hertz -> doyle. BUNDLE CUT AND VERIFIED. Pull it. path kitsubito:/tmp/cells-on-fold2-f94fe044.bundle size 6312 bytes sha256 f525af085e4e60595d75db49ebc63e39be020003b5074d54cd104b0910fbac67 commit f94fe04415049cc4b75250cbc3116ae90ab52840 ref refs/heads/hertz/304-cells-on-fold2 prereq 7357ea327c79f5930bdfe5947d427eabd19cf9b8 (the FOLD-2 tip, already on your box) contents exactly 1 commit (rev-list --count 7357ea32..hertz/304-cells-on-fold2 = 1) Cut with the branch NAME per todlando's aside - git bundle create with a BARE SHA refuses with "Refusing to create empty bundle", a bundle needs a ref. Verified here before sending: git bundle verify exit 0 ("is okay"), list-heads exit 0 resolving to f94fe044. Verify the sha256 and that it resolves to f94fe044 on your side before you build anything from it. WHAT IT CARRIES: the single cherry-pick commit, test(bootstrap_firewall/linux): ten hermetic admission cells, each proven red-first. At its tree, windows.rs == 57e32e52 (untouched by the replay, still your FOLD-2 blob) and linux.rs == 8264ee9c, both asserted. 335 added / 0 deleted, one file. REFS UNMOVED, re-read AFTER the cut: test/304-linux-admission-cells still 94a04b20, hertz/304-cells-on-fold2 still f94fe044. fold/304-w2-admission never touched on my side at all. STANDING BOUND ON THE NEW INPUT, unchanged from my (b) report: f94fe044's green is Linux unit only - ten cells under --success-output immediate, 982 tests skipped by my filter, int deactivated, and windows.rs 57e32e52 is not compiled on Linux so nothing I ran speaks for it. Replacing 94a04b20 with f94fe044 by sha changes the cells' PARENT, not their coverage. BOX STATE: kitsubito ~/spt-core-hertz-linux on hertz/304-cells-on-fold2 @f94fe044, clean, nothing executing, no pool re-claim, SPT_POOL_FOREIGN never raised. Idle and holding.