phase_watch.py runs give a sharper tally than the earlier inducer test, because the only difference between the groups is one tool: pilot alone went clean to 936s and 1064s (2 runs), while pilot + phase_watch froze at ~70s, ~253s and ~126s (3 runs). Same boot path, same pilot, same mission. What phase_watch adds is find_mission(), which does TWO full sweeps of guest memory at startup plus ~130 small reads every 5s. The sweeps are the same shape as the heavy_read.py scans the earlier n=2 experiment implicated. Still correlation, not cause -- 3 vs 2, and the earlier inducer test produced a clean counter-example. But it is the best-supported version of 'the instrument provokes the freeze' so far, and it is my instrument, which makes it actionable. The cheap test is named: find_mission only needs to run once, so re-run the watch with the sweeps replaced by an address from a prior run. Freezes stopping implicates the sweeps; continuing implicates the per-sample reads. Cost so far: three attempts at observing a phase advance, all truncated inside four minutes.