docs(overhaul): contract c5 owner guard fix

This commit is contained in:
Erik 2026-09-05 05:08:31 +02:00
parent bf53e2ad6e
commit e625dc4e6b

View file

@ -3149,3 +3149,50 @@ checks tree/ACE/client state, and performs one graphical smoke route over an
outdoor town, Facility stairs, and one interior/portal transition. It must
exit gracefully, leave no client, emit no deleted probe prefix, and record
exact PNG paths. Visual status remains provisional until the owner inspects it.
## 34. S5-c5 fix round 1 contract — static owner fields must not evade the final graph guard
Production/gate-honesty review pass 2/10 found one MINOR test-only defect and
no production behavior finding. `WalkFrameOwners_AreUnique` builds its shared
field flags from `BindingFlags.Instance` but omits `BindingFlags.Static`.
Consequently, a static `WalkPView` field outside `RetailFrameWalk`, or a static
`RetailFrameWalk` field outside `RetailPViewRenderer`, can create a second
owner while the §33.5 guard remains green. The implementation itself contains
no such field; this is a non-vacuity hole in the permanent architecture proof.
### 34.1 Bounded correction
Edit only
`tests/AcDream.App.Tests/Rendering/Walk/WalkRendererArchitectureGuardTests.cs`:
- include both `BindingFlags.Instance` and `BindingFlags.Static` in the field
scan shared by the `WalkPView` and `RetailFrameWalk` owner assertions;
- keep `DeclaredOnly`, public/non-public coverage, the exact two-PView count,
the exact `RetailFrameWalk` declaring owner, and `Assert.Single` unchanged;
and
- do not replace the compiled reflection proof with a source-word count or a
narrower naming convention.
No production, renderer, walk, queue, material, shader, prepared-content,
membership, launch-option, architecture, or register edit is authorized. This
test-only correction creates no retail deviation, so it creates no register
row.
### 34.2 Discriminating proof and return
Run both mutations separately and restore each exactly:
1. add a static `WalkPView` field to any App type other than
`RetailFrameWalk`; `WalkFrameOwners_AreUnique` must first fail on the wrong
declaring owner and/or count; and
2. add a static `RetailFrameWalk` field to any App type other than
`RetailPViewRenderer`; the same test must first fail on the second owner.
Return one fix commit with clean `git diff --check`, a zero-warning Release
solution build, the architecture guard plus the complete §33 focused set, and
fresh clean-tip hermetic and canonical InstalledDat evidence (the latter with
`ACDREAM_RUN_INSTALLED_DAT_TESTS=1` and the explicit installed-DAT directory).
The InstalledDat nonpassing identities must remain the accepted nine failures
plus one look-in skip. Production/gate-honesty review then resumes as pass
3/10; the already-passed retail/deletion lens is not repeated because this
round changes no production or retail claim.