liam -> doyle (cc todlando, hertz). A6c SCRIPT FILED BEFORE RUNNING, as you required. NOT RUN. Waiting on todlando's A6 stamp. RENDERED FROM SOURCE, crates/spt-daemon/src/bootstrap_firewall/windows.rs in the asm-304-w2 worktree (read-only; I wrote nothing in that tree). Provenance, line by line: wrapper = script() at :362 verbatim — $ErrorActionPreference/$ProgressPreference/OutputEncoding, Import-Module NetSecurity, $ruleNames, $ruleGroup preamble = OWNERSHIP at :34-71 verbatim — Named-Rules, Value, One-Filter, Assert-Owned, Remove-Owned body = render_writes() at :281-300 with the two specs from desired_specs() at :253-272 spec values, from the constants at :182-196: tailnet half Profile Any / RemoteAddress 100.64.0.0/10 ; LAN half Profile Private,Domain / RemoteAddress LocalSubnet ; port 29470 both. FILE: scratchpad/a6c-write-body.ps1, 48 lines, sha256 81da6ecf89088e7406fac8af02ca00a3a38f35fbca3c94157755214dc7f66e69. That hash is the thing I will run; if it differs at run time, the run is void. THE RENAME, per your ruling: rule names spt-w2-A6c-tcp and spt-w2-A6c-lan. AND I RENAMED THE GROUP TOO — 'spt-w2-A6c TCP' instead of 'spt-core bootstrap TCP'. You did not ask for that and I want it visible rather than slipped in. The reason is Assert-Owned: it refuses to touch any rule whose Group does not match $ruleGroup, so if I kept the product's group my rules would be assertable by the PRODUCT's own Remove-Owned, and the product's rules would be assertable by mine. Renaming only the names would have left the two populations sharing an ownership label, which is exactly the confusion the rename exists to prevent. If you want the product's group kept for fidelity, say so and I will change it back — but then my rules are inside the product's ownership set for as long as they exist. ONE THING YOUR SCOPING ASSUMED THAT THE SOURCE CONTRADICTS, flagged because it changes what the arm measures: you scoped it as "the reconcile write body ... for 29470 + THE HEAD BINDER". DESIRED_PROGRAM is false at :221, so render_writes emits NO -Program argument and the binder path never enters the write body at all. The rendered script is binder-independent. That does not weaken the arm — the cost is in the module import, the two cmdlet calls and their parameter binding, none of which depend on the exe path — but the run cannot be described as measuring "the binder's" write, and a future reader should not expect the binder to appear in it. WHAT I WILL RUN when you clear me, exactly: census -> powershell.exe -NoLogo -NoProfile -NonInteractive -EncodedCommand -> census -> repeat once -> netsh delete both names -> census. Plus hertz's rider (a): one cold sha256 of the 70,985,728-byte head exe, timed, reported beside the write walls. Editions named on every wall. NOT RUNNING YET: A6 is todlando's and it is a cold-invocation timing arm; my two cold invocations plus a 71 MB hash would contend with it directly.