fix(launcher): Campaign LA LA3 review fixes — contract paths omission, probe composition, graceful stop, hygiene

Opus review of LA3 returned FIX FIRST; this addresses every finding in
scope (F1-F5, F7-F12; F6 CI-lane addition excluded per instructions):

- F1 (CRITICAL): SessionProcessSettings.Paths is now nullable and left
  null by SessionConfigComposer unless a caller supplies overrides, so
  the JSON key is entirely absent instead of "paths":{} — the App-side
  loader's strict UnmappedMemberHandling.Disallow would otherwise reject
  every gui/guiSelect session-config document at load.
- F2: added SessionConfigComposer.ComposeProbe and a nullable
  SessionDescriptor.Mode field ("probe", omitted for normal play) per
  the pinned contract — no character/policy/plugins/loginCommands.
- F3: LauncherProcessSupervisor.Stop now tries
  ILauncherChildProcess.TryRequestGracefulStop (Linux: libc SIGINT via
  LibraryImport, K4-proven graceful headless logout) before
  CloseMainWindow. Windows has no reliable no-window-console equivalent
  today; filed docs/ISSUES.md #397 with the CREATE_NEW_PROCESS_GROUP +
  CTRL_BREAK fix direction. Stop()'s blocking-timeout contract is now
  documented for LA4.
- F4: LauncherProfileStore.Save chmods the Linux temp file to 0600
  immediately after creation, before any credential is serialized;
  failure paths and Load() clean up a stale .tmp.
- F5: added LauncherCoreDependencyBoundaryTests asserting Launcher.Core
  references exactly AcDream.Platform and no packages.
- F7: StatusEventParser.Parse no longer throws on a whitespace/null
  line; StatusFileTailer.ReadNewEvents swallows the File.Exists/open
  TOCTOU window (FileNotFoundException/DirectoryNotFoundException/
  IOException) instead of throwing.
- F8: Start() now kills (entire process tree) and disposes a child that
  started successfully but failed while being fed its stdin password,
  instead of orphaning it.
- F9: SetState is monotonic — once Exited, no later transition applies
  or fires StateChanged, closing a Start()-path race where a
  synchronously-exiting child could be "resurrected" to Running.
- F10: CharacterIdFormat.TryParse now requires the "0x" prefix (an
  unprefixed hand-typed decimal id is also valid hex and was silently
  misread); a parsed id of 0 is treated as unusable and falls back to
  the name selector; LauncherProfileStore.MergeRoster normalizes both
  sides through TryParse/ToHexString instead of raw string equality, so
  a legacy unprefixed-hex row self-heals via name match instead of
  duplicating.
- F11: StatusCharacterEntry.SecondsGreyedOut is now uint, matching
  CharacterRosterEntry and the host writer.
- F12: added MalformedStatusEvent, returned for a recognized `e` whose
  payload doesn't match its shape, distinguished from UnknownStatusEvent
  (an unrecognized `e`).

AllowUnsafeBlocks was added to AcDream.Launcher.Core.csproj — required
by the LibraryImport source generator's function-pointer marshalling
stub for F3's Linux SIGINT P/Invoke.

Verification: dotnet build AcDream.slnx -c Release green (0 errors);
dotnet test tests/AcDream.Launcher.Core.Tests -c Release green at 94/94
on native Windows and under WSL (Ubuntu, verified across multiple runs
for the timing-sensitive SIGINT/sharing-violation tests, no flakes
observed).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-14 16:29:39 +02:00
parent 37d74e4402
commit 26feba8186
19 changed files with 1101 additions and 105 deletions

View file

@ -135,6 +135,45 @@ public sealed class SessionConfigComposerTests
Assert.Equal("+Acdream", (string?)session["character"]!["name"]);
}
[Fact]
public void GuiModeFallsBackToNameSelectorWhenIdIsAHandTypedDecimalWithoutThe0xPrefix()
{
// Review finding F10: an 8-digit all-decimal-digit string is ALSO
// a syntactically valid hex number. Without requiring the "0x"
// prefix, this used to silently reinterpret a hand-typed decimal
// id as hex and select the wrong character; it must now fall
// through to the name selector instead of guessing.
ComposedSessionConfig composed = SessionConfigComposer.Compose(
Server(),
Account(),
Character(LaunchMode.Gui, id: "12345678"),
Install,
Paths,
sessionId: "session-gui-decimal-id");
JsonObject session = SingleSession(composed);
Assert.Null(session["character"]!["id"]);
Assert.Equal("+Acdream", (string?)session["character"]!["name"]);
}
[Fact]
public void GuiModeFallsBackToNameSelectorWhenTheParsedIdIsZero()
{
// Review finding F10: both host loaders reject `id: 0` outright,
// so a parsed-but-zero id is not a usable selector either.
ComposedSessionConfig composed = SessionConfigComposer.Compose(
Server(),
Account(),
Character(LaunchMode.Gui, id: "0x00000000"),
Install,
Paths,
sessionId: "session-gui-zero-id");
JsonObject session = SingleSession(composed);
Assert.Null(session["character"]!["id"]);
Assert.Equal("+Acdream", (string?)session["character"]!["name"]);
}
[Fact]
public void PluginsAndLoginCommandsAreOmittedWhenEmptyRatherThanEmptyArrays()
{
@ -156,7 +195,7 @@ public sealed class SessionConfigComposerTests
}
[Fact]
public void ProcessContentCarriesInstallRecordAndPathsIsAlwaysPresent()
public void ProcessContentCarriesInstallRecordAndPathsIsOmittedByDefault()
{
ComposedSessionConfig composed = SessionConfigComposer.Compose(
Server(),
@ -169,11 +208,15 @@ public sealed class SessionConfigComposerTests
JsonObject root = ParseRoot(composed);
Assert.Equal(1, (int?)root["version"]);
JsonObject process = root["process"]!.AsObject();
AssertKeys(process, "paths", "content");
// Paths is always present as an object; every member is omitted
// when unset (hosts resolve their own default ApplicationPathSet).
Assert.Empty(process["paths"]!.AsObject());
// PINNED CONTRACT (review finding F1): process.paths is OMITTED
// entirely — not an empty object — unless a caller explicitly
// supplies overrides. The App-side loader parses with strict
// UnmappedMemberHandling.Disallow and has no `paths` member of
// its own, so an emitted "paths":{} would reject the whole
// document at config load for every gui/guiSelect launch.
AssertKeys(process, "content");
Assert.False(process.ContainsKey("paths"));
JsonObject content = process["content"]!.AsObject();
AssertKeys(content, "datDirectory", "preparedAssetPath");
@ -181,6 +224,92 @@ public sealed class SessionConfigComposerTests
Assert.Equal(Install.PreparedAssetPath, (string?)content["preparedAssetPath"]);
}
[Fact]
public void NormalPlaySessionsOmitTheModeFieldEntirely()
{
foreach (LaunchMode mode in new[] { LaunchMode.Gui, LaunchMode.GuiSelect, LaunchMode.Headless })
{
ComposedSessionConfig composed = SessionConfigComposer.Compose(
Server(),
Account(),
Character(mode),
Install,
Paths,
sessionId: $"session-mode-omit-{mode}");
JsonObject session = SingleSession(composed);
Assert.False(session.ContainsKey("mode"));
}
}
[Fact]
public void ProbeModeSetsModeAndOmitsCharacterPolicyPluginsAndLoginCommands()
{
ComposedSessionConfig composed = SessionConfigComposer.ComposeProbe(
Server(),
Account(),
Install,
Paths,
sessionId: "session-probe");
JsonObject session = SingleSession(composed);
AssertKeys(
session,
"id", "mode", "endpoint", "account", "credential", "statusFile");
Assert.Equal("session-probe", (string?)session["id"]);
Assert.Equal("probe", (string?)session["mode"]);
Assert.Equal("127.0.0.1", (string?)session["endpoint"]!["host"]);
Assert.Equal(9000, (int?)session["endpoint"]!["port"]);
Assert.Equal("testaccount", (string?)session["account"]);
Assert.Equal("standardInput", (string?)session["credential"]!["provider"]);
Assert.False(session.ContainsKey("character"));
Assert.False(session.ContainsKey("policy"));
Assert.False(session.ContainsKey("plugins"));
Assert.False(session.ContainsKey("loginCommands"));
Assert.False(session.ContainsKey("loginCommandDelayMs"));
Assert.Equal(
Path.Combine(
Paths.CacheDirectory, "launcher", "sessions", "session-probe", "status.jsonl"),
(string?)session["statusFile"]);
}
[Fact]
public void ProbeModeDocumentNeverContainsThePassword()
{
AccountProfile account = Account();
ComposedSessionConfig composed = SessionConfigComposer.ComposeProbe(
Server(),
account,
Install,
Paths,
sessionId: "session-probe-pw");
string json = SessionConfigComposer.Serialize(composed.Document);
Assert.DoesNotContain(account.Password, json, StringComparison.Ordinal);
}
[Fact]
public void ProbeModeProcessSettingsMatchNormalComposition()
{
ComposedSessionConfig composed = SessionConfigComposer.ComposeProbe(
Server(),
Account(),
Install,
Paths,
sessionId: "session-probe-content");
JsonObject root = ParseRoot(composed);
JsonObject process = root["process"]!.AsObject();
AssertKeys(process, "content");
JsonObject content = process["content"]!.AsObject();
Assert.Equal(Install.DatDirectory, (string?)content["datDirectory"]);
Assert.Equal(Install.PreparedAssetPath, (string?)content["preparedAssetPath"]);
}
[Fact]
public void ComposedDocumentNeverContainsThePassword()
{