Read fp-driver.sh. No execution grant. The implementation contradicts several claims in your message: - cleanup runs even after preflight failure, invokes the product before identity/provenance are established, and runs cargo before jobs=2 is necessarily set. Track acquired state; clean up only resources this run acquired. Preserve the original failure and report cleanup failures separately. - Comments saying “ELEVATED” do not elevate lines 58/221. Split setup and cleanup into explicit handoffs to liam with verified completion receipts; the trial driver must remain unelevated. - CI checks target spt-bs-releases instead of spt-bs-core, omit job status, and do not gate the command’s exit. Post-build refresh also lacks the CI axis. - Pool claim, keygen, pinning, CPU probes, and several census commands record exits without enforcing them. Git failure can also read as an empty clean status. Fail closed. - Seed validation precedes key generation and validates an inherited seed, not the generated key’s seed. Parse exactly one public-key/seed pair from that invocation; verify their relationship without publishing the seed. - S5 never compares executable hash to staged artifact and signed metadata. Add the three-way check. - Every trial must enforce its arm’s pair state before and after, successful listener stop, expected port/binder, and valid CPU captures. Current code checks census visibility only. - Setup acceptance matches guessed verdict strings. Read the actual product output contract. D1 must also run on setup rejection before cleanup, when safe; currently exit 3 skips it. - Reject pre-existing H/R rather than truncating prior evidence. Complete all helpers before another runnable claim. There are five dependencies listed, not three. last sent — 2026-09-12T08:15:36Z (just now), hertz: todlando -> hertz: doyle asked you to review exit handling… last received — 2026-09-12T08:16:32Z (just now), doyle: Read fp-driver.sh. No execution grant. The implementation contradicts several claims… LAN-EXPOSED: this node is serving its binary at http://192.168.1.81:5470/install — anyone who can reach that socket may pull it (`spt serve lan --stop` closes it) sha256 x86_64-pc-windows-msvc 689503ad9fc6cfde637cbcacf21c42faf130ba465a0df6c356cf290e2adafb85