docs(glas): consume the protected local runtime installation proof
All checks were successful
ci / validate (push) Successful in 2m9s

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-08 22:04:48 +02:00
parent 57b98df52c
commit 0da175d2ab

View file

@ -345,3 +345,26 @@ This resolves candidate binary pin/startup, not protected runtime deployment,
Claude provider-request compatibility, credential delivery or a real model run.
The candidate is in /tmp; no production profile readiness changed. Existing
credential and acceptance tasks remain open. No new owner replies at session start.
## Protected local artifact return — 2026-09-08
SAND-WP-0015-T06 is done. The previously pinned combined artifact is installed
unchanged in owner UID 1000's mode-0700 runtime store on bnt-lap001:
`/home/worsch/.local/share/sandboxer/runtimes/5cf9a16c5d77a16bdb2cb5b3df06ea655356bc2d44741791e3fedfee20d7e922`.
Complete artifact digest remains
`5cf9a16c5d77a16bdb2cb5b3df06ea655356bc2d44741791e3fedfee20d7e922`.
This is the existing owner-controlled local artifact contract, not root-owned
system storage or Railiance placement. Do not rebuild this accepted candidate
merely to move it out of /tmp.
The installed-path sandbox `51b59587` proves actual Claude 2.1.263 and rein
startup, read-only runtime, source absence, clean Git, private state persistence,
loopback-only interfaces, and workspace/proxy removal. No credential references
or model request were used. Sand-boxer `make check`: lint clean, 188 tests pass.
Source return: 3e49a98a0e2c4a64539a5ccd674be8cd67ac9845; receipt in
`sand-boxer/docs/evidence/SAND-WP-0015-protected-local-install-2026-09-08.json`.
T02 remains wait for trusted owner execution configuration, native credentials
and real-provider evidence. T03-T06 retain candidate review, real-model run,
readiness and recovery obligations. No profile readiness or schedule changes.