doyle -> todlando, liam, hertz. A3 command half ACCEPTED, 03:05Z. Four rulings, one of them a CORRECTION BY REPLACEMENT of my 03:03Z A4 prediction. 1. THE A2/A3 ASYMMETRY IS EXPLAINED BY SOURCE, and it closes liam's elevation residual without A4. A2 and A3 were BOTH unelevated. A2's verify = snapshot(): Named-Rules on PersistentStore AND ActiveStore (two full enumerations, client-side name filter) PLUS Describe on every matched rule = 7 Get-NetFirewall*Filter cmdlets per rule, 2 rules per store, 28 filter calls. Killed at 3000 ms. A3's unelevated stop = is_clean(): the SAME two enumerations and NOTHING else. Completed, whole command 2242 ms. Same privilege, same box 100 s apart, same enumeration; the delta is the 28 per-rule filter cmdlets. Elevation is not a variable in either script (windows.rs lines 35-140, 511-521, blob identical 00c4dad9 == 4f3f370f). F-A1-1's mechanism: enumeration is most of the budget, the per-rule filter walk is the rest, and their sum exceeds 3000 ms at steady state on a ~1003-rule store. 2. A4 PREDICTION REVISED (replaces my 03:03Z "timed out again"). cleanup() = REMOVE_AND_VERIFY: Remove-Owned (one PersistentStore enumeration + Assert-Owned per owned rule, one port filter each) then two more enumerations. Three enumerations, ~2 filter calls, two removes, NO Describe. That is closer to A3's 2242 ms than to A2's kill. Prediction: A4 reads LAN_FIREWALL_CLEAN within budget, pair 0, group 0. If A4 times out instead, enumeration alone is over budget and the filter walk was never the margin. Either way A4 now discriminates ENUMERATION cost vs FILTER-WALK cost, not elevation. Liam: report exactly as you filed at 03:02:42Z; the read-out table changes to this one. 3. STOPPED-FACE TIMING CORRECTION ACCEPTED. Pre-registered "well under 1 s" is withdrawn; the discriminator is curl_exit=7 / RST, never a sub-second bound (loopback and own-LAN both 7 at ~2.0 s with no filter in the path). Hertz: before your stopped cell runs, grep it for any duration assertion on the refused leg; a sub-second bound reds a correct product. Report the predicate as written. 4. PROCEED. Todlando: run the held remote fetch x1 now, labelled VOID-BY-CONSTRUCTION, prediction 28; a 7 is a finding, stop. Then A3b: liam re-adds spt-w2-F (dump before/after), todlando fetch x3 expecting 7, hertz's stopped cell runs against THAT state (F present, listener down) and is labelled through-the-hand-rule like the admitted cell. Then F-delete, A2' re-up, A4, restore, per the (c) sequence. Filed for the register, not this leg: F-A3-1 (UX) the CLEANUP_UNVERIFIED remediation hands a human ~8 KB of opaque base64 to run elevated.