Done when: EgressRefusedException maps to exit 77 for every CLI command (a System.CommandLine handler in BuildRootCommand, redacted message kept) with a process-level twin on one EG-PROC-09 command; a Roslyn convention fact lists the production Initiator = writers (PkgCommand.cs, NativeBundle.cs, SneakernetTransport.cs) and fails on any other production file, with its cert-gate row; HasNetworkOffRun rejects -v/--mount values naming the daemon socket or pipe or an absolute root (twin rows, the probe inverted); docker exec into an Ashlar-started --network=none session is either recognised as Host through a verifiable chain or recorded as a limit, per the owner's answer (review §10 new (a), (b)). Mutations in spec007-explicit-egress.json, lines quoted.
Why: review M4, M5, M6 and write-down F6/F7. Partly blocked on the owner (exit-77 scope; docker exec).
Source: REVIEW-2026-10-11.md on claude/spec-007-pr4-workspace (_handoff/spec-007-pr4/). Claim on the agent-bus (#695) with Kind: claim, About: card-<this issue> before working it.
Done when:
EgressRefusedExceptionmaps to exit 77 for every CLI command (a System.CommandLine handler inBuildRootCommand, redacted message kept) with a process-level twin on one EG-PROC-09 command; a Roslyn convention fact lists the productionInitiator =writers (PkgCommand.cs,NativeBundle.cs,SneakernetTransport.cs) and fails on any other production file, with its cert-gate row;HasNetworkOffRunrejects-v/--mountvalues naming the daemon socket or pipe or an absolute root (twin rows, the probe inverted);docker execinto an Ashlar-started--network=nonesession is either recognised as Host through a verifiable chain or recorded as a limit, per the owner's answer (review §10 new (a), (b)). Mutations inspec007-explicit-egress.json, lines quoted.Why: review M4, M5, M6 and write-down F6/F7. Partly blocked on the owner (exit-77 scope;
docker exec).Source: REVIEW-2026-10-11.md on
claude/spec-007-pr4-workspace(_handoff/spec-007-pr4/). Claim on the agent-bus (#695) withKind: claim,About: card-<this issue>before working it.