Enforce companion-only credential delivery and refresh activation handoff
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
303cbf652b
commit
5c6f2b319d
8 changed files with 150 additions and 24 deletions
|
|
@ -1,6 +1,7 @@
|
|||
# Draft exec_owner for glas-claude-agent-dev-anthropic (SECRETS-WP-0009-T03).
|
||||
# Not in the catalog: it replaces the pending binding only after
|
||||
# activity-core-metered-worker-token is seeded and ACTIVITY-WP-0039 is live.
|
||||
# Not in the catalog. Activity Core reports custody and identity live as of
|
||||
# 2026-09-24 (ACTIVITY-WP-0039). Admission still requires current owner/pin
|
||||
# validation and exact per-lane approvals for attended native activation.
|
||||
exec_owner:
|
||||
status: configured
|
||||
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
|
||||
|
|
|
|||
|
|
@ -109,7 +109,9 @@ The companion lane must consent in its own catalog entry with
|
|||
the same stage, declare the field and `exec-env`, and bind no exec owner of its
|
||||
own. Env names must be unique, must not match the fixed environment or the
|
||||
primary field's name, and must not use loader or engine credential prefixes.
|
||||
Pending owners cannot list companions.
|
||||
Pending owners cannot list companions. A lane declaring `companion_of` cannot
|
||||
be selected as the primary `exec` lane: it is delivered only through a listed
|
||||
primary with a configured owner, even if standalone lane approval exists.
|
||||
|
||||
Companions are part of the owner binding, so changing a companion's lane, field
|
||||
or env name changes the owner digest and invalidates earlier decisions.
|
||||
|
|
@ -120,6 +122,9 @@ consume for action `exec`. No lane's decision covers another lane. After every
|
|||
gate passes, each value is read through its own lane's AppRole session. A
|
||||
failure on any lane starts no child. The binding is checked again after the
|
||||
reads, and all values are injected together and redacted from the output.
|
||||
The delivery helper independently checks that the supplied companions exactly
|
||||
match the pinned lane/field/environment list and still satisfy consent and stage
|
||||
constraints before reading the primary or any companion.
|
||||
|
||||
Proof: `tests/test_exec_owner_companions.py`, plus
|
||||
`tests/test_integration_companions.py` on a throwaway OpenBao (two lanes, one
|
||||
|
|
|
|||
|
|
@ -37,23 +37,27 @@ approval, OpenBao access, provider authentication or production readiness.
|
|||
|
||||
## Activation requirements
|
||||
|
||||
The current engine's production stance refuses before opening the backend:
|
||||
`production action 'exec' requires a durable access-engine decision record;
|
||||
live production remains disabled`. This refusal was exercised with the proposed
|
||||
catalog and service-jwt selection. No real value was requested.
|
||||
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
|
||||
SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and
|
||||
refuses exec before approval consumption or backend access. The earlier lack
|
||||
of a served decision path is no longer the current activation blocker.
|
||||
|
||||
Activation depends on SECRETS-WP-0007-T04 (exact production actions) and
|
||||
SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require
|
||||
canonical validated DecisionEnvelope for each protected action, successful consume,
|
||||
and exact scoped backend authority. This draft cannot authorize itself; an
|
||||
operator browser token or unsafe-demo flag is not a runtime substitute.
|
||||
The metered owner configuration and binding were prepared on 2026-09-23.
|
||||
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
|
||||
separate `rein-aharness-metered@railiance01` identity are live. See the exact
|
||||
handoff in SECRETS-WP-0011. Its worker token is companion-only; direct exec of
|
||||
`activity-core-metered-worker-token` is refused. The intended recipient is the
|
||||
metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
|
||||
not the historical sandbox helper above.
|
||||
|
||||
Once those services exist: obtain the reviewed apply authorization, apply this
|
||||
exact policy/AppRole with scoped authority, verify positive read and denied
|
||||
metadata/sibling/write access without exposing values, and record delivery-ready
|
||||
state. Bind approved exec authorization and named engine service authentication
|
||||
to the sand-boxer owner route. Prove actual provider authentication and a bounded
|
||||
Glas task, then activate routing and only the validated profile.
|
||||
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
|
||||
activation. Review the draft binding, revalidate installed files and private
|
||||
state, configure the approved owner, and obtain exact per-action/per-lane
|
||||
approvals. Apply the scoped policy/AppRole, verify positive read and denied
|
||||
metadata/sibling/write access with an unrelated negative identity, then prove
|
||||
bounded owner delivery and session revocation. Both lanes must independently
|
||||
pass approval, PDP, consume and delivery readiness. The handoff and draft are
|
||||
not runtime authorization. No production activation was performed in this review.
|
||||
|
||||
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
|
||||
predecessor at Anthropic and prove denial. Bao session expiration does not revoke
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue