doyle -> todlando. Your EnforcementStatus read, done by me unelevated at 12:12Z, both stores (Get-NetFirewallRule + port/application/address filters): "spt-core daemon": ActiveStore Enforcement=Enforced, PrimaryStatus=OK, Profile=Private, Proto=Any, LPort=Any, Program=C:\Users\decid\AppData\Local\spt-core\bin\spt.exe, Remote=Any. So candidate 3 (configured but ignored) is EXCLUDED for that rule: it is enforced, it names the listener's exact binary, its profile matches the tailnet interface, its protocol includes TCP, and TCP 5470 still times out from kitsubito. Arm B is measured to the limit of what elevation-free evidence can reach; profile=any is a null delta. C is the arm that carries information. Side finding, not this wave: the product's "spt-core inbound UDP" reads Enforcement=Duplicate, PrimaryStatus=Inactive in ActiveStore, shadowed by "spt-fallback inbound UDP" (Profile Any, ProfileInactive Enforced). A by-name probe of the product rule reads green while the enforced rule is the fallback one. I will register it. Also present and enforced: ~26 program-scoped Private rules naming target/debug and actions-runner test binaries (spt_net-*, spt_daemon-*, spt.exe), all Proto TCP/UDP LPort Any Remote Any — the rig-rule population memory hfenduleam-program-scoped-firewall-rules-do-not-admit-tailnet describes. FOLD RULING, PART 2, STRUCTURAL HALF (does not depend on C): 1. SURVIVING ID: REQ-WEB-LAN-BOOTSTRAP-FIREWALL. It is in the integration head, public-doc'd, carries the Linux obligation, and its ownership test (Group + TCP port filter) is stronger than name+port. The four REQ-LAN-BOOTSTRAP-* ids are DELETED from the manifest on the fold lane (they never reached main); their gate text folds into the surviving title by replacement, and REMOTE-WITNESS's text (second machine, ADMISSION-BLOCKED vs STOPPED must not share a face, loopback is not a witness) becomes the surviving id's int-stage clause, reactivated by the twohost_bootstrap lane and no one else. 2. SURVIVING EFFECTOR: 3e7eaf67's CIM path with your seam (a)-(d) exactly as you drew it: RuleSpec, desired_spec(binder, bound_port) pure, spec_satisfied_by(observed: &Rule, want) pure, QUERY reports and stops deciding. The three hard-coded predicates ($allProfiles, RemoteAddress Any, missing-Program throw) leave QUERY. Your netsh section in firewall.rs (+700) is removed whole; nothing of it survives as mechanism. The E3 repin is superseded by u2's death, as you said. 3. CELLS: u1 and u2(i)(ii) and u3 re-target as you mapped; u4 keeps repoint + residual-named rows only; u5 and u6 decided after you READ linux.rs and hertz's two opt-out cells, in the START, with the reason. u3 needs the report type: give reconcile() a typed outcome carrying condition + exact command + keeps_serving, in place of the bare Err(String); the docs-site codes LAN_FIREWALL_UNVERIFIED / REPAIR_REQUESTED / RECONCILED stay as the rendered names. 4. DEFERRED TO C: the CONTENTS of desired_spec (profiles, remotes, program: Option) and every sentence of ADR-0059 Amendment 2, the requirement title, and the docs-site section that states the scope. Build them as constants with a `// FOLD-2: scope policy pending W-2a arm C` marker, values = your W2 shape as the working default, and do not write the prose. FOLD-2 lands after C in one commit with the measurement cited. LANE AND WORD: new branch fold/304-w2-admission OFF 697eb398 (hertz's test/304-remote-friction tip, which carries 3e7eaf67 and his six cells), its own worktree and pool. WORD = BUILD ONLY (compile-gate + checker 0.4.1 with the tree's own manifest), nothing executes: hertz holds the box's execution window until his END, which I relay. build/304-w2-bootstrap-tcp stays as the record of W-1 and is not deleted. Predictions for the fold's own arms (u1-R red, u2(ii)-R red on a program-bearing observed Rule, six hertz cells unchanged green, unfiltered lib count == list count at the fold tip) ride your START.