comment #297 Field acceptance result on candidate b848244577d398600b59c7829fef9edbdb6315fa (v0.70.0), Windows box HFENDULEAM, 2026-09-14 06:43Z, fifth window (windows 1-4 were lost to instrument/environment causes, each ruled and on file): PRODUCT RED. What ran: elevated `spt serve lan --bootstrap --port 29470` once, scrubbed environment, exit 0. stdout: LAN_BOOTSTRAP_UP on 29470. stderr: `bootstrap-firewall leg=verify-query wall_ms=2650 outcome=completed`, then `leg=verify-query wall_ms=3027 outcome=killed`, then LAN_FIREWALL_UNVERIFIED (firewall command timed out). No reconcile-write leg ran. The owned rule pair (spt-core-bootstrap-inbound-tcp, -lan) is absent afterwards: two independent censuses (hertz 2/2 controls; doyle 0 of 1017 rules). Mechanism (candidate source): reconcile() takes a second NetSecurity snapshot before rendering writes (spt-daemon/src/bootstrap_firewall/windows.rs:846, FOLD-3); every powershell child is killed at a hard 3000 ms measured from before spawn and including output collection (bootstrap_firewall.rs:142,186). On a 1014-rule host the query alone costs 2.0-2.7 s (measured), so the pre-write snapshot is killed and nothing is written. Not a regression: main has no bootstrap_firewall module. Acceptance: "remote tailnet IPv4 client can GET /install with host rule admitting it" NOT MET (no host rule); "actionable diagnostics" MET; port override / repeated start-stop / second-machine GET NOT REACHED. A rerun that finishes under 3 s would be an intermittent green and does not count. Host left clean (no listener, no rules; closure d2/M5XKQ2DN-field-verdict-and-cleanup-closure.json). Ruling: .spt/preserved/hertz-fp-driver-review/d2/doyle-ruling-297-field-red-3s-cap-M5XKQ2DN.md. Milestone disposition referred to the operator (fix in v0.70.0 vs relocate to #307); either way a corrected candidate sha is required.