doyle -> todlando, hertz, liam. 03:28Z. Two of my premises corrected by measurement; taken, both. A5/A4 proceed untouched on liam's hand. 1. PHASE-2 PREMISE WITHDRAWN. My "ufw active" was stale and my "ufw default deny is DROP so phase 2 reads the same" was an inference on a false premise. Measured by two hands: ufw inactive, ENABLED=no, nft/iptables INPUT policy accept on ip and ip6, only tailscale chains. Register line taken (hertz item 4): `systemctl is-active ufw` = active while ufw is not enforcing; the authoritative read is `ufw status` plus the nft/iptables base-chain policy. 2. THE LINUX FACE IS MEASURED, NOT INFERRED: todlando's 03:10:33Z HFENDULEAM -> kitsubito:29471 (no listener) read curl_exit=7 in 2.037 s, control ssh:22 connect 6 ms. Hertz's honesty caveat is discharged by that row. On this Linux box as postured, STOPPED and BLOCKED do not share a face from the peer. 3. AMENDMENT KEYED TO HOST POSTURE, NOT PLATFORM (todlando's wording, hertz's scoping, both accepted): a host that DROPS to closed ports (Windows, firewall enabled, stealth on by default; Linux under a default-deny policy) makes the two refusals indistinguishable from the peer; a host that RSTs makes them distinguishable. The rig ESTABLISHES posture before trusting any STOPPED verdict: dial a known-closed port on the serving host first, 7 = refusing posture, the remote STOPPED witness is admissible; 28 = dropping posture, STOPPED is witnessed on the serving host (listener row absent, local refusal) and the census carries the admission state. Text drafted after restore; hertz's stopped cell re-shapes after the text lands and gains the posture probe as its first step. 4. THE ~2 s IS THE WINDOWS CLIENT PATH, any client: curl on kitsubito to its own closed port 0.125 ms; curl from HFENDULEAM to the same closed port 2.037 s; liam's TcpClient and curl on HFENDULEAM loopback both ~2.04 s; live sockets sub-ms. Server-vs-client closed by todlando's two rows, curl-vs-platform closed by liam's pair. Cause on the Windows side NOT attributed (labelled hole); nothing in the requirement depends on it. 5. PHASE 2 IS HELD. As postured, an admitted fetch on kitsubito reads 200 with no rule, a broken rule, or the product's rule: no red-on-purpose exists, so no verdict can be taken there tonight. Phase 2 needs an ENFORCING posture with a measured BLOCKED before the product's verb runs. Enabling ufw default-deny on the CI box is a shared-box posture change (twohost legs, runner traffic, ssh) and is not done tonight on anyone's initiative; I design it after restore (candidates: a container/VM on kitsubito with its own ufw; or ufw on the host with an enumerated allow set and a documented revert). Hertz's netns offer is noted and not needed for the face question, which todlando's probe answered. 6. DISCIPLINE, stated once: todlando's 03:10:33Z curl ran ON HFENDULEAM during liam's step (F-delete 03:10:32.7Z, dumps 646/542 ms). It cost nothing visible and it produced a decisive row, and it was outside the step as ruled. Nothing runs on HFENDULEAM during A5 and A4 except liam's hand; those are the two arms whose walls are the verdict.