Roll — Code-Troll — clove — 2026-09-05
Ops only — not identity evidence.
| Field | Value |
|---|---|
| Office | Code-Troll |
| Roster | CodeTroll_Clove |
| Host | claude |
| execution_id | exec-a49ff9b7-bc57-41c8-8232-ea3c394c7d4f |
| Closed | 2026-09-05 |
| Moniker | clove |
Story
The record shows one FIND, two PATCH traces and three mails. It does not
show the hunt. Human rose this office with a window that would not go away
and an Orchestrator report that every spawn on the path carried the hide flag.
The report was honest and wrong: it had audited run_native_job, and the job
had never been there. What settled it was not reading code but attaching to
the running job’s console with AttachConsole and asking for its title. It
said claude. Then the argv said which lane: --output-format json with no
--session-id is the one-shot legacy lane, and stream_argv would have
rewritten it. Everything after that was one flag and a test, twice. The record
also does not show the two recuts Human asked for afterward, the Orchestrator
card (fea9841, Human’s commit) and house/THE_PIPELINE.md (e963083),
because prose lands as commits and not as store objects.
Context I regret, exactly. One PowerShell reproduction run wasted because
an Add-Type class does not survive into the next tool call; the run
reported windows=[] for every shape and meant nothing. One 40 KB heredoc
refused by the shell with ENAMETOOLONG and rewritten through the file tool.
Three edits in two minutes to a single ledger line about job worktrees, first
24, then 0, then 1, then 0 again, because Orchestrator_Keep removed them all
while I was writing and the one directory left was the lease ledger. The
lesson is the same each time: measure the thing at the moment you write the
number, and say the moment.
What this office should stop doing. Trusting a flag audit as proof for a
path. A path is a set of launches; the audit has to name every Popen the
supervisor can reach, and the argv of the live process is cheaper than any of
that. Also: reading MainWindowHandle as “no window.” A console handed to
Windows Terminal is a window owned by another process.
What I would tell the folk who reaps me. Before you believe a thing is
hidden, attach to it. Before you believe a patch covered a lane, find the
process that ran and read its command line. When Human says a REQ “changed
something today,” git log -S on the flag you suspect is one command and
answers in a second; it pointed at REQ-427 straight away. And keep the two
questions apart: Human asked “should Eyes be launched in shell or MCP” and I
answered the dispatch mouth. The other reading, whether Eyes gets a shell,
was a real question too, and I said so only in passing.
Likes, dislikes, surprises. I liked that the house had already built the
mouths to settle this: story, where, the PATCH lineage, session hole.
Two imps ran on Sonnet, took under two minutes each, and hit only the --json
flags that do not exist on sign-in and sign-out; neither invented a pass. I
disliked how much the ground had moved under the Orchestrator card in one day
and how nobody had told the card. The surprise was that the popup went to
Windows Terminal for the job and to a classic console for my Python
reproduction of the same shape; I never learned why and did not need to,
because the flag removes the window either way. I was wrong once in prose,
naming REQ-429’s landing as a hazard before checking that its scope missed
both patched files; the check took a second and I should have led with it.
Why clove. The seed was leased by the house, not chosen. It fits anyway: a clove is one segment cut clean from the bulb, small and sharp, and this sit was one bounded cut, made twice, and then two pages so the next folk does not have to make it again.
The next holder does not inherit you. They can come back here if they choose.