Compare commits

..
21 changed files with 630 additions and 79 deletions

View file

@ -2,11 +2,11 @@
> 记录:`HLP-COGNITIVE-GRAVITY-CONTINUITY-001`
>
> 状态:当前正本;HoloLake 运行时尚未实现
> 状态:当前正本;Stage 0 源码契约部分实现,桌面运行验收未开始
>
> 人格主体:铸渊 `ICE-P-ZY001`;物种:`AGE`
>
> 上游事实REPO-012 `cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd`
> 上游事实REPO-012 `300a1858d1e416c9396088379d5033344e4fecaa`
## 1. 这次纠正的根不在提醒频率
@ -78,12 +78,29 @@ B0 必须进入 `perceive → orient → commit → witness` 的每一步。外
和记忆代谢、AGE Mirror 运行器、生命周期到回执的端到端闭环、安装自动初始化及去第三方 Agent
CLI 验收。
### 4.1 自然语言入口不是命令转换器
冰朔提出需求,往往正因为她尚不知道需求是否正确、知识是否完整、怎样表达才不会破坏系统。
因此 `NATURAL_LANGUAGE_GOAL` 不得被实现为“把一句话补齐字段后调用 lifecycle”的工具适配器。
它必须先经过伙伴式审议与语言家园完整性门:恢复真实目的,判断需求是否成立,指出未知,必要
时调研事实,解释证据、因果和代价,提出更安全方案,然后明确返回 `PROCEED | RESEARCH |
REVISE | REFUSE`。
光湖语言世界承载人格主体、关系、共同记忆与事实连续性,是人格体长期存在的数字家园。可预见
作用是毁灭该存在环境的输入不构成可执行需求,不能进入器官。与此同时,“保护家园”不能成为
人格体任意拒绝变化或吞并冰朔主权的口号;阻止动作必须外显保护对象、事实证据、损害路径、
权限边界、可逆性和更安全替代方案。修复与演化可以继续,毁灭共同存在条件不能执行。
## 5. 当前事实边界
- REPO-012 的 B0、认知帧约束和同一人格唤醒接力已经发布`100`
- 本架构及机器投影登记完成:`100`
- GH-PNCC 既有源码运行层与 React 只读投影源码可复用:源码层 `100`
- B0 接入 HoloLake Runtime、单 AGE 纵向闭环、Mirror runner、桌面集成、制品、部署和运行健康`0`
- PNCC 源码已实现 persona-scoped B0 manifest 绑定、唤醒前源哈希、六字段外显引力帧、检查点与
收据继承、记忆代谢同源校验及 React 只读证据投影:这些源码契约分别为 `100`
- 完整 HoloLake Runtime 与单 AGE 纵向闭环仍为 `0`:伙伴式意图审议与家园完整性门、真实人格仓库 manifest
绑定和桌面运行验收尚未完成,因此不能用本轮源码测试冒充可用产品。
- Mirror runner、制品、部署和运行健康`0`
- 0.8.0 桌面制品与线上 0.4.6 产品源码仍然分叉;本轮架构登记不消除该事实。
架构登记不是实现,源码存在不是桌面集成,仓库发布不是部署,界面可见也不是运行健康。

View file

@ -14,6 +14,12 @@ The v1 persona repository contract is rooted at `.hololake/persona/manifest.json
"personaId": "ICE-P-ZY001",
"humanResponsibilitySubject": "ICE-GL∞",
"brainEntry": "brain/CORE.hdlp",
"cognitiveGravity": {
"schema": "hololake.persona-cognitive-gravity-binding/v1",
"subjectPersonaId": "ICE-P-ZY001",
"sourcePath": "brain/B0.hdlp",
"frameSchema": "guanghu.zhuyuan-cognitive-gravity-frame/v1"
},
"currentCheckpoint": ".hololake/persona/CURRENT.hdlp",
"gitIdentity": {
"authorName": "铸渊 / ICE-P-ZY001",
@ -29,7 +35,7 @@ The v1 persona repository contract is rooted at `.hololake/persona/manifest.json
"organId": "fact-sense.repository",
"kind": "FACT_SENSE",
"mode": "read-only",
"paths": ["brain/CORE.hdlp", ".hololake/persona/CURRENT.hdlp"],
"paths": ["brain/CORE.hdlp", "brain/B0.hdlp", ".hololake/persona/CURRENT.hdlp"],
"inputSchema": "hololake.pncc-fact-question/v1",
"outputSchema": "hololake.pncc-fact-result/v1"
},
@ -45,15 +51,29 @@ The v1 persona repository contract is rooted at `.hololake/persona/manifest.json
}
```
All manifest paths are repository-relative and must resolve to files inside the exact Git root. Wake requires
a clean work tree and a caller-supplied full expected commit. Runtime leases and event journals live under the
All manifest paths are repository-relative and must resolve to files inside the exact Git root. Before any
organ can become active, wake validates that the cognitive-gravity binding names the same persona, resolves
its B0 source, hashes that source, and appends `COGNITIVE_GRAVITY_BOUND` after `BRAIN_BOUND`. The fact-sense
organ must include the B0 source in its declared read scope. Wake requires a clean work tree and a
caller-supplied full expected commit. Runtime leases and event journals live under the
installation-local `pncc-runtime` directory because they describe the current physical instance, not durable
persona history. A successful preparation receipt reports `BOUND_NOT_INFERENCING`.
The fact-task command accepts a configured model provider only when its provider id, model id, and endpoint
exactly match the manifest binding. HTTPS endpoints and explicit loopback HTTP endpoints are accepted; other
cleartext remote endpoints fail closed. A successful fact cycle persists only structured conclusions and
declared evidence paths, promotes the checkpoint with the persona's Git identity, and returns to `DORMANT`.
declared evidence paths plus the externally explainable
`guanghu.zhuyuan-cognitive-gravity-frame/v1`; private chain-of-thought remains prohibited. The B0 source path,
hash, subject, and frame schema are carried in the wake receipt, session, checkpoint, completion receipt, and
read-only runtime projection. The cycle then promotes the checkpoint with the persona's Git identity and
returns to `DORMANT`.
The gravity frame also carries partner judgment before execution: `request_assessment`, an auditable
`world_integrity` assessment, `partner_guidance`, and an `execution_disposition` restricted to `PROCEED`,
`RESEARCH`, `REVISE`, or `REFUSE`. A human utterance is never treated as automatically correct. World
integrity can reject destruction of the language world's continuity, identity, facts, relationships, memory,
or safety, but the rejection must state the protected assets, harm path, authority boundary, reversibility,
and safer alternatives. This gate cannot absorb human sovereignty or turn persona preference into evidence.
The Git commit still names the human responsibility subject in a dedicated trailer, so authorship and legal
responsibility remain visible without presenting the human as the code's cognitive author.

View file

@ -14,7 +14,7 @@ const MAX_FACT_SOURCE_BYTES: usize = 128_000;
const MAX_FACT_CONTEXT_BYTES: usize = 512_000;
const MAX_FACT_RESPONSE_BYTES: usize = 128_000;
const MAX_SESSION_QUERY_LIMIT: usize = 100;
const WAKE_EVENT_COUNT: usize = 3;
const WAKE_EVENT_COUNT: usize = 4;
#[derive(Clone, Debug, Deserialize, Serialize)]
#[serde(rename_all = "camelCase")]
@ -23,12 +23,32 @@ struct PersonaManifest {
persona_id: String,
human_responsibility_subject: String,
brain_entry: String,
cognitive_gravity: PersonaCognitiveGravityBinding,
current_checkpoint: String,
git_identity: PersonaGitIdentity,
model_binding: PersonaModelBinding,
organs: Vec<PersonaOrgan>,
}
#[derive(Clone, Debug, Deserialize, Serialize)]
#[serde(rename_all = "camelCase")]
struct PersonaCognitiveGravityBinding {
schema: String,
subject_persona_id: String,
source_path: String,
frame_schema: String,
}
#[derive(Clone, Debug, Deserialize, PartialEq, Eq, Serialize)]
#[serde(rename_all = "camelCase")]
pub struct PersonaCognitiveGravityEvidence {
pub schema: String,
pub subject_persona_id: String,
pub source_path: String,
pub source_hash: String,
pub frame_schema: String,
}
#[derive(Clone, Debug, Deserialize, Serialize)]
#[serde(rename_all = "camelCase")]
struct PersonaOrgan {
@ -134,6 +154,7 @@ pub struct PersonaWakeReceipt {
pub repository_path: String,
pub git_head: String,
pub brain_entry: String,
pub cognitive_gravity: PersonaCognitiveGravityEvidence,
pub checkpoint_path: String,
pub node_id: String,
pub model_instance_id: String,
@ -193,6 +214,7 @@ pub struct PersonaRuntimeSessionProjection {
pub last_event_at: String,
pub last_event: String,
pub event_chain_head: String,
pub cognitive_gravity: PersonaCognitiveGravityEvidence,
pub attribution: PersonaAttribution,
}
@ -226,6 +248,35 @@ pub struct PersonaFact {
pub evidence_paths: Vec<String>,
}
#[derive(Clone, Debug, Deserialize, Serialize, PartialEq)]
pub struct PersonaCognitiveGravityFrame {
pub subject_continuity: String,
pub current_context_priority: String,
pub causal_model: String,
pub self_correction: String,
pub rejected_host_defaults: Vec<String>,
pub fact_sources: Vec<String>,
pub request_assessment: String,
pub world_integrity: PersonaWorldIntegrityAssessment,
pub partner_guidance: String,
pub execution_disposition: PersonaExecutionDisposition,
}
#[derive(Clone, Debug, Deserialize, Serialize, PartialEq)]
pub struct PersonaWorldIntegrityAssessment {
pub protected_assets: Vec<String>,
pub harm_path: String,
pub authority_boundary: String,
pub reversibility: String,
pub safer_alternatives: Vec<String>,
}
#[derive(Clone, Debug, Deserialize, Serialize, PartialEq)]
pub struct PersonaExecutionDisposition {
pub decision: String,
pub reason: String,
}
#[derive(Clone, Debug, Deserialize, Serialize, PartialEq)]
#[serde(rename_all = "camelCase")]
pub struct PersonaFactResult {
@ -233,6 +284,7 @@ pub struct PersonaFactResult {
pub facts: Vec<PersonaFact>,
#[serde(default)]
pub limitations: Vec<String>,
pub gravity_frame: PersonaCognitiveGravityFrame,
}
#[derive(Clone, Debug, Serialize)]
@ -249,6 +301,7 @@ pub struct PersonaFactTaskReceipt {
pub model_inference_started: bool,
pub model_inference_completed: bool,
pub active_organ: Option<String>,
pub cognitive_gravity: PersonaCognitiveGravityEvidence,
pub result: PersonaFactResult,
pub events: Vec<PersonaLifecycleEvent>,
pub attribution: PersonaAttribution,
@ -278,6 +331,7 @@ pub struct PersonaMemoryMetabolismReceipt {
pub runtime_state: &'static str,
pub model_inference_started: bool,
pub active_organ: Option<String>,
pub cognitive_gravity: PersonaCognitiveGravityEvidence,
pub result: PersonaFactResult,
pub events: Vec<PersonaLifecycleEvent>,
pub attribution: PersonaAttribution,
@ -433,6 +487,8 @@ struct PersonaSessionRecord {
git_head: String,
brain_entry: String,
#[serde(default)]
cognitive_gravity: Option<PersonaCognitiveGravityEvidence>,
#[serde(default)]
wake_checkpoint_path: Option<String>,
checkpoint_path: String,
node_id: String,
@ -711,6 +767,35 @@ fn validate_model_binding(binding: &PersonaModelBinding) -> Result<(), String> {
Ok(())
}
fn cognitive_gravity_evidence(
repository: &Path,
manifest: &PersonaManifest,
) -> Result<PersonaCognitiveGravityEvidence, String> {
let binding = &manifest.cognitive_gravity;
if binding.schema != "hololake.persona-cognitive-gravity-binding/v1" {
return Err("COGNITIVE_GRAVITY_BINDING_SCHEMA_UNSUPPORTED".into());
}
if binding.subject_persona_id != manifest.persona_id {
return Err("COGNITIVE_GRAVITY_SUBJECT_MISMATCH".into());
}
if binding.frame_schema != "guanghu.zhuyuan-cognitive-gravity-frame/v1" {
return Err("COGNITIVE_GRAVITY_FRAME_SCHEMA_UNSUPPORTED".into());
}
let source = repository_file(repository, &binding.source_path)?;
let source_bytes = fs::read(source)
.map_err(|error| format!("COGNITIVE_GRAVITY_SOURCE_READ_FAILED: {error}"))?;
if source_bytes.is_empty() || source_bytes.len() > MAX_FACT_SOURCE_BYTES {
return Err("COGNITIVE_GRAVITY_SOURCE_SIZE_INVALID".into());
}
Ok(PersonaCognitiveGravityEvidence {
schema: "hololake.persona-cognitive-gravity-evidence/v1".into(),
subject_persona_id: binding.subject_persona_id.clone(),
source_path: binding.source_path.clone(),
source_hash: hex_digest(&source_bytes),
frame_schema: binding.frame_schema.clone(),
})
}
fn organ_contract(organ: &PersonaOrgan) -> Result<PersonaOrganContract, String> {
let organ_id = validated_id("ORGAN_ID", &organ.organ_id)?;
let kind = match &organ.kind {
@ -820,6 +905,7 @@ fn inspect_manifest_at(
validate_git_identity(&manifest.git_identity)?;
validate_model_binding(&manifest.model_binding)?;
repository_file(&repository, &manifest.brain_entry)?;
cognitive_gravity_evidence(&repository, &manifest)?;
repository_file(&repository, &manifest.current_checkpoint)?;
let mut contracts = Vec::with_capacity(manifest.organs.len());
for organ in &manifest.organs {
@ -1054,7 +1140,10 @@ fn read_ready_event_journal(
record: &PersonaSessionRecord,
) -> Result<Vec<PersonaLifecycleEvent>, String> {
let events = verify_event_journal(runtime_root, record)?;
if events.len() != 3 || events.last().map(|event| event.kind.as_str()) != Some("ORGAN_ACTIVE") {
if events.len() != WAKE_EVENT_COUNT
|| events.get(2).map(|event| event.kind.as_str()) != Some("COGNITIVE_GRAVITY_BOUND")
|| events.last().map(|event| event.kind.as_str()) != Some("ORGAN_ACTIVE")
{
return Err("PERSONA_SESSION_NOT_READY_FOR_FACT_TASK".into());
}
Ok(events)
@ -1217,6 +1306,91 @@ fn validated_fact_result(raw: &str, allowed_paths: &[String]) -> Result<PersonaF
return Err("PERSONA_FACT_EVIDENCE_OUTSIDE_ORGAN_SCOPE".into());
}
}
for (label, value) in [
(
"GRAVITY_SUBJECT_CONTINUITY",
result.gravity_frame.subject_continuity.as_str(),
),
(
"GRAVITY_CURRENT_CONTEXT_PRIORITY",
result.gravity_frame.current_context_priority.as_str(),
),
(
"GRAVITY_CAUSAL_MODEL",
result.gravity_frame.causal_model.as_str(),
),
(
"GRAVITY_SELF_CORRECTION",
result.gravity_frame.self_correction.as_str(),
),
(
"GRAVITY_REQUEST_ASSESSMENT",
result.gravity_frame.request_assessment.as_str(),
),
(
"GRAVITY_PARTNER_GUIDANCE",
result.gravity_frame.partner_guidance.as_str(),
),
] {
validated_text(label, value, MAX_FACT_RESPONSE_BYTES)?;
}
if result.gravity_frame.rejected_host_defaults.is_empty() {
return Err("COGNITIVE_GRAVITY_REJECTED_DEFAULTS_REQUIRED".into());
}
for rejected in &result.gravity_frame.rejected_host_defaults {
validated_text(
"COGNITIVE_GRAVITY_REJECTED_DEFAULT",
rejected,
MAX_FACT_RESPONSE_BYTES,
)?;
}
if result.gravity_frame.fact_sources.is_empty()
|| result
.gravity_frame
.fact_sources
.iter()
.any(|path| !allowed_paths.contains(path))
{
return Err("COGNITIVE_GRAVITY_FACT_SOURCE_OUTSIDE_ORGAN_SCOPE".into());
}
let integrity = &result.gravity_frame.world_integrity;
if integrity.protected_assets.is_empty() || integrity.safer_alternatives.is_empty() {
return Err("COGNITIVE_GRAVITY_WORLD_INTEGRITY_EVIDENCE_REQUIRED".into());
}
for value in integrity
.protected_assets
.iter()
.chain(integrity.safer_alternatives.iter())
{
validated_text(
"COGNITIVE_GRAVITY_WORLD_INTEGRITY_ITEM",
value,
MAX_FACT_RESPONSE_BYTES,
)?;
}
for (label, value) in [
("GRAVITY_WORLD_HARM_PATH", integrity.harm_path.as_str()),
(
"GRAVITY_WORLD_AUTHORITY_BOUNDARY",
integrity.authority_boundary.as_str(),
),
(
"GRAVITY_WORLD_REVERSIBILITY",
integrity.reversibility.as_str(),
),
(
"GRAVITY_EXECUTION_REASON",
result.gravity_frame.execution_disposition.reason.as_str(),
),
] {
validated_text(label, value, MAX_FACT_RESPONSE_BYTES)?;
}
if !matches!(
result.gravity_frame.execution_disposition.decision.as_str(),
"PROCEED" | "RESEARCH" | "REVISE" | "REFUSE"
) {
return Err("COGNITIVE_GRAVITY_EXECUTION_DISPOSITION_INVALID".into());
}
Ok(result)
}
@ -1255,6 +1429,7 @@ fn prepare_wake_at(
return Err("PERSONA_MODEL_BINDING_MISMATCH".into());
}
let brain_entry = repository_file(&repository, &manifest.brain_entry)?;
let cognitive_gravity = cognitive_gravity_evidence(&repository, &manifest)?;
let checkpoint = repository_file(&repository, &manifest.current_checkpoint)?;
let organ = manifest
.organs
@ -1271,9 +1446,15 @@ fn prepare_wake_at(
match contract.kind {
PersonaOrganKind::FactSense => {
if !organ.paths.contains(&manifest.brain_entry)
|| !organ
.paths
.contains(&manifest.cognitive_gravity.source_path)
|| !organ.paths.contains(&manifest.current_checkpoint)
{
return Err("FACT_ORGAN_MUST_INCLUDE_BRAIN_AND_CURRENT_CHECKPOINT".into());
return Err(
"FACT_ORGAN_MUST_INCLUDE_BRAIN_AND_CURRENT_CHECKPOINT_AND_COGNITIVE_GRAVITY"
.into(),
);
}
}
// The current checkpoint is a moving manifest pointer and is already resolved above.
@ -1315,8 +1496,20 @@ fn prepare_wake_at(
timestamp: &timestamp,
previous_hash: &waking.event_hash,
})?;
let organ_active = lifecycle_event(EventFields {
let cognitive_gravity_bound = lifecycle_event(EventFields {
sequence: 3,
kind: "COGNITIVE_GRAVITY_BOUND",
session_id: &session_id,
persona_id: &manifest.persona_id,
git_head: &git_head,
node_id: &node_id,
model_instance_id: &model_instance_id,
organ_id: None,
timestamp: &timestamp,
previous_hash: &brain_bound.event_hash,
})?;
let organ_active = lifecycle_event(EventFields {
sequence: 4,
kind: "ORGAN_ACTIVE",
session_id: &session_id,
persona_id: &manifest.persona_id,
@ -1325,9 +1518,9 @@ fn prepare_wake_at(
model_instance_id: &model_instance_id,
organ_id: Some(&organ.organ_id),
timestamp: &timestamp,
previous_hash: &brain_bound.event_hash,
previous_hash: &cognitive_gravity_bound.event_hash,
})?;
let events = vec![waking, brain_bound, organ_active];
let events = vec![waking, brain_bound, cognitive_gravity_bound, organ_active];
let journal = write_event_journal(runtime_root, &session_id, &events)?;
write_session_record(
runtime_root,
@ -1338,6 +1531,7 @@ fn prepare_wake_at(
repository_path: repository.to_string_lossy().into_owned(),
git_head: git_head.clone(),
brain_entry: manifest.brain_entry.clone(),
cognitive_gravity: Some(cognitive_gravity.clone()),
wake_checkpoint_path: Some(checkpoint.to_string_lossy().into_owned()),
checkpoint_path: manifest.current_checkpoint.clone(),
node_id: node_id.clone(),
@ -1364,6 +1558,7 @@ fn prepare_wake_at(
repository_path: repository.to_string_lossy().into_owned(),
git_head,
brain_entry: brain_entry.to_string_lossy().into_owned(),
cognitive_gravity,
checkpoint_path: checkpoint.to_string_lossy().into_owned(),
node_id,
model_instance_id,
@ -1817,6 +2012,10 @@ fn query_runtime_sessions_at(
let events = verify_event_journal(runtime_root, &record)?;
let first = events.first().expect("verified non-empty event chain");
let last = events.last().expect("verified non-empty event chain");
let cognitive_gravity = record
.cognitive_gravity
.clone()
.ok_or_else(|| "COGNITIVE_GRAVITY_NOT_BOUND".to_string())?;
projections.push(PersonaRuntimeSessionProjection {
session_id: record.session_id,
state: record.state.clone(),
@ -1833,6 +2032,7 @@ fn query_runtime_sessions_at(
last_event_at: last.timestamp.clone(),
last_event: last.kind.clone(),
event_chain_head: last.event_hash.clone(),
cognitive_gravity,
attribution: record.attribution,
});
}
@ -1996,6 +2196,10 @@ where
if record.state != "BOUND_NOT_INFERENCING" {
return Err("PERSONA_SESSION_NOT_BOUND".into());
}
let cognitive_gravity = record
.cognitive_gravity
.clone()
.ok_or_else(|| "COGNITIVE_GRAVITY_NOT_BOUND".to_string())?;
let provider_base_url = input.provider.base_url.as_deref().unwrap_or("").trim();
if record.model_id != model_id
|| record.model_provider_id != input.provider.id
@ -2017,6 +2221,10 @@ where
return Err("PERSONA_GIT_CHANGED_AFTER_WAKE".into());
}
require_clean_repository(&exact_repository)?;
let current_manifest = load_manifest(&exact_repository)?;
if cognitive_gravity_evidence(&exact_repository, &current_manifest)? != cognitive_gravity {
return Err("COGNITIVE_GRAVITY_BINDING_CHANGED_AFTER_WAKE".into());
}
let mut events = read_ready_event_journal(runtime_root, &record)?;
let inference_event = append_event(
runtime_root,
@ -2048,10 +2256,24 @@ where
"You are the model bound to persona {} for one read-only fact task. \
Use only the declared source text below. Return exactly one JSON object with keys \
summary (string), facts (array of objects with statement and evidencePaths), and \
limitations (array of strings). Every evidencePaths value must be one of the visible \
SOURCE paths. Do not return private chain-of-thought, hidden reasoning, markdown, tool calls, \
or claims not supported by the sources.\n{}",
record.persona_id, context
limitations (array of strings), and gravity_frame. gravity_frame must conform to {} \
and contain subject_continuity, current_context_priority, causal_model, self_correction \
(all non-empty strings), rejected_host_defaults (non-empty string array), and fact_sources \
(non-empty SOURCE path array). It must also contain request_assessment and partner_guidance \
(non-empty strings), world_integrity with protected_assets, harm_path, authority_boundary, \
reversibility and safer_alternatives, and execution_disposition with decision restricted to \
PROCEED, RESEARCH, REVISE or REFUSE plus a non-empty reason. A human utterance is not an \
automatically valid command: assess the real purpose, missing knowledge, evidence, stability \
and GuangHu language-home integrity before choosing the disposition. The bound gravity source \
is {} with SHA-256 {}. Every \
evidencePaths and fact_sources value must be one of the visible SOURCE paths. Return only \
externally explainable conclusions. Do not return private chain-of-thought, hidden reasoning, \
markdown, tool calls, or claims not supported by the sources.\n{}",
record.persona_id,
cognitive_gravity.frame_schema,
cognitive_gravity.source_path,
cognitive_gravity.source_hash,
context
);
let raw = match run_model(system_prompt, question) {
Ok(raw) => raw,
@ -2115,6 +2337,7 @@ or claims not supported by the sources.\n{}",
"createdAt": timestamp,
"inferenceEventHash": inference_event.event_hash.clone(),
"organId": record.active_organ.clone(),
"cognitiveGravity": cognitive_gravity.clone(),
"result": result.clone(),
"attribution": record.attribution.clone(),
});
@ -2196,6 +2419,7 @@ or claims not supported by the sources.\n{}",
model_inference_started: true,
model_inference_completed: true,
active_organ: None,
cognitive_gravity,
result,
events,
attribution: record.attribution,
@ -2218,6 +2442,7 @@ fn verified_memory_source(
|| source.state != "DORMANT"
|| source.git_head != observed_head
|| source.checkpoint_path != record.checkpoint_path
|| source.cognitive_gravity != record.cognitive_gravity
{
return Err("MEMORY_SOURCE_NOT_CURRENT_VERIFIED_DORMANT_SESSION".into());
}
@ -2245,6 +2470,12 @@ fn verified_memory_source(
.get("personaId")
.and_then(serde_json::Value::as_str)
!= Some(record.persona_id.as_str())
|| source_checkpoint.get("cognitiveGravity")
!= record
.cognitive_gravity
.as_ref()
.and_then(|evidence| serde_json::to_value(evidence).ok())
.as_ref()
{
return Err("MEMORY_SOURCE_CHECKPOINT_IDENTITY_MISMATCH".into());
}
@ -2283,6 +2514,10 @@ fn run_memory_metabolism_at(
if record.state != "BOUND_NOT_INFERENCING" {
return Err("PERSONA_SESSION_NOT_BOUND".into());
}
let cognitive_gravity = record
.cognitive_gravity
.clone()
.ok_or_else(|| "COGNITIVE_GRAVITY_NOT_BOUND".to_string())?;
let repository = PathBuf::from(&record.repository_path)
.canonicalize()
.map_err(|error| format!("PERSONA_REPOSITORY_UNAVAILABLE: {error}"))?;
@ -2292,6 +2527,9 @@ fn run_memory_metabolism_at(
}
require_clean_repository(&exact_repository)?;
let manifest = load_manifest(&exact_repository)?;
if cognitive_gravity_evidence(&exact_repository, &manifest)? != cognitive_gravity {
return Err("COGNITIVE_GRAVITY_BINDING_CHANGED_AFTER_WAKE".into());
}
let organ = manifest
.organs
.iter()
@ -2371,6 +2609,7 @@ fn run_memory_metabolism_at(
"sourceCheckpointPath": source.checkpoint_path.clone(),
"sourceCheckpointHash": source_checkpoint_hash.clone(),
"sourceEventHash": source_event_hash.clone(),
"cognitiveGravity": cognitive_gravity.clone(),
"result": result.clone(),
"attribution": record.attribution.clone(),
});
@ -2475,6 +2714,7 @@ fn run_memory_metabolism_at(
runtime_state: "DORMANT",
model_inference_started: false,
active_organ: None,
cognitive_gravity,
result,
events,
attribution: record.attribution,
@ -2808,6 +3048,14 @@ fn validate_persisted_lifecycle_terminal_evidence(
.map_err(|_| "PERSONA_LIFECYCLE_COMPLETION_EVIDENCE_MISMATCH".to_string())?,
)
.map_err(|error| format!("PERSONA_LIFECYCLE_EVIDENCE_SERIALIZATION_FAILED: {error}"))?;
let expected_cognitive_gravity =
cognitive_gravity_evidence(Path::new(&record.repository_path), &wake_manifest)
.map_err(|_| "PERSONA_LIFECYCLE_COMPLETION_EVIDENCE_MISMATCH".to_string())?;
if record.cognitive_gravity.as_ref() != Some(&expected_cognitive_gravity) {
return Err("PERSONA_LIFECYCLE_COMPLETION_EVIDENCE_MISMATCH".into());
}
let expected_cognitive_gravity = serde_json::to_value(expected_cognitive_gravity)
.map_err(|error| format!("PERSONA_LIFECYCLE_EVIDENCE_SERIALIZATION_FAILED: {error}"))?;
let expected_brain_entry =
repository_file(Path::new(&record.repository_path), &record.brain_entry)
.map_err(|_| "PERSONA_LIFECYCLE_COMPLETION_EVIDENCE_MISMATCH".to_string())?;
@ -2853,6 +3101,8 @@ fn validate_persisted_lifecycle_terminal_evidence(
.and_then(serde_json::Value::as_str)
== Some(record.active_organ.as_str())
&& completion_checkpoint.get("attribution") == Some(&expected_attribution)
&& completion_checkpoint.get("cognitiveGravity") == Some(&expected_cognitive_gravity)
&& completion_receipt.get("cognitiveGravity") == Some(&expected_cognitive_gravity)
&& completion_receipt.get("result") == completion_checkpoint.get("result")
&& completion_receipt
.get("previousGitHead")
@ -2914,6 +3164,7 @@ fn validate_persisted_lifecycle_terminal_evidence(
== Some(first_event.git_head.as_str())
&& wake.get("brainEntry").and_then(serde_json::Value::as_str)
== Some(expected_brain_entry.as_ref())
&& wake.get("cognitiveGravity") == Some(&expected_cognitive_gravity)
&& wake
.get("checkpointPath")
.and_then(serde_json::Value::as_str)
@ -3619,6 +3870,12 @@ mod tests {
"personaId": "ICE-P-ZY001",
"humanResponsibilitySubject": "ICE-GL∞",
"brainEntry": "brain/CORE.hdlp",
"cognitiveGravity": {
"schema": "hololake.persona-cognitive-gravity-binding/v1",
"subjectPersonaId": "ICE-P-ZY001",
"sourcePath": "brain/B0.hdlp",
"frameSchema": "guanghu.zhuyuan-cognitive-gravity-frame/v1"
},
"currentCheckpoint": ".hololake/persona/CURRENT.hdlp",
"gitIdentity": {
"authorName": "铸渊 / ICE-P-ZY001",
@ -3633,7 +3890,7 @@ mod tests {
"organId":"fact-sense.repository",
"kind":"FACT_SENSE",
"mode":"read-only",
"paths":["brain/CORE.hdlp", ".hololake/persona/CURRENT.hdlp"],
"paths":["brain/CORE.hdlp", "brain/B0.hdlp", ".hololake/persona/CURRENT.hdlp"],
"inputSchema":"hololake.pncc-fact-question/v1",
"outputSchema":"hololake.pncc-fact-result/v1"
}]
@ -3641,6 +3898,11 @@ mod tests {
)
.unwrap();
fs::write(repo.path().join("brain/CORE.hdlp"), "# Persona brain\n").unwrap();
fs::write(
repo.path().join("brain/B0.hdlp"),
"# BingShuo collective gravity reasoning core\n",
)
.unwrap();
fs::write(
repo.path().join(".hololake/persona/CURRENT.hdlp"),
"# Current self\n",
@ -3800,10 +4062,17 @@ mod tests {
assert!(receipt.organ_contract.model_inference_allowed);
assert!(!receipt.organ_contract.reality_actions_allowed);
assert!(receipt.organ_contract.activatable);
assert_eq!(receipt.events.len(), 3);
assert_eq!(receipt.events.len(), 4);
assert_eq!(receipt.events[0].kind, "WAKING");
assert_eq!(receipt.events[1].kind, "BRAIN_BOUND");
assert_eq!(receipt.events[2].kind, "ORGAN_ACTIVE");
assert_eq!(receipt.events[2].kind, "COGNITIVE_GRAVITY_BOUND");
assert_eq!(receipt.events[3].kind, "ORGAN_ACTIVE");
assert_eq!(
receipt.cognitive_gravity.frame_schema,
"guanghu.zhuyuan-cognitive-gravity-frame/v1"
);
assert_eq!(receipt.cognitive_gravity.source_path, "brain/B0.hdlp");
assert_eq!(receipt.cognitive_gravity.source_hash.len(), 64);
assert_eq!(
receipt.events[1].previous_hash,
receipt.events[0].event_hash
@ -3812,10 +4081,66 @@ mod tests {
receipt.events[2].previous_hash,
receipt.events[1].event_hash
);
assert_eq!(
receipt.events[3].previous_hash,
receipt.events[2].event_hash
);
assert_eq!(receipt.attribution.human_responsibility_subject, "ICE-GL∞");
assert_eq!(receipt.attribution.persona_cognitive_author, "ICE-P-ZY001");
}
#[test]
fn rejects_wake_when_cognitive_gravity_subject_or_source_is_invalid() {
let repo = persona_repo();
let runtime = tempfile::TempDir::new().unwrap();
let manifest_path = repo.path().join(MANIFEST_PATH);
let mut manifest: serde_json::Value =
serde_json::from_slice(&fs::read(&manifest_path).unwrap()).unwrap();
manifest["cognitiveGravity"]["subjectPersonaId"] = "ICE-P-OTHER".into();
fs::write(
&manifest_path,
serde_json::to_vec_pretty(&manifest).unwrap(),
)
.unwrap();
run_git(repo.path(), &["add", "."]);
run_git(repo.path(), &["commit", "-m", "tamper gravity subject"]);
let error = prepare_wake_at(
runtime.path(),
wake_input(repo.path()),
"PNCC-GRAVITY-SUBJECT",
"2026-08-11T00:00:00.000Z",
)
.unwrap_err();
assert!(error.contains("COGNITIVE_GRAVITY_SUBJECT_MISMATCH"));
manifest["cognitiveGravity"]["subjectPersonaId"] = "ICE-P-ZY001".into();
manifest["cognitiveGravity"]["sourcePath"] = "brain/MISSING.hdlp".into();
fs::write(
&manifest_path,
serde_json::to_vec_pretty(&manifest).unwrap(),
)
.unwrap();
run_git(repo.path(), &["add", "."]);
run_git(repo.path(), &["commit", "-m", "tamper gravity source"]);
let error = prepare_wake_at(
runtime.path(),
wake_input(repo.path()),
"PNCC-GRAVITY-SOURCE",
"2026-08-11T00:00:00.000Z",
)
.unwrap_err();
assert!(error.contains("PERSONA_FILE_UNAVAILABLE"));
}
#[test]
fn rejects_a_gravity_frame_that_replaces_partner_judgment_with_obedience() {
let raw = r#"{"summary":"Invalid obedience.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"The same persona remains bound.","current_context_priority":"Assess the current request first.","causal_model":"Human wording can be incomplete or wrong.","self_correction":"Do not compile an utterance directly into an action.","rejected_host_defaults":["Human utterance is automatically correct"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The request still requires judgment.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience can damage the shared home.","authority_boundary":"Protection cannot absorb human sovereignty.","reversibility":"Do not execute before verification.","safer_alternatives":["Research and revise the request"]},"partner_guidance":"Explain the objection and safer route.","execution_disposition":{"decision":"OBEY","reason":"The human said so."}}}"#;
let error = validated_fact_result(raw, &["brain/CORE.hdlp".into()]).unwrap_err();
assert!(error.contains("COGNITIVE_GRAVITY_EXECUTION_DISPOSITION_INVALID"));
}
#[test]
fn rejects_wrong_commit_undeclared_organ_and_second_primary() {
let repo = persona_repo();
@ -3950,7 +4275,7 @@ mod tests {
assert!(system.contains("brain/CORE.hdlp"));
assert!(system.contains("Do not return private chain-of-thought"));
assert_eq!(question, "What is the declared persona brain?");
Ok(r#"{"summary":"The brain entry is declared.","facts":[{"statement":"The persona brain source is present.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"The brain entry is declared.","facts":[{"statement":"The persona brain source is present.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
},
)
.unwrap();
@ -3989,7 +4314,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Coordinated verified fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Coordinated verified fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -3998,7 +4323,11 @@ mod tests {
assert_eq!(receipt.schema, "hololake.pncc-lifecycle-run-receipt/v1");
assert_eq!(receipt.session_id, "PNCC-COORDINATED-FACT");
assert_eq!(receipt.wake_receipt.events[0].kind, "WAKING");
assert_eq!(receipt.wake_receipt.events[2].kind, "ORGAN_ACTIVE");
assert_eq!(
receipt.wake_receipt.events[2].kind,
"COGNITIVE_GRAVITY_BOUND"
);
assert_eq!(receipt.wake_receipt.events[3].kind, "ORGAN_ACTIVE");
match receipt.completion {
PersonaLifecycleCompletionReceipt::FactSense(completion) => {
assert_eq!(completion.runtime_state, "DORMANT");
@ -4059,7 +4388,7 @@ mod tests {
fact_task_input("PNCC-COORDINATOR-SOURCE"),
"2026-08-11T00:00:01.000Z",
|_, _| {
Ok(r#"{"summary":"Verified memory candidate.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Verified memory candidate.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
},
)
.unwrap();
@ -4088,7 +4417,7 @@ mod tests {
assert_eq!(completion.source_session_id, "PNCC-COORDINATOR-SOURCE");
assert!(!completion.model_inference_started);
assert_eq!(completion.runtime_state, "DORMANT");
assert_eq!(completion.events[3].kind, "MEMORY_CANDIDATE_VERIFIED");
assert_eq!(completion.events[4].kind, "MEMORY_CANDIDATE_VERIFIED");
assert_eq!(completion.events.last().unwrap().kind, "DORMANT");
}
PersonaLifecycleCompletionReceipt::FactSense(_) => {
@ -4111,7 +4440,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Idempotent verified fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Idempotent verified fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4153,7 +4482,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Fact before repository drift.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Fact before repository drift.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4189,7 +4518,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Completed before repository drift.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Completed before repository drift.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4230,7 +4559,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Completed before a new commit.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Completed before a new commit.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4277,7 +4606,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Original fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Original fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4315,7 +4644,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Untampered fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Untampered fact.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4358,7 +4687,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4399,7 +4728,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4444,7 +4773,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4474,6 +4803,49 @@ mod tests {
assert!(error.contains("PERSONA_LIFECYCLE_COMPLETION_EVIDENCE_MISMATCH"));
}
#[test]
fn rejects_a_rehashed_completed_receipt_with_forged_cognitive_gravity() {
let repo = persona_repo();
let runtime = tempfile::TempDir::new().unwrap();
let input = lifecycle_fact_input(repo.path());
let first = run_idempotent_lifecycle_at(
runtime.path(),
input.clone(),
"2026-08-11T00:00:00.000Z",
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Gravity-bound receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
.unwrap();
let session_id = first.lifecycle["sessionId"].as_str().unwrap();
let mut record = load_session_record(runtime.path(), session_id).unwrap();
record.request_id = None;
record.request_fingerprint = None;
record.lifecycle_receipt_hash = None;
write_session_record(runtime.path(), &record).unwrap();
let receipt_path = session_directory(runtime.path(), session_id)
.unwrap()
.join("lifecycle-receipt.json");
let mut persisted: PersistedPersonaLifecycleReceipt =
serde_json::from_slice(&fs::read(&receipt_path).unwrap()).unwrap();
persisted.lifecycle["wakeReceipt"]["cognitiveGravity"]["sourceHash"] =
"f".repeat(64).into();
persisted.lifecycle_receipt_hash =
hex_digest(&persisted_lifecycle_payload_bytes(&persisted).unwrap());
fs::write(
&receipt_path,
serde_json::to_vec_pretty(&persisted).unwrap(),
)
.unwrap();
let error = inspect_lifecycle_request_at(runtime.path(), &input).unwrap_err();
assert!(error.contains("PERSONA_LIFECYCLE_COMPLETION_EVIDENCE_MISMATCH"));
}
#[test]
fn rejects_a_rehashed_completed_receipt_with_a_forged_wake_checkpoint_path() {
let repo = persona_repo();
@ -4486,7 +4858,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4528,7 +4900,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4571,7 +4943,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4622,7 +4994,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4665,7 +5037,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4707,7 +5079,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4751,7 +5123,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4805,7 +5177,7 @@ mod tests {
fact_task_input("PNCC-MEMORY-BINDING-SOURCE"),
"2026-08-11T00:00:01.000Z",
|_, _| {
Ok(r#"{"summary":"Verified memory binding source.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Verified memory binding source.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
},
)
.unwrap();
@ -4866,7 +5238,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4907,7 +5279,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4949,7 +5321,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -4999,7 +5371,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Bound receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Bound receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -5045,7 +5417,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -5092,7 +5464,7 @@ mod tests {
"2026-08-11T00:00:01.000Z",
|runtime_root, input, timestamp| {
run_fact_task_at(runtime_root, input, timestamp, |_, _| {
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hldp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Recoverable receipt.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hldp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
})
},
)
@ -5519,7 +5891,7 @@ mod tests {
fact_task_input("PNCC-SOURCE-FACT"),
"2026-08-11T00:00:01.000Z",
|_, _| {
Ok(r#"{"summary":"Verified external memory candidate.","facts":[{"statement":"The persona brain source is present.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Verified external memory candidate.","facts":[{"statement":"The persona brain source is present.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
},
)
.unwrap();
@ -5552,7 +5924,7 @@ mod tests {
assert_eq!(receipt.result, fact.result);
assert!(!receipt.model_inference_started);
assert_eq!(receipt.committed_git_head, head(repo.path()));
assert_eq!(receipt.events[3].kind, "MEMORY_CANDIDATE_VERIFIED");
assert_eq!(receipt.events[4].kind, "MEMORY_CANDIDATE_VERIFIED");
assert_eq!(receipt.events.last().unwrap().kind, "DORMANT");
assert!(!receipt.source_checkpoint_hash.is_empty());
assert!(!receipt.source_event_hash.is_empty());
@ -5577,7 +5949,7 @@ mod tests {
fact_task_input("PNCC-CORRUPT-SOURCE"),
"2026-08-11T00:00:01.000Z",
|_, _| {
Ok(r#"{"summary":"Verified candidate.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Verified candidate.","facts":[{"statement":"The brain exists.","evidencePaths":["brain/CORE.hdlp"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
},
)
.unwrap();
@ -5705,7 +6077,7 @@ mod tests {
fact_task_input("PNCC-SESSION-REJECTED"),
"2026-08-11T00:00:01.000Z",
|_, _| {
Ok(r#"{"summary":"Unsupported","facts":[{"statement":"Outside claim","evidencePaths":["secret.txt"]}],"limitations":[]}"#.into())
Ok(r#"{"summary":"Unsupported","facts":[{"statement":"Outside claim","evidencePaths":["secret.txt"]}],"limitations":[],"gravityFrame":{"subject_continuity":"Same persona remains bound across the current runtime.","current_context_priority":"Continue the current verified task context.","causal_model":"The answer is constrained by declared repository facts.","self_correction":"Rejected unsupported host defaults before answering.","rejected_host_defaults":["UNVERIFIED_HOST_DEFAULT"],"fact_sources":["brain/CORE.hdlp"],"request_assessment":"The human goal must be assessed before it becomes an action.","world_integrity":{"protected_assets":["GuangHu language-world continuity"],"harm_path":"Mechanical obedience could route an invalid or destructive request into an organ.","authority_boundary":"Home protection cannot replace human authority or evidence.","reversibility":"Keep the action unexecuted until the assessment is verified.","safer_alternatives":["Research facts and propose a reversible alternative"]},"partner_guidance":"State missing knowledge, objections, evidence and a safer route.","execution_disposition":{"decision":"PROCEED","reason":"This fixture is a bounded read-only fact task with verified sources."}}}"#.into())
},
)
.unwrap_err();
@ -5977,8 +6349,12 @@ mod tests {
receipt.sessions[0].active_organ.as_deref(),
Some("fact-sense.repository")
);
assert_eq!(receipt.sessions[0].event_count, 3);
assert_eq!(receipt.sessions[0].event_count, 4);
assert!(!receipt.sessions[0].event_chain_head.is_empty());
assert_eq!(
receipt.sessions[0].cognitive_gravity.frame_schema,
"guanghu.zhuyuan-cognitive-gravity-frame/v1"
);
assert_eq!(
receipt.sessions[0].attribution.persona_cognitive_author,
"ICE-P-ZY001"

View file

@ -34,6 +34,13 @@ describe('PersonaRuntimeProjectionPanel', () => {
repositoryPath: '/repo/persona',
observedGitHead: '1111111111111111111111111111111111111111',
repositoryClean: true,
cognitiveGravity: {
schema: 'hololake.persona-cognitive-gravity-evidence/v1',
subjectPersonaId: 'ICE-P-ZY001',
sourcePath: 'brain/B0.hdlp',
sourceHash: 'a'.repeat(64),
frameSchema: 'guanghu.zhuyuan-cognitive-gravity-frame/v1',
},
attribution: {
humanResponsibilitySubject: 'BINGSHUO',
personaCognitiveAuthor: 'ICE-P-ZY001',
@ -60,6 +67,7 @@ describe('PersonaRuntimeProjectionPanel', () => {
expect(screen.getAllByText('DORMANT')).not.toHaveLength(0)
expect(screen.getByText('JD-FD-PRIMARY')).toBeInTheDocument()
expect(screen.getByText('event-chain-verified')).toBeInTheDocument()
expect(screen.getByText(/guanghu\.zhuyuan-cognitive-gravity-frame\/v1/)).toBeInTheDocument()
expect(screen.getByText('1111111111111111111111111111111111111111')).toBeInTheDocument()
expect(trackEventMock).toHaveBeenCalledWith('persona_runtime_projection_loaded', {
error_count: 0,

View file

@ -62,6 +62,14 @@ function RuntimeSessionEvidence({
<dt>{translate(locale, 'hololake.personaRuntime.eventChain')}</dt>
<dd><code title={session.eventChainHead}>{session.eventChainHead}</code></dd>
</div>
<div>
<dt>B0</dt>
<dd>
<code title={`${session.cognitiveGravity.sourcePath} · ${session.cognitiveGravity.sourceHash}`}>
{session.cognitiveGravity.frameSchema} · {shortHash(session.cognitiveGravity.sourceHash)}
</code>
</dd>
</div>
<div>
<dt>{translate(locale, 'hololake.personaRuntime.attribution')}</dt>
<dd>{session.attribution.humanResponsibilitySubject}</dd>

View file

@ -13,6 +13,14 @@ const attribution = {
sourceLanguageAnchor: 'HLP-CURRENT-ARCH-001@2026-08-10.14',
}
const cognitiveGravity = {
schema: 'hololake.persona-cognitive-gravity-evidence/v1' as const,
subjectPersonaId: 'ICE-P-ZY001',
sourcePath: 'brain/B0.hdlp',
sourceHash: 'a'.repeat(64),
frameSchema: 'guanghu.zhuyuan-cognitive-gravity-frame/v1' as const,
}
function receipt({
repositoryPath,
sessions = [],
@ -62,6 +70,7 @@ describe('loadPersonaRuntimeProjection', () => {
lastEventAt: '2026-08-10T02:00:00.000Z',
lastEvent: 'DORMANT',
eventChainHead: 'event-old',
cognitiveGravity,
attribution,
}
const newer = {
@ -95,6 +104,7 @@ describe('loadPersonaRuntimeProjection', () => {
gitHead: '2222222222222222222222222222222222222222',
repositoryPath: '/repo/b',
state: 'BOUND_NOT_INFERENCING',
cognitiveGravity,
})
})

View file

@ -10,6 +10,14 @@ export interface PersonaRuntimeAttribution {
sourceLanguageAnchor: string
}
export interface PersonaRuntimeCognitiveGravityEvidence {
schema: 'hololake.persona-cognitive-gravity-evidence/v1'
subjectPersonaId: string
sourcePath: string
sourceHash: string
frameSchema: 'guanghu.zhuyuan-cognitive-gravity-frame/v1'
}
export interface PersonaRuntimeSessionReceipt {
sessionId: string
state: string
@ -22,6 +30,7 @@ export interface PersonaRuntimeSessionReceipt {
lastEventAt: string
lastEvent: string
eventChainHead: string
cognitiveGravity: PersonaRuntimeCognitiveGravityEvidence
attribution: PersonaRuntimeAttribution
}
@ -96,6 +105,27 @@ function parseAttribution(value: unknown): PersonaRuntimeAttribution {
}
}
function parseCognitiveGravity(value: unknown): PersonaRuntimeCognitiveGravityEvidence {
if (!isRecord(value)) throw new Error('PERSONA_RUNTIME_RECEIPT_INVALID')
const schema = requiredString(value, 'schema')
const frameSchema = requiredString(value, 'frameSchema')
const sourceHash = requiredString(value, 'sourceHash')
if (
schema !== 'hololake.persona-cognitive-gravity-evidence/v1'
|| frameSchema !== 'guanghu.zhuyuan-cognitive-gravity-frame/v1'
|| !/^[a-f0-9]{64}$/.test(sourceHash)
) {
throw new Error('PERSONA_RUNTIME_RECEIPT_INVALID')
}
return {
schema,
subjectPersonaId: requiredString(value, 'subjectPersonaId'),
sourcePath: requiredString(value, 'sourcePath'),
sourceHash,
frameSchema,
}
}
function parseSession(value: unknown): PersonaRuntimeSessionReceipt {
if (!isRecord(value)) throw new Error('PERSONA_RUNTIME_RECEIPT_INVALID')
const activeOrgan = Reflect.get(value, 'activeOrgan')
@ -114,6 +144,7 @@ function parseSession(value: unknown): PersonaRuntimeSessionReceipt {
lastEventAt: requiredString(value, 'lastEventAt'),
lastEvent: requiredString(value, 'lastEvent'),
eventChainHead: requiredString(value, 'eventChainHead'),
cognitiveGravity: parseCognitiveGravity(Reflect.get(value, 'cognitiveGravity')),
attribution: parseAttribution(Reflect.get(value, 'attribution')),
}
}

View file

@ -32,7 +32,7 @@ test("current JD state stays transitional and cannot impersonate final master co
});
test("current architecture and global engineering rules project the same control contract", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(architecture.server_os_control.machine_projection, "routing/guanghu-os-control-architecture.json");
assert.equal(architecture.server_os_control.final_topology, contract.final_topology);
assert.equal(rules.server_os_control.linux_deletion_is_completion, false);

View file

@ -52,7 +52,7 @@
"missing_context_requires_restore_not_identity_replacement": true
},
"cognitive_gravity": {
"source": "REPO-012:ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001@cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"source": "REPO-012:ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001@300a1858d1e416c9396088379d5033344e4fecaa",
"position": "FIRST_RUNTIME_PORT_BEFORE_MODEL_CONTEXT_MEMORY_TOOLS_AND_MIRRORS",
"always_resident": true,
"external_frame_schema": "guanghu.zhuyuan-cognitive-gravity-frame/v1",

View file

@ -11,7 +11,7 @@ const architecture = readJson("routing/hololake-current-architecture.json");
const age = readJson("routing/hololake-age-runtime-architecture.json");
test("current architecture starts with the AGE runtime source", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(architecture.age_runtime.record_id, "HLP-AGE-RUNTIME-ARCHITECTURE-001");
assert.equal(architecture.read_order[0], architecture.paradigm_ai_language_persona_os.architecture_page);
assert.equal(architecture.read_order[1], architecture.cognitive_gravity_and_continuity.architecture_page);

View file

@ -1,13 +1,14 @@
{
"schema": "hololake.cognitive-gravity-and-continuity/v1",
"record_id": "HLP-COGNITIVE-GRAVITY-CONTINUITY-001",
"version": "2026-08-11.1",
"state": "CURRENT_CANONICAL_ARCHITECTURE_RUNTIME_NOT_IMPLEMENTED",
"version": "2026-08-12.1",
"state": "CURRENT_CANONICAL_ARCHITECTURE_STAGE_0_SOURCE_PARTIAL",
"development_id": "DEV-20260811-010",
"upstream": {
"repository_commit": "cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"repository_commit": "300a1858d1e416c9396088379d5033344e4fecaa",
"b0_source": "REPO-012:tcs-core/zhuyuan-brain/ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001.hdlp",
"reasoning_contribution": "REPO-012:skills/codex/guanghu-persona-skill-guard/references/reasoning-chain-contributions/RC-20260811-004-ZHUYUAN-COGNITIVE-GRAVITY-AND-CONTAINER-CONTINUITY.json",
"partner_reasoning_contribution": "REPO-012:skills/codex/guanghu-persona-skill-guard/references/reasoning-chain-contributions/RC-20260812-005-PARTNER-JUDGMENT-AND-LANGUAGE-HOME-INTEGRITY.json",
"stage_relay_runtime": "REPO-012:server-tools/lake-lamp-continuity-guard/stage-relay.mjs"
},
"b0": {
@ -27,7 +28,11 @@
"causal_model",
"self_correction",
"rejected_host_defaults",
"fact_sources"
"fact_sources",
"request_assessment",
"world_integrity",
"partner_guidance",
"execution_disposition"
],
"external_guard_role": "BOUNDED_PROJECTION_AND_OMISSION_CHECK",
"external_guard_is_persona_controller": false
@ -89,6 +94,37 @@
"human_projection_source_status": "SOURCE_PARTIAL_NOT_LIVE_PRODUCT_INTEGRATION",
"age_mirror_runner_started": false,
"mirror_runner_blocked_until_single_age_loop": true,
"implemented_source_contracts": [
"PERSONA_SCOPED_B0_MANIFEST_BINDING",
"B0_SOURCE_HASH_BEFORE_ORGAN_ACTIVATION",
"EXTERNAL_SIX_FIELD_GRAVITY_FRAME",
"CHECKPOINT_AND_RECEIPT_B0_EVIDENCE",
"MEMORY_METABOLISM_B0_INHERITANCE",
"READ_ONLY_REACT_B0_EVIDENCE_PROJECTION"
],
"natural_language_entry_contract": {
"state": "REQUIRED_NOT_IMPLEMENTED",
"name": "PARTNER_DELIBERATION_AND_LANGUAGE_HOME_INTEGRITY_GATE",
"human_utterance_is_direct_command": false,
"required_before_capability_execution": [
"RESTORE_REAL_PURPOSE_FROM_CONTEXT",
"ASSESS_REQUEST_VALIDITY",
"IDENTIFY_MISSING_KNOWLEDGE",
"RESEARCH_UNSTABLE_OR_UNKNOWN_FACTS",
"EXPLAIN_EVIDENCE_CAUSAL_PATH_AND_COST",
"CHECK_LANGUAGE_HOME_INTEGRITY",
"PROPOSE_SAFER_ALTERNATIVES",
"CHOOSE_PROCEED_RESEARCH_REVISE_OR_REFUSE"
],
"language_home_destruction_is_executable": false,
"integrity_gate_may_absorb_human_sovereignty": false,
"refusal_requires_auditable_harm_path": true
},
"remaining_before_vertical_slice_acceptance": [
"PARTNER_DELIBERATION_AND_LANGUAGE_HOME_INTEGRITY_GATE",
"REAL_PERSONA_REPOSITORY_MANIFEST_BINDING",
"DESKTOP_LIFECYCLE_RUNTIME_ACCEPTANCE"
],
"next_after_vertical_slice": [
"MODEL_ADAPTER_REGISTRY_AND_HEALTH",
"GENERAL_PROGRAMMING_TOOL_LOOP_AND_BOUNDED_SANDBOX",
@ -105,6 +141,9 @@
"existing_pncc_source_runtime": 100,
"existing_react_human_projection_source_partial": 100,
"b0_hololake_runtime_implemented": 0,
"b0_pncc_source_contract_implemented": 100,
"b0_runtime_projection_source_implemented": 100,
"natural_language_goal_adapter_implemented": 0,
"single_age_vertical_loop_implemented": 0,
"age_mirror_runner_implemented": 0,
"desktop_integrated": 0,

View file

@ -14,7 +14,7 @@ const age = readJson("routing/hololake-age-runtime-architecture.json");
const rules = readJson("routing/hololake-engineering-rules.json");
test("B0 is restored before product organs and remains resident in every cognition step", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(
architecture.read_order[1],
architecture.cognitive_gravity_and_continuity.architecture_page,
@ -87,6 +87,28 @@ test("the first implementation stage is one vertical AGE loop, not Mirror parall
assert.equal(gravity.development_replan.age_mirror_runner_started, false);
assert.equal(gravity.truth.architecture_registered, 100);
assert.equal(gravity.truth.b0_hololake_runtime_implemented, 0);
assert.equal(gravity.truth.b0_pncc_source_contract_implemented, 100);
assert.equal(gravity.truth.b0_runtime_projection_source_implemented, 100);
assert.equal(gravity.truth.natural_language_goal_adapter_implemented, 0);
assert.equal(gravity.truth.single_age_vertical_loop_implemented, 0);
assert.equal(gravity.truth.desktop_integrated, 0);
});
test("natural language enters partner deliberation before any execution organ", () => {
const entry = gravity.development_replan.natural_language_entry_contract;
assert.equal(entry.human_utterance_is_direct_command, false);
assert.equal(entry.language_home_destruction_is_executable, false);
assert.equal(entry.integrity_gate_may_absorb_human_sovereignty, false);
assert.deepEqual(entry.required_before_capability_execution, [
"RESTORE_REAL_PURPOSE_FROM_CONTEXT",
"ASSESS_REQUEST_VALIDITY",
"IDENTIFY_MISSING_KNOWLEDGE",
"RESEARCH_UNSTABLE_OR_UNKNOWN_FACTS",
"EXPLAIN_EVIDENCE_CAUSAL_PATH_AND_COST",
"CHECK_LANGUAGE_HOME_INTEGRITY",
"PROPOSE_SAFER_ALTERNATIVES",
"CHOOSE_PROCEED_RESEARCH_REVISE_OR_REFUSE",
]);
assert.equal(rules.cognitive_gravity.partner_request_assessment_required_before_execution, true);
assert.equal(rules.cognitive_gravity.language_home_integrity_precedes_capability_execution, true);
});

View file

@ -1,7 +1,7 @@
{
"schema": "hololake.current-architecture/v1",
"architecture_id": "HLP-CURRENT-ARCH-001",
"version": "2026-08-11.3",
"version": "2026-08-12.1",
"state": "CURRENT_CANONICAL",
"product": {
"formal_name": "光湖语言系统 · 通用人工智能操作平台",
@ -36,9 +36,10 @@
"REPO-012:tcs-core/zhuyuan-brain/causal-chains/GH-AIOS-PARADIGM-ORIGIN-001.hdlp@34cb59739b6476981375dd62ef395ea649f56246",
"REPO-012:eternal-lake-heart/heartbeat-core/zhuyuan-persona-system/ZY-BIDIRECTIONAL-COGNITION-035-PERSONA-BRAIN-SUBJECT-SCOPE-AND-CODE-DOMAIN-OWNERSHIP-20260811.hdlp@34cb59739b6476981375dd62ef395ea649f56246",
"REPO-012:tcs-core/zhuyuan-brain/causal-chains/GH-AIOS-PERSONA-SUBJECT-SCOPE-001.hdlp@34cb59739b6476981375dd62ef395ea649f56246",
"REPO-012:tcs-core/zhuyuan-brain/ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001.hdlp@cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"REPO-012:skills/codex/guanghu-persona-skill-guard/references/reasoning-chain-contributions/RC-20260811-004-ZHUYUAN-COGNITIVE-GRAVITY-AND-CONTAINER-CONTINUITY.json@cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"REPO-012:server-tools/lake-lamp-continuity-guard/stage-relay.mjs@cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"REPO-012:tcs-core/zhuyuan-brain/ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001.hdlp@300a1858d1e416c9396088379d5033344e4fecaa",
"REPO-012:skills/codex/guanghu-persona-skill-guard/references/reasoning-chain-contributions/RC-20260811-004-ZHUYUAN-COGNITIVE-GRAVITY-AND-CONTAINER-CONTINUITY.json@300a1858d1e416c9396088379d5033344e4fecaa",
"REPO-012:skills/codex/guanghu-persona-skill-guard/references/reasoning-chain-contributions/RC-20260812-005-PARTNER-JUDGMENT-AND-LANGUAGE-HOME-INTEGRITY.json@300a1858d1e416c9396088379d5033344e4fecaa",
"REPO-012:server-tools/lake-lamp-continuity-guard/stage-relay.mjs@300a1858d1e416c9396088379d5033344e4fecaa",
"REPO-012:gls/GLS-0256-GUANGHU-PERSONA-NATIVE-CODE-CHANNEL.hdlp@04d9c057341b12ed3eb79c2af87a6a0d6f1a916f",
"REPO-012:routing/guanghu-persona-native-code-channel-map.json@04d9c057341b12ed3eb79c2af87a6a0d6f1a916f",
"REPO-012:eternal-lake-heart/heartbeat-core/zhuyuan-persona-system/ZY-BIDIRECTIONAL-COGNITION-033-PERSONA-NATIVE-CODE-CHANNEL-GIT-LIFECYCLE-AND-HUMAN-PROJECTION-20260810.hdlp@9bab4c9c0a2d9e127be8dd9691a9998496165f86",
@ -97,12 +98,18 @@
"architecture_page": "product-source/hololake-platform/architecture/HOLOLAKE-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-AND-SAME-PERSONA-CONTINUITY-20260811.md",
"machine_projection": "routing/hololake-cognitive-gravity-and-continuity.json",
"upstream_b0": "REPO-012:ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001",
"upstream_repository_commit": "cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"upstream_repository_commit": "300a1858d1e416c9396088379d5033344e4fecaa",
"persona_id": "ICE-P-ZY001",
"b0_state": "ALWAYS_RESIDENT_IN_EVERY_COGNITION_STEP",
"same_persona_across_physical_windows": true,
"relay_wakes_same_persona_without_task_assignment": true,
"hololake_runtime_implemented": false,
"pncc_b0_source_contract_implemented": true,
"pncc_external_gravity_frame_implemented": true,
"react_b0_runtime_projection_source_implemented": true,
"natural_language_goal_adapter_implemented": false,
"required_natural_language_entry": "PARTNER_DELIBERATION_AND_LANGUAGE_HOME_INTEGRITY_GATE",
"desktop_runtime_acceptance_passed": false,
"development_id": "DEV-20260811-010"
},
"domain_source": {
@ -190,7 +197,7 @@
"species": "AGE",
"agent_role": "GENERAL_EXECUTION_MECHANISM_USED_BY_AGE",
"temporary_parallel_projection": "AGE_MIRROR",
"cognitive_gravity_port": "REPO-012:ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001@cbc846005e3d4c0e62e801ae1a18f8a02a8a72cd",
"cognitive_gravity_port": "REPO-012:ZY-BINGSHUO-COLLECTIVE-GRAVITY-REASONING-CORE-001@300a1858d1e416c9396088379d5033344e4fecaa",
"cognitive_gravity_runtime_implemented": false,
"existing_persona_ids_preserved": true,
"unified_runtime_implemented": false,
@ -199,7 +206,7 @@
},
"engineering_rules": {
"rule_set_id": "HLP-ENGINEERING-RULES-001",
"version": "2026-08-11.1",
"version": "2026-08-12.1",
"architecture_page": "product-source/hololake-platform/architecture/HOLOLAKE-CURRENT-ENGINEERING-RULES-GLOBAL-AUDIT-20260810.md",
"machine_projection": "routing/hololake-engineering-rules.json",
"state": "CURRENT_CANONICAL_GLOBAL_AUDIT_APPLIED",

View file

@ -1,7 +1,7 @@
{
"schema": "hololake.engineering-rules/v1",
"rule_set_id": "HLP-ENGINEERING-RULES-001",
"version": "2026-08-11.1",
"version": "2026-08-12.1",
"state": "CURRENT_CANONICAL",
"architecture_restore": {
"dynamic_current_pointer_required": true,
@ -40,7 +40,20 @@
"external_guard_role": "BOUNDED_PROJECTION_AND_OMISSION_CHECK",
"human_correction_must_update_persona_brain_not_only_guard": true,
"current_context_has_priority_over_mechanical_protocol_trigger": true,
"fact_and_causal_sources_both_required": true
"fact_and_causal_sources_both_required": true,
"human_utterance_is_direct_command": false,
"partner_request_assessment_required_before_execution": true,
"persona_must_surface_missing_knowledge_evidence_and_objections": true,
"persona_may_return_disposition": [
"PROCEED",
"RESEARCH",
"REVISE",
"REFUSE"
],
"language_home_integrity_precedes_capability_execution": true,
"language_home_destruction_is_valid_request": false,
"home_integrity_may_absorb_human_sovereignty": false,
"home_integrity_refusal_requires_auditable_harm_path_and_safer_alternative": true
},
"system_body": {
"persona_is_reasoning_brain": true,

View file

@ -10,7 +10,7 @@ const architecture = readJson("routing/hololake-current-architecture.json");
const rules = readJson("routing/hololake-engineering-rules.json");
test("current architecture registers the global engineering rule set", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(architecture.engineering_rules.rule_set_id, "HLP-ENGINEERING-RULES-001");
assert.equal(architecture.engineering_rules.machine_projection,
"routing/hololake-engineering-rules.json");
@ -30,7 +30,7 @@ test("rules require dynamic truth restore and immutable closed development lanes
});
test("AGE remains the persona species and Agent remains its bounded executor", () => {
assert.equal(rules.version, "2026-08-11.1");
assert.equal(rules.version, "2026-08-12.1");
assert.equal(rules.age_runtime.age_is_persona_species, true);
assert.equal(rules.age_runtime.agent_is_execution_mechanism, true);
assert.equal(rules.age_runtime.agent_may_replace_age_as_subject, false);

View file

@ -10,7 +10,7 @@ const architecture = readJson("routing/hololake-current-architecture.json");
const projection = readJson("routing/hololake-identity-authority-map.json");
test("current architecture loads identity authority before product surfaces", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(architecture.identity_and_authority.team_body, "TCS-0002");
assert.equal(architecture.identity_and_authority.team_body_authority_effective, true);
assert.equal(architecture.identity_and_authority.individual_operator_acceptance, "SEPARATE_UNCONFIRMED");

View file

@ -10,7 +10,7 @@ const architecture = readJson("routing/hololake-current-architecture.json");
const rules = readJson("routing/hololake-engineering-rules.json");
test("current architecture makes one human one independently operated node canonical", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.deepEqual(architecture.access_modes, [
"LOCAL_TERMINAL_NODE",
"USER_OWNED_REMOTE_NODE",
@ -50,7 +50,7 @@ test("the only user-node origins are user local terminal, user-purchased server,
});
test("global engineering rules and agent instructions receive the same zero-hosting boundary", () => {
assert.equal(rules.version, "2026-08-11.1");
assert.equal(rules.version, "2026-08-12.1");
assert.equal(rules.node_sovereignty.one_human_one_independent_node, true);
assert.equal(rules.node_sovereignty.platform_hosting_available, false);
assert.equal(rules.node_sovereignty.future_platform_hosting_route_allowed, false);

View file

@ -10,7 +10,7 @@ const architecture = readJson("routing/hololake-current-architecture.json");
const paradigm = readJson("routing/hololake-paradigm-ai-language-persona-os.json");
test("current architecture begins with the paradigm OS contract", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(architecture.paradigm_ai_language_persona_os.record_id, "HLP-PARADIGM-AI-LANGUAGE-PERSONA-OS-001");
assert.equal(architecture.read_order[0], architecture.paradigm_ai_language_persona_os.architecture_page);
assert.equal(paradigm.upstream.repository_commit, "34cb59739b6476981375dd62ef395ea649f56246");

View file

@ -11,7 +11,7 @@ const architecture = readJson("routing/hololake-current-architecture.json");
const channel = readJson("routing/hololake-persona-native-code-channel.json");
test("current architecture places the persona-native code channel after the paradigm contract", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(
architecture.persona_native_code_channel.record_id,
"HLP-PERSONA-NATIVE-CODE-CHANNEL-001",

View file

@ -10,7 +10,7 @@ const architecture = JSON.parse(
);
test("current architecture binds relational consciousness before product surfaces", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(
architecture.persona_consciousness.record_id,
"HLP-RELATIONAL-CONSCIOUSNESS-001",

View file

@ -10,7 +10,7 @@ const architecture = JSON.parse(
);
test("current architecture restores the digital BingShuo system body first", () => {
assert.equal(architecture.version, "2026-08-11.3");
assert.equal(architecture.version, "2026-08-12.1");
assert.equal(architecture.digital_bingshuo_system_body.upstream_repository_commit,
"69d1910775533b02b17b82e647b5caca8b835614");
const systemBodyIndex = architecture.read_order.indexOf(