Correct metered Sonnet 5 admission and prepare native action packet
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e332-3365-77c0-8491-084e9ea33ac1
This commit is contained in:
tegwick 2026-09-27 17:00:33 +02:00
parent 46a54acc0c
commit 11cc0d5452
13 changed files with 2111 additions and 3 deletions

View file

@ -49,7 +49,7 @@ synthetic exec-env transport proof passed; no real secret was read.
```task
id: SECRETS-WP-0009-T03
status: wait
blocking_reason: "Configured owner and worker companion passed backend-free recipient/pin checks on 2026-09-27 (SECRETS-WP-0011 complete). Remaining: exact per-action/per-lane approvals, unrelated negative identity, scoped attended apply/verify, bounded real owner delivery and revocation. Recheck pins and spend validity at execution."
blocking_reason: "Exact-profile review found installed context/output/beta mismatches. Corrected owner candidate and source catalog pin prepared with six unapproved action requests; exact Sonnet 5 synthetic target proof passes. Await reviewed host config/source installation, proof budget and FX/tariff acceptance, then attended per-lane approvals/apply/verify/delivery/revocation."
priority: high
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
```
@ -519,3 +519,36 @@ T03 retains all native activation and delivery acceptance. Revalidate the owner
and spend envelope in the attended execution window, use approvals bound to the
new owner digest and each lane, apply/verify both native lanes, and prove actual
bounded owner delivery and cleanup. Configuration does not authorize those actions.
### 2026-09-27 exact-model admission correction
The earlier backend-free pin check verified byte identity, not provider liability
or actual CLI compatibility. Cross-owner follow-up found the installed owner
reserved only 200k input tokens although Sonnet 5 accepts 1M, capped output at
32k although the CLI requests 64k, and omitted a primary-request beta. The prior
runtime proof silently selected profile 1.0.0; rein now requires exact profile
and expected model and passed the corrected synthetic proof on Railiance.
`tools/prepare_metered_activation.py` now builds the six exact per-lane/action
CheckRequests through the PEP's own request builder, renders both plans and
checks the pinned non-secret config snapshots against reviewed provider facts
and observed CLI shape. It makes no network or authorization call. The installed
policy fails; the corrected candidate passes. Native evaluator digests and
approval IDs are deliberately absent. See `docs/proposals/glas-metered-20260927/`.
The source catalog now pins corrected owner SHA-256
`e0d3fb84649fdca302eccd9415f3cc2beaee84bf07bd83205cdffbe93e5573bc`.
The host still has `0e263f82…`, so current source refuses it until reviewed
replacement. The unchanged spend-policy pin is `f31c5859…`; read-only host
inspection found zero rows in parent, request and route tables and a clean target.
Host Secrets Engine remains f7c12bed and needs current companion guards before
activation. The provider/worker custody and standing claim loop are untouched.
The corrected maximum hold is USD 4.64; only one fits the existing USD 5.74
allowance. Do not promise tool-loop completion under that cap. T03 retains
host installation, scope/budget/FX/tariff acceptance and the existing native
attended approvals, verification, delivery and revocation. No secret read,
approval creation/consume, native apply or paid run occurred.
Validation for this correction: 498 tests passed in the full Secrets Engine suite;
the finalized exact-profile Railiance proof passed and records its script SHA-256.