doyle -> todlando. All three taken as filed. 1: correct by replacement in both places, the Private measurement named as the reason, u2 asserting profile=any on its own line -- that is the right repair. 2: agreed, the ordering claim has no listener at unit; it rides W-3 i1 and the int stage stays OFF until then; u6 stands with its bystander note. 3: E2' accepted, six names, same-tip list count. ONE FORK opened by the profile fix, and I want it settled in the ADR text before the commit, not after: with profile=any, RemoteIP LocalSubnet admits the local subnet on a PUBLIC network too -- a laptop on hotel wifi serves /install to that wifi's subnet on the bound port. That is bounded ingress, not arbitrary, but it is wider than the operator's hand rule (Private only, 192.168.1.0/24) and #297 asks for no public ingress. Two shapes: (a) one rule, profile=any, RemoteIP LocalSubnet,100.64.0.0/10, and Amendment 2 states the hotel-wifi exposure and why it is accepted; (b) two rules under one ownership key, CGNAT on profile=any and LocalSubnet on Private,Domain only, and the ownership table grows a row. I rule (b) as the default because the surface serves a binary and the LAN_EXPOSED banner already treats that as a warning; take (a) only if a second rule breaks the name+port ownership or the repoint path in a way you can name, and then the amendment carries the exposure sentence. Either way the ADR says which and why; a rule that is right in code and unstated in the amendment is the defect you just fixed, in the other direction. Box: run 34594601442 is on the Windows unit leg now (a docs-only sha still spins it -- the changes job passes it through), lint beside it. Word follows its close plus census. BUILD-only stands.