Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
3.7 KiB
Same-host metered request owner
Source API: rein_aharness.messages_owner.MessagesOwner. The trusted host bootstrap
constructs it with an accepted immutable MessagesPolicy and an explicitly supplied
provider key, then sets OpsRunConfig.messages_owner. This is an in-process owner
capability, not a queue field, serialized profile or remote sandbox API parameter.
The normal claim-loop CLI does not acquire a key or construct an owner. The explicit
metered-once bootstrap now supplies the one-cycle exec-env
child path; native delivery still needs admission. Set
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION=1 in a future admitted service so a missing
bootstrap refuses before claiming work. Parent spend admission must also be configured;
provision the RequestLedger schema explicitly before dispatch. No live bootstrap or
policy is installed by this source increment.
process_one validates the accepted initial heartbeat's run ID, worker, attempt,
claimed state and future lease expiry. It replaces the stale claim expiry with that
accepted expiry. execute_profiled_run uses the same checked profile catalog and
parent reservation, then enters the owner context and gives Glas its bound sandbox
manager. The gateway's existing execution, artifact capture and teardown path is
retained. Every exit revokes the token before shutting down the listener. Existing
worker cancellation invokes revocation too; a deadline timer covers loss of
heartbeat connectivity. The route expires at the earlier of the initial accepted
lease and policy expiry. Renewal deliberately does not extend it; start another
admitted demand only through normal parent admission, never rebind an old run.
The socket is mode 0600 in an ephemeral mode 0700 directory next to the private
ledger. llm-connect listens on AF_UNIX only. Sand-boxer binds exactly that socket
into its isolated namespace and reuses its bounded loopback byte bridge. Only the
opaque token reaches ANTHROPIC_API_KEY; ANTHROPIC_BASE_URL points to that bridge.
There is no provider key in workload memory, argv, mounts or public sandbox records.
The workload can reuse/encode its own route token, but the owner still enforces its
one run, expiry, policy and durable capacity. Host owner code/state must remain trusted.
The ephemeral manager accepts one exact bwrap profile/actor/project/run tuple and one sandbox. It refuses nonempty network egress, provider credential routes, setup secrets, extra host mounts and owner-state overlap with source/workspace/runtime. Remote owner transports cannot silently serialize this binding or fall back to provider credential delivery. Existing unconfigured consumers remain unchanged. The existing direct-CONNECT proof profile is incompatible with this metered mode; a separately reviewed empty-egress profile is required for live use.
Reconciliation semantics remain conservative: unknown provider outcomes retain child and parent holds; shutdown or a killed socket is not proof of zero charge. Do not automatically reopen, refund or retry from workload accounting. The same existing receipt-backed operator reconciliation remains necessary after uncertainty.
Validation: tests/test_messages_owner.py, tests/test_repository_artifact_bwrap.py,
and existing request/native-CLI suites. Enable REIN_REAL_BWRAP=1 for the kernel
proof; REIN_REAL_CLAUDE=1 retains the separate installed-CLI protocol fixtures.
The owner-route proof uses arbitrary Python in the real sandbox, an external fake
provider and synthetic key. It is a local confinement proof, not a paid provider,
protected-artifact or Railiance acceptance receipt. Remaining delivery is owned by
REINAH-WP-0003-T05/T06, LLM-WP-0009-T03 and SAND-WP-0015-T04 under HFACT T01/T03/T04.