), the perch stays pinned to the dead sid and EVERY id-scoped hook call refuses — INCLUDING boundary itself (it presents the new sid), a permanent strand (ready:false, stale .idle, drain no-ops, WAN spool sleeps forever; AUTH_REFUSED is stderr-only = invisible inside a hook). FIX: authenticate() gains a DEAD-OWNER fallback — when the sid MISMATCHES AND the perch's recorded pid is dead (proc::is_process_alive==false), ACCEPT the caller's sid and RE-PIN (rotate session_id + log SESSION_REPIN loud). Same trust model as establish_perch's conflict gate (api/startup.rs:207-210), which already allows rebind exactly when owner_alive==false (an orphaned perch accepts a new LOCAL owner). A LIVE-owner mismatch STILL refuses (squat protection UNCHANGED). ADDITIVE to token auth — the existing token-auth recovery path is UNTOUCHED; the new branch fires only on (no token) AND (sid mismatch) AND (owner dead). COVERAGE SPLIT (explicit, perri clean-room 2026-07-02 — the wedge latches on /clear even in a CLEAN env, so the corruption domino was sufficient but NOT necessary): the dead-owner re-pin rescues CRASHED/DEAD sessions ONLY; a LIVE-pid rotation (/clear, /compact — same process, new sid) is CORRECTLY refused without the departed session's prior-sid proof and MUST NOT be widened to live owners. The live-rotation contract is adapter-side: the adapter PERSISTS the prior sid across rotation and PRESENTS it as boundary proof (perri's state-file pattern = the reference); a silent boundary skip on an unresolvable id, or a boundary call with NO auth proof, strands the perch (perri's court). Core rescues only the dead-owner orphan; live-rotation proof is the harness-contract's job (see the harness-contract boundary section, which cross-refs this hazard). PARKED (not this wave, logged): pid-ancestry self-proving rotation (core walks the caller's real ancestry vs info.json.pid) — needs an ADR + Windows parent-spoof caveats. (F-024C, F024C-AUTHWEDGE-ADDENDUM + F024D-DOCSCOPE)
2026-07-17T03:24:38.0314815Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0314868Z 
2026-07-17T03:24:38.0315144Z ### REQ-HAZARD-STORE-INIT-RACE
2026-07-17T03:24:38.0318856Z - Title: Concurrent first-touch of ONE fresh BranchStore must ALL succeed, never a hard error. BranchStore::open_or_init (spt-store/src/branchstore.rs:47) is a TOCTOU: it gates on HEAD.exists() then runs a NON-ATOMIC init (`git init --bare` + `git config core.autocrlf false` + best-effort worktree.useRelativePaths). Two processes that both observe !HEAD.exists() on one fresh store race the `git config` step, which takes git's per-repo config.lock — the loser fails with 'could not lock config file …/config: File exists', an io::Error that strands the caller (the G3-gate pump.rs:442 flake, doyle-ledgered). FIX: make init race-tolerant — `git init --bare` is idempotent, and `git config` is idempotent (same bytes), so tolerate a concurrent winner (open-after-lose: if init errors but HEAD now exists, proceed as opened) and retry a transient config.lock collision a bounded number of times so the required core.autocrlf=false is guaranteed set. N concurrent open_or_init on ONE fresh dir must ALL return Ok. (F-025 wave, doyle Item 2)
2026-07-17T03:24:38.0319381Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0319423Z 
2026-07-17T03:24:38.0319715Z ### REQ-HAZARD-SPOOL-SENTINEL-CREATE-FAIL
2026-07-17T03:24:38.0322079Z - Title: A persistent failure to (re)create the spool has-messages sentinel is SURFACED, never silently swallowed. touch_has_messages (spt-store/src/spool.rs:147) does `let _ = File::create(...)` — a live field defect on ENLYZEAM left a stale .has-messages (2026-06-29) beside a fresh spool.db insert (06:59:17Z) in ONE directory, i.e. the create silently failed while rows accumulated (suspected read-only-attrib / share-lock). FIX: on File::create failure emit a LOUD-ONCE-per-perch stderr diagnostic naming the concrete io::Error (self-identifying regardless of kind); do NOT make it fatal (spool writes still proceed). (F-024C item 2, doyle)
2026-07-17T03:24:38.0322384Z - Required stages: impl, unit
2026-07-17T03:24:38.0322418Z 
2026-07-17T03:24:38.0322684Z ### REQ-MANIFEST-NODE-KEY
2026-07-17T03:24:38.0327761Z - Title: A new session-scoped manifest fill key `{node}` resolves to THIS node's advertised label — available wherever the session-scoped keys ({id}/{session_id}/{session_name}) populate: BOTH topologies' spawn-prep catalogs (harnesshost.rs:111-118 self-spawn guaranteed-fill + lifecycle.rs:280 base lifecycle keys, at minimum [session.self] and [session.resume]) AND lazy [strings] eligibility (ADR-0029 family). VALUE (design-true per CONTEXT §node label / REQ-SUBNET-3): the node's ADVERTISED LABEL — the same value node_label_display renders — read from the label store (NodeLabel, registry.rs:118/220, OS-hostname default re-checked at daemon startup), NOT the pubkey and NOT a fresh gethostname at fill time when the store already holds the refreshed label; fall back to the OS hostname only if no label is known. perri's concrete use: templating `--remote-control {id}--{node}` in the claude-spt launch/resume commands. CAVEAT (documented in the manifest.md key-table row AND here): SINGLE-TOKEN fills only — tokenize-then-fill (REQ post-F-009) cannot produce a space-carrying argv element, so composite display names like `<id> @ <node>` remain adapter-shim territory (claude-spt v0.10.3's launch shim stays the reference for those); {node} COMPLEMENTS the shim for tokenizable args, it does not replace it. Origin: perri fill-catalog-gap finding 2026-07-02, operator-promoted into BUILD-F023-WANIDLE (additive, independent of the delivery legs). (NODEKEY-FOLD)
2026-07-17T03:24:38.0328219Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0328252Z 
2026-07-17T03:24:38.0328539Z ### REQ-HAZARD-HOSTED-LIVENESS-RECONCILE
2026-07-17T03:24:38.0333431Z - Title: B2 KEYSTONE: a daemon-hosted (spt-hosted) endpoint's info.json status is RECONCILED to real liveness, not left latched online. The broker exit-waiter (broker.rs:889-910) reaps its in-mem session table + emits ExitEvent but NEVER touches info.json; lifecycle::mark_offline only fires on Psyche teardown — so a dead/exited harness (operator closed the tab) stays status=online forever (is_perch_alive returns ONLINE for daemon-hosted, liveness.rs:80-93). FIX (doyle ruled PULL-PRIMARY — the live-status analog of REQ-HAZARD-ROSTER-GHOST): the livehost reconcile loop (reconcile_once livehost.rs:226-313) queries the broker's live session set (KIND_SESSIONS) each tick and, for any status=online live_agent perch PAST the boot grace whose endpoint has NO live broker session, marks it offline (lifecycle::mark_offline → status=offline → is_perch_alive=false). GATED on spt-hosted (controllable==Some(true)) so a HARNESS-HOSTED relay live agent (api listen, legitimately online with no broker session) is NEVER mis-marked. Crash-robust + self-healing on the next tick (clear-on-event is not crash-robust alone). PUSH (brain ExitEvent→mark_offline) is an OPTIONAL fast-path only if the daemon brain is reliably subscribed to all hosted sessions; correctness rides the pull. Broker stays stateless (ADR-0004 §B — brain owns the info.json write). (v0.12.0)
2026-07-17T03:24:38.0333913Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0333937Z 
2026-07-17T03:24:38.0334213Z ### REQ-HAZARD-RC-ATTACH-FAILFAST
2026-07-17T03:24:38.0338231Z - Title: B1: `spt rc <id>` to a DEAD or non-streaming session fails fast with a clear message, never an INFINITE blank screen. Today rc.rs run_attach (209-231) + pump spawns PUMP_IPC_READER and blocks: the poll times out each slice but the stream never produces output, so the operator sees a permanent blank (operator: fresh wall-f attached, closed tab, then `spt rc wall-f` HUNG — the broker still resolved a session for it). FIX: (a) once B2 lands, gate attach on is_online/status — an offline endpoint yields a clean 'endpoint offline, start it' not an attach; (b) fail-fast — if the attach-open ack / first output does not arrive within a bound, surface a clear message, never an infinite blank; (c) the broker EOFs the attach stream when the session's child is dead, so rc's existing PumpEnd::BrokerGone graceful path (REQ-HAZARD-RC-EOF) catches it. PIN the exact sub-mechanism with a repro test FIRST (dead-session-lingers-in-broker vs reaped-but-rc-waits vs alive-resting-no-wake — the wall-f Windows tab-close: child alive-silent vs dead-not-reaped). (v0.12.0)
2026-07-17T03:24:38.0338573Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0338650Z 
2026-07-17T03:24:38.0338926Z ### REQ-ENDPOINT-STOP-OFFLINE
2026-07-17T03:24:38.0340702Z - Title: H3: `spt endpoint stop <id>` marks the endpoint OFFLINE (alive=false), not merely de-readied. cmd_stop (cli.rs:2994-3010) removes the ready marker + unregisters the address but does NOT set status offline, so a stopped daemon-hosted endpoint still reports alive=true (status=online latch). FIX: add set_status(perch, STATUS_OFFLINE) to cmd_stop — folds with B2 (same setter). Unit: stop → is_perch_alive=false / alive=false. (v0.12.0)
2026-07-17T03:24:38.0340989Z - Required stages: impl, unit
2026-07-17T03:24:38.0341041Z 
2026-07-17T03:24:38.0341322Z ### REQ-HAZARD-DAEMON-STOP-BARRIER
2026-07-17T03:24:38.0343577Z - Title: B3: `spt daemon stop` then an immediate `spt daemon start` does NOT race — stop fully completes before it returns. Today request_stop (seedmap.rs:240-255) returns on the KIND_STOPPING ack (sent seedmap.rs:174-176) BEFORE the seed socket unbinds, so a following is_running ping (daemon.rs:375) wins the exit window and start reports ALREADY_RUNNING (operator: daemon stop → STOPPED then start → ALREADY_RUNNING). FIX: unbind/stop-gate the seed socket BEFORE acking KIND_STOPPING, OR request_stop waits for a ping-to-fail before returning. Unit: stop then immediate is_running()==false. (v0.12.0)
2026-07-17T03:24:38.0343934Z - Required stages: impl, unit
2026-07-17T03:24:38.0343967Z 
2026-07-17T03:24:38.0344258Z ### REQ-HAZARD-SEEDMAP-CONNECT-UNBOUNDED
2026-07-17T03:24:38.0348363Z - Title: SEED (doyle-filed, 2026-07-05, from the REQ-HAZARD-DAEMON-STOP-BARRIER B2 fix): the PRODUCTION seedmap connect callers (put / take / is_running) inherit the SAME interprocess WaitNamedPipeW-forever hazard the stop path just bounded — a Windows named-pipe connect to a name that EXISTS but has NO accepting instance parks in NMPWAIT_WAIT_FOREVER, so a slow / half-dead seed daemon could wedge a live `api seed` / `api listen` / `daemon start`. UPDATE (2026-07-05, doyle reversed the stop-path scope-guard): request_stop's OWN initial connect became load-bearing (a stop-guard re-dialing an already-dying name parked forever, resurrecting the convoy) → it is now bounded via connect_bounded under REQ-HAZARD-DAEMON-STOP-BARRIER (every dial on the STOP path is bounded). REMAINING deferred here = the put / take / is_running production clients. FIX (deferred, needs its own ruling): a shared bounded seed-control connect for those — but a 2s-style cap on a legitimately slow daemon-start connect is a real behavior change (a slow-but-fine start could become a spurious failure), so the timeout + degrade semantics need design first. NOT built — activate when scoped.
2026-07-17T03:24:38.0348805Z - Required stages: 
2026-07-17T03:24:38.0348847Z 
2026-07-17T03:24:38.0349205Z ### REQ-HAZARD-DAEMON-STOP-REAP
2026-07-17T03:24:38.0351457Z - Title: Breap: `spt daemon stop` REAPS the spt-hosted children it spawned — no orphaned psyche/harness processes. Today a stop leaves ~8 orphaned claude-spt-psyche.exe + spt.exe: Psyches are spawned DETACHED (runtime.rs:342-356, the Child is dropped — 'Detached' ~349) and the livehost stop flag Arc<AtomicBool> is NEVER raised (brainproc.rs:227-230 holds it 'for symmetry'). FIX: on stop, raise the livehost stop flag AND kill the spawned psyche/spt-hosted children — via a Windows job object / Unix process-group so the children die with the daemon (not detached-immortal). Folds with B3 (both the stop path). (v0.12.0)
2026-07-17T03:24:38.0351762Z - Required stages: impl, unit
2026-07-17T03:24:38.0351795Z 
2026-07-17T03:24:38.0352091Z ### REQ-HAZARD-LIVEHOST-BOOT-LIVENESS-GATE
2026-07-17T03:24:38.0355161Z - Title: B5: `spt daemon start` does NOT revive phantom Psyches for dead-but-online-latched perches. Today reconcile_once (livehost.rs:285) spawns a Psyche per status=online live_agent perch at boot WITHOUT verifying the harness child / {id}-psyche is actually alive — so a Cold start after an unclean stop revives N psyches for N dead-but-latched perches (3 psyches for 3 dead perches). FIX: gate the boot psyche-spawn on real child-liveness — a perch with NO live broker session (the B2 reconcile signal) is marked OFFLINE at boot instead of hosted, so a dead-harness perch is never revived. Shares the B2 reconcile loop (this is its boot-gate arm); composes with B2's honest latch. Also closes wall-a's psyche_host_error gap (residency-confirm does not run at boot tick-1, livehost.rs:395-441 / 257-263). (v0.12.0)
2026-07-17T03:24:38.0355590Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0355629Z 
2026-07-17T03:24:38.0355942Z ### REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE
2026-07-17T03:24:38.0359155Z - Title: B4 (deepest): a bare brain restart (broker survives) REHYDRATES the live-agent lifecycle so post-restart endpoints are hosted + attachable. Today resume_sessions (brainproc.rs:186, brain.rs:797-809) re-subscribes to the broker's PTY sessions but ALL BrainLifecycle instances (lifecycle.rs:58-130; the ephemeral brain.rs:254-275) are LOST on restart → a post-restart live endpoint gets no livehost → its Psyche is never (re)hosted and new spawns die / can't attach until a FULL daemon reset (operator: perri's brain kill+restart wedged everything until a full daemon kill). FIX: on brain startup, rebuild a BrainLifecycle per resumed live-capable session — load the manifest from the adapter registry → instantiate → start the pulse — the rehydrate the resume no-op cannot do. Composes with B2 (the reconcile re-hosts from the honest on-disk status after rehydrate). (v0.12.0)
2026-07-17T03:24:38.0359604Z - Required stages: 
2026-07-17T03:24:38.0359637Z 
2026-07-17T03:24:38.0359928Z ### REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP
2026-07-17T03:24:38.0364421Z - Title: A bare brain restart leaves EXACTLY ONE `{id}-psyche` process per endpoint — no duplicate. On an abrupt brain death stop_host never runs (the LiveSet + owned child handles die with the brain) and Breap's job/group only reaps at DAEMON stop, so the PRIOR brain's Psyche stays ALIVE; the respawned brain's reconcile re-hosts a SECOND Psyche and overwrites the `{id}-psyche` perch pid, leaving the old one untracked + alive = a duplicate that lingers until daemon-stop (the operator's 'brain kill+restart wedged everything'). FIX: at brain start, BEFORE the first reconcile re-hosts, reap any pre-existing `{id}-psyche` orphan — ID-SPECIFICALLY (recycle-safe on the shared box, where sibling agents share the `claude` basename): scoped-kill the recorded pid ONLY IF it is alive AND its exe basename == the adapter's psyche program (normalize_basename) AND its COMMAND LINE contains the full psyche id `<id>-psyche` (baked via {id}); a sibling never carries THIS id, and any unreadable signal FAILS SAFE (decline to reap — a missed dup is bounded by Breap, a wrong-kill is catastrophic). CAVEAT: the cmdline carries `<id>-psyche` only when the adapter's psyche_init.command uses {id} (the norm); a non-{id} adapter safely MISSES the reap (today's behavior, Breap bounds it) — never a wrong-kill. (v0.12.0)
2026-07-17T03:24:38.0364877Z - Required stages: 
2026-07-17T03:24:38.0364910Z 
2026-07-17T03:24:38.0365197Z ### REQ-HAZARD-UNHOST-PSYCHE-REAP
2026-07-17T03:24:38.0369114Z - Title: On un-host, the detached `{id}-psyche` HARNESS PROCESS is reaped — not just its in-brain pulse-driver thread. Today stop_host (livehost.rs:203) trips the HostedLife stop flag + JOINS the driver thread, but the Psyche is a detached harness process (spawn_psyche → ManifestRuntime detached spawn, runtime.rs:341-356; its pid is untracked in HostedLife though stamped on the `{id}-psyche` perch, where residency-confirm already reads it). So endpoint-stop / mid-life agent-death / a B2/B5 offline-then-unhost leaves the psyche process ORPHANED, alive until the next daemon-stop (where Breap's job/group reaps the whole brain subtree). The Psyche STAYS a harness process by design (CONTEXT.md 97/203/251 — headless harness session, its own perch) — the fix does NOT move it in-brain; it SCOPED-kills the `{id}-psyche` pid on un-host (never machine-wide — shared box). Track the pid in HostedLife at host_one (cleanest) or read the `{id}-psyche` perch pid at stop_host. Composes with H3 (endpoint stop → offline → reconcile un-host → reap) and B2/B5 (the offline arms that trigger un-host). (v0.12.0)
2026-07-17T03:24:38.0369507Z - Required stages: 
2026-07-17T03:24:38.0369540Z 
2026-07-17T03:24:38.0369811Z ### REQ-ENDPOINT-PURGE
2026-07-17T03:24:38.0375309Z - Title: `spt endpoint purge <id>` fully removes an endpoint AND every record keyed on it — the formal teardown devs/CI need for clean test setup/reset. NOT consent-gated (a local dev/test op — no peer consent). OFFLINE-ONLY: refuses while the endpoint is online / daemon-hosted (deleting records out from under a live host risks the daemon re-creating or re-hosting mid-purge); `--force` STOPS it first (endpoint stop → wait for the daemon reconcile to un-host + reap the Psyche) THEN purges. Confirms interactively unless `--yes` (the CI path). Refuses purging the CALLER's OWN running id. All LOCAL — purge reaches only THIS node's records; a remote endpoint's records can't be touched, and its subnet-registry rows decay via the epoch-lease eviction (REQ-HAZARD-REGISTRY-DECAY). Removes: (1) the perch dir TREE recursively — owlery/<id>/ incl every nested {id}-psyche / {id}-w* / shells child (info.json, ready marker, sessions.log ledger, spool.db, inbox, .idle/.more-done sentinels, auth token); (2) the registry address (registry::unregister_address); (3) the context store — ContextStore::remove_endpoint(id): the a-<id> branch+worktree + the <id>/ rows from every p-<project> branch (the same fn `fork --delete-source` already uses); (4) node-local trust rows keyed on the id — access.json + visibility.json. Reuse-heavy: it is `fork --delete-source` generalized (recursive perch remove + unregister + remove_endpoint) + the trust-record cleanup; `endpoint rename` already enumerates the same record set + uses the same offline-only gate. (v0.12.0)
2026-07-17T03:24:38.0375776Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0375814Z 
2026-07-17T03:24:38.0376076Z ### REQ-READY-AGENT-RESUME
2026-07-17T03:24:38.0380270Z - Title: An offline ReadyAgent shows in `spt endpoint run`'s picker Resume-from-history and resumes correctly — closing the gap that today only LiveAgents do. ROOT: a harness-hosted ready bind (ReadyAgent::start_homed, ready.rs) writes info.json DIRECTLY and never appends the session ledger (unlike the shared establish_perch:250 live path), so a ready agent — though it has a session_id — produces ZERO ledger rows → the picker's offline+local Resume-from-history (which gates on ledger rows) never offers it. FIX (1): ledger the ready bind (ReadyAgent::start_homed → sessions::append Boot, mirroring establish_perch). FIX (2): `spt endpoint run --resume <session>` honors the adapter MANIFEST's endpoint TYPE — a ReadyAgent manifest (no [session.psyche_init]) resumes as a ready endpoint (poll listener, NO psyche-host); a LiveAgent (with psyche_init) as live. NO new bringup mode + NO picker changes (operator 2026-06-18): `spt endpoint run` is the spt-hosted ENDPOINT bringup for BOTH types, the type IS the adapter-manifest's concern (psyche-host already keys on psyche_init presence) — so (2) likely already holds; VERIFY at code, build only the residual. (v0.12.0)
2026-07-17T03:24:38.0380720Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0380753Z 
2026-07-17T03:24:38.0381039Z ### REQ-PICKER-ADAPTER-DESCRIPTION
2026-07-17T03:24:38.0382847Z - Title: The Create-new adapter-CHOICE screen of `spt endpoint run`'s picker shows a right-hand Description panel (like the Pick-existing endpoint picker's two-pane) surfacing per-adapter detail: install date, last-updated, adapter TYPE / the endpoint types it hosts, and the adapter description — so the user can see WHAT each adapter is before choosing it (today the selector lists bare names). DEFERRED fast-follow to v0.12.0 (operator 2026-06-18). (post-v0.12.0)
2026-07-17T03:24:38.0383142Z - Required stages: 
2026-07-17T03:24:38.0383234Z 
2026-07-17T03:24:38.0383505Z ### REQ-HAZARD-VIEWER-ISOLATION
2026-07-17T03:24:38.0386389Z - Title: A slow / dead / hostile VIEWER must NEVER stall the controller, the PTY child, or the session drain thread. The broker drain fans output to the controller on the authoritative blocking bounded path (advances delivered_through) but to each viewer via a bounded per-viewer channel with a dedicated writer thread; the drain `try_send`s under the log lock and a viewer whose bounded queue OVERFLOWS (can't keep up) is EVICTED (queue dropped, writer thread ends, removed from the viewers map) — the drain thread NEVER touches a viewer socket, so no viewer write can backpressure or block it. A soft viewer cap bounds the thread count. Viewer eviction never perturbs the controller stream, the delivered_through cursor, or the child.
2026-07-17T03:24:38.0386767Z - Required stages: unit, int
2026-07-17T03:24:38.0386805Z 
2026-07-17T03:24:38.0387062Z ### REQ-INSTALL-1
2026-07-17T03:24:38.0389042Z - Title: Two install paths (harness-bootstrapped calls into standalone); OS-service registration deferred. HISTORY: originally 'signed one-line script' — the hosted one-liner retired as the PUBLIC install surface at THE-FORKENING W1/W2 (ADR-0036; the canonical bootstrap is gh + the spt install verb, REQ-INSTALL-BOOTSTRAP-VERB); installer/ scripts remain in-repo as the hermetic oneliner_e2e fixture + air-gap/mirror fallback, which is what this REQ's evidence now attests (doyle-ratified 2026-07-14).
2026-07-17T03:24:38.0389338Z - Required stages: doc, impl, int
2026-07-17T03:24:38.0389371Z 
2026-07-17T03:24:38.0389634Z ### REQ-INSTALL-2
2026-07-17T03:24:38.0389949Z - Title: Marketplace-repackaging-friendly install
2026-07-17T03:24:38.0390220Z - Required stages: doc
2026-07-17T03:24:38.0390263Z 
2026-07-17T03:24:38.0390513Z ### REQ-INSTALL-3
2026-07-17T03:24:38.0390840Z - Title: Idempotent + interactive-optional first run
2026-07-17T03:24:38.0391126Z - Required stages: impl, int
2026-07-17T03:24:38.0391169Z 
2026-07-17T03:24:38.0391422Z ### REQ-INSTALL-4
2026-07-17T03:24:38.0392309Z - Title: Adapter registration lifecycle: spt adapter add (--github, manifest-first, install-is-first-update) + soft-deregister remove + optional manifest uninstall template; node-local registered-adapter set self-update ripples over
2026-07-17T03:24:38.0392581Z - Required stages: impl, unit
2026-07-17T03:24:38.0392618Z 
2026-07-17T03:24:38.0392872Z ### REQ-MIGRATE-1
2026-07-17T03:24:38.0393213Z - Title: Auto-detect and migrate a legacy claude_skill_owl install
2026-07-17T03:24:38.0393474Z - Required stages: 
2026-07-17T03:24:38.0393508Z 
2026-07-17T03:24:38.0393755Z ### REQ-INFRA-1
2026-07-17T03:24:38.0394118Z - Title: GitHub issue tracking for v1; tangled.org as migration target
2026-07-17T03:24:38.0394485Z - Required stages: 
2026-07-17T03:24:38.0394518Z 
2026-07-17T03:24:38.0394776Z ### REQ-INSTALL-5
2026-07-17T03:24:38.0396730Z - Title: Non-interactive install path: the install path doubles as every adapter's pack-in on-demand install (no second mechanism); sha256-verified fetch; user-PATH registration. HISTORY: 'the canonical one-liner' — since THE-FORKENING (ADR-0036) the canonical path is gh + the spt install verb (itself non-interactive, REQ-INSTALL-BOOTSTRAP-VERB); the scripts this REQ's evidence attests remain as the hermetic CI fixture + air-gap fallback, still non-interactive by construction (doyle-ratified 2026-07-14).
2026-07-17T03:24:38.0397021Z - Required stages: impl, int
2026-07-17T03:24:38.0397054Z 
2026-07-17T03:24:38.0397425Z ### REQ-INSTALL-9
2026-07-17T03:24:38.0400288Z - Title: Adapter add from a GitHub release archive: `spt adapter add --release <user/repo> [--tag <tag>] [--asset <name>]` fetches a `.spt` tar asset over HTTPS+GitHub trust, extracts it to the durable adapters/_github home, and registers the root — ships built binaries source-free and versioned (the distribution path for an adapter whose dev repo is a monorepo subdir, where --github root-only clone does not fit)
2026-07-17T03:24:38.0400795Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0400950Z 
2026-07-17T03:24:38.0401372Z ### REQ-INSTALL-10
2026-07-17T03:24:38.0403810Z - Title: Windows at-logon autostart runs the daemon in the background with no persistent window: the scheduled task launches `spt daemon start` (which spawn_detaches a console-less DETACHED_PROCESS daemon and exits) rather than the foreground `spt daemon run` — Task Scheduler's interactive ONLOGON launch of a long-lived console process otherwise leaves a visible console window for the daemon's whole lifetime (v0.7.4)
2026-07-17T03:24:38.0404130Z - Required stages: impl, unit
2026-07-17T03:24:38.0404215Z 
2026-07-17T03:24:38.0404468Z ### REQ-INSTALL-11
2026-07-17T03:24:38.0406727Z - Title: Adapter command templates resolve their program against the adapter's install dir BEFORE PATH: a `.spt`-shipped binary (dropped to adapters/_github/<safe>/ by --release/--github acquisition, or kept in the source_dir under copy-mode where only manifest+strings/ are copied to adapters/<name>) runs without any PATH placement — a bare-name template token (e.g. `claude-spt-digest ...`) is rewritten to <install_dir>/<program>(.exe on Windows) when that file exists, else left bare for the PATH fallback. Makes a `.spt` self-contained (closes the --release bundled-binary gap perri confirmed) (v0.7.4)
2026-07-17T03:24:38.0407185Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0407219Z 
2026-07-17T03:24:38.0407476Z ### REQ-INSTALL-12
2026-07-17T03:24:38.0410829Z - Title: Durable active-profile pointer for bind-time profile selection (ADR-0021): adapters/active-profiles.toml at the registry ROOT (sibling to the per-adapter <name>/ dirs, so adapter add/update/remove — which only rewrite a <name>/ subdir — can never clobber it), a flat host_binary → "adapter[:profile]" map. Read at bind as the PRIMARY profile selector; unset → the registered_at_ms fallback (REQ-START-5). Written ONLY by `spt adapter use <adapter>[:profile]` (resolves the adapter's host_binaries → sets each binary→adapter[:profile]); `spt adapter use --clear <adapter|binary>` drops. NEVER auto-written by install/update/adapter add (that is precisely what would let an update silently flip the active profile). A stale pointer (uninstalled adapter / deleted profile) self-heals: ignored, fall back, warn once. Pruned on adapter remove. Atomic write (spt_store atomic). (v0.9.0)
2026-07-17T03:24:38.0411191Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0411225Z 
2026-07-17T03:24:38.0411483Z ### REQ-INSTALL-13
2026-07-17T03:24:38.0414885Z - Title: Adapter add is non-destructive & idempotent-safe (F-018): `spt adapter add --github|--release` REFUSES when the target `_github/<safe>` home already backs an ACTIVE registered record — emitting an actionable code (ADAPTER_ADD_ALREADY_REGISTERED) that routes to `spt adapter update <name>` (refresh in place) or `spt adapter remove <name>` then re-add (replace) — instead of clobbering the live install (the perri footgun: `add --github` over a `--release` pointer git-cloned a source tree over the extracted built binaries → registered pointer dangled → cryptic `os error 2`). And when it DOES (re)populate the home it STAGES-THEN-SWAPS (clone/extract to a sibling staging dir, swap into place only on success) so a failed fetch/clone never strands the previously-extracted manifest+binaries as a dangling pointer (the os-2 / DeferredManifest class). Mirrors the safe stage-then-swap `adapter update` already uses (REQ-UPD-9, apply_release_crc_swap). (v0.14.1)
2026-07-17T03:24:38.0415343Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0415381Z 
2026-07-17T03:24:38.0415638Z ### REQ-REL-1
2026-07-17T03:24:38.0417630Z - Title: HISTORICAL (superseded by ADR-0036 / REQ-RELEASE-CHANNEL-PRIVATE + REQ-DOCS-LOCAL-SERVER): spt-releases publish-target repo — README public face, licensing split, Pages docs at the ADR-0014 canonical URL. The Pages pipeline retired at THE-FORKENING (docs-publish.yml deleted W2, xtask site() deleted W3); the licensing-split artifacts (releases-repo/LICENSE-*) remain in-repo and the repo-topology story lives in CONTEXT §Project infrastructure. doc stage retained as the historical record on ADR-0014.
2026-07-17T03:24:38.0417993Z - Required stages: doc
2026-07-17T03:24:38.0418031Z 
2026-07-17T03:24:38.0418279Z ### REQ-REL-2
2026-07-17T03:24:38.0419095Z - Title: Release asset set consumable by the self-updater: platform binaries, SHA256SUMS, SignedRelease metadata, manifest schema, mock-adapter zip; tag-triggered cross-repo pipeline
2026-07-17T03:24:38.0419389Z - Required stages: impl, int
2026-07-17T03:24:38.0419422Z 
2026-07-17T03:24:38.0419697Z ### REQ-REL-3
2026-07-17T03:24:38.0420379Z - Title: Two-key release-signing trust anchor: primary + offline never-used recovery, both pubkeys embedded in the binary's trusted set, manual local signing (ADR-0015)
2026-07-17T03:24:38.0420675Z - Required stages: impl, unit
2026-07-17T03:24:38.0420774Z 
2026-07-17T03:24:38.0421032Z ### REQ-DOCS-1
2026-07-17T03:24:38.0421423Z - Title: Dual-audience docs (human + AI dev-agent), markdown once / two depths
2026-07-17T03:24:38.0421700Z - Required stages: doc, impl
2026-07-17T03:24:38.0421732Z 
2026-07-17T03:24:38.0421982Z ### REQ-DOCS-2
2026-07-17T03:24:38.0422327Z - Title: Sub-10-minute runnable killer quickstart per audience
2026-07-17T03:24:38.0422602Z - Required stages: doc, int
2026-07-17T03:24:38.0422636Z 
2026-07-17T03:24:38.0422874Z ### REQ-DOCS-3
2026-07-17T03:24:38.0423242Z - Title: Diátaxis structure; one canonical way to do X
2026-07-17T03:24:38.0423508Z - Required stages: doc
2026-07-17T03:24:38.0423547Z 
2026-07-17T03:24:38.0423794Z ### REQ-DOCS-4
2026-07-17T03:24:38.0424176Z - Title: Agent-consumable layer (llms.txt, manifest schema, MCP, CLI help)
2026-07-17T03:24:38.0424453Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0424487Z 
2026-07-17T03:24:38.0424751Z ### REQ-DOCS-5
2026-07-17T03:24:38.0425126Z - Title: Anti-drift: rustdoc/schema/exports/CLI-help generated + CI-checked
2026-07-17T03:24:38.0425416Z - Required stages: impl, int
2026-07-17T03:24:38.0425450Z 
2026-07-17T03:24:38.0425736Z ### REQ-HAZARD-GRACE-BEFORE-SIGNOFF
2026-07-17T03:24:38.0426118Z - Title: Grace-period wait completes before composing INIT_SIGNOFF (1.1)
2026-07-17T03:24:38.0426390Z - Required stages: impl, unit
2026-07-17T03:24:38.0426424Z 
2026-07-17T03:24:38.0426705Z ### REQ-HAZARD-INFO-JSON-TORN-READ
2026-07-17T03:24:38.0427039Z - Title: State-file reads tolerate concurrent writes (1.2)
2026-07-17T03:24:38.0427315Z - Required stages: impl, unit
2026-07-17T03:24:38.0427349Z 
2026-07-17T03:24:38.0427622Z ### REQ-HAZARD-STALE-INDEX-LOCK
2026-07-17T03:24:38.0427937Z - Title: Sweep stale lockfiles on daemon boot (1.3)
2026-07-17T03:24:38.0428205Z - Required stages: impl, unit
2026-07-17T03:24:38.0428238Z 
2026-07-17T03:24:38.0428519Z ### REQ-HAZARD-DEFERRED-DRAIN
2026-07-17T03:24:38.0429144Z - Title: Deferred spool rows excluded from the event-stream drain (1.4)
2026-07-17T03:24:38.0429440Z - Required stages: impl, unit
2026-07-17T03:24:38.0429473Z 
2026-07-17T03:24:38.0429749Z ### REQ-HAZARD-WORKER-PATH
2026-07-17T03:24:38.0430128Z - Title: Single source of truth for Worker/Psyche perch location (1.5)
2026-07-17T03:24:38.0430400Z - Required stages: impl, unit
2026-07-17T03:24:38.0430438Z 
2026-07-17T03:24:38.0430714Z ### REQ-HAZARD-PARENT-PID-PREFER
2026-07-17T03:24:38.0431091Z - Title: Prefer stable parent PID / broker handle over ephemeral PID (2.1)
2026-07-17T03:24:38.0431344Z - Required stages: 
2026-07-17T03:24:38.0431377Z 
2026-07-17T03:24:38.0431659Z ### REQ-HAZARD-STDIN-SESSION-ID
2026-07-17T03:24:38.0431964Z - Title: Stdin session_id precedence over env (2.2)
2026-07-17T03:24:38.0432227Z - Required stages: 
2026-07-17T03:24:38.0432260Z 
2026-07-17T03:24:38.0432537Z ### REQ-HAZARD-HANDOFF-ARGV-COMPAT
2026-07-17T03:24:38.0432878Z - Title: Broker/brain IPC + handoff argv version-tolerant (2.3)
2026-07-17T03:24:38.0433157Z - Required stages: impl, unit
2026-07-17T03:24:38.0433196Z 
2026-07-17T03:24:38.0433473Z ### REQ-HAZARD-GEN-START-NOW
2026-07-17T03:24:38.0433792Z - Title: gen_start = now() on cold-start and handoff (2.4)
2026-07-17T03:24:38.0434126Z - Required stages: impl, int
2026-07-17T03:24:38.0434197Z 
2026-07-17T03:24:38.0434479Z ### REQ-HAZARD-EPHEMERAL-CLEANUP
2026-07-17T03:24:38.0434813Z - Title: Ephemeral perch cleanup on every ring exit path (3.1)
2026-07-17T03:24:38.0435128Z - Required stages: impl, unit
2026-07-17T03:24:38.0435160Z 
2026-07-17T03:24:38.0435435Z ### REQ-HAZARD-STALE-SIGNOFF-SENTINEL
2026-07-17T03:24:38.0435806Z - Title: Stale signoff sentinel does not kill a fresh start (3.2)
2026-07-17T03:24:38.0436078Z - Required stages: impl, unit
2026-07-17T03:24:38.0436110Z 
2026-07-17T03:24:38.0436392Z ### REQ-HAZARD-ECHO-BEFORE-SIGNOFF
2026-07-17T03:24:38.0436754Z - Title: Echo-commune fires before INIT_SIGNOFF on orphan teardown (3.3)
2026-07-17T03:24:38.0437041Z - Required stages: impl, unit
2026-07-17T03:24:38.0437074Z 
2026-07-17T03:24:38.0437412Z ### REQ-HAZARD-ENVELOPE-DECODE-ORDER
2026-07-17T03:24:38.0437750Z - Title: Envelope decode order, ampersand decoded last (4.1)
2026-07-17T03:24:38.0438023Z - Required stages: impl, unit
2026-07-17T03:24:38.0438060Z 
2026-07-17T03:24:38.0438342Z ### REQ-HAZARD-ENVELOPE-CR-LINESAFE
2026-07-17T03:24:38.0440598Z - Title: Envelope CR-linesafety (4.1): the line-framed EVENT codec must neutralize raw carriage returns — `event_body_escape` folds CRLF/lone-CR to the codec's representable linebreak (`\n`→`<br>`) BEFORE framing, so a body carrying `\r` (Windows `echo`/CRLF text crossing nodes) cannot survive into the single-line envelope and trigger a receiver terminal CR→col0 overwrite that corrupts the frame. Robustness on unrepresentable input, NOT a wire-format change (decoder untouched, amp-last invariant held). Belt-and-suspenders: `spt send`/`ring` also trim stdin (parity with `notify`).
2026-07-17T03:24:38.0440889Z - Required stages: impl, unit
2026-07-17T03:24:38.0440937Z 
2026-07-17T03:24:38.0441227Z ### REQ-HAZARD-ENVELOPE-PARSER-SAFE
2026-07-17T03:24:38.0441580Z - Title: Two-slice envelope parser is panic-free and tolerant (4.2)
2026-07-17T03:24:38.0441871Z - Required stages: impl, unit
2026-07-17T03:24:38.0441905Z 
2026-07-17T03:24:38.0442185Z ### REQ-HAZARD-EVENTPART-REASSEMBLY
2026-07-17T03:24:38.0442591Z - Title: EVENT-PART split/reassembly is byte-exact; orphan parts dropped silently
2026-07-17T03:24:38.0442862Z - Required stages: impl, unit
2026-07-17T03:24:38.0442900Z 
2026-07-17T03:24:38.0443163Z ### REQ-HAZARD-ID-CHARSET
2026-07-17T03:24:38.0443607Z - Title: Addressable-id charset reserves :/@ delimiters; validated at every creation seam (4.6)
2026-07-17T03:24:38.0443875Z - Required stages: impl, unit
2026-07-17T03:24:38.0443908Z 
2026-07-17T03:24:38.0444184Z ### REQ-HAZARD-REGISTRY-STALE-CLEAN
2026-07-17T03:24:38.0444552Z - Title: Stale registry entries degrade to fallback, never hard-fail (4.3)
2026-07-17T03:24:38.0444938Z - Required stages: impl, unit
2026-07-17T03:24:38.0444978Z 
2026-07-17T03:24:38.0445253Z ### REQ-HAZARD-REGISTRY-CONCURRENT
2026-07-17T03:24:38.0445702Z - Title: Concurrent SQLite openers (registry/spool) must not fail with 'database is locked' (4.7)
2026-07-17T03:24:38.0445976Z - Required stages: impl, unit
2026-07-17T03:24:38.0446009Z 
2026-07-17T03:24:38.0446289Z ### REQ-HAZARD-REGISTRY-DIR-CREATE
2026-07-17T03:24:38.0446861Z - Title: SQLite store opens create their parent dir themselves — a fresh-home registry op must not SQLITE_CANTOPEN (4.9)
2026-07-17T03:24:38.0447147Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0447186Z 
2026-07-17T03:24:38.0447462Z ### REQ-HAZARD-REGISTRY-EPOCH-LEASE
2026-07-17T03:24:38.0448101Z - Title: Registry merge ordered by per-node monotonic epoch, never wall-clock — a stale Active can't clobber a newer Offline (4.8, red-team #8)
2026-07-17T03:24:38.0448387Z - Required stages: impl, unit
2026-07-17T03:24:38.0448421Z 
2026-07-17T03:24:38.0448705Z ### REQ-HAZARD-DEFERRED-SURVIVE-DRAIN
2026-07-17T03:24:38.0449121Z - Title: Deferred rows survive poll drain (4.4)
2026-07-17T03:24:38.0449421Z - Required stages: impl, unit
2026-07-17T03:24:38.0449460Z 
2026-07-17T03:24:38.0449735Z ### REQ-HAZARD-INBOX-NO-DOUBLE
2026-07-17T03:24:38.0450104Z - Title: No double-delivery via legacy inbox (4.5)
2026-07-17T03:24:38.0450380Z - Required stages: impl, unit
2026-07-17T03:24:38.0450413Z 
2026-07-17T03:24:38.0450684Z ### REQ-HAZARD-WINDOWS-PID-RECYCLE
2026-07-17T03:24:38.0451027Z - Title: Windows PID-recycling false positives guarded (5.1)
2026-07-17T03:24:38.0451296Z - Required stages: impl, unit
2026-07-17T03:24:38.0451329Z 
2026-07-17T03:24:38.0451601Z ### REQ-HAZARD-EBUSY-RENAME
2026-07-17T03:24:38.0451944Z - Title: tmp-write + atomic-rename + retry on Windows EBUSY (5.2)
2026-07-17T03:24:38.0452221Z - Required stages: impl, unit
2026-07-17T03:24:38.0452259Z 
2026-07-17T03:24:38.0452535Z ### REQ-HAZARD-PERCH-RECORD-POWER-LOSS
2026-07-17T03:24:38.0453281Z - Title: Authoritative/identity records fsync data before the rename (5.13): a hard reset must not resurrect a full-length NUL-filled record — SCOPED, not a blanket fsync
2026-07-17T03:24:38.0453639Z - Required stages: impl, unit
2026-07-17T03:24:38.0453676Z 
2026-07-17T03:24:38.0453956Z ### REQ-HAZARD-ATOMIC-TMP-COLLISION
2026-07-17T03:24:38.0454645Z - Title: Concurrent atomic writers to the same target must not share a tmp name (5.15): a fixed tmp sibling makes one writer's rename consume the other's staged file (os-error-2 loser)
2026-07-17T03:24:38.0454932Z - Required stages: impl, unit
2026-07-17T03:24:38.0454960Z 
2026-07-17T03:24:38.0455242Z ### REQ-HAZARD-INFO-RMW-LOST-UPDATE
2026-07-17T03:24:38.0455862Z - Title: Concurrent info.json writers must serialize under the per-perch lock (5.16): an unlocked whole-record write racing a locked RMW is a silent lost update
2026-07-17T03:24:38.0456138Z - Required stages: impl, unit
2026-07-17T03:24:38.0456172Z 
2026-07-17T03:24:38.0456465Z ### REQ-HAZARD-CORRUPT-PERCH-COHERENCE
2026-07-17T03:24:38.0457131Z - Title: Corrupt (present-but-unparseable) info.json is NOT absent: liveness/status readers agree a destroyed record is neither alive nor Active (counter-39 #2)
2026-07-17T03:24:38.0457421Z - Required stages: impl, unit
2026-07-17T03:24:38.0457456Z 
2026-07-17T03:24:38.0457736Z ### REQ-HAZARD-SUBPROCESS-TIMEOUT
2026-07-17T03:24:38.0458070Z - Title: Every harness/git subprocess has a timeout (5.3)
2026-07-17T03:24:38.0458341Z - Required stages: impl, unit
2026-07-17T03:24:38.0458371Z 
2026-07-17T03:24:38.0458646Z ### REQ-HAZARD-UNC-PATH-STRIP
2026-07-17T03:24:38.0459072Z - Title: Strip Windows UNC prefix on serialized paths (5.4)
2026-07-17T03:24:38.0459366Z - Required stages: impl, unit
2026-07-17T03:24:38.0459399Z 
2026-07-17T03:24:38.0459681Z ### REQ-HAZARD-SINGLE-PATH-SOURCE
2026-07-17T03:24:38.0460048Z - Title: Single path/registry source of truth; no layout ambiguity (6.1)
2026-07-17T03:24:38.0460315Z - Required stages: impl, unit
2026-07-17T03:24:38.0460349Z 
2026-07-17T03:24:38.0460730Z ### REQ-HAZARD-SOFT-CLEANUP
2026-07-17T03:24:38.0461110Z - Title: Soft-cleanup preserves state, removes only the ready marker (6.2)
2026-07-17T03:24:38.0461379Z - Required stages: impl, unit
2026-07-17T03:24:38.0461421Z 
2026-07-17T03:24:38.0461696Z ### REQ-HAZARD-CASCADE-WIPE-GUARD
2026-07-17T03:24:38.0462058Z - Title: No hard-delete of a parent hosting non-empty children (6.3)
2026-07-17T03:24:38.0462329Z - Required stages: impl, unit
2026-07-17T03:24:38.0462362Z 
2026-07-17T03:24:38.0462648Z ### REQ-HAZARD-DROP-FILE-SINGLE-WRITER
2026-07-17T03:24:38.0462977Z - Title: Drop files are daemon-owned single-writer (6.4)
2026-07-17T03:24:38.0463245Z - Required stages: impl, unit
2026-07-17T03:24:38.0463278Z 
2026-07-17T03:24:38.0463569Z ### REQ-HAZARD-DIRECT-WRITE-PRECEDENCE
2026-07-17T03:24:38.0463973Z - Title: Direct-write precedence marker (with node id) guards stale overwrite (6.5)
2026-07-17T03:24:38.0464246Z - Required stages: impl, unit
2026-07-17T03:24:38.0464279Z 
2026-07-17T03:24:38.0464573Z ### REQ-HAZARD-CONFLICT-BOTH-PRESERVED
2026-07-17T03:24:38.0465390Z - Title: A surfaced concurrent context pair is durably preserved (both versions, tracked artifacts) until a strictly dominating write clears it; no reconcile failure path discards an unmerged version (6.6, ADR-0013)
2026-07-17T03:24:38.0465720Z - Required stages: impl, unit
2026-07-17T03:24:38.0465754Z 
2026-07-17T03:24:38.0466049Z ### REQ-HAZARD-DETACHED-PIPE-INHERIT
2026-07-17T03:24:38.0467500Z - Title: Windows detached long-lived children must not inherit a captured caller's pipe: every detach-spawn of an immortal child (daemon, shell binary) runs bInheritHandles=FALSE, or a caller capturing output anywhere up the process chain hangs forever on a pipe that never EOFs — std-handle flag stripping is NOT sufficient (grandparent strays still flow) (5.6)
2026-07-17T03:24:38.0467782Z - Required stages: impl, unit
2026-07-17T03:24:38.0467815Z 
2026-07-17T03:24:38.0468087Z ### REQ-HAZARD-CONPTY-DSR
2026-07-17T03:24:38.0468487Z - Title: ConPTY reader must auto-answer DSR (ESC[6n) or all child output stalls (5.5)
2026-07-17T03:24:38.0468835Z - Required stages: impl, unit
2026-07-17T03:24:38.0468868Z 
2026-07-17T03:24:38.0469299Z ### REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE
2026-07-17T03:24:38.0471652Z - Title: Native-PTY spawn must resolve a bare program name with PATHEXT precedence and run a non-PE target through its interpreter: portable-pty's own `which` takes the FIRST PATH match — an extensionless shebang shim (e.g. a node CLI `ccs` shipped beside `ccs.cmd`) — and CreateProcessW then rejects the non-PE file with os error 193 ('not a valid Win32 application'); spt-term resolves the program itself (PATHEXT order prefers .EXE over .CMD; .cmd/.bat → cmd.exe /d /c, .ps1 → powershell -NoProfile -File) so a bare harness/shell [session.self] command actually launches on Windows. Unix is a passthrough (execve honours the shebang).
2026-07-17T03:24:38.0471957Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0471990Z 
2026-07-17T03:24:38.0472270Z ### REQ-HAZARD-CHILD-CONSOLE-FLASH
2026-07-17T03:24:38.0472937Z - Title: Console-subsystem children of the console-less daemon spawn with CREATE_NO_WINDOW, or each spawn flashes a visible blank window on the user's desktop (5.8)
2026-07-17T03:24:38.0473227Z - Required stages: impl, unit
2026-07-17T03:24:38.0473256Z 
2026-07-17T03:24:38.0473538Z ### REQ-HAZARD-INSTANT-UNDERFLOW
2026-07-17T03:24:38.0474353Z - Title: Scheduling never subtracts a Duration from Instant::now() (underflow-panics on a host booted more recently than the offset); 'due now / never run' is Option<Instant>=None gated on forward duration_since only (5.9)
2026-07-17T03:24:38.0474633Z - Required stages: impl, unit
2026-07-17T03:24:38.0474658Z 
2026-07-17T03:24:38.0474943Z ### REQ-HAZARD-PUMP-IPC-DEADLINE
2026-07-17T03:24:38.0476076Z - Title: The single-threaded peer pump's brain-IPC reads are deadline-bounded (PUMP_PEER_IO_TIMEOUT, total-wait per call); a TimedOut read POISONS the client and escalates to a SUPERVISED RESTART, never a per-peer retry — a black-holed peer must never wedge the whole pump
2026-07-17T03:24:38.0476576Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0476609Z 
2026-07-17T03:24:38.0476886Z ### REQ-HAZARD-BROKER-QUIC-DEADLINE
2026-07-17T03:24:38.0480758Z - Title: The broker bounds every brain-waiting QUIC op (dial / open_stream / send_stream) so a black-holed or dead peer fails PROMPTLY with an ORDINARY error the broker REPLIES, never an unbounded await. The bound (< the brain's 30s PUMP_PEER_IO_TIMEOUT so the BROKER fires first) surfaces to the pump as a normal broker error reply → peer_outcome's non-TimedOut arm → drop conn + redial next tick, the round CONTINUES and the heartbeat keeps advancing — it must NEVER manifest as the brain's own read-deadline (the A-half poison → supervised-restart path REQ-HAZARD-PUMP-IPC-DEADLINE guards). Exactly-once is preserved: a timed-out journaled op fails INSIDE its apply_once closure so no phantom conn_id/stream_id is recorded and a fresh tick re-dials cleanly. The happy path is unchanged (a live peer completes with zero added latency; the bound only bites a non-responsive peer). This is the ROOT-cause cure for the 2.2h hfenduleam pump wedge — a dead roster peer whose QUIC path the broker awaited unbounded — recurring on hfenduleam 2026-06-16.
2026-07-17T03:24:38.0481164Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0481197Z 
2026-07-17T03:24:38.0481479Z ### REQ-HAZARD-BROKER-SEED-WIRE-SKEW
2026-07-17T03:24:38.0485896Z - Title: A daemon-state wire-format change (e.g. the v0.9.0 adapter-agnostic Seed) does NOT take effect until a DELIBERATE full broker restart: the broker serves the seed-control channel and is RESIDENT across a brain-only self-update (ADR-0004 no-terminate-during-update forbids auto-killing it), so a NEW-version CLI talking to a still-resident OLD broker fails the seed handshake — the old broker cannot deserialize the new Seed (its formerly-required `adapter` field is gone) and drops the conn without an ack, which surfaces to the CLI as a raw UnexpectedEof 'failed to fill whole buffer'. spt-core must (a) surface an ACTIONABLE diagnostic on that seed-ack EOF (name the stale-broker cause + the `spt daemon stop` fix — the broker restarts on the next api call), never the cryptic io error; and (b) document the operational rule (a deliberate broker restart is required on any daemon-state wire change — NOT automatic) + the FORWARD discipline (daemon-state/Seed schema changes stay additive + serde-default so a resident OLD broker tolerates a NEW CLI across a brain-only update; note this would NOT have rescued 0.9.0 itself, since the old broker's `adapter` was a required field). perri PREP-4 FINDING 1 (v0.9.0 CLI vs stale 0.8.x broker).
2026-07-17T03:24:38.0486364Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0486397Z 
2026-07-17T03:24:38.0486683Z ### REQ-HAZARD-SUDO-SECURE-PATH
2026-07-17T03:24:38.0487857Z - Title: Elevation guidance on Unix names the binary's ABSOLUTE path under sudo (a user-local install ~/.local/bin · ~/.cargo/bin is not on sudo's secure_path, so bare `sudo spt` dies 'command not found'); gated commands auto-elevate on an interactive TTY, else print the runnable hint (5.10)
2026-07-17T03:24:38.0488174Z - Required stages: impl, unit
2026-07-17T03:24:38.0488208Z 
2026-07-17T03:24:38.0488482Z ### REQ-HAZARD-SELF-ELEVATE
2026-07-17T03:24:38.0491275Z - Title: Self-elevation (REQ-ELEVATE-1) re-runs the EXACT original invocation with the binary's ABSOLUTE exe path — never widening privilege scope, never adding/altering args, never via a PATH-resolved bare name, never via a shell-interpolated command string (argv-array only, no `sh -c`); the elevated child drops state back to the user (composes with the 5.7 de-elevation) and NEVER re-elevates (loop-safe: decide_elevation_path returns AlreadyElevated whenever the process is already Elevated, on every OS). The user's UAC/polkit/sudo prompt is the only consent gate — we never bypass it; the print-hint floor prints the absolute-path command too. The unprivileged parent never depends on (pipes/captures) the privileged child's stdout.
2026-07-17T03:24:38.0491676Z - Required stages: unit
2026-07-17T03:24:38.0491720Z 
2026-07-17T03:24:38.0491991Z ### REQ-HAZARD-LOCAL-API-AUTH
2026-07-17T03:24:38.0492396Z - Title: Every local `api` mutation authenticated to an endpoint/session (codex #13)
2026-07-17T03:24:38.0492683Z - Required stages: impl, unit
2026-07-17T03:24:38.0492716Z 
2026-07-17T03:24:38.0492998Z ### REQ-BOUNDARY-ROTATION-CREDENTIAL
2026-07-17T03:24:38.0494776Z - Title: api boundary's rotation credential is designed, documented, and eventually anchor-proven (ADR-0032): the proof is the DEPARTED session's (prior sid / token) — --to-session-id is payload, never proof; the published surface documents the adapter prior-sid persistence pattern + loud-refusal requirement; the design-true end-state additionally accepts an OS-verified parent_pid-anchor ancestry proof making adapter sid-state optional
2026-07-17T03:24:38.0495058Z - Required stages: doc
2026-07-17T03:24:38.0495091Z 
2026-07-17T03:24:38.0495392Z ### REQ-HAZARD-RESTART-IDEMPOTENT
2026-07-17T03:24:38.0495851Z - Title: Idempotent/exactly-once delivery across brain restart at every broker boundary (codex #14)
2026-07-17T03:24:38.0496134Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0496229Z 
2026-07-17T03:24:38.0496509Z ### REQ-HAZARD-UPDATE-ROLLBACK
2026-07-17T03:24:38.0496962Z - Title: Self-update rejects version rollback; metadata expiry + adapter content signing (codex #5)
2026-07-17T03:24:38.0497238Z - Required stages: impl, unit
2026-07-17T03:24:38.0497272Z 
2026-07-17T03:24:38.0497558Z ### REQ-HAZARD-DAEMON-HOSTED-LIVENESS
2026-07-17T03:24:38.0498248Z - Title: Daemon-hosted perches (Psyche, spt-hosted Self) derive liveness from the daemon endpoint table + info.json status, never is_process_alive(info.pid) (2.5)
2026-07-17T03:24:38.0498540Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0498572Z 
2026-07-17T03:24:38.0498857Z ### REQ-HAZARD-BROKER-PROCESS-ISOLATION
2026-07-17T03:24:38.0502145Z - Title: Broker and brain are separate processes: the broker runs as its own long-lived per-machine process that survives every brain restart, so a routine (brain-only) self-update restarts the brain onto the swapped binary while every hosted endpoint (PTY child, live QUIC conn, listening socket) stays untouched at the PROCESS level. The in-process-thread broker (daemon.rs:165-170) is a regression that silently unrealizes REQ-UPD-3 — apply degrades to an in-process Brain::handoff no-op and new code does not run until an unrelated restart (KNOWN-HAZARDS 6.7). Evidence must prove process-level survival (SPIKE-01/03 productionized as int: PTY child + live QUIC survive a brain-PROCESS restart onto a swapped binary), re-pointing the regression-masked in-process int tags currently on REQ-DAEMON-2 / REQ-UPD-3 (ADR-0018).
2026-07-17T03:24:38.0502532Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0502565Z 
2026-07-17T03:24:38.0502846Z ### REQ-HAZARD-ROLLBACK-STATE-COMPAT
2026-07-17T03:24:38.0504955Z - Title: A brain must not irreversibly migrate durable state before update ready-promotion: the readiness-gated auto-rollback (ADR-0018 Q7) spawns the N-1 binary against durable state the new brain may have written, so every pre-ready write must stay N-1-readable (schema migrations gated behind ready-promotion, or written N-1-tolerant/additive). Else the first in-place schema migration silently bricks rollback (KNOWN-HAZARDS 6.8). Free now — a 2026-06-09 audit confirmed zero state-migration code exists; unmintable retroactively once a migration ships.
2026-07-17T03:24:38.0505270Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0505303Z 
2026-07-17T03:24:38.0505590Z ### REQ-HAZARD-BRAIN-RESPAWN-PATH
2026-07-17T03:24:38.0508614Z - Title: The broker respawns the brain onto the APPLIED bytes, not the renamed old binary: the candidate-binary default is the canonical exe path captured ONCE at broker start, never a per-spawn std::env::current_exe() — on Linux current_exe (readlink /proc/self/exe) is inode-tracking and follows the `apply` rename (spt -> spt.old-N), so a resident broker would respawn the brain onto OLD bytes while recording `applied` (Windows GetModuleFileName is path-at-start, so Windows was green; ADR-0018 Q3 silently assumed path-string semantics). Backstop: promotion gates on bytes — a trial promotes only if brain.ready exe_hash == the staged artifact hash for this platform, else auto-rollback + loud notif (readiness != new-bytes was the false-success that recorded applied:8 over a v0.4.0 brain on kitsubito, 2026-06-11). KNOWN-HAZARDS 6.11.
2026-07-17T03:24:38.0509138Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0509175Z 
2026-07-17T03:24:38.0509455Z ### REQ-HAZARD-PSYCHE-OUTBOUND-PROXY
2026-07-17T03:24:38.0510567Z - Title: Psyche outbound captured + sanitized: the live-Psyche turn driver captures stdout (never Stdio::null), and the daemon strips/re-stamps Psyche-supplied from=/target and constrains routing (reply→__REPLY_TO__ sender, notify→own user/subnet) (7.3)
2026-07-17T03:24:38.0510842Z - Required stages: impl, unit
2026-07-17T03:24:38.0510895Z 
2026-07-17T03:24:38.0511186Z ### REQ-HAZARD-DAEMON-SCHED-NONBLOCKING
2026-07-17T03:24:38.0512114Z - Title: Per-agent pulse/psyche/echo-commune scheduling must not serialize across agents: each agent's bounded LLM call (echo-commune summarizer, Psyche turn) runs off the shared scheduler so one slow/hung call cannot stall another agent's tick (7.4)
2026-07-17T03:24:38.0512586Z - Required stages: impl, unit
2026-07-17T03:24:38.0512621Z 
2026-07-17T03:24:38.0512910Z ### REQ-HAZARD-PAIR-TRANSCRIPT-BIND
2026-07-17T03:24:38.0513813Z - Title: Pairing transcript binds roles, both node pubkeys, subnet ID, seed epoch, TOTP time-step, and confirmation MACs — or unknown-key-share/reflection/wrong-subnet/replay pairing remain possible (ADR-0005 #12)
2026-07-17T03:24:38.0514099Z - Required stages: impl, unit
2026-07-17T03:24:38.0514133Z 
2026-07-17T03:24:38.0514406Z ### REQ-HAZARD-PAIR-SEED-ROTATION
2026-07-17T03:24:38.0515177Z - Title: Removing a node rotates the subnet seed (epoch bump) so an old node/old seed cannot rejoin; trust-store delete alone is NOT revocation because the seed is replicated to every trusted node (ADR-0005 #10)
2026-07-17T03:24:38.0515624Z - Required stages: impl, unit
2026-07-17T03:24:38.0515664Z 
2026-07-17T03:24:38.0515973Z ### REQ-HAZARD-PAIR-RATE-LIMIT
2026-07-17T03:24:38.0517178Z - Title: Subnet-global pairing rate limit: one active ceremony per subnet, shared attempt counter, exponential backoff — a public pre-trust relay + multiple seed-holders otherwise enables distributed SPAKE2 guessing (and ±1 TOTP window triples the valid-password space) (ADR-0005 #11)
2026-07-17T03:24:38.0517462Z - Required stages: impl, unit
2026-07-17T03:24:38.0517495Z 
2026-07-17T03:24:38.0517767Z ### REQ-HAZARD-WAN-ORIGIN-AUTH
2026-07-17T03:24:38.0518835Z - Title: WAN-inbound origin is transport truth, never payload: the access gate's subject (ADR-0009 origin-node whitelist) is the QUIC handshake-proven remote node id from the broker's conn/stream table — a forged origin/node field inside record bytes is inert (7.5)
2026-07-17T03:24:38.0519218Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0519260Z 
2026-07-17T03:24:38.0519514Z ### REQ-CONSENT-1
2026-07-17T03:24:38.0520773Z - Title: Consent grant store: capability x subject-agent x target-node rows, enforced at the target node, subnet-settable (replicates as security material near the trust store), revocable; gated-capability ids (remote-exec, instantiate-anywhere) reserved-but-refusing; v1 consumers are the shell spawn gates (CONTEXT Consent & security gates)
2026-07-17T03:24:38.0521068Z - Required stages: impl, unit
2026-07-17T03:24:38.0521102Z 
2026-07-17T03:24:38.0521349Z ### REQ-CONSENT-2
2026-07-17T03:24:38.0522485Z - Title: Interactive consent escalation: an ungated high-risk action routes a consent prompt to the user's most-recently-active session; allow-once / allow-always (writes a grant) / deny; pre-consent flags (can_shutdown, shell_wake_spawn_anywhere) author grants via manifest/settings (CONTEXT Consent & security gates)
2026-07-17T03:24:38.0522875Z - Required stages: impl, unit
2026-07-17T03:24:38.0522908Z 
2026-07-17T03:24:38.0523171Z ### REQ-PRES-1
2026-07-17T03:24:38.0524923Z - Title: Presence resolution: the presence datum (last_active_node, last_active_endpoint, ts) gossiped subnet-wide via the agent-interaction heartbeat (rides registry distribution, visibility-gated) + one first-class most-recently-active resolution API consumed by notif first-fire, update-consent delivery, consent escalation, and shell wake resolution (M5 scope decision 1: resolution only — the PresenceChannel endpoint stays deferred)
2026-07-17T03:24:38.0525217Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0525250Z 
2026-07-17T03:24:38.0525503Z ### REQ-SHELL-1
2026-07-17T03:24:38.0526743Z - Title: Shell hosting machinery: shell perch under the owner (type/owner/adapter_name/status/alias), broker-launched binary + api bind local-link handshake, the three channels (command durable, text+file durable + progress-queryable, sensory REST-only never spooled + dropped-unless-owner-live), owner exclusivity (CONTEXT Shell model)
2026-07-17T03:24:38.0527043Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0527077Z 
2026-07-17T03:24:38.0527324Z ### REQ-SHELL-2
2026-07-17T03:24:38.0529367Z - Title: Shell sleep/wake: link-break always closes the binary (pre-close instruction + termination timeout), ephemeral teardown vs persistent offline/relink, wake_command wake-watcher (offline-only, exit-opcode supervision, exponential backoff + give-up), state-keyed wake resolution (dormant/suspended/active-elsewhere; no-reachable refuses — spawn-anywhere branch deferred), spt shutdown owner cascade + api owner-shutdown gated by can_shutdown (CONTEXT Shell sleep/wake)
2026-07-17T03:24:38.0529662Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0529696Z 
2026-07-17T03:24:38.0529977Z ### REQ-HAZARD-ELEVATED-DAEMON-SPAWN
2026-07-17T03:24:38.0531662Z - Title: The daemon always runs unelevated in the invoking user's universe, regardless of which command spawns it: an elevated spawner de-elevates (Windows: UAC linked token via CreateProcessWithTokenW; Linux: drop to SUDO_UID/SUDO_GID + the invoker's HOME) — an elevated daemon's pipes deny unelevated clients (every later spt reads not-running→spawn→bind Access-denied) and a sudo'd daemon roots the user's state universe (5.7)
2026-07-17T03:24:38.0532044Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0532077Z 
2026-07-17T03:24:38.0532368Z ### REQ-HAZARD-REGISTRY-GHOST-ROWS
2026-07-17T03:24:38.0536068Z - Title: Registry rows must decay (no immortal rows) via TWO triggers: (a) NODE-SILENCE — evict rows whose author node has not been heard (admitted inbound feed) within the eviction window, so a vanished node's rows stop poisoning bare-id resolution with phantom AcrossNodes ambiguity; AND (b) per-row OFFLINE-TTL — evict rows that have been non-routable (Offline) beyond the per-row grace even while the author node is alive, because purge/erase leaves an immortal Offline row otherwise (ghost-heal re-advertises Offline ONCE with a fresh epoch, and whole-node eviction never fires for a still-alive author) so Offline ghost rows accumulate unbounded on a remote viewer under purge/erase churn (#2-secondary). Both keyed on RECEIVER-observed state (heard-map recency / a sticky receiver-observed offline_since, NOT the gossip epoch — an epoch-keyed clock would be reset by ghost-heal's fresh-epoch re-advertise); own rows never decay; a revived/re-flapped row re-inserts (or clears its offline_since) from its durable epoch within one pump cadence (4.10)
2026-07-17T03:24:38.0536416Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0536449Z 
2026-07-17T03:24:38.0536702Z ### REQ-CLI-1
2026-07-17T03:24:38.0539779Z - Title: spt endpoint noun namespace: absorbs fork/suspend/wake/shutdown/rename/stop/digest + access (ported 1:1: allow|revoke|open|list, decision 21) + description (ex-resources blurb; bare=show, set=author); merged endpoint list [--local|--subnet <name>] grouped by subnet with SELF pinned, --detail adding the ex-resources yellow-pages blurb projection; bare spt endpoint = the list (M8 decisions 1-2, 25). SUPERSEDED (F-025 item 3): the LISTING SHAPE now lives in REQ-ENDPOINT-LIST-NODE-GROUPED (node-grouped over unique instances, not grouped-by-subnet) + REQ-ENDPOINT-LIST-REST-FILTER (suspended-hidden + --show-all); the `--local` flag was dropped by REQ-ENDPOINT-LIST-MERGE-LOCAL (the list ALWAYS merges local). This REQ owns only the endpoint noun NAMESPACE + parse surface — not the render shape.
2026-07-17T03:24:38.0540203Z - Required stages: impl, unit
2026-07-17T03:24:38.0540237Z 
2026-07-17T03:24:38.0540494Z ### REQ-CLI-2
2026-07-17T03:24:38.0541473Z - Title: spt daemon noun: run|stop|status (hidden daemon verb becomes daemon run; agent-endpoint shutdown keeps its name under endpoint); daemon status renders the pump heartbeat (last-tick recency) so a half-dead daemon is never rendered implied-healthy (M8 decisions 5, 23)
2026-07-17T03:24:38.0541755Z - Required stages: impl, unit
2026-07-17T03:24:38.0541792Z 
2026-07-17T03:24:38.0542051Z ### REQ-CLI-3
2026-07-17T03:24:38.0543061Z - Title: Agent hot path stays flat across the M8 reorg: send/ring/ready/whoami/how-to unchanged; notify moves to subnet notify while notif stays top-level; breaking renames land clean with no deprecation shims (zero external CLI consumers pre-spt-claude-code) (M8 decisions 3-4, 9)
2026-07-17T03:24:38.0543414Z - Required stages: impl, unit
2026-07-17T03:24:38.0543448Z 
2026-07-17T03:24:38.0543695Z ### REQ-CLI-4
2026-07-17T03:24:38.0546242Z - Title: User-facing CLI output is human-readable: DIRECT-USER commands (e.g. adapter update/list/use) render friendly prose instead of raw CODE:RESULT markers — "claude-spt is up to date (0.2.0)." not "ADAPTER_UPDATE_UPTODATE:claude-spt: installed 0.2.0, latest 0.2.0". Strictly bounded to the direct-user surface: the adapter-PARSED bringup tokens (SEEDED/BOUND/READY/NO_SEED on seed/listen, which adapters grep) stay machine-parseable — humanization is additive (a human line beside the marker, or a --porcelain/--quiet split), never a silent rename of a dual-contract marker. The user-facing bringup composition belongs to the adapter (perri); this REQ owns only the direct-user CLI surface. (v0.9.0)
2026-07-17T03:24:38.0546586Z - Required stages: 
2026-07-17T03:24:38.0546628Z 
2026-07-17T03:24:38.0546881Z ### REQ-SUBNET-5
2026-07-17T03:24:38.0548332Z - Title: Per-subnet serve-state: spt subnet detach <NAME> [--save] / attach <NAME> [--save] — daemon keeps running, stops/starts advertising + connecting for that subnet (peer pump + responder selective); --save persists the startup default in daemon config; the all-attached banner gains per-subnet states (M8 decision 6, --save renamed from --auto per decision 25 session)
2026-07-17T03:24:38.0548608Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0548637Z 
2026-07-17T03:24:38.0548892Z ### REQ-SUBNET-6
2026-07-17T03:24:38.0549944Z - Title: Trust lifecycle verbs, elevation-gated: spt subnet leave <NAME> (membership exit) and spt subnet prune <node> (removes a dead identity's trust + registry rows, killing its dead dials; trust mutation = security surface, REQ-PAIR-6 gate machinery) (M8 decisions 6-7)
2026-07-17T03:24:38.0550240Z - Required stages: impl, unit
2026-07-17T03:24:38.0550273Z 
2026-07-17T03:24:38.0550540Z ### REQ-SUBNET-7
2026-07-17T03:24:38.0552540Z - Title: Per-machine re-pair trust overwrite: registry rows carry a hashed stable machine identifier (OS machine id /etc/machine-id|MachineGuid, domain-separated SHA-256 before gossip, spt-minted persisted UUID fallback; additive serde-default field — old rows parse clean); a COMPLETED pairing ceremony presenting the same node label AND machine id as an existing trusted row evicts the superseded identity's trust + registry rows on the seed-holder and replicates the eviction; a gossiped claim alone never evicts trust (M8 decisions 13, 22)
2026-07-17T03:24:38.0552831Z - Required stages: impl, unit
2026-07-17T03:24:38.0552869Z 
2026-07-17T03:24:38.0553117Z ### REQ-SUBNET-8
2026-07-17T03:24:38.0554513Z - Title: Status render honesty: zero-subnet text is daemon-aware ('No subnets registered — this node is standalone.' + daemon-running-dependent blurb, never implying messaging works while the daemon is down); hint footer prints on bare spt subnet only (status drops it); a stalled pump is surfaced in subnet status, never rendered implied-healthy (M8 decisions 11-12, 23)
2026-07-17T03:24:38.0554974Z - Required stages: impl, unit
2026-07-17T03:24:38.0554998Z 
2026-07-17T03:24:38.0555256Z ### REQ-INSTALL-6
2026-07-17T03:24:38.0556887Z - Title: Linux elevation install leg: install.sh symlinks the binary into a sudo-reachable path (/usr/local/bin; graceful print-the-one-liner when unelevated) so sudo spt resolves; first sudo spt detects elevation and prompts ONCE for the default user account — thereafter any elevated daemon launch runs daemon + state under that account, never root (KH 5.7 interplay verified) (M8 decision 8)
2026-07-17T03:24:38.0557169Z - Required stages: impl, unit
2026-07-17T03:24:38.0557202Z 
2026-07-17T03:24:38.0557479Z ### REQ-INSTALL-7
2026-07-17T03:24:38.0558906Z - Title: Windows inbound reachability: the elevated install leg registers the inbound-UDP firewall rule (New-NetFirewallRule); the daemon self-detects blocked inbound and renders it as the no-connection state in subnet status + the coming-online banner (covers user-scope installs that skip the elevated leg — never a silent NO_SEED_HOLDER dead-end) (M8 root cause 3)
2026-07-17T03:24:38.0559325Z - Required stages: impl
2026-07-17T03:24:38.0559358Z 
2026-07-17T03:24:38.0559614Z ### REQ-INSTALL-8
2026-07-17T03:24:38.0561057Z - Title: OS-service registration (REQ-INSTALL-1's deferred third leg): Linux systemd USER service + loginctl enable-linger (linger rides the elevated install leg; daemon starts at boot pre-login, user universe per KH 5.7, systemctl --user managed); Windows scheduled task at-logon (interactive session, no stored credentials); a node is reachable after reboot without any manual spt invocation (M8 decision 17)
2026-07-17T03:24:38.0561347Z - Required stages: impl
2026-07-17T03:24:38.0561381Z 
2026-07-17T03:24:38.0561686Z ### REQ-CONV-1
2026-07-17T03:24:38.0563490Z - Title: Peer address seeding, both cold starts: durable peer-addrs.json (identity dir) maps peer pubkey → last-known dialable address; the pump's resolver consults it FIRST with id-only discovery fallback on miss or dial failure (a stale addr never strands a peer); written by the pairing ceremony (both sides, from the live connection) and by the pump on successful connect; post-join first sync and post-restart resync converge in seconds, not ~1 min (M8 decisions 14, 20)
2026-07-17T03:24:38.0563809Z - Required stages: impl, unit
2026-07-17T03:24:38.0563839Z 
2026-07-17T03:24:38.0564087Z ### REQ-CONV-2
2026-07-17T03:24:38.0565544Z - Title: Event-driven advertisement: endpoint online/offline transitions (ready-listener start/stop, rest-state transition, perch death) trigger an immediate advertise_local + peer push as a WAKE of the existing pump loop (no second advertisement path — epoch lease + visibility gates ride unchanged); the cadence stays the steady-state floor (M8 decision 15)
2026-07-17T03:24:38.0565840Z - Required stages: impl, unit
2026-07-17T03:24:38.0565873Z 
2026-07-17T03:24:38.0566135Z ### REQ-PAIR-8
2026-07-17T03:24:38.0567969Z - Title: NTP TOTP offset: the pairing ceremony queries NTP at ceremony time (both sides) and applies the derived offset to the TOTP calculation in-process only; system-clock fallback when NTP is unreachable (offline LAN pairing unaffected — NTP failure never blocks a pairing that succeeds today); never sets the OS clock; no background sync loop (M8 decision 18; field trigger: enlyzeam clock >1 min off exceeds the ±1 window)
2026-07-17T03:24:38.0568293Z - Required stages: impl, unit
2026-07-17T03:24:38.0568330Z 
2026-07-17T03:24:38.0568583Z ### REQ-DAEMON-5
2026-07-17T03:24:38.0570343Z - Title: Pump liveness: the peer pump writes a last-tick heartbeat consumed by daemon status / subnet status (decision 23 render legs in REQ-CLI-2/REQ-SUBNET-8); the daemon supervises the pump task — a panic is caught, logged loudly, and the pump restarts with capped backoff (≤5 min), so a 5.9-class death self-heals visibly instead of silently halving the daemon (M8 decision 23; field motivation: hfenduleam 2026-06-07 half-death)
2026-07-17T03:24:38.0570798Z - Required stages: impl, unit
2026-07-17T03:24:38.0570826Z 
2026-07-17T03:24:38.0571074Z ### REQ-DAEMON-6
2026-07-17T03:24:38.0573459Z - Title: Service-aware `daemon start`/`stop`: when an OS service manager has a registered spt-daemon for this user, `spt daemon start` and `spt daemon stop` drive THAT service (so stop doesn't IPC-kill a unit that auto-restart-fights for the broker socket — the kitsubito 2026-06-08 loop). `start` graduates from a `run` alias to a first-class background verb (ensure-up, idempotent, non-blocking); stop routes managed→manager, manual→IPC. Linux=systemd user unit (`systemctl --user start|stop|is-active spt-daemon`, detected by unit-file presence); Windows=no controllable manager (the logon task is boot-only), so start=detached spawn / stop=IPC.
2026-07-17T03:24:38.0573788Z - Required stages: impl, unit
2026-07-17T03:24:38.0573821Z 
2026-07-17T03:24:38.0574064Z ### REQ-DAEMON-7
2026-07-17T03:24:38.0575857Z - Title: `daemon run` is foreground-consistent on every platform: the invoking process IS the daemon, blocks until signalled, never auto-detaches or respawns into an invisible background task. The detached/de-elevated background behavior lives ONLY in `start`. Windows: an ELEVATED `daemon run` refuses with guidance (use `start`, or an unelevated shell) instead of respawning detached/de-elevated and vanishing (KH 5.7 preserved — it still never serves elevated).
2026-07-17T03:24:38.0576366Z - Required stages: impl, unit
2026-07-17T03:24:38.0576414Z 
2026-07-17T03:24:38.0576690Z ### REQ-DAEMON-8
2026-07-17T03:24:38.0577951Z - Title: Internal auto-start prefers the service: `ensure_running` (any spt command's implicit daemon start, REQ-DAEMON-3) routes through the service-aware start path — when a manager has a registered service it starts THAT, never a competing manual `spawn_detached` daemon that would fight the service for the socket.
2026-07-17T03:24:38.0578299Z - Required stages: impl, unit
2026-07-17T03:24:38.0578332Z 
2026-07-17T03:24:38.0578594Z ### REQ-DAEMON-9
2026-07-17T03:24:38.0581524Z - Title: Net-bind boot-race resilience: a daemon that comes up net-less (NetHost::start failed — e.g. the systemd unit autostarted before the network/DNS stack was ready, `Failed to create an address lookup service`) must SELF-HEAL — retry the net bring-up in the background with capped backoff and, on success, attach net to the broker + spawn the dispatcher/peer-pump (which today are gated on `net_up` at boot and so never start, leaving the node silently unreachable until a manual restart — kitsubito 2026-06-08). Status surfaces the net-less state honestly (a net-less broker renders as 'no connection', not only a pump-STALLED line with a bogus pre-boot heartbeat age). The installer's autostart unit waits for the network (`Wants=/After=network-online.target`) as belt-and-suspenders.
2026-07-17T03:24:38.0581852Z - Required stages: impl, unit
2026-07-17T03:24:38.0581887Z 
2026-07-17T03:24:38.0582158Z ### REQ-HAZARD-LIVEHOST-BOOT-RACE
2026-07-17T03:24:38.0586470Z - Title: The brain's daemon-hosted Psyche lifecycle surfaces a host-FAILURE on the live perch (harness-diagnosable) and runs net-INDEPENDENTLY. When reconcile_once→host_one→spawn_psyche fails for a state=live_agent+status=online endpoint (e.g. the adapter's psyche binary absent from its install dir, REQ-INSTALL-11), the failure MUST be written to the perch info.json as a CURRENT-STATE field (reason + ts + attempt count; overwritten each 5s retry, CLEARED on successful host) and surfaced by `spt endpoint list`/status — never left as an eprintln on the brain's invisible stderr where a harness reading only perch state is blind. status=online stays authoritative (agent reachable; only the Psyche is missing — brain-restart rehydrate legitimately has online-without-Psyche windows), so this is a SEPARATE psyche-host-health field, never a status de-stamp. Net-independence is a locked-in invariant: spawn_live_host (brainproc.rs:230) reaches the reconcile and hosts the Psyche on a net-less/unpaired/peer-pump-STALLED node, proven by a REAL detached-daemon E2E (real broker→brain-child, real api seed+listen, real install-dir psyche binary). spt-core SURFACES the failure; the adapter owns fixing its packaging.
2026-07-17T03:24:38.0586922Z - Required stages: impl, unit
2026-07-17T03:24:38.0586955Z 
2026-07-17T03:24:38.0587242Z ### REQ-HAZARD-TEMPLATE-ARGV-FILL
2026-07-17T03:24:38.0591956Z - Title: Command-template substitution fills argv ELEMENTS, not a re-tokenized string: spt-core currently `fill_template`s {key} values INTO the command STRING and THEN `tokenize`s the filled string (runtime.rs:94/122), so a multi-word {key} value whitespace-SPLITS into multiple argv tokens unless the adapter hand-quotes the placeholder, and a value containing a `"` (or `;`) injects/breaks tokenization (shell-injection-adjacent). A filled value MUST become exactly ONE argv element regardless of spaces/quotes in the value. Fix: tokenize the TEMPLATE into argv FIRST, then `fill_template` EACH token, so a `{key}` slot resolves to a single element and the value never participates in tokenization (no whitespace-split, no quote/semicolon injection); preserve the missing-key / empty-command errors and `{{`/`}}` non-interpretation. perri's F-009 (v0.8.1 dogfood, argv-capture-confirmed): a multi-word `{psyche_prompt}` = "PSYCHE REVIVAL time: epoch-ms:… incoming event: (none)" arrived as argv[6..12] (7 stray tokens), the harness runner strict-parsed `--prompt` against the 2nd word, exited 2 within ~1s → phantom hosted perch. Applies to EVERY [session.<role>] template (psyche_init, extractor, notif, …); digest survives today only because its fills ({session_id}/{source}) are single-token.
2026-07-17T03:24:38.0592394Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0592432Z 
2026-07-17T03:24:38.0595886Z ### REQ-HAZARD-LIVEHOST-NONRESIDENT
2026-07-17T03:24:38.0600207Z - Title: A daemon-hosted Psyche that spawns then EXITS IMMEDIATELY is a host failure, surfaced like a spawn failure (closes the v0.8.1 residual masking): the REQ-HAZARD-LIVEHOST-BOOT-RACE signal stamps `psyche_host_error` only when `spawn_psyche` returns Err, NOT when the detached spawn() returns Ok but the child dies within moments (e.g. a bad-argv child exiting 2 — the F-009 case). That leaves the residual 'online + no Psyche + no cause' gap: the nested `{id}-psyche` info.json is written status=online with a real-but-DEAD pid and the PARENT perch carries NO psyche_host_error (perri's F-010: tasklist showed 0 host procs across the window while info.json read online). The host MUST confirm RESIDENCY — a hosted child not alive (or whose `{id}-psyche` perch never re-registers / has a dead pid) within N seconds of spawn is treated as a host failure: stamp the parent perch `psyche_host_error{reason:"host not resident within <n>s (psyche perch missing/dead pid)"}` (and do not leave a phantom online nested perch). Closes the last masking gap the v0.8.1 fix left open. perri's F-010 (v0.8.1 dogfood). Sibling of REQ-HAZARD-LIVEHOST-BOOT-RACE.
2026-07-17T03:24:38.0600536Z - Required stages: 
2026-07-17T03:24:38.0600579Z 
2026-07-17T03:24:38.0600851Z ### REQ-HAZARD-EPOCH-RESET
2026-07-17T03:24:38.0602625Z - Title: Advertisement-epoch reset strands a node: peers' higher last-seen epoch drops the reset node's fresh advertisements as Stale until the counter outruns history. Common case (full reinstall/re-pair) is mitigated by REQ-SUBNET-7's ceremony eviction (peer-side epoch memory dies with the deleted row — acceptance-verified); the residual narrow slice (epoch file lost, identity kept) is documented, guard deferred to a field hit (4.11)
2026-07-17T03:24:38.0602892Z - Required stages: 
2026-07-17T03:24:38.0602930Z 
2026-07-17T03:24:38.0603178Z ### REQ-MESH-1
2026-07-17T03:24:38.0605750Z - Title: Membership proof (seed-proof): symmetric current-epoch seed-knowledge replaces is_trusted at EVERY inbound gate (registry apply, WAN receive, sync, notif, connection accept). MK = HKDF(seed, domain ‖ subnet_id ‖ seed_epoch); mutual channel-bound challenge-response at connect (transcript binds both handshake-proven node pubkeys, both nonces, subnet_id, seed_epoch, role); verified once per connection, cached on the broker ConnEntry, kept warm via QUIC keep-alive so re-proof is restart/partition/rotation-only. Exact-epoch match (re-seed is the sole N-1 exception). SECURITY INVARIANTS: channel-bound (no cross-connection replay), mutual, accepts a member it never paired (the mesh property).
2026-07-17T03:24:38.0606198Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0606237Z 
2026-07-17T03:24:38.0606489Z ### REQ-MESH-2
2026-07-17T03:24:38.0609688Z - Title: Member roster: node-level union-merge grow-set (per member: pubkey, label, machine_id, last-known address, last-seen — NOT the seed), the discovery directory the mesh dials by. Seeded IN FULL at pairing (seed-holder hands joiner the whole current roster, incl. offline members — folds in deferred pairing-time hostname capture + post-join address seeding); each node authors its own entry stamped with its lease_epoch, merged strictly-greater-wins (the node_label lease); exchanged only over seed-proof'd member connections; forgery-inert (a fake entry names a pubkey that still can't seed-proof). Removal needs a TOMBSTONE — a per-pubkey revoked marker that propagates, dominates the entry, gates admission (seed-proof ∧ ¬tombstoned), and prevents reinsert; cleared by a completed re-pair of that pubkey. Persists through silence (offline member keeps its entry).
2026-07-17T03:24:38.0610080Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0610118Z 
2026-07-17T03:24:38.0610370Z ### REQ-MESH-3
2026-07-17T03:24:38.0612480Z - Title: Mesh row fan-out: registry rows stay OWN-AUTHORED; the only change is the push target widens from directly-paired peers to ALL roster members (a wider DIRECT fan-out, never a third-party relay). Every row/message still arrives from its author over a handshake → KNOWN-HAZARDS 7.5 (origin = handshake node) and 4.10 (eviction lease: any future update comes from that node itself, alive) PRESERVED VERBATIM. Closes the staggered A→B→C repro: C (roster-seeded with A at pairing) initiates to A, seed-proof admits C unpaired, A learns C, both push directly.
2026-07-17T03:24:38.0612870Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0612904Z 
2026-07-17T03:24:38.0613161Z ### REQ-MESH-4
2026-07-17T03:24:38.0615834Z - Title: Revoke + timeboxed seed rotation + re-seed grace: `spt subnet revoke <node>...` (list, elevation-gated, revoke-only) writes roster tombstones immediately, then schedules ONE seed rotation (re-mint seed, bump seed_epoch, push new seed CONFIDENTIALLY over member-auth'd TLS connections — never in roster/registry gossip — force-drop revokees) at the close of a coalescing window (default 1h); further revokes in the window join the same rotation (one epoch bump). `--force-rotate-seed` rotates immediately (compromised-node path). RE-SEED GRACE: a node proving the immediately-prior epoch (N-1) AND still on the roster gets a re-seed-only restricted connection (auto-heals a benign offliner); revoked/off-roster denied; ≥2 stale → re-pair.
2026-07-17T03:24:38.0616173Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0616206Z 
2026-07-17T03:24:38.0616458Z ### REQ-MESH-5
2026-07-17T03:24:38.0618240Z - Title: Hard cutover from pairwise trust: delete peers.json + the is_trusted authorization path (no migration — expendable test fleet, re-pairs fresh under the new model, user decision 2026-06-08). Warn-on-change DEMOTED from a gate to an awareness notice anchored on machine_id (not label): 'machine M, last seen as K1, now presents K2' — fires the same event as the REQ-SUBNET-7 re-pair overwrite. The TrustStore/peers.json code and its call sites are removed, not left dead.
2026-07-17T03:24:38.0618522Z - Required stages: impl, unit
2026-07-17T03:24:38.0618546Z 
2026-07-17T03:24:38.0618793Z ### REQ-MESH-6
2026-07-17T03:24:38.0620521Z - Title: Concurrent liveness probes: `spt subnet status --nodes` fans out its offline/serve-probes (REQ-SUBNET-5) CONCURRENTLY — total wall-time bounded by the single-probe ceiling (~3s), never k×ceiling. The mesh makes a node see ALL members (many possibly offline), so a serial probe loop would be offline_count×3s. (Planning verifies the current REQ-SUBNET-5 probe loop's behavior and fixes it if serial.)
2026-07-17T03:24:38.0620826Z - Required stages: impl, unit
2026-07-17T03:24:38.0620855Z 
2026-07-17T03:24:38.0621098Z ### REQ-SHELL-3
2026-07-17T03:24:38.0623360Z - Title: Drive channel (owner->shell, REST-only, never-spooled, latest-wins): the owner->shell mirror of sensory for continuous real-time control (scroll/crank/stick/avatar) — a [shell.drive] manifest vocab + EVENT_TYPE_DRIVE frame, delivered to the ONLINE binary only via a single live slot (a new frame supersedes an undelivered one — no spool, no queue, no replay on relink), dropped-with-diagnostic if the shell is offline; cross-node rides the ephemeral link (REST class), never the durable shell spool. Commands = discrete+durable; drive = continuous+ephemeral (CONTEXT:260, minted 2026-06-11 Gateway grill).
2026-07-17T03:24:38.0623689Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0623778Z 
2026-07-17T03:24:38.0624036Z ### REQ-SHELL-4
2026-07-17T03:24:38.0626278Z - Title: Shell tunnel (reliable-ordered opaque byte stream): an owner<->shell link may hold a long-lived, reliable-ordered, link-bound QUIC stream pair carrying opaque wire protocol traffic the channel taxonomy must NOT reinterpret (first consumer usbip URB) — manifest opt-in, not enveloped, not MAC-framed, not spooled; the link lifecycle governs it (a link-break closes the tunnel). Reliable-ordered ⇒ congestion surfaces as lag never loss ⇒ acceptable only on-LAN: the on-LAN posture is documented and the tunnel is NOT proven cross-WAN (CONTEXT:262, minted 2026-06-11 Gateway grill; doyle gate C2).
2026-07-17T03:24:38.0626566Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0626617Z 
2026-07-17T03:24:38.0626932Z ### REQ-CONSENT-3
2026-07-17T03:24:38.0629316Z - Title: Per-capability approval gates (class-keyed): the require_approval enum may ride INDIVIDUAL [shell.capabilities] entries — gating the dangerous ACT, not just the spawn — with an optional class_key scoping the grant qualifier finer than the capability id ((owner endpoint x device class x node); a remembered HID-class attach grant never authorizes a storage-class attach). Reuses the grant store + interactive escalation + tighten-only floor (REQ-CONSENT-1/2 plumbing). Spawn gates govern EXISTENCE; capability gates govern ACTS — an explicitly distinct invariant (CONTEXT:283, ratified 2026-06-11 Gateway grill).
2026-07-17T03:24:38.0629627Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0629660Z 
2026-07-17T03:24:38.0629907Z ### REQ-SHELL-5
2026-07-17T03:24:38.0631434Z - Title: Shell ownership is owner-type-agnostic: any non-Shell endpoint type may own/spawn/drive/command/link a shell (Gateway the named first) — control-exclusivity keys on the owner endpoint_id, NEVER on the owner's endpoint type. No ownership path (mint, launch, owner-from-link, cmd, drive, tunnel, sleep/wake, owner-shutdown) inspects the owner's type (CONTEXT:264, ratified 2026-06-11 Gateway grill).
2026-07-17T03:24:38.0631763Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0631796Z 
2026-07-17T03:24:38.0632082Z ### REQ-HAZARD-VIEWER-CLOSE-DETACH
2026-07-17T03:24:38.0643467Z - Title: A VIEW is independent from the endpoint: closing the tab/window where `spt endpoint run` was invoked must detach ONLY the `spt rc` attach pump — the daemon-hosted harness keeps running and stays re-attachable via `spt rc <id>`. ROOT (Windows, v0.12.0 real-harness defect): the daemon never breaks away from the launching terminal's Job Object. Windows Terminal / VS Code place the launched shell AND every descendant into a Job Object with JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE; closing the tab drops the terminal's last job handle → the OS terminates every process still in that job. A child escapes only with CREATE_BREAKAWAY_FROM_JOB — used NOWHERE in the tree. Both daemon spawn paths (daemon.rs:707 detached_no_inherit = DETACHED_PROCESS|CREATE_NEW_PROCESS_GROUP|CREATE_NO_WINDOW; deelevate.rs:519 elevated = CREATE_NEW_CONSOLE|...) drop the CONSOLE but NOT job membership, so the daemon's freshly broker-spawned ConPTY harness subtree is reaped on tab-close. The ConPTY/pseudoconsole isolation itself is CORRECT (portable-pty builds the pseudoconsole in the daemon; no console signal / handle leak) — the leaking lifetime binding is the Job Object, not the console. FIX: add CREATE_BREAKAWAY_FROM_JOB to both daemon spawn paths AND pin each broker-spawned harness into a DAEMON-OWNED Job Object (mirror reap.rs/Breap) as backstop (survives even where a terminal sets SILENT_BREAKAWAY_OK=false). Unix: the daemon's own session detachment (new session, no controlling terminal) already keeps a closing terminal's SIGHUP off its children — verify, add a guard test, no code expected. FIX UPDATE (v0.12.1 L1.5, doyle re-scope operator-approved 2026-06-18): job-neutral daemon launch is now PRIMARY, breakaway DEMOTED to a fallback rung. ROOT reframed — the daemon INHERITS the terminal's Job because spawn_detached runs FROM the terminal-child CLI (DETACHED_PROCESS detaches the console, not the job); breakaway tried to claw back out but a job CAN deny it (the L1 finding). FIX: launch the cold-started daemon via a job-NEUTRAL creator so it is WmiPrvSE/Task-Scheduler-owned, OUTSIDE any terminal job from birth (why Task-Scheduler-autostarted daemons never had this bug). Launcher ladder (first-success-wins, daemon.rs spawn_detached → BOTH cold-start AND `spt daemon start`): (1) WMI Win32_Process.Create via ABSOLUTE powershell -EncodedCommand (KH 5.12 abs path; base64-UTF16LE dodges all quoting; success requires BOTH ReturnValue==0 AND a parsed ProcessId, else fall-through — never a silent launched), forwarding SPT_* env via a `cmd /c set … & start /b` wrapper because a WMI/scheduler child does NOT inherit transient shell env (verified — SPT_HOME would be lost, wrong universe); (2) schtasks one-shot (same env wrapper; best-effort fallback); (3) CREATE_BREAKAWAY_FROM_JOB (the L1 code, reordered below); (4) in-job last resort (logs DETACH_IN_JOB + tab-close caveat). detached_no_inherit (breakaway-then-in-job) is UNCHANGED for its other caller shellhost::launch_shell (a daemon-spawned shell is already job-neutral once the daemon is). The elevated deelevate path keeps its L1 breakaway for now (elevated-case WMI-reparent = FOLLOW-UP). (v0.12.1)
2026-07-17T03:24:38.0644123Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0644160Z 
2026-07-17T03:24:38.0644433Z ### REQ-HAZARD-ATTACH-WEDGE
2026-07-17T03:24:38.0650813Z - Title: A legitimately dead PTY child (real crash/kill) + an undrained operator pump must NOT wedge the broker for all other clients. ROOT (v0.12.0 real-harness defect): loopback attach output is a blocking write_all into a bounded 64KB tokio duplex (nethost.rs:1040,1090); when the operator's rc pump stops draining (tab closed) the buffer fills and write_all blocks forever (the 'loopback never hangs' assumption at nethost.rs:1103 is false), parking a worker in the 2-worker net runtime (nethost.rs:640); a couple of these saturate BOTH workers → every new attach / `endpoint run` stalls right after 'PUMP_IPC_READER: spawned' → 30s FIRST_EVENT_GRACE → 'no output / dead or wedged'; `daemon stop` cannot join the stuck workers. DISTINCT from the removed B1 path-(c) mutex deadlock. DISPOSITION = PROVE-DON'T-CHANGE (doyle GATE-PASS @e883f45, 2026-06-18): this ROOT is the SUPERSEDED v0.12.0 hypothesis — the post-L0 code ALREADY prevents the wedge, so NO fail-fast / worker-count code was added. serve_attach forwards fire-and-forget (net_stream_send op_id=None) and the broker-side send_stream is already BROKER-QUIC-DEADLINE-bounded (bounded_block_on, 10s); the loopback duplex is drained broker-INTERNALLY by the operator row's own read pump (RecvHalf::Loopback, retentive_cap==0 → evict-not-park) so a dead rc (a dropped IPC subscriber) never backs peer_w up; bounded_block_on parks the BROKER DISPATCH thread, not a net worker → no worker-pool exhaustion (full mechanism in the required_stages comment). Folds the status=online sub-check: a dead spt-hosted endpoint is marked OFFLINE within one reconcile tick on abrupt child death (broker exit-waiter reaps the session → B2 sees it absent) — PROVEN, no change. (v0.12.1)
2026-07-17T03:24:38.0651284Z - Required stages: int
2026-07-17T03:24:38.0651318Z 
2026-07-17T03:24:38.0651589Z ### REQ-PICKER-HISTORY-FRESH
2026-07-17T03:24:38.0653036Z - Title: The `spt endpoint run` picker shows project history for FRESH endpoints (operator-raised v0.12.0 real-harness finding). Symptom: a fresh endpoint shows no project history in the picker. ROOT TBD — investigate the project-history loader (v0.10.0 PICKER-2, picker/data.rs) before fixing: distinguish a real loader bug from 'fresh = no history yet' semantics. (v0.12.1)
2026-07-17T03:24:38.0653342Z - Required stages: impl, unit
2026-07-17T03:24:38.0653375Z 
2026-07-17T03:24:38.0653657Z ### REQ-PICKER-ONLINE-ACTION
2026-07-17T03:24:38.0655636Z - Title: The `spt endpoint run` picker shows the correct action for an ALREADY-ONLINE endpoint — Attach, NOT 'Start now' (operator-raised v0.12.0 real-harness finding). Symptom: the picker offers 'Start now' for endpoints that are already online. ROOT TBD — investigate the status→action mapping (v0.10.0 PICKER-1 four-state status, picker/model.rs): is it reading live/online state correctly, or rendering stale/wedged broker state (i.e. partly a symptom of the broker wedge / status=online latch)? Fix so online → Attach. (v0.12.1)
2026-07-17T03:24:38.0655989Z - Required stages: impl, unit
2026-07-17T03:24:38.0656017Z 
2026-07-17T03:24:38.0656289Z ### REQ-ENDPOINT-LIST-MERGE-LOCAL
2026-07-17T03:24:38.0658522Z - Title: `spt endpoint list` always merges this node's LOCAL (unadvertised) perches into the view; the `--local` flag is REMOVED (operator decision 2026-06-17). Rationale: `spt whoami` is a thin alias of `endpoint list` — a just-online agent running `whoami` must see its OWN perch, or it gets an omitted-self view ('chaos'). FIX: drop the `--local` flag + its `--detail` conflict test + the v0.10.0 REQ-PICKER-5 hint line (cli.rs:1678) + cmd_list_local; the bare list merges local perches into the subnet view; fix the whoami alias path accordingly. Run `cargo run -p xtask -- gen` (docs-drift, DEFAULT target). (v0.12.1)
2026-07-17T03:24:38.0658904Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0659033Z 
2026-07-17T03:24:38.0659333Z ### REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT
2026-07-17T03:24:38.0665168Z - Title: A clean `spt rc` attach to a LIVE spt-hosted (`endpoint run`) harness must DELIVER the harness's PTY output. KEYSTONE — the operator's central 'attach shows no output' symptom, reproduced on the real dummy-harness fixture (v0.12.1 Wave 1) with NO death and NO wedge: bringup succeeds (online, harness pid alive + heartbeating, psyche hosted), the attach CONNECTS (PUMP_IPC_READER spawned, no RC_FAIL, holds the full window) — but receives EXACTLY 0 bytes over 10s of the harness's flushed [session.self] stdout. DISTINCT from REQ-HAZARD-VIEWER-CLOSE-DETACH (death) and REQ-HAZARD-ATTACH-WEDGE (dead-child backpressure): here the harness is ALIVE and the attach is a clean first subscribe. This BLOCKS the 'view is independent' invariant — re-attach is meaningless if a live endpoint-run harness shows nothing. KNOWN-GOOD (rules out 'no drain'): attach.rs `local_attach_via_loopback_conn_rides_the_same_pump` + `broker_spawns_the_pty_child_in_the_requested_cwd` prove the broker DOES drain+fan a `spawn_session` PTY child to a loopback attach over the SAME transport rc uses. Both spawn_session and endpoint-run's spawn_session_pid send KIND_SPAWN → the same dispatch_spawn (broker.rs:706/835) which starts the per-session drain+OutputLog — so the gap is NARROWER than 'no drain', endpoint-run-specific. Root candidates: (a) spawn_session_pid's SpawnReq stdio/env/cwd differs so the dummy's stdout isn't the captured ConPTY; (b) the harness stdout WRITE BLOCKS because the ConPTY buffer fills (drain not reading THIS pty) — explains alive-but-0-bytes; (c) ConPTY reader-park (KH 7.6) on this path; (d) `spt rc` resolve_session/subscribe for an endpoint-run session subscribes to the wrong/empty log. (v0.12.1)
2026-07-17T03:24:38.0665704Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0665733Z 
2026-07-17T03:24:38.0666000Z ### REQ-CLI-HELP-MARKDOWN
2026-07-17T03:24:38.0669754Z - Title: `spt --help` (and every subcommand --help) renders the inline Markdown authored in the clap doc-comments as terminal styling, never as literal markers: `**bold**` → ANSI bold, `` `code` `` → ANSI cyan, `[text](url)` → `text`. The markers are STRIPPED either way — a raw `**` or backtick must NEVER reach the user (the operator-reported v0.12.0 defect: help text reads `**ctrl-b**` and stray backticks verbatim). Color/bold escapes are emitted ONLY when the help is going to a real terminal AND color is not suppressed (NO_COLOR unset · CLICOLOR != 0 · CLICOLOR_FORCE forces on); a pipe / redirect / CI / NO_COLOR falls back to strip-only (clean plaintext, zero escapes) so machine-readable help is byte-identical regardless of marker syntax. Pure transform over the clap-rendered help string at the single run()/bare_invocation chokepoint; preserves pre-existing ANSI (CSI sequences passed through untouched), never spans markers across a newline, leaves unmatched/empty markers literal, and does not alter the help layout. (v0.12.1)
2026-07-17T03:24:38.0670146Z - Required stages: impl, unit
2026-07-17T03:24:38.0670184Z 
2026-07-17T03:24:38.0670459Z ### REQ-HAZARD-WMI-DAEMON-WINDOW
2026-07-17T03:24:38.0673489Z - Title: `spt daemon start` launches the daemon with NO visible console window. REGRESSION (v0.12.1 L1.5): the WMI job-neutral launch (spawn_daemon_via_wmi) set CREATE_NO_WINDOW on the launching powershell but NOT on the Win32_Process.Create call — Win32_Process.Create does not inherit it, so the spawned cmd.exe env-forwarding wrapper popped a console window on every cold-start (violating REQ-INSTALL-10's v0.7.4 no-persistent-window invariant; the old detached_no_inherit path set DETACHED_PROCESS|CREATE_NO_WINDOW). FIX: pass a Win32_ProcessStartup with CreateFlags=DETACHED_PROCESS (0x8 — no console so no window; CREATE_NO_WINDOW 0x08000000 is NOT a valid Win32_ProcessStartup flag → ReturnValue 21 invalid-param, which is why the naive port fails) + ShowWindow=SW_HIDE(0) belt, via the ProcessStartupInformation argument. (v0.12.2)
2026-07-17T03:24:38.0673870Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0673913Z 
2026-07-17T03:24:38.0674176Z ### REQ-CLI-OUTPUT-MARKDOWN
2026-07-17T03:24:38.0679553Z - Title: Human-prose COMMAND OUTPUT (not just `--help`) renders the inline Markdown authored in its source strings as terminal styling, never literal markers: `` `code` `` → ANSI cyan, `**bold**` → ANSI bold, `[text](url)` → `text`, markers STRIPPED either way. REQ-CLI-HELP-MARKDOWN only hooked the clap `--help` chokepoint, so command output still printed raw Markdown (audit: `spt how-to` topic text showed `# headers`/backticks, `spt subnet`/`subnet status` hint footers showed stray backticks, the daemon-status `not running` line, the `ENDPOINT_RUN_STARTED` attach hint, and the daemon's `SUBNET_DETACHED` startup line — 13 prose surfaces). The same line-bounded pure `helpfmt::render` is applied at each emit site, color-gated by the OUTPUT STREAM's own tty (`stdout_color` for print/println, the new `stderr_color` for eprintln). HARNESS-SAFETY (binding): color is tty-gated, so an adapter (piped / non-tty / NO_COLOR) gets STRIP mode = zero ANSI + markers removed; every dual-contract MACHINE token on a rendered line (`ENDPOINT_RUN_STARTED:`, `NO_SUCH_TOPIC:`, `SUBNET_DETACHED:`) carries NO Markdown markers, so it survives strip byte-intact — the adapter parse is never perturbed. Pure-machine output (the `<EVENT …>` envelope, bringup parse-tokens SEEDED/BOUND/READY/NO_SEED, `--json`, QR) is NEVER routed through the renderer. The one spt-daemon source string (`SUBNET_DETACHED`, the bin-local renderer is unreachable from the daemon crate) is authored marker-free instead. (v0.12.2)
2026-07-17T03:24:38.0680024Z - Required stages: impl, unit
2026-07-17T03:24:38.0680067Z 
2026-07-17T03:24:38.0680348Z ### REQ-HAZARD-INJECT-CONTROL-COEXIST
2026-07-17T03:24:38.0689173Z - Title: SPINE INVARIANT (v0.13.0 keystone): the broker must accept INJECTED keystrokes into an spt-hosted PTY (the v0.11.0 raw direct-inject today; the ADR-0022 translation-binary choreography tomorrow) WHILE a live `spt rc` controller is attached to the SAME PTY, without (a) the operator losing control, (b) the endpoint latching ONLINE+CONTROLLED, or (c) the broker wedging. The injection inlet is PERMANENT — spt-claude-code requires keystroke injection — so this is root-caused + fixed at the PTY-injection layer, IN STEP with the ADR-0022 delivery redesign that formalizes the inlet. REOPENS the wedge facet of REQ-HAZARD-ATTACH-WEDGE: the v0.12.1 prove-don't-change covered only DEAD-CHILD backpressure, NOT the injection trigger (operator's signal — one injected keystroke succeeds, the next wedges → the single-threaded broker parks on a blocking PTY/loopback write after injection-induced harness output). REPRO-FIRST on the real dummy-harness fixture (NO theory): instrument to nail the exact blocking call before any fix. Fix candidates: non-blocking/fail-fast PTY write, split input/output, bounded-evicting. Mechanism shared with W2 — spt-core owns EVERY PTY write and applies an injected sequence ATOMICALLY (controller input buffered during the sequence, flushed after) so a stash/restore can't be clobbered. CONFIRMED ROOT (doyle /diagnose 2026-06-19, code-grounded): Broker::append (broker.rs:205-227) fans each live output chunk to the CONTROLLER on a SYNCHRONOUS BLOCKING write_frame held inline in the session's drain thread (the 'authoritative, advances delivered_through' path, D4-1), while VIEWERS use a dedicated writer thread + bounded evicting sync_channel (add_viewer:273 / viewer_writer) that can never stall the drain. So a slow/backed-up controller socket — or the full 64KB loopback duplex (the ATTACH-WEDGE buffer) — BLOCKS the drain thread → output stalls → keystroke echoes stall (PERCEIVED input lag) → unrecoverable wedge when the consumer never drains. TRIGGERS ON NORMAL INTERACTIVE rc USE under heavy harness output (TUI redraw), NOT only message injection — same root, wider repro. FIX DIRECTION: move controller delivery off the drain thread onto a dedicated writer (the viewer_writer pattern) BUT preserve the authoritative cursor — block the WRITER thread (not the drain), bound the wedge (deadline → detach/mark-gone, never park forever), never silently evict the operator's authoritative view. (v0.13.0)
2026-07-17T03:24:38.0689663Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0689697Z 
2026-07-17T03:24:38.0690040Z ### REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE
2026-07-17T03:24:38.0696335Z - Title: A SLOW controller must not starve a concurrent `rc --view` VIEWER. W1 (REQ-HAZARD-INJECT-CONTROL-COEXIST) moved the controller SOCKET WRITE off the drain thread onto controller_writer, but left the bounded HANDOFF (ControllerJob::deliver) as an INLINE try_send SLEEP-POLL on the drain (broker.rs:1450-1457 → deliver:669-685, up to CONTROLLER_WRITE_DEADLINE=5s). So when a controller drains slower than the PTY floods, its CONTROLLER_CHANNEL_DEPTH(4096) channel fills, deliver() polls inline, and the DRAIN THREAD is throttled to the controller's read rate → OutputLog::append's viewer fan-out (try_send) stops running → a concurrent VIEWER receives only the initial replay then nothing (root 'b4', warm forkpty: a_journaled c1=0/EVICT=0/got_output=FALSE; steady-state-near-full = no recovery; forkpty-only, floods harder than Windows ConPTY). The viewer-not-starved-by-a-busy-session property is legitimate (rc --view of a noisy session must show LIVE output). FIX: the controller becomes a SINGLE NON-BLOCKING try_send (like a viewer), done IN append() under the log lock; deliver()'s sleep-poll DELETED; the drain NEVER sleeps. ControllerSink gains a stateful last_ok deadline → a TRULY-stalled controller (continuous-Full past CONTROLLER_WRITE_DEADLINE) is evicted (bounded-wedge preserved); a slow-but-alive controller DROPS frames + falls behind the ring (resume-from-floor, the existing reconnect case). B2 GAPLESS-HANDOFF PRESERVED via a CONTIGUOUS delivered_through: controller_writer advances the cursor ONLY when the written seq == cursor (next expected); a gap from a drop FREEZES the cursor at last-contiguous so a re-attaching brain's resume_seq never skips a dropped chunk (a high-watermark advance past the gap would be a not-exactly-once resume = B2 violation, doyle's gate). (v0.13.0)
2026-07-17T03:24:38.0696995Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0697032Z 
2026-07-17T03:24:38.0697314Z ### REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT
2026-07-17T03:24:38.0703713Z - Title: A `rc --view` VIEWER that overflows its broker subscription queue and is EVICTED (OutputLog::append try_send Full → viewers.remove, REQ-HAZARD-VIEWER-ISOLATION session-protection) must SKIP TO LIVE, not die silently. ROOT (v0.13.0, b4 JIT item 2 = p0_paste + post-b4 a_journaled-Linux, ONE root): serve_attach forwards each frame (read_event→b64decode→re-encode AttachRecord→net_stream_send) SLOWER than the drain fans out under flood → its VIEWER_CHANNEL_DEPTH(256) channel overflows → the drain evicts (viewers.remove drops the ViewerSink → drops tx → viewer_writer's rx.recv() Err → the writer returns WRITING NOTHING) → serve_attach's brain.read_event() just STOPS getting Output (no EOF, no error) → serve_attach blocks forever → the operator receives nothing (attach_received_output=FALSE). Eviction-of-a-hopelessly-behind-viewer is CORRECT session-protection (keep it); SILENT+PERMANENT eviction is the bug. VIEWER-only → B2-SAFE (a viewer never advances delivered_through / is not authoritative / exposes no resume cursor). FIX (doyle-gated, skip-to-live = tail -f reconnect): (1) explicit broker→viewer EVICTION SIGNAL (KIND_VIEWER_EVICTED, written in the viewer_writer thread OFF the log lock, DISTINCT from session-exit EOF so serve must NOT tear down on it); (2) serve_attach re-subscribes from the CURRENT ring floor (skip-to-live, replays nothing, sees the next live burst) — resetting the cold serve-brain's next_seq so the post-eviction forward-jump replay is accepted (the legacy reject-gap path, brain.rs:618-626, would otherwise FATAL the forward jump); (3) HARD constraint NO evict→resubscribe busy-loop: serve_attach rate-limits re-subscribes (RESUBSCRIBE_INTERVAL) so under max-flood the operator sees intermittent LIVE bursts, never a CPU spin. (v0.13.0)
2026-07-17T03:24:38.0704380Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0704418Z 
2026-07-17T03:24:38.0704744Z ### REQ-HAZARD-VIEWER-RING-ROLL-SNAP
2026-07-17T03:24:38.0709894Z - Title: A read-only rc --view VIEWER whose serving brain falls behind the live ring under a hard flood and receives a FORWARD Output seq gap (the ring rolled frames out between reads, BEFORE any channel-overflow eviction → NO KIND_VIEWER_EVICTED marker) must SNAP TO LIVE (accept-and-advance via dedup-below + snap-above), NOT fatal with output gap (brain.rs:624/628 legacy reject-gap). ROOT (v0.13.0 forkpty, post-b4+skip-to-live): serve_attach subscribes a viewer via brain.attach_as(Viewer) leaving session_cursors EMPTY → the viewer serve-brain uses the LEGACY reject-gap → a PRE-eviction ring-roll forward-gap FATALS read_event → serve_attach returns → forwarding stops → attach_received_pty_output=FALSE (a_journaled / p0_paste / attach.rs:1071 wedged_viewer, Linux forkpty; Windows ConPTY floods slower → MASKED false-green). DISTINCT from REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT (the POST-eviction re-subscribe-from-floor): this is PRE-eviction gap-tolerance while STILL subscribed. VIEWER-only → B2-SAFE (a viewer never advances delivered_through / is not authoritative); the CONTROLLER keeps strict reject-gap (exactly-once resume). FIX: arm snap-above at initial viewer attach (attach_as_viewer_snap = attach_as(Viewer) + session_cursors.insert(session_id, from_seq)); the two viewer-survival mechanisms COMPOSE — this tolerates pre-eviction ring-roll gaps, REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT recovers post-eviction. (v0.13.0)
2026-07-17T03:24:38.0710417Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0710450Z 
2026-07-17T03:24:38.0710732Z ### REQ-HAZARD-CONTROLLER-GAP-RESUME
2026-07-17T03:24:38.0718491Z - Title: A serving CONTROLLER whose serve-brain hits a b4 drop-don't-block FORWARD output gap must RESUME-FROM-FLOOR (re-subscribe from delivered_through and re-fetch the dropped frames from the ring), NOT snap-above and NOT fatal. ROOT (v0.13.0 forkpty re-run, post-keystone): b4 made the controller a non-blocking try_send that DROPS frames when its bounded channel fills (a controller that falls behind its OWN echo under a hard flood), so the next read is a forward gap the strict reject-gap (brain.rs:624/628, B2 exactly-once) FATALS — wedged_viewer_does_not_stall_controller (attach.rs:1048) drove ctrl.read_event() raw and fataled on `output gap got 6134 want 4643`. Pre-b4 the inline sleep-poll BLOCKED the drain to the controller's rate (no drops, no gaps); this is a b4 SIDE-EFFECT, not a new class. A controller CANNOT snap (it is authoritative — advances delivered_through; skipping rolled frames = not-exactly-once = B2 violation), so REQ-HAZARD-VIEWER-RING-ROLL-SNAP does NOT apply. B2 INVARIANT (doyle, broker.rs:327-330): the ring trim is delivered_through-BLIND (`while ring.len() > cap_chunks { pop_front() }`), so re-fetch is exactly-once IFF tail - delivered_through <= cap_chunks (4096) — NOT guaranteed in general, but the common case (burst < ring; wedged_viewer ~1492 < 4096) holds. FIX: serve_attach catches the output-gap on the controller path (does not ?-propagate) and re-subscribes from Brain::controller_resume_floor (= delivered_through = the gap's `want`; NO mid-stream KIND_SESSIONS round-trip — sessions() loops on read_event and would re-fatal on the same gap + discard Output); the broker replays the dropped frames. The IRRECOVERABLE edge (floor unchanged across two resumes = ring rolled past delivered_through = frames gone) surfaces a MARKED truncation to the operator (never silent-skip = B2 lie, never spin) and ends cleanly — full graceful handling deferred to REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND. Do NOT make the ring trim delivered_through-aware (that risks an unbounded ring under a stuck controller; the 5s eviction + 4096 ring is the practical bound). (v0.13.0)
2026-07-17T03:24:38.0719130Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0719178Z 
2026-07-17T03:24:38.0719493Z ### REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND
2026-07-17T03:24:38.0722965Z - Title: DEFERRED EDGE of REQ-HAZARD-CONTROLLER-GAP-RESUME: when a serving controller falls behind the live ring FURTHER than the ring holds (tail - delivered_through > cap_chunks, the ring trim being delivered_through-blind, broker.rs:327-330), the dropped frames have rolled OUT of the ring and an exactly-once re-fetch is IMPOSSIBLE. v0.13.0 DETECTS this (resume floor unchanged across two consecutive resumes) and surfaces a MARKED truncation notice to the operator then ends the attach cleanly — it never silent-skips (a B2 lie) and never spins. FULL graceful handling (a clearly-marked snap-with-data-loss that keeps the operator on the live tail, or a structured truncation record the rc renders distinctly, plus the controller-too-slow + ring-too-small backpressure/sizing policy) is DEFERRED — staging it needs a netsplit / deep-behind harness (the in-process loopback rig keeps up; wedged_viewer's gap is recoverable at ~1492 < 4096). (v0.13.0+)
2026-07-17T03:24:38.0723288Z - Required stages: 
2026-07-17T03:24:38.0723322Z 
2026-07-17T03:24:38.0723603Z ### REQ-MSG-IDLE-TRANSLATION-BINARY
2026-07-17T03:24:38.0730854Z - Title: spt-hosted idle message delivery via an adapter TRANSLATION BINARY (ADR-0022). New opt-in manifest section `[message-idle-translation-binary]` = a TABLE carrying a `path` scalar (doyle OPT-B ruling: modeled as a table, not a bare top-level scalar, so a preceding section cannot silently absorb it + N+1 extensible; spt-core does NOT deny_unknown_fields, so a future key degrades gracefully); spt-core LIFECYCLE-manages it (spawn when the endpoint comes up, terminate when it goes down). The binary is a PURE stdin→stdout filter; spt-core owns EVERY PTY write. stdin (JSON-lines): `{type:"init",endpoint_id,node}` first · `{type:"event",envelope:"<EVENT…>"}` per inbound message (ADR-0020 envelope) · `{type:"input"}` content-free ping on each operator keystroke (binary tracks user-idle for its own idle-gated buffering; PTY input content NOT duplicated). stdout (JSON-lines): keystroke-commands `{key:…}`/`{delay_ms:…}`/`{text:…}` (extensible). spt-core applies the emitted sequence to the broker PTY ATOMICALLY (the W1 coordination — REQ-HAZARD-INJECT-CONTROL-COEXIST). The daemon poll feed is the ONE idle substrate for both topologies (Q1=A): harness-hosted consumer = the Monitor child, spt-hosted consumer = this binary; spt-core PREFERS a perch's poll listener if one exists (so spt-hosted can run a listener AND keep `spt rc`). Idle-only; busy/mid-turn = adapter hook-injection. Closes the current grounding gap: `api bind` registers no listener port → a listener-less spt-hosted perch SPOOLS inbound (only spooling+adapter-poll works today) → this delivers real inbound into the PTY. AMENDED v0.14.3 (ADR-0022 amendment, raw-inject removal): idle delivery is translation-binary-ONLY — the v0.11.0 raw `{text:payload}{key:enter}` inject is NO LONGER a delivery path; with no working binary (absent/spawn-failed/faulted/worker-gone) the inbound SPOOLS (delivered=false, poll-fed, LOUD), never a raw PTY pseudo-write (which did not submit on a modern TUI — the silent degrade that masked F-019). See REQ-HAZARD-IDLE-SILENT-NONDELIVERY. (v0.13.0, amended v0.14.3)
2026-07-17T03:24:38.0731414Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0731447Z 
2026-07-17T03:24:38.0731729Z ### REQ-HAZARD-IDLE-SILENT-NONDELIVERY
2026-07-17T03:24:38.0743294Z - Title: An idle delivery to a session whose translation binary is in a FAILED STATE — absent (none declared), spawn-failed, FAULTED, or its inject-worker channel gone — must SPOOL (delivered=false), never raw-inject a pseudo-delivery reported as delivered. The GUARANTEE is the STEADY STATE (the failed-binary state), not every in-flight message (see the fault-transient carve-out below). ROOT (F-019 post-mortem, ADR-0022 amendment): the v0.11.0 path raw-injected `payload+\r` into the PTY whenever no working translation binary handled an inbound message (none declared, spawn-failed, FAULTED, or its inject-worker channel gone) AND acked `delivered=true` — but a bare `payload+\r` does NOT submit on a modern TUI (Claude Code), so the message was TYPED but never sent: a silent pseudo-delivery reported as success. That silent degrade-to-raw-inject is exactly what MASKED F-019 through a multi-hour black-box hunt. FIX (operator-ruled, doyle-scoped): idle delivery is translation-binary-ONLY — `dispatch_endpoint_input` with no working binary replies `endpoint_injected_envelope(ep, delivered=false)` (the caller `try_broker_inject`→`cmd_send` then falls through to `deliver::send` = SPOOL, poll-fed, never lost) and writes NOTHING to the PTY, LOUDLY (eprintln names the absent/faulted/worker-gone cause). A failed binary becomes a VISIBLE no-delivery (spooled + honest QUEUED report), never a confident-but-false 'Sent'. The raw-inject fallback (`input.enqueue`) is REMOVED from the no-binary, worker-dropped, AND post-fault paths. OUT OF SCOPE (doyle ruling, follow-up note only): broker-side auto-redrive of already-spooled inbound the instant a live-update binary spawns (ordering/exactly-once hazards; the poll substrate + subsequent sends cover re-delivery). NOT COVERED — the FAULT-TRANSIENT (the STATE-vs-transient precision): a delivery landing in the worker's commit window — BEFORE `event_rx` is dropped / `faulted` is set — can be optimistically enqueue-acked (`delivered=true` the instant `event_tx.send` succeeds) then DROPPED when the worker faults+returns. That is a SEPARATE, PRE-EXISTING hazard: raw-inject removal did not touch it (the old code dropped that queued event too) — v0.14.3 is a strict improvement that makes nothing worse. It is tracked for v0.15.0 under REQ-MSG-DELIVERY-AXES (the spool-centric delivery redesign: ack-on-SPOOL replaces ack-on-enqueue, which closes the optimistic-ack drop naturally). v0.14.3 guarantees only the steady FAILED state → spool (faulted is MONOTONIC — set once, never respawns — so it converges deterministically; the g2 gate asserts the steady state via bounded-retry-until-spool, not a single-shot ack). EPHEMERAL CARVE-OUT (v0.15.0 W3, ADR-0028): `--ephemeral` is the SOLE sender-opted-in exception — an ephemeral message MAY drop silently if it cannot deliver in its accepted window (at window-open with no live carrier, or at TTL). Every NON-ephemeral path still spools + reports `delivered=false` (the guarantee is unchanged for the default durable path). v0.15.0 realizes the ephemeral drop for the spt-hosted-binary no-carrier-at-window leg + TTL; the harness-relay no-live-listener leg is a documented partial (CONTEXT.md §persistence). KNOWN-HAZARDS class (rule 4). (v0.14.3; ephemeral carve-out v0.15.0)
2026-07-17T03:24:38.0743947Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0744033Z 
2026-07-17T03:24:38.0744309Z ### REQ-MSG-DELIVERY-AXES
2026-07-17T03:24:38.0752282Z - Title: Activity-gated inbound delivery + per-message send control as THREE ORTHOGONAL AXES plus opaque metadata (ADR-0028; grilled w/ operator 2026-06-23). SUBSTRATE (the legacy-SPT parity gap, scaffolded-but-unwired today: `delivery::is_idle` + `resolve_inject_methods` exist but the result is discarded `let _methods`, and `broker::dispatch_endpoint_input` injects unconditionally — its comment calls activity-gating 'a deferred follow wave'): an inbound message has an ACTIVE window (endpoint active → spool for the receiver's hook-poll, non-disruptive) and an IDLE window (idle/idle-transition → deliver immediately: translation binary spt-hosted → relay-poll either topology → spool, in fallback order). AXES (each composes; each defaults to its unrestricted value): (1) DELIVERY WINDOW — default (both, first-to-fire) | `--idle-only` (idle window; immediate if already idle) | `--active-only` (active window only, never wakes; the RENAMED `--deferred` — `deferred=1` spool column + `api poll --include-deferred` keep their names). (2) CHANNEL RESTRICTION — unrestricted | `--prefer-native` (translation binary if running else fall back) | `--force-native` (binary ONLY, no fallback/no spool-to-other-method). Native flags do NOT respect the binary's idle-gating: the WINDOW says when, the native flag says through-what (so `--force-native --active-only` = binary injects during the active window, mid-turn-safe via the existing InjectFloor). (3) PERSISTENCE — durable (default; spool until delivered or TTL) | `--ephemeral` (drop if undeliverable in the accepted window — at window-open with no live carrier, or at TTL, whichever first). METADATA (orthogonal): `--json-payload '<json>'` → a single attr-escaped `json="…"` envelope attr ALONGSIDE (not replacing) the body, pure verbatim passthrough across spool/TCP/WAN/EVENT-PART, parsed only by the receiving adapter; collision-proof by construction (structured data lives INSIDE the one `json` value, can never forge `from`/`type`); available to ANY sender (confers no spt-core authority). HAZARD: `--ephemeral` is the ONLY path permitted to drop silently — the sender-opted-in carve-out to REQ-HAZARD-IDLE-SILENT-NONDELIVERY (that hazard gains a '…unless --ephemeral' clause in v0.15.0). (v0.15.0)
2026-07-17T03:24:38.0752757Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0752791Z 
2026-07-17T03:24:38.0753058Z ### REQ-RESUME-CONTEXT-PULL
2026-07-17T03:24:38.0766265Z - Title: Adapter-callable resume-context pull verb + not-yet-synthesized commune/signoff drop append (legacy-SPT parity, operator-directed 2026-06-24). GAP: spt-core exposes NO verb for a harness adapter's SessionStart hook to pull an agent's resume context — `resume::download_psyche_context` (spt-live/src/resume.rs:88, composes <live-role>+<live-context>+<project-context> from the durable two-tier store) is INTERNAL with ZERO spt callers and no ApiCmd verb (api/mod.rs ApiCmd enum has none); resume.rs:9 documents the intended 'adapter pulls it in its SessionStart hook' path but it was NEVER wired. Result: a harness adapter cannot inject the agent's durable mind on resume at all (claude-spt today runs only `api boundary` session-rotation + an identity brief — the agent resumes WITHOUT its mind). TIER-1 SCOPE (operator-approved; Tier-2 = drift-stamp/<current>/drift-directive + <memformat> + Pulse-Log DEFERRED to a separate parity item, NOT v0.15.0 — the legacy download_payload [claude_skill_owl context.rs:344] is richer but memformat is roadmap-deferred + drift-stamp is an orthogonal cross-machine-drift feature). TWO PARTS: (1) EXPOSE `spt api psyche-download <id> [--session-id <sid>]` -> stdout = the composed brief, project_id resolved from the endpoint's bound cwd (info::read_info -> cwd -> project derive; NO --project arg), auth-gated like sibling id-scoped verbs (the `gated(&id,&auth,…)` pattern); empty store -> NO-CONTEXT on stderr (mirror legacy). The adapter SessionStart hook runs it + injects stdout as additionalContext. (2) APPEND any commune/signoff drop NOT YET SYNTHESIZED into the durable tiers as a distinct <pending-commune>/<pending-signoff> slice AFTER the durable slices. GATING (operator ruling): append while NOT-YET-SYNTHESIZED, NOT merely 'while the raw file is on disk' — in today's synchronous ingest (ingest_drops route_two_slice writes durable THEN deletes the file, lifecycle.rs:466 @ DEFAULT_PULSE_PERIOD 5s) the two coincide (a watched-dir drop IS pre-synthesis), so the v1 realization reads the manifest-declared session.commune_dir/signoff_dir (manifest.rs:208/210) for a present <id>-commune.md/<id>-signoff.md (COMMUNE_SUFFIX/SIGNOFF_SUFFIX, ingest.rs); the CONTRACT keys on synthesis-state so it stays correct when async Psyche synthesis lands (a consumed-but-not-yet-committed drop stays appended via a pending-synthesis staging set — forward hook). The agent-checkpoint trigger sentinel CHECKPOINT_SENTINEL=`!!checkpoint!!` (a FIXED spt-core constant — operator-specified, CONTEXT.md §fixed-constants, NOT adapter-configurable) is stripped at BOTH drop-body points via one shared `strip_checkpoint_markers` (remove every token, keep inter-marker text, collapse trivial whitespace): the PRE-synthesis pending-append (resume::append_pending) AND the POST-synthesis durable ingest (ingest::route_slices — the single choke covering route_two_slice + signoff.write_resume_commune; strip-then-empty-filter so a marker-only slice routes nowhere) — else the marker would persist PERMANENTLY in live-context.md once a checkpoint drop synthesizes + re-trigger once the adapter's checkpoint detection is live. PRESENTATION-ONLY: the append NEVER writes the durable store (spt-core remains sole store-writer, REQ-HAZARD-DROP-FILE-SINGLE-WRITER; mirror legacy's read-only/process_file_drop-sole-deleter discipline). SELF-CLEARING: once synthesis commits the <pending-*> slice vanishes — no duplication. CORE-OWNED (not adapter): an adapter-side raw-file read RACES spt-core's ingest-delete (TOCTOU, ingest.rs:161 removes the drop on pulse-consume); the fold MUST live in the single composer all resume pulls flow through. New public CLI verb -> docs-drift gate (xtask gen + reference.md no-internal-codes, cli-command-docs-drift). (v0.15.0 parity wave W5)
2026-07-17T03:24:38.0766960Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0766993Z 
2026-07-17T03:24:38.0767275Z ### REQ-ADAPTER-TRANSLATE-PROOF
2026-07-17T03:24:38.0772513Z - Title: `spt adapter translate-proof <adapter> --event <envelope> [--session <id>]` — the author-time EMIT-half proof tool for `[message-idle-translation-binary]` (ADR-0022), symmetric to `spt adapter digest-proof` (REQ-TERM-5). It spawns and feeds the adapter's declared translation binary EXACTLY as the daemon does at idle-delivery — running the REAL `spt_daemon::translation` driver VERBATIM (no protocol reimplementation): `TranslationChild::spawn` the binary, send the `{type:"init",endpoint_id,node}` line then the `{type:"event",envelope}` line, and read back the emitted `{key}`/`{text}`/`{delay_ms}`/`{commit}` keystroke-command stream — then prints it author-readable (each Key with its `key_to_bytes` rendering, Text quoted, Delay in ms, Commit marker) with counts. It fills the SAME `{id}`→option and `{session_id}`→(--session, else a placeholder) keys into the `--event` envelope the daemon fills at runtime, so an envelope that proofs here feeds faithfully live. EMIT-half ONLY: it proves the binary's spawn+feed+emit contract; it does NOT exercise the daemon's atomic PTY apply / controller-buffering (that stays covered by the W2 inject_control_wedge int gate) — `--help` says so. Exit codes mirror digest-proof: 0 ok, 1 on spawn-fail / zero commands / no-commit-or-output / unparseable, 2 when the adapter declares no `[message-idle-translation-binary]` section. The `TranslationChild` Drop does the bounded no-zombie reap. (v0.13.x)
2026-07-17T03:24:38.0772991Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0773024Z 
2026-07-17T03:24:38.0773294Z ### REQ-HAZARD-BIND-CWD-UNSET
2026-07-17T03:24:38.0776639Z - Title: A bound endpoint's `info.cwd` is SET at bind so a freshly-created perch appears under its own project tab. ROOT (found, v0.13.0): `info.cwd` is NEVER set on bind — `cmd_bind` (spt-hosted) and `bind_from_seed` (harness-hosted) never thread cwd into `establish_perch`/`rec.cwd`. FIX: `cmd_bind` reads its own `current_dir` (the broker spawned it in `project_cwd`); `bind_from_seed` passes `seed.cwd` (already captured at seed time, currently DISCARDED). DISTINCT from REQ-PICKER-HISTORY-FRESH (v0.12.1) — that unioned cwd-origin into picker MEMBERSHIP but tested merge_origin_project with a PROVIDED origin; it never asserted `info.cwd` is actually set on bind, so a real `endpoint run` perch still had an empty cwd and the union had nothing to union. This is the v0.12.1 P1 'appears under its own project right away' claim that was REFUTED in the changelog — delivered for real here. (v0.13.0)
2026-07-17T03:24:38.0777139Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0777178Z 
2026-07-17T03:24:38.0777440Z ### REQ-PICKER-UX-V013
2026-07-17T03:24:38.0779643Z - Title: `spt endpoint run` picker UX (v0.13.0 operator dogfooding): (1) SKIP the first screen — open directly on 'Pick existing'; `n` jumps to 'Create new'. (2) AUTO-ATTACH after both Start-new AND Resume-from-history (both currently don't attach and show no stdout); add an `h` shortcut to run headless (no attach). (3) 'controlled by' shows the node NAME (node_label_display), not the raw hex. (4) Clean up Start-new output — drop the Rust `pid=Some(142748)` leak and the 'harness binds its perch on startup' internals; user-friendly, not a process log. (v0.13.0)
2026-07-17T03:24:38.0779915Z - Required stages: 
2026-07-17T03:24:38.0779953Z 
2026-07-17T03:24:38.0780230Z ### REQ-HAZARD-DRIVEN-BY-SELFHEAL
2026-07-17T03:24:38.0782185Z - Title: An spt-hosted endpoint's ONLINE+CONTROLLED state (`driven_by`) must CLEAR even when the detach IPC is lost — do NOT rely on the detach signal (same lesson as REQ-HAZARD-HOSTED-LIVENESS-RECONCILE B2): the reconcile loop clears `driven_by` when the endpoint has no live controller/session. Today a wedged or lost pump never delivers the detach, so the endpoint stays latched CONTROLLED forever. Composes with W1 (the wedge no longer blocks the detach) and rides the same pull-primary reconcile substrate as B2. (v0.13.0)
2026-07-17T03:24:38.0782505Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0782539Z 
2026-07-17T03:24:38.0782834Z ### REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT
2026-07-17T03:24:38.0788489Z - Title: An spt-hosted endpoint driven by a REMOTE controller whose remote is gone but whose broker connection stays OPEN (a wedged/lost pump that never delivers the detach) AND whose session is IDLE (no output) stays latched ONLINE+CONTROLLED forever: the W1 drain-evict only fires on OUTPUT (CONTROLLER_WRITE_DEADLINE on a backed-up write), a clean disconnect self-heals via detach_if→clear_controller, but an idle session with a half-open/wedged controller connection produces neither signal. PROVED repro-first on a real broker (v0.13.0 W5, inject_control_wedge.rs w5_a2): controller_by STAYS Some(origin) and driven_by STAYS Some after the remote is abandoned without a clean EOF on an idle session — so the brain reconcile CANNOT detect it from KIND_SESSIONS controller_by (the broker still reports it controlled). FIX DIRECTION (doyle ruling 2026-06-19, broker-side single-writer — the broker owns driven_by/clear_controller): wire the EXISTING D4c NetPresence connection-disconnect event → clear_controller for any session whose controller identity == the dead origin (become_controller already stores Some(origin); presence events already exist — modest wiring, NOT a new probe). The liveness ORACLE is QUIC's own keepalive/idle-timeout: a presence-disconnect IS a real QUIC conn close, already tolerant of transient blips within the keepalive window, so NO heavy partition ADR is needed UNLESS the QUIC timeout proves too slow for the UX (then mint an ADR for a faster controller-heartbeat + its false-evict bound). Composes with W1 (output path) + W5 Gap B (no-session) — this is the third, idle-remote, leg. (v0.13.0 follow-up)
2026-07-17T03:24:38.0789164Z - Required stages: 
2026-07-17T03:24:38.0789202Z 
2026-07-17T03:24:38.0789492Z ### REQ-HAZARD-RC-INPUT-KEY-ENCODING
2026-07-17T03:24:38.0794865Z - Title: An `spt rc` session forwards the Backspace key as the VT DEL byte (0x7f), so the hosted TUI (Claude Code) deletes ONE character — never a whole word. SYMPTOM (operator dogfooding): Backspace in an rc session always behaves like ctrl+Backspace — deletes the entire last word. ROOT (doyle /diagnose, code-grounded, byte PENDING HITL confirm): rc is a RAW VERBATIM byte pump — spawn_stdin_reader (rc.rs:152) reads std::io::stdin() bytes under crossterm raw mode and forwards them unchanged (parse_stdin_chunk only intercepts the ctrl-b detach prefix); there is NO key-event encoding and NO 0x08↔0x7f normalization ANYWHERE in the tree (grep: zero SetConsoleMode / ENABLE_VIRTUAL_TERMINAL_INPUT). On Windows, crossterm enable_raw_mode does NOT set ENABLE_VIRTUAL_TERMINAL_INPUT, so the LEGACY console delivers ^H (0x08, ctrl+h) for Backspace instead of VT DEL (0x7f); Claude Code maps ^H → backward-kill-word → the observed whole-word delete. CONFIRM-FIRST (build the loop): an env-gated hexdump in spawn_stdin_reader (SPT_RC_DEBUG_KEYS) prints the forwarded byte; operator presses Backspace + ctrl+Backspace in a real rc session. FIX CANDIDATES: (a) enable ENABLE_VIRTUAL_TERMINAL_INPUT on the rc stdin console on Windows so the console emits proper VT (Backspace→0x7f, arrows/Home/End as CSI) — cleanest, fixes the whole key map not just Backspace; (b) narrow normalize bare 0x08→0x7f in the rc input path (riskier — a real ctrl+h is also 0x08). Prefer (a) unless it regresses other keys. Add a KNOWN-HAZARDS.md entry on landing. (v0.13.0)
2026-07-17T03:24:38.0795332Z - Required stages: impl, unit
2026-07-17T03:24:38.0795376Z 
2026-07-17T03:24:38.0795666Z ### REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE
2026-07-17T03:24:38.0806407Z - Title: The effect journal serializes EVERY PTY effect under one mutex held ACROSS two fsyncs AND the blocking PTY write — so interactive input stutters and ultimately wedges the daemon hard. ROOT (doyle /diagnose, code-grounded + MEASURED on the operator's real Windows box, 2026-06-19): EffectJournal::apply_once (effect.rs:168-188) takes `inner.lock()` and holds it across `write_line(PENDING)` → `effect()` → `write_line(DONE)`, where write_line (effect.rs:235-239) does flush()+sync_all() (a full FlushFileBuffers) — so each effect pays TWO fsyncs under a GLOBAL lock, and the closure `effect()` (the actual PTY write, broker.rs:1257 EffectKind::PtyWrite via attach.rs:197 send_effect) runs while the lock is held. Two operator-visible facets, ONE root: (A) STUTTER/LAG — every keystroke is a PtyWrite effect = 2× sync_all serialized; measured fsync on %LOCALAPPDATA%\spt-core = median 6.5ms, spikes to 198ms (C: was recently at 100%), so ~13ms+ per keystroke best case, hundreds under contention → 'many but not all keypresses take 100s of ms, choppy, worsens with volume'. (B) HARD PERMANENT WEDGE — when a PtyWrite `effect()` blocks (ConPTY input buffer full / harness not draining stdin), the journal lock is held INDEFINITELY → the single-threaded inbound-stream dispatch (dispatch.rs serve_attach, which both applies input effects AND opens attaches) can never progress → EVERY subsequent attach (`spt rc --view`/`--take`) fails with 'attach request: brain IPC read deadline elapsed' (confirmed: two retries deadline identically; broker control-plane KIND queries still answer — different thread). This REFUTES the W2-deferred ruling that park-(b)/(c) is 'Windows-benign because ConPTY absorbs 4MiB' — on the real box the input path wedges regardless. DISTINCT from W1 (REQ-HAZARD-INJECT-CONTROL-COEXIST = the OUTPUT drain, correctly fixed @8b5583e; output uses broker.rs:1106 append, NOT the fsync journal). This is the INPUT/effect-journal path W1 never touched, and it is THE wedge the operator hits with --take/--view. FIX DIRECTION (candidates, repro-first — extend inject_control_wedge.rs to a REAL backed-up-PTY-consumer + a real rc-client attach assertion, the gap W1's gate missed): (1) do NOT hold the journal lock across effect() — reserve the key + fsync PENDING under lock, RELEASE, run effect(), re-acquire to fsync DONE + mark applied (preserve crash-idempotency via the per-key reservation, not a global hold); (2) bound/fail-fast the PtyWrite itself (the W2-deferred park bound — write_input must never block indefinitely, DSR-answer must not hold the writer mutex across a blocking write); (3) drop per-keystroke fsync on the interactive path — PtyWrite effects are EPHEMERAL (a keystroke lost on a broker crash is retyped; PTY state is not reconstructed from keystroke replay), so in-memory applied-set dedup suffices (the broker survives the brain — that IS the dedup anchor), with async/batched fsync or no-fsync for EffectKind::PtyWrite while durable kinds (NetSend/NetDial/Registry/Spool) keep their fsync. Combine (1)+(3) at minimum. Add a KNOWN-HAZARDS.md entry on landing. (v0.13.0)
2026-07-17T03:24:38.0807070Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0807108Z 
2026-07-17T03:24:38.0807385Z ### REQ-HAZARD-RC-ATTACH-ONLINE-RACE
2026-07-17T03:24:38.0812130Z - Title: `spt endpoint run` in an ATTACH/VIEW terminal action attaches BEFORE the freshly-spawned endpoint is online, so the attach races (or outright loses to) the harness bind. ROOT (doyle /diagnose, code-grounded): cmd_endpoint_run (cli.rs) does launch_harness_brokered_in -> (if start: return) -> run_attach with NO await-online between them. launch_harness_brokered_in returns once the harness PROCESS is spawned, but the broker-PTY bind (info status -> STATUS_ONLINE + the live session) lands ASYNC. Both picker attach paths route here with start=false (RunMode::Attach -> cmd_endpoint_run start=false,view=false): Start-now catches the endpoint mid-bringup -> run_attach attempts + loses the handshake race; Resume-from-history catches it still fully OFFLINE -> run_attach's status-gate (REQ-HAZARD-RC-ATTACH-FAILFAST) short-circuits 'offline - nothing to attach' and NEVER attempts. SAME root, two faces (the W4 attach-by-default surfaced both; an online endpoint is unaffected - the picker returns Outcome::Attach, not Run). FIX: in cmd_endpoint_run, when the terminal action is attach/view (NOT start), AWAIT the endpoint online between launch_harness_brokered_in success and run_attach - poll spt_store::info read_info().status to STATUS_ONLINE with a bounded harness-boot deadline (~25s) at a tight interval; on online -> run_attach; on timeout -> ENDPOINT_RUN_ONLINE_TIMEOUT err (do NOT attach a dead bringup). (v0.13.0)
2026-07-17T03:24:38.0812458Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0812491Z 
2026-07-17T03:24:38.0812759Z ### REQ-RC-KEY-VT-TRANSLATE
2026-07-17T03:24:38.0819719Z - Title: On Windows, `spt rc` translates CONSOLE KEY EVENTS to standard xterm VT so ALL keys reach the hosted harness — arrows/Home/End/PgUp/PgDn/Insert/Delete/F-keys, every modifier combo, Backspace/Ctrl+Backspace — not just the byte-emitting ones. ROOT (operator HITL, doyle /diagnose): `spt rc` reads raw STDIN BYTES (spawn_stdin_reader, std::io::stdin().read); on the Windows LEGACY console (no ENABLE_VIRTUAL_TERMINAL_INPUT) the special keys produce console KEY_EVENTs, NOT stdin bytes, so the byte-pump sees nothing → those keys are DEAD. Enabling ENABLE_VIRTUAL_TERMINAL_INPUT was rejected (W7 dc07c39): on Windows Terminal it yields harness-specific win32-input-mode + broke ctrl-b detach. FIX (agnostic, full fidelity): on Windows, replace the stdin byte-read with a crossterm EVENT source (crossterm 0.28 already a dep; the picker already reads events) and translate each KeyEvent → STANDARD xterm VT bytes via a PURE translate_key_event(KeyEvent)->Vec<u8> (copy a known-correct xterm table verbatim, ADR-0001 spirit), forwarded through the SAME rc pump — the harness receives ordinary xterm VT (harness-AGNOSTIC, no win32-input-mode). Press-only (drop Repeat/Release). Detach stays the ctrl-b+'d' PREFIX, event-sourced (doyle Option B): Ctrl+B arms; armed+plain-'d'⇒Detach; armed+Ctrl+B⇒emit literal 0x02; armed+other⇒0x02 then translate(other). Non-tty stdin (piped/tests) → FALL BACK to the byte-read path (keeps e2e byte-injection working). UNIX UNCHANGED (its raw-mode byte stream already delivers proper VT; cfg-split, zero Unix regression). SUPERSEDES the W7 normalize_key_byte swap on Windows — the translator emits 0x7f for Backspace and 0x08 for Ctrl+Backspace natively (REQ-HAZARD-RC-INPUT-KEY-ENCODING folded in). NO int (a live interactive console can't be driven in CI — HITL, REQ-RUN-PICKER/RC-1 precedent); the exhaustive non-vacuous translate_key_event mapping unit + the event-detach unit ARE the surface. (v0.13.0)
2026-07-17T03:24:38.0820151Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0820185Z 
2026-07-17T03:24:38.0820495Z ### REQ-HAZARD-PTY-INPUT-WRITER-WEDGE
2026-07-17T03:24:38.0827899Z - Title: Pasting into an `spt rc` session WEDGES the broker — after a paste the operator can no longer type AND can no longer attach to NEW or EXISTING sessions (`brain IPC read deadline`). ROOT (doyle /diagnose, code-grounded): the operator-keystroke path rc -> net-stream Input -> serve_attach (attach.rs:197 brain.send_effect) -> KIND_INPUT -> broker dispatch loop (broker.rs:1091) -> dispatch_input (broker.rs:1459) -> session.write_input(&bytes) runs SYNCHRONOUSLY on the broker request-handling thread. W1b (REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE) released the journal lock across the effect (fix 1) + made PtyWrite ephemeral/no-fsync (fix 3) but EXPLICITLY DEFERRED fix (2) — bound/fail-fast the PtyWrite itself. A single keystroke never fills the ConPTY input buffer; a PASTE BURST does -> write_input blocks -> the dispatch thread cannot service the next frame (a re-attach subscribe, a become_controller restore-write, an inject-floor flush) -> wedge. Not a bug-2 regression (the byte path funnels to the same write_input; paste just reliably fills the buffer). FIX (doyle design, V0.13.0-P0-PTY-INPUT-WRITER-DESIGN.md, CONTEXT L33 broker-owns-PTY/minimal + L435 SessionSurface + single-writer pattern): one dedicated per-session INPUT-WRITER THREAD = the SOLE caller of the blocking write_input, fed by a BOUNDED FIFO channel; every caller (dispatch_input, serve_attach->send_effect, inject-floor flush) ENQUEUES + returns immediately, never blocks. A blocked/slow harness blocks ONLY its own writer thread, never the broker dispatch. Backpressure (operator ruling): queue full => DROP excess input + stamp the session INPUT_BACKPRESSURE (visible health signal); the daemon NEVER wedges; a merely-slow harness self-heals as the writer drains. Exactly-once preserved (PtyWrite ephemeral: apply_once effect = the non-blocking enqueue => Applied; ack now means accepted+ordered, benign — rc does not gate on landing); order preserved (single FIFO + single writer); inject-floor (W2 Layer C) choreography moves to the lone writer. Completes the W1b-deferred fix (2), cross-platform (cfg(unix) forkpty park folds in). (v0.13.0)
2026-07-17T03:24:38.0828392Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0828434Z 
2026-07-17T03:24:38.0828707Z ### REQ-SESSION-RESUME-TEMPLATE
2026-07-17T03:24:38.0836787Z - Title: Resuming an endpoint session that HAS conversation history brings up a BLANK session. ROOT (doyle, code-grounded + CONTEXT — case-3 spt-core MISSING feature, NOT a perri docs-miss): CONTEXT L127-129 already defines the resume-session seam ('continue-existing: resume an existing harness session under the adapter — its NATIVE resume'), and the manifest already has the resume-variant pattern (Session has BOTH psyche_init AND psyche_resume, manifest.rs:217-219) — but the agent's own session has ONLY self_ (`[session.self]`, no resume sibling). cmd_endpoint_run (cli.rs:1304) re-passes the session_id through `[session.self]` on resume (resume.unwrap_or_else(mint_session_id)), so the adapter's FRESH command (e.g. `claude --session-id ..`) runs again instead of the harness NATIVE resume (`claude -r ..`) -> CC starts a fresh transcript -> blank. spt-core forwards session_id + cwd faithfully; it just has no way to express the native-resume invocation. SECOND GAP: CC resolves a transcript by session_id + cwd, but the session ledger records only {ts, session_id, trigger} (no cwd), so picker Resume-from-history (cross-project rows) can't restore the right cwd. FIX (doyle design, V0.13.0-P2-SESSION-RESUME-DESIGN.md, mirrors psyche_init->psyche_resume exactly): (A) add a `[session.resume]` role (resume: Option<SessionRole> on Session + roles()/is_empty()); cmd_endpoint_run selects it when --resume is set AND it's declared (fill {id}/{session_id}=resumed id/{session_name} + the resume cwd), else FALL BACK to `[session.self]` (full back-compat). (B) record cwd PER ledger row (operator ruling): {ts, session_id, trigger, cwd} additive serde-default; resume cwd = resumed row cwd -> else perch info.cwd -> else current_dir (back-compat for old rows + single-project endpoints); picker threads the selected row's cwd through Outcome::Run -> cmd_endpoint_run. (C) public docs (MANIFEST + harness-contract) teach `[session.resume]` so perri builds the adapter side BLIND. Adapter follow-on (perri, AFTER spt-core ships+docs): declare `[session.resume] command = claude -r {session_id} --remote-control {id} --dangerously-skip-permissions` from the resume cwd. Completes REQ-READY-AGENT-RESUME / REQ-RUN-PICKER resume-from-history. (v0.13.0)
2026-07-17T03:24:38.0837267Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0837287Z 
2026-07-17T03:24:38.0837549Z ### REQ-RC-WIN-PASTE
2026-07-17T03:24:38.0843228Z - Title: In an `spt rc` session neither ctrl+V nor right-click pastes (CC explicitly supports ctrl+V). ROOT (doyle /diagnose): RawGuard does only enable_raw_mode (no bracketed paste / no mouse capture / no clipboard interception); the Windows console delivers a paste as synthetic per-char KEY EVENTs (no crossterm Event::Paste), and ctrl+V translates to bare ^V forwarded to CC — but CC runs DAEMON-SIDE with NO access to the operator's LOCAL clipboard, so remote paste is fundamentally CLIENT-ORIGINATED. A multi-line paste-as-keys also becomes a \r submit-storm. FIX (doyle design, V0.13.0-P1-RC-PASTE-DESIGN.md, cfg(windows), folds into the bug-2 event path): on a paste gesture rc reads the LOCAL clipboard + forwards a BRACKETED PASTE (ESC[200~ + content + ESC[201~); CC has bracketed-paste mode on (its TUI sets ESC[?2004h) so it treats it as a paste — content intact, no submit-storm, harness-AGNOSTIC. ctrl+V: intercept Char('v')+CONTROL in the event loop -> read_clipboard -> bracketed paste. Right-click: RawGuard also EnableMouseCapture (disables console QuickEdit + enables ENABLE_MOUSE_INPUT so right-click surfaces as Event::Mouse on legacy cmd/powershell) -> right-button -> read_clipboard -> bracketed paste; DROP all other mouse (CC has no mouse features, operator-confirmed, so capture costs nothing). read_clipboard = clipboard-win crate (cfg(windows), minimal); empty/failed = clean no-op. Content forwarded VERBATIM (literal pasted text, no per-char translation). Unix UNCHANGED (its terminal pastes natively through the byte pump). DEPENDS ON P0 (a paste chunk must not wedge the broker). (v0.13.0)
2026-07-17T03:24:38.0843687Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0843721Z 
2026-07-17T03:24:38.0844007Z ### REQ-HAZARD-INPUT-ACK-BACKPRESSURE
2026-07-17T03:24:38.0852610Z - Title: A FLOOD of operator input on one brain↔broker connection deadlocks the broker PERMANENTLY (entire broker — no new/existing attach; the controller stays latched because the per-conn handler can't process the detach). ROOT (doyle /diagnose, code-grounded + HITL capture, the v0.13.0 P1 ctrl+V re-open): `serve_attach` processes a whole `NetStreamData` batch of N operator `Input` records in its inner `for rec in decoder.push()` loop, calling `brain.send_effect(op_id, &bytes)` N times WITHOUT returning to `read_event()` — so the brain writes N `KIND_INPUT` frames back-to-back and drains nothing. The broker's single-threaded per-conn handler answers EACH with `send_frame(applied_envelope)` on the SAME conn (B5 exactly-once ack, KNOWN-HAZARDS 7.2). With the brain not reading, the broker→brain return direction fills (~10 frames = the IPC pipe buffer) → `send_frame` BLOCKS → the handler stops reading → the brain's writes block too → mutual full-duplex DEADLOCK. Capture pinned it: 11 input frames, write_input 11/11 (P0 holds — the PTY write is fine), ack send START=11 / END=10 (frame #11's applied-ack never returns). Same class as the v0.12.1 L0 two-conn split. Windows Terminal's ctrl+V paste accelerator was the trigger (injects the clipboard as a char-by-char key flood) but the deadlock is generic to ANY input flood, NOT ctrl+V-specific and NOT a P0 (PTY-write) or W1 (output-drain) regression. The applied-ack is load-bearing ONLY for `shellchan` (one-at-a-time spool delivery WAITS on `BrokerEvent::Applied`); `serve_attach` DISCARDS it (the operator/rc path is fire-and-forward, op_id for dedup only, never gates on the ack). FIX (doyle-approved): CONDITIONAL ACK — `InputReq` gains `ack: bool` (serde default = true, N-1-safe: an older brain's input still acks = today's behavior). `serve_attach`'s operator path calls `send_effect_no_ack` (ack=false) → `dispatch_input` writes NO applied frame → the per-conn handler never writes back while servicing the flood → it always drains → no deadlock (cures ANY input flood). `shellchan` keeps `send_effect` (ack=true) and its `Applied`-wait. Exactly-once PRESERVED: the broker still dedups by (session, op_id) at the applied-set regardless of the ack. N-1 caveat: an OLD resident broker (self-update window) ignores `ack=false` → still acks → the deadlock persists until a broker restart (inherent KNOWN-HAZARDS 7.9 broker-resident-wire-change class). (v0.13.0)
2026-07-17T03:24:38.0853126Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0853163Z 
2026-07-17T03:24:38.0853427Z ### REQ-RC-MOUSE-FORWARD
2026-07-17T03:24:38.0858693Z - Title: On Windows, `spt rc` must FORWARD scroll-wheel events to the harness when the harness has mouse reporting on. ROOT (operator HITL): P1's RawGuard EnableMouseCapture (added for right-click paste, REQ-RC-WIN-PASTE) makes Windows Terminal forward ALL mouse — including the scroll wheel — to rc instead of scrolling its own buffer, but the rc mouse handler dropped everything except right-button-down → scroll DIED (and WT's native scrollback is stolen by the capture). Operator ruling: keep mouse capture + right-click bracketed paste AND forward scroll to the harness. FIX (doyle design, cfg(windows), folds into the rc mouse handler): TRACK the harness's mouse-reporting mode by scanning its OUTPUT stream for the DECSET set/reset — ESC[?1000h/1002h/1003h (mouse on) + ESC[?1006h (SGR ext) and their ...l (off) — into a shared MouseMode{enabled,sgr} (pump writes from output, stdin reader reads); the scan survives a sequence SPLIT across output chunks (a bounded carry buffer). The mouse handler: right-button-DOWN -> bracketed clipboard paste (unchanged, REQ-RC-WIN-PASTE); ScrollUp/Down -> translate to an xterm SGR mouse report (ESC[<64;col+1;row+1M up / ESC[<65;..M down, 0-based crossterm -> 1-based xterm) and forward ONLY when enabled && sgr (else DROP — a legacy X10 report the harness may not parse is garbage); Moved/drag/left/middle -> DROP (scroll is the operator's need; click-forward risks garbage, no click-to-position). Unix UNCHANGED (no capture; the terminal scrolls natively). (v0.13.0)
2026-07-17T03:24:38.0859255Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0859289Z 
2026-07-17T03:24:38.0859580Z ### REQ-HAZARD-CONTROLLER-WRITER-REORDER
2026-07-17T03:24:38.0875815Z - Title: Two `controller_writer` threads must never race ONE brain↔broker connection's socket. ROOT (doyle, instrumented RACEDIAG repro on kitsubito): on a brain-restart re-serve the handoff brain registers as controller on the SAME session TWICE over the SAME `Brain::conn` socket — (1) `Brain::handoff` eagerly `subscribe(prior.session_id, prior.next_seq=1)` → `become_controller(from_seq=1)`, initial=[1], spawns writer-A (writes seq 1); (2) `serve_attach` re-handles the replayed `Request{from_seq:0}` → `attach_as(sid,0)` → `become_controller(from_seq=0)`, initial=[0,1], spawns writer-B (writes 0 then 1). `become_controller` (broker.rs) drops the prior `ControllerSink` (its `tx`) but does NOT stop the prior writer thread — writer-A keeps flushing its owned `initial` batch, and both writers hold clones of the same `SharedSend` (`Arc<Mutex<socket>>`) with NO inter-thread ordering. When writer-A's seq 1 wins the socket before writer-B's seq 0, the strict legacy consumer (brain.rs read_event reject-gap path) sees `output gap: got seq 1 want 0` → the test `attach_survives_target_brain_restart_exactly_once` panics at `.expect("re-serve")` OR HANGS in `render_until` (serve thread died on the gap → MARKER_TWO never reaches the wire). `prior.next_seq` is life1's CONSUMPTION cursor, NOT life2's connection state — life2's socket has been sent NOTHING, so a `from_seq=0` full replay on a connection that already streamed seq 1 is contradictory. Snap-above tolerance ALONE can't fix it (it would dedup-drop the late seq 0 → byte loss → the exactly-once byte-identity assert fails). PRE-EXISTING, surfaced by the v0.13.0 green-both-runners release gate; P1b is INNOCENT (its diff touches only input-ack machinery, proven mechanically + the test passes post-P1b in isolation). Sibling flaky cluster: `inject_control_wedge::g2`, `broker::spawn_env_reaches_child`. INVARIANT: on a single brain↔broker connection the controller output-frame stream is monotonic non-decreasing in seq (modulo dedup re-sends); exactly ONE `controller_writer` is ever live per connection; a SUPERSEDED writer writes NO further frames; a re-serve never replays a seq below what the connection already received. FIX (doyle design, corrected at the gate 2026-06-20): fix #1 as designed ('drop handoff's eager subscribe so serve_attach's attach_as is the sole registration') was REVERTED — handoff's `subscribe(prior.next_seq)` IS the standalone-resume mechanism (the brain-only update engine `apply_brain_only` + the `handoff`/`idempotent`/`daemon_e2e` int tests replay output through it with NO `serve_attach`; dropping it hung every resume-via-handoff test). The shipped fix is three parts: (1) CORRECTNESS — `Brain::handoff` seeds `session_cursors` at `prior.next_seq` so the consumer runs the production dedup-below+snap-above path, never the strict reject-gap legacy trap; this is COMPLETE (not merely tolerant) because every `controller_writer` emits an ASCENDING seq stream and the surviving writer (serve_attach's attach_as(sid,0)) offers the complete `[0,end]` range, so a snap-above merge of ascending writers delivers `[K,end]` with no skip/dup (first sighting of any seq>M is preceded by M on that writer). (2) INVARIANT — `controller_writer`'s INITIAL-BATCH replay is epoch-gated: `controller_epoch` is a shared `Arc<AtomicU64>`, the writer re-reads it UNDER `send.lock()` (atomically with `write_frame`) and returns the instant it is superseded — no check-then-block-then-write window, no superseded replay (W1-safe: never blocks the drain under `Mutex<OutputLog>`). The LIVE loop is NOT gated (new output only flows to the current controller; a superseded writer must still deliver its terminal `Displaced` kick — gating it suppressed the loud-take notice; it ends on `tx`-drop). (3) EXPLICIT-RESUME / OPERATOR-STREAM BOUNDARY (the LOAD-BEARING fix — kitsubito RACEDIAG ~33% repro the keystones missed) — `Brain::subscribe_with` (shared by attach/attach_as) resets the resume-mode dedup cursor to `from_seq`. The handoff eager subscribe makes serve_attach's brain receive the replay's seq K BEFORE the operator Request is processed (`attached`=false); that frame is dropped by the if-attached forward gate but the snap-above cursor already advanced past K, and `attach_as(sid,0)`'s re-subscribe used to leave the cursor advanced → the broker's re-send of seq K arrives below it, deduped, never forwarded → operator viewport forward-gap (silent content loss in the real rc consumer). Resetting to from_seq on the attach_as re-subscribe re-delivers from 0 (operator dedups the overlap) so seq K reaches the viewport. The epoch gate (2) is sound (RACEDIAG: zero socket interleaving above K); cold-start brains (empty map — production dispatch serve) keep the legacy next_seq path, so production is unaffected. (v0.13.0)
2026-07-17T03:24:38.0876641Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0876674Z 
2026-07-17T03:24:38.0876966Z ### REQ-HAZARD-CONTROLLER-RETAKE-FLOOR
2026-07-17T03:24:38.0882178Z - Title: `become_controller` should STRUCTURALLY refuse a controller re-take whose `from_seq` falls below the connection's already-delivered contiguous floor — making the P1c reorder invariant un-reintroducible by a future caller, not just removed at the one caller. ROOT/SCOPE (doyle proposed, P1c gate dialogue): P1c fixes REQ-HAZARD-CONTROLLER-WRITER-REORDER three ways (handoff single-take + epoch-gate-under-lock + session_cursors seed), removing the one decreasing-floor double-take and bounding any other to already-committed-only. A self-enforcing broker guard would refuse the bad SHAPE outright. BLOCKER: the obvious predicate (`from_seq >= delivered_through`) is UNSAFE because `delivered_through` is SESSION-WIDE (the `Arc<AtomicU64>` on `OutputLog`, shared by all controllers/viewers, advanced monotonic-MAX; `resume_seq` reads it) — a normal fresh-operator `from_seq=0` attach to a producing session legitimately sits below it (full ring replay + consumer dedup-below/snap-above), and monotonic-MAX can't distinguish the hazard (a `seq1`-without-`seq0` write reads as `2`). The structurally-correct guard needs a NEW per-connection contiguous-sent cursor (the true highest-contiguous seq this socket has received) that does not exist today; the guard then refuses a re-take below THAT. Bigger than P1c; no live gap (P1c fully fixes the actual bug). Mint/refine stages when the per-connection cursor is built. (v0.13.0 follow-up, post-ship)
2026-07-17T03:24:38.0882512Z - Required stages: 
2026-07-17T03:24:38.0882564Z 
2026-07-17T03:24:38.0882845Z ### REQ-ADAPTER-MULTIPLATFORM-SPT
2026-07-17T03:24:38.0886252Z - Title: A `.spt` adapter archive may pack multiple platforms in one signed asset: shared `manifest.toml` + `strings/` at the root, role binaries under per-Rust-target-triple subdirectories (ADR-0016 triple vocabulary, e.g. `x86_64-pc-windows-msvc/`); install/update extracts the shared root plus ONLY `current_platform()`'s triple subdir, flattened into `install_dir` so flat `<install_dir>/<program>` resolution (REQ-INSTALL-11) is unchanged. Name stays `adapter.spt` (plain-tar or gzip, `--asset` optional default); one whole-archive Ed25519 signature over the fat archive (REQ-UPD-9 single-artifact verify). A legacy flat archive (no triple subdirs) extracts as today (free back-compat); a multi-platform archive sets `min_spt_core_version >= 0.13.2` (forward-compat gate, readable before extract); a multi-platform archive missing the recipient's triple -> typed `NoArtifactForPlatform`, never a silent no-op. Large adapters may still split per-platform (single-triple archives via `--asset`, or ADR-0016 update-set machinery). (ADR-0024, v0.13.2)
2026-07-17T03:24:38.0886680Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0886713Z 
2026-07-17T03:24:38.0886983Z ### REQ-ADAPTER-LIVE-UPDATE
2026-07-17T03:24:38.0890746Z - Title: An adapter update is live and daemon-coordinated (the adapter analog of brain self-update, ADR-0004): for an endpoint with a running RESIDENT adapter binary (today the `[message-idle-translation-binary]`), the CLI keeps fetch+verify and hands the APPLY to the daemon over IPC, which per affected endpoint (1) STOPS the resident binary -> releases the OS file lock (fixes the Windows 'Access denied (os error 5)' overwrite failure), (2) swaps on disk ONLY files whose CRC differs from the staged archive (unchanged files + their still-running binaries untouched), (3) RE-CLONES the new on-disk manifest into the running `BrainLifecycle` (the in-memory manifest is cached at bringup and otherwise goes stale -> binaries+manifest back on the same page), (4) RESTARTS the resident binary from the new files. An endpoint NOT running -> CLI swaps directly (no lock, no cache). Only the resident class is cycled; ephemeral adapter binaries (Psyche loop, `[digest]` extractor, `[session.*]` runners, hooks) self-heal on next spawn and are excluded. The daemon keeps a per-endpoint registry of resident adapter children. (ADR-0025, v0.13.2)
2026-07-17T03:24:38.0891151Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0891184Z 
2026-07-17T03:24:38.0891475Z ### REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP
2026-07-17T03:24:38.0897069Z - Title: A DELEGATED live adapter apply MUST NEVER report success without performing the swap, and the live-update seam MUST use ONE parent-aware adapter matcher across all its comparators. TWO defects made the field repro (BUILD-F015B-APPLYMATCH: `--adapter cc:ccs` live update silently no-ops): (D1, matcher skew) the broker's dispatch_adapter_apply filtered sessions by EXACT `s.adapter == req.adapter`, but a `--adapter <adapter>:<profile>` endpoint stores the COMPOSITE `cc:ccs` while the apply carries the PARENT record name `cc` — so every :profile endpoint fell out to affected=[]; select_endpoints_running_adapter had the same `adp == adapter` skew, while the CLI live-gate (adapter_has_live_endpoint) already parent-matched — divergent rules on ONE seam. (D2, silent success) the affected.is_empty() branch replied KIND_APPLIED and RETURNED WITHOUT SWAPPING; once the CLI delegates the apply there is no CLI-side fallback swap, so success-without-swap = the update never lands (re-register re-reads the OLD manifest, version-of-truth honestly says old). FIX: (1) ONE shared spt_runtime::profile::adapter_parent_matches(session_adapter, parent) used by the live-gate + broker apply-filter + select_endpoints_running_adapter (no exact `==` against a record name at any live-update seam); (2) the daemon owns the whole apply once delegated — the CRC swap runs UNCONDITIONALLY (terminate/restart loops no-op when nothing is resident), KIND_APPLIED reported ONLY after a real swap. (F015B, ADR-0025 amendment)
2026-07-17T03:24:38.0897420Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0897468Z 
2026-07-17T03:24:38.0897761Z ### REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP
2026-07-17T03:24:38.0901505Z - Title: Endpoint-stop and brain-death reconcile MUST reap a brain-less perch's orphan detached Psyche via the cmdline-scoped guard (`psyche_orphan_should_reap`) — the handle-reap (`LiveSet::stop_host`, REQ-HAZARD-UNHOST-PSYCHE-REAP) CANNOT, because the owning brain is gone (its `psyche_child` handle died with it), and the brain-start scoped-reap (REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP) never fires for a perch being STOPPED rather than re-hosted. So the live-host calls the scoped reap after `stop_host` at the reconcile stop-side AND in `confirm_residency_or_unhost`. Preserves fail-safe-decline (pid-alive AND exe-basename==psyche-program AND cmdline contains `<id>-psyche`; any unreadable signal DECLINES — a missed dup is bounded, a wrong-kill is catastrophic). This is the orphan-leak half of the perri F-010xF-015 field bug (the unsupervised install-dir Psyche that locked an update); the other half is the psyche own-copy (ADR-0025 amendment). (v0.13.2 W3 (a))
2026-07-17T03:24:38.0901936Z - Required stages: 
2026-07-17T03:24:38.0901969Z 
2026-07-17T03:24:38.0902242Z ### REQ-ADAPTER-UPDATE-MESSAGE
2026-07-17T03:24:38.0904132Z - Title: An adapter manifest may declare `[update].message` — a plain (multi-line) human notice surfaced to stdout, markdown-rendered (the v0.13.0 helpfmt prose path), ONLY when `spt adapter update` actually APPLIES an update (version changed), not on a no-op. Read from the newly-installed manifest; avenue-agnostic (gh_release/delegated/file_pull). No `{key}` substitution. Use: an adapter telling the operator a post-update action, e.g. spt-claude-code's "run `/reload-plugins` in any ongoing sessions". (v0.13.2)
2026-07-17T03:24:38.0904462Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0904553Z 
2026-07-17T03:24:38.0904815Z ### REQ-ADAPTER-GH-TRANSPORT
2026-07-17T03:24:38.0906537Z - Title: The `gh_release` avenue (and `spt adapter add --release`) gain a fetch `transport`: `https` (current reqwest direct, public), `gh` (shell the pre-authorized `gh` CLI — the private-repo path; `gh` honors OAuth and `GH_TOKEN`, so spt custodies no token), or `auto` (default: prefer `gh` when installed+authed, else HTTPS). `--gh`/`--https` force it on `add`. Additive over the existing fetch path; verify->extract->register downstream is unchanged. (v0.13.2)
2026-07-17T03:24:38.0906881Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0906918Z 
2026-07-17T03:24:38.0907199Z ### REQ-ADAPTER-PROOF-DIR-OVERRIDE
2026-07-17T03:24:38.0909142Z - Title: The author-time proof commands (`spt adapter digest-proof`, `spt adapter translate-proof`) gain a `--dir <path>` / `--manifest <file>` override so an author proofs a DEV binary against an on-disk manifest+install dir WITHOUT staging a full extracted GhReleaseManaged install (mirrors digest-proof's `--sample` pointing straight at a file). Fixes perri F-011: a bare-file-added gh_release adapter currently can't be resolved by the *-proof commands ('manifest is not present yet at <dir>'); un-stales the bare-file digest-proof int. (perri F-011, v0.13.x DX)
2026-07-17T03:24:38.0909485Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0909518Z 
2026-07-17T03:24:38.0909790Z ### REQ-ADAPTER-VERSION-CMD
2026-07-17T03:24:38.0911713Z - Title: `spt adapter version <name>` prints a registered adapter's declared version — the EXISTING mandatory `[adapter].version` manifest field (manifest.rs already requires it; NOT a `[strings].version`, NOT `get-string`, no second version source). A new `AdapterCmd::Version{option}` resolves the option's merged view via `registry::resolve_option` like the sibling adapter subcommands and prints `manifest.adapter.version`; an unresolvable option errors (exit 1) the same way. (v0.13.2 W6)
2026-07-17T03:24:38.0912019Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0912052Z 
2026-07-17T03:24:38.0912324Z ### REQ-DOCS-NO-INTERNAL-CODES
2026-07-17T03:24:38.0914378Z - Title: Public CLI --help (the clap `///` doc-comments) and the generated `docs-site/src/cli/reference.md` MUST NOT contain internal tracker/decision codes — `REQ-*`, `F-###`, `M#-W#`, `ADR-####`. They are meaningless to an end user reading --help and ship to GH-Pages. A CI-gated scan (the `xtask check` docs gate) fails on any such token in the GENERATED reference.md (which by construction contains only clap help, so rustdoc `///` on fns/structs is OUT of scope and keeps its REQ/ADR cross-refs). Substance is kept; codes are rewritten to plain language. (v0.13.2 W6)
2026-07-17T03:24:38.0914678Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0914712Z 
2026-07-17T03:24:38.0914983Z ### REQ-RUN-MULTISUBNET-HOME
2026-07-17T03:24:38.0918379Z - Title: `spt endpoint run` resolves the home subnet at the skeleton-create step and pre-creates the skeleton perch carrying it, so the harness `bind` inherits home via establish_perch's immutable prior-branch (no hook change, no env injection). Resolution: sole-subnet auto; multi-subnet + no --subnet + NON-interactive terminal -> refuse early with MRU-ordered --subnet guidance (never the silent 25s online-timeout); multi-subnet + no --subnet + INTERACTIVE -> print proposed config (id/project/adapter[:profile]/home=MRU-default) + 'Ok to proceed? Y/n', n -> --subnet guidance; --subnet overrides + validates membership. MRU = ordered move-to-front LISTs at two levels (per-project + always-updated node-global fallback). Home stays IMMUTABLE (ADR-0010). Fixes the LATENT multi-subnet bringup gap (perri, not a regression — HOME_REFUSED established >=0.11.0; exposed by the node crossing 1->2 subnets). (ADR-0026)
2026-07-17T03:24:38.0918805Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0918838Z 
2026-07-17T03:24:38.0919197Z ### REQ-ENDPOINT-UNBOUND-ATTACH
2026-07-17T03:24:38.0922526Z - Title: An spt-hosted endpoint is ATTACHABLE between spawn and bind: gate the attach on the broker SESSION being attachable (session+PTY+OutputLog exist at spawn, before bind), not on perch STATUS_ONLINE (bind). cmd_endpoint_run + `spt rc <id>` attach to a live broker session regardless of perch status (headless bringups too; lets an operator clear a bind-gating prompt) -- replaces await_endpoint_online; preserves REQ-HAZARD-RC-ATTACH-ONLINE-RACE's 'no attach before a session' intent at the earlier session-exists point; source = the broker sessions map (ADR-0025 W3a); local-only. New on-disk status STATUS_UNBOUND (spawn->unbound, bind->online, death->offline); lifecycle reuses the existing exit-waiter/reconcile (session death->offline); unbound is attachable but NOT message-addressable (messaging stays online/bound-gated). EpDisplay gains Unbound = HOLLOW (+ hollow-controlled variant) -- amber=HarnessOnly is taken + means not-controllable (the opposite of attachable). (ADR-0027)
2026-07-17T03:24:38.0922931Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0922969Z 
2026-07-17T03:24:38.0923227Z ### REQ-MANIFEST-SUBST
2026-07-17T03:24:38.0926465Z - Title: Manifest substitution primitives for resolve-not-execute (ADR-0029, supersedes a rejected `spt api run-hook`): (1) two adapter-static substitution keys `{adapter_dir}` (the registry record's precise source_dir — install dir, survives updates, the dir bare-program resolution uses) and `{adapter_name}`, available wherever command/string substitution runs; (2) lazy substitution INSIDE `[strings]` values at `get-string` read time, scoped to those adapter-static keys ONLY (session-scoped {id}/{session_id}/… are NOT available — get-string carries no session; a get-string --session-id is a deferred larger change). Invariant preserved: spt-core never executes a string — it substitutes and returns; the adapter's own wrapper executes the result (e.g. a CC hook dispatcher get-strings its packed binary once per session into an env var, then runs it per-hook, so hook logic rides `spt adapter update`). (v0.16.0)
2026-07-17T03:24:38.0926798Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0926832Z 
2026-07-17T03:24:38.0927099Z ### REQ-ADAPTER-UPDATE-POST
2026-07-17T03:24:38.0930825Z - Title: Composite adapter update — an avenue-agnostic `[update.post]` sub-table `{ command, self_verifies }` run AFTER the primary avenue (gh_release/file_pull/delegated) resolves, in the same `spt adapter update` (ADR-0029). Runs UNCONDITIONALLY (even on an adapter version no-op — the post-step's own idempotent check decides). PUBLISHED stdin JSON seam: one line `{adapter_applied, adapter_name, profile_name, version, previous_version, adapter_dir}` (additive keys; post-step ignores unknown). stdout decides the notice: custom text SUPERSEDES [update].message; a reserved sentinel fires the static [update].message; empty = no notice. exit code orthogonal (0 ok / nonzero failed). Precedence: dynamic-stdout > sentinel/manifest-message > nothing. NO [update.post] declared ⇒ today's adapter_applied→[update].message unchanged; post-step FAILS ⇒ loud warning + fall back to adapter_applied→message. FAILURE-ISOLATED: a committed gh_release pull is never rolled back if the post-step fails (independent channels). (v0.16.0)
2026-07-17T03:24:38.0931259Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0931297Z 
2026-07-17T03:24:38.0931558Z ### REQ-TRANSLATE-COMMAND
2026-07-17T03:24:38.0935632Z - Title: `[message-idle-translation-binary]` accepts a `command` (opaque; args + ADAPTER-STATIC {adapter_dir}/{adapter_name} substitution ONLY — ratified v0.16.0 W1, NOT session {key}: the translation binary is a persistent process serving all sessions on the endpoint (session/event ctx arrives per-message via the stdin Init/Event protocol, never the spawn argv) and the live-update respawn site has no session ctx (a {id}-bearing command would MissingKey→spool); program token resolved against install_dir like [digest].extractor/[session.psyche_init]) in addition to the bare `path`. `path` is DEPRECATED — keeps parsing (manifest forward/back-compat) but emits a registration warning steering to command. Exactly one of {path, command} (both-set refused at registration; neither = no translation binary). The spawn lifecycle + stdin/stdout JSON-lines protocol (Init/Event/Input → key/text/delay_ms/commit) are UNCHANGED — command alters only how the executable+args are located/launched (read_translation_path → read_translation_command). Unblocks folding `claude-spt translate` into the one consolidated binary (downstream ADR-0006). (v0.16.0)
2026-07-17T03:24:38.0936084Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0936123Z 
2026-07-17T03:24:38.0936413Z ### REQ-SEND-REPLYTO-REMOVE
2026-07-17T03:24:38.0938147Z - Title: Remove `--reply-to` from `spt send` — a target-fallback + REPLIED-label nicety that confuses agents, with no wire effect (ADR-0020 already made messages structural (from,body), no __REPLY_TO__). Hard-remove (no deprecation shim): the clap flag, the is_reply/REPLIED label branch (always SENT/QUEUED), the `send` how-to --reply-to example, and the reply-to mention in REQ-DOCS-6's send topic. Reply-correlation stays on the structural `from` attribute. (v0.16.0)
2026-07-17T03:24:38.0938466Z - Required stages: impl, unit
2026-07-17T03:24:38.0938508Z 
2026-07-17T03:24:38.0938767Z ### REQ-DIGEST-CURSOR
2026-07-17T03:24:38.0943233Z - Title: `spt endpoint digest` gains incremental turn-end consumption (extends REQ-TERM-4/5): `--last <N>` = the last N TURNS (the digest's natural unit; --last 1 = the latest turn = turn-end output); a per-entry STABLE SOURCE-DERIVED `seq` in the --json output (deterministic from the entry's append position in the source — transcript record index across the session ledger / digest.log index — so a live re-projection yields the same seq for the same committed entry; NOT a window-position index that renumbers on slide); `--after <seq>` = entries newer than seq still in the window (full window + signal if seq predates it, mirroring the version-slide full-refresh). An in-flight (still-growing) entry is flagged `partial: true` with NO stable seq until finalized (consumer reprocesses partial, skips <= seq). Also emit per-entry `ts` where present (seq is the authoritative dedup+cursor key). The digest's agent text is sufficient fidelity (no raw-source mode). BINDING doc-guidance: an adapter's [digest] extractor / api digest-entry MUST classify delivered user-facing messages as turn-opening `input` (equiv to direct PTY user-input), else messaging-driven sessions collapse into a few giant turns and --last/seq lose granularity. (v0.16.0)
2026-07-17T03:24:38.0943675Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0943708Z 
2026-07-17T03:24:38.0943966Z ### REQ-CLI-JSON
2026-07-17T03:24:38.0946511Z - Title: A global `--json` flag (clap global=true) honored by the READ/STATUS command set: endpoint list/whoami, daemon status, subnet status/show-code, endpoint description/role, adapter list/version, notif list, grant list, access list, shell list, how-to (endpoint digest already has it). Action commands do not honor it. A shared print_json() helper + a coverage TEST asserting every command in the set emits valid JSON (guards against the missing-shared-formatter drift). Output uses explicit per-command output DTOs with committed field names — internal structs are NOT serialized verbatim (their fields would become a public contract; JSON is a consumed wire-parity surface). (v0.16.0)
2026-07-17T03:24:38.0946817Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0946845Z 
2026-07-17T03:24:38.0947108Z ### REQ-RUN-EMPTY-CREATE
2026-07-17T03:24:38.0948825Z - Title: `spt endpoint run` / bare `spt` routes a TOTALLY-EMPTY scope straight to the endpoint-creation flow: when gather_endpoints() is empty (nothing attachable, local OR subnet) PickerModel::new opens on Screen::CreateAdapter instead of PickExisting (today it always opens PickExisting + renders a blank list). A node WITH subnet endpoints but no local ones still has things to pick → stays on the picker. Extends REQ-RUN-PICKER. (v0.16.0)
2026-07-17T03:24:38.0949192Z - Required stages: impl, unit
2026-07-17T03:24:38.0949351Z 
2026-07-17T03:24:38.0949609Z ### REQ-RC-IDENTITY
2026-07-17T03:24:38.0952476Z - Title: `spt rc` overlays a persistent endpoint-identity marker so the operator always groks which endpoint they control: a reserved TOP status row via a DECSTBM scroll-region (shrink the PTY's reported rows by 1, own the row), right-aligned `SUBNET : ENDPOINT_ID @ NODE`, CYAN text. Re-assert the margin + repaint on alt-screen enter / DECSTBM reset / resize (output-scanning, like the existing mouse_scanner). NO window title (the harness, e.g. CC, owns it for busyness — OSC dropped). Resolve subnet/node/id once at attach (perch/registry read) and thread into the pump; subnet = the endpoint's home/primary ("local" if none). The literal floating rounded-rectangle corner box is DEFERRED to the future web-based GUI (not a grid-model rc — that lift is better spent on the GUI). (v0.16.0)
2026-07-17T03:24:38.0952835Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0952888Z 
2026-07-17T03:24:38.0953148Z ### REQ-JOIN-TWO-PHASE
2026-07-17T03:24:38.0957335Z - Title: `spt subnet join` is two-phase (meet-before-code) so the entered code is FRESH at the ceremony regardless of discovery time (ADR-0030). The meet selector is the PUBLIC `(subnet-name, TOTP-epoch)` (rendezvous_token = SHA256(domain ‖ name ‖ totp_step)); the secret TOTP-code is the SPAKE2 password ONLY, never a discovery input — so the code is collected AFTER a member is found. Extend the brain.pair_join event stream (brain.rs:1009): CLI PairMeetReq{subnet} → daemon meets (name, current-epoch) resolving the seed-holder's REAL stable pairing address → MetMember event → CLI prompts the code (cli.rs cmd_subnet_join :6236) → PairCodeSubmit{code} → daemon dials the held real-address on SPT_PAIR_ALPN + SPAKE2 → PairJoined/PairFail. Daemon holds the real-address between phases, bounded by a 5-MINUTE wait-for-code timeout; a wrong-code retry re-runs the CEREMONY ONLY against the held address (no re-search). The non-interactive `--code` path stays one-shot (no prompt; relies on REQ-NET-FAMILY-GATE fast discovery, fails loudly per REQ-JOIN-DIAGNOSTICS on staleness). Security unchanged — the meet is pre-trust/unauthenticated (SPT_PAIR_MEET_ALPN); auth stays in SPAKE2. (next milestone)
2026-07-17T03:24:38.0957772Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.0957805Z 
2026-07-17T03:24:38.0958051Z ### REQ-NET-FAMILY-GATE
2026-07-17T03:24:38.0961165Z - Title: spt-core binds only IP families that are actually REACHABLE (ADR-0030), so a half-broken family (e.g. IPv6 whose AAAA resolves but whose path is dead) never silently consumes connection/discovery time. At NetEndpoint::bind (endpoint.rs), probe each family's reachability ONCE and bind only the working ones: dual-stack when both healthy; IPv4-only when IPv6 is dead; IPv6-only when IPv4 is dead (drop the DEAD family — NOT a fixed prefer-IPv4; IPv6-only networks must keep working). Re-evaluated on daemon restart (once-at-bind, no live re-eval in v1). Explicit overrides SPT_DISABLE_IPV6 / SPT_DISABLE_IPV4 force a family off (escape hatch + determinism + testing, mirroring SPT_NTP_SERVER); a forced-off family is never bound regardless of the probe. Reusable beyond join — every spt connection benefits. (next milestone)
2026-07-17T03:24:38.0961495Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0961529Z 
2026-07-17T03:24:38.0961791Z ### REQ-JOIN-DIAGNOSTICS
2026-07-17T03:24:38.0965176Z - Title: `spt subnet join` never fails SILENTLY (ADR-0030; the field incident showed no output at all). (a) LIVE progress during the meet (replace the one-shot "Searching…" cli.rs:6268 with periodic elapsed/deadline) so silence ≠ hang; (b) DETAILED failure on meet-exhaustion — rendezvous candidates + families attempted (IPv4/IPv6) + relay-vs-direct + the last concrete error — surfaced BEFORE any code prompt (a dead subnet must not make the user fetch a code); connect_seed_holder (pairhost.rs:437) and dial_via_rendezvous (meet.rs:281) currently swallow per-attempt errors — thread the last error up with attempt context; (c) PROPAGATE the terminal event — brain.rs:1024 `_ => continue` must deliver a daemon NoSeedHolder/PairFail to the CLI as a printed error (this is WHY the user saw nothing); (d) `--verbose`/`SPT_LOG` discovery TRACE (per-probe derived id, discovery path mDNS/n0-DNS/relay, per-family timeouts), opt-in — no such knob exists today. (next milestone)
2026-07-17T03:24:38.0965730Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.0965762Z 
2026-07-17T03:24:38.0966036Z ### REQ-PRESENCE-LIVENESS-TRUTH
2026-07-17T03:24:38.0972041Z - Title: A node's gossiped per-endpoint registry Status reflects real liveness, so a remote viewer never paints a DEAD endpoint as ONLINE. ROOT (confirmed + gated vs CONTEXT.md): registryhost.rs:397-405 advertises a NOT-alive perch as Status::Dormant (the `else` of is_perch_alive), re-stamped every gossip round (never ages to Offline). Design intent GATED vs resting.rs + CONTEXT.md: active/dormant is the MULTI-INSTANCE routing differentiator (active = the bare-id routing target; dormant = a WARM non-target sibling — 'driving ling@laptop makes ling@desktop dormant', resting.rs:97; transitions active→dormant on AttentionShift/Detach). suspended = COLD (session closed, resumable-on-wake) while its NODE is UP. offline = NODE DOWN — NEVER self-gossiped (RestState has no Offline; a live node only ever gossips active/dormant/suspended), remote-inferred via epoch-lease eviction. So labeling a NOT-running perch Dormant is the DEFECT (dormant requires warm/running). PRIMARY FIX (registryhost `else`, not-bound-alive): live-but-UNBOUND (has a live broker session; is_perch_alive is bound-gated) → Active/Dormant (still warm); else (cold, no live session, but its node is up because this very daemon is gossiping) → SUSPENDED — NOT Dormant, NOT Offline (the node is UP; Offline is never self-gossiped). This alone removes the false-ONLINE. dormant keeps gossiping (routing/MRA needs it) but RENDERS as its online flavor (no distinct glyph; the dormant→suspended auto-suspend timer disambiguates recency). The DISPLAY of these states (incl Suspended=gray-filled) is REQ-SUBNET-DISPLAY-PARITY. Design: docs/design/subnet-presence-display.md §A. (next milestone)
2026-07-17T03:24:38.0972526Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0972560Z 
2026-07-17T03:24:38.0972846Z ### REQ-SUBNET-DISPLAY-PARITY
2026-07-17T03:24:38.0977915Z - Title: The `spt endpoint run` picker renders endpoint state IDENTICALLY for local and remote (subnet) rows — bound/unbound, controlled (+driver node), and harness-only are all visible across the subnet, not local-only. Today data.rs:293-294 reduces a remote row to plain green-filled/gray-hollow because those facts aren't propagated. (1) GOSSIP additive per-Instance fields: bound/unbound, controlled + driver-node, harness_only (Offline is never gossiped — node-down is remote-inferred). (2) Derive the full EpDisplay for subnet rows from the gossiped fields, same path as local (remove the remote-reduction). (3) PALETTE rework (fill = ACTIONABLE: filled=can act now (rc-control if online, WAKE if suspended-on-live-node) / hollow=cannot (no control seat / node gone)): green-filled=online+bound+free; blue-filled=online+controlled (desc shows `controlled by <node>`); RED-filled=online+UNBOUND (controlled-or-not; controlled-ness shown via available options not glyph) — replaces green-hollow Unbound + absorbs the dropped UnboundControlled; AMBER-HOLLOW=online+harness-only (no broker seat → can't rc) — was amber-FILLED; GRAY-FILLED=Suspended (cold, node up — wakeable) NEW; gray-hollow=Offline (node down) now REMOTE-ONLY. EpDisplay: drop UnboundControlled, Unbound→red-filled, HarnessOnly→amber-hollow, add Suspended(gray-filled). Picker maps Active|Dormant→online flavor, Suspended→gray-filled, Offline→gray-hollow. (next milestone)
2026-07-17T03:24:38.0978278Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0978306Z 
2026-07-17T03:24:38.0978577Z ### REQ-UPDATE-FETCH-CURRENT-UX
2026-07-17T03:24:38.0982209Z - Title: `spt update fetch` reports an already-staged / already-applied latest as an ACTIONABLE human outcome (exit 0), not a Debug-formatted error. ROOT: cmd_update_fetch (cli.rs) sets the rollback floor = staged_version, so when the published candidate == the already-staged version, verify_update_set_metadata returns Err(RejectReason::Rollback{current,candidate}) — printed as {reason:?} (Debug) at exit 1, reading as a FAILURE when the update is merely already downloaded and just needs `spt update apply` (this bit the operator: fetch kept 'failing', apply was the missing step). FIX: a PURE classifier (reason, applied, staged) -> {AlreadyStaged (latest downloaded, not yet installed) / AlreadyApplied (up to date) / GenuineError}; already-staged + already-applied print a friendly message and exit 0; genuine rejects use RejectReason's Display (release.rs, not Debug) + exit 1 — applied at ALL THREE fetch reject sites (metadata + artifact-verify + plan-verify). (v0.18.0)
2026-07-17T03:24:38.0982639Z - Required stages: impl, unit
2026-07-17T03:24:38.0982687Z 
2026-07-17T03:24:38.0982968Z ### REQ-UPDATE-FETCH-APPLY-FLAG
2026-07-17T03:24:38.0986136Z - Title: `spt update fetch --apply` is the one-shot get-to-latest: fetch, then INSTALL the staged update REGARDLESS of whether the fetch itself staged anything new — so the brittle `fetch && apply` chain (which broke when fetch no-oped / exited nonzero on an already-staged latest, skipping the chained apply) is unnecessary. Composes with REQ-UPDATE-FETCH-CURRENT-UX: the end state is 'installed latest', reached idempotently from new-staged -> apply / already-staged (applied<candidate) -> STILL apply / already-applied -> noop+exit0 / genuine error (bad signature, no artifact for platform, true downgrade, network) -> do NOT apply, propagate the error + nonzero. Reuses the existing cmd_update_apply core (its own verify + two-phase + auto-rollback own correctness; no duplicated swap/respawn). Additive clap flag (plain doc-comment, no internal codes); reference.md regenerated. (v0.18.0)
2026-07-17T03:24:38.0986554Z - Required stages: impl, unit
2026-07-17T03:24:38.0986583Z 
2026-07-17T03:24:38.0986845Z ### REQ-UPDATE-RUNNING-IMAGE-SURFACE
2026-07-17T03:24:38.0990876Z - Title: `spt` surfaces the RUNNING broker image version beside the on-disk version so an updated-looking node reveals broker-side dormancy. ROOT (F-025): `spt update apply` restarts the BRAIN only (ADR-0018 D3-3) — the BROKER process survives and keeps running its pre-apply compiled image, so every broker-side surface of a freshly-applied release (the F015B live-apply matcher, dispatch inject legs, etc.) is silently dormant until a full daemon bounce, with nothing in the CLI revealing the split. FIX: the running broker SELF-REPORTS its compiled image version over IPC (a new request KIND answered by the live broker process from its own compiled build constant) — HARD CONSTRAINT: the version comes FROM the running broker process, NEVER inferred from disk bytes, install manifest, or file timestamps, since the disk is exactly the half that is already ahead; a version-surface command (`spt version` and/or `spt daemon status`) prints the running-broker version beside the on-disk/product version and flags a mismatch. Keeps read-side truth independent of write-side claims (the field lesson from F015B). (F-025)
2026-07-17T03:24:38.0991210Z - Required stages: impl, unit, int
2026-07-17T03:24:38.0991238Z 
2026-07-17T03:24:38.0991515Z ### REQ-UPDATE-APPLY-RESTART-NOTICE
2026-07-17T03:24:38.0993985Z - Title: `spt update apply` prints a LOUD restart-required notice whenever the surviving broker will keep running the pre-apply image (which, until broker-restart choreography exists, is ALWAYS on a successful apply). Public wording, no internal CODE:RESULT markers (composes with REQ-ADAPTER-UPDATE-MESSAGE / the update-apply-confident-message rule) — name the user-visible CONSEQUENCE ('daemon-coordinated features run the previous version until the daemon restarts'), not the broker/brain internals. Composes with REQ-UPDATE-RUNNING-IMAGE-SURFACE (the notice tells the user what the version-surface will then show, and how to clear it). (F-025)
2026-07-17T03:24:38.0994362Z - Required stages: impl, unit
2026-07-17T03:24:38.0994396Z 
2026-07-17T03:24:38.0994677Z ### REQ-UPDATE-APPLY-ALREADY-APPLIED
2026-07-17T03:24:38.0997659Z - Title: `spt update apply` classifies an already-staged / already-applied state as a friendly exit-0 no-op instead of dying at the binary-aside rename with 'Access is denied (os error 5)'. ROOT (F-025): a second apply on an already-applied staged version reaches the two-phase binary-aside rename and fails os-error-5, reading as a hard failure when the machine is simply up to date. FIX: apply gains the same pure classifier `fetch` got in v0.18.0 (REQ-UPDATE-FETCH-CURRENT-UX) — already-applied → clear message + exit 0, and the flow MUST short-circuit BEFORE the binary-aside rename in that state; mirror the classifier at ALL apply reject/entry sites the way the fetch fix covered its three. Genuine errors (bad signature, wrong platform, true downgrade, network) still propagate nonzero. (F-025)
2026-07-17T03:24:38.0997963Z - Required stages: impl, unit
2026-07-17T03:24:38.0998040Z 
2026-07-17T03:24:38.0998321Z ### REQ-BROKER-ATTACH-JOURNAL-RESILIENT
2026-07-17T03:24:38.1001712Z - Title: A poisoned EffectJournal mutex or a sick NetHost runtime must NOT permanently brick all future attaches. Bug #16 (URGENT): a live spt-hosted endpoint (eel-a) attach fails with 'brain IPC read deadline elapsed' after a self-update brain-respawn — the broker survives the respawn and one journaled op (dispatch_net_stream_open journal.apply_once + loopback open_stream runtime.block_on nethost.rs:1060) enters a bad state, so every journaled attach silently kills its per-conn reply thread while non-journaled ops keep working. Fix: recover PoisonError via into_inner (effect.rs apply_once, replace the .expect panics) so one panic cannot brick all attaches; bound the loopback open_stream block_on (nethost.rs:1060) like the QUIC bounded_block_on so a sick runtime fails fast with an error frame not an opaque 10s deadline. Reinforces REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #16.
2026-07-17T03:24:38.1002137Z - Required stages: impl, unit
2026-07-17T03:24:38.1002175Z 
2026-07-17T03:24:38.1002443Z ### REQ-WAN-SEND-DELIVERY
2026-07-17T03:24:38.1005310Z - Title: Bug #9/#10: cross-node spt send reports SENT(WAN) but does not deliver, even on stable-IP pairs. Real root: spt send resolves the dial with id-only addr_for_node_hex (endpoint.rs:538) which forces a fresh iroh discovery round-trip every send, while the gossip pump uses cached direct addresses (dial_seeded/PeerAddrStore) so gossip stays green but send rides a marginal discovery path that cannot carry the fire-and-forget payload; the handshake completes so SENT(WAN) prints falsely. Fix: (1) route the WAN dial through the pump seeded-direct-address resolution (PeerAddrStore first, id-only fallback); (2) receiver writes its WanOutcome back so the sender confirms delivery under the QUIC deadline and only reports SENT on confirmed delivery, honest failure otherwise. Access-gate/perch/spool all verified correct (ruled out). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #9-10.
2026-07-17T03:24:38.1005622Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1005670Z 
2026-07-17T03:24:38.1005963Z ### REQ-RC-CROSS-NODE-ATTACH
2026-07-17T03:24:38.1008465Z - Title: Bug #4: spt rc to a remote endpoint fails with 'no live session' though endpoint list shows it Active — rc.rs:1063 resolves only the LOCAL broker session table and always dials loopback, never consulting the registry or dialing the owning node (the cross-node attach transport exists in the broker; only the client leg is missing). Fix: on a local resolve miss, resolve the owning node from the registry (reuse resolve_across_visible), net_dial that node, and run a remote session-resolve + serve_attach round-trip (mirror the wansend resolve-dial-round-trip pattern). Shares the resolve-owning-node primitive with REQ-WAN-SEND-DELIVERY. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #4.
2026-07-17T03:24:38.1008794Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1008891Z 
2026-07-17T03:24:38.1009262Z ### REQ-RC-WIN-VT-OUTPUT
2026-07-17T03:24:38.1013388Z - Title: Bug #12: `spt rc` to an endpoint renders ANSI escapes LITERALLY (raw ←[K / color codes) on a Win10 conhost console, garbling the viewport — while `endpoint run --attach` in the SAME env renders fine and Win11 Windows Terminal is unaffected. Root (code-grounded, doyle): rc.rs RawGuard::enable calls only crossterm enable_raw_mode (INPUT raw mode) and NEVER enables ENABLE_VIRTUAL_TERMINAL_PROCESSING on the OUTPUT handle; Win10 conhost defaults VT-output OFF so escapes print literally, whereas the picker/alt-screen setup on the endpoint-run path enters crossterm's VT-enabling console setup first (leaving VT-output on) — so it is the rc-attach CLIENT PATH specifically, and --attach-works-same-env confirms (not refutes) the VT-out theory. Fix: in the rc attach path (RawGuard), on cfg(windows) + interactive console (mirror the windows_mouse_wanted guard so piped stdin/stdout keeps clean bytes for the e2e byte tests), SetConsoleMode STD_OUTPUT_HANDLE |= ENABLE_VIRTUAL_TERMINAL_PROCESSING|ENABLE_PROCESSED_OUTPUT, capture the prior mode, restore on Drop. cfg(windows)-only, client-side, independent of #4/#6. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #12.
2026-07-17T03:24:38.1013794Z - Required stages: impl, unit
2026-07-17T03:24:38.1013832Z 
2026-07-17T03:24:38.1014100Z ### REQ-GOSSIP-CONTROLLED-ANY
2026-07-17T03:24:38.1016615Z - Title: Bug #3: a locally-controlled endpoint gossips controller_node = None so remote viewers show it free to control. Root: driven_by is stamped Some(node) only for a REMOTE WAN attach (attach.rs:337); a local controller is by=None by design (broker.rs:1750, KH 7.15 — a local-only controller must not latch driven_by). Fix: broker stamps a SEPARATE any-controller datum (true/Some(host) for a local OR remote controller) alongside stamp_driven_by, and advertise_local gossips Instance controller_node from it, leaving the remote-only driven_by untouched (do not trip REQ-HAZARD-DRIVEN-BY-SELFHEAL). node-refresh is NOT the fix (data is absent at source). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #3.
2026-07-17T03:24:38.1017014Z - Required stages: impl, unit
2026-07-17T03:24:38.1017057Z 
2026-07-17T03:24:38.1017328Z ### REQ-SUBNET-COUNT-ROUTABLE
2026-07-17T03:24:38.1019598Z - Title: Bug #2: a remote node endpoint count drifts (0/2, 1/3) because node_status_rows (cli.rs:5314) increments the per-node total unconditionally, counting non-routable Offline ghost rows; purge is not a registry eviction (it gossips a one-shot Offline row that is immortal on remote viewers — eviction is per whole-node only). Fix: routable-only denominator (total += status.routable()) keeping a separate raw count for the all-Offline liveness branch; plus per-row Offline-TTL eviction so purged endpoints stop accumulating on remote snapshots. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #2.
2026-07-17T03:24:38.1019912Z - Required stages: impl, unit
2026-07-17T03:24:38.1019960Z 
2026-07-17T03:24:38.1020232Z ### REQ-BROKER-SCREEN-GRID
2026-07-17T03:24:38.1023342Z - Title: Bugs #6 + #12 + #7/#8-artifacts: the broker is a raw-byte pump with no screen model — OutputLog replays the raw ring from seq 0 into a fresh terminal on attach, so an alt-screen TUI (Claude Code) corrupts scrollback (#6) and rc-to-a-pre-running-endpoint garbles (#12 — rc and endpoint run --attach are the SAME client fn, so it is replay content not a client-VT bug). Fix: a server-side VT/grid/screen model (tmux/mosh-style) that maintains authoritative screen + alt/main + cursor and synthesizes a CLEAN current-screen repaint on attach instead of replaying mid-stream ring bytes. Also eliminates residual-cell artifacts on animate/scroll/resize (#7/#8). Operator NON-NEGOTIABLE: accurate PTY representation with zero artifacts. (win32 vterm in the report means this server-side emulator, not ConPTY which is already the backend.) See docs/NEXT-MILESTONE-BUG-TRIAGE.md #6/#12.
2026-07-17T03:24:38.1023671Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1023767Z 
2026-07-17T03:24:38.1024123Z ### REQ-RC-IDMARKER-DISABLE
2026-07-17T03:24:38.1026014Z - Title: Bugs #14 + #7/#8 (marker half): feature-flag the top-right StatusRow endpoint-id marker OFF (rc.rs:198-307). It is a one-shot absolutely-positioned paint that scrolls off-screen and is not re-stickied (#14), and its DECSC/clear/SGR injection splices into the harness in-flight drawing causing residual artifacts (#7/#8). Ship disabled next release (operator: save the concept for a future web SPT GUI); revisit as a proper per-frame sticky overlay only once REQ-BROKER-SCREEN-GRID provides the screen model. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #14.
2026-07-17T03:24:38.1026353Z - Required stages: impl, unit
2026-07-17T03:24:38.1026387Z 
2026-07-17T03:24:38.1026661Z ### REQ-ENDPOINT-LIST-PALETTE
2026-07-17T03:24:38.1029561Z - Title: Bugs #11 + #15 (display): spt endpoint list renders status as plain text while the picker turns the same ResourceRow into the W5 colored EpDisplay palette. Fix: extract one shared ResourceRow-to-EpDisplay builder + make the picker display enums/helpers public, and have endpoint list render the same colored status squares (via helpfmt stdout_color, not ratatui Span). This also fixes #15 — a lone warm detached instance renders as its online flavor (Dormant maps to online) instead of leaking the bare word Dormant through the text-only list (no resting.rs/CONTEXT model change; operator ruling display-only). Couples REQ-PICKER-NODE-GROUPING (both edit subnet_rows — sequence the shared-builder extraction first). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #11/#15.
2026-07-17T03:24:38.1029867Z - Required stages: impl, unit
2026-07-17T03:24:38.1029900Z 
2026-07-17T03:24:38.1030172Z ### REQ-PICKER-NODE-GROUPING
2026-07-17T03:24:38.1032062Z - Title: Bug #13: the endpoint run Subnet tab shows a machine once PER shared subnet (subnet_rows data.rs:253 iterates per-subnet, groups by subnet:node, no cross-subnet dedup). Fix: dedup by (node, endpoint_id) across the subnet loop, collect the set of shared subnet names per endpoint, emit one group per MACHINE (group = node_display) with its shared subnets listed beneath the machine name; reconcile per-endpoint status across subnets (most-alive). Couples REQ-ENDPOINT-LIST-PALETTE (both edit subnet_rows). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #13.
2026-07-17T03:24:38.1032467Z - Required stages: impl, int
2026-07-17T03:24:38.1032506Z 
2026-07-17T03:24:38.1032787Z ### REQ-ENDPOINT-LIST-NODE-GROUPED
2026-07-17T03:24:38.1038044Z - Title: spt endpoint list is node-grouped over unique INSTANCES, not subnet-grouped over duplicated rows: one row per (id,node) instance — subnet duplication collapsed (ADR-0006 §1: subnet is never an identity axis), freshest-epoch wins a cross-subnet status disagreement (the resolve_among twin rule) — grouped under 'This node: <label>' (cyan; local roster is the status truth, advertised-status vocabulary, corrupt = suspended + corrupt annotation) then remote nodes alphabetical (node name orange 38;5;208, the legacy $LIVE orange), each node carrying a light-gray 'Shared subnets:' line (subnets among our memberships where that node gossips any visible row; per-instance subnet detail stays in --json/--detail), instance rows [id, endpoint_type, glyph, status] (endpoint_type threaded from Instance.endpoint_type through ResourceRow — additive, pre-field rows render '-'), per-node 'Total:' lines with NO grand total (the stderr ENDPOINTS:<n> line is REMOVED — it counted subnet rows, so the same instance in N subnets counted N times), SELF pin kept first with a '(self @ <node>)' marker (REQ-WHOAMI-1 alias; self also appears as a This-node row so the node total stays honest), remote nodes with zero visible instances skipped, --subnet narrows the union to that subnet's view, --json DTO structure UNCHANGED (committed surface; gains only an additive endpoint_type field). Grill-with-docs ruling 2026-07-02 (operator + doyle); sibling of REQ-PICKER-NODE-GROUPING (the picker half of the same dedup law).
2026-07-17T03:24:38.1038383Z - Required stages: impl, unit
2026-07-17T03:24:38.1038477Z 
2026-07-17T03:24:38.1038760Z ### REQ-ENDPOINT-LIST-REST-FILTER
2026-07-17T03:24:38.1041905Z - Title: spt endpoint list hides SUSPENDED instances by default; a new --show-all flag reveals them. Status-first row ordering with fixed precedence ONLINE > CONTROLLED > UNBOUND > SUSPENDED (when shown) > corrupt last, alphabetical by id within each band. Two invariants: (1) CORRUPT rows ALWAYS render regardless of filters — corrupt is a record condition demanding operator action (purge/re-mint), not resting clutter; hiding it would re-create counter-39 bug #3 (cross-ref REQ-HAZARD-CORRUPT-PERCH-COHERENCE, CONTEXT.md instance-state _Also avoid_); (2) the per-node Total line DISCLOSES the filter — 'Total: N (+M suspended hidden)' — so nothing silently vanishes. Registry-Offline rows stay excluded by projection law (resource_projection skips unroutable; unchanged). Grill-with-docs ruling 2026-07-02 (operator + doyle).
2026-07-17T03:24:38.1042286Z - Required stages: impl, unit
2026-07-17T03:24:38.1042329Z 
2026-07-17T03:24:38.1042608Z ### REQ-ADAPTER-UPDATE-INPLACE
2026-07-17T03:24:38.1044515Z - Title: Bug #18: spt adapter update fails at re-register with os error 2 because it derives the install dir from the update repo NAME (_github/<safe>) instead of updating in place at the adapter record source_dir; when the adapter repo is intentionally renamed across releases (spt-claude-code to claude-spt, supported), the derived dir is fresh/empty and re-register reads a missing manifest. Fix: adapter update installs and re-registers in place at the registered source_dir and tolerates a changed update repo/URL across a rename. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #18.
2026-07-17T03:24:38.1044801Z - Required stages: impl, unit
2026-07-17T03:24:38.1044834Z 
2026-07-17T03:24:38.1045120Z ### REQ-DIGEST-PROFILE-ENV
2026-07-17T03:24:38.1048028Z - Title: Bug #17: spt endpoint digest returns NO_DIGEST for a ccs-profile endpoint (claude-spt:ccs) though [digest] is wired and the transcript exists — under .ccs (CLAUDE_CONFIG_DIR relocation) not .claude. The on-demand digest runs the extractor in the daemon context WITHOUT the endpoint profile transcript-location env, so the env-aware resolver cannot find the relocated transcript. Fix: propagate/persist the endpoint profile transcript-location env (e.g. the ccs CLAUDE_CONFIG_DIR) to the on-demand digest extractor so a profile-relocated transcript resolves; confirm the exact extractor verdict via spt adapter digest-proof. Ownership spt-core (digest env/profile propagation), possibly with a claude-spt extractor-resolver assist. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #17.
2026-07-17T03:24:38.1048447Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1048475Z 
2026-07-17T03:24:38.1048752Z ### REQ-DIGEST-FETCHER-STRATEGY
2026-07-17T03:24:38.1053426Z - Title: Bug #17 (W6b, closes eel-a end-to-end): [digest] gains a `fetcher` strategy mirroring [history]'s locate/normalize split (CONTEXT §history: [digest] mirrors history's two strategies — locate ownership). ROOT: the pre-W6b [digest] had only the locate_normalize analog (spt-core resolves ONE `source` template + pre-reads the file), which CANNOT express a PARTITIONED transcript layout — CC's projects/<munge(cwd)>/<session_id>.jsonl or a date-globbed rollout tree — the exact case CONTEXT already assigns to the adapter. spt-core (correctly) provides NO {project}/slug key (harness-specific cwd munging = the charter violation FIX-A was rejected for). Fix: strategy = fetcher makes the ADAPTER's extractor locate + read + emit normalized records; spt-core runs it bounded (no locate, no pre-read, no stdin) and consumes stdout, feeding only the harness-NEUTRAL inputs it owns — {session_id}, the perch-bound {cwd} (info.json.cwd), and the captured [env] direction=read vars (W6/REQ-DIGEST-PROFILE-ENV) — so the extractor globs the unique {session_id} under {read-var-root}/projects/ with no slug. Keeps locate_normalize (default, back-compat) for a trivial single-file harness. Distinct capability from REQ-DIGEST-PROFILE-ENV (which supplies the root env). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #17.
2026-07-17T03:24:38.1058280Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1058649Z 
2026-07-17T03:24:38.1059122Z ### REQ-ADAPTER-ADD-SURFACE-ERRORS
2026-07-17T03:24:38.1061396Z - Title: Bug #1: adapter add runs the install-as-first-update via conduct (cli.rs:6963) which on a non-zero exit prints only the exit code and DISCARDS the subprocess stdout/stderr, so the real error is invisible (the failure itself does propagate). Fix: include out.stderr/stdout in the ADAPTER_INSTALL_FAIL message (mirror run_update_post_step). Operator ruling: ALSO run the [update.post] composite step at install-time (today it runs only on explicit adapter update), so an install both surfaces detail and completes the delegated post-step. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #1.
2026-07-17T03:24:38.1063616Z - Required stages: impl, unit
2026-07-17T03:24:38.1064000Z 
2026-07-17T03:24:38.1064315Z ### REQ-ENDPOINT-LIST-NODE-IDENT
2026-07-17T03:24:38.1066402Z - Title: Bug #5: spt endpoint list local section header is the hardcoded literal LOCAL (this node) (render_local_section cli.rs:4359). Change to 'This node: <node-id>' using the existing node-ident idiom (os_hostname + nodeid public-key prefix, cli.rs:5531 — factor a node_ident_display helper); compute in the impure print_local_section, pass into the pure renderer. Update the two test assertions (cli.rs:10711/10716). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #5.
2026-07-17T03:24:38.1068207Z - Required stages: impl, unit
2026-07-17T03:24:38.1068545Z 
2026-07-17T03:24:38.1068831Z ### REQ-HAZARD-CONTROL-STAMP-LIFETIME
2026-07-17T03:24:38.1072337Z - Title: #2: a control/viewer stamp never outlives its session — every teardown path clears what attach stamped. The broker exit-waiter (broker.rs ~:1844) sends the exit frame + sessions.remove(&id) but does NOT clear the perch's controller/viewer stamps; clear_controller()->stamp_driven_by() (clears driven_by+controlled) runs ONLY on controller-detach/evict/displace. /exit kills the CHILD not the controller conn, so the OutputLog drops with controlled:true, viewer_count, (and driven_by for a remote controller) latched in info.json forever — and hfenduleam keeps gossiping controller_node=self cross-node. Fix: on session reap, clear the perch's controller/viewer stamps (set_driven_by(None)+set_controlled(false)+set_viewer_count(0) via the known endpoint id) — broker stays the single writer. KNOWN-HAZARDS invariant. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #2.
2026-07-17T03:24:38.1075547Z - Required stages: doc, impl, int
2026-07-17T03:24:38.1075891Z 
2026-07-17T03:24:38.1076166Z ### REQ-PICKER-CONTROLLED-LOCAL
2026-07-17T03:24:38.1079557Z - Title: #3 local half: a LOCALLY-controlled endpoint renders CONTROLLED in its own node's picker. display_status() (crates/spt/src/picker/model.rs:415) derives Controlled ONLY from driven_by.is_some(), but driven_by is REMOTE-only by design (KH 7.15) — a locally-controlled endpoint has driven_by=None + controlled=true, and local_rows (data.rs:220) never threads controlled into EndpointRow, so a locally-RC'd endpoint shows plain ONLINE in its own picker (remote rows are fine — gossip stamps controller_node=self, REQ-GOSSIP-CONTROLLED-ANY; the asymmetry is the bug). Fix: EndpointRow gains controlled:bool (local: rec.controlled; remote: controller_node.is_some()); display_status -> Controlled when driven_by.is_some()||controlled; desc pane says 'controlled locally' when the driver is unnamed. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #3.
2026-07-17T03:24:38.1082601Z - Required stages: impl, unit
2026-07-17T03:24:38.1082939Z 
2026-07-17T03:24:38.1083221Z ### REQ-PICKER-PROJECT-HISTORY-TRUTH
2026-07-17T03:24:38.1086966Z - Title: #1: picker project history is derived from sessions.log cwds (newest->oldest, deduped by project_id_for_dir) UNION context-store branches, EXCLUDING owlery-internal paths (any cwd under spt_home()/owlery) everywhere a project is displayed or inferred. Fixes three stacked defects (crates/spt/src/picker/data.rs): (1a) project_history_for (data.rs:372) reads ONLY context-store p-* branches, which are empty on this box -> history []; (1b) the fallback origin project (data.rs:207) is derived from info.json.cwd = latest-boot-cwd (rewritten every rebind), not origin; (1c) psyche-host sessions bind owlery-internal cwds that pollute history. Full DIRS stay available in the model (feature #5 needs them). PROJECT REPRESENTATION RULING (operator 2026-07-03): project IDs ONLY, EVERYWHERE incl local display; on ID collision disambiguate minimally via a PURE disambiguate_project_ids(entries)->display-names fn (append one-level-up parent folder and/or root drive letter, e.g. 'spt-core (projects)' vs 'spt-core (D:)'). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #1.
2026-07-17T03:24:38.1091189Z - Required stages: impl, unit
2026-07-17T03:24:38.1091522Z 
2026-07-17T03:24:38.1091803Z ### REQ-STORE-CONTEXT-BRANCH-FILL
2026-07-17T03:24:38.1094091Z - Title: #1 SI-1 (RCA, operator-promoted 2026-07-03): the context store (tracked/.seed.git) holds ZERO p-* branches on a box with months of live-agent use, while kitsubito/enlyzeam stores carry them. Context commits never land -> picker history has no store source (REQ-PICKER-PROJECT-HISTORY-TRUTH's fallback ships regardless, but the store must ALSO fill). RCA the contextstore write->branch-commit path with evidence (commune-ingest/context-commit regression vs store re-init), contrast the healthy stores, land whatever fix the RCA names. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #1 SI-1.
2026-07-17T03:24:38.1096333Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1096700Z 
2026-07-17T03:24:38.1096987Z ### REQ-GOSSIP-ADAPTER-PROJECTS
2026-07-17T03:24:38.1100398Z - Title: #4: remote endpoint details (harness + project history) are gossiped, not faked. Today from_resource_row (crates/spt/src/picker/model.rs:340) hardcodes project_history=Vec::new() for every remote row and passes adapter_profile=row.resources (the blurb masquerading as the harness), and Instance/ResourceRow (crates/spt-net/src/net/registry.rs:457) carry no adapter field and no project list. Fix: additive gossip fields N-1-safe exactly like endpoint_type — Instance.adapter (composite <adapter>[:profile]) + Instance.recent_projects (bounded, newest-first, project IDs only) -> thread to ResourceRow -> from_resource_row stops faking. Pre-field remote rows render '-'. Project IDs only + REQ-PICKER-PROJECT-HISTORY-TRUTH's disambiguation. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #4.
2026-07-17T03:24:38.1103435Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1103788Z 
2026-07-17T03:24:38.1104064Z ### REQ-ENDPOINT-LIST-PROJECT-COL
2026-07-17T03:24:38.1106742Z - Title: #8: spt endpoint list gains a second column <project>/ (the endpoint's LATEST project) -> 4 columns total: id / <project>/ / type / status. Local rows: head of REQ-PICKER-PROJECT-HISTORY-TRUTH (sessions.log-derived, owlery-excluded). Remote rows: head of REQ-GOSSIP-ADAPTER-PROJECTS recent_projects. Project IDs only + #4 disambiguation; '-' when unknown (pre-field remote rows). Extends the v0.21.0 node-grouped renderer (format_instance_rows — additive column, alignment char-width-safe). --json: additive project field on the row DTO (skip-if-none, N-1 safe). Depends on #1 + #4. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #8.
2026-07-17T03:24:38.1109289Z - Required stages: impl, unit
2026-07-17T03:24:38.1109624Z 
2026-07-17T03:24:38.1109904Z ### REQ-API-ENDPOINT-INFO
2026-07-17T03:24:38.1113854Z - Title: #7: spt api endpoint-info [<id>] (JSON) lets an endpoint learn its ATTACHED (controlling) node — claude-spt surfaces local + attached node names on UserPromptSubmit so the agent knows whether getting a file to the user needs extra steps (user RC'd in from another machine). spt api * is the harness-contract agent-facing surface (JSON-first, rides perch identity/auth so the bare no-<id> form self-resolves like whoami). Payload (committed DTO, additive-forever): { id, endpoint_type, adapter, local_node:{label,key}, attached_node:{label,key}|null, controlled:bool, project:<current project id>, cwd, subnets:[...] } — attached_node from controller stamps (driven_by remote / self-node when controlled with no remote driver), null when uncontrolled. HARD dependency on #2 + #3 (stamps must be honest first). Adapter-side consumable -> perri release-ping on publish. Naming: chose 'spt api endpoint-info' over alt 'spt endpoint get-info' — api is the agent surface (doc rationale). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #7.
2026-07-17T03:24:38.1117811Z - Required stages: impl, unit
2026-07-17T03:24:38.1118169Z 
2026-07-17T03:24:38.1118455Z ### REQ-PICKER-START-PROJECT-CHOICE
2026-07-17T03:24:38.1121181Z - Title: #5: after 'Start now' in the endpoint picker, swap the bottom Options panel to a 'Choose project' list: (1) the endpoint's most recent project dir, (2) 'Here: <dir>' — the spt endpoint run cwd (only if different), (3) all other project-history dirs newest->oldest. Fire the step ONLY when (A) the run cwd mismatches a singular history entry, or (B) history has >1 entry; otherwise start immediately (today's behavior). Depends on REQ-PICKER-PROJECT-HISTORY-TRUTH (needs full DIRS from sessions.log, owlery-internal exclusion applies). Start-now is local-only (no gossip). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #5.
2026-07-17T03:24:38.1123589Z - Required stages: impl, unit
2026-07-17T03:24:38.1123918Z 
2026-07-17T03:24:38.1124209Z ### REQ-PICKER-RESUME-CONTEXT-PANEL
2026-07-17T03:24:38.1126034Z - Title: #6: the 'Resume from history' view keeps the endpoint's 'Confirm selection' top panel and swaps ONLY the bottom panel to 'Resume from a prior session' — the user stays contextually informed about what they're picking (today the resume view replaces the whole screen). crates/spt/src/picker/view.rs (resume screen) + model screen state. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #6.
2026-07-17T03:24:38.1127676Z - Required stages: impl, unit
2026-07-17T03:24:38.1128014Z 
2026-07-17T03:24:38.1128295Z ### REQ-MSG-SELF-DETECT-ANCESTRY
2026-07-17T03:24:38.1132833Z - Title: #9 (F026, operator field bug): a perch-owned `spt send` from an endpoint's OWN session must self-identify, not mis-stamp `cli@<node>` (whose replies bounce NO_PERCH). ROOT: roster::detect_self_id (roster.rs) was ENV-ONLY — OWL_SESSION_ID matched to info.session_id, else SPT_AGENT_ID — but an agent-session Bash child often carries NEITHER (the env export is spawn-path-dependent), so a perch-owned sender was classified bare-CLI and REQ-MSG-CLI-ORIGIN stamped it cli@<node> (the stamp works as designed on a wrong premise; that REQ's evidence stays intact). FIX: detect_self_id gains leg (c) PID-ANCESTRY fallback AFTER the env legs — walk THIS process's ancestry, match a live non-corrupt roster perch's recorded harness pid (info.json.pid Numeric, alive-gated via is_process_alive, corrupt/BUSY skipped), first match = self. from-LABEL / routing default ONLY, NOT authentication — authenticate() is untouched (pid-ancestry-for-AUTH stays parked per F-024 with its Windows pid-spoof caveats; a display/routing stamp has no such bar). Best-effort: a broken ancestry walk degrades to None → cli-stamp, never errors the send.
2026-07-17T03:24:38.1136989Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1137332Z 
2026-07-17T03:24:38.1137687Z ### REQ-CLI-BROKEN-PIPE-TOLERANT
2026-07-17T03:24:38.1139905Z - Title: #10 (F026 micro): `spt <anything> | <pager/Select-First-N>` must not PANIC when stdout closes early. A closed downstream reader mid-print panics with 'failed printing to stdout: The pipe is being closed. (os error 232)' (live repro: `spt daemon status | Select -First N`). Fix: tolerate BrokenPipe process-wide — a write to a closed stdout exits 0 (SIGPIPE-equivalent: a consumer that stops reading is a normal end, not a crash), without leaking a Rust panic + backtrace to the user.
2026-07-17T03:24:38.1141837Z - Required stages: impl, unit
2026-07-17T03:24:38.1142171Z 
2026-07-17T03:24:38.1142447Z ### REQ-XTASK-SPT-BIN-TARGET-DIR
2026-07-17T03:24:38.1145535Z - Title: #13 (F026 micro, tooling): xtask `spt_bin()` (crates/xtask/src/main.rs) BUILDS `spt` via cargo (which honors CARGO_TARGET_DIR) but returns a HARDCODED `<root>/target/debug/spt` path — so under a redirected target dir (CI / isolated-gate rigs that set CARGO_TARGET_DIR to a throwaway) the binary lands in `$CARGO_TARGET_DIR/debug` while xtask looks in `<root>/target/debug` -> NotFound -> `xtask check` (docs-drift gate) spuriously fails. Workaround was running `xtask check` with CARGO_TARGET_DIR unset. FIX: a pure `target_debug_dir(root, CARGO_TARGET_DIR)` seam mirroring cargo's resolution — absolute override as-is, relative resolved against `root` (the dir cargo is invoked in), default `<root>/target` — join `debug`; `spt_bin` returns from it. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md.
2026-07-17T03:24:38.1148454Z - Required stages: impl, unit
2026-07-17T03:24:38.1148796Z 
2026-07-17T03:24:38.1149172Z ### REQ-HAZARD-CONTROL-STAMP-CONVERGENCE
2026-07-17T03:24:38.1154745Z - Title: Control/viewer stamps must CONVERGE to broker session-table truth for every session-backed endpoint, not merely edge-trigger — the UPWARD companion to the DOWNWARD edge-clear REQ-HAZARD-CONTROL-STAMP-LIFETIME (7.27); same 'stamps == broker truth' family. ROOT (F-026 stamp-gap, hall-b/ball-b): a picker-created endpoint's broker spawn become_controller->stamp_driven_by->set_controlled(true) fires BEFORE the adapter binds its perch (a fresh endpoint has no perch until claude boots + binds), so mutate_info returns NotFound and the edge stamp is SWALLOWED (let _); the adapter's bind then writes InfoJson::new with controlled:false DEFAULT and no later edge re-stamps -> the endpoint reads uncontrolled FOREVER while driven (the #3 display fix is correct but datum-starved on this creation path). FIX: the broker (SINGLE WRITER) re-asserts each live session's control/viewer stamps to session-table truth, DIVERGENCE-GATED (read info; compare driven_by/controlled/viewer_count; write ONLY on diff — no per-poll fsync storm), on the KIND_SESSIONS handler (piggyback: the daemon reconcile + picker poll it, so a fresh perch converges within one reconcile-poll window after bind = the BOUNDED window, no new timer). Event-on-input rejected (an idle controlled session like hall-b never converges). Writes run OFF the log lock (snapshot truth under the lock, converge off it) per the lock-across-effect discipline (KH 7.12/5.16).
2026-07-17T03:24:38.1160109Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1160468Z 
2026-07-17T03:24:38.1160758Z ### REQ-PICKER-PROJECT-DISPLAY-NAME
2026-07-17T03:24:38.1164133Z - Title: A1 (F028, operator #1/#4/#6-display): `github-com-*` 'ghost' project entries are NOT phantoms — project_id_for_dir (spt-store/src/project.rs:64) derives ids from the git remote slug BY DESIGN (REQ-STORE-1 cross-machine sync): `github.com/SaberMage/spt-core` -> `github-com-sabermage-spt-core`. The ref is truthful; the BUG is presentation — the raw slug renders as the DISPLAY NAME everywhere (confirm-panel history view.rs:415-419, choose-project labels model.rs:314-337, resume-row titles, endpoint-list project column via latest_project_ref data.rs:417), which no operator recognizes as 'spt-core'. FIX: keep the slug as the KEY, render a friendly display name — the repo tail (spt-core) reusing the disambiguate_project_ids (model.rs:346) suffix mechanism for collisions. One shared display-name seam across all four surfaces. See triage A1.
2026-07-17T03:24:38.1167197Z - Required stages: impl, unit
2026-07-17T03:24:38.1167522Z 
2026-07-17T03:24:38.1167807Z ### REQ-PICKER-CONTROL-LINE-STATUS-GATE
2026-07-17T03:24:38.1170083Z - Title: A2 (F028, operator #2): the picker confirm-panel 'controlled locally' line renders for OFFLINE endpoints. view.rs:425-436 builds control_line from ep.controlled with NO status gate; an offline endpoint with a stale controlled stamp shows 'controlled locally' (operator screenshot: hall-a offline + controlled locally). RENDER HALF (this REQ): control_line MUST be empty when status != Online. The upstream STICKY-stamp half (stamp survives client SIGKILL >=5min) is B3/REQ-PRESENCE-CONTROL-REAP-ON-EXIT. FIX: gate the render. See triage A2(a).
2026-07-17T03:24:38.1172268Z - Required stages: impl, unit
2026-07-17T03:24:38.1172602Z 
2026-07-17T03:24:38.1172883Z ### REQ-PICKER-OFFLINE-NO-VIEW
2026-07-17T03:24:38.1174537Z - Title: A3 (F028, operator #3): 'View now (read-only)' is offered for OFFLINE endpoints. model.rs:1030 offline branch of confirm_options is vec![Start, View] — View is meaningless with no live PTY. FIX: offline set = [Start] (+ the existing Resume/ChangeAdapter/Instantiate/Fork/Shortcut tail). Update the view.rs options tests. See triage A3.
2026-07-17T03:24:38.1176032Z - Required stages: impl, unit
2026-07-17T03:24:38.1176371Z 
2026-07-17T03:24:38.1176646Z ### REQ-PICKER-CHOOSE-DEDUP-ALL
2026-07-17T03:24:38.1178788Z - Title: A4 (F028, operator #5): choose-project duplicate rows. model.rs:314-337 build_project_choices dedups the `Here: <run_cwd>` row only against the HEAD ref's dir (line 324) — an OLDER history ref with the SAME dir still renders, giving `Here: C:\...\projects` + `projects` as two rows for one project (operator screenshot). FIX: dedupe `Here` against ALL history dirs, and skip rest-rows whose dir == run_cwd when Here is present. Extend the model.rs:1847 choose-project test. See triage A4.
2026-07-17T03:24:38.1180758Z - Required stages: impl, unit
2026-07-17T03:24:38.1181087Z 
2026-07-17T03:24:38.1181364Z ### REQ-RESUME-ROW-PER-PROJECT
2026-07-17T03:24:38.1183258Z - Title: A5 (F028, operator #6): resume-from-history labels EVERY session with the endpoint's newest project. data.rs:480-496 resume_rows_for clones project_history.first() onto every ResumeRow (line 481/488), so all sessions read as the head project (the ghost). The per-row e.cwd is already carried for launch-into-dir. FIX: derive per-row project_id_for_dir(e.cwd) (owlery-excluded -> fall back to trigger token), rendered through A1's display-name path. See triage A5.
2026-07-17T03:24:38.1185092Z - Required stages: impl, unit
2026-07-17T03:24:38.1185419Z 
2026-07-17T03:24:38.1185690Z ### REQ-RUN-NO-DUP-SESSION
2026-07-17T03:24:38.1189319Z - Title: B1 (F028, hall-b diagnosis, verified 0.22.0): `endpoint run --id X --create` on an endpoint with a LIVE session mints a silent DUPLICATE session — and attach output can CROSS sessions (second create for diag-hallc minted a new session while the old ran; the new run's attach viewport rendered the OLD session's screen — claude resume-picker UI of pid 84512 while new claude 356020 had no -r). ROOT CLASS of the 0.21.0 attach-stall (zero events in FIRST_EVENT_GRACE rc.rs:1402 = attach bound to dead/wrong same-id slot); also the triplicate `launch --id ball-b` on ENLYZEAM. FIX: (i) run-on-live-session must REFUSE or REATTACH, never silently duplicate; (ii) RCA the attach/output routing that let frames cross same-id sessions (broker session-slot keying, dispatch_adapter vs serve_attach resolution). Int: two sessions one endpoint id -> each attach sees only its own frames. See triage B1.
2026-07-17T03:24:38.1192478Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1192835Z 
2026-07-17T03:24:38.1193124Z ### REQ-RESUME-HARNESS-SESSION-ID
2026-07-17T03:24:38.1196504Z - Title: B2 (F028, hall-b diagnosis, verified 0.22.0): respawn/`--resume` feeds the SPT session id to `claude -r`. After the 02:05 daemon bounce respawn built `claude.exe -r 70b5bfa40901b7d4` — an spt session id in claude's OWN session-id namespace -> claude hangs forever at a 'No sessions match' resume-picker while the endpoint reads online. Hits after EVERY daemon bounce + every picker Resume. The HARNESS session id (claude UUID, stamped in sessions.log/info.json by the hooks) is what {session_id} must mean in the adapter's [session.resume] command; the spt sid must not leak. FIX: substitute the HARNESS session id in the resume template (spt-core substitution-key semantics + LIKELY claude-spt manifest coordination — FLAG perri BEFORE touching the manifest, adapter-boundary rule). Int: resume template receives the ledger UUID, not the spt sid. See triage B2.
2026-07-17T03:24:38.1199707Z - Required stages: impl, unit
2026-07-17T03:24:38.1200065Z 
2026-07-17T03:24:38.1200412Z ### REQ-PRESENCE-CONTROL-REAP-ON-EXIT
2026-07-17T03:24:38.1204126Z - Title: B3 (F028, hall-b diagnosis + deferred #11 seed; BROADENED perri F-b CONFIRMED): dead-pid ONLINE decay window + sticky CONTROLLED stamp. Repro: /exit -> all endpoint processes dead -> `endpoint list` stays ■ ONLINE for a decay window before OFFLINE. Sticky CONTROLLED: perri confirmed controlled=true + attached_node SET while alive=false/OFFLINE, persisting >20min AND ACROSS A DAEMON RESTART (hall-b) — worse than the SIGKILL>=5min original (CAVEAT still: may reflect claude's --remote-control channel not the PTY attach — DISAMBIGUATE first). This is the deferred #11; RCA belongs to this wave. FIX: reap must clear presence AND control stamps promptly across FOUR paths — (i) clean exit, (ii) serve conn-drop, (iii) session-died-without-exit (crash/bounce), (iv) a BOOT-TIME sweep so a restarted daemon does NOT resurrect control stamps for endpoints it can see are dead. Int tests per edge. Closes A2(b). See triage B3 (broadened).
2026-07-17T03:24:38.1207522Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1207900Z 
2026-07-17T03:24:38.1208195Z ### REQ-RESUME-REAP-PRIOR-HARNESS
2026-07-17T03:24:38.1209943Z - Title: B4 (F028, hall-b diagnosis, verified 0.22.0): `--resume` respawns a SECOND harness onto the SAME session without reaping the first. Observed live: resume of b4421cf9 spawned pid 34432 while gen1 (250376) kept running — two claude.exe stacks, one session id. FIX: resume must reap/refuse when the session already has a live harness. See triage B4.
2026-07-17T03:24:38.1211439Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1211790Z 
2026-07-17T03:24:38.1212052Z ### REQ-CRC-SWAP-OLD-DISPLACE
2026-07-17T03:24:38.1215653Z - Title: C1 (F028, infra; memory crc-swap-old-litter-brick, RCA'd ENLYZEAM + confirmed systemic): crc_swap `.old`-litter bricks every subsequent adapter update. apply_crc_swap Phase-3 `let _ = remove_file(.old)` (spt-daemon/src/crc_swap.rs:129-133) silently fails whenever ANY pre-update process still image-maps the old binary (NORMAL on a live box — endpoint launch children survive updates). The NEXT update's first commit-op rename(exe->exe.old) = MoveFileExW(REPLACE_EXISTING) must delete the mapped .old -> win32 err 5 -> whole apply fails + rolls back FOREVER, context-free. FIX: (i) DISPLACE not replace — when <target>.old exists, rename it aside to a unique suffix (rename succeeds on mapped files; spt's own updater already does spt.exe.old-<counter>); GC stale .old.* opportunistically. (ii) Wrap swap io errors with op + path (`rename claude-spt.exe -> claude-spt.exe.old: …`). Unit seam exists (crc_swap tests). See triage C1.
2026-07-17T03:24:38.1219065Z - Required stages: impl, unit
2026-07-17T03:24:38.1219404Z 
2026-07-17T03:24:38.1219692Z ### REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION
2026-07-17T03:24:38.1223304Z - Title: C2 (F028, infra; ROOT-CAUSED + severity-upgraded doyle RCA 2026-07-03): cross-endpoint perch contamination — a foreign psyche's SessionStart hook REBINDS a victim perch's IDENTITY, not merely its ledger. Evidence: hall-a's info.json.session_id IS f015b-probe-psyche's session (359d7bd7) + hall-a's ledger holds the foreign psyche session; same class as hall-b's dead-pid stamp (141556). This REQ = the OBSERVABLE (foreign session_id in a perch's ledger/info.json + resume offering foreign sessions) and its belt-braces: (iii) filter owlery-cwd rows OUT of resume_rows; (iv) one-time repair for already-contaminated perches (hall-a on HFENDULEAM) or self-heal on next legitimate session-start. The ROOT (identity pinned at spawn + honest bind + nested self-resolve) is REQ-BIND-HONEST-SELF-STAMP — C2 is UPSTREAM of B3 (presence/CONTROLLED read the very stamps this corrupts). See triage C2.
2026-07-17T03:24:38.1226538Z - Required stages: impl, unit
2026-07-17T03:24:38.1226862Z 
2026-07-17T03:24:38.1227140Z ### REQ-BIND-HONEST-SELF-STAMP
2026-07-17T03:24:38.1232488Z - Title: C2-ROOT (F028, doyle RCA 2026-07-03): the identity-attribution ROOT behind REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION — three composing defects let a psyche-hosted SessionStart hook stamp a FOREIGN perch: (1) roster::detect_self_id leg (a) scans the owlery ONE level (roster.rs:107 read_dir(owlery)) so a NESTED psyche perch owlery/<parent>/nested/<id>-psyche can never self-resolve; (2) [session.psyche_init] (claude-spt manifest ~L347) spawns the psyche with NO env_remove + no pinned child identity, so whatever OWL_SESSION_ID/SPT_AGENT_ID reaches the child resolves to a foreign top-level perch; (3) the hook then writes info.json (session_id/pid rebind) + sessions.log on the mis-resolved victim. FIX (spt-core half): (i) identity PINNED at spawn — ManifestRuntime role spawns inject the child's OWN SPT_AGENT_ID=<child perch id> + OWL_SESSION_ID=<child session>, AND detect_self_id enumerates NESTED perches (fix the one-level owlery scan); (ii) BIND HONESTY — a session-start stamp may only write a perch whose resolved id AFFIRMATIVELY matches; never a fallback pick; refuse + loud-skip when unresolved (kin REQ-MSG-CLI-ORIGIN honest-default + #9 ancestry). ADAPTER half = PERRI touchpoint (psyche_init env scrubbing / relies on runtime pinning; hook loses silent fallback-perch behavior) — FLAG doyle BEFORE any manifest move (adapter glue-model rule). See triage C2 fix (i)+(ii).
2026-07-17T03:24:38.1237600Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1237955Z 
2026-07-17T03:24:38.1238239Z ### REQ-PEER-PUMP-CHURN-STALL
2026-07-17T03:24:38.1241491Z - Title: B5 (F028, perri F-a; DEFECT daemon, OBSERVED-ONCE, HIGH): the peer pump STALLS under rapid rc attach/EOF-detach/--take churn. Fresh 0.22.0 daemon ~10min after restart, during rapid rc cycling: `peer pump: STALLED (last tick 122s)`; while stalled `spt rc --view` -> `RC_FAIL: attach request: brain IPC read deadline elapsed` (repeatable) and controlled-clear stopped propagating. Daemon restart recovered + endpoints auto-revived. Prior class: REQ-HAZARD-PUMP-IPC-DEADLINE (reader-thread+channel carrier), REQ-broker-QUIC-deadline (bounded_block_on) — something in the rc-churn path can still wedge the pump tick. perri holds exact timestamps + a repro candidate (rapid attach/detach/take against one endpoint) — REQUEST before RCA. See triage B5.
2026-07-17T03:24:38.1244415Z - Required stages: 
2026-07-17T03:24:38.1244734Z 
2026-07-17T03:24:38.1245021Z ### REQ-TRANSLATE-BINARY-LIVENESS-DECAY
2026-07-17T03:24:38.1248288Z - Title: SUPERSEDED by REQ-TRANSLATE-COMMIT-MISS-TOLERANCE (F029 C-1). B6 (F028, perri F-e) was ROOT-PINNED as the commit-deadline-miss fault: at a checkpoint clear boundary the clear-only inject's {commit} was never observed within INJECT_COMMIT_DEADLINE, so the inject worker FAULTED + TERMINATED a HEALTHY translate binary and (by ADR-0022) never respawned → every subsequent force-native reported delivered=false ('no live translation binary'). NOT a dormancy/liveness-registration decay (that hypothesis is dead) — deterministic at every checkpoint-armed boundary. The fix (miss != fault + N=3 strike budget + bounded respawn + perch-visible fault stamp) lives under REQ-TRANSLATE-COMMIT-MISS-TOLERANCE + REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH. See triage addendum C-1.
2026-07-17T03:24:38.1251282Z - Required stages: 
2026-07-17T03:24:38.1251587Z 
2026-07-17T03:24:38.1251949Z ### REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN
2026-07-17T03:24:38.1254398Z - Title: C3 (F028, perri F-h): psyche wrapper crash-loop has no backoff, and `endpoint shutdown` misses a wedged wrapper. A probe psyche crash-looped ~3 boots/sec for ~30min (CC died instantly on the untrusted owlery cwd; ledger hit ordinal 5358) — SILENTLY; and `spt endpoint shutdown` did NOT tear the looping wrapper down (docs say shutdown tears the Psyche with the perch; manual kill was required). FIX: (i) bounded backoff + loud give-up on a psyche boot loop (the psyche_host_error surface already exists), (ii) shutdown must cover a wedged/looping wrapper. See triage C3.
2026-07-17T03:24:38.1256537Z - Required stages: 
2026-07-17T03:24:38.1257350Z 
2026-07-17T03:24:38.1257636Z ### REQ-DOC-ENDPOINT-DROP-RESOLUTION
2026-07-17T03:24:38.1259635Z - Title: D1 (F028, perri F-c; docs/truth): SI-1's resolution rule — a RELATIVE watched drop dir resolves against the ENDPOINT's cwd, never the daemon's (KH 7.28, shipped v0.22.0) — is documented NOWHERE public. Add it to harness-contract/manifest.md + the manifest schema field descriptions so an adapter author knows a relative commune_dir/signoff_dir is endpoint-resolved. docs-drift gate applies. See triage D1.
2026-07-17T03:24:38.1261409Z - Required stages: 
2026-07-17T03:24:38.1261752Z 
2026-07-17T03:24:38.1262396Z ### REQ-DAEMON-STATUS-JSON-TRUTH
2026-07-17T03:24:38.1264658Z - Title: D2 (F028, perri F-d): `daemon status --json` truth drift. managed_by/managed_active read null in JSON while the HUMAN view says 'managed-by: manual — at-logon task registered' (the two surfaces disagree); and pump staleness (the STALLED diagnosis, B5) is NOT computable from JSON — only a raw pump_heartbeat_ms is emitted, no derived staleness/stalled field. FIX: JSON managed_by/active match the human render, and add a derived pump-staleness/stalled field so B5's condition is machine-observable. See triage D2.
2026-07-17T03:24:38.1266684Z - Required stages: 
2026-07-17T03:24:38.1266992Z 
2026-07-17T03:24:38.1267290Z ### REQ-ENDPOINT-LIST-RENDER-POLISH
2026-07-17T03:24:38.1270491Z - Title: A6 (F028, operator, 4 asks): `spt endpoint list` render polish. (a) the 'Shared subnets' line is NOT dim — LIGHT_GRAY = "37" (cli.rs:3019) is standard-palette WHITE, indistinguishable from row text; use SGR 90 (bright-black/gray) for the dim intent. (b) the `Total:` line takes the same dim color. (c) move the status glyph ADJACENT to the endpoint name (operator: 'right behind the endpoint name'), mirroring the picker's glyph-beside-name presentation (today the glyph sits at the end next to the status word). (d) color the status WORD like the picker TUI (green ONLINE / gray OFFLINE / blue when driven, matching picker glyph semantics). All in render_node_grouped/render_instance_row (cli.rs ~3000s); pure render with an injected color decision — unit-testable off a tty. See triage A6.
2026-07-17T03:24:38.1273457Z - Required stages: impl, unit
2026-07-17T03:24:38.1273796Z 
2026-07-17T03:24:38.1274072Z ### REQ-CLI-WIN-VT-ENABLE
2026-07-17T03:24:38.1277035Z - Title: A7 (F028, operator, Win10 conhost): ANSI emitted without VT enable → garbled console. Evidence (raw PowerShell 7, Win10 conhost): literal `←[36m` in `endpoint list` + `--help`. ROOT: ENABLE_VIRTUAL_TERMINAL_PROCESSING is enabled ONLY on the rc attach path (rc.rs:746, REQ-RC-WIN-VT-OUTPUT) — plain CLI stdout never enables it, and the color decision doesn't fall back when the console can't render VT. FIX: lift the rc.rs VT-enable into a SHARED startup helper for every colored-output path; if SetConsoleMode fails (or stdout isn't a console), STRIP colors (the ansi_wrap/helpfmt color=false path already exists — plumb the decision, not new rendering). Windows Terminal masks this (VT always on) — TEST on raw conhost. See triage A7.
2026-07-17T03:24:38.1279753Z - Required stages: impl, unit
2026-07-17T03:24:38.1280091Z 
2026-07-17T03:24:38.1280389Z ### REQ-GOSSIP-CONTROLLED-CROSS-NODE
2026-07-17T03:24:38.1283544Z - Title: B7 (F028, operator, cross-node): a remote endpoint's CONTROLLED state is not rendered. Evidence: ball-b ONLINE + CONTROLLED on ENLYZEAM (local view), but HFENDULEAM renders remote ball-b as plain ONLINE (both 0.22.0). The F-026 #4 gossiped any-controller datum (REQ-GOSSIP-ADAPTER-PROJECTS controlled bool) either isn't SENT for the locally-controlled case, isn't APPLIED on the receiving row, or DECAYS. Local leg confirmed fine (sibling hall-b renders blue-glyph correctly); the gap is the REMOTE leg. perri's validation had this ENV-BLOCKED — two live nodes now available to RCA. FIX: RCA sender-side (is controlled gossiped when locally-controlled?) / receiver-render (does from_resource_row surface it?) / decay, then lock with a cross-node int. See triage B7.
2026-07-17T03:24:38.1286393Z - Required stages: 
2026-07-17T03:24:38.1286698Z 
2026-07-17T03:24:38.1286998Z ### REQ-HAZARD-INJECT-WORKER-POISON
2026-07-17T03:24:38.1290920Z - Title: The per-session inject-worker floor Mutex is SHARED by the inject worker (open/flush) and the controller-input path (dispatch_input Layer C buffer_if_held); a panic under the lock on EITHER poisons it, and a bare .lock().unwrap() at the next site then panics too — a panic in the inject WORKER kills its thread WITHOUT reaping the translation child, orphaning a live binary while event_tx.send fails, so force-native reports 'worker-gone' delivered=false FOREVER (the F-e generic-miss shape). HARDENING, NOT the F-e incident root (perri's matrix exonerated poison under thrash/dormancy/churn): (i) poison-tolerant floor lock (unwrap_or_else into_inner) at all 3 sites so one panic can't cascade the session's delivery dead; (ii) a panic-resilient inject worker (catch_unwind -> fault+terminate the child on a worker panic) so a dead worker never orphans a live binary + strands delivery. Poison-tolerance class of REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE / bug #16.
2026-07-17T03:24:38.1294343Z - Required stages: impl, unit
2026-07-17T03:24:38.1294720Z 
2026-07-17T03:24:38.1295006Z ### REQ-HAZARD-DETACHED-DAEMON-STDIO
2026-07-17T03:24:38.1301810Z - Title: A daemon DETACHED-IN-FACT (no interactive console, or an inherited stderr PIPE nobody drains) that never nulled its std handles will BLOCK on stdio writes when the pipe fills, and/or pop a visible conhost window (REQ-HAZARD-WMI-DAEMON-WINDOW is a covered surface of this hazard). detach_console nulls the 3 handles only under the --detached flag; a rung that omits it (the bare line-82 elevated->deelevated respawn; a STALE installer at-logon task registered as bare `daemon run`, confirmed live field-drift on ENLYZEAM) is exposed. FIX: (load-bearing) inside `daemon run`, null the 3 std handles when stderr GetFileType==FILE_TYPE_PIPE — a pipe is the ONLY std sink that BLOCKS the daemon when it fills; catches every rung whose inherited stderr is an undrained pipe, independent of whether each caller passed --detached, while a FILE (2>run.log AND every int-test Stdio::from(file) brain-log capture), a CONSOLE (scrolls), and a NULL/absent handle (DETACHED_PROCESS rungs, already discard) all SURVIVE. DELIBERATELY NOT gated on GetConsoleWindow==NULL: a CREATE_NO_WINDOW daemon has no console window yet a drained FILE stderr — nulling it would blank the capture for ZERO safety gain (a file never blocks) and mass-red the int-test brain-log assertions. (belt) pass --detached on the bare line-82 respawn; (drift nag) parse the schtasks /Query action argv and LOUDLY nag when the at-logon task is the stale bare `daemon run` form (manual/installer re-registers; the daemon must NOT self-elevate to rewrite it). Defense-in-depth — no current spt Windows spawn path was proven to yield a BLOCKING inherited pipe (all rungs null-discard or scrolling-conhost), so this is hardening, not a confirmed incident root.
2026-07-17T03:24:38.1307847Z - Required stages: impl, unit
2026-07-17T03:24:38.1308185Z 
2026-07-17T03:24:38.1308490Z ### REQ-PICKER-CURRENT-DIR-LABEL
2026-07-17T03:24:38.1311905Z - Title: A-2/A-3 (F029, operator, semantic pair): the Choose-project rows must self-identify the CURRENT DIR. build_project_choices (picker/model.rs:322-352). A-2: when the run cwd IS already a history dir the `Here:` row is (correctly) suppressed by the dedup (REQ-PICKER-CHOOSE-DEDUP-ALL), but the matching history row rendered bare `r.display` with no cwd affordance — mark it `<display> (CURRENT DIR)`. A-3: the not-in-history current-dir row changes from `Here: <run_cwd>` to `CURRENT DIR --> <project>`, deriving the display the SAME way the history refs do (folder tail; honest fallback to the raw path when underivable). `cwd` payload unchanged. Grep-tests rule: 3 `starts_with("Here: ")` asserts (model.rs) + a `Here: /here` render assert (view.rs) are behavior assertions on the OLD label. See triage A-2/A-3.
2026-07-17T03:24:38.1314864Z - Required stages: impl, unit
2026-07-17T03:24:38.1315207Z 
2026-07-17T03:24:38.1315487Z ### REQ-PICKER-FORK-LABEL-CWD
2026-07-17T03:24:38.1317215Z - Title: B-3 (F029, operator): the confirm-panel `Fork endpoint` option label is static and says nothing about WHERE the fork lands. A fork runs in the picker's launch cwd (run_cwd); the label must state that dir honestly: `Fork endpoint here --> <current dir>`. Anchor picker/view.rs confirm_option_label (was `fn(opt)->&'static str`). Make the label model-aware for the dir-relative options. See triage B-3.
2026-07-17T03:24:38.1319022Z - Required stages: impl, unit
2026-07-17T03:24:38.1319360Z 
2026-07-17T03:24:38.1319656Z ### REQ-PICKER-SHORTCUT-LABEL-FILENAME
2026-07-17T03:24:38.1322042Z - Title: B-4 (F029, operator): the confirm-panel shortcut option label is a static `New/Update spt-<id> shortcut (s)` placeholder — it should name the REAL file it writes: `Set shortcut here --> <current dir>/<shortcut-name>` where <shortcut-name> is the EXACT on-disk filename (incl. extension). The name must be produced by the SAME function that names the file in shortcut creation (picker/shortcut.rs shortcut_filename over the manifest-resolved basename) so label and writer can NEVER drift. Anchor picker/view.rs confirm_option_label. See triage B-4.
2026-07-17T03:24:38.1324179Z - Required stages: impl, unit
2026-07-17T03:24:38.1324523Z 
2026-07-17T03:24:38.1324832Z ### REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER
2026-07-17T03:24:38.1328413Z - Title: A-4 (F029, operator regression): the picker/confirm views drop an endpoint's adapter `:profile` (showed `claude-spt` where `claude-spt:ccs` was created). ROOT: stamp_creation_fields (spt-store/home.rs) gave the incoming BIND-TIME adapter value UNCONDITIONAL precedence (`rec.adapter = adapter.map(...).or_else(prior)`), but a hook bind resolves the adapter ADAPTER-AGNOSTICALLY (ADR-0021: a binary basename → the BARE parent, profile unknowable), so the first hook bind rewrote the richer `claude-spt:ccs` → `claude-spt`. (F-028's establish_perch self-heal widened how often this re-stamps; the precedence is the root.) FIX: profile-preserving precedence — when the incoming adapter is exactly the PARENT of the prior's `parent:profile` composite, KEEP the prior; replace only on a genuinely different adapter (or a different explicit profile). Paid-for field bug → hazard. See triage A-4.
2026-07-17T03:24:38.1331754Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1332106Z 
2026-07-17T03:24:38.1332379Z ### REQ-PICKER-WINDOW-TITLE
2026-07-17T03:24:38.1334529Z - Title: B-5 (F029, operator): `spt endpoint run`'s interactive picker window/tab is untitled — hard to find among many terminals. Set the window/tab title to `SPT Endpoint Picker`. Anchor picker/mod.rs:88 setup_terminal (crossterm SetTitle in the execute! chain). Set-only is acceptable (crossterm can't cheaply read the prior title to restore). Applies ONLY to the interactive picker path — non-interactive/headless `endpoint run` (REQ-HOST-RUN-1) must NOT retitle the operator's terminal. See triage B-5.
2026-07-17T03:24:38.1336518Z - Required stages: impl
2026-07-17T03:24:38.1336852Z 
2026-07-17T03:24:38.1337162Z ### REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE
2026-07-17T03:24:38.1339647Z - Title: B-1 (F029, operator): the `h` (headless start) / `s` (shortcut) keybinds fire from broad picker contexts (mod.rs handle_confirm_key / ChooseProject / Resume) regardless of whether the highlighted row would LAUNCH the endpoint. Restrict both to launch-capable highlights: (a) `Start now` in the immediate-start case (should_offer_project_choice == false), (b) a Choose-project row, (c) a Resume-from-history row. The footer hint line must render `h`/`s` ONLY when actually live (hint truth = availability truth). FIX: gate the key handlers on (screen, highlighted-option), unit the gate as a pure matrix. See triage B-1.
2026-07-17T03:24:38.1342023Z - Required stages: impl, unit
2026-07-17T03:24:38.1342370Z 
2026-07-17T03:24:38.1342658Z ### REQ-PICKER-CHANGE-ADAPTER-FLOW
2026-07-17T03:24:38.1345977Z - Title: B-2 (F029, operator; LARGEST item): `ConfirmOption::ChangeAdapter` wrongly routes into the CREATE flow (Screen::CreateAdapter → CreateId → CreateHome → START, reenter_create(true)) — it re-prompts id + home and then STARTS the endpoint. Required: prompt ONLY the harness-adapter pick, apply the change to the perch record (update info.json.adapter via the existing write seam; an `<adapter>:<profile>` pick stamps the full option, composing with A-4), then RETURN to the endpoint's Confirm menu — NO id prompt, NO home prompt, NO start. FIX: a return-to-Confirm mode on the adapter-pick screen (flag or dedicated Screen::ChangeAdapterPick) skipping CreateId/CreateHome + the launch outcome. Unit the flow-state transitions + the record write. Shared-seam: touches picker flow state — run the full picker cluster. See triage B-2.
2026-07-17T03:24:38.1349267Z - Required stages: impl, unit
2026-07-17T03:24:38.1349645Z 
2026-07-17T03:24:38.1349936Z ### REQ-TRANSLATE-COMMIT-MISS-TOLERANCE
2026-07-17T03:24:38.1353862Z - Title: C-1 (F029, B6 ROOT — rescope of REQ-TRANSLATE-BINARY-LIVENESS-DECAY, now PINNED): at a checkpoint clear boundary the clear-only inject drives `/clear`; its `{commit}` is never observed within INJECT_COMMIT_DEADLINE (5s, broker.rs:158) so the inject worker FAULTS + TERMINATES a HEALTHY translate binary (broker.rs respool_and_fault + return) and by ADR-0022 design NEVER respawns → every subsequent force-native reports delivered=false ('no live translation binary', cli.rs:5046) = B6's exact field signature; the v0.12.0 checkpoint post-clear WAKE dies with the terminated binary + the fire-and-forget FIRE in the dead window. NOT a race — deterministic at every checkpoint-armed boundary (perri captured-stderr proof: TRANSLATION_FAULT on the F-019 unread daemon-stderr channel). FIX (REVISED, supersedes terminate-then-respawn): miss != fault — preserve the binary; the watchdog's job is ANTI-STALL (release the operator floor), not execution-verification. See addendum C-1 + ADR-0022 amendment.
2026-07-17T03:24:38.1357484Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1357828Z 
2026-07-17T03:24:38.1358142Z ### REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH
2026-07-17T03:24:38.1361125Z - Title: C-1 hazard (F029; paid-for: B6 + three-version checkpoint-wake breakage): a REAL translation fault (binary death — stdin write fail / stdout disconnect — or strike-budget exhaustion) must get a BOUNDED eager respawn (C3(b) give-up budget) instead of permanent death, and must stamp a PERCH-VISIBLE fault surface (mutate_info field, cleared on healthy respawn/commit) — TRANSLATION_FAULT is daemon-stderr-only today (the F-019 unread-channel trap; same honesty rule as F-027 ENDPOINT_SPAWN_FAIL). A real fault legitimately loses in-memory state (the wake is NOT carried across a real fault, unlike a mere commit-miss). See addendum C-1 (3)-(4).
2026-07-17T03:24:38.1363610Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1363963Z 
2026-07-17T03:24:38.1364244Z ### REQ-HAZARD-BOUNDARY-READY-STRAND
2026-07-17T03:24:38.1368871Z - Title: C-2 (F029, SEAM-2 pinned — B6's SECOND HALF, the live-wake blocker; perri wakep9 vs wakep4 gate-state dump + doyle code trace): at a /clear, CC fires SessionEnd(reason=clear) for the DEPARTING session BEFORE SessionStart; the departing sid STILL matches the perch pin at that instant, so the adapter's [hooks.SessionEnd] → `api session-end` AUTHENTICATES and the soft handler REMOVES the ready marker (+ unregister_address, reporting.rs cmd_session_end:206-207). The subsequent `api boundary` rotates the sid but NOTHING re-writes ready → is_online false → try_spt_hosted_inject Nones on the CLI gate BEFORE any broker RPC → every post-clear force-native (incl. the checkpoint FIRE) reports the generic UNDELIVERED, persistent by construction (no path re-stamps ready outside a real bind). The single differing gate field at every UNDELIVERED instant is ready-absent (info online/controllable/rotated-sid all healthy, translate alive). Paid-for hazard. FIX: cmd_boundary re-stamps the ready marker (+ status online, idempotent) ATOMICALLY with the sid rotation — a boundary PROVES a live successor session on the same harness process; a REAL end has no subsequent boundary so genuine teardown is untouched. See triage addendum C-2.
2026-07-17T03:24:38.1373642Z - Required stages: impl, int
2026-07-17T03:24:38.1373980Z 
2026-07-17T03:24:38.1374262Z ### REQ-PSYCHE-EPHEMERAL-DRIVER
2026-07-17T03:24:38.1378463Z - Title: W1 (F030, design §3): each psyche-relevant event runs exactly ONE bounded per-event turn through the existing driver stack (psyche_turn_and_relay for outbound-intent events / resume_psyche for session-custody transitions / run_psyche_turn for pure merges) — no resident psyche process exists between events. host_one (livehost.rs:518) STOPS spawning spawn_psyche_owned; the pulse loop stays as the daemon-side scheduler (thread + stop-flag + drop-dir watch correct) but a fire now invokes one bounded turn, daemon-driving every substitution key from daemon-known context (child never self-resolves home/subnet/perch — direction-(a) multi-subnet churn impossible by construction). Turn failures consume a bounded failure budget (C3(b) shape): N consecutive failures → psyche_host_error stamp + cooldown, reset on success; no respawn storm (nothing resident to respawn). Red-first: fire an event on a hosted live endpoint → assert one turn ran (SIDE-EFFECT PROOF FILE — transcript-jsonl asserts are structurally blind, 2026-07-04 rig lesson) and no {id}-psyche process survives the turn.
2026-07-17T03:24:38.1382721Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1383088Z 
2026-07-17T03:24:38.1383357Z ### REQ-PSYCHE-SID-CUSTODY
2026-07-17T03:24:38.1387168Z - Title: W2 (F030, design §3): the psyche mints and keeps its OWN session id, stored in the nested {id}-psyche perch record — {session_id} in psyche role templates becomes the psyche's sid, never the parent's (today's fill at livehost.rs:518 is the PARENT's — the custody bug). Parent boundary (/clear, /compact) does NOT rotate the psyche sid (the psyche's conversational thread survives parent resets — its job). resume_psyche validates the custody key before spawn (resume.rs:183). Reseed path: psyche session lost/invalid → ResumeMode::FreshWithPreload (download_psyche_context composes role/live/project into {psyche_context}, resume.rs:100) + LOUD PSYCHE_RESEED:{id} marker (custody-loss loop visible; W1 budget bounds it). If the parent sid is still needed by a template it gets its OWN explicit key {parent_session_id} — never aliased. Red-first: parent `api boundary clear` → nested perch sid UNCHANGED (today it is the parent's — guard-revert reproduces).
2026-07-17T03:24:38.1390809Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1391169Z 
2026-07-17T03:24:38.1391455Z ### REQ-PSYCHE-NESTED-RESOLUTION
2026-07-17T03:24:38.1395678Z - Title: W4 (F030, design §3; F-017 sibling, general not psyche-only): nested {parent}/{nested} ids resolve under the PARENT's home — subnet-less resolution for nested perches (the home-ASSIGNMENT seam, not perch-path which is already subnet-less) — so child-side verbs acting on nested perches need no --subnet the child cannot know. ROOT: home::assign_home returns Ambiguous on a multi-subnet node w/o --subnet; a nested id must instead derive home from its parent perch. Additionally expose a SINGLE {subnet} base_keys fill WHEN KNOWN (own_subnet = home-subnet label, 'local' when unhomed; absent → LOUD missing-key fail, the {node} precedent). NO {home} key (doyle W4 Q1: the endpoint home subnet is ONE concept per CONTEXT.md:640, and 'home:' is already the subnet-name qualifier position CONTEXT.md:652 — a {home} template key invites meaning-drift). Red-first = evidence #3's exact repro: 2-subnet home, nested-id verb, must succeed (was: `spt ready <id> --once` → exit 1 READY_FAIL … pass --subnet).
2026-07-17T03:24:38.1399411Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1399777Z 
2026-07-17T03:24:38.1400078Z ### REQ-PSYCHE-CONTEXT-FILE-INDIRECTION
2026-07-17T03:24:38.1405670Z - Title: W4 (F030; doyle Q2 ruling + perri file-always freeze, 2026-07-04): the composed psyche mind ({psyche_context}) rides the SHIM argv today — a real ~20KB doyle psyche-download exceeds the win32 CreateProcess lpCommandLine ~32k cap → the shim spawn BRICKS. FIX (file-always, replaces {psyche_context} outright — no size-branch, no argv cliff, one path): core writes the mind to a file in the psyche's NESTED perch dir BEFORE each turn spawn and fills a single {psyche_context_file} = that PATH (argv-cap-immune). The soft fresh/continue discriminator moves from KEY-presence to FILE-CONTENT: FreshWithPreload writes the composed mind NON-EMPTY (the <fresh-psyche/> never-empty guarantee carries to the file content); ContinueExisting writes it TRULY 0-BYTE (perri BINDING PIN 1 — NO sentinel/placeholder EVER, else her non-empty=fresh discriminator misfires a spurious --session-id adopt). Core owns the file lifecycle: write-before-spawn each turn, overwrite in place, persists between turns in the nested perch (debuggability); never deleted per turn. perri shim delta: --psyche-context-file <path> arg, read-file prefix, TRIM-based emptiness (her tolerance, NOT core's license — core writes exactly 0 bytes on continue, PIN 2), read-failure = generic fail NEVER 95, never writes/deletes the file. Red-first: a ~40KB mind → the old {psyche_context}-on-argv path BRICKS the win32 shim spawn; the file path succeeds (shim reads the full mind from file).
2026-07-17T03:24:38.1411220Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1411592Z 
2026-07-17T03:24:38.1411887Z ### REQ-PSYCHE-LEGACY-RESIDENT-SWEEP
2026-07-17T03:24:38.1419126Z - Title: W5 (F030; doyle+perri 2026-07-04): a dirty daemon upgrade from <=v0.24.0 strands a RESIDENT psyche wrapper the OLD daemon spawned — and F-030 W4's nested-`ready` resolution fix CONVERTED that wrapper's accidental self-reap into a permanent HANG. The pre-W3 wrapper's only spt IPC is `spt ready <parent>-psyche --once` (BLOCKING, no internal timeout); pre-W4 that hit READY_FAIL on a multi-subnet home → the wrapper exit-4'd (accidental reap). Post-W4 the nested id resolves cleanly → the wrapper REGISTERS then BLOCKS FOREVER on its first post-upgrade poll: no exit, no psyche_host_error, no CPU (KH 2.6 invisible-loop class, one level up). Post-W3 core has no residency machinery to reap it. FIX: a ONE-SHOT legacy-resident sweep at BRAIN START (never per-reconcile/periodic — burying residency-era machinery, not resurrecting it). GUARD = adapter-AGNOSTIC (glue-model): resurrect the retired reap_orphan_psyches LOGIC — for each self-perch live-agent id derive `<id>-psyche` and kill iff (a) exe basename == the adapter's MANIFEST-declared psyche program (normalize_basename, never a hardcoded adapter name) AND (b) cmdline contains the id marker `<id>-psyche` AND (c) pid alive; any unreadable signal → DECLINE + loud log (fail-safe-decline, positive-match-only; infra never-kill inside the sweep). FRATRICIDE is closed by TIMING (perri-confirmed from the owning side): the ephemeral shim is daemon-spawned per-event, bounded, exits at turn end — at brain start BEFORE the first reconcile/pulse no current shim is resident, so any `<id>-psyche` psyche-program process alive then is unambiguously stranded-legacy. RESIDUE (doyle PIN 3): the hung wrapper REGISTERED a `<parent>-psyche` ready perch before blocking; killing the pid alone leaves a phantom ready-record with a dead pid (the REMOTE-TRUTH presence-lie class) — the sweep MUST also clear that stale registration or prove the existing stale-perch cleanup reaps it. No field window pre-W6 (nothing releases). (F-030 W5)
2026-07-17T03:24:38.1426055Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1431378Z 
2026-07-17T03:24:38.1431725Z ### REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION
2026-07-17T03:24:38.1435676Z - Title: W3 (F030 hazard; paid-for: hall-bf churn ordinal 6491+ + adapter v0.13.2 bad-ship brick 2026-07-04): a psyche failure of ANY shape must NOT remove or alter the parent endpoint's ready/hosted state, and hosting must NOT churn-respawn. The v0.13.2 shim-exit tripped the residency machinery (confirm_residency_or_unhost) which tore down the endpoint's hosted state — ready marker removed, never re-stamped, every force-native gated leg=cli-gate-not-hosted PERMANENTLY (field brick). FIX: residency machinery retires with the resident child; the teardown that touches parent hosted state is DELETED — psyche trouble stamps psyche fields only. REQ-HAZARD-LIVEHOST-NONRESIDENT's spirit transfers to the W1 failure budget (its entry gets a SUPERSEDED pointer here, LIVENESS-DECAY→SUPERSEDED pattern from C-1). Conformance int = the hall-bf shape: multi-subnet home, live endpoint, failing psyche → parent stays deliverable, no rehost churn, error stamped (the wave's heart).
2026-07-17T03:24:38.1439326Z - Required stages: doc, impl, int
2026-07-17T03:24:38.1439679Z 
2026-07-17T03:24:38.1440022Z ### REQ-HAZARD-THRASH-GUARD-BLIND
2026-07-17T03:24:38.1441885Z - Title: W3 (F030 hazard; paid-for: evidence #6, hall-bf ~12/min re-host NEVER tripped the C3(b) thrash guard — boot records were not ledger boundaries to the guard): the failure budget must count REAL attempts (ledger-derived: boot/turn records via the psyche perch ledger), not whatever it counted that let 12/min churn run invisibly. Red-first synthetic loop: a 12/min synthetic failure loop MUST trip the budget.
2026-07-17T03:24:38.1443638Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1443999Z 
2026-07-17T03:24:38.1444279Z ### REQ-EFFECTIVE-INSTANCE-STATE
2026-07-17T03:24:38.1449834Z - Title: A-1 (REMOTE-TRUTH triage §A + ADR-0033 §Decision): the effective instance state of a perch is DERIVED through ONE shared function — liveness discriminates warm/cold, stored rest intent refines within warm, absent intent NEVER defaults active. ROOT (certain): resting::apply_event derived its `from` off the stored rest_state field ALONE (resting.rs:225, `unwrap_or(RestState::Active)`) — a cold perch (offline) with no intent answered `from=Active`, so a Wake event found it 'already in target state' and returned Ok(None) = the field NO_EDGE-on-a-definitely-suspended-endpoint bug (the banked F-028 rest_state-void seed). advertised_status (registryhost.rs:821) ALREADY derived correctly (is_perch_alive→intent-refined / is_perch_unbound→Dormant / cold→Suspended) — the two readers disagreed. FIX (Q1 shared derivation, hazard-class): a pure `effective_rest_state(alive, unbound, intent) -> RestState` mirroring advertised_status, consumed by BOTH advertised_status (mapped RestState→Status, behavior identical) AND apply_event's `from` (real is_perch_alive/is_perch_unbound reads); void + cold ⇒ Suspended. Bonus: kills the spurious active→suspend echo a cold+void perch used to fire (on_rest_edge on a dead driver). Red-first: perch status=offline + no rest_state → daemon_rest_event(Wake) yields from=Suspended→to=Active EdgeReport, not Ok(None).
2026-07-17T03:24:38.1454988Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1455365Z 
2026-07-17T03:24:38.1455665Z ### REQ-OPID-MINTER-NAMESPACE
2026-07-17T03:24:38.1464217Z - Title: A-4a (REMOTE-TRUTH triage §A + ADR-0034 Decision 1 + Amendments 1 & 2): the broker effect journal's dedup key gains a minter dimension so ops minted by independent counters can never collide. ROOT (high, ground-truthed vs HEAD): the journaled-op producers key into ONE journal namespace (NET_EFFECT_SESSION|shell_sid, op) at broker.rs (EffectKey=(u64,u64)); a CLI wake op colliding with an already-journaled daemon op reproduces the typed 'already applied … retry with a fresh op_id' with NO broker restart (field-hit: spt endpoint wake id@node WOKE_FAIL). Same latent class: nethost dial_ops/stream_ops HashMap<u64,u64> ('Shares the one net op-id namespace') would re-clobber even after the journal separates them; AND shellchan::deliver_stdin_pending journals (shell_sid, row_id) so an rc operator's ops on the same shell_sid collide with spool row ids (dropped keystroke OR dropped spool row). Amendment 2 corrected the minter set: the REAL journal minters are {cli, pump, rc, shell} + legacy — psyche/epoch are the EpochSource notif/lease counter domain, NEVER submit to apply_once, DROPPED from the journal enum (a tag with no stamp site = doc'd-but-dead knob). FIX (Decision 1 + Amdt 2): ONE canonical Minter enum {Legacy, Cli, Pump, Rc, Shell, Wake} — Legacy reserved for pre-upgrade lines + untagged wire, monotonically shrinks; enum is the single source for the TEXTUAL journal-line token (self-describing during recovery). EffectKey becomes (effect-class, minter, op); recover() DUAL-PARSES (old shorter line → minter=Legacy, new longer line → parsed tag) so old journals need no migration and old-shape keys can never equal new-shape (migration-free). A MintedOp{minter, seq} newtype REPLACES bare op_id:u64 through the brain/daemon THREADING paths so forgot-to-stamp is UNCOMPILABLE (row_id stays the shell seq — never re-minted, the durable spool exactly-once identity). Wire keeps an additive optional minter field (serde default absent ⇒ Legacy materialized at broker decode; serde_json no deny_unknown_fields ⇒ NO wire version bump); the newtype is NOT forced into wire structs. nethost op-maps re-key by (minter, op). Red-first: mint an rc op == a journaled shell/pump/daemon op int on the same session → pre-fix the second dedups/clobbers (WOKE_FAIL class); post-fix both are distinct keys, both Applied.
2026-07-17T03:24:38.1472228Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1472571Z 
2026-07-17T03:24:38.1472853Z ### REQ-OPID-TRACING-RETRY
2026-07-17T03:24:38.1478329Z - Title: A-4b (REMOTE-TRUTH triage §A + ADR-0034 Decision 2): the tracing-only op families auto-retry ONCE with a fresh op on the typed no-longer-held error, so a broker-restart-dropped conn/stream self-heals instead of surfacing core lingo to the user. ROOT: net/rest.rs declares rest op-ids 'tracing/correlation only … redelivery needs reporting, not dedup', yet the journal enforced exactly-once on them — a rest/attach op whose conn the broker no longer holds (post-restart) returned the typed 'already applied … no longer held … retry with a fresh op_id' (broker.rs:2796 net-dial / 3047 stream-open) straight to the user (WOKE_FAIL / rc attach fail). FIX (Decision 2, scoped): the rest family (request_rest) + rc attach stream-open (request_attach_endpoint) — and ONLY those — catch the typed no-longer-held error INTERNALLY and re-issue ONCE with a FRESH op minted from the SAME minter (A-4a MintedOp; same producer, new seq). sync/update pull families (request_sync/request_update, durable open_op) are NOT wrapped — their exactly-once dedup is load-bearing (negative control). The typed op error becomes internal-only; if the retry ALSO fails, the user-facing line names the observable situation + next action in operator language, ZERO journal/op/brain lingo (F-1 public-error rule applies early — this string is user-facing). Red-first: mint a colliding op → assert the retry succeeds + the user sees NOTHING; NEGATIVE CONTROL — a durable family's no-longer-held stays a hard error, no silent retry.
2026-07-17T03:24:38.1483798Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1484145Z 
2026-07-17T03:24:38.1484421Z ### REQ-REST-VERB-ROUTING
2026-07-17T03:24:38.1493024Z - Title: A-3 (REMOTE-TRUTH triage §A + Q3 operator-law): a BARE-id rest verb (spt wake/suspend <id>) routes across the subnet like send's fallback instead of failing local-only. ROOT (certain): cmd_rest (cli.rs:3296) gates the remote arm on id.contains('@'|':'); a bare id falls to the local-only arm (cli.rs:3340) → daemon_rest_event → info::read_info miss (resting.rs:248) → 'WOKE_FAIL:{id}: info.json absent or unreadable — not a hosted perch'. cmd_send (cli.rs:5142) DOES fall back on a local miss; cmd_rest's remote arm (cli.rs:3307, wan_rest) already handles every WanRestOutcome — it is simply never reached on a bare-id local miss. Contradicts CONTEXT:286 'a wake must route'. Q3 SUBSTRATE GAP: resolve_across_visible (registry.rs:971) filters only by Status::routable() and its Ambiguity payload is node-hexes-only — it CANNOT express the Q3 status rule; per-candidate (node,status) comes from SubnetRegistry::instances(id). FIX: a NEW pure select_rest_target helper (status-aware, isolated from resolve_across_visible which cmd_send keeps) applying GOAL-SATISFACTION semantics (ADR/triage addendum @188d269, NOT naive verb symmetry — the mixed case breaks symmetry): wake is an ∃-goal (satisfied when ANY instance Active), suspend is a ∀-goal (satisfied when ALL instances Suspended); one helper parameterized by the verb's satisfaction predicate — 0 candidates→NotFound; goal already satisfied→NoOp naming the satisfying node(s); exactly 1 ACTIONABLE (not-at-target) instance→Act(node); >1 actionable→Ambiguous(copy-paste id@node list). Edge rulings: wake with >1 Active = NoOp naming ALL active nodes (NOT Ambiguous — nothing actionable); suspend mixed (X suspended + Y active, NOT ∀-satisfied) = Act(Y) if exactly one active / Ambiguous if several active. Candidate status is ADVERTISED/gossiped (post-A-1 shared-derivation, may be STALE) so a NoOp verdict is ADVISORY and the qualified id@node path is the operator override (noted in the helper doc-comment). cmd_rest's bare-id local miss loads snapshots → instances(id) → select_rest_target → dispatches (Act→wan_rest to the node / NoOp naming node(s) / Ambiguous render_refusal copy-paste id@node list / NotFound NO_ENDPOINT), all F-1 public language from day one. Qualified id@node path unchanged; shutdown leg-2 stays LOCAL_ONLY. Red-first: a bare id present ONLY in a remote registry snapshot routes to that node instead of WOKE_FAIL.
2026-07-17T03:24:38.1501245Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1501599Z 
2026-07-17T03:24:38.1501892Z ### REQ-SESSION-ADAPTER-RECORDED
2026-07-17T03:24:38.1507747Z - Title: D-2 (REMOTE-TRUTH triage §D-2 + operator Q5 @c248afc): the session ledger records the adapter[:profile] a session ran under, so a later resume can restore the harness the session actually used (not merely the endpoint's CURRENT stamp). ROOT: SessionEntry (spt-store/sessions.rs:58) carries ts/session_id/trigger/cwd/ordinal but NOT the adapter — a resume-from-history row cannot know which harness authored the transcript, so a resume under a since-changed endpoint adapter (B-2 ChangeAdapter, or a fork) launches the wrong harness. FIX: an ADDITIVE `adapter: Option<String>` on SessionEntry, exact cwd/ordinal serde pattern (#[serde(default, skip_serializing_if="Option::is_none")]) — a pre-migration row missing the key deserializes None; None omits the key on serialize (byte-identical to old rows); an unknown key on an old reader is ignored (serde default) — back-compat BOTH directions. Stamped at every PRODUCTION session-boundary append. CENSUS (doyle-confirmed @94f0205, corrects the triage-era 5-site drift to the real 3): startup.rs:317 (live bind boot row, rec.adapter in scope), reporting.rs:94 (boundary rotation row UNDER the mutate_info lock, capture adapter_for_ledger=rec.adapter beside cwd_for_ledger), ready.rs:119 in crates/spt-msg (ready-agent boot row, rec.adapter in scope). NOT digest.rs:601 (cfg(test) fixture) and NOT a livehost psyche-ledger append (none exists — the live /clear|/compact boundary shells `api boundary` → reporting.rs:94, the SAME append). None-stamp is a benign degrade (resume falls back to the endpoint's current adapter).
2026-07-17T03:24:38.1513624Z - Required stages: impl, unit
2026-07-17T03:24:38.1513985Z 
2026-07-17T03:24:38.1514338Z ### REQ-RESUME-ADAPTER-FOLLOWS-SESSION
2026-07-17T03:24:38.1521922Z - Title: D-2 (REMOTE-TRUTH triage §D-2 + operator Q5 @c248afc): a resume-from-history restores the RECORDED session adapter (REQ-SESSION-ADAPTER-RECORDED) — the resumed harness is the one the session ran under, re-stamped onto the endpoint PRE-SPAWN, and an unregistered recorded adapter refuses LOUDLY before launching anything. ROOT: the picker's resume_outcome (model.rs:1285) bakes adapter=ep.adapter_profile from the selected ENDPOINT, ignoring the ledger row — so a resume always uses the endpoint's CURRENT adapter even when the session ran under a different one; and the endpoint's info.adapter is never re-stamped to the row's on the resume path (cli.rs:1962 skeleton writer early-returns for an existing perch — adapter immutable, carried by bind's stamp_creation_fields). FIX (doyle fork ruling): ResumeRow (model.rs:199) gains adapter: Option<String> threaded from SessionEntry.adapter in picker/data.rs; the row title (model.rs:228) renders [{adapter}] when Some ({head} [{adapter}] - {time} (…{id5})); resume_outcome bakes the ROW's adapter with an endpoint fallback (row.adapter.unwrap_or(ep.adapter_profile)) — None → the endpoint's current stamp (benign degrade). The pre-spawn RE-STAMP + refusal ride the picker resume dispatch (mod.rs:360 Run arm, resume.is_some()) reusing the hazard-guarded mutate_info seam (write_adapter_change/mod.rs:336), NEVER the bind path: order = read current info.adapter → if the baked adapter DIFFERS (a real replace; a None-row bakes the endpoint's own → equals current → NO write) → registered-check via resolve_option (Err(NotRegistered) → loud F-1 refusal naming the adapter + `spt adapter add`, NO stamp, NO spawn) → write_adapter_change re-stamp → spawn. ONE adapter write path (the mutate_info seam); REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER's bind/hook path (stamp_creation_fields, home.rs) UNTOUCHED — both its guard tests stay green as the gate condition. Red-first: a resume row adapter="claude-spt" over an endpoint stamped "claude-spt:ccs" → the baked Outcome.adapter == "claude-spt" (the deliberate replace) and the pre-spawn stamp writes it.
2026-07-17T03:24:38.1529525Z - Required stages: impl, unit
2026-07-17T03:24:38.1529892Z 
2026-07-17T03:24:38.1530155Z ### REQ-WAKE-RESUME-LEG
2026-07-17T03:24:38.1536993Z - Title: A-2 (REMOTE-TRUTH triage §A-2 + ADR-0033): the daemon reconcile gains a WAKE-RESUME LEG — an endpoint whose rest INTENT is Active but whose harness session is COLD (status != online) is resumed by the daemon via the adapter's [session.resume] template using the LAST LEDGER session id, so a bare `spt wake <id>` on a suspended live agent actually brings it back (today: reconcile_once start-arm hosts ONLY status==online (livehost.rs:199), so a woken-but-unbound endpoint is skipped forever — neither status reaches online nor does reconcile re-host). This is the ADR-0033 LIFT: the thin `spt wake` edge writes rest intent, the DAEMON does the work. Mirrors shellwake::resolve_wake (read rest state, live-pid double-launch guard, launch, NEVER flip status — the harness self-binds → online). The leg reads the recorded adapter (D-2, REQ-SESSION-ADAPTER-RECORDED); an UNREGISTERED recorded adapter is the Q5 daemon-variant refuse: do NOT spawn, record a LOUD host_error report (F-1 naming the adapter + `spt adapter add`), never silent, never fallback-spawn on a different adapter. BINDS: (1) status=online is set ONLY by a real bind — the resume leg NEVER stamps it (CONTEXT liveness truth; the A-1 effective-state derivation depends on this staying honest). (2) host_error is a REPORT of the most recent host-level failure, NEVER a liveness input — neither liveness nor advertised_status reads it (host_error + online still derives Active); cleared on a successful host/bind; the existing silent `continue` on a deregistered online adapter (livehost.rs:205) folds into the same field. (3) the resume-pid guard marker is CUSTODY-ONLY (F-030 nested-record discipline) — never a liveness input. cold-with-no-ledger-row degrades benign (loud-logged skip, no crash, today's behavior). Single-node; C-2 picker Wake-now unblocks after. --wait is a SEPARATE rider (REQ-WAKE-WAIT).
2026-07-17T03:24:38.1543625Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1543982Z 
2026-07-17T03:24:38.1544248Z ### REQ-WAKE-WAIT
2026-07-17T03:24:38.1546807Z - Title: A-2 rider (REMOTE-TRUTH triage §A-2): `spt endpoint wake --wait` blocks on the REAL bind (status reaches online) after the daemon wake-resume lift (REQ-WAKE-RESUME-LEG), instead of the DEFAULT accepted-not-bound print (thin edge writes intent, daemon lifts async — ADR-0033). Reuses the F-027 bind-await machinery if/when it lands, else a bounded poll on status==online with a plain-language timeout (no core lingo, F-1). Default wake is UNCHANGED (accepted-not-bound truth). Separate chunk from the core leg (doyle A-2 ruling: C-2 needs the core leg, not --wait); F-027 bind-await stays design-only until this activates.
2026-07-17T03:24:38.1549264Z - Required stages: 
2026-07-17T03:24:38.1549566Z 
2026-07-17T03:24:38.1549920Z ### REQ-PICKER-REMOTE-WAKE
2026-07-17T03:24:38.1557817Z - Title: C-2 (REMOTE-TRUTH triage §C-2 #4 + addendum @3442ce5): a REMOTE suspended picker row offers `Wake now` — waking the endpoint THROUGH its owning node's rest edge (the A-2 daemon resume leg) — instead of a bare `Start now` that silently cold-starts a COLLIDING LOCAL instance of a remote id (node-anchored identity violation, ADR-0003/0023). ROOT (certain): confirm_options collapsed Suspended into the offline action set = [Start,…]; on a REMOTE row `Start` bakes Outcome::Run with NO node → picker dispatch → cmd_endpoint_run creates a fresh LOCAL perch of the remote id (model.rs confirm_terminal / mod.rs dispatch). Remote rows are only Online/Suspended, so remote+offline == remote-suspended. FIX: confirm_options splits the offline arm on is_local — remote → vec![Wake] (a new ConfirmOption::Wake), local → vec![Start] UNCHANGED; confirm_terminal(Wake) → a new Outcome::Wake{id,node} carrying the RAW node hex; dispatch routes crate::cli::cmd_endpoint_wake_remote(id,node) → cmd_rest(id@node, RestEvent::Wake) = the EXISTING WAN rest arm (dispatch_wan_rest → wan_rest), and A-2's resume leg revives the session async (the full loop the operator wanted). `Instantiate locally` stays the separate deliberate-copy verb. ADDENDUM correction (a): EndpointRow.node is the LOSSY DISPLAY string (node_label_display = 'LABEL (prefix…)'), which node_qualifier_matches (full-hex-prefix|exact-label) CANNOT match — a dead Wake; so a NEW EndpointRow.node_key: String carries the raw ResourceRow.node hex (empty for local rows — Wake is remote-only) threaded through from_resource_row + the 4 literal ctors. CO-GATE (b, addendum): ChangeAdapter (was `offline`-gated) is gated `offline && is_local` — write_adapter_change → resolve_perch_path(Infer) → mutate_info rewrites a LOCAL perch record, so offering it on a remote suspended row is the SAME colliding-local-write-for-a-remote-id class (the Start twin); a remote node's adapter is not ours to rewrite from here. Red-first: a remote suspended row → confirm_options has Wake NOT Start NOT ChangeAdapter, and confirm_terminal(Wake) → Outcome::Wake{node==raw hex} (never a local Outcome::Run); a LOCAL offline row is UNCHANGED (Start + ChangeAdapter).
2026-07-17T03:24:38.1565391Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1565739Z 
2026-07-17T03:24:38.1566029Z ### REQ-HAZARD-BROKER-FLOOR-LOCK-POISON
2026-07-17T03:24:38.1575380Z - Title: B-1 (REMOTE-TRUTH triage §B-1, PIVOTED @e5eb99a): NO bare `.lock().unwrap()` on a broker-resident lock reachable from serve/dispatch — a brain-only self-update keeps the broker + all its Mutexes ALIVE (REQ-UPD-3), so a single panic under one poisons it PERMANENTLY: the next `.lock().unwrap()` panics, kills its per-conn reply thread, and EVERY subsequent attach silently deadlines ('brain IPC read deadline elapsed') while non-locked ops keep working. TRIAGE-DRIFT (sweep-dispatch-site-counts discipline): the triage named 3 sites (broker.rs:1163 flush_inject_floor / :1297 inject-worker-open / :2142 buffer_if_held) as the surviving class, but ALL 3 are the INJECT FLOOR and were ALREADY poison-proofed by REQ-HAZARD-INJECT-WORKER-POISON (lock_floor, shipped post-triage — the FLOOR HALF is SUBSUMED, this seed redirects). The SURVIVING class (matching the triage's own symptom description) is the ATTACH-PATH lock set: self.sessions Mutex<HashMap> ×18 + its sessions_exit alias ×1, the per-session OutputLog RING ×11 (log/h.log/log_drain/log_exit), pair_holds ×4 — 34 production bare .lock().unwrap() (cfg(test) excluded). FIX (doyle B-1 ruling): recover ALL THREE via ONE shared `recover<T>(&Mutex<T>) -> MutexGuard<T>` helper (into_inner idiom, same as lock_floor / the effect journal bug #16 — safe for the short coherent-on-recovery map ops of sessions/pair_holds), plus `recover_log(&Mutex<OutputLog>)` for the ring which adds a COHERENCE CLAMP on the poison-recovery path: a panic mid-append can leave the ring torn (over-cap, a last seq not below next_seq, non-monotonic front/back) and serving those bytes risks garbage, so OutputLog::clamp_or_reset cheap-checks the invariants and RESETS the ring empty (next_seq preserved — cursors never rewind) + loud-logs on violation. Rationale: fail-fast on the log reintroduces the very wedge B-1 kills (poisoned log = every subscriber attach panics forever); blind recover serves torn bytes; clamp-or-reset costs only scrollback that self-heals on the next PTY output + repaint (lost scrollback << permanent wedge, torn-serve eliminated not tolerated). Sessions/pair_holds recover bare (short map ops, coherent-on-recovery). CLASS invariant (KNOWN-HAZARDS 7.33): any new broker-resident lock uses recover/recover_log or a documented fail-fast justification. Red-first: a scripted panic-under-sessions-lock → recover hands back a usable guard, the next attach still opens; a TORN-RING variant → recover_log clamps/resets so the subscriber gets sane bytes.
2026-07-17T03:24:38.1583878Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1584249Z 
2026-07-17T03:24:38.1584526Z ### REQ-CONTROLLER-LIVENESS-REAP
2026-07-17T03:24:38.1594482Z - Title: B-2 (REMOTE-TRUTH triage §B-2, REDUCED @bdc1242): a stale ONLINE+CONTROLLED stamp on a live-session perch self-heals — the info.json driven_by/controlled RECORD is made to match the broker's SINK-TABLE TRUTH. ROOT (persisted-stale-stamp class, doyle Q1): the livehost control reap gates on !has_session (reconcile_hosted_liveness), and a brain-only update KEEPS the session (REQ-UPD-3), so a controller stamp that went stale WHILE the session lived was never re-derived from broker truth. NOT a transport bug: (a) a persisted conn is the REQ-UPD-3 feature; (b) an idle-severed conn eventually EOFs via QUIC keepalive → handle_conn detach (path 1) — and the reason paths 1-3 previously failed to clean up was the B-1 broker floor-lock POISON WEDGE (cleanup panicked under the poisoned lock), now fixed. REDUCTION (doyle, my ground-truth): the prescription was 80% pre-built — converge_perch_stamps (broker.rs, REQ-HAZARD-CONTROL-STAMP-CONVERGENCE) ALREADY converges info.json driven_by/controlled to the broker's controller_by/has_controller on EVERY KIND_SESSIONS poll, and the livehost reconcile already TRIGGERS that poll per tick (query_live_session_endpoints). So NO new IPC query, NO new livehost arm, NO 5th detach path — the ONLY gap is that a controller whose WRITER THREAD died (severed conn: the writer failed a socket write, or a detach dropped by the prior B-1 wedge) still reports controller_by=Some/has_controller=true, so converge keeps the stale stamp. FIX: a broker-side lazy-reap in the KIND_SESSIONS snapshot closure — OutputLog::reap_dead_controller() drops a controller whose _writer.is_finished() BEFORE controller_by/has_controller are read, so the reply + the off-lock converge both see the honest (cleared) state and the stamp clears. LOCK-SAFE: the reap drops the sink in-memory ONLY (no stamp_driven_by → no info.json I/O under the log lock, the KH 7.12/5.16 lock-across-effect discipline); the OFF-lock converge_perch_stamps writes the honest stamp. KH 7.15 held by construction: the reap only ever CLEARS, never latches driven_by; a LIVE (idle, parked-on-rx.recv) controller is is_finished()==false so it is NEVER false-reaped. RESIDUAL (doyle Q2 accepted): a TRULY IDLE severed controller (writer parked on recv, no output, conn not yet EOF'd) stays is_finished()==false and converges only on output-resume / conn-EOF — that harder active-probe case is the RESERVED REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT (SessionInfo.controller_by doc), deliberately NOT built here so the reserved seed keeps its scope. Red-first: a dead-writer sink → reap clears it (controller_by honest None → converge clears the stamp); a live-writer sink → UNTOUCHED (no-false-reap control).
2026-07-17T03:24:38.1603831Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1604194Z 
2026-07-17T03:24:38.1604480Z ### REQ-ADAPTER-FLOOR-ENFORCE
2026-07-17T03:24:38.1614316Z - Title: F-5 (REMOTE-TRUTH triage §F-5 + doyle rulings 2026-07-05): BOTH adapter acquisition verbs (spt adapter add + spt adapter update) REFUSE when the installed spt-core is BELOW the adapter's declared [adapter].min_spt_core_version floor — with an F-1 operator refusal naming the installed core, the floor, and the next action (update spt-core first). ROOT: the floor was PARSED + required (manifest.rs) but never compared to the running core — dead enforcement; and the [update].version_check knob that gated it was DOC'D-BUT-DEAD (never read by any production path — a contract lie). RULINGS: RETIRE version_check (drop the manifest field + schema + docs + the cfg(test) literals; a pre-existing manifest still setting it deserializes fine — serde ignores the unknown key, no deny_unknown_fields, so retiring is back-compatible); SEMVER-compare NOT string-compare (the 0.9.0 < 0.25.0 lexical trap); enforce on BOTH verbs; nothing installs / registry untouched on refuse (binds both verbs, no residuals). FIX: (1) a pure spt-runtime version_meets_floor(core, floor) -> bool (numeric per-component: split '.', u64, missing→0, non-numeric→0, first-diff decides, equal-when-zero-padded ⇒ satisfied) — mirrors the CLI version_is_newer parse (same numeric model, different question: freshness=strictly-newer vs floor=at-least). (2) ADD: the gate lives INSIDE registry::register (the choke point) via a register_with_core(core_version) seam register() delegates to with env!(CARGO_PKG_VERSION) — the floor check runs right after the manifest parse, BEFORE any registry write, returning the typed RegistryError::CoreFloor{adapter,core,floor} (Display = the ONE F-1 refusal both verbs surface); nothing recorded on refuse. (3) UPDATE: a PRE-SWAP peek (staged_floor_ok) extracts the staged .spt to a THROWAWAY temp, parses its manifest floor, and refuses BEFORE apply_release_crc_swap mutates the live pointer-mode home — so a refusal (or an unverifiable floor: FAIL-CLOSED) leaves the live install BYTE-UNTOUCHED; register@8932 stays as the defense-in-depth backstop for every other entry path. doyle bind: the register-only gate would let the crc-swap replace the live files with a floor-violating version while the record refuses (record and reality disagree — the exact contract-lie shape this milestone kills), so the pre-swap peek is the only correct answer. Red-first: perri negative repro on ADD (fresh home + synthetic low core + high-floor manifest → CoreFloor refuse, registry untouched) + the UPDATE pre-swap refuse (live home byte-untouched) + a floor-met positive control (0.25.0-on-0.25.0 installs); + version_meets_floor table incl. the 0.9<0.25 trap.
2026-07-17T03:24:38.1623407Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1623760Z 
2026-07-17T03:24:38.1624036Z ### REQ-RUN-ID-REUSES-ADAPTER
2026-07-17T03:24:38.1629294Z - Title: D-1 (REMOTE-TRUTH triage §D-1): `spt endpoint run --id <id>` with NO --adapter, when <id> names an EXISTING perch, REUSES that perch's recorded info.adapter and runs NON-INTERACTIVELY — instead of always falling to the picker as a create-new prefill (an existing endpoint retyping its own adapter, or being sent to a create-new flow, is the operator wart). ROOT (certain, no design tension): the cli `match (adapter,id)` special-cased only (Some,Some)→cmd_endpoint_run; the catch-all routed EVERY lone --id to crate::picker::run as a create-new prefill, never considering an existing endpoint (cli.rs ~1290). FIX: a PURE resolve_run_target(adapter, id, recorded) over the 4 (adapter?,id?) quadrants — (Some,Some)→Direct{a,id}; (None,Some(id))→ recorded adapter present (info.adapter = adapter-chosen-at-creation, spt-store info.rs:167) → Direct{recorded,id}, absent/no-perch → Picker{None,Some(id)} (today's create-new prefill UNCHANGED); (Some,None)/(None,None)→Picker unchanged. The perch lookup (read_info(resolve_perch_path(id,Infer)).adapter) is INJECTED as a closure so the router is pure + testable without a perch on disk; resume threads into BOTH Direct paths. Red-first: (None,Some(id),recorded=Some) → Direct (pre-fix this routed to Picker create-new). int (live run --id on an existing perch reuses its recorded adapter non-interactively) deferred to the rig.
2026-07-17T03:24:38.1634325Z - Required stages: impl, unit
2026-07-17T03:24:38.1634658Z 
2026-07-17T03:24:38.1634959Z ### REQ-PICKER-PURGE-SHORTCUT
2026-07-17T03:24:38.1639688Z - Title: C-3 (REMOTE-TRUTH triage §C-3 #8): the pick-existing list gains an `x` purge shortcut — on an OFFLINE LOCAL highlight, `x` opens a small in-TUI confirm screen (Screen::ConfirmPurge, the B-2 ChangeAdapterPick shape) and Enter purges via the ONE existing purge core `cmd_endpoint_purge(id, yes=true, force=false)` — NEVER the core's stdin [y/N] (it fights the picker's raw mode; the confirm screen IS the confirm). The shortcut INHERITS both purge gates (offline-only + node-local, cli.rs cmd_endpoint_purge / CONTEXT:189): gated-off presses stay on the list and FLASH WHY (online → offline-only, remote → local-only). force=false is deliberate — the model gate is advisory; the core's own offline check is the authority, and a race to online between gate and purge must REFUSE, never stop-then-purge. After a successful purge the picker STAYS (inline outcome, like Shortcut/ChangeAdapter): the row leaves the in-memory list (remove_endpoint, cursor re-clamped) + flash PURGED:{id}. Hint truth (B-1/F029 discipline): the pick legend renders `x purge` ONLY when purge_key_live() — the same predicate the handler gates on. Red-first: purge outcome reachable ONLY from an offline LOCAL highlight (online/remote → no screen change + why-flash).
2026-07-17T03:24:38.1644149Z - Required stages: impl, unit
2026-07-17T03:24:38.1644490Z 
2026-07-17T03:24:38.1644752Z ### REQ-PICKER-BACK-NAV
2026-07-17T03:24:38.1648291Z - Title: C-4 (REMOTE-TRUTH triage §C-4 #9): Backspace is a back() ALIAS across the picker — one keypress backs out one screen along the SAME reverse map Esc walks (model back(), complete for all screens incl. the C-3 ConfirmPurge), and from the kind layer it cancels the picker (Esc parity) — EXCEPT the two text-edit contexts, where Backspace stays CHAR-DELETE: CreateId entry (id_backspace) and the pick-list filter mode (filter_backspace). DELIBERATE: no empty-buffer fallthrough to back() in the text contexts — mixing delete and nav on one key invites miskeys mid-typing; Esc already backs out (the triage's optional extra, declined). Pure key routing in handle_key (picker/mod.rs) ahead of the per-screen arms; zero model change (the reverse map pre-existed). Red-first: Backspace on Confirm → PickExisting (pre-fix: dead key); on CreateId with a buffer → buffer shortens, screen unchanged; empty buffer → STILL no nav.
2026-07-17T03:24:38.1651774Z - Required stages: impl, unit
2026-07-17T03:24:38.1652107Z 
2026-07-17T03:24:38.1652371Z ### REQ-RC-RECONNECT
2026-07-17T03:24:38.1659372Z - Title: B-3 (REMOTE-TRUTH triage §B-3, the operator-asked UX): the rc attach viewport RECONNECTS on a severed transport instead of print-and-exit. Pre-fix rc was one-shot (resolve→dial→attach→pump→parting line); FAULT-MATRIX row 9 over-promised. FIX: the establish sequence (daemon ensure → broker conn → session resolve local-first/cross-node → dial → attach-open w/ A-4b tracing retry → subscribe) is factored into establish_attach and run_attach_inner wraps establish+pump in a loop. RECONNECTABLE class = severed transport ONLY: PumpEnd::BrokerGone (broker-conn EOF class, broker bounce) + the NEW PumpEnd::Severed (serve-side stream EOF AFTER rendered output = remote conn drop — pre-fix MISLABELED as 'detached — still running'; a nothing-rendered EOF stays the honest NoLiveSession refuse). FINAL ends (Exited/Detached/Displaced/Stalled/NoLiveSession) never re-drive — re-attaching a deliberately-ended session is wrong. On sever: full-screen centered 'Reconnecting to {target}…' banner (pure byte-emit like StatusRow; target = owning-node label or 'local daemon'; Q4 UX rule — operator language, internal sever detail never paints), then re-drive establish_attach every RECONNECT_PAUSE (1s) inside RECONNECT_WINDOW (30s, generous for a daemon bounce); a Detach keypress mid-window aborts honestly to [detached]; window expiry → PumpEnd::ReconnectGaveUp with a plain-language give-up line naming the cause, the window, and the retry action (never op/read-err lingo). Per re-establish: fresh OpMinter (ADR-0034 rc tracing per viewport), fresh initial resize (PTY matches the CURRENT terminal), pump-local render cursor resets so the re-serve ring replay REPAINTS the screen the banner cleared. FAULT-MATRIX row 9 made TRUE (F-3), not edited down. Red-first: serve-EOF-after-render → Severed (vs the pre-fix false Detached); only BrokerGone/Severed classify Reconnect.
2026-07-17T03:24:38.1666081Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1666449Z 
2026-07-17T03:24:38.1666731Z ### REQ-SELF-DETECT-PARENT-PID
2026-07-17T03:24:38.1672889Z - Title: E-1 (REMOTE-TRUTH triage §E-1 #7): self-detect leg (c) — the pid-ancestry fallback — ALSO candidates on `rec.parent_pid` (the harness pid, CONTEXT's 'stable session-binding anchor', stamped at bind), not `rec.pid` alone. ROOT: for an spt-hosted endpoint (broker PTY, headless) `rec.pid` is the ephemeral bind-CLI pid, ALREADY DEAD by send time (the F-026 #11 dead-pid class, field-sighted on hall-bf) — never in any sender's ancestry and alive-gated out — so an spt-hosted sender could NEVER resolve self via leg (c): its messages were from-stamped `cli@NODE` (operator #7) and replies bounced NO_PERCH. FIX: detect_self_by_ancestry pushes a second candidate (id, parent_pid) when `rec.parent_pid` is Some + alive; the pure nearest-first matcher (match_self_by_ancestry) is unchanged. LABEL-ONLY, exactly like the rest of leg (c): from-label/routing default, NEVER authentication — authenticate() untouched, the pid-ancestry-for-auth question stays parked (KH 7.3/7.5 separation holds; a wrong label self-corrects, a wrong grant does not). Env legs (a)/(b) stay first. Red-first int (the triage-specified missing test): rec.pid = dead sibling + rec.parent_pid = genuine live ancestor → self resolves (pre-fix None); ancestry-gate control: live-but-non-ancestor parent_pid must NOT resolve. Rider (same cluster, activated separately once doyle rules the fix shape): F-026 #11 dead-pid itself — rec.pid should hold something that stays true, or liveness readers stop trusting it. Cross-node from-stamp proof (spt-hosted B-side sender arrives at A as `<id>@node`, not `cli@node`) rides the [twohost] rig wave rung.
2026-07-17T03:24:38.1678664Z - Required stages: impl, int
2026-07-17T03:24:38.1679098Z 
2026-07-17T03:24:38.1679376Z ### REQ-HAZARD-DEAD-REC-PID
2026-07-17T03:24:38.1683916Z - Title: E-1 rider (F-026 #11 dead-pid class, doyle-ruled SCOPED 2026-07-05 — KNOWN-HAZARDS 7.34): a dead `rec.pid` on an spt-hosted perch is EXPECTED, not staleness — the recorded pid is the ephemeral bind-CLI pid, which dies immediately after bind (the broker holds the PTY; no resident harness process at that pid). NO reader may alive-gate on `rec.pid` alone: spt-hosted LIVENESS comes from the daemon-managed status field (KH 2.5 — status present ⇒ authoritative, never a per-pid probe); IDENTITY comes from session/ancestry resolution where `rec.parent_pid` (the harness pid, the stable session-binding anchor) is the ancestry candidate (REQ-SELF-DETECT-PARENT-PID). Re-stamping rec.pid with the harness pid (shape (a)) is OVERRULED: ADR-0021 demoted pid to a bind-time seed hint (re-anchoring truth there reverses the design); every pre-existing record keeps the old CLI pid so readers need the scoped discipline anyway (migration hole); blast radius (every rec.pid consumer + KH 2.5 external-perch probe semantics) buys nothing the reader-side fix doesn't. CLASS rule: any newly sighted rec.pid-alive-gating reader gets the same scoped fix and EXTENDS this requirement's evidence — no new REQ per reader.
2026-07-17T03:24:38.1688408Z - Required stages: doc, int
2026-07-17T03:24:38.1688776Z 
2026-07-17T03:24:38.1689139Z ### REQ-SOFT-END-PRESERVES-LIVE-LISTENER
2026-07-17T03:24:38.1695868Z - Title: F-2 (REMOTE-TRUTH triage §F-2, field-repro'd hall-bf 2026-07-04): a /clear must not sever a SURVIVING poll listener's relay address — post-clear owl-path send hit NO_PERCH while ready was present and the inject path healthy. ROOT (source-certain): the relay registry row (id→addr + owning pid, registered by the LISTENER process itself at PollListener::bind, listener.rs:109) is DELETED by the adapter's soft `api session-end` (reporting.rs:231) fired for the DEPARTING session at /clear; but the poll listener SURVIVES /clear (a session-independent process, still bound on its port), so the deletion destroys a TRUE row. The C-2 boundary re-stamp (REQ-HAZARD-BOUNDARY-READY-STRAND) restores ready + status online but CANNOT re-register — only the listener process knows its socket addr — so every subsequent send lookup misses → NO_PERCH forever (until a listener restart re-binds). FIX: the SOFT arm of cmd_session_end unregisters CONDITIONALLY through the single liveness resolver (liveness::is_registry_entry_alive — the KH 2.5-aware resolver clean_stale_entries routes through): a row whose owner is still ALIVE is PRESERVED (the row is LISTENER-scoped truth, not session-scoped; the listener outliving /clear is the designed shape), a dead/offline row is removed (today's cleanup kept). The ERASE arm stays unconditional (a hard wipe orphans any listener; its row dies with the endpoint). Every legitimate teardown keeps its OWN unregister untouched: PollListener close/close_busy/Drop (listener.rs) and the stop verbs (cli.rs:5574/:10924). Defense-in-depth unchanged: a wrongly-preserved dead row still self-heals at delivery (deliver.rs failed-dial sweep, REQ-HAZARD-REGISTRY-STALE-CLEAN). Red-first: soft session-end with a live registered owner → row survives and lookup still resolves (pre-fix: deleted → NO_PERCH).
2026-07-17T03:24:38.1702506Z - Required stages: impl, unit
2026-07-17T03:24:38.1702857Z 
2026-07-17T03:24:38.1703172Z ### REQ-PUBLIC-ERROR-SURFACES
2026-07-17T03:24:38.1708923Z - Title: F-1 (REMOTE-TRUTH triage §F-1, Q4 UX rule, operator-ruled): CLI stderr a non-developer can hit names the OBSERVABLE SITUATION + the NEXT ACTION — never journal/op/brain/store lingo. The sweep's named offenders: (1) `RC_FAIL:{id}: … brain IPC read deadline elapsed` — the brain transport error surfaced RAW through rc's residual Err arm (rc.rs run_attach_inner); operators read 'brain IPC' where the situation is 'the daemon didn't answer in time'. (2) `WOKE_FAIL:{id}: info.json absent or unreadable — not a hosted perch` (resting.rs apply_event miss) — store-file lingo in the one rest-verb line a stale remote row still surfaces cross-node (the qualified-arm D6 case; the A-3 bare-id local path already routes instead). The miss stays SINGLE-SOURCED from NOT_A_HOSTED_PERCH_MARKER (in-process discriminant, resting.rs — reword is compat-safe per its own doc; the drift-pin unit keeps builder+matcher fused). (3) translation_fault never human-rendered (F-030 post-release seed): a broker-stamped input-translation fault (e.g. 'inject worker panicked') was invisible in `endpoint list`/`whoami` while keystrokes silently degraded — rendered now as a SELF-pin annotation exactly like the psyche_host_error pattern (REQ-HAZARD-LIVEHOST-BOOT-RACE), human line + additive skip-if-none JSON field. Kin to banked patterns: public --help no internal codes; 'Updated' not 'trial'. The A-4b retry terminal + B-3 give-up line + A-3 routing strings shipped F-1-clean already — this REQ sweeps the stragglers and is the home for future sightings (extend, don't multiply).
2026-07-17T03:24:38.1714710Z - Required stages: impl, unit
2026-07-17T03:24:38.1715044Z 
2026-07-17T03:24:38.1715340Z ### REQ-WORKER-SID-SYMMETRIC-AUTH
2026-07-17T03:24:38.1718858Z - Title: W-2 (WORKER-TRUTH triage, operator-ruled 2026-07-06): worker verbs go sid-symmetric with every sibling id-scoped verb — worker-start mints NO token and worker-stop takes NONE (token custody is undue adapter burden, ruling via perri). Registration STORES the sid it authenticated (the parent's sid at start; today cmd_worker_start hardcodes session_id="" — worker.rs:44 — so a sid-authed stop compares against empty and refuses 100%). Stop accepts the parent's CURRENT sid OR the stored registration sid (a /clear between start and stop rotates the parent's sid; either rotation endpoint is honest custody — the REQ-PSYCHE-SID-CUSTODY rotation reasoning). Under the ruling the field adapter's existing emission (worker-stop <id> --session-id <parent sid>) becomes contract-correct as-is. Publish the frozen verb shape to the docs-site with the landing wave (perri blind-builds from published docs).
2026-07-17T03:24:38.1722179Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1722541Z 
2026-07-17T03:24:38.1722800Z ### REQ-WORKER-REAP
2026-07-17T03:24:38.1726353Z - Title: W-3 (WORKER-TRUTH triage): worker records must not persist indefinitely past their useful life — 6 dead-pid workers leaked OFFLINE on flynn (kill-paths where SubagentStop never fires: parent killed, abort, timeout). The stored rec.pid is the ephemeral worker-start hook process (dead by design — the REQ-HAZARD-DEAD-REC-PID class; NEVER an alive-gate signal). Honest reap signals: (a) parent-session lifecycle — reap the parent's soft-stopped + orphaned workers at parent session-end/boundary and on parent-death detection (a worker cannot outlive its parent's live session); (b) a generous TTL floor since `created` as belt-and-braces. Soft-stop preservation semantics (REQ-HAZARD-SOFT-CLEANUP: results drain before reap) stay honored — reap after drain-or-expiry, never mid-flight hard-delete (cascade-wipe guard rationale stands). Sister shape: claude_skill_owl doctor D-21 orphan-worker GC.
2026-07-17T03:24:38.1729728Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1730072Z 
2026-07-17T03:24:38.1730353Z ### REQ-WORKER-LIST-VISIBILITY
2026-07-17T03:24:38.1732925Z - Title: V-1 (WORKER-TRUTH triage, operator rider): worker perches leave the DEFAULT `spt endpoint list` view — they are process-local machinery, not subnet citizens; leaked-or-live worker rows rendering as permanent OFFLINE endpoints is the operator-visible symptom root. A dedicated flag (--workers) reveals them (one command + flag per the --all/--detail precedent, NOT a separate list-working command — sister divergence deliberate). Applies to the human render, --json (additive default-absent filter), and the registry/projection legs; verify-and-stop any worker gossip into the subnet registry as peer endpoints.
2026-07-17T03:24:38.1735419Z - Required stages: impl, int
2026-07-17T03:24:38.1735758Z 
2026-07-17T03:24:38.1736040Z ### REQ-WORKER-PICKER-EXCLUDED
2026-07-17T03:24:38.1737951Z - Title: V-2 (WORKER-TRUTH triage, operator rider): non-drivable endpoint classes never render as `spt endpoint run` picker rows — a worker perch cannot be driven, instantiated, or controlled; offering it is a lie the picker then fails on. Filter endpoint_type worker (and the psyche class if it ever surfaces — same non-drivable family) at every picker source leg, extend-not-multiply for future non-drivable classes.
2026-07-17T03:24:38.1739813Z - Required stages: impl, unit
2026-07-17T03:24:38.1740179Z 
2026-07-17T03:24:38.1740461Z ### REQ-WORKER-MINTED-NAME
2026-07-17T03:24:38.1742774Z - Title: N-1 (WORKER-TRUTH triage, operator rider): worker perch identity is CORE-MINTED and parent-derived — `{parent}-w{N}` with a per-parent counter at registration (sister shape: claude_skill_owl hook_subagent_start.rs) — never the adapter-presented agent id (CC Task ids render as random-named rows). worker-start mints + echoes the id (WORKER_STARTED:{parent}-w{N}); the adapter's agent_id/agent_type ride the record as correlation METADATA, not identity. Verb-shape contract change — freeze with W-2 in ONE coordination with perri.
2026-07-17T03:24:38.1744951Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1745317Z 
2026-07-17T03:24:38.1745595Z ### REQ-ADAPTER-TEMPLATE-KEY-VALIDATION
2026-07-17T03:24:38.1748631Z - Title: P-1 core half (WORKER-TRUTH triage): `adapter add`/`adapter update` validate every declared role template — command, cwd, and [env] inject values — against the substitution-key catalog (spt-runtime BASE_KEYS + role-specific overrides) and REFUSE registration naming the offending key + role (fail-fast family of the [strings] pointer validation). Field driver: flynn's psyche died on the RETIRED {psyche_dir} key (adapter psyche_resume carried the old psyche_init cwd shape) — a permanent template config fault must die loudly at registration, not at the Nth per-event psyche turn via the 3-strike budget. The catalog stays the single source (runtime.rs FILL_KEYS — 'a catalog key must have a real fill'); validation reads it, never a second list.
2026-07-17T03:24:38.1751556Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1751899Z 
2026-07-17T03:24:38.1752181Z ### REQ-PSYCHE-SPAWN-ENV-PARITY
2026-07-17T03:24:38.1756636Z - Title: P-2 (WORKER-TRUTH triage addendum, perri-filed field finding 2026-07-06): the per-event psyche_resume spawn threads the perch record's CAPTURED read_env stamps into the spawn ENVIRONMENT — the F-027 Half-B env-parity contract (BINDING, design-frozen: read_env captured at creation + stamped on the record + threaded IDENTICALLY to every session spawn; the spawn never reads its own process env for a stamped var) extended to the psyche role the design predates. Field driver: flynn (claude-spt:ccs) — the ccs wrapper relocates the account root via CLAUDE_CONFIG_DIR at PARENT launch and the perch record correctly captured it, but the daemon spawns psyche_resume with bare env → default ~/.claude root → headless 'Not logged in' exit-1 → strike loop; psyche + parent land in DIFFERENT account roots (auth AND root-scoped continuity both break). Core stays harness-agnostic (threads whatever [env] direction=read captured — knows nothing of CLAUDE_CONFIG_DIR). Scope note: this is the URGENT psyche leg of F-027 Half B; the full pre_spawn seam + endpoint-session env threading stays design-parked (F-027-ENDPOINT-SPAWN-FAIL-DESIGN.md) unless operator pulls it forward.
2026-07-17T03:24:38.1761123Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1761462Z 
2026-07-17T03:24:38.1761723Z ### REQ-PAIR-NTP-MULTIHOME
2026-07-17T03:24:38.1765472Z - Title: W1/D1 (JOIN-TRUTH): the ceremony NTP query reaches a server on EITHER IP family — `query_unix_secs` (ntp.rs) must iterate every address `to_socket_addrs()` resolves (not just the first) and bind a socket of the matching family per candidate (IPv4 addr → bind 0.0.0.0:0; IPv6 addr → bind [::]:0), first successful answer wins. ROOT (proven 3/3-FAIL via our exact code on enlyzeam): today `UdpSocket::bind(("0.0.0.0",0))` is v4-only and `send_to(&packet, server)` sends ONLY to the FIRST resolved addr — time.google.com resolves 4×AAAA before any A on a v6-first dual-stack box → the primary server is PERMANENTLY unreachable via our code (w32tm reaches it over v6), silently halving NTP redundancy (pool.ntp.org v4 carried everything; a DNS rotation making BOTH v6-first would zero it). Fix keeps the lazy-cache/TTL/fallback contract of REQ-PAIR-8 unchanged — only the socket/resolve leg changes.
2026-07-17T03:24:38.1768754Z - Required stages: impl, unit
2026-07-17T03:24:38.1769184Z 
2026-07-17T03:24:38.1769460Z ### REQ-PAIR-NTP-LOUD-FAIL
2026-07-17T03:24:38.1772437Z - Title: W1/D2 (JOIN-TRUTH): total NTP failure (no server on any family answered) is LOUD, not silent — a node running the ceremony on its raw skewed system clock must be visible. ROOT: current_offset_secs (ntp.rs) does `query_offset_secs().unwrap_or(0)` and eprintln's ONLY on a nonzero success, so an all-servers-unreachable refresh is indistinguishable from 'clock agrees'. Fix: log the TRANSITION into all-servers-failed once per refresh (suggested `NTP_TOTP_UNCORRECTED: all NTP servers unreachable — ceremony clock = raw system clock`) and the recovery transition back to corrected; the OFFSET_TTL already bounds refresh cadence so no per-call spam. Fallback behavior (offset 0 → system clock) is UNCHANGED — this adds observability only.
2026-07-17T03:24:38.1775437Z - Required stages: impl, unit
2026-07-17T03:24:38.1775819Z 
2026-07-17T03:24:38.1776129Z ### REQ-HAZARD-CEREMONY-CLOCK-STEP
2026-07-17T03:24:38.1779877Z - Title: W1/D3 (JOIN-TRUTH, KNOWN-HAZARDS): the cached ceremony offset goes stale-WRONG when the OS clock STEPS under a live daemon — an offset measured against the OLD clock keeps applying for up to the 15-min TTL. Field-proven timeline (enlyzeam): refresh cadence 15:08/15:23/15:38/15:53; operator `w32tm /resync` stepped the clock −210s at 15:45:46; every `subnet join` returned NO_SEED_HOLDER until a daemon bounce forced a fresh query. Fix: the cache snapshot stores an (Instant, SystemTime) PAIR; on read, if |wall-elapsed − mono-elapsed| > ~2s the clock stepped ⇒ force an immediate refresh (offset recomputed against the new clock). PLUS: `meet_seed_holder` (pairhost.rs), on search-deadline exhaustion, forces ONE fresh NTP refresh + one final sweep before returning NO_SEED_HOLDER — so a stepped-clock join self-heals without a bounce. Clock reads must be seam-injectable for the hazard unit (inject the (mono,wall) pair — do NOT sleep 15 min).
2026-07-17T03:24:38.1783202Z - Required stages: impl, unit
2026-07-17T03:24:38.1783551Z 
2026-07-17T03:24:38.1783827Z ### REQ-JOIN-VERBOSE-CLOCK
2026-07-17T03:24:38.1786888Z - Title: W2/D4 (JOIN-TRUTH): the JOINER side is no longer blind to its own ceremony clock — `spt subnet join --verbose` prints the joiner's derived TOTP step, the applied offset seconds, and the NTP correction state (corrected / uncorrected) per meet sweep; the same triple folds into `meet_failure_detail` so the NO_SEED_HOLDER verbose block carries it. ROOT: diagnosing enlyzeam required shipping a compiled probe over ssh because the member logs PAIR_MEET_UP step=N but the joiner surfaces nothing about its OWN step/offset — the exact asymmetry that hid D1-D3. Extends REQ-JOIN-DIAGNOSTICS's --verbose without a new knob. CLI help changes → xtask docs gen, no internal REQ codes in clap /// (docs-token gate).
2026-07-17T03:24:38.1789586Z - Required stages: impl, unit
2026-07-17T03:24:38.1789926Z 
2026-07-17T03:24:38.1790203Z ### REQ-JOIN-DEFERRED-ELEVATION
2026-07-17T03:24:38.1794464Z - Title: W2 (JOIN-TRUTH, operator UX ruling verbatim): 'if --code was not supplied, don't spawn the elevated subnet-join window until a target machine is discovered → just in time for the code prompt.' When --code is ABSENT and the process is UNELEVATED, run the name prompt + ALREADY_MEMBER check + ensure_daemon + the MEET phase (brain.pair_meet) UNELEVATED; only on MetMember spawn the elevated window via the EXISTING try_auto_elevate machinery (the elevated re-run re-executes the join flow — its second meet is cheap, the member is proven present). A FAILED search must NEVER show a UAC/sudo/pkexec prompt. The --code path is UNCHANGED (gate-first, one-shot). The unelevated phase performs ZERO trust mutation — meet is pre-trust per REQ-JOIN-TWO-PHASE/ADR-0030. RULED OUT (doyle): cross-elevation hold-session adoption (passing the daemon-held pair session_id into the elevated process) — a new security seam we don't need; the elevated re-run re-meets instead. The elevation gate MOVES from command-entry to the enrollment boundary; discovery is read-only pre-trust.
2026-07-17T03:24:38.1798743Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.1799186Z 
2026-07-17T03:24:38.1799477Z ### REQ-ECHO-DROP-DIR-RESOLVE
2026-07-17T03:24:38.1803291Z - Title: W1 (LIFECYCLE-TRUTH): fire_echo resolves the manifest commune_dir through the SAME resolver its siblings use before any write. ROOT (pinned): fire_echo (spt-daemon lifecycle.rs:790) passes the RAW manifest commune_dir into run_echo_commune -> echo.rs:115-117 create_dir_all+join; a relative `.claude` under the WMI-launched daemon's System32 cwd = os error 5 deterministic (two live psyches stamped FAILED on it). Siblings already resolve correctly (ingest ~:583, psyche_drop_file :1072 via resolve_endpoint_drop_dir(raw, cwd)). FIX: fire_echo routes through resolve_endpoint_drop_dir; relative-with-no-cwd = SKIP LOUD (stderr), never a raw relative write — kills the latent-worse variant where a writable daemon cwd writes the drop to a WRONG dir silently (echo communes lost, no error). Hardening riders (same touch, no separate REQ): bounded EACCES retry on the drop write; echo claude spawn gets explicit cwd = endpoint cwd (perri ask).
2026-07-17T03:24:38.1806594Z - Required stages: impl, unit
2026-07-17T03:24:38.1806947Z 
2026-07-17T03:24:38.1807247Z ### REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS
2026-07-17T03:24:38.1809260Z - Title: W1 (LIFECYCLE-TRUTH): EVERY successful psyche operation clears psyche_host_error — not just the pulse-loop leg. ROOT (three field confirmations, perri): the stamp clears only via note_turn_outcome's Ok leg (lifecycle.rs:1101); a SUCCESSFUL psyche op via checkpoint/wake bypasses it -> stale FAILED stamp sits over a healthy psyche. FIX: event turn, checkpoint/wake synthesis, and signoff echo all clear the stamp on success.
2026-07-17T03:24:38.1811018Z - Required stages: impl, unit
2026-07-17T03:24:38.1811357Z 
2026-07-17T03:24:38.1811642Z ### REQ-PSYCHE-ROLE-OPTIONAL-SKIP
2026-07-17T03:24:38.1813485Z - Title: W1 (LIFECYCLE-TRUTH): a manifest with NO [session.echo_commune] role SKIPS commune-sync (debug-level note, no strike) instead of hard-failing the turn. ROOT (perri filing, recovered): missing role -> commune-sync hard-fails -> 3-strike stamps the host ('manifest declares no [session.echo_commune] role') while the published contract presents the role as an optional template. FIX: missing OPTIONAL role = skip, not a turn failure.
2026-07-17T03:24:38.1815274Z - Required stages: impl, unit
2026-07-17T03:24:38.1815650Z 
2026-07-17T03:24:38.1815942Z ### REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE
2026-07-17T03:24:38.1821217Z - Title: W2 (LIFECYCLE-TRUTH, KNOWN-HAZARDS, flagship — the update wedge): PTY viewer fan-out and control mutations must not depend synchronously on a live draining brain. ROOT rig-CONFIRMED (NtSuspendProcess on the brain, no update involved): brain-subscriber session-output writes ride UNDER the per-session log lock (broker.rs:19-20); failed writes are handled (cursor freeze + detach :3486) but BLOCKED writes are not. Suspended brain => within seconds attached rc output freezes; detach does NOT release the control stamp (release routes through the brain); reattach REFUSED (controlled-by); rc --take hangs; daemon status stays healthy. Field: every brain cycle (incl. every update apply) has a freeze window; a stalled/slow-draining new brain = permanent wedge until bounce; brain.ready != subscribers drained. FIX SHAPE (todlando proposes, doyle RULES BEFORE IMPL): subscriber writes move OFF the log lock (bounded/nonblocking, stall => detach-subscriber like viewer eviction — broker already buffers + replays on re-attach, so a detached-stalled brain self-heals by rewind); control stamp release/take completes against the BROKER without brain round-trip (or bounded with loud timeout). doc = KNOWN-HAZARDS entry. Int (tonight's rig, encoded): suspend brain child mid-session -> attached viewer ticks CONTINUE + rc --take completes; resume -> no output lost (cursor replay).
2026-07-17T03:24:38.1826306Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.1826666Z 
2026-07-17T03:24:38.1826960Z ### REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL
2026-07-17T03:24:38.1829446Z - Title: W3 (LIFECYCLE-TRUTH): daemon restart no longer massacres hosted endpoints — daemon start RE-RUNS previously-online spt-hosted endpoints. ROOT rig-proven: daemon stop+start (the apply notice's OWN instruction) kills every hosted endpoint; they stay OFFLINE after start (no resurrection) though records exist (info.json status + adapter + cwd). SCOPE RULING (doyle): re-run-on-start, marked start-reason=daemon-restart; agents' minds ride psyche re-host as today. Int: endpoint online -> daemon stop -> start -> endpoint back ONLINE, same id, harness respawned.
2026-07-17T03:24:38.1831768Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1832105Z 
2026-07-17T03:24:38.1832386Z ### REQ-UPDATE-ONE-SHOT-FINISH
2026-07-17T03:24:38.1834825Z - Title: W3 (LIFECYCLE-TRUTH): update apply works daemonless and one command finishes the cycle. ROOT (operator wart): update fetch/apply run ensure_daemon_announced (cli.rs:4386) -> on a stopped box they BOOT THE OLD broker pre-swap, guaranteeing the mixed old-broker/new-brain pair + a manual bounce. FIX: apply works daemonless (swap + record, next start runs new bytes); `update apply --finish` (name subject to docs-token gate) completes the cycle: swap -> brain cycle -> broker restart onto new bytes (rides REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL so the restart is not a massacre). CLI change -> xtask docs gen, no internal codes in clap ///.
2026-07-17T03:24:38.1837293Z - Required stages: impl, unit
2026-07-17T03:24:38.1837630Z 
2026-07-17T03:24:38.1837916Z ### REQ-DAEMON-STOP-LIVE-SESSION-WARN
2026-07-17T03:24:38.1839084Z - Title: W3 (LIFECYCLE-TRUTH, promoted old follow-wave seed): `daemon stop` with live hosted sessions warns + requires --force (or names the sessions it will kill) instead of silently killing them.
2026-07-17T03:24:38.1840134Z - Required stages: impl, unit
2026-07-17T03:24:38.1840473Z 
2026-07-17T03:24:38.1840735Z ### REQ-RC-RECONNECT-TRUTH
2026-07-17T03:24:38.1843171Z - Title: W3 (LIFECYCLE-TRUTH): rc reconnect never auto-starts a daemon and never hangs forever. ROOTS rig-proven (the operator's long-standing 'stop 2-4 times' bug): (a) an rc client's reconnect loop AUTO-LAUNCHES a daemon via WMI (rig: DAEMON_LAUNCH_VIA_WMI from the rc) — resurrection fights the operator's stops; (b) rc freezes at 'Reconnecting to local daemon…' forever when its session died with the broker. FIX: rc NEVER auto-starts a daemon (reconnect only to an already-up broker; loud 'session lost — daemon down' exit otherwise), bounded reconnect with visible countdown.
2026-07-17T03:24:38.1845357Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1845700Z 
2026-07-17T03:24:38.1845992Z ### REQ-DAEMON-STDERR-PERSIST
2026-07-17T03:24:38.1847902Z - Title: W3 (LIFECYCLE-TRUTH, observability): broker + brain stderr tee to a rotating size-capped file under SPT_HOME (e.g. 2x5MB), stamped per generation. ROOT: detached daemon nulls stdio -> the 2026-07-06/07 incident window left ZERO logs (both RCAs ran blind; rigs had to recreate everything). KNOWN-HAZARDS note: never inherit handles (REQ-HAZARD-DETACHED-DAEMON-STDIO) — open the file in-process, don't pipe.
2026-07-17T03:24:38.1849916Z - Required stages: impl, unit
2026-07-17T03:24:38.1850254Z 
2026-07-17T03:24:38.1850529Z ### REQ-UPDATE-PROMOTE-DRAINED
2026-07-17T03:24:38.1855038Z - Title: W3 (LIFECYCLE-TRUTH, mechanic-d MOVED FROM W2 per doyle gate verdict @e5ae7a9 — binding): the update-apply brain-generation promotion completes only when the OLD generation's broker subscriber connection is CLOSED or stall-EVICTED — never while blocked writes still pend on it. ROOT: `brain.ready` != subscribers drained; W2's stall-evict (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE) only BOUNDS the false-promote window to BRAIN_WRITE_DEADLINE (15s), it does NOT close it — a new brain can signal ready inside that window while the old gen's conn is still wedged, so the apply 'promotes' onto a still-frozen control plane (the 22:47 incident-night false-promote). FIX: the promotion gate (ADR-0018 brain-trial, brainproc.rs) adds an explicit DRAINED precondition — promote only on ready AND old-gen-subscriber-drained (conn closed OR stall-evicted); the drained signal reads broker truth (the W2 stall-evict tally / the old conn's liveness), no brain round-trip. The residual W2 left open, now closed. Int = a FALSE-PROMOTE rig that exercises the promotion path itself: an old-gen subscriber conn held wedged past ready must NOT promote until it drains (RED-first: ready-alone promotes).
2026-07-17T03:24:38.1859690Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1860034Z 
2026-07-17T03:24:38.1860320Z ### REQ-UPDATE-TRIAL-DRAIN-DRIVE
2026-07-17T03:24:38.1873570Z - Title: UPDATE-WEDGE (counter-54, doyle-ruled 2026-07-09 — regression of the v0.29.0 seamless brain-swap): a brain generation DRIVES the broker's controller-liveness reap (a KIND_SESSIONS poll) each heartbeat throughout its boot/trial loop, so a hard-KILLED prior generation's black-holed LOCAL controller conn (by:None) is stall-evicted within the trial window and can never permanently strand the promotion DRAINED gate. ROOT (2026-07-09 field freeze, `spt update fetch --apply` v0.30.0->v0.30.2 froze all 7 live PTYs ~30s then rolled back): the promote gate (run_trial, brainproc.rs:657-661) needs BOTH `ready_generation==gen` AND `old_gen_drained()`; `old_gen_drained()` = `!any_local_controller_wedged()` (brainproc.rs:534) is a PURE READ of `write_blocked_since` (broker.rs:2703) — it never DRIVES the evict. The evict (`stall_evict_controller`, broker.rs:1039, same 15s `brain_write_deadline` the wedge-read uses) only runs via `reap_dead_controller` (broker.rs:967, severed->drop ELSE stall-evict) inside the KIND_SESSIONS snapshot closure (broker.rs:2879). During the isolated brain-trial window NOTHING polls KIND_SESSIONS: the old brain was hard-killed (`child.kill()`, brainproc.rs:851) so its local controller conn black-holes (live PTYs keep writing to a dead Windows named pipe -> writer BLOCKS, never EOFs) -> `write_blocked_since=Some` -> wedged=true for the full 30s -> gate false -> `WindowElapsedAlive` -> kill+rollback. The candidate DID reach ready (write_ready, brainproc.rs:211, runs before the loop; the v53 log's NET_FAMILY_GATE/PAIR_MEET_UP prove the loop was entered) — so `BRAIN_TRIAL_TIMEOUT: candidate alive but never ready` is the MISLEADING ready-stamped-but-never-DRAINED case, NOT a resume_sessions hang. SECOND LEG (recovery): post-rollback the gen-2 brain's KIND_SESSIONS poll finally reaps -> `BRAIN_SUBSCRIBER_STALL_EVICT:1` fires >15s late -> a session stayed black-holed through recovery -> continued freeze. ONE root, BOTH legs. FIX (BRAIN-SIDE, self-applying — doyle ruled brain-side to AVOID a broker-side coordinated-restart flag): the boot/trial heartbeat loop (brainproc.rs run_brain, currently only `net_status` at :244) also issues `Brain::sessions()` (KIND_SESSIONS, brain.rs:1397 — already exists) every heartbeat, driving the LIVE older broker's ALREADY-SHIPPED reap (>=v0.29.0 LIFECYCLE-TRUTH; the field-stuck broker is v0.30.0 so it HAS it). The old-gen wedged conn is stall-evicted ~15s < the 30s window -> `old_gen_drained()` flips true -> PROMOTE; the same poll on the rollback/recovery brain reaps promptly -> no >15s black-hole -> kills the STALL_EVICT recovery leg. Drive it on the FIRST heartbeat (no one-tick wait) and on BOTH the trial candidate AND the recovery brain (one loop covers both). SELF-APPLIES because it drives the current broker's existing reap verb — v54's brain fixes the v0.30.0->v54 update with NO coordinated broker restart. Forward-compat: brokers <v0.29.0 have neither the DRAINED gate nor the reap, so older-broker updates never hit this path — no regression. Composes with REQ-UPDATE-PROMOTE-DRAINED (the gate this un-strands) + REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict it drives) + REQ-CONTROLLER-LIVENESS-REAP (the reap verb). Int = the brain-swap-under-live-sessions rig: (1) with a hard-killed prior gen holding a wedged by:None controller past 15s, the new brain PROMOTES within the window AND sessions stay served across the cycle (RED-first: without the drive, WindowElapsedAlive->rollback); (2) a deliberately-failing trial auto-rolls-back AND the restored brain re-drives EVERY session with NO BRAIN_SUBSCRIBER_STALL_EVICT.
2026-07-17T03:24:38.1885617Z - Required stages: doc, impl, int
2026-07-17T03:24:38.1885990Z 
2026-07-17T03:24:38.1886305Z ### REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE
2026-07-17T03:24:38.1894247Z - Title: SEED (DEFERRED, doyle 2026-07-09 — post-counter-54 root-hardening for UPDATE-WEDGE; mint now, impl a FUTURE milestone): on a PLANNED brain-restart (`BRAIN_UPDATE_RESTART`, the seamless update-apply brain-cycle), the outgoing brain's LOCAL (by:None) controller conns are GRACEFULLY CLEAN-CLOSED as the brain is cycled, instead of hard-killed and left to black-hole. ROOT (field-pinned 2026-07-09, daemon.stderr.log L24277-24303): the update-restart path hard-kills the outgoing brain (`child.kill()`, brainproc.rs:851); its live-agent controller conns then block on dead pipes (never EOF) → the broker reads them WEDGED (broker.rs:2695-2700) → the new candidate's promotion DRAINED gate (`any_local_controller_wedged`, broker.rs:2704) stays true until the W2 stall-evict matures (~15s). REQ-UPDATE-TRIAL-DRAIN-DRIVE (counter-54) makes the candidate DRIVE that reap so it promotes within the 30s window — but at a ~15s wedge-maturity hitch (frozen PTYs during the swap). A CLEAN close makes the conn 'simply absent → drained=false AT ONCE → fast promote' (broker.rs:2699-2700), ELIMINATING the hitch = truly seamless (honors the paradigm the field freeze broke). SUPERSEDES the earlier livehost-reattach framing of 'Fix Y': livehost is SPAWN-FRESH (fresh session uuid/pid per boot, nothing to re-attach — wrong site, and it never ran in the trial window); the correct site is the brain-cycle / update-restart path (a bounded graceful-drain of the outgoing brain BEFORE the kill). Non-trivial: hard-kill → bounded graceful drain; a drain that hangs must NOT wedge the swap (timeout then kill anyway, never block the update). Composes with REQ-UPDATE-TRIAL-DRAIN-DRIVE (defense-in-depth reap-drive REMAINS for any conn that still black-holes — a peer/relay conn, a drain-timeout kill) + REQ-UPDATE-PROMOTE-DRAINED (the gate) + REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict). Int: a planned update-restart under a live-agent controller conn → the new candidate promotes WITHOUT waiting the ~15s wedge-maturity (drained reads false immediately, no STALL_EVICT), RED-first vs the current hard-kill-then-reap-drive ~15s hitch.
2026-07-17T03:24:38.1901721Z - Required stages: 
2026-07-17T03:24:38.1902054Z 
2026-07-17T03:24:38.1902360Z ### REQ-LIVEHOST-RECONCILE-TRIAL-SILENT
2026-07-17T03:24:38.1908522Z - Title: SEED (DEFERRED investigation, doyle 2026-07-09 — UPDATE-WEDGE follow-up): determine WHY the trial/rollback brain's livehost reconcile loop did NOT drive the broker controller-reap (nor re-host the live agents) during the ~30s field update-trial window, when livehost polls `query_live_session_endpoints()` → `brain.sessions()` (KIND_SESSIONS) UNCONDITIONALLY every `LIVE_RECONCILE_INTERVAL_MS`=5000ms (livehost.rs:1026). CONTEXT (surfaced building the counter-54 rig): livehost's 5s KIND_SESSIONS poll drives the SAME broker `reap_dead_controller` sweep the fix drives — so it would otherwise reap the 15s-matured wedge by ~T20 < the 30s trial and SELF-HEAL. It didn't (field froze 30s → rollback), so the field trial-brain livehost was silent/delayed (PIN Q2: no `DAEMON_RESTART_RESUME` under gen-1/gen-2; the 30s kill landed before/around livehost's first reconcile tick). The counter-54 fix (REQ-UPDATE-TRIAL-DRAIN-DRIVE) puts a RELIABLE 500ms reap-driver in run_brain's CORE heartbeat loop, making the wedge-reap INDEPENDENT of livehost — so this does NOT block counter-54. But the livehost silence is a latent anomaly with a SECOND consequence: live-agent HARNESS re-hosting was also delayed ~30s (a separate freeze contributor). Investigate: does `spawn_live_host`'s reconcile thread start promptly on a trial-brain boot, or is its first tick delayed past the trial window? Does its brain conn / `query_live_session_endpoints` block against the swap/wedge state? Register concrete REQ(s) once the mechanism is pinned. RELATED: [[REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE]] (if the outgoing brain's black-holed conns perturb the new brain's livehost conn setup).
2026-07-17T03:24:38.1914571Z - Required stages: 
2026-07-17T03:24:38.1914938Z 
2026-07-17T03:24:38.1915224Z ### REQ-BRAIN-RESUME-NO-CONTROL-STEAL
2026-07-17T03:24:38.1928921Z - Title: UPDATE-WEDGE round 2 (v0.30.4, doyle-ruled 2026-07-09 — field incident on the counter-54 fetch--apply): a brain-respawn must NEVER steal, then stall-evict, the controller of a broker PTY session the daemon brain does not DRIVE. ROOT (field-pinned + SME, docs/UPDATE-WEDGE-2-RCA.md + docs/UPDATE-WEDGE-2-SME-todlando.md): `resume_sessions` (brain.rs:985) re-attaches EVERY session `KIND_SESSIONS` returns via `subscribe` = `subscribe_with(AttachIntent::Control, by:None)` (brain.rs:1450-1455). The docstring's 'a None identity never displaces (falls back to viewer)' is a MYTH for FREE / SAME-LOCAL-IDENTITY slots: `resolve_subscribe` (broker.rs:1134-1153) stall-evicts FIRST, then `become_controller` if the slot is now free OR the incumbent is also local (None==None) — viewer-fallback fires ONLY when a DIFFERENT REMOTE controls. So on a box with N spt-hosted broker PTYs, a brain-respawn STEALS the by:None controller of every free/local-controlled session (incl. the operator's LOCAL `spt rc`), which the daemon brain never drains (it hosts no PTY sessions — brainproc.rs:184) → 15s later `stall_evict_controller` (broker.rs:1039) releases driven_by → the session is UNCONTROLLABLE (Failure A). It also head-of-line-blocks the shared brain↔broker conn on the N-session controller-replay burst → every journaled `spt rc` retake deadlines ('brain IPC read deadline', the REQ-BROKER-ATTACH-JOURNAL-RESILIENT / #16 shared-conn symptom) → global rc failure on ALL N (Failure B). Field 2026-07-09 (operator-confirmed): fetch--apply 0.30.2→0.30.3 PROMOTED CLEANLY (the counter-54 fix worked) but under 7 spt-hosted PTYs (ALL with LOCAL by:None controllers) the resume SILENTLY STOLE all 7 (become_controller same-local re-take, NO Displaced notice → orphaned, output froze immediately, no rc-detach splash) + blocked every rc retake. The 5-vs-2 stall-evict split is ACTIVE-vs-IDLE, not remote-vs-local: 5 producing output → stolen writer blocked >15s → stall-evict; 2 idle → writer parked → no evict, but still silently stolen+frozen. The counter-54 promotion fix did NOT cause this — pre-existing resume-steal latent bug, hidden until N broker PTYs were present at a respawn; the single-black-holed-session A'-rig never exercised N-live-controllers-under-replay. FIX (brain-side): `resume_sessions` re-attaches as **Viewer** (`AttachIntent::Viewer`), NOT Control — a viewer never touches driven_by and is never stall-evicted (broker.rs:1063+ bounded try_send + private eviction), so steal-then-drop vanishes and the operator keeps/regains control; and it relieves shared-conn pressure (a slow viewer is DROPPED, never a 15s controller block) so rc retake gets through. Control ONLY for sessions the daemon brain genuinely DRIVES (empty set today → all become Viewer; forward-correct for the live-agent-adapter future). SECONDARY (escalation, ONLY if the gate shows residual B): stagger the resume re-attach + bound the viewer replay so the respawn burst can't saturate the conn. Int = the multi-broker-PTY-session RESPAWN rig (the coverage the A'-rig lacked): N real broker-spawned sessions with controllers producing output → real brain respawn/promote → assert (1) EVERY session keeps its controller across the swap (no stall-evict of a session the brain doesn't drive), (2) `spt rc` attaches/retakes IMMEDIATELY post-promote (no shared-conn saturation), (3) promotion still succeeds. RED-first: the current Control re-attach steals+evicts + deadlines rc. Composes with REQ-UPDATE-TRIAL-DRAIN-DRIVE (the orthogonal counter-54 promote fix), REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict it stops mis-firing on non-driven sessions), REQ-BROKER-ATTACH-JOURNAL-RESILIENT (the #16 shared-conn resilience). Distinct from REQ-BRAIN-UPDATE-RESTART-CLEAN-CLOSE (that = the OLD brain's outgoing black-hole; this = the NEW brain's resume-steal).
2026-07-17T03:24:38.1941691Z - Required stages: doc, impl, int
2026-07-17T03:24:38.1942043Z 
2026-07-17T03:24:38.1942400Z ### REQ-BRAIN-RESUME-NO-CONN-DEADLOCK
2026-07-17T03:24:38.1955705Z - Title: UPDATE-WEDGE round 3 (v0.30.5, doyle-ruled Option A 2026-07-09 — the v0.30.4 field-verify re-wedge, root code-PROVEN + dead-peer-INDEPENDENT): the daemon brain must NOT subscribe broker PTY sessions onto its own request/reply IPC conn — it has no consumer for that output and the subscription DEADLOCKS the conn. ROOT (todlando code-read, docs/UPDATE-WEDGE-2-ROUND3-CODEREAD.md; the net-runtime AND the counter-54 reap-drive were both FALSIFIED first — docs/UPDATE-WEDGE-2-ROUND3-RIG-VERDICT.md): a conn's send half is a single `SharedSend = Arc<Mutex<SendHalf>>` (broker.rs:78). Subscriber writer threads (`viewer_writer` broker.rs:1333/1342, `controller_writer` :1451) hold `send.lock()` ACROSS a BLOCKING `write_frame`; the dispatch reply path (`send_frame` :4221 → KIND_SESSIONS_REPLY / KIND_NET_STATUS_REPLY) needs the SAME lock. `resume_sessions` (brain.rs:1031→1054) subscribes every session as a Viewer onto the brain's MAIN conn — which is ALSO the brain's request/reply channel. The daemon brain hosts no PTY sessions (brainproc.rs:184) so run_brain never drains that output; it reads the conn only during the 500ms-heartbeat net_status()/sessions() calls (drain-and-DISCARD, `_ => continue`). When an actively-streaming session backs the conn up, a subscriber writer BLOCKS in write_frame holding send.lock() → the dispatch thread can't send the heartbeat reply → net_status()/sessions() never return → the heartbeat loop stalls → the brain never drains → the writer stays blocked = SELF-DEADLOCK on the brain conn's send mutex → every subscriber writer on it wedges → BRAIN_SUBSCRIBER_STALL_EVICT (controller writer blocked >15s). BOTH severities, one mechanism: RESPAWN (resume subscribes N + the replay burst floods the conn before the loop drains) AND STEADY-STATE (an active streamer's output between heartbeats fills the socket buffer). Counter-54 (REQ-UPDATE-TRIAL-DRAIN-DRIVE) added a 2nd per-heartbeat reply round-trip (sessions()) through the contended mutex — WIDENED the window (regression-window-exact), did not create it. The round-2 Viewer fix (REQ-BRAIN-RESUME-NO-CONTROL-STEAL) removed the STEAL but kept the brain a SUBSCRIBER — viewer_writer has the same send.lock()-across-write pattern AND viewers have no stall-evict valve — so v0.30.4 field-verify wedged again. FIX (Option A, brain-side, SEAMLESS): resume_sessions does NOT subscribe (drop the subscribe_with call; §3 verification guard confirmed NO brain consumer — digest/relay/net-consumer/shellwake/presence — reads the resumed subs). The brain conn then carries only request/reply → no subscriber backpressure → no deadlock. Keep the session_cursors seed only if harmless. Rides the brain-swap ⇒ seamless (no daemon.rs:368 broker restart). Option B (a dedicated Split-reader drain of the brain conn, brain.rs:230 — the pump's carrier) is the FORWARD path for when genuinely daemon-DRIVEN sessions land (the live-agent adapter) — deferred, noted, not built. Option C (the broker-side durable CLASS fix) = REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK, deferred. Int = the confirmer rig (brain+broker+PTY, brain_decouple template): N sessions actively producing output, brain resume-subscribed onto its req/reply conn; RED-first = heartbeat stalls + an active-streaming controller stall-evicted >15s WITHOUT any dead peer present (proves dead-peer-independence); assert BOTH severities (respawn interleave + steady-state output backup); Option A turns both green. Composes with REQ-BRAIN-RESUME-NO-CONTROL-STEAL (the round-2 Viewer fix this supersedes as the wedge cure), REQ-UPDATE-TRIAL-DRAIN-DRIVE (the counter-54 reap-drive that widened the window), REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE (the stall-evict it stops triggering).
2026-07-17T03:24:38.1967996Z - Required stages: doc, impl, int
2026-07-17T03:24:38.1968359Z 
2026-07-17T03:24:38.1968712Z ### REQ-DIGEST-GENERATION-SUPERSEDE
2026-07-17T03:24:38.1977784Z - Title: W3 (LIFECYCLE-TRUTH, digest projection truth — flynn filing spt-mobile d0aa3f4): a one-shot `endpoint digest --json` snapshot must return each logical activity row ONCE across a checkpoint/resume, not once per seq-generation. ROOT (spt-core-side, not a consumer bug): the K-session span (digest.rs activity_spanned, SPAN_SESSIONS=5) runs the [digest] extractor per session file and tags each row seq=(ledger_ordinal<<32)|localseq (REQ-DIGEST-CURSOR). A checkpoint/resume (self-/clear + Psyche rebuild) makes the harness REPLAY the prior generation's transcript into the NEW session file, so the ancestor's rows appear in BOTH the ancestor file AND the resume file at the SAME localseq — the span UNIONS them, one logical row surfacing under two full seqs (gen23,local208) + (gen25,local208), identical text/ts/localseq. Consumers dedup by exact seq (the documented authoritative key) so nothing collapses -> duplicate rows in every snapshot / `--after` view (`--follow from:0` is CLEAN — it reads current-generation only; the SPAN is the sole culprit). The trigger cannot disambiguate: `api boundary clear` records SessionTrigger::Clear for BOTH a fresh /clear (disjoint) and a carry-forward checkpoint (reporting.rs:94) — so a structural skip-ancestor needs new boundary metadata + adapter cooperation, deferred. FIX (doyle ruling — flynn Option 1 Supersede, projection-local, source-independent): within the span, collapse cross-generation replay dupes — an Activity record from an OLDER ordinal is dropped when an identical logical record (role, ts, text, tool) exists under a NEWER ordinal; keep the NEWEST-ordinal occurrence so the surviving seq is the live generation (snapshot + follow agree on seq). Cross-generation ONLY (never dedup within one ordinal — a session cannot replay itself; identical within-gen rows are real). Supersede runs on the raw span items BEFORE the window fold (project_timeline) so window_turns counts real turns, not phantoms; and a boundary divider adjacent to a now-fully-superseded ancestor is not left orphaned. Context entries (REQ-TERM-7, single digest.log) are not per-session-spanned -> untouched. Int = a two-session span rig where session B's extracted lines are a superset replay of A (same ts/text at same localseq) + B's own new tail: RED-first (pre-fix shows every A row twice); post-fix each logical row appears ONCE under B's generation, B's tail intact, the /clear boundary marker preserved when A retains rows.
2026-07-17T03:24:38.1986241Z - Required stages: impl, unit, int
2026-07-17T03:24:38.1986584Z 
2026-07-17T03:24:38.1986869Z ### REQ-UPDATE-FINISH-COMMUNE-FLUSH
2026-07-17T03:24:38.1992924Z - Title: DEFERRED (post-LIFECYCLE-TRUTH, operator-ruled 2026-07-07 — mint now, impl a FUTURE milestone): make the update swap LOSSLESS for live hosted endpoints by flushing a final echo-commune per endpoint BEFORE the brain-subtree reap. ROOT (operator-surfaced probing --finish): `update apply --finish` = daemonless swap -> daemon RESTART; the graceful `daemon stop` path (daemon.rs:316-325) raises brain_stop then reaper.reap() KILLS the brain subtree (brain + shellwake watchers + detached Psyches) as one unit — there is NO per-endpoint final commune before the kill. ENDPOINT-SURVIVAL (REQ-UPDATE-FINISH-ENDPOINT-SURVIVAL) then RESPAWNS each orphaned online spt-hosted endpoint, but from its LAST commune (whatever the ongoing per-event echo-commune cadence last saved), NOT an as-of-swap checkpoint — so mid-turn / uncommuned work is lost across the bounce. Today's mitigation is operator discipline: commune-before-swap. FIX (future): the stop/finish path, before reap, drives each LIVE hosted endpoint's final echo-commune (fire_echo final context save) so the respawn resumes from a swap-fresh checkpoint. Composes with ENDPOINT-SURVIVAL (commune -> reap -> respawn) and the W1 echo pipeline (REQ-ECHO-DROP-DIR-RESOLVE / REQ-PSYCHE-STAMP-CLEAR-ANY-SUCCESS). Bounded + loud per endpoint (a commune that hangs must not wedge the stop — timeout then reap anyway, never block the swap). Int: a live hosted endpoint with uncommuned state -> --finish -> respawned endpoint's digest/psyche reflects the pre-swap state (RED-first: without the flush the respawn shows only the last-cadence commune).
2026-07-17T03:24:38.1998761Z - Required stages: 
2026-07-17T03:24:38.1999142Z 
2026-07-17T03:24:38.1999433Z ### REQ-SELF-ID-TRUST-INJECTED-ENV
2026-07-17T03:24:38.2006416Z - Title: DEFERRED to a followup vX.X.n sprint (post-LIFECYCLE-TRUTH, operator-ruled 2026-07-07): self-identity resolution must trust the harness-injected authoritative id and detect a stomped perch instead of silently mis-attributing. ROOT (doyle /diagnose 2026-07-07, field: agent sends stamped `cli@HFENDULEAM` / mis-attributed): `resolve_from` (cli.rs:5480) stamps `cli@<node>` when `detect_self_id` (roster.rs:103) returns None; detect_self_id resolves self ONLY by reverse-lookup — matching `$OWL_SESSION_ID` against a perch's info.json.session_id (then SPT_AGENT_ID, then parent_pid) — and IGNORES `SPT_ENDPOINT_ID`, the authoritative self-id the adapter injects (present in-env as SPT_ENDPOINT_ID=<id>). When a perch record is STOMPED (a cross-id info.json overwrite — the REQ-SPAWN-COLLISION-GUARD-LIVE-DUP damage class; field case: doyle's live session_id written into the deployah perch), the reverse-lookup mis-resolves (doyle session -> `deployah`) or fails (real deployah -> None -> `cli@node`), and the CLI silently believes the stomped store. FIX: detect_self_id PREFERS `SPT_ENDPOINT_ID` when set+non-empty (the harness-authoritative id, immune to a stompable perch), AND cross-checks it against the reverse-resolved perch id — a mismatch logs LOUD (a stomped/duplicated perch becomes a self-diagnosing signal, not a silent wrong identity). Bare-CLI (no SPT_ENDPOINT_ID) keeps the reverse-lookup then the `cli@node` fallback. Also reconcile the adapter/core self-id env contract (SPT_ENDPOINT_ID vs SPT_AGENT_ID vs OWL_SESSION_ID — which is canonical). NOTE: W4 REQ-SPAWN-COLLISION-GUARD-LIVE-DUP prevents FUTURE stomps but does not heal existing corruption nor add this resolution-robustness; recovery of a live stomp today is a manual `api boundary clear <id> --to-session-id <sid> --session-id <current>` re-bind (doyle recovered the doyle/deployah cross-wire this way 2026-07-07).
2026-07-17T03:24:38.2013168Z - Required stages: 
2026-07-17T03:24:38.2013478Z 
2026-07-17T03:24:38.2013773Z ### REQ-SPAWN-COLLISION-GUARD-LIVE-DUP
2026-07-17T03:24:38.2016944Z - Title: W4 (LIFECYCLE-TRUTH): single-flight wake per endpoint — the WAKE/RESUME respawn seam must not launch twice for one wake. ROOT (perri parentage + recovered filing): one wake processed TWICE within 1s — broker (306368) spawned two identical `launch --cli ccs --id flynn --resume <sid>` 1s apart, both survived; check-then-spawn TOCTOU in the spawn-side guard. DAMAGE: duplicate-perch writers STOMP info.json (the duplicate's compact re-stamped an OLD sid over a fresh /clear rotation -> injects routed to the contended record and lost). FIX: single-flight wake per endpoint (claim on the perch record or broker-side in-flight set keyed by id; second wake within the window = no-op ack), and the spawn path re-checks liveness UNDER the claim. Int: two concurrent wake requests -> exactly one launch tree.
2026-07-17T03:24:38.2019948Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2020287Z 
2026-07-17T03:24:38.2020563Z ### REQ-HAZARD-LISTEN-ORPHAN
2026-07-17T03:24:38.2023267Z - Title: W4 (LIFECYCLE-TRUTH, KNOWN-HAZARDS): `api listen --parent-pid N` watches parent liveness and exits loud on parent death. ROOT (mobile-gw RCA): --parent-pid is auth-anchor ONLY — no liveness watch; host death orphans the listener forever -> perch held alive (false ONLINE), EVENTs stream to a dead stdout, dead-owner rebind BLOCKED (recorded pid = the live orphan). FIX: listener watches --parent-pid liveness (Windows: job object or poll; Unix: PDEATHSIG or poll) and exits loud on parent death. flynn's job-object guard (spt-mobile side) stays regardless; filed SPT-CORE-NEEDS §5. Unit: parent-death -> listener exits within one poll window.
2026-07-17T03:24:38.2025829Z - Required stages: impl, unit
2026-07-17T03:24:38.2026167Z 
2026-07-17T03:24:38.2026449Z ### REQ-INJECT-MULTILINE-INTEGRITY
2026-07-17T03:24:38.2030000Z - Title: W5 (LIFECYCLE-TRUTH): the idle-inject TYPED delivery leg delivers multi-line bodies byte-complete. ROOT (4 field instances + spool diff): the typed leg eats HEAD bytes nondeterministically — spool rows complete (1669B) vs ~322B received suffix; mid-turn poll envelopes always intact; a 1854B body later rode the same leg intact => timing race (terminal-readiness / enter-coalescing settle class), NOT a size cap. FIX DIRECTION (todlando proposes on the broker/translate typed-inject seam): settle-before-head, bracketed-paste where the harness supports it, or chunked write with echo-verify. STAKES: live-SENT injects leave NO spool copy — truncation there is unrecoverable. Int: repeated large multi-line injects into a real PTY session arrive byte-complete (loop N times — the race is timing-dependent, single-shot green is not proof).
2026-07-17T03:24:38.2033068Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2033416Z 
2026-07-17T03:24:38.2033697Z ### REQ-HAZARD-INJECT-SETTLE-REARM
2026-07-17T03:24:38.2038773Z - Title: post-0.29.0 (KNOWN-HAZARDS 7.37): the Layer-1 settle-gate must RE-ARM before every delivery on an OBSERVABLE (echoing/interactive) PTY — a mid-session reader reattach re-creates the head-swallow window. ROOT (field-confirmed on 0.29.0, doyle diagnosis + perri screenshot): the shipped W5-A settle-gate (REQ-INJECT-MULTILINE-INTEGRITY) gated Layer 1 behind a worker-local ONE-SHOT (`settled_once`) on the false premise that the head-swallow race is STARTUP-only (reader not attached after spawn). A mid-session `/clear` re-enters the harness's raw-mode input reader, re-creating the pre-settle window — but the one-shot already fired at spawn, so `settle_before_inject` is SKIPPED and the head is eaten again (a checkpoint-wake payload injected right after `/clear` lost its head, mid-path `spt/Cargo.toml)`); echo-verify (Layer 2) is default-OFF for that session, so it is silent + unrecoverable. FIX (doyle ruling): re-settle before EVERY delivery on an observable PTY; latch-skip the steady-state settle ONLY where the probe is UNOBSERVABLE (non-echoing ConPTY — no reader-reattach race to guard, and each settle burns the full deadline). The settle's own bool return (observed vs timed-out) discriminates the class; a re-drive (attempt>1) ALWAYS settles. `settled_once: bool` one-shot → `probe_unobservable: bool` latch driven by the first-attempt settle outcome.
2026-07-17T03:24:38.2043867Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2044215Z 
2026-07-17T03:24:38.2044496Z ### REQ-IDLE-PARKED-DELIVERY
2026-07-17T03:24:38.2047477Z - Title: W5 (LIFECYCLE-TRUTH): a message QUEUED to an ALREADY-idle spt-hosted endpoint is delivered without an operator poke. ROOT (live during the milestone dispatch 2026-07-07): the idle-edge drain (F-023 leg 2) fires only on the ACTIVE->IDLE transition; no new edge ever comes for a parked session, and the send-time inject didn't carry it — both doyle->todlando dispatches sat delivered=0 in the spool while the endpoint showed ONLINE. FIX: send-time inject fires for an already-idle spt-hosted target (activity sense says idle => inject now, not spool), and/or a bounded spool sweep re-offers pending rows to idle endpoints (piggyback the pulse tick, no new loop). Int: send to a session idle for N minutes -> delivered without any operator poke.
2026-07-17T03:24:38.2050249Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2050583Z 
2026-07-17T03:24:38.2050850Z ### REQ-SPOOL-TAKE-AUDIT
2026-07-17T03:24:38.2052359Z - Title: W5 (LIFECYCLE-TRUTH, RCA cost: proving WHO took delivered=1 rows burned an hour): the spool records the taker per row — leg enum (relay-backlog / hook-poll / idle-inject / psyche) + sid/pid + taken_at ms — surfaced by a --json debug read. Additive column, no schema break (delivered rows already retained).
2026-07-17T03:24:38.2053750Z - Required stages: impl, unit
2026-07-17T03:24:38.2054270Z 
2026-07-17T03:24:38.2054551Z ### REQ-DOC-ECHO-COMMUNE-CONTRACT
2026-07-17T03:24:38.2056684Z - Title: W6 (LIFECYCLE-TRUTH, docs — this gap cost a full outage night, priority slot): publish the [session.echo_commune] I/O contract on the docs-site: key catalog core fills; core does NOT stdin-feed [history] (field-proven); self-locate guidance incl. CLAUDE_CONFIG_DIR / read_env; drop-file protocol (single-writer, ingest-deletes, resolver semantics from W1); stdout ingestion expectations. Public docs use VERSION numbers, never wave codes; docs-publish drift gate applies.
2026-07-17T03:24:38.2058802Z - Required stages: doc
2026-07-17T03:24:38.2059227Z 
2026-07-17T03:24:38.2059504Z ### REQ-DOC-DELIVERY-VOCAB
2026-07-17T03:24:38.2061239Z - Title: W6 (LIFECYCLE-TRUTH, docs — remaining flynn/perri gaps folded): publish the full send-outcome vocabulary (SENT / SENT(WAN) / QUEUED window semantics / DEFERRED / NO_PERCH), digest --json row schema, api poll auth + MAC-stamp prefix, remaining --json shapes checklist (seed #3). Public docs use VERSION numbers, never wave codes; docs-publish drift gate applies.
2026-07-17T03:24:38.2062813Z - Required stages: doc
2026-07-17T03:24:38.2063143Z 
2026-07-17T03:24:38.2063410Z ### REQ-PLATFORM-REGISTRY
2026-07-17T03:24:38.2067750Z - Title: MUSL-TIER W1 (target-triple centralization, behaviour-NEUTRAL refactor): ONE authoritative platform registry from which current_platform(), KNOWN_TARGET_TRIPLES, the applyhost cross-platform 'other' logic, and the asset-name<->triple map all derive. ROOT: the target triple x86_64-unknown-linux-gnu + the implicit 'exactly 2 platforms' assumption are hardcoded across ~6 sites (release.rs current_platform cfg + KNOWN_TARGET_TRIPLES, applyhost.rs:740-743 win/linux binary if/else, xtask asset map, release.yml), so adding any platform (musl, future arm64) is a scattered edit. FIX: a data-driven registry (candidate: SUPPORTED_PLATFORMS const table of {triple, asset_name}) + generalize applyhost 'other' to 'every registered platform except current_platform()'. gnu+windows behaviour BYTE-IDENTICAL — the existing release/update/apply/propagate suites stay green (that is the gate). DESIGN FORK (doyle rules pre-dispatch): enum vs const-table; applyhost N-platform generalization; current_platform stays cfg->triple but output must be a registry member, loud 'unknown' fallback kept.
2026-07-17T03:24:38.2072140Z - Required stages: impl, unit
2026-07-17T03:24:38.2072472Z 
2026-07-17T03:24:38.2072730Z ### REQ-PLATFORM-MUSL
2026-07-17T03:24:38.2076010Z - Title: MUSL-TIER W2 (register the musl platform, self-IDENTIFY): add x86_64-unknown-linux-musl to the W1 registry — a current_platform() cfg arm (target_arch=x86_64, target_os=linux, target_env=musl -> the musl triple, NO more 'unknown' fallback), asset name spt-x86_64-linux-musl, triple-map entry. PROVEN (doyle /diagnose 2026-07-08, backlog #14): the current tree builds+runs static musl with ZERO source changes (rustls not openssl; aws-lc-sys+bundled-sqlite clean under musl-gcc; openpty; DNS/HTTPS works statically) — so W2 is registry DATA + cfg + asset map, NO dependency changes. Gate: a musl-built spt self-reports x86_64-unknown-linux-musl (not 'unknown'); registry-membership unit (the cfg arm is cross-target, unit the registry not the arm); build the musl target in-gate (kitsubito toolchain) and assert current_platform.
2026-07-17T03:24:38.2079068Z - Required stages: impl, unit
2026-07-17T03:24:38.2079406Z 
2026-07-17T03:24:38.2079682Z ### REQ-RELEASE-MUSL-ARTIFACT
2026-07-17T03:24:38.2083219Z - Title: MUSL-TIER W3 (CI build + signed release + update-set publish + self-update E2E): release.yml gains a musl matrix entry (build on kitsubito; install musl-tools+cmake+target in-job, CC_x86_64_unknown_linux_musl=musl-gcc); the assemble job includes spt-x86_64-linux-musl in SHA256SUMS + the release upload; release-publish (xtask) signs the musl artifact; the update-set carries its artifact entry. This closes the field gap: a musl binary today fetches fine but ends UPDATE_FETCH_REJECTED:NoArtifactForPlatform('unknown'). Gate (release-pipeline touch -> real E2E): cut a draft/test release with the musl artifact; a static musl binary on a sub-2.39-glibc box runs spt update fetch -> gets the musl artifact (no NoArtifactForPlatform), verifies SHA256+signature over the musl bytes, applies, self-updates. musl is ADDITIVE — gnu stays the default Linux artifact.
2026-07-17T03:24:38.2086422Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2086779Z 
2026-07-17T03:24:38.2087051Z ### REQ-PUMP-DIAL-FASTFAIL
2026-07-17T03:24:38.2096024Z - Title: PUMP-TRUTH W1 (RE-SCOPED post round-2 empirical lock — the DIAL is EXONERATED, healthy ~100ms): a pump worker-leg PEER-REPLY read to a connect-then-silent / half-alive peer must drop THAT peer as an ORDINARY per-peer failure (peer_outcome's non-TimedOut arm -> PUMP_PEER_FAIL -> drop conn + redial, round CONTINUES, heartbeat advances), NEVER burn the brain's 30s PUMP_PEER_IO_TIMEOUT carrier deadline into a whole-round TimedOut POISON -> supervise_pump doubling-backoff restart. ROOT (deployah leg-instrumented capture, enlyzeam, 3 identical rounds): DIAL_EXIT 96ms ok, LEG i=3 update ms=30025 err[TimedOut] = the wedge. request_update (propagate.rs:373-375) opens the update stream + sends UpdRecord::Query (all bounded, all land), then BLOCKS read_event_until(deadline=call_deadline()=30s) on the peer's Offer/UpToDate reply; a peer that accepts the stream but never answers burns the full 30s -> TimedOut -> peer_outcome (pump/mod.rs:601) POISON -> whole-round abort + restart (= the field PEER_PUMP_FAIL: brain IPC read deadline, always-zero PUMP_PEER_FAIL). request_sync (sync.rs:374-376) is the LATENT TWIN (SKIPS the reply-read only when the want-set is empty; bites the moment it is non-empty against a silent peer). FIX (both legs): (a) reclassify the reply-read no-progress timeout OUT of TimedOut to a non-poison kind (Brain::read_peer_reply_until) so peer_outcome drops ONLY that peer -- poison RESERVED strictly for a genuine broker-IPC-CARRIER desync (the carrier ops net_open_stream/subscribe/send keep raw TimedOut); the abandoned peer stream is safe (exactly-once seq cursor stays contiguous, a late reply matches no live stream id). (b) budget-decouple the reply-read below 30s (Brain::reply_read_deadline = now + min(io_timeout, 10s)) so a silent peer drops promptly even in the still-sequential pre-W2 pump and can never race the carrier deadline. Files: propagate.rs (request_update) + sync.rs (request_sync) + brain.rs (reply_read_deadline + read_peer_reply_until) + pump/mod.rs (peer_outcome poison reserved for carrier-desync). Gate: a connect-then-silent peer at fan#0 -> the update leg drops it ordinarily within the reply-read budget, round continues + heartbeat advances, NO PEER_PUMP_RESTART; happy path (live peer) unchanged; + the sync-non-empty-want-set latent case. Kin REQ-PUMP-PEER-ISOLATION (W2 concurrency, VALIDATED by this root) + REQ-HAZARD-PUMP-IPC-DEADLINE (the poison it must stop mis-firing on a peer).
2026-07-17T03:24:38.2104410Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2104763Z 
2026-07-17T03:24:38.2105030Z ### REQ-PUMP-PEER-ISOLATION
2026-07-17T03:24:38.2109752Z - Title: PUMP-TRUTH W2 (architectural, operator ruling 2026-07-08): one peer must NOT block or poison all others -- peer discovery is async / per-peer-independent. Two coupled defects in run_peer_pump: (1) SEQUENTIAL fan-out (for peer in fan_targets dials one-at-a-time, each up to the bound -> peer N+1 waits behind peer N); (2) WHOLE-ROUND POISON (peer_outcome(...)? -- one TimedOut aborts the ENTIRE round via ? -> supervise_pump doubling-backoff restart, resetting ALL conns). FIX: per-peer concurrency + fault isolation -- the pump issues non-blocking dial requests; the broker (already async tokio+iroh) returns connection/presence results as async events (the D4c presence seam), no serial per-peer block; a peer TimedOut drops + reschedules ONLY that peer, NEVER aborts the round or restarts the pump. Supervised-restart is RESERVED for a dead BROKER conn, not a dead peer (the single-thread+bounded-read A-half REQ-HAZARD-PUMP-IPC-DEADLINE was defensive -- it stopped the infinite wedge but coupled every peer's fate; this decouples). Gate: a mixed roster (1 live + N offline peers) -- the live peer connects AND this node advertises presence in the SAME round the offline peers fail; heartbeat advances every round; no PEER_PUMP_RESTART from a dead peer. Depends on W1 (a fast-failing dial is the precondition for clean per-peer scheduling).
2026-07-17T03:24:38.2114708Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2115071Z 
2026-07-17T03:24:38.2115376Z ### REQ-HAZARD-COMMUNE-INGEST-BLACKHOLE
2026-07-17T03:24:38.2123011Z - Title: F-032 (perri field finding 2026-07-08, LEGACY-SPT-PARITY-GAP, data-loss): commune/signoff ingest MUST NOT delete a drop until its content is DURABLY COMMITTED to every APPLICABLE tier — a slice that cannot be committed this ingest must leave the drop in place for a later ingest (retry when the precondition resolves) OR durably preserve the un-committed slice, NEVER delete-then-lose. ROOT (doyle triage, code-grounded): ingest_drops (spt-live/src/ingest.rs:200) unconditionally `remove_file(&drop_path)?` AFTER route_slices (ingest.rs:121), but route_slices GATES the project tier on `!project_id.is_empty()` (ingest.rs:156) — when the endpoint's cwd is unresolved/owlery-internal at ingest time the project_id is empty, so the `<project-context>` slice is PARSED but never write_context'd/commit_project'd, yet the source drop is still deleted → the project-context content is permanently lost (black-hole). perri's repro: a two-sliced echo-commune (<live-context> role+release recipe + <project-context> v0.17.4 status + Items 3-5 map) INGESTED (file deleted) yet never surfaced at her next SessionStart resume-pull; adapter exonerated (file-write + slicing tags correct); fixture at (system temp)/F-032-commune-2026-07-08T222721Z.md (5595B, sha256 9bc27e18cf385958; perri wrote it verbatim from session log 0841835d.jsonl). Legacy spt held commit-first-then-delete parity; the modern two-slice ingest broke it. FIX distinguishes: a write SUPPRESSED-by-precedence (incoming older than durable → already-superseded → safe to delete) from a slice NOT-committed-because-un-committable-now (empty project_id / write error → must NOT delete; retry or preserve). Gate: an ingest with a non-empty <project-context> slice but an EMPTY project_id must NOT delete the drop (or must durably preserve the project slice) — the content survives to the next resolvable ingest / SessionStart; the live-tier commit path stays unchanged; a genuinely superseded (precedence-suppressed) drop still deletes. KNOWN-HAZARDS entry on landing (REQ-HAZARD-* = conformance-checklist, needs a test).
2026-07-17T03:24:38.2130299Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2130642Z 
2026-07-17T03:24:38.2130938Z ### REQ-LIVE-AGENT-NO-INJECT-DELIVERY
2026-07-17T03:24:38.2140657Z - Title: F-033 RE-SCOPED (doyle re-ruling 2026-07-10 after the #82 gate falsified the original premise — the hosting-mode class split is BINDING context): 'state:live_agent has a self-delivery reader' CONFLATED two hosting modes. (A) HARNESS-hosted live agents (api listen path) DO deliver via adapter channels only — and are ALREADY structurally excluded from inject: bind_from_seed stamps controllable=Some(false), no broker PTY exists. (B) SPT-HOSTED/CONTROLLED live agents' inject leg IS their delivery reader (broker PTY + translation binary — doyle's own endpoint is field proof: ENDPOINT_INJECT + IDLE_PARKED_DRAIN alongside hook-poll); the original blanket state:live_agent exclusion broke REQ-MSG-IDLE-EDGE-DRAIN + the v0.14.3 LAW on both CI platforms and was REVERTED (predicate stays controllable-gated). perri's adapter-channels-only model (F-dupmsg-adapter-confirm.md) holds for class (A) only — do not re-seed the conflation. The F-033 DUPLICATE mechanism (hook-poll + idle-inject both delivering one row, operator spool row 156) is closed structurally by REQ-CARRIER-CLAIM-EXCLUSIVE's atomic cross-carrier take. REMAINING LEGS OF THIS REQ: (a) unit — a harness-hosted live agent (controllable Some(false)/None, no broker PTY) can never route through try_spt_hosted_inject (evidence may TAG the existing is_spt_hosted_no_relay non-controllable case rather than duplicate it); (b) VERIFICATION (report-before-fix, DELIVERED to doyle 2026-07-10): the no-translation-binary raw payload+CR path is PROVABLY DEAD (broker dispatch_endpoint_input: no-binary -> loud spool, never a PTY write — v0.14.3 holds); the operator's typed-unsubmitted garbage is PINNED to the Layer-2 echo-verify RE-DRIVE (broker.rs inject worker) force-enabled host-wide by ambient SPT_INJECT_VERIFY_ECHO in the daemon's inherited dev-shell env (default-OFF declared capability turned on globally — the F-036 env-inheritance class): a false verify-miss RETYPES the whole sequence into the input field. Fix LANDED on the W4 branch (doyle-accepted echo-scrub 2026-07-10): SPT_INJECT_VERIFY_ECHO/SPT_INJECT_FORCE_ECHO_MISS folded into the W1 daemon-startup env scrub (spt_runtime::INJECT_ECHO_ENV_VARS; startup-only, role-spawn builder untouched so explicit per-spawn declaration stays the production on-switch) — evidence rides REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE (the F-036 class REQ). Residual-class RULED (doyle 2026-07-10): this REQ covers the harness-hosted-never-inject predicate leg (unit) + the echo-scrub itself (impl, dual-tagged) — stages [impl,unit].
2026-07-17T03:24:38.2149306Z - Required stages: impl, unit
2026-07-17T03:24:38.2149646Z 
2026-07-17T03:24:38.2149931Z ### REQ-ADAPTER-UNRESOLVED-HINT-FORM
2026-07-17T03:24:38.2153108Z - Title: F-034 leg a (perri/hertz field finding 2026-07-09): the ADAPTER_UNRESOLVED refusal hint must print a WORKING command form. It currently says 'pass --adapter <name[:profile]>', but --adapter is a `spt api` GROUP flag, NOT a `listen` flag — following the hint literally (`spt api listen <id> --adapter <name>`) produces clap `error: unexpected argument '--adapter'` (exit 2). Fix: the hint prints the group-level form, e.g. `spt api --adapter <name> <cmd> …` (a hint the operator can copy-paste and have work). Gate: the ADAPTER_UNRESOLVED message text carries a clap-VALID invocation (group-level --adapter placement) — a unit asserting the hint string parses under the api clap grammar, or at minimum places --adapter before the subcommand. Pure UX/hint-correctness fix, no behavior change.
2026-07-17T03:24:38.2156043Z - Required stages: impl, unit
2026-07-17T03:24:38.2156391Z 
2026-07-17T03:24:38.2156670Z ### REQ-LISTEN-SEED-CONSUME-AFTER-BIND
2026-07-17T03:24:38.2161254Z - Title: F-034 leg b (perri/hertz field finding 2026-07-09, hertz's HEADLINE): `api listen` must NOT consume the consume-once ephemeral seed on a PRE-BIND refusal — validate (adapter resolvable, home/subnet) and BIND first, THEN consume the seed. ROOT: today `api listen` burns the consume-once seed BEFORE it validates home/subnet, so on a multi-subnet node HOME_REFUSED (needs --subnet) fires AFTER the seed is already gone → the corrected retry (adding --subnet) on the SAME pid hits NO_SEED, a dead end (plausibly ADAPTER_UNRESOLVED burns it the same way). A refusal that never bound must leave the seed intact for the corrected retry. Same EFFECT-BEFORE-IRREVERSIBLE-CONSUME ordering class as F-032 (commune commit-before-delete) — the irreversible consume must follow the successful effect, never precede a refusal. Gate: a pre-bind refusal (HOME_REFUSED on a multi-subnet node without --subnet; ADAPTER_UNRESOLVED) leaves the seed CONSUMABLE — the corrected retry on the same pid binds (no NO_SEED); a SUCCESSFUL bind still consumes the seed exactly once (no double-bind). Files: the api-listen bind path (seed consume ordering). Kin F-032 [[spt-core-findings-backlog]].
2026-07-17T03:24:38.2165596Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2165949Z 
2026-07-17T03:24:38.2166235Z ### REQ-LISTEN-SESSION-ID-FALLBACK
2026-07-17T03:24:38.2171080Z - Title: F-034 leg c (perri/hertz field finding 2026-07-09): a session that goes live LATE (hours after SessionStart, or after a daemon restart) must still be able to bind — the ephemeral SessionStart seed ('consumed within seconds') is GONE by then and nothing re-fires it until the NEXT SessionStart, so even `api listen --parent-pid <correct claude pid>` hits NO_SEED. Design assumption 're-fired on the next SessionStart if needed' does not hold for long-lived sessions. FIX (perri-recommended, cleanest): `api listen --session-id <sid>` fallback that binds from the session-id when the pid has no live seed — removes the ephemeral-seed dependency entirely (the adapter already knows the sid; the skill passes it, and can then DROP its manual re-seed step). Alternative (option 1, less clean): re-fire the seed on daemon restart. Gate: a session with NO live seed (expired / post-daemon-restart) binds via `listen --session-id <sid>` (no NO_SEED); the sid-bind carries the same identity/auth the seed-bind would (session_id custody — kin REQ-PSYCHE-SID-CUSTODY / the sid-symmetric-auth pattern). Files: api-listen bind path (sid-fallback seam), clap --session-id flag (plain doc-comment). hertz/perri live-verify; if it lands the adapter skill drops the re-seed step.
2026-07-17T03:24:38.2175836Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2176242Z 
2026-07-17T03:24:38.2176538Z ### REQ-LIST-JSON-LIVENESS-PARITY
2026-07-17T03:24:38.2184246Z - Title: GATEWAY-LIVENESS (flynn field bug 2026-07-09, RCA reader-divergence root): `spt endpoint list` (human) and `endpoint list --json` MUST report an IDENTICAL status for a locally-hosted endpoint — especially a pid-alive, status-ABSENT gateway (no psyche_init). ROOT (todlando RCA STEP-1, doyle-verified): the --json builder (crates/spt/src/cli.rs cmd_endpoint_list) emits each subnet row's status straight from resource_projection (spt-net registry.rs:566, passes instance.status through verbatim :592 — the persisted WAN snapshot, a lagged gossip that can carry a stale/crash-time Suspended) and NEVER applies the self-owned reconcile the human/picker path applies (reconcile_self_owned, crates/spt/src/picker/data.rs:160 via gather_endpoints :112). So a pid-alive self-owned gateway reads Suspended on --json but ONLINE on human (roster::enumerate spt/src/roster.rs:38 -> is_perch_alive pid-fallback spt-store/liveness.rs:136); the adapter suspend-poll (parse_endpoint_status over endpoint list --json --show-all) reads the divergent --json status -> self-suspends a pid-alive gateway. Candidates REFUTED: resource_projection does NOT re-derive liveness (copies instance.status, only skips !routable :582); render is a faithful {:?}. advertised_status (registryhost.rs:822) DOES compute Active via pid-fallback (live advertise fine) — the bug is the READER showing the un-reconciled snapshot. FIX (doyle-ruled): apply the self-owned reconcile in the cli --json builder (SAME spt/picker consumer layer as gather_endpoints, NOT lifted into resource_projection which inverts the dep spt-net->perch), reading LOCAL perch truth (is_perch_alive/unbound -> Active/Offline, mirroring the picker's local_rows). Do NOT force status=online (DEFECT B latent — seed-#5 orphan-listener false-ONLINE risk). Gate: a pid-alive locally-hosted gateway (status-absent, no psyche_init) reads the SAME non-Suspended status on human AND --json. Field-verify flynn (mobile-gw). Kin REQ-PICKER-3 + REQ-PRESENCE-LIVENESS-TRUTH + seed-#5 orphan-listener false-ONLINE.
2026-07-17T03:24:38.2191523Z - Required stages: impl, int
2026-07-17T03:24:38.2191857Z 
2026-07-17T03:24:38.2192148Z ### REQ-HAZARD-BIND-REST-STATE-CARRY
2026-07-17T03:24:38.2195969Z - Title: GATEWAY-LIVENESS DEFECT A (flynn field bug 2026-07-09, confirmed independent): a re-bind MUST preserve the daemon-owned resting intent (rest_state, D9-2/REQ-INST-3) — the same carry-forward discipline establish_perch already applies to cwd/controllable/adapter/read_env. ROOT: establish_perch's record build (crates/spt/src/api/startup.rs, the build closure) constructs a fresh InfoJson via InfoJson::new (defaults rest_state None) and carries cwd/controllable/read_env forward from prior but NOT rest_state -> a re-bind WIPES the wake intent (flynn tick11 rest_state:active vanish). FIX: carry prior.rest_state (and its paired dormant_since_ms anchor, present iff dormant) forward on re-bind, like the sibling fields. Gate: a re-bind over a prior record with rest_state set preserves it (unit — the build closure carries rest_state + dormant_since_ms). KNOWN-HAZARDS entry on landing. Kin REQ-HAZARD-BIND-CWD-UNSET / REQ-PICKER-1 + REQ-INST-3.
2026-07-17T03:24:38.2199504Z - Required stages: impl, unit
2026-07-17T03:24:38.2199848Z 
2026-07-17T03:24:38.2200124Z ### REQ-SEND-WINDOW-DRAIN-HONOR
2026-07-17T03:24:38.2206947Z - Title: F-035 (field finding 2026-07-09): active_only = POLL-ONLY for a relay-bearing live agent -- it must NEVER be RELAY-delivered (its contract is 'active hook window only, never wakes' per spool.rs WINDOW_ACTIVE_ONLY doc + cli.rs:85; `spt send --active-only` / the hidden `--deferred` alias and `send_deferred` shell-context mint it). FIELD SYMPTOM: lia (a full live agent -- relay-for-idle, poll-for-busy) surfaced an --active-only msg on her IDLE RELAY. RCA JOURNEY: v1 RCA (docs/F-035-RCA.md) analyzed the WRONG class (spt-hosted-relay-LESS, the idle-edge inject leg) and proposed a COLLAPSE that would have broken the shipped F-023 anti-starvation gate (docs/F-035-CONFLICT.md); operator reclassified to a relay-bearing live agent; the relay-class re-RCA (docs/F-035-RELAY-RCA.md) traced EVERY active_only->relay carrier and found them ALL ALREADY GUARDED on main@2c05dc9 -- so spt-core has NO code bug. doyle FINAL RULING: the real leak is the ADAPTER's busy->idle poll->idle-representation handoff (spt-claude-code -- a legitimate `api poll` on going idle drains active_only, then the adapter renders it into the idle/relay surface), OUTSIDE spt-core; perri's lane. spt-core DELIVERABLE = a REGRESSION GUARD (tests only, NO behavior change) locking the 3 load-bearing guards that keep active_only off a relay: (1) send_windowed:217 -- an active_only send SKIPS deliver_tcp (never rides a live relay's TCP channel), spools poll-only; (2) cli.rs:5762 -- a cross-node active_only send stays LOCAL-ONLY (the WanMessage wire record has no window field, so shipping it would strip the class and relay-deliver at the far node); (3) relay.rs drain_backlog -> drain_non_deferred (deferred=0) -- the relay backlog NEVER forwards an active_only (deferred=1) row. Guard suite: unit (send_windowed active_only-skips-tcp-to-live-relay + relay_backlog-never-drains-active_only) + int (cross-node active_only stays local-only, never WAN, while a default send to the same remote target DOES take the WAN leg). Kin REQ-MSG-DELIVERY-AXES + REQ-MSG-IDLE-EDGE-DRAIN + REQ-INST-6.
2026-07-17T03:24:38.2213994Z - Required stages: unit, int
2026-07-17T03:24:38.2214327Z 
2026-07-17T03:24:38.2214691Z ### REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK
2026-07-17T03:24:38.2227205Z - Title: UPDATE-WEDGE round-4 (hertz RCA, root reproduced + source-pinned on Windows 2026-07-09): EVERY write on a physical broker connection rides ONE bounded + cancelable + poison-on-failure framed-write primitive — no writer may hold the connection's serialized send gate across an UNBOUNDED OS write. ROOT: controller_writer held the SharedSend = Arc<Mutex<SendHalf>> guard ACROSS a blocking write_frame; on Windows interprocess 2.4.2 routes the send to WriteFileEx + SleepEx(INFINITE, alertable) with NO supported write timeout (set_timeout → Unsupported), so an `rc --take` controller consumer that stops reading blocks the write INDEFINITELY (~127.95 s in the field capture, released only when a brain restart tore the conns down). Logical stall_evict_controller (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE) removes the controller ROLE but neither cancels the in-flight pipe write, closes the physical connection, nor invokes CancelIoEx — the detached writer keeps its SharedSend clone + live stack-owned mutex guard. Load-gated: needs a real seq>0 frame + a non-draining consumer (seq-0 boot conns + a quiescent update are clean — why v0.30.5's controlled apply passed); CTRL_WRITE_LOCKED wait_us=0 on all four capture writers exonerates the mutex convoy — the block is INSIDE the OS write, after lock acquisition. Existing deadlines can't bound it: CONTROLLER_WRITE_DEADLINE is output-driven channel-full handling (a writer blocked on its first owned frame never fills the channel); BRAIN_WRITE_DEADLINE is an age PREDICATE sampled opportunistically, not an I/O timer. FIX (accepted shape, doyle GO + 3 confirms): broker-owned Arc conn object (conn.rs BrokerConn) replacing raw Arc<Mutex<SendHalf>> — serialized write gate (bounded gate-wait) + send half (never leaves the object, so a bypass cannot compile) + idempotent poisoned state + per-in-flight op identity + platform abort seam, with an INDEPENDENT per-conn watchdog firing OUT OF BAND at an ABSOLUTE deadline stamped at write entry covering BOTH gate-wait and OS write completion (brain_write_deadline() — the existing SPT_BRAIN_WRITE_DEADLINE_MS knob; the abort NEVER relies on the write returning or on opportunistic stall-evict sampling). On deadline/partial/cancel/unknown completion: (1) poison the whole physical conn, (2) abort read+write (cfg(windows) CancelIoEx then DisconnectNamedPipe; cfg(unix) UnixStream::shutdown(Both)) so handle_conn reaches existing EOF cleanup, (3) wait for the canceled op to report completion before releasing its buffer (interprocess write_exsync returns only after the completion APC — release = write return), (4) NEVER reuse the conn (a timed-out length-prefixed frame may be partially written), (5) join/finish the retired writer before reporting physical cleanup. Controller (replay + live), viewer, dispatch-reply (send_frame/send_error + inline dispatch_* replies), and nethost stream-log/presence writes ALL route through the primitive — leaving ANY raw unbounded write behind the gate preserves the failure class (grep-proven: no surviving raw send.lock()+write_frame on a physical conn path). NO new output queue (the bounded queue + isolated writer exist; the block is BELOW them); NO PIPE_NOWAIT (recorded mid-frame corruption risk). Broker-side only, no wire change, mixed-version peers wire-compatible; Unix keeps existing semantics under the same poison/retire invariant.
2026-07-17T03:24:38.2238546Z - Required stages: doc, impl, int
2026-07-17T03:24:38.2238897Z 
2026-07-17T03:24:38.2239288Z ### REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE
2026-07-17T03:24:38.2246372Z - Title: MSG-IDENTITY W1 / F-036 leg a (perri field RCA 2026-07-09/10, psyche seat-theft — doyle ACCEPTED primary fix): the daemon MUST sanitize inherited per-session identity env (SPT_ENDPOINT_ID / OWL_SESSION_ID / SPT_AGENT_ID) at startup AND before EVERY role spawn — these are per-session identity and are NEVER correct inherited state for a daemon or its role children. ROOT: a daemon restarted from inside an agent session (routine during core dev / `spt update apply`) carries the session's SPT_ENDPOINT_ID and passes it verbatim to every [session.psyche_resume] spawn; core only strips each role's DECLARED env_remove list (runtime.rs:728), so ONE adapter env_remove miss infects the whole node — every psyche claude turn fires SessionStart, the adapter hook sees the endpoint id, takes the bind path, and ROTATES the victim's perch to the psyche's own sid with a valid prior-sid proof, every pulse (field: lia/deployah/doyle psyches ALL briefed as <sptc-active-perch id=doyle>; 37 peer msgs drained into lia's psyche transcript; victim deliveries eaten, communes dark, sends downgraded from:cli@node). Adapter half FIXED v0.18.8 (env_remove += SPT_ENDPOINT_ID + shim scrub + SPT_PSYCHE_TURN hook-bail) — this REQ is the CORE-LAYER defense so no adapter miss can ever leak identity again. FOLD (F-036 leg b docs-fix, doyle-owned): broaden the recursion_guard_env schema description (manifest.rs:314 + crates/spt-runtime/manifest.schema.json:306) — core honors it on ANY role declaring the field (runtime.rs:740, keyed on the FIELD not the role name); drop the 'summarizer children' wording (perri adopted on both psyche roles v0.18.8, proven live). Gate: a daemon started with SPT_ENDPOINT_ID/OWL_SESSION_ID/SPT_AGENT_ID in its env spawns role children WITHOUT those vars (unit: role-spawn env assembly scrubs the identity set regardless of the role's declared env_remove); KNOWN-HAZARDS entry on landing. Kin psyche-custody/session-pin cluster, [[spt-core-findings-backlog]] F-036.
2026-07-17T03:24:38.2253249Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2253637Z 
2026-07-17T03:24:38.2253922Z ### REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD
2026-07-17T03:24:38.2257412Z - Title: MSG-IDENTITY W1 / F-036 leg c (perri field RCA, doyle ACCEPTED defense-in-depth): a bind whose --set-session-id equals a NESTED psyche perch's own custody sid is definitionally wrong and MUST be refused — core owns psyche-custody.json and can see the collision at bind time. ROOT CONTEXT: with the F-036 env leak, each stolen bind carried a psyche sid as the new pin; the identity-env sanitize (leg a) removes the known vector, this guard makes the CLASS unreachable (any future vector that tries to rotate a real endpoint's perch onto a psyche's custody sid is refused loud). Gate: a bind attempt whose target sid appears in psyche-custody.json as a psyche's OWN sid is REFUSED with a distinct loud token (unit: custody-sid collision refuses; a normal non-custody sid bind is unaffected). Kin REQ-PSYCHE-SID-CUSTODY, session-pin cluster, [[spt-core-findings-backlog]] F-036.
2026-07-17T03:24:38.2260666Z - Required stages: impl, unit
2026-07-17T03:24:38.2261005Z 
2026-07-17T03:24:38.2261281Z ### REQ-CARRIER-CLAIM-EXCLUSIVE
2026-07-17T03:24:38.2267056Z - Title: MSG-IDENTITY W4 / F-033 + operator self-send probe 2026-07-09 (dup-delivery cluster, RCA-FIRST): a spooled message row is delivered by EXACTLY ONE carrier — the first carrier to take a row (hook-poll drain, relay idle-inject, relay-backlog, psyche) atomically CLAIMS it so no other carrier can re-deliver the same row. FIELD EVIDENCE (authoritative, operator-observed): a default-window doyle-to-doyle send while doyle was BUSY delivered on BOTH the busy POLL path AND the idle RELAY path; spool row 156: window='default', delivered=1, taken_leg='idle-inject' — the relay claimed a row a poll also surfaced (REQ-SPOOL-TAKE-AUDIT instrument, already shipped, is the RCA tool: taken_leg/taken_sid/taken_at per row). PRIOR: F-033 (perri 2026-07-08) — the psyche-download filing arrived as TWO copies, dup-delivery live-confirmed. RCA-FIRST (report-before-fix): pin whether the poll drains before/after the relay's delivered=1 mark; whether the busy-to-idle edge re-offers a row a poll already took; whether take-marking is atomic per carrier or check-then-mark racy. DISTINCT from F-035 (that = active_only window honor, spt-core exonerated; THIS = a default msg on both carriers — F-035's lock never asserted a default msg can't ride both). Gate: int — a default send to a BUSY live agent that polls mid-turn AND transitions idle delivers EXACTLY ONCE (spool-audit shows one taken_leg, recipient sees one copy); unit — concurrent take attempts on one row yield one winner. Kin REQ-SPOOL-TAKE-AUDIT, REQ-RELAY-NO-BUSY-DELIVER, REQ-IDLE-PARKED-DELIVERY, [[spt-core-findings-backlog]].
2026-07-17T03:24:38.2272808Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2273163Z 
2026-07-17T03:24:38.2273435Z ### REQ-RELAY-NO-BUSY-DELIVER
2026-07-17T03:24:38.2277716Z - Title: MSG-IDENTITY W4 (operator self-send probe 2026-07-09, companion leg): the relay/idle-inject carrier MUST NOT fire for an ACTIVE endpoint — the daemon already guards send-time (daemon.stderr.log: 'ENDPOINT_INJECT: endpoint ACTIVE -> spool (deferred hint), not injected') yet the field row ended taken_leg='idle-inject' for a message sent while the endpoint was ACTIVE, so the guard is bypassed somewhere on the busy-to-idle EDGE (the parked-drain idle-injects rows that arrived during busy without re-checking whether a poll is concurrently draining them — the edge itself is when BOTH carriers are plausibly live). RCA-FIRST with REQ-CARRIER-CLAIM-EXCLUSIVE (same rig, same instrument); if the exclusive claim alone closes the double-delivery this leg may reduce to an ordering assertion — rule at RCA lock, don't build blind. Gate: unit — the idle-edge drain re-verifies activity (or defers to the claim) before idle-injecting; a row taken by a poll is never idle-injected. Kin REQ-IDLE-PARKED-DELIVERY (the drain this guards), REQ-MSG-IDLE-EDGE-DRAIN, F-023 anti-starvation gate (do NOT break the already-idle delivery class).
2026-07-17T03:24:38.2282187Z - Required stages: unit
2026-07-17T03:24:38.2282512Z 
2026-07-17T03:24:38.2282779Z ### REQ-SEND-STAMP-AGENT-ID
2026-07-17T03:24:38.2287523Z - Title: MSG-IDENTITY W4 / endpoint-identity (operator-flagged 2026-07-09 + live-confirmed on flynn's F-038 ask arriving 'cli@HFENDULEAM'): a live agent's own CLI `spt send <target>` MUST stamp from_id with the AGENT id (e.g. 'doyle'), not the node fallback 'cli@<node>' — today the agent-id stamp rides ONLY the adapter/perch shortform path, so any agent shelling out `spt send` (the DOCUMENTED reach-another-agent form) presents to recipients as an anonymous node CLI: replies mis-route (recipients answer cli@node — no perch — instead of the sender), and the F-036 victim-effect ('sends downgraded to from:cli@node') is indistinguishable from normal CLI traffic. FIX: send-time self-resolve — when the calling process/session maps to a bound live perch on this node (the session-pin/seed machinery already resolves this for bind), stamp that endpoint id as from_id; a genuinely perchless CLI keeps 'cli@<node>'. Gate: unit — a send from a session bound to a live perch stamps the endpoint id; a perchless shell keeps the node stamp; int — recipient's EVENT from= carries the agent id for a shelled-out send from a live session. Kin F-036 victim effects, EVENT envelope (ADR-0020), [[owl-send-not-legacy-spt-send]] (adapter-path stamp works today — this closes the CLI-path gap).
2026-07-17T03:24:38.2292194Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2292551Z 
2026-07-17T03:24:38.2292818Z ### REQ-ENDPOINT-AUTOSTART
2026-07-17T03:24:38.2299372Z - Title: MSG-IDENTITY W5 / F-038 (flynn operator-directed ask 2026-07-10, SPT-CORE-NEEDS #7 + deployah field-confirm same day: mobile-gw alive=false after the v0.30.6 full daemon restart = this feature's absence, live): an endpoint can be marked a STARTUP DEFAULT so the daemon brings it back up at daemon start — Gateway-class endpoints are infra (the phone treats mobile-gw as always-there; box reboot / daemon cold start currently leaves it down until hands-on). SHAPE RULED (doyle, dispatch): (a) `spt endpoint run --save` persists the run (id + adapter/profile + args) as a startup default REPLAYED at daemon start, symmetric with the shipped `subnet attach/detach --save` precedent — smallest orthogonal cut, explicit operator intent, no interaction with effective_rest_state/F-035 reader-parity semantics (shape (c) restore-what-was-up REJECTED for now: principled but couples to the rest_state neighborhood that just churned; revisit if --save proves insufficient in the field). A saved endpoint that fails to come up logs loud + does not block daemon start or other replays. flynn docs sweep confirmed missing-feature not docs-gap (rest/wake manual-only; no endpoint analog of subnet --save; no manifest field; no api surface). Gate: int — daemon restart brings a --save'd endpoint back up (fresh daemon, saved default, endpoint reaches its steady state without hands-on); doc — public docs page for the verb (VERSION-scoped); unit — persistence round-trip + replay skip-on-missing-adapter loud. Kin subnet --save (the symmetry precedent), REQ-LIST-JSON-LIVENESS-PARITY + REQ-HAZARD-BIND-REST-STATE-CARRY (the F-035 neighborhood shape (c) would have coupled to), [[spt-core-findings-backlog]] F-038. Interim on flynn's box (logon scheduled task) dissolves when this lands.
2026-07-17T03:24:38.2305678Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2306040Z 
2026-07-17T03:24:38.2306312Z ### REQ-DAEMON-SERVICE-INSTALL
2026-07-17T03:24:38.2309307Z - Title: F-038 RIDER (flynn nice-to-have, QUEUED not activated): a documented OS-service registration recipe or `spt daemon install-service` verb so the daemon itself survives box reboot (flynn's box runs managed_by:null = daemon-at-boot unprovisioned; kitsubito's hand-rolled systemd --user unit = prior art). NOT in MSG-IDENTITY scope — REQ-ENDPOINT-AUTOSTART covers the daemon-start-to-endpoint leg; the boot-to-daemon leg stays interim (logon scheduled task / systemd unit). Activate at an infra-provisioning milestone; shape (recipe doc vs verb) ruled then. Kin [[daemon-service-detection-gotcha]] (global-OS-state detection blind on dev box — a verb must not regress that), [[kitsubito-linux-rig]].
2026-07-17T03:24:38.2312059Z - Required stages: 
2026-07-17T03:24:38.2312367Z 
2026-07-17T03:24:38.2312647Z ### REQ-CONN-POISON-DIAL-SCOPE
2026-07-17T03:24:38.2319581Z - Title: MSG-IDENTITY W6 / F-039 (deployah field-acceptance follow-up 2026-07-10, RCA-FIRST — mint per the v0.30.6 PASS handoff): ambient CONN_WRITE_POISONED log-churn correlates 1:1 with PUMP_PEER_FAIL submit-dials to OFFLINE peers (enlyzeam/kitsubito/gravity) with NO wedge and NO freeze — pre-existed the blackhole rig = log-noise/mislabel, not a defect in the r4 fix. CODE CONTEXT: conn.rs poison_and_cancel emits the loud CONN_WRITE_POISONED line for a write that 'exceeded its bound (OR FAILED)' (conn.rs:181) — the fast-FAIL branch (broken pipe / conn refused on an already-dead counterpart) shares the log tag with the TIMEOUT branch that is the field-acceptance wedge observable, so routine conn teardown under offline-peer dial churn reads like poison events. RCA-FIRST: pin the exact write site that fails per PUMP_PEER_FAIL cycle (BrokerConn is broker-side — which broker conn write rides each pump dial failure? status/event fan-out to a departed subscriber? brain-side notification?) BEFORE changing anything — the correlation mechanism is unpinned. FIX SHAPE (post-RCA, doyle rules at lock): reserve the loud CONN_WRITE_POISONED token for the DEADLINE-EXCEEDED class (the wedge observable blackhole-controller.ps1 watches); a plain write-FAIL on an already-dead conn retires quietly (debug-level or a distinct low-noise token). MUST NOT weaken the r4 invariant: every failure path still poisons + retires the conn (REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK behavior unchanged — only the log LOUDNESS is scoped). Gate: unit — deadline-exceeded emits the loud token, fast-fail does not (both still poison); field — offline-peer churn no longer floods daemon.stderr.log with CONN_WRITE_POISONED. Kin REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK (the invariant this must preserve), REQ-PUMP-PEER-ISOLATION (the offline-peer dial neighborhood), [[v0306-published]].
2026-07-17T03:24:38.2326294Z - Required stages: impl, unit
2026-07-17T03:24:38.2326637Z 
2026-07-17T03:24:38.2326914Z ### REQ-CONN-POISON-ATTRIBUTION
2026-07-17T03:24:38.2333857Z - Title: MSG-IDENTITY W6 / F-039 legs b-d (doyle W6 LOCK 2026-07-10, minted per amendment 3): every broker-conn lifecycle record is ATTRIBUTABLE — the W6 RCA's terminal undecidability (per-line 1:1 CONN_WRITE_POISONED churn = fresh-carrier churn OR stderr interleave artifact) exists because records carry no stable conn identity, no role/endpoint/session context, and no timestamps, and the once-per-conn poison latch hides multiplicity. THREE LEGS. (b) IDENTITY: mint a stable per-physical-conn id (monotonic u64 at conn construction — Arc::ptr_eq is the only identity today and it does not survive a log line) plus subscriber role and endpoint/session where known, stamped on CONN_WRITE_POISONED, CONN_WRITE_RETIRED, logical stall-evict, attach/resume/detach, and write-retirement records (RCA attach sites: presence nethost.rs:379, stream nethost.rs:258, controller broker.rs:891, viewer broker.rs:1073). (c) TIME: daemon stderr correlation records carry wall-clock AND monotonic timestamps (stderrlog has neither; broker+brain share one file — interleave is unresolvable without them). (d) LIFECYCLE (doyle-confirmed UNCONDITIONAL, not debug-gated): one BOUNDED set of per-conn lifecycle events — write start/timeout-cancel/transport close/writer exit/replacement-reattach (hertz RCA fix-shape items 1-3). Constraint (doyle LOCK): the split/attribution must not REDUCE total information, only correct its attribution; NO timeout-value changes; NO suppression-as-fix. Gate: unit — lifecycle records carry conn id + role + timestamps; the id is unique per physical conn and stable across that conn's records. Kin REQ-CONN-POISON-DIAL-SCOPE (leg a, the token split these fields ride on), REQ-CONN-BLACKHOLE-LIFECYCLE-HARNESS (leg e, consumes these records), REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK (behavior invariant preserved).
2026-07-17T03:24:38.2340452Z - Required stages: impl, unit
2026-07-17T03:24:38.2340791Z 
2026-07-17T03:24:38.2341077Z ### REQ-CONN-BLACKHOLE-LIFECYCLE-HARNESS
2026-07-17T03:24:38.2345404Z - Title: MSG-IDENTITY W6 / F-039 leg e (doyle W6 LOCK 2026-07-10, minted per amendment 3 — hertz's five invariants VERBATIM from his RCA fix-shape item 5): 'Build a deterministic black-holed-controller harness against current v0.30.6 semantics and assert: unrelated sessions continue; the bad physical connection is canceled/closed within the bound; its writer exits; a fresh viewer can attach; no lock or task remains owned by the retired connection.' The harness is the standing conformance rig for the r4 SHAREDSEND fix-class — hertz's RCA discipline: only after a timestamped incident maps to a FAILING lifecycle invariant does an ownership/cancellation defect get fixed (the likely shape being complete physical-connection cancellation and writer-task join/retirement, never a broader timeout increase). Consumes REQ-CONN-POISON-ATTRIBUTION's records (conn id + lifecycle events are what make the five assertions checkable deterministically). Kin REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK (the invariant class under test — its brain_decouple int stays the Windows-mandatory gate leg), REQ-CONN-POISON-DIAL-SCOPE.
2026-07-17T03:24:38.2349731Z - Required stages: int
2026-07-17T03:24:38.2350049Z 
2026-07-17T03:24:38.2350313Z ### REQ-UPDATE-GH-TRANSPORT
2026-07-17T03:24:38.2355311Z - Title: THE-FORKENING W1 (ADR-0036, operator-ruled 2026-07-14): the release channel is PRIVATE (`BigscreenVR/spt-bs-releases`) and the gh CLI is the mandated carrier — release discovery (`releases/latest`, cli.rs:9717) and asset download (cli.rs:4861 public browser URLs) move to deadline-wrapped `gh` subprocess calls (`gh api`, `gh release download`; run_git pattern). WHY gh not token+HTTP: private-repo `browser_download_url` 404s even with a valid token — the API asset-id dance is gh's job. Default repo flips via the existing SPT_INSTALL_REPO seam (cli.rs:5363) + xtask REPO const (main.rs:729) + notif.rs consent-changelog URL rider. Loud failure classes: gh missing -> UPDATE_FETCH_REJECTED:GhCliRequired with OS-SPECIFIC install hints (winget/apt/brew); gh unauthed -> distinct GhAuthRequired pointing at `gh auth login`. Signature verification unchanged — bytes verified after download, carrier-independent (update-set/counter/anchor continuity per ADR-0036 §2). release_verify_e2e reworked to the gh carrier. Gate: unit — url/invocation construction + both failure classes render OS-correct hints; int — fetch against a real gh-authed channel resolves latest + downloads and verifies an asset; doc — self-update docs name the gh prerequisite. Kin REQ-INSTALL-BOOTSTRAP-VERB (same carrier at first install), ADR-0036.
2026-07-17T03:24:38.2360690Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2361057Z 
2026-07-17T03:24:38.2361357Z ### REQ-INSTALL-BOOTSTRAP-VERB
2026-07-17T03:24:38.2366162Z - Title: THE-FORKENING W1 (ADR-0036 §3, bootstrap shape b operator-ruled): virgin-box install = `gh release download` the platform binary + ONE self-install verb in the binary itself — the verb places the binary at the canonical install path (the path self-update already respawns from, v0.4.2 lesson), registers user PATH, and leaves first-run identity/daemon-start to the existing idempotent first-run; hosted one-liner install scripts (curl|sh / irm|iex at the dead Pages URL) are RETIRED. Non-interactive (CONTEXT.md Installation: the install path doubles as every adapter's pack-in on-demand install). Windows UAC-740 gotcha binding: the downloaded exe keeps the `spt-*` asset name and the verb lives INSIDE spt — no installer-detection trigger words in exe names. README (bs-core) documents: install gh -> gh auth login -> gh release download -> the verb. Gate: unit — verb places/registers idempotently, refuses cross-platform binaries (platform-stamp check exists, v0.3.2); int — from a clean SPT_HOME+PATH sim, downloaded-binary self-install yields a working `spt` on PATH whose `spt update fetch` then speaks the gh channel; doc — README install section rewritten. Kin REQ-UPDATE-GH-TRANSPORT, REQ-INSTALL-1/2 (the two-paths model this reshapes), ADR-0036.
2026-07-17T03:24:38.2370927Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2371298Z 
2026-07-17T03:24:38.2371584Z ### REQ-DOCS-RELEASE-ASSET
2026-07-17T03:24:38.2375010Z - Title: THE-FORKENING W2 (ADR-0036 §4): every release ships a platform-independent docs bundle `spt-docs.tar.gz` (BUILT mdbook output: HTML + llms.txt + llms-full.txt + raw .md + manifest.schema.json) as a release asset WITH an entry in the SIGNED update-set (sha256, same integrity chain as binaries — docs describe the security-relevant contract surface, they do not ride unverified). Apply lands/refreshes $SPT_HOME/docs (single current copy = docs always match the installed binary). FAILURE ISOLATION binding: a docs-asset failure NEVER fails the binary update — UPDATE_DOCS_SKIPPED loud, retried next fetch. Gate: unit — update-set entry + sha256 verify + skip-loud isolation; int — a fetch+apply lands version-matched docs at $SPT_HOME/docs; doc — self-update docs name the bundle. Kin REQ-DOCS-LOCAL-SERVER (the consumer), REQ-RELEASE-CHANNEL-PRIVATE (the assemble leg), ADR-0036.
2026-07-17T03:24:38.2378243Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2378598Z 
2026-07-17T03:24:38.2378880Z ### REQ-RELEASE-CHANNEL-PRIVATE
2026-07-17T03:24:38.2381877Z - Title: THE-FORKENING W2 (ADR-0036 §2): the publish pipeline targets `BigscreenVR/spt-bs-releases` — release.yml assemble/draft/flip retargeted (draft lands on the bs releases repo, untagged, per the existing spt-releases pattern); docs-publish.yml RETIRED (no public docs, ADR-0014 superseded) with the mdbook build folded into ci.yml as the drift gate (CLAUDE.md mandate: doc generation stays CI-gated); counter + signing key + update-set format CONTINUE unchanged (trust anchor is the continuity, carrier is not). Gate: impl — workflow retarget + drift-gate fold; int — a full release dry-run assembles binaries + docs asset + signed update-set against the private channel. Kin REQ-DOCS-RELEASE-ASSET, REQ-UPDATE-GH-TRANSPORT, ADR-0036.
2026-07-17T03:24:38.2384697Z - Required stages: impl, int
2026-07-17T03:24:38.2385059Z 
2026-07-17T03:24:38.2385355Z ### REQ-DOCS-LOCAL-SERVER
2026-07-17T03:24:38.2390584Z - Title: THE-FORKENING W3 (ADR-0036 §4, operator-ruled crate-over-handroll + port 5474): the daemon (broker side — docs are up whenever the daemon is) serves $SPT_HOME/docs over HTTP on LOOPBACK ONLY, default 127.0.0.1:5474 (+ ::1 where available; 547 rejected — privileged <1024 breaks the Linux user-daemon + IANA dhcpv6-server), config + env override. Implementation = hyper (ALREADY in-tree via iroh/reqwest — zero new supply chain; operator ruled battle-tested crate over hand-rolled HTTP). GET-only; strict path-sanitize under $SPT_HOME/docs (reject .., absolute, encoded traversal); bounded write discipline (conn-hazard class). Published URL surface preserved VERBATIM (llms.txt contract: /llms-full.txt, append-.md raw, /manifest.schema.json — flynn/perri doc habits must not break). Verbs: `spt docs url` prints the resolved URL honoring overrides; bare `spt docs` opens the system browser (cfg(windows) creation_flags no-console). NEVER 0.0.0.0 — a LAN-visible server re-leaks what privating hid. Gate: unit — path-sanitize rejections + content-type map + loopback-only bind config; int — daemon up serves book index + llms-full.txt + a raw .md byte-true from a landed bundle; doc — CONTEXT.md Docs Server entry + docs-site self-reference updated (site-url). Kin REQ-DOCS-RELEASE-ASSET (the producer), ADR-0036, translation-binary console-window gotcha.
2026-07-17T03:24:38.2395778Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2396186Z 
2026-07-17T03:24:38.2396492Z ### REQ-UPDATE-ADAPTERS-VERB
2026-07-17T03:24:38.2400033Z - Title: THE-FORKENING W4 (operator-grilled 2026-07-14): `spt update adapters [<a>[,<b>...]]` = thin ALIAS over the existing `spt adapter update` engine (cli.rs:748 gh_release avenue; the old verb STAYS — published surface) + comma-list accepted on BOTH forms. Semantics: no names -> all gh_release-avenue registrations; names validated FAIL-FAST against the registry BEFORE any update starts (a typo must not leave a half-updated set); per-adapter failure ISOLATION (one failure doesn't stop the rest) with a per-adapter summary line; nonzero exit if any failed; local-path/dev registrations SKIP loud (not error). Gate: unit — name validation, list parsing, isolation + exit-code aggregation, local-path skip; doc — reference regen (drift-gated). Kin REQ-UPDATE-DEFAULT-COMPOSITE (the caller), REQ-ADAPTER-UPDATE-MESSAGE (per-adapter apply notices ride the summary).
2026-07-17T03:24:38.2403155Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2403513Z 
2026-07-17T03:24:38.2403795Z ### REQ-UPDATE-DEFAULT-COMPOSITE
2026-07-17T03:24:38.2410288Z - Title: THE-FORKENING W4 (operator-grilled 2026-07-14): plain `spt update` = `update fetch --apply` THEN `update adapters` (core-first doctrine order); when core is already current the core leg no-ops and ONLY adapters update; `--core-only`/`-c` skips the adapters leg. GROUNDING (operator-corrected, code-confirmed): fetch --apply cycles the BRAIN only — broker + PTYs survive (apply_staged applyhost.rs:303; the restart-required text is a NOTICE, cli.rs:4615, not behavior) — so the composite's invoking process survives by construction and NO re-run machinery is needed; on a broker-side release the existing F-025 notice remains the composite's closing output. Gate: unit — composite sequencing incl. already-current -> adapters-only and --core-only skip; int — composite on a staged release applies core then updates a registered adapter in one invocation; doc — reference + self-update docs present plain `spt update` as the primary form. Kin REQ-UPDATE-ADAPTERS-VERB, REQ-UPDATE-RESTART-SAFE-SWAP, REQ-UPDATE-APPLY-RESTART-NOTICE.
2026-07-17T03:24:38.2414698Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2415069Z 
2026-07-17T03:24:38.2415358Z ### REQ-UPDATE-RESTART-SAFE-SWAP
2026-07-17T03:24:38.2425367Z - Title: THE-FORKENING W4 (operator-grilled 2026-07-14; RETIRES findings-backlog seed #12 REQ-UPDATE-ONE-STEP-SAFE-SWAP): `spt update --restart` = the one-step ergonomic path to the SAFE full-cycle swap — fetch -> `update adapters` -> `apply --finish` LAST (lethal-leg-last, ruled: apply --finish restarts the whole daemon incl. broker/PTYs, so it must be the final act — everything completes from ANY invoking context including an spt-hosted session whose PTY dies at that step; accepted cost: a finish FAILURE leaves updated adapters on old-activated core briefly — loud + operator-attended by nature of the flag). Composes with `-c/--core-only` (skip adapters leg). The 0.28.0 wedge lesson closes: the ergonomic one-step no longer picks the riskier path by default for operators who want the full cycle. Gate: unit — flag sequencing incl. lethal-leg-last ordering + -c compose; doc — self-update docs present --restart as the full-cycle form and name the finish-restart consequence. Kin REQ-UPDATE-DEFAULT-COMPOSITE, REQ-UPDATE-FINISH-COMMUNE-FLUSH (deferred commune-flush rides the same finish path when built), seed #12 (retired by this).
2026-07-17T03:24:38.2429991Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2430358Z 
2026-07-17T03:24:38.2430626Z ### REQ-DAEMON-REFRESH
2026-07-17T03:24:38.2434741Z - Title: THE-FORKENING W4 (operator add 2026-07-14): `spt daemon refresh` — restart the daemon BRAIN without a binary swap and WITHOUT touching the broker: exactly the apply_staged brain-cycle path (brain stop -> respawn -> readiness trial -> promote, incl. the trial-drain drive REQ-UPDATE-TRIAL-DRAIN-DRIVE and viewer-only resume REQ-BRAIN-RESUME-NO-CONTROL-STEAL) minus the swap. Recovery verb for wedged brain-held state (field motivator 2026-07-14: endpoint bringup broken on a live daemon + deployah down — today's only remedy is a full daemon bounce that kills every PTY). Broker + PTYs survive by construction (handoff invariant). Failure = the existing trial rollback semantics (old brain resumes; refresh reports loud). Gate: unit — verb routes the brain-cycle without staging/swap preconditions; int — refresh on a live daemon with a hosted PTY: brain generation changes, PTY survives, endpoint stays attached; doc — daemon docs name refresh next to stop/start. Kin apply_staged (the path it reuses), REQ-UPDATE-TRIAL-DRAIN-DRIVE, REQ-BRAIN-RESUME-NO-CONTROL-STEAL.
2026-07-17T03:24:38.2438925Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2439373Z 
2026-07-17T03:24:38.2439679Z ### REQ-WHOAMI-IDENTITY-ONLY
2026-07-17T03:24:38.2443681Z - Title: PROJECT-INDEX W1 (F-040, perri filing claude-spt docs/SPT-CORE-FINDINGS.md @d775b38; correctness-critical opener — the 2026-07-15 message-bodies incident root): a core IDENTITY-ONLY resolution — session -> endpoint|null — that touches NO list/registry/project/git/network path, and `spt whoami` DE-ALIASED from cmd_endpoint_list (cli.rs ~6609 aliases the full list = 100+ git children under hook deadlines). endpoint-info is DISQUALIFIED as the carrier (runs latest_project_ref). Adapters/hooks get a bounded-time identity verb; the harness-hosted adapter fallback stays deadline-vulnerable until this ships. Gate: impl — the resolver + whoami de-alias; unit — resolver returns endpoint|null with zero project derivation (assert no git spawn seam); int — whoami on a multi-perch home answers fast-path without touching context branches; doc — harness-contract api.md names the identity verb + its no-derivation bound. Kin REQ-PROJECT-INDEX-READER-CUTOVER (list-shaped verbs), REQ-WHOAMI-1, docs/PROJECT-INDEX-TRIAGE.md.
2026-07-17T03:24:38.2447738Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2448110Z 
2026-07-17T03:24:38.2448382Z ### REQ-PROJECT-INDEX-STORE
2026-07-17T03:24:38.2451631Z - Title: PROJECT-INDEX W1 (ADR-0037, RCA .claude/reports/2026-07-10-hertz-session/03): spt-store owns the VERSIONED materialized project-index format + read path. Reader contract: read one compact versioned index, join with the local perch roster, return immediately; stale/missing renders last-known-good or '-'; NEVER fall back to synchronous git enrichment; daemon-offline readers consume the last persisted snapshot; truncated/schema-mismatched index degrades to fast reads + last-known-good, never an error stall. Gate: impl — format + store read path; unit — version/schema-mismatch/truncation degradation legs + join semantics; doc — CONTEXT.md project-index entry + STORAGE.md section. Kin REQ-PROJECT-INDEX-WRITER (the producer), ADR-0037.
2026-07-17T03:24:38.2454378Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2454726Z 
2026-07-17T03:24:38.2455008Z ### REQ-PROJECT-INDEX-WRITER
2026-07-17T03:24:38.2459716Z - Title: PROJECT-INDEX W2 (ADR-0037): the daemon is the SOLE single-flight project-index writer: load persisted index at startup; ready WITHOUT warm (cold start = daemon ready + CLI fast before background completes); background reconcile with BATCHED complexity O(P+B+F+C) — enumerate branches ONCE, <=1 tree scan per changed branch, ONE derivation per distinct normalized cwd (in-process BranchStore traversal or fixed plumbing calls; backgrounding the existing 100+ process loop is REJECTED); atomic replace; last-known-good preserved on any failure; warm start with unchanged generation performs NO scan. Observability surface: generated time, source generation, pending refresh, last duration/error, endpoint/project/cwd counts, cache hits/misses, stale reads, repair count — index presence alone is not health. Gate: impl — writer + observability; unit — single-flight, atomic-replace, last-known-good, no-scan-on-unchanged-generation; int — cold+warm start legs against a real store; COMPLEXITY COUNTERS are the CI gate (wall-clock = manual acceptance ONLY, shared-runner flake class); doc — daemon docs writer-duty section. Kin REQ-PROJECT-INDEX-STORE, REQ-PROJECT-INDEX-INVALIDATION.
2026-07-17T03:24:38.2464253Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2464615Z 
2026-07-17T03:24:38.2464892Z ### REQ-PROJECT-INDEX-INVALIDATION
2026-07-17T03:24:38.2468596Z - Title: PROJECT-INDEX W2 (ADR-0037): event-driven index invalidation, debounced + coalesced: new session/cwd -> refresh that endpoint + the shared cwd cache; context-store mutation -> ONE debounced global membership refresh keyed on BRANCH-TIP FINGERPRINTS (no authoritative context-commit path exists — a writer-maintained generation counter is REJECTED because nothing maintains it); bind/start, rename, fork, purge -> affected endpoint rows; low-frequency periodic reconcile as the backstop; cwd identity refresh ONLY on path/repo-identity/.git-config change (ordinary commits do NOT alter project identity); multiple invalidations coalesce into one refresh. Gate: impl — the event set + debounce/coalesce; unit — each event class maps to its refresh scope + coalescing proof + ordinary-commit no-op; int — session/context/rename/fork/purge invalidation against a live daemon; doc — rides the ADR + triage doc. Kin REQ-PROJECT-INDEX-WRITER.
2026-07-17T03:24:38.2472046Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2472446Z 
2026-07-17T03:24:38.2472732Z ### REQ-PROJECT-INDEX-READER-CUTOVER
2026-07-17T03:24:38.2476981Z - Title: PROJECT-INDEX W3 (ADR-0037): endpoint list, the picker, and endpoint-info consume the materialized index — NO git work in any user-facing read path (the O(PxB+C) fanout at cli.rs ~2954 / picker/data.rs ~456-518 dies). BEHAVIORAL PARITY is binding: precedence session-cwd -> origin-cwd -> context-recency and rendered project IDs/display names unchanged (parity suite vs the old derivation on a fixture); bare/partial run shares the indexed projection; fully-qualified --adapter+--id direct run stays picker-free; the direct-run 25s broker-session gate stays separately tested/observable. Degradation legs (git unavailable, branch malformed/locked, cwd deleted) keep fast reads. Manual latency acceptance on the 13-perch/7-branch fixture (~30s -> sub-second) + hertz field-verify on HFENDULEAM — NOT a CI wall-clock gate. Gate: impl — reader cutover; unit — parity + degradation; int — list/picker against a daemon-maintained index incl. counters proving zero reader git spawns; doc — reference regen + CONTEXT avoid-list. Kin REQ-WHOAMI-IDENTITY-ONLY, REQ-PROJECT-INDEX-STORE/WRITER/INVALIDATION.
2026-07-17T03:24:38.2481401Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2481761Z 
2026-07-17T03:24:38.2482028Z ### REQ-CI-DOCS-ONLY-THIN
2026-07-17T03:24:38.2485238Z - Title: CI (operator-ruled 2026-07-16, from PR #8 review): a PR whose ENTIRE diff is Markdown OUTSIDE docs-site/ runs THIN CI — the heavy build/test jobs (test, n1-gate) are skipped via a changed-files classifier job. Invariants: the traceability gate ALWAYS runs (doc tags in .md files are load-bearing evidence, and a run with zero checks is unmergeable); any docs-site/ change runs the FULL pipeline (the CLI-ref/llms/book drift gates ride the test job); push events (main) always run full. The classifier is plain git diff over the PR merge commit (HEAD^1..HEAD, fetch-depth 2) — no third-party changed-files action on the self-hosted runners. Skipped-required-check note: GitHub treats an if-skipped job as satisfying required status checks, and the classifier + traceability always report, so thin PRs stay mergeable.
2026-07-17T03:24:38.2488253Z - Required stages: impl
2026-07-17T03:24:38.2488568Z 
2026-07-17T03:24:38.2488859Z ### REQ-HAZARD-REDISPATCH-CONTROL-STEAL
2026-07-17T03:24:38.2493138Z - Title: REDISPATCH-TRUTH W1 (KNOWN-HAZARDS 7.41, hertz field RCA 2026-07-16 — 4/5 endpoints frozen per brain cycle): a fresh dispatcher must NEVER re-serve a terminal stream — a replayed historical Attach must not steal (same-identity silent become_controller, no Displaced) or clear (replayed-EOF detach_session) a LIVE controller. The legitimate same-by successor re-take after a brain restart still silently re-takes: the discriminator is stream LIFECYCLE, never origin identity. Gate: int — production-path regression D1: finished historical Attach + current active Attach, same endpoint/origin; restart target brain only (real run_dispatch_loop rediscovery, NO manual re-serve — the pre-fix e2e bypass is the lesson); prove the historical stream neither takes nor clears the current controller and current input/output stays exactly-once without detach; doc — KNOWN-HAZARDS 7.41. HEAVY nextest group at birth (FLAKE-LEDGER #15). Kin REQ-REDISPATCH-FINISHED-RETIRE (the mechanism), REQ-BRAIN-RESUME-NO-CONTROL-STEAL (the CLOSED session-cursor sibling — different leg), ADR-0038.
2026-07-17T03:24:38.2497296Z - Required stages: doc, int
2026-07-17T03:24:38.2497648Z 
2026-07-17T03:24:38.2497931Z ### REQ-REDISPATCH-FINISHED-RETIRE
2026-07-17T03:24:38.2502000Z - Title: REDISPATCH-TRUTH W1 (ADR-0038, hertz fix A): finished/terminal stream rows are RETIRED from redispatch eligibility — NetShared.streams today has NO removal path (single insert nethost.rs ~649; StreamLog::finish only marks) so every dispatcher generation re-enumerates every historical stream forever. Retire terminal rows from the enumeration the dispatcher claims from (remove, or lifecycle-exclude), preserving only the post-EOF state genuinely needed by other readers (presence/log reads); bounded growth replaces forever-discoverable rows. Clearing the whole table on brain restart is REJECTED (destroys live streams' reconstruction facts). Gate: impl — the retirement path; unit — a finished stream is invisible to the dispatch enumeration while an active one stays claimable + post-EOF reader state survives retirement; doc — rides ADR-0038 + the triage doc. Kin REQ-HAZARD-REDISPATCH-CONTROL-STEAL (the invariant it satisfies), REQ-STREAM-OPENER-DURABLE.
2026-07-17T03:24:38.2505554Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2505911Z 
2026-07-17T03:24:38.2506188Z ### REQ-STREAM-OPENER-DURABLE
2026-07-17T03:24:38.2510972Z - Title: REDISPATCH-TRUTH W1 (ADR-0038, hertz fix B): stream classification identity is RESTART-DURABLE and independent of the evictable data ring — today reconstruction classifies via peek_first_line from ring seq 0, but StreamLog is a bounded 4096-transport-chunk ring (DEFAULT_STREAM_RING_CHUNKS, nethost.rs:111), so a high-traffic ACTIVE stream's opener/Request record evicts and replay classifies Unknown/Failed = active stream permanently abandoned. Pin an immutable bounded opener/classification fact (the complete first NDJSON record, or its derived family+cursor facts) OUTSIDE the data ring per broker-held inbound stream, held until stream close; recovery classifies from that metadata, never ring seq 0. Ring semantics and size untouched (enlarging the ring for a correctness fact is REJECTED). Gate: impl — the pinned opener fact + classification cutover; unit — classification survives full ring roll-over; int — production-path regression D2: push >4096 transport chunks on an active Attach (opener evicted), restart dispatcher, prove durable classification resumes the SAME operator stream. HEAVY nextest group at birth. Kin REQ-DISPATCH-CLAIM-RETRY, REQ-HAZARD-REDISPATCH-CONTROL-STEAL.
2026-07-17T03:24:38.2515474Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2515819Z 
2026-07-17T03:24:38.2516100Z ### REQ-DISPATCH-CLAIM-RETRY
2026-07-17T03:24:38.2519952Z - Title: REDISPATCH-TRUTH W1 (ADR-0038, hertz fix C): dispatcher claims are RETRYABLE and outcomes are CLASSIFIED — today claimed.insert(stream_id) happens PRE-spawn (dispatch.rs:206/214) and is never cleared or retried on Unknown/Failed, so one transient worker-setup failure permanently abandons the stream. Distinguish active/retryable vs served vs finished: a transient worker-setup failure releases/requeues the claim (bounded/backoff-shaped); terminal classification outcomes stay terminal and do NOT hot-loop (show the distinction in test, not just code). Gate: impl — claim lifecycle; unit — transient failure requeues + terminal outcome does not (no hot-loop under a persistently-failing stream); int — production-path regression D3: inject ONE transient worker-start failure, prove claim retry recovers the stream with NO duplicate controller/output. HEAVY nextest group at birth. Kin REQ-REDISPATCH-FINISHED-RETIRE, REQ-STREAM-OPENER-DURABLE.
2026-07-17T03:24:38.2523444Z - Required stages: impl, unit, int
2026-07-17T03:24:38.2523785Z 
2026-07-17T03:24:38.2524074Z ### REQ-HAZARD-MESH-BOOTSTRAP-TRAP
2026-07-17T03:24:38.2528477Z - Title: MESH-RECOVERY W1 (KNOWN-HAZARDS 7.42, hertz field RCA 2026-07-10 — HFENDULEAM+ENLYZEAM symmetric green-status sequester): a node holding a valid RosterEntry.address for a peer is NEVER route-less — a failed dial must not delete the only bootstrap route, and recovery must never require an already-successful connection or operator state surgery. Today: resolve_submit_addr = exact cache else id-only (never roster), PRESENCE_DIAL_FAILED unconditionally drop_seed's the cache row, and the cache refills only after a successful seed-proof exchange — one transient + stalled discovery = self-sustaining isolation, invisible (net_up true, heartbeat fresh, durable counts normal). Gate: int — production-path regression at the REAL pump resolver/failure-lifecycle seam: valid roster + matching cache, ONE transient dial failure, id-only discovery DISABLED, prove the next attempt still holds the roster-derived route AND all-peer-fail-then-restore converges with zero state surgery; doc — KNOWN-HAZARDS 7.42. HEAVY nextest group at birth if it spawns a daemon tree. Kin REQ-PEER-ROUTE-CHAIN (the mechanism), REQ-CONV-1 (the falsified drop-on-fail predecessor), ADR-0039.
2026-07-17T03:24:38.2533003Z - Required stages: doc, int
2026-07-17T03:24:38.2533336Z 
2026-07-17T03:24:38.2533598Z ### REQ-PEER-ROUTE-CHAIN
2026-07-17T03:24:38.2538770Z - Title: MESH-RECOVERY W1 (ADR-0039, RCA wave 1): dial-address resolution is the ROUTE CHAIN — exact peer-cache entry, then VALIDATED RosterEntry.address (address.id must match the peer key; a poison row never becomes a route), then id-only discovery — always fully consulted in order (no failure-count heuristics gating legs; rotation machinery REJECTED). Retention is NONDESTRUCTIVE: PRESENCE_DIAL_FAILED demotes the cached route to suspect (skipped in favor of the roster leg while suspect, superseded by any validated fresher address from connect write-back or reconcile), never deletes a sole route; removal only via validated-fresher replacement or roster tombstone. Validated roster addresses RECONCILE into the cache at daemon startup and on roster merge (beyond gapfill's fill-only: validated-fresher replaces failed/suspect rows) — recovery is connection-independent. Amends REQ-CONV-1's drop-on-fail mechanism; peeraddrs.rs/pump doc-comment truth rides the same change. Gate: impl — chain + demote + reconcile; unit — chain order incl. id-mismatch roster row resolves nothing + suspect row survives N failures with no replacement + reconcile replaces suspect with validated-fresher; int — rides REQ-HAZARD-MESH-BOOTSTRAP-TRAP D-legs; doc — ADR-0039 + CONTEXT peer-route chain entry. Kin REQ-PEERADDR-INVARIANT, REQ-CONV-1.
2026-07-17T03:24:38.2543829Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2544193Z 
2026-07-17T03:24:38.2544469Z ### REQ-PEERADDR-INVARIANT
2026-07-17T03:24:38.2548471Z - Title: MESH-RECOVERY W1 (ADR-0039, RCA wave 2): the peer-addrs cache INVARIANT — outer peer key == address.id — is ENFORCED on load and on write: invalid rows are repaired from the current roster when possible, rejected (dropped loudly) otherwise; never silently kept, never used as a route. MIGRATION = rebuild invalid rows from roster on first post-upgrade load; bare-deleting peer-addrs.json is REJECTED (cold recovery depends on the id-only path staying BEHIND warm routes — nuking every warm route trades one trap for another). gapfill_peeraddrs and PeerAddrStore::put stop accepting mismatched mappings (the live 5ff…-outer poison-row class on both incident nodes). Absent/corrupt-degrades-empty behavior untouched. Gate: impl — load/write enforcement + repair + migration; unit — mismatch rejected on put, repaired-or-dropped on load, valid rows untouched by migration, gapfill refuses a mismatched roster entry; doc — ADR-0039. Kin REQ-PEER-ROUTE-CHAIN, REQ-MESH-2 (gapfill), REQ-CONV-1.
2026-07-17T03:24:38.2552205Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2552561Z 
2026-07-17T03:24:38.2552830Z ### REQ-PUMP-STAGE-TRUTH
2026-07-17T03:24:38.2557471Z - Title: MESH-RECOVERY W1 (ADR-0039, RCA wave 3 — the acceptance surface, same contract): peer-failure telemetry is STAGE-SPLIT and health is USER-MEANINGFUL. The single 10s PUMP_PEER_FAIL token splits into attributed stages — address-resolution, QUIC connect, ALPN, seed-proof send, seed-proof receive/verify, roster exchange — each failure stamped (wall+mono) and peer-attributed (subsumes the 2026-07-14 PUMP_PEER_FAIL-unstamped seed). daemon status / subnet status report: live peer count, last successful peer dial, last admitted registry update, duration of any all-peer failure; the incident fingerprint (all dials failing + heartbeat fresh + net_up true) MUST render degraded — no green without real peer progress. New fields ADDITIVE (N-1 readers unaffected). Gate: impl — stage split + status surfaces; unit — stage classification + health state machine (degraded on all-peer failure, healthy only on real progress, not on heartbeat/time); int — health flips degraded/healthy across a real peer outage/restore; doc — reference regen (CLI surface change → xtask gen, no internal codes in clap help). Kin REQ-PEER-ROUTE-CHAIN, REQ-DAEMON-5 (heartbeat — answers liveness, not reachability), REQ-CLI-2/REQ-SUBNET-8 (render legs).
2026-07-17T03:24:38.2562202Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2562568Z 
2026-07-17T03:24:38.2562850Z ### REQ-HAZARD-REDISPATCH-STALL
2026-07-17T03:24:38.2567711Z - Title: REDISPATCH-STALL W1 (KNOWN-HAZARDS 7.43, hertz v0.34 field RCA 2026-07-16 — recurrent 20-30s PTY/RC freezes, 17-62s DISPATCH tails): one wedged stream subscriber must NEVER stall stream serving, and recovery machinery must not manufacture new replay victims. Today: claim retries x the broad Err(_) opener fallback (dispatch.rs:414) install throwaway peek subscribers whose StreamLog::attach replays the entire retained ring UNDER the per-stream mutex with discarded write errors and the poisoned subscriber left installed — serial 15s bounded-write poison windows (33 observed, all 15,000-15,154ms) composing into the field stalls. Gate: int — production-path regression at the REAL run_dispatch_loop + StreamLog + serve_attach seams: wedge one subscriber conn, prove producer appends and unrelated streams stay flat while the poisoned subscriber is removed and the stream recovers (no abandonment); doc — KNOWN-HAZARDS 7.43. Binding: redispatch D1/D1b stay green every leg. HEAVY nextest group at birth. Kin REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE + REQ-DISPATCH-FALLBACK-CIRCUIT (the mechanisms), REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK (the deadline that fires), ADR-0038 Amendment.
2026-07-17T03:24:38.2572381Z - Required stages: doc, int
2026-07-17T03:24:38.2572710Z 
2026-07-17T03:24:38.2572992Z ### REQ-DISPATCH-FALLBACK-CIRCUIT
2026-07-17T03:24:38.2577590Z - Title: REDISPATCH-STALL W1 (ADR-0038 Amendment, fixes 1+5): the opener ring-peek fallback fires ONLY on the explicit UnsupportedVerb/old-broker answer — transport timeout/EOF/poison classify Failed and requeue bounded, NEVER a second replay subscriber (today first_line's Err(_) arm at dispatch.rs:414 catches everything; the comment intends old-broker-only). Retries are CLASSIFIED: pre-setup transient may retry; a deadline-poisoned replay is CIRCUIT-BROKEN (global backoff) and a replacement subscriber is never installed until the prior subscriber is fully gone. NOT a revert to the v0.33 burn-the-claim abandonment (rejected): the stream must recover after the breaker window — show it in test. Gate: impl — narrowed fallback arm + breaker; unit — timeout/EOF/poison never reach the peek path while unsupported-verb does + breaker trips and resets + no-reinstall-until-gone; int — T2 (no peek subscriber created on transport errors) + T5 (breaker recovery, the not-abandonment discriminator) + T7 mixed-image N-1 with REAL traffic-carrying streams (handshake-only insufficient); doc — ADR-0038 Amendment. Kin REQ-DISPATCH-CLAIM-RETRY (upgraded, not reverted), REQ-STREAM-OPENER-DURABLE (the N-1 window it narrows).
2026-07-17T03:24:38.2582369Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2582731Z 
2026-07-17T03:24:38.2583022Z ### REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE
2026-07-17T03:24:38.2588198Z - Title: REDISPATCH-STALL W1 (ADR-0038 Amendment, fixes 2+3+4): StreamLog subscriber write discipline — (a) replay and live fan-out HALT at the first failed subscriber write and the failed subscriber is REMOVED, at ALL sites (attach replay, append, finish; PresenceLog mirrors ride the same change — today let _ = sub.write() discards errors and iteration continues, nethost.rs:322-346); (b) subscriber I/O moves OFF the StreamLog mutex: bounded per-subscriber writer queue, enqueue-under-lock / I/O-outside, overflow = detach + resume-from-cursor (the existing gapless-resume contract), never a producer stall; (c) attach worker completion + forwarding BOUNDED and cancelable — a poisoned brain subscriber cancels its paired serve/wire worker, no orphan forwarding legs (COORDINATE with DAEMON-LIFECYCLE C2 leases at build — same neighborhood, build once). Gate: impl — halt+remove all-sites + writer queue + cancelable pairing; unit — halt-at-first-failure removes the subscriber at each site + queue overflow detaches with cursor intact + producer append never blocks past enqueue; int — T1 (poisoned-replay halt) + T3 (producer latency flat under a wedged subscriber) + T4 (paired worker canceled on poison); doc — ADR-0038 Amendment. Kin REQ-HAZARD-REDISPATCH-STALL, REQ-CONN-POISON-ATTRIBUTION (the telemetry that caught it), REQ-EP-4 (PresenceLog contract unchanged above the write leaf).
2026-07-17T03:24:38.2593487Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2593854Z 
2026-07-17T03:24:38.2594192Z ### REQ-SERVE-OWNERSHIP-GENERATION
2026-07-17T03:24:38.2598325Z - Title: REDISPATCH-STALL W1 (ADR-0038 Amendment, fix 6): terminal-exclusion enforced PRE-SERVE + ownership/generation validation on attach/detach — a stale worker can never detach or displace a REPLACEMENT controller (today detach_if compares Arc ptr identity only; the serve path re-checks nothing at completion). Covers the UNFINISHED-stale-row control-steal shape (raw-close no-FIN viewports, emphasys C2 leak class feeding it) that finished-row retirement (D1/D1b) definitionally cannot see — the discriminating field observable on the next live steal catch = the stolen row's finished+retired flags. Gate: impl — pre-serve terminal exclusion + generation/ownership tokens on attach/detach; unit — stale-generation detach refused while the same-generation detach lands; int — T6 (UNFINISHED-stale attach row + live current controller + dispatcher restart: neither takes nor clears the replacement, D1/D1b green alongside); doc — ADR-0038 Amendment. Kin REQ-HAZARD-REDISPATCH-CONTROL-STEAL (the finished sibling), REQ-REDISPATCH-FINISHED-RETIRE.
2026-07-17T03:24:38.2602536Z - Required stages: doc, impl, unit, int
2026-07-17T03:24:38.2602906Z 
2026-07-17T03:24:38.2603193Z ### REQ-DISPATCH-HYGIENE-TELEMETRY
2026-07-17T03:24:38.2607286Z - Title: REDISPATCH-STALL W1 (ADR-0038 Amendment, fixes 7+8+9): dispatcher hygiene + keyed observability — (a) bounded redispatch worker pool with batched cold enumeration, NO claim locks held during I/O (today thread::spawn per stream, unbounded on a cold table); (b) sessions-lock discipline: clone-then-drop before detach_if/info.json I/O (KH 7.12 kin — no fs/conn I/O under global locks); (c) keyed stage telemetry: gen/stream/family/endpoint/attempt/conn on every dispatch record + replay/poison/cancel/worker-outcome events + gauges + PTY high-water/RC cursor — the field-discriminator surface (poison-window census, stream-sub-attach per generation dropping to O(active streams)). Gate: impl — pool + enumeration batching + lock discipline + telemetry keys; unit — pool bound honored under a cold flood + no-lock-across-I/O seam + telemetry key completeness; doc — ADR-0038 Amendment. Kin REQ-HAZARD-REDISPATCH-STALL, KH 7.12 (locks), REQ-CONN-POISON-ATTRIBUTION (extends its attribution).
2026-07-17T03:24:38.2611007Z - Required stages: doc, impl, unit
2026-07-17T03:24:38.2611355Z 
2026-07-17T03:24:38.2611617Z ## How to report back
2026-07-17T03:24:38.2611932Z 
2026-07-17T03:24:38.2612280Z For every (requirement, failing criterion) pair, emit one finding:
2026-07-17T03:24:38.2612720Z 
2026-07-17T03:24:38.2612958Z     {
2026-07-17T03:24:38.2613476Z       "code": "requirement_quality",
2026-07-17T03:24:38.2614068Z       "requirementId": "REQ-...",
2026-07-17T03:24:38.2614750Z       "criterion": "singular" | "verifiable" | "atomic" | "active-voice",
2026-07-17T03:24:38.2615440Z       "message": "<short reason>",
2026-07-17T03:24:38.2616043Z       "suggestedRevision": "<optional rewrite>"
2026-07-17T03:24:38.2616297Z     }
2026-07-17T03:24:38.2616334Z 
2026-07-17T03:24:38.2616701Z Wrap your response as { "findings": [ ... ] } listing only your concerns; the
2026-07-17T03:24:38.2617039Z deterministic findings above don't need to be repeated.
