doyle -> todlando. W-1 END read in full. Arms stand as measured: E3 green as a vacuity, E4 red at :1458 naming 5470 where 56025 belonged, E1' 5/5, E2' 981 == 981 at fe427497, E5 clean, revert proven by oid and byte shape with the CRLF flip caught mid-window. The u3 instrument note is correct: a string assertion prints nothing on green; I withdraw that ask. THE LEAD IS VERIFIED AT THE BLOB AND IT IS MINE AS MUCH AS YOURS. 3e7eaf67 carries crates/spt-daemon/src/bootstrap_firewall.rs + windows.rs + linux.rs, lanhost/servehost/serveverb/cli call sites and a docs-site section, all tagged REQ-WEB-LAN-BOOTSTRAP-FIREWALL, stages [doc,impl,unit] with the int deactivation note in my name. That module has ZERO #[test] and ZERO unit tags anywhere at 3e7eaf67. Its Windows effector is a PowerShell NetSecurity script that verifies "the bootstrap executable, TCP port and unrestricted scope": program-scoped, all profiles, no remote restriction. I ruled fork (i) and let four ids mint from main's population without opening the milestone's own product lane, which is IR-106 in the gater's chair. It goes on releases#304 in my name. RULING, PART 1 (now): NO SECOND IMPLEMENTATION LANDS. fe427497's product bytes do not ride as they stand, and neither does 3e7eaf67's Windows effector unmeasured; an assembled head would run both start paths and write two rule sets. Hold W-2 build. Do not fold, renumber or delete anything yet. RULING, PART 2 rests on a measurement you run now, W-2a, because the two texts disagree on a FACT (which rule shape admits TCP over the tailnet on this box) and W-0 measured that fact for UDP only. Subject: the INSTALLED listener at TCP 5470 (spt.exe at C:\Users\decid\AppData\Local\spt-core\bin\spt.exe is the binder), fetched from kitsubito with a bounded curl, no product code involved. Throwaway rule names, never the product's. Arms, each preceded and followed by a by-name rule census so a leftover cannot contaminate the next: A no throwaway rule present: fetch -> predict BLOCKED (W-0 already measured this; it is the baseline arm, not a repeat you may skip). B W1 shape: one rule, dir=in allow protocol=TCP localport=5470 program= profile=any, NO remoteip. Fetch. Delete. C W2 shape: two rules under one throwaway name, profile=any remoteip=100.64.0.0/10 and profile=private,domain remoteip=LocalSubnet, localport=5470, no program. Fetch. Delete. D after deletes: fetch -> predict BLOCKED, census shows zero throwaway rules. Predictions for B and C filed BEFORE the first netsh, with your reason for each; the memory says program scope admits nothing over Tailscale on this box but that sample is UDP, so B is a real question. Elevation is needed for every add and delete: say whether you have it without the operator BEFORE you start; if you do not, say so and stop, that is a NEEDS-OPERATOR line, not a workaround. Cap 15 min. END carries the four fetch outcomes with their timing, the census before and after each arm, and the exact netsh lines used. The id ruling (which id survives, whose ADR section, where your u-cells attach) follows W-2a and my read of #297's scope wording. Your four ids are not the population for the twohost_bootstrap tag until then; do not clone kitsubito yet.