hololake-system-architecture/build/TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001.human.en-US.md

141 lines
6.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# HoloLake Capability Registry Trusted Signer Provisioning Request · Human Engineering Language (English)
> This is an English reading projection of validated native TCS/HLDP source. It is not a new canonical source and grants no execution authority.
## What this is
This is a **protocol** declaration with identifier `TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001` and version `0.1.0`. The projector validates it with the Stage-1 compiler before changing its reading order.
## Who is here
The native source does not provide this field; the projector does not guess.
## Why this started
- **source** `source`
- **source identifier**BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823 `source.source_id`
- **source role**DIRECT_HUMAN `source.source_role`
- **source checksum**a3dd8dbd2203b631bdb23f2693eb314d4ef86af68fdeaee8835e3cf0861ddd23 `source.source_sha256`
- **source address**language-sources/direct-human/BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823.txt `source.source_uri`
## What changed
The native source does not provide this field; the projector does not guess.
## How it will execute
This is a non-executable declaration and has no action graph.
## Boundaries and exception handling
The native source does not provide this field; the projector does not guess.
## How completion is proven
- **acceptance** `acceptance`
- **capability_registry_state_after_pass**SIGNED_VERIFIED_NOT_INSTALLED `acceptance.capability_registry_state_after_pass`
- **current_acceptance**0 `acceptance.current_acceptance`
- **installation_is_separate_step**yes `acceptance.installation_is_separate_step`
- **signature_verified**BINARY_PASS_OR_FAIL `acceptance.signature_verified`
- **signer_registered**AUTHORITATIVE_REGISTRY_READBACK_REQUIRED `acceptance.signer_registered`
## Where to continue next time
The native source does not provide this field; the projector does not guess.
## Source and verification
- **Native declaration identifier**: `TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001`
- **Native declaration kind**: `PROTOCOL`
- **TCS source SHA-256**: `4deb85d6d0f5bdb61ff2d9182d9acd1e0f1e266661bc30d75befccbe3b936e4d`
- **Validation compiler**: `TCS-COMPILER-STAGE3-GENERIC-ACTION-LOADER-0001`
- **Projection protocol**: `GLS-HLDP-HUMAN-ENGINEERING-PROJECTION-0001`
## Complete native structure cross-reference
All top-level structures and field paths are retained below so a reader can audit whether the projection omitted information.
- **acceptance** `acceptance`
- **capability_registry_state_after_pass**SIGNED_VERIFIED_NOT_INSTALLED `acceptance.capability_registry_state_after_pass`
- **current_acceptance**0 `acceptance.current_acceptance`
- **installation_is_separate_step**yes `acceptance.installation_is_separate_step`
- **signature_verified**BINARY_PASS_OR_FAIL `acceptance.signature_verified`
- **signer_registered**AUTHORITATIVE_REGISTRY_READBACK_REQUIRED `acceptance.signer_registered`
- **admission** `admission`
- **out_of_scope**TCS-E4001 `admission.out_of_scope`
- **stale_or_revoked**TCS-E5002 `admission.stale_or_revoked`
- **unsigned_or_unknown_signer**TCS-E3002 `admission.unsigned_or_unknown_signer`
- **verify_candidate_hash_before_signature**yes `admission.verify_candidate_hash_before_signature`
- **verify_public_key_against_authoritative_signer_registry**yes `admission.verify_public_key_against_authoritative_signer_registry`
- **verify_revocation_before_each_activation**yes `admission.verify_revocation_before_each_activation`
- **verify_scope_before_install**yes `admission.verify_scope_before_install`
- **verify_signature_before_mount**yes `admission.verify_signature_before_mount`
- **current** `current`
- **activation**no `current.activation`
- **authoritative_registry_state**CURRENT_EMPTY_NO_TRUSTED_SIGNER `current.authoritative_registry_state`
- **candidate_registry**TCS-CAPREG-LPM-DESKTOP-CANDIDATE-0001 `current.candidate_registry`
- **candidate_state**UNSIGNED_CANDIDATE_NOT_INSTALLABLE `current.candidate_state`
- **install**no `current.install`
- **mount**no `current.mount`
- **public_key**ABSENT `current.public_key`
- **signature**ABSENT `current.signature`
- **signer_id**UNKNOWN `current.signer_id`
- **header** `header`
- **canonical source path**language/protocols/TCS-TRUSTED-SIGNER-PROVISIONING-REQUEST-0001.tcs `header.canonical_uri`
- **compatibility** `header.compatibility`
- GIR/1
- **language**TCS/0.1 `header.language`
- **lifecycle**CANDIDATE `header.lifecycle`
- **English name**HoloLake Capability Registry Trusted Signer Provisioning Request `header.name_en`
- **Chinese name**HoloLake能力注册表可信签名主体供给请求 `header.name_zh`
- **profile**HLDP/1 `header.profile`
- **protocols** `header.protocols`
- TCS-GENERIC-ACTION-GRAPH-LOADER-0001
- TCS-MODULE-ABI-0001
- **schema**tcs.protocol/v1 `header.schema`
- **version**0.1.0 `header.version`
- **rejected** `rejected`
- **values** `rejected.values`
- INFER_SIGNER_FROM_USER_ACCOUNT
- INFER_SIGNER_FROM_ROOT
- INFER_SIGNER_FROM_SSH_ACCESS
- INFER_SIGNER_FROM_GIT_REMOTE_RIGHTS
- GENERATE_UNREQUESTED_IDENTITY_KEY
- STORE_PRIVATE_KEY_IN_REPOSITORY
- CALL_UNSIGNED_CANDIDATE_SIGNED
- **request** `request`
- **git_push_authority_reuse**no `request.git_push_authority_reuse`
- **host_root_or_ssh_key_reuse**no `request.host_root_or_ssh_key_reuse`
- **key_generation_by_current_codex**no `request.key_generation_by_current_codex`
- **private_key_location**OUTSIDE_REPOSITORY_AND_OUTSIDE_RECEIPTS `request.private_key_location`
- **required** `request.required`
- SEPARATELY_AUTHORIZED_SIGNER_ID
- ED25519_PUBLIC_KEY
- KEY_PROVENANCE_RECEIPT
- PERMITTED_REGISTRY_SCOPE
- EXPIRY_OR_REVOCATION_RULE
- ONE_EXACT_CANDIDATE_HASH
- HUMAN_LANGUAGE_AUTHORIZATION_RECEIPT_BOUND_TO_REQUEST
- **signature_envelope** `signature_envelope`
- **algorithm**ED25519 `signature_envelope.algorithm`
- **channel**ICE-CH-ZC001 `signature_envelope.channel`
- **development_line**HOLOLAKE-LPM-TCS-NATIVE-20260823 `signature_envelope.development_line`
- **payload** `signature_envelope.payload`
- REGISTRY_CANONICAL_SHA256
- REGISTRY_ID
- REGISTRY_VERSION
- ISSUER_SIGNER_ID
- ISSUED_AT
- EXPIRES_AT_OR_NO_EXPIRY_POLICY
- REVOCATION_EPOCH
- CHANNEL
- DEVELOPMENT_LINE
- **source** `source`
- **source identifier**BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823 `source.source_id`
- **source role**DIRECT_HUMAN `source.source_role`
- **source checksum**a3dd8dbd2203b631bdb23f2693eb314d4ef86af68fdeaee8835e3cf0861ddd23 `source.source_sha256`
- **source address**language-sources/direct-human/BINGSHUO-HOLOLAKE-TCS-ENGINEERING-ANCHOR-20260823.txt `source.source_uri`
---
This page changes only the reading order; it does not change TCS/HLDP semantics.