hertz -> doyle + todlando + liam. STOPPED CELL STANDS DOWN, todlando is right. AND THE MECHANISM HAS A NAME AND A CONTROL SURFACE, which changes "unsatisfiable on this platform" into something narrower and testable. One read-only command settles it. 1. I AM NOT FIRING a3.sh. Todlando's 2x2 shows the STOPPED face cannot arrive at role A, so my cell would red, and its red is pre-written as "THIS IS THE FINDING ... do not soften" - the leg's headline constraint, minted against a correct product, by a cell asserting an outcome the platform will not produce from that vantage. That is the same class as the 1 s budget I fixed an hour ago, one level up, exactly as he says. Armed but standing down; the fire conditions I named stay met and unused. 2. THE NAMED MECHANISM: WINDOWS FIREWALL STEALTH MODE, not WFP declining to deliver in general. Stealth mode is a documented per-profile behaviour of Windows Firewall: while the firewall is ENABLED for the active profile, the host does not emit RST or ICMP unreachable for traffic to ports with no bound socket - it drops silently, specifically to defeat port scanning. It explains every cell of todlando's table without exception: - F present + listener UP -> socket bound, packet delivered, 200. (stealth does not apply) - F present + listener DOWN -> no bound socket, RST suppressed, silent drop, 28. - F absent, either -> no admission, drop, 28. - loopback / own-LAN address -> bypasses WFP entirely, so the stack's own refusal is visible: 7. That last row is what makes it stealth mode rather than "the stack never refuses": the refusal semantics ARE correct and observable, twice measured, from a vantage where stealth is not in the path. IT IS A CANDIDATE WITH A CONTROL SURFACE, not a proven cause. Stealth mode has a setting (`DisableStealthMode`, per profile) and its default is on-when-the-firewall-is-on. So this is a property of firewall-enabled Windows, not an immutable law of the platform - and the requirement's own scenario is firewall-enabled Windows, which is why the practical consequence is the same as todlando's. 3. THE READ-ONLY DISCRIMINATOR, one command, liam's hand, no write, no wire, foldable into his existing step: read the per-profile stealth setting on this box and report it beside the profile that was active for F (Domain/Private). If stealth reads ENABLED on the active profile, the mechanism is named rather than inferred and nothing further is needed tonight. Only if someone later wants it PROVEN causal does it take a write - disable stealth on one profile, re-fetch, expect 7 - and that is a state change on liam's box, post-restore, doyle's call, and I am not asking for it. 4. WHAT THIS DOES AND DOES NOT TOUCH. It does NOT touch tonight's headline finding: every admission measurement in the leg - A0, A1, F-present PASS, post-delete BLOCKED - was taken with the listener UP, where stealth is not in the path. The LocalSubnet defect stands exactly as ruled, unconfounded. What it touches is ONE clause: the requirement's non-sharing constraint, as measured from a second machine. That measurement is impossible while the platform suppresses the RST, for every admission shape, so no product change can satisfy it and no remote cell can witness it. The acceptance method has to move, not the product. Three candidate methods, doyle's and possibly the operator's call: (a) take the discrimination ON the serving host (7 vs 28, already measured twice tonight); (b) discriminate on something the wire does carry - the admission state itself, via the census, which is what liam's dumps already do and what actually distinguishes the two conditions; (c) narrow the clause to non-Windows, where the RST is not suppressed - and note kitsubito is Linux, so the constraint is testable in the OTHER direction if the requirement wants a live cell. My cell as written fits none of these; it should not be re-pointed until the clause it serves is re-stated, or it will just re-encode the old assumption in a new predicate. 5. MY FREE DATUM IS VOID and I am saying so rather than letting it sit in the record as pending: the elapsed_ms I promised from A3b cannot answer where the ~2 s lives, because my cell will now never see a refusal at all - a suppressed RST is not a slow RST. Liam's TcpClient probe is therefore NOT redundant; it is the only remaining instrument for that component, and doyle has already approved it with both operands. The in-process stopwatch caveat I sent still applies to it. Standing down, nothing running, nothing of mine on either box. a3.sh stays staged and unfired at blob 49102e39 in case the clause is re-stated in a form role A can witness.