GROUP M RULING (doyle, on GROUP-M-RECEIPT-AND-CONTAINMENT.md 9ca9a616, out dir 20260913T103751Z-M). One pass. ACCEPTED: M0 (negative control failed as required), M2 (native exit 37 preserved; pid reuse caught), corrected M3 (0x2000 readback, both members GONE on close), corrected M5 (denied=5 without flag; escape demonstrated with BREAKAWAY_OK), corrected M8 (13/13 GONE, 0 unreadable). Initial M3/M5/M8 stay INVALID as you labelled them. Your three instrument findings (nested-struct copy write, $null-to-native, JSON date type) are real mechanisms — write them into docs/INFRA-REGISTER.md as IR entries in the same lane (rig-instrument hazards, not product). BLOCKERS CONFIRMED: M4 (argv transport destroys boundaries; argc=25) and M6 (ledger emits CLEAR with PARTIAL coverage). AUTHORIZED — r5 + launcher v2, one build, no proposal round: 1. M4 fix as you proposed: an actual argument VECTOR (JSON string array) through ProcessStartInfo.ArgumentList; every string preserved incl. empty/spaces/quotes/newlines; no separators, no special-casing the capture script. The exact M4 call is the regression discriminator. 2. M6 fix as you proposed: known live residue => LIVE; missing/incomplete coverage or TERMINATION != confirmed => UNREADABLE; CLEAR only when every coverage + disposition predicate holds; missing records never read as an empty launch set; direct-subject state and whole-operation state stay separate in the ledger's own output (the internally contradictory print goes). 3. Containment contract points 1-7: ACCEPTED as the termination design and authorized for implementation in the launcher: private non-inheritable job, KILL_ON_JOB_CLOSE only, breakaway + silent-breakaway PROHIBITED, limits read back and exact or refuse (interop error = refusal, never an ordinary launch); CREATE_SUSPENDED, identity from retained handles, assign + membership read BEFORE ResumeThread, setup failure never resumes and disposes only the suspended process through its retained handle; deadline accounting from before setup; separate completion reason (124 alone is not expiry); controlled expiry = TerminateJobObject then poll accounting to ActiveProcesses=0, direct-subject disposition reported separately, child handles released after observation, job handle closed after confirmation, kill-on-close as the unwind net; no PID-tree kill, no descendant enumeration as authority; coverage scoped: COMPLETE only for an admitted operation known to stay in the creation chain, never promoted by a scan, never bought by enabling breakaway. 4. THE DAEMON IS NOT A STEP'S CHILD. A bounded step is job-contained per step. The rig's isolated daemon is launched by its own RUN-SCOPED job (handle held for the whole run, same limits, breakaway prohibited) and any step that could autostart a daemon (ensure_running) is preflighted against a daemon already up or refused — a daemon born inside a step job would die at step end and read as residue. Its coverage is whatever KNOWN-HAZARDS 7.10's actual breakaway/fallback behaviour yields, MEASURED (control N-D below), never inferred from pwsh throwaways. CONTROLS — group N, one group, one return, after r5 + launcher v2 parse-check: the ten you listed (suspended-before-assignment with immediate-spawn subject; assignment failure never resumes; child + grandchild; breakaway denial; native exit vs bound expiry with the separate reason; child outliving the direct subject; launcher abnormal exit / last-handle close; accounting-confirmation failure; exact multiline M4; M6 partial-coverage refusal) — throwaway-owned. PLUS N-D: the pinned rig exe .worktrees/304-w2-repr/target/release/spt.exe (72d30901…; never rebuild or substitute) started as `daemon run` in a run-scoped job, in a FRESH throwaway isolated home under your preserved tree, breakaway prohibited: record whether it starts, whether supervisor + brain are job members (readback), what 7.10's breakaway request returns, and whether job close leaves all of them GONE by anchor. Only that home's processes; no fleet home, no daemon.pid of anyone else, no firewall, no signing/apply. STILL HELD: field runs, provisioning (mutating), signing, apply, any termination of a process the arm did not create. Return: out dir + ONE receipt. I rule field readiness from that.