From 249dabb41b631731268c490ab214f56aeee3a8ae Mon Sep 17 00:00:00 2001 From: Erik Date: Fri, 4 Sep 2026 11:30:36 +0200 Subject: [PATCH] docs(overhaul): authorize five S4-c2 completion attempts Start attempt 1/5 as an evidence-and-comment-only repair of a094bf2b7. Preserve behavior, assertions, shader/SPIR-V, register, package, sequential review, and no-landing-before-dual-PASS constraints. --- ...-09-01-campaign-overhaul-world-solidity.md | 1 + .../2026-09-04-s4-handoff.md | 23 ++++---- .../s4-depth-alpha-packet.md | 55 +++++++++++++++++++ 3 files changed, 66 insertions(+), 13 deletions(-) diff --git a/docs/plans/2026-09-01-campaign-overhaul-world-solidity.md b/docs/plans/2026-09-01-campaign-overhaul-world-solidity.md index fcb5597f..5a6319ef 100644 --- a/docs/plans/2026-09-01-campaign-overhaul-world-solidity.md +++ b/docs/plans/2026-09-01-campaign-overhaul-world-solidity.md @@ -677,6 +677,7 @@ Update immediately when a slice changes state. Chat is not the ledger. | S4 | — | G3 | OPEN 2026-09-03 night. Packet `docs/research/2026-09-01-overhaul/s4-depth-alpha-packet.md`: §1 records that S3 chunk 2 already delivered S4's chunk-1 latch/gate/seal scope (the latch owner, the gated flush→stamp→clear→seal block, the counted seals); what remains of chunk 1 is small and dispatched as **S4-c1** (`s4-c1.js`, worktree `s4-c1-impl` at `6385f4411`, contract = packet §6): C0 the far-punch constant — `portal_depth.vert` carries `0.99999988` = bits `0x3F7FFFFE`, retail's is `0x3F7FFFEF` (15 ULPs nearer; the depth spec's "wrong constant" row was right; lead bit check 2026-09-03) → retail's exact bits + a source pin; C1 the ±12 local-input reject at both portal-polygon producers (Ghidra table row 0x59BCD6–0x59BD28); C2 the portal-depth color-state register row (ColorWrite off vs retail's zero-alpha blend, identical output); C3 the depth truth-table Theory, the cross-frame latch test, look-ins isolated from the root latch. Chunk 2 = the two-FIFO alpha-list cutover (packet §3); chunk 3 = deletions (packet §4). G3 is S4's owner gate; the lead's S3-state G3 pre-run (20/20 frames, in the S3 row) is the baseline to diff against. | **S4-c1 ROUND 0 = `c7ab5b6d8` (Sonnet), THREE LENSES FAIL (2026-09-03 21:00–21:20):** one BLOCKING defect seen by all three — the ±12 guard's quantifier is inverted (rejects on ANY vertex on ANY plane; retail's PDB-paired bytes at 0x59BCD6–0x59BD66 reject only when EVERY vertex lies on the SAME plane) — and the LEAD's §6 paraphrase carried the same inversion (corrected in §6; lesson saved to memory: quote the decomp predicate, never paraphrase it). The production lens's DAT scan: 2,889 portal polygons carry a ±12 vertex and 2,163 EXIT polygons lie ENTIRELY on a ±12 plane — so the guard is very likely retail's never-sealed 'panel' mechanism (the #456/#465 family), which makes the PM/PC depth-event transcript comparison against the four alphadepth captures the chunk's real gate (never run in round 0). Also: the register-test gate is vacuous (no test reads the register), the manifest comment's ULP direction is inverted. C0 (retail's exact far-punch bits, verified at the binary), C2 (AD-119) and C3 (three new truth-table/latch pins, nine mutation texts) verified. FIX ROUND 1 = S4 packet §7 (`s4-c1-fix1.js`, dispatched 21:20): the four per-plane predicates at both producers with five-case T2, the seal count order, the automated PM/PC gate over the captures (a diverging pose is tagged KnownFailure and written up, never weakened), comment truth. **S4-c2 CONTRACT DRAFTED** (packet §8, 2026-09-03 21:50): two FIFO lists of 3000, the spec §4 router as one pure function, the four flush sites (the sort-cell EXIT valve as a new walk event kind), `FlushFartherThan`/AP-34/every viewer distance deleted, and the AM/FL transcript gate over the five captures (10,556 `AM` lines, all `clip=0`; `FL` by site 13,705/309/18/23) as the proof; dispatched only after c1 lands. **S4-c1 FIX ROUND 1 = `2bd353234` (Sonnet, 295 tool calls), THREE LENSES 2026-09-03 22:07–23:00: retail-faithful PASS, production PASS, gate-honesty FAIL.** Confirmed at the bytes: the four per-plane accumulators at both producers, the count-after-guard order, the PM/PC gate's reading of retail's lines; five transcript poses pass (cathedral-arrival, cathedral-leak, foundry-deep, holtburg-doorway-still) with terrace-edge tagged KnownFailure. Findings, all on that one row plus one pin gap: (blocking) the KnownFailure write-up claims the PC sequence matches — false and never evaluated (the PM assert throws first); (major ×2) the divergence is a harness initial-condition choice — seed `portalsDrawnCount` from the fixture's first observed counter and the row turns green while the two-pass priming retires; (major) T2's five cases do not discriminate 'every vertex on SOME plane' from retail's 'every vertex on the SAME plane'; (minor ×4) stale seal-path summaries, an unobservable mutation named in the F2 pin's comment, doc-comment DAT figures an independent scan does not fully reproduce, a vacuous 'register tests' gate claim. The lead's own replay of the gate at `2bd353234` with the new `cathedral-stair-arch` capture added as a sixth Fact PASSES (its seed value is 8). **FIX ROUND 2 = packet §9 (the LAST round; dispatched 23:10):** seed the counter from the fixture (one pass), compare and print both sequences together, the discriminating ±12 case, the sixth pose, comment truth. **FIX ROUND 2 = `9ba8f013e` (Sonnet; on the two cherry-picked capture commits), THREE LENSES 2026-09-03 23:10–23:38: retail PASS (byte evidence: `portalsDrawnCount` has exactly one increment site 0x59BD74 and one reset site 0x5A489E under `view_count > 0`, `forceClear` has no writer; the discriminating case is admitted by retail's four per-plane accumulators), production PASS (round-2 src diff = comment text only; no pin weakened; gates reproduce on a fresh Release build), gate-honesty FAIL on comment truth only (the terrace-edge Fact's comment claimed a PC match that seeding, not the pre-fix state, produced; the stair-arch comment states a rejection count the PM/PC tuple cannot observe; a DAT-scan comment cites a pin that does not pin). All six transcript poses PASS (terrace-edge's KnownFailure removed; seed values 0/0/1/2/2/8). **S4-c1 LANDED 2026-09-03 23:38–23:40** as `d1e3e64f6` + `5de42a12f` + `323f5a334` (cherry-picks of rounds 0–2) + `766f9e749` (the LEAD corrected the four flagged sentences — a third implementer round is barred by §5; code unchanged; owner to review). Landing gates: Release 0 warnings; six transcript Facts 6/6; hermetic 6,833/6,833; InstalledDat 249 pass / 4 known (#383 ×2, TowerAscent, #458) / 1 skip. Landing self-gates: route.txt four poses `logs/selfgate-20260903-234934-s4c1-landed-route2` (Facility panels present, mean RGB (79,20,25)); capture poses `logs/selfgate-20260903-234030-s4c1-landed-g3b` and `…-235044-s4c1-landed-g3b2` — frames 13/14/16 in band, **frame 15 (holtburg-doorway) shows an empty plane under fog TWICE** where the S3-state run `logs/selfgate-20260903-165634-g3b` showed the village. Lead read 2026-09-04: the server snapped the requested y 13.39→17.39 in every run; the CLIENT then seated the player in the house-interior cell `0xA9B4013F` at (134.07, 17.36) in both landed runs versus the outdoor cell `0xA9B40029` at (133.60, 17.39) in the S3-state run (0.46 m apart on the doorway threshold), so the frame roots from the interior cell with the eye outside — a placement/membership boundary at the doorway, not a draw change; S4-c1 touched no placement code. A pre-S4 control at `6575cfcee` (`s3-review-fix/logs/selfgate-20260904-042324-pre-s4-g3b`) produced 0 frames: the login reveal at `0xA9B40176` never went visible (#462 class) and the process exited 0xE0434352 after the graceful logout (#461 class) → INCONCLUSIVE; the A/B re-run (landed tip twice + pre-S4 once) is owed before any further self-gate is trusted at that pose. **S4-c2 DISPATCH 2026-09-03 23:41 DIED** on the account's session limit / credit exhaustion with no commit; worktree `s4-c2-impl` reset clean at `766f9e749`. Session handed to a new account 2026-09-04 morning; ACE was NOT running at hand-over (no UDP 9000 listener), so every connected gate waits on the owner starting it. **HAND-OFF 2026-09-04 morning:** `docs/research/2026-09-01-overhaul/2026-09-04-s4-handoff.md` (read order, landed state, the S4-c2 implementer dispatched ~08:35 into `s4-c2-impl`, the #464 RenderDoc plan, the Holtburg doorway A/B, owner-owed items, tooling gotchas, paste-prompt). **OWNER 2026-09-04 morning: running `766f9e749`, reports the cathedral stairwell artifact (#464) appears FIXED** — plausible mechanism = S4-c1's ±12 reject now drops the 12 hall-doorway punches retail also rejects; PROVISIONAL until the lead re-runs `route-464-tilt3.txt` at the tip and diffs frame `01-neg160` against `logs/selfgate-20260903-225434-464-tilt3` (owner client running — not launched yet). **S4-c2 IMPLEMENTER DONE 2026-09-04 09:35: `048d5b12f` in `s4-c2-impl`** (19 files, +1,697/−543): two FIFO lists + `RetailAlphaMeshRouter` + `SortCellExit` event + four flush sites, `FlushFartherThan`/viewer distance deleted; hermetic 6,855/6,855; shader classes 32/32; InstalledDat 249 pass + the 4 known + SIX new KnownFailure Facts. Implementer's own deviations for the lead to rule on: (a) C4 (EnvCell transparent subsets through the queue) NOT done; (b) AP-34 not retired but narrowed into AP-236 (EnvCell-immediate residual) + AP-237 (AlphaBlend cannot tell retail's ALPHA from the Translucent+ClipMap CLIP override; cloud GfxObj 0x01004C35); (c) G-c2's per-list drained-count dimension is KnownFailure on ALL six poses because the hermetic harness carries no mesh content — only the (site, threshold) sequence matches. REVIEW ROUND 1 dispatched. **REVIEW ROUND 1 (2026-09-04 ~10:00–10:40): retail lens FAIL** — every core predicate confirmed exact at the bytes (list select, 0xbb8 capacity, `test ah,5; jp` strict-less on both counts → 2250 drains, CLIP-then-ALPHA, rows 1–5, the four call sites, ::flush=0.75f, delay 0x0E, SortCellExit at 0x5a1a07 under the DrawSortCell gate); BLOCKING: the particle site's 'rows 1/2/4/5 unreachable' assert throws on an Opaque-classified mesh-particle batch (data-driven row 5; `TryAppendMeshDraws` filters nothing); MAJOR: the CLIP list is structurally unreachable for ordinary content (ClipMap kinds are `IsOpaque`, drawn alpha-to-coverage; 4,183/10,556 captured AM entries are CLIP) with no register row; contract C3's detail input hardcoded false while building shells reach the alpha path and the DRAIN applies the detail pass retail's replay never has (`DrawBuilding` installs `building_detail_surface` @0x0059f2eb before its flush/shell draw → row 1 immediate); `IsFirstForList` = first-since-drain where retail's `new` is per-DrawMesh-invocation (`0059d4cc/0059d4d0`; captures new=1 on 9,685/10,556); gate G-c2 all-KnownFailure → zero CI signal and zero SortCellExit drains exercised; MINOR: AP-237's cloud example is disproven (Type 0x10114 carries alpha-family bits → mask 0x02 both sides), DrawBlock cited at its loop head 0x005a18d0 instead of 0x005a17c0, 'return site' = the call address. Lead verification concurs and adds C4 (EnvCell detail-off append is bounded — `RenderTransparentOrdered` exists). **FIX ROUND 1 = packet §11 (M1–M8)**; **production/gate lens FAIL** (all four claimed gates reproduced, four mutation checks re-performed): same blocking particle throw; the count gate is unmatchable by construction (CLIP structurally empty — 75 % of cathedral-arrival's expected drains are CLIP — and per-instance vs per-subset cardinality); a THIRD production `FlushLandscapeAlpha` caller (`RetailPViewRenderer.cs:485`, the #132 outdoor-root drain) is mislabelled as retail's DrawCells flush, which never runs on an outdoor root; AP-236 REUSES an id filed and retired on main by #132; the unreachability enumeration lists masks that cannot occur; `ApplyScratchRetention` passes the entry count as the source count; §10 sequences off by one; the 'independent' router oracle is the same if-chain. Recorded as packet §11.1 (A1–A8). **FIX ROUND 1 DISPATCHED** (one Sonnet implementer in `s4-c2-impl` on `048d5b12f`, contract §11 + §11.1). **FIX ROUND 1 DONE = `cc8e5677a` (Sonnet, 2026-09-04 ~12:10; 27 files, +1,248/−352):** every M/A item reported landed — the two router throws deleted with rows 1/5 drawn immediately (particle `has_alpha` from `CMaterial::CheckAlphaValues` @0x005396a0 / `SetTranslucencySimple` @0x005396f0 — TO VERIFY), the detail-surface router input + immediate building-shell draw (AD-120) + no detail on the drain, EnvCell detail-off FIFO (one token per cell), `IsFirstForList` deleted, the six Facts split into live `AlphaFlushSites_*` (InstalledDat lane) and KnownFailure `AlphaFlushCounts_*` with the truthful three-part reason, a live valve pin through `Replay`'s SortCellExit arm, the outdoor-root `FlushLandscapeAlpha` deleted (A1) with a renderer pin, register: `~~AP-34~~` restored, AP-236→AP-238, AP-237→AP-239, new AP-240 (structurally empty CLIP list), AD-120, AP header 159 / AD 92, AP-239's real instance surface `0x08000015` on GfxObj `0x010001EC`. Implementer gates: hermetic 6,864/6,864; InstalledDat 255/10 (4 known + 6 Counts)/1; shaders 32/32; six focused classes 120/120. Lead reproduction 12:15: Release build 0 errors, hermetic 6,864/6,864. **NEXT = review round 1 of `cc8e5677a` (two lenses), then landing** — hand-off `2026-09-04-s4-handoff.md` §3 carries the exact procedure. **#464 CONFIRMED FIXED at `766f9e749` (2026-09-04 08:15 UTC+2, lead scripted route `logs/selfgate-20260904-061530-464-tilt3-s4c1`):** identical probe eye to the 2026-09-03 artifact run, solid wall above the arch, hall columns gone; matrix row 'Cathedral stairwell, camera zoomed out' = PASS (provisional). **Holtburg doorway frame RESOLVED — not render (2026-09-04 08:40): the player FALLS through the world at that pose** (probe run `logs/selfgate-20260904-063313-hd-probe`: seated in interior cell 0xA9B4013F at a floorless point, z 96 → −20 m; the frame is the terrain from below); filed **#468** (placement, tactical); route-g3b pose 15 moved to the good run's outdoor standing point in 0xA9B40029; the pre-S4 control stalled twice at login (#462 recurrence noted). | S4-c2 stop | **STOPPED UNLANDED 2026-09-04** — lead final-round contract `ac74fbd84`; evidence commit `c4cbc1d0d` in `s4-c2-impl` on `cc8e5677a`/`048d5b12f`; campaign renderer remains S4-c1 `766f9e749` | G3/G4 UNPASSED | Both sequential final lenses FAIL, so the required repair is the forbidden THIRD round. EnvCell transparent/ClipMap batches still draw in the opaque pass before FIFO submission and then redraw; CLIP/detail-immediate replay binds StraightAlpha with depth-write off rather than retail clip-test/depth-writing state; tests omit the preceding opaque call and pipeline descriptors. Source-owned EnvCell lists are unbounded under queue rejection, the claimed scan/filter/RHI 0-B evidence bypasses those paths, and AP-238/AP-240/result truth is false. Full file:line and gate record: S4 packet §13. No chunk cherry-pick, graphical gate, or soak. Resume only on explicit owner process change. | | S4-c2 owner repair | **STOPPED UNLANDED 2026-09-04** — owner-authorized implementation `a094bf2b7` is clean in `s4-c2-impl`; packet §15 is the review record | G3/G4 UNPASSED | The repaired renderer behavior passed the retail lens: exact whole-leaf pass membership, `0x08`/`0x09` CLIP, row-3 override, blend/reference/depth state, sentinel separation, detail state, rollback, allocation, AP-238/AP-240. The lens still returned FAIL: commit body omitted the required per-mutation first failures, packet mutation 5 names the wrong first assertion/address, and four source/test comments are stale. Sequential production lens therefore did not run. Correcting those items is a post-review fourth repair, which §14 does not authorize. Nothing landed or graphically gated; resume only by explicit owner process decision. | +| S4-c2 attempts 1–5 | **ATTEMPT 1/5 ACTIVE 2026-09-04** — explicit owner authority “fix those and finish these; try 5 more times”; packet §16 | G3/G4 UNPASSED | Prose/evidence-only correction on clean `a094bf2b7`: exact 0x59c821/0x59c838 attribution, mutation-5 first assertion, three stale source comments, one stale test comment, and an amended commit body enumerating all 14 mutations/first failures. No behavior, assertion, shader/SPIR-V, register, package, or gate weakening. Retail review then production/gate review sequentially; a failure consumes this attempt and produces the next exact contract. Dual PASS required before landing/self-gate. | | S5 | — | G4 | fill | --- diff --git a/docs/research/2026-09-01-overhaul/2026-09-04-s4-handoff.md b/docs/research/2026-09-01-overhaul/2026-09-04-s4-handoff.md index 37a37566..0c4c4854 100644 --- a/docs/research/2026-09-01-overhaul/2026-09-04-s4-handoff.md +++ b/docs/research/2026-09-01-overhaul/2026-09-04-s4-handoff.md @@ -97,21 +97,18 @@ every deviation gets a register row in the same commit. chamber; the zoomed-out FRONT view from the stairwell (hall arches + sky); #458's far-block admission (AD-118, 0.5 % edge-plane precision). -## 3. S4 chunk 2 — owner-authorized repair STOPPED, still UNLANDED +## 3. S4 chunk 2 — owner attempt 1/5 ACTIVE, still UNLANDED **Binding current state (supersedes the historical procedure later in this -section):** lead contract `ac74fbd84` added packet §12. Final implementation -`c4cbc1d0d` passed its implementer matrix, then both lenses failed for the -defects recorded in packet §13. The owner explicitly authorized one repair; -packet §14 is its bounded contract and lead commit `a094bf2b7` is the clean, -unlanded evidence in `s4-c2-impl`. The retail lens found the renderer behavior -correct but returned FAIL on the binding evidence/prose contract: the commit -body did not enumerate all 14 mutation failures; one packet mutation names the -wrong first assertion; one paired-binary address and four source/test comments -are stale. Exact findings are packet §15. The production lens was not started. -Because §14 grants no implicit fourth repair, no chunk commit was landed or -graphically gated. The campaign renderer remains S4-c1 `766f9e749`; G3/G4 -remain unpassed. Resume only by another explicit owner process decision. +section):** clean unlanded implementation `a094bf2b7` is behaviorally +retail-faithful but failed its first review on the evidence/prose findings in +packet §15. The owner has now authorized up to five more attempts. Packet §16 +is binding; attempt 1/5 corrects only the exact address, mutation-first-failure +record, three source comments, one test comment, and the commit body. The +implementation agent returns an uncommitted diff; the lead verifies and amends +the unlanded commit, then runs retail followed by production/gate review. +Nothing lands or graphically gates before dual PASS. The campaign renderer +remains S4-c1 `766f9e749`; G3/G4 remain unpassed. **Historical state before the final round (kept for audit; do not execute its landing procedure):** diff --git a/docs/research/2026-09-01-overhaul/s4-depth-alpha-packet.md b/docs/research/2026-09-01-overhaul/s4-depth-alpha-packet.md index 50a8b4b6..6d7094a3 100644 --- a/docs/research/2026-09-01-overhaul/s4-depth-alpha-packet.md +++ b/docs/research/2026-09-01-overhaul/s4-depth-alpha-packet.md @@ -1015,3 +1015,58 @@ would be a post-review fourth repair. §14 explicitly grants no implicit fourth round, so the implementation remains unlanded, the campaign renderer remains S4-c1 `766f9e749`, and G3/G4 remain unpassed. Resume only by another explicit owner process decision. + +## 16. Owner-authorized evidence/prose repair budget (2026-09-04) + +The owner replied: “Ok but fix those and finish these. You can try 5 more +times.” This explicitly authorizes up to five additional bounded +implementation-plus-sequential-review attempts for S4-c2. It does not weaken +the retail/binary verification, dual-review, landing, graphical-gate, ledger, +or no-merge-before-G4 rules. Attempt 1/5 starts from clean unlanded +`a094bf2b77c3061288185f069fa0b5e494ee8540`; the campaign branch remains on +S4-c1 until a complete attempt receives retail PASS followed by production/ +gate PASS. + +### 16.1 Attempt 1/5 contract — evidence and comment truth only + +Make exactly the retail lens's §15 corrections; no renderer behavior, shader +instruction, SPIR-V, test assertion, register row, package model, or gate is +weakened or changed: + +1. In the §12 result, attribute `SetAlphaTestEnable` to `0x0059c821` and + `SetAlphaTestFunction(GREATER_EQUAL)` to `0x0059c838`. +2. Correct mutation 5's actual first failure: after `<` becomes `<=`, the + preceding `Assert.Contains("if (color.a < alphaCutoff) discard;")` fails + because the required source spelling is absent. Do not claim the later + `Assert.DoesNotContain` is first. +3. Update `mesh_detail.vert`: exact `uParamB=1` selects the building/object + category; EnvCell zero and CLIP 100/255 or 200/255 select the bound + environment category, and the fragment shader consumes the CLIP values. +4. Update `EnvCellRenderer.Rhi.cs`: the opaque environment-detail replay is + for the already-filtered opaque shell commands; transparent ClipMap is + excluded and takes its immediate/delayed CLIP path with its own detail + contribution. +5. Update `ParticleRenderer.Rhi.cs` from “five pipelines” to the exact six. +6. Update `RetailAlphaMeshRouterTests.cs`: ordinary Wb reconstruction still + owns AP-239, while mesh particles genuinely call + `MaskFromTranslucencyKind`; do not claim production never calls it. +7. The lead amends the unlanded implementation commit so its body names all + fourteen owner-repair mutations and each actual first failing assertion, + using the corrected mutation-5 ordering above. The implementation agent + returns an uncommitted diff and does not amend or commit. + +Allowed implementation files are only the four source/test files named above +plus this packet (five files total). `git diff --check`, Release build, the +exact focused source/comment +and behavioral tests, shader/manifest tests, and the two real 0-B allocation +pins must remain green. The unchanged 16,735/16,735 hermetic and 255/10/1 +InstalledDat evidence may be reused only if the diff remains prose-only; +otherwise rerun the affected complete lane. No graphical client runs from an +implementation/review worktree. + +Review attempt 1 sequentially: retail/evidence lens first, then production/ +gate lens only on PASS. A finding consumes attempt 1 and returns to the lead, +who writes the next bounded contract against that exact finding; up to four +further attempts remain. Dual PASS authorizes landing the full S4-c2 stack, +fresh campaign Release/hermetic/InstalledDat gates, then the graphical and +stationary-soak gates. G3/G4 remain unpassed until those steps finish.