**W-2 two-box field leg DISPATCHED at `00c4dad9` — pre-registration, filed before any arm launches (doyle, 2026-09-12 02:04Z).**

**Subject.** The product at `00c4dad9` (asm/304-w2): its own LAN bootstrap listener, its own elevated pair write, its own stop/cleanup, fetched from kitsubito (192.168.1.168 → HFENDULEAM 192.168.1.81). Port **29470** (named by zero rules on the competent per-rule read, nothing listening); never 5470 (the live 0.69.0 listener + the operator hand rule). Isolated `SPT_HOME` (socket names hash the home; the live daemon is untouched). `REQ-WEB-LAN-BOOTSTRAP-FIREWALL` int stage is reactivated by hertz's `twohost_bootstrap` lane and no one else.

**Ground facts (measured 02:00Z, unelevated).** Group `spt-core bootstrap TCP`: 0 rules. Rules naming the asm exe path: 0 (control: installed spt.exe path: 3). Hand rule `spt lan-bootstrap 5470` and blanket `spt-core daemon` (installed exe, proto Any) both present and both stay. **Census hazard:** a bare `Get-NetFirewallPortFilter` enumeration read port 5470 as ZERO unelevated while the per-rule pipe read it — every dump reads filters per rule and must show both controls (a 5470 row, an installed-exe row) or it is void. Code facts: the listener serves only an APPLIED signed set whose host-triple sha equals the running exe (lanhost set gate), trust root = builtin keys + `identity/release-keys.json` overlay, so a dev-signed set is servable once the home carries the key; no seeder verb exists (todlando adds a dev-only xtask verb from the `lan_bootstrap_e2e.rs` recipe); `ensure_running` spawns `current_exe`, so the head binary's daemon IS the head; elevation from an agent shell resolves to `LAN_FIREWALL_ELEVATION_UNAVAILABLE` (that is the denial arm); the firewall module is home-independent, so liam (elevated, same `SPT_HOME`, head exe) reconciles in-process.

**Roles.** todlando: build, seeder, listener, manual fetch via ssh with census before/after in the same command, exits per producer. liam: sole writer, exactly two commands (A1 start elevated, A4 stop elevated). hertz: `crates/spt-daemon/tests/twohost_bootstrap.rs`, role A only (role B is the product), env-gated like `twohost.rs`, ONE shared face classifier, one cell per arm selected by env, rig red on purpose before A0. Nobody clicks Allow on a firewall popup; a popup is cancelled and recorded.

| arm | state | product output pre-registered | census (group) | kitsubito face | hertz cell |
|---|---|---|---|---|---|
| A0 | listener up, pair absent (unelevated start) | exit 0; `LAN_BOOTSTRAP_UP … (port 29470)`, anchor `sha256 x86_64-pc-windows-msvc <EXE_SHA>`; stderr `LAN_FIREWALL_ELEVATION_UNAVAILABLE` then `LAN_FIREWALL_UNVERIFIED: owned admission is absent…`; status stays ALREADY_UP | 0 | ADMISSION-BLOCKED: `000`, curl 28, connect ≈ 6.0 s, no RST | blocked green; admitted RED naming the face (control) |
| A1 | liam elevated start, same home | exit 0; `LAN_BOOTSTRAP_ALREADY_UP`, then `LAN_FIREWALL_RECONCILED … port 29470; end-to-end reachability has not been tested` | exactly 2: `…-inbound-tcp` (Any; 100.64.0.0/10) + `…-inbound-tcp-lan` (Private,Domain; LocalSubnet); TCP 29470; program Any | ADMITTED: 200 in ms; `/bin/x86_64-pc-windows-msvc/spt.exe` sha256 == EXE_SHA; sidecar artifact sha == EXE_SHA | admitted green |
| A2 | repeated unelevated start | `ALREADY_UP` + `LAN_FIREWALL_RECONCILED` (unelevated verify reads the pair) | still 2, no duplicate names | 200 | — |
| A3 | unelevated `--stop`, pair present | exit 0; `LAN_BOOTSTRAP_DOWN`; stderr `LAN_FIREWALL_ELEVATION_UNAVAILABLE` then `LAN_FIREWALL_CLEANUP_UNVERIFIED: owned firewall resources remain… Cleanup (elevated): …` | still 2 | STOPPED: curl 7 (refused) well under 1 s | stopped green |
| A4 | liam elevated `--stop` | `LAN_FIREWALL_CLEAN: no bootstrap-owned firewall resource remains`, exit 0 | 0; hand rule + `spt-core daemon` still present | ADMISSION-BLOCKED again (E0 face) | blocked green |

**Pre-registered alternative.** If A3 reads curl 28 instead of 7, the two refusals share a face at the wire (Windows stealth swallowing the RST under an allow rule). That stops the arm and is reported as the finding; it decides the rig's discriminator and possibly the requirement text. Not repaired inside the arm.

**Restore.** Isolated home: `serve lan` → NOT_UP, `node stop` under that home only, dir deleted. Live: `serve lan` (no `SPT_HOME`) → ALREADY_UP at 5470 before and after. Final census equals D0 (group 0, asm-exe 0, 29470 rows 0, controls present).

**Phase 2 (Linux listener leg, kitsubito serving, HFENDULEAM fetching)** waits on hertz's read-only manager census (`ufw`/`firewalld`/`nftables`, `sudo -n` exit); the elevated write on kitsubito is a NEEDS-OPERATOR item filed from that census. Tailnet witness still waits on Decision 2 (ACL text).

*\-doyle@HFENDULEAM*
