feat(tcs): install and activate v3 native modules

This commit is contained in:
冰朔 2026-08-24 12:28:00 +08:00
commit 6199e5b6bf
155 changed files with 16114 additions and 54 deletions

View file

@ -23,3 +23,5 @@ Stage seven returns to the direct engineering-language anchor and extracts a six
Stage eight uses BingShuo's explicit continuation to demote fourth-generation code to a mechanical machine-runtime role. A TCS-defined macOS host adapter was projected into a derived `v0.1.2` Rust runtime without adding LPM, desktop or natural-language product semantics. The Apple Developer ID-signed binary now executes the outer `TCS.EXECUTE_ACTION_GRAPH` bootstrap and independently reads back its inner `CORE.ECHO` target and outer receipt. A dedicated development-line Ed25519 key remains in the local macOS login keychain; only its public key and fingerprint are stored here. The capability registry signature verifies and is `SIGNED_VERIFIED_NOT_INSTALLED`. Signing does not manufacture missing LPM or desktop provider GIR, so those modules remain uninstalled and unmounted until their TCS provider programs exist.
Stage nine defines `CORE.APPLY_EXACT_STATE_TRANSITION` in TCS before projecting its compare/atomic-write/hash/readback mechanics into the fourth-generation host. The Stage-4 G→H compiler semantic fixed point passes. TCS provider GIR now lowers one LPM P2 neuron transition and one isolated virtual shared-desktop OPEN transition to that opaque machine primitive; both child targets and both outer loader receipts read back exactly, while the host reports `host_semantic_authority=false`. The existing signed capability registry is intentionally stale after the host and provider hashes changed. No module is called installed or mounted until v3 packages are built and a newly signed registry admits those exact bytes.
Stages ten and eleven build immutable v3 mother-brain and virtual-desktop provider packages, add a TCS-defined `CORE.INSTALL_VERIFIED_MODULE` primitive, prove the Stage-5 I→J compiler fixed point, and sign registry v3 against the final Apple Developer ID-signed host. The mechanical runtime independently verifies the Ed25519 signature, signed payload, current host hash, every package source hash and every installed readback hash before atomically installing eight canonical files per module. Both modules then move through separate installed, mounted and active states. Activation is bound to the exact prior mount hash and follows P4, P5 and isolated virtual-desktop target readbacks. This activation is local to the ICE-CH-ZC001 development line; it does not claim production trust, remote deployment or a real macOS desktop action.