Add owner-metered Messages transport with conservative admission
Assistant: codex Assistant-Model: gpt-5.6-luna Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
00560945f8
commit
526e073e28
5 changed files with 878 additions and 0 deletions
69
workplans/LLM-WP-0009-owner-metered-messages-transport.md
Normal file
69
workplans/LLM-WP-0009-owner-metered-messages-transport.md
Normal file
|
|
@ -0,0 +1,69 @@
|
|||
---
|
||||
id: LLM-WP-0009
|
||||
type: workplan
|
||||
title: "Owner-metered Messages transport for bounded factory execution"
|
||||
domain: agents
|
||||
repo: llm-connect
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: llm-connect
|
||||
created: "2026-09-09"
|
||||
updated: "2026-09-09"
|
||||
related:
|
||||
- HFACT-WP-0001
|
||||
- REINAH-WP-0003
|
||||
- GLAS-WP-0015
|
||||
---
|
||||
|
||||
The factory's installed-CLI proof demonstrated native dollar-threshold overshoot.
|
||||
Implement its accepted next source slice in the transport owner, reusing rein's
|
||||
parent ledger. This workplan records implementation under the user's continued
|
||||
factory programme; it grants no operating, custody, deployment or paid authority.
|
||||
|
||||
## Define request admission and implement the narrow transport
|
||||
|
||||
```task
|
||||
id: LLM-WP-0009-T01
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Implemented immutable policy/upper-rate liability, explicit owner meter protocol,
|
||||
fixed-origin HTTPS Messages forwarding, strict supported features and beta
|
||||
allowlist, bounded streaming, full-charge accounting and uncertain-outcome holds.
|
||||
No retry, proxy discovery, redirect or existing /execute bypass exists on this
|
||||
listener. See `contracts/functional/messages-admission.md`.
|
||||
|
||||
## Prove admission through the real consumer CLI with a fake provider
|
||||
|
||||
```task
|
||||
id: LLM-WP-0009-T02
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Rein's real HTTP/SQLite tests cover exhausted capacity, concurrent requests,
|
||||
unknown prior outcomes, replay, revoked/expired leases and parent recovery.
|
||||
The installed Claude Code 2.1.266 proof refuses the USD 0.01 counterexample with
|
||||
zero upstream requests; a permitted two-request tool session creates its file.
|
||||
No actual inference, provider credential or live price/FX policy is involved.
|
||||
|
||||
## Integrate the admitted owner route and prove production confinement
|
||||
|
||||
```task
|
||||
id: LLM-WP-0009-T03
|
||||
status: wait
|
||||
priority: high
|
||||
blocking_reason: "Requires trusted owner hosting and actual lease/token delivery, provider custody and direct-route denial under HFACT T03/T04; accepted tariff/FX and G0 remain HFACT T01."
|
||||
```
|
||||
|
||||
Return to HFACT-WP-0001-T01 and REINAH-WP-0003-T05/T06: integrate this transport
|
||||
inside the protected owner runtime, initialize the request extension explicitly,
|
||||
bind a run-scoped route to the real lease, inject only its base URL/token into
|
||||
the workload and revoke on lease loss. Keep the provider key and ledger outside
|
||||
the sandbox, enforce sole egress through the owner, and prove bypass denial.
|
||||
Pin accepted provider context/output and maximum tariffs with validity and FX;
|
||||
review compatibility of the exact CLI/beta combination against the actual
|
||||
provider before accepting a live profile. Local fake-provider evidence cannot
|
||||
close this task or establish a hard live EUR ceiling. Reuse GLAS-WP-0015 identity
|
||||
and native-delivery owner work; completed verifier CCRs are not reopened.
|
||||
Loading…
Add table
Add a link
Reference in a new issue