rein-aharness/docs/native-metered-proof.md
tegwick 43e621439a
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
fix: reject broken runtime launchers and preserve failed proof evidence
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
2026-09-27 23:19:50 +02:00

6.1 KiB

Attended disposable proof — 2026-09-27

Existing work: REINAH-WP-0003-T05/T06 and SECRETS-WP-0009-T03. No new workplan, publication, automatic retry, or factory operating admission.

The operator accepted replacement spend memo infd-20260927-b02, confirmed USD 10 including tax/conversion fees fits EUR 10, and accepted all six metered-20260927-{provider,worker}-{apply,verify,exec} decisions. Native submission confirmations and replacement host installation are separate receipts in docs/evidence/2026-09-27-metered-*.json. The earlier expired spend grant is preserved and never used.

scripts/metered-native-owner.py checks the frozen six-request packet and exact recipient files before native claim/PDP checks. The provider's human-control flag and the worker companion's ordinary flag remain unchanged. Apply and verify each consume their own native approval before OpenBao effects. Exec uses the existing Secrets Engine primary/companion consume and delivery code; the procedure does not manufacture decisions, claims, or delivery state.

The attended workstation wrapper scripts/attended-metered-proof.py follows the existing scoped approval-client reader and nested platform-admin OIDC procedure. The operator-controlled SSH session runs the controller on Railiance because the approved command and owner-file bindings name that host. Client secret, short-lived operator/negative-test tokens and PDP caller token cross encrypted SSH stdin only. The host uses a fresh owner-only temporary directory on /run/user/1000 tmpfs. Approval bearer tokens are minted in memory. No cluster reader, persistent service, credential rotation or new custody path is created. Warden self-revokes both attended sessions; private files and the named-pod forwarding processes are removed on normal exit, including failure. The delivered model child receives only its catalog-bound environment plus its separately approved provider and worker credentials.

Before activation, the installer locks and checks all three old ledger tables, refusing any prior reservation or liability. It preserves the old ledger and backs up both old configuration files. A new private ledger is initialized without resetting old evidence. Replacement file hashes retire dispatch using the old catalog pins. The immutable runtime's backend-free owner check passes.

The single trigger occurs after both lanes verify. The controller waits for exactly one open, unclaimed, attempt-zero task with the admitted profile and one-file/one-commit/no-publication grant. It records trigger and exec intent before either action. An existing execution receipt refuses all replays, including uncertain/failed attempts. The scheduled definition stays disabled.

The approved maximum request hold remains USD 4.64; at most two such holds fit the USD 10 liability cap. The provider tariff was rechecked immediately before activation: Sonnet 5 global standard output is USD 10/million tokens; the conservative input bound of USD 4/million covers one-hour cache writes. The proof has no authority to enlarge these limits.

After interruption, inspect the durable local/remote receipts and native consume state before any further action. Explicitly reconcile remaining metered-native-* / metered-attended-* private runtime directories and any open queue item; never rerun the command as a cleanup strategy. Hard-kill cleanup is not claimed by this wrapper. Provider-request reservations remain conservative until reconciled. T04's tenant migrations and broader T06 acceptance requirements remain in the existing workplan.

Actual execution and corrections

All six decisions were accepted and consumed once. Both lane apply/verify operations passed; exec delivered through two AppRole sessions whose revocation succeeded. The single definition trigger initially produced a row with no grant: the deployed Activity Core worker predated the API's grant-carriage support. Activity Core 428f2d7 and Platform c3607ff changed only the worker image to the already-deployed grant-aware API image through the existing GitOps parent and child applications. Argo reports Synced/Healthy/Succeeded.

The explicit repair script validates and locks the original disabled definition and original open, unclaimed, attempt-zero job. It copies only the exact typed grant from that definition; it creates no row or trigger. Nine negative/positive guard tests pass. This repair is recorded separately and is not represented as successful natural grant carriage by the old producer.

The resume mode is limited to that recorded pre-execution queue-binding failure. It verifies the four completed native actions, installed policies/role limits, zero prior request/reservation counts, and the same repaired job. It repeats neither apply/verify nor queue creation. Both remaining exec approvals were then consumed. There is no further resume path for the attempted job.

Job 6efa9436-6a91-47c0-94e5-b31b5a0e7e3a closed failed, attempt 1, with its lease cleared. Its installed Python launchers still referenced a deleted build directory: uv's long-path shell trampoline had escaped the builder's direct shebang rewrite. A no-credential synthetic probe reproduced exit 127 for both launchers inside the actual pinned bwrap artifact, with zero provider forwards. The runtime builder correction is Sand-boxer 81b5fcf; relocation tests execute after the old build directory disappears. Rein now also rejects these launchers before claim and retains bounded gateway stage/cleanup facts on accounting refusal.

The approved artifact itself remains unchanged. Sandbox b67907f1 and its workspace are destroyed; the repository is clean at its original commit, the lock is available, and no close-outbox item or private credential directory is left over. The request route is revoked and there are no provider-request reservations. The parent EUR 10 reservation remains held; observed billing was not invented and the ledger was not reset. A corrected artifact and its changed pins need admission, held-liability reconciliation remains an owner action, and another attempt requires separate authority. REINAH-WP-0003 stays blocked.