feat: return combined bwrap runtime candidate to Glas
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Answer the GLAS-WP-0015 handoff for SAND-WP-0015-T04 without activating any
production path.

Add candidate profile profile.claude-agent-dev-proof v1.1.0 (ext.bwrap,
localhost-only, default: deny, declared api.anthropic.com:443) for GLAS-WP-0012
review. The committed profile grants no egress by itself — ext.bwrap refuses it
unless owner extension config independently allowlists the destination — and a
regression test asserts that fail-closed default.

Reconcile the differing project examples in favour of the acceptance runner's
actor agt / project glas-local-proof, keeping the documented credential route
bound to that single project rather than broadening it.

Record the return contract (profile revision, host scope, consumer tuple,
runtime digest and mount paths, declared egress, value-free denial/cleanup
receipts) in docs/bwrap-runtime.md.

T04 stays wait: Claude credential lane, owner machine authentication, pinned
Claude executable and real-model acceptance remain operator gated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HjyScPKb8MV8y2VZHGFSSV

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 716401@bnt-lap001
Assistant-Session: 0d02392b-d4a8-4fed-98e3-32333f768169
This commit is contained in:
tegwick 2026-09-06 20:34:51 +02:00
parent 17d4160b6e
commit 23d0c2b34d
6 changed files with 124 additions and 4 deletions

View file

@ -20,7 +20,7 @@ Owner extension configuration has this shape (proposal only):
credential_routes:
glas-claude-agent-dev-anthropic:
profiles: [profile.claude-agent-dev-proof]
projects: [glas-harness]
projects: [glas-local-proof]
actors: [agt]
exec_argv:
- /absolute/owner/venv/bin/python
@ -38,6 +38,13 @@ credential_routes:
- --
```
The consumer tuple is exactly `actor: agt`, `project: glas-local-proof`,
`profile.claude-agent-dev-proof` — the identity the Glas real acceptance runner
presents. The earlier `glas-harness` example in this document was a generic
consumer illustration, not a reviewed binding, and is superseded here. The route
stays bound to that single project; it is not broadened to every Glas project,
and `glas-harness` remains only a generic consumer name in unrelated fixtures.
Do not install this example until the exact provider runtime, service identity,
approval contract and profile exist and are reviewed. No production route is
configured by this change. Owner config is trusted executable configuration;