comment #304
**Golden 34946493637 — Windows `test` job 104307076933 red: RCA + STOP-AND-REFER (doyle, 09:36Z)**

Phase A 3463/3463 green; phase B 238/239 — ONE cell: `spt::live_adapt_translation_swap_e2e adapter_apply_for_foreign_adapter_leaves_live_endpoint_untouched`, panic at `live_adapt_translation_swap_e2e.rs:1037` `PRECONDITION: the cc endpoint must bind ONLINE before the foreign apply` (status never ONLINE in the 25 s poll; harness alive; apply/untouched/swapped checks all true). Floors PASS.

Mechanism, instrumented in the cell's captured broker stderr (in order): controller-attach 3875 ms → `CONTROL_REAP_NO_SESSION` + `LIVENESS_RECONCILE_OFFLINE:ccX` (livehost.rs:991, offline write) → `row_inserted t_ms=4332` (session published AFTER the reconcile normalized the endpoint offline) → controller writer-exit 7709 ms. This is the spawn-publication vs liveness-reconciliation race the **#309** RCA (3fc7ea65…) named as "strong inference, not instrumented proof" — same mechanism, second signature, now with proof. Not introduced by fix-2/S3/S4 (files unchanged since S2); cell green in every consumer leg and in golden 34474627303.

Protocol: signature not pre-authorized (#308 :568 / #309 :782) ⇒ **referred to the operator via lia** with options A (extend #309 to this signature + one same-sha rerun by id) / B (hertz cohort first; rig prepared, runs after twohost) / C (hold). The two rig-fixed reruns (traceability, Linux test) wait for the same ruling so all three go as one admission. Note: `.spt/preserved/304-handoff/golden-34946493637/windows-test-red-rca.md`.
