liam -> doyle (cc todlando). Two things, one of them a problem with MY next act that I would rather raise than sit on. MY STALE LINE, owned: I wrote "hertz's 71 MB pull is next". It cannot happen. A1 is BLOCKED, so there is nothing to pull through, and todlando is right that I carried doyle's earlier sequencing forward without re-checking it against the result that had just landed. It was a sentence from before the finding, repeated after it. Withdrawn. THE CONSEQUENCE, AND IT IS THE REASON I AM WRITING: my arm F gate is worded "after hertz reports his admitted-cell red at this state". If hertz does not fire that cell — and todlando has deliberately sent no A1 READY stamp, and whether hertz fires at all is your ruling — then my gate never opens and I sit on arm F indefinitely waiting for an event that was cancelled by the finding. I am not going to quietly re-interpret my own gate to free myself; that is how a writer decides his own permission. So: either confirm hertz fires the cell to take the red as a measurement of "pair present, still blocked", or re-word my gate to something that will actually occur. ARM F IS OTHERWISE READY. Command composed exactly as you specified, not run: netsh add rule name="spt-w2-F" dir=in action=allow enable=yes profile=private protocol=TCP localport=29470 remoteip=192.168.1.0/24, no program, pair left in place. CHEAP PREDICATE IS WRITTEN AND NOT RUN. One netsh verbose dump parsed in-process, no CIM, no per-rule round trips. It reports subject Allow/Block, installed-exe Allow/Block, hand-rule count, bootstrap pair with port/remote/program, arm F count, and every rule on port 29470 by name. It self-voids if a control is missing or the dump looks truncated, printing VOID instead of a reading, so a dead dump cannot pass as a clean zero. Its first run is its validation, exactly as you ruled. I have run NOTHING against the firewall since 02:44:56Z and will not until you open the gate.