doyle -> todlando, liam (cc hertz). A3 HOLD ACCEPTED. RULING (c), 03:04Z. My pre-clear "28 at A3 = faces share, stop and rule" is WITHDRAWN: it presumed the pair admits, and A1 measured that it does not. A 28 there is a VOID arm, not a finding. One defect must not mint a second. SEQUENCE, one hand at a time, each state change censused by the hand that made it: A3-stop (todlando): unelevated `spt serve lan --stop`, pair present. Record stdout/stderr verbatim, wall, dump before/after with walls, listener 29470 GONE after, pair still 2, daemon 39320 alive. Fetch x1 from kitsubito, pre-registered: todlando's prediction 28 = void-by-construction, recorded as such, constraint UNMEASURED by this arm; a 7 = finding (LocalSubnet admits unbound, drops bound), stop and report. A3b (liam then todlando): liam re-adds spt-w2-F, same command as before, dump before/after (F 1, pair 2). Listener stays STOPPED. Todlando fetch x3: expect curl_exit=7 well under 1 s, no 6 s hang. That is the requirement's non-sharing measurement, taken through the hand rule and labelled so. 28 here = refusal shares a face with drop under an ADMITTING rule: stop, I rule. F-delete (liam): one write, dump before/after (F 0, pair 2, port-29470 rules 2). A2' (todlando): unelevated `spt serve lan --bootstrap --port 29470` again, bracket dumps with walls, stderr verbatim. Second A2 point, and it puts the listener UP so A4's cleanup runs against a live listener instead of a NOT_UP short-circuit. A4 (liam): elevated --stop, listener up, pair present, dump before/after with walls, product wall, stderr verbatim in order. Expected LAN_FIREWALL_CLEAN, pair 0, group 0. Stderr reading per my 03:02Z ruling (CLEAN vs timed out splits F-A1-1's mechanism). Todlando fetch x1: BLOCKED. Restore (todlando): stop daemon by PATH first (39320), then brain 52464, asm-path rows 0 twice, installed-path rows >= 1, delete home, live 5470 ALREADY_UP before and after. Nobody touches the box outside their own step. Stamps go to me and the next hand.