rein-aharness/docs/native-metered-proof.md
tegwick 43e621439a
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
fix: reject broken runtime launchers and preserve failed proof evidence
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
2026-09-27 23:19:50 +02:00

97 lines
6.1 KiB
Markdown

# Attended disposable proof — 2026-09-27
Existing work: REINAH-WP-0003-T05/T06 and SECRETS-WP-0009-T03.
No new workplan, publication, automatic retry, or factory operating admission.
The operator accepted replacement spend memo `infd-20260927-b02`, confirmed
USD 10 including tax/conversion fees fits EUR 10, and accepted all six
`metered-20260927-{provider,worker}-{apply,verify,exec}` decisions. Native
submission confirmations and replacement host installation are separate receipts
in `docs/evidence/2026-09-27-metered-*.json`. The earlier expired spend grant is
preserved and never used.
`scripts/metered-native-owner.py` checks the frozen six-request packet and exact
recipient files before native claim/PDP checks. The provider's human-control
flag and the worker companion's ordinary flag remain unchanged. Apply and
verify each consume their own native approval before OpenBao effects. Exec
uses the existing Secrets Engine primary/companion consume and delivery code;
the procedure does not manufacture decisions, claims, or delivery state.
The attended workstation wrapper `scripts/attended-metered-proof.py` follows
the existing scoped approval-client reader and nested platform-admin OIDC
procedure. The operator-controlled SSH session runs the controller on Railiance
because the approved command and owner-file bindings name that host. Client
secret, short-lived operator/negative-test tokens and PDP caller token cross
encrypted SSH stdin only. The host uses a fresh owner-only temporary directory
on `/run/user/1000` tmpfs. Approval bearer tokens are minted in memory. No
cluster reader, persistent service, credential rotation or new custody path is
created. Warden self-revokes both attended sessions; private files and the
named-pod forwarding processes are removed on normal exit, including failure.
The delivered model child receives only its catalog-bound environment plus
its separately approved provider and worker credentials.
Before activation, the installer locks and checks all three old ledger tables,
refusing any prior reservation or liability. It preserves the old ledger and
backs up both old configuration files. A new private ledger is initialized
without resetting old evidence. Replacement file hashes retire dispatch using
the old catalog pins. The immutable runtime's backend-free owner check passes.
The single trigger occurs after both lanes verify. The controller waits for
exactly one open, unclaimed, attempt-zero task with the admitted profile and
one-file/one-commit/no-publication grant. It records trigger and exec intent
before either action. An existing execution receipt refuses all replays,
including uncertain/failed attempts. The scheduled definition stays disabled.
The approved maximum request hold remains USD 4.64; at most two such holds fit
the USD 10 liability cap. The [provider tariff](https://platform.claude.com/docs/en/about-claude/pricing)
was rechecked immediately before activation: Sonnet 5 global standard output is
USD 10/million tokens; the conservative input bound of USD 4/million covers
one-hour cache writes. The proof has no authority to enlarge these limits.
After interruption, inspect the durable local/remote receipts and native
consume state before any further action. Explicitly reconcile remaining
`metered-native-*` / `metered-attended-*` private runtime directories and any
open queue item; never rerun the command as a cleanup strategy. Hard-kill
cleanup is not claimed by this wrapper. Provider-request reservations remain
conservative until reconciled. T04's tenant migrations and broader T06
acceptance requirements remain in the existing workplan.
## Actual execution and corrections
All six decisions were accepted and consumed once. Both lane apply/verify
operations passed; exec delivered through two AppRole sessions whose revocation
succeeded. The single definition trigger initially produced a row with no grant:
the deployed Activity Core worker predated the API's grant-carriage support.
Activity Core `428f2d7` and Platform `c3607ff` changed only the worker image to
the already-deployed grant-aware API image through the existing GitOps parent
and child applications. Argo reports Synced/Healthy/Succeeded.
The explicit repair script validates and locks the original disabled definition
and original open, unclaimed, attempt-zero job. It copies only the exact typed
grant from that definition; it creates no row or trigger. Nine negative/positive
guard tests pass. This repair is recorded separately and is not represented as
successful natural grant carriage by the old producer.
The `resume` mode is limited to that recorded pre-execution queue-binding failure.
It verifies the four completed native actions, installed policies/role limits,
zero prior request/reservation counts, and the same repaired job. It repeats
neither apply/verify nor queue creation. Both remaining exec approvals were then
consumed. There is no further resume path for the attempted job.
Job `6efa9436-6a91-47c0-94e5-b31b5a0e7e3a` closed `failed`, attempt 1, with its
lease cleared. Its installed Python launchers still referenced a deleted build
directory: uv's long-path shell trampoline had escaped the builder's direct
shebang rewrite. A no-credential synthetic probe reproduced exit 127 for both
launchers inside the actual pinned bwrap artifact, with zero provider forwards.
The runtime builder correction is Sand-boxer `81b5fcf`; relocation tests execute
after the old build directory disappears. Rein now also rejects these launchers
before claim and retains bounded gateway stage/cleanup facts on accounting refusal.
The approved artifact itself remains unchanged. Sandbox `b67907f1` and its
workspace are destroyed; the repository is clean at its original commit, the
lock is available, and no close-outbox item or private credential directory is
left over. The request route is revoked and there are no provider-request
reservations. The parent EUR 10 reservation remains held; observed billing was
not invented and the ledger was not reset. A corrected artifact and its changed
pins need admission, held-liability reconciliation remains an owner action, and
another attempt requires separate authority. REINAH-WP-0003 stays blocked.