Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
131 lines
6.3 KiB
Markdown
131 lines
6.3 KiB
Markdown
---
|
|
id: LLM-WP-0009
|
|
type: workplan
|
|
title: "Owner-metered Messages transport for bounded factory execution"
|
|
domain: agents
|
|
repo: llm-connect
|
|
status: active
|
|
owner: codex
|
|
topic_slug: llm-connect
|
|
created: "2026-09-09"
|
|
updated: "2026-09-09"
|
|
related:
|
|
- HFACT-WP-0001
|
|
- REINAH-WP-0003
|
|
- GLAS-WP-0015
|
|
state_hub_workstream_id: "d396a090-c2ed-5042-aaea-b75fd1d3a471"
|
|
---
|
|
|
|
The factory's installed-CLI proof demonstrated native dollar-threshold overshoot.
|
|
Implement its accepted next source slice in the transport owner, reusing rein's
|
|
parent ledger. This workplan records implementation under the user's continued
|
|
factory programme; it grants no operating, custody, deployment or paid authority.
|
|
|
|
## Define request admission and implement the narrow transport
|
|
|
|
```task
|
|
id: LLM-WP-0009-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "a1d7a2f0-9b98-5c3a-8832-0e500b444059"
|
|
```
|
|
|
|
Implemented immutable policy/upper-rate liability, explicit owner meter protocol,
|
|
fixed-origin HTTPS Messages forwarding, strict supported features and beta
|
|
allowlist, bounded streaming, full-charge accounting and uncertain-outcome holds.
|
|
No retry, proxy discovery, redirect or existing /execute bypass exists on this
|
|
listener. See `contracts/functional/messages-admission.md`.
|
|
|
|
## Prove admission through the real consumer CLI with a fake provider
|
|
|
|
```task
|
|
id: LLM-WP-0009-T02
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "abd0af2e-377a-5603-bea8-c0a760bdf242"
|
|
```
|
|
|
|
Rein's real HTTP/SQLite tests cover exhausted capacity, concurrent requests,
|
|
unknown prior outcomes, replay, revoked/expired leases and parent recovery.
|
|
The installed Claude Code 2.1.266 proof refuses the USD 0.01 counterexample with
|
|
zero upstream requests; a permitted two-request tool session creates its file.
|
|
No actual inference, provider credential or live price/FX policy is involved.
|
|
|
|
## Integrate the admitted owner route and prove production confinement
|
|
|
|
```task
|
|
id: LLM-WP-0009-T03
|
|
status: wait
|
|
priority: high
|
|
blocking_reason: "Local Unix hosting, worker lease/token lifecycle and bwrap confinement proved; requires admitted credential-to-owner bootstrap, matched protected artifact and Railiance custody/placement under HFACT T03/T04; live tariff/FX and G0 remain HFACT T01."
|
|
state_hub_task_id: "98a38d75-73ab-5f37-b710-5df9d9681e49"
|
|
```
|
|
|
|
Return to HFACT-WP-0001-T01 and REINAH-WP-0003-T05/T06: integrate this transport
|
|
inside the protected owner runtime, initialize the request extension explicitly,
|
|
bind a run-scoped route to the real lease, inject only its base URL/token into
|
|
the workload and revoke on lease loss. Keep the provider key and ledger outside
|
|
the sandbox, enforce sole egress through the owner, and prove bypass denial.
|
|
Pin accepted provider context/output and maximum tariffs with validity and FX;
|
|
review compatibility of the exact CLI/beta combination against the actual
|
|
provider before accepting a live profile. Local fake-provider evidence cannot
|
|
close this task or establish a hard live EUR ceiling. Reuse GLAS-WP-0015 identity
|
|
and native-delivery owner work; completed verifier CCRs are not reopened.
|
|
|
|
|
|
Pre-release quality return: configured repository-wide checks expose 177 Ruff
|
|
diagnostics and 36 mypy errors, reproduced identically at the original 00560945
|
|
source baseline. The new transport adds none after its protocol types were
|
|
completed. The 263 passing tests are not a claim of green full-repository CI.
|
|
Resolve or explicitly disposition those existing checks before an owner accepts
|
|
the protected artifact/release. Evidence:
|
|
`docs/evidence/2026-09-09-request-admission-quality.json`.
|
|
|
|
### Local owner-route integration return — 2026-09-09
|
|
|
|
`MessagesOwner` now starts an owner-only Unix Messages listener after the worker
|
|
reserves its parent envelope. The initial accepted Activity Core heartbeat supplies
|
|
its exact expiry, run, worker and attempt binding. Lease loss, timeout, signals,
|
|
gateway exceptions and normal exit revoke the route. A timer also enforces the
|
|
initial lease deadline; heartbeat renewal does not extend this first route.
|
|
Only the opaque token and namespace-local base URL reach the child. Provider key,
|
|
ledger and owner socket directory remain outside the workload's mounts and PID
|
|
namespace. The sandbox refuses direct egress, alternate credential delivery,
|
|
extra host mounts, consumer mismatches and additional sandboxes for this binding.
|
|
|
|
Real local bwrap tests prove sole-route forwarding, direct host/public-IP denial,
|
|
private-state absence, revocation with no second forward, and teardown. The actual
|
|
worker/Glas/bwrap/ledger path also imports its permitted fixture commit and replays
|
|
a lost terminal close without repeating the request or authoring. Queue, provider,
|
|
credential and authoring remain deterministic fixtures; factory attempts remain 0.
|
|
Worker suite: 377 passed, including installed CLI and real namespace tests.
|
|
Sand-boxer required `make check`: lint clean, 199 tests passed. LLM suite: 264
|
|
passed; changed transport adds no lint/type diagnostics, with existing full-repo
|
|
177 Ruff/36 mypy diagnostics still requiring pre-release disposition.
|
|
|
|
This closes local source route/lease/token/confinement wiring. Remaining return:
|
|
admitted owner bootstrap that supplies the provider key to `MessagesOwner`, matched
|
|
protected runtime/CLI artifact, Railiance host/profile/consumer/custody/recovery
|
|
admission, live provider compatibility and accepted bounds/tariffs/FX, then G0 and
|
|
natural model/queue evidence. No protected runtime was installed or promoted,
|
|
no existing CCR changed, no secret read or paid execution took place.
|
|
|
|
## Repair historical source identities blocking primary synchronization
|
|
|
|
```task
|
|
id: LLM-WP-0009-T04
|
|
status: done
|
|
priority: medium
|
|
state_hub_task_id: "c9418f44-1ce6-5d72-b764-4865528caec1"
|
|
```
|
|
|
|
HFACT-WP-0001-T02 side quest: qualified 65 historical parent-local task IDs to
|
|
match their already-existing Hub record IDs across five finished workplans.
|
|
Preserved all workplan/task UUIDs, parent links, statuses and task content;
|
|
qualified local references and retained an exact before/after mapping in
|
|
`docs/evidence/2026-09-09-legacy-task-qualification.json`. This is source identity
|
|
repair, not a UUID migration, record recreation or retirement. Six missing
|
|
historical ad-hoc source bindings also resolve to existing matching Hub UUIDs;
|
|
only Repo Manager's managed-field write may restore those pointers. The
|
|
AGENTS.md versus registry prefix disagreement remains a future-instruction
|
|
issue; published workplan IDs are unchanged.
|