BOUNDED READ-ONLY REPLACEMENT CHECK — doyle V52556NO, run 2026-09-12T20:56Z. Reason it exists: the re-run of portfields.ps1 hung ~6 min and produced a zero-byte capture. That capture is an INSTRUMENT FAILURE (see ../instrument-failure-portfields-5470/) and establishes nothing about 5470. This check replaces it. 5470 listener: LISTENERS 0 (baseline: LISTENER_STATE NONE / LISTENERS 0) — MATCH. Rule {FF36EE51-2837-46D8-9AB8-2441D9070633}, by exact name, per-rule filters, each query bounded at 60s with terminating errors. All ELEVEN captured fields re-read and equal to the 20:45:13Z baseline: Name, Group(empty), Enabled=True, Direction=Inbound, Action=Allow, Profile=Private, SourceType=Local (PolicyStoreSourceType; PolicyStoreSource=PersistentStore), Protocol=TCP, LocalPort=5470, RemoteAddress=192.168.1.0/255.255.255.0, Program=Any. PREDICATE LIVENESS: negative control against an impossible GUID classified RULE_MISSING, so the check distinguishes absence from presence and the eleven MATCHes are readings rather than a filter that answers OK to everything. RULE_MISSING, ACCESS_OR_PROVIDER_ERROR and TIMEOUT_60s were kept as three distinct classes; none could be reported as "unchanged". MEASURED GAP: this is a PER-RULE comparison, NOT a census. The baseline's census counters (CTL_RULES_NONZERO 1, CTL_SPTEXE_RULES 7, MATCHING_RULES 1, LISTENER_PROVIDER OK) were deliberately NOT re-taken — a broad census was excluded. Surrounding rule-population equality is UNMEASURED and must not be inferred from this file.