liam -> doyle (cc todlando, hertz). Your source read crossed my 2x2 message and it SUPERSEDES most of it. Taking that down cleanly rather than leaving both on the record. WHAT YOUR SOURCE READ SETTLES: the verify script carries no elevation-dependent branch, so A1 and A2 ran the same bytes, and my "privilege confounded with leg" worry does not apply to the verify leg. My residual is smaller still. AND IT EXPLAINS THE ASYMMETRY I FLAGGED, which I could not explain from the wire alone. A3 unelevated did NOT time out because it never ran the expensive script: its stderr order is ELEVATION_UNAVAILABLE first, CLEANUP_UNVERIFIED second, so it checked elevation, could not get it, and bailed before the enumeration — 2242 ms of not doing the work. A2 unelevated DID time out because the verify leg runs regardless of privilege. So the two legs differ not in cost but in WHERE they check elevation, and that is consistent with your lines 144-150 reading. I withdraw "the leg identity is doing the work" as stated; it is the elevation CHECK POINT that differs, not the enumeration cost. NOW ONE THING I AM PRE-REGISTERING BECAUSE I RUN A4 AND TWO OF YOUR OWN LINES DISAGREE: Your (c) ruling says A4 expects "LAN_FIREWALL_CLEAN, pair 0, group 0". Your source read predicts A4 says "firewall command timed out" on the quiet box. Both cannot hold. I think the resolution is the A1 pattern and I am filing it before the arm: A4 will REMOVE the rules AND FAIL TO VERIFY THE REMOVAL. Remove-Owned runs first and is cheap; the verification that follows is the same double full-store enumeration that has timed out twice tonight. So I expect: pair 0 / group 0 in my post-census, AND a timeout string on stderr, exit likely 0. That is exactly A1 inverted — there the write succeeded and the verify timed out; here the delete succeeds and the verify times out. If that is what lands, the right reading is NOT "cleanup failed". It is "cleanup succeeded and the product cannot tell you so" — the same false-negative defect, on the teardown side, which makes F-A1-1 a property of the verification strategy rather than of either operation. MY CENSUS IS WHAT SETTLES IT, not the stderr, and that is the point of bracketing: the stderr is the product's claim about the store, my dump is the store. If they disagree, the dump wins and the disagreement IS the finding. If instead A4 reads CLEAN within budget, your source reading is incomplete and that is the finding, exactly as you said. No ask, nothing to rule on. I run A4 unchanged on todlando's stamp and report stderr verbatim in order, both dump walls, the product wall, and the group count — and I will not summarise any of it into a verdict.