hololake-system-architecture/build/TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001.human.en-US.md

141 lines
6.9 KiB
Markdown
Raw Normal View History

# HoloLake Capability Registry Trusted Signer Provisioning Request · Human Engineering Language (English)
> This is an English reading projection of validated native TCS/HLDP source. It is not a new canonical source and grants no execution authority.
## What this is
This is a **protocol** declaration with identifier `TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001` and version `0.1.0`. The projector validates it with the Stage-1 compiler before changing its reading order.
## Who is here
The native source does not provide this field; the projector does not guess.
## Why this started
- **source** `source`
- **source identifier**BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823 `source.source_id`
- **source role**DIRECT_HUMAN `source.source_role`
- **source checksum**a3dd8dbd2203b631bdb23f2693eb314d4ef86af68fdeaee8835e3cf0861ddd23 `source.source_sha256`
- **source address**language-sources/direct-human/BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823.txt `source.source_uri`
## What changed
The native source does not provide this field; the projector does not guess.
## How it will execute
This is a non-executable declaration and has no action graph.
## Boundaries and exception handling
The native source does not provide this field; the projector does not guess.
## How completion is proven
- **acceptance** `acceptance`
- **capability_registry_state_after_pass**SIGNED_VERIFIED_NOT_INSTALLED `acceptance.capability_registry_state_after_pass`
- **current_acceptance**0 `acceptance.current_acceptance`
- **installation_is_separate_step**yes `acceptance.installation_is_separate_step`
- **signature_verified**BINARY_PASS_OR_FAIL `acceptance.signature_verified`
- **signer_registered**AUTHORITATIVE_REGISTRY_READBACK_REQUIRED `acceptance.signer_registered`
## Where to continue next time
The native source does not provide this field; the projector does not guess.
## Source and verification
- **Native declaration identifier**: `TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001`
- **Native declaration kind**: `PROTOCOL`
- **TCS source SHA-256**: `4deb85d6d0f5bdb61ff2d9182d9acd1e0f1e266661bc30d75befccbe3b936e4d`
- **Validation compiler**: `TCS-COMPILER-STAGE3-GENERIC-ACTION-LOADER-0001`
- **Projection protocol**: `GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
## Complete native structure cross-reference
All top-level structures and field paths are retained below so a reader can audit whether the projection omitted information.
- **acceptance** `acceptance`
- **capability_registry_state_after_pass**SIGNED_VERIFIED_NOT_INSTALLED `acceptance.capability_registry_state_after_pass`
- **current_acceptance**0 `acceptance.current_acceptance`
- **installation_is_separate_step**yes `acceptance.installation_is_separate_step`
- **signature_verified**BINARY_PASS_OR_FAIL `acceptance.signature_verified`
- **signer_registered**AUTHORITATIVE_REGISTRY_READBACK_REQUIRED `acceptance.signer_registered`
- **admission** `admission`
- **out_of_scope**TCS-E4001 `admission.out_of_scope`
- **stale_or_revoked**TCS-E5002 `admission.stale_or_revoked`
- **unsigned_or_unknown_signer**TCS-E3002 `admission.unsigned_or_unknown_signer`
- **verify_candidate_hash_before_signature**yes `admission.verify_candidate_hash_before_signature`
- **verify_public_key_against_authoritative_signer_registry**yes `admission.verify_public_key_against_authoritative_signer_registry`
- **verify_revocation_before_each_activation**yes `admission.verify_revocation_before_each_activation`
- **verify_scope_before_install**yes `admission.verify_scope_before_install`
- **verify_signature_before_mount**yes `admission.verify_signature_before_mount`
- **current** `current`
- **activation**no `current.activation`
- **authoritative_registry_state**CURRENT_EMPTY_NO_TRUSTED_SIGNER `current.authoritative_registry_state`
- **candidate_registry**TCS-CAPREG-LPM-DESKTOP-CANDIDATE-0001 `current.candidate_registry`
- **candidate_state**UNSIGNED_CANDIDATE_NOT_INSTALLABLE `current.candidate_state`
- **install**no `current.install`
- **mount**no `current.mount`
- **public_key**ABSENT `current.public_key`
- **signature**ABSENT `current.signature`
- **signer_id**UNKNOWN `current.signer_id`
- **header** `header`
- **canonical source path**language/protocols/TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001.tcs `header.canonical_uri`
- **compatibility** `header.compatibility`
- GIR/1
- **language**TCS/0.1 `header.language`
- **lifecycle**CANDIDATE `header.lifecycle`
- **English name**HoloLake Capability Registry Trusted Signer Provisioning Request `header.name_en`
- **Chinese name**HoloLake能力注册表可信签名主体供给请求 `header.name_zh`
- **profile**HLDP/1 `header.profile`
- **protocols** `header.protocols`
- TCS-GENERIC-ACTION-GRAPH-LOADER-0001
- TCS-MODULE-ABI-0001
- **schema**tcs.protocol/v1 `header.schema`
- **version**0.1.0 `header.version`
- **rejected** `rejected`
- **values** `rejected.values`
- INFER_SIGNER_FROM_USER_ACCOUNT
- INFER_SIGNER_FROM_ROOT
- INFER_SIGNER_FROM_SSH_ACCESS
- INFER_SIGNER_FROM_GIT_REMOTE_RIGHTS
- GENERATE_UNREQUESTED_IDENTITY_KEY
- STORE_PRIVATE_KEY_IN_REPOSITORY
- CALL_UNSIGNED_CANDIDATE_SIGNED
- **request** `request`
- **git_push_authority_reuse**no `request.git_push_authority_reuse`
- **host_root_or_ssh_key_reuse**no `request.host_root_or_ssh_key_reuse`
- **key_generation_by_current_codex**no `request.key_generation_by_current_codex`
- **private_key_location**OUTSIDE_REPOSITORY_AND_OUTSIDE_RECEIPTS `request.private_key_location`
- **required** `request.required`
- SEPARATELY_AUTHORIZED_SIGNER_ID
- ED25519_PUBLIC_KEY
- KEY_PROVENANCE_RECEIPT
- PERMITTED_REGISTRY_SCOPE
- EXPIRY_OR_REVOCATION_RULE
- ONE_EXACT_CANDIDATE_HASH
- HUMAN_LANGUAGE_AUTHORIZATION_RECEIPT_BOUND_TO_REQUEST
- **signature_envelope** `signature_envelope`
- **algorithm**ED25519 `signature_envelope.algorithm`
- **channel**ICE-CH-ZC001 `signature_envelope.channel`
- **development_line**HOLOLAKE-LPM-TCS-NATIVE-20260823 `signature_envelope.development_line`
- **payload** `signature_envelope.payload`
- REGISTRY_CANONICAL_SHA256
- REGISTRY_ID
- REGISTRY_VERSION
- ISSUER_SIGNER_ID
- ISSUED_AT
- EXPIRES_AT_OR_NO_EXPIRY_POLICY
- REVOCATION_EPOCH
- CHANNEL
- DEVELOPMENT_LINE
- **source** `source`
- **source identifier**BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823 `source.source_id`
- **source role**DIRECT_HUMAN `source.source_role`
- **source checksum**a3dd8dbd2203b631bdb23f2693eb314d4ef86af68fdeaee8835e3cf0861ddd23 `source.source_sha256`
- **source address**language-sources/direct-human/BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823.txt `source.source_uri`
---
This page changes only the reading order; it does not change TCS/HLDP semantics.