diff --git a/modules/rust/PLAN.md b/modules/rust/PLAN.md index 87851aa..d2f93cb 100644 --- a/modules/rust/PLAN.md +++ b/modules/rust/PLAN.md @@ -1,7 +1,7 @@ # `module-rust` — the plan **Before the Module-Rust cutover (phase 19):** the first player walk's fixes and the org lead's -decisions from it (D159–D175) are planned in [`PLAN_FIXES.md`](PLAN_FIXES.md), 2026-09-26. +decisions from it (D159–D179) are planned in [`PLAN_FIXES.md`](PLAN_FIXES.md), 2026-09-26. **Status:** phases 0 and 1 done, 2026-09-15. **Twenty-two decisions of record, no open questions.** Audited against the whole contract, not just the game-facing chapters (§7); the event and engagement catalogues are §9 and §10; §11 is a second pass over `MODULE_API.md` @@ -6989,7 +6989,7 @@ line, `confirms it connected.` (installer#34). The first walk of [`PLAYER_WALK.md`][pw] with a real player (the Oxide pass, org lead in game) found fifteen places where the bridge or the site does something other than this plan and [`PROTOCOL.md`][protocol] say, and the -org lead took seventeen decisions on it (D159–D175) — among them **D160, which reverses D31**: the site now owns every +org lead took seventeen decisions on it (D159–D175), and four more as step 1 began (D176–D179) — among them **D160, which reverses D31**: the site now owns every permission and group, not only those it authored. They are planned in their own document, [`PLAN_FIXES.md`](PLAN_FIXES.md), so this one stays a record of the phases as built. diff --git a/modules/rust/PLAN_FIXES.md b/modules/rust/PLAN_FIXES.md index d55c895..05e93f9 100644 --- a/modules/rust/PLAN_FIXES.md +++ b/modules/rust/PLAN_FIXES.md @@ -1,7 +1,7 @@ # `module-rust` — plan fixes -**Status:** plan, awaiting the org lead's approval, 2026-09-26; its four open questions were answered the same -day (D169–D175). **Everything in it — fixes and redesigns alike — lands before Module-Rust's cutover +**Status:** plan, approved 2026-09-26; its open questions were answered the same day (D169–D175), and step 1's +shape was settled as work began (D176–D179). **Everything in it — fixes and redesigns alike — lands before Module-Rust's cutover (phase 19, [`PLAN.md`](PLAN.md) §34, D145; D169).** Everything here comes from the first walk of [`PLAYER_WALK.md`](../../rust-link/PLAYER_WALK.md) with a real player in the game — the Oxide pass, walked by the org lead on the `rust-oxide` rig with every frame checked on the console, the sidecar and the site's @@ -59,6 +59,10 @@ Taken by the org lead during and straight after the walk. | **D173** | **"Quests completed" counts Rust's own missions** — the ones the game's NPCs already hand out on the map. No quest plugin. How the bridge detects a completed mission is settled by a spike on the rig (§4.6), because uMod's catalogue names no mission hook and [`CARBON.md`](CARBON.md) lists none among Carbon's own. | | **D174** | **The title rules §4.6 recommended are adopted:** the two kill-distance titles are *best* columns (the longest single kill), not sums; a weapon-class kill counts any kill the player is credited with (players, NPCs, animals), from weapon lists kept in one place; the APC and the helicopter credit the killing blow; healing counts only other players. | | **D175** | **The titles in §4.6 are the module's defaults, not fixed names.** An admin can write their own title for any category, and it supersedes the default everywhere that category is used; clearing it brings the default back. A rule may still carry its own text, which wins over both. | +| **D176** | **F15 is held for protocol 13** and releases with it, not ahead of it as a patch. Rejected: a Rust-Plugins v0.1.2 on protocol 12. | +| **D177** | **F9 and F10 open protocol 13.** They are built first, on `edge` in Rust-Plugins, Rust-Link and Module-Rust; the rest of §6 step 2 joins the same bump, and all of it releases together. Rejected: F9 alone as protocol 13 with the rest as 14; and a wider window now as a stop-gap. | +| **D178** | **A reload fails on evidence, not on a clock.** While a configuration reload is pending the plugin reads the framework's new log lines each second and rolls back the moment they show the target plugin failing to compile or initialise. The ceiling is 30 s; when it passes, the plugin checks whether the target is loaded (a hook it missed) before restoring anything, and reports what actually loaded (F10). A framework hook for a failed load, if the rig shows one, replaces the log read. Rejected: the clock alone with a longer ceiling, which leaves a broken plugin down for the whole ceiling. | +| **D179** | **The configuration page polls the write.** The save is recorded as `reloading`; ingest settles that row from the outcome frame, and the page polls it every couple of seconds until it does. Rejected: pushing the outcome over the admin event stream. | ## 2. Fixes @@ -87,7 +91,9 @@ needing no compile, passed. The window races work whose length the plugin does n plugin size, Carbon's own compiler. Operators must not have to tune Oxide to make the site work. *Fix:* answer the save at once ("saved, reloading…") and deliver the outcome as a frame when it arrives, under a long ceiling (30 s or more). Roll back on a real failure — Oxide logs "Failed to initialize plugin" the moment -it happens (configuration step 4 showed it) — not on a clock. Protocol-visible (§5). +it happens (configuration step 4 showed it) — not on a clock. Protocol-visible (§5). Settled by D177–D179: the +plugin reads the log for that failure, the ceiling is 30 s with a loaded check before any restore, and the site +records the write as `reloading` and polls it. **F10 — the rollback can say "did not come back" about a plugin that did, and can race it.** *(Rust-Plugins)* After F9's timeout the plugin restored the file and fired a second reload, but the log shows one compile, so @@ -366,13 +372,16 @@ once: building, repairs, heals, rockets, explosives, and the two per-interval maxima for kill distance (§4.6). - `world.expired` handled by the site (F14, D170) — no wire change beyond F13's. -F15 changes no message shape and ships ahead of the bump. +F15 changes no message shape, but it is held for the bump and releases with it (D176). The work lands on `edge` +in Rust-Plugins, Rust-Link and Module-Rust, and the three cut over to `main` together once §6 step 2 is done +(D177). ## 6. Order, and what gates the cutover **All of it lands before Module-Rust's cutover (D169).** The order inside that: -1. **First:** F15 (data corruption), and F9 + F10 (they throw away edits). Small; F15 changes no message shape. +1. **First:** F15 (data corruption), and F9 + F10 (they throw away edits) — the opening of protocol 13, on `edge` + (D176, D177). 2. **Protocol 13 with the remaining fixes:** F13, F14, F12, F1, F3, F8, F7, F2, F4 in the bridge and the module, and F5/F6 in the module. 3. **The redesigns**, each planned in detail before code and walked on both frameworks: the permission manager