107 lines
6.3 KiB
Markdown
107 lines
6.3 KiB
Markdown
|
|
# Metered owner activation candidate — 2026-09-27
|
||
|
|
|
||
|
|
This is a reviewed source candidate, not native authorization. No provider key
|
||
|
|
was read, no approval created or consumed, and no paid/production queue attempt
|
||
|
|
was made. The live owner still has the old file; the source catalog now pins the
|
||
|
|
corrected file and will refuse that old file.
|
||
|
|
|
||
|
|
## Concrete correction
|
||
|
|
|
||
|
|
`owner.json` retains the installed runtime, spend-policy digest and authority
|
||
|
|
reference. Only its Messages policy changes:
|
||
|
|
|
||
|
|
- input liability context: 200000 → 1000000 (Sonnet 5 has no 200k variant);
|
||
|
|
- output ceiling: 32000 → 64000 (observed from the pinned actual CLI);
|
||
|
|
- allow `mid-conversation-system-2026-04-07`, observed on the primary request;
|
||
|
|
- tariff reference: dated 2026-09-27 review of first-party global standard pricing.
|
||
|
|
|
||
|
|
The optional CLI title-generation request remains refused: its structured-output
|
||
|
|
beta/format are not admitted. The primary request succeeds in the synthetic
|
||
|
|
proof. Mid-conversation system-role messages remain refused by the narrow
|
||
|
|
transport; this first-response proof does not establish a complete tool loop.
|
||
|
|
Do not broaden that transport as an implied consequence of allowing the header.
|
||
|
|
|
||
|
|
The input upper rate remains 4 micro-USD/token (covers one-hour cache creation),
|
||
|
|
output 10. Maximum full-output request hold: USD 4.64. At the configured 0.87
|
||
|
|
EUR/USD treatment that is EUR 4.0368. The existing USD 5.74 run reservation can
|
||
|
|
fit **one** such request; even a second minimum-output request cannot fit after
|
||
|
|
it. Actual low usage does not refund the full conservative charge.
|
||
|
|
Two full-output requests would require USD 9.28 (EUR 8.0736 at that configured
|
||
|
|
conversion); increasing the existing EUR 5 cap requires a new spend-policy/grant,
|
||
|
|
ledger and recipient pins. It is not part of this correction. The preserved
|
||
|
|
EUR 20 daily/EUR 500 total and validity through January 2027 are installed proof
|
||
|
|
policy values, not acceptance of the old factory proposal or a guaranteed future
|
||
|
|
FX/tariff ceiling. Recheck FX, tariff validity and the execution window before use.
|
||
|
|
|
||
|
|
Sources: [model limits](https://platform.claude.com/docs/en/models/sonnet-5/whats-new-sonnet-5)
|
||
|
|
and [pricing](https://platform.claude.com/docs/en/about-claude/pricing), inspected
|
||
|
|
2026-09-27. `provider-facts.json` records these inputs and the observed CLI shape.
|
||
|
|
|
||
|
|
Validation: the complete Secrets Engine suite passed **498 tests**. The exact
|
||
|
|
final proof script hash is recorded in the target receipt.
|
||
|
|
|
||
|
|
## Evidence and exact requests
|
||
|
|
|
||
|
|
- `activation-review.json`: six unapproved exact CheckRequests, apply/verify/exec
|
||
|
|
for each of the provider and worker-token lanes, plus their two native plans.
|
||
|
|
- `../../evidence/2026-09-27-installed-policy-refusal.json`: the installed policy
|
||
|
|
fails context, output and beta compatibility checks.
|
||
|
|
- `../../evidence/2026-09-27-sonnet5-runtime-proof.json`: actual Railiance CLI
|
||
|
|
2.1.266/profile 1.1.1/model Sonnet 5, positive fake stream, zero-forward capacity
|
||
|
|
refusal, private-state exclusion, read-only unchanged artifact and teardown.
|
||
|
|
- `../../evidence/2026-09-27-metered-host-preflight.json`: old mode-0600 owner pin,
|
||
|
|
unchanged spend pin, all three ledger tables empty, clean target and active
|
||
|
|
Activity Core forward. These are observations, not permanent preconditions.
|
||
|
|
|
||
|
|
The six requests are built by the same `_expected_request` code as the PEP.
|
||
|
|
They have no issued approval IDs or evaluator-origin digests. Do not use a local
|
||
|
|
hash as a native evaluator digest. The provider lane requires human control;
|
||
|
|
the companion retains its separately accepted ordinary lane approval.
|
||
|
|
|
||
|
|
Reproduce the offline review from the secrets-engine root:
|
||
|
|
|
||
|
|
```sh
|
||
|
|
uv run python tools/prepare_metered_activation.py \
|
||
|
|
--catalog-dir catalog \
|
||
|
|
--owner-snapshot docs/proposals/glas-metered-20260927/owner.json \
|
||
|
|
--spend-snapshot docs/proposals/glas-metered-20260927/spend-policy.snapshot.json \
|
||
|
|
--provider-facts docs/proposals/glas-metered-20260927/provider-facts.json \
|
||
|
|
--output /tmp/new-metered-activation-review.json
|
||
|
|
```
|
||
|
|
|
||
|
|
The output must not already exist. This command performs no network access,
|
||
|
|
credential retrieval, host mutation, queue claim or approval consumption.
|
||
|
|
|
||
|
|
## Remaining native sequence
|
||
|
|
|
||
|
|
1. Approve the corrected host owner file and exact source release. Replace only
|
||
|
|
`/home/tegwick/hfact/owner-metered/owner.json`, preserving mode 0600. Require
|
||
|
|
the old SHA-256 `0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274`,
|
||
|
|
unchanged spend-policy pin and empty parent/request/route tables before the
|
||
|
|
replacement. Refuse drift; do not reset or recreate the existing ledger.
|
||
|
|
2. Update the host Secrets Engine from `f7c12bed` to the reviewed source including
|
||
|
|
the companion-only guards and corrected catalog pin. No worker restart or
|
||
|
|
profile promotion is required for this file-only correction. Validate the
|
||
|
|
exact recipient path/pins and run its backend-free `metered-once --check`.
|
||
|
|
3. Choose and accept the next proof's budget and scope. The existing EUR 5 cap
|
||
|
|
permits one bounded model response but cannot establish a completed native
|
||
|
|
tool session. Do not queue the one-commit task expecting two calls to fit.
|
||
|
|
4. Use the current owner routing catalog and scoped attended requester lane
|
||
|
|
`secrets-engine-requester-login` to obtain evaluator bindings and create fresh
|
||
|
|
exact approvals. Use the admitted human review surface for the provider
|
||
|
|
lane. Do not seed human entries, reuse OpenRouter IDs, or reinterpret CCR
|
||
|
|
custody as action approval. Refresh Railiance Clock admission at execution.
|
||
|
|
5. Under the scoped approval-client reader and separately attended backend lane,
|
||
|
|
apply only the two data-read policies/AppRoles (5m TTL, max 15m, single-use
|
||
|
|
SecretIDs, eight token uses). Verify exact read and unrelated identity,
|
||
|
|
sibling path, metadata/list/write denials and revocation separately per lane.
|
||
|
|
Keep existing KV values and the standing claim-loop credential untouched.
|
||
|
|
6. Invoke only the pinned one-cycle owner after both lanes pass their own
|
||
|
|
claim/PDP/consume/readiness gates. Record natural claim/heartbeat/close,
|
||
|
|
request holds, cleanup, actual outcome and revocation. Retain failures.
|
||
|
|
|
||
|
|
Native configuration, requester login, real human entries and paid execution
|
||
|
|
are not performed by this packet. Required attended authentication cannot be
|
||
|
|
substituted by an agent action. The complete factory G0 and useful delivery
|
||
|
|
remain HFACT T01/T05; this packet is the narrower disposable Glas proof.
|