Files
browser/openspec/changes/replace-scum-projections-with-real-data-management/tasks.md
T

47 KiB

1. Prompt Boundaries

  • 1.1 正向提示词 (Positive prompt): Rebuild the SCUM portion of the first-party 服务器管理 area around authentic current-server login events, verified current-service database facts, dedicated local records, trustworthy user/squad/map/gift management, and a preserved AI assistant. Success requires exactly five SCUM tabs, automatic player creation and synchronization, no fabricated values, and permission-checked reviewable writes.
  • 1.2 方向提示词 (Directional prompt): Work in platform/, platform_web/, plugins/, and explicit browser-repository protocol contracts while coordinating a separately authorized task in the independent git@git.npc0.com:admin343/run.git repository. Use /Users/tasia/Desktop/code/go/scum/scum_robot only as a read-only behavioral reference for login ingestion and user/squad/map/gift interactions; derive schema, joins, commands, coordinates, and mutation semantics exclusively from the active bound service. Preserve durable jobs, channel isolation, plugin ownership, API/type directory boundaries, and the black-mecha/magical-girl visual system. Required evidence includes Platform/Plugins/Web and SCUM companion tests, the external Run task's own tests/commit/deployment evidence, current-service and browser acceptance, scripts/check-structure.sh, and strict OpenSpec validation.
  • 1.3 任务边界 (Boundary prompt): Do not add a run/ source tree to this repository; modify /Users/tasia/Desktop/code/go/scum/scum_robot; edit the independent Run repository except inside its own separately authorized/rooted task; touch unrelated roots; use an unbound repository/reference/cached SCUM.db as current-service evidence; trust generated/reference structs as production schema; expose raw SQL/RCON/XML/paths/credentials/sockets to browser or AI; add billing/cloud-host/agent-provider workflows; fabricate players/world facts/backups/results; create a platform-admin approval queue; or reintroduce projection, observation, audit-initiation, manual-refresh, pending-review, or Workflow product concepts. A short-lived read-only snapshot created by Run is allowed only when fenced to the active binding/database identity, timestamped, checksummed, and invalidated on source change.
  • 1.4 Before implementation, confirm the browser repository is on main and record existing dirty files; if the branch is not main or local changes block a safe switch, stop without creating another branch or editing files.

2. Minimal Run Probe and Current-Service Evidence Gate

External Run evidence (2026-08-12)

  • The separately rooted Run task implemented and pushed generic schema-probe support at git@git.npc0.com:admin343/run.git commit 6cb6ba3 (add bounded sqlite schema probe); its focused protocol/runtime tests and go test ./... passed.
  • The executor advertises remote.run.db.sqlite.probe, accepts only package-scoped logical databases/... SQLite targets, applies query-only fixed introspection plus binding/job/fence and output bounds, and returns SHA-256-fingerprinted redacted envelopes without SCUM-specific branches or raw database content.
  • The active binding server-run-server-scum-1785923898033 on 枣庄服务器 has been updated and reports remote.run.db.sqlite.probe; the endpoint was observed online through the Platform API at 2026-08-12T08:21:27Z with 28 capabilities including the schema-probe capability.
  • A follow-up separately rooted Run task fixed logical SQLite data-target materialization at commit 8fe6f9b (Fix SQLite probe data target mapping); focused runtime/data-target tests and go test ./... passed in the independent Run repository before deployment.
  • The fixed Run distribution run-dist-server-scum-1785923898033-windows-amd64-1-zao-zhuang-data-target-run-fix-2026081-6988495348508259730 with checksum sha256:a5ac9fe31ed0e0f595e70e3d3322f44aa81bd165183530e4be6939aff81c3016 was installed on 枣庄服务器, and the active endpoint advertises both remote.run.db.sqlite.probe and remote.run.db.sqlite.query.

Server-management diagnostic evidence (2026-08-12)

  • Per operator direction, the Run install target is 枣庄服务器 (FyBDIohqPhRx7Cia); personal server-management MCP inventory and test_connection both succeeded for that device.

  • Bounded SSH diagnostics checked only process/service/capability metadata and emitted no raw SQL, database content, credentials, SCUM rows, or database reads. The server has a Windows Run process for server-run-server-scum-1785923898033, the current SCUM server process is running, and https://scum.npc0.com/healthz returned 200 from the server side; per operator clarification, scum.npc0.com is the NAT entry back to the local Platform.

  • Platform durable probe job job-remote-adapter-server-scum-1785923898033-3442596095552254276 was queued through POST /api/v1/server-instances/server-scum-1785923898033/scum/schema-probe with idempotency key zao-zhuang-schema-probe-20260812-1632, claimed by the authenticated active Run binding, acknowledged, and executed with target databases/scum-database, MaxAttempts=1, and a nonzero fencing token.

  • The probe terminal result was accepted by Platform as a typed sqlite.schema-probe result with safe status failed, safe error code target_unavailable, result digest sha256:41624741855866ce10b3143edba66c3a6b771029256b9489a30f395885526b61, and observed time 2026-08-12T08:31:45Z. This proves the Platform durable job path and active Run probe executor are wired, but it does not prove current SCUM schema compatibility.

  • The first generated Run workspace contained lifecycle package assets but no databases/scum-database logical database target, so current-service schema capture was initially blocked at the package/database-target mapping layer. That failure stayed closed and kept database-backed SCUM read/write gates disabled until the later Run data-target fix produced successful schema metadata.

  • Follow-up bounded SSH diagnostics on 2026-08-12 located exactly one active SCUM.db candidate by process-relative metadata only, with no SQL execution or row reads; the live file was locked for direct hashing/copying. This supports the package-target diagnosis but is not current-service schema evidence for tasks 2.5-2.9.

  • Platform/plugin contracts now declare a plugin-owned runtimeProfiles.dataTargets sqlite snapshot target for scum-database that materializes to databases/scum-database inside the generated Run workspace; SCUM schema-probe dispatch fails closed when that data target is absent. The later independent Run materializer fix supplied the matching generic data-target behavior required for the successful durable probe.

  • Operator clarification on 2026-08-12 narrowed the architecture boundary: Platform/plugin must not download or parse SCUM.db, but an operator-directed, server-local Python diagnostic on 枣庄服务器 is acceptable discovery evidence when it is read-only, bounded, redacted, and not treated as the product execution path. The diagnostic captured schema metadata in place and is recorded in evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; database-backed product gates remain disabled until durable Run envelopes and versioned adapters are accepted.

  • After the Run data-target fix and Platform sourceFingerprint decode fix, durable probe job job-remote-adapter-server-scum-1785923898033-7249327407638289501 succeeded through the product path. Platform persisted probe status succeeded, source fingerprint sha256:d8f3e2f5e9c8241f55b931008309a7ab5f241118a82cbd3620ddedf233e74c13, schema fingerprint sha256:ebd477d6c6ead9c34c41169af489236d762a76186d45dedd753d50f1b81e26f0, result digest sha256:ef13678df4add731c758bba157627dc8af80138a69476facd81bbe354c31d7f1, 161 schema objects, observed time 2026-08-12T12:17:39.0088015Z, and terminal time 2026-08-12T12:29:24.857542Z.

  • Server-management MCP verification on 2026-08-12 confirmed test_connection succeeded for 枣庄服务器, SCUMServer.exe was running, and the target durable probe job had 0 active entries and 0 pending-result entries in the remote Run journal after Platform accepted the typed result. The redacted evidence is stored in evidence/scum-durable-run-schema-probe-2026-08-12.md.

  • Follow-up server-local read-only Python probes on 2026-08-12 verified the actual current-service joins and nullable fields for external identity, profile/prisoner/entity relationships, squad members, flag/base ownership candidates, vehicle identity, bank-account balances, and XML payload candidates. The results are recorded in evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; unproven rank leader semantics, squad-territory ownership, currency labels/units, command confirmation, and 855 mapping remain gated rather than guessed.

  • A task 2.8 confirmation pass on 2026-08-13 separately checked the SCUM live-data manifest, platform/plugin declarations, and read-only scum_robot reference behavior for economy commands, gift aliases/transports, map asset/transform authorization, and 855. No economy command, gift catalog/transport, distributable map asset/transform, or 855 preset mapping is verified enough to enable; the old bridge/domain/reference declarations remain hypothesis or legacy facade material only, and the affected capabilities stay disabled until digest-referenced current-service adapter evidence exists.

  • 2.1 Add a release gate that keeps every database-backed SCUM read and write capability disabled until capability-specific current-service evidence matches a versioned plugin adapter; do not add production SQL or mutation assets before this group is complete.

  • 2.2 Define the minimal generic schema-probe request/result contract, safe error model, binding identity, bounds, and redacted evidence DTO needed by Platform and the plugin without embedding SCUM table names or host paths in Run-facing generic code.

  • 2.3 If the active binding lacks the minimal bounded query-only probe executor, create/hand off a separately authorized task rooted in the independent Run repository, wait for its tests/commit/deployment evidence, and record that evidence here; do not edit or vendor Run source from this change.

  • 2.4 Use the personal server-management MCP (list_devices, test_connection, then ssh_exec only when needed) for device inventory, connectivity checks, and bounded diagnostics. Execute product/acceptance schema probes only as Platform durable jobs through the active authenticated Run binding; an operator-directed server-local Python diagnostic may inspect the active database in place for discovery but must not become a Platform/plugin/browser data path.

  • 2.5 Capture sqlite_master, applicable read-only PRAGMA metadata, indexes, foreign keys, declared types, cardinalities, and small redacted samples for candidate player, profile/entity, squad/member, vehicle, flag/base, economy, coordinate, and character-profile payload sources.

  • 2.6 Verify actual joins and meanings for external player identity, profiles/entities, squad ranks/leaders, flag ownership, vehicle identity, currency units/types, nullable fields, and the real table/column containing character XML; do not assume that user_profile.template_xml or any reference-project field exists.

  • 2.7 Measure coordinate ranges and update cadence, query latency, lock/busy behavior, snapshot consistency, safe timeout/row limits, and whether a verified companion position source is needed for the advertised realtime-map cadence.

  • 2.8 Confirm separately which economy commands support safe confirmation, which gift item aliases/transports are real, which distributable map asset/transform is authorized, and what named attributes—if any—the operator means by the 855 preset.

  • 2.9 Store sanitized probe evidence or an immutable referenced test artifact and derive the observed schema fingerprint/evidence matrix; do not claim final adapter compatibility until the versioned adapters and query contracts in group 3 exist.

3. Plugin SDK, Manifest, and Immutable SCUM Assets

Login-log fixture evidence (2026-08-13)

  • Server-management MCP list_devices/test_connection confirmed 枣庄服务器 (FyBDIohqPhRx7Cia) was reachable, and bounded ssh_exec diagnostics observed the active SCUMServer.exe process without returning host paths or raw protected values.
  • Recursive active-service log discovery found 30 login_{date}{digits}.log files under the current service log root. The newest active login log fingerprint is sha256:752c3ee3789fe73b80245dfcb97776db27f977c4350c3b50516278afbecb9dad, generation sha256:57b5be4818757e4d64070e5e0f026dbd471bdba189d0426a38b618423f7e1439, 0 bytes, last written 2026-08-12T01:18:15.6090680Z; Run tailing must handle zero-byte active files and later append/rotation boundaries.
  • Authentic non-empty login fixtures are UTF-16LE and match {timestamp}: '{network_redacted} {external_player_id}:{display_name}({profile_local_id})' logged {in|out} at: X={coordinate} Y={coordinate} Z={coordinate}. Sanitized fixture rows bind expected scum.login/scum.logout events to server server-scum-1785923898033, Run binding server-run-server-scum-1785923898033, plugin game.scum 0.1.6, pending parser key scum-login-log-parser.pending-real-fixture-v1, parser version pending-scum-login-log-v1, parser digest sha256:5bb528cb9f6e04d8d8b819db3a71f855569c78a5135f22a982301301ae1da50a, transport cursor (sourceIdentity, streamGeneration, sequence), and separate privacy-safe logical event identities. Evidence is stored in evidence/scum-login-log-fixtures-2026-08-13.md.

Login-log parser implementation evidence (2026-08-13)

  • Added plugin-owned parser asset assets/scum-live/login-log-parser.json and manifest declarations for scum.login/scum.logout under scumLiveData.logParsers, digest-referenced as sha256:264835fb36255071fed46dd50724ec511986db901ac8056b08ddafb10f5f0056 while keeping database/write capability gates disabled.
  • Implemented versioned companion parser scum-login-log-parser-v1 / scum-login-log-v1 for UTF-16LE login_{date}{digits}.log lines with transport cursor (sourceIdentity, streamGeneration, sequence) and a privacy-safe logical identity that excludes network material, coordinates, source identity, stream generation, and sequence.
  • Added focused companion tests for successful login/logout, failed login, partial, undecodable, oversized, malformed lines, rotation/copy-truncate overlap across a new generation, restart/resume acknowledgements, duplicate transport/logical delivery, out-of-order delivery, and absence of network/coordinate material in parsed event storage/fingerprints.
  • Verification passed: (cd plugins/examples/scum-server-plugin/companion && go test ./...) and (cd plugins && npm run validate:manifest).

Map asset implementation evidence (2026-08-13)

  • Added plugin-owned SCUM current-service coordinate-map metadata and transform assets under assets/scum-live/map/, digest-referenced from scumLiveData.mapAssets as sha256:74800836553c7e4372a0747c5e9511adcee940b057194488bbf65bf164df372b and sha256:f1941109167a86818e9e71996821884aeb8bd7e863584454b891e525695ba478.
  • The packaged asset is explicitly limited to first-party-generated coordinate metadata and the observed current-service coordinate envelope from evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; no unauthorized SCUM base-map artwork is shipped, and positions.read remains disabled until compatible evidence enables it.
  • Added manifest-validator checks and fixture tests for map metadata/schema compatibility, transform adapter/schema fingerprint matching, declared bounds/image consistency, known-point projection fixtures, non-finite/out-of-bounds rejection, and digest-preserving adapter incompatibility.
  • Verification passed: (cd plugins && npm test -- manifest-validation.test.ts) and (cd plugins && npm run validate:manifest).

Typed RCON and gift catalog gate evidence (2026-08-13)

  • Reviewed current-service evidence in evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md: Fame/currency commands, notification-as-RCON semantics, gift aliases/transports, conclusive per-item receipts, and catalog aliases remain unverified. Therefore the production SCUM manifest continues to declare no scumLiveData.typedRconTemplates, no scumLiveData.giftCatalogs, and no digest-referenced RCON/gift assets.
  • Kept economy-command.write and gift-command.write disabled with missing evidence status; no command text, gift alias, starter-pack catalog, legacy hard-coded gift, or notification transport is exposed through live-data assets.
  • Tightened SDK/schema/validator contracts so any future SCUM typed RCON template must carry a bounded confirmationSchemaRef in addition to payload/result schemas, contained asset paths, immutable digests, protected RCON transport, and server.game-client.command permission.
  • Added manifest tests proving production omits unverified typed RCON templates and gift catalogs, and rejects any SCUM typed RCON declaration without a conclusive confirmation schema.
  • Verification passed: (cd plugins && npm test -- manifest-validation.test.ts).

Current-service baseline refresh (2026-08-13)

  • Per operator correction, the change now stores current-service structure baselines before attempting further capability declarations. evidence/scum-current-service-db-schema-baseline-2026-08-13.md records the full 161-table compact schema inventory from a server-local read-only Python diagnostic, including row counts, columns, primary-key columns, foreign-key counts, and index counts without raw rows, SQL, XML, paths, credentials, sockets, IPs, or player identities.

  • evidence/scum-current-service-log-structure-baseline-2026-08-13.md records the process-adjacent log inventory from a successful server-local diagnostic: 1200 log/text files across hashed directories, including login_{digits}.log, admin_{digits}.log, gameplay_{digits}.log, economy_{digits}.log, chat_{digits}.log, vehicle_destruction_{digits}.log, SCUM.log, and service/runtime log families. Raw log lines and paths were not emitted or stored.

  • evidence/scum-current-service-content-features-baseline-2026-08-13.md records redacted content features from the current service: XML tag/attribute/value-shape summaries, selected DB content distributions, and log skeleton marker sets. It confirms user_profile.template_xml parses as CharacterTemplate with named character attributes and Skill entries, confirms sampled prisoner_skill.xml values are not parseable XML documents, and classifies item_entity.xml as item metadata rather than a profile attribute source.

  • A broader line-shape diagnostic confirmed coordinate-shaped and network-shaped tokens exist in multiple log families, so parser assets must stay per-file-pattern and strip network material before durable storage. The authoritative file inventory remains the successful v4 evidence file.

  • Task 3.10 remains unchecked: the refreshed content-feature baseline confirms user_profile.template_xml is the parseable named-attribute source candidate, but it still does not prove preserving patch semantics, offline/backup/readback requirements, activation semantics, write safety, or an operator-confirmed 855 preset mapping.

  • 3.1 Add SDK and manifest types for versioned log parsers, SQLite query assets, parameter/result schemas, capability-specific schema fingerprints, sync cadence/limits, map metadata, typed RCON templates, gift item catalogs, and guarded mutation declarations.

  • 3.2 Extend plugin validation to require asset digests, contained package paths, unique template keys, bounded parameters/results, compatible adapter versions, and explicit permission bindings, and to reject raw caller-supplied SQL, RCON, XML, paths, or undeclared parameters.

  • 3.3 Capture sanitized authentic login-log fixtures from the active service and bind their expected events to server, Run binding, plugin version, parser version/digest, a transport cursor (source identity, stream generation, sequence), and a separate privacy-safe logical event identity stable across rotation overlap.

  • 3.4 Implement the versioned SCUM login/logout parser and tests for successful login/logout, failed login, partial/undecodable/oversized/malformed lines, copy-truncate/rotation overlap under a new generation, Run restart/resume, duplicate delivery, and out-of-order delivery while discarding IP/network material before storage or logical fingerprinting.

  • 3.5 Add parameterized, read-only player identity/detail/economy/session-enrichment query assets and exact result schemas only for joins and fields proven by the probe.

  • 3.6 Add parameterized squad/member, vehicle, flag/territory, and position query assets and exact result schemas, keeping ambiguous ranks, ownership, coordinates, and missing numeric values null.

  • 3.7 Add query-asset tests for single SELECT/CTE or approved introspection boundaries, parameter binding, pagination/cursors, timeout/row/byte limits, schema-version matching, and rejection of DDL, mutation, ATTACH, extension loading, write PRAGMAs, and multi-statement input.

  • 3.8 Package the authorized SCUM map asset, identity/version, verified world bounds, layer metadata, and coordinate transform, with fixture tests for known points, out-of-bounds/non-finite coordinates, and adapter incompatibility.

  • 3.9 Declare only verified typed RCON templates for supported Fame/currency/notification/gift operations and a version-scoped gift item catalog; omit any command whose execution and confirmation semantics remain unknown.

  • 3.10 Declare a guarded preserving XML mutation only after the real XML source and named attributes are proven; expose 855 only as a reviewed named-attribute preset and never as a database column, generic integer field, or guessed mapping.

  • 3.11 Add immutable asset/digest declarations and plugin package validation; defer generated Run-package execution wiring until the complete protocol/result envelope and independent Run capability evidence in group 4 are frozen.

  • 3.12 Remove SCUM Workflow/projection declarations and obsolete page/action declarations from the plugin manifest while preserving the five required pages and AI configuration assistance.

  • 3.13 Match the observed fingerprint/evidence matrix against each completed adapter, add per-capability compatibility/release-gate tests, and leave every unsupported or ambiguous player/squad/vehicle/flag/position/write capability disabled.

4. Generic External Run Execution and Result Contracts

Platform probe wiring evidence (2026-08-12)

  • Platform now has an internal-only RequestSCUMSchemaProbeForSession path that builds a durable remote.run.db.sqlite.probe job from the SCUM plugin's manifest declaration, active runtime binding, logical target key, adapter version, and bounded probe limits; public remote-adapter and plugin-page requests for the probe capability are denied.

  • Run terminal results may carry executionResult.sqliteSchemaProbe; Platform DTO/domain/validator/job-channel code validates the typed redacted envelope, job/request identity, and binding fence before persisting it on the durable job.

  • Generated Run packages now carry redacted autonomous lifecycle dataTargets entries for plugin-owned sqlite snapshots, and browser-facing runtime-profile responses continue to omit those source declarations.

  • Focused evidence: go test ./dto ./service -run 'Test(RunJobResultRequestParsesSQLiteSchemaProbeEnvelope|SCUMSchemaProbeDispatchIsPlatformScheduledAndFenced|RemoteAdapterRequestPropagatesTypedInputsToRunJob)' and (cd platform && go test ./...) passed locally. These tests do not prove the active Windows Run deployment or current SCUM schema, so tasks 2.3-2.9 and 4.2-4.9 remain unchecked.

  • 4.1 Add Platform protocol contracts under platform/protocol, API DTOs under platform/dto, validation under platform/validator, and plugin contracts/assets under plugins/sdk and plugins/schemas, plus contract documentation/mocks for probes, read-only template execution, typed RCON, guarded SQLite/XML mutation, parsed log events, and terminal result envelopes.

  • 4.2 Freeze the generic executor/result contract and hand off a separately authorized Run-repository task for packaged SQLite-template execution with query-only connections, bound parameters, one-statement validation, short busy/operation timeouts, cancellation, and row/result-byte limits.

  • 4.3 Require the independent Run task to return typed envelopes containing server/plugin binding, adapter/schema version, template key, asset digest, job identity, observed time, checksum, rows or affected-row count, and stable safe result/error codes.

  • 4.4 Require the independent Run task to implement generic plugin-owned typed RCON-template execution without accepting browser command text or adding branches for SCUM, SCUM keys, SCUM commands, or SCUM tables.

  • 4.5 Require the independent Run task to implement generic guarded single-row SQLite/XML mutation execution with expected identity/value/checksum guards, a bounded transaction, preserving XML patching, rollback on zero/multiple affected rows, and read-after-write confirmation.

  • 4.6 Require the independent Run task to implement or extend generic plugin-declared log-source tailing so cursor persistence, rotation, truncate, restart, partial-line buffering, parser digest fencing, logical event fingerprinting, and replay remain independent of SCUM-specific source paths.

  • 4.7 Verify from the independent Run task's acceptance evidence that control/job/log/artifact priorities, leases, fencing, acknowledgements, idempotency, and late/duplicate terminal-result handling remain intact for the new generic capabilities.

  • 4.8 Add Platform-side capability negotiation so probe, player/squad/vehicle/flag/position reads, typed commands, gifts, and guarded mutations are gated independently for each active Run/plugin/adapter binding.

  • 4.9 After the external Run contract tests/commit/deployment evidence is available, wire immutable assets and digests into generated Run packages and add distribution/contract tests proving Platform sends only template keys, bounded parameters, adapter version, and expected digest.

5. Dedicated Platform SCUM Persistence

  • 5.1 Define SCUM domain types and narrow repository/service interfaces in the required platform/ directories, keeping API DTOs, database models, validation, and repository contracts separate.
  • 5.2 Add dedicated player, session, player-detail, source-event, sync-cursor, capability-evidence, and completed-generation records with server-scoped identities and nullable unknown fields.
  • 5.3 Add dedicated squad, squad-member, vehicle, flag/territory, and current-position records with source checksum/time, adapter version, generation, and server-scoped indexes.
  • 5.4 Add dedicated gift-package, gift-item, frozen-delivery, per-item receipt, eligibility-period reservation, notification-result, and immutable completed-delivery records.
  • 5.5 Implement normalized MySQL models and explicit migrations with uniqueness constraints for player/event/session identity, generation rows, gift idempotency, and concurrent eligibility reservations.
  • 5.6 Implement the default file-backend SCUM store as a platform-owned SQLite sidecar under the configured data directory, with pinned driver/migration behavior and no high-frequency writes to the global metadata snapshot.
  • 5.7 Implement the memory backend with the same server isolation, uniqueness, transaction, null, generation, and idempotency semantics for tests.
  • 5.8 Implement transactional generation commits so a complete validated scan may mark missing rows absent, while partial/failed/older scans preserve the last completed generation unchanged.
  • 5.9 Add health, migration, rollback/disable, and database-instance invalidation behavior; never migrate old projection/Workflow snapshot values into the new tables as game facts.
  • 5.10 Add backend-parity tests for migrations, uniqueness, concurrent first login, nullable numeric values, failed-generation retention, server isolation, and gift reservation/idempotency constraints.

6. Authentic Login Ingestion and Automatic Synchronization

  • 6.1 Add a typed parsed-log event ingress that authenticates and correlates server binding, plugin/adapter/parser digest, transport cursor (source identity, stream generation, sequence), separate stable logical event identity, and occurrence time before calling SCUM ingestion.
  • 6.2 Atomically upsert one (server_instance_id, external_player_id) player and open one session for an authentic successful login without waiting for database enrichment.
  • 6.3 Close only the matching current session on logout, do not fabricate a session for an unmatched logout, and prevent older logout/login events from regressing a newer display name, last-seen time, or online session.
  • 6.4 Close or mark sessions unknown with a bounded reason when a binding/source epoch is replaced, server stops, or log continuity is lost without a logout; never leave them permanently confirmed online from database save timestamps.
  • 6.5 Strip raw IP addresses and all network identifiers before durable player/session/event storage and exclude them from every SCUM API, diagnostic, and AI context.
  • 6.6 Add ingestion tests for concurrent first login, replayed events, duplicate/out-of-order events, failed login, unmatched logout, partial-line resume, copy-truncate/rotation overlap replay under a new generation, Run restart, parser-digest mismatch, cross-server events, and database timestamps that must not imply online state; an overlapped logical login SHALL still produce one player/session.
  • 6.7 Add an automatic scheduler that starts a capability-specific probe when an active binding lacks current evidence, starts an initial bounded scan after compatibility succeeds, then uses plugin-declared jittered cadences, backoff, and per-server/per-capability concurrency limits.
  • 6.8 Schedule bounded player-detail enrichment after a new login without delaying player creation, and use the measured safe position cadence or a declared verified companion source without fabricated intermediate motion.
  • 6.9 Create every durable Run job before dispatch and attach the expected server/plugin/template/digest/schema/generation correlation needed for immediate, late, and duplicate results.
  • 6.10 Add a terminal-job hook that validates the full result envelope and row schema before calling the matching transactional SCUM sync service.
  • 6.11 Reject malformed, foreign, duplicate, or older results idempotently; commit only complete generations and retain prior rows plus a safe connection/sync error after locks, timeouts, partial results, or incompatible schemas.
  • 6.12 Publish safe player/session/squad/map updates through a platform-owned event stream/SSE while keeping Platform Web reads backed by local records.
  • 6.13 Add tests proving page opens/retries never create schema probes, Run queries, projection refreshes, real-data refreshes, manual syncs, or audit jobs.

7. Player Management APIs

  • 7.1 Add safe player-list/detail/session DTOs, request schemas, validators, API clients/contracts, and routes in their fixed directories without exposing raw logs, database rows, XML, SQL, paths, or network material.
  • 7.2 Implement server-side player pagination, bounded name/external-ID search, online and squad filters, deterministic allowlisted sorting, and total/page metadata against the local SCUM store.
  • 7.3 Implement player detail with identity, verified nullable facts, current verified coordinate, bounded login history, source collection times, and explicit not-yet-synchronized/confirmed-empty/incompatible/connection-failed states.
  • 7.4 Enforce target-server read authorization before lookup and prevent cross-server player IDs, squad filters, selectors, counts, or existence from leaking.
  • 7.5 Preserve unknown values as null/absent throughout storage, service, DTO, and JSON handling; never substitute zero, sample data, guessed profile IDs, or database save time as online evidence.
  • 7.6 Remove player-intelligence, alias-history, shared-IP, access-attempt, automatic-risk, security-signal, and hard-coded increment dependencies from the SCUM player API and ingestion flow.
  • 7.7 Add repository/service/API tests for search/filter/sort bounds, pagination stability, confirmed-empty versus unavailable data, nullable facts, login history, authorization, cross-server isolation, and absence of manual-refresh endpoints.

8. Squad Management and Realtime Map APIs

  • 8.1 Implement server-scoped paginated/searchable/sortable squad list and detail APIs with verified members, adapter-declared rank meanings, leader when proven, flags/territory, and ordinary collection times.
  • 8.2 Keep leader, rank, territory, and ownership unknown when joins or enum meanings are ambiguous, gate squad/member/flag/territory resources independently, and test that reference constants or proximity/history heuristics are not evidence.
  • 8.3 Implement bounded local vehicle and flag APIs containing only verified identity, class/status, coordinate, ownership, and collection fields supported by each active adapter capability.
  • 8.4 Implement a safe current-map dataset API for players, vehicles, flags, squads/territories, layer filters, and source collection times without returning database or Run connection material.
  • 8.5 Apply the plugin-declared map version/bounds/coordinate transform server-side or through a shared tested contract, rejecting incompatible, non-finite, and out-of-bounds coordinates instead of generating fallback points.
  • 8.6 Publish newer verified position/map updates through the platform event stream with entity identity and server/version fencing; page subscriptions must not dispatch Run reads.
  • 8.7 Enforce server authorization, bounded selectors/result sizes, and no cross-server existence leaks across all squad/map endpoints.
  • 8.8 Add service/API tests for successful and failed generations, per-resource gating, unknown ownership/ranks, last-complete rows after interruption, transform fixtures, layer filtering, event ordering, and incompatible-map unavailable results.

9. Gift Management, Eligibility, and Delivery

  • 9.1 Add server/plugin-version-scoped gift package and typed item validators for names, classification, active state, quantities, eligibility rules, period limits, and only plugin-catalogued item keys.
  • 9.2 Implement server.game-client.read package/history reads, server.game-client.maintenance package create/update/enable/delete, and server.game-client.command reviewed delivery APIs using the current session's effective target-server permissions.
  • 9.3 Evaluate per-player/server/period eligibility in the server's declared timezone and reserve limit capacity transactionally for in-flight, partial, and unknown deliveries so concurrent requests cannot exceed the configured limit.
  • 9.4 Freeze target player, package/items, quantities, plugin/game/adapter version, period reservation, delivery identity, and idempotency key before dispatch; later package edits must not alter a delivery.
  • 9.5 Dispatch only plugin-declared typed item aliases and quantities through the controlled command path, never arbitrary browser command strings.
  • 9.6 Treat queued, claimed, acknowledged, or started jobs as in progress; record delivered only after a schema-valid conclusive receipt for every required item.
  • 9.7 Preserve reservations and per-item receipts for timed-out, missing, partial, or unknown outcomes, require confirmation before an explicit retry, and never automatically redeliver the whole package or already confirmed items.
  • 9.8 Release a period reservation only after conclusive evidence that no game effect occurred; record post-delivery notification failure separately without changing the delivered fact or triggering redelivery.
  • 9.9 Add server-scoped package statistics, searchable/filterable pagination, real player selection, reviewed send requests, and ordinary delivery-history/result APIs without Workflow or audit terminology.
  • 9.10 Add concurrency, idempotency, timezone-boundary, cross-server, catalog-version, partial/unknown outcome, reservation-release, notification-failure, permission, and immutable-history tests.

10. Controlled Manual and AI/Agent Writes

  • 10.1 Define one named-field write draft containing server/player/action/field, verified current value/checksum, proposed value, reason, adapter/digest, idempotency key, safety requirements, and a safe reviewable diff.
  • 10.2 Authorize the current user's effective target-server permission when a draft is created, reviewed, confirmed, and dispatched, with backend checks authoritative and no component-principal, manifest-declaration, or callback-presence bypass.
  • 10.3 Supply the plugin page host with the current session's effective permissions and readable denial reasons while keeping direct API denial authoritative.
  • 10.4 Route verified Fame/cash/gold writes through plugin-owned typed RCON templates with server.game-client.command, validated absolute target values, explicit reason, idempotency, and declared confirmation reads.
  • 10.5 Route database/XML writes only with effective server.game-client.maintenance, verified target/offline or maintenance state when required, genuine same-instance restorable backup evidence, expected before values/checksum, and an explicit dangerous-operation confirmation; do not create a platform-admin approval workflow or approval queue.
  • 10.6 Execute preserving named-attribute XML patches only against the probe-confirmed source, reject malformed XML or absent/undeclared nodes, preserve unknown content, and update exactly one guarded row.
  • 10.7 Keep 855 absent until its named mapping is confirmed; when available, expand it into an explicit per-attribute before/after review rather than accepting fieldKey=855, prisoner.value, or a generic integer.
  • 10.8 Validate command/mutation terminal envelopes and readback before success, update local verified details only after conclusive confirmation, and represent missing/mismatched results as failed, conflict, or unknown without automatic retry.
  • 10.9 Never chain kill, death, respawn, kick, or another destructive activation to attribute save; any verified required activation must be a separate explicitly named, permission-checked, confirmed action.
  • 10.10 Preserve AI-assisted plugin configuration through the existing platform-mediated reviewable config-diff path without exposing provider keys or granting the plugin page direct write authority.
  • 10.11 Make AI/Agent player-operation suggestions create the exact same named-field draft as manual forms, reject undeclared fields/protected payloads, retain the initiating user, and require that user's current effective permission plus explicit confirmation.
  • 10.12 Add tests for read-only users, revoked permissions between draft and dispatch, cross-server targets, invented AI fields, stale checksums, fake backup evidence, unsafe online state, zero/multiple rows, malformed XML, missing nodes, unknown results, confirmation mismatch, duplicate requests, and no approval-queue creation.

11. Five-Tab SCUM Product Surface

  • 11.1 Place SCUM API clients/types, route definitions, page contracts, component contracts, schemas/validators, bridge/SDK types, and shared utilities in their fixed frontend/plugin directories rather than inside page components.
  • 11.2 Make the SCUM detail navigation contain exactly 用户管理, 队伍管理, 实时地图, 礼包管理, AI 助手 in that order, default to 用户管理, and fall back from legacy manage, workflows, or invalid sections without affecting non-SCUM plugins.
  • 11.3 Preserve the existing server-list deployment action and relocate display-name and administrator-membership controls to a compact detail-header settings drawer/dialog with existing owner authorization; do not add another permanent management tab.
  • 11.4 Build 用户管理 as a full-width server-paginated table with bounded filters/search/sort, online evidence, nullable verified facts, detail/login-history drawer, and explicit named-field edit dialogs.
  • 11.5 Build 队伍管理 as a full-width paginated squad table and semantic detail drawer separating leader/ranks, members, flags, and territory while showing unknown facts honestly.
  • 11.6 Build 实时地图 from the authorized map asset and tested transform with distinct player/vehicle/flag/territory layers, filters, legend, source coordinates/collection time, safe live updates, and a clear incompatible/unavailable state.
  • 11.7 Build 礼包管理 with real package statistics/table, CRUD dialogs, typed items and limits, real player selection, reviewed delivery, and delivery history for in-progress/delivered/failed/partial/unknown/notification-failure outcomes.
  • 11.8 Keep AI 助手 as the final tab for plugin configuration diffs and controlled player-operation drafts, with apply disabled when effective permission is absent.
  • 11.9 Hide or disable write controls according to current effective permissions with textual reasons, and re-check authorization server-side on every apply request.
  • 11.10 Load only platform-local resource APIs and the platform event stream; display ordinary connection and last synchronized/collected information, and let retry repeat only a local read.
  • 11.11 Reuse shared tables, drawers, dialogs, status, console-*, and theme tokens; preserve black-mecha and magical-girl readability, keep CSS declarations compressed, and add no page-local fixed decoration or generic opaque SaaS card system.
  • 11.12 Cover keyboard/focus behavior, non-color-only status, responsive full-width working surfaces, bounded compact actions, and readable destructive confirmations.
  • 11.13 Add frontend tests for exact navigation/order/default/fallback, settings ownership, local-only loading, permission presentation, null/empty/error states, real map/gift data, AI review parity, and absence of fake actions or placeholder records.

12. Projection, Workflow, Intelligence, and Placeholder Removal

  • 12.1 Inventory references before deletion and distinguish SCUM-only projection/Workflow/player-intelligence code from generic durable Run jobs, internal write evidence, and non-SCUM consumers.
  • 12.2 Remove SCUM Workflow instance/step/status APIs, repositories, services, routes, clients, manifest declarations, page components, workflow creation/listing, pending-review counters, operation approval routes, and approval/confirmation queue surfaces without removing generic Run job execution.
  • 12.3 Remove SCUM projection/observation/freshness snapshot types, ingestion, metadata fields, refresh/audit services, page actions, and manual synchronization endpoints; removed endpoints must return not found or a stable removal response and dispatch no job.
  • 12.4 Remove SCUM dependencies on alias history, shared IP/fingerprint, access attempts, automatic risk/security signals, and player intelligence; delete shared implementation only after proving it has no remaining non-SCUM consumer.
  • 12.5 Remove the standalone 管理 and Workflow 状态 tabs, legacy placeholders/routes, fake maintenance/backup evidence, hard-coded increments, opaque 855 action, hard-coded starter-pack, fixed notification, gradient-only map, arbitrary percentage points, and sample/generated players/world data.
  • 12.6 Remove runtime product copy including Workflow 状态, 投影, 真实投影, 玩家投影, 刷新投影, 刷新世界投影, 刷新真实数据, 发起审计, 创建发放 workflow, typed workflow, typed observation, typed operation, 待审操作, 审批/确认队列, 清理旧入口, 目前暂无真实投影数据, 暂无真实投影数据, 暂无玩家投影, and Companion 可用.
  • 12.7 Add upgrade behavior that starts the new SCUM stores empty, populates only from post-upgrade authenticated logs/current-service sync, invalidates incompatible bindings, and never translates old snapshot values into real facts.
  • 12.8 Add a rollback/feature-disable path that disables incompatible SCUM reads/writes while leaving diagnostic local records intact and never re-enables fake projection or Workflow data.
  • 12.9 Add scoped runtime-source/manifest/API tests or assertions proving banned copy/actions/routes are absent, removed endpoints cannot dispatch jobs, and generic lifecycle, logs, jobs, AI provider management, and non-SCUM plugin navigation still work.
  • 12.10 Record the supersession mapping from the completed-but-unarchived legacy SCUM changes to these unique replacement capabilities; do not archive obsolete deltas into the main baseline, and leave any history consolidation to a separate reviewed skip-specs/equivalent archival task.

13. End-to-End Verification and Release

  • 13.1 Run focused Go tests after each Platform repository, migration, ingestion, scheduler, API, gift, permission, and terminal-result change, then run (cd platform && go test ./...).
  • 13.2 Run plugin SDK/parser/query/map/manifest tests and final checks with (cd plugins && npm run typecheck && npm run test && npm run validate:manifest), then run (cd plugins/examples/scum-server-plugin/companion && go test ./...).
  • 13.3 Run frontend tests and final checks with (cd platform_web && npm run typecheck && npm run test && npm run build).
  • 13.4 In the separately authorized Run-repository task, run go test ./... from that repository's own root and record its tested commit/version plus deployment compatibility evidence here; do not edit, stage, or commit Run source from the browser-repository apply task.
  • 13.5 Against the active current service, verify read-only schema compatibility, authentic login-created local player/session data, automatic player/squad/vehicle/flag/position sync, generation retention after an induced safe read failure, and no unbound copied/cache/fixture database use.
  • 13.6 Verify login-log acceptance with sanitized real fixtures covering partial lines, failed login, rotation, truncate, restart/resume, duplicate, and out-of-order events plus server/Run binding/plugin/parser-digest fencing.
  • 13.7 Extend and run scripts/browser-acceptance.sh against synchronized local data for the exact five tabs, local-only page reads, user/squad/map/gift behavior, permission-aware edit reviews, AI configuration/player drafts, legacy-route fallback, and absence of projection/Workflow/manual-refresh/audit controls.
  • 13.8 Verify controlled writes against isolated test data or an explicitly authorized test player only; prove permission, explicit confirmation, guards, backup/offline requirements, idempotency, readback, unknown-result handling, XML preservation, and no implicit respawn.
  • 13.9 Perform scoped security checks proving browser/API/AI/job-safe responses contain no raw SQL, RCON, XML, host/database paths, credentials, sockets, IP data, or cross-server resource existence, and that external Run has no SCUM-specific executor branches.
  • 13.10 Run scripts/check-structure.sh and fix every relevant structural violation without moving implementation outside its owning root.
  • 13.11 Run openspec validate replace-scum-projections-with-real-data-management --strict, review task evidence and the final diff, and leave any task unchecked if its real-service, external-Run, test, or safety evidence is missing.
  • 13.12 On main, stage only files belonging to this change, create a concise commit after all required verification succeeds, and push the configured remote without including unrelated pre-existing worktree changes.