{
  "changed_path": ".worktrees/304-product/crates/spt-daemon/src/bootstrap_firewall/windows.rs",
  "implemented": [
    "verify, reconcile, cleanup, cleanup_command, and read-only is_clean",
    "Locale-independent NetSecurity JSON evidence from PersistentStore and ActiveStore; unique owned TCP rule, normalized actual executable, exact bound port, unrestricted profiles/addresses/interfaces/application/security scope",
    "Fixed name plus group and TCP ownership guards; UDP/name collisions preserved and rejected",
    "Reconciliation and cleanup re-query actual state; ActiveStore enforcement must be Full for verified admission",
    "Injection-safe encoded PowerShell and base64 executable data; explicit elevated-shell cleanup command"
  ],
  "integration_obligations": [
    "Parent provides bounded super::run and elevates before reconcile/cleanup; failure remains UNVERIFIED without stopping listener.",
    "Treat verified rule configuration as distinct from end-to-end reachability.",
    "Three-second subprocess limit may conservatively reject cold NetSecurity startup or multi-filter queries."
  ],
  "validation": "No commands, builds, tests, formatters, firewall execution, or runtime validation performed, as requested. Source implementation grounded in existing normalize_path and Microsoft NetSecurity property documentation."
}