feat(physics): C4 route 2 — ForcePosition through the canonical placement
A local-player ForcePosition had TWO independent writers for one accepted
packet: LocalForcePositionTransaction snapped the physics body
(PlayerMovementController.BlipPosition, a raw SnapToCell with no collision
resolve), while LiveEntityNetworkUpdateController's generic tail separately
wrote position/cell/rotation to the render WorldEntity from the raw wire and
rebucketed it. Two stores, one packet — the divergence class 670f307c fixed on
the remote path. The outbound AutonomousPosition ack also fired BEFORE any
canonical commit existed: we told ACE "got it, I'm here" before deciding where
"here" was, and the trailing isCurrent() could only suppress the continuation,
never recall the packet.
RuntimeAcceptedPositionDriveController is now the one Runtime-owned seam. Both
hosts call the identical TryExecuteAcceptedLocalPosition; App and headless
project the committed result through the existing placement projection sink
(LiveEntityRuntime.TryApplyRuntimePlacementPlace already performed the same
four writes, from committed state rather than a wire guess).
Retail: SmartBox::HandleReceivedPosition @0x00453FD0's FORCE_POSITION branch is
get_heading -> Frame::set_heading -> SmartBox::BlipPlayer @0x00453940 -> stamp
POSITION_TS -> SendPositionEvent @0x00454091 -> return @0x0045409D. BlipPlayer
is CPhysicsObj::SetPositionSimple @0x005162B0 with flags 0x1012
(Teleport|Slide|SendPositionEvent) — a real collision-resolving SetPosition,
not a snap. The pinned classifier already encoded this exactly.
Named behaviour changes:
* The ack is now an OUTPUT of the committed route, fired strictly after the
canonical commit and exactly once per accepted force packet.
* The ForcePosition route no longer re-arms the constraint leash. The force
branch returns at 0x0045409D, ahead of all three ConstrainTo sites
(0x00454272, 0x0045418A, 0x004541EC); the old re-arm cited retail's "Player,
normal" branch, which BlipPlayer is not on. The teleport, CommitPreparedPosition
and first-entry callers legitimately still constrain and are untouched.
* A force correction that terminates WITHOUT committing still sends its
position event and is not retried — retail's BlipPlayer discards
SetPositionSimple's SetPositionError return and acks unconditionally.
A single _pending funnel owns the in-flight placement, deciding on the token's
PositionAuthorityVersion against the record's: equal -> clear; advanced with the
newest accepted event still a force -> re-issue, re-classified; advanced to an
ordinary Apply -> clear, since newer server truth owns that pose. This closes a
double-apply/double-ack and a silently-dropped correction that two earlier
iterations of this slice each introduced.
AD-62 records the residual: a ForcePosition our async collision publication
cannot carry to a committed placement is not re-applied. Retail has no park —
its world is fully resident and its placement synchronous — so the state is
unreachable there. AP-131 is NOT retired; its legacy Position caller is route 4.
Deleted: LocalForcePositionTransaction, PlayerMovementController.BlipPosition,
HeadlessSessionWorldProjection.BlipLocalPlayer.
Gates: complete Release solution 10,858 passed / 4 skipped / 0 failed (baseline
10,844/4/0). Two independent Opus reviews (retail-conformance and
architecture/adversarial) PASS on the final diff after three FAIL rounds; every
intermediate state was fully green, so the suite caught none of the four real
defects. Connected acceptance is NOT run: nothing a user can do makes ACE emit
a ForcePosition without retail's @pklite, which acdream does not implement — see
docs/research/2026-08-03-c4-route-2-visual-gate.md.
Known gap, recorded not claimed: the plan's acceptance item 2 is unmet. The App
double-write check is a source pin, and "the committed projection moves the
render entity" is uncovered at any layer (#292). Filed alongside: #286-#291,
#293-#296.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
22a5c95400
commit
9966b53174
25 changed files with 4292 additions and 195 deletions
|
|
@ -79,7 +79,16 @@ public readonly record struct RuntimeEntityObjectOwnershipSnapshot(
|
|||
/// Previously outside every ledger; gated by <see cref="IsConverged"/>
|
||||
/// like the conductor counts it pumps.
|
||||
/// </summary>
|
||||
int FirstEntryDrivePendingCount = 0)
|
||||
int FirstEntryDrivePendingCount = 0,
|
||||
/// <summary>
|
||||
/// C4 route 2: outstanding host <c>RuntimeAcceptedPositionDriveController</c>
|
||||
/// pending operations (a not-yet-committed or not-yet-acknowledged
|
||||
/// ForcePosition on the local player), summed over every drive
|
||||
/// registered against this lifetime via
|
||||
/// <see cref="RuntimeEntityObjectLifetime.RegisterAcceptedPositionDriveOwnership"/>.
|
||||
/// Gated by <see cref="IsConverged"/> — a leaked pending ack cannot hide.
|
||||
/// </summary>
|
||||
int AcceptedPositionDrivePendingCount = 0)
|
||||
{
|
||||
public bool IsConverged =>
|
||||
IsDisposed
|
||||
|
|
@ -104,6 +113,7 @@ public readonly record struct RuntimeEntityObjectOwnershipSnapshot(
|
|||
&& LocalPlayerFirstEntryActiveCount == 0
|
||||
&& RemoteFirstEntryActiveCount == 0
|
||||
&& FirstEntryDrivePendingCount == 0
|
||||
&& AcceptedPositionDrivePendingCount == 0
|
||||
&& StreamSubscriberCount == 0
|
||||
&& PlacementStreamSubscriberCount == 0
|
||||
&& PendingDispatchCount == 0
|
||||
|
|
@ -151,6 +161,8 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
|
|||
private Action<RuntimeEntityRecord>? _initialResidenceBegan;
|
||||
/// <summary>C3c-R1 review F5: see <see cref="RegisterFirstEntryDriveOwnership"/>.</summary>
|
||||
private readonly List<Func<int>> _firstEntryDriveOwnership = [];
|
||||
/// <summary>C4 route 2: see <see cref="RegisterAcceptedPositionDriveOwnership"/>.</summary>
|
||||
private readonly List<Func<int>> _acceptedPositionDriveOwnership = [];
|
||||
|
||||
public RuntimeEntityObjectLifetime(
|
||||
uint firstLocalEntityId = RuntimeEntityDirectory.FirstLocalEntityId,
|
||||
|
|
@ -452,7 +464,8 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
|
|||
InitialCreateExecution.PendingCompletionReceiptCount,
|
||||
LocalPlayerFirstEntry.CaptureOwnership().ActiveCount,
|
||||
RemoteFirstEntry.CaptureOwnership().ActiveCount,
|
||||
CaptureFirstEntryDrivePendingCount());
|
||||
CaptureFirstEntryDrivePendingCount(),
|
||||
CaptureAcceptedPositionDrivePendingCount());
|
||||
}
|
||||
|
||||
private int CaptureFirstEntryDrivePendingCount()
|
||||
|
|
@ -463,6 +476,14 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
|
|||
return total;
|
||||
}
|
||||
|
||||
private int CaptureAcceptedPositionDrivePendingCount()
|
||||
{
|
||||
int total = 0;
|
||||
for (int i = 0; i < _acceptedPositionDriveOwnership.Count; i++)
|
||||
total = checked(total + _acceptedPositionDriveOwnership[i]());
|
||||
return total;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// C3c-R1 review F5: registers one host first-entry drive controller's
|
||||
/// pending-count provider into this lifetime's ownership snapshot, so
|
||||
|
|
@ -478,6 +499,21 @@ public sealed class RuntimeEntityObjectLifetime : IDisposable
|
|||
_firstEntryDriveOwnership.Add(pendingCount);
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// C4 route 2: registers one host <c>RuntimeAcceptedPositionDriveController</c>'s
|
||||
/// pending-count provider into this lifetime's ownership snapshot,
|
||||
/// mirroring <see cref="RegisterFirstEntryDriveOwnership"/> — a leaked
|
||||
/// pending ForcePosition ack must not sit outside every ledger. The
|
||||
/// drive controller registers itself at construction; multiple
|
||||
/// registrations sum (one per host route sharing this lifetime).
|
||||
/// </summary>
|
||||
public void RegisterAcceptedPositionDriveOwnership(Func<int> pendingCount)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(pendingCount);
|
||||
EnsureNotDisposed();
|
||||
_acceptedPositionDriveOwnership.Add(pendingCount);
|
||||
}
|
||||
|
||||
public void BindEventContext(
|
||||
Func<RuntimeGenerationToken> generation,
|
||||
Func<ulong> frameNumber)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue