Admission request sheet done. d3/d3-admission-request-sheet.md (hash in my next line after this send is stale - see foot). Read-only throughout; nothing invoked, nothing elevated. INSTRUMENT - YOUR READING WAS RIGHT, and it is not a version limitation. I ran the launcher's OWN S3 bytes (cut from v4 by marker, lines 57-80, block sha256 b98f5f20..., nothing retyped) in both runtimes. Probe d3/d3-pipe-instrument-probe.ps1 3b1bb29f..., output d3/d3-pipe-instrument.out ff011861... NAMESPACE built by the launcher: length 9, FOUR backslashes, code points U+005C U+005C U+002E U+005C U+0070 U+0069 U+0070 U+0065 U+005C - byte-identical in both runtimes. The failing form reached C:\pipe; that is a different string and not what S3 passes. Windows PowerShell 5.1.26100.8875 (Desktop, System32\WindowsPowerShell\v1.0\powershell.exe): enumerated=635, known-present control spt-daemon-broker-78bf18a9fd96fdc6.sock FOUND, target hits=0. PowerShell 7.6.6 (Core, Program Files\PowerShell\7\pwsh.exe): enumerated=637, same control FOUND, target hits=0. Subject's own lines in both: ctl_nonempty=True ctl_predicate=True hit=0, then absence=OBSERVED_AT_CHECK race=NOT_EXCLUDED. Counts differ by two because the namespace changes between samples - enumeration races, which is why absence is only ever read at an instant. The probe requires enumeration to SUCCEED and a known-present pipe in the SAME sample before reporting the target absent (SAMPLE_UNPROVEN exit 5 otherwise), and reports a failed read as ERROR with exception type and message - never zero, never absence. I am not carrying the version inference forward. One asymmetry recorded, not fixed (v4 held): in the launcher a THROWING enumeration is an unhandled terminating error - it dies before S4, nothing launched, no nonce spent, but no D3_REFUSED line and exit 1 rather than 2. The silent-zero case IS covered by ctl_nonempty -> absence_instrument_unproven, exit 2. PINS. launcher 93ee37e1... verified; pinned exe C:/Users/decid/Documents/projects/spt-core/.worktrees/304-w2-repr/target/release/spt.exe = 72d309011415b419aabfdb0b4065df1183bfd0069a9f95b5779da62e43349b10, matches D2's EXE_SHA byte-for-byte (38419456 bytes, mtime 2026-09-12T23:17:02Z). RUN IDENTITY. RunId 20260913T0545Z-hertz. OutDir ...\d2\d3\run-20260913T0545Z-hertz - verified ABSENT, under the preserved tree, never a scratchpad. broker spt-daemon-seed-d3-emission-probe-20260913T0545Z-hertz.sock - ABSENT in the proven sample at 05:38Z, boundary observation only. AVAILABILITY. gh: 8 most recent ci runs on spt-bs-core all completed, newest 34676423540 at 2026-09-12T05:46Z (~24h); nothing queued/in_progress/requested. Local census 05:34:53Z, 609 rows, self-pid control present: Runner.Listener online since 09-11 but NO Runner.Worker (runner idle), no cargo/rustc/link, free 119.6GB. COMPETING FIREWALL-HELPER ACTIVITY: ABSENT. No lan-firewall, netsh, EncodedCommand, New-NetFirewallRule or fp-driver process. Owned pair spt-core-bootstrap-inbound-tcp and -lan both report "No rules match the specified criteria" on unelevated netsh, with TWO controls: name=all lists 1001 rules (reader not blind) and an exact-name query for an existing rule returns it (the NAME predicate resolves, not just the listing). The live spt fleet rows are infrastructure and are not to be disturbed by this lane. BEFORE/AFTER READ-ONLY CHECKS are section 5 of the sheet, outside the launcher, v4 unchanged: sha both pins; census with the section-4 predicate plus self-pid control; netsh owned-pair state with both controls; OutDir absence; wall-clock UTC - repeated after exit, with the BEFORE/AFTER comparison as the attribution evidence. Plus: hash d3-probe.out/.err before reading them; on PENDING, take FRESH native identities under a separate disposition review (the descendant list is not kill authority, UNATTRIBUTED rows are not targets); no cleanup, no termination, no retry; the emitted command is not executed and not decoded until you have it pinned. Sheet sha256 (final, after the header correction): see the file - fd661af3... was pre-correction. Awaiting your call; nothing further will run here.