4.5 KiB
Run SQLite Template Execution Handoff (2026-08-13)
This is a browser-repository handoff for a separately authorized task in the independent Run repository git@git.npc0.com:admin343/run.git. It is not Run implementation or deployment evidence, and it does not enable SCUM database-backed reads by itself.
Positive prompt (正向提示词)
Implement generic packaged SQLite-template execution for Run's remote.run.db.sqlite.query capability so Platform can dispatch current-service SCUM read jobs without sending SQL text, host paths, credentials, sockets, raw XML, raw RCON, or browser-supplied table names. Success means Run accepts only a typed leased sqliteTemplate request containing a logical target key, template key, adapter/schema version, immutable asset digest, canonical parameter digest, bounded scalar parameters, and strict limits; executes a query-only package-resolved SQLite template; and returns a typed sqlite.template-query terminal envelope that Platform can validate against the original durable job.
Directional prompt (方向提示词)
Work only in the independent Run repository. Preserve Run as a generic executor: resolve package-scoped logical databases/... targets and packaged assets from the generated Run workspace, verify the asset digest and adapter/schema fingerprint, validate canonical bounded parameters, open SQLite in query-only/read-only mode or use a fenced short-lived read-only snapshot, enforce one-statement validation, reject mutation/DDL/ATTACH/extension loading/write PRAGMAs/multi-statement input, bind parameters, apply short busy and operation timeouts, honor cancellation, and enforce row/result-byte limits. Return the terminal envelope through the existing signed job-result channel with request/job/binding identity, capability, target/template key, adapter version, schema fingerprint, asset digest, parameter digest, source fingerprint, observed time, result digest, row count, bounded rows, truncation flag, applied limits, status, and stable safe error code.
Expected Run verification: focused protocol/runtime tests for valid template execution, digest mismatch, schema mismatch, parameter validation, cancellation, busy/timeout handling, result limits, one-statement enforcement, mutation/DDL/ATTACH/extension/write-PRAGMA rejection, duplicate/late terminal result behavior, and go test ./... from the Run repository root. After implementation, record the tested Run commit, distribution/deployment evidence for the active binding, and safe terminal-envelope evidence back in this browser-repository change before enabling DB-backed read gates.
Boundary prompt (任务边界)
Do not edit or vendor Run source into this browser repository, add a run/ tree here, download or parse SCUM.db on the platform/plugin/browser side, expose raw SQL/RCON/XML/paths/credentials/sockets/IPs/player identities in evidence, accept browser command/query text, add SCUM-specific executor branches, infer SCUM table semantics inside Run, enable write capabilities, enable database-backed read gates before tested Run evidence is recorded, or treat this handoff as product acceptance evidence. Run must remain game-agnostic and execute only package-declared generic assets under the active signed binding and lease.
Browser-side frozen contract
- Platform domain/DTO contracts define
SCUMSQLiteTemplateRequest,SCUMSQLiteTemplateResult, bounded template limits, scalar parameters/rows, and stable terminal statuses. - Job-channel DTOs expose leased
executionInput.sqliteTemplateto Run and parse terminalexecutionResult.sqliteTemplatefrom Run. - Validators reject unsafe template keys, protected material, raw SQL/path-like values, unsupported capabilities, invalid digests, loose bounds, mismatched row counts, and unsafe result rows.
- Service job completion accepts
sqlite.template-queryonly forremote.run.db.sqlite.query, requires the typed result on success, checks leased job/binding/template/schema/asset/parameter identity, and includes typed result digests in terminal idempotency fingerprints.
Remaining evidence required before enabling reads
- Tested Run commit and
go test ./...output from the independent Run repository. - Generated Run package carrying the packaged query assets and immutable digests.
- Active binding deployment evidence showing the compatible Run advertises and executes
remote.run.db.sqlite.querythrough the typed envelope. - Platform acceptance evidence for at least one safe read-only template job with no raw SQL, host paths, credentials, sockets, raw XML, raw RCON, or browser-supplied query material.