== Enclave network-test — dedicated-IP identity == ports (ENCLAVE_PORTS): http:8000=33277,tcp:7777=7777 egress (ENCLAVE_EGRESS): socks5h://0x1295fd214f126a4e0da29a47d8418362473136eaf289847a61518a07f717134e:****@127.0.0.1:1080 [1] identity (SOCKS BND.ADDR, platform-derived): 2a01:4f9:c013:9b52:ae:a479:7f98:6b87 [2] explicit egress fetch (icanhazip.com): internet sees 2a01:4f9:c013:9b52:ae:a479:7f98:6b87 [3] transparent fetch (unmodified std::net): internet sees 2a01:4f9:c013:9b52:ae:a479:7f98:6b87 -> matches [1]: outbound is transparently source-tagged (phase 2 live) [4] loopback dial 127.0.0.1:8080: CONNECTED (io: Ok(64)) — pre-phase-2 posture (raw inherit-network still granted) [4b] same dial via connect_timeout: CONNECTED with I/O — raw network is open (pre-phase-2) On an egress-enabled enclave with the phase-2 toolchain: [1] == [2] == [3], [4] denied — one stable IPv6 identity in both directions (this page is served on that same address via the tcp6-relay), with no way to egress off-identity.