4 KiB
Factory continuation: replay acceptance and operating contract
2026-09-09. Programme: HFACT-WP-0001 in prj-helixforge-factory. Machine-readable return.
The Secrets Engine consumer now implements FLEX-DEC-2026-012. It binds an allow to the exact submitted request, including its approval claim, compares the two evaluator-origin approval digests, rechecks freshness after Check, and consumes the evaluated request digest with its decision id before protected effects. 334 regression tests and 13 real local KeyCape/Approval Engine/Flex Auth checks passed. Registry override, changed submission, wrong action, real dual-control policy, consumed approvals and CAS retry/conflict are covered. The former PDP double limitation is resolved for component conformance; no live native delivery or governed factory run is claimed. The historical live fixture remains intact and refuses because it lacks the new submitted binding.
Implementation: Secrets Engine ee4e901; published final source and exact
Railiance primary reconciliation are in the machine-readable return.
SECRETS-WP-0008-T02 is wait for current deployed PDP/approval-path adoption.
SECRETS-WP-0009-T03 keeps native delivery; RPF-WP-0035-T06, AUDIT-WP-0009-T09
and APPROVAL-WP-0002 keep client-side/audit/service admission. Completed verifier
CCRs were neither reopened nor treated as broader read authority.
The bounded operating packet brings G0 preparation forward. Its proposed identity/profile/host, accountable owners, one-commit v1 path grant, useful demand and independent oracle are explicit. The actual rein parser accepts the grant and rejects publish=true. The proposed demand extends reuse-surface with typed hosted-discovery refusals for factory intake and vergabe-teilnahme's delivery checks. Product selection remains reuse-surface first, vergabe-teilnahme as customer service/UI, Railiance Fabric for later placement utility. The packet is a blocked draft, not an execution or spending grant.
Source review identified two precise returns before admission:
- HFACT-WP-0001-T01: the Claude adapter's before/after token bookkeeping does not establish a hard monetary cap. Prove an actual provider/runtime spend bound, including retries and persistent daily/total reservations, before paid execution and final operating acceptance.
- HFACT-WP-0001-T05: the outer worker already checks grants and writes durable metrics. The selected sandbox mirrors the checkout; its commit must be preserved and imported under the original baseline/lease/transaction before teardown. Returning a commit identifier cannot satisfy host acceptance. Keep existing checks/outbox and prove this actual artifact join with the owners.
These findings refine the original integration plan. The next increment should address those two mechanisms alongside existing credential/audit/service admission, then accept the exact operating/profile/placement tuple and execute one real queue run. Broad historical cleanup and extra factory frameworks do not become new prerequisites.
Efficiency improved by removing an unsatisfiable consumer contract, testing three actual components together, and identifying runtime gaps before an attended model/deployment attempt. No elapsed-time savings or production throughput are inferred. The factory ledger still contains zero governed attempts; all G0-G5 acceptance gates remain open and the fourteen-day observation window has not begun. Source-backed task fields are verified after publication; any repaired projection omissions remain an unresolved Repo Manager defect.
Custodian publication exception: its full Repo Manager projection refuses the pre-existing CUST-WP-0000b identity and repeated unqualified T01–T10 task IDs. Existing CUST-IN-0017 owns these legacy identity failures. The assessment is committed/published through Git; no Custodian primary projection is claimed. Secrets Engine and the factory project both have exact primary receipts.