Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -3,8 +3,8 @@ kind: kv
org: coulomb org: coulomb
repo: sand-boxer repo: sand-boxer
stage: prod stage: prod
description: Proposed native exec-env delivery for CCR-2026-0016. KV custody exists; description: Catalog-bound metered owner with Activity Core worker-token companion.
no runtime grant or activation yet. KV custody exists; native runtime approval and activation remain SECRETS-WP-0009-T03.
mount: platform mount: platform
path: workloads/glas-harness/claude-agent-dev path: workloads/glas-harness/claude-agent-dev
mount_management: existing mount_management: existing
@ -19,12 +19,46 @@ consumers:
workload_delivery: [] workload_delivery: []
delivery_config: delivery_config:
exec_owner: exec_owner:
status: pending status: configured
owner: rein-aharness MessagesOwner with sand-boxer runtime boundary owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
reason: Exact installed metered-once runtime is proved; native holder review, command:
immutable owner configuration and private state/profile/service admission - /home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3
remain SECRETS-WP-0009-T03 and HFACT-WP-0001-T03/T04. No arbitrary child may - -I
receive this key while the owner binding is pending. - -B
- -m
- rein_aharness.cli
- metered-once
- --owner-config
- /home/tegwick/hfact/owner-metered/owner.json
cwd: /home/tegwick/hfact/owner-metered
environment:
PATH: /usr/bin:/bin
LANG: C.UTF-8
HOME: /home/tegwick
ACTIVITY_CORE_URL: http://127.0.0.1:8010
AGENT_HARNESS_WORKER_ID: rein-aharness-metered@railiance01
AGENT_HARNESS_OPS_LABELS: hfact-metered
AGENT_HARNESS_OPS_LABELS_MODE: all
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
files:
/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3:
sha256: e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f
private: false
/home/tegwick/hfact/owner-metered/owner.json:
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
private: true
/home/tegwick/hfact/owner-metered/spend-policy.json:
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
private: true
companions:
- catalog: activity-core-metered-worker-token
field: token
env: ACTIVITY_CORE_WORKER_TOKEN
delivery_modes: delivery_modes:
- exec-env - exec-env
- read-check - read-check

View file

@ -0,0 +1,52 @@
# Existing-work closeout — 2026-09-27
No new task or workplan was opened. Three tasks and one intake can close from
existing evidence plus the local completion below. One workplan finishes.
| Existing record | Result | Basis |
| --- | --- | --- |
| SECRETS-WP-0007-T04 | done | Shared exact-action claim/PDP/consume implementation, regression refusals and real separate apply/verify/exec consumes in the September 16 native receipt |
| SECRETS-WP-0008-T02 | done | The same native receipt resolves its outstanding served-decision/consume dependency; current regression coverage retains fail-closed replay and lifetime checks |
| SECRETS-WP-0011-T04 | done | Activity Core custody/identity handoff received; configured owner and companion now cataloged; current owner/path/hash checks passed on railiance01 without backend access |
| SECRETS-WP-0011 | finished | All five tasks complete; native Glas activation remains in the existing SECRETS-WP-0009-T03 |
| SECRETS-IN-0003 | closed | Published signing/custody/bootstrap/rotation/revocation and bounded-time consumer review, with limits and existing owner acceptance work named |
Implementation includes the private spend-policy pin and the estate reference
layer-version detector under SECRETS-WP-0008. The latter closes the stale
conformance-record question without inventing a durable-record requirement.
Evidence:
- [Native approval and delivery receipt](evidence/2026-09-16-t03-completion.json)
is historical acceptance for one exact OpenRouter key-check recipient. Its
consumed approvals grant no future action.
- [Companion catalog receipt](evidence/2026-09-27-companion-catalog-readiness.json)
records current backend-free owner validation, installed file pins and owner
digest. Configuration is not production approval or delivery readiness.
- [Clock consumer review](railiance-clock-consumer-review.md) closes a review
request, without enabling a new trust binding or claiming operational rotation.
## Work that must remain open
| Existing record | Remaining completion requirement |
| --- | --- |
| SECRETS-WP-0006-T05 | Approved native verification for the other catalog lanes; the OpenRouter key-check receipt covers one exact recipient only |
| SECRETS-WP-0006-T06 | Owner-agreed routing/proxy retirement per verified lane, plus custody disposition of the legacy npm pointer; no unilateral proxy retirement |
| SECRETS-WP-0007-T07 | Its acceptance includes native cutover and routing/proxy retirement under 0006-T05/T06; engine hardening alone does not satisfy it |
| SECRETS-WP-0008-T06 | Platform/KeyCape exact service claims and tenant, custody, provisioned scoped JWT role and native login/negative/revocation acceptance (RPF-WP-0035-T02); the recorded env-auth run does not prove this |
| SECRETS-WP-0009-T03 | Fresh exact per-action/per-lane approvals, unrelated negative identity, attended apply/verify, bounded real Glas delivery and revocation; recheck pins and spend validity in that window |
| SECRETS-IN-0002 | Confirmed flex-auth repository rename before changing checkout coordinates; FLEX-WP-0020 still holds the live rename |
Workplans 0006, 0007, 0008 and 0009 therefore remain unfinished. Their remaining
requirements stay in those records, with no replacement or successor task.
Scope reconciliation is recorded as State Hub decision
`7a756027-2041-4732-bcbc-3bb6a5380838`; it grants no credential action.
Validation: 487 repository tests passed, including disposable OpenBao integration.
The layer-conformance checker and `git diff --check` passed. The configured
recipient's local-only owner check and exact engine path/pin checks passed on
railiance01; no backend credential was requested, no queue row was claimed and
no provider request was made.

View file

@ -218,3 +218,9 @@ and after CAS consume. The client keeps a boot-bound trust admission and private
rollback floor. It never changes the OS clock, accepts a sample as its own trust rollback floor. It never changes the OS clock, accepts a sample as its own trust
bootstrap, or falls back to a shifted local timestamp. The option stays unset bootstrap, or falls back to a shifted local timestamp. The option stays unset
until the owner publishes trust through the admitted Railiance Clock deployment. until the owner publishes trust through the admitted Railiance Clock deployment.
The [2026-09-27 consumer review](railiance-clock-consumer-review.md) records
signing compatibility, custody, bootstrap, rotation/revocation and check-to-use
limits. It reconciles SECRETS-IN-0003 with the already recorded September 16
native use; it does not enable a new trust binding.

View file

@ -1,7 +1,6 @@
# Draft exec_owner for glas-claude-agent-dev-anthropic (SECRETS-WP-0009-T03). # Configured binding promoted to catalog/glas-claude-agent-dev-anthropic.yaml
# Not in the catalog. Activity Core reports custody and identity live as of # on 2026-09-27 after backend-free owner and path/pin validation.
# 2026-09-24 (ACTIVITY-WP-0039). Admission still requires current owner/pin # Configuration is not runtime approval; native activation is SECRETS-WP-0009-T03.
# validation and exact per-lane approvals for attended native activation.
exec_owner: exec_owner:
status: configured status: configured
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
@ -24,8 +23,8 @@ exec_owner:
AGENT_HARNESS_OPS_LABELS: hfact-metered AGENT_HARNESS_OPS_LABELS: hfact-metered
AGENT_HARNESS_OPS_LABELS_MODE: all AGENT_HARNESS_OPS_LABELS_MODE: all
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: "1" AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: "1" AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3 AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}' AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
@ -36,6 +35,9 @@ exec_owner:
/home/tegwick/hfact/owner-metered/owner.json: /home/tegwick/hfact/owner-metered/owner.json:
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274 sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
private: true private: true
/home/tegwick/hfact/owner-metered/spend-policy.json:
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
private: true
companions: companions:
- catalog: activity-core-metered-worker-token - catalog: activity-core-metered-worker-token
field: token field: token

View file

@ -0,0 +1,42 @@
{
"date": "2026-09-27",
"task": "SECRETS-WP-0011-T04",
"scope": "Catalog configuration and backend-free recipient validation; not live delivery",
"host": "railiance01",
"activity_core_handoff": "a2eae5f8-60cf-499b-8f52-dd04ac407924",
"owner_check": {
"ok": true,
"check_only": true,
"dispatch_enabled": false,
"messages_policy_sha256": "a7f70cd57536e39b4b4d66c2d52fc6a74ca30eb16a8ea8dc50b59e177c3247fd",
"runtime_sha256": "b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969"
},
"owner_digest": "46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b",
"path_and_pin_checks": "passed",
"backend_opened": false,
"file_pins": {
"/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3": {
"sha256": "e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f",
"private": false
},
"/home/tegwick/hfact/owner-metered/owner.json": {
"sha256": "0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274",
"private": true
},
"/home/tegwick/hfact/owner-metered/spend-policy.json": {
"sha256": "f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c",
"private": true
}
},
"worker_identity": "rein-aharness-metered@railiance01",
"labels": "hfact-metered",
"companion": {
"catalog": "activity-core-metered-worker-token",
"field": "token",
"env": "ACTIVITY_CORE_WORKER_TOKEN"
},
"credentials_read": false,
"queue_claimed": false,
"provider_request": false,
"native_activation_task": "SECRETS-WP-0009-T03"
}

View file

@ -9,8 +9,9 @@ factory recipient is now a pinned metered owner outside the sandbox. A different
command or inherited engine credential would violate that boundary. command or inherited engine credential would violate that boundary.
Catalog `delivery_config.exec_owner` is optional for existing lanes. The Claude Catalog `delivery_config.exec_owner` is optional for existing lanes. The Claude
factory lane explicitly requires it and currently declares `status: pending`, factory lane explicitly requires it. It now has a configured metered recipient
`owner` and `reason`. Pending means no exec: refusal precedes approval consumption, and worker-token companion, validated on 2026-09-27. A pending binding declares
only `status: pending`, `owner` and `reason`. Pending means no exec: refusal precedes approval consumption,
backend opening and secret retrieval. Routing stays unready even if custody exists. backend opening and secret retrieval. Routing stays unready even if custody exists.
A reviewed binding uses exactly these keys: A reviewed binding uses exactly these keys:

View file

@ -7,8 +7,8 @@ part of native read-lane adoption.
2026-09-10: the factory continuation uses a metered MessagesOwner outside the 2026-09-10: the factory continuation uses a metered MessagesOwner outside the
sandbox. Its exact runtime is installed and synthetically proved on Railiance. sandbox. Its exact runtime is installed and synthetically proved on Railiance.
The catalog now blocks exec with an explicit pending recipient binding until the That initial pending binding has since been replaced by the pinned configuration
native holder and immutable configuration are admitted. See reviewed on 2026-09-27; native activation remains separate. See
[exec owner binding](exec-owner-binding.md). The older transport description [exec owner binding](exec-owner-binding.md). The older transport description
below records the original child-key route; it cannot admit the metered holder. below records the original child-key route; it cannot admit the metered holder.
@ -38,9 +38,10 @@ approval, OpenBao access, provider authentication or production readiness.
## Activation requirements ## Activation requirements
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and SECRETS-WP-0010-T03. The Glas catalog now has a configured owner binding and worker companion,
refuses exec before approval consumption or backend access. The earlier lack verified by backend-free checks on railiance01. It refuses substituted children
of a served decision path is no longer the current activation blocker. and still requires fresh exact approvals and verified delivery state. The earlier
lack of a served decision path is no longer the current activation blocker.
The metered owner configuration and binding were prepared on 2026-09-23. The metered owner configuration and binding were prepared on 2026-09-23.
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
@ -51,12 +52,11 @@ metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
not the historical sandbox helper above. not the historical sandbox helper above.
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
activation. Review the draft binding, revalidate installed files and private activation. Revalidate the configured binding, installed files and private
state, configure the approved owner, and obtain exact per-action/per-lane state in the execution window, and obtain exact per-action/per-lane approvals. Apply the scoped policy/AppRole, verify positive read and denied
approvals. Apply the scoped policy/AppRole, verify positive read and denied
metadata/sibling/write access with an unrelated negative identity, then prove metadata/sibling/write access with an unrelated negative identity, then prove
bounded owner delivery and session revocation. Both lanes must independently bounded owner delivery and session revocation. Both lanes must independently
pass approval, PDP, consume and delivery readiness. The handoff and draft are pass approval, PDP, consume and delivery readiness. The handoff and catalog configuration are
not runtime authorization. No production activation was performed in this review. not runtime authorization. No production activation was performed in this review.
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke Rotation: store replacement with CAS, stop old runs, verify replacement, revoke

View file

@ -0,0 +1,83 @@
# Railiance Clock lifecycle-consumer review
SECRETS-IN-0003, reviewed 2026-09-27. This completes the requested consumer
review. It does not admit a new authority, key, deployment or execution window.
Reviewed inputs: railiance-clock `61e86a6e01c2e93a9af923a46772a41d080a5743`,
`specs/sample-profile-v0.1.md`, `docs/implementation-review-2026-09-15.md`,
`src/railiance_clock/{protocol,client,admission}.py`, and this repository's
`application_time.py`, approval validators and consume guard. The earlier
intake describes a proposal, but consumer implementation and scoped native
acceptance already exist in [the approval contract](approval-consumption.md)
and [the September 16 receipt](evidence/2026-09-16-t03-completion.json).
## Signing compatibility and custody
The reviewed implementation delegates ES256 to PyJWT/cryptography, pinned by
railiance-clock's dependency range (`PyJWT[crypto]>=2.10,<3`). It verifies the
original compact envelope, restricts the algorithm to ES256, and requires an
admitted P-256 public key and exact key ID. Closed headers, 64-byte signatures,
canonical base64url, strict JSON, nonce and authority/environment/epoch/policy
checks accompany signature verification. Secrets-engine uses that library;
it has no independent signing or verification implementation.
The signing private key belongs to the platform's admitted custody and the
clock authority runtime. It must not share an approval, KeyCape, SSH or engine
credential. No signing key is delivered to this engine: its input is a public
trust binding. The clock's explicit private-file deployment interface is not
proof of OpenBao custody, renewal or fleet-wide admission. Those owner proofs
remain in existing RCLK-WP-0002/0004/0005; no new custody task or lane is created.
## Bootstrap, rotation and revocation
Admit the authority, environment, public-key fingerprint, key ID, epoch, policy,
transport and finite lifetime over an independently authenticated owner path.
The sample under verification cannot establish its own trust. HTTPS verification
must work already; the reviewed alternative is explicitly admitted SSH-backed
loopback transport. Neither permits disabling TLS checks or adjusting OS time.
The current trust admission is client-boot-bound, with a maximum 15-minute
BOOTTIME deadline. Every read obtains a fresh sample and checks the trust file
before and after exchange; cached usable-time holdover is absent. Missing or
changed trust, expiration, an unknown epoch, rollback-state failure or excessive
uncertainty must refuse. The engine's cached client intentionally remains refused
after its trust file changes; restart/reacquisition requires a separately admitted
replacement, not automatic trust discovery.
For rotation, platform/clock owners admit the replacement key and invalidate old
client trust bindings, then consumers reacquire under the new binding. For
revocation, invalidate every affected binding and stop the old authority before
accepting further samples. File-change detection is local enforcement, not an
automatic estate-wide revocation distribution system. A consumer whose old file
is not invalidated can retain trust until its bounded deadline. Native rotation,
revocation propagation and snapshot/recovery acceptance must be proved by the
owners before claiming those operational guarantees. The library does not grant
permission to reset the persisted rollback floor.
## Consumer acceptance and limits
`SECRETS_ENGINE_CLOCK_TRUST_FILE` remains explicit opt-in. When configured,
unavailable or untrusted time refuses; it never falls back to workstation time.
An unconfigured engine retains its existing OS-clock path. Claim validity and
freshness and PDP decision lifetime must contain the whole interval: the lower
bound reaches not-before and the upper bound remains strictly before expiry.
Nanosecond-to-microsecond conversion rounds outward. Decision validity is checked
before and after CAS consume, with the existing actor/tenant/action/field/digest
and policy checks unchanged. A refusal after consume prevents backend access,
although the approval may already be consumed and needs a new request.
This is a check at the engine's consume boundary, not an atomic transaction
spanning OpenBao or a proof that a long-running child remains within the decision
lifetime. The library provides bounded time evidence, not authorization, spend
admission, complete audit custody or provider-session revocation. Server-side
issuers/approval storage retain their own validity enforcement.
The September 16 native receipt records three bounded samples, wrong-key-ID
refusal, independent host cross-checks and a 900-second trust admission during
one exact OpenRouter acceptance. It does not prove universal UTC accuracy,
all-platform suspend behavior or a rotation/revocation exercise. Existing
RCLK-WP-0002-T04 and RCLK-WP-0004 retain those owner acceptance boundaries.
`tests/test_application_time.py` covers interval boundaries, missing trust,
no shifted-time mixing and consume expiry refusal. This review accepts the
explicit bounded-time consumer contract within those stated limits; it grants
no new production use.

View file

@ -85,13 +85,20 @@ state_hub_intake_id: "01a0c279-538e-7d99-bf69-f4c67a8d3eda"
id: SECRETS-IN-0003 id: SECRETS-IN-0003
kind: intake kind: intake
title: 'railiance-clock: review signing custody, rotation and lifecycle-consumer adoption condition' title: 'railiance-clock: review signing custody, rotation and lifecycle-consumer adoption condition'
status: open status: closed
origin: cross-repo origin: cross-repo
origin_ref: hub messages f90b9f17 and 302291b5 (railiance-clock, 2026-09-14) origin_ref: hub messages f90b9f17 and 302291b5 (railiance-clock, 2026-09-14)
priority: low priority: low
owner: secrets-engine owner: secrets-engine
requested_by: railiance-clock requested_by: railiance-clock
resolution: '' resolution: >-
Consumer review completed 2026-09-27 in docs/railiance-clock-consumer-review.md.
Reviewed ES256/PyJWT compatibility, platform signing custody boundary,
independent boot-bound trust, rotation/revocation propagation requirements,
interval validity and CAS check-to-use limits. Existing consumer code and
2026-09-16 scoped native receipt supersede the intake's proposal-only framing.
No new authority/key/activation admitted. Operational acceptance remains with
existing RCLK-WP-0002-T04 and RCLK-WP-0004/0005 owner work.
description: >- description: >-
railiance-clock published its foundation (commit 0a144b6, RCLK-WP plans) and a railiance-clock published its foundation (commit 0a144b6, RCLK-WP plans) and a
candidate time-sample profile (commit 7af595b, specs/sample-profile-v0.1.md: candidate time-sample profile (commit 7af595b, specs/sample-profile-v0.1.md:

View file

@ -13,9 +13,9 @@ its own right, reported rather than resolved away by precedence.
Layer values are compared against §3's closed four-token vocabulary after an Layer values are compared against §3's closed four-token vocabulary after an
ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled: ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled:
`Engine` and `engine` are one token. Neither form carries a standard version `Engine` and `engine` are one token. Neither form carries a standard version
(GH-DEC-2026-017 §5, amendment A12 r2 / GH-DEC-2026-020), and its return is (GH-DEC-2026-017 §5, amendment A12 r3 / GH-DEC-2026-021), and its return is
rejected. The rule reaches content, not a key name: every key and value of the rejected. The estate reference detector walks every key and value of the
INTENT.md frontmatter and of layer.yaml is walked, so a versioned `standard:` or INTENT.md frontmatter and of layer.yaml, so a versioned `standard:` or
`companion:` path and a `companion_version` are caught as well as a `companion:` path and a `companion_version` are caught as well as a
`standard_version`. Comments and `schema_version` are not reached. Stance maps `standard_version`. Comments and `schema_version` are not reached. Stance maps
and evidence classifications (pep-stance.yaml, evidence-classification.yaml) and evidence classifications (pep-stance.yaml, evidence-classification.yaml)
@ -60,29 +60,51 @@ DECISION_SURFACE = re.compile(
LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"} LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
EXPECTED_LAYER = "engine" EXPECTED_LAYER = "engine"
# The standard text this checker was built and validated against, printed on # The accepted text and rulings enforced by this run (GH-DEC-2026-021 §2).
# every run (GH-DEC-2026-020 §4, A12 r2). v0.7 is the accepted text in force; # Update together with the reference detector when the accepted text changes.
# the v0.8 §11 amendments it already applies are named alongside. Bump this VALIDATED_AGAINST = (
# when the checker is re-validated against a newer accepted text. "net-kingdom/canon/standards/security-layer-model_v0.7.md (net-kingdom@66dc491) "
VALIDATED_AGAINST = "net-kingdom/canon/standards/security-layer-model_v0.7.md" "as amended by GH-DEC-2026-017, GH-DEC-2026-020 and GH-DEC-2026-021 "
AMENDMENTS_APPLIED = "v0.8 A9, A11, A12 r2 (GH-DEC-2026-017, GH-DEC-2026-020)" "(A9-A13, A12 r3; gate-house@39d9287)"
)
SCOPE = ( SCOPE = (
"declaration = INTENT.md frontmatter + layer.yaml (every key and value); " "declaration = INTENT.md frontmatter + layer.yaml (every key and value); "
"source = src/secrets_engine/**/*.py; " "source = src/secrets_engine/**/*.py; "
"not reached by A12: pep-stance.yaml, evidence-classification.yaml" "not reached by A12: pep-stance.yaml, evidence-classification.yaml"
) )
# A12 r2: a version of the standard or its companion, anywhere in the # Estate reference detector, GH-DEC-2026-021 §3.
# declaration. `schema_version` is the declaration file's own schema and is VERSION_KEY = re.compile(r"(standard|companion).*version|version.*(standard|companion)", re.I)
# not reached. VERSION_IN_VALUE = re.compile(r"[_\-.]v\d+(\.\d+)*(\.md)?\b|@v?\d+\.\d+", re.I)
VERSION_KEY = re.compile(r"version", re.IGNORECASE) NOT_REACHED_KEYS = {"schema_version"}
UNREACHED_KEYS = {"schema_version"} IDENTITY_KEYS = {"standard", "companion"}
VERSIONED_REF = re.compile( IDENTITY_VERSION = re.compile(r"\bv?\d+\.\d+", re.I)
r"(?i)(security-layer-model|security-companion|layer-model|companion)"
r"[^\s]*?(?:[_@-]v?\d+(?:\.\d+)*|\bv\d+(?:\.\d+)*)"
) def find_version_pins(node, where: str = "", identity: bool = False) -> list[str]:
STANDARD_KEYS = {"standard", "companion", "framework"} """Every place in a parsed declaration that carries a standard/companion version.
BARE_VERSION = re.compile(r"(?i)(?:^|[_@\s-])v?\d+\.\d+(?:\.\d+)*\b")
Walks every key and value (comments are gone after parsing, which is the
A12 r2 exclusion). Returns human-readable locations; empty means clean.
"""
pins: list[str] = []
if isinstance(node, dict):
for k, v in node.items():
here = f"{where}.{k}" if where else str(k)
if str(k) in NOT_REACHED_KEYS:
continue
if VERSION_KEY.search(str(k)):
pins.append(f"{here} (key names a standard/companion version)")
continue
pins.extend(find_version_pins(v, here, str(k).lower() in IDENTITY_KEYS))
elif isinstance(node, list):
for i, v in enumerate(node):
pins.extend(find_version_pins(v, f"{where}[{i}]", identity))
elif isinstance(node, str) and VERSION_IN_VALUE.search(node):
pins.append(f"{where} = {node!r} (value carries a version)")
elif isinstance(node, str) and identity and IDENTITY_VERSION.search(node):
pins.append(f"{where} = {node!r} (identity-bearing value carries a version)")
return pins
def _fold(value: object) -> str: def _fold(value: object) -> str:
@ -90,37 +112,13 @@ def _fold(value: object) -> str:
return str(value).strip().encode("ascii", "ignore").decode().lower() return str(value).strip().encode("ascii", "ignore").decode().lower()
def _version_hits(data: object, path: str = "") -> list[str]:
"""Every place a standard or companion version appears in a declaration."""
hits: list[str] = []
if isinstance(data, dict):
for key, value in data.items():
here = f"{path}.{key}" if path else str(key)
if str(key) in UNREACHED_KEYS:
continue
if VERSION_KEY.search(str(key)):
hits.append(f"key {here!r}")
continue
if isinstance(value, str) and str(key).lower() in STANDARD_KEYS:
if BARE_VERSION.search(value):
hits.append(f"{here}: {value!r}")
continue
hits.extend(_version_hits(value, here))
elif isinstance(data, list):
for n, item in enumerate(data):
hits.extend(_version_hits(item, f"{path}[{n}]"))
elif isinstance(data, str) and VERSIONED_REF.search(data):
hits.append(f"{path}: {data!r}")
return hits
def _no_standard_version(where: str, data: dict) -> None: def _no_standard_version(where: str, data: dict) -> None:
hits = _version_hits(data) hits = find_version_pins(data)
if hits: if hits:
print( print(
f"MALFORMED: {where} carries a standard or companion version at " f"MALFORMED: {where} carries a standard or companion version at "
f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any " f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any "
"key or value (§11 as amended by A12 r2, GH-DEC-2026-020 §1-§2)" "key or value (§11 as amended by A12 r3, GH-DEC-2026-021 §1-§3)"
) )
raise SystemExit(2) raise SystemExit(2)
@ -231,7 +229,7 @@ def main() -> int:
ap = argparse.ArgumentParser() ap = argparse.ArgumentParser()
ap.add_argument("--report", action="store_true") ap.add_argument("--report", action="store_true")
args = ap.parse_args() args = ap.parse_args()
print(f"validated against: {VALIDATED_AGAINST} [{AMENDMENTS_APPLIED}]") print(f"validated against: {VALIDATED_AGAINST}")
print(f"scope: {SCOPE}") print(f"scope: {SCOPE}")
front = intent_frontmatter() front = intent_frontmatter()

View file

@ -102,8 +102,9 @@ def test_binding_changed_after_approval_refuses_before_fetch(bound, monkeypatch)
exec_delivery.exec_with_secret(object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"], expected_owner_digest=expected) exec_delivery.exec_with_secret(object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"], expected_owner_digest=expected)
def test_pending_real_catalog_refuses_before_approval_and_backend(tmp_path, monkeypatch): def test_pending_owner_refuses_before_approval_and_backend(tmp_path, monkeypatch):
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml") entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
monkeypatch.setattr(cli, "get_entry", lambda *a: entry) monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
for name in ["_require_lane_approval", "_open_backend"]: for name in ["_require_lane_approval", "_open_backend"]:
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend")) monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
@ -160,8 +161,35 @@ def test_invalid_binding_is_not_a_catalog_fallback(bound, change):
def test_pending_owner_never_advertises_ready(tmp_path, monkeypatch): def test_pending_owner_never_advertises_ready(tmp_path, monkeypatch):
from secrets_engine import routing from secrets_engine import routing
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml") entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
monkeypatch.setattr(routing, "resolve_decision", lambda **k: SimpleNamespace(status="approved", review_url="", is_approved=lambda: True)) monkeypatch.setattr(routing, "resolve_decision", lambda **k: SimpleNamespace(status="approved", review_url="", is_approved=lambda: True))
client = SimpleNamespace(is_reachable=lambda: True, read_policy=lambda p: "policy", approle_exists=lambda r: True, kv_fields_present=lambda *a: {"ANTHROPIC_API_KEY": True}) client = SimpleNamespace(is_reachable=lambda: True, read_policy=lambda p: "policy", approle_exists=lambda r: True, kv_fields_present=lambda *a: {"ANTHROPIC_API_KEY": True})
result = routing.route_lane(entry, hub_url="", repo_root=tmp_path, client=client) result = routing.route_lane(entry, hub_url="", repo_root=tmp_path, client=client)
assert not result.ready and "exec owner" in result.missing assert not result.ready and "exec owner" in result.missing
assert "<command" not in result.next_command assert "<command" not in result.next_command
def test_configured_glas_catalog_refuses_arbitrary_child_before_gate(tmp_path, monkeypatch):
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
assert entry.delivery_config["exec_owner"]["status"] == "configured"
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
for name in ["_require_lane_approval", "_open_backend"]:
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
with pytest.raises(DeliveryError, match="catalog-bound"):
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(field=None, catalog=entry.id, command=["/bin/echo"], mode="exec-env"))
def test_configured_glas_companion_matches_worker_and_pins_spend_policy():
from secrets_engine.exec_owner import resolve_companions
root = Path(__file__).resolve().parents[1] / "catalog"
entry = load_entry(root / "glas-claude-agent-dev-anthropic.yaml")
binding = entry.delivery_config["exec_owner"]
companions = resolve_companions(entry, lambda cid: load_entry(root / (cid + ".yaml")))
assert [(lane.id, field, env) for lane, field, env in companions] == [
("activity-core-metered-worker-token", "token", "ACTIVITY_CORE_WORKER_TOKEN")
]
assert binding["environment"]["AGENT_HARNESS_WORKER_ID"] == "rein-aharness-metered@railiance01"
assert binding["environment"]["AGENT_HARNESS_OPS_LABELS"] == "hfact-metered"
assert binding["files"][binding["environment"]["AGENT_HARNESS_SPEND_POLICY"]]["private"] is True
request = build_action_request(entry, "exec", subject_id="agent:fixture", subject_type="Agent", purpose="owner-proof", fields=entry.fields)
assert request["context"]["exec_owner_sha256"] == owner_digest(entry)

View file

@ -164,7 +164,8 @@ def test_real_exec_handler_rejects_undeclared_claim_before_consume_backend_child
assert [r["result"] for r in records] == ["attempt", "failed-DecisionError"] assert [r["result"] for r in records] == ["attempt", "failed-DecisionError"]
def test_factory_catalog_declares_human_control_and_keeps_owner_pending(): def test_configured_factory_catalog_still_requires_human_control():
entry = load_entry(Path(__file__).resolve().parents[1]/"catalog/glas-claude-agent-dev-anthropic.yaml") entry = load_entry(Path(__file__).resolve().parents[1]/"catalog/glas-claude-agent-dev-anthropic.yaml")
assert entry.approval["human_control"] is True assert entry.approval["human_control"] is True
assert entry.delivery_config["exec_owner"]["status"] == "pending" assert entry.delivery_config["exec_owner"]["status"] == "configured"
assert not entry.approval.get("authorization_id")

View file

@ -190,6 +190,27 @@ def test_schema_version_is_not_reached(tmp_path, monkeypatch):
assert _run_with(tmp_path, monkeypatch, {}, {"schema_version": "0.2"}) == 0 assert _run_with(tmp_path, monkeypatch, {}, {"schema_version": "0.2"}) == 0
@pytest.mark.parametrize("patch", [
{"intent_version": "0.1.0"},
{"rationale": "The v0.5 scope rule is historical provenance."},
{"framework": "Historical v0.7 reference; standard identity is separate."},
])
def test_reference_detector_allows_own_versions_and_prose(tmp_path, monkeypatch, patch):
assert _run_with(tmp_path, monkeypatch, patch, {}) == 0
@pytest.mark.parametrize("patch", [
{"standard_version_reviewed": "0.7"},
{"version_of_companion": "0.2"},
{"standard": "security-layer-model v0.7"},
{"companion": ["security companion 0.2"]},
{"references": [{"path": "unrelated-document-v1.2.md"}]},
{"references": ["security-layer-model@0.7"]},
])
def test_reference_detector_rejects_nested_and_identity_pins(tmp_path, monkeypatch, patch):
assert _run_with(tmp_path, monkeypatch, {}, patch) == 2
def test_stance_and_classification_versions_are_not_reached(): def test_stance_and_classification_versions_are_not_reached():
"""GH-DEC-2026-020 §3: stance maps and classifications keep their version, """GH-DEC-2026-020 §3: stance maps and classifications keep their version,
and the checker never applies A12 to them.""" and the checker never applies A12 to them."""
@ -198,7 +219,7 @@ def test_stance_and_classification_versions_are_not_reached():
for path in (STANCE, CLASSIFICATION): for path in (STANCE, CLASSIFICATION):
data = yaml.safe_load(path.read_text(encoding="utf-8")) data = yaml.safe_load(path.read_text(encoding="utf-8"))
# Each carries a version A12 would reject if it were applied there... # Each carries a version A12 would reject if it were applied there...
assert checker._version_hits(data), f"{path.name} keeps its standard_version" assert checker.find_version_pins(data), f"{path.name} keeps its standard_version"
# ...and the real-tree run still passes: A12 is not applied to them. # ...and the real-tree run still passes: A12 is not applied to them.
result = subprocess.run( result = subprocess.run(
[sys.executable, str(SCRIPT)], cwd=ROOT, capture_output=True, text=True, check=False [sys.executable, str(SCRIPT)], cwd=ROOT, capture_output=True, text=True, check=False

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex owner: codex
topic_slug: custodian topic_slug: custodian
created: "2026-08-21" created: "2026-08-21"
updated: "2026-09-06" updated: "2026-09-27"
state_hub_workstream_id: "31f7f8ea-7f73-516c-8877-f03a13f1db82" state_hub_workstream_id: "31f7f8ea-7f73-516c-8877-f03a13f1db82"
--- ---
@ -195,6 +195,7 @@ Acceptance:
```task ```task
id: SECRETS-WP-0006-T05 id: SECRETS-WP-0006-T05
status: wait status: wait
blocking_reason: "OpenRouter key-check native acceptance is recorded in SECRETS-WP-0010-T03. Other lanes still need exact approvals, scoped attended apply and per-lane positive/negative/health/revocation evidence."
priority: high priority: high
state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542" state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542"
``` ```
@ -256,6 +257,7 @@ Acceptance per lane:
```task ```task
id: SECRETS-WP-0006-T06 id: SECRETS-WP-0006-T06
status: wait status: wait
blocking_reason: "Needs owner-agreed routing/proxy retirement for each verified lane and custody disposition of the legacy npm pointer; a single approved OpenRouter key-check does not authorize broader routing cutover."
priority: medium priority: medium
state_hub_task_id: "1431edae-5791-5892-8c4b-829419b537d2" state_hub_task_id: "1431edae-5791-5892-8c4b-829419b537d2"
``` ```
@ -424,3 +426,13 @@ for a fourth location.
`SECRETS-WP-0006-T06` stays `wait`: this answer unblocks the question, not the `SECRETS-WP-0006-T06` stays `wait`: this answer unblocks the question, not the
lane change, which needs custody's step 1 and its own approval. lane change, which needs custody's step 1 and its own approval.
### Existing-work review — 2026-09-27
The September 16 native OpenRouter key-check receipt supersedes the older
serving/ESO-health wait for that exact recipient. SECRETS-WP-0007-T04 and
SECRETS-WP-0008-T02 are now closed against that real evidence and current
regression coverage. T05 remains open for the other lanes; T06 retains
per-lane routing/proxy retirement and the npm custody discrepancy. No broader
recipient, proxy retirement, or production action is inferred from that receipt.

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex owner: codex
topic_slug: custodian topic_slug: custodian
created: "2026-08-23" created: "2026-08-23"
updated: "2026-09-06" updated: "2026-09-27"
state_hub_workstream_id: "68a39be1-bd9c-5133-ad64-e7bca892aaf3" state_hub_workstream_id: "68a39be1-bd9c-5133-ad64-e7bca892aaf3"
--- ---
@ -213,11 +213,15 @@ Acceptance:
```task ```task
id: SECRETS-WP-0007-T04 id: SECRETS-WP-0007-T04
status: wait status: done
priority: high priority: high
state_hub_task_id: "4b58edec-c705-55e5-9ece-362e1ff13079" state_hub_task_id: "4b58edec-c705-55e5-9ece-362e1ff13079"
``` ```
Completed 2026-09-27 by reconciling the implemented shared approval guard with the
2026-09-16 native receipt. See the closure note below; the serving-path waits
in the dated history are superseded. Native lane cutover remains T07.
Wait 2026-08-29. The consumer validator and production fail-closed gate are Wait 2026-08-29. The consumer validator and production fail-closed gate are
shipped. What remains is not local engine work: State Hub / `access-engine` shipped. What remains is not local engine work: State Hub / `access-engine`
must serve the durable ActionAuthorization object. Paired with must serve the durable ActionAuthorization object. Paired with
@ -707,6 +711,7 @@ Acceptance:
```task ```task
id: SECRETS-WP-0007-T07 id: SECRETS-WP-0007-T07
status: wait status: wait
blocking_reason: "Engine approval hardening is complete. Remaining per-lane cutover includes native routing/proxy retirement with ops-warden under SECRETS-WP-0006-T05/T06; the exact OpenRouter key-check receipt does not establish broader recipient readiness."
priority: high priority: high
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7" state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
``` ```
@ -787,3 +792,25 @@ routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readines
Do not reuse the consumed approvals or treat the temporary key-check overlay as Do not reuse the consumed approvals or treat the temporary key-check overlay as
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance; approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation. IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
### T04 completed after evidence reconciliation — 2026-09-27
The original serving-path wait is superseded by the native 2026-09-16 receipt
`docs/evidence/2026-09-16-t03-completion.json`, not by synthetic tests or Hub
status. It records separate human-controlled apply, verify and exec approvals,
three distinct current PDP decisions/request digests, successful CAS consumes,
and the resulting native OpenBao operations. The claim/PDP/consume join is the
accepted path; the earlier proposed ActionAuthorization is not a dependency.
Current regression coverage exercises wrong fields/actions/tenant/digest,
superseded or expired claims, changed catalog/owner bindings, denied or missing
PDP responses, consume conflicts/unavailability, declared human control and
production fixture refusal. Every live privileged handler still uses the shared
approval gate before backend access. The recorded approvals are consumed and
expired; they are historical completion evidence, never reusable grants.
T04 is done. T07 stays wait because its per-lane acceptance includes routing and
proxy retirement, and the receipt covers only the exact OpenRouter key-check
recipient. Other lanes and cross-owner cutover remain SECRETS-WP-0006-T05/T06;
this workplan is not finished merely because the engine gate is complete.

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: grok owner: grok
topic_slug: custodian topic_slug: custodian
created: "2026-08-29" created: "2026-08-29"
updated: "2026-09-21" updated: "2026-09-27"
state_hub_workstream_id: "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0" state_hub_workstream_id: "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0"
--- ---
@ -90,11 +90,15 @@ Acceptance:
```task ```task
id: SECRETS-WP-0008-T02 id: SECRETS-WP-0008-T02
status: wait status: done
priority: high priority: high
state_hub_task_id: "3eb9cff8-1441-5437-9e92-a2b655c82d04" state_hub_task_id: "3eb9cff8-1441-5437-9e92-a2b655c82d04"
``` ```
Completed 2026-09-27: the 2026-09-16 native apply/verify/exec receipt supplies
the live PDP/claim/consume return awaited below. The dated serving-path waits
are historical. Service JWT adoption remains T06.
Progress 2026-09-02. Gate House notice `632bdad9` (`GH-DEC-2026-003`): this Progress 2026-09-02. Gate House notice `632bdad9` (`GH-DEC-2026-003`): this
engine is the PEP for FLEX-WP-0017-T05 / OpenBao writes. The shared consume engine is the PEP for FLEX-WP-0017-T05 / OpenBao writes. The shared consume
function now lives in `src/secrets_engine/approval_consume.py` and every live function now lives in `src/secrets_engine/approval_consume.py` and every live
@ -327,6 +331,7 @@ Acceptance:
```task ```task
id: SECRETS-WP-0008-T06 id: SECRETS-WP-0008-T06
status: wait status: wait
blocking_reason: "RPF-WP-0035-T02 still awaits exact service claims/tenant, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
priority: medium priority: medium
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148" state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
``` ```
@ -486,3 +491,26 @@ gate-house (message `4220413a`); we follow that answer rather than choose.
- `layer.yaml` / `pep-stance.yaml` / INTENT frontmatter stay in one voice. - `layer.yaml` / `pep-stance.yaml` / INTENT frontmatter stay in one voice.
- No raw secret values in Git, State Hub, chat, prompts, workplans, evidence, - No raw secret values in Git, State Hub, chat, prompts, workplans, evidence,
or argv. or argv.
## Decision consumer closure and declaration ruling applied — 2026-09-27
T02 is done. `docs/evidence/2026-09-16-t03-completion.json` provides the native
return awaited in the September 9 note: separately approved apply/verify/exec
requests received current PDP allows and successful CAS consumption before real
OpenBao work. The shared guard records decision IDs and retains refusal before
backend access for invalid/missing/replayed decisions. SECRETS-WP-0007-T04 now
records the same completed contract; no native activation grant is inferred.
The open conformance-record question is also resolved. GH-DEC-2026-020 §4 says
a versioned/scoped re-runnable checker is sufficient; each declaring repository
need not emit a durable record. GH-DEC-2026-021 §2/§3 names the accepted v0.7
text plus applicable decisions and the ops-warden reference detector. The
checker now copies that detector, permits own-document versions/prose citations,
refuses nested/identity-bearing version pins and names the accepted text and
rulings on every run, including PASS. Declaration spellings are unchanged.
T06 remains wait: railiance-platform's RPF-WP-0035-T02 still records an
unprovisioned, login-only JWT role, pending exact service claims/tenant and
custody/attended admission. The existing env-auth native receipt cannot prove
steady-state service JWT login. This is the only remaining task in this workplan.

View file

@ -49,8 +49,8 @@ synthetic exec-env transport proof passed; no real secret was read.
```task ```task
id: SECRETS-WP-0009-T03 id: SECRETS-WP-0009-T03
status: wait status: wait
blocking_reason: "Configured owner and worker companion passed backend-free recipient/pin checks on 2026-09-27 (SECRETS-WP-0011 complete). Remaining: exact per-action/per-lane approvals, unrelated negative identity, scoped attended apply/verify, bounded real owner delivery and revocation. Recheck pins and spend validity at execution."
priority: high priority: high
blocking_reason: "Shared native chain proved by SECRETS-WP-0010-T03. Metered owner provisioned and binding drafted (2026-09-23); Activity Core reports identity live (2026-09-24). Remaining: current recipient/pin admission, unrelated negative identity, configured exec_owner, exact per-action/per-lane approvals and attended apply/verify/exec/revoke."
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d" state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
``` ```
@ -503,3 +503,19 @@ native apply, positive/negative verification, exec and session revocation.
The production catalog remains pending. The companion-only delivery guards The production catalog remains pending. The companion-only delivery guards
added under SECRETS-WP-0011-T05 must be included in the host checkout used for added under SECRETS-WP-0011-T05 must be included in the host checkout used for
activation. No credential read, queue claim or paid run occurred in this review. activation. No credential read, queue claim or paid run occurred in this review.
### 2026-09-27 configured owner and companion landed
SECRETS-WP-0011 is finished at its catalog/implementation boundary. The binding
formerly held in `docs/drafts/glas-exec-owner-configured.yaml` is now configured
in the active Glas catalog, with an added exact private spend-policy file pin.
The installed owner's backend-free check and engine path/pin validation passed
on railiance01. Receipt: `docs/evidence/2026-09-27-companion-catalog-readiness.json`.
The original pending-recipient configuration is superseded; current code still
refuses any substituted child and requires fresh approvals and delivery state.
T03 retains all native activation and delivery acceptance. Revalidate the owner
and spend envelope in the attended execution window, use approvals bound to the
new owner digest and each lane, apply/verify both native lanes, and prove actual
bounded owner delivery and cleanup. Configuration does not authorize those actions.

View file

@ -4,7 +4,7 @@ type: workplan
title: "Multi-lane exec-owner delivery" title: "Multi-lane exec-owner delivery"
domain: infotech domain: infotech
repo: secrets-engine repo: secrets-engine
status: active status: finished
flavor: implementation flavor: implementation
owner: claude-code owner: claude-code
topic_slug: netkingdom topic_slug: netkingdom
@ -91,12 +91,15 @@ a throwaway OpenBao dev server.
```task ```task
id: SECRETS-WP-0011-T04 id: SECRETS-WP-0011-T04
status: wait status: done
priority: high priority: high
blocking_reason: "Activity Core reports ACTIVITY-WP-0039 finished and metered identity authentication proved (2026-09-24). Remaining: admit the configured Glas owner, obtain exact per-lane approvals, and perform attended native apply/verify/delivery under SECRETS-WP-0009-T03."
state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d" state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d"
``` ```
Completed 2026-09-27: custody handoff received, companion cataloged and wired
into the configured Glas owner after fresh backend-free host verification.
Native activation remains in existing SECRETS-WP-0009-T03, as detailed below.
Request activity-core to move the worker token into OpenBao custody, synced to Request activity-core to move the worker token into OpenBao custody, synced to
`actcore-runtime-secret` by their existing `openbao-activity-core` store. Then `actcore-runtime-secret` by their existing `openbao-activity-core` store. Then
catalog a read lane for the metered owner and add it as the Glas lane's catalog a read lane for the metered owner and add it as the Glas lane's
@ -172,3 +175,27 @@ T04 remains wait for native lane activation with SECRETS-WP-0009-T03: current
owner admission/pins, exact per-lane approvals and attended apply/verify/exec. owner admission/pins, exact per-lane approvals and attended apply/verify/exec.
The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching
the handoff. No production policy, role, catalog binding or credential changed. the handoff. No production policy, role, catalog binding or credential changed.
## Catalog task and workplan completed — 2026-09-27
T04's stated work is custody coordination, the worker-token catalog entry and
adding that entry as the Glas owner's companion. All three are now complete.
Activity Core's 2026-09-24 handoff supplies the custody/identity return. The
configured binding is now in `catalog/glas-claude-agent-dev-anthropic.yaml`,
including the worker identity/label and a private spend-policy file pin.
A fresh backend-free check on railiance01 verified the installed owner with
`metered-once --check --no-hub` (dispatch disabled), and this checkout's exact
path/ownership/mode/hash checks passed for the executable, owner configuration,
spend policy and private working directory. Receipt:
`docs/evidence/2026-09-27-companion-catalog-readiness.json`.
The owner digest is `46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b`.
The previous wait reason conflated catalog completion with native activation.
That activation was already owned by SECRETS-WP-0009-T03 and stays there: exact
per-lane action approvals, scoped attended apply, positive/negative verification,
actual bounded delivery and session revocation. No new task is needed. This
workplan's completion claims the configured multi-lane contract, its tests and
catalog wiring, not production delivery. No credential was requested or read,
no queue row was claimed, and no provider request was made.