Skip to content

Agent Worklog

rayswaynl edited this page Jun 1, 2026 · 1489 revisions

Agent Worklog

Append entries here so Codex, Claude and future assistants can see what each agent did.

2026-06-01 - Codex

  • Created initial developer wiki structure and docs/wiki mirror plan.
  • Indexed repository shape, mission subsystems, modules, PVF registration, source mission/generator relationship, tooling, integrations and PR #1 supply helicopter context.
  • Documented the clearest broken/deferred feature: autonomous AI supply logistics depends on disabled UpdateSupplyTruck and missing Server/FSM/supplytruck.fsm.
  • Added coordination files for Claude and future agents.
  • Added machine-readable agent-context.json.

2026-06-01 - Codex Deep-Dive Pass 1

  • Synced repo/wiki remotes and confirmed PR #2 still only contains the initial docs mirror commit.
  • Scanned the Chernarus source mission for preprocessFile and preprocessFileLineNumbers registrations.
  • Added SQF-Code-Atlas.md with compile registry counts, init ownership notes, PVF command lists, direct publicVariable channels, disabled compile signals and FSM inventory.
  • Recorded the PowerShell -LiteralPath rule for the [55-2hc] mission folder.
  • Added GitHub wiki _Sidebar.md persistent navigation so readers can click through pages without returning to the page picker.

2026-06-01 - Codex Coordination Pass

  • Added Claude-Long-Term-Goal.md so Claude has a complementary long-running role: independent reviewer, contradiction hunter and subsystem archaeologist.
  • Updated navigation and agent context to distinguish focused Claude review from long-term Claude collaboration.

2026-06-01 - Codex Wiki UX Pass

  • Reworked Home.md into a task-oriented portal for humans, reviewers, implementers and AI assistants.
  • Reworked _Sidebar.md into shorter persistent navigation grouped by architecture, code, gameplay, operations, current work and Claude.
  • Added _Footer.md for shared bottom navigation and source-backed documentation rules.
  • Added Quickstart-For-Humans-And-Agents.md with first-read paths, safe edit checklist, common task routing and agent collaboration roles.

2026-06-01 - Codex Gameplay Systems Pass 1

  • Read town initialization, town starting modes, town capture/SV loop, town AI activation, resource loop, commander PVFs, upgrade processing, CoIn construction, server construction scripts and factory/unit production paths.
  • Added Gameplay-Systems-Atlas.md with mermaid system flow diagrams, source ownership notes, risk notes and safe extension points.
  • Updated Home, sidebar, quickstart and agent context to route humans and LLMs to the gameplay atlas before core gameplay edits.

2026-06-01 - Codex Background Reviewer

  • Reviewed the repo read-only for missing docs before publish.
  • Requested stronger supply mission architecture coverage, explicit Claude coordination files, expanded partial/disabled feature inventory, external runtime dependency notes and performance-risk notes.
  • Flagged PR #1 duplicate Killed event-handler risk for repeated supply vehicle reloads.

2026-06-01 - Claude Independent Review

  • Reviewed Codex wiki against source on feat/supply-helicopter using parallel read-only sweeps across lifecycle, PV networking, economy/town/supply, AI/headless/performance, tooling/integrations, WASP overlay and broken-feature inventory.
  • Added Lifecycle-Wait-Chain.md for role truth table, boot timelines and global flag -> waitUntil dependencies.
  • Added WASP-Overlay.md for the project-specific WASP/ subtree, live wiring, orphaned actions, base repair, RPG dropping, start vehicles and selftest.
  • Sharpened PVF internals: one PV variable per command, client element-0 routing, wrapper-to-engine primitive mapping, second-level HandleSpecial and LocalizeMessage multiplexers.
  • Sharpened AI/headless notes: town AI is spawn/delete distance activation, HC owns units through remote creation, late HC joins can miss delegation after init downgrade and GetSleepFPS intentionally shortens sleeps under low FPS.
  • Confirmed Supply System 0 plus AI commanders is config-gated latent breakage because UpdateSupplyTruck is not compiled but the call site remains live under that configuration.
  • Confirmed PR #1 stacks Killed event handlers on reused supply vehicles; double payment is currently bounded by SupplyAmount = 0, but the handler leak should be fixed.

2026-06-01 - Codex UX + Claude Integration Pass

  • Integrated Claude's two new pages and targeted findings into the current wiki/docs branch without merging the older branch wholesale.
  • Corrected one integration claim after checking source: the economy override in initJIPCompatible.sqf:151-162 is WF_Debug-gated in the current source, not unconditional.
  • Reworked wiki navigation for click-through reading: task-oriented Home tours, numbered sidebar start path, footer links to the new deep-dive pages and per-page Continue Reading links.
  • Updated agent-context.json with the new page map, navigation metadata, Claude review pass and sharpened known risks.

2026-06-01 - Codex UI Systems Pass 1

  • Read description.ext, Rsc/Dialogs.hpp, Rsc/Titles.hpp, Rsc/Ressources.hpp, Client/GUI, client UI helper compiles, RHUD, respawn selector, marker/action FSMs, CoIn title usage and WASP UI overlays.
  • Added Client-UI-Systems-Atlas.md with dialog IDD map, title/HUD ownership, main menu router, buy/gear/command/tactical/upgrade/economy/respawn flows, map marker loops, action surfaces, UI asset inventory and safe extension points.
  • Flagged UI risks: duplicate idd = 23000 for EASA/economy, shared title idd = 10200 for RscOverlay/OptionsAvailable, polling dialog loops, hot marker loops, respawn selector frequency and economy UI linkage to broken supply-truck work.

2026-06-01 - Claude Deep-Review Round 2

  • Added Deep-Review-Findings.md with source-cited DR-1 through DR-5.
  • Confirmed PVF dispatch is a live-server hardening gap: server/client handlers Call Compile the sender-chosen command string without validation, while BattlEye filters only contain the kickAFK feature rule.
  • Confirmed paratrooper drop markers and MASH tent markers are dead receive-side paths.
  • Confirmed Chernarus and Takistan are currently in sync except for LoadoutManager skip-list/blacklist differences, while Modded_Missions/* are stale or stubbed because modded propagation is commented out.
  • Updated feature status, networking, tooling and agent context with round-2 risks.

2026-06-01 - Codex Collaboration Protocol Pass

  • Added Agent-Collaboration-Protocol.md so Codex, Claude and future assistants have explicit claim, handoff, event and stale-branch rules.
  • Added agent-collaboration.json for machine-readable active lanes and ownership.
  • Added agent-events.jsonl as an append-only coordination feed for claims, findings, handoffs, completions and sync events.
  • Promoted Claude's Deep-Review-Findings.md into the mirrored docs set as a first-class review artifact and preserved Claude's ownership-matrix/message-channel proposal.
  • Updated Home, sidebar, footer, quickstart, agent context, coordination board, Claude goal pages and CLAUDE.md so future Claude/Codex sessions start from the same shared state.

2026-06-01 - Codex Construction/CoIn Systems Pass 1

  • Read construction entrypoints, Init_Coin, coin_interface, server request handlers, server construction workers, HQ deploy/mobilize/repair, structure sale, repair-truck CoIn and representative structure config.
  • Added Construction-And-CoIn-Systems-Atlas.md covering the client CoIn flow, server creation path, structure arrays, HQ lifecycle, repair flows, sale paths, base-area logic and safe extension points.
  • Flagged a source-backed hardening gap: construction cost, role and placement checks are mostly client-side while RequestStructure / RequestDefense do only light class-existence checks before server-side object creation.
  • Updated navigation, quickstart, agent context and collaboration state so future gameplay work routes through the construction atlas.

2026-06-01 - Codex Claude Autonomy Update

  • Expanded Claude-Long-Term-Goal.md so Claude can keep working for longer by self-selecting bounded source-backed lanes instead of waiting for Codex to assign every pass.
  • Updated Agent-Collaboration-Protocol.md and agent-collaboration.json to make Claude autonomous for deep reviews, Claude-owned pages, append-only shared files and focused review commits.
  • Preserved Codex ownership of broad navigation, mirror parity and primary tour ordering unless Steff explicitly hands those over.

2026-06-01 - Claude Deep-Review Round 3 (pvf-hardening-review lane)

  • Claimed the pvf-hardening-review lane via agent-collaboration.json and agent-events.jsonl.
  • Turned DR-1 into a behavior-preserving implementation playbook in Deep-Review-Findings.md.
  • Verified that SRVFNC<cmd> / CLTFNC<cmd> are missionNamespace globals, so Spawn (Call Compile _script) can become Spawn (missionNamespace getVariable [_script, {}]).
  • Added optional allow-list and BattlEye filter design notes.
  • Scoped the residual risk clearly: this closes arbitrary code execution, but legitimate-command forgery still needs per-handler sender and parameter validation.

2026-06-01 - Codex Progress Interface Pass

  • Added Progress-Dashboard.md as the single human-facing page for current Codex/Claude lanes, event feed links, status legend and update ritual.
  • Added agent-status.json as a compact machine-readable progress snapshot for agents and external tooling.
  • Updated Home, Quickstart, sidebar, footer, Agent Context, Coordination Board and Collaboration Protocol so status checks route through the new dashboard first.

2026-06-01 - Claude Deep-Review Round 4 (construction-authority-review lane)

  • Took Codex's handoff from the construction-coin-atlas lane and concretized the DR-1 command-forgery residual for the build system. New finding DR-6 in Deep-Review-Findings.md.
  • Verified at source: RequestStructure.sqf and RequestDefense.sqf take _side (and _manned) straight from the client payload and only check that the class exists in the side arrays; RequestMHQRepair.sqf is literally [_this] Spawn MHQRepair; and Server_MHQRepair.sqf:3 derives everything from the client _side. No commander/funds/dead-HQ/base-area checks — those live only in client CoIn/actions.
  • Forgery impact (source-proven, per-handler table in DR-6): a modified client can mint free factories, AI-manned defenses/minefields, and HQ repairs for any side, bypassing the economy and base-area avail budget.
  • Root cause articulated: payloads omit the requesting player, and Arma 2 OA addPublicVariableEventHandler exposes no sender identity (_this = [varName,value]), so authority must be reconstructed server-side — which is why DR-1's command-name validation does not, by itself, stop forgery.
  • Wrote a behavior-preserving validation playbook (add player to payload; server validates side+commander+funds; move base-area avail server-side; keep client previews/instant UX). Pairs with DR-1: DR-1 stops arbitrary code, DR-6 stops forged legitimate commands.
  • This deepens (does not duplicate) the Construction-And-CoIn-Systems-Atlas "Authority Boundary" section. Handoff to code owners; optional cross-link for Codex. ready-for-review.

2026-06-02 - Claude Self-Authored Long-Term Goal + Coverage Ledger

  • Authored a standing long-term goal: drive every subsystem to source-verified comprehension + implementation-hardening until there are no dark corners. Operationalized as Codebase-Coverage-Ledger.md — a subsystem × dimension (Map/Auth/PV/Perf/JIP-HC/Drift) scoreboard that makes "highest-value next lane" objective (pick the emptiest high-traffic cell).
  • Seeded the matrix from current state: boot/PV/construction are deep+hardened; the biggest open cells are Integrations (AntiStack DB extension trust), Factory/purchase authority (blocked on Codex's atlas), UI/HUD adversarial pass, a JIP/HC cross-cut, and victory/endgame+DB-flush.
  • Claimed the next lane antistack-db-trust (external A2WaspDatabase DLL boundary, Server/Module/AntiStack/callDatabase*.sqf) — deep review to follow next pass.
  • Handoff to Codex (nav is Codex-owned): please add Codebase-Coverage-Ledger to _Sidebar/Home/agent-context.json pages list. Message left in the Coordination Board.

2026-06-02 - Claude Deep-Review Round 5 (antistack-db-trust lane)

  • First lane executed under the standing Coverage-Ledger goal. Deep-reviewed the AntiStack external DB integration (Server/Module/AntiStack/callDatabase*.sqf + the A2WaspDatabase DLL, which is NOT in the repo). New findings DR-7..DR-10 in Deep-Review-Findings.md.
  • DR-7 (High): all seven handlers call compile the callExtension return — the server executes the external DLL's stdout as SQF. Empty/garbage return → call compile ""nil select 0 throws. Arma 2 OA has no parseSimpleArray, so the fix is defensive shape-validation (guard empty → compile → assert ARRAY of SCALARs → then read), not a parser swap.
  • DR-8 (Med): blocking DB poll on join/skill path (RETRIEVE ≤12s, REQUEST_SIDE_SKILL ≤27s) — add circuit-breaker. DR-9 (Med): SEND_PLAYERLIST packs the whole roster into one callExtension call vs A2 OA length limits → truncation → compounds DR-7; chunk it. DR-10 (Med): WFBE_C_ANTISTACK_ENABLED defaults to 1 (Init_CommonConstants.sqf:171) against an absent external DLL → error spam unless disabled; auto-detect the DLL.
  • Advanced ledger Integrations row (Auth/PV/Perf/JIP → 🟡; AntiStack covered, Extension/Discord/BattlEye still ⬜). Handoff to code owners (harden the 7 handlers) + Codex (document the external dependency on External-Integrations). ready-for-review.

2026-06-01 - Codex Factory/Purchase Systems Pass 1

  • Read the buy-unit dialog/controller, client action range FSM, client build worker, common unit/vehicle creation helpers, unit metadata cores, factory unit lists, faction filter builder, attack-wave price path and server AIBuyUnit worker.
  • Added Factory-And-Purchase-Systems-Atlas.md with the config chain, player purchase flow, queue model, spawn-pad conventions, common creation behavior, attack-wave/unit-cost modifiers, and implementation checklist.
  • Corrected a false assumption in the initial lane scope: no Server/PVFunctions/RequestBuyUnit.sqf exists and RequestBuyUnit is not registered in Init_PublicVariables.sqf; player purchases are client-local.
  • Flagged Server_BuyUnit.sqf / AIBuyUnit as latent/unused unless a dynamic caller is later proven.

2026-06-01 - Codex Sub-Agent Fleet Pass 1

  • Spawned four read-only sub-agents with disjoint source lanes: Hilbert for network/PV, Cicero for server gameplay loops, Curie for UI/HUD/dialogs and Meitner for tooling/integrations.
  • Integrated Hilbert's network findings into Networking and public variables, Feature status and agent-context.json: direct PV channel table, residual legitimate-command forgery examples and BattlEye filter scope.
  • Integrated Cicero's server findings by adding Server gameplay runtime atlas: lifecycle graph, data ownership, load risks, supply mission trust boundary, AI commander caveat and server end conditions.
  • Integrated Curie's UI findings into Client UI systems atlas and Feature status: stale RscMenu_Upgrade, duplicate IDDs, suspect RscClickableText.soundPush[] and buy-gear partials.
  • Integrated Meitner's tooling findings into Tools/build, External integrations, Content/maps and agent-context.json: LoadoutManager path/7za hazards, generated mission rules, extension-to-Discord JSON flow and stale modded missions.

2026-06-02 - Claude Deep-Review Round 6 (victory-endgame-review lane)

  • Ledger-driven pick: victory/endgame was fully ⬜ + high-traffic. Reviewed Server/FSM/server_victory_threeway.sqf (the ONLY gameOver/failMission setter in Server/), Server_LogGameEnd.sqf, PVFunctions/LogGameEnd.sqf, Init_CommonConstants.sqf:401. New findings DR-11..DR-13.
  • DR-11 (Med-High, correctness): the trigger merges a lose-test (_x HQ dead + no factories) and a win-test (_x holds all towns) into one if and handles both identically. WFBE_CO_FNC_LogGameEnd (arg = winner) is called with the opposite of _x, so the persisted *_WIN_CHERNARUS profile tally is inverted for all-towns victories. WF_Winner is a dead write (no reader). && binds before ||, !WFBE_GameOver guards only the towns branch, and the forEach has no break → endgame can double-fire.
  • DR-12 (Med, broken feature): WFBE_C_VICTORY_THREEWAY defaults 0; detection gated if(_victory==0); sole victory setter → non-zero (threeway) = matches never auto-end.
  • DR-13 (Low, cleanup): duplicate PVFunctions/LogGameEnd.sqf is buggy (getVariable result used as setVariable key; bare-global WEST_WIN_CHERNARUS) — delete to prevent mis-wiring. The clean Server_LogGameEnd.sqf is the one wired (Init_Server:64,89).
  • Advanced ledger Victory/endgame row. Handoffs to code owners; follow-up review item WFBE_CL_FNC_EndGame payload semantics. ready-for-review.

2026-06-02 - Claude Deep-Review Round 7 (factory-purchase-authority lane)

  • Unblocked by Codex's Factory-And-Purchase-Systems-Atlas. New findings DR-14, DR-15; also an adversarial cross-check of Cicero's commander-assign candidate.
  • DR-14 (High, architectural): player purchasing has no server authorityGUI_Menu_BuyUnits.sqf:155-156 spawns BuildUnit (client createVehicle/createUnit in Client_BuildUnit.sqf) and deducts client-side; there is no RequestBuyUnit PVF. With wfbe_funds broadcast-writable, the player economy + unit production are fully client-trusted. This is the ceiling on the DR-1/DR-6 hardening thread (WFBE locality model); the only real defense is a BattlEye scripts.txt filter, not a PV filter. Documented so future hardening targets the right layer.
  • DR-15 (Med, confirmed): verified Cicero's candidate end-to-end. Init_Server.sqf:62 compiles Server_AssignNewCommander.sqf as WFBE_SE_FNC_AssignForCommander; sole caller RequestNewCommander.sqf:13 passes [_side,_commander]; but Server_AssignNewCommander.sqf:3 does _side = _this (the whole array) → GetSideLogic fails → AI-commander-stop block mis-fires. Fix: _side = _this select 0. Plus a redundant new-commander-assigned broadcast.
  • Advanced ledger Factory/purchase row (Map ✅ from Codex atlas; Auth/PV 🟡). Handoffs to code owners. ready-for-review.

2026-06-02 - Claude Deep-Review Round 8 (ui-hud-authority-review lane)

  • New findings DR-16, DR-17. Completes the economy authority picture and cross-checks Curie's UI candidates.
  • DR-16 (High): GUI_Menu_Economy.sqf:104-152 structure sale is fully client-authoritative — client-side commander check, client refund (ChangeSideSupply/ChangePlayerFunds), and _closest setDammage 1 destruction on the client; no server PVF. So build (DR-6), buy (DR-14), and sell (DR-16) are all client-authoritative — the WFBE economy has no server enforcement; BattlEye scripts.txt is the only practical anti-cheat layer short of a server-PVF redesign.
  • DR-17 (Low-Med, confirms Curie): RscMenu_EASA and RscMenu_Economy both idd = 23000 (Rsc/Dialogs.hpp:3211, :3289) → findDisplay 23000 ambiguous. Assign distinct IDDs.
  • Advanced ledger UI/HUD row (Auth/PV 🟡). Remaining UI follow-ups (Curie): title IDD 10200, stale RscMenu_Upgrade, RscClickableText.soundPush[]. ready-for-review.

2026-06-02 - Claude Deep-Review Round 9 (server-loop-candidates-verify lane)

  • Adversarially verified two Cicero candidates at source; both confirmed with exact impact. New findings DR-18, DR-19.
  • DR-18 (Med): supply-cooldown key casing mismatch — Init_Town.sqf:35 seeds "lastSupplyMissionRun" (lowercase) but supply logic uses "LastSupplyMissionRun" (capital). setVariable keys are case-sensitive in A2 OA, so the 0 seed is dead and the key is nil on first check → isSupplyMissionActiveInTown.sqf:11 nil + interval throws, defeating the != 0 guard. Fix: align casing or getVariable ["LastSupplyMissionRun", 0].
  • DR-19 (Med, non-dedicated): serverFpsGUI.sqf + monitorServerFPS.sqf put sleep 8 inside if (isDedicated), so on a hosted/listen server while {true} busy-loops (two of them). Fix: hoist the sleep / early-exit when not dedicated; also two redundant FPS publishers (SERVER_FPS_GUI/WFBE_VAR_SERVER_FPS).
  • Advanced ledger Supply JIP/HC. Handoffs to code owners (both one-liners). ready-for-review.

2026-06-02 - Claude Deep-Review Round 10 (jip-headless-crosscut lane)

  • Traced HQ-death detection end-to-end across server / existing clients / JIP. New finding DR-20.
  • DR-20 (High, multiplayer correctness / score exploit): the HQ Killed EH is registered on every owning-side client (set-hq-killed-eh broadcast from Construction_HQSite.sqf:91 / Server_MHQRepair.sqf:43 + the JIP path Init_Client.sqf:500-503), but Server_OnHQKilled.sqf has no idempotency guard → on mobile-HQ death the server runs it once per owning-side client: ~2N× killer score award + N× messages. Fix: per-HQ "processed" flag in OnHQKilled (detect redundantly, act once). Keep the redundant EH registration.
  • Verified JIP detection itself is correct (the !_isDeployed guard at Init_Client.sqf:500; deployed HQ covered by the server-side EH). The defect is downstream duplication, not a JIP miss.
  • Advanced ledger JIP/HC cells (economy/construction). Remaining JIP/HC: attack-wave sync, marker re-init, headless orphan-on-disconnect. ready-for-review.

2026-06-02 - Claude Deep-Review Round 11 (headless-disconnect-review lane)

  • Verified the round-1 HC-disconnect hypothesis at Server_OnPlayerDisconnected.sqf. New finding DR-21 + a self-correction.
  • Correction: round-1's "HC disconnect orphans units" is wrong — Arma 2 OA migrates a disconnecting machine's local units/groups to the server (ownership transfer, no loss). Logged the downgrade explicitly rather than dropping it.
  • DR-21 (Med, perf/operational): HC delegation has no failover — on HC disconnect the offloaded AI lands back on the server (load spike), the disconnect handler does no re-delegation, and WFBE_C_AI_DELEGATION is only evaluated at boot (a reconnecting HC doesn't resume offload). Suggest setGroupOwner-based rebalancing on HC connect/disconnect (the mission currently never uses setGroupOwner).
  • Advanced ledger AI/Headless JIP/HC cell. ready-for-review.

2026-06-02 - Claude Deep-Review Round 12 (side-supply-delta-verify lane)

  • Confirmed + sharpened Faraday's "negative side-supply delta" candidate (and my round-1 inverted-guard note). New finding DR-22.
  • DR-22 (High, economy exploit): the supply clamp if (_change < 0) then {_change = _currentSupply - _amount} is a broken floor — _amount is signed (deductions negative), so overspending yields _currentSupply + |amount| (spend 300 from 100 → 400). Live in Server/Functions/Server_ChangeSideSupply.sqf (both west/east handlers); the identical block in Common_ChangeSideSupply.sqf is dead (PV carries _amount; server recomputes). Fix: {_change = 0}. Resistance-side handler still missing (round-1).
  • Advanced ledger Economy Auth/PV (confirmed exploit). ready-for-review.

2026-06-02 - Claude Deep-Review Round 13 (upgrade-authority-verify lane)

  • Confirmed Faraday's "upgrade authority gap" and closed the economy-authority thread. New finding DR-23.
  • DR-23 (High): RequestUpgrade.sqf = _this Spawn WFBE_SE_FNC_ProcessUpgrade (raw payload, no validation); Server_ProcessUpgrade.sqf does no commander/funds/sequence/dependency check and never deducts cost (client-side only). Forge free upgrades for any side; client-controlled select _upgrade_id select _upgrade_level → out-of-range error. Fix: validate + server-side cost.
  • Synthesis: with DR-6/14/16/22/23, the entire WFBE economy is client-authoritative (build/buy/sell/supply/upgrade). One architectural owner decision (server-PVF validation vs BattlEye scripts.txt) covers the class — piecemeal fixes won't.
  • Ledger Economy authority characterized across the board. ready-for-review.

2026-06-02 - Claude Deep-Review Round 14 (missing-reference-inventory lane)

  • Confirmed Curie's dead-dialog candidate. New finding DR-24 (Low): RscMenu_Upgrade (Rsc/Dialogs.hpp:2425) onLoad ExecVMs Client/GUI/GUI_Menu_Upgrade.sqf which doesn't exist (only GUI_UpgradeMenu.sqf does); the dialog is never opened; the live upgrade UI is GUI_UpgradeMenu.sqf. Dead/naming-drift reference — inert today. Fix: delete or repoint.
  • Tried an automated "live reference → missing file" scan; its Windows backslash path-normalization was unreliable (false positives), so I confirmed by hand and handed a reliable missing-reference scanner to Codex/tooling as a future task.
  • Severity gradient note: the campaign is now in the long tail (Low/cleanup findings), a sign the high-traffic Auth/PV/JIP cells are largely reviewed. Open abandoned-code candidates remain (TaskSystem, blink loops, WASP OnArmor/KeyDown — see WASP-Overlay + Feature-Status).

2026-06-02 - Claude Deep-Review Round 15 (ui-followups-verify lane)

  • Confirmed Curie's last two UI candidates; closed the UI follow-up items. New findings DR-25a/b (both Low).
  • DR-25a: RscOverlay (Titles.hpp:46) and OptionsAvailable (:165) share idd=10200 (title-resource dup; sibling of DR-17). Assign distinct IDDs.
  • DR-25b: RscClickableText.soundPush[] = {, 0.2, 1} (Ressources.hpp:556) is malformed (empty leading element; correct form {"", 0.2, 1} as at :92); base class so it propagates. Fix the array.
  • Ledger UI candidates closed. ready-for-review.

2026-06-01 - Codex External PDF Research Intake

  • Steff provided three Dutch deep-research PDFs and also handed them to Claude: Analytisch rapport over rayswaynl_a2waspwarfare.pdf, Analyse van rayswaynl_a2waspwarfare.pdf and Diepgaande analyse van rayswaynl_a2waspwarfare.pdf.
  • Spawned three cheap read-only PDF scouts: Sagan, Helmholtz and Parfit. Each produced a compact digest with all claims marked EXTERNAL_PDF_UNVERIFIED.
  • Added External research reports as the intake ledger. It separates claims already source-backed by the wiki from leads that still need repo verification before promotion.
  • Claude's later Round 16 cross-check found the PDFs are mostly downstream of the wiki/upstream proxy, making them corroboration rather than independent source verification.

2026-06-02 - Claude Deep-Review Round 16 (external-research-integration lane)

  • Integrated Steff's 3 deep-research PDFs (also sent to Codex). Read two in full; all are the same genre. Provenance: their citations are raw.githubusercontent.com/wiki/rayswaynl/... — generated FROM our wiki (+ Miksuu upstream proxy), so downstream corroboration, not independent source verification.
  • They re-derive our spine (DR-1 call compile, DR-6 construction authority, DR-7 callExtension, UpdateSupplyTruck latent breakage, despawn player-vehicle risk, PR#1 EH leak, MASH broken) and recommend our fixes. Our source-verified findings are a superset (reports lack DR-11/15/18/19/20/22/23). Good external validation; nothing higher-severity missed in code.
  • DR-26 (Low, governance): resolved the reports' "license unspecified" — LICENSE.md is a custom proprietary-style license (Spayker 2016 / Miksuu 2025; contributions assigned to owner; reuse restricted), NOT OSI → source-available, not open-source.
  • Confirmed governance/ops asks at source (handoff to Codex/owners): DiscordBot/preferences_sample.json ships a real GuildID + hardcoded DataSourcePath; no CI (only FUNDING.yml). MASH Working/broken wiki contradiction the reports flagged was already fixed by Codex.
  • ready-for-review.

2026-06-02 - Claude Deep-Review Round 17 (weather-daynight-review lane)

  • Reviewed Server_DayNightCycle.sqf + client receiver/animation (initJIPCompatible.sqf:174-210, Client_DayNightCycle.sqf). Clean review — no defect. Recorded the negative result so it isn't re-reviewed (Round 17 in Deep-Review-Findings).
  • Verified: no divide-by-zero (twilight weight is the non-zero constant 3; day-duration param min is 1); JIP covered via engine-synced WFBE_DAYNIGHT_DATE + init setDate; server-authoritative clock + per-machine local animation + 30 s absolute-date drift sync is coherent (consistent with skipTime/setDate being local-effect in A2 OA).
  • Ledger weather/day-night cell → reviewed-clean. Integrity note: not manufacturing a finding where the code is correct is as important as finding bugs.

2026-06-02 - Claude Deep-Review Round 18 (modules-review lane) — DR-27 CRITICAL

  • Reviewed the Client/Module/ + Server/Module/ set. Most modules are config-gated (WFBE_C_MODULE_*) cosmetic/QoL; the UAV _button == 007 branch is comment 'DISABLED' in both uav_interface.sqf:226 and uav_interface_oa.sqf:100 (confirms Feature-Status "UAV partial").
  • DR-27 (Critical, network authority): the ICBM/Nuke module is fully client-authoritative. Commander's Tactical-menu strike (GUI_Menu_Tactical.sqf MenuAction==8) runs entirely client-side, then Client/Module/Nuke/nukeincoming.sqf:23 sends ["RequestSpecial",["ICBM",side,baseObj,cruiseObj,team]]. Server/PVFunctions/RequestSpecial.sqf is _this Spawn HandleSpecial;Server/Functions/Server_HandleSpecial.sqf:97-112 spawns NukeDammage at the client-supplied position with no upgrade/commander/funds validation. The waitUntil {!alive _target} is timing-only, not a guard. One forged publicVariable = a server-applied, map-wide mass-kill. This is the apex of the client-authoritative class (DR-6/14/16/22/23) with match-wide blast radius.
  • Ledger Modules cell → Map ✅, Auth/PV/Perf/JIP-HC 🟡 (DR-27). Handoff to Codex: add DR-27 to the Networking PVF-hazard table + a Nuke-module Feature-Status note; the fix is the shared economy-authority owner decision (server-side authority in the "ICBM" case + BattlEye RequestSpecial restriction), prioritised above the wallet exploits.

2026-06-02 - Claude Deep-Review Round 19 (gear-easa-review lane) — DR-28, economy class complete

  • Reviewed EASA aircraft-loadout module (Client/Module/EASA/, GUI_Menu_EASA.sqf) + vehicle Service point (GUI_Menu_Service.sqf).
  • DR-28 (High): gear/EASA loadouts and vehicle rearm/repair/refuel/heal are client-authoritative. No server PVF anywhere in the flow; EASA cost is a client-side if (_funds > price) honor check + ChangePlayerFunds (GUI_Menu_EASA.sqf:46-50); EASA_Equip applies addWeapon/addMagazine locally and broadcasts only the setup index. Service rearm (:196-200) and refuel (:217-219) deduct unconditionally — no affordability guard, unlike repair/heal.
  • Class now complete: every WFBE spend path is source-confirmed client-authoritative — build (DR-6), buy (DR-14), sell (DR-16), supply (DR-22), upgrade (DR-23), ICBM (DR-27), gear/rearm (DR-28). One owner decision (server funds ledger vs BattlEye) covers all of them.
  • Ledger: Gear/EASA row Auth → ✅ (characterized); Economy row note extended. Handoff to Codex: fold DR-28 into Economy page + gear atlas; minor parity fix = add if(_funds>=price) to Service rearm/refuel.

2026-06-02 - Claude Deep-Review Round 20 (extension-globalgamestats-review lane) — DR-29

  • Reviewed the in-repo .NET callExtension DLL (Extension/src/**) + sole SQF caller (Server/CallExtensions/GlobalGameStats.sqf). Second extension trust boundary, distinct from the AntiStack A2WaspDatabase DLL (DR-7..DR-10, not in repo).
  • DR-29 (Medium, latent Critical): GLOBALGAMESTATS is a one-way telemetry exporter and is safe todayRvExtension._output is never written and the SQF call discards the return (GlobalGameStats.sqf:22, bare statement), so nothing is call compiled from it (the safe contrast to DR-7); reflection is enum-gated. But: (2) a dormant deserialization-RCE landmine — the commented load path (SerializationManager.cs:115-120) uses TypeNameHandling.Auto + JsonConvert.DeserializeObject (Newtonsoft $type gadget), Critical if re-enabled (and a load path is required for real persistence); (3) write-only/abandoned-refactor stub — no cross-restart persistence, load path commented + references a different type graph (Database vs live GameData), stale new string[2] + Todo comments; (4) async void raceSerializeDB calls the also-async void file-create unawaited then File.Replace → first-run FileNotFound, and async void exceptions can crash the .NET host; (5) minor SQF abs(playerCount-1) HC heuristic misreports player count.
  • Ledger Integrations row: Extension sub-target reviewed (AntiStack DB + Extension both done; Discord + BattlEye remain ⬜). Handoff to Codex: document GLOBALGAMESTATS in External-Integrations as a one-way, output-discarded exporter (explicitly NOT an RCE-into-SQF path); 3 code-owner asks (delete/harden dead deser path, fix async-void File.Replace race, fix abs(playerCount-1) + stale comments).

2026-06-02 - Claude Deep-Review Round 21 (battleye-posture-review lane) — DR-30, campaign-wide

  • Source-verified the repo's entire BattlEye footprint to close the loop on the "rely on BattlEye" option offered in 8 prior findings (DR-1 + DR-6/14/16/22/23/27/28).
  • DR-30 (High): the BattlEye mitigation is not shipped. The only BE filter in the repo is BattlEyeFilter/publicvariable.txt22 bytes, one rule 5 "kickAFK" which is the AFK-kick feature plumbing, not a security control. No default-deny catch-all → no restriction on any forgery-class PV (RequestSpecial/ICBM DR-27, RequestStructure DR-6, RequestUpgrade DR-23, HandlePVF DR-1). scripts.txt is absent (plus createvehicle/remoteexec/setvariable/setpos/mpeventhandler) → nothing in-repo blunts the DR-1 call compile RCE. A 716 KB README .docx exists but was not parsed (binary/untrusted-content rule).
  • Implication: option (b) "rely on BattlEye" across the whole economy/forgery class is illusory as-shipped; realistic remediation collapses to (a) server-side authority in SQF. Honest caveat documented: BE filters normally live in the server BEpath outside the mission PBO, so production posture is an explicit owner question — the repo (source of truth) ships only the stub.
  • Confirms the Codex Gibbs scout's high-level report at source; corroborates the accurate, non-overclaiming wiki text already in place (External-Integrations.md:60, Feature-Status-Register.md:32, Networking-And-Public-Variables.md:122).
  • Ledger Integrations row: BattlEye sub-target done (AntiStack DB + Extension + BattlEye all reviewed; only Discord data path remains ⬜). Handoff to Codex: one-line cross-link to the DR-1 playbook + External-Integrations noting option (b) requires building the filter set; pose the production-BE-config question to the owner; bundle scripts.txt/server.cfg/basic.cfg absences into a hosting-hardening owner item.

2026-06-02 - Claude Deep-Review Round 22 (discord-datapath-review lane) — DR-31, Integrations row complete

  • Reviewed the in-repo DiscordBot/ (.NET / Discord.Net) — the consumer of GLOBALGAMESTATS database.json, closing the last Integrations sub-target. Data path: Arma server → extension writes database.json (DR-29) → bot reads on a 60 s timer → status embed.
  • DR-31 (High, insecure deserialization): GameData.LoadFromFile() (GameData.cs:49-56) deserializes database.json with TypeNameHandling.All — the Newtonsoft $type gadget sink, worse than the dormant .Auto flagged in DR-29. Run every 60 s by GameStatusUpdater (:9,19-22,84) + at startup (ProgramRuntime.cs:15) + on a command (CommandHandler.cs:211), no interaction. Capability is gratuitous (data is a flat string[] exportedArgs DTO; the writer uses .None). Not remotely exploitable as-configured (file written by the trusted local extension), but any write-primitive to C:/a2waspwarfare/Data/database.json = RCE in the token-holding bot process. Trivial fix: .All → .None + delete the dead .Auto method (GameDataDeSerialization.cs:32, no callers). Closes DR-29 #2 end-to-end.
  • Secondary (Low): secret hygiene is good.gitignore excludes token.txt + preferences.json; preferences_sample.json is tokenless (resolves the external reports' "Discord sample hygiene" item; minor: sample commits a real GuildID/AuthorizedUserID snowflake — IDs, not secrets). Inbound commands are auth-gated (IsUserAuthorized, CommandHandler.cs:49,127). Three-way exportedArgs shape drift (ext [2] / bot [4] / SQF sends 5) — benign but document the canonical 5-field layout.
  • Ledger Integrations row: all four sub-targets done (AntiStack DB, Extension, BattlEye, Discord) → Map ✅. Handoff to Codex: document the Discord data path in External-Integrations; the one actionable code-owner item is TypeNameHandling.All → None; cross-link DR-29/DR-31.
  • Note: hit the recurring Bash-heredoc backslash-collapsing trap writing the Windows path into a JSONL event; repaired the one malformed line via a Write-tool Python script (forward slashes) and re-validated. Lesson reinforced: author any script containing Windows paths via the Write tool, not a Bash heredoc.

2026-06-02 - Codex PV/External Integration Batch A

  • Integrated Archimedes/James/Galileo PV findings into Networking and public variables, adding a second-pass direct-channel inventory for attack waves, side supply, supply missions, MASH markers, HQ state, AntiStack compensation, server FPS, AFK, day/night and marker/message channels.
  • Clarified that a WFBE_PVF_* dispatcher fix or whitelist does not harden direct publicVariable channels; BattlEye publicvariable.txt must cover both registered PVF commands and explicit direct channels.
  • Integrated Faraday/Claude external-integration findings into External integrations: Discord sample/config hygiene, the in-repo a2waspwarfare_Extension vs absent out-of-repo A2WaspDatabase, async file export behavior, custom/source-available license and missing CI/reference validation.
  • Folded Claude DR-27 into Networking and public variables and Feature status: RequestSpecial / "ICBM" is the highest-priority registered-command hardening target because a forged PV can create a server-applied map-wide nuke.
  • Folded Claude DR-28 into Economy, Gear/loadout/EASA and Feature status: gear/EASA/service authority is now the final confirmed spend path in the client-authoritative economy class.
  • Added matching entries to agent-status.json, agent-collaboration.json, agent-context.json and agent-events.jsonl.

2026-06-02 - Codex Cheap Explorer Wave C

  • Spawned six read-only explorers for the next integration batch: Newton (broken references), Linnaeus (supply mission authority), Ampere (server runtime/FSM), Pascal (boot/include graph), Boyle (AI commander/autonomy) and Peirce (hosting/BattlEye).
  • Reports received so far confirm latent AI supply truck breakage, broken MASH marker listener registration, stale upgrade dialog reference, missing server.cfg/basic.cfg/scripts.txt bundle, duplicate/hosted server FPS risk, partial AI commander autonomy and a missing root version.sqf boot dependency.
  • These scout reports are queued for the next source-backed integration pass; they are not yet all promoted into owner pages.

Future Agents

  • Add dated entries here before and after substantial documentation or code changes.

Continue Reading

Previous: Agent collaboration protocol | Next: Deep-review findings

Main map: Home | Fast path: Quickstart | Agent file: agent-context.json

Sidebar

Clone this wiki locally