docs: record enforced provider egress acceptance
All checks were successful
ci / validate (push) Successful in 3m12s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-05 22:08:18 +02:00
parent 13027544f4
commit 0c3d8e1a88
2 changed files with 34 additions and 0 deletions

View file

@ -202,3 +202,12 @@ One version-pinned local profile runs its actual rein/model task entirely in
the declared sandbox, produces validated local output, and tears down cleanly.
Its readiness describes the proven runtime scope. Other profile readiness and
consumer schedules remain independently governed.
## 2026-09-05 egress owner return
Owner-controlled HTTPS egress is implemented and live-tested through both the
extension and a persisted manager: provider TLS/HTTP response, undeclared-host
and direct-IP denial, isolated namespace and proxy/workspace cleanup passed.
See [egress evidence](../docs/evidence/GLAS-WP-0012-egress-2026-09-05.md).
T02 remains waiting on machine auth, protected credential delivery, the pinned
Claude executable and the combined production acceptance. Profiles remain blocked.