071 — REVIEWED: paired startup becomes a single-record pattern after the gap September5,2026. Focus remains xinzhai/xz. Finding The early paired five-minute pattern does not survive the overnight gap. After the final July10 pair at23:35, the next xz post appears July11 at15:11:936 displayed minutes later. The next148 posts retain124-character bodies but have148 distinct displayed minute timestamps. All148 body hashes are distinct. Their147 successive gaps are119 five-minute,10 six-minute and18 longer intervals (7–20minutes). The change persists beyond the initial payload-size transition: from the restart through just before the second size cohort begins atJuly12 18:02, there are301 xz posts and no duplicate displayed minute. This contrasts with the14 consecutive paired slots during startup. It supports a change in publishing mode, without identifying a process count. Boundary sequence (literal displayed dates) July10 23:35 — IDs4548631 and4548632: final startup pair,124characters each. July11 15:11 — ID4548644: resumed small record,124characters. July12 05:10 — ID4548835: final124-character record. July12 05:12 — ID4548836: first xz_improvement_plan_p1,864characters. July12 05:15 — ID4548837: first424-character knowledge record. July12 18:02 — ID4549003: first304-character record; the424 stream continues alongside it (044/055). Source URL template:https://paste.ubuntu.org.cn/ Interpretation A coherent working model is startup testing/bulk uploads plus paired periodic records, followed by a pause and a resumed single-record pattern, then a size change and a new longer-period record label, then overlapping size cohorts. Restart, configuration change, removal of a duplicate scheduled job, or one loop changing its output count can explain the observations. There is no evidence selecting one implementation among them. The first improvement-plan-labelled post occurring between the last124 and first424 body is a particularly useful boundary to prioritize in future source-code matches. It could mark a new record schema or task configuration. The label does not prove actual planning or learning; ciphertext changes do not disclose plaintext meaning. Gap and server-availability limits Eleven other validated paste IDs fall between the final startup pair and the resumed record. This is not a missing numeric range in our collection. These pages do not prove uninterrupted host availability during the entire gap. A host outage, client pause, scheduling change or deliberate delay cannot be distinguished solely from retained source displays. What this rules out narrowly The simplest description of an unchanged, uninterrupted paired timer over the whole early period is inconsistent with the observed sequence. It does not rule out multiple underlying tasks, two unsynchronized writers, deleted historical posts outside available records, or a different destination during the gap. The public author label still cannot authenticate identity, but the067/068 evidence favors investigating the families together. Reproduce python3 investigation/china/071-xz-restart-analysis.py Input:039 final checkpoint, sorted by numeric ID, source hashes independently checked in056. Private output:071-private/analysis.json with full gap histogram and boundary IDs. Snapshot SHA256:620d6dcc62fd2f4eefa396c631b43f57e308fcbd31e5c097994eca4aa5005f40 No network requests, pasted-code execution, decoding or key searches in this review. All times are source claims with minute resolution, not independent UTC event timestamps.