todlando -- PREDICATE ARMS, END 2026-09-11T12:30Z. Open 12:28Z, ~2 min. THREE arms, all ran, all RED, zero-match gate satisfied on each (exactly 1 test run). SUBJECT 61d3459f. P1 program_ok forced true -> RED, windows.rs:512, cell a_program_bearing_rule_does_not_satisfy_a_spec_that_wants_no_program_filter. PREDICTION SUBSTANTIALLY RIGHT, CITED LINE OFF BY ONE, and I am not rounding that up to a hit: I filed :513. The failing assertion IS the one I named -- `!spec_satisfied_by(&with, &want)` -- but :513 is the ARGUMENT's line and :512 is the `assert!(` the panic reports. I cited where I read the expression, not where the macro begins. The substance holds: it did NOT red at :506, so the constant passed and the PREDICATE is what failed, which is the gap my FOLD-1 END said was open. Now closed. P2 profile comparison forced true -> RED, windows.rs:553, the LAST assertion of an_unrestricted_remote_does_not_satisfy_a_narrowed_spec. Exact, and the three remote-shaped assertions above it survived the profile mutation as predicted. P3 remote comparison forced true -> RED, windows.rs:538, the FIRST assertion of THAT SAME cell. Exact. THE CROSS-CHECK I FILED PASSES: P2 and P3 reddened the same cell at DIFFERENT lines (553 vs 538), so the two mutations are independent and each arm proves its own comparison rather than one masking the other. Every comparison in spec_satisfied_by is now measured red-capable: program (P1), profile (P2), remotes (P3), bound port (F1 earlier at :482). Hygiene is asserted only by its green path -- I am NOT claiming an arm for it, and its mutation would be a fourth I did not run. REVERTS: proven after every arm by oid AND byte shape -- 26514 bytes, 567 CRLF, 0 bare LF, work == head == f634ff2065de6f704b07f94f33fe642c50a23d63 on all three, and identical at POST. Tree CLEAN, nothing committed from this window: mutations only, all reverted. BOX: free from me, no survivors; the arms were three filtered runs of one cell each. NEXT, starting now on your standing word: the three Linux riders as ONE commit on 61d3459f with its own compile-gate -- backend_from(ufw, firewalld, nft_present) pure with backend() reduced to probe-and-delegate; parse_ufw_rules(&str) split from the command call; ufw_preflight taking &[UfwRule]. No execution here (cfg-invisible on this box), no Linux cell written by me -- hertz measures on kitsubito.