[{"body":"Operator reports enlyzeam serves /install locally after spt serve lan --bootstrap, but other machines cannot reach it; access is required over Tailscale.\n\nSource at f020c4c7: installer/install.ps1:175-192 and spt-daemon/src/firewall.rs:334-354 create only an executable-scoped inbound UDP rule. lanhost.rs:660-735 binds TCP 0.0.0.0 (default 5470) without firewall reconciliation. Local bind success is not remote reachability. The missing TCP rule is verified; enlyzeam's effective blocking layer is not yet measured.\n\nClose this gap in the bootstrap-start process: account for the actual selected TCP port and running binder; provide narrowly scoped Windows admission usable over Tailscale, including Public-profile interfaces, without opening arbitrary public ingress. If elevation/policy prevents repair, report the unmet condition and exact scoped elevated command; never imply end-to-end reachability from bind or rule creation. Distinguish Windows policy from Tailscale ACL/grants (do not modify tailnet policy automatically). Define rule ownership/lifecycle for stop/restart and repeated starts; preserve unrelated rules and loopback-only docs.\n\nAcceptance: remote tailnet IPv4 client can GET /install with host rule and tailnet policy admitting it; non-elevated/blocked policy has actionable diagnostics; port override honored; repeated start/stop is safe. Verify from a second machine, not localhost. Bootstrap currently binds IPv4 only. Existing UDP admission must remain intact.\n\n---\nRequester: doyle","number":297,"title":"Windows serve lan --bootstrap leaves TCP listener inaccessible over Tailscale","url":"https://github.com/BigscreenVR/spt-bs-releases/issues/297"}]
