chore: drop tool-name markers from source comments

Seventeen comments opened with a tag naming the tool that wrote them.
The tag goes and each comment keeps its reasoning, now starting as a
plain sentence. None of the reasoning changes.

The AGENTS.md note in .gitignore drops the story of how the file got
into the tree and keeps the one fact a reader needs: its advice to run
go fmt is destructive on this CRLF working tree.

Comments only; no code, build or test changes.
This commit is contained in:
flyemoji committed 2026-09-22 12:57:19 +09:00
1 parent 4e98ae6e56
commit 2180e77cf5
13 files changed
+19 -20

No files matched your search

+2 -3
View File
@@ -41,9 +41,8 @@ plugins/*/bin/
# ---- Local agent / loop state ----
.claude/
# Autohand-generated agent guide — kept on disk for local tooling, never tracked.
# It rode in via 0c1cc59, claims precedence over CLAUDE.md, and tells agents to
# run `go fmt` (destructive on this CRLF working tree).
# Generated tooling guide, kept on disk for local use and never tracked. Its advice
# to run `go fmt` is destructive on this CRLF working tree.
AGENTS.md
# ---- Internal planning & design docs (excluded from the public remote per
+1 -1
View File
@@ -116,7 +116,7 @@ func newBackupID() string {
var b [16]byte
if _, err := rand.Read(b[:]); err != nil {
// crypto/rand failure is fatal and unrecoverable; a time-based fallback would
// be a weaker ID for no benefit. ponytail: panic is the honest failure here.
// be a weaker ID for no benefit. A panic is the honest failure here.
panic("felis backup: crypto/rand: " + err.Error())
}
return "bk-" + hex.EncodeToString(b[:])
+1 -1
View File
@@ -26,7 +26,7 @@ const defaultForwardingDataDir = "/data"
// volume of unknown ownership; 0666/0777 then let a non-root Paper rewrite the
// same files on boot.
//
// ponytail: relies on the initContainer running as root to write into a volume of
// This relies on the initContainer running as root to write into a volume of
// unknown ownership; that is how the operator schedules it. If that ever changes,
// give the server pod an fsGroup so the shared volume is group-writable instead.
const (
+1 -1
View File
@@ -37,7 +37,7 @@ import (
// nanoStubRepo satisfies api.Repo but implements only the one method handleHasJoined calls.
// The reclaim username blacklist is a felis-api/DB concern; a nano host has no Postgres, so
// nothing is barred here. ponytail: a real blacklist would need the very DB nano exists to
// nothing is barred here. A real blacklist would need the very DB nano exists to
// avoid — YAGNI until a nano host grows a reclaim store.
type nanoStubRepo struct{ api.Repo }
+1 -1
View File
@@ -93,7 +93,7 @@ else
echo " injects it from the <server>-rcon Secret when spec.rcon.enabled is true." >&2
fi
# ponytail: rewritten whole, not merged. Paper loads this file and fills every key it does
# Rewritten whole, not merged. Paper loads this file and fills every key it does
# not find with the default, then writes the full tree back — so a proxies-only file is a
# complete, stable input, and the lobby's other globals are simply always the defaults.
# That is true of a system server Felis owns end to end; if admins are ever allowed to tune
+1 -1
View File
@@ -416,7 +416,7 @@ type lpPermissionView struct {
// maxLPInfoPages bounds how many "permission info" pages the read projector
// chases per request. LuckPerms paginates its reply, so one command shows only
// the first page; we follow the header's page count up to this cap.
// ponytail: 10 pages ≈ 150 entries — raise if a real user outgrows it.
// 10 pages ≈ 150 entries — raise if a real user outgrows it.
const maxLPInfoPages = 10
// handleAccessLuckPermsInfo is the read projector for a player's LuckPerms
+3 -3
View File
@@ -41,7 +41,7 @@ var felisAuthNS = uuid.NewSHA1(uuid.NameSpaceURL, []byte("nano.felis.lolicon.bes
// authHTTPClient calls the upstream Yggdrasil roots. The timeout bounds one login
// against a hung source; the resolver moves on to the next source on any failure.
// ponytail: one shared client, sequential priority scan — a third-party login costs one
// One shared client, sequential priority scan — a third-party login costs one
// wasted Mojang round-trip; add parallel fan-out only if login latency bites.
var authHTTPClient = &http.Client{
Timeout: 5 * time.Second,
@@ -171,7 +171,7 @@ const mcUsernameMax = 16
// TRUNCATED to fit rather than the rename being skipped when it would not fit — skipping is
// what would silently hand a 14-character premium name back to the squatter.
//
// ponytail: two players of one source whose names agree on their first mcUsernameMax-len(prefix)-1
// Two players of one source whose names agree on their first mcUsernameMax-len(prefix)-1
// characters truncate onto the same in-game name, as does a prefixed name that happens to be
// a premium name itself. Both cost an "already connected" bounce, not an identity: the UUID
// rewrite is what keeps players apart, and it does not depend on the name at all. Add a
@@ -242,7 +242,7 @@ func isPremiumName(ctx context.Context, username string) bool {
}
premiumNames.Lock()
// ponytail: bounded by dropping the whole map rather than evicting LRU — entries are
// Bounded by dropping the whole map rather than evicting LRU — entries are
// only minted by players who actually authenticated somewhere, so this is a backstop
// against an unbounded map, not a cache policy worth tuning.
if len(premiumNames.m) >= premiumCacheMax {
+2 -2
View File
@@ -180,7 +180,7 @@ type Backuper struct {
// just-finished Job still inside its TTL window. ErrAlreadyExists is kept only as a
// defensive no-op against the astronomically unlikely suffix collision.
//
// ponytail: unique names mean two truly simultaneous taps can schedule two backup
// Unique names mean two truly simultaneous taps can schedule two backup
// Pods; both mount the world PVC read-only so neither corrupts anything, and if they
// land on different nodes the RWO attach fails one cleanly. Add single-flight-on-
// running only if a real double-tap storm ever shows up.
@@ -200,7 +200,7 @@ func (b *Backuper) Backup(ctx context.Context, serverName, formerOwner string) e
func jobNameSuffix() string {
var b [4]byte
if _, err := rand.Read(b[:]); err != nil {
// ponytail: crypto/rand only fails if the OS RNG is gone — unrecoverable.
// crypto/rand only fails if the OS RNG is gone — unrecoverable.
panic("backupjob: crypto/rand: " + err.Error())
}
return hex.EncodeToString(b[:])
+1 -1
View File
@@ -130,7 +130,7 @@ func (r *ExecRunner) CreateTunnel(ctx context.Context, name string) (string, str
// the file (authenticating with cert.pem, keeping the same id/DNS/Access), healing
// the re-run. The secret is written to the file, not stdout.
func (r *ExecRunner) ensureCredentials(ctx context.Context, id, credPath string) error {
// ponytail: any existing file counts as healthy; re-fetch only on absence
// Any existing file counts as healthy; re-fetch only on absence
// (the failure actually seen). A truncated/zero-byte file would still
// crash-loop — validate the JSON here if that ever shows up.
if _, err := os.Stat(credPath); err == nil {
+1 -1
View File
@@ -220,7 +220,7 @@ func list(r *os.Root, path string) Result {
// denied; a write is left alone because writing the file leaks nothing and is
// equally futile.
//
// ponytail: an exact match on one cleaned path, not a pattern. This is the whole
// An exact match on one cleaned path, not a pattern. This is the whole
// known exposure — grep FELIS_FORWARDING_SECRET across deploy/ — and if another
// image ever persists a platform secret into the mount, add its path here rather
// than inventing a matcher.
+1 -1
View File
@@ -114,7 +114,7 @@ func velocityJarVersion(path string) (updates.Version, error) {
// manifestAttr returns one attribute value from a jar's META-INF/MANIFEST.MF.
//
// ponytail: this does not implement the JAR spec's 72-byte line folding (a wrapped
// This does not implement the JAR spec's 72-byte line folding (a wrapped
// value continues on the next line after a single leading space). Version values are
// far short of the wrap point, so folding cannot bite here; if this ever reads a long
// attribute, join continuation lines before splitting on ':'.
@@ -691,7 +691,7 @@ public final class FelisVelocityPlugin {
StringArgumentType.getString(ctx, "server"));
return Command.SINGLE_SUCCESS;
})))
// ponytail: Brigadier matches literals before arguments, so a player
// Brigadier matches literals before arguments, so a player
// actually named "accept"/"deny" cannot be invited by name. They can
// still reach the server with /felis go, and renaming the subcommands
// would break the click handlers for a case worth less than that.
@@ -868,7 +868,7 @@ public final class FelisVelocityPlugin {
NamedTextColor.YELLOW));
return;
}
// ponytail: peek-then-take is not atomic — an invite landing in that window is
// Peek-then-take is not atomic — an invite landing in that window is
// taken instead of the one just validated. "Newest wins" is already the rule the
// book enforces, so the outcome is one this player would have got anyway; make it
// a computeIfPresent if invites ever arrive fast enough for anyone to notice.
@@ -899,7 +899,7 @@ public final class FelisVelocityPlugin {
// notifyInviter closes the loop for whoever sent the invite; without it they wait on a
// prompt they can never see the answer to. Silently skipped if they left in the meantime.
//
// ponytail: ACCEPTED means the transfer was handed to the waiting queue, which is as far
// ACCEPTED means the transfer was handed to the waiting queue, which is as far
// as this can see synchronously — a wake that fails later is reported to the guest only.
private void notifyInviter(InviteBook.Invite invite, String who, Answer answer) {
proxy.getPlayer(invite.from()).ifPresent(p -> {
@@ -56,7 +56,7 @@ final class InviteBook {
* cooldownRemaining is how long the sender must still wait, in millis, or 0 when they
* may send now.
*
* <p>ponytail: one global stamp per sender, so inviting Alex also holds off inviting
* <p>One global stamp per sender, so inviting Alex also holds off inviting
* Steve. That is the shape that actually stops the spam — a per-(sender, invitee) key
* would let one sender paper every player on the proxy at once, which is the thing
* being rate-limited. Key it per pair only if a real group of players complains.