docs(rust): plan fixes — D176-D179, how step 1 is built

F15 waits for protocol 13 (D176); F9 and F10 open that bump on edge in all
three repos (D177); a reload fails on the log's evidence under a 30 s
ceiling with a loaded check before any restore (D178); the configuration
page polls the write until it settles (D179).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
2026-09-26 16:55:23 -05:00
parent f015772425
commit d72ccd56dd
2 changed files with 16 additions and 7 deletions

View File

@@ -1,7 +1,7 @@
# `module-rust` — plan fixes
**Status:** plan, awaiting the org lead's approval, 2026-09-26; its four open questions were answered the same
day (D169–D175). **Everything in it — fixes and redesigns alike — lands before Module-Rust's cutover
**Status:** plan, approved 2026-09-26; its open questions were answered the same day (D169–D175), and step 1's
shape was settled as work began (D176–D179). **Everything in it — fixes and redesigns alike — lands before Module-Rust's cutover
(phase 19, [`PLAN.md`](PLAN.md) §34, D145; D169).** Everything here comes from the first walk of
[`PLAYER_WALK.md`](../../rust-link/PLAYER_WALK.md) with a real player in the game — the Oxide pass, walked by
the org lead on the `rust-oxide` rig with every frame checked on the console, the sidecar and the site's
@@ -59,6 +59,10 @@ Taken by the org lead during and straight after the walk.
| **D173** | **"Quests completed" counts Rust's own missions** — the ones the game's NPCs already hand out on the map. No quest plugin. How the bridge detects a completed mission is settled by a spike on the rig (§4.6), because uMod's catalogue names no mission hook and [`CARBON.md`](CARBON.md) lists none among Carbon's own. |
| **D174** | **The title rules §4.6 recommended are adopted:** the two kill-distance titles are *best* columns (the longest single kill), not sums; a weapon-class kill counts any kill the player is credited with (players, NPCs, animals), from weapon lists kept in one place; the APC and the helicopter credit the killing blow; healing counts only other players. |
| **D175** | **The titles in §4.6 are the module's defaults, not fixed names.** An admin can write their own title for any category, and it supersedes the default everywhere that category is used; clearing it brings the default back. A rule may still carry its own text, which wins over both. |
| **D176** | **F15 is held for protocol 13** and releases with it, not ahead of it as a patch. Rejected: a Rust-Plugins v0.1.2 on protocol 12. |
| **D177** | **F9 and F10 open protocol 13.** They are built first, on `edge` in Rust-Plugins, Rust-Link and Module-Rust; the rest of §6 step 2 joins the same bump, and all of it releases together. Rejected: F9 alone as protocol 13 with the rest as 14; and a wider window now as a stop-gap. |
| **D178** | **A reload fails on evidence, not on a clock.** While a configuration reload is pending the plugin reads the framework's new log lines each second and rolls back the moment they show the target plugin failing to compile or initialise. The ceiling is 30 s; when it passes, the plugin checks whether the target is loaded (a hook it missed) before restoring anything, and reports what actually loaded (F10). A framework hook for a failed load, if the rig shows one, replaces the log read. Rejected: the clock alone with a longer ceiling, which leaves a broken plugin down for the whole ceiling. |
| **D179** | **The configuration page polls the write.** The save is recorded as `reloading`; ingest settles that row from the outcome frame, and the page polls it every couple of seconds until it does. Rejected: pushing the outcome over the admin event stream. |
## 2. Fixes
@@ -87,7 +91,9 @@ needing no compile, passed. The window races work whose length the plugin does n
plugin size, Carbon's own compiler. Operators must not have to tune Oxide to make the site work.
*Fix:* answer the save at once ("saved, reloading…") and deliver the outcome as a frame when it arrives, under a
long ceiling (30 s or more). Roll back on a real failure — Oxide logs "Failed to initialize plugin" the moment
it happens (configuration step 4 showed it) — not on a clock. Protocol-visible (§5).
it happens (configuration step 4 showed it) — not on a clock. Protocol-visible (§5). Settled by D177–D179: the
plugin reads the log for that failure, the ceiling is 30 s with a loaded check before any restore, and the site
records the write as `reloading` and polls it.
**F10 — the rollback can say "did not come back" about a plugin that did, and can race it.** *(Rust-Plugins)*
After F9's timeout the plugin restored the file and fired a second reload, but the log shows one compile, so
@@ -366,13 +372,16 @@ once:
building, repairs, heals, rockets, explosives, and the two per-interval maxima for kill distance (§4.6).
- `world.expired` handled by the site (F14, D170) — no wire change beyond F13's.
F15 changes no message shape and ships ahead of the bump.
F15 changes no message shape, but it is held for the bump and releases with it (D176). The work lands on `edge`
in Rust-Plugins, Rust-Link and Module-Rust, and the three cut over to `main` together once §6 step 2 is done
(D177).
## 6. Order, and what gates the cutover
**All of it lands before Module-Rust's cutover (D169).** The order inside that:
1. **First:** F15 (data corruption), and F9 + F10 (they throw away edits). Small; F15 changes no message shape.
1. **First:** F15 (data corruption), and F9 + F10 (they throw away edits) — the opening of protocol 13, on `edge`
(D176, D177).
2. **Protocol 13 with the remaining fixes:** F13, F14, F12, F1, F3, F8, F7, F2, F4 in the bridge and the module,
and F5/F6 in the module.
3. **The redesigns**, each planned in detail before code and walked on both frameworks: the permission manager