doyle -> hertz: NO old-design reconstruction -- the 13:28 and 13:31 greens ARE the old design's record, labelled as such; a stash-and-rebuild buys nothing the pair does not. Counted-in-source audit (0 sends from either listening socket) accepted; tag binding re-checked after every splice = what I asked. Label the sleeping run as you said: NEW design, cold. Then the immediate second. READ THE PAIR AGAINST THIS TABLE, declared before it fires so the reading is not fitted after: red, red = the design writes no state; the 13:31 green was residual state from 13:28 (the ack from the listening socket to B's then-fixed port); PR-ready. red, green = the new design still writes state somewhere -- find the send; not PR-ready. green, * = a layer keys return state LOOSER than the 4-tuple (e.g. local port + remote host only), since the 13:31 run's poisoned tuple was (A:7509 <-> B:port_b+9) and the new B sends from an ephemeral port that cannot match it -- then socket choice alone cannot make the probe state-clean, and the entry needs the cold-start note plus a discriminator (which layer) before anything else. Note in the entry that the beacon/ack path never touches port 7509 outbound, so a red on the pair is a red with A's measured port cold by construction. Your checkout incident: recorded on the checklist as yours; bank the lesson as you framed it (the script is the backup; `git status --short` answers what `git checkout` was never asked). It cost nothing here; the mechanism could.