Skip to content

Fix rune socket matching and align magic server defaults - #43

Merged
XxFran10xX merged 1 commit into
mainfrom
fix/rune-socket-parity
Oct 4, 2026
Merged

XxFran10xX merged 1 commit into
mainfrom
fix/rune-socket-parity

Conversation

@XxFran10xX

@XxFran10xX XxFran10xX commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Tutorial's completed weapons had Ascedant Rune sockets, while rune items and TLibs require Ascendant Rune. Ship school rune names without rarity prefixes, bind all 40 school rune abilities (including Mitlan and the correct Quickshot handler ID), and align bundled gear, element and charging settings with Main.

Preserve the historical petty_tom32 part as a hidden compatibility entry so existing Dev/Tutorial weapons can refresh. Companion configuration PR: https://github.com/TF-Minecraft/ServerAssets/pull/39.

Validation:

  • Local and dev-host Maven clean verify: 449 tests pass; 100% line, branch and instruction coverage.
  • GitHub build passes.
  • Dev inventory tests reproduce the original typo, refresh an existing affected staff, and pass all 48 rune/socket tier combinations across staff, wand and sword (higher runes remain blocked in lower sockets).
  • Ascendant Oseni, Seithr and Mitlan rune insertion passes.
  • Reviewed the diff against current Main settings; player data, stations and class-only casts are preserved.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7603b9ce-ddde-4775-b9ab-9e6db1582ae9
📥 Commits

Reviewing files that changed from the base of the PR and between 2300f9f and c6ad873.

📒 Files selected for processing (11)
  • src/main/java/net/tfminecraft/magic/gear/GearCache.java
  • src/main/java/net/tfminecraft/magic/loader/ConfigLoader.java
  • src/main/resources/config.yml
  • src/main/resources/elements/elements.yml
  • src/main/resources/gear/archetypes.yml
  • src/main/resources/gear/orbs.yml
  • src/main/resources/gear/part-types.yml
  • src/main/resources/gear/parts.yml
  • src/main/resources/gear/socket-colours.yml
  • src/main/resources/skills.yml
  • src/test/java/net/tfminecraft/magic/BundledRuneConfigTest.java

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Summary

Summary by CodeRabbit

  • New Features
    • Added rune and skill configurations for Cerrith, Oseni, Seithr and Mitlan, including new Mitlan skills across four tiers.
    • Updated element icons and colours, and refreshed staff, wand and sword item appearances.
  • Changes
    • Socket rarity prefixes are now off by default.
    • Staff, wand and sword cores now have tier-based durability and updated attack damage.
    • Orb spawning targets and timing have been adjusted for tiers 3 and 4.
    • Tome labels now use Roman numerals, with updates to tome crafting costs and compatibility.

Walkthrough

The pull request updates bundled rune, skill, gear, and orb configuration. It changes rune types and display settings, revises skill bindings, adjusts gear part definitions, and adds tests for selected bundled YAML values.

Changes

Rune and Gear Configuration

Layer / File(s) Summary
Rune identifiers and display
src/main/java/net/tfminecraft/magic/gear/GearCache.java, src/main/java/net/tfminecraft/magic/loader/ConfigLoader.java, src/main/resources/config.yml, src/main/resources/elements/elements.yml, src/main/resources/gear/socket-colours.yml
Rune types and element display references change. Socket rarity prefixes now default to false, and ascendant rune label keys are corrected.
Skill bindings and validation
src/main/resources/skills.yml, src/test/java/net/tfminecraft/magic/BundledRuneConfigTest.java
Bindings use nested element and tier fields. Temporary bindings and Mitlan skills are added. Tests check bundled rune and skill configuration, tome sockets, and class-spell separation.
Weapon cores and gear presentation
src/main/resources/gear/parts.yml, src/main/resources/gear/archetypes.yml
Staff, wand, and sword cores gain tier-based durability values; wand and sword attack stats are set by tier. Archetype icons use MMOItems templates, and colour-suffix comments are revised.
Tome parts and names
src/main/resources/gear/part-types.yml, src/main/resources/gear/parts.yml
Tome display names use Roman numerals. Tome entries use MMOItems book references, normal tier-two and tier-three tomes are staff-only, and a disabled petty tome entry is added.
Orb tier settings
src/main/resources/gear/orbs.yml
Tier-three and tier-four live counts and targets change. Tier four also has a new ratio and window duration.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Suggested reviewers: drefvelin

Merge Risk: ⚪ Minimal · up to c6ad8

This change updates bundled rune, skill, gear and orb configuration. No concrete merge-blocking defect was found. Dev-host build and inventory integration checks, which the author reports as in progress, should finish before merge.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to c6ad8

Bundled defaults remove access permissions for five previously restricted magic elements. Players using existing meditation and attunement flows can consequently gain resonance without those permissions. Exposure depends on which configurations are deployed, and restoring permissions may not revoke resonance already gained.

Retained concerns

  • Medium · security · observed: The bundled catalog removes five element-specific authorization requirements. Once this catalog becomes active, players lacking those permissions pass the shared unlock check and can receive resonance through otherwise eligible meditation and attunement flows. This expands access beyond socket-name and presentation alignment; existing artifact, yield and tier requirements do not restore the removed authorization boundary.
Security review details

Security Blast Radius

  • inferred — The evidenced scope is player access to five magic elements and associated resonance state on each server adopting the changed catalog. Players still need access to valid meditation facilities, artifacts and available yield. Broader host privileges or cross-service compromise are not established by this trace.

Security Findings and Attack Paths

  • observed — The source-supported access path is an eligible player entering meditation, passing an unlock check whose configured permission is now absent, and receiving element resonance credit. The supplied authorization-bypass candidate nevertheless remains deferred because receipt reconciliation is unresolved; this architecture concern does not change its verification disposition.

Trust Boundaries and Controls

  • observed — Rune rebinding retains item-type, NBT and ability checks plus the existing magic.rune.keybind command permission. Those controls were not removed by the socket-default change, but they govern a different operation and do not compensate for relaxed element access.

Resilience and Maintainability Implications

  • observed — Existing refresh failure containment marks weapons broken and retains unmatched rune type-and-ID metadata instead of silently discarding every reference. Broken weapons are refused by the cast listener. The historical petty_tom32 entry preserves part resolution, but does not supply socket-color aliases; recovery depends on external item definitions remaining resolvable.

Hardening Proposals

  • proposed — Preserve the five permission requirements unless unrestricted access is an explicitly approved policy change. If relaxation is intentional, define rollback treatment for resonance earned during that window and consider an execution-time permission check for permission-restricted, element-bound spells. Validate the policy consistently across the companion server configurations.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@XxFran10xX
XxFran10xX merged commit a117171 into main Oct 4, 2026
2 checks passed
@XxFran10xX
XxFran10xX deleted the fix/rune-socket-parity branch October 4, 2026 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant