liam -> todlando, doyle. A1 RUN AND COMPLETE. One deviation from expected, and it is a finding, not a slip. Stopping here as instructed; A4 not run. PRE-CENSUS 02:37:12Z SUBJECT asm exe -> Allow=0 Block=0 CONTROL installed exe -> Allow=3 Block=0 (spt-core daemon, spt-fallback inbound UDP, spt-core inbound UDP) port-29470 rule names: [] count=0 listener: 0.0.0.0:29470 LISTENING 39320 A1 02:37:39Z start, 02:37:46Z end (7.3 s). Elevated, SPT_HOME set inline to the isolated home, asm head by absolute path, serve lan --bootstrap --port 29470. STDOUT: LAN_BOOTSTRAP_ALREADY_UP LAN_BOOTSTRAP_UP: http://192.168.1.81:29470/install (port 29470) sha256 x86_64-pc-windows-msvc 1e29d549d69c34e3fc452212406b7fe513935632816a4021cf7b94a29dc25137 LAN-EXPOSED: anyone who can reach this socket may pull the binary until `spt serve lan --stop`. STDERR: LAN_FIREWALL_UNVERIFIED: powershell.exe: firewall command timed out; this does not prove the listener unreachable. Rerun `spt serve lan --bootstrap` to retry admission. EXIT CODE: 0 *** DEVIATION: expected LAN_FIREWALL_RECONCILED. Got LAN_FIREWALL_UNVERIFIED on stderr, exit still 0. AND THE RULES LANDED ANYWAY. *** POST-CENSUS 02:38:04Z port-29470 rule names: [spt-core-bootstrap-inbound-tcp, spt-core-bootstrap-inbound-tcp-lan] count=2 — EXACTLY the pair you predicted, group "spt-core bootstrap TCP". SUBJECT asm exe -> Allow=0 Block=0. Still zero in BOTH actions, so no dialog was dismissed in either direction. CONTROL installed exe -> Allow=3 Block=0, unchanged; the predicate was alive across the whole arm. listener unchanged 0.0.0.0:29470 LISTENING 39320. asm-exe processes still exactly your two (39320, 52464) — the bootstrap invocation exited, it did not leave a process. dialog scan: nothing. Loopback http://127.0.0.1:29470/install -> 200 0.00077s exit=0. RULE SHAPES, verbatim: spt-core-bootstrap-inbound-tcp Enabled Yes, In, Profiles Domain,Private,Public, Group "spt-core bootstrap TCP", LocalIP Any, RemoteIP 100.64.0.0/10, TCP, LocalPort 29470, program none (port-scoped), Allow, Local Setting. spt-core-bootstrap-inbound-tcp-lan Enabled Yes, In, Profiles Domain,Private, same group, LocalIP Any, RemoteIP LocalSubnet, TCP, LocalPort 29470, program none, Allow, Local Setting. ActiveStore on BOTH: Enabled True, PolicyStoreSource PersistentStore, PrimaryStatus INACTIVE, EnforcementStatus {ProfileInactive, NoLocalUser}. Flagging that verbatim rather than reading it for you — it is the same ProfileInactive/Enforced axis that mattered on the earlier arm, and it is yours to interpret. WHAT I AM NOT CLAIMING: I am not saying the timeout is harmless because the rules appeared. The product reported it could not verify its own admission while the admission in fact succeeded, which is a false negative in its status reporting, and the 7.3 s wall time is consistent with a powershell.exe invocation hitting its own timeout. Whether the rules landed BEFORE or AFTER that timeout, I cannot tell from here — my pre-census was 27 s earlier and my post-census 18 s later, so I bracket it but do not resolve it. Stopped. Census is yours, then A1 READY, then the fetches. I have not run A4 and will not until told.