architecture: converge HoloLake stage-one desktop mainline
This commit is contained in:
parent
461517c25f
commit
874bcf1b8f
8 changed files with 371 additions and 14 deletions
|
|
@ -37,3 +37,19 @@ The rollback executor is implemented, but production updater activation remains
|
|||
`npm run release:macos -- release/inputs/<version>.json` is the only product-owned macOS release entry. It fails before building unless the embedded trust contains the exact registered HoloLake HTTPS endpoint and updater public key, the immutable `v<version>` tag equals the clean `main` head, and the Developer ID, Tauri updater-signing and Apple notarization credential sets are supplied at runtime. The pipeline runs all product and Rust gates, creates updater artifacts through a temporary Tauri override, then requires strict code-signature verification, Gatekeeper acceptance and stapled Apple notarization before writing the HoloLake broadcast and receipts.
|
||||
|
||||
Generated packages, private release inputs and credentials are not committed. The pipeline never uploads or activates a release; its terminal artifact is a bounded folder ready for a separately authorized JD-controller upload and server-owned readback receipt.
|
||||
|
||||
## Stage-one convergence verdict
|
||||
|
||||
The Tauri source in this directory is the only future HoloLake desktop mainline. An installed build of it is an acceptance candidate, not a separate product line and not proof that stage one exists. The Electron 0.8.0 product and the legacy Tauri/platform sources remain read-only UX, behavior, engineering and protected-data donors until inventory, backup, readback, reversible migration rehearsal and signed installed-runtime acceptance all pass.
|
||||
|
||||
The current candidate already has useful under-lake organs: the signed native shell, local broker and resumable session, authenticated read-only PNCC projection, human-confirmed repository mount, deterministic routing, and fail-closed update/rollback machinery. They remain in the architecture, but their existence does not satisfy the visible stage-one body.
|
||||
|
||||
The implementation order is now fixed:
|
||||
|
||||
1. personal-channel identity, task, event and receipt kernel;
|
||||
2. knowledge tree, page, search and local persistence;
|
||||
3. human approval center and Git evidence readback;
|
||||
4. lake-lamp cross-session continuity projection;
|
||||
5. signed installation, opt-in update, rollback and reversible data migration.
|
||||
|
||||
Architecture registration, source implementation, built artifact, signed artifact, desktop installation, data migration, server deployment and service health remain separate receipts. The machine contract is `routing/hololake-stage-one-desktop-convergence.json`.
|
||||
|
|
|
|||
Loading…
Reference in a new issue