feat(physics): C4 route 4b-3 — remote teleport + cell-less through the canonical placement

Flips the last remote classification (SetPosition: teleport-advanced and
cell-less) onto 4b-1's RuntimeRemotePlacementDriveController, runs retail's
teleport_hook before the placement, and deletes the legacy remote-teleport
machinery. Contract: docs/research/2026-08-04-c4-route-4b-3-contract.md.

Retail: MoveOrTeleport @0x00516330's branch @0x00516386 -> teleport_hook
@0x005163EF -> SetFlags(0x1012) @0x00516414 -> SetPosition @0x00516420 ->
return 1 @0x00516438. The hook @0x00514ED0 runs BEFORE the placement and
regardless of its outcome. Retail places this branch unconditionally, at any
distance and any contact state (arg4 is read only @0x0051638E, after the
branch) — which is what retires AP-137's cell-less enqueue-vs-place delta.

D1 — the classifier's cell-less input is now the PRE-merge committed cell.
Retail's predicate is `this_1->cell == 0`, the BODY's own cell at
MoveOrTeleport entry (this_1 is assigned from this @0x00516334). acdream fed
the POST-merge canonical.FullCellId, which RefreshSnapshot ->
RefreshDerivedState -> SetFullCell has already stamped with the accepted wire
cell; a zero wire cell fails validation into RejectedData first. The shipped
remote cell-less predicate was therefore dead code, not merely different from
remotePlacementRequired. Threaded via a builder overload; route 1's overload
is untouched. The graphical !IsSpatiallyVisible arm of
projectionRequiresTeleportHook is deleted — a presentation predicate with no
retail analogue that fired the teleport machinery on a routine hot path.

Deleted: RemoteTeleportController (605), RemoteTeleportPlacement (85),
RemoteShadowPlacementSynchronizer (49), their 1,709 lines of tests, the
remotePlacementRequired predicate, the TeleportHookRequired plumbing, the
legacy pre-operation ConstrainTo fallback, and the player arm's legacy
!IsGrounded fallback. Net -2,030 lines.

Structural fix (two independent Opus reviews, round 1 FAIL/FAIL): three of the
four MAJORs were one defect — OnPosition carried two parallel inline copies of
the routing tail (player-guid, NPC-guid) that had drifted. Extracted
RunRemoteArmTail (3 call sites) and ApplyWireAirborneLeftoverBookkeeping (2),
both branches now share one implementation.

  A1  ToConstraintArm mapped AirborneSnap -> AirborneNoOperation, so the NPC
      arm armed ConstrainTo ZERO times for an out-of-contact wire-grounded
      creature — a regression this slice introduced while closing a
      structurally identical hole. Now maps to NearInterpolate; switch made
      total with a throwing default proven unreachable.
  R1  D2's write-nothing shape existed on the player arm only; NPC packets
      fell through and wrote the body. Retail makes no player/NPC distinction.
  R2  report_collision_end(this,1) @0x00514F31 was bound to
      ShadowObjects.Suspend, a port of a DIFFERENT retail function
      (remove_shadows_from_cells) that teleport_hook never calls. Now routes
      to RuntimeCollisionReportingState.LeaveWorld, which wraps the private
      ForceEnd in an admission-blocking transaction so a DoCollisionEnd
      callback cannot recreate the contact table.
  R3/A2 A teleported NPC synthesized ServerVelocity from the teleport distance
      (~1,000+ m/s) and planned a run cycle from it. Both the install and
      RemoteServerControlledVelocityCycle.Apply now gate on !isTeleportRoute.

BISECT HAZARD — A1's fix is correct only BECAUSE R1 landed. AirborneSnap is
reachable wire-airborne on the NPC arm only while D2's shape is missing there.
Reverting R1 alone silently inverts A1 into the opposite divergence: arming
where retail returns 0. Revert both or neither.

Also in the velocity hunk: the NPC block's two !IsPlayerGuid(update.Guid)
guards were dropped when it was wrapped in `if (!isTeleportRoute)`. Safe — all
five exit paths of the enclosing IsPlayerGuid block return, so the predicate is
unconditionally false below it — but it was unremarked by both reviews.

Register: AP-137 REWRITTEN (not deleted) to the surviving acdream-only
divergences — null classification during the login window and Rejected*
through UnroutedCatchUp keep a row. AD-42's RemoteTeleportController citation
retired; AP-136/AP-138 writer lists corrected to the two surviving non-Position
rebucket writers; AP-138 gains the teleport arm as a second producer of the
visible-without-collision residual (retirement path remains #309). AP-135 is
untouched and its two airborne bookkeeping writes are preserved on both arms.
AP-131 does not retire; #276 does not close.

Proof obligation 1: ParkCollisionResidents' overlap throw stays unreachable —
the teleport arm adds packets to the same TryBeginExclusiveAuthoredPlacement
one-operation-per-key machinery the far arm uses, opens no new operation shape,
and every DeferredCell outcome cancels synchronously with
restoreCancelledPark: true. The guarded property remains
HasOldPrefixPlacementDebt's stall, not a throw (4b-1's B2 caveat stands).

Correction to an earlier claim: LiveEntityPresentationController's
_activePlacementOwners was NOT write-never at HEAD —
remotePlacementRequired -> BeginPlacement -> Begin -> BeginAuthoritativePlacement
was a live writer chain. It becomes write-never BECAUSE this slice deletes that
chain, which is why deleting the dead half is behaviour-preserving.

Probe: ACDREAM_PROBE_REMOTE_TELEPORT=1 emits one [remote-teleport] line per
routed arm (guid, cause, hook-ran, placement status). TEMPORARY, strip with the
probe family.

Carried, disclosed not fixed: no dedicated bidirectional collision-partner test
for R2 (the wiring, not LeaveWorld itself, is what lacks coverage); the
stress test's teleport step drives hand-written field assignments rather than
the canonical arm; the per-packet runTeleportHook closure allocation (network
path, not the resolve path Slice I's 0 B discipline governs — file before
route 5 adds a fourth call site). B2: IRuntimeCollisionReportObserver has zero
production implementations, so retail's bidirectional DoCollisionEnd half still
reaches no gameplay consumer — this fix closes the wrong-function binding, not
that nobody listens.

Complete Release suite MEASURED at 11,013 passed / 4 skipped / 0 failed
(baseline 11,027/4/0; net -14 = ~33 deleted test cases against ~19 added).
Neither known flake fired (#302 PortalProjectionTests GC-allocation, #308
NakEmissionTests wall-clock).

STILL OWED: the two-client connected gate, which MUST use an NPC/creature
teleport target. Both round-1 MAJORs lived on the NPC arm and the velocity
cycle early-returns for 0x50xxxxxx guids, so a player target structurally
cannot observe A1, A2, or R3.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-04 16:00:10 +02:00
parent 3e002993dd
commit 6dc7ba51ee
53 changed files with 2980 additions and 3372 deletions

View file

@ -31,7 +31,6 @@ public sealed class LiveEntityPresentationController : IDisposable
private readonly LiveEntityPartArrayEnterWorldPort _partArrayEnterWorld;
private readonly HashSet<RuntimeEntityKey> _readyOwners = [];
private readonly HashSet<RuntimeEntityKey> _suspendedShadowOwners = [];
private readonly HashSet<RuntimeEntityKey> _activePlacementOwners = [];
private readonly HashSet<LiveEntityRecord> _drainingRecords = new();
private bool _disposed;
@ -102,73 +101,12 @@ public sealed class LiveEntityPresentationController : IDisposable
return ApplyPendingTransitions(record);
}
/// <summary>
/// Retains ownership of a collision shadow that another retail transition
/// suspended while this incarnation's spatial projection is unavailable.
/// Hidden/UnHide and teleport rollback intentionally converge on this one
/// generation-scoped restoration marker.
/// </summary>
public bool DeferShadowRestore(uint serverGuid, ushort generation)
=> CompleteAuthoritativePlacement(serverGuid, generation, deferShadowRestore: true);
/// <summary>
/// Completes active placement ownership after its final frame/cell is
/// known, either returning a stable deferred restore to presentation or
/// clearing the suspension for an immediate controller-owned restore.
/// </summary>
public bool CompleteAuthoritativePlacement(
uint serverGuid,
ushort generation,
bool deferShadowRestore)
{
if (!_liveEntities.TryGetRecord(serverGuid, out LiveEntityRecord record)
|| record.Generation != generation
|| record.WorldEntity is null)
{
return false;
}
RuntimeEntityKey key = RequireProjectionKey(record);
_activePlacementOwners.Remove(key);
if (deferShadowRestore)
_suspendedShadowOwners.Add(key);
else
_suspendedShadowOwners.Remove(key);
return true;
}
/// <summary>
/// Transfers a deferred restore to a newer authoritative placement before
/// that placement rebuckets and can become visible. The placement hands
/// ownership back after it reaches a stable Hidden destination/rollback;
/// this prevents an intervening UnHide from restoring an unresolved pose.
/// </summary>
public bool BeginAuthoritativePlacement(uint serverGuid, ushort generation)
{
if (!_liveEntities.TryGetRecord(serverGuid, out LiveEntityRecord record)
|| record.Generation != generation)
{
return false;
}
RuntimeEntityKey key = RequireProjectionKey(record);
_activePlacementOwners.Add(key);
_suspendedShadowOwners.Remove(key);
return true;
}
internal bool HasDeferredShadowRestore(uint serverGuid) =>
TryGetCurrentProjectionKey(serverGuid, out RuntimeEntityKey key)
&& _suspendedShadowOwners.Contains(key);
internal bool HasActivePlacement(uint serverGuid) =>
TryGetCurrentProjectionKey(serverGuid, out RuntimeEntityKey key)
&& _activePlacementOwners.Contains(key);
internal int ReadyOwnerCount => _readyOwners.Count;
internal int DeferredShadowRestoreCount => _suspendedShadowOwners.Count;
internal int ActivePlacementCount => _activePlacementOwners.Count;
public void Forget(LiveEntityRecord record)
{
@ -177,7 +115,6 @@ public sealed class LiveEntityPresentationController : IDisposable
{
_readyOwners.Remove(key);
_suspendedShadowOwners.Remove(key);
_activePlacementOwners.Remove(key);
}
_drainingRecords.Remove(record);
}
@ -186,7 +123,6 @@ public sealed class LiveEntityPresentationController : IDisposable
{
_readyOwners.Clear();
_suspendedShadowOwners.Clear();
_activePlacementOwners.Clear();
_drainingRecords.Clear();
}
@ -233,8 +169,7 @@ public sealed class LiveEntityPresentationController : IDisposable
if (!IsCurrent(record, entity))
return false;
_shadows.Suspend(entity.Id);
if (!IsPlacementActive(record))
_suspendedShadowOwners.Add(RequireProjectionKey(record));
_suspendedShadowOwners.Add(RequireProjectionKey(record));
// Retail CPhysicsObj::set_hidden @ 0x00514C60 calls
// CPartArray::HandleEnterWorld after hiding the object
// from its cell. Despite the name, this is the motion
@ -261,8 +196,7 @@ public sealed class LiveEntityPresentationController : IDisposable
_partArrayEnterWorld.HandleEnterWorld(entity.Id);
if (!IsCurrent(record, entity))
return false;
bool restored = !IsPlacementActive(record)
&& RestoreShadow(record, entity);
bool restored = RestoreShadow(record, entity);
if (!IsCurrent(record, entity))
return false;
if (restored)
@ -313,8 +247,12 @@ public sealed class LiveEntityPresentationController : IDisposable
// projection edge that suspends its object clock. Keep the retained
// registration so a stationary object can be restored immediately on
// hydration; it may have no later movement quantum to repair itself.
// Projectiles and active authoritative placements own their matching
// suspend/restore transaction in their dedicated controllers.
// Projectiles own their matching suspend/restore transaction in their
// dedicated controller. C4 route 4b-3 deleted the standalone remote-
// teleport placement controller (and its `_activePlacementOwners`
// suspension gate here) — the canonical Runtime placement owner now
// handles that path, and this class no longer defers to a second
// authority.
if (!visible)
{
SuspendOrdinaryShadowOutsideProjection(record, entity);
@ -322,7 +260,6 @@ public sealed class LiveEntityPresentationController : IDisposable
}
if ((record.FinalPhysicsState & PhysicsStateFlags.Hidden) != 0
|| IsPlacementActive(record)
|| !TryGetProjectionKey(record, out RuntimeEntityKey key)
|| !_readyOwners.Contains(key)
|| !_suspendedShadowOwners.Contains(key))
@ -343,7 +280,6 @@ public sealed class LiveEntityPresentationController : IDisposable
{
if (record.IsSpatiallyVisible
|| record.ProjectileRuntime is not null
|| IsPlacementActive(record)
|| !TryGetProjectionKey(record, out RuntimeEntityKey key)
|| !_readyOwners.Contains(key)
|| !_shadows.Suspend(entity.Id))
@ -362,10 +298,6 @@ public sealed class LiveEntityPresentationController : IDisposable
&& ReferenceEquals(current, record)
&& ReferenceEquals(current.WorldEntity, entity);
private bool IsPlacementActive(LiveEntityRecord record) =>
TryGetProjectionKey(record, out RuntimeEntityKey key)
&& _activePlacementOwners.Contains(key);
private bool TryGetCurrentProjectionKey(
uint serverGuid,
out RuntimeEntityKey key)

View file

@ -2143,6 +2143,22 @@ public sealed class LiveEntityRuntime : ILiveEntityRadarSource
return false;
}
/// <summary>
/// R2 fix round (2026-08-04): the App-layer entry point for retail
/// <c>CPhysicsObj::report_collision_end(this, 1)</c> —
/// <c>teleport_hook</c>'s sixth action (@0x00514F31 → @0x00514620,
/// force-end-all with bidirectional <c>DoCollisionEnd</c> on both this
/// object and every collision-table partner). Forwards to
/// <see cref="RuntimeCollisionReportingState.LeaveWorld"/>, the exact
/// retail leave-world/teleport/Hidden force-end entry point — NOT
/// <c>ShadowObjectRegistry.Suspend</c>, which ports a DIFFERENT retail
/// function (<c>remove_shadows_from_cells</c>) that <c>teleport_hook</c>
/// never calls; that mapping predated this fix and was carried without
/// re-derivation.
/// </summary>
internal void ForceEndCollisionReporting(RuntimeEntityRecord canonical) =>
_physics.CollisionReports.LeaveWorld(canonical);
public bool TryGetRemoteMotionRuntime(
uint serverGuid,
out IRuntimeRemoteMotion runtime)
@ -2406,29 +2422,16 @@ public sealed class LiveEntityRuntime : ILiveEntityRadarSource
System.Numerics.Vector3? currentLocalVelocity,
out PositionTimestampDisposition disposition,
out WorldSession.EntitySpawn accepted,
out AcceptedPhysicsTimestamps timestamps)
{
bool projectionRequiresTeleportHook =
_directory.TryGetActive(
update.Guid,
out RuntimeEntityRecord canonical)
&& (canonical.FullCellId == 0u
|| !_projections.TryGet(
canonical,
out LiveEntityRecord? projection)
|| !projection.IsSpatiallyProjected
|| !projection.IsSpatiallyVisible);
return _entityObjects.TryApplyPosition(
out AcceptedPhysicsTimestamps timestamps) =>
_entityObjects.TryApplyPosition(
update,
isLocalPlayer,
forcePositionRotation,
currentLocalVelocity,
projectionRequiresTeleportHook,
acknowledgeProjection: null,
out disposition,
out accepted,
out timestamps);
}
/// <summary>
/// C4 route 4a: borrows the canonical Runtime classification for one

View file

@ -28,7 +28,6 @@ internal sealed class LiveEntityRuntimeTeardownController
private readonly LiveEntityRuntime? _runtime;
private readonly LiveEntityPresentationController? _presentation;
private readonly EntityEffectController? _effects;
private readonly RemoteTeleportController? _remoteTeleport;
private readonly SelectionInteractionController? _interactions;
private readonly SelectionState? _selection;
private readonly LiveEntityAnimationRuntimeView<LiveEntityAnimationState>? _animations;
@ -47,7 +46,6 @@ internal sealed class LiveEntityRuntimeTeardownController
LiveEntityRuntime runtime,
LiveEntityPresentationController presentation,
EntityEffectController effects,
RemoteTeleportController remoteTeleport,
SelectionInteractionController? interactions,
SelectionState selection,
LiveEntityAnimationRuntimeView<LiveEntityAnimationState> animations,
@ -63,7 +61,6 @@ internal sealed class LiveEntityRuntimeTeardownController
_runtime = runtime ?? throw new ArgumentNullException(nameof(runtime));
_presentation = presentation ?? throw new ArgumentNullException(nameof(presentation));
_effects = effects ?? throw new ArgumentNullException(nameof(effects));
_remoteTeleport = remoteTeleport ?? throw new ArgumentNullException(nameof(remoteTeleport));
_interactions = interactions;
_selection = selection ?? throw new ArgumentNullException(nameof(selection));
_animations = animations ?? throw new ArgumentNullException(nameof(animations));
@ -110,7 +107,6 @@ internal sealed class LiveEntityRuntimeTeardownController
{
() => _presentation!.Forget(record),
() => _effects!.OnLiveEntityUnregistered(record),
() => _remoteTeleport!.Forget(record),
() =>
{
bool replacementExists =