test(twohost): ask whether B's datagrams reach A, before the ceremony does A golden run spent 900 s on each half discovering that B's datagrams never reached A: 75 QUIC dials, each dying on its 10 s bound, cadenced at exactly 12.00 s, never one ADMIT. Two layers were behind it and either alone produces the same silence — the receiver's per-executable host firewall, and an asymmetric tailnet ACL — so the failure was triaged as product, then as rig, before it was measured as box. These two cells ask that question first, in their own words, and the workflow runs them as their own step before the ceremony (inside one `cargo test` the cells are threads and nothing orders them). The probe IS the test binary, not a shell script beside it: the Windows rule is per-executable, so a probe written in pwsh or python would go green the moment anyone allowed the prober and would certify the exact failure it exists to catch. THERE IS NO SHARED CLOCK, so there is no fixed window. The step boundary orders the probe on ONE host; it does not align two. A fixed symmetric window adds a third cause that looks exactly like the other two — "the peer is not up yet" — and measured, not argued: the first hand-run of this probe redded INBOUND_BLOCKED at 10.24 s purely because cargo's start-up on the sender put its first datagram after the receiver's window closed. So the rendezvous is data: A listens up to the rig's own budget and beacons to B once a second; B binds before it sends, waits for a beacon, and only then starts a ten-second clock, so its red has already excluded "A is not up". A acks the first probe; B stops on the ack. THE LISTENING SOCKET NEVER SENDS, and that is the design rather than a detail. Every outbound datagram from the measured port opens stateful return state for it, so B's probe then arrives SOLICITED and crosses under both faults. Measured: with the beacon sharing the listening socket, an out-of-grant control (probe port forced to 7509, outside the operator's udp 7460-7499 rule) went GREEN — the probe certified a path a listen-only run had measured BLOCKED eight minutes earlier. B likewise sends from an ephemeral port, so no run repeats a 4-tuple a previous run opened and none can poison the next. The ack is addressed to B's rig port, not to the probe's source port. Also measured: acking to `from` leaves it unsolicited at B — it comes from A's ephemeral socket rather than the port B dialled — and a receiver whose inbound rule is a port RANGE drops it, so B reported INBOUND_BLOCKED on a link its own peer had just certified, A-side OK and B-side blocked in the same run. Four outcomes, four names: A's INBOUND_BLOCKED carries both layers and both operator fixes; B's INBOUND_BLOCKED is the fast one and says A is provably up; PROBE_NO_BEACON is a rendezvous failure and says so rather than blaming a firewall; and green is green. IN-SITU, both boxes, at this tree (2026-09-09, hfenduleam + kitsubito): dir 1 A=hfenduleam B=kitsubito udp 7489 GREEN, ack after 1 datagram dir 2 A=kitsubito B=hfenduleam udp 7489 GREEN, ack after 1 datagram control, probe port forced to 7509 (outside the operator's grant), run TWICE back to back: RED, RED — A after 40 s with 39 beacons sent, B in 10 s with 48 and 47 datagrams sent and no ack. Two consecutive reds are the proof that the design writes no state of its own; one would only have proved a timeout. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01WAw9XAcTR8oSwzYPsqZoY2 Co-authored by: hertz