feat(events): what an author borrows, and two one-shots (Phase 12b)
Five targeted leases over two planes, the item grant, the world save, and the atlas work the spawner dropdown needed. FIVE LEASES, ONE FACTORY `uo.spawner.maxcount`, `.mindelay`, `.maxdelay`, `.running` and `uo.seasonal.status`. The four callables differ only in which key they name, so they are built rather than repeated: five copies would be five chances for one of them to forget the drift check, which is the one thing §F says a lease must not be allowed to skip. It is `MaxCount`, not the `Amount` EVENTS_PLAN.md named -- there is no such property on ServUO 57.4. `MinDelay`/`MaxDelay` are TimeSpans, so the wire carries SECONDS: the spawn files' own `DelayInSec` flag proves both units are in use on a real tree, and a unit that cannot express five seconds cannot express this shard's own data. The seasonal lease is a THREE-value enum over EIGHT events. §G called `GetEntry(type).Status` "a nine-value enum" and had it backwards: `EventStatus` has three values and it is `EventType` that has nine entries. Eight rather than nine because `TreasuresOfTokuno` is excluded -- `IsActive()` reads its own `DropEra` rather than `Status`, so leasing it would apply cleanly, read back, restore cleanly and do nothing at all. Two behaviours worth the review. `inForce()` reads the frame's `holds` rather than a row's `held` flag, because a catalog walk can enumerate the keys but never the holds on a targeted one. And a target that VANISHED mid-run is a SUCCESSFUL restore: there is nothing to give back, and reporting it failed would leave a ledger row unresolved for ever over an object that is gone -- 12a's `gone` in the lease plane's vocabulary. THE GRANT NAMES A RUN, NEVER A RECIPIENT LIST Core has the participants in `event_run_participants`, but a module cannot read core's tables -- so the alternative was a new core surface handing them over. Not needed: the shard has held the run's ledger since it opened, keyed by the same serials core stores as `member_key`. And the grant is RETRYABLE. §G called it un-retryable because a lost acknowledgement and a grant that never applied were the same event, which is exactly the argument that made `uo.broadcast` answer `retry: false` in Phase 9. Protocol 6's idempotency key closes it. `uo.rewards` counts ITEMS rather than grants: 500 gold to forty people and a candle to forty people are not the same imposition. THE ATLAS KEEPS UniqueId AGAIN, AND THE SPAWNER SOURCE SEARCHES The parser has read `<UniqueId>` and thrown it away since the atlas shipped, on a line citing a committed artifact -- there is no committed artifact, as `spawnAtlasSource.js` says in its own header. It is the ONLY name for one particular spawner that exists off the shard, so a property lease could not have had a dropdown without it. `PARSER_VERSION` -> 4 so an unchanged tree is re-read. `uo.options.spawners` is the first searchable source and the first that had to be: 6,707 spawn points against `MAX_OPTIONS`' 2,000, so a flat list would drop two thirds of the world and say nothing about which two thirds. ONE DEFECT IN ALREADY-MERGED CODE, AND IT WOULD HAVE BROKEN EVERYTHING The protocol pin never left 5. `uo_link_config.protocol` reaches the sidecar as `X-UOLink-Version` on every REST call and an exact mismatch is a 409, so from Phase 11a onward every sidecar call on a real deployment would have been refused -- the whole event plane dead, loudly, for a reason nobody would look here for. 11a took the wire to 6 and 12a to 7; neither moved the pin, in either of the two places this repo declares it. It survived both because both live walks set the column by hand while standing the rig up, which is exactly what makes a migration nobody runs invisible. All three sites go to 7. The test that guards them is worth understanding before trusting it: `schemaFragment.test.js` asserts the three declarations agree WITH EACH OTHER -- a real check they once failed -- but all three being equally stale passes it, and nothing in this repo can anchor it to the wire. Recorded in the model's own header so the next reader knows. CHECKS `npm test`: 620 pass, 0 fail (was 605). `check:imports` and `check:externals` clean; the client builds and its 42 tests pass. `check:swagger` reports the fragment stale -- it is ALREADY stale on `edge` (verified by stashing this branch's changes and re-running) and this phase adds no route, so it is left alone rather than regenerated inside an unrelated change. Two bugs the new tests caught in this branch's own code before it left: `counted()` returns `.count` and the grant read `.value`, so every grant went out with `amount: undefined` and the non-stackable guard never fired; and `optionalInt`'s `ok` was ignored, so a bad hue passed silently instead of refusing. Refs: docs/link/v7.md §11-§14, docs/website/EVENTS_PLAN.md Phase 12b Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
This commit is contained in:
@@ -236,28 +236,45 @@ const adminBroadcast = ({ actor, text, hue, idempotencyKey }) =>
|
||||
// holding it. One read serves both questions core asks — `read()` wants the
|
||||
// current value, `inForce()` wants to know whether the shard still has a record
|
||||
// of the hold — so a lease costs one round trip, not two.
|
||||
const getLeases = () => call('/lease')
|
||||
// **A targeted lease must name its target here** (protocol 7 part b). A key like
|
||||
// `Spawner.MaxCount` is one capability over thousands of spawners, so it has no
|
||||
// single `current` and the catalog walk cannot fill one in — while `read()` needs
|
||||
// exactly one value for exactly one target before it applies anything. Naming both
|
||||
// narrows the frame to that row and fills it.
|
||||
//
|
||||
// The frame also carries `holds`: every hold this shard has, whatever key or
|
||||
// target. A catalog walk enumerates the KEYS but can never enumerate the holds on
|
||||
// a targeted one — there is no list of spawners to walk — so `inForce()` reads
|
||||
// that rather than the row's `held` flag.
|
||||
const getLeases = ({ key, target } = {}) => {
|
||||
const params = new URLSearchParams()
|
||||
if (key) params.set('key', key)
|
||||
if (target) params.set('target', target)
|
||||
const query = params.toString()
|
||||
return call(query ? `/lease?${query}` : '/lease')
|
||||
}
|
||||
|
||||
// `holdMs` is authoritative and `untilMs` is display only. An absolute deadline
|
||||
// computed here and honoured there is a deadline measured against two clocks, and
|
||||
// a shard running ten minutes fast would restore a ten-minute lease the moment it
|
||||
// took it. Values cross as TEXT whatever the lease's declared type: `1200` and
|
||||
// `1200.0` are one number to a JSON parser and two strings to a compare-and-set.
|
||||
const applyLease = ({ key, value, holdMs, untilMs, runId, idempotencyKey }) =>
|
||||
const applyLease = ({ key, target, value, holdMs, untilMs, runId, idempotencyKey }) =>
|
||||
call('/lease', {
|
||||
method: 'POST',
|
||||
body: { key, value: String(value), holdMs, untilMs, runId, idempotencyKey },
|
||||
body: { key, target, value: String(value), holdMs, untilMs, runId, idempotencyKey },
|
||||
})
|
||||
|
||||
// `expected` is what this run applied and `baseline` is what to put back, both out
|
||||
// of core's ledger rather than the shard's memory — so a release still works after
|
||||
// a reconnect, and a shard that has forgotten the lease entirely (a restart, which
|
||||
// reverts every config lease by design) answers honestly instead of refusing.
|
||||
const releaseLease = ({ key, expected, baseline, idempotencyKey }) =>
|
||||
const releaseLease = ({ key, target, expected, baseline, idempotencyKey }) =>
|
||||
call('/lease/release', {
|
||||
method: 'POST',
|
||||
body: {
|
||||
key,
|
||||
target,
|
||||
expected: expected == null ? undefined : String(expected),
|
||||
baseline: baseline == null ? undefined : String(baseline),
|
||||
idempotencyKey,
|
||||
@@ -324,6 +341,35 @@ const respondPage = (pageId, { message, close }) =>
|
||||
call(`/pages/${encodeURIComponent(pageId)}/respond`, { method: 'POST', body: { message, close } })
|
||||
const closePage = (pageId) => call(`/pages/${encodeURIComponent(pageId)}/close`, { method: 'POST' })
|
||||
|
||||
// ── The one-shots (protocol 7 part b, EVENTS_PLAN.md Phase 12b) ────────────
|
||||
//
|
||||
// Neither owned nor borrowed: done is done. Both are gated on the shard by the
|
||||
// same `Bridge.EventsEnabled` as the rest of the plane.
|
||||
|
||||
// What this shard will actually build, with the bounds it will build within. The
|
||||
// module holds the same allowlist for its dropdown, so the form still works with
|
||||
// the shard down; this is what is true when that copy is wrong.
|
||||
const getGrantCatalog = () => call('/items')
|
||||
|
||||
// **The recipients are not sent.** The shard has held this run's participation
|
||||
// ledger since it opened, keyed by the same character serials core stores as
|
||||
// `member_key`, so the grant names a run and the shard resolves who was there.
|
||||
// Sending a list would put the same list on the wire twice with a window in which
|
||||
// the two disagree — and would have needed a core surface handing a module core's
|
||||
// own participants.
|
||||
const grantItem = ({ runId, item, amount, hue, name, where, idempotencyKey }) =>
|
||||
call('/items/grant', {
|
||||
method: 'POST',
|
||||
body: { runId: String(runId), item, amount, hue, name, where, idempotencyKey },
|
||||
})
|
||||
|
||||
// Starts a save. What actually happened rides `world.save.before`/`after` on the
|
||||
// event stream, which have been there since protocol 2 — so this asserts only that
|
||||
// the save was started, and a caller that needs the completion watches the feed it
|
||||
// is already connected to.
|
||||
const saveWorld = ({ idempotencyKey } = {}) =>
|
||||
call('/world/save', { method: 'POST', body: { idempotencyKey } })
|
||||
|
||||
module.exports = {
|
||||
TIMEOUT_MS,
|
||||
invalidateConfig,
|
||||
@@ -361,6 +407,9 @@ module.exports = {
|
||||
spawnWorld,
|
||||
ownedWorld,
|
||||
despawnWorld,
|
||||
getGrantCatalog,
|
||||
grantItem,
|
||||
saveWorld,
|
||||
adminKick,
|
||||
adminBan,
|
||||
adminUnban,
|
||||
|
||||
Reference in New Issue
Block a user