Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
6.1 KiB
Attended disposable proof — 2026-09-27
Existing work: REINAH-WP-0003-T05/T06 and SECRETS-WP-0009-T03. No new workplan, publication, automatic retry, or factory operating admission.
The operator accepted replacement spend memo infd-20260927-b02, confirmed
USD 10 including tax/conversion fees fits EUR 10, and accepted all six
metered-20260927-{provider,worker}-{apply,verify,exec} decisions. Native
submission confirmations and replacement host installation are separate receipts
in docs/evidence/2026-09-27-metered-*.json. The earlier expired spend grant is
preserved and never used.
scripts/metered-native-owner.py checks the frozen six-request packet and exact
recipient files before native claim/PDP checks. The provider's human-control
flag and the worker companion's ordinary flag remain unchanged. Apply and
verify each consume their own native approval before OpenBao effects. Exec
uses the existing Secrets Engine primary/companion consume and delivery code;
the procedure does not manufacture decisions, claims, or delivery state.
The attended workstation wrapper scripts/attended-metered-proof.py follows
the existing scoped approval-client reader and nested platform-admin OIDC
procedure. The operator-controlled SSH session runs the controller on Railiance
because the approved command and owner-file bindings name that host. Client
secret, short-lived operator/negative-test tokens and PDP caller token cross
encrypted SSH stdin only. The host uses a fresh owner-only temporary directory
on /run/user/1000 tmpfs. Approval bearer tokens are minted in memory. No
cluster reader, persistent service, credential rotation or new custody path is
created. Warden self-revokes both attended sessions; private files and the
named-pod forwarding processes are removed on normal exit, including failure.
The delivered model child receives only its catalog-bound environment plus
its separately approved provider and worker credentials.
Before activation, the installer locks and checks all three old ledger tables, refusing any prior reservation or liability. It preserves the old ledger and backs up both old configuration files. A new private ledger is initialized without resetting old evidence. Replacement file hashes retire dispatch using the old catalog pins. The immutable runtime's backend-free owner check passes.
The single trigger occurs after both lanes verify. The controller waits for exactly one open, unclaimed, attempt-zero task with the admitted profile and one-file/one-commit/no-publication grant. It records trigger and exec intent before either action. An existing execution receipt refuses all replays, including uncertain/failed attempts. The scheduled definition stays disabled.
The approved maximum request hold remains USD 4.64; at most two such holds fit the USD 10 liability cap. The provider tariff was rechecked immediately before activation: Sonnet 5 global standard output is USD 10/million tokens; the conservative input bound of USD 4/million covers one-hour cache writes. The proof has no authority to enlarge these limits.
After interruption, inspect the durable local/remote receipts and native
consume state before any further action. Explicitly reconcile remaining
metered-native-* / metered-attended-* private runtime directories and any
open queue item; never rerun the command as a cleanup strategy. Hard-kill
cleanup is not claimed by this wrapper. Provider-request reservations remain
conservative until reconciled. T04's tenant migrations and broader T06
acceptance requirements remain in the existing workplan.
Actual execution and corrections
All six decisions were accepted and consumed once. Both lane apply/verify
operations passed; exec delivered through two AppRole sessions whose revocation
succeeded. The single definition trigger initially produced a row with no grant:
the deployed Activity Core worker predated the API's grant-carriage support.
Activity Core 428f2d7 and Platform c3607ff changed only the worker image to
the already-deployed grant-aware API image through the existing GitOps parent
and child applications. Argo reports Synced/Healthy/Succeeded.
The explicit repair script validates and locks the original disabled definition and original open, unclaimed, attempt-zero job. It copies only the exact typed grant from that definition; it creates no row or trigger. Nine negative/positive guard tests pass. This repair is recorded separately and is not represented as successful natural grant carriage by the old producer.
The resume mode is limited to that recorded pre-execution queue-binding failure.
It verifies the four completed native actions, installed policies/role limits,
zero prior request/reservation counts, and the same repaired job. It repeats
neither apply/verify nor queue creation. Both remaining exec approvals were then
consumed. There is no further resume path for the attempted job.
Job 6efa9436-6a91-47c0-94e5-b31b5a0e7e3a closed failed, attempt 1, with its
lease cleared. Its installed Python launchers still referenced a deleted build
directory: uv's long-path shell trampoline had escaped the builder's direct
shebang rewrite. A no-credential synthetic probe reproduced exit 127 for both
launchers inside the actual pinned bwrap artifact, with zero provider forwards.
The runtime builder correction is Sand-boxer 81b5fcf; relocation tests execute
after the old build directory disappears. Rein now also rejects these launchers
before claim and retains bounded gateway stage/cleanup facts on accounting refusal.
The approved artifact itself remains unchanged. Sandbox b67907f1 and its
workspace are destroyed; the repository is clean at its original commit, the
lock is available, and no close-outbox item or private credential directory is
left over. The request route is revoked and there are no provider-request
reservations. The parent EUR 10 reservation remains held; observed billing was
not invented and the ledger was not reset. A corrected artifact and its changed
pins need admission, held-liability reconciliation remains an owner action, and
another attempt requires separate authority. REINAH-WP-0003 stays blocked.