The module half of the read path. Seven tables, an ingest cursor, four public routes, and one file whose only job is deciding who may see what. **The record and the window are different things.** `rust_player_wipe_stats` and `rust_gather_totals` are permanent and per-wipe, so all-time is those rows SUMmed rather than a second set of counters that can disagree with them — that is R12's "per-wipe detail plus all-time rollups" in one table instead of two. `rust_events` is a bounded 30-day window of raw frames for the killfeed, and `rust_presence` is a board: replaced wholesale, never appended. **The feed is a cursor, not a socket, and the header says why.** Core runs Node 20, where a global WebSocket is still behind a flag, so a socket means taking `ws` — against a release that asserts it has no runtime dependencies (D5). The deciding argument is the other one though: a socket needs a cursor anyway, for whatever it missed while the module was restarting, and the catch-up path is the one that has to be right. A cursor alone is one mechanism exercised every five seconds rather than two where the second only runs after an outage. **The cursor advances after the batch, never before.** A crash between the two re-reads events already counted, which inflates a total; the other order loses them silently and for ever. One is visible and bounded, the other is invisible and permanent, so the code fails in the visible direction. A server with no cursor starts at the sidecar's current END rather than at zero — replaying a fortnight of deaths into stats for wipes the site never saw is not a catch-up. **`catalogue.js` is a security boundary, default-deny.** Protocol 2 carries IP addresses (login attempts, approvals, bans), one player's report about another, and the grid reference of somebody's base. They are stored, because an operator chasing ban evasion needs them; they are not served below the admin tier. The allowlist lives here rather than as a field on the wire, because a boundary declared by the sender is one a compromised or merely out-of-date game host can widen — the same reason core's own shard fan-out filters on the serving side. A kind this build has never heard of is not public, and a test holds the list against PROTOCOL.md §8.4 so that adding a kind to the protocol without classifying it fails a build. `PROTOCOL_VERSION` goes to 2 here in the same change as the emitters, though this module consumes none of the new frames yet: the sidecar refuses a mismatched client with a 409, so a module left on 1 would stop being able to read the board it has been reading all along. A constant that lags the deployment is an outage with a version number on it. 95 server tests, 20 client tests, every guard green, and `routes.manifest.json` regenerated against a real core at the pinned ref: 10 routes, all documented, none of core's moved. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
50 lines
2.3 KiB
JSON
50 lines
2.3 KiB
JSON
{
|
|
"$comment": [
|
|
"What a release copies into the bundle, declared ONCE. Read by .gitea/workflows/release.yml when",
|
|
"it assembles the tarball, and by server/scripts/checkBundle.js when CI asks whether that list",
|
|
"still covers everything the module's entry point can reach.",
|
|
"",
|
|
"This is an INCLUDE list on purpose. An exclude list ships whatever it forgot: the day someone",
|
|
"adds server/tools/ with a scratch credential in it, an exclude list packs it and nobody finds",
|
|
"out. The cost of that choice is that a new top-level directory silently drops OUT of every",
|
|
"release instead — which is exactly what happened to Module-uo between v0.3.0 and v1.0.0, where",
|
|
"server/commands/ arrived with a cutover, the list did not learn about it, and the module",
|
|
"installed and then died at the register stage on the operator's box. checkBundle.js exists so",
|
|
"that cannot happen twice, and it runs on the PR that adds the directory.",
|
|
"",
|
|
"server[] entries are paths under server/; root[] and generated[] are paths under the module",
|
|
"root.",
|
|
"",
|
|
"node_modules is NOT here, and its absence is asserted rather than assumed: this module declares",
|
|
"no runtime dependencies (everything the shipped half needs arrives on ctx), so the release runs",
|
|
"no npm ci and packs no dependency tree. checkBundle.js fails the PR that adds a `dependencies`",
|
|
"entry to server/package.json without also teaching the release to pack it — because a module",
|
|
"whose bundle silently lacks its own dependency fails the same way the missing directory did.",
|
|
"",
|
|
"generated[] ships but is not copied — release.yml writes module.json through jq to stamp the",
|
|
"released version into it, since the committed one is a floor rather than a record of the last",
|
|
"release. It is listed because server/index.js requires it, and a check that did not know it",
|
|
"ships would report the module's own manifest as missing from the bundle."
|
|
],
|
|
"server": [
|
|
"boot.js",
|
|
"catalogue.js",
|
|
"core.js",
|
|
"db",
|
|
"index.js",
|
|
"ingest.js",
|
|
"model",
|
|
"package.json",
|
|
"router",
|
|
"sidecarClient.js"
|
|
],
|
|
"root": [
|
|
"swagger-fragment.json",
|
|
"LICENSE.md",
|
|
"README.md"
|
|
],
|
|
"generated": [
|
|
"module.json"
|
|
]
|
|
}
|