Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
4.1 KiB
One-cycle owner bootstrap
rein-aharness metered-once --owner-config /absolute/private/owner.json is the
explicit exec-env child entry point. It prepares the exact admitted pins, consumes
only the deliberately delivered ANTHROPIC_API_KEY, removes provider authentication
and base-URL variables before other child processes, and runs at most one claim
cycle. The provider key is held by MessagesOwner outside the sandbox. Missing/mixed
credentials, invalid pins, missing ledgers, blocked profiles, failed readiness and
unclaimed refusals return nonzero. Receipt output excludes raw errors and prompts.
There is no key fetch, alternate provider, key file, OAuth/HOME or daemon fallback.
--check validates local pins without a key, queue access or workload dispatch;
it can advance the ledger's clock watermark but never initializes/reset its schema.
Use the standalone candidate interpreter as python -I -B -m rein_aharness.cli.
-I excludes editable PYTHONPATH/user-site fallbacks; -B prevents bytecode writes
from changing the complete artifact digest. The source and namespace rein commands
continue to use their existing entry points. The owner config selects the pinned
runtime through the trusted, ephemeral sandbox binding; it cannot add egress or
provider credentials to the child. Normal claim-loop behavior is unchanged.
The mode-0600, regular, owner-owned config has exactly these fields:
{
"version": "1",
"authority_ref": "REPLACE_WITH_ACCEPTED_SPEND_AUTHORITY",
"spend_policy_sha256": "REPLACE_WITH_ACCEPTED_SPEND_POLICY_DIGEST",
"messages_policy": {
"tariff_ref": "REPLACE_WITH_ACCEPTED_PROVIDER_BOUNDS_AND_RATES",
"model": "claude-sonnet-4-6",
"context_tokens": 0,
"max_output_tokens": 0,
"input_microusd_per_token": 0,
"output_microusd_per_token": 0,
"allowed_betas": []
},
"runtime": {
"path": "/absolute/accepted/runtime",
"sha256": "REPLACE_WITH_ACCEPTED_COMPLETE_ARTIFACT_DIGEST"
}
}
The placeholders and zero bounds deliberately refuse. The authority reference and spend digest must match the private existing SpendPolicy. Worker/project, exact profile/descriptor digests, operational readiness, model, empty-egress bwrap profile and runtime digest are checked before claim. Runtime, owner state and target checkout must not overlap. Provision parent and request ledgers as separate reviewed actions. The normal ACTIVITY_CORE/AGENT_HARNESS worker and state configuration still applies.
This config is not an authorization decision or a custody provenance proof. The
invoking credential engine must already have passed its exact action approval,
consume, scoped backend/readiness and admitted consumer checks. Its reviewed command
must be the fixed one-cycle owner entry point, with the accepted immutable config.
The current glas-claude-agent-dev-anthropic catalog describes delivery through the
sandbox helper and does not yet admit this owner holder. SECRETS-WP-0009-T03 and
HFACT-WP-0001-T03/T04 retain that review, existing client/audit/service dependencies,
Railiance placement and live negative tests. No real key is read by local validation.
This initial bootstrap obtains delivery before one claim cycle; an empty queue still uses that delivery attempt. It intentionally exits after that cycle. Native scheduled activation must not wrap a persistent claim loop with one reusable provider credential. Later per-run acquisition for a continuous worker belongs to REINAH-WP-0003-T05/T06 and the same credential owner; it must retain exact action/lease/budget semantics.
scripts/prove-metered-runtime.py runs with a built candidate's python -I -B.
It verifies all four packages and definitions come from the artifact, exercises this
CLI once against an empty fake HTTP queue with a synthetic exec-env key, and runs the
pinned actual Claude CLI through the protected bwrap mount and metered owner. The
positive fake stream and pre-forward insufficient-capacity refusal are separate
cases. It checks unchanged artifact digest and teardown. Queue/provider/key/profile
are disposable fixtures, never evidence of live admission. The project records the
candidate result in prj-helixforge-factory/evidence/2026-09-09-owner-bootstrap.json.