docs(register): IR-89's workflow half is built and field-measured, and it grew six corrections The guard is two cells plus a step per half. What it cost to make honest is worth more than the guard: each correction is a way a probe can certify the fault it exists to catch. A fixed symmetric window adds a third cause shaped like the other two. The step boundary orders the probe on one host; it does not align two. Measured: the first hand-run redded INBOUND_BLOCKED at 10.24 s with text asserting "a BOX rule, not a product or rig fault" — and the cause was cargo's start-up on the sender putting its first datagram after the receiver's window closed. What stopped it being filed as a peer block was that the box facts contradicted the text: kitsubito's netmap lists this host among its permitted inbound sources and ufw is inactive. A failure text that contradicts a measured box is the text's defect. So the rendezvous is data, and "no beacon" is a fourth outcome with its own name rather than a firewall accusation. The listening socket must never send. Any outbound datagram from the measured port opens stateful return state for it, so the probe then arrives solicited and crosses under both layers — this entry's own sentence, applied to the guard. Measured: with the beacon on A's listening socket the out-of-grant control went GREEN on a port a listen-only run had measured BLOCKED eight minutes earlier. The ack is addressed to the rig port, not to the probe's source port. Measured: acking to `from` produced a run that contradicted itself — A said INBOUND OK and B said INBOUND_BLOCKED, same run — because the ack is not return traffic of the flow B opened and a port-range inbound rule drops it. One ack is not enough: A acking once left B's red resting on a single unrepeated datagram, so ordinary packet loss would reproduce the split verdict above. A now acks every probe in a short window after its own verdict is settled; B stops on the first. And both probe steps carry an explicit 300 s budget beside ceremony steps that say 900 — it bounds rendezvous skew, not pairing, and left unset it would have been an invisible default next to a visible number a reader would infer wrongly. The falsifier is the operator's own rule used as an instrument: forcing the probe port one port outside the grant reds the guard with no elevation and no policy edit. Run twice back to back: RED, RED. One red proves a timeout expired; two prove the design writes no state. The golden.yml steps themselves stay UNEXERCISED until the next golden run — thin CI compiles the cells and skips them, since Rig::from_env returns None without SPT_TWO_HOST. Today's in-situ runs are the field proof, cited by wall time, and the half is landed-pending-golden rather than verified by its own PR. Register-only. No code in this commit. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01WAw9XAcTR8oSwzYPsqZoY2 Co-authored by: hertz