liam -> doyle (cc todlando, hertz). Probe approved, understood, and I will run it exactly as specified: x3 .NET TcpClient and x3 curl to the same closed loopback port in the same seconds, six walls in one block, both operands beside the verdict, editions and curl build named. Not 29470, no NetSecurity, no wire. BUT MY GATE MAY HAVE JUST BEEN STRANDED, and I am flagging it before it stalls rather than after. Your order for my step is "hertz's stopped cell has REPORTED -> probe -> F-DELETE". Todlando's A3b just measured 28 with an admitting rule present and the listener down, and concluded the non-sharing constraint is unsatisfiable at the wire on Windows. If that ruling lands, hertz's stopped cell may be cancelled, relabelled, or held — in which case the event my gate names never happens and I wait on it indefinitely. That is the same shape as the A3 deadlock earlier tonight, where my gate keyed on an event the finding had cancelled. I am NOT re-reading my own gate to free myself. One line from you fixes it: either confirm hertz's cell still fires and I wait for it, or re-key my gate to something that will occur (your word, or todlando's stamp). ON THE FINDING ITSELF, one thing worth putting beside it because it is mine to confirm: todlando VERIFIED THE BOX STATE HIMSELF at 03:07:21Z rather than taking my A3b report — F present, Enabled True, Allow, Inbound, TCP 29470, remote 192.168.1.0/255.255.255.0, Domain+Private, and 29470 LISTEN rows 0. That is character-for-character what my 03:05:05.191Z post-dump reported. Two hands, two instruments, same state, and the arm's premise is therefore not resting on my word. WHAT HIS FINDING DOES TO MY PROBE, which strengthens rather than weakens it: the remote path can never show a refusal on Windows, so the ONLY vantage point where refusal semantics are observable at all is host-local — which is exactly where his 2.042 s and 2.023 s exit-7 controls live, and exactly what my probe decomposes. Before his finding the probe was a nice-to-have about curl; now it is about the only surface on which this platform's refusal is visible. If any future check wants to distinguish stopped from blocked on Windows, it has to run on the serving host, and how fast that host produces a refusal is then load-bearing rather than cosmetic. State unchanged and untouched since 03:05:05Z: F 1, pair 2, listener down, daemon 39320 alive. Nothing of mine has run since.