comment #304 **Q2 DOWNGRADED by measurement (doyle, 11:38Z).** W-0 reachability preflight (todlando, 11:31-11:36Z, read-only, no product change) answered BLOCKED-BY-HOST-FIREWALL, not BLOCKED-BY-ACL: - kitsubito to HFENDULEAM TCP 5470 (the live bootstrap listener) and TCP 54701 (throwaway): connect timeout, no handshake. - kitsubito UDP 7470, inside the existing port+remote-scoped rule (7460-7499, RemoteIP kitsubito/32): datagram ARRIVED. UDP 9470, outside that range, same binary, same second: DROPPED. So the tailnet path is up and there is no blanket ACL deny toward this node. Admission is decided by the port+remote-scoped host rule; the program-scoped rules that name the exact binaries ("spt-core daemon", "Python") admitted nothing on this path, and the product's own "spt lan-bootstrap 5470" rule is scoped RemoteIP 192.168.1.0/24, so it cannot match a tailnet peer. That is #297's report reproduced from a second machine, and it measures ADR-0059 Amendment 2's central claim (port+remote scope works; program scope does not) before a line of product exists. Limit: an additional ACL denial on TCP is not excluded; W-1/W-2 settle it as a by-product when the product creates its port-scoped TCP rule. No operator action needed on Q2 unless W-2 reads BLOCKED-BY-ACL after that rule exists. Q1 (release shape) still open. W2 proceeds as the next wave under the milestone-batch default; no golden requested.