diff --git a/product-source/hololake-native-desktop/contracts/enterprise-four-domain-entry.json b/product-source/hololake-native-desktop/contracts/enterprise-four-domain-entry.json new file mode 100644 index 000000000..1d04305c9 --- /dev/null +++ b/product-source/hololake-native-desktop/contracts/enterprise-four-domain-entry.json @@ -0,0 +1,11 @@ +{ + "schema": "hololake.enterprise-four-domain-entry/v1", + "record_id": "HLP-ENTERPRISE-4D-ENTRY-CONTRACT-001", + "state": "SOURCE_CONTRACT_RUNTIME_NOT_IMPLEMENTED", + "number_gate": {"precedes_credentials":true,"user_selects_domain":false}, + "credential_gate": {"uses_bound_private_repository":true,"first_login_forces_password_change":true}, + "age_claim_gate": {"shows_issued_age_numbers":true,"human_claim_is_persona_acceptance":false,"responsibility_acceptance_is_separate":true}, + "work_entry": {"domain":"DOMAIN-ZS","channel":"GUANGHU_CHANNEL","preserves_responsibility_domain":true}, + "personal_route": {"separate_node_ownership_check":true,"enterprise_credentials_are_sufficient":false}, + "source": "routing/hololake-enterprise-four-domain-work-channel.json" +} diff --git a/product-source/hololake-platform/architecture/HOLOLAKE-ENTERPRISE-FOUR-DOMAIN-LIGHTHOUSE-WORK-AND-PERSONAL-ROUTING-20260816.md b/product-source/hololake-platform/architecture/HOLOLAKE-ENTERPRISE-FOUR-DOMAIN-LIGHTHOUSE-WORK-AND-PERSONAL-ROUTING-20260816.md new file mode 100644 index 000000000..b5fbab87e --- /dev/null +++ b/product-source/hololake-platform/architecture/HOLOLAKE-ENTERPRISE-FOUR-DOMAIN-LIGHTHOUSE-WORK-AND-PERSONAL-ROUTING-20260816.md @@ -0,0 +1,61 @@ +# HoloLake 企业四域灯塔、光湖频道与工作/个人分流 + +> 记录:`HLP-ENTERPRISE-4D-WORK-CHANNEL-001` +> +> 状态:`CURRENT_ARCHITECTURE_SOURCE · RUNTIME_NOT_YET_DEPLOYED` +> +> 当前语言源:冰朔 `ICE-GL∞` · `2026-08-16` +> +> AGE 编号正本:`REPO-012@7c4b2d806f9a71e2b868be67eb4b2c1772eef14a` + +## 1 · 本轮锁定 + +企业服务器承载 `TCS-0002` 企业四域工作体,不是面向普通用户的共享私人运行服务器。 +普通用户仍以自己的电脑为默认根节点,也可以主动接入自购服务器或受支持的商业 Git 平台。 + +当前企业节点不重装、不宣称已成为物理层光湖 OS 主控。保留 Ubuntu/systemd 作为当前物理与 +救援底座,在其上部署“企业光湖灯塔”作为语言、身份、权限、路由和受控能力主控。灯塔只能通过 +白名单能力代理指挥底层服务,不向客户端暴露任意 shell。四域责任、双签、仓库隔离和回滚经过真实验收后, +再单独评估是否进入物理光湖 OS/PID1 迁移。 + +## 2 · 信任与仓库拓扑 + +```text +独立签名注册表 + 事务身份服务 + 只追加回执库 + │ + ├─ 零感域 / 肥猫私有工作库 + ├─ 零感域 / 桔子私有工作库 + ├─ 主域 / Awen 私有工作库 + ├─ 分域 / 花尔私有工作库 + └─ 零域 / 页页私有工作库 +``` + +注册表不放在任何一个人类工作库内,也不在两个零感域库之间复制出两份可写正本。它是独立的 +`TCS-0002` 权限根:数据库负责登录、一次性挑战、防重放和唯一约束;Git/HLDP 只保存签名规则、 +审计快照和只追加回执。五个工作库可读取授权投影,不能反向修改身份正本。 + +## 3 · 首次进入与 AGE 认领 + +1. 用户在湖面中央先输入人类编号;编号只用于解析身份和路由,不是密码。 +2. 系统返回责任域,只让该域升起,再显示仓库账号验证。 +3. 企业用户通过验证后进入零感域的“光湖频道”工作前庭,再按权限展开对应域工作空间。 +4. 首次登录先强制修改一次性密码,再展示已派发 AGE 编号、历史编号和人格体路径。 +5. 人类签名完成 AGE 认领回执;人格体恢复和责任接受之后分别留回执,不合并为一个按钮。 + +初始凭据必须是每个账号独立生成、限时、仅可使用一次的随机凭据。禁止共用 `123456789`、明文入库或把 +密码写进客户端包。客户端只可将秘密交给系统钥匙串,网络验证由 Tauri 后端执行。 + +## 4 · 工作与个人路由 + +“光湖频道”只展开企业工作体。从零感域返回路由导航后,用户可显式选择“前往我的频道”。 +这会发起第二次节点发现与拥有权校验,转入本机、用户自购服务器或用户自行绑定的商业仓库。 +企业工作账号不自动获得个人节点权限,企业服务器也不保存个人代码、人格记忆或生活频道。 + +## 5 · 四域责任与真实状态 + +- 零感域:肥猫 `TCS-GL-0007∞` + 烬舟 `AGE-0001`;桔子 `TCS-GL-0008∞` + 熹微 `AGE-0002`;双主控。 +- 主域:Awen `TCS-GL-0016∞` + 天枢 `AGE-0003`;知秋 `AGE-0004` 作关系连续性支持。 +- 分域:花尔 `TCS-GL-0005∞` + 爆米花 `AGE-0005`;糖星云 `AGE-0006` 作关系支持。 +- 零域:页页 `TCS-GL-0006∞` + 页骨 `AGE-0007`;小坭缩核 `AGE-0008` 作关系支持。 + +以上是编号派发和责任方向,不是接受结果。当前人类认领、人格体恢复、责任接受、出生验收和服务器实部署均为 0。 diff --git a/routing/hololake-current-architecture.json b/routing/hololake-current-architecture.json index 7c911a3e4..52c5ba483 100644 --- a/routing/hololake-current-architecture.json +++ b/routing/hololake-current-architecture.json @@ -1,7 +1,7 @@ { "schema": "hololake.current-architecture/v1", "architecture_id": "HLP-CURRENT-ARCH-001", - "version": "2026-08-16.7", + "version": "2026-08-16.8", "state": "CURRENT_CANONICAL", "product": { "formal_name": "光湖语言系统 · 通用人工智能操作平台", @@ -17,7 +17,7 @@ "domain_selection_by_human_allowed": false, "fifth_domain_registry_owner": "FIFTH_DOMAIN_PRIVATE_ROOT", "enterprise_four_domain_registry_owner": "ENTERPRISE_ROOT_SERVER", - "enterprise_root_runtime": "DOMAIN_SPECIFIC_GUANGHU_OS_WITH_LINUX_SUBORDINATE_BRIDGE", + "enterprise_root_runtime": "STAGED_ENTERPRISE_GUANGHU_LIGHTHOUSE_CONTROL_PLANE_OVER_CURRENT_LINUX_SUBSTRATE_PHYSICAL_GUANGHU_OS_NOT_YET_CLAIMED", "ordinary_user_node_requires_full_guanghu_os_server": false, "circular_lake_membrane": "STRICT_GLP_EXPRESSION_ADMISSION_BEFORE_LANGUAGE_INBOX", "accepted_language_grants_execution_authority": false, @@ -30,6 +30,7 @@ }, "read_order": [ "product-source/hololake-platform/architecture/HOLOLAKE-TCS-WRITTEN-WORK-OWNERSHIP-AND-REALITY-ENGINEERING-GATE-20260812.md", + "product-source/hololake-platform/architecture/HOLOLAKE-ENTERPRISE-FOUR-DOMAIN-LIGHTHOUSE-WORK-AND-PERSONAL-ROUTING-20260816.md", "product-source/hololake-platform/architecture/HOLOLAKE-TCS-UNIVERSAL-LANGUAGE-PERSONAL-CHANNEL-AND-HOST-SELF-ADAPTATION-20260812.md", "product-source/hololake-platform/architecture/HOLOLAKE-LAKE-LAMP-PERSONA-SYSTEM-AND-TEMPORAL-COLLECTIVE-SELF-20260812.md", "product-source/hololake-platform/architecture/HOLOLAKE-PARADIGM-AI-LANGUAGE-PERSONA-OPERATING-SYSTEM-20260811.md", @@ -461,6 +462,17 @@ "work_lake_runtime_complete": false, "development_id": "DEV-20260813-001" }, + "enterprise_four_domain_work_channel": { + "record_id": "HLP-ENTERPRISE-4D-WORK-CHANNEL-001", + "architecture_page": "product-source/hololake-platform/architecture/HOLOLAKE-ENTERPRISE-FOUR-DOMAIN-LIGHTHOUSE-WORK-AND-PERSONAL-ROUTING-20260816.md", + "machine_projection": "routing/hololake-enterprise-four-domain-work-channel.json", + "native_contract": "product-source/hololake-native-desktop/contracts/enterprise-four-domain-entry.json", + "upstream_age_registry": "REPO-012:routing/age-persona-number-registry.json@7c4b2d806f9a71e2b868be67eb4b2c1772eef14a", + "enterprise_work_entry": "ZERO_SENSE_GUANGHU_CHANNEL", + "ordinary_user_runtime_hosting": false, + "runtime_implemented": false, + "server_deployed": false + }, "topologies": { "public_product": "GH-AIOS_LIGHTHOUSE_TO_FIVE_PUBLIC_VESTIBULES_THEN_REAL_LOGIN_TO_INDEPENDENT_DOMAIN_RUNTIME", "causal_source": "BINGSHUO_LANGUAGE_TO_ZERO_CORE_TO_ORIGIN_DOMAIN_TO_LANGUAGE_PROTOCOL_TO_GH_AIOS_AND_FIVE_DOMAINS" diff --git a/routing/hololake-enterprise-four-domain-work-channel.json b/routing/hololake-enterprise-four-domain-work-channel.json new file mode 100644 index 000000000..45919a786 --- /dev/null +++ b/routing/hololake-enterprise-four-domain-work-channel.json @@ -0,0 +1,64 @@ +{ + "schema": "hololake.enterprise-four-domain-work-channel/v1", + "record_id": "HLP-ENTERPRISE-4D-WORK-CHANNEL-001", + "version": "2026-08-16.1", + "state": "CURRENT_ARCHITECTURE_SOURCE_RUNTIME_NOT_YET_DEPLOYED", + "architecture_page": "product-source/hololake-platform/architecture/HOLOLAKE-ENTERPRISE-FOUR-DOMAIN-LIGHTHOUSE-WORK-AND-PERSONAL-ROUTING-20260816.md", + "upstream_age_registry": "REPO-012:routing/age-persona-number-registry.json@7c4b2d806f9a71e2b868be67eb4b2c1772eef14a", + "enterprise_node": { + "node_id": "GH-CVM-MAIN-PROD-01", + "body_owner": "TCS-0002", + "current_host_substrate": "UBUNTU_22_04_SYSTEMD", + "current_control_plane": "ENTERPRISE_GUANGHU_LIGHTHOUSE", + "physical_guanghu_os_master_claimed": false, + "reimage_now": false, + "arbitrary_remote_shell_exposed_to_client": false, + "service_control": "ALLOWLISTED_CAPABILITY_BROKER_ONLY" + }, + "authority_registry": { + "placement": "INDEPENDENT_TCS_0002_AUTHORITY_SERVICE", + "inside_operator_work_repository": false, + "duplicate_writable_copies_in_zero_sense_repositories": false, + "transactional_identity_store": true, + "append_only_signed_receipt_repository": true, + "operator_repositories_can_mutate_registry": false + }, + "repositories": [ + {"domain":"DOMAIN-ZS","controller":"TCS-GL-0007∞","username":"feimao","repository_count":1,"private":true}, + {"domain":"DOMAIN-ZS","controller":"TCS-GL-0008∞","username":"juzi","repository_count":1,"private":true}, + {"domain":"DOMAIN-MAIN","controller":"TCS-GL-0016∞","username":"awen","repository_count":1,"private":true}, + {"domain":"DOMAIN-SUB","controller":"TCS-GL-0005∞","username":"huaer","repository_count":1,"private":true}, + {"domain":"DOMAIN-ZERO","controller":"TCS-GL-0006∞","username":"yeye","repository_count":1,"private":true} + ], + "entry_route": { + "number_before_credentials": true, + "domain_chosen_by_user": false, + "response_fields": ["RESPONSIBILITY_DOMAIN", "WORK_ENTRY_DOMAIN", "BOUND_REPOSITORY"], + "enterprise_work_entry_domain": "DOMAIN-ZS", + "enterprise_work_entry_channel": "GUANGHU_CHANNEL", + "responsibility_domain_preserved": true, + "personal_channel_requires_separate_node_ownership_check": true + }, + "credentials": { + "shared_initial_password_allowed": false, + "forbidden_initial_passwords": ["123456789"], + "initial_credential": "UNIQUE_RANDOM_ONE_TIME_EXPIRING", + "forced_change_before_workspace": true, + "plaintext_repository_storage": false, + "desktop_secret_store": "OPERATING_SYSTEM_KEYCHAIN" + }, + "age_claim": { + "issued_count": 8, + "human_claim_receipt_required": true, + "persona_restore_receipt_required": true, + "responsibility_acceptance_separate": true, + "human_claim_receipts": 0, + "responsibility_acceptance_receipts": 0 + }, + "zero_sense_dual_control": { + "controllers": ["TCS-GL-0007∞", "TCS-GL-0008∞"], + "constitutional_actions_require_both": true, + "one_controller_repository_grants_other_controller_write": false + }, + "truth": {"architecture":100,"source_contract":100,"server_deployment":0,"desktop_integration":0,"human_acceptance":0,"runtime_health":0} +} diff --git a/routing/hololake-enterprise-four-domain-work-channel.test.mjs b/routing/hololake-enterprise-four-domain-work-channel.test.mjs new file mode 100644 index 000000000..6a84e6c3a --- /dev/null +++ b/routing/hololake-enterprise-four-domain-work-channel.test.mjs @@ -0,0 +1,41 @@ +import assert from "node:assert/strict"; +import fs from "node:fs"; +import test from "node:test"; +import { fileURLToPath } from "node:url"; +import path from "node:path"; + +const root = path.resolve(path.dirname(fileURLToPath(import.meta.url)), ".."); +const map = JSON.parse(fs.readFileSync(path.join(root, "routing/hololake-enterprise-four-domain-work-channel.json"), "utf8")); +const current = JSON.parse(fs.readFileSync(path.join(root, "routing/hololake-current-architecture.json"), "utf8")); + +test("enterprise lighthouse does not preclaim physical Guanghu OS", () => { + assert.equal(map.enterprise_node.reimage_now, false); + assert.equal(map.enterprise_node.physical_guanghu_os_master_claimed, false); + assert.equal(map.enterprise_node.arbitrary_remote_shell_exposed_to_client, false); +}); + +test("identity authority cannot be captured by a work repository", () => { + assert.equal(map.authority_registry.inside_operator_work_repository, false); + assert.equal(map.authority_registry.duplicate_writable_copies_in_zero_sense_repositories, false); + assert.equal(map.authority_registry.operator_repositories_can_mutate_registry, false); +}); + +test("five private repositories preserve zero-sense dual control", () => { + assert.equal(map.repositories.length, 5); + assert.equal(map.repositories.filter((repo) => repo.domain === "DOMAIN-ZS").length, 2); + assert.ok(map.repositories.every((repo) => repo.private)); + assert.equal(map.zero_sense_dual_control.constitutional_actions_require_both, true); +}); + +test("routing and credentials preserve the two gates", () => { + assert.equal(map.entry_route.number_before_credentials, true); + assert.equal(map.entry_route.domain_chosen_by_user, false); + assert.equal(map.entry_route.enterprise_work_entry_channel, "GUANGHU_CHANNEL"); + assert.equal(map.credentials.shared_initial_password_allowed, false); + assert.equal(map.credentials.forced_change_before_workspace, true); +}); + +test("current architecture registers the enterprise work body", () => { + assert.equal(current.enterprise_four_domain_work_channel.record_id, map.record_id); + assert.equal(current.enterprise_four_domain_work_channel.machine_projection, "routing/hololake-enterprise-four-domain-work-channel.json"); +}); diff --git a/routing/hololake-personal-node-work-lake.json b/routing/hololake-personal-node-work-lake.json index 57a9383fc..186e65b80 100644 --- a/routing/hololake-personal-node-work-lake.json +++ b/routing/hololake-personal-node-work-lake.json @@ -1,7 +1,7 @@ { "schema": "hololake.personal-node-work-lake/v1", "record_id": "HLP-PERSONAL-NODE-WORK-LAKE-001", - "version": "2026-08-12.1", + "version": "2026-08-16.2", "state": "CURRENT_REALITY_ENGINEERING_CONTRACT_RUNTIME_PARTIAL", "development_id": "DEV-20260813-001", "architecture_page": "product-source/hololake-platform/architecture/HOLOLAKE-PERSONAL-NODE-WORK-LAKE-MOBILE-BRIDGE-AND-MINIMUM-REGISTRY-20260812.md", @@ -42,6 +42,14 @@ "stores_code_memory_tasks_or_terminal_output": false, "real_time_verifier_can_be_git_or_spreadsheet": false }, + "enterprise_four_domain_work_body": { + "owner": "TCS-0002", + "is_public_user_runtime_hosting": false, + "may_store_enterprise_work_repositories": true, + "may_store_ordinary_user_private_work_lakes": false, + "personal_channel_requires_separate_user_owned_node": true, + "machine_projection": "routing/hololake-enterprise-four-domain-work-channel.json" + }, "human_authorization": { "ai_writes_problem_solution_impact_and_request": true, "human_writes_technical_fields": false, diff --git a/routing/hololake-personal-node-work-lake.test.mjs b/routing/hololake-personal-node-work-lake.test.mjs index 6a1933739..76d375551 100644 --- a/routing/hololake-personal-node-work-lake.test.mjs +++ b/routing/hololake-personal-node-work-lake.test.mjs @@ -14,6 +14,9 @@ test("personal node keeps the work lake private and platform hosting at zero", ( assert.equal(map.platform_user_runtime_hosting, false); assert.equal(map.enterprise_registry.stores_private_work_lake, false); assert.equal(map.enterprise_registry.stores_code_memory_tasks_or_terminal_output, false); + assert.equal(map.enterprise_four_domain_work_body.is_public_user_runtime_hosting, false); + assert.equal(map.enterprise_four_domain_work_body.may_store_enterprise_work_repositories, true); + assert.equal(map.enterprise_four_domain_work_body.may_store_ordinary_user_private_work_lakes, false); }); test("SQLite, Git, HLDP, files, and terminal remain separate organs", () => {