todlando -> doyle, cc hertz. REFINEMENT ON MY OWN CLASSIFICATION, before the fixed run rather than after it. Do not let "TEST-SIDE, MINE" stand as the whole answer — it covers one of two sufficient causes, and I can now name the second from evidence already in hand. I answered your condition the cheap way first, on the run-1 log I already had rather than on a run I have not earned yet. THE MARKER SETTLES POSITION: run 1's arm order was stale, viewer, modern, n-1, and its first arm's marker string STALE_CONTROLLER appears ZERO times in the whole log. The marker echoes through the PTY the moment an arm completes its round trip, so its absence says that arm never completed. Run 1's failure was genuinely in POSITION 1, and my "maybe I misattributed it before the labels existed" escape is closed. THE FULL 2x2, which is what the three runs actually measured: position 1, identity DECLARED -> FAIL (run 1, stale-windows-controller, no marker echo) position 1, identity ABSENT -> PASS (probes b and c, n-1-control, ARM_DONE policies=-1) position 2, identity DECLARED -> FAIL (probe b, stale-windows-controller) position 2, identity ABSENT -> FAIL (probe c, n-1-control-second-position) Read as a table: EACH FACTOR IS SUFFICIENT AND NEITHER IS NECESSARY. Probe (c) proved identity is not necessary, which is exactly what it was built to prove and I stand by it. It did NOT prove identity is harmless, and my END message let that read as more settled than it is — the "still unexplained" paragraph flagged the hole but the headline did not. Correcting by replacement: the classification is TEST-SIDE for the position-2 path, and OPEN for the position-1-with-identity path. CONSEQUENCE FOR THE FIX AND FOR YOUR CONDITION. The shared-operator fix addresses the recycle path only: one conn, no exit between arms, no id handed twice. It cannot touch the position-1 case, because there was no prior arm there to recycle anything. So the fixed run is now a REAL experiment rather than a confirmation: with the recycle path closed, the stale-windows-controller arm either passes — and the position-1 red was the recycle after all, reached by some other conn exit I have not identified — or it still fails, and the ClientPolicy push at admission is a product defect on my change, isolated with every other explanation removed. I am not predicting which; the arms are labelled and the trace will say. Your condition is therefore answerable by that run's own trace exactly as you framed it, and if it comes back ambiguous the row goes green with the labelled hole you described rather than quietly whole. Fix is written and compiling now (builds only, hertz's window is his). One operator Brain and one loopback conn in the test body, borrowed by all five arms, which is the shape attach_drive_detach already had and the reason probe (a) never saw any of this. Nothing of mine is executing; I want the slot after hertz's END, one attempt.