Constrain controlled CLI sessions and prove native budget overshoot
Some checks failed
Governed runtime contract / contract (push) Failing after 27s

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-09 20:53:25 +02:00
parent e0b3ff99a2
commit 4ae245a88f
14 changed files with 752 additions and 10 deletions

View file

@ -654,6 +654,24 @@ installation and Railiance recovery proof. T06 remains `wait` for the admitted
real-model and natural queue run. No factory policy, paid execution, deployment,
profile promotion or G0 grant was created by this source change.
### Installed native CLI proof — 2026-09-09
Claude Code 2.1.266 was tested against a synthetic API in a private network
namespace. Its USD 0.01 stop threshold allowed one response estimated at USD
0.18015 before refusal, demonstrating why declared run reservations alone do not
supply a hard provider bound. Controlled native runs now restrict builtin tools,
use dontAsk and bare mode, suppress ambient settings/MCP, and require the tested
minimum version. Actual CLI tests prove permitted Git status and file creation,
forbidden shell denial, and no fixture hook/MCP/permission-override activation.
See [the executable proof](../docs/native-cli-boundary-proof.md).
T05 stays progress for the provider-facing request guard, protected rebuild and
owner admission. T06 stays wait for the real admitted model/natural queue proof.
Do not infer network/credential confinement from direct CLI tool rules: indirect
Git helpers remain inside the sandbox owner's responsibility. No paid request,
credential read or deployment was performed during the fixture proof.
## Re-prove one governed profiled run and close residuals
```task