S6ESSJ3N PREP ACCEPTED (plan ab33e028; PREP measured; 85f as base ACCEPTED — my ancestry query was the wrong direction, yours stands). Assembly is running now on asm/304-v3 (worktree .worktrees/asm-304-v3, base 85f84d73 + origin/main + feat/300-input-acceptance + diag/49-267-obs + diag/302-rc-hitch). The xtask git_stdout `.env_remove("SPT_DEBUG_RELEASE_SEED")` repair lands on that branch (todlando) BEFORE my one build; the module tuple 848a23fe/08f615c4/c30d6b54 is an explicit admission gate I check post-merge. You will get: final commit sha, absolute paths + SHA256 of spt.exe and xtask.exe from that tree. fe427 is not merged. GRANTED NOW, in parallel with my build (no field, no keys, no rig writes): G1. The r5 common-absolute-deadline revision you specified (min(now+120, requested_wait_end, phase_work_deadline); cleanup uses WORK_DEADLINE = REPORT_DEADLINE-30; final sleep clamped; nonce/authorizer/signal behaviour preserved) as r6, qualified by no-field throwaway controls on the deadline boundary. Original r5 bytes untouched. Return pins. G2. Prepare (do not run) the dummy-sentinel custody discriminator (A.1) against a disposable qualification staging root outside rig and fleet; it runs the moment my xtask.exe hash lands. PRE-RULING — ONE authorization for the rest, recorded now so no further round is needed. Your ordered plan A.1–A.4, B.5–B.7, C.8–C.9, D.10–D.15, E.16–E.19, the native boundary + F5 budgets, and the D3 cleanup section are AUTHORIZED AS WRITTEN, conditional on ALL of: (c1) the admission tuple is complete and matches: my assembled commit + the three module blobs + my spt.exe SHA/path + my xtask.exe SHA/path + final configured r6 + support manifest + RIG_ROOT/N=202609130001/KEY_ID hertz-r5-S6ESSJ3N + fresh host/rule/port samples; any missing/changed member = NOT_STARTED; (c2) A.1 custody qualification PASSES with booleans/roles/births only (signer sees the sentinel, both git children and every helper report absence, forbidden-helper arm rejected, teardown + post-window absence) — a real key is minted only after that; (c3) G1's r6 qualification PASSES before invocation; (c4) D.15 breadcrumb retirement: GRANTED exactly as specified (atomic no-overwrite move of the exact owned H/daemon.pid to EVID/provision-daemon.pid.retired with receipt; unexpected contents/identity = refuse); (c5) one 600 s preparation deadline carried into the configured run; no hidden builds inside it. GO: pre-authorized against that tuple — record my decision against the FIRST matching run nonce after every gate above succeeds; a second attempt, a changed tuple, or any gate failure voids it and comes back to me. Secret custody: private dir %LOCALAPPDATA%\spt-rig-secrets\hertz-r5-S6ESSJ3N as specified; seed-file retirement after owned-job disappearance is granted; never archived. Elevated D3 executor stays the specifically authorized one, payload pinned 416280db / teardown-command.pinned 38e0f21b; a differing rendered payload = stop. Disposal of RIG_ROOT afterwards is NOT granted here — separate receipt, separate ask.