docs(rust): perm.inventory in PROTOCOL 19.9, and the permission manager as built
PROTOCOL.md 19.9 specifies perm.inventory (owners, groups with parents, holders, leased pairs; sliced, paged, one snapshot) and perm.sync's protocol-13 changes (parents, titles and ranks written, absent means leave it, managed and foreign gone). PLAN_REDESIGNS 1.9 records what the build settled and the walk on both rigs. Refs RunicGateway/Module-Rust#21 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
@@ -222,6 +222,56 @@ rig), and a change to a shared group (split off, the other rig unchanged). Then
|
||||
and Grant all / Revoke all. The plugin buttons must be by owner: `nokits` is under ZoneManager. The
|
||||
large-store measurement is in §1.2.
|
||||
|
||||
### 1.9 As built, and as walked (2026-09-28)
|
||||
|
||||
Rust-Plugins `feat/perm-inventory`, Rust-Link `feat/perm-inventory`, Module-Rust `feat/perm-manager`. The
|
||||
wire is [`PROTOCOL.md`](../../rust-link/PROTOCOL.md) §19.9, and the admin API is the module's swagger
|
||||
fragment (`/admin/rust/permissions…`).
|
||||
|
||||
**What the build settled that the plan left open:**
|
||||
|
||||
- **The data model.** Groups are rows with ids: `rust_permgroups`, plus `_servers` (with `included = 0`
|
||||
to take one server out of an all-servers group), `_permissions`, `_members`, `_steam_members` and
|
||||
`_chat`. The chat style belongs to a group row now, because one server's `vip` may be styled
|
||||
differently. Steam-account grants are `rust_perm_steam_grants`, and D190's exceptions are
|
||||
`rust_perm_exceptions`. `rust_servers.perm_policy`, `rust_perm_sync.imported_at`,
|
||||
`rust_perm_catalogue.owner` and `rust_perm_drift.direction` are new columns. The old group tables
|
||||
are copied once at boot (a `rust_settings` marker makes it once) and are then left unread.
|
||||
- **Every sync is read → reconcile → push.** The reconcile step runs under one fleet-wide lock, so two
|
||||
servers never split one shared group at once. Each desired row remembers the authored rows that
|
||||
produced it (its *sources*). That is how a removal knows whether to delete a row, add an exception, or
|
||||
split a group.
|
||||
- **Two things are never judged.** A permission the server does not register right now (an unloaded
|
||||
plugin is not a revocation), and a pair an event lease holds.
|
||||
- **A removal at the first import is pushed back**, not deleted. D198 imports what is present; a
|
||||
snapshot taken the moment the site first looked is not taken as a revocation.
|
||||
- **An event's grant removed in the game** is pushed back under auto-adopt, with a notice. The event
|
||||
owns it, and its revert withdraws it.
|
||||
- **Under `adopt`**, a removal or a changed group is *held*: it is not pushed back, retired or recorded
|
||||
until a person answers. "Put back" works by forgetting the ledger row, and the next sync pushes it.
|
||||
- **A group the site already authored keeps the site's title** at import. `walkvoice`, made by the site
|
||||
before the rebuild, overwrote the game's empty title with "Walk voice" on Oxide.
|
||||
- **The announcement voice names a group by id.** A setting saved as a name before the rebuild still
|
||||
resolves, to the first styled group of that name.
|
||||
|
||||
**Walked** on `rust-oxide` and `rust-carbon`, against the walk core on `rustp16` (backed up first):
|
||||
|
||||
| Case | Result |
|
||||
|---|---|
|
||||
| Migration of the old groups | 2 copied (`site` → Oxide only; `walkvoice` → every server) |
|
||||
| First import (D198) on an existing install | Oxide: `default`, `admin` made its own, 2 hand grants → Steam grants, the site's own grants recorded as landed; Carbon: `default`, `admin`, `moderator` with titles kept byte for byte |
|
||||
| Auto-adopt: `oxide.grant` + `oxide.revoke` | adopted within one 30 s tick; the revoked Steam grant deleted |
|
||||
| Fleet grant (`*`) revoked in the game on Oxide (D190) | an exception for `rust-oxide`; still pushed and landed on Carbon |
|
||||
| `oxide.unload Kits` | nothing deleted; the report lists both `kits.*` as unresolved |
|
||||
| `c.grant group walkvoice kits.admin` on Carbon (D190) | split: Carbon got its own `walkvoice` with the change and the style; the shared one excludes Carbon; a notice waits |
|
||||
| Policy `adopt` | one addition and one removal waited; the removal was held, not pushed back; adopt and accept answered them |
|
||||
| Policy `revoke` | an in-game grant undone at the next sync (`revokes: 1`) |
|
||||
| Server view | plugins by owner (`nokits` under ZoneManager), groups with where they are, players named, the exception listed |
|
||||
|
||||
**Not walked yet:** a group with a parent; sharing and unsharing from the screen, and its conflict answer;
|
||||
Grant all / Revoke all; the screen itself in a browser (every endpoint behind it was called); and the
|
||||
large-store measurement.
|
||||
|
||||
---
|
||||
|
||||
## 2. The event step editor and the kit weekend (§4.2, §4.3; U-3–U-6, F11; D164)
|
||||
|
||||
Reference in New Issue
Block a user