feat(physics): C4 route 4b-3 — remote teleport + cell-less through the canonical placement

Flips the last remote classification (SetPosition: teleport-advanced and
cell-less) onto 4b-1's RuntimeRemotePlacementDriveController, runs retail's
teleport_hook before the placement, and deletes the legacy remote-teleport
machinery. Contract: docs/research/2026-08-04-c4-route-4b-3-contract.md.

Retail: MoveOrTeleport @0x00516330's branch @0x00516386 -> teleport_hook
@0x005163EF -> SetFlags(0x1012) @0x00516414 -> SetPosition @0x00516420 ->
return 1 @0x00516438. The hook @0x00514ED0 runs BEFORE the placement and
regardless of its outcome. Retail places this branch unconditionally, at any
distance and any contact state (arg4 is read only @0x0051638E, after the
branch) — which is what retires AP-137's cell-less enqueue-vs-place delta.

D1 — the classifier's cell-less input is now the PRE-merge committed cell.
Retail's predicate is `this_1->cell == 0`, the BODY's own cell at
MoveOrTeleport entry (this_1 is assigned from this @0x00516334). acdream fed
the POST-merge canonical.FullCellId, which RefreshSnapshot ->
RefreshDerivedState -> SetFullCell has already stamped with the accepted wire
cell; a zero wire cell fails validation into RejectedData first. The shipped
remote cell-less predicate was therefore dead code, not merely different from
remotePlacementRequired. Threaded via a builder overload; route 1's overload
is untouched. The graphical !IsSpatiallyVisible arm of
projectionRequiresTeleportHook is deleted — a presentation predicate with no
retail analogue that fired the teleport machinery on a routine hot path.

Deleted: RemoteTeleportController (605), RemoteTeleportPlacement (85),
RemoteShadowPlacementSynchronizer (49), their 1,709 lines of tests, the
remotePlacementRequired predicate, the TeleportHookRequired plumbing, the
legacy pre-operation ConstrainTo fallback, and the player arm's legacy
!IsGrounded fallback. Net -2,030 lines.

Structural fix (two independent Opus reviews, round 1 FAIL/FAIL): three of the
four MAJORs were one defect — OnPosition carried two parallel inline copies of
the routing tail (player-guid, NPC-guid) that had drifted. Extracted
RunRemoteArmTail (3 call sites) and ApplyWireAirborneLeftoverBookkeeping (2),
both branches now share one implementation.

  A1  ToConstraintArm mapped AirborneSnap -> AirborneNoOperation, so the NPC
      arm armed ConstrainTo ZERO times for an out-of-contact wire-grounded
      creature — a regression this slice introduced while closing a
      structurally identical hole. Now maps to NearInterpolate; switch made
      total with a throwing default proven unreachable.
  R1  D2's write-nothing shape existed on the player arm only; NPC packets
      fell through and wrote the body. Retail makes no player/NPC distinction.
  R2  report_collision_end(this,1) @0x00514F31 was bound to
      ShadowObjects.Suspend, a port of a DIFFERENT retail function
      (remove_shadows_from_cells) that teleport_hook never calls. Now routes
      to RuntimeCollisionReportingState.LeaveWorld, which wraps the private
      ForceEnd in an admission-blocking transaction so a DoCollisionEnd
      callback cannot recreate the contact table.
  R3/A2 A teleported NPC synthesized ServerVelocity from the teleport distance
      (~1,000+ m/s) and planned a run cycle from it. Both the install and
      RemoteServerControlledVelocityCycle.Apply now gate on !isTeleportRoute.

BISECT HAZARD — A1's fix is correct only BECAUSE R1 landed. AirborneSnap is
reachable wire-airborne on the NPC arm only while D2's shape is missing there.
Reverting R1 alone silently inverts A1 into the opposite divergence: arming
where retail returns 0. Revert both or neither.

Also in the velocity hunk: the NPC block's two !IsPlayerGuid(update.Guid)
guards were dropped when it was wrapped in `if (!isTeleportRoute)`. Safe — all
five exit paths of the enclosing IsPlayerGuid block return, so the predicate is
unconditionally false below it — but it was unremarked by both reviews.

Register: AP-137 REWRITTEN (not deleted) to the surviving acdream-only
divergences — null classification during the login window and Rejected*
through UnroutedCatchUp keep a row. AD-42's RemoteTeleportController citation
retired; AP-136/AP-138 writer lists corrected to the two surviving non-Position
rebucket writers; AP-138 gains the teleport arm as a second producer of the
visible-without-collision residual (retirement path remains #309). AP-135 is
untouched and its two airborne bookkeeping writes are preserved on both arms.
AP-131 does not retire; #276 does not close.

Proof obligation 1: ParkCollisionResidents' overlap throw stays unreachable —
the teleport arm adds packets to the same TryBeginExclusiveAuthoredPlacement
one-operation-per-key machinery the far arm uses, opens no new operation shape,
and every DeferredCell outcome cancels synchronously with
restoreCancelledPark: true. The guarded property remains
HasOldPrefixPlacementDebt's stall, not a throw (4b-1's B2 caveat stands).

Correction to an earlier claim: LiveEntityPresentationController's
_activePlacementOwners was NOT write-never at HEAD —
remotePlacementRequired -> BeginPlacement -> Begin -> BeginAuthoritativePlacement
was a live writer chain. It becomes write-never BECAUSE this slice deletes that
chain, which is why deleting the dead half is behaviour-preserving.

Probe: ACDREAM_PROBE_REMOTE_TELEPORT=1 emits one [remote-teleport] line per
routed arm (guid, cause, hook-ran, placement status). TEMPORARY, strip with the
probe family.

Carried, disclosed not fixed: no dedicated bidirectional collision-partner test
for R2 (the wiring, not LeaveWorld itself, is what lacks coverage); the
stress test's teleport step drives hand-written field assignments rather than
the canonical arm; the per-packet runTeleportHook closure allocation (network
path, not the resolve path Slice I's 0 B discipline governs — file before
route 5 adds a fourth call site). B2: IRuntimeCollisionReportObserver has zero
production implementations, so retail's bidirectional DoCollisionEnd half still
reaches no gameplay consumer — this fix closes the wrong-function binding, not
that nobody listens.

Complete Release suite MEASURED at 11,013 passed / 4 skipped / 0 failed
(baseline 11,027/4/0; net -14 = ~33 deleted test cases against ~19 added).
Neither known flake fired (#302 PortalProjectionTests GC-allocation, #308
NakEmissionTests wall-clock).

STILL OWED: the two-client connected gate, which MUST use an NPC/creature
teleport target. Both round-1 MAJORs lived on the NPC arm and the velocity
cycle early-returns for 0x50xxxxxx guids, so a player target structurally
cannot observe A1, A2, or R3.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-04 16:00:10 +02:00
parent 3e002993dd
commit 6dc7ba51ee
53 changed files with 2980 additions and 3372 deletions

View file

@ -56,7 +56,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 200f),
DecoyWirePose,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.FarSnapPlacement,
@ -105,7 +106,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 200f),
DecoyWirePose,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.False(remote.Interp.IsActive);
fixture.DrainPlacementFifo();
@ -146,7 +148,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 200f),
DecoyWirePose,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.FarSnapPlacement,
@ -214,7 +217,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 200f),
DecoyWirePose,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Refused,
@ -254,7 +258,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
route: null,
target,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.UnroutedCatchUp,
@ -294,7 +299,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
route: null,
target,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.UnroutedCatchUp,
@ -327,7 +333,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
rejected,
target,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.UnroutedCatchUp,
@ -337,13 +344,16 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
}
/// <summary>
/// Retail's cell-less body takes <c>this_1-&gt;cell == 0</c> @0x00516386
/// (<c>SetPosition</c>), never the far branch — and route 4b-3, not this
/// slice, owns it. Claiming it here would be exactly route 4a's
/// "'not Interpolate' is not 'far'" finding one level up.
/// C4 route 4b-3 (D1/D5): retail's cell-less body takes
/// <c>this_1-&gt;cell == 0</c> @0x00516386 — the SAME teleport branch as a
/// fresh TELEPORT_TS — never the far/near/leftover arms. The hook runs
/// (before the placement, per D3) and the body ends at the canonical
/// RESOLVED destination, not at the caller's separately-supplied
/// <paramref name="target"/> wire pose (the decoy discriminates the same
/// way the far-snap test above does).
/// </summary>
[Fact]
public void CellLessRemote_TakesTheUnroutedCatchUp_AndNeverThePlacementOwner()
public void CellLessRemote_TakesTheTeleportArm_RunsTheHookAndPlacesCanonically()
{
using var fixture = new RemotePlacementDriveFixture();
fixture.PublishDestinationCollision();
@ -360,6 +370,7 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
RuntimeAuthoritativePositionDisposition.SetPosition,
cellLess.Disposition);
int hookCalls = 0;
LiveEntityNetworkUpdateController.RemoteContactRouting routing =
LiveEntityNetworkUpdateController.ApplyRemoteContactRouting(
fixture.Drive,
@ -368,12 +379,27 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
cellLess,
target,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () =>
{
hookCalls++;
return true;
});
Assert.Equal(1, hookCalls);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.UnroutedCatchUp,
LiveEntityNetworkUpdateController.RemoteContactArm.TeleportPlacement,
routing.Arm);
Assert.Equal(target, body.Position);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Committed,
routing.Placement);
Assert.Equal(
Destination + RemotePlacementDriveFixture.DestinationWorldOffset,
body.Position);
Assert.NotEqual(target, body.Position);
Assert.Equal(RemotePlacementDriveFixture.DestinationCell, record.FullCellId);
fixture.DrainPlacementFifo();
Assert.Equal(0, fixture.LiveOperationCount);
Assert.Equal(0, fixture.RemotePlacementLedger);
}
@ -409,7 +435,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 200f),
target,
Quaternion.Identity,
willBeDrTicked: true);
willBeDrTicked: true,
runTeleportHook: () => true);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.AirborneSnap,
@ -418,6 +445,77 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Assert.Equal(0, fixture.LiveOperationCount);
}
/// <summary>
/// C4 route 4b-3, test-plan item 6 / contract D5: the teleport/cell-less
/// classification is decided BEFORE <c>ApplyRemoteContactRouting</c> ever
/// reads <c>remote.Body.InContact</c> — retail's <c>MoveOrTeleport</c>
/// tests <c>this_1-&gt;cell == 0 || newer_event(TELEPORT_TS)</c>
/// @0x00516375-@0x00516386 strictly before the wire-contact branch at
/// @0x0051638E. A mid-arc body's teleport packet must therefore still
/// place canonically — the OPPOSITE outcome of
/// <see cref="AirborneBody_OutranksTheFarSnap"/> above, which proves the
/// far arm defers to airborne precedence while this proves the teleport
/// arm does not. Fails against a broken ordering that lets the airborne
/// carve-out claim the packet first: <paramref name="body"/> would then
/// sit at the raw <c>target</c> wire pose the airborne branch writes,
/// never resolved through the canonical destination.
/// </summary>
[Fact]
public void AirborneBody_TeleportOutranksAirborneSnap()
{
using var fixture = new RemotePlacementDriveFixture();
fixture.PublishDestinationCollision();
fixture.AllowDestination();
(RuntimeEntityRecord record, RemoteMotion remote, PhysicsBody body) =
fixture.AddRemote(0x7000400Cu, Destination);
// Same mid-arc state as AirborneBody_OutranksTheFarSnap: no wire
// contact, free flight in both the old and new terms of the gate.
remote.Airborne = true;
remote.Body.TransientState = TransientStateFlags.Active;
var target = new Vector3(60f, 10f, 7f);
RuntimeAuthoritativePositionRoute cellLess = Classify(
hasContact: false,
playerDistance: 200f,
committedCellId: 0u);
Assert.Equal(
RuntimeAuthoritativePositionDisposition.SetPosition,
cellLess.Disposition);
int hookCalls = 0;
LiveEntityNetworkUpdateController.RemoteContactRouting routing =
LiveEntityNetworkUpdateController.ApplyRemoteContactRouting(
fixture.Drive,
record,
remote,
cellLess,
target,
Quaternion.Identity,
willBeDrTicked: true,
runTeleportHook: () =>
{
hookCalls++;
return true;
});
Assert.Equal(1, hookCalls);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm.TeleportPlacement,
routing.Arm);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Committed,
routing.Placement);
Assert.Equal(
Destination + RemotePlacementDriveFixture.DestinationWorldOffset,
body.Position);
Assert.NotEqual(target, body.Position);
Assert.Equal(RemotePlacementDriveFixture.DestinationCell, record.FullCellId);
fixture.DrainPlacementFifo();
Assert.Equal(0, fixture.LiveOperationCount);
Assert.Equal(0, fixture.RemotePlacementLedger);
}
/// <summary>
/// Per-entity independence across the two arms in the same tick: one
/// remote's committed placement must not touch another's body or leak
@ -444,7 +542,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 200f),
DecoyWirePose,
Quaternion.Identity,
willBeDrTicked: true).Arm);
willBeDrTicked: true,
runTeleportHook: () => true).Arm);
Assert.Equal(
LiveEntityNetworkUpdateController.RemoteContactArm
.SteadyStateInterpolate,
@ -455,7 +554,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
Classify(hasContact: true, playerDistance: 10f),
nearBefore + new Vector3(0.5f, 0f, 0f),
Quaternion.Identity,
willBeDrTicked: true).Arm);
willBeDrTicked: true,
runTeleportHook: () => true).Arm);
Assert.Equal(
Destination + RemotePlacementDriveFixture.DestinationWorldOffset,
@ -497,7 +597,8 @@ public sealed class LiveEntityNetworkRemoteFarSnapIntegrationTests
airborne,
new Vector3(60f, 10f, 7f),
Quaternion.Identity,
willBeDrTicked: true));
willBeDrTicked: true,
runTeleportHook: () => true));
Assert.Equal(before, body.Position);
Assert.False(remote.Interp.IsActive);