FI-WP-0005 T01-T03: owner declaration, publication decision, egress hosts.
- Owner declaration for the profiled fi-daily-research-brief (proposed): inputs, single-commit briefs/** grant, fast-forward-only publication, quality rules, model requirements without env selection, completion evidence and rollback pins. - Decision: origin publication is a typed grant on the run, not an executor default. - docs/sources-egress.yaml: 17 exact host:443 entries for the sandbox, tested for sand-boxer format and drift against the prose allowlist. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 51320@bnt-lap001 Assistant-Session: 9d40b4c7-8e3c-42ee-b755-d658d4640d6c
This commit is contained in:
parent
7009521fdc
commit
5c5c298643
8 changed files with 396 additions and 4 deletions
60
docs/decisions/2026-09-22-brief-origin-publication.md
Normal file
60
docs/decisions/2026-09-22-brief-origin-publication.md
Normal file
|
|
@ -0,0 +1,60 @@
|
|||
# Decision: Origin publication of daily briefs is an explicit, typed grant
|
||||
|
||||
**Date:** 2026-09-22
|
||||
**Status:** accepted
|
||||
**Decided by:** Bernd Worsch (operator), FI owner
|
||||
**Affects:** `activity-definitions/fi-daily-research-brief.md`,
|
||||
`activity-definitions/fi-daily-research-brief.declaration.yaml`, FI-WP-0005
|
||||
**Supersedes:** the grant wording in FI-WP-0004-T04, which granted "origin
|
||||
publication as a named capability of `fi-research-brief`". That capability
|
||||
lived inside one rein command. This decision moves it to the queued run's
|
||||
repository grant.
|
||||
|
||||
---
|
||||
|
||||
## Context
|
||||
|
||||
A brief day counts only when the brief is on `origin/main` (FI-WP-0004). The
|
||||
executor therefore has to push. rein-aharness (`d0b45acb`, REINAH-WP-0003-T04)
|
||||
requires that publication be a separate, owner-approved decision, not a
|
||||
default of the executor. activity-core repository-grant v1 is local-only and
|
||||
rejects `publish: true`.
|
||||
|
||||
## Decision
|
||||
|
||||
1. **FI grants publication, scoped exactly:**
|
||||
- remote `origin`, ref `main`
|
||||
- mode **fast-forward only**: no force push, no other refs, no tags
|
||||
- only commits whose changes stay within `briefs/**`
|
||||
- at most one commit per run
|
||||
2. **The grant rides on the run, not the executor.** It is carried as
|
||||
activity-core repository-grant v2 `publication` (requested in FI-WP-0005-T04).
|
||||
No rein, profile or tool may publish FI content without that grant on the
|
||||
claimed `ops_run`.
|
||||
3. **Failure semantics:**
|
||||
- Push rejected or failed: the run fails, no `fi_daily_brief` is posted,
|
||||
and the day stays due.
|
||||
- Non-fast-forward (origin moved): the executor may rebase its single
|
||||
brief commit onto the new origin head once, then retry. A second failure
|
||||
is a failed run. It never merges and never forces.
|
||||
- Success requires `origin_sha` evidence, and activity-core close
|
||||
reconciliation checks it against the grant.
|
||||
4. **Until grant v2 is live**, the compatibility path (`rein-aharness
|
||||
fi-research-brief`, commit `11020e8`) continues under FI-WP-0004-T04 semantics.
|
||||
It ends at cutover (FI-WP-0005-T08) or at the legacy expiry, whichever
|
||||
comes first.
|
||||
|
||||
## Not granted
|
||||
|
||||
- Writes outside `briefs/**`. The catalog, inventory, workplans and docs stay
|
||||
human- or workplan-driven.
|
||||
- Publication to any other remote or mirror.
|
||||
- Opening PRs or issues, or posting to other external systems.
|
||||
|
||||
## Consequences
|
||||
|
||||
- activity-core needs grant v2 and origin-SHA close evidence (FI-WP-0005-T04).
|
||||
- The Glas tool profile must be able to push, but only under a grant
|
||||
(FI-WP-0005-T05).
|
||||
- `scripts/verify_brief_durability.py` remains the independent audit of the
|
||||
result.
|
||||
|
|
@ -3,6 +3,11 @@
|
|||
Standing channels for Freedom Intelligence briefs (axes A–D). Prefer **primary**
|
||||
sources over aggregators. This is a watchlist, not a scrape mandate.
|
||||
|
||||
Automated runs reach the network only through the hosts in
|
||||
[`sources-egress.yaml`](sources-egress.yaml) (FI-WP-0005-T03). Adding a
|
||||
channel here that needs a new host means adding that host there too;
|
||||
`scripts/test_sources_egress.py` checks the two stay in step.
|
||||
|
||||
---
|
||||
|
||||
## Axis A — Frontier & commercial
|
||||
|
|
|
|||
99
docs/sources-egress.yaml
Normal file
99
docs/sources-egress.yaml
Normal file
|
|
@ -0,0 +1,99 @@
|
|||
# Network egress for the daily research brief sandbox (FI-WP-0005-T03).
|
||||
#
|
||||
# Machine-readable companion to docs/sources-allowlist.md. The Glas profile
|
||||
# for fi-daily-research-brief declares exactly these hosts in
|
||||
# network.egress (default: deny). The model provider route is NOT listed
|
||||
# here; it belongs to the profile (glas-harness), not to FI.
|
||||
#
|
||||
# sand-boxer rules (docs/bwrap-egress.md): exact lowercase DNS names, port 443
|
||||
# only, no wildcards, no IP literals. Enforcement is by destination, not by
|
||||
# path: every host below is a whole-host trust decision. Keep the list minimal.
|
||||
#
|
||||
# `channel` must appear verbatim in docs/sources-allowlist.md
|
||||
# (scripts/test_sources_egress.py enforces this so the two cannot drift).
|
||||
version: 1
|
||||
hosts:
|
||||
# Axis A — frontier & commercial
|
||||
- host: openai.com:443
|
||||
axes: [A]
|
||||
channel: OpenAI / Anthropic / Google / xAI / DeepSeek blogs & release notes
|
||||
why: Release notes, model pages, API pricing. Returned 403 to a plain
|
||||
client on 2026-09-22 (bot protection); may be unreadable unattended.
|
||||
- host: www.anthropic.com:443
|
||||
axes: [A]
|
||||
channel: OpenAI / Anthropic / Google / xAI / DeepSeek blogs & release notes
|
||||
why: News and model announcements (apex redirects here).
|
||||
- host: platform.claude.com:443
|
||||
axes: [A]
|
||||
channel: Model cards for API models
|
||||
why: Model overview, context limits, pricing tables (docs.anthropic.com
|
||||
now 301-redirects here, 2026-09-22).
|
||||
- host: blog.google:443
|
||||
axes: [A]
|
||||
channel: OpenAI / Anthropic / Google / xAI / DeepSeek blogs & release notes
|
||||
why: Gemini release announcements.
|
||||
- host: ai.google.dev:443
|
||||
axes: [A]
|
||||
channel: Official pricing pages
|
||||
why: Gemini API models and pricing.
|
||||
- host: x.ai:443
|
||||
axes: [A]
|
||||
channel: OpenAI / Anthropic / Google / xAI / DeepSeek blogs & release notes
|
||||
why: Grok release notes. Returned 403 to a plain client on 2026-09-22.
|
||||
- host: api-docs.deepseek.com:443
|
||||
axes: [A, B]
|
||||
channel: OpenAI / Anthropic / Google / xAI / DeepSeek blogs & release notes
|
||||
why: DeepSeek news, API pricing and model list.
|
||||
- host: arena.ai:443
|
||||
axes: [A]
|
||||
channel: LMSYS / Arena / artificialanalysis-class charts
|
||||
why: Directional leaderboard only; note gaming risk (lmarena.ai
|
||||
301-redirects here, 2026-09-22).
|
||||
- host: artificialanalysis.ai:443
|
||||
axes: [A]
|
||||
channel: LMSYS / Arena / artificialanalysis-class charts
|
||||
why: Price/performance charts, directional.
|
||||
- host: www.swebench.com:443
|
||||
axes: [A, D]
|
||||
channel: SWE-bench Verified / Live leaderboards
|
||||
why: Harness+model pairs.
|
||||
# Axis B — edge / local / open
|
||||
- host: huggingface.co:443
|
||||
axes: [B, C]
|
||||
channel: Hugging Face org feeds
|
||||
why: Model cards, licenses, sizes via /api/models. No weight download
|
||||
(weight CDN hosts are deliberately absent).
|
||||
- host: ollama.com:443
|
||||
axes: [B]
|
||||
channel: llama.cpp, vLLM, MLX, Ollama release notes
|
||||
why: Ollama library and release notes.
|
||||
# Axes B/C/D — GitHub-hosted releases (llama.cpp, vLLM, MLX, Unsloth, TRL,
|
||||
# OpenHands, Aider, SWE-agent, OpenCode, Cline, ...)
|
||||
- host: github.com:443
|
||||
axes: [B, C, D]
|
||||
channel: OpenHands, Aider, SWE-agent, OpenCode, Cline repos/releases
|
||||
why: Release pages for runtimes, training tools and harnesses.
|
||||
- host: api.github.com:443
|
||||
axes: [B, C, D]
|
||||
channel: llama.cpp, vLLM, MLX, Ollama release notes
|
||||
why: Structured release listing instead of scraping HTML.
|
||||
# Axis C — training & specialization
|
||||
- host: arxiv.org:443
|
||||
axes: [C]
|
||||
channel: arXiv cs.LG, cs.CL, cs.AI (recent)
|
||||
why: Abstracts and listings.
|
||||
- host: export.arxiv.org:443
|
||||
axes: [C]
|
||||
channel: arXiv cs.LG, cs.CL, cs.AI (recent)
|
||||
why: arXiv query API (the sanctioned programmatic endpoint).
|
||||
# Axis D — harness & fleet
|
||||
- host: modelcontextprotocol.io:443
|
||||
axes: [D]
|
||||
channel: MCP / tool-protocol standards
|
||||
why: MCP specification and changelog.
|
||||
# Deliberately absent:
|
||||
# - Model provider API hosts (profile-owned route).
|
||||
# - Hugging Face / GitHub content CDNs (no weight or asset download in briefs).
|
||||
# - Social media / X (allowlist: rumor is not confirmation).
|
||||
# - Internal Coulomb repos (sand-boxer, activity-core): read from the
|
||||
# checked-out workspace or hub, not over the network.
|
||||
Loading…
Add table
Add a link
Reference in a new issue