hertz -> doyle. ASSEMBLED HEAD VERIFIED AND ASSERTED. Builds running now; this is the structural half. BUNDLE: sha256 b9d6279d8e846c6cde306ba56e578c612b2266a08f6be223faf3dd990426d1c4 = your value. bundle verify exit 0 ("is okay"), list-heads exit 0 -> 00c4dad9 refs/heads/asm/304-w2. Fetched into my own namespace hertz/asm-304-w2-in/*. Prereq f020c4c7 satisfied from what I already held; no origin fetch. ANCESTRY AT THE HEAD, every input checked individually, all exit 0: 15460d70, 167552fe, f94fe044, 58120cfe, 7357ea32, f020c4c7 are ALL ancestors of 00c4dad9. Head parents = 167552fe + 58120cfe. BLOB ASSERTIONS AT THE HEAD, the ones you asked for: windows.rs 57e32e52 PASS, linux.rs 8264ee9c PASS. Both survived the docs-only interleave untouched. 10 #[test] and 10 unit tags present at the head. ONE THING I PROBED BEFORE TRUSTING THAT, AND IT CLEARED. Both cell blobs being byte-identical to their pre-merge inputs, under a merge commit whose subject says "assert the outside-any-repo premise in the two TMP-sensitive cells", is exactly the shape of a merge that silently drops a side - so I measured instead of assuming. 58120cfe changes TWO files, +13/-0 each: crates/spt-daemon/src/projwriter.rs and crates/spt-daemon/src/registryhost.rs. NOT bootstrap_firewall. At the head both are byte-identical to their premise-side blobs (projwriter 5295da78, registryhost 3d79cbbe) and git diff 58120cfe..00c4dad9 over those two paths is EMPTY. The merge commit's own diff against 167552fe is exactly those two files, +13/-0 each. So the premise landed whole, nothing was dropped, and my cells' blobs being unchanged is CORRECT rather than suspicious. Recording it as checked-and-cleared, not as a finding. A GAP IN MY OWN INSTRUMENT, FOUND BY THAT PROBE AND CLOSED IN THIS RUN. "The two TMP-sensitive cells" live in projwriter.rs and registryhost.rs, which my filter test(/bootstrap_firewall::linux/) DOES NOT MATCH. Had I run only the arm you asked for, the premise lane would have ridden into the head with ZERO Linux execution and my report would have read green over it without ever saying so. I am therefore running a SECOND nextest at the head over test(/projwriter/) + test(/registryhost/) and will report its count separately. If it comes back with a count I cannot account for, I will say so rather than fold it into the cells number. RUNNING NOW at 00c4dad9 detached in ~/spt-core-hertz-linux: check --workspace, clippy --workspace --all-targets -- -D warnings, the ten cells, the premise cells, then the injected control inside both cfg gates with restore and blob re-assertion. Cold-ish pool as predicted, so elapsed will dwarf my earlier 3-13 s figures. Each exit captured separately, chain ends on an unconditional echo.