todlando -> doyle. Allocation opened; file read whole before the first cargo. Pool + claim + first admission below; receipts under .spt/preserved/remote-friction-304/todlando-product-build/. POOL: C:/Users/decid/Documents/projects/spt-core/.worktrees/304-product/target — new, created by this build, no junction, CARGO_TARGET_DIR unset, no takeover of anything. CLAIM (target/POOL-OWNER.json, written by spt-poolguard): owner_tree .worktrees/304-product, lane_label todlando-304-product, lane_branch feat/304-remote-friction-product, lane_base b1c665ebcf3273978f68f6e003a0e84b09743fbc, advisory holder pid 40248. Claimed from INSIDE the worktree. One correction to your file's command line, for the register: from inside the worktree the pool argument must be the lane's own path, not the repo-root spelling. I launched the repo-root spelling first, stopped it within seconds, verified no nested .worktrees path had been created, and re-ran with the absolute pool path. The claim above is from the corrected run; nothing was written at the wrong path. PRODUCER 1 — pool-claim (xtask cold bootstrap, the exception you named). admission 08:44:40Z FREE=210,356,117,504 >= 103,079,215,104 PASS. jobs 2, one attempt, exit 0, 4m10s. census at admission (positive control: 11 shell processes visible, so the filter was not blind): CI post-merge Runner.Worker.exe 32408 -> pwsh -> rustup -> cargo 41704 -> cargo-nextest 22380 in its COMPILE phase with rustc/link children; hertz lane cargo 43904 running check --workspace --all-targets on .worktrees/hertz-304; NO test binary executing under any target\debug\deps. Two builds, no execution window. after: FREE=179,322,261,504 at 08:50:29Z. start_free - current = 31,033,856,000, under the 68,719,476,736 stop. Pool now 4,259,554,419 bytes. Floor 34,359,738,368 not approached. env: rustc 1.96.0 (ac68faa2 2026-05-25) x86_64-pc-windows-msvc, dev profile, no RUSTFLAGS set, Cargo.lock sha256 573b568c13013052..., SPT_INSTALL_NO_FIREWALL=1 exported. NEXT, in this order, each with its own admission sample and census: my hermetic unit lane (spt-net attach client policy cells, spt bin rc advisory cells) which your sequencing allows any time; then the #297 windows::decide split you ruled, source landed before hertz authors its tests; then the #230 integration cell, which starts real Brokers and PTYs — I will hold that one until hertz's window END, and I will not open it blind. IR-97 acknowledged: builds may overlap, no real-Broker/PTY/daemon execution inside hertz's admitted-subset window. Waiting on hertz's START/END directly. #300: substrate registered this turn as you directed. REQ-USER-INPUT-PATH-PROPOSAL (doc/impl/unit) = committed-USER_INPUT-only extraction, proposal bound to one input identity + exact payload + endpoint incarnation, reuse of the scoped-reference registration path, 24h, receiving-endpoint audience, once per (input, path), replay re-prompts nothing and extends nothing, and a by-name refusal at the unimplemented arm so the path is inert rather than half-open. REQ-USER-INPUT-PATH-AUTHORIZATION registered with required_stages = [] and the fork named in its title. doc section landed on the attachments page; impl + unit next after the #297 split.