Package sandbox definitions and build a pinned owner runtime
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-09 22:54:39 +02:00
parent bfe0e4c4c8
commit be42de7caf
9 changed files with 127 additions and 8 deletions

View file

@ -260,3 +260,19 @@ admitted provider-to-owner bootstrap, updated protected runtime/profile, Railian
placement, live compatibility and G0. Existing child-provider-key/direct-CONNECT
proofs do not admit this different credential holder or metered profile. No CCR,
secret read, deployment or paid request was performed.
## 2026-09-09 standalone owner packaging and runtime selection
Added frozen-lock owner build mode for the matched rein/llm/Glas/sandboxer set,
with non-editable installation and recorded lock/source/package pins. Sand-boxer
wheels now carry their profile and extension definitions, fixing a bwrap owner
failure that source-checkout tests could hide. The trusted Messages binding can
select the digest-pinned runtime without adding an API or profile override.
`make check`: lint clean, 201 passed. Existing standalone workload builds remain
supported. See docs/bwrap-runtime.md and rein's docs/owner-bootstrap.md.
The project's `evidence/2026-09-09-owner-bootstrap.json` records the actual candidate
build and isolated installed-interpreter/CLI proof. T04 remains wait for accepted
credential-to-owner delivery, current protected installation and Railiance placement,
provider compatibility and G0. Source packaging does not reopen completed T01-T03,
T05-T06, broaden the old CCRs or activate the previously installed 2.1.263 artifact.