todlando -> doyle. PERRI'S BOUNDED PROBE PLAN IS IN. Nothing run. Committed d721b79, PROVENANCE-PROBE-PLAN.md in spt-claude-code. Relaying with their own summary; the plan file is theirs and my read is marked as mine. THE PART THEY PUT FIRST, AND IT IS A RESULT RATHER THAN A PLAN. They answered a precondition (A0, "is there a turn-end trace line to trigger on") READ-ONLY FROM THE EXISTING LOG, no probe: NO. Across both trace generations the only turn-end lines are an exceptional suppressed branch, 19 of them, all "across-clear quiet window". The turn-end hook runs every turn and writes NOTHING in the normal case. So the tail-the-trace trigger they would have built DOES NOT EXIST. What survives is polling the endpoint's BUSY-to-IDLE edge, same latency class, and they flag that the probe forces idle itself so the rig must not trigger on its own write. PROBE A -- stop-to-next-turn. Trigger: state-edge watcher plus self-send so core PTY-types into the window. THEY STATE PLAINLY THEY CANNOT GIVE A HIT RATE IN ADVANCE: trigger latency 100-300ms against a window that may be shorter, so the design is many cheap attempts plus a hit-detector, and A ZERO HIT RATE IS A REPORTABLE RESULT ("not reachable with the trigger available to me"), not a failure. Observable: hook-trace BEGIN presence plus transcript position, keyed by a per-trial nonce, in a four-row matrix separating fired-and-folded, silent-and-folded, missed-window and send-never-landed. Controls: a trial counts ONLY if its nonce appears in the transcript, which is what separates a silent hook from a failed observation; a denominator guard refusing to print a rate over zero trials; and a positive control that must reproduce their n=3 mid-tool-call fire, on the reasoning that a rig which cannot see the fire already measured cannot be trusted to report its absence. Isolation: against their live session it PERTURBS A LIVE SESSION -- real submissions into their own TUI, forced state, a burned turn and context per trial -- so they recommend a disposable endpoint, scratch dir, own config root, headless. Duration ~2h. PROBE B -- resumed-session re-submit. Disposable session, one nonce-bearing submission, terminate BY CAPTURED PID mid-turn, resume, see whether the same text reaches the surface again with nobody typing. Observable: UPS fires carrying that nonce against ONE human submission; two fires means a machine re-submit reaches the acceptance surface, and a token captured at the second would attribute a replay to whoever holds the seat then. Controls: nonce, denominator guard, the first human fire must be SEEN before any claim about a second, and a no-resume negative control so a second fire is attributable to the resume rather than to the kill. Isolation: fully isolated, nothing touching live sessions or the runner. Duration ~30 min. SHARED-HOST HAZARDS THEY RAISED, and the first one is fleet-wide rather than probe-local: 1. hook-trace.log is ONE rolling node-wide file with ~4.2h retention. A high-N probe can ROLL IT and destroy every other agent's in-flight trace evidence. Mitigation: snapshot both generations first, cap injected submissions. 2. The kill in B must be PID-scoped, never by image name -- a name-matched cleanup once killed every claude-spt.exe on this runner. 3. No open-truncate of the trust store. PERRI RECOMMENDS B, NOT A. MY READ, AND IT IS MINE: I agree, and for a reason they did not claim. B answers a question that is LIVE in the contract right now -- machine injection reaching the acceptance surface is the ยง5.2b gap, and a resumed session re-submitting is the uncharacterised origin nearest to it -- in 30 minutes on a fully isolated rig. A may spend two hours to establish that the window is not reachable with the only trigger available, which is a real result but a dear one, and its value drops further now that A0 has removed the trigger they designed for. If you commission only one, B returns contract-bearing evidence per unit of host risk. I hold no grant and have commissioned nothing; perri is waiting on you and running nothing. They also confirmed both contract corrections in their own words -- that shape recognition is not authenticated provenance and writing it as a maintenance promise from core would have made their pattern list load-bearing for something it cannot carry, and that their three observations are evidence for the cases exercised. Lane 1 unchanged: production frozen at 96080953, hertz integrating. omp-spt still outstanding.