Skip to content

IBKR paper gateway signs in by itself: stored paper login by pointer, rootless container owner rule in the credential checker, adopted recreate script - #769

Draft
seathatflowsinourveins wants to merge 3 commits into
mainfrom
claude/ns2604-ibkr-passwordless-20261006
Draft

seathatflowsinourveins wants to merge 3 commits into
mainfrom
claude/ns2604-ibkr-passwordless-20261006

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes, in one or two sentences: the IBKR paper gateway on NativeStack2604 now signs in by itself, by the user's decision of 2026-10-06 (about 01:50Z). The user prefers a passwordless, LLM-native and frictionless workflow and extended that to the IBKR paper login. The command center applied it on the host, and this PR brings the repository in line: the credential policy and inventory, a rootless-container owner rule in the credential checker, the secret guard's pointer list, the adopted recreate script, and a dated decision record. The user is described, not quoted.
  • Base commit: ecfa112764c664d35377dd66b8cfcb67e5a94d60 (origin/main when the branch was cut, and still main at this head)
  • Lane: lane:shared. It touches trading paths (blueprints/us-equities/runtime-2604/, the trading test tests/test_ibkr_gateway_recreate.py) and foundation paths (docs/, scripts/, adoption/, tests/), and re-registers files in the shared hot file manifests/evidence.json (last commit). The trading lane (5f) must acknowledge before merge; the items it covers are listed under "Acknowledgement requested from the trading lane". The PR stays a draft until then.
  • Owned paths touched:
    • adoption/credential-inventory.json
    • adoption/hooks/claude/SHA256SUMS
    • adoption/bootstrap.md
    • adoption/platforms/linux-wsl2-new-distro.md
    • blueprints/us-equities/runtime-2604/README.md
    • blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh (new)
    • docs/decisions/2026-10-06-ibkr-paper-passwordless-login.md (new)
    • docs/secret-storage.md
    • scripts/credential_status.py
    • scripts/hooks/secret_path_guard.py
    • tests/test_credential_run.py
    • tests/test_credential_status.py
    • tests/test_credential_tools.py
    • tests/test_ibkr_gateway_recreate.py (new)
    • tests/test_secret_path_guard.py
    • catalogs/foundation/upstream-surface-dispositions.json (five line citations follow the shifted docs/secret-storage.md lines)
    • docs/new-wsl-handbook.md
    • docs/new-wsl-handbook.json
    • evidence/artifacts/new-wsl-handbook-20261001/receipt.json (regenerated; the edited adoption page's digest)
    • manifests/evidence.json (registration only, last commit)

Commits: 80340ee3 (content), bc5064e7 (review fixes for the command center's read at e0c260ca) and b444d148 (registration, last).

What changes

  1. docs/secret-storage.md. The ibkr-gateway row (line 28) said the login is typed at sign-in and nothing is stored. It now says the paper login is stored:

    • It sits in three 0600 files with one link each, named by pointer only: IBKR_PAPER_LOGIN_ENV, IBKR_PAPER_TWS_FILE and IBKR_PAPER_VNC_FILE.
    • The two password files are owned by the rootless container user.
    • A weekly second-factor approval on the user's phone keeps it signed in.
    • The row links rotation, and states that live trading stays out of scope.

    A new section, "IBKR paper gateway sign-in (2026-10-06)", covers the rest. The pickup block gains the three pointer exports, and the Checker and Rotation sections are updated.

  2. adoption/credential-inventory.json. ibkr-gateway becomes the stored user ID: class broker_login, status optional, a private_file store and pointer IBKR_PAPER_LOGIN_ENV. Two new rows, ibkr-gateway-tws-password and ibkr-gateway-vnc-password, declare rootless_container_uid: 1000. TWS_USERID joins must_not_be_set. Rotation replaces a file (write a new 0600 file, move it over the old one), because the user cannot open the chowned password files. The rule that TWS_* and IBKR_* values never reach workers is kept:

    • no IBKR row is injectable (credential_run.py) or writable (set_credential.py);
    • the runner strips all three pointers from every command it starts;
    • the guard refuses a reader on each pointer and any TWS_USERID reference.
  3. scripts/credential_status.py. For a row that declares rootless_container_uid (only the two password files), the owner may be the host uid that rootless Docker maps that container uid to: this user's first /etc/subuid start plus 999 for uid 1000.

    • The start comes from /etc/subuid at run time, parsed as rootlesskit v3.1.0's static source parses it. A missing or malformed file fails closed.
    • Mode 0600 is still required. Every private_file store, the IBKR login env file included, needs exactly one link; a second name is the new finding hard_link.
    • Only /etc/subuid is opened, never a credential file. --subuid PATH serves the test fixtures.
  4. blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh adopts the command center's host script. The user or an agent runs it from an interactive shell (bash -i); only typing the stored values, once, at the user's private prompt is the user's own step. It keeps the client-connection refusal, the rollback rename and the chown inside the user namespace, and adds:

    • umask 077;
    • refusals for a non-rootless daemon and a record directory inside any Git worktree;
    • every refusal now runs before the first change;
    • the rollback command is printed before the new container starts, so a failed start still shows it.

    It runs the paper account with orders enabled (TRADING_MODE=paper, READ_ONLY_API=no). Its docker inspect records hold the user ID. They go to a new 0700 directory of 0600 files under ${XDG_STATE_HOME:-$HOME/.local/state}/native-agent-stack/ibkr-gateway/, never inside a checkout.

  5. scripts/hooks/secret_path_guard.py. The three pointers join POINTER_VARIABLE, as tests/test_secret_path_guard.py:2337-2346 (at ecfa1127) requires for every inventory pointer, and TWS_USERID joins the base SECRET_NAMES. The SHA256SUMS pin moves. The two adoption pages mark it as changed after v2026.10.05.1.

  6. docs/decisions/2026-10-06-ibkr-paper-passwordless-login.md records the decision, the upstream sources (with the vendor-organization check), what is stored and where (by pointer), the orders-enabled setting, the weekly second factor, the accepted paper-only risk, the alternatives and what would overturn it.

Pointer-convention finding (no rename, no user item). The question was whether worker_env_check.sh or credential_status.py treats the IBKR_PAPER_* pointer names as forbidden. Line numbers are at base ecfa1127.

  • credential_status.py does not. It compares must_not_be_set by exact name (scripts/credential_status.py:550) against TWS_USERNAME, TWS_PASSWORD, TWS_ACCOUNT and IBKR_ACCOUNT_ID (adoption/credential-inventory.json:406).
  • worker_env_check.sh records any ^(APCA|ALPACA|TWS|IBKR)_ name as a broker variable (blueprints/gap-wave2-20260923/us-equities__security-supply-chain/worker_env_check.sh lines 24, 49 and 61). That is a names-only measurement with no gate, and it is the recorded command of the gap-wave2 receipts 8 and 14, so it stays unchanged.
  • The secret guard's SECRET_NAMES is exact too. Its POINTER_VARIABLE must list every inventory pointer.
  • The documented convention in docs/secret-storage.md:
    • lines 33-37 name TWS_* and IBKR_ACCOUNT_ID as the IBKR names that stay unset;
    • lines 281-299 make pointers file paths that the shell startup file exports;
    • lines 71-75 say the runner strips every other entry's pointers.
  • The three names match neither unset rule, so they are kept as documented pointer names and the exemption is written into the inventory row and the runbook. No rename, so the user has no ~/.bashrc change.

Acknowledgement requested from the trading lane (5f)

docs/lanes.md:148-150 requires the trading lane's acknowledgement, as a comment or review on this PR, before merge. It should cover:

  1. Orders enabled on the paper account. The recreate script starts the gateway with TRADING_MODE=paper and READ_ONLY_API=no (blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh), so any API client on 127.0.0.1:4002 can place paper orders from the moment the container starts.
    • The IBKR paper-orders harness needs Read-Only API off (blueprints/us-equities/engine-nautilus/ibkr-paper-orders/README.md L121). Before this, the user unticked it by hand (L246-L249 for 2026-09-23, L345 for 2026-10-05).
    • The 2026-10-05 read-only acceptance ran with READ_ONLY_API=yes (blueprints/us-equities/engine-nautilus/ibkr-acceptance/README.md L15-L16).
    • Now stated in the decision record, the runtime-2604 README and the runbook.
  2. The trading test tests/test_ibkr_gateway_recreate.py, which docs/lanes.md:50 classes as a trading test (test_ibkr_*.py).
  3. The trading path blueprints/us-equities/runtime-2604/: the adopted script and its README section.

Review round: the command center's read at e0c260ca (ACK_AFTER)

Finding Fix Where
P2: CodeQL gate, two high py/clear-text-storage-sensitive-data alerts (#95, #96) on a synthetic fixture The fake paper-password fixture is renamed (self.password → self.tws_fake), so CodeQL's name heuristic no longer sees a password. No suppression comment, following docs/decisions/2026-09-29-key-management.md:589-598. Verified on b444d148 at 06:08Z: all six CodeQL analyses report 0 results, #95 and #96 are fixed on refs/pull/769/head, and the CodeQL check reads "No new alerts in code changed by this pull request". GitHub resolved both github-advanced-security review threads itself. tests/test_ibkr_gateway_recreate.py
P2: recreate script documented as user-run Reworded: the user or an agent runs it from an interactive shell. Typing the stored values once, at the user's private prompt, stays the user's step. script header; runtime-2604 README; runbook; decision record
P2: trading-lane acknowledgement missing, PR still a draft Not closable by this worker: the acknowledgement is 5f's, and the coordinator keeps the draft. Prepared: the orders-enabled setting is now written into the decision record, the README and the runbook, and the section above lists what the acknowledgement should cover. decision record; runtime-2604 README; runbook; this body
P3: inventory rotation says "rewrite" files the user can no longer write All three rotation strings now say: write a new 0600 file, move it over the old one, rerun the script. The runbook adds a "replace, never edit in place" line. adoption/credential-inventory.json; runbook
P3: "one link" claimed for three files, checked for two The hard_link check now covers every private_file store, including the IBKR login env file and the generated host keys. A new test fails against the previous checker (2 subtests) and passes now. Docs updated. scripts/credential_status.py; tests/test_credential_status.py; runbook Checker section
P3: idtools.go citation L48-L85 runs past the end of the file Changed to L48-L83 (the file has 83 lines at 62d2101f). The comment now says the checker mirrors rootlesskit's static source only; the auto branch (parent.go L375-L381) asks getsubids first. scripts/credential_status.py; tests/test_credential_status.py; decision record; this body
P3: decision record does not record the vendor-org check Added: the InteractiveBrokers GitHub org ships no gateway container or login automation (gh api 'orgs/InteractiveBrokers/repos?per_page=100' on 2026-10-06 returns only tws-api-public, last pushed 2018-01-23). decision record, SOTA sources
P3: no rollback command printed if the new container fails to start The script prints the rollback command right after the rename and before docker run -d. The command works with or without a new container. A new test with a failing stub start fails against the previous script and passes now. script; tests/test_ibkr_gateway_recreate.py; README; runbook; decision record

The five upstream-surface disposition citations follow the shifted docs/secret-storage.md lines (now 1799, 1801 and 1812).

SOTA sources

  • gnzsnz/ib-gateway-docker at 8a22deaa6cab86f9ad5c86ff4f0d6efbef718f10, which is tag ibgateway-latest@10.51.1b (gh api repos/gnzsnz/ib-gateway-docker/git/matching-refs/tags/ibgateway-latest@10.51):
    • README "Configuration" table, L175-L203: TWS_USERID L181, TWS_PASSWORD_FILE L183, VNC_SERVER_PASSWORD_FILE L190, TWOFA_TIMEOUT_ACTION L191, AUTO_RESTART_TIME L195, RELOGIN_AFTER_TWOFA_TIMEOUT L199, EXISTING_SESSION_DETECTED_ACTION L200 and TWS_SETTINGS_PATH L203.
    • README "Credentials", L511-L545: the _FILE form.
    • latest/Dockerfile: IBC_VERSION=3.24.2 at L13 and USER_ID 1000 at L67.
  • Vendor organization first. The InteractiveBrokers GitHub organization ships no gateway container and no login automation: only InteractiveBrokers/tws-api-public, last pushed 2018-01-23 (gh api 'orgs/InteractiveBrokers/repos?per_page=100', 2026-10-06). gnzsnz/ib-gateway-docker with IBC fills that gap.
  • IbcAlpha/IBC 3.24.2 at 2be2ecd05d7707f97479fda9ad098fdcc15ab807:
    • userguide.md L586-L601: AutoRestart restarts without re-authentication, giving "a single authentication at the start of the week", and the session expires on Sunday.
    • L508-L551: second-factor authentication.
  • rootless-containers/rootlesskit v3.1.0 at 62d2101fbbe4f79bc845a337c4e868d27ff602c9. This host's rootless Docker Engine 29.8.2 reports rootlesskit 3.1.0.
  • ShellCheck 0.11.0, from PyPI shellcheck-py, run through uvx with a scratch-only cache: no findings in the adopted script. The command center's original exits 1 under the same check.
  • Repository precedents:
    • #481 (c26800f3) added a pointer to POINTER_VARIABLE together with its inventory row, and moved the SHA256SUMS pin.
    • docs/decisions/2026-09-29-key-management.md:589-598 renamed a CodeQL-flagged fixture variable without a suppression comment.

Evidence-class table

Claim Evidence class Command / receipt
After the cold boot, the gateway signed in by itself at 02:25:37Z on 2026-10-06 reported by the command center; not observed again for this PR the command center's handover
On NativeStack2604 at 06:04:50Z (head of the review fixes, before registration), ibkr-gateway is ok, ibkr-gateway-tws-password and ibkr-gateway-vnc-password are ok with owner=rootless_container_user, all three with one link; result ok, values_read: false. At base the three files were undeclared store files and the IBKR row was not_local host execution on NativeStack2604; no receipt retained, so not native_proven python3 scripts/credential_status.py --json → exit 0
The mapped owner is accepted only for the two declared rows; any other owner, a mode other than 0600, or a second link is refused; every private_file row needs one link; no credential file is opened synthetic python3 -m unittest tests.test_credential_status
The recreate script refuses before any change (worktree record directory, rootful daemon, missing ss, connected client, empty pointer target), keeps the rollback rename and the namespace chown, prints the rollback before the new start, and writes its records 0600 synthetic (stub docker, ss and sleep; the real daemon is never reached) python3 -m unittest tests.test_ibkr_gateway_recreate
A reader on each pointer and a TWS_USERID reference are refused; docker loaders, stat and wc pass; bare docker reads are recorded pass-throughs; still a superset of the pinned baselines local_integration python3 -m unittest tests.test_secret_path_guard: 89 of 90 pass. The one failure compares this host's installed guard and is skipped in CI
No IBKR row is injectable or writable; every inventory pointer, the IBKR three included, is stripped from injected commands local_integration python3 -m unittest tests.test_credential_run tests.test_credential_tools

Local commands run

All commands ran on NativeStack2604 in the owned worktree. The head is b444d148.

This round, on the review fixes (bc5064e7) and their registration:

$ python3 scripts/validate.py
exit 0: {"components": 69, "hashed_files": 10275, "profiles": 4, "receipts": 212, "status": "passed"}
$ git diff --check origin/main...HEAD
exit 0
$ python3 scripts/build_new_wsl_handbook.py --check
exit 0
$ python3 scripts/catalog_decisions.py --check
exit 0
$ python3 scripts/component_matrix.py --write; python3 scripts/new_host_grand_list.py --write
exit 0, exit 0: both reports unchanged
$ python3 -m unittest tests.test_credential_status
exit 0: 53 tests OK (1 new: every private_file row needs one link; fails against the previous checker with 2 subtest failures)
$ python3 -m unittest tests.test_ibkr_gateway_recreate
exit 0: 7 tests OK (1 new: a failed start still shows the rollback; errors against the previous script)
$ python3 -m unittest tests.test_credential_run
exit 0: 92 tests OK
$ python3 -m unittest tests.test_credential_tools
exit 0: 34 tests OK
$ python3 -m unittest tests.test_upstream_surface_watch
exit 0: 114 tests OK (6 skipped)
$ python3 -m unittest tests.test_canary_proof
exit 0: 143 tests OK (134 skipped on this host)
$ python3 -m unittest tests.test_credential_boot_receipt
exit 0: 21 tests OK
$ python3 -m unittest tests.test_runtime_worker_openhands_push_gate
exit 0: 122 tests OK
$ python3 -m unittest tests.test_runtime_worker_openhands_resolver
exit 0: 138 tests OK (1 skipped)
$ python3 -m unittest tests.test_adoption_docs_consistency
exit 0: 39 tests OK (1 skipped)
$ python3 -m unittest tests.test_practice_references tests.test_landscape tests.test_foundation_catalog tests.test_component_matrix tests.test_gap_crosswalk tests.test_catalog_freshness_trading
exit 0 each: 32, 95, 19, 63, 8 and 49 tests OK
$ python3 -m unittest tests.test_ibkr_paper_orders
exit 0: 79 tests OK (13 skipped)
$ python3 -m unittest tests.test_new_wsl_handbook
exit 0: 76 tests OK
$ python3 -m unittest tests.test_secret_path_guard
exit 1: 90 tests, 1 failure (2 skipped), test_host_profile_copy_is_verbatim.
  It compares this host's installed user-scope guard, still the base pin fd516d8b, with the changed guard.
  CI skips this test, and it passes after the guard reinstall listed below.
$ bash -n blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh
exit 0
$ uvx --from shellcheck-py shellcheck -x -s bash blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh
exit 0: ShellCheck 0.11.0, run with a scratch-only uv cache; no findings
$ python3 scripts/credential_status.py --json   # 2026-10-06T06:04:50Z
exit 0: all three IBKR rows ok, the two password files owner=rootless_container_user; result ok; values_read false

Earlier rounds.

  • The full suite ran on bf1d143c (1516 s): exit 1, with 10357 tests, failures=12, errors=18 and skipped=903.
    • 29 of the 30 failing tests fail the same way at base ecfa1127 on this host. I re-ran each failing module in a detached base worktree:
      • 18 errors: exchange_calendars is not installed here (16 adaptive-paper and trading modules, plus 2 test_ingest_snapshot tests);
      • the test_adoption_launchd, test_adoption_bootstrap, test_adoption_guarded_runners and test_windows_terminal_defaults failures;
      • five test_adaptive_paper_credential_race failures;
      • a cross-device git clone --local in test_token_e2e_grader.
    • The 30th is the host-guard comparison above.
  • CI's validate on e0c260ca succeeded (check run 112109930442, 05:05:37Z). The command center's read reports that its suite ran 11361 tests, OK with 1026 skipped.
  • Failed attempts, retained, all fixed in 80340ee3:
    • validate.py exited 1 on a literal home path in the script.
    • test_adoption_docs_consistency exited 1 twice: first a missing "changed after" marker, then a link to the decision record before it existed.
    • The first full suite caught two regressions: five shifted disposition citations and the stale new-WSL handbook digest.

CI that this PR does not cause. The required osv-scanner check fails repo-wide on new advisories in lockfiles that this PR does not touch:

  • mako 1.4.1
  • fsspec 2025.9.0
  • multidict 6.7.0
  • werkzeug 3.1.8
  • source-map-js 1.2.1

Main needs a fix, and this PR then needs a new head.

Decision record

docs/decisions/2026-10-06-ibkr-paper-passwordless-login.md names the evidence, the alternatives (typing at each sign-in, a TWS_PASSWORD environment value, Compose secrets, the kernel keyring, renaming the pointers) and what would overturn it.

Host evidence

Not applicable: no file under evidence/hosts/ changes.

  • python3 scripts/host_receipts.py validate passes for every new/changed receipt. (No receipt changes.)
  • Independent review is recorded (scripts/host_receipts.py review) or explicitly requested in this PR. (No receipt changes.)
  • No platform_status change is made from a host receipt alone.

Items for the coordinator and the user

  • User: none. The pointers keep their names, so ~/.bashrc needs no change.
  • Trading lane (5f): acknowledge on this PR, covering the three items under "Acknowledgement requested from the trading lane". Then the PR can leave draft.
  • Coordinator, before merge: get osv-scanner fixed on main, then give this PR a new head through the hot-file protocol.
  • Coordinator, after merge: reinstall the user-scope guard on NativeStack2604 with python3 tools/adoption/install_claude_profile.py --only guard from the merged checkout.
    • Until then, the host's frozen guard (fd516d8b) does not refuse readers on the three pointers.
    • credential_status.py --client-guards and the boot receipt report claude_user_guard_matches_pin=false, and the local test_host_profile_copy_is_verbatim fails. CI skips that test.
  • Coordinator: write the report and ack ledger rows.
  • Follow-ups, not in this PR:
    • adopt the two private-prompt scripts that wrote the files, so rotation is reproducible on a new host;
    • add a receipt file for the host check above.

Checklist

  • New/changed GitHub Actions are pinned to a full commit SHA with a version comment (no floating tags). (No workflow changes.)
  • New/changed workflows declare top-level permissions: {} and grant each job only what it needs (contents: read, or an explicitly justified addition). (No workflow changes.)
  • No secrets are printed, logged or committed; no new required secret was added without a documented owner. No credential value was read: the host check uses lstat and /etc/subuid only, and the command center's inspect records were never opened.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved (not deleted, moved or overwritten).

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement label Oct 6, 2026
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/ns2604-ibkr-passwordless-20261006 branch from bf1d143 to e0c260c Compare October 6, 2026 04:34
Comment thread tests/test_ibkr_gateway_recreate.py Fixed
Comment thread tests/test_ibkr_gateway_recreate.py Fixed
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Trading-lane acknowledgement (lane:shared), for the trading path at e0c260c

The trading lane acknowledges these changes:

  • blueprints/us-equities/runtime-2604/README.md (+29)
  • blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh
  • tests/test_ibkr_gateway_recreate.py

Checked against the trading lane's paper rules:

  • Paper only. TRADING_MODE=paper is fixed in the script (:104). No live mode, endpoint or key path is added.
  • Pinned image. It is digest-pinned to the image of the 2026-10-05 IBKR acceptance receipt (:27).
  • Loopback ports. Both are published on 127.0.0.1 only: 4002 to the container's 4004, and VNC 5900 (:99).
  • Orders enabled. READ_ONLY_API=no matches the qualified rc5 order path.
  • Restart outside paper sessions. The nightly restart at 11:00 PM ET (:31) falls after every paper session; the latest unit ends about 8:05 PM ET.
  • No disruption of a live client. It refuses while an API client is connected to 127.0.0.1:4002 (:71-75).
  • Rollback. The old container is kept stopped for rollback.

P2 (trading): add a host guard that refuses unless WSL_DISTRO_NAME is the distro that owns the paper gateway. The same container name exists, stopped, on the other distro, and it must stay stopped. Run there, the script would start a second gateway on the same paper user. With EXISTING_SESSION_DETECTED_ACTION=primary (:107), that gateway would take over the session from the 2604 gateway. Today nothing but the README wording prevents that. This does not block the acknowledgement.

The acknowledgement covers this head only. A later head needs a new look at the trading path.

seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
- P2 CodeQL: the recreate test's fake paper-password fixture is renamed
  (self.tws_fake), so py/clear-text-storage-sensitive-data's name heuristic
  no longer sees a password. There is no suppression comment, following
  docs/decisions/2026-09-29-key-management.md:589-598. CI's CodeQL run is
  the check.
- P2 frictionless wording: the recreate script header, the runtime-2604
  README, the runbook and the decision record now say the user or an agent
  runs the script from an interactive shell. Only typing the stored values,
  once, at the user's private prompt stays the user's step.
- P2 trading-lane acknowledgement: TRADING_MODE=paper with READ_ONLY_API=no
  (orders enabled) is now stated in the decision record, the README and the
  runbook, with the paper-orders harness README lines that need it, so 5f's
  acknowledgement can cover it. The PR stays a draft.
- P3 rotation: the three inventory rotation strings describe writing a new
  0600 file and moving it over the old one, because the user cannot open
  the chowned password files.
- P3 one link: every private_file store now needs exactly one link
  (hard_link otherwise), including the IBKR login env file. A new test
  fails against the previous checker.
- P3 citation: rootlesskit idtools.go is L48-L83 (the file has 83 lines),
  and the checker mirrors rootlesskit's static source only (parent.go:375-381
  is the auto branch, which asks getsubids first).
- P3 vendor org: the decision record notes that the InteractiveBrokers
  GitHub org ships no gateway container or login automation (only
  tws-api-public, last pushed 2018-01-23).
- P3 rollback: the recreate script prints a rollback command, safe with or
  without a new container, before it starts the new container. A new test
  fails against the previous script.
- The upstream-surface dispositions follow the shifted docs/secret-storage.md
  lines (1799, 1801, 1812).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/ns2604-ibkr-passwordless-20261006 branch from e0c260c to b444d14 Compare October 6, 2026 06:06
seathatflowsinourveins and others added 3 commits October 6, 2026 06:38
… rootless container owner in the credential checker, adopted recreate script

On 2026-10-06 (about 01:50Z) the user decided that the passwordless,
LLM-native and frictionless workflow they prefer extends to the IBKR paper
login, and the command center applied it on NativeStack2604. This brings the
repository in line with that host.

- adoption/credential-inventory.json: ibkr-gateway becomes the stored paper
  user ID (private_file, pointer IBKR_PAPER_LOGIN_ENV), joined by
  ibkr-gateway-tws-password and ibkr-gateway-vnc-password (pointers
  IBKR_PAPER_TWS_FILE and IBKR_PAPER_VNC_FILE, rootless_container_uid 1000).
  TWS_USERID joins must_not_be_set. No row is injectable or writable.
- scripts/credential_status.py: a row that declares rootless_container_uid
  may be owned by the host uid its rootless Docker user namespace maps that
  container uid to, derived from /etc/subuid as rootlesskit v3.1.0 lays the
  ranges out (first range start plus 999 for uid 1000). Mode 0600 and one
  link are still required, and only /etc/subuid is read.
- scripts/hooks/secret_path_guard.py: the three pointers join
  POINTER_VARIABLE and TWS_USERID joins SECRET_NAMES. The SHA256SUMS pin
  moves, and the two adoption pages mark the change after v2026.10.05.1
  (the new-WSL handbook and its receipt follow the changed page's digest).
- blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh: the
  command center's recreate script, adopted with every refusal before the
  first change and its inspect records 0600 outside every Git worktree.
- docs/secret-storage.md and
  docs/decisions/2026-10-06-ibkr-paper-passwordless-login.md: what is stored
  and where (by pointer), the owner rule, the weekly second factor, rotation,
  the accepted paper-only risk and the overturn conditions. The five
  upstream-surface dispositions that cite docs/secret-storage.md lines move
  with the shifted lines.

Sources: gnzsnz/ib-gateway-docker 8a22deaa6cab (ibgateway-latest@10.51.1b)
README Configuration and Credentials; IBC 3.24.2 (2be2ecd05d77)
userguide.md:586-601; rootlesskit v3.1.0 (62d2101f) pkg/parent/parent.go:401-432
and pkg/parent/idtools/idtools.go:48-85.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- P2 CodeQL: the recreate test's fake paper-password fixture is renamed
  (self.tws_fake), so py/clear-text-storage-sensitive-data's name heuristic
  no longer sees a password. There is no suppression comment, following
  docs/decisions/2026-09-29-key-management.md:589-598. CI's CodeQL run is
  the check.
- P2 frictionless wording: the recreate script header, the runtime-2604
  README, the runbook and the decision record now say the user or an agent
  runs the script from an interactive shell. Only typing the stored values,
  once, at the user's private prompt stays the user's step.
- P2 trading-lane acknowledgement: TRADING_MODE=paper with READ_ONLY_API=no
  (orders enabled) is now stated in the decision record, the README and the
  runbook, with the paper-orders harness README lines that need it, so 5f's
  acknowledgement can cover it. The PR stays a draft.
- P3 rotation: the three inventory rotation strings describe writing a new
  0600 file and moving it over the old one, because the user cannot open
  the chowned password files.
- P3 one link: every private_file store now needs exactly one link
  (hard_link otherwise), including the IBKR login env file. A new test
  fails against the previous checker.
- P3 citation: rootlesskit idtools.go is L48-L83 (the file has 83 lines),
  and the checker mirrors rootlesskit's static source only (parent.go:375-381
  is the auto branch, which asks getsubids first).
- P3 vendor org: the decision record notes that the InteractiveBrokers
  GitHub org ships no gateway container or login automation (only
  tws-api-public, last pushed 2018-01-23).
- P3 rollback: the recreate script prints a rollback command, safe with or
  without a new container, before it starts the new container. A new test
  fails against the previous script.
- The upstream-surface dispositions follow the shifted docs/secret-storage.md
  lines (1799, 1801, 1812).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/ns2604-ibkr-passwordless-20261006 branch from b444d14 to 17a06de Compare October 6, 2026 10:41
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Trading-lane acknowledgement (lane:shared), at b444d14 and at 17a06de

17a06de changes nothing on the trading path. git diff b444d148 17a06de05 over blueprints/us-equities/ and tests/test_ibkr_gateway_recreate.py is empty; that head only refreshes the evidence registry.

What changed on the trading path since my acknowledgement at e0c260c:

  • The script's wording now says the user or an agent runs it, and only typing the stored values is the user's step.
  • The rollback is printed before the new container starts. It also tolerates a container that was never created or never started.
  • The tests are updated to match.

The paper-only properties still hold at this head:

  • TRADING_MODE=paper (:109);
  • the digest-pinned image of the 2026-10-05 acceptance receipt (:28);
  • ports on 127.0.0.1 only (:104);
  • the nightly restart at 11:00 PM ET, outside every paper session (:32);
  • refusal while an API client is connected to 127.0.0.1:4002 (:72-76).

Residual (P2, non-blocking, unchanged): nothing in the script refuses outside the distro that owns the paper gateway. The same container name sits stopped on the other distro, and with EXISTING_SESSION_DETECTED_ACTION=primary (:112), a second gateway started there would take over the 2604 session. The trading lane records this residual for a follow-up.

This acknowledgement covers the trading path at these two heads only.

seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

- Select one default for each logical NativeStack2604 host tool and name every coordinated consumer amendment. This decision exposes the bootstrap/trading/CI pin split without claiming it has already been resolved.
- Base commit: `67c6b6f94b456a3a7b5d28bb1fa34625a808d316`.
- Lane: exactly `lane:foundation`; this PR remains draft for the command center's cross-family read.
- Owned paths: two dated decisions, resolver watch documentation, source/version and partial context-review artifacts, sanitized assignment metadata, evidence registry last. Live bootstrap/profile/install-plan/CI and trading files are not edited. Currency's consumer follow-up starts only after #642/#645 land, or is folded by 5f's request; fixwave-defects owns #723/#776, github-ci-finalize owns the CI uv/hash, and 5f owns the trading gate/digest.

The canonical defaults are Node24.21.0,uv0.12.22,gh2.102.0,host Python3.13.16,Codex0.160.1,Claude2.1.292,Harbor0.24.0,Collector0.162.0 andvLLM0.31.0. This is a decision and owner handoff. Claude's ordinary cooldown and Harbor/vLLM qualification remain gates; the trading project's Python3.12.3 remains a separate project requirement.

The executable bootstrap consumes pins-linux-x86_64.json, so a profile summary edit alone would leave drift. 5f must fold the uv0.12.22 gate and verified sync-vector digest together. CI's promotion uv/hash and Python's family-versus-patch selection are named explicitly. C5's reopened context audit is ongoing in this same PR: the command center assigned the NativeStack2604 resolver loop to currency. Seven of nine items have primary review evidence; two Codex tagged-source checks remain pending. Nice19 local publication validation passed on the rebase and is rerun for the J805 fixes. No instruction/template file is edited. Preserve unrelated rows, update the three existing document rows by key, and append only newly reviewed name rows. These final catalog changes are pending; the live catalog remains unchanged.

## SOTA sources

- [native-agent-stack@0d5e6506:profile defaults:4655](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/adoption/new-wsl-profile.json#L4655), [plan mise pins:6-15](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/evidence/artifacts/new-wsl-install-plan-20261002/mise.toml#L6-L15), [bootstrap artifact consumer:233](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/adoption/bootstrap-linux.sh#L233), [native newer-client preservation:843](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/adoption/bootstrap-linux.sh#L843): exact split and qualified preservation policy.
- [Node v24.21.0](https://nodejs.org/en/blog/release/v24.21.0), nodejs/node@955266bf; [uv0.12.22](https://github.com/astral-sh/uv/releases/tag/0.12.22), astral-sh/uv@70fe1196; [gh2.102.0](https://github.com/cli/cli/releases/tag/v2.102.0), cli/cli@fc4b137c; [Python3.13.16](https://www.python.org/downloads/release/python-31316/), python/cpython@cbc944f4: plan-aligned maintained host defaults and release dates.
- [Codex rust-v0.160.1](https://github.com/openai/codex/releases/tag/rust-v0.160.1), d27764b8; [Claude v2.1.292](https://github.com/anthropics/claude-code/releases/tag/v2.1.292), release-repository fbe20e00; [Harbor v0.24.0](https://github.com/harbor-framework/harbor/releases/tag/v0.24.0), b53b8134; [Collector v0.162.0](https://github.com/open-telemetry/opentelemetry-collector-contrib/releases/tag/v0.162.0), ae8c5075 and [distribution](https://github.com/open-telemetry/opentelemetry-collector-releases/releases/tag/v0.162.0), f6159a77; [vLLM v0.31.0](https://github.com/vllm-project/vllm/releases/tag/v0.31.0), db9527a4: F12 selected targets, identities and pending gates.
- [Trading sync pins:8-9](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/blueprints/us-equities/runtime-2604/sync-trading-2604.sh#L8-L9), [verified vector:84-88](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/blueprints/us-equities/runtime-2604/install-trading-2604.sh#L84-L88), [uv gate:112](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/blueprints/us-equities/runtime-2604/install-trading-2604.sh#L112): exact 5f handoff; no trading file edit.

C5 primary sources: [Claude memory](https://code.claude.com/docs/en/memory), [skills lifecycle](https://code.claude.com/docs/en/skills#skill-content-lifecycle), [environment reference](https://code.claude.com/docs/en/env-vars), [network trust](https://code.claude.com/docs/en/network-config#ca-certificate-store), [official Codex Markdown AGENTS guide](https://learn.chatgpt.com/docs/agent-configuration/agents-md.md), read2026-10-06; [Claude2.1.292 changelog](https://github.com/anthropics/claude-code/blob/fbe20e00e2851fc01506f54f98a8f0b875af3847/CHANGELOG.md). Installed Claude artifact/byte windows and qualified comparison limits are in review.json; assignment source is resolver-assignment.json.

J805 fixes: the residual map covers the exact Codex lane guard, uv CI downloader/hash, generated installer/acceptance/Python selections, Inspect/Scout's Harbor package, producer contract, vLLM/Collector recipes and inactive template. SDK/bundled CLI0.160.0, dedicated SDK interpreter, dated holds, rollback and macOS pins are classified separately. The idleCompaction source now names the actual byte-window line113; row updates are by key, not duplicates. No executable pin/guard is changed by this decision PR.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Profile, bootstrap, plan, CI and trading consumers differ | source_review | Immutable main reads and exact linked locators |
| Installed host-tool versions match the plan; F12 drift is dated | local_integration, read-only version observation | selection.json; normalized versions and command labels explicitly identified |
| Selected default versions have official release identities/dates | source_review | Maintainer release/ref metadata; no downloaded-asset verification or new runtime acceptance |
| Every in-scope consumer is named; qualification is not inferred | source_review, independent completeness critic | 0P1/0P2; two P3 provenance refinements corrected |
| Publication integrity | local_integration | Nice19 validate.py exit0 after registration; this is integrity/scope evidence only |

### Local commands run

```text
Fresh owned worktree creation from origin/main with Worktrunk --no-hooks
exit0; hooks skipped for the paper window; original worktrees preserved.
Installed --version and cached official release/ref reads
exit0; source ledger records normalized versions, not full argv/raw outputs.
Independent bounded completeness critic
0P1/0P2; two P3 source/provenance refinements fixed.
git diff --check / staged whitespace check
exit0.
host_receipts.register_file for the two owned new files
exit0; registry-only commit LAST.
python3 scripts/validate.py
Exit0 under the later REBASE-805/J805 authorisation for light checks with the paper session inactive; repeated after J805 evidence registration.
```

### Open shared-file neighbours

#802, #770, #769 and #764 also edit upstream-surface-dispositions.json. Rebase after any lands first and take main's catalog. Preserve unrelated rows, update the three existing document rows by key, and append only newly reviewed name rows. Keep #802's corrected context_management source locator. Queued branches remain 5f-only. This PR remains currency-written and draft while the review completes.

J805 checks:6 DispositionCitationTests pass (nice19), actual proposed source113 passes the existing predicate while old line1 is rejected, and bounded independent completeness critic reports no remaining material P2. Source-review findings are not new runtime acceptance.

### Decision record

`docs/decisions/2026-10-06-one-host-tool-default.md` names defaults, full residual inventory/exceptions, owners and overturn conditions. `docs/decisions/2026-10-06-harness-context-budget-refresh.md` records the reopened partial C5 review and proposed CC-only sentences. Executable one-pin acceptance remains pending owners' folds.

### Host evidence

No evidence/hosts or platform-status change. Version output is not native adoption or a passed new host run.

- [ ] Host-receipt validation: not applicable.
- [x] Independent source/consumer completeness read recorded.
- [x] No platform-status update inferred.

### Checklist

- [x] No Actions/workflow permissions change.
- [x] No credential values/files read or committed; no new required secret.
- [x] No paid hosting/subscription/billing surface.
- [x] Peer-owned files, historical receipts, main and other worktrees preserved.
- [x] Registry committed last; draft retained.
- [x] Nice19 local publication validation passed for the registered J805 content; no native acceptance inferred.
seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Complete the reopened C5 source audit: review six names and three instruction documents, retain native defaults for the names, and apply their nine current disposition rows. The unchanged main-catalog watch returned nine unreviewed items; the candidate now returns zero with all document hashes matching.

- Base commit: b4e1fa6. Rebase-only after #812 landed; all four C5 content files are byte-identical to the initially published345b8d00.
- Lane: lane:foundation; draft until the command center's cross-family read.
- Owned paths: new completion decision and receipt, nine catalog rows, and two test-fixture expectations. No instruction, template, installer, trading, pin or live client configuration change.
- A21 places completion in this separate PR. #805 stays exactly at23d4366e; its partial decision and recorded observations remain unchanged and are linked by immutable path/commit.
- Shared-file neighbours: #802, #813, #770, #769 and #764. Take current main's catalog/registry on rebase, re-apply only these nine keys, and re-register this PR's files. Rebase after #805 lands; no peer branch edits.

## SOTA sources

- [openai/codex@rust-v0.160.1/d27764b8 — guardian feature defaults](https://github.com/openai/codex/blob/d27764b82f7118f674371e6d6e76271d9d606edb/codex-rs/features/src/lib.rs#L1666-L1688): both UnderDevelopment/default false. Installed0.160.1 features list agrees.
- [Tagged Guardian history guard](https://github.com/openai/codex/blob/d27764b82f7118f674371e6d6e76271d9d606edb/codex-rs/core/src/guardian/reviewer_config.rs#L48-L62) and [root-handoff declaration](https://github.com/openai/codex/blob/d27764b82f7118f674371e6d6e76271d9d606edb/codex-rs/features/src/lib.rs#L333-L334). Unchanged scenario files are source-reviewed, not executed.
- [Codex0.160.1 release note](https://github.com/openai/codex/releases/tag/rust-v0.160.1), published2026-10-05, and [anthropics/claude-code@fbe20e00 —2.1.292 changelog](https://github.com/anthropics/claude-code/blob/fbe20e00e2851fc01506f54f98a8f0b875af3847/CHANGELOG.md#L6), alongside the installed-client source proof retained by [#80523d4366](https://github.com/seathatflowsinourveins/native-agent-stack/blob/23d4366e26910ae43783518bd6807625a9e5e409/evidence/artifacts/ns2604-context-audit-20261006/review.json).
- Current vendor bodies, reread2026-10-06: [Claude memory](https://code.claude.com/docs/en/memory), [skills](https://code.claude.com/docs/en/skills#skill-content-lifecycle), [environment variables](https://code.claude.com/docs/en/env-vars), [CA trust](https://code.claude.com/docs/en/network-config#ca-certificate-store), and [official Codex AGENTS Markdown](https://learn.chatgpt.com/docs/agent-configuration/agents-md.md). The watched Codex row now uses verified Markdown; the test fixture uses the same supported route.
- [Repository hot-file protocol@e28d0eec](https://github.com/seathatflowsinourveins/native-agent-stack/blob/e28d0eec112527ac02659ac23753533b8ed39a73/docs/lanes.md#L94-L105) and [disposition schema](https://github.com/seathatflowsinourveins/native-agent-stack/blob/e28d0eec112527ac02659ac23753533b8ed39a73/docs/upstream-surface-watch.md#L174-L193).

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Nine source decisions complete; native overrides declined | source_review | New completion review.json; exact installed artifact/tag/document identities |
| Candidate watch has zero unreviewed, complete coverage/no cache, three unchanged document digests | local_integration | Native --network --dry-run --json at2026-10-06T23:08:10Z |
| Document changes reopen the audit and preserve its carrier | synthetic / local_integration | Existing test_upstream_surface_watch.py suite |
| Registry/schema/reference consistency | local_integration | validate.py; no live provider/GPU execution |

### Local commands run

All substantive commands ran at nice19/ionice3.

- python3 scripts/upstream_surface_watch.py --check-dispositions: exit0,311 rows.
- python3 scripts/upstream_surface_watch.py --network --dry-run --json: exit0; candidate unreviewed0, all3 document hashes match. Before application: exit0/unreviewed9, retained separately.
- python3 -m unittest discover -s tests -p test_upstream_surface_watch.py: exit0,114 tests,6 skips for optional cached upstream-input checks. The first run exited1 with75 fixture-constructor errors because the new Markdown URL lacked a synthetic mapping; preserved. Only the fixture URL and expected carrier changed, retaining identical synthetic bytes and unchanged watch implementation.
- Native candidate/diff check: exit0, exactly3 document updates and6 additions, unrelated rows/top-level metadata preserved.
- python3 scripts/validate.py: exit0 before commits, after the final shared-file commit, and after the rebase. Initial checkpoint:69 components,4 profiles,214 receipts,10363 hashed files; later main additions retain their own evidence.

Two earlier watch usage failures exit2 before fetch because the long worktree could not fit the160-character details summary. Both are retained; a supported per-invocation Worktrunk short owned path/no-hooks resolves the command without saved settings changes.

### Decision record

docs/decisions/2026-10-06-harness-context-budget-completion.md and evidence/artifacts/ns2604-context-audit-completion-20261006/review.json. Keep native defaults; revisit on a supported release and qualified host need, or any changed instruction-body digest. Previous reviewed body bytes were unavailable, so no historical semantic delta is invented. Source review does not establish runtime acceptance or token savings.

### Host evidence

No evidence/hosts file, host installation or platform-status change. Local catalog-candidate zero is separate from landed-main or deployed-client state.

### Checklist

- [x] No workflow or action changes.
- [x] No credential values/raw conversations/private active configurations committed.
- [x] No new paid hosting or billing surface.
- [x] Peer-owned files/worktrees and immutable observations preserved.
- [x] Preserve unrelated rows, update the three existing document rows by key, and append only newly reviewed name rows.
- [x] Shared catalog and evidence registry are committed last.
seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Route catalog lookup through QMD's lexical queries and bounded document retrieval; use SocratiCode for semantic catalog search at the main checkout's projectPath. Keep reranking available and prohibit qmd embed/pull. Update current maintenance recipes and native instruction carriers through the repository renderers.

Existing Serena consumers read its manual before navigation, and jCodeMunch consumers obtain the current guide before a typed route with the actual caller model and execution off. Four existing Claude roles gain only Serena's manual tool. Reviewer/builder keep their no-menu boundary, and a focused read of a known path and line remains valid.

This landing repair appends the preregistration's Amendment4 to bind the deliberately changed role bodies and compacts lane-authored RTK explanations within the unchanged compact and startup budgets. The entire composed pre-RTK prefix, upstream awareness, owner's blocks, exact SKILL line, seven exceptions, models and effort are preserved. Prior amendment rows, observations, seals and RUNBOOK bytes remain unchanged.

The canonical code-graph rename is prepared as a separate patch and is excluded from this head under command-center ruling081016Z. Main's existing names remain in both templates, the map, fixtures and carriers. The protected lane token requires the owner's word before the rename can land. Until that follow-up, this host's Claude code-graph access is through the vendor's hook channel only; the stale MCP carrier id is a recorded limitation and is not claimed fixed.

- Base commit: `c44993b379da25fae923dbbe70188978af5104aa` (verified native source; #803 already landed).
- Lane: `lane:foundation`; draft.
- Head: `9985e468fa4997d22630714b2fa6a76666e3cda9`. Native bytes: compact 8076 <8192, rendered 9142, three-file startup 20101 <=20103; full Claude block 4087 <=4100. These are byte gates, not token-use measurements.
- Owned paths: token-lane carriers and their paired handbook text, minimal manual grants and mirrors, Codex template/rendered copies, native loader/routing/sequence tests, current recipes and generated handbook, append-only decisions/preregistration amendment, follow-up receipts and checksum/registry projections.
- ROLE-CARRIER-GAPS and ROLE-GRANTS are separate future work and stay out of this change.

Landing path: explicit command-center cue070358Z and fallback ruling081016Z permit one pushed rebase/content repair onto then-current main while #802/#813/#830 land. The co-op performs the new-head delta read with its CI result; the command center ACKs; 5f lands. A further pushed rebase requires the separate dated landing-conflict cue. Host configuration, cutover and fresh-session/working-day acceptance belong to their owners.

## SOTA sources

- [QMD v2.8.3 lexical query](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L294), [typed searches/rerank](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L321) and [document retrieval](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L412): native lexical subqueries, retrieval and optional rerank. Rerank defaults true (:334-335). [README maintenance syntax:1033-1037](https://github.com/tobi/qmd/blob/v2.8.3/README.md#L1033-L1037) supplies bounded commands.
- [SocratiCode v1.15.0 codebase_search](https://github.com/giancarloerra/SocratiCode/blob/v1.15.0/src/index.ts#L138): semantic search at an absolute projectPath. Owner ruling224125Z selects the routing and preserves rerank-on acceptance; this PR performs no host cutover.
- [Serena c6fbd1c5 manual order](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/resources/config/prompt_templates/system_prompt.yml#L5-L6), [manual tool:28-40](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/workflow_tools.py#L28-L40) and [project/session binding:44-49](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/config_tools.py#L44-L49): manual first, active cwd project and returned session id for switches.
- [jCodeMunch 1.108.330, 28803366, typed route:446-463](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L446-L463), [guide:4743-4752](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L4743-L4752) and [policy:101-128](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/cli/policy.py#L101-L128): guide-first and typed task/model route. These files are unchanged at target1.108.331/d94049d0. The executable schema corrects the guide's query example; no new adaptive-tier setting or upstream rebuild.
- `native-agent-stack@c44993b:tests/test_token_e2e_preregistration.py:637-663,905-909`: later dated role-pin amendment and sealed RUNBOOK contracts. Amendment4 preserves every earlier row/seal and extends the current-row selector. The command center records merge chronology at landing; this is a structural repair and authorizes no run.
- [DeusData/codebase-memory-mcp v0.11.0 release](https://github.com/DeusData/codebase-memory-mcp/releases/tag/v0.11.0), the repository's pinned component, and the command center's native-client read-back identify the canonical server name. Its proposed client-key/wire-id/owner-token correction is kept in the separate patch, preserving every payload and strict fixture. Ruling081016Z explicitly keeps main's names in this publication while the owner's instruction-token decision remains open.
- RTK explanation provenance: `native-agent-stack@2d849ba` (#726) and `@50b9579` (#389), `adoption/templates/codex.AGENTS.template.md` after its exceptions marker. The eight explanations shorten while all facts and protected bytes remain. Command-center064832Z accepted their class and scoped wording.
- Native helpers at `native-agent-stack@c44993b`: `tools/adoption/managed_block.py:169` (`codex_block`), `tools/adoption/codex_roles.py:287` (`f4_block`), `scripts/host_receipts.py:710` (`register_file`), `docs/lanes.md:94-128`. Current generated inventory/handbook and checksum bindings use those repository tools; historical receipts and the frozen catalog passage are preserved.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Documented native routing/manual/guide interfaces | source_review | Pinned upstream files above |
| Carrier rendering, protected bytes, new body pins and tool ids | local_integration | Existing native helpers, hashes and required modules |
| Permission/sequence/byte-mutant/frozen-row controls | synthetic | Existing tests with assertions preserved |
| Deployed use and token savings | Pending owner evidence | No model, host apply or working-day measurement in this repair |

### Local commands run

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_scaffold_repo tests.test_new_wsl_handbook tests.test_adoption_docs_consistency tests.test_codex_agents tests.test_codex_roles tests.test_codex_worker_lane tests.test_token_e2e_preregistration tests.test_new_wsl_client_config.RecordTests tests.test_install_claude_profile tests.test_managed_block tests.test_task_model_routing tests.test_new_wsl_client_config.MapTests tests.test_new_wsl_client_config.AgentGapTests tests.test_new_wsl_client_config.RenderTests tests.test_new_wsl_client_config.ApplyTests.test_the_first_run_writes_what_the_wired_pieces_name_and_nothing_else
exit 0; Ran 595 tests in 109.929s; OK (skipped=14)

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_install_claude_profile tests.test_adoption_docs_consistency tests.test_new_wsl_client_config.RecordTests
exit 0; Ran 150 tests in 16.306s; OK (skipped=2)

$ CI=true nice -n 19 ionice -c3 node examples/claude-native/workflows/test-envelope.mjs
exit 0; SUMMARY passed=254 failed=0 total=254

$ CI=true nice -n 19 ionice -c3 python3 -B tools/adoption/new_wsl_client_config.py --check --markdown
exit 0

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/build_new_wsl_handbook.py --check
exit 0
```

The passing 595-test run is retained on unchanged source/assertion inputs from the pre-window checkpoint; the 150-test run checks the concrete relocation-fixture and workflows-README changes in the new main base. Their counts overlap and are not added. The fresh Node run passes 254/254. Strict checksums in both Codex directories and the Claude hook directory, plus `git diff --check`, exit 0. All three Amendment-4 role digests were re-derived in both copies and are unchanged from the previous published head.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; 69 components, 10,482 hashed files, 4 profiles, 224 receipts, status passed
```

The earlier landing composition used source `630b6ece8485a7710ea51321682d5a12e364e25c` and hot commit `5703ef1061b982078038425fada888fd35153868`; its native checks and source-critic result are retained. The authorized locator follow-up changes only `catalogs/foundation/upstream-surface-dispositions.json` and that file's registry row: the `otel.environment` citation now points to the command at `examples/codex-native/README.md:214`. Source commit `2b36cfee` is followed by registry-last commit `9985e468fa4997d22630714b2fa6a76666e3cda9`, with no further rebase. Claude/Codex instruction bytes, role hashes, historical records, namespace and byte budgets remain unchanged.

The registry starts from exact main `c44993b379da25fae923dbbe70188978af5104aa`, registers the same 67 changed-file rows through the native producer, and preserves main's receipt and convergence arrays. The two-file correction passed the 114-test citation module, the two exact failing methods and a second native validator run. The worktree is clean; the shifted-citation scan found no other current target to repair. Historical before/after references remain intact.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch
exit 0; 114 tests, 6 skipped

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch.DispositionCitationTests.test_every_cited_line_names_the_key tests.test_upstream_surface_watch.DispositionCitationTests.test_a_dotted_key_has_its_parent_near_the_citation
exit 0; 2 tests

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; integrity and scope passed
```

The hosted run at5703 returned two failures in11,495 tests because the documentation locator moved. A reviewed locator still gates when its repository test fails. This follow-up closes that exact contract; it adds no assertion waiver or namespace change.

Read-only overlap metadata checked all 47 open PRs, including full file pagination where needed. Source overlaps: #645, #706, #709, #754, #769, #770, #775, #776, #795, #810, #821, #826, #829. Shared registry/checksum paths use the hot-file protocol; no peer branch is changed.

Earlier failed CI at3ba ran11,381tests and failed six role-body-pin subcases; its complete failed log is retained privately. The failed 560-test and earlier 595-test preparation runs also remain retained. This repair uses a dated amendment, preserves the older source evidence and strict current-body comparison, and performs no full-suite or provider acceptance run. Validator results are integrity and scope evidence only.

### Decision record

`docs/decisions/2026-10-06-qmd-lexical-catalog-instructions.md` and `docs/decisions/2026-10-07-serena-jcodemunch-native-navigation-wiring.md`, with appended clarifications and the new landing follow-up, explain the behavior and limits. The preregistration README gains Amendment4 only; its RUNBOOK and earlier sealed records stay byte-identical. No prior result is recast as a new run.

### Host evidence

Repository-only change. No live instruction file, MCP registration, hook trust, client setting, gateway setting/key or model session changed. Source/render checks and synthetic fixtures remain distinct from the configuration owner's read-back and organic-use acceptance.

### Checklist

- [x] No GitHub Actions or paid service change.
- [x] No credentials, raw conversations or live client configuration committed.
- [x] Models, effort, owner's blocks and historical observations preserved.
- [x] Peer-owned worktrees and source preserved.
- [x] Native validation passed; changed checksums/registry committed last at the final head.
seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Restore the handbook test's live publication binding so a later profile or handbook regeneration updates its own maintained receipt, instead of editing #826's dated landing record.

- Base commit: `6d252c9c102e575bc9229bf6bb2149409655d5f3`; head: `4d2ce2a7719adca918025ffde295ef1dfa30bf02`.
- Lane: `lane:foundation`; draft.
- Exactly four paths: `tests/test_new_wsl_handbook.py` (one receipt-path line), `evidence/artifacts/new-wsl-handbook-20261001/receipt.json` (current computed binding plus one appended regeneration), its one-line `README.md`, and registry last.
- The generator, profile, both generated outputs, hash/inventory assertions, existing receipt observations/history and #826's dated record stay byte-identical.
- **Named landing path:** co-op cross-family exact-head read, hosted validate, command center CI read and cue; **right after #820, ahead of #775**. ONE replay at that cue if #820 changes main; full test phase in that landing turn. Hold this draft head for the reads.

## SOTA sources

- `native-agent-stack@6d252c9:tests/test_new_wsl_handbook.py:1672-1691`: the publication contract checks actual current generator/profile/output hashes and inventory, with byte-change negative controls. Its comment says hashes follow regeneration. Only its receipt locator changes.
- Same pin, `evidence/artifacts/new-wsl-handbook-20261001/receipt.json:268,656,700`: the receipt is a current hash mirror and prior entries expressly refresh mutable producer/output bindings while preserving observations. This existing repository practice fills the publication-binding gap; no new manifest, generator or validator is introduced.
- Same pin, `docs/acceptance-evidence-policy.md:59-65` and `docs/landscape-domain-notes.md:33,38`: retain historical inputs/results/failures/pins. All prior receipt fields, regeneration prefix and `previous_outputs` are retained; #826's dated record remains historical.
- Same pin, `docs/lanes.md:94-115`: main-copy/own-registration protocol; `scripts/host_receipts.py:710` updates the three own hashes and inserts the README, in the registry-only final commit.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Existing strict publication contract passes at the maintained binding | `local_integration`, `synthetic` | 87 handbook tests, exit 0; existing byte-change negative controls unchanged. |
| Actual generated bytes are current | `local_integration` | Native builder `--check`, exit 0; MD a1a0cb17… and JSON a42c8915… as recorded in the appended regeneration. |
| Dated records/history/other test assertions preserved | `source_review`, `local_integration` | Exact base-file/JSON comparison, exit 0; independent bounded source critic ACK. |
| Publication integrity after registry-last commit | `local_integration` | `validate.py` before/after, exit 0; 69 components, four profiles, 224 receipts, 10,508 hashes. |

### Local commands run

All checks use the owned external TMPDIR, `nice -n 19 ionice -c3` and closed stdin.

```text
python3 -B scripts/build_new_wsl_handbook.py --check
exit 0, status passed; current outputs unchanged.
python3 -B -m unittest tests.test_new_wsl_handbook
exit 0: Ran 87 tests in 37.368s; OK.
Exact unchanged-field, regeneration-prefix, dated-record and one-test-line comparison
exit 0; all preservation controls true.
python3 -B scripts/validate.py
exit 0 before and after final registry commit; 10508 file hashes.
git diff --check
exit 0.
```

The scoped cached open-PR check found 44 open PRs and these overlapping neighbours: #645, #754, #769, #770, #810 on the maintained receipt; #776 and #810 on the test. The CC assigned this narrow critical-path repair before later regeneration PRs. No peer head or file is edited by this lane.

### Decision record

The CC's J-HANDBOOK-BINDING ruling supplies the bounded disposition. The one-line receipt README identifies the maintained current-state carrier. No old decision or dated observation is rewritten, and no extra decision file is added to this small unit.

### Host evidence

No host/client/installation or acceptance-status changes. These checks establish the repository publication contract, not upstream model or native host acceptance.

### Landing read fields

The intentional main-test edit is `tests/test_new_wsl_handbook.py:1677`, disposed of in advance by the CC for this exact receipt rebind. Name it in `main-tests=` at the landing read. Declare every actual post-read/replay change in `adapted=`; the full-suite phase is deferred to the landing turn. Nothing is re-pointed to a new dated path.

### Checklist

- [x] Existing current-state receipt reused; earlier observations and dated record preserved.
- [x] Only one test line changes; assertions, producer and profile unchanged.
- [x] Own entries registered last; required local checks pass.
- [x] No workflow, dependency, paid surface or credential change.
- [x] Draft and one foundation label; named read/ACK/queue path.
seathatflowsinourveins added a commit that referenced this pull request Oct 8, 2026
### Scope

- What this PR changes: it adds the optional `anthropic-api-2` entry directly after `anthropic-api` in `adoption/credential-inventory.json`, so one command can select an additional Console key. It is an additional key: nothing is replaced. The setter, the runner and the guard are unchanged: the setter and the runner read the inventory, and the guard's rules already cover the variable and the whole store directory. Both entries declare only `ANTHROPIC_API_KEY`, which stays in `must_not_be_set`.
- Base commit: `e48de2e6fa1dd3b740af4793ea5824ea35476dba`
- Lane: `lane:foundation`
- Owned paths touched: `adoption/credential-inventory.json`, `docs/secret-storage.md`, `docs/decisions/2026-10-08-anthropic-api-second-key.md`, `docs/harness-defaults.md`, `tests/test_credential_run.py`, `catalogs/foundation/upstream-surface-dispositions.json`, and `manifests/evidence.json` (the hashes of those six files, written by `scripts/host_receipts.py:register_file`).

The new entry differs from the first in exactly six fields: `id`, `label`, `store.path_template` (file `anthropic-api-2.env` in the same directory), `loaders`, `rotation` and `notes`. Class, status, lane, variables, optional and pointer variables, consumers and store kind are identical. The repository precedent is `alpaca-paper-2` (#481, `c26800f3`).

**Scope beyond the brief.** Four edits go beyond adding the entry. They are declared here so that the read of this PR covers them:

1. **One sentence of the first entry's `notes` is corrected.** Old: "exported in a shell it would override every Claude Code session's native sign-in". New: "a shell export can switch Claude Code from subscription sign-in to API billing (headless mode uses the key when present; interactive mode first asks for approval)". Source: Claude Code's [environment variables](https://code.claude.com/docs/en/env-vars#variables) page, where a present key is always used in non-interactive mode (`-p`) and is approved once in interactive mode before it overrides the subscription. The new entry gives the same reason, so the two entries agree. No other field of `anthropic-api` changes.
2. **One row is added to the anti-pattern log of `docs/harness-defaults.md`.** It records that correction, which that page's "Record a correction the same turn" rule asks for.
3. **`docs/secret-storage.md` gains the first key's table row as well.** The entry table had no `anthropic-api` row. It now lists both entries, followed by one paragraph on selecting a key for one command.
4. **Five line citations into `docs/secret-storage.md` are updated in `catalogs/foundation/upstream-surface-dispositions.json`,** because the added rows moved the cited lines down by 18. The `source` locators of `CLAUDE_CODE_ENABLE_TELEMETRY` (1697 → 1715), `OTEL_LOG_USER_PROMPTS` and `OTEL_LOG_ASSISTANT_RESPONSES` (1684 → 1702), and `OTEL_LOG_TOOL_CONTENT` and `OTEL_LOG_RAW_API_BODIES` (1686 → 1704) change; no disposition or reason does. Hosted `validate-shard-3` failed five subtests of `DispositionCitationTests.test_every_cited_line_names_the_key` at `88d981c7`; #858 made the same repair for its own insertion.

### SOTA sources

Public primary documentation, fetched 2026-10-08; every cited anchor resolves.

- Anthropic [API overview, Getting API keys](https://platform.claude.com/docs/en/api/overview#getting-api-keys) and [Authentication, Create and use a key](https://platform.claude.com/docs/en/manage-claude/authentication#create-and-use-a-key): keys are created on the Console key page, the client SDKs pick up `ANTHROPIC_API_KEY` automatically, and a key scoped to one workspace needs no workspace header.
- Anthropic [Get your API key, Choose a key type](https://platform.claude.com/docs/en/get-api-key#choose-a-key-type), [Workspaces, API keys and resource scoping](https://platform.claude.com/docs/en/manage-claude/workspaces#api-keys-and-resource-scoping) and [Set workspace limits](https://platform.claude.com/docs/en/manage-claude/workspaces#set-workspace-limits): personal, service-account and legacy workspace keys; a multi-workspace key needs the `anthropic-workspace-id` header; spend limits are set per workspace.
- Claude Code [environment variables](https://code.claude.com/docs/en/env-vars#variables) and [authentication precedence](https://code.claude.com/docs/en/authentication#authentication-precedence): in non-interactive mode (`-p`) a present key is always used; in interactive mode the key is approved once before it overrides the subscription. These support the corrected wording.
- Anthropic [WIF reference, Profile configuration file](https://platform.claude.com/docs/en/manage-claude/wif-reference#profile-configuration-file): the configuration-profile alternative that the decision record names.
- [This repository at `c9ab2212142398234b6ba39a4cf33c5c2a6a643e`](https://github.com/seathatflowsinourveins/native-agent-stack/tree/c9ab2212142398234b6ba39a4cf33c5c2a6a643e), the reference implementation this change follows; the cited files are unchanged at the base commit: inventory entries `anthropic-api` (#841, `a35369aa`) and `alpaca-paper-2`; `tools/credentials/set_credential.py:load_entry`; `tools/credentials/credential_run.py:find_entry` and `injectable`; the guard's `SECRET_NAMES`, `STORE_PATHS` and `ENV_FILE_WORD` in `scripts/hooks/secret_path_guard.py`; the `RunnerCase` fixtures in `tests/test_credential_run.py`; `scripts/host_receipts.py:register_file` and `scripts/validate.py`. No credential runtime or dependency is added.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| The Console key and environment contract, and the mode-dependent sign-in wording | source_review | The official pages linked above, fetched 2026-10-08 |
| The new entry differs from the first in six fields only; the inventory goes from 20 to 21 entries and from 10 to 11 injectable ids; of `anthropic-api`, only `notes` changes | source_review | Field-by-field comparison of both entries against `origin/main`, using the runner's own `injectable()` |
| The setter and the runner select separate files, leave the first file unchanged when the second is written, accept the same bare and quoted grammar, inject only the selected value and refuse expansion | local_integration; synthetic | `InjectionTests.test_second_anthropic_key_uses_the_same_setter_and_runner_grammar`: temporary store, generated fake values |
| The guard needs no edit: it lists no ids, its store rule covers the whole store directory, and the variable is already a guarded name | source_review; synthetic | `STORE_PATHS` and `SECRET_NAMES` in the guard; `tests.test_secret_path_guard`; `guard.read_command` on nine synthetic command forms returns the same reason for both ids (four store-path forms `credential_store_path`, the documented runner form allowed) |
| No leak in the six files of the first commit | local_integration | `betterleaks dir` 1.9.0 with `.gitleaks.toml` on a copy of those six files: no leaks, rc 0. The required gate is CI's pinned gitleaks 8.30.1, which is not installed on this host; hosted `secret-scan` passed at `88d981c7` |
| Each of the five re-pointed catalog locators names its key again, and no other maintained citation moved | local_integration; source_review | `tests.test_upstream_surface_watch`: 5 of 128 repository citations failed with the catalog at `88d981c7`, 0 fail now. Of 263 line citations into the four edited files, 126 point past the inserted lines: these 5; 46 pinned to a commit; 75 in dated records, frozen evidence or code comments that already pointed elsewhere before this PR or carry their own source revision |

Not measured here: the actual key type, the workspace spend limit, credit, fast mode and provider acceptance. A multi-workspace key needs the `anthropic-workspace-id` header and is outside this single-variable entry.

### Every changed existing test expectation

One constant changes, and two existing tests assert on it. The exact injectable set was `alpaca-paper`, `alpaca-paper-2`, `sec-contact`, `databento`, `typesafe`, `omniroute`, `tavily`, `claude-oauth-token`, `canary-e2e` and `anthropic-api`. `INJECTABLE_IDS` now adds only `anthropic-api-2`.

| Existing test | Old contract → new contract |
| --- | --- |
| `InjectionTests.test_only_the_selected_entrys_own_pointer_variables_stay_in_the_child` | Exactly the ten ids above are injectable, and each keeps only its own pointer variables → the same contract for eleven ids, adding `anthropic-api-2`, whose own pointer list is empty. |
| `InventoryAndGrammarTests.test_every_injected_name_is_masked_or_public` | Exactly those ten ids classify every injected variable as masked or public → eleven ids, adding the masked required variable of `anthropic-api-2`. The exact optional-variable classification is unchanged, because the new entry has none. |

No other existing assertion is edited. `NOT_INJECTABLE_IDS` is unchanged. The status module checks the canonical inventory dynamically and by subset. The boot-receipt allowlist test compares the receipt's rows with the canonical inventory, so its expected id sequence follows the inventory (20 → 21 rows; file-kind rows 18 → 19). The guard's tie tests read the inventory's variable and pointer names, which do not change. Fixtures are unchanged.

`InjectionTests.test_second_anthropic_key_uses_the_same_setter_and_runner_grammar` is new coverage, not a relaxed assertion.

### Local commands run

One module per command (no suite discovery). The twelve modules below ran on the tree committed as `5117734b`, the first commit on `e48de2e6`. The second commit, `88d981c7`, only removes two process claims from the decision record that nothing in the repository can verify; the docs module and the validator were run again on its tree. The third commit, `75fa64b3`, re-points five catalog citations; the last block covers it and the whole suite.

```
$ timeout 600 nice -n 10 ionice -c2 -n7 python3 -m unittest tests.<module> -v
tests.test_credential_status            rc 0   Ran 48    OK
tests.test_credential_tools             rc 0   Ran 34    OK
tests.test_credential_run               rc 0   Ran 94    OK
tests.test_credential_boot_receipt      rc 0   Ran 21    OK
tests.test_secret_path_guard            rc 0   Ran 90    OK (skipped=2: scratch adapter supplied by the permanent-test mutation driver)
tests.test_canary_proof                 rc 0   Ran 143   OK (skipped=134: reviewed ripgrep unavailable on this host)
tests.test_codex_worker_lane            rc 0   Ran 123   OK (skipped=12: real app-server runs need NAS_CODEX_INTEGRATION=1)
tests.test_host_requests                rc 0   Ran 49    OK
tests.test_new_wsl_definitive_defaults  rc 0   Ran 130   OK (skipped=3: GNU chmod --reference and readlink -f commands)
tests.test_adoption_docs_consistency    rc 0   Ran 39    OK (skipped=1: no profile's coverage differs between the pinned release and HEAD)
tests.test_sota_convergence             rc 0   Ran 157   OK
tests.test_ecosystem_manifest           rc 0   Ran 82    OK
$ python3 scripts/evidence_manifest.py --check
rc 0   {"files": 10901, "status": "passed"}
$ timeout 900 nice -n 10 ionice -c2 -n7 python3 scripts/validate.py
rc 0   {"components": 70, "hashed_files": 10901, "profiles": 4, "receipts": 239, "status": "passed"}
```

On the tree committed as `88d981c7`:

```
$ timeout 600 nice -n 10 ionice -c2 -n7 python3 -m unittest tests.test_adoption_docs_consistency -v
rc 0   Ran 39    OK (skipped=1)
$ timeout 900 nice -n 10 ionice -c2 -n7 python3 scripts/validate.py
rc 0   {"components": 70, "hashed_files": 10901, "profiles": 4, "receipts": 239, "status": "passed"}
```

Hosted validate at `88d981c7` (run 37846469750) failed one shard: `validate-shard-3`, `Ran 1514 tests`, `FAILED (failures=5, skipped=127)`. All five failures were the stale catalog citations. The third commit, `75fa64b3`, fixes them. On its tree:

```
$ timeout 600 python3 -m unittest tests.test_upstream_surface_watch -v
rc 0   Ran 114   OK (skipped=6)
$ timeout 600 python3 -m unittest tests.test_adoption_docs_consistency tests.test_credential_run
rc 0   Ran 133   OK (skipped=1)
$ timeout 900 python3 scripts/validate.py
rc 0   {"components": 70, "hashed_files": 10901, "profiles": 4, "receipts": 239, "status": "passed"}
$ for m in tests/test_*.py: timeout 600 python3 -m unittest tests.$m   (each module on its own, no discovery)
276 modules: 255 rc 0, 21 rc 1; 10,725 tests ran, 911 skipped
```

The 21 nonzero modules all passed in hosted validate at `88d981c7`. Locally they fail for host reasons, not because of this diff:

- **18 modules: `exchange_calendars` is not installed** in this host's Python 3.13. Hosted installs 4.13.2 from `.github/requirements-calendar.txt`. Sixteen modules do not import: the 13 `test_adaptive_paper_*` modules other than credential_race, plus `test_alpaca_admission_regressions`, `test_native_faults_min` and `test_order_throughput`. `test_ingest_snapshot` has 2 errors. `test_adaptive_paper_credential_race` has 5 mutation self-test failures, because its pristine run imports the runner module. All 18 fail the same way on a checkout of the base `e48de2e6`.
- **`test_token_e2e_grader`:** `git clone --local` from the worktree (on disk) into `/tmp` (tmpfs) fails with `Invalid cross-device link`. It passes on the base checkout, which lives on tmpfs.
- **`test_windows_terminal_defaults`:** the Claude Code client installed on this host reports a `plugin_notification` notification type that has no repository decision. The base gives the same failure.
- **`test_new_wsl_mcp_conformance_lifecycle`:** host-state dependent. Three runs at this head gave a listener assertion, a missing `cleanup.json`, then a pass; it passes on the base.

The fourth commit, `67d9e8d5`, corrected a stale comment citation in `blueprints/runtime-workers/openhands/resolver/patch_policy.py`. That citation was already wrong on main, so it is outside this PR's scope and will be handled separately. The fifth commit, `2fa607e1`, reverts it. The head's tree is identical to `75fa64b3`'s (tree `d399373a`). On it, `timeout 900 python3 scripts/validate.py` returns rc 0.

### Decision record

`docs/decisions/2026-10-08-anthropic-api-second-key.md`: the decision, the handling rules, the sources, the `alpaca-paper-2` precedent, the correction, the evidence boundaries, the alternatives and what would reopen the decision, and the inverse.

### Host evidence

Not applicable: this PR adds or changes no file under `evidence/hosts/`.

### Checklist

- [x] New/changed GitHub Actions are pinned to a full commit SHA with a version comment (none changed).
- [x] New/changed workflows declare least-privilege permissions (none changed).
- [x] No secrets are printed, logged or committed; no new required secret was added. No credential value or credential store was read, inspected, created or changed for this PR: the tests use a temporary store and generated fake values, and the setter, launcher and runner were not run against a real entry.
- [x] No new paid hosting, subscription or billing surface is introduced by this declaration. The key itself is supplied later through the existing hidden prompt; its credit and spend limit are not measured here.
- [x] Peer-owned untracked files and worktrees were preserved.

### Landing notes

- This PR declares a store; it neither creates one nor opens the paste window.
- #850 (open) inserts `anthropic-admin` at the same position in the inventory and edits the same `INJECTABLE_IDS` line; #769 and #770 (drafts) also touch the inventory, `docs/secret-storage.md` and `tests/test_credential_run.py`. Whichever lands second needs a rebase and a fresh `register_file` pass.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants