58 KiB
1. Prompt Boundaries
- 1.1 正向提示词 (Positive prompt): Rebuild the SCUM portion of the first-party
服务器管理area around authentic current-server login events, verified current-service database facts, dedicated local records, trustworthy user/squad/map/gift management, and a preserved AI assistant. Success requires exactly five SCUM tabs, automatic player creation and synchronization, no fabricated values, and permission-checked reviewable writes. - 1.2 方向提示词 (Directional prompt): Work in
platform/,platform_web/,plugins/, and explicit browser-repository protocol contracts while coordinating a separately authorized task in the independentgit@git.npc0.com:admin343/run.gitrepository. Use/Users/tasia/Desktop/code/go/scum/scum_robotonly as a read-only behavioral reference for login ingestion and user/squad/map/gift interactions; derive schema, joins, commands, coordinates, and mutation semantics exclusively from the active bound service. Preserve durable jobs, channel isolation, plugin ownership, API/type directory boundaries, and the black-mecha/magical-girl visual system. Required evidence includes Platform/Plugins/Web and SCUM companion tests, the external Run task's own tests/commit/deployment evidence, current-service and browser acceptance,scripts/check-structure.sh, and strict OpenSpec validation. - 1.3 任务边界 (Boundary prompt): Do not add a
run/source tree to this repository; modify/Users/tasia/Desktop/code/go/scum/scum_robot; edit the independent Run repository except inside its own separately authorized/rooted task; touch unrelated roots; use an unbound repository/reference/cachedSCUM.dbas current-service evidence; trust generated/reference structs as production schema; expose raw SQL/RCON/XML/paths/credentials/sockets to browser or AI; add billing/cloud-host/agent-provider workflows; fabricate players/world facts/backups/results; create a platform-admin approval queue; or reintroduce projection, observation, audit-initiation, manual-refresh, pending-review, or Workflow product concepts. A short-lived read-only snapshot created by Run is allowed only when fenced to the active binding/database identity, timestamped, checksummed, and invalidated on source change. - 1.4 Before implementation, confirm the browser repository is on
mainand record existing dirty files; if the branch is notmainor local changes block a safe switch, stop without creating another branch or editing files.
2. Minimal Run Probe and Current-Service Evidence Gate
External Run evidence (2026-08-12)
- The separately rooted Run task implemented and pushed generic schema-probe support at
git@git.npc0.com:admin343/run.gitcommit6cb6ba3(add bounded sqlite schema probe); its focused protocol/runtime tests andgo test ./...passed. - The executor advertises
remote.run.db.sqlite.probe, accepts only package-scoped logicaldatabases/...SQLite targets, applies query-only fixed introspection plus binding/job/fence and output bounds, and returns SHA-256-fingerprinted redacted envelopes without SCUM-specific branches or raw database content. - The active binding
server-run-server-scum-1785923898033on枣庄服务器has been updated and reportsremote.run.db.sqlite.probe; the endpoint was observed online through the Platform API at2026-08-12T08:21:27Zwith 28 capabilities including the schema-probe capability. - A follow-up separately rooted Run task fixed logical SQLite data-target materialization at commit
8fe6f9b(Fix SQLite probe data target mapping); focused runtime/data-target tests andgo test ./...passed in the independent Run repository before deployment. - The fixed Run distribution
run-dist-server-scum-1785923898033-windows-amd64-1-zao-zhuang-data-target-run-fix-2026081-6988495348508259730with checksumsha256:a5ac9fe31ed0e0f595e70e3d3322f44aa81bd165183530e4be6939aff81c3016was installed on枣庄服务器, and the active endpoint advertises bothremote.run.db.sqlite.probeandremote.run.db.sqlite.query.
Server-management diagnostic evidence (2026-08-12)
-
Per operator direction, the Run install target is
枣庄服务器(FyBDIohqPhRx7Cia); personal server-management MCP inventory andtest_connectionboth succeeded for that device. -
Bounded SSH diagnostics checked only process/service/capability metadata and emitted no raw SQL, database content, credentials, SCUM rows, or database reads. The server has a Windows Run process for
server-run-server-scum-1785923898033, the current SCUM server process is running, andhttps://scum.npc0.com/healthzreturned200from the server side; per operator clarification,scum.npc0.comis the NAT entry back to the local Platform. -
Platform durable probe job
job-remote-adapter-server-scum-1785923898033-3442596095552254276was queued throughPOST /api/v1/server-instances/server-scum-1785923898033/scum/schema-probewith idempotency keyzao-zhuang-schema-probe-20260812-1632, claimed by the authenticated active Run binding, acknowledged, and executed with targetdatabases/scum-database,MaxAttempts=1, and a nonzero fencing token. -
The probe terminal result was accepted by Platform as a typed
sqlite.schema-proberesult with safe statusfailed, safe error codetarget_unavailable, result digestsha256:41624741855866ce10b3143edba66c3a6b771029256b9489a30f395885526b61, and observed time2026-08-12T08:31:45Z. This proves the Platform durable job path and active Run probe executor are wired, but it does not prove current SCUM schema compatibility. -
The first generated Run workspace contained lifecycle package assets but no
databases/scum-databaselogical database target, so current-service schema capture was initially blocked at the package/database-target mapping layer. That failure stayed closed and kept database-backed SCUM read/write gates disabled until the later Run data-target fix produced successful schema metadata. -
Follow-up bounded SSH diagnostics on
2026-08-12located exactly one activeSCUM.dbcandidate by process-relative metadata only, with no SQL execution or row reads; the live file was locked for direct hashing/copying. This supports the package-target diagnosis but is not current-service schema evidence for tasks 2.5-2.9. -
Platform/plugin contracts now declare a plugin-owned
runtimeProfiles.dataTargetssqlite snapshot target forscum-databasethat materializes todatabases/scum-databaseinside the generated Run workspace; SCUM schema-probe dispatch fails closed when that data target is absent. The later independent Run materializer fix supplied the matching generic data-target behavior required for the successful durable probe. -
Operator clarification on
2026-08-12narrowed the architecture boundary: Platform/plugin must not download or parseSCUM.db, but an operator-directed, server-local Python diagnostic on枣庄服务器is acceptable discovery evidence when it is read-only, bounded, redacted, and not treated as the product execution path. The diagnostic captured schema metadata in place and is recorded inevidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; database-backed product gates remain disabled until durable Run envelopes and versioned adapters are accepted. -
After the Run data-target fix and Platform
sourceFingerprintdecode fix, durable probe jobjob-remote-adapter-server-scum-1785923898033-7249327407638289501succeeded through the product path. Platform persisted probe statussucceeded, source fingerprintsha256:d8f3e2f5e9c8241f55b931008309a7ab5f241118a82cbd3620ddedf233e74c13, schema fingerprintsha256:ebd477d6c6ead9c34c41169af489236d762a76186d45dedd753d50f1b81e26f0, result digestsha256:ef13678df4add731c758bba157627dc8af80138a69476facd81bbe354c31d7f1,161schema objects, observed time2026-08-12T12:17:39.0088015Z, and terminal time2026-08-12T12:29:24.857542Z. -
Server-management MCP verification on
2026-08-12confirmedtest_connectionsucceeded for枣庄服务器,SCUMServer.exewas running, and the target durable probe job had0active entries and0pending-result entries in the remote Run journal after Platform accepted the typed result. The redacted evidence is stored inevidence/scum-durable-run-schema-probe-2026-08-12.md. -
Follow-up server-local read-only Python probes on
2026-08-12verified the actual current-service joins and nullable fields for external identity, profile/prisoner/entity relationships, squad members, flag/base ownership candidates, vehicle identity, bank-account balances, and XML payload candidates. The results are recorded inevidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; unproven rank leader semantics, squad-territory ownership, currency labels/units, command confirmation, and855mapping remain gated rather than guessed. -
A task 2.8 confirmation pass on
2026-08-13separately checked the SCUM live-data manifest, platform/plugin declarations, and read-onlyscum_robotreference behavior for economy commands, gift aliases/transports, map asset/transform authorization, and855. No economy command, gift catalog/transport, distributable map asset/transform, or855preset mapping is verified enough to enable; the old bridge/domain/reference declarations remain hypothesis or legacy facade material only, and the affected capabilities stay disabled until digest-referenced current-service adapter evidence exists. -
2.1 Add a release gate that keeps every database-backed SCUM read and write capability disabled until capability-specific current-service evidence matches a versioned plugin adapter; do not add production SQL or mutation assets before this group is complete.
-
2.2 Define the minimal generic schema-probe request/result contract, safe error model, binding identity, bounds, and redacted evidence DTO needed by Platform and the plugin without embedding SCUM table names or host paths in Run-facing generic code.
-
2.3 If the active binding lacks the minimal bounded query-only probe executor, create/hand off a separately authorized task rooted in the independent Run repository, wait for its tests/commit/deployment evidence, and record that evidence here; do not edit or vendor Run source from this change.
-
2.4 Use the personal server-management MCP (
list_devices,test_connection, thenssh_execonly when needed) for device inventory, connectivity checks, and bounded diagnostics. Execute product/acceptance schema probes only as Platform durable jobs through the active authenticated Run binding; an operator-directed server-local Python diagnostic may inspect the active database in place for discovery but must not become a Platform/plugin/browser data path. -
2.5 Capture
sqlite_master, applicable read-only PRAGMA metadata, indexes, foreign keys, declared types, cardinalities, and small redacted samples for candidate player, profile/entity, squad/member, vehicle, flag/base, economy, coordinate, and character-profile payload sources. -
2.6 Verify actual joins and meanings for external player identity, profiles/entities, squad ranks/leaders, flag ownership, vehicle identity, currency units/types, nullable fields, and the real table/column containing character XML; do not assume that
user_profile.template_xmlor any reference-project field exists. -
2.7 Measure coordinate ranges and update cadence, query latency, lock/busy behavior, snapshot consistency, safe timeout/row limits, and whether a verified companion position source is needed for the advertised realtime-map cadence.
-
2.8 Confirm separately which economy commands support safe confirmation, which gift item aliases/transports are real, which distributable map asset/transform is authorized, and what named attributes—if any—the operator means by the
855preset. -
2.9 Store sanitized probe evidence or an immutable referenced test artifact and derive the observed schema fingerprint/evidence matrix; do not claim final adapter compatibility until the versioned adapters and query contracts in group 3 exist.
3. Plugin SDK, Manifest, and Immutable SCUM Assets
Login-log fixture evidence (2026-08-13)
- Server-management MCP
list_devices/test_connectionconfirmed枣庄服务器(FyBDIohqPhRx7Cia) was reachable, and boundedssh_execdiagnostics observed the activeSCUMServer.exeprocess without returning host paths or raw protected values. - Recursive active-service log discovery found
30login_{date}{digits}.logfiles under the current service log root. The newest active login log fingerprint issha256:752c3ee3789fe73b80245dfcb97776db27f977c4350c3b50516278afbecb9dad, generationsha256:57b5be4818757e4d64070e5e0f026dbd471bdba189d0426a38b618423f7e1439,0bytes, last written2026-08-12T01:18:15.6090680Z; Run tailing must handle zero-byte active files and later append/rotation boundaries. - Authentic non-empty login fixtures are UTF-16LE and match
{timestamp}: '{network_redacted} {external_player_id}:{display_name}({profile_local_id})' logged {in|out} at: X={coordinate} Y={coordinate} Z={coordinate}. Sanitized fixture rows bind expectedscum.login/scum.logoutevents to serverserver-scum-1785923898033, Run bindingserver-run-server-scum-1785923898033, plugingame.scum0.1.6, pending parser keyscum-login-log-parser.pending-real-fixture-v1, parser versionpending-scum-login-log-v1, parser digestsha256:5bb528cb9f6e04d8d8b819db3a71f855569c78a5135f22a982301301ae1da50a, transport cursor(sourceIdentity, streamGeneration, sequence), and separate privacy-safe logical event identities. Evidence is stored inevidence/scum-login-log-fixtures-2026-08-13.md.
Login-log parser implementation evidence (2026-08-13)
- Added plugin-owned parser asset
assets/scum-live/login-log-parser.jsonand manifest declarations forscum.login/scum.logoutunderscumLiveData.logParsers, digest-referenced assha256:264835fb36255071fed46dd50724ec511986db901ac8056b08ddafb10f5f0056while keeping database/write capability gates disabled. - Implemented versioned companion parser
scum-login-log-parser-v1/scum-login-log-v1for UTF-16LElogin_{date}{digits}.loglines with transport cursor(sourceIdentity, streamGeneration, sequence)and a privacy-safe logical identity that excludes network material, coordinates, source identity, stream generation, and sequence. - Added focused companion tests for successful login/logout, failed login, partial, undecodable, oversized, malformed lines, rotation/copy-truncate overlap across a new generation, restart/resume acknowledgements, duplicate transport/logical delivery, out-of-order delivery, and absence of network/coordinate material in parsed event storage/fingerprints.
- Verification passed:
(cd plugins/examples/scum-server-plugin/companion && go test ./...)and(cd plugins && npm run validate:manifest).
Map asset implementation evidence (2026-08-13)
- Added plugin-owned SCUM current-service coordinate-map metadata and transform assets under
assets/scum-live/map/, digest-referenced fromscumLiveData.mapAssetsassha256:74800836553c7e4372a0747c5e9511adcee940b057194488bbf65bf164df372bandsha256:f1941109167a86818e9e71996821884aeb8bd7e863584454b891e525695ba478. - The packaged asset is explicitly limited to first-party-generated coordinate metadata and the observed current-service coordinate envelope from
evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md; no unauthorized SCUM base-map artwork is shipped, andpositions.readremains disabled until compatible evidence enables it. - Added manifest-validator checks and fixture tests for map metadata/schema compatibility, transform adapter/schema fingerprint matching, declared bounds/image consistency, known-point projection fixtures, non-finite/out-of-bounds rejection, and digest-preserving adapter incompatibility.
- Verification passed:
(cd plugins && npm test -- manifest-validation.test.ts)and(cd plugins && npm run validate:manifest).
Typed RCON and gift catalog gate evidence (2026-08-13)
- Reviewed current-service evidence in
evidence/scum-current-service-sqlite-diagnostic-2026-08-12.md: Fame/currency commands, notification-as-RCON semantics, gift aliases/transports, conclusive per-item receipts, and catalog aliases remain unverified. Therefore the production SCUM manifest continues to declare noscumLiveData.typedRconTemplates, noscumLiveData.giftCatalogs, and no digest-referenced RCON/gift assets. - Kept
economy-command.writeandgift-command.writedisabled withmissingevidence status; no command text, gift alias, starter-pack catalog, legacy hard-coded gift, or notification transport is exposed through live-data assets. - Tightened SDK/schema/validator contracts so any future SCUM typed RCON template must carry a bounded
confirmationSchemaRefin addition to payload/result schemas, contained asset paths, immutable digests, protected RCON transport, andserver.game-client.commandpermission. - Added manifest tests proving production omits unverified typed RCON templates and gift catalogs, and rejects any SCUM typed RCON declaration without a conclusive confirmation schema.
- Verification passed:
(cd plugins && npm test -- manifest-validation.test.ts).
Current-service baseline refresh (2026-08-13)
- Per operator correction, the change now stores current-service structure baselines before attempting further capability declarations.
evidence/scum-current-service-db-schema-baseline-2026-08-13.mdrecords the full161-table compact schema inventory from a server-local read-only Python diagnostic, including row counts, columns, primary-key columns, foreign-key counts, and index counts without raw rows, SQL, XML, paths, credentials, sockets, IPs, or player identities. evidence/scum-current-service-log-structure-baseline-2026-08-13.mdrecords the process-adjacent log inventory from a successful server-local diagnostic:1200log/text files across hashed directories, includinglogin_{digits}.log,admin_{digits}.log,gameplay_{digits}.log,economy_{digits}.log,chat_{digits}.log,vehicle_destruction_{digits}.log,SCUM.log, and service/runtime log families. Raw log lines and paths were not emitted or stored.evidence/scum-current-service-content-features-baseline-2026-08-13.mdrecords redacted content features from the current service: XML tag/attribute/value-shape summaries, selected DB content distributions, and log skeleton marker sets. It confirmsuser_profile.template_xmlparses asCharacterTemplatewith named character attributes andSkillentries, confirms sampledprisoner_skill.xmlvalues are not parseable XML documents, and classifiesitem_entity.xmlas item metadata rather than a profile attribute source.- A broader line-shape diagnostic confirmed coordinate-shaped and network-shaped tokens exist in multiple log families, so parser assets must stay per-file-pattern and strip network material before durable storage. The authoritative file inventory remains the successful v4 evidence file.
- Task 3.10 remains unchecked: the refreshed content-feature baseline confirms
user_profile.template_xmlis the parseable named-attribute source candidate, but it still does not prove preserving patch semantics, offline/backup/readback requirements, activation semantics, write safety, or an operator-confirmed855preset mapping.
Adapter evidence matrix and release gates (2026-08-13)
-
Matched the production SCUM live-data adapter gates to the current-service schema fingerprint
sha256:ebd477d6c6ead9c34c41169af489236d762a76186d45dedd753d50f1b81e26f0and packaged query/map asset digests. The schema-probe gate is nowenabled/compatiblebecause the product durable Run schema-probe path succeeded, while the database-backed read gates remaindisabled/missinguntil the group 4 SQLite-template terminal envelope is implemented and accepted. -
Added manifest-validator enforcement that every declared SCUM SQLite query, typed command, guarded mutation, map asset, and gift catalog must have a matching capability gate with the same adapter version, schema fingerprint where applicable, and immutable asset digest. This prevents future assets from bypassing the release gate matrix.
-
Kept unsupported or ambiguous write capabilities disabled: no typed RCON templates, no gift catalogs, no guarded XML mutations, no
855preset, and no command/readback claims were added. Squad rank/leader, vehicle ownership, territory semantics, and sub-10s map cadence remain nullable/gated instead of invented. -
Verification passed:
(cd plugins && npm test -- manifest-validation.test.ts),(cd plugins && npm run validate:manifest), and(cd platform && go test ./validator ./domain). -
3.1 Add SDK and manifest types for versioned log parsers, SQLite query assets, parameter/result schemas, capability-specific schema fingerprints, sync cadence/limits, map metadata, typed RCON templates, gift item catalogs, and guarded mutation declarations.
-
3.2 Extend plugin validation to require asset digests, contained package paths, unique template keys, bounded parameters/results, compatible adapter versions, and explicit permission bindings, and to reject raw caller-supplied SQL, RCON, XML, paths, or undeclared parameters.
-
3.3 Capture sanitized authentic login-log fixtures from the active service and bind their expected events to server, Run binding, plugin version, parser version/digest, a transport cursor
(source identity, stream generation, sequence), and a separate privacy-safe logical event identity stable across rotation overlap. -
3.4 Implement the versioned SCUM login/logout parser and tests for successful login/logout, failed login, partial/undecodable/oversized/malformed lines, copy-truncate/rotation overlap under a new generation, Run restart/resume, duplicate delivery, and out-of-order delivery while discarding IP/network material before storage or logical fingerprinting.
-
3.5 Add parameterized, read-only player identity/detail/economy/session-enrichment query assets and exact result schemas only for joins and fields proven by the probe.
-
3.6 Add parameterized squad/member, vehicle, flag/territory, and position query assets and exact result schemas, keeping ambiguous ranks, ownership, coordinates, and missing numeric values null.
-
3.7 Add query-asset tests for single SELECT/CTE or approved introspection boundaries, parameter binding, pagination/cursors, timeout/row/byte limits, schema-version matching, and rejection of DDL, mutation,
ATTACH, extension loading, write PRAGMAs, and multi-statement input. -
3.8 Package the authorized SCUM map asset, identity/version, verified world bounds, layer metadata, and coordinate transform, with fixture tests for known points, out-of-bounds/non-finite coordinates, and adapter incompatibility.
-
3.9 Declare only verified typed RCON templates for supported Fame/currency/notification/gift operations and a version-scoped gift item catalog; omit any command whose execution and confirmation semantics remain unknown.
-
3.10 Declare a guarded preserving XML mutation only after the real XML source and named attributes are proven; expose
855only as a reviewed named-attribute preset and never as a database column, generic integer field, or guessed mapping. -
3.11 Add immutable asset/digest declarations and plugin package validation; defer generated Run-package execution wiring until the complete protocol/result envelope and independent Run capability evidence in group 4 are frozen.
-
3.12 Remove SCUM Workflow/projection declarations and obsolete page/action declarations from the plugin manifest while preserving the five required pages and AI configuration assistance.
-
3.13 Match the observed fingerprint/evidence matrix against each completed adapter, add per-capability compatibility/release-gate tests, and leave every unsupported or ambiguous player/squad/vehicle/flag/position/write capability disabled.
4. Generic External Run Execution and Result Contracts
Platform probe wiring evidence (2026-08-12)
- Platform now has an internal-only
RequestSCUMSchemaProbeForSessionpath that builds a durableremote.run.db.sqlite.probejob from the SCUM plugin's manifest declaration, active runtime binding, logical target key, adapter version, and bounded probe limits; public remote-adapter and plugin-page requests for the probe capability are denied. - Run terminal results may carry
executionResult.sqliteSchemaProbe; Platform DTO/domain/validator/job-channel code validates the typed redacted envelope, job/request identity, and binding fence before persisting it on the durable job. - Generated Run packages now carry redacted autonomous lifecycle
dataTargetsentries for plugin-owned sqlite snapshots, and browser-facing runtime-profile responses continue to omit those source declarations. - Focused evidence:
go test ./dto ./service -run 'Test(RunJobResultRequestParsesSQLiteSchemaProbeEnvelope|SCUMSchemaProbeDispatchIsPlatformScheduledAndFenced|RemoteAdapterRequestPropagatesTypedInputsToRunJob)'and(cd platform && go test ./...)passed locally. These tests did not prove the active Windows Run deployment or current SCUM schema, so the later current-service and external-Run acceptance tasks stayed gated until additional evidence was recorded.
SQLite-template contract freeze and Run handoff evidence (2026-08-13)
- Platform protocol docs now freeze the read-only
sqliteTemplaterequest andsqlite.template-queryterminal envelope: template key, logical target key, adapter/schema fingerprint, asset digest, parameter digest, bounded scalar parameters, query-only execution limits, row/result-byte limits, cancellation, and stable safe status/error codes. - Added Platform domain/DTO/job-channel/validator/service contracts for
SCUMSQLiteTemplateRequestandSCUMSQLiteTemplateResult. Run assignments can carry only the typed template request, Run results can return only the typed envelope, and Platform verifies leased job identity, binding, capability, target/template key, schema fingerprint, asset digest, parameter digest, row count, and result digest before accepting a successful result. - Added focused tests for DTO parsing, safe validator rejection of raw SQL/path-like material and loose bounds, typed row/result validation, service lease fencing, and digest mismatch rejection. Verification passed:
go test ./dto ./validator ./service -run 'Test(RunJobResultRequestParsesSQLite|ValidateSCUMSQLiteTemplate|CoreServiceRunJobSQLiteTemplateEnvelopeIsFencedToLease)'. - Recorded the separately rooted Run handoff prompt in
evidence/run-sqlite-template-execution-handoff-2026-08-13.mdwith positive, directional, and boundary prompts. This is a contract handoff only; tasks 4.7, 4.9, and DB-backed read gates remain unchecked until tested Run commit/deployment/terminal-envelope evidence is recorded.
Typed RCON-template contract freeze and Run handoff evidence (2026-08-13)
- Platform protocol docs now freeze the generic
rconTemplaterequest andrcon.template-commandterminal envelope: logical transport/target/template keys, adapter/schema fingerprint when required, asset digest, payload digest, confirmation digest, target identity digest, idempotency key, bounded scalar payload, safe review reason, response/confirmation limits, conclusive confirmation status, and stable safe result/error codes. - Added Platform domain/DTO/job-channel/validator/service contracts for
SCUMTypedRCONTemplateRequestandSCUMTypedRCONTemplateResult. Run assignments can carry only the typed template request, not browser command text; Run results can return only safe digests/status/summary; Platform verifies leased job identity, binding, transport, template, schema, asset, payload, confirmation, and target digests before accepting success. - Added focused tests for DTO parsing, validator rejection of raw command-like payload keys, unsafe review reasons, loose bounds, unconfirmed success, unsafe summaries, service lease fencing, and payload digest mismatch rejection. Verification passed:
go test ./dto ./validator ./service -run 'Test(RunJobResultRequestParses(SQLite|TypedRCON)|ValidateSCUM(SQLiteTemplate|TypedRCON)|CoreServiceRunJob(SQLiteTemplate|TypedRCONTemplate)EnvelopeIsFencedToLease)'. - Recorded the separately rooted Run handoff prompt in
evidence/run-typed-rcon-template-execution-handoff-2026-08-13.mdwith positive, directional, and boundary prompts. This is a contract handoff only; typed RCON templates, gift catalogs, write gates, and task 4.7 remain unchecked until tested Run commit/deployment/current-service command/readback evidence is recorded.
Guarded SQLite/XML mutation contract freeze and Run handoff evidence (2026-08-13)
- Platform protocol docs now freeze the generic
guardedMutationrequest andsqlite.guarded-mutationterminal envelope: logical target/template key, adapter/schema fingerprint, asset digest, target identity digest, expected row/value/XML digests, preserving patch digest, backup/offline/danger-confirmation evidence digests, readback expectation digest, idempotency key, bounded scalar payload, safe review reason, single-row limit, affected-row count, readback status, and stable safe result/error codes. - Added Platform domain/DTO/job-channel/validator/service contracts for
SCUMGuardedMutationRequestandSCUMGuardedMutationResult. Run assignments can carry only the typed guarded mutation request, not raw SQL/XML/browser mutation text; Run results can return only safe digests/status/summary; Platform verifies leased job identity, binding, template, schema, asset, target, guard, patch, backup, offline, danger confirmation, and readback digests before accepting success. - Added focused tests for DTO parsing, validator rejection of raw XML/SQL/path-like material,
855field payloads, missing backup/offline/danger-confirmation/readback digests, loose affected-row bounds, unsafe summaries, multi-row success, missing readback, service lease fencing, and patch digest mismatch rejection. Verification passed:go test ./dto ./validator ./service -run 'Test(RunJobResultRequestParses(SQLite|TypedRCON|GuardedMutation)|ValidateSCUM(SQLiteTemplate|TypedRCON|GuardedMutation)|CoreServiceRunJob(SQLiteTemplate|TypedRCONTemplate|GuardedMutation)EnvelopeIsFencedToLease)'. - Recorded the separately rooted Run handoff prompt in
evidence/run-guarded-sqlite-xml-mutation-handoff-2026-08-13.mdwith positive, directional, and boundary prompts. This is a contract handoff only; no guarded XML mutation asset,855preset, write gate, external Run implementation evidence, or real-service mutation acceptance is enabled by this task. - Session verification also passed:
(cd platform && go test ./...),scripts/check-structure.sh,openspec validate replace-scum-projections-with-real-data-management --strict, andgit diff --check.
Log-source tailing contract freeze and Run handoff evidence (2026-08-13)
- Platform protocol docs now freeze the generic
log.parsed-eventsterminal envelope for plugin-declared log-source tailing/backfill: leased source/stream key, parser key/version, adapter version, parser asset digest, parser digest, first/last redacted source identity and stream-generation cursors, event count, tail state, replay/partial flags, logical event digests, payload digests, safe summaries, safe errors, and applied limits. - Added Platform domain/DTO/job-channel/validator/service contracts for
SCUMParsedLogBatchResult, parsed events/cursors, batch bounds, and log-tail states. Run results can carry only sanitized scalar event payloads, not raw log lines, paths, globs, IP/network identifiers, SQL, XML, sockets, credentials, or unredacted player identities. - Service job completion accepts
log.parsed-eventsonly forlogs.backfilljobs carrying a leased declaredfile.tailsource, checks server/Run endpoint, source/stream key, plugin id/version when frozen, parser key/version/digest/adapter version when frozen, and single source identity/generation boundaries. - Added focused tests for DTO parsing, validator rejection of raw-line/network/path material, loose max-line bounds, missing parser digest, service lease fencing, and parser digest mismatch rejection. Verification passed:
go test ./dto ./validator ./service -run 'Test(RunJobResultRequestParses(SQLite|TypedRCON|GuardedMutation|ParsedLog)|ValidateSCUM(SQLiteTemplate|TypedRCON|GuardedMutation|ParsedLog)|CoreServiceRunJob(SQLiteTemplate|TypedRCONTemplate|GuardedMutation|ParsedLogBatch)EnvelopeIsFencedToLease)'. - Recorded the separately rooted Run handoff prompt in
evidence/run-log-source-tailing-handoff-2026-08-13.mdwith positive, directional, and boundary prompts. This is a contract handoff only; no external Run implementation evidence, parsed-login ingestion enablement, or player/session creation acceptance is enabled by this task.
Run acceptance audit and Platform capability negotiation (2026-08-13)
-
Re-audited the browser evidence files, ignored independent Run checkout, and
枣庄服务器through server-management MCP. The audit found only the prior schema-probe/data-target Run commits and redacted current-service probe evidence; it found no independent Run implementation/deployment/acceptance evidence for generic SQLite-template execution, typed RCON-template execution, guarded SQLite/XML mutation execution, parsed log-source tailing, or their late/duplicate terminal-result behavior. The audit is recorded inevidence/scum-capability-negotiation-and-run-acceptance-audit-2026-08-13.md, and task 4.7 remains unchecked. -
Added Platform-side read-only SCUM capability negotiation at
GET /api/v1/server-instances/{id}/scum/capabilities. It evaluates each manifest gate independently for the active server/plugin/Run endpoint/runtime binding using the bound Run capability list and latest accepted typed terminal evidence for matching binding, adapter, schema fingerprint, database identity, and asset digests. -
The negotiation route returns only safe capability state and reasons, dispatches no Run job, and does not expose terminal rows, SQL, XML, RCON text, host paths, DSNs, sockets, credentials, protected payloads, or raw current-service content.
-
Verification passed:
go test ./domain ./dto ./service ./api -run 'TestSCUMCapabilityNegotiation|TestSCUMSchemaProbeEndpointQueuesPlatformScheduledDurableJob|TestLegacySCUMEndpointsReturnNotFoundWithoutDispatchingJobs'. -
4.1 Add Platform protocol contracts under
platform/protocol, API DTOs underplatform/dto, validation underplatform/validator, and plugin contracts/assets underplugins/sdkandplugins/schemas, plus contract documentation/mocks for probes, read-only template execution, typed RCON, guarded SQLite/XML mutation, parsed log events, and terminal result envelopes. -
4.2 Freeze the generic executor/result contract and hand off a separately authorized Run-repository task for packaged SQLite-template execution with query-only connections, bound parameters, one-statement validation, short busy/operation timeouts, cancellation, and row/result-byte limits.
-
4.3 Require the independent Run task to return typed envelopes containing server/plugin binding, adapter/schema version, template key, asset digest, job identity, observed time, checksum, rows or affected-row count, and stable safe result/error codes.
-
4.4 Require the independent Run task to implement generic plugin-owned typed RCON-template execution without accepting browser command text or adding branches for SCUM, SCUM keys, SCUM commands, or SCUM tables.
-
4.5 Require the independent Run task to implement generic guarded single-row SQLite/XML mutation execution with expected identity/value/checksum guards, a bounded transaction, preserving XML patching, rollback on zero/multiple affected rows, and read-after-write confirmation.
-
4.6 Require the independent Run task to implement or extend generic plugin-declared log-source tailing so cursor persistence, rotation, truncate, restart, partial-line buffering, parser digest fencing, logical event fingerprinting, and replay remain independent of SCUM-specific source paths.
-
4.7 Verify from the independent Run task's acceptance evidence that control/job/log/artifact priorities, leases, fencing, acknowledgements, idempotency, and late/duplicate terminal-result handling remain intact for the new generic capabilities.
-
4.8 Add Platform-side capability negotiation so probe, player/squad/vehicle/flag/position reads, typed commands, gifts, and guarded mutations are gated independently for each active Run/plugin/adapter binding.
-
4.9 After the external Run contract tests/commit/deployment evidence is available, wire immutable assets and digests into generated Run packages and add distribution/contract tests proving Platform sends only template keys, bounded parameters, adapter version, and expected digest.
5. Dedicated Platform SCUM Persistence
- 5.1 Define SCUM domain types and narrow repository/service interfaces in the required
platform/directories, keeping API DTOs, database models, validation, and repository contracts separate. - 5.2 Add dedicated player, session, player-detail, source-event, sync-cursor, capability-evidence, and completed-generation records with server-scoped identities and nullable unknown fields.
- 5.3 Add dedicated squad, squad-member, vehicle, flag/territory, and current-position records with source checksum/time, adapter version, generation, and server-scoped indexes.
- 5.4 Add dedicated gift-package, gift-item, frozen-delivery, per-item receipt, eligibility-period reservation, notification-result, and immutable completed-delivery records.
- 5.5 Implement normalized MySQL models and explicit migrations with uniqueness constraints for player/event/session identity, generation rows, gift idempotency, and concurrent eligibility reservations.
- 5.6 Implement the default file-backend SCUM store as a platform-owned SQLite sidecar under the configured data directory, with pinned driver/migration behavior and no high-frequency writes to the global metadata snapshot.
- 5.7 Implement the memory backend with the same server isolation, uniqueness, transaction, null, generation, and idempotency semantics for tests.
- 5.8 Implement transactional generation commits so a complete validated scan may mark missing rows absent, while partial/failed/older scans preserve the last completed generation unchanged.
- 5.9 Add health, migration, rollback/disable, and database-instance invalidation behavior; never migrate old projection/Workflow snapshot values into the new tables as game facts.
- 5.10 Add backend-parity tests for migrations, uniqueness, concurrent first login, nullable numeric values, failed-generation retention, server isolation, and gift reservation/idempotency constraints.
6. Authentic Login Ingestion and Automatic Synchronization
- 6.1 Add a typed parsed-log event ingress that authenticates and correlates server binding, plugin/adapter/parser digest, transport cursor
(source identity, stream generation, sequence), separate stable logical event identity, and occurrence time before calling SCUM ingestion. - 6.2 Atomically upsert one
(server_instance_id, external_player_id)player and open one session for an authentic successful login without waiting for database enrichment. - 6.3 Close only the matching current session on logout, do not fabricate a session for an unmatched logout, and prevent older logout/login events from regressing a newer display name, last-seen time, or online session.
- 6.4 Close or mark sessions unknown with a bounded reason when a binding/source epoch is replaced, server stops, or log continuity is lost without a logout; never leave them permanently confirmed online from database save timestamps.
- 6.5 Strip raw IP addresses and all network identifiers before durable player/session/event storage and exclude them from every SCUM API, diagnostic, and AI context.
- 6.6 Add ingestion tests for concurrent first login, replayed events, duplicate/out-of-order events, failed login, unmatched logout, partial-line resume, copy-truncate/rotation overlap replay under a new generation, Run restart, parser-digest mismatch, cross-server events, and database timestamps that must not imply online state; an overlapped logical login SHALL still produce one player/session.
- 6.7 Add an automatic scheduler that starts a capability-specific probe when an active binding lacks current evidence, starts an initial bounded scan after compatibility succeeds, then uses plugin-declared jittered cadences, backoff, and per-server/per-capability concurrency limits.
- 6.8 Schedule bounded player-detail enrichment after a new login without delaying player creation, and use the measured safe position cadence or a declared verified companion source without fabricated intermediate motion.
- 6.9 Create every durable Run job before dispatch and attach the expected server/plugin/template/digest/schema/generation correlation needed for immediate, late, and duplicate results.
- 6.10 Add a terminal-job hook that validates the full result envelope and row schema before calling the matching transactional SCUM sync service.
- 6.11 Reject malformed, foreign, duplicate, or older results idempotently; commit only complete generations and retain prior rows plus a safe connection/sync error after locks, timeouts, partial results, or incompatible schemas.
- 6.12 Publish safe player/session/squad/map updates through a platform-owned event stream/SSE while keeping Platform Web reads backed by local records.
- 6.13 Add tests proving page opens/retries never create schema probes, Run queries, projection refreshes, real-data refreshes, manual syncs, or audit jobs.
7. Player Management APIs
- 7.1 Add safe player-list/detail/session DTOs, request schemas, validators, API clients/contracts, and routes in their fixed directories without exposing raw logs, database rows, XML, SQL, paths, or network material.
- 7.2 Implement server-side player pagination, bounded name/external-ID search, online and squad filters, deterministic allowlisted sorting, and total/page metadata against the local SCUM store.
- 7.3 Implement player detail with identity, verified nullable facts, current verified coordinate, bounded login history, source collection times, and explicit not-yet-synchronized/confirmed-empty/incompatible/connection-failed states.
- 7.4 Enforce target-server read authorization before lookup and prevent cross-server player IDs, squad filters, selectors, counts, or existence from leaking.
- 7.5 Preserve unknown values as null/absent throughout storage, service, DTO, and JSON handling; never substitute zero, sample data, guessed profile IDs, or database save time as online evidence.
- 7.6 Remove player-intelligence, alias-history, shared-IP, access-attempt, automatic-risk, security-signal, and hard-coded increment dependencies from the SCUM player API and ingestion flow.
- 7.7 Add repository/service/API tests for search/filter/sort bounds, pagination stability, confirmed-empty versus unavailable data, nullable facts, login history, authorization, cross-server isolation, and absence of manual-refresh endpoints.
8. Squad Management and Realtime Map APIs
- 8.1 Implement server-scoped paginated/searchable/sortable squad list and detail APIs with verified members, adapter-declared rank meanings, leader when proven, flags/territory, and ordinary collection times.
- 8.2 Keep leader, rank, territory, and ownership unknown when joins or enum meanings are ambiguous, gate squad/member/flag/territory resources independently, and test that reference constants or proximity/history heuristics are not evidence.
- 8.3 Implement bounded local vehicle and flag APIs containing only verified identity, class/status, coordinate, ownership, and collection fields supported by each active adapter capability.
- 8.4 Implement a safe current-map dataset API for players, vehicles, flags, squads/territories, layer filters, and source collection times without returning database or Run connection material.
- 8.5 Apply the plugin-declared map version/bounds/coordinate transform server-side or through a shared tested contract, rejecting incompatible, non-finite, and out-of-bounds coordinates instead of generating fallback points.
- 8.6 Publish newer verified position/map updates through the platform event stream with entity identity and server/version fencing; page subscriptions must not dispatch Run reads.
- 8.7 Enforce server authorization, bounded selectors/result sizes, and no cross-server existence leaks across all squad/map endpoints.
- 8.8 Add service/API tests for successful and failed generations, per-resource gating, unknown ownership/ranks, last-complete rows after interruption, transform fixtures, layer filtering, event ordering, and incompatible-map unavailable results.
9. Gift Management, Eligibility, and Delivery
- 9.1 Add server/plugin-version-scoped gift package and typed item validators for names, classification, active state, quantities, eligibility rules, period limits, and only plugin-catalogued item keys.
- 9.2 Implement
server.game-client.readpackage/history reads,server.game-client.maintenancepackage create/update/enable/delete, andserver.game-client.commandreviewed delivery APIs using the current session's effective target-server permissions. - 9.3 Evaluate per-player/server/period eligibility in the server's declared timezone and reserve limit capacity transactionally for in-flight, partial, and unknown deliveries so concurrent requests cannot exceed the configured limit.
- 9.4 Freeze target player, package/items, quantities, plugin/game/adapter version, period reservation, delivery identity, and idempotency key before dispatch; later package edits must not alter a delivery.
- 9.5 Dispatch only plugin-declared typed item aliases and quantities through the controlled command path, never arbitrary browser command strings.
- 9.6 Treat queued, claimed, acknowledged, or started jobs as in progress; record
deliveredonly after a schema-valid conclusive receipt for every required item. - 9.7 Preserve reservations and per-item receipts for timed-out, missing, partial, or unknown outcomes, require confirmation before an explicit retry, and never automatically redeliver the whole package or already confirmed items.
- 9.8 Release a period reservation only after conclusive evidence that no game effect occurred; record post-delivery notification failure separately without changing the delivered fact or triggering redelivery.
- 9.9 Add server-scoped package statistics, searchable/filterable pagination, real player selection, reviewed send requests, and ordinary delivery-history/result APIs without Workflow or audit terminology.
- 9.10 Add concurrency, idempotency, timezone-boundary, cross-server, catalog-version, partial/unknown outcome, reservation-release, notification-failure, permission, and immutable-history tests.
10. Controlled Manual and AI/Agent Writes
- 10.1 Define one named-field write draft containing server/player/action/field, verified current value/checksum, proposed value, reason, adapter/digest, idempotency key, safety requirements, and a safe reviewable diff.
- 10.2 Authorize the current user's effective target-server permission when a draft is created, reviewed, confirmed, and dispatched, with backend checks authoritative and no component-principal, manifest-declaration, or callback-presence bypass.
- 10.3 Supply the plugin page host with the current session's effective permissions and readable denial reasons while keeping direct API denial authoritative.
- 10.4 Route verified Fame/cash/gold writes through plugin-owned typed RCON templates with
server.game-client.command, validated absolute target values, explicit reason, idempotency, and declared confirmation reads. - 10.5 Route database/XML writes only with effective
server.game-client.maintenance, verified target/offline or maintenance state when required, genuine same-instance restorable backup evidence, expected before values/checksum, and an explicit dangerous-operation confirmation; do not create a platform-admin approval workflow or approval queue. - 10.6 Execute preserving named-attribute XML patches only against the probe-confirmed source, reject malformed XML or absent/undeclared nodes, preserve unknown content, and update exactly one guarded row.
- 10.7 Keep
855absent until its named mapping is confirmed; when available, expand it into an explicit per-attribute before/after review rather than acceptingfieldKey=855,prisoner.value, or a generic integer. - 10.8 Validate command/mutation terminal envelopes and readback before success, update local verified details only after conclusive confirmation, and represent missing/mismatched results as failed, conflict, or unknown without automatic retry.
- 10.9 Never chain kill, death, respawn, kick, or another destructive activation to attribute save; any verified required activation must be a separate explicitly named, permission-checked, confirmed action.
- 10.10 Preserve AI-assisted plugin configuration through the existing platform-mediated reviewable config-diff path without exposing provider keys or granting the plugin page direct write authority.
- 10.11 Make AI/Agent player-operation suggestions create the exact same named-field draft as manual forms, reject undeclared fields/protected payloads, retain the initiating user, and require that user's current effective permission plus explicit confirmation.
- 10.12 Add tests for read-only users, revoked permissions between draft and dispatch, cross-server targets, invented AI fields, stale checksums, fake backup evidence, unsafe online state, zero/multiple rows, malformed XML, missing nodes, unknown results, confirmation mismatch, duplicate requests, and no approval-queue creation.
11. Five-Tab SCUM Product Surface
- 11.1 Place SCUM API clients/types, route definitions, page contracts, component contracts, schemas/validators, bridge/SDK types, and shared utilities in their fixed frontend/plugin directories rather than inside page components.
- 11.2 Make the SCUM detail navigation contain exactly
用户管理,队伍管理,实时地图,礼包管理,AI 助手in that order, default to用户管理, and fall back from legacymanage,workflows, or invalid sections without affecting non-SCUM plugins. - 11.3 Preserve the existing server-list deployment action and relocate display-name and administrator-membership controls to a compact detail-header settings drawer/dialog with existing owner authorization; do not add another permanent management tab.
- 11.4 Build
用户管理as a full-width server-paginated table with bounded filters/search/sort, online evidence, nullable verified facts, detail/login-history drawer, and explicit named-field edit dialogs. - 11.5 Build
队伍管理as a full-width paginated squad table and semantic detail drawer separating leader/ranks, members, flags, and territory while showing unknown facts honestly. - 11.6 Build
实时地图from the authorized map asset and tested transform with distinct player/vehicle/flag/territory layers, filters, legend, source coordinates/collection time, safe live updates, and a clear incompatible/unavailable state. - 11.7 Build
礼包管理with real package statistics/table, CRUD dialogs, typed items and limits, real player selection, reviewed delivery, and delivery history for in-progress/delivered/failed/partial/unknown/notification-failure outcomes. - 11.8 Keep
AI 助手as the final tab for plugin configuration diffs and controlled player-operation drafts, with apply disabled when effective permission is absent. - 11.9 Hide or disable write controls according to current effective permissions with textual reasons, and re-check authorization server-side on every apply request.
- 11.10 Load only platform-local resource APIs and the platform event stream; display ordinary connection and last synchronized/collected information, and let retry repeat only a local read.
- 11.11 Reuse shared tables, drawers, dialogs, status,
console-*, and theme tokens; preserve black-mecha and magical-girl readability, keep CSS declarations compressed, and add no page-local fixed decoration or generic opaque SaaS card system. - 11.12 Cover keyboard/focus behavior, non-color-only status, responsive full-width working surfaces, bounded compact actions, and readable destructive confirmations.
- 11.13 Add frontend tests for exact navigation/order/default/fallback, settings ownership, local-only loading, permission presentation, null/empty/error states, real map/gift data, AI review parity, and absence of fake actions or placeholder records.
12. Projection, Workflow, Intelligence, and Placeholder Removal
- 12.1 Inventory references before deletion and distinguish SCUM-only projection/Workflow/player-intelligence code from generic durable Run jobs, internal write evidence, and non-SCUM consumers.
- 12.2 Remove SCUM Workflow instance/step/status APIs, repositories, services, routes, clients, manifest declarations, page components, workflow creation/listing, pending-review counters, operation approval routes, and approval/confirmation queue surfaces without removing generic Run job execution.
- 12.3 Remove SCUM projection/observation/freshness snapshot types, ingestion, metadata fields, refresh/audit services, page actions, and manual synchronization endpoints; removed endpoints must return not found or a stable removal response and dispatch no job.
- 12.4 Remove SCUM dependencies on alias history, shared IP/fingerprint, access attempts, automatic risk/security signals, and player intelligence; delete shared implementation only after proving it has no remaining non-SCUM consumer.
- 12.5 Remove the standalone
管理andWorkflow 状态tabs, legacy placeholders/routes, fake maintenance/backup evidence, hard-coded increments, opaque855action, hard-codedstarter-pack, fixed notification, gradient-only map, arbitrary percentage points, and sample/generated players/world data. - 12.6 Remove runtime product copy including
Workflow 状态,投影,真实投影,玩家投影,刷新投影,刷新世界投影,刷新真实数据,发起审计,创建发放 workflow,typed workflow,typed observation,typed operation,待审操作,审批/确认队列,清理旧入口,目前暂无真实投影数据,暂无真实投影数据,暂无玩家投影, andCompanion 可用. - 12.7 Add upgrade behavior that starts the new SCUM stores empty, populates only from post-upgrade authenticated logs/current-service sync, invalidates incompatible bindings, and never translates old snapshot values into real facts.
- 12.8 Add a rollback/feature-disable path that disables incompatible SCUM reads/writes while leaving diagnostic local records intact and never re-enables fake projection or Workflow data.
- 12.9 Add scoped runtime-source/manifest/API tests or assertions proving banned copy/actions/routes are absent, removed endpoints cannot dispatch jobs, and generic lifecycle, logs, jobs, AI provider management, and non-SCUM plugin navigation still work.
- 12.10 Record the supersession mapping from the completed-but-unarchived legacy SCUM changes to these unique replacement capabilities; do not archive obsolete deltas into the main baseline, and leave any history consolidation to a separate reviewed skip-specs/equivalent archival task.
13. End-to-End Verification and Release
- 13.1 Run focused Go tests after each Platform repository, migration, ingestion, scheduler, API, gift, permission, and terminal-result change, then run
(cd platform && go test ./...). - 13.2 Run plugin SDK/parser/query/map/manifest tests and final checks with
(cd plugins && npm run typecheck && npm run test && npm run validate:manifest), then run(cd plugins/examples/scum-server-plugin/companion && go test ./...). - 13.3 Run frontend tests and final checks with
(cd platform_web && npm run typecheck && npm run test && npm run build). - 13.4 In the separately authorized Run-repository task, run
go test ./...from that repository's own root and record its tested commit/version plus deployment compatibility evidence here; do not edit, stage, or commit Run source from the browser-repository apply task. - 13.5 Against the active current service, verify read-only schema compatibility, authentic login-created local player/session data, automatic player/squad/vehicle/flag/position sync, generation retention after an induced safe read failure, and no unbound copied/cache/fixture database use.
- 13.6 Verify login-log acceptance with sanitized real fixtures covering partial lines, failed login, rotation, truncate, restart/resume, duplicate, and out-of-order events plus server/Run binding/plugin/parser-digest fencing.
- 13.7 Extend and run
scripts/browser-acceptance.shagainst synchronized local data for the exact five tabs, local-only page reads, user/squad/map/gift behavior, permission-aware edit reviews, AI configuration/player drafts, legacy-route fallback, and absence of projection/Workflow/manual-refresh/audit controls. - 13.8 Verify controlled writes against isolated test data or an explicitly authorized test player only; prove permission, explicit confirmation, guards, backup/offline requirements, idempotency, readback, unknown-result handling, XML preservation, and no implicit respawn.
- 13.9 Perform scoped security checks proving browser/API/AI/job-safe responses contain no raw SQL, RCON, XML, host/database paths, credentials, sockets, IP data, or cross-server resource existence, and that external Run has no SCUM-specific executor branches.
- 13.10 Run
scripts/check-structure.shand fix every relevant structural violation without moving implementation outside its owning root. - 13.11 Run
openspec validate replace-scum-projections-with-real-data-management --strict, review task evidence and the final diff, and leave any task unchecked if its real-service, external-Run, test, or safety evidence is missing. - 13.12 On
main, stage only files belonging to this change, create a concise commit after all required verification succeeds, and push the configured remote without including unrelated pre-existing worktree changes.