|
D-125 egress gate executed (throwaway VM, as ruled): bridge-in PROVEN, upstream NAT egress fails -- gate OPEN pending one sudo measurement
Run 1 was a test artifact (probe used DHCP; uplink /24 has no <dhcp> by design -- DOCFIX queued for the gate wording). Run 2 static: gateway ping 3/3 across the nested bridge = the D-125 property PASSES; 1.1.1.1 fails for ICMP and TCP alike. Controls pass and net-dumpxml shows the working/failing NATs are substantively identical, so the suspect is vcloud's live virbr4 rules, not the design -- double-NAT fallback deliberately NOT invoked. Probe guest + temp addresses removed. CURRENT-STATE updated in this commit (GA-R1/C1). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KiUu1oqt76tWvV4vEC3NAr |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/d125-egress-gate-20260720.txt 0 → 100644 |
|---|
| docs/changelog-20260719-dc0-deploy-stepB.md |
|---|