docs: contract #477 synchronization repair from native validation

This commit is contained in:
Erik 2026-09-05 11:25:52 +02:00
parent 8fd5e434b6
commit 29730506c5
6 changed files with 330 additions and 2 deletions

View file

@ -94,6 +94,15 @@ No driver replacement, TDR-delay changes, skipped waits or forced recovery.
Exact stack, hashes, local Windows report and limits:
`research/2026-09-01-overhaul/475-owner-regate.md`.
One bounded core+sync validation run at8fd5e434b completed/exit0 but FAILS
three proven dependency families: acquire-to-layout transition, sampleable
MSAA depth/stencil resolve masks and terrain buffer grow/copy transfer reads.
Ten capped reports per family; no driver reset reproduced. Lead verified
production sites and Khronos rules. `research/2026-09-01-overhaul/477-validation-reproduction.md`
records exact evidence; `477-gpu-synchronization-contract.md` binds the repair.
Eliminating these hazards is necessary API correctness, not proof that the
original AMD reset has only this cause.
## #476 — First post-resize graphical gate PNG is horizontally corrupted
**Status:** OPEN, observed2026-09-05 during #474 regression; capture-lifetime

View file

@ -713,7 +713,7 @@ Update immediately when a slice changes state. Chat is not the ledger.
| S5-#470 | **LANDED + REVIEW-CLOSED 2026-09-05; LEAD GRAPHICAL A/B PROVISIONAL PASS.** Campaign implementation stack `15a796c3a` -> `7506e5f14` -> `b333edb4f`; route `19b44e5e3`; reviewed scratch `51f974da4` -> `2cad9c84` -> `98c004aa7`; packet §§2730. | G4 UNPASSED | Retail/behavior pass 2/10 and production pass 4/10 closed the two evidence-only findings. Fresh campaign Release 0W/0E and focused 48/48; exact scratch hermetic 16,976/16,976 and canonical InstalledDat 386/10/1, manifests 30/30. Pinned gate `logs/selfgate-20260905-032132-s5-470-pinned-shadow-ab-r1`: retail/off -> High -> retail/off, 3/3 PNGs, exit 0, graceful, no client; visual PASS provisional. The stale recipe-8 pre-route launch is excluded and recorded in §30. |
| S5-#469 | **LANDED + REVIEW-CLOSED 2026-09-05; LEAD GRAPHICAL TRANSITION PROVISIONAL PASS.** Contract `809887524`; reviewed scratch `c09b6cf0f`; campaign implementation `94ddde69a`; route `62efc72cb`; packet §§3132. | G4 UNPASSED | Retail/deviation pass 1/10 and production pass 2/10 both PASS with no finding. The two atmospheric vertex receivers keep retail's authored unnormalized `uLights` direction across every shadow gate; celestial direction remains for opt-in shadow/volumetric projection; IA-24 corrected in the same commit. Exact scratch: Release 0W/0E, focused 126/126, Vulkan 2/2, hermetic 16,983/16,983, InstalledDat 386/10/1. Fresh campaign Release 0W/0E, focused 82/82, Vulkan 2/2. Gate `logs/selfgate-20260905-040449-s5-469-lighting-transition-r1`: five PNGs, active 2,500-caster/four-cascade High rows, no near-black relight, exit 0/graceful, no client; visual PASS provisional. |
| S5-c5 | **CLOSED + LANDED 2026-09-05; LEAD GRAPHICAL SMOKE PROVISIONAL PASS.** Contract `b77989c32`; campaign `bf53e2ad6` -> `e625dc4e6` -> `1b7ee4e58`; reviewed scratch tip `158656f0d`; packet §§3335. | G4 UNPASSED | Retail/deletion pass 1/10 PASS. Production pass 2/10 found one static-field hole in the owner guard; fix round 1 reproduced both static-owner mutations, and production pass 3/10 PASS. Exact scratch hermetic 16,921/16,921, canonical InstalledDat 368/9/1, manifests 30/30. Fresh campaign Release 0W/0E, App 146/146, Core 8/8. A stale recipe-8 preflight is excluded; a non-destructive recipe-10 bake produced 2,237,865 keys with zero failures. Corrected gate `logs/selfgate-20260905-052130-s5-c5-landed-v10`: five PNGs, exit 0/graceful, no fatal/deleted-prefix match, no client left; geometry matches S5-c4, visual PASS provisional. |
| S5 | **#473 EXTERIORS OWNER-ACCEPTED; #474/#475 LANDED + REVIEW-CLOSED; recall timing narrowly OWNER-ACCEPTED. Latest owner gate FAIL on #477#481 (2026-09-05).** #475 `de427d2c0`; c1c5 plus #470/#469 landed. | G4 FAIL / UNPASSED | Packet §§7 and1249 bind. #474 `220bda797` repaired the publication/placement ACK cycle. #475 exact eleven-file return `ab989d717` is blob-identical to integration `de427d2c0`, including architecture/AD-2; one test-only fix round, both review lenses closed. Lead independent Release0W0E, hermeticRuntime1891/1891, Headless48/48, App297/297; evidence `475-lead-verification.md`. Fresh campaign Release0W0E; owner-requested clean-binary run PID26920 completed five reveal generations but CRASHED with ErrorDeviceLost/Windows LiveKernelEvent141 while owner jumped in Neftet (#477). Network logout cleanup is NOT successful process exit. Other owner findings: dark Town Network/dungeons (#478), hanging Rynthid partly shifted (#479), invisible wielded items (#480), initial low FPS (#481). Recall timing seems OK per owner, not an exact benchmark. `475-owner-regate.md` records hashes/logs/events and limitations; no PNG this round. Owner AFK authorizes autonomous continuation. First priority crash diagnosis; four-agent maximum, OpenAI only, no client/build overlap. Both clients absent, ACE UDP9000 PID13340 up at11:09+02, recheck before action. No current root-cause or repair claim for #477#481. Still owed: exact nine-hop timing repeat, separate confirmed #476 capture-before-submit repair, preserved C1c nine-file test/doc landing (both reviews closed; lead68/68), §45 real geometry/membership witness, full canonical lanes/C2 and owner G4. Never merge main before G4. |
| S5 | **#473 EXTERIORS OWNER-ACCEPTED; #474/#475 LANDED + REVIEW-CLOSED; recall timing narrowly OWNER-ACCEPTED. Latest owner gate FAIL on #477#481 (2026-09-05).** #475 `de427d2c0`; c1c5 plus #470/#469 landed. | G4 FAIL / UNPASSED | Packet §§7 and1249 bind. #474 `220bda797` repaired the publication/placement ACK cycle. #475 exact eleven-file return `ab989d717` is blob-identical to integration `de427d2c0`, including architecture/AD-2; one test-only fix round, both review lenses closed. Lead independent Release0W0E, hermeticRuntime1891/1891, Headless48/48, App297/297; evidence `475-lead-verification.md`. Fresh campaign Release0W0E; owner-requested clean-binary run PID26920 completed five reveal generations but CRASHED with ErrorDeviceLost/Windows LiveKernelEvent141 while owner jumped in Neftet (#477). Network logout cleanup is NOT successful process exit. Other owner findings: dark Town Network/dungeons (#478), hanging Rynthid partly shifted (#479), invisible wielded items (#480), initial low FPS (#481). Recall timing seems OK per owner, not an exact benchmark. `475-owner-regate.md` records hashes/logs/events and limitations; no PNG this round. Owner AFK authorizes autonomous continuation. First priority crash diagnosis; four-agent maximum, OpenAI only, no client/build overlap. Both clients absent, ACE UDP9000 PID13340 up at11:09+02, recheck before action. One core+sync validation run at8fd5e434b exited0 but reported three proven GPU dependency faults (30 capped messages): acquire transition, depth/stencil resolve and terrain migration. `477-validation-reproduction.md` records hashes/PNG FAIL/partial PASS; `477-gpu-synchronization-contract.md` binds the next repair, not yet implemented. Original AMD reset attribution remains unproven. #480 cold-cache publication omission is statically identified; #478 needs High/Classic comparison; notes `478-480-readonly-diagnosis.md`. Still owed: exact nine-hop timing repeat, separate confirmed #476 capture-before-submit repair, preserved C1c nine-file test/doc landing (both reviews closed; lead68/68), §45 real geometry/membership witness, full canonical lanes/C2 and owner G4. Never merge main before G4. |
---

View file

@ -0,0 +1,143 @@
# #477 — repair three observed GPU synchronization dependencies
Lead contract2026-09-05. **NOT IMPLEMENTED.** Base is the commit containing
this contract, on the campaign's reviewed renderer stack after `de427d2c0`.
One OpenAI implementer, then lead verification and sequential API/behavior
and production/lifetime lenses. No more than the owner's ten review passes;
each code finding gets a bounded fix round. No main merge before G4.
## 1. Objective and evidence boundary
Eliminate the three native synchronization hazards in
`477-validation-reproduction.md` without changing scene membership, draw
order, shaders, quality, streaming budgets, frame pacing or resource lifetime.
These are demonstrated Vulkan API defects. Their role in the owner's AMD
watchdog/device loss is not yet proven; do not promise this contract alone
fixes the reset. #478#481, #476 screenshot lifetime and the exact #475 timing
route stay separate. In particular, do not hide the first-frame malformed
image by dropping it or adding a delay.
This chunk adds no AC-specific algorithm or new claimed retail behavior.
Retail scene/walk/alpha ordering and all existing register deviations remain
unchanged. The following primary API sources govern these native dependencies:
- [Khronos render-pass specification](https://docs.vulkan.org/spec/latest/chapters/renderpass.html):
fixed-function resolves use color-output stages/access masks for both color
and depth/stencil attachments.
- [Khronos submit reference](https://docs.vulkan.org/refpages/latest/refpages/source/VkSubmitInfo.html):
acquired-image layout transitions must chain to the semaphore wait stage.
- [Khronos synchronization specification](https://docs.vulkan.org/spec/latest/chapters/synchronization.html):
dependent memory accesses and layout transitions need execution and memory
dependencies. In-queue order alone is not a transfer-write/read barrier.
Lead read these primary sources and the production native structures before
contracting. No new named-retail/paired-binary claim is inferred from Vulkan.
Any implementation deviation must be reported and registered in its landing
commit; expected new intentional retail deviations: none.
## 2. Bounded scope
Required production sites:
- `src/AcDream.App/Rendering/Gpu/Vk/VulkanGpuDevice.Resources.cs`:
TransitionBackbufferForRendering, depth-resolve entry and sampling exit.
- `src/AcDream.App/Rendering/Gpu/Vk/VulkanUploadQueue.cs`:
native device-buffer migration dependency at queue recording.
- `VulkanGpuDevice.cs` only if needed to share the already-existing acquire
wait-stage value with the actual barrier; no frame-lifetime or error-policy
redesign. Passive native-barrier construction helpers are permitted if
directly consumed by production and needed for genuine tests.
- Focused App Vulkan tests under `tests/AcDream.App.Tests/Rendering/Gpu/Vk/`;
reuse current test infrastructure. Relevant architecture paragraph/comments.
No edits to Runtime, terrain allocation policy, shader/SPIR-V, capture path,
quality/settings, package/DAT format or other worktrees. No second queue owner,
general recorder framework or synthetic model pretending to be production.
Do not introduce a device-idle wait, change semaphore/timeline ownership, or
replace narrow dependencies with new ALL_COMMANDS/ALL_MEMORY barriers.
Existing unrelated masks are not a license for a broad synchronization rewrite.
## 3. Required behavior
### A. Acquired-image execution dependency
The first swapchain transition currently sources TopOfPipe, while the submit
wait uses ColorAttachmentOutput. Chain the transition to that real wait.
Preserve first-use SrcAccess=None, Undefined->ColorAttachmentOptimal,
queue-family-ignored/color subresource, and later-pass read/write content
preservation. The same production helper serves ordinary world and filmic
presentation; both remain supported. Do not change the presentable image's
ownership, acquire timeout, pacing or first-use discard semantics.
### B. Sampleable MSAA depth/stencil resolve dependency
Use ColorAttachmentOutput/ColorAttachmentWrite for the single-sample depth
resolve destination's entry dependency and its sampling-exit source.
Retain Early|LateFragmentTests/DepthStencilAttachmentWrite for ordinary
non-resolved depth. Cover 1x sampleable depth, multisample non-sampleable
depth and 4x sampleable resolved depth. Keep image identity, both aspects,
layouts, SampleZero resolve mode, sample counts and fragment sampling masks
unchanged. Do not treat the multisample attachment and resolve result as the
same writer just because both carry a depth format.
### C. Device-buffer grow/copy dependency
Before a migration copy reads device-buffer data, make preceding transfer
writes visible to that transfer read. This must work when upload and growth
are in the SAME drain, A->B->C migration chains are in one drain, and the
producer was recorded in an earlier drain/frame on the same queue.
Adding TransferRead only to the trailing consumer barrier is insufficient.
Retain exact ordered copy ranges and the existing draw/shader visibility
barrier, stage-buffer lifetime, completion-serial retirement and queue clear.
Distinguish device migration from independent host-staged writes so the fix
does not put a new global barrier before every ordinary staging copy.
No unbounded dependency/history map or per-frame duplicate copy ownership.
## 4. Proof and mutations
Tests must inspect native structures produced by the actual production
construction/recording path. If passive helpers are extracted, bind their
real call sites and command order using the project's existing source/IL
guards plus effect-discriminating mutations; testing an unused helper is not
proof. Prefer a narrow production seam to a new test GPU framework.
- Acquire: native barrier and actual semaphore-wait stage agree; first and
subsequent pass masks/layouts/access preserved; ordinary/filmic callers.
- Depth: distinguish the three configurations above; assert entry AND exit,
exact image/aspects/layout, ordinary depth masks unchanged.
- Copy: stage->migration, A->B->C and across-drain/frame producers; barrier
must precede dependent read, with exact source buffer/range where scoped.
Independent staging stays batched and the original draw visibility remains.
Use real production queue recording or a narrowly extracted recording body
that production actually invokes, not a separately reimplemented planner.
- Existing frame-flight, memory/ring, swapchain, world-pass and Vulkan rendering
tests remain green; zero new skips or changed tolerance/quality expectations.
Perform four separate actual-production mutations: restore old acquire source
stage; restore old resolve entry masks; restore old resolve exit masks; remove
the pre-migration dependency. Each must fail its intended assertion, not build
or setup. Restore exact raw source hashes after each cycle and rebuild green.
Return commands, TRX/output paths and hashes. Lead repeats discriminating
checks before accepting, then the two independent review lenses.
## 5. Execution and graphical closure
Use a fresh exact-base scratch on a `codex/` branch. Keep the existing #475,
#474 and C1c scratches untouched. Only the lead commits/integrates. Before
EVERY build/test or launch, check AcDream.App and retail absence; no tests
beside a running graphical client, even in another worktree. No agent launch
or debugger attachment; lead owns one graphical process at a time.
Implementer returns Release 0W0E, new/affected tests, exact source list and
production hashes, four mutation results with restoration, and a compact
report. No full-solution PASS is claimed from a focused lane. No new test
framework, ignored findings or undocumented scope expansion.
After lead verification/reviews and integration: fresh Release build, ACE9000
up, neither client running, repeat the committed bounded Neftet route with
core+sync validation (`VK_LAYER_VALIDATE_SYNC=1`), same quality/resolution.
All three hazard families must disappear; inspect any new message instead of
filtering it. Preserve every PNG and report PASS/FAIL with paths, provisional
until owner inspection. A clean validation run is API evidence, not proof
that the original AMD TDR cannot recur. Retain later ordinary (uninstrumented)
Neftet movement/portal/performance and full owner-G4 obligations.

View file

@ -1,6 +1,7 @@
# #477 — one bounded GPU validation reproduction
Prepared2026-09-05; **NOT RUN YET.** No production behavior change. This is a
2026-09-05; **RUN COMPLETE: synchronization FAIL, no crash reproduced.**
No production behavior change. This is a
diagnostic recipe under the owner's AFK continuation authorization, not a
repair contract, new review round, timing benchmark or G4 PASS.
@ -62,3 +63,71 @@ run does not close #477; preserve the first-failure propagation defect and
choose the next narrow diagnostic based on evidence. Do not enter an
unbounded sequence of GPU-reset reproductions. Other owner findings and the
remaining campaign gates stay open.
## Run r1 results
Clean source `8fd5e434b68dd808ac45d16f73b612b2bef7978d`; production files
unchanged from reviewed `de427d2c0`. Fresh Release 0W0E/exit0,21.06s.
App.exe SHA256 `E37EC4579456295231440CA209F9EFA42074E435D73F071F013DEC8B5624F4C9`;
App.dll `E3D29F7C7D547997AEED03AF4C5DDD307CBF30460E43C6FFA4184FFBFFDE6F23`.
Recipe10 package unchanged. Exact command/environment above; actual High
near4/far25/MSAA4/A2Ctrue/aniso16/completions4 confirmed by startup output.
Run: `logs/selfgate-20260905-111914-477-neftet-validation-r1/`, PID12428,
started09:19:14.370058Z, final checkpoint09:20:15Z. Runner and client exit0,
route complete, graceful logout requested/confirmed, no unhandled/device-loss
or incomplete-shutdown match. Both clients absent on privileged post-check;
ACE9000 PID13340 up. No debugger attach, concurrent build/test or second run.
The layer explicitly reports the deprecated synchronization flag and its
replacement `VK_LAYER_VALIDATE_SYNC=1`: validation really loaded. Use the
replacement on future runs. No global settings were changed.
Thirty reported errors, ten per message ID (the layer caps repeats):
| Hazard | Actual operation | Confirmed production defect |
|---|---|---|
| WRITE_AFTER_READ | First swapchain-image layout transition vs acquire; vk-world and atmospheric-filmic | `TransitionBackbufferForRendering` uses TopOfPipe source while submit waits acquire at ColorAttachmentOutput |
| WRITE_AFTER_WRITE | Atmospheric sampleable MSAA depth/stencil resolve entry and exit transition | Both barriers use ordinary depth-test writer masks, but the fixed-function resolve writes at ColorAttachmentOutput/ColorAttachmentWrite |
| READ_AFTER_WRITE | Terrain vertex/index buffer migration reads previously copied data | Upload drain lacks transfer-write to transfer-read dependency before a migration copy, including same-drain growth |
Lead read the native error messages and independently checked the named
production barriers, submit wait and upload-copy loop. The source diagnosis
matches the messages. Thirty messages are not thirty distinct bugs and
repeat suppression means this is not an exhaustive occurrence count.
No evidence attributes the owner's AMD reset to one particular hazard yet.
All five checkpoints exist. Final reveal generation2/destination8763000E
is ready/materialized/complete/visible, failures0, waitCueShown=false;
all transit ownership counters0. Twelve jump press/release pairs ran and
stamina fell, but no explicit twelve-airborne-transition assertion was
captured. Do not equate injected inputs with twelve successful jumps.
Validation frame times are not a performance gate.
### PNG inspection (lead; provisional)
All three images opened by the lead,1600x900, under `artifacts/screenshots/`:
- `477-00-first-resize.png`: **FAIL visual evidence**; radial stretched
geometry fills the view, not a valid settled scene. Retained, not discarded.
This run started at1600x900 already, so the route's same-size resize does
not reproduce #476's extent-change allocation. Cause not established here.
- `477-01-neftet-before.png`: coherent Neftet scene, but portal-space wait
text still visible; not a settled visual PASS or equipment PASS.
- `477-03-neftet-after.png`: coherent settled scene and wait text gone,
**provisional PASS for this narrow settled-cue check only**. Hands remain
empty; no claim that #480 or any overall renderer gate passed.
SHA256:
| File | SHA256 |
|---|---|
| client.log |1387BB25509264C22353739FAE4D61344082394EA07B1FF0C137BC9573D18380|
| client.err.log |E66FB4C4E8B767F4AD7064D35A3DB33722D658FB7B570F329655ED6BC93CD880|
| 477-00-first-resize.png |85B769BF1C47781667E651205E1AE02087F05D653F86C781A9A7F1294655F4CC|
| 477-01-neftet-before.png |6ECC46345293BCADAC553FDC4BC9DC953A896830EA3F2552233BC6A9A8C8034A|
| 477-03-neftet-after.png |9A0072B108B9180727A89A25CA31F8E2563E0D0D54FCE8B3734F50EBC7115614|
Next bounded code contract is `477-gpu-synchronization-contract.md` for
these three proven API dependencies. First-failure propagation remains a
known diagnostic limitation; do not combine unrelated recovery work into
this repair or call a no-crash validation run a resolution of the AMD incident.

View file

@ -0,0 +1,85 @@
# Owner gate follow-up — lighting and equipped-item read-only diagnosis
2026-09-05, source `de427d2c0` / documentation HEAD `8fd5e434b`.
No implementation, test execution or visual acceptance in this note.
#477's proven GPU synchronization faults are the immediate repair priority.
#479 object identity/transform and #481 entry performance remain unmeasured.
## #480 — missing publication before equipped render membership
James's bounded read-only trace identified an absent production edge; lead
independently read the controller, ordinary materializer, prepared publisher,
registry and walk consumer to confirm the chain:
1. EquippedChildRenderController resolves the actual GfxObj from DAT for its
template/availability, then BuildChildRenderParts (12021214) relies only
on PhysicsDataCache.GetGfxObj/GetVisualBounds.
2. Ordinary DatLiveEntityProjectionMaterializer explicitly calls
LiveCollisionAssetPublisher.CacheGfxObj before membership construction.
The attached path does not. Attached Position-null hydration bypasses the
ordinary materializer; the cache getters do not lazily load the package.
3. ShadowShapeBuilder.FromSetupRenderParts skips a visual part when cached
physics and visual bounds are both absent. This can return an empty list
despite DAT-backed drawable mesh/template data existing.
4. AttachChild (controller693698) accepts that product, and the controller
logs successful attachment regardless of the ignored Boolean result.
Even when the root CELLARRAY is inherited successfully, an empty part
array emits zero RetailPartEntry rows.
5. WalkProductionWorldData.ResolveCellView (286 onward) reads only those
rows, so that child contributes no draw or downstream selection part.
Parent-cell fallback would conceal, not repair, the missing producer.
The owner log has local-player attachment messages (lines212,882,905), but
does not expose the current GfxObj cache state. Thus the reachable production
defect is established statically; its occurrence for each owner item remains
to be demonstrated by a genuine composed regression or live observation.
The proposed repair is to reuse the existing strict prepared-asset publisher
before constructing child render parts, never invent bounds/collision or a
second cache. Composition already owns that publisher.
Proposed discriminating test: extend the actual controller OnSpawn fixture
with a nonempty child Setup/GfxObj and cold production-style cache, backed by
prepared collision content. Give the parent a real retail CELLARRAY. Assert
attachment success as control, then exact child local-ID/part/GfxObj rows in
the registry and the same child's EquippedChild record through the walk.
Current code should fail at the first row assertion. Test nonempty fixture,
effective part replacements and cleanup; do not manually inject membership.
Existing controller fixtures use empty Setups; registry fixtures inject
handmade child shapes, and selection tests inject visible parts directly.
Agent named-retail pointers (lead binary re-verification still owed before
any AC-specific repair contract): CPhysicsObj::add_shadows_to_cells recursively
visits children; CPartArray::AddPartsShadow visits every non-null visual part.
Named pseudo-C lines282819282901 and285933285955. No new retail claim is
accepted merely from a successful attachment log.
## #478 — distinguish local-light selection from High postprocessing
Rawls's bounded read-only report supplied named-retail/paired-executable
checks; the lead has not yet independently repeated its complete retail
proof. Treat the following as investigation targets, not an authorized fix:
- Current sealed-interior ambient .2 and no sunlight appear to match
CellManager::ChangePosition; WorldRenderFrameBuilder593612. Do not raise
global ambient to compensate for another error.
- LightManager590645 fills one eight-slot EnvCell set with dynamic lights
before statics. Existing AP-16/AP-35/AP-85 record the divergence from
retail's distinct dynamic hardware lights and all-static vertex-lighting
product. Enough dynamics can exclude every static fixture; the owner log
lacks the current selected set, so this cause is not yet proven in-frame.
- High's AtmosphericPostProcessGraph9951053 applies filmic/exposure/vignette
indoors. IsOutdoor gates rays/volumetrics, not the final filmic pass. This
may amplify a low local-light contribution. Compare identical frozen pose
in High versus Classic before changing a lighting formula.
- Existing meshless Setup-light publication appears intact. Town Network's
Setup02000365 carries a warm intensity100 light; actual selected membership
must be observed. #469's directional correction does not cover this path:
EnvCells use LightingMode1 and do not receive the outdoor directional shadow.
Next bounded evidence after #477: stable00070143 High/Classic image pair plus
actual registered dynamic/static counts, snapshot membership and the eight
selected cell indices/contributions. Reuse current diagnostics/test seams;
do not create a global telemetry framework or resurrect camera-flood light
selection. No current PNG/light-membership witness exists for the failed
owner session. If a genuinely required retail fact cannot be recovered
statically, follow the owner's stop rule; do not invent it.

View file

@ -4644,3 +4644,25 @@ silently dropped, but the next graphical run must serve the confirmed crash
investigation. Both clients absent; ACE UDP9000 PID13340 remains up. Check
again before builds/launches; one run per background command, close only our
own gracefully. G4 FAIL; no merge main.
### #477 bounded validation result and next contract
Clean8fd5e434b, same productionde427d2c0, fresh Release0W0E. One run
`logs/selfgate-20260905-111914-477-neftet-validation-r1`, PID12428, core+sync
validation, High/near4/far25/MSAA4/A2Ctrue,1600x900. Route completed and
client/runner exited0, no device loss reproduced; both clients absent afterward.
Validation FAIL: three confirmed native dependency faults, ten capped messages
each—swapchain acquire transition, sampleable MSAA depth/stencil resolve,
terrain migration transfer read-after-write. Lead verified source and primary
Khronos rules; this is actionable API evidence, not proof of the AMD TDR's
specific cause. Exact hashes/PNG outcomes: `477-validation-reproduction.md`.
First capture is malformed (retained FAIL); later settled Neftet cue clears
(narrow provisional PASS), not an overall renderer/equipment acceptance.
`477-gpu-synchronization-contract.md` binds only these three dependencies,
native-structure/recording proofs, four actual-production mutations and the
same validation repeat after review/integration. No new retail algorithm or
intentional deviation, no frame-idle workaround, no screenshot/lighting/items
smuggled into the chunk. Other read-only findings and next proof targets are
in `478-480-readonly-diagnosis.md`; #480 has a concrete missing prepared-cache
publication edge, while #478 needs an identical-pose High/Classic witness.