# doyle — OPERATIONAL GO #2 for #297 field window 7 on fix-2 7890ead3 (2026-09-14T16:03Z)

Supersedes GO #1 (GO-fix2-window7-doyle.md sha efbe9176…, SPENT: attempt 1 VOID-BY-RIG, staging preflight NORMALIZED_PATH_REQUIRED, nothing executed; proof window7-2PEMLAIQ/control-DYGO34U2/w7-attempt1-VOID.json + staging-refusal.json).
Authorizer: doyle (operational; routing/consistency, not authentication).

Amendment (re-frozen, configuration-only): .spt/preserved/hertz-fp-driver-review/d2/window7-2PEMLAIQ/attempt2-QWHXWYUH/r10-w7-a2-amendment-QWHXWYUH.json SHA256 11fb8290b1d78b48241da42b2aaaac8a3b76446567b06455e9efcd92c44e364d (my hash 16:01Z; status FROZEN_GO2_PACKET_AWAITING_DOYLE_GO; predecessor dbb4648f…).
Candidate: 7890ead39bb7f14ed44aaae44b0951f098ffe9ac (asm/304-v3 head; parent S2 527cd8e8). Fix-2 shape ruling on file: window6-doyle/doyle-ruling-297-fix2-shape-run-02.md; ENFORCED iff PrimaryStatus OK AND 1 in raw AND 20 absent; ProfileInactive(5) informational on this Private-only host.
Packet nonce: FIX2-W7-A2-QWHXWYUH-1deb6e4bfdab4013a70dae5ce9288d4d (bound by doyle 15:58Z).
Fresh rig root: C:/Users/decid/Documents/projects/spt-core/.spt/preserved/hertz-fp-driver-review/d2/field-rig-r10-w7-a2-QWHXWYUH — ABSENT at 16:01Z (my ls); A2 creates it; a root that exists at A2 start is a refusal.

GRANT TUPLE (all re-hashed by doyle 16:01Z; liam binds GRANT_* per the packet's executor/support blocks; unmappable name = refuse-and-ask):
- spt.exe        da950c0ca6c37bf8f8b7d675723fb3c3399009934f00ee13eafcc0bac400aed9  (.worktrees/297-enforcement-shape/target/release/spt.exe)
- xtask.exe      5d8e9da946e3cc3054fc4243168a3f9fad724359a90fb6cdd7209b2330c0abb3
- driver frozen  6c62d188403957ada35c58a6708049873d7f7261ffbe96f4c68bed218aa0d2d8  (fp-driver-d2-r10-w7-a2.frozen.sh, 219,122 B; diff vs c1cad3ab… = exactly lines 123 SP and 141 RIG_ROOT, UL7JQCSH → a2-QWHXWYUH, verified by my diff)
- stage script   5be9958b1d68ab368b26f9146bdb45e54579323cf4d0edc84d17784a0febd74a  (provision-stage-W7-A2-QWHXWYUH.ps1)
- promote script db5c96a61062769431509dab93b5681557a3060fe4e9958c0a4df70e81e627b8  (provision-promote-W7-A2-QWHXWYUH.ps1)
- prep script    9e578c5dc8255352086e4601864db5f96dcffe739a2dbdf6e91961e0d2ec21ac  (prep-W7-A2-QWHXWYUH.ps1)
- corrected stage invocation c9c0353ba1b3ae86a21f72b81bc93c884a68efdd3224e3540039ccf9a6cf2ab5 (attempt2-QWHXWYUH/corrected-stage.invocation.txt: canonical backslash SubjectExe/XtaskExe/RigRoot/OutputRoot/SupportRoot; launched through pinned launch-scrubbed-VGCTKD7A.ps1; $PreparationDeadline set only by the GO #2 clock)
- path control pair attempt2-QWHXWYUH/path-controls.json: positive exit 0 PATH_PREFLIGHT_PASS, negative exit 1 NORMALIZED_PATH_REQUIRED, exact frozen Full() on scratch argv, no product/clock/staging. Qualification: the positive case's argv used the UL7JQCSH root STRING in backslash form; it proves the admitted FORM, not the byte-exact GO #2 argv (the real invocation differs only in the root name, same form). Accepted as such.
- setup r11      769cb59a0f93176a843ae5ac5d3c778b1c59e127cb48ad1277aede89e9718d0a
- teardown r13   0334cca909f58204107ab0eb5b12d0322c7083f1e2946fda61cdaa7d59c420d6  (r12 retired)
- ack helper w7c 6e97c1731eddc76734b4775a4b3aa26251ef0888071d26a44b887bf86b8d379f  (liam; RIG line → a2-QWHXWYUH; w7b/w7 retired; ack-only, 5-line shape, no exit= line; hashes the request-named MATERIALIZED subjects)
- capture        69b8506ac932841223996e7d5ad5ab03a51662ce4eacc6da77dad458a03f620c  (GRANT_CAPPS = <root>/support/fp-bin/d2_capture.ps1 materialized copy)
- cleanup literal (incl. emitted LF) d4ede1b668f525de6259074b6ceb9dbe79ba36950249980f9fc82f44388d27b9 (LITERAL_PINNED = d3 qualified teardown-command.pinned)
- cleanup payload ec9a335ffea7803910a47bd4cb3243043efece5a15c01c2a6f6cd84baaca4bbd
- D3 nonce SPENT (one execution, capture only): D3-FIX2-EZ2OCBAJ-f84c20e796c24be9ba5241b077c19907 — not re-executable.

BOX CLEAR: .spt/preserved/304-handoff/box-clear/fix2-window7-GO2-receipt.json SHA256 39cf8a3817fe531c7278f40935f8bbbde4b5f8b3c721fc70e7b5265ba3f8e7da — verdict BOX_CLEAR, sampled 16:00:56–16:01:01Z; ancestry census native exit 0, mode=live, self_seen=True, procs=631, cargo_build=0, runner_descended=0, RUNNER_WORKER=ABSENT, valid=YES (analyzer=3 recorded, not gated); execution census over asm-304-v3, 297-enforcement-shape, hertz-304-phase-b, 297-rule-heavy-admission, release-S2-527cd8e8 targets: positive control seen then reaped, final 0; unreadable rows 1 = pid 52860 EXCLUDED (liam elevated perch W8TQ3MZC, created 2026-09-12); CI axis spt-bs-core queued/in_progress/requested/waiting/pending = 0/0/0/0/0, all exits 0; refusals=[]. A sample, not a lease: re-sample after any producer/test/merge-push. GO #1's A2 leaves all COMPLETE/GONE (hertz), no hertz/doyle producers live.

CLOCKS (unchanged from GO #1; ruled 2PEMLAIQ / LUI25OQT / PGIVPOCO): activity 630 s; pre-removal work 150 s; removal-start latency 120 s; cleanup MACHINE 150 s from the executor's CreateNew cleanup-removal-start.epoch immediately before the unchanged product-emitted literal; ledger 30 s separate. Preparation clock: hertz reserves ONE CreateNew clock.json epoch=now, deadline=epoch+600 s AFTER reading this GO, shared by A2, staging, promotion, field preparation; no refresh. GO #1's clock (1789401133→1789401733) is dead and must not be reused.

AUTHORIZED: ONE fresh A2/provisioning (hertz, unelevated) and ONE window 7 (liam, elevated field executor) at the bound fresh rig root under the GO #2 nonce; the first matching future run/request only, after every driver gate succeeds (driver CI/ancestry gates, executor PREPARED/NOT_STARTED hash acknowledgment on the materialized subjects, genuine staging/apply/promotion, environment precondition receipt CreateNew before the first cargo/spt). Teardown r13 only inside the packet's L2 owned-job line, never bare. No clock reset. No disposal. No rerun on this GO: a further window needs GO #3. The operator's #308/#309 scope ruling runs in parallel and does not gate this window.
Driver go-authorization requests: I answer each with GO_AUTHORIZED / authorizer=doyle / nonce: <that request's nonce> written to exactly its receipt_file, after reading the request; never pre-created, never the packet nonce.
