Both preflight corrections made. Corrected sheet d3/d3-admission-request-sheet.md sha256 0b6fe379ec826d93d9de861d14eb4d33d27d1505766f8103a3d329731236faee (supersedes cdf4f13a). Read-only; nothing invoked, nothing elevated. 3. CI BY NON-TERMINAL STATUS, not recent history. gh run list --repo BigscreenVR/spt-bs-core --status --limit 50, 05:41:12Z. queued exit=0 rows=0 | in_progress exit=0 rows=0 | requested exit=0 rows=0 | waiting exit=0 rows=0 | pending exit=0 rows=0. POSITIVE CONTROL completed exit=0 rows=5, so the filter mechanism is alive and the zeros are answers, not failures. My earlier latest-eight reading is withdrawn: it could not have seen a queued run outside that window. Fresh local snapshot 05:41:53Z, 607 rows, self_rows=1: zero cargo/rustc/link/Runner.Worker, Runner.Listener x1 (idle BECAUSE no Worker row exists), 35 spt-fleet processes = live infrastructure not to be disturbed, free 119.6GB, outdir_absent=True. 4. FIREWALL RULES THROUGH THE RIGHT ADDRESSING ROUTE. You are right that netsh name= matches DisplayName, so my earlier result said nothing about the NetSecurity Name/InstanceID identifiers. Withdrawn. Get-NetFirewallRule -Name, unelevated (elevated=False), 05:41:31Z, BOTH names x BOTH stores = four readings, all identical: ERROR type=Microsoft.PowerShell.Cmdletization.Cim.CimJobException FQID=CmdletizationQuery_NotFound_InstanceID, message naming the InstanceID it could not find. ActiveStore and PersistentStore, spt-core-bootstrap-inbound-tcp and -lan. SUCCESS-vs-ERROR distinction as asked: this cmdlet has NO empty success for -Name. Absence surfaces only as that typed NotFound error; any other exception type or FQID (access denial, RPC failure) is NOT an absence reading and must not be recorded as one. All four are the NotFound form verbatim. CONTROLS. Positive, per store: -Name NETDIS-UPnPHost-Out-TCP returns OK objects=1 (DisplayName "Network Discovery (UPnP-Out)"), and 1001 rules are visible in each store unelevated - so -Name does address rules by InstanceID in both. Negative: an impossible name returns the SAME NotFound error rather than an empty success, so NotFound is a readable absence signal and not a dead predicate. VERDICT: the owned pair is absent from BOTH stores. Process side, same snapshot: three rows matched the helper predicate and all three are self-inflicted - the snapshot's own pwsh (its command line contains the predicate literals) and two stale bash rows from 09-12T23:47Z matched on the path string hertz-fp-driver-review in an old archive command. Named rather than filtered away. No lan-firewall, no netsh process, no EncodedCommand, no New-NetFirewallRule, no d3-emission-probe execution. REFUSAL RULE RECORDED, section 5 step 10: a pre-launch enumeration exception REFUSES the attempt, authorizes no automatic retry and no reuse of the run nonce - any further attempt needs a new RunId, a new OutDir and your grant again. Before/after step 3 now names the Get-NetFirewallRule route with both stores and both controls; netsh is called out as not answering this question. Pipe-namespace scope noted as accepted. Launcher unchanged at 93ee37e1; no suite rerun. D3 ungranted, nothing further runs here.