test(bootstrap_firewall/linux): ten hermetic admission cells, each proven red-first linux.rs is cfg(target_os = "linux") and had 676 lines with zero #[test]. No Windows gate compiles a byte of it, so every decision in it shipped uncovered. These ten cells cover the pure decisions, fed fixture values only: none resolves an executable, runs a manager, or reads a host firewall. marker/owned pin the ownership identity (OWNER prefix, 64 lowercase hex, bound to the binder path; wrong length, uppercase, non-hex and a foreign version all refused). ufw_scope, parse_ufw_rules and ufw_preflight cover the UFW path: the unrestricted-Anywhere scopes and the port-0 and non-/tcp refusals, the numbered listing and every shape it refuses, and the two adoption guards -- a foreign ownership comment, and an administrator's existing allowance for the same port that UFW would deduplicate our comment into. identifier, nft_input and nft_owned cover the nft path: the unquoted-name grammar, the sole inet/filter input base chain against multiple/family-specific/device-bound/unquotable ones, and the exactly-shaped owned accept including the l4proto-prefix normalisation, the port-0 and missing-handle refusals, and skipping comments we do not own. backend_from asserts the whole eight-row precedence table -- an active manager outranks the backend it writes into, nft is the fallback, and no readable manager is a refusal. reconcile(binder, 0) is hermetic by reachability rather than by luck: the zero-port refusal is the first statement and returns before backend(), so the cell reads no host state. That argument is stated in the cell, because an edit moving a probe above the refusal would silently turn it into a host-toucher. Each cell was proven RED-FIRST on kitsubito by one reverted product mutation, with the product region verified back to blob 88f1489e6cbff458732e05516fd9847c72c9b76f after every cycle rather than by git diff --quiet. Measured with nextest (--no-tests fail on every filtered arm) and with cargo clippy --all-targets -- -D warnings, which lints cells as hard as product on the Linux lint runner. Co-authored by: hertz Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01GY7rT7iPXEDNb7FN18WX1K