Files
browser/openspec/changes/replace-scum-projections-with-real-data-management/evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md
T

8.3 KiB
Raw Blame History

SCUM Current-Service SQLite Diagnostic Evidence — 2026-08-12

Scope

  • Evidence kind: operator-directed, server-local, read-only diagnostic discovery.
  • Execution target: 枣庄服务器 through the personal server-management MCP (list_devices, test_connection, ssh_exec).
  • Product boundary: Platform/plugin did not download or parse SCUM.db. The diagnostic script executed on the game server host and emitted only schema metadata, aggregates, hashes, and redacted samples.
  • Release boundary: this evidence supports adapter discovery. It does not replace the Platform durable Run job / typed Run envelope required before enabling database-backed production capabilities.

Database Identity and Read Behavior

  • One active SCUM.db candidate was found beside the running SCUM service metadata; no host path is recorded in this artifact.
  • Read mode: Python sqlite3 URI mode=ro, PRAGMA query_only=ON, 2s timeout.
  • Database size: 80,805,888 bytes.
  • SQLite metadata: schema_version=765, user_version=57, journal_mode=wal, page_size=4096, page_count=19728, freelist_count=1.
  • Object inventory: 293 schema objects, 161 tables.
  • Safe-read timing observed: full schema inventory 61ms; focused groups 3ms, 13ms, 3ms; join/range metrics 25ms; follow-up join/meaning probes 27.3ms and 5.68ms. No read lock/busy failure was observed during these diagnostics.
  • Fingerprints: full schema objects 57e34ee72660d7e4334644ee70cd6d285ac7961a3964fafdc3956d74e88dfa4f; focused table groups 12a34e49f851879ae71ba287719c8d95019909f3060e823be4ce0973ce764841, a856bc4e105ab0a5e34b758237d3f96cff0ba5a65b38e7cf1eb81ab16b40caf4, 60c97a8c782086c4b2600eb3a9b29c3074b971d5fdc6cf54137ce48e0970b26e; join/range metrics 4905d09b70303b42cfb8e7fc936fe0df2065d7100c43e92ef79a464958249af4.

Evidence Matrix

Area Current-service evidence Remaining ambiguity
External player identity user has 74 rows with id TEXT primary key, id_type, provider, last_login_time, creation_time, is_banned, and network-address field present but not persisted in this artifact. Follow-up aggregates show all 74 users have id_type=Steam, provider Server, and non-null identity/login/banned fields. Product APIs must hash or fence external IDs where appropriate and must never expose IP/network material.
Player profile join user_profile has 73 rows; all 73 join to user through user_profile.user_id -> user.id; all profiles have type=1. user_profile.prisoner_id -> prisoner.id and prisoner.user_profile_id -> user_profile.id both resolve 72 profiles. Indexes on (user_id,type,name), type, and prisoner_id were observed. Profile type=1 is observed but not independently named; adapter labels must stay version-scoped rather than using reference-project meanings.
Character/prisoner join prisoner has 72 rows and prisoner_entity has 72 rows mapping prisoner_id -> prisoner.id and entity_id -> entity.id. Join metrics: 73 profiles, 73 with user, 72 with prisoner, 72 with prisoner entity, 72 with entity; exactly one profile has null prisoner_id. One profile has no current prisoner/entity. Online state must still come from authenticated login/session evidence, not database timestamps alone.
Character XML / payload user_profile.template_xml is present and non-null for 73/73 profiles, length range 25412673; samples were hash+length only. prisoner_skill.xml has 72/1656 non-null rows, length 1565; item_entity.xml has 42304/62844 non-null rows, length 1364781. user_profile.template_xml is the verified profile-level XML source candidate, but write semantics, named attributes, and 855 mapping remain unverified.
Player coordinates entity has 63364 rows with location_x/y/z, rotation_x/y/z, scale, flags, class, and optional BLOB data. Joined prisoner entity range: x -872217.6875..567603.0625, y -843655.8125..554482.125, z 221.87356567382812..82958.546875; prisoner.last_save_time range 1773202437..1786533149. Save/update cadence and whether this can satisfy realtime map cadence still need measurement.
Squad squad has 7 rows; squad_member has 18 rows with squad_id, user_profile_id, rank; all members join to both squad and profile. Rank distribution: 1:6, 2:2, 3:4, 4:6; squad sizes are 1 member for 3 squads, 2 members for 2 squads, 3 members for 1 squad, and 8 members for 1 squad. Rank meanings / leader semantics are not present in the probed schema. Keep rank labels neutral and leader unknown unless a versioned adapter proves the mapping.
Vehicles vehicle_spawner.vehicle_entity_id -> vehicle_entity.entity_id -> entity.id resolves all 313 vehicle spawners; 15 distinct vehicle_asset_id values and one redacted alias value were observed. is_vehicle_functional distribution is 303 true / 10 false and all spawners are marked automatically created. Vehicle entity coordinate range: x -898438..601692.3125, y -881533.25..605226.5, z -84.04053497314453..98312.640625. Vehicle ownership meanings are absent from the verified join. Status can be limited to the probed functional/automatic-created fields; owner stays null.
Flags / bases base_element_flag.element_id -> base_element.element_id -> base.id resolves all 5 flags. All 5 flags have an owner_profile_id; 4 of those owner profiles currently have exactly one squad membership and 1 has no current squad membership; 0 overtaker profiles are present. Profile ownership is verified by column/join. Squad territory ownership remains separately gated because one owner has no squad membership and membership may not be the same fact as base ownership.
Economy / balances bank_account_registry.account_owner_user_profile_id -> user_profile.id resolves all 73 accounts; bank_account_registry_currencies.bank_account_id -> bank_account_registry.id -> account_owner_user_profile_id resolves all 146 currency rows. The nullable user_profile_id columns in both bank tables are entirely null. Currency distribution: type 1 has 73 rows, account_balance range -3000..830328; type 2 has 73 rows, range 0..14636. Currency type meanings, units, safe command/readback semantics, and gift item aliases remain unverified. Query adapters may expose numeric type only behind version-scoped labels until commands/readback are proven.
Spawn/location table prisoner_spawn_location has 78 rows with location_x/y/z, rotation, velocity, type, optional shelter_id; coordinate range roughly matches player entity bounds. This is spawn-location evidence, not current position evidence.

Redaction Notes

  • Player names, squad names/messages, map names, aliases, XML, BLOB payloads, tokens, and network-address material were represented only as hash+type+length when sampled.
  • Three player join samples were retained only as hash of external player id plus numeric profile/prisoner/entity IDs, timestamps, fame points, and coordinates.
  • Follow-up probes returned only aggregate counts, distributions, nullable counts, column names, coordinate ranges, and timing; no raw rows, host paths, XML, player/squad names, IP/network material, commands, credentials, or sockets were recorded.
  • No raw SQL, host database path, credentials, direct sockets, raw XML, raw player names, or raw IP/network identifiers are recorded here.

Resulting Gates

  • Task 2.5 schema capture is satisfied for discovery: sqlite_schema, read-only PRAGMA metadata, indexes, foreign keys, declared types, cardinalities, and redacted samples were captured for the candidate sources.
  • Task 2.6 join/meaning verification is satisfied for discovery: external identity, profile/prisoner/entity joins, flag/base joins, vehicle identity joins, bank-account joins, nullable fields, and the profile XML source candidate are recorded. Unproven rank leader semantics, squad-territory ownership, currency labels/units, and write meanings remain explicitly gated rather than guessed.
  • Tasks 2.72.8 remain open: update cadence, query latency/lock behavior under repeated reads, map transform, gift aliases/transports, command confirmation, and 855 named-attribute mapping still require explicit verification.
  • Database-backed SCUM read/write capabilities remain disabled until the corresponding versioned adapters and Run durable execution envelopes are implemented and accepted.