llm-connect/workplans/LLM-WP-0009-owner-metered-messages-transport.md
tegwick 718e6730e4
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Provide a private Unix listener for owner-metered Messages
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 22:20:55 +02:00

6.3 KiB

id type title domain repo status owner topic_slug created updated related state_hub_workstream_id
LLM-WP-0009 workplan Owner-metered Messages transport for bounded factory execution agents llm-connect active codex llm-connect 2026-09-09 2026-09-09
HFACT-WP-0001
REINAH-WP-0003
GLAS-WP-0015
d396a090-c2ed-5042-aaea-b75fd1d3a471

The factory's installed-CLI proof demonstrated native dollar-threshold overshoot. Implement its accepted next source slice in the transport owner, reusing rein's parent ledger. This workplan records implementation under the user's continued factory programme; it grants no operating, custody, deployment or paid authority.

Define request admission and implement the narrow transport

id: LLM-WP-0009-T01
status: done
priority: high
state_hub_task_id: "a1d7a2f0-9b98-5c3a-8832-0e500b444059"

Implemented immutable policy/upper-rate liability, explicit owner meter protocol, fixed-origin HTTPS Messages forwarding, strict supported features and beta allowlist, bounded streaming, full-charge accounting and uncertain-outcome holds. No retry, proxy discovery, redirect or existing /execute bypass exists on this listener. See contracts/functional/messages-admission.md.

Prove admission through the real consumer CLI with a fake provider

id: LLM-WP-0009-T02
status: done
priority: high
state_hub_task_id: "abd0af2e-377a-5603-bea8-c0a760bdf242"

Rein's real HTTP/SQLite tests cover exhausted capacity, concurrent requests, unknown prior outcomes, replay, revoked/expired leases and parent recovery. The installed Claude Code 2.1.266 proof refuses the USD 0.01 counterexample with zero upstream requests; a permitted two-request tool session creates its file. No actual inference, provider credential or live price/FX policy is involved.

Integrate the admitted owner route and prove production confinement

id: LLM-WP-0009-T03
status: wait
priority: high
blocking_reason: "Local Unix hosting, worker lease/token lifecycle and bwrap confinement proved; requires admitted credential-to-owner bootstrap, matched protected artifact and Railiance custody/placement under HFACT T03/T04; live tariff/FX and G0 remain HFACT T01."
state_hub_task_id: "98a38d75-73ab-5f37-b710-5df9d9681e49"

Return to HFACT-WP-0001-T01 and REINAH-WP-0003-T05/T06: integrate this transport inside the protected owner runtime, initialize the request extension explicitly, bind a run-scoped route to the real lease, inject only its base URL/token into the workload and revoke on lease loss. Keep the provider key and ledger outside the sandbox, enforce sole egress through the owner, and prove bypass denial. Pin accepted provider context/output and maximum tariffs with validity and FX; review compatibility of the exact CLI/beta combination against the actual provider before accepting a live profile. Local fake-provider evidence cannot close this task or establish a hard live EUR ceiling. Reuse GLAS-WP-0015 identity and native-delivery owner work; completed verifier CCRs are not reopened.

Pre-release quality return: configured repository-wide checks expose 177 Ruff diagnostics and 36 mypy errors, reproduced identically at the original 00560945 source baseline. The new transport adds none after its protocol types were completed. The 263 passing tests are not a claim of green full-repository CI. Resolve or explicitly disposition those existing checks before an owner accepts the protected artifact/release. Evidence: docs/evidence/2026-09-09-request-admission-quality.json.

Local owner-route integration return — 2026-09-09

MessagesOwner now starts an owner-only Unix Messages listener after the worker reserves its parent envelope. The initial accepted Activity Core heartbeat supplies its exact expiry, run, worker and attempt binding. Lease loss, timeout, signals, gateway exceptions and normal exit revoke the route. A timer also enforces the initial lease deadline; heartbeat renewal does not extend this first route. Only the opaque token and namespace-local base URL reach the child. Provider key, ledger and owner socket directory remain outside the workload's mounts and PID namespace. The sandbox refuses direct egress, alternate credential delivery, extra host mounts, consumer mismatches and additional sandboxes for this binding.

Real local bwrap tests prove sole-route forwarding, direct host/public-IP denial, private-state absence, revocation with no second forward, and teardown. The actual worker/Glas/bwrap/ledger path also imports its permitted fixture commit and replays a lost terminal close without repeating the request or authoring. Queue, provider, credential and authoring remain deterministic fixtures; factory attempts remain 0. Worker suite: 377 passed, including installed CLI and real namespace tests. Sand-boxer required make check: lint clean, 199 tests passed. LLM suite: 264 passed; changed transport adds no lint/type diagnostics, with existing full-repo 177 Ruff/36 mypy diagnostics still requiring pre-release disposition.

This closes local source route/lease/token/confinement wiring. Remaining return: admitted owner bootstrap that supplies the provider key to MessagesOwner, matched protected runtime/CLI artifact, Railiance host/profile/consumer/custody/recovery admission, live provider compatibility and accepted bounds/tariffs/FX, then G0 and natural model/queue evidence. No protected runtime was installed or promoted, no existing CCR changed, no secret read or paid execution took place.

Repair historical source identities blocking primary synchronization

id: LLM-WP-0009-T04
status: done
priority: medium
state_hub_task_id: "c9418f44-1ce6-5d72-b764-4865528caec1"

HFACT-WP-0001-T02 side quest: qualified 65 historical parent-local task IDs to match their already-existing Hub record IDs across five finished workplans. Preserved all workplan/task UUIDs, parent links, statuses and task content; qualified local references and retained an exact before/after mapping in docs/evidence/2026-09-09-legacy-task-qualification.json. This is source identity repair, not a UUID migration, record recreation or retirement. Six missing historical ad-hoc source bindings also resolve to existing matching Hub UUIDs; only Repo Manager's managed-field write may restore those pointers. The AGENTS.md versus registry prefix disagreement remains a future-instruction issue; published workplan IDs are unchanged.