98 lines
6.1 KiB
Markdown
98 lines
6.1 KiB
Markdown
|
|
# Attended disposable proof — 2026-09-27
|
||
|
|
|
||
|
|
Existing work: REINAH-WP-0003-T05/T06 and SECRETS-WP-0009-T03.
|
||
|
|
No new workplan, publication, automatic retry, or factory operating admission.
|
||
|
|
|
||
|
|
The operator accepted replacement spend memo `infd-20260927-b02`, confirmed
|
||
|
|
USD 10 including tax/conversion fees fits EUR 10, and accepted all six
|
||
|
|
`metered-20260927-{provider,worker}-{apply,verify,exec}` decisions. Native
|
||
|
|
submission confirmations and replacement host installation are separate receipts
|
||
|
|
in `docs/evidence/2026-09-27-metered-*.json`. The earlier expired spend grant is
|
||
|
|
preserved and never used.
|
||
|
|
|
||
|
|
`scripts/metered-native-owner.py` checks the frozen six-request packet and exact
|
||
|
|
recipient files before native claim/PDP checks. The provider's human-control
|
||
|
|
flag and the worker companion's ordinary flag remain unchanged. Apply and
|
||
|
|
verify each consume their own native approval before OpenBao effects. Exec
|
||
|
|
uses the existing Secrets Engine primary/companion consume and delivery code;
|
||
|
|
the procedure does not manufacture decisions, claims, or delivery state.
|
||
|
|
|
||
|
|
The attended workstation wrapper `scripts/attended-metered-proof.py` follows
|
||
|
|
the existing scoped approval-client reader and nested platform-admin OIDC
|
||
|
|
procedure. The operator-controlled SSH session runs the controller on Railiance
|
||
|
|
because the approved command and owner-file bindings name that host. Client
|
||
|
|
secret, short-lived operator/negative-test tokens and PDP caller token cross
|
||
|
|
encrypted SSH stdin only. The host uses a fresh owner-only temporary directory
|
||
|
|
on `/run/user/1000` tmpfs. Approval bearer tokens are minted in memory. No
|
||
|
|
cluster reader, persistent service, credential rotation or new custody path is
|
||
|
|
created. Warden self-revokes both attended sessions; private files and the
|
||
|
|
named-pod forwarding processes are removed on normal exit, including failure.
|
||
|
|
The delivered model child receives only its catalog-bound environment plus
|
||
|
|
its separately approved provider and worker credentials.
|
||
|
|
|
||
|
|
Before activation, the installer locks and checks all three old ledger tables,
|
||
|
|
refusing any prior reservation or liability. It preserves the old ledger and
|
||
|
|
backs up both old configuration files. A new private ledger is initialized
|
||
|
|
without resetting old evidence. Replacement file hashes retire dispatch using
|
||
|
|
the old catalog pins. The immutable runtime's backend-free owner check passes.
|
||
|
|
|
||
|
|
The single trigger occurs after both lanes verify. The controller waits for
|
||
|
|
exactly one open, unclaimed, attempt-zero task with the admitted profile and
|
||
|
|
one-file/one-commit/no-publication grant. It records trigger and exec intent
|
||
|
|
before either action. An existing execution receipt refuses all replays,
|
||
|
|
including uncertain/failed attempts. The scheduled definition stays disabled.
|
||
|
|
|
||
|
|
The approved maximum request hold remains USD 4.64; at most two such holds fit
|
||
|
|
the USD 10 liability cap. The [provider tariff](https://platform.claude.com/docs/en/about-claude/pricing)
|
||
|
|
was rechecked immediately before activation: Sonnet 5 global standard output is
|
||
|
|
USD 10/million tokens; the conservative input bound of USD 4/million covers
|
||
|
|
one-hour cache writes. The proof has no authority to enlarge these limits.
|
||
|
|
|
||
|
|
After interruption, inspect the durable local/remote receipts and native
|
||
|
|
consume state before any further action. Explicitly reconcile remaining
|
||
|
|
`metered-native-*` / `metered-attended-*` private runtime directories and any
|
||
|
|
open queue item; never rerun the command as a cleanup strategy. Hard-kill
|
||
|
|
cleanup is not claimed by this wrapper. Provider-request reservations remain
|
||
|
|
conservative until reconciled. T04's tenant migrations and broader T06
|
||
|
|
acceptance requirements remain in the existing workplan.
|
||
|
|
|
||
|
|
## Actual execution and corrections
|
||
|
|
|
||
|
|
All six decisions were accepted and consumed once. Both lane apply/verify
|
||
|
|
operations passed; exec delivered through two AppRole sessions whose revocation
|
||
|
|
succeeded. The single definition trigger initially produced a row with no grant:
|
||
|
|
the deployed Activity Core worker predated the API's grant-carriage support.
|
||
|
|
Activity Core `428f2d7` and Platform `c3607ff` changed only the worker image to
|
||
|
|
the already-deployed grant-aware API image through the existing GitOps parent
|
||
|
|
and child applications. Argo reports Synced/Healthy/Succeeded.
|
||
|
|
|
||
|
|
The explicit repair script validates and locks the original disabled definition
|
||
|
|
and original open, unclaimed, attempt-zero job. It copies only the exact typed
|
||
|
|
grant from that definition; it creates no row or trigger. Nine negative/positive
|
||
|
|
guard tests pass. This repair is recorded separately and is not represented as
|
||
|
|
successful natural grant carriage by the old producer.
|
||
|
|
|
||
|
|
The `resume` mode is limited to that recorded pre-execution queue-binding failure.
|
||
|
|
It verifies the four completed native actions, installed policies/role limits,
|
||
|
|
zero prior request/reservation counts, and the same repaired job. It repeats
|
||
|
|
neither apply/verify nor queue creation. Both remaining exec approvals were then
|
||
|
|
consumed. There is no further resume path for the attempted job.
|
||
|
|
|
||
|
|
Job `6efa9436-6a91-47c0-94e5-b31b5a0e7e3a` closed `failed`, attempt 1, with its
|
||
|
|
lease cleared. Its installed Python launchers still referenced a deleted build
|
||
|
|
directory: uv's long-path shell trampoline had escaped the builder's direct
|
||
|
|
shebang rewrite. A no-credential synthetic probe reproduced exit 127 for both
|
||
|
|
launchers inside the actual pinned bwrap artifact, with zero provider forwards.
|
||
|
|
The runtime builder correction is Sand-boxer `81b5fcf`; relocation tests execute
|
||
|
|
after the old build directory disappears. Rein now also rejects these launchers
|
||
|
|
before claim and retains bounded gateway stage/cleanup facts on accounting refusal.
|
||
|
|
|
||
|
|
The approved artifact itself remains unchanged. Sandbox `b67907f1` and its
|
||
|
|
workspace are destroyed; the repository is clean at its original commit, the
|
||
|
|
lock is available, and no close-outbox item or private credential directory is
|
||
|
|
left over. The request route is revoked and there are no provider-request
|
||
|
|
reservations. The parent EUR 10 reservation remains held; observed billing was
|
||
|
|
not invented and the ledger was not reset. A corrected artifact and its changed
|
||
|
|
pins need admission, held-liability reconciliation remains an owner action, and
|
||
|
|
another attempt requires separate authority. REINAH-WP-0003 stays blocked.
|