Implement authorized landmark roaming (#130)
This commit is contained in:
40
docs/grid-agent-landmarks.md
Normal file
40
docs/grid-agent-landmarks.md
Normal file
@@ -0,0 +1,40 @@
|
||||
# Landmark intake, teleport, and roaming
|
||||
|
||||
Landmark authority is private. Public chat and non-allow-listed IM can neither
|
||||
accept offers nor see teleport/schedule tools. The policy layer seals the
|
||||
authenticated avatar into every mutation; tool schemas contain a catalog
|
||||
selector or bounded interval, never an avatar, region, coordinate, inventory
|
||||
folder, or L$ field.
|
||||
|
||||
The live adapter subscribes through the original LibreMetaverse compatibility
|
||||
events but lives entirely in `metacrate-grid-agent`. Authorized landmark and
|
||||
folder offers are accepted into `MetaCrate Received Landmarks`, which is a
|
||||
quarantine and recovery folder. Direct items are cataloged only after the
|
||||
server returns authoritative item metadata. Folder descendants are fetched
|
||||
with bounded breadth/depth and asset-fetch counts; a cycle, link, duplicate
|
||||
asset, bad type, empty folder, stale response, or limit breach leaves the
|
||||
quarantined inventory untouched and out of the catalog. Task offers and all
|
||||
unauthorized or arbitrary inventory offers are declined.
|
||||
|
||||
The persisted catalog contains sender UUID, inventory UUID, asset UUID,
|
||||
permission fingerprint, display name, receipt time, validation state, and last
|
||||
outcome. Names are untrusted. Persistence is bounded, versioned, atomically
|
||||
replaced, and mode `0600` on Unix. Teleport selection prefers stable IDs and
|
||||
requires clarification for duplicate names. Immediately before the native
|
||||
landmark teleport, the item is fetched again and its type, asset UUID, and
|
||||
permissions must match. One semaphore, a timeout, cooldown, and lifecycle
|
||||
cancellation prevent overlapping or stale teleports.
|
||||
|
||||
Roaming schedules retain the authorizing avatar UUID and safe minimum/maximum
|
||||
intervals. Randomness is injectable. A due run chooses without immediate
|
||||
repetition when possible and schedules its next deadline from the current time,
|
||||
so downtime never creates catch-up bursts. Conversation, operator, degraded,
|
||||
build, and viewport-capture pause reasons all suppress selection. Disabling a
|
||||
schedule is persistent and cancellation stops in-flight native teleport work.
|
||||
|
||||
Focused verification:
|
||||
|
||||
```console
|
||||
cargo test --locked -p metacrate-grid-agent --lib landmark_tests
|
||||
cargo check --locked -p metacrate-grid-agent --all-targets --features live-grid
|
||||
```
|
||||
Reference in New Issue
Block a user