{
  "label": "trace-check",
  "argv": [
    "traceable-reqs",
    "check"
  ],
  "cwd": "C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\297-enforcement-shape",
  "environment_names": [
    "3DVPATH",
    "AGENT",
    "ALLUSERSPROFILE",
    "APPDATA",
    "AWS_PAGER",
    "BAT_PAGER",
    "CARGO_BUILD_JOBS",
    "CARGO_INCREMENTAL",
    "CARGO_TARGET_DIR",
    "CARGO_TERM_COLOR",
    "CARGO_TERM_PROGRESS_WHEN",
    "CHOCOLATEYINSTALL",
    "CHOCOLATEYLASTPATHUPDATE",
    "CI",
    "CLAUDECODE",
    "CLOUDSDK_CORE_DISABLE_PROMPTS",
    "COMMONPROGRAMFILES",
    "COMMONPROGRAMFILES(X86)",
    "COMMONPROGRAMW6432",
    "COMPOSER_NO_INTERACTION",
    "COMPUTERNAME",
    "COMSPEC",
    "DEBIAN_FRONTEND",
    "DELTA_PAGER",
    "DRIVERDATA",
    "EDITOR",
    "ELEVENLABS_API_KEY",
    "GH_PAGER",
    "GH_PROMPT_DISABLED",
    "GIT_EDITOR",
    "GIT_PAGER",
    "GIT_TERMINAL_PROMPT",
    "GLAB_PAGER",
    "GPG_TTY",
    "HOMEBREW_PAGER",
    "HOMEDRIVE",
    "HOMEPATH",
    "JAVA_HOME",
    "LANG",
    "LC_ALL",
    "LESS",
    "LOCALAPPDATA",
    "LOGONSERVER",
    "MANPAGER",
    "MYSQL_PAGER",
    "NO_COLOR",
    "NPM_CONFIG_AUDIT",
    "NPM_CONFIG_FUND",
    "NPM_CONFIG_PROGRESS",
    "NPM_CONFIG_UPDATE_NOTIFIER",
    "NPM_CONFIG_YES",
    "NUMBER_OF_PROCESSORS",
    "OMPCODE",
    "OMP_SPT_NODE",
    "OMP_SPT_OMP_BIN",
    "OMP_SPT_PROJECT",
    "ONEDRIVE",
    "OS",
    "PAGER",
    "PATH",
    "PATHEXT",
    "PIP_DISABLE_PIP_VERSION_CHECK",
    "PIP_NO_INPUT",
    "PI_RPC_EMIT_TITLE",
    "PNPM_DISABLE_SELF_UPDATE_CHECK",
    "PNPM_UPDATE_NOTIFIER",
    "POWERSHELL_DISTRIBUTION_CHANNEL",
    "PROCESSOR_ARCHITECTURE",
    "PROCESSOR_IDENTIFIER",
    "PROCESSOR_LEVEL",
    "PROCESSOR_REVISION",
    "PROGRAMDATA",
    "PROGRAMFILES",
    "PROGRAMFILES(X86)",
    "PROGRAMW6432",
    "PROMPT",
    "PSMODULEPATH",
    "PSQL_PAGER",
    "PUBLIC",
    "PWD",
    "PYTHONIOENCODING",
    "PYTHONUNBUFFERED",
    "PYTHONUTF8",
    "SHLVL",
    "SSH_ASKPASS",
    "SYSTEMDRIVE",
    "SYSTEMD_PAGER",
    "SYSTEMROOT",
    "TEMP",
    "TERM",
    "TF_INPUT",
    "TF_IN_AUTOMATION",
    "TMP",
    "USERDOMAIN",
    "USERDOMAIN_ROAMINGPROFILE",
    "USERNAME",
    "USERPROFILE",
    "VISUAL",
    "WINDIR",
    "YARN_ENABLE_PROGRESS_BARS",
    "YARN_ENABLE_TELEMETRY",
    "_",
    "__PI_NATIVE_VARIANT_CACHE"
  ],
  "owl_spt_names": [],
  "started_utc": "2026-09-14T12:32:56.965605+00:00",
  "free_before": 107146891264,
  "min_free_bytes": 107146891264,
  "samples": [
    {
      "time": 1789389176.972697,
      "free_bytes": 107146891264
    }
  ],
  "exit": 0,
  "ended_utc": "2026-09-14T12:33:01.973842+00:00",
  "free_after": 107153174528,
  "log_sha256": "2ee9891218d8eb6d611b5f291a344042b3becc129edca10bab5c37d28b23f5d5",
  "summary_lines": [
    "       F-034 leg a (perri/hertz field finding 2026-07-09): the ADAPTER_UNRESOLVED refusal hint must print a WORKING command form. It currently says 'pass --adapter <name[:profile]>', but --adapter is a `spt api` GROUP flag, NOT a `listen` flag \u2014 following the hint literally (`spt api listen <id> --adapter <name>`) produces clap `error: unexpected argument '--adapter'` (exit 2). Fix: the hint prints the group-level form, e.g. `spt api --adapter <name> <cmd> \u2026` (a hint the operator can copy-paste and have work). Gate: the ADAPTER_UNRESOLVED message text carries a clap-VALID invocation (group-level --adapter placement) \u2014 a unit asserting the hint string parses under the api clap grammar, or at minimum places --adapter before the subcommand. Pure UX/hint-correctness fix, no behavior change.",
    "       A perch directory is RESIDUE only on a POSITIVE record-absence predicate, and the store that answers it is the owlery tree itself (3.4 extension; releases#109, doyle-ruled 2026-08-04). There is NO independent endpoint-existence store on a node: `spt::roster::enumerate`, the daemon's `projwriter::enumerate_perches` and `perch::list_self_perch_ids_checked` all derive the endpoint set from `read_dir(owlery)`, and a dir with no `info.json` is not a perch \u2014 so THE PERCH DIRECTORY PLUS ITS PARSEABLE RECORD IS THE ENDPOINT RECORD. The local registry is NOT that store and must never be asked: KNOWN-HAZARDS 4.3 has `clean_stale_entries` DELETE dead-pid rows and `unregister_address` fire on an ordinary stop, so registry-absence is the normal steady state of every OFFLINE endpoint (measured HFENDULEAM 2026-08-04: 6 of 14). PREDICATE: residue iff no `info.json` is present on ANY read attempt. Positive, present-tense, one read, and NEVER an age/mtime heuristic \u2014 a dormant endpoint, a suspended session and a long-idle live agent are indistinguishable from 'old' by mtime. Absent is the ONLY answer that authorizes deletion, so the read keeps NotFound distinct from every other I/O error: unreadable \u21d2 occupied, corrupt (present, unparseable) \u21d2 occupied (a destroyed record belongs to an endpoint that exists). REAP POPULATION IS NARROWER THAN RESIDUE: recordless AND spool-less AND non-empty AND no record-write in flight (`.info.lock` held \u21d2 a bringup mid-create) AND every nested/shells child independently reapable (deepest-first; a recordless parent holding ANY non-reaped child is itself refused). A REFUSED DIRECTORY SHIELDS ITS WHOLE SUBTREE (doyle, ruled 2026-08-04): a descendant that would qualify on its own is reported SHIELDED-BY-REFUSED-PARENT and left alone, because refusing a directory must mean not modifying its CONTENTS either \u2014 carving a child out destroys part of what the refusal report just asked the operator to look at, and can move the parent's own classification on the next pass, and a sweep whose refusals are unstable across its own runs is untrustworthy. A recordless dir carrying a SPOOL is refused permanently \u2014 undeliverable-by-construction settles deliverability, not VALUE, and that spool is the only surviving copy of what was queued. An EMPTY dir is refused permanently \u2014 the mid-create race 3.4 protects exists here identically and no positive discriminator for 'not mid-create' exists for an empty dir. A reparse point anywhere in the subtree is refused. Store unavailable (`read_dir` on the root fails) \u21d2 DO NOTHING and say so, reported distinctly from an empty owlery.",
    "       releases#106: the release workflow REFUSES to publish a release whose built binary disagrees with the tag. `.github/workflows/release.yml` already guards the CHANGELOG against the tag (`ver=\"${GITHUB_REF_NAME#v}\"`, `::error::` + `exit 1`) but nothing proves the ARTIFACT carries that version \u2014 a tag pushed without bumping `[workspace.package] version` (and the first-party `spt-*` lines in `Cargo.lock`) ships a binary that self-reports the previous release. Shape: after the platform builds and BEFORE `gh release create`, execute the freshly built binary FOR THE RUNNER'S OWN PLATFORM with `--version`, compare to `${GITHUB_REF_NAME#v}`, and on mismatch fail with a named error stating BOTH values and naming the fix. SCOPE CONSTRAINT, load-bearing: a cross-compiled `matrix.target` artifact CANNOT be executed on the runner, so the assert must sit where a natively-runnable artifact is in scope \u2014 the native (non-`matrix.target`) leg, or the notes job after artifact download if the native asset is fetchable there. The assert lands in the RELEASE workflow, never as a new CI window (two-runs-per-sha ruling). SHIPPED SITE: the `assemble` job after `download-artifact` and before the docs bundle and `gh release create` \u2014 the one place the whole asset set exists at once on a box that can natively execute part of it, and the bytes there are the ones about to be published rather than a build-tree lookalike. The two Linux assets are covered; the WINDOWS asset is not, stated rather than glossed \u2014 no Linux runner can execute it, and a matching Linux artifact is evidence the workspace version was bumped, not evidence the Windows leg built from that tree. VERIFICATION STANCE, recorded at mint and honored: the workflow is tag-triggered and cannot be run locally, so no green is claimed for it. Instead the logic was EXTRACTED to `.github/ci/release-version-assert.sh` (the repo's own convention for CI logic, beside `ci-notify.sh` and the reap-census pair) precisely so it stops being unrehearsable, and its selftest runs on every golden Linux leg. Gate: impl \u2014 the script plus release.yml calling it; unit \u2014 `release-version-assert-selftest.sh`, 12 assertions, over half of them negative controls (stale binary, binary ahead of tag, missing artifact, unrunnable binary, empty asset list, absent tag)."
  ]
}