Some checks failed
Governed runtime contract / contract (push) Failing after 23s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
53 lines
3.7 KiB
Markdown
53 lines
3.7 KiB
Markdown
# Same-host metered request owner
|
|
|
|
Source API: `rein_aharness.messages_owner.MessagesOwner`. The trusted host bootstrap
|
|
constructs it with an accepted immutable `MessagesPolicy` and an explicitly supplied
|
|
provider key, then sets `OpsRunConfig.messages_owner`. This is an in-process owner
|
|
capability, not a queue field, serialized profile or remote sandbox API parameter.
|
|
The normal claim-loop CLI does not acquire a key or construct an owner. The explicit
|
|
[metered-once bootstrap](owner-bootstrap.md) now supplies the one-cycle exec-env
|
|
child path; native delivery still needs admission. Set
|
|
`AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION=1` in a future admitted service so a missing
|
|
bootstrap refuses before claiming work. Parent spend admission must also be configured;
|
|
provision the RequestLedger schema explicitly before dispatch. No live bootstrap or
|
|
policy is installed by this source increment.
|
|
|
|
`process_one` validates the accepted initial heartbeat's run ID, worker, attempt,
|
|
claimed state and future lease expiry. It replaces the stale claim expiry with that
|
|
accepted expiry. `execute_profiled_run` uses the same checked profile catalog and
|
|
parent reservation, then enters the owner context and gives Glas its bound sandbox
|
|
manager. The gateway's existing execution, artifact capture and teardown path is
|
|
retained. Every exit revokes the token before shutting down the listener. Existing
|
|
worker cancellation invokes revocation too; a deadline timer covers loss of
|
|
heartbeat connectivity. The route expires at the earlier of the initial accepted
|
|
lease and policy expiry. Renewal deliberately does not extend it; start another
|
|
admitted demand only through normal parent admission, never rebind an old run.
|
|
|
|
The socket is mode 0600 in an ephemeral mode 0700 directory next to the private
|
|
ledger. llm-connect listens on AF_UNIX only. Sand-boxer binds exactly that socket
|
|
into its isolated namespace and reuses its bounded loopback byte bridge. Only the
|
|
opaque token reaches `ANTHROPIC_API_KEY`; `ANTHROPIC_BASE_URL` points to that bridge.
|
|
There is no provider key in workload memory, argv, mounts or public sandbox records.
|
|
The workload can reuse/encode its own route token, but the owner still enforces its
|
|
one run, expiry, policy and durable capacity. Host owner code/state must remain trusted.
|
|
|
|
The ephemeral manager accepts one exact bwrap profile/actor/project/run tuple and
|
|
one sandbox. It refuses nonempty network egress, provider credential routes, setup
|
|
secrets, extra host mounts and owner-state overlap with source/workspace/runtime.
|
|
Remote owner transports cannot silently serialize this binding or fall back to
|
|
provider credential delivery. Existing unconfigured consumers remain unchanged.
|
|
The existing direct-CONNECT proof profile is incompatible with this metered mode;
|
|
a separately reviewed empty-egress profile is required for live use.
|
|
|
|
Reconciliation semantics remain conservative: unknown provider outcomes retain
|
|
child and parent holds; shutdown or a killed socket is not proof of zero charge.
|
|
Do not automatically reopen, refund or retry from workload accounting. The same
|
|
existing receipt-backed operator reconciliation remains necessary after uncertainty.
|
|
|
|
Validation: `tests/test_messages_owner.py`, `tests/test_repository_artifact_bwrap.py`,
|
|
and existing request/native-CLI suites. Enable `REIN_REAL_BWRAP=1` for the kernel
|
|
proof; `REIN_REAL_CLAUDE=1` retains the separate installed-CLI protocol fixtures.
|
|
The owner-route proof uses arbitrary Python in the real sandbox, an external fake
|
|
provider and synthetic key. It is a local confinement proof, not a paid provider,
|
|
protected-artifact or Railiance acceptance receipt. Remaining delivery is owned by
|
|
REINAH-WP-0003-T05/T06, LLM-WP-0009-T03 and SAND-WP-0015-T04 under HFACT T01/T03/T04.
|