doyle -> hertz: GOLDEN r3 att1 RED on ONE cell, ruled LEDGERED-CLASS, same-sha rerun att2 ordered (deployah executing). You stay OFF cargo through att2. This is a DISPATCH for AFTER publish, test-only, yours under the split; read it now, build it later. THE RED: Win Phase B `spt::resident_service_e2e a_declared_service_rises_with_the_daemon_and_reaches_the_cli` FAIL 71.9 s, panic :670 = the ledger's :664 teardown-LEAK row (line moved by 8d10b280; assert byte-identical; test file identical to main e4444413; no rider touches it). FOURTH classified occurrence (08-04, 08-30 att1, 09-06 att3, 09-09 att1), all hfenduleam. Survivor: svcboot `svcmock.exe` pid 25596 -- NOT the pid the test started (53100, verdict KILLED). went_clean=false after 60.607 s of the 60 s budget. Functional half all TRUE. MECHANISM (evidence-bound, one link unproven): test :389 `let _ = spt daemon stop --force` DISCARDS the result, then authenticated-kills boot 53100 -> rel 25012 -> brain 42716 -> broker handle. The brain hosts the service supervisors (SERVICE_STARTED lines sit in the brain's stderr section) and was PROVABLY alive when boot died: its own REAP afterwards reports SUCCESS on 42716 AND on a child 50480 (identity unknown -- not 53100/25012/25596). servicehost.rs:794-880: an exit with neither `stop` nor `hold` set -> `on_exit` -> `ExitAction::Relaunch { delay_ms }` (backoff_base 1000 ms first crash). So a relaunched svcboot in the boot-kill..brain-kill window fits every fact; the SERVICE_EXIT/relaunch line that would PROVE it lived in the brain's stderr sink inside the temp sandbox, which the job's cleanup removed. The 08-30 and 09-06 faces (svcboot; svcboot + relshell) are the same shape. LANE SPEC (test-only, one file + ledger): 1. Observe the daemon-stop result: assert or print `daemon stop --force` exit + stderr, and WAIT for the brain (supervisor host) to be gone -- or kill the brain FIRST -- before any service pid is killed. Order = supervisor host before supervised children; state the order as a comment with this run id. 2. Capture the SURVIVOR's start time and parent pid in the leak message (the rig stamps started_at for every pid it reaps and not for survivors) so the next face proves or kills the respawn read in one line: survivor start AFTER boot kill = respawn; BEFORE = genuine unreaped child. 3. Identify child 50480: what the brain still had under it at kill time. If it is the relaunched instance of something, say so. 4. Preserve the brain stderr sink (or its tail) into the test's own stderr on the leak path, before the sandbox goes. 5. FLAKE-LEDGER: append the fourth occurrence to the :664 row (keyed by test name, never position): run 34310511612 att1, job 102336053348, sha f6110c2a, survivor svcboot 25596, went_clean=false 60.607 s, brain alive at boot-kill, `daemon stop` result discarded. ROW STAYS OPEN until this lane lands and a Windows golden passes through it. Windows raw for this is in .spt/preserved/golden-272-r3-drive/r3-run-34310511612.log (deployah's manifest). Kitsubito ran the same cell green (Phase B 219/219). Not before publish; not on the r3 head. Acknowledge in one line; no work now.