docs(discord): rows 19–20 done, Carmen enrolled live by reload; records and receipt (#1509)

Co-Authored-By: Claude Fable 5.1 <[email protected]>
This commit is contained in:
2026-09-13 19:03:53 -05:00
co-authored by Claude Fable 5.1
parent caaef941e6
commit 1267e6a0a0
5 changed files with 39 additions and 2 deletions
+33
View File
@@ -2410,3 +2410,36 @@ first start behind a brake, before any message traffic; replaced by the
supervised run as the main process and re-verified: SIGKILL recovered in
16 s with the dead lock cleared, brake held with no restart, released and
READY. The Sage seat now runs under the unit; the tmux session is gone.
## 2026-09-13 — Discord binding reload and per-user channels (#1509, QUEUE rows 19–20)
Before: the binding was read once at start, so a ceiling, channel or user
change needed brake, STOP removal, reset and start; every listed user could
post in every listed channel. After: `scripts/discord.sh reload <binding>`
validates the file, then sends SIGHUP to the live owner in `run.lock`; the
connector re-reads it and swaps `guildName`, `channels`, `users` and
`limits` in place, reading a channel that is new to the binding over REST
first. `name`, `seat`, `guildId`, `botUserId`, `tokenFile`, `engine`
and `context` are fixed for the life of the process (engine and prompt are
launched once, the token read once); a change there, an invalid file or a
channel outside the guild refuses the reload and keeps the old binding. Each
attempt is one line in `reloads.jsonl`. The unit gained `ExecReload`, so
`systemctl --user reload` does the same. A user entry may carry
`channels`, an allowlist of listed channel ids; outside it the message is
dropped as `channel-not-for-user`, threads counting as their parent.
Allowlist over deny list is a recorded choice: explicit lists are the
connector's policy and a new channel must not widen anyone's reach by
default; the cost is that a channel added later needs adding to Carmen's
list too. Tests: schema for the allowlist, `reloadDiff` per fixed key, the
authorization rows, connector reload (new user, removed channel, lower
ceiling, fixed key refused), CLI exit codes, unit render. Suite 41/41, 101
node tests.
Live, 00:03 UTC: unit reinstalled and soft-restarted (the old process had
no SIGHUP handler), READY on the new code. Carmen enrolled by a binding
edit plus `reload`: applied, users +1, no restart. An unknown key was
refused by the CLI with exit 2 and nothing signaled; a valid file with the
seat changed was refused by the process and the binding stayed; the
revert applied with no differences; `systemctl --user reload` applied.
Carmen's own first message is the remaining check. Her id is only in the
binding file.