chore: drop tool-name markers from source comments
Seventeen comments opened with a tag naming the tool that wrote them. The tag goes and each comment keeps its reasoning, now starting as a plain sentence. None of the reasoning changes. The AGENTS.md note in .gitignore drops the story of how the file got into the tree and keeps the one fact a reader needs: its advice to run go fmt is destructive on this CRLF working tree. Comments only; no code, build or test changes.
This commit is contained in:
13 files changed
+19
-20
No files matched your search
+2
-3
@@ -41,9 +41,8 @@ plugins/*/bin/
|
|||||||
|
|
||||||
# ---- Local agent / loop state ----
|
# ---- Local agent / loop state ----
|
||||||
.claude/
|
.claude/
|
||||||
# Autohand-generated agent guide — kept on disk for local tooling, never tracked.
|
# Generated tooling guide, kept on disk for local use and never tracked. Its advice
|
||||||
# It rode in via 0c1cc59, claims precedence over CLAUDE.md, and tells agents to
|
# to run `go fmt` is destructive on this CRLF working tree.
|
||||||
# run `go fmt` (destructive on this CRLF working tree).
|
|
||||||
AGENTS.md
|
AGENTS.md
|
||||||
|
|
||||||
# ---- Internal planning & design docs (excluded from the public remote per
|
# ---- Internal planning & design docs (excluded from the public remote per
|
||||||
|
|||||||
+1
-1
@@ -116,7 +116,7 @@ func newBackupID() string {
|
|||||||
var b [16]byte
|
var b [16]byte
|
||||||
if _, err := rand.Read(b[:]); err != nil {
|
if _, err := rand.Read(b[:]); err != nil {
|
||||||
// crypto/rand failure is fatal and unrecoverable; a time-based fallback would
|
// crypto/rand failure is fatal and unrecoverable; a time-based fallback would
|
||||||
// be a weaker ID for no benefit. ponytail: panic is the honest failure here.
|
// be a weaker ID for no benefit. A panic is the honest failure here.
|
||||||
panic("felis backup: crypto/rand: " + err.Error())
|
panic("felis backup: crypto/rand: " + err.Error())
|
||||||
}
|
}
|
||||||
return "bk-" + hex.EncodeToString(b[:])
|
return "bk-" + hex.EncodeToString(b[:])
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ const defaultForwardingDataDir = "/data"
|
|||||||
// volume of unknown ownership; 0666/0777 then let a non-root Paper rewrite the
|
// volume of unknown ownership; 0666/0777 then let a non-root Paper rewrite the
|
||||||
// same files on boot.
|
// same files on boot.
|
||||||
//
|
//
|
||||||
// ponytail: relies on the initContainer running as root to write into a volume of
|
// This relies on the initContainer running as root to write into a volume of
|
||||||
// unknown ownership; that is how the operator schedules it. If that ever changes,
|
// unknown ownership; that is how the operator schedules it. If that ever changes,
|
||||||
// give the server pod an fsGroup so the shared volume is group-writable instead.
|
// give the server pod an fsGroup so the shared volume is group-writable instead.
|
||||||
const (
|
const (
|
||||||
|
|||||||
+1
-1
@@ -37,7 +37,7 @@ import (
|
|||||||
|
|
||||||
// nanoStubRepo satisfies api.Repo but implements only the one method handleHasJoined calls.
|
// nanoStubRepo satisfies api.Repo but implements only the one method handleHasJoined calls.
|
||||||
// The reclaim username blacklist is a felis-api/DB concern; a nano host has no Postgres, so
|
// The reclaim username blacklist is a felis-api/DB concern; a nano host has no Postgres, so
|
||||||
// nothing is barred here. ponytail: a real blacklist would need the very DB nano exists to
|
// nothing is barred here. A real blacklist would need the very DB nano exists to
|
||||||
// avoid — YAGNI until a nano host grows a reclaim store.
|
// avoid — YAGNI until a nano host grows a reclaim store.
|
||||||
type nanoStubRepo struct{ api.Repo }
|
type nanoStubRepo struct{ api.Repo }
|
||||||
|
|
||||||
|
|||||||
@@ -93,7 +93,7 @@ else
|
|||||||
echo " injects it from the <server>-rcon Secret when spec.rcon.enabled is true." >&2
|
echo " injects it from the <server>-rcon Secret when spec.rcon.enabled is true." >&2
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ponytail: rewritten whole, not merged. Paper loads this file and fills every key it does
|
# Rewritten whole, not merged. Paper loads this file and fills every key it does
|
||||||
# not find with the default, then writes the full tree back — so a proxies-only file is a
|
# not find with the default, then writes the full tree back — so a proxies-only file is a
|
||||||
# complete, stable input, and the lobby's other globals are simply always the defaults.
|
# complete, stable input, and the lobby's other globals are simply always the defaults.
|
||||||
# That is true of a system server Felis owns end to end; if admins are ever allowed to tune
|
# That is true of a system server Felis owns end to end; if admins are ever allowed to tune
|
||||||
|
|||||||
@@ -416,7 +416,7 @@ type lpPermissionView struct {
|
|||||||
// maxLPInfoPages bounds how many "permission info" pages the read projector
|
// maxLPInfoPages bounds how many "permission info" pages the read projector
|
||||||
// chases per request. LuckPerms paginates its reply, so one command shows only
|
// chases per request. LuckPerms paginates its reply, so one command shows only
|
||||||
// the first page; we follow the header's page count up to this cap.
|
// the first page; we follow the header's page count up to this cap.
|
||||||
// ponytail: 10 pages ≈ 150 entries — raise if a real user outgrows it.
|
// 10 pages ≈ 150 entries — raise if a real user outgrows it.
|
||||||
const maxLPInfoPages = 10
|
const maxLPInfoPages = 10
|
||||||
|
|
||||||
// handleAccessLuckPermsInfo is the read projector for a player's LuckPerms
|
// handleAccessLuckPermsInfo is the read projector for a player's LuckPerms
|
||||||
|
|||||||
@@ -41,7 +41,7 @@ var felisAuthNS = uuid.NewSHA1(uuid.NameSpaceURL, []byte("nano.felis.lolicon.bes
|
|||||||
|
|
||||||
// authHTTPClient calls the upstream Yggdrasil roots. The timeout bounds one login
|
// authHTTPClient calls the upstream Yggdrasil roots. The timeout bounds one login
|
||||||
// against a hung source; the resolver moves on to the next source on any failure.
|
// against a hung source; the resolver moves on to the next source on any failure.
|
||||||
// ponytail: one shared client, sequential priority scan — a third-party login costs one
|
// One shared client, sequential priority scan — a third-party login costs one
|
||||||
// wasted Mojang round-trip; add parallel fan-out only if login latency bites.
|
// wasted Mojang round-trip; add parallel fan-out only if login latency bites.
|
||||||
var authHTTPClient = &http.Client{
|
var authHTTPClient = &http.Client{
|
||||||
Timeout: 5 * time.Second,
|
Timeout: 5 * time.Second,
|
||||||
@@ -171,7 +171,7 @@ const mcUsernameMax = 16
|
|||||||
// TRUNCATED to fit rather than the rename being skipped when it would not fit — skipping is
|
// TRUNCATED to fit rather than the rename being skipped when it would not fit — skipping is
|
||||||
// what would silently hand a 14-character premium name back to the squatter.
|
// what would silently hand a 14-character premium name back to the squatter.
|
||||||
//
|
//
|
||||||
// ponytail: two players of one source whose names agree on their first mcUsernameMax-len(prefix)-1
|
// Two players of one source whose names agree on their first mcUsernameMax-len(prefix)-1
|
||||||
// characters truncate onto the same in-game name, as does a prefixed name that happens to be
|
// characters truncate onto the same in-game name, as does a prefixed name that happens to be
|
||||||
// a premium name itself. Both cost an "already connected" bounce, not an identity: the UUID
|
// a premium name itself. Both cost an "already connected" bounce, not an identity: the UUID
|
||||||
// rewrite is what keeps players apart, and it does not depend on the name at all. Add a
|
// rewrite is what keeps players apart, and it does not depend on the name at all. Add a
|
||||||
@@ -242,7 +242,7 @@ func isPremiumName(ctx context.Context, username string) bool {
|
|||||||
}
|
}
|
||||||
|
|
||||||
premiumNames.Lock()
|
premiumNames.Lock()
|
||||||
// ponytail: bounded by dropping the whole map rather than evicting LRU — entries are
|
// Bounded by dropping the whole map rather than evicting LRU — entries are
|
||||||
// only minted by players who actually authenticated somewhere, so this is a backstop
|
// only minted by players who actually authenticated somewhere, so this is a backstop
|
||||||
// against an unbounded map, not a cache policy worth tuning.
|
// against an unbounded map, not a cache policy worth tuning.
|
||||||
if len(premiumNames.m) >= premiumCacheMax {
|
if len(premiumNames.m) >= premiumCacheMax {
|
||||||
|
|||||||
@@ -180,7 +180,7 @@ type Backuper struct {
|
|||||||
// just-finished Job still inside its TTL window. ErrAlreadyExists is kept only as a
|
// just-finished Job still inside its TTL window. ErrAlreadyExists is kept only as a
|
||||||
// defensive no-op against the astronomically unlikely suffix collision.
|
// defensive no-op against the astronomically unlikely suffix collision.
|
||||||
//
|
//
|
||||||
// ponytail: unique names mean two truly simultaneous taps can schedule two backup
|
// Unique names mean two truly simultaneous taps can schedule two backup
|
||||||
// Pods; both mount the world PVC read-only so neither corrupts anything, and if they
|
// Pods; both mount the world PVC read-only so neither corrupts anything, and if they
|
||||||
// land on different nodes the RWO attach fails one cleanly. Add single-flight-on-
|
// land on different nodes the RWO attach fails one cleanly. Add single-flight-on-
|
||||||
// running only if a real double-tap storm ever shows up.
|
// running only if a real double-tap storm ever shows up.
|
||||||
@@ -200,7 +200,7 @@ func (b *Backuper) Backup(ctx context.Context, serverName, formerOwner string) e
|
|||||||
func jobNameSuffix() string {
|
func jobNameSuffix() string {
|
||||||
var b [4]byte
|
var b [4]byte
|
||||||
if _, err := rand.Read(b[:]); err != nil {
|
if _, err := rand.Read(b[:]); err != nil {
|
||||||
// ponytail: crypto/rand only fails if the OS RNG is gone — unrecoverable.
|
// crypto/rand only fails if the OS RNG is gone — unrecoverable.
|
||||||
panic("backupjob: crypto/rand: " + err.Error())
|
panic("backupjob: crypto/rand: " + err.Error())
|
||||||
}
|
}
|
||||||
return hex.EncodeToString(b[:])
|
return hex.EncodeToString(b[:])
|
||||||
|
|||||||
@@ -130,7 +130,7 @@ func (r *ExecRunner) CreateTunnel(ctx context.Context, name string) (string, str
|
|||||||
// the file (authenticating with cert.pem, keeping the same id/DNS/Access), healing
|
// the file (authenticating with cert.pem, keeping the same id/DNS/Access), healing
|
||||||
// the re-run. The secret is written to the file, not stdout.
|
// the re-run. The secret is written to the file, not stdout.
|
||||||
func (r *ExecRunner) ensureCredentials(ctx context.Context, id, credPath string) error {
|
func (r *ExecRunner) ensureCredentials(ctx context.Context, id, credPath string) error {
|
||||||
// ponytail: any existing file counts as healthy; re-fetch only on absence
|
// Any existing file counts as healthy; re-fetch only on absence
|
||||||
// (the failure actually seen). A truncated/zero-byte file would still
|
// (the failure actually seen). A truncated/zero-byte file would still
|
||||||
// crash-loop — validate the JSON here if that ever shows up.
|
// crash-loop — validate the JSON here if that ever shows up.
|
||||||
if _, err := os.Stat(credPath); err == nil {
|
if _, err := os.Stat(credPath); err == nil {
|
||||||
|
|||||||
@@ -220,7 +220,7 @@ func list(r *os.Root, path string) Result {
|
|||||||
// denied; a write is left alone because writing the file leaks nothing and is
|
// denied; a write is left alone because writing the file leaks nothing and is
|
||||||
// equally futile.
|
// equally futile.
|
||||||
//
|
//
|
||||||
// ponytail: an exact match on one cleaned path, not a pattern. This is the whole
|
// An exact match on one cleaned path, not a pattern. This is the whole
|
||||||
// known exposure — grep FELIS_FORWARDING_SECRET across deploy/ — and if another
|
// known exposure — grep FELIS_FORWARDING_SECRET across deploy/ — and if another
|
||||||
// image ever persists a platform secret into the mount, add its path here rather
|
// image ever persists a platform secret into the mount, add its path here rather
|
||||||
// than inventing a matcher.
|
// than inventing a matcher.
|
||||||
|
|||||||
@@ -114,7 +114,7 @@ func velocityJarVersion(path string) (updates.Version, error) {
|
|||||||
|
|
||||||
// manifestAttr returns one attribute value from a jar's META-INF/MANIFEST.MF.
|
// manifestAttr returns one attribute value from a jar's META-INF/MANIFEST.MF.
|
||||||
//
|
//
|
||||||
// ponytail: this does not implement the JAR spec's 72-byte line folding (a wrapped
|
// This does not implement the JAR spec's 72-byte line folding (a wrapped
|
||||||
// value continues on the next line after a single leading space). Version values are
|
// value continues on the next line after a single leading space). Version values are
|
||||||
// far short of the wrap point, so folding cannot bite here; if this ever reads a long
|
// far short of the wrap point, so folding cannot bite here; if this ever reads a long
|
||||||
// attribute, join continuation lines before splitting on ':'.
|
// attribute, join continuation lines before splitting on ':'.
|
||||||
|
|||||||
@@ -691,7 +691,7 @@ public final class FelisVelocityPlugin {
|
|||||||
StringArgumentType.getString(ctx, "server"));
|
StringArgumentType.getString(ctx, "server"));
|
||||||
return Command.SINGLE_SUCCESS;
|
return Command.SINGLE_SUCCESS;
|
||||||
})))
|
})))
|
||||||
// ponytail: Brigadier matches literals before arguments, so a player
|
// Brigadier matches literals before arguments, so a player
|
||||||
// actually named "accept"/"deny" cannot be invited by name. They can
|
// actually named "accept"/"deny" cannot be invited by name. They can
|
||||||
// still reach the server with /felis go, and renaming the subcommands
|
// still reach the server with /felis go, and renaming the subcommands
|
||||||
// would break the click handlers for a case worth less than that.
|
// would break the click handlers for a case worth less than that.
|
||||||
@@ -868,7 +868,7 @@ public final class FelisVelocityPlugin {
|
|||||||
NamedTextColor.YELLOW));
|
NamedTextColor.YELLOW));
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
// ponytail: peek-then-take is not atomic — an invite landing in that window is
|
// Peek-then-take is not atomic — an invite landing in that window is
|
||||||
// taken instead of the one just validated. "Newest wins" is already the rule the
|
// taken instead of the one just validated. "Newest wins" is already the rule the
|
||||||
// book enforces, so the outcome is one this player would have got anyway; make it
|
// book enforces, so the outcome is one this player would have got anyway; make it
|
||||||
// a computeIfPresent if invites ever arrive fast enough for anyone to notice.
|
// a computeIfPresent if invites ever arrive fast enough for anyone to notice.
|
||||||
@@ -899,7 +899,7 @@ public final class FelisVelocityPlugin {
|
|||||||
// notifyInviter closes the loop for whoever sent the invite; without it they wait on a
|
// notifyInviter closes the loop for whoever sent the invite; without it they wait on a
|
||||||
// prompt they can never see the answer to. Silently skipped if they left in the meantime.
|
// prompt they can never see the answer to. Silently skipped if they left in the meantime.
|
||||||
//
|
//
|
||||||
// ponytail: ACCEPTED means the transfer was handed to the waiting queue, which is as far
|
// ACCEPTED means the transfer was handed to the waiting queue, which is as far
|
||||||
// as this can see synchronously — a wake that fails later is reported to the guest only.
|
// as this can see synchronously — a wake that fails later is reported to the guest only.
|
||||||
private void notifyInviter(InviteBook.Invite invite, String who, Answer answer) {
|
private void notifyInviter(InviteBook.Invite invite, String who, Answer answer) {
|
||||||
proxy.getPlayer(invite.from()).ifPresent(p -> {
|
proxy.getPlayer(invite.from()).ifPresent(p -> {
|
||||||
|
|||||||
@@ -56,7 +56,7 @@ final class InviteBook {
|
|||||||
* cooldownRemaining is how long the sender must still wait, in millis, or 0 when they
|
* cooldownRemaining is how long the sender must still wait, in millis, or 0 when they
|
||||||
* may send now.
|
* may send now.
|
||||||
*
|
*
|
||||||
* <p>ponytail: one global stamp per sender, so inviting Alex also holds off inviting
|
* <p>One global stamp per sender, so inviting Alex also holds off inviting
|
||||||
* Steve. That is the shape that actually stops the spam — a per-(sender, invitee) key
|
* Steve. That is the shape that actually stops the spam — a per-(sender, invitee) key
|
||||||
* would let one sender paper every player on the proxy at once, which is the thing
|
* would let one sender paper every player on the proxy at once, which is the thing
|
||||||
* being rate-limited. Key it per pair only if a real group of players complains.
|
* being rate-limited. Key it per pair only if a real group of players complains.
|
||||||
|
|||||||
Reference in new issue
Block a user