141 lines
6.9 KiB
Markdown
141 lines
6.9 KiB
Markdown
|
|
# HoloLake Capability Registry Trusted Signer Provisioning Request · Human Engineering Language (English)
|
|||
|
|
|
|||
|
|
> This is an English reading projection of validated native TCS/HLDP source. It is not a new canonical source and grants no execution authority.
|
|||
|
|
|
|||
|
|
## What this is
|
|||
|
|
|
|||
|
|
This is a **protocol** declaration with identifier `TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001` and version `0.1.0`. The projector validates it with the Stage-1 compiler before changing its reading order.
|
|||
|
|
|
|||
|
|
## Who is here
|
|||
|
|
|
|||
|
|
The native source does not provide this field; the projector does not guess.
|
|||
|
|
|
|||
|
|
## Why this started
|
|||
|
|
|
|||
|
|
- **source** `source`
|
|||
|
|
- **source identifier**:BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823 `source.source_id`
|
|||
|
|
- **source role**:DIRECT_HUMAN `source.source_role`
|
|||
|
|
- **source checksum**:a3dd8dbd2203b631bdb23f2693eb314d4ef86af68fdeaee8835e3cf0861ddd23 `source.source_sha256`
|
|||
|
|
- **source address**:language-sources/direct-human/BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823.txt `source.source_uri`
|
|||
|
|
|
|||
|
|
## What changed
|
|||
|
|
|
|||
|
|
The native source does not provide this field; the projector does not guess.
|
|||
|
|
|
|||
|
|
## How it will execute
|
|||
|
|
|
|||
|
|
This is a non-executable declaration and has no action graph.
|
|||
|
|
|
|||
|
|
## Boundaries and exception handling
|
|||
|
|
|
|||
|
|
The native source does not provide this field; the projector does not guess.
|
|||
|
|
|
|||
|
|
## How completion is proven
|
|||
|
|
|
|||
|
|
- **acceptance** `acceptance`
|
|||
|
|
- **capability_registry_state_after_pass**:SIGNED_VERIFIED_NOT_INSTALLED `acceptance.capability_registry_state_after_pass`
|
|||
|
|
- **current_acceptance**:0 `acceptance.current_acceptance`
|
|||
|
|
- **installation_is_separate_step**:yes `acceptance.installation_is_separate_step`
|
|||
|
|
- **signature_verified**:BINARY_PASS_OR_FAIL `acceptance.signature_verified`
|
|||
|
|
- **signer_registered**:AUTHORITATIVE_REGISTRY_READBACK_REQUIRED `acceptance.signer_registered`
|
|||
|
|
|
|||
|
|
## Where to continue next time
|
|||
|
|
|
|||
|
|
The native source does not provide this field; the projector does not guess.
|
|||
|
|
|
|||
|
|
## Source and verification
|
|||
|
|
|
|||
|
|
- **Native declaration identifier**: `TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001`
|
|||
|
|
- **Native declaration kind**: `PROTOCOL`
|
|||
|
|
- **TCS source SHA-256**: `4deb85d6d0f5bdb61ff2d9182d9acd1e0f1e266661bc30d75befccbe3b936e4d`
|
|||
|
|
- **Validation compiler**: `TCS-COMPILER-STAGE3-GENERIC-ACTION-LOADER-0001`
|
|||
|
|
- **Projection protocol**: `GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
|
|||
|
|
|
|||
|
|
## Complete native structure cross-reference
|
|||
|
|
|
|||
|
|
All top-level structures and field paths are retained below so a reader can audit whether the projection omitted information.
|
|||
|
|
|
|||
|
|
- **acceptance** `acceptance`
|
|||
|
|
- **capability_registry_state_after_pass**:SIGNED_VERIFIED_NOT_INSTALLED `acceptance.capability_registry_state_after_pass`
|
|||
|
|
- **current_acceptance**:0 `acceptance.current_acceptance`
|
|||
|
|
- **installation_is_separate_step**:yes `acceptance.installation_is_separate_step`
|
|||
|
|
- **signature_verified**:BINARY_PASS_OR_FAIL `acceptance.signature_verified`
|
|||
|
|
- **signer_registered**:AUTHORITATIVE_REGISTRY_READBACK_REQUIRED `acceptance.signer_registered`
|
|||
|
|
- **admission** `admission`
|
|||
|
|
- **out_of_scope**:TCS-E4001 `admission.out_of_scope`
|
|||
|
|
- **stale_or_revoked**:TCS-E5002 `admission.stale_or_revoked`
|
|||
|
|
- **unsigned_or_unknown_signer**:TCS-E3002 `admission.unsigned_or_unknown_signer`
|
|||
|
|
- **verify_candidate_hash_before_signature**:yes `admission.verify_candidate_hash_before_signature`
|
|||
|
|
- **verify_public_key_against_authoritative_signer_registry**:yes `admission.verify_public_key_against_authoritative_signer_registry`
|
|||
|
|
- **verify_revocation_before_each_activation**:yes `admission.verify_revocation_before_each_activation`
|
|||
|
|
- **verify_scope_before_install**:yes `admission.verify_scope_before_install`
|
|||
|
|
- **verify_signature_before_mount**:yes `admission.verify_signature_before_mount`
|
|||
|
|
- **current** `current`
|
|||
|
|
- **activation**:no `current.activation`
|
|||
|
|
- **authoritative_registry_state**:CURRENT_EMPTY_NO_TRUSTED_SIGNER `current.authoritative_registry_state`
|
|||
|
|
- **candidate_registry**:TCS-CAPREG-LPM-DESKTOP-CANDIDATE-0001 `current.candidate_registry`
|
|||
|
|
- **candidate_state**:UNSIGNED_CANDIDATE_NOT_INSTALLABLE `current.candidate_state`
|
|||
|
|
- **install**:no `current.install`
|
|||
|
|
- **mount**:no `current.mount`
|
|||
|
|
- **public_key**:ABSENT `current.public_key`
|
|||
|
|
- **signature**:ABSENT `current.signature`
|
|||
|
|
- **signer_id**:UNKNOWN `current.signer_id`
|
|||
|
|
- **header** `header`
|
|||
|
|
- **canonical source path**:language/protocols/TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001.tcs `header.canonical_uri`
|
|||
|
|
- **compatibility** `header.compatibility`
|
|||
|
|
- GIR/1
|
|||
|
|
- **language**:TCS/0.1 `header.language`
|
|||
|
|
- **lifecycle**:CANDIDATE `header.lifecycle`
|
|||
|
|
- **English name**:HoloLake Capability Registry Trusted Signer Provisioning Request `header.name_en`
|
|||
|
|
- **Chinese name**:HoloLake能力注册表可信签名主体供给请求 `header.name_zh`
|
|||
|
|
- **profile**:HLDP/1 `header.profile`
|
|||
|
|
- **protocols** `header.protocols`
|
|||
|
|
- TCS-GENERIC-ACTION-GRAPH-LOADER-0001
|
|||
|
|
- TCS-MODULE-ABI-0001
|
|||
|
|
- **schema**:tcs.protocol/v1 `header.schema`
|
|||
|
|
- **version**:0.1.0 `header.version`
|
|||
|
|
- **rejected** `rejected`
|
|||
|
|
- **values** `rejected.values`
|
|||
|
|
- INFER_SIGNER_FROM_USER_ACCOUNT
|
|||
|
|
- INFER_SIGNER_FROM_ROOT
|
|||
|
|
- INFER_SIGNER_FROM_SSH_ACCESS
|
|||
|
|
- INFER_SIGNER_FROM_GIT_REMOTE_RIGHTS
|
|||
|
|
- GENERATE_UNREQUESTED_IDENTITY_KEY
|
|||
|
|
- STORE_PRIVATE_KEY_IN_REPOSITORY
|
|||
|
|
- CALL_UNSIGNED_CANDIDATE_SIGNED
|
|||
|
|
- **request** `request`
|
|||
|
|
- **git_push_authority_reuse**:no `request.git_push_authority_reuse`
|
|||
|
|
- **host_root_or_ssh_key_reuse**:no `request.host_root_or_ssh_key_reuse`
|
|||
|
|
- **key_generation_by_current_codex**:no `request.key_generation_by_current_codex`
|
|||
|
|
- **private_key_location**:OUTSIDE_REPOSITORY_AND_OUTSIDE_RECEIPTS `request.private_key_location`
|
|||
|
|
- **required** `request.required`
|
|||
|
|
- SEPARATELY_AUTHORIZED_SIGNER_ID
|
|||
|
|
- ED25519_PUBLIC_KEY
|
|||
|
|
- KEY_PROVENANCE_RECEIPT
|
|||
|
|
- PERMITTED_REGISTRY_SCOPE
|
|||
|
|
- EXPIRY_OR_REVOCATION_RULE
|
|||
|
|
- ONE_EXACT_CANDIDATE_HASH
|
|||
|
|
- HUMAN_LANGUAGE_AUTHORIZATION_RECEIPT_BOUND_TO_REQUEST
|
|||
|
|
- **signature_envelope** `signature_envelope`
|
|||
|
|
- **algorithm**:ED25519 `signature_envelope.algorithm`
|
|||
|
|
- **channel**:ICE-CH-ZC001 `signature_envelope.channel`
|
|||
|
|
- **development_line**:HOLOLAKE-LPM-TCS-NATIVE-20260823 `signature_envelope.development_line`
|
|||
|
|
- **payload** `signature_envelope.payload`
|
|||
|
|
- REGISTRY_CANONICAL_SHA256
|
|||
|
|
- REGISTRY_ID
|
|||
|
|
- REGISTRY_VERSION
|
|||
|
|
- ISSUER_SIGNER_ID
|
|||
|
|
- ISSUED_AT
|
|||
|
|
- EXPIRES_AT_OR_NO_EXPIRY_POLICY
|
|||
|
|
- REVOCATION_EPOCH
|
|||
|
|
- CHANNEL
|
|||
|
|
- DEVELOPMENT_LINE
|
|||
|
|
- **source** `source`
|
|||
|
|
- **source identifier**:BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823 `source.source_id`
|
|||
|
|
- **source role**:DIRECT_HUMAN `source.source_role`
|
|||
|
|
- **source checksum**:a3dd8dbd2203b631bdb23f2693eb314d4ef86af68fdeaee8835e3cf0861ddd23 `source.source_sha256`
|
|||
|
|
- **source address**:language-sources/direct-human/BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823.txt `source.source_uri`
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
This page changes only the reading order; it does not change TCS/HLDP semantics.
|