fix(streaming): make a demoted landblock render-ready like a published one (#280 D-1)

Both #280 review lenses returned FAIL on the same defect, and both were
right. IsRenderNeighborhoodResident's widened outer arm requires
IsRenderReady out to FarRadius, justified by "a Far-tier landblock
registers with an empty mesh set and is therefore render-ready." That held
only for a landblock that ARRIVED as Far. The second, equally first-class
way to be Far tier is a Near->Far DEMOTE:

  DemoteLandblock -> EnqueueNearLayerRetirement
    -> LandblockRetirementStage.MeshReferences
    -> GpuWorldState.ReleaseLandblockMeshReferences
    -> LandblockSpawnAdapter.OnLandblockUnloaded  => WantsLoaded = false

while DetachNearLayer deliberately keeps the landblock loaded, terrain-mesh
resident, terrain-collision resident and DRAWN. Nothing re-publishes an
already-loaded landblock, so the demoted member satisfied NEITHER arm of
the gate, permanently: wormhole tunnel plus centered "In Portal Space -
Please Wait..." forever, no recovery short of relog.

Reachable by ordinary play. Two consecutive recalls to the same landblock
with walking in between makes ChangesStreamingCenter false, so there is no
origin recenter and the region recentres through the ordinary demote diff.
Also reachable via a mid-hold quality-preset drop -- ironically the exact
scenario ReconcileDestinationReservationRadius was added to support. The
pre-#280 radius-1 gate never touched that band, because nothing inside the
Near ring can demote.

FIX SHAPE. Make the two routes genuinely equivalent rather than teaching
the predicate to tolerate the difference. ReleaseLandblockMeshReferences
becomes "reconcile the registration to the post-retirement tier": after the
release converges, if the landblock is still loaded AND still Far tier,
re-assert the empty registration -- the identical OnLandblockLoaded(lb,
empty) a PublicationKind.Far activation makes. It is empty by construction:
DetachNearLayer retains only live server projections, which the adapter's
atlas-tier filter skips. A full retirement is unaffected (DetachLandblock
clears both _loaded and _tierByLandblock), and a throwing release still
retries because the re-assert is only reached after the adapter converged.

The alternative -- "|| (IsFarTier && IsLoaded)" at the gate -- was
rejected: it fixes one caller while leaving IsRenderReady meaning two
different things, which is precisely how this defect arose. After this
change the predicate reads "drawable at its current tier" for every caller,
with no knowledge of how the landblock got there.

WHY THE TESTS MISSED IT, fixed here too:

- Proof obligation P2 was discharged against RESIDENCY (the FarRadius+2
  eviction threshold) rather than against IsRenderReady, the gate's actual
  atom. The contract now carries the correction and the restated
  obligation: no transition may REVOKE IsRenderReady from a landblock that
  stays inside FarRadius.
- WorldRevealDerivedWindowIntegrationTests advertised itself as end-to-end
  against the real GpuWorldState but constructed it with no spawn adapter,
  so its IsRenderReady degenerated to IsLoaded via the "?? true". The
  single most load-bearing predicate in the change was stubbed out by a
  null in the test named after it -- the same shape as C5b's D3 and #276's
  three settler tests. Every fixture in that file now owns a real
  LandblockSpawnAdapter.
- The P1 test's comment described its subject as "a Near-shaped completion
  the streaming window has since DEMOTED to Far". It is not; it is a fresh
  PublishAsFar, the case that does hold. Corrected, since a future reader
  would have taken it as demote coverage.

Four new regression tests, all driving the real GpuWorldState +
LandblockSpawnAdapter + LandblockPresentationPipeline through an actual
demote, and all sabotage-verified in both directions (fail with the
production change reverted, pass with it):

  NearToFarDemote_LeavesTheLandblockRenderReadyThroughTheRealPipeline
  NearToFarDemote_LeavesTheLandblockRenderReadyUnderBudgetedRetirement
  TieredWindow_StaysResidentAfterAnOuterRingDemote
  OutdoorReveal_SurvivesAnOuterRingDemoteDuringTheHold

The budgeted variant exists because production composes
LandblockRetirementCoordinator.CreateBudgeted, whose MeshReferences stage
is a separate call site from the legacy pipeline's.

SECONDARY, same commit:

- R-1: ACDREAM_PROBE_REVEAL_RADIUS=0 was parser-accepted and
  Runtime-rejected -- it yields far = 0 for an outdoor destination, which
  fails invalid-readiness-shape on every acknowledgement, hanging the very
  A/B route the probe exists to measure. Parser floor raised to 1, with a
  7-case table test.
- R-2: the composite-warmup TRIGGER had silently moved onto the far
  window's critical path. Pre-#280 the gate and the composite domain were
  the same radius-1 square; #280 widened the gate without widening the
  domain, so every composite upload serialised behind the last outer-ring
  landblock for no readiness benefit. Warmup now starts once the NEAR
  sub-window is published -- trigger scope == domain scope, as before. The
  reveal gate is untouched: Evaluate still requires the full window AND
  composite readiness.
- AP-150 filed: acdream's RetailWaitCueDelay = 5 s arming is NOT retail's
  trigger, and #280's commit message got this wrong on both clauses. Retail
  emits the notice unconditionally per tunnel rotation segment, in the else
  arm of the segment-expiry test at 0x004D6FCD; segment duration is
  RandDouble(0.6, 1.8) s, byte-decoded at 0x004D6FE6. The 5.0 constant at
  VA 0x007991B0 is CellManager::CheckPrefetchStatus's prefetch RETRY
  cadence and has nothing to do with the cue. acdream's own 0.6/1.8 segment
  constants already match retail exactly; only the arming is wrong.
  Adopting retail's unconditional emit is filed as #329 rather than folded
  in here -- it is a user-visible presentation change and wants the user's
  eyes.
- AP-151 filed: the gate is materially STRICTER than retail on the
  mesh-build/GPU-upload axis. Retail's LScape::PreFetchCells blocks on DAT
  RESIDENCY only -- no geometry construction, no upload; that work is lazy
  at draw. acdream requires a DAT read, terrain mesh build, render-thread
  upload, spatial commit, collision admission and spawn-adapter activation
  per member of a 625-member window, metered at MaxCompletionsPerFrame.
  Nothing bounds the hold. This is the OPPOSITE asymmetry from AP-149; both
  are live at once, on different axes.
- AD-2's amendment stated the false Far-tier readiness assumption verbatim;
  corrected, along with the same error in
  claude-memory/reference_two_tier_streaming.md, which now carries an
  explicit DO-NOT-RETRY on the special-case-the-predicate shape.
- AP-115 scope-noted (it covers the cue's presentation, not its arming).
- #326's SmartBox::set_mid_radius citation corrected: the entry is
  0x00453180; 0x004531D0 is the mid-function re-arm branch.

Blast radius: GpuWorldState, LandblockSpawnAdapter,
WorldRevealReadinessBarrier and StreamingDiagnostics are all App-internal;
AcDream.Headless and AcDream.Runtime reference none of them outside
comments. Headless tests run green as part of the gate below, per C5b's
lesson about surveys that skip the no-window host.

Gates: Release build 0 errors, 18 pre-existing xUnit analyzer warnings.
Complete suite "dotnet test AcDream.slnx -c Release -m:1" with
ACDREAM_PAK_PATH set: 11,192 passed / 4 skipped / 0 failed, from a clean
rebuild (a prior session's deleted probe file had been compiled into a
stale test DLL). Baseline at fafc0b65 was 11,179 / 4 / 0; the +13 delta
reconciles exactly to this commit's additions -- 3 readiness tests, 1
integration test, 7 parser table cases, 2 warmup-trigger tests. None of the
known flakes #302/#308/#321 surfaced, and none is conflated with the
finding above.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-06 07:27:28 +02:00
parent fafc0b65d9
commit 73cdb95c7b
13 changed files with 1456 additions and 38 deletions

View file

@ -565,9 +565,13 @@ public sealed class StreamingControllerReadinessTests
publishBeforeSpatialCommit: (_, _) => { },
state);
// A Near-shaped completion that the streaming window has since demoted
// to Far: entities and physics payload are stripped by PublishAsFar,
// which is exactly the shape an outer-ring landblock is published in.
// A Near-shaped completion the streaming window has DOWNGRADED before
// publication: entities and physics payload are stripped by
// PublishAsFar, which is exactly the shape an outer-ring landblock
// ARRIVES in. This is not the demote transition — a landblock that was
// already published Near and is later retired to Far takes a different
// route (LandblockPresentationPipeline.BeginNearLayerRetirement) and is
// covered separately below.
var entity = new WorldEntity
{
Id = 1,
@ -606,6 +610,178 @@ public sealed class StreamingControllerReadinessTests
controller.IsRenderNeighborhoodResident(landblockId, 0, 0));
}
/// <summary>
/// #280 D-1 regression, the OTHER way a landblock reaches Far tier. A
/// Near&#8594;Far demote retires the Near mesh layer while
/// <c>GpuWorldState.DetachNearLayer</c> keeps the landblock loaded,
/// terrain-resident and drawn. Before the fix the retirement's
/// MeshReferences stage left <c>WantsLoaded == false</c> forever — nothing
/// re-publishes an already-loaded landblock — so the demoted block
/// satisfied NEITHER arm of the widened reveal gate and the client hung in
/// portal space until relog.
///
/// <para>
/// Driven through the real <see cref="GpuWorldState"/>, the real
/// <see cref="LandblockSpawnAdapter"/> and the real
/// <see cref="LandblockPresentationPipeline"/>, which is the production
/// route <c>StreamingController.DemoteLandblock</c> takes.
/// </para>
/// </summary>
[Fact]
public void NearToFarDemote_LeavesTheLandblockRenderReadyThroughTheRealPipeline()
{
const uint landblockId = 0x1236FFFFu;
const ulong gfxObjId = 0x01000010ul;
var meshes = new ReadinessMeshAdapter();
var state = new GpuWorldState(new LandblockSpawnAdapter(meshes));
var pipeline = new LandblockPresentationPipeline(
publishBeforeSpatialCommit: (_, _) => { },
state);
meshes.ReadyIds.Add(gfxObjId);
var entity = new WorldEntity
{
Id = 1,
ServerGuid = 0,
SourceGfxObjOrSetupId = (uint)gfxObjId,
Position = System.Numerics.Vector3.Zero,
Rotation = System.Numerics.Quaternion.Identity,
MeshRefs = [new MeshRef((uint)gfxObjId, System.Numerics.Matrix4x4.Identity)],
};
state.AddLandblock(
new LoadedLandblock(landblockId, new LandBlock(), new[] { entity }));
Assert.True(state.IsNearTier(landblockId));
Assert.True(state.IsRenderReady(landblockId));
Assert.Equal(1, meshes.ReferenceCounts[gfxObjId]);
pipeline.BeginNearLayerRetirement(landblockId);
// The demote really happened: Near layer gone, mesh reference released.
Assert.False(state.IsNearTier(landblockId));
Assert.DoesNotContain(gfxObjId, meshes.ReferenceCounts.Keys);
// ...and the landblock is still loaded and still drawn.
Assert.True(state.IsLoaded(landblockId));
// The demoted block must now be indistinguishable from one that
// arrived as Far: registered, empty desired set, render-ready.
Assert.True(state.IsRenderReady(landblockId));
}
/// <summary>
/// #280 D-1, at the gate rather than at the predicate. A full Near window
/// satisfies the tiered gate; demoting one OUTER-ring member — which is
/// what an ordinary region recenter or a mid-hold quality drop does — must
/// not make the gate permanently unsatisfiable.
/// </summary>
[Fact]
public void TieredWindow_StaysResidentAfterAnOuterRingDemote()
{
var meshes = new ReadinessMeshAdapter();
var state = new GpuWorldState(new LandblockSpawnAdapter(meshes));
var pipeline = new LandblockPresentationPipeline(
publishBeforeSpatialCommit: (_, _) => { },
state);
StreamingController controller = CreateController(state);
for (int dx = -2; dx <= 2; dx++)
for (int dy = -2; dy <= 2; dy++)
AddPublished(state, 0x12 + dx, 0x36 + dy);
Assert.True(controller.IsRenderNeighborhoodResident(0x12360022u, 1, 2));
// Chebyshev distance 2 from the destination: inside the gate's far
// window, outside its near ring — the exact band a demote can land in.
pipeline.BeginNearLayerRetirement(0x1434FFFFu);
Assert.True(state.IsLoaded(0x1434FFFFu));
Assert.False(state.IsNearTier(0x1434FFFFu));
Assert.True(controller.IsRenderNeighborhoodResident(0x12360022u, 1, 2));
}
/// <summary>
/// The same transition through the METERED retirement coordinator
/// production actually composes (<c>CreateBudgeted</c>), whose
/// MeshReferences stage is a separate call site from the legacy pipeline's.
/// </summary>
[Fact]
public void NearToFarDemote_LeavesTheLandblockRenderReadyUnderBudgetedRetirement()
{
const uint landblockId = 0x1236FFFFu;
const ulong gfxObjId = 0x01000010ul;
var meshes = new ReadinessMeshAdapter();
var state = new GpuWorldState(new LandblockSpawnAdapter(meshes));
meshes.ReadyIds.Add(gfxObjId);
var entity = new WorldEntity
{
Id = 1,
ServerGuid = 0,
SourceGfxObjOrSetupId = (uint)gfxObjId,
Position = System.Numerics.Vector3.Zero,
Rotation = System.Numerics.Quaternion.Identity,
MeshRefs = [new MeshRef((uint)gfxObjId, System.Numerics.Matrix4x4.Identity)],
};
state.AddLandblock(
new LoadedLandblock(landblockId, new LandBlock(), new[] { entity }));
LandblockRetirementCoordinator coordinator =
LandblockRetirementCoordinator.CreateBudgeted(
state,
AdvanceNoopPresentationStep,
static ticket =>
{
while (AdvanceNoopPresentationStep(ticket)
!= LandblockRetirementOperationResult.NoWork)
{
}
});
coordinator.BeginNearLayer(landblockId);
int frames = 0;
while (coordinator.PendingCount != 0 && frames++ < 64)
{
var meter = new StreamingWorkMeter(new StreamingWorkBudget(
maxUpdateTime: TimeSpan.FromSeconds(1),
maxCompletionAdmissions: 64,
maxAdoptedCpuBytes: 64 * 1024 * 1024,
maxEntityOperations: 64,
maxGpuUploadBytes: 64 * 1024 * 1024,
maxGlRetireOperations: 64,
destinationReserveFraction: 0.75f));
coordinator.Advance(meter);
meter.FinishFrame();
}
Assert.Equal(0, coordinator.PendingCount);
Assert.True(state.IsLoaded(landblockId));
Assert.False(state.IsNearTier(landblockId));
Assert.DoesNotContain(gfxObjId, meshes.ReferenceCounts.Keys);
Assert.True(state.IsRenderReady(landblockId));
}
private static LandblockRetirementOperationResult AdvanceNoopPresentationStep(
LandblockRetirementTicket ticket) =>
ticket.NextIncompleteStage switch
{
LandblockRetirementStage.EntityLighting
or LandblockRetirementStage.EntityTranslucency =>
ticket.RunEntityStep(
ticket.NextIncompleteStage,
static _ => true,
static _ => { }),
LandblockRetirementStage.PluginProjection =>
ticket.RunEntityStep(
LandblockRetirementStage.PluginProjection,
static entity => entity.ServerGuid == 0,
static _ => { }),
LandblockRetirementStage.Terrain
or LandblockRetirementStage.Physics
or LandblockRetirementStage.CellVisibility
or LandblockRetirementStage.BuildingRegistry
or LandblockRetirementStage.EnvironmentCells =>
ticket.RunOnceStep(ticket.NextIncompleteStage, static () => { }),
_ => LandblockRetirementOperationResult.NoWork,
};
private static StreamingController CreateController(GpuWorldState state)
=> new(
(_, _) => { },