feat(tcs): lock shared desktop behavior framework

This commit is contained in:
冰朔 2026-08-24 00:26:34 +08:00
commit 148f24a7e7
9 changed files with 1093 additions and 0 deletions

View file

@ -15,3 +15,5 @@ The current boundary audit proves why the outer loader is not yet runnable: the
Mother-brain corpus admission now has an explicit TCS source gate. A transport `user` role is not author proof; host injection, pasted model output, persona-derived pages, language-world simulation and unverified embedded quotes cannot be promoted as direct BingShuo language. The first new five-event correction chain preserves the original text hashes separately from the rebuildable interpretation graph and remains provisional until the original rollout envelope and native LPM replay both pass.
Stage five applied that gate to the first five-event chain and failed it closed: two derived copies agree byte-for-byte, but the original laptop rollout is unavailable and the task-service readback returned an upstream access challenge. The candidate graph is preserved without core promotion. Work continued from the stronger current direct-language anchor instead, producing a seven-node contiguous chain from the bidirectional translation gap through language-world growth, mother-brain/library separation and bounded Agent TCS brains. Its minimum `CORE.ECHO` replay has executed with target readback; this is evidence of bounded TCS replay, not native LPM graph execution.
Stage six converts the frozen twelve-repository desktop research package into one TCS-native framework behavior contract. No upstream project is selected as HoloLake and no old-language product source is imported. The framework is the TCS protocol itself: observe one structured object tree, resolve one snapshot-scoped stable object, authorize one exact semantic action, execute, reobserve, read the state diff, verify the declared effect through independent target readback, and only then issue a receipt. Dispatch success, process exit, screenshots and pixel coordinates are not effect proof. The protocol and its bilingual projections compile under the Stage-3 fixed-point compiler; desktop execution remains pending the generic GIR action-graph machine primitive, signed capability registry, module installation and mounting.