Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -49,8 +49,8 @@ synthetic exec-env transport proof passed; no real secret was read.
```task
id: SECRETS-WP-0009-T03
status: wait
blocking_reason: "Configured owner and worker companion passed backend-free recipient/pin checks on 2026-09-27 (SECRETS-WP-0011 complete). Remaining: exact per-action/per-lane approvals, unrelated negative identity, scoped attended apply/verify, bounded real owner delivery and revocation. Recheck pins and spend validity at execution."
priority: high
blocking_reason: "Shared native chain proved by SECRETS-WP-0010-T03. Metered owner provisioned and binding drafted (2026-09-23); Activity Core reports identity live (2026-09-24). Remaining: current recipient/pin admission, unrelated negative identity, configured exec_owner, exact per-action/per-lane approvals and attended apply/verify/exec/revoke."
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
```
@ -503,3 +503,19 @@ native apply, positive/negative verification, exec and session revocation.
The production catalog remains pending. The companion-only delivery guards
added under SECRETS-WP-0011-T05 must be included in the host checkout used for
activation. No credential read, queue claim or paid run occurred in this review.
### 2026-09-27 configured owner and companion landed
SECRETS-WP-0011 is finished at its catalog/implementation boundary. The binding
formerly held in `docs/drafts/glas-exec-owner-configured.yaml` is now configured
in the active Glas catalog, with an added exact private spend-policy file pin.
The installed owner's backend-free check and engine path/pin validation passed
on railiance01. Receipt: `docs/evidence/2026-09-27-companion-catalog-readiness.json`.
The original pending-recipient configuration is superseded; current code still
refuses any substituted child and requires fresh approvals and delivery state.
T03 retains all native activation and delivery acceptance. Revalidate the owner
and spend envelope in the attended execution window, use approvals bound to the
new owner digest and each lane, apply/verify both native lanes, and prove actual
bounded owner delivery and cleanup. Configuration does not authorize those actions.