# Tasks: Remembered Machines Tasks by their numbers in the project-wide sequence, which continues across every spec. Each was built and checked in one piece, so they are not broken into phases. - [x] T249 Forget a machine remembered only for a connection once no network port connects to it, list an untrusted record as on the network only when a session is advertised at its address, and connect to a remembered machine by its listed identifier, per FR-P01, FR-P02, FR-P03 (R-105) — done: `drop_unused_peers` runs when a network port disconnects, replaces its peer or is deleted; `merge_known_peers` matches a trusted machine by host and any other by address; `resolve_peer` looks among remembered machines after advertised ones. The machines test checks a disconnected machine leaves the configuration, a contract test connects by a listed identifier and finds a named machine kept after disconnecting, and the merge test gains the untrusted cases. - [x] T250 Follow a machine to where its session is advertised when its link is down, per FR-P04, SC-P01 (R-105), Constitution Principle I — done: `PeerConfig.advertised_as` holds the session name advertised at the machine's address; discovery wakes a watcher when a session is resolved or goes, and a session reporting a change prompts the same look; the session supervisor's `Move` command refuses for a machine carrying MIDI. No contract change. A test starts a network port whose machine is at a dead port, hands the daemon an advertisement as discovery reports one, and checks the connection, the stored address, and that a connected machine is not moved; `next_step` is unit tested for port, host, trust and identity. Checked live between two daemons on one Mac (R-105). - [x] T251 Prove which network port a session is, and follow a proved port to another host or under another name, per FR-P05, FR-P06, FR-P07, SC-P02 (R-106) — done: an Ed25519 key per daemon in `identity.key`; `mhkey` and `mhport` in each session's TXT record through all three responders; `IdentityPacket` in the RTP-MIDI crate, read by the packet fuzz target; the supervisor answers a challenge and sends one with `Prove`; `PeerConfig.key` and `port_id` are stored once proved at the address connected to. New dependencies `ed25519-dalek` and `hex`. No contract change. Tests over real sockets: a daemon without the key advertising it is not followed and one with it is, with trust kept; a forged key at a connected machine's address is not stored and the real one is. Removing the comparison with the expected key fails both. The packet round trip and the proof's refusals are unit tested. Checked live between two daemons on one Mac (R-106), and the packet fuzz target ran 1,474,155 inputs in 61 s without a finding. The Linux gates pass, and a port advertised through Avahi was listed by Audio MIDI Setup, connected to Apple's session, and was invited by rtpmidid, with a note each way (R-106). Not run: the Windows responder. - [x] T252 Answer a machine at the address it was heard from, scope included, so an invitation over an IPv6 link-local address is accepted (R-107), per FR-011, Constitution Principle I — done: `canonical` keeps an IPv6 address whole and `on_port` moves an address to the data port without rebuilding it. A unit test over the two functions covers an IPv4-mapped sender and a link-local one on each port. Checked live: Apple's Session 1 invited a port on Linux over `fe80::` and joined, with a note each way.