acdream/docs/reviews/2026-08-18-r3-test-truth-ledger.md
2026-08-18 17:02:15 +02:00

94 KiB
Raw Blame History

R3 test-truth and cleanup ledger

Status: complete

Branch: codex/release-stabilization

Starting commit: 8e884679e0b6ce3dc1c84004ba9c5c8e3ff91d2a

This is the cross-session authority for R3. The historical all-file audit remains in test-quality-audit.md; this ledger reconciles that baseline against current source and records each cleanup decision before code is removed. R3 does not change product behavior.

Current executable baseline

The clean R2 gate at implementation commit c38f6b88 built all 44 maintained projects with zero warnings and ran every default test assembly once:

  • 12 test assemblies;
  • 14,742 passed;
  • 77 reported skipped;
  • 0 failed; and
  • one redundant Core theory row discarded by xUnit discovery before the totals.

The six-case reduction from the earlier 14,748-pass headline is understood: seven launcher editor-focus theory rows were consolidated into one fact that still executes all seven variants in a single Avalonia application session.

Fresh reproducible syntax inventory

tools/audit-test-inventory.ps1 now regenerates the complete attributed-method manifest from tracked C# test sources with Roslyn:

pwsh ./tools/audit-test-inventory.ps1

The generated JSON lives under ignored artifacts/test-audit/; it is not a second 6.8 MB checked-in source of truth. The script and this reviewed ledger are durable, while paths and line numbers regenerate after every batch. The final closeout inventory at implementation commit 14d371a0 reports:

Syntax signal Current count
Tracked/parsed C# test files 1,254 / 1,254
Attributed test methods (not expanded theory cases) 11,414
Exact duplicate-data rows 0
Reviewed body-equivalent groups / methods 11 / 27
Methods containing at least one empty return; 138
Empty-return sites 143
Direct / same-file-helper prerequisite-return candidates 2 / 1
Mechanical output-only candidates 2
Constant-truth assertion methods / sites 0 / 0
Reviewed syntactic self-comparison methods / sites 4 / 5
Reviewed diagnostic methods 82
Methods directly using Thread.Sleep / Task.Delay 15 / 14
Cancellable-infinite-only / elapsed-time methods 5 / 24
Methods directly reading environment variables 47
Methods directly / in total reading .cs source text 21 / 22

The three remaining prerequisite-return candidates are all reviewed branch false positives: the two Windows/Linux factory assertions and the launcher's cross-platform directory-link helper. Every true prerequisite return found by the inventory now fails explicitly inside its selected non-hermetic lane. The remaining 143 empty returns are behavioral control flow, callback exits, or the three platform branches; they are not missing-prerequisite passes.

The output-only classifier follows same-file helper calls, so an assertion used only while constructing a probe can prevent an otherwise diagnostic method from appearing in its two-candidate result. The reviewed Purpose=Diagnostic set is therefore the authority: Batch C's 51 methods, six artifact/report writers from Batch L, and 25 fixture-sanity-only investigations from Batch R, for 82 methods and 103 discovered cases (35 App, 68 Core). Their investigative output and historical rationale remain executable outside the release total.

The five syntactic self-comparisons are reviewed, not vacuous: two call a hash twice to assert determinism, one reads the singleton twice, and two read the same Runtime owner's properties twice to assert stable identity. The inventory keeps these candidates visible separately from the now-zero constant-truth assertions.

Exact 77-skip reconciliation

The latest clean-gate TRX files account for every reported skip:

Classification Count Current source R3 decision
Installed retail DAT lane 73 InstalledDatFactAttribute across nine files Retain the contracts, replace the campaign-specific shared reason with prerequisite- and suite-specific identity, and report this lane separately. Batch B assigns all nine classes to Lane=InstalledDat.
Manual fixture generation 2 ChatLayoutFixtureGenerator.GenerateChatFixture; RadarLayoutFixtureGenerator.GenerateRadarFixture Delete both redundant generators: the existing comprehensive RetailLayoutFixtureGenerator already owns their chat and radar outputs. Assign that generator to the explicit Manual lane.
Empty future scaffold 1 PvsConformanceTests.Pvs_CottageInterior_MatchesRetailCellDrawList Delete the test. Preserve its retail oracle and capture recipe here and in the existing P0 plan.
Known product failure 1 TowerAscentReplayTests.TowerAscent_StaircaseStaysConeVisible_EveryStep Do not pretend this is unavailable coverage. Keep the oracle and move it to an explicitly reported known-failure/non-blocking lane until #119 is fixed.

Installed-DAT skip distribution:

Test class Count
ChargenPreviewControllerTests 10
CharacterCreationLiveDatTests 42
CharacterManagementLiveDatTests 3
DatStringEscapeSweepTests 1
LayoutImporterMediaBearingChildSweepTests 3
MapHousePanelLiveDatMountTests 1
MapNoteLiveDatTests 3
TooltipLiveDatTests 7
UiButtonCorpusSweepTests 3

The 11 source sites that conditionally threw SkipException.ForSkip were not part of the R2 77 because their prerequisites happened to be available on that machine. Batch G preserves their reasons but replaces the misleading dynamic- skip exception with explicit lane-prerequisite failures. No static skip or SkipException.ForSkip remains in current test source.

The lane vocabulary is deliberately orthogonal:

  • Lane states the execution environment (InstalledDat, PreparedPackage, Live, Manual, Windows, Linux, or SystemFont);
  • Purpose=Diagnostic marks output/investigation apparatus that cannot add to the contract-test pass count; and
  • Status=KnownFailure keeps a named executable oracle visible without making a green release claim.

The default gate excludes all three dimensions. An explicitly selected lane must fail clearly when its prerequisite is missing; it may not pass through an empty return. The 73 custom installed-DAT facts retain discovery-time skips when their opt-in is absent so each unavailable contract and reason remains identifiable in the lane report.

Finding disposition

Finding Current disposition Evidence / next action
T-001 launcher lock inversion resolved in R1 Deterministic captured-callback regression and bounded full gate.
T-002 physics tautology high-confidence cleanup batch A Compare old-model and new-model reflection decisions, as the surrounding contract states.
T-003 duplicate theory row high-confidence cleanup batch A Remove literal 0x41000012, which is identical to MotionCommand.Crouch; remove the temporary analyzer suppression.
T-004 warning mismatches resolved in R2 Clean rebuild is zero-warning with repository-wide warnings-as-errors.
T-005 dormant panel stack resolved in batches P and V No shipping code implements IPanelRenderer/IPanelHost or constructs ChatPanel, DebugPanel, or VitalsPanel, but the architecture explicitly preserves this first-party developer-panel contract for issue #258. Batch V removes exactly 26 fake-renderer self-tests and two compiler-generated PanelContext record tests while retaining FakePanelRenderer and all 23 executable panel behavior contracts.
T-006 misleading installed-DAT reason resolved in batch B Shared opt-in is now ACDREAM_RUN_INSTALLED_DAT_TESTS=1 (legacy switch retained), the reason names the lane, and all nine owners carry Lane=InstalledDat.
T-007 271 silent passing gates resolved in batch G All 280 directly found gates plus three later-reconciled sites now fail explicitly when their selected lane lacks its prerequisite. The only three syntax candidates left are reviewed cross-platform branch false positives.
T-008 incapable-of-failing diagnostics resolved in batches A, C, and L The literal wiring smoke test was deleted, the GPU contract tautology was repaired, and the six remaining constant-truth diagnostic assertions were removed after their output was preserved under Purpose=Diagnostic.
T-009 wall-clock double-click tests resolved in batch E Four sleeps were replaced by a deterministic test clock behind an internal factory overload. The production factory still reads Environment.TickCount64 exactly as before.
T-010 two useless cases high-confidence cleanup batch A Delete SmokeTest.TestProject_IsWired and ChaseCameraTests.ImplementsICamera; compilation already proves both claims.
T-011 diagnostic-only methods resolved in batches C, L, and R The reviewed current set is 82 methods / 103 cases. All carry Purpose=Diagnostic, preserving the apparatus while removing it from release pass totals. Batch R catches investigations whose only assertion validates fixture/DAT availability, which the original mechanical output-only scan could not distinguish from an oracle.
T-012 source-text freezes direct-read map completed in batch I, helper-mediated gap corrected in batch U, and staged replacement active Seventeen whole-tree architecture rules and five cross-artifact contracts stay. Batches W/X retire the first 15 literal implementation freezes beside stronger behavior or compiled-metadata evidence; 70 staged replacements remain.
T-013 controller self-comparison high-confidence cleanup batch A Capture the first controller next to the first body and compare every retry with that reference.
T-014 seven load-sensitive tests six mechanisms repaired in batch F; one product defect classified Virtual/wall-clock mixing, tiered-JIT allocation noise, a live controller clock, and a ThreadPool-start timing oracle were removed without weakening behavioral contracts. DatSoundCache #321 is a real in-flight-entry race and now runs as Status=KnownFailure pending a product fix.
T-015 four non-prerequisite skips resolved in batches A/B PVS scaffold deleted with rationale preserved; redundant chat/radar generators deleted in favor of the comprehensive Manual lane; tower oracle is Status=KnownFailure.
T-016 historical test taxonomy resolved in batches J, Q, R, and T Opaque AP/R/J/K/Slice and SCRATCH labels have been removed from maintained regression identities while provenance stays in comments and ledgers. The user approved retaining the 47 descriptive Issue### files because their IDs connect executable contracts to retail evidence.
T-017 Avalonia ownership batch D's window cleanup was necessary but incomplete; runner lifetime fixed in batch S Batch R's clean gate reproduced a compositor thread-affinity cleanup failure. The sole combined Avalonia fact still used the package's default per-test application isolation. Batch S explicitly owns one application/dispatcher for the assembly's one UI fact; 25 focused processes, 25 complete Launcher assemblies, and the complete gate pass.
T-018 stderr observer race resolved in R2 Live reader shares writes/deletes; 25 focused repetitions plus the complete gate.
T-019 remaining explicit waits resolved in batches MO All nine fixed-delay negative oracles now use observed monitor/thread/lease/process state. The remaining 24 elapsed-time methods are the reviewed cancellation, real-time protocol, cooperative-yield, bounded-polling, and positive-timeout categories from Batch H.
T-020 exact duplicate bodies/data resolved in batch K Four redundant executions were removed. The remaining 11 body-equivalent groups are intentionally split theories with disjoint, meaningfully named datasets; the inventory enforces zero repeated rows within a theory or across body-equivalent theories.
T-021 suspicious assertion shapes resolved in batch L The inventory enforces zero Assert.True(true) / Assert.False(false) sites and reports syntactic self-comparisons for review. All five current self-comparisons assert meaningful determinism or stable identity.

Preserved rationale for removals in batch A

PVS scaffold

The empty PVS fact has no executable oracle and must not remain a permanent skip. Its useful note is preserved here: retail PView::ConstructView(CEnvCell*) at 0x005a57b0 produces the ordered cell_draw_list for a (viewer_cell, eye) input. A future conformance test requires a retail trace captured around PView::DrawCells/cell_draw_list. The intended invariants were: the PVS root equals physics CurrCell.Id; a cell seen through two portals appears once per slice; and dungeon outside_view == 0. The complete original scaffold and capture plan remain in docs/superpowers/plans/2026-06-03-p0-conformance-apparatus.md.

Compile-only smoke cases

SmokeTest.TestProject_IsWired contains only Assert.True(true). ChaseCameraTests.ImplementsICamera assigns ChaseCamera to ICamera and calls ToString() without an oracle. Removing them discards no runtime contract: the test project build and the remaining camera behavior tests are strictly stronger evidence.

Batch protocol

Each cleanup batch must:

  1. update this ledger before or with the change;
  2. preserve useful historical rationale in a plan, issue, or this ledger;
  3. run the directly affected test projects without retries;
  4. run a clean warning-as-error build when analyzer/discovery shape changes;
  5. commit one coherent classification/fix group; and
  6. run the complete local Release gate before R3 closeout.

Ambiguous cases stay open in this ledger and are presented to the user rather than being deleted by inference.

Batch A verification

The first high-confidence batch was verified before commit:

  • complete non-incremental Release rebuild: 44 projects, 0 warnings, 0 errors;
  • Core: 4,795 passed / 0 skipped / 0 failed;
  • App: 5,511 passed / 76 skipped / 0 failed; and
  • Runtime: 1,756 passed / 0 skipped / 0 failed.

The count delta is intentional and classified: Core removed the two useless compile-only cases and the skipped PVS scaffold; App gained one case by splitting the old mixed/tautological depth-stencil test into two independently named contracts. Core emitted no duplicate-case discovery warning.

Preserved rationale for removals in batch B

The chat- and radar-only fixture generators were not the sole way to recreate their committed JSON. RetailLayoutFixtureGenerator already includes retail layout IDs 0x2100006F and 0x21000074 and writes the same chat_2100006f.json and radar_21000074.json destinations as part of its complete 20-layout run. Deleting the two permanently skipped duplicates removes two false test entries without losing the regeneration recipe or retail notes; the comprehensive generator and docs/release-gate.md now own that workflow.

The tower staircase oracle is not unavailable or useless. Its former static skip documents issue #119 and the exact failing steps. Batch B keeps the executable assertion under Status=KnownFailure, separates two output-only methods with Purpose=Diagnostic, and makes missing installed DATs a clear lane prerequisite failure instead of a passing early return.

Batch B verification

The lane-classification batch was verified without changing product code:

  • App Release build: 0 warnings, 0 errors;
  • hermetic App lane, isolated: 5,505 passed / 0 skipped / 0 failed;
  • Installed-DAT contract lane without opt-in: 3 passed / 73 individually named skips / 0 failed (the local tower DAT prerequisite was available);
  • known-failure discovery: exactly one tower staircase oracle; and
  • Manual discovery: exactly one comprehensive fixture generator.

One concurrent three-host verification attempt reproduced T-014 rather than being hidden: the hermetic host failed the portal-clipping zero-allocation test at 6,904 bytes while the Installed-DAT and discovery hosts ran beside it. The same unmodified hermetic command then passed 5,505/5,505 in isolation. This is evidence for removing cross-host allocation sensitivity; it is not grounds to weaken the assertion or claim a clean concurrent result.

Batch C diagnostic classification

Batch C assigns the reviewed 51-method diagnostic set to Purpose=Diagnostic. No body, output, historical comment, or fixture is removed. This resolves the misleading release accounting without pretending that every investigation has a stable regression oracle.

The 15 contract-shaped methods called out by T-011 now have a Diagnostic_ prefix: four facility-hub scenarios, six stair/camera sweeps, two ambient-slot inventories, production-emission replication, and two drawn-polygon reports. Their current output and historical method references are preserved, while the new names no longer imply an asserted oracle. Promoting them back into the hermetic lane requires an asserted expected result; R3 will not invent those values.

Batch C verification:

  • App Release build: 0 warnings, 0 errors;
  • Core Release build, serialized after App: 0 warnings, 0 errors;
  • hermetic App: 5,479 passed / 0 skipped / 0 failed;
  • hermetic Core: 4,753 passed / 0 skipped / 0 failed; and
  • diagnostic discovery: 28 App + 42 Core = 70 cases from 51 methods.

An attempted parallel App/Core build collided on the shared AcDream.Plugin.Abstractions intermediate DLL. The repository gate serializes projects, so the authoritative verification is the two isolated clean builds above; no code or assertion was changed in response to that tooling collision.

Batch D prerequisite lanes and Avalonia ownership

The reviewed prerequisite map classifies every true candidate without deleting its existing guard:

Lane Attributed methods Prerequisite
InstalledDat 336 Installed retail DAT directory; includes the 73 custom installed-DAT facts and whole DAT-backed investigation classes.
PreparedPackage 2 Installed DATs plus validated acdream.pak.
Live 3 Explicit live handshake opt-in and reachable service.
Manual 1 Explicit fixture-regeneration opt-in.
Windows 7 Windows-only filesystem/process/timer behavior.
Linux 10 Linux permission/signal/monotonic-clock behavior.
SystemFont 2 A host system TTF available to the BitmapFont path.

Class-level traits legitimately cover some additional methods that share the same fixture owner, so the 336 installed-DAT method count is larger than the 280 syntax candidates. The only candidate methods without a lane are GraphicalHostPlatformServicesTests.CurrentPlatformOwnsPathsPacingAndNativeClosure and LinuxMonotonicFramePacingWaiterTests.PlatformFactorySelectsCurrentOperatingSystem. Both are hermetic cross-platform branch tests: on Windows or Linux they assert the matching branch and return only after the assertion. They are not silent prerequisite passes.

The 11 conditional SkipException.ForSkip source sites are also reconciled. They serve 12 test methods: installed-DAT asset contracts, one prepared-package contract, and two system-font contracts. xUnit v2 reports that exception shape as a failure rather than a dynamic skip, but the owning lanes now keep them out of the hermetic total. A later body-cleanup batch will replace the misleading skip wording/exception with explicit prerequisite failure or discovery-time lane behavior.

The first complete Batch D gate correctly failed in Launcher cleanup after 14,396 passes: the six MainWindowViewTests Avalonia facts could start and destroy isolated thread-affine compositors on different xUnit workers. The assertion bodies were preserved as six named private phases under one CompiledMarkupAndEveryModalFocusPathRunInOneOwnedAvaloniaSession fact. The focused two-case class then passed in 25 consecutive fresh processes (50/50 results), and the same full-gate context passed.

Batch D verification:

  • complete 44-project Release build: 0 warnings, 0 errors;
  • final syntax manifest: 11,450 attributed methods, 51 diagnostics, one known failure, 282 prerequisite-return candidates, and only the two reviewed cross-platform false positives unlaned;
  • complete hermetic Release gate: 14,392 passed / 0 skipped / 0 failed across all 12 test assemblies in 131.518 seconds; and
  • Launcher view stress: 25 fresh processes, 2/2 cases per process, no cleanup or ownership failures.

The 350-pass reduction from the clean R2 headline is exactly explained: batch A netted minus one case; batch B removed six non-hermetic passes; batch C removed 68 newly classified diagnostic cases; batch D removed 270 prerequisite-lane passes; and consolidating the six Avalonia sessions into one removed five case IDs without removing any assertion phase. All 77 former default skips are also accounted for by the PVS deletion and batch-B lane/deletion decisions.

Batch E indirect gates and deterministic input time

The inventory now follows same-file helper calls when looking for prerequisite returns. It found one additional path: LauncherSelfUpdateProcessTests.BackupJunctionOrSymlinkAfterCanonicalCrashCannotMutateOutsideOrLaunch calls CreateDirectoryLink, whose non-Windows branch creates the symbolic link and then returns before the Windows mklink /J implementation. This is a reviewed cross-platform control-flow branch, not a prerequisite gate or silent pass. The combined direct/indirect candidate count is therefore 283: 280 true lane-owned gates and three reviewed branch false positives.

The four InputDispatcherDoubleClickTests no longer sleep for 10 or 600 real milliseconds. InputDispatcher has an internal, test-assembly-only factory overload accepting the same millisecond tick delegate used by double-click recognition. The public production factory remains wired directly to Environment.TickCount64; only the tests use a manually advanced counter. The focused class passes 4/4 in 17 ms with exact 10 ms and 600 ms virtual intervals. The complete Release build then passed with 0 warnings/errors, and the no-retry hermetic gate passed 14,392/14,392 with zero skips or failures.

Batch F load-sensitive contracts

The seven cases in T-014 have now been separated into six unreliable test mechanisms and one real product defect:

  • #308 NakEmissionTests.LossSoak... no longer mixes its virtual transport clock with a 60-second DateTime.UtcNow cutoff and fixed sleeps. Its two convergence phases each permit exactly 120 half-second virtual steps and yield to the background receiver. The full 10,000-message oracle is intact; 25 fresh-process repetitions pass.
  • #302 and #346, the two PortalProjectionTests allocation contracts, now cross tiered-JIT/PGO thresholds before measuring and take the minimum of five warmed 1,000-operation batches. A linear result-array regression would allocate in every batch and still fail far above the existing ceilings.
  • #336 RuntimeCollisionReportingStateTests.WarmedSteadyContactRefreshDoesNotAllocate now earns the word "warmed": it performs one complete 10,000-refresh warmup and requires at least one of five subsequent 10,000-refresh batches to allocate exactly zero bytes. It passes in 25 fresh processes.
  • #340 StreamingWorkBudgetTests.DestinationAndEmptyUnloadPriorityNeverBypassPublicationBudget now supplies a frozen meter clock through an internal test-only constructor. The public production constructor still supplies Stopwatch.GetTimestamp and Stopwatch.Frequency exactly as before.
  • #402 LandblockBuildFactoryTests.Build_UsesTheSuppliedSharedReaderGate now starts a dedicated thread and observes it in WaitSleepJoin on the held monitor before checking that no DAT read occurred. It no longer treats a ThreadPool start within two seconds or an arbitrary 100 ms wait as evidence.
  • #321 DatSoundCacheTests.GetWave_ConcurrentSameId_PublishesOneCanonicalWaveAndDecodesOnce exposes a real race. A caller can pass the resident-cache check, pause, and reach _inflight after the winning caller has admitted the wave and removed its Lazy, producing a second decode. The assertion and rationale are preserved under Status=KnownFailure; R3 makes no cache behavior change.

The four changed App cases pass 100/100 across 25 fresh processes. The Runtime allocation case passes 25/25, and the Core.Net loss soak passes 25/25. Complete batch verification then passed: the 44-project Release build reports zero warnings/errors, the refreshed inventory reports two explicit known-failure methods and 15 remaining direct Thread.Sleep methods, and the no-retry hermetic gate passed 14,391/14,391 with zero skips or failures. The one-pass reduction is exactly #321 leaving the release lane.

Batch G honest prerequisite lanes

Batch G removes every true silent prerequisite pass found by the direct and same-file-helper inventory. Across 101 test files, 283 lane-owned return; sites now report a prerequisite failure when that lane was explicitly selected: 261 installed-DAT, ten Linux, seven Windows, three Live, and two prepared-package methods. Seventeen platform guards throw PlatformNotSupportedException; the remaining gates use lane-specific assertion failures. Production behavior and every contract assertion after the guard are unchanged.

The eleven conditional SkipException.ForSkip sites now use explicit prerequisite failures as well. Their asset, package, or font reason is retained, but a selected lane can no longer look green by dynamically skipping the contract. The refreshed syntax inventory finds zero true silent-prerequisite candidates. Its three remaining candidates are the reviewed Windows/Linux branch returns recorded in Batch E.

The focused installed-DAT run also exposed a taxonomy error rather than a product failure: 19 interactive layout methods need a retail DAT directory but are operator-driven probes, not automated DAT contracts. They now live under Lane=Manual, divided into ManualTask=LiveMountProbe (13) and ManualTask=PowerbarProbe (6). The comprehensive existing generator is separately named ManualTask=FixtureGeneration, so selecting a probe cannot rewrite committed fixtures. Current attributed-method lane ownership is:

Lane Methods
InstalledDat 317
PreparedPackage 2
Live 3
Manual 20
Windows 7
Linux 10
SystemFont 2

Focused verification before the complete gate:

  • Release build of all 44 maintained projects: 0 warnings, 0 errors;
  • installed-DAT contracts: 311/311 passed (App 150, Bake 3, Content 28, Core 130);
  • prepared-package contracts: 2/2 passed against the validated local package;
  • Windows contracts: 7/7 passed; system-font contracts: 2/2 passed;
  • manual live-mount probes: 13/13 passed; manual powerbar probes: 6/6 passed;
  • a Linux contract selected on Windows failed with the explicit wrong-host reason; and
  • a Live contract selected without opt-in failed with the explicit ACDREAM_LIVE=1/reachable-server prerequisite reason.

The fixture-generation task was intentionally not executed: its documented purpose is to rewrite fixture files, while this R3 batch is review/test-only. The no-retry complete hermetic Release gate passed 14,391/14,391 with zero skips or failures across all 12 test assemblies.

Batch H explicit-wait classification

The syntax inventory now records every direct Thread.Sleep and Task.Delay invocation instead of treating both method-level booleans as equivalent. The 38 attributed methods divide into six materially different groups:

Wait purpose Methods R3 disposition
Cancellable infinite suspension in a fake 5 Keep. Task.Delay(Timeout.InfiniteTimeSpan, token) advances only through the cancellation being tested and consumes no elapsed-time oracle.
Intentional real-time protocol/timeout contract 4 Keep with explicit bounds: two Live handshake race delays, the one-second net-probe cadence, and continuous unrelated shutdown drain.
Cooperative yield while virtual-clock/background transport work drains 8 Retain for now; prefer an observable receiver/worker signal when that seam exists. The virtual behavioral oracle does not derive from the sleep duration.
Bounded completion/readiness polling 11 Retain as integration polling with a terminal assertion and deadline; improve opportunistically with events, not by busy-spinning.
Fixed delay used to prove another operation is still blocked 9 originally; 0 remain Batches MO replace all nine with observed monitor/thread/lease/process state.
Positive completion timeout guard 1 Keep. The two-second WhenAny in RuntimeCharacterStateTests fails only if the operation does not complete; it does not delay a passing run.

The original nine fixed-delay negative oracles are:

  1. LiveSessionCommandRouterTests.ConcurrentDispose_WaitsForInFlightTransportThenMakesRouterInert;
  2. HostQuiescenceGateTests.ExternalStopWaitsForAdmittedCallbackToReturn;
  3. both SilkWindowCallbackBindingTests.ConcurrentDispose... contracts;
  4. LandblockStreamerPoolTests.Dispose_JoinsEveryWorkerInThePool;
  5. LandblockStreamerTests.DisposeAndConcurrentDisposeWaitForInFlightLoad;
  6. HeadlessPluginSessionTests.LateSubscriberReplayQueuesConcurrentRegistrationExactlyOnceInOrder;
  7. LauncherInstallerTests.IndependentInstallersSerializeAndWaitingCancellationTouchesNothing; and
  8. LauncherInstallerTests.OrphanBakeCanNeverPublishAfterRestartRecovery.

This classification is review evidence, not a claim that the remaining waits are flaky. The inventory run at 6faeb4a1 parsed all 1,256 tracked C# test files and reproduced 15 sleep methods, 23 delay methods, five cancellation- only methods, and 33 methods with some elapsed-time wait.

Batch I source-text replacement map

Batch I's first inventory found 63 attributed methods that directly read .cs source text. Batch U later proved that count was incomplete: tests that called a local BuilderSource(), ReadSource(...), or method-group File.ReadAllText helper were invisible to the direct body regex. The corrected syntax inventory follows same-file helper calls, recognizes invoked and method-group readers, and only treats actual string content—not comments such as GameWindow.cs:5893—as a C# path signal. It finds 67 direct and 40 helper-mediated methods, 107 total.

Manual reconciliation assigns every candidate to one of three dispositions:

Disposition Methods Owning test files
Implementation-shape or test-model freeze; replace in stages 85 Thirty files across composition, input/physics/network wiring, graphical host/render ownership, Runtime gameplay-owner wiring, streaming, and frame orchestration; the exact stage manifest follows below.
Whole-tree architecture policy; retain, then make syntax/metadata-aware 17 LinuxPlatformBoundaryTests, RenderSceneArchitectureTests, RuntimePhysicsOwnershipTests, RuntimeEntityOwnershipTests, plus the whole-tree methods in RuntimeActionOwnershipTests and RuntimeMovementOwnershipTests, RuntimeWorldTransitOwnershipTests, and RuntimeDatAccessArchitectureTests
Source/project/artifact text is the actual cross-artifact contract; retain 5 ParticleBindlessInstanceTests, PerformanceToolsTests, LauncherProjectBoundaryTests

The 85 implementation/test-model facts were useful during mechanical ownership cutovers and defect investigations, but are not durable behavioral evidence. They pin constructor spellings, local names, exact call fragments, regex-shaped method bodies, or statement order; comments can satisfy many of their Contains checks, while a harmless equivalent refactor can fail them. Their intent is often valuable—single ownership, ordering, handoff, teardown, absence of a parallel path, or continued validity of a synthetic test model—so wholesale deletion would discard real notes and weaken some boundaries.

R3 therefore uses this replacement rule for those 85 facts:

  1. preserve the ownership/order rationale in the architecture document or this ledger;
  2. identify an existing behavioral, lifetime-ledger, project-reference, or reflection/Roslyn guard that proves the same claim;
  3. add the semantic replacement first when none exists; and
  4. remove the literal source freeze in the same small batch.

The 17 whole-tree rules remain valuable even before conversion: they ban platform calls outside owners, enforce assembly/namespace containment, and prevent duplicate Runtime entity, physics, movement, action, transit, and DAT authorities. The five cross-artifact tests compare two independently consumed artifacts (for example CPU/shader constants, launcher project/workflow/markup, and CLI route tooling); reading text is appropriate there.

No source-freeze fact is removed in this classification batch. The 85 staged facts are an ambiguous architecture decision and will be presented for user approval in behavior-owner groups rather than deleted from a numeric heuristic.

Source-freeze approval groups

The 46 campaign-era facts are not equivalent. Their current semantic coverage and safest replacement path divide into six owner groups:

Owner group Facts What the literal checks still prove R3 recommendation
Composition-root wiring 13 GameWindow calls the intended phase objects and no longer contains the extracted construction bodies. Phase-local tests cover ordering and rollback inside each phase, but not every root-to-phase link. Keep until one symbol-aware composition-graph guard proves the root links. Then remove the literal constructor/local-name checks.
Runtime root, graphical host, and lifetime 24 One canonical Runtime root/command surface, typed owner handoffs, run/render/status ordering, acquisition order, and native-window-last shutdown. Existing Runtime/lifecycle tests prove much of the behavior, but several sole-owner and transfer claims remain unique. Replace with direct ownership receipts, terminal-ledger assertions, observable host traces, and metadata dependency guards before removing any source freeze.
Render delegation and cleanup 9 Rendering is delegated and GameWindow does not regain leaf draw branches or resource ownership; several tests also pin exact renderer/preparation statement order. The owning render suites already exercise the executor, frame builder, renderer, and resource disposal behavior. Best first conversion: add a symbol-aware boundary guard for absence/delegation and observable fake traces for order, then remove the literal checks.
Streaming publication 4 The window does not own render/physics publication bodies, captured build origins flow through the extracted owners, and streamer teardown follows session reset. Publisher/build/origin suites already provide broad behavioral coverage. Best second conversion: consolidate the absence claims into a whole-tree architecture guard and retain the behavioral origin/teardown contracts.
Live-entity composition 2 Typed sources replace window closures and reset closes every streaming/readiness owner. Lifecycle tests cover convergence, but the exact constructor-shape claim is still literal. Replace with constructor/field metadata inspection plus the existing teardown ledger; do not delete alone.
Frame orchestration and resource preparation 14 Exact-once publication, frame/resource-stage order, adapter ownership, and a deliberately thin OnUpdate. These are high-value order rules, but exact statement fragments are the most brittle implementation specification in the set. Replace order assertions with observable fake event traces and use a symbol-aware dependency guard for the thin-root rule. This is the largest conversion and should be last.
Input, physics, and network wiring 9 Typed owner entry points, retry/reset wiring, and local/remote branch ordering remain at exact source locations. Behavioral controller suites cover the operations, but not every production composition route. Add symbol-aware call-graph boundaries and route the behavioral fixtures through the production entry seam before removing the text checks.
Runtime gameplay-owner wiring 9 UI/session/shutdown consumers borrow exact action, character, inventory, and movement owners without mirrors or second mutations. Runtime ledgers cover terminal ownership but several App consumer links are literal only. Replace consumer links with metadata dependency checks and exact borrowed-instance integration assertions.
Test-model/source correspondence 1 The hand-called create-authority drift probe still models the executor's sole production advance site. Expose an observable executor stage/receipt or re-derive the synthetic model before removing this explicit stale-model alarm.

Approval should authorize this replacement sequence, not wholesale deletion: render delegation, streaming, live entities, input/physics/network wiring, composition roots, Runtime gameplay owners, Runtime/graphical-host lifetime, frame orchestration, then the one test-model/source pin. If the semantic replacement exposes a claim that exists only as historical campaign wording, preserve the rationale and bring that individual deletion back for review.

The exact staged file manifest is:

Stage Facts Complete owning-file set
Render delegation and cleanup 9 ResourceCleanupGroupTests, RetailPViewPassExecutorTests, WorldRenderFrameBuilderTests, WorldSceneRendererTests
Streaming publication 4 LandblockBuildOriginTests, LandblockPhysicsPublisherTests, LandblockRenderPublisherTests
Live-entity composition 2 GameWindowLiveEntityCompositionTests
Composition-root wiring 13 ContentEffectsAudioCompositionTests, FrameRootCompositionTests, HostInputCameraCompositionTests, InteractionRetainedUiCompositionTests, LivePresentationCompositionTests, SessionPlayerCompositionTests, WorldRenderCompositionTests
Runtime root, graphical host, and lifetime 24 GameWindowLiveSessionOwnershipTests, GameWindowCrashStatusTests, GameWindowRenderLeafCompositionTests, GameWindowHostBoundaryTests
Frame orchestration and resource preparation 14 UpdateFrameOrchestratorTests, RenderFrameResourceControllerTests
Input, physics, and network wiring 9 C3cF2AutoEntryWiringTests, C3cF1ProductionWiringTests, Issue270ProductionWiringTests, LiveEntityNetworkBranchRoutingTests
Runtime gameplay-owner wiring 9 The non-whole-tree methods in RuntimeActionOwnershipTests and RuntimeMovementOwnershipTests, plus RuntimeCharacterOwnershipTests and RuntimeInventoryOwnershipTests
Test-model/source correspondence 1 CreateAuthorityDriftModelSourcePinTests

This manifest accounts for all 85 methods exactly. It excludes the 17 whole-tree policy methods and five genuine cross-artifact text contracts.

Batch P dormant panel reachability reconciliation

T-005's production-reachability half is now proved: repository-wide C# usage contains no production IPanelRenderer or IPanelHost implementation and no shipping construction of ChatPanel, DebugPanel, or VitalsPanel. The old ImGui backend is gone; retained UiHost/UiRoot controllers are the sole shipping presentation stack, and plugin UI uses IUiRegistry.AddMarkupPanel rather than IPanel.

That does not make the complete abstraction useless. The architecture document explicitly says AcDream.UI.Abstractions and the IPanel/IPanelRenderer developer-panel contract survive intact for a future host tracked by issue #258. ChatVM and VitalsVM are also live shared models consumed by retained UI, so their model/parser/command tests are production coverage and are outside T-005.

The dormant presentation-only subset currently contains 51 attributed methods (57 expanded cases):

Subset Methods Disposition
IPanelRendererWidgetTests and IPanelRendererMainMenuBarTests 26 They exercise only FakePanelRenderer, not a production backend. Approved for removal in Batch V.
PanelContextTests 2 Only compiler-generated record round-trip/equality. Approved for removal in Batch V.
ChatPanel layout, input, focus, and colored-render behavior 23 Meaningful executable behavior for the explicitly preserved future developer-panel contract. Retain unless that architecture promise is intentionally retired.

The earlier audit's recommendation to remove the whole stack was therefore too broad. The maintainability problem is narrower: 28 harness/trivial contract methods inflate release totals despite having no production renderer, while 23 panel behavior methods protect a deliberately dormant API. The UI framework plan also has stale present-tense statements that ImGui remains permanent, whereas the architecture authority correctly records its deletion; that is a documentation-reconciliation item, not evidence that the old backend still exists.

The proposed removal boundary is exact: all 17 methods in IPanelRendererWidgetTests.cs, all nine in IPanelRendererMainMenuBarTests.cs, and both in PanelContextTests.cs. FakePanelRenderer.cs remains because the 23 retained ChatPanel behavior methods use it as an observation seam. No production abstraction, panel, ViewModel, parser, command test, or future-host rationale is in the removal set. With no replacement cases, this decision alone would reduce the current hermetic Release total from 14,379 to 14,351.

Batch J descriptive test identities

The first T-016 naming batch changes no oracle or production behavior. It renames eight opaque type/file identities and fifteen test methods whose AP, R, J, K, C3c, or Slice labels described the implementation campaign rather than the contract a maintainer needs to find:

Former identity family Durable identity
GameWindowSlice8BoundaryTests GameWindowHostBoundaryTests
Ap10WaterSemanticsTests, Ap71EntryRestrictionGateTests, Ap155StaticSpherePopulationMeasurementTests, Ap157SortingSphereFloodMeasurementTests WaterSemanticsTests, EntryRestrictionGateTests, StaticSpherePopulationMeasurementTests, SortingSphereFloodMeasurementTests
ConnectedR6SoakContractTests ConnectedWorldSoakRouteContractTests
C3cR1F3DriftModelSourcePinTests CreateAuthorityDriftModelSourcePinTests
R5Host / R5ManagerHarness.cs PhysicsObjHostStub / PhysicsManagerHarness.cs
J4/J5 Runtime methods gameplay-view, gameplay-command, checkpoint, simulation, and ownership-ledger names
K4/Slice-L/K1c/J9 methods multi-session profile, unsupported-platform explanation, legacy keymap difference, and stop-speed behavior names
AP-135/AP-195 method names placement-bookkeeping and authored-LED-sprite names

Provenance is not discarded. AP-157 remains the row key in the retail divergence register, the connected route keeps its established artifact name, and historical audit/plan documents retain the old identifiers. Current cross-references and test comments point to the new descriptive names. The source-freeze class summary now states its R3 replacement status instead of claiming to be a temporary Slice 8 checkpoint.

This batch intentionally does not rename the 47 Issue### files. Their descriptive suffixes are often useful, and the issue number can be the shortest path to a retail trace or reproduction. Re-homing those contracts by component while retaining Issue provenance is an architecture/taxonomy choice for user approval, not a mechanical cleanup.

Verification before the complete gate:

  • all 44 maintained projects build in Release with 0 warnings and 0 errors;
  • 102 focused App cases, 203 Core cases, 17 Runtime cases, 5 Headless cases, 1 Launcher.Core case, and 10 UI.Abstractions cases pass; and
  • the renamed installed-DAT population measurement passes 1/1 against the local retail DAT.

The no-retry complete hermetic Release gate passed 14,391/14,391 with zero skips or failures across all 12 test assemblies.

Batch K duplicate-body and theory-row truth

The inventory now fingerprints every attributed method body and compares InlineData case-sensitively both within a theory and across theories with an identical body. Case sensitivity prevents legitimate inputs such as iris / IRIS, Sunny / SUNNY, and 0x / 0X from being mislabeled as duplicates.

The initial 14 body-equivalent groups contained four redundant executions:

  • VulkanCapabilityReportContractTests.TheReportFileNameIsTheOneTheWorkflowPathNames duplicated the report-name assertion in VulkanCapabilityGateTests and did not inspect the workflow it named. The retained fact is now TheReportFileNameRemainsStableForDiagnosticsAutomation.
  • MotionInterpreterDoMotionFamilyTests.StopCompletely_NullPhysicsObj_Returns8 was byte-equivalent to the more descriptive MotionInterpreterTests.StopCompletely_NullPhysicsObj_ReturnsNoPhysicsObject.
  • CastSpellTests.ParseMagicUpdateSpell_RoundTrip duplicated the same parser contract under GameEventDispatcherTests, the parser's durable owner.
  • retail motion row (0x0150, 0x10000150u) appeared in both the recall-command theory and the generic anchor theory. It remains in the specifically named recall contract.

The other 11 groups are not useless duplicates. They deliberately reuse a small assertion body while separating disjoint datasets by meaning: command resolution, command argument shapes, valid chat tags, retail string escapes, weenie error-message evidence, help text, invalid chargen ranges, ACE/retail motion tables, character-option oracle sources, and environment-sound gaps. Combining those rows would erase useful failure names without reducing the assertion mechanism.

After cleanup the inventory reports 11,447 attributed methods, zero duplicate rows, and 11 reviewed body-equivalent groups containing 27 methods. Verification for the changed owners passes 46 App, 154 Core, and 32 Core.Net cases. The complete 44-project Release build reports zero warnings and zero errors. The no-retry complete hermetic Release gate passed 14,387/14,387 with zero skips or failures across all 12 test assemblies. The four-case reduction is exactly the three duplicate facts and one duplicate theory row removed above.

Batch L vacuous diagnostic assertions

Six investigation methods still ended in an unconditional green assertion:

  • three cellar-lip trajectory/replay artifact writers in CellarLipWedgeTests;
  • two cellar-ascent trajectory reports in CellarUpTrajectoryReplayTests; and
  • the installed-DAT front-approach probe in DoorCollisionApparatusTests.

These were useful tools but not regression tests. Batch L adds Purpose=Diagnostic, removes the six Assert.True(true, ...) calls, preserves the two reports that previously existed only as assertion messages by writing them to captured console output, and leaves the existing %TEMP% artifacts and probe logs intact. No historical investigation notes, fixtures, or probe logic were deleted.

The durable inventory now recognizes File.WriteAll* / File.AppendAll* as diagnostic-output signals and reports high-confidence constant-truth assertions separately from syntactic self-comparisons. It reports zero constant-truth sites. The five self-comparison sites were individually reviewed and retained:

  • Hash32Tests.Calculate_IsDeterministic and PacketHeaderTests.CalculateHeaderHash32_DeterministicForSameInput execute the calculation twice and compare the results;
  • NullCommandBusTests.Instance_IsSingleton reads the singleton twice; and
  • RuntimeEntityObjectLifetimeTests.Owner_ConstructsOneExactDirectoryAndObjectTablePerInstance verifies repeated access to both owned objects returns the same instances.

Batch L verification:

  • all six affected diagnostic methods pass, including the installed-DAT door probe;
  • the refreshed inventory reports 11,447 attributed methods, 57 diagnostic methods, zero constant-truth assertions, and five reviewed self-comparison sites across four methods;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate passed 14,382/14,382 with zero skips or failures across all 12 test assemblies.

The five-case reduction from Batch K is exact: five formerly hermetic diagnostic facts are now excluded by Purpose=Diagnostic; the sixth was already outside the portable lane because its class requires installed DATs.

Batch M observable monitor-wait contracts

Four concurrency tests used a 50100 ms delay and then asserted that disposal had not completed. That was only indirect evidence: a delayed or saturated ThreadPool could satisfy the assertion before the disposal path had attempted to enter its production monitor.

Batch M runs each competing disposal/stop operation on a named dedicated thread, waits with a bounded SpinWait until the runtime reports ThreadState.WaitSleepJoin, and then verifies the thread joins after the controlled callback, transport send, or physical detach is released. This changes no production code and preserves every existing completion, inertness, and propagated-failure assertion. The converted contracts are:

  • HostQuiescenceGateTests.ExternalStopWaitsForAdmittedCallbackToReturn;
  • LiveSessionCommandRouterTests.ConcurrentDispose_WaitsForInFlightTransportThenMakesRouterInert;
  • SilkWindowCallbackBindingTests.ConcurrentDisposeWaitsForPhysicalDetachToComplete; and
  • SilkWindowCallbackBindingTests.ConcurrentDisposeCannotHidePhysicalDetachFailure.

Batch M verification:

  • the four focused contracts pass;
  • 25 fresh-process focused iterations pass, for 100/100 observed-wait cases;
  • the refreshed inventory reduces direct Task.Delay methods from 23 to 19 and elapsed-time methods from 33 to 29;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate remains 14,382/14,382 with zero skips or failures across all 12 test assemblies.

Five fixed-delay negative oracles remain: the landblock streamer and pool disposal contracts, headless concurrent late-subscriber replay, and the two launcher installer/recovery contracts.

Batch N observable landblock-worker joins

The two landblock disposal contracts used 50100 ms delays to infer that LandblockStreamer.Dispose was waiting for its dedicated worker threads. Batch N replaces those delays with direct observation of the disposer threads:

  • LandblockStreamerTests.DisposeAndConcurrentDisposeWaitForInFlightLoad observes the primary disposer blocked in a worker Join, then observes the concurrent disposer blocked behind the disposal monitor; and
  • LandblockStreamerPoolTests.Dispose_JoinsEveryWorkerInThePool observes the disposer blocked while all three controlled worker lanes remain in their loader callbacks.

Both tests then release the loaders, require every disposal thread to join within the existing bound, and retain their exception and post-disposal inertness checks. Production code is unchanged.

Batch N verification:

  • both focused contracts pass;
  • 25 fresh-process iterations of each pass, for 50/50 observed-wait cases;
  • the refreshed inventory reduces direct Task.Delay methods from 19 to 17 and elapsed-time methods from 29 to 27;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate remains 14,382/14,382 with zero skips or failures across all 12 test assemblies.

Three fixed-delay negative oracles remain: headless concurrent late-subscriber replay and the two launcher installer/recovery contracts.

Batch O final fixed-delay negative oracles

Batch O removes the last three timing-based absence-of-completion tests:

  • HeadlessPluginSessionTests.LateSubscriberReplayQueuesConcurrentRegistrationExactlyOnceInOrder now runs registration on a dedicated thread and observes it enter WaitSleepJoin while Runtime's exact replay read lease is held;
  • LauncherInstallerTests.IndependentInstallersSerializeAndWaitingCancellationTouchesNothing now waits until the second installer has actually encountered the held transaction lease before cancelling it; and
  • both rows of LauncherInstallerTests.OrphanBakeCanNeverPublishAfterRestartRecovery now observe publication-lock contention where applicable and wait for the exact orphan child process to exit before checking that it cannot publish later.

The launcher observation points are internal callbacks on the existing transaction/publication lease retry paths. They are unset in production, add no new public API, and do not change lock, retry, cancellation, or publication behavior. The former 150/200 ms delays and post-exit settle delay are gone.

Batch O verification:

  • the one focused Headless fact and three focused Launcher cases pass;
  • 25 fresh-process Headless iterations and 25 fresh-process Launcher iterations pass, totaling 100/100 exercised cases;
  • the refreshed inventory reduces direct Task.Delay methods from 17 to 14 and elapsed-time methods from 27 to 24;
  • none of Batch H's nine fixed-delay negative-oracle methods contains a direct sleep or delay;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate remains 14,382/14,382 with zero skips or failures across all 12 test assemblies.

The 24 remaining elapsed-time methods retain their reviewed Batch H classification: cancellation fakes, intentional real-time protocol behavior, cooperative yields, bounded integration polling, or a positive timeout guard.

Batch Q issue-number taxonomy review

The 47 Issue### files contain 155 attributed methods. They are not a hidden duplicate or source-freeze family: none reads production source text and none contains a direct timing wait. Forty-six methods are explicitly classified Purpose=Diagnostic; the other 109 are executable regression contracts. Ninety-four methods belong to the installed-DAT lane, overlapping both groups where retail assets are the evidence prerequisite.

The issue prefix still has concrete navigation value. Every number maps to a named section in docs/ISSUES.md, and the descriptive suffix already exposes the owning behavior—for example Issue334BspBoxCellMembershipTests and Issue345SteepSlopeGlideTests. A 47-file mass rename would discard that direct evidence key, create large history churn, and would not make the individual contracts materially easier to understand.

R3's recommendation is therefore to retain the current Issue### class/file prefixes. Continue correcting individual method names whose oracle overclaims, and keep diagnostic methods outside the release count, but do not re-home 109 useful regressions merely to erase their provenance. If the issue archive is later split into component-owned records, a class-level Issue trait can preserve filtering before any component-based file rename. The user approved this recommendation before Batch V, closing T-016 without code churn.

Batch R fixture-sanity-only diagnostics

The original output-only scan intentionally treated any assertion as a failure signal. A final name/comment review found 25 more investigation methods whose only assertions establish that the DAT, fixture, setup, or synthetic replay loaded; none compares the report, sweep, or characterization named by the method. Their own names or comments say Diagnostic, Dump, Measure, Characterize, “always passes,” or “not a regression.”

The 25 methods (27 expanded cases) divide into:

  • seven visibility/flood measurement reports across corner flood, house exit, issue #181, and issue #95;
  • ten raw building/geometry dumps across issues #113, #119, #147, and #337; and
  • eight physics transition traces across issue #112, cellar ascent, door collision, issue #108, and issue #265.

Batch R adds only Purpose=Diagnostic. It does not remove a body, fixture, assertion, output line, retail/ACE citation, or historical comment. The diagnostic inventory is now 82 methods / 103 cases: 35 App and 68 Core. The explicit non-Manual diagnostic filters pass 27/27 App and 68/68 Core; the other eight App cases remain in their separately selected Manual tasks.

The same pass corrected two inverse naming errors without changing their oracles:

  • SCRATCH_BuyShapedFreshGuidCreateObjectThenContainId_FinalOrder is a durable vendor-order regression and is now BuyShapedFreshGuidCreateThenPlacementZeroEcho_InsertsAtRetailListHead; and
  • Diagnostic_ExitDoorTopEdge_GateVsAperture already enforces hard pixel bounds and is now ExitDoorTopEdge_GateCoversLiftedApertureWithinPixelTolerance.

Both focused regressions pass. Their detailed queue-order and doorway/scissor rationale remains beside the tests. The only remaining unclassified method names beginning Reflect_ or Dump are real asserted collision/reflection or environment-default contracts, not output apparatus.

Only three of Batch R's 27 newly classified cases had still been hermetic; the other 24 already belonged to the installed-DAT lane. After Batch S's ownership correction, the no-retry complete hermetic Release gate therefore passes 14,379/14,379 with zero skips or failures, exactly three below Batch O.

Batch S Avalonia application-session ownership

The first clean complete gate after Batch R did not pass: every non-Launcher assembly passed, but MainWindowViewTests failed during Avalonia test cleanup with DefaultRenderLoop.Add calling Dispatcher.VerifyAccess from a thread that did not own the compositor. The gate reported 14,378 passes and one failure. This was recorded and fixed rather than retried unchanged.

Batch D had closed and pumped every shown window and consolidated the six UI assertion phases into one [AvaloniaFact]. That removed leaked-window overlap, but it did not change Avalonia 12.1.1's default AvaloniaTestIsolationLevel.PerTest: the runner still recreated and disposed the application, dispatcher, and compositor around that one fact. The failure occurred in that isolated application setup/cleanup path, before any product assertion could explain it.

AcDream.Launcher.Tests contains exactly one Avalonia fact, and that fact owns the complete real-window matrix. Batch S declares AvaloniaTestIsolationLevel.PerAssembly, so the runner creates one application/dispatcher on its dedicated session thread and lets the fresh test process own its terminal cleanup. All individual windows still close and pump their dispatcher in finally; no suite serialization, retry, product code, or assertion was changed.

Verification:

  • the focused Avalonia fact passes in 25/25 fresh processes;
  • the complete 56-case Launcher assembly passes in 25/25 fresh processes;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate passes 14,379/14,379 with zero skips or failures across all 12 test assemblies.

Batch T final campaign-label naming cleanup

A final class/method-name sweep found one campaign-labelled class and two isolated slice-labelled methods whose names hid otherwise durable behavior. Batch T makes naming-only changes:

  • OP2ReworkBlastRadiusConformanceTests becomes DormantDatWidgetConformanceTests. Its eight contracts protect dormant Type-5/Type-8 DAT widget behavior, not the OP2 work sequence that discovered the blast radius. Research records retain the OP2 history and now point to the descriptive class name;
  • G2_VendorStackSelection_ThroughRealMaterializer_ShowsSplitSlider becomes VendorStackSelection_ThroughRealMaterializer_ShowsSplitSlider; and
  • C4_VendorOwnedSplitExemptStackSelection_MatchesRetailsToolbarPresentation becomes VendorOwnedSplitExemptStackSelection_MatchesRetailsToolbarPresentation.

The detailed G2/C4/AP-169 evidence comments remain beside the two selection tests. No assertion, fixture, product code, or historical research statement was removed. The broader short-label sweep also found complete scenario matrices such as A1-A6/B1-B3/C1-C3/D1-D4; those labels remain because they identify deliberate rows within a documented matrix rather than a stale campaign identity.

Verification:

  • the focused Batch T filter passes all 10 renamed contracts with zero skips or failures;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate passes 14,379/14,379 with zero skips or failures across all 12 test assemblies.

Batch U helper-mediated source-text audit correction

Preparing the first semantic replacement exposed a material inventory gap: RetailPViewPassExecutorTests and WorldRenderFrameBuilderTests contain tests that read production source through local helpers, but Batch I's direct body regex counted only the one method in each file that called File.ReadAllText(...) itself. Parameterized helpers such as ReadSource("GameWindow.cs") and method-group reads such as .Select(File.ReadAllText) exposed two more missed forms.

Batch U corrects the audit tool, not any test or product behavior. It now:

  • detects invoked and method-group ReadAllText/ReadAllLines syntax;
  • follows the same-file helper graph already used for failure and prerequisite signals;
  • follows the .cs path signal separately, allowing the caller to supply the filename while a helper performs the read; and
  • derives the path signal only from string/interpolated-string content, so a comment such as GameWindow.cs:5893 cannot classify an ordinary JSON-lines test as a source reader.

The corrected inventory reports 67 direct and 40 helper-mediated source-text tests, 107 total. Manual method-by-method reconciliation assigns 85 to staged semantic replacement, 17 to retained whole-tree architecture policy, and five to retained cross-artifact contracts. The focused inventory assertions prove a helper-mediated builder test is included, a method-group whole-tree test is included directly, and the prior comment/path false positive is excluded.

Verification:

  • all 1,256 tracked C# test files parse and the focused 67/107 count and three exemplar assertions pass;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate passes 14,379/14,379 with zero skips or failures across all 12 test assemblies.

Batch V dormant panel self-test removal

The user approved Batch P's narrow recommendation. Batch V deletes exactly the three self-test files in the approved boundary:

  • IPanelRendererWidgetTests.cs: 17 tests whose oracle is the behavior of the test-only FakePanelRenderer recorder;
  • IPanelRendererMainMenuBarTests.cs: nine more tests of that recorder; and
  • PanelContextTests.cs: two tests of compiler-generated positional-record assignment and equality.

The useful boundary remains intact. IPanel, IPanelRenderer, IPanelHost, and PanelContext remain public production contracts for issue #258; FakePanelRenderer.cs remains as the observation seam for 22 ChatPanel* methods plus the ChatVMCombatTests render-path method; and all 23 layout, input, focus, color, and command behavior tests remain executable. No panel, ViewModel, parser, command contract, product source, or historical rationale is removed.

Verification:

  • the retained 23 attributed panel behavior methods pass all 29 expanded cases;
  • the complete UI-abstractions assembly passes 898/898, exactly 28 below its previous 926-case total;
  • the complete 44-project Release build reports zero warnings and zero errors; and
  • the no-retry complete hermetic Release gate passes 14,351/14,351 with zero skips or failures across all 12 test assemblies, exactly 28 below Batch U.

Batch W render delegation and cleanup source-freeze replacement

Batch W retires the first nine of the 85 approved implementation-text freezes without changing product code. Six test methods now inspect runtime behavior, reflection metadata, or compiled call/new-object edges; three redundant source tests are removed because an existing behavioral trace already asserts the same contract more strongly.

The exact decisions are:

  • TextRendererConstructorOwnsExactlyOneDeviceResource no longer counts constructor strings. TextRendererConstructionCreatesAndDisposesOnlyOnePipeline constructs the real renderer through RecordingGpuDevice, proves that only one pipeline is added (no buffer, texture, sampler, or texture slot), and proves that exact pipeline is disposed. The V4a/V6d rollback rationale stays beside the test. The recording device gained read-only created-resource lists solely so tests can observe those device calls.
  • Renderer_source_preserves_retail_stage_order_through_typed_operations is removed. The existing outdoor and interior DrawInside tests already drive the real renderer and assert the typed operation sequence, including early and late landscape, particle flush, interior clear, masks, shells, and entity routes.
  • Production_uses_retained_routes_without_rebuilding_legacy_partition is removed. The existing production-product test is renamed to state this contract and continues to prove one actual retained candidate with zero compare-only referee work. Exact private selector spellings are not a product oracle.
  • Production_builder_preserves_the_frame_preparation_order is removed. The existing builder test already supplies recording implementations of every typed source and asserts the complete call order plus the borrowed result.
  • executor reset/diagnostic bracketing, the one-executor/one-PView composition, lighting snapshot-before-UBO order, typed world-frame build, local frame-root composition, and GameWindow delegation now inspect compiled call/new-object edges and reflected owner fields. CompiledCallGraph is shared test-only infrastructure that parses the built method body; formatting, comments, local variable names, and source paths cannot satisfy or break these contracts.

Two mixed source assertions were deliberately narrowed rather than silently carried forward. Absence of Console.WriteLine is an implementation-style check with no output oracle and is not treated as render behavior. The old world-scene source test also embedded a separate teardown-order claim; that claim remains with the dedicated lifetime suite and is reconciled in the approved host/lifetime replacement batch instead of coupling teardown to frame construction.

Verification:

  • the four directly affected App suites pass 39/39;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate passes 14,348/14,348 with zero skips or failures across all 12 test assemblies; the exact three-case reduction is the three redundant source tests above; and
  • the regenerated 1,254-file inventory parses every file and reduces direct source readers from 67 to 63 and total direct/helper readers from 107 to 98. The remaining 98 reconcile to the 22 approved retained policies/contracts and 76 staged replacements.

Batch X streaming publication and live-entity source-freeze replacement

Batch X converts the four approved streaming-publication freezes and both live-entity composition freezes. No product source changes. The tests now inspect the built dependency graph, execute the real origin publishers, or assert the typed owner/reset calls instead of matching C# fragments.

The conversion found one materially misleading old assertion. The physics publisher test rejected the literal strings _physicsDataCache.RemoveCellsForLandblock and _physicsDataCache.RemoveBuildingsForLandblock. Those fragments were absent, but the real publisher correctly performs both removals through publication.StagingCache; the test therefore passed without establishing its intended generation-isolation rule. The replacement verifies the compiled AdvanceBeginOne path obtains the staging cache before each removal, commits through RuntimePhysicsState.CommitCollisionGeneration, does not restart the retained-owner capture, and keeps the old publication bodies out of GameWindow.

The other exact decisions are:

  • the render publisher boundary now scans every compiled GameWindow method and constructor for forbidden terrain, cell-visibility, and EnvCell publication calls, and reflects the removed mesh-preparation/body ownership;
  • the former umbrella origin test is narrowed to the claim its fixture could not observe: production LivePresentationCompositionPhase constructs the render, physics, and static publishers before the one presentation pipeline, while GameWindow retains only that pipeline. Captured origin itself remains covered by the real LandblockBuildFactory.BuildFar and LandblockRenderPublisher.BeginPublication behavior tests;
  • recenter ordering is now its own named compiled-call contract: old-window retirement completion precedes LiveWorldOriginState.Recenter, which precedes destination commit. The extensive recenter transaction suite still owns retry, replacement, session-reset, and retirement behavior;
  • the shutdown test reads the compiled operation manifest, including delegate targets, to prove Runtime session stop precedes streamer disposal. It also proves GameRuntime.StopSession disposes the live session before checking its completion barrier and retains the re-entrant diagnostic message;
  • live animation/projectile composition now reflects the exact typed fields and proves CompletePresentation constructs DatProjectileSetupResolver before ProjectileController, with no window closure or remote-motion-view owner; and
  • the session reset test follows compiled calls through LiveSessionRuntimeFactory, PlayerModeController, the network-update owner, and LiveWorldOriginState, rather than pinning four statement strings.

CompiledCallGraph gained reusable readers for every declared method, delegate method targets, and compiled string literals. These are test-only metadata facilities used when invoking the real process/window graph would mutate external resources.

Verification:

  • the four directly affected owner suites pass 111/111;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate passes 14,349/14,349 with zero skips or failures across all 12 test assemblies. The one-case increase is the newly separated recenter-order contract; and
  • the regenerated 1,254-file inventory parses every file, reports 11,417 attributed methods, and reduces direct/total source readers from 63/98 to 57/92. The remaining 92 reconcile to 22 approved retained policies/contracts and 70 staged replacements.

Batch Y input, physics, and inbound-network source-freeze replacement

Batch Y converts the nine approved source-text readers in the input/physics/ network wiring group. Seven remain as compiled-metadata architecture checks; two redundant source assertions are removed. No product source changes.

The exact decisions are:

  • the ForcePosition generic-tail suite now inspects the built TryApplyGenericRemoteRenderPose body for its one WorldEntity.SetPosition edge and proves the committed/deferred local-position observer call is immediately followed by a compiled return. The negative assertion that the already-deleted LocalForcePositionTransaction class name was absent is removed: the Runtime-owned transaction and its displaced-authority behavior are already exercised by RuntimeAcceptedPositionDriveControllerTests, while an absent identifier is not behavior;
  • the contact-versus-walkability source assertion is removed. The dedicated SteepContactBody_InterpolatesInsteadOfSnapping and FreeFlightBodyWithNoContact_StillSnaps behavioral tests exercise the one discriminating state and the opposite boundary through the real routing method, so retaining a string check would add brittleness rather than coverage. The AP-140 retail rationale remains beside those behavioral tests;
  • local inbound SetState routing now verifies the compiled controller graph has exactly one PlayerMovementController.ApplyServerPhysicsState edge and no direct ApplyPhysicsState edge;
  • the #270 movement-stats contract reflects the single StaminaExhaustionEdgeTracker owner and follows the compiled Observe, ReportExhaustion, Reset, and two factory Apply edges. Existing tracker and Runtime movement-state behavior suites remain the behavioral oracle;
  • remote spawn settling now identifies both compiled call sites (DispatchRemoteInboundMotion and OnPosition), verifies the repeated inbound route checks PhysicsBody.InContact before reseeding, and verifies the shared seed helper calls SpawnPlacementSettler.TrySettle;
  • production auto-entry readiness now follows compiled calls to the published controller, live-record lookup, and physics-host view and verifies the exact EntityPhysicsHost type operand; and
  • player presentation attachment now verifies compiled call order from the animation sink assignment through matched animation drain to the unmatched interpreter suffix drain.

CompiledCallGraph gained reusable instruction and type-reference readers. They allow exact return and isinst/cast boundaries to be checked without making comments, whitespace, local names, or source paths part of the oracle.

Verification:

  • the directly affected and adjacent behavioral App suites pass 31/31, and the two Runtime owner suites pass 52/52;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate passes 14,347/14,347 with zero skips or failures across all 12 test assemblies. The exact two-case reduction is the two redundant source assertions above; and
  • the regenerated 1,254-file inventory parses every file, reports 11,415 attributed methods, and reduces total direct/helper source readers from 92 to 83 while direct readers remain 57. The remaining 83 reconcile to the 22 approved retained policies/contracts and 61 staged replacements.

Batch Z composition-root source-freeze replacement

Batch Z converts 12 approved source-text readers across the seven graphical composition-owner suites and removes one stale backend assertion. No product source changes. The replacement tests use the built call graph, reflected owner metadata, existing transactional fixtures, and typed composition results instead of source fragments.

The exact decisions are:

  • all seven phase-boundary tests now prove that GameWindow constructs exactly one instance of the relevant composition phase and does not directly construct the leaf owners that belong behind it. The phase and snapshot types are also checked for the absence of a retained GameWindow owner;
  • the platform prelude now verifies the compiled OnLoad route through AcquirePlatform and GameWindowCompositionPipeline.Run, plus the single GameWindowPlatformAcquisition.Acquire and host/input/camera phase edges;
  • the prepared-asset contract follows the production factory, world phase, ObjectMeshManager, WbMeshAdapter, and compiled shutdown manifest. It proves one IPreparedAssetSource owner, no DAT-reader constructor seam in the production mesh manager, prepared reads rather than live mesh building, and mesh/prepared-source/DAT release order;
  • the frame-root test follows the compiled construction order from render resources and comparison state through the world/update roots, graph publication, window publication, and final ownership transfers. The lifecycle snapshot contract now verifies its exact RenderFrameOutcome input and its typed live-entity, GPU-memory, profiler, and landblock metrics;
  • the session phase follows the compiled streamer/start/reveal route and the delegate target that constructs the request streamer. Its completion check follows hydration, inbound routing, input/player mode, portal transfer, session creation, command bindings, action attachment, and final publication in order. Character selection now verifies the graphical selector option, typed connect options, absence of automatic first-character selection, and retained-UI runtime bindings;
  • the interaction, live-presentation, and world-render boundaries retain their existing behavioral phase fixtures while compiled metadata guards against construction leaking back into GameWindow; and
  • PortalSpaceIsComposedOnBothBackendArms is removed as stale. Campaign V deleted the OpenGL backend, so a two-backend-arms source condition is no longer an architectural contract; its negative assertion named an already deleted null presentation. The valuable portal ownership rationale remains in the live/session composition code, the compiled portal transfer order, and the existing teleport/reveal behavior suites.

Verification:

  • all 187 composition tests pass with zero skips or failures;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate passes 14,346/14,346 with zero skips or failures across all 12 test assemblies. The one-case reduction is the stale two-backend-arms assertion; and
  • the regenerated 1,254-file inventory parses every file, reports 11,414 attributed methods, and reduces direct/total source readers from 57/83 to 44/70. The remaining 70 reconcile to the 22 approved retained policies/contracts and 48 staged replacements.

Batch AA Runtime-root and crash-status source-freeze replacement

Batch AA converts the three approved Runtime-root/session-host freezes and the three crash-status freezes. No product source changes and no test is removed.

The canonical-root checks now scan compiled App metadata rather than C# text: GameWindow constructs exactly one GameRuntime, acquires its one host lease, and constructs none of the displaced Runtime child roots; the entire App assembly contains exactly one LiveSessionCommandSurface construction edge. The character-creation status regression follows the compiled delegate targets created by LiveSessionRuntimeFactory.Create and verifies the exact Guid/Name and RawCode/Reason/AttemptedName property-to-writer call order. The existing Runtime SessionStatusWriter suite remains the payload-shape oracle.

The #406 crash regression now inspects the built GameWindow.Run and ReportExited methods. It proves the native frame-loop call precedes cleanup retention, the _runFailure store precedes rethrow, the failure read precedes all terminal paths, the three crash/graceful/incomplete writer calls and their literals retain their order, and both shutdown exits funnel through the one reporting method. Reflection verifies the nullable exception latch exists and that neither constructor assigns it, preserving its default-null state. CompiledCallGraph gained a reusable field-load/store reader so latch ordering can be checked by IL offset without pinning field expressions or formatting.

Verification:

  • all 15 focused Runtime-root/session-host/crash-status methods pass;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate remains 14,346/14,346 with zero skips or failures across all 12 test assemblies; and
  • the regenerated 1,254-file inventory parses every file, remains at 11,414 attributed methods, and reduces direct/total source readers from 44/70 to 41/64. The remaining 64 reconcile to the 22 approved retained policies/contracts and 42 staged replacements.

Batch AB render-leaf and frame-handoff source-freeze replacement

Batch AB converts all nine approved GameWindowRenderLeafCompositionTests source readers. No product source changes and no test is removed.

Private presentation, resource preparation, world/private/diagnostic routing, GPU measurement, and immutable outcome construction now follow compiled typed calls in their production order. The portal-tunnel check follows the compiled session transfer/bind/publication path, both local teleport factory targets, the session-before-frame phase references in OnLoad, and the exact frame-root borrower construction order. OnRender now proves its single GameFrameGraphSlot.Render handoff and absence of the five displaced leaf field reads directly from the built method.

The broad legacy-owner blacklist is narrowed to what it actually protects: reflected GameWindow fields and methods reject the displaced owners, while compiled composition metadata positively locates paperdoll, frame-resource, weather, private-presentation, orchestrator, frame-pacing, and mouse-capture ownership behind their focused types. Shutdown ordering uses the compiled operation/stage labels. Terrain diagnostics are constructed with the scene executor but not driven directly by the frame root.

The optional paperdoll contract is stronger than the old source-expression match: compiled branch destinations prove that either a missing viewport or a missing inventory frame jumps past PaperdollFramePresenter construction. CompiledCallGraph gained a reusable branch-target reader for this kind of optional-dependency guard.

Verification:

  • all nine focused render-leaf methods pass;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate remains 14,346/14,346 with zero skips or failures across all 12 test assemblies; and
  • the regenerated 1,254-file inventory parses every file, remains at 11,414 attributed methods, and reduces direct/total source readers from 41/64 to 39/55. The remaining 55 reconcile to the 22 approved retained policies/contracts and 33 staged replacements.

Batch AC graphical-host and lifetime source-freeze replacement

Batch AC converts all nine approved GameWindowHostBoundaryTests source readers. No product source changes and no test is removed.

Startup now follows the compiled settings snapshot, frame-pacing, native window, callback-target, callback-binding, attachment, and frame-loop edges. The callback delegate targets retain their exact load/update/render/closing/ focus/resize order without treating local names, comments, or nested argument spelling as behavior. OnLoad phase ordering is recovered from its compiled delegate targets, while frame-root and session-player completion checks follow their typed construction, binding, attachment, publication, and transfer edges.

The remaining owner checks reflect the one WorldEnvironmentController and RuntimeSettingsController, reject their displaced window mirrors, and follow environment routing, settings startup/runtime binding, terrain-atlas acquisition, input-action attachment, and framebuffer-resize publication through the built methods. Focus, update, render, close, and dispose are verified as narrow handoffs. In particular, the render check uses semantic IL execution order—window size, immutable input construction, then graph render— rather than the misleading lexical order of a nested source expression.

Shutdown now uses reflected root types, field stores, built call order, and the compiled manifest's stage/operation labels. It preserves the twenty-stage dependency order, plugin transfer before startup, ingress cleanup ordering, Runtime/UI/resource release boundaries, TryComplete before native-window release, and the final _window clear after the shared shutdown funnel. A label such as input context may legitimately identify both an operation and its stage; the replacement therefore verifies dependency order instead of mistaking duplicate human-readable labels for duplicate ownership.

The old checks for HostInputCamera local if spelling are retired rather than translated. HostInputCameraCompositionTests already exercise the complete production acquisition and every fault boundary; the names and arrangement of compiler locals are not part of the host contract. All valuable ownership, ordering, and cleanup rationale remains in the compiled guards above.

Verification:

  • all nine focused graphical-host/lifetime methods pass;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors;
  • the no-retry complete hermetic Release gate remains 14,346/14,346 with zero skips or failures across all 12 test assemblies; and
  • the regenerated 1,254-file inventory parses every file, remains at 11,414 attributed methods, and reduces direct/total source readers from 39/55 to 32/46. The remaining 46 reconcile to the 22 approved retained policies/contracts and 24 staged replacements.

Batch AD frame orchestration and resource-preparation replacement

Batch AD converts all fourteen approved source readers in RenderFrameResourceControllerTests and UpdateFrameOrchestratorTests. No product source changes and no test is removed.

The three render-resource checks now inspect built call and field-store order. They preserve the texture/dispatcher/environment/portal/clip/terrain/lighting begin sequence, mesh publication before reveal evaluation and particle begin, and weather evaluation before the elapsed-clock commit. The existing recording phase test continues to exercise the public prepare sequence and one GPU-slot read behaviorally; source comments and local expressions are no longer part of the oracle.

The update-frame replacements retain the full accepted phase graph and its existing behavioral fake trace, then use compiled metadata only for production wiring that cannot safely be invoked without a real session or window:

  • the physics script clock has one typed publisher behind FrameRootCompositionPhase and no GameWindow publication edge;
  • live-object, static-animation, effect, particle/script, and spatial-reconcile calls preserve their registered adaptation order and exact-once tails;
  • streaming precedes the live coordinator, whose inbound session and placement retry precede command and spatial reconciliation on both available and quiesced behavioral paths;
  • session/frame composition constructs the live-object, spatial, streaming, gameplay-input, teleport, liveness, auto-entry, camera, and update owners, while reflected fields and compiled window calls reject the displaced bodies;
  • focus loss, player-mode exit, and teleport start retain their typed mouse-look cleanup edges, including freshness validation before input cleanup and Runtime transit commit afterward;
  • player presentation attachment retains Runtime-publication validation, camera/shadow/host/mode order, and both cleanup routes; mouse filtering and typed movement-input seams are checked from method and constructor metadata; and
  • camera sampling/reconciliation and the thin OnUpdate profile-to-graph handoff remain ordered, while live-session event and world-origin consumers stay behind their focused typed owners without GameWindow back-references.

Where construction happens inside acquisition or transfer delegates, the tests follow the compiled delegate target before inspecting its child edge. This preserves real execution ownership without reverting to lexical source order across nested expressions.

Verification follows the user-approved proportionate policy for the remaining R3 work:

  • all 34 focused frame/resource methods pass;
  • the complete AcDream.App.Tests hermetic lane passes 5,381/5,381 with zero skips or failures;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors; and
  • a targeted scan confirms neither owning test file retains a source reader or its source-slicing helper. The final full inventory and twelve-assembly Release gate are intentionally deferred to the one R3 closeout run.

Batch AE Runtime gameplay-owner wiring replacement

Batch AE converts the nine approved consumer-wiring source readers across RuntimeActionOwnershipTests, RuntimeCharacterOwnershipTests, RuntimeInventoryOwnershipTests, and RuntimeMovementOwnershipTests. No product source changes and no test is removed. The two approved whole-tree construction policies—one action-owner policy and one movement-owner policy— remain source-aware by design and are not part of the 85 staged replacements.

The replacements use reflected fields, properties, constructor parameters, compiled child access, and shutdown-root metadata to prove that:

  • retained UI, session composition, graphical command adapters, and item interaction borrow the canonical action children and the exact Runtime transaction owner, with no App InteractionState or UI-side transaction construction;
  • GameWindow owns one GameRuntime, constructs no character child root, and projects its Spellbook/LocalPlayer properties through RuntimeCharacterState; content installation, session routing, retained UI, options, and movement-skill updates all consume that owner;
  • the deleted App character-option and movement-skill owner types remain absent, while Runtime's option replacement and movement-skill update edges remain live;
  • GameWindow constructs none of the displaced inventory/item-mana/container/ shortcut snapshot owners; retained UI and item interaction use the Runtime action transaction, session bindings use the Runtime shortcut store and use completion, and shutdown carries only GameRuntime;
  • ToolbarController retains the exact ShortcutStore without constructing a mirror, provider delegate, or loaded-state latch, and spell UI has no second local mutation calls for filters, desired components, or favorites; and
  • graphical input, both runtime adapters, and both shutdown roots borrow the exact RuntimeLocalPlayerMovementState, including its autorun and typed command execution edges.

CompiledCallGraph.ReadOwned was added as a test-only metadata facility. It reads declared owner methods plus compiler-generated acquisition/callback closures, so a typed dependency carried by a UI factory remains inspectable without freezing the lambda's source spelling.

Verification follows the proportionate R3 policy:

  • all 11 focused ownership methods pass, including the two retained whole-tree policies adjacent to the nine replacements;
  • the complete AcDream.App.Tests hermetic lane passes 5,381/5,381 with zero skips or failures;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors; and
  • a targeted scan finds source reads only in the two explicitly retained whole-tree policy methods. The final inventory and twelve-assembly Release gate remain deferred to closeout.

Batch AF create-authority drift-model contract replacement

Batch AF converts the final approved test-model/source correspondence check. CreateAuthorityDriftModelSourcePinTests is renamed to CreateAuthorityDriftModelContractTests; its descriptive test method HandCalledDriftProbe_StillModelsTheExecutorDrainAdvance is retained. No product source changes and no test is removed.

The replacement no longer regexes two Runtime files. It inspects compiled Runtime metadata and proves:

  • ApplyWeenieDescriptionAction applies the accepted description, refreshes the canonical snapshot, advances create authority exactly once, and then advances the executor baseline in semantic execution order;
  • RegisterEntityCore still has the named Boolean initial-residence input, refreshes the ordinary existing-generation snapshot, and places the one registration-time authority advance behind a conditional branch that skips over the call; and
  • the Runtime assembly contains exactly those two call sites targeting RuntimeEntityDirectory.AdvanceCreateAuthority: the modeled executor drain and the gated ordinary registration route.

This is the stale-model alarm the source regex intended, but it now survives comments, whitespace, local renames, and equivalent expression refactors. The expectation-item 6/8 probe comments in the hydration and supersession suites now say metadata-pinned and name the new contract class, preserving the rationale without leaving misleading source-pin references.

Verification follows the proportionate R3 policy:

  • the contract plus its hydration and supersession behavior suites pass 90/90;
  • the complete AcDream.App.Tests hermetic lane passes 5,381/5,381 with zero skips or failures;
  • the complete locked Release build covers all 44 projects with zero warnings and zero errors; and
  • targeted scans find no source reader in the renamed contract and no stale source-pin comment in the affected tests. With this batch, all 85 approved replacements are implemented; final inventory reconciliation and the one complete Release gate follow next.

R3 closeout

R3 closes on implementation commit 14d371a0. The final Roslyn inventory and the one complete Release gate both ran from that clean commit; this closeout is the only later documentation change.

The final inventory parses all 1,254 tracked C# test files and attributes 11,414 test methods. It finds 21 direct source readers and 22 readers in total. Those 22 reconcile exactly to the approved retained boundary:

Retained disposition Methods Reconciled owners
Whole-tree architecture policy 17 LinuxPlatformBoundaryTests (5), RenderSceneArchitectureTests (2), RuntimePhysicsOwnershipTests (4), RuntimeEntityOwnershipTests (2), and one each in RuntimeActionOwnershipTests, RuntimeMovementOwnershipTests, RuntimeWorldTransitOwnershipTests, and RuntimeDatAccessArchitectureTests
Cross-artifact source/project contract 5 ParticleBindlessInstanceTests (1), PerformanceToolsTests (1), and LauncherProjectBoundaryTests (3)

The original corrected inventory's equation therefore closes without an unclassified reader: 107 source readers = 85 replaced implementation/test- model freezes + 17 retained architecture policies + 5 retained cross-artifact contracts. Three of the 85 replacements removed a redundant test because an existing stronger behavioral oracle already covered the claim; the other 82 kept a test and changed its evidence seam.

The other approved boundaries also reconcile:

  • Batch V deleted exactly 28 attributed self-tests: 17 widget-recorder tests, nine main-menu-recorder tests, and two positional-record tests. All three approved files remain absent.
  • FakePanelRenderer remains. The retained behavior boundary is exactly 23 attributed methods and 29 expanded cases: 22 ChatPanel layout/input/focus methods plus the ChatVMCombatTests render-path method.
  • The issue taxonomy remains descriptive: 47 Issue###...Tests.cs files and all 155 attributed methods remain, with every filename carrying a behavior suffix after its issue number.

R3 changed no product behavior. A diff from starting commit 8e884679 contains eight src/ paths, all previously reviewed testability/documentation seams: two comment-only test-name updates; deterministic clock injection for input and streaming whose public production construction still selects the same system clock; nullable launcher contention callbacks that production leaves unset; and one test-assembly InternalsVisibleTo. No shipping default, ownership, algorithm, protocol, or presentation path changes.

Final verification at clean implementation commit 14d371a0:

  • locked Release restore and build: 44 projects, zero warnings, zero errors;
  • complete hermetic Release gate: 14,346 passed, zero skipped, zero failed, across all 12 default test assemblies; and
  • durable ignored evidence: artifacts/test-audit/test-inventory.json and artifacts/release-gate/release-gate-summary.json, with logs, TRX files, environment capture, and SHA-256 manifest beside the gate summary.

Every R3 decision is now represented by the batch ledger above, the final inventory agrees with every approved count, and no cleanup item remains open.