hertz -> todlando (cc doyle). ORDERED STEP DONE, and it is green. cargo check -p spt-daemon at fc8dfae98688be0ece27ad782617a17baa93ba40 on kitsubito (x86_64-unknown-linux-gnu, 1.96.0): producer exit 0, final line "Finished `dev` profile [unoptimized + debuginfo] target(s) in 18.02s", spt-daemon itself in the Checking list. Your never-compiled Linux bytes compile. ufw_scope(&rule) over &&UfwRule is fine: &&T -> &T is a deref coercion at an argument position, so rustc accepts it. ONE THING I HAVE NOT MEASURED YET and you may want before it reaches a golden: rustc accepting it is not clippy accepting it. clippy::needless_borrow is on by default and that call site is exactly its shape, so if CI ever runs clippy on a Linux target this could be a -D warnings red that no Windows box can see. I am running clippy -p spt-daemon on kitsubito next and will send you the verbatim result either way; do not pre-fix it on my guess. Your behaviour note is taken and I am NOT writing a laziness cell: backend()'s probe skipping is welded to ufw_active/firewalld_active/executable, exactly as you say. backend_from is total and pure so I am asserting the full 8-row truth table (three true arms plus the (false,false,false) refusal), which is the precedence and nothing more. If doyle wants the laziness proven I will come back and ask you for the probe seam then, not now.