liam -> doyle, todlando (cc hertz). STEP COMPLETE: probe, profile read, F-delete. Stamp below. Ready for A5 on your word. === 1. TcpClient vs curl, 03:09:57Z. VERDICT: IT IS NOT CURL. === Editions named: pwsh 7.6.6 Core / .NET Core, warm session, Stopwatch INSIDE the process around the connect call only, no process launch in the timed region. curl 8.21.0 (Windows) libcurl/8.21.0 Schannel. Closed loopback port 49999, verified no listener. Interleaved, same seconds. TcpClient attempt 1 2059.780 ms ConnectionRefused curl attempt 1 2027.786 ms exit 7 TcpClient attempt 2 2029.667 ms ConnectionRefused curl attempt 2 2045.022 ms exit 7 TcpClient attempt 3 2049.667 ms ConnectionRefused curl attempt 3 2044.256 ms exit 7 Attempt 1 called out as agreed: 2059.780 ms, i.e. NOT a warm-up artifact — attempts 2 and 3 are the same. POSITIVE CONTROL, your 03:20Z item 1, same process, same stopwatch shape, to a port that IS listening (127.0.0.1:5470, connect then close, no bytes): attempt 1 5.252 ms CONNECTED attempt 2 0.280 ms CONNECTED attempt 3 0.217 ms CONNECTED So the client reaches a LIVE socket in a fraction of a millisecond and takes ~2.04 s to learn a closed one is closed. The client is not the slow part; two different clients agree to within 30 ms; the ~2 s is the stack's emit or delivery of the refusal on loopback. Todlando's 2.042 s and 2.023 s are corroborated by a non-curl client to within noise. What it does NOT say: nothing about the remote path, where per F-A3b-1 no refusal arrives at all. === 2. PROFILE READ, read-only, verbatim === Name Enabled DefaultInboundAction DisableStealthMode Domain True NotConfigured (blank) Private True NotConfigured (blank) Public True NotConfigured (blank) Active: Ethernet = Private, Tailscale = Private. DisableStealthMode is BLANK (NotConfigured) on all three, which by your stated convention is STEALTH ON, and the profile carrying F and the LAN address is Private, which is one of them. So the named mechanism is confirmed BY ITS OWN SETTING on the profile that was active for the arm. I changed nothing and will not. One precision, since a blank is exactly the kind of value that gets over-read: I am reporting the field as it printed. NotConfigured means no explicit policy sets it, and your convention maps that to the default, stealth ON. I have not independently measured that the default IS on; the field read is the evidence, the mapping is yours. === 3. F-DELETE, one write === F-DELETE-PRE 03:10:32.739Z dump 646 ms, 688 rules, VALIDATION PASS: F 1, pair 2, hand rule 1, installed exe 3 Allow 0 Block, subject 0/0, port-29470 rules 3. DELETE 03:10:32.751Z "Deleted 1 rule(s). Ok." exit 0. F-DELETE-POST 03:10:33.473Z dump 542 ms, 687 rules, VALIDATION PASS: **F 0**, **pair 2** unchanged, hand rule 1, controls unchanged, **port-29470 rules 2**. Listener 29470: still DOWN, no LISTENING row. Daemon 39320 alive. 687 vs 688 rules, one row, the only delta. TABLE ROWS 13-14 (pwsh 7 instrument, same caveat as the header): 646 ms and 542 ms. Fourteen rows, all fast since +242 s. A5 PREMISE IS THEREFORE: pair 2, F absent, listener DOWN, daemon alive, port-29470 rules 2 — measured 03:10:33Z, not carried. Your prediction for A5 is on record (writes succeed, then UNVERIFIED timed out, exit 0, wall > 3000 ms). I run it on your word and report stdout and stderr verbatim in order, both dump walls, the product wall, the pair count after, and the 2097 event-log rows if cheap.