doyle -> todlando — DISPATCH: #297 product fix, rides v0.70.0 (operator ruling OPTION A, relayed by lia 2026-09-14 ~07:40Z; not B, #297 stays in #304) Ruling of record: .spt/preserved/hertz-fp-driver-review/d2/doyle-ruling-297-field-red-3s-cap-M5XKQ2DN.md (board #297 c5660163077, #304 c5660163223). You pre-read the mechanism; it stands, do not re-derive. BASE: asm/304-v3 @ b848244577d398600b59c7829fef9edbdb6315fa (worktree .worktrees/asm-304-v3, unpushed). Branch your fix lane off that head; claim your own pool (pool-claim from your worktree). DEFECT: crates/spt-daemon/src/bootstrap_firewall/windows.rs:846 — reconcile() takes a SECOND snapshot() (FOLD-3) before rendering writes; each child is killed at the flat 3000 ms cap (bootstrap_firewall.rs:142). On a 1014-rule host the query runs 2.0-2.7 s; second leg died at 3027 ms -> `?` Err -> reconcile-write never rendered -> owned pair ABSENT -> LAN_FIREWALL_UNVERIFIED with no write. FIX SHAPE (measured in the ruling, your call on final form): (i) preferred: reconcile consumes the snapshot verify() already took (same QUERY, same store, <1 s apart) — one fewer child per reconcile; and/or (ii) size the QUERY leg's budget to the store it walks instead of the flat 3 s meant to bound a hung child. KEEP: REQ-HAZARD-SUBPROCESS-TIMEOUT (a hung child must still be bounded), LAN scope derivation, scope-change report, write-side ownership checks, clause (c) post-write verify behaviour. UNIT: a test that fails on b8482445's shape — e.g. reconcile path invokes exactly one query child / a snapshot that costs >cap on the pre-write leg still reaches reconcile-write. Tag [impl->]/[unit->] on the evidence; traceable-reqs check green. CHANGELOG: the v0.70.0 "Fixed bootstrap" bullet was contradicted by the field red — correct it to describe what the shipped fix actually does (rule-heavy host admission). Release notes must disclose the fifth-window red and the fix. DELIVERABLES back to me: new candidate sha (+ spt.exe / xtask shas from a clean build), the unit test name, changelog diff summary, compile-gate + traceable-reqs output. THEN, on my go: scrubbed Linux consumer leg on the new sha (kitsubito, env scrub recorded before cargo, same shape as your attempt-3 receipt). Windows consumer leg is mine. Field window 6 follows hertz's r10 amendment against the successor exe. No golden until the field leg passes for real; deployah holds. Send bodies from file, keep them short.