Confine metered runs to an ephemeral owner Messages route
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-09 22:20:56 +02:00
parent 3e49a98a0e
commit bfe0e4c4c8
7 changed files with 231 additions and 5 deletions

View file

@ -8,7 +8,7 @@ status: blocked
owner: codex
topic_slug: bwrap-runtime-and-private-state
created: "2026-09-05"
updated: "2026-09-08"
updated: "2026-09-09"
state_hub_workstream_id: "d3f12387-fd23-58f0-b979-9c811507614d"
---
@ -248,3 +248,15 @@ full check used that canonical basename. Evidence:
`docs/evidence/SAND-WP-0015-protected-local-install-2026-09-08.json`.
T04 retains owner execution configuration, native credential/egress and real-model
acceptance; Railiance installation needs its own target-specific return.
## 2026-09-09 factory metered route source return
Implemented the trusted, ephemeral Messages route described in
[docs/bwrap-messages-route.md](../docs/bwrap-messages-route.md). Actual local
bwrap owner transport proves provider key/ledger separation, direct-route denial,
revocation and teardown; rein also proves metered request plus commit import and
close replay. `make check`: lint clean, 199 passed. T04 remains waiting for the
admitted provider-to-owner bootstrap, updated protected runtime/profile, Railiance
placement, live compatibility and G0. Existing child-provider-key/direct-CONNECT
proofs do not admit this different credential holder or metered profile. No CCR,
secret read, deployment or paid request was performed.