feat(session): the in-world logoff — LogOut animation, reverse wormhole, live return to character select

Retires AD-74 (Exit to Character Selection 'behaves as Exit Game') and
files AD-110 (the composed handoff edge) — register rows in this commit.

Retail derivation (named decomp):
- gmGamePlayUI::UseTime @0x004EA3A0: confirmed Yes drains into
  CPlayerSystem::LogOffCharacter(0) when grounded (transient_state &
  CONTACT); the grounded three-way branch now also covers the
  indicator-bar end-session control (it was Options-only).
- CPlayerSystem::LogOffCharacter @0x00563520: SaveToServer FIRST (the
  existing pre-logoff flush hook), then RequestLogOff @0x00562DD0:
  'Logging off...' chat (type 0), 0xF653 via Proto_UI::LogOffCharacter
  @0x00546A20, logOffRequestTime = now + 3.0 (+20.0 when
  IsPlayerKiller @0x0058C910 — PWD bits 0x20|0x2000000), and
  CommandInterpreter::HandleLogOff @0x006B3330 -> Disable.
- The log-off ANIMATION is server-driven: ACE broadcasts
  MotionCommand.LogOut (0x1000011E, Player.cs:596 SendMotionAsCommands)
  and it plays on the local player through the existing inbound
  unpack_movement funnel during the 3 s hold — retail plays nothing
  locally; Disable() is the whole client-side effect.
- gmSmartBoxUI::UseTime @0x004D6E64: hold elapsed ->
  BeginTeleportAnimation(TAS_WORLD_FADE_OUT) @0x004D6E83 (enter cue
  @0x004D638E, unconditional) -> TunnelFadeIn -> Tunnel. The tunnel
  plays the SAME forward 40 fps animation; nothing renders backwards,
  and NO exit cue ever fires on logout (the char-select swap preempts
  the TunnelContinue/FadeOut tail).
- Inbound 0xF653 echo (dispatch case 3 @0x0055C963) ->
  ExecuteLogOff @0x0055D780: world teardown with the LOGON CONNECTION
  KEPT (ExitWorldDisconnect @0x00541E00 removes every connection
  except logonRecID_ — one connection against ACE) and
  Proto_UI::SetEventCounter(0) @0x00541E79; the fresh CharacterList in
  the same batch re-shows character management (gmGamePlayUI::Update
  @0x004E9CD0 -> QueueUIMode(0x1000000a)). ACE mirrors it:
  SendFinalLogOffMessages (Session.cs:249) sends 0xF653 + CharacterList
  + ServerName >=6 s after the request and leaves the session
  AuthConnected — a second EnterWorld needs no re-handshake.

Implementation:
- RuntimeWorldTransitState: the canonical logout lifecycle
  (Requested/PresentationActive/Confirmed, retail 3 s/+20 s holds,
  cancel/reset/ownership convergence).
- WorldSession: RequestCharacterLogOff (non-blocking 0xF653),
  IsCharacterLogOffConfirmed, ReturnToCharacterSelect (InWorld ->
  InCharacterSelect + game-action sequence reset; transport untouched).
- LiveSessionController: BeginCharacterLogOff (flush-first request) and
  CompleteCharacterLogOff — the return-to-selection transaction
  (ReconnectCore minus the transport swap: retire the world
  generation's routes, host reset, state flip, fresh generation
  re-bind, roster re-applied from the pushed CharacterList; failures
  degrade to the full StopCore teardown).
- RuntimeLocalPlayerMovementState.DisableCommandInterpreter +
  DispatcherMovementInputSource gate: retail's Disable() — held keys
  produce no movement while the server LogOut motion plays; cleared by
  the generation reset.
- LocalPlayerTeleportController: the logout pump as the third arm of
  the one wormhole machine (request/hold/wormhole/confirmed handoff;
  teleport starts refused during logout; the handoff runs the session
  transaction whose world reset retires the tunnel as the fresh
  selection state re-shows the character screen).
- UI: both end-session surfaces share the retail three-way grounded
  gate and now run the REAL flow; Options' Exit Game keeps the app
  exit (window close -> the existing graceful-shutdown logoff).

Tests: +5 transit lifecycle, +4 session transaction, +7 logout pump.
Runtime 1756/0 (baseline 1747), App live-DAT 5523/3 (baseline 5512/3
+ 11 this round), Core.Net 1004/0, full solution green (0 failures).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-17 14:02:40 +02:00
parent 2bc81480d4
commit d233f81dce
17 changed files with 1399 additions and 37 deletions

View file

@ -1050,6 +1050,104 @@ public sealed class RuntimeWorldTransitStateTests
state.ResetSession();
}
// ── Logout round (2026-08-17): the character-logoff lifecycle —
// retail CPlayerSystem::RequestLogOff @ 0x00562DD0 (3 s hold, +20 PK),
// gmSmartBoxUI::UseTime @ 0x004D6E64 (hold-elapsed presentation begin),
// ExecuteLogOff @ 0x0055D780 (the 0xF653 echo), and the char-select
// handoff. ────────────────────────────────────────────────────────────
[Fact]
public void LogoutLifecycle_RequestHoldPresentationConfirmComplete()
{
var state = new RuntimeWorldTransitState();
Assert.Equal(RuntimeLogoutStage.None, state.LogoutStage);
Assert.True(state.TryBeginLogoutRequest(isPlayerKiller: false));
Assert.Equal(RuntimeLogoutStage.Requested, state.LogoutStage);
Assert.Equal(1, state.CaptureOwnership().ActiveLogoutCount);
Assert.False(state.CaptureOwnership().IsSessionIdle);
// A second request while one is in flight refuses.
Assert.False(state.TryBeginLogoutRequest(isPlayerKiller: false));
// The retail 3.0 s hold: not elapsed at 2.9, elapsed at 3.0+.
Assert.False(state.AdvanceLogoutHold(2.9d));
Assert.Equal(RuntimeLogoutStage.Requested, state.LogoutStage);
Assert.True(state.AdvanceLogoutHold(0.2d));
Assert.Equal(
RuntimeLogoutStage.PresentationActive,
state.LogoutStage);
// The begin edge fires exactly once.
Assert.False(state.AdvanceLogoutHold(1.0d));
Assert.True(state.AcknowledgeLogoutConfirmed());
Assert.Equal(RuntimeLogoutStage.Confirmed, state.LogoutStage);
Assert.False(state.AcknowledgeLogoutConfirmed());
Assert.True(state.CompleteLogout());
Assert.Equal(RuntimeLogoutStage.None, state.LogoutStage);
Assert.False(state.CompleteLogout());
Assert.True(state.CaptureOwnership().IsSessionIdle);
}
[Fact]
public void LogoutHold_PlayerKillerAddsTwentySeconds()
{
var state = new RuntimeWorldTransitState();
Assert.True(state.TryBeginLogoutRequest(isPlayerKiller: true));
// 3 s is not enough for a PK (RequestLogOff @ 0x00562E67: +20.0).
Assert.False(state.AdvanceLogoutHold(3.5d));
Assert.False(state.AdvanceLogoutHold(19.0d));
Assert.True(state.AdvanceLogoutHold(0.6d));
Assert.Equal(
RuntimeLogoutStage.PresentationActive,
state.LogoutStage);
}
[Fact]
public void LogoutConfirmation_LegalFromTheRequestHold()
{
// ACE's >= 6 s confirmation floor makes this unreachable live, but
// the machine is total: a confirmation during the hold cancels the
// pending wormhole (retail ExecuteLogOff clears logOffRequested).
var state = new RuntimeWorldTransitState();
Assert.True(state.TryBeginLogoutRequest(isPlayerKiller: false));
Assert.True(state.AcknowledgeLogoutConfirmed());
Assert.Equal(RuntimeLogoutStage.Confirmed, state.LogoutStage);
// The hold no longer advances a confirmed lifecycle.
Assert.False(state.AdvanceLogoutHold(10.0d));
Assert.True(state.CompleteLogout());
}
[Fact]
public void LogoutRequest_RefusedDuringTeleportAndCancelRollsBack()
{
var state = new RuntimeWorldTransitState();
_ = BeginPortal(state, OutdoorCell, sequence: 3);
Assert.False(state.TryBeginLogoutRequest(isPlayerKiller: false));
var idle = new RuntimeWorldTransitState();
Assert.True(idle.TryBeginLogoutRequest(isPlayerKiller: false));
Assert.True(idle.CancelLogoutRequest());
Assert.Equal(RuntimeLogoutStage.None, idle.LogoutStage);
Assert.True(idle.CaptureOwnership().IsSessionIdle);
// Cancel is only legal from Requested.
Assert.False(idle.CancelLogoutRequest());
}
[Fact]
public void LogoutLifecycle_ClearsOnSessionReset()
{
var state = new RuntimeWorldTransitState();
Assert.True(state.TryBeginLogoutRequest(isPlayerKiller: false));
state.ResetSession();
Assert.Equal(RuntimeLogoutStage.None, state.LogoutStage);
Assert.True(state.CaptureOwnership().IsSessionIdle);
// A fresh session can log out again.
Assert.True(state.TryBeginLogoutRequest(isPlayerKiller: false));
}
private static long BeginPortal(
RuntimeWorldTransitState state,
uint cell,