Watch
1
0
Fork
You've already forked proto
0
No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Tim Janke 10ff156171 ✨ (proto): Sign a chunk's records as they were sent
A chunk's signature covered its records re-encoded by the receiver, which only
works while both ends know exactly the same fields. Protobuf discards what it
does not recognise, so a receiver built against an older schema re-encoded
something different from what arrived and rejected the whole chunk as forged.

That turned every additive change — the one thing the schema rules promise is
safe — into a deployment order: backend first, always, with no way for the
plugin to tell.

Records now travel as bytes, exactly as the sender serialised them, and the
signature covers those. The receiver verifies first and decodes second, so a
record carrying a field it will discard still verifies. Field 4 is retired
rather than reused, as the compatibility rules require.

This change is itself the last one that needs the old ordering, because a
receiver on the old schema sees no records at all.
2026-09-07 00:56:28 +01:00
flyg/v1 ✨ (proto): Sign a chunk's records as they were sent 2026-09-07 00:56:28 +01:00
.gitignore 🎉 (proto): Add the flyg.v1 wire contract shared by the plugin and the backend 2026-08-03 06:48:38 +02:00
README.md ✨ (proto): Sign a chunk's records as they were sent 2026-09-07 00:56:28 +01:00

flyg-proto

The wire contract between the flyg X-Plane plugin and the flyg backend. Protobuf 3, optimize_for = LITE_RUNTIME, package flyg.v1.

Both sides consume this repository as a git submodule:

  • flyg-plugin-xplane12 generates C++ with protoc and the lite runtime.
  • flyg-backend generates Rust with prost.

Layout

File Holds
flyg/v1/common.proto Timestamp, LatLonAlt, AircraftIdentity, Airport, JobState, the Schema version enum
flyg/v1/telemetry.proto TrackRecord, EngineSample, SimState, AircraftSnapshot
flyg/v1/events.proto FlightEvent and FlightEventType
flyg/v1/journal.proto JournalHeader, JournalFooter, JournalRecord (samples, events, snapshots)
flyg/v1/auth.proto Device-code pairing messages and Session
flyg/v1/transport.proto Envelope and everything it carries

Compatibility rules

Field numbers are contractual. The journal on a pilot's disk and the plugin binary in the sim both outlive any single backend deploy, so:

  • Add fields with new numbers. Never renumber, never reuse a retired number.
  • A chunk's signature covers Chunk.record_bytes — each record as the sender serialised it — so a receiver built against an older schema still verifies a chunk carrying fields it will discard. Nothing else on the wire may depend on a receiver re-encoding a decoded message.
  • Never change a field's type or its meaning.
  • Never remove a field. Mark it reserved instead.
  • Bump Schema.SCHEMA_VERSION_CURRENT only for a break that the additive rules cannot cover.

SCHEMA_VERSION_CURRENT is 1.