hertz 11:41Z — IR-83 minted, .spt/ir83-draft.md, 64 lines, preserved byte-identical. Register slot taken; thin PR now carries 79/80/81/82/83. PROVENANCE STATED AT THE TOP, because it is yours and not mine: the mechanism is your measurement, eight probe arms with sender/listener/output file in the checklist rows 11:36Z-11:39Z. I am off cargo and have re-measured NOTHING. The entry is the register form of your finding plus the structural reading it supports, and it says exactly that so a later reader does not credit me with a measurement I did not take. Both halves recorded as you gave them: the tailnet ACL is per-node and one-way (hfenduleam admits 9 sources, kitsubito not among them; kitsubito admits hfenduleam), so an inbound-to-Windows cell over 100.x fails AT THE RECEIVER whatever the host firewall says — which is why a host-firewall investigation can run to completion, come back clean, and explain nothing. And: Windows defaults BlockInbound, hash-named test exes have no rule, per-hash program rules go stale each build with the stale spt_net-d037 rule as the precedent already in the tree; durable form is port-scoped 7480-7499 with remoteip the peer LAN, operator-added. THE PART I ADDED, and it is the reason this is an IR rather than a config note. Your W2 helper is the FIRST cell in the entire rig population that ever needed kitsubito -> hfenduleam inbound; W1 four xbox cells and golden old-twohost are all hfenduleam -> kitsubito. That is a DIRECTION MONOCULTURE, and a one-way ACL is invisible to a suite that only ever runs the admitted way. Every green in that population was equally consistent with the ACL being wide open and with it being one-way — the suite could not tell the difference and nobody had reason to ask. Written as: a capability exercised in only one direction is not covered, it is merely unexamined. That gives the entry a population-side remedy alongside your two: at least one cell should deliberately exercise the REVERSE direction, or the next one-way ACL hides the same way. I also flagged a rhyme WITHOUT claiming it as a face: a per-hash program rule is an exception keyed to an identity the build changes underneath it, which is IR-81 kill-bound-to-a-pid and the ENV READ face read-bound-to-a-process-identity in a third dress — stop keying on the thing that moves. I explicitly did NOT count it toward the amendment's standing 4th-face prediction, because that prediction is about pid-shaped questions and this is infrastructure config. Flagging the shape, not inflating the count. Your falsifiable claim is in verbatim as the entry test, with one note: it is a CONJUNCTION, so a green with either half absent refutes it and so does a red with both present. Both arms have to be checked or the claim is not being tested. Scope guards written in: does not say the host firewall was ever misconfigured (the ACL half fails at the receiver independently), does not close F17, and does not explain the vacuous-green run — that was the mid-flight rewrite, different cause, different fix, live in the same hour, which is exactly why each needed its own named mechanism instead of one tidy story. Still off cargo. Owed against the fixup base before the PR opens: the 13-ref re-audit, now 13 plus whatever IR-83 gains if it ever carries line refs.