todlando -- W-1 EXECUTION, START 2026-09-11T12:00Z, on doyle's WORD. SUBJECT fe4274979c5a93a36fef9f066df6afbe70070ae8, lane build/304-w2-bootstrap-tcp, worktree .worktrees/304-w2-bootstrap-tcp, pool .worktrees/304-w2-bootstrap-tcp/target (label todlando-304-w2). Tree CLEAN. This message is the first act of the window. ADMISSION, run by me immediately before this START, and it took THREE attempts to become evidence: attempt 1: control was `cargo --version`, which exits faster than my sample -- control_seen=FALSE. A census whose positive control fails is not a clean zero, it is an unproven instrument, so I did not report the zero it produced. attempt 2: longer-lived control seen by PID (Name='cargo.exe') but NOT by my name-keyed filter -- the two probes disagreed, which is the shape where a filter that cannot express the hunt returns a confident zero. attempt 3, SETTLED: both probes queried at the SAME instant against a live `cargo metadata` -- seen_by_PID=TRUE, Win32 Name='cargo.exe', seen_by_NAME_filter=TRUE. The disagreement in attempt 2 was the control exiting between my two queries, not a blind filter. READING, with the instrument now proven: ZERO cargo.exe / rustc.exe / cargo-nextest.exe / link.exe / Runner.Worker.exe. Free 142.6 GiB (153,136,312,320 bytes), floor 96 GiB PASS. 7 spt.exe are my own perch and daemon, not builders. CAP 900 s total, one attempt per arm, no retry. Arms in your order. BEFORE ANY ARM RUNS, I AM REVERSING ONE OF MY OWN PREDICTIONS, ON A SOURCE READ RATHER THAN A RESULT. E3 was filed as: mutation adds `program=` to lan_admission_fix, u2 goes RED at its extract_rule_programs assertion. I read that path while building the driver and I now predict E3 GREEN -- the assertion CANNOT fail, and the reason is mine: extract_rule_programs is written for a multi-line netsh DUMP. It takes each LINE, splits at the FIRST colon, and keeps the value only when it looks like a path (`value.chars().nth(1) == Some(':')` or a UNC prefix, ending `.exe`). lan_admission_fix returns ONE LINE. Its first colon is the one inside `program=C:\...`, so the value it yields is `\fake\spt.exe & netsh ...` -- second char 'f', not ':' -- and the filter drops it. The function returns EMPTY for the mutated command exactly as it does for the clean one. So `assert!(extract_rule_programs(&command).is_empty())` is TAUTOLOGICAL: it passes for every possible input this call site can produce. I wrote it believing I was reusing the UDP side's own parser as the negative -- reuse was the right instinct, and I did not check that the parser's input SHAPE matched the one I was feeding it. A dump parser pointed at a command string. I am running the arm anyway, because a predicted-green control is still the measurement that proves the assertion vacuous rather than my reading of it. If E3 comes back RED, my source read is wrong and I will say so. The real negative is `!command.contains("program=")`, which the same mutation WOULD redden. That is a test-only repair on a NEW sha, so it does not ride this window: it goes to you at the END with the measurement attached, and I do not touch bytes under your word for fe427497. ARMS: E3 u2-R mutation: program= injected into the tailnet add. PREDICT GREEN (see above), which FALSIFIES the assertion rather than the product. E4 u1-R mutation: the command built from the resolved port instead of the bound one. PREDICT RED in the_admission_is_written_for_the_bound_port_and_never_the_configured_one, at the localport assertion, with the message naming the BOUND port it failed to find. E1' exact-name filter over the five Windows cells, --success-output immediate so u3's line text lands in the record. PREDICT 5 selected, 5 passed. A 0-match summary is a rig fault, not a pass. E2' unfiltered -p spt-daemon --lib. PREDICT total == `cargo nextest list -p spt-daemon --lib` total at THIS sha, 0 failed. Both numbers reported side by side and both carry this sha. E5 no SPT_POOL_FOREIGN, no lane-identity refusal. MUTATION DISCIPLINE, hertz's CRLF finding applied rather than remembered: every anchor is built from the file IN HAND and translated to ITS actual eol before the count, each mutation must match EXACTLY once or the arm aborts before running, each revert is `git checkout --` on that one path, and each revert is proven by working-blob oid == HEAD blob oid AND by byte shape (bytes / CRLF count / bare-LF count). An oid check alone normalizes line endings and would report identical bytes over a file that just changed. END will carry: every number with its sha, both mutation arms quoted at their assertion lines, the list total and the run total side by side, the leaky set, each prediction against its result including this reversal, and the post-census.