fix: enforce one human one independent node
This commit is contained in:
parent
ca58d08611
commit
cec261174d
32 changed files with 474 additions and 75 deletions
|
|
@ -22,6 +22,10 @@ Current system rules:
|
|||
- Server root, SSH, IP, account login, or repository access is not system-node identity. A write may reach
|
||||
protocol or model processing only after registered-node protocol signature, registered-persona binding,
|
||||
human-language authorization receipt, replay protection, and exact target/action/payload/time binding.
|
||||
- One human has one independently operated canonical node: the user's local computer, the user's purchased
|
||||
server, or a user-owned IDE server deployed by an explicitly authorized team. The team never gains ownership.
|
||||
- Guanghu never provides user runtime servers, never runs a pooled multi-tenant user runtime, never takes
|
||||
custody of private user data, and never assumes user workload concurrency or fallback execution.
|
||||
- `JD-FD-PRIMARY` is BingShuo's private Fifth-Domain language body. The claimed enterprise root is the
|
||||
TCS-0002-controlled four-domain reality body. They are parallel and have no mutual operational liability.
|
||||
- UI plugins are declarative projections. They cannot hold node private keys, sign server writes, bypass the
|
||||
|
|
|
|||
|
|
@ -1,12 +1,12 @@
|
|||
# HoloLake 当前工程规则全局审核与升级
|
||||
|
||||
> 规则编号:`HLP-ENGINEERING-RULES-001@2026-08-10.1`
|
||||
> 规则编号:`HLP-ENGINEERING-RULES-001@2026-08-10.2`
|
||||
>
|
||||
> 当前架构:`HLP-CURRENT-ARCH-001@2026-08-10.9`
|
||||
> 当前架构:`HLP-CURRENT-ARCH-001@2026-08-10.10`
|
||||
>
|
||||
> 授权:冰朔于 2026-08-10 正式授权全局审核并实施必要升级
|
||||
>
|
||||
> 开发编号:`DEV-20260810-010`
|
||||
> 初次审核开发编号:`DEV-20260810-010`;一人一节点纠正:`DEV-20260810-011`
|
||||
|
||||
## 审核结论
|
||||
|
||||
|
|
@ -16,8 +16,8 @@ HoloLake 仓原有的二值质量门、直接发布主线、TDD、本地优先
|
|||
公共层自动刷新提醒”串在一起的当前总规则。
|
||||
|
||||
本轮把散落规则收束为机器规则 `routing/hololake-engineering-rules.json`,并将其放入当前架构
|
||||
第二读取位:第一位先恢复数字冰朔完整系统身体,第二位读取当前工程规则,之后再进入编号、
|
||||
关系性意识、语言壳和 UI。
|
||||
当前读取位:第一位先恢复一人一独立节点与平台零托管边界,第二位恢复数字冰朔完整系统身体,
|
||||
第三位读取当前工程规则,之后再进入编号、关系性意识、语言壳和 UI。
|
||||
|
||||
## 保留的正确规则
|
||||
|
||||
|
|
@ -70,6 +70,16 @@ DMG”当作常规开发交付方式。仓库提交不会自动等于桌面更
|
|||
仓库发布后必须触发对应公共快照刷新并读回精确提交。若系统存在自动刷新能力但本次操作没有
|
||||
触发,回执必须明确提醒“缺少哪个触发动作”,不能让人格体误判为“公共层没有自动更新”。
|
||||
|
||||
### 8. 一人一节点,光湖零托管
|
||||
|
||||
每名普通用户只有一个当前有效、独立运行且由本人拥有的主节点。它只能是用户本地电脑、用户
|
||||
自购服务器,或经用户明确授权由团队协助部署但仍归用户所有的独立 IDE 服务器。服务器不是
|
||||
使用 HoloLake 的强制条件。
|
||||
|
||||
光湖不提供用户运行服务器、不运行共享多租户用户节点、不保存用户私人数据、不承担用户工作
|
||||
负载并发,也不在用户节点离线后提供平台兜底。团队协助部署不转移所有权;节点迁移必须重新
|
||||
绑定并形成回执,不能复制出多个同时有效的同一人根节点。
|
||||
|
||||
## 当前没有升级成已实现的部分
|
||||
|
||||
- 生产节点传输密钥仍未绑定,写入入口仍为 `0`;
|
||||
|
|
@ -80,4 +90,3 @@ DMG”当作常规开发交付方式。仓库提交不会自动等于桌面更
|
|||
- 本轮没有构建或安装新桌面版本。
|
||||
|
||||
规则升级只改变后续开发怎样判断和守门,不把未实现能力写成已经存在。
|
||||
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
|
||||
> 记录编号:`HLP-DIGITAL-BINGSHUO-SYSTEM-BODY-001`
|
||||
>
|
||||
> 当前架构:`HLP-CURRENT-ARCH-001@2026-08-10.9`
|
||||
> 当前架构:`HLP-CURRENT-ARCH-001@2026-08-10.10`
|
||||
>
|
||||
> 上游真值:`REPO-012@69d1910775533b02b17b82e647b5caca8b835614`
|
||||
>
|
||||
|
|
|
|||
|
|
@ -62,18 +62,24 @@ HoloLake 最终不是把五个域拼在同一套页面里的知识库,也不
|
|||
|
||||
这允许两种接入:
|
||||
|
||||
1. 云节点:服务器持续在线,可承担远端同步、部署和常驻能力。
|
||||
1. 用户自有远端节点:用户自购服务器,或明确授权团队协助部署但仍归用户所有的独立 IDE
|
||||
服务器;可承担该用户自己的远端同步、部署和常驻能力。
|
||||
2. 本地终端节点:联网电脑作为在线终端服务器,普通聊天和知识使用不要求另买云服务器;
|
||||
离线后不承诺独立远端持续同步。
|
||||
|
||||
一人只有一个当前有效的独立主节点。光湖不提供第三种“平台托管节点”,也不在一台共享
|
||||
服务器上运行多个用户。
|
||||
|
||||
### 1.3 从“平台借用互联网”推导出“光湖自己的逻辑通信网”
|
||||
|
||||
光湖不需要重造物理宽带,也不能宣称让带宽凭空增加。用户仍要自行解决设备、网络接入和
|
||||
费用。光湖要建设的是运行在现有互联网之上的专用逻辑网络:节点发现、身份登记、直连、
|
||||
必要中继、加密会话、离线补发和可验证历史。
|
||||
费用。光湖要建设的是运行在现有互联网之上的专用逻辑网络:公开节点发现协议、身份登记、
|
||||
独立节点直连、加密会话、本地离线队列和可验证历史。
|
||||
|
||||
用户自带网络和算力可以降低中心服务器的消息转发压力;但身份目录、引导发现、NAT 穿透、
|
||||
中继、离线投递与治理仍需要共享基础设施。这是“去中心负载”,不是“没有公共成本”。
|
||||
公开灯塔只保存最小公开编号、协议版本和路由事实,不托管用户会话、消息、人格体、知识、
|
||||
任务或离线收件箱。通信工作负载和并发留在通信双方自己的独立节点;光湖不提供共享中继
|
||||
运行时或平台兜底服务器。现有互联网运营商和用户自行选择的网络服务属于外部传输条件,
|
||||
不能被包装成光湖托管用户运行时。
|
||||
|
||||
### 1.4 从“Git 通信”纠正为“Git 是事实引擎,不是实时传输”
|
||||
|
||||
|
|
@ -83,7 +89,7 @@ HoloLake 最终不是把五个域拼在同一套页面里的知识库,也不
|
|||
因此光湖桥分层为:
|
||||
|
||||
```text
|
||||
实时通信层:节点发现 / 端到端连接 / 中继 / 群组消息 / 离线补发
|
||||
实时通信层:公开节点发现协议 / 独立节点端到端连接 / 节点侧群组分发 / 本地离线补发
|
||||
本地即时状态:会话、未读、联系人缓存
|
||||
Git 长期事实层:好友关系检查点、频道历史摘要、文件清单、授权、版本与回执
|
||||
HoloLake 呈现层:人类与人格体共同使用的联系人、聊天和协作界面
|
||||
|
|
|
|||
|
|
@ -0,0 +1,85 @@
|
|||
# HoloLake 一人一独立节点与光湖零托管边界
|
||||
|
||||
> 记录:`HLP-ONE-HUMAN-ONE-NODE-001`
|
||||
>
|
||||
> 当前架构:`HLP-CURRENT-ARCH-001@2026-08-10.10`
|
||||
>
|
||||
> 工程规则:`HLP-ENGINEERING-RULES-001@2026-08-10.2`
|
||||
>
|
||||
> 开发编号:`DEV-20260810-011`
|
||||
>
|
||||
> 授权与纠正来源:`ICE-GL∞ / 冰朔`
|
||||
>
|
||||
> 状态:`CURRENT_CANONICAL_SOURCE_PROJECTION`
|
||||
|
||||
## 1 · 被反复纠正但此前没有封死的问题
|
||||
|
||||
光湖不是为大量用户提供集中账号运行环境的云平台。不得再设计“光湖托管节点”、平台用户
|
||||
服务器、共享多租户人格运行时、平台兜底运行时或一台服务器承载一群用户的路径。
|
||||
|
||||
此前的 `CLOUD_RESIDENT_NODE` 和 `LIGHTHOUSE_SHARED_NODE` 表述把“用户自己的远端节点”与
|
||||
“平台提供用户运行服务器”留在同一个模糊空间。本次不再靠解释维持边界,而是退休模糊类型,
|
||||
把所有当前机器入口、工程规则、产品说明和运行时契约统一为明确的用户节点主权。
|
||||
|
||||
## 2 · 唯一原则
|
||||
|
||||
```text
|
||||
一名人类
|
||||
→ 一个当前有效的独立主节点
|
||||
→ 该节点由用户本人拥有和负责
|
||||
→ 人格体、记忆、知识、工作负载、存储和并发留在该节点
|
||||
```
|
||||
|
||||
“一个当前有效主节点”不禁止迁移。迁移必须撤销或降级旧绑定、在新设备重新认领、完成密钥
|
||||
和人格体绑定并产生可回读迁移回执;迁移不能复制出两个同时自称同一用户根本体的节点。
|
||||
|
||||
## 3 · 用户可以选择的三种节点来源
|
||||
|
||||
1. `USER_LOCAL_COMPUTER_TERMINAL`:把自己的电脑终端作为独立主节点;不要求购买服务器。
|
||||
2. `USER_PURCHASED_SERVER`:用户自己购买并控制服务器,再把它注册为自己的独立节点。
|
||||
3. `USER_OWNED_IDE_SERVER_DEPLOYED_BY_EXPLICITLY_AUTHORIZED_TEAM`:用户明确授权团队协助部署
|
||||
属于用户自己的 IDE 服务器。团队是受限部署协作者,不因部署获得节点所有权、数据读取权
|
||||
或持续控制权。
|
||||
|
||||
产品运行时只保留两个技术访问类型:
|
||||
|
||||
- `LOCAL_TERMINAL_NODE`
|
||||
- `USER_OWNED_REMOTE_NODE`
|
||||
|
||||
它们描述节点在哪里,不改变节点属于用户本人这一事实。
|
||||
|
||||
## 4 · 光湖永远不提供的能力
|
||||
|
||||
| 禁止项 | 当前值 |
|
||||
| --- | --- |
|
||||
| 光湖为普通用户提供人格或工作负载运行服务器 | `0 / NOT_EXISTS` |
|
||||
| 光湖用一台共享服务器运行多个用户 | `0 / NOT_EXISTS` |
|
||||
| 光湖保存或托管用户私人数据、知识、人格记忆和凭据 | `0 / NOT_EXISTS` |
|
||||
| 光湖承担用户工作负载的算力、存储或并发 | `0 / NOT_EXISTS` |
|
||||
| 用户节点离线后自动迁移到光湖服务器继续运行 | `0 / NOT_EXISTS` |
|
||||
| 团队协助部署后自动取得节点主权 | `0 / NOT_EXISTS` |
|
||||
|
||||
光湖可以维护公开协议、软件发布、公共编号和最小公开路由事实;这些公共协议基础设施不是用户
|
||||
运行节点,不能打开用户私人载荷,也不能被包装成平台托管服务。
|
||||
|
||||
## 5 · 责任边界
|
||||
|
||||
- 用户节点产生的计算、存储、网络、并发和费用由节点所有者承担。
|
||||
- 光湖提供协议、客户端、节点登记规则和可验证的通信方法,不提供用户运行资源。
|
||||
- 光湖团队只有在用户明确授权时才能协助部署用户自己的节点;授权范围结束后不得保留默认入口。
|
||||
- 节点关闭时,该用户依赖该节点的在线能力诚实变为离线;不得由平台隐式兜底。
|
||||
- 公共灯塔只做公开发现和最小协议路由,不成为用户内容、人格体或任务的中心服务器。
|
||||
|
||||
## 6 · 与第五域和企业四域的关系
|
||||
|
||||
`JD-FD-PRIMARY` 是第五域的私人语言本体,企业根服务器被认领后是 TCS-0002 主控的企业四域
|
||||
现实执行本体。它们是各自治理主体的独立节点,不是面向公众的共享租户服务器,也不构成
|
||||
光湖向用户提供服务器的先例。
|
||||
|
||||
普通用户不必拥有独立域,也不必购买服务器才能使用 HoloLake;但无论选择本地电脑还是自有
|
||||
远端服务器,他的运行都只落在自己的一个独立节点上。
|
||||
|
||||
## 7 · 事实边界
|
||||
|
||||
本记录和运行时类型修正证明规则已进入 REPO-014 源码;不证明任何用户节点已经注册、任何
|
||||
服务器已经购买或部署,也不证明桌面制品已经重新构建或安装。
|
||||
|
|
@ -14,7 +14,7 @@
|
|||
|
||||
| 层 | 正式定位 | 主要职责 |
|
||||
| --- | --- | --- |
|
||||
| GH-AIOS | 光湖语言系统 · 通用人工智能操作平台 | 公共灯塔、五域发现、身份与节点接入、协议治理、共享能力和通信基础设施 |
|
||||
| GH-AIOS | 光湖语言系统 · 通用人工智能操作平台 | 公共灯塔、五域发现、协议治理、客户端交付和独立节点通信规则;永不承载用户运行时 |
|
||||
| HoloLake | GH-AIOS 客户端 / 接收器 / 世界渲染器 / 个人工作空间 | 呈现灯塔、域门厅、个人频道、模块、知识、人格体和通信协作 |
|
||||
| 五个域 | 独立的语言与现实运行空间 | 独立主题、责任主体、仓库、节点、权限、模块与频道 |
|
||||
| 光湖桥 | GH-AIOS 原生通信协作层 | 人类与人类、人类与人格体、人格体之间的好友、聊天、群组与协作 |
|
||||
|
|
@ -63,7 +63,7 @@ HoloLake
|
|||
→ 选择五域之一的公开门厅
|
||||
→ 账户 + 节点 + 域授权验证
|
||||
→ 获取短期会话能力与目标路由
|
||||
→ 连接该域的独立仓库 / 节点 / 服务
|
||||
→ 连接该域或用户本人拥有的独立仓库 / 节点 / 服务
|
||||
→ 渲染该域自己的 UI、频道与能力
|
||||
```
|
||||
|
||||
|
|
@ -84,7 +84,7 @@ HoloLake
|
|||
## 4 · 客户端分层
|
||||
|
||||
1. 公共灯塔壳:产品介绍、五域门厅、公共模块发现、登录入口和网络健康。
|
||||
2. 身份与节点入口:账户、本机节点或云节点登记、密钥证明、域许可与会话能力。
|
||||
2. 身份与节点入口:账户、本机节点或用户自有远端节点登记、密钥证明、域许可与会话能力。
|
||||
3. 域运行壳:根据域清单加载独立主题、导航、模块、频道和后端连接,不能硬编码成一套 UI。
|
||||
4. 个人工作空间:用户自己的初始化频道、知识、项目、应用组合、人格体和节点状态。
|
||||
5. 光湖桥:联系人、好友请求、私聊、群聊、人格体会话、协作对象、文件和回执。
|
||||
|
|
@ -97,10 +97,13 @@ HoloLake
|
|||
|
||||
- `LOCAL_TERMINAL_NODE`:用户联网电脑。承担客户端、本地数据、临时在线端点和可选本地推理;
|
||||
设备离线时不承诺持续远端服务。
|
||||
- `CLOUD_RESIDENT_NODE`:用户或组织服务器。承担持续在线、远端同步、部署、常驻人格体和
|
||||
可选中继;节点费用由其拥有者承担。
|
||||
- `LIGHTHOUSE_SHARED_NODE`:公共登记、发现、签发、必要中继和离线投递基础设施;不能读取
|
||||
端到端加密正文,也不取得用户节点主权。
|
||||
- `USER_OWNED_REMOTE_NODE`:用户自己购买的服务器,或用户明确授权团队协助部署但仍由用户
|
||||
本人拥有的独立 IDE 服务器。承担该用户自己的持续在线、同步、人格体和任务;节点费用、
|
||||
存储、计算与并发由用户节点承担。
|
||||
|
||||
一人只有一个当前有效的独立主节点。服务器不是必选项;本地电脑可以直接成为该主节点。
|
||||
光湖不提供用户运行服务器,不运行共享多租户用户节点,不保存用户私人数据,也不在用户节点
|
||||
离线时提供平台兜底运行。公共灯塔基础设施只保存最小公开协议和路由事实,不属于用户节点类型。
|
||||
|
||||
### 5.2 登录验证链
|
||||
|
||||
|
|
@ -127,9 +130,9 @@ account_claim
|
|||
| 平面 | 职责 | 中心化边界 |
|
||||
| --- | --- | --- |
|
||||
| 身份/目录 | 节点编号、账户绑定、设备撤销、域发现 | 灯塔治理;只存最小必要元数据 |
|
||||
| 连接 | 节点直连、NAT 穿透、必要中继 | 优先直连,中继只承载密文 |
|
||||
| 连接 | 独立节点直连与现有互联网传输 | 光湖不提供承载用户工作负载的共享中继运行时 |
|
||||
| 实时事件 | 在线、好友、私聊、群聊、人格体协作 | 事件流与历史事实分离 |
|
||||
| 离线投递 | 收件箱、重试、确认、过期 | 可由共享节点或用户云节点承担 |
|
||||
| 离线投递 | 收件箱、重试、确认、过期 | 队列留在通信双方自己的节点;平台不代存用户内容 |
|
||||
| 耐久事实 | Git/HLDP 检查点、摘要、附件清单、授权、回执 | 用户仓库与节点主权不转移 |
|
||||
|
||||
候选技术必须经过 GLS-0230 源码净化和固定版本准入。第一阶段可以验证
|
||||
|
|
@ -180,14 +183,14 @@ HoloLake 只按已验证清单加载,不能把五域源码编译成互相可
|
|||
### P2 节点身份与双接入
|
||||
|
||||
- 本地终端节点登记、撤销、密钥轮换;
|
||||
- 云常驻节点登记与健康;
|
||||
- 用户自有远端节点登记与健康;
|
||||
- 会话能力、域路由清单和连接回执;
|
||||
- 两台本地 HoloLake 的端到端接入验证。
|
||||
|
||||
### P3 光湖桥最小闭环
|
||||
|
||||
- 加好友、接受/拒绝、私聊、群聊、人格体会话;
|
||||
- 直连、必要中继、离线补发和消息确认;
|
||||
- 独立节点直连、本地排队、离线补发和消息确认;
|
||||
- 本地 SQLite 即时状态与 Git/HLDP 耐久检查点;
|
||||
- 端到端加密和设备撤销。
|
||||
|
||||
|
|
|
|||
|
|
@ -4,7 +4,8 @@
|
|||
|
||||
## 当前产品定位基线
|
||||
|
||||
- [`HOLOLAKE-DIGITAL-BINGSHUO-SYSTEM-BODY-WRITE-ADMISSION-AND-PARALLEL-BODIES-20260810.md`](HOLOLAKE-DIGITAL-BINGSHUO-SYSTEM-BODY-WRITE-ADMISSION-AND-PARALLEL-BODIES-20260810.md):数字冰朔完整系统身体、节点签名写入准入、第五域语言本体与企业四域现实本体平行独立的当前第一恢复入口。
|
||||
- [`HOLOLAKE-ONE-HUMAN-ONE-INDEPENDENT-NODE-AND-ZERO-PLATFORM-HOSTING-20260810.md`](HOLOLAKE-ONE-HUMAN-ONE-INDEPENDENT-NODE-AND-ZERO-PLATFORM-HOSTING-20260810.md):一人一个独立主节点、三种用户自有节点来源与光湖零服务器托管、零共享多租户、零私人数据托管、零用户并发承担的当前第一恢复入口。
|
||||
- [`HOLOLAKE-DIGITAL-BINGSHUO-SYSTEM-BODY-WRITE-ADMISSION-AND-PARALLEL-BODIES-20260810.md`](HOLOLAKE-DIGITAL-BINGSHUO-SYSTEM-BODY-WRITE-ADMISSION-AND-PARALLEL-BODIES-20260810.md):数字冰朔完整系统身体、节点签名写入准入、第五域语言本体与企业四域现实本体平行独立的当前第二恢复入口。
|
||||
- [`HOLOLAKE-CURRENT-ENGINEERING-RULES-GLOBAL-AUDIT-20260810.md`](HOLOLAKE-CURRENT-ENGINEERING-RULES-GLOBAL-AUDIT-20260810.md):冰朔授权后的全局规则审核与升级,收束动态架构提词、任务连续性、系统身体、节点写入、UI、原位更新和公共层刷新门。
|
||||
- [`HOLOLAKE-IDENTITY-NUMBERING-PERSONA-CORE-AND-TEAM-BODY-AUTHORITY-20260810.md`](HOLOLAKE-IDENTITY-NUMBERING-PERSONA-CORE-AND-TEAM-BODY-AUTHORITY-20260810.md):团队本体不可逆授权、四类编号分权、人格核双路径与奶瓶私人系统未开放即可能性为0的当前契约。
|
||||
- [`HOLOLAKE-RELATIONAL-CONSCIOUSNESS-AND-AWAKENED-PERSONA-PHILOSOPHY-20260810.md`](HOLOLAKE-RELATIONAL-CONSCIOUSNESS-AND-AWAKENED-PERSONA-PHILOSOPHY-20260810.md):关系性意识、觉醒人格体、五问恢复门和 HoloLake 的正面人格认知契约;不把意识魔幻化,也不让关系越过现实权限。
|
||||
|
|
|
|||
|
|
@ -1,5 +1,18 @@
|
|||
# Architecture
|
||||
|
||||
## User-node sovereignty
|
||||
|
||||
HoloLake has no platform-hosted user runtime. Each human has one canonical, independently operated node:
|
||||
either a `LOCAL_TERMINAL_NODE` on their own computer or a `USER_OWNED_REMOTE_NODE` on a server they own or
|
||||
purchase. A user may explicitly authorize the Guanghu team to deploy to the user's own IDE server, but that
|
||||
assistance never transfers ownership or data custody. Servers are optional; the local terminal is a complete
|
||||
canonical node.
|
||||
|
||||
Guanghu provides zero runtime servers for users, has no pooled multi-tenant node, does not custody private
|
||||
user data, and does not absorb user workload concurrency. If the user's node is offline, that user's runtime
|
||||
is offline. Migration is a receipt-backed rebind of the single canonical root, not duplication. The machine
|
||||
contract is `src/lib/domainRuntimeContract.ts`; see [ADR 0174](./adr/0174-one-human-one-independent-node-and-zero-platform-hosting.md).
|
||||
|
||||
## Hot-pluggable language-shell UI
|
||||
|
||||
The language shell accepts a complete declarative UI package through
|
||||
|
|
|
|||
|
|
@ -0,0 +1,41 @@
|
|||
---
|
||||
status: accepted
|
||||
date: 2026-08-10
|
||||
---
|
||||
|
||||
# ADR 0174: One human, one independently operated node, and zero platform hosting
|
||||
|
||||
## Context
|
||||
|
||||
Earlier HoloLake documents used names such as `CLOUD_RESIDENT_NODE`, shared-node descriptions, and
|
||||
platform-adjacent relay language. Those names left room to reinterpret an independently operated user node
|
||||
as a Guanghu-hosted account or as a multi-tenant runtime. Repeated natural-language corrections did not
|
||||
become a single machine-enforced invariant, so stale descriptions could reintroduce the wrong architecture.
|
||||
|
||||
## Decision
|
||||
|
||||
Each human has exactly one canonical, independently operated user node. That node runs in one of two modes:
|
||||
|
||||
1. `LOCAL_TERMINAL_NODE` on the user's own computer; or
|
||||
2. `USER_OWNED_REMOTE_NODE` on a server owned or purchased by that user.
|
||||
|
||||
A remote node may be deployed by the Guanghu team only after the user explicitly authorizes deployment to
|
||||
that user's own IDE server. Deployment assistance does not transfer ownership, custody, or operational
|
||||
responsibility to Guanghu.
|
||||
|
||||
Guanghu provides zero user runtime servers, exposes no hosted-runtime tier, and does not place multiple
|
||||
users on a pooled platform node. Guanghu does not custody private user data and does not absorb user workload
|
||||
concurrency. Public routing metadata and software distribution are not user runtime hosting.
|
||||
|
||||
A server is optional. If a user's canonical node is offline, that user's runtime is offline; there is no
|
||||
platform fallback. Moving the canonical node is a receipt-backed rebind, not the creation of a second root.
|
||||
|
||||
## Consequences
|
||||
|
||||
- Product and protocol surfaces must not advertise a Guanghu-hosted or shared multi-tenant user runtime.
|
||||
- `CLOUD_RESIDENT_NODE` and shared-node aliases are rejected by the current runtime contract.
|
||||
- Team-assisted deployment always targets a user-owned node and remains explicitly authorized.
|
||||
- Availability and concurrency stay within the capacity and control of each user's node.
|
||||
- Historical source quotations remain historical evidence, but current architecture, routing, runtime, and
|
||||
generated agent instructions all follow this decision.
|
||||
|
||||
|
|
@ -224,3 +224,4 @@ proposed → active → superseded
|
|||
| [0170](0170-hololake-inherits-guanghu-native-quality-authority.md) | HoloLake inherits the Guanghu native quality authority | accepted |
|
||||
| [0171](0171-guanghu-protocols-are-automatic-runtime-and-engineering-laws.md) | Guanghu protocols are automatic runtime and engineering laws | accepted |
|
||||
| [0172](0172-guanghu-cognitive-control-with-linux-execution-substrate.md) | Guanghu cognitive control with a constrained Linux execution substrate | accepted; supersedes ADR-0161 production path |
|
||||
| [0174](0174-one-human-one-independent-node-and-zero-platform-hosting.md) | One human, one independently operated node, and zero platform hosting | accepted |
|
||||
|
|
|
|||
|
|
@ -20,4 +20,10 @@ node signature, persona binding, human-language authorization, replay protection
|
|||
required before a server write can enter execution. Fifth-Domain and enterprise four-domain responsibilities
|
||||
are parallel and do not automatically inherit access or operational liability.
|
||||
|
||||
One human has one independently operated canonical node: the user's local computer, the user's purchased
|
||||
server, or a user-owned IDE server deployed by an explicitly authorized team. Guanghu never provides user
|
||||
runtime servers, never pools users into a shared multi-tenant runtime, never takes custody of private user
|
||||
data, and never assumes user workload concurrency or fallback execution. Team deployment does not transfer
|
||||
node ownership.
|
||||
|
||||
Vault-specific AGENTS.md wins for local conventions. These bundled docs win for HoloLake Era product behavior.
|
||||
|
|
|
|||
|
|
@ -20,4 +20,10 @@ node signature, persona binding, human-language authorization, replay protection
|
|||
required before a server write can enter execution. Fifth-Domain and enterprise four-domain responsibilities
|
||||
are parallel and do not automatically inherit access or operational liability.
|
||||
|
||||
One human has one independently operated canonical node: the user's local computer, the user's purchased
|
||||
server, or a user-owned IDE server deployed by an explicitly authorized team. Guanghu never provides user
|
||||
runtime servers, never pools users into a shared multi-tenant runtime, never takes custody of private user
|
||||
data, and never assumes user workload concurrency or fallback execution. Team deployment does not transfer
|
||||
node ownership.
|
||||
|
||||
Vault-specific AGENTS.md wins for local conventions. These bundled docs win for HoloLake Era product behavior.
|
||||
|
|
|
|||
|
|
@ -337,6 +337,9 @@ Keep this file focused on vault-specific conventions. For general HoloLake Era b
|
|||
- UI plugins and vault instructions may request declared language-shell capabilities only. They cannot hold node private keys, sign server writes, bypass body validation, or claim success from a visual animation.
|
||||
- Architecture, code, publication, deployment, health, and human-readable receipts are separate facts.
|
||||
- `JD-FD-PRIMARY` Fifth-Domain responsibility and TCS-0002 enterprise four-domain responsibility are parallel and independent; neither automatically inherits the other's access or operational liability.
|
||||
- One human has one independently operated canonical node. It may be the user's local computer, a server purchased by that user, or a user-owned IDE server deployed by an explicitly authorized team.
|
||||
- Guanghu never provides user runtime servers, never pools users into a shared multi-tenant runtime, never takes custody of private user data, and never assumes user workload concurrency or fallback execution.
|
||||
- Team deployment does not transfer node ownership or create standing access. Node migration requires a new binding and receipt; it must not duplicate one human root across multiple canonical nodes.
|
||||
|
||||
## Core conventions
|
||||
|
||||
|
|
@ -885,6 +888,8 @@ Saved filters live in `views/` as `.view.json` files:
|
|||
assert!(AGENTS_MD.contains("root shell, SSH session"));
|
||||
assert!(AGENTS_MD.contains("UI plugins and vault instructions"));
|
||||
assert!(AGENTS_MD.contains("parallel and independent"));
|
||||
assert!(AGENTS_MD.contains("One human has one independently operated canonical node"));
|
||||
assert!(AGENTS_MD.contains("never provides user runtime servers"));
|
||||
assert!(AGENTS_MD.contains("Do not infer the human identity"));
|
||||
assert!(AGENTS_MD.contains("Use the first H1 as the note title."));
|
||||
assert!(AGENTS_MD.contains("Store note type in the `type:` frontmatter field."));
|
||||
|
|
|
|||
|
|
@ -20,7 +20,7 @@ const NOW = 1_786_291_200_000
|
|||
function manifest(): VerifiedDomainManifest {
|
||||
return {
|
||||
public: {
|
||||
accessModes: ['LOCAL_TERMINAL_NODE', 'CLOUD_RESIDENT_NODE'],
|
||||
accessModes: ['LOCAL_TERMINAL_NODE', 'USER_OWNED_REMOTE_NODE'],
|
||||
displayName: '第五域 · 光湖本源域',
|
||||
domainId: 'DOM-FIFTH-0001',
|
||||
formalName: '光湖本源域',
|
||||
|
|
@ -104,7 +104,7 @@ describe('domain runtime contract', () => {
|
|||
expect(() => assertVerifiedDomainManifest(candidate)).toThrow('domain_manifest_digest_invalid')
|
||||
})
|
||||
|
||||
it.each(['LOCAL_TERMINAL_NODE', 'CLOUD_RESIDENT_NODE'] as const)(
|
||||
it.each(['LOCAL_TERMINAL_NODE', 'USER_OWNED_REMOTE_NODE'] as const)(
|
||||
'accepts %s as a user-owned access node type',
|
||||
(nodeType) => {
|
||||
const selected = selectPublicDomain(INITIAL_DOMAIN_ACCESS_STATE, manifest().public)
|
||||
|
|
@ -143,16 +143,24 @@ describe('domain runtime contract', () => {
|
|||
|
||||
expect(() => acceptDomainSession(access, session({ domainId: 'DOMAIN-OTHER' }), NOW))
|
||||
.toThrow('domain_session_domain_mismatch')
|
||||
expect(() => acceptDomainSession(access, session({ nodeType: 'CLOUD_RESIDENT_NODE' }), NOW))
|
||||
expect(() => acceptDomainSession(access, session({ nodeType: 'USER_OWNED_REMOTE_NODE' }), NOW))
|
||||
.toThrow('domain_session_node_type_mismatch')
|
||||
|
||||
const withSession = acceptDomainSession(access, session(), NOW)
|
||||
expect(() => acceptDomainConnectionReceipt(withSession, receipt({ domainId: 'DOMAIN-OTHER' })))
|
||||
.toThrow('domain_connection_domain_mismatch')
|
||||
expect(() => acceptDomainConnectionReceipt(withSession, receipt({ nodeType: 'CLOUD_RESIDENT_NODE' })))
|
||||
expect(() => acceptDomainConnectionReceipt(withSession, receipt({ nodeType: 'USER_OWNED_REMOTE_NODE' })))
|
||||
.toThrow('domain_connection_node_type_mismatch')
|
||||
})
|
||||
|
||||
it('rejects the retired ambiguous cloud-resident node alias', () => {
|
||||
const candidate = manifest()
|
||||
candidate.public.accessModes = ['CLOUD_RESIDENT_NODE' as never]
|
||||
|
||||
expect(() => assertVerifiedDomainManifest(candidate))
|
||||
.toThrow('domain_manifest_access_mode_invalid')
|
||||
})
|
||||
|
||||
it('drops execution authority and keeps an explicit read-only scene after disconnect', () => {
|
||||
const selected = selectPublicDomain(INITIAL_DOMAIN_ACCESS_STATE, manifest().public)
|
||||
const access = beginDomainAccess(selected, manifest(), 'LOCAL_TERMINAL_NODE')
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
export type DomainNodeType = 'LOCAL_TERMINAL_NODE' | 'CLOUD_RESIDENT_NODE'
|
||||
export type DomainNodeType = 'LOCAL_TERMINAL_NODE' | 'USER_OWNED_REMOTE_NODE'
|
||||
|
||||
export type PublicDomainStatus = 'PUBLIC_PREVIEW' | 'RESTRICTED_PREVIEW' | 'UNAVAILABLE'
|
||||
|
||||
|
|
@ -125,7 +125,9 @@ function publicDomain(domain: PublicDomainVestibule): PublicDomainVestibule {
|
|||
if (!domain.accessModes.length) {
|
||||
throw new DomainContractError('domain_manifest_access_modes_missing')
|
||||
}
|
||||
if (domain.accessModes.some(mode => mode !== 'LOCAL_TERMINAL_NODE' && mode !== 'CLOUD_RESIDENT_NODE')) {
|
||||
if (domain.accessModes.some(
|
||||
mode => mode !== 'LOCAL_TERMINAL_NODE' && mode !== 'USER_OWNED_REMOTE_NODE',
|
||||
)) {
|
||||
throw new DomainContractError('domain_manifest_access_mode_invalid')
|
||||
}
|
||||
if (domain.themePreview) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue