Some checks failed
Governed runtime contract / contract (push) Failing after 23s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
73 lines
4.1 KiB
Markdown
73 lines
4.1 KiB
Markdown
# One-cycle owner bootstrap
|
|
|
|
`rein-aharness metered-once --owner-config /absolute/private/owner.json` is the
|
|
explicit exec-env child entry point. It prepares the exact admitted pins, consumes
|
|
only the deliberately delivered `ANTHROPIC_API_KEY`, removes provider authentication
|
|
and base-URL variables before other child processes, and runs at most one claim
|
|
cycle. The provider key is held by MessagesOwner outside the sandbox. Missing/mixed
|
|
credentials, invalid pins, missing ledgers, blocked profiles, failed readiness and
|
|
unclaimed refusals return nonzero. Receipt output excludes raw errors and prompts.
|
|
There is no key fetch, alternate provider, key file, OAuth/HOME or daemon fallback.
|
|
`--check` validates local pins without a key, queue access or workload dispatch;
|
|
it can advance the ledger's clock watermark but never initializes/reset its schema.
|
|
|
|
Use the standalone candidate interpreter as `python -I -B -m rein_aharness.cli`.
|
|
`-I` excludes editable PYTHONPATH/user-site fallbacks; `-B` prevents bytecode writes
|
|
from changing the complete artifact digest. The source and namespace rein commands
|
|
continue to use their existing entry points. The owner config selects the pinned
|
|
runtime through the trusted, ephemeral sandbox binding; it cannot add egress or
|
|
provider credentials to the child. Normal `claim-loop` behavior is unchanged.
|
|
|
|
The mode-0600, regular, owner-owned config has exactly these fields:
|
|
|
|
```json
|
|
{
|
|
"version": "1",
|
|
"authority_ref": "REPLACE_WITH_ACCEPTED_SPEND_AUTHORITY",
|
|
"spend_policy_sha256": "REPLACE_WITH_ACCEPTED_SPEND_POLICY_DIGEST",
|
|
"messages_policy": {
|
|
"tariff_ref": "REPLACE_WITH_ACCEPTED_PROVIDER_BOUNDS_AND_RATES",
|
|
"model": "claude-sonnet-4-6",
|
|
"context_tokens": 0,
|
|
"max_output_tokens": 0,
|
|
"input_microusd_per_token": 0,
|
|
"output_microusd_per_token": 0,
|
|
"allowed_betas": []
|
|
},
|
|
"runtime": {
|
|
"path": "/absolute/accepted/runtime",
|
|
"sha256": "REPLACE_WITH_ACCEPTED_COMPLETE_ARTIFACT_DIGEST"
|
|
}
|
|
}
|
|
```
|
|
|
|
The placeholders and zero bounds deliberately refuse. The authority reference and
|
|
spend digest must match the private existing SpendPolicy. Worker/project, exact
|
|
profile/descriptor digests, operational readiness, model, empty-egress bwrap profile
|
|
and runtime digest are checked before claim. Runtime, owner state and target checkout
|
|
must not overlap. Provision parent and request ledgers as separate reviewed actions.
|
|
The normal ACTIVITY_CORE/AGENT_HARNESS worker and state configuration still applies.
|
|
|
|
This config is not an authorization decision or a custody provenance proof. The
|
|
invoking credential engine must already have passed its exact action approval,
|
|
consume, scoped backend/readiness and admitted consumer checks. Its reviewed command
|
|
must be the fixed one-cycle owner entry point, with the accepted immutable config.
|
|
The current `glas-claude-agent-dev-anthropic` catalog describes delivery through the
|
|
sandbox helper and does not yet admit this owner holder. SECRETS-WP-0009-T03 and
|
|
HFACT-WP-0001-T03/T04 retain that review, existing client/audit/service dependencies,
|
|
Railiance placement and live negative tests. No real key is read by local validation.
|
|
|
|
This initial bootstrap obtains delivery before one claim cycle; an empty queue still
|
|
uses that delivery attempt. It intentionally exits after that cycle. Native scheduled
|
|
activation must not wrap a persistent claim loop with one reusable provider credential.
|
|
Later per-run acquisition for a continuous worker belongs to REINAH-WP-0003-T05/T06
|
|
and the same credential owner; it must retain exact action/lease/budget semantics.
|
|
|
|
`scripts/prove-metered-runtime.py` runs with a built candidate's `python -I -B`.
|
|
It verifies all four packages and definitions come from the artifact, exercises this
|
|
CLI once against an empty fake HTTP queue with a synthetic exec-env key, and runs the
|
|
pinned actual Claude CLI through the protected bwrap mount and metered owner. The
|
|
positive fake stream and pre-forward insufficient-capacity refusal are separate
|
|
cases. It checks unchanged artifact digest and teardown. Queue/provider/key/profile
|
|
are disposable fixtures, never evidence of live admission. The project records the
|
|
candidate result in `prj-helixforge-factory/evidence/2026-09-09-owner-bootstrap.json`.
|