QA sweep: three silent leaks, and cut the overzoom raster cost in half #37
Labels
No labels
agent
agent:ci
agent:done
agent:failed
agent:needs-input
agent:refined
agent:refining
agent:running
agent:shipped
agent:skip
autonomous
autopilot
driven
local
plan
proposal
qa
qa-gap
research
retro
ship
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
jeroen/cartopolis#37
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
A four-agent QA + efficiency sweep of viberfox (three read-only lanes plus the
simulator lane) found defects and waste across the simulator, the tile pipeline
and the client's per-frame path. The simulator had never been touched by any of
the 18 prior
perfcommits.The sweep also confirmed the codebase is in good shape: all 7 invariants
documented in CLAUDE.md's "Known issues / workarounds" still hold in code —
the egui panel
.chain(), matching shadow cascades, derivedPROTOCOL_VERSION,avatar ground height across its three sites, fall/climb rates across three,
text_edit_focusedkeyboard gating, and the Android cfg seams.Approach
Landed on this branch, 7 commits. Every behavioural fix has a test that fails
without it (verified for the avatar leak by reverting the fix).
crates/simulator/src/net.rs:194— 23 bare?in the incoming-frame armreturned out of
handle_connection, jumping over the teardown. One malformedframe from an authenticated client leaked its avatar, which
state.rs:218then broadcast to every client at the tick rate for the life of the process.
crates/viberfox/src/platform/stream.rs:224—forgetdropped a key fromrequestedbut left it in the dispatch queue, so a re-request enqueued asecond copy. Both dispatched, one released; the concurrency cap shrank
permanently. Fatal where the cap is 1 (far buildings vs. public Overpass):
the lane dies silently and
busy()never quiesces.crates/geo/src/vector_tiles.rs:441— the overzoom loop built and strokedevery feature of the source tile regardless of the sub-tile window. Measured
on the Groningen fixture: z17 84.9 -> 41.0 ms/tile, z16 123.1 -> 78.5 ms.
179 of a fresh anchor's 424 requests are overzoomed.
crates/geo/src/routing.rs:1686—corridor_tiles_atwalked the fullbounding box (~3e7
hypotiterations for an intercontinental pair) beforerefusing, contradicting its own doc comment.
crates/viberfox/src/lib.rs:3100— the rain shell drew a full-viewportblended pass with three noise octaves per fragment when dry.
crates/viberfox/src/systems/player/avatar.rs:717— two allocations peravatar per frame before the early-out that skips single-holder avatars.
Notes updated in place:
tile-raster-cost.md(the overzoom cause + measurement)and
wasm-performance.md, whosecheck:line had become a false green —it matched only the comment saying the file was no longer a
Valuewalk.Acceptance criteria
cargo testgreen: 273 viberfox, 94 geo, 19 core, 16 simulator, 14 big_spacecargo check --workspace --all-targetspassescargo fmt --checkpasses across the five owned cratescargo shotson a workstation confirms rain still renders at--rain 1Verification
cargo check --workspace --all-targets,cargo test -p viberfox_geo,cargo test -p viberfox,cargo test -p viberfox_simulator,cargo test -p big_space --lib.The overzoom cull's gate is
culling_off_screen_features_changes_no_pixels,which renders seven sub-tiles across factors 2/4/8 with the cull on and off and
asserts byte-identical rasters — that is what pins the stroke-reach margin.
bench_overzoom_cull(ignored) reproduces the timing table.Needs a machine with a GPU: the rain change is visually unverified. This
container has no Vulkan driver, so
--rain 1cannot be rendered here. The logicmirrors
update_cloudsin the same file exactly.Out of scope — follow-up tickets
SimWorld::observeris one global field, last-writer-wins across allconnections (
state.rs:34,net.rs:214). A second client 500 m away emptiesthe first's AoI; a NaN position empties it for everyone.
discards after the first snapshot (
network.rs:374). Same restructure as theobserver fix; changes wire semantics, so it needs a
PROTOCOL_HISTORYrow.DeletePrimany prim (net.rs:225), sessiontokens have no TTL/revocation and never re-check
disabled(auth.rs:102),and the pre-auth hello read has no timeout (
net.rs:89).platform/workers.rs:149—PAUSED/PARKEDare checked and pushednon-atomically, which can strand a job for a whole
--shotrun.Branch:
perf/37-qa-sweep-leaks-and-overzoom