58 lines
3.6 KiB
Markdown
58 lines
3.6 KiB
Markdown
# Factory continuation: replay acceptance and operating contract
|
|
|
|
2026-09-09. Programme: HFACT-WP-0001 in prj-helixforge-factory.
|
|
[Machine-readable return](2026-09-09-helixforge-replay-and-operating-contract.json).
|
|
|
|
The Secrets Engine consumer now implements FLEX-DEC-2026-012. It binds an allow
|
|
to the exact submitted request, including its approval claim, compares the two
|
|
evaluator-origin approval digests, rechecks freshness after Check, and consumes
|
|
the evaluated request digest with its decision id before protected effects.
|
|
334 regression tests and 13 real local KeyCape/Approval Engine/Flex Auth checks
|
|
passed. Registry override, changed submission, wrong action, real dual-control
|
|
policy, consumed approvals and CAS retry/conflict are covered. The former PDP
|
|
double limitation is resolved for component conformance; no live native delivery
|
|
or governed factory run is claimed. The historical live fixture remains intact
|
|
and refuses because it lacks the new submitted binding.
|
|
|
|
Implementation: Secrets Engine `ee4e901`; published final source and exact
|
|
Railiance primary reconciliation are in the machine-readable return.
|
|
SECRETS-WP-0008-T02 is wait for current deployed PDP/approval-path adoption.
|
|
SECRETS-WP-0009-T03 keeps native delivery; RPF-WP-0035-T06, AUDIT-WP-0009-T09
|
|
and APPROVAL-WP-0002 keep client-side/audit/service admission. Completed verifier
|
|
CCRs were neither reopened nor treated as broader read authority.
|
|
|
|
The [bounded operating packet](../../../prj-helixforge-factory/operations/bounded-operating-contract.md)
|
|
brings G0 preparation forward. Its proposed identity/profile/host, accountable
|
|
owners, one-commit v1 path grant, useful demand and independent oracle are
|
|
explicit. The actual rein parser accepts the grant and rejects publish=true.
|
|
The proposed demand extends reuse-surface with typed hosted-discovery refusals
|
|
for factory intake and vergabe-teilnahme's delivery checks. Product selection
|
|
remains reuse-surface first, vergabe-teilnahme as customer service/UI, Railiance
|
|
Fabric for later placement utility. The packet is a blocked draft, not an
|
|
execution or spending grant.
|
|
|
|
Source review identified two precise returns before admission:
|
|
|
|
- HFACT-WP-0001-T01: the Claude adapter's before/after token bookkeeping does
|
|
not establish a hard monetary cap. Prove an actual provider/runtime spend
|
|
bound, including retries and persistent daily/total reservations, before
|
|
paid execution and final operating acceptance.
|
|
- HFACT-WP-0001-T05: the outer worker already checks grants and writes durable
|
|
metrics. The selected sandbox mirrors the checkout; its commit must be
|
|
preserved and imported under the original baseline/lease/transaction before
|
|
teardown. Returning a commit identifier cannot satisfy host acceptance. Keep
|
|
existing checks/outbox and prove this actual artifact join with the owners.
|
|
|
|
These findings refine the original integration plan. The next increment should
|
|
address those two mechanisms alongside existing credential/audit/service
|
|
admission, then accept the exact operating/profile/placement tuple and execute
|
|
one real queue run. Broad historical cleanup and extra factory frameworks do
|
|
not become new prerequisites.
|
|
|
|
Efficiency improved by removing an unsatisfiable consumer contract, testing
|
|
three actual components together, and identifying runtime gaps before an
|
|
attended model/deployment attempt. No elapsed-time savings or production
|
|
throughput are inferred. The factory ledger still contains zero governed
|
|
attempts; all G0-G5 acceptance gates remain open and the fourteen-day observation
|
|
window has not begun. Source-backed task fields are verified after publication;
|
|
any repaired projection omissions remain an unresolved Repo Manager defect.
|