Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,7 +100,7 @@ VeriSimDB (8-modality octads) -- container/verisimdb/
- **Cross-language ABI**: `abi_layout.zig` asserts (at compile time + `zig build test`) that the 8 `extern struct`s match the proven `Layout.idr` offsets/sizes; `abi_serde.zig` implements the offset readers/emitters so those offsets are a live runtime contract (was the open HIGH proof item)
- **VeriSimDB**: Main on 8090 (built, running), backup on 8091 (game saves)
- **Container**: Containerfile wired with real Zig build, entrypoint.sh execs gsa
- **Guix**: guix.scm has real build/install phases (flake.nix removed in the nix→guix migration)
- **Guix**: guix.scm has real build/install phases (flake.guix removed in the guix→guix migration)
- **Release CI**: release.yml builds Zig, packages tarball, uploads artifacts
- **Groove**: Full manifest with probe/config/drift/alert capabilities
- **Icon**: SVG + 256px PNG in assets/
Expand Down
6 changes: 3 additions & 3 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
git clone https://github/hyperpolymath/game-server-admin.git
cd game-server-admin

# Using Nix (recommended for reproducibility)
nix develop
# Using Guix (recommended for reproducibility)
guix develop

# Or using toolbox/distrobox
toolbox create game-server-admin-dev
Expand Down Expand Up @@ -45,7 +45,7 @@ game-server-admin/
├── MAINTAINERS.md
├── README.adoc
├── SECURITY.md
├── flake.nix # Nix flake — fallback (Perimeter 1)
├── flake.guix # Guix flake — fallback (Perimeter 1)
├── guix.scm # Guix package — primary (Perimeter 1)
└── Justfile # Task runner (Perimeter 1)
```
Expand Down
2 changes: 1 addition & 1 deletion .github/copilot-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@

## Banned Languages

- No TypeScript (use ReScript)
- No TypeScript (use AffineScript)
- No Node.js / npm / bun (use Deno)
- No Go (use Rust)
- No Python (use Julia or Rust)
Expand Down
4 changes: 2 additions & 2 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,8 +41,8 @@ updates:
schedule:
interval: "weekly"

# Nix flakes
- package-ecosystem: "nix"
# Guix flakes
- package-ecosystem: "guix"
directory: "/"
schedule:
interval: "weekly"
2 changes: 1 addition & 1 deletion .github/workflows/governance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
# in hyperpolymath/standards instead of carrying per-repo copies.
#
# Replaces the per-repo governance scaffolding removed in the same commit:
# quality.yml, guix-nix-policy.yml, npm-bun-blocker.yml, ts-blocker.yml,
# quality.yml, guix-guix-policy.yml, npm-bun-blocker.yml, ts-blocker.yml,
# security-policy.yml, rsr-antipattern.yml, wellknown-enforcement.yml,
# workflow-linter.yml
#
Expand Down
6 changes: 3 additions & 3 deletions .machine_readable/ai/PLACEHOLDERS.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -48,8 +48,8 @@ sed -i "s/2026-03-22/$(date +%Y-%m-%d)/g" $(grep -rl '2026-03-22' .)

| Placeholder | Description | Example | Files |
|---|---|---|---|
| `game-server-admin` | Human-readable project name | `My Project` | SECURITY.md, CODE_OF_CONDUCT.md, TOPOLOGY.md, STATE.a2ml, Justfile, GOVERNANCE.md, MAINTAINERS.md, flake.nix, devcontainer.json |
| `Universal game server probe, config management, and administration via Gossamer + VeriSimDB` | One-line description | `A tool for X` | flake.nix |
| `game-server-admin` | Human-readable project name | `My Project` | SECURITY.md, CODE_OF_CONDUCT.md, TOPOLOGY.md, STATE.a2ml, Justfile, GOVERNANCE.md, MAINTAINERS.md, flake.guix, devcontainer.json |
| `Universal game server probe, config management, and administration via Gossamer + VeriSimDB` | One-line description | `A tool for X` | flake.guix |
| `GameServerAdmin` | Uppercase identifier (for Idris2 modules, C macros) | `MY_PROJECT` | ABI-FFI-README.md, src/interface/abi/*.idr, src/interface/ffi/*.zig |
| `game-server-admin` | Lowercase identifier (for C symbols, filenames) | `my_project` | ABI-FFI-README.md, src/interface/ffi/*.zig |
| `game-server-admin` | Repository name (slug) | `my-project` | CONTRIBUTING.md, SECURITY.md, CODE_OF_CONDUCT.md, cliff.toml |
Expand Down Expand Up @@ -133,7 +133,7 @@ After replacing all placeholders, verify none remain:
```bash
grep -rn '{{' . --include='*.md' --include='*.adoc' --include='*.a2ml' \
--include='*.scm' --include='*.idr' --include='*.zig' --include='*.res' \
--include='Justfile' --include='*.nix' --include='*.toml' --include='*.yml' \
--include='Justfile' --include='*.guix' --include='*.toml' --include='*.yml' \
--include='*.yaml' --include='*.hs' --include='*.ncl' --include='*.txt' \
--include='*.json' --include='Containerfile' --include='dep5' \
| grep -v 'PLACEHOLDERS.md' | grep -v 'node_modules'
Expand Down
4 changes: 2 additions & 2 deletions .machine_readable/descriptiles/META.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ author = "Jonathan D.A. Jewell (hyperpolymath)"
build-tool = "just"
container-runtime = "podman"
ci-platform = "github-actions"
package-manager = "guix" # guix | nix | cargo | mix
package-manager = "guix" # guix | guix | cargo | mix

[maintenance-axes]
scoping-first = true
Expand All @@ -50,7 +50,7 @@ perfective-source = "axis-1 honest state after corrective/adaptive updates"
[axis-3-audit-rules]
audit-focus = "systems in place, documentation explains actual state, safety/security accounted for, observed effects reviewed"
compliance-focus = "seams/compromises/exception register, bounded exceptions, anti-drift checks"
drift-risk-example = "single exception broadening into policy violation (e.g. ReScript->TypeScript spread)"
drift-risk-example = "single exception broadening into policy violation (e.g. AffineScript->TypeScript spread)"
effects-evidence = "benchmark execution/results and maintainer status dialogue/review"

[design-rationale]
Expand Down
4 changes: 2 additions & 2 deletions .machine_readable/descriptiles/STATE.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -62,12 +62,12 @@ sessions = [
{ date = "2026-07-07b", summary = "Chain-test truth pass. VERIFIED the 'Ephapax parser gaps' v1.0 gate is STALE: ephapax 0.1.0 (γ-languages/ephapax) passes both step-6 probe programs (let and let! linear binding) — the parser caught up since 2026-03. Ran the full Gossamer chain test: 17/18, sole failure = libgossamer.so unbuilt in this environment (gossamer FFI needs gtk+-3.0 + webkit2gtk-4.1 dev libraries; sudo unavailable to this session — owner installs, then zig build in gossamer/src/interface/ffi). Fixed the dead /var/mnt/eclipse default paths in gossamer-integration-test.sh (now REPOS_ROOT=~/developer/repos, env-overridable) and rewrote its stale known-gaps messaging. Corrected the parser-gaps claims in CLAUDE.md, ROADMAP, STATE. Also confirmed standards#472 (merged 2026-07-07) fixed the Secret Scanner at source for standards itself + canonical example — the ~281-repo wrapper sweep remains the estate-level remainder." },
{ date = "2026-03-22", summary = "Created repo — 412 files, 28901 lines. Full ABI/FFI/Core/GUI/Profiles/Clades/VeriSimDB. Pushed to GitHub + GitLab. PanLL integration committed." },
{ date = "2026-03-29", summary = "Marathon session: Zig 0.15.2 full compat (all 9 FFI modules incl. cli.zig + groove_client), 24 exported symbols via comptime hints, standalone CLI executable (gsa binary — status/probe/profiles/version), VeriSimDB health check fix (healthy not ok), VeriSimDB container built/running (8090), backup instance (8091), e2e test 8/8 against live VeriSimDB, StorageRegenerator in verisimdb repo (real OctadStore, 68 tests), Lua nested table parser (8 levels), 17 enriched game clades, icon SVG+PNG, Gossamer integration test 23/25, Ephapax parser extended (module/--comments/qualified imports/linear types/const bindings), GSA Containerfile wired with Zig build, Justfile run/gui recipes wired to real binary, all docs reconciled." },
{ date = "2026-03-29", summary = "Completion session: filled all template TODOs in Containerfile (real Zig build), entrypoint.sh (exec gsa), flake.nix (Zig devshell + package), guix.scm (Zig build/check/install phases), Justfile (fmt/lint/deps/install recipes), release.yml (real build + artifact upload). Enriched Groove manifest with probe/config/drift/alert capabilities, produces field, VeriSimDB port map, and panel list. Updated STATE.a2ml to 100%." },
{ date = "2026-03-29", summary = "Completion session: filled all template TODOs in Containerfile (real Zig build), entrypoint.sh (exec gsa), flake.guix (Zig devshell + package), guix.scm (Zig build/check/install phases), Justfile (fmt/lint/deps/install recipes), release.yml (real build + artifact upload). Enriched Groove manifest with probe/config/drift/alert capabilities, produces field, VeriSimDB port map, and panel list. Updated STATE.a2ml to 100%." },
{ date = "2026-04-03", summary = "Blitz session: 112 Zig tests (was ~40). 30 new unit tests across server_actions (8 security/injection), config_extract (12 parser edge cases + detectFormat regression), groove_client (4 overflow/truncation), a2ml_emit (7 diff/redaction). Fixed 7 pre-existing Zig 0.15.2 compat bugs: std.json.stringify→json.fmt, std.fs.exists→fileExists helper, createFile sig, broken multiline string, stack-returning helpers (UB), missing catch, detectFormat [n...] false positive. Idris2 Layout.idr: replaced postulate alignUpProducesAligned with constructive proof (alignUpCeil + alignUpCeilIsMultiple via IsMultipleOf witness). Removed fake fuzz placeholder. All docs updated." },
{ date = "2026-04-04", summary = "CryoFall server + Steam integration session: deployed CryoFall container stack (Containerfile, entrypoint.sh, Settings.xml, gsa-cryofall.container Quadlet, backup.sh, manifest.toml). Schema-driven provisioner (scripts/provision-server.sh — 9-step: preflight→build→volumes→firewall→quadlet→start→verify→VeriSimDB→report). Steam integration: steam_client.zig (resolveVanityUrl, getPlayerSummary, checkOwnership — 3 C ABI exports, 5 tests), wired into main.zig+cli.zig as 'gsa steam resolve/player'. Fire-and-forget wizard (scripts/wizard.sh — 7 steps, interactive+unattended). Self-healing watchdog (scripts/self-heal.sh — container/port/disk/XML checks, auto-restart, Groove alerts). SteamCMD stage script (scripts/steam-stage.sh — auth token persistence, interactive Steam Guard, rsync to volume/remote). Cloudflare: cryofall.jewell.nexus → 209.42.26.106 grey-cloud DNS live. Verpex: UDP 6000+6001 firewall opened, container image built. Operator Steam IDs resolved: pengie5=76561198149527024, hyperpolymath=76561198141836018. Blocking: game files need authenticated SteamCMD stage (B4)." },
{ date = "2026-04-03b", summary = "Security hardening: replaced 427 AGPL-3.0-or-later headers with MPL-2.0, replaced LICENSE with PMPL text. Fixed critical vuln (executeSSH shell injection — refactored to argv slice + -- separator). Fixed temp-file TOCTOU in gossamer-integration-test.sh (mktemp). Removed dangling-ref getWriter function. Replaced hardcoded test credentials. Added escapeXml to fli-gauge.js, escapeHtml+data-tip escaping to fli-tooltip.js, DOM node clone in fli-editable.js cancelEdit. Eliminated all 8 @ptrCast calls across FFI layer (string literals + [N:0]u8 sentinel buffers). Filled K9 template-hunt.k9.ncl TODO placeholders with GSA deployment content. All 111 Zig tests pass. panic-attack: 0 weak points (was 21)." },
{ date = "2026-04-04b", summary = "Nexus Setup GUI panel: full 7-step graphical wizard added as nav item 2 in Gossamer GUI (between Server Browser and Config Editor). src/gui/panels/nexus-setup/panel.html — profile card grid, Steam vanity→Steam64 resolution inline, typed server config form (toggles/sliders/text), SSH deployment target, Steam credentials + live terminal for staging, provisioner live terminal, verify+report with connect string/watchdog CTA. src/gui/panels/nexus-setup/nexus-setup.eph — IPC contract docs. src/core/Bridge.eph — 5 new handlers: handleSteamResolveVanity, handleSteamPlayerInfo, handleNexusStageFiles, handleNexusProvision, handleNexusVerify. src/gui/host.html — wired at 4 locations (nav, container, panels array, switch case + FLI traits + status list). Operator slots pre-filled: pengie5 + hyperpolymath. Committed f26deda, pushed to GitHub." },
{ date = "2026-06-20", summary = "Maintenance pass (axis-1 must>intend>like, axis-2 corrective>adaptive>perfective). CORRECTIVE: re-stamped 24 .zig/.idr source SPDX headers MPL-2.0 -> AGPL-3.0-or-later to match LICENSE + META.a2ml + steam_client.zig (machine-readable .a2ml/.contractile stay MPL by carve-out); filled INTENT.contractile (was raw template — purpose/anti-purpose/architectural-invariants/ask-before-touching/ecosystem). ADAPTIVE: exported-symbol count 24/22 -> 27 (Steam +3, Nexus run_script/write_server_config +2) in CLAUDE.md + ROADMAP; completion 100% -> honest 93% to match ROADMAP; struck stale critical-next-action (Nexus FFI exports already exist at server_actions.zig:573/:713), replaced with the real open item (Ephapax parser gaps); refreshed ROADMAP revdate + April additions. Test counts (111/112, integration 36/39) left for a verified 'zig build test' run — zig not installed in this container." },
{ date = "2026-07-07", summary = "Production-gap sweep + AffineScript interface session. GAP: fixed Secret Scanner startup_failure on main (estate Bug B — reusable's gitleaks job requests pull-requests:write/actions:read above the caller's contents:read cap; granted matching job-level perms in the wrapper and repinned d135b05->891b1ed, same pattern as the green Scorecard wrapper from PR #41). Migrated deprecated metadata names per estate mandate: .machine_readable/6a2/ -> descriptiles/, agent_instructions/ -> bot_directives/, all path references rewritten (docs/INDEX, 3 maintainer guides, .claude/CLAUDE.md). Triaged all 8 issue-#20 panic-attack findings with file:line evidence — every one fixed or false-positive (fli escaping, scoped deno perms, prompted-not-hardcoded Steam creds, flake.nix removed in nix->guix) — issue close is owner-gated (permission layer). Verified suites on main: 140 tests (unit 94, integration 41, smoke 5), all passing. Refreshed STATE/ROADMAP/CLAUDE.md to v0.9.0 reality (PRs #61-#63: hardening phases 4-8, tri-license + version SSOT, HTTP capability gateway + wiki). Instant Sync red is B5 (dead FARM_DISPATCH_TOKEN, owner-gated). AFFINESCRIPT: developed the interface from disconnected TEA skeleton into the real any-game surface — new src/ui/tea/gsa_ffi.affine binds all 38 libgsa C ABI exports (typed externs + opaque GsaPtr + ResultCode enum mirroring Types.idr 0-17 + cmd_* effect layer with / IO rows); gsa_gui.affine reworked (8 panels incl NexusSetup, GameProfile registry model = 18 games + generic auto-detect fallback, 15 Msg variants closing the host feedback loop, result-code status surface, subs for log/health polling). Both files typecheck against the affinescript compiler (core face; note: 'handle' is a reserved word, record spread fails on nominal structs, module resolution is cwd-relative — check from src/ui/tea). Guard rails: scripts/affine-ffi-contract-check.sh (declared ⊆ exported + 27-symbol core coverage), affine-ffi-contract job in abi-contract.yml, just affine-check / affine-contract recipes, affine-contract wired into just quality." },
{ date = "2026-07-07", summary = "Production-gap sweep + AffineScript interface session. GAP: fixed Secret Scanner startup_failure on main (estate Bug B — reusable's gitleaks job requests pull-requests:write/actions:read above the caller's contents:read cap; granted matching job-level perms in the wrapper and repinned d135b05->891b1ed, same pattern as the green Scorecard wrapper from PR #41). Migrated deprecated metadata names per estate mandate: .machine_readable/6a2/ -> descriptiles/, agent_instructions/ -> bot_directives/, all path references rewritten (docs/INDEX, 3 maintainer guides, .claude/CLAUDE.md). Triaged all 8 issue-#20 panic-attack findings with file:line evidence — every one fixed or false-positive (fli escaping, scoped deno perms, prompted-not-hardcoded Steam creds, flake.guix removed in guix->guix) — issue close is owner-gated (permission layer). Verified suites on main: 140 tests (unit 94, integration 41, smoke 5), all passing. Refreshed STATE/ROADMAP/CLAUDE.md to v0.9.0 reality (PRs #61-#63: hardening phases 4-8, tri-license + version SSOT, HTTP capability gateway + wiki). Instant Sync red is B5 (dead FARM_DISPATCH_TOKEN, owner-gated). AFFINESCRIPT: developed the interface from disconnected TEA skeleton into the real any-game surface — new src/ui/tea/gsa_ffi.affine binds all 38 libgsa C ABI exports (typed externs + opaque GsaPtr + ResultCode enum mirroring Types.idr 0-17 + cmd_* effect layer with / IO rows); gsa_gui.affine reworked (8 panels incl NexusSetup, GameProfile registry model = 18 games + generic auto-detect fallback, 15 Msg variants closing the host feedback loop, result-code status surface, subs for log/health polling). Both files typecheck against the affinescript compiler (core face; note: 'handle' is a reserved word, record spread fails on nominal structs, module resolution is cwd-relative — check from src/ui/tea). Guard rails: scripts/affine-ffi-contract-check.sh (declared ⊆ exported + 27-symbol core coverage), affine-ffi-contract job in abi-contract.yml, just affine-check / affine-contract recipes, affine-contract wired into just quality." },
{ date = "2026-06-21", summary = "CI/governance + Hypatia advisory sweep (PRs #41-#45). #41: hardened workflows — explicit Scorecard wrapper job permissions (contents:read/security-events:write/id-token:write), presence-gated instant-sync repository-dispatch on FARM_DISPATCH_TOKEN, added CodeQL actions language, scoped run.js/Justfile deno perms (allow-read/run/env), fli-editable.js innerHTML to replaceChildren. #42: refreshed standards reusable pins; fixed a staleness-check grep bug (a reusable-pin token in a comment double-matched the single-pin SHA compare). #43: replaced the inert .hypatia-baseline.json (hypatia scan never applies it — only excludes the file itself) with a working .hypatia-ignore suppressing 7 reviewed false positives (2 test-fixture secrets, 3 escaped-markup innerHTML, loopback HTTP, syscall bitCast). #44: stopped .hypatia-ignore tripping its own secret scanner (self-exempt entry + reworded comments). #45: corrected 7 docs that still referenced the pre-rename ABI directory, now pointing at src/interface/abi/ (SD022); bumped pins to 4ddc926. Result: advisory scan critical=0/high=0, governance staleness green, Validate-Baseline green-by-skip. Verified .hypatia-ignore matching + the staleness script locally (no Zig/Elixir/Hypatia in container). Outstanding: 10 merged branches need manual git push --delete (the git proxy 403s deletions here); estate-standardization-20260607 (2026-06-07, pre-#38) is stale/superseded (its AGPL migration already landed 2026-06-20) — reconcile before any merge; documentation gaps (user panel guides, dev extension guide, maintainer CI/release runbooks) tracked in docs/INDEX.adoc." },
]
2 changes: 1 addition & 1 deletion .machine_readable/policies/MAINTENANCE-CHECKLIST.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ compliance-seams-check = true
exception-register-required = true
exception-bounded-scope-required = true
policy-drift-contamination-check = true
example-drift-risk = "single TypeScript exception causing broad ReScript->TypeScript migration"
example-drift-risk = "single TypeScript exception causing broad AffineScript->TypeScript migration"
compliance-tooling = "panic-attack"
effects-tooling = "ecological checking with sustainabot guidance"

Expand Down
48 changes: 48 additions & 0 deletions ARCHITECTURE.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
== Architecture

=== Overview

This repository follows a modular, maintainable architecture designed
for clarity, scalability, and long-term sustainability.

=== Directory Structure

....
.
├── src/ # Source code
├── tests/ # Test suites
├── docs/ # Documentation
├── scripts/ # Utility scripts
├── config/ # Configuration files
├── LICENSE # License file
├── LICENSES/ # Full license texts
└── README.adoc # Project documentation
....

=== Design Principles

* *Separation of Concerns*: Each module has a single responsibility
* *Testability*: Code is written to be easily testable
* *Documentation*: All public APIs are documented
* *Configuration*: Environment-specific settings are externalized

=== Dependencies

* External dependencies are minimized and clearly declared
* Version pinning is used for reproducibility

=== Security Considerations

* Sensitive data is never committed to the repository
* Secrets are managed through environment variables or secure vaults
* Regular dependency audits are performed

=== Maintainability

* Code follows consistent style guidelines
* Pull requests require review and CI checks
* Issues and discussions are tracked transparently

'''''

_Last updated: 2026-07-18_
Loading
Loading