Accept Run SQLite schema probe source fingerprints

This commit is contained in:
npc0-hue
2026-08-12 22:20:33 +08:00
parent 2246859984
commit 3fe74399a9
10 changed files with 139 additions and 15 deletions
@@ -0,0 +1,45 @@
# SCUM Current-Service SQLite Diagnostic Evidence — 2026-08-12
## Scope
- Evidence kind: operator-directed, server-local, read-only diagnostic discovery.
- Execution target: `枣庄服务器` through the personal server-management MCP (`list_devices`, `test_connection`, `ssh_exec`).
- Product boundary: Platform/plugin did not download or parse `SCUM.db`. The diagnostic script executed on the game server host and emitted only schema metadata, aggregates, hashes, and redacted samples.
- Release boundary: this evidence supports adapter discovery. It does not replace the Platform durable Run job / typed Run envelope required before enabling database-backed production capabilities.
## Database Identity and Read Behavior
- One active `SCUM.db` candidate was found beside the running SCUM service metadata; no host path is recorded in this artifact.
- Read mode: Python `sqlite3` URI `mode=ro`, `PRAGMA query_only=ON`, 2s timeout.
- Database size: `80,805,888` bytes.
- SQLite metadata: `schema_version=765`, `user_version=57`, `journal_mode=wal`, `page_size=4096`, `page_count=19728`, `freelist_count=1`.
- Object inventory: `293` schema objects, `161` tables.
- Safe-read timing observed: full schema inventory `61ms`; focused groups `3ms`, `13ms`, `3ms`; join/range metrics `25ms`. No read lock/busy failure was observed during these diagnostics.
- Fingerprints: full schema objects `57e34ee72660d7e4334644ee70cd6d285ac7961a3964fafdc3956d74e88dfa4f`; focused table groups `12a34e49f851879ae71ba287719c8d95019909f3060e823be4ce0973ce764841`, `a856bc4e105ab0a5e34b758237d3f96cff0ba5a65b38e7cf1eb81ab16b40caf4`, `60c97a8c782086c4b2600eb3a9b29c3074b971d5fdc6cf54137ce48e0970b26e`; join/range metrics `4905d09b70303b42cfb8e7fc936fe0df2065d7100c43e92ef79a464958249af4`.
## Evidence Matrix
| Area | Current-service evidence | Remaining ambiguity |
| --- | --- | --- |
| External player identity | `user` has `74` rows with `id TEXT` primary key, `id_type`, `provider`, `last_login_time`, `creation_time`, `is_banned`, and network-address field present but not persisted in this artifact. Redacted samples show `id_type=Steam` and provider `Server`. | Product APIs must hash or fence external IDs where appropriate and must never expose IP/network material. |
| Player profile join | `user_profile` has `73` rows; `user_profile.user_id -> user.id`; `user_profile.prisoner_id -> prisoner.id`; indexes on `(user_id,type,name)`, `type`, and `prisoner_id`. | Profile `type` meanings still need explicit adapter mapping. |
| Character/prisoner join | `prisoner` has `72` rows and `prisoner.user_profile_id -> user_profile.id`; `prisoner_entity` has `72` rows mapping `prisoner_id -> prisoner.id` and `entity_id -> entity.id`. Join metrics: `73` profiles, `73` with user, `72` with prisoner, `72` with prisoner entity, `72` with entity. | One profile has no current prisoner/entity. Online state must still come from authenticated login/session evidence, not database timestamps alone. |
| Character XML / payload | `user_profile.template_xml` is present and non-null for `73/73` profiles, length range `25412673`; samples were hash+length only. `prisoner_skill.xml` has `72/1656` non-null rows, length `1565`; `item_entity.xml` has `42298/62838` non-null rows, length `1364781`. | `user_profile.template_xml` is a strong candidate, but write semantics, named attributes, and `855` mapping remain unverified. |
| Player coordinates | `entity` has `63364` rows with `location_x/y/z`, `rotation_x/y/z`, scale, flags, class, and optional BLOB data. Joined prisoner entity range: x `-872217.6875..567603.0625`, y `-843655.8125..554482.125`, z `221.87356567382812..82958.546875`; `prisoner.last_save_time` range `1773202437..1786533149`. | Save/update cadence and whether this can satisfy realtime map cadence still need measurement. |
| Squad | `squad` has `7` rows; `squad_member` has `18` rows with `squad_id`, `user_profile_id`, `rank`; all members join to both squad and profile. Rank distribution: `1:6`, `2:2`, `3:4`, `4:6`. | Rank meanings / leader semantics are not proven. Keep labels neutral until verified. |
| Vehicles | `vehicle_spawner` and `vehicle_entity` each have `313` rows; all vehicle spawner rows join to `vehicle_entity` and `entity`; `15` distinct vehicle assets observed. Vehicle entity coordinate range: x `-898438..601692.3125`, y `-881533.25..605226.5`, z `-84.04053497314453..98312.640625`. | Vehicle ownership/status meanings beyond the observed fields remain capability-gated. |
| Flags / bases | `base` has `5` rows; `base_element` has `1533`; `base_element_flag` has `5`; all flags join to base elements and bases; all flags have an owner profile through the base element; no overtaker profile observed. | Confirm whether `base_element.owner_profile_id` is the authoritative flag owner before exposing owner labels. |
| Economy / balances | `economy` and `bank_general_data` each have `1` global row. `bank_account_registry` has `73` accounts; `bank_account_registry_currencies` has `146` rows; all currency rows join to an owner profile. Currency distribution: type `1` has `73` rows, balance range `-3000..830328`; type `2` has `73` rows, balance range `0..14636`. | Currency type meanings, units, safe command/readback semantics, and gift item aliases remain unverified. |
| Spawn/location table | `prisoner_spawn_location` has `78` rows with `location_x/y/z`, rotation, velocity, `type`, optional `shelter_id`; coordinate range roughly matches player entity bounds. | This is spawn-location evidence, not current position evidence. |
## Redaction Notes
- Player names, squad names/messages, map names, aliases, XML, BLOB payloads, tokens, and network-address material were represented only as hash+type+length when sampled.
- Three player join samples were retained only as hash of external player id plus numeric profile/prisoner/entity IDs, timestamps, fame points, and coordinates.
- No raw SQL, host database path, credentials, direct sockets, raw XML, raw player names, or raw IP/network identifiers are recorded here.
## Resulting Gates
- Task 2.5 schema capture is satisfied for discovery: `sqlite_schema`, read-only PRAGMA metadata, indexes, foreign keys, declared types, cardinalities, and redacted samples were captured for the candidate sources.
- Tasks 2.62.8 remain open: join semantics, rank meanings, currency meanings/commands, update cadence, map transform, gift aliases, and `855` named-attribute mapping still require explicit verification.
- Database-backed SCUM read/write capabilities remain disabled until the corresponding versioned adapters and Run durable execution envelopes are implemented and accepted.
@@ -0,0 +1,51 @@
# SCUM Durable Run Schema Probe Evidence — 2026-08-12
## Scope
- Evidence kind: product-path durable Run job result accepted by Platform.
- Target server: `枣庄服务器` via the active authenticated Run binding `server-run-server-scum-1785923898033`.
- Boundary: Platform/plugin/browser did not download or parse `SCUM.db`; the database probe was produced by Run as a typed, redacted `sqlite.schema-probe` envelope and then persisted by Platform.
- Redaction: this artifact intentionally omits host paths, database paths, credentials, sockets, raw SQL, raw rows, raw XML, raw player names, and network material.
## External Run Deployment Evidence
- Independent Run repository: `git@git.npc0.com:admin343/run.git`.
- Tested Run fix: commit `8fe6f9b` (`Fix SQLite probe data target mapping`).
- Run verification performed in the independent Run repository: focused data-target/runtime tests and `go test ./...` passed before deployment.
- Installed distribution on `枣庄服务器`: `run-dist-server-scum-1785923898033-windows-amd64-1-zao-zhuang-data-target-run-fix-2026081-6988495348508259730`.
- Distribution checksum: `sha256:a5ac9fe31ed0e0f595e70e3d3322f44aa81bd165183530e4be6939aff81c3016`.
- Runtime capability evidence: the active endpoint advertises `remote.run.db.sqlite.probe` and `remote.run.db.sqlite.query` after installation.
## Platform Acceptance Evidence
- Durable job: `job-remote-adapter-server-scum-1785923898033-7249327407638289501`.
- Platform terminal state: `succeeded` with progress `100` and message `SQLite schema probe completed`.
- Terminal time: `2026-08-12T12:29:24.857542Z`.
- Probe observed time: `2026-08-12T12:17:39.0088015Z`.
- Probe status: `succeeded`.
- Source fingerprint: `sha256:d8f3e2f5e9c8241f55b931008309a7ab5f241118a82cbd3620ddedf233e74c13`.
- Schema fingerprint: `sha256:ebd477d6c6ead9c34c41169af489236d762a76186d45dedd753d50f1b81e26f0`.
- Result digest: `sha256:ef13678df4add731c758bba157627dc8af80138a69476facd81bbe354c31d7f1`.
- Schema object count: `161`.
- Safe error: empty / not retryable.
## Platform Decode Fix
- Run emits `sourceFingerprint` in successful SQLite schema-probe results.
- Platform DTO/domain/validator handling now accepts and persists `sourceFingerprint` only when it is a safe digest/fingerprint.
- Validator coverage rejects raw path-shaped values such as a host database path and permits bounded generic Run `data_target_*` safe error codes without allowing path material.
## Server-Management SSH Verification
- The personal server-management MCP inventory found `枣庄服务器` with device id `FyBDIohqPhRx7Cia`.
- `test_connection` succeeded for `枣庄服务器`.
- `ssh_exec` was used for bounded, read-only PowerShell status checks only; no SCUM database query or file copy was performed.
- Remote process summary at `2026-08-12T14:13:56.4937358Z`: `SCUMServer.exe` process count `1`.
- Run journal summary: scanned `1` job journal, target job active count `0`, target pending result count `0`, total active count `0`, total pending count `1`.
- Interpretation: the durable schema-probe job is not stuck in the remote Run active queue or pending-results spool after Platform accepted the typed result. The remaining unrelated pending result, if any, is outside this evidence item.
## Resulting Gates
- This proves the product acceptance path for schema probing: Platform durable job → authenticated active Run binding → Run-side typed/redacted SQLite schema-probe envelope → Platform validation and persistence.
- This does not prove player/squad/vehicle/flag/position query adapter compatibility, rank meanings, currency semantics, map transform, gift aliases/transports, or `855` named-attribute mapping.
- Database-backed player/squad/map/gift/write capabilities remain disabled until the versioned adapters and query/mutation contracts in later task groups are implemented and matched against this evidence matrix.