docs(overhaul): seal final visual controls and retain shutdown failure

This commit is contained in:
Erik 2026-09-05 21:40:59 +02:00
parent 89a9a7f2ac
commit 64d7a3981a
5 changed files with 258 additions and 7 deletions

View file

@ -2747,6 +2747,18 @@ kinds. Same class as the VM6 fix; do not guess the values.
## #422 — Intermittent heap-corruption exit (0xC0000374) at process exit after an offline capture (pack on OR off)
**2026-09-05 final OVERHAUL control recurrence:** unchanged eea83ac88 Release,
connected wall route, PID35004. All seven checkpoints/PNGs and graceful
network logout completed, but actual OS exit was -1073740940 despite client
status exited/code0/graceful. The complete run is FAIL, not rescued by its
successful collision observations. No new Application1000/1001/1026 or
System4101 event, WER/CrashDumps artifact or managed crash JSON was found in
the scoped post-run checks. This matches the symptom recorded here, not a
proven same root cause and not evidence of AMD#477. No registry/driver change
or speculative native-lifetime fix. Evidence and exact screenshot locations:
`docs/research/2026-09-01-overhaul/s5-final-visual-controls.md`; run
`logs/selfgate-20260905-212132-s5-final-wall-eea83ac88/`.
**Status:** OPEN — filed 2026-08-22 at Campaign VM VM3; **characterised at VM7 (2026-08-23) — rare, pack-INDEPENDENT, exit-time, not yet caught with a stack.** Facts: (1) it fired once more, on the **retail (pack-off)** row of `tools/run-atmospheric-performance-matrix.ps1` at 1920×1080 / 45 s warm-up / uncapped on `621a0edf` — the first launch after a fresh build — so "retail/off never reproduced it" is withdrawn and the title's "pack-on" is wrong: the exit is in the common teardown. (2) It did not fire in 16 runs with cdb attached (High, 720p, 12 s), 24 runs launched under cdb's debug heap (High, 720p, 12 s), 6 runs under the debug heap with the exact matrix recipe, or 10 plain runs with the exact recipe and a forced non-incremental rebuild before run 1 (`tools/i422/loop-debugheap.ps1`, `tools/i422/loop-plain.ps1`) — 1 in ~57 offline runs today, ~2 %. (3) The fail-fast leaves NO Application event-log entry and NO WER report on this machine (WerSvc is in its normal on-demand state, nothing disabled), so there is no dump to read; a per-user `HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\AcDream.App.exe` key (`DumpType=2`, `DumpFolder`) is the one-time user action that turns the next occurrence into a full dump — the project does not set registry keys itself. (4) The pre-campaign binary (`6c79d35c` + VM0 patches) CANNOT be tested with this tool: it predates the gate's in-process close verb, so every run ends in the gate's forced kill and never reaches the graceful-exit path where the fault lives (10/10 "automation close timed out") — whether the fault predates Campaign AR is therefore unknown, not disproven. Evidence: `docs/research/evidence/vm7/i422-*.txt`, `artifacts/vm7-matrix/uncapped-retail-1920x1080/` (the crashing run's log — managed shutdown complete, `MossTank disabled` last). **Owner decision 2026-08-23: accepted as carried; Campaign VM merged with it open.** Next step when it recurs: the LocalDumps key above, then `tools/i422/loop-plain.ps1` / `loop-debugheap.ps1`. **Recurred 2026-08-24:** the #432 attribution run (`probe-432-094728`, connected live session, graceful WM_CLOSE, managed shutdown complete) exited `-1073740940` — third sighting, first on a CONNECTED (non-offline-capture) run; still no dump (the LocalDumps key remains unset). One earlier #429-round sighting was also at graceful close (~1 in 10 diagnostic runs that day).
**Component:** rendering / render packs (Campaign AR) — native teardown

View file

@ -706,7 +706,15 @@ ACE disconnects. High preset retained; images provisional, not owner G4.
Existing R6 workload-change/cache-growth warnings and distinct Windows
RADAR_PRE_LEAK_64 observation are retained, not declared a leak or AMD cause.
See `docs/research/2026-09-01-overhaul/s5-final-lifecycle-stability-verification.md`.
Remaining matrix/adjacent-portal controls and owner G4 are still owed.
The adjacent-portal, wall, two-dungeon, fixed-view and moving-stair controls
are now terminal (51 inspected PNGs); see
`docs/research/2026-09-01-overhaul/s5-final-visual-controls.md`.
Nine portal hops reveal without the old deadlock; dungeon lighting and
wall block/escape pass their narrow functional checks. Four runs exited0;
the wall run instead exited0xC0000374 after graceful status/ACK. This is a
retained FAIL matching carried#422's symptom, not proven same root cause or
AMD#477. No speculative fix or Windows diagnostic-setting change.
Broader owner matrix and G4 are still owed; these observations do not close it.
Known retail leak unchanged, FPS/C2 deferred, no main merge.
### Rollback ledger

View file

@ -5295,3 +5295,25 @@ PNG names and remaining matrix: s5-final-lifecycle-stability-verification.md.
Next: exact adjacent-portal, cathedral/wall and ordinary-dungeon controls,
then the uncovered owner matrix. FPS/C2 deferred; known retail leak unchanged;
G4 unpassed, no main merge.
## 70. Final visual controls and native-exit recurrence — 2026-09-05
Unchanged eea83ac88 Release, existing one-client routes, no product edits.
Portal20 checkpoints/seven PNGs: all nine exact hops reveal in5.605.68s
command-to-visible, final ownership settles, actual exit0. Wall7/7:
functional block/escape and adjacent segment PASS, but complete run **FAIL**
on actual native exit-1073740940/0xC0000374 after the client wrote graceful
code0. UDP disconnect/status are not process success. This matches known
carried#422's symptom, not a proved common cause or AMD#477. No new Windows
event/dump/local crash JSON; source-only inspection proved no native fix.
No native diagnostic loop, registry/driver/ACL change or speculative patch.
The two preselected dungeon High/off controls5/5, G3 fixed views13 PNGs and
moving stairs19 PNGs all exit0; lead opened all51 images across five runs.
No broad G4 claim: G3/stairs have no ownership checkpoints, later stair frames
stop at a doorway, and Nanto is one heading. Exact result boundaries, process
identities, PNG paths, known warnings and the corrected offline wall-exit
argument are in `s5-final-visual-controls.md`. Earlier sealed lifecycle/R6
evidence stays unchanged; successful runs do not erase the native failure.
Next is owner G4's still-uncovered matrix and acceptance. FPS/C2 deferred;
retail cathedral leak unchanged; no main merge.

View file

@ -125,12 +125,14 @@ reproduced; #477's initiating cause remains unknown.
## Still owed
Current-binary cathedral/wall/dungeon/adjacent-portal visual controls,
the final owner matrix and acceptance. Existing narrow routes are
route-g3.txt, route-482-cathedral-wall.txt, route-478-dungeon-controls.txt and
route-474-portal-reveal.txt under tools/overhaul-selfgate; route-464-run.txt
adds actual moving cathedral-stair images. These are not broader gates by
themselves. Exterior-ramp standing has no pinned pose; two-client wall
The current-binary cathedral/wall/dungeon/adjacent-portal controls and moving
stairs are now terminal; see `s5-final-visual-controls.md` for all51 inspected
PNGs. Four runs exit0. Wall collision block/escape passes functionally, but
that run's actual native exit0xC0000374 is FAIL despite its graceful status:
a symptom-level recurrence of carried#422, not proven AMD#477 causation.
The earlier three successful runs above remain valid; they do not erase it.
Final owner matrix and acceptance remain. These narrow controls are not
broader gates by themselves. Exterior-ramp standing has no pinned pose; two-client wall
occlusion, complete Facility stair circuit, Nanto continuous rotation,
ordinary-dungeon traversal/camera seams, real Tusker combat/casting and
ten minutes' free movement remain owner checks. Wall acceptance is

View file

@ -0,0 +1,207 @@
# S5 final visual controls — 2026-09-05
Production binary remains clean-built eea83ac884d0b0fd74d86a17a16d7d5d93f64d94;
launch HEAD89a9a7f2a changes documentation only. The stair run's dirty=true
is solely this then-untracked report, captured in stairs.process.json;
there were no product/test changes. App/Core hashes were rechecked
against `c1a-integrated-verification.md`. No rebuild, product change, FPS work,
native cleanup workaround, or main merge. Each launch uses the existing
one-client self-gate runner, the validated recipe10 package, unique status
file and precheck of clients/debuggers plus ACE UDP9000/PID13340. The runner
requests graceful close only. The OS exit result, not the runner command's
own success or the client's status event, determines process success.
Operational evidence is under `logs/s5-final-live-eea83ac88/` and the run
directories below. The earlier79-entry lifecycle/R6 manifest is unchanged.
`validate-controls.ps1` reads the canonical lifecycle predicate definitions
without executing their launch/kill wrappers; screenshot metadata uses the
unchanged render-pack verifier. It also checks route checkpoint order/PID,
actual materialization cell order, screenshot signatures, fatal log markers,
unique script completion/logout ACK, terminal status and ACE disconnect.
Portal's immediate before/after checkpoints are not falsely treated as
settled ownership: the full stable predicate runs on its final10s checkpoint.
G3/moving-stair routes have no checkpoints and cannot prove those counters.
All screenshot judgments are lead-provisional until owner inspection.
## Portal reveal #474 — PASS, narrowly scoped
Unmodified `tools/overhaul-selfgate/route-474-portal-reveal.txt`.
Run `logs/selfgate-20260905-211702-s5-final-474-eea83ac88/`:
PID29400,20 ordered checkpoints/seven PNGs, actual OS exit0. Client terminal
status19:18:30.901844UTC, ACK once, ACE disconnect21:18:32.510+02 for63392.
Precheck19:17:02.5138416UTC, ACE offset14661239. PID is recorded in all
checkpoints; UDP63392 is inferred from the sole new testaccount ACE session
in this run interval, not a retained live OS endpoint query. That limitation
does not invalidate the nine observed materializations, but must not be
upgraded into exact live process/endpoint capture.
All nine intended hops materialized in order:0904 →3032 →3031 →3032 →3031
→3032 →3031 →8A02 →A9B4. Command-to-visible checkpoint deltas are
5674.121,5612.467,5602.210,5603.718,5600.776,5602.383,5599.955,5616.037,
5622.903ms. These include command/frame overhead, not isolated asset latency.
Reveal summaries are55525603ms for the nine portals. Final generation10
is completed, visible and idle, materialization count9, readiness all true,
invariant failures0; ten streaming backlog fields and staged work converge.
Lead opened every PNG under that run's `artifacts/screenshots/`:
`474-00-login.png`, `474-02-source-3032.png`, `474-03-destination-3031.png`,
`474-05-destination-revisit.png`, `474-07-destination-third.png`,
`474-08-facility-control.png`, `474-09-holtburg-control.png`.
All show revealed world geometry, including the repeated adjacent target;
Facility walls and Holtburg houses are present. The early PNGs still show
the portal caption/effect tail; this is not a caption-free/animation-complete
claim at every capture. Final completed state is checkpoint evidence, not a
final settled screenshot. High/MSAA4/near4/far25 at1024x768; no stuck reveal
reproduced. This is not a full portal-user-experience acceptance.
## Cathedral exterior wall #482 — functional PASS; process FAIL
Unmodified `tools/overhaul-selfgate/route-482-cathedral-wall.txt`.
Run `logs/selfgate-20260905-212132-s5-final-wall-eea83ac88/`:
precheck19:21:32.6214278UTC, ACE offset14678282; PID35004 started
19:21:32.7654956UTC, live-observed UDP63540. Seven ordered checkpoints and
seven PNGs pass readiness/ownership/metadata checks;50 world-edge landblock
misses retain the canonical warning classification. High/MSAA4/1280x720.
The screenshot chat's actual /loc values at F4180012 (z160.004990) are:
| Action | Observed x | Observed y | Functional result |
|---|---:|---:|---|
| Owner overlap [48.002960,39.257545] |48.891850|39.257545|Placed outside wall|
| Strafe right from placement |51.650188|39.257545|Can leave wall|
| Forward into west-facing wall from x49 |48.497448|39.257545|Blocked before penetrating|
| Back away |52.816803|39.257545|Can escape, no sticking|
| Forward at adjacent wall point |48.497448|41.000000|Adjacent segment also blocks|
Lead opened all seven `artifacts/screenshots/` PNGs:
`482-01-overlap.png`, `482-01b-overlap-escape.png`, `482-02-approach.png`,
`482-03-escape.png`, `482-04-adjacent-wall.png`,
`482-05-cathedral-interior.png`, `482-06-holtburg-doorway.png`.
The wall stands between character and interior in the approach frames;
the valid cathedral terrace and Holtburg doorway controls render. The Options
panel overlays the right side; no whole-frame occlusion proof is claimed.
The route's old comment suggesting exact x48.48 is not the acceptance rule:
the owner explicitly accepted functional block/escape over exact settlement.
**The complete run is FAIL:** although all route actions finished and the
client emitted exited/code0/reason graceful at19:22:52.4434342UTC, the runner
observed actual process exit **-1073740940 (0xC0000374)**. ACE still received
the graceful packet disconnect at21:22:54.036+02. Neither the status event
nor network cleanup converts a native crash to success. An initial offline
validation was invoked with exit0 before incorporating the newly returned
runner output; it was immediately corrected with the actual nonzero code.
The retained `wall.validation.json` is FAIL; no accepted proof uses the
erroneous argument. No rerun is used to erase this observation.
Microsoft names this status
[STATUS_HEAP_CORRUPTION](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-erref/596a1078-e883-4972-9bbc-49e60bebca55).
It matches the **symptom** of carried issue#422, already owner-accepted as
open at Campaign VM and previously seen connected as well as offline.
It is not proof of the same root cause or of AMD#477. At19:24:19UTC the
scoped Application1000/1001/1026 and System4101 queries returned no new
matching event; targeted WER/CrashDumps/local crash-report searches found
no new artifact. Existing#422 records the same missing-event behavior.
A bounded source-only shutdown trace found no proven double free.
`GameWindow.CompleteShutdown` emits status after lifetime/native-window
release returns; native release is one-shot. `VulkanGpuDevice.Dispose`
guards re-entry and OpenAL clears released native handles. These facts do
not prove the native heap stayed valid after the calls returned. The needed
attribution evidence remains a native fault stack/module. No new diagnostic
loop, registry/LocalDumps setting, driver/TDR/ACL change or speculative fix.
The managed crash writer is not expected to catch a native process fail-fast
after its guarded frame loop; its existing coverage is unchanged.
## Ordinary dungeon lighting #478 — PASS for captured controls
Unmodified `tools/overhaul-selfgate/route-478-dungeon-controls.txt`.
Run `logs/selfgate-20260905-212614-s5-final-dungeons-eea83ac88/`:
precheck19:26:14.8608717UTC, ACE offset14690636; PID7652 started
19:26:15.0017221UTC, live-observed UDP55709. Five ordered stable checkpoints,
five metadata-verified PNGs, all three materializations in order, no automatic
failures/warnings. Actual OS exit0; status19:27:13.7962886UTC graceful,
one ACK and ACE21:27:15.404+02 disconnect.1600x900, High/off per route.
Lead opened all five `artifacts/screenshots/` PNGs:
`478-control-0125-high.png`, `478-control-0125-retail.png`,
`478-control-8c04-high.png`, `478-control-8c04-retail.png`,
`478-control-holtburg-return.png`.
Both dungeon rooms have visible walls, floors, objects and characters under
both profiles; no near-black-room defect in these captures. High is restored
for the intact Holtburg return. These are lighting/arrival/return controls,
not dungeon traversal, stair collision, camera-seam or combat coverage.
## Fixed cathedral/Facility/Holtburg/Nanto views — limited PASS
Unmodified `tools/overhaul-selfgate/route-g3.txt`; run
`logs/selfgate-20260905-212822-s5-final-g3-eea83ac88/`.
Precheck19:28:22.9202246UTC, ACE offset14701303; PID16564 started
19:28:23.0577467UTC, live-observed UDP62452. All12 teleports materialized
in the requested cell order.13 PNGs, actual exit0, terminal graceful
19:31:10.3284035UTC, one ACK, ACE21:31:11.948+02 disconnect. The canonical
log check retains100 expected world-edge landblock misses as warnings.
High/MSAA4/1600x900. No stable checkpoint/ownership counts exist in this route.
Lead opened every `artifacts/screenshots/` PNG:
`00-login.png`, `01-cathedral-stairs.png`, `02-facility-stairs.png`,
`03-holtburg-house.png`, `04-holtburg-terrain-leak.png`,
`05-cathedral-south-0106.png`, `06-cathedral-south-0104.png`,
`07-cathedral-stairs-0107.png`, `08-cathedral-stairs-0112.png`,
`09-cathedral-terrace-edge.png`, `10-facility-015E.png`,
`11-facility-015F.png`, `12-nanto-falls.png`.
Cathedral walls/arches/terrace and stair chamber remain drawn across the
pairs; Facility stair/landing geometry and Holtburg interior remain present.
The Nanto frame includes the waterfall at its left edge and an intact house;
it does not prove the required continuous-rotation waterfall behavior.
No full remote-actor/wielded-item depth or retail pixel-equivalence claim.
## Moving cathedral stairs — limited PASS
Unmodified `tools/overhaul-selfgate/route-464-run.txt`; run
`logs/selfgate-20260905-213154-s5-final-stairs-eea83ac88/`.
Precheck19:31:54.0826213UTC, ACE offset14713110; PID14848 started
19:31:54.2224090UTC, live-observed UDP61728. Both exact F4180113
materializations and both forward press/release pairs occurred.19 PNGs,
actual exit0, terminal graceful19:32:44.7955857UTC, one ACK and
ACE21:32:46.448+02 disconnect.50 expected edge misses remain warnings.
High/MSAA4/1600x900; no checkpoint-based ownership proof in this route.
Lead opened all19 `artifacts/screenshots/` PNGs: `464-run-00-still.png`,
`464-run-01.png` through `464-run-10.png`, `464-run-11-stopped.png`,
`464-run-21.png` through `464-run-26.png`, `464-run-27-stopped.png`.
The early frames show actual descent/camera motion and intact chamber walls,
floor and arches. Later frames settle against the right side of the doorway
while the run animation continues; they are not continued travel through the
whole cathedral. Frame21 has a foreground stair/slab occluding the lower
view. No new moving wall-textured triangles or missing chamber wall was seen
in this sequence, but it is not proof of retail-exact slab extent, all zoom
angles or a full stair circuit. Portal-caption tails also remain visible in
early images. Known retail slab leakage is not declared fixed.
## Remaining acceptance
All five control routes are terminal; all51 PNGs were inspected. Four process
runs exited0; the wall run's native exit remains FAIL. Final owner G4 remains
unpassed. Two-client wall occlusion,
the full Facility circuit, continuous Nanto rotation, ordinary-dungeon
traversal/camera seams, real Tusker combat/casting and ten minutes of free
movement are not replaced by the stills. The exterior-ramp stand has no
pinned pose; the indoor020009A2 membership witness is not a substitute.
Known retail slab leakage is unchanged; FPS/C2 remains owner-deferred.
## Sealed artifact inventory
`logs/s5-final-live-eea83ac88/controls-SHA256SUMS.txt` contains187 entries,
including all51 PNGs, their metadata, five route/run records, terminal exit
observations and the offline validators. Every entry was independently
rehashed after generation; manifest SHA-256:
`238AE47379FE0C82D953801FD838575831C87E1C0E518F937CE6034D15BC1133`.
The earlier lifecycle/R6 manifest and all79 entries were also rechecked
unchanged (manifest SHA-256
`EC2B59F822B1D9A081479A07F00693888BA4B09C8313DB3F47DA15332C4F07BA`).
`seal-controls.ps1` refuses to overwrite an existing controls manifest.
The retained final state query at19:36:17.4279719UTC found no client/debugger
process, ACE still listening on UDP9000/PID13340, and no matching new
Application1000/1001/1026 or System4101 event since the controls began.
An empty Windows query does not negate the recorded wall-process failure.