---
name: a-fixed-probe-window-without-a-rendezvous-mints-a-false-box-red
description: A cross-host probe with a fixed symmetric window (A listens N s, B sends N s) and no rendezvous reds as the box fault it hunts whenever the peer starts late — measured 2026-09-09 (hertz dir 2 attempt 1: cargo startup on the Windows sender alone exceeded a 10 s window, text said 'BOX rule, not rig')
metadata:
  type: feedback
---

**Measured 2026-09-09 13:14Z (hertz, IR-89 in-situ, d882297f):** A on kitsubito listened 10 s, B on
hfenduleam sent 10 s behind `cargo test`; A red `INBOUND_BLOCKED` at 10.24 s. Re-run with direct
binaries 13:16Z: datagram 1 in 1.93 s, green. Nothing on the wire changed. Same session, the 7509 arm
(port outside the ACL grant) red identically at 10.21 s — the REAL drop and the LATE PEER print the
same text.

**Why:** a step boundary orders steps on ONE host; the last cross-host rendezvous is whatever
converged last (the ladder's final rung), and after it each half pays wrap scripts + a cargo
invocation + Defender first-touch, seconds to tens of seconds on Windows. A failure text that names
two layers while a third cause (peer not up) produces the identical silence is the defect class the
probe was written to catch, reproduced inside the guard.

**How to apply:** a probe window is bounded by the PEER'S PROVEN PRESENCE, never a fixed span:
listen up to the rig's budget and stop on first arrival; ACK for the fast green; a beacon over the
direction that is known open so the sender's short clock starts at proof the receiver is up; and
give "no beacon" its own outcome name. Before believing any cold-inbound red, ask whether the peer
was up inside the window — the box facts (netmap source list, host firewall state) are the
cross-check. Kin: [[windows-runner-firewall-drops-cold-inbound-to-rule-less-test-exes]],
[[a-barrier-cannot-ride-a-carrier-its-sender-outlives]].
