diff --git a/workplans/ACTIVITY-WP-0032-glas-profile-execution-contract.md b/workplans/ACTIVITY-WP-0032-glas-profile-execution-contract.md index 22d70a0..78ae699 100644 --- a/workplans/ACTIVITY-WP-0032-glas-profile-execution-contract.md +++ b/workplans/ACTIVITY-WP-0032-glas-profile-execution-contract.md @@ -9,7 +9,7 @@ owner: claude topic_slug: activity-core priority: medium created: "2026-08-21" -updated: "2026-08-23" +updated: "2026-09-04" related: - ACT-ADR-006 - ACTIVITY-WP-0026 @@ -271,6 +271,22 @@ Returned to wait on upstream `GLAS-IN-0002`: the managed consumer is denied inside the sandbox. Resume after that contract is implemented; do not trigger another pilot until the upstream blocker changes. +Rechecked 2026-09-04. The blocker has not changed: State Hub intake +`01a02b76-f020-7d60-a3ce-12a34c13ebce` remains open, sand-boxer has no active +workplan for it, and both Glas local profiles explicitly report +`operational_readiness: blocked`. Sand-boxer still publishes only a PID and +workspace plus a consumer-side `nsenter` hint; its Glas integration prose has +not yet been reconciled with the proven permission failure. The bwrap profile +also contains no rein runtime and declares network default-deny with no egress. + +State Hub message `c57919ed-1cfd-491b-98a2-d72042ef10cb` asks sand-boxer to +promote the intake and deliver an owner-mediated execution boundary (or an +equivalent reviewed contract), in-sandbox runtime, explicit egress, identity +binding, and teardown proof. Credential delivery must use catalog references; +the open-weight lane is `rein-openweights-openrouter-approle`, whose current +delegation explicitly remains interim and lacks an owner-fronted read. No key +was requested or copied, and the disabled pilot remains untouched. + ## Acceptance - [x] Invocation shape decided and recorded as an ADR, with the boundary stated