docs(reqs): register the #297 LAN-bootstrap TCP admission axis, all stages inactive Four requirements and ADR-0059 Amendment 2 for releases#304 W2 / #297, on doyle's ruling of fork (i): close the TCP admission axis in its own binary, and leave the twohost_web QUIC/UDP coverage hole labelled exactly where it is. WHY FOUR NEW IDS AND NOT AN EXTENSION. The REQ-INBOUND-* family is the UDP/QUIC surface: program-scoped by design, verify-not-repair on Linux, and REQ-INBOUND-WINDOWS-RULE-BINDER-PATH-MATCH is a PATH match on purpose. #297 needs the opposite scope on a different protocol — a port+remote TCP rule for the port the listener ACTUALLY bound — so extending that requirement would collapse two contracts that disagree deliberately. Each new title names the distinction rather than leaving a later reader to find it. REQ-LAN-BOOTSTRAP-TCP-ADMISSION bound port, port+remote scope, never program scope REQ-LAN-BOOTSTRAP-ADMISSION-REFUSAL-HONEST a refused rule write keeps the listener SERVING and names the unmet condition REQ-LAN-BOOTSTRAP-RULE-OWNERSHIP-LIFECYCLE stop deletes only our own rule, reports residuals, never holds the socket hostage to the firewall REQ-LAN-BOOTSTRAP-REMOTE-WITNESS int ONLY: a second machine, and loopback is not a witness ALL FOUR ARE required_stages = [] and stay that way until doyle's W2 build word — the activate-don't-pre-fail rule. The registry gains the ids the ruling hangs on; the coverage gate pre-fails nothing. The amendment carries the doc-stage evidence for three of them (the fourth has no doc stage by construction: no local artifact can carry a claim whose whole content is that a different machine observed it). Its closing section states the scope boundary in the file itself, so a passing TCP fetch is never read later as evidence about the UDP direction. TRACEABILITY, with its instrument named. Local checker is 0.4.1; this tree (off origin/main) pins 0.2.0 in ci.yml and golden.yml, so this reading is a DIFFERENT rule than the gate this lane will meet — IR-104's mismatch, stated rather than papered over. Under 0.4.1: all four new requirements read [OK] with required [], three showing +doc from the amendment tags and the witness one showing -doc as intended. `check` exits 1 with 312 [must] misplaced_tag findings — and the SAME 312, same class, come from the unmodified main checkout, so every one of them is pre-existing and none is mine. No other finding class appears in either run. No code, no tests, no build: nothing in this commit is executable. releases#304 releases#297 Co-authored by: todlando Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01V8rmw2TwXUSA88iFjYV3ii