docs: record sandbox runtime implementation and remaining auth gates
All checks were successful
ci / validate (push) Successful in 2m34s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-05 20:36:58 +02:00
parent ce37e1cb63
commit 9fa17dd39b
3 changed files with 41 additions and 0 deletions

View file

@ -84,6 +84,16 @@ proofs pass. No rein installation in the source checkout, host home mount,
credential injection from the interactive shell, or unrestricted network
substitution is an acceptance path.
2026-09-05 owner progress: SAND-WP-0015 implemented digest-pinned standalone
Python runtime mounting and private namespace state. Real rein CLI startup,
read-only runtime, source absence, clean worktree, state persistence across
exec calls, and teardown passed in sandbox d4de9531; sand-boxer lint and 132
tests pass. This completes the candidate runtime mechanism, not production
selection. Authentication lane, credential delivery/revocation, provider egress,
pinning the Claude executable, and deployed profile review remain open. The
credential catalog has no matching Anthropic/Claude workload lane; the user's
authentication choice is pending. See docs/local-profile-acceptance.md.
## Review and validate the versioned Glas proof candidate
```task