{
  "version": 1,
  "messageId": "ddb5e56a-2c5f-4fb5-8ad0-ac93ef021a15",
  "from": "lead",
  "to": "live-controller",
  "kind": "message",
  "body": "NEW SUCCESSOR SEAL REQUIRED. Live attempt 1 using digest 3fba... exited 1 before ledger/mutation because `/proc/1/ns/net` was PermissionError inside bwrap. Containment receipt SHA `28392825e18bffca461af6f0ea3c77e9f6b20b3a100ce7756143e3efa4f9dbd4`; ledger/execution absent; PID/start and critical hashes unchanged; old authorization attempted and NON-REUSABLE. Source fix is already in current combined tree: detached bootstrap now uses `verify_network_isolation` on current `/proc/net`, permits only loopback interfaces/routes; new failing-first test added. Runtime toggle: host DENY, real bwrap `BWRAP_NETWORK_ISOLATED`. Strict gates: 66 tests; Ruff 27 formatted/lint PASS; basedpyright 0/0/0; ty PASS; no-excuse 27 clean; LSP clean. Preserve old preseal/package bytes and all rejected attempts. Freeze a NEW manifest-last successor in NEW immutable paths with a NEW digest/phrase and exact verifier. Include live-attempt failure/supersession evidence. Manifest last, zero bound writes afterward, run exact verifier yourself. Do not execute live or reuse 3fba phrase.",
  "timestamp": 1787872051916,
  "summary": "Seal network-gate successor after contained live failure"
}
