feat(physics): C4 route 4b-3 — remote teleport + cell-less through the canonical placement

Flips the last remote classification (SetPosition: teleport-advanced and
cell-less) onto 4b-1's RuntimeRemotePlacementDriveController, runs retail's
teleport_hook before the placement, and deletes the legacy remote-teleport
machinery. Contract: docs/research/2026-08-04-c4-route-4b-3-contract.md.

Retail: MoveOrTeleport @0x00516330's branch @0x00516386 -> teleport_hook
@0x005163EF -> SetFlags(0x1012) @0x00516414 -> SetPosition @0x00516420 ->
return 1 @0x00516438. The hook @0x00514ED0 runs BEFORE the placement and
regardless of its outcome. Retail places this branch unconditionally, at any
distance and any contact state (arg4 is read only @0x0051638E, after the
branch) — which is what retires AP-137's cell-less enqueue-vs-place delta.

D1 — the classifier's cell-less input is now the PRE-merge committed cell.
Retail's predicate is `this_1->cell == 0`, the BODY's own cell at
MoveOrTeleport entry (this_1 is assigned from this @0x00516334). acdream fed
the POST-merge canonical.FullCellId, which RefreshSnapshot ->
RefreshDerivedState -> SetFullCell has already stamped with the accepted wire
cell; a zero wire cell fails validation into RejectedData first. The shipped
remote cell-less predicate was therefore dead code, not merely different from
remotePlacementRequired. Threaded via a builder overload; route 1's overload
is untouched. The graphical !IsSpatiallyVisible arm of
projectionRequiresTeleportHook is deleted — a presentation predicate with no
retail analogue that fired the teleport machinery on a routine hot path.

Deleted: RemoteTeleportController (605), RemoteTeleportPlacement (85),
RemoteShadowPlacementSynchronizer (49), their 1,709 lines of tests, the
remotePlacementRequired predicate, the TeleportHookRequired plumbing, the
legacy pre-operation ConstrainTo fallback, and the player arm's legacy
!IsGrounded fallback. Net -2,030 lines.

Structural fix (two independent Opus reviews, round 1 FAIL/FAIL): three of the
four MAJORs were one defect — OnPosition carried two parallel inline copies of
the routing tail (player-guid, NPC-guid) that had drifted. Extracted
RunRemoteArmTail (3 call sites) and ApplyWireAirborneLeftoverBookkeeping (2),
both branches now share one implementation.

  A1  ToConstraintArm mapped AirborneSnap -> AirborneNoOperation, so the NPC
      arm armed ConstrainTo ZERO times for an out-of-contact wire-grounded
      creature — a regression this slice introduced while closing a
      structurally identical hole. Now maps to NearInterpolate; switch made
      total with a throwing default proven unreachable.
  R1  D2's write-nothing shape existed on the player arm only; NPC packets
      fell through and wrote the body. Retail makes no player/NPC distinction.
  R2  report_collision_end(this,1) @0x00514F31 was bound to
      ShadowObjects.Suspend, a port of a DIFFERENT retail function
      (remove_shadows_from_cells) that teleport_hook never calls. Now routes
      to RuntimeCollisionReportingState.LeaveWorld, which wraps the private
      ForceEnd in an admission-blocking transaction so a DoCollisionEnd
      callback cannot recreate the contact table.
  R3/A2 A teleported NPC synthesized ServerVelocity from the teleport distance
      (~1,000+ m/s) and planned a run cycle from it. Both the install and
      RemoteServerControlledVelocityCycle.Apply now gate on !isTeleportRoute.

BISECT HAZARD — A1's fix is correct only BECAUSE R1 landed. AirborneSnap is
reachable wire-airborne on the NPC arm only while D2's shape is missing there.
Reverting R1 alone silently inverts A1 into the opposite divergence: arming
where retail returns 0. Revert both or neither.

Also in the velocity hunk: the NPC block's two !IsPlayerGuid(update.Guid)
guards were dropped when it was wrapped in `if (!isTeleportRoute)`. Safe — all
five exit paths of the enclosing IsPlayerGuid block return, so the predicate is
unconditionally false below it — but it was unremarked by both reviews.

Register: AP-137 REWRITTEN (not deleted) to the surviving acdream-only
divergences — null classification during the login window and Rejected*
through UnroutedCatchUp keep a row. AD-42's RemoteTeleportController citation
retired; AP-136/AP-138 writer lists corrected to the two surviving non-Position
rebucket writers; AP-138 gains the teleport arm as a second producer of the
visible-without-collision residual (retirement path remains #309). AP-135 is
untouched and its two airborne bookkeeping writes are preserved on both arms.
AP-131 does not retire; #276 does not close.

Proof obligation 1: ParkCollisionResidents' overlap throw stays unreachable —
the teleport arm adds packets to the same TryBeginExclusiveAuthoredPlacement
one-operation-per-key machinery the far arm uses, opens no new operation shape,
and every DeferredCell outcome cancels synchronously with
restoreCancelledPark: true. The guarded property remains
HasOldPrefixPlacementDebt's stall, not a throw (4b-1's B2 caveat stands).

Correction to an earlier claim: LiveEntityPresentationController's
_activePlacementOwners was NOT write-never at HEAD —
remotePlacementRequired -> BeginPlacement -> Begin -> BeginAuthoritativePlacement
was a live writer chain. It becomes write-never BECAUSE this slice deletes that
chain, which is why deleting the dead half is behaviour-preserving.

Probe: ACDREAM_PROBE_REMOTE_TELEPORT=1 emits one [remote-teleport] line per
routed arm (guid, cause, hook-ran, placement status). TEMPORARY, strip with the
probe family.

Carried, disclosed not fixed: no dedicated bidirectional collision-partner test
for R2 (the wiring, not LeaveWorld itself, is what lacks coverage); the
stress test's teleport step drives hand-written field assignments rather than
the canonical arm; the per-packet runTeleportHook closure allocation (network
path, not the resolve path Slice I's 0 B discipline governs — file before
route 5 adds a fourth call site). B2: IRuntimeCollisionReportObserver has zero
production implementations, so retail's bidirectional DoCollisionEnd half still
reaches no gameplay consumer — this fix closes the wrong-function binding, not
that nobody listens.

Complete Release suite MEASURED at 11,013 passed / 4 skipped / 0 failed
(baseline 11,027/4/0; net -14 = ~33 deleted test cases against ~19 added).
Neither known flake fired (#302 PortalProjectionTests GC-allocation, #308
NakEmissionTests wall-clock).

STILL OWED: the two-client connected gate, which MUST use an NPC/creature
teleport target. Both round-1 MAJORs lived on the NPC arm and the velocity
cycle early-returns for 0x50xxxxxx guids, so a player target structurally
cannot observe A1, A2, or R3.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-04 16:00:10 +02:00
parent 3e002993dd
commit 6dc7ba51ee
53 changed files with 2980 additions and 3372 deletions

View file

@ -1237,7 +1237,6 @@ public sealed class RuntimeAcceptedPositionDriveControllerTests
isLocalPlayer: true,
forcePositionRotation: controller.BodyOrientation,
currentLocalVelocity: controller.BodyVelocity,
projectionRequiresTeleportHook: false,
acknowledgeProjection: null,
out PositionTimestampDisposition disposition,
out _,
@ -1306,7 +1305,6 @@ public sealed class RuntimeAcceptedPositionDriveControllerTests
Teleport: teleport,
ForcePosition: 1,
TeleportAdvanced: false,
TeleportHookRequired: false,
PreviousTeleport: teleport);
/// <summary>

View file

@ -1935,6 +1935,327 @@ public sealed class RuntimeRemotePlacementDriveControllerTests
}
}
// ── C4 route 4b-3: the teleport/cell-less arm ───────────────────────────
// TryExecuteAcceptedRemotePosition/SubmitAndResolve's own mechanics
// (commit/park/reject dispatch, currency, ledger convergence) are already
// exhaustively proven above for SetPosition-disposition routes — several
// far-snap tests already construct SetPosition routes because
// TryExecuteAcceptedRemotePosition is disposition-agnostic. What is new
// here is ApplyAcceptedRemoteTeleport's OWN behaviour: the route guard,
// the store_position fallback wired for the teleport disposition
// specifically, and (D3) that it does NOT clear the interpolation queue
// itself — unlike the far arm, retail's clear for this branch lives
// inside teleport_hook, not in MoveOrTeleport.
/// <summary>
/// Mirrors <see cref="Committed_WhenDestinationIsWithinServiceWindowAndCollisionGenerationCommitted"/>
/// through the teleport arm specifically.
/// </summary>
[Fact]
public void Teleport_Committed_PlacesFromCanonicalDestination()
{
using var lifetime = new RuntimeEntityObjectLifetime(FlatEngine());
CommitLandblockCollision(lifetime, DestinationLandblock);
RuntimeEntityRecord record = CreateRemoteRecord(lifetime, 0x70003040u);
PhysicsBody body = AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
var window = new FakeServiceWindow();
window.Allow(DestinationLandblock);
RuntimeRemotePlacementDriveController drive = CreateDrive(lifetime, window);
var destination = new Vector3(12f, 14f, SpawnHeight);
RuntimeAuthoritativePositionRoute route = MakeRoute(
record,
RuntimeAuthoritativePositionDisposition.SetPosition,
DestinationCell,
destination);
RuntimeRemotePlacementExecutionStatus status =
drive.ApplyAcceptedRemoteTeleport(record, remote, route);
Assert.Equal(RuntimeRemotePlacementExecutionStatus.Committed, status);
Assert.Equal(destination + new Vector3(192f, 0f, 0f), body.Position);
DrainPlacementFifo(lifetime);
Assert.Equal(
0, lifetime.Physics.CaptureOwnership().SetPositionOperationCount);
AssertConverged(lifetime);
}
/// <summary>
/// Invariant 1: a teleport whose destination the service window declines
/// still advances the body to the accepted destination — retail's
/// no-transition <c>store_position</c> branch, identical to the far arm's
/// own fallback.
/// </summary>
[Fact]
public void Teleport_RefusedByServiceWindow_StillStoresTheDestinationPose()
{
using var lifetime = new RuntimeEntityObjectLifetime(FlatEngine());
// The world frame must still be published (store_position resolves
// through it); the service window is what refuses — mirrors
// FarSnap_ClearsTheInterpolationQueue_IndependentlyOfThePlacementOutcome's
// setup, which is the far arm's own Refused-fallback test.
CommitLandblockCollision(lifetime, DestinationLandblock);
RuntimeEntityRecord record = CreateRemoteRecord(lifetime, 0x70003041u);
PhysicsBody body = AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
Vector3 positionBefore = body.Position;
// Deliberately does not Allow(DestinationLandblock) — the service
// window refuses.
var window = new FakeServiceWindow();
RuntimeRemotePlacementDriveController drive = CreateDrive(lifetime, window);
var destination = new Vector3(12f, 14f, SpawnHeight);
RuntimeAuthoritativePositionRoute route = MakeRoute(
record,
RuntimeAuthoritativePositionDisposition.SetPosition,
DestinationCell,
destination);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Refused,
drive.ApplyAcceptedRemoteTeleport(record, remote, route));
Assert.NotEqual(positionBefore, body.Position);
Assert.True(body.InWorld);
AssertConverged(lifetime);
}
/// <summary>
/// The non-storing half of retail's partition, through the teleport arm:
/// the engine's own sweep refused the destination
/// (<c>RejectedByPlacement</c>), so the body must be left exactly where
/// it was — mirrors
/// <see cref="FarSnap_EngineRefusedTheDestination_LeavesTheBodyWhereItWas"/>.
/// </summary>
[Fact]
public void Teleport_EngineRefusedTheDestination_LeavesTheBodyWhereItWas()
{
PhysicsEngine engine = FlatEngine();
using var lifetime = new RuntimeEntityObjectLifetime(engine);
CommitLandblockCollision(lifetime, DestinationLandblock);
RuntimeEntityRecord record = CreateRemoteRecord(lifetime, 0x70003042u);
PhysicsBody body = AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
Vector3 positionBefore = body.Position;
var window = new FakeServiceWindow();
window.Allow(DestinationLandblock);
RuntimeRemotePlacementDriveController drive = CreateDrive(lifetime, window);
engine.TransitionCellCollisionTestHook =
static (_, _, _, _) => TransitionState.Collided;
var destination = new Vector3(12f, 14f, SpawnHeight);
RuntimeAuthoritativePositionRoute route = MakeRoute(
record,
RuntimeAuthoritativePositionDisposition.SetPosition,
DestinationCell,
destination);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.RejectedByPlacement,
drive.ApplyAcceptedRemoteTeleport(record, remote, route));
Assert.Equal(positionBefore, body.Position);
Assert.NotEqual(destination + new Vector3(192f, 0f, 0f), body.Position);
AssertConverged(lifetime);
}
/// <summary>
/// D3: unlike the far arm, <c>ApplyAcceptedRemoteTeleport</c> must NOT
/// clear the interpolation queue itself — the classifier's teleport
/// branch carries <c>StopInterpolating: false</c> on purpose, because
/// retail's clear for this branch lives inside <c>teleport_hook</c>'s
/// <c>PositionManager::StopInterpolating</c> @0x00514EFD, which the
/// CALLER (<c>ApplyRemoteContactRouting</c>) runs before this method. If
/// this method also cleared the queue, the two would race on which side
/// "owns" the retail action.
/// </summary>
[Fact]
public void Teleport_DoesNotClearTheInterpolationQueueItself()
{
using var lifetime = new RuntimeEntityObjectLifetime(FlatEngine());
CommitLandblockCollision(lifetime, DestinationLandblock);
RuntimeEntityRecord record = CreateRemoteRecord(lifetime, 0x70003043u);
PhysicsBody body = AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
remote.Interp.Enqueue(
new Vector3(40f, 40f, SpawnHeight),
Quaternion.Identity,
isMovingTo: false,
currentBodyPosition: body.Position,
currentBodyOrientation: body.Orientation);
Assert.True(remote.Interp.IsActive);
var window = new FakeServiceWindow();
window.Allow(DestinationLandblock);
RuntimeRemotePlacementDriveController drive = CreateDrive(lifetime, window);
RuntimeAuthoritativePositionRoute route = MakeRoute(
record,
RuntimeAuthoritativePositionDisposition.SetPosition,
DestinationCell,
new Vector3(12f, 14f, SpawnHeight));
Assert.False(route.StopInterpolating);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Committed,
drive.ApplyAcceptedRemoteTeleport(record, remote, route));
Assert.True(remote.Interp.IsActive);
DrainPlacementFifo(lifetime);
}
/// <summary>
/// The teleport arm must never be handed a route it does not own — the
/// caller selects with
/// <c>RuntimeRemoteTeleportPosition.OwnsTeleportPlacement</c>. Mirrors
/// <see cref="FarSnap_ThrowsForARouteThisArmDoesNotOwn"/>.
/// </summary>
[Fact]
public void Teleport_ThrowsForARouteThisArmDoesNotOwn()
{
using var lifetime = new RuntimeEntityObjectLifetime(FlatEngine());
RuntimeEntityRecord record = CreateRemoteRecord(lifetime, 0x70003044u);
AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
RuntimeRemotePlacementDriveController drive =
CreateDrive(lifetime, new FakeServiceWindow());
foreach (RuntimeAuthoritativePositionDisposition disposition in
new[]
{
RuntimeAuthoritativePositionDisposition.SetPositionSimple,
RuntimeAuthoritativePositionDisposition.Interpolate,
RuntimeAuthoritativePositionDisposition.NoPositionOperation,
RuntimeAuthoritativePositionDisposition.RejectedData,
})
{
RuntimeAuthoritativePositionRoute route = MakeRoute(
record, disposition, DestinationCell);
Assert.Throws<ArgumentException>(
() => drive.ApplyAcceptedRemoteTeleport(record, remote, route));
}
}
/// <summary>
/// Test-plan item 7 / contract D3's currency rule, "now for the teleport
/// arm" — the R5 shape
/// <see cref="FarSnap_SupersededIncarnation_DoesNotStoreThroughTheStaleRecord"/>
/// already pins for <c>ApplyAcceptedRemoteFarSnap</c>. Retail's
/// <c>store_position</c> fallback is the SAME method
/// (<c>StoreAcceptedDestinationPose</c>) both arms call through, but that
/// sharing is exactly why it needs its own pin: a future edit could special-
/// case one arm's call site without the other, and only a same-shaped test
/// for each caller catches that. Reaches the stale-record state the same
/// deterministic way — dropping the record from the active directory while
/// its body/key/snapshot stay exactly as the packet left them, so the
/// currency guard (not a null check) is what's under test.
/// </summary>
[Fact]
public void Teleport_SupersededIncarnation_DoesNotStoreThroughTheStaleRecord()
{
using var lifetime = new RuntimeEntityObjectLifetime(FlatEngine());
CommitLandblockCollision(lifetime, DestinationLandblock);
RuntimeEntityRecord record = CreateRemoteRecord(lifetime, 0x70003045u);
PhysicsBody body = AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
Vector3 positionBefore = body.Position;
// Deliberately does not Allow(DestinationLandblock) — the service
// window refuses, landing on the SAME store_position fallback the far
// arm's currency test exercises.
RuntimeRemotePlacementDriveController drive =
CreateDrive(lifetime, new FakeServiceWindow());
var destination = new Vector3(12f, 14f, SpawnHeight);
RuntimeAuthoritativePositionRoute route = MakeRoute(
record,
RuntimeAuthoritativePositionDisposition.SetPosition,
DestinationCell,
destination);
Assert.True(lifetime.Entities.RemoveActive(record));
Assert.False(lifetime.Entities.IsCurrent(record));
Assert.NotNull(record.PhysicsBody);
Assert.NotNull(record.Key);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Refused,
drive.ApplyAcceptedRemoteTeleport(record, remote, route));
Assert.Equal(positionBefore, body.Position);
Assert.NotEqual(destination + new Vector3(192f, 0f, 0f), body.Position);
AssertConverged(lifetime);
}
/// <summary>
/// Test-plan item 8 / proof obligation 2: teardown, session reset, and
/// generation change all converge <c>RemotePlacementDrivePendingCount</c>
/// to zero — driven through <see cref="ApplyAcceptedRemoteTeleport"/>
/// itself, not assumed transitively from
/// <see cref="LedgerConverges_AfterDetachRouteClearsTrackedEntries"/>
/// (which seeds its retained entry through the lower shared
/// <c>TryExecuteAcceptedRemotePosition</c> entry point, bypassing the
/// teleport arm's own route-ownership check entirely). <c>DetachRoute</c>
/// is the one production convergence hook this controller exposes —
/// <c>GameRuntime</c>'s teardown, session reset, and generation-change
/// paths all funnel through it, exactly as they do for the far arm's own
/// already-covered case; there is no separate per-cause API to test
/// independently at this layer.
///
/// <para>
/// Retains via the SAME "retryable preparation" shape
/// <see cref="FarSnap_RetryablePreparation_StoresThePoseAndStillRetainsTheRetry"/>
/// uses (an unresolved Setup collision reports <c>Contention</c> and
/// parks an entry in <c>_pending</c> for the cadence pump) — so the
/// convergence this test proves is genuinely draining a LIVE retained
/// teleport retry, not an already-empty ledger.
/// </para>
/// </summary>
[Fact]
public void Teleport_LedgerConverges_AfterDetachRouteClearsARetainedRetry()
{
using var lifetime = new RuntimeEntityObjectLifetime(FlatEngine());
CommitLandblockCollision(lifetime, DestinationLandblock);
RuntimeEntityRecord record = CreateRemoteRecord(
lifetime, 0x70003046u, setupTableId: 0x02000001u);
PhysicsBody body = AttachBody(lifetime, record, SourceCell);
RemoteMotion remote = lifetime.Physics.GetOrCreateRemoteMotion(record);
Vector3 positionBefore = body.Position;
var window = new FakeServiceWindow();
window.Allow(DestinationLandblock);
RuntimeRemotePlacementDriveController drive = CreateDrive(lifetime, window);
var route = new object();
drive.AttachRoute(route);
var destination = new Vector3(12f, 14f, SpawnHeight);
RuntimeAuthoritativePositionRoute teleportRoute = MakeRoute(
record,
RuntimeAuthoritativePositionDisposition.SetPosition,
DestinationCell,
destination,
stopInterpolating: true);
Assert.Equal(
RuntimeRemotePlacementExecutionStatus.Contention,
drive.ApplyAcceptedRemoteTeleport(record, remote, teleportRoute));
// The retained retry is live (not assumed) — a second call through
// the arm proves it, mirroring the far arm's own
// FarSnap_RetryablePreparation test's shape.
Assert.Equal(1, drive.PendingCount);
Assert.Equal(
1, lifetime.CaptureOwnership().RemotePlacementDrivePendingCount);
Assert.Equal(
destination + new Vector3(192f, 0f, 0f), body.Position);
Assert.NotEqual(positionBefore, body.Position);
drive.DetachRoute(route);
Assert.Equal(0, drive.PendingCount);
Assert.Equal(
0, lifetime.CaptureOwnership().RemotePlacementDrivePendingCount);
AssertConverged(lifetime);
}
// ── Fixture ──────────────────────────────────────────────────────────
/// <summary>