Close local runtime loose ends and record external blockers
Some checks failed
Governed runtime contract / contract (push) Failing after 15s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
tegwick 2026-09-27 17:46:34 +02:00
parent e18e386e0e
commit 73aaa4bcd4
8 changed files with 752 additions and 24 deletions

View file

@ -4,13 +4,13 @@ type: workplan
title: "Governed runtime integrity and intent convergence"
domain: infotech
repo: rein-aharness
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: rein-aharness
priority: high
created: "2026-08-23"
updated: "2026-09-09"
updated: "2026-09-27"
related:
- REIN-A-0004
- GLAS-IN-0002
@ -517,7 +517,7 @@ Freedom Intelligence `d0b45acb-0002-405b-9620-cc44568170fb`, Binky
```task
id: REINAH-WP-0003-T05
status: progress
status: wait
priority: high
state_hub_task_id: "c4a3f08f-2874-5672-9f29-aecddd697d90"
```
@ -691,6 +691,34 @@ runtime installation. LLM-WP-0009-T03 retains the transport integration return;
T06 remains wait for admitted real-model/natural-queue evidence. No production
policy, listener, credential, deployment or paid attempt was created.
### Exact profile return — 2026-09-27
Followed LLM-WP-0009 dependencies into the current Secrets Engine and target.
ACTIVITY-WP-0039 now supplies the dedicated live metered identity; owner config,
private ledgers and runtime b6e4e8a4 are already provisioned on Railiance.
The previous proof script always resolved profile 1.0.0, so its September 23
receipt did not prove the new Sonnet 5 profile. Corrected the script to require
`--profile-ref` and `--expected-model`, check both, echo the selected model in
fake provider responses and record only request-shape metadata.
The real target proof now passes with profile 1.1.1 / Sonnet 5 / CLI 2.1.266:
one fake forward, zero on insufficient capacity, bootstrap empty fake queue,
route revocation, private-state exclusion, read-only artifact and clean teardown.
Receipt: `docs/evidence/2026-09-27-sonnet5-runtime-proof.json`.
The narrowed Sonnet 5 fixture rejects manual thinking/non-default sampling.
This proves the first-response shape, not provider acceptance or a tool loop.
Found three installed policy defects: 200k reservation against Sonnet 5's 1M
context, 32k output limit against the CLI's actual 64k request, and a missing
mid-conversation beta. Secrets Engine's corrected owner candidate and six exact
unapproved action requests live in
`../secrets-engine/docs/proposals/glas-metered-20260927/README.md`.
The USD 4.64 full hold fits only once in the existing USD 5.74 envelope; native
tool-loop success needs a separately accepted budget or another proven tighter
accounting design. T05/T06 remain open for native config/delivery, accepted
FX/tariff validity, actual queue/model/commit and recovery. No production owner
file, ledger, worker or protected runtime was changed.
## Re-prove one governed profiled run and close residuals
```task
@ -792,3 +820,62 @@ The current catalog/CCRs, live credentials, profile readiness, host service and
factory queue remain unchanged. Protected placement, provider bounds/tariffs/FX,
G0 and natural execution remain. Per-run acquisition for a future continuous worker
is retained here; a delivered key must not authorize an unbounded daemon lifetime.
### Approved installation and tool-session proposal — 2026-09-27
The user approved the configuration/code update and separately requested preparation
of the €10 tool-session proposal. Installed Secrets Engine `11cc0d5` and corrected
owner `e0d3fb84` on Railiance; exact path/hash checks, substituted-command refusal,
standalone companion refusal and backend-free owner check pass. Standing worker,
spend limits and existing ledger are unchanged; no credentials read or paid calls.
Deployment receipt: `../secrets-engine/docs/evidence/2026-09-27-metered-owner-deployment.json`.
Actual pinned CLI/profile 1.1.1/runtime b6e4e8a4 passes a synthetic two-request Bash
tool/result exchange and zero-forward underfunded refusal, with teardown and
unchanged artifact. Receipt: `../rein-aharness/docs/evidence/2026-09-27-sonnet5-tool-session-proof.json`.
The inactive proposal is `../prj-helixforge-factory/operations/metered-tool-session-proposal.md`:
EUR 10 run cap, USD 10 liability, EUR/USD 1.00 treatment, existing native USD 5
threshold/daily EUR 20/total EUR 500 retained. Two USD 4.64 holds fit. Installed
0.87 FX is below the latest observed 0.876962 reference; fresh validity/FX acceptance
is required. No new grant or paid execution is authorized by proposal preparation.
Remaining owner tasks retain their waiting status: fresh spend grant/window,
accounting continuity and replacement recipient pins; attended native per-lane
approval/delivery/revocation; then natural queue/model/tool/commit/recovery proof.
This return supersedes earlier installation-pending statements, not those gates.
### Loose-end review — 2026-09-27
Reviewed every workplan in this repository and the current FI/factory owner
returns. T01–T03 are complete; T04–T06 cannot meet their remaining acceptance
criteria through changes in this repository alone. The plan is now `blocked`
and T05 joins T04/T06 in `wait`. No new tasks or workplans were created.
Completed the remaining local CI wiring under T05: the pinned Forgejo job now
runs `make contract-test recovery-test`, so deterministic lease, crash, lock,
close-outage and replay checks run on every main push as well as at release.
Reviewed and retained the previously uncommitted exact-profile proof script,
bootstrap documentation and two synthetic receipts. The tool-session receipt's
script digest matches the committed script; the earlier single-response receipt
records its earlier script revision. Neither is a paid provider or natural-queue
success claim.
| Task | Evidence required to resume |
| --- | --- |
| T04 | Owner-approved replacement and rollback evidence for FI and all three Binky schedules. FI-WP-0005's September 27 review still leaves T04/T05/T07/T08 waiting on grant v2, a runnable FI profile, canary and five weekday runs. Its compatibility publication is the FI-WP-0004 named grant recorded in the inventory; the September 4 local-only note above is historical. Binky has supplied no replacement evidence in this repo's inbox. Keep the dated compatibility path until those returns exist. |
| T05 | An admitted production artifact and live crash/lease/API-close/teardown recovery evidence. The synthetic pinned-artifact and local recovery proofs do not establish production recovery. Native continuous-worker credential acquisition also depends on the credential owner's per-run contract. HFACT-WP-0001-T01/T03/T04 retains fresh spend/window, accounting continuity, recipient pins and attended delivery/revocation. |
| T06 | T04/T05 completion, fresh native approvals and an actual queue/model/tool/accepted-commit run with cleanup and owner acknowledgement. HFACT-WP-0001's September 27 return still explicitly requires these gates; the inactive EUR 10 proposal does not grant paid execution. |
All residual work remains in these existing tasks and owner records. Other
workplans already have every task done; REINAH-WP-0001's historical top-level
`done` spelling was normalized to the canonical `finished` without changing its
identity or task history.
Validation: full suite `392 passed, 8 skipped`; isolated clean source checkouts
at every revision in `deploy/runtime-contract-lock.json`, installed using
`uv sync --frozen --no-editable --extra glas --extra llm --extra dev`, pass
the contract gate (`169 passed, 1 skipped`) and recovery gate (`131 passed,
1 skipped`). Skips are explicitly opt-in real CLI/kernel proofs, not missing
runtime packages. All sibling imports and exact source-lock checks pass. The
proof script parses and its isolated installed-package `--help` succeeds.
State Hub readback confirms the plan is `blocked` and T05 is `wait`.