docs(overhaul): prepare ordered geometry witness after owner gate

This commit is contained in:
Erik 2026-09-05 08:50:23 +02:00
parent aae5758971
commit 41ca024515
2 changed files with 149 additions and 1 deletions

View file

@ -696,7 +696,7 @@ Update immediately when a slice changes state. Chat is not the ledger.
| S5-#470 | **LANDED + REVIEW-CLOSED 2026-09-05; LEAD GRAPHICAL A/B PROVISIONAL PASS.** Campaign implementation stack `15a796c3a` -> `7506e5f14` -> `b333edb4f`; route `19b44e5e3`; reviewed scratch `51f974da4` -> `2cad9c84` -> `98c004aa7`; packet §§2730. | G4 UNPASSED | Retail/behavior pass 2/10 and production pass 4/10 closed the two evidence-only findings. Fresh campaign Release 0W/0E and focused 48/48; exact scratch hermetic 16,976/16,976 and canonical InstalledDat 386/10/1, manifests 30/30. Pinned gate `logs/selfgate-20260905-032132-s5-470-pinned-shadow-ab-r1`: retail/off -> High -> retail/off, 3/3 PNGs, exit 0, graceful, no client; visual PASS provisional. The stale recipe-8 pre-route launch is excluded and recorded in §30. |
| S5-#469 | **LANDED + REVIEW-CLOSED 2026-09-05; LEAD GRAPHICAL TRANSITION PROVISIONAL PASS.** Contract `809887524`; reviewed scratch `c09b6cf0f`; campaign implementation `94ddde69a`; route `62efc72cb`; packet §§3132. | G4 UNPASSED | Retail/deviation pass 1/10 and production pass 2/10 both PASS with no finding. The two atmospheric vertex receivers keep retail's authored unnormalized `uLights` direction across every shadow gate; celestial direction remains for opt-in shadow/volumetric projection; IA-24 corrected in the same commit. Exact scratch: Release 0W/0E, focused 126/126, Vulkan 2/2, hermetic 16,983/16,983, InstalledDat 386/10/1. Fresh campaign Release 0W/0E, focused 82/82, Vulkan 2/2. Gate `logs/selfgate-20260905-040449-s5-469-lighting-transition-r1`: five PNGs, active 2,500-caster/four-cascade High rows, no near-black relight, exit 0/graceful, no client; visual PASS provisional. |
| S5-c5 | **CLOSED + LANDED 2026-09-05; LEAD GRAPHICAL SMOKE PROVISIONAL PASS.** Contract `b77989c32`; campaign `bf53e2ad6` -> `e625dc4e6` -> `1b7ee4e58`; reviewed scratch tip `158656f0d`; packet §§3335. | G4 UNPASSED | Retail/deletion pass 1/10 PASS. Production pass 2/10 found one static-field hole in the owner guard; fix round 1 reproduced both static-owner mutations, and production pass 3/10 PASS. Exact scratch hermetic 16,921/16,921, canonical InstalledDat 368/9/1, manifests 30/30. Fresh campaign Release 0W/0E, App 146/146, Core 8/8. A stale recipe-8 preflight is excluded; a non-destructive recipe-10 bake produced 2,237,865 keys with zero failures. Corrected gate `logs/selfgate-20260905-052130-s5-c5-landed-v10`: five PNGs, exit 0/graceful, no fatal/deleted-prefix match, no client left; geometry matches S5-c4, visual PASS provisional. |
| S5 | **#473 REPAIR LANDED/REVIEW-CLOSED `bf23673f3`; sampled exterior self-gate PROVISIONAL PASS, owner re-gate pending (2026-09-05).** c1c5 plus #470/#469 landed; lead PASS does not supersede owner FAIL. C1 offline evidence complete; C1c test correction frozen pending review. | G4 | Packet §§7 and 1242 bind. §42 repairs detail-active opaque A2C coverage loss at the owner's 4x/A2C=true settings. Both independent reviews PASS; post-commit Release 0W/0E and 158/158 adjacent tests; old-arm mutation fails12/12. All52 affected base/LOD prepared payloads match fresh extraction. §42.6 exact-binary PNGs show intact visible Holtburg/cathedral exteriors, detail ON in both modes; Facility control passes provisionally. Framing/foliage limitations are explicit; no every-face/LOD claim. All four sequential clients exited0/gracefully; none remains, ACE up. C1c review/landing, real geometry/membership hash, full-lane closure, C2 and full owner G4 remain. Never merge main before G4. |
| S5 | **#473 REPAIR LANDED/REVIEW-CLOSED `bf23673f3`; sampled exterior self-gate PROVISIONAL PASS, owner re-gate OPEN (2026-09-05).** c1c5 plus #470/#469 landed; lead PASS does not supersede owner FAIL. C1 offline evidence complete; C1c test/doc correction REVIEW-CLOSED, pending landing. | G4 | Packet §§7 and 1244 bind. §42 repairs detail-active opaque A2C coverage loss at the owner's 4x/A2C=true settings. Both independent reviews PASS; post-commit Release 0W/0E and 158/158 adjacent tests; old-arm mutation fails12/12. All52 affected base/LOD prepared payloads match fresh extraction. §42.6 exact-binary PNGs show intact visible Holtburg/cathedral exteriors, detail ON in both modes; Facility control passes provisionally. Framing/foliage limitations are explicit; no every-face/LOD claim. All four automated clients exited0/gracefully. §43 C1c retail pass1 found only AD-118's stale retirement marker/count, corrected directly by lead; production pass2 PASS. Lead fresh test-assembly-only Release and 68/68 scoped tests pass; no canonical full-lane claim. §44 records the subsequently launched manual owner client PID16892 on unchanged bf23673f3 binary, ACE UDP9000 PID13340. Hold builds, second clients and automated controls while the owner tests; no verdict yet. Exact C1c landing, real geometry/membership hash, full-lane closure, C2 and full owner G4 remain. Never merge main before G4. |
---

View file

@ -4224,3 +4224,151 @@ a launch failure. No owner verdict has been received; #473 and G4 remain open.
Hold builds, second clients, and automated movement/closure while the owner
tests. Only read-only review and documentation may continue. Preserve the
unchanged tested binary until the owner ends the gate or authorizes closure.
## 45. C1a geometry/membership witness — activation addendum, not dispatched
This is read-only preparation during the owner's §44 exterior re-gate. It
does not authorize a build, test run, second client, new production code, or
changes to C1c's reviewed scratch return. The previous goal turn was a
verified wait: PID16892 was confirmed live, with ACE UDP9000 PID13340.
No owner verdict has been received. G4 remains unpassed.
### 45.1 Preconditions and bounded return
First confirm authoritatively that no graphical/retail client remains. An
owner verdict alone does not authorize disturbing an open session; an
instruction to close still requires graceful closure and verified exit.
Record the verdict separately; do not infer it or process exit from a stale
log or elapsed time. Then land §43's exact reviewed nine-file C1c
return, preserving #473 and the subsequent ledger. Its corrected AD-118
retirement marker/header belong to that same landing. Run and classify the
post-landing Release/canonical conformance before activating this chunk.
Resolve the new scratch base to that actual clean commit, not C1c's old
02219318a base. Do not reuse or overwrite the nine-file uncommitted scratch.
§37.337.4 remain the geometry contract, with the precise reading below.
Allowed implementation: one InstalledDat App test class and at most one
test-only prepared-collision adapter, plus the packet's return note. No
production, fixture, shader, package, gate-script, or register change. No
golden from §38's abandoned draft may be reused. No graphical run belongs to
this test-only chunk. Both sequential review lenses remain required, with
the owner's ten-pass ceiling and direct lead correction of docs-only issues.
### 45.2 Lead-checked production path and complete ordered product
The factory/extractor/publication APIs exist; no new production seam is
needed. Each capture opens a fresh bounded installed DatCollection, reads
the real Region13000000 height table, and owns fresh DatPreparedAssetSource,
LandblockBuildFactory, PhysicsDataCache.CreateProduction and PhysicsEngine.
Build F418FFFF as LoadNear with captured origin(F4,18), hence zero world
offset. Build already constructs the flat collision closure and removes
parsed collision graphs from the publication bundle. The adapter may use
FlatCollisionAssetBuilder, never construct or filter membership.
The sequence in §37.3 is confirmed by HeadlessSessionWorldProjection's
production publication body: BuildTerrainSurface, PublishPreparedCells,
CacheBuildings, CachePreparedObjects, StageCollisionAssets, then
PublishStaticCollision. RuntimePhysicsState.StageCollisionAssets invokes
prepared.Engine.AddLandblock. The test uses the fresh engine's AddLandblock
at that same point; it does not reproduce the host's generation transaction
or claim a lifecycle/transaction gate. PublishStaticCollision owns all BSP,
Setup, render-only and reflood dispatch; do not copy those branches.
Serialize the actual ordered visibility-cell and shell-placement arrays,
source tuples, full placement transforms, every referenced Setup/GfxObj
mesh product and ordered SetupParts, and actual published static input order.
For entities, retain id/source id, position/quaternion/scale, nullable
ParentCellId and EffectCellId presence/value, IsBuildingShell, and all
ordered MeshRefs with full16-float transforms. Do not omit the complete
vertex position/normal/UV or index payload. For shell subset order use
ObjectMeshManager.OrderedUploadBatches; for ordinary mesh format maps only
unordered outer keys may be sorted. Preserve each list's internal order,
source surface index, raw surface type, retail mask, IsCellShell and format.
Every variable-length section has its own length; every float is raw bits.
**Membership has two distinct serializations, not one filtered projection:**
1. Visit the actual publication input entities in their original order.
Record HasLogicalOwner and TryGetRetailCellArray presence separately,
RetailCellArrayRoute, and the exact returned CELLARRAY sequence. A shell
or absent product is recorded explicitly, not silently omitted.
2. Form an outer cell-ID domain from the real published cells and the union
of the actual retained CELLARRAYs; outer cell keys alone may be sorted.
For each cell, serialize its complete, **unfiltered**
GetRetailPartEntriesInCell result once, retaining every entry's EntityId,
PartIndex, GfxObjId, CellId and ClipPlanesRequired in actual list order.
Do not filter by owner, group by EntityId, or sort entries. Cross-owner
insertion order is part of the product and would be erased by those
transformations. Assert every observed entry refers to a captured owner
whose actual CELLARRAY includes that cell; no synthetic expected rows.
Keep the exact F4180104 nonempty shell and seven-part020009A2 ramp facts in
§37.3 (ordered cells F4180112,F4180113,F4180009;21entries; all clip-required),
the independent-owner runs and labeled three-hash/count output. Add a
non-vacuity assertion that the canonical product has a cell with entries
from at least two distinct owners. Counts alone never establish correctness.
### 45.3 Golden provenance and required discrimination
Verify the four complete installed file SHA256s before pinning the product;
the existing CellStructSurfaceConstructionInstalledDatTests corpus records:
| File | Accepted SHA256 |
|---|---|
| client_portal.dat | DC6E500BA22E6B186DB7171E3F3345238B6444C85D798ADC85E550973B8D12E4 |
| client_cell_1.dat | 6DB0ABF00FBCEED62C3F1EE842EE7C1F423D732BED77A5B7C102EE89A52AB99E |
| client_highres.dat | 503E0828D14F2F9CCBC31431E1055AC188464BF4B499DE37F4C3D5B2D9F3E727 |
| client_local_English.dat | E85C820280C88FAC7DF6C8043F5E24596E9C8774193AF4123D756546F78FB2BB |
An iteration/catalog identity is not a substitute for these file digests.
The table is the accepted identity, not a claim that a fresh hash or new
product run occurred during the open owner gate. A mismatch fails explicitly.
Only after independent captures agree and the semantic facts are verified
may their version-tagged combined hash become the pinned golden.
Retain §37.4's vertex-bit, distinct-index, real pre-publication part/CELLARRAY
order and ramp clip-bit mutations, each reached by this actual corpus and
failing the pinned product with unchanged relevant counts. In addition,
swap two real entries belonging to different owners within one cell's
serialization: it must fail the pinned membership/combined proof without
changing per-owner entries, CELLARRAYs or counts. If such a pair cannot be
observed, return a finding; do not manufacture one. Restore every mutation
byte-for-byte. C1c already owns the missing-sixth-fixture discriminator;
retain its evidence and rerun its unchanged shared25-frame consumer after
landing rather than authoring a second fixture/replay path here.
The §37.4 return still requires two fresh focused test processes at the same
clean commit, exact digest/count agreement, zero-warning Release build,
official literal hermetic and canonical InstalledDat artifacts/manifests,
and exact classification of every nonpassing identity. No test has run and
no geometry hash is claimed in this addendum. C2 remains after these gates.
### 45.4 Independent retail/order evidence for this clarification
The lead re-read the named add_shadows_to_cells00514AE0,
AddPartsShadow00517E40, CPartCell::add_part0052E740 and
CELLARRAY::add_cell006B4FF0, then section-mapped the paired executable
directly, without launching it or attaching a debugger. File SHA256 remains
006FFEADC5D679C871497112A5BD1F87714D0E273E2166BAE5052DDE369297B1,
CodeView9E847E2F-777C-4BD9-886C-22256BB87F32 age1.
The ordinary add_shadows_to_cells arm traverses CELLARRAY in index order;
AddPartsShadow traverses non-null parts in index order and chooses clip
planes only for count>1 (`83 F8 01` / unsigned JBE). CPartCell::add_part
appends to its one cell-wide shadow_part_list, not an owner-partitioned map:
its tail loads the current count, stores count+1, then writes the new pointer
at the old index (`8B4704 8B4F08 8D5001 895704 5F 893481`). CELLARRAY::add_cell
rejects an existing ID and otherwise appends. Thus preserving only each
owner's projection is insufficient to witness the real per-cell stream.
No particle/child/lifecycle universality is inferred from this narrow check.
| Paired code window | Bytes | SHA256 |
|---|---:|---|
| 00514B62 ordinary cell-loop window | 101 | 347593BB75787A3DA6522D0ACCE96F028759FA59BB0F84C77E1D1DECB15AD85B |
| 00517E40 AddPartsShadow | 89 | 63C6ACFF37CE039B6929EBD51A08889F6EB4904B53F29C77C0E162B19CE95C75 |
| 0052E740 CPartCell::add_part | 114 | DDB3571A2F3888EAB88EC18767F884027B16A4F695C8DF553FD72680A74F2719 |
| 006B4FF0 CELLARRAY::add_cell | 85 | 4E319A770ACFD90DD08C4B3BEC8281AE1E0A5BDCD570B2B6F57E463F2AE6A123 |
This clarifies a not-yet-implemented test contract. It introduces no retail
deviation, renderer change or new review-fix round. The owner gate remains
the executable priority; after it, C1c landing precedes this activation.