[
  {
    "command": [
      "git",
      "rev-parse",
      "7890ead39bb7f14ed44aaae44b0951f098ffe9ac^"
    ],
    "start_utc": "2026-09-14T12:52:44.517294+00:00",
    "end_utc": "2026-09-14T12:52:45.122091+00:00",
    "exit": 0,
    "stdout": "527cd8e8d7ef192892d5630fce10e69a6d811893\n",
    "stderr": ""
  },
  {
    "command": [
      "git",
      "bundle",
      "create",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\candidate.bundle",
      "7890ead39bb7f14ed44aaae44b0951f098ffe9ac",
      "^527cd8e8d7ef192892d5630fce10e69a6d811893"
    ],
    "start_utc": "2026-09-14T12:52:45.123595+00:00",
    "end_utc": "2026-09-14T12:52:45.188968+00:00",
    "exit": 128,
    "stdout": "",
    "stderr": "fatal: Refusing to create empty bundle.\n"
  },
  {
    "command": [
      "git",
      "for-each-ref",
      "--points-at=7890ead39bb7f14ed44aaae44b0951f098ffe9ac",
      "--format=%(refname)"
    ],
    "start_utc": "2026-09-14T12:52:53.079635+00:00",
    "end_utc": "2026-09-14T12:52:54.020122+00:00",
    "exit": 0,
    "stdout": "refs/heads/asm/304-v3\nrefs/heads/fix/297-enforcement-shape\n",
    "stderr": ""
  },
  {
    "command": [
      "git",
      "bundle",
      "create",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\candidate.bundle",
      "refs/heads/fix/297-enforcement-shape",
      "^527cd8e8d7ef192892d5630fce10e69a6d811893"
    ],
    "start_utc": "2026-09-14T12:53:03.026439+00:00",
    "end_utc": "2026-09-14T12:53:05.736539+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "git",
      "bundle",
      "list-heads",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\candidate.bundle"
    ],
    "start_utc": "2026-09-14T12:53:05.738075+00:00",
    "end_utc": "2026-09-14T12:53:06.212283+00:00",
    "exit": 0,
    "stdout": "7890ead39bb7f14ed44aaae44b0951f098ffe9ac refs/heads/fix/297-enforcement-shape\n",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "mkdir -p /home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3"
    ],
    "start_utc": "2026-09-14T12:53:06.212809+00:00",
    "end_utc": "2026-09-14T12:53:06.473165+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\candidate.bundle",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/candidate.bundle"
    ],
    "start_utc": "2026-09-14T12:53:06.473165+00:00",
    "end_utc": "2026-09-14T12:53:07.013488+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 -"
    ],
    "start_utc": "2026-09-14T12:53:57.438989+00:00",
    "end_utc": "2026-09-14T12:53:58.012767+00:00",
    "exit": 0,
    "stdout": "{\"sha\": \"7890ead39bb7f14ed44aaae44b0951f098ffe9ac\", \"parent\": \"527cd8e8d7ef192892d5630fce10e69a6d811893\", \"tree\": \"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-7890ead3\", \"free_bytes\": 67309170688, \"active\": [], \"bundle_sha256\": \"c9655eb7359a016092328ad27d9baf3de5120a922a882f013beab134d61d511f\"}\n",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\prepare-linux.py",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\run-linux-7890ead3.py",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T12:53:58.013813+00:00",
    "end_utc": "2026-09-14T12:53:58.522388+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      "-r",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/.",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3"
    ],
    "start_utc": "2026-09-14T13:06:12.434914+00:00",
    "end_utc": "2026-09-14T13:06:13.124241+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\finalize-refusal.py",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:06:57.593291+00:00",
    "end_utc": "2026-09-14T13:06:57.977357+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 /home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/finalize-refusal.py"
    ],
    "start_utc": "2026-09-14T13:06:57.977357+00:00",
    "end_utc": "2026-09-14T13:06:58.758499+00:00",
    "exit": 0,
    "stdout": "{\"cleanup_release\": {\"command\": [\"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-304-b8482445/target/debug/xtask\", \"pool-release\", \"--pool\", \"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-7890ead3/target\"], \"start_utc\": \"2026-09-14T13:06:58.584278+00:00\", \"end_utc\": \"2026-09-14T13:06:58.591090+00:00\", \"exit\": 0, \"log_sha256\": \"24760d16e5c406d76a46695e130850ce5b60d2c6c24cbb4b72ec6095441632dd\", \"reason\": \"First bookkeeping release was killed by producer disk-floor guard; safe cleanup-only release, no cargo/test retry.\", \"environment_names\": [\"DBUS_SESSION_BUS_ADDRESS\", \"HOME\", \"LANG\", \"LOGNAME\", \"PATH\", \"PWD\", \"SHELL\", \"SHLVL\", \"SSH_CLIENT\", \"SSH_CONNECTION\", \"USER\", \"XDG_RUNTIME_DIR\", \"XDG_SESSION_CLASS\", \"XDG_SESSION_ID\", \"XDG_SESSION_TYPE\", \"_\"]}, \"final\": {\"utc\": \"2026-09-14T13:06:58.610925+00:00\", \"free_bytes\": 33836695552, \"active\": [], \"owned_survivors\": [], \"source_sha\": \"7890ead39bb7f14ed44aaae44b0951f098ffe9ac\", \"source_status\": \"\", \"own_target_size_bytes\": 33453008024, \"pool_release_exit\": 0, \"source_clean\": true, \"cache_retained\": true}}\n",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      "-r",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/.",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3"
    ],
    "start_utc": "2026-09-14T13:06:58.759017+00:00",
    "end_utc": "2026-09-14T13:06:59.685504+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\classify-closed-targets.py",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:08:39.408943+00:00",
    "end_utc": "2026-09-14T13:08:40.210558+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\classify-closed-targets.py",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:09:06.451566+00:00",
    "end_utc": "2026-09-14T13:09:06.926858+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 -"
    ],
    "start_utc": "2026-09-14T13:09:22.543474+00:00",
    "end_utc": "2026-09-14T13:09:22.792195+00:00",
    "exit": 0,
    "stdout": "{\"heavy-source-line.txt\": \"022492a479c3b37430f2684c0abec9808bb9c3ef21cdcc3c8b5891f8367c030a\", \"pool-release-cleanup-receipt.json\": \"9b73fc94c0d3e886928b73511e71221e2cacfb52bac3171d2c522fdde02892f3\", \"phase-a-inventory.log\": \"88d211e9b96d073594d0c12d881c7626ac4a59f65e866a6c6512da5690d1afbe\", \"preflight-owned-reap.json\": \"cde3ba3d093cd1b1fef0fd092012f0a39b5070ed5f18fde3495b85ea64e0cd8f\", \"temp-boundary.json\": \"8deed8ca703cc42d5dc4b376983d38f564e9b159c248108d7588179e0acb79de\", \"pool-claim.log\": \"0611651ebcc8ac225e0a08320fd9218398bba03628d5b848e60f36681232e4c6\", \"run-linux-7890ead3.py\": \"f4592de4b72597456ea9e184f5e8a1ce5b0867a6bf56bbe7c8001de3741a4ce3\", \"phase-a-inventory-admission.json\": \"c86a15982a8ce547b6fe94e2c1e614eb77989ce0019afb131fc8e62bab00a940\", \"pool-release-disk-samples.json\": \"c40edf54d724604da806ef65742c685ce63b90c5809ab004f32863b4383a8f72\", \"driver-error.json\": \"aafc7aeb9b6fbadb74bc72fbae1424ff939d1607b15e98c03b82679f60d70701\", \"pool-release.log\": \"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855\", \"final-census.json\": \"91273aa99ba5d1fc97379b0f9092b11ea2420277b3c869bef6d6b880773a20b5\", \"driver-receipt.json\": \"66ed0eb46e30d1ad2ad5d7734f3635aa601cee714d727ea0fb6a57200141c19e\", \"launch-linux.py\": \"395807d8b03ce17c6baf11d28a142d5e16721f82682917efa9e467cfb63ab70c\", \"environment.json\": \"45e922f2e4c8c8bebc6f4b448149538d04bad15c8aa91d36f4fafeedb16a7568\", \"driver.log\": \"b4a3c68b15326a126f8f4c64f33c301ffe7f72c4e820875ec273aa00230f1559\", \"temp-setup-disk-samples.json\": \"30a070607db9eaf4cf74e43607712bff35771ae387c9ae4e895fe4be9263b767\", \"classify-closed-targets.py\": \"f1f481efc8c7323a5e0cfcb8967515b62bfabf6ca5f700935ffc956e900a7e5a\", \"temp.env\": \"308a395743ebbf0f69fc420c34df91ee6259d2d140d4274cd004c2283aa64be8\", \"temp-git-probes.jsonl\": \"9f63da6822bea93c1bc95590baadf3589c2b6dd30d5bebed4f6cae2a26cf1d7f\", \"pre-reap-census.json\": \"484c0b46b0d47733570a97749bf828a4a12a66f82910f96b7a9aeb12474c5d36\", \"phase-a-inventory-receipt.json\": \"6dc69a0c3da6e2ffb21409b2a32f002c3a8c0bb7252332ac36f93808a822743e\", \"remote-preflight.json\": \"9e547e11eba22b62aa1aaa4f1e2280a3fa7f1b9ec1b66b6721092d55762217e0\", \"pool-claim-receipt.json\": \"1383de9c5f57159adc95ab885511d3afa06fcb2ef00e499b3877272d93a1c8df\", \"pool-release-cleanup.log\": \"24760d16e5c406d76a46695e130850ce5b60d2c6c24cbb4b72ec6095441632dd\", \"prepare-linux.py\": \"ababd2ff0afe63d988e31716337dc187d52c0eec5c8249e716ecb1d9a94134bc\", \"candidate.bundle\": \"c9655eb7359a016092328ad27d9baf3de5120a922a882f013beab134d61d511f\", \"finalize-refusal.py\": \"91b7a195fd86d6553b6599a3a131140da398198041385a20975bd43764006fae\", \"cleanup-before.json\": \"2b413c174d6200fdc1ad468eb9da3900a21eb73e694c228d9f655f589530ef82\", \"start-admission.json\": \"3be6487e811d5555d94a1e948849479038fc4a8b2049402567f62c9e7c4b1fe6\", \"worktree-setup.json\": \"d8217eec938dbe68c593ff95cd1a397f030e4ee224909064bde0e3fc4a9b1c7f\", \"heavy.txt\": \"875a08c4b8646ac349397f0c3c51137b73530f9e8d037ed3e6bdab5bf1f2844f\", \"temp-setup.log\": \"917e7ebdf47f1971e44eaa5afffaef9c140af0328ff12810704ae043e8628d5e\", \"temp-setup-receipt.json\": \"2ee026b8e1dce4e2d9605ea0b6ccb9009489a260e5ce17c8aae562b4fa7ccc49\", \"phase-a-inventory-disk-samples.json\": \"62bfd3a82f191481680541b120baab5785efa8e4e6118d37b3d35e3289d5d55c\", \"pool-release-receipt.json\": \"424452204fdc82b89dd074db7f3ccec59b8fd4b6dfb5ce79f01db7530183a8b5\", \"pool-claim-disk-samples.json\": \"6d5efa4f2fc986918432c3f823ac17c5ac6860f654d679394c888db145c6110d\"}\n",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/closed-target-classification.json",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3"
    ],
    "start_utc": "2026-09-14T13:10:02.221751+00:00",
    "end_utc": "2026-09-14T13:10:02.726665+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\reclaim-and-prepare-warm.py",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:11:03.747782+00:00",
    "end_utc": "2026-09-14T13:11:04.077011+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 /home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/reclaim-and-prepare-warm.py"
    ],
    "start_utc": "2026-09-14T13:11:04.077532+00:00",
    "end_utc": "2026-09-14T13:11:07.576470+00:00",
    "exit": 0,
    "stdout": "{\"reclaim\": {\"authority\": \"doyle MNRQVISD via Main\", \"path\": \"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-7890ead3/target\", \"start_utc\": \"2026-09-14T13:11:04.606650+00:00\", \"apparent_bytes_before\": 33453008024, \"allocated_bytes_from_classification\": 33472147456, \"free_bytes_before\": 33836564480, \"operation\": \"shutil.rmtree only this validated real target subtree\", \"source_worktree_preserved\": true, \"proof_preserved\": true, \"active_before\": [], \"end_utc\": \"2026-09-14T13:11:07.527636+00:00\", \"free_bytes_after\": 67308711936, \"target_absent\": true, \"measured_free_increase_bytes\": 33472147456}, \"admission\": {\"utc\": \"2026-09-14T13:11:07.575351+00:00\", \"sha\": \"7890ead39bb7f14ed44aaae44b0951f098ffe9ac\", \"source_clean\": true, \"free_bytes\": 67308687360, \"floor_bytes\": 34359738368, \"target\": \"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-S2-527cd8e8/target\", \"target_preserved\": true, \"pool_record_before\": {\"owner_tree\": \"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-S2-527cd8e8\", \"written_by\": \"spt-poolguard\"}, \"producer_started\": false}}\n",
    "stderr": ""
  },
  {
    "command": [
      "git",
      "diff",
      "527cd8e8d7ef192892d5630fce10e69a6d811893",
      "7890ead39bb7f14ed44aaae44b0951f098ffe9ac",
      "--",
      "crates"
    ],
    "start_utc": "2026-09-14T13:12:34.638419+00:00",
    "end_utc": "2026-09-14T13:12:34.909558+00:00",
    "exit": 0,
    "stdout": "diff --git a/crates/spt-daemon/src/bootstrap_firewall/windows.rs b/crates/spt-daemon/src/bootstrap_firewall/windows.rs\nindex 56ff9176..c7cc6786 100644\n--- a/crates/spt-daemon/src/bootstrap_firewall/windows.rs\n+++ b/crates/spt-daemon/src/bootstrap_firewall/windows.rs\n@@ -29,7 +29,7 @@ const RULE_GROUP: &str = \"spt-core bootstrap TCP\";\n /// and `desired_specs` all derive from these constants instead of repeating them.\n const RULE_NAMES: &[&str] = &[RULE_NAME_TAILNET, RULE_NAME_LAN];\n \n-/// The one ActiveStore enforcement code that certifies a rule is in force.\n+/// The positive ActiveStore code, combined with PrimaryStatus and the code-20 veto.\n ///\n /// A NUMBER, NEVER A SPELLING. The host renders this code as a display string, and\n /// which string is a property of the host rather than of the rule: measured on\n@@ -41,19 +41,12 @@ const RULE_NAMES: &[&str] = &[RULE_NAME_TAILNET, RULE_NAME_LAN];\n // [impl->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n const ENFORCEMENT_SUCCESS: u16 = 1;\n \n-/// The COMPLETE certified evidence: exactly one element, the success code.\n-///\n-/// STRICTNESS IS THE REQUIREMENT, not an implementation detail. This is compared with\n-/// `!=` against the whole slice, so `[1, 1]` and `[1, 5]` both refuse. Equality must\n-/// never become membership: a success code sitting beside another code means the host\n-/// reported something else as well. What an array of several codes MEANS is not\n-/// resolved -- the documented values describe individual codes and say nothing about\n-/// how a multi-element array should be read -- so this policy refuses rather than\n-/// interpreting. Empty, unknown and additional values all refuse here, and\n-/// anything the query could not transport as a number never reaches this comparison at\n-/// all -- it fails deserialization and surfaces as a query error instead.\n+/// Run-02 on HFENDULEAM measured OK/[5,1] without a package binding and\n+/// Inactive/[5,20] with `-Package Any`. A multi-profile rule need not have a\n+/// singleton enforcement array: the inactive Domain profile contributes 5.\n // [impl->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n-const ENFORCEMENT_CERTIFIED: [u16; 1] = [ENFORCEMENT_SUCCESS];\n+const ENFORCEMENT_NO_LOCAL_USER: u16 = 20;\n+const PRIMARY_STATUS_OK: u16 = 1;\n \n // Enumerate then compare the exact immutable name: a failed query must not be\n // confused with NetSecurity's non-terminating 'named object not found' error.\n@@ -74,11 +67,11 @@ function Value($object, $name) {\n # verdict compared against \"Full\" -- so the success value itself was refused and no host\n # state could satisfy the arm. The repair is this ACCESSOR, not a cast: casting the\n # adapted value throws on \"Enforced\". CimInstanceProperties is the unadapted CIM view.\n-function RawValue($object, $name) {\n+function RawValue($object, $name, $expectedType = 'UInt16Array') {\n     $property = $object.CimInstanceProperties[$name]\n     if ($null -eq $property) { throw \"ENFORCEMENT_REPRESENTATION_FAULT: NetSecurity omitted required CIM property $name\" }\n-    if ([string]$property.CimType -ne 'UInt16Array') {\n-        throw \"ENFORCEMENT_REPRESENTATION_FAULT: CIM property $name has type $($property.CimType), expected UInt16Array\"\n+    if ([string]$property.CimType -ne $expectedType) {\n+        throw \"ENFORCEMENT_REPRESENTATION_FAULT: CIM property $name has type $($property.CimType), expected $expectedType\"\n     }\n     $property.Value\n }\n@@ -142,12 +135,14 @@ function Describe($rule) {\n     # NOT: it is reported below and decided in Rust, because a policy expressed\n     # only as text handed to another interpreter cannot be unit-tested, which is\n     # how two contradictory amendments coexisted with nothing red (releases#304).\n+    # Run-02 measured an empty Package when New-NetFirewallRule omitted -Package.\n+    # Literal Any is a binding here, unlike the Program filter's unrestricted spelling.\n     $hygiene = (Is $rule 'Enabled' 'True') -and\n         (Is $rule 'Direction' 'Inbound') -and (Is $rule 'Action' 'Allow') -and\n         (Empty $rule 'Platform') -and (Empty $rule 'Owner') -and\n         (Is $port 'RemotePort' 'Any') -and (Is $port 'DynamicTarget' 'Any') -and\n         (Is $address 'LocalAddress' 'Any') -and\n-        (Is $app 'Package' 'Any') -and (Is $service 'Service' 'Any') -and\n+        (Empty $app 'Package') -and (Is $service 'Service' 'Any') -and\n         (Is $interface 'InterfaceAlias' 'Any') -and (Is $type 'InterfaceType' 'Any') -and\n         (Is $security 'Authentication' 'NotRequired') -and (Is $security 'Encryption' 'NotRequired') -and\n         (Is $security 'OverrideBlockRules' 'False') -and\n@@ -185,6 +180,10 @@ function Describe($rule) {\n         }\n         [int]$_\n     })\n+    $primaryStatusRaw = RawValue $rule 'PrimaryStatus' 'UInt16'\n+    if ($null -eq $primaryStatusRaw -or $primaryStatusRaw -isnot [uint16]) {\n+        throw \"ENFORCEMENT_REPRESENTATION_FAULT: invalid raw PrimaryStatus for $name, expected System.UInt16\"\n+    }\n     # WHERE THE EFFECTIVE RULE CAME FROM. Reported, never judged here: the Rust\n     # side decides what counts as persistent. 'Local' names the local persistent\n     # store as this effective rule's source, which is how ONE ActiveStore pass\n@@ -199,6 +198,7 @@ function Describe($rule) {\n         remotes = @(Value $address 'RemoteAddress' | ForEach-Object { [string]$_ })\n         hygiene = [bool]$hygiene\n         enforcement = $enforcement\n+        primaryStatus = [int]$primaryStatusRaw\n     }\n }\n # ONE STORE PASS, NOT TWO. The old query enumerated PersistentStore and\n@@ -259,14 +259,12 @@ struct Rule {\n     /// anything the query cannot transport as a number -- a null, a display\n     /// string, a negative -- fails deserialization and surfaces as a query error\n     /// rather than arriving as a code the verdict would then judge.\n-    ///\n-    /// NO NAME IS ATTACHED TO ANY CODE, here or anywhere downstream. The captured\n-    /// class on the measuring host exposes ValueMap (0..25) with the Values\n-    /// qualifier ABSENT, so no code-to-name mapping is derivable from the host at\n-    /// all -- including for the success code. Naming one would be documentation\n-    /// smuggled in as an observation.\n+    /// PrimaryStatus is transported separately so a success code cannot override\n+    /// the provider reporting the rule inactive.\n     // [impl->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n     enforcement: Vec<u16>,\n+    #[serde(rename = \"primaryStatus\")]\n+    primary_status: u16,\n     /// Which store this EFFECTIVE rule came from, as NetSecurity reports it:\n     /// `Local` for the local persistent store, `GroupPolicy` for domain policy,\n     /// `Dynamic` for a rule that exists only until reboot. Reported here and\n@@ -456,6 +454,8 @@ fn desired_specs(binder_normalized: &str, bound_port: u16, lan: &LanScope) -> Ve\n /// the emitted rule text can be compared against the spec WITHOUT a live\n /// NetSecurity, and an effector whose output nothing can read is how a scope\n /// policy expressed as script text went unchecked in the first place.\n+/// Run-02 isolated `-Package Any` as the argument making the rule inactive.\n+/// Omit the binding; Get-NetFirewallApplicationFilter reports an empty Package.\n // [impl->REQ-WEB-LAN-BOOTSTRAP-FIREWALL]\n fn render_writes(want: &[RuleSpec]) -> String {\n     want.iter()\n@@ -465,7 +465,7 @@ fn render_writes(want: &[RuleSpec]) -> String {\n                 r#\"\n New-NetFirewallRule -PolicyStore PersistentStore -Name '{name}' -DisplayName '{name}' -Group $ruleGroup `\n     -Enabled True -Direction Inbound -Action Allow -Profile {profile} -Protocol TCP -LocalPort {port} `\n-    -RemotePort Any -LocalAddress Any -RemoteAddress {remotes} {program_arg}-Package Any -Service Any `\n+    -RemotePort Any -LocalAddress Any -RemoteAddress {remotes} {program_arg}-Service Any `\n     -InterfaceAlias Any -InterfaceType Any -Authentication NotRequired -Encryption NotRequired `\n     -LocalUser Any -RemoteUser Any -RemoteMachine Any -OverrideBlockRules $false -DynamicTarget Any `\n     -EdgeTraversalPolicy Block -ErrorAction Stop | Out-Null\n@@ -832,11 +832,15 @@ fn decide(state: &Snapshot, expected_program: &str, port: u16) -> Result<bool, S\n     }\n     for rule in &state.active {\n         // [impl->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n-        if rule.enforcement.as_slice() != ENFORCEMENT_CERTIFIED {\n+        if rule.primary_status != PRIMARY_STATUS_OK\n+            || !rule.enforcement.contains(&ENFORCEMENT_SUCCESS)\n+            || rule.enforcement.contains(&ENFORCEMENT_NO_LOCAL_USER)\n+        {\n             return Err(format!(\n-                \"Bootstrap rule {} is configured but ActiveStore enforcement codes are {:?}, \\\n-                 not exactly [{}]\",\n-                rule.name, rule.enforcement, ENFORCEMENT_SUCCESS\n+                \"Bootstrap rule {} is configured but ActiveStore PrimaryStatus is {} and \\\n+                 enforcement codes are {:?}; expected PrimaryStatus {} with code {} present and code {} absent\",\n+                rule.name, rule.primary_status, rule.enforcement, PRIMARY_STATUS_OK,\n+                ENFORCEMENT_SUCCESS, ENFORCEMENT_NO_LOCAL_USER\n             ));\n         }\n     }\n@@ -1029,10 +1033,10 @@ mod tests {\n             \"active\": [\n                 {\"name\": RULE_NAME_TAILNET, \"program\": \"Any\", \"ports\": [\"29470\"],\n                  \"profile\": \"Any\", \"remotes\": [\"100.64.0.0/10\"], \"hygiene\": true,\n-                 \"enforcement\": [1], \"sourceType\": \"Local\"},\n+                 \"enforcement\": [1], \"primaryStatus\": 1, \"sourceType\": \"Local\"},\n                 {\"name\": RULE_NAME_LAN, \"program\": \"Any\", \"ports\": [\"29470\"],\n                  \"profile\": \"Private,Domain\", \"remotes\": [\"192.168.1.0/24\"],\n-                 \"hygiene\": true, \"enforcement\": [1], \"sourceType\": \"Local\"}\n+                 \"hygiene\": true, \"enforcement\": [5, 1], \"primaryStatus\": 1, \"sourceType\": \"Local\"}\n             ],\n             \"addresses\": addresses\n         }).to_string();\n@@ -1157,6 +1161,7 @@ mod tests {\n             remotes: remotes.iter().map(|r| r.to_string()).collect(),\n             hygiene: true,\n             enforcement: vec![ENFORCEMENT_SUCCESS],\n+            primary_status: PRIMARY_STATUS_OK,\n             source_type: \"Local\".to_string(),\n         }\n     }\n@@ -1658,6 +1663,33 @@ mod tests {\n         );\n     }\n \n+    /// The run-02 scratch control isolates `-Package Any`: adding it to an\n+    /// otherwise identical rule changes OK/[5,1] to Inactive/[5,20].\n+    /// An unrestricted bootstrap rule must omit that package binding entirely.\n+    // [unit->REQ-WEB-LAN-BOOTSTRAP-FIREWALL]\n+    #[test]\n+    fn unrestricted_rules_omit_the_package_parameter() {\n+        let want = desired_specs(\"c:/spt/spt.exe\", 5470, &one_lan());\n+        let rendered = render_writes(&want);\n+        let mut calls = rendered.split(\"New-NetFirewallRule\").skip(1);\n+        for spec in &want {\n+            let call = calls\n+                .next()\n+                .expect(\"each admission half must have a create call\");\n+            assert!(\n+                call.contains(spec.name),\n+                \"the assertion must inspect the named half\"\n+            );\n+            assert!(\n+                !call\n+                    .split_ascii_whitespace()\n+                    .any(|argument| argument == \"-Package\"),\n+                \"{} must not acquire the package restriction measured to disable admission: {call}\",\n+                spec.name\n+            );\n+        }\n+    }\n+\n     // ---- observed-spelling regression cells (hertz, releases#304 W2) ----\n     //\n     // Appended onto FOLD-4 (10d18b7f). Boundary agreed with todlando: everything\n@@ -1719,23 +1751,46 @@ mod tests {\n         }\n     }\n \n-    /// H2 \u00e2\u20ac\u201d AN UNENFORCED RULE IS STILL REFUSED, AFTER THE PAIR MATCHES.\n-    ///\n-    /// Enforcement is decided at its own `decide` arm, on a field the FOLD-4\n-    /// normalizers never see, and it returns `Err` rather than `Ok(false)`. No\n-    /// sibling asserts it: the source-store arm has :1136, this one had nothing.\n-    /// It exists so a comparison repair cannot fold enforcement into a WEAKER\n-    /// comparison \u00e2\u20ac\u201d a rule that is configured but not in force must stay a LOUD\n-    /// refusal and not a quiet non-match. That intent is unchanged; only its\n-    /// mechanism moved. It once guarded against folding enforcement into STRING\n-    /// handling, because the field was Vec<String>; the field is now Vec<u16> and\n-    /// the live risk is equality silently becoming MEMBERSHIP, so the cases below\n-    /// include a repeated success code and a success code beside a non-success one.\n-    ///\n-    /// No case here asserts a NAME for any code. The host that produced the A7\n-    /// capture rendered its codes as display text and exposed no Values qualifier,\n-    /// so no code-to-name mapping is derivable from it; what makes 1 the success\n-    /// code is the documented specification, asserted nowhere but in the constant.\n+    // [unit->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n+    #[test]\n+    fn an_ok_multi_profile_rule_with_codes_5_and_1_is_enforced() {\n+        let want = desired_specs(\"c:/spt/spt.exe\", 29470, &one_lan());\n+        let mut active = reconciled_store(&want);\n+        active[1].enforcement = vec![5, 1];\n+        let state = Snapshot {\n+            active,\n+            addresses: one_lan_census(),\n+        };\n+        assert_eq!(decide(&state, \"c:/spt/spt.exe\", 29470), Ok(true));\n+    }\n+\n+    // [unit->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n+    #[test]\n+    fn an_inactive_rule_with_codes_5_and_20_is_refused() {\n+        let want = desired_specs(\"c:/spt/spt.exe\", 29470, &one_lan());\n+        let mut active = reconciled_store(&want);\n+        active[1].primary_status = 2;\n+        active[1].enforcement = vec![5, 20];\n+        let state = Snapshot {\n+            active,\n+            addresses: one_lan_census(),\n+        };\n+        assert!(decide(&state, \"c:/spt/spt.exe\", 29470).is_err());\n+    }\n+\n+    // [unit->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n+    #[test]\n+    fn an_ok_rule_with_code_1_is_enforced() {\n+        let want = desired_specs(\"c:/spt/spt.exe\", 29470, &one_lan());\n+        let state = Snapshot {\n+            active: reconciled_store(&want),\n+            addresses: one_lan_census(),\n+        };\n+        assert_eq!(decide(&state, \"c:/spt/spt.exe\", 29470), Ok(true));\n+    }\n+\n+    /// A matching rule still needs positive enforcement and no code-20 veto.\n+    /// Null/type faults remain a separate query/deserialization failure.\n     // [unit->REQ-WEB-LAN-BOOTSTRAP-FIREWALL]\n     #[test]\n     fn an_unenforced_rule_is_refused_loudly_after_the_pair_matches() {\n@@ -1751,28 +1806,15 @@ mod tests {\n             \"control: the unperturbed snapshot decides reconciled\"\n         );\n \n-        // Every case is a REFUSAL, and the list is the requirement's acceptance\n-        // table written as literals: [0], [2], [5], [20], [1,1], [1,5] and [].\n-        // [5,20] is carried beyond that list because two non-success codes is a\n-        // distinct shape from one. The arms that matter after the repair are the\n-        // REPEATED success code and the success code accompanied by a non-success\n-        // one \u00e2\u20ac\u201d they fail only if `as_slice() != ENFORCEMENT_CERTIFIED` is ever\n-        // softened into \"contains the success code\".\n-        //\n-        // WHAT THIS FILE CANNOT COVER, so that it is not read as covered: the\n-        // requirement's null arms and its distinguishable REPRESENTATION FAULT\n-        // live in the PowerShell query, before any JSON exists. Their Rust-side\n-        // shadow is the deserialization cell below \u00e2\u20ac\u201d a null element and a null\n-        // field both refuse there; the faults themselves are the\n-        // extraction-boundary exercise's subject.\n+        // An empty or non-success array cannot certify admission. Code 20 vetoes\n+        // even an otherwise positive array; inactive-profile code 5 alone is not success.\n         // [unit->REQ-BOOTSTRAP-FIREWALL-ENFORCEMENT-CODES]\n         for status in [\n             vec![0u16],\n             vec![2u16],\n             vec![5u16],\n             vec![20u16],\n-            vec![ENFORCEMENT_SUCCESS, ENFORCEMENT_SUCCESS],\n-            vec![ENFORCEMENT_SUCCESS, 5u16],\n+            vec![ENFORCEMENT_SUCCESS, ENFORCEMENT_NO_LOCAL_USER],\n             vec![5u16, 20u16],\n             Vec::new(),\n         ] {\n@@ -1787,6 +1829,16 @@ mod tests {\n                  (status {status:?}): {refusal}\"\n             );\n         }\n+        let mut inactive = effective;\n+        inactive[0].primary_status = 2;\n+        let state = Snapshot {\n+            active: inactive,\n+            addresses: one_lan_census(),\n+        };\n+        assert!(\n+            decide(&state, \"c:/spt/spt.exe\", 29470).is_err(),\n+            \"a success code cannot override non-OK PrimaryStatus\"\n+        );\n     }\n \n \n@@ -1807,7 +1859,7 @@ mod tests {\n             format!(\n                 r#\"{{\"name\":\"n\",\"program\":\"Any\",\"ports\":[\"29470\"],\"profile\":\"Any\",\n                    \"remotes\":[\"Any\"],\"hygiene\":true,\"enforcement\":{enforcement},\n-                   \"sourceType\":\"Local\"}}\"#\n+                   \"primaryStatus\":1,\"sourceType\":\"Local\"}}\"#\n             )\n         }\n \n@@ -1859,14 +1911,12 @@ mod tests {\n     //     filters plus DynamicTarget and the Platform/Owner emptiness checks. Those\n     //     cmdlets were never run, so the inputs do not exist. `true` here ISOLATES\n     //     the representation axes; it does not assert what the host would report.\n-    //   - `enforcement`: SYNTHETIC. The capture reads {ProfileInactive, NoLocalUser} in\n-    //     ActiveStore. Those are the host\u00e2\u20ac\u2122s ADAPTED DISPLAY NAMES, not codes, and THE\n-    //     BOOTSTRAP PAIR\u00e2\u20ac\u2122S NUMERIC VALUES REMAIN UNKNOWN: the raw UInt16 1 was measured\n-    //     on a SEPARATE, pre-existing 5470 rule, not on either bootstrap rule. So nothing\n-    //     here may be read as \"the pair really carried 1 and only rendered badly\".\n-    //     ENFORCEMENT_SUCCESS is used because it keeps these cells about the COMPARISON\n-    //     axes; it asserts nothing about what that host would have reported. The captured\n-    //     value is a SEPARATE FINDING, reported to doyle, not smuggled into a fixture.\n+    //   - `enforcement` and `primary_status`: the September 12 display-name capture\n+    //     was not a successful pair. Window 6 subsequently measured its raw [5,20]\n+    //     refusal. These comparison fixtures now use OK/[5,1], measured on the\n+    //     Private+Domain scratch rule without -Package in run-02 (2026-09-14).\n+    //     It is deliberately COMPOSED evidence: not a new capture of these named\n+    //     bootstrap rules, and not a measured all-profile/tailnet array.\n     //   - the port: SYNTHETIC. Its captured value is not in hand. The port axis is not an\n     //     equivalence axis and R5 covers its drift, so the spec's port is used.\n \n@@ -1880,7 +1930,8 @@ mod tests {\n             profile: \"Any\".to_string(),                              // captured\n             remotes: vec![\"100.64.0.0/255.192.0.0\".to_string()],     // captured \u00e2\u20ac\u201d MASK form\n             hygiene: true,                                           // SYNTHETIC, not captured \u00e2\u20ac\u201d see above\n-            enforcement: vec![ENFORCEMENT_SUCCESS],                   // SYNTHETIC, not captured \u00e2\u20ac\u201d see above\n+            enforcement: vec![5, ENFORCEMENT_SUCCESS], // run-02 enforced-shape composition\n+            primary_status: PRIMARY_STATUS_OK,\n             source_type: \"Local\".to_string(),                        // captured\n         }\n     }\n@@ -1895,7 +1946,8 @@ mod tests {\n             profile: \"Domain, Private\".to_string(),                  // captured\n             remotes: vec![\"192.168.1.0/255.255.255.0\".to_string()],  // captured \u00e2\u20ac\u201d MASK form\n             hygiene: true,                                           // SYNTHETIC, not captured \u00e2\u20ac\u201d see above\n-            enforcement: vec![ENFORCEMENT_SUCCESS],                   // SYNTHETIC, not captured \u00e2\u20ac\u201d see above\n+            enforcement: vec![5, ENFORCEMENT_SUCCESS], // run-02 enforced-shape composition\n+            primary_status: PRIMARY_STATUS_OK,\n             source_type: \"Local\".to_string(),                        // captured\n         }\n     }\n",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\linux-baseline-names.json",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\fix2-source-delta.diff",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\candidate-bootstrap-firewall-module.txt",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\cold-void-receipt.json",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\cold-void-receipt.txt",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:14:12.086206+00:00",
    "end_utc": "2026-09-14T13:14:12.789810+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      "-r",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\full49-warm",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:14:12.790855+00:00",
    "end_utc": "2026-09-14T13:14:13.113574+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 /home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/full49-warm/prepare-full49.py"
    ],
    "start_utc": "2026-09-14T13:14:13.115613+00:00",
    "end_utc": "2026-09-14T13:14:13.567160+00:00",
    "exit": 0,
    "stdout": "{\"sha\": \"7890ead39bb7f14ed44aaae44b0951f098ffe9ac\", \"utc\": \"2026-09-14T13:14:13.565438+00:00\", \"free_bytes\": 67308113920, \"floor_bytes\": 34359738368, \"source_clean\": true, \"target\": \"/home/reavus/projects/spt-core/spt-core/.worktrees/consumer-linux-49a08a07/target\", \"target_preserved\": true, \"active\": [], \"producer_started\": false}\n",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/full49-warm/phase-a*",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\full49-warm"
    ],
    "start_utc": "2026-09-14T13:16:00.542421+00:00",
    "end_utc": "2026-09-14T13:16:01.389436+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 -"
    ],
    "start_utc": "2026-09-14T13:19:29.805554+00:00",
    "end_utc": "2026-09-14T13:19:30.227169+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\linux-baseline-names.json",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\platform-reconciliation.json",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/"
    ],
    "start_utc": "2026-09-14T13:19:30.229192+00:00",
    "end_utc": "2026-09-14T13:19:30.818676+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\full49-warm\\phase-a-inventory-names.json",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3\\full49-warm\\phase-b-inventory-names.json",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/full49-warm/"
    ],
    "start_utc": "2026-09-14T13:19:30.820180+00:00",
    "end_utc": "2026-09-14T13:19:31.385212+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "scp",
      "-r",
      "reavus@kitsubito:/home/reavus/projects/spt-core/spt-core/.spt/preserved/304-handoff/consumer-linux-7890ead3/.",
      ".spt\\preserved\\304-handoff\\consumer-linux-7890ead3"
    ],
    "start_utc": "2026-09-14T13:35:20.783893+00:00",
    "end_utc": "2026-09-14T13:35:23.521413+00:00",
    "exit": 0,
    "stdout": "",
    "stderr": ""
  },
  {
    "command": [
      "ssh",
      "reavus@kitsubito",
      "python3 -"
    ],
    "start_utc": "2026-09-14T13:35:42.512159+00:00",
    "end_utc": "2026-09-14T13:35:42.814066+00:00",
    "exit": 0,
    "stdout": "{\"heavy-source-line.txt\": \"022492a479c3b37430f2684c0abec9808bb9c3ef21cdcc3c8b5891f8367c030a\", \"platform-reconciliation.json\": \"c7143940ee09902bdfb1847ad1a0e484d22fb3e69b9964b7ca405c90bc72559d\", \"pool-release-cleanup-receipt.json\": \"9b73fc94c0d3e886928b73511e71221e2cacfb52bac3171d2c522fdde02892f3\", \"phase-a-inventory.log\": \"88d211e9b96d073594d0c12d881c7626ac4a59f65e866a6c6512da5690d1afbe\", \"preflight-owned-reap.json\": \"cde3ba3d093cd1b1fef0fd092012f0a39b5070ed5f18fde3495b85ea64e0cd8f\", \"temp-boundary.json\": \"8deed8ca703cc42d5dc4b376983d38f564e9b159c248108d7588179e0acb79de\", \"pool-claim.log\": \"0611651ebcc8ac225e0a08320fd9218398bba03628d5b848e60f36681232e4c6\", \"cold-void-receipt.txt\": \"8d09137a5272c5d122b994568a9dae093155e6db912403231a849ac52e79f161\", \"linux-baseline-names-pre-fingerprint-correction.json\": \"707047596e17daf7d605f197a119b2f29d780aa8ebe5988060f979a1ef577b23\", \"candidate-bootstrap-firewall-module.txt\": \"938c1bf246b0b8e615a13c1bfd6a1174c28787de6f99b48bdb5c450404cad596\", \"run-linux-7890ead3.py\": \"f4592de4b72597456ea9e184f5e8a1ce5b0867a6bf56bbe7c8001de3741a4ce3\", \"phase-a-inventory-admission.json\": \"c86a15982a8ce547b6fe94e2c1e614eb77989ce0019afb131fc8e62bab00a940\", \"fix2-source-delta.diff\": \"8315a085bf7fb2ba59c0e400c9703d192333aa3b0296d4f2b83719dda9b4ef63\", \"pool-release-disk-samples.json\": \"c40edf54d724604da806ef65742c685ce63b90c5809ab004f32863b4383a8f72\", \"driver-error.json\": \"aafc7aeb9b6fbadb74bc72fbae1424ff939d1607b15e98c03b82679f60d70701\", \"pool-release.log\": \"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855\", \"final-census.json\": \"91273aa99ba5d1fc97379b0f9092b11ea2420277b3c869bef6d6b880773a20b5\", \"reclaim-and-prepare-warm.py\": \"57ac4787aa7543ca5cf59b54fed72c6ee70143f31d66af927985533bb24ba48e\", \"driver-receipt.json\": \"66ed0eb46e30d1ad2ad5d7734f3635aa601cee714d727ea0fb6a57200141c19e\", \"launch-linux.py\": \"395807d8b03ce17c6baf11d28a142d5e16721f82682917efa9e467cfb63ab70c\", \"environment.json\": \"45e922f2e4c8c8bebc6f4b448149538d04bad15c8aa91d36f4fafeedb16a7568\", \"driver.log\": \"b4a3c68b15326a126f8f4c64f33c301ffe7f72c4e820875ec273aa00230f1559\", \"approved-reclaim-before.json\": \"63484e4c6d8fcfac349de2121787160f9abb45f6ec7a5ff69f6064e2ece580c3\", \"approved-reclaim.json\": \"9be701b25a675051b7254455736e9b8a781a18291ff5bf6dffad22cc5d383705\", \"temp-setup-disk-samples.json\": \"30a070607db9eaf4cf74e43607712bff35771ae387c9ae4e895fe4be9263b767\", \"classify-closed-targets.py\": \"f1f481efc8c7323a5e0cfcb8967515b62bfabf6ca5f700935ffc956e900a7e5a\", \"temp.env\": \"308a395743ebbf0f69fc420c34df91ee6259d2d140d4274cd004c2283aa64be8\", \"temp-git-probes.jsonl\": \"9f63da6822bea93c1bc95590baadf3589c2b6dd30d5bebed4f6cae2a26cf1d7f\", \"pre-reap-census.json\": \"484c0b46b0d47733570a97749bf828a4a12a66f82910f96b7a9aeb12474c5d36\", \"phase-a-inventory-receipt.json\": \"6dc69a0c3da6e2ffb21409b2a32f002c3a8c0bb7252332ac36f93808a822743e\", \"remote-preflight.json\": \"9e547e11eba22b62aa1aaa4f1e2280a3fa7f1b9ec1b66b6721092d55762217e0\", \"pool-claim-receipt.json\": \"1383de9c5f57159adc95ab885511d3afa06fcb2ef00e499b3877272d93a1c8df\", \"pool-release-cleanup.log\": \"24760d16e5c406d76a46695e130850ce5b60d2c6c24cbb4b72ec6095441632dd\", \"prepare-linux.py\": \"ababd2ff0afe63d988e31716337dc187d52c0eec5c8249e716ecb1d9a94134bc\", \"candidate.bundle\": \"c9655eb7359a016092328ad27d9baf3de5120a922a882f013beab134d61d511f\", \"finalize-refusal.py\": \"91b7a195fd86d6553b6599a3a131140da398198041385a20975bd43764006fae\", \"cleanup-before.json\": \"2b413c174d6200fdc1ad468eb9da3900a21eb73e694c228d9f655f589530ef82\", \"start-admission.json\": \"3be6487e811d5555d94a1e948849479038fc4a8b2049402567f62c9e7c4b1fe6\", \"worktree-setup.json\": \"d8217eec938dbe68c593ff95cd1a397f030e4ee224909064bde0e3fc4a9b1c7f\", \"heavy.txt\": \"875a08c4b8646ac349397f0c3c51137b73530f9e8d037ed3e6bdab5bf1f2844f\", \"temp-setup.log\": \"917e7ebdf47f1971e44eaa5afffaef9c140af0328ff12810704ae043e8628d5e\", \"closed-target-classification.json\": \"7197e56e7074cd773650bec4ec062130c3ef585e73474e3a31074c6c8a8c7e32\", \"temp-setup-receipt.json\": \"2ee026b8e1dce4e2d9605ea0b6ccb9009489a260e5ce17c8aae562b4fa7ccc49\", \"linux-baseline-names.json\": \"b8eba0599b39ff1072618d0ce70767d7f180b39e762faa2e505c2446f7776f59\", \"phase-a-inventory-disk-samples.json\": \"62bfd3a82f191481680541b120baab5785efa8e4e6118d37b3d35e3289d5d55c\", \"cold-void-receipt.json\": \"0946b11288b43ea127e689615afa5b7a9534ae4dcfd0ceaeb7da9624d6fdbddb\", \"pool-release-receipt.json\": \"424452204fdc82b89dd074db7f3ccec59b8fd4b6dfb5ce79f01db7530183a8b5\", \"pool-claim-disk-samples.json\": \"6d5efa4f2fc986918432c3f823ac17c5ac6860f654d679394c888db145c6110d\", \"warm-attempt/fresh-admission.json\": \"bac3b12ae741fec257a53f0d660489d342ca5241c41b3a231310a592425ea0f4\", \"warm-attempt/takeover-setup.json\": \"051fd711da75db567e4e466892c2d16fef1f657fce0eed18d1a2c5dcbfe856fb\", \"full49-warm/heavy-source-line.txt\": \"022492a479c3b37430f2684c0abec9808bb9c3ef21cdcc3c8b5891f8367c030a\", \"full49-warm/phase-a-disk-samples.json\": \"f9ebccba3c1dd5149e570280301f05b49eef4e0ca85585ef52868b12182d1b09\", \"full49-warm/phase-a-inventory.log\": \"e17936b1ca876974cd2db5d23d36157bf008c2f61a684a737beff48e34297861\", \"full49-warm/preflight-owned-reap.json\": \"30cba5d80338cec0751de1105f24bf00482d8a29ff9ad6fad6ae7b13e369094b\", \"full49-warm/temp-boundary.json\": \"e62ed4af9d018f8cb51d0cd5d1c09c9fa1baf6587fc36101f9f75b6eeb57ce69\", \"full49-warm/phase-a-inventory-names.json\": \"520b74804676b8315f86ecf84daa6789bf2a4229154bba0691f8028c9c1c7cef\", \"full49-warm/pool-claim.log\": \"d60979e3e8b9b56527c9fde611354ab9804cfa665add7cb55aa3dae1d82dab54\", \"full49-warm/phase-b-inventory-disk-samples.json\": \"6d1656232031530a41afd65a7e92eb1916cbe295076ec6ed9baa8a7b8abc3b53\", \"full49-warm/run-linux-7890ead3.py\": \"4368147d73439bcf1d27dbd727a9c3e9a9c139d643719c4edc6749ee483cc86d\", \"full49-warm/phase-a-inventory-admission.json\": \"ad3639817a996654b009f7e79d2ded9ed0aba4f88ad624d3ffd914f4caffb02c\", \"full49-warm/pool-release-disk-samples.json\": \"645bbb8b09906db2233271ef2f50ed74a3b0531e101830b6d600b420208c59b2\", \"full49-warm/phase-a-admission.json\": \"7c8fe25a7f4eb4283d8be215820e91cf8b37e298e884cb0fb71551c333253724\", \"full49-warm/pool-release.log\": \"0260adbe57b59b104b7294cdde3f9250c48520f615699ed03ce607f9203acab1\", \"full49-warm/final-census.json\": \"fabafb874287f7e3bcd2d8c5584564089be46ee6555af5c82aa28b45f6875fae\", \"full49-warm/driver-receipt.json\": \"dc1191df7394f60f56405db7008afedab981857c857acc7df8a632aab34a90ed\", \"full49-warm/launch-linux.py\": \"4b0fb1fae097317592856f799616a66abbbeddd4a39991679bcd8056252a43e3\", \"full49-warm/phase-b-admission.json\": \"464f757fd1801cb36c9b0b709cb136f366a7e38718ad2a3b9836f6ee1452bef7\", \"full49-warm/environment.json\": \"2194d744369b16428e9e0fee26b720fcf3387d7f03ad8926f4185746eeeef5e1\", \"full49-warm/driver.log\": \"a135d1e5671081435cbf86cd57e4c3c2d51b49f44989d8f91a9e2516ed52aeef\", \"full49-warm/phase-a-receipt.json\": \"373955a6676cc959ac5588c58ae8a26e869e3799c12928f9fb2dae5ff86d97fb\", \"full49-warm/temp-setup-disk-samples.json\": \"fa6f1137ad7f7f5bfcf36448d68aa8f736a8fe451c6c7161166229eab63a8b5e\", \"full49-warm/phase-b-inventory-receipt.json\": \"dd68e1e5b20c4473bd75aee1ec3a89e061a3d3ec1f92c4a8461121024208f065\", \"full49-warm/temp.env\": \"c8115da2b73c81d4e4a4b2bc8f57c6b3e7fbef4f36a20f06e26a9a5e762fba04\", \"full49-warm/prepare-full49.py\": \"ef666969399b5aeda83de931b8f621635e55b3f9a53ee30deceb7fb8071b5763\", \"full49-warm/temp-git-probes.jsonl\": \"9ed2b1fd38a497fc6429d48648c31e04b4a47b0154ae8274463327652560dd74\", \"full49-warm/pre-reap-census.json\": \"50bf15bd8773f0211d3c8dbf91f2d20d7eb79af55f58ff5210326bc53a403d83\", \"full49-warm/phase-b-receipt.json\": \"27bee7a4f3be022ed46c847268f9fef755378f0634d17ac92b0ccffee76dbcbe\", \"full49-warm/phase-a-inventory-receipt.json\": \"28843fcc36ca3c3830bfa807c3a0801eff8207dd86259aaf2f3438f754082294\", \"full49-warm/phase-b-disk-samples.json\": \"d25ff564dd4701a8b110946f0f8169cc6cfbab262777c93935c24556742ee6de\", \"full49-warm/phase-b-inventory-names-pre-fingerprint-correction.json\": \"d4e5a38a05cc067ae17b4a02c5467c91949215ea83016fab2e2cb532bf481888\", \"full49-warm/phase-b-owned-reap.json\": \"30cba5d80338cec0751de1105f24bf00482d8a29ff9ad6fad6ae7b13e369094b\", \"full49-warm/pool-claim-receipt.json\": \"3271cfb9f15361c9ce25b781ab0cd8ca547a03ab2f872037fff46b9e7b20ee01\", \"full49-warm/phase-b-inventory-names.json\": \"2dc7862a8462cead6916798b90705dbbb9b918177b6ebf16473b008576b87430\", \"full49-warm/phases.json\": \"3ad5dfb390bef03ca0da98fd977d08b864384512a54187221e9f3d09b132b2f9\", \"full49-warm/fresh-admission.json\": \"45410bc5ae7d5117ea3c543284bd7903e7e9c9de1038a7ac5eefea8e51e6f8f5\", \"full49-warm/phase-b-inventory.log\": \"c90abe8c674a0618d482f89990d4926e0935aedfe783a0154da6b59f695ff4a4\", \"full49-warm/start-admission.json\": \"86e1bfd379722cc089bb2899b1c2ec7f4ac4f06b69dbb204519c7d78834f3164\", \"full49-warm/phase-a-inventory-names-pre-fingerprint-correction.json\": \"e36be4881d18d9e7ab15743fa67ea2cde4c8707e2782ad63162f2d05dcb91691\", \"full49-warm/takeover-setup.json\": \"fbfcf41a4a831c25af3d3feef330f6f36b3a2ea80181ef46886543bb14d71b49\", \"full49-warm/heavy.txt\": \"875a08c4b8646ac349397f0c3c51137b73530f9e8d037ed3e6bdab5bf1f2844f\", \"full49-warm/temp-setup.log\": \"4e41c2fefdb7de06b9a37e0fc024eab35cdd0916d13bbb5d68a43a5fa1b72a18\", \"full49-warm/phase-b-inventory-admission.json\": \"f73afa9b1357f4f4f1fc9382a0a88f44948a2d7bf71e001bd2ba9c884d575e5f\", \"full49-warm/receipt.json\": \"7efb739a6d5b325f1775afa31b5768c0a870876f3cb400c023490d4cfbe65e4b\", \"full49-warm/temp-setup-receipt.json\": \"9bbc819ae98355ee6844ae4a759ecffe335d694da1432ea950f321e5ef179080\", \"full49-warm/phase-a-inventory-disk-samples.json\": \"f2ce49b094e6c3e496f9e8d9523e7b81952438e9ec67e02f4d49f275b553b374\", \"full49-warm/pool-release-receipt.json\": \"e638dfa6b6eb47e1bd15f71027871703dce2e58ea489793c2751ad4f51bc7115\", \"full49-warm/phase-a.log\": \"c5c11eac7ba8bccf106425f070215e40021fbb83ddcd6f01b16491b8e855b627\", \"full49-warm/pool-claim-disk-samples.json\": \"105f28cb0039a5510d9c6dbf9c68c49cbd680a2ac924833d870088fcf0810c55\", \"full49-warm/phase-a-owned-reap.json\": \"f591246e78318ec574b84a51ce5114fc45c4d0f8a1aa538bda4ce91d46ca8a8d\", \"full49-warm/phase-b.log\": \"a3c49e8b53ff740552768e571f616531182f7f7f921d0e8ca14b1c6b06686770\"}\n",
    "stderr": ""
  }
]
