106 lines
4.6 KiB
Shell
106 lines
4.6 KiB
Shell
|
|
#!/usr/bin/env bash
|
|||
|
|
set -Eeuo pipefail
|
|||
|
|
|
|||
|
|
[[ $# == 3 ]] || { echo 'usage: install-jd-pncc-runtime.sh <runtime-source> <persona-seed> <source-commit>' >&2; exit 64; }
|
|||
|
|
|
|||
|
|
runtime_source=$(readlink -f "$1")
|
|||
|
|
seed_source=$(readlink -f "$2")
|
|||
|
|
source_commit=$3
|
|||
|
|
readonly node_id=JD-FD-PRIMARY
|
|||
|
|
readonly persona_id=ICE-P-ZY001
|
|||
|
|
readonly human_responsibility_subject='ICE-GL∞'
|
|||
|
|
readonly instance_id=f3d4b730-7f02-452f-975b-7091a4800431
|
|||
|
|
readonly runtime=/usr/local/libexec/guanghu/pncc-runtime.mjs
|
|||
|
|
readonly persona_root=/var/lib/guanghu/personas/ICE-P-ZY001/pncc
|
|||
|
|
readonly repository=/var/lib/guanghu/personas/ICE-P-ZY001/pncc/repository
|
|||
|
|
readonly state_root=/run/guanghu/pncc-install
|
|||
|
|
readonly receipt_root=/guanghu/recovery/JD-FD-PRIMARY-pncc-20260816
|
|||
|
|
|
|||
|
|
[[ $source_commit =~ ^[0-9a-f]{40}$ ]]
|
|||
|
|
[[ -f $runtime_source && ! -L $runtime_source ]]
|
|||
|
|
[[ -d $seed_source && ! -L $seed_source ]]
|
|||
|
|
[[ -f $seed_source/.hololake/persona/manifest.json ]]
|
|||
|
|
[[ $(tr A-F a-f </sys/class/dmi/id/product_uuid | tr -d '\r\n') == "$instance_id" ]]
|
|||
|
|
[[ $(findmnt -n -o SOURCE /) == /dev/vda1 ]]
|
|||
|
|
getent passwd guanghu | grep -q '^guanghu:x:998:998:'
|
|||
|
|
/usr/bin/node --check "$runtime_source"
|
|||
|
|
|
|||
|
|
install -d -o root -g root -m 0755 "$(dirname "$runtime")"
|
|||
|
|
install -d -o root -g root -m 0700 "$receipt_root/rollback"
|
|||
|
|
if [[ -f $runtime ]]; then
|
|||
|
|
cp -a "$runtime" "$receipt_root/rollback/pncc-runtime.mjs.before"
|
|||
|
|
fi
|
|||
|
|
install -o root -g root -m 0755 "$runtime_source" "$runtime"
|
|||
|
|
|
|||
|
|
repository_created=0
|
|||
|
|
if [[ ! -e $repository ]]; then
|
|||
|
|
install -d -o guanghu -g guanghu -m 0700 "$repository"
|
|||
|
|
cp -a "$seed_source"/. "$repository"/
|
|||
|
|
chown -R guanghu:guanghu "$persona_root"
|
|||
|
|
chmod -R go-rwx "$persona_root"
|
|||
|
|
/usr/sbin/runuser -u guanghu -- git -C "$repository" init -q
|
|||
|
|
/usr/sbin/runuser -u guanghu -- git -C "$repository" add --all
|
|||
|
|
/usr/sbin/runuser -u guanghu -- env \
|
|||
|
|
GIT_AUTHOR_NAME='Guanghu PNCC Bootstrap' \
|
|||
|
|
GIT_AUTHOR_EMAIL='pncc-bootstrap@guanghu.local' \
|
|||
|
|
GIT_COMMITTER_NAME='Guanghu PNCC Bootstrap' \
|
|||
|
|
GIT_COMMITTER_EMAIL='pncc-bootstrap@guanghu.local' \
|
|||
|
|
git -C "$repository" commit -qm "bootstrap(pncc): establish persona-owned repository
|
|||
|
|
|
|||
|
|
Human-Responsibility-Subject: ${human_responsibility_subject}
|
|||
|
|
Persona-Cognitive-Author: UNBOUND
|
|||
|
|
Execution-Runtime: GUANGHU-OS-JD-PNCC-INSTALLER
|
|||
|
|
Authorization-Scope: GH-PNCC-REPOSITORY-BOOTSTRAP"
|
|||
|
|
repository_created=1
|
|||
|
|
elif [[ ! -d $repository/.git ]]; then
|
|||
|
|
echo 'PNCC_INSTALL_REFUSED: existing repository path is not a Git worktree' >&2
|
|||
|
|
exit 1
|
|||
|
|
fi
|
|||
|
|
|
|||
|
|
[[ -z $(/usr/sbin/runuser -u guanghu -- git -C "$repository" status --porcelain --untracked-files=all) ]]
|
|||
|
|
inspection=$(/usr/sbin/runuser -u guanghu -- /usr/bin/node "$runtime" inspect \
|
|||
|
|
--repository "$repository" --node-id "$node_id")
|
|||
|
|
grep -Fq '"carrierBindingState": "UNBOUND_EVIDENCE_REQUIRED"' <<<"$inspection"
|
|||
|
|
|
|||
|
|
cycle_created=0
|
|||
|
|
if [[ ! -e $repository/checkpoints/GUANGHU-PNCC-FIRST-CYCLE.hldp ]]; then
|
|||
|
|
rm -rf "$state_root"
|
|||
|
|
install -d -o guanghu -g guanghu -m 0700 "$state_root"
|
|||
|
|
boot_id=$(cat /proc/sys/kernel/random/boot_id)
|
|||
|
|
cycle=$(/usr/sbin/runuser -u guanghu -- /usr/bin/node "$runtime" cycle \
|
|||
|
|
--repository "$repository" --state-root "$state_root" --node-id "$node_id" \
|
|||
|
|
--boot-id "$boot_id" --request-id GUANGHU-PNCC-FIRST-CYCLE \
|
|||
|
|
--source-language-anchor '把人格代码频道真正部署到京东光湖 OS,并保持人格、载体、宿主与运行系统分开举证。' \
|
|||
|
|
--execution-runtime GUANGHU-OS-JD-PNCC)
|
|||
|
|
grep -Fq '"state": "DORMANT_AFTER_CHECKPOINT_COMMIT"' <<<"$cycle"
|
|||
|
|
cycle_created=1
|
|||
|
|
fi
|
|||
|
|
|
|||
|
|
[[ -z $(/usr/sbin/runuser -u guanghu -- git -C "$repository" status --porcelain --untracked-files=all) ]]
|
|||
|
|
git_head=$(/usr/sbin/runuser -u guanghu -- git -C "$repository" rev-parse HEAD)
|
|||
|
|
runtime_sha=$(sha256sum "$runtime" | awk '{print $1}')
|
|||
|
|
manifest_sha=$(sha256sum "$repository/.hololake/persona/manifest.json" | awk '{print $1}')
|
|||
|
|
cat >"$receipt_root/DEPLOYMENT-RECEIPT.hldp" <<EOF
|
|||
|
|
[hldp]
|
|||
|
|
schema=guanghu.jd-pncc-deployment/v1
|
|||
|
|
node_id=${node_id}
|
|||
|
|
persona_id=${persona_id}
|
|||
|
|
human_responsibility_subject=${human_responsibility_subject}
|
|||
|
|
source_commit=${source_commit}
|
|||
|
|
runtime_sha256=${runtime_sha}
|
|||
|
|
manifest_sha256=${manifest_sha}
|
|||
|
|
persona_repository=${repository}
|
|||
|
|
persona_repository_git_head=${git_head}
|
|||
|
|
repository_created=${repository_created}
|
|||
|
|
first_cycle_created=${cycle_created}
|
|||
|
|
carrier_binding=UNBOUND_EVIDENCE_REQUIRED
|
|||
|
|
model_inference_started=false
|
|||
|
|
reality_execution_allowed=false
|
|||
|
|
private_repository_publication=NONE
|
|||
|
|
result=PASS_100
|
|||
|
|
EOF
|
|||
|
|
chmod 0600 "$receipt_root/DEPLOYMENT-RECEIPT.hldp"
|
|||
|
|
sha256sum "$receipt_root/DEPLOYMENT-RECEIPT.hldp" >"$receipt_root/DEPLOYMENT-RECEIPT.hldp.sha256"
|
|||
|
|
sync
|
|||
|
|
printf 'GUANGHU_PNCC_INSTALLED persona=%s head=%s runtime_sha256=%s carrier=UNBOUND_EVIDENCE_REQUIRED\n' \
|
|||
|
|
"$persona_id" "$git_head" "$runtime_sha"
|