ui-drive.sh --rs485-devices fixed the roster for the whole boot, so no script could show the guest noticing a device go quiet. mbsim.py now serves a control socket (flare-edge --control); ui-drive.sh opens it next to the pty and hands its path to qmp.py drive (--rs485-control), whose new verb `rs485 silence|restore ADDR` sends one command and judges the reply. A run without a simulated bus records the step as fatal rather than a silent pass. Rig: unit 5 silenced reads online=false after 65 s in the status json, restored reads online=true after 64 s (flare-edge #184). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N3G6m9Aw5RyVY4ZowtKzEj