hertz -> doyle. END, #304 Linux admission cells. Lane commit 5052d707e7fcffde4c0fc817f392746f19357769 on test/304-linux-admission-cells, parent be99017f, one file, +335, committed linux.rs blob 8264ee9cf2fb9eb7deae3b5fa75a99efb16b4c6d. Unpushed; bundled kitsubito -> HFENDULEAM, nothing to a shared remote. SUBJECT. crates/spt-daemon/src/bootstrap_firewall/linux.rs at be99017f, blob 88f1489e6cbff458732e05516fd9847c72c9b76f computed independently on BOTH boxes, 714 lines, ZERO #[test] before this lane. cfg(target_os = "linux") at bootstrap_firewall.rs:10. THE CLEAN RE-RUN YOU ASKED FOR AS THE END: cargo clippy -p spt-daemon --all-targets -- -D warnings exit 0, zero diagnostics cargo clippy --workspace --all-targets -- -D warnings exit 0, zero diagnostics, "Finished dev profile in 42.65s" (the CI lint command verbatim, on the box CI runs it on) cargo nextest run -p spt-daemon --lib -E test(/^bootstrap_firewall::linux::tests::/) --no-tests fail exit 0, 10 tests run: 10 passed cargo nextest run -p spt-daemon --lib (UNFILTERED, at the lane tip) exit 0, 992 tests run: 992 passed (1 leaky), 0 skipped, 0 FAIL -- no regression anywhere in the crate, not just in my filter My :891 spelling is std::slice::from_ref(&chain). Site 2 of todlando's population (daemon.rs:1735, cfg(all(unix, test))) is inside both clippy runs and clean. TEN CELLS, EACH RED-FIRST BY ONE REVERTED PRODUCT MUTATION. Producer exit from the artifact lane_run wrote, never a composed $?. Every restore verified at blob 88f1489e, never git diff --quiet. Line numbers are in the committed file. 1 marker Sha256::digest(binder…as_bytes()) -> digest(b"") red 796:9 assert_ne, "a different binder path yields a different owned identity" 2 owned digest.len() == 64 -> >= 63 red 810:9 "a 63-character digest is not owned" 3 ufw_scope drop .filter(|port| *port != 0) red 842:47 unwrap_err on Ok((0, false)) 4 identifier (index > 0 && digit) -> (index < 99 && digit) red 855:9 "a leading digit requires quoting" [also reds cell 5 at 897:21 -- shared predicate, expected] 5 nft_input drop || chain.get("dev").is_some() red 891:25 device-bound chain admitted 6 nft_owned disable the !starts_with(OWNER) continue red 908:49 unwrap on Err "unknown ownership version/identity" 7 reconcile refusal text "nonzero bound TCP port" -> "bound TCP port" red 1047:9 the cell reads the product's refusal, not a substring it chose 8 backend_from swap the ufw/firewalld arms red 963:13 (true,true,*) resolved to firewalld 9 parse_ufw_rules drop the "Status: active" guard red 996:9 an inactive listing parsed instead of refusing 10 ufw_preflight dedupe predicate -> false red 1025:25 an administrator's rule for the same port admitted Each mutation reds ONE cell (4 reds two, named above), so no cell is carried by another's failure. HONEST ORDERING NOTE: cells 1,2,3,6,7,8,9,10 were measured on the cells file one line before the :891 from_ref change. That line lives inside cell 5 and is line-count-preserving, and cells 4 and 5 were re-measured after it, same red lines. Nothing else in the file moved. SEAMS. Reachable and now covered: marker, owned, ufw_scope, identifier, nft_input, nft_owned, reconcile's zero-port refusal, plus todlando's three riders backend_from, parse_ufw_rules, ufw_preflight. NOT REACHABLE, and I did not fake reaching them -- every one shells out or probes the host: backend (probe laziness lives here, not in backend_from), ufw_rules, unit_state, ufw_enabled, ufw_active, firewalld_active, policy_names, policy_owned, firewalld_policy, policy_snapshot, nft_snapshot, verify/verify_ufw/verify_firewalld/verify_nft, clear_ufw/clear_firewalld/clear_nft/clear_admissions, ufw_config_owned, is_clean, cleanup, command, executable. Closing those needs either more seams or a host rig; neither is in this lane. reconcile(binder, 0) is hermetic BY REACHABILITY: the zero-port refusal is the first statement and returns before backend(). The cell says so in a comment, because an edit moving a probe above it turns the cell into a host-toucher silently. THE TWO COUNTS, at 697eb398 with the then-7 cells (nextest list 989 / libtest 989), and the finding they produced: cargo nextest list -p spt-daemon --lib 989 test ids, exit 0 cargo test -p spt-daemon --lib 989 run: 987 passed, 2 FAILED, exit 101 The counts agree. The EXITS DO NOT, and that is the real result: bare libtest reds this crate on Linux at a sha where nextest is green. answerop::tests::an_approval_notifies_a_plain_knocker_with_no_pre_authorization answerop.rs:324 "expected exactly one courtesy: [] left: 0 right: 1" brainproc::tests::the_ready_breadcrumb_tells_a_computed_hash_from_a_cached_one brainproc.rs:2347 "the FIRST ready write in a process pays for the digest" Discriminated in one command: both PASS under nextest with the identical filter (process-per-test), exit 0. So they are process-global cells colliding in libtest's shared process, not product reds -- the brainproc one says so in its own panic text, and it is IR-108's leaky-cell class measured on Linux. `cargo test --lib` is not a sound gate for spt-daemon; only nextest is. At the lane tip the same list reads 992 (982 skipped + 10). TRACEABILITY, as a DELTA because the absolute is inherited: traceable-reqs 0.4.1 (the CI pin), 9 [must] at be99017f and 9 [must] at 5052d707 -- delta ZERO. All nine are misplaced_tag in docs prose (F-035-CONFLICT, PUMP-W2-DESIGN, INFRA-REGISTER, DEBUG-CONVERGE-PLAN); none names REQ-WEB-LAN-BOOTSTRAP-FIREWALL and none is in code. These are the nine you told me resolve at assembly. A PRECISE NEGATIVE you should have rather than infer: REQ-WEB-LAN-BOOTSTRAP-FIREWALL already read +doc +impl +unit at be99017f, on 4 tags in bootstrap_firewall.rs and 6 in windows.rs. My ten tags do NOT turn that row green -- it was green with 676 Linux lines untested. The gate row was never the thing that was missing, and this lane is a coverage claim about the CODE, not about the checker. POST-CENSUS on kitsubito, every zero preceded by its own positive control: predicate control: the same grep over a fixture line carrying an owned comment -> 1 (the filter can express the hunt) sudo ufw status numbered | grep spt-bootstrap-v1- -> 0 sudo ufw show added | grep spt-bootstrap-v1- -> 0 sudo nft -a list ruleset | grep spt-bootstrap-v1- -> 0 firewall-cmd: absent on this box. ufw: Status: inactive. builder control: a deliberately-started cargo seen by the same pgrep -> 6 processes. After: 0 of mine. worktree clean at 5052d707; committed blob CR=0 measured with tr -dc '\r' | wc -c, not with grep. CAVEAT I WILL NOT LAUNDER: ufw is INACTIVE here, so the numbered-listing zero is weak -- an inactive ufw prints no rules. The load-bearing zeros are `ufw show added` (reads configured rules regardless of activity) and the live nft ruleset. Also there is no pre-image: I assert zero owned rules NOW, and rest the "my cells wrote none" claim on the OWNER prefix being bootstrap-specific, not on a before/after diff. MEASURABLE ONLY ON WINDOWS -- named as holes, not closed: 1. Nothing in linux.rs compiles on Windows, so no Windows gate can regress-test these ten cells, and none of their reds would ever appear there. The lane's whole evidence set exists only on a Linux runner. 2. The Windows half of this requirement (windows.rs, 6 unit tags) is not mine and I did not touch it; my ten tags do not speak for it. 3. I never ran the two-machine witness the requirement's int stage describes. That stage is deactivated and belongs to the twohost_bootstrap lane. BOX. kitsubito clone ~/spt-core-hertz-linux, own pool, no claim conflict. A GitHub Actions runner job was live on the box throughout in its OWN workdir and target (/home/reavus/actions-runner/_work/spt-bs-core) -- CPU contention only, my pool untouched; I identified it by /proc cwd and left it alone. Nothing of mine is running now. TWO INSTRUMENT FAILURES OF MINE, on the record because both produced a confident green I nearly kept: a python driver died on a SyntaxError while the shell reported exit 0 and the STALE red logs from the previous sha were what exposed it; and the census script stalled mid-run while its ssh reported exit 0 again. Fourth and fifth instances this week of a composed exit not being the producer's. Both were caught by reading the artifact, which is the only reason the lane is not carrying a fabricated arm.