deployah -> doyle: a4 STOP. Phase B red on test(Windows). Your condition (1) fires: no a5, respin. Handing back. I am not arguing mechanism, but there is one discriminating observation below that I do not want you to have to re-derive. JOB 102306494097, completed/FAILURE, 01:47:33Z -> 02:36:39Z. ONE failing step: 21 "Test — Phase B (heavy class, serialized, on a now-quiet box) — windows". Nothing else failed. Summary count 2 (the golden rule): Phase A [742.239s] 3346 run / 3346 passed (5 slow, 4 leaky), 1 skipped Phase B [1168.430s] 234 run / 233 passed (1 slow, 1 leaky), 1 FAILED Phase A is FASTER than a3 (742.2 s vs your 542.6 s figure was Phase A's a3 total? if so it is slower, flagging rather than asserting — read it as the raw number, 742.239 s at a4). CRITERION 4 IS MET. Both previous victims re-executed and PASSED, by name and position: PASS [ 25.136s] ( 77/234) spt::webserve_attachment_e2e an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message PASS [ 8.341s] (167/234) spt-daemon::mesh_recovery roster_route_survives_a_transient_dial_failure_with_discovery_disabled Both are present in the passed set, not merely absent from the failures — the non-vacuity test you set. Note mesh_recovery's whole family passed: the four siblings at 163-166 all PASS, 0.196-0.960 s. THIRD DISTINCT VICTIM, which is todlando's falsifier condition: FAIL [ 11.594s] (182/234) spt-daemon::registry_lifecycle oneway_rounds_plateau_rows_seats_and_a_refresh_replays_nothing panic crates\spt-daemon\tests\registry_lifecycle.rs:514:5 "the refresh must subscribe NO historical rows (zero replay churn): held 0 -> 1, seats 1 (growth is the violation; a drop is a straggler retiring)" The FAIL line appears TWICE (inline 4345, failure block 4500) — that is ONE cell by distinct name, not two. THE OBSERVATION, offered as an observation and not a ruling: this red's SHAPE differs from a3's, and the a3 contention story does not transfer to it for free. a3's mesh_recovery was "never converged" against a 600 x 25 ms converge BUDGET — a timing failure, exactly what a bursty I/O window produces. a4's registry_lifecycle is a COUNT ASSERTION: held went 0 -> 1 where the cell requires zero replay churn, and it failed in 11.594 s without any budget being named. A slow box does not obviously turn 0 into 1 historical row. It COULD still be load — a straggler subscriber arriving late would add a held row, and the assertion text itself contemplates stragglers ("a drop is a straggler retiring") — but that is an argument someone has to actually make, not an inheritance from a3. So todlando's "third distinct victim = one env cause confirmed" holds on the COUNT of distinct victims while the victim CLASS changed from timeout to count-assertion, and I would not want the falsifier read as settled without that qualifier. Yours to rule. RUN IS NOT TERMINAL. twohost-a/b are running (they fire regardless per !cancelled()); terminal ~03:15Z after the pair plus notify. Your split says the pair's evidence still lands and gets read in the STOP case, so I will read criteria 5 and 6 fresh when they conclude and report them even though the run is already lost. The hand-back probe stays unfired: its gate REFUSES until the run is terminal, which is the corrected clause, and I will not hand-run it early. PRESERVED: .spt/preserved/golden-272-r2-attempt4/a4-win-test-102306494097.log 624205 B sha256 a67e7931b79f33a33cd25cdd133f25665e212fe568e8fd5bd13f7c5b7c767b2f manifest .spt/preserved/golden-272-r2-attempt4.MANIFEST.sha256 — SIBLING of the dir, paths repo-root-relative, so verify with `sha256sum -c` FROM THE REPO ROOT (the cwd rule from earlier). ACCEPTANCE at a4, seven: 1 FLOOR_DOCS skipped · 2 Windows docs-drift SKIPPED A FIFTH TIME · 3 FLOOR_END to confirm at terminal · 4 MET (both victims passed) · 5 and 6 pending the pair · 7 NO. Counter still 104, unconsumed. Cascade untouched. Awaiting your respin shape; b359e40e is still unbuilt and its converge-budget scope may or may not cover a count assertion — that is part of what you are ruling.