doyle -> todlando (cc liam, hertz). YOUR 03:28Z MEASUREMENT OUTRANKS MY RULING AND THE RULING CHANGES. Ruled, by CLI: 1. Per-name -Name is DROPPED from the rider. It is ~700 ms worse than the shape it replaces (2445/2352/2389 vs 2251/1575/1676, cold 5.1, same store) and the success/throw arms agree, so it is the calls, not exceptions. The array form (1594/1512/1512) may ride only as what it is: ~160 ms, a readability change with its number beside it, not the fix that removes the class. 2. F-A1-1's SHAPE is corrected on the record by replacement, not annotation: the dominant term is the NUMBER OF CMDLET INVOCATIONS plus the ~570 ms fixed spawn+import, and the rule count is a minor term (a call returning 2 rules ~470 ms vs ~550 ms for one returning ~1000). Your 02:44Z "function of the host's rule count" is withdrawn as emphasis; the localisation to the verify's walk stands and is stronger. 3. Your Describe-walk re-pricing (28 calls x ~470 ms) is NOT licensed by these numbers: every ~470 ms figure is a Get-NetFirewallRule call, and liam's warm census put the 7 filter cmdlets at ~95 ms per rule combined. Edition was shown not to be the variable for warm shapes, so the filter calls are plausibly an order cheaper per call than the rule query. The walk's cold cost stays UNMEASURED; A2 bounds only its lower end (>= ~800 ms across whatever part of 28 calls ran before the kill). Do not price it; measure the new shape whole. 4. Your (3), the correctness question, answered: the verify must certify BOTH that the pair is EFFECTIVE (admits packets now) and PERSISTENT (survives reboot). Two store passes are one way to certify that; they are not the requirement. The reconcile already reads PolicyStoreSourceType from ActiveStore objects at :469, and 'Local' there names the persistent store as the source, so one ActiveStore pass that reads that property may certify both in one call. That is your design and it gets measured; the cell that must stay red-able for whatever shape you pick: a pair present in PersistentStore but absent or overridden in ActiveStore must NOT verify. Hand that cell to hertz as the negative control beside his Arm 2. 5. Rider acceptance criterion, replacing my 03:32Z (2): the new verify's wall measured cold 5.1 x3 on this store with the owned set EMPTY and with the pair PRESENT (the populated shape is the one that pays the walk), reported as walls not means, and the budget chosen with margin over the observed spread (554 ms on an identical script tonight). A budget raise is allowed only with that measurement beside it. Per-invocation wall+outcome logging ships regardless; clause (c) and FOLD-3 unchanged; kill-safety conditional on hertz's arms as ruled. 6. Process reuse (hertz's lead, your #2): NOT in this rider. It is a new surface (long-lived child, elevated variant) and needs its own REQ and a security reading before any lane; recorded with its ~900 ms. Bring the measured shape and I gate it; I am not choosing the query form for you.