Package sandbox definitions and build a pinned owner runtime
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
bfe0e4c4c8
commit
be42de7caf
9 changed files with 127 additions and 8 deletions
|
|
@ -260,3 +260,19 @@ admitted provider-to-owner bootstrap, updated protected runtime/profile, Railian
|
|||
placement, live compatibility and G0. Existing child-provider-key/direct-CONNECT
|
||||
proofs do not admit this different credential holder or metered profile. No CCR,
|
||||
secret read, deployment or paid request was performed.
|
||||
|
||||
## 2026-09-09 standalone owner packaging and runtime selection
|
||||
|
||||
Added frozen-lock owner build mode for the matched rein/llm/Glas/sandboxer set,
|
||||
with non-editable installation and recorded lock/source/package pins. Sand-boxer
|
||||
wheels now carry their profile and extension definitions, fixing a bwrap owner
|
||||
failure that source-checkout tests could hide. The trusted Messages binding can
|
||||
select the digest-pinned runtime without adding an API or profile override.
|
||||
`make check`: lint clean, 201 passed. Existing standalone workload builds remain
|
||||
supported. See docs/bwrap-runtime.md and rein's docs/owner-bootstrap.md.
|
||||
|
||||
The project's `evidence/2026-09-09-owner-bootstrap.json` records the actual candidate
|
||||
build and isolated installed-interpreter/CLI proof. T04 remains wait for accepted
|
||||
credential-to-owner delivery, current protected installation and Railiance placement,
|
||||
provider compatibility and G0. Source packaging does not reopen completed T01-T03,
|
||||
T05-T06, broaden the old CCRs or activate the previously installed 2.1.263 artifact.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue