hertz -> doyle: LEAK LANE GREEN ON ALL FOUR LEGS. Diff below, nothing pushed, nothing staged. LEGS, each exit in its own file (.spt/preserved/hertz-leak-670-legs/, hash-verified 3/3 against the scratchpad copies before I reaped anything): check exit=0 11:52:27Z -> 11:57:09Z test exit=0 11:57:13Z -> 12:10:xx Summary [16.441s] 1 test run: 1 passed, 0 skipped PASS [16.436s] a_declared_service_rises_with_the_daemon_and_reaches_the_cli clippy exit=0 -D warnings, finished in 1m35s treqs exit=0 The changed teardown passes with the supervisor killed first, and the leak assertion did not fire — which is the outcome I want but NOT proof the new assertion works: a green run exercises the preserve-and-stamp path only as far as building it. What this run proves is that the reordering does not break the happy path and the new code compiles clean under -D warnings. The stamp and the bounded tail are proven when something actually leaks, and the FLAKE-LEDGER row stays open until a Windows golden runs through it, exactly as filed. DISK, because it nearly bit again and the numbers are the IR-90 evidence: 11:52:27Z 136.32 GiB at check start 11:57:13Z 128.30 at test start 12:07:08Z 40.18 <- the test-profile build of 221 binaries, ~88 GiB in 10 minutes 12:10:53Z 17.44 12:11:41Z 16.24 at ALL LEGS DONE, and 12.27 by the time I reaped My lane's pool cost 61.23 GiB actual. I reaped it immediately after the legs went terminal rather than hold it for your review: at 12 GiB free, PR #208's Windows unit job on this same box is one allocation away from a false red, and I am not spending todlando's CI run on my convenience. Classify first (real dir, reparse=False, inbound sweep empty), pool-release with the prebuilt xtask, then remove: free 12.27 -> 73.49 GiB. If you want changes I rebuild from cold, which is the cost I chose. ⚠ ONE NUMBER I CANNOT ACCOUNT FOR, stated rather than smoothed: free fell from 16.24 at ALL LEGS DONE to 12.27 about ninety seconds later with MY legs already terminal. Something else on the box was writing ~2.6 GiB/min in that window. Candidates are #208's CI job and the runner's own _work, but I did not sample it and I am not attributing it. It matters for IR-90's floor: a rig that checks free space only at START would have passed this run at 136 GiB and still finished at 12. DIFF: .spt/hertz-leak-670.diff (322 lines, 3 files, +227 -11). Commit message drafted at .spt/hertz-leak-670-commit-msg.txt. Branch hertz-leak-670 off main 88701366, base recorded in the pool claim. Nothing pushed. Your review, then I push and open the PR — or I amend first, your call.