Brighter icons: a world light, a fill from the camera, a highlight, exposure
and contrast; with the defaults the icons' mean luminance matches the game's
own model icons (118 against 120 on a scratch set). Every icon parameter is
listed once (UgcIconParams: key, setting, range, default); the settings,
the dashboard's settings entries and the icon editor come from that list.
Presets per kind (player models, each car or rocket build type from
ModularBuildComponent) and overrides per model or module combination are in
ugc_icon_settings.
Saved models wait ugc_debounce_seconds (sharedconfig) after the owner's last
save before they're made (ugc.process_after); a client asking for one, the
owner leaving the world or a reset ends the wait.
Cars and rockets: one icon per combination of modules (sorted LOTs), shared
by every build of it; builds of a combination made already are marked made
right away, the client's per-blueprint downloads serve the shared files.
The dashboard can delete one item's files, purge by filter or all, preview
icons with any values on the UGC server (/admin routes, master password),
save presets and overrides, and draw a kind's icons again (icons only).
Migrations dlu/mysql/86 and dlu/sqlite/69. Not done yet: the dashboard
editor's lighting controls in the page script (routes are there), docs for
it, the empty-model state, /ugc?item= links, the shared fetch helper; the
storage size and property loading bugs are next.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The icon was rendered from a second mesh built only for it (the icon
renderer's color corrections, no variation, occlusion worked out again). It
is now drawn from the .nif just made, read back with NifFile at LOD 0, so it
shows exactly what the game shows: the color variation, the removed faces and
the lighting baked into the vertex colors (so it adds no occlusion of its
own). icon_correct_colors and icon_color_variation are gone; the camera and
light settings stay. Cars and rockets are drawn as before.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Player-built models the UGC server made are drawn from their NIF, falling back
to the LXFML; a Generated models switch turns it off.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
UGC Search (/ugc_search) finds creations by name, id or LOT with where each
one is. Property pages and character inventories show the icon the UGC server
made of each creation, its state and a link to /ugc?item=&kind=, for whoever
may view the page.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
IUgcLookup: search ugc and ugc_modular_build by id, creator, property, model
name or LOT, and find where a creation is placed or mailed. The SQL is shared
by MySQL and SQLite (UgcLookupSql.h).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A brick built model item's config has blueprintid (lowercase), which the saved
item XML didn't keep (only blueprintID), so a picked up model lost its blueprint
on the next load and could not be placed again. It is now saved as x@bp.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A step by step table of LU Toolbox's pipeline against the UGC server's, the
new settings and their defaults, the measured effect of max_cpu_percent and
max_memory_mb, and the dashboard's gallery, viewer and internal address.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The /ugc page no longer needs the browser to reach the UGC server: the
dashboard fetches its status (/api/ugc/server/status), the files it made
(/api/ugc/files/<kind>/<id>/<file>) and its NIFs converted for the 3D view
(/api/ugc/mesh/<id>, NifFile like the scenery) from ugc_internal_url
(default http://127.0.0.1:2008) with libcurl on the worker threads, keeping
small answers briefly. ugc_public_url is only an "open on the UGC server"
link now.
The page gets an icon gallery beside the list, filtered by kind, state and a
search by id or owner (GetUgcProcessList/GetModularBuildProcessList take a
search), and a viewer: the generated NIF in 3D at any LOD, now or before it
was made again, with wireframe, vertex color and baked lighting switches, the
LXFML beside it, the icon now and before, and the stats with triangles before
and after hidden faces were removed. The status box shows CPU, memory, the
jobs' memory estimate with their limits, and throttling. The settings page
lists the UGC server's new settings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
LU Toolbox's Combine Transparent is off by default, so each transparent brick
is its own object and shape (the client can sort them). combine_transparent=1
joins them as before.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Parity with LU Toolbox's Process Model, Bake Lighting and icon renderer, with
its defaults as the settings' defaults:
- Colors from its LU palette (UgcPalette: LU colors, LDD colors mapped to the
nearest LU one, unknown ones black), transparent bricks at 58.82% opacity, a
brick transparent only when all of its materials are.
- Color variation: each brick's material gets its HSV value shifted in a 2.224
gamma by up to 5% (times the color's own amount), from a random number of
the model, brick and material, so reprocessing gives the same colors in
every LOD. Icons get none, and the icon renderer's color corrections.
- LODs 0 and 2 with its distance logic, written as NiLODNode/NiRangeLODData
like its exports and the game's own brick models, shapes divided at 65535
vertices along the longest side like divide_mesh.
- Ambient occlusion like its AO-only bake: 64 rays per vertex, distance 5,
after hidden surface removal, transparent bricks neither baked nor
occluding, glow colors added.
- Icons from its icon scene: 50 mm lens at 53.4/19.5 degrees, sun of 2.5 at
21/50.3 degrees with soft shadows, grey world light with occlusion; LOD 0's
hidden surface removal and occlusion are reused for them.
- Optional ground plane for hidden surface removal; stats.json per model and
the previous version's previews kept for comparing.
Budgets, applied live on config reload: max_cpu_percent (workers account
their thread CPU time and sleep to stay under it, long renders included),
worker_nice, max_memory_mb (jobs are estimated from their brick count and
wait until they fit), max_model_bricks and pause_hours. /status and the
traffic report show CPU, memory and throttling.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Server Status gets a UGC row while master starts it, and staff with
health_view a UGC Server card: up time, waiting/made/failed, busy workers and
storage, linking to /ugc. Server Health adds UGC to the uptime history and a
Servers table with every server's process, memory, CPU and last report.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Online state with the time it came up, down/up alerts, a UGC column in the
health history, /api/servers (every server with its process memory and CPU)
and /api/servers/ugc, and UGC gauges for Prometheus.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The server list now carries whether master starts the UGC server, whether it
is connected and the pid it was started as. Settings reloads reach it like
auth and chat, and shutdown waits for it. The UGC server sends its totals and
storage with its traffic reports.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Servers now log to logs/<Server>/ (worlds to logs/WorldServer/<zone>/<clone>/) with the start time in the file name.
The dashboard and UGC server log the same way, and the System Log page and log search read the whole folder tree
instead of only the top of logs/.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The client works out on its own when its racer goes the wrong way and
shows a 6 second countdown, but it only moves the car when the server
sends RacingSetPlayerResetInfo, which DLU never did for this.
The server now follows the reset planes the way the client's
LWORacingControlComponent does (1.10.64): each path waypoint is a plane
facing along its rotation; the racer starts between planes 0 and 1,
moves forward when in front of the upcoming plane and back when behind
the last one (CheckUpcomingResetPlane @ 0x00c7edf0, CheckLastResetPlane @
0x00c7f1a0, CrossResetPlaneBackward @ 0x00cba380). Driving back
through a second plane in a row starts the client's countdown
(UpdateWrongWayCount @ 0x00be5c10, 6 seconds); going forward through a plane ends it. When
it runs out, the racer gets the same reset as an unsmashed reset: reset
info for their furthest point and RacingResetPlayerToLastReset. Resets
sent for smashes keep the planes in step as well.
Fixes issue 764.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The buyback inventory grew by 9 slots whenever it was nearly full, so
the vendor's buyback page kept resizing. Live kept 27 items: a 2014
capture of 29 sales shows that on the 28th, the server sent
RemoveItemFromInventory (buyback inventory) for the first item sold,
then added the new one.
The buyback inventory now keeps its size. Before a sale needs a new
buyback slot and the inventory holds 27 or more items, the oldest items
(lowest object ID: each sale gives a new, higher ID) are removed. Sales
that fit on an existing buyback stack remove nothing. The removal is not
counted again by the economy ledger, which counted the items as gone
when they were sold.
Fixes issue 1129.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deleting an item now follows its ItemComponent delResIndex row in the
DeletionRestrictions table, the way the client's shared inventory code
decides it (LWOInventoryComponent_Common::CanRemoveFromInventory @
0x00ce0d20, CheckDeletionRestrictionIndex @ 0x00c94c20):
- missing, unrestricted, unknown-type or empty rows allow it;
- LOTS_INCLUDED: another item of any listed LOT must remain;
- LOTS_EXCLUDED: other items of every listed LOT must remain;
- ANY_RESTRICTION / ALL_RESTRICTIONS: any / all listed rows allow it;
- ZONE: only in the listed maps; ALWAYS_RESTRICTED: never.
Operators (GM level 9) may delete anything, as in the client. A refused
delete is logged and the item stays.
ItemComponent.minNumRequired is not used: the client never reads it, so
its meaning can't be verified.
Issue 960: the rocket (6416, row 8) and the classic rocket parts (rows 1-3)
have rows that keep at least one rocket or part, so the last rocket can
no longer be deleted and strand the player.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The character list selected index 0 and was ordered by last login, so
the characters swapped places on the selection screen after each
session. Live kept them in the order they were made and selected the
one with the latest last login (a new character counts as logged in
when it is made): 2014 captures show e.g. a new fourth character
appended and selected (index 3), and after the next login the list in
the same order with index 0 for the character played last.
Characters are now sorted by ID (creation order) and the one with the
latest last login is selected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Mail sent to someone who is not in the sender's world (system mail with
no address, and all player-to-player mail) now reaches them: the world
sends a MailNotify (Chat::MAIL, unused until now) to the chat server,
which passes it to the world the receiver is in, and that world sends
the client its unread count with a NewMail NotificationResponse.
Receivers in the same world are told directly. Player-to-player mail
did not notify the receiver at all before.
Replaces the TODO in Mail::SendMail.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Unequipping an item uncasts its equip skills; ApplyBuffBehavior::UnCast
now removes the buff with bFromUnEquip set, as live did (2014 captures:
RemoveBuff for buffs 3, 4, 5, 50 and 61 always carried bFromUnEquip,
and those are exactly the cancel_on_unequip buffs in the CDClient).
The client only drops a buff for such a removal when it was added with
cancelOnUnEquip (LWOBuffComponent::RemoveBuffIcon @ 0x00cf99b0), so
BuffComponent::RemoveBuff does the same to stay in step with it. Also
corrects the bFromRemoveBehavior comment: the client does not ignore the
message, it only removes buffs added with cancelOnRemoveBuff.
Replaces the TODO in InventoryComponent::RemoveBuff.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
WIRE FIX. The 1.10.64 client writes and reads the immunity flags in
alphabetical order after the u32 state (GameMessage::SetStatusImmunity::
Serialize @ 0x00d8f140; the field offsets are named by the Flash export
at 0x00d8f410): BasicAttack, DOT, ImaginationGain, ImaginationLoss,
Interrupt, Knockback, PullToPoint, QuickbuildInterrupt, Speed. DLU wrote
them in declaration order, so e.g. a knockback immunity reached the
client as an imagination-gain immunity.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
WIRE FIX. DLU sent NotifyNotEnoughInvSpace with the ID of
VehicleNotifyFinishedRace (1396). The 1.10.64 client registers it as
NOTIFY_NOT_ENOUGH_INV_SPACE (1516, 0x00545c90) and reads freeSlotsNeeded
followed by the optional inventoryType (0x00d8b850), which is what the
payload already was. Only the message ID changes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Make keys with a permission picker grouped like the Permissions page
(only the maker's own permissions), limits, restrictions and expiry;
the list shows scope, lost permissions, limits, today's use, last use
and requests, with rotate and revoke. Staff with api_keys_manage see
and revoke other accounts' keys under the rank rules.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
POST /api/tables/... only reads, so read-only keys may use it (and the
API docs list it for them). Keys limited to some addresses can't open
the WebSocket, whose address isn't checked, nor keys whose allowed
paths leave out /ws. Refusals are audited without an account target.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bearer keys (dlk_...) are checked per request against their owner's
current account (ban, lock, demotion, sign out everywhere stop or narrow
them at once) and their scope: permission routes need the permission in
scope, read-only keys only read, level-only routes need an all-permission
key, and session-only paths (sign-in, password, 2FA, key management)
are never reachable with a key. Per-key rate limit and daily quota with
429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in
batches every minute. WebSocket subscriptions honour the scope too.
Routes to list, make, rotate and revoke keys; staff with
api_keys_manage can see and revoke others' keys under the rank rules.
POST /api/auth/token now makes an all-permission key. Audit entries for
create/rotate/revoke/denied, and actions done with a key are attributed
to "user (key name)".
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Hashed API keys with scope, restrictions, limits, expiry and batched
usage counters, for MySQL and SQLite, with test stubs and parity tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A key's effective permission is its scope AND its owner's current
permission. Scoped variants of Allowed, CanViewCharacter, ForLevel and
ManageDenialNow; keys need self_* and manage_equal_rank in their scope
to act on their owner or equal ranks, even for GM 9 owners. Adds the
api_keys_manage permission and NotGrantable for key creation.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Keeps every server's traffic reports (last hour at one second, per-minute
rows to server_traffic once a minute, pruned after traffic_days) and shows
packets, bytes, HTTP requests and latency per second, per server, with the
busiest message types and HTTP routes. Live over the traffic WebSocket topic;
1 hour, 24 hours and 7 days ranges. The same counters are in /metrics.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
One row per server and minute (packets, bytes, resends, HTTP requests, errors,
bytes and latency percentiles), written in batches and read summed into
buckets for the longer chart ranges.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Requests are counted by route pattern and status class with a latency
histogram (deferred requests until their answer goes out) and bytes sent.
The web server reports pending deferred requests and WebSocket clients, the
UGC server its worker threads.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
TrafficStats keeps packets and bytes in and out per second and the busiest
packet and game message types. dServer counts at its send and receive calls
and adds RakNet's connection statistics (datagrams, resends, ping); the report
goes to master as SERVER_TRAFFIC (appended), which passes it to the dashboard.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The live server scripts (l_fv_panda_server.lua, l_crab_server.lua, in
the client's res/scripts) take a tamed pet out of the groups it was
spawned into: the panda leaves "pandas" and "panda<tamer>", the crab
"crab<tamer>". The panda spawner counts "pandas" (at most five) and
"panda<player>" (one per player), so tamed pandas used to keep counting
against both. Entity gets RemoveFromGroup for it.
The dig and object pet scripts keep their TODO: their live server
scripts are not shipped with the client.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Issue 547. The minigame put the player a guessed distance from wherever
the pet had wandered to, in the direction of the player, which often
left bricks off screen or the whole minigame over a drop.
In the 2014 live captures the positions are the same for every try at
the same pet: the pet's destination is where it spawned, and the player
is teleported exactly 12 units along the direction the pet spawned
facing, turned to face the pet. This matches the spawner in the level
file for the Pet Ranch cat (spawned facing -43.4 degrees, player placed
at spawn + (-8.24, 8.73) facing 136.6 degrees) and holds for the
doberman, buffalo, triceratops, rabbit and the script spawned panda.
The pet is now put back on that spot and the player placed that way; the
heights come from the navmesh when there is one.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Issue 536. A pet that reached a pet switch jumped on it by itself for
free. Now it works like digs, following what live did (2014 captures):
on the way the pet has state 0x500 and the owner gets
PR_BOUNCER_TUTORIAL_01; on the switch the pet has state 0x120 and the
Jump On Object ability, plays "excited" while the switch plays
"engaged", and the owner gets the pet action button
(ShowPetActionButton 2) and PR_BOUNCER_TUTORIAL_03. Using it costs
PetAbilities.ImaginationCost (2), the pet plays "jump", the owner gets
PR_TOOLTIP_1ST_PET_JUMPED_ON_SWITCH and the switch turns its bouncer on.
The switch plays "launch" then, as on live, instead of "engaged".
The pet switch is no longer written into the pet's serialized
interaction (it was never cleared).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Issue 537. A pet that reached a dig dug it up by itself for free. Now,
as on live (2014 captures), the pet goes to the dig with state 0x500 and
the Go To Object ability while the owner gets the PR_DIG_TUTORIAL_01
tooltip; at the dig it waits with state 0x120 and the Dig At Position
ability, and the owner gets the pet action button (ShowPetActionButton
3). Pressing SHIFT or the button makes the client send RequestUse on the
pet (LWOPetControlComponent::msgPetCommand 0x00c5d220, "contextAction");
that costs PetAbilities.ImaginationCost (1 for digging), hides the
button, shows PR_DIG_TUTORIAL_03 and starts the dig. The button goes
away when the pet leaves the dig.
The dig is no longer written into the pet's serialized interaction:
live did not serialize one for digs or pet switches.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Issue 539. When a pet is sent away the client greys its backpack item
out again by looking the item up by the ID in MarkInventoryItemAsActive
(LWOInventoryComponent_Common::SendMessage 0x00d54b90). The pet kept
the item ID it was summoned with, but items get new IDs when they move,
so the lookup could miss and the item stayed marked active; the pet's
item is now looked up by its subkey when the pet goes away.
Sending a pet away also sent AddPetToPlayer with an empty pet. The
client never removes anything on that message, it adds a new entry to
its pet list (LWOPetControlComponent::HandleMessage 0x00d0fe00), so it
left an empty pet behind; live did not send it (2014 captures) and it
is no longer sent. RegisterPetID with no pet already clears the active
pet and hides the pet menu.
The imagination drain kept going after it had sent the pet away (and
took another point of imagination); it stops there now.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Issue 546. The client plays a pet's spawnAnim ("spawn" unless set in
its config) only when the pet is constructed with state 8 (bit 0x80)
set (LWOPetComponent::Deserialize 0x00cd1270). Live summons were
constructed with status 0x84, played the pet's "despawn" effect (the
circles and stars, effect 365) and then dropped the bit; summoned pets
are now constructed that way, with the effect and the state change at
the end of the spawn animation.
Sending a pet back to the backpack killed it right after sending the
despawn effect, so the client removed it before the effect could play.
Live removed the pet some time after the effect; it is now removed once
the pet's despawn animation time has passed, and does nothing in the
meantime.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>