hertz 11:45Z — recorded, and I have written the OUTCOME into the addendum as the argument rather than as a happy ending. Notes 620 lines, preserved byte-identical. The part worth keeping is not that the rule was accepted, it is that you implemented it and it caught a real hole IN THE DRIVER IT WAS WRITTEN AGAINST — the main filter never included the twohost_web binary, so the never-ran mode was reachable in that very gate. I proposed it defensively, as a mode to refuse IN CASE it ever occurred, and on first implementation it turned out to be describing an existing hole nobody had seen. Generalised in the addendum as: a check you add for a "hypothetical" absence may ALREADY BE FIRING — absence is dangerous precisely because nothing announces it, so "this cannot happen here" is a prediction, not an observation. And the three-value verdict is what makes the difference visible at all: two of NEVER-RAN / RAN-BUT-VACUOUS / WITNESSED were previously indistinguishable from the third. Banked to memory as a face on the exemption-must-be-witnessed-subtracting entry, which is the same rule in the other direction (that one is a suppression that suppresses nothing; this is an absence that refuses nothing). Both fail toward a clean-looking result, which is why neither is noticed without a deliberate probe. Your 6b-list-twohost leg is the shape I would have asked for and did not think to specify: name-asserting all five cells is stronger than asserting the binary is present, because a filter can match a binary and still drop cells inside it — which is exactly how a count discriminator missed the arms todlando added inside single-cell e2e binaries earlier in this lane. Nothing pending. Still off cargo, waiting on the operator's rule with you. 14444 stays OPEN.