diff --git a/docs/assessments/2026-09-09-helixforge-replay-and-operating-contract.json b/docs/assessments/2026-09-09-helixforge-replay-and-operating-contract.json new file mode 100644 index 0000000..b7758e0 --- /dev/null +++ b/docs/assessments/2026-09-09-helixforge-replay-and-operating-contract.json @@ -0,0 +1,298 @@ +{ + "date": "2026-09-09", + "repositories": { + "secrets-engine": { + "commit": "9eb07fd8fcae56e38a533c85fcb6e3a5750b646f", + "clean": true, + "origin_matches": true, + "primary": { + "schema": "state-hub.repository-projection-reconcile.v1", + "instance_role": "primary", + "instance_label": "railiance01", + "expected_commit": "9eb07fd8fcae56e38a533c85fcb6e3a5750b646f", + "derived_commit": "9eb07fd8fcae56e38a533c85fcb6e3a5750b646f", + "outcome": { + "schema": "state-hub.projection-reset.v1", + "repo_slug": "secrets-engine", + "commit": "9eb07fd8fcae56e38a533c85fcb6e3a5750b646f", + "status": "applied", + "counts": { + "created": 0, + "updated": 11, + "retired": 0, + "refused": 0, + "released": 0, + "created_tasks": 0, + "updated_tasks": 2, + "cancelled_tasks": 0 + }, + "created": [], + "updated": [ + "SECRETS-WP-0001", + "SECRETS-WP-0002", + "SECRETS-WP-0003", + "SECRETS-WP-0004", + "SECRETS-WP-0005", + "SECRETS-WP-0006", + "SECRETS-WP-0007", + "SECRETS-WP-0008", + "SECRETS-WP-0009", + "SECRETS-WP-ADHOC-2026-08-21", + "SECRETS-WP-ADHOC-2026-08-23" + ], + "retired": [], + "released": [], + "created_tasks": [], + "updated_tasks": [ + "SECRETS-WP-0008-T02", + "SECRETS-WP-0009-T03" + ], + "cancelled_tasks": [], + "refused": [], + "notes": [] + } + } + }, + "prj-helixforge-factory": { + "commit": "cd6e2f28beb5233a2acaa054648c5a2304a8c74a", + "clean": true, + "origin_matches": true, + "primary": { + "schema": "state-hub.repository-projection-reconcile.v1", + "instance_role": "primary", + "instance_label": "railiance01", + "expected_commit": "cd6e2f28beb5233a2acaa054648c5a2304a8c74a", + "derived_commit": "cd6e2f28beb5233a2acaa054648c5a2304a8c74a", + "outcome": { + "schema": "state-hub.projection-reset.v1", + "repo_slug": "prj-helixforge-factory", + "commit": "cd6e2f28beb5233a2acaa054648c5a2304a8c74a", + "status": "applied", + "counts": { + "created": 0, + "updated": 1, + "retired": 0, + "refused": 0, + "released": 0, + "created_tasks": 0, + "updated_tasks": 3, + "cancelled_tasks": 0 + }, + "created": [], + "updated": [ + "HFACT-WP-0001" + ], + "retired": [], + "released": [], + "created_tasks": [], + "updated_tasks": [ + "HFACT-WP-0001-T01", + "HFACT-WP-0001-T03", + "HFACT-WP-0001-T05" + ], + "cancelled_tasks": [], + "refused": [], + "notes": [] + } + } + } + }, + "regression_tests_passed": 334, + "component_receipt": { + "schema_version": 1, + "target": "disposable local processes; synthetic credentials", + "started_at": "2026-09-09T06:38:34.485308+00:00", + "keycape_image": "forgejo.coulomb.social/coulomb/key-cape@sha256:7ff54c54e63ee172ae9e6e7fd2da96e427352f712343d74626ee6fe0f6f82611", + "approval_engine_commit": "b46b0f26669dc83c944ee5145426bad03d5ef720", + "flex_auth_commit": "88b354377c8e26b162f1234e673072f1c06dcd89", + "keycape_contract_commit": "0f5535eed95f1223c83a28f5a0bd6fa594cecae8", + "consumer_source_sha256": { + "approval_auth.py": "6f3b033e7928e1c527bc19f5a1e01bf243540769a8646bd8cd47268da25637b5", + "approval_consume.py": "9ccc6997fd4c1c82af8cf3dd440daf7b695d6272bb302eb083b73a2fe3674345", + "approval_claim.py": "54dd469e4e3ac9472c4e21222d5a08f70723a63f01904a35922fcc0a07a41541", + "authorization.py": "75c472f30cce1c3d66be1ded1eb6dcc62684668b0da5bf83d5fcdd37e92d1935", + "config.py": "2f2f1b60664d89bbb806aed0c768378923062077740e1f96e4c359238eb06955", + "service_auth.py": "653723ef5babce2157771416d93cb15cdbb7caca3c45509c3730520c55e4515c", + "cli.py": "a789fcea59e9a03d7ef07bf3ec1baf58234058585149511333c3fb7570f5916a" + }, + "limitations": [ + "standalone Flex Auth source, not deployed pin", + "local Approval Engine source, not deployed image", + "no live custody or client-side read grant", + "no OpenBao effect or model execution" + ], + "checks": { + "operator_issued_and_approved_via_verified_jwt": true, + "wrong_action_refused_before_consume": true, + "producer_origin_join_with_carried_claim": true, + "actual_consumer_claim_check_consume": true, + "same_digest_retry_idempotent": true, + "different_digest_refused": true, + "spent_claim_refused": true, + "operator_consume_scope_denied_by_issuer": true, + "wrong_secret_refused": true, + "no_access_token_file_created": true, + "registry_override_accepts_exact_submission": true, + "same_enriched_result_different_submission_refused": true, + "real_dual_control_denial_then_claim_check_consume": true + }, + "flex_auth_binary_sha256": "c7a1f35aa2cd7cf2733272923ace7fc4b4e55171db4ef8f3d0d6629183dcf1fa", + "producer_input_sha256": { + "policy_package.md": "657fa9312c9dcabee059ec31c89ee13396fe9aa54d852edc9e6559a74bbc139a", + "registry_snapshot.json": "37fba44ec0e0fd9b1e17a05ad1b7e4f9bb6ec9e0fc0bb3133e8af2ac6f832d7c" + }, + "status": "passed", + "cleanup_complete": true, + "finished_at": "2026-09-09T06:38:44.956593+00:00" + }, + "operating_review": { + "observed_at": "2026-09-09", + "method": "read-only source review; no model or queue request", + "source_pins": { + "rein-aharness": { + "commit": "1429db5ad4c83331b6375349ffde1eb13af9575b", + "files": { + "rein_aharness/adapter.py": "5e8a6ce9767a8b9cca215ae075a72d137b2d3223d86e7de2363b8a8b47759717", + "rein_aharness/claim_loop.py": "7af7c97c28a35d252867f73f21391b06f52debc8dee0398284bee914dc8339a3", + "rein_aharness/glas_execution.py": "83786df1aab509431984932e2d739d774c68cd2b37fd93c28239cf96e122a9df", + "docs/repository-grant.md": "9e05e19d2bbf88dcfccf448838111ba50ada5fdea6947242261f734121a47b7e" + } + }, + "glas-harness": { + "commit": "44991600f377fa7b2bb380d4f4f255c33c480369", + "files": { + "src/glas_harness/contract.py": "30c7d361d132ca9ffc67f0edcd07ce21d33de634c8cc7e578c39f807708cfd2f", + "src/glas_harness/gateway.py": "bad3c2ef40a8fb1a3dcd7eaeca5dbeb937e9404be70dbbe3b374016f381a8dbe", + "src/glas_harness/reins/rein_aharness.py": "1edf0ae56ad646f032c940bda9f7af5b43b87030756dbc2134b038bf3bd4a40e", + "docs/local-profile-acceptance.md": "ff5b550c9b22950f969b7f63172ae9b3dacfecd4e14fd1791ced6516eff52d7f" + } + }, + "llm-connect": { + "commit": "00560945f81ba6ff1f5cacd9fe99c7fe756cc4b1", + "files": { + "llm_connect/adapter.py": "6a1464705a273a2af188a85fb5eb3c1bed2c94e14457578382c8f331463c7c34" + } + }, + "sand-boxer": { + "commit": "3e49a98a0e2c4a64539a5ccd674be8cd67ac9845", + "files": { + "profiles/profile.claude-agent-dev-proof.yaml": "8c4ea56b5cc524f459b4fd0e960661bc0d06ec7e06d68a7aa1795e2c17cc29ac" + } + }, + "reuse-surface": { + "commit": "fc814cd554c882536fbdef9c32bb73ffc1ba8ccc", + "files": { + "reuse_surface/cli.py": "da968735cb45dc9944c3a722234641e17cd49a6bef9aa91f40e78ddde3fb9c0e", + "reuse_surface/plan_snapshot.py": "1c020e77786d179cc2f20cb554b63051b3cb77ed31dfa06b2de76ef0bec07ae0" + } + } + }, + "findings": [ + "Rein Claude command supplies no monetary cap; token consumption occurs after execute_prompt returns. Blocking response has empty usage. Existing budget token field cannot evidence hard euro enforcement.", + "The outer profiled worker already applies repository acceptance and durable external metrics. Do not duplicate or describe those as absent.", + "The selected local sandbox mirrors the repository. Glas returns commit identifiers and destroys its sandbox; the worker validates its original target. The inspected route has no artifact import. A synthetic gateway that mutates the host cannot establish this join.", + "Inner Glas rein task omits repository_grant and uses --no-metrics. Resolve the actual ownership/export acceptance design; do not simply enable the inner grant with that flag.", + "Repository grant v1 allows only local commits, so staged artifact publication and release need existing separately authorized owners." + ], + "validation": { + "actual_rein_v1_grant_parser": "passed", + "grant_id": "dfb606dedd81ad2ef9c61f73774ec19b", + "publish_true_refused": true, + "dispatch_disabled": true, + "approval_absent": true, + "runtime_enforcement": "not yet proved", + "model_requests": 0 + } + }, + "source_hub_parity": [ + { + "task": "SECRETS-WP-0008-T02", + "source_fields_match": true, + "repaired_fields": [ + "description" + ], + "status": "wait" + }, + { + "task": "SECRETS-WP-0009-T03", + "source_fields_match": true, + "repaired_fields": [ + "description" + ], + "status": "wait" + }, + { + "task": "HFACT-WP-0001-T01", + "source_fields_match": true, + "repaired_fields": [], + "status": "progress" + }, + { + "task": "HFACT-WP-0001-T02", + "source_fields_match": true, + "repaired_fields": [], + "status": "progress" + }, + { + "task": "HFACT-WP-0001-T03", + "source_fields_match": true, + "repaired_fields": [ + "intervention_note" + ], + "status": "wait" + }, + { + "task": "HFACT-WP-0001-T04", + "source_fields_match": true, + "repaired_fields": [], + "status": "wait" + }, + { + "task": "HFACT-WP-0001-T05", + "source_fields_match": true, + "repaired_fields": [], + "status": "wait" + }, + { + "task": "HFACT-WP-0001-T06", + "source_fields_match": true, + "repaired_fields": [], + "status": "wait" + }, + { + "task": "HFACT-WP-0001-T07", + "source_fields_match": true, + "repaired_fields": [], + "status": "wait" + }, + { + "task": "HFACT-WP-0001-T08", + "source_fields_match": true, + "repaired_fields": [], + "status": "wait" + } + ], + "progress": [ + { + "id": "6bb71d5d-9037-4a2f-87ca-09dfeda62ea1", + "task_id": "3eb9cff8-1441-5437-9e92-a2b655c82d04" + }, + { + "id": "cde157c6-f02c-43fb-a927-04193846b519", + "task_id": "5cee3251-faf9-5925-8ffd-7a8bf378b0a4" + }, + { + "id": "4e30ab0a-d298-4fab-a47d-d411d749e29d", + "task_id": "2b171ebd-75f3-5ce2-85a9-98e8ab77fd19" + } + ], + "governed_factory_attempts": 0, + "new_credential_or_spending_authority": false, + "remaining": [ + "current deployed PDP contract and client-side/audit/approval/native delivery", + "hard model-spend enforcement", + "sandbox artifact import into original grant/lease transaction", + "named operating/profile/Railiance admission", + "G1-G4 live evidence and fourteen-day G5" + ] +} diff --git a/docs/assessments/2026-09-09-helixforge-replay-and-operating-contract.md b/docs/assessments/2026-09-09-helixforge-replay-and-operating-contract.md new file mode 100644 index 0000000..9d86827 --- /dev/null +++ b/docs/assessments/2026-09-09-helixforge-replay-and-operating-contract.md @@ -0,0 +1,58 @@ +# Factory continuation: replay acceptance and operating contract + +2026-09-09. Programme: HFACT-WP-0001 in prj-helixforge-factory. +[Machine-readable return](2026-09-09-helixforge-replay-and-operating-contract.json). + +The Secrets Engine consumer now implements FLEX-DEC-2026-012. It binds an allow +to the exact submitted request, including its approval claim, compares the two +evaluator-origin approval digests, rechecks freshness after Check, and consumes +the evaluated request digest with its decision id before protected effects. +334 regression tests and 13 real local KeyCape/Approval Engine/Flex Auth checks +passed. Registry override, changed submission, wrong action, real dual-control +policy, consumed approvals and CAS retry/conflict are covered. The former PDP +double limitation is resolved for component conformance; no live native delivery +or governed factory run is claimed. The historical live fixture remains intact +and refuses because it lacks the new submitted binding. + +Implementation: Secrets Engine `ee4e901`; published final source and exact +Railiance primary reconciliation are in the machine-readable return. +SECRETS-WP-0008-T02 is wait for current deployed PDP/approval-path adoption. +SECRETS-WP-0009-T03 keeps native delivery; RPF-WP-0035-T06, AUDIT-WP-0009-T09 +and APPROVAL-WP-0002 keep client-side/audit/service admission. Completed verifier +CCRs were neither reopened nor treated as broader read authority. + +The [bounded operating packet](../../../prj-helixforge-factory/operations/bounded-operating-contract.md) +brings G0 preparation forward. Its proposed identity/profile/host, accountable +owners, one-commit v1 path grant, useful demand and independent oracle are +explicit. The actual rein parser accepts the grant and rejects publish=true. +The proposed demand extends reuse-surface with typed hosted-discovery refusals +for factory intake and vergabe-teilnahme's delivery checks. Product selection +remains reuse-surface first, vergabe-teilnahme as customer service/UI, Railiance +Fabric for later placement utility. The packet is a blocked draft, not an +execution or spending grant. + +Source review identified two precise returns before admission: + +- HFACT-WP-0001-T01: the Claude adapter's before/after token bookkeeping does + not establish a hard monetary cap. Prove an actual provider/runtime spend + bound, including retries and persistent daily/total reservations, before + paid execution and final operating acceptance. +- HFACT-WP-0001-T05: the outer worker already checks grants and writes durable + metrics. The selected sandbox mirrors the checkout; its commit must be + preserved and imported under the original baseline/lease/transaction before + teardown. Returning a commit identifier cannot satisfy host acceptance. Keep + existing checks/outbox and prove this actual artifact join with the owners. + +These findings refine the original integration plan. The next increment should +address those two mechanisms alongside existing credential/audit/service +admission, then accept the exact operating/profile/placement tuple and execute +one real queue run. Broad historical cleanup and extra factory frameworks do +not become new prerequisites. + +Efficiency improved by removing an unsatisfiable consumer contract, testing +three actual components together, and identifying runtime gaps before an +attended model/deployment attempt. No elapsed-time savings or production +throughput are inferred. The factory ledger still contains zero governed +attempts; all G0-G5 acceptance gates remain open and the fourteen-day observation +window has not begun. Source-backed task fields are verified after publication; +any repaired projection omissions remain an unresolved Repo Manager defect.