Close local runtime loose ends and record external blockers
Some checks failed
Governed runtime contract / contract (push) Failing after 15s
Some checks failed
Governed runtime contract / contract (push) Failing after 15s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
parent
e18e386e0e
commit
73aaa4bcd4
8 changed files with 752 additions and 24 deletions
|
|
@ -4,13 +4,13 @@ type: workplan
|
|||
title: "Governed runtime integrity and intent convergence"
|
||||
domain: infotech
|
||||
repo: rein-aharness
|
||||
status: active
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
owner: codex
|
||||
topic_slug: rein-aharness
|
||||
priority: high
|
||||
created: "2026-08-23"
|
||||
updated: "2026-09-09"
|
||||
updated: "2026-09-27"
|
||||
related:
|
||||
- REIN-A-0004
|
||||
- GLAS-IN-0002
|
||||
|
|
@ -517,7 +517,7 @@ Freedom Intelligence `d0b45acb-0002-405b-9620-cc44568170fb`, Binky
|
|||
|
||||
```task
|
||||
id: REINAH-WP-0003-T05
|
||||
status: progress
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "c4a3f08f-2874-5672-9f29-aecddd697d90"
|
||||
```
|
||||
|
|
@ -691,6 +691,34 @@ runtime installation. LLM-WP-0009-T03 retains the transport integration return;
|
|||
T06 remains wait for admitted real-model/natural-queue evidence. No production
|
||||
policy, listener, credential, deployment or paid attempt was created.
|
||||
|
||||
### Exact profile return — 2026-09-27
|
||||
|
||||
Followed LLM-WP-0009 dependencies into the current Secrets Engine and target.
|
||||
ACTIVITY-WP-0039 now supplies the dedicated live metered identity; owner config,
|
||||
private ledgers and runtime b6e4e8a4 are already provisioned on Railiance.
|
||||
The previous proof script always resolved profile 1.0.0, so its September 23
|
||||
receipt did not prove the new Sonnet 5 profile. Corrected the script to require
|
||||
`--profile-ref` and `--expected-model`, check both, echo the selected model in
|
||||
fake provider responses and record only request-shape metadata.
|
||||
|
||||
The real target proof now passes with profile 1.1.1 / Sonnet 5 / CLI 2.1.266:
|
||||
one fake forward, zero on insufficient capacity, bootstrap empty fake queue,
|
||||
route revocation, private-state exclusion, read-only artifact and clean teardown.
|
||||
Receipt: `docs/evidence/2026-09-27-sonnet5-runtime-proof.json`.
|
||||
The narrowed Sonnet 5 fixture rejects manual thinking/non-default sampling.
|
||||
This proves the first-response shape, not provider acceptance or a tool loop.
|
||||
|
||||
Found three installed policy defects: 200k reservation against Sonnet 5's 1M
|
||||
context, 32k output limit against the CLI's actual 64k request, and a missing
|
||||
mid-conversation beta. Secrets Engine's corrected owner candidate and six exact
|
||||
unapproved action requests live in
|
||||
`../secrets-engine/docs/proposals/glas-metered-20260927/README.md`.
|
||||
The USD 4.64 full hold fits only once in the existing USD 5.74 envelope; native
|
||||
tool-loop success needs a separately accepted budget or another proven tighter
|
||||
accounting design. T05/T06 remain open for native config/delivery, accepted
|
||||
FX/tariff validity, actual queue/model/commit and recovery. No production owner
|
||||
file, ledger, worker or protected runtime was changed.
|
||||
|
||||
## Re-prove one governed profiled run and close residuals
|
||||
|
||||
```task
|
||||
|
|
@ -792,3 +820,62 @@ The current catalog/CCRs, live credentials, profile readiness, host service and
|
|||
factory queue remain unchanged. Protected placement, provider bounds/tariffs/FX,
|
||||
G0 and natural execution remain. Per-run acquisition for a future continuous worker
|
||||
is retained here; a delivered key must not authorize an unbounded daemon lifetime.
|
||||
|
||||
### Approved installation and tool-session proposal — 2026-09-27
|
||||
|
||||
The user approved the configuration/code update and separately requested preparation
|
||||
of the €10 tool-session proposal. Installed Secrets Engine `11cc0d5` and corrected
|
||||
owner `e0d3fb84` on Railiance; exact path/hash checks, substituted-command refusal,
|
||||
standalone companion refusal and backend-free owner check pass. Standing worker,
|
||||
spend limits and existing ledger are unchanged; no credentials read or paid calls.
|
||||
Deployment receipt: `../secrets-engine/docs/evidence/2026-09-27-metered-owner-deployment.json`.
|
||||
|
||||
Actual pinned CLI/profile 1.1.1/runtime b6e4e8a4 passes a synthetic two-request Bash
|
||||
tool/result exchange and zero-forward underfunded refusal, with teardown and
|
||||
unchanged artifact. Receipt: `../rein-aharness/docs/evidence/2026-09-27-sonnet5-tool-session-proof.json`.
|
||||
The inactive proposal is `../prj-helixforge-factory/operations/metered-tool-session-proposal.md`:
|
||||
EUR 10 run cap, USD 10 liability, EUR/USD 1.00 treatment, existing native USD 5
|
||||
threshold/daily EUR 20/total EUR 500 retained. Two USD 4.64 holds fit. Installed
|
||||
0.87 FX is below the latest observed 0.876962 reference; fresh validity/FX acceptance
|
||||
is required. No new grant or paid execution is authorized by proposal preparation.
|
||||
|
||||
Remaining owner tasks retain their waiting status: fresh spend grant/window,
|
||||
accounting continuity and replacement recipient pins; attended native per-lane
|
||||
approval/delivery/revocation; then natural queue/model/tool/commit/recovery proof.
|
||||
This return supersedes earlier installation-pending statements, not those gates.
|
||||
|
||||
### Loose-end review — 2026-09-27
|
||||
|
||||
Reviewed every workplan in this repository and the current FI/factory owner
|
||||
returns. T01–T03 are complete; T04–T06 cannot meet their remaining acceptance
|
||||
criteria through changes in this repository alone. The plan is now `blocked`
|
||||
and T05 joins T04/T06 in `wait`. No new tasks or workplans were created.
|
||||
|
||||
Completed the remaining local CI wiring under T05: the pinned Forgejo job now
|
||||
runs `make contract-test recovery-test`, so deterministic lease, crash, lock,
|
||||
close-outage and replay checks run on every main push as well as at release.
|
||||
Reviewed and retained the previously uncommitted exact-profile proof script,
|
||||
bootstrap documentation and two synthetic receipts. The tool-session receipt's
|
||||
script digest matches the committed script; the earlier single-response receipt
|
||||
records its earlier script revision. Neither is a paid provider or natural-queue
|
||||
success claim.
|
||||
|
||||
| Task | Evidence required to resume |
|
||||
| --- | --- |
|
||||
| T04 | Owner-approved replacement and rollback evidence for FI and all three Binky schedules. FI-WP-0005's September 27 review still leaves T04/T05/T07/T08 waiting on grant v2, a runnable FI profile, canary and five weekday runs. Its compatibility publication is the FI-WP-0004 named grant recorded in the inventory; the September 4 local-only note above is historical. Binky has supplied no replacement evidence in this repo's inbox. Keep the dated compatibility path until those returns exist. |
|
||||
| T05 | An admitted production artifact and live crash/lease/API-close/teardown recovery evidence. The synthetic pinned-artifact and local recovery proofs do not establish production recovery. Native continuous-worker credential acquisition also depends on the credential owner's per-run contract. HFACT-WP-0001-T01/T03/T04 retains fresh spend/window, accounting continuity, recipient pins and attended delivery/revocation. |
|
||||
| T06 | T04/T05 completion, fresh native approvals and an actual queue/model/tool/accepted-commit run with cleanup and owner acknowledgement. HFACT-WP-0001's September 27 return still explicitly requires these gates; the inactive EUR 10 proposal does not grant paid execution. |
|
||||
|
||||
All residual work remains in these existing tasks and owner records. Other
|
||||
workplans already have every task done; REINAH-WP-0001's historical top-level
|
||||
`done` spelling was normalized to the canonical `finished` without changing its
|
||||
identity or task history.
|
||||
|
||||
Validation: full suite `392 passed, 8 skipped`; isolated clean source checkouts
|
||||
at every revision in `deploy/runtime-contract-lock.json`, installed using
|
||||
`uv sync --frozen --no-editable --extra glas --extra llm --extra dev`, pass
|
||||
the contract gate (`169 passed, 1 skipped`) and recovery gate (`131 passed,
|
||||
1 skipped`). Skips are explicitly opt-in real CLI/kernel proofs, not missing
|
||||
runtime packages. All sibling imports and exact source-lock checks pass. The
|
||||
proof script parses and its isolated installed-package `--help` succeeds.
|
||||
State Hub readback confirms the plan is `blocked` and T05 is `wait`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue