srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/data/packs/hacking.json
AgeCommit message (Collapse)AuthorFilesLines
2026-01-14Make every passage long enough to be worth timing, and credit all of themsrdusr1-1/+57
The dataset's median passage was 69 characters, about twelve words, which is over in twelve seconds at an ordinary speed. Some packs were worse: shell had a median of 46 and a shortest entry of 17. That is the reason packs felt small. It was not the number of entries, which was 15 to 37 per pack, but the length of each one. Multiplayer had already hit this and worked around it: load_race_texts filters to 120 characters or more. That filter left only 61 of 350 passages eligible, 38 of them from two packs, so races repeated constantly and four packs could never come up at all. Both halves are fixed. Content: 104 longer passages added across every pack. The command packs get whole pipelines rather than single flags, which is how the tools are actually used and what the explanations were always for. Prose packs get passages that run 150 to 320 characters. Selection: a floor of 120 characters. Prose packs draw from their long entries where a pack holds at least five, so no pack is reduced to the same few passages. The command packs chain consecutive entries into one drill, which is the natural shape for them, and the explanations are collected so each line is still described. Measured over 400 draws per pack, every category now runs a median of 146 to 218 characters with a shortest draw of 120. The race pool went from 61 of 350 to 130 of 454. Attribution: 24 passages had none and displayed nothing at all under the text. They now say Unknown, which is the honest answer for a fact written for the pack, and the pangram is credited as one. The results and typing screens both fall back to Unknown rather than rendering an empty line, and the pack name is shown beside the source. Multiplayer results, three fixes: - PB never appeared. A race has no mode of its own, so modeKey was undefined, so recordResult never ran. Races share one key, because the passage is whatever the server dealt and a per-passage best would never be beaten. - Play Again started a solo test. A race carries standings and a solo run does not, so the results screen can tell them apart and now queues for another race. The end screen's own cleanup leaves the old room first. - CONSISTENCY was the longest label on the screen and made the accuracy column wider than the WPM column opposite it. It reads CON. RaceText carries the pack name so the results can show it for a race the same way single player does. 24 Rust tests and 3 browser tests pass.
2025-12-07Rebuild the generic packs, add shell and sysadmin, fix short race passagessrdusr1-23/+212
The packs were not proper. An audit found 86 of 253 items (33%) carrying an attribution that just restated the category - prose *about* a topic with an invented source, which is the same fault the movies pack had. Six of thirteen packs were mostly that: technology had 15 items and one distinct attribution. - science, technology, history, nature and business are now sourced quotes with real attributions: Feynman, Curie, Hopper, Dijkstra, Lincoln, Carson, Drucker, Goodhart. 82 items, all attributed to a person or a work. - general is original factual prose, so it now carries no attribution at all rather than claiming "General knowledge" as a source. merge_packs no longer invents one from the pack's filename. - Four explanatory passages in philosophy lost their "Philosophy" attribution for the same reason. - One duplicated passage removed. Generic attributions: 86/253 before, 0/349 now. New technical packs - shell: 24 awk, sed and pipeline drills, each explaining what the line does - field splitting, associative arrays, !seen[$0]++, process substitution, xargs -0, strict mode. - sysadmin: 24 operational one-liners across systemd, disk, processes, network, permissions, SSH, backup and containers. - programming grew to 37 and hacking to 30, with git bisect, window functions, EXPLAIN ANALYZE, certificate transparency and capability audits. - All 115 technical drills carry an explanation. Race passage length - Multiplayer drew from the same pool as single player, so a race could land on a 22-character quote and be over before anyone had their hands in position. Races now require 120 characters; the filter is applied when the pool is loaded, not to the packs, since a short quote is fine to type alone. For reference, TypeRacer organises by difficulty and language rather than topic: one default English pool of ~11,900 texts plus per-language universes and specials (accuracy, repeat, easytexts, anime). Their scale comes from user submission with moderation, which is still the feature this does not have.
2025-12-07Move the server to PostgreSQL, harden the lyrics proxy, add a hacking modesrdusr1-0/+24
PostgreSQL - sqlx switched from the sqlite feature to postgres; the server now runs on Postgres 18 and the SQLite file is gone. - 95 placeholders renumbered from ? to $N. - REAL widened to DOUBLE PRECISION: Postgres REAL is float4 and will not decode into the f64 the code reads. - flagged and is_bot are real BOOLEANs rather than 0/1 integers, with the decode side reading bool. - The leaderboard's derived table gained the alias Postgres requires, its flag comparisons became boolean predicates, and INSERT OR IGNORE became ON CONFLICT DO NOTHING. - u32 binds cast to i64; Postgres has no unsigned integer types. - Integration tests run against a real database - Postgres has no in-memory mode - each in a throwaway schema, with search_path set per connection because it is session state and the pool opens more than one. - Timestamps stay TEXT for now and LISTEN/NOTIFY is still unused; both are recorded in TODO-postgres.md rather than left implied. Custom text and lyrics, checked rather than assumed - Custom files never reach the server: they are read in the browser through the File API, so there is no upload, no path handling and no remote file inclusion to have. Verified by driving a hostile file - markup in the body and in the filename - all the way onto the typing screen: it renders as literal characters, no nodes are created, nothing executes, and the filename is escaped in the attribution too. - That test found a real regression: picking Custom from the new mode picker selected it without ever starting it, so the mode was unstartable. - /api/lyrics fixes its upstream host, so it cannot be pointed elsewhere, but it was an unbounded relay: now rate limited per IP, with length caps on artist and track and a ceiling on the response body it will read. Hacking mode - 22 single-line drills across recon, web, memory safety, exploit development, crypto, post-exploitation and defence, each syntax highlighted and each explaining what the line actually does. All 19 modes verified to start, render and be typable.