feat: live updates move every server onto a new build without a restart

With new binaries in place, master moves everything onto them while the
server keeps running (the dashboard's Live update, /liveupdate or SIGUSR2 to
master):

- database migrations of the new build first; a failure stops there
- UGC finishes the jobs it is running (queued rows stay pending), auth
  restarts, chat hands its teams to master for the next chat server; master
  starts the new processes and retries ones that don't come back
- once the new chat server is up (CHAT_SERVER_READY) every world connects at
  once and sends its players again (LoginSessionNotify resync, no login logged)
- every world instance is replaced with an instance migration: public worlds
  and private ones (same password) at once, properties after the old instance
  saved and froze the property (MIGRATE_PREPARE: no building, claiming or
  saving there any more), activity zones and character select once their
  players left or after a wait; empty instances just stop, zones in
  prestart_worlds get a new one first
- the dashboard restarts last and picks the status up again

Players land where they stood (position carried in CarriedPlayerState, also on
properties and Moon Base). Draining instances get no new players
(InstanceMigration::AcceptsNewPlayers) and show as "Moving players" in the
world list. The order lives in LiveUpdateMachine.h without master state and is
unit tested; master's glue is LiveUpdateCoordinator. Master itself is not
replaced. Message IDs are appended only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Aaron Kimbrell
2026-09-28 15:01:05 -05:00
parent bfc45dc662
commit 109a936798
47 changed files with 3213 additions and 59 deletions

View File

@@ -17,9 +17,24 @@ namespace MigrationCoordinator {
// Where statuses go (every world, so the GM who asked hears about it wherever they are); set once at startup
void SetReporter(std::function<void(const MigrationStatus&)> reporter);
// A migration was asked for (a GM command, or later a dashboard); anything but NONE means it was refused (and
// Also told every status, including those nobody asked for in game (live updates follow their migrations here)
void SetObserver(std::function<void(const MigrationStatus&)> observer);
// What a live update (LiveUpdateCoordinator) changes about a migration
struct Options {
// Moves what CheckSource refuses (see CheckLiveUpdateSource): character selection, private instances,
// properties and activity zones
bool liveUpdate{};
// Properties: the source saves and freezes the property (MIGRATE_PREPARE) before the new instance is started
bool prepare{};
uint16_t prepareWaitSeconds{ 60 };
// Players who are dead or building wait this long before they are moved anyway
uint16_t playerWaitSeconds{ MigratePlayersOrder::DEFAULT_MAX_WAIT_SECONDS };
};
// A migration was asked for (a GM command, or a live update); anything but NONE means it was refused (and
// reported as FAILED)
InstanceMigration::eRefusal Start(const InstanceMigrationRequest& request);
InstanceMigration::eRefusal Start(const InstanceMigrationRequest& request, const Options& options = {});
// A world reported progress on a migration it is running
void HandleStatus(const SystemAddress& from, const MigrationStatus& status);