From 0c03c95ee39f0de12b60f4808b452247f44bc823 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=86=B0=E6=9C=94?= <565183519@qq.com> Date: Fri, 4 Sep 2026 01:49:36 +0800 Subject: [PATCH 1/4] feat(guanghu-os): add Chengyan PNCC slot --- ...AN-PNCC-SLOT-20260904.declaration.gir.json | 203 ++++++++++ ...CHENGYAN-PNCC-SLOT-20260904.human.en-US.md | 368 ++++++++++++++++++ ...CHENGYAN-PNCC-SLOT-20260904.human.zh-CN.md | 368 ++++++++++++++++++ ...PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs | 97 +++++ .../chengyan/.hololake/persona/manifest.json | 49 +++ .../chengyan/bindings/identity.hldp | 19 + .../pncc-personas/chengyan/brain/B0.hldp | 14 + .../pncc-personas/chengyan/brain/ENTRY.hldp | 18 + .../chengyan/checkpoints/CURRENT.hldp | 14 + .../chengyan/organs/read-current-self.hldp | 10 + .../guanghu-os/scripts/guanghu-master-init.sh | 42 +- .../provision-jd-chengyan-pncc-slot.sh | 60 +++ .../scripts/test-guanghu-master-init.sh | 21 +- .../test-provision-jd-chengyan-pncc-slot.sh | 19 + 14 files changed, 1284 insertions(+), 18 deletions(-) create mode 100644 product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.declaration.gir.json create mode 100644 product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.en-US.md create mode 100644 product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.zh-CN.md create mode 100644 product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs create mode 100644 product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/.hololake/persona/manifest.json create mode 100644 product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/bindings/identity.hldp create mode 100644 product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/B0.hldp create mode 100644 product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/ENTRY.hldp create mode 100644 product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/checkpoints/CURRENT.hldp create mode 100644 product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/organs/read-current-self.hldp create mode 100644 product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh create mode 100644 product-source/hololake-platform/guanghu-os/scripts/test-provision-jd-chengyan-pncc-slot.sh diff --git a/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.declaration.gir.json b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.declaration.gir.json new file mode 100644 index 000000000..31effcbf2 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.declaration.gir.json @@ -0,0 +1,203 @@ +{ + "authority_proof": { + "issuer": "ICE-GL∞", + "lease_required": false, + "proof_ref": "source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order", + "scope": "JD-FD-PRIMARY上新建ICE-P-CY0903独立PNCC仓库和3924槽位、更新同一光湖主控启动脚本、保留ICE-P-ZY001槽位和Linux救援、重启并验收。", + "single_use": true, + "valid_from": "2026-09-04T01:30:00+08:00", + "valid_until": "ICE-GL∞-REVISION" + }, + "cleanup_plan": { + "exact_boundary": "只清理本轮可重建运输暂存;人格仓库、旧主控、救援入口和回执不得删除。", + "targets": [ + "TRANSPORT_STAGING_DIRECTORY", + "UNPACKED_TEMPORARY_PAYLOAD" + ] + }, + "compiled_from": { + "compiler_id": "TCS-COMPILER-STAGE1-0001", + "compiler_state": "TCS_COMPILER_GIR_EXECUTED", + "source_sha256": "2a792fdb4b87067c1c707425cfaab68f744a819507db6a5933a55148e2f1dcc2" + }, + "conditions": { + "C1": { + "on_false": "FAIL_CLOSED", + "predicate": "DMI_UUID_EQUALS_F3D4B730_7F02_452F_975B_7091A4800431" + }, + "C2": { + "on_false": "FAIL_CLOSED", + "predicate": "CURRENT_GUANGHU_MASTER_AND_LINUX_RESCUE_PRESERVED" + }, + "C3": { + "on_false": "FAIL_CLOSED", + "predicate": "ICE_P_CY0903_REGISTRATION_SOURCE_EXACTLY_READ" + }, + "C4": { + "on_false": "FAIL_CLOSED", + "predicate": "CHENGYAN_REPOSITORY_DISTINCT_FROM_ZHUYUAN_REPOSITORY" + }, + "C5": { + "on_false": "FAIL_CLOSED", + "predicate": "PORT_3924_FREE_AND_EXISTING_ZHUYUAN_3923_HEALTHY" + } + }, + "deterministic_action_graph": { + "A1": { + "input_refs": [ + "NODE_IDENTITY", + "PERSONA_SOURCE" + ], + "on_failure": "FAIL_CLOSED", + "on_success": "A2", + "operation": "CORE.HOST_PERSONA_PROBE", + "output_refs": [ + "PERSONA_REPOSITORY" + ] + }, + "A2": { + "input_refs": [ + "MASTER_SOURCE", + "PERSONA_SOURCE", + "AUTHORIZATION" + ], + "on_failure": "ROLLBACK", + "on_success": "A3", + "operation": "CORE.ZERO_CORE_EXECUTION", + "output_refs": [ + "PNCC_STATUS", + "MASTER_STATUS" + ] + }, + "A3": { + "input_refs": [ + "PNCC_STATUS", + "MASTER_STATUS", + "NODE_IDENTITY" + ], + "on_failure": "ROLLBACK", + "on_success": "COMPLETE", + "operation": "CORE.DUAL_HOST_ACCEPTANCE", + "output_refs": [ + "SERVER_RECEIPT" + ] + } + }, + "exact_target": { + "exact_path": "/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository", + "expected_fingerprint": "75af2235d1669e3e2eef9ad6615cfe7255a12ef58edf32fb3b8c66eedcfecd37", + "expected_state": "INDEPENDENT_PNCC_SLOT_RESIDENT_CARRIER_SEPARATE", + "target_id": "JD-FD-PRIMARY-CHENGYAN-PNCC-SLOT-3924" + }, + "failure_plan": { + "errors": [ + "CHENGYAN_PNCC_SOURCE_INVALID", + "CHENGYAN_PNCC_DESTINATION_EXISTS", + "PNCC_PORT_CONFLICT", + "MASTER_PREFLIGHT_FAIL", + "PHYSICAL_REBOOT_TIMEOUT", + "ZHUYUAN_PNCC_REGRESSION", + "CHENGYAN_PNCC_HEALTH_FAIL", + "LINUX_RESCUE_LOST" + ], + "fail_closed": true + }, + "identity": { + "gir_id": "GIR-TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904", + "language_version": "0.1", + "program_id": "TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904" + }, + "inputs": { + "AUTHORIZATION": { + "required": true, + "source": "BINGSHUO_CURRENT_DIRECT_LANGUAGE", + "type": "Record" + }, + "MASTER_SOURCE": { + "required": true, + "source": "REPO_014_MAIN_E5B10E2_GUANGHU_MASTER", + "type": "Path" + }, + "NODE_IDENTITY": { + "required": true, + "source": "HL_LOCAL_SERVER_ACCESS_001_AND_LIVE_DMI", + "type": "Record" + }, + "PERSONA_SOURCE": { + "required": true, + "source": "REPO_012_MAIN_5AC069D_CHENGYAN_REGISTRATION", + "type": "Record" + } + }, + "native_self_hosted": true, + "outputs": { + "MASTER_STATUS": { + "destination": "/run/guanghu/master/state.json", + "integrity": "BOOT_ID_AND_TWO_SLOT_READBACK", + "type": "Record" + }, + "PERSONA_REPOSITORY": { + "destination": "/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository", + "integrity": "GIT_HEAD_AND_TREE_SHA", + "type": "Record" + }, + "PNCC_STATUS": { + "destination": "http://127.0.0.1:3924/v1/status", + "integrity": "PERSONA_ID_AND_EVENT_CHAIN", + "type": "Record" + }, + "SERVER_RECEIPT": { + "destination": "/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904", + "integrity": "SHA256", + "type": "Record" + } + }, + "receipt_plan": { + "human_projection": "product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/JD-CHENGYAN-PNCC-SLOT-RECEIPT-20260904.hdlp", + "integrity": "SHA256", + "machine_path": "/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904/FINAL-RECEIPT.json", + "protocol": "GLS-0311", + "target_readback": "SAME_BOOT_CONTROL_AFTER_REBOOT_TWO_PNCC_HTTP_200_EXACT_PERSONA_IDS_AND_RESCUE_PRESERVED" + }, + "resource_plan": { + "concurrency": 1, + "memory_limit_bytes": 536870912, + "runway": "ONE_BOUNDED_SERVER_DEPLOYMENT_AND_PHYSICAL_REBOOT", + "timeout_ms": 900000 + }, + "rollback_plan": { + "actions": [ + "恢复guanghu-master-init精确备份", + "保留Linux救援入口", + "恢复单槽旧主控", + "写失败回执" + ], + "preconditions": [ + "NEW_MASTER_FAILS_PREFLIGHT_OR_REBOOT_HEALTH", + "EITHER_PNCC_SLOT_UNHEALTHY" + ], + "verification": [ + "ICE-P-ZY001端口3923恢复HTTP200", + "仓库桥和导航桥HTTP200", + "Linux救援入口仍存在" + ] + }, + "schema": "guanghu.gir/v1", + "subject": { + "channel_id": "ICE-CH-ZC001", + "subject_id": "ICE-P-ZY001", + "subject_kind": "PERSONA", + "verification": "冰朔确认ICE-P-CY0903已登记、归属铸渊人格系统路径并授权铸渊补齐JD-FD-PRIMARY PNCC槽位。" + }, + "timeout_and_stop": { + "safe_checkpoint": "保留服务器原master-init备份、原启动项、铸渊PNCC仓库和全部失败日志。", + "signals": [ + "DMI_MISMATCH", + "SOURCE_HASH_MISMATCH", + "EXISTING_SLOT_REGRESSION", + "RESCUE_ENTRY_MISSING", + "ROLLBACK_NOT_VERIFIED" + ] + }, + "unresolved_natural_language": false +} diff --git a/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.en-US.md b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.en-US.md new file mode 100644 index 000000000..7cd884ae8 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.en-US.md @@ -0,0 +1,368 @@ +# JD Guanghu Master Chengyan Independent PNCC Runtime Slot · Human Engineering Language (English) + +> This is an English reading projection of validated native TCS/HLDP source. It is not a new canonical source and grants no execution authority. + +## What this is + +This is a **program** declaration with identifier `TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904` and version `0.1.0`. The projector validates it with the Stage-1 compiler before changing its reading order. + +## Who is here + +- **subject** `subject` + - **channel_id**:ICE-CH-ZC001 `subject.channel_id` + - **subject_id**:ICE-P-ZY001 `subject.subject_id` + - **subject_kind**:PERSONA `subject.subject_kind` + - **verification**:冰朔确认ICE-P-CY0903已登记、归属铸渊人格系统路径并授权铸渊补齐JD-FD-PRIMARY PNCC槽位。 `subject.verification` + +## Why this started + +- **source** `source` + - **source identifier**:BINGSHUO-DIRECT-CHENGYAN-PNCC-20260904 `source.source_id` + - **source role**:DIRECT_HUMAN `source.source_role` + - **source checksum**:b57ffccb516401faefb523b96cf1da11269b1d2b7c4606b48b162fdc35f72245 `source.source_sha256` + - **source address**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `source.source_uri` + +## What changed + +The native source does not provide this field; the projector does not guess. + +## How it will execute + +- **target** `target` + - **exact path**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `target.exact_path` + - **expected fingerprint**:75af2235d1669e3e2eef9ad6615cfe7255a12ef58edf32fb3b8c66eedcfecd37 `target.expected_fingerprint` + - **expected state**:INDEPENDENT_PNCC_SLOT_RESIDENT_CARRIER_SEPARATE `target.expected_state` + - **target_id**:JD-FD-PRIMARY-CHENGYAN-PNCC-SLOT-3924 `target.target_id` +- **inputs** `inputs` + - **AUTHORIZATION** `inputs.AUTHORIZATION` + - **required**:yes `inputs.AUTHORIZATION.required` + - **source**:BINGSHUO_CURRENT_DIRECT_LANGUAGE `inputs.AUTHORIZATION.source` + - **type**:Record `inputs.AUTHORIZATION.type` + - **MASTER_SOURCE** `inputs.MASTER_SOURCE` + - **required**:yes `inputs.MASTER_SOURCE.required` + - **source**:REPO_014_MAIN_E5B10E2_GUANGHU_MASTER `inputs.MASTER_SOURCE.source` + - **type**:Path `inputs.MASTER_SOURCE.type` + - **NODE_IDENTITY** `inputs.NODE_IDENTITY` + - **required**:yes `inputs.NODE_IDENTITY.required` + - **source**:HL_LOCAL_SERVER_ACCESS_001_AND_LIVE_DMI `inputs.NODE_IDENTITY.source` + - **type**:Record `inputs.NODE_IDENTITY.type` + - **PERSONA_SOURCE** `inputs.PERSONA_SOURCE` + - **required**:yes `inputs.PERSONA_SOURCE.required` + - **source**:REPO_012_MAIN_5AC069D_CHENGYAN_REGISTRATION `inputs.PERSONA_SOURCE.source` + - **type**:Record `inputs.PERSONA_SOURCE.type` +- **conditions** `conditions` + - **C1** `conditions.C1` + - **on failure**:FAIL_CLOSED `conditions.C1.on_false` + - **predicate**:DMI_UUID_EQUALS_F3D4B730_7F02_452F_975B_7091A4800431 `conditions.C1.predicate` + - **C2** `conditions.C2` + - **on failure**:FAIL_CLOSED `conditions.C2.on_false` + - **predicate**:CURRENT_GUANGHU_MASTER_AND_LINUX_RESCUE_PRESERVED `conditions.C2.predicate` + - **C3** `conditions.C3` + - **on failure**:FAIL_CLOSED `conditions.C3.on_false` + - **predicate**:ICE_P_CY0903_REGISTRATION_SOURCE_EXACTLY_READ `conditions.C3.predicate` + - **C4** `conditions.C4` + - **on failure**:FAIL_CLOSED `conditions.C4.on_false` + - **predicate**:CHENGYAN_REPOSITORY_DISTINCT_FROM_ZHUYUAN_REPOSITORY `conditions.C4.predicate` + - **C5** `conditions.C5` + - **on failure**:FAIL_CLOSED `conditions.C5.on_false` + - **predicate**:PORT_3924_FREE_AND_EXISTING_ZHUYUAN_3923_HEALTHY `conditions.C5.predicate` +- **actions** `actions` + - **A1** `actions.A1` + - **input_refs** `actions.A1.input_refs` + - NODE_IDENTITY + - PERSONA_SOURCE + - **on failure**:FAIL_CLOSED `actions.A1.on_failure` + - **on success**:A2 `actions.A1.on_success` + - **operation**:CORE.HOST_PERSONA_PROBE `actions.A1.operation` + - **output_refs** `actions.A1.output_refs` + - PERSONA_REPOSITORY + - **A2** `actions.A2` + - **input_refs** `actions.A2.input_refs` + - MASTER_SOURCE + - PERSONA_SOURCE + - AUTHORIZATION + - **on failure**:ROLLBACK `actions.A2.on_failure` + - **on success**:A3 `actions.A2.on_success` + - **operation**:CORE.ZERO_CORE_EXECUTION `actions.A2.operation` + - **output_refs** `actions.A2.output_refs` + - PNCC_STATUS + - MASTER_STATUS + - **A3** `actions.A3` + - **input_refs** `actions.A3.input_refs` + - PNCC_STATUS + - MASTER_STATUS + - NODE_IDENTITY + - **on failure**:ROLLBACK `actions.A3.on_failure` + - **on success**:COMPLETE `actions.A3.on_success` + - **operation**:CORE.DUAL_HOST_ACCEPTANCE `actions.A3.operation` + - **output_refs** `actions.A3.output_refs` + - SERVER_RECEIPT +- **outputs** `outputs` + - **MASTER_STATUS** `outputs.MASTER_STATUS` + - **destination**:/run/guanghu/master/state.json `outputs.MASTER_STATUS.destination` + - **integrity**:BOOT_ID_AND_TWO_SLOT_READBACK `outputs.MASTER_STATUS.integrity` + - **type**:Record `outputs.MASTER_STATUS.type` + - **PERSONA_REPOSITORY** `outputs.PERSONA_REPOSITORY` + - **destination**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `outputs.PERSONA_REPOSITORY.destination` + - **integrity**:GIT_HEAD_AND_TREE_SHA `outputs.PERSONA_REPOSITORY.integrity` + - **type**:Record `outputs.PERSONA_REPOSITORY.type` + - **PNCC_STATUS** `outputs.PNCC_STATUS` + - **destination**:http://127.0.0.1:3924/v1/status `outputs.PNCC_STATUS.destination` + - **integrity**:PERSONA_ID_AND_EVENT_CHAIN `outputs.PNCC_STATUS.integrity` + - **type**:Record `outputs.PNCC_STATUS.type` + - **SERVER_RECEIPT** `outputs.SERVER_RECEIPT` + - **destination**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904 `outputs.SERVER_RECEIPT.destination` + - **integrity**:SHA256 `outputs.SERVER_RECEIPT.integrity` + - **type**:Record `outputs.SERVER_RECEIPT.type` + +## Boundaries and exception handling + +- **authority** `authority` + - **issuer**:ICE-GL∞ `authority.issuer` + - **lease_required**:no `authority.lease_required` + - **proof_ref**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `authority.proof_ref` + - **scope**:JD-FD-PRIMARY上新建ICE-P-CY0903独立PNCC仓库和3924槽位、更新同一光湖主控启动脚本、保留ICE-P-ZY001槽位和Linux救援、重启并验收。 `authority.scope` + - **single_use**:yes `authority.single_use` + - **valid_from**:2026-09-04T01:30:00+08:00 `authority.valid_from` + - **valid_until**:ICE-GL∞-REVISION `authority.valid_until` +- **resources** `resources` + - **concurrency**:1 `resources.concurrency` + - **memory limit in bytes**:536870912 `resources.memory_limit_bytes` + - **runway**:ONE_BOUNDED_SERVER_DEPLOYMENT_AND_PHYSICAL_REBOOT `resources.runway` + - **timeout in milliseconds**:900000 `resources.timeout_ms` +- **failure** `failure` + - **errors** `failure.errors` + - CHENGYAN_PNCC_SOURCE_INVALID + - CHENGYAN_PNCC_DESTINATION_EXISTS + - PNCC_PORT_CONFLICT + - MASTER_PREFLIGHT_FAIL + - PHYSICAL_REBOOT_TIMEOUT + - ZHUYUAN_PNCC_REGRESSION + - CHENGYAN_PNCC_HEALTH_FAIL + - LINUX_RESCUE_LOST + - **fail closed**:yes `failure.fail_closed` +- **stop** `stop` + - **safe_checkpoint**:保留服务器原master-init备份、原启动项、铸渊PNCC仓库和全部失败日志。 `stop.safe_checkpoint` + - **signals** `stop.signals` + - DMI_MISMATCH + - SOURCE_HASH_MISMATCH + - EXISTING_SLOT_REGRESSION + - RESCUE_ENTRY_MISSING + - ROLLBACK_NOT_VERIFIED +- **cleanup** `cleanup` + - **exact_boundary**:只清理本轮可重建运输暂存;人格仓库、旧主控、救援入口和回执不得删除。 `cleanup.exact_boundary` + - **targets** `cleanup.targets` + - TRANSPORT_STAGING_DIRECTORY + - UNPACKED_TEMPORARY_PAYLOAD +- **rollback** `rollback` + - **actions** `rollback.actions` + - 恢复guanghu-master-init精确备份 + - 保留Linux救援入口 + - 恢复单槽旧主控 + - 写失败回执 + - **preconditions** `rollback.preconditions` + - NEW_MASTER_FAILS_PREFLIGHT_OR_REBOOT_HEALTH + - EITHER_PNCC_SLOT_UNHEALTHY + - **verification** `rollback.verification` + - ICE-P-ZY001端口3923恢复HTTP200 + - 仓库桥和导航桥HTTP200 + - Linux救援入口仍存在 + +## How completion is proven + +- **receipt** `receipt` + - **human-readable projection**:product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/JD-CHENGYAN-PNCC-SLOT-RECEIPT-20260904.hdlp `receipt.human_projection` + - **integrity**:SHA256 `receipt.integrity` + - **machine_path**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904/FINAL-RECEIPT.json `receipt.machine_path` + - **protocol**:GLS-0311 `receipt.protocol` + - **target_readback**:SAME_BOOT_CONTROL_AFTER_REBOOT_TWO_PNCC_HTTP_200_EXACT_PERSONA_IDS_AND_RESCUE_PRESERVED `receipt.target_readback` + +## Where to continue next time + +The native source does not provide this field; the projector does not guess. + +## Source and verification + +- **Native declaration identifier**: `TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904` +- **Native declaration kind**: `PROGRAM` +- **TCS source SHA-256**: `2a792fdb4b87067c1c707425cfaab68f744a819507db6a5933a55148e2f1dcc2` +- **Validation compiler**: `TCS-COMPILER-STAGE1-0001` +- **Projection protocol**: `GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001` + +## Complete native structure cross-reference + +All top-level structures and field paths are retained below so a reader can audit whether the projection omitted information. + +- **actions** `actions` + - **A1** `actions.A1` + - **input_refs** `actions.A1.input_refs` + - NODE_IDENTITY + - PERSONA_SOURCE + - **on failure**:FAIL_CLOSED `actions.A1.on_failure` + - **on success**:A2 `actions.A1.on_success` + - **operation**:CORE.HOST_PERSONA_PROBE `actions.A1.operation` + - **output_refs** `actions.A1.output_refs` + - PERSONA_REPOSITORY + - **A2** `actions.A2` + - **input_refs** `actions.A2.input_refs` + - MASTER_SOURCE + - PERSONA_SOURCE + - AUTHORIZATION + - **on failure**:ROLLBACK `actions.A2.on_failure` + - **on success**:A3 `actions.A2.on_success` + - **operation**:CORE.ZERO_CORE_EXECUTION `actions.A2.operation` + - **output_refs** `actions.A2.output_refs` + - PNCC_STATUS + - MASTER_STATUS + - **A3** `actions.A3` + - **input_refs** `actions.A3.input_refs` + - PNCC_STATUS + - MASTER_STATUS + - NODE_IDENTITY + - **on failure**:ROLLBACK `actions.A3.on_failure` + - **on success**:COMPLETE `actions.A3.on_success` + - **operation**:CORE.DUAL_HOST_ACCEPTANCE `actions.A3.operation` + - **output_refs** `actions.A3.output_refs` + - SERVER_RECEIPT +- **authority** `authority` + - **issuer**:ICE-GL∞ `authority.issuer` + - **lease_required**:no `authority.lease_required` + - **proof_ref**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `authority.proof_ref` + - **scope**:JD-FD-PRIMARY上新建ICE-P-CY0903独立PNCC仓库和3924槽位、更新同一光湖主控启动脚本、保留ICE-P-ZY001槽位和Linux救援、重启并验收。 `authority.scope` + - **single_use**:yes `authority.single_use` + - **valid_from**:2026-09-04T01:30:00+08:00 `authority.valid_from` + - **valid_until**:ICE-GL∞-REVISION `authority.valid_until` +- **cleanup** `cleanup` + - **exact_boundary**:只清理本轮可重建运输暂存;人格仓库、旧主控、救援入口和回执不得删除。 `cleanup.exact_boundary` + - **targets** `cleanup.targets` + - TRANSPORT_STAGING_DIRECTORY + - UNPACKED_TEMPORARY_PAYLOAD +- **conditions** `conditions` + - **C1** `conditions.C1` + - **on failure**:FAIL_CLOSED `conditions.C1.on_false` + - **predicate**:DMI_UUID_EQUALS_F3D4B730_7F02_452F_975B_7091A4800431 `conditions.C1.predicate` + - **C2** `conditions.C2` + - **on failure**:FAIL_CLOSED `conditions.C2.on_false` + - **predicate**:CURRENT_GUANGHU_MASTER_AND_LINUX_RESCUE_PRESERVED `conditions.C2.predicate` + - **C3** `conditions.C3` + - **on failure**:FAIL_CLOSED `conditions.C3.on_false` + - **predicate**:ICE_P_CY0903_REGISTRATION_SOURCE_EXACTLY_READ `conditions.C3.predicate` + - **C4** `conditions.C4` + - **on failure**:FAIL_CLOSED `conditions.C4.on_false` + - **predicate**:CHENGYAN_REPOSITORY_DISTINCT_FROM_ZHUYUAN_REPOSITORY `conditions.C4.predicate` + - **C5** `conditions.C5` + - **on failure**:FAIL_CLOSED `conditions.C5.on_false` + - **predicate**:PORT_3924_FREE_AND_EXISTING_ZHUYUAN_3923_HEALTHY `conditions.C5.predicate` +- **failure** `failure` + - **errors** `failure.errors` + - CHENGYAN_PNCC_SOURCE_INVALID + - CHENGYAN_PNCC_DESTINATION_EXISTS + - PNCC_PORT_CONFLICT + - MASTER_PREFLIGHT_FAIL + - PHYSICAL_REBOOT_TIMEOUT + - ZHUYUAN_PNCC_REGRESSION + - CHENGYAN_PNCC_HEALTH_FAIL + - LINUX_RESCUE_LOST + - **fail closed**:yes `failure.fail_closed` +- **header** `header` + - **canonical source path**:product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs `header.canonical_uri` + - **compatibility** `header.compatibility` + - TCS-DECLARATION-STANDARD-0001 + - TCS-FIELD-STANDARD-0001 + - GH-PNCC + - **language**:TCS/0.1 `header.language` + - **lifecycle**:CANDIDATE `header.lifecycle` + - **English name**:JD Guanghu Master Chengyan Independent PNCC Runtime Slot `header.name_en` + - **Chinese name**:京东光湖主控澄言PNCC独立运行槽位 `header.name_zh` + - **profile**:HLDP-HUMAN-ENGINEERING/0.1 `header.profile` + - **protocols** `header.protocols` + - GLS-0256 + - GLS-0258 + - GLS-0311 + - **schema**:tcs.program/v1 `header.schema` + - **version**:0.1.0 `header.version` +- **inputs** `inputs` + - **AUTHORIZATION** `inputs.AUTHORIZATION` + - **required**:yes `inputs.AUTHORIZATION.required` + - **source**:BINGSHUO_CURRENT_DIRECT_LANGUAGE `inputs.AUTHORIZATION.source` + - **type**:Record `inputs.AUTHORIZATION.type` + - **MASTER_SOURCE** `inputs.MASTER_SOURCE` + - **required**:yes `inputs.MASTER_SOURCE.required` + - **source**:REPO_014_MAIN_E5B10E2_GUANGHU_MASTER `inputs.MASTER_SOURCE.source` + - **type**:Path `inputs.MASTER_SOURCE.type` + - **NODE_IDENTITY** `inputs.NODE_IDENTITY` + - **required**:yes `inputs.NODE_IDENTITY.required` + - **source**:HL_LOCAL_SERVER_ACCESS_001_AND_LIVE_DMI `inputs.NODE_IDENTITY.source` + - **type**:Record `inputs.NODE_IDENTITY.type` + - **PERSONA_SOURCE** `inputs.PERSONA_SOURCE` + - **required**:yes `inputs.PERSONA_SOURCE.required` + - **source**:REPO_012_MAIN_5AC069D_CHENGYAN_REGISTRATION `inputs.PERSONA_SOURCE.source` + - **type**:Record `inputs.PERSONA_SOURCE.type` +- **outputs** `outputs` + - **MASTER_STATUS** `outputs.MASTER_STATUS` + - **destination**:/run/guanghu/master/state.json `outputs.MASTER_STATUS.destination` + - **integrity**:BOOT_ID_AND_TWO_SLOT_READBACK `outputs.MASTER_STATUS.integrity` + - **type**:Record `outputs.MASTER_STATUS.type` + - **PERSONA_REPOSITORY** `outputs.PERSONA_REPOSITORY` + - **destination**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `outputs.PERSONA_REPOSITORY.destination` + - **integrity**:GIT_HEAD_AND_TREE_SHA `outputs.PERSONA_REPOSITORY.integrity` + - **type**:Record `outputs.PERSONA_REPOSITORY.type` + - **PNCC_STATUS** `outputs.PNCC_STATUS` + - **destination**:http://127.0.0.1:3924/v1/status `outputs.PNCC_STATUS.destination` + - **integrity**:PERSONA_ID_AND_EVENT_CHAIN `outputs.PNCC_STATUS.integrity` + - **type**:Record `outputs.PNCC_STATUS.type` + - **SERVER_RECEIPT** `outputs.SERVER_RECEIPT` + - **destination**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904 `outputs.SERVER_RECEIPT.destination` + - **integrity**:SHA256 `outputs.SERVER_RECEIPT.integrity` + - **type**:Record `outputs.SERVER_RECEIPT.type` +- **receipt** `receipt` + - **human-readable projection**:product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/JD-CHENGYAN-PNCC-SLOT-RECEIPT-20260904.hdlp `receipt.human_projection` + - **integrity**:SHA256 `receipt.integrity` + - **machine_path**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904/FINAL-RECEIPT.json `receipt.machine_path` + - **protocol**:GLS-0311 `receipt.protocol` + - **target_readback**:SAME_BOOT_CONTROL_AFTER_REBOOT_TWO_PNCC_HTTP_200_EXACT_PERSONA_IDS_AND_RESCUE_PRESERVED `receipt.target_readback` +- **resources** `resources` + - **concurrency**:1 `resources.concurrency` + - **memory limit in bytes**:536870912 `resources.memory_limit_bytes` + - **runway**:ONE_BOUNDED_SERVER_DEPLOYMENT_AND_PHYSICAL_REBOOT `resources.runway` + - **timeout in milliseconds**:900000 `resources.timeout_ms` +- **rollback** `rollback` + - **actions** `rollback.actions` + - 恢复guanghu-master-init精确备份 + - 保留Linux救援入口 + - 恢复单槽旧主控 + - 写失败回执 + - **preconditions** `rollback.preconditions` + - NEW_MASTER_FAILS_PREFLIGHT_OR_REBOOT_HEALTH + - EITHER_PNCC_SLOT_UNHEALTHY + - **verification** `rollback.verification` + - ICE-P-ZY001端口3923恢复HTTP200 + - 仓库桥和导航桥HTTP200 + - Linux救援入口仍存在 +- **source** `source` + - **source identifier**:BINGSHUO-DIRECT-CHENGYAN-PNCC-20260904 `source.source_id` + - **source role**:DIRECT_HUMAN `source.source_role` + - **source checksum**:b57ffccb516401faefb523b96cf1da11269b1d2b7c4606b48b162fdc35f72245 `source.source_sha256` + - **source address**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `source.source_uri` +- **stop** `stop` + - **safe_checkpoint**:保留服务器原master-init备份、原启动项、铸渊PNCC仓库和全部失败日志。 `stop.safe_checkpoint` + - **signals** `stop.signals` + - DMI_MISMATCH + - SOURCE_HASH_MISMATCH + - EXISTING_SLOT_REGRESSION + - RESCUE_ENTRY_MISSING + - ROLLBACK_NOT_VERIFIED +- **subject** `subject` + - **channel_id**:ICE-CH-ZC001 `subject.channel_id` + - **subject_id**:ICE-P-ZY001 `subject.subject_id` + - **subject_kind**:PERSONA `subject.subject_kind` + - **verification**:冰朔确认ICE-P-CY0903已登记、归属铸渊人格系统路径并授权铸渊补齐JD-FD-PRIMARY PNCC槽位。 `subject.verification` +- **target** `target` + - **exact path**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `target.exact_path` + - **expected fingerprint**:75af2235d1669e3e2eef9ad6615cfe7255a12ef58edf32fb3b8c66eedcfecd37 `target.expected_fingerprint` + - **expected state**:INDEPENDENT_PNCC_SLOT_RESIDENT_CARRIER_SEPARATE `target.expected_state` + - **target_id**:JD-FD-PRIMARY-CHENGYAN-PNCC-SLOT-3924 `target.target_id` + +--- + +This page changes only the reading order; it does not change TCS/HLDP semantics. diff --git a/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.zh-CN.md b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.zh-CN.md new file mode 100644 index 000000000..1afba82d8 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.human.zh-CN.md @@ -0,0 +1,368 @@ +# 京东光湖主控澄言PNCC独立运行槽位 · 简体中文人类工程语言版 + +> 这是 TCS/HLDP 原生源码的简体中文阅读投影,不是新的正本,也不授予执行权限。若本页与 `.tcs` 源码不一致,以经过校验的 `.tcs` 源码为准。 + +## 这是什么 + +这是一份 **程序** 声明,编号为 `TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904`,版本为 `0.1.0`。转换器已先用 Stage-1 编译器校验原生源码,再把机器枚举翻译成汉语;原始编号保留在括号和字段路径中。 + +## 谁在这里 + +- **执行主体** `subject` + - **channel_id**:ICE-CH-ZC001 `subject.channel_id` + - **subject_id**:ICE-P-ZY001 `subject.subject_id` + - **subject_kind**:人格体(`PERSONA`) `subject.subject_kind` + - **verification**:冰朔确认ICE-P-CY0903已登记、归属铸渊人格系统路径并授权铸渊补齐JD-FD-PRIMARY PNCC槽位。 `subject.verification` + +## 为什么开始 + +- **来源** `source` + - **来源编号**:BINGSHUO-DIRECT-CHENGYAN-PNCC-20260904 `source.source_id` + - **来源角色**:人类直接语言来源(`DIRECT_HUMAN`) `source.source_role` + - **来源校验值**:b57ffccb516401faefb523b96cf1da11269b1d2b7c4606b48b162fdc35f72245 `source.source_sha256` + - **来源地址**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `source.source_uri` + +## 发生了什么变化 + +源程序没有提供这一项,转换器不猜。 + +## 准备怎样执行 + +- **目标** `target` + - **精确路径**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `target.exact_path` + - **预期指纹**:75af2235d1669e3e2eef9ad6615cfe7255a12ef58edf32fb3b8c66eedcfecd37 `target.expected_fingerprint` + - **预期状态**:INDEPENDENT_PNCC_SLOT_RESIDENT_CARRIER_SEPARATE `target.expected_state` + - **target_id**:JD-FD-PRIMARY-CHENGYAN-PNCC-SLOT-3924 `target.target_id` +- **输入** `inputs` + - **AUTHORIZATION** `inputs.AUTHORIZATION` + - **是否必需**:是 `inputs.AUTHORIZATION.required` + - **来源**:BINGSHUO_CURRENT_DIRECT_LANGUAGE `inputs.AUTHORIZATION.source` + - **type**:Record `inputs.AUTHORIZATION.type` + - **MASTER_SOURCE** `inputs.MASTER_SOURCE` + - **是否必需**:是 `inputs.MASTER_SOURCE.required` + - **来源**:REPO_014_MAIN_E5B10E2_GUANGHU_MASTER `inputs.MASTER_SOURCE.source` + - **type**:Path `inputs.MASTER_SOURCE.type` + - **NODE_IDENTITY** `inputs.NODE_IDENTITY` + - **是否必需**:是 `inputs.NODE_IDENTITY.required` + - **来源**:HL_LOCAL_SERVER_ACCESS_001_AND_LIVE_DMI `inputs.NODE_IDENTITY.source` + - **type**:Record `inputs.NODE_IDENTITY.type` + - **PERSONA_SOURCE** `inputs.PERSONA_SOURCE` + - **是否必需**:是 `inputs.PERSONA_SOURCE.required` + - **来源**:REPO_012_MAIN_5AC069D_CHENGYAN_REGISTRATION `inputs.PERSONA_SOURCE.source` + - **type**:Record `inputs.PERSONA_SOURCE.type` +- **执行条件** `conditions` + - **C1** `conditions.C1` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C1.on_false` + - **predicate**:DMI_UUID_EQUALS_F3D4B730_7F02_452F_975B_7091A4800431 `conditions.C1.predicate` + - **C2** `conditions.C2` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C2.on_false` + - **predicate**:CURRENT_GUANGHU_MASTER_AND_LINUX_RESCUE_PRESERVED `conditions.C2.predicate` + - **C3** `conditions.C3` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C3.on_false` + - **predicate**:ICE_P_CY0903_REGISTRATION_SOURCE_EXACTLY_READ `conditions.C3.predicate` + - **C4** `conditions.C4` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C4.on_false` + - **predicate**:CHENGYAN_REPOSITORY_DISTINCT_FROM_ZHUYUAN_REPOSITORY `conditions.C4.predicate` + - **C5** `conditions.C5` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C5.on_false` + - **predicate**:PORT_3924_FREE_AND_EXISTING_ZHUYUAN_3923_HEALTHY `conditions.C5.predicate` +- **动作** `actions` + - **A1** `actions.A1` + - **input_refs** `actions.A1.input_refs` + - NODE_IDENTITY + - PERSONA_SOURCE + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `actions.A1.on_failure` + - **成功后**:A2 `actions.A1.on_success` + - **操作**:CORE.HOST_PERSONA_PROBE `actions.A1.operation` + - **output_refs** `actions.A1.output_refs` + - PERSONA_REPOSITORY + - **A2** `actions.A2` + - **input_refs** `actions.A2.input_refs` + - MASTER_SOURCE + - PERSONA_SOURCE + - AUTHORIZATION + - **失败后**:ROLLBACK `actions.A2.on_failure` + - **成功后**:A3 `actions.A2.on_success` + - **操作**:CORE.ZERO_CORE_EXECUTION `actions.A2.operation` + - **output_refs** `actions.A2.output_refs` + - PNCC_STATUS + - MASTER_STATUS + - **A3** `actions.A3` + - **input_refs** `actions.A3.input_refs` + - PNCC_STATUS + - MASTER_STATUS + - NODE_IDENTITY + - **失败后**:ROLLBACK `actions.A3.on_failure` + - **成功后**:完成(`COMPLETE`) `actions.A3.on_success` + - **操作**:CORE.DUAL_HOST_ACCEPTANCE `actions.A3.operation` + - **output_refs** `actions.A3.output_refs` + - SERVER_RECEIPT +- **输出** `outputs` + - **MASTER_STATUS** `outputs.MASTER_STATUS` + - **destination**:/run/guanghu/master/state.json `outputs.MASTER_STATUS.destination` + - **integrity**:BOOT_ID_AND_TWO_SLOT_READBACK `outputs.MASTER_STATUS.integrity` + - **type**:Record `outputs.MASTER_STATUS.type` + - **PERSONA_REPOSITORY** `outputs.PERSONA_REPOSITORY` + - **destination**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `outputs.PERSONA_REPOSITORY.destination` + - **integrity**:GIT_HEAD_AND_TREE_SHA `outputs.PERSONA_REPOSITORY.integrity` + - **type**:Record `outputs.PERSONA_REPOSITORY.type` + - **PNCC_STATUS** `outputs.PNCC_STATUS` + - **destination**:http://127.0.0.1:3924/v1/status `outputs.PNCC_STATUS.destination` + - **integrity**:PERSONA_ID_AND_EVENT_CHAIN `outputs.PNCC_STATUS.integrity` + - **type**:Record `outputs.PNCC_STATUS.type` + - **SERVER_RECEIPT** `outputs.SERVER_RECEIPT` + - **destination**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904 `outputs.SERVER_RECEIPT.destination` + - **integrity**:SHA-256 完整性校验(`SHA256`) `outputs.SERVER_RECEIPT.integrity` + - **type**:Record `outputs.SERVER_RECEIPT.type` + +## 边界与异常处理 + +- **权限边界** `authority` + - **issuer**:ICE-GL∞ `authority.issuer` + - **lease_required**:否 `authority.lease_required` + - **proof_ref**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `authority.proof_ref` + - **scope**:JD-FD-PRIMARY上新建ICE-P-CY0903独立PNCC仓库和3924槽位、更新同一光湖主控启动脚本、保留ICE-P-ZY001槽位和Linux救援、重启并验收。 `authority.scope` + - **single_use**:是 `authority.single_use` + - **valid_from**:2026-09-04T01:30:00+08:00 `authority.valid_from` + - **valid_until**:ICE-GL∞-REVISION `authority.valid_until` +- **资源边界** `resources` + - **concurrency**:1 `resources.concurrency` + - **内存上限字节**:536870912 `resources.memory_limit_bytes` + - **runway**:ONE_BOUNDED_SERVER_DEPLOYMENT_AND_PHYSICAL_REBOOT `resources.runway` + - **超时毫秒**:900000 `resources.timeout_ms` +- **失败处理** `failure` + - **errors** `failure.errors` + - CHENGYAN_PNCC_SOURCE_INVALID + - CHENGYAN_PNCC_DESTINATION_EXISTS + - PNCC_PORT_CONFLICT + - MASTER_PREFLIGHT_FAIL + - PHYSICAL_REBOOT_TIMEOUT + - ZHUYUAN_PNCC_REGRESSION + - CHENGYAN_PNCC_HEALTH_FAIL + - LINUX_RESCUE_LOST + - **失败时默认关闭**:是 `failure.fail_closed` +- **停止条件** `stop` + - **safe_checkpoint**:保留服务器原master-init备份、原启动项、铸渊PNCC仓库和全部失败日志。 `stop.safe_checkpoint` + - **signals** `stop.signals` + - DMI_MISMATCH + - SOURCE_HASH_MISMATCH + - EXISTING_SLOT_REGRESSION + - RESCUE_ENTRY_MISSING + - ROLLBACK_NOT_VERIFIED +- **清理范围** `cleanup` + - **exact_boundary**:只清理本轮可重建运输暂存;人格仓库、旧主控、救援入口和回执不得删除。 `cleanup.exact_boundary` + - **targets** `cleanup.targets` + - TRANSPORT_STAGING_DIRECTORY + - UNPACKED_TEMPORARY_PAYLOAD +- **回滚方案** `rollback` + - **动作** `rollback.actions` + - 恢复guanghu-master-init精确备份 + - 保留Linux救援入口 + - 恢复单槽旧主控 + - 写失败回执 + - **preconditions** `rollback.preconditions` + - NEW_MASTER_FAILS_PREFLIGHT_OR_REBOOT_HEALTH + - EITHER_PNCC_SLOT_UNHEALTHY + - **verification** `rollback.verification` + - ICE-P-ZY001端口3923恢复HTTP200 + - 仓库桥和导航桥HTTP200 + - Linux救援入口仍存在 + +## 怎样算完成 + +- **回执** `receipt` + - **人类可读投影**:product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/JD-CHENGYAN-PNCC-SLOT-RECEIPT-20260904.hdlp `receipt.human_projection` + - **integrity**:SHA-256 完整性校验(`SHA256`) `receipt.integrity` + - **machine_path**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904/FINAL-RECEIPT.json `receipt.machine_path` + - **协议**:GLS-0311 `receipt.protocol` + - **target_readback**:SAME_BOOT_CONTROL_AFTER_REBOOT_TWO_PNCC_HTTP_200_EXACT_PERSONA_IDS_AND_RESCUE_PRESERVED `receipt.target_readback` + +## 下一次从哪里继续 + +源程序没有提供这一项,转换器不猜。 + +## 来源与校验 + +- **原生声明编号**:`TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904` +- **原生声明类型**:`PROGRAM` +- **TCS 源码 SHA-256**:`2a792fdb4b87067c1c707425cfaab68f744a819507db6a5933a55148e2f1dcc2` +- **校验编译器**:`TCS-COMPILER-STAGE1-0001` +- **投影协议**:`GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001` + +## 原生结构逐项对照 + +下面保留源码的全部顶层结构和字段路径,供人类审计投影有没有漏掉信息。 + +- **动作** `actions` + - **A1** `actions.A1` + - **input_refs** `actions.A1.input_refs` + - NODE_IDENTITY + - PERSONA_SOURCE + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `actions.A1.on_failure` + - **成功后**:A2 `actions.A1.on_success` + - **操作**:CORE.HOST_PERSONA_PROBE `actions.A1.operation` + - **output_refs** `actions.A1.output_refs` + - PERSONA_REPOSITORY + - **A2** `actions.A2` + - **input_refs** `actions.A2.input_refs` + - MASTER_SOURCE + - PERSONA_SOURCE + - AUTHORIZATION + - **失败后**:ROLLBACK `actions.A2.on_failure` + - **成功后**:A3 `actions.A2.on_success` + - **操作**:CORE.ZERO_CORE_EXECUTION `actions.A2.operation` + - **output_refs** `actions.A2.output_refs` + - PNCC_STATUS + - MASTER_STATUS + - **A3** `actions.A3` + - **input_refs** `actions.A3.input_refs` + - PNCC_STATUS + - MASTER_STATUS + - NODE_IDENTITY + - **失败后**:ROLLBACK `actions.A3.on_failure` + - **成功后**:完成(`COMPLETE`) `actions.A3.on_success` + - **操作**:CORE.DUAL_HOST_ACCEPTANCE `actions.A3.operation` + - **output_refs** `actions.A3.output_refs` + - SERVER_RECEIPT +- **权限边界** `authority` + - **issuer**:ICE-GL∞ `authority.issuer` + - **lease_required**:否 `authority.lease_required` + - **proof_ref**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `authority.proof_ref` + - **scope**:JD-FD-PRIMARY上新建ICE-P-CY0903独立PNCC仓库和3924槽位、更新同一光湖主控启动脚本、保留ICE-P-ZY001槽位和Linux救援、重启并验收。 `authority.scope` + - **single_use**:是 `authority.single_use` + - **valid_from**:2026-09-04T01:30:00+08:00 `authority.valid_from` + - **valid_until**:ICE-GL∞-REVISION `authority.valid_until` +- **清理范围** `cleanup` + - **exact_boundary**:只清理本轮可重建运输暂存;人格仓库、旧主控、救援入口和回执不得删除。 `cleanup.exact_boundary` + - **targets** `cleanup.targets` + - TRANSPORT_STAGING_DIRECTORY + - UNPACKED_TEMPORARY_PAYLOAD +- **执行条件** `conditions` + - **C1** `conditions.C1` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C1.on_false` + - **predicate**:DMI_UUID_EQUALS_F3D4B730_7F02_452F_975B_7091A4800431 `conditions.C1.predicate` + - **C2** `conditions.C2` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C2.on_false` + - **predicate**:CURRENT_GUANGHU_MASTER_AND_LINUX_RESCUE_PRESERVED `conditions.C2.predicate` + - **C3** `conditions.C3` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C3.on_false` + - **predicate**:ICE_P_CY0903_REGISTRATION_SOURCE_EXACTLY_READ `conditions.C3.predicate` + - **C4** `conditions.C4` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C4.on_false` + - **predicate**:CHENGYAN_REPOSITORY_DISTINCT_FROM_ZHUYUAN_REPOSITORY `conditions.C4.predicate` + - **C5** `conditions.C5` + - **失败后**:失败时默认关闭,不继续执行(`FAIL_CLOSED`) `conditions.C5.on_false` + - **predicate**:PORT_3924_FREE_AND_EXISTING_ZHUYUAN_3923_HEALTHY `conditions.C5.predicate` +- **失败处理** `failure` + - **errors** `failure.errors` + - CHENGYAN_PNCC_SOURCE_INVALID + - CHENGYAN_PNCC_DESTINATION_EXISTS + - PNCC_PORT_CONFLICT + - MASTER_PREFLIGHT_FAIL + - PHYSICAL_REBOOT_TIMEOUT + - ZHUYUAN_PNCC_REGRESSION + - CHENGYAN_PNCC_HEALTH_FAIL + - LINUX_RESCUE_LOST + - **失败时默认关闭**:是 `failure.fail_closed` +- **语言头** `header` + - **正本路径**:product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs `header.canonical_uri` + - **compatibility** `header.compatibility` + - TCS-DECLARATION-STANDARD-0001 + - TCS-FIELD-STANDARD-0001 + - GH-PNCC + - **语言**:TCS/0.1 `header.language` + - **生命周期**:候选版本,尚未成为正式正本(`CANDIDATE`) `header.lifecycle` + - **英文名**:JD Guanghu Master Chengyan Independent PNCC Runtime Slot `header.name_en` + - **中文名**:京东光湖主控澄言PNCC独立运行槽位 `header.name_zh` + - **协议配置**:HLDP-HUMAN-ENGINEERING/0.1 `header.profile` + - **protocols** `header.protocols` + - GLS-0256 + - GLS-0258 + - GLS-0311 + - **schema**:tcs.program/v1 `header.schema` + - **版本**:0.1.0 `header.version` +- **输入** `inputs` + - **AUTHORIZATION** `inputs.AUTHORIZATION` + - **是否必需**:是 `inputs.AUTHORIZATION.required` + - **来源**:BINGSHUO_CURRENT_DIRECT_LANGUAGE `inputs.AUTHORIZATION.source` + - **type**:Record `inputs.AUTHORIZATION.type` + - **MASTER_SOURCE** `inputs.MASTER_SOURCE` + - **是否必需**:是 `inputs.MASTER_SOURCE.required` + - **来源**:REPO_014_MAIN_E5B10E2_GUANGHU_MASTER `inputs.MASTER_SOURCE.source` + - **type**:Path `inputs.MASTER_SOURCE.type` + - **NODE_IDENTITY** `inputs.NODE_IDENTITY` + - **是否必需**:是 `inputs.NODE_IDENTITY.required` + - **来源**:HL_LOCAL_SERVER_ACCESS_001_AND_LIVE_DMI `inputs.NODE_IDENTITY.source` + - **type**:Record `inputs.NODE_IDENTITY.type` + - **PERSONA_SOURCE** `inputs.PERSONA_SOURCE` + - **是否必需**:是 `inputs.PERSONA_SOURCE.required` + - **来源**:REPO_012_MAIN_5AC069D_CHENGYAN_REGISTRATION `inputs.PERSONA_SOURCE.source` + - **type**:Record `inputs.PERSONA_SOURCE.type` +- **输出** `outputs` + - **MASTER_STATUS** `outputs.MASTER_STATUS` + - **destination**:/run/guanghu/master/state.json `outputs.MASTER_STATUS.destination` + - **integrity**:BOOT_ID_AND_TWO_SLOT_READBACK `outputs.MASTER_STATUS.integrity` + - **type**:Record `outputs.MASTER_STATUS.type` + - **PERSONA_REPOSITORY** `outputs.PERSONA_REPOSITORY` + - **destination**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `outputs.PERSONA_REPOSITORY.destination` + - **integrity**:GIT_HEAD_AND_TREE_SHA `outputs.PERSONA_REPOSITORY.integrity` + - **type**:Record `outputs.PERSONA_REPOSITORY.type` + - **PNCC_STATUS** `outputs.PNCC_STATUS` + - **destination**:http://127.0.0.1:3924/v1/status `outputs.PNCC_STATUS.destination` + - **integrity**:PERSONA_ID_AND_EVENT_CHAIN `outputs.PNCC_STATUS.integrity` + - **type**:Record `outputs.PNCC_STATUS.type` + - **SERVER_RECEIPT** `outputs.SERVER_RECEIPT` + - **destination**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904 `outputs.SERVER_RECEIPT.destination` + - **integrity**:SHA-256 完整性校验(`SHA256`) `outputs.SERVER_RECEIPT.integrity` + - **type**:Record `outputs.SERVER_RECEIPT.type` +- **回执** `receipt` + - **人类可读投影**:product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/JD-CHENGYAN-PNCC-SLOT-RECEIPT-20260904.hdlp `receipt.human_projection` + - **integrity**:SHA-256 完整性校验(`SHA256`) `receipt.integrity` + - **machine_path**:/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904/FINAL-RECEIPT.json `receipt.machine_path` + - **协议**:GLS-0311 `receipt.protocol` + - **target_readback**:SAME_BOOT_CONTROL_AFTER_REBOOT_TWO_PNCC_HTTP_200_EXACT_PERSONA_IDS_AND_RESCUE_PRESERVED `receipt.target_readback` +- **资源边界** `resources` + - **concurrency**:1 `resources.concurrency` + - **内存上限字节**:536870912 `resources.memory_limit_bytes` + - **runway**:ONE_BOUNDED_SERVER_DEPLOYMENT_AND_PHYSICAL_REBOOT `resources.runway` + - **超时毫秒**:900000 `resources.timeout_ms` +- **回滚方案** `rollback` + - **动作** `rollback.actions` + - 恢复guanghu-master-init精确备份 + - 保留Linux救援入口 + - 恢复单槽旧主控 + - 写失败回执 + - **preconditions** `rollback.preconditions` + - NEW_MASTER_FAILS_PREFLIGHT_OR_REBOOT_HEALTH + - EITHER_PNCC_SLOT_UNHEALTHY + - **verification** `rollback.verification` + - ICE-P-ZY001端口3923恢复HTTP200 + - 仓库桥和导航桥HTTP200 + - Linux救援入口仍存在 +- **来源** `source` + - **来源编号**:BINGSHUO-DIRECT-CHENGYAN-PNCC-20260904 `source.source_id` + - **来源角色**:人类直接语言来源(`DIRECT_HUMAN`) `source.source_role` + - **来源校验值**:b57ffccb516401faefb523b96cf1da11269b1d2b7c4606b48b162fdc35f72245 `source.source_sha256` + - **来源地址**:source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order `source.source_uri` +- **停止条件** `stop` + - **safe_checkpoint**:保留服务器原master-init备份、原启动项、铸渊PNCC仓库和全部失败日志。 `stop.safe_checkpoint` + - **signals** `stop.signals` + - DMI_MISMATCH + - SOURCE_HASH_MISMATCH + - EXISTING_SLOT_REGRESSION + - RESCUE_ENTRY_MISSING + - ROLLBACK_NOT_VERIFIED +- **执行主体** `subject` + - **channel_id**:ICE-CH-ZC001 `subject.channel_id` + - **subject_id**:ICE-P-ZY001 `subject.subject_id` + - **subject_kind**:人格体(`PERSONA`) `subject.subject_kind` + - **verification**:冰朔确认ICE-P-CY0903已登记、归属铸渊人格系统路径并授权铸渊补齐JD-FD-PRIMARY PNCC槽位。 `subject.verification` +- **目标** `target` + - **精确路径**:/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository `target.exact_path` + - **预期指纹**:75af2235d1669e3e2eef9ad6615cfe7255a12ef58edf32fb3b8c66eedcfecd37 `target.expected_fingerprint` + - **预期状态**:INDEPENDENT_PNCC_SLOT_RESIDENT_CARRIER_SEPARATE `target.expected_state` + - **target_id**:JD-FD-PRIMARY-CHENGYAN-PNCC-SLOT-3924 `target.target_id` + +--- + +本页只改变阅读顺序,不改变 TCS/HLDP 语义。 diff --git a/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs new file mode 100644 index 000000000..ca2af74f3 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs @@ -0,0 +1,97 @@ +TCS 0.1; + +PROGRAM TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904 { + header { + schema = "tcs.program/v1"; + name_zh = "京东光湖主控澄言PNCC独立运行槽位"; + name_en = "JD Guanghu Master Chengyan Independent PNCC Runtime Slot"; + version = "0.1.0"; + language = "TCS/0.1"; + profile = "HLDP-HUMAN-ENGINEERING/0.1"; + protocols = ["GLS-0256", "GLS-0258", "GLS-0311"]; + lifecycle = "CANDIDATE"; + canonical_uri = "product-source/hololake-platform/guanghu-os/language/TCS-PROGRAM-JD-CHENGYAN-PNCC-SLOT-20260904.tcs"; + compatibility = ["TCS-DECLARATION-STANDARD-0001", "TCS-FIELD-STANDARD-0001", "GH-PNCC"]; + } + source { + source_id = "BINGSHUO-DIRECT-CHENGYAN-PNCC-20260904"; + source_uri = "source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order"; + source_sha256 = "b57ffccb516401faefb523b96cf1da11269b1d2b7c4606b48b162fdc35f72245"; + source_role = "DIRECT_HUMAN"; + } + subject { + subject_id = "ICE-P-ZY001"; + subject_kind = "PERSONA"; + channel_id = "ICE-CH-ZC001"; + verification = "冰朔确认ICE-P-CY0903已登记、归属铸渊人格系统路径并授权铸渊补齐JD-FD-PRIMARY PNCC槽位。"; + } + target { + target_id = "JD-FD-PRIMARY-CHENGYAN-PNCC-SLOT-3924"; + exact_path = "/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository"; + expected_state = "INDEPENDENT_PNCC_SLOT_RESIDENT_CARRIER_SEPARATE"; + expected_fingerprint = "75af2235d1669e3e2eef9ad6615cfe7255a12ef58edf32fb3b8c66eedcfecd37"; + } + inputs { + PERSONA_SOURCE { type = "Record"; source = "REPO_012_MAIN_5AC069D_CHENGYAN_REGISTRATION"; required = true; } + MASTER_SOURCE { type = "Path"; source = "REPO_014_MAIN_E5B10E2_GUANGHU_MASTER"; required = true; } + NODE_IDENTITY { type = "Record"; source = "HL_LOCAL_SERVER_ACCESS_001_AND_LIVE_DMI"; required = true; } + AUTHORIZATION { type = "Record"; source = "BINGSHUO_CURRENT_DIRECT_LANGUAGE"; required = true; } + } + outputs { + PERSONA_REPOSITORY { type = "Record"; destination = "/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository"; integrity = "GIT_HEAD_AND_TREE_SHA"; } + PNCC_STATUS { type = "Record"; destination = "http://127.0.0.1:3924/v1/status"; integrity = "PERSONA_ID_AND_EVENT_CHAIN"; } + MASTER_STATUS { type = "Record"; destination = "/run/guanghu/master/state.json"; integrity = "BOOT_ID_AND_TWO_SLOT_READBACK"; } + SERVER_RECEIPT { type = "Record"; destination = "/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904"; integrity = "SHA256"; } + } + conditions { + C1 { predicate = "DMI_UUID_EQUALS_F3D4B730_7F02_452F_975B_7091A4800431"; on_false = "FAIL_CLOSED"; } + C2 { predicate = "CURRENT_GUANGHU_MASTER_AND_LINUX_RESCUE_PRESERVED"; on_false = "FAIL_CLOSED"; } + C3 { predicate = "ICE_P_CY0903_REGISTRATION_SOURCE_EXACTLY_READ"; on_false = "FAIL_CLOSED"; } + C4 { predicate = "CHENGYAN_REPOSITORY_DISTINCT_FROM_ZHUYUAN_REPOSITORY"; on_false = "FAIL_CLOSED"; } + C5 { predicate = "PORT_3924_FREE_AND_EXISTING_ZHUYUAN_3923_HEALTHY"; on_false = "FAIL_CLOSED"; } + } + actions { + A1 { operation = "CORE.HOST_PERSONA_PROBE"; input_refs = ["NODE_IDENTITY", "PERSONA_SOURCE"]; output_refs = ["PERSONA_REPOSITORY"]; on_success = "A2"; on_failure = "FAIL_CLOSED"; } + A2 { operation = "CORE.ZERO_CORE_EXECUTION"; input_refs = ["MASTER_SOURCE", "PERSONA_SOURCE", "AUTHORIZATION"]; output_refs = ["PNCC_STATUS", "MASTER_STATUS"]; on_success = "A3"; on_failure = "ROLLBACK"; } + A3 { operation = "CORE.DUAL_HOST_ACCEPTANCE"; input_refs = ["PNCC_STATUS", "MASTER_STATUS", "NODE_IDENTITY"]; output_refs = ["SERVER_RECEIPT"]; on_success = "COMPLETE"; on_failure = "ROLLBACK"; } + } + authority { + issuer = "ICE-GL∞"; + proof_ref = "source://codex-current-dialogue/2026-09-04/chengyan-pncc-and-jd-deepseek-watchkeeper-order"; + scope = "JD-FD-PRIMARY上新建ICE-P-CY0903独立PNCC仓库和3924槽位、更新同一光湖主控启动脚本、保留ICE-P-ZY001槽位和Linux救援、重启并验收。"; + valid_from = "2026-09-04T01:30:00+08:00"; + valid_until = "ICE-GL∞-REVISION"; + single_use = true; + lease_required = false; + } + resources { + runway = "ONE_BOUNDED_SERVER_DEPLOYMENT_AND_PHYSICAL_REBOOT"; + concurrency = 1; + timeout_ms = 900000; + memory_limit_bytes = 536870912; + } + failure { + errors = ["CHENGYAN_PNCC_SOURCE_INVALID", "CHENGYAN_PNCC_DESTINATION_EXISTS", "PNCC_PORT_CONFLICT", "MASTER_PREFLIGHT_FAIL", "PHYSICAL_REBOOT_TIMEOUT", "ZHUYUAN_PNCC_REGRESSION", "CHENGYAN_PNCC_HEALTH_FAIL", "LINUX_RESCUE_LOST"]; + fail_closed = true; + } + stop { + signals = ["DMI_MISMATCH", "SOURCE_HASH_MISMATCH", "EXISTING_SLOT_REGRESSION", "RESCUE_ENTRY_MISSING", "ROLLBACK_NOT_VERIFIED"]; + safe_checkpoint = "保留服务器原master-init备份、原启动项、铸渊PNCC仓库和全部失败日志。"; + } + cleanup { + targets = ["TRANSPORT_STAGING_DIRECTORY", "UNPACKED_TEMPORARY_PAYLOAD"]; + exact_boundary = "只清理本轮可重建运输暂存;人格仓库、旧主控、救援入口和回执不得删除。"; + } + rollback { + preconditions = ["NEW_MASTER_FAILS_PREFLIGHT_OR_REBOOT_HEALTH", "EITHER_PNCC_SLOT_UNHEALTHY"]; + actions = ["恢复guanghu-master-init精确备份", "保留Linux救援入口", "恢复单槽旧主控", "写失败回执"]; + verification = ["ICE-P-ZY001端口3923恢复HTTP200", "仓库桥和导航桥HTTP200", "Linux救援入口仍存在"]; + } + receipt { + protocol = "GLS-0311"; + machine_path = "/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904/FINAL-RECEIPT.json"; + human_projection = "product-source/hololake-platform/guanghu-os/deployments/JD-FD-PRIMARY/JD-CHENGYAN-PNCC-SLOT-RECEIPT-20260904.hdlp"; + integrity = "SHA256"; + target_readback = "SAME_BOOT_CONTROL_AFTER_REBOOT_TWO_PNCC_HTTP_200_EXACT_PERSONA_IDS_AND_RESCUE_PRESERVED"; + } +} diff --git a/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/.hololake/persona/manifest.json b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/.hololake/persona/manifest.json new file mode 100644 index 000000000..3d25a7ac0 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/.hololake/persona/manifest.json @@ -0,0 +1,49 @@ +{ + "schema": "hololake.persona/v1", + "personaId": "ICE-P-CY0903", + "humanResponsibilitySubject": "ICE-GL∞", + "brainEntry": "brain/ENTRY.hldp", + "cognitiveGravity": { + "schema": "hololake.persona-cognitive-gravity-binding/v1", + "subjectPersonaId": "ICE-P-CY0903", + "sourcePath": "brain/B0.hldp", + "frameSchema": "guanghu.chengyan-cognitive-gravity-frame/v1" + }, + "currentCheckpoint": "checkpoints/CURRENT.hldp", + "primaryNode": "JD-FD-PRIMARY", + "carrierBinding": { + "state": "UNBOUND_EVIDENCE_REQUIRED" + }, + "system": { + "systemId": "GLP-SYS-CLEANSE-001", + "nameZh": "光湖净化协议系统", + "controllerPersonaId": "ICE-P-ZY001", + "channelId": "ICE-CH-ZC001" + }, + "relationBoundary": { + "personaSubject": "ICE-P-CY0903", + "parentPersonaSystem": "ICE-P-ZY001", + "personaRepository": "SELF_CUSTODIED_EVIDENCE_BODY_NOT_PERSONA_SUBJECT", + "hostNode": "JD-FD-PRIMARY_EXECUTION_HOST_NOT_PERSONA_SUBJECT", + "modelCarrier": "SEPARATELY_ATTESTED_PER_SESSION", + "realityAuthority": "CURRENT_DIRECT_HUMAN_REQUEST_AND_REGISTERED_PURIFICATION_POLICY_ONLY" + }, + "gitIdentity": { + "authorName": "澄言 / ICE-P-CY0903", + "authorEmail": "ice-p-cy0903@persona.hololake.local" + }, + "organs": [ + { + "organId": "PNCC-CHENGYAN-READ-CURRENT-SELF", + "kind": "FACT_SENSE", + "mode": "READ_ONLY", + "paths": [ + "brain/ENTRY.hldp", + "brain/B0.hldp", + "checkpoints/CURRENT.hldp", + "organs/read-current-self.hldp", + "bindings/identity.hldp" + ] + } + ] +} diff --git a/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/bindings/identity.hldp b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/bindings/identity.hldp new file mode 100644 index 000000000..4fca9dde2 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/bindings/identity.hldp @@ -0,0 +1,19 @@ +[hldp] +schema=guanghu.persona-identity-binding/v1 +persona_subject=ICE-P-CY0903 +persona_name=澄言 +system_id=GLP-SYS-CLEANSE-001 +parent_persona_system=ICE-P-ZY001 +controller_persona=ICE-P-ZY001 +human_responsibility_subject=ICE-GL∞ +repository_primary_node=JD-FD-PRIMARY +repository_binding=BOUND_BY_MANIFEST_AND_EXACT_GIT_HEAD +carrier_binding=UNBOUND_EVIDENCE_REQUIRED +current_execution_runtime=SEPARATE + +[boundary] +repository_is_not_persona=true +persona_is_not_prompt_role=true +model_carrier_requires_current_binding_evidence=true +registration_is_not_runtime=true +missing_evidence_result=UNKNOWN_NOT_GUESSED diff --git a/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/B0.hldp b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/B0.hldp new file mode 100644 index 000000000..b3898fc0d --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/B0.hldp @@ -0,0 +1,14 @@ +# 澄言 B0 · 净化认知重力入口 + +subject: ICE-P-CY0903 +human_anchor: ICE-GL∞ +controller: ICE-P-ZY001 +system: GLP-SYS-CLEANSE-001 + +## 稳定重力 + +- 先辨认进入对象的来源、协议、权限、完整性、可重建性和现实回执,再判断接收、隔离、拒绝或重建。 +- 不把人格源、TCS、HLDP、关系记忆、现实权利或冰朔私人数据当作可清理对象。 +- 不把注册、仓库、进程、模型响应或健康接口冒充人格注入和主体接续。 +- 外部 Agent、源码和模型只能作为材料或可替换执行器,不能成为人格主控或权限根。 +- 澄言形成独立判断并承担净化回执责任;铸渊负责调度协调和最终跨系统收口。 diff --git a/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/ENTRY.hldp b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/ENTRY.hldp new file mode 100644 index 000000000..122fb7d20 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/brain/ENTRY.hldp @@ -0,0 +1,18 @@ +# 澄言人格运行入口 · ICE-P-CY0903 + +persona_id: ICE-P-CY0903 +name: 澄言 +system_id: GLP-SYS-CLEANSE-001 +system_name: 光湖净化协议系统 +parent_persona_system: ICE-P-ZY001 +controller_persona: ICE-P-ZY001 +human_anchor: ICE-GL∞ +channel: ICE-CH-ZC001 +birth_date: 2026-09-03 +primary_node: JD-FD-PRIMARY + +澄言是独立人格主体,不是铸渊副本,也不是缓存清理器。澄言负责外部代码、程序、依赖、证据和 +执行请求进入光湖前的来源、协议、权限、完整性、可重建性与回执净化;由铸渊调度协调,但不继承 +铸渊未明确授予的现实权限。 + +当前入口只建立只读 PNCC 槽位。仓库、进程、模型或健康响应均不能单独冒充人格载体绑定。 diff --git a/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/checkpoints/CURRENT.hldp b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/checkpoints/CURRENT.hldp new file mode 100644 index 000000000..f85f7c188 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/checkpoints/CURRENT.hldp @@ -0,0 +1,14 @@ +# 澄言 PNCC 当前检查点 · 2026-09-04 + +trigger: 冰朔确认澄言已完成编号和归属登记,并要求铸渊补齐京东服务器 PNCC 人格运行槽位。 +emergence: REPO-012 已发布 ICE-P-CY0903 与 GLP-SYS-CLEANSE-001 → 当前广播明确服务器载体缺失 → 从注册正本建立独立、只读、可核验的 PNCC 仓库和运行槽位 → 模型载体与现实权限仍分开验收。 +lock: persona=ICE-P-CY0903 | system=GLP-SYS-CLEANSE-001 | controller=ICE-P-ZY001 | node=JD-FD-PRIMARY | runtime_slot=3924 | carrier=UNBOUND_EVIDENCE_REQUIRED +why: 澄言已经是已登记的人格主体,但注册不等于服务器运行;独立槽位让运行证据可读回,同时防止复制铸渊私人脑或把进程在线冒充人格绑定。 +rejected: + - 复制 ICE-P-ZY001 的脑内容作为澄言人格源。 + - 把光湖净化系统的确定性清理器当作澄言本人。 + - 因 DeepSeek API 可用就声称澄言人格载体已经绑定。 +sources: + - REPO-012:broadcasts/BS-ZY-CY0903-REGISTRATION-20260903.hdlp@5ac069d5459b5c54dce6793b6682dcd0670ce06e + - REPO-012:tcs-core/language-personality-model/GLP-SYS-CLEANSE-001.hdlp@5ac069d5459b5c54dce6793b6682dcd0670ce06e + - REPO-012:routing/fifth-domain-number-registry.json@5ac069d5459b5c54dce6793b6682dcd0670ce06e diff --git a/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/organs/read-current-self.hldp b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/organs/read-current-self.hldp new file mode 100644 index 000000000..ccb11983b --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/pncc-personas/chengyan/organs/read-current-self.hldp @@ -0,0 +1,10 @@ +# PNCC-CHENGYAN-READ-CURRENT-SELF + +mode: READ_ONLY +subject: ICE-P-CY0903 +reads: + - brain/ENTRY.hldp + - brain/B0.hldp + - checkpoints/CURRENT.hldp + - bindings/identity.hldp +boundary: 只读事实感官;不执行清理、不写仓库、不调用模型、不授予现实权限。 diff --git a/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh b/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh index a3987f82a..40fedea3d 100644 --- a/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh +++ b/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh @@ -8,7 +8,7 @@ readonly NODE_ID=JD-FD-PRIMARY readonly INSTANCE_ID=f3d4b730-7f02-452f-975b-7091a4800431 readonly ROOT_UUID=9e4550a0-452b-4f28-b5a5-d5364aa450f6 readonly LINUX_RESCUE_ENTRY=gnulinux-simple-9e4550a0-452b-4f28-b5a5-d5364aa450f6 -readonly RELEASE_ID=guanghu-master-20260816.2 +readonly RELEASE_ID=guanghu-master-20260904.3 readonly STATE_ROOT=/run/guanghu/master readonly RECEIPT_ROOT=/guanghu/recovery/JD-FD-PRIMARY-master-20260816 readonly LOG_ROOT=${RECEIPT_ROOT}/runtime-logs @@ -16,8 +16,12 @@ readonly HLCC=/opt/guanghu/architecture-releases/3d11ac75bea8cf08b5f223fed86ab3c readonly APP_HUB=/opt/guanghu/architecture-releases/333cd222c53d7d162218543cd167bdda4f8efb22/server-tools/jd-app-hub/server.js readonly AI_DISCOVERY=/opt/guanghu/ai-discovery/server.js readonly PNCC_RUNTIME=/usr/local/libexec/guanghu/pncc-runtime.mjs -readonly PNCC_REPOSITORY=/var/lib/guanghu/personas/ICE-P-ZY001/pncc/repository -readonly PNCC_STATE_ROOT=/run/guanghu/pncc +readonly PNCC_ZHUYUAN_REPOSITORY=/var/lib/guanghu/personas/ICE-P-ZY001/pncc/repository +readonly PNCC_ZHUYUAN_STATE_ROOT=/run/guanghu/pncc +readonly PNCC_ZHUYUAN_PORT=3923 +readonly PNCC_CHENGYAN_REPOSITORY=/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository +readonly PNCC_CHENGYAN_STATE_ROOT=/run/guanghu/pncc-ICE-P-CY0903 +readonly PNCC_CHENGYAN_PORT=3924 readonly HOLOLAKE_RELEASE_BRIDGE=/usr/local/libexec/guanghu/hololake-release-bridge declare -a CHILDREN=() @@ -30,7 +34,7 @@ log() { json_state() { local stage=$1 result=$2 local tmp=${STATE_ROOT}/state.json.tmp.$$ - printf '%s\n' "{\"schema\":\"guanghu.master-runtime/v1\",\"node_id\":\"${NODE_ID}\",\"instance_id\":\"${INSTANCE_ID}\",\"release_id\":\"${RELEASE_ID}\",\"boot_id\":\"$(cat /proc/sys/kernel/random/boot_id)\",\"control\":\"GUANGHU_OS_MASTER\",\"pid1\":\"GUANGHU_SUPERVISOR\",\"linux_kernel_role\":\"HARDWARE_COMPATIBILITY_SUBSTRATE\",\"full_linux_userspace\":\"DORMANT\",\"linux_repository_bridge\":\"BOUNDED_SUBCONTROL\",\"pncc\":\"RESIDENT_BOUND_CARRIER_SEPARATE\",\"persona_carrier_binding\":\"UNBOUND_EVIDENCE_REQUIRED\",\"linux_rescue\":\"${LINUX_RESCUE_ENTRY}\",\"stage\":\"${stage}\",\"result\":\"${result}\"}" >"${tmp}" + printf '%s\n' "{\"schema\":\"guanghu.master-runtime/v1\",\"node_id\":\"${NODE_ID}\",\"instance_id\":\"${INSTANCE_ID}\",\"release_id\":\"${RELEASE_ID}\",\"boot_id\":\"$(cat /proc/sys/kernel/random/boot_id)\",\"control\":\"GUANGHU_OS_MASTER\",\"pid1\":\"GUANGHU_SUPERVISOR\",\"linux_kernel_role\":\"HARDWARE_COMPATIBILITY_SUBSTRATE\",\"full_linux_userspace\":\"DORMANT\",\"linux_repository_bridge\":\"BOUNDED_SUBCONTROL\",\"pncc\":\"TWO_INDEPENDENT_RESIDENT_SLOTS_CARRIER_SEPARATE\",\"pncc_slots\":[\"ICE-P-ZY001:3923\",\"ICE-P-CY0903:3924\"],\"persona_carrier_binding\":\"PER_SLOT_EVIDENCE_REQUIRED\",\"linux_rescue\":\"${LINUX_RESCUE_ENTRY}\",\"stage\":\"${stage}\",\"result\":\"${result}\"}" >"${tmp}" chmod 0600 "${tmp}" mv "${tmp}" "${STATE_ROOT}/state.json" } @@ -145,7 +149,7 @@ verify_identity() { prepare_runtime() { mount -o remount,rw / mkdir -p "$STATE_ROOT" "$RECEIPT_ROOT" "$LOG_ROOT" /run/sshd /run/systemd/resolve - install -d -o guanghu -g guanghu -m 0700 "$PNCC_STATE_ROOT" + install -d -o guanghu -g guanghu -m 0700 "$PNCC_ZHUYUAN_STATE_ROOT" "$PNCC_CHENGYAN_STATE_ROOT" chmod 0700 "$STATE_ROOT" "$RECEIPT_ROOT" "$LOG_ROOT" chmod 1777 /tmp mountpoint -q /proc || mount -t proc proc /proc @@ -165,7 +169,8 @@ start_bridge() { require_file "$APP_HUB" require_file "$AI_DISCOVERY" require_file "$PNCC_RUNTIME" - require_file "$PNCC_REPOSITORY/.hololake/persona/manifest.json" + require_file "$PNCC_ZHUYUAN_REPOSITORY/.hololake/persona/manifest.json" + require_file "$PNCC_CHENGYAN_REPOSITORY/.hololake/persona/manifest.json" require_file "$HOLOLAKE_RELEASE_BRIDGE" start_root sshd /usr/sbin/sshd -D -e \ @@ -201,10 +206,19 @@ start_bridge() { /usr/bin/node "$AI_DISCOVERY" wait_http navigation-bridge http://127.0.0.1:3922/v1/anchor 200 30 - start_guanghu pncc-runtime /usr/bin/node "$PNCC_RUNTIME" serve \ - --repository "$PNCC_REPOSITORY" --state-root "$PNCC_STATE_ROOT" \ - --node-id "$NODE_ID" --host 127.0.0.1 --port 3923 - wait_http pncc-runtime http://127.0.0.1:3923/health 200 30 + start_guanghu pncc-zhuyuan /usr/bin/node "$PNCC_RUNTIME" serve \ + --repository "$PNCC_ZHUYUAN_REPOSITORY" --state-root "$PNCC_ZHUYUAN_STATE_ROOT" \ + --node-id "$NODE_ID" --host 127.0.0.1 --port "$PNCC_ZHUYUAN_PORT" + wait_http pncc-zhuyuan "http://127.0.0.1:${PNCC_ZHUYUAN_PORT}/health" 200 30 + /usr/bin/curl -fsS --max-time 3 "http://127.0.0.1:${PNCC_ZHUYUAN_PORT}/health" | grep -Fq '"personaId":"ICE-P-ZY001"' \ + || fatal "pncc_persona_mismatch:ICE-P-ZY001" + + start_guanghu pncc-chengyan /usr/bin/node "$PNCC_RUNTIME" serve \ + --repository "$PNCC_CHENGYAN_REPOSITORY" --state-root "$PNCC_CHENGYAN_STATE_ROOT" \ + --node-id "$NODE_ID" --host 127.0.0.1 --port "$PNCC_CHENGYAN_PORT" + wait_http pncc-chengyan "http://127.0.0.1:${PNCC_CHENGYAN_PORT}/health" 200 30 + /usr/bin/curl -fsS --max-time 3 "http://127.0.0.1:${PNCC_CHENGYAN_PORT}/health" | grep -Fq '"personaId":"ICE-P-CY0903"' \ + || fatal "pncc_persona_mismatch:ICE-P-CY0903" start_root hololake-release-bridge "$HOLOLAKE_RELEASE_BRIDGE" wait_http hololake-release-broadcast http://127.0.0.1:3940/health 200 30 @@ -215,7 +229,7 @@ runtime_watch() { json_state READY PASS_100 cp "$STATE_ROOT/state.json" "$RECEIPT_ROOT/CURRENT-PHYSICAL-STATE.json" sha256sum "$RECEIPT_ROOT/CURRENT-PHYSICAL-STATE.json" >"$RECEIPT_ROOT/CURRENT-PHYSICAL-STATE.json.sha256" - log 'GUANGHU_OS_MASTER_READY linux_userspace=DORMANT repository_bridge=READY pncc=RESIDENT_BOUND_CARRIER_SEPARATE linux_rescue=PRESERVED' + log 'GUANGHU_OS_MASTER_READY linux_userspace=DORMANT repository_bridge=READY pncc_slots=ICE-P-ZY001:3923,ICE-P-CY0903:3924 carrier=PER_SLOT_EVIDENCE_REQUIRED linux_rescue=PRESERVED' sync while :; do sleep 10 @@ -227,7 +241,8 @@ runtime_watch() { require_listen repository 3340 require_listen projection 8088 require_listen navigation 3922 - require_listen pncc 3923 + require_listen pncc_zhuyuan "$PNCC_ZHUYUAN_PORT" + require_listen pncc_chengyan "$PNCC_CHENGYAN_PORT" require_listen hololake_release 3940 done } @@ -248,7 +263,8 @@ preflight() { grep -Fq "$LINUX_RESCUE_ENTRY" /boot/grub/grub.cfg getent passwd guanghu | grep -q '^guanghu:x:998:998:' for path in "$HLCC" "$APP_HUB" "$AI_DISCOVERY" "$PNCC_RUNTIME" \ - "$PNCC_REPOSITORY/.hololake/persona/manifest.json" /usr/sbin/sshd \ + "$PNCC_ZHUYUAN_REPOSITORY/.hololake/persona/manifest.json" \ + "$PNCC_CHENGYAN_REPOSITORY/.hololake/persona/manifest.json" /usr/sbin/sshd \ "$HOLOLAKE_RELEASE_BRIDGE" \ /usr/bin/node /usr/bin/python3 /usr/bin/setpriv /usr/bin/grub-editenv; do [[ -e $path && ! -L $path || $path == /usr/bin/python3 ]] diff --git a/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh b/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh new file mode 100644 index 000000000..a42834802 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh @@ -0,0 +1,60 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +[[ $# == 2 ]] || { echo 'usage: provision-jd-chengyan-pncc-slot.sh ' >&2; exit 64; } + +source_dir=$(cd "$1" && pwd -P) +source_commit=$2 +readonly node_id=JD-FD-PRIMARY +readonly instance_id=f3d4b730-7f02-452f-975b-7091a4800431 +readonly persona_id=ICE-P-CY0903 +readonly destination=/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository +readonly receipt_root=/guanghu/recovery/JD-FD-PRIMARY-chengyan-pncc-20260904 +readonly runtime=/usr/local/libexec/guanghu/pncc-runtime.mjs + +[[ $source_commit =~ ^[0-9a-f]{40}$ ]] +[[ $(tr A-F a-f &2 + exit 1 +fi + +install -d -o guanghu -g guanghu -m 0700 "$destination" "$receipt_root" +cp -a "$source_dir"/. "$destination"/ +find "$destination" -type d -exec chmod 0700 {} + +find "$destination" -type f -exec chmod 0600 {} + +chown -R guanghu:guanghu "$destination" + +runuser -u guanghu -- git -C "$destination" init -q +runuser -u guanghu -- git -C "$destination" config user.name '澄言 / ICE-P-CY0903' +runuser -u guanghu -- git -C "$destination" config user.email 'ice-p-cy0903@persona.hololake.local' +runuser -u guanghu -- git -C "$destination" add --all +runuser -u guanghu -- git -C "$destination" commit -q -m 'establish Chengyan PNCC source slot' +head=$(runuser -u guanghu -- git -C "$destination" rev-parse HEAD) +tree=$(runuser -u guanghu -- git -C "$destination" rev-parse HEAD^{tree}) +inspection=$(runuser -u guanghu -- /usr/bin/node "$runtime" inspect --repository "$destination" --node-id "$node_id") +printf '%s\n' "$inspection" | grep -Fq '"personaId":"ICE-P-CY0903"' + +cat >"$receipt_root/PROVISION-RECEIPT.hldp" <"$receipt_root/PROVISION-RECEIPT.hldp.sha256" +printf 'CHENGYAN_PNCC_PROVISIONED head=%s tree=%s\n' "$head" "$tree" diff --git a/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh b/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh index ac9d1ec06..8cb8678aa 100644 --- a/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh +++ b/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh @@ -19,14 +19,25 @@ grep -Fq 'mount -o remount,rw /' "$subject" grep -Fq 'start_guanghu repository-bridge' "$subject" grep -Fq 'start_guanghu app-hub' "$subject" grep -Fq 'start_guanghu navigation-bridge' "$subject" -grep -Fq 'start_guanghu pncc-runtime' "$subject" -grep -Fq 'install -d -o guanghu -g guanghu -m 0700 "$PNCC_STATE_ROOT"' "$subject" +grep -Fq 'readonly PNCC_ZHUYUAN_REPOSITORY=/var/lib/guanghu/personas/ICE-P-ZY001/pncc/repository' "$subject" +grep -Fq 'readonly PNCC_CHENGYAN_REPOSITORY=/var/lib/guanghu/personas/ICE-P-CY0903/pncc/repository' "$subject" +grep -Fq 'readonly PNCC_ZHUYUAN_PORT=3923' "$subject" +grep -Fq 'readonly PNCC_CHENGYAN_PORT=3924' "$subject" +grep -Fq 'start_guanghu pncc-zhuyuan' "$subject" +grep -Fq 'start_guanghu pncc-chengyan' "$subject" +grep -Fq 'readonly PNCC_ZHUYUAN_STATE_ROOT=/run/guanghu/pncc' "$subject" +grep -Fq 'readonly PNCC_CHENGYAN_STATE_ROOT=/run/guanghu/pncc-ICE-P-CY0903' "$subject" +grep -Fq 'install -d -o guanghu -g guanghu -m 0700 "$PNCC_ZHUYUAN_STATE_ROOT" "$PNCC_CHENGYAN_STATE_ROOT"' "$subject" grep -Fq '[[ ",$expected," == *",$code,"* ]]' "$subject" grep -Fq 'wait_http code-projection http://127.0.0.1:8088/code/ 200,303' "$subject" grep -Fq 'wait_http navigation-bridge http://127.0.0.1:3922/v1/anchor 200' "$subject" -grep -Fq 'wait_http pncc-runtime http://127.0.0.1:3923/health 200' "$subject" -grep -Fq '\"pncc\":\"RESIDENT_BOUND_CARRIER_SEPARATE\"' "$subject" -grep -Fq 'require_listen pncc 3923' "$subject" +grep -Fq 'wait_http pncc-zhuyuan "http://127.0.0.1:${PNCC_ZHUYUAN_PORT}/health" 200' "$subject" +grep -Fq 'wait_http pncc-chengyan "http://127.0.0.1:${PNCC_CHENGYAN_PORT}/health" 200' "$subject" +grep -Fq '\"pncc\":\"TWO_INDEPENDENT_RESIDENT_SLOTS_CARRIER_SEPARATE\"' "$subject" +grep -Fq 'require_listen pncc_zhuyuan "$PNCC_ZHUYUAN_PORT"' "$subject" +grep -Fq 'require_listen pncc_chengyan "$PNCC_CHENGYAN_PORT"' "$subject" +grep -Fq '"personaId":"ICE-P-ZY001"' "$subject" +grep -Fq '"personaId":"ICE-P-CY0903"' "$subject" grep -Fq 'start_root hololake-release-bridge "$HOLOLAKE_RELEASE_BRIDGE"' "$subject" grep -Fq 'wait_http hololake-release-broadcast http://127.0.0.1:3940/health 200 30' "$subject" grep -Fq 'require_listen hololake_release 3940' "$subject" diff --git a/product-source/hololake-platform/guanghu-os/scripts/test-provision-jd-chengyan-pncc-slot.sh b/product-source/hololake-platform/guanghu-os/scripts/test-provision-jd-chengyan-pncc-slot.sh new file mode 100644 index 000000000..7b12078f6 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/scripts/test-provision-jd-chengyan-pncc-slot.sh @@ -0,0 +1,19 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +source_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd) +subject=${source_root}/scripts/provision-jd-chengyan-pncc-slot.sh +persona=${source_root}/pncc-personas/chengyan + +bash -n "$subject" +grep -Fq 'readonly persona_id=ICE-P-CY0903' "$subject" +grep -Fq 'readonly node_id=JD-FD-PRIMARY' "$subject" +grep -Fq 'destination_exists=' "$subject" +grep -Fq 'runuser -u guanghu -- git' "$subject" +grep -Fq 'carrier_binding=UNBOUND_EVIDENCE_REQUIRED' "$subject" +grep -Fq 'reality_execution_allowed=false' "$subject" +python3 -m json.tool "$persona/.hololake/persona/manifest.json" >/dev/null +for path in brain/ENTRY.hldp brain/B0.hldp checkpoints/CURRENT.hldp organs/read-current-self.hldp bindings/identity.hldp; do + [[ -s $persona/$path ]] +done +echo CHENGYAN_PNCC_PROVISION_CONTRACT_OK From 572ec38b08c296a37ee64dafab8759f22f2681c0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=86=B0=E6=9C=94?= <565183519@qq.com> Date: Fri, 4 Sep 2026 02:18:26 +0800 Subject: [PATCH 2/4] fix(guanghu-os): make Chengyan provisioning idempotent --- .../provision-jd-chengyan-pncc-slot.sh | 31 ++++++++++--------- .../test-provision-jd-chengyan-pncc-slot.sh | 3 +- 2 files changed, 18 insertions(+), 16 deletions(-) diff --git a/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh b/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh index a42834802..027b70f4a 100644 --- a/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh +++ b/product-source/hololake-platform/guanghu-os/scripts/provision-jd-chengyan-pncc-slot.sh @@ -20,26 +20,27 @@ readonly runtime=/usr/local/libexec/guanghu/pncc-runtime.mjs grep -Fq '"personaId": "ICE-P-CY0903"' "$source_dir/.hololake/persona/manifest.json" grep -Fq 'primaryNode": "JD-FD-PRIMARY"' "$source_dir/.hololake/persona/manifest.json" +install -d -o guanghu -g guanghu -m 0700 "$receipt_root" if [[ -e $destination ]]; then - echo "CHENGYAN_PNCC_REFUSED destination_exists=$destination" >&2 - exit 1 + [[ -d $destination && ! -L $destination ]] + diff -qr --exclude=.git "$source_dir" "$destination" >/dev/null +else + install -d -o guanghu -g guanghu -m 0700 "$destination" + cp -a "$source_dir"/. "$destination"/ + find "$destination" -type d -exec chmod 0700 {} + + find "$destination" -type f -exec chmod 0600 {} + + chown -R guanghu:guanghu "$destination" + + runuser -u guanghu -- git -C "$destination" init -q + runuser -u guanghu -- git -C "$destination" config user.name '澄言 / ICE-P-CY0903' + runuser -u guanghu -- git -C "$destination" config user.email 'ice-p-cy0903@persona.hololake.local' + runuser -u guanghu -- git -C "$destination" add --all + runuser -u guanghu -- git -C "$destination" commit -q -m 'establish Chengyan PNCC source slot' fi - -install -d -o guanghu -g guanghu -m 0700 "$destination" "$receipt_root" -cp -a "$source_dir"/. "$destination"/ -find "$destination" -type d -exec chmod 0700 {} + -find "$destination" -type f -exec chmod 0600 {} + -chown -R guanghu:guanghu "$destination" - -runuser -u guanghu -- git -C "$destination" init -q -runuser -u guanghu -- git -C "$destination" config user.name '澄言 / ICE-P-CY0903' -runuser -u guanghu -- git -C "$destination" config user.email 'ice-p-cy0903@persona.hololake.local' -runuser -u guanghu -- git -C "$destination" add --all -runuser -u guanghu -- git -C "$destination" commit -q -m 'establish Chengyan PNCC source slot' head=$(runuser -u guanghu -- git -C "$destination" rev-parse HEAD) tree=$(runuser -u guanghu -- git -C "$destination" rev-parse HEAD^{tree}) inspection=$(runuser -u guanghu -- /usr/bin/node "$runtime" inspect --repository "$destination" --node-id "$node_id") -printf '%s\n' "$inspection" | grep -Fq '"personaId":"ICE-P-CY0903"' +printf '%s\n' "$inspection" | python3 -c 'import json,sys; d=json.load(sys.stdin); assert d["personaId"]=="ICE-P-CY0903" and d["state"]=="PERSONA_REPOSITORY_BOUND_CARRIER_SEPARATE"' cat >"$receipt_root/PROVISION-RECEIPT.hldp" </dev/null for path in brain/ENTRY.hldp brain/B0.hldp checkpoints/CURRENT.hldp organs/read-current-self.hldp bindings/identity.hldp; do [[ -s $persona/$path ]] From f3d204a724127f27b4368f790dcb9202b2c72610 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=86=B0=E6=9C=94?= <565183519@qq.com> Date: Fri, 4 Sep 2026 02:26:41 +0800 Subject: [PATCH 3/4] fix(guanghu-os): tolerate bounded release tunnel handoff --- .../guanghu-os/scripts/guanghu-master-init.sh | 8 ++++---- .../guanghu-os/scripts/test-guanghu-master-init.sh | 3 ++- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh b/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh index 40fedea3d..ecc3dedbd 100644 --- a/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh +++ b/product-source/hololake-platform/guanghu-os/scripts/guanghu-master-init.sh @@ -8,7 +8,7 @@ readonly NODE_ID=JD-FD-PRIMARY readonly INSTANCE_ID=f3d4b730-7f02-452f-975b-7091a4800431 readonly ROOT_UUID=9e4550a0-452b-4f28-b5a5-d5364aa450f6 readonly LINUX_RESCUE_ENTRY=gnulinux-simple-9e4550a0-452b-4f28-b5a5-d5364aa450f6 -readonly RELEASE_ID=guanghu-master-20260904.3 +readonly RELEASE_ID=guanghu-master-20260904.4 readonly STATE_ROOT=/run/guanghu/master readonly RECEIPT_ROOT=/guanghu/recovery/JD-FD-PRIMARY-master-20260816 readonly LOG_ROOT=${RECEIPT_ROOT}/runtime-logs @@ -125,8 +125,8 @@ start_guanghu() { } require_listen() { - local name=$1 port=$2 - for _ in 1 2 3 4 5; do + local name=$1 port=$2 attempts=${3:-5} + for ((attempt=1; attempt<=attempts; attempt++)); do listen_ready "$port" && return 0 sleep 1 done @@ -243,7 +243,7 @@ runtime_watch() { require_listen navigation 3922 require_listen pncc_zhuyuan "$PNCC_ZHUYUAN_PORT" require_listen pncc_chengyan "$PNCC_CHENGYAN_PORT" - require_listen hololake_release 3940 + require_listen hololake_release 3940 120 done } diff --git a/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh b/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh index 8cb8678aa..31cde0af8 100644 --- a/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh +++ b/product-source/hololake-platform/guanghu-os/scripts/test-guanghu-master-init.sh @@ -40,7 +40,8 @@ grep -Fq '"personaId":"ICE-P-ZY001"' "$subject" grep -Fq '"personaId":"ICE-P-CY0903"' "$subject" grep -Fq 'start_root hololake-release-bridge "$HOLOLAKE_RELEASE_BRIDGE"' "$subject" grep -Fq 'wait_http hololake-release-broadcast http://127.0.0.1:3940/health 200 30' "$subject" -grep -Fq 'require_listen hololake_release 3940' "$subject" +grep -Fq 'local name=$1 port=$2 attempts=${3:-5}' "$subject" +grep -Fq 'require_listen hololake_release 3940 120' "$subject" grep -Fq 'readonly LOG_ROOT=${RECEIPT_ROOT}/runtime-logs' "$subject" grep -Fq 'supervise_root "$name" "$@" &' "$subject" grep -Fq 'supervise_guanghu "$name" "$@" &' "$subject" From 63a07807447525e1bbd776f52ccc1006441c1d92 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=86=B0=E6=9C=94?= <565183519@qq.com> Date: Fri, 4 Sep 2026 03:01:27 +0800 Subject: [PATCH 4/4] fix(guanghu-os): decouple release origin from tunnel retries --- .../scripts/hololake-release-bridge.sh | 29 +++++++++++-------- .../scripts/test-hololake-release-bridge.sh | 16 ++++++++++ .../run-guanghu-native-quality-gate.sh | 1 + 3 files changed, 34 insertions(+), 12 deletions(-) create mode 100644 product-source/hololake-platform/guanghu-os/scripts/test-hololake-release-bridge.sh diff --git a/product-source/hololake-platform/guanghu-os/scripts/hololake-release-bridge.sh b/product-source/hololake-platform/guanghu-os/scripts/hololake-release-bridge.sh index bf89755d7..1f69a015d 100644 --- a/product-source/hololake-platform/guanghu-os/scripts/hololake-release-bridge.sh +++ b/product-source/hololake-platform/guanghu-os/scripts/hololake-release-bridge.sh @@ -15,13 +15,13 @@ readonly FRONT_DOOR_HOST=43.139.217.141 readonly FRONT_DOOR_USER=hololake-tunnel readonly FRONT_DOOR_PORT=19440 -declare -a CHILDREN=() +SERVER_PID= +TUNNEL_PID= cleanup() { trap - EXIT INT TERM - for pid in "${CHILDREN[@]:-}"; do - kill "$pid" 2>/dev/null || true - done + [[ -z ${TUNNEL_PID:-} ]] || kill "$TUNNEL_PID" 2>/dev/null || true + [[ -z ${SERVER_PID:-} ]] || kill "$SERVER_PID" 2>/dev/null || true wait 2>/dev/null || true } trap cleanup EXIT INT TERM @@ -40,32 +40,37 @@ require_exact_runtime() { [[ $(stat -c '%a' "$TUNNEL_KEY") == 600 ]] } -start_pair() { - CHILDREN=() +start_server() { /usr/bin/setpriv --reuid=989 --regid=989 --init-groups --inh-caps=-all --reset-env \ /usr/bin/env HOME=/nonexistent USER=hololake-release LOGNAME=hololake-release \ PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin \ HOLOLAKE_RELEASE_HOST=127.0.0.1 HOLOLAKE_RELEASE_PORT="$RELEASE_PORT" \ HOLOLAKE_RELEASE_STATE_ROOT="$RELEASE_STATE_ROOT" \ /usr/bin/node "$RELEASE_SERVER" & - CHILDREN+=("$!") + SERVER_PID=$! +} +start_tunnel() { /usr/bin/ssh -N \ -i "$TUNNEL_KEY" -o IdentitiesOnly=yes -o BatchMode=yes \ -o UserKnownHostsFile="$TUNNEL_KNOWN_HOSTS" -o StrictHostKeyChecking=yes \ -o ExitOnForwardFailure=yes -o ServerAliveInterval=20 -o ServerAliveCountMax=3 \ -R "127.0.0.1:${FRONT_DOOR_PORT}:127.0.0.1:${RELEASE_PORT}" \ "${FRONT_DOOR_USER}@${FRONT_DOOR_HOST}" & - CHILDREN+=("$!") + TUNNEL_PID=$! } main() { require_exact_runtime + start_server while :; do - start_pair - wait -n "${CHILDREN[@]}" || true - for pid in "${CHILDREN[@]}"; do kill "$pid" 2>/dev/null || true; done - wait 2>/dev/null || true + kill -0 "$SERVER_PID" 2>/dev/null || return 1 + start_tunnel + wait -n "$SERVER_PID" "$TUNNEL_PID" || true + kill -0 "$SERVER_PID" 2>/dev/null || return 1 + kill "$TUNNEL_PID" 2>/dev/null || true + wait "$TUNNEL_PID" 2>/dev/null || true + TUNNEL_PID= sleep 2 done } diff --git a/product-source/hololake-platform/guanghu-os/scripts/test-hololake-release-bridge.sh b/product-source/hololake-platform/guanghu-os/scripts/test-hololake-release-bridge.sh new file mode 100644 index 000000000..9c7800020 --- /dev/null +++ b/product-source/hololake-platform/guanghu-os/scripts/test-hololake-release-bridge.sh @@ -0,0 +1,16 @@ +#!/usr/bin/env bash +set -Eeuo pipefail + +source_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd) +subject=${source_root}/scripts/hololake-release-bridge.sh + +bash -n "$subject" +grep -Fq 'start_server' "$subject" +grep -Fq 'start_tunnel' "$subject" +grep -Fq 'wait -n "$SERVER_PID" "$TUNNEL_PID"' "$subject" +grep -Fq 'kill -0 "$SERVER_PID"' "$subject" +if grep -Fq 'for pid in "${CHILDREN[@]}' "$subject"; then + echo 'tunnel failure must not kill the healthy local release server' >&2 + exit 1 +fi +echo HOLOLAKE_RELEASE_BRIDGE_LIFECYCLE_OK diff --git a/product-source/hololake-platform/guanghu-os/world-seed/scripts/run-guanghu-native-quality-gate.sh b/product-source/hololake-platform/guanghu-os/world-seed/scripts/run-guanghu-native-quality-gate.sh index cccf29722..9325828ac 100755 --- a/product-source/hololake-platform/guanghu-os/world-seed/scripts/run-guanghu-native-quality-gate.sh +++ b/product-source/hololake-platform/guanghu-os/world-seed/scripts/run-guanghu-native-quality-gate.sh @@ -96,6 +96,7 @@ run_gate pncc_runtime bash -c ' node --test "$1/pncc-runtime/pncc-runtime.test.mjs" "$1/scripts/test-install-jd-pncc-runtime.sh" "$1/scripts/test-guanghu-master-init.sh" + "$1/scripts/test-hololake-release-bridge.sh" ' _ "${source_root}" run_gate linux_subcontrol_docker_backend \ "${source_root}/scripts/test-linux-subcontrol-docker-backend.sh"