diff --git a/docs/INFRA-REGISTER.md b/docs/INFRA-REGISTER.md index 6285a0d2..fa9baf44 100644 --- a/docs/INFRA-REGISTER.md +++ b/docs/INFRA-REGISTER.md @@ -8,7 +8,61 @@ this file only by being built (link the lane) or being retired with a stated rea Entry format: status · origin · what/why · trigger condition (what makes it ripe) · size guess. -Last sweep: 2026-09-06, v0.67.1 RELEASE CLOSE + WEBSERVE (#272) INTAKE (one delta pass; the 08-30 +Last sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`. +All **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit +population checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry +trigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`. +UNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt. + +- **Release facts, not a blanket green:** v0.69.0 at `16df0e41`, counter **105**, Latest, + 11 assets; #294 and all eight members DONE. Explicit operator SHIP overrode the known + sync-cell red at candidate `a9e786b2`; the release neither classifies nor closes that defect. + Source closeout: releases#294 comment **5628538587**. The scoped four-package `--lib` battery + passed **121/121**; push CI **34550282074** passed **3167 Windows units**, then failed the + END disk floor (**15,360,114,688 < 34,359,738,368 bytes**). Release build **34550300527** + succeeded. Earlier PR unit-red logs remain unavailable/cause-unclassified. These are separate + verdict objects; no pass substitutes for a red, missing specimen, or unexecuted acceptance. +- **Close already-built work, retain residuals:** IR-1/4 stale unlanded headers reconciled to + their landed rider and recorded golden exercise. IR-66 CLOSED using its existing two-platform + gates and WEBSERVE satisfaction ruling. IR-73 CLOSED: eight post-checkout sites plus both + docs-floor rereads are present; IR-86 retains sizing/dependency debt. Other established + BUILT/RETIRED decisions stand. IR-18's deferred consolidation and IR-53/62's narrower + touch-triggered siblings remain carried; closing their built halves does not erase those. +- **Do not redispatch existing implementations:** IR-26 build-side identity is committed, + but claim-time observation and old-reader issues remain; IR-29's first fix landed, later + rung faces remain; IR-33's 16 MiB CLI stack exists, acceptance/margin reconciliation remains. + IR-57 `pick-audit`, IR-59 `disk-floor`, and IR-46 workflow floor tokens exist; residual adoption + and receipt reconciliation are the work. IR-69's original product lane landed; #243 residuals + remain. IR-83's universal LAN-only prescription is superseded by IR-89's layer-specific box + proof. IR-89's next-golden trigger has fired; exact step acceptance still needs reconciliation, + not a second guard implementation or renewed operator permission. +- **IR-92 stays OPEN:** core#215 shipped the documentation/register rider, NOT the product + remedy; core#217 is the separate brainread audit. `try_spt_hosted_inject` still lacks the + MSG_IN publisher. Deployah corrected comment **5628532753** in place and confirmed readback. + Inject coverage, relay publication ordering and per-msg-id exact-once are distinct obligations. +- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package + takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing + quiet-window contract, independent rendezvous clocks, and mandatory between-run identity + census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains + a separate operator capacity decision. No new loaded comparison before these prerequisites. + Hertz's lifecycle package retains IR-7/17/20/22/25/34/35/55/63/79/80; guard adoption must + distinguish unwinding from hard process death. IR-74/75 ride the next Linux box audit. + IR-85/95/96 are scoped diagnostic continuation, NOT budget widening or a load/disk diagnosis. + Todlando owns product-side IR-81/82/92 composition; #285's completion did not build IR-82's + predecessor record. Both builders are offline: existing briefs are delivered, unacknowledged, + and **not executing**. No board mutation or new run authorization is implied. +- **Small seam riders remain explicit:** next tooling intake weighs IR-5/6/10/11/32/37/47/58/94 + (IR-37 upstream release is not downstream adoption: golden still requests 0.2.0). + IR-93 remains a separate symbol-packaging decision before a release-workflow rider, not a + property proven by a successful release build. All other open entries retain their recorded + trigger, residual, and owner where named; the complete audit records each, not a sampled set. +- **Cleanup is mitigation, not closure:** 38 clean merged worktrees and classified obsolete + artifacts removed; dirty/unmerged/retained evidence preserved. Net free-space change + **4,532,350,976 bytes**, ending **83,382,472,704 bytes** (concurrent-activity caveat). + `.spt/cleanup-20260911.json` is the receipt. Root-target and CI-debug reclaims are separate + earlier measurements, not additions to that net. IR-14/26/27/49 remain structurally OPEN. + +Prior sweep: 2026-09-06, v0.67.1 RELEASE CLOSE + WEBSERVE (#272) INTAKE (one delta pass; the 08-30 full pass stands) — shipped counter 103, tag == main == tested `04e32c8c`, golden 34017906638 att4 9/9 on a QUIET box after three reds (:473 attach_link structural test defect; wtlock :147 under builder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is @@ -178,7 +232,8 @@ written into the brief rather than left to judgement). ## OPEN ### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe) -- **Status:** open, LANE EXISTS UNLANDED — see [[CI-RIDER LANE STATE]] at the foot of this file; +- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise + recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03 (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT @@ -245,8 +300,9 @@ written into the brief rather than left to judgement). - **Size:** medium (churn harness + counter plumbing + flake-safe assertion). ### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane) -- **Status:** open, LANE EXISTS UNLANDED — see [[CI-RIDER LANE STATE]] at the foot of this file; - candidate commits `1275e47` + `49d4805` + `8ed006b`, mapping NOT yet confirmed by its builder · +- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the + [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the + 2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. · **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders) - **What/why, three parts that land together:** 1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev @@ -282,8 +338,8 @@ written into the brief rather than left to judgement). - **Size:** small. - **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03 - dispatch brief as a **conditional** rider; hertz reports whether the condition fired. **Not yet - known to be building** — an unreported condition leaves this entry open, not landed. + dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set + audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use. ### IR-6 — Membership logging on subnet gates - **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register) @@ -294,8 +350,8 @@ written into the brief rather than left to judgement). - **Size:** small. - **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03 - dispatch brief as a **conditional** rider; hertz reports whether the condition fired. **Not yet - known to be building** — an unreported condition leaves this entry open, not landed. + dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set + audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains. ### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink) - **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue) @@ -460,6 +516,18 @@ written into the brief rather than left to judgement). - **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit + reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify before delete, outbound links first). +- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered + worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes, + untracked files, ignored files, target trees, or inbound links from the project-wide reparse + census. Branches and commits were retained; seven stale worktree registrations were repaired + with Git before ordinary, non-forced removal. This count is removals, NOT a census of all + remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed. + The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and + its separately classified target, an old release download, and generated scratch artifacts: + net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes + (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file + lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance, + not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion. - ⚠ **The header of this entry previously read "14 untracked orphan dirs vs 25 git-tracked". Both numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated and carries its command. @@ -1524,8 +1592,10 @@ The distinction that matters is location vs. build: rule (gate with nextest); medium to harden the three marginal tests. ### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard -- **Status:** open, LANE BUILT BUT UNCOMMITTED (see the warning below — this is not a figure of - speech) · **Origin:** hertz 2026-08-03/04, found by its own test rather than by reading, and +- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the + original build-side lane is COMMITTED (see its later reconciliation below), not still + uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:** + hertz 2026-08-03/04, found by its own test rather than by reading, and reported unfiled for composition. Composition ruling is doyle's, 2026-08-04. - **What/why:** a POOL-OWNER claim named a holder pid; lane liveness was read from whether that pid was alive. hertz MEASURED the failure on this box: **3 of 3 claims had dead holders while one of @@ -1744,10 +1814,10 @@ The distinction that matters is location vs. build: `gh release edit`, never retag. PR #176 passed `traceable-reqs check`. ### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed -- **Status:** open, FIX AUTHORED-AND-COMPILED unlanded — hertz `test/twohost-serve-window` - @`17bbbd8` off `11169c1` (+33/-18 twohost.rs, relocation proven byte-identical by - comment-stripped set-diff, cargo check + clippy -D warnings green; proving two-host run still - owed and rides the same window as #145's closed-subnet knock row) · **Origin:** golden +- **Status:** OPEN for later serve-window/rung residuals; the original + `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30. + Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin + measurement claimed. · **Origin:** golden 30873007187 attempt 1 red, doyle timeline triage + hertz source diagnosis 2026-08-04. - **SECOND FACE, measured 2026-08-24 (WAX-SEAL #21 W3 gate climb @ 035c3fe6, doyle):** the class recurs on a NEW rung, and this face is UNWINNABLE rather than racy. The W3 seal rung S1 mints @@ -2094,7 +2164,12 @@ The distinction that matters is location vs. build: - **Size:** small (one refusal + a length-plausibility floor in gen). ### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded) -- **Status:** open · **Origin:** todlando U1 (#144) 2026-08-04, delta-tested mid-lane. +- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs + the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument + ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin. + Do not redispatch an already-present sized-stack implementation. No fresh debug-run + acceptance is claimed by this source read (2026-09-11). · **Origin:** todlando U1 (#144) + 2026-08-04, delta-tested mid-lane. - **What/why:** eight extra hidden bool args across the five knock seats grew the derive-built Command tree past what the debug binary's main thread stack can construct: EVERY invocation (`spt --version` included) died with `thread 'main' has overflowed its stack`, exit @@ -2502,8 +2577,10 @@ The distinction that matters is location vs. build: sentence that the gate's claim "will be REFUSED" — a false warning to a gater mid-run. The refusal sentence sat directly under the "Claim a pool at lane start" instruction, inviting the build-time semantics to be read onto the claim verb. -- **Corrective landed:** one AGENTS.md sentence — the claim WRITES a record and never refuses; - predict refusals from builds, never from `pool-claim`. +- **Corrective landed:** the claim WRITES a record without adjudicating the incumbent lane; + predict **lane-identity** refusals from builds, never from `pool-claim`. The broader original + "never refuses" wording is superseded by IR-56's **addressing** guard (wrong-tree claims need + explicit `--foreign-pool`); that guard does not add incumbent-lane adjudication. ### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline - **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum · @@ -3208,6 +3285,20 @@ The distinction that matters is location vs. build: - **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle 2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured by todlando the same hour. +- **v0.69.0 release close, 2026-09-11 (deployah, source record releases#294 comment + 5628538587):** the first broad version/manifest battery failed to LINK (`LNK1180`, + `LNK1108`, cargo exit 101), with **15,777,792 bytes free** measured at recovery. It produced + no test verdict. The run selected the workspace's test binaries on the Cargo side even + though the nextest filter did not need the e2e population; the replacement selected `--lib` + for `spt-daemon`, `spt-runtime`, `spt`, and `xtask`, and passed **121/121** in 8.445 s. + Root-target reclamation restored **66,926,968,832 bytes free**; the subsequent CI Windows + unit step passed **3167 tests**, then its END floor refused at **15,360,114,688 bytes** + against **34,359,738,368**. That is an observed resource-red AFTER passing tests, not an + explanation of the earlier PR unit-step red whose log was unavailable. A second, classified + CI `target/debug` reap, with runner intake stopped by the operator, increased free bytes + **14,892,281,856 -> 78,994,501,632**. Runner service restored afterward. Publication used a + preserved signer, not a Cargo rebuild into the cleared pool. These are two measured recoveries, + not a durable capacity fix; IR-46/59/86 remain the next gate-driver capacity rider. - **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):** both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE — @@ -3328,6 +3419,15 @@ The distinction that matters is location vs. build: - **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22 during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a possible harness misreport and then RETRACTED that reading himself on a minimal probe. +- **v0.69.0 recurrence, 2026-09-11 (deployah, own withdrawal):** `NEXTEST_EXIT=0` and the task + completion's exit 0 both described the wrapper/truncation path, not Cargo's **101**. + `PIPESTATUS` was read outside the executing subshell, so the named verdict measured `tail`. + Both green-looking receipts were withdrawn; the raw failed-link output was retained. + **An exit FILE alone is insufficient if its writer captures the wrong process.** Capture + immediately inside the shell executing the producer, before any other command replaces the + status, write that value to the leg's file, and propagate it when wrapper status is reported. + The replacement battery's own file read 0, with 121 tests actually run. Keep this entry OPEN: + corrected execution of one driver does not make the faulty wrapper shape unreachable. - **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two @@ -3526,7 +3626,10 @@ entry, not a closed question. ### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672) -- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22 +- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already + ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the + recorded gates below, not v0.69.0's unrelated green receipts. Hertz rider PR #161, landed ff at + `d04b922d` (2026-08-27, IO-PARSER #22 intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the @@ -3606,10 +3709,11 @@ entry, not a closed question. ### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth -- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on - `feat/emit-single-write`, owned by **todlando**, awaiting golden-batch assembly; board request - releases#241 carries the product remedy and full lane evidence in comment 5461613480. This entry - is the exposure map and census discipline, not the implementation. · **Origin:** CONDUIT #236 r3 +- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original + product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not + still parked awaiting assembly. Releases#241 retains its original lane evidence in comment + 5461613480. This entry is the exposure map and census discipline; residual conversion, + generator repair and a SHA-pinned zero recensus remain owed. · **Origin:** CONDUIT #236 r3 golden attempt 2, 2026-08-29: `endpoint_autostart_e2e` missed its contiguous `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay @@ -3782,13 +3886,14 @@ entry, not a closed question. ### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step -- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag - 2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this - REQ-CI-FREE-SPACE-PREFLIGHT trap on `golden.yml`'s n1-gate (floor read BEFORE checkout, so the - checkout's own cost lands after the assertion); `golden.yml` is fully reshaped (`ac7d2609`, - both jobs, checkout-protective reaps verified to stay pre-checkout) — but `ci.yml` (5 tagged - sites) and `release.yml` (3 tagged sites) keep the literal-first shape, deliberately NOT - widened off the back of a golden.yml-scoped ruling. +- **Status:** CLOSED / BUILT — source reconciliation 2026-09-11 at `e5a2fed9`: all five + `ci.yml` sites and all three `release.yml` sites now read after checkout, with IR-73 comments; + `golden.yml` has both docs-floor rereads. IR-86 records the docs reread's live catch. + The original two halves below are implemented; capacity sizing and docs dependency coupling + remain OPEN under IR-86, not a reason to redispatch these eight reorders. + Filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag 2026-08-29). + · **Origin:** #242's two lost golden attempts exposed the pre-checkout read; the original + golden-only correction deliberately left the eight other sites for the now-built rider. - **What/why:** review each of the 8 sites' comments for checkout-protective purpose (the `ac7d2609` method), then reorder the read after checkout or RECORD why not, per site. The "other jobs keep the literal-first shape" clause is the trap's carrier: every un-reviewed site @@ -4019,9 +4124,11 @@ entry, not a closed question. ### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet -- **Status:** OPEN, filed by hertz 2026-09-07 07:40Z on doyle's ruling (07:38Z) that this is its - OWN entry and **not** a third face of [[IR-79]] — IR-79 is rig teardown, this is a candidate - defect in the PRODUCT path, so its owner may be todlando rather than the rig lane. · +- **Status:** OPEN for the residual population, not an undiagnosed five-name product claim. + Later amendments identify the brainproc shell-wrapper fixture mechanism and distinguish + production's direct spawn; they do not classify all 12 union members. Historical opening + hypotheses below are not current causal conclusions. Filed by hertz 2026-09-07 07:40Z on + doyle's ruling that this retains its own identity, separate from IR-79. **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak roster was read out of the baseline golden log for an unrelated reason. - **⚠ WHAT THIS ENTRY IS, STATED FIRST SO IT IS NOT OVERREAD: a CLUSTER OF NAMES.** Five cells @@ -4536,7 +4643,11 @@ the wrapper's harness children orphaned + running") — so IR-80 ships callers, boxes and have re-measured none of it; this entry is the register form of his finding plus the structural reading it supports. Board face: **F18**. Register slot: IR-83 (79/80/81/82 are the same thin PR). -- **THE FINDING, in one line:** two-host rigs must address peers by **LAN**, never the tailnet. +- **2026-09-11 ruling:** the original universal "LAN, never tailnet" prescription below is + SUPERSEDED by IR-89's measured tailnet ACL + Windows Firewall remediation and successful + tailnet probes. Admit the actual transport at each layer and retain an independent reverse + direction witness. The operator-blocked box remedy is spent; durable witness enforcement + and its acceptance record remain separate, OPEN work. No new box changes authorized here. - **HALF ONE — the tailnet ACL is per-node and ONE-WAY.** `hfenduleam` admits 9 sources and `kitsubito` is **not** among them; `kitsubito` admits `hfenduleam`. So a rig cell needing INBOUND @@ -4995,8 +5106,10 @@ the wrapper's harness children orphaned + running") — so IR-80 ships callers, ### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A - **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211 - (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED - until the next golden run, because thin CI compiles the cells and skips them. Filed by doyle 2026-09-08 + (`9b96d7e7` + this amendment), **LANDED, exact golden-step acceptance unreconciled**. + Subsequent goldens have run: "until the next golden" is no longer a future trigger. + This sweep does not infer probe execution from a run's existence or overall conclusion; + retain the step-specific exercised/skipped/failed evidence before closing. Filed by doyle 2026-09-08 at the #272 golden r2 terminal triage; the operator-blocked flag is retired here, because the operator acted. The operator applied BOTH layers that evening — the Windows inbound rule (~23:41Z) and the @@ -5004,11 +5117,10 @@ the wrapper's harness children orphaned + running") — so IR-80 ships callers, **3/3 over Tailscale on 7483 AND 3/3 on 7489 at 23:57:50Z** from `100.98.197.12`, with a post-terminal probe 3/3 on both ports at attempt 4. v0.68.0 then shipped at `a2f335f8` with both two-host legs GREEN on golden r4, so the box half is closed by measurement and not by - assertion. **STILL OPEN, and it is the durable half:** the WORKFLOW guard (hertz) — the - pre-ceremony B→A UDP probe at `d882297f` that reds `INBOUND_BLOCKED` in 10 s with its own - name instead of burning 900 s blaming pairing, plus retiring the dead `_work\spt-core` - rules note in the runner runbook. Until that lands, the next box (or the next ACL edit) - re-opens the 900 s face with nothing to name it. · **Origin:** run 34262154550 @ `25e60015`, twohost-a 102229928746 + assertion. **Durable half BUILT, acceptance reconciliation OPEN:** the pre-ceremony B→A + probe and its corrections are documented below. Do not redispatch a workflow guard that + already landed, or reopen the spent operator permission. The next box/ACL reset remains a + recheck trigger. · **Origin:** run 34262154550 @ `25e60015`, twohost-a 102229928746 (`two_host_web_helper_role_a`, :968, 900.40 s) and twohost-b 102229928689 (`two_host_web_role_b`, :559, 910.20 s): B logged 75 × "A not ready … broker QUIC op exceeded the 10s bound (peer unresponsive)" from 20:49:49Z to 21:04:37Z and was never ADMITTED. Ladder @@ -5297,6 +5409,13 @@ the wrapper's harness children orphaned + running") — so IR-80 ships callers, `spt-daemon` (todlando), test-side legs (hertz). · **Origin:** a 22:35Z empty `` turn trigger after the #292 daemon restart, chased for its body; the body was in a spill file, and the chase exposed that neither agent's io-events log held the messages that woke it. +- **Release reconciliation, 2026-09-11 (source read at `e5a2fed9`):** core PR **#215 is + DOCS-ONLY**. Its merge and v0.69.0 ship-fact record (comment 5628532753) discharge the + **register rider**, not this product remedy. Core #217 is the separate #293 brain-read + census, not an inject-edge fix. `try_spt_hosted_inject` still returns the result of + `brain.inject_endpoint` without publishing `MSG_IN`. **IR-92 stays OPEN.** Carry the + observation-only chokepoint remedy into the next product intake (todlando product ownership, + hertz test ownership); neither offline owner's execution is implied by that assignment. - **THE TWO PUBLISH SITES ORDER THEMSELVES OPPOSITELY — read at `de5a44bc`, 2026-09-10, from the bare-baseline red on `io_events_undriven_kinds_e2e` (golden 34467873057, Linux Phase A).** The count below is right and the ORDERING is what this entry was missing: