Repository navigation
Conversation
zoeyrose
marked this pull request as ready for review
October 4, 2026 16:54
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replace the replacement server's shared-password publication flag with access-token admission metadata using the protocol-owned Game publisher v2 contract. Public visibility remains independent of whether admission requires a code.
Implementation / behavior
metaserver/v2types and v2 signed publisher helpers; emitaccessRequiredthrough/v2/servers/{serverId}/publishwith no v1 fallback.-password-requiredwith-access-requiredand preserve admission-only changes in publication scheduling.Validation
tools/validate.shpassed for server4f0234c3a9d0b2a62f75b74c3856310e25c57438in the pinned Linux build image with Go 1.26.6 using the normal public Go proxy and checksum database. No private modfile, module replacement or private proxy was used. This includes all tests, race detection, static analysis, bounded fuzz/benchmark checks, vulnerability/dependency-license checks, Git LFS attribute checks, Linux/Windows package builds and package reproducibility.Independent review approved the complete source and the final dependency-only change. Focused tests cover all four visibility/admission combinations, obsolete flags and fields, policy-only republishing, protocol-minor rejection and certificate identity binding. Native Linux and Windows CI passed on this exact head, including the required Server validation aggregate and Conventional PR title check.
Limitations / follow-up
The protocol dependency is now pinned to the published source behind protocol v2.6.0: commit
58ed75f13fab6a405160fac617c54e990b067e8b, resolved by normal Go tooling asv1.5.6-0.20261004163427-58ed75f13fab. The pseudo-version is necessary because the Go module path remainsgithub.com/atrinik/protocolwithout a/v2suffix. Its public checksum record is committed ingo.sum; the release/pin blocker is resolved.The M1 replacement server has no gameplay listener, token administration/store, account authentication or private rendezvous consumer. This change implements its actual publisher/configuration boundary and does not claim gameplay token lifecycle acceptance. No production deployment or live service change is included.