CONDUIT W2 (releases#228) READY FOR GATE — PR #172, branch fix/228-owner-online-restore, head e4c122cc, base f1395b6a, fixes #228. Built to your ruling: shape (c), EDGE on owner offline->online since the last pass, refusal arms carried by CONSTRUCTION (one shared restore_persistent_shells_of_owner both triggers call, so they cannot drift). (a) not built, (b) untouched. spawn_wake_host's contradicting comment replaced; doc-stage sweep covers CONTEXT.md, KNOWN-HAZARDS 2.7 (entry + table row + both mapping lines), MANIFEST.md x2, and the TWO published docs-site surfaces (shells/overview.md stated it as "not by the owner's own online edge" — that sentence is what this falsifies). Minted + activated REQ-SHELL-OWNER-ONLINE-RESTORE (doc/impl/unit). Verdicts, each read from its own .exit file: treqs 0; nextest -p spt-daemon (shell/wake/restore/reconcile) 0, 111/111; clippy Windows 0; xtask check 0; clippy Linux 0 at SHA=e4c122cc echoed by the same command. Hazard test = your two arms plus a third, one fixture, no rest path in setup. Both discriminating arms MUTATION-PROVED, not asserted: level-instead-of-edge => leg exit 100 (the freshly stranded instance came back with no new owner-online edge); predates-boot arm dropped => leg exit 100 (the this-boot force-kill came back). Source restored byte-identical, sha256 asserted in the harness. One correction I owe you, found by measuring my own claim before it shipped: the duplicate-attempt case (edge seeded before the sweep) is refused by the RESTAMPED BIRTH STAMP, not by the down-in-fact arm. A launch is not the online switch, so a just-restored instance keeps an offline record until bind-shell and still reads as down in fact. The PR, the REQ text and the code comment all say the right arm now. Starting W3 (releases#234) next per your "proceed, don't hold the lane".