feat: the module skeleton and every bundle seam #1
Reference in New Issue
Block a user
No description provided.
Delete Branch "feat/phase-1-skeleton"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
First code in this repo.
module-rust, idrust, built from the Integration Kit's template — which makes it the kit's acceptance test from the inside.Phase 1 of
modules/rust/PLAN.md. Lands with Rust-Link#1, Rust-Plugins#1 and the docs PR.What is here
/ruston all three tiers (R14), because the loader holdsmodule.json'smountsagainst what is registered in both directions. The player tier is honestly thin: it answers the server list on the authenticated tier, delegating to the same model the public tier uses so the two cannot drift while they are meant to be the same. It is the address the app will call, registered now rather than moved later.rust_serversis configuration an operator writes;rust_server_stateis what a sidecar reported. Separate because they have different writers, lifetimes and audiences — and because purging observed state while keeping the configuration is a thing an operator will want.ctx.secretBox, write-only in the API. The admin list reportshasTokenand never the credential, and an empty token on a save leaves the stored one alone — a form that posts its own blank field would otherwise erase a credential every time somebody renamed a server.{ok, status, data}, and the status is what tells a wrong URL from a wrong token from a mismatched protocol. All three present as "the site says my server is offline" and each has a different fix.check:imports,check:swagger,check:externals, and both suites (42 server tests, 20 client).What is deliberately NOT registered
No Team provider, no triggers, no audiences, no engagement seeds, no notification streams, no event budgets/leases/actions/option sources, no extension slots. A test asserts their absence so that removing it is deliberate.
The reasoning: a declared trigger nothing emits and a declared slot nothing fills are both surfaces an operator can configure and then wait on, which is worse than an absent one because the absence is visible.
Two corrections to the kit's template
Feedback for phase 19, and both are the kit being right about the general case and specific about the wrong detail.
registration.test.jsread one page BY NAME to check declared slots are rendered, so a module declaring none dies onENOENTbefore reaching the loop that would have been empty. It now scans every file undersrc/routes.test/_fakes.jssuppliedvalidator: {}. An admin router that builds validation chains at file scope cannot be required with that, so the fake holds the real express-validator — for the same reason it holds a real express Router.The kit was right about
noGameConnection.test.js: its header predicts that a module adding a sidecar client will see the check go red, namessidecarClient.jsas the file to allow, and says narrow it rather than delete it. That is exactly what happened on the first run, and the fix was the one line the header names. A test was added holding the allowlist against the tree, since a stale entry is a silent hole.How it was verified
Installed into a real core (
website@edge) and booted:started, publishes itsserverscapability on/api/v1/public/modules, and core serves its chunk.{"ok":true,"status":"ok"}withplugin_connected: true), and within one poll the public route rendered a server whoseserver.hellooriginated in a live Rust server — hostname, level, seed, world size and the game process's boot id.200with the server reported offline, and the probe reportstransport-error.🤖 Generated with Claude Code
https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
module-rust, id 'rust', built from the Integration Kit's template. Phase 1's job is the kit's own argument: get every seam working at once with almost nothing in them, so that afterwards you break exactly one at a time. What is here: * /rust on all three tiers, because the loader holds module.json's mounts against what is registered in BOTH directions -- so the declaration and the registration land together or not at all. The player tier is honestly thin: it answers the server list on the authenticated tier, delegating to the same model the public tier uses so the two cannot drift while they are meant to be the same. It is the address the app will call, registered now rather than moved later. * Two tables. rust_servers is configuration an operator writes; rust_server_state is what a sidecar reported. Separate tables because they have different writers, lifetimes and audiences -- and because purging observed state while keeping the configuration is a thing an operator will want. * Per-server sidecar tokens through ctx.secretBox, write-only in the API. The admin list reports hasToken and never the credential, and an empty token on a save leaves the stored one alone -- a form that posts its own blank field would otherwise erase a credential every time somebody renamed a server. * A real sidecar client. It never throws: every call answers {ok, status, data}, and the status is what tells a wrong URL from a wrong token from a mismatched protocol -- all three present as 'the site says my server is offline' and each has a different fix. * The five guards, green: check:imports, check:swagger, check:externals, and both suites. What is deliberately NOT registered: the Team provider, triggers, audiences, engagement seeds, notification streams, the four event catalogues, and the two extension slots. Each arrives with the phase that has something real to put in it, and a test asserts their absence so that removing it is deliberate. A declared trigger nothing emits and a declared slot nothing fills are both surfaces an operator can configure and then wait on, which is worse than an absent one because the absence is visible. Two corrections to the kit's template, both feedback for a later phase: * registration.test.js read one page BY NAME to check declared slots are rendered, so a module declaring none dies on ENOENT before reaching the loop that would have been empty. It now scans every file under src/routes. * test/_fakes.js supplied validator: {}. An admin router that builds validation chains at file scope cannot be required with that, so the fake holds the real express-validator -- for the same reason it holds a real express Router. The kit was right about noGameConnection.test.js: its header predicts that a module adding a sidecar client will see the check go red, names sidecarClient.js as the file to allow, and says narrow it rather than delete it. That is exactly what happened on the first run, and the fix was the one line the header names. Installed into a real core and verified: the module reaches 'started', publishes its capability, serves its chunk, and renders a server whose server.hello originated in a live Rust server. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4