Point the OpenRouter cycle at memo version 3.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Fresh receipts use the new approval IDs. A matching live policy and AppRole
skips apply without claiming that approval. A difference fails closed.

Assistant: grok
Assistant-Session: 01a0e2a1-8058-7553-9999-b7d106c17047
This commit is contained in:
codex 2026-09-27 15:33:09 +02:00
parent 1cd546e77c
commit 53825190ca
5 changed files with 47 additions and 17 deletions

View file

@ -1,8 +1,11 @@
# T03 continuation after Railiance Clock deployment
The original requests expired unconsumed. Replacement request IDs and immutable
memo version 2 are recorded in the creation receipt and Secrets Engine workplan.
The exact apply/verify/exec action requests and checker pins are unchanged.
The 2026-09-16 requests were consumed. The next cycle uses three new approval
IDs and immutable memo version 3. The creation receipt is
`docs/evidence/2026-09-27-t03-approval-requests.json`; execution receipts are
`secrets-engine/docs/evidence/2026-09-27-t03-native-execution.json` and
`docs/evidence/2026-09-27-t03-attended-delivery.json`. The exact
apply/verify/exec action requests and checker pins are unchanged.
Run the requester and execution worker with
`/home/worsch/secrets-engine/.venv/bin/python`; this environment includes Clock,
@ -20,6 +23,6 @@ The outer lane remains secrets-engine-approval-client-login; its reviewed
Both retain their own self-revocation and private runtime cleanup.
Human review: https://decisions.coulomb.social/review?memo_id=SECRETS-WP-0010-T03-apply
(and identifiers ending -verify and -exec). Version 2 is required. The requester
has no approval or consume scope; no human entries are copied from version 1.
(and identifiers ending -verify and -exec). Version 3 is required. The requester
has no approval or consume scope; no human entries are copied from version 2.
No execution may begin before the new approvals pass native claim/PDP checks.