Inheritance-state theory
OriginOS starts from the idea that AI should not continue from inherited state as if it were automatically safe. Before action continues, the inherited state must be reviewed inside a governed logical body.
OriginOS gives AI a governed logical body before it touches the outside world. The shared foundation behind Lingling and OriginOS Pro.
A safe personal AI companion for continuity, connected tools, connected devices, gentle assistance, and human-centered interaction. Lingling is for people who want AI to stay helpful, bounded, and context-aware in personal scenarios.
A governed runtime for AI external actions across SSH, APIs, cloud systems, databases, development workflows, connected devices, IoT, robots, and industrial resources. Pro is for teams that need AI actions to be reviewed, approved, verified, recoverable, and recorded.
The profile defines target host, port, operator identity, target root, allowed paths, timeout policy, and protected credential visibility.
Before any execution, the console shows which environment will be bound, which root path is locked, which files may be touched, and what verification and rollback plan exists.
SSH-bound execution requires explicit final confirmation. A plan confirmation alone is not enough to run commands or modify files.
OriginOS does not expose a free shell. It only allows governed execution through approved command packages that are tied to target paths, hashes, verification, rollback, and evidence.
SSH output is not treated as raw text only. The runtime classifies syntax signals, HTTP checks, missing files, permission errors, timeout states, and verification failures.
Each governed development run can be recorded as a traceable chain covering request, plan, confirmations, SSH binding, command package, result, verification, rollback decision, and final status.
The operator submits a request through a chatbox-style input and can provide code, exports, logs, screenshots, documents, and test evidence as attachments.
The console must show concrete steps, expected outcomes, target files, full paths, operation types, risk levels, verification, rollback, and evidence requirements.
SSH binding and development execution are blocked until the user approves the plan and gives final second confirmation for the execution preview.
The console must stop for SSH timeout, authentication failure, host mismatch, path mismatch, permission denial, production-risk changes, sensitive output, destructive commands, verification failure, missing rollback, or unclear responsibility binding.
After plan approval and final SSH execution confirmation, OriginOS may run governed automatic patch packages for new-file creation, existing-file modification, verification, rollback preparation, and evidence recording.
These anchors are intentionally visible in page source so the Operator Console can be audited without granting free shell, arbitrary command, credential exposure, unlocked targets, or free LLM action.
Lingling preserves identity, live state, boundary awareness, continuity, reflection, stop reasons, and self-state visibility without adding autonomous execution.
Pro preserves enterprise identity, policy boundary, known-good state, signed command package posture, audit evidence visibility, governance dashboard, and enterprise UI theme.
The EI closure endpoint exposes the final split-product closure object for read-only verification.