Finish companion catalog work and reconcile completed approval tasks
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
41e4c4a3d8
commit
e33f9c3ca5
18 changed files with 472 additions and 87 deletions
|
|
@ -3,8 +3,8 @@ kind: kv
|
|||
org: coulomb
|
||||
repo: sand-boxer
|
||||
stage: prod
|
||||
description: Proposed native exec-env delivery for CCR-2026-0016. KV custody exists;
|
||||
no runtime grant or activation yet.
|
||||
description: Catalog-bound metered owner with Activity Core worker-token companion.
|
||||
KV custody exists; native runtime approval and activation remain SECRETS-WP-0009-T03.
|
||||
mount: platform
|
||||
path: workloads/glas-harness/claude-agent-dev
|
||||
mount_management: existing
|
||||
|
|
@ -19,12 +19,46 @@ consumers:
|
|||
workload_delivery: []
|
||||
delivery_config:
|
||||
exec_owner:
|
||||
status: pending
|
||||
owner: rein-aharness MessagesOwner with sand-boxer runtime boundary
|
||||
reason: Exact installed metered-once runtime is proved; native holder review,
|
||||
immutable owner configuration and private state/profile/service admission
|
||||
remain SECRETS-WP-0009-T03 and HFACT-WP-0001-T03/T04. No arbitrary child may
|
||||
receive this key while the owner binding is pending.
|
||||
status: configured
|
||||
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
|
||||
command:
|
||||
- /home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3
|
||||
- -I
|
||||
- -B
|
||||
- -m
|
||||
- rein_aharness.cli
|
||||
- metered-once
|
||||
- --owner-config
|
||||
- /home/tegwick/hfact/owner-metered/owner.json
|
||||
cwd: /home/tegwick/hfact/owner-metered
|
||||
environment:
|
||||
PATH: /usr/bin:/bin
|
||||
LANG: C.UTF-8
|
||||
HOME: /home/tegwick
|
||||
ACTIVITY_CORE_URL: http://127.0.0.1:8010
|
||||
AGENT_HARNESS_WORKER_ID: rein-aharness-metered@railiance01
|
||||
AGENT_HARNESS_OPS_LABELS: hfact-metered
|
||||
AGENT_HARNESS_OPS_LABELS_MODE: all
|
||||
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
|
||||
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
|
||||
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
|
||||
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
|
||||
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
|
||||
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
|
||||
files:
|
||||
/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3:
|
||||
sha256: e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f
|
||||
private: false
|
||||
/home/tegwick/hfact/owner-metered/owner.json:
|
||||
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
|
||||
private: true
|
||||
/home/tegwick/hfact/owner-metered/spend-policy.json:
|
||||
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
|
||||
private: true
|
||||
companions:
|
||||
- catalog: activity-core-metered-worker-token
|
||||
field: token
|
||||
env: ACTIVITY_CORE_WORKER_TOKEN
|
||||
delivery_modes:
|
||||
- exec-env
|
||||
- read-check
|
||||
|
|
|
|||
52
docs/2026-09-27-loose-end-closeout.md
Normal file
52
docs/2026-09-27-loose-end-closeout.md
Normal file
|
|
@ -0,0 +1,52 @@
|
|||
# Existing-work closeout — 2026-09-27
|
||||
|
||||
No new task or workplan was opened. Three tasks and one intake can close from
|
||||
existing evidence plus the local completion below. One workplan finishes.
|
||||
|
||||
| Existing record | Result | Basis |
|
||||
| --- | --- | --- |
|
||||
| SECRETS-WP-0007-T04 | done | Shared exact-action claim/PDP/consume implementation, regression refusals and real separate apply/verify/exec consumes in the September 16 native receipt |
|
||||
| SECRETS-WP-0008-T02 | done | The same native receipt resolves its outstanding served-decision/consume dependency; current regression coverage retains fail-closed replay and lifetime checks |
|
||||
| SECRETS-WP-0011-T04 | done | Activity Core custody/identity handoff received; configured owner and companion now cataloged; current owner/path/hash checks passed on railiance01 without backend access |
|
||||
| SECRETS-WP-0011 | finished | All five tasks complete; native Glas activation remains in the existing SECRETS-WP-0009-T03 |
|
||||
| SECRETS-IN-0003 | closed | Published signing/custody/bootstrap/rotation/revocation and bounded-time consumer review, with limits and existing owner acceptance work named |
|
||||
|
||||
Implementation includes the private spend-policy pin and the estate reference
|
||||
layer-version detector under SECRETS-WP-0008. The latter closes the stale
|
||||
conformance-record question without inventing a durable-record requirement.
|
||||
|
||||
Evidence:
|
||||
|
||||
- [Native approval and delivery receipt](evidence/2026-09-16-t03-completion.json)
|
||||
is historical acceptance for one exact OpenRouter key-check recipient. Its
|
||||
consumed approvals grant no future action.
|
||||
- [Companion catalog receipt](evidence/2026-09-27-companion-catalog-readiness.json)
|
||||
records current backend-free owner validation, installed file pins and owner
|
||||
digest. Configuration is not production approval or delivery readiness.
|
||||
- [Clock consumer review](railiance-clock-consumer-review.md) closes a review
|
||||
request, without enabling a new trust binding or claiming operational rotation.
|
||||
|
||||
## Work that must remain open
|
||||
|
||||
| Existing record | Remaining completion requirement |
|
||||
| --- | --- |
|
||||
| SECRETS-WP-0006-T05 | Approved native verification for the other catalog lanes; the OpenRouter key-check receipt covers one exact recipient only |
|
||||
| SECRETS-WP-0006-T06 | Owner-agreed routing/proxy retirement per verified lane, plus custody disposition of the legacy npm pointer; no unilateral proxy retirement |
|
||||
| SECRETS-WP-0007-T07 | Its acceptance includes native cutover and routing/proxy retirement under 0006-T05/T06; engine hardening alone does not satisfy it |
|
||||
| SECRETS-WP-0008-T06 | Platform/KeyCape exact service claims and tenant, custody, provisioned scoped JWT role and native login/negative/revocation acceptance (RPF-WP-0035-T02); the recorded env-auth run does not prove this |
|
||||
| SECRETS-WP-0009-T03 | Fresh exact per-action/per-lane approvals, unrelated negative identity, attended apply/verify, bounded real Glas delivery and revocation; recheck pins and spend validity in that window |
|
||||
| SECRETS-IN-0002 | Confirmed flex-auth repository rename before changing checkout coordinates; FLEX-WP-0020 still holds the live rename |
|
||||
|
||||
Workplans 0006, 0007, 0008 and 0009 therefore remain unfinished. Their remaining
|
||||
requirements stay in those records, with no replacement or successor task.
|
||||
|
||||
|
||||
Scope reconciliation is recorded as State Hub decision
|
||||
`7a756027-2041-4732-bcbc-3bb6a5380838`; it grants no credential action.
|
||||
|
||||
|
||||
Validation: 487 repository tests passed, including disposable OpenBao integration.
|
||||
The layer-conformance checker and `git diff --check` passed. The configured
|
||||
recipient's local-only owner check and exact engine path/pin checks passed on
|
||||
railiance01; no backend credential was requested, no queue row was claimed and
|
||||
no provider request was made.
|
||||
|
|
@ -218,3 +218,9 @@ and after CAS consume. The client keeps a boot-bound trust admission and private
|
|||
rollback floor. It never changes the OS clock, accepts a sample as its own trust
|
||||
bootstrap, or falls back to a shifted local timestamp. The option stays unset
|
||||
until the owner publishes trust through the admitted Railiance Clock deployment.
|
||||
|
||||
|
||||
The [2026-09-27 consumer review](railiance-clock-consumer-review.md) records
|
||||
signing compatibility, custody, bootstrap, rotation/revocation and check-to-use
|
||||
limits. It reconciles SECRETS-IN-0003 with the already recorded September 16
|
||||
native use; it does not enable a new trust binding.
|
||||
|
|
|
|||
|
|
@ -1,7 +1,6 @@
|
|||
# Draft exec_owner for glas-claude-agent-dev-anthropic (SECRETS-WP-0009-T03).
|
||||
# Not in the catalog. Activity Core reports custody and identity live as of
|
||||
# 2026-09-24 (ACTIVITY-WP-0039). Admission still requires current owner/pin
|
||||
# validation and exact per-lane approvals for attended native activation.
|
||||
# Configured binding promoted to catalog/glas-claude-agent-dev-anthropic.yaml
|
||||
# on 2026-09-27 after backend-free owner and path/pin validation.
|
||||
# Configuration is not runtime approval; native activation is SECRETS-WP-0009-T03.
|
||||
exec_owner:
|
||||
status: configured
|
||||
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
|
||||
|
|
@ -24,8 +23,8 @@ exec_owner:
|
|||
AGENT_HARNESS_OPS_LABELS: hfact-metered
|
||||
AGENT_HARNESS_OPS_LABELS_MODE: all
|
||||
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
|
||||
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: "1"
|
||||
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: "1"
|
||||
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
|
||||
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
|
||||
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
|
||||
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
|
||||
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
|
||||
|
|
@ -36,6 +35,9 @@ exec_owner:
|
|||
/home/tegwick/hfact/owner-metered/owner.json:
|
||||
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
|
||||
private: true
|
||||
/home/tegwick/hfact/owner-metered/spend-policy.json:
|
||||
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
|
||||
private: true
|
||||
companions:
|
||||
- catalog: activity-core-metered-worker-token
|
||||
field: token
|
||||
|
|
|
|||
42
docs/evidence/2026-09-27-companion-catalog-readiness.json
Normal file
42
docs/evidence/2026-09-27-companion-catalog-readiness.json
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
{
|
||||
"date": "2026-09-27",
|
||||
"task": "SECRETS-WP-0011-T04",
|
||||
"scope": "Catalog configuration and backend-free recipient validation; not live delivery",
|
||||
"host": "railiance01",
|
||||
"activity_core_handoff": "a2eae5f8-60cf-499b-8f52-dd04ac407924",
|
||||
"owner_check": {
|
||||
"ok": true,
|
||||
"check_only": true,
|
||||
"dispatch_enabled": false,
|
||||
"messages_policy_sha256": "a7f70cd57536e39b4b4d66c2d52fc6a74ca30eb16a8ea8dc50b59e177c3247fd",
|
||||
"runtime_sha256": "b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969"
|
||||
},
|
||||
"owner_digest": "46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b",
|
||||
"path_and_pin_checks": "passed",
|
||||
"backend_opened": false,
|
||||
"file_pins": {
|
||||
"/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3": {
|
||||
"sha256": "e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f",
|
||||
"private": false
|
||||
},
|
||||
"/home/tegwick/hfact/owner-metered/owner.json": {
|
||||
"sha256": "0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274",
|
||||
"private": true
|
||||
},
|
||||
"/home/tegwick/hfact/owner-metered/spend-policy.json": {
|
||||
"sha256": "f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c",
|
||||
"private": true
|
||||
}
|
||||
},
|
||||
"worker_identity": "rein-aharness-metered@railiance01",
|
||||
"labels": "hfact-metered",
|
||||
"companion": {
|
||||
"catalog": "activity-core-metered-worker-token",
|
||||
"field": "token",
|
||||
"env": "ACTIVITY_CORE_WORKER_TOKEN"
|
||||
},
|
||||
"credentials_read": false,
|
||||
"queue_claimed": false,
|
||||
"provider_request": false,
|
||||
"native_activation_task": "SECRETS-WP-0009-T03"
|
||||
}
|
||||
|
|
@ -9,8 +9,9 @@ factory recipient is now a pinned metered owner outside the sandbox. A different
|
|||
command or inherited engine credential would violate that boundary.
|
||||
|
||||
Catalog `delivery_config.exec_owner` is optional for existing lanes. The Claude
|
||||
factory lane explicitly requires it and currently declares `status: pending`,
|
||||
`owner` and `reason`. Pending means no exec: refusal precedes approval consumption,
|
||||
factory lane explicitly requires it. It now has a configured metered recipient
|
||||
and worker-token companion, validated on 2026-09-27. A pending binding declares
|
||||
only `status: pending`, `owner` and `reason`. Pending means no exec: refusal precedes approval consumption,
|
||||
backend opening and secret retrieval. Routing stays unready even if custody exists.
|
||||
|
||||
A reviewed binding uses exactly these keys:
|
||||
|
|
|
|||
|
|
@ -7,8 +7,8 @@ part of native read-lane adoption.
|
|||
|
||||
2026-09-10: the factory continuation uses a metered MessagesOwner outside the
|
||||
sandbox. Its exact runtime is installed and synthetically proved on Railiance.
|
||||
The catalog now blocks exec with an explicit pending recipient binding until the
|
||||
native holder and immutable configuration are admitted. See
|
||||
That initial pending binding has since been replaced by the pinned configuration
|
||||
reviewed on 2026-09-27; native activation remains separate. See
|
||||
[exec owner binding](exec-owner-binding.md). The older transport description
|
||||
below records the original child-key route; it cannot admit the metered holder.
|
||||
|
||||
|
|
@ -38,9 +38,10 @@ approval, OpenBao access, provider authentication or production readiness.
|
|||
## Activation requirements
|
||||
|
||||
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
|
||||
SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and
|
||||
refuses exec before approval consumption or backend access. The earlier lack
|
||||
of a served decision path is no longer the current activation blocker.
|
||||
SECRETS-WP-0010-T03. The Glas catalog now has a configured owner binding and worker companion,
|
||||
verified by backend-free checks on railiance01. It refuses substituted children
|
||||
and still requires fresh exact approvals and verified delivery state. The earlier
|
||||
lack of a served decision path is no longer the current activation blocker.
|
||||
|
||||
The metered owner configuration and binding were prepared on 2026-09-23.
|
||||
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
|
||||
|
|
@ -51,12 +52,11 @@ metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
|
|||
not the historical sandbox helper above.
|
||||
|
||||
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
|
||||
activation. Review the draft binding, revalidate installed files and private
|
||||
state, configure the approved owner, and obtain exact per-action/per-lane
|
||||
approvals. Apply the scoped policy/AppRole, verify positive read and denied
|
||||
activation. Revalidate the configured binding, installed files and private
|
||||
state in the execution window, and obtain exact per-action/per-lane approvals. Apply the scoped policy/AppRole, verify positive read and denied
|
||||
metadata/sibling/write access with an unrelated negative identity, then prove
|
||||
bounded owner delivery and session revocation. Both lanes must independently
|
||||
pass approval, PDP, consume and delivery readiness. The handoff and draft are
|
||||
pass approval, PDP, consume and delivery readiness. The handoff and catalog configuration are
|
||||
not runtime authorization. No production activation was performed in this review.
|
||||
|
||||
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
|
||||
|
|
|
|||
83
docs/railiance-clock-consumer-review.md
Normal file
83
docs/railiance-clock-consumer-review.md
Normal file
|
|
@ -0,0 +1,83 @@
|
|||
# Railiance Clock lifecycle-consumer review
|
||||
|
||||
SECRETS-IN-0003, reviewed 2026-09-27. This completes the requested consumer
|
||||
review. It does not admit a new authority, key, deployment or execution window.
|
||||
|
||||
Reviewed inputs: railiance-clock `61e86a6e01c2e93a9af923a46772a41d080a5743`,
|
||||
`specs/sample-profile-v0.1.md`, `docs/implementation-review-2026-09-15.md`,
|
||||
`src/railiance_clock/{protocol,client,admission}.py`, and this repository's
|
||||
`application_time.py`, approval validators and consume guard. The earlier
|
||||
intake describes a proposal, but consumer implementation and scoped native
|
||||
acceptance already exist in [the approval contract](approval-consumption.md)
|
||||
and [the September 16 receipt](evidence/2026-09-16-t03-completion.json).
|
||||
|
||||
## Signing compatibility and custody
|
||||
|
||||
The reviewed implementation delegates ES256 to PyJWT/cryptography, pinned by
|
||||
railiance-clock's dependency range (`PyJWT[crypto]>=2.10,<3`). It verifies the
|
||||
original compact envelope, restricts the algorithm to ES256, and requires an
|
||||
admitted P-256 public key and exact key ID. Closed headers, 64-byte signatures,
|
||||
canonical base64url, strict JSON, nonce and authority/environment/epoch/policy
|
||||
checks accompany signature verification. Secrets-engine uses that library;
|
||||
it has no independent signing or verification implementation.
|
||||
|
||||
The signing private key belongs to the platform's admitted custody and the
|
||||
clock authority runtime. It must not share an approval, KeyCape, SSH or engine
|
||||
credential. No signing key is delivered to this engine: its input is a public
|
||||
trust binding. The clock's explicit private-file deployment interface is not
|
||||
proof of OpenBao custody, renewal or fleet-wide admission. Those owner proofs
|
||||
remain in existing RCLK-WP-0002/0004/0005; no new custody task or lane is created.
|
||||
|
||||
## Bootstrap, rotation and revocation
|
||||
|
||||
Admit the authority, environment, public-key fingerprint, key ID, epoch, policy,
|
||||
transport and finite lifetime over an independently authenticated owner path.
|
||||
The sample under verification cannot establish its own trust. HTTPS verification
|
||||
must work already; the reviewed alternative is explicitly admitted SSH-backed
|
||||
loopback transport. Neither permits disabling TLS checks or adjusting OS time.
|
||||
|
||||
The current trust admission is client-boot-bound, with a maximum 15-minute
|
||||
BOOTTIME deadline. Every read obtains a fresh sample and checks the trust file
|
||||
before and after exchange; cached usable-time holdover is absent. Missing or
|
||||
changed trust, expiration, an unknown epoch, rollback-state failure or excessive
|
||||
uncertainty must refuse. The engine's cached client intentionally remains refused
|
||||
after its trust file changes; restart/reacquisition requires a separately admitted
|
||||
replacement, not automatic trust discovery.
|
||||
|
||||
For rotation, platform/clock owners admit the replacement key and invalidate old
|
||||
client trust bindings, then consumers reacquire under the new binding. For
|
||||
revocation, invalidate every affected binding and stop the old authority before
|
||||
accepting further samples. File-change detection is local enforcement, not an
|
||||
automatic estate-wide revocation distribution system. A consumer whose old file
|
||||
is not invalidated can retain trust until its bounded deadline. Native rotation,
|
||||
revocation propagation and snapshot/recovery acceptance must be proved by the
|
||||
owners before claiming those operational guarantees. The library does not grant
|
||||
permission to reset the persisted rollback floor.
|
||||
|
||||
## Consumer acceptance and limits
|
||||
|
||||
`SECRETS_ENGINE_CLOCK_TRUST_FILE` remains explicit opt-in. When configured,
|
||||
unavailable or untrusted time refuses; it never falls back to workstation time.
|
||||
An unconfigured engine retains its existing OS-clock path. Claim validity and
|
||||
freshness and PDP decision lifetime must contain the whole interval: the lower
|
||||
bound reaches not-before and the upper bound remains strictly before expiry.
|
||||
Nanosecond-to-microsecond conversion rounds outward. Decision validity is checked
|
||||
before and after CAS consume, with the existing actor/tenant/action/field/digest
|
||||
and policy checks unchanged. A refusal after consume prevents backend access,
|
||||
although the approval may already be consumed and needs a new request.
|
||||
|
||||
This is a check at the engine's consume boundary, not an atomic transaction
|
||||
spanning OpenBao or a proof that a long-running child remains within the decision
|
||||
lifetime. The library provides bounded time evidence, not authorization, spend
|
||||
admission, complete audit custody or provider-session revocation. Server-side
|
||||
issuers/approval storage retain their own validity enforcement.
|
||||
|
||||
The September 16 native receipt records three bounded samples, wrong-key-ID
|
||||
refusal, independent host cross-checks and a 900-second trust admission during
|
||||
one exact OpenRouter acceptance. It does not prove universal UTC accuracy,
|
||||
all-platform suspend behavior or a rotation/revocation exercise. Existing
|
||||
RCLK-WP-0002-T04 and RCLK-WP-0004 retain those owner acceptance boundaries.
|
||||
`tests/test_application_time.py` covers interval boundaries, missing trust,
|
||||
no shifted-time mixing and consume expiry refusal. This review accepts the
|
||||
explicit bounded-time consumer contract within those stated limits; it grants
|
||||
no new production use.
|
||||
|
|
@ -85,13 +85,20 @@ state_hub_intake_id: "01a0c279-538e-7d99-bf69-f4c67a8d3eda"
|
|||
id: SECRETS-IN-0003
|
||||
kind: intake
|
||||
title: 'railiance-clock: review signing custody, rotation and lifecycle-consumer adoption condition'
|
||||
status: open
|
||||
status: closed
|
||||
origin: cross-repo
|
||||
origin_ref: hub messages f90b9f17 and 302291b5 (railiance-clock, 2026-09-14)
|
||||
priority: low
|
||||
owner: secrets-engine
|
||||
requested_by: railiance-clock
|
||||
resolution: ''
|
||||
resolution: >-
|
||||
Consumer review completed 2026-09-27 in docs/railiance-clock-consumer-review.md.
|
||||
Reviewed ES256/PyJWT compatibility, platform signing custody boundary,
|
||||
independent boot-bound trust, rotation/revocation propagation requirements,
|
||||
interval validity and CAS check-to-use limits. Existing consumer code and
|
||||
2026-09-16 scoped native receipt supersede the intake's proposal-only framing.
|
||||
No new authority/key/activation admitted. Operational acceptance remains with
|
||||
existing RCLK-WP-0002-T04 and RCLK-WP-0004/0005 owner work.
|
||||
description: >-
|
||||
railiance-clock published its foundation (commit 0a144b6, RCLK-WP plans) and a
|
||||
candidate time-sample profile (commit 7af595b, specs/sample-profile-v0.1.md:
|
||||
|
|
|
|||
|
|
@ -13,9 +13,9 @@ its own right, reported rather than resolved away by precedence.
|
|||
Layer values are compared against §3's closed four-token vocabulary after an
|
||||
ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled:
|
||||
`Engine` and `engine` are one token. Neither form carries a standard version
|
||||
(GH-DEC-2026-017 §5, amendment A12 r2 / GH-DEC-2026-020), and its return is
|
||||
rejected. The rule reaches content, not a key name: every key and value of the
|
||||
INTENT.md frontmatter and of layer.yaml is walked, so a versioned `standard:` or
|
||||
(GH-DEC-2026-017 §5, amendment A12 r3 / GH-DEC-2026-021), and its return is
|
||||
rejected. The estate reference detector walks every key and value of the
|
||||
INTENT.md frontmatter and of layer.yaml, so a versioned `standard:` or
|
||||
`companion:` path and a `companion_version` are caught as well as a
|
||||
`standard_version`. Comments and `schema_version` are not reached. Stance maps
|
||||
and evidence classifications (pep-stance.yaml, evidence-classification.yaml)
|
||||
|
|
@ -60,29 +60,51 @@ DECISION_SURFACE = re.compile(
|
|||
LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
|
||||
EXPECTED_LAYER = "engine"
|
||||
|
||||
# The standard text this checker was built and validated against, printed on
|
||||
# every run (GH-DEC-2026-020 §4, A12 r2). v0.7 is the accepted text in force;
|
||||
# the v0.8 §11 amendments it already applies are named alongside. Bump this
|
||||
# when the checker is re-validated against a newer accepted text.
|
||||
VALIDATED_AGAINST = "net-kingdom/canon/standards/security-layer-model_v0.7.md"
|
||||
AMENDMENTS_APPLIED = "v0.8 A9, A11, A12 r2 (GH-DEC-2026-017, GH-DEC-2026-020)"
|
||||
# The accepted text and rulings enforced by this run (GH-DEC-2026-021 §2).
|
||||
# Update together with the reference detector when the accepted text changes.
|
||||
VALIDATED_AGAINST = (
|
||||
"net-kingdom/canon/standards/security-layer-model_v0.7.md (net-kingdom@66dc491) "
|
||||
"as amended by GH-DEC-2026-017, GH-DEC-2026-020 and GH-DEC-2026-021 "
|
||||
"(A9-A13, A12 r3; gate-house@39d9287)"
|
||||
)
|
||||
SCOPE = (
|
||||
"declaration = INTENT.md frontmatter + layer.yaml (every key and value); "
|
||||
"source = src/secrets_engine/**/*.py; "
|
||||
"not reached by A12: pep-stance.yaml, evidence-classification.yaml"
|
||||
)
|
||||
|
||||
# A12 r2: a version of the standard or its companion, anywhere in the
|
||||
# declaration. `schema_version` is the declaration file's own schema and is
|
||||
# not reached.
|
||||
VERSION_KEY = re.compile(r"version", re.IGNORECASE)
|
||||
UNREACHED_KEYS = {"schema_version"}
|
||||
VERSIONED_REF = re.compile(
|
||||
r"(?i)(security-layer-model|security-companion|layer-model|companion)"
|
||||
r"[^\s]*?(?:[_@-]v?\d+(?:\.\d+)*|\bv\d+(?:\.\d+)*)"
|
||||
)
|
||||
STANDARD_KEYS = {"standard", "companion", "framework"}
|
||||
BARE_VERSION = re.compile(r"(?i)(?:^|[_@\s-])v?\d+\.\d+(?:\.\d+)*\b")
|
||||
# Estate reference detector, GH-DEC-2026-021 §3.
|
||||
VERSION_KEY = re.compile(r"(standard|companion).*version|version.*(standard|companion)", re.I)
|
||||
VERSION_IN_VALUE = re.compile(r"[_\-.]v\d+(\.\d+)*(\.md)?\b|@v?\d+\.\d+", re.I)
|
||||
NOT_REACHED_KEYS = {"schema_version"}
|
||||
IDENTITY_KEYS = {"standard", "companion"}
|
||||
IDENTITY_VERSION = re.compile(r"\bv?\d+\.\d+", re.I)
|
||||
|
||||
|
||||
def find_version_pins(node, where: str = "", identity: bool = False) -> list[str]:
|
||||
"""Every place in a parsed declaration that carries a standard/companion version.
|
||||
|
||||
Walks every key and value (comments are gone after parsing, which is the
|
||||
A12 r2 exclusion). Returns human-readable locations; empty means clean.
|
||||
"""
|
||||
pins: list[str] = []
|
||||
if isinstance(node, dict):
|
||||
for k, v in node.items():
|
||||
here = f"{where}.{k}" if where else str(k)
|
||||
if str(k) in NOT_REACHED_KEYS:
|
||||
continue
|
||||
if VERSION_KEY.search(str(k)):
|
||||
pins.append(f"{here} (key names a standard/companion version)")
|
||||
continue
|
||||
pins.extend(find_version_pins(v, here, str(k).lower() in IDENTITY_KEYS))
|
||||
elif isinstance(node, list):
|
||||
for i, v in enumerate(node):
|
||||
pins.extend(find_version_pins(v, f"{where}[{i}]", identity))
|
||||
elif isinstance(node, str) and VERSION_IN_VALUE.search(node):
|
||||
pins.append(f"{where} = {node!r} (value carries a version)")
|
||||
elif isinstance(node, str) and identity and IDENTITY_VERSION.search(node):
|
||||
pins.append(f"{where} = {node!r} (identity-bearing value carries a version)")
|
||||
return pins
|
||||
|
||||
|
||||
def _fold(value: object) -> str:
|
||||
|
|
@ -90,37 +112,13 @@ def _fold(value: object) -> str:
|
|||
return str(value).strip().encode("ascii", "ignore").decode().lower()
|
||||
|
||||
|
||||
def _version_hits(data: object, path: str = "") -> list[str]:
|
||||
"""Every place a standard or companion version appears in a declaration."""
|
||||
hits: list[str] = []
|
||||
if isinstance(data, dict):
|
||||
for key, value in data.items():
|
||||
here = f"{path}.{key}" if path else str(key)
|
||||
if str(key) in UNREACHED_KEYS:
|
||||
continue
|
||||
if VERSION_KEY.search(str(key)):
|
||||
hits.append(f"key {here!r}")
|
||||
continue
|
||||
if isinstance(value, str) and str(key).lower() in STANDARD_KEYS:
|
||||
if BARE_VERSION.search(value):
|
||||
hits.append(f"{here}: {value!r}")
|
||||
continue
|
||||
hits.extend(_version_hits(value, here))
|
||||
elif isinstance(data, list):
|
||||
for n, item in enumerate(data):
|
||||
hits.extend(_version_hits(item, f"{path}[{n}]"))
|
||||
elif isinstance(data, str) and VERSIONED_REF.search(data):
|
||||
hits.append(f"{path}: {data!r}")
|
||||
return hits
|
||||
|
||||
|
||||
def _no_standard_version(where: str, data: dict) -> None:
|
||||
hits = _version_hits(data)
|
||||
hits = find_version_pins(data)
|
||||
if hits:
|
||||
print(
|
||||
f"MALFORMED: {where} carries a standard or companion version at "
|
||||
f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any "
|
||||
"key or value (§11 as amended by A12 r2, GH-DEC-2026-020 §1-§2)"
|
||||
"key or value (§11 as amended by A12 r3, GH-DEC-2026-021 §1-§3)"
|
||||
)
|
||||
raise SystemExit(2)
|
||||
|
||||
|
|
@ -231,7 +229,7 @@ def main() -> int:
|
|||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--report", action="store_true")
|
||||
args = ap.parse_args()
|
||||
print(f"validated against: {VALIDATED_AGAINST} [{AMENDMENTS_APPLIED}]")
|
||||
print(f"validated against: {VALIDATED_AGAINST}")
|
||||
print(f"scope: {SCOPE}")
|
||||
|
||||
front = intent_frontmatter()
|
||||
|
|
|
|||
|
|
@ -102,8 +102,9 @@ def test_binding_changed_after_approval_refuses_before_fetch(bound, monkeypatch)
|
|||
exec_delivery.exec_with_secret(object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"], expected_owner_digest=expected)
|
||||
|
||||
|
||||
def test_pending_real_catalog_refuses_before_approval_and_backend(tmp_path, monkeypatch):
|
||||
def test_pending_owner_refuses_before_approval_and_backend(tmp_path, monkeypatch):
|
||||
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
|
||||
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
|
||||
for name in ["_require_lane_approval", "_open_backend"]:
|
||||
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
|
||||
|
|
@ -160,8 +161,35 @@ def test_invalid_binding_is_not_a_catalog_fallback(bound, change):
|
|||
def test_pending_owner_never_advertises_ready(tmp_path, monkeypatch):
|
||||
from secrets_engine import routing
|
||||
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
|
||||
monkeypatch.setattr(routing, "resolve_decision", lambda **k: SimpleNamespace(status="approved", review_url="", is_approved=lambda: True))
|
||||
client = SimpleNamespace(is_reachable=lambda: True, read_policy=lambda p: "policy", approle_exists=lambda r: True, kv_fields_present=lambda *a: {"ANTHROPIC_API_KEY": True})
|
||||
result = routing.route_lane(entry, hub_url="", repo_root=tmp_path, client=client)
|
||||
assert not result.ready and "exec owner" in result.missing
|
||||
assert "<command" not in result.next_command
|
||||
|
||||
|
||||
def test_configured_glas_catalog_refuses_arbitrary_child_before_gate(tmp_path, monkeypatch):
|
||||
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||
assert entry.delivery_config["exec_owner"]["status"] == "configured"
|
||||
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
|
||||
for name in ["_require_lane_approval", "_open_backend"]:
|
||||
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
|
||||
with pytest.raises(DeliveryError, match="catalog-bound"):
|
||||
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(field=None, catalog=entry.id, command=["/bin/echo"], mode="exec-env"))
|
||||
|
||||
|
||||
def test_configured_glas_companion_matches_worker_and_pins_spend_policy():
|
||||
from secrets_engine.exec_owner import resolve_companions
|
||||
root = Path(__file__).resolve().parents[1] / "catalog"
|
||||
entry = load_entry(root / "glas-claude-agent-dev-anthropic.yaml")
|
||||
binding = entry.delivery_config["exec_owner"]
|
||||
companions = resolve_companions(entry, lambda cid: load_entry(root / (cid + ".yaml")))
|
||||
assert [(lane.id, field, env) for lane, field, env in companions] == [
|
||||
("activity-core-metered-worker-token", "token", "ACTIVITY_CORE_WORKER_TOKEN")
|
||||
]
|
||||
assert binding["environment"]["AGENT_HARNESS_WORKER_ID"] == "rein-aharness-metered@railiance01"
|
||||
assert binding["environment"]["AGENT_HARNESS_OPS_LABELS"] == "hfact-metered"
|
||||
assert binding["files"][binding["environment"]["AGENT_HARNESS_SPEND_POLICY"]]["private"] is True
|
||||
request = build_action_request(entry, "exec", subject_id="agent:fixture", subject_type="Agent", purpose="owner-proof", fields=entry.fields)
|
||||
assert request["context"]["exec_owner_sha256"] == owner_digest(entry)
|
||||
|
|
|
|||
|
|
@ -164,7 +164,8 @@ def test_real_exec_handler_rejects_undeclared_claim_before_consume_backend_child
|
|||
assert [r["result"] for r in records] == ["attempt", "failed-DecisionError"]
|
||||
|
||||
|
||||
def test_factory_catalog_declares_human_control_and_keeps_owner_pending():
|
||||
def test_configured_factory_catalog_still_requires_human_control():
|
||||
entry = load_entry(Path(__file__).resolve().parents[1]/"catalog/glas-claude-agent-dev-anthropic.yaml")
|
||||
assert entry.approval["human_control"] is True
|
||||
assert entry.delivery_config["exec_owner"]["status"] == "pending"
|
||||
assert entry.delivery_config["exec_owner"]["status"] == "configured"
|
||||
assert not entry.approval.get("authorization_id")
|
||||
|
|
|
|||
|
|
@ -190,6 +190,27 @@ def test_schema_version_is_not_reached(tmp_path, monkeypatch):
|
|||
assert _run_with(tmp_path, monkeypatch, {}, {"schema_version": "0.2"}) == 0
|
||||
|
||||
|
||||
@pytest.mark.parametrize("patch", [
|
||||
{"intent_version": "0.1.0"},
|
||||
{"rationale": "The v0.5 scope rule is historical provenance."},
|
||||
{"framework": "Historical v0.7 reference; standard identity is separate."},
|
||||
])
|
||||
def test_reference_detector_allows_own_versions_and_prose(tmp_path, monkeypatch, patch):
|
||||
assert _run_with(tmp_path, monkeypatch, patch, {}) == 0
|
||||
|
||||
|
||||
@pytest.mark.parametrize("patch", [
|
||||
{"standard_version_reviewed": "0.7"},
|
||||
{"version_of_companion": "0.2"},
|
||||
{"standard": "security-layer-model v0.7"},
|
||||
{"companion": ["security companion 0.2"]},
|
||||
{"references": [{"path": "unrelated-document-v1.2.md"}]},
|
||||
{"references": ["security-layer-model@0.7"]},
|
||||
])
|
||||
def test_reference_detector_rejects_nested_and_identity_pins(tmp_path, monkeypatch, patch):
|
||||
assert _run_with(tmp_path, monkeypatch, {}, patch) == 2
|
||||
|
||||
|
||||
def test_stance_and_classification_versions_are_not_reached():
|
||||
"""GH-DEC-2026-020 §3: stance maps and classifications keep their version,
|
||||
and the checker never applies A12 to them."""
|
||||
|
|
@ -198,7 +219,7 @@ def test_stance_and_classification_versions_are_not_reached():
|
|||
for path in (STANCE, CLASSIFICATION):
|
||||
data = yaml.safe_load(path.read_text(encoding="utf-8"))
|
||||
# Each carries a version A12 would reject if it were applied there...
|
||||
assert checker._version_hits(data), f"{path.name} keeps its standard_version"
|
||||
assert checker.find_version_pins(data), f"{path.name} keeps its standard_version"
|
||||
# ...and the real-tree run still passes: A12 is not applied to them.
|
||||
result = subprocess.run(
|
||||
[sys.executable, str(SCRIPT)], cwd=ROOT, capture_output=True, text=True, check=False
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
|||
owner: codex
|
||||
topic_slug: custodian
|
||||
created: "2026-08-21"
|
||||
updated: "2026-09-06"
|
||||
updated: "2026-09-27"
|
||||
state_hub_workstream_id: "31f7f8ea-7f73-516c-8877-f03a13f1db82"
|
||||
---
|
||||
|
||||
|
|
@ -195,6 +195,7 @@ Acceptance:
|
|||
```task
|
||||
id: SECRETS-WP-0006-T05
|
||||
status: wait
|
||||
blocking_reason: "OpenRouter key-check native acceptance is recorded in SECRETS-WP-0010-T03. Other lanes still need exact approvals, scoped attended apply and per-lane positive/negative/health/revocation evidence."
|
||||
priority: high
|
||||
state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542"
|
||||
```
|
||||
|
|
@ -256,6 +257,7 @@ Acceptance per lane:
|
|||
```task
|
||||
id: SECRETS-WP-0006-T06
|
||||
status: wait
|
||||
blocking_reason: "Needs owner-agreed routing/proxy retirement for each verified lane and custody disposition of the legacy npm pointer; a single approved OpenRouter key-check does not authorize broader routing cutover."
|
||||
priority: medium
|
||||
state_hub_task_id: "1431edae-5791-5892-8c4b-829419b537d2"
|
||||
```
|
||||
|
|
@ -424,3 +426,13 @@ for a fourth location.
|
|||
|
||||
`SECRETS-WP-0006-T06` stays `wait`: this answer unblocks the question, not the
|
||||
lane change, which needs custody's step 1 and its own approval.
|
||||
|
||||
|
||||
### Existing-work review — 2026-09-27
|
||||
|
||||
The September 16 native OpenRouter key-check receipt supersedes the older
|
||||
serving/ESO-health wait for that exact recipient. SECRETS-WP-0007-T04 and
|
||||
SECRETS-WP-0008-T02 are now closed against that real evidence and current
|
||||
regression coverage. T05 remains open for the other lanes; T06 retains
|
||||
per-lane routing/proxy retirement and the npm custody discrepancy. No broader
|
||||
recipient, proxy retirement, or production action is inferred from that receipt.
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
|||
owner: codex
|
||||
topic_slug: custodian
|
||||
created: "2026-08-23"
|
||||
updated: "2026-09-06"
|
||||
updated: "2026-09-27"
|
||||
state_hub_workstream_id: "68a39be1-bd9c-5133-ad64-e7bca892aaf3"
|
||||
---
|
||||
|
||||
|
|
@ -213,11 +213,15 @@ Acceptance:
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0007-T04
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "4b58edec-c705-55e5-9ece-362e1ff13079"
|
||||
```
|
||||
|
||||
Completed 2026-09-27 by reconciling the implemented shared approval guard with the
|
||||
2026-09-16 native receipt. See the closure note below; the serving-path waits
|
||||
in the dated history are superseded. Native lane cutover remains T07.
|
||||
|
||||
Wait 2026-08-29. The consumer validator and production fail-closed gate are
|
||||
shipped. What remains is not local engine work: State Hub / `access-engine`
|
||||
must serve the durable ActionAuthorization object. Paired with
|
||||
|
|
@ -707,6 +711,7 @@ Acceptance:
|
|||
```task
|
||||
id: SECRETS-WP-0007-T07
|
||||
status: wait
|
||||
blocking_reason: "Engine approval hardening is complete. Remaining per-lane cutover includes native routing/proxy retirement with ops-warden under SECRETS-WP-0006-T05/T06; the exact OpenRouter key-check receipt does not establish broader recipient readiness."
|
||||
priority: high
|
||||
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
|
||||
```
|
||||
|
|
@ -787,3 +792,25 @@ routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readines
|
|||
Do not reuse the consumed approvals or treat the temporary key-check overlay as
|
||||
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
|
||||
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
|
||||
|
||||
|
||||
### T04 completed after evidence reconciliation — 2026-09-27
|
||||
|
||||
The original serving-path wait is superseded by the native 2026-09-16 receipt
|
||||
`docs/evidence/2026-09-16-t03-completion.json`, not by synthetic tests or Hub
|
||||
status. It records separate human-controlled apply, verify and exec approvals,
|
||||
three distinct current PDP decisions/request digests, successful CAS consumes,
|
||||
and the resulting native OpenBao operations. The claim/PDP/consume join is the
|
||||
accepted path; the earlier proposed ActionAuthorization is not a dependency.
|
||||
|
||||
Current regression coverage exercises wrong fields/actions/tenant/digest,
|
||||
superseded or expired claims, changed catalog/owner bindings, denied or missing
|
||||
PDP responses, consume conflicts/unavailability, declared human control and
|
||||
production fixture refusal. Every live privileged handler still uses the shared
|
||||
approval gate before backend access. The recorded approvals are consumed and
|
||||
expired; they are historical completion evidence, never reusable grants.
|
||||
|
||||
T04 is done. T07 stays wait because its per-lane acceptance includes routing and
|
||||
proxy retirement, and the receipt covers only the exact OpenRouter key-check
|
||||
recipient. Other lanes and cross-owner cutover remain SECRETS-WP-0006-T05/T06;
|
||||
this workplan is not finished merely because the engine gate is complete.
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
|||
owner: grok
|
||||
topic_slug: custodian
|
||||
created: "2026-08-29"
|
||||
updated: "2026-09-21"
|
||||
updated: "2026-09-27"
|
||||
state_hub_workstream_id: "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0"
|
||||
---
|
||||
|
||||
|
|
@ -90,11 +90,15 @@ Acceptance:
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0008-T02
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "3eb9cff8-1441-5437-9e92-a2b655c82d04"
|
||||
```
|
||||
|
||||
Completed 2026-09-27: the 2026-09-16 native apply/verify/exec receipt supplies
|
||||
the live PDP/claim/consume return awaited below. The dated serving-path waits
|
||||
are historical. Service JWT adoption remains T06.
|
||||
|
||||
Progress 2026-09-02. Gate House notice `632bdad9` (`GH-DEC-2026-003`): this
|
||||
engine is the PEP for FLEX-WP-0017-T05 / OpenBao writes. The shared consume
|
||||
function now lives in `src/secrets_engine/approval_consume.py` and every live
|
||||
|
|
@ -327,6 +331,7 @@ Acceptance:
|
|||
```task
|
||||
id: SECRETS-WP-0008-T06
|
||||
status: wait
|
||||
blocking_reason: "RPF-WP-0035-T02 still awaits exact service claims/tenant, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
|
||||
priority: medium
|
||||
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
|
||||
```
|
||||
|
|
@ -486,3 +491,26 @@ gate-house (message `4220413a`); we follow that answer rather than choose.
|
|||
- `layer.yaml` / `pep-stance.yaml` / INTENT frontmatter stay in one voice.
|
||||
- No raw secret values in Git, State Hub, chat, prompts, workplans, evidence,
|
||||
or argv.
|
||||
|
||||
|
||||
## Decision consumer closure and declaration ruling applied — 2026-09-27
|
||||
|
||||
T02 is done. `docs/evidence/2026-09-16-t03-completion.json` provides the native
|
||||
return awaited in the September 9 note: separately approved apply/verify/exec
|
||||
requests received current PDP allows and successful CAS consumption before real
|
||||
OpenBao work. The shared guard records decision IDs and retains refusal before
|
||||
backend access for invalid/missing/replayed decisions. SECRETS-WP-0007-T04 now
|
||||
records the same completed contract; no native activation grant is inferred.
|
||||
|
||||
The open conformance-record question is also resolved. GH-DEC-2026-020 §4 says
|
||||
a versioned/scoped re-runnable checker is sufficient; each declaring repository
|
||||
need not emit a durable record. GH-DEC-2026-021 §2/§3 names the accepted v0.7
|
||||
text plus applicable decisions and the ops-warden reference detector. The
|
||||
checker now copies that detector, permits own-document versions/prose citations,
|
||||
refuses nested/identity-bearing version pins and names the accepted text and
|
||||
rulings on every run, including PASS. Declaration spellings are unchanged.
|
||||
|
||||
T06 remains wait: railiance-platform's RPF-WP-0035-T02 still records an
|
||||
unprovisioned, login-only JWT role, pending exact service claims/tenant and
|
||||
custody/attended admission. The existing env-auth native receipt cannot prove
|
||||
steady-state service JWT login. This is the only remaining task in this workplan.
|
||||
|
|
|
|||
|
|
@ -49,8 +49,8 @@ synthetic exec-env transport proof passed; no real secret was read.
|
|||
```task
|
||||
id: SECRETS-WP-0009-T03
|
||||
status: wait
|
||||
blocking_reason: "Configured owner and worker companion passed backend-free recipient/pin checks on 2026-09-27 (SECRETS-WP-0011 complete). Remaining: exact per-action/per-lane approvals, unrelated negative identity, scoped attended apply/verify, bounded real owner delivery and revocation. Recheck pins and spend validity at execution."
|
||||
priority: high
|
||||
blocking_reason: "Shared native chain proved by SECRETS-WP-0010-T03. Metered owner provisioned and binding drafted (2026-09-23); Activity Core reports identity live (2026-09-24). Remaining: current recipient/pin admission, unrelated negative identity, configured exec_owner, exact per-action/per-lane approvals and attended apply/verify/exec/revoke."
|
||||
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
|
||||
```
|
||||
|
||||
|
|
@ -503,3 +503,19 @@ native apply, positive/negative verification, exec and session revocation.
|
|||
The production catalog remains pending. The companion-only delivery guards
|
||||
added under SECRETS-WP-0011-T05 must be included in the host checkout used for
|
||||
activation. No credential read, queue claim or paid run occurred in this review.
|
||||
|
||||
|
||||
### 2026-09-27 configured owner and companion landed
|
||||
|
||||
SECRETS-WP-0011 is finished at its catalog/implementation boundary. The binding
|
||||
formerly held in `docs/drafts/glas-exec-owner-configured.yaml` is now configured
|
||||
in the active Glas catalog, with an added exact private spend-policy file pin.
|
||||
The installed owner's backend-free check and engine path/pin validation passed
|
||||
on railiance01. Receipt: `docs/evidence/2026-09-27-companion-catalog-readiness.json`.
|
||||
The original pending-recipient configuration is superseded; current code still
|
||||
refuses any substituted child and requires fresh approvals and delivery state.
|
||||
|
||||
T03 retains all native activation and delivery acceptance. Revalidate the owner
|
||||
and spend envelope in the attended execution window, use approvals bound to the
|
||||
new owner digest and each lane, apply/verify both native lanes, and prove actual
|
||||
bounded owner delivery and cleanup. Configuration does not authorize those actions.
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Multi-lane exec-owner delivery"
|
||||
domain: infotech
|
||||
repo: secrets-engine
|
||||
status: active
|
||||
status: finished
|
||||
flavor: implementation
|
||||
owner: claude-code
|
||||
topic_slug: netkingdom
|
||||
|
|
@ -91,12 +91,15 @@ a throwaway OpenBao dev server.
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0011-T04
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
blocking_reason: "Activity Core reports ACTIVITY-WP-0039 finished and metered identity authentication proved (2026-09-24). Remaining: admit the configured Glas owner, obtain exact per-lane approvals, and perform attended native apply/verify/delivery under SECRETS-WP-0009-T03."
|
||||
state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d"
|
||||
```
|
||||
|
||||
Completed 2026-09-27: custody handoff received, companion cataloged and wired
|
||||
into the configured Glas owner after fresh backend-free host verification.
|
||||
Native activation remains in existing SECRETS-WP-0009-T03, as detailed below.
|
||||
|
||||
Request activity-core to move the worker token into OpenBao custody, synced to
|
||||
`actcore-runtime-secret` by their existing `openbao-activity-core` store. Then
|
||||
catalog a read lane for the metered owner and add it as the Glas lane's
|
||||
|
|
@ -172,3 +175,27 @@ T04 remains wait for native lane activation with SECRETS-WP-0009-T03: current
|
|||
owner admission/pins, exact per-lane approvals and attended apply/verify/exec.
|
||||
The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching
|
||||
the handoff. No production policy, role, catalog binding or credential changed.
|
||||
|
||||
|
||||
## Catalog task and workplan completed — 2026-09-27
|
||||
|
||||
T04's stated work is custody coordination, the worker-token catalog entry and
|
||||
adding that entry as the Glas owner's companion. All three are now complete.
|
||||
Activity Core's 2026-09-24 handoff supplies the custody/identity return. The
|
||||
configured binding is now in `catalog/glas-claude-agent-dev-anthropic.yaml`,
|
||||
including the worker identity/label and a private spend-policy file pin.
|
||||
|
||||
A fresh backend-free check on railiance01 verified the installed owner with
|
||||
`metered-once --check --no-hub` (dispatch disabled), and this checkout's exact
|
||||
path/ownership/mode/hash checks passed for the executable, owner configuration,
|
||||
spend policy and private working directory. Receipt:
|
||||
`docs/evidence/2026-09-27-companion-catalog-readiness.json`.
|
||||
The owner digest is `46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b`.
|
||||
|
||||
The previous wait reason conflated catalog completion with native activation.
|
||||
That activation was already owned by SECRETS-WP-0009-T03 and stays there: exact
|
||||
per-lane action approvals, scoped attended apply, positive/negative verification,
|
||||
actual bounded delivery and session revocation. No new task is needed. This
|
||||
workplan's completion claims the configured multi-lane contract, its tests and
|
||||
catalog wiring, not production delivery. No credential was requested or read,
|
||||
no queue row was claimed, and no provider request was made.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue