No description
| Filename | Latest commit message | Latest commit date |
|---|---|---|
A chunk's signature covered its records re-encoded by the receiver, which only works while both ends know exactly the same fields. Protobuf discards what it does not recognise, so a receiver built against an older schema re-encoded something different from what arrived and rejected the whole chunk as forged. That turned every additive change — the one thing the schema rules promise is safe — into a deployment order: backend first, always, with no way for the plugin to tell. Records now travel as bytes, exactly as the sender serialised them, and the signature covers those. The receiver verifies first and decodes second, so a record carrying a field it will discard still verifies. Field 4 is retired rather than reused, as the compatibility rules require. This change is itself the last one that needs the old ordering, because a receiver on the old schema sees no records at all. |
||
| flyg/v1 | ||
| .gitignore | ||
| README.md | ||
flyg-proto
The wire contract between the flyg X-Plane plugin and the flyg backend. Protobuf 3,
optimize_for = LITE_RUNTIME, package flyg.v1.
Both sides consume this repository as a git submodule:
flyg-plugin-xplane12generates C++ withprotocand the lite runtime.flyg-backendgenerates Rust withprost.
Layout
| File | Holds |
|---|---|
flyg/v1/common.proto |
Timestamp, LatLonAlt, AircraftIdentity, Airport, JobState, the Schema version enum |
flyg/v1/telemetry.proto |
TrackRecord, EngineSample, SimState, AircraftSnapshot |
flyg/v1/events.proto |
FlightEvent and FlightEventType |
flyg/v1/journal.proto |
JournalHeader, JournalFooter, JournalRecord (samples, events, snapshots) |
flyg/v1/auth.proto |
Device-code pairing messages and Session |
flyg/v1/transport.proto |
Envelope and everything it carries |
Compatibility rules
Field numbers are contractual. The journal on a pilot's disk and the plugin binary in the sim both outlive any single backend deploy, so:
- Add fields with new numbers. Never renumber, never reuse a retired number.
- A chunk's signature covers
Chunk.record_bytes— each record as the sender serialised it — so a receiver built against an older schema still verifies a chunk carrying fields it will discard. Nothing else on the wire may depend on a receiver re-encoding a decoded message. - Never change a field's type or its meaning.
- Never remove a field. Mark it
reservedinstead. - Bump
Schema.SCHEMA_VERSION_CURRENTonly for a break that the additive rules cannot cover.
SCHEMA_VERSION_CURRENT is 1.