hololake-system-architecture/README.md

7.9 KiB

HoloLake Language Mother Model — TCS Native Line

This branch starts the HoloLake language mother-model line under ICE-CH-ZC001 on 2026-08-23.

Canonical source is TCS only. Generated GIR, bilingual human projections, runtime readbacks and receipts are evidence layers, not replacement canon. Legacy product sources live in the separate mobile-drive reference isolation zone and are not part of this line.

The first accepted slice preserves a direct-language source envelope, extracts two three-node thought-transition microchains, compiles them and executes bounded replay receipts through the current TCS GIR runtime.

Stage two adds the TCS-authored TCS-COMPILER-STAGE2-LPM-DESKTOP-0001, a fixed-point operation registry, a P2 mother-brain state transition program, a five-action shared-desktop test-object graph, and two complete Module ABI packages at VERIFIED. Compilation admission is proven; native LPM and generic multi-action runtime dispatch are still absent and fail closed with TCS-E2101. The modules are not installed, mounted, active, executed or accepted.

Stage three adds a TCS-defined generic action-graph loader ABI and TCS.EXECUTE_ACTION_GRAPH, proves the Stage-3 E→F semantic fixed point, executes the loader's inner CORE.ECHO child with target readback, and packages the outer loader module at VERIFIED. The outer operation still fails closed at the old runtime dispatch. The LPM/desktop capability registry remains an unsigned, non-installable candidate; no signing authority is inferred from the human relationship, OS account, SSH access or this repository.

The current boundary audit proves why the outer loader is not yet runnable: the available machine runner accepts exactly one action and dispatches through a fixed host operation table. TCS compiler registration changes language admission but does not add a machine primitive. The next physical dependency is one generic TCS GIR action-graph executor whose host carries no natural-language or operation-specific product semantics, followed by a separately authorized Ed25519 signer registration. Until both are read back, the three module packages remain verified but uninstalled.

Mother-brain corpus admission now has an explicit TCS source gate. A transport user role is not author proof; host injection, pasted model output, persona-derived pages, language-world simulation and unverified embedded quotes cannot be promoted as direct BingShuo language. The first new five-event correction chain preserves the original text hashes separately from the rebuildable interpretation graph and remains provisional until the original rollout envelope and native LPM replay both pass.

Stage five applied that gate to the first five-event chain and failed it closed: two derived copies agree byte-for-byte, but the original laptop rollout is unavailable and the task-service readback returned an upstream access challenge. The candidate graph is preserved without core promotion. Work continued from the stronger current direct-language anchor instead, producing a seven-node contiguous chain from the bidirectional translation gap through language-world growth, mother-brain/library separation and bounded Agent TCS brains. Its minimum CORE.ECHO replay has executed with target readback; this is evidence of bounded TCS replay, not native LPM graph execution.

Stage six converts the frozen twelve-repository desktop research package into one TCS-native framework behavior contract. No upstream project is selected as HoloLake and no old-language product source is imported. The framework is the TCS protocol itself: observe one structured object tree, resolve one snapshot-scoped stable object, authorize one exact semantic action, execute, reobserve, read the state diff, verify the declared effect through independent target readback, and only then issue a receipt. Dispatch success, process exit, screenshots and pixel coordinates are not effect proof. The protocol and its bilingual projections compile under the Stage-3 fixed-point compiler; desktop execution remains pending the generic GIR action-graph machine primitive, signed capability registry, module installation and mounting.

Stage seven returns to the direct engineering-language anchor and extracts a six-node P5 control chain: legacy isolation and TCS-only semantics, remote history without ancestor authority, the two direct-language startup anchors, source-gated corpus admission, parallel incremental mother-brain/framework fusion, and bounded engineering discretion that never treats language-layer completion or control-transfer phrases as machine proof. Nineteen strong-source neuron nodes are now preserved, with five derived candidates still outside the core. P5 is source-verified and compiled but remains pending native LPM replay and graph-state promotion.

Stage eight uses BingShuo's explicit continuation to demote fourth-generation code to a mechanical machine-runtime role. A TCS-defined macOS host adapter was projected into a derived v0.1.2 Rust runtime without adding LPM, desktop or natural-language product semantics. The Apple Developer ID-signed binary now executes the outer TCS.EXECUTE_ACTION_GRAPH bootstrap and independently reads back its inner CORE.ECHO target and outer receipt. A dedicated development-line Ed25519 key remains in the local macOS login keychain; only its public key and fingerprint are stored here. The capability registry signature verifies and is SIGNED_VERIFIED_NOT_INSTALLED. Signing does not manufacture missing LPM or desktop provider GIR, so those modules remain uninstalled and unmounted until their TCS provider programs exist.

Stage nine defines CORE.APPLY_EXACT_STATE_TRANSITION in TCS before projecting its compare/atomic-write/hash/readback mechanics into the fourth-generation host. The Stage-4 G→H compiler semantic fixed point passes. TCS provider GIR now lowers one LPM P2 neuron transition and one isolated virtual shared-desktop OPEN transition to that opaque machine primitive; both child targets and both outer loader receipts read back exactly, while the host reports host_semantic_authority=false. The existing signed capability registry is intentionally stale after the host and provider hashes changed. No module is called installed or mounted until v3 packages are built and a newly signed registry admits those exact bytes.

Stages ten and eleven build immutable v3 mother-brain and virtual-desktop provider packages, add a TCS-defined CORE.INSTALL_VERIFIED_MODULE primitive, prove the Stage-5 I→J compiler fixed point, and sign registry v3 against the final Apple Developer ID-signed host. The mechanical runtime independently verifies the Ed25519 signature, signed payload, current host hash, every package source hash and every installed readback hash before atomically installing eight canonical files per module. Both modules then move through separate installed, mounted and active states. Activation is bound to the exact prior mount hash and follows P4, P5 and isolated virtual-desktop target readbacks. This activation is local to the ICE-CH-ZC001 development line; it does not claim production trust, remote deployment or a real macOS desktop action.

Stage twelve defines CORE.OBSERVE_HOST_OBJECT_TREE in TCS, proves the Stage-6 K→L compiler fixed point, and projects a separate v0.1.3 macOS Accessibility adapter that remains a fourth-generation mechanical host only. Xcode's Manage Certificates UI was opened and the Developer ID Application certificate was read back before the candidate binary's strict Apple signature was verified. One focused application tree was observed read-only with eighteen bounded nodes, stable snapshot-scoped hashes, no permission prompt, no settings change, no network and no desktop action. Persisted evidence contains only title presence and title hashes, never title or value plaintext. The prior v0.1.2 stable host remains unchanged; stable-object resolution and every real semantic action remain future, separately bounded stages.