W3 continuity execution plan — source preparation only; NO W3 build/runtime authorization. Owner: hertz. Product interpretation/fixes: todlando, triage/allocation: doyle. W1 boundary c468e9df remains unchanged. W1's cold-pool authorization does not cover these cases. No second producer while W1 runs. Evidence reviewed - todlando-304-w3-source-maps.json, complete attach and roster reports. - spt-daemon/tests/attach_idempotent_replay.rs:32-55 explicitly records that removing the discriminator leaves the integration green. Its raw broker consumer and Shell-minter input omit the serve-worker/actual RC composition. Header claims about ORIGINAL writer are not proven by its echo. - spt/tests/daemon_refresh_e2e.rs uses invalid node seed, real daemon refresh, and process/perch assertions. That is valid lifecycle coverage, not old viewport/input continuity. Do not replace valid lifecycle assertions with another survival-only test. - docs/DEBUG-ROLLOUT.md and ADR-0016 require signed per-platform artifact, private channel/key overlay, monotonic version, apply-time verification and brain-compatible classification with live resources. No current cause established for #302, #49 or #267. Reconnect input draining is a source observation, not incident attribution. Acceptance protocol Run actual persistent spt rc controller plus read-only rc observer, not direct Brain output consumers as the acceptance surface. Keep the same frontend processes, stdin, endpoint/session and decoder state throughout each case. No detach/re-attach before the primary verdict. A real hosted child reads framed INPUT(run_nonce, sequence, sender_monotonic_ns) lines. It records each parsed command and execution ordinal to an independent append-only child ledger, then emits transformed ACK(run_nonce, sequence, ordinal) bytes. ACK differs from the input so PTY line echo cannot masquerade as delivery. A separate child timer emits HEARTBEAT(run_nonce, heartbeat_sequence). Serialize output writes to avoid artificial interleaving. Driver submits at 4 Hz; heartbeats at 4 Hz. Record source writes, child parsed/effected records, child emitted output, controller capture, observer capture and trigger start/end with monotonic timestamps. A pipe write is submission, NOT proof of target acceptance. Distinguish submitted-but-never-parsed, duplicate child effect, output replay, missing rendering, and delayed rendering; report all submitted gaps, do not hide them by counting only successful ACKs. Require every numbered submitted command to yield exactly one child effect and one logically rendered ACK in order within the case deadline; retain raw capture to distinguish legitimate VT repaint from application duplicates. Compare both viewports to independently advancing child heartbeat/effect ledgers. Preserve identifiers for broker/brain generation, PTY pid+birth, session and stream/controller seat where available. Apparatus control: deliberately pause only the capture/render path in a separate negative-control cell. Oracle must identify view lag while child progresses. Separately duplicate one command in an apparatus-only transport control and require duplicate-effect detection. Controls prove the rig's oracle, not any product bug. Do not mutate the W1 tree to run controls. Independent cases, no shared-cause assumption 1 Local steady-state: 180 seconds, no refresh/update, fixed modest workload. Retain max/inter-heartbeat gaps and complete input-to-ACK latency series. A recurring 5–10 second delay matching #302 is a candidate reproduction; small scheduler variance is not. 2 Target refresh: 30 seconds pre, real daemon refresh while input continues, at least 90 seconds post. Require observed brain generation transition, unchanged broker/PTY/session, continued OLD viewports. No manual serve_attach replacement. If primary verdict fails, preserve evidence BEFORE a separately labelled same-session manual detach/re-attach recovery observation (#267). 3 Explicit live core apply: same workload, normally verified signed brain-compatible candidate staged only in fixture home. Invoke apply and observe activated candidate independently of broker/PTY identity. No broker-breaking candidate or quiescing live endpoints to make the case pass. 4 Plain composite update: separate case and fixture home; core-already-current/adapters-noop baseline, then core-apply/adapters-noop. Record core and adapter phase boundaries. Actual adapter-change case requires separately pinned adapter artifact; not silently substituted. 5 Remote steady-state: same 180-second protocol over two explicitly allocated isolated hosts, with local-on-source and local-on-target controls in separate serial cells. No refresh/update mixed into this case. 6 Remote target refresh, source refresh, and update: separate follow-on cells; not part of initial local allocation. No real fleet trust/routes/relays or production endpoints. A non-reproducing case reports only its observed protocol and duration; it does not close field incidents. Historical v0.69.0 provenance must be verified separately before claiming reproduction of that version. Proposed sizing — estimates/caps, NOT measured need or permission Local first allocation: one Windows host, one serial lane, up to 12 owned processes including driver, broker, supervised brain, hosted child, controller RC, observer RC, transient trigger CLI and ConPTY/translation helpers. Fail closed if the actual fixture exceeds the enumerated cap; no automatic widening. Proposed aggregate owned working-set ceiling 8 GiB and host available-memory floor 8 GiB; sum is a conservative operational measure, not private committed-memory attribution. At most four initial local scenario classes above, each separately stopped/reaped before next. Steady case outer 240s; trigger/update case outer 300s; startup 45s; teardown 30s. Trigger command uses its existing bound; no product timeout changes. Proposed total local runtime allocation 30 minutes, no retries. Case loops record elapsed, budget type, iterations and producer progress on success/failure. Disk: separate W3 allocation after W1 release. Preferred sequential reuse of this SAME tree's released pool only after a new source freeze and toolchain/owner check; no foreign-tree sharing. Warm incremental proposal ceiling 16 GiB plus 4 GiB retained candidate/fixture/evidence, protected reserve32 GiB; admission52 GiB. If warm equivalence fails, this proposal is invalid: request a new cold allocation (64 GiB growth +32 GiB reserve), not silently reuse the W1 grant. Build jobs2, maximum45 minutes warm build; only exact required fixture/CLI binaries. Candidate copies retained under fixture artifact space; never overwrite source-tree running spt or install paths. Actual binary sizes and candidate count must be measured before admitting update cells. Remote allocation: explicitly assigned second host and private transport path, max16 owned processes aggregate,8 GiB working set per host,8 GiB available floor per host,4 GiB runtime artifact growth per host,32 GiB disk reserve per host. No remote builds in this request; missing matching artifacts require a separate build allocation. Proposed20-minute remote runtime ceiling, serial cells. These are requested limits, not a claim that remote resources are already available. Isolation and cleanup gates Private SPT_HOME, node identity, caller identity, TMP/TEMP/TMPDIR/RUNNER_TEMP, release keys/channel and staged binaries. Scrub live perch/session/environment identity. SPT_INSTALL_NO_FIREWALL=1 everywhere. Valid private identity does NOT by itself disable discovery, relay, STUN, auto-update fetch or fleet peer interaction: concrete production-daemon controls or network sandbox must be identified and checked before launch. Until then real-daemon fixtures remain BLOCKED, even if loopback sockets work. Use retained process handles and PID+birth identities; on Windows prefer owned job containment with kill-on-close, accounting for intentional broker/brain process behavior. Retain scoped image/cwd/argv census before/after each case, report unreadable process fields without claiming universal clearance. No blanket image kills, PID-only delayed kills, service changes, firewall changes or pool deletion. Stop on quiet-window refusal, capacity/memory/identity uncertainty, first failure or timeout; retain actual exit plus failure-time observations before cleanup. Release pool using prebuilt xtask; no cargo run for teardown. Coverage replacement boundary After a discriminating replacement has compiled and its negative control failed as intended, replace attach_idempotent_replay's ineffective freeze gate; retain genuinely independent lease/wire behavior only where it has a distinct observable contract. Migrate REQ-ATTACH-IDEMPOTENT-REPLAY evidence to the real composition, and preserve REQ-DAEMON-REFRESH's actual lifecycle evidence. No new test claiming exactly-once delivery from substring/nonempty/survival assertions. No source deletions during W1 freeze. All traceability changes/checks belong to the later explicitly allocated W3 source boundary. Pending implementation details Read-only apparatus/update scouts are identifying reusable production fixture APIs, exact ConPTY versus pipe behavior, local daemon network isolation, signed candidate setup, concrete binary prerequisites and cleanup gaps. Resolve these before requesting launch; this plan is not an executable or validated rig. Source-grounded apparatus addendum Piped actual RC uses rc.rs:1405-1445 byte-reader fallback; it does not exercise Windows interactive crossterm input. Add a separately named outer-ConPTY vehicle using spt_term::PtySession::spawn_program_in_env / SessionSurface::write_input / take_reader; never claim interactive-console proof from piped success. Reuse rc_attach_truth adapter/endpoint setup and twohost_cli continuous capture shape, but do not import its unnumbered tick/banner/tick oracle or whole two-host suite. Extend mock-session's existing manifest bind/ready contract with a fixture-only bidirectional continuity mode; current dummy/hold-unbound heartbeats never consume stdin. console_mode_probe.rs supplies byte CR/LF framing precedent. Binary minimum: actual spt, mock-session, exact continuity rig; staged psychebin is a copy, not a separate build. An outer ConPTY adds console-host overhead to the proposed process cap. Negative-control refinement: child deliberately pauses input consumption while staying alive and continuing fresh heartbeats. Oracle must fail effect/ACK progress despite both PID and output progress. Replaying an ACK without a journal entry is a delivery duplicate, not a duplicate child effect. Child ledger must never deduplicate input for the product. Verified blocker: daemon.rs:529-558 hardcodes LocalDiscovery::Mdns and BindScope::All and calls firewall::verify_and_record_self. firewall.rs:614-627 can repair Windows rules when elevated and does NOT consult SPT_INSTALL_NO_FIREWALL in that path. That variable protects install reconciliation, not this daemon verify/repair. Require an explicitly allocated disposable network-isolated, non-elevated environment; do not launch on the current workstation or add speculative product test knobs to make it appear isolated. A custom in-process NetConfig::Loopback fixture cannot substitute for the actual supervised-daemon acceptance boundary. Cleanup reuse: common::reap observe/authenticated_kill/target_gone/population_sweep, with independently bounded reader drain. Existing output_bounded polling is followed by blocking wait/reader joins and is not a complete hard-wall persistent-process supervisor. Numeric-only delayed taskkill is not acceptable. Traceability handoff from todlando delivery30: upcoming #230 regressions map to REQ-ATTACH-CLIENT-STALE (doc/impl/unit/int), not an arbitrary viewer warning. REQ-ROSTER-WAIT-ATTRIBUTION is separate doc/impl diagnostic work and does not claim continuity evidence.