Skip to content

Game Bridge v0.2: prompt → spec → playable preview → export #45

Description

@zedarvates

Outcome

Close the largest product-UX gap identified after comparing StoryCore with prompt-to-game builders: turn a short prompt into a reviewable public game specification, launch an explicit local playable preview, then create a deterministic source export.

Target flow:

prompt + bounded options -> editable draft spec -> strict validation -> trusted local Godot preview -> deterministic export

This is a separate v0.2 slice. Do not expand or merge draft PR #44 as part of this issue.

Dependency and promotion gate

Public architecture

Reuse the existing desktop shell instead of creating a second application:

  • React workspace under creative-studio-ui/src;
  • Electron IPC for local filesystem and process boundaries;
  • src/game_bridge remains the validating/compiling authority;
  • Godot remains a non-authoritative consumer of the compiled manifest.

The first public drafting adapter is deliberately bounded and honest:

  • local-template converts a prompt plus explicit fields (locales, title, world, actor, drop-loop parameters) into contract v0.1;
  • it supports the original rune-drop fixture family only;
  • identical normalized input produces identical draft/evidence;
  • any future model/provider adapter is replaceable and its output is treated as untrusted until strict contract validation passes.

No claim of general text-to-any-game generation is allowed in v0.2.

UX states

  1. Describe — prompt, locales and bounded gameplay options.
  2. Review — editable structured fields plus JSON view.
  3. Validate — exact field-path errors; never silently repair or discard unknown data.
  4. Preview — user-triggered launch with a user-selected trusted Godot 4 executable.
  5. Export — reproducible source bundle with specification, manifest, evidence and Godot project.

Browser-only mode may validate and export but must clearly explain that local playable preview requires the desktop shell.

Security and authority rules

  • no credentials, accounts, billing, hosted inference or network publishing;
  • no private commercial server, internal orchestration, reasoning modules, algorithms or provider adapters;
  • never pass user input through a shell command;
  • spawn the trusted Godot executable with a fixed argument vector, timeout and bounded log capture;
  • keep input/output under an explicitly selected workspace; reject traversal and symlink escapes;
  • treat the Godot process and all generated/model output as non-authoritative;
  • no automatic execution of downloaded projects;
  • no public-fork code on self-hosted runners carrying personal, signing, deployment or production credentials;
  • production authority may connect later only through the public external-contract boundary.

Deterministic export

Export a source-only bundle containing:

  • storycore_game_spec.json;
  • storycore_game_manifest.json;
  • storycore_game_evidence.json;
  • the public Godot template;
  • an export manifest with file paths, SHA-256 digests, contract/compiler version and declared license.

Use stable file ordering, normalized line endings and normalized archive timestamps. Do not bundle Godot binaries, model weights, generated private media or third-party assets.

Acceptance criteria

  • one bilingual prompt completes Describe -> Review -> Validate -> Preview -> Export;
  • the resulting spec passes the strict feat(game-bridge): add deterministic StoryCore-to-Godot contract fixture #44 compiler without coercion;
  • invalid/unknown fields produce actionable path-specific errors;
  • the same normalized inputs produce byte-identical spec, manifest, evidence and export digest;
  • Electron preview uses no shell and rejects untrusted executable/workspace paths;
  • the preview verifies the embedded manifest hash before play;
  • automated full-quest smoke prints STORYCORE_GAME_SMOKE_PASS;
  • exported files contain no credential, private component, provider implementation or third-party asset;
  • UI tests cover keyboard flow, validation focus and EN/FR strings;
  • IPC/path tests cover absolute paths, .., unexpected characters and symlink escapes;
  • an isolated trusted Godot run confirms import, parse and full-quest smoke;
  • a human reviewer signs off the public/private boundary;
  • MIT/ISC repository metadata is reconciled before release.

Non-goals

  • general-purpose AI game generation;
  • automatic repair loops, autonomous agents or hidden prompt rewriting;
  • embedded web export, hosting, deployment or marketplace publishing;
  • multiplayer/MMO/server authority;
  • asset generation, 3D reconstruction or provider benchmarking;
  • temporal/VLM video validation, which remains tracked separately in StoryCore: preview-time temporal validator and Dhee architecture audit #38.

Exit condition

A new user can enter a bounded game prompt, inspect every generated field, obtain explicit validation evidence, play the local fixture, and export a reproducible source bundle without an account, network call, private backend or proprietary component.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions