feat(runtime): bridge executor completion to the placement stream

Cutover slice C0 (docs/plans/2026-08-02-placement-cutover.md): the seam
work that lets C3 flip hosts onto a complete receipt stream instead of
growing one mid-cutover. The executor's Released exit now publishes an
acknowledge-only ExecutorCompleted receipt through the one placement
projection stream — registered before observer dispatch, correlated to
the full execution receipt, reaped exactly once on acknowledgement/
discard/session-clear, and counted in the convergence ledger. All three
production placement sinks acknowledge-and-ignore the new kind via early
returns proven behavior-preserving for every existing kind; without them
the first such receipt at cutover would permanently wedge the exact-head
FIFO behind sinks that return false. Provably inert today: the publisher
has no production caller.

Execute's live inputs now derive from Runtime's own owners bound at
GameRuntime construction: UsePositionFromServer is retail's exact
autonomy_level != 2 (CommandInterpreter::UsePositionFromServer
0x006B3B40, startup-only knob), and PlayerDistance uses the live movement
controller's position with a null-safe fallback to the caller struct —
never a fabricated origin. TryPrepareAndSubmitAuthoredPlacement chains
the prepared-collision Setup read through PrepareMover to submission with
zero validation-semantics changes. TryCommitParent and CommitWithdrawal
gain the sibling cancellation flow (residence + ordinary placement
family); TryCommitParent deliberately omits LeaveWorld — retail's
set_parent performs its single gated leave_world (0x00515A90) and a
second would have no counterpart.

Not fully dormant: the two cancellation fixes change Runtime paths
production already calls (today as no-op-adjacent hardening, since
nothing upstream begins a residence yet); everything else is reachable
only by tests. Reviewed: retail-conformance PASS + architecture/
adversarial PASS after one fix round (sink wedge, completion-receipt
lifecycle, null-controller distance). Runtime 921/921; complete Release
solution 10,716 passed / 4 intentional skips.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-02 05:22:37 +02:00
parent 27e05b99e4
commit 67f63e85e5
14 changed files with 1639 additions and 11 deletions

View file

@ -155,6 +155,44 @@ public sealed class RuntimePlacementPresentationSinkTests
Assert.Equal(priorVisible, record.IsSpatiallyVisible);
}
[Fact]
public void ExecutorCompleted_IsAckOnlyNoOpEvenWhenTokenIsStaleOrSidecarIsGone()
{
// F1: mirrors Discard_IsAckOnlyNoOpEvenWhenTokenIsStaleOrSidecarIsGone
// exactly - proves ExecutorCompleted is acknowledged unconditionally
// (never wedges the FIFO on a record-lookup failure) and never
// mutates presentation state, even under a completely bogus token.
Fixture fixture = Fixture.Create();
LiveEntityRecord record = fixture.Materialize(Spawn(Guid, 1, SourceCell));
WorldEntity entity = record.WorldEntity!;
RuntimePlacementProjectionSnapshot completion = Placement(
fixture,
record,
RuntimePlacementProjectionKind.ExecutorCompleted,
new Vector3(900f),
Quaternion.CreateFromAxisAngle(Vector3.UnitX, 1f)) with
{
Token = Placement(fixture, record,
RuntimePlacementProjectionKind.Place,
Vector3.Zero,
Quaternion.Identity).Token with
{
SessionLifetimeVersion = ulong.MaxValue,
PositionAuthorityVersion = ulong.MaxValue,
ExactCellId = 0xDEAD0001u,
},
};
Vector3 priorPosition = entity.Position;
Quaternion priorRotation = entity.Rotation;
bool priorVisible = record.IsSpatiallyVisible;
Assert.True(fixture.Sink.TryApply(in completion));
Assert.Equal(priorPosition, entity.Position);
Assert.Equal(priorRotation, entity.Rotation);
Assert.Equal(priorVisible, record.IsSpatiallyVisible);
}
[Fact]
public void Place_RejectsStaleCanonicalVersionsWithoutChangingSidecar()
{