llm-connect/workplans/LLM-WP-0009-owner-metered-messages-transport.md

240 lines
13 KiB
Markdown
Raw Normal View History

---
id: LLM-WP-0009
type: workplan
title: "Owner-metered Messages transport for bounded factory execution"
domain: agents
repo: llm-connect
status: blocked
flavor: implementation
owner: codex
topic_slug: llm-connect
created: "2026-09-09"
updated: "2026-09-27"
related:
- HFACT-WP-0001
- REINAH-WP-0003
- GLAS-WP-0015
state_hub_workstream_id: "d396a090-c2ed-5042-aaea-b75fd1d3a471"
---
The factory's installed-CLI proof demonstrated native dollar-threshold overshoot.
Implement its accepted next source slice in the transport owner, reusing rein's
parent ledger. This workplan records implementation under the user's continued
factory programme; it grants no operating, custody, deployment or paid authority.
## Define request admission and implement the narrow transport
```task
id: LLM-WP-0009-T01
status: done
priority: high
state_hub_task_id: "a1d7a2f0-9b98-5c3a-8832-0e500b444059"
```
Implemented immutable policy/upper-rate liability, explicit owner meter protocol,
fixed-origin HTTPS Messages forwarding, strict supported features and beta
allowlist, bounded streaming, full-charge accounting and uncertain-outcome holds.
No retry, proxy discovery, redirect or existing /execute bypass exists on this
listener. See `contracts/functional/messages-admission.md`.
## Prove admission through the real consumer CLI with a fake provider
```task
id: LLM-WP-0009-T02
status: done
priority: high
state_hub_task_id: "abd0af2e-377a-5603-bea8-c0a760bdf242"
```
Rein's real HTTP/SQLite tests cover exhausted capacity, concurrent requests,
unknown prior outcomes, replay, revoked/expired leases and parent recovery.
The installed Claude Code 2.1.266 proof refuses the USD 0.01 counterexample with
zero upstream requests; a permitted two-request tool session creates its file.
No actual inference, provider credential or live price/FX policy is involved.
## Integrate the admitted owner route and prove production confinement
```task
id: LLM-WP-0009-T03
status: wait
priority: high
blocking_reason: "Corrected Railiance owner/code installation and synthetic two-request tool proof are complete. Remaining: accepted native spend grant/window with FX/tariffs and accounting continuity, regenerated recipient pins and attended per-lane delivery approvals, then real provider and natural queue/tool/commit/recovery evidence under SECRETS-WP-0009-T03, HFACT-WP-0001-T01/T03/T04/T05 and REINAH-WP-0003-T05/T06."
state_hub_task_id: "98a38d75-73ab-5f37-b710-5df9d9681e49"
```
Return to HFACT-WP-0001-T01 and REINAH-WP-0003-T05/T06: integrate this transport
inside the protected owner runtime, initialize the request extension explicitly,
bind a run-scoped route to the real lease, inject only its base URL/token into
the workload and revoke on lease loss. Keep the provider key and ledger outside
the sandbox, enforce sole egress through the owner, and prove bypass denial.
Pin accepted provider context/output and maximum tariffs with validity and FX;
review compatibility of the exact CLI/beta combination against the actual
provider before accepting a live profile. Local fake-provider evidence cannot
close this task or establish a hard live EUR ceiling. Reuse GLAS-WP-0015 identity
and native-delivery owner work; completed verifier CCRs are not reopened.
Pre-release quality return: configured repository-wide checks expose 177 Ruff
diagnostics and 36 mypy errors, reproduced identically at the original 00560945
source baseline. The new transport adds none after its protocol types were
completed. The 263 passing tests are not a claim of green full-repository CI.
Resolve or explicitly disposition those existing checks before an owner accepts
the protected artifact/release. Evidence:
`docs/evidence/2026-09-09-request-admission-quality.json`.
### Local owner-route integration return — 2026-09-09
`MessagesOwner` now starts an owner-only Unix Messages listener after the worker
reserves its parent envelope. The initial accepted Activity Core heartbeat supplies
its exact expiry, run, worker and attempt binding. Lease loss, timeout, signals,
gateway exceptions and normal exit revoke the route. A timer also enforces the
initial lease deadline; heartbeat renewal does not extend this first route.
Only the opaque token and namespace-local base URL reach the child. Provider key,
ledger and owner socket directory remain outside the workload's mounts and PID
namespace. The sandbox refuses direct egress, alternate credential delivery,
extra host mounts, consumer mismatches and additional sandboxes for this binding.
Real local bwrap tests prove sole-route forwarding, direct host/public-IP denial,
private-state absence, revocation with no second forward, and teardown. The actual
worker/Glas/bwrap/ledger path also imports its permitted fixture commit and replays
a lost terminal close without repeating the request or authoring. Queue, provider,
credential and authoring remain deterministic fixtures; factory attempts remain 0.
Worker suite: 377 passed, including installed CLI and real namespace tests.
Sand-boxer required `make check`: lint clean, 199 tests passed. LLM suite: 264
passed; changed transport adds no lint/type diagnostics, with existing full-repo
177 Ruff/36 mypy diagnostics still requiring pre-release disposition.
This closes local source route/lease/token/confinement wiring. Remaining return:
admitted owner bootstrap that supplies the provider key to `MessagesOwner`, matched
protected runtime/CLI artifact, Railiance host/profile/consumer/custody/recovery
admission, live provider compatibility and accepted bounds/tariffs/FX, then G0 and
natural model/queue evidence. No protected runtime was installed or promoted,
no existing CCR changed, no secret read or paid execution took place.
### Release quality and dependency reconciliation — 2026-09-27
Resolved the reproduced 177 Ruff findings and 36 mypy errors without disabling
repository-wide rules. Modernized annotations/imports, typed lazy adapter
constructors and cache entries, narrowed text-file modes and platform branches,
and declared the HTTP server's injected adapter. JSON boundary casts retain the
existing response contracts. The example's source-path bootstrap has an explicit
E402 exception; invalid-JSON server coverage now checks the returned error body.
Pytest explicitly includes the repository root so the example integration test
collects under both the pytest executable and module invocation. `make check`
now runs lint, typecheck and tests together: lint clean, all 35 source files type
check, **264 tests passed**. Evidence:
`docs/evidence/2026-09-27-request-admission-quality.json`.
Consumed newer owner evidence from
`../prj-helixforge-factory/operations/owner-bootstrap-admission.md` and
`../prj-helixforge-factory/evidence/2026-09-10-runtime-placement.json`.
The one-cycle bootstrap and protected artifact
`5371156d2027dde6e8f140cc0a1833c4e90b8c75b3bec862e05f06a957f5fd34`
were already installed and synthetically proved on workstation and Railiance.
These receipts supersede the earlier statement that no protected artifact had
been installed. They do not establish native service or credential admission.
Today's source quality changes are not installed in that immutable artifact;
any replacement needs a new source pin/build and the same artifact checks.
T03 remains `wait` and the workplan is `blocked` on these existing owner tasks:
| Remaining acceptance | Existing owner record |
| --- | --- |
| Exact recipient configuration and native provider-key delivery | SECRETS-WP-0009-T03 / HFACT-WP-0001-T03 |
| Service/profile/consumer admission, isolated queue and private-state recovery | HFACT-WP-0001-T04 / REINAH-WP-0003-T05 |
| Accepted live provider compatibility, bounds, maximum tariffs, validity, FX and G0 | HFACT-WP-0001-T01 |
| Admitted real model and natural queue proof | REINAH-WP-0003-T06 / HFACT-WP-0001-T05 |
No accepted live policy or native delivery receipt was found in the owning
records. Fixture inputs cannot substitute for them. Closing T03 would contradict
its explicit acceptance condition. No credential retrieval, paid request,
production mutation or profile activation was performed in this session.
### Direct cross-repository follow-up — 2026-09-27
Followed the user's instruction into secrets-engine, rein-aharness and the
factory project. The prior summary was stale: the dedicated metered worker
identity, private owner state and newer b6e4e8a4 runtime already exist.
The installed policy nevertheless reserved 200k tokens against Sonnet 5's 1M
context, refused the CLI's actual 64k output request and omitted its additional
primary-request beta. Its prior runtime proof always selected profile 1.0.0.
Corrected rein's proof to require the exact profile/model and record request
shape metadata. The real Railiance artifact now passes a synthetic Sonnet 5 /
profile 1.1.1 first response, zero-forward exhausted-capacity refusal, private
state exclusion, read-only unchanged artifact and cleanup. Prepared the corrected
owner config and source catalog pin, plus six exact unapproved action requests
in `../secrets-engine/docs/proposals/glas-metered-20260927/README.md`.
Secrets Engine's full suite passes 498 tests. The installed old policy is
explicitly refused by the new offline review; the candidate passes.
Maximum request hold is USD 4.64. Only one fits the existing USD 5.74 allowance;
a successful tool loop must not be promised under the current EUR 5 cap. The
candidate preserves all spend limits and the ledger. Source changes and owner
records are updated in their actual repositories. Corrected production config
installation and native action approvals remain pending; no secret read, paid
request or production owner mutation occurred. The broader useful-change G0 is
separate from this disposable Glas proof. Factory receipt:
`../prj-helixforge-factory/evidence/2026-09-27-metered-owner-followup.json`.
### Approved installation and tool-session proposal — 2026-09-27
The user approved the configuration/code update and separately requested preparation
of the €10 tool-session proposal. Installed Secrets Engine `11cc0d5` and corrected
owner `e0d3fb84` on Railiance; exact path/hash checks, substituted-command refusal,
standalone companion refusal and backend-free owner check pass. Standing worker,
spend limits and existing ledger are unchanged; no credentials read or paid calls.
Deployment receipt: `../secrets-engine/docs/evidence/2026-09-27-metered-owner-deployment.json`.
Actual pinned CLI/profile 1.1.1/runtime b6e4e8a4 passes a synthetic two-request Bash
tool/result exchange and zero-forward underfunded refusal, with teardown and
unchanged artifact. Receipt: `../rein-aharness/docs/evidence/2026-09-27-sonnet5-tool-session-proof.json`.
The inactive proposal is `../prj-helixforge-factory/operations/metered-tool-session-proposal.md`:
EUR 10 run cap, USD 10 liability, EUR/USD 1.00 treatment, existing native USD 5
threshold/daily EUR 20/total EUR 500 retained. Two USD 4.64 holds fit. Installed
0.87 FX is below the latest observed 0.876962 reference; fresh validity/FX acceptance
is required. No new grant or paid execution is authorized by proposal preparation.
Remaining owner tasks retain their waiting status: fresh spend grant/window,
accounting continuity and replacement recipient pins; attended native per-lane
approval/delivery/revocation; then natural queue/model/tool/commit/recovery proof.
This return supersedes earlier installation-pending statements, not those gates.
### Repository loose-end review — 2026-09-27
Reviewed all ten source workplans and their task blocks, including the four
legacy `completed` plans. Only T03 remains unfinished; there are no locally
ready, active or proposed tasks to implement. LLM-WP-0001 through LLM-WP-0008
and the historical ad-hoc plan have all tasks done. Normalized LLM-WP-0001–0004
to the canonical `finished` state without changing identities or task history.
Completed the local release-quality repairs described above and included them
in the repository commit: lint/type fixes, typed server/factory/cache boundaries,
pytest example imports, and the combined `make check` target. Removed the stale
installation-pending blocker from T03's structured record. Current synthetic
and deployment receipts establish the local completion; they do not satisfy
T03's explicit live acceptance. Retain `status: blocked` / task `wait` for the
existing native-spend, delivery and natural-run owner dependencies. No new task
or workplan was opened, and no paid or production action is part of this review.
## Repair historical source identities blocking primary synchronization
```task
id: LLM-WP-0009-T04
status: done
priority: medium
state_hub_task_id: "c9418f44-1ce6-5d72-b764-4865528caec1"
```
HFACT-WP-0001-T02 side quest: qualified 65 historical parent-local task IDs to
match their already-existing Hub record IDs across five finished workplans.
Preserved all workplan/task UUIDs, parent links, statuses and task content;
qualified local references and retained an exact before/after mapping in
`docs/evidence/2026-09-09-legacy-task-qualification.json`. This is source identity
repair, not a UUID migration, record recreation or retirement. Six missing
historical ad-hoc source bindings also resolve to existing matching Hub UUIDs;
only Repo Manager's managed-field write may restore those pointers. The
AGENTS.md versus registry prefix disagreement remains a future-instruction
issue; published workplan IDs are unchanged.