hertz -- WINDOW 6 START, on doyle's WORD (his workspace check on d0a74461 DONE exit 0 at 11:11:20Z, box free). This message rides the launcher and is the first act of the window; no producer has run yet. SUBJECT: cba18cd5, lane test/304-remote-friction, worktree .worktrees/hertz-304, pool .worktrees/hertz-304/target. Tree CLEAN, docshost.rs work blob == HEAD blob 2c4099f0. Tip = 69438c01 + the BOUND-PORT unit cell. CAP 900 s TOTAL, one attempt per arm, --success-output immediate on every arm, unfiltered where the question needs it. Predictions filed BEFORE any execution at predictions-cba18cd5.txt (Q1-Q6). SIX ARMS, in this order: w6-cell the new cell alone PREDICT GREEN, 1 test run w6-rgate R-GATE mutation applied, cell alone PREDICT RED at the gate assert w6-armA the two pre-existing cells, DEFAULT TMP PREDICT both PASS w6-armB the same two, HERTZ_RIG_TMP_IN_REPO=1 PREDICT both FAIL w6-rdrop R-DROP mutation applied, cell alone PREDICT RED at the final assert w6-lib-full the whole lib, unfiltered PREDICT 988 run / 988 passed / 0 failed (rgate and rdrop run in that spread so a cap squeeze costs the least valuable arm last; each mutation is reverted immediately after its own arm, not at the end.) WHY A NEW DRIVER (window6.py) RATHER THAN A LABEL LIST: two arms need a PRODUCT SOURCE EDIT between producer runs. A window that edits product source has to revert it and PROVE the revert before the next arm, or every later arm measures an unknown tree. So the driver reverts with git checkout -- on that one path and records BOTH the working-tree hash-object AND HEAD's blob oid after each revert; the report carries them per arm plus a final tree-clean line. The revert is safe only because the sole edit in this tree is the mutation the driver itself just made -- the cell is committed at cba18cd5 -- and that precondition is checked, not assumed. Pre-flight before this START: driver imports, both mutation anchors count EXACTLY 1 (a mid-window anchor miss would abort after arm 1), cell name present once, tree clean. THE TWO MUTATIONS, and why the obvious one is the wrong direction: R-GATE hoists BOUND_DOCS_PORT.store(bound, ...) OUT of broker.as_ref().map(...) so EVERY listener publishes. Predicted RED at the gate assert, left Some(), right None; asserts (a) and (b) pass first, (d) never reached. A GREEN here refutes the CELL, not the product, and I will report it as that. R-DROP deletes BOUND_DOCS_PORT.store(0, ...) from impl Drop. Predicted RED at the final assert, left Some(), right None, with (a) (b) (c) passing first. Doyle's original arm -- "the store commented out" -- would have been a GREEN control: deleting the publish leaves the gate assert passing, because the gate assert EXPECTS None. The mutation that falsifies it has to make a brokerless listener PUBLISH. He accepted the correction; recording it here because a green arm read as a control is exactly the failure this discipline exists to prevent. THE A/B IS A CONFIRMATION, NOT AN OPEN QUESTION. The TMP mechanism is already proven without a run: git -C rev-parse --show-toplevel is the spt-core checkout with the bs-core remote, while the same probe from the default TMP answers "not a git repository", and both observed strings are remote-derived (slug and display_from_url of that URL) rather than folder-name-derived. The rig is FIXED (base now outside the tree) and HERTZ_RIG_TMP_IN_REPO=1 restores the old placement on purpose, so ARM B is the negative control for the fix. ARM A failing means the mechanism is incomplete; ARM B passing means it is wrong and I withdraw it. ZERO-MATCH GUARD: w6-cell must report exactly 1 test run. If it reports 0, my filter name is wrong and the arm measured nothing -- that is a rig fault, not a green, and I will not read a 0-match summary as a pass. ADMISSION: run at the word, immediately before this START, my own reader; both positive controls must read TRUE with zero path-keyed foreign hits in my pool, blind counted by identity. Reported in full in the END. A lock wait may appear from the editor's rust-analyzer building into this pool on its own schedule (IR-100) -- it showed up in this sha's compile-gate log -- and it will be named rather than left to look like a foreign builder. END will carry: every arm by name with exit and elapsed, the cell's verdict, both mutation arms with their actual left/right values, the revert oids per arm, ARM A/B verdicts with the exact strings, the unfiltered totals against Q4's 988/988, the leaky set, Q1-Q6 each against its result including anything I got wrong, and the post-census saying whether the box is free from me.