fix(streaming): make a demoted landblock render-ready like a published one (#280 D-1)

Both #280 review lenses returned FAIL on the same defect, and both were
right. IsRenderNeighborhoodResident's widened outer arm requires
IsRenderReady out to FarRadius, justified by "a Far-tier landblock
registers with an empty mesh set and is therefore render-ready." That held
only for a landblock that ARRIVED as Far. The second, equally first-class
way to be Far tier is a Near->Far DEMOTE:

  DemoteLandblock -> EnqueueNearLayerRetirement
    -> LandblockRetirementStage.MeshReferences
    -> GpuWorldState.ReleaseLandblockMeshReferences
    -> LandblockSpawnAdapter.OnLandblockUnloaded  => WantsLoaded = false

while DetachNearLayer deliberately keeps the landblock loaded, terrain-mesh
resident, terrain-collision resident and DRAWN. Nothing re-publishes an
already-loaded landblock, so the demoted member satisfied NEITHER arm of
the gate, permanently: wormhole tunnel plus centered "In Portal Space -
Please Wait..." forever, no recovery short of relog.

Reachable by ordinary play. Two consecutive recalls to the same landblock
with walking in between makes ChangesStreamingCenter false, so there is no
origin recenter and the region recentres through the ordinary demote diff.
Also reachable via a mid-hold quality-preset drop -- ironically the exact
scenario ReconcileDestinationReservationRadius was added to support. The
pre-#280 radius-1 gate never touched that band, because nothing inside the
Near ring can demote.

FIX SHAPE. Make the two routes genuinely equivalent rather than teaching
the predicate to tolerate the difference. ReleaseLandblockMeshReferences
becomes "reconcile the registration to the post-retirement tier": after the
release converges, if the landblock is still loaded AND still Far tier,
re-assert the empty registration -- the identical OnLandblockLoaded(lb,
empty) a PublicationKind.Far activation makes. It is empty by construction:
DetachNearLayer retains only live server projections, which the adapter's
atlas-tier filter skips. A full retirement is unaffected (DetachLandblock
clears both _loaded and _tierByLandblock), and a throwing release still
retries because the re-assert is only reached after the adapter converged.

The alternative -- "|| (IsFarTier && IsLoaded)" at the gate -- was
rejected: it fixes one caller while leaving IsRenderReady meaning two
different things, which is precisely how this defect arose. After this
change the predicate reads "drawable at its current tier" for every caller,
with no knowledge of how the landblock got there.

WHY THE TESTS MISSED IT, fixed here too:

- Proof obligation P2 was discharged against RESIDENCY (the FarRadius+2
  eviction threshold) rather than against IsRenderReady, the gate's actual
  atom. The contract now carries the correction and the restated
  obligation: no transition may REVOKE IsRenderReady from a landblock that
  stays inside FarRadius.
- WorldRevealDerivedWindowIntegrationTests advertised itself as end-to-end
  against the real GpuWorldState but constructed it with no spawn adapter,
  so its IsRenderReady degenerated to IsLoaded via the "?? true". The
  single most load-bearing predicate in the change was stubbed out by a
  null in the test named after it -- the same shape as C5b's D3 and #276's
  three settler tests. Every fixture in that file now owns a real
  LandblockSpawnAdapter.
- The P1 test's comment described its subject as "a Near-shaped completion
  the streaming window has since DEMOTED to Far". It is not; it is a fresh
  PublishAsFar, the case that does hold. Corrected, since a future reader
  would have taken it as demote coverage.

Four new regression tests, all driving the real GpuWorldState +
LandblockSpawnAdapter + LandblockPresentationPipeline through an actual
demote, and all sabotage-verified in both directions (fail with the
production change reverted, pass with it):

  NearToFarDemote_LeavesTheLandblockRenderReadyThroughTheRealPipeline
  NearToFarDemote_LeavesTheLandblockRenderReadyUnderBudgetedRetirement
  TieredWindow_StaysResidentAfterAnOuterRingDemote
  OutdoorReveal_SurvivesAnOuterRingDemoteDuringTheHold

The budgeted variant exists because production composes
LandblockRetirementCoordinator.CreateBudgeted, whose MeshReferences stage
is a separate call site from the legacy pipeline's.

SECONDARY, same commit:

- R-1: ACDREAM_PROBE_REVEAL_RADIUS=0 was parser-accepted and
  Runtime-rejected -- it yields far = 0 for an outdoor destination, which
  fails invalid-readiness-shape on every acknowledgement, hanging the very
  A/B route the probe exists to measure. Parser floor raised to 1, with a
  7-case table test.
- R-2: the composite-warmup TRIGGER had silently moved onto the far
  window's critical path. Pre-#280 the gate and the composite domain were
  the same radius-1 square; #280 widened the gate without widening the
  domain, so every composite upload serialised behind the last outer-ring
  landblock for no readiness benefit. Warmup now starts once the NEAR
  sub-window is published -- trigger scope == domain scope, as before. The
  reveal gate is untouched: Evaluate still requires the full window AND
  composite readiness.
- AP-150 filed: acdream's RetailWaitCueDelay = 5 s arming is NOT retail's
  trigger, and #280's commit message got this wrong on both clauses. Retail
  emits the notice unconditionally per tunnel rotation segment, in the else
  arm of the segment-expiry test at 0x004D6FCD; segment duration is
  RandDouble(0.6, 1.8) s, byte-decoded at 0x004D6FE6. The 5.0 constant at
  VA 0x007991B0 is CellManager::CheckPrefetchStatus's prefetch RETRY
  cadence and has nothing to do with the cue. acdream's own 0.6/1.8 segment
  constants already match retail exactly; only the arming is wrong.
  Adopting retail's unconditional emit is filed as #329 rather than folded
  in here -- it is a user-visible presentation change and wants the user's
  eyes.
- AP-151 filed: the gate is materially STRICTER than retail on the
  mesh-build/GPU-upload axis. Retail's LScape::PreFetchCells blocks on DAT
  RESIDENCY only -- no geometry construction, no upload; that work is lazy
  at draw. acdream requires a DAT read, terrain mesh build, render-thread
  upload, spatial commit, collision admission and spawn-adapter activation
  per member of a 625-member window, metered at MaxCompletionsPerFrame.
  Nothing bounds the hold. This is the OPPOSITE asymmetry from AP-149; both
  are live at once, on different axes.
- AD-2's amendment stated the false Far-tier readiness assumption verbatim;
  corrected, along with the same error in
  claude-memory/reference_two_tier_streaming.md, which now carries an
  explicit DO-NOT-RETRY on the special-case-the-predicate shape.
- AP-115 scope-noted (it covers the cue's presentation, not its arming).
- #326's SmartBox::set_mid_radius citation corrected: the entry is
  0x00453180; 0x004531D0 is the mid-function re-arm branch.

Blast radius: GpuWorldState, LandblockSpawnAdapter,
WorldRevealReadinessBarrier and StreamingDiagnostics are all App-internal;
AcDream.Headless and AcDream.Runtime reference none of them outside
comments. Headless tests run green as part of the gate below, per C5b's
lesson about surveys that skip the no-window host.

Gates: Release build 0 errors, 18 pre-existing xUnit analyzer warnings.
Complete suite "dotnet test AcDream.slnx -c Release -m:1" with
ACDREAM_PAK_PATH set: 11,192 passed / 4 skipped / 0 failed, from a clean
rebuild (a prior session's deleted probe file had been compiled into a
stale test DLL). Baseline at fafc0b65 was 11,179 / 4 / 0; the +13 delta
reconciles exactly to this commit's additions -- 3 readiness tests, 1
integration test, 7 parser table cases, 2 warmup-trigger tests. None of the
known flakes #302/#308/#321 surfaced, and none is conflated with the
finding above.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-06 07:27:28 +02:00
parent fafc0b65d9
commit 73cdb95c7b
13 changed files with 1456 additions and 38 deletions

View file

@ -565,9 +565,13 @@ public sealed class StreamingControllerReadinessTests
publishBeforeSpatialCommit: (_, _) => { },
state);
// A Near-shaped completion that the streaming window has since demoted
// to Far: entities and physics payload are stripped by PublishAsFar,
// which is exactly the shape an outer-ring landblock is published in.
// A Near-shaped completion the streaming window has DOWNGRADED before
// publication: entities and physics payload are stripped by
// PublishAsFar, which is exactly the shape an outer-ring landblock
// ARRIVES in. This is not the demote transition — a landblock that was
// already published Near and is later retired to Far takes a different
// route (LandblockPresentationPipeline.BeginNearLayerRetirement) and is
// covered separately below.
var entity = new WorldEntity
{
Id = 1,
@ -606,6 +610,178 @@ public sealed class StreamingControllerReadinessTests
controller.IsRenderNeighborhoodResident(landblockId, 0, 0));
}
/// <summary>
/// #280 D-1 regression, the OTHER way a landblock reaches Far tier. A
/// Near&#8594;Far demote retires the Near mesh layer while
/// <c>GpuWorldState.DetachNearLayer</c> keeps the landblock loaded,
/// terrain-resident and drawn. Before the fix the retirement's
/// MeshReferences stage left <c>WantsLoaded == false</c> forever — nothing
/// re-publishes an already-loaded landblock — so the demoted block
/// satisfied NEITHER arm of the widened reveal gate and the client hung in
/// portal space until relog.
///
/// <para>
/// Driven through the real <see cref="GpuWorldState"/>, the real
/// <see cref="LandblockSpawnAdapter"/> and the real
/// <see cref="LandblockPresentationPipeline"/>, which is the production
/// route <c>StreamingController.DemoteLandblock</c> takes.
/// </para>
/// </summary>
[Fact]
public void NearToFarDemote_LeavesTheLandblockRenderReadyThroughTheRealPipeline()
{
const uint landblockId = 0x1236FFFFu;
const ulong gfxObjId = 0x01000010ul;
var meshes = new ReadinessMeshAdapter();
var state = new GpuWorldState(new LandblockSpawnAdapter(meshes));
var pipeline = new LandblockPresentationPipeline(
publishBeforeSpatialCommit: (_, _) => { },
state);
meshes.ReadyIds.Add(gfxObjId);
var entity = new WorldEntity
{
Id = 1,
ServerGuid = 0,
SourceGfxObjOrSetupId = (uint)gfxObjId,
Position = System.Numerics.Vector3.Zero,
Rotation = System.Numerics.Quaternion.Identity,
MeshRefs = [new MeshRef((uint)gfxObjId, System.Numerics.Matrix4x4.Identity)],
};
state.AddLandblock(
new LoadedLandblock(landblockId, new LandBlock(), new[] { entity }));
Assert.True(state.IsNearTier(landblockId));
Assert.True(state.IsRenderReady(landblockId));
Assert.Equal(1, meshes.ReferenceCounts[gfxObjId]);
pipeline.BeginNearLayerRetirement(landblockId);
// The demote really happened: Near layer gone, mesh reference released.
Assert.False(state.IsNearTier(landblockId));
Assert.DoesNotContain(gfxObjId, meshes.ReferenceCounts.Keys);
// ...and the landblock is still loaded and still drawn.
Assert.True(state.IsLoaded(landblockId));
// The demoted block must now be indistinguishable from one that
// arrived as Far: registered, empty desired set, render-ready.
Assert.True(state.IsRenderReady(landblockId));
}
/// <summary>
/// #280 D-1, at the gate rather than at the predicate. A full Near window
/// satisfies the tiered gate; demoting one OUTER-ring member — which is
/// what an ordinary region recenter or a mid-hold quality drop does — must
/// not make the gate permanently unsatisfiable.
/// </summary>
[Fact]
public void TieredWindow_StaysResidentAfterAnOuterRingDemote()
{
var meshes = new ReadinessMeshAdapter();
var state = new GpuWorldState(new LandblockSpawnAdapter(meshes));
var pipeline = new LandblockPresentationPipeline(
publishBeforeSpatialCommit: (_, _) => { },
state);
StreamingController controller = CreateController(state);
for (int dx = -2; dx <= 2; dx++)
for (int dy = -2; dy <= 2; dy++)
AddPublished(state, 0x12 + dx, 0x36 + dy);
Assert.True(controller.IsRenderNeighborhoodResident(0x12360022u, 1, 2));
// Chebyshev distance 2 from the destination: inside the gate's far
// window, outside its near ring — the exact band a demote can land in.
pipeline.BeginNearLayerRetirement(0x1434FFFFu);
Assert.True(state.IsLoaded(0x1434FFFFu));
Assert.False(state.IsNearTier(0x1434FFFFu));
Assert.True(controller.IsRenderNeighborhoodResident(0x12360022u, 1, 2));
}
/// <summary>
/// The same transition through the METERED retirement coordinator
/// production actually composes (<c>CreateBudgeted</c>), whose
/// MeshReferences stage is a separate call site from the legacy pipeline's.
/// </summary>
[Fact]
public void NearToFarDemote_LeavesTheLandblockRenderReadyUnderBudgetedRetirement()
{
const uint landblockId = 0x1236FFFFu;
const ulong gfxObjId = 0x01000010ul;
var meshes = new ReadinessMeshAdapter();
var state = new GpuWorldState(new LandblockSpawnAdapter(meshes));
meshes.ReadyIds.Add(gfxObjId);
var entity = new WorldEntity
{
Id = 1,
ServerGuid = 0,
SourceGfxObjOrSetupId = (uint)gfxObjId,
Position = System.Numerics.Vector3.Zero,
Rotation = System.Numerics.Quaternion.Identity,
MeshRefs = [new MeshRef((uint)gfxObjId, System.Numerics.Matrix4x4.Identity)],
};
state.AddLandblock(
new LoadedLandblock(landblockId, new LandBlock(), new[] { entity }));
LandblockRetirementCoordinator coordinator =
LandblockRetirementCoordinator.CreateBudgeted(
state,
AdvanceNoopPresentationStep,
static ticket =>
{
while (AdvanceNoopPresentationStep(ticket)
!= LandblockRetirementOperationResult.NoWork)
{
}
});
coordinator.BeginNearLayer(landblockId);
int frames = 0;
while (coordinator.PendingCount != 0 && frames++ < 64)
{
var meter = new StreamingWorkMeter(new StreamingWorkBudget(
maxUpdateTime: TimeSpan.FromSeconds(1),
maxCompletionAdmissions: 64,
maxAdoptedCpuBytes: 64 * 1024 * 1024,
maxEntityOperations: 64,
maxGpuUploadBytes: 64 * 1024 * 1024,
maxGlRetireOperations: 64,
destinationReserveFraction: 0.75f));
coordinator.Advance(meter);
meter.FinishFrame();
}
Assert.Equal(0, coordinator.PendingCount);
Assert.True(state.IsLoaded(landblockId));
Assert.False(state.IsNearTier(landblockId));
Assert.DoesNotContain(gfxObjId, meshes.ReferenceCounts.Keys);
Assert.True(state.IsRenderReady(landblockId));
}
private static LandblockRetirementOperationResult AdvanceNoopPresentationStep(
LandblockRetirementTicket ticket) =>
ticket.NextIncompleteStage switch
{
LandblockRetirementStage.EntityLighting
or LandblockRetirementStage.EntityTranslucency =>
ticket.RunEntityStep(
ticket.NextIncompleteStage,
static _ => true,
static _ => { }),
LandblockRetirementStage.PluginProjection =>
ticket.RunEntityStep(
LandblockRetirementStage.PluginProjection,
static entity => entity.ServerGuid == 0,
static _ => { }),
LandblockRetirementStage.Terrain
or LandblockRetirementStage.Physics
or LandblockRetirementStage.CellVisibility
or LandblockRetirementStage.BuildingRegistry
or LandblockRetirementStage.EnvironmentCells =>
ticket.RunOnceStep(ticket.NextIncompleteStage, static () => { }),
_ => LandblockRetirementOperationResult.NoWork,
};
private static StreamingController CreateController(GpuWorldState state)
=> new(
(_, _) => { },

View file

@ -1,3 +1,4 @@
using AcDream.App.Rendering.Wb;
using AcDream.App.Streaming;
using AcDream.Core.Physics;
using AcDream.Core.World;
@ -36,7 +37,7 @@ public sealed class WorldRevealDerivedWindowIntegrationTests
int nearRadius,
int farRadius)
{
var world = new GpuWorldState();
GpuWorldState world = CreateWorld();
var physics = new PhysicsEngine();
var transit = new RuntimeWorldTransitState();
var streaming = new RecordingReservations();
@ -94,7 +95,7 @@ public sealed class WorldRevealDerivedWindowIntegrationTests
{
const int nearRadius = 1;
const int farRadius = 3;
var world = new GpuWorldState();
GpuWorldState world = CreateWorld();
var physics = new PhysicsEngine();
var transit = new RuntimeWorldTransitState();
StreamingController controller = CreateController(
@ -137,7 +138,7 @@ public sealed class WorldRevealDerivedWindowIntegrationTests
const uint indoorCell = (uint)CenterX << 24
| (uint)CenterY << 16
| 0x0100u;
var world = new GpuWorldState();
GpuWorldState world = CreateWorld();
var physics = new PhysicsEngine();
var transit = new RuntimeWorldTransitState();
StreamingController controller = CreateController(world, 2, 6);
@ -159,6 +160,78 @@ public sealed class WorldRevealDerivedWindowIntegrationTests
Assert.Equal(0, transit.Snapshot.InvariantFailureCount);
}
/// <summary>
/// #280 D-1, end to end. The reveal gate opens on a fully published
/// window, then a Near&#8594;Far demote lands on an outer-ring member —
/// the ordinary outcome of a region recenter that does not move the world
/// origin, and of a mid-hold quality-preset drop. Before the fix, the
/// demoted member could never become <c>IsRenderReady</c> again, so the
/// coordinator never returned <c>IsReady</c> and the client stayed in
/// portal space until relog.
/// </summary>
[Fact]
public void OutdoorReveal_SurvivesAnOuterRingDemoteDuringTheHold()
{
const int nearRadius = 1;
const int farRadius = 3;
var meshes = new RecordingMeshAdapter();
var world = new GpuWorldState(new LandblockSpawnAdapter(meshes));
var physics = new PhysicsEngine();
var transit = new RuntimeWorldTransitState();
var pipeline = new LandblockPresentationPipeline(
publishBeforeSpatialCommit: (_, _) => { },
world);
StreamingController controller = CreateController(
world,
nearRadius,
farRadius);
WorldRevealCoordinator coordinator = CreateCoordinator(
transit,
controller,
physics,
streaming: null);
coordinator.BeginLogin(DestinationCell);
// Publish the WHOLE window at Near tier, entities included. That is
// what a region centred on the destination actually produces before it
// starts trimming its trailing edge.
for (int radius = 0; radius <= farRadius; radius++)
PublishRing(world, physics, radius, LandblockStreamTier.Near, withEntity: true);
Assert.True(coordinator.Evaluate(DestinationCell).IsReady);
// A single outer-ring member demotes. Chebyshev 3: inside the far
// window, outside the near ring.
uint demoted = ((uint)(CenterX + farRadius) << 24)
| ((uint)(CenterY - farRadius) << 16)
| 0xFFFFu;
pipeline.BeginNearLayerRetirement(demoted);
Assert.True(world.IsLoaded(demoted));
Assert.False(world.IsNearTier(demoted));
Assert.True(coordinator.Evaluate(DestinationCell).IsReady);
Assert.Equal(0, transit.Snapshot.InvariantFailureCount);
}
private sealed class RecordingMeshAdapter : IWbMeshAdapter
{
public Dictionary<ulong, int> ReferenceCounts { get; } = new();
public void IncrementRefCount(ulong id) =>
ReferenceCounts[id] = ReferenceCounts.GetValueOrDefault(id) + 1;
public void DecrementRefCount(ulong id)
{
int next = ReferenceCounts.GetValueOrDefault(id) - 1;
if (next <= 0)
ReferenceCounts.Remove(id);
else
ReferenceCounts[id] = next;
}
public bool IsRenderDataReady(ulong id) => true;
}
private sealed class RecordingReservations : IWorldRevealStreamingScheduler
{
public List<(long Generation, uint Cell, int Radius)> Begins { get; } = [];
@ -206,11 +279,22 @@ public sealed class WorldRevealDerivedWindowIntegrationTests
nearRadius: nearRadius,
farRadius: farRadius);
/// <summary>
/// The gate's most load-bearing predicate is
/// <c>GpuWorldState.IsRenderReady</c>, which degenerates to
/// <c>IsLoaded</c> when no spawn adapter is wired. Every fixture here owns
/// a real <see cref="LandblockSpawnAdapter"/> so the predicate is actually
/// under test.
/// </summary>
private static GpuWorldState CreateWorld() =>
new(new LandblockSpawnAdapter(new RecordingMeshAdapter()));
private static void PublishRing(
GpuWorldState world,
PhysicsEngine physics,
int radius,
LandblockStreamTier tier)
LandblockStreamTier tier,
bool withEntity = false)
{
for (int dx = -radius; dx <= radius; dx++)
for (int dy = -radius; dy <= radius; dy++)
@ -221,8 +305,27 @@ public sealed class WorldRevealDerivedWindowIntegrationTests
uint id = ((uint)(CenterX + dx) << 24)
| ((uint)(CenterY + dy) << 16)
| 0xFFFFu;
WorldEntity[] entities = withEntity
?
[
new WorldEntity
{
Id = 1,
ServerGuid = 0,
SourceGfxObjOrSetupId = 0x01000010u,
Position = System.Numerics.Vector3.Zero,
Rotation = System.Numerics.Quaternion.Identity,
MeshRefs =
[
new MeshRef(
0x01000010u,
System.Numerics.Matrix4x4.Identity),
],
},
]
: Array.Empty<WorldEntity>();
world.AddLandblock(
new LoadedLandblock(id, new LandBlock(), Array.Empty<WorldEntity>()),
new LoadedLandblock(id, new LandBlock(), entities),
tier: tier);
// The Far tier publishes terrain COLLISION as well as terrain
// render (LandblockPhysicsPublisher, reached for

View file

@ -7,6 +7,13 @@ public sealed class WorldRevealReadinessBarrierTests
private sealed class State
{
public bool RenderReady;
/// <summary>
/// Radius-aware override, so a test can distinguish "the Near
/// sub-window is published" from "the whole Far window is published".
/// </summary>
public Func<int, int, bool>? RenderReadyByRadius;
public bool SpawnCellReady;
public bool TerrainReady;
public bool CompositeReady;
@ -33,7 +40,8 @@ public sealed class WorldRevealReadinessBarrierTests
{
RenderNearRadius = nearRadius;
RenderFarRadius = farRadius;
return RenderReady;
return RenderReadyByRadius?.Invoke(nearRadius, farRadius)
?? RenderReady;
},
isSpawnCellReady: _ => SpawnCellReady,
isTerrainNeighborhoodReady: (cell, radius) =>
@ -197,6 +205,55 @@ public sealed class WorldRevealReadinessBarrierTests
Assert.Equal(0, state.Preparations);
}
/// <summary>
/// The composite warmup TRIGGER is scoped to the composite DOMAIN. #280
/// widened the reveal gate to the whole Far window but left the domain at
/// <c>NearRadius</c>; leaving the trigger on the gate would serialise every
/// composite upload behind the last outer-ring landblock and lengthen the
/// hold by the whole warmup duration for no readiness benefit.
/// </summary>
[Fact]
public void Prepare_StartsWarmupOnceTheNearSubWindowIsPublished()
{
const uint outdoorCell = 0x11340021u;
var state = new State
{
Window = new StreamingRevealWindow(4, 12),
// Published out to the Near radius only — the Far ring is still
// streaming, which is the normal state for most of the hold.
RenderReadyByRadius = (_, farRadius) => farRadius <= 4,
};
var barrier = state.Build();
barrier.Prepare(outdoorCell);
Assert.Equal(1, state.Preparations);
Assert.Equal(state.Window.NearRadius, state.PreparedRadius);
Assert.Equal(state.Window.NearRadius, state.RenderFarRadius);
// ...and the gate itself has NOT opened: it still measures the whole
// derived window, and composites are not ready yet either.
Assert.False(barrier.IsReady(outdoorCell));
Assert.Equal(state.Window.FarRadius, state.RenderFarRadius);
}
/// <summary>
/// The Near sub-window is a real precondition, not a formality: an
/// unpublished destination neighbourhood still blocks warmup.
/// </summary>
[Fact]
public void Prepare_StillWaitsWhenTheNearSubWindowIsIncomplete()
{
var state = new State
{
Window = new StreamingRevealWindow(4, 12),
RenderReadyByRadius = (_, _) => false,
};
state.Build().Prepare(0x11340021u);
Assert.Equal(0, state.Preparations);
}
[Fact]
public void ImpossibleClaim_CrossesExistingLoudRecoveryPath()
{
@ -290,4 +347,24 @@ public sealed class WorldRevealReadinessBarrierTests
new StreamingRevealWindow(4, 25),
StreamingDiagnostics.ApplyRevealRadiusOverride(window, 25));
}
/// <summary>
/// The probe's parser floor is 1, not 0. A zero override makes
/// <c>RequiredWindow</c> return far = 0 for an OUTDOOR destination, which
/// Runtime's <c>invalid-readiness-shape</c> invariant rejects on every
/// acknowledgement — i.e. the probe would hang the exact A/B route it
/// exists to measure. Reject it where it is read, not where it detonates.
/// </summary>
[Theory]
[InlineData(null, null)]
[InlineData("", null)]
[InlineData("nonsense", null)]
[InlineData("0", null)]
[InlineData("-1", null)]
[InlineData("1", 1)]
[InlineData("12", 12)]
public void RevealRadiusOverride_ParserRefusesRadiiRuntimeWouldReject(
string? raw,
int? expected) =>
Assert.Equal(expected, StreamingDiagnostics.ParseRadius(raw));
}