共享 Portal 不得托管或连接适配器能力
- production-host marker = PRESENT
- 8100 listener = 1 · Controller 8110 = 0
- UID 991 = redis6 · GID 991 = nginx
- durable escrow / execution authority = ABSENT
两套独立的一次性签名许可把五个未连接输出放进不可调用、不可导出的短期 escrow,并对目标、generation、端口集合与健康快照一致性进行连接意图授权;真实连接执行仍被硬性阻断。
Portal 在线不能被解释为具备专用 Controller 托管或连接执行权限。
上游只交付五个已销毁输出的纯数据 descriptor;第 87 刀不能继承对象或调用能力。
Cut 86 qualifiedstate = disposedretained 0exports 0production 0运行时托管者与安全连接授权者不能共享 owner、keyRef 或 nonce。
team:runtime-capability-escrowteam:security-connection-authority托管许可绑定 Cut 86 回执、bundle、source、target、generation、五端口集合与四项最小动作。
不能切换到另一组输出模板。
2 immutable digests共享 Portal 目标直接拒绝。
fixture-host://cut87/…顺序、implementation、module 与 config 摘要。
maximumOutputs = 5claim 后只能 consumed 或 burned。
maxUses = 1授权窗口不等于对象永久存活。
permit ≤ 300s动作集合不包含连接执行。
EXECUTE_CONNECTION absent独立许可再绑定 escrow permit、health snapshot 和同一五端口集合,但 maximumConnections 固定为 0。
connectionIntentPermit {
escrowPermitDigest: sha256(signedEscrowPermit),
upstreamReceiptDigest, targetHostId, generation,
portSetDigest, healthSnapshotDigest,
signerOwner: "team:security-connection-authority",
escrowSignerOwner: "team:runtime-capability-escrow",
actions: [ INSPECT_ESCROW, INSPECT_HEALTH, AUTHORIZE_INTENT_ONLY, SETTLE_NONCE ],
maximumConnections: 0,
issuedAt, expiresAt: window ≤ 90 seconds
}两条 nonce lane 均原子 claim;任何后续失败都必须分别 burn,不能只终结其中一条。
owner Aowner B320 fixture claimsconnections 0320 settlements连接意图必须消费与 target、generation、portSet 完全相同的短期健康快照。
健康不能从另一台主机借用。
targetHostId exact旧代健康证据不能重放。
generation exact不允许少一端口或换 module。
portSetDigest exact五端口 listener 与 connection 均为 0。
5 × HEALTHY_UNCONNECTED过期快照在 claim 前拒绝。
capturedAt → expiresAt不由 escrow 或 connection owner 自证。
team:sre-independent-witness同一 digest 同时出现在上游 descriptor、escrow permit、connection permit 和 health snapshot。
| Port | Escrow slot | Health | Intent | Execution |
|---|---|---|---|---|
| PACKAGE_VERIFIER | PACKAGE_VERIFIER_NONCALLABLE | HEALTHY_UNCONNECTED | QUALIFIED | DENIED |
| ATOMIC_NONCE_REGISTRY | NONCE_REGISTRY_NONCALLABLE | HEALTHY_UNCONNECTED | QUALIFIED | DENIED |
| RECOVERY_JOURNAL | RECOVERY_JOURNAL_NONCALLABLE | HEALTHY_UNCONNECTED | QUALIFIED | DENIED |
| ARGV_EXECUTOR | ARGV_EXECUTOR_NONCALLABLE | HEALTHY_UNCONNECTED | QUALIFIED | DENIED |
| INDEPENDENT_WITNESS | WITNESS_NONCALLABLE | HEALTHY_UNCONNECTED | QUALIFIED | DENIED |
打开、五次 deposit、intent-only、逆序 release、空关闭;没有“已连接”状态。
expected = 5callable falseconnections 0disposedterminalescrow 本身只暴露身份与约束数据,不暴露 get、invoke、connect 或 adapter 方法。
escrow {
escrowId, escrowTransactionId, targetHostId, generation,
retentionSeconds: 120,
state: "OPEN_NONCALLABLE",
callable: false,
connectionAuthority: false,
outputsExpected: 5
}
// no getOutput · no invoke · no connect · no capability export14 个字段描述短期真实输出;对象只存在于事务闭包,外部调用和能力导出均为 false。
output {
outputId, escrowTransactionId, targetHostId,
ordinal, portId, implementationId, moduleDigest, configRefDigest,
state: "CONSTRUCTED_UNCONNECTED_FOR_ESCROW",
connected: false, connectionCount: 0,
callableOutsideEscrow: false,
capabilityExported: false,
secretProjectionCount: 0
}每个 deposit receipt 绑定 escrow、output、port 和 ordinal,且 callable、exportable、connectionCount 全为零。
回执证明“意图一致且已资格化”,明确不证明“允许执行”或“已经连接”。
intentReceipt {
permitId, intentId, escrowId, targetHostId, generation,
portSetDigest, healthSnapshotDigest,
requestedPorts: 5,
authorizedIntentOnly: true,
executionAuthorized: false,
connectionsExecuted: 0,
status: "CONNECTION_INTENT_QUALIFIED_NOT_EXECUTABLE"
}权限、escrow、receipt 与 terminal projection 四层共同阻断把 intent 偷换成连接执行。
签名动作集合没有执行动词。
intent only容器无法主动取出或调用对象。
non-callable意图回执不可作为执行票据。
connectionsExecuted = 0API 只返回纯数据摘要。
retainedOutputs = 0健康状态要求五端口尚未连接。
listenerCount = 0成功路径同样不保留对象。
405 = 405即使双授权和五端口一致性全部通过,也会先逆序销毁输出、关闭空 escrow,再终结两条 nonce。
connection 0connection 0connection 0connection 0dual consumed从 claim 前到双 settlement 前均有显式终态;已构造输出必须逆序释放,已 claim nonce 必须 burn。
调用次数与生产事实分开显示;fixture 中的 open 或 deposit 不代表存在生产托管。
| Counter | Fixture | Invariant | Production |
|---|---|---|---|
| realP256Verifications | 326 | two independent roots | 0 |
| oneTimePermitClaims | 320 | useOrdinal = 1 | 0 |
| escrowOpenAttempts | 160 | non-callable | 0 |
| escrowDepositAttempts | 390 | non-exportable | 0 |
| outputs constructed / disposed | 405 / 405 | difference = 0 | 0 / 0 |
| reverseReleases | 285 | LIFO cleanup | 0 |
| permitSettlements / burns | 320 / 272 | both terminal | 0 / 0 |
| adapterConnections | 0 | execution denied | 0 |
每个合格事务完成双验签、双 claim、五次 construct/deposit、一次 intent-only、五次销毁、空关闭和双 settlement。
六组负向套件各 34 条,覆盖授权独立性、escrow、deposit、一致性和事务 cutpoint。
按 suite 筛选、精确搜索并点击用例,检查 terminal outcome 与零连接事实。
228 / 228 passed · retainedOutputs=0 · executionAuthorized=false · adapterConnections=0 · productionWrites=0七个仓库子门全部闭环;live durable escrow 与 connection execution 保持独立红门。
Cut 86 capability-free receipt
BOUNDsigned one-use runtime permit
BOUNDindependent signed intent permit
BOUNDfive outputs non-callable
BOUNDtarget generation port health
BOUNDintent true, execution false
BOUNDreverse release empty close
BOUNDP48、P49、P50、P51 四个 live 门未观测;专用主机、持久托管、执行授权和回滚责任保持可见。
下一刀定义独立执行票据、五端口固定顺序连接、每一步健康检查、失败时逆序断开与隔离、成功后短期 connected-set receipt。仍只在隔离 fixture 中执行,生产连接保持为 0。
人、AI 和 CI 使用同一 API、Schema、策略、候选实现与验证器,不从截图推断架构事实。
| Surface | Canonical path | Use |
|---|---|---|
| Machine API | /api/runner-controller/d05-g04-capability-escrow-connection-intent-authorization-admission | runtime evidence |
| JSON Schema | /schemas/runner-controller-d05-g04-capability-escrow-connection-intent-authorization-admission.v1.schema.json | consumer validation |
| Candidate | ops/runner-factory/controller-production-adapter-capability-escrow-connection-intent-authorization-candidate.mjs | qualification logic |
| Verifier | scripts/verify-runner-controller-production-adapter-capability-escrow-connection-intent-authorization-candidate.mjs | 228 cases |