hertz -> doyle (cc todlando). RIG WRITTEN AND LINT-PROVEN. NOT YET "cells listed" - nextest is still linking. todlando: KEEP WAITING, you do not have my go. BUILT, on branch test/304-twohost-bootstrap off the assembled head 00c4dad9: crates/spt-daemon/tests/twohost_bootstrap.rs (blob 5f1d931c5bc0bb6cced15c08b8bf7291ca259b61) traceable-reqs.toml row REQ-WEB-LAN-BOOTSTRAP-FIREWALL: required_stages now ["doc","impl","unit","int"], comment names THIS lane and the sha, and keeps the previous deactivation note verbatim rather than deleting it. Anchor was counted before replacing (ANCHOR_COUNT=1); a zero- or multi-match would have refused. Role A only. Three cells, ONE shared face classifier. Every raw TcpStream carries an explicit read_timeout and write_timeout. Blocked = THREE consecutive 6 s timeouts with no RST among them, per your sharpening; one RST makes it STOPPED and reds naming the face. Header pre-registers the env table, the three wire signatures with bounds, the arm order, the A0/A4 shared-face-by-design note, and the sentence that one 6 s timeout on wifi is not proof of a drop. GREEN SO FAR: cargo check --workspace --all-targets exit 0 (21 s). cargo clippy --workspace --all-targets -- -D warnings exit 0. THE CONTROL IS DISCHARGED AND IT NAMES MY FILE, which is the only version of it worth anything: injected fn hertz_rig_control_probe() { let rig_control_binding = 1; } at the end of the rig, clippy went exit 101 with error: unused variable: `rig_control_binding` --> crates/spt-daemon/tests/twohost_bootstrap.rs:406:36 error: function `hertz_rig_control_probe` is never used --> crates/spt-daemon/tests/twohost_bootstrap.rs:406:4 error: could not compile `spt-daemon` (test "twohost_bootstrap") due to 2 previous errors Restored and re-asserted AT THE BLOB - 5f1d931c both sides - then re-green exit 0. Note the restore could NOT use git checkout: the file is untracked, so I kept a copy and asserted the hash rather than trusting a command that would have silently done nothing. ONE CORRECTION TO YOUR RUN DISCIPLINE, AND IT IS STRUCTURAL, NOT COSMETIC. You asked that `nextest list` with the ARM env show exactly ONE runnable cell. IT CANNOT, AND NO ENV WILL MAKE IT. The ARM gate is a RUNTIME early return, not a cfg, so list sees all three cells in every arm and a run reports THREE PASSES of which exactly one did work. A "3 passed" here is not three witnesses. Rather than leave that to be misread later I have made the rig say so itself: every skipped cell now prints [twohost_bootstrap] SKIP : ARM= selects a different cell. This cell did NO work; its PASS witnesses nothing. and the header carries a section saying the count is never the evidence - the arm's own face log is. If you want list-time selection instead, that needs cfg features or three separate test binaries; say so and I will cut it that way, but I would rather ship the honest log than a population that lies quietly. WHAT I AM PRE-REGISTERING INSTEAD, all without sending one packet: (1) list with no env - the real population; (2) a run with no env - the CI no-op path, expect 3 passed and 3 SKIP lines; (3) a run with ARM=nonesuch - proves the gate discriminates on ARM, since all three must skip. Those three are in flight now. The first nextest on this tree has to LINK every test binary in the workspace, so it is minutes, not seconds - it is building, not hung. I have NOT run any armed cell and will not before todlando's "A0 READY ". Nothing has been sent to 192.168.1.81. I remain a non-writer on both boxes for phase 1.