feat(runtime): C3c - production placement cutover: both hosts on the residence conductors (routes 1+8)

Campaign P remaining-physics-divergence, placement cutover slice C3c
(docs/plans/2026-08-02-placement-cutover.md). Both production hosts now
register every initial Create through the residence + continuation-
executor + first-entry-conductor machinery (C0-C3b):

- Graphical (route 1): RegisterEntityWithInitialResidence at Create; the
  shared RuntimeFirstEntryDriveController pumps both conductors from the
  placement-receipt flow; MaterializeProjection and RebucketLiveEntity
  are presentation-only while a residence is ACTIVE (ExecutorCompleted is
  the presentation-binding receipt); post-residence entities take the
  full legacy path including the prepare_to_enter_world clock edges.
  PlayerModeController attaches presentation to the Runtime-published
  controller; its legacy resolve/step-heights/host-construction path is
  deleted; presentation-only rollback (retail has no entry-flow rollback).
- Headless (route 8): OnSpawned registers with residence when a drive
  exists; content-less sessions keep the pre-flip direct registration;
  SynchronizeLocalPlayer/CreateController/ApplySetupStepHeights deleted;
  prepared-collision read failure is a typed AwaitingCollisionSource
  retry; far remotes outside the service window complete celless.
- RuntimeLocalPlayerMovementState.Controller setter sealed internal; all
  controller mutation flows through the publication lifecycle.

Fix slices landed within this cutover, each dual-gated:
- F1: live movement-stat/server-physics application routed through the
  Runtime ownership seam (post-logout ingest crash on the retired
  controller eliminated; RuntimeMovementSkillProjection deleted).
- F2: login activation wedge - collision-admission prefix gate factored
  out of the seal (reentrant-commit RejectedAuthority), rearm generation
  identity corrected, PlayerModeAutoEntry requires the Runtime-published
  controller (world reveal can no longer seal unmaterialized).
- F3: landblock-prefix 0-sentinel replaced by explicit absent-id guards;
  map-corner landblocks (grid row/col 0) fully legal through admission,
  park/rearm/retire, quiescence, and outdoor shadow seeds.
- F5: local-player first-entry ground contact seeded by the shared
  SpawnPlacementSettler (moved App->Core) at FinalizeActivation - the
  retail first-gravity-frame touch (enter_world 0x00516170 carries no
  seed); the legacy unconditional force-seed is overwritten by a real
  floor-found contact; airborne spawns stay airborne; outbound contact
  bit verified end-to-end. Fixes the standing-cast 'You can't do that
  while in the air!' rejections.
- R1 (dual-review round): login constraint leash armed at the committed
  placement (HandleReceivedPosition 0x00453FD0 analog); register rows
  AD-61 (settle-timing compression now covering the local player) and
  AD-42 (repointed off the deleted resolve split) in this commit;
  residence-conversion owner API; wire-landblock guards; drive-pending
  ledger in IsConverged; route attach/detach latch; executor-drain drift
  model documented + source-pinned.

Gates: Runtime 1,003, App 4,039/3 skips, Headless 79, complete solution
10,816/0 failed/4 skips (Release, -m:1); connected lifecycle/reconnect
gate PASS (logs/connected-world-gate-20260802-175401; graceful exits,
world-visible, zero airborne rejections). The nine-stop soak remains red
for the pre-existing 6b28ff99 whole-world collision-clone throughput
regression (attributed with evidence; scheduled as its own slice before
C5). Dual Opus reviews (retail-conformance + adversarial): delta PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-02 18:10:33 +02:00
parent 78f1eb1896
commit 529e0e9d88
68 changed files with 5977 additions and 831 deletions

View file

@ -278,13 +278,43 @@ internal sealed class RuntimeLocalPlayerPhysicsPublicationState : IDisposable
getObjectA: id => _physics.TryGetPhysicsHost(id, out var host)
? host
: null,
handleUpdateTarget: movement.HandleUpdateTarget,
// C3c: the [autowalk-target]/[autowalk-end] probes moved here
// with controller construction (previously App-side in
// PlayerModeController.BuildControllerAndCamera); they stay on
// the PhysicsDiagnostics owner exactly as before.
handleUpdateTarget: info =>
{
if (PhysicsDiagnostics.ProbeAutoWalkEnabled)
{
Console.WriteLine(
$"[autowalk-target] object=0x{info.ObjectId:X8} "
+ $"status={info.Status} context={info.ContextId} "
+ $"target=({info.TargetPosition.Frame.Origin.X:F2},"
+ $"{info.TargetPosition.Frame.Origin.Y:F2},"
+ $"{info.TargetPosition.Frame.Origin.Z:F2})");
}
movement.HandleUpdateTarget(info);
},
interruptCurrentMovement: () =>
movement.CancelMoveTo(WeenieError.ActionCancelled));
{
if (PhysicsDiagnostics.ProbeAutoWalkEnabled
&& movement.IsMovingTo())
{
Console.WriteLine("[autowalk-end] reason=interrupt");
}
movement.CancelMoveTo(WeenieError.ActionCancelled);
});
movement.MakeMoveToManager();
motion.UnstickFromObject = physicsHost.PositionManager.UnStick;
motion.InterruptCurrentMovement = () =>
{
if (PhysicsDiagnostics.ProbeAutoWalkEnabled
&& movement.IsMovingTo())
{
Console.WriteLine("[autowalk-end] reason=interrupt");
}
movement.CancelMoveTo(WeenieError.ActionCancelled);
};
controller.PositionManager = physicsHost.PositionManager;
// This checkpoint publishes ownership only. The subsequent canonical
// SetPosition transaction is the sole authority which may enter the
@ -687,11 +717,106 @@ internal sealed class RuntimeLocalPlayerPhysicsPublicationState : IDisposable
_physics.SetPosition.DispatchDormantLocalActivationShadow(committed);
if (!IsCommittedActivationSuffixCurrent(activation, committed))
return committed.Status;
ArmFirstEntryConstraintLeash(activation);
SettleFirstEntryGroundContact(activation);
_physics.SetPosition.DispatchDormantLocalActivationPlacement(committed);
projection = committed.Projection.Token;
return committed.Status;
}
/// <summary>
/// C3c-R1: the login-entry constraint-leash arm the flip deleted with
/// the App-side <c>CommitPreparedPosition</c> caller. Ordering, with
/// file:line justification:
/// <list type="bullet">
/// <item>NOT at <c>Prepare</c> — <c>PreparePositionForCommit</c> (:219)
/// runs with <c>publishSharedState: false</c> and the controller's
/// <c>PositionManager</c> binds only later at :318, so the leash cannot
/// exist there (nor should it: the position is not accepted yet).</item>
/// <item>NOT at publication <c>Commit</c> — the activation's placement
/// evaluation (retail find-placement ring search) may still move or
/// reject the position.</item>
/// <item>HERE, after <c>TryApplyDormantLocalActivationFinalCommit</c>
/// (RuntimeSetPositionState.cs:2494-2516 commits the final cell,
/// activates the controller, and publishes the shared current cell) and
/// inside the same <c>IsCommittedActivationSuffixCurrent</c> gate the
/// settle uses — a stale suffix skips the arm exactly like the settle
/// (never armed on stale authority).</item>
/// <item>BEFORE <see cref="SettleFirstEntryGroundContact"/> — retail
/// arms anchored to the RECEIVED position
/// (<c>SmartBox::HandleReceivedPosition</c> 0x00453FD0) and only then
/// simulates the first gravity frame, which the settle compresses; the
/// anchor is therefore the committed placement, not the post-settle
/// pose.</item>
/// <item>Exactly once — <c>_activation</c> is nulled at :716 before
/// this suffix, so a resumed <c>AwaitingFinalShadowPreparation</c>
/// retry can never re-enter it after a successful final commit.</item>
/// </list>
/// </summary>
private void ArmFirstEntryConstraintLeash(Activation activation)
{
// Same containment as the settle below: the placement commit has
// already succeeded; a leash-arm failure must not unwind the suffix.
try
{
activation.Controller.ArmConstraintLeashAtCommittedPlacement();
}
catch
{
_activationDispatchFailureCount++;
}
}
/// <summary>
/// C3c-F5: retail seeds the LOCAL player's ground contact from the first
/// gravity frame after <c>enter_world</c>, never from the placement
/// itself — <c>SmartBox::HandleCreateObject</c> (0x00454C80) runs
/// <c>init_player</c> (0x00455010) then <c>CPhysicsObj::enter_world</c>
/// (0x00455095 → 0x00516170), whose <c>SetPosition</c> validates the
/// spot but records no touch and whose tail only sets ACTIVE (0x80).
/// Every retail CPhysicsObj then simulates, falls the few centimetres
/// onto the floor, and the transition's touch grants the contact plane
/// + CONTACT/ON_WALKABLE. The dormant activation's just-finished commit
/// is the faithful SetPosition port, so a fresh login body would start
/// airborne here; this compresses the settle exactly like the #270
/// remote-spawn seed (the shared <see cref="SpawnPlacementSettler"/>):
/// a short downward sweep whose real touch produces the state retail's
/// first frame would. No floor within reach (a genuine airborne spawn)
/// leaves the body airborne — the ordinary per-tick gravity fall owns
/// it from there. The body transients this commits ARE the controller's
/// grounded state (<c>PlayerMovementController.CanSendPositionEvent</c>
/// reads <c>InContact &amp;&amp; OnWalkable</c> off the same body) and
/// the outbound wire contact bit (<c>LocalPlayerOutboundController</c>
/// serializes that predicate) — the flag ACE's "You can't do that while
/// in the air!" gate reads.
/// </summary>
private void SettleFirstEntryGroundContact(Activation activation)
{
// Same post-commit callback-dispatch containment as the ground-edge
// dispatch in CommitActivation: the placement commit has already
// succeeded; a HitGround-side failure must not unwind the suffix.
try
{
_ = SpawnPlacementSettler.TrySettle(
_physics.Engine,
activation.Body,
activation.Body.Position,
activation.Body.CellPosition.ObjCellId,
activation.ActivationPreparation.Radius,
activation.ActivationPreparation.Height,
ObjectInfoState.IsPlayer
| ObjectInfoState.EdgeSlide
| activation.Controller.OwnPvpFlags,
activation.Controller.LocalEntityId,
activation.Movement.HitGround,
activation.Motion.LeaveGround);
}
catch
{
_activationDispatchFailureCount++;
}
}
private bool IsActivationPrephaseEnvelopeCurrent(
Activation activation,
in RuntimeDormantSetPositionCommitReceipt receipt) =>