fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
parent
4e666d6fa3
commit
43e621439a
26 changed files with 1367 additions and 3 deletions
|
|
@ -47,6 +47,9 @@ profile/descriptor digests, operational readiness, model, empty-egress bwrap pro
|
|||
and runtime digest are checked before claim. Runtime, owner state and target checkout
|
||||
must not overlap. Provision parent and request ledgers as separate reviewed actions.
|
||||
The normal ACTIVITY_CORE/AGENT_HARNESS worker and state configuration still applies.
|
||||
The governed Python console launchers must be executable regular files naming
|
||||
`/opt/sandboxer/runtime/bin/python3`, rather than a build-host interpreter.
|
||||
The installed bwrap proof also runs their `--help` commands before any model request.
|
||||
|
||||
This config is not an authorization decision or a custody provenance proof. The
|
||||
invoking credential engine must already have passed its exact action approval,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue