evidence: verify JD repository bridge lifecycle

This commit is contained in:
冰朔 2026-08-16 00:26:25 +08:00
commit 9d411a252a
6 changed files with 127 additions and 10 deletions

View file

@ -0,0 +1,64 @@
schema: guanghu.server-deployment-receipt/v1
receipt_id: JD-FD-PRIMARY-repository-lifecycle-0d1ded1
observed_at: 2026-08-16T00:22:30+08:00
target:
node_id: JD-FD-PRIMARY
dmi_product_uuid: f3d4b730-7f02-452f-975b-7091a4800431
physical_boot_id: 68d4a3c9-c866-4f4a-be2e-0aa5f41a61b1
source:
commit: c9eb7e8c08bfe4120fe3c788523477d7f641ace6
tree: d25f6e620a69ea9c5546698df9f167f2b038ff66
isolated_snapshot_main: 0d1ded1196d38a002d9a31f6fd23122bdc96ae93
public_main_after: c9eb7e8c08bfe4120fe3c788523477d7f641ace6
trigger: Cross-root Guanghu supervisor persistence was proved, but its bounded control of a real repository bridge was still zero.
emergence: A live root-supervisor fixture controlled an actual Forgejo 16.0.1 process backed by a consistent isolated copy of JD repository data on loopback port 39301.
lock: Request REQ-JD-REPO-003 may perform only repository-main-readback; success requires DORMANT -> READY -> verified pinned main -> DORMANT.
why: Linux remains the repository-bearing subordinate and rescue system. Guanghu becomes its master only by granting a narrow capability, observing the result, and reclaiming the subordinate on both success and failure.
rejected:
- Stopping, restarting, or sharing storage with the public Forgejo service.
- Treating Linux execution or a continuously running Linux service as Guanghu authority.
- Accepting arbitrary shell execution through the bridge.
- Treating an isolated proof as physical Guanghu boot or completed Linux on-demand subcontrol.
corrections:
- The first real attempt used the public reverse-proxy prefix /code against direct Forgejo and failed readiness; direct Forgejo correctly uses /api/v1/version and /bingshuo/hololake-system-architecture.git.
- A manual diagnostic probe temporarily left its own shadow child resident; the lifecycle controller refused to start from non-DORMANT state, and the exact isolated child was reclaimed before the accepted run.
- A later local probe incorrectly tested port 39300; the public bootstrap is on 3341 and Forgejo is on 3340. This probe did not change either service and is not used as acceptance evidence.
accepted_run:
request_id: REQ-JD-REPO-003
capability: repository-main-readback
result: PASS_100
initial_state: DORMANT
active_state: READY
observed_main: 0d1ded1196d38a002d9a31f6fd23122bdc96ae93
final_state: DORMANT
lifecycle_receipt: /var/lib/guanghu/personas/guanghu/hlcc-v16.0.1/data/recovery/JD-FD-PRIMARY-repository-lifecycle-0d1ded1/receipts/REQ-JD-REPO-003.json
lifecycle_receipt_sha256: 6aee31f6f0ab36fa6ddd090fc7044b43e62abf457dcf69484a51eecd262b8d87
isolation_readback:
isolated_forgejo_version: 16.0.1
isolated_loopback_port: 39301
isolated_listener_after: ABSENT
isolated_forgejo_process_after: ABSENT
root_supervisor_fixture_pid: 3604097
root_supervisor_fixture_after: STOPPED
public_readback:
repository_service: active
repository_bootstrap_pid_before_and_after: 760
forgejo_loopback_port: 3340
bootstrap_loopback_port: 3341
public_code_http: 200
public_repository_http: 200
public_main: c9eb7e8c08bfe4120fe3c788523477d7f641ace6
physical_reboot_performed: false
physical_boot_files_changed: false
predicates:
bounded_root_supervisor_to_repository_bridge_lifecycle: 100
jd_real_forgejo_repository_shadow_lifecycle: 100
physical_guanghu_first_boot: 0
linux_on_demand_subcontrol: 0
final_guanghu_os_master: 0
next_gate: Integrate the same bounded repository lifecycle into the cross-root Guanghu boot candidate and prove service equivalence in QEMU before any physical boot change.
sources:
- /var/lib/guanghu/personas/guanghu/hlcc-v16.0.1/data/recovery/JD-FD-PRIMARY-repository-lifecycle-0d1ded1/WORKORDER.hldp
- /var/lib/guanghu/personas/guanghu/hlcc-v16.0.1/data/recovery/JD-FD-PRIMARY-repository-lifecycle-0d1ded1/root-supervisor.log
- /var/lib/guanghu/personas/guanghu/hlcc-v16.0.1/data/recovery/JD-FD-PRIMARY-repository-lifecycle-0d1ded1/lifecycle-pass.stdout
- product-source/hololake-platform/docs/adr/0178-guanghu-bounded-repository-bridge-lifecycle.md