docs(rust): protocol 13 opens — the configuration save that answers first (PROTOCOL.md §19)

§19 starts protocol 13 with its first piece: config.write answers pending
with a writeId and ceilingMs, a reload fails on the framework log's evidence
under a 30 s ceiling judged by what is loaded, a rollback waits for the
restore, and the outcome is a staff-class config.outcome event (F9, F10,
D178). F15's UTF-8 decode rides in the same release. §11.4 points at the
amendment; §2 says 13. PLAYER_WALK.md's configuration steps now expect
"Saved. Reloading…", add a cold-compile save and a non-ASCII save, use
Kits' chat command instead of a ZoneManager setting that does not exist
(D-2), and name Carbon's failure wording as the thing step 4 pins.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
2026-09-26 17:19:14 -05:00
parent f015772425
commit b9d8689061
2 changed files with 117 additions and 5 deletions

View File

@@ -205,9 +205,11 @@ other, which is the whole point of putting them in one container.
| # | Do this | You should see |
|---|---|---|
| 1 | **Open Admin → Rust mod config** and pick the server | The tree the framework actually uses — `oxide/config` on Oxide, `carbon/configs` on Carbon — grouped by plugin, with every loaded plugin's version beside it |
| 2 | **Open `ZoneManager.json`, change a setting, leave the reload target on its guess, and save** | "Saved, and the plugin reloaded." At the console, `oxide.show`/`c.show` is irrelevant — the proof is the plugin behaving differently, so pick a setting you can see: `Auto Show Zones`, or an entry message |
| 2 | **Open `Kits.json`, change Kits' chat command, leave the reload target on its guess, and save** | "Saved. Reloading Kits…", then — without leaving the page — "Saved, and the plugin reloaded." The proof is the game behaving differently: the new command works in chat for every player. (ZoneManager 3.1.14 has no "Auto Show Zones", D-2) |
| 2a | **Do step 2 again after the server has been idle over a minute** (Oxide's compiler stops after 60 s) | The same answer, however long the cold compile takes. Protocol 12 rolled this edit back (F9); `rg.config` at the console shows the write waiting, and for how long |
| 2b | **Save a value with é, — and an emoji** in a string field | The file on the host holds the same characters, not `é` or `â€"` (F15) |
| 3 | **Check a float nobody touched**, e.g. a rate ending `.0`, in the file on the host | It is still `1.0`, not `1`. This is the trap the whole editor exists for, and a server whose configs are full of whole-numbered floats is where it bites |
| 4 | **Break a config on purpose** — in Raw JSON, give a numeric field a string, or anything the plugin's own class cannot deserialize — and save with that plugin as the reload target | Within about four seconds: *"The plugin did not come back, so the old file was put back automatically"*, the compiler's own line underneath it, and the file on the host back as it was. `oxide.plugins` shows the plugin **loaded** — because the restore was reloaded too |
| 4 | **Break a config on purpose** — in Raw JSON, give a numeric field a string, or anything the plugin's own class cannot deserialize — and save with that plugin as the reload target | "Saved. Reloading…", then within a few seconds *"The plugin did not come back, so the old file was put back automatically"*, the framework's own line underneath it, and the file on the host back as it was. `oxide.plugins` shows the plugin **loaded** — the outcome waits for the restore's reload, and says so if the plugin did not come back on the old file either |
| 5 | **Save a nested file** (`Kits/kits.json`, or any `config/<Mod>/x.json`) **and confirm the reload target** | The right plugin reloads. Reloading the wrong one is the failure this field exists to prevent, and it reports success — so check `oxide.plugins`' timestamps, not the website's word |
| 6 | **Open the bridge's own config** | `Host`, `Port` and `ServerId` are read-only with the reason; `QueueCap` saves; the reload dropdown does not offer this plugin. The save says it was written and **not** reloaded, which is the honest answer — our settings apply on the next deliberate reload |
| 7 | **Edit a file on the host over SSH while the website has it open, then save from the website** | A conflict, with the current file offered — never an overwrite |
@@ -222,9 +224,12 @@ this phase has two specific things to confirm rather than assume:
exactly like a command that worked (`CARBON.md` §5), so the proof is `OnPluginLoaded` arriving,
not the command being accepted.
- **`OnPluginLoaded` / `OnPluginUnloaded` firing at all.** They are the rollback's only evidence. If
either does not fire on a framework, every save there rolls itself back four seconds later and
reports a plugin that is in fact perfectly fine. `rg.hooks` at the console is the standing answer:
either does not fire on a framework, every save there waits out the 30-second ceiling, and the
plugin then has to judge by whether the target is loaded (PROTOCOL.md §19.1). `rg.hooks` at the console is the standing answer:
both names are in `ExpectedHooks`, so a framework that never raises one shows a zero.
- **The failure words.** Since protocol 13 a broken reload is recognised by the framework's log line
(PROTOCOL.md §19.1). Step 4 on Carbon is what pins Carbon's wording: if it waits the full 30 seconds
before rolling back, the line Carbon printed is not on the list yet.
**What counts as a pass:** a setting typed on the website changes what the running game does; a
deliberately broken config leaves the plugin loaded and the operator holding the reason; and no file