# #304 REMOTE-FRICTION — golden-head hand-off to deployah (doyle 2026-09-13, re-pinned 2026-09-14 14:25Z to fix-2, re-pinned 2026-09-15 07:48Z to A' successor S3, re-pinned 08:09Z to docs-only S4, re-pinned 10:22Z to test-only S5 after the S4 golden closed red — HAND-OFF)

Fields marked ⟨…⟩ are filled at hand-off; anything still ⟨…⟩ at hand-off means NOT READY.

## Candidate — CURRENT HEAD (supersedes the S4 / S3 / 7890ead3 / b848 pins below, which are kept as chain history)
- `asm/304-v3` head: **`ddd7fc7f070667524578c282894dd44a2e36062f`** `test(daemon): give the twohost web owner seed control and a docs listener` (S5, hertz, TEST-ONLY, parent exact S4 `35d6f7a3`; fixes the S4 golden's twohost red — see "S5" and "S4 golden … CLOSED RED" below). Exactly one blob vs S4 (diff-tree): `crates/spt-daemon/tests/twohost_web.rs` a59a946a→d8dcafda, +42/−1; zero deltas under `src/`, `Cargo*`, `build.rs`, `adapters/`, `docs-site/` ⇒ shipped inputs byte-identical to S4/S3/fix-2 ⇒ the #297 field carry-forward and the fix-2 release-build pins stand. Gate (doyle): traceable-reqs 0.4.1 exit 0 (918/918, 0 findings) and 0.2.0 exit 0 in the assembly tree at S5; raw trailer `Co-authored by: hertz`; hertz check 0 / clippy -D warnings 0 / 7/7 unopted-in twohost_web cells 0 / traceable 0.4.1 0 (proof `.spt/preserved/hertz-S4-twohost-seed-docs/S5-handoff.json`). Worktree ff'd 2026-09-15 10:21Z (`35d6f7a3..ddd7fc7f`, fast-forward), **UNPUSHED** — deployah pushes/runs. Chain: … → fix-2 `7890ead3` → S3 `6c89e8f7` (test) → S4 `35d6f7a3` (docs) → S5 `ddd7fc7f` (test).
- Previous head S4: **`35d6f7a38f2189455f1a9e1a85a86b1e4bc0481a`** `docs(release): keep bootstrap notes focused on user impact` (todlando, DOCS-ONLY, parent exact S3 `6c89e8f7`; deployah blocker JYRLUUFT / hold 5676690730). Exactly two blobs vs S3 (diff-tree): `CHANGELOG.md` 29617492→b6745ec2 and `docs-site/src/changelog.md` 11c33765→e9d9d6de, +2/−22 — the v0.70.0 bootstrap bullet replaced with deployah's approved end-user wording verbatim (CHANGELOG.md:50), the four mechanism/history strings (`pre-write census`, `NetSecurity`, `-Package Any`, `NoLocalUser`) absent from both files; xtask gen/check exit 0 source-matched on kitsubito, traceable 918/918; raw trailer `Co-authored by: todlando`; proof `s4-release-note/receipt.txt`. No production/build input changed ⇒ S3's suite receipts and the fix-2 field carry-forward stand; docs-site is regenerated content only (b848 precedent: cargo no-op, executables byte-identical). Chain: `b8482445` → `49a08a07` → S2 `527cd8e8` → fix-2 `7890ead3` `fix(firewall): omit Package binding and accept mixed-profile enforcement` (6 files, +188/−82, all under `bootstrap_firewall` + its tests/fixtures/toml) → S3 `6c89e8f7` `test(daemon): c1 give-up spool waits for generation completion` (2 test blobs, +72/−27; gate + both-OS suite receipts under "A' successor S3") → S4 `35d6f7a3`. Version still 0.70.0. Worktree ff'd 2026-09-15 08:08Z (`6c89e8f7..35d6f7a3`, fast-forward), **UNPUSHED** — deployah pushes/runs.
- Shipped-binary inputs are byte-identical between 7890ead3 and S3 (S3-equivalence.md), so the fix-2 release-build pins and #297 field acceptance below carry forward (deployah F6MFZJOZ).
- Gate on 7890ead3 (doyle): ancestry/trailer/scope/tags PASS; traceable-reqs 0.2.0 (CI pin) AND 0.4.1 exit 0.
- Release build (todlando cold build, re-hashed by doyle): `.worktrees/297-enforcement-shape/target/release/spt.exe` **da950c0ca6c37bf8f8b7d675723fb3c3399009934f00ee13eafcc0bac400aed9** (38,938,624 B); `xtask.exe` **5d8e9da946e3cc3054fc4243168a3f9fad724359a90fb6cdd7209b2330c0abb3** (5,222,400 B). Pins relayed to hertz + deployah (msgs EZ2OCBAJ / BR76TFXZ).
- Fix-2 shape ruling: `window6-doyle/doyle-ruling-297-fix2-shape-run-02.md`; board #297 comment 5664256150, #304 comment 5664256397. ENFORCED ⇔ PrimaryStatus OK ∧ 1 ∈ raw ∧ 20 ∉ raw; ProfileInactive(5) informational on a Private-only host.

## Consumer receipts on 7890ead3 (golden-mirror HEAVY expression; see RIG DELTA in DISPOSITION.md — env knobs NOT mirrored)
- Linux (todlando, kitsubito, warm takeover of the full49 tree after a capacity VOID + approved one-target reclaim): `consumer-linux-7890ead3/receipt.txt` sha256 f7186226d1aa9456e8fec28bc8fc2ef1278805ccd0af608c17a6850067e31b6f — A 3417 passed / 1 skipped, B 224 passed, inventories exact vs baseline, delta 0 (fix-2 is `#[cfg(windows)]`), HEAD pinned 7890ead3. ACCEPTED by doyle.
- Windows (doyle, asm warm target): `consumer-windows-7890ead3/attempt1-receipt.txt` sha256 0aed8db470963e1f34289d7914cd6ae6f548268b1b70c0281a11beb57b938004 — A exit 0, 3463 passed / 1 skipped (= S2 3459 + 4 new, as predicted); **B exit 100, 236 passed, 3 FAILED** — full record + mechanisms + cohort/ruling holes: `consumer-windows-7890ead3/DISPOSITION.md`. Board: #304 comment 5665188212. 6 leaky phase-A spt.exe reaped (`attempt1-orphan-reap.txt`), pool released.
  - (1) `webserve_attachment_e2e` registry lost-update: pre-existing, diff-disjoint, source-proven cross-process race → **#308** (BUGFIX, backlog; RCA comment 5665237597, sizing comment 5665285296). Cohort rate 1/10 serialized (hertz; DISPOSITION.md). Milestone home: operator ruling A (2026-09-15) — ship on record with #308 named, backlog fast-follow; fix draft in Linux-only validation (todlando, authorized after the S3 receipt).
  - (2)(3) `inject_control_wedge` g1/g7 "brain IPC read deadline elapsed" @2.04 s: candidate RIG-SHAPE reds — both consumer legs lacked golden's `SPT_ATTACH_IPC_DEADLINE_MS=30000` and `SPT_ATTACH_GATE_WATCHDOG_MS=120000` (advisory ports WAS set; the env receipt is written pre-overlay); cohort arms DONE (hertz, DISPOSITION.md §arms): arm 1 consumer shape 2 s — g1 10/10, g7 10/10, spawn tail to 1967 ms against the 2000 ms budget; arm 2 golden shape — g1 10/10, g7 10/10; arm 6 full-HEAVY golden — g1 PASS 13.4 s, g7 PASS 15.6 s. Reading: 2 s/30 s discriminator INCONCLUSIVE under serialized load; golden shape executes under full load; original causality inconclusive, on record.

## Candidate (09-13 draft pins — HISTORY)
- Branch `asm/304-v3`, worktree `.worktrees/asm-304-v3`. Base: `85f84d73` (fold `7357ea32` + assembly + repairs + numeric suite; hertz-ruled S6ESSJ3N) + `origin/main f4e7635c` + `feat/300-input-acceptance 982b9084` + `diag/49-267-obs 21c6c76c` + `diag/302-rc-hitch 86696e17` + xtask seed scrub + two authorized test/whitespace commits + release shape.
- Assembly sha (pre-bump): `4caea32205127959edee68648cf21f66331eb679`. Release-shape sha (v0.70.0): `c9663459f2064a24e55bab8a8fcb893e27945445` (todlando, four files; lockfile audit in `.spt/preserved/asm-304-v3-todlando/release-0.70.0/`). FINAL CANDIDATE after deployah's notes corrections: `b848244577d398600b59c7829fef9edbdb6315fa` (CHANGELOG.md + generated docs-site changelog only; rebuild a cargo no-op, executables byte-identical).
- Gates on the final source (todlando, proof `.spt/preserved/asm-304-v3-todlando/`): cargo check --workspace --all-targets PASS; clippy -D warnings PASS; traceable-reqs 0.4.1 918/918; xtask check PASS; 195/195 named hermetic cells (122 spt / 39 daemon / 33 store / 1 xtask), 0 retries. Re-run on the bump sha: xtask gen + check PASS, traceable 918/918, debug CLI reports 0.70.0.
- Firewall module blobs at the candidate: `bootstrap_firewall.rs c30d6b54`, `windows.rs 31ef24c8` (848a23fe + nine test-only borrows + five whitespace-only diagnostic literals), `linux.rs 08f615c4`.
- Release build (doyle, one build, jobs=2, pool claimed from the worktree): `target/release/spt.exe` 68d9f9312368e042c2bdb066a0815a72fac669ac2571c5e5de9aa64b521ae887 (38,884,352 B, `spt 0.70.0`), `target/release/xtask.exe` de215d4a24ec0ee5a4a2e5057bc89c5605806d725efe10d9fac56f34486f7f41 (5,217,280 B); log `release-build.log`, 10m18s, BUILD_EXIT=0. Linux triple: none built (Windows-to-Windows bootstrap does not require it; REQ-WEB-LAN-BOOTSTRAP-INTEGRITY per-triple gate 404s a missing triple by name).
- Version: 0.70.0, CHANGELOG [0.70.0] - 2026-09-13, docs-site changelog regenerated.

## Evidence map (fulfilment, per request)
| Req | Evidence | Status |
|---|---|---|
| #301 root/docs redirect, #282 bound-port URLs, #288 cmd capability wording, #251 viewer detach | product branch (W1 receipt 5633659233) | done |
| #230 stale-client advisory | 38e0e723, b1c665eb | done |
| #300 remote rc USER_INPUT → scoped helper | core-only per operator ruling (board comment 5653212174); 9aaf037d + 4dbd2518; doc/impl/unit active; int = two-node field leg POST-PUBLISH (operator-ruled 2026-09-14 via lia; recorded #304 comment 5659459346) | done modulo int (post-publish) |
| #299 list stalls | attribution + remedy A (982b9084; ceiling 10 s → 2.5 s; closing comment 5653090543; follow-up #306) | done |
| #297 LAN bootstrap firewall | fix-2 7890ead3 (drop `-Package Any`; verifier Empty Package; PrimaryStatus raw UInt16; decide() = OK+1∈raw+20∉raw). Window 6 on S2 = WRITTEN-NOT-ENFORCED (ruling `window6-doyle/doyle-ruling-297-window6-S2-written-not-enforced.md`; run-02 probe isolated `-Package Any`). **Window 7 on the fix-2 exe (da950c0c) = ENFORCED + LAN-REACHABLE** (GO #2 `box-clear/GO2-fix2-window7-doyle.md` sha 82caac32…; GO #1 spent, VOID-BY-RIG, chain in `box-clear/GO-hash-chain.md`; run 20260914T160645Z; verdict `window7-doyle/verdict.md` sha 61d685d9…; board #297 comment 5667101807): both rules raw [5,1], OK, 20 absent; remote GET from kitsubito over LAN = 200 (window 6: timeout); sibling port refused. Cleanup CLEAN: `window7-doyle/cleanup.md` (receipt 81350f88…, native 743287d6…, pair census 0/0 with live positive control). | **DONE** |
| #49/#267 refresh freeze | observables only (REQ-REFRESH-WAIT-ATTRIBUTION doc+impl); Q1/Q3 unanswered | RELOCATED to fast-follow #307 (backlog); operator-ruled 2026-09-14 via lia; #304 comment 5659459346, #307 comment 5659464087 |
| #302 rc hitch | diagnostic probe only (SPT_RC_HITCH_DIAG, REQ-RC-HITCH-DISCRIMINATOR); candidates + remedy design in .spt/preserved/302/; field reading travels with #307 (operator, post-ship) | RELOCATED to fast-follow #307 (backlog); same ruling/comments |

## First-execution cells (never green before this candidate)
- REQ-INPUT-PROVENANCE-ACCEPTANCE-REPORT unit set (28 + 4 cadence/trim cells; names in `.spt/preserved/todlando-300-input-acceptance/selected300-review.txt`).
- REQ-UNLISTED-PRESENCE-PROBE re-pinned ceiling cell + the second #299 CLI cell (`selected299.txt`).
- xtask seed-scrub isolated git-child cell.
- REQ-RC-HITCH-DISCRIMINATOR smoke arms (`.spt/preserved/302/smoke.json`).
- Seven changed Windows bootstrap diagnostic/spec cells (`selected-cells.txt`).
- **ADDENDUM 2026-09-15 (fix-2 + S3 cells; the list above is the b848-era set):**
  - Fix-2 `7890ead3` added four `#[cfg(windows)]` unit cells in `spt-daemon bootstrap_firewall::windows::tests`: `unrestricted_rules_omit_the_package_parameter`, `an_ok_multi_profile_rule_with_codes_5_and_1_is_enforced`, `an_inactive_rule_with_codes_5_and_20_is_refused`, `an_ok_rule_with_code_1_is_enforced`. First executed: Windows consumer A on 7890ead3, all PASS (`consumer-windows-7890ead3/attempt1-phase-a.log`, cells 874/876/877/895 of 3463 — the "+4 vs S2 3459"). Re-executed PASS on S3: `consumer-windows-S3/s3-daemon-v2r-run.log` cells 84/86/87/101 of 1296. Linux: not compiled (cfg), 0 occurrences in the Linux inventory, delta 0 as recorded.
  - S3 `6c89e8f7` changed no cell NAMES (inventories identical to fix-2: 1296 Windows / 1256 Linux). It changed the BODY of one cell, `spt-daemon::inject_control_wedge c1_strike_fault_stamps_perch_and_bounded_respawns_then_gives_up` (generation barrier), and the fixture BIN `xlate_choreo_fixture` (+15, consumed by `inject_control_wedge.rs` and `broker.rs` integration tests). Executed on S3: Windows PASS 1227/1296 4.728 s (`s3-daemon-v2r-run.log`); Linux PASS 1192/1256 1.127 s (`corrected-workspace/phase-daemon.log`). Every fixture consumer ran in those same legs: `inject_control_wedge` 19/19 PASS on both OSes; `broker` in the same package(spt-daemon) expression, 0 reds.

## Shared-seam consumer receipts (RELEASE-RUNBOOK.md:152-166 — crates whose last full run predates the change run IN FULL on BOTH OSes BEFORE hand-off)
Affected test crates: spt, spt-daemon, spt-net, spt-store (every seam below lives in one of them; their last full runs predate this batch). Execution mirrors golden.yml exactly (HEAVY verbatim from the candidate's golden.yml; phase A `not (HEAVY)`, phase B `HEAVY`; `--workspace --no-fail-fast`; `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1`).
- Windows (doyle, profile ci-windows, asm worktree's own target, attempt3 under full OWL_*/SPT_* name scrub — env after=[] in `attempt3-env.txt`): `.spt/preserved/304-handoff/consumer-windows/attempt3-receipt.txt` — sha b848244577d398600b59c7829fef9edbdb6315fa; phase A exit 0, 3457 run / 3457 passed (8 leaky), 1 skipped, 339.5 s; phase B exit 0, 239 run / 239 passed (1 slow), 892.6 s. Attempts 1–2 VOID (inherited live-agent identity env; IR-107); the four attempt1 reds all pass in attempt3 (identity-refusal class, seam page `WINDOWS-REDS-SEAM.md`). 14 orphaned test daemons reaped post-run, 0 survivors. The 1 skipped cell is `spt-net net::endpoint::tests::mdns_discovery_connects_by_id`, the tree's only `#[ignore]` (`endpoint.rs:746`, needs LAN multicast) — standing author ignore, identical under golden, not a #304 exclusion.
- Linux (todlando on kitsubito, profile default, isolated worktree+target at the corrected sha, bundle transfer, attempt3 under full OWL_*/SPT_* name purge — `environment.json` 13 key-name snapshots, incoming OWL/SPT=[], forbidden=[] throughout): `.spt/preserved/304-handoff/consumer-linux/attempt3/receipt.txt` — sha b848244577d398600b59c7829fef9edbdb6315fa; phase A exit 0, 3417 run / 3417 passed (1 leaky), 1 skipped, 39.3 s; phase B exit 0, 224 run / 224 passed (1 slow), 1148.6 s. Raw log SHA256s verified against producer receipts; six own post-A survivors reaped, zero post-B; pool released. Attempt1 VOID (IR-107 TMPDIR), attempt2 retained valid-modulo-capture-gap (`attempt2-QUALIFICATION.json`); attempt3 is the clean-environment evidence. Same `#[ignore]` skip as Windows.
Seams touched (for the reader; the receipts above are the artifact):
- `crates/spt-daemon/src/broker.rs` InputWriter/InputRecord seam (deliverybytes): consumers = REQ-HAZARD-PTY-INPUT-WRITER-WEDGE order cell, inject-floor cells, translation re-drive cells — in the daemon unit lane.
- `crates/spt/src/api/nowsignal.rs` FILE_ACCESS_HELPER (local arm removed): consumers = now-signal category cells; REQ-NOW-SIGNAL-FILE-ACCESS-HELPER title amended.
- `crates/spt/src/rc.rs` pump (InputPaths records): consumers = attach.rs local/remote attach cells, netstream restart cells (integration lane).
- `crates/spt-net/src/net/attach.rs` AttachRecord (two additive kinds): round-trip cell updated.
- `crates/spt-store/src/serving.rs` add_input_reference: serving registry cells.
- `crates/spt/src/cli.rs` PRESENCE_PROBE_CEILING: roster/presence cells.

## Board records required before golden (greenlit-form)
- #300: operator core-only ruling recorded (comment 5653212174). Staging cross-reference on #304: comment 5659459346 (two-node field leg POST-PUBLISH). DONE.
- #49/#267, #302: operator disposition RELOCATE → milestone #307 (fast-follow), state backlog, recorded on #304 via alchemy comment 5659459346 (+ #307 seed comment 5659464087). Detached from #304, attached to #307. DONE.
- #297: field acceptance recorded — comment 5667101807 (window 7 verdict on fix-2 7890ead3; shape ruling 5664256150). DONE.

## Milestone membership at golden (greenlit-form)
- #304 rides with 8 members: #230 #251 #282 #288 #297 #299 #300 #301. (#49 #267 #302 relocated to #307.) Confirm the alchemy board shows exactly these 8 before golden.

## Operator ruling + pre-agreed protocol (2026-09-15)
- Ruling A + A' (Reavo in-session 2026-09-15, via lia RRWDOYDQ; #304 comments 5676009820 + 5676014821): ship on record with #308/#309 named; A' successor S3 = hertz's test-only c1 repin on 7890ead3, spt-daemon suite both OSes.
- deployah acceptance (DT5AOKTE): rerun protocol accepted — only the CLASSIFIED #308/#309 failure signatures qualify (not a line number alone); doyle records the specific failure + ruling on #304 BEFORE deployah runs ONE same-sha rerun of that leg; second red in that leg or any unclassified red ⇒ STOP AND REFER; originals retained; a later green proves neither defect fixed. Field carry-forward accepted WITHOUT a fresh window iff the COMPLETE diff proves exactly the two test-file changes with all production/build inputs unchanged — attach the full diff, name list and blob comparison (diff --stat insufficient); provenance stays "7890ead3 / exe da950c0c…, accepted for S3 by verified equivalence", never "field executed at S3". S3 needs its own test/gate receipts; tested sha == shipped sha = S3; any production/build-input delta voids the carry-forward.

## A' successor S3 (2026-09-15)
- **S3 = `6c89e8f7545db54772ea5686b4d59718573d1f08`**, parent exact 7890ead3, branch `test/c1-generation-barrier-7890ead3` (hertz), one commit `test(daemon): c1 give-up spool waits for generation completion`, raw trailer `Co-authored by: hertz`. Exactly two blobs changed (whole-tree ls-tree compare, no add/remove): `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs` 64411a37→dbad14a7 (+15), `crates/spt-daemon/tests/inject_control_wedge.rs` e545bd80→0913e2d5 (84 lines); 72+/27−. Evidence: `consumer-windows-S3/S3-equivalence.md` (e24098e6…), `S3-full.diff` (0ff32ee4…), `S3-lstree.diff` (19812864…), `S3-diff-tree.txt`; hertz receipt `.spt/preserved/hertz-c1-Aprime-LYGSHB3E/S3-handoff.json`.
- Gate: hertz check/clippy(-D warnings) 0; doyle traceable-reqs 0.2.0 = 0 and 0.4.1 = 0 (918/918); parent/trailer/clean verified by doyle.
- **deployah CARRY-FORWARD ACCEPTED (F6MFZJOZ, independently verified):** the fixture is a separate binary target, not a shipped-binary input; no fresh #297 field window. Provenance: window 7 executed 7890ead3 / exe da950c0c…, accepted for S3 by verified shipped-input equivalence. S3 still needs its own suite receipts + golden; carry-forward ≠ intake approval.
- Suites on S3 — rig lesson first: a `-p spt-daemon` invocation does NOT build the cross-package fixture bin `mock-adapter/capture-player` (spt-term `fixture_bin.rs:40` panics), so both OSes' first attempts are **VOID-BY-RIG** and preserved, and the corrected shape on both is `cargo build -p mock-adapter --bin capture-player` + existence assert → `nextest list/run --workspace -E 'package(spt-daemon)'`, golden three-knob values recorded.
  - **Linux (todlando, kitsubito) GREEN**: `successor-linux-daemon/corrected-workspace/` (43 proof files, driver bdca4c67…, fixture 8f99cfa4… built 07:14:04–09Z, inventory 1,256 names missing=[] added=[] vs prior A/B daemon union) — `Summary [228.830s] 1256 tests run: 1256 passed (1 slow, 1 leaky), 0 skipped`, native exit 0, 07:14:14–07:18:04Z, raw-log c249cadf…; pool released, census 0/0, 32 GiB floor held. Void package-only attempt kept under the parent dir with VOID-BY-RIG.json.
  - **Windows (doyle, hertz's tree)**: attempt 1 `-p` = VOID-BY-RIG kept (`s3-daemon-*`: 1296 run, 1293 passed, **exactly the 3 predicted `attach_resize_capture` cells red**, exit 100, 06:59–07:17Z). Attempt 2 launch A (`s3-daemon-v2-*`) died at fixture build with rustc `STATUS_CONTROL_C_EXIT` — launcher shape, not the candidate (`s3-daemon-v2-DEAD-ctrlc.txt`). Relaunch **`s3-daemon-v2r-*` GREEN** (driver adf67271…, hidden new console, pid 37536): fixture build exit 0 07:19:35Z (final `capture-player.exe` sha 8539c367…, re-linked by the workspace build 07:19:47Z), inventory exit 0 07:33:16Z, run — `Summary [644.610s] 1296 tests run: 1296 passed (4 slow, 6 leaky), 0 skipped`, native exit 0, end 07:44:31Z, run-log sha 7fac2267…; orphan sweep 0; pool lane `consumer-windows-S3-daemon` released from inside hertz's tree (exit 0), tree clean. Cell count 1296 = attempt 1's 1296 (same inventory; the 3 rig reds are the only delta).

## S5 — test-only successor for the twohost rig (2026-09-15)
- **What it changes:** `twohost_web.rs` role B (the web owner) hosted its brain's broker under an invented name and started neither seed control nor a docs listener. The candidate's serve-for correctly asks the canonical seed control for `DocsStatus` (REQ-WEB-URL-BOUND-PORT: a served URL uses the daemon's actually bound docs port, never a default), so B could register the reference but failed `DOCS_PORT_DISCOVERY_FAILED` before replying with a URL. S5 gives role B separate canonical broker and seed-control sockets, starts the real `seedmap::serve_seed_control` (waits for its ping), binds a broker-backed loopback docs listener on an ephemeral port, and requires `DocsStatus` to report that bound port; role A and every helper/byte-equality/authorization/completion expectation are unchanged (A forwards B's returned URL; `wan.rs:1365-1385` uses broker IPC only). Tag `[int->REQ-WEB-URL-BOUND-PORT]` at the listener + discovery precondition.
- **Proof it is rig-only (todlando, unchanged S4 product code, kitsubito, 10:16Z):** bare B-shaped fixture native exit 101 with the golden's exact `WEB_SERVE_FOR … DOCS_PORT_DISCOVERY_FAILED: Connection refused (os error 111)`; same fixture + canonical seed control + broker-backed docs listener native exit 0, `Registered` at the actual bound port 33319. 24 receipt hashes verified: `.spt/preserved/304-web-helper-rca/linux/`. No product change anywhere in S5.
- **Caveat stated, not hidden:** the seven `twohost_web` cells are role-gated; unopted-in Windows execution exercises only their early-return paths. The S5 golden's twohost-a/b jobs own the real cross-host proof. Single-host suites (spt-daemon crate, phase A/B) were not re-run on S5: the only changed blob is a twohost-only test file, so the S3 receipts (Windows 1296/1296, Linux 1256/1256) carry for the daemon crate; the golden re-executes every leg.
- **Rerun protocol for the S5 golden (doyle under the operator's delegation, board 5678415472; deployah NC6GZTVT):** one same-sha rerun per classified signature after doyle records the failure on #304 — #308 `:568` registry lost-update, #309 `:782` ER-briefing liveness, and the Windows `live_adapt_translation_swap_e2e … leaves_live_endpoint_untouched` ONLINE-precondition cell (#309's second signature, instrumented in run 34946493637). The traceability and Linux-test rig reds are repaired (kitsubito checker 0.4.1; kitsubito 268.9 GB free, hfenduleam ~158 GB). Any other red ⇒ RCA-first, doyle decides rerun vs fix.

## S4 golden 34946493637 — CLOSED RED on record (2026-09-15 08:21–09:48Z; deployah run pin comment 5677066108)
- Jobs: changes ✓ · n1-gate Win ✓ · n1-gate Linux ✓ · notify ✓ · **traceability ✗ (rig)** · **test Linux ✗ (resource)** · **test Windows ✗ (one cell)** · **twohost-a/b ✗ (one paired cell)**. Zero reruns submitted; originals retained.
- traceability (job 104307030366): checker cache miss — golden.yml `WANT=0.4.1` (commit 71caedd4, in this candidate) vs kitsubito 0.2.0 → token-less clone → exit 128 before any check. **Repaired**: box at 0.4.1 (tag commit d9af11d2 asserted, 0.2.0 kept), runner-workspace probe predicate HIT + `check --json` 918/918. Board 5677419018 / 5677482212.
- test Linux (job 104307076832): every stage green (A 3417/1 skipped, B 224, doctests, clippy, e2e-notify 1, e2e-installer 2), then FLOOR_DOCS/FLOOR_END red at 29.3 GB — the job's own 81 GB pre-cleanup footprint; needs ≥130 GB free at start. **Repaired**: finished-lane targets reclaimed (todlando S3 89 GB, hertz gate-r3 73 GB) → kitsubito 268.9 GB free. Board 5677482212.
- test Windows (job 104307076933): A 3463/3463; B 238/239 — `spt::live_adapt_translation_swap_e2e adapter_apply_for_foreign_adapter_leaves_live_endpoint_untouched` :1037 PRECONDITION online; broker trace = **#309's mechanism** (LIVENESS_RECONCILE_OFFLINE before row_inserted 4332 ms), new signature, now instrumented. Ruled (doyle under the operator's delegation, board 5678415472): #309's second signature; joins the one-same-sha-rerun list. Note `golden-34946493637/windows-test-red-rca.md`. Board 5677935370.
- twohost-a/b (jobs 104325921368 / 104325921347): the web HELPER leg — B `WEB_SERVE_FOR … DOCS_PORT_DISCOVERY_FAILED: Connection refused (os error 111)`; RIG-ONLY: role B of `twohost_web.rs` never starts the seed control plane (DocsStatus lives on it, `seedmap.rs:182`) nor a docs listener, which the candidate's REQ-WEB-URL-BOUND-PORT contract now requires; the brain's canonical seed dial is the product design. Fix = S5 (hertz, test-only). Note `golden-34946493637/twohost-red-rca.md`. Board 5678231496.
- **Operator ruling (Reavo in-session ~10:10Z): PROCEED TO S5; doyle drives to publish on own judgment.** Board 5678415472.

## Known holds / deferred (stated, not hidden)
- **Windows consumer B on 7890ead3 ran TWICE in full: attempt1 (local env) 236/3, attempt2 = arm 6 (golden env) 237/2 — 5 distinct red cells, none red twice, all on record** (DISPOSITION.md). deployah's condition: later greens never erase them. Classified: **#308** registry lost-update (product, not introduced by fix-2, 1/10 serialized cohort); **#309** engine-room briefing liveness race (product, not introduced by fix-2; RCA sha 3fc7ea65…); g1/g7 red at the local 2 s default only, green under golden's 30 s at full load, causality inconclusive; c1 give-up-spool = TEST DEFECT (fixed-sleep drive; hertz RCA), test-only repin candidate rider. Milestone home for #308/#309 and ship/hold: RULED 2026-09-15 (A + A', section below) — ship on record, #308/#309 named as backlog fast-follows.
- **HISTORY — superseded 2026-09-15: this rider became S3 `6c89e8f7`, committed, gated, suite-green on both OSes (see "A' successor S3").** Original entry: Rider A' candidate (hertz, TEST-ONLY, then uncommitted/unbuilt, awaiting operator inclusion + doyle GO): `.worktrees/hertz-304-phase-b` branch `test/c1-generation-barrier-7890ead3`, exactly two files (`inject_control_wedge.rs`, `xlate_choreo_fixture.rs`): per-generation native birth identity, wait initial+two respawns provably gone before the next event, reuses the bounded `Brain::inject_endpoint` typed reply, asserts three inits + fault stamp + true exhausted-budget false; rustfmt stdin parse 0, traceable-reqs 918/0. Receipt `window7-2PEMLAIQ/attempt2-QWHXWYUH/deferred-deliverables.json`.
- #308 fix draft (todlando, PREP-ONLY, uncommitted, unbuilt): `.worktrees/308-registry-process-lock` branch `fix/308-registry-process-lock`, 13 files +548/−199; #308 comment 5667201851.
- Next-leg consumer drivers with knob VALUES recorded (hertz, smoke-only, not run): Windows `consumer-windows-7890ead3/run-attempt3.ps1` sha 1a400676a70fbc8e006a242b9e5ded52635510b1d6afbfa626a026ec04e0ba96 (PhaseBOnly retained); Linux `consumer-linux-7890ead3/golden-env-values/run-linux-7890ead3.py` sha 1f5181a8e284354b0cb11f9f01353dda06bfc18fb06f0e67abe582eaea5a1468 (launcher a6309496 unchanged; local copy = kitsubito).
- Consumer-rig env drift: legs mirrored golden's HEAVY expression but not its two deadline knobs. Corrected drivers (hertz): Windows `consumer-windows-7890ead3/run-attempt2.ps1` sha256 3dfed3e608f265636a61a6856ca26c1762bac565bda9c4ef5398a17b9b94a15a (RUN as arm 6); Linux `consumer-linux-7890ead3/golden-env/run-linux-7890ead3.py` sha256 5484959da963fb01244921edd3f0ddaf0c4c389f6270d3c981fa28d815f7b715 (child-env smoke only, NOT run — Linux was green at the stricter local defaults; historical full49-warm evidence unchanged).
- #300 int stage unactivated; two-node field leg POST-PUBLISH (operator-ruled).
- #302 remedy not built (design only); #49/#267 observation not run — all relocated to #307 fast-follow.
- IR-127–129 (hertz instrument hazards) registered; IR follow-ups from #299 (457 ms pre-subnet block; 30 s dial vs ceiling) in the #299 closing comment.
