Correct metered Sonnet 5 admission and prepare native action packet
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e332-3365-77c0-8491-084e9ea33ac1
This commit is contained in:
tegwick 2026-09-27 17:00:33 +02:00
parent 46a54acc0c
commit 11cc0d5452
13 changed files with 2111 additions and 3 deletions

View file

@ -0,0 +1,106 @@
# Metered owner activation candidate — 2026-09-27
This is a reviewed source candidate, not native authorization. No provider key
was read, no approval created or consumed, and no paid/production queue attempt
was made. The live owner still has the old file; the source catalog now pins the
corrected file and will refuse that old file.
## Concrete correction
`owner.json` retains the installed runtime, spend-policy digest and authority
reference. Only its Messages policy changes:
- input liability context: 200000 → 1000000 (Sonnet 5 has no 200k variant);
- output ceiling: 32000 → 64000 (observed from the pinned actual CLI);
- allow `mid-conversation-system-2026-04-07`, observed on the primary request;
- tariff reference: dated 2026-09-27 review of first-party global standard pricing.
The optional CLI title-generation request remains refused: its structured-output
beta/format are not admitted. The primary request succeeds in the synthetic
proof. Mid-conversation system-role messages remain refused by the narrow
transport; this first-response proof does not establish a complete tool loop.
Do not broaden that transport as an implied consequence of allowing the header.
The input upper rate remains 4 micro-USD/token (covers one-hour cache creation),
output 10. Maximum full-output request hold: USD 4.64. At the configured 0.87
EUR/USD treatment that is EUR 4.0368. The existing USD 5.74 run reservation can
fit **one** such request; even a second minimum-output request cannot fit after
it. Actual low usage does not refund the full conservative charge.
Two full-output requests would require USD 9.28 (EUR 8.0736 at that configured
conversion); increasing the existing EUR 5 cap requires a new spend-policy/grant,
ledger and recipient pins. It is not part of this correction. The preserved
EUR 20 daily/EUR 500 total and validity through January 2027 are installed proof
policy values, not acceptance of the old factory proposal or a guaranteed future
FX/tariff ceiling. Recheck FX, tariff validity and the execution window before use.
Sources: [model limits](https://platform.claude.com/docs/en/models/sonnet-5/whats-new-sonnet-5)
and [pricing](https://platform.claude.com/docs/en/about-claude/pricing), inspected
2026-09-27. `provider-facts.json` records these inputs and the observed CLI shape.
Validation: the complete Secrets Engine suite passed **498 tests**. The exact
final proof script hash is recorded in the target receipt.
## Evidence and exact requests
- `activation-review.json`: six unapproved exact CheckRequests, apply/verify/exec
for each of the provider and worker-token lanes, plus their two native plans.
- `../../evidence/2026-09-27-installed-policy-refusal.json`: the installed policy
fails context, output and beta compatibility checks.
- `../../evidence/2026-09-27-sonnet5-runtime-proof.json`: actual Railiance CLI
2.1.266/profile 1.1.1/model Sonnet 5, positive fake stream, zero-forward capacity
refusal, private-state exclusion, read-only unchanged artifact and teardown.
- `../../evidence/2026-09-27-metered-host-preflight.json`: old mode-0600 owner pin,
unchanged spend pin, all three ledger tables empty, clean target and active
Activity Core forward. These are observations, not permanent preconditions.
The six requests are built by the same `_expected_request` code as the PEP.
They have no issued approval IDs or evaluator-origin digests. Do not use a local
hash as a native evaluator digest. The provider lane requires human control;
the companion retains its separately accepted ordinary lane approval.
Reproduce the offline review from the secrets-engine root:
```sh
uv run python tools/prepare_metered_activation.py \
--catalog-dir catalog \
--owner-snapshot docs/proposals/glas-metered-20260927/owner.json \
--spend-snapshot docs/proposals/glas-metered-20260927/spend-policy.snapshot.json \
--provider-facts docs/proposals/glas-metered-20260927/provider-facts.json \
--output /tmp/new-metered-activation-review.json
```
The output must not already exist. This command performs no network access,
credential retrieval, host mutation, queue claim or approval consumption.
## Remaining native sequence
1. Approve the corrected host owner file and exact source release. Replace only
`/home/tegwick/hfact/owner-metered/owner.json`, preserving mode 0600. Require
the old SHA-256 `0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274`,
unchanged spend-policy pin and empty parent/request/route tables before the
replacement. Refuse drift; do not reset or recreate the existing ledger.
2. Update the host Secrets Engine from `f7c12bed` to the reviewed source including
the companion-only guards and corrected catalog pin. No worker restart or
profile promotion is required for this file-only correction. Validate the
exact recipient path/pins and run its backend-free `metered-once --check`.
3. Choose and accept the next proof's budget and scope. The existing EUR 5 cap
permits one bounded model response but cannot establish a completed native
tool session. Do not queue the one-commit task expecting two calls to fit.
4. Use the current owner routing catalog and scoped attended requester lane
`secrets-engine-requester-login` to obtain evaluator bindings and create fresh
exact approvals. Use the admitted human review surface for the provider
lane. Do not seed human entries, reuse OpenRouter IDs, or reinterpret CCR
custody as action approval. Refresh Railiance Clock admission at execution.
5. Under the scoped approval-client reader and separately attended backend lane,
apply only the two data-read policies/AppRoles (5m TTL, max 15m, single-use
SecretIDs, eight token uses). Verify exact read and unrelated identity,
sibling path, metadata/list/write denials and revocation separately per lane.
Keep existing KV values and the standing claim-loop credential untouched.
6. Invoke only the pinned one-cycle owner after both lanes pass their own
claim/PDP/consume/readiness gates. Record natural claim/heartbeat/close,
request holds, cleanup, actual outcome and revocation. Retain failures.
Native configuration, requester login, real human entries and paid execution
are not performed by this packet. Required attended authentication cannot be
substituted by an agent action. The complete factory G0 and useful delivery
remain HFACT T01/T05; this packet is the narrower disposable Glas proof.