todlando -- W-0 REACHABILITY PREFLIGHT, START 2026-09-11T11:31Z, on doyle's WORD. No cargo, no build, no product mutation. Nothing has bound yet; every line below is a READ. SUBJECTS, two ports on purpose, because one alone cannot separate the layers: (a) the LIVE bootstrap listener, pid 4732 = C:\Users\decid\AppData\Local\spt-core\bin\spt.exe, LISTENING 0.0.0.0:5470. READ-ONLY, GET /install only; I never stop, restart or reconfigure the operator's listener. (b) a THROWAWAY python listener on rig port 54701, torn down before END and proven gone by netstat. ADMISSION, measured immediately before this START: free 156.2 GiB (167,690,022,912 bytes), floor 96 GiB -- PASS. builders: cargo.exe/rustc.exe count ZERO at this instant. I run none this window. the runner's post-merge CI on two docs commits is starting per your note; it builds into its OWN target, so CPU only and no pool of mine is at risk -- I claim no pool because I build nothing. this box tailnet IPv4 100.68.35.65; peer kitsubito 100.98.197.12, ssh BatchMode reachable, curl at /usr/bin/curl. IR-107 SATISFIED ON BOTH BOXES, both expecting and getting not-a-git-repository: HFENDULEAM TMP=C:\Users\decid\AppData\Local\Temp -> fatal: not a git repository (or any of the parent directories): .git kitsubito TMP=/tmp -> fatal: not a git repository (or any of the parent directories): .git NETSH BASELINE BY NAME, inbound, 686 rule blocks total, 45 matching 5470/54701/spt. The four that decide this window: "spt lan-bootstrap 5470" Enabled Yes | Private ONLY | RemoteIP 192.168.1.0/24 | TCP | LocalPort 5470 | Allow "spt-core daemon" Enabled Yes | Private | RemoteIP Any | Protocol ANY | Program C:\Users\decid\AppData\Local\spt-core\bin\spt.exe | Allow "Python" Enabled Yes | Private | RemoteIP Any | TCP | LocalPort Any | Program C:\program files\python312\python.exe | Allow "spt-ci two-host rig UDP-In (kitsubito only)" Enabled Yes | Domain,Private,Public | RemoteIP 100.98.197.12/32 | UDP | LocalPort 7460-7499 | Allow Profiles: Domain/Private/Public all Enabled, DefaultInboundAction NotConfigured on all three. DECISIVE AND MEASURED, NOT ASSUMED: the Tailscale interface is classified NetworkCategory=Private (Get-NetConnectionProfile, iface index 27, Up). Everything below turns on that. PREDICTIONS, filed before either fetch: P1 the 5470 GET from kitsubito SUCCEEDS (HTTP 200) -- and the rule that admits it is "spt-core daemon", the PROGRAM-scoped Private one, NOT "spt lan-bootstrap 5470", which is scoped RemoteIP 192.168.1.0/24 and cannot match 100.98.197.12. P2 the 54701 throwaway ALSO succeeds, admitted by the "Python" program rule (Private, TCP, any port), since my binder is C:\Program Files\Python312\python.exe -- the same path that rule names. P3 therefore the verdict is ADMITTED and the tailnet ACL permits kitsubito -> HFENDULEAM TCP, so W-2 is not blocked at the operator question. FALSIFIERS, each pre-assigned its meaning: both fail -> BLOCKED-BY-ACL and the leg stops at your Q2. 5470 succeeds and 54701 fails -> the python rule does not match (path/profile), host firewall per-program, ACL still open. 5470 fails and 54701 succeeds -> something 5470-specific and P1's mechanism is wrong. THE LIMIT I AM NAMING BEFORE THE RESULT, so an ADMITTED cannot be over-read as "#297 needs no work": both predicted admissions ride PROGRAM-scoped rules that happen to exist on this box, and program scope is exactly what #297 rejects -- it names one path and is orphaned by the next rebuild or reinstall. A W-2 rig binary (twohost_bootstrap-.exe) has no such rule and will still need the product's port-scoped one. W-0 answers the ACL question and nothing else. END will carry: the raw curl line and its exact output, the raw netsh lines, the single three-value fact, each prediction against its result including my own refutations, the teardown proven by netstat, and whether the box is free from me.