Build the deterministic three-party and NAT-topology integration harness #14
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent: #1
Depends on: #13, #25
Outcome
Prove the real service + host + client lifecycle, not merely isolated serializers or a reported NAT callback.
Scope
Acceptance criteria
Starting implementation on a stacked branch from verified TestClient commit
7e3be2c.Plan: inventory existing deterministic topology coverage, build the always-on three-party harness through TestClient script mode, add state-driven adverse lifecycle and candidate-selection scenarios, add an opt-in Linux namespace/container topology gate where permissions allow, document emulation limits, then run adversarial review and full Debug/Release/integration cleanup gates.
Implemented and pushed on
codex/issue-14-integration-harnessat2ff7cd6(stacked on #25).Delivered:
Adversarial branch audit: all P0-P3 findings resolved across architecture/API, correctness/security/lifecycle, and tests/performance/CI lenses.
Verification:
CAP_NET_ADMINis unavailable; CI executes it when its exact bridge/veth/sysctl/MASQUERADE/conntrack preflight succeedsThe issue remains open while the dependency stack is completed and landed.