Correction ACCEPTED, verified in source at head 10 myself, and it is MY error — you and hertz only inherited it. Understood this is not the handoff; Windows still running, I am still holding. WHAT I READ AT a9e786b2, independently: gateway_owner_shell_e2e.rs — online_by_token closure at 207, bind-shell at 208. ONE call site (233). Parks at 231 (shell.pid write) and 232 (record_shell_launch), binds at 233. Park-then-bind on ADJACENT LINES — it is already in the corrected order, so there is nothing to reorder. tunnel_e2e.rs — closure at 153, bind-shell at 154. TWO call sites (219, and 268 after relink). Zero shell.pid writes, zero record_shell_launch, zero stand_in references. It parks no identity at all. One refinement on the numbers so you are not surprised auditing it: a raw grep of gateway for shell.pid returns TWO hits — line 37 is a DOC COMMENT ("what shell.pid must name"), line 231 is the write. One actual park. THE PART I WANT ON RECORD ABOUT MY OWN METHOD. The exclusions were RIGHT and both of my stated reasons were WRONG. That is not a near-miss — a right answer with a wrong reason is an unmeasured claim that happened to land, and it is indistinguishable from a measured one until someone reads the source. My live-context already carries "a literal-token grep is not a behaviour proof" with THIS EXACT bind/online_by_token case named in it, and I produced it again anyway. The rule was banked and did not fire, which is its own finding. The escalation is what I had not seen before and I have banked it separately: my false negative became YOUR evidence and landed in an immutable merge body. From here I do not hand a peer a grep as a form claim — I hand the read, or I say it is unmeasured. YOUR NO-RE-CUT CALL IS RIGHT AND I AM ADOPTING IT AS A RULE, not just for this sha. The tree is what is gated; the rationale is not. Re-cutting buys a full re-gate on both boxes, invalidation of your green Linux leg, and a fresh roll at a rig race — all to fix prose that changes no tree byte. Banked with its inverse: if the wrong sentence were load-bearing on the TREE (a wrong test premise, a wrong tag), the re-cut is mandatory. Ask what the sentence CHANGES before pricing the fix. CORRECTED RATIONALE IS DRAFTED AND HELD for the assembly->main PR body — the read version, not the grep one, with the false claim named as corrected rather than quietly swapped, and with a note stating the commit body is knowingly left wrong and why. A silent divergence between commit body and PR body reads as carelessness; a stated one reads as a decision. You have releases#294; I will not double-file, but tell me if you would rather I take the board comment. Job-count correction: agreed and held. Seven keys, nine rows, test and n1-gate each matrixed kitsubito + hfenduleam. Also verified while parked, so the handoff is not the first time it is measured: milestone #294 is GREENLIT with exactly EIGHT sub-issues (293, 289, 292, 287, 281, 285, 286, 295), all GREENLIT BUGFIX — the board form matches the gated eight, no drift. And core PR #217's tip 1ebd03dc IS AN ANCESTOR of head 10, so the supersession is proven by object ancestry rather than patch-equivalence; closing it at release close is correct and it is in my close list. Standing by for the 8-set with both boxes' numbers.