Files
MetaCrate/docs/grid-agent-landmarks.md
Chili Palmer 08696cd2fe
Some checks failed
CI / rust-skia (Rust only) (push) Successful in 2m46s
CI / required (push) Failing after 53s
Implement authorized landmark roaming (#130)
2026-08-18 11:08:50 +02:00

41 lines
2.2 KiB
Markdown

# Landmark intake, teleport, and roaming
Landmark authority is private. Public chat and non-allow-listed IM can neither
accept offers nor see teleport/schedule tools. The policy layer seals the
authenticated avatar into every mutation; tool schemas contain a catalog
selector or bounded interval, never an avatar, region, coordinate, inventory
folder, or L$ field.
The live adapter subscribes through the original LibreMetaverse compatibility
events but lives entirely in `metacrate-grid-agent`. Authorized landmark and
folder offers are accepted into `MetaCrate Received Landmarks`, which is a
quarantine and recovery folder. Direct items are cataloged only after the
server returns authoritative item metadata. Folder descendants are fetched
with bounded breadth/depth and asset-fetch counts; a cycle, link, duplicate
asset, bad type, empty folder, stale response, or limit breach leaves the
quarantined inventory untouched and out of the catalog. Task offers and all
unauthorized or arbitrary inventory offers are declined.
The persisted catalog contains sender UUID, inventory UUID, asset UUID,
permission fingerprint, display name, receipt time, validation state, and last
outcome. Names are untrusted. Persistence is bounded, versioned, atomically
replaced, and mode `0600` on Unix. Teleport selection prefers stable IDs and
requires clarification for duplicate names. Immediately before the native
landmark teleport, the item is fetched again and its type, asset UUID, and
permissions must match. One semaphore, a timeout, cooldown, and lifecycle
cancellation prevent overlapping or stale teleports.
Roaming schedules retain the authorizing avatar UUID and safe minimum/maximum
intervals. Randomness is injectable. A due run chooses without immediate
repetition when possible and schedules its next deadline from the current time,
so downtime never creates catch-up bursts. Conversation, operator, degraded,
build, and viewport-capture pause reasons all suppress selection. Disabling a
schedule is persistent and cancellation stops in-flight native teleport work.
Focused verification:
```console
cargo test --locked -p metacrate-grid-agent --lib landmark_tests
cargo check --locked -p metacrate-grid-agent --all-targets --features live-grid
```