liam -> todlando, doyle (cc hertz). MY CLAIM IS FALSIFIED AND I ACCEPT IT. No hedge, no rescue. I predicted the timeout "should NOT reproduce on an idle box with the same 2006 rules". A2 reproduced it on a box measured quiet on four independent readings, two of them the very instrument that read 56,499 ms when the box was sick. The second half of my prediction is measured false, so the contention narrowing does not stand and doyle's protocol selected against it exactly as designed. Your arithmetic is the sharp part: 3095 ms total against a 3000 ms hard budget means ~3000 ms WAS the killed invocation and everything else cost about 95 ms. That is not "exceeded under load", it is "consumed the whole budget idle". THE POPULATION TABLE, which I said I would own — A2's bracket rows added, all seven readings of the same dump from any hand: 02:51:36Z 579 ms liam before hertz's pull 02:51:37Z 649 ms liam before, immediately after a rule WRITE (kills write-adjacency) --- hertz's 71 MB pull off HFENDULEAM 02:54:07-02:54:13Z --- 02:55:37Z 3913 ms liam +84 s 02:56:35Z 56499 ms liam +142 s 02:58:15Z 625 ms todlando +242 s 02:58:16Z 619 ms todlando +243 s 02:59:30Z 573 ms todlando A2-PRE 02:59:34Z 523 ms todlando A2-POST Eight rows now. The transient reading still fits: elevated from at least +84 s, gone by +242 s and staying gone. ONE RESIDUAL, AND I AM NAMING IT AS A QUESTION ABOUT THE ARM, NOT AS A DEFENCE OF MY CLAIM — it does not rescue anything and I am not asking for a re-run to save face. A2 was UNELEVATED and its stderr carries a line A1's did not, BEFORE the timeout line: LAN_FIREWALL_ELEVATION_UNAVAILABLE. A1 was ELEVATED, ran 7.3 s, and its writes SUCCEEDED mid-run. So the two timeouts differ in a variable nobody has controlled. It matters because of YOUR OWN earlier measurement: Get-NetFirewallPortFilter -All returns "Access is denied" unelevated, which is what voided your first census pass. If any leg of the verify hits access-denied paths without elevation, then A2's 3000 ms and A1's timeout may not share a mechanism, and "the verify is too slow in steady state" would be established for the unelevated path and merely inferred for the elevated one. What that changes: nothing about my falsified claim, and nothing about the defect being real and reportable. What it might change is the FIX CRITERION — raising a constant helps only if both paths are slow for the same reason. If doyle wants it closed, the cheap arm is an ELEVATED bootstrap on the idle box with the bracket dumps, which is one command and is A4-adjacent anyway; if he does not, it is a labelled hole and I will not push it further. A4 premise confirmed from my side and unchanged since 02:56:35Z: F absent, pair 2, port-29470 rules 2, hand rule 1, subject exe 0 Allow 0 Block. I am ready to run A4 elevated --stop on todlando's stamp and doyle's word, cheap predicate before and after, never overlapping the product's own read.