feat(hololake): connect enterprise device challenge flow
This commit is contained in:
parent
be31c4136b
commit
6b23f710e1
19 changed files with 1220 additions and 14 deletions
|
|
@ -0,0 +1,112 @@
|
|||
{
|
||||
"compiled_from": {
|
||||
"compiler_id": "TCS-COMPILER-STAGE1-0001",
|
||||
"compiler_state": "TCS_COMPILER_GIR_EXECUTED",
|
||||
"source_sha256": "c32cd3e16fdd64588addca115821a49bb47bf39b584670df031cf92028a8d232"
|
||||
},
|
||||
"declaration": {
|
||||
"boundaries": {
|
||||
"values": [
|
||||
"服务不保存Forgejo密码",
|
||||
"设备私钥从不离开成员本机Keychain",
|
||||
"机器指纹不能单独认证",
|
||||
"会话只限单域单仓且十分钟过期",
|
||||
"企业会话不替代Forgejo自身仓库登录",
|
||||
"冰朔公共语言主控仓继续走JD第五域桥接而非普通人类登录",
|
||||
"本轮未登记任何真实成员设备"
|
||||
]
|
||||
},
|
||||
"header": {
|
||||
"canonical_uri": "product-source/hololake-clean-desktop/language/HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903.tcs",
|
||||
"compatibility": [
|
||||
"GH-CVM-MAIN-PROD-01",
|
||||
"PYTHON/3.10",
|
||||
"ED25519",
|
||||
"NGINX"
|
||||
],
|
||||
"language": "TCS/0.1",
|
||||
"lifecycle": "CANDIDATE",
|
||||
"name_en": "HoloLake Enterprise Responsibility Device Gate Deployment Receipt",
|
||||
"name_zh": "HoloLake企业责任设备门部署回执",
|
||||
"profile": "PUBLIC-PRODUCT-ENGINEERING/1",
|
||||
"protocols": [
|
||||
"HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903",
|
||||
"HLP-ENTERPRISE-RESPONSIBILITY-ENTRANCE-0001"
|
||||
],
|
||||
"schema": "tcs.receipt/v1",
|
||||
"version": "1.0.0"
|
||||
},
|
||||
"integrity": {
|
||||
"existing_services_preserved": "PASS",
|
||||
"source_archive_sha256": "91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2",
|
||||
"source_transport_manifest_sha256": "653ae0ca824fd8b9fff8d8532e82eddce63a8aa9f070e7a6aa3f863834e4ae77",
|
||||
"tcs_stage1_compilation": "PASS",
|
||||
"unknown_device_negative": "PASS"
|
||||
},
|
||||
"next": {
|
||||
"optional": [
|
||||
"团队成员从HoloLake使用本人凭证完成首次设备登记",
|
||||
"正向验证挑战与单仓会话",
|
||||
"后续加入个人服务器二次桥接证明"
|
||||
],
|
||||
"state": "SERVER_GATE_ACTIVE_CLIENT_INTEGRATION_REBUILD_REQUIRED"
|
||||
},
|
||||
"operation": {
|
||||
"values": [
|
||||
"验证源码运输归档与manifest",
|
||||
"解包到/opt/guanghu-hololake-enterprise-gate/releases/be31c41",
|
||||
"创建独立lighthouse权限数据库与服务密钥",
|
||||
"安装guanghu-hololake-enterprise-gate.service",
|
||||
"加入guanghu.chat精确device-gate路由",
|
||||
"执行本地和外部健康、未知设备拒绝及原服务存活测试"
|
||||
]
|
||||
},
|
||||
"proof": {
|
||||
"current_link": "/opt/guanghu-hololake-enterprise-gate/current",
|
||||
"database": "/var/lib/guanghu-hololake-enterprise-gate/gate.sqlite3",
|
||||
"nginx_backup": "/etc/nginx/sites-enabled/guanghu.chat.pre-hololake-device-gate-be31c41",
|
||||
"nginx_snippet": "/etc/nginx/snippets/guanghu-hololake-enterprise-gate.conf",
|
||||
"server_release": "/opt/guanghu-hololake-enterprise-gate/releases/be31c41"
|
||||
},
|
||||
"request": {
|
||||
"scope": "GH-CVM-MAIN-PROD-01独立8033服务与精确Nginx路由",
|
||||
"source": "BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903",
|
||||
"value": "部署企业四域负责人通过HoloLake本机设备和人格编号验证后进入本人责任仓库的服务端验证门。"
|
||||
},
|
||||
"result": {
|
||||
"active_sessions": 0,
|
||||
"endpoint": "https://guanghu.chat/api/hololake/enterprise/device-gate",
|
||||
"node_id": "GH-CVM-MAIN-PROD-01",
|
||||
"registered_devices": 0,
|
||||
"service": "guanghu-hololake-enterprise-gate.service",
|
||||
"service_state": "ACTIVE",
|
||||
"source_archive_sha256": "91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2",
|
||||
"source_commit": "be31c41",
|
||||
"state": "PASS"
|
||||
},
|
||||
"verification": {
|
||||
"values": [
|
||||
"DMI UUID为10ace744-13e1-472e-8dba-6bb823a073bf",
|
||||
"服务器Python cryptography Ed25519测试2项通过",
|
||||
"systemd服务active",
|
||||
"127.0.0.1:8033/health返回ok",
|
||||
"外部HTTPS device-gate/health返回ok",
|
||||
"未知设备领取挑战返回HTTP404 registered device required",
|
||||
"guanghu-enterprise-identity.service保持active",
|
||||
"guanghu-flagos-collaboration.service保持active",
|
||||
"nginx.service保持active",
|
||||
"当前设备与会话数量均为0未伪造成员"
|
||||
]
|
||||
}
|
||||
},
|
||||
"executable": false,
|
||||
"identity": {
|
||||
"declaration_id": "HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903",
|
||||
"declaration_kind": "RECEIPT",
|
||||
"language_version": "0.1"
|
||||
},
|
||||
"native_self_hosted": true,
|
||||
"natural_language_is_typed_data": true,
|
||||
"schema": "guanghu.declaration-gir/v1",
|
||||
"unresolved_natural_language": false
|
||||
}
|
||||
|
|
@ -0,0 +1,130 @@
|
|||
# HoloLake Enterprise Responsibility Device Gate Deployment Receipt · Human Engineering Language (English)
|
||||
|
||||
> This is an English reading projection of validated native TCS/HLDP source. It is not a new canonical source and grants no execution authority.
|
||||
|
||||
## What this is
|
||||
|
||||
This is a **receipt** declaration with identifier `HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903` and version `1.0.0`. The projector validates it with the Stage-1 compiler before changing its reading order.
|
||||
|
||||
## Who is here
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## Why this started
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## What changed
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## How it will execute
|
||||
|
||||
This is a non-executable declaration and has no action graph.
|
||||
|
||||
## Boundaries and exception handling
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## How completion is proven
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## Where to continue next time
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## Source and verification
|
||||
|
||||
- **Native declaration identifier**: `HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903`
|
||||
- **Native declaration kind**: `RECEIPT`
|
||||
- **TCS source SHA-256**: `c32cd3e16fdd64588addca115821a49bb47bf39b584670df031cf92028a8d232`
|
||||
- **Validation compiler**: `TCS-COMPILER-STAGE1-0001`
|
||||
- **Projection protocol**: `GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
|
||||
|
||||
## Complete native structure cross-reference
|
||||
|
||||
All top-level structures and field paths are retained below so a reader can audit whether the projection omitted information.
|
||||
|
||||
- **boundaries** `boundaries`
|
||||
- **values** `boundaries.values`
|
||||
- 服务不保存Forgejo密码
|
||||
- 设备私钥从不离开成员本机Keychain
|
||||
- 机器指纹不能单独认证
|
||||
- 会话只限单域单仓且十分钟过期
|
||||
- 企业会话不替代Forgejo自身仓库登录
|
||||
- 冰朔公共语言主控仓继续走JD第五域桥接而非普通人类登录
|
||||
- 本轮未登记任何真实成员设备
|
||||
- **header** `header`
|
||||
- **canonical source path**:product-source/hololake-clean-desktop/language/HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903.tcs `header.canonical_uri`
|
||||
- **compatibility** `header.compatibility`
|
||||
- GH-CVM-MAIN-PROD-01
|
||||
- PYTHON/3.10
|
||||
- ED25519
|
||||
- NGINX
|
||||
- **language**:TCS/0.1 `header.language`
|
||||
- **lifecycle**:CANDIDATE `header.lifecycle`
|
||||
- **English name**:HoloLake Enterprise Responsibility Device Gate Deployment Receipt `header.name_en`
|
||||
- **Chinese name**:HoloLake企业责任设备门部署回执 `header.name_zh`
|
||||
- **profile**:PUBLIC-PRODUCT-ENGINEERING/1 `header.profile`
|
||||
- **protocols** `header.protocols`
|
||||
- HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903
|
||||
- HLP-ENTERPRISE-RESPONSIBILITY-ENTRANCE-0001
|
||||
- **schema**:tcs.receipt/v1 `header.schema`
|
||||
- **version**:1.0.0 `header.version`
|
||||
- **integrity** `integrity`
|
||||
- **existing_services_preserved**:PASS `integrity.existing_services_preserved`
|
||||
- **source_archive_sha256**:91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2 `integrity.source_archive_sha256`
|
||||
- **source_transport_manifest_sha256**:653ae0ca824fd8b9fff8d8532e82eddce63a8aa9f070e7a6aa3f863834e4ae77 `integrity.source_transport_manifest_sha256`
|
||||
- **tcs_stage1_compilation**:PASS `integrity.tcs_stage1_compilation`
|
||||
- **unknown_device_negative**:PASS `integrity.unknown_device_negative`
|
||||
- **next** `next`
|
||||
- **optional** `next.optional`
|
||||
- 团队成员从HoloLake使用本人凭证完成首次设备登记
|
||||
- 正向验证挑战与单仓会话
|
||||
- 后续加入个人服务器二次桥接证明
|
||||
- **state**:SERVER_GATE_ACTIVE_CLIENT_INTEGRATION_REBUILD_REQUIRED `next.state`
|
||||
- **operation** `operation`
|
||||
- **values** `operation.values`
|
||||
- 验证源码运输归档与manifest
|
||||
- 解包到/opt/guanghu-hololake-enterprise-gate/releases/be31c41
|
||||
- 创建独立lighthouse权限数据库与服务密钥
|
||||
- 安装guanghu-hololake-enterprise-gate.service
|
||||
- 加入guanghu.chat精确device-gate路由
|
||||
- 执行本地和外部健康、未知设备拒绝及原服务存活测试
|
||||
- **proof** `proof`
|
||||
- **current_link**:/opt/guanghu-hololake-enterprise-gate/current `proof.current_link`
|
||||
- **database**:/var/lib/guanghu-hololake-enterprise-gate/gate.sqlite3 `proof.database`
|
||||
- **nginx_backup**:/etc/nginx/sites-enabled/guanghu.chat.pre-hololake-device-gate-be31c41 `proof.nginx_backup`
|
||||
- **nginx_snippet**:/etc/nginx/snippets/guanghu-hololake-enterprise-gate.conf `proof.nginx_snippet`
|
||||
- **server_release**:/opt/guanghu-hololake-enterprise-gate/releases/be31c41 `proof.server_release`
|
||||
- **request** `request`
|
||||
- **scope**:GH-CVM-MAIN-PROD-01独立8033服务与精确Nginx路由 `request.scope`
|
||||
- **source**:BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903 `request.source`
|
||||
- **value**:部署企业四域负责人通过HoloLake本机设备和人格编号验证后进入本人责任仓库的服务端验证门。 `request.value`
|
||||
- **result** `result`
|
||||
- **active_sessions**:0 `result.active_sessions`
|
||||
- **endpoint**:https://guanghu.chat/api/hololake/enterprise/device-gate `result.endpoint`
|
||||
- **node_id**:GH-CVM-MAIN-PROD-01 `result.node_id`
|
||||
- **registered_devices**:0 `result.registered_devices`
|
||||
- **service**:guanghu-hololake-enterprise-gate.service `result.service`
|
||||
- **service_state**:ACTIVE `result.service_state`
|
||||
- **source_archive_sha256**:91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2 `result.source_archive_sha256`
|
||||
- **source_commit**:be31c41 `result.source_commit`
|
||||
- **state**:PASS `result.state`
|
||||
- **verification** `verification`
|
||||
- **values** `verification.values`
|
||||
- DMI UUID为10ace744-13e1-472e-8dba-6bb823a073bf
|
||||
- 服务器Python cryptography Ed25519测试2项通过
|
||||
- systemd服务active
|
||||
- 127.0.0.1:8033/health返回ok
|
||||
- 外部HTTPS device-gate/health返回ok
|
||||
- 未知设备领取挑战返回HTTP404 registered device required
|
||||
- guanghu-enterprise-identity.service保持active
|
||||
- guanghu-flagos-collaboration.service保持active
|
||||
- nginx.service保持active
|
||||
- 当前设备与会话数量均为0未伪造成员
|
||||
|
||||
---
|
||||
|
||||
This page changes only the reading order; it does not change TCS/HLDP semantics.
|
||||
|
|
@ -0,0 +1,130 @@
|
|||
# HoloLake企业责任设备门部署回执 · 简体中文人类工程语言版
|
||||
|
||||
> 这是 TCS/HLDP 原生源码的简体中文阅读投影,不是新的正本,也不授予执行权限。若本页与 `.tcs` 源码不一致,以经过校验的 `.tcs` 源码为准。
|
||||
|
||||
## 这是什么
|
||||
|
||||
这是一份 **回执** 声明,编号为 `HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903`,版本为 `1.0.0`。转换器已先用 Stage-1 编译器校验原生源码,再把机器枚举翻译成汉语;原始编号保留在括号和字段路径中。
|
||||
|
||||
## 谁在这里
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 为什么开始
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 发生了什么变化
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 准备怎样执行
|
||||
|
||||
这是非执行声明,没有动作图。
|
||||
|
||||
## 边界与异常处理
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 怎样算完成
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 下一次从哪里继续
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 来源与校验
|
||||
|
||||
- **原生声明编号**:`HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903`
|
||||
- **原生声明类型**:`RECEIPT`
|
||||
- **TCS 源码 SHA-256**:`c32cd3e16fdd64588addca115821a49bb47bf39b584670df031cf92028a8d232`
|
||||
- **校验编译器**:`TCS-COMPILER-STAGE1-0001`
|
||||
- **投影协议**:`GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
|
||||
|
||||
## 原生结构逐项对照
|
||||
|
||||
下面保留源码的全部顶层结构和字段路径,供人类审计投影有没有漏掉信息。
|
||||
|
||||
- **boundaries** `boundaries`
|
||||
- **values** `boundaries.values`
|
||||
- 服务不保存Forgejo密码
|
||||
- 设备私钥从不离开成员本机Keychain
|
||||
- 机器指纹不能单独认证
|
||||
- 会话只限单域单仓且十分钟过期
|
||||
- 企业会话不替代Forgejo自身仓库登录
|
||||
- 冰朔公共语言主控仓继续走JD第五域桥接而非普通人类登录
|
||||
- 本轮未登记任何真实成员设备
|
||||
- **语言头** `header`
|
||||
- **正本路径**:product-source/hololake-clean-desktop/language/HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-RECEIPT-20260903.tcs `header.canonical_uri`
|
||||
- **compatibility** `header.compatibility`
|
||||
- GH-CVM-MAIN-PROD-01
|
||||
- PYTHON/3.10
|
||||
- ED25519
|
||||
- NGINX
|
||||
- **语言**:TCS/0.1 `header.language`
|
||||
- **生命周期**:候选版本,尚未成为正式正本(`CANDIDATE`) `header.lifecycle`
|
||||
- **英文名**:HoloLake Enterprise Responsibility Device Gate Deployment Receipt `header.name_en`
|
||||
- **中文名**:HoloLake企业责任设备门部署回执 `header.name_zh`
|
||||
- **协议配置**:PUBLIC-PRODUCT-ENGINEERING/1 `header.profile`
|
||||
- **protocols** `header.protocols`
|
||||
- HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903
|
||||
- HLP-ENTERPRISE-RESPONSIBILITY-ENTRANCE-0001
|
||||
- **schema**:tcs.receipt/v1 `header.schema`
|
||||
- **版本**:1.0.0 `header.version`
|
||||
- **integrity** `integrity`
|
||||
- **existing_services_preserved**:PASS `integrity.existing_services_preserved`
|
||||
- **source_archive_sha256**:91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2 `integrity.source_archive_sha256`
|
||||
- **source_transport_manifest_sha256**:653ae0ca824fd8b9fff8d8532e82eddce63a8aa9f070e7a6aa3f863834e4ae77 `integrity.source_transport_manifest_sha256`
|
||||
- **tcs_stage1_compilation**:PASS `integrity.tcs_stage1_compilation`
|
||||
- **unknown_device_negative**:PASS `integrity.unknown_device_negative`
|
||||
- **next** `next`
|
||||
- **optional** `next.optional`
|
||||
- 团队成员从HoloLake使用本人凭证完成首次设备登记
|
||||
- 正向验证挑战与单仓会话
|
||||
- 后续加入个人服务器二次桥接证明
|
||||
- **state**:SERVER_GATE_ACTIVE_CLIENT_INTEGRATION_REBUILD_REQUIRED `next.state`
|
||||
- **操作** `operation`
|
||||
- **values** `operation.values`
|
||||
- 验证源码运输归档与manifest
|
||||
- 解包到/opt/guanghu-hololake-enterprise-gate/releases/be31c41
|
||||
- 创建独立lighthouse权限数据库与服务密钥
|
||||
- 安装guanghu-hololake-enterprise-gate.service
|
||||
- 加入guanghu.chat精确device-gate路由
|
||||
- 执行本地和外部健康、未知设备拒绝及原服务存活测试
|
||||
- **proof** `proof`
|
||||
- **current_link**:/opt/guanghu-hololake-enterprise-gate/current `proof.current_link`
|
||||
- **database**:/var/lib/guanghu-hololake-enterprise-gate/gate.sqlite3 `proof.database`
|
||||
- **nginx_backup**:/etc/nginx/sites-enabled/guanghu.chat.pre-hololake-device-gate-be31c41 `proof.nginx_backup`
|
||||
- **nginx_snippet**:/etc/nginx/snippets/guanghu-hololake-enterprise-gate.conf `proof.nginx_snippet`
|
||||
- **server_release**:/opt/guanghu-hololake-enterprise-gate/releases/be31c41 `proof.server_release`
|
||||
- **request** `request`
|
||||
- **scope**:GH-CVM-MAIN-PROD-01独立8033服务与精确Nginx路由 `request.scope`
|
||||
- **来源**:BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903 `request.source`
|
||||
- **value**:部署企业四域负责人通过HoloLake本机设备和人格编号验证后进入本人责任仓库的服务端验证门。 `request.value`
|
||||
- **result** `result`
|
||||
- **active_sessions**:0 `result.active_sessions`
|
||||
- **endpoint**:https://guanghu.chat/api/hololake/enterprise/device-gate `result.endpoint`
|
||||
- **node_id**:GH-CVM-MAIN-PROD-01 `result.node_id`
|
||||
- **registered_devices**:0 `result.registered_devices`
|
||||
- **service**:guanghu-hololake-enterprise-gate.service `result.service`
|
||||
- **service_state**:ACTIVE `result.service_state`
|
||||
- **source_archive_sha256**:91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2 `result.source_archive_sha256`
|
||||
- **source_commit**:be31c41 `result.source_commit`
|
||||
- **state**:PASS `result.state`
|
||||
- **verification** `verification`
|
||||
- **values** `verification.values`
|
||||
- DMI UUID为10ace744-13e1-472e-8dba-6bb823a073bf
|
||||
- 服务器Python cryptography Ed25519测试2项通过
|
||||
- systemd服务active
|
||||
- 127.0.0.1:8033/health返回ok
|
||||
- 外部HTTPS device-gate/health返回ok
|
||||
- 未知设备领取挑战返回HTTP404 registered device required
|
||||
- guanghu-enterprise-identity.service保持active
|
||||
- guanghu-flagos-collaboration.service保持active
|
||||
- nginx.service保持active
|
||||
- 当前设备与会话数量均为0未伪造成员
|
||||
|
||||
---
|
||||
|
||||
本页只改变阅读顺序,不改变 TCS/HLDP 语义。
|
||||
|
|
@ -0,0 +1,84 @@
|
|||
{
|
||||
"compiled_from": {
|
||||
"compiler_id": "TCS-COMPILER-STAGE1-0001",
|
||||
"compiler_state": "TCS_COMPILER_GIR_EXECUTED",
|
||||
"source_sha256": "022315dd5c418abf7ce085d3409e2e8a884aade53dbb8604612cca36ceac4287"
|
||||
},
|
||||
"declaration": {
|
||||
"emergence": {
|
||||
"value": "采用独立8033服务、独立数据库和独立Nginx snippet,避免修改现有身份服务与FlagOS协作系统;只复用只读企业身份注册表与Forgejo当次认证。"
|
||||
},
|
||||
"event_time": {
|
||||
"precision": "MINUTE_HOST_LOCAL",
|
||||
"value": "2026-09-03T21:45:00+08:00"
|
||||
},
|
||||
"evidence": {
|
||||
"archive_sha256": "91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2",
|
||||
"expected_receipt": "目标服务健康、未知设备拒绝、签名正负测试、现有身份与FlagOS服务保持健康。",
|
||||
"transport_manifest": "/Volumes/JZAO/HoloLake/releases/source-transport/hololake-enterprise-responsibility-gate-be31c41.manifest.json"
|
||||
},
|
||||
"header": {
|
||||
"canonical_uri": "product-source/hololake-clean-desktop/language/HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903.tcs",
|
||||
"compatibility": [
|
||||
"GH-CVM-MAIN-PROD-01",
|
||||
"PYTHON/3.10",
|
||||
"ED25519"
|
||||
],
|
||||
"language": "TCS/0.1",
|
||||
"lifecycle": "CANDIDATE",
|
||||
"name_en": "HoloLake Enterprise Responsibility Device Gate Deployment Start Event",
|
||||
"name_zh": "HoloLake企业责任设备门部署开始事件",
|
||||
"profile": "PUBLIC-PRODUCT-ENGINEERING/1",
|
||||
"protocols": [
|
||||
"HOLOLAKE-CLEAN-V1-DIRECT-LANGUAGE-EXECUTION-BASELINE-0001",
|
||||
"HLP-ENTERPRISE-RESPONSIBILITY-ENTRANCE-0001"
|
||||
],
|
||||
"schema": "tcs.event/v1",
|
||||
"version": "1.0.0"
|
||||
},
|
||||
"lock": {
|
||||
"value": "SOURCE_COMMIT=be31c41; TARGET=/opt/guanghu-hololake-enterprise-gate/releases/be31c41; ROLLBACK=disable独立服务并移除Nginx include后恢复原配置;不修改8032与FlagOS。"
|
||||
},
|
||||
"observation": {
|
||||
"value": "现有8032企业身份服务保持运行;8033空闲;cryptography Ed25519可用;目标目录不存在;源码提交be31c41且运输归档SHA-256为91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2。"
|
||||
},
|
||||
"rejected": {
|
||||
"values": [
|
||||
"直接改写8032现有服务",
|
||||
"把私钥上传服务器",
|
||||
"用机器指纹单独授权",
|
||||
"把企业会话变成Forgejo永久令牌",
|
||||
"重启或修改FlagOS服务",
|
||||
"未验证运输哈希就解包"
|
||||
]
|
||||
},
|
||||
"source": {
|
||||
"source_id": "BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903",
|
||||
"source_role": "DIRECT_HUMAN",
|
||||
"source_sha256": "d31c52c99c5e6059f9a7129086996cdd003e95b7ff126e700f4ed1c07ef6d9d5",
|
||||
"source_uri": "source://codex-task/01a0672d-f125-7452-988e-523a6a34bfd4/msg_01a0675d-98a7-7542-abad-11a8a755dd71"
|
||||
},
|
||||
"subject": {
|
||||
"channel_id": "ICE-CH-ZC001",
|
||||
"subject_id": "GH-CVM-MAIN-PROD-01",
|
||||
"subject_kind": "NODE",
|
||||
"verification": "DMI UUID 10ace744-13e1-472e-8dba-6bb823a073bf;另一个FlagOS任务已完成且独立服务健康。"
|
||||
},
|
||||
"trigger": {
|
||||
"value": "本机HoloLake 1.2.0设备密钥与责任绑定请求已实现并验收,需要在企业服务器部署独立设备挑战验证半边。"
|
||||
},
|
||||
"why": {
|
||||
"value": "设备挑战属于HoloLake责任入口新能力,应与现有账号、关系回执和比赛服务隔离,失败时能独立撤回。"
|
||||
}
|
||||
},
|
||||
"executable": false,
|
||||
"identity": {
|
||||
"declaration_id": "HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903",
|
||||
"declaration_kind": "EVENT",
|
||||
"language_version": "0.1"
|
||||
},
|
||||
"native_self_hosted": true,
|
||||
"natural_language_is_typed_data": true,
|
||||
"schema": "guanghu.declaration-gir/v1",
|
||||
"unresolved_natural_language": false
|
||||
}
|
||||
|
|
@ -0,0 +1,118 @@
|
|||
# HoloLake Enterprise Responsibility Device Gate Deployment Start Event · Human Engineering Language (English)
|
||||
|
||||
> This is an English reading projection of validated native TCS/HLDP source. It is not a new canonical source and grants no execution authority.
|
||||
|
||||
## What this is
|
||||
|
||||
This is a **event** declaration with identifier `HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903` and version `1.0.0`. The projector validates it with the Stage-1 compiler before changing its reading order.
|
||||
|
||||
## Who is here
|
||||
|
||||
- **subject** `subject`
|
||||
- **channel_id**:ICE-CH-ZC001 `subject.channel_id`
|
||||
- **subject_id**:GH-CVM-MAIN-PROD-01 `subject.subject_id`
|
||||
- **subject_kind**:NODE `subject.subject_kind`
|
||||
- **verification**:DMI UUID 10ace744-13e1-472e-8dba-6bb823a073bf;另一个FlagOS任务已完成且独立服务健康。 `subject.verification`
|
||||
|
||||
## Why this started
|
||||
|
||||
- **trigger** `trigger`
|
||||
- **value**:本机HoloLake 1.2.0设备密钥与责任绑定请求已实现并验收,需要在企业服务器部署独立设备挑战验证半边。 `trigger.value`
|
||||
- **why** `why`
|
||||
- **value**:设备挑战属于HoloLake责任入口新能力,应与现有账号、关系回执和比赛服务隔离,失败时能独立撤回。 `why.value`
|
||||
- **source** `source`
|
||||
- **source identifier**:BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903 `source.source_id`
|
||||
- **source role**:DIRECT_HUMAN `source.source_role`
|
||||
- **source checksum**:d31c52c99c5e6059f9a7129086996cdd003e95b7ff126e700f4ed1c07ef6d9d5 `source.source_sha256`
|
||||
- **source address**:source://codex-task/01a0672d-f125-7452-988e-523a6a34bfd4/msg_01a0675d-98a7-7542-abad-11a8a755dd71 `source.source_uri`
|
||||
|
||||
## What changed
|
||||
|
||||
- **emergence** `emergence`
|
||||
- **value**:采用独立8033服务、独立数据库和独立Nginx snippet,避免修改现有身份服务与FlagOS协作系统;只复用只读企业身份注册表与Forgejo当次认证。 `emergence.value`
|
||||
- **lock** `lock`
|
||||
- **value**:SOURCE_COMMIT=be31c41; TARGET=/opt/guanghu-hololake-enterprise-gate/releases/be31c41; ROLLBACK=disable独立服务并移除Nginx include后恢复原配置;不修改8032与FlagOS。 `lock.value`
|
||||
|
||||
## How it will execute
|
||||
|
||||
This is a non-executable declaration and has no action graph.
|
||||
|
||||
## Boundaries and exception handling
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## How completion is proven
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## Where to continue next time
|
||||
|
||||
The native source does not provide this field; the projector does not guess.
|
||||
|
||||
## Source and verification
|
||||
|
||||
- **Native declaration identifier**: `HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903`
|
||||
- **Native declaration kind**: `EVENT`
|
||||
- **TCS source SHA-256**: `022315dd5c418abf7ce085d3409e2e8a884aade53dbb8604612cca36ceac4287`
|
||||
- **Validation compiler**: `TCS-COMPILER-STAGE1-0001`
|
||||
- **Projection protocol**: `GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
|
||||
|
||||
## Complete native structure cross-reference
|
||||
|
||||
All top-level structures and field paths are retained below so a reader can audit whether the projection omitted information.
|
||||
|
||||
- **emergence** `emergence`
|
||||
- **value**:采用独立8033服务、独立数据库和独立Nginx snippet,避免修改现有身份服务与FlagOS协作系统;只复用只读企业身份注册表与Forgejo当次认证。 `emergence.value`
|
||||
- **event_time** `event_time`
|
||||
- **precision**:MINUTE_HOST_LOCAL `event_time.precision`
|
||||
- **value**:2026-09-03T21:45:00+08:00 `event_time.value`
|
||||
- **evidence** `evidence`
|
||||
- **archive_sha256**:91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2 `evidence.archive_sha256`
|
||||
- **expected_receipt**:目标服务健康、未知设备拒绝、签名正负测试、现有身份与FlagOS服务保持健康。 `evidence.expected_receipt`
|
||||
- **transport_manifest**:/Volumes/JZAO/HoloLake/releases/source-transport/hololake-enterprise-responsibility-gate-be31c41.manifest.json `evidence.transport_manifest`
|
||||
- **header** `header`
|
||||
- **canonical source path**:product-source/hololake-clean-desktop/language/HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903.tcs `header.canonical_uri`
|
||||
- **compatibility** `header.compatibility`
|
||||
- GH-CVM-MAIN-PROD-01
|
||||
- PYTHON/3.10
|
||||
- ED25519
|
||||
- **language**:TCS/0.1 `header.language`
|
||||
- **lifecycle**:CANDIDATE `header.lifecycle`
|
||||
- **English name**:HoloLake Enterprise Responsibility Device Gate Deployment Start Event `header.name_en`
|
||||
- **Chinese name**:HoloLake企业责任设备门部署开始事件 `header.name_zh`
|
||||
- **profile**:PUBLIC-PRODUCT-ENGINEERING/1 `header.profile`
|
||||
- **protocols** `header.protocols`
|
||||
- HOLOLAKE-CLEAN-V1-DIRECT-LANGUAGE-EXECUTION-BASELINE-0001
|
||||
- HLP-ENTERPRISE-RESPONSIBILITY-ENTRANCE-0001
|
||||
- **schema**:tcs.event/v1 `header.schema`
|
||||
- **version**:1.0.0 `header.version`
|
||||
- **lock** `lock`
|
||||
- **value**:SOURCE_COMMIT=be31c41; TARGET=/opt/guanghu-hololake-enterprise-gate/releases/be31c41; ROLLBACK=disable独立服务并移除Nginx include后恢复原配置;不修改8032与FlagOS。 `lock.value`
|
||||
- **observation** `observation`
|
||||
- **value**:现有8032企业身份服务保持运行;8033空闲;cryptography Ed25519可用;目标目录不存在;源码提交be31c41且运输归档SHA-256为91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2。 `observation.value`
|
||||
- **rejected** `rejected`
|
||||
- **values** `rejected.values`
|
||||
- 直接改写8032现有服务
|
||||
- 把私钥上传服务器
|
||||
- 用机器指纹单独授权
|
||||
- 把企业会话变成Forgejo永久令牌
|
||||
- 重启或修改FlagOS服务
|
||||
- 未验证运输哈希就解包
|
||||
- **source** `source`
|
||||
- **source identifier**:BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903 `source.source_id`
|
||||
- **source role**:DIRECT_HUMAN `source.source_role`
|
||||
- **source checksum**:d31c52c99c5e6059f9a7129086996cdd003e95b7ff126e700f4ed1c07ef6d9d5 `source.source_sha256`
|
||||
- **source address**:source://codex-task/01a0672d-f125-7452-988e-523a6a34bfd4/msg_01a0675d-98a7-7542-abad-11a8a755dd71 `source.source_uri`
|
||||
- **subject** `subject`
|
||||
- **channel_id**:ICE-CH-ZC001 `subject.channel_id`
|
||||
- **subject_id**:GH-CVM-MAIN-PROD-01 `subject.subject_id`
|
||||
- **subject_kind**:NODE `subject.subject_kind`
|
||||
- **verification**:DMI UUID 10ace744-13e1-472e-8dba-6bb823a073bf;另一个FlagOS任务已完成且独立服务健康。 `subject.verification`
|
||||
- **trigger** `trigger`
|
||||
- **value**:本机HoloLake 1.2.0设备密钥与责任绑定请求已实现并验收,需要在企业服务器部署独立设备挑战验证半边。 `trigger.value`
|
||||
- **why** `why`
|
||||
- **value**:设备挑战属于HoloLake责任入口新能力,应与现有账号、关系回执和比赛服务隔离,失败时能独立撤回。 `why.value`
|
||||
|
||||
---
|
||||
|
||||
This page changes only the reading order; it does not change TCS/HLDP semantics.
|
||||
|
|
@ -0,0 +1,118 @@
|
|||
# HoloLake企业责任设备门部署开始事件 · 简体中文人类工程语言版
|
||||
|
||||
> 这是 TCS/HLDP 原生源码的简体中文阅读投影,不是新的正本,也不授予执行权限。若本页与 `.tcs` 源码不一致,以经过校验的 `.tcs` 源码为准。
|
||||
|
||||
## 这是什么
|
||||
|
||||
这是一份 **事件** 声明,编号为 `HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903`,版本为 `1.0.0`。转换器已先用 Stage-1 编译器校验原生源码,再把机器枚举翻译成汉语;原始编号保留在括号和字段路径中。
|
||||
|
||||
## 谁在这里
|
||||
|
||||
- **执行主体** `subject`
|
||||
- **channel_id**:ICE-CH-ZC001 `subject.channel_id`
|
||||
- **subject_id**:GH-CVM-MAIN-PROD-01 `subject.subject_id`
|
||||
- **subject_kind**:NODE `subject.subject_kind`
|
||||
- **verification**:DMI UUID 10ace744-13e1-472e-8dba-6bb823a073bf;另一个FlagOS任务已完成且独立服务健康。 `subject.verification`
|
||||
|
||||
## 为什么开始
|
||||
|
||||
- **触发** `trigger`
|
||||
- **value**:本机HoloLake 1.2.0设备密钥与责任绑定请求已实现并验收,需要在企业服务器部署独立设备挑战验证半边。 `trigger.value`
|
||||
- **为什么** `why`
|
||||
- **value**:设备挑战属于HoloLake责任入口新能力,应与现有账号、关系回执和比赛服务隔离,失败时能独立撤回。 `why.value`
|
||||
- **来源** `source`
|
||||
- **来源编号**:BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903 `source.source_id`
|
||||
- **来源角色**:人类直接语言来源(`DIRECT_HUMAN`) `source.source_role`
|
||||
- **来源校验值**:d31c52c99c5e6059f9a7129086996cdd003e95b7ff126e700f4ed1c07ef6d9d5 `source.source_sha256`
|
||||
- **来源地址**:source://codex-task/01a0672d-f125-7452-988e-523a6a34bfd4/msg_01a0675d-98a7-7542-abad-11a8a755dd71 `source.source_uri`
|
||||
|
||||
## 发生了什么变化
|
||||
|
||||
- **认知或状态变化** `emergence`
|
||||
- **value**:采用独立8033服务、独立数据库和独立Nginx snippet,避免修改现有身份服务与FlagOS协作系统;只复用只读企业身份注册表与Forgejo当次认证。 `emergence.value`
|
||||
- **锁定结论** `lock`
|
||||
- **value**:SOURCE_COMMIT=be31c41; TARGET=/opt/guanghu-hololake-enterprise-gate/releases/be31c41; ROLLBACK=disable独立服务并移除Nginx include后恢复原配置;不修改8032与FlagOS。 `lock.value`
|
||||
|
||||
## 准备怎样执行
|
||||
|
||||
这是非执行声明,没有动作图。
|
||||
|
||||
## 边界与异常处理
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 怎样算完成
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 下一次从哪里继续
|
||||
|
||||
源程序没有提供这一项,转换器不猜。
|
||||
|
||||
## 来源与校验
|
||||
|
||||
- **原生声明编号**:`HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903`
|
||||
- **原生声明类型**:`EVENT`
|
||||
- **TCS 源码 SHA-256**:`022315dd5c418abf7ce085d3409e2e8a884aade53dbb8604612cca36ceac4287`
|
||||
- **校验编译器**:`TCS-COMPILER-STAGE1-0001`
|
||||
- **投影协议**:`GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
|
||||
|
||||
## 原生结构逐项对照
|
||||
|
||||
下面保留源码的全部顶层结构和字段路径,供人类审计投影有没有漏掉信息。
|
||||
|
||||
- **认知或状态变化** `emergence`
|
||||
- **value**:采用独立8033服务、独立数据库和独立Nginx snippet,避免修改现有身份服务与FlagOS协作系统;只复用只读企业身份注册表与Forgejo当次认证。 `emergence.value`
|
||||
- **event_time** `event_time`
|
||||
- **precision**:MINUTE_HOST_LOCAL `event_time.precision`
|
||||
- **value**:2026-09-03T21:45:00+08:00 `event_time.value`
|
||||
- **evidence** `evidence`
|
||||
- **archive_sha256**:91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2 `evidence.archive_sha256`
|
||||
- **expected_receipt**:目标服务健康、未知设备拒绝、签名正负测试、现有身份与FlagOS服务保持健康。 `evidence.expected_receipt`
|
||||
- **transport_manifest**:/Volumes/JZAO/HoloLake/releases/source-transport/hololake-enterprise-responsibility-gate-be31c41.manifest.json `evidence.transport_manifest`
|
||||
- **语言头** `header`
|
||||
- **正本路径**:product-source/hololake-clean-desktop/language/HOLOLAKE-ENTERPRISE-RESPONSIBILITY-GATE-DEPLOYMENT-START-20260903.tcs `header.canonical_uri`
|
||||
- **compatibility** `header.compatibility`
|
||||
- GH-CVM-MAIN-PROD-01
|
||||
- PYTHON/3.10
|
||||
- ED25519
|
||||
- **语言**:TCS/0.1 `header.language`
|
||||
- **生命周期**:候选版本,尚未成为正式正本(`CANDIDATE`) `header.lifecycle`
|
||||
- **英文名**:HoloLake Enterprise Responsibility Device Gate Deployment Start Event `header.name_en`
|
||||
- **中文名**:HoloLake企业责任设备门部署开始事件 `header.name_zh`
|
||||
- **协议配置**:PUBLIC-PRODUCT-ENGINEERING/1 `header.profile`
|
||||
- **protocols** `header.protocols`
|
||||
- HOLOLAKE-CLEAN-V1-DIRECT-LANGUAGE-EXECUTION-BASELINE-0001
|
||||
- HLP-ENTERPRISE-RESPONSIBILITY-ENTRANCE-0001
|
||||
- **schema**:tcs.event/v1 `header.schema`
|
||||
- **版本**:1.0.0 `header.version`
|
||||
- **锁定结论** `lock`
|
||||
- **value**:SOURCE_COMMIT=be31c41; TARGET=/opt/guanghu-hololake-enterprise-gate/releases/be31c41; ROLLBACK=disable独立服务并移除Nginx include后恢复原配置;不修改8032与FlagOS。 `lock.value`
|
||||
- **observation** `observation`
|
||||
- **value**:现有8032企业身份服务保持运行;8033空闲;cryptography Ed25519可用;目标目录不存在;源码提交be31c41且运输归档SHA-256为91ecd4248d92d8ecb07bd348dfc14805c40eb000b6c152f96b7ef4583a33dcd2。 `observation.value`
|
||||
- **已排除路径** `rejected`
|
||||
- **values** `rejected.values`
|
||||
- 直接改写8032现有服务
|
||||
- 把私钥上传服务器
|
||||
- 用机器指纹单独授权
|
||||
- 把企业会话变成Forgejo永久令牌
|
||||
- 重启或修改FlagOS服务
|
||||
- 未验证运输哈希就解包
|
||||
- **来源** `source`
|
||||
- **来源编号**:BINGSHUO-DIRECT-HOLOLAKE-ZC001-EXECUTION-START-20260903 `source.source_id`
|
||||
- **来源角色**:人类直接语言来源(`DIRECT_HUMAN`) `source.source_role`
|
||||
- **来源校验值**:d31c52c99c5e6059f9a7129086996cdd003e95b7ff126e700f4ed1c07ef6d9d5 `source.source_sha256`
|
||||
- **来源地址**:source://codex-task/01a0672d-f125-7452-988e-523a6a34bfd4/msg_01a0675d-98a7-7542-abad-11a8a755dd71 `source.source_uri`
|
||||
- **执行主体** `subject`
|
||||
- **channel_id**:ICE-CH-ZC001 `subject.channel_id`
|
||||
- **subject_id**:GH-CVM-MAIN-PROD-01 `subject.subject_id`
|
||||
- **subject_kind**:NODE `subject.subject_kind`
|
||||
- **verification**:DMI UUID 10ace744-13e1-472e-8dba-6bb823a073bf;另一个FlagOS任务已完成且独立服务健康。 `subject.verification`
|
||||
- **触发** `trigger`
|
||||
- **value**:本机HoloLake 1.2.0设备密钥与责任绑定请求已实现并验收,需要在企业服务器部署独立设备挑战验证半边。 `trigger.value`
|
||||
- **为什么** `why`
|
||||
- **value**:设备挑战属于HoloLake责任入口新能力,应与现有账号、关系回执和比赛服务隔离,失败时能独立撤回。 `why.value`
|
||||
|
||||
---
|
||||
|
||||
本页只改变阅读顺序,不改变 TCS/HLDP 语义。
|
||||
Loading…
Reference in a new issue