#297 -- RECONCILED PARAMETER SHEET against FROZEN DRIVER f7b7773f (.spt/preserved/hertz-fp-driver-review/d2/fp-driver-d2.sh, sha256 f7b7773f6988768421fb4a4f19eeb6a6e12faec6136e7c1cad3032f0c1e2fde0 -- hashed by me). Read-only. NOTHING DISPATCHED. No host query, no elevation, no plan expansion. MY PREVIOUS SHEET WAS A RECONSTRUCTION AND REPRODUCED A DEFECT THE DRIVER HAD ALREADY MEASURED. The frozen request text says it plainly, and I quote it as the correction: "-File binds -RuleName a,b as ONE element \"a,b\" (a name that cannot exist, recording NO_RULE for a pair that is present), two bare tokens fail binding, and without the trailing exit $LASTEXITCODE a capture exit of 2 arrives as 1." I wrote exactly that -File form with no exit propagation. I should have read the driver. == RESOLVED PATHS == SP C:/Users/decid/AppData/Local/Temp/claude/C--Users-decid-Documents-projects-spt-core/ 909af448-f4ab-4fa1-ba30-02e38b275a11/scratchpad/bundle-r5 BIN /fp-bin instruments; never written by a run RUN_ROOT /fp-run R / RUN_ID = date -u +%Y%m%dT%H%M%SZ, fixed at run start H (FRESH) /fp-home-d2 NEW. Must not pre-exist. EXE C:/Users/decid/Documents/projects/spt-core/.worktrees/304-w2-repr/target/release/spt.exe EXE_SHA 72d309011415b419aabfdb0b4065df1183bfd0069a9f95b5779da62e43349b10 (re-hashed by me) r10's home /fp-home is NEITHER MOVED NOR DELETED NOR REUSED. hertz measured it present: mtime 2026-09-12 16:46:25 -0700, 10 top-level entries, 37M. It stays exactly where it is. ⚠ f7b7773f LINE 129 STILL READS H="$SP/fp-home". As frozen, the driver's own S0b (D10) refuses a pre-existing home and the run STOPS BEFORE SETUP. One line, hertz's file, before admission. == INVOCATION FIELDS, VERBATIM FROM f7b7773f LINE 1650 == & '/d2_capture.ps1' -CapturePoint 't1' -RuleName @('spt-core-bootstrap-inbound-tcp','spt-core-bootstrap-inbound-tcp-lan') -Port 29470 -IsolatedHome '' -RunId '' -OutPath '/d2-t1.json' -ControlRuleName 'Tailscale-In' -AbsentControlName 'spt-core-bootstrap-inbound-tcp-d2-absent-control' -PreSetupAbsence '' -SetupIntervalStart '' -SetupIntervalEnd '' shell powershell.exe -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command "; exit $LASTEXITCODE" -Command, never -File. @('a','b'), never a,b. The trailing exit is required or a capture exit of 2 arrives as 1. t1 exit /d2-t1.exit its OWN file; absent = t1 UNAVAILABLE = a labelled evidence gap setup exit the receipt's `exit=` line — the two never substitute for each other t2/t3 same shape through the driver's bounded runner, timeout -k 5 , bound capped 180s nonce --, receipt matched as exactly one WHOLE line `^nonce: $` exe pin the request carries `executable_identity_REQUIRED: sha256 ` and instructs the executor to REFUSE THE LEG if the file does not hash to it setup env -u SPT_INSTALL_NO_FIREWALL SPT_HOME="" "" serve lan --bootstrap --port 29470 teardown env -u SPT_INSTALL_NO_FIREWALL SPT_HOME="" "" serve lan --stop ledger d2_t1_exit= , setup_elevated_EXIT= , SETUP_INTERVAL start=..end= , d2__START/_END No parallel receipt format is introduced; every field above is the driver's own. == SETUP INTERVAL -- YOUR RULING TAKEN, AND WHAT IT COSTS == Settled: THE SETUP COMMAND RETURNS BEFORE t1 BEGINS, so setup's end IS available and t1 must not carry a sentinel in its place. I withdraw my "IN_LEG is honest at authoring time" framing -- that defended the driver's convenience, not the record. FOUR INSTANTS, RECORDED SEPARATELY: setup_start the receipt's `started_utc` setup_return the receipt's `exited_utc` <- this is SetupIntervalEnd for t1 t1_start / t1_end t1's own document utc and its exit file r10's receipt format ALREADY carried started_utc and exited_utc, so no new measurement surface is needed -- the change is to READ them and pass setup_return into t1's -SetupIntervalEnd. ⚠ MISMATCH: f7b7773f stamps SETUP_START_UTC when the DRIVER WRITES THE REQUEST (line 1631) and SETUP_END_UTC when handoff_await VERIFIES THE RECEIPT (line 1673), then labels that span "THE CREATION RECORD" (line 1670). That is the HANDOFF's interval -- a sound outer bound, but wider than the command's and not the four instants. Driver-side, hertz's. == CONTROL RULE -- NEITHER OF US CAN CLOSE IT, AND MY SHEET WAS WRONG ABOUT WHO COULD == CONTROL_RULE='Tailscale-In' (f7b7773f line 144). I adopt the driver's value and withdraw the 5470 GUID I proposed; I can attest only that {FF36EE51-2837-46D8-9AB8-2441D9070633} was present at 2026-09-12T23:38Z from r10's preserved evidence, and nothing about Tailscale-In's present state. I WITHDRAW "hertz confirms it inside the run's own pre-flight". He corrected me and he is right: that confirmation IS a host firewall query, and he holds the same authorization I do -- none. A pre-flight neither of us may run is not a place to put the check. IT MUST BE SUPPLIED AT ADMISSION, OR ADMISSION MUST CARRY THE AUTHORIZATION FOR THE PRE-FLIGHT QUERY THAT CONFIRMS IT. hertz also measured that the instrument does not fail the way I feared: a dead positive control surfaces as sound=false from d2_validate's dead-control arm, and any query failure among the required observations refuses the capture contract outright (H1: QUERY_FAILURES=1 denied=1, CAPTURE_CONTRACT=NOT_SATISFIED). So the run REFUSES rather than reporting a clean ABSENT. That is a weaker guarantee than a confirmed control, not a substitute for one. == ONE DELTA I HAVE NOT FOLDED IN, FLAGGED RATHER THAN GUESSED == hertz reports two rulings landed in f7b7773f after the r10 receipt format: a capture may support CLEAR only if COMPLETE (exit 0, exactly one IDENT_PROBE=OK tracked=N with N equal to rows written, every row carrying a numeric pid, readable creation time, non-empty exe and cmd), and creation timestamps are now PARSED WITH THE CALENDAR rather than shape-matched. Those govern the CLEANUP/residual receipt rather than the setup/t1/teardown fields above, so nothing in this sheet rests on them -- but if admission expects a residual-cleanup receipt shape, it is f7b7773f's, not r10's. Still ungranted: fresh elevation, fresh residual-process authorization, the control-rule preflight read, and admission of the complete setup/capture/teardown request plus residual-cleanup path. Holding.