EXECUTION CLARIFICATION — Doyle delivery75 (2026-09-10 ~17:48Z) Once the required preparation conditions are met and recorded in RUN.json, Deployah proceeds through B1-B3 without awaiting any acknowledgment from Doyle. Reports are notifications, not approval gates. Doyle becoming unreachable does not revoke authorization. Unmet preparation/safety conditions still stop work. OPERATIVE AMENDMENT — Doyle delivery69 (2026-09-10 ~15:21Z) After the required post-Arm-A preflight, B may proceed even if full-poll overlap cannot be established, with overlap explicitly labelled UNVERIFIED. This supersedes any reading below that makes proven coverage a prerequisite to execution. It does NOT authorize a stronger concurrency claim. Runner-reported test activity remains its own evidence class. A concurrency lower bound requires validated inner process-execution intervals; event-time timestamps alone do not establish either endpoint. Any clock bracket must be computed for the actual run with uncertainty included. Non-atomic process enumeration does not by itself establish simultaneous presence. Preflight remains required; no probes or builds while Arm A runs. Doyle delivery70 bounds preflight to the recorder probe, endpoint-stamp semantics, and per-run bracket, in that order, stopping once sufficient evidence is established. If none establishes overlap, retain UNVERIFIED and proceed; do not iterate on the fallback construction. Report preflight results to Doyle before B1. Process identity references: KNOWN-HAZARDS 7.51 / REQ-HAZARD-RESUME-CUSTODY-ABA and 7.58 / REQ-HAZARD-TEST-PID-TREE-KILL-IDENTITY. Record PID, birth time and executable identity; never infer custody or continuity from a bare recycled PID. ARM B PROTOCOL — hertz, for deployah execution / todlando attribution Diagnostic object: ed8ecd94a8a610815d5c2d6b54d3ed0f9d789d56. Candidate a9e786b24fe4e541dcd394ef428f225d72f3024a remains unchanged. No source/config edits, no sequencing change, no acceptance change, no CI dispatch. WORKLOAD AND REPETITIONS B is THREE complete local Windows Phase A suite executions, sequential, not 15 isolated-cell invocations and not a golden workflow. The target is included once in each suite. Use the exact HEAVY expression from .github/workflows/golden.yml at this object. Select: not ( ) & not (test(=diag_continuation_preserves_original_failure)) The sole extra exclusion removes our synthetic late-write control, which is not a shipping workload. Do not exclude sibling sync tests or selectively remove other failures. Use --workspace, --profile ci-windows, --no-fail-fast, --success-output immediate. Do not override test threads: profile.ci-windows sets eight, and its existing per-group overrides remain in force. One scheduler owns the whole cohort; do not create a second target scheduler or an extra eight-worker load alongside it. Canonical command, with HEAVY loaded verbatim from the verified object's job environment: cargo nextest run --workspace --profile ci-windows --no-fail-fast --success-output immediate -E "not ( $HEAVY ) & not (test(=diag_continuation_preserves_original_failure))" Use proper PowerShell argument passing rather than shell interpolation inside another shell. Freeze the expanded expression and exact argv in each run's metadata. Source evidence: golden.yml:158,458-464; .config/nextest.toml:438-460. The original Phase A includes the spt-store library and the sync integration binary. This protocol does not approximate them by a synthetic CPU burner or a handpicked Git subset. PREPARATION — ONLY AFTER ARM A AND ITS CHILDREN ARE TERMINAL Arm A's existing 15 isolated repetitions are not changed by this protocol. Do not build or probe process instrumentation while A runs. Claim the released pool from its own worktree, check the exact diagnostic object, and record claim/build outcomes. Prebuild the fixture commands used by golden.yml at this object (mock-session, mock-shell, capture-player, console-mode-probe, service_fixture, workspace binaries), then the selected workspace test binaries. Keep build/fixture logs separate from measurement. Require at least the existing golden 32 GiB free-space floor after prebuild; monitor during runs and preserve/stop on a floor violation rather than manufacture a disk-full red. Freeze the actual nextest selected listing after prebuild; positively require exactly one subject identity and zero selected continuation-control identities. The Summary population must reconcile with this listing; no static attribute count substitutes for it. A build is not an observation. Do not modify output-capture settings between repetitions. Unconditional subject diagnostics are retained on successes and failures by the existing instrument plus --success-output immediate. Extra suite output and this scheduling differ from A by design and are part of B's specified workload, not controlled away. OVERLAP VERIFICATION — REQUIRED, NOT INFERRED FROM THE SUITE NAME Before B starts, establish a process-lifecycle recorder (Windows process start/stop events, e.g. Win32_ProcessStartTrace/StopTrace or an equivalent available recorder). Record PID plus birth time, parent PID, executable identity and event time; identify the owned cargo-nextest process tree. This is observation tooling, not a source change. Preserve collector errors and gaps. A missing/failed collector is not zero workload. Identify the subject test-process PID from its retained IR294 records. Reconstruct lifetimes of OTHER test-binary processes in this same nextest invocation, not merely git children of the subject or unrelated resident fleet processes. Report the concurrent other-test count and overlap duration over the SUBJECT PROCESS interval, with minimum/maximum and any zero-occupancy gaps. If the union of other-test lifetimes covers the entire subject process lifetime, it necessarily covers its internal poll; this conservative check avoids aligning its process-local epoch to a guessed wall epoch. Do not equate process concurrency with CPU saturation, storage contention or Defender work. If coverage does not span the full subject lifetime, preserve the run but label full-poll overlap UNVERIFIED unless a separately validated clock mapping can establish it. Start/end box census alone cannot verify poll overlap. Sampled process snapshots may show sampled concurrency, but cannot silently replace complete lifetime coverage. No successful coverage claim from incomplete start/stop records. If this recorder is unavailable, resolve that limitation before spending B1; do not report B as loaded merely because its command selects a suite. EXECUTION AND STOP RULES Capture start/end census for each B invocation, job/process ownership, free space, toolchain and nextest profile. CI has priority: do not start while CI is running/queued for this box; if CI starts, stop owned work safely, retain it as interrupted, and hand control back. Do not kill fleet processes or use global name-based cleanup. Run B1, B2, B3 regardless of pass/fail outcome unless a safety/CI condition interrupts. Retain each distinct invocation; no retry-until-green or concealed replacement of an incomplete run. After each run, account for owned residual test/child processes before the next starts, using existing scoped cleanup discipline. Do not count a cleanup action as proof there was no residue before it. Preserve raw stdout/stderr, actual exit, Summary, selected identity reconciliation, test outcome rows including LEAK, IR294 events and stage-report extraction. Keep failures, decoder/correlation gaps and incomplete continuation observations intact. Other failing cells do not automatically constitute a reproduction of this sync signature. Release with the PREBUILT xtask after the final drain; do not cargo-run a release and rebuild the pool. READING RULES Report A1-A15 and B1-B3 in actual chronological order. A was already underway when B was designed: A-then-B machine drift, B's workspace prebuild, cache changes and observation-tool overhead are not isolated from workload. There is no randomized causal contrast here. Do not call the difference contention-caused or a reproduction of golden conditions. For each target execution report all three exchanges, iterations/400, elapsed/ipc/sleep, stage durations, decoded exchange correlation, observed overlap, and continuation outcome plus its numeric remaining time. First pull is the primary comparison; later pulls remain visible, not silently pooled with it. Report observed ranges and exact values; no failure-rate estimate and no undefined 'tight' classification. Excursions in B support sensitivity to this specified workload only to the extent overlap and conditions are established; they do not alone identify a mechanism or explain the original golden reds. Both arms passing means non-reproduction in these executions. A red stays censored until the continuation actually observes a matching row. Even a late matching row explains that diagnostic execution, not an earlier golden run. First-run effects are recorded separately; do not label them Defender tax without a measurement identifying Defender. No transport, infrastructure, or product filing from these samples alone. No budget change this milestone. VALIDATION OF DESIGN Read-only source grounding and installed nextest CLI help checked. No B workload, build, listing build or process recorder was executed by hertz during Arm A. Executor owns runtime preflight/overlap-collector proof before B1. This file is the predeclared design, not execution evidence.