{
  "review_only": true,
  "edits_or_execution": "None.",
  "locking_proposal": "Reuse public spt_store::wtlock::acquire_with_bound under a securely root-owned fixed /run/spt-bootstrap-firewall directory and constant / key; hold the RAII guard across the entire privileged reconcile/cleanup transaction including final verification. Existing implementation provides bounded waiting, stable sentinel and crash release. Never key by home/binder/port or unlink the sentinel.",
  "remaining_race": "This serializes bootstrap helpers, not external administrator UFW commands; numbered UFW deletion retains an external TOCTOU despite immediate reinspection.",
  "firewalld_cleanup_consequence": "Confirmed: stop clears both scopes and deletes the permanent owned policy; inert runtime policy remains. Subsequent bootstrap intentionally requires operator reprovisioning because the permanent ownership record is gone, and after reload the runtime policy is also absent. Retaining reusable inert scaffolding would require explicitly relaxing cleanup/is_clean from resource absence to admission absence."
}