D-125 egress isolation gate: PASS / CLOSED -- bridge-in proven end to end (2 identical runs)
Measurement disproved the missing-rule hypothesis first: operator-run nft
dumps show virbr4 structurally identical to the working virbr11, with all
three masquerade rules present INCLUDING the generic one, already fired --
so the pre-staged net-destroy/net-start was correctly not run. Matrix
re-probe: gateway ping 0, internet ping 0, curl 1.1.1.1 301, curl
archive.ubuntu.com 200, twice. Run-2's one-off ICMP failure recorded
UNEXPLAINED rather than swept. Side observation kept: the WAN segment
cannot reach the Office1 LAN through the ISP NAT (D-122/SEC-010 intent
holding) -- queued as an explicit hardening assertion.
CURRENT-STATE position + G10 row updated in this commit (GA-R1/C1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KiUu1oqt76tWvV4vEC3NAr
1 parent 792ca48 commit fa0c5c8688bd85a3db7389691998826490781eb5
@JANeumatrix JANeumatrix authored 20 hours ago
Showing 3 changed files
View
docs/CURRENT-STATE.md
View
docs/audit/d125-egress-gate-20260720-matrix.txt 0 → 100644
View
docs/changelog-20260719-dc0-deploy-stepB.md