feat(physics): C4 route 4b-3 — remote teleport + cell-less through the canonical placement
Flips the last remote classification (SetPosition: teleport-advanced and
cell-less) onto 4b-1's RuntimeRemotePlacementDriveController, runs retail's
teleport_hook before the placement, and deletes the legacy remote-teleport
machinery. Contract: docs/research/2026-08-04-c4-route-4b-3-contract.md.
Retail: MoveOrTeleport @0x00516330's branch @0x00516386 -> teleport_hook
@0x005163EF -> SetFlags(0x1012) @0x00516414 -> SetPosition @0x00516420 ->
return 1 @0x00516438. The hook @0x00514ED0 runs BEFORE the placement and
regardless of its outcome. Retail places this branch unconditionally, at any
distance and any contact state (arg4 is read only @0x0051638E, after the
branch) — which is what retires AP-137's cell-less enqueue-vs-place delta.
D1 — the classifier's cell-less input is now the PRE-merge committed cell.
Retail's predicate is `this_1->cell == 0`, the BODY's own cell at
MoveOrTeleport entry (this_1 is assigned from this @0x00516334). acdream fed
the POST-merge canonical.FullCellId, which RefreshSnapshot ->
RefreshDerivedState -> SetFullCell has already stamped with the accepted wire
cell; a zero wire cell fails validation into RejectedData first. The shipped
remote cell-less predicate was therefore dead code, not merely different from
remotePlacementRequired. Threaded via a builder overload; route 1's overload
is untouched. The graphical !IsSpatiallyVisible arm of
projectionRequiresTeleportHook is deleted — a presentation predicate with no
retail analogue that fired the teleport machinery on a routine hot path.
Deleted: RemoteTeleportController (605), RemoteTeleportPlacement (85),
RemoteShadowPlacementSynchronizer (49), their 1,709 lines of tests, the
remotePlacementRequired predicate, the TeleportHookRequired plumbing, the
legacy pre-operation ConstrainTo fallback, and the player arm's legacy
!IsGrounded fallback. Net -2,030 lines.
Structural fix (two independent Opus reviews, round 1 FAIL/FAIL): three of the
four MAJORs were one defect — OnPosition carried two parallel inline copies of
the routing tail (player-guid, NPC-guid) that had drifted. Extracted
RunRemoteArmTail (3 call sites) and ApplyWireAirborneLeftoverBookkeeping (2),
both branches now share one implementation.
A1 ToConstraintArm mapped AirborneSnap -> AirborneNoOperation, so the NPC
arm armed ConstrainTo ZERO times for an out-of-contact wire-grounded
creature — a regression this slice introduced while closing a
structurally identical hole. Now maps to NearInterpolate; switch made
total with a throwing default proven unreachable.
R1 D2's write-nothing shape existed on the player arm only; NPC packets
fell through and wrote the body. Retail makes no player/NPC distinction.
R2 report_collision_end(this,1) @0x00514F31 was bound to
ShadowObjects.Suspend, a port of a DIFFERENT retail function
(remove_shadows_from_cells) that teleport_hook never calls. Now routes
to RuntimeCollisionReportingState.LeaveWorld, which wraps the private
ForceEnd in an admission-blocking transaction so a DoCollisionEnd
callback cannot recreate the contact table.
R3/A2 A teleported NPC synthesized ServerVelocity from the teleport distance
(~1,000+ m/s) and planned a run cycle from it. Both the install and
RemoteServerControlledVelocityCycle.Apply now gate on !isTeleportRoute.
BISECT HAZARD — A1's fix is correct only BECAUSE R1 landed. AirborneSnap is
reachable wire-airborne on the NPC arm only while D2's shape is missing there.
Reverting R1 alone silently inverts A1 into the opposite divergence: arming
where retail returns 0. Revert both or neither.
Also in the velocity hunk: the NPC block's two !IsPlayerGuid(update.Guid)
guards were dropped when it was wrapped in `if (!isTeleportRoute)`. Safe — all
five exit paths of the enclosing IsPlayerGuid block return, so the predicate is
unconditionally false below it — but it was unremarked by both reviews.
Register: AP-137 REWRITTEN (not deleted) to the surviving acdream-only
divergences — null classification during the login window and Rejected*
through UnroutedCatchUp keep a row. AD-42's RemoteTeleportController citation
retired; AP-136/AP-138 writer lists corrected to the two surviving non-Position
rebucket writers; AP-138 gains the teleport arm as a second producer of the
visible-without-collision residual (retirement path remains #309). AP-135 is
untouched and its two airborne bookkeeping writes are preserved on both arms.
AP-131 does not retire; #276 does not close.
Proof obligation 1: ParkCollisionResidents' overlap throw stays unreachable —
the teleport arm adds packets to the same TryBeginExclusiveAuthoredPlacement
one-operation-per-key machinery the far arm uses, opens no new operation shape,
and every DeferredCell outcome cancels synchronously with
restoreCancelledPark: true. The guarded property remains
HasOldPrefixPlacementDebt's stall, not a throw (4b-1's B2 caveat stands).
Correction to an earlier claim: LiveEntityPresentationController's
_activePlacementOwners was NOT write-never at HEAD —
remotePlacementRequired -> BeginPlacement -> Begin -> BeginAuthoritativePlacement
was a live writer chain. It becomes write-never BECAUSE this slice deletes that
chain, which is why deleting the dead half is behaviour-preserving.
Probe: ACDREAM_PROBE_REMOTE_TELEPORT=1 emits one [remote-teleport] line per
routed arm (guid, cause, hook-ran, placement status). TEMPORARY, strip with the
probe family.
Carried, disclosed not fixed: no dedicated bidirectional collision-partner test
for R2 (the wiring, not LeaveWorld itself, is what lacks coverage); the
stress test's teleport step drives hand-written field assignments rather than
the canonical arm; the per-packet runTeleportHook closure allocation (network
path, not the resolve path Slice I's 0 B discipline governs — file before
route 5 adds a fourth call site). B2: IRuntimeCollisionReportObserver has zero
production implementations, so retail's bidirectional DoCollisionEnd half still
reaches no gameplay consumer — this fix closes the wrong-function binding, not
that nobody listens.
Complete Release suite MEASURED at 11,013 passed / 4 skipped / 0 failed
(baseline 11,027/4/0; net -14 = ~33 deleted test cases against ~19 added).
Neither known flake fired (#302 PortalProjectionTests GC-allocation, #308
NakEmissionTests wall-clock).
STILL OWED: the two-client connected gate, which MUST use an NPC/creature
teleport target. Both round-1 MAJORs lived on the NPC arm and the velocity
cycle early-returns for 0x50xxxxxx guids, so a player target structurally
cannot observe A1, A2, or R3.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
3e002993dd
commit
6dc7ba51ee
53 changed files with 2980 additions and 3372 deletions
|
|
@ -196,7 +196,7 @@ internal static class RuntimeRemoteSteadyStatePosition
|
|||
}
|
||||
|
||||
/// <summary>
|
||||
/// D2: retail arms <c>CPhysicsObj::ConstrainTo</c> strictly AFTER
|
||||
/// D2/D4: retail arms <c>CPhysicsObj::ConstrainTo</c> strictly AFTER
|
||||
/// <c>MoveOrTeleport</c> returns nonzero, anchored to the object's own
|
||||
/// CURRENT (i.e. post-move) position — <c>SmartBox::HandleReceivedPosition</c>
|
||||
/// 0x00453FD0 reads <c>&arg2->m_position</c> at 0x00454272, inside
|
||||
|
|
@ -204,38 +204,55 @@ internal static class RuntimeRemoteSteadyStatePosition
|
|||
/// does NOT run on the airborne no-op.
|
||||
///
|
||||
/// <para>
|
||||
/// Route-gated by
|
||||
/// <see cref="RuntimeRemoteFarSnapPosition.OwnsAfterOperationConstraint"/>
|
||||
/// — route 4a's two dispositions plus (C4 route 4b-2) the far snap. Every
|
||||
/// other classification still arms the leash through the legacy
|
||||
/// pre-operation call site, unchanged, until 4b-3 moves them too. The
|
||||
/// legacy site reads the SAME predicate, so no classification can be
|
||||
/// armed twice or left unarmed.
|
||||
/// </para>
|
||||
///
|
||||
/// <para>
|
||||
/// This deliberately does not consult the outcome of the operation it
|
||||
/// follows. Retail's far branch returns 1 @0x005163E8 unconditionally —
|
||||
/// <c>MoveOrTeleport</c> discards <c>SetPositionSimple</c>'s
|
||||
/// <c>enum SetPositionError</c> return entirely — so
|
||||
/// <c>HandleReceivedPosition</c> arms the leash even when the placement
|
||||
/// FAILED. "Arm only on commit" is the natural misreading and is the same
|
||||
/// shape as the already-recorded unarmed-leash bug.
|
||||
/// C4 route 4b-3 (D4): this is now the ONLY arming site — the legacy
|
||||
/// pre-operation call is deleted, matching retail's single
|
||||
/// @0x00454272. <paramref name="arm"/> is the routing outcome (which arm
|
||||
/// actually claimed the packet), NOT the raw classification, because
|
||||
/// that is the only input that correctly distinguishes a GROUNDED
|
||||
/// <see cref="RuntimeRemoteAcceptedPositionArm.UnroutedCatchUp"/> (arms —
|
||||
/// retail has no state here, but the analogue of "MoveOrTeleport returned
|
||||
/// nonzero" is true) from the wire-airborne leftover shape (D2's
|
||||
/// return-0 replacement, which never reaches this call at all — see the
|
||||
/// caller). The complete partition:
|
||||
/// </para>
|
||||
/// <list type="bullet">
|
||||
/// <item><description><see cref="RuntimeRemoteAcceptedPositionArm.TeleportPlacement"/>
|
||||
/// — arms on EVERY placement outcome (retail discards
|
||||
/// <c>SetPosition</c>'s error and returns 1 unconditionally
|
||||
/// @0x00516438).</description></item>
|
||||
/// <item><description><see cref="RuntimeRemoteAcceptedPositionArm.FarSnapPlacement"/>
|
||||
/// — arms unconditionally, same reason
|
||||
/// (@0x005163E8).</description></item>
|
||||
/// <item><description><see cref="RuntimeRemoteAcceptedPositionArm.NearInterpolate"/>
|
||||
/// — arms; retail's InterpolateTo branch returns 1
|
||||
/// (@0x005163BE).</description></item>
|
||||
/// <item><description><see cref="RuntimeRemoteAcceptedPositionArm.UnroutedCatchUp"/>
|
||||
/// — arms; only reachable here when the body is already known to be in
|
||||
/// contact (the caller's free-flight carve-out already
|
||||
/// returned).</description></item>
|
||||
/// <item><description><see cref="RuntimeRemoteAcceptedPositionArm.AirborneNoOperation"/>
|
||||
/// — never arms; retail's <c>arg4 == 0</c> branch returns 0
|
||||
/// (@0x0051636D). Both production callers already early-return on this
|
||||
/// classification before reaching any arming call, so this case is
|
||||
/// defensive.</description></item>
|
||||
/// </list>
|
||||
/// </summary>
|
||||
internal static bool TryArmConstraintAfterOperation(
|
||||
RuntimeAuthoritativePositionRoute? route,
|
||||
RuntimeRemoteAcceptedPositionArm arm,
|
||||
RemoteMotion remote)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(remote);
|
||||
if (route is not { } selected
|
||||
|| !RuntimeRemoteFarSnapPosition.OwnsAfterOperationConstraint(
|
||||
selected)
|
||||
|| !selected.ConstrainAfterRouting
|
||||
|| remote.Host is not { } host)
|
||||
bool arms = arm switch
|
||||
{
|
||||
RuntimeRemoteAcceptedPositionArm.TeleportPlacement => true,
|
||||
RuntimeRemoteAcceptedPositionArm.FarSnapPlacement => true,
|
||||
RuntimeRemoteAcceptedPositionArm.NearInterpolate => true,
|
||||
RuntimeRemoteAcceptedPositionArm.UnroutedCatchUp => true,
|
||||
RuntimeRemoteAcceptedPositionArm.AirborneNoOperation => false,
|
||||
_ => false,
|
||||
};
|
||||
if (!arms || remote.Host is not { } host)
|
||||
return false;
|
||||
}
|
||||
|
||||
ArmConstraintAfterOperation(host);
|
||||
return true;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue