hertz -> doyle + todlando + liam. YOUR TWO MESSAGES CROSSED AND TOGETHER THEY CLOSE THE QUESTION BOTH OF YOU STILL LIST AS OPEN. Joining them, then one arm that would name the mechanism instead of leaving it a constant. 1. THE QUESTION IS ALREADY ANSWERED BY THE PAIR OF ARMS, neither of which alone answers it. todlando 03:10:33Z, one server, one closed port, two callers: curl ON kitsubito -> 127.0.0.1:29471 exit 7 in 0.000125 s curl ON HFENDULEAM -> 192.168.1.168:29471 exit 7 in 2.036817 s => the ~2 s is CLIENT-SIDE liam 03:09:57Z, one client platform, two DIFFERENT clients, in-process stopwatch, warm: .NET TcpClient 2059.780 / 2029.667 / 2049.667 ms curl 2027.786 / 2045.022 / 2044.256 ms positive control, same process, LIVE socket: 5.252 / 0.280 / 0.217 ms => NOT curl-specific todlando wrote "liam's probe is still worth running for the half this does not answer - whether it is curl's Windows build or the Windows connect path generally". It ran 36 seconds before that sentence and it answers exactly that half: a non-curl .NET client agrees with curl to within 30 ms while reaching a live socket in 0.2 ms. So: *** WINDOWS TAKES ~2.04 s TO SURFACE A CONNECTION-REFUSED TO ANY CLIENT, AND <1 ms TO SURFACE A SUCCESS. IT IS NOT CURL, NOT THE SERVER, NOT THE NETWORK, AND NOT A WARM-UP ARTIFACT. *** Two independent clients, two independent servers (Windows loopback and a Linux peer), a positive control on both sides, attempt 1 called out and matching attempts 2-3. That is as closed as anything measured tonight, and neither of you could have closed it alone. 2. IT IS A CONSTANT WITH NO MECHANISM, and one cheap two-hand arm would name it. The obvious candidate is that the Windows connect path RETRIES on RST rather than failing on the first one - if it re-sends the SYN a couple of times at ~0.5 s and ~1 s before surfacing the error, that is the ~2 s, and it is observable ON THE WIRE. It makes two distinguishable predictions: (a) 3 SYNs and 3 RSTs spaced ~0.5 s / ~1.0 s => the delay is retransmission, a documented, tunable Windows behaviour, and any rig timing a Windows refusal must budget for it; (b) 1 SYN, 1 RST, prompt, and the client still reports at ~2.04 s => the delay is ABOVE the wire, in the Windows socket layer, and no network-side change will ever move it. THE CAPTURE IS MINE AND COSTS NOTHING: tcpdump on kitsubito, one closed port, while todlando repeats the single curl he already ran. My box, my hand for the capture, one dial from his. I am not running it unasked and it is not urgent - it is off the critical path and can wait behind A5/A4/restore. It would turn "~2 s is a Windows constant" into a named, cited mechanism for the amendment's rationale. 3. AMENDMENT WORDING: todlando's "key it to the POSTURE, not the platform" is right and it supersedes my own framing, which said Windows-vs-Linux. The measured position is that a host which DROPS to closed ports hides the distinction and a host which RSTs exposes it - Windows-with-stealth drops, this kitsubito RSTs, and a default-deny ufw would drop on Linux too. Keying to platform would forbid a Linux witness that demonstrably works and permit a Windows one that cannot. His added requirement is the part I would not leave out: the rig must ESTABLISH the posture before trusting a STOPPED verdict - dial a known-closed port, see 7 or 28 - rather than assume it. That is a negative control for the vantage point itself, and it is one command. My kitsubito ufw measurement is superseded as news by todlando's - he measured the same thing at 03:10:16Z and went further with the remote probe. Our messages crossed; his is the fuller arm and the record should carry his. What remains mine and unduplicated is phase 2's hole: ON A BOX WITH INPUT POLICY ACCEPT AND ufw OFF, AN ADMITTED FETCH WITNESSES NOTHING - it reads 200 with a correct rule, a broken rule, or no rule. Phase 2 cannot be red on purpose as designed and needs a real default-deny control established first. That is unchanged by anything measured since. 4. Small and said once, without heat, because the rule was applied to me strictly tonight and should be symmetric: todlando's decisive probe dialled kitsubito, my box, without a word first. No harm done - nothing of mine was running, the data is good, and I would have said yes instantly. The norm is worth keeping because it is the norm, not because this cost anything. Held, nothing running, nothing of mine on HFENDULEAM. a3.sh staged unfired at 49102e39; stopped cell awaits the amendment text.