Commit graph

41 commits

Author SHA1 Message Date
02b29af9ca fix(workplans): declare type: workplan on records the hub already holds
All checks were successful
ci / validate (push) Successful in 1m16s
These files carried no type field at all. Selection is by 'type: workplan', so
they were invisible to every projection while the hub held a record for each —
and a forge-derived reset read those correct records as no longer deriving and
queued them for retirement.

Only the type line is added.

Refs STATE-WP-0083-T05

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-26 20:56:02 +02:00
baeadb6b23 fix(workplans): move work-record identifiers onto the repository prefix
Some checks failed
ci / validate (push) Has been cancelled
Identifiers predating the PREFIX-WP-NNNN convention were rejected by the canon
registry, so none of this repository's work records could be registered.

One prefix per repository (ADR-007). Existing conforming identifiers keep their
numbers where possible; the pre-convention records take the next free numbers
rather than renumbering work that was already correct.

Projection UUIDs are re-derived from the new canonical ids (ADR-007 decision 2).
Nothing was registered on central under the old identifiers, so no hub record is
orphaned by this.

Refs CUST-WP-0068-T03

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 22:41:31 +02:00
1c657af28d fix(workplans): adopt ADR-007 derived identifiers
All checks were successful
ci / validate (push) Successful in 5m6s
Records absent from central carried random pre-ADR-007 identifiers minted by
the retired local hub, which C-06 refused as stale references. Deriving from
the canonical record id takes no identity from anything.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 19:30:12 +02:00
repo-manager
6bd2e10e6b chore(registrar): assign State Hub identifiers
All checks were successful
ci / validate (push) Successful in 1m15s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 12:54:19 +02:00
695438019c Harden SSH and profile resolution boundaries
Some checks failed
ci / validate (push) Has been cancelled
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 12:53:05 +02:00
repo-manager
60564fda68 chore(registrar): assign State Hub identifiers
All checks were successful
ci / validate (push) Successful in 1m14s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 11:59:04 +02:00
3aabd07347 Align operational handoff instructions
All checks were successful
ci / validate (push) Successful in 44s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 11:53:24 +02:00
repo-manager
ef245000b9 chore(registrar): assign State Hub identifiers
All checks were successful
ci / validate (push) Successful in 1m46s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 11:34:00 +02:00
cac605abd7 Make profile runtime readiness explicit
Some checks failed
ci / validate (push) Has been cancelled
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 11:32:23 +02:00
repo-manager
a224e71555 chore(registrar): assign State Hub identifiers
All checks were successful
ci / validate (push) Successful in 2m19s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 10:49:01 +02:00
13aea7ff6f docs: reconcile scope with verified capability
Some checks failed
ci / validate (push) Has been cancelled
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 10:47:02 +02:00
5bfc4a6a7d docs: record production namespace boundary proof
All checks were successful
ci / validate (push) Successful in 1m12s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 01:52:26 +02:00
repo-manager
4061ce860f chore(registrar): assign State Hub identifiers
All checks were successful
ci / validate (push) Successful in 3m49s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 01:46:52 +02:00
79bf88a3c4 fix: validate sandbox consumer actors early
Some checks failed
ci / validate (push) Has been cancelled
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-23 01:45:35 +02:00
ae2a706a68 docs: refresh sandbox owner handoff
All checks were successful
ci / validate (push) Successful in 3m20s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-22 23:56:56 +02:00
repo-manager
862292486d chore(registrar): assign State Hub identifiers
Some checks failed
ci / validate (push) Has been cancelled
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0233b-178d-7162-b92f-31a31ea8ca9b
2026-08-22 23:53:48 +02:00
3cb53ab310 docs: record green hardening CI [skip ci] 2026-08-21 10:59:17 +02:00
994b2daf1f test: isolate git identity in CI
All checks were successful
ci / validate (push) Successful in 2m3s
2026-08-21 10:56:14 +02:00
5c9724de45 chore: record sandbox hardening gate
Some checks failed
ci / validate (push) Failing after 2m48s
2026-08-21 10:41:29 +02:00
f773b5c101 fix: enforce sandbox execution boundary
Some checks failed
ci / validate (push) Has been cancelled
2026-08-21 10:40:29 +02:00
1cd890d871 feat: add versioned execution profiles
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-21 00:21:53 +02:00
f65260e9e3 Mark GLAS-0001 bootstrap workplan finished
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:02:49 +02:00
e574562b74 Mark GLAS-WP-0001/0002/0003 finished
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:01:05 +02:00
17adfe4d64 Close GLAS-WP-0002-T02: live OpenBao verification succeeded for real
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ops-mason built the real AppRole/policy/KV path infrastructure, the
founder completed provisioning, and a real task ran through
rein-openweights with OPENROUTER_API_KEY explicitly unset -- real
AppRole login, real KV v2 read, real OpenRouter call, real commit. Full
build record (including two real bugs found and fixed along the way)
in ops-mason/plans/rein-openweights-openrouter-approle.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:53:06 +02:00
d3130162b1 Formalize the CLI as the first Channel extension (GLAS-WP-0003)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
channels/base.py: GatewayInvocation dataclass + Channel ABC
(parse_invocation/render_result), mirroring Rein one layer up -- a
channel turns an external invocation into what run_task_through_rein
needs, and turns its result back into whatever the invocation medium
expects.

channels/cli_channel.py: CLIChannel, a pure refactor of what cli.py did
inline -- argparse Namespace -> GatewayInvocation, result dict ->
json.dumps(..., indent=2). cli.py's run handler is now a thin
construct-parse-invoke-render wrapper.

docs/channel-contract.md documents the pattern and sketches (without
building) a second channel.

Found and fixed a real bug while live-testing this refactor:
ReinAharness's default cli_bin was still "agent-harness", stale from
before HARNESS-WP-0002-T02's rename.

4 new tests (27/27 passing), plus a real live run through
python3 -m glas_harness.cli against rein-aharness/real Claude Code
confirming identical output shape and a real commit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 22:41:51 +02:00
aaf8cc5f7a Scope first channel extension as GLAS-WP-0003, closing GLAS-WP-0002-T04
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
GLAS-WP-0002 is now fully done (4/4): formalize the CLI as the first
Channel extension (contract + refactor + tests + second-channel
documentation), not building a second channel yet -- same
generalize-from-a-real-second-example discipline as ADR-002/ADR-004.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 20:23:48 +02:00
custodian-sync
6bac3c19e1 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-26:
  - workplan status: proposed → active
2026-07-26 20:23:06 +02:00
9bbff9d336 ADR-004: composable reins as middleware stays deferred (GLAS-WP-0002-T01)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Checked ADR-002 part 2's deferred question against the two observability
additions that landed since (rein-aharness's tool-event stream,
glas-harness's own gateway hub event) -- both turned out simpler as
direct implementations, neither needed a wrapping middleware layer.
Still zero real candidates for that shape. docs/harness-contract.md
gains the Middleware ABC as a documented, unimplemented sketch for if a
real third case ever appears -- no code written now.

Also flagged GLAS-WP-0002-T02 (live OpenBao verification) as blocked:
`bao token lookup` from this workstation returns 403, no usable vault
session to provision a new AppRole with. Needs the operator.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 20:22:55 +02:00
2925538b93 Wire the gateway's own State Hub reporting (GLAS-WP-0002-T03)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
hub.py mirrors the two reins' hub.py under author: agt-glas-harness.
run_task_through_rein gains report_to_hub (default True), posting one
gateway_run progress event from a finally block -- fires on both
success and failure, giving the gateway an audit trail independent of
whatever the rein itself reports. cli.py gained a matching --no-hub
flag.

Live-verified: ran a real task through ReinOpenWeights with hub
reporting enabled, confirmed the gateway_run event landed with correct
detail and a real commit sha. 4 new tests, 23/23 passing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 20:20:17 +02:00
a6bf746c21 Add GLAS-WP-0002: observability and composability follow-ups
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Bundles the four items surfaced while closing out GLAS-WP-0001/
HARNESS-WP-0002/SAND-WP-0013/REIN-OW-WP-0001: composable-reins-as-
middleware design (ADR-002 part 2), live-verifying rein-openweights'
OpenBao path, wiring the gateway's own State Hub reporting, and scoping
a first slice of glas-harness's remaining charter pillars. None were
blocking; all are worth doing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 20:13:26 +02:00
5520ba3ab2 Close out statehub-register bootstrap housekeeping (GLAS-0001)
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Refined the auto-generated SCOPE.md/AGENTS.md from generic templates
to real repo specifics, added a Developer Workflow section with
actual install/test/run commands. Real workplan (GLAS-WP-0001) was
already seeded and done.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 19:45:47 +02:00
bb2bbc70d7 Close GLAS-WP-0001-T04: live-prove the gateway against rein-aharness too
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Ran run_task_through_rein for real (user's explicit go-ahead) with
rein=ReinAharness(): real ext.bwrap sandbox, real kaizen-agentic schedule
prepare persona load, real claude --print --permission-mode acceptEdits
session under green-commit-only, real commit (8b63424a) in 11.4s,
verified via git rev-parse HEAD, sandbox torn down, executor-sandbox
untouched. Both reins now have a live end-to-end proof through the same
gateway code -- the parity proof this task and HARNESS-WP-0002 were
gated on. GLAS-WP-0001 is now fully done (6/6).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:52:24 +02:00
5ac81efd60 Record live proof: gateway -> bwrap sandbox -> ReinOpenWeights -> real OpenRouter -> verified commit
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
Ran run_task_through_rein for real (user's explicit go-ahead): profile.bwrap-local
sandbox, ReinOpenWeights against qwen/qwen-2.5-72b-instruct on the real
OpenRouter API. 2-turn tool-calling loop produced a real commit
(2effe57a), verified via git rev-parse HEAD, sandbox torn down,
executor-sandbox itself untouched. Proves the glas-harness -> sand-boxer
-> rein -> verified-commit path end-to-end for one rein; the same proof
against rein-aharness/Claude Code CLI specifically remains open (T04).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:46:05 +02:00
266f99a2fe Add ReinOpenWeights adapter, closing GLAS-WP-0001-T05
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
glas_harness/reins/rein_openweights.py implements the Rein ABC by
shelling out to `rein-openweights run --task-file ... --no-hub
[--model ...]`, mirroring reins/rein_aharness.py exactly. Factored the
duplicated git_head/write_task_file logic into reins/_shared.py, used
by both adapters now. registry/reins/rein-openweights.yaml flipped to
status: implemented. 8 new tests (mocked subprocess), 18/18 passing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:42:29 +02:00
603b7cfb9f Update T05: rein-openweights standalone loop done, glas-harness adapter still open
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
REIN-OW-WP-0001 T01-T04 landed in the rein-openweights repo. The
glas_harness/reins/rein_openweights.py adapter (mirroring
reins/rein_aharness.py) that actually plugs it into the gateway is the
remaining piece.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:37:38 +02:00
139b76e9c1 ADR-002: resolve credential brokering for rein-openweights (Option B)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
rein-openweights acquires its OpenRouter credential directly
(OpenBao/ops-warden), consistent with rein-aharness's existing
credential-holder principle — glas-harness does not broker
LLM-provider credentials. Confirmed llm-connect itself never brokers
credentials either (resolve_api_key() only reads an
already-materialized key from explicit/env/file), so routing through
llm-connect vs. a leaner wrapper doesn't change this. Composable reins
as middleware (monitoring/eval/optimization) is recorded as a separate,
deliberately deferred question in the same ADR — one candidate
capability isn't evidence of a recurring pattern yet.

GLAS-WP-0001-T06 done; T05 (bootstrap rein-openweights) unblocked.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:26:00 +02:00
custodian-sync
7aa029ffe8 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-26:
  - workplan status: proposed → active
2026-07-26 13:03:18 +02:00
5681fce787 Implement the harness contract and prove it against rein-aharness (GLAS-WP-0001-T02/T03/T04)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
- src/glas_harness/contract.py: Rein ABC (start_session/dispatch_tool/
  end_session), SandboxHandle/ToolCall/ToolResult, per docs/harness-contract.md.
- reins/rein_aharness.py: adapter around the rein-aharness CLI. Collapses
  a whole `agent-harness run` into one dispatch_tool call for now (no
  per-tool hooks yet — tracked in rein-aharness HARNESS-WP-0002-T03);
  verifies success via new-commit detection, mirroring rein-aharness's
  own success signal.
- gateway.py + cli.py: resolves a sand-boxer sandbox, runs one task
  through a rein, tears the sandbox down.
- registry/reins/*.yaml (rein-aharness implemented, rein-openweights
  planned) and profiles/harness.agent-dev{,-local}.yaml, pairing with
  sand-boxer's profile.agent-dev and the new profile.bwrap-local.

Tested against a real local git repo + mocked SandboxManager/CLI
subprocess (10 tests, all passing). A real live run against the actual
Claude Code CLI is deliberately left for a human-triggered follow-up —
not executed autonomously since it spends real API credits/credentials.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:02:59 +02:00
97a50fc780 Define the harness contract (GLAS-WP-0001-T01)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
start_session/dispatch_tool/end_session, mirroring sand-boxer's
SandboxExtension ABC one layer up: sand-boxer establishes where work
runs, this contract governs how an agent session runs on top of it.
Unblocks the rein-aharness parity proof (T04) and rein-openweights
bootstrap (T05).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:37:59 +02:00
7a3c8669c7 Fix ADR-001 workplan reference after HARNESS-WP-0002 rename
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:33:07 +02:00
c2a788aed9 Add ADR-001: rein harness family, and first workplan
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Establishes glas-harness as the framework routing between concrete
harness backends ("reins"): rein-aharness (renamed from agent-harness)
and the newly chartered rein-openweights. GLAS-WP-0001 defines the
harness contract, rein registry, and a minimal gateway proving parity
against rein-aharness.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:29:02 +02:00