fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
tegwick 2026-09-27 23:19:50 +02:00
parent 4e666d6fa3
commit 43e621439a
26 changed files with 1367 additions and 3 deletions

View file

@ -47,6 +47,9 @@ profile/descriptor digests, operational readiness, model, empty-egress bwrap pro
and runtime digest are checked before claim. Runtime, owner state and target checkout
must not overlap. Provision parent and request ledgers as separate reviewed actions.
The normal ACTIVITY_CORE/AGENT_HARNESS worker and state configuration still applies.
The governed Python console launchers must be executable regular files naming
`/opt/sandboxer/runtime/bin/python3`, rather than a build-host interpreter.
The installed bwrap proof also runs their `--help` commands before any model request.
This config is not an authorization decision or a custody provenance proof. The
invoking credential engine must already have passed its exact action approval,