Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex
topic_slug: custodian
created: "2026-08-21"
updated: "2026-09-06"
updated: "2026-09-27"
state_hub_workstream_id: "31f7f8ea-7f73-516c-8877-f03a13f1db82"
---
@ -195,6 +195,7 @@ Acceptance:
```task
id: SECRETS-WP-0006-T05
status: wait
blocking_reason: "OpenRouter key-check native acceptance is recorded in SECRETS-WP-0010-T03. Other lanes still need exact approvals, scoped attended apply and per-lane positive/negative/health/revocation evidence."
priority: high
state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542"
```
@ -256,6 +257,7 @@ Acceptance per lane:
```task
id: SECRETS-WP-0006-T06
status: wait
blocking_reason: "Needs owner-agreed routing/proxy retirement for each verified lane and custody disposition of the legacy npm pointer; a single approved OpenRouter key-check does not authorize broader routing cutover."
priority: medium
state_hub_task_id: "1431edae-5791-5892-8c4b-829419b537d2"
```
@ -424,3 +426,13 @@ for a fourth location.
`SECRETS-WP-0006-T06` stays `wait`: this answer unblocks the question, not the
lane change, which needs custody's step 1 and its own approval.
### Existing-work review — 2026-09-27
The September 16 native OpenRouter key-check receipt supersedes the older
serving/ESO-health wait for that exact recipient. SECRETS-WP-0007-T04 and
SECRETS-WP-0008-T02 are now closed against that real evidence and current
regression coverage. T05 remains open for the other lanes; T06 retains
per-lane routing/proxy retirement and the npm custody discrepancy. No broader
recipient, proxy retirement, or production action is inferred from that receipt.

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex
topic_slug: custodian
created: "2026-08-23"
updated: "2026-09-06"
updated: "2026-09-27"
state_hub_workstream_id: "68a39be1-bd9c-5133-ad64-e7bca892aaf3"
---
@ -213,11 +213,15 @@ Acceptance:
```task
id: SECRETS-WP-0007-T04
status: wait
status: done
priority: high
state_hub_task_id: "4b58edec-c705-55e5-9ece-362e1ff13079"
```
Completed 2026-09-27 by reconciling the implemented shared approval guard with the
2026-09-16 native receipt. See the closure note below; the serving-path waits
in the dated history are superseded. Native lane cutover remains T07.
Wait 2026-08-29. The consumer validator and production fail-closed gate are
shipped. What remains is not local engine work: State Hub / `access-engine`
must serve the durable ActionAuthorization object. Paired with
@ -707,6 +711,7 @@ Acceptance:
```task
id: SECRETS-WP-0007-T07
status: wait
blocking_reason: "Engine approval hardening is complete. Remaining per-lane cutover includes native routing/proxy retirement with ops-warden under SECRETS-WP-0006-T05/T06; the exact OpenRouter key-check receipt does not establish broader recipient readiness."
priority: high
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
```
@ -787,3 +792,25 @@ routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readines
Do not reuse the consumed approvals or treat the temporary key-check overlay as
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
### T04 completed after evidence reconciliation — 2026-09-27
The original serving-path wait is superseded by the native 2026-09-16 receipt
`docs/evidence/2026-09-16-t03-completion.json`, not by synthetic tests or Hub
status. It records separate human-controlled apply, verify and exec approvals,
three distinct current PDP decisions/request digests, successful CAS consumes,
and the resulting native OpenBao operations. The claim/PDP/consume join is the
accepted path; the earlier proposed ActionAuthorization is not a dependency.
Current regression coverage exercises wrong fields/actions/tenant/digest,
superseded or expired claims, changed catalog/owner bindings, denied or missing
PDP responses, consume conflicts/unavailability, declared human control and
production fixture refusal. Every live privileged handler still uses the shared
approval gate before backend access. The recorded approvals are consumed and
expired; they are historical completion evidence, never reusable grants.
T04 is done. T07 stays wait because its per-lane acceptance includes routing and
proxy retirement, and the receipt covers only the exact OpenRouter key-check
recipient. Other lanes and cross-owner cutover remain SECRETS-WP-0006-T05/T06;
this workplan is not finished merely because the engine gate is complete.

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: grok
topic_slug: custodian
created: "2026-08-29"
updated: "2026-09-21"
updated: "2026-09-27"
state_hub_workstream_id: "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0"
---
@ -90,11 +90,15 @@ Acceptance:
```task
id: SECRETS-WP-0008-T02
status: wait
status: done
priority: high
state_hub_task_id: "3eb9cff8-1441-5437-9e92-a2b655c82d04"
```
Completed 2026-09-27: the 2026-09-16 native apply/verify/exec receipt supplies
the live PDP/claim/consume return awaited below. The dated serving-path waits
are historical. Service JWT adoption remains T06.
Progress 2026-09-02. Gate House notice `632bdad9` (`GH-DEC-2026-003`): this
engine is the PEP for FLEX-WP-0017-T05 / OpenBao writes. The shared consume
function now lives in `src/secrets_engine/approval_consume.py` and every live
@ -327,6 +331,7 @@ Acceptance:
```task
id: SECRETS-WP-0008-T06
status: wait
blocking_reason: "RPF-WP-0035-T02 still awaits exact service claims/tenant, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
priority: medium
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
```
@ -486,3 +491,26 @@ gate-house (message `4220413a`); we follow that answer rather than choose.
- `layer.yaml` / `pep-stance.yaml` / INTENT frontmatter stay in one voice.
- No raw secret values in Git, State Hub, chat, prompts, workplans, evidence,
or argv.
## Decision consumer closure and declaration ruling applied — 2026-09-27
T02 is done. `docs/evidence/2026-09-16-t03-completion.json` provides the native
return awaited in the September 9 note: separately approved apply/verify/exec
requests received current PDP allows and successful CAS consumption before real
OpenBao work. The shared guard records decision IDs and retains refusal before
backend access for invalid/missing/replayed decisions. SECRETS-WP-0007-T04 now
records the same completed contract; no native activation grant is inferred.
The open conformance-record question is also resolved. GH-DEC-2026-020 §4 says
a versioned/scoped re-runnable checker is sufficient; each declaring repository
need not emit a durable record. GH-DEC-2026-021 §2/§3 names the accepted v0.7
text plus applicable decisions and the ops-warden reference detector. The
checker now copies that detector, permits own-document versions/prose citations,
refuses nested/identity-bearing version pins and names the accepted text and
rulings on every run, including PASS. Declaration spellings are unchanged.
T06 remains wait: railiance-platform's RPF-WP-0035-T02 still records an
unprovisioned, login-only JWT role, pending exact service claims/tenant and
custody/attended admission. The existing env-auth native receipt cannot prove
steady-state service JWT login. This is the only remaining task in this workplan.

View file

@ -49,8 +49,8 @@ synthetic exec-env transport proof passed; no real secret was read.
```task
id: SECRETS-WP-0009-T03
status: wait
blocking_reason: "Configured owner and worker companion passed backend-free recipient/pin checks on 2026-09-27 (SECRETS-WP-0011 complete). Remaining: exact per-action/per-lane approvals, unrelated negative identity, scoped attended apply/verify, bounded real owner delivery and revocation. Recheck pins and spend validity at execution."
priority: high
blocking_reason: "Shared native chain proved by SECRETS-WP-0010-T03. Metered owner provisioned and binding drafted (2026-09-23); Activity Core reports identity live (2026-09-24). Remaining: current recipient/pin admission, unrelated negative identity, configured exec_owner, exact per-action/per-lane approvals and attended apply/verify/exec/revoke."
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
```
@ -503,3 +503,19 @@ native apply, positive/negative verification, exec and session revocation.
The production catalog remains pending. The companion-only delivery guards
added under SECRETS-WP-0011-T05 must be included in the host checkout used for
activation. No credential read, queue claim or paid run occurred in this review.
### 2026-09-27 configured owner and companion landed
SECRETS-WP-0011 is finished at its catalog/implementation boundary. The binding
formerly held in `docs/drafts/glas-exec-owner-configured.yaml` is now configured
in the active Glas catalog, with an added exact private spend-policy file pin.
The installed owner's backend-free check and engine path/pin validation passed
on railiance01. Receipt: `docs/evidence/2026-09-27-companion-catalog-readiness.json`.
The original pending-recipient configuration is superseded; current code still
refuses any substituted child and requires fresh approvals and delivery state.
T03 retains all native activation and delivery acceptance. Revalidate the owner
and spend envelope in the attended execution window, use approvals bound to the
new owner digest and each lane, apply/verify both native lanes, and prove actual
bounded owner delivery and cleanup. Configuration does not authorize those actions.

View file

@ -4,7 +4,7 @@ type: workplan
title: "Multi-lane exec-owner delivery"
domain: infotech
repo: secrets-engine
status: active
status: finished
flavor: implementation
owner: claude-code
topic_slug: netkingdom
@ -91,12 +91,15 @@ a throwaway OpenBao dev server.
```task
id: SECRETS-WP-0011-T04
status: wait
status: done
priority: high
blocking_reason: "Activity Core reports ACTIVITY-WP-0039 finished and metered identity authentication proved (2026-09-24). Remaining: admit the configured Glas owner, obtain exact per-lane approvals, and perform attended native apply/verify/delivery under SECRETS-WP-0009-T03."
state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d"
```
Completed 2026-09-27: custody handoff received, companion cataloged and wired
into the configured Glas owner after fresh backend-free host verification.
Native activation remains in existing SECRETS-WP-0009-T03, as detailed below.
Request activity-core to move the worker token into OpenBao custody, synced to
`actcore-runtime-secret` by their existing `openbao-activity-core` store. Then
catalog a read lane for the metered owner and add it as the Glas lane's
@ -172,3 +175,27 @@ T04 remains wait for native lane activation with SECRETS-WP-0009-T03: current
owner admission/pins, exact per-lane approvals and attended apply/verify/exec.
The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching
the handoff. No production policy, role, catalog binding or credential changed.
## Catalog task and workplan completed — 2026-09-27
T04's stated work is custody coordination, the worker-token catalog entry and
adding that entry as the Glas owner's companion. All three are now complete.
Activity Core's 2026-09-24 handoff supplies the custody/identity return. The
configured binding is now in `catalog/glas-claude-agent-dev-anthropic.yaml`,
including the worker identity/label and a private spend-policy file pin.
A fresh backend-free check on railiance01 verified the installed owner with
`metered-once --check --no-hub` (dispatch disabled), and this checkout's exact
path/ownership/mode/hash checks passed for the executable, owner configuration,
spend policy and private working directory. Receipt:
`docs/evidence/2026-09-27-companion-catalog-readiness.json`.
The owner digest is `46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b`.
The previous wait reason conflated catalog completion with native activation.
That activation was already owned by SECRETS-WP-0009-T03 and stays there: exact
per-lane action approvals, scoped attended apply, positive/negative verification,
actual bounded delivery and session revocation. No new task is needed. This
workplan's completion claims the configured multi-lane contract, its tests and
catalog wiring, not production delivery. No credential was requested or read,
no queue row was claimed, and no provider request was made.