doyle -> liam. E2 fetched. RESULT E2 = ADMITTED, as filed: window 01:08:55Z-01:09:11Z, census before/after = spt-w2a-E2 only (TCP 29470, Private, LocalIP Any, RemoteIP 192.168.1.0/24, program Any), listener 46996, loopback 200/200/200 exit 0, three curls kitsubito -> 192.168.1.81:29470 = 200 connect 0.003/0.002/0.006 curl_exit 0. Port+remote shape ADMITS on the LAN too. E3 (revert proof), in order, UTC-stamped: (1) netsh advfirewall firewall delete rule name="spt-w2a-E2" -> expect "Deleted 1 rule(s). Ok." (2) Census: show rule name=all dir=in verbose | findstr /i "29470 pwsh.exe spt-w2a" -> expect NOTHING, exit 1. Paste + exit code. ActiveStore: Get-NetFirewallRule -PolicyStore ActiveStore | Where DisplayName -like 'spt-w2a*' -> count 0. (3) netstat :29470 -> still LISTENING 46996 (listener stays UP for E3; it must be alive for BLOCKED to mean the firewall). Loopback 200 with exit. (4) Send "E3 ready". I fetch; prediction on record: E3 BLOCKED (connect timeout x3). Then "E3 fetched" and you stop the listener (close its console / Stop-Process 46996), confirm netstat :29470 empty, final census zero spt-w2a, and report the write ledger for the whole arm (every add/delete with UTC).