feat(runtime): C3c - production placement cutover: both hosts on the residence conductors (routes 1+8)
Campaign P remaining-physics-divergence, placement cutover slice C3c
(docs/plans/2026-08-02-placement-cutover.md). Both production hosts now
register every initial Create through the residence + continuation-
executor + first-entry-conductor machinery (C0-C3b):
- Graphical (route 1): RegisterEntityWithInitialResidence at Create; the
shared RuntimeFirstEntryDriveController pumps both conductors from the
placement-receipt flow; MaterializeProjection and RebucketLiveEntity
are presentation-only while a residence is ACTIVE (ExecutorCompleted is
the presentation-binding receipt); post-residence entities take the
full legacy path including the prepare_to_enter_world clock edges.
PlayerModeController attaches presentation to the Runtime-published
controller; its legacy resolve/step-heights/host-construction path is
deleted; presentation-only rollback (retail has no entry-flow rollback).
- Headless (route 8): OnSpawned registers with residence when a drive
exists; content-less sessions keep the pre-flip direct registration;
SynchronizeLocalPlayer/CreateController/ApplySetupStepHeights deleted;
prepared-collision read failure is a typed AwaitingCollisionSource
retry; far remotes outside the service window complete celless.
- RuntimeLocalPlayerMovementState.Controller setter sealed internal; all
controller mutation flows through the publication lifecycle.
Fix slices landed within this cutover, each dual-gated:
- F1: live movement-stat/server-physics application routed through the
Runtime ownership seam (post-logout ingest crash on the retired
controller eliminated; RuntimeMovementSkillProjection deleted).
- F2: login activation wedge - collision-admission prefix gate factored
out of the seal (reentrant-commit RejectedAuthority), rearm generation
identity corrected, PlayerModeAutoEntry requires the Runtime-published
controller (world reveal can no longer seal unmaterialized).
- F3: landblock-prefix 0-sentinel replaced by explicit absent-id guards;
map-corner landblocks (grid row/col 0) fully legal through admission,
park/rearm/retire, quiescence, and outdoor shadow seeds.
- F5: local-player first-entry ground contact seeded by the shared
SpawnPlacementSettler (moved App->Core) at FinalizeActivation - the
retail first-gravity-frame touch (enter_world 0x00516170 carries no
seed); the legacy unconditional force-seed is overwritten by a real
floor-found contact; airborne spawns stay airborne; outbound contact
bit verified end-to-end. Fixes the standing-cast 'You can't do that
while in the air!' rejections.
- R1 (dual-review round): login constraint leash armed at the committed
placement (HandleReceivedPosition 0x00453FD0 analog); register rows
AD-61 (settle-timing compression now covering the local player) and
AD-42 (repointed off the deleted resolve split) in this commit;
residence-conversion owner API; wire-landblock guards; drive-pending
ledger in IsConverged; route attach/detach latch; executor-drain drift
model documented + source-pinned.
Gates: Runtime 1,003, App 4,039/3 skips, Headless 79, complete solution
10,816/0 failed/4 skips (Release, -m:1); connected lifecycle/reconnect
gate PASS (logs/connected-world-gate-20260802-175401; graceful exits,
world-visible, zero airborne rejections). The nine-stop soak remains red
for the pre-existing 6b28ff99 whole-world collision-clone throughput
regression (attributed with evidence; scheduled as its own slice before
C5). Dual Opus reviews (retail-conformance + adversarial): delta PASS.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
parent
78f1eb1896
commit
529e0e9d88
68 changed files with 5977 additions and 831 deletions
|
|
@ -14,6 +14,70 @@ public interface IRuntimeLocalPlayerMotionSource
|
|||
MotionInterpreter? Motion { get; }
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// C3c-F1 (2026-08-02): typed outcome of routing a server movement-stat
|
||||
/// recompute through the Runtime movement owner. The dropped outcomes are
|
||||
/// the J3.6 displaced-callback-rejection pattern — never an exception and
|
||||
/// never a silent void: the caller logs them under its existing
|
||||
/// diagnostics. A skill write against a dead session is meaningless by
|
||||
/// design; the next login re-derives everything from PlayerDescription.
|
||||
/// </summary>
|
||||
public enum RuntimeMovementStatsApplication
|
||||
{
|
||||
/// <summary>Applied to the live (published/standalone) controller —
|
||||
/// byte-identical to the pre-F1 direct application path.</summary>
|
||||
AppliedLive,
|
||||
|
||||
/// <summary>Applied to the Runtime-owned dormant controller during the
|
||||
/// committed-but-not-yet-activated first-entry window. The same
|
||||
/// instance goes live at activation, so the values are already current
|
||||
/// when movement starts.</summary>
|
||||
AppliedDormant,
|
||||
|
||||
/// <summary>No controller is installed (pre-first-entry, mid-candidate
|
||||
/// construction, or after session teardown cleared the owner).</summary>
|
||||
DroppedNoController,
|
||||
|
||||
/// <summary>The skill snapshot has no authoritative run/jump values yet
|
||||
/// (PlayerDescription not processed) — same silent skip as the pre-F1
|
||||
/// path.</summary>
|
||||
DroppedIncompleteSnapshot,
|
||||
|
||||
/// <summary>The installed controller is terminal (sealed, retired, or
|
||||
/// discarded): a displaced post-teardown write, reported instead of
|
||||
/// faulting the session.</summary>
|
||||
DroppedDisplacedController,
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// C3c-F1 (2026-08-02): typed outcome of routing an inbound server
|
||||
/// PhysicsState push through the local movement controller's publication
|
||||
/// lifecycle. Same displaced-callback-rejection family as
|
||||
/// <see cref="RuntimeMovementStatsApplication"/>, with one deliberate
|
||||
/// difference: the dormant window DROPS the push rather than applying it,
|
||||
/// because the activation transaction owns the dormant body's physics
|
||||
/// state exclusively (it re-reads the canonical record's FinalPhysicsState
|
||||
/// through <c>RefreshDormantRuntimePhysicsState</c> at both activation
|
||||
/// phases), and the App-side push carries that exact same unchanged record
|
||||
/// value while the accepted SetState itself is queued behind the initial
|
||||
/// residence — dropping it is value-preserving by construction.
|
||||
/// </summary>
|
||||
public enum RuntimeServerPhysicsStateApplication
|
||||
{
|
||||
/// <summary>Applied to the live (published/standalone) controller —
|
||||
/// byte-identical to the direct <c>ApplyPhysicsState</c> path.</summary>
|
||||
AppliedLive,
|
||||
|
||||
/// <summary>The controller is Runtime-owned dormant: the activation
|
||||
/// pipeline is the sole authority for the dormant body's physics state
|
||||
/// and re-reads the canonical value itself.</summary>
|
||||
DroppedDormantActivationOwned,
|
||||
|
||||
/// <summary>The installed controller is terminal — a displaced
|
||||
/// post-teardown push.</summary>
|
||||
DroppedDisplacedController,
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Canonical local movement lifetime and intent owner. Graphical input,
|
||||
/// presentation, diagnostics, and future no-window hosts borrow this exact
|
||||
|
|
@ -37,7 +101,13 @@ public sealed class RuntimeLocalPlayerMovementState
|
|||
public PlayerMovementController? Controller
|
||||
{
|
||||
get => _controller;
|
||||
set
|
||||
// C3c seal: the public write escape hatch is closed. Production
|
||||
// controller installation flows only through the publication
|
||||
// lifecycle (CommitRuntimeOwnedController via
|
||||
// RuntimeLocalPlayerPhysicsPublicationState.Commit) and teardown
|
||||
// through ResetSession/Dispose/DiscardActivation. The setter stays
|
||||
// reachable for tests via InternalsVisibleTo only.
|
||||
internal set
|
||||
{
|
||||
ObjectDisposedException.ThrowIf(_disposed, this);
|
||||
if (ReferenceEquals(_controller, value))
|
||||
|
|
@ -189,6 +259,44 @@ public sealed class RuntimeLocalPlayerMovementState
|
|||
return true;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// C3c-F1 (2026-08-02): the ONLY route by which server-authoritative
|
||||
/// movement stats (run/jump skill, burden, stamina, PK status — the
|
||||
/// exact field set of the deleted
|
||||
/// <c>RuntimeMovementSkillProjection.ApplyTo</c>) reach the local
|
||||
/// movement controller. App holds no controller reference for stat
|
||||
/// application and performs no direct configuration mutation; the
|
||||
/// owner's publication lifecycle decides whether the write lands
|
||||
/// (live/dormant) or is reported as a typed displaced drop (terminal) —
|
||||
/// the fix for the connected-gate post-logout ingest crash at
|
||||
/// <c>PlayerMovementController.EnsureConfigurationMutable</c>.
|
||||
/// Deliberately tolerant of a disposed owner: a recompute displaced
|
||||
/// past teardown observes <see cref="RuntimeMovementStatsApplication.DroppedNoController"/>
|
||||
/// instead of faulting the session.
|
||||
/// </summary>
|
||||
public RuntimeMovementStatsApplication ApplyCharacterMovementStats(
|
||||
RuntimeMovementSkillState skills)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(skills);
|
||||
if (_controller is not { } controller)
|
||||
return RuntimeMovementStatsApplication.DroppedNoController;
|
||||
RuntimeMovementSkillSnapshot snapshot = skills.Snapshot;
|
||||
if (!snapshot.IsComplete)
|
||||
return RuntimeMovementStatsApplication.DroppedIncompleteSnapshot;
|
||||
return controller.ApplyCharacterMovementStats(snapshot);
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// C3c-F1: routes the stamina-exhaustion EVENT (retail
|
||||
/// <c>CommandInterpreter::HandleExhaustion</c>) through the owner so the
|
||||
/// App edge-tracker never touches the gated controller motion surface.
|
||||
/// Returns false when no live controller can dispatch it (absent,
|
||||
/// dormant, terminal, or disposed owner) — displaced-callback-tolerant
|
||||
/// for the same reason as <see cref="ApplyCharacterMovementStats"/>.
|
||||
/// </summary>
|
||||
public bool ReportExhaustion() =>
|
||||
_controller?.ReportExhaustionAtMovementBoundary() == true;
|
||||
|
||||
/// <summary>
|
||||
/// Direct-host projection of the same combat readiness query used by the
|
||||
/// graphical attack adapter. A host without a constructed local movement
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue