fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
parent
4e666d6fa3
commit
43e621439a
26 changed files with 1367 additions and 3 deletions
97
docs/native-metered-proof.md
Normal file
97
docs/native-metered-proof.md
Normal file
|
|
@ -0,0 +1,97 @@
|
|||
# Attended disposable proof — 2026-09-27
|
||||
|
||||
Existing work: REINAH-WP-0003-T05/T06 and SECRETS-WP-0009-T03.
|
||||
No new workplan, publication, automatic retry, or factory operating admission.
|
||||
|
||||
The operator accepted replacement spend memo `infd-20260927-b02`, confirmed
|
||||
USD 10 including tax/conversion fees fits EUR 10, and accepted all six
|
||||
`metered-20260927-{provider,worker}-{apply,verify,exec}` decisions. Native
|
||||
submission confirmations and replacement host installation are separate receipts
|
||||
in `docs/evidence/2026-09-27-metered-*.json`. The earlier expired spend grant is
|
||||
preserved and never used.
|
||||
|
||||
`scripts/metered-native-owner.py` checks the frozen six-request packet and exact
|
||||
recipient files before native claim/PDP checks. The provider's human-control
|
||||
flag and the worker companion's ordinary flag remain unchanged. Apply and
|
||||
verify each consume their own native approval before OpenBao effects. Exec
|
||||
uses the existing Secrets Engine primary/companion consume and delivery code;
|
||||
the procedure does not manufacture decisions, claims, or delivery state.
|
||||
|
||||
The attended workstation wrapper `scripts/attended-metered-proof.py` follows
|
||||
the existing scoped approval-client reader and nested platform-admin OIDC
|
||||
procedure. The operator-controlled SSH session runs the controller on Railiance
|
||||
because the approved command and owner-file bindings name that host. Client
|
||||
secret, short-lived operator/negative-test tokens and PDP caller token cross
|
||||
encrypted SSH stdin only. The host uses a fresh owner-only temporary directory
|
||||
on `/run/user/1000` tmpfs. Approval bearer tokens are minted in memory. No
|
||||
cluster reader, persistent service, credential rotation or new custody path is
|
||||
created. Warden self-revokes both attended sessions; private files and the
|
||||
named-pod forwarding processes are removed on normal exit, including failure.
|
||||
The delivered model child receives only its catalog-bound environment plus
|
||||
its separately approved provider and worker credentials.
|
||||
|
||||
Before activation, the installer locks and checks all three old ledger tables,
|
||||
refusing any prior reservation or liability. It preserves the old ledger and
|
||||
backs up both old configuration files. A new private ledger is initialized
|
||||
without resetting old evidence. Replacement file hashes retire dispatch using
|
||||
the old catalog pins. The immutable runtime's backend-free owner check passes.
|
||||
|
||||
The single trigger occurs after both lanes verify. The controller waits for
|
||||
exactly one open, unclaimed, attempt-zero task with the admitted profile and
|
||||
one-file/one-commit/no-publication grant. It records trigger and exec intent
|
||||
before either action. An existing execution receipt refuses all replays,
|
||||
including uncertain/failed attempts. The scheduled definition stays disabled.
|
||||
|
||||
The approved maximum request hold remains USD 4.64; at most two such holds fit
|
||||
the USD 10 liability cap. The [provider tariff](https://platform.claude.com/docs/en/about-claude/pricing)
|
||||
was rechecked immediately before activation: Sonnet 5 global standard output is
|
||||
USD 10/million tokens; the conservative input bound of USD 4/million covers
|
||||
one-hour cache writes. The proof has no authority to enlarge these limits.
|
||||
|
||||
After interruption, inspect the durable local/remote receipts and native
|
||||
consume state before any further action. Explicitly reconcile remaining
|
||||
`metered-native-*` / `metered-attended-*` private runtime directories and any
|
||||
open queue item; never rerun the command as a cleanup strategy. Hard-kill
|
||||
cleanup is not claimed by this wrapper. Provider-request reservations remain
|
||||
conservative until reconciled. T04's tenant migrations and broader T06
|
||||
acceptance requirements remain in the existing workplan.
|
||||
|
||||
## Actual execution and corrections
|
||||
|
||||
All six decisions were accepted and consumed once. Both lane apply/verify
|
||||
operations passed; exec delivered through two AppRole sessions whose revocation
|
||||
succeeded. The single definition trigger initially produced a row with no grant:
|
||||
the deployed Activity Core worker predated the API's grant-carriage support.
|
||||
Activity Core `428f2d7` and Platform `c3607ff` changed only the worker image to
|
||||
the already-deployed grant-aware API image through the existing GitOps parent
|
||||
and child applications. Argo reports Synced/Healthy/Succeeded.
|
||||
|
||||
The explicit repair script validates and locks the original disabled definition
|
||||
and original open, unclaimed, attempt-zero job. It copies only the exact typed
|
||||
grant from that definition; it creates no row or trigger. Nine negative/positive
|
||||
guard tests pass. This repair is recorded separately and is not represented as
|
||||
successful natural grant carriage by the old producer.
|
||||
|
||||
The `resume` mode is limited to that recorded pre-execution queue-binding failure.
|
||||
It verifies the four completed native actions, installed policies/role limits,
|
||||
zero prior request/reservation counts, and the same repaired job. It repeats
|
||||
neither apply/verify nor queue creation. Both remaining exec approvals were then
|
||||
consumed. There is no further resume path for the attempted job.
|
||||
|
||||
Job `6efa9436-6a91-47c0-94e5-b31b5a0e7e3a` closed `failed`, attempt 1, with its
|
||||
lease cleared. Its installed Python launchers still referenced a deleted build
|
||||
directory: uv's long-path shell trampoline had escaped the builder's direct
|
||||
shebang rewrite. A no-credential synthetic probe reproduced exit 127 for both
|
||||
launchers inside the actual pinned bwrap artifact, with zero provider forwards.
|
||||
The runtime builder correction is Sand-boxer `81b5fcf`; relocation tests execute
|
||||
after the old build directory disappears. Rein now also rejects these launchers
|
||||
before claim and retains bounded gateway stage/cleanup facts on accounting refusal.
|
||||
|
||||
The approved artifact itself remains unchanged. Sandbox `b67907f1` and its
|
||||
workspace are destroyed; the repository is clean at its original commit, the
|
||||
lock is available, and no close-outbox item or private credential directory is
|
||||
left over. The request route is revoked and there are no provider-request
|
||||
reservations. The parent EUR 10 reservation remains held; observed billing was
|
||||
not invented and the ledger was not reset. A corrected artifact and its changed
|
||||
pins need admission, held-liability reconciliation remains an owner action, and
|
||||
another attempt requires separate authority. REINAH-WP-0003 stays blocked.
|
||||
Loading…
Add table
Add a link
Reference in a new issue