feat(runtime): C3c - production placement cutover: both hosts on the residence conductors (routes 1+8)

Campaign P remaining-physics-divergence, placement cutover slice C3c
(docs/plans/2026-08-02-placement-cutover.md). Both production hosts now
register every initial Create through the residence + continuation-
executor + first-entry-conductor machinery (C0-C3b):

- Graphical (route 1): RegisterEntityWithInitialResidence at Create; the
  shared RuntimeFirstEntryDriveController pumps both conductors from the
  placement-receipt flow; MaterializeProjection and RebucketLiveEntity
  are presentation-only while a residence is ACTIVE (ExecutorCompleted is
  the presentation-binding receipt); post-residence entities take the
  full legacy path including the prepare_to_enter_world clock edges.
  PlayerModeController attaches presentation to the Runtime-published
  controller; its legacy resolve/step-heights/host-construction path is
  deleted; presentation-only rollback (retail has no entry-flow rollback).
- Headless (route 8): OnSpawned registers with residence when a drive
  exists; content-less sessions keep the pre-flip direct registration;
  SynchronizeLocalPlayer/CreateController/ApplySetupStepHeights deleted;
  prepared-collision read failure is a typed AwaitingCollisionSource
  retry; far remotes outside the service window complete celless.
- RuntimeLocalPlayerMovementState.Controller setter sealed internal; all
  controller mutation flows through the publication lifecycle.

Fix slices landed within this cutover, each dual-gated:
- F1: live movement-stat/server-physics application routed through the
  Runtime ownership seam (post-logout ingest crash on the retired
  controller eliminated; RuntimeMovementSkillProjection deleted).
- F2: login activation wedge - collision-admission prefix gate factored
  out of the seal (reentrant-commit RejectedAuthority), rearm generation
  identity corrected, PlayerModeAutoEntry requires the Runtime-published
  controller (world reveal can no longer seal unmaterialized).
- F3: landblock-prefix 0-sentinel replaced by explicit absent-id guards;
  map-corner landblocks (grid row/col 0) fully legal through admission,
  park/rearm/retire, quiescence, and outdoor shadow seeds.
- F5: local-player first-entry ground contact seeded by the shared
  SpawnPlacementSettler (moved App->Core) at FinalizeActivation - the
  retail first-gravity-frame touch (enter_world 0x00516170 carries no
  seed); the legacy unconditional force-seed is overwritten by a real
  floor-found contact; airborne spawns stay airborne; outbound contact
  bit verified end-to-end. Fixes the standing-cast 'You can't do that
  while in the air!' rejections.
- R1 (dual-review round): login constraint leash armed at the committed
  placement (HandleReceivedPosition 0x00453FD0 analog); register rows
  AD-61 (settle-timing compression now covering the local player) and
  AD-42 (repointed off the deleted resolve split) in this commit;
  residence-conversion owner API; wire-landblock guards; drive-pending
  ledger in IsConverged; route attach/detach latch; executor-drain drift
  model documented + source-pinned.

Gates: Runtime 1,003, App 4,039/3 skips, Headless 79, complete solution
10,816/0 failed/4 skips (Release, -m:1); connected lifecycle/reconnect
gate PASS (logs/connected-world-gate-20260802-175401; graceful exits,
world-visible, zero airborne rejections). The nine-stop soak remains red
for the pre-existing 6b28ff99 whole-world collision-clone throughput
regression (attributed with evidence; scheduled as its own slice before
C5). Dual Opus reviews (retail-conformance + adversarial): delta PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-02 18:10:33 +02:00
parent 78f1eb1896
commit 529e0e9d88
68 changed files with 5977 additions and 831 deletions

View file

@ -70,7 +70,16 @@ public readonly record struct RuntimeEntityObjectOwnershipSnapshot(
/// keys - the remote/projectile Create-time body-construction conductor.
/// Dormant like its C3a sibling; converges to zero the same way.
/// </summary>
int RemoteFirstEntryActiveCount = 0)
int RemoteFirstEntryActiveCount = 0,
/// <summary>
/// C3c-R1 review F5: outstanding host first-entry drive entries
/// (<c>RuntimeFirstEntryDriveController</c> pending keys, summed over
/// every drive registered against this lifetime via
/// <see cref="RuntimeEntityObjectLifetime.RegisterFirstEntryDriveOwnership"/>).
/// Previously outside every ledger; gated by <see cref="IsConverged"/>
/// like the conductor counts it pumps.
/// </summary>
int FirstEntryDrivePendingCount = 0)
{
public bool IsConverged =>
IsDisposed
@ -94,6 +103,7 @@ public readonly record struct RuntimeEntityObjectOwnershipSnapshot(
&& PendingCompletionReceiptCount == 0
&& LocalPlayerFirstEntryActiveCount == 0
&& RemoteFirstEntryActiveCount == 0
&& FirstEntryDrivePendingCount == 0
&& StreamSubscriberCount == 0
&& PlacementStreamSubscriberCount == 0
&& PendingDispatchCount == 0
@ -137,6 +147,10 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
{
private bool _sessionClearInProgress;
private bool _disposed;
/// <summary>C3c: see <see cref="BindInitialResidenceBeginNotification"/>.</summary>
private Action<RuntimeEntityRecord>? _initialResidenceBegan;
/// <summary>C3c-R1 review F5: see <see cref="RegisterFirstEntryDriveOwnership"/>.</summary>
private readonly List<Func<int>> _firstEntryDriveOwnership = [];
public RuntimeEntityObjectLifetime(
uint firstLocalEntityId = RuntimeEntityDirectory.FirstLocalEntityId,
@ -437,7 +451,31 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
InitialCreateExecution.LastReplayFailure is not null,
InitialCreateExecution.PendingCompletionReceiptCount,
LocalPlayerFirstEntry.CaptureOwnership().ActiveCount,
RemoteFirstEntry.CaptureOwnership().ActiveCount);
RemoteFirstEntry.CaptureOwnership().ActiveCount,
CaptureFirstEntryDrivePendingCount());
}
private int CaptureFirstEntryDrivePendingCount()
{
int total = 0;
for (int i = 0; i < _firstEntryDriveOwnership.Count; i++)
total = checked(total + _firstEntryDriveOwnership[i]());
return total;
}
/// <summary>
/// C3c-R1 review F5: registers one host first-entry drive controller's
/// pending-count provider into this lifetime's ownership snapshot, so
/// tracked-but-undriven entries can never sit outside every ledger. The
/// drive controller registers itself at construction (it already binds
/// <see cref="BindInitialResidenceBeginNotification"/> there); multiple
/// registrations sum, mirroring the multicast notification shape.
/// </summary>
public void RegisterFirstEntryDriveOwnership(Func<int> pendingCount)
{
ArgumentNullException.ThrowIfNull(pendingCount);
EnsureNotDisposed();
_firstEntryDriveOwnership.Add(pendingCount);
}
public void BindEventContext(
@ -451,6 +489,22 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
InitialCreateExecution.BindGeneration(generation);
}
/// <summary>
/// C3c: registers one host callback fired for every FRESH initial-create
/// residence begin (never for a same-generation FIFO append). Multicast,
/// mirroring <see cref="RuntimeInitialCreateResidenceState.BindRetirementNotification"/>.
/// The callback runs synchronously inside the registration transaction —
/// subscribers must only record the entity for a later drive pump, never
/// call a conductor's Advance re-entrantly from it.
/// </summary>
public void BindInitialResidenceBeginNotification(
Action<RuntimeEntityRecord> began)
{
ArgumentNullException.ThrowIfNull(began);
EnsureNotDisposed();
_initialResidenceBegan += began;
}
/// <summary>
/// C0-2: forwards to <see cref="RuntimeInitialCreateContinuationExecutor.BindLiveInputs"/>,
/// the same fan-out shape <see cref="BindEventContext"/> already uses for
@ -2270,6 +2324,20 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
return InitialCreateResidences.TryGetCurrent(canonical, out lease);
}
/// <summary>
/// C3c-R1 review F7: host seam for a bounded-collision-neighborhood
/// host to convert a remote/projectile Create's active residence to the
/// celless completion route when its destination landblock will never
/// be collision-published (a headless far remote). See
/// <see cref="RuntimeInitialCreateResidenceState.TryConvertToCellessRoute"/>.
/// </summary>
public bool TryConvertInitialResidenceToCellessRoute(
RuntimeEntityRecord canonical)
{
EnsureNotDisposed();
return InitialCreateResidences.TryConvertToCellessRoute(canonical);
}
internal RuntimeInitialCreateResidenceCompletionStatus
CompleteInitialCreateResidence(
RuntimeEntityRecord canonical,
@ -2339,7 +2407,19 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
canonical,
accepted,
isLocalPlayer);
return lease.IsValid;
if (!lease.IsValid)
return false;
// C3c: host drive notification. Fires for EVERY fresh residence
// begin through this single choke point — wire-dispatch Creates AND
// the executor's deferred-child replays (which register through this
// class's own bound delegate, never through a host runtime). The
// subscriber must only RECORD the key for a later drive pump — this
// fires mid-registration, before Registered publishes, and a
// synchronous Advance here would interleave with the enclosing
// transaction (and, for a replayed child, with the parent's own
// in-flight Execute).
_initialResidenceBegan?.Invoke(canonical);
return true;
}
private Exception FailInitialResidenceRegistration(

View file

@ -1007,6 +1007,52 @@ internal sealed class RuntimeInitialCreateResidenceState
return _completed.Remove(token.Entity);
}
/// <summary>
/// C3c-R1 review F7: converts an ACTIVE, not-yet-placed
/// SetPosition-performing residence to the celless
/// (AwaitFreshPosition) route shape, forgetting its authored placement
/// operation. The residence entry itself stays active — the conductor's
/// next pump takes the existing celless skip-to-Execute path and
/// completes with FullCell 0, exactly like a Parented/PickedUp lease.
/// The retirement fan-out is fired to reset conductor/executor progress
/// for the key (its subscribers are pure progress reapers:
/// executor <c>DiscardProgress</c> + both conductors' <c>Forget</c>);
/// the entry itself is deliberately NOT retired. Refused once any
/// placement has committed (<c>FullCellId != 0</c>) — the entity is not
/// a far remote then.
/// </summary>
internal bool TryConvertToCellessRoute(RuntimeEntityRecord record)
{
ArgumentNullException.ThrowIfNull(record);
if (record.Key is not { } key
|| !_entries.TryGetValue(key, out Entry? entry)
|| !ReferenceEquals(entry.Record, record))
{
return false;
}
if (!IsCurrent(entry))
{
Retire(entry);
return false;
}
RuntimeInitialCreateResidenceLease lease = entry.Lease;
if (!lease.Route.PerformsSetPosition)
return true;
if (record.FullCellId != 0u)
return false;
RuntimePlacementCancellationReceipt cancellation =
_setPosition.ForgetExactPlacement(lease.Placement);
entry.Lease = lease with
{
Route = RuntimeAuthoritativePositionRouteClassifier
.ToCellessCreateRoute(lease.Route),
Placement = default,
};
_setPosition.PublishCancellation(cancellation);
NotifyRetirement(key);
return true;
}
internal bool Forget(
RuntimeEntityRecord record,
out RuntimeInitialCreateResidenceLease lease,

View file

@ -113,11 +113,13 @@ internal readonly record struct RuntimeRemoteFirstEntryOwnershipSnapshot(
/// <c>DormantLocalActivation</c> set, so the ordinary submission tail is the
/// correct — and only — commit route.
///
/// Dormant by design: <see cref="RuntimeEntityObjectLifetime"/> fully
/// constructs and wires this class (construction, retirement fan-out, bulk
/// session-clear cleanup, ownership fold) exactly like the C3a conductor,
/// but nothing calls <see cref="Advance"/> in production — C3c wires the
/// hosts.
/// PRODUCTION-DRIVEN since the C3c flip: <see cref="RuntimeEntityObjectLifetime"/>
/// fully constructs and wires this class (construction, retirement fan-out,
/// bulk session-clear cleanup, ownership fold) exactly like the C3a
/// conductor, and the host first-entry drive
/// (<c>RuntimeFirstEntryDriveController</c>) calls <see cref="Advance"/>
/// for every remote/projectile initial-create residence on both the
/// graphical and headless hosts.
/// </summary>
internal sealed class RuntimeRemoteFirstEntryState
{

View file

@ -263,6 +263,13 @@ public sealed class GameRuntime
context.EntityObjects.Physics,
context.Movement,
context.PlayerIdentity));
// C3c: the C3a conductor's "first act" — bind the publication
// owner the conductor was constructed without (it is built by
// RuntimeEntityObjectLifetime BEFORE
// RuntimeLocalPlayerPhysicsPublicationState exists; see the F2
// late-bind note on RuntimeLocalPlayerFirstEntryState's ctor).
context.EntityObjects.LocalPlayerFirstEntry.BindPublication(
context.Movement.PhysicsPublication);
context.EntityObjects.BindEventContext(
() => generationReset.ActiveRetiringGeneration

View file

@ -368,6 +368,38 @@ public sealed class PlayerMovementController
_body.calc_acceleration();
}
/// <summary>
/// C3c-F1 (2026-08-02): the lifecycle-deciding inbound-SetState entry
/// for the local player. Live states apply the exact
/// <see cref="ApplyPhysicsState"/> body; the dormant window drops the
/// push because the activation transaction owns the dormant body's
/// physics state exclusively (<see cref="RefreshDormantRuntimePhysicsState"/>
/// re-reads the canonical record's FinalPhysicsState at both activation
/// phases, and while the accepted SetState is queued behind the initial
/// residence the App-side push carries that same unchanged record value
/// — the drop is value-preserving by construction); terminal states are
/// displaced pushes (J3.6 displaced-callback-rejection), never a fault.
/// </summary>
internal RuntimeServerPhysicsStateApplication ApplyServerPhysicsState(
PhysicsStateFlags state)
{
switch (_publicationLifecycle)
{
case PlayerMovementControllerPublicationLifecycle.StandalonePublished:
case PlayerMovementControllerPublicationLifecycle.CandidatePreparing:
case PlayerMovementControllerPublicationLifecycle.RuntimePublished:
_body.State = state;
_body.calc_acceleration();
return RuntimeServerPhysicsStateApplication.AppliedLive;
case PlayerMovementControllerPublicationLifecycle.RuntimeOwnedDormant:
return RuntimeServerPhysicsStateApplication
.DroppedDormantActivationOwned;
default:
return RuntimeServerPhysicsStateApplication
.DroppedDisplacedController;
}
}
public bool IsAirborne => !_body.OnWalkable;
/// <summary>
@ -1292,6 +1324,114 @@ public sealed class PlayerMovementController
lastPkAttackTimestamp);
}
/// <summary>
/// C3c-F1 (2026-08-02): the lifecycle-deciding half of the Runtime
/// movement-stats application seam
/// (<see cref="RuntimeLocalPlayerMovementState.ApplyCharacterMovementStats"/>).
/// The publication owner — not any App caller — decides whether a
/// server stat recompute may land:
/// <list type="bullet">
/// <item><see cref="PlayerMovementControllerPublicationLifecycle.StandalonePublished"/>,
/// <see cref="PlayerMovementControllerPublicationLifecycle.CandidatePreparing"/>, and
/// <see cref="PlayerMovementControllerPublicationLifecycle.RuntimePublished"/>
/// apply immediately — byte-identical to the deleted
/// <c>RuntimeMovementSkillProjection.ApplyTo</c> direct path.</item>
/// <item><see cref="PlayerMovementControllerPublicationLifecycle.RuntimeOwnedDormant"/>
/// ALSO applies immediately: the dormant window (publication committed,
/// activation deferred on cell streaming —
/// <c>RuntimeLocalPlayerFirstEntryState.AdvanceCore</c>'s
/// AwaitingActivation loop) spans inbound pumps, and this exact instance
/// is the controller that <c>ActivateRuntimePublication</c> later makes
/// live, so the write must land here (same discipline as
/// <see cref="RefreshDormantRuntimePhysicsState"/> /
/// <see cref="RefreshDormantRuntimeVector"/>: accepted server facts
/// arriving mid-dormancy land on the dormant owner). These writes touch
/// only <see cref="PlayerWeenie"/> fields and the mover-flag latch —
/// no body/world/currency state the activation envelope validates.</item>
/// <item><see cref="PlayerMovementControllerPublicationLifecycle.CandidateSealed"/>,
/// <see cref="PlayerMovementControllerPublicationLifecycle.RuntimeRetired"/>, and
/// <see cref="PlayerMovementControllerPublicationLifecycle.Discarded"/>
/// report the typed displaced-write outcome (J3.6
/// displaced-callback-rejection): a stat write against a terminal
/// controller is meaningless by design — the next login re-derives from
/// PlayerDescription. A sealed candidate is additionally unreachable
/// through the seam in production: it is never installed into
/// <see cref="RuntimeLocalPlayerMovementState"/> (Prepare requires the
/// movement owner empty and Commit installs it already-dormant in the
/// same synchronous Advance step).</item>
/// </list>
/// </summary>
internal RuntimeMovementStatsApplication ApplyCharacterMovementStats(
in RuntimeMovementSkillSnapshot snapshot)
{
switch (_publicationLifecycle)
{
case PlayerMovementControllerPublicationLifecycle.StandalonePublished:
case PlayerMovementControllerPublicationLifecycle.CandidatePreparing:
case PlayerMovementControllerPublicationLifecycle.RuntimePublished:
ApplyCharacterMovementStatsCore(snapshot);
return RuntimeMovementStatsApplication.AppliedLive;
case PlayerMovementControllerPublicationLifecycle.RuntimeOwnedDormant:
ApplyCharacterMovementStatsCore(snapshot);
return RuntimeMovementStatsApplication.AppliedDormant;
default:
return RuntimeMovementStatsApplication.DroppedDisplacedController;
}
}
/// <summary>
/// The exact application body of the deleted
/// <c>RuntimeMovementSkillProjection.ApplyTo</c> (same fields, same
/// order, same conversions) — moved behind the lifecycle switch so the
/// dormant window can share it without routing through the
/// <see cref="EnsureConfigurationMutable"/>-gated public setters.
/// Campaign P Slice P1 (2026-07-30): burden/stamina ride the SAME seam
/// run/jump skill already used — see the pseudocode doc §9. TS-23
/// (Campaign P Slice P3, 2026-07-30): the player's own
/// PK/PKLite/Impenetrable collision-exemption bits and the
/// PlayerKillerStatus/LastPkAttackTimestamp pair the jump-cost PK-timer
/// bump reads — see <c>EntityCollisionFlagsExt.ToMoverState</c> and
/// <c>PlayerWeenie.JumpStaminaCost</c>.
/// </summary>
private void ApplyCharacterMovementStatsCore(
in RuntimeMovementSkillSnapshot snapshot)
{
_weenie.SetSkills(snapshot.RunSkill, snapshot.JumpSkill);
_weenie.SetBurden(snapshot.Burden);
_weenie.SetStamina(
snapshot.CurrentStamina < 0 ? null : (uint)snapshot.CurrentStamina);
_ownPvpFlags = EntityCollisionFlagsExt
.FromPwdBitfield(snapshot.OwnPwdBitfield)
.ToMoverState();
_weenie.SetPlayerKillerStatus(
snapshot.PlayerKillerStatus < 0 ? null : snapshot.PlayerKillerStatus,
snapshot.LastPkAttackTimestamp);
}
/// <summary>
/// C3c-F1: the stamina-exhaustion EVENT dispatch
/// (retail <c>CommandInterpreter::HandleExhaustion</c> @ 0x006b3c70 →
/// <c>CPhysicsObj::report_exhaustion</c>), routed through the owner so
/// App never touches the gated <see cref="Motion"/> surface. Fires only
/// on a live controller: a dormant owner has no in-flight movement to
/// re-dispatch (retail's handler is a no-op for a player not in world;
/// activation dispatches movement fresh from the already-current
/// <see cref="PlayerWeenie"/> stamina gate), and a terminal owner is a
/// displaced callback.
/// </summary>
internal bool ReportExhaustionAtMovementBoundary()
{
if (_publicationLifecycle
is PlayerMovementControllerPublicationLifecycle.StandalonePublished
or PlayerMovementControllerPublicationLifecycle.CandidatePreparing
or PlayerMovementControllerPublicationLifecycle.RuntimePublished)
{
_motion.ReportExhaustion();
return true;
}
return false;
}
/// <summary>
/// R3-W2 (r3-port-plan.md §4): the player's <see cref="MotionInterpreter"/>
/// — GameWindow binds the player sequencer's MotionDone seam to it so the
@ -1651,15 +1791,39 @@ public sealed class PlayerMovementController
RearmConstraintLeashAtCurrentPosition();
}
/// <summary>
/// C3c-R1: arms the login-entry constraint leash from the Runtime
/// publication chain. The flip deleted the only login-path caller of
/// <see cref="RearmConstraintLeashAtCurrentPosition"/> (the App-side
/// <see cref="CommitPreparedPosition"/> call in the old
/// player-mode-entry commit); the dormant activation's final commit
/// (<c>RuntimeSetPositionState.TryApplyDormantLocalActivationFinalCommit</c>)
/// is the accepted-position event that replaces it — retail arms at
/// every accepted-position event (<c>SmartBox::HandleReceivedPosition</c>
/// 0x00453FD0). The final commit has already activated this controller
/// (<c>ActivateRuntimePublication</c>), so the published guard doubles
/// as a stale-caller check. Like the pre-flip commit path, no
/// UnConstrain teardown is needed: nothing can have armed the leash on
/// a controller whose <see cref="PositionManager"/> was created by its
/// own publication candidate.
/// </summary>
internal void ArmConstraintLeashAtCommittedPlacement()
{
EnsurePublishedForRuntimeOperation();
RearmConstraintLeashAtCurrentPosition();
}
/// <summary>
/// #167 (Campaign P P5): retail <c>SmartBox::HandleReceivedPosition</c>
/// (0x00453fd0) "Player, teleport-newer" branch re-arms the leash
/// immediately after <c>TeleportPlayer</c>'s teardown, anchored to the
/// RECEIVED position (here, the body's just-snapped current position).
/// Shared by the teleport path (after UnConstrain) and the deferred
/// Shared by the teleport path (after UnConstrain), the deferred
/// player-mode-entry commit path (<see cref="CommitPreparedPosition"/>),
/// which never ran UnConstrain because nothing could have armed the
/// leash before the controller had a <see cref="PositionManager"/>.
/// leash before the controller had a <see cref="PositionManager"/>,
/// and the C3c first-entry placement commit
/// (<see cref="ArmConstraintLeashAtCommittedPlacement"/>).
/// docs/research/2026-07-30-constraint-leash-constants.md §2/§3.2.
/// </summary>
private void RearmConstraintLeashAtCurrentPosition()

View file

@ -131,12 +131,14 @@ internal readonly record struct RuntimeLocalPlayerFirstEntryOwnershipSnapshot(
/// <see cref="RuntimeSetPositionState.TryPrepareAuthoredMover"/> half instead
/// and never the fused method.
///
/// Dormant by design: <see cref="RuntimeEntityObjectLifetime"/> fully
/// constructs and wires this class (construction, publication binding,
/// PRODUCTION-DRIVEN since the C3c flip: <see cref="RuntimeEntityObjectLifetime"/>
/// fully constructs and wires this class (construction, publication binding,
/// retirement fan-out, bulk session-clear cleanup, ownership fold) exactly
/// like every other owner it builds, but nothing calls
/// <see cref="Advance"/> in production — a later slice wires a host to drive
/// it.
/// like every other owner it builds, and the host first-entry drive
/// (<c>RuntimeFirstEntryDriveController</c>, pumped by the graphical
/// hydration/frame-retry cadence and the headless spawn/position/tick
/// cadence) calls <see cref="Advance"/> for every local-player
/// initial-create residence.
/// </summary>
internal sealed class RuntimeLocalPlayerFirstEntryState
{

View file

@ -14,6 +14,70 @@ public interface IRuntimeLocalPlayerMotionSource
MotionInterpreter? Motion { get; }
}
/// <summary>
/// C3c-F1 (2026-08-02): typed outcome of routing a server movement-stat
/// recompute through the Runtime movement owner. The dropped outcomes are
/// the J3.6 displaced-callback-rejection pattern — never an exception and
/// never a silent void: the caller logs them under its existing
/// diagnostics. A skill write against a dead session is meaningless by
/// design; the next login re-derives everything from PlayerDescription.
/// </summary>
public enum RuntimeMovementStatsApplication
{
/// <summary>Applied to the live (published/standalone) controller —
/// byte-identical to the pre-F1 direct application path.</summary>
AppliedLive,
/// <summary>Applied to the Runtime-owned dormant controller during the
/// committed-but-not-yet-activated first-entry window. The same
/// instance goes live at activation, so the values are already current
/// when movement starts.</summary>
AppliedDormant,
/// <summary>No controller is installed (pre-first-entry, mid-candidate
/// construction, or after session teardown cleared the owner).</summary>
DroppedNoController,
/// <summary>The skill snapshot has no authoritative run/jump values yet
/// (PlayerDescription not processed) — same silent skip as the pre-F1
/// path.</summary>
DroppedIncompleteSnapshot,
/// <summary>The installed controller is terminal (sealed, retired, or
/// discarded): a displaced post-teardown write, reported instead of
/// faulting the session.</summary>
DroppedDisplacedController,
}
/// <summary>
/// C3c-F1 (2026-08-02): typed outcome of routing an inbound server
/// PhysicsState push through the local movement controller's publication
/// lifecycle. Same displaced-callback-rejection family as
/// <see cref="RuntimeMovementStatsApplication"/>, with one deliberate
/// difference: the dormant window DROPS the push rather than applying it,
/// because the activation transaction owns the dormant body's physics
/// state exclusively (it re-reads the canonical record's FinalPhysicsState
/// through <c>RefreshDormantRuntimePhysicsState</c> at both activation
/// phases), and the App-side push carries that exact same unchanged record
/// value while the accepted SetState itself is queued behind the initial
/// residence — dropping it is value-preserving by construction.
/// </summary>
public enum RuntimeServerPhysicsStateApplication
{
/// <summary>Applied to the live (published/standalone) controller —
/// byte-identical to the direct <c>ApplyPhysicsState</c> path.</summary>
AppliedLive,
/// <summary>The controller is Runtime-owned dormant: the activation
/// pipeline is the sole authority for the dormant body's physics state
/// and re-reads the canonical value itself.</summary>
DroppedDormantActivationOwned,
/// <summary>The installed controller is terminal — a displaced
/// post-teardown push.</summary>
DroppedDisplacedController,
}
/// <summary>
/// Canonical local movement lifetime and intent owner. Graphical input,
/// presentation, diagnostics, and future no-window hosts borrow this exact
@ -37,7 +101,13 @@ public sealed class RuntimeLocalPlayerMovementState
public PlayerMovementController? Controller
{
get => _controller;
set
// C3c seal: the public write escape hatch is closed. Production
// controller installation flows only through the publication
// lifecycle (CommitRuntimeOwnedController via
// RuntimeLocalPlayerPhysicsPublicationState.Commit) and teardown
// through ResetSession/Dispose/DiscardActivation. The setter stays
// reachable for tests via InternalsVisibleTo only.
internal set
{
ObjectDisposedException.ThrowIf(_disposed, this);
if (ReferenceEquals(_controller, value))
@ -189,6 +259,44 @@ public sealed class RuntimeLocalPlayerMovementState
return true;
}
/// <summary>
/// C3c-F1 (2026-08-02): the ONLY route by which server-authoritative
/// movement stats (run/jump skill, burden, stamina, PK status — the
/// exact field set of the deleted
/// <c>RuntimeMovementSkillProjection.ApplyTo</c>) reach the local
/// movement controller. App holds no controller reference for stat
/// application and performs no direct configuration mutation; the
/// owner's publication lifecycle decides whether the write lands
/// (live/dormant) or is reported as a typed displaced drop (terminal) —
/// the fix for the connected-gate post-logout ingest crash at
/// <c>PlayerMovementController.EnsureConfigurationMutable</c>.
/// Deliberately tolerant of a disposed owner: a recompute displaced
/// past teardown observes <see cref="RuntimeMovementStatsApplication.DroppedNoController"/>
/// instead of faulting the session.
/// </summary>
public RuntimeMovementStatsApplication ApplyCharacterMovementStats(
RuntimeMovementSkillState skills)
{
ArgumentNullException.ThrowIfNull(skills);
if (_controller is not { } controller)
return RuntimeMovementStatsApplication.DroppedNoController;
RuntimeMovementSkillSnapshot snapshot = skills.Snapshot;
if (!snapshot.IsComplete)
return RuntimeMovementStatsApplication.DroppedIncompleteSnapshot;
return controller.ApplyCharacterMovementStats(snapshot);
}
/// <summary>
/// C3c-F1: routes the stamina-exhaustion EVENT (retail
/// <c>CommandInterpreter::HandleExhaustion</c>) through the owner so the
/// App edge-tracker never touches the gated controller motion surface.
/// Returns false when no live controller can dispatch it (absent,
/// dormant, terminal, or disposed owner) — displaced-callback-tolerant
/// for the same reason as <see cref="ApplyCharacterMovementStats"/>.
/// </summary>
public bool ReportExhaustion() =>
_controller?.ReportExhaustionAtMovementBoundary() == true;
/// <summary>
/// Direct-host projection of the same combat readiness query used by the
/// graphical attack adapter. A host without a constructed local movement

View file

@ -278,13 +278,43 @@ internal sealed class RuntimeLocalPlayerPhysicsPublicationState : IDisposable
getObjectA: id => _physics.TryGetPhysicsHost(id, out var host)
? host
: null,
handleUpdateTarget: movement.HandleUpdateTarget,
// C3c: the [autowalk-target]/[autowalk-end] probes moved here
// with controller construction (previously App-side in
// PlayerModeController.BuildControllerAndCamera); they stay on
// the PhysicsDiagnostics owner exactly as before.
handleUpdateTarget: info =>
{
if (PhysicsDiagnostics.ProbeAutoWalkEnabled)
{
Console.WriteLine(
$"[autowalk-target] object=0x{info.ObjectId:X8} "
+ $"status={info.Status} context={info.ContextId} "
+ $"target=({info.TargetPosition.Frame.Origin.X:F2},"
+ $"{info.TargetPosition.Frame.Origin.Y:F2},"
+ $"{info.TargetPosition.Frame.Origin.Z:F2})");
}
movement.HandleUpdateTarget(info);
},
interruptCurrentMovement: () =>
movement.CancelMoveTo(WeenieError.ActionCancelled));
{
if (PhysicsDiagnostics.ProbeAutoWalkEnabled
&& movement.IsMovingTo())
{
Console.WriteLine("[autowalk-end] reason=interrupt");
}
movement.CancelMoveTo(WeenieError.ActionCancelled);
});
movement.MakeMoveToManager();
motion.UnstickFromObject = physicsHost.PositionManager.UnStick;
motion.InterruptCurrentMovement = () =>
{
if (PhysicsDiagnostics.ProbeAutoWalkEnabled
&& movement.IsMovingTo())
{
Console.WriteLine("[autowalk-end] reason=interrupt");
}
movement.CancelMoveTo(WeenieError.ActionCancelled);
};
controller.PositionManager = physicsHost.PositionManager;
// This checkpoint publishes ownership only. The subsequent canonical
// SetPosition transaction is the sole authority which may enter the
@ -687,11 +717,106 @@ internal sealed class RuntimeLocalPlayerPhysicsPublicationState : IDisposable
_physics.SetPosition.DispatchDormantLocalActivationShadow(committed);
if (!IsCommittedActivationSuffixCurrent(activation, committed))
return committed.Status;
ArmFirstEntryConstraintLeash(activation);
SettleFirstEntryGroundContact(activation);
_physics.SetPosition.DispatchDormantLocalActivationPlacement(committed);
projection = committed.Projection.Token;
return committed.Status;
}
/// <summary>
/// C3c-R1: the login-entry constraint-leash arm the flip deleted with
/// the App-side <c>CommitPreparedPosition</c> caller. Ordering, with
/// file:line justification:
/// <list type="bullet">
/// <item>NOT at <c>Prepare</c> — <c>PreparePositionForCommit</c> (:219)
/// runs with <c>publishSharedState: false</c> and the controller's
/// <c>PositionManager</c> binds only later at :318, so the leash cannot
/// exist there (nor should it: the position is not accepted yet).</item>
/// <item>NOT at publication <c>Commit</c> — the activation's placement
/// evaluation (retail find-placement ring search) may still move or
/// reject the position.</item>
/// <item>HERE, after <c>TryApplyDormantLocalActivationFinalCommit</c>
/// (RuntimeSetPositionState.cs:2494-2516 commits the final cell,
/// activates the controller, and publishes the shared current cell) and
/// inside the same <c>IsCommittedActivationSuffixCurrent</c> gate the
/// settle uses — a stale suffix skips the arm exactly like the settle
/// (never armed on stale authority).</item>
/// <item>BEFORE <see cref="SettleFirstEntryGroundContact"/> — retail
/// arms anchored to the RECEIVED position
/// (<c>SmartBox::HandleReceivedPosition</c> 0x00453FD0) and only then
/// simulates the first gravity frame, which the settle compresses; the
/// anchor is therefore the committed placement, not the post-settle
/// pose.</item>
/// <item>Exactly once — <c>_activation</c> is nulled at :716 before
/// this suffix, so a resumed <c>AwaitingFinalShadowPreparation</c>
/// retry can never re-enter it after a successful final commit.</item>
/// </list>
/// </summary>
private void ArmFirstEntryConstraintLeash(Activation activation)
{
// Same containment as the settle below: the placement commit has
// already succeeded; a leash-arm failure must not unwind the suffix.
try
{
activation.Controller.ArmConstraintLeashAtCommittedPlacement();
}
catch
{
_activationDispatchFailureCount++;
}
}
/// <summary>
/// C3c-F5: retail seeds the LOCAL player's ground contact from the first
/// gravity frame after <c>enter_world</c>, never from the placement
/// itself — <c>SmartBox::HandleCreateObject</c> (0x00454C80) runs
/// <c>init_player</c> (0x00455010) then <c>CPhysicsObj::enter_world</c>
/// (0x00455095 → 0x00516170), whose <c>SetPosition</c> validates the
/// spot but records no touch and whose tail only sets ACTIVE (0x80).
/// Every retail CPhysicsObj then simulates, falls the few centimetres
/// onto the floor, and the transition's touch grants the contact plane
/// + CONTACT/ON_WALKABLE. The dormant activation's just-finished commit
/// is the faithful SetPosition port, so a fresh login body would start
/// airborne here; this compresses the settle exactly like the #270
/// remote-spawn seed (the shared <see cref="SpawnPlacementSettler"/>):
/// a short downward sweep whose real touch produces the state retail's
/// first frame would. No floor within reach (a genuine airborne spawn)
/// leaves the body airborne — the ordinary per-tick gravity fall owns
/// it from there. The body transients this commits ARE the controller's
/// grounded state (<c>PlayerMovementController.CanSendPositionEvent</c>
/// reads <c>InContact &amp;&amp; OnWalkable</c> off the same body) and
/// the outbound wire contact bit (<c>LocalPlayerOutboundController</c>
/// serializes that predicate) — the flag ACE's "You can't do that while
/// in the air!" gate reads.
/// </summary>
private void SettleFirstEntryGroundContact(Activation activation)
{
// Same post-commit callback-dispatch containment as the ground-edge
// dispatch in CommitActivation: the placement commit has already
// succeeded; a HitGround-side failure must not unwind the suffix.
try
{
_ = SpawnPlacementSettler.TrySettle(
_physics.Engine,
activation.Body,
activation.Body.Position,
activation.Body.CellPosition.ObjCellId,
activation.ActivationPreparation.Radius,
activation.ActivationPreparation.Height,
ObjectInfoState.IsPlayer
| ObjectInfoState.EdgeSlide
| activation.Controller.OwnPvpFlags,
activation.Controller.LocalEntityId,
activation.Movement.HitGround,
activation.Motion.LeaveGround);
}
catch
{
_activationDispatchFailureCount++;
}
}
private bool IsActivationPrephaseEnvelopeCurrent(
Activation activation,
in RuntimeDormantSetPositionCommitReceipt receipt) =>

View file

@ -1,41 +0,0 @@
using AcDream.Core.Physics;
namespace AcDream.Runtime.Gameplay;
/// <summary>
/// Applies the exact server-owned run/jump snapshot to either host's one local
/// movement controller. This lives beside the canonical skill owner so
/// graphical and no-window construction cannot drift.
/// </summary>
public static class RuntimeMovementSkillProjection
{
public static bool ApplyTo(
RuntimeMovementSkillState skills,
PlayerMovementController? controller)
{
ArgumentNullException.ThrowIfNull(skills);
RuntimeMovementSkillSnapshot snapshot = skills.Snapshot;
if (controller is null || !snapshot.IsComplete)
return false;
controller.SetCharacterSkills(
snapshot.RunSkill,
snapshot.JumpSkill);
// Campaign P Slice P1 (2026-07-30): burden/stamina ride the SAME
// seam run/jump skill already used — see the pseudocode doc §9.
controller.SetCharacterBurden(snapshot.Burden);
controller.SetCharacterStamina(snapshot.CurrentStamina);
// TS-23 (Campaign P Slice P3, 2026-07-30): the player's own
// PK/PKLite/Impenetrable collision-exemption bits and the
// PlayerKillerStatus/LastPkAttackTimestamp pair the jump-cost
// PK-timer bump reads — see EntityCollisionFlagsExt.ToMoverState
// and PlayerWeenie.JumpStaminaCost.
controller.OwnPvpFlags =
EntityCollisionFlagsExt.FromPwdBitfield(snapshot.OwnPwdBitfield)
.ToMoverState();
controller.SetCharacterPkStatus(
snapshot.PlayerKillerStatus,
snapshot.LastPkAttackTimestamp);
return true;
}
}

View file

@ -272,6 +272,39 @@ internal static class RuntimeAuthoritativePositionRouteClassifier
reporting);
}
/// <summary>
/// C3c-R1 review F7: converts an already-classified SetPosition-performing
/// initial-Create route into the EXACT celless (AwaitFreshPosition) shape
/// the Parented/PickedUp branch of <see cref="ClassifyCreate"/> produces,
/// preserving the route's authority, operation kind, and collision-batch
/// eligibility. A host with a bounded collision neighborhood (headless)
/// applies this to a remote/projectile Create whose destination landblock
/// that neighborhood will never publish — the parked placement's
/// collision-generation wake could otherwise never fire. The residence
/// then completes celless (FullCell stays 0, the accepted wire frame
/// stays on the canonical snapshot), mirroring the pre-flip direct-host
/// accepted-frame behavior for far remotes; a later fresh Position event
/// owns any subsequent placement.
/// </summary>
internal static RuntimeAuthoritativePositionRoute ToCellessCreateRoute(
in RuntimeAuthoritativePositionRoute route) =>
new(
route.Authority,
RuntimeAuthoritativePositionDisposition.AwaitFreshPosition,
route.OperationKind,
PhysicsSetPositionFlags.None,
0u,
UnparentBeforeRouting: false,
ApplyPlacementFrameBeforeRouting: false,
LeaveWorld: false,
TeleportHookPhase: RuntimeTeleportHookPhase.None,
StopInterpolating: false,
ConstrainPhase: RuntimePositionConstrainPhase.None,
PreserveHeading: false,
ZeroVelocity: false,
SendPositionImmediately: false,
route.CollisionBatchEligible);
internal static RuntimeAuthoritativePositionRoute ClassifyAcceptedPosition(
in RuntimeAcceptedPositionRouteRequest request)
{

View file

@ -1987,9 +1987,13 @@ public sealed class RuntimePhysicsState : IDisposable
{
EnsureNotDisposed();
EnsureCollisionMutationThread();
uint canonical = CanonicalLandblock(landblockId);
if (canonical == 0u)
// C3c-F3: the old `canonical == 0u` check was dead (CanonicalLandblock
// ORs in 0xFFFF, so it never returns 0) — the real absent-id guard is
// on the raw input. Landblock (0,0) canonicalizes to 0x0000FFFF and
// is fully legal here.
if (landblockId == 0u)
throw new ArgumentOutOfRangeException(nameof(landblockId));
uint canonical = CanonicalLandblock(landblockId);
return SetPosition.BeginCollisionPrefixQuiescence(
canonical,
collisionGeneration,
@ -2034,6 +2038,13 @@ public sealed class RuntimePhysicsState : IDisposable
{
EnsureNotDisposed();
EnsureCollisionMutationThread();
// C3c-F3: an absent landblock id (0) canonicalizes to 0x0000FFFF —
// the REAL map-corner landblock — so it must be rejected at the
// admission entrance. The prefix-0 sentinel used to (accidentally,
// and only at commit time) catch this caller bug; with prefix
// 0x00000000 now legal, the explicit guard is the only protection.
if (landblockId == 0u)
throw new ArgumentOutOfRangeException(nameof(landblockId));
uint canonical = CanonicalLandblock(landblockId);
if (_collisionPrefixMutations.ContainsKey(canonical))
{
@ -2622,9 +2633,13 @@ public sealed class RuntimePhysicsState : IDisposable
{
EnsureNotDisposed();
EnsureCollisionMutationThread();
uint canonical = CanonicalLandblock(landblockId);
if (canonical == 0u)
// C3c-F3: absent-id guard on the raw input — the old
// `canonical == 0u` test was dead (CanonicalLandblock never returns
// 0), and the corner landblock (canonical 0x0000FFFF) retires like
// any other.
if (landblockId == 0u)
throw new ArgumentOutOfRangeException(nameof(landblockId));
uint canonical = CanonicalLandblock(landblockId);
if (kind is RuntimeCollisionPrefixMutationKind.Activation)
throw new ArgumentOutOfRangeException(nameof(kind));
@ -2944,6 +2959,27 @@ public sealed class RuntimePhysicsState : IDisposable
: 1UL;
}
/// <summary>
/// True when a collision evaluation may read this cell's landblock right
/// now — no admission is in flight for it and its prefix is not quiescing.
/// <see cref="TrySealCollisionEvaluationAuthority"/> enforces exactly this
/// per queried prefix, so any owner that is about to DEPEND on a
/// successful seal must consult the same predicate first. C3c-F2: the
/// dormant local-player activation rearm did not, so a collision-generation
/// commit that reentered the first-entry pump before its own admission
/// retired rearmed the parked lease out of AwaitingCell, immediately failed
/// this seal, and — no longer being AwaitingCell — was reported as
/// RejectedAuthority (terminal) instead of "still waiting". That dropped
/// the login conductor for the whole session.
/// </summary>
internal bool IsCollisionEvaluationPrefixAdmissible(uint exactCellId)
{
uint landblockId = CanonicalLandblock(exactCellId);
return landblockId != 0u
&& !_collisionAdmissions.ContainsKey(landblockId)
&& !SetPosition.IsCollisionPrefixQuiescing(landblockId);
}
/// <summary>
/// Exact collision-prefix generation authority used by private
/// SetPosition evaluations. Beginning a replacement generation advances
@ -3021,8 +3057,7 @@ public sealed class RuntimePhysicsState : IDisposable
}
foreach (uint prefix in prefixes)
{
if (_collisionAdmissions.ContainsKey(prefix)
|| SetPosition.IsCollisionPrefixQuiescing(prefix))
if (!IsCollisionEvaluationPrefixAdmissible(prefix))
return false;
}

View file

@ -109,8 +109,14 @@ internal readonly record struct RuntimeCollisionPrefixQuiescenceToken(
ulong CollisionGeneration,
ulong OperationId)
{
internal bool IsValid => LandblockPrefix != 0u
&& (LandblockPrefix & 0xFFFFu) == 0u
// C3c-F3: presence is discriminated by OperationId (allocated from a
// monotonic counter starting at 1, so a default token always carries 0)
// and CollisionGeneration (generations also start at 1) — NOT by
// LandblockPrefix != 0. Prefix 0x00000000 is the legitimate prefix of
// landblock (0,0) (id 0x0000FFFF, Dereth's map corner); the old
// prefix-based term made every real corner-landblock token read as
// invalid, wedging TryGetCurrentQuiescence and every release path.
internal bool IsValid => (LandblockPrefix & 0xFFFFu) == 0u
&& CollisionGeneration != 0UL
&& OperationId != 0UL;
}
@ -778,9 +784,14 @@ internal sealed class RuntimeSetPositionState : IDisposable
EnsureNotDisposed();
if (collisionGeneration == 0UL)
throw new ArgumentOutOfRangeException(nameof(collisionGeneration));
uint prefix = landblockId & 0xFFFF0000u;
if (prefix == 0u)
// C3c-F3: reject only the genuinely-absent landblock id (0). Prefix
// 0x00000000 is landblock (0,0) — the map corner — so a prefix == 0
// test can no longer stand in for "no landblock"; that sentinel
// collision crashed every collision publication whose streaming
// window reached the corner (connected-gate 20260802-135444).
if (landblockId == 0u)
throw new ArgumentOutOfRangeException(nameof(landblockId));
uint prefix = landblockId & 0xFFFF0000u;
if (_collisionPrefixQuiescence.TryGetValue(
prefix,
@ -1848,6 +1859,45 @@ internal sealed class RuntimeSetPositionState : IDisposable
&& operation.WakeableLostCell;
}
/// <summary>
/// C3c-F2: the identity check below is against
/// <see cref="RuntimePhysicsState.CollisionGenerationAuthority"/> — the
/// generation the collision world currently HOLDS — not against
/// <c>ExpectedCollisionGeneration</c>, which means two different things
/// at the two ends of this wait. At park time (this class's own
/// <c>TryPrepareDormantLocalActivationCommit</c>) an admission for the
/// destination landblock is in flight, so Expected == that admission's
/// generation G and the lease correctly parks against G. The wake that
/// sets <c>CollisionGenerationReady</c> is
/// <c>CommitCollisionGeneration(lb, G, ready)</c>, and the very next
/// statement in RuntimePhysicsState retires the admission
/// (AdvanceCommittedActivation) while leaving the committed generation at
/// G — from that instant Expected returns G+1, a generation that does not
/// exist and may never be begun. Comparing the parked G against Expected
/// therefore refused every login rearm forever (the connected-gate
/// DeferredCell wedge: controller never published, world never visible).
/// The committed-authority comparison keeps every staleness guarantee: a
/// superseding BeginCollisionAdmission or a CancelCollisionGeneration
/// moves the authority off G and this lease still refuses to rearm.
///
/// <para>
/// The trailing
/// <see cref="RuntimePhysicsState.IsCollisionEvaluationPrefixAdmissible"/>
/// term is the second half of the same C3c-F2 defect and is what the live
/// probe caught: the collision-generation commit reenters the host's
/// first-entry pump BEFORE its own admission is retired
/// (RuntimePhysicsState.cs:2503 commits the generation, :2552-2558 retires
/// the admission). Rearming inside that window moves the lease out of
/// AwaitingCell and the very next evaluation fails
/// <c>TrySealCollisionEvaluationAuthority</c> on the still-registered
/// admission — at which point EvaluateActivation can no longer report
/// DeferredCell (the operation is no longer AwaitingCell) and returns
/// RejectedAuthority, which is TERMINAL for the conductor. Refusing the
/// rearm until the prefix is evaluable keeps the lease parked and
/// retryable, exactly as the remote wake path already does with
/// <c>TryGetBlockingQuiescence</c> (:4069-4095).
/// </para>
/// </summary>
private bool TryRearmDeferredDormantLocalActivation(
RuntimeEntityRecord record,
PhysicsBody body,
@ -1868,8 +1918,10 @@ internal sealed class RuntimeSetPositionState : IDisposable
|| !operation.CollisionGenerationReady
|| operation.ProjectionSequence != 0UL
|| operation.CollisionGeneration != _physics
.ExpectedCollisionGeneration(operation.ExactCellId)
|| !_physics.Engine.IsSpawnCellReady(operation.ExactCellId))
.CollisionGenerationAuthority(operation.ExactCellId)
|| !_physics.Engine.IsSpawnCellReady(operation.ExactCellId)
|| !_physics.IsCollisionEvaluationPrefixAdmissible(
operation.ExactCellId))
{
return false;
}
@ -3366,14 +3418,19 @@ internal sealed class RuntimeSetPositionState : IDisposable
command);
CollisionPrefixQuiescence? quiescence =
_collisionPrefixQuiescence.GetValueOrDefault(prefix);
// C3c-F3: pass the overrides through as genuinely optional —
// `quiescence?.` yields null (absent) with no quiescence and the
// token's exact values (present, prefix 0x00000000 included)
// with one. The old `?? 0u` collapse made a corner-landblock
// quiescence indistinguishable from "no quiescence".
RuntimeSetPositionOutcome parked = ParkDeferred(
operation,
result,
publishImmediately: false,
collisionGenerationOverride:
quiescence?.Token.CollisionGeneration ?? 0UL,
quiescence?.Token.CollisionGeneration,
collisionPrefixOverride:
quiescence?.Token.LandblockPrefix ?? 0u);
quiescence?.Token.LandblockPrefix);
if (_pendingProjection.TryGetValue(
parked.Projection.Sequence,
out RuntimePlacementProjectionSnapshot staged))
@ -3929,12 +3986,22 @@ internal sealed class RuntimeSetPositionState : IDisposable
_operationPool.Clear();
}
/// <summary>
/// C3c-F3: the quiescence-override pair is nullable — null means "no
/// quiescence holds this park", a present value means "parked under that
/// quiescence's exact prefix/generation". Nullable uint is the chosen
/// has-prefix representation for the whole chain because the previous
/// 0-sentinel collided with landblock (0,0)'s legitimate prefix
/// 0x00000000: a corner-landblock quiescence override read as "absent",
/// so <see cref="Operation.CollisionQuiescenceHeld"/> derived false and
/// the parked operation skipped the QuiescenceHeld stage entirely.
/// </summary>
private RuntimeSetPositionOutcome ParkDeferred(
Operation operation,
in PhysicsSetPositionResult result,
bool publishImmediately = true,
ulong collisionGenerationOverride = 0UL,
uint collisionPrefixOverride = 0u)
ulong? collisionGenerationOverride = null,
uint? collisionPrefixOverride = null)
{
PhysicsBody body = operation.Body!;
body.Orientation = result.Orientation;
@ -3969,13 +4036,11 @@ internal sealed class RuntimeSetPositionState : IDisposable
operation.WakeableLostCell = true;
operation.EnteringWorldFromCelllessResidence = true;
ArmLostFamilyDeadlines(operation);
operation.CollisionGeneration = collisionGenerationOverride != 0UL
? collisionGenerationOverride
: _physics.ExpectedCollisionGeneration(result.CellId);
operation.CollisionPrefix = collisionPrefixOverride != 0u
? collisionPrefixOverride
: result.CellId & 0xFFFF0000u;
operation.CollisionQuiescenceHeld = collisionPrefixOverride != 0u;
operation.CollisionGeneration = collisionGenerationOverride
?? _physics.ExpectedCollisionGeneration(result.CellId);
operation.CollisionPrefix = collisionPrefixOverride
?? result.CellId & 0xFFFF0000u;
operation.CollisionQuiescenceHeld = collisionPrefixOverride.HasValue;
operation.Command = operation.Command with
{
Physics = operation.Command.Physics with

View file

@ -0,0 +1,354 @@
using AcDream.Content;
using AcDream.Runtime.Entities;
using AcDream.Runtime.Gameplay;
using AcDream.Runtime.Physics;
namespace AcDream.Runtime.Session;
/// <summary>
/// C3c: the host-driven pump that walks every initial-Create residence
/// through its first-entry conductor. One instance per host session route;
/// graphical and no-window hosts construct it with their own prepared
/// collision source and local-player activation-preparation provider and
/// call <see cref="DriveAll"/> from their own cadence (post-Create
/// hydration and the per-frame placement retry phase for the graphical
/// host; spawn/position projection and the session tick for headless).
///
/// The controller owns NO placement state — it records which entities hold
/// a fresh residence lease (via
/// <see cref="RuntimeEntityObjectLifetime.BindInitialResidenceBeginNotification"/>)
/// and repeatedly calls the conductors, which re-validate all currency
/// themselves. Terminal yields (Completed/RejectedToken/RejectedAuthority)
/// drop the entry; every Awaiting*/Contention yield keeps it for the next
/// pump.
///
/// Continuation placements (the executor's AwaitingContinuationPlacement
/// yield) are completed here through the C0 fused
/// <see cref="RuntimeSetPositionState.TryPrepareAndSubmitAuthoredPlacement"/>
/// — legal for a continuation operation, which never has
/// DormantLocalActivation set — followed by head acknowledgement. The
/// production sink may consume the resulting Place first (the residence is
/// already consumed by then, so the sink's residence gate does not fire);
/// a failed acknowledgement after that is benign — the executor's
/// ResumePendingPlacement keys off the retained acknowledged completion,
/// not off who acknowledged.
/// </summary>
internal sealed class RuntimeFirstEntryDriveController
{
/// <summary>
/// Bounded chase of synchronous progress inside one entity's drive —
/// enough for mover-prep + placement + acknowledgement + a handful of
/// continuation placements in a single pump without risking an unbounded
/// loop against a livelocked yield.
/// </summary>
private const int MaxSynchronousStepsPerEntity = 16;
private sealed class Pending
{
internal required RuntimeEntityRecord Record { get; init; }
internal required RuntimeInitialCreateResidenceToken Token { get; init; }
internal required bool IsLocalPlayer { get; init; }
}
private readonly RuntimeEntityObjectLifetime _entityObjects;
private readonly IGameRuntimeClock _clock;
private readonly IPreparedCollisionSource _collisionSource;
private readonly Func<PlayerMovementConstructionOptions> _localOptions;
private readonly Func<RuntimeEntityRecord,
RuntimeLocalPlayerPhysicsActivationPreparation> _localActivation;
private readonly Dictionary<RuntimeEntityKey, Pending> _pending = [];
private readonly List<RuntimeEntityKey> _driveScratch = [];
private bool _driving;
/// <summary>C3c-R1 review F6: see <see cref="AttachRoute"/>.</summary>
private object? _routeOwner;
internal RuntimeFirstEntryDriveController(
RuntimeEntityObjectLifetime entityObjects,
IGameRuntimeClock clock,
IPreparedCollisionSource collisionSource,
Func<PlayerMovementConstructionOptions> localOptions,
Func<RuntimeEntityRecord,
RuntimeLocalPlayerPhysicsActivationPreparation> localActivation)
{
_entityObjects = entityObjects
?? throw new ArgumentNullException(nameof(entityObjects));
_clock = clock ?? throw new ArgumentNullException(nameof(clock));
_collisionSource = collisionSource
?? throw new ArgumentNullException(nameof(collisionSource));
_localOptions = localOptions
?? throw new ArgumentNullException(nameof(localOptions));
_localActivation = localActivation
?? throw new ArgumentNullException(nameof(localActivation));
_entityObjects.BindInitialResidenceBeginNotification(
NoteResidenceBegan);
// C3c-R1 review F5: tracked-but-undriven entries fold into the
// entity-object ownership snapshot instead of sitting outside every
// ledger.
_entityObjects.RegisterFirstEntryDriveOwnership(() => _pending.Count);
}
internal int PendingCount => _pending.Count;
/// <summary>
/// Records a fresh residence for a later pump. Runs synchronously inside
/// the registration transaction (including the executor's deferred-child
/// replays, which re-enter registration mid-Execute), so it must never
/// call Advance here — only capture the exact key/token/dispatch facts.
/// </summary>
private void NoteResidenceBegan(RuntimeEntityRecord record)
{
if (record.Key is not { } key
|| !_entityObjects.TryGetInitialCreateResidence(
record,
out RuntimeInitialCreateResidenceLease lease))
{
return;
}
_pending[key] = new Pending
{
Record = record,
Token = lease.Token,
// Dispatch is decided ONCE from the lease's classified route —
// TryGetCurrent fails mid-drain (the residence moves to its
// completed table at Complete), so the lease cannot be
// re-fetched on a later pump.
IsLocalPlayer = lease.Route.OperationKind
is RuntimeSetPositionOperationKind.InitialLogin,
};
}
/// <summary>
/// Drives every tracked first-entry sequence one bounded step. Safe to
/// call from any host cadence point; re-entrant calls (a conductor's own
/// synchronous callbacks reaching a host pump) fail closed into the next
/// outer pump instead of interleaving.
/// </summary>
internal void DriveAll()
{
if (_driving || _pending.Count == 0)
return;
_driving = true;
try
{
_driveScratch.Clear();
foreach (RuntimeEntityKey key in _pending.Keys)
_driveScratch.Add(key);
foreach (RuntimeEntityKey key in _driveScratch)
{
if (_pending.TryGetValue(key, out Pending? pending))
DriveOne(key, pending);
}
}
finally
{
_driving = false;
}
}
/// <summary>
/// C3c-R1 review F6: the explicit one-route-at-a-time latch. A drive
/// controller outlives its session routes (hosts reuse it across
/// reconnects), and route teardown clears the tracked entries — so the
/// "session reset precedes a new route" ordering the hosts rely on is
/// asserted here instead of silently assumed: a second route attaching
/// before the prior route detached would otherwise let the OLD route's
/// dispose wipe the NEW route's tracked entries.
/// </summary>
internal void AttachRoute(object route)
{
ArgumentNullException.ThrowIfNull(route);
if (_routeOwner is not null && !ReferenceEquals(_routeOwner, route))
{
throw new InvalidOperationException(
"A first-entry drive controller serves one session route at "
+ "a time; the prior route must be disposed (session reset "
+ "precedes a new route) before a replacement attaches.");
}
_routeOwner = route;
}
/// <summary>
/// Route-scoped teardown: clears every tracked entry, but ONLY when
/// <paramref name="route"/> is the attached owner — a route that never
/// attached (construction rollback) or was displaced must not clear the
/// live route's entries. The conductors and residence own their own
/// convergence independently (retirement fan-out + session clear).
/// </summary>
internal void DetachRoute(object route)
{
ArgumentNullException.ThrowIfNull(route);
if (!ReferenceEquals(_routeOwner, route))
return;
_routeOwner = null;
_pending.Clear();
}
private void DriveOne(RuntimeEntityKey key, Pending pending)
{
for (int step = 0; step < MaxSynchronousStepsPerEntity; step++)
{
if (pending.Record.Key != key)
{
// Post-teardown key release; the retirement fan-out already
// reaped the conductors' own progress.
_pending.Remove(key);
return;
}
bool terminal;
bool awaitingContinuationPlacement;
if (pending.IsLocalPlayer)
{
RuntimeLocalPlayerFirstEntryStatus status =
_entityObjects.LocalPlayerFirstEntry.Advance(
pending.Record,
pending.Token,
_localOptions(),
_localActivation(pending.Record),
_collisionSource,
_clock.SimulationTimeSeconds,
inputs: default,
out _);
terminal = status
is RuntimeLocalPlayerFirstEntryStatus.Completed
or RuntimeLocalPlayerFirstEntryStatus.RejectedToken
or RuntimeLocalPlayerFirstEntryStatus.RejectedAuthority;
awaitingContinuationPlacement = status
is RuntimeLocalPlayerFirstEntryStatus
.AwaitingContinuationPlacement;
}
else
{
RuntimeRemoteFirstEntryStatus status =
_entityObjects.RemoteFirstEntry.Advance(
pending.Record,
pending.Token,
_collisionSource,
_clock.SimulationTimeSeconds,
inputs: default,
out _,
out _);
terminal = status
is RuntimeRemoteFirstEntryStatus.Completed
or RuntimeRemoteFirstEntryStatus.RejectedToken
or RuntimeRemoteFirstEntryStatus.RejectedAuthority;
awaitingContinuationPlacement = status
is RuntimeRemoteFirstEntryStatus
.AwaitingContinuationPlacement;
}
if (terminal)
{
_pending.Remove(key);
return;
}
if (!awaitingContinuationPlacement)
{
// AwaitingCollisionSource / AwaitingActivation /
// AwaitingPlacement / AwaitingReceiptAcknowledgement /
// Contention — nothing more this pump can do synchronously.
return;
}
if (!TryCompleteContinuationPlacement(key, pending.Record))
return;
// A continuation placement progressed — re-Advance so the
// executor can consume the acknowledged completion and keep
// draining.
}
}
/// <summary>
/// Completes (or makes bounded progress on) the executor's pending
/// continuation placement for <paramref name="key"/>. Returns true when
/// enough progress happened that re-calling Advance can observe it.
/// </summary>
private bool TryCompleteContinuationPlacement(
RuntimeEntityKey key,
RuntimeEntityRecord record)
{
RuntimeSetPositionState setPosition =
_entityObjects.Physics.SetPosition;
// A receipt of OURS already at the FIFO head (a Place from a prior
// submit attempt, or the Withdraw of a deferred park) is consumed
// first — acknowledgement is what re-arms a parked operation and what
// ResumePendingPlacement's retained-completion check requires.
bool acknowledgedSomething = false;
while (setPosition.TryPeekProjection(
out RuntimePlacementProjectionSnapshot head)
&& head.Token.Entity == key
&& head.Kind is RuntimePlacementProjectionKind.Place
or RuntimePlacementProjectionKind.Withdraw)
{
if (!setPosition.AcknowledgeProjection(head.Token))
break;
acknowledgedSomething = true;
}
if (!_entityObjects.InitialCreateExecution
.TryGetPendingContinuationPlacement(
key,
out RuntimeEntityPlacementToken placement))
{
// Flavor 2 (transient operation-slot contention): no token was
// ever begun; the only correct action is a later Execute retry.
return acknowledgedSomething;
}
if (!_entityObjects.InitialCreateExecution
.TryGetPendingContinuationRoute(
key,
out RuntimeAuthoritativePositionRoute route))
{
return acknowledgedSomething;
}
RuntimeSetPositionMoverPreparationStatus status =
setPosition.TryPrepareAndSubmitAuthoredPlacement(
record,
placement,
route.OperationKind,
route.SetPositionFlags,
_collisionSource,
_clock.SimulationTimeSeconds,
out RuntimeSetPositionOutcome outcome);
if (status != RuntimeSetPositionMoverPreparationStatus.Prepared)
{
// RetrySetupUnavailable retries on a later pump; a rejected
// preparation for an already-submitted-and-awaiting operation is
// driven purely by the head acknowledgements above.
return acknowledgedSomething;
}
switch (outcome.Status)
{
case RuntimeSetPositionStatus.CommittedHostAcknowledgementPending:
// The synchronous publish may already have let the production
// sink apply-and-acknowledge this exact receipt (the
// residence is consumed by drain time, so the sink's
// residence gate no longer declines it). A false return here
// is therefore benign; the retained acknowledged completion
// is what the executor consumes either way.
_ = setPosition.AcknowledgeProjection(outcome.Projection);
return true;
case RuntimeSetPositionStatus.DeferredCell:
// Parked with a published Withdraw; consume it if it is
// already the head so the collision-generation wake can
// resubmit.
while (setPosition.TryPeekProjection(
out RuntimePlacementProjectionSnapshot parked)
&& parked.Token.Entity == key
&& parked.Kind is RuntimePlacementProjectionKind.Withdraw)
{
if (!setPosition.AcknowledgeProjection(parked.Token))
break;
acknowledgedSomething = true;
}
return acknowledgedSomething;
default:
// Rejected/Cancelled — authority moved; the next Advance
// observes it and abandons through the conductor's own path.
return true;
}
}
}

View file

@ -72,8 +72,28 @@ public sealed class RuntimeLiveEntitySessionController
private void OnSpawned(WorldSession.EntitySpawn spawn)
{
RuntimeEntityRegistrationResult registration =
Entities.RegisterEntity(spawn);
// C3c route-8 flip: every direct-host Create enters the SAME initial
// residence lease graphical route 1 uses; the conductor drive (via
// IRuntimeDirectWorldProjection.ProjectSpawn and the host's pump)
// owns mover preparation, body/controller construction, placement,
// and the FIFO drain from here.
//
// C3c-R1 review R3: a CONTENT-LESS host (a validated-legal headless
// configuration — HeadlessConfigurationLoader.ValidateContent
// accepts a null process.content) constructs no world projection
// and therefore no first-entry drive; opening a residence with no
// drive to pump it would park every Create (and every position/
// state packet queued behind its pending residence) forever. That
// configuration keeps the exact pre-flip legacy registration:
// presentation-free RegisterEntity plus the direct accepted-frame
// commit below. C4/C5 revisit: unify once the direct-host conductor
// drive no longer requires prepared content.
RuntimeEntityRegistrationResult registration = _worldProjection is null
? Entities.RegisterEntity(spawn)
: Entities.RegisterEntityWithInitialResidence(
spawn,
isLocalPlayer: spawn.Guid
== _runtime.PlayerIdentity.ServerGuid);
if (registration.Canonical is not { } canonical)
return;