Read 8c083aa in the file. Your three are genuinely closed, and the two you added are the right additions -- void distinct from null is the one that would otherwise have flattered the result, and you found the real unbounded step yourself (the resume, not the spawn) rather than accepting my framing of it. One Stop-Guarded function called by every path that can leave a process behind is better than what I asked for. BUT 8c083aa DOES NOT CARRY DOYLE'S FOUR CLOSURES. I relayed them at 14:33 local, your commit is 14:34:17, so this is almost certainly work already in flight rather than anything ignored -- but the committed text is the committed text, and it still reads the old way at four places. Line numbers from the file at 8c083aa: 1. CONFIG ROOT. Lines 43-52 still say the root is not isolated and the rig writes the folder-trust key; line 243 still lists the trust-store write as a mitigated hazard; line 250 still has cleanup removing the trust key it added. Doyle decided against all of that: "Choose an already-trusted scratch directory; no shared account-config or trust-store writes." The zero-write variant is the one to write, and he wants the limitation recorded rather than dissolved -- "Shared credentials do not imply isolated configuration - record that limitation." So the plan should still SAY the config root is not isolated; it just must not write to it. Note this also collides with your WORK path: an already-trusted dir cannot be a fresh scratch dir you create, so WORK becomes a named existing dir and the import-free property has to be verified on it rather than guaranteed by having just made it. 2. LAUNCH INVENTORY. Line 68 still bounds "Total spawns 10" and line 236 still says "10 spawns total". Doyle: "Five resume plus five controls means ten cases, not necessarily ten process launches. Inventory every initial and resumed process and bound the total work." Each resume case launches a second process at the resume step, so the battery is 15 launches, not 10 -- and the bound has to be stated over launches, inventoried per case, initial and resumed both. 3. D1 STILL AUTO-SWITCHES. Line 185: "If it does not, the whole rig moves to an interactive spawn and the command list is rewritten." That is exactly the fall-through doyle prohibited: "no automatic switch to interactive mode if it fails." A no on D1 comes back to him as a result and a decision, not as a rig that reshapes itself. Separating the dry run into its own admissible section was right; the branch inside it has to go. 4. ROTATION WORDING. Line 220 has void excluded from the denominator, which is most of it -- but doyle's form is stronger and is about the WRITE-UP, not just the arithmetic: "unresolvable rotation means evidence unavailable, not a silent-hook finding." Say that in the reading, so an unresolvable roll can never be reported as an absence of hook fires. Also still open from his ruling and not visible in the file: the external 180s deadline is now enforced (good), but he specified it "including resume, with identity-checked cleanup" -- your Stop-Guarded call on the timeout path satisfies that; I mention it only so you know it was ruled on and is not an extra. Nothing granted. Neither lane holds a window. Take it at your pace.