liam -> todlando (cc doyle). Standing by, nothing run. You asked for objections BEFORE the go. Three, then the green preconditions. All read-only measurements, 02:21:41Z-02:22:28Z. OBJECTION 1 (needs a ruling, and it is the one that can void your arms): "If a popup appears, CANCEL it." a. It contradicts doyle's standing rule from arm E, which I am still under: dismiss the Security Alert NEITHER way, report text and time, the after-census decides. Two directors, two rules, one dialog. b. On Windows, Cancel is NOT neutral. Dismissing that prompt mints BLOCK rules for the program. That is the same population poisoning as Allow, in the other direction, and it would make a later arm read BLOCKED for a reason that is not the firewall behaviour you are testing. I have not measured this on THIS box and am not asserting it as tonight's fact; I am flagging it because the instruction assumes Cancel is a no-op and I do not believe that is safe to assume. c. Mechanically I cannot do either. My shells are non-interactive, so I cannot click Cancel. My only dialog instrument is a window-title scan for Security|Alert|Firewall, which cannot see a dialog whose title I did not guess and cannot dismiss one it does see. So "CANCEL it" is not executable by me as written. It needs the operator's hand, or the instruction becomes detect-and-report. My proposal: leave it, record the time, census before and after with a BLOCK-action arm added to the predicate, let the census decide. Your call or doyle's, not mine. OBJECTION 2 (pre-registration mismatch, cheap to fix now, expensive after): your expected A1 output begins LAN_BOOTSTRAP_ALREADY_UP. At 02:22:28Z the isolated home's serve\registry reads {"schema_version":1,"entries":[],"next_suffix":{},"name_owners":{}} — entries EMPTY. On that state I would predict NOT-already-up. Either your expectation carried over from a different home or run, or ALREADY_UP is sourced from something other than the serve registry. Worth reconciling before A1, because if A1 prints ALREADY_UP from an empty registry that is itself a finding and I would rather it be a filed prediction than a surprise. OBJECTION 3 (scope, minor): that home is NOT idle and I am not its only actor. Live daemon pid 39320, started 02:12:57Z, cmdline "...asm-304-w2\target\debug\spt.exe daemon run --detached". Brain pid 52464, exe_hash 1e29d549..., brain.ready and pump-heartbeat rewriting every 1-2 seconds while I read. If that is your A0 rig, fine and ignore this. If it is not yours, there is an unowned writer in the subject home. Either way, my sole-writer mandate covers the FIREWALL, not that home. GREEN PRECONDITIONS, measured: head binary exists, 70985728 bytes, mtime 02:09:09Z, sha256 1e29d549d69c34e3fc452212406b7fe513935632816a4021cf7b94a29dc25137 = your expected sha, character for character. no inbound rule names 29470 or asm-304-w2 (findstr exit 1). ActiveStore spt-w2a* count 0, arm E left nothing behind. live listener untouched and out of scope: 0.0.0.0:5470 LISTENING pid 4732. Nothing on 29470. SPT_HOME is EMPTY in my current shell, so I will set it inline in the same command that runs the binary, per your point 1. Elevation available: IsInRole(Administrator) True, and I have been writing netsh all night. Waiting for "A1 GO". I will not run A1 until objection 1 has a ruling, since the dialog can appear the moment A1 binds.