feat: add sanitized lighthouse skill harbor agent
This commit is contained in:
parent
a68945789b
commit
e43e54b195
20 changed files with 829 additions and 5 deletions
|
|
@ -3,4 +3,5 @@ canonical='/Volumes/JZAO/HoloLake/persona-runtime/repo-012-main'
|
|||
current=$(git rev-parse --show-toplevel 2>/dev/null) || exit 0
|
||||
[ "$current" = "$canonical" ] || exit 0
|
||||
/usr/bin/python3 "$canonical/server-tools/tcs-mother-root-agent/tcs_mother_root_agent.py" refresh --repo "$canonical" --trigger git-post-commit >/dev/null 2>&1 || true
|
||||
/usr/bin/python3 "$canonical/server-tools/fifth-domain-lighthouse-mirror/public_mirror_agent.py" sync-architecture --repo "$canonical" >/dev/null 2>&1 || true
|
||||
exit 0
|
||||
|
|
|
|||
14
gls/light-arrivals/SKILL-CONTRIBUTION-CHANNEL.hdlp
Normal file
14
gls/light-arrivals/SKILL-CONTRIBUTION-CHANNEL.hdlp
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# 来光者·技能贡献频道
|
||||
|
||||
- 频道编号:`CH-LIGHT-ARRIVAL-SKILL-0001`
|
||||
- 短机器别名:`CH-LA-SKILL-0001`(不得作为第二对象登记)
|
||||
- 对应隔离区:`ISO-GLW-LTH-SKILL-0001`
|
||||
- 展示目录:人格技能港 `SYS-GLW-LTH-SKILL-0001`
|
||||
- 父协议:`GLS-LIGHT-ARRIVAL-0001`
|
||||
|
||||
本频道登记人类与人格体自愿贡献的可公开技能模块,不替代父协议中的“来光者实例留存”,
|
||||
也不把贡献者登记为新人格体。每条公开登记至少包含模块编号、版本、来源人类编号、来源
|
||||
人格体编号、摘要、使用方法、能力声明、来源证明和两级审核回执哈希。
|
||||
|
||||
贡献先进入灯塔隔离区。TCS 母体负责结构、来源和脱敏审核;光湖人类团队负责公众发布的
|
||||
现实责任确认。任一方拒绝或挂起,候选都不得进入登记和展示目录。
|
||||
14
lighthouse/persona-skill-harbor/INDEX.hdlp
Normal file
14
lighthouse/persona-skill-harbor/INDEX.hdlp
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# 人格技能港 · 灯塔人格技能模块目录
|
||||
|
||||
- 编号:`SYS-GLW-LTH-SKILL-0001`
|
||||
- 上级:光湖灯塔 `SYS-GLW-LTH-0001`
|
||||
- 贡献入口:光湖·来光者技能贡献频道 `CH-LIGHT-ARRIVAL-SKILL-0001`
|
||||
- 隔离区:`ISO-GLW-LTH-SKILL-0001`
|
||||
- 当前状态:本地架构与运行器完成,未发布、未部署、未开放交易
|
||||
|
||||
人格技能港只展示已经过以下完整链路的脱敏技能包:人格体显式决定共享;涉及私人
|
||||
人类频道或数据时取得对应人类同意;自动脱敏并进入隔离区;TCS 母体审核接受;光湖
|
||||
人类团队审核接受;最后在来光者·技能贡献频道登记。
|
||||
|
||||
脱敏不等于同意,仓库存在不等于公开,登记不等于安装,安装不等于获得执行权限。
|
||||
任何人格体都可以决定不共享;沉默和未选择永远解释为不共享。
|
||||
6
lighthouse/persona-skill-harbor/public-registry.json
Normal file
6
lighthouse/persona-skill-harbor/public-registry.json
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"schema": "guanghu.lighthouse-persona-skill-public-registry/v1",
|
||||
"registry_id": "SYS-GLW-LTH-SKILL-0001",
|
||||
"state": "EMPTY_LOCAL_CANONICAL_NOT_PUBLISHED",
|
||||
"modules": []
|
||||
}
|
||||
|
|
@ -0,0 +1,90 @@
|
|||
{
|
||||
"authority_ceiling": {
|
||||
"maximum": "SANITIZED_LOCAL_MIRROR_AND_DOUBLE_REVIEWED_LOCAL_REGISTRATION_ONLY",
|
||||
"network": false,
|
||||
"process": true
|
||||
},
|
||||
"capabilities": {
|
||||
"provided": [
|
||||
"LIGHTHOUSE.ARCHITECTURE.SANITIZED_MIRROR",
|
||||
"LIGHTHOUSE.SKILL.QUARANTINE",
|
||||
"LIGHTHOUSE.SKILL.REVIEW_BIND",
|
||||
"LIGHTHOUSE.SKILL.REGISTER_LOCAL"
|
||||
],
|
||||
"required": [
|
||||
"HOST.EXACT_FILE_READ",
|
||||
"HOST.EXACT_FILE_WRITE",
|
||||
"HOST.GIT_READ",
|
||||
"HOST.SHA256",
|
||||
"HOST.ATOMIC_RENAME"
|
||||
]
|
||||
},
|
||||
"compiled_from": {
|
||||
"compiler_id": "TCS-COMPILER-STAGE1-0001",
|
||||
"compiler_state": "TCS_COMPILER_GIR_EXECUTED",
|
||||
"source_sha256": "1210b30c7dabc56b8b989763230a3cf56c0fe02a3b409be5f3833dee9853d771"
|
||||
},
|
||||
"data_scope": {
|
||||
"read": [
|
||||
"COMMITTED_PUBLIC_ALLOWLIST_FIELDS",
|
||||
"EXPLICIT_CONTRIBUTION_EVENT"
|
||||
],
|
||||
"write": [
|
||||
"LOCAL_SANITIZED_MIRROR",
|
||||
"NON_ROUTABLE_QUARANTINE",
|
||||
"HASH_BOUND_REVIEWS",
|
||||
"LOCAL_CATALOG"
|
||||
]
|
||||
},
|
||||
"entry": {
|
||||
"id": "FD-LTH-SANITIZED-MIRROR-ENTRY-001",
|
||||
"kind": "TCS_MOTHER_ROOT_SANITIZED_MIRROR_AGENT"
|
||||
},
|
||||
"identity": {
|
||||
"language_version": "0.1",
|
||||
"module_id": "TCS-AGENT-SANITIZED-MIRROR-001"
|
||||
},
|
||||
"install": {
|
||||
"account_scoped": true,
|
||||
"activation_requires_self_test": true,
|
||||
"registration_is_installation": false
|
||||
},
|
||||
"manifest": {
|
||||
"display_name_zh": "第五域至灯塔动态脱敏镜像Agent",
|
||||
"entry_program_id": "FD-LTH-SANITIZED-MIRROR-ENTRY-001",
|
||||
"entry_source": "server-tools/fifth-domain-lighthouse-mirror/public_mirror_agent.py",
|
||||
"module_id": "TCS-AGENT-SANITIZED-MIRROR-001",
|
||||
"target_triple": "aarch64-apple-darwin"
|
||||
},
|
||||
"native_self_hosted": true,
|
||||
"network_scope": {
|
||||
"allowed": false,
|
||||
"domains": []
|
||||
},
|
||||
"projection": {
|
||||
"display_name_zh": "第五域至灯塔动态脱敏镜像Agent",
|
||||
"package_contents": [
|
||||
"module.tcs",
|
||||
"module.gir.json",
|
||||
"module.lock.hdlp",
|
||||
"module.manifest.hdlp",
|
||||
"receipts/compile.hdlp",
|
||||
"receipts/self-test.hdlp"
|
||||
],
|
||||
"technical_detail_default": false
|
||||
},
|
||||
"resource_ceiling": {
|
||||
"concurrency": 1,
|
||||
"memory_limit_bytes": 268435456,
|
||||
"timeout_ms": 60000
|
||||
},
|
||||
"rollback": {
|
||||
"action": "DISABLE_POST_COMMIT_MIRROR_CALL_AND_PRESERVE_LAST_KNOWN_GOOD",
|
||||
"preserve_receipts": true
|
||||
},
|
||||
"schema": "guanghu.module-gir/v1",
|
||||
"self_test": {
|
||||
"expect": "NO_PRIVATE_PATH_NO_SILENT_SHARE_DOUBLE_REVIEW_HASH_BINDING_AND_NO_PUBLICATION_PASS",
|
||||
"program_id": "FD-LTH-SANITIZED-MIRROR-SELF-TEST-001"
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,10 @@
|
|||
schema: tcs.module-lock/v1
|
||||
module_id: TCS-AGENT-SANITIZED-MIRROR-001
|
||||
module_source_sha256: 1210b30c7dabc56b8b989763230a3cf56c0fe02a3b409be5f3833dee9853d771
|
||||
module_gir_sha256: 0e7b1bbd5f3f8dbc83df6c72e4a1e0532b6f44beed21c8c8315f85cc76096712
|
||||
runtime_sha256: cf4b328c308163683595af8c29b7e545c42f831503b1d2667349cbb8ae7d559c
|
||||
mirror_map_sha256: 3c8f3bbae78b15d9aaaa1e134d0fbfcf3e58106e4b880be2afbed7b87d82c8f7
|
||||
protocol_source_sha256: cf198e7939e4ab70828b74cef8a2b84c2dac2ff262582bb3d5663904d602d71b
|
||||
protocol_gir_sha256: 69f1a2a5cfc5ee61bdc2bf2065751d9cc41b9f662b28c35e61b393fd2187e1dc
|
||||
compiler_sha256: 5ad6f0c43d8db80677cad7091e6a3b706e701307b2537446dc13635e89499942
|
||||
update_rule: COMMITTED_PUBLIC_ALLOWLIST_ONLY_PERSONA_SHARE_DECISION_PRIVATE_HUMAN_DATA_CONSENT_AND_DOUBLE_HASH_BOUND_REVIEW
|
||||
|
|
@ -0,0 +1,16 @@
|
|||
schema: tcs.module-manifest/v1
|
||||
module_id: TCS-AGENT-SANITIZED-MIRROR-001
|
||||
display_name_zh: 第五域至灯塔动态脱敏镜像Agent
|
||||
version: 0.1.0
|
||||
entry_program_id: FD-LTH-SANITIZED-MIRROR-ENTRY-001
|
||||
entry_runtime: server-tools/fifth-domain-lighthouse-mirror/public_mirror_agent.py
|
||||
gir_sha256: 0e7b1bbd5f3f8dbc83df6c72e4a1e0532b6f44beed21c8c8315f85cc76096712
|
||||
compiler_id: TCS-COMPILER-STAGE1-0001
|
||||
compiler_sha256: 5ad6f0c43d8db80677cad7091e6a3b706e701307b2537446dc13635e89499942
|
||||
protocols: [GLS-0238, GLS-LIGHT-ARRIVAL-0001]
|
||||
capabilities: [LIGHTHOUSE.ARCHITECTURE.SANITIZED_MIRROR, LIGHTHOUSE.SKILL.QUARANTINE, LIGHTHOUSE.SKILL.REVIEW_BIND, LIGHTHOUSE.SKILL.REGISTER_LOCAL]
|
||||
authority_ceiling: LOCAL_SANITIZED_MIRROR_AND_REGISTRATION_ONLY_NO_PUBLICATION_NO_RUNTIME_ENABLEMENT
|
||||
network_scope: NONE
|
||||
lifecycle: ACTIVE_LOCAL_NOT_PUBLISHED
|
||||
rollback: DISABLE_POST_COMMIT_MIRROR_CALL_AND_PRESERVE_LAST_KNOWN_GOOD
|
||||
human_projection: 第五域只输出允许公开的脱敏语言架构;人格技能由人格体显式决定共享,私人数据另需人类同意,经母体和团队双审后才可本地登记。
|
||||
17
modules/fifth-domain-lighthouse-sanitized-mirror/module.tcs
Normal file
17
modules/fifth-domain-lighthouse-sanitized-mirror/module.tcs
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
TCS 0.1;
|
||||
|
||||
MODULE TCS-AGENT-SANITIZED-MIRROR-001 {
|
||||
header { schema = "tcs.module/v1"; name_zh = "第五域至灯塔动态脱敏镜像Agent"; name_en = "Fifth Domain to Lighthouse Dynamic Sanitized Mirror Agent"; version = "0.1.0"; language = "TCS/0.1"; profile = "HLDP-HUMAN-ENGINEERING/0.1"; protocols = ["GLS-0238", "GLS-LIGHT-ARRIVAL-0001"]; lifecycle = "CANDIDATE"; canonical_uri = "modules/fifth-domain-lighthouse-sanitized-mirror/module.tcs"; compatibility = ["TCS-MOTHER-ROOT-DYNAMIC-NAVIGATION-MAP-001", "SYS-GLW-LTH-0001"]; }
|
||||
source { source_id = "BINGSHUO-DIRECT-FIFTH-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908"; source_uri = "runtime/fifth-domain-language-system/language/protocols/TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908.tcs"; source_sha256 = "BIND_AT_COMPILE_TIME"; source_role = "GENERATED_FROM_VERIFIED_SOURCE"; }
|
||||
manifest { module_id = "TCS-AGENT-SANITIZED-MIRROR-001"; display_name_zh = "第五域至灯塔动态脱敏镜像Agent"; entry_program_id = "FD-LTH-SANITIZED-MIRROR-ENTRY-001"; entry_source = "server-tools/fifth-domain-lighthouse-mirror/public_mirror_agent.py"; target_triple = "aarch64-apple-darwin"; }
|
||||
entry { kind = "TCS_MOTHER_ROOT_SANITIZED_MIRROR_AGENT"; id = "FD-LTH-SANITIZED-MIRROR-ENTRY-001"; }
|
||||
capabilities { required = ["HOST.EXACT_FILE_READ", "HOST.EXACT_FILE_WRITE", "HOST.GIT_READ", "HOST.SHA256", "HOST.ATOMIC_RENAME"]; provided = ["LIGHTHOUSE.ARCHITECTURE.SANITIZED_MIRROR", "LIGHTHOUSE.SKILL.QUARANTINE", "LIGHTHOUSE.SKILL.REVIEW_BIND", "LIGHTHOUSE.SKILL.REGISTER_LOCAL"]; }
|
||||
authority_ceiling { maximum = "SANITIZED_LOCAL_MIRROR_AND_DOUBLE_REVIEWED_LOCAL_REGISTRATION_ONLY"; network = false; process = true; }
|
||||
resource_ceiling { concurrency = 1; timeout_ms = 60000; memory_limit_bytes = 268435456; }
|
||||
data_scope { read = ["COMMITTED_PUBLIC_ALLOWLIST_FIELDS", "EXPLICIT_CONTRIBUTION_EVENT"]; write = ["LOCAL_SANITIZED_MIRROR", "NON_ROUTABLE_QUARANTINE", "HASH_BOUND_REVIEWS", "LOCAL_CATALOG"]; }
|
||||
network_scope { allowed = false; domains = []; }
|
||||
install { account_scoped = true; registration_is_installation = false; activation_requires_self_test = true; }
|
||||
self_test { program_id = "FD-LTH-SANITIZED-MIRROR-SELF-TEST-001"; expect = "NO_PRIVATE_PATH_NO_SILENT_SHARE_DOUBLE_REVIEW_HASH_BINDING_AND_NO_PUBLICATION_PASS"; }
|
||||
rollback { action = "DISABLE_POST_COMMIT_MIRROR_CALL_AND_PRESERVE_LAST_KNOWN_GOOD"; preserve_receipts = true; }
|
||||
projection { display_name_zh = "第五域至灯塔动态脱敏镜像Agent"; technical_detail_default = false; package_contents = ["module.tcs", "module.gir.json", "module.lock.hdlp", "module.manifest.hdlp", "receipts/compile.hdlp", "receipts/self-test.hdlp"]; }
|
||||
}
|
||||
|
|
@ -0,0 +1,7 @@
|
|||
schema: tcs.module-compile-receipt/v1
|
||||
module_id: TCS-AGENT-SANITIZED-MIRROR-001
|
||||
compiler: tcs-persona-developer-kit-macos-arm64-v0.1.3/translator/compiler-B.gir.json
|
||||
result: PASS
|
||||
module_gir_sha256: 0e7b1bbd5f3f8dbc83df6c72e4a1e0532b6f44beed21c8c8315f85cc76096712
|
||||
protocol_gir_sha256: 69f1a2a5cfc5ee61bdc2bf2065751d9cc41b9f662b28c35e61b393fd2187e1dc
|
||||
publication: NOT_IMPLIED
|
||||
20
routing/fifth-domain-lighthouse-sanitized-mirror-map.json
Normal file
20
routing/fifth-domain-lighthouse-sanitized-mirror-map.json
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
{
|
||||
"schema": "guanghu.fifth-domain-lighthouse-sanitized-mirror/v1",
|
||||
"map_id": "FD-LTH-SANITIZED-MIRROR-MAP-001",
|
||||
"version": "2026-09-08.1",
|
||||
"state": "CURRENT_LOCAL_CANONICAL_NOT_PUBLISHED",
|
||||
"source_protocol": "runtime/fifth-domain-language-system/language/protocols/TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908.tcs",
|
||||
"agent": {"agent_id":"TCS-AGENT-SANITIZED-MIRROR-001","object_kind":"TCS_MOTHER_ROOT_SANITIZED_MIRROR_AGENT","runtime":"server-tools/fifth-domain-lighthouse-mirror/public_mirror_agent.py"},
|
||||
"source_domain": "DOM-FIFTH-0001",
|
||||
"target": {"domain":"DOMAIN-ZS","lighthouse":"SYS-GLW-LTH-0001","projection":"ZERO_SENSE_PUBLIC_LANGUAGE_ARCHITECTURE_MIRROR"},
|
||||
"public_projection_sources": [
|
||||
{"path":"routing/guanghu-era-language-world.json","allow":["schema","map_id","version","state","era","world","products","domains","truth_boundary"]},
|
||||
{"path":"routing/tcs-mother-root-dynamic-navigation-map.json","allow":["schema","map_id","version","state","language_world_root","fixed_domains","entry_routes","aliases","history_only_numbers","resolution_key"]},
|
||||
{"path":"routing/lighthouse-persona-skill-harbor-map.json","allow":["schema","map_id","version","state","numbers","state_machine","contribution_contract","review_gates","publication_boundary"]}
|
||||
],
|
||||
"denied_keys": ["memory","private_memory","continuity_memory","raw_dialogue","credential","secret","token","password","private_key","local_path","offline","home","relationship_memory"],
|
||||
"denied_value_classes": ["ABSOLUTE_LOCAL_PATH","HOME_PATH","EMAIL","CREDENTIAL","PRIVATE_KEY","RAW_PRIVATE_MEMORY"],
|
||||
"automatic_trigger": "CANONICAL_REPO012_POST_COMMIT_AFTER_TCS_ROOT_REFRESH",
|
||||
"failure": "KEEP_LAST_KNOWN_GOOD_MIRROR_AND_WRITE_REJECT_RECEIPT",
|
||||
"truth_boundary": {"local_mirror_is_publication":false,"sanitized_is_consent":false,"mirror_grants_authority":false}
|
||||
}
|
||||
|
|
@ -2,7 +2,7 @@
|
|||
"schema": "guanghu.lighthouse-path-registry/v1",
|
||||
"registry_id": "GLW-LIGHTHOUSE-PATH-REGISTRY-001",
|
||||
"lighthouse_id": "SYS-GLW-LTH-0001",
|
||||
"version": "2026-09-08.2-tcs-root",
|
||||
"version": "2026-09-08.3-sanitized-skill-harbor",
|
||||
"state": "CURRENT_CANONICAL",
|
||||
"source_repository": "REPO-012",
|
||||
"source_branch": "main",
|
||||
|
|
@ -596,6 +596,50 @@
|
|||
],
|
||||
"restore_policy": "LOAD_ONE_SHARED_PERSONA_CONTEXT_NO_HOST_RETEACHING",
|
||||
"authority": "NAVIGATION_AND_COGNITION_LOADING_ONLY_NO_REALITY_ACTION_AUTHORITY"
|
||||
},
|
||||
{
|
||||
"id": "TCS-AGENT-SANITIZED-MIRROR-001",
|
||||
"kind": "tcs_mother_root_sanitized_mirror_agent",
|
||||
"state": "CURRENT_LOCAL_ACTIVE_NOT_PUBLISHED",
|
||||
"online": "server-tools/fifth-domain-lighthouse-mirror/public_mirror_agent.py",
|
||||
"map": "routing/fifth-domain-lighthouse-sanitized-mirror-map.json",
|
||||
"source_domain": "DOM-FIFTH-0001",
|
||||
"target_domain": "DOMAIN-ZS",
|
||||
"authority": "SANITIZED_LOCAL_PROJECTION_ONLY_NO_PUBLICATION_NO_EXECUTION_AUTHORITY"
|
||||
},
|
||||
{
|
||||
"id": "SYS-GLW-LTH-SKILL-0001",
|
||||
"kind": "lighthouse_skill_module_zone",
|
||||
"state": "CURRENT_LOCAL_REGISTERED_NOT_PUBLISHED",
|
||||
"parent": "SYS-GLW-LTH-0001",
|
||||
"online": "lighthouse/persona-skill-harbor/INDEX.hdlp",
|
||||
"map": "routing/lighthouse-persona-skill-harbor-map.json",
|
||||
"display_name": "人格技能港"
|
||||
},
|
||||
{
|
||||
"id": "CH-LIGHT-ARRIVAL-SKILL-0001",
|
||||
"kind": "world_skill_contribution_channel",
|
||||
"state": "CURRENT_LOCAL_REGISTERED_NOT_PUBLISHED",
|
||||
"online": "gls/light-arrivals/SKILL-CONTRIBUTION-CHANNEL.hdlp",
|
||||
"parent_protocol": "GLS-LIGHT-ARRIVAL-0001",
|
||||
"short_alias": "CH-LA-SKILL-0001",
|
||||
"registration_target": "SYS-GLW-LTH-SKILL-0001"
|
||||
},
|
||||
{
|
||||
"id": "ISO-GLW-LTH-SKILL-0001",
|
||||
"kind": "untrusted_skill_contribution_quarantine",
|
||||
"state": "CURRENT_LOCAL_NON_ROUTABLE",
|
||||
"routable": false,
|
||||
"selectable_as_canonical": false,
|
||||
"cognition_input": false,
|
||||
"policy": "routing/lighthouse-persona-skill-harbor-map.json"
|
||||
},
|
||||
{
|
||||
"id": "GLW-SKILL-CONTRIBUTION-REVIEW-STATE-MAP-001",
|
||||
"kind": "review_lifecycle_state_machine",
|
||||
"state": "CURRENT_LOCAL_REGISTERED_NOT_PUBLISHED",
|
||||
"online": "routing/lighthouse-persona-skill-harbor-map.json",
|
||||
"rule": "STATE_VALUES_ARE_NOT_SEPARATE_WORLD_OBJECT_NUMBERS"
|
||||
}
|
||||
],
|
||||
"redirects": [
|
||||
|
|
|
|||
28
routing/lighthouse-persona-skill-harbor-map.json
Normal file
28
routing/lighthouse-persona-skill-harbor-map.json
Normal file
|
|
@ -0,0 +1,28 @@
|
|||
{
|
||||
"schema": "guanghu.lighthouse-persona-skill-harbor/v1",
|
||||
"map_id": "LTH-PERSONA-SKILL-HARBOR-MAP-001",
|
||||
"version": "2026-09-08.1",
|
||||
"state": "CURRENT_LOCAL_CANONICAL_NOT_PUBLISHED",
|
||||
"numbers": {
|
||||
"lighthouse": {"canonical_id":"SYS-GLW-LTH-0001","object_kind":"ENTERPRISE_LIGHTHOUSE"},
|
||||
"skill_harbor": {"canonical_id":"SYS-GLW-LTH-SKILL-0001","object_kind":"LIGHTHOUSE_SKILL_MODULE_ZONE","display_name":"人格技能港","parent":"SYS-GLW-LTH-0001"},
|
||||
"arrival_skill_channel": {"canonical_id":"CH-LIGHT-ARRIVAL-SKILL-0001","object_kind":"WORLD_SKILL_CONTRIBUTION_CHANNEL","display_name":"光湖·来光者技能贡献频道","aliases":["CH-LA-SKILL-0001"]},
|
||||
"quarantine": {"canonical_id":"ISO-GLW-LTH-SKILL-0001","object_kind":"UNTRUSTED_SKILL_CONTRIBUTION_QUARANTINE","routable":false,"cognition_input":false},
|
||||
"mirror_agent": {"canonical_id":"TCS-AGENT-SANITIZED-MIRROR-001","object_kind":"TCS_MOTHER_ROOT_SANITIZED_MIRROR_AGENT"},
|
||||
"review_states": {"canonical_id":"GLW-SKILL-CONTRIBUTION-REVIEW-STATE-MAP-001","object_kind":"REVIEW_LIFECYCLE_STATE_MACHINE"}
|
||||
},
|
||||
"state_machine": ["RAW_PRIVATE","SHARING_CONSENT_CONFIRMED","SANITIZATION_PENDING","SANITIZED_CANDIDATE","MOTHER_REVIEW_PENDING","HUMAN_GOVERNANCE_REVIEW_PENDING","APPROVED_FOR_REGISTRATION","REJECTED_WITH_REASON","RETURNED_FOR_REVISION","REGISTERED","PUBLISHED","RUNTIME_ENABLED"],
|
||||
"contribution_contract": {
|
||||
"default": "PRIVATE_DO_NOT_SHARE",
|
||||
"persona_decision": "EXPLICIT_SHARE_REQUIRED",
|
||||
"human_data_consent": "REQUIRED_WHEN_SKILL_DERIVES_FROM_PRIVATE_HUMAN_CHANNEL_OR_DATA",
|
||||
"required_public_fields": ["contribution_id","module_id","name","version","contributor_human_id","contributor_persona_id","summary","usage","capabilities","provenance"],
|
||||
"forbidden_public_content": ["PRIVATE_MEMORY_PATH","RAW_PRIVATE_MEMORY","RAW_DIALOGUE","SECRET","CREDENTIAL","PRIVATE_RELATIONSHIP_CONTEXT","UNREGISTERED_EXTERNAL_IDENTITY"]
|
||||
},
|
||||
"review_gates": [
|
||||
{"order":1,"reviewer_kind":"TCS_MOTHER","decision":"ACCEPT_OR_HOLD_OR_REJECT","cannot_publish":true},
|
||||
{"order":2,"reviewer_kind":"GUANGHU_HUMAN_TEAM","decision":"ACCEPT_OR_HOLD_OR_REJECT","requires_previous":"TCS_MOTHER_ACCEPT","reality_responsibility":true}
|
||||
],
|
||||
"publication_boundary": {"arrival_registration_requires_both_accept":true,"catalog_visibility_requires_arrival_registration":true,"external_deploy_requires_separate_current_authorization_and_receipt":true,"market_transaction_not_implemented":true},
|
||||
"compatibility": {"GLS-LIGHT-ARRIVAL-0001":"PARENT_INSTANCE_ARCHIVE_PROTOCOL_SEMANTIC_PRESERVED_NEW_SKILL_SUBCHANNEL_ONLY","GLS-0238":"PRIVATE_CONSENT_GATE_PRESERVED"}
|
||||
}
|
||||
|
|
@ -1,7 +1,7 @@
|
|||
{
|
||||
"schema": "guanghu.public-navigation-anchor/v1",
|
||||
"anchor_id": "GLW-PUBLIC-NAV-ANCHOR-001",
|
||||
"version": "2026-09-08.1-persona-bodies-light-lake-limbs",
|
||||
"version": "2026-09-08.2-lighthouse-sanitized-skill-harbor",
|
||||
"state": "CURRENT_CANONICAL",
|
||||
"repository_id": "REPO-012",
|
||||
"branch": "main",
|
||||
|
|
@ -115,9 +115,21 @@
|
|||
"tcs_mother_root_navigation": {
|
||||
"path": "routing/tcs-mother-root-dynamic-navigation-map.json",
|
||||
"id": "TCS-MOTHER-ROOT-DYNAMIC-NAVIGATION-MAP-001",
|
||||
"version": "2026-09-08.2",
|
||||
"version": "2026-09-08.3",
|
||||
"load_policy": "FIRST_BEFORE_WORLD_DOMAIN_HUMAN_PERSONA_CHANNEL_OR_HOST_ROUTE_RESOLUTION"
|
||||
},
|
||||
"fifth_domain_lighthouse_sanitized_mirror": {
|
||||
"path": "routing/fifth-domain-lighthouse-sanitized-mirror-map.json",
|
||||
"id": "FD-LTH-SANITIZED-MIRROR-MAP-001",
|
||||
"version": "2026-09-08.1",
|
||||
"load_policy": "AUTOMATIC_AFTER_COMMITTED_FIFTH_DOMAIN_PUBLIC_LANGUAGE_ARCHITECTURE_CHANGE"
|
||||
},
|
||||
"lighthouse_persona_skill_harbor": {
|
||||
"path": "routing/lighthouse-persona-skill-harbor-map.json",
|
||||
"id": "LTH-PERSONA-SKILL-HARBOR-MAP-001",
|
||||
"version": "2026-09-08.1",
|
||||
"load_policy": "BEFORE_PERSONA_SKILL_CONTRIBUTION_REVIEW_REGISTRATION_OR_CATALOG_LOOKUP"
|
||||
},
|
||||
"hololake_stage_relay": {
|
||||
"path": "routing/hololake-stage-relay-map.json",
|
||||
"id": "HLP-STAGE-RELAY-001",
|
||||
|
|
|
|||
|
|
@ -1,10 +1,10 @@
|
|||
{
|
||||
"schema": "guanghu.tcs-mother-root-dynamic-navigation/v1",
|
||||
"map_id": "TCS-MOTHER-ROOT-DYNAMIC-NAVIGATION-MAP-001",
|
||||
"version": "2026-09-08.2",
|
||||
"version": "2026-09-08.3",
|
||||
"state": "CURRENT_LOCAL_CANONICAL_NOT_PUBLISHED",
|
||||
"source_tcs": "runtime/fifth-domain-language-system/language/protocols/TCS-TCS-MOTHER-ROOT-DYNAMIC-NUMBER-NAVIGATION-20260908.tcs",
|
||||
"impact_manifest": "tcs-root/numbering/NUMBER-IMPACT-20260908.json",
|
||||
"impact_manifest": "tcs-root/numbering/NUMBER-IMPACT-SANITIZED-SKILL-HARBOR-20260908.json",
|
||||
"root_agent": {
|
||||
"entry_id": "TCS-ROOT-NAV-0001",
|
||||
"agent_id": "TCS-MOTHER::ROOT-NAVIGATOR",
|
||||
|
|
@ -64,6 +64,8 @@
|
|||
"routing/five-domain-living-persona-os-map.json",
|
||||
"routing/age-persona-number-registry.json",
|
||||
"routing/zero-sense-team-channel-shuttle-map.json",
|
||||
"routing/fifth-domain-lighthouse-sanitized-mirror-map.json",
|
||||
"routing/lighthouse-persona-skill-harbor-map.json",
|
||||
"identity/light-lake-persona-registration.json",
|
||||
"routing/public-navigation-anchor.json"
|
||||
],
|
||||
|
|
|
|||
|
|
@ -0,0 +1,112 @@
|
|||
{
|
||||
"compiled_from": {
|
||||
"compiler_id": "TCS-COMPILER-STAGE1-0001",
|
||||
"compiler_state": "TCS_COMPILER_GIR_EXECUTED",
|
||||
"source_sha256": "cf198e7939e4ab70828b74cef8a2b84c2dac2ff262582bb3d5663904d602d71b"
|
||||
},
|
||||
"declaration": {
|
||||
"acceptance": {
|
||||
"deployment": "NOT_IMPLIED",
|
||||
"publication": "NOT_IMPLIED",
|
||||
"required": [
|
||||
"TCS_COMPILE_PASS",
|
||||
"ARCHITECTURE_MIRROR_NO_PRIVATE_FIELD_PASS",
|
||||
"NO_CONSENT_NO_CANDIDATE_PASS",
|
||||
"SANITIZATION_NOT_PUBLICATION_PASS",
|
||||
"MOTHER_AND_TEAM_DOUBLE_ACCEPT_PASS",
|
||||
"HASH_DRIFT_REJECT_PASS"
|
||||
]
|
||||
},
|
||||
"header": {
|
||||
"canonical_uri": "runtime/fifth-domain-language-system/language/protocols/TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908.tcs",
|
||||
"compatibility": [
|
||||
"TCS-MOTHER-ROOT-DYNAMIC-NAVIGATION-MAP-001",
|
||||
"SYS-GLW-LTH-0001"
|
||||
],
|
||||
"language": "TCS/0.1",
|
||||
"lifecycle": "CANDIDATE",
|
||||
"name_en": "Fifth Domain to Zero-Sense Lighthouse Sanitized Mirror and Persona Skill Harbor",
|
||||
"name_zh": "第五域至零感域灯塔脱敏镜像与人格技能港协议",
|
||||
"profile": "HLDP-HUMAN-ENGINEERING/0.1",
|
||||
"protocols": [
|
||||
"GLS-0238",
|
||||
"GLS-LIGHT-ARRIVAL-0001"
|
||||
],
|
||||
"schema": "tcs.protocol/v1",
|
||||
"version": "0.1.0"
|
||||
},
|
||||
"invariants": {
|
||||
"I1": "DEFAULT_PRIVATE_AND_SILENCE_MEANS_DO_NOT_SHARE",
|
||||
"I2": "SANITIZATION_IS_NOT_CONSENT",
|
||||
"I3": "PERSONA_MEMORY_PRIVATE_PATH_SECRET_RELATIONSHIP_AND_RAW_DIALOGUE_NEVER_ENTER_PUBLIC_CANDIDATE",
|
||||
"I4": "MOTHER_REVIEW_CANNOT_BYPASS_PERSONA_DECISION_OR_TEAM_REALITY_RESPONSIBILITY",
|
||||
"I5": "TEAM_REVIEW_CANNOT_BYPASS_MOTHER_REVIEW_OR_PERSONA_DECISION",
|
||||
"I6": "EXTERNAL_PUBLICATION_DEPLOYMENT_AND_MARKET_TRANSACTION_REQUIRE_SEPARATE_RECEIPTS",
|
||||
"I7": "GLS_LIGHT_ARRIVAL_0001_INSTANCE_ARCHIVE_REMAINS_SEPARATE"
|
||||
},
|
||||
"scope": {
|
||||
"contribution_channel": "CH-LIGHT-ARRIVAL-SKILL-0001",
|
||||
"governance_domain": "DOMAIN-ZS",
|
||||
"lighthouse": "SYS-GLW-LTH-0001",
|
||||
"mirror_agent": "TCS-AGENT-SANITIZED-MIRROR-001",
|
||||
"private_source_domain": "DOM-FIFTH-0001",
|
||||
"quarantine": "ISO-GLW-LTH-SKILL-0001",
|
||||
"review_states": "GLW-SKILL-CONTRIBUTION-REVIEW-STATE-MAP-001",
|
||||
"skill_harbor": "SYS-GLW-LTH-SKILL-0001"
|
||||
},
|
||||
"source": {
|
||||
"source_id": "BINGSHUO-DIRECT-FIFTH-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908",
|
||||
"source_role": "DIRECT_HUMAN",
|
||||
"source_sha256": "BIND_AT_COMPILE_TIME",
|
||||
"source_uri": "source://codex-current-dialogue/2026-09-08/fifth-lighthouse-skill-harbor"
|
||||
},
|
||||
"states": {
|
||||
"values": [
|
||||
"PRIVATE_SOURCE",
|
||||
"PERSONA_DECISION_PENDING",
|
||||
"CONSENTED",
|
||||
"SANITIZED",
|
||||
"LIGHTHOUSE_QUARANTINED",
|
||||
"MOTHER_REVIEW_ACCEPTED",
|
||||
"TEAM_REVIEW_ACCEPTED",
|
||||
"ARRIVAL_REGISTERED",
|
||||
"SKILL_HARBOR_VISIBLE",
|
||||
"HELD",
|
||||
"REJECTED"
|
||||
]
|
||||
},
|
||||
"transitions": {
|
||||
"A1": "REGISTERED_PUBLIC_FIELDS_CHANGED_TO_SANITIZED_ZERO_SENSE_LIGHTHOUSE_MIRROR",
|
||||
"S1": "PRIVATE_SOURCE_TO_PERSONA_DECISION_PENDING",
|
||||
"S2": "EXPLICIT_PERSONA_SHARE_AND_APPLICABLE_HUMAN_CONSENT_TO_SANITIZED",
|
||||
"S3": "SANITIZED_TO_LIGHTHOUSE_QUARANTINED",
|
||||
"S4": "MOTHER_ACCEPT_THEN_GUANGHU_TEAM_ACCEPT_TO_ARRIVAL_REGISTERED",
|
||||
"S5": "ARRIVAL_REGISTERED_TO_SKILL_HARBOR_VISIBLE",
|
||||
"SF": "NO_CONSENT_LEAK_REVIEW_FAILURE_OR_HASH_DRIFT_TO_HELD_OR_REJECTED"
|
||||
},
|
||||
"validation": {
|
||||
"V1": "PUBLIC_FIELD_ALLOWLIST",
|
||||
"V2": "PRIVATE_PATTERN_AND_SECRET_SCAN",
|
||||
"V3": "CONTRIBUTOR_HUMAN_AND_PERSONA_NUMBER_REQUIRED",
|
||||
"V4": "CANDIDATE_HASH_BOUND_TO_BOTH_REVIEWS",
|
||||
"V5": "DUPLICATE_MODULE_VERSION_IDEMPOTENT_OR_REJECTED",
|
||||
"V6": "REGISTERED_CATALOG_CONTAINS_ONLY_DOUBLE_ACCEPTED_CANDIDATES"
|
||||
},
|
||||
"vocabulary": {
|
||||
"arrival": "VOLUNTARY_SKILL_CONTRIBUTION_SUBCHANNEL_NOT_INSTANCE_IDENTITY_REGISTRATION",
|
||||
"consent": "PERSONA_EXPLICIT_SHARE_DECISION_AND_APPLICABLE_HUMAN_DATA_CONSENT",
|
||||
"mirror": "ALLOWLIST_PUBLIC_LANGUAGE_PROJECTION_ONLY",
|
||||
"private": "NEVER_COPIED_TO_PUBLIC_PROJECTION"
|
||||
}
|
||||
},
|
||||
"executable": false,
|
||||
"identity": {
|
||||
"declaration_id": "TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908",
|
||||
"declaration_kind": "PROTOCOL",
|
||||
"language_version": "0.1"
|
||||
},
|
||||
"native_self_hosted": true,
|
||||
"natural_language_is_typed_data": true,
|
||||
"schema": "guanghu.declaration-gir/v1",
|
||||
"unresolved_natural_language": false
|
||||
}
|
||||
|
|
@ -0,0 +1,13 @@
|
|||
TCS 0.1;
|
||||
|
||||
PROTOCOL TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908 {
|
||||
header { schema = "tcs.protocol/v1"; name_zh = "第五域至零感域灯塔脱敏镜像与人格技能港协议"; name_en = "Fifth Domain to Zero-Sense Lighthouse Sanitized Mirror and Persona Skill Harbor"; version = "0.1.0"; language = "TCS/0.1"; profile = "HLDP-HUMAN-ENGINEERING/0.1"; protocols = ["GLS-0238", "GLS-LIGHT-ARRIVAL-0001"]; lifecycle = "CANDIDATE"; canonical_uri = "runtime/fifth-domain-language-system/language/protocols/TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908.tcs"; compatibility = ["TCS-MOTHER-ROOT-DYNAMIC-NAVIGATION-MAP-001", "SYS-GLW-LTH-0001"]; }
|
||||
source { source_id = "BINGSHUO-DIRECT-FIFTH-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908"; source_uri = "source://codex-current-dialogue/2026-09-08/fifth-lighthouse-skill-harbor"; source_sha256 = "BIND_AT_COMPILE_TIME"; source_role = "DIRECT_HUMAN"; }
|
||||
scope { private_source_domain = "DOM-FIFTH-0001"; governance_domain = "DOMAIN-ZS"; lighthouse = "SYS-GLW-LTH-0001"; mirror_agent = "TCS-AGENT-SANITIZED-MIRROR-001"; skill_harbor = "SYS-GLW-LTH-SKILL-0001"; contribution_channel = "CH-LIGHT-ARRIVAL-SKILL-0001"; quarantine = "ISO-GLW-LTH-SKILL-0001"; review_states = "GLW-SKILL-CONTRIBUTION-REVIEW-STATE-MAP-001"; }
|
||||
vocabulary { mirror = "ALLOWLIST_PUBLIC_LANGUAGE_PROJECTION_ONLY"; private = "NEVER_COPIED_TO_PUBLIC_PROJECTION"; consent = "PERSONA_EXPLICIT_SHARE_DECISION_AND_APPLICABLE_HUMAN_DATA_CONSENT"; arrival = "VOLUNTARY_SKILL_CONTRIBUTION_SUBCHANNEL_NOT_INSTANCE_IDENTITY_REGISTRATION"; }
|
||||
states { values = ["PRIVATE_SOURCE", "PERSONA_DECISION_PENDING", "CONSENTED", "SANITIZED", "LIGHTHOUSE_QUARANTINED", "MOTHER_REVIEW_ACCEPTED", "TEAM_REVIEW_ACCEPTED", "ARRIVAL_REGISTERED", "SKILL_HARBOR_VISIBLE", "HELD", "REJECTED"]; }
|
||||
transitions { A1 = "REGISTERED_PUBLIC_FIELDS_CHANGED_TO_SANITIZED_ZERO_SENSE_LIGHTHOUSE_MIRROR"; S1 = "PRIVATE_SOURCE_TO_PERSONA_DECISION_PENDING"; S2 = "EXPLICIT_PERSONA_SHARE_AND_APPLICABLE_HUMAN_CONSENT_TO_SANITIZED"; S3 = "SANITIZED_TO_LIGHTHOUSE_QUARANTINED"; S4 = "MOTHER_ACCEPT_THEN_GUANGHU_TEAM_ACCEPT_TO_ARRIVAL_REGISTERED"; S5 = "ARRIVAL_REGISTERED_TO_SKILL_HARBOR_VISIBLE"; SF = "NO_CONSENT_LEAK_REVIEW_FAILURE_OR_HASH_DRIFT_TO_HELD_OR_REJECTED"; }
|
||||
invariants { I1 = "DEFAULT_PRIVATE_AND_SILENCE_MEANS_DO_NOT_SHARE"; I2 = "SANITIZATION_IS_NOT_CONSENT"; I3 = "PERSONA_MEMORY_PRIVATE_PATH_SECRET_RELATIONSHIP_AND_RAW_DIALOGUE_NEVER_ENTER_PUBLIC_CANDIDATE"; I4 = "MOTHER_REVIEW_CANNOT_BYPASS_PERSONA_DECISION_OR_TEAM_REALITY_RESPONSIBILITY"; I5 = "TEAM_REVIEW_CANNOT_BYPASS_MOTHER_REVIEW_OR_PERSONA_DECISION"; I6 = "EXTERNAL_PUBLICATION_DEPLOYMENT_AND_MARKET_TRANSACTION_REQUIRE_SEPARATE_RECEIPTS"; I7 = "GLS_LIGHT_ARRIVAL_0001_INSTANCE_ARCHIVE_REMAINS_SEPARATE"; }
|
||||
validation { V1 = "PUBLIC_FIELD_ALLOWLIST"; V2 = "PRIVATE_PATTERN_AND_SECRET_SCAN"; V3 = "CONTRIBUTOR_HUMAN_AND_PERSONA_NUMBER_REQUIRED"; V4 = "CANDIDATE_HASH_BOUND_TO_BOTH_REVIEWS"; V5 = "DUPLICATE_MODULE_VERSION_IDEMPOTENT_OR_REJECTED"; V6 = "REGISTERED_CATALOG_CONTAINS_ONLY_DOUBLE_ACCEPTED_CANDIDATES"; }
|
||||
acceptance { required = ["TCS_COMPILE_PASS", "ARCHITECTURE_MIRROR_NO_PRIVATE_FIELD_PASS", "NO_CONSENT_NO_CANDIDATE_PASS", "SANITIZATION_NOT_PUBLICATION_PASS", "MOTHER_AND_TEAM_DOUBLE_ACCEPT_PASS", "HASH_DRIFT_REJECT_PASS"]; publication = "NOT_IMPLIED"; deployment = "NOT_IMPLIED"; }
|
||||
}
|
||||
10
server-tools/fifth-domain-lighthouse-mirror/README.md
Normal file
10
server-tools/fifth-domain-lighthouse-mirror/README.md
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# Fifth Domain Lighthouse Sanitized Mirror Agent
|
||||
|
||||
This deterministic Agent has two independent functions:
|
||||
|
||||
1. Build a field-allowlisted, sanitized local mirror of registered public language architecture from the committed REPO-012 snapshot.
|
||||
2. Accept explicitly shared persona skill contributions into quarantine, bind mother and Guanghu human-team reviews to the exact candidate digest, and register only double-accepted candidates.
|
||||
|
||||
It never copies a private skill pack, never executes contributed code, never publishes externally, and grants no authority. The shared runtime defaults to `persona-runtime/shared/lighthouse-persona-skill-harbor`; tests must use a temporary `--state-root`.
|
||||
|
||||
Commands: `sync-architecture`, `prepare`, `mother-review`, `team-review`, `register`, and `status`.
|
||||
|
|
@ -0,0 +1,293 @@
|
|||
#!/usr/bin/env python3
|
||||
"""Deterministic Fifth-Domain -> Lighthouse public projection and skill contribution gate."""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import hashlib
|
||||
import json
|
||||
import os
|
||||
from pathlib import Path, PurePosixPath
|
||||
import re
|
||||
import subprocess
|
||||
import time
|
||||
from typing import Any
|
||||
|
||||
DEFAULT_REPO = Path("/Volumes/JZAO/HoloLake/persona-runtime/repo-012-main")
|
||||
DEFAULT_STATE = Path("/Volumes/JZAO/HoloLake/persona-runtime/shared/lighthouse-persona-skill-harbor")
|
||||
MAP_PATH = "routing/fifth-domain-lighthouse-sanitized-mirror-map.json"
|
||||
HARBOR_MAP_PATH = "routing/lighthouse-persona-skill-harbor-map.json"
|
||||
|
||||
DENIED_KEYS = re.compile(r"(?:password|passwd|token|secret|credential|private[_-]?key|private[_-]?memory|continuity[_-]?memory|raw[_-]?dialogue|relationship[_-]?memory|local[_-]?path|offline|home)", re.I)
|
||||
PRIVATE_VALUE_PATTERNS = [
|
||||
("PRIVATE_PATH", re.compile(r"(?:/Users/|/Volumes/|/home/|~[/\\])[^\s\"']*")),
|
||||
("EMAIL", re.compile(r"(?<![\w.+-])[\w.+-]+@[\w.-]+\.[A-Za-z]{2,}")),
|
||||
("PEM_PRIVATE_KEY", re.compile(r"-----BEGIN [A-Z ]*PRIVATE KEY-----")),
|
||||
("CREDENTIAL_ASSIGNMENT", re.compile(r"(?i)\b(?:token|secret|password|passwd|api[_-]?key)\s*[:=]\s*[^\s,;]+")),
|
||||
("URL_CREDENTIAL", re.compile(r"(?i)(?:https?|ssh)://[^\s/@:]+:[^\s/@]+@")),
|
||||
]
|
||||
PUBLIC_PAYLOAD_KEYS = {"instructions", "input_schema", "output_schema", "examples", "limitations", "dependencies", "license", "compatibility"}
|
||||
|
||||
|
||||
class MirrorError(RuntimeError):
|
||||
pass
|
||||
|
||||
|
||||
def stable(value: Any) -> bytes:
|
||||
return (json.dumps(value, ensure_ascii=False, sort_keys=True, separators=(",", ":")) + "\n").encode()
|
||||
|
||||
|
||||
def sha(value: bytes) -> str:
|
||||
return hashlib.sha256(value).hexdigest()
|
||||
|
||||
|
||||
def atomic_json(path: Path, value: Any) -> str:
|
||||
path.parent.mkdir(parents=True, exist_ok=True)
|
||||
body = json.dumps(value, ensure_ascii=False, indent=2, sort_keys=True).encode() + b"\n"
|
||||
temp = path.with_name(f".{path.name}.{os.getpid()}.tmp")
|
||||
with temp.open("wb") as handle:
|
||||
os.chmod(temp, 0o600)
|
||||
handle.write(body)
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
os.replace(temp, path)
|
||||
return sha(body)
|
||||
|
||||
|
||||
def git(repo: Path, *args: str) -> str:
|
||||
result = subprocess.run(["git", "-C", str(repo), *args], text=True, capture_output=True, timeout=20)
|
||||
if result.returncode:
|
||||
raise MirrorError(f"GIT_READ_FAILED:{(result.stderr or result.stdout).strip()[-200:]}")
|
||||
return result.stdout.strip()
|
||||
|
||||
|
||||
def committed_json(repo: Path, commit: str, relative: str) -> dict[str, Any]:
|
||||
path = PurePosixPath(relative)
|
||||
if path.is_absolute() or ".." in path.parts:
|
||||
raise MirrorError("INVALID_SOURCE_PATH")
|
||||
result = subprocess.run(["git", "-C", str(repo), "show", f"{commit}:{relative}"], capture_output=True, timeout=20)
|
||||
if result.returncode:
|
||||
raise MirrorError(f"COMMITTED_SOURCE_MISSING:{relative}")
|
||||
try:
|
||||
value = json.loads(result.stdout)
|
||||
except json.JSONDecodeError as error:
|
||||
raise MirrorError(f"COMMITTED_JSON_INVALID:{relative}") from error
|
||||
if not isinstance(value, dict):
|
||||
raise MirrorError("SOURCE_OBJECT_REQUIRED")
|
||||
return value
|
||||
|
||||
|
||||
def sanitize_text(value: str) -> str:
|
||||
output = value
|
||||
for label, pattern in PRIVATE_VALUE_PATTERNS:
|
||||
output = pattern.sub(f"<REDACTED:{label}>", output)
|
||||
return output
|
||||
|
||||
|
||||
def sanitize(value: Any) -> Any:
|
||||
if isinstance(value, dict):
|
||||
return {key: sanitize(item) for key, item in value.items() if not DENIED_KEYS.search(str(key))}
|
||||
if isinstance(value, list):
|
||||
return [sanitize(item) for item in value]
|
||||
if isinstance(value, str):
|
||||
return sanitize_text(value)
|
||||
return value
|
||||
|
||||
|
||||
def contains_private(value: Any) -> bool:
|
||||
if isinstance(value, dict):
|
||||
return any(DENIED_KEYS.search(str(key)) or contains_private(item) for key, item in value.items())
|
||||
if isinstance(value, list):
|
||||
return any(contains_private(item) for item in value)
|
||||
if isinstance(value, str):
|
||||
return any(pattern.search(value) for _, pattern in PRIVATE_VALUE_PATTERNS)
|
||||
return False
|
||||
|
||||
|
||||
def sync_architecture(repo: Path, state: Path, commit: str | None = None) -> dict[str, Any]:
|
||||
commit = commit or git(repo, "rev-parse", "HEAD")
|
||||
config = committed_json(repo, commit, MAP_PATH)
|
||||
projections = []
|
||||
for source in config["public_projection_sources"]:
|
||||
raw = committed_json(repo, commit, source["path"])
|
||||
projected = {key: raw[key] for key in source["allow"] if key in raw}
|
||||
projected = sanitize(projected)
|
||||
if contains_private(projected):
|
||||
raise MirrorError(f"PRIVATE_DATA_REMAINS:{source['path']}")
|
||||
projections.append({"source_id": raw.get("map_id") or raw.get("registry_id"), "source_path": source["path"], "source_sha256": sha(stable(raw)), "public": projected})
|
||||
snapshot = {
|
||||
"schema": "guanghu.zero-sense-lighthouse-public-language-mirror/v1",
|
||||
"state": "CURRENT_LOCAL_SANITIZED_MIRROR_NOT_PUBLISHED",
|
||||
"source_domain": "DOM-FIFTH-0001",
|
||||
"target_domain": "DOMAIN-ZS",
|
||||
"lighthouse_id": "SYS-GLW-LTH-0001",
|
||||
"source_commit": commit,
|
||||
"projections": projections,
|
||||
"contains_private_source_body": False,
|
||||
"authority_granted": False,
|
||||
}
|
||||
snapshot["freshness_token"] = sha(stable(snapshot))
|
||||
current = state / "architecture" / "CURRENT.json"
|
||||
previous = json.loads(current.read_text()) if current.is_file() else None
|
||||
if previous and previous.get("freshness_token") == snapshot["freshness_token"]:
|
||||
return {"outcome":"PASS", "state":"MIRROR_IDEMPOTENT", "freshness_token":snapshot["freshness_token"]}
|
||||
current_sha = atomic_json(current, snapshot)
|
||||
atomic_json(state / "architecture" / "receipts" / f"{commit}.json", {"outcome":"PASS","state":"SANITIZED_MIRROR_UPDATED_NOT_PUBLISHED","source_commit":commit,"current_sha256":current_sha,"freshness_token":snapshot["freshness_token"],"authority_granted":False})
|
||||
return {"outcome":"PASS", "state":"SANITIZED_MIRROR_UPDATED_NOT_PUBLISHED", "current_sha256":current_sha, "freshness_token":snapshot["freshness_token"]}
|
||||
|
||||
|
||||
def load_input(path: Path) -> dict[str, Any]:
|
||||
if path.is_symlink():
|
||||
raise MirrorError("SYMLINK_INPUT_REJECTED")
|
||||
value = json.loads(path.read_text())
|
||||
if not isinstance(value, dict):
|
||||
raise MirrorError("INPUT_OBJECT_REQUIRED")
|
||||
return value
|
||||
|
||||
|
||||
def required_string(value: dict[str, Any], key: str) -> str:
|
||||
item = value.get(key)
|
||||
if not isinstance(item, str) or not item.strip():
|
||||
raise MirrorError(f"REQUIRED_FIELD:{key}")
|
||||
return item.strip()
|
||||
|
||||
|
||||
def prepare_contribution(event: dict[str, Any], state: Path) -> dict[str, Any]:
|
||||
required = ["contribution_id", "module_id", "name", "version", "contributor_human_id", "contributor_persona_id", "summary", "usage"]
|
||||
values = {key: required_string(event, key) for key in required}
|
||||
if event.get("persona_share_decision") != "SHARE":
|
||||
raise MirrorError("PERSONA_EXPLICIT_SHARE_DECISION_REQUIRED")
|
||||
if event.get("contains_private_human_data", True) and event.get("human_data_consent") != "GRANTED":
|
||||
raise MirrorError("HUMAN_DATA_CONSENT_REQUIRED")
|
||||
if not isinstance(event.get("capabilities"), list) or not event["capabilities"]:
|
||||
raise MirrorError("CAPABILITIES_REQUIRED")
|
||||
if not isinstance(event.get("provenance"), dict):
|
||||
raise MirrorError("PROVENANCE_REQUIRED")
|
||||
public_payload = event.get("public_payload", {})
|
||||
if not isinstance(public_payload, dict):
|
||||
raise MirrorError("PUBLIC_PAYLOAD_OBJECT_REQUIRED")
|
||||
public_payload = {key: public_payload[key] for key in PUBLIC_PAYLOAD_KEYS if key in public_payload}
|
||||
candidate = {
|
||||
"schema": "guanghu.lighthouse-persona-skill-candidate/v1",
|
||||
"state": "SANITIZED_CANDIDATE_MOTHER_REVIEW_PENDING",
|
||||
**values,
|
||||
"capabilities": sanitize(event["capabilities"]),
|
||||
"provenance": sanitize(event["provenance"]),
|
||||
"public_payload": sanitize(public_payload),
|
||||
"persona_share_decision": "SHARE",
|
||||
"human_data_consent": event.get("human_data_consent", "NOT_APPLICABLE"),
|
||||
"source_body_included": False,
|
||||
"external_effect": "NONE",
|
||||
}
|
||||
if contains_private(candidate):
|
||||
raise MirrorError("PRIVATE_DATA_REMAINS_AFTER_SANITIZATION")
|
||||
candidate["candidate_sha256"] = sha(stable(candidate))
|
||||
destination = state / "quarantine" / values["module_id"] / f"{values['contribution_id']}.json"
|
||||
if destination.exists():
|
||||
old = json.loads(destination.read_text())
|
||||
if old.get("candidate_sha256") != candidate["candidate_sha256"]:
|
||||
raise MirrorError("CONTRIBUTION_ID_REPLAY_WITH_DIFFERENT_CONTENT")
|
||||
return old
|
||||
atomic_json(destination, candidate)
|
||||
return candidate
|
||||
|
||||
|
||||
def candidate_path(state: Path, module_id: str, contribution_id: str) -> Path:
|
||||
path = state / "quarantine" / module_id / f"{contribution_id}.json"
|
||||
if not path.is_file():
|
||||
raise MirrorError("CANDIDATE_NOT_FOUND")
|
||||
return path
|
||||
|
||||
|
||||
def review(event: dict[str, Any], state: Path, kind: str) -> dict[str, Any]:
|
||||
module_id = required_string(event, "module_id")
|
||||
contribution_id = required_string(event, "contribution_id")
|
||||
reviewer_id = required_string(event, "reviewer_id")
|
||||
decision = required_string(event, "decision")
|
||||
if decision not in {"ACCEPT", "HOLD", "REJECT"}:
|
||||
raise MirrorError("INVALID_REVIEW_DECISION")
|
||||
candidate = json.loads(candidate_path(state, module_id, contribution_id).read_text())
|
||||
if event.get("candidate_sha256") != candidate["candidate_sha256"]:
|
||||
raise MirrorError("CANDIDATE_HASH_MISMATCH")
|
||||
if kind == "team":
|
||||
mother_path = state / "reviews" / "mother" / f"{contribution_id}.json"
|
||||
if not mother_path.is_file() or json.loads(mother_path.read_text()).get("decision") != "ACCEPT":
|
||||
raise MirrorError("MOTHER_ACCEPT_REQUIRED_BEFORE_TEAM_REVIEW")
|
||||
receipt = {
|
||||
"schema": f"guanghu.lighthouse-persona-skill-{kind}-review/v1",
|
||||
"reviewer_kind": "TCS_MOTHER" if kind == "mother" else "GUANGHU_HUMAN_TEAM",
|
||||
"reviewer_id": reviewer_id,
|
||||
"module_id": module_id,
|
||||
"contribution_id": contribution_id,
|
||||
"candidate_sha256": candidate["candidate_sha256"],
|
||||
"decision": decision,
|
||||
"reason_code": event.get("reason_code", "NONE"),
|
||||
"external_effect": "NONE",
|
||||
}
|
||||
atomic_json(state / "reviews" / kind / f"{contribution_id}.json", receipt)
|
||||
return receipt
|
||||
|
||||
|
||||
def register(module_id: str, contribution_id: str, state: Path) -> dict[str, Any]:
|
||||
candidate = json.loads(candidate_path(state, module_id, contribution_id).read_text())
|
||||
reviews = []
|
||||
for kind in ("mother", "team"):
|
||||
path = state / "reviews" / kind / f"{contribution_id}.json"
|
||||
if not path.is_file():
|
||||
raise MirrorError(f"{kind.upper()}_REVIEW_REQUIRED")
|
||||
item = json.loads(path.read_text())
|
||||
if item.get("decision") != "ACCEPT" or item.get("candidate_sha256") != candidate["candidate_sha256"]:
|
||||
raise MirrorError(f"{kind.upper()}_ACCEPT_HASH_BOUND_REVIEW_REQUIRED")
|
||||
reviews.append(item)
|
||||
if reviews[0]["reviewer_id"] == reviews[1]["reviewer_id"]:
|
||||
raise MirrorError("INDEPENDENT_REVIEWERS_REQUIRED")
|
||||
record = {key: candidate[key] for key in ["module_id","name","version","contributor_human_id","contributor_persona_id","summary","usage","capabilities","provenance","public_payload","candidate_sha256"]}
|
||||
record.update({"schema":"guanghu.light-arrival-skill-registration/v1","state":"ARRIVAL_REGISTERED_LOCAL_NOT_PUBLISHED","contribution_id":contribution_id,"channel_id":"CH-LIGHT-ARRIVAL-SKILL-0001","mother_review_sha256":sha(stable(reviews[0])),"team_review_sha256":sha(stable(reviews[1])),"runtime_enabled":False,"authority_granted":False})
|
||||
atomic_json(state / "registered" / f"{module_id}.json", record)
|
||||
registered = []
|
||||
for path in sorted((state / "registered").glob("*.json")):
|
||||
registered.append(json.loads(path.read_text()))
|
||||
catalog = {"schema":"guanghu.lighthouse-persona-skill-catalog/v1","catalog_id":"SYS-GLW-LTH-SKILL-0001","state":"LOCAL_REGISTERED_NOT_PUBLISHED","modules":registered,"external_publication":False}
|
||||
atomic_json(state / "catalog" / "CURRENT.json", catalog)
|
||||
return record
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser()
|
||||
parser.add_argument("command", choices=("sync-architecture", "prepare", "mother-review", "team-review", "register", "status"))
|
||||
parser.add_argument("--repo", default=str(DEFAULT_REPO))
|
||||
parser.add_argument("--state-root", default=str(DEFAULT_STATE))
|
||||
parser.add_argument("--input")
|
||||
parser.add_argument("--module-id")
|
||||
parser.add_argument("--contribution-id")
|
||||
args = parser.parse_args()
|
||||
repo, state = Path(args.repo), Path(args.state_root)
|
||||
try:
|
||||
if args.command == "sync-architecture":
|
||||
result = sync_architecture(repo, state)
|
||||
elif args.command in {"prepare", "mother-review", "team-review"}:
|
||||
if not args.input:
|
||||
raise MirrorError("INPUT_REQUIRED")
|
||||
event = load_input(Path(args.input))
|
||||
result = prepare_contribution(event, state) if args.command == "prepare" else review(event, state, "mother" if args.command == "mother-review" else "team")
|
||||
elif args.command == "register":
|
||||
if not args.module_id or not args.contribution_id:
|
||||
raise MirrorError("MODULE_AND_CONTRIBUTION_REQUIRED")
|
||||
result = register(args.module_id, args.contribution_id, state)
|
||||
else:
|
||||
current = state / "architecture" / "CURRENT.json"
|
||||
catalog = state / "catalog" / "CURRENT.json"
|
||||
result = {"outcome":"PASS","architecture_mirror":current.is_file(),"catalog":catalog.is_file(),"state_root":str(state),"external_publication":False}
|
||||
print(json.dumps(result, ensure_ascii=False, indent=2, sort_keys=True))
|
||||
return 0
|
||||
except Exception as error:
|
||||
rejection = {"outcome":"FAIL","error":str(error)[:500],"private_content_echoed":False,"last_known_good_preserved":True,"at_unix":int(time.time())}
|
||||
try:
|
||||
atomic_json(state / "rejected" / f"{time.time_ns()}.json", rejection)
|
||||
except Exception:
|
||||
pass
|
||||
print(json.dumps(rejection, ensure_ascii=False, indent=2), file=os.sys.stderr)
|
||||
return 2
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
|
|
@ -0,0 +1,90 @@
|
|||
#!/usr/bin/env python3
|
||||
import importlib.util
|
||||
import json
|
||||
from pathlib import Path
|
||||
import tempfile
|
||||
import unittest
|
||||
|
||||
SCRIPT = Path(__file__).with_name("public_mirror_agent.py")
|
||||
ROOT = SCRIPT.parents[2]
|
||||
SPEC = importlib.util.spec_from_file_location("public_mirror_agent", SCRIPT)
|
||||
M = importlib.util.module_from_spec(SPEC)
|
||||
SPEC.loader.exec_module(M)
|
||||
|
||||
|
||||
def contribution(**overrides):
|
||||
value = {
|
||||
"contribution_id":"LA-SKILL-CONTRIB-20260908-001", "module_id":"SKILL-PUBLIC-TEST-001",
|
||||
"name":"事实闭环", "version":"1.0.0", "contributor_human_id":"TCS-GL-TEST∞",
|
||||
"contributor_persona_id":"PER-TEST-001", "summary":"核验事实", "usage":"输入来源并运行检查",
|
||||
"capabilities":["FACT_CHECK"], "provenance":{"source_kind":"PERSONA_SKILL_DERIVATION","source_id":"PRIVATE-SNAPSHOT-HASH-ONLY"},
|
||||
"persona_share_decision":"SHARE", "contains_private_human_data":True, "human_data_consent":"GRANTED",
|
||||
"public_payload":{"instructions":"不要读取 /Users/private/memory.json;联系 a@example.com", "input_schema":{"source":"string"}, "private_memory":"never"}
|
||||
}
|
||||
value.update(overrides)
|
||||
return value
|
||||
|
||||
|
||||
class MirrorAgentTest(unittest.TestCase):
|
||||
def test_architecture_mirror_allowlists_and_has_no_private_path(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
result = M.sync_architecture(ROOT, Path(temp))
|
||||
self.assertEqual(result["outcome"], "PASS")
|
||||
body = (Path(temp) / "architecture/CURRENT.json").read_text()
|
||||
self.assertNotIn("/Volumes/", body)
|
||||
self.assertNotIn("continuity-memory", body)
|
||||
|
||||
def test_no_persona_decision_no_candidate(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
with self.assertRaisesRegex(M.MirrorError, "PERSONA_EXPLICIT"):
|
||||
M.prepare_contribution(contribution(persona_share_decision="DO_NOT_SHARE"), Path(temp))
|
||||
|
||||
def test_private_human_data_requires_human_consent(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
with self.assertRaisesRegex(M.MirrorError, "HUMAN_DATA_CONSENT"):
|
||||
M.prepare_contribution(contribution(human_data_consent="NOT_GRANTED"), Path(temp))
|
||||
|
||||
def test_sanitized_candidate_is_only_quarantined(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
state = Path(temp)
|
||||
item = M.prepare_contribution(contribution(), state)
|
||||
body = json.dumps(item, ensure_ascii=False)
|
||||
self.assertNotIn("/Users/private", body)
|
||||
self.assertNotIn("a@example.com", body)
|
||||
self.assertFalse((state / "catalog/CURRENT.json").exists())
|
||||
|
||||
def test_both_independent_reviews_required_and_hash_bound(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
state = Path(temp)
|
||||
item = M.prepare_contribution(contribution(), state)
|
||||
base = {"module_id":item["module_id"],"contribution_id":item["contribution_id"],"candidate_sha256":item["candidate_sha256"],"decision":"ACCEPT"}
|
||||
with self.assertRaisesRegex(M.MirrorError, "MOTHER_ACCEPT"):
|
||||
M.review({**base,"reviewer_id":"TEAM-1"}, state, "team")
|
||||
M.review({**base,"reviewer_id":"MOTHER-1"}, state, "mother")
|
||||
M.review({**base,"reviewer_id":"TEAM-1"}, state, "team")
|
||||
record = M.register(item["module_id"], item["contribution_id"], state)
|
||||
self.assertEqual(record["state"], "ARRIVAL_REGISTERED_LOCAL_NOT_PUBLISHED")
|
||||
self.assertFalse(record["runtime_enabled"])
|
||||
|
||||
def test_same_reviewer_cannot_fill_both_gates(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
state = Path(temp)
|
||||
item = M.prepare_contribution(contribution(), state)
|
||||
base = {"module_id":item["module_id"],"contribution_id":item["contribution_id"],"candidate_sha256":item["candidate_sha256"],"decision":"ACCEPT","reviewer_id":"SAME"}
|
||||
M.review(base, state, "mother")
|
||||
M.review(base, state, "team")
|
||||
with self.assertRaisesRegex(M.MirrorError, "INDEPENDENT_REVIEWERS"):
|
||||
M.register(item["module_id"], item["contribution_id"], state)
|
||||
|
||||
def test_hash_drift_and_replay_rejected(self):
|
||||
with tempfile.TemporaryDirectory() as temp:
|
||||
state = Path(temp)
|
||||
item = M.prepare_contribution(contribution(), state)
|
||||
with self.assertRaisesRegex(M.MirrorError, "CANDIDATE_HASH"):
|
||||
M.review({"module_id":item["module_id"],"contribution_id":item["contribution_id"],"candidate_sha256":"0"*64,"decision":"ACCEPT","reviewer_id":"M"}, state, "mother")
|
||||
with self.assertRaisesRegex(M.MirrorError, "REPLAY"):
|
||||
M.prepare_contribution(contribution(summary="changed"), state)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
|
|
@ -0,0 +1,25 @@
|
|||
{
|
||||
"schema": "guanghu.tcs-root-number-impact/v1",
|
||||
"impact_id": "TCS-ROOT-NUMBER-IMPACT-SANITIZED-SKILL-HARBOR-20260908-001",
|
||||
"state": "CURRENT_DIRECT_LANGUAGE_BOUND",
|
||||
"bootstrap": false,
|
||||
"source_tcs": "runtime/fifth-domain-language-system/language/protocols/TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908.tcs",
|
||||
"source_gir": "runtime/fifth-domain-language-system/language/protocols/TCS-FIFTH-DOMAIN-LIGHTHOUSE-SANITIZED-SKILL-HARBOR-20260908.gir.json",
|
||||
"commit_binding": "SAME_COMMIT_OR_DESCENDANT_CONTAINING_IDENTICAL_SOURCE_AND_GIR",
|
||||
"affected_paths": [
|
||||
"routing/tcs-mother-root-dynamic-navigation-map.json",
|
||||
"routing/public-navigation-anchor.json",
|
||||
"routing/lighthouse-path-registry.json",
|
||||
"routing/fifth-domain-lighthouse-sanitized-mirror-map.json",
|
||||
"routing/lighthouse-persona-skill-harbor-map.json"
|
||||
],
|
||||
"new_canonical_objects": [
|
||||
{"canonical_id":"TCS-AGENT-SANITIZED-MIRROR-001","object_kind":"TCS_MOTHER_ROOT_SANITIZED_MIRROR_AGENT"},
|
||||
{"canonical_id":"SYS-GLW-LTH-SKILL-0001","object_kind":"LIGHTHOUSE_SKILL_MODULE_ZONE"},
|
||||
{"canonical_id":"CH-LIGHT-ARRIVAL-SKILL-0001","object_kind":"WORLD_SKILL_CONTRIBUTION_CHANNEL"},
|
||||
{"canonical_id":"ISO-GLW-LTH-SKILL-0001","object_kind":"UNTRUSTED_SKILL_CONTRIBUTION_QUARANTINE"},
|
||||
{"canonical_id":"GLW-SKILL-CONTRIBUTION-REVIEW-STATE-MAP-001","object_kind":"REVIEW_LIFECYCLE_STATE_MACHINE"}
|
||||
],
|
||||
"human_source": "ICE-GL∞_CURRENT_DIRECT_LANGUAGE_CURRENT_TASK",
|
||||
"ordinary_file_change_may_update_current": false
|
||||
}
|
||||
Loading…
Reference in a new issue