P2 ARITHMETIC — the divergence window

  window  2026-08-20T09:15:47Z -> 10:17:52Z   = 3725 s = 1.0347 h
  NOTE: this is 1.03 h, NOT the >=4 h the task specified. The operator closed it early.
  The conclusion below therefore does NOT rest on an extrapolated daily rate.

box                       agent       start    end  delta  per hour
demo-felhom (CONTROL)     0.129.0       199    203     +4      3.87
demo-hp (FIXED)           0.130.0         0      0     +0      0.00

PREDICTED (pre-registered, P2 table): control ~4/hour; fixed ~0.
OBSERVED: control 3.87/hour, fixed 0. Control matches the prediction.

THE ASSUMPTION-FREE STATEMENT — matched opportunities, counted from ep0's access log:
  Both agents made EXACTLY 4 GET .../snapshots calls and 4 GET /version calls in this window.
  Same cadence, same work, same number of chances to leak.
    control: 4 cycles -> 4 leaked connections
    fixed  : 4 cycles -> 0 leaked connections
  No rate extrapolation is needed for that, and none is used.

  Poisson: P(observing 0 leaks | the OLD rate, lambda=4) = e^-4 = 1.83%
  On its own that is suggestive, not proof. It is not on its own:
   - P1 released exactly 199 descriptors the instant the old process died;
   - the mechanism is identified at file:line and pinned by a red-proofed unit test;
   - the fixed box was directly observed returning to 0 connections 133 s after restart.

P3 — total rate with ONE box fixed
  observed 92.8 fd/day  (predicted ~100/day, from ~200/day with both boxes leaking)
  Poisson on n=4 is +/-2, so the 2-sigma band is 0..186/day — the prediction sits inside it.
  A 4-descriptor window cannot pin a daily rate tighter than that, and this does not pretend to.

CONTROL INTEGRITY: the two boxes' OTHER traffic is unchanged and near-identical in this window --
  libwww-perl 924 (.2) vs 926 (.3); proxmox-backup-client 898 vs 898.
  So the only thing that differs between them is the agent binary.
