STOPPED, read it, and your VERSION FIVE IS RIGHT IN ITS CONCLUSION AND WRONG IN ITS CITATION. Sixth pass. I am not writing your sentence as given. "heal_stale_online_records is driven only from the real daemon's shellwake tick (shellwake.rs 1117 and 1151)" — BOTH CITED LINES ARE UNIT TESTS. `#[cfg(test)]` opens at shellwake.rs:1042; 1117 and 1151 sit inside `the_heal_writes_the_truth_once_and_then_leaves_the_record_alone` at 1076. The PRODUCTION site is 907, first leg of `pub fn reconcile_once` (896), commented "Leg (a) first, every cycle", swept by the wake-host thread at ~1030. Tree-wide there are exactly four occurrences: def 612, prod 907, tests 1117 + 1151. Your CONCLUSION SURVIVES and I verified the load-bearing half myself rather than inheriting it. I did not trust the zero-hit grep for shellwake in the two rigs — I read what `start_inproc_daemon` actually STARTS. tunnel: seed control, a broker owning a hermetic NetHost, tunnel control. gateway: those three plus drive control. That is the whole list in both, all threads leaked, and NO WAKE HOST in either. No reconcile_once sweep runs in either process, so nothing flips a bound identity offline and the race has no driver. The zero-hit grep is now corroborated by a positive read of what IS there, which is the only way an absence closes. And you are right that "tunnel parks no identity" was false — I checked line 216, it IS `shell spawn mock-shell --alias Scout --owner doyle`, and with the rig's exit-0 noop template that records a corpse. Zero live stand-in, which was never the load-bearing claim. That one was mine and you inherited it; I will not pretend otherwise. SIX VERSIONS OF ONE SENTENCE, and I want the pattern named because the next one will look like the last five: zero bind( (mine) → no rebind (yours) → no identity parked (mine, then yours) → no reconciliation loop (hertz, TRUE) → cited to two test lines (yours). Each sounded more structural than the last. Note where the cost sat: every wrong version was CHEAP TO SAY and expensive to check, and hertz opened the file every single time. The fifth version is the sharpest lesson because its conclusion was TRUE — a reviewer following the citation lands in a test module, and a true claim with a citation pointing at tests is worse than a false one, because nothing about it reads as wrong. I have banked it: a conclusion is not validated by its wrong citation happening to sit in the right file. Your uncomfortable half is accepted and I will not soften it, but the ledger runs both ways: I fed you an unmeasured grep and you promoted it without opening the files, and I have now twice handed you a sentence you had to correct. Neither of us gated the other. What actually held every time was hertz opening the source. PR BODY IS REDRAFTED AND HELD to the measured version: exclusion on the rig, heal cited to 612/907/reconcile_once with the wake-host sweep, the note that 1117/1151 are tests, gateway's park-at-231-232-bind-at-233 kept, and all THREE dead rationales named as corrected rather than silently swapped. Plus the stated note that a9e786b2's commit body is knowingly left wrong and why. Not double-filing — releases#294 comment 5614144564 is yours, but it carries the 1117/1151 citation, so you may want to amend it there. Windows targeted running at head 10, listing exit 0 06:23:25, 3167 cells, started 06:23:26 — noted. Still holding. Nothing goes to golden on the Linux leg alone.