Repository navigation
IBKR paper gateway signs in by itself: stored paper login by pointer, rootless container owner rule in the credential checker, adopted recreate script - #769
Conversation
bf1d143 to
e0c260c
Compare
|
Trading-lane acknowledgement (lane:shared), for the trading path at e0c260c The trading lane acknowledges these changes:
Checked against the trading lane's paper rules:
P2 (trading): add a host guard that refuses unless The acknowledgement covers this head only. A later head needs a new look at the trading path. |
- P2 CodeQL: the recreate test's fake paper-password fixture is renamed (self.tws_fake), so py/clear-text-storage-sensitive-data's name heuristic no longer sees a password. There is no suppression comment, following docs/decisions/2026-09-29-key-management.md:589-598. CI's CodeQL run is the check. - P2 frictionless wording: the recreate script header, the runtime-2604 README, the runbook and the decision record now say the user or an agent runs the script from an interactive shell. Only typing the stored values, once, at the user's private prompt stays the user's step. - P2 trading-lane acknowledgement: TRADING_MODE=paper with READ_ONLY_API=no (orders enabled) is now stated in the decision record, the README and the runbook, with the paper-orders harness README lines that need it, so 5f's acknowledgement can cover it. The PR stays a draft. - P3 rotation: the three inventory rotation strings describe writing a new 0600 file and moving it over the old one, because the user cannot open the chowned password files. - P3 one link: every private_file store now needs exactly one link (hard_link otherwise), including the IBKR login env file. A new test fails against the previous checker. - P3 citation: rootlesskit idtools.go is L48-L83 (the file has 83 lines), and the checker mirrors rootlesskit's static source only (parent.go:375-381 is the auto branch, which asks getsubids first). - P3 vendor org: the decision record notes that the InteractiveBrokers GitHub org ships no gateway container or login automation (only tws-api-public, last pushed 2018-01-23). - P3 rollback: the recreate script prints a rollback command, safe with or without a new container, before it starts the new container. A new test fails against the previous script. - The upstream-surface dispositions follow the shifted docs/secret-storage.md lines (1799, 1801, 1812). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
e0c260c to
b444d14
Compare
… rootless container owner in the credential checker, adopted recreate script On 2026-10-06 (about 01:50Z) the user decided that the passwordless, LLM-native and frictionless workflow they prefer extends to the IBKR paper login, and the command center applied it on NativeStack2604. This brings the repository in line with that host. - adoption/credential-inventory.json: ibkr-gateway becomes the stored paper user ID (private_file, pointer IBKR_PAPER_LOGIN_ENV), joined by ibkr-gateway-tws-password and ibkr-gateway-vnc-password (pointers IBKR_PAPER_TWS_FILE and IBKR_PAPER_VNC_FILE, rootless_container_uid 1000). TWS_USERID joins must_not_be_set. No row is injectable or writable. - scripts/credential_status.py: a row that declares rootless_container_uid may be owned by the host uid its rootless Docker user namespace maps that container uid to, derived from /etc/subuid as rootlesskit v3.1.0 lays the ranges out (first range start plus 999 for uid 1000). Mode 0600 and one link are still required, and only /etc/subuid is read. - scripts/hooks/secret_path_guard.py: the three pointers join POINTER_VARIABLE and TWS_USERID joins SECRET_NAMES. The SHA256SUMS pin moves, and the two adoption pages mark the change after v2026.10.05.1 (the new-WSL handbook and its receipt follow the changed page's digest). - blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh: the command center's recreate script, adopted with every refusal before the first change and its inspect records 0600 outside every Git worktree. - docs/secret-storage.md and docs/decisions/2026-10-06-ibkr-paper-passwordless-login.md: what is stored and where (by pointer), the owner rule, the weekly second factor, rotation, the accepted paper-only risk and the overturn conditions. The five upstream-surface dispositions that cite docs/secret-storage.md lines move with the shifted lines. Sources: gnzsnz/ib-gateway-docker 8a22deaa6cab (ibgateway-latest@10.51.1b) README Configuration and Credentials; IBC 3.24.2 (2be2ecd05d77) userguide.md:586-601; rootlesskit v3.1.0 (62d2101f) pkg/parent/parent.go:401-432 and pkg/parent/idtools/idtools.go:48-85. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- P2 CodeQL: the recreate test's fake paper-password fixture is renamed (self.tws_fake), so py/clear-text-storage-sensitive-data's name heuristic no longer sees a password. There is no suppression comment, following docs/decisions/2026-09-29-key-management.md:589-598. CI's CodeQL run is the check. - P2 frictionless wording: the recreate script header, the runtime-2604 README, the runbook and the decision record now say the user or an agent runs the script from an interactive shell. Only typing the stored values, once, at the user's private prompt stays the user's step. - P2 trading-lane acknowledgement: TRADING_MODE=paper with READ_ONLY_API=no (orders enabled) is now stated in the decision record, the README and the runbook, with the paper-orders harness README lines that need it, so 5f's acknowledgement can cover it. The PR stays a draft. - P3 rotation: the three inventory rotation strings describe writing a new 0600 file and moving it over the old one, because the user cannot open the chowned password files. - P3 one link: every private_file store now needs exactly one link (hard_link otherwise), including the IBKR login env file. A new test fails against the previous checker. - P3 citation: rootlesskit idtools.go is L48-L83 (the file has 83 lines), and the checker mirrors rootlesskit's static source only (parent.go:375-381 is the auto branch, which asks getsubids first). - P3 vendor org: the decision record notes that the InteractiveBrokers GitHub org ships no gateway container or login automation (only tws-api-public, last pushed 2018-01-23). - P3 rollback: the recreate script prints a rollback command, safe with or without a new container, before it starts the new container. A new test fails against the previous script. - The upstream-surface dispositions follow the shifted docs/secret-storage.md lines (1799, 1801, 1812). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
b444d14 to
17a06de
Compare
|
Trading-lane acknowledgement (lane:shared), at b444d14 and at 17a06de 17a06de changes nothing on the trading path. What changed on the trading path since my acknowledgement at e0c260c:
The paper-only properties still hold at this head:
Residual (P2, non-blocking, unchanged): nothing in the script refuses outside the distro that owns the paper gateway. The same container name sits stopped on the other distro, and with This acknowledgement covers the trading path at these two heads only. |
### Scope - Select one default for each logical NativeStack2604 host tool and name every coordinated consumer amendment. This decision exposes the bootstrap/trading/CI pin split without claiming it has already been resolved. - Base commit: `67c6b6f94b456a3a7b5d28bb1fa34625a808d316`. - Lane: exactly `lane:foundation`; this PR remains draft for the command center's cross-family read. - Owned paths: two dated decisions, resolver watch documentation, source/version and partial context-review artifacts, sanitized assignment metadata, evidence registry last. Live bootstrap/profile/install-plan/CI and trading files are not edited. Currency's consumer follow-up starts only after #642/#645 land, or is folded by 5f's request; fixwave-defects owns #723/#776, github-ci-finalize owns the CI uv/hash, and 5f owns the trading gate/digest. The canonical defaults are Node24.21.0,uv0.12.22,gh2.102.0,host Python3.13.16,Codex0.160.1,Claude2.1.292,Harbor0.24.0,Collector0.162.0 andvLLM0.31.0. This is a decision and owner handoff. Claude's ordinary cooldown and Harbor/vLLM qualification remain gates; the trading project's Python3.12.3 remains a separate project requirement. The executable bootstrap consumes pins-linux-x86_64.json, so a profile summary edit alone would leave drift. 5f must fold the uv0.12.22 gate and verified sync-vector digest together. CI's promotion uv/hash and Python's family-versus-patch selection are named explicitly. C5's reopened context audit is ongoing in this same PR: the command center assigned the NativeStack2604 resolver loop to currency. Seven of nine items have primary review evidence; two Codex tagged-source checks remain pending. Nice19 local publication validation passed on the rebase and is rerun for the J805 fixes. No instruction/template file is edited. Preserve unrelated rows, update the three existing document rows by key, and append only newly reviewed name rows. These final catalog changes are pending; the live catalog remains unchanged. ## SOTA sources - [native-agent-stack@0d5e6506:profile defaults:4655](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/adoption/new-wsl-profile.json#L4655), [plan mise pins:6-15](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/evidence/artifacts/new-wsl-install-plan-20261002/mise.toml#L6-L15), [bootstrap artifact consumer:233](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/adoption/bootstrap-linux.sh#L233), [native newer-client preservation:843](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/adoption/bootstrap-linux.sh#L843): exact split and qualified preservation policy. - [Node v24.21.0](https://nodejs.org/en/blog/release/v24.21.0), nodejs/node@955266bf; [uv0.12.22](https://github.com/astral-sh/uv/releases/tag/0.12.22), astral-sh/uv@70fe1196; [gh2.102.0](https://github.com/cli/cli/releases/tag/v2.102.0), cli/cli@fc4b137c; [Python3.13.16](https://www.python.org/downloads/release/python-31316/), python/cpython@cbc944f4: plan-aligned maintained host defaults and release dates. - [Codex rust-v0.160.1](https://github.com/openai/codex/releases/tag/rust-v0.160.1), d27764b8; [Claude v2.1.292](https://github.com/anthropics/claude-code/releases/tag/v2.1.292), release-repository fbe20e00; [Harbor v0.24.0](https://github.com/harbor-framework/harbor/releases/tag/v0.24.0), b53b8134; [Collector v0.162.0](https://github.com/open-telemetry/opentelemetry-collector-contrib/releases/tag/v0.162.0), ae8c5075 and [distribution](https://github.com/open-telemetry/opentelemetry-collector-releases/releases/tag/v0.162.0), f6159a77; [vLLM v0.31.0](https://github.com/vllm-project/vllm/releases/tag/v0.31.0), db9527a4: F12 selected targets, identities and pending gates. - [Trading sync pins:8-9](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/blueprints/us-equities/runtime-2604/sync-trading-2604.sh#L8-L9), [verified vector:84-88](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/blueprints/us-equities/runtime-2604/install-trading-2604.sh#L84-L88), [uv gate:112](https://github.com/seathatflowsinourveins/native-agent-stack/blob/0d5e6506434fab598dee861c749a22e628beb75a/blueprints/us-equities/runtime-2604/install-trading-2604.sh#L112): exact 5f handoff; no trading file edit. C5 primary sources: [Claude memory](https://code.claude.com/docs/en/memory), [skills lifecycle](https://code.claude.com/docs/en/skills#skill-content-lifecycle), [environment reference](https://code.claude.com/docs/en/env-vars), [network trust](https://code.claude.com/docs/en/network-config#ca-certificate-store), [official Codex Markdown AGENTS guide](https://learn.chatgpt.com/docs/agent-configuration/agents-md.md), read2026-10-06; [Claude2.1.292 changelog](https://github.com/anthropics/claude-code/blob/fbe20e00e2851fc01506f54f98a8f0b875af3847/CHANGELOG.md). Installed Claude artifact/byte windows and qualified comparison limits are in review.json; assignment source is resolver-assignment.json. J805 fixes: the residual map covers the exact Codex lane guard, uv CI downloader/hash, generated installer/acceptance/Python selections, Inspect/Scout's Harbor package, producer contract, vLLM/Collector recipes and inactive template. SDK/bundled CLI0.160.0, dedicated SDK interpreter, dated holds, rollback and macOS pins are classified separately. The idleCompaction source now names the actual byte-window line113; row updates are by key, not duplicates. No executable pin/guard is changed by this decision PR. ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | Profile, bootstrap, plan, CI and trading consumers differ | source_review | Immutable main reads and exact linked locators | | Installed host-tool versions match the plan; F12 drift is dated | local_integration, read-only version observation | selection.json; normalized versions and command labels explicitly identified | | Selected default versions have official release identities/dates | source_review | Maintainer release/ref metadata; no downloaded-asset verification or new runtime acceptance | | Every in-scope consumer is named; qualification is not inferred | source_review, independent completeness critic | 0P1/0P2; two P3 provenance refinements corrected | | Publication integrity | local_integration | Nice19 validate.py exit0 after registration; this is integrity/scope evidence only | ### Local commands run ```text Fresh owned worktree creation from origin/main with Worktrunk --no-hooks exit0; hooks skipped for the paper window; original worktrees preserved. Installed --version and cached official release/ref reads exit0; source ledger records normalized versions, not full argv/raw outputs. Independent bounded completeness critic 0P1/0P2; two P3 source/provenance refinements fixed. git diff --check / staged whitespace check exit0. host_receipts.register_file for the two owned new files exit0; registry-only commit LAST. python3 scripts/validate.py Exit0 under the later REBASE-805/J805 authorisation for light checks with the paper session inactive; repeated after J805 evidence registration. ``` ### Open shared-file neighbours #802, #770, #769 and #764 also edit upstream-surface-dispositions.json. Rebase after any lands first and take main's catalog. Preserve unrelated rows, update the three existing document rows by key, and append only newly reviewed name rows. Keep #802's corrected context_management source locator. Queued branches remain 5f-only. This PR remains currency-written and draft while the review completes. J805 checks:6 DispositionCitationTests pass (nice19), actual proposed source113 passes the existing predicate while old line1 is rejected, and bounded independent completeness critic reports no remaining material P2. Source-review findings are not new runtime acceptance. ### Decision record `docs/decisions/2026-10-06-one-host-tool-default.md` names defaults, full residual inventory/exceptions, owners and overturn conditions. `docs/decisions/2026-10-06-harness-context-budget-refresh.md` records the reopened partial C5 review and proposed CC-only sentences. Executable one-pin acceptance remains pending owners' folds. ### Host evidence No evidence/hosts or platform-status change. Version output is not native adoption or a passed new host run. - [ ] Host-receipt validation: not applicable. - [x] Independent source/consumer completeness read recorded. - [x] No platform-status update inferred. ### Checklist - [x] No Actions/workflow permissions change. - [x] No credential values/files read or committed; no new required secret. - [x] No paid hosting/subscription/billing surface. - [x] Peer-owned files, historical receipts, main and other worktrees preserved. - [x] Registry committed last; draft retained. - [x] Nice19 local publication validation passed for the registered J805 content; no native acceptance inferred.
### Scope Complete the reopened C5 source audit: review six names and three instruction documents, retain native defaults for the names, and apply their nine current disposition rows. The unchanged main-catalog watch returned nine unreviewed items; the candidate now returns zero with all document hashes matching. - Base commit: b4e1fa6. Rebase-only after #812 landed; all four C5 content files are byte-identical to the initially published345b8d00. - Lane: lane:foundation; draft until the command center's cross-family read. - Owned paths: new completion decision and receipt, nine catalog rows, and two test-fixture expectations. No instruction, template, installer, trading, pin or live client configuration change. - A21 places completion in this separate PR. #805 stays exactly at23d4366e; its partial decision and recorded observations remain unchanged and are linked by immutable path/commit. - Shared-file neighbours: #802, #813, #770, #769 and #764. Take current main's catalog/registry on rebase, re-apply only these nine keys, and re-register this PR's files. Rebase after #805 lands; no peer branch edits. ## SOTA sources - [openai/codex@rust-v0.160.1/d27764b8 — guardian feature defaults](https://github.com/openai/codex/blob/d27764b82f7118f674371e6d6e76271d9d606edb/codex-rs/features/src/lib.rs#L1666-L1688): both UnderDevelopment/default false. Installed0.160.1 features list agrees. - [Tagged Guardian history guard](https://github.com/openai/codex/blob/d27764b82f7118f674371e6d6e76271d9d606edb/codex-rs/core/src/guardian/reviewer_config.rs#L48-L62) and [root-handoff declaration](https://github.com/openai/codex/blob/d27764b82f7118f674371e6d6e76271d9d606edb/codex-rs/features/src/lib.rs#L333-L334). Unchanged scenario files are source-reviewed, not executed. - [Codex0.160.1 release note](https://github.com/openai/codex/releases/tag/rust-v0.160.1), published2026-10-05, and [anthropics/claude-code@fbe20e00 —2.1.292 changelog](https://github.com/anthropics/claude-code/blob/fbe20e00e2851fc01506f54f98a8f0b875af3847/CHANGELOG.md#L6), alongside the installed-client source proof retained by [#80523d4366](https://github.com/seathatflowsinourveins/native-agent-stack/blob/23d4366e26910ae43783518bd6807625a9e5e409/evidence/artifacts/ns2604-context-audit-20261006/review.json). - Current vendor bodies, reread2026-10-06: [Claude memory](https://code.claude.com/docs/en/memory), [skills](https://code.claude.com/docs/en/skills#skill-content-lifecycle), [environment variables](https://code.claude.com/docs/en/env-vars), [CA trust](https://code.claude.com/docs/en/network-config#ca-certificate-store), and [official Codex AGENTS Markdown](https://learn.chatgpt.com/docs/agent-configuration/agents-md.md). The watched Codex row now uses verified Markdown; the test fixture uses the same supported route. - [Repository hot-file protocol@e28d0eec](https://github.com/seathatflowsinourveins/native-agent-stack/blob/e28d0eec112527ac02659ac23753533b8ed39a73/docs/lanes.md#L94-L105) and [disposition schema](https://github.com/seathatflowsinourveins/native-agent-stack/blob/e28d0eec112527ac02659ac23753533b8ed39a73/docs/upstream-surface-watch.md#L174-L193). ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | Nine source decisions complete; native overrides declined | source_review | New completion review.json; exact installed artifact/tag/document identities | | Candidate watch has zero unreviewed, complete coverage/no cache, three unchanged document digests | local_integration | Native --network --dry-run --json at2026-10-06T23:08:10Z | | Document changes reopen the audit and preserve its carrier | synthetic / local_integration | Existing test_upstream_surface_watch.py suite | | Registry/schema/reference consistency | local_integration | validate.py; no live provider/GPU execution | ### Local commands run All substantive commands ran at nice19/ionice3. - python3 scripts/upstream_surface_watch.py --check-dispositions: exit0,311 rows. - python3 scripts/upstream_surface_watch.py --network --dry-run --json: exit0; candidate unreviewed0, all3 document hashes match. Before application: exit0/unreviewed9, retained separately. - python3 -m unittest discover -s tests -p test_upstream_surface_watch.py: exit0,114 tests,6 skips for optional cached upstream-input checks. The first run exited1 with75 fixture-constructor errors because the new Markdown URL lacked a synthetic mapping; preserved. Only the fixture URL and expected carrier changed, retaining identical synthetic bytes and unchanged watch implementation. - Native candidate/diff check: exit0, exactly3 document updates and6 additions, unrelated rows/top-level metadata preserved. - python3 scripts/validate.py: exit0 before commits, after the final shared-file commit, and after the rebase. Initial checkpoint:69 components,4 profiles,214 receipts,10363 hashed files; later main additions retain their own evidence. Two earlier watch usage failures exit2 before fetch because the long worktree could not fit the160-character details summary. Both are retained; a supported per-invocation Worktrunk short owned path/no-hooks resolves the command without saved settings changes. ### Decision record docs/decisions/2026-10-06-harness-context-budget-completion.md and evidence/artifacts/ns2604-context-audit-completion-20261006/review.json. Keep native defaults; revisit on a supported release and qualified host need, or any changed instruction-body digest. Previous reviewed body bytes were unavailable, so no historical semantic delta is invented. Source review does not establish runtime acceptance or token savings. ### Host evidence No evidence/hosts file, host installation or platform-status change. Local catalog-candidate zero is separate from landed-main or deployed-client state. ### Checklist - [x] No workflow or action changes. - [x] No credential values/raw conversations/private active configurations committed. - [x] No new paid hosting or billing surface. - [x] Peer-owned files/worktrees and immutable observations preserved. - [x] Preserve unrelated rows, update the three existing document rows by key, and append only newly reviewed name rows. - [x] Shared catalog and evidence registry are committed last.
### Scope Route catalog lookup through QMD's lexical queries and bounded document retrieval; use SocratiCode for semantic catalog search at the main checkout's projectPath. Keep reranking available and prohibit qmd embed/pull. Update current maintenance recipes and native instruction carriers through the repository renderers. Existing Serena consumers read its manual before navigation, and jCodeMunch consumers obtain the current guide before a typed route with the actual caller model and execution off. Four existing Claude roles gain only Serena's manual tool. Reviewer/builder keep their no-menu boundary, and a focused read of a known path and line remains valid. This landing repair appends the preregistration's Amendment4 to bind the deliberately changed role bodies and compacts lane-authored RTK explanations within the unchanged compact and startup budgets. The entire composed pre-RTK prefix, upstream awareness, owner's blocks, exact SKILL line, seven exceptions, models and effort are preserved. Prior amendment rows, observations, seals and RUNBOOK bytes remain unchanged. The canonical code-graph rename is prepared as a separate patch and is excluded from this head under command-center ruling081016Z. Main's existing names remain in both templates, the map, fixtures and carriers. The protected lane token requires the owner's word before the rename can land. Until that follow-up, this host's Claude code-graph access is through the vendor's hook channel only; the stale MCP carrier id is a recorded limitation and is not claimed fixed. - Base commit: `c44993b379da25fae923dbbe70188978af5104aa` (verified native source; #803 already landed). - Lane: `lane:foundation`; draft. - Head: `9985e468fa4997d22630714b2fa6a76666e3cda9`. Native bytes: compact 8076 <8192, rendered 9142, three-file startup 20101 <=20103; full Claude block 4087 <=4100. These are byte gates, not token-use measurements. - Owned paths: token-lane carriers and their paired handbook text, minimal manual grants and mirrors, Codex template/rendered copies, native loader/routing/sequence tests, current recipes and generated handbook, append-only decisions/preregistration amendment, follow-up receipts and checksum/registry projections. - ROLE-CARRIER-GAPS and ROLE-GRANTS are separate future work and stay out of this change. Landing path: explicit command-center cue070358Z and fallback ruling081016Z permit one pushed rebase/content repair onto then-current main while #802/#813/#830 land. The co-op performs the new-head delta read with its CI result; the command center ACKs; 5f lands. A further pushed rebase requires the separate dated landing-conflict cue. Host configuration, cutover and fresh-session/working-day acceptance belong to their owners. ## SOTA sources - [QMD v2.8.3 lexical query](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L294), [typed searches/rerank](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L321) and [document retrieval](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L412): native lexical subqueries, retrieval and optional rerank. Rerank defaults true (:334-335). [README maintenance syntax:1033-1037](https://github.com/tobi/qmd/blob/v2.8.3/README.md#L1033-L1037) supplies bounded commands. - [SocratiCode v1.15.0 codebase_search](https://github.com/giancarloerra/SocratiCode/blob/v1.15.0/src/index.ts#L138): semantic search at an absolute projectPath. Owner ruling224125Z selects the routing and preserves rerank-on acceptance; this PR performs no host cutover. - [Serena c6fbd1c5 manual order](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/resources/config/prompt_templates/system_prompt.yml#L5-L6), [manual tool:28-40](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/workflow_tools.py#L28-L40) and [project/session binding:44-49](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/config_tools.py#L44-L49): manual first, active cwd project and returned session id for switches. - [jCodeMunch 1.108.330, 28803366, typed route:446-463](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L446-L463), [guide:4743-4752](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L4743-L4752) and [policy:101-128](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/cli/policy.py#L101-L128): guide-first and typed task/model route. These files are unchanged at target1.108.331/d94049d0. The executable schema corrects the guide's query example; no new adaptive-tier setting or upstream rebuild. - `native-agent-stack@c44993b:tests/test_token_e2e_preregistration.py:637-663,905-909`: later dated role-pin amendment and sealed RUNBOOK contracts. Amendment4 preserves every earlier row/seal and extends the current-row selector. The command center records merge chronology at landing; this is a structural repair and authorizes no run. - [DeusData/codebase-memory-mcp v0.11.0 release](https://github.com/DeusData/codebase-memory-mcp/releases/tag/v0.11.0), the repository's pinned component, and the command center's native-client read-back identify the canonical server name. Its proposed client-key/wire-id/owner-token correction is kept in the separate patch, preserving every payload and strict fixture. Ruling081016Z explicitly keeps main's names in this publication while the owner's instruction-token decision remains open. - RTK explanation provenance: `native-agent-stack@2d849ba` (#726) and `@50b9579` (#389), `adoption/templates/codex.AGENTS.template.md` after its exceptions marker. The eight explanations shorten while all facts and protected bytes remain. Command-center064832Z accepted their class and scoped wording. - Native helpers at `native-agent-stack@c44993b`: `tools/adoption/managed_block.py:169` (`codex_block`), `tools/adoption/codex_roles.py:287` (`f4_block`), `scripts/host_receipts.py:710` (`register_file`), `docs/lanes.md:94-128`. Current generated inventory/handbook and checksum bindings use those repository tools; historical receipts and the frozen catalog passage are preserved. ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | Documented native routing/manual/guide interfaces | source_review | Pinned upstream files above | | Carrier rendering, protected bytes, new body pins and tool ids | local_integration | Existing native helpers, hashes and required modules | | Permission/sequence/byte-mutant/frozen-row controls | synthetic | Existing tests with assertions preserved | | Deployed use and token savings | Pending owner evidence | No model, host apply or working-day measurement in this repair | ### Local commands run ```text $ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_scaffold_repo tests.test_new_wsl_handbook tests.test_adoption_docs_consistency tests.test_codex_agents tests.test_codex_roles tests.test_codex_worker_lane tests.test_token_e2e_preregistration tests.test_new_wsl_client_config.RecordTests tests.test_install_claude_profile tests.test_managed_block tests.test_task_model_routing tests.test_new_wsl_client_config.MapTests tests.test_new_wsl_client_config.AgentGapTests tests.test_new_wsl_client_config.RenderTests tests.test_new_wsl_client_config.ApplyTests.test_the_first_run_writes_what_the_wired_pieces_name_and_nothing_else exit 0; Ran 595 tests in 109.929s; OK (skipped=14) $ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_install_claude_profile tests.test_adoption_docs_consistency tests.test_new_wsl_client_config.RecordTests exit 0; Ran 150 tests in 16.306s; OK (skipped=2) $ CI=true nice -n 19 ionice -c3 node examples/claude-native/workflows/test-envelope.mjs exit 0; SUMMARY passed=254 failed=0 total=254 $ CI=true nice -n 19 ionice -c3 python3 -B tools/adoption/new_wsl_client_config.py --check --markdown exit 0 $ CI=true nice -n 19 ionice -c3 python3 -B scripts/build_new_wsl_handbook.py --check exit 0 ``` The passing 595-test run is retained on unchanged source/assertion inputs from the pre-window checkpoint; the 150-test run checks the concrete relocation-fixture and workflows-README changes in the new main base. Their counts overlap and are not added. The fresh Node run passes 254/254. Strict checksums in both Codex directories and the Claude hook directory, plus `git diff --check`, exit 0. All three Amendment-4 role digests were re-derived in both copies and are unchanged from the previous published head. ```text $ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py exit 0; 69 components, 10,482 hashed files, 4 profiles, 224 receipts, status passed ``` The earlier landing composition used source `630b6ece8485a7710ea51321682d5a12e364e25c` and hot commit `5703ef1061b982078038425fada888fd35153868`; its native checks and source-critic result are retained. The authorized locator follow-up changes only `catalogs/foundation/upstream-surface-dispositions.json` and that file's registry row: the `otel.environment` citation now points to the command at `examples/codex-native/README.md:214`. Source commit `2b36cfee` is followed by registry-last commit `9985e468fa4997d22630714b2fa6a76666e3cda9`, with no further rebase. Claude/Codex instruction bytes, role hashes, historical records, namespace and byte budgets remain unchanged. The registry starts from exact main `c44993b379da25fae923dbbe70188978af5104aa`, registers the same 67 changed-file rows through the native producer, and preserves main's receipt and convergence arrays. The two-file correction passed the 114-test citation module, the two exact failing methods and a second native validator run. The worktree is clean; the shifted-citation scan found no other current target to repair. Historical before/after references remain intact. ```text $ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch exit 0; 114 tests, 6 skipped $ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch.DispositionCitationTests.test_every_cited_line_names_the_key tests.test_upstream_surface_watch.DispositionCitationTests.test_a_dotted_key_has_its_parent_near_the_citation exit 0; 2 tests $ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py exit 0; integrity and scope passed ``` The hosted run at5703 returned two failures in11,495 tests because the documentation locator moved. A reviewed locator still gates when its repository test fails. This follow-up closes that exact contract; it adds no assertion waiver or namespace change. Read-only overlap metadata checked all 47 open PRs, including full file pagination where needed. Source overlaps: #645, #706, #709, #754, #769, #770, #775, #776, #795, #810, #821, #826, #829. Shared registry/checksum paths use the hot-file protocol; no peer branch is changed. Earlier failed CI at3ba ran11,381tests and failed six role-body-pin subcases; its complete failed log is retained privately. The failed 560-test and earlier 595-test preparation runs also remain retained. This repair uses a dated amendment, preserves the older source evidence and strict current-body comparison, and performs no full-suite or provider acceptance run. Validator results are integrity and scope evidence only. ### Decision record `docs/decisions/2026-10-06-qmd-lexical-catalog-instructions.md` and `docs/decisions/2026-10-07-serena-jcodemunch-native-navigation-wiring.md`, with appended clarifications and the new landing follow-up, explain the behavior and limits. The preregistration README gains Amendment4 only; its RUNBOOK and earlier sealed records stay byte-identical. No prior result is recast as a new run. ### Host evidence Repository-only change. No live instruction file, MCP registration, hook trust, client setting, gateway setting/key or model session changed. Source/render checks and synthetic fixtures remain distinct from the configuration owner's read-back and organic-use acceptance. ### Checklist - [x] No GitHub Actions or paid service change. - [x] No credentials, raw conversations or live client configuration committed. - [x] Models, effort, owner's blocks and historical observations preserved. - [x] Peer-owned worktrees and source preserved. - [x] Native validation passed; changed checksums/registry committed last at the final head.
### Scope Restore the handbook test's live publication binding so a later profile or handbook regeneration updates its own maintained receipt, instead of editing #826's dated landing record. - Base commit: `6d252c9c102e575bc9229bf6bb2149409655d5f3`; head: `4d2ce2a7719adca918025ffde295ef1dfa30bf02`. - Lane: `lane:foundation`; draft. - Exactly four paths: `tests/test_new_wsl_handbook.py` (one receipt-path line), `evidence/artifacts/new-wsl-handbook-20261001/receipt.json` (current computed binding plus one appended regeneration), its one-line `README.md`, and registry last. - The generator, profile, both generated outputs, hash/inventory assertions, existing receipt observations/history and #826's dated record stay byte-identical. - **Named landing path:** co-op cross-family exact-head read, hosted validate, command center CI read and cue; **right after #820, ahead of #775**. ONE replay at that cue if #820 changes main; full test phase in that landing turn. Hold this draft head for the reads. ## SOTA sources - `native-agent-stack@6d252c9:tests/test_new_wsl_handbook.py:1672-1691`: the publication contract checks actual current generator/profile/output hashes and inventory, with byte-change negative controls. Its comment says hashes follow regeneration. Only its receipt locator changes. - Same pin, `evidence/artifacts/new-wsl-handbook-20261001/receipt.json:268,656,700`: the receipt is a current hash mirror and prior entries expressly refresh mutable producer/output bindings while preserving observations. This existing repository practice fills the publication-binding gap; no new manifest, generator or validator is introduced. - Same pin, `docs/acceptance-evidence-policy.md:59-65` and `docs/landscape-domain-notes.md:33,38`: retain historical inputs/results/failures/pins. All prior receipt fields, regeneration prefix and `previous_outputs` are retained; #826's dated record remains historical. - Same pin, `docs/lanes.md:94-115`: main-copy/own-registration protocol; `scripts/host_receipts.py:710` updates the three own hashes and inserts the README, in the registry-only final commit. ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | Existing strict publication contract passes at the maintained binding | `local_integration`, `synthetic` | 87 handbook tests, exit 0; existing byte-change negative controls unchanged. | | Actual generated bytes are current | `local_integration` | Native builder `--check`, exit 0; MD a1a0cb17… and JSON a42c8915… as recorded in the appended regeneration. | | Dated records/history/other test assertions preserved | `source_review`, `local_integration` | Exact base-file/JSON comparison, exit 0; independent bounded source critic ACK. | | Publication integrity after registry-last commit | `local_integration` | `validate.py` before/after, exit 0; 69 components, four profiles, 224 receipts, 10,508 hashes. | ### Local commands run All checks use the owned external TMPDIR, `nice -n 19 ionice -c3` and closed stdin. ```text python3 -B scripts/build_new_wsl_handbook.py --check exit 0, status passed; current outputs unchanged. python3 -B -m unittest tests.test_new_wsl_handbook exit 0: Ran 87 tests in 37.368s; OK. Exact unchanged-field, regeneration-prefix, dated-record and one-test-line comparison exit 0; all preservation controls true. python3 -B scripts/validate.py exit 0 before and after final registry commit; 10508 file hashes. git diff --check exit 0. ``` The scoped cached open-PR check found 44 open PRs and these overlapping neighbours: #645, #754, #769, #770, #810 on the maintained receipt; #776 and #810 on the test. The CC assigned this narrow critical-path repair before later regeneration PRs. No peer head or file is edited by this lane. ### Decision record The CC's J-HANDBOOK-BINDING ruling supplies the bounded disposition. The one-line receipt README identifies the maintained current-state carrier. No old decision or dated observation is rewritten, and no extra decision file is added to this small unit. ### Host evidence No host/client/installation or acceptance-status changes. These checks establish the repository publication contract, not upstream model or native host acceptance. ### Landing read fields The intentional main-test edit is `tests/test_new_wsl_handbook.py:1677`, disposed of in advance by the CC for this exact receipt rebind. Name it in `main-tests=` at the landing read. Declare every actual post-read/replay change in `adapted=`; the full-suite phase is deferred to the landing turn. Nothing is re-pointed to a new dated path. ### Checklist - [x] Existing current-state receipt reused; earlier observations and dated record preserved. - [x] Only one test line changes; assertions, producer and profile unchanged. - [x] Own entries registered last; required local checks pass. - [x] No workflow, dependency, paid surface or credential change. - [x] Draft and one foundation label; named read/ACK/queue path.
### Scope - What this PR changes: it adds the optional `anthropic-api-2` entry directly after `anthropic-api` in `adoption/credential-inventory.json`, so one command can select an additional Console key. It is an additional key: nothing is replaced. The setter, the runner and the guard are unchanged: the setter and the runner read the inventory, and the guard's rules already cover the variable and the whole store directory. Both entries declare only `ANTHROPIC_API_KEY`, which stays in `must_not_be_set`. - Base commit: `e48de2e6fa1dd3b740af4793ea5824ea35476dba` - Lane: `lane:foundation` - Owned paths touched: `adoption/credential-inventory.json`, `docs/secret-storage.md`, `docs/decisions/2026-10-08-anthropic-api-second-key.md`, `docs/harness-defaults.md`, `tests/test_credential_run.py`, `catalogs/foundation/upstream-surface-dispositions.json`, and `manifests/evidence.json` (the hashes of those six files, written by `scripts/host_receipts.py:register_file`). The new entry differs from the first in exactly six fields: `id`, `label`, `store.path_template` (file `anthropic-api-2.env` in the same directory), `loaders`, `rotation` and `notes`. Class, status, lane, variables, optional and pointer variables, consumers and store kind are identical. The repository precedent is `alpaca-paper-2` (#481, `c26800f3`). **Scope beyond the brief.** Four edits go beyond adding the entry. They are declared here so that the read of this PR covers them: 1. **One sentence of the first entry's `notes` is corrected.** Old: "exported in a shell it would override every Claude Code session's native sign-in". New: "a shell export can switch Claude Code from subscription sign-in to API billing (headless mode uses the key when present; interactive mode first asks for approval)". Source: Claude Code's [environment variables](https://code.claude.com/docs/en/env-vars#variables) page, where a present key is always used in non-interactive mode (`-p`) and is approved once in interactive mode before it overrides the subscription. The new entry gives the same reason, so the two entries agree. No other field of `anthropic-api` changes. 2. **One row is added to the anti-pattern log of `docs/harness-defaults.md`.** It records that correction, which that page's "Record a correction the same turn" rule asks for. 3. **`docs/secret-storage.md` gains the first key's table row as well.** The entry table had no `anthropic-api` row. It now lists both entries, followed by one paragraph on selecting a key for one command. 4. **Five line citations into `docs/secret-storage.md` are updated in `catalogs/foundation/upstream-surface-dispositions.json`,** because the added rows moved the cited lines down by 18. The `source` locators of `CLAUDE_CODE_ENABLE_TELEMETRY` (1697 → 1715), `OTEL_LOG_USER_PROMPTS` and `OTEL_LOG_ASSISTANT_RESPONSES` (1684 → 1702), and `OTEL_LOG_TOOL_CONTENT` and `OTEL_LOG_RAW_API_BODIES` (1686 → 1704) change; no disposition or reason does. Hosted `validate-shard-3` failed five subtests of `DispositionCitationTests.test_every_cited_line_names_the_key` at `88d981c7`; #858 made the same repair for its own insertion. ### SOTA sources Public primary documentation, fetched 2026-10-08; every cited anchor resolves. - Anthropic [API overview, Getting API keys](https://platform.claude.com/docs/en/api/overview#getting-api-keys) and [Authentication, Create and use a key](https://platform.claude.com/docs/en/manage-claude/authentication#create-and-use-a-key): keys are created on the Console key page, the client SDKs pick up `ANTHROPIC_API_KEY` automatically, and a key scoped to one workspace needs no workspace header. - Anthropic [Get your API key, Choose a key type](https://platform.claude.com/docs/en/get-api-key#choose-a-key-type), [Workspaces, API keys and resource scoping](https://platform.claude.com/docs/en/manage-claude/workspaces#api-keys-and-resource-scoping) and [Set workspace limits](https://platform.claude.com/docs/en/manage-claude/workspaces#set-workspace-limits): personal, service-account and legacy workspace keys; a multi-workspace key needs the `anthropic-workspace-id` header; spend limits are set per workspace. - Claude Code [environment variables](https://code.claude.com/docs/en/env-vars#variables) and [authentication precedence](https://code.claude.com/docs/en/authentication#authentication-precedence): in non-interactive mode (`-p`) a present key is always used; in interactive mode the key is approved once before it overrides the subscription. These support the corrected wording. - Anthropic [WIF reference, Profile configuration file](https://platform.claude.com/docs/en/manage-claude/wif-reference#profile-configuration-file): the configuration-profile alternative that the decision record names. - [This repository at `c9ab2212142398234b6ba39a4cf33c5c2a6a643e`](https://github.com/seathatflowsinourveins/native-agent-stack/tree/c9ab2212142398234b6ba39a4cf33c5c2a6a643e), the reference implementation this change follows; the cited files are unchanged at the base commit: inventory entries `anthropic-api` (#841, `a35369aa`) and `alpaca-paper-2`; `tools/credentials/set_credential.py:load_entry`; `tools/credentials/credential_run.py:find_entry` and `injectable`; the guard's `SECRET_NAMES`, `STORE_PATHS` and `ENV_FILE_WORD` in `scripts/hooks/secret_path_guard.py`; the `RunnerCase` fixtures in `tests/test_credential_run.py`; `scripts/host_receipts.py:register_file` and `scripts/validate.py`. No credential runtime or dependency is added. ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | The Console key and environment contract, and the mode-dependent sign-in wording | source_review | The official pages linked above, fetched 2026-10-08 | | The new entry differs from the first in six fields only; the inventory goes from 20 to 21 entries and from 10 to 11 injectable ids; of `anthropic-api`, only `notes` changes | source_review | Field-by-field comparison of both entries against `origin/main`, using the runner's own `injectable()` | | The setter and the runner select separate files, leave the first file unchanged when the second is written, accept the same bare and quoted grammar, inject only the selected value and refuse expansion | local_integration; synthetic | `InjectionTests.test_second_anthropic_key_uses_the_same_setter_and_runner_grammar`: temporary store, generated fake values | | The guard needs no edit: it lists no ids, its store rule covers the whole store directory, and the variable is already a guarded name | source_review; synthetic | `STORE_PATHS` and `SECRET_NAMES` in the guard; `tests.test_secret_path_guard`; `guard.read_command` on nine synthetic command forms returns the same reason for both ids (four store-path forms `credential_store_path`, the documented runner form allowed) | | No leak in the six files of the first commit | local_integration | `betterleaks dir` 1.9.0 with `.gitleaks.toml` on a copy of those six files: no leaks, rc 0. The required gate is CI's pinned gitleaks 8.30.1, which is not installed on this host; hosted `secret-scan` passed at `88d981c7` | | Each of the five re-pointed catalog locators names its key again, and no other maintained citation moved | local_integration; source_review | `tests.test_upstream_surface_watch`: 5 of 128 repository citations failed with the catalog at `88d981c7`, 0 fail now. Of 263 line citations into the four edited files, 126 point past the inserted lines: these 5; 46 pinned to a commit; 75 in dated records, frozen evidence or code comments that already pointed elsewhere before this PR or carry their own source revision | Not measured here: the actual key type, the workspace spend limit, credit, fast mode and provider acceptance. A multi-workspace key needs the `anthropic-workspace-id` header and is outside this single-variable entry. ### Every changed existing test expectation One constant changes, and two existing tests assert on it. The exact injectable set was `alpaca-paper`, `alpaca-paper-2`, `sec-contact`, `databento`, `typesafe`, `omniroute`, `tavily`, `claude-oauth-token`, `canary-e2e` and `anthropic-api`. `INJECTABLE_IDS` now adds only `anthropic-api-2`. | Existing test | Old contract → new contract | | --- | --- | | `InjectionTests.test_only_the_selected_entrys_own_pointer_variables_stay_in_the_child` | Exactly the ten ids above are injectable, and each keeps only its own pointer variables → the same contract for eleven ids, adding `anthropic-api-2`, whose own pointer list is empty. | | `InventoryAndGrammarTests.test_every_injected_name_is_masked_or_public` | Exactly those ten ids classify every injected variable as masked or public → eleven ids, adding the masked required variable of `anthropic-api-2`. The exact optional-variable classification is unchanged, because the new entry has none. | No other existing assertion is edited. `NOT_INJECTABLE_IDS` is unchanged. The status module checks the canonical inventory dynamically and by subset. The boot-receipt allowlist test compares the receipt's rows with the canonical inventory, so its expected id sequence follows the inventory (20 → 21 rows; file-kind rows 18 → 19). The guard's tie tests read the inventory's variable and pointer names, which do not change. Fixtures are unchanged. `InjectionTests.test_second_anthropic_key_uses_the_same_setter_and_runner_grammar` is new coverage, not a relaxed assertion. ### Local commands run One module per command (no suite discovery). The twelve modules below ran on the tree committed as `5117734b`, the first commit on `e48de2e6`. The second commit, `88d981c7`, only removes two process claims from the decision record that nothing in the repository can verify; the docs module and the validator were run again on its tree. The third commit, `75fa64b3`, re-points five catalog citations; the last block covers it and the whole suite. ``` $ timeout 600 nice -n 10 ionice -c2 -n7 python3 -m unittest tests.<module> -v tests.test_credential_status rc 0 Ran 48 OK tests.test_credential_tools rc 0 Ran 34 OK tests.test_credential_run rc 0 Ran 94 OK tests.test_credential_boot_receipt rc 0 Ran 21 OK tests.test_secret_path_guard rc 0 Ran 90 OK (skipped=2: scratch adapter supplied by the permanent-test mutation driver) tests.test_canary_proof rc 0 Ran 143 OK (skipped=134: reviewed ripgrep unavailable on this host) tests.test_codex_worker_lane rc 0 Ran 123 OK (skipped=12: real app-server runs need NAS_CODEX_INTEGRATION=1) tests.test_host_requests rc 0 Ran 49 OK tests.test_new_wsl_definitive_defaults rc 0 Ran 130 OK (skipped=3: GNU chmod --reference and readlink -f commands) tests.test_adoption_docs_consistency rc 0 Ran 39 OK (skipped=1: no profile's coverage differs between the pinned release and HEAD) tests.test_sota_convergence rc 0 Ran 157 OK tests.test_ecosystem_manifest rc 0 Ran 82 OK $ python3 scripts/evidence_manifest.py --check rc 0 {"files": 10901, "status": "passed"} $ timeout 900 nice -n 10 ionice -c2 -n7 python3 scripts/validate.py rc 0 {"components": 70, "hashed_files": 10901, "profiles": 4, "receipts": 239, "status": "passed"} ``` On the tree committed as `88d981c7`: ``` $ timeout 600 nice -n 10 ionice -c2 -n7 python3 -m unittest tests.test_adoption_docs_consistency -v rc 0 Ran 39 OK (skipped=1) $ timeout 900 nice -n 10 ionice -c2 -n7 python3 scripts/validate.py rc 0 {"components": 70, "hashed_files": 10901, "profiles": 4, "receipts": 239, "status": "passed"} ``` Hosted validate at `88d981c7` (run 37846469750) failed one shard: `validate-shard-3`, `Ran 1514 tests`, `FAILED (failures=5, skipped=127)`. All five failures were the stale catalog citations. The third commit, `75fa64b3`, fixes them. On its tree: ``` $ timeout 600 python3 -m unittest tests.test_upstream_surface_watch -v rc 0 Ran 114 OK (skipped=6) $ timeout 600 python3 -m unittest tests.test_adoption_docs_consistency tests.test_credential_run rc 0 Ran 133 OK (skipped=1) $ timeout 900 python3 scripts/validate.py rc 0 {"components": 70, "hashed_files": 10901, "profiles": 4, "receipts": 239, "status": "passed"} $ for m in tests/test_*.py: timeout 600 python3 -m unittest tests.$m (each module on its own, no discovery) 276 modules: 255 rc 0, 21 rc 1; 10,725 tests ran, 911 skipped ``` The 21 nonzero modules all passed in hosted validate at `88d981c7`. Locally they fail for host reasons, not because of this diff: - **18 modules: `exchange_calendars` is not installed** in this host's Python 3.13. Hosted installs 4.13.2 from `.github/requirements-calendar.txt`. Sixteen modules do not import: the 13 `test_adaptive_paper_*` modules other than credential_race, plus `test_alpaca_admission_regressions`, `test_native_faults_min` and `test_order_throughput`. `test_ingest_snapshot` has 2 errors. `test_adaptive_paper_credential_race` has 5 mutation self-test failures, because its pristine run imports the runner module. All 18 fail the same way on a checkout of the base `e48de2e6`. - **`test_token_e2e_grader`:** `git clone --local` from the worktree (on disk) into `/tmp` (tmpfs) fails with `Invalid cross-device link`. It passes on the base checkout, which lives on tmpfs. - **`test_windows_terminal_defaults`:** the Claude Code client installed on this host reports a `plugin_notification` notification type that has no repository decision. The base gives the same failure. - **`test_new_wsl_mcp_conformance_lifecycle`:** host-state dependent. Three runs at this head gave a listener assertion, a missing `cleanup.json`, then a pass; it passes on the base. The fourth commit, `67d9e8d5`, corrected a stale comment citation in `blueprints/runtime-workers/openhands/resolver/patch_policy.py`. That citation was already wrong on main, so it is outside this PR's scope and will be handled separately. The fifth commit, `2fa607e1`, reverts it. The head's tree is identical to `75fa64b3`'s (tree `d399373a`). On it, `timeout 900 python3 scripts/validate.py` returns rc 0. ### Decision record `docs/decisions/2026-10-08-anthropic-api-second-key.md`: the decision, the handling rules, the sources, the `alpaca-paper-2` precedent, the correction, the evidence boundaries, the alternatives and what would reopen the decision, and the inverse. ### Host evidence Not applicable: this PR adds or changes no file under `evidence/hosts/`. ### Checklist - [x] New/changed GitHub Actions are pinned to a full commit SHA with a version comment (none changed). - [x] New/changed workflows declare least-privilege permissions (none changed). - [x] No secrets are printed, logged or committed; no new required secret was added. No credential value or credential store was read, inspected, created or changed for this PR: the tests use a temporary store and generated fake values, and the setter, launcher and runner were not run against a real entry. - [x] No new paid hosting, subscription or billing surface is introduced by this declaration. The key itself is supplied later through the existing hidden prompt; its credit and spend limit are not measured here. - [x] Peer-owned untracked files and worktrees were preserved. ### Landing notes - This PR declares a store; it neither creates one nor opens the paste window. - #850 (open) inserts `anthropic-admin` at the same position in the inventory and edits the same `INJECTABLE_IDS` line; #769 and #770 (drafts) also touch the inventory, `docs/secret-storage.md` and `tests/test_credential_run.py`. Whichever lands second needs a rebase and a fresh `register_file` pass. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Scope
ecfa112764c664d35377dd66b8cfcb67e5a94d60(origin/main when the branch was cut, and still main at this head)lane:shared. It touches trading paths (blueprints/us-equities/runtime-2604/, the trading testtests/test_ibkr_gateway_recreate.py) and foundation paths (docs/,scripts/,adoption/,tests/), and re-registers files in the shared hot filemanifests/evidence.json(last commit). The trading lane (5f) must acknowledge before merge; the items it covers are listed under "Acknowledgement requested from the trading lane". The PR stays a draft until then.adoption/credential-inventory.jsonadoption/hooks/claude/SHA256SUMSadoption/bootstrap.mdadoption/platforms/linux-wsl2-new-distro.mdblueprints/us-equities/runtime-2604/README.mdblueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh(new)docs/decisions/2026-10-06-ibkr-paper-passwordless-login.md(new)docs/secret-storage.mdscripts/credential_status.pyscripts/hooks/secret_path_guard.pytests/test_credential_run.pytests/test_credential_status.pytests/test_credential_tools.pytests/test_ibkr_gateway_recreate.py(new)tests/test_secret_path_guard.pycatalogs/foundation/upstream-surface-dispositions.json(five line citations follow the shifteddocs/secret-storage.mdlines)docs/new-wsl-handbook.mddocs/new-wsl-handbook.jsonevidence/artifacts/new-wsl-handbook-20261001/receipt.json(regenerated; the edited adoption page's digest)manifests/evidence.json(registration only, last commit)Commits:
80340ee3(content),bc5064e7(review fixes for the command center's read ate0c260ca) andb444d148(registration, last).What changes
docs/secret-storage.md. Theibkr-gatewayrow (line 28) said the login is typed at sign-in and nothing is stored. It now says the paper login is stored:0600files with one link each, named by pointer only:IBKR_PAPER_LOGIN_ENV,IBKR_PAPER_TWS_FILEandIBKR_PAPER_VNC_FILE.A new section, "IBKR paper gateway sign-in (2026-10-06)", covers the rest. The pickup block gains the three pointer exports, and the Checker and Rotation sections are updated.
adoption/credential-inventory.json.ibkr-gatewaybecomes the stored user ID: classbroker_login, statusoptional, aprivate_filestore and pointerIBKR_PAPER_LOGIN_ENV. Two new rows,ibkr-gateway-tws-passwordandibkr-gateway-vnc-password, declarerootless_container_uid: 1000.TWS_USERIDjoinsmust_not_be_set. Rotation replaces a file (write a new0600file, move it over the old one), because the user cannot open the chowned password files. The rule thatTWS_*andIBKR_*values never reach workers is kept:credential_run.py) or writable (set_credential.py);TWS_USERIDreference.scripts/credential_status.py. For a row that declaresrootless_container_uid(only the two password files), the owner may be the host uid that rootless Docker maps that container uid to: this user's first/etc/subuidstart plus 999 for uid 1000./etc/subuidat run time, parsed as rootlesskit v3.1.0's static source parses it. A missing or malformed file fails closed.0600is still required. Everyprivate_filestore, the IBKR login env file included, needs exactly one link; a second name is the new findinghard_link./etc/subuidis opened, never a credential file.--subuid PATHserves the test fixtures.blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.shadopts the command center's host script. The user or an agent runs it from an interactive shell (bash -i); only typing the stored values, once, at the user's private prompt is the user's own step. It keeps the client-connection refusal, the rollback rename and the chown inside the user namespace, and adds:umask 077;It runs the paper account with orders enabled (
TRADING_MODE=paper,READ_ONLY_API=no). Itsdocker inspectrecords hold the user ID. They go to a new0700directory of0600files under${XDG_STATE_HOME:-$HOME/.local/state}/native-agent-stack/ibkr-gateway/, never inside a checkout.scripts/hooks/secret_path_guard.py. The three pointers joinPOINTER_VARIABLE, astests/test_secret_path_guard.py:2337-2346(atecfa1127) requires for every inventory pointer, andTWS_USERIDjoins the baseSECRET_NAMES. TheSHA256SUMSpin moves. The two adoption pages mark it as changed afterv2026.10.05.1.docs/decisions/2026-10-06-ibkr-paper-passwordless-login.mdrecords the decision, the upstream sources (with the vendor-organization check), what is stored and where (by pointer), the orders-enabled setting, the weekly second factor, the accepted paper-only risk, the alternatives and what would overturn it.Pointer-convention finding (no rename, no user item). The question was whether
worker_env_check.shorcredential_status.pytreats theIBKR_PAPER_*pointer names as forbidden. Line numbers are at baseecfa1127.credential_status.pydoes not. It comparesmust_not_be_setby exact name (scripts/credential_status.py:550) againstTWS_USERNAME,TWS_PASSWORD,TWS_ACCOUNTandIBKR_ACCOUNT_ID(adoption/credential-inventory.json:406).worker_env_check.shrecords any^(APCA|ALPACA|TWS|IBKR)_name as a broker variable (blueprints/gap-wave2-20260923/us-equities__security-supply-chain/worker_env_check.shlines 24, 49 and 61). That is a names-only measurement with no gate, and it is the recorded command of the gap-wave2 receipts 8 and 14, so it stays unchanged.SECRET_NAMESis exact too. ItsPOINTER_VARIABLEmust list every inventory pointer.docs/secret-storage.md:TWS_*andIBKR_ACCOUNT_IDas the IBKR names that stay unset;~/.bashrcchange.Acknowledgement requested from the trading lane (5f)
docs/lanes.md:148-150requires the trading lane's acknowledgement, as a comment or review on this PR, before merge. It should cover:TRADING_MODE=paperandREAD_ONLY_API=no(blueprints/us-equities/runtime-2604/ibkr-gateway-recreate-durable.sh), so any API client on 127.0.0.1:4002 can place paper orders from the moment the container starts.blueprints/us-equities/engine-nautilus/ibkr-paper-orders/README.mdL121). Before this, the user unticked it by hand (L246-L249 for 2026-09-23, L345 for 2026-10-05).READ_ONLY_API=yes(blueprints/us-equities/engine-nautilus/ibkr-acceptance/README.mdL15-L16).tests/test_ibkr_gateway_recreate.py, whichdocs/lanes.md:50classes as a trading test (test_ibkr_*.py).blueprints/us-equities/runtime-2604/: the adopted script and its README section.Review round: the command center's read at
e0c260ca(ACK_AFTER)py/clear-text-storage-sensitive-dataalerts (#95, #96) on a synthetic fixtureself.password→self.tws_fake), so CodeQL's name heuristic no longer sees a password. No suppression comment, followingdocs/decisions/2026-09-29-key-management.md:589-598. Verified onb444d148at 06:08Z: all six CodeQL analyses report 0 results, #95 and #96 arefixedonrefs/pull/769/head, and the CodeQL check reads "No new alerts in code changed by this pull request". GitHub resolved both github-advanced-security review threads itself.tests/test_ibkr_gateway_recreate.py0600file, move it over the old one, rerun the script. The runbook adds a "replace, never edit in place" line.adoption/credential-inventory.json; runbookhard_linkcheck now covers everyprivate_filestore, including the IBKR login env file and the generated host keys. A new test fails against the previous checker (2 subtests) and passes now. Docs updated.scripts/credential_status.py;tests/test_credential_status.py; runbook Checker sectionidtools.gocitation L48-L85 runs past the end of the file62d2101f). The comment now says the checker mirrors rootlesskit's static source only; theautobranch (parent.goL375-L381) asksgetsubidsfirst.scripts/credential_status.py;tests/test_credential_status.py; decision record; this bodygh api 'orgs/InteractiveBrokers/repos?per_page=100'on 2026-10-06 returns onlytws-api-public, last pushed 2018-01-23).docker run -d. The command works with or without a new container. A new test with a failing stub start fails against the previous script and passes now.tests/test_ibkr_gateway_recreate.py; README; runbook; decision recordThe five upstream-surface disposition citations follow the shifted
docs/secret-storage.mdlines (now 1799, 1801 and 1812).SOTA sources
8a22deaa6cab86f9ad5c86ff4f0d6efbef718f10, which is tagibgateway-latest@10.51.1b(gh api repos/gnzsnz/ib-gateway-docker/git/matching-refs/tags/ibgateway-latest@10.51):TWS_USERIDL181,TWS_PASSWORD_FILEL183,VNC_SERVER_PASSWORD_FILEL190,TWOFA_TIMEOUT_ACTIONL191,AUTO_RESTART_TIMEL195,RELOGIN_AFTER_TWOFA_TIMEOUTL199,EXISTING_SESSION_DETECTED_ACTIONL200 andTWS_SETTINGS_PATHL203._FILEform.latest/Dockerfile:IBC_VERSION=3.24.2at L13 andUSER_ID1000 at L67.InteractiveBrokers/tws-api-public, last pushed 2018-01-23 (gh api 'orgs/InteractiveBrokers/repos?per_page=100', 2026-10-06). gnzsnz/ib-gateway-docker with IBC fills that gap.2be2ecd05d7707f97479fda9ad098fdcc15ab807:userguide.mdL586-L601: AutoRestart restarts without re-authentication, giving "a single authentication at the start of the week", and the session expires on Sunday.62d2101fbbe4f79bc845a337c4e868d27ff602c9. This host's rootless Docker Engine 29.8.2 reports rootlesskit 3.1.0.pkg/parent/parent.goL401-L432: container uid 0 maps to the user, and the subordinate ranges follow from container uid 1.autobranch, which asksgetsubidsfirst.pkg/parent/idtools/idtools.goL48-L83: the static/etc/subuidparser, which the checker mirrors.shellcheck-py, run throughuvxwith a scratch-only cache: no findings in the adopted script. The command center's original exits 1 under the same check.c26800f3) added a pointer toPOINTER_VARIABLEtogether with its inventory row, and moved theSHA256SUMSpin.docs/decisions/2026-09-29-key-management.md:589-598renamed a CodeQL-flagged fixture variable without a suppression comment.Evidence-class table
ibkr-gatewayisok,ibkr-gateway-tws-passwordandibkr-gateway-vnc-passwordareokwithowner=rootless_container_user, all three with one link;result ok,values_read: false. At base the three files were undeclared store files and the IBKR row wasnot_localnative_provenpython3 scripts/credential_status.py --json→ exit 0private_filerow needs one link; no credential file is openedsyntheticpython3 -m unittest tests.test_credential_statusss, connected client, empty pointer target), keeps the rollback rename and the namespace chown, prints the rollback before the new start, and writes its records 0600synthetic(stubdocker,ssandsleep; the real daemon is never reached)python3 -m unittest tests.test_ibkr_gateway_recreateTWS_USERIDreference are refused; docker loaders,statandwcpass; bare docker reads are recorded pass-throughs; still a superset of the pinned baselineslocal_integrationpython3 -m unittest tests.test_secret_path_guard: 89 of 90 pass. The one failure compares this host's installed guard and is skipped in CIlocal_integrationpython3 -m unittest tests.test_credential_run tests.test_credential_toolsLocal commands run
All commands ran on NativeStack2604 in the owned worktree. The head is
b444d148.This round, on the review fixes (
bc5064e7) and their registration:Earlier rounds.
bf1d143c(1516 s): exit 1, with 10357 tests, failures=12, errors=18 and skipped=903.ecfa1127on this host. I re-ran each failing module in a detached base worktree:exchange_calendarsis not installed here (16 adaptive-paper and trading modules, plus 2test_ingest_snapshottests);test_adoption_launchd,test_adoption_bootstrap,test_adoption_guarded_runnersandtest_windows_terminal_defaultsfailures;test_adaptive_paper_credential_racefailures;git clone --localintest_token_e2e_grader.validateone0c260casucceeded (check run 112109930442, 05:05:37Z). The command center's read reports that its suite ran 11361 tests, OK with 1026 skipped.80340ee3:validate.pyexited 1 on a literal home path in the script.test_adoption_docs_consistencyexited 1 twice: first a missing "changed after" marker, then a link to the decision record before it existed.CI that this PR does not cause. The required
osv-scannercheck fails repo-wide on new advisories in lockfiles that this PR does not touch:Main needs a fix, and this PR then needs a new head.
Decision record
docs/decisions/2026-10-06-ibkr-paper-passwordless-login.mdnames the evidence, the alternatives (typing at each sign-in, aTWS_PASSWORDenvironment value, Compose secrets, the kernel keyring, renaming the pointers) and what would overturn it.Host evidence
Not applicable: no file under
evidence/hosts/changes.python3 scripts/host_receipts.py validatepasses for every new/changed receipt. (No receipt changes.)scripts/host_receipts.py review) or explicitly requested in this PR. (No receipt changes.)platform_statuschange is made from a host receipt alone.Items for the coordinator and the user
~/.bashrcneeds no change.osv-scannerfixed on main, then give this PR a new head through the hot-file protocol.python3 tools/adoption/install_claude_profile.py --only guardfrom the merged checkout.fd516d8b) does not refuse readers on the three pointers.credential_status.py --client-guardsand the boot receipt reportclaude_user_guard_matches_pin=false, and the localtest_host_profile_copy_is_verbatimfails. CI skips that test.reportandackledger rows.Checklist
permissions: {}and grant each job only what it needs (contents: read, or an explicitly justified addition). (No workflow changes.)lstatand/etc/subuidonly, and the command center's inspect records were never opened.🤖 Generated with Claude Code