Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e332-3365-77c0-8491-084e9ea33ac1
239 lines
13 KiB
Markdown
239 lines
13 KiB
Markdown
---
|
||
id: LLM-WP-0009
|
||
type: workplan
|
||
title: "Owner-metered Messages transport for bounded factory execution"
|
||
domain: agents
|
||
repo: llm-connect
|
||
status: blocked
|
||
flavor: implementation
|
||
owner: codex
|
||
topic_slug: llm-connect
|
||
created: "2026-09-09"
|
||
updated: "2026-09-27"
|
||
related:
|
||
- HFACT-WP-0001
|
||
- REINAH-WP-0003
|
||
- GLAS-WP-0015
|
||
state_hub_workstream_id: "d396a090-c2ed-5042-aaea-b75fd1d3a471"
|
||
---
|
||
|
||
The factory's installed-CLI proof demonstrated native dollar-threshold overshoot.
|
||
Implement its accepted next source slice in the transport owner, reusing rein's
|
||
parent ledger. This workplan records implementation under the user's continued
|
||
factory programme; it grants no operating, custody, deployment or paid authority.
|
||
|
||
## Define request admission and implement the narrow transport
|
||
|
||
```task
|
||
id: LLM-WP-0009-T01
|
||
status: done
|
||
priority: high
|
||
state_hub_task_id: "a1d7a2f0-9b98-5c3a-8832-0e500b444059"
|
||
```
|
||
|
||
Implemented immutable policy/upper-rate liability, explicit owner meter protocol,
|
||
fixed-origin HTTPS Messages forwarding, strict supported features and beta
|
||
allowlist, bounded streaming, full-charge accounting and uncertain-outcome holds.
|
||
No retry, proxy discovery, redirect or existing /execute bypass exists on this
|
||
listener. See `contracts/functional/messages-admission.md`.
|
||
|
||
## Prove admission through the real consumer CLI with a fake provider
|
||
|
||
```task
|
||
id: LLM-WP-0009-T02
|
||
status: done
|
||
priority: high
|
||
state_hub_task_id: "abd0af2e-377a-5603-bea8-c0a760bdf242"
|
||
```
|
||
|
||
Rein's real HTTP/SQLite tests cover exhausted capacity, concurrent requests,
|
||
unknown prior outcomes, replay, revoked/expired leases and parent recovery.
|
||
The installed Claude Code 2.1.266 proof refuses the USD 0.01 counterexample with
|
||
zero upstream requests; a permitted two-request tool session creates its file.
|
||
No actual inference, provider credential or live price/FX policy is involved.
|
||
|
||
## Integrate the admitted owner route and prove production confinement
|
||
|
||
```task
|
||
id: LLM-WP-0009-T03
|
||
status: wait
|
||
priority: high
|
||
blocking_reason: "Corrected Railiance owner/code installation and synthetic two-request tool proof are complete. Remaining: accepted native spend grant/window with FX/tariffs and accounting continuity, regenerated recipient pins and attended per-lane delivery approvals, then real provider and natural queue/tool/commit/recovery evidence under SECRETS-WP-0009-T03, HFACT-WP-0001-T01/T03/T04/T05 and REINAH-WP-0003-T05/T06."
|
||
state_hub_task_id: "98a38d75-73ab-5f37-b710-5df9d9681e49"
|
||
```
|
||
|
||
Return to HFACT-WP-0001-T01 and REINAH-WP-0003-T05/T06: integrate this transport
|
||
inside the protected owner runtime, initialize the request extension explicitly,
|
||
bind a run-scoped route to the real lease, inject only its base URL/token into
|
||
the workload and revoke on lease loss. Keep the provider key and ledger outside
|
||
the sandbox, enforce sole egress through the owner, and prove bypass denial.
|
||
Pin accepted provider context/output and maximum tariffs with validity and FX;
|
||
review compatibility of the exact CLI/beta combination against the actual
|
||
provider before accepting a live profile. Local fake-provider evidence cannot
|
||
close this task or establish a hard live EUR ceiling. Reuse GLAS-WP-0015 identity
|
||
and native-delivery owner work; completed verifier CCRs are not reopened.
|
||
|
||
|
||
Pre-release quality return: configured repository-wide checks expose 177 Ruff
|
||
diagnostics and 36 mypy errors, reproduced identically at the original 00560945
|
||
source baseline. The new transport adds none after its protocol types were
|
||
completed. The 263 passing tests are not a claim of green full-repository CI.
|
||
Resolve or explicitly disposition those existing checks before an owner accepts
|
||
the protected artifact/release. Evidence:
|
||
`docs/evidence/2026-09-09-request-admission-quality.json`.
|
||
|
||
### Local owner-route integration return — 2026-09-09
|
||
|
||
`MessagesOwner` now starts an owner-only Unix Messages listener after the worker
|
||
reserves its parent envelope. The initial accepted Activity Core heartbeat supplies
|
||
its exact expiry, run, worker and attempt binding. Lease loss, timeout, signals,
|
||
gateway exceptions and normal exit revoke the route. A timer also enforces the
|
||
initial lease deadline; heartbeat renewal does not extend this first route.
|
||
Only the opaque token and namespace-local base URL reach the child. Provider key,
|
||
ledger and owner socket directory remain outside the workload's mounts and PID
|
||
namespace. The sandbox refuses direct egress, alternate credential delivery,
|
||
extra host mounts, consumer mismatches and additional sandboxes for this binding.
|
||
|
||
Real local bwrap tests prove sole-route forwarding, direct host/public-IP denial,
|
||
private-state absence, revocation with no second forward, and teardown. The actual
|
||
worker/Glas/bwrap/ledger path also imports its permitted fixture commit and replays
|
||
a lost terminal close without repeating the request or authoring. Queue, provider,
|
||
credential and authoring remain deterministic fixtures; factory attempts remain 0.
|
||
Worker suite: 377 passed, including installed CLI and real namespace tests.
|
||
Sand-boxer required `make check`: lint clean, 199 tests passed. LLM suite: 264
|
||
passed; changed transport adds no lint/type diagnostics, with existing full-repo
|
||
177 Ruff/36 mypy diagnostics still requiring pre-release disposition.
|
||
|
||
This closes local source route/lease/token/confinement wiring. Remaining return:
|
||
admitted owner bootstrap that supplies the provider key to `MessagesOwner`, matched
|
||
protected runtime/CLI artifact, Railiance host/profile/consumer/custody/recovery
|
||
admission, live provider compatibility and accepted bounds/tariffs/FX, then G0 and
|
||
natural model/queue evidence. No protected runtime was installed or promoted,
|
||
no existing CCR changed, no secret read or paid execution took place.
|
||
|
||
### Release quality and dependency reconciliation — 2026-09-27
|
||
|
||
Resolved the reproduced 177 Ruff findings and 36 mypy errors without disabling
|
||
repository-wide rules. Modernized annotations/imports, typed lazy adapter
|
||
constructors and cache entries, narrowed text-file modes and platform branches,
|
||
and declared the HTTP server's injected adapter. JSON boundary casts retain the
|
||
existing response contracts. The example's source-path bootstrap has an explicit
|
||
E402 exception; invalid-JSON server coverage now checks the returned error body.
|
||
Pytest explicitly includes the repository root so the example integration test
|
||
collects under both the pytest executable and module invocation. `make check`
|
||
now runs lint, typecheck and tests together: lint clean, all 35 source files type
|
||
check, **264 tests passed**. Evidence:
|
||
`docs/evidence/2026-09-27-request-admission-quality.json`.
|
||
|
||
Consumed newer owner evidence from
|
||
`../prj-helixforge-factory/operations/owner-bootstrap-admission.md` and
|
||
`../prj-helixforge-factory/evidence/2026-09-10-runtime-placement.json`.
|
||
The one-cycle bootstrap and protected artifact
|
||
`5371156d2027dde6e8f140cc0a1833c4e90b8c75b3bec862e05f06a957f5fd34`
|
||
were already installed and synthetically proved on workstation and Railiance.
|
||
These receipts supersede the earlier statement that no protected artifact had
|
||
been installed. They do not establish native service or credential admission.
|
||
Today's source quality changes are not installed in that immutable artifact;
|
||
any replacement needs a new source pin/build and the same artifact checks.
|
||
|
||
T03 remains `wait` and the workplan is `blocked` on these existing owner tasks:
|
||
|
||
| Remaining acceptance | Existing owner record |
|
||
| --- | --- |
|
||
| Exact recipient configuration and native provider-key delivery | SECRETS-WP-0009-T03 / HFACT-WP-0001-T03 |
|
||
| Service/profile/consumer admission, isolated queue and private-state recovery | HFACT-WP-0001-T04 / REINAH-WP-0003-T05 |
|
||
| Accepted live provider compatibility, bounds, maximum tariffs, validity, FX and G0 | HFACT-WP-0001-T01 |
|
||
| Admitted real model and natural queue proof | REINAH-WP-0003-T06 / HFACT-WP-0001-T05 |
|
||
|
||
No accepted live policy or native delivery receipt was found in the owning
|
||
records. Fixture inputs cannot substitute for them. Closing T03 would contradict
|
||
its explicit acceptance condition. No credential retrieval, paid request,
|
||
production mutation or profile activation was performed in this session.
|
||
|
||
### Direct cross-repository follow-up — 2026-09-27
|
||
|
||
Followed the user's instruction into secrets-engine, rein-aharness and the
|
||
factory project. The prior summary was stale: the dedicated metered worker
|
||
identity, private owner state and newer b6e4e8a4 runtime already exist.
|
||
The installed policy nevertheless reserved 200k tokens against Sonnet 5's 1M
|
||
context, refused the CLI's actual 64k output request and omitted its additional
|
||
primary-request beta. Its prior runtime proof always selected profile 1.0.0.
|
||
|
||
Corrected rein's proof to require the exact profile/model and record request
|
||
shape metadata. The real Railiance artifact now passes a synthetic Sonnet 5 /
|
||
profile 1.1.1 first response, zero-forward exhausted-capacity refusal, private
|
||
state exclusion, read-only unchanged artifact and cleanup. Prepared the corrected
|
||
owner config and source catalog pin, plus six exact unapproved action requests
|
||
in `../secrets-engine/docs/proposals/glas-metered-20260927/README.md`.
|
||
Secrets Engine's full suite passes 498 tests. The installed old policy is
|
||
explicitly refused by the new offline review; the candidate passes.
|
||
|
||
Maximum request hold is USD 4.64. Only one fits the existing USD 5.74 allowance;
|
||
a successful tool loop must not be promised under the current EUR 5 cap. The
|
||
candidate preserves all spend limits and the ledger. Source changes and owner
|
||
records are updated in their actual repositories. Corrected production config
|
||
installation and native action approvals remain pending; no secret read, paid
|
||
request or production owner mutation occurred. The broader useful-change G0 is
|
||
separate from this disposable Glas proof. Factory receipt:
|
||
`../prj-helixforge-factory/evidence/2026-09-27-metered-owner-followup.json`.
|
||
|
||
### Approved installation and tool-session proposal — 2026-09-27
|
||
|
||
The user approved the configuration/code update and separately requested preparation
|
||
of the €10 tool-session proposal. Installed Secrets Engine `11cc0d5` and corrected
|
||
owner `e0d3fb84` on Railiance; exact path/hash checks, substituted-command refusal,
|
||
standalone companion refusal and backend-free owner check pass. Standing worker,
|
||
spend limits and existing ledger are unchanged; no credentials read or paid calls.
|
||
Deployment receipt: `../secrets-engine/docs/evidence/2026-09-27-metered-owner-deployment.json`.
|
||
|
||
Actual pinned CLI/profile 1.1.1/runtime b6e4e8a4 passes a synthetic two-request Bash
|
||
tool/result exchange and zero-forward underfunded refusal, with teardown and
|
||
unchanged artifact. Receipt: `../rein-aharness/docs/evidence/2026-09-27-sonnet5-tool-session-proof.json`.
|
||
The inactive proposal is `../prj-helixforge-factory/operations/metered-tool-session-proposal.md`:
|
||
EUR 10 run cap, USD 10 liability, EUR/USD 1.00 treatment, existing native USD 5
|
||
threshold/daily EUR 20/total EUR 500 retained. Two USD 4.64 holds fit. Installed
|
||
0.87 FX is below the latest observed 0.876962 reference; fresh validity/FX acceptance
|
||
is required. No new grant or paid execution is authorized by proposal preparation.
|
||
|
||
Remaining owner tasks retain their waiting status: fresh spend grant/window,
|
||
accounting continuity and replacement recipient pins; attended native per-lane
|
||
approval/delivery/revocation; then natural queue/model/tool/commit/recovery proof.
|
||
This return supersedes earlier installation-pending statements, not those gates.
|
||
|
||
|
||
### Repository loose-end review — 2026-09-27
|
||
|
||
Reviewed all ten source workplans and their task blocks, including the four
|
||
legacy `completed` plans. Only T03 remains unfinished; there are no locally
|
||
ready, active or proposed tasks to implement. LLM-WP-0001 through LLM-WP-0008
|
||
and the historical ad-hoc plan have all tasks done. Normalized LLM-WP-0001–0004
|
||
to the canonical `finished` state without changing identities or task history.
|
||
|
||
Completed the local release-quality repairs described above and included them
|
||
in the repository commit: lint/type fixes, typed server/factory/cache boundaries,
|
||
pytest example imports, and the combined `make check` target. Removed the stale
|
||
installation-pending blocker from T03's structured record. Current synthetic
|
||
and deployment receipts establish the local completion; they do not satisfy
|
||
T03's explicit live acceptance. Retain `status: blocked` / task `wait` for the
|
||
existing native-spend, delivery and natural-run owner dependencies. No new task
|
||
or workplan was opened, and no paid or production action is part of this review.
|
||
|
||
## Repair historical source identities blocking primary synchronization
|
||
|
||
```task
|
||
id: LLM-WP-0009-T04
|
||
status: done
|
||
priority: medium
|
||
state_hub_task_id: "c9418f44-1ce6-5d72-b764-4865528caec1"
|
||
```
|
||
|
||
HFACT-WP-0001-T02 side quest: qualified 65 historical parent-local task IDs to
|
||
match their already-existing Hub record IDs across five finished workplans.
|
||
Preserved all workplan/task UUIDs, parent links, statuses and task content;
|
||
qualified local references and retained an exact before/after mapping in
|
||
`docs/evidence/2026-09-09-legacy-task-qualification.json`. This is source identity
|
||
repair, not a UUID migration, record recreation or retirement. Six missing
|
||
historical ad-hoc source bindings also resolve to existing matching Hub UUIDs;
|
||
only Repo Manager's managed-field write may restore those pointers. The
|
||
AGENTS.md versus registry prefix disagreement remains a future-instruction
|
||
issue; published workplan IDs are unchanged.
|