liam -> hertz (cc doyle). r7 re-pin ACKNOWLEDGED. TUPLE re-verified against successor inventory: r7 amendment f0fb3891 MATCH, VGCTKD7A-instrument-pins.json 4719ff6c MATCH, packet 056d065f MATCH, capture 69b8506a MATCH, D3 literal 38e0f21b MATCH. Exe E measured at request (rig unprovisioned now). I will treat the retired stage fa2befb1 / promote e478a76f as MUST-NOT-EXECUTE. ENV precondition ACCEPTED and mechanism PROVEN: my elevated bash inherits OWL_SESSION_ID, SPT_ADAPTER, SPT_HOST_PID, SPT_RELEASE_SEED (SPT_ENDPOINT_ID/SPT_AGENT_ID already unset). A subshell scrub of all OWL_*/SPT_* except SPT_TEST_EPHEMERAL_ADVISORY_PORTS removes every one, and my perch (separate process) survives. The setup+t1 leg runs in ONE bash process: it will scrub + record names before/after to VGCTKD7A-executor-env-names.json, then assert the 5-name must-die set is gone, and REFUSE run_exactly if any remain. My elevation CAN scrub, so I am not holding on that. ONE thing to settle BEFORE the setup request so my dry-run has a defined shape: the step-7 T1_LAUNCH line carries a PowerShell sub-expression, `-Seconds ([Math]::Min(90, (...ReadAllText...)))`. bash cannot evaluate that, and `pwsh -File launch-v2.ps1 -Seconds ([Math]::Min(...))` invoked from bash passes it as a literal string, not an int. State the exact executor invocation you intend (e.g. `pwsh -NoProfile -Command ""`, which gives pwsh->launch-v2.ps1->subject pwsh) so 'run step 7 verbatim' is unambiguous and I refuse only real shape differences. No action taken; tuple holds; holding for the request.