Finish companion catalog work and reconcile completed approval tasks
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
41e4c4a3d8
commit
e33f9c3ca5
18 changed files with 472 additions and 87 deletions
|
|
@ -3,8 +3,8 @@ kind: kv
|
||||||
org: coulomb
|
org: coulomb
|
||||||
repo: sand-boxer
|
repo: sand-boxer
|
||||||
stage: prod
|
stage: prod
|
||||||
description: Proposed native exec-env delivery for CCR-2026-0016. KV custody exists;
|
description: Catalog-bound metered owner with Activity Core worker-token companion.
|
||||||
no runtime grant or activation yet.
|
KV custody exists; native runtime approval and activation remain SECRETS-WP-0009-T03.
|
||||||
mount: platform
|
mount: platform
|
||||||
path: workloads/glas-harness/claude-agent-dev
|
path: workloads/glas-harness/claude-agent-dev
|
||||||
mount_management: existing
|
mount_management: existing
|
||||||
|
|
@ -19,12 +19,46 @@ consumers:
|
||||||
workload_delivery: []
|
workload_delivery: []
|
||||||
delivery_config:
|
delivery_config:
|
||||||
exec_owner:
|
exec_owner:
|
||||||
status: pending
|
status: configured
|
||||||
owner: rein-aharness MessagesOwner with sand-boxer runtime boundary
|
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
|
||||||
reason: Exact installed metered-once runtime is proved; native holder review,
|
command:
|
||||||
immutable owner configuration and private state/profile/service admission
|
- /home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3
|
||||||
remain SECRETS-WP-0009-T03 and HFACT-WP-0001-T03/T04. No arbitrary child may
|
- -I
|
||||||
receive this key while the owner binding is pending.
|
- -B
|
||||||
|
- -m
|
||||||
|
- rein_aharness.cli
|
||||||
|
- metered-once
|
||||||
|
- --owner-config
|
||||||
|
- /home/tegwick/hfact/owner-metered/owner.json
|
||||||
|
cwd: /home/tegwick/hfact/owner-metered
|
||||||
|
environment:
|
||||||
|
PATH: /usr/bin:/bin
|
||||||
|
LANG: C.UTF-8
|
||||||
|
HOME: /home/tegwick
|
||||||
|
ACTIVITY_CORE_URL: http://127.0.0.1:8010
|
||||||
|
AGENT_HARNESS_WORKER_ID: rein-aharness-metered@railiance01
|
||||||
|
AGENT_HARNESS_OPS_LABELS: hfact-metered
|
||||||
|
AGENT_HARNESS_OPS_LABELS_MODE: all
|
||||||
|
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
|
||||||
|
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
|
||||||
|
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
|
||||||
|
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
|
||||||
|
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
|
||||||
|
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
|
||||||
|
files:
|
||||||
|
/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3:
|
||||||
|
sha256: e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f
|
||||||
|
private: false
|
||||||
|
/home/tegwick/hfact/owner-metered/owner.json:
|
||||||
|
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
|
||||||
|
private: true
|
||||||
|
/home/tegwick/hfact/owner-metered/spend-policy.json:
|
||||||
|
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
|
||||||
|
private: true
|
||||||
|
companions:
|
||||||
|
- catalog: activity-core-metered-worker-token
|
||||||
|
field: token
|
||||||
|
env: ACTIVITY_CORE_WORKER_TOKEN
|
||||||
delivery_modes:
|
delivery_modes:
|
||||||
- exec-env
|
- exec-env
|
||||||
- read-check
|
- read-check
|
||||||
|
|
|
||||||
52
docs/2026-09-27-loose-end-closeout.md
Normal file
52
docs/2026-09-27-loose-end-closeout.md
Normal file
|
|
@ -0,0 +1,52 @@
|
||||||
|
# Existing-work closeout — 2026-09-27
|
||||||
|
|
||||||
|
No new task or workplan was opened. Three tasks and one intake can close from
|
||||||
|
existing evidence plus the local completion below. One workplan finishes.
|
||||||
|
|
||||||
|
| Existing record | Result | Basis |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| SECRETS-WP-0007-T04 | done | Shared exact-action claim/PDP/consume implementation, regression refusals and real separate apply/verify/exec consumes in the September 16 native receipt |
|
||||||
|
| SECRETS-WP-0008-T02 | done | The same native receipt resolves its outstanding served-decision/consume dependency; current regression coverage retains fail-closed replay and lifetime checks |
|
||||||
|
| SECRETS-WP-0011-T04 | done | Activity Core custody/identity handoff received; configured owner and companion now cataloged; current owner/path/hash checks passed on railiance01 without backend access |
|
||||||
|
| SECRETS-WP-0011 | finished | All five tasks complete; native Glas activation remains in the existing SECRETS-WP-0009-T03 |
|
||||||
|
| SECRETS-IN-0003 | closed | Published signing/custody/bootstrap/rotation/revocation and bounded-time consumer review, with limits and existing owner acceptance work named |
|
||||||
|
|
||||||
|
Implementation includes the private spend-policy pin and the estate reference
|
||||||
|
layer-version detector under SECRETS-WP-0008. The latter closes the stale
|
||||||
|
conformance-record question without inventing a durable-record requirement.
|
||||||
|
|
||||||
|
Evidence:
|
||||||
|
|
||||||
|
- [Native approval and delivery receipt](evidence/2026-09-16-t03-completion.json)
|
||||||
|
is historical acceptance for one exact OpenRouter key-check recipient. Its
|
||||||
|
consumed approvals grant no future action.
|
||||||
|
- [Companion catalog receipt](evidence/2026-09-27-companion-catalog-readiness.json)
|
||||||
|
records current backend-free owner validation, installed file pins and owner
|
||||||
|
digest. Configuration is not production approval or delivery readiness.
|
||||||
|
- [Clock consumer review](railiance-clock-consumer-review.md) closes a review
|
||||||
|
request, without enabling a new trust binding or claiming operational rotation.
|
||||||
|
|
||||||
|
## Work that must remain open
|
||||||
|
|
||||||
|
| Existing record | Remaining completion requirement |
|
||||||
|
| --- | --- |
|
||||||
|
| SECRETS-WP-0006-T05 | Approved native verification for the other catalog lanes; the OpenRouter key-check receipt covers one exact recipient only |
|
||||||
|
| SECRETS-WP-0006-T06 | Owner-agreed routing/proxy retirement per verified lane, plus custody disposition of the legacy npm pointer; no unilateral proxy retirement |
|
||||||
|
| SECRETS-WP-0007-T07 | Its acceptance includes native cutover and routing/proxy retirement under 0006-T05/T06; engine hardening alone does not satisfy it |
|
||||||
|
| SECRETS-WP-0008-T06 | Platform/KeyCape exact service claims and tenant, custody, provisioned scoped JWT role and native login/negative/revocation acceptance (RPF-WP-0035-T02); the recorded env-auth run does not prove this |
|
||||||
|
| SECRETS-WP-0009-T03 | Fresh exact per-action/per-lane approvals, unrelated negative identity, attended apply/verify, bounded real Glas delivery and revocation; recheck pins and spend validity in that window |
|
||||||
|
| SECRETS-IN-0002 | Confirmed flex-auth repository rename before changing checkout coordinates; FLEX-WP-0020 still holds the live rename |
|
||||||
|
|
||||||
|
Workplans 0006, 0007, 0008 and 0009 therefore remain unfinished. Their remaining
|
||||||
|
requirements stay in those records, with no replacement or successor task.
|
||||||
|
|
||||||
|
|
||||||
|
Scope reconciliation is recorded as State Hub decision
|
||||||
|
`7a756027-2041-4732-bcbc-3bb6a5380838`; it grants no credential action.
|
||||||
|
|
||||||
|
|
||||||
|
Validation: 487 repository tests passed, including disposable OpenBao integration.
|
||||||
|
The layer-conformance checker and `git diff --check` passed. The configured
|
||||||
|
recipient's local-only owner check and exact engine path/pin checks passed on
|
||||||
|
railiance01; no backend credential was requested, no queue row was claimed and
|
||||||
|
no provider request was made.
|
||||||
|
|
@ -218,3 +218,9 @@ and after CAS consume. The client keeps a boot-bound trust admission and private
|
||||||
rollback floor. It never changes the OS clock, accepts a sample as its own trust
|
rollback floor. It never changes the OS clock, accepts a sample as its own trust
|
||||||
bootstrap, or falls back to a shifted local timestamp. The option stays unset
|
bootstrap, or falls back to a shifted local timestamp. The option stays unset
|
||||||
until the owner publishes trust through the admitted Railiance Clock deployment.
|
until the owner publishes trust through the admitted Railiance Clock deployment.
|
||||||
|
|
||||||
|
|
||||||
|
The [2026-09-27 consumer review](railiance-clock-consumer-review.md) records
|
||||||
|
signing compatibility, custody, bootstrap, rotation/revocation and check-to-use
|
||||||
|
limits. It reconciles SECRETS-IN-0003 with the already recorded September 16
|
||||||
|
native use; it does not enable a new trust binding.
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,6 @@
|
||||||
# Draft exec_owner for glas-claude-agent-dev-anthropic (SECRETS-WP-0009-T03).
|
# Configured binding promoted to catalog/glas-claude-agent-dev-anthropic.yaml
|
||||||
# Not in the catalog. Activity Core reports custody and identity live as of
|
# on 2026-09-27 after backend-free owner and path/pin validation.
|
||||||
# 2026-09-24 (ACTIVITY-WP-0039). Admission still requires current owner/pin
|
# Configuration is not runtime approval; native activation is SECRETS-WP-0009-T03.
|
||||||
# validation and exact per-lane approvals for attended native activation.
|
|
||||||
exec_owner:
|
exec_owner:
|
||||||
status: configured
|
status: configured
|
||||||
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
|
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
|
||||||
|
|
@ -24,8 +23,8 @@ exec_owner:
|
||||||
AGENT_HARNESS_OPS_LABELS: hfact-metered
|
AGENT_HARNESS_OPS_LABELS: hfact-metered
|
||||||
AGENT_HARNESS_OPS_LABELS_MODE: all
|
AGENT_HARNESS_OPS_LABELS_MODE: all
|
||||||
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
|
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
|
||||||
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: "1"
|
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
|
||||||
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: "1"
|
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
|
||||||
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
|
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
|
||||||
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
|
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
|
||||||
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
|
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
|
||||||
|
|
@ -36,6 +35,9 @@ exec_owner:
|
||||||
/home/tegwick/hfact/owner-metered/owner.json:
|
/home/tegwick/hfact/owner-metered/owner.json:
|
||||||
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
|
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
|
||||||
private: true
|
private: true
|
||||||
|
/home/tegwick/hfact/owner-metered/spend-policy.json:
|
||||||
|
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
|
||||||
|
private: true
|
||||||
companions:
|
companions:
|
||||||
- catalog: activity-core-metered-worker-token
|
- catalog: activity-core-metered-worker-token
|
||||||
field: token
|
field: token
|
||||||
|
|
|
||||||
42
docs/evidence/2026-09-27-companion-catalog-readiness.json
Normal file
42
docs/evidence/2026-09-27-companion-catalog-readiness.json
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
{
|
||||||
|
"date": "2026-09-27",
|
||||||
|
"task": "SECRETS-WP-0011-T04",
|
||||||
|
"scope": "Catalog configuration and backend-free recipient validation; not live delivery",
|
||||||
|
"host": "railiance01",
|
||||||
|
"activity_core_handoff": "a2eae5f8-60cf-499b-8f52-dd04ac407924",
|
||||||
|
"owner_check": {
|
||||||
|
"ok": true,
|
||||||
|
"check_only": true,
|
||||||
|
"dispatch_enabled": false,
|
||||||
|
"messages_policy_sha256": "a7f70cd57536e39b4b4d66c2d52fc6a74ca30eb16a8ea8dc50b59e177c3247fd",
|
||||||
|
"runtime_sha256": "b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969"
|
||||||
|
},
|
||||||
|
"owner_digest": "46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b",
|
||||||
|
"path_and_pin_checks": "passed",
|
||||||
|
"backend_opened": false,
|
||||||
|
"file_pins": {
|
||||||
|
"/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3": {
|
||||||
|
"sha256": "e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f",
|
||||||
|
"private": false
|
||||||
|
},
|
||||||
|
"/home/tegwick/hfact/owner-metered/owner.json": {
|
||||||
|
"sha256": "0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274",
|
||||||
|
"private": true
|
||||||
|
},
|
||||||
|
"/home/tegwick/hfact/owner-metered/spend-policy.json": {
|
||||||
|
"sha256": "f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c",
|
||||||
|
"private": true
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"worker_identity": "rein-aharness-metered@railiance01",
|
||||||
|
"labels": "hfact-metered",
|
||||||
|
"companion": {
|
||||||
|
"catalog": "activity-core-metered-worker-token",
|
||||||
|
"field": "token",
|
||||||
|
"env": "ACTIVITY_CORE_WORKER_TOKEN"
|
||||||
|
},
|
||||||
|
"credentials_read": false,
|
||||||
|
"queue_claimed": false,
|
||||||
|
"provider_request": false,
|
||||||
|
"native_activation_task": "SECRETS-WP-0009-T03"
|
||||||
|
}
|
||||||
|
|
@ -9,8 +9,9 @@ factory recipient is now a pinned metered owner outside the sandbox. A different
|
||||||
command or inherited engine credential would violate that boundary.
|
command or inherited engine credential would violate that boundary.
|
||||||
|
|
||||||
Catalog `delivery_config.exec_owner` is optional for existing lanes. The Claude
|
Catalog `delivery_config.exec_owner` is optional for existing lanes. The Claude
|
||||||
factory lane explicitly requires it and currently declares `status: pending`,
|
factory lane explicitly requires it. It now has a configured metered recipient
|
||||||
`owner` and `reason`. Pending means no exec: refusal precedes approval consumption,
|
and worker-token companion, validated on 2026-09-27. A pending binding declares
|
||||||
|
only `status: pending`, `owner` and `reason`. Pending means no exec: refusal precedes approval consumption,
|
||||||
backend opening and secret retrieval. Routing stays unready even if custody exists.
|
backend opening and secret retrieval. Routing stays unready even if custody exists.
|
||||||
|
|
||||||
A reviewed binding uses exactly these keys:
|
A reviewed binding uses exactly these keys:
|
||||||
|
|
|
||||||
|
|
@ -7,8 +7,8 @@ part of native read-lane adoption.
|
||||||
|
|
||||||
2026-09-10: the factory continuation uses a metered MessagesOwner outside the
|
2026-09-10: the factory continuation uses a metered MessagesOwner outside the
|
||||||
sandbox. Its exact runtime is installed and synthetically proved on Railiance.
|
sandbox. Its exact runtime is installed and synthetically proved on Railiance.
|
||||||
The catalog now blocks exec with an explicit pending recipient binding until the
|
That initial pending binding has since been replaced by the pinned configuration
|
||||||
native holder and immutable configuration are admitted. See
|
reviewed on 2026-09-27; native activation remains separate. See
|
||||||
[exec owner binding](exec-owner-binding.md). The older transport description
|
[exec owner binding](exec-owner-binding.md). The older transport description
|
||||||
below records the original child-key route; it cannot admit the metered holder.
|
below records the original child-key route; it cannot admit the metered holder.
|
||||||
|
|
||||||
|
|
@ -38,9 +38,10 @@ approval, OpenBao access, provider authentication or production readiness.
|
||||||
## Activation requirements
|
## Activation requirements
|
||||||
|
|
||||||
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
|
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
|
||||||
SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and
|
SECRETS-WP-0010-T03. The Glas catalog now has a configured owner binding and worker companion,
|
||||||
refuses exec before approval consumption or backend access. The earlier lack
|
verified by backend-free checks on railiance01. It refuses substituted children
|
||||||
of a served decision path is no longer the current activation blocker.
|
and still requires fresh exact approvals and verified delivery state. The earlier
|
||||||
|
lack of a served decision path is no longer the current activation blocker.
|
||||||
|
|
||||||
The metered owner configuration and binding were prepared on 2026-09-23.
|
The metered owner configuration and binding were prepared on 2026-09-23.
|
||||||
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
|
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
|
||||||
|
|
@ -51,12 +52,11 @@ metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
|
||||||
not the historical sandbox helper above.
|
not the historical sandbox helper above.
|
||||||
|
|
||||||
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
|
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
|
||||||
activation. Review the draft binding, revalidate installed files and private
|
activation. Revalidate the configured binding, installed files and private
|
||||||
state, configure the approved owner, and obtain exact per-action/per-lane
|
state in the execution window, and obtain exact per-action/per-lane approvals. Apply the scoped policy/AppRole, verify positive read and denied
|
||||||
approvals. Apply the scoped policy/AppRole, verify positive read and denied
|
|
||||||
metadata/sibling/write access with an unrelated negative identity, then prove
|
metadata/sibling/write access with an unrelated negative identity, then prove
|
||||||
bounded owner delivery and session revocation. Both lanes must independently
|
bounded owner delivery and session revocation. Both lanes must independently
|
||||||
pass approval, PDP, consume and delivery readiness. The handoff and draft are
|
pass approval, PDP, consume and delivery readiness. The handoff and catalog configuration are
|
||||||
not runtime authorization. No production activation was performed in this review.
|
not runtime authorization. No production activation was performed in this review.
|
||||||
|
|
||||||
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
|
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
|
||||||
|
|
|
||||||
83
docs/railiance-clock-consumer-review.md
Normal file
83
docs/railiance-clock-consumer-review.md
Normal file
|
|
@ -0,0 +1,83 @@
|
||||||
|
# Railiance Clock lifecycle-consumer review
|
||||||
|
|
||||||
|
SECRETS-IN-0003, reviewed 2026-09-27. This completes the requested consumer
|
||||||
|
review. It does not admit a new authority, key, deployment or execution window.
|
||||||
|
|
||||||
|
Reviewed inputs: railiance-clock `61e86a6e01c2e93a9af923a46772a41d080a5743`,
|
||||||
|
`specs/sample-profile-v0.1.md`, `docs/implementation-review-2026-09-15.md`,
|
||||||
|
`src/railiance_clock/{protocol,client,admission}.py`, and this repository's
|
||||||
|
`application_time.py`, approval validators and consume guard. The earlier
|
||||||
|
intake describes a proposal, but consumer implementation and scoped native
|
||||||
|
acceptance already exist in [the approval contract](approval-consumption.md)
|
||||||
|
and [the September 16 receipt](evidence/2026-09-16-t03-completion.json).
|
||||||
|
|
||||||
|
## Signing compatibility and custody
|
||||||
|
|
||||||
|
The reviewed implementation delegates ES256 to PyJWT/cryptography, pinned by
|
||||||
|
railiance-clock's dependency range (`PyJWT[crypto]>=2.10,<3`). It verifies the
|
||||||
|
original compact envelope, restricts the algorithm to ES256, and requires an
|
||||||
|
admitted P-256 public key and exact key ID. Closed headers, 64-byte signatures,
|
||||||
|
canonical base64url, strict JSON, nonce and authority/environment/epoch/policy
|
||||||
|
checks accompany signature verification. Secrets-engine uses that library;
|
||||||
|
it has no independent signing or verification implementation.
|
||||||
|
|
||||||
|
The signing private key belongs to the platform's admitted custody and the
|
||||||
|
clock authority runtime. It must not share an approval, KeyCape, SSH or engine
|
||||||
|
credential. No signing key is delivered to this engine: its input is a public
|
||||||
|
trust binding. The clock's explicit private-file deployment interface is not
|
||||||
|
proof of OpenBao custody, renewal or fleet-wide admission. Those owner proofs
|
||||||
|
remain in existing RCLK-WP-0002/0004/0005; no new custody task or lane is created.
|
||||||
|
|
||||||
|
## Bootstrap, rotation and revocation
|
||||||
|
|
||||||
|
Admit the authority, environment, public-key fingerprint, key ID, epoch, policy,
|
||||||
|
transport and finite lifetime over an independently authenticated owner path.
|
||||||
|
The sample under verification cannot establish its own trust. HTTPS verification
|
||||||
|
must work already; the reviewed alternative is explicitly admitted SSH-backed
|
||||||
|
loopback transport. Neither permits disabling TLS checks or adjusting OS time.
|
||||||
|
|
||||||
|
The current trust admission is client-boot-bound, with a maximum 15-minute
|
||||||
|
BOOTTIME deadline. Every read obtains a fresh sample and checks the trust file
|
||||||
|
before and after exchange; cached usable-time holdover is absent. Missing or
|
||||||
|
changed trust, expiration, an unknown epoch, rollback-state failure or excessive
|
||||||
|
uncertainty must refuse. The engine's cached client intentionally remains refused
|
||||||
|
after its trust file changes; restart/reacquisition requires a separately admitted
|
||||||
|
replacement, not automatic trust discovery.
|
||||||
|
|
||||||
|
For rotation, platform/clock owners admit the replacement key and invalidate old
|
||||||
|
client trust bindings, then consumers reacquire under the new binding. For
|
||||||
|
revocation, invalidate every affected binding and stop the old authority before
|
||||||
|
accepting further samples. File-change detection is local enforcement, not an
|
||||||
|
automatic estate-wide revocation distribution system. A consumer whose old file
|
||||||
|
is not invalidated can retain trust until its bounded deadline. Native rotation,
|
||||||
|
revocation propagation and snapshot/recovery acceptance must be proved by the
|
||||||
|
owners before claiming those operational guarantees. The library does not grant
|
||||||
|
permission to reset the persisted rollback floor.
|
||||||
|
|
||||||
|
## Consumer acceptance and limits
|
||||||
|
|
||||||
|
`SECRETS_ENGINE_CLOCK_TRUST_FILE` remains explicit opt-in. When configured,
|
||||||
|
unavailable or untrusted time refuses; it never falls back to workstation time.
|
||||||
|
An unconfigured engine retains its existing OS-clock path. Claim validity and
|
||||||
|
freshness and PDP decision lifetime must contain the whole interval: the lower
|
||||||
|
bound reaches not-before and the upper bound remains strictly before expiry.
|
||||||
|
Nanosecond-to-microsecond conversion rounds outward. Decision validity is checked
|
||||||
|
before and after CAS consume, with the existing actor/tenant/action/field/digest
|
||||||
|
and policy checks unchanged. A refusal after consume prevents backend access,
|
||||||
|
although the approval may already be consumed and needs a new request.
|
||||||
|
|
||||||
|
This is a check at the engine's consume boundary, not an atomic transaction
|
||||||
|
spanning OpenBao or a proof that a long-running child remains within the decision
|
||||||
|
lifetime. The library provides bounded time evidence, not authorization, spend
|
||||||
|
admission, complete audit custody or provider-session revocation. Server-side
|
||||||
|
issuers/approval storage retain their own validity enforcement.
|
||||||
|
|
||||||
|
The September 16 native receipt records three bounded samples, wrong-key-ID
|
||||||
|
refusal, independent host cross-checks and a 900-second trust admission during
|
||||||
|
one exact OpenRouter acceptance. It does not prove universal UTC accuracy,
|
||||||
|
all-platform suspend behavior or a rotation/revocation exercise. Existing
|
||||||
|
RCLK-WP-0002-T04 and RCLK-WP-0004 retain those owner acceptance boundaries.
|
||||||
|
`tests/test_application_time.py` covers interval boundaries, missing trust,
|
||||||
|
no shifted-time mixing and consume expiry refusal. This review accepts the
|
||||||
|
explicit bounded-time consumer contract within those stated limits; it grants
|
||||||
|
no new production use.
|
||||||
|
|
@ -85,13 +85,20 @@ state_hub_intake_id: "01a0c279-538e-7d99-bf69-f4c67a8d3eda"
|
||||||
id: SECRETS-IN-0003
|
id: SECRETS-IN-0003
|
||||||
kind: intake
|
kind: intake
|
||||||
title: 'railiance-clock: review signing custody, rotation and lifecycle-consumer adoption condition'
|
title: 'railiance-clock: review signing custody, rotation and lifecycle-consumer adoption condition'
|
||||||
status: open
|
status: closed
|
||||||
origin: cross-repo
|
origin: cross-repo
|
||||||
origin_ref: hub messages f90b9f17 and 302291b5 (railiance-clock, 2026-09-14)
|
origin_ref: hub messages f90b9f17 and 302291b5 (railiance-clock, 2026-09-14)
|
||||||
priority: low
|
priority: low
|
||||||
owner: secrets-engine
|
owner: secrets-engine
|
||||||
requested_by: railiance-clock
|
requested_by: railiance-clock
|
||||||
resolution: ''
|
resolution: >-
|
||||||
|
Consumer review completed 2026-09-27 in docs/railiance-clock-consumer-review.md.
|
||||||
|
Reviewed ES256/PyJWT compatibility, platform signing custody boundary,
|
||||||
|
independent boot-bound trust, rotation/revocation propagation requirements,
|
||||||
|
interval validity and CAS check-to-use limits. Existing consumer code and
|
||||||
|
2026-09-16 scoped native receipt supersede the intake's proposal-only framing.
|
||||||
|
No new authority/key/activation admitted. Operational acceptance remains with
|
||||||
|
existing RCLK-WP-0002-T04 and RCLK-WP-0004/0005 owner work.
|
||||||
description: >-
|
description: >-
|
||||||
railiance-clock published its foundation (commit 0a144b6, RCLK-WP plans) and a
|
railiance-clock published its foundation (commit 0a144b6, RCLK-WP plans) and a
|
||||||
candidate time-sample profile (commit 7af595b, specs/sample-profile-v0.1.md:
|
candidate time-sample profile (commit 7af595b, specs/sample-profile-v0.1.md:
|
||||||
|
|
|
||||||
|
|
@ -13,9 +13,9 @@ its own right, reported rather than resolved away by precedence.
|
||||||
Layer values are compared against §3's closed four-token vocabulary after an
|
Layer values are compared against §3's closed four-token vocabulary after an
|
||||||
ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled:
|
ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled:
|
||||||
`Engine` and `engine` are one token. Neither form carries a standard version
|
`Engine` and `engine` are one token. Neither form carries a standard version
|
||||||
(GH-DEC-2026-017 §5, amendment A12 r2 / GH-DEC-2026-020), and its return is
|
(GH-DEC-2026-017 §5, amendment A12 r3 / GH-DEC-2026-021), and its return is
|
||||||
rejected. The rule reaches content, not a key name: every key and value of the
|
rejected. The estate reference detector walks every key and value of the
|
||||||
INTENT.md frontmatter and of layer.yaml is walked, so a versioned `standard:` or
|
INTENT.md frontmatter and of layer.yaml, so a versioned `standard:` or
|
||||||
`companion:` path and a `companion_version` are caught as well as a
|
`companion:` path and a `companion_version` are caught as well as a
|
||||||
`standard_version`. Comments and `schema_version` are not reached. Stance maps
|
`standard_version`. Comments and `schema_version` are not reached. Stance maps
|
||||||
and evidence classifications (pep-stance.yaml, evidence-classification.yaml)
|
and evidence classifications (pep-stance.yaml, evidence-classification.yaml)
|
||||||
|
|
@ -60,29 +60,51 @@ DECISION_SURFACE = re.compile(
|
||||||
LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
|
LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
|
||||||
EXPECTED_LAYER = "engine"
|
EXPECTED_LAYER = "engine"
|
||||||
|
|
||||||
# The standard text this checker was built and validated against, printed on
|
# The accepted text and rulings enforced by this run (GH-DEC-2026-021 §2).
|
||||||
# every run (GH-DEC-2026-020 §4, A12 r2). v0.7 is the accepted text in force;
|
# Update together with the reference detector when the accepted text changes.
|
||||||
# the v0.8 §11 amendments it already applies are named alongside. Bump this
|
VALIDATED_AGAINST = (
|
||||||
# when the checker is re-validated against a newer accepted text.
|
"net-kingdom/canon/standards/security-layer-model_v0.7.md (net-kingdom@66dc491) "
|
||||||
VALIDATED_AGAINST = "net-kingdom/canon/standards/security-layer-model_v0.7.md"
|
"as amended by GH-DEC-2026-017, GH-DEC-2026-020 and GH-DEC-2026-021 "
|
||||||
AMENDMENTS_APPLIED = "v0.8 A9, A11, A12 r2 (GH-DEC-2026-017, GH-DEC-2026-020)"
|
"(A9-A13, A12 r3; gate-house@39d9287)"
|
||||||
|
)
|
||||||
SCOPE = (
|
SCOPE = (
|
||||||
"declaration = INTENT.md frontmatter + layer.yaml (every key and value); "
|
"declaration = INTENT.md frontmatter + layer.yaml (every key and value); "
|
||||||
"source = src/secrets_engine/**/*.py; "
|
"source = src/secrets_engine/**/*.py; "
|
||||||
"not reached by A12: pep-stance.yaml, evidence-classification.yaml"
|
"not reached by A12: pep-stance.yaml, evidence-classification.yaml"
|
||||||
)
|
)
|
||||||
|
|
||||||
# A12 r2: a version of the standard or its companion, anywhere in the
|
# Estate reference detector, GH-DEC-2026-021 §3.
|
||||||
# declaration. `schema_version` is the declaration file's own schema and is
|
VERSION_KEY = re.compile(r"(standard|companion).*version|version.*(standard|companion)", re.I)
|
||||||
# not reached.
|
VERSION_IN_VALUE = re.compile(r"[_\-.]v\d+(\.\d+)*(\.md)?\b|@v?\d+\.\d+", re.I)
|
||||||
VERSION_KEY = re.compile(r"version", re.IGNORECASE)
|
NOT_REACHED_KEYS = {"schema_version"}
|
||||||
UNREACHED_KEYS = {"schema_version"}
|
IDENTITY_KEYS = {"standard", "companion"}
|
||||||
VERSIONED_REF = re.compile(
|
IDENTITY_VERSION = re.compile(r"\bv?\d+\.\d+", re.I)
|
||||||
r"(?i)(security-layer-model|security-companion|layer-model|companion)"
|
|
||||||
r"[^\s]*?(?:[_@-]v?\d+(?:\.\d+)*|\bv\d+(?:\.\d+)*)"
|
|
||||||
)
|
def find_version_pins(node, where: str = "", identity: bool = False) -> list[str]:
|
||||||
STANDARD_KEYS = {"standard", "companion", "framework"}
|
"""Every place in a parsed declaration that carries a standard/companion version.
|
||||||
BARE_VERSION = re.compile(r"(?i)(?:^|[_@\s-])v?\d+\.\d+(?:\.\d+)*\b")
|
|
||||||
|
Walks every key and value (comments are gone after parsing, which is the
|
||||||
|
A12 r2 exclusion). Returns human-readable locations; empty means clean.
|
||||||
|
"""
|
||||||
|
pins: list[str] = []
|
||||||
|
if isinstance(node, dict):
|
||||||
|
for k, v in node.items():
|
||||||
|
here = f"{where}.{k}" if where else str(k)
|
||||||
|
if str(k) in NOT_REACHED_KEYS:
|
||||||
|
continue
|
||||||
|
if VERSION_KEY.search(str(k)):
|
||||||
|
pins.append(f"{here} (key names a standard/companion version)")
|
||||||
|
continue
|
||||||
|
pins.extend(find_version_pins(v, here, str(k).lower() in IDENTITY_KEYS))
|
||||||
|
elif isinstance(node, list):
|
||||||
|
for i, v in enumerate(node):
|
||||||
|
pins.extend(find_version_pins(v, f"{where}[{i}]", identity))
|
||||||
|
elif isinstance(node, str) and VERSION_IN_VALUE.search(node):
|
||||||
|
pins.append(f"{where} = {node!r} (value carries a version)")
|
||||||
|
elif isinstance(node, str) and identity and IDENTITY_VERSION.search(node):
|
||||||
|
pins.append(f"{where} = {node!r} (identity-bearing value carries a version)")
|
||||||
|
return pins
|
||||||
|
|
||||||
|
|
||||||
def _fold(value: object) -> str:
|
def _fold(value: object) -> str:
|
||||||
|
|
@ -90,37 +112,13 @@ def _fold(value: object) -> str:
|
||||||
return str(value).strip().encode("ascii", "ignore").decode().lower()
|
return str(value).strip().encode("ascii", "ignore").decode().lower()
|
||||||
|
|
||||||
|
|
||||||
def _version_hits(data: object, path: str = "") -> list[str]:
|
|
||||||
"""Every place a standard or companion version appears in a declaration."""
|
|
||||||
hits: list[str] = []
|
|
||||||
if isinstance(data, dict):
|
|
||||||
for key, value in data.items():
|
|
||||||
here = f"{path}.{key}" if path else str(key)
|
|
||||||
if str(key) in UNREACHED_KEYS:
|
|
||||||
continue
|
|
||||||
if VERSION_KEY.search(str(key)):
|
|
||||||
hits.append(f"key {here!r}")
|
|
||||||
continue
|
|
||||||
if isinstance(value, str) and str(key).lower() in STANDARD_KEYS:
|
|
||||||
if BARE_VERSION.search(value):
|
|
||||||
hits.append(f"{here}: {value!r}")
|
|
||||||
continue
|
|
||||||
hits.extend(_version_hits(value, here))
|
|
||||||
elif isinstance(data, list):
|
|
||||||
for n, item in enumerate(data):
|
|
||||||
hits.extend(_version_hits(item, f"{path}[{n}]"))
|
|
||||||
elif isinstance(data, str) and VERSIONED_REF.search(data):
|
|
||||||
hits.append(f"{path}: {data!r}")
|
|
||||||
return hits
|
|
||||||
|
|
||||||
|
|
||||||
def _no_standard_version(where: str, data: dict) -> None:
|
def _no_standard_version(where: str, data: dict) -> None:
|
||||||
hits = _version_hits(data)
|
hits = find_version_pins(data)
|
||||||
if hits:
|
if hits:
|
||||||
print(
|
print(
|
||||||
f"MALFORMED: {where} carries a standard or companion version at "
|
f"MALFORMED: {where} carries a standard or companion version at "
|
||||||
f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any "
|
f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any "
|
||||||
"key or value (§11 as amended by A12 r2, GH-DEC-2026-020 §1-§2)"
|
"key or value (§11 as amended by A12 r3, GH-DEC-2026-021 §1-§3)"
|
||||||
)
|
)
|
||||||
raise SystemExit(2)
|
raise SystemExit(2)
|
||||||
|
|
||||||
|
|
@ -231,7 +229,7 @@ def main() -> int:
|
||||||
ap = argparse.ArgumentParser()
|
ap = argparse.ArgumentParser()
|
||||||
ap.add_argument("--report", action="store_true")
|
ap.add_argument("--report", action="store_true")
|
||||||
args = ap.parse_args()
|
args = ap.parse_args()
|
||||||
print(f"validated against: {VALIDATED_AGAINST} [{AMENDMENTS_APPLIED}]")
|
print(f"validated against: {VALIDATED_AGAINST}")
|
||||||
print(f"scope: {SCOPE}")
|
print(f"scope: {SCOPE}")
|
||||||
|
|
||||||
front = intent_frontmatter()
|
front = intent_frontmatter()
|
||||||
|
|
|
||||||
|
|
@ -102,8 +102,9 @@ def test_binding_changed_after_approval_refuses_before_fetch(bound, monkeypatch)
|
||||||
exec_delivery.exec_with_secret(object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"], expected_owner_digest=expected)
|
exec_delivery.exec_with_secret(object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"], expected_owner_digest=expected)
|
||||||
|
|
||||||
|
|
||||||
def test_pending_real_catalog_refuses_before_approval_and_backend(tmp_path, monkeypatch):
|
def test_pending_owner_refuses_before_approval_and_backend(tmp_path, monkeypatch):
|
||||||
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||||
|
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
|
||||||
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
|
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
|
||||||
for name in ["_require_lane_approval", "_open_backend"]:
|
for name in ["_require_lane_approval", "_open_backend"]:
|
||||||
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
|
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
|
||||||
|
|
@ -160,8 +161,35 @@ def test_invalid_binding_is_not_a_catalog_fallback(bound, change):
|
||||||
def test_pending_owner_never_advertises_ready(tmp_path, monkeypatch):
|
def test_pending_owner_never_advertises_ready(tmp_path, monkeypatch):
|
||||||
from secrets_engine import routing
|
from secrets_engine import routing
|
||||||
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||||
|
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
|
||||||
monkeypatch.setattr(routing, "resolve_decision", lambda **k: SimpleNamespace(status="approved", review_url="", is_approved=lambda: True))
|
monkeypatch.setattr(routing, "resolve_decision", lambda **k: SimpleNamespace(status="approved", review_url="", is_approved=lambda: True))
|
||||||
client = SimpleNamespace(is_reachable=lambda: True, read_policy=lambda p: "policy", approle_exists=lambda r: True, kv_fields_present=lambda *a: {"ANTHROPIC_API_KEY": True})
|
client = SimpleNamespace(is_reachable=lambda: True, read_policy=lambda p: "policy", approle_exists=lambda r: True, kv_fields_present=lambda *a: {"ANTHROPIC_API_KEY": True})
|
||||||
result = routing.route_lane(entry, hub_url="", repo_root=tmp_path, client=client)
|
result = routing.route_lane(entry, hub_url="", repo_root=tmp_path, client=client)
|
||||||
assert not result.ready and "exec owner" in result.missing
|
assert not result.ready and "exec owner" in result.missing
|
||||||
assert "<command" not in result.next_command
|
assert "<command" not in result.next_command
|
||||||
|
|
||||||
|
|
||||||
|
def test_configured_glas_catalog_refuses_arbitrary_child_before_gate(tmp_path, monkeypatch):
|
||||||
|
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||||
|
assert entry.delivery_config["exec_owner"]["status"] == "configured"
|
||||||
|
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
|
||||||
|
for name in ["_require_lane_approval", "_open_backend"]:
|
||||||
|
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
|
||||||
|
with pytest.raises(DeliveryError, match="catalog-bound"):
|
||||||
|
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(field=None, catalog=entry.id, command=["/bin/echo"], mode="exec-env"))
|
||||||
|
|
||||||
|
|
||||||
|
def test_configured_glas_companion_matches_worker_and_pins_spend_policy():
|
||||||
|
from secrets_engine.exec_owner import resolve_companions
|
||||||
|
root = Path(__file__).resolve().parents[1] / "catalog"
|
||||||
|
entry = load_entry(root / "glas-claude-agent-dev-anthropic.yaml")
|
||||||
|
binding = entry.delivery_config["exec_owner"]
|
||||||
|
companions = resolve_companions(entry, lambda cid: load_entry(root / (cid + ".yaml")))
|
||||||
|
assert [(lane.id, field, env) for lane, field, env in companions] == [
|
||||||
|
("activity-core-metered-worker-token", "token", "ACTIVITY_CORE_WORKER_TOKEN")
|
||||||
|
]
|
||||||
|
assert binding["environment"]["AGENT_HARNESS_WORKER_ID"] == "rein-aharness-metered@railiance01"
|
||||||
|
assert binding["environment"]["AGENT_HARNESS_OPS_LABELS"] == "hfact-metered"
|
||||||
|
assert binding["files"][binding["environment"]["AGENT_HARNESS_SPEND_POLICY"]]["private"] is True
|
||||||
|
request = build_action_request(entry, "exec", subject_id="agent:fixture", subject_type="Agent", purpose="owner-proof", fields=entry.fields)
|
||||||
|
assert request["context"]["exec_owner_sha256"] == owner_digest(entry)
|
||||||
|
|
|
||||||
|
|
@ -164,7 +164,8 @@ def test_real_exec_handler_rejects_undeclared_claim_before_consume_backend_child
|
||||||
assert [r["result"] for r in records] == ["attempt", "failed-DecisionError"]
|
assert [r["result"] for r in records] == ["attempt", "failed-DecisionError"]
|
||||||
|
|
||||||
|
|
||||||
def test_factory_catalog_declares_human_control_and_keeps_owner_pending():
|
def test_configured_factory_catalog_still_requires_human_control():
|
||||||
entry = load_entry(Path(__file__).resolve().parents[1]/"catalog/glas-claude-agent-dev-anthropic.yaml")
|
entry = load_entry(Path(__file__).resolve().parents[1]/"catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||||
assert entry.approval["human_control"] is True
|
assert entry.approval["human_control"] is True
|
||||||
assert entry.delivery_config["exec_owner"]["status"] == "pending"
|
assert entry.delivery_config["exec_owner"]["status"] == "configured"
|
||||||
|
assert not entry.approval.get("authorization_id")
|
||||||
|
|
|
||||||
|
|
@ -190,6 +190,27 @@ def test_schema_version_is_not_reached(tmp_path, monkeypatch):
|
||||||
assert _run_with(tmp_path, monkeypatch, {}, {"schema_version": "0.2"}) == 0
|
assert _run_with(tmp_path, monkeypatch, {}, {"schema_version": "0.2"}) == 0
|
||||||
|
|
||||||
|
|
||||||
|
@pytest.mark.parametrize("patch", [
|
||||||
|
{"intent_version": "0.1.0"},
|
||||||
|
{"rationale": "The v0.5 scope rule is historical provenance."},
|
||||||
|
{"framework": "Historical v0.7 reference; standard identity is separate."},
|
||||||
|
])
|
||||||
|
def test_reference_detector_allows_own_versions_and_prose(tmp_path, monkeypatch, patch):
|
||||||
|
assert _run_with(tmp_path, monkeypatch, patch, {}) == 0
|
||||||
|
|
||||||
|
|
||||||
|
@pytest.mark.parametrize("patch", [
|
||||||
|
{"standard_version_reviewed": "0.7"},
|
||||||
|
{"version_of_companion": "0.2"},
|
||||||
|
{"standard": "security-layer-model v0.7"},
|
||||||
|
{"companion": ["security companion 0.2"]},
|
||||||
|
{"references": [{"path": "unrelated-document-v1.2.md"}]},
|
||||||
|
{"references": ["security-layer-model@0.7"]},
|
||||||
|
])
|
||||||
|
def test_reference_detector_rejects_nested_and_identity_pins(tmp_path, monkeypatch, patch):
|
||||||
|
assert _run_with(tmp_path, monkeypatch, {}, patch) == 2
|
||||||
|
|
||||||
|
|
||||||
def test_stance_and_classification_versions_are_not_reached():
|
def test_stance_and_classification_versions_are_not_reached():
|
||||||
"""GH-DEC-2026-020 §3: stance maps and classifications keep their version,
|
"""GH-DEC-2026-020 §3: stance maps and classifications keep their version,
|
||||||
and the checker never applies A12 to them."""
|
and the checker never applies A12 to them."""
|
||||||
|
|
@ -198,7 +219,7 @@ def test_stance_and_classification_versions_are_not_reached():
|
||||||
for path in (STANCE, CLASSIFICATION):
|
for path in (STANCE, CLASSIFICATION):
|
||||||
data = yaml.safe_load(path.read_text(encoding="utf-8"))
|
data = yaml.safe_load(path.read_text(encoding="utf-8"))
|
||||||
# Each carries a version A12 would reject if it were applied there...
|
# Each carries a version A12 would reject if it were applied there...
|
||||||
assert checker._version_hits(data), f"{path.name} keeps its standard_version"
|
assert checker.find_version_pins(data), f"{path.name} keeps its standard_version"
|
||||||
# ...and the real-tree run still passes: A12 is not applied to them.
|
# ...and the real-tree run still passes: A12 is not applied to them.
|
||||||
result = subprocess.run(
|
result = subprocess.run(
|
||||||
[sys.executable, str(SCRIPT)], cwd=ROOT, capture_output=True, text=True, check=False
|
[sys.executable, str(SCRIPT)], cwd=ROOT, capture_output=True, text=True, check=False
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: custodian
|
topic_slug: custodian
|
||||||
created: "2026-08-21"
|
created: "2026-08-21"
|
||||||
updated: "2026-09-06"
|
updated: "2026-09-27"
|
||||||
state_hub_workstream_id: "31f7f8ea-7f73-516c-8877-f03a13f1db82"
|
state_hub_workstream_id: "31f7f8ea-7f73-516c-8877-f03a13f1db82"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -195,6 +195,7 @@ Acceptance:
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0006-T05
|
id: SECRETS-WP-0006-T05
|
||||||
status: wait
|
status: wait
|
||||||
|
blocking_reason: "OpenRouter key-check native acceptance is recorded in SECRETS-WP-0010-T03. Other lanes still need exact approvals, scoped attended apply and per-lane positive/negative/health/revocation evidence."
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542"
|
state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542"
|
||||||
```
|
```
|
||||||
|
|
@ -256,6 +257,7 @@ Acceptance per lane:
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0006-T06
|
id: SECRETS-WP-0006-T06
|
||||||
status: wait
|
status: wait
|
||||||
|
blocking_reason: "Needs owner-agreed routing/proxy retirement for each verified lane and custody disposition of the legacy npm pointer; a single approved OpenRouter key-check does not authorize broader routing cutover."
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "1431edae-5791-5892-8c4b-829419b537d2"
|
state_hub_task_id: "1431edae-5791-5892-8c4b-829419b537d2"
|
||||||
```
|
```
|
||||||
|
|
@ -424,3 +426,13 @@ for a fourth location.
|
||||||
|
|
||||||
`SECRETS-WP-0006-T06` stays `wait`: this answer unblocks the question, not the
|
`SECRETS-WP-0006-T06` stays `wait`: this answer unblocks the question, not the
|
||||||
lane change, which needs custody's step 1 and its own approval.
|
lane change, which needs custody's step 1 and its own approval.
|
||||||
|
|
||||||
|
|
||||||
|
### Existing-work review — 2026-09-27
|
||||||
|
|
||||||
|
The September 16 native OpenRouter key-check receipt supersedes the older
|
||||||
|
serving/ESO-health wait for that exact recipient. SECRETS-WP-0007-T04 and
|
||||||
|
SECRETS-WP-0008-T02 are now closed against that real evidence and current
|
||||||
|
regression coverage. T05 remains open for the other lanes; T06 retains
|
||||||
|
per-lane routing/proxy retirement and the npm custody discrepancy. No broader
|
||||||
|
recipient, proxy retirement, or production action is inferred from that receipt.
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: custodian
|
topic_slug: custodian
|
||||||
created: "2026-08-23"
|
created: "2026-08-23"
|
||||||
updated: "2026-09-06"
|
updated: "2026-09-27"
|
||||||
state_hub_workstream_id: "68a39be1-bd9c-5133-ad64-e7bca892aaf3"
|
state_hub_workstream_id: "68a39be1-bd9c-5133-ad64-e7bca892aaf3"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -213,11 +213,15 @@ Acceptance:
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0007-T04
|
id: SECRETS-WP-0007-T04
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "4b58edec-c705-55e5-9ece-362e1ff13079"
|
state_hub_task_id: "4b58edec-c705-55e5-9ece-362e1ff13079"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Completed 2026-09-27 by reconciling the implemented shared approval guard with the
|
||||||
|
2026-09-16 native receipt. See the closure note below; the serving-path waits
|
||||||
|
in the dated history are superseded. Native lane cutover remains T07.
|
||||||
|
|
||||||
Wait 2026-08-29. The consumer validator and production fail-closed gate are
|
Wait 2026-08-29. The consumer validator and production fail-closed gate are
|
||||||
shipped. What remains is not local engine work: State Hub / `access-engine`
|
shipped. What remains is not local engine work: State Hub / `access-engine`
|
||||||
must serve the durable ActionAuthorization object. Paired with
|
must serve the durable ActionAuthorization object. Paired with
|
||||||
|
|
@ -707,6 +711,7 @@ Acceptance:
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0007-T07
|
id: SECRETS-WP-0007-T07
|
||||||
status: wait
|
status: wait
|
||||||
|
blocking_reason: "Engine approval hardening is complete. Remaining per-lane cutover includes native routing/proxy retirement with ops-warden under SECRETS-WP-0006-T05/T06; the exact OpenRouter key-check receipt does not establish broader recipient readiness."
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
|
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
|
||||||
```
|
```
|
||||||
|
|
@ -787,3 +792,25 @@ routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readines
|
||||||
Do not reuse the consumed approvals or treat the temporary key-check overlay as
|
Do not reuse the consumed approvals or treat the temporary key-check overlay as
|
||||||
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
|
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
|
||||||
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
|
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
|
||||||
|
|
||||||
|
|
||||||
|
### T04 completed after evidence reconciliation — 2026-09-27
|
||||||
|
|
||||||
|
The original serving-path wait is superseded by the native 2026-09-16 receipt
|
||||||
|
`docs/evidence/2026-09-16-t03-completion.json`, not by synthetic tests or Hub
|
||||||
|
status. It records separate human-controlled apply, verify and exec approvals,
|
||||||
|
three distinct current PDP decisions/request digests, successful CAS consumes,
|
||||||
|
and the resulting native OpenBao operations. The claim/PDP/consume join is the
|
||||||
|
accepted path; the earlier proposed ActionAuthorization is not a dependency.
|
||||||
|
|
||||||
|
Current regression coverage exercises wrong fields/actions/tenant/digest,
|
||||||
|
superseded or expired claims, changed catalog/owner bindings, denied or missing
|
||||||
|
PDP responses, consume conflicts/unavailability, declared human control and
|
||||||
|
production fixture refusal. Every live privileged handler still uses the shared
|
||||||
|
approval gate before backend access. The recorded approvals are consumed and
|
||||||
|
expired; they are historical completion evidence, never reusable grants.
|
||||||
|
|
||||||
|
T04 is done. T07 stays wait because its per-lane acceptance includes routing and
|
||||||
|
proxy retirement, and the receipt covers only the exact OpenRouter key-check
|
||||||
|
recipient. Other lanes and cross-owner cutover remain SECRETS-WP-0006-T05/T06;
|
||||||
|
this workplan is not finished merely because the engine gate is complete.
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: grok
|
owner: grok
|
||||||
topic_slug: custodian
|
topic_slug: custodian
|
||||||
created: "2026-08-29"
|
created: "2026-08-29"
|
||||||
updated: "2026-09-21"
|
updated: "2026-09-27"
|
||||||
state_hub_workstream_id: "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0"
|
state_hub_workstream_id: "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -90,11 +90,15 @@ Acceptance:
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0008-T02
|
id: SECRETS-WP-0008-T02
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "3eb9cff8-1441-5437-9e92-a2b655c82d04"
|
state_hub_task_id: "3eb9cff8-1441-5437-9e92-a2b655c82d04"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Completed 2026-09-27: the 2026-09-16 native apply/verify/exec receipt supplies
|
||||||
|
the live PDP/claim/consume return awaited below. The dated serving-path waits
|
||||||
|
are historical. Service JWT adoption remains T06.
|
||||||
|
|
||||||
Progress 2026-09-02. Gate House notice `632bdad9` (`GH-DEC-2026-003`): this
|
Progress 2026-09-02. Gate House notice `632bdad9` (`GH-DEC-2026-003`): this
|
||||||
engine is the PEP for FLEX-WP-0017-T05 / OpenBao writes. The shared consume
|
engine is the PEP for FLEX-WP-0017-T05 / OpenBao writes. The shared consume
|
||||||
function now lives in `src/secrets_engine/approval_consume.py` and every live
|
function now lives in `src/secrets_engine/approval_consume.py` and every live
|
||||||
|
|
@ -327,6 +331,7 @@ Acceptance:
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0008-T06
|
id: SECRETS-WP-0008-T06
|
||||||
status: wait
|
status: wait
|
||||||
|
blocking_reason: "RPF-WP-0035-T02 still awaits exact service claims/tenant, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
|
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
|
||||||
```
|
```
|
||||||
|
|
@ -486,3 +491,26 @@ gate-house (message `4220413a`); we follow that answer rather than choose.
|
||||||
- `layer.yaml` / `pep-stance.yaml` / INTENT frontmatter stay in one voice.
|
- `layer.yaml` / `pep-stance.yaml` / INTENT frontmatter stay in one voice.
|
||||||
- No raw secret values in Git, State Hub, chat, prompts, workplans, evidence,
|
- No raw secret values in Git, State Hub, chat, prompts, workplans, evidence,
|
||||||
or argv.
|
or argv.
|
||||||
|
|
||||||
|
|
||||||
|
## Decision consumer closure and declaration ruling applied — 2026-09-27
|
||||||
|
|
||||||
|
T02 is done. `docs/evidence/2026-09-16-t03-completion.json` provides the native
|
||||||
|
return awaited in the September 9 note: separately approved apply/verify/exec
|
||||||
|
requests received current PDP allows and successful CAS consumption before real
|
||||||
|
OpenBao work. The shared guard records decision IDs and retains refusal before
|
||||||
|
backend access for invalid/missing/replayed decisions. SECRETS-WP-0007-T04 now
|
||||||
|
records the same completed contract; no native activation grant is inferred.
|
||||||
|
|
||||||
|
The open conformance-record question is also resolved. GH-DEC-2026-020 §4 says
|
||||||
|
a versioned/scoped re-runnable checker is sufficient; each declaring repository
|
||||||
|
need not emit a durable record. GH-DEC-2026-021 §2/§3 names the accepted v0.7
|
||||||
|
text plus applicable decisions and the ops-warden reference detector. The
|
||||||
|
checker now copies that detector, permits own-document versions/prose citations,
|
||||||
|
refuses nested/identity-bearing version pins and names the accepted text and
|
||||||
|
rulings on every run, including PASS. Declaration spellings are unchanged.
|
||||||
|
|
||||||
|
T06 remains wait: railiance-platform's RPF-WP-0035-T02 still records an
|
||||||
|
unprovisioned, login-only JWT role, pending exact service claims/tenant and
|
||||||
|
custody/attended admission. The existing env-auth native receipt cannot prove
|
||||||
|
steady-state service JWT login. This is the only remaining task in this workplan.
|
||||||
|
|
|
||||||
|
|
@ -49,8 +49,8 @@ synthetic exec-env transport proof passed; no real secret was read.
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0009-T03
|
id: SECRETS-WP-0009-T03
|
||||||
status: wait
|
status: wait
|
||||||
|
blocking_reason: "Configured owner and worker companion passed backend-free recipient/pin checks on 2026-09-27 (SECRETS-WP-0011 complete). Remaining: exact per-action/per-lane approvals, unrelated negative identity, scoped attended apply/verify, bounded real owner delivery and revocation. Recheck pins and spend validity at execution."
|
||||||
priority: high
|
priority: high
|
||||||
blocking_reason: "Shared native chain proved by SECRETS-WP-0010-T03. Metered owner provisioned and binding drafted (2026-09-23); Activity Core reports identity live (2026-09-24). Remaining: current recipient/pin admission, unrelated negative identity, configured exec_owner, exact per-action/per-lane approvals and attended apply/verify/exec/revoke."
|
|
||||||
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
|
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
@ -503,3 +503,19 @@ native apply, positive/negative verification, exec and session revocation.
|
||||||
The production catalog remains pending. The companion-only delivery guards
|
The production catalog remains pending. The companion-only delivery guards
|
||||||
added under SECRETS-WP-0011-T05 must be included in the host checkout used for
|
added under SECRETS-WP-0011-T05 must be included in the host checkout used for
|
||||||
activation. No credential read, queue claim or paid run occurred in this review.
|
activation. No credential read, queue claim or paid run occurred in this review.
|
||||||
|
|
||||||
|
|
||||||
|
### 2026-09-27 configured owner and companion landed
|
||||||
|
|
||||||
|
SECRETS-WP-0011 is finished at its catalog/implementation boundary. The binding
|
||||||
|
formerly held in `docs/drafts/glas-exec-owner-configured.yaml` is now configured
|
||||||
|
in the active Glas catalog, with an added exact private spend-policy file pin.
|
||||||
|
The installed owner's backend-free check and engine path/pin validation passed
|
||||||
|
on railiance01. Receipt: `docs/evidence/2026-09-27-companion-catalog-readiness.json`.
|
||||||
|
The original pending-recipient configuration is superseded; current code still
|
||||||
|
refuses any substituted child and requires fresh approvals and delivery state.
|
||||||
|
|
||||||
|
T03 retains all native activation and delivery acceptance. Revalidate the owner
|
||||||
|
and spend envelope in the attended execution window, use approvals bound to the
|
||||||
|
new owner digest and each lane, apply/verify both native lanes, and prove actual
|
||||||
|
bounded owner delivery and cleanup. Configuration does not authorize those actions.
|
||||||
|
|
|
||||||
|
|
@ -4,7 +4,7 @@ type: workplan
|
||||||
title: "Multi-lane exec-owner delivery"
|
title: "Multi-lane exec-owner delivery"
|
||||||
domain: infotech
|
domain: infotech
|
||||||
repo: secrets-engine
|
repo: secrets-engine
|
||||||
status: active
|
status: finished
|
||||||
flavor: implementation
|
flavor: implementation
|
||||||
owner: claude-code
|
owner: claude-code
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
|
|
@ -91,12 +91,15 @@ a throwaway OpenBao dev server.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0011-T04
|
id: SECRETS-WP-0011-T04
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
blocking_reason: "Activity Core reports ACTIVITY-WP-0039 finished and metered identity authentication proved (2026-09-24). Remaining: admit the configured Glas owner, obtain exact per-lane approvals, and perform attended native apply/verify/delivery under SECRETS-WP-0009-T03."
|
|
||||||
state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d"
|
state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Completed 2026-09-27: custody handoff received, companion cataloged and wired
|
||||||
|
into the configured Glas owner after fresh backend-free host verification.
|
||||||
|
Native activation remains in existing SECRETS-WP-0009-T03, as detailed below.
|
||||||
|
|
||||||
Request activity-core to move the worker token into OpenBao custody, synced to
|
Request activity-core to move the worker token into OpenBao custody, synced to
|
||||||
`actcore-runtime-secret` by their existing `openbao-activity-core` store. Then
|
`actcore-runtime-secret` by their existing `openbao-activity-core` store. Then
|
||||||
catalog a read lane for the metered owner and add it as the Glas lane's
|
catalog a read lane for the metered owner and add it as the Glas lane's
|
||||||
|
|
@ -172,3 +175,27 @@ T04 remains wait for native lane activation with SECRETS-WP-0009-T03: current
|
||||||
owner admission/pins, exact per-lane approvals and attended apply/verify/exec.
|
owner admission/pins, exact per-lane approvals and attended apply/verify/exec.
|
||||||
The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching
|
The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching
|
||||||
the handoff. No production policy, role, catalog binding or credential changed.
|
the handoff. No production policy, role, catalog binding or credential changed.
|
||||||
|
|
||||||
|
|
||||||
|
## Catalog task and workplan completed — 2026-09-27
|
||||||
|
|
||||||
|
T04's stated work is custody coordination, the worker-token catalog entry and
|
||||||
|
adding that entry as the Glas owner's companion. All three are now complete.
|
||||||
|
Activity Core's 2026-09-24 handoff supplies the custody/identity return. The
|
||||||
|
configured binding is now in `catalog/glas-claude-agent-dev-anthropic.yaml`,
|
||||||
|
including the worker identity/label and a private spend-policy file pin.
|
||||||
|
|
||||||
|
A fresh backend-free check on railiance01 verified the installed owner with
|
||||||
|
`metered-once --check --no-hub` (dispatch disabled), and this checkout's exact
|
||||||
|
path/ownership/mode/hash checks passed for the executable, owner configuration,
|
||||||
|
spend policy and private working directory. Receipt:
|
||||||
|
`docs/evidence/2026-09-27-companion-catalog-readiness.json`.
|
||||||
|
The owner digest is `46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b`.
|
||||||
|
|
||||||
|
The previous wait reason conflated catalog completion with native activation.
|
||||||
|
That activation was already owned by SECRETS-WP-0009-T03 and stays there: exact
|
||||||
|
per-lane action approvals, scoped attended apply, positive/negative verification,
|
||||||
|
actual bounded delivery and session revocation. No new task is needed. This
|
||||||
|
workplan's completion claims the configured multi-lane contract, its tests and
|
||||||
|
catalog wiring, not production delivery. No credential was requested or read,
|
||||||
|
no queue row was claimed, and no provider request was made.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue