REITS / ARCHITECTURED05 · G04 · CUT 87
P51 · escrow intent qualified · execution held

Hold the capability.
Authorize the intent.
Execute nothing.

两套独立的一次性签名许可把五个未连接输出放进不可调用、不可导出的短期 escrow,并对目标、generation、端口集合与健康快照一致性进行连接意图授权;真实连接执行仍被硬性阻断。

global cut87 / 10417 cuts left
QA228 / 2282,564 cumulative
qualified24intent transactions
rejected204before execution
P-256326real verifications
outputs405 = 405built = disposed
reverse285abort releases
connections0execution denied
01

CURRENT EXTERNAL RED GATE

Portal 在线不能被解释为具备专用 Controller 托管或连接执行权限。

DENY CURRENT EC2

共享 Portal 不得托管或连接适配器能力

  • production-host marker = PRESENT
  • 8100 listener = 1 · Controller 8110 = 0
  • UID 991 = redis6 · GID 991 = nginx
  • durable escrow / execution authority = ABSENT
source release62370b9 · Cut 86
qualified host0
live escrow permit0
live connection permit0
retained outputs0
connections0
02

CUT 86 CAPABILITY-FREE INPUT

上游只交付五个已销毁输出的纯数据 descriptor;第 87 刀不能继承对象或调用能力。

216 / 216factory transaction QACut 86 qualified
5 DESCRIPTORSidentity + digest onlystate = disposed
212 = 212constructed = disposedretained 0
CAPABILITY FREEno object crossingexports 0
LIVE ESCROWnot configuredproduction 0
03

INDEPENDENT DUAL AUTHORITY

运行时托管者与安全连接授权者不能共享 owner、keyRef 或 nonce。

ESCROW AUTHORITY

Runtime capability escrow

  • 允许构造、deposit、release、close
  • 最长 300 秒 · escrow 保留 120 秒
  • maximumOutputs = 5
team:runtime-capability-escrow
separate
CONNECTION AUTHORITY

Security connection intent

  • 允许检查 escrow、health、签发 intent
  • 最长 90 秒
  • maximumConnections = 0
team:security-connection-authority
04

20-FIELD ESCROW PERMIT

托管许可绑定 Cut 86 回执、bundle、source、target、generation、五端口集合与四项最小动作。

UPSTREAM

receipt + bundle digests

不能切换到另一组输出模板。

2 immutable digests
TARGET

host + generation

共享 Portal 目标直接拒绝。

fixture-host://cut87/…
PORT SET

five exact bindings

顺序、implementation、module 与 config 摘要。

maximumOutputs = 5
ONE USE

nonce + maxUses

claim 后只能 consumed 或 burned。

maxUses = 1
RETENTION

120-second escrow

授权窗口不等于对象永久存活。

permit ≤ 300s
NO CONNECT

four exact actions

动作集合不包含连接执行。

EXECUTE_CONNECTION absent
05

21-FIELD CONNECTION-INTENT PERMIT

独立许可再绑定 escrow permit、health snapshot 和同一五端口集合,但 maximumConnections 固定为 0。

connectionIntentPermit {
  escrowPermitDigest: sha256(signedEscrowPermit),
  upstreamReceiptDigest, targetHostId, generation,
  portSetDigest, healthSnapshotDigest,
  signerOwner: "team:security-connection-authority",
  escrowSignerOwner: "team:runtime-capability-escrow",
  actions: [ INSPECT_ESCROW, INSPECT_HEALTH, AUTHORIZE_INTENT_ONLY, SETTLE_NONCE ],
  maximumConnections: 0,
  issuedAt, expiresAt: window ≤ 90 seconds
}
06

DUAL ONE-TIME NONCE STATE MACHINE

两条 nonce lane 均原子 claim;任何后续失败都必须分别 burn,不能只终结其中一条。

ESCROW AVAILABLEunique nonce Aowner A
CONNECTION AVAILABLEunique nonce Bowner B
DUAL CLAIMEDuseOrdinal = 1 × 2320 fixture claims
INTENT / ABORTno execution branchconnections 0
CONSUMED / BURNEDboth terminal320 settlements
07

60-SECOND FIVE-PORT HEALTH SNAPSHOT

连接意图必须消费与 target、generation、portSet 完全相同的短期健康快照。

TARGET

same isolated host

健康不能从另一台主机借用。

targetHostId exact
GENERATION

same rollout generation

旧代健康证据不能重放。

generation exact
PORT SET

same five digests

不允许少一端口或换 module。

portSetDigest exact
STATE

healthy unconnected

五端口 listener 与 connection 均为 0。

5 × HEALTHY_UNCONNECTED
FRESH

≤ 60 seconds

过期快照在 claim 前拒绝。

capturedAt → expiresAt
WITNESS

independent SRE

不由 escrow 或 connection owner 自证。

team:sre-independent-witness
08

FIVE-PORT CONSISTENCY BOARD

同一 digest 同时出现在上游 descriptor、escrow permit、connection permit 和 health snapshot。

PortEscrow slotHealthIntentExecution
PACKAGE_VERIFIERPACKAGE_VERIFIER_NONCALLABLEHEALTHY_UNCONNECTEDQUALIFIEDDENIED
ATOMIC_NONCE_REGISTRYNONCE_REGISTRY_NONCALLABLEHEALTHY_UNCONNECTEDQUALIFIEDDENIED
RECOVERY_JOURNALRECOVERY_JOURNAL_NONCALLABLEHEALTHY_UNCONNECTEDQUALIFIEDDENIED
ARGV_EXECUTORARGV_EXECUTOR_NONCALLABLEHEALTHY_UNCONNECTEDQUALIFIEDDENIED
INDEPENDENT_WITNESSWITNESS_NONCALLABLEHEALTHY_UNCONNECTEDQUALIFIEDDENIED
09

ESCROW LIFECYCLE

打开、五次 deposit、intent-only、逆序 release、空关闭;没有“已连接”状态。

OPENnon-callableexpected = 5
DEPOSIT × 5non-exportable slotscallable false
INTENT QUALIFIEDexecution falseconnections 0
RELEASE × 5reverse orderdisposed
CLOSED EMPTYretained 0terminal
10

NONCALLABLE ESCROW DESCRIPTOR

escrow 本身只暴露身份与约束数据,不暴露 get、invoke、connect 或 adapter 方法。

escrow {
  escrowId, escrowTransactionId, targetHostId, generation,
  retentionSeconds: 120,
  state: "OPEN_NONCALLABLE",
  callable: false,
  connectionAuthority: false,
  outputsExpected: 5
}
// no getOutput · no invoke · no connect · no capability export
11

ESCROW OUTPUT CONTRACT

14 个字段描述短期真实输出;对象只存在于事务闭包,外部调用和能力导出均为 false。

output {
  outputId, escrowTransactionId, targetHostId,
  ordinal, portId, implementationId, moduleDigest, configRefDigest,
  state: "CONSTRUCTED_UNCONNECTED_FOR_ESCROW",
  connected: false, connectionCount: 0,
  callableOutsideEscrow: false,
  capabilityExported: false,
  secretProjectionCount: 0
}
12

FIVE NON-EXPORTABLE DEPOSIT SLOTS

每个 deposit receipt 绑定 escrow、output、port 和 ordinal,且 callable、exportable、connectionCount 全为零。

01 · PACKAGEHELD_NONCALLABLEslotOrdinal 1 · writes 0
02 · NONCEHELD_NONCALLABLEslotOrdinal 2 · writes 0
03 · JOURNALHELD_NONCALLABLEslotOrdinal 3 · writes 0
04 · ARGVHELD_NONCALLABLEslotOrdinal 4 · writes 0
05 · WITNESSHELD_NONCALLABLEslotOrdinal 5 · writes 0
13

CONNECTION-INTENT RECEIPT

回执证明“意图一致且已资格化”,明确不证明“允许执行”或“已经连接”。

intentReceipt {
  permitId, intentId, escrowId, targetHostId, generation,
  portSetDigest, healthSnapshotDigest,
  requestedPorts: 5,
  authorizedIntentOnly: true,
  executionAuthorized: false,
  connectionsExecuted: 0,
  status: "CONNECTION_INTENT_QUALIFIED_NOT_EXECUTABLE"
}
14

FOUR-LAYER EXECUTION FIREWALL

权限、escrow、receipt 与 terminal projection 四层共同阻断把 intent 偷换成连接执行。

PERMIT

maximumConnections = 0

签名动作集合没有执行动词。

intent only
ESCROW

connectionAuthority = false

容器无法主动取出或调用对象。

non-callable
RECEIPT

executionAuthorized = false

意图回执不可作为执行票据。

connectionsExecuted = 0
TERMINAL

capabilityExports = 0

API 只返回纯数据摘要。

retainedOutputs = 0
HEALTH

unconnected evidence

健康状态要求五端口尚未连接。

listenerCount = 0
DISPOSAL

all objects destroyed

成功路径同样不保留对象。

405 = 405
15

SUCCESS PATH — QUALIFY THEN DESTROY

即使双授权和五端口一致性全部通过,也会先逆序销毁输出、关闭空 escrow,再终结两条 nonce。

WITNESSrelease 05connection 0
ARGVrelease 04connection 0
JOURNALrelease 03connection 0
NONCErelease 02connection 0
PACKAGE → CLOSErelease 01 · emptydual consumed
16

TEN FAILURE CUTPOINTS

从 claim 前到双 settlement 前均有显式终态;已构造输出必须逆序释放,已 claim nonce 必须 burn。

01 · BEFORE ESCROW CLAIMno capability · no settlement
02 · AFTER DUAL CLAIMburn both nonces
03 · AFTER ESCROW OPENclose empty · burn both
04 · AFTER FIRST DEPOSITreverse 1 · close · burn
05 · AFTER SECOND DEPOSITreverse 2 · close · burn
06 · AFTER THIRD DEPOSITreverse 3 · close · burn
07 · AFTER FOURTH DEPOSITreverse 4 · close · burn
08 · BEFORE INTENTreverse 5 · close · burn
09 · DURING REVERSE RELEASEfail closed · retained 0
10 · BEFORE DUAL SETTLEMENTboth terminal · execution 0
17

ESCROW & NONCE ACCOUNTING

调用次数与生产事实分开显示;fixture 中的 open 或 deposit 不代表存在生产托管。

CounterFixtureInvariantProduction
realP256Verifications326two independent roots0
oneTimePermitClaims320useOrdinal = 10
escrowOpenAttempts160non-callable0
escrowDepositAttempts390non-exportable0
outputs constructed / disposed405 / 405difference = 00 / 0
reverseReleases285LIFO cleanup0
permitSettlements / burns320 / 272both terminal0 / 0
adapterConnections0execution denied0
18

24 QUALIFIED ESCROW INTENTS

每个合格事务完成双验签、双 claim、五次 construct/deposit、一次 intent-only、五次销毁、空关闭和双 settlement。

19

204 DETERMINISTIC REJECTIONS

六组负向套件各 34 条,覆盖授权独立性、escrow、deposit、一致性和事务 cutpoint。

34ESCROW PERMITscope · owner · target · expiry
34CONNECTION PERMITseparation · scope · maximum 0
34ESCROW ENVELOPEidentity · callable · authority
34DEPOSITslot · export · connection · writes
34CONSISTENCYtarget · generation · port · health
34TRANSACTIONconstruct · deposit · reverse release
20

228-CASE EXECUTABLE QA LAB

按 suite 筛选、精确搜索并点击用例,检查 terminal outcome 与零连接事实。

Select a QA case228 / 228 passed · retainedOutputs=0 · executionAuthorized=false · adapterConnections=0 · productionWrites=0
21

P51A–G SUBGATES

七个仓库子门全部闭环;live durable escrow 与 connection execution 保持独立红门。

P51A · UPSTREAM

Cut 86 capability-free receipt

BOUND
P51B · ESCROW AUTH

signed one-use runtime permit

BOUND
P51C · CONNECTION AUTH

independent signed intent permit

BOUND
P51D · ESCROW

five outputs non-callable

BOUND
P51E · CONSISTENCY

target generation port health

BOUND
P51F · ZERO EXECUTION

intent true, execution false

BOUND
P51G · TERMINAL

reverse release empty close

BOUND
22

105 / 109 QUALITY GATES & VISIBLE DEBT

P48、P49、P50、P51 四个 live 门未观测;专用主机、持久托管、执行授权和回滚责任保持可见。

PLATFORM · DEDICATED HOSTqualified isolated Controller host
RUNTIME · DURABLE ESCROWencrypted non-callable capability store
SECURITY · DUAL LIVE AUTHORITYindependent escrow and execution roots
SRE · HEALTH & COMPENSATIONsigned five-port witness and quarantine
RELEASE · TERMINAL RECEIPTexpiry, rollback and empty-close proof
CUT 88 / 104 · 17 CUTS REMAIN

CUT 88 HANDOFF — atomic zero-or-five connection execution transaction

下一刀定义独立执行票据、五端口固定顺序连接、每一步健康检查、失败时逆序断开与隔离、成功后短期 connected-set receipt。仍只在隔离 fixture 中执行,生产连接保持为 0。

01 · EXECUTION TICKETthird one-use authority
02 · FIVE-PORT ORDERatomic zero-or-five state
03 · COMPENSATIONreverse disconnect + quarantine
04 · TERMINAL RECEIPTfixture connected set, production zero
24

API & COLLABORATION CONTRACT

人、AI 和 CI 使用同一 API、Schema、策略、候选实现与验证器,不从截图推断架构事实。

SurfaceCanonical pathUse
Machine API/api/runner-controller/d05-g04-capability-escrow-connection-intent-authorization-admissionruntime evidence
JSON Schema/schemas/runner-controller-d05-g04-capability-escrow-connection-intent-authorization-admission.v1.schema.jsonconsumer validation
Candidateops/runner-factory/controller-production-adapter-capability-escrow-connection-intent-authorization-candidate.mjsqualification logic
Verifierscripts/verify-runner-controller-production-adapter-capability-escrow-connection-intent-authorization-candidate.mjs228 cases