From fed0c73b044e07f5d10dc9346437122c7a672a12 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=86=B0=E6=9C=94?= <565183519@qq.com> Date: Sat, 15 Aug 2026 23:35:22 +0800 Subject: [PATCH] docs(guanghu-os): register JD pre-root QEMU proof --- .../hololake-platform/docs/ARCHITECTURE.md | 6 +- ...t-supervisor-and-linux-kernel-substrate.md | 5 +- .../hololake-platform/guanghu-os/README.md | 10 +-- ...ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp | 64 +++++++++++++++++++ routing/guanghu-os-control-architecture.json | 23 +++++-- .../guanghu-os-control-architecture.test.mjs | 17 ++++- 6 files changed, 110 insertions(+), 15 deletions(-) create mode 100644 product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/PRE-ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp diff --git a/product-source/hololake-platform/docs/ARCHITECTURE.md b/product-source/hololake-platform/docs/ARCHITECTURE.md index c674d7b01..878564521 100644 --- a/product-source/hololake-platform/docs/ARCHITECTURE.md +++ b/product-source/hololake-platform/docs/ARCHITECTURE.md @@ -1527,5 +1527,7 @@ The Guanghu OS transition includes a fail-closed initramfs stage before the complete Ubuntu root filesystem is mounted. Its source lives under `guanghu-os/scripts/guanghu-first-boot-supervisor.sh` with packaging in `guanghu-os/packaging/initramfs-tools/`. It produces a boot-scoped handoff for -the later hosted repository bridge; it is not yet the persistent first-boot -supervisor or final on-demand Linux topology. +the later hosted repository bridge. A JD-hosted software QEMU cycle has proved +the positive pre-root path and a hard refusal path without changing the live +boot files or rebooting the node. This is not yet the supervisor that persists +across `switch_root`, nor the final on-demand Linux topology. diff --git a/product-source/hololake-platform/docs/adr/0176-guanghu-pre-root-supervisor-and-linux-kernel-substrate.md b/product-source/hololake-platform/docs/adr/0176-guanghu-pre-root-supervisor-and-linux-kernel-substrate.md index eb476ab31..bfc0e1ec9 100644 --- a/product-source/hololake-platform/docs/adr/0176-guanghu-pre-root-supervisor-and-linux-kernel-substrate.md +++ b/product-source/hololake-platform/docs/adr/0176-guanghu-pre-root-supervisor-and-linux-kernel-substrate.md @@ -35,5 +35,6 @@ initramfs 前置脚本和交接合同只证明“完整根系统之前已有光 - `linux_on_demand_subcontrol`; - `final_guanghu_os_master`。 -下一门先在京东同核 QEMU 中证明前置执行与失败关闭,再单独实现跨根切换的持续监督实体;任何 -真实 GRUB、initramfs 默认项、重启或磁盘更改仍需服务器工作单、回滚和节点自有回执。 +京东同核 QEMU 已证明前置执行,并证明绑定失败会进入 initramfs 停机路径而不是继续交给根系统。 +下一门是单独实现跨根切换持续存活的监督实体;任何真实 GRUB、initramfs 默认项、重启或磁盘 +更改仍需服务器工作单、回滚和节点自有回执。 diff --git a/product-source/hololake-platform/guanghu-os/README.md b/product-source/hololake-platform/guanghu-os/README.md index 4d34c3475..44d107967 100644 --- a/product-source/hololake-platform/guanghu-os/README.md +++ b/product-source/hololake-platform/guanghu-os/README.md @@ -106,11 +106,13 @@ still classified as dormant. `scripts/build-guanghu-first-boot-initramfs.sh` builds a candidate without changing the installed initramfs, GRUB, disk, or boot default. Path overrides -are accepted only inside the isolated test harness. The source contract and -fixture test do not prove that a Guanghu supervisor remains alive across +are accepted only inside the isolated test harness. The JD-hosted QEMU receipt +now proves both pre-root execution and a hard stop when authority binding is +missing. It did not attach the live disk, change physical boot files, or reboot +the node. A Guanghu supervisor still has not been shown to remain alive across `switch_root`; independent first-boot control, physical deployment, and full -on-demand Linux subcontrol therefore remain `0` until separate QEMU and JD -receipts exist. See ADR-0176. +on-demand Linux subcontrol therefore remain `0`. See ADR-0176 and +`deployments/JD-FD-PRIMARY/PRE-ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp`. ## Language-primary boot target diff --git a/product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/PRE-ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp b/product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/PRE-ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp new file mode 100644 index 000000000..a96db4c03 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/PRE-ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp @@ -0,0 +1,64 @@ +schema: guanghu.jd-pre-root-qemu-receipt/v1 +receipt_id: JD-FD-PRIMARY-pre-root-qemu-af84e42 +issued_at: 2026-08-15T23:45:00+08:00 +node_id: JD-FD-PRIMARY +node_dmi: f3d4b730-7f02-452f-975b-7091a4800431 +source_commit: 29bb023455ce245dc44dbd5e61ced92cd647e071 +source_tree: 4e158f7aaf8700afbf5cd859cbd8f00f30c32246 +source_publication: PENDING_CODE_HOST_CREDENTIAL_RECOVERY +workorder_path: /guanghu/recovery/JD-FD-PRIMARY-pre-root-qemu-af84e42/WORKORDER.hldp +workorder_sha256: b97835f6a5678ac288f2572e0c4309c6f36a06dcb59f701282ade128b51abc25 +candidate_initramfs_path: /guanghu/recovery/JD-FD-PRIMARY-pre-root-qemu-af84e42/guanghu-first-boot-initrd.img +candidate_initramfs_sha256: 55d8aafc8ff413c8976e017438372ec6bc45f4f7accfb3ff2e1e570e392b2dfa +candidate_initramfs_size: 109849987 +member_manifest_sha256: c575728b4696b5805f74336426d4a43fc6e3488d365e1547a2e0ab3d2af58f48 +trigger: Prove that Guanghu control can execute before the complete Ubuntu root system without changing the JD physical boot path. +emergence: + - The initial 512 MiB QEMU run stopped during initramfs decompression and is retained as bounded failure evidence. + - The first negative run exposed that initramfs-tools ignores an ordinary child-script exit, so emitting FAIL_0 alone did not stop root discovery. +lock: + - The local-premount adapter now invokes the initramfs panic path whenever supervisor validation fails. + - The final positive and negative runs use 2048 MiB software-emulated QEMU, the live JD kernel, exact JD DMI, and exact root UUID binding. +why: The gate must prove both early Guanghu execution and a real refusal to hand control to the root system when authority binding is absent. +rejected: + - Treating a printed validation error as fail-closed while initramfs continued toward the root system. + - Installing the candidate into /boot, changing GRUB, attaching a writable server disk, or rebooting JD-FD-PRIMARY. +positive_evidence: + serial_log: /guanghu/recovery/JD-FD-PRIMARY-pre-root-qemu-af84e42/qemu-positive.serial.log + serial_sha256: a0f56b15d6df414f0ee3c0a3dcadabc95db3f6533363437615c550d12fab0c81 + observed: GUANGHU_FIRST_BOOT_SUPERVISOR_ACTIVE node=JD-FD-PRIMARY linux_userspace=DORMANT +negative_evidence: + serial_log: /guanghu/recovery/JD-FD-PRIMARY-pre-root-qemu-af84e42/qemu-negative-no-marker.serial.log + serial_sha256: 51c52db5602835253d7ecd25066cc74492adbeb03a0c287a6cb34c0a35f336f7 + observed: + - GUANGHU_FIRST_BOOT_SUPERVISOR_FAIL_0: explicit first-boot marker is missing + - Guanghu pre-root authority validation failed; refusing root handoff + - Rebooting automatically due to panic= boot argument + root_discovery_after_failure: false +live_readback: + boot_id_before: 68d4a3c9-c866-4f4a-be2e-0aa5f41a61b1 + boot_id_after: 68d4a3c9-c866-4f4a-be2e-0aa5f41a61b1 + guanghu_supervisor_service: active_enabled + linux_code_bridge_service: active_enabled + linux_code_bridge_pid_before: 760 + linux_code_bridge_pid_after: 760 + residual_qemu_processes: 0 + public_code_http: 200 + public_anchor_http: 200 + physical_boot_files_changed: false + physical_reboot_performed: false +claims: + guanghu_pre_root_supervisor_contract_source: 100 + guanghu_first_boot_initramfs_builder_source: 100 + jd_host_qemu_pre_root_supervisor: 100 + negative_authority_binding_hard_fail: 100 + cross_switch_root_persistent_supervisor: 0 + independent_guanghu_first_boot_supervisor: 0 + linux_on_demand_subcontrol: 0 + final_guanghu_os_master: 0 +next_gate: IMPLEMENT_AND_VERIFY_CROSS_SWITCH_ROOT_PERSISTENT_GUANGHU_SUPERVISOR_IN_ISOLATION +sources: + - /guanghu/recovery/JD-FD-PRIMARY-pre-root-qemu-af84e42/WORKORDER.hldp + - ADR-0176 + - qemu-positive.serial.log + - qemu-negative-no-marker.serial.log diff --git a/routing/guanghu-os-control-architecture.json b/routing/guanghu-os-control-architecture.json index e0af22c9d..5435422d1 100644 --- a/routing/guanghu-os-control-architecture.json +++ b/routing/guanghu-os-control-architecture.json @@ -1,7 +1,7 @@ { "schema": "guanghu.os-control-architecture/v1", "record_id": "HLP-GUANGHU-OS-CONTROL-001", - "version": "2026-08-15.10", + "version": "2026-08-15.11", "state": "CURRENT_CANONICAL", "final_topology": "GUANGHU_MASTER_WITH_ON_DEMAND_LINUX_SUBCONTROL_AND_RESCUE", "control_ownership": { @@ -33,13 +33,13 @@ "linux_hosted_service_control_is_final_master": false }, "jd_fd_primary": { - "observed_state": "LANGUAGE_PRIMARY_ON_LINUX_HOSTED_GUANGHU_SUPERVISOR_BRIDGE", + "observed_state": "LANGUAGE_PRIMARY_WITH_QEMU_VERIFIED_PRE_ROOT_GUANGHU_SUPERVISOR", "guanghu_semantic_service_control": 100, "guanghu_final_boot_control": 0, "linux_on_demand_subcontrol": 0, "linux_rescue_preserved": 100, "final_guanghu_os_master": 0, - "next_engineering_gate": "BUILD_AND_VERIFY_JD_HOST_QEMU_PRE_ROOT_GUANGHU_SUPERVISOR_WITHOUT_BOOT_CHANGE" + "next_engineering_gate": "IMPLEMENT_AND_VERIFY_CROSS_SWITCH_ROOT_PERSISTENT_GUANGHU_SUPERVISOR_IN_ISOLATION" }, "implementation": { "guanghu_supervisor_lifecycle_contract_source": 100, @@ -72,7 +72,7 @@ "linux_code_bridge_under_guanghu_supervisor": 100, "guanghu_pre_root_supervisor_contract_source": 100, "guanghu_first_boot_initramfs_builder_source": 100, - "jd_host_qemu_pre_root_supervisor": 0, + "jd_host_qemu_pre_root_supervisor": 100, "independent_guanghu_first_boot_supervisor": 0, "jd_physical_deployment": 0 }, @@ -92,6 +92,21 @@ "final_guanghu_os_master": 0, "observed_at": "2026-08-15T22:44:59+08:00" }, + "pre_root_supervisor_qemu_evidence": { + "source_commit": "29bb023455ce245dc44dbd5e61ced92cd647e071", + "source_tree": "4e158f7aaf8700afbf5cd859cbd8f00f30c32246", + "repository_receipt": "product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/PRE-ROOT-SUPERVISOR-QEMU-RECEIPT-20260815.hldp", + "server_receipt": "/guanghu/recovery/JD-FD-PRIMARY-pre-root-qemu-af84e42/DEPLOYMENT-RECEIPT.hldp", + "server_receipt_sha256": "446d7226ac89967489785d60b5bdaa5011547e14b8c9c1d90adae8095fdab986", + "candidate_initramfs_sha256": "55d8aafc8ff413c8976e017438372ec6bc45f4f7accfb3ff2e1e570e392b2dfa", + "positive_pre_root_execution": 100, + "negative_authority_binding_hard_fail": 100, + "physical_boot_files_changed": false, + "physical_reboot_performed": false, + "cross_switch_root_persistent_supervisor": 0, + "final_guanghu_os_master": 0, + "observed_at": "2026-08-15T23:45:00+08:00" + }, "current_target_evidence": { "server_receipt": "/guanghu/recovery/JD-FD-PRIMARY-linux-subcontrol-f5217fe/DEPLOYMENT-RECEIPT.hldp", "server_receipt_sha256": "4a7d0cb354ff0472dbd8e2e43d89021d65b21f0beea3c702dcbeacdd1c73bfbc", diff --git a/routing/guanghu-os-control-architecture.test.mjs b/routing/guanghu-os-control-architecture.test.mjs index 4b62b72a6..030ae3e56 100644 --- a/routing/guanghu-os-control-architecture.test.mjs +++ b/routing/guanghu-os-control-architecture.test.mjs @@ -34,17 +34,21 @@ test("final topology makes Guanghu the master while preserving Linux as on-deman test("current JD state stays transitional and cannot impersonate final master control", () => { assert.equal( contract.jd_fd_primary.observed_state, - "LANGUAGE_PRIMARY_ON_LINUX_HOSTED_GUANGHU_SUPERVISOR_BRIDGE", + "LANGUAGE_PRIMARY_WITH_QEMU_VERIFIED_PRE_ROOT_GUANGHU_SUPERVISOR", ); assert.equal(contract.jd_fd_primary.guanghu_semantic_service_control, 100); assert.equal(contract.jd_fd_primary.guanghu_final_boot_control, 0); assert.equal(contract.jd_fd_primary.linux_on_demand_subcontrol, 0); assert.equal(contract.jd_fd_primary.linux_rescue_preserved, 100); assert.equal(contract.jd_fd_primary.final_guanghu_os_master, 0); + assert.equal( + contract.jd_fd_primary.next_engineering_gate, + "IMPLEMENT_AND_VERIFY_CROSS_SWITCH_ROOT_PERSISTENT_GUANGHU_SUPERVISOR_IN_ISOLATION", + ); }); test("the physical shadow and host QEMU cycles are registered without impersonating Guanghu-owned boot control", () => { - assert.equal(contract.version, "2026-08-15.10"); + assert.equal(contract.version, "2026-08-15.11"); assert.equal(contract.implementation.guanghu_supervisor_lifecycle_contract_source, 100); assert.equal(contract.implementation.target_readback_and_mandatory_reclaim_state_machine, 100); assert.equal(contract.implementation.declared_supervisor_core_line_and_function_coverage, 100); @@ -74,7 +78,7 @@ test("the physical shadow and host QEMU cycles are registered without impersonat assert.equal(contract.implementation.linux_code_bridge_under_guanghu_supervisor, 100); assert.equal(contract.implementation.guanghu_pre_root_supervisor_contract_source, 100); assert.equal(contract.implementation.guanghu_first_boot_initramfs_builder_source, 100); - assert.equal(contract.implementation.jd_host_qemu_pre_root_supervisor, 0); + assert.equal(contract.implementation.jd_host_qemu_pre_root_supervisor, 100); assert.equal(contract.implementation.independent_guanghu_first_boot_supervisor, 0); assert.equal(contract.implementation.jd_physical_deployment, 0); assert.equal(contract.current_target_evidence.final_state, "DORMANT"); @@ -82,6 +86,13 @@ test("the physical shadow and host QEMU cycles are registered without impersonat assert.equal(contract.native_service_qemu_evidence.native_physical_residency, 0); assert.equal(contract.native_service_qemu_evidence.public_native_service_equivalence, 0); assert.match(contract.native_service_qemu_evidence.server_receipt_sha256, /^[0-9a-f]{64}$/); + assert.equal(contract.pre_root_supervisor_qemu_evidence.positive_pre_root_execution, 100); + assert.equal(contract.pre_root_supervisor_qemu_evidence.negative_authority_binding_hard_fail, 100); + assert.equal(contract.pre_root_supervisor_qemu_evidence.physical_boot_files_changed, false); + assert.equal(contract.pre_root_supervisor_qemu_evidence.physical_reboot_performed, false); + assert.equal(contract.pre_root_supervisor_qemu_evidence.cross_switch_root_persistent_supervisor, 0); + assert.equal(contract.pre_root_supervisor_qemu_evidence.final_guanghu_os_master, 0); + assert.match(contract.pre_root_supervisor_qemu_evidence.server_receipt_sha256, /^[0-9a-f]{64}$/); assert.equal(contract.native_public_projection_shadow_evidence.synthetic_ready_shadow_readback, 100); assert.equal(contract.native_public_projection_shadow_evidence.post_test_state, "DORMANT"); assert.equal(contract.native_public_projection_shadow_evidence.live_native_freshness_readback, 0);