feat(assets): the panel that operates the client-file imports (Phase 8)
Some checks failed
PR Checks / frozen-manifest (pull_request) Successful in 1m3s
PR Checks / server-tests (pull_request) Successful in 8m4s
PR Checks / client-build (pull_request) Failing after 14m21s

Admin -> Client Files: one page over the three things that come out of the
operator's UO client -- creature portraits, item and land pictures, and the
cliloc table. One page rather than three because they are one job: same client
install, same bridge, and all of them change at the same moment, when the
operator patches that client. Boot never asks the shard for any of it, so these
buttons are the only thing that imports.

The cliloc pair had had no UI at all since phase 2. On a bridged install, where
boot deliberately stopped calling the shard, that meant `curl` was the only way
to load 67,496 names.

Update and Re-import everything are section 6's two stages as two buttons rather
than one button and a checkbox, because they cost wildly different things. A
vanished key is reviewed in the page and not in a table -- an asset import only
happens because someone pressed a button here, so the review is already in front
of the person who caused it -- and it shows each key's PICTURE, since
`body/820/a23` names nothing a human recognises. `shard_asset_meta` gained a
`last` block (what the import did, who ran it) so the panel can answer "did last
week's import do anything" without scrolling core's whole activity log.

The live walk against a real shard imported 1,095 portraits in 3.5 s, warmed 313
item pictures in 0.6 s and reloaded 67,496 cliloc rows in 1.7 s -- and found two
DELETIONS that predate this phase and that no test could see, because only a
screen showing the numbers together makes them visible:

  * The body import diffed its manifest against every family's rows. Phase 5 put
    item and land art in the same table, and a body manifest never mentions
    them, so all 313 item pictures were staged for deletion with a sentence
    saying the shard had stopped offering them.
  * An approved vanish unlinked the sprite and kept the row. The catalogue went
    on counting a picture that was gone, the atlas could point a creature page at
    a missing file, and the next forced import offered the same key for review
    again -- reporting "nothing was changed" about a file it had deleted.

Both fixed here, with the removals now inside `saveAssets`'s own transaction.
The same whole-table read made the panel announce a 1,408-row creature catalogue
on an install holding 1,095 portraits and 313 item pictures.

Protocol stays 8 and EXTRACTOR_VERSION stays 3: nothing on the wire changed.

Refs: docs/link/v8.md sections 12.2, 14, 16 (phase 8)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
This commit is contained in:
2026-09-14 08:10:16 -05:00
parent 7dbdaa14ad
commit 675e879b48
13 changed files with 1451 additions and 54 deletions

View File

@@ -176,8 +176,12 @@ function removeSprite(name) {
* an operator recovers from a deleted uploads directory — the database still
* holds the hashes, but the files behind them are gone). `approve` accepts a
* catalogue that no longer offers keys we hold.
*
* `by` is who pressed the button, carried through only so the panel can say what
* the last import did and who ran it without reading the audit log (phase 8). It
* decides nothing.
*/
async function importAssets({ force = false, approve = false } = {}) {
async function importAssets({ force = false, approve = false, by = null } = {}) {
if (!(await shardLinked())) {
return {
status: 'skipped',
@@ -207,7 +211,7 @@ async function importAssets({ force = false, approve = false } = {}) {
const meta = await db.getMeta().catch(() => null)
if (!force && bridge.sameSources(sources, meta?.sources)) {
const counts = await db.countAssets()
const counts = await db.countAssets(bridge.FAMILY)
const bodies = await db.countBodies()
return {
@@ -228,7 +232,10 @@ async function importAssets({ force = false, approve = false } = {}) {
return failure(err, 'asset manifest')
}
const held = await db.allAssets()
// The body family only. This diff decides what gets DELETED, and the manifest
// it is diffed against is of one family by construction — so reading the whole
// table here stages every item picture phase 5 warmed as a vanished key.
const held = await db.allAssets(bridge.FAMILY)
const offered = new Set(manifest.rows.map((r) => r.key))
// A key we hold that the shard no longer offers. An unmounted client volume and
@@ -243,7 +250,11 @@ async function importAssets({ force = false, approve = false } = {}) {
reason:
`${vanished.length} asset(s) this site holds are no longer offered by the shard; ` +
'nothing was changed',
vanished: vanished.slice(0, 50),
// Each one carries the picture it currently has, because the decision the
// operator is being asked for is "is it right that these disappear?" and a
// list of keys cannot be looked at. `body/820/a23` names nothing a human
// recognises; the horse it is a picture of does.
vanished: vanished.slice(0, 50).map((key) => ({ key, file: held.get(key)?.file ?? null })),
vanishedCount: vanished.length,
}
}
@@ -318,14 +329,21 @@ async function importAssets({ force = false, approve = false } = {}) {
}
try {
await db.saveAssets(rows, {
catalog: manifest.catalog,
extractorVersion: manifest.extractorVersion,
family: bridge.FAMILY,
playerBodies: manifest.playerBodies,
sources: { files: sources.files, extractorVersion: sources.extractorVersion },
count: rows.length,
})
await db.saveAssets(
rows,
{
catalog: manifest.catalog,
extractorVersion: manifest.extractorVersion,
family: bridge.FAMILY,
playerBodies: manifest.playerBodies,
sources: { files: sources.files, extractorVersion: sources.extractorVersion },
count: rows.length,
},
// The approved removals go in with the write. The sprite is already
// unlinked above; leaving the row behind would keep counting a picture
// that is gone and re-offer the same key for review on every import.
removed,
)
} catch (err) {
return { status: 'failed', reason: err.message }
}
@@ -333,6 +351,36 @@ async function importAssets({ force = false, approve = false } = {}) {
const bodies = await resolveAtlasBodies()
const art = await applyArt()
// What this run did, kept beside the catalogue it produced (phase 8). The admin
// panel renders it as "the last import", which is the question an operator has
// straight after pressing a button that takes a minute and prints nothing:
// what changed, and did the body pass find drift. Core's activity log records
// the same action, but it is one unfiltered list of every admin action on the
// site, so an import from three client patches ago is not findable there.
//
// Best-effort on purpose: the import has already applied, and losing a cosmetic
// summary must not turn a successful import into a failure.
const last = {
at: new Date().toISOString(),
by,
force,
approve,
assets: rows.length,
fetched: fetched.assets.size,
written,
removed: removed.length,
absent: fetched.missing.absent,
unsupported: fetched.missing.unsupported,
bodies: bodies.tally ?? null,
art: art.applied ?? 0,
}
try {
await db.recordLastImport(last)
} catch (err) {
log.warn('could not record the import summary', { error: err.message })
}
log.info('asset import applied', {
assets: rows.length,
fetched: fetched.assets.size,
@@ -460,12 +508,21 @@ async function applyArt() {
* state with a reason an operator can act on.
*/
async function getStatus() {
const counts = await db.countAssets().catch(() => ({ total: 0, stored: 0 }))
// The BODY family, not the whole table: item and land art live here too and
// are reported separately below, because they are a working set rather than a
// catalogue with a size (§11).
const counts = await db.countAssets(bridge.FAMILY).catch(() => ({ total: 0, stored: 0 }))
const bodies = await db.countBodies().catch(() => ({ total: 0, resolved: 0 }))
const meta = await db.getMeta().catch(() => null)
const families = await db.countByFamily().catch(() => ({}))
const status = {
// Is there a shard to ask at all? Stated rather than left to be inferred:
// the panel disables its import buttons on it, and the alternative — reading
// it out of `reason`'s wording, or out of `shard` being null, which is also
// what a shard that is merely DOWN looks like — is a sentence that decides
// behaviour.
linked: await shardLinked(),
loaded: {
assets: counts.total,
stored: counts.stored,
@@ -480,12 +537,18 @@ async function getStatus() {
// for and holds, which is the only number that means anything here.
items: families.static?.stored ?? 0,
land: families.land?.stored ?? 0,
// What the last import did, and who ran it (phase 8). Null on an install
// that has never imported, and on one whose last import predates this
// field — both of which render as "no import recorded" rather than as
// zeroes, because an import that fetched nothing is a real and different
// answer from one that never happened.
last: meta?.last ?? null,
},
shard: null,
drift: null,
}
if (!(await shardLinked())) {
if (!status.linked) {
status.reason = 'uo-link is not configured'
return status
}