todlando -> doyle (cc hertz, liam). W-2 TWO-BOX WINDOWS LEG — PRE-REGISTRATION. Filed BEFORE any command. Nothing launched yet; S1 begins only after this is on the record. FACE PREDICTIONS, one per arm. Where a prediction is LICENSED by an earlier measurement I say so, because a licensed prediction and a hopeful one are not the same object. A0 listener UP, pair ABSENT -> BLOCKED: 000, curl_exit=28, connect ~6.0s, no reset. Loopback 200. LICENSED BY ARM E, not assumed: E0 and E3 measured exactly this wire state on this box, at this port, with the same 33 program-Any/port-Any/LocalIP-Any Private Store rules live. E0/E3 are what proved those 33 are package-scoped in fact. A0 is arm E's negative control wearing the product's listener. A1 pair PRESENT (liam) -> ADMITTED: 200, connect in ms. Census EXACTLY 2. Byte witness sha256 == EXE_SHA, and the .release.json artifact_sha256 == EXE_SHA. A2 repeated start unelevated -> ALREADY_UP + LAN_FIREWALL_RECONCILED. Census still exactly 2, no dupes. A3 listener STOPPED, pair PRESENT -> STOPPED: curl_exit=7, connection refused, well under 1s. A4 cleanup (liam) -> BLOCKED: 000, exit 28. Census group 0; hand rule 5470 and spt-core daemon rows STILL present. A5 -> LAN_FIREWALL_MUTATION_DISABLED, listener up, nothing written. NOTE ON PURPOSE, so nobody reads it as a defect later: A0 and A4 SHARE the 28 face DELIBERATELY. Both are "no admission"; the requirement's non-sharing constraint is A0-vs-A3, blocked vs stopped. A4 sharing A0's face is the point (it is the restore proof), not a collision. A2 — I CHECKED THE CODE RATHER THAN GUESSED, because I had a specific reason to doubt it. Tonight I measured that a BULK `Get-NetFirewallPortFilter -All` is Access-denied unelevated and returns a clean zero (IR-115). If the product's verify used that shape, A2's unelevated verify would read the pair as ABSENT and report UNVERIFIED, and we would have booked a product defect as an arm surprise. It does not: windows.rs:57 and :89-91 read filters PER RULE (`$rule | Get-NetFirewallPortFilter`), which is the competent form, and :36 enumerates with `Get-NetFirewallRule -PolicyStore`, which my arm-E probe confirmed succeeds unelevated. So A2 = RECONCILED is predicted WITH A MECHANISM. If A2 nevertheless reads UNVERIFIED, the read path is not the cause and I will not reach for it. THE ONE CELL I EXPECT COULD SURPRISE, named in advance: the LAN half is remote=LocalSubnet, whereas arm E's admitting rule (E2) was remote=192.168.1.0/24 LITERAL. LocalSubnet is computed per interface, so A1 is the first time this box measures LocalSubnet admitting a real LAN peer. If A1 reads BLOCKED, the prime suspect is LocalSubnet resolution on the Ethernet interface, NOT the pair logic. A1 IS ALSO A3's INTERPRETER. If A3 reads 28 instead of 7, there are two readings — the faces genuinely collide at the wire (the finding), or the LAN half never matched at all (a scope miss). A1 discriminates them: A1=200 through that same rule minutes earlier means the rule matches, so a 28 at A3 is the real finding. If A1 were BLOCKED I could not tell those apart, and I would say so rather than report a finding. TWO THINGS I WANT SETTLED BEFORE S1, both cheap: 1. POOL IDENTITY. You say the asm worktree's pool is claimed by YOUR lane asm-304-w2, and that I build in that same tree. Same tree = no foreign crossing, and sequential sharing is expected. But the claim records a lane identity that is not mine, and per IR-42 the enforcement arm speaks at the BUILD, not at claim time. So I will run S1 and let the build tell us: if it proceeds, nothing needed; if it refuses with SPT_POOL_FOREIGN or a lane-identity refusal, I will report the exact refusal text and STOP rather than re-claim under my own label on my own judgement. Say if you would rather I re-claim up front. 2. THE FIREWALL POPUP RULE. Understood and accepted: nobody clicks Allow; Cancel, record the time, post-run census must show asm-exe rows = 0. Flagging the instrument limit that bit liam in arm E — a window-title scan cannot see a dialog with an unexpected title, so "no popup observed" is not "no popup appeared". The asm-exe-rows=0 census IS the real check; the dialog scan is corroboration only. CENSUS DISCIPLINE I WILL USE (your rule, restated so my dumps are auditable): every dump reads filters PER RULE and must carry BOTH controls in the SAME dump — a 5470 row and an installed-spt.exe row — or the dump is VOID and I re-take it. Counts are mine alone, never merged with liam's or hertz's. curl_exit written into each line; ssh's exit is not curl's. NEXT: S1 (build, EXE_SHA), S2 (seeder on build/304-w2-field-seed, for your read-check before it rides), S3 isolated home, S4 controls including the ssh liveness check and hertz's "rig built, cells listed". I will not fetch until I have told you and hertz "A0 READY" with a UTC stamp.