feat(os): make Guanghu the language-primary boot target
This commit is contained in:
parent
8ab7f4fc28
commit
44bccdd2be
9 changed files with 490 additions and 9 deletions
|
|
@ -74,6 +74,22 @@
|
||||||
- 按需唤醒模型、人格执行体和模块,清除无关常驻服务;
|
- 按需唤醒模型、人格执行体和模块,清除无关常驻服务;
|
||||||
- 公共导航继续自动读取同一 REPO-012 主线锚点。
|
- 公共导航继续自动读取同一 REPO-012 主线锚点。
|
||||||
|
|
||||||
|
阶段 C 的服务器启动合同由 `guanghu-language-primary.target` 承担。它不是把 Linux
|
||||||
|
换一个品牌名称,而是把启动完成判定从普通 `graphical.target` 改为以下不可拆分的门:
|
||||||
|
|
||||||
|
```text
|
||||||
|
五域世界与节点授权有效
|
||||||
|
→ 铸渊语言主控在线
|
||||||
|
→ 固定执行桥只读策略有效
|
||||||
|
→ 授权、架构部署和事件服务在线
|
||||||
|
→ 公共代码与导航入口 HTTP 200
|
||||||
|
→ 写入服务器启动回执
|
||||||
|
```
|
||||||
|
|
||||||
|
门失败时不得把系统标记为光湖语言主控完成。安装器只有在当前运行周期通过全部门后才
|
||||||
|
切换 systemd 默认目标;失败会恢复原默认目标。该切换不写磁盘启动区、不改变 Linux
|
||||||
|
内核,也不删除并行保存的 GOSK/GHAL 裸机候选。
|
||||||
|
|
||||||
### 阶段 D:分布式执行
|
### 阶段 D:分布式执行
|
||||||
|
|
||||||
- 用户设备登记自己的渲染、文件、应用和推理能力;
|
- 用户设备登记自己的渲染、文件、应用和推理能力;
|
||||||
|
|
@ -93,14 +109,14 @@
|
||||||
- 生产路线架构纠正;
|
- 生产路线架构纠正;
|
||||||
- 第一条类型化协议执行桥;
|
- 第一条类型化协议执行桥;
|
||||||
- systemd 状态与重启动作的白名单、授权、回滚和目标读回合同;
|
- systemd 状态与重启动作的白名单、授权、回滚和目标读回合同;
|
||||||
|
- 光湖语言主控的世界启动门、系统服务依赖、公共入口验收和服务器回执合同;
|
||||||
- 对应单元和集成测试。
|
- 对应单元和集成测试。
|
||||||
|
|
||||||
仍未完成:
|
仍未完成:
|
||||||
|
|
||||||
- REPO-012 当前协议提交的不可变绑定;
|
- 光湖语言主控目标在京东节点的安装与重启后实机回读;
|
||||||
- 京东节点策略生成与只读部署;
|
|
||||||
- 模型路由、人格生命周期和分布式设备执行器;
|
- 模型路由、人格生命周期和分布式设备执行器;
|
||||||
- 全部注册协议的工程实现;
|
- 全部注册协议的工程实现;
|
||||||
- 生产主控入口切换。
|
- 普通 Linux 管理入口的紧急维护边界收紧。
|
||||||
|
|
||||||
这些未完成项分别保持 0,不能由本架构文件或本地测试冒充为已部署。
|
这些未完成项分别保持 0,不能由本架构文件或本地测试冒充为已部署。
|
||||||
|
|
|
||||||
|
|
@ -6,12 +6,12 @@
|
||||||
> Bare-metal GOSK/GHAL remains a parallel research and recovery lane. It no
|
> Bare-metal GOSK/GHAL remains a parallel research and recovery lane. It no
|
||||||
> longer blocks the first production cognitive-control delivery.
|
> longer blocks the first production cognitive-control delivery.
|
||||||
>
|
>
|
||||||
> Protected native residency and recovery control are `PASS_100`. Production
|
> Protected bare-metal residency, recovery control, and native anchor HTTP are
|
||||||
> native anchor HTTP is now `PASS_100` on the physical JD node: a standard
|
> `PASS_100` on the physical JD node. Bare-metal production cutover remains
|
||||||
> client read the complete `GLW-PUBLIC-NAV-ANCHOR-001` response after the TCP
|
> `0`, because that research kernel does not yet provide code-channel and
|
||||||
> option and sequence corrections. Production cutover remains `0` because the
|
> public-front-door service equivalence. This no longer blocks the accepted
|
||||||
> native code-channel and public-front-door equivalence gates are still open.
|
> production path: Guanghu is the language-primary control system, while Linux
|
||||||
> Linux therefore remains the unattended default.
|
> remains the cooperative execution and rescue substrate.
|
||||||
|
|
||||||
This directory implements the handoff from the registered HLDP language world
|
This directory implements the handoff from the registered HLDP language world
|
||||||
to deterministic real-world execution. `crates/execution-bridge` is the first
|
to deterministic real-world execution. `crates/execution-bridge` is the first
|
||||||
|
|
@ -50,6 +50,27 @@ The registered translation chain is:
|
||||||
TCS -> HLDP -> GLC -> GIR -> BTCP -> GOSK -> GHAL -> hardware
|
TCS -> HLDP -> GLC -> GIR -> BTCP -> GOSK -> GHAL -> hardware
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Language-primary boot target
|
||||||
|
|
||||||
|
`guanghu-language-primary.target` makes the accepted cognitive-control model
|
||||||
|
an explicit boot contract instead of leaving the controller as an unrelated
|
||||||
|
Linux service. The target:
|
||||||
|
|
||||||
|
1. validates the exact JD machine, `/guanghu/current` five-domain world,
|
||||||
|
standing authorization, and read-only execution policy;
|
||||||
|
2. requires the Zhuyuan controller, public navigation, authorization,
|
||||||
|
architecture provision, and deployment-event services;
|
||||||
|
3. accepts the boot only after the controller reports `RUNNING_COMPANION`,
|
||||||
|
the execution substrate reports `PASS_100`, and both public entrypoints
|
||||||
|
return HTTP 200; and
|
||||||
|
4. writes a server-owned receipt without changing the kernel, bootloader, or
|
||||||
|
preserved bare-metal candidate.
|
||||||
|
|
||||||
|
`scripts/install-jd-language-primary-target.sh` starts and verifies the target
|
||||||
|
before changing the systemd default. Any failed installation restores the
|
||||||
|
previous default target and removes only the newly installed boot-contract
|
||||||
|
files.
|
||||||
|
|
||||||
## World contents
|
## World contents
|
||||||
|
|
||||||
`WORLD-MANIFEST.hldp` registers exactly five domains, one logical broadcast
|
`WORLD-MANIFEST.hldp` registers exactly five domains, one logical broadcast
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,28 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Verify the complete Guanghu language-primary boot projection
|
||||||
|
Requires=guanghu-world-gate.service
|
||||||
|
After=guanghu-world-gate.service
|
||||||
|
After=network-online.target
|
||||||
|
After=bingshuo-tcs-living-controller.service
|
||||||
|
After=guanghu-ai-discovery.service
|
||||||
|
After=lake-lamp-authz.service
|
||||||
|
After=lake-lamp-architecture-provision.service
|
||||||
|
After=lake-lamp-deployment-event-worker.service
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
ExecStart=/usr/local/libexec/guanghu-os/verify-jd-language-primary-acceptance
|
||||||
|
RemainAfterExit=yes
|
||||||
|
User=root
|
||||||
|
Group=root
|
||||||
|
NoNewPrivileges=yes
|
||||||
|
PrivateTmp=yes
|
||||||
|
ProtectSystem=strict
|
||||||
|
ProtectHome=yes
|
||||||
|
ReadOnlyPaths=/guanghu /opt/guanghu/execution-bridge
|
||||||
|
ReadWritePaths=/var/lib/guanghu/language-primary/receipts
|
||||||
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
||||||
|
LockPersonality=yes
|
||||||
|
UMask=0077
|
||||||
|
|
||||||
|
|
@ -0,0 +1,20 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Guanghu OS language-primary control target
|
||||||
|
Requires=multi-user.target
|
||||||
|
Requires=guanghu-world-gate.service
|
||||||
|
Requires=bingshuo-tcs-living-controller.service
|
||||||
|
Requires=guanghu-ai-discovery.service
|
||||||
|
Requires=lake-lamp-authz.service
|
||||||
|
Requires=lake-lamp-architecture-provision.service
|
||||||
|
Requires=lake-lamp-deployment-event-worker.service
|
||||||
|
Requires=guanghu-boot-acceptance.service
|
||||||
|
After=multi-user.target
|
||||||
|
After=guanghu-world-gate.service
|
||||||
|
After=bingshuo-tcs-living-controller.service
|
||||||
|
After=guanghu-ai-discovery.service
|
||||||
|
After=lake-lamp-authz.service
|
||||||
|
After=lake-lamp-architecture-provision.service
|
||||||
|
After=lake-lamp-deployment-event-worker.service
|
||||||
|
After=guanghu-boot-acceptance.service
|
||||||
|
AllowIsolate=yes
|
||||||
|
|
||||||
|
|
@ -0,0 +1,23 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Validate the Guanghu language world before normal controllers start
|
||||||
|
After=local-fs.target
|
||||||
|
Before=bingshuo-tcs-living-controller.service
|
||||||
|
Before=guanghu-ai-discovery.service
|
||||||
|
Before=lake-lamp-authz.service
|
||||||
|
Before=lake-lamp-architecture-provision.service
|
||||||
|
Before=lake-lamp-deployment-event-worker.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
ExecStart=/usr/local/libexec/guanghu-os/verify-jd-language-primary-world
|
||||||
|
RemainAfterExit=yes
|
||||||
|
User=root
|
||||||
|
Group=root
|
||||||
|
NoNewPrivileges=yes
|
||||||
|
PrivateTmp=yes
|
||||||
|
ProtectSystem=strict
|
||||||
|
ProtectHome=yes
|
||||||
|
ReadOnlyPaths=/guanghu /opt/guanghu/execution-bridge
|
||||||
|
RestrictAddressFamilies=AF_UNIX
|
||||||
|
LockPersonality=yes
|
||||||
|
|
||||||
|
|
@ -0,0 +1,135 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
usage() {
|
||||||
|
echo "usage: install-jd-language-primary-target.sh <guanghu-os-source> <source-commit>" >&2
|
||||||
|
exit 64
|
||||||
|
}
|
||||||
|
|
||||||
|
test "$#" = 2 || usage
|
||||||
|
test "${EUID}" = 0 || exit 77
|
||||||
|
|
||||||
|
source_root="$(readlink -f "$1")"
|
||||||
|
source_commit=$2
|
||||||
|
expected_machine_id="caa7b1019517470f9d1368b6e79db49e"
|
||||||
|
expected_instance_id="f3d4b730-7f02-452f-975b-7091a4800431"
|
||||||
|
install_root="/usr/local/libexec/guanghu-os"
|
||||||
|
state_root="/var/lib/guanghu/language-primary"
|
||||||
|
receipt_root="${state_root}/receipts"
|
||||||
|
backup_root="${state_root}/backups/${source_commit}"
|
||||||
|
previous_default="$(systemctl get-default)"
|
||||||
|
installed=0
|
||||||
|
default_changed=0
|
||||||
|
|
||||||
|
[[ ${source_commit} =~ ^[0-9a-f]{40}$ ]]
|
||||||
|
test -f "${source_root}/.guanghu-source-commit"
|
||||||
|
test "$(cat "${source_root}/.guanghu-source-commit")" = "${source_commit}"
|
||||||
|
test "$(cat /etc/machine-id)" = "${expected_machine_id}"
|
||||||
|
test "$(tr '[:upper:]' '[:lower:]' </sys/class/dmi/id/product_uuid)" = \
|
||||||
|
"${expected_instance_id}"
|
||||||
|
test -f "${source_root}/packaging/systemd/guanghu-language-primary.target"
|
||||||
|
test -f "${source_root}/packaging/systemd/guanghu-world-gate.service"
|
||||||
|
test -f "${source_root}/packaging/systemd/guanghu-boot-acceptance.service"
|
||||||
|
test -f "${source_root}/scripts/verify-jd-language-primary-world.sh"
|
||||||
|
test -f "${source_root}/scripts/verify-jd-language-primary-acceptance.sh"
|
||||||
|
test "${previous_default}" = graphical.target
|
||||||
|
test ! -e "${backup_root}"
|
||||||
|
|
||||||
|
/guanghu/bin/ghctl authorize /guanghu/current install_world_version |
|
||||||
|
grep -q '^GUANGHU_ACTION_AUTHORIZED$'
|
||||||
|
|
||||||
|
for path in \
|
||||||
|
/etc/systemd/system/guanghu-language-primary.target \
|
||||||
|
/etc/systemd/system/guanghu-world-gate.service \
|
||||||
|
/etc/systemd/system/guanghu-boot-acceptance.service \
|
||||||
|
"${install_root}/verify-jd-language-primary-world" \
|
||||||
|
"${install_root}/verify-jd-language-primary-acceptance"; do
|
||||||
|
test ! -e "${path}"
|
||||||
|
done
|
||||||
|
|
||||||
|
rollback() {
|
||||||
|
if test "${default_changed}" = 1; then
|
||||||
|
systemctl set-default "${previous_default}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
if test "${installed}" = 1; then
|
||||||
|
systemctl stop guanghu-language-primary.target \
|
||||||
|
guanghu-boot-acceptance.service guanghu-world-gate.service \
|
||||||
|
>/dev/null 2>&1 || true
|
||||||
|
rm -f \
|
||||||
|
/etc/systemd/system/guanghu-language-primary.target \
|
||||||
|
/etc/systemd/system/guanghu-world-gate.service \
|
||||||
|
/etc/systemd/system/guanghu-boot-acceptance.service \
|
||||||
|
"${install_root}/verify-jd-language-primary-world" \
|
||||||
|
"${install_root}/verify-jd-language-primary-acceptance"
|
||||||
|
systemctl daemon-reload || true
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
trap rollback ERR
|
||||||
|
|
||||||
|
install -d -o root -g root -m 0755 "${install_root}"
|
||||||
|
install -d -o root -g root -m 0700 \
|
||||||
|
"${receipt_root}" "${backup_root}"
|
||||||
|
printf '%s\n' "${previous_default}" >"${backup_root}/previous-default-target"
|
||||||
|
|
||||||
|
install -o root -g root -m 0644 \
|
||||||
|
"${source_root}/packaging/systemd/guanghu-language-primary.target" \
|
||||||
|
/etc/systemd/system/guanghu-language-primary.target
|
||||||
|
install -o root -g root -m 0644 \
|
||||||
|
"${source_root}/packaging/systemd/guanghu-world-gate.service" \
|
||||||
|
/etc/systemd/system/guanghu-world-gate.service
|
||||||
|
install -o root -g root -m 0644 \
|
||||||
|
"${source_root}/packaging/systemd/guanghu-boot-acceptance.service" \
|
||||||
|
/etc/systemd/system/guanghu-boot-acceptance.service
|
||||||
|
install -o root -g root -m 0755 \
|
||||||
|
"${source_root}/scripts/verify-jd-language-primary-world.sh" \
|
||||||
|
"${install_root}/verify-jd-language-primary-world"
|
||||||
|
install -o root -g root -m 0755 \
|
||||||
|
"${source_root}/scripts/verify-jd-language-primary-acceptance.sh" \
|
||||||
|
"${install_root}/verify-jd-language-primary-acceptance"
|
||||||
|
installed=1
|
||||||
|
|
||||||
|
systemctl daemon-reload
|
||||||
|
systemctl start guanghu-language-primary.target
|
||||||
|
test "$(systemctl is-active guanghu-language-primary.target)" = active
|
||||||
|
test "$(systemctl is-active guanghu-world-gate.service)" = active
|
||||||
|
test "$(systemctl is-active guanghu-boot-acceptance.service)" = active
|
||||||
|
|
||||||
|
systemctl set-default guanghu-language-primary.target >/dev/null
|
||||||
|
default_changed=1
|
||||||
|
test "$(systemctl get-default)" = guanghu-language-primary.target
|
||||||
|
|
||||||
|
boot_id="$(cat /proc/sys/kernel/random/boot_id)"
|
||||||
|
boot_receipt="${receipt_root}/JD-FD-PRIMARY-LANGUAGE-PRIMARY-BOOT-${boot_id}.json"
|
||||||
|
test -f "${boot_receipt}"
|
||||||
|
jq -e '.result == "PASS_100" and .boot_changed == false' \
|
||||||
|
"${boot_receipt}" >/dev/null
|
||||||
|
|
||||||
|
install_receipt="${receipt_root}/JD-FD-PRIMARY-LANGUAGE-PRIMARY-INSTALL-${source_commit}.json"
|
||||||
|
jq -n \
|
||||||
|
--arg source_commit "${source_commit}" \
|
||||||
|
--arg previous_default "${previous_default}" \
|
||||||
|
--arg boot_receipt "${boot_receipt}" \
|
||||||
|
--arg observed_at "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
|
||||||
|
'{
|
||||||
|
schema: "guanghu.language-primary-install-receipt/v1",
|
||||||
|
receipt_id: ("JD-FD-PRIMARY-LANGUAGE-PRIMARY-INSTALL-" + $source_commit),
|
||||||
|
target_node_id: "JD-FD-PRIMARY",
|
||||||
|
source_repository: "REPO-014",
|
||||||
|
source_commit: $source_commit,
|
||||||
|
previous_default_target: $previous_default,
|
||||||
|
current_default_target: "guanghu-language-primary.target",
|
||||||
|
boot_receipt: $boot_receipt,
|
||||||
|
control_role: "GUANGHU_OS_LANGUAGE_PRIMARY",
|
||||||
|
linux_role: "COOPERATIVE_EXECUTION_AND_RESCUE_SUBSTRATE",
|
||||||
|
native_candidate_preserved: true,
|
||||||
|
disk_or_bootloader_changed: false,
|
||||||
|
rollback: ("systemctl set-default " + $previous_default),
|
||||||
|
observed_at: $observed_at,
|
||||||
|
result: "PASS_100"
|
||||||
|
}' >"${install_receipt}.tmp"
|
||||||
|
chmod 0600 "${install_receipt}.tmp"
|
||||||
|
mv "${install_receipt}.tmp" "${install_receipt}"
|
||||||
|
|
||||||
|
trap - ERR
|
||||||
|
printf 'PASS_100 target=guanghu-language-primary.target receipt=%s\n' \
|
||||||
|
"${install_receipt}"
|
||||||
|
|
@ -0,0 +1,88 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
source_root=${1:-}
|
||||||
|
[[ -n ${source_root} ]] || {
|
||||||
|
echo "usage: test-jd-language-primary-target-contract.sh <guanghu-os-source>" >&2
|
||||||
|
exit 64
|
||||||
|
}
|
||||||
|
|
||||||
|
target=${source_root}/packaging/systemd/guanghu-language-primary.target
|
||||||
|
world_gate_unit=${source_root}/packaging/systemd/guanghu-world-gate.service
|
||||||
|
acceptance_unit=${source_root}/packaging/systemd/guanghu-boot-acceptance.service
|
||||||
|
world_gate=${source_root}/scripts/verify-jd-language-primary-world.sh
|
||||||
|
acceptance=${source_root}/scripts/verify-jd-language-primary-acceptance.sh
|
||||||
|
installer=${source_root}/scripts/install-jd-language-primary-target.sh
|
||||||
|
|
||||||
|
for path in \
|
||||||
|
"${target}" \
|
||||||
|
"${world_gate_unit}" \
|
||||||
|
"${acceptance_unit}" \
|
||||||
|
"${world_gate}" \
|
||||||
|
"${acceptance}" \
|
||||||
|
"${installer}"; do
|
||||||
|
test -f "${path}"
|
||||||
|
done
|
||||||
|
|
||||||
|
grep -Fxq 'Requires=multi-user.target' "${target}"
|
||||||
|
grep -Fq 'guanghu-world-gate.service' "${target}"
|
||||||
|
grep -Fq 'guanghu-boot-acceptance.service' "${target}"
|
||||||
|
grep -Fq 'bingshuo-tcs-living-controller.service' "${target}"
|
||||||
|
grep -Fq 'guanghu-ai-discovery.service' "${target}"
|
||||||
|
grep -Fq 'lake-lamp-authz.service' "${target}"
|
||||||
|
grep -Fq 'lake-lamp-architecture-provision.service' "${target}"
|
||||||
|
grep -Fq 'lake-lamp-deployment-event-worker.service' "${target}"
|
||||||
|
grep -Fxq 'AllowIsolate=yes' "${target}"
|
||||||
|
|
||||||
|
grep -Fxq 'Type=oneshot' "${world_gate_unit}"
|
||||||
|
grep -Fxq 'RemainAfterExit=yes' "${world_gate_unit}"
|
||||||
|
grep -Fq 'Before=bingshuo-tcs-living-controller.service' "${world_gate_unit}"
|
||||||
|
grep -Fq '/usr/local/libexec/guanghu-os/verify-jd-language-primary-world' \
|
||||||
|
"${world_gate_unit}"
|
||||||
|
|
||||||
|
grep -Fxq 'Type=oneshot' "${acceptance_unit}"
|
||||||
|
grep -Fxq 'RemainAfterExit=yes' "${acceptance_unit}"
|
||||||
|
grep -Fq 'After=guanghu-world-gate.service' "${acceptance_unit}"
|
||||||
|
grep -Fq '/usr/local/libexec/guanghu-os/verify-jd-language-primary-acceptance' \
|
||||||
|
"${acceptance_unit}"
|
||||||
|
grep -Fq 'ReadWritePaths=/var/lib/guanghu/language-primary/receipts' \
|
||||||
|
"${acceptance_unit}"
|
||||||
|
|
||||||
|
grep -Fq '/guanghu/bin/ghctl wake /guanghu/current' "${world_gate}"
|
||||||
|
grep -Fq '/guanghu/bin/ghctl authorize /guanghu/current run_tests_and_health_checks' \
|
||||||
|
"${world_gate}"
|
||||||
|
grep -Fq 'caa7b1019517470f9d1368b6e79db49e' "${world_gate}"
|
||||||
|
grep -Fq 'f3d4b730-7f02-452f-975b-7091a4800431' "${world_gate}"
|
||||||
|
|
||||||
|
for service in \
|
||||||
|
bingshuo-tcs-living-controller.service \
|
||||||
|
guanghu-ai-discovery.service \
|
||||||
|
lake-lamp-authz.service \
|
||||||
|
lake-lamp-architecture-provision.service \
|
||||||
|
lake-lamp-deployment-event-worker.service; do
|
||||||
|
grep -Fq "${service}" "${acceptance}"
|
||||||
|
done
|
||||||
|
grep -Fq 'https://guanghulab.com/code/' "${acceptance}"
|
||||||
|
grep -Fq 'https://guanghulab.com/api/ai/v1/anchor' "${acceptance}"
|
||||||
|
grep -Fq '"phase" == "RUNNING_COMPANION"' "${acceptance}"
|
||||||
|
grep -Fq '"execution_substrate.state" == "PASS_100"' "${acceptance}"
|
||||||
|
grep -Fq 'boot_changed: false' "${acceptance}"
|
||||||
|
|
||||||
|
grep -Fq 'install_world_version' "${installer}"
|
||||||
|
grep -Fq '.guanghu-source-commit' "${installer}"
|
||||||
|
grep -Fq 'systemctl start guanghu-language-primary.target' "${installer}"
|
||||||
|
grep -Fq 'systemctl set-default guanghu-language-primary.target' "${installer}"
|
||||||
|
grep -Fq 'systemctl set-default "${previous_default}"' "${installer}"
|
||||||
|
grep -Fq 'rollback' "${installer}"
|
||||||
|
|
||||||
|
if grep -Eiq 'eval|sh -c|bash -c|rm -rf /|systemctl reboot|grub-reboot' \
|
||||||
|
"${world_gate}" "${acceptance}" "${installer}"; then
|
||||||
|
echo "language-primary path contains a forbidden unbounded execution primitive" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
for script in "${world_gate}" "${acceptance}" "${installer}"; do
|
||||||
|
bash -n "${script}"
|
||||||
|
done
|
||||||
|
|
||||||
|
echo "JD_LANGUAGE_PRIMARY_TARGET_CONTRACT_PASS_100"
|
||||||
|
|
@ -0,0 +1,107 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
expected_machine_id="caa7b1019517470f9d1368b6e79db49e"
|
||||||
|
receipt_root="/var/lib/guanghu/language-primary/receipts"
|
||||||
|
services=(
|
||||||
|
"bingshuo-tcs-living-controller.service"
|
||||||
|
"guanghu-ai-discovery.service"
|
||||||
|
"lake-lamp-authz.service"
|
||||||
|
"lake-lamp-architecture-provision.service"
|
||||||
|
"lake-lamp-deployment-event-worker.service"
|
||||||
|
)
|
||||||
|
|
||||||
|
test "$(cat /etc/machine-id)" = "${expected_machine_id}"
|
||||||
|
install -d -o root -g root -m 0700 "${receipt_root}"
|
||||||
|
|
||||||
|
ready=0
|
||||||
|
controller_json=""
|
||||||
|
authz_json=""
|
||||||
|
public_code_http="000"
|
||||||
|
public_anchor_http="000"
|
||||||
|
for _attempt in $(seq 1 30); do
|
||||||
|
services_ready=1
|
||||||
|
for service in "${services[@]}"; do
|
||||||
|
if test "$(systemctl is-active "${service}")" != active; then
|
||||||
|
services_ready=0
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
controller_json="$(
|
||||||
|
curl -fsS --max-time 3 http://127.0.0.1:3930/health 2>/dev/null || true
|
||||||
|
)"
|
||||||
|
authz_json="$(
|
||||||
|
curl -fsS --max-time 3 http://127.0.0.1:3921/health 2>/dev/null || true
|
||||||
|
)"
|
||||||
|
public_code_http="$(
|
||||||
|
curl -LfsS -o /dev/null -w '%{http_code}' --max-time 5 \
|
||||||
|
https://guanghulab.com/code/ 2>/dev/null || printf '000'
|
||||||
|
)"
|
||||||
|
public_anchor_http="$(
|
||||||
|
curl -LfsS -o /dev/null -w '%{http_code}' --max-time 5 \
|
||||||
|
https://guanghulab.com/api/ai/v1/anchor 2>/dev/null || printf '000'
|
||||||
|
)"
|
||||||
|
|
||||||
|
if test "${services_ready}" = 1 &&
|
||||||
|
jq -e '
|
||||||
|
."phase" == "RUNNING_COMPANION"
|
||||||
|
and ."execution_substrate.state" == "PASS_100"
|
||||||
|
and ."execution_substrate.linux_role" == "COOPERATIVE_EXECUTION_SUBSTRATE"
|
||||||
|
and ."execution_substrate.arbitrary_shell" == false
|
||||||
|
' <<<"${controller_json}" >/dev/null 2>&1 &&
|
||||||
|
jq -e '
|
||||||
|
.ok == true
|
||||||
|
and .merge_deployment_gate.configured == true
|
||||||
|
and .merge_deployment_gate.mode == "human-merged-pull-request-only"
|
||||||
|
' <<<"${authz_json}" >/dev/null 2>&1 &&
|
||||||
|
test "${public_code_http}" = 200 &&
|
||||||
|
test "${public_anchor_http}" = 200; then
|
||||||
|
ready=1
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
test "${ready}" = 1
|
||||||
|
|
||||||
|
boot_id="$(cat /proc/sys/kernel/random/boot_id)"
|
||||||
|
observed_at="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
||||||
|
receipt="${receipt_root}/JD-FD-PRIMARY-LANGUAGE-PRIMARY-BOOT-${boot_id}.json"
|
||||||
|
world_target="$(readlink -f /guanghu/current)"
|
||||||
|
execution_release="$(readlink -f /opt/guanghu/execution-bridge/current)"
|
||||||
|
controller_receipt="$(
|
||||||
|
jq -r '.receipt_id' <<<"${controller_json}"
|
||||||
|
)"
|
||||||
|
|
||||||
|
jq -n \
|
||||||
|
--arg boot_id "${boot_id}" \
|
||||||
|
--arg observed_at "${observed_at}" \
|
||||||
|
--arg world_target "${world_target}" \
|
||||||
|
--arg execution_release "${execution_release}" \
|
||||||
|
--arg controller_receipt "${controller_receipt}" \
|
||||||
|
'{
|
||||||
|
schema: "guanghu.language-primary-boot-receipt/v1",
|
||||||
|
receipt_id: ("JD-FD-PRIMARY-LANGUAGE-PRIMARY-BOOT-" + $boot_id),
|
||||||
|
target_node_id: "JD-FD-PRIMARY",
|
||||||
|
boot_id: $boot_id,
|
||||||
|
control_role: "GUANGHU_OS_LANGUAGE_PRIMARY",
|
||||||
|
linux_role: "COOPERATIVE_EXECUTION_AND_RESCUE_SUBSTRATE",
|
||||||
|
world_target: $world_target,
|
||||||
|
execution_release: $execution_release,
|
||||||
|
controller_receipt: $controller_receipt,
|
||||||
|
world_gate: "PASS_100",
|
||||||
|
controller_gate: "PASS_100",
|
||||||
|
execution_substrate_gate: "PASS_100",
|
||||||
|
service_gate: "PASS_100",
|
||||||
|
public_code_http: 200,
|
||||||
|
public_anchor_http: 200,
|
||||||
|
arbitrary_shell: false,
|
||||||
|
boot_changed: false,
|
||||||
|
bare_metal_candidate_preserved: true,
|
||||||
|
observed_at: $observed_at,
|
||||||
|
result: "PASS_100"
|
||||||
|
}' >"${receipt}.tmp"
|
||||||
|
chmod 0600 "${receipt}.tmp"
|
||||||
|
mv "${receipt}.tmp" "${receipt}"
|
||||||
|
|
||||||
|
printf 'GUANGHU_LANGUAGE_PRIMARY_BOOT_PASS_100 receipt=%s\n' "${receipt}"
|
||||||
|
|
||||||
|
|
@ -0,0 +1,43 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
expected_machine_id="caa7b1019517470f9d1368b6e79db49e"
|
||||||
|
expected_instance_id="f3d4b730-7f02-452f-975b-7091a4800431"
|
||||||
|
execution_policy="/opt/guanghu/execution-bridge/current/policy.json"
|
||||||
|
|
||||||
|
test "$(cat /etc/machine-id)" = "${expected_machine_id}"
|
||||||
|
test "$(tr '[:upper:]' '[:lower:]' </sys/class/dmi/id/product_uuid)" = \
|
||||||
|
"${expected_instance_id}"
|
||||||
|
test -L /guanghu/current
|
||||||
|
test -f /guanghu/current/WORLD-MANIFEST.hldp
|
||||||
|
test -f /guanghu/current/CURRENT.hldp
|
||||||
|
test -x /guanghu/bin/ghctl
|
||||||
|
test -f "${execution_policy}"
|
||||||
|
|
||||||
|
wake_output="$(/guanghu/bin/ghctl wake /guanghu/current)"
|
||||||
|
grep -Fxq 'GUANGHU_WORLD_OK' <<<"${wake_output}"
|
||||||
|
grep -Fxq 'world_id=GLW-ROOT-0001' <<<"${wake_output}"
|
||||||
|
grep -Fxq 'domains=5' <<<"${wake_output}"
|
||||||
|
grep -Fxq 'authorization=GH-OS-AUTH-BINGSHUO-JD-FD-PRIMARY-001' \
|
||||||
|
<<<"${wake_output}"
|
||||||
|
|
||||||
|
authorization_output="$(
|
||||||
|
/guanghu/bin/ghctl authorize /guanghu/current run_tests_and_health_checks
|
||||||
|
)"
|
||||||
|
grep -Fxq 'GUANGHU_ACTION_AUTHORIZED' <<<"${authorization_output}"
|
||||||
|
grep -Fxq 'target=JD-FD-PRIMARY' <<<"${authorization_output}"
|
||||||
|
|
||||||
|
jq -e '
|
||||||
|
.schema == "guanghu.execution-policy/v1"
|
||||||
|
and .target_node_id == "JD-FD-PRIMARY"
|
||||||
|
and .allow_status == true
|
||||||
|
and .allow_restart == false
|
||||||
|
and .mutation_grants == []
|
||||||
|
' "${execution_policy}" >/dev/null
|
||||||
|
|
||||||
|
printf '%s\n' \
|
||||||
|
'GUANGHU_LANGUAGE_PRIMARY_WORLD_PASS_100' \
|
||||||
|
'target=JD-FD-PRIMARY' \
|
||||||
|
'world=GLW-ROOT-0001' \
|
||||||
|
'domains=5' \
|
||||||
|
'linux_role=COOPERATIVE_EXECUTION_SUBSTRATE'
|
||||||
Loading…
Reference in a new issue