# Windows reds: failure seams and falsifiable predictions

Candidate **b848244577d398600b59c7829fef9edbdb6315fa**. Source analysis only; no Windows runs/builds/indexing. Filed without reading scrubbed-rerun outcomes. Doyle has declared Windows attempt 1 **VOID** for inherited environment. This is a third classification—**rig/environment**, not automatically load or candidate.

References: `T` = candidate `crates/spt/tests/`; `B` = `crates/spt-daemon/src/broker.rs`; `C` = `crates/spt/src/cli.rs`. `A`/`W` = `consumer-windows/attempt1-VOID-phase-{a,b}.log` alongside this page. Source paths are within `.worktrees/asm-304-v3/`.

## Four cells

**Attach wedge — environment-class, demonstrated.** `W:22,103–104`: victim/fresh endpoint start, online state, rc heartbeat rendering and victim reconciliation all succeeded; only stop failed, explicitly `DAEMON_STOP_REFUSED` because `OWL_SESSION_ID` was set. `T/attach_wedge_e2e.rs:112–151,229–263,294–321` exercises detached broker, PTY death, abruptly killed output-reading rc, subsequent attach, reconciliation and bounded stop. It never writes rc stdin. The new pump runs, but its InputPaths worker is lazy; no intended USER_INPUT report activates it. `C:8140–8148` refuses before stop-inhibit/teardown; `--force` cannot override identity. **Exact precedent:** IR-22 (`docs/INFRA-REGISTER.md:1499–1514`) records this same cell and successive inherited-marker refusals; hazard 7.11 documents the already-bounded loopback path. **Prediction [INFERENCE]:** clean runner identity removes this refusal; quiet alone does not. A clean rerun failing an earlier online/render/reconcile assertion is a different seam, not recurrence of this observed failure.

**Daemon-stop convoy — environment-class, demonstrated.** `A:74–75`, `T/daemon_stop_convoy_e2e.rs:79–99,146–156`: eight `api capability` children race with stop, which fails the same identity guard. The run never reaches post-stop autostart suppression or exactly-one restart assertions. `api capability` is not `api state` USER_INPUT; no rc/input-path transaction is intended. **History:** IR-96 is a confounded diagnostic-tree-versus-candidate/load differential, explicitly cause-unclassified; IR-97 records unequal leaked-child populations, not measured load. Neither explains away this explicit refusal. **Prediction [INFERENCE]:** scrub removes the observed early failure; only then can a down-state/autostart-count failure test the convoy mechanism.

**Windows WMI escape — environment-class prediction, not proven IPC failure.** `W:724–727` reports WMI rung, lethal control, daemon survival and authenticated cleanup all successful; only `reachable=false`. `T/job_escape_e2e.rs:502–519,608` defines reachability as successful `daemon stop`, discarding stderr. A policy refusal therefore masquerades as IPC loss. Whole cell 6.288s cannot have exhausted its 20s stop wait; neither 40s readiness nor 25s cleanup was exhausted. Real path: Windows job → WMI/env wrapper → broker/brain → job termination → stop; no rc or input injection. Hazard 7.10 covers job-neutral launch and WMI environment forwarding; shared-load/leak history does not establish this failure's cause. **Prediction [INFERENCE]:** inherited identity explains the false oracle and a clean run passes. A repeated failure needs actual stop status/error distinguished from launch/survival. Linux excludes this `cfg(windows)` module (`T:39–47`); it did **not** pass this cell.

**Briefing presentation — eligibility seam, unclassified.** `W:488,495–497`: arm 5's replacement row remains pending, untaken; initial native delivery and intentional miss already passed. `T/er_briefing_presented_e2e.rs:631–679,782` allows 45s for new-session delivery. The actual product branch is the **10s eligibility expiry** (`B:2226–2282`), before `drain_spool_native`: online/ready/liveness, no relay, controllable must coincide. Successful earlier delivery traverses translation and changed InputRecord/deliverybytes; the failed offer does not. Mock heartbeat modes issue neither USER_INPUT nor an idle edge. IR-76/77 and the flake ledger document shared-load/readiness uncertainty, but no exact arm-5 load recurrence was found. **Prediction [INFERENCE]:** scrubbed quiet rerun obtains a different delivered native row, pending zero, without new-generation eligibility expiry. Repetition falsifies clearance and strengthens the eligibility/platform seam; a pass alone proves neither load causation nor absence of a load-sensitive candidate regression.

## Batch boundaries and Linux evidence

`rc.rs:3086,3170–3171,3237,3422–3449`: pump adds audience/reply-channel setup and polling; worker starts only on InputPaths. `api/{mod.rs:778–786,nowsignal.rs:1106–1108}` gates receipt IPC behind USER_INPUT and quoted paths. Physical writer bookkeeping is shared infrastructure, not automatically the failed branch. `PRESENCE_PROBE_CEILING` (`C:7002–7033`) governs UNLISTED probes, not these named-target verbs. Controller-close diagnostic emission is trace-gated; brain promotion-trial logging is not cold-start execution. Xtаsk's release-seed scrub affects git children, not these runtime calls.

Linux attempt 2 logs show convoy **1.073s** in A, attach **15.565s** and briefing **55.963s** in B; no WMI execution. Retained **“valid modulo identity-env capture gap”**: its restricted `environment.json` cannot establish inherited-marker absence. Authorized attempt 3 now supplies full environment **key names only**, purges every inherited OWL_/SPT_ name and permits only the leg's ephemeral-port setting. None of these Windows void-attempt observations is candidate acceptance evidence.
