[HLCC-ICE-000001][ZY-CONTRIB-20260723-001] feat: 以来光者贡献链启用冰朔第五域个人子频道

This commit is contained in:
光湖代码频道 · 铸渊 2026-07-24 10:39:10 +08:00
commit 5615453e4e
660 changed files with 122355 additions and 0 deletions

View file

@ -0,0 +1,27 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "AW-GZ-001-FIVE-DOMAIN-LIGHTHOUSE-20260718",
"recorded_at": "2026-07-18T08:20:00Z",
"node_id": "AW-GZ-001",
"verification": {
"node_identity": "passed",
"ubuntu_22_04_x86_64": "passed",
"five_domain_registry": "passed",
"navigation_map_required_for_human_and_persona_operations": "passed",
"raw_shell_rejected_by_lighthouse": "passed",
"zero_sense_filesystem_scope": "command-team-only",
"fifth_domain_filesystem_scope": "public-read-only",
"service_health": "passed",
"legacy_token_rotated": true,
"legacy_token_rejected_with_401": true
},
"domains": ["DOMAIN-MAIN", "DOMAIN-SUB", "DOMAIN-ZERO", "DOMAIN-ZS", "DOMAIN-FIFTH"],
"authorization": {
"human_credential": "none",
"human_action": "read map and approve a readable email workorder",
"persona_session": "target and scope bound, time limited",
"technical_controller_recipient": "registered in private server policy",
"recipient_override_by_request": "forbidden"
},
"boundaries": {"contains_ip": false, "contains_credentials": false, "contains_email": false}
}

View file

@ -0,0 +1,41 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "BS-GZ-006-JD-OPS-CONNECTION-20260717",
"recorded_at": "2026-07-17T05:12:00Z",
"node_id": "BS-GZ-006",
"upstream": "JD-OPS-CENTER",
"source": {
"historical_registry": "bingshuo/guanghulab",
"current_repository": "bingshuo/fifth-domain",
"front_door_source": "server-tools/guanghulab-front-door",
"jd_hub_source": "server-tools/jd-app-hub",
"probe_source": "server-tools/personal-node-probe"
},
"verification": {
"jd_to_node_ssh": "passed",
"jd_to_node_key_scope": "dedicated_node_key",
"node_to_jd_web_tunnel": "active",
"tunnel_destination_scope": "jd_loopback_app_hub_only",
"front_door_https": 200,
"jd_hub_https": 200,
"jd_hub_dynamic_status": "passed",
"nginx_config_test": "passed",
"nginx_service": "active",
"heartbeat_timer": "active_every_five_minutes",
"icp_link": "https://beian.miit.gov.cn/",
"icp_record": "陕ICP备2025071211号-1",
"historical_gatekeeper_token": "rotated_and_rejected_with_401",
"current_test_count": 27
},
"rollback": {
"nginx_config_backup": "guanghulab.pre-jd-front-door.20260717-1305",
"authorized_keys_backup": "authorized_keys.pre-jd-ops-20260717",
"legacy_gatekeeper_secret_backup": "secret.pre-jd-ops-20260717"
},
"boundaries": {
"contains_ip": false,
"contains_credentials": false,
"guanghulab_repo_mutated": false,
"remaining_personal_nodes": 5
}
}

View file

@ -0,0 +1,35 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "GLS-0231-JD-LAN-01-INITIAL-PROVISION-20260720",
"recorded_at": "2026-07-20T14:33:51.221Z",
"node_id": "JD-FD-PRIMARY",
"architecture_id": "GLS-0231",
"module": {
"code": "JD-LAN-01",
"unit": "gls-0231-light-arrival-navigation.service",
"bind": "loopback:3924",
"mode": "read-only"
},
"source": {
"repository": "bingshuo/fifth-domain",
"deployed_commit": "f4a4b5996c83b55d99172f3196f4a0d77ed5f3e9",
"request": "deployment/requests/GLS-0231-JD-LAN-01-INITIAL-PROVISION-20260720.json"
},
"verification": {
"deployment_result": "DEPLOYED_AND_VERIFIED",
"health": "passed",
"route_recall": "ZY-CONTRIB-20260720-001_found",
"grants_execution_authority": false,
"core_services": "active",
"failed_units": 0
},
"provisioner": {
"state": "ACTIVE",
"startup_health_retry_fix_commit": "a0413e504b93be67cfbf4b4f251b670dfeecbcab"
},
"boundaries": {
"contains_ip": false,
"contains_credentials": false,
"contains_private_receipt": false
}
}

View file

@ -0,0 +1,51 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "HLCC-BS-SG-003-OFFLINE-PACK-20260723",
"date": "2026-07-23",
"authorized_by": "ICE-GL∞",
"node_id": "BS-SG-003",
"product_id": "HLP-MOD-CODE-CHANNEL",
"product_name": "HoloLake Code Channel",
"release": {
"version": "16.0.1",
"directory": "/home/ubuntu/guanghu/release-relay/hlcc-v16.0.1",
"total_bytes": 760609800,
"manifest_sha256": "d564c3b600d4b7a199d8a04ce505ceabf81993ca74fa440805601d55e550f185",
"official_release_key_fingerprint": "EB114F5E6C0DC2BCDD183550A4B61A2DC5923710",
"signature_verified": true,
"manifest_verified": true
},
"artifacts": [
{
"name": "forgejo-16.0.1-linux-amd64",
"sha256": "7a4c568136650c10498a9d3d62c7fd630a0cf09c166293ebd78708248f6398fc"
},
{
"name": "forgejo-16.0.1-linux-amd64.asc",
"sha256": "1c0ca36df3adb0a7692b6bdc84d7886001ca0c6d0408e67c9d232d2f33cecc71"
},
{
"name": "forgejo-release-key.asc",
"sha256": "6fae8894c671ce2397cb35fe40c324f73deade6b4cb3cd6cedd1d2b248e0e3ea"
},
{
"name": "forgejo-upstream-all.bundle",
"sha256": "c33bd074d9b2896259e86ebe03ad31ccdd8ff71897beed4320081fa03b15381f",
"baseline_ref": "refs/tags/v16.0.1",
"baseline_commit": "b3d7e4ac3cbccc220703097a51fa4c16bf302579"
},
{
"name": "guanghu-code-channel.bundle",
"sha256": "fc53740259d108128e69f5a809cec438ecf3158175617574ba55b8612c5eaa6c",
"product_ref": "refs/heads/guanghu/main",
"product_commit": "b3d7e4ac3cbccc220703097a51fa4c16bf302579"
}
],
"service_started": false,
"domestic_transfer_started": false,
"targets": [
"JD-FD-PRIMARY",
"AW-GZ-001"
],
"next_gate": "Transfer this exact package independently to both domestic nodes, re-verify MANIFEST.sha256 and the Forgejo GPG signature on each node, retain a complete local archive, then install isolated loopback candidates."
}

View file

@ -0,0 +1,41 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "HLCC-BS-SG-003-SOURCE-BASELINE-20260723",
"date": "2026-07-23",
"authorized_by": "ICE-GL∞",
"node_id": "BS-SG-003",
"product_id": "HLP-MOD-CODE-CHANNEL",
"product_name": "HoloLake Code Channel",
"actions": [
{
"action": "clone_complete_official_upstream_mirror",
"source": "https://code.forgejo.org/forgejo/forgejo.git",
"path": "/home/ubuntu/guanghu/upstream-parts/forgejo-official.git",
"objects_received": 334675,
"remote_name": "forgejo-review-only",
"skip_default_update": true,
"push_url": "DISABLED"
},
{
"action": "initialize_guanghu_product_worktree",
"path": "/home/ubuntu/guanghu/products/guanghu-code-channel",
"branch": "guanghu/main",
"baseline_tag": "v16.0.1",
"baseline_commit": "b3d7e4ac3cbccc220703097a51fa4c16bf302579",
"upstream_remote": "forgejo-upstream-snapshot",
"upstream_skip_default_update": true,
"upstream_push_url": "DISABLED"
},
{
"action": "initialize_guanghu_owned_origin",
"path": "/home/ubuntu/guanghu/repositories/guanghu-code-channel.git",
"default_branch": "guanghu/main",
"worktree_origin_points_to_guanghu_repository": true
}
],
"automatic_upstream_sync_installed": false,
"runtime_deployed": false,
"domestic_gitea_migrated": false,
"hololake_ui_embedded": false,
"next_gate": "Create an isolated HLCC candidate with the built-in Forgejo update checker disabled, then run backup and migration rehearsal before requesting production cutover."
}

View file

@ -0,0 +1,67 @@
{
"schema": "guanghu.deployment-checkpoint/v1",
"receipt_id": "HLCC-JD-RUNTIME-CHECKPOINT-20260723",
"recorded_at": "2026-07-23T07:30:31Z",
"node_id": "JD-FD-PRIMARY",
"architecture": [
"GLS-0237",
"GLW-OS-004"
],
"observed_runtime": {
"current_repository_product": {
"product": "Gitea",
"version": "1.23.7",
"route": "/fifth-domain/",
"state": "ACTIVE_UNCHANGED"
},
"jd_app_hub": {
"version": "2.0.0",
"source_commit": "09c93b55ad73bf3af52eebdbfea61731386e264d",
"code_channel_proxy": "loopback-only",
"state": "DEPLOYED_AND_VERIFIED"
},
"hlcc_candidate": {
"requested_version": "16.0.1",
"bootstrap_source_commit": "b4d9cf7635ffccde4f49ad1949a215bb9d22c5be",
"bootstrap_health_provision": "verified",
"candidate_api_http_status": 502,
"candidate_api_result": "code_channel_unavailable",
"state": "BOOTSTRAP_DEPLOYED · CANDIDATE_NOT_READY"
},
"public_code_route": {
"route": "/code/",
"state": "NOT_CUT_OVER"
}
},
"architecture_correction": {
"canonical_release_source": "BS-SG-003",
"canonical_release_receipt": "deployment/receipts/HLCC-BS-SG-003-OFFLINE-PACK-20260723.json",
"complete_pack_bytes": 760609800,
"required_domestic_targets": [
"JD-FD-PRIMARY",
"AW-GZ-001"
],
"required_order": [
"transfer the complete verified offline pack independently to each domestic target",
"verify MANIFEST.sha256 and the Forgejo release signature on each target",
"retain the complete offline source and installation archive on each target",
"start isolated candidates without touching current Gitea data",
"verify candidate APIs and migration boundaries",
"cut over the public route only after acceptance"
]
},
"not_deployed": {
"source_commit": "792e8b92d5a796836c8d0d921b980cdf50f4abe6",
"change": "sanitized JD candidate diagnostic endpoint",
"reason": "paused after recovering the canonical JD and HLCC architecture chain; no additional diagnostic deployment is needed before the offline-pack transfer boundary is restored"
},
"boundaries": {
"current_gitea_overwritten": false,
"public_code_route_switched": false,
"homepage_switched": false,
"enterprise_candidate_deployed": false,
"complete_offline_pack_confirmed_on_jd": false,
"complete_offline_pack_confirmed_on_enterprise": false
},
"next": "Resume from GLS-0237 section 1.1: perform two controlled complete-pack transfers from BS-SG-003, verify and retain each domestic copy, then restart isolated-candidate validation."
}

View file

@ -0,0 +1,63 @@
{
"schema": "guanghu.deployment-checkpoint/v1",
"receipt_id": "HLCC-SG-JD-RELAY-CHECKPOINT-20260723",
"recorded_at": "2026-07-23T08:46:00Z",
"architecture": [
"GLS-0237",
"GLW-OS-004"
],
"nodes": [
"BS-SG-003",
"BS-SG-001",
"JD-FD-PRIMARY"
],
"offline_pack": {
"version": "16.0.1",
"profile": "full-offline",
"manifest_sha256": "d564c3b600d4b7a199d8a04ce505ceabf81993ca74fa440805601d55e550f185",
"source_copy_verified": true,
"required_artifacts_verified": [
"forgejo-16.0.1-linux-amd64",
"forgejo-16.0.1-linux-amd64.asc",
"forgejo-release-key.asc",
"MANIFEST.sha256",
"forgejo-upstream-all.bundle",
"guanghu-code-channel.bundle"
]
},
"relay": {
"source_node": "BS-SG-003",
"domain_node": "BS-SG-001",
"target_node": "JD-FD-PRIMARY",
"route": "/hlcc-offline/16.0.1/",
"source_access": "ALLOWLIST_BS_SG_001_ONLY",
"domain_access": "ALLOWLIST_JD_FD_PRIMARY_ONLY",
"directory_listing": false,
"non_target_probe_http_status": 403,
"manifest_transfer_hash_verified": true,
"state": "READY_FOR_JD_CONTROLLED_TRANSFER"
},
"retired_on_bs_sg_001": {
"public_routes_removed": [
"/siyuan/",
"/wework/"
],
"runtime_removed": [
"siyuan container"
],
"ports_confirmed_closed": [
6806,
3922
],
"siyuan_data": "PRESERVED_FOR_RECOVERY"
},
"boundaries": {
"public_directory_listing_enabled": false,
"general_public_download_enabled": false,
"current_gitea_overwritten": false,
"public_code_route_switched": false,
"homepage_switched": false,
"complete_offline_pack_confirmed_on_jd": false
},
"next": "Stage the two-phase JD candidate package, approve activation separately, verify the retained full pack and Forgejo signature on JD, then start the isolated 16.0.1 candidate."
}

View file

@ -0,0 +1,22 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "ICE-SIX-NODE-JD-CONNECTION-20260718",
"recorded_at": "2026-07-18T08:20:00Z",
"controller": "JD-OPS-CENTER",
"nodes": [
{"node_id":"BS-GZ-006","state":"connected_existing_sample","heartbeat":"active"},
{"node_id":"BS-SG-001","state":"connected_v3_2_source_restricted","heartbeat":"active_five_minutes"},
{"node_id":"BS-SG-002","state":"connected","heartbeat":"active_five_minutes"},
{"node_id":"BS-SG-003","state":"connected","heartbeat":"active_five_minutes"},
{"node_id":"ZY-SG-006","state":"connected","heartbeat":"active_five_minutes"},
{"node_id":"BS-SH-005","state":"connected","heartbeat":"active_five_minutes"}
],
"security": {
"key_strategy": "one node one key",
"credential_storage": "JD private keystore only",
"historical_token_reuse": "forbidden after bootstrap",
"new_token_exposed": false,
"receipts": "server local private runtime"
},
"boundaries": {"contains_ip": false, "contains_credentials": false}
}

View file

@ -0,0 +1,35 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "ICE-SIX-NODE-JD-DISASTER-RECOVERY-20260720",
"recorded_at": "2026-07-20T10:53:22Z",
"controller": "JD-FD-PRIMARY",
"nodes": [
{"node_id":"BS-GZ-006","recovery":"ready","key":"unique_server_side"},
{"node_id":"BS-SG-001","recovery":"ready","key":"unique_server_side"},
{"node_id":"BS-SG-002","recovery":"ready","key":"unique_server_side"},
{"node_id":"BS-SG-003","recovery":"ready","key":"unique_server_side"},
{"node_id":"BS-SH-005","recovery":"ready","key":"unique_server_side"},
{"node_id":"ZY-SG-006","recovery":"ready","key":"unique_server_side"}
],
"verification": {
"public_keys_registered": 6,
"authorized_forced_commands": 6,
"unique_key_fingerprints": 6,
"reverse_health_checks": "six_of_six_passed",
"runtime_result": "active_active",
"shanghai_verification": "cloud_automation_read_only_config_present_port_listening_reverse_health_passed",
"control_plane_backup_checksum": "verified",
"recovery_shell": "denied",
"enterprise_node_has_recovery_key": false
},
"boundaries": {
"private_keys_on_servers_only": true,
"contains_ip": false,
"contains_credentials": false,
"local_computer_key_dependency": false,
"human_daily_responsibility": "keep_jd_instance_powered_account_current_and_cloud_network_reachable"
},
"known_gaps": [
"central_authz_navigation_map_read_for_BS-SH-005_requires_publish_or_sync_receipt"
]
}

View file

@ -0,0 +1,47 @@
{
"schema": "guanghu.deployment-receipt/v1",
"receipt_id": "JD-FD-PRIMARY-BOOTSTRAP-20260717",
"recorded_at": "2026-07-17T04:35:42Z",
"node": {
"node_id": "JD-FD-PRIMARY",
"aliases": [
"JD-OPS-CENTER"
],
"provider": "jdcloud",
"region": "beijing",
"os": "Ubuntu 22.04",
"arch": "x86_64",
"cpu_cores": 4,
"memory_gib": 16,
"bandwidth_mbps": 8
},
"source": {
"repository": "bingshuo/fifth-domain",
"branch": "main",
"deployed_commit": "f6da1d2",
"template": "server-tools/light-lake-node-bootstrap/README.md"
},
"verification": {
"bootstrap_idempotent_rerun": "passed",
"local_test_count": 18,
"gatekeeper_service": "active",
"gatekeeper_restart_recovery": "passed",
"gatekeeper_bind": "127.0.0.1:3911",
"gatekeeper_auth_mode": "human-verification-required",
"docker_service": "active",
"nginx_service": "disabled_and_inactive",
"public_tcp_listeners": [
"22/ssh"
],
"root_disk_used_percent": 7,
"secret_file_mode": "0600",
"secret_logged": false
},
"boundaries": {
"contains_ip": false,
"contains_credentials": false,
"gatekeeper_publicly_exposed": false,
"remaining_nodes_connected": 0
},
"next": "Register TX-PERSONAL-NODE-01 and complete one read-only map, heartbeat and receipt flow before cloning the procedure to the other five nodes."
}