47 KiB
1. Prompt Boundaries
- 1.1 正向提示词 (Positive prompt): Rebuild the SCUM portion of the first-party
服务器管理area around authentic current-server login events, verified current-service database facts, dedicated local records, trustworthy user/squad/map/gift management, and a preserved AI assistant. Success requires exactly five SCUM tabs, automatic player creation and synchronization, no fabricated values, and permission-checked reviewable writes. - 1.2 方向提示词 (Directional prompt): Work in
platform/,platform_web/,plugins/, and explicit browser-repository protocol contracts while coordinating a separately authorized task in the independentgit@git.npc0.com:admin343/run.gitrepository. Use/Users/tasia/Desktop/code/go/scum/scum_robotonly as a read-only behavioral reference for login ingestion and user/squad/map/gift interactions; derive schema, joins, commands, coordinates, and mutation semantics exclusively from the active bound service. Preserve durable jobs, channel isolation, plugin ownership, API/type directory boundaries, and the black-mecha/magical-girl visual system. Required evidence includes Platform/Plugins/Web and SCUM companion tests, the external Run task's own tests/commit/deployment evidence, current-service and browser acceptance,scripts/check-structure.sh, and strict OpenSpec validation. - 1.3 任务边界 (Boundary prompt): Do not add a
run/source tree to this repository; modify/Users/tasia/Desktop/code/go/scum/scum_robot; edit the independent Run repository except inside its own separately authorized/rooted task; touch unrelated roots; use an unbound repository/reference/cachedSCUM.dbas current-service evidence; trust generated/reference structs as production schema; expose raw SQL/RCON/XML/paths/credentials/sockets to browser or AI; add billing/cloud-host/agent-provider workflows; fabricate players/world facts/backups/results; create a platform-admin approval queue; or reintroduce projection, observation, audit-initiation, manual-refresh, pending-review, or Workflow product concepts. A short-lived read-only snapshot created by Run is allowed only when fenced to the active binding/database identity, timestamped, checksummed, and invalidated on source change. - 1.4 Before implementation, confirm the browser repository is on
mainand record existing dirty files; if the branch is notmainor local changes block a safe switch, stop without creating another branch or editing files.
2. Minimal Run Probe and Current-Service Evidence Gate
External Run evidence (2026-08-12)
- The separately rooted Run task implemented and pushed generic schema-probe support at
git@git.npc0.com:admin343/run.gitcommit6cb6ba3(add bounded sqlite schema probe); its focused protocol/runtime tests andgo test ./...passed. - The executor advertises
remote.run.db.sqlite.probe, accepts only package-scoped logicaldatabases/...SQLite targets, applies query-only fixed introspection plus binding/job/fence and output bounds, and returns SHA-256-fingerprinted redacted envelopes without SCUM-specific branches or raw database content. - The active binding
server-run-server-scum-1785923898033on枣庄服务器has been updated and reportsremote.run.db.sqlite.probe; the endpoint was observed online through the Platform API at2026-08-12T08:21:27Zwith 28 capabilities including the schema-probe capability. - A follow-up separately rooted Run task fixed logical SQLite data-target materialization at commit
8fe6f9b(Fix SQLite probe data target mapping); focused runtime/data-target tests andgo test ./...passed in the independent Run repository before deployment. - The fixed Run distribution
run-dist-server-scum-1785923898033-windows-amd64-1-zao-zhuang-data-target-run-fix-2026081-6988495348508259730with checksumsha256:a5ac9fe31ed0e0f595e70e3d3322f44aa81bd165183530e4be6939aff81c3016was installed on枣庄服务器, and the active endpoint advertises bothremote.run.db.sqlite.probeandremote.run.db.sqlite.query.
Server-management diagnostic evidence (2026-08-12)
-
Per operator direction, the Run install target is
枣庄服务器(FyBDIohqPhRx7Cia); personal server-management MCP inventory andtest_connectionboth succeeded for that device. -
Bounded SSH diagnostics checked only process/service/capability metadata and emitted no raw SQL, database content, credentials, SCUM rows, or database reads. The server has a Windows Run process for
server-run-server-scum-1785923898033, the current SCUM server process is running, andhttps://scum.npc0.com/healthzreturned200from the server side; per operator clarification,scum.npc0.comis the NAT entry back to the local Platform. -
Platform durable probe job
job-remote-adapter-server-scum-1785923898033-3442596095552254276was queued throughPOST /api/v1/server-instances/server-scum-1785923898033/scum/schema-probewith idempotency keyzao-zhuang-schema-probe-20260812-1632, claimed by the authenticated active Run binding, acknowledged, and executed with targetdatabases/scum-database,MaxAttempts=1, and a nonzero fencing token. -
The probe terminal result was accepted by Platform as a typed
sqlite.schema-proberesult with safe statusfailed, safe error codetarget_unavailable, result digestsha256:41624741855866ce10b3143edba66c3a6b771029256b9489a30f395885526b61, and observed time2026-08-12T08:31:45Z. This proves the Platform durable job path and active Run probe executor are wired, but it does not prove current SCUM schema compatibility. -
The first generated Run workspace contained lifecycle package assets but no
databases/scum-databaselogical database target, so current-service schema capture was initially blocked at the package/database-target mapping layer. That failure stayed closed and kept database-backed SCUM read/write gates disabled until the later Run data-target fix produced successful schema metadata. -
Follow-up bounded SSH diagnostics on
2026-08-12located exactly one activeSCUM.dbcandidate by process-relative metadata only, with no SQL execution or row reads; the live file was locked for direct hashing/copying. This supports the package-target diagnosis but is not current-service schema evidence for tasks 2.5-2.9. -
Platform/plugin contracts now declare a plugin-owned
runtimeProfiles.dataTargetssqlite snapshot target forscum-databasethat materializes todatabases/scum-databaseinside the generated Run workspace; SCUM schema-probe dispatch fails closed when that data target is absent. The later independent Run materializer fix supplied the matching generic data-target behavior required for the successful durable probe. -
Operator clarification on
2026-08-12narrowed the architecture boundary: Platform/plugin must not download or parseSCUM.db, but an operator-directed, server-local Python diagnostic on枣庄服务器is acceptable discovery evidence when it is read-only, bounded, redacted, and not treated as the product execution path. The diagnostic captured schema metadata in place and is recorded inevidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; database-backed product gates remain disabled until durable Run envelopes and versioned adapters are accepted. -
After the Run data-target fix and Platform
sourceFingerprintdecode fix, durable probe jobjob-remote-adapter-server-scum-1785923898033-7249327407638289501succeeded through the product path. Platform persisted probe statussucceeded, source fingerprintsha256:d8f3e2f5e9c8241f55b931008309a7ab5f241118a82cbd3620ddedf233e74c13, schema fingerprintsha256:ebd477d6c6ead9c34c41169af489236d762a76186d45dedd753d50f1b81e26f0, result digestsha256:ef13678df4add731c758bba157627dc8af80138a69476facd81bbe354c31d7f1,161schema objects, observed time2026-08-12T12:17:39.0088015Z, and terminal time2026-08-12T12:29:24.857542Z. -
Server-management MCP verification on
2026-08-12confirmedtest_connectionsucceeded for枣庄服务器,SCUMServer.exewas running, and the target durable probe job had0active entries and0pending-result entries in the remote Run journal after Platform accepted the typed result. The redacted evidence is stored inevidence/scum-durable-run-schema-probe-2026-08-12.md. -
Follow-up server-local read-only Python probes on
2026-08-12verified the actual current-service joins and nullable fields for external identity, profile/prisoner/entity relationships, squad members, flag/base ownership candidates, vehicle identity, bank-account balances, and XML payload candidates. The results are recorded inevidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; unproven rank leader semantics, squad-territory ownership, currency labels/units, command confirmation, and855mapping remain gated rather than guessed. -
A task 2.8 confirmation pass on
2026-08-13separately checked the SCUM live-data manifest, platform/plugin declarations, and read-onlyscum_robotreference behavior for economy commands, gift aliases/transports, map asset/transform authorization, and855. No economy command, gift catalog/transport, distributable map asset/transform, or855preset mapping is verified enough to enable; the old bridge/domain/reference declarations remain hypothesis or legacy facade material only, and the affected capabilities stay disabled until digest-referenced current-service adapter evidence exists. -
2.1 Add a release gate that keeps every database-backed SCUM read and write capability disabled until capability-specific current-service evidence matches a versioned plugin adapter; do not add production SQL or mutation assets before this group is complete.
-
2.2 Define the minimal generic schema-probe request/result contract, safe error model, binding identity, bounds, and redacted evidence DTO needed by Platform and the plugin without embedding SCUM table names or host paths in Run-facing generic code.
-
2.3 If the active binding lacks the minimal bounded query-only probe executor, create/hand off a separately authorized task rooted in the independent Run repository, wait for its tests/commit/deployment evidence, and record that evidence here; do not edit or vendor Run source from this change.
-
2.4 Use the personal server-management MCP (
list_devices,test_connection, thenssh_execonly when needed) for device inventory, connectivity checks, and bounded diagnostics. Execute product/acceptance schema probes only as Platform durable jobs through the active authenticated Run binding; an operator-directed server-local Python diagnostic may inspect the active database in place for discovery but must not become a Platform/plugin/browser data path. -
2.5 Capture
sqlite_master, applicable read-only PRAGMA metadata, indexes, foreign keys, declared types, cardinalities, and small redacted samples for candidate player, profile/entity, squad/member, vehicle, flag/base, economy, coordinate, and character-profile payload sources. -
2.6 Verify actual joins and meanings for external player identity, profiles/entities, squad ranks/leaders, flag ownership, vehicle identity, currency units/types, nullable fields, and the real table/column containing character XML; do not assume that
user_profile.template_xmlor any reference-project field exists. -
2.7 Measure coordinate ranges and update cadence, query latency, lock/busy behavior, snapshot consistency, safe timeout/row limits, and whether a verified companion position source is needed for the advertised realtime-map cadence.
-
2.8 Confirm separately which economy commands support safe confirmation, which gift item aliases/transports are real, which distributable map asset/transform is authorized, and what named attributes—if any—the operator means by the
855preset. -
2.9 Store sanitized probe evidence or an immutable referenced test artifact and derive the observed schema fingerprint/evidence matrix; do not claim final adapter compatibility until the versioned adapters and query contracts in group 3 exist.
3. Plugin SDK, Manifest, and Immutable SCUM Assets
Login-log fixture evidence (2026-08-13)
- Server-management MCP
list_devices/test_connectionconfirmed枣庄服务器(FyBDIohqPhRx7Cia) was reachable, and boundedssh_execdiagnostics observed the activeSCUMServer.exeprocess without returning host paths or raw protected values. - Recursive active-service log discovery found
30login_{date}{digits}.logfiles under the current service log root. The newest active login log fingerprint issha256:752c3ee3789fe73b80245dfcb97776db27f977c4350c3b50516278afbecb9dad, generationsha256:57b5be4818757e4d64070e5e0f026dbd471bdba189d0426a38b618423f7e1439,0bytes, last written2026-08-12T01:18:15.6090680Z; Run tailing must handle zero-byte active files and later append/rotation boundaries. - Authentic non-empty login fixtures are UTF-16LE and match
{timestamp}: '{network_redacted} {external_player_id}:{display_name}({profile_local_id})' logged {in|out} at: X={coordinate} Y={coordinate} Z={coordinate}. Sanitized fixture rows bind expectedscum.login/scum.logoutevents to serverserver-scum-1785923898033, Run bindingserver-run-server-scum-1785923898033, plugingame.scum0.1.6, pending parser keyscum-login-log-parser.pending-real-fixture-v1, parser versionpending-scum-login-log-v1, parser digestsha256:5bb528cb9f6e04d8d8b819db3a71f855569c78a5135f22a982301301ae1da50a, transport cursor(sourceIdentity, streamGeneration, sequence), and separate privacy-safe logical event identities. Evidence is stored inevidence/scum-login-log-fixtures-2026-08-13.md.
Login-log parser implementation evidence (2026-08-13)
- Added plugin-owned parser asset
assets/scum-live/login-log-parser.jsonand manifest declarations forscum.login/scum.logoutunderscumLiveData.logParsers, digest-referenced assha256:264835fb36255071fed46dd50724ec511986db901ac8056b08ddafb10f5f0056while keeping database/write capability gates disabled. - Implemented versioned companion parser
scum-login-log-parser-v1/scum-login-log-v1for UTF-16LElogin_{date}{digits}.loglines with transport cursor(sourceIdentity, streamGeneration, sequence)and a privacy-safe logical identity that excludes network material, coordinates, source identity, stream generation, and sequence. - Added focused companion tests for successful login/logout, failed login, partial, undecodable, oversized, malformed lines, rotation/copy-truncate overlap across a new generation, restart/resume acknowledgements, duplicate transport/logical delivery, out-of-order delivery, and absence of network/coordinate material in parsed event storage/fingerprints.
- Verification passed:
(cd plugins/examples/scum-server-plugin/companion && go test ./...)and(cd plugins && npm run validate:manifest).
Map asset implementation evidence (2026-08-13)
- Added plugin-owned SCUM current-service coordinate-map metadata and transform assets under
assets/scum-live/map/, digest-referenced fromscumLiveData.mapAssetsassha256:74800836553c7e4372a0747c5e9511adcee940b057194488bbf65bf164df372bandsha256:f1941109167a86818e9e71996821884aeb8bd7e863584454b891e525695ba478. - The packaged asset is explicitly limited to first-party-generated coordinate metadata and the observed current-service coordinate envelope from
evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; no unauthorized SCUM base-map artwork is shipped, andpositions.readremains disabled until compatible evidence enables it. - Added manifest-validator checks and fixture tests for map metadata/schema compatibility, transform adapter/schema fingerprint matching, declared bounds/image consistency, known-point projection fixtures, non-finite/out-of-bounds rejection, and digest-preserving adapter incompatibility.
- Verification passed:
(cd plugins && npm test -- manifest-validation.test.ts)and(cd plugins && npm run validate:manifest).
Typed RCON and gift catalog gate evidence (2026-08-13)
- Reviewed current-service evidence in
evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md: Fame/currency commands, notification-as-RCON semantics, gift aliases/transports, conclusive per-item receipts, and catalog aliases remain unverified. Therefore the production SCUM manifest continues to declare noscumLiveData.typedRconTemplates, noscumLiveData.giftCatalogs, and no digest-referenced RCON/gift assets. - Kept
economy-command.writeandgift-command.writedisabled withmissingevidence status; no command text, gift alias, starter-pack catalog, legacy hard-coded gift, or notification transport is exposed through live-data assets. - Tightened SDK/schema/validator contracts so any future SCUM typed RCON template must carry a bounded
confirmationSchemaRefin addition to payload/result schemas, contained asset paths, immutable digests, protected RCON transport, andserver.game-client.commandpermission. - Added manifest tests proving production omits unverified typed RCON templates and gift catalogs, and rejects any SCUM typed RCON declaration without a conclusive confirmation schema.
- Verification passed:
(cd plugins && npm test -- manifest-validation.test.ts).
Current-service baseline refresh (2026-08-13)
-
Per operator correction, the change now stores current-service structure baselines before attempting further capability declarations.
evidence/scum-current-service-db-schema-baseline-2026-08-13.mdrecords the full161-table compact schema inventory from a server-local read-only Python diagnostic, including row counts, columns, primary-key columns, foreign-key counts, and index counts without raw rows, SQL, XML, paths, credentials, sockets, IPs, or player identities. -
evidence/scum-current-service-log-structure-baseline-2026-08-13.mdrecords the process-adjacent log inventory from a successful server-local diagnostic:1200log/text files across hashed directories, includinglogin_{digits}.log,admin_{digits}.log,gameplay_{digits}.log,economy_{digits}.log,chat_{digits}.log,vehicle_destruction_{digits}.log,SCUM.log, and service/runtime log families. Raw log lines and paths were not emitted or stored. -
evidence/scum-current-service-content-features-baseline-2026-08-13.mdrecords redacted content features from the current service: XML tag/attribute/value-shape summaries, selected DB content distributions, and log skeleton marker sets. It confirmsuser_profile.template_xmlparses asCharacterTemplatewith named character attributes andSkillentries, confirms sampledprisoner_skill.xmlvalues are not parseable XML documents, and classifiesitem_entity.xmlas item metadata rather than a profile attribute source. -
A broader line-shape diagnostic confirmed coordinate-shaped and network-shaped tokens exist in multiple log families, so parser assets must stay per-file-pattern and strip network material before durable storage. The authoritative file inventory remains the successful v4 evidence file.
-
Task 3.10 remains unchecked: the refreshed content-feature baseline confirms
user_profile.template_xmlis the parseable named-attribute source candidate, but it still does not prove preserving patch semantics, offline/backup/readback requirements, activation semantics, write safety, or an operator-confirmed855preset mapping. -
3.1 Add SDK and manifest types for versioned log parsers, SQLite query assets, parameter/result schemas, capability-specific schema fingerprints, sync cadence/limits, map metadata, typed RCON templates, gift item catalogs, and guarded mutation declarations.
-
3.2 Extend plugin validation to require asset digests, contained package paths, unique template keys, bounded parameters/results, compatible adapter versions, and explicit permission bindings, and to reject raw caller-supplied SQL, RCON, XML, paths, or undeclared parameters.
-
3.3 Capture sanitized authentic login-log fixtures from the active service and bind their expected events to server, Run binding, plugin version, parser version/digest, a transport cursor
(source identity, stream generation, sequence), and a separate privacy-safe logical event identity stable across rotation overlap. -
3.4 Implement the versioned SCUM login/logout parser and tests for successful login/logout, failed login, partial/undecodable/oversized/malformed lines, copy-truncate/rotation overlap under a new generation, Run restart/resume, duplicate delivery, and out-of-order delivery while discarding IP/network material before storage or logical fingerprinting.
-
3.5 Add parameterized, read-only player identity/detail/economy/session-enrichment query assets and exact result schemas only for joins and fields proven by the probe.
-
3.6 Add parameterized squad/member, vehicle, flag/territory, and position query assets and exact result schemas, keeping ambiguous ranks, ownership, coordinates, and missing numeric values null.
-
3.7 Add query-asset tests for single SELECT/CTE or approved introspection boundaries, parameter binding, pagination/cursors, timeout/row/byte limits, schema-version matching, and rejection of DDL, mutation,
ATTACH, extension loading, write PRAGMAs, and multi-statement input. -
3.8 Package the authorized SCUM map asset, identity/version, verified world bounds, layer metadata, and coordinate transform, with fixture tests for known points, out-of-bounds/non-finite coordinates, and adapter incompatibility.
-
3.9 Declare only verified typed RCON templates for supported Fame/currency/notification/gift operations and a version-scoped gift item catalog; omit any command whose execution and confirmation semantics remain unknown.
-
3.10 Declare a guarded preserving XML mutation only after the real XML source and named attributes are proven; expose
855only as a reviewed named-attribute preset and never as a database column, generic integer field, or guessed mapping. -
3.11 Add immutable asset/digest declarations and plugin package validation; defer generated Run-package execution wiring until the complete protocol/result envelope and independent Run capability evidence in group 4 are frozen.
-
3.12 Remove SCUM Workflow/projection declarations and obsolete page/action declarations from the plugin manifest while preserving the five required pages and AI configuration assistance.
-
3.13 Match the observed fingerprint/evidence matrix against each completed adapter, add per-capability compatibility/release-gate tests, and leave every unsupported or ambiguous player/squad/vehicle/flag/position/write capability disabled.
4. Generic External Run Execution and Result Contracts
Platform probe wiring evidence (2026-08-12)
-
Platform now has an internal-only
RequestSCUMSchemaProbeForSessionpath that builds a durableremote.run.db.sqlite.probejob from the SCUM plugin's manifest declaration, active runtime binding, logical target key, adapter version, and bounded probe limits; public remote-adapter and plugin-page requests for the probe capability are denied. -
Run terminal results may carry
executionResult.sqliteSchemaProbe; Platform DTO/domain/validator/job-channel code validates the typed redacted envelope, job/request identity, and binding fence before persisting it on the durable job. -
Generated Run packages now carry redacted autonomous lifecycle
dataTargetsentries for plugin-owned sqlite snapshots, and browser-facing runtime-profile responses continue to omit those source declarations. -
Focused evidence:
go test ./dto ./service -run 'Test(RunJobResultRequestParsesSQLiteSchemaProbeEnvelope|SCUMSchemaProbeDispatchIsPlatformScheduledAndFenced|RemoteAdapterRequestPropagatesTypedInputsToRunJob)'and(cd platform && go test ./...)passed locally. These tests do not prove the active Windows Run deployment or current SCUM schema, so tasks 2.3-2.9 and 4.2-4.9 remain unchecked. -
4.1 Add Platform protocol contracts under
platform/protocol, API DTOs underplatform/dto, validation underplatform/validator, and plugin contracts/assets underplugins/sdkandplugins/schemas, plus contract documentation/mocks for probes, read-only template execution, typed RCON, guarded SQLite/XML mutation, parsed log events, and terminal result envelopes. -
4.2 Freeze the generic executor/result contract and hand off a separately authorized Run-repository task for packaged SQLite-template execution with query-only connections, bound parameters, one-statement validation, short busy/operation timeouts, cancellation, and row/result-byte limits.
-
4.3 Require the independent Run task to return typed envelopes containing server/plugin binding, adapter/schema version, template key, asset digest, job identity, observed time, checksum, rows or affected-row count, and stable safe result/error codes.
-
4.4 Require the independent Run task to implement generic plugin-owned typed RCON-template execution without accepting browser command text or adding branches for SCUM, SCUM keys, SCUM commands, or SCUM tables.
-
4.5 Require the independent Run task to implement generic guarded single-row SQLite/XML mutation execution with expected identity/value/checksum guards, a bounded transaction, preserving XML patching, rollback on zero/multiple affected rows, and read-after-write confirmation.
-
4.6 Require the independent Run task to implement or extend generic plugin-declared log-source tailing so cursor persistence, rotation, truncate, restart, partial-line buffering, parser digest fencing, logical event fingerprinting, and replay remain independent of SCUM-specific source paths.
-
4.7 Verify from the independent Run task's acceptance evidence that control/job/log/artifact priorities, leases, fencing, acknowledgements, idempotency, and late/duplicate terminal-result handling remain intact for the new generic capabilities.
-
4.8 Add Platform-side capability negotiation so probe, player/squad/vehicle/flag/position reads, typed commands, gifts, and guarded mutations are gated independently for each active Run/plugin/adapter binding.
-
4.9 After the external Run contract tests/commit/deployment evidence is available, wire immutable assets and digests into generated Run packages and add distribution/contract tests proving Platform sends only template keys, bounded parameters, adapter version, and expected digest.
5. Dedicated Platform SCUM Persistence
- 5.1 Define SCUM domain types and narrow repository/service interfaces in the required
platform/directories, keeping API DTOs, database models, validation, and repository contracts separate. - 5.2 Add dedicated player, session, player-detail, source-event, sync-cursor, capability-evidence, and completed-generation records with server-scoped identities and nullable unknown fields.
- 5.3 Add dedicated squad, squad-member, vehicle, flag/territory, and current-position records with source checksum/time, adapter version, generation, and server-scoped indexes.
- 5.4 Add dedicated gift-package, gift-item, frozen-delivery, per-item receipt, eligibility-period reservation, notification-result, and immutable completed-delivery records.
- 5.5 Implement normalized MySQL models and explicit migrations with uniqueness constraints for player/event/session identity, generation rows, gift idempotency, and concurrent eligibility reservations.
- 5.6 Implement the default file-backend SCUM store as a platform-owned SQLite sidecar under the configured data directory, with pinned driver/migration behavior and no high-frequency writes to the global metadata snapshot.
- 5.7 Implement the memory backend with the same server isolation, uniqueness, transaction, null, generation, and idempotency semantics for tests.
- 5.8 Implement transactional generation commits so a complete validated scan may mark missing rows absent, while partial/failed/older scans preserve the last completed generation unchanged.
- 5.9 Add health, migration, rollback/disable, and database-instance invalidation behavior; never migrate old projection/Workflow snapshot values into the new tables as game facts.
- 5.10 Add backend-parity tests for migrations, uniqueness, concurrent first login, nullable numeric values, failed-generation retention, server isolation, and gift reservation/idempotency constraints.
6. Authentic Login Ingestion and Automatic Synchronization
- 6.1 Add a typed parsed-log event ingress that authenticates and correlates server binding, plugin/adapter/parser digest, transport cursor
(source identity, stream generation, sequence), separate stable logical event identity, and occurrence time before calling SCUM ingestion. - 6.2 Atomically upsert one
(server_instance_id, external_player_id)player and open one session for an authentic successful login without waiting for database enrichment. - 6.3 Close only the matching current session on logout, do not fabricate a session for an unmatched logout, and prevent older logout/login events from regressing a newer display name, last-seen time, or online session.
- 6.4 Close or mark sessions unknown with a bounded reason when a binding/source epoch is replaced, server stops, or log continuity is lost without a logout; never leave them permanently confirmed online from database save timestamps.
- 6.5 Strip raw IP addresses and all network identifiers before durable player/session/event storage and exclude them from every SCUM API, diagnostic, and AI context.
- 6.6 Add ingestion tests for concurrent first login, replayed events, duplicate/out-of-order events, failed login, unmatched logout, partial-line resume, copy-truncate/rotation overlap replay under a new generation, Run restart, parser-digest mismatch, cross-server events, and database timestamps that must not imply online state; an overlapped logical login SHALL still produce one player/session.
- 6.7 Add an automatic scheduler that starts a capability-specific probe when an active binding lacks current evidence, starts an initial bounded scan after compatibility succeeds, then uses plugin-declared jittered cadences, backoff, and per-server/per-capability concurrency limits.
- 6.8 Schedule bounded player-detail enrichment after a new login without delaying player creation, and use the measured safe position cadence or a declared verified companion source without fabricated intermediate motion.
- 6.9 Create every durable Run job before dispatch and attach the expected server/plugin/template/digest/schema/generation correlation needed for immediate, late, and duplicate results.
- 6.10 Add a terminal-job hook that validates the full result envelope and row schema before calling the matching transactional SCUM sync service.
- 6.11 Reject malformed, foreign, duplicate, or older results idempotently; commit only complete generations and retain prior rows plus a safe connection/sync error after locks, timeouts, partial results, or incompatible schemas.
- 6.12 Publish safe player/session/squad/map updates through a platform-owned event stream/SSE while keeping Platform Web reads backed by local records.
- 6.13 Add tests proving page opens/retries never create schema probes, Run queries, projection refreshes, real-data refreshes, manual syncs, or audit jobs.
7. Player Management APIs
- 7.1 Add safe player-list/detail/session DTOs, request schemas, validators, API clients/contracts, and routes in their fixed directories without exposing raw logs, database rows, XML, SQL, paths, or network material.
- 7.2 Implement server-side player pagination, bounded name/external-ID search, online and squad filters, deterministic allowlisted sorting, and total/page metadata against the local SCUM store.
- 7.3 Implement player detail with identity, verified nullable facts, current verified coordinate, bounded login history, source collection times, and explicit not-yet-synchronized/confirmed-empty/incompatible/connection-failed states.
- 7.4 Enforce target-server read authorization before lookup and prevent cross-server player IDs, squad filters, selectors, counts, or existence from leaking.
- 7.5 Preserve unknown values as null/absent throughout storage, service, DTO, and JSON handling; never substitute zero, sample data, guessed profile IDs, or database save time as online evidence.
- 7.6 Remove player-intelligence, alias-history, shared-IP, access-attempt, automatic-risk, security-signal, and hard-coded increment dependencies from the SCUM player API and ingestion flow.
- 7.7 Add repository/service/API tests for search/filter/sort bounds, pagination stability, confirmed-empty versus unavailable data, nullable facts, login history, authorization, cross-server isolation, and absence of manual-refresh endpoints.
8. Squad Management and Realtime Map APIs
- 8.1 Implement server-scoped paginated/searchable/sortable squad list and detail APIs with verified members, adapter-declared rank meanings, leader when proven, flags/territory, and ordinary collection times.
- 8.2 Keep leader, rank, territory, and ownership unknown when joins or enum meanings are ambiguous, gate squad/member/flag/territory resources independently, and test that reference constants or proximity/history heuristics are not evidence.
- 8.3 Implement bounded local vehicle and flag APIs containing only verified identity, class/status, coordinate, ownership, and collection fields supported by each active adapter capability.
- 8.4 Implement a safe current-map dataset API for players, vehicles, flags, squads/territories, layer filters, and source collection times without returning database or Run connection material.
- 8.5 Apply the plugin-declared map version/bounds/coordinate transform server-side or through a shared tested contract, rejecting incompatible, non-finite, and out-of-bounds coordinates instead of generating fallback points.
- 8.6 Publish newer verified position/map updates through the platform event stream with entity identity and server/version fencing; page subscriptions must not dispatch Run reads.
- 8.7 Enforce server authorization, bounded selectors/result sizes, and no cross-server existence leaks across all squad/map endpoints.
- 8.8 Add service/API tests for successful and failed generations, per-resource gating, unknown ownership/ranks, last-complete rows after interruption, transform fixtures, layer filtering, event ordering, and incompatible-map unavailable results.
9. Gift Management, Eligibility, and Delivery
- 9.1 Add server/plugin-version-scoped gift package and typed item validators for names, classification, active state, quantities, eligibility rules, period limits, and only plugin-catalogued item keys.
- 9.2 Implement
server.game-client.readpackage/history reads,server.game-client.maintenancepackage create/update/enable/delete, andserver.game-client.commandreviewed delivery APIs using the current session's effective target-server permissions. - 9.3 Evaluate per-player/server/period eligibility in the server's declared timezone and reserve limit capacity transactionally for in-flight, partial, and unknown deliveries so concurrent requests cannot exceed the configured limit.
- 9.4 Freeze target player, package/items, quantities, plugin/game/adapter version, period reservation, delivery identity, and idempotency key before dispatch; later package edits must not alter a delivery.
- 9.5 Dispatch only plugin-declared typed item aliases and quantities through the controlled command path, never arbitrary browser command strings.
- 9.6 Treat queued, claimed, acknowledged, or started jobs as in progress; record
deliveredonly after a schema-valid conclusive receipt for every required item. - 9.7 Preserve reservations and per-item receipts for timed-out, missing, partial, or unknown outcomes, require confirmation before an explicit retry, and never automatically redeliver the whole package or already confirmed items.
- 9.8 Release a period reservation only after conclusive evidence that no game effect occurred; record post-delivery notification failure separately without changing the delivered fact or triggering redelivery.
- 9.9 Add server-scoped package statistics, searchable/filterable pagination, real player selection, reviewed send requests, and ordinary delivery-history/result APIs without Workflow or audit terminology.
- 9.10 Add concurrency, idempotency, timezone-boundary, cross-server, catalog-version, partial/unknown outcome, reservation-release, notification-failure, permission, and immutable-history tests.
10. Controlled Manual and AI/Agent Writes
- 10.1 Define one named-field write draft containing server/player/action/field, verified current value/checksum, proposed value, reason, adapter/digest, idempotency key, safety requirements, and a safe reviewable diff.
- 10.2 Authorize the current user's effective target-server permission when a draft is created, reviewed, confirmed, and dispatched, with backend checks authoritative and no component-principal, manifest-declaration, or callback-presence bypass.
- 10.3 Supply the plugin page host with the current session's effective permissions and readable denial reasons while keeping direct API denial authoritative.
- 10.4 Route verified Fame/cash/gold writes through plugin-owned typed RCON templates with
server.game-client.command, validated absolute target values, explicit reason, idempotency, and declared confirmation reads. - 10.5 Route database/XML writes only with effective
server.game-client.maintenance, verified target/offline or maintenance state when required, genuine same-instance restorable backup evidence, expected before values/checksum, and an explicit dangerous-operation confirmation; do not create a platform-admin approval workflow or approval queue. - 10.6 Execute preserving named-attribute XML patches only against the probe-confirmed source, reject malformed XML or absent/undeclared nodes, preserve unknown content, and update exactly one guarded row.
- 10.7 Keep
855absent until its named mapping is confirmed; when available, expand it into an explicit per-attribute before/after review rather than acceptingfieldKey=855,prisoner.value, or a generic integer. - 10.8 Validate command/mutation terminal envelopes and readback before success, update local verified details only after conclusive confirmation, and represent missing/mismatched results as failed, conflict, or unknown without automatic retry.
- 10.9 Never chain kill, death, respawn, kick, or another destructive activation to attribute save; any verified required activation must be a separate explicitly named, permission-checked, confirmed action.
- 10.10 Preserve AI-assisted plugin configuration through the existing platform-mediated reviewable config-diff path without exposing provider keys or granting the plugin page direct write authority.
- 10.11 Make AI/Agent player-operation suggestions create the exact same named-field draft as manual forms, reject undeclared fields/protected payloads, retain the initiating user, and require that user's current effective permission plus explicit confirmation.
- 10.12 Add tests for read-only users, revoked permissions between draft and dispatch, cross-server targets, invented AI fields, stale checksums, fake backup evidence, unsafe online state, zero/multiple rows, malformed XML, missing nodes, unknown results, confirmation mismatch, duplicate requests, and no approval-queue creation.
11. Five-Tab SCUM Product Surface
- 11.1 Place SCUM API clients/types, route definitions, page contracts, component contracts, schemas/validators, bridge/SDK types, and shared utilities in their fixed frontend/plugin directories rather than inside page components.
- 11.2 Make the SCUM detail navigation contain exactly
用户管理,队伍管理,实时地图,礼包管理,AI 助手in that order, default to用户管理, and fall back from legacymanage,workflows, or invalid sections without affecting non-SCUM plugins. - 11.3 Preserve the existing server-list deployment action and relocate display-name and administrator-membership controls to a compact detail-header settings drawer/dialog with existing owner authorization; do not add another permanent management tab.
- 11.4 Build
用户管理as a full-width server-paginated table with bounded filters/search/sort, online evidence, nullable verified facts, detail/login-history drawer, and explicit named-field edit dialogs. - 11.5 Build
队伍管理as a full-width paginated squad table and semantic detail drawer separating leader/ranks, members, flags, and territory while showing unknown facts honestly. - 11.6 Build
实时地图from the authorized map asset and tested transform with distinct player/vehicle/flag/territory layers, filters, legend, source coordinates/collection time, safe live updates, and a clear incompatible/unavailable state. - 11.7 Build
礼包管理with real package statistics/table, CRUD dialogs, typed items and limits, real player selection, reviewed delivery, and delivery history for in-progress/delivered/failed/partial/unknown/notification-failure outcomes. - 11.8 Keep
AI 助手as the final tab for plugin configuration diffs and controlled player-operation drafts, with apply disabled when effective permission is absent. - 11.9 Hide or disable write controls according to current effective permissions with textual reasons, and re-check authorization server-side on every apply request.
- 11.10 Load only platform-local resource APIs and the platform event stream; display ordinary connection and last synchronized/collected information, and let retry repeat only a local read.
- 11.11 Reuse shared tables, drawers, dialogs, status,
console-*, and theme tokens; preserve black-mecha and magical-girl readability, keep CSS declarations compressed, and add no page-local fixed decoration or generic opaque SaaS card system. - 11.12 Cover keyboard/focus behavior, non-color-only status, responsive full-width working surfaces, bounded compact actions, and readable destructive confirmations.
- 11.13 Add frontend tests for exact navigation/order/default/fallback, settings ownership, local-only loading, permission presentation, null/empty/error states, real map/gift data, AI review parity, and absence of fake actions or placeholder records.
12. Projection, Workflow, Intelligence, and Placeholder Removal
- 12.1 Inventory references before deletion and distinguish SCUM-only projection/Workflow/player-intelligence code from generic durable Run jobs, internal write evidence, and non-SCUM consumers.
- 12.2 Remove SCUM Workflow instance/step/status APIs, repositories, services, routes, clients, manifest declarations, page components, workflow creation/listing, pending-review counters, operation approval routes, and approval/confirmation queue surfaces without removing generic Run job execution.
- 12.3 Remove SCUM projection/observation/freshness snapshot types, ingestion, metadata fields, refresh/audit services, page actions, and manual synchronization endpoints; removed endpoints must return not found or a stable removal response and dispatch no job.
- 12.4 Remove SCUM dependencies on alias history, shared IP/fingerprint, access attempts, automatic risk/security signals, and player intelligence; delete shared implementation only after proving it has no remaining non-SCUM consumer.
- 12.5 Remove the standalone
管理andWorkflow 状态tabs, legacy placeholders/routes, fake maintenance/backup evidence, hard-coded increments, opaque855action, hard-codedstarter-pack, fixed notification, gradient-only map, arbitrary percentage points, and sample/generated players/world data. - 12.6 Remove runtime product copy including
Workflow 状态,投影,真实投影,玩家投影,刷新投影,刷新世界投影,刷新真实数据,发起审计,创建发放 workflow,typed workflow,typed observation,typed operation,待审操作,审批/确认队列,清理旧入口,目前暂无真实投影数据,暂无真实投影数据,暂无玩家投影, andCompanion 可用. - 12.7 Add upgrade behavior that starts the new SCUM stores empty, populates only from post-upgrade authenticated logs/current-service sync, invalidates incompatible bindings, and never translates old snapshot values into real facts.
- 12.8 Add a rollback/feature-disable path that disables incompatible SCUM reads/writes while leaving diagnostic local records intact and never re-enables fake projection or Workflow data.
- 12.9 Add scoped runtime-source/manifest/API tests or assertions proving banned copy/actions/routes are absent, removed endpoints cannot dispatch jobs, and generic lifecycle, logs, jobs, AI provider management, and non-SCUM plugin navigation still work.
- 12.10 Record the supersession mapping from the completed-but-unarchived legacy SCUM changes to these unique replacement capabilities; do not archive obsolete deltas into the main baseline, and leave any history consolidation to a separate reviewed skip-specs/equivalent archival task.
13. End-to-End Verification and Release
- 13.1 Run focused Go tests after each Platform repository, migration, ingestion, scheduler, API, gift, permission, and terminal-result change, then run
(cd platform && go test ./...). - 13.2 Run plugin SDK/parser/query/map/manifest tests and final checks with
(cd plugins && npm run typecheck && npm run test && npm run validate:manifest), then run(cd plugins/examples/scum-server-plugin/companion && go test ./...). - 13.3 Run frontend tests and final checks with
(cd platform_web && npm run typecheck && npm run test && npm run build). - 13.4 In the separately authorized Run-repository task, run
go test ./...from that repository's own root and record its tested commit/version plus deployment compatibility evidence here; do not edit, stage, or commit Run source from the browser-repository apply task. - 13.5 Against the active current service, verify read-only schema compatibility, authentic login-created local player/session data, automatic player/squad/vehicle/flag/position sync, generation retention after an induced safe read failure, and no unbound copied/cache/fixture database use.
- 13.6 Verify login-log acceptance with sanitized real fixtures covering partial lines, failed login, rotation, truncate, restart/resume, duplicate, and out-of-order events plus server/Run binding/plugin/parser-digest fencing.
- 13.7 Extend and run
scripts/browser-acceptance.shagainst synchronized local data for the exact five tabs, local-only page reads, user/squad/map/gift behavior, permission-aware edit reviews, AI configuration/player drafts, legacy-route fallback, and absence of projection/Workflow/manual-refresh/audit controls. - 13.8 Verify controlled writes against isolated test data or an explicitly authorized test player only; prove permission, explicit confirmation, guards, backup/offline requirements, idempotency, readback, unknown-result handling, XML preservation, and no implicit respawn.
- 13.9 Perform scoped security checks proving browser/API/AI/job-safe responses contain no raw SQL, RCON, XML, host/database paths, credentials, sockets, IP data, or cross-server resource existence, and that external Run has no SCUM-specific executor branches.
- 13.10 Run
scripts/check-structure.shand fix every relevant structural violation without moving implementation outside its owning root. - 13.11 Run
openspec validate replace-scum-projections-with-real-data-management --strict, review task evidence and the final diff, and leave any task unchecked if its real-service, external-Run, test, or safety evidence is missing. - 13.12 On
main, stage only files belonging to this change, create a concise commit after all required verification succeeds, and push the configured remote without including unrelated pre-existing worktree changes.