Status: Phase 0 foundations and Phases 1 through 4 are complete. The normal no-argument product launch decodes and validates the product-owned campaign and perk YAML, opens the campaign startup gate, runs all 27 ordinary positions through position 29, and stops at AwaitingPhase5. --campaign-showcase remains a compatibility alias for that same authored campaign; --single-encounter explicitly selects the unchanged Phase 3 acceptance surface. That sandbox remains one product-owned finite encounter with five deterministic packs, 29 top-level tokens, all six top-level ordinary hostile roles, and four canonical mini-splitter descendants. It exercises the existing off-screen placement, activation, role authority, local avoidance, relevance, catch-up, recycling, token liability, legitimate completion, copied presentation, and in-window replay systems. Safety-valve resolution, directional surges, rewards, bosses, audio, final release balance, and release packaging have not begun.
Phase Progress
| Phase | Status | Boundary |
| Phase 0 | Complete | Product ownership, deterministic core, headless execution, interactive composition, and HUD foundation |
| Phase 1 | Complete | Boundless movement, origin rebasing, dash, camera, resize, and world presentation |
| Phase 2 | Complete | Weapons, projectiles, collision, damage, resources, and pickups |
| Phase 3 | Complete | Seven ordinary hostile roles and the representative encounter sandbox |
| Phase 4 | Complete | Runtime-authored campaign, perks, drafts, checkpoints, replay epochs, run UI, and Gate C structural/systems acceptance |
| Phase 5 | Not started | Begins with the lockfield, boss scheduling, and Core; bosses and positions 30/31 are unavailable |
| Phase 6 | Partially pre-implemented | Camera shake, accessibility, and bounded presentation effects exist; final VFX and audio do not |
| Phase 7 | Substantial foundations | Determinism, bounded storage, diagnostics, replay, automated acceptance, and performance evidence exist; balancing, packaging, and release hardening remain |
Phase 4 Gate C Acceptance
Gate C is passed for boundless campaign viability, deterministic ordinary-wave progression, campaign/perk/draft/checkpoint/replay/UI integration, ordinary product-resource viability, mechanically differentiated builds, bounded execution/storage, and the absence of a severity-high unresolved Phase 4 authority defect. It is not acceptance of final balance, final visual clarity, final campaign intensity, boss viability, or release readiness.
Accepted nonblocking follow-up findings are:
- late Act III feels underpopulated and spatially modest;
- Chain Burst and ricochet feedback are understated;
- Magnet Field lacked observable pickup coverage in the accepted late segment;
- Stasis lacks a distinct readable boundary;
- Phoenix was not naturally triggered in the accepted durability segment;
- the post-terminal focus/diagnostics restart incident remains unconfirmed; and
- richer camera, shield, aim, VFX, audio, and controller feedback remain later presentation work.
Phase 5 begins with the lockfield, boss scheduling, and Core. Boss authority and playable positions 30/31 remain unimplemented. Audio, final VFX, final balance, packaging, and release hardening remain later work.
The GDD is normative product intent, not evidence that every proposed system or example type exists. No pre-product blocker remains: Phase 0 is complete, and missing product-owned systems are implementation work in their own GDD phases.
Manual Playtest Correction
The first native Windows playtest exposed a presentation and input-observability problem that deterministic headless tests could not show. The Arena HUD manifest registered no font while the document declared no inherited family, so every text update emitted RmlUi missing-font warnings and the HUD appeared blank. The product binary now carries only the existing shared IBM Plex Sans Regular asset, registers that one face before document loading, and applies it at the document root. Startup and sustained runtime tests reject either missing-font warning.
Player movement tuning schema 2 selects 6.75 WU/s maximum speed, 2.25 WU/s per tick acceleration, 3.375 WU/s per tick braking, and 6.0 WU/s per tick reversal. That reaches maximum speed in three fixed ticks, rest in at most two, and a full reversal in three. From rest, the logical camera reaches the edge of the 45-WU vertical play span in approximately 3.35 seconds. Run configuration schema 16, authoritative checksum schema 19, and execution replay schema 18 record the revised tuning and explicit defeat lifecycle.
The sustained-upward report was not an authoritative coordinate or rebase stall. The warning flood could stall presentation, while a focus-loss reset intentionally suppressed a physically held movement key until a clean release/repress without making that state visible. Focus suppression now lives in the common Arena input adapter used by native and synthetic paths. Focus loss stages neutral movement; focus recovery continues to suppress held input until release. Synthetic interactive tests hold W and Up for 1,200 authoritative ticks across multiple rebases and cover release/repress, focus recovery, vertical transitions, cardinal directions, replay, headless, and 30/60/144/irregular presentation schedules.
Logical world coordinates now have one explicit convention: +X is right and +Y is up. W/Up and S/Down map to +Y and -Y respectively, and the top-left native cursor is converted once at the input boundary so cursor-above produces +Y logical aim. The observed inversion came from the Arena runtime view omitting the Vulkan projection Y flip already used by the engine's extracted views. The corrected runtime projection applies that flip once for all player, projectile, hostile, grid, marker, and shake presentation. Framebuffer cursor coordinates also account for native content scale before viewport-local aim resolution.
Lethal player damage now finishes the current canonical tick, emits exactly one role-owned player-death event, neutralizes movement/dash/held fire, and changes the authoritative run state from Running to Defeated. No later fixed tick, encounter admission, relevance, movement, fire, collision, or director advancement occurs until restart, while application, RmlUi, and copied presentation updates continue. The compact Defeated overlay exposes R — RESTART and ESC — EXIT; R is edge-triggered and resets the existing configured session and seed without replacing the native window or renderer. Reset clears authoritative and presentation transients through the established reset contracts, then gameplay input remains suppressed until a clean physical release/repress. F1 now shows physical movement keys, screen-relative cursor aim, logical aim, focus, and suppression state. A bounded blue armor-hit or red health-hit ring and restrained defeated player pose provide copied, presentation-only damage awareness.
The layer now retains adjacent authoritative observations and applies the existing accumulator alpha only to camera/world, projectile, and stable-ID actor presentation. The player remains exactly centered, aim remains based on the unshaken logical center, rebases interpolate in persistent logical coordinates, and new/reused or implausibly displaced actor identities snap instead of blending. The default HUD is compact and shows only immediate vitals, weapons, dash, and encounter state. F1 reveals sampled/staged/consumed movement, authoritative motion, interpolated camera, fixed ticks, pending quanta, clamp counts, focus, and suppression state. Layered player/aim geometry, role outlines, subdued grid contrast, and neutral ambient markers improve the current primitive playtest without changing collision authority.
The production presentation pass replaces the oversized solid player and remaining solid hostile blocks with compact dark-interior silhouettes, thin role-colored outlines, restrained local glow, sharper bounded projectiles, smaller environmental markers, and protected negative space around the player. The default HUD now uses a small top-left pilot/readiness group, a top-center encounter strip, and a bottom-edge F1 hint; it exposes no invented score, wave, or campaign state. Runtime render preparation clears and reuses its retained sprite storage instead of replacing the complete render-data object every presentation frame. F1 copies bounded preparation timing, sprite-count, capacity, and storage-growth high-water diagnostics without feeding authority.
The product still owns exactly one configured finite encounter and does not advance to another encounter, wave, or campaign state. Resolved is presented as legitimately complete only after pending and in-play tokens, active threat, active hostiles, unresolved descendants, recycle-queued hostiles, and hard-stalled hostiles are all zero. At that boundary, zero active threat is the expected result: the default status and compact overlay read ENCOUNTER RESOLVED, with R — REPLAY ENCOUNTER and ESC — EXIT. The edge-triggered R path reuses the existing in-window session reset and configured seed policy, restores player resources, and clears authoritative and copied transients without replacing the native window or renderer. It reconstructs the same encounter; it does not create progression.
F1 pacing diagnostics now distinguish successful present-to-present interval from application-loop interval and CPU stage timings. The former Frame cadence field recorded the elapsed value delivered to the Arena layer, so debug validation, event-loop blocking, resize/focus activity, swapchain recreation, and device-idle waits could all enter the same percentile window. The replacement uses fixed reusable histograms and separately records focused steady gameplay, platform move/resize/swapchain activity, and focus-loss/minimized suspension. F2 resets the measurement window on a key edge. Focused samples expose count, average, p50, p95, p99, maximum, achieved presentation rate, fixed ticks per presented frame, clamp/discard totals, stage timings, and bounded timing/presentation storage. Platform and suspended samples remain visible but do not enter focused percentiles.
Move/resize callbacks no longer emit one normally enabled log entry per position or size notification. Per-frame saturated callback counts provide the bounded classification signal. A platform-activity or suspended frame advances no Arena authority, and the interactive frame clock is rebased after swapchain reconstruction, so recovery resumes from the next logical delta without a catch-up burst. Replay, checksum, and headless execution remain presentation-independent.
Phase 3 operator visual acceptance is complete. Enemy speed/readability balance remains subject to later content balancing; no complete-wave, reward, perk, boss, audio, or campaign work is included here. Representative release performance gates across supported GPUs, refresh policies, and long-run content loads also remain future performance debt; the local F1 sampling contract is diagnostic evidence, not a release certification matrix.
Product ownership exists under products/boundless_vector_arena. //products/boundless_vector_arena:arena_core is the stable product facade for the presentation-independent deterministic session, player-movement, and dash kernel, and //products/boundless_vector_arena:session_execution is the product-private headless execution facade over that core. The genuine interactive composition root exists at //products/boundless_vector_arena:boundless-vector-arena, with an explicit product-owned runtime closure containing the minimal RmlUi HUD document and stylesheet. Logical coordinates, movement, aim, and dash now exist in the authoritative core; product-owned platform input and centered player/world presentation consume only recorded commands and copied observations. Supported aspect/resize handling and presentation-only camera shake now close Phase 1. Versioned logical fire commands, a finite-capacity projectile simulation, and product-owned interactive fire/projectile presentation start Phase 2. A bounded product-owned target, broadphase, collision, damage, and death kernel now supplies presentation-independent combat authority. Phase 3 adds bounded Runner, Shooter, Charger, Kamikaze, Splitter, mini-splitter, and Tank role partitions that reuse target identity, position, radius, health, projectile damage, and death rather than duplicating them. Gamepad input, debug rebase controls, safety-valve resolution, production waves, directional surges, bosses, final authored perk tuning, rewards, audio, replay-file persistence, distribution packaging, and release readiness do not exist.
Reusable PixelBullet Capability
| Current capability | Reuse boundary |
| Application bootstrap, application specification, layer lifecycle, input, window, timing, logging, and platform services | Hosts the Arena composition root; Arena still owns session rules and lifecycle. |
| Scene/ECS storage, authored scenes and prefabs, typed serialization, YAML node IO, and asset dependency validation | Provides reusable data and entity foundations; does not define Arena schemas or deterministic run state. |
| @assets/@shared resolution with an application asset base | Provides the required alias distinction. Arena's product-local HUD closure exists, and BulletSketch can select its root generically with --asset-base <application-root>. |
| Vulkan rendering, DXC-to-SPIR-V shader pipeline, sprite extraction, and graphics diagnostics | Existing public sprite rendering draws the centered cyan player and bounded gold primary/scatter projectile presentation. Arena owns its camera model, origin seam, grid/marker/projectile geometry and budgets, and presentation effects. |
| RmlUi surfaces/data-model integration and miniaudio-backed audio resources | The public runtime-UI facade hosts the product-owned campaign HUD, draft, pause, checkpoint, defeat, and terminal panels. Cue policy, captions, richer feedback, and any justified audio use remain later product work. |
| Jolt integration | Available for optional presentation or later variants; the GDD does not require it for authoritative Arena combat. |
| framework/scene_play locomotion, interaction, inventory, progression, combat/loadout, weapon-presentation, behavior, and runtime inspection capabilities | Useful reference and possible later extraction sources; the current scene runtime is authored-scene-oriented and variable-delta, not Arena's deterministic session core. |
| BulletSketch Play in Viewport and Run Standalone | Existing authored-scene workflows now use a validated explicit product asset base when selected; Run Standalone forwards the canonical selection to the generic scene runner. |
| Bazel-first toolchains, repository policy/audit suites, unit/integration conventions, smoke lanes, and documentation builds | Provides delivery and proof infrastructure. Core, headless, input, presentation, interactive-equivalence, binary/asset, and repeated first-frame startup proofs are registered in the established lanes. |
Phase 0 Work
The five bounded Phase 0 foundation slices are complete. The interactive root owns product session and presentation lifecycle directly; none of that authority was moved into the generic scene runner.
The bounded implementation sequence is:
- build(arena): establish product ownership and asset boundary — complete
- Established the product Bazel root and an explicit product-local runtime asset closure, subsequently populated only by the Phase 0 HUD files.
- feat(editor): support selectable authoring asset bases
- Complete. BulletSketch accepts --asset-base <application-root>, isolates asset-bearing authoring state by canonical root identity, and preserves Play in Viewport and Run Standalone responsibilities.
- feat(arena): add deterministic run-session core
- Complete. Added the product-owned lifecycle, versioned configuration and fixed-tick command records, exact 60 Hz tick contract, isolated RNG streams, authoritative checksum, diagnostics, reset, and teardown.
- test(arena): add headless execution and observability
- Complete. Added product-owned noninteractive execution, exact integer fixed-step accumulation, deterministic presentation-schedule proof, bounded diagnostics/checksum observations, and in-memory replay capture and consumption without renderer, UI, audio, or VFX authority.
- feat(arena): establish interactive composition root
- Complete. Added the genuine product executable over the existing execution driver, application/layer lifecycle, copied read-only HUD model, product-owned RmlUi assets, interactive/headless authority-equivalence proof, and repeated startup through the first successfully presented frame.
These slices state bounded outcomes, not immutable file, class, or target layouts. Phase 0 design may refine concrete names while preserving ownership and acceptance intent.
The Phase 0 foundation acceptance gate is satisfied by the deterministic core, headless execution, interactive authority-equivalence, explicit HUD asset closure, lifecycle teardown, and first-presented-frame startup proofs.
Phase 1 Work
Five bounded Phase 1 slices are complete.
feat(arena): add logical world and player movement core established normalized signed chunk/local 2D positions, deterministic player velocity and movement, versioned tuning, exact signed 1/60 integration remainders, fixed-tick movement commands, and cadence-invariant replay/checksum proof. No ECS was introduced.
feat(arena): add interactive input centered camera and player presentation adds the following bounded surface:
- action-oriented WASD and arrow mapping with opposite cancellation and a synthetic input seam; platform sampling never writes authority directly;
- next-tick command staging for interactive movement and aim, including focus-loss/reset neutralization so movement cannot remain latched;
- deterministic Q1,000,000 aim derived from cursor minus current logical viewport center, with a configurable center dead radius, last-valid-direction retention, and finite/zero-length guards;
- an exact-centered presentation camera whose logical position equals the authoritative player position, with no dead zone, damping, velocity/aim look-ahead, shake, or large raw logical coordinates in shaders;
- a centered cyan geometric body and short aim stem through existing public sprite rendering over the restrained dark background, with RmlUi remaining HUD-only; and
- copied position, velocity, and aim HUD diagnostics plus deterministic interactive-command capture and headless replay equivalence.
feat(arena): add origin rebasing and stable world presentation adds the following bounded surface:
- an Arena-owned origin state updated only after movement on each fixed tick, with a default 64 WU threshold and 32 WU alignment while persistent normalized chunk/local player coordinates remain authoritative;
- checksum/reset/replay/cadence coverage for origin position, local player displacement, and revision, with long positive/negative travel and gameplay-RNG isolation proofs;
- a minor/major grid prepared from persistent logical camera phase so rebasing and backtracking cannot move its logical anchors;
- deterministic sparse ambient-marker identities and positions derived by a product-local cosmetic cell hash without consuming or mutating gameplay RNG; and
- bounded CPU preparation and sprite counts through the existing flat-white sprite support closure, with no new shader, texture, product asset, ECS, terrain, or streaming system.
feat(arena): add deterministic dash ability adds the following bounded surface:
- versioned Arena-owned tuning at exactly nine active 60 Hz ticks (0.15 seconds), a 108-tick cooldown (1.8 seconds), and 12,250,000 logical subunits per second, producing exactly 1,837,500 subunits (approximately 1.84 WU) for a cardinal dash;
- a tick-addressed edge request whose direction is sampled once from current nonzero movement, last valid movement, valid aim, then deterministic +X; steering cannot redirect an active dash and dash displacement replaces ordinary movement integration for its nine ticks;
- cooldown beginning on the activation tick, eligibility returning 108 ticks later, deterministic rejection counters during active/cooldown state, and zero exit-grace ticks;
- authoritative dash-active/invulnerability state, replay/checksum/reset coverage, fixed logical-coordinate and origin-rebase integration, and no RNG consumption;
- Space as the initial keyboard binding through an adapter-retained press edge that cannot be lost between presentation frames and fixed ticks, cannot autorepeat while held, and is cleared safely on focus loss/reset; and
- a copied HUD ready/active/cooldown state, a brightened elongated player body, and at most three cyan/white afterimages through the existing sprite support closure.
feat(arena): complete Phase 1 camera and presentation adds the following bounded surface:
- one shared resolved form of the existing Arena logical viewport, preserving the current 45 WU vertical gameplay span across 4:3, 16:9, 16:10, 21:9, and ordinary live resize while wider views expose more horizontal presentation;
- viewport-local cursor conversion against the current unshaken center, exact player centering, safe invalid/minimized/non-finite extent handling, and clean presentation resumption without authoritative mutation;
- viewport-scaled player, dash, grid, and marker presentation with logical grid phase and marker identity preserved across resize, plus bounded preparation;
- a product-owned direct camera-impulse seam whose additive intensity clamps to one, decays by elapsed presentation time, and translates only the rendered world through a deterministic cosmetic wave without using authoritative RNG; and
- focused closure proof across supported aspects, resize during movement, dash, and origin rebasing, logical-versus-rendered camera separation, UI isolation, replay/RNG/checksum invariance, 30/60/144/irregular schedules, interactive/headless equivalence, and lifecycle teardown.
The shake seam is deliberately unconnected until a later product event has a real need for it. Gamepad input remains deferred behind the action boundary. Movement tuning remains an initial product baseline. Debug rebase controls, dash collision/damage, and enemy/encounter semantics remain unimplemented.
Phase 2 Work
feat(arena): add bounded weapon and projectile core starts Phase 2 with the following presentation-independent authority:
- versioned initial primary tuning at an exact 6,600 cadence quanta with 1,000 quanta per 60 Hz tick, producing a deterministic 6.6-tick average interval without rounding the 0.11-second target to a permanent seven-tick cadence;
- versioned primary and scatter projectile definitions, including the initial 14.84 WU/s primary speed, 1.55-second lifetime, 22.5 WU range, six-pellet scatter, one-second cooldown, bounded spread, and finite scatter lifetime/range;
- persistent held-primary and edge-requested scatter commands with addressed tick, ordered replay, atomic malformed/duplicate rejection, valid-aim requirement, and no platform input binding;
- one initialization-time contiguous product-owned pool with a default 2,500 active capacity and 3,000 hard tuning guard, stable monotonically assigned projectile identity, deterministic slot reuse/iteration, atomic shot rejection when capacity is insufficient, and no eviction of active projectiles;
- exact 60 Hz signed fixed-point integration with previous/current logical positions, velocity, accumulated travel, age, definition identity, and origin-local copied observations; origin rebasing changes only the copied local frame and never trajectory or distance;
- deterministic lifetime-first tie handling followed by range retirement, complete reset/teardown clearing, checksum coverage, and a dedicated checksum-covered weapon-spread stream isolated from all other authoritative RNG streams; and
- weapon_projectile_tests plus session_execution_weapon_tests coverage for cadence, release, scatter ordering/cooldown, capacity, identity/slot reuse, finite lifecycle, signed arbitrary-direction travel, rebasing, replay, repeated construction, delayed-frame behavior, and 30/60/144/irregular schedule equivalence.
feat(arena): add interactive firing and projectile presentation adds the following bounded product surface:
- left mouse button maps to held-primary state and right mouse button maps to a retained one-request-per-press scatter edge; only addressed logical commands reach authority, pending edges survive presentation frames until their fixed tick, and focus loss/reset releases primary and clears scatter safely;
- copied projectile observations include stable identity, definition, previous/current origin-local positions, direction, age/lifetime, travel, active count, and configured capacity without exposing mutable authority or persistent large coordinates;
- a capacity-bounded presentation model interpolates read-only projectile positions, draws compact gold primary bodies and smaller orange scatter pellets, prepares short capped trails, and marks the current authoritative position so slot reuse cannot blend unrelated identities;
- accepted shots produce bounded presentation-only primary/scatter muzzle pulses and aim-stem recoil; no physical recoil, camera impulse, audio, or generic VFX/event system was added;
- the diagnostic HUD copies primary held state, scatter readiness/cooldown, active/capacity counts, and capacity rejections; and
- arena_fire_input_tests, arena_projectile_presentation_tests, and arena_phase_two_integration_tests prove input retention/suppression, interpolation, identity reuse, retirement disappearance, rebase/resize/shake separation, bounded preparation, first projectile presentation, teardown, interactive/headless replay equivalence, and 30/60/144/irregular schedule invariance.
feat(arena): add spatial collision and damage kernel adds the following presentation-independent authority:
- versioned initial damageable-target records with stable caller-supplied identity, logical/origin-local position, circular radius, collision filter, maximum/current health, and alive/dead state, provisioned only through run configuration and copied observations;
- a product-owned uniform 2D broadphase with versioned 2 WU cells, sorted signed cell coordinates and target identities, deterministic candidate deduplication, bounded occupied-cell/entry/query storage, and explicit insertion, query, candidate, and overflow diagnostics;
- swept projectile-circle collision over previous-to-current logical trajectories, expanded target radii, quantized earliest time of impact, stable-target-ID tie-breaking, team/mask and dead-target filtering, and deterministic first-hit projectile retirement;
- bounded ordered projectile-hit, damage, health-change, and death events, with health mutated only in the canonical damage-resolution step, exactly one death event, deferred target removal, and explicit non-lossy overflow failure;
- checksum and replay coverage for target state, broadphase-relevant configuration and results, events, diagnostics, and hit retirement, while origin rebasing and general, movement, dash, marker, and weapon-spread RNG streams remain unchanged; and
- spatial_broadphase_tests, collision_damage_tests, and session_execution_collision_tests, plus the Phase 2 interactive/headless integration proof, covering signed cells, capacity, tunneling, exact hit identity/point, stable ordering, canonical damage/death, reset/teardown, replay, origin invariance, and 30/60/144/irregular schedule equivalence.
feat(arena): complete combat-kernel presentation and lifecycle closes Phase 2 with:
- restrained copied-observation presentation for neutral combat dummies, circular collision extent, bounded health indication, authoritative impact rings, once-per-event hit response, and death dissolve; cosmetic effects are bounded, may drop without changing authority, consume no gameplay RNG, and clear independently on reset, teardown, or purge;
- versioned maximum/current player health and armor plus versioned health and armor pickup records with stable identity, logical/origin-local position, circular radius, amount, and finite lifetime;
- an initialization-time bounded pickup pool with deterministic sorted provisioning and first-free slots, exact overlap after a separate bounded uniform-broadphase query, explicit capacity rejection, deterministic collection/expiry, clamping, copied observations, and complete reset/teardown ownership;
- a replayable PurgeCombatTransients command that retires projectiles without hits, clears current hit/damage/health/death events, removes pickups, and clears presentation effects separately while preserving configured target health/alive state and current player resources;
- checksum and replay coverage for resource tuning/state, pickup capacity/identity/lifecycle/broadphase/events, projectile purge retirement, and authoritative purge count; and
- pickup_resources_tests, arena_combat_presentation_tests, the extended session_execution_collision_tests, and arena_phase_two_integration_tests proving signed/rebased pickup coordinates, overlap and near miss, expiry, clamping, first-free reset, purge policy, replay, 30/60/144/irregular schedule equality, interactive/headless equivalence, presentation bounds and de-duplication, first collision/collection feedback, and clean startup/shutdown.
Neutral damageable targets remain non-enemy dummies: they have no AI, movement, attacks, drops, score, rewards, role, encounter token, or wave ownership. Their geometric presentation communicates only current target authority.
Phase 3 Work
feat(arena): add Runner enemy and player damage foundation starts Phase 3 with the following bounded product-owned authority:
- one versioned Runner role mapped one-to-one to an existing DamageableTarget; the target remains the sole owner of stable identity, logical position, circular collision, maximum/current health, projectile damage, alive state, and death, while Runner state adds only role, fixed-tick velocity and integration remainders, active state, and per-source contact cooldown;
- deterministic direct pursuit at the initial 3.28 WU/s bound with signed chunk/local coordinates, zero-distance handling, exact 60 Hz integration, origin-rebase invariance, no all-pairs scan, and no RNG consumption;
- bounded contact candidates from the existing target broadphase followed by exact circular overlap, an initial 20 kinetic damage and 30-tick per-Runner cooldown, dash-invulnerability rejection without cooldown consumption, and attributable contact, player-damage, resource-change, and player-death events;
- player armor absorption before health, explicit alive/dead state, exactly-once death with later same-tick contact suppression, and a minimal dead-player rule that suppresses ordinary movement, fire, and dash authority until reset;
- reset and teardown coverage for player resources, target/Runner state, integration remainders, cooldowns, counters, and events; and
- copied magenta triangular Runner presentation at authoritative radius with readable heading and existing hit/death feedback, kept visually distinct from neutral dummies, plus diagnostic HUD counts for Runners, contact damage, player resources, and player death.
The Runner foundation originally began active immediately. Encounter admission now owns deterministic off-screen placement and the complete activation transition; relevance and recycling remain unimplemented. runner_enemy_tests, session_execution_runner_tests, arena_runner_presentation_tests, and arena_phase_three_integration_tests prove the bounded authority, replay, 30/60/144/irregular schedule invariance, interactive/headless equivalence, presentation transforms, reset/teardown, and RNG isolation.
feat(arena): add Shooter and hostile projectile foundation adds the next bounded product-owned authority:
- one versioned Shooter role mapped one-to-one to an existing DamageableTarget; the target remains the sole owner of stable identity, logical position, circular collision, maximum/current health, player-projectile damage, alive state, and death;
- deterministic fixed-tick approach above 4.5 WU, retreat below 3.5 WU, and restrained target-ID-directed lateral strafe inside the inclusive band, with zero-distance hold, bounded 2.19 WU/s maximum speed, exact signed integration, origin-rebase invariance, no all-pairs scan, and no RNG use;
- an exact 18-tick pre-fire telegraph, aim locked when telegraph begins, 78-tick release-to-release cadence, no catch-up burst, and observable capacity rejection that still advances cadence;
- a separate bounded hostile partition in the existing projectile authority, with shared stable identity, previous/current logical position, finite speed/lifetime/range, source Shooter attribution, atomic no-eviction capacity rejection, deterministic first-hit retirement, and no player-weapon spread RNG consumption;
- swept hostile-projectile collision against the player circle, including no-tunneling motion, dash-invulnerability rejection with projectile retirement, armor-before-health damage, attributable hit/damage/resource events, and exactly-once player death; hostile shots cannot damage targets, and player shots cannot damage the player;
- copied lime square Shooter presentation with heading, telegraph compression and release pulse, compact crimson hostile projectiles with bounded trails and an authoritative-position marker, plus focused Shooter/projectile/player damage HUD diagnostics; and
- checksum, reset, purge, teardown, replay, 30/60/144/irregular schedule, interactive/headless, presentation-transform, and unrelated-RNG isolation proof in shooter_enemy_tests, session_execution_shooter_tests, arena_shooter_presentation_tests, and arena_phase_three_integration_tests.
Encounter admission now places each configured Shooter off-screen and gates its targetability, cadence, telegraph, firing, and dangerous presentation through the shared activation lifecycle.
feat(arena): add Charger and Kamikaze threat roles adds the next bounded product-owned authority:
- separate bounded Charger and Kamikaze role partitions, each mapped one-to-one to an existing DamageableTarget; the target remains the sole authority for stable identity, logical position, collision radius, health, player-projectile damage, alive state, and death;
- a deterministic Charger Approach -> Acquire -> Telegraph -> Commit -> Recover -> Approach sequence: 2.66 WU/s approach, 4.5 WU acquisition distance, one sampled direction with a +X zero-distance fallback, exactly 30 telegraph ticks, 6.9 WU/s no-steering commitment for at most 18 ticks, and exactly 24 recovery ticks;
- swept Charger commitment contact that attributes 25 kinetic damage once and ends the commitment; ordinary non-committed overlap is non-damaging, while dash invulnerability rejects damage but still ends that commitment;
- deterministic 5 WU/s Kamikaze pursuit with a versioned 30-tick pulse, swept terminal contact, one attributable 12-damage attempt, and canonical self-resolution through target health/death; dash invulnerability rejects player damage while the Kamikaze still resolves, and the instance cannot detonate again;
- armor-before-health player damage and exactly-once player death through the existing player resource authority, plus role/contact/source/target/channel/ amount/point/tick attribution that survives Kamikaze self-death;
- combat-transient purge that clears Charger telegraph/commit state, Kamikaze pulse state, and one-shot events without removing configured actors, changing player resources, or producing contact, damage, or death effects;
- copied orange diamond Charger presentation with sampled direction, telegraph, committed stretch, recovery calm, and existing hit/death feedback; copied narrow yellow Kamikaze presentation with heading, pulse, and one restrained terminal ring; and diagnostic HUD role counts, Charger contacts, Kamikaze detonations, and latest threat damage source; and
- checksum, reset, purge, teardown, replay, 30/60/144/irregular schedule, interactive/headless, presentation-transform, startup, target-slot-reuse, and unrelated-RNG proof in threat_enemies_tests, session_execution_threat_tests, arena_threat_presentation_tests, and arena_phase_three_integration_tests.
Encounter admission now places configured Chargers and Kamikazes off-screen and enforces their reaction floors and role-specific arming before acquire, telegraph, commit, terminal damage, or dangerous presentation can begin.
feat(arena): add Splitter descendant foundation adds the next bounded product-owned authority:
- separate versioned Splitter and mini-splitter role partitions mapped one-to-one to canonical DamageableTarget identity, position, radius, health, player-projectile damage, alive state, and death;
- deterministic exact-coordinate pursuit at initial 2.03 WU/s and 3.44 WU/s bounds with signed, diagonal, zero-distance, and origin-rebased behavior, fixed integration remainders, and no RNG consumption;
- admission-time reservation of exactly two stable child role/target mappings per configured Splitter, explicit bounded Splitter, mini-splitter, pending request, event, and target capacities, and atomic rejection without eviction or partial child creation;
- one canonical parent death scheduling exactly one descendant request, followed by a deferred authoritative commit of both children using stable identities and deterministic two-sided placement clear of the parent death point and player; repeated death observation cannot duplicate children;
- mini-splitters with parent attribution and no descendant capability; ordinary overlap is non-damaging until a later contact-design slice;
- purge discarding uncommitted requests without actor, damage, death, reward, or presentation side effects; reset rebuilding only configured starting roles; and teardown clearing role, target, reservation, pending, event, and diagnostic state;
- copied turquoise pentagon and small cyan triangle presentation at authoritative radii with stable headings, existing hit/death response, one-shot fracture and bounded two-direction materialization cues, and HUD active/alive/pending/rejection/commit diagnostics; and
- exact capacity, mapping, movement, death, purge, reset, teardown, replay, 30/60/144/irregular schedule, interactive/headless, presentation-transform, startup, slot-reuse, and unrelated-RNG proof in splitter_enemies_tests, session_execution_splitter_tests, arena_splitter_presentation_tests, and arena_phase_three_integration_tests.
Configured Splitters now remain inert until stable pack admission, and mini-splitters are committed only as descendants inheriting the parent token's liability. Top-level Splitters now use off-screen placement and visibility/reaction activation; descendant materialization remains canonical. Wave progression, relevance, and recycling remain deferred.
feat(arena): add Tank and bounded local avoidance adds the next bounded product-owned authority:
- a versioned Tank role mapped one-to-one to canonical DamageableTarget identity, logical position, 0.375 WU radius, eight-health baseline, player-projectile damage, alive state, and death; Tank-owned state is limited to bounded 1.41 WU/s pursuit velocity/heading, exact integration remainder, active/armed state, and one 45-tick contact cooldown;
- bounded target-broadphase contact followed by exact circular overlap, attributable 30 kinetic damage through the canonical armor-first player-resource path, dash-invulnerability rejection, cooldown suppression of sustained overlap, exactly-once player death, and no physical body or projectile blocking;
- one versioned local-avoidance pass that snapshots living active hostile positions after origin update, builds a private bounded uniform broadphase, processes sorted/deduplicated target-ID candidates without mutation during iteration, and applies fixed-point separation before role movement;
- moderate Runner and Splitter weights, Shooter separation subordinate to its approach/retreat/preferred-band intent, light mini-splitter separation, and the strongest Tank anchor weight; Kamikaze deliberately uses zero separation to preserve urgency, and Charger accepts avoidance only during approach and recovery while telegraph and committed direction remain unchanged;
- a stable non-random anti-symmetric target-ID fallback for exact coincident positions, per-role speed clamping, rebase-stable results, and explicit actor, query-candidate, per-actor result, high-water, rejection, overflow, query, and fallback diagnostics;
- reset reconstructing configured Tanks and clearing avoidance diagnostics, purge preserving configured roles while clearing Tank events and transient avoidance snapshots/corrections, teardown releasing both partitions, and deterministic slot reuse with no eviction;
- copied violet hexagonal Tank presentation at authoritative radius with heading and existing bounded hit/death feedback, plus HUD active/alive Tank, contact, avoidance query/high-water/fallback/rejection/overflow diagnostics; presentation remains read-only through interpolation, resize, origin rebase, shake, and slot reuse; and
- focused capacity, mapping, movement, contact/resource/death, all-role policy, broadphase ordering, coincident overlap, reset/purge/teardown, replay/checksum, 30/60/144/irregular schedule, direct headless, presentation, startup, and unrelated-RNG proof in tank_enemy_tests, local_avoidance_tests, role_avoidance_integration_tests, session_execution_tank_avoidance_tests, arena_tank_avoidance_presentation_tests, and arena_phase_three_integration_tests.
The authoritative fixed-tick order is player command/movement, origin rebase, hostile snapshot and broadphase build, stable avoidance accumulation, role intent plus bounded movement integration, projectile advancement and collision, deferred Splitter death/descendant request and commit, Runner/Tank player contact, hostile-projectile and Charger/Kamikaze contact, then pickup/resource finalization. Canonical death is synchronized before each role moves, dead/inactive roles do not enter the next snapshot, projectile collision ordering is unchanged, and avoidance does not alter Splitter child identity or placement.
feat(arena): add encounter tokens and director skeleton adds the next bounded product-owned authority:
- versioned stable encounter, pack, token, and role-target references with integer threat costs, bounded capacities, atomic validation, and stable token-ID plus (admission offset, pack ID) ordering;
- exact one-token ownership for every configured top-level hostile while neutral dummies own no token and mini-splitters inherit their parent Splitter token;
- Pending, InPlay, and Defeated token state plus Ready, Active, Draining, and Resolved director state, with atomic pack admission and deterministic waiting under active threat/count caps;
- inert, non-colliding, avoidance-excluded, ordinarily hidden roles before admission, with existing role and target identity preserved;
- canonical death-only defeat accounting, including Kamikaze self-resolution, exact duplicate suppression, and Splitter liability that remains unresolved through parent death and any pending or purged child commit until both inherited descendants canonically resolve;
- a drain barrier requiring all committed obligations plus a later tick with no deferred authoritative combat events, without automatic next-encounter progression;
- purge preserving configured actors and director progress without awarding defeat, reset rebuilding the original packs/tokens/roles and removing prior descendants, and teardown clearing all encounter mappings and diagnostics;
- copied director/threat/token/pack/hostile/liability/blocking observations and HUD fields, checksum schema 14, replay schema 14, run-configuration schema 13 at that slice boundary, deterministic schedule/replay/headless equivalence, and no gameplay RNG consumption; and
- focused proof in encounter_director_tests, run_session_encounter_tests, session_execution_encounter_tests, and arena_encounter_presentation_tests.
That slice deliberately used configured positions and immediate activation as a temporary bridge. The following placement/activation slice supersedes that bridge without changing encounter identity, cap, liability, or drain semantics.
feat(arena): add off-screen placement and activation lifecycle adds the next bounded product-owned authority:
- one versioned conservative logical spawn envelope derived from the stable 45 WU vertical gameplay span and maximum supported 21:9 aspect, expanded by 0.5 WU on every side; the resulting 106 by 46 WU rectangle contains every supported 4:3 through 21:9 unshaken view and remains independent of native window dimensions, resize, presentation shake, replay, and headless execution;
- a dedicated deterministic placement stream, 16 fixed signed directions, a bounded 62–72 WU annulus, 32 ordered attempts, pack-local radial/tangential formation offsets, broadphase-backed overlap filtering, and exact candidate-to-player swept-entry-path rejection against the player, living hostiles, and neutral combat dummies;
- atomic whole-pack placement with no partial commit, no hidden all-world scan, explicit invalid/broadphase/no-candidate diagnostics, stable pack ordering under the existing threat/count caps, no overtaking, and one-tick deterministic retry after placement failure;
- the shared Pending -> SpawnedConcealed -> PreEntry -> VisibleArming ->
Active lifecycle for all six top-level configured hostile roles, preserving token, role, target, position, and health identity while excluding concealed actors from rendering, targeting, projectile/contact collision, attacks, role-state progression, and local avoidance;
- first logical-envelope intersection begins targetable but non-dangerous arming exactly once. Runner arms for 6 ticks, Shooter for 21, Charger for 27, Kamikaze for 30, Splitter for 9, and Tank for 9. Accepted placement predicts at least 39, 48, 60, 66, 39, and 39 ticks respectively before dangerous activity;
- copied activation observations only in presentation: concealed actors are omitted, visible-arming actors use a restrained blue-gray outline, dangerous role cues remain active-only, and each activation transition emits one bounded cosmetic cue. HUD diagnostics expose lifecycle counts, placement attempts/failures, blocked pack/reason, minimum accepted reaction, activation transitions, and spawn-envelope dimensions;
- combat-transient purge clears only transient placement diagnostics and activation events. It neither admits nor activates a pack, grants defeat, discards token liability, nor rewinds an actor lifecycle. Reset reconstructs the configured encounter and original placement stream; teardown clears all placement and activation authority; and
- run-configuration schema 14, checksum schema 15, and replay schema 15 cover envelope/tuning/capacities, placement stream and accepted placements, retry/blocking state, lifecycle/timers/first-visible tick, copied diagnostics, and purge/reset/teardown effects without perturbing movement, dash, marker, weapon-spread, Shooter, or other existing RNG streams.
Focused proof in spawn_placement_tests, run_session_spawn_activation_tests, encounter_director_tests, run_session_encounter_tests, session_execution_encounter_tests, arena_encounter_presentation_tests, and arena_phase_three_integration_tests includes a deterministic 100,000-candidate placement matrix, signed and rebased worlds, supported aspects, collision and failure boundaries, exact arming, role gating, replay/schedule/headless equivalence, copied presentation, reset, purge, teardown, and RNG isolation. Mini-splitters retain their descendant materialization semantics and do not receive independent annular placement.
feat(arena): add sector heat relevance and recycling adds the next bounded product-owned authority:
- all ordinary and recycled placement uses 16 stable logical angular sectors with integer recent-placement heat, exact tick decay, active approaching threat, temporary reservation, attempts/failures, stable sector-ID tie-breaking, and small deterministic variation derived only from the existing isolated placement stream. Sector selection and diagnostics are signed-coordinate and origin-rebase invariant and independent of camera, resize, and shake;
- one versioned relevance policy classifies actor-radius-inclusive positions against the existing conservative unshaken logical envelope: core/visible, soft, catch-up, hard-recycle, and absolute-guard regions use ordered 8, 14, 18, and 24 WU margins. Actors outside soft relevance enter the shared CatchUp lifecycle, become non-attacking/non-colliding/non-avoiding, and return directly without teleporting, pathfinding, role RNG, or local avoidance at a bounded 2x role-speed multiplier;
- catch-up return reaches the existing VisibleArming state before Active, so Shooter fire, Charger acquisition/telegraph/commit, Kamikaze detonation, Runner/Tank contact, Splitter/Tank cues, and ordinary targeting cannot resume early. Existing hostile projectiles retain their established lifetime and cleanup behavior;
- continuous hard-region dwell, recent dealt/received combat protection, Charger commitment, terminal/descendant liability, mini-splitter ownership, and alive/resolved checks gate recycling. An eligible actor moves atomically to RecycleQueued, preserves stable token, role, target, health, threat, and Splitter liability, grants no defeat/progress/reward/damage/death side effect, clears transient role/contact/telegraph state, and requests fair re-placement through the same placement service;
- accepted recycle placement re-enters through SpawnedConcealed -> PreEntry -> VisibleArming -> Active. The initial per-actor limit is three; exhausting it leaves the token unresolved in catch-up and records a hard stall rather than manufacturing a defeat. Recycle-queued tokens continue to consume finite threat/count liability and prevent pack/director resolution;
- combat-transient purge clears attacks, projectiles, and tick events while preserving deterministic catch-up/recycle lifecycle and token progress. Reset reconstructs original sector heat, placement stream, relevance state, and recycle counters; teardown clears all such authority; and
- copied presentation hides concealed, catch-up-offscreen, and recycle-queued actors, retains the existing arming treatment for re-entry, and never emits a death-like recycle cue. HUD observations expose sector heat/selection, approaching threat/reservations, active/catch-up/queued/hard-stall counts, relevance transitions, recycle attempts/successes/failures, and unresolved no-visible-threat duration.
Run-configuration schema 15, checksum schema 16, and replay schema 16 cover the new tuning, sector state, classifications, dwell/recent-combat timestamps, catch-up/recycle state, token mapping, diagnostics, purge, reset, and teardown. Focused spawn_placement_tests, run_session_relevance_tests, placement, activation, role-safety, straight-line travel, recycle, hard-stall, replay, schedule, origin-rebase, copied-presentation, and interactive/headless proof remains bounded. Complete wave definitions, directional surges, cross-angle events, player-heading prediction, rewards, audio, perks, bosses, campaign progression, and safety-valve defeat resolution remain deliberately deferred.
feat(arena): complete representative encounter sandbox closes Phase 3:
- five deterministic packs admit at offsets 0, 240, 480, 720, and 960 ticks without overtaking: 4 Runner + 2 Shooter; 3 Runner + Shooter + 2 Charger
; Runner + Splitter + Tank + Shooter; Runner + Kamikaze +
Splitter + Tank; and 4 Runner + 2 Shooter + Charger + Kamikaze;
- the finite total is 29 top-level tokens: 13 Runner, 6 Shooter, 3 Charger, 3 Kamikaze, 2 Splitter, and 2 Tank. Canonical Splitter deaths create four mini-splitters; no mini-splitter is startup content;
- active threat and hostile-liability caps remain 55 and 16. The reference playthrough resolves at authoritative tick 4546 (75.77 seconds), defeats all 29 tokens and four descendants, records no recycle or hard stall, and has a longest post-pressure zero-visible-threat interval of 249 ticks;
- optimized native Windows acceptance resolves two complete runs through the same-window R path at ticks 6617 (110.28 seconds) and 6555 (109.25 seconds). Both end with 29 defeated top-level tokens, zero pending/in-play tokens, zero threat/hostiles/descendant liability/recycle-queued work, and zero hard stalls. The longest pressure gaps are 354 and 99 ticks, both below six seconds;
- Run 1 ends at 100 health and 73 armor with 2/2 recycle attempts/successes. Run 2 ends at 100 health and 100 armor with 1/1 recycle attempts/successes. Each run materializes four descendants and visibly exercises all ordinary roles, player damage, movement, aim, held and released primary fire, scatter, dash, and origin rebasing;
- completion remains exact: Resolved requires zero pending/in-play tokens, threat, active hostiles, unresolved descendants, recycle-queued actors, and hard stalls plus drained authoritative combat events. Ordinary input cannot advance the resolved encounter, and no next encounter or reward transition exists;
- the resolved RmlUi card explicitly gives its title and detail children block flow, preserving ENCOUNTER / RESOLVED, the blank hierarchy gap, and the two unwrapped commands at 4:3, 720p, 1080p, 2560x1334 scale 1.5, and 21:9, including with F1 visible; and
- run-configuration schema 16, authoritative checksum schema 19, and execution replay schema 18 cover the representative configuration, encounter start/resolution ticks, pressure-gap telemetry, reset, replay, and presentation-independent outcomes.
This is still one executable encounter. Switching the executable to the test-proven campaign progression, score, drops, rewards, perk drafting, bosses, audio, checkpoints, campaign menus, new weapons, packaging, display/power policy, and editor Run Product integration remain deferred.
Phase 4 Work
Phase 4 is complete. Slice 1, feat(arena): add typed campaign and wave definitions, establishes only the product-owned content-definition boundary:
- campaign schema 1 defines strong campaign, ordinary-wave, and pack IDs, positions 1 through 31, Acquisition/Combination/Mastery/Finale act assignment, ordinary-encounter versus boss-placeholder kinds, and the milestone markers after positions 5, 10, 15, 20, and 25;
- the topology is 31 numbered positions total. Positions 10, 20, 30, and 31 are boss positions; positions 1 through 29 therefore contain 27 ordinary encounters around placeholders at 10 and 20. Positions 30 and 31 remain reserved boss placeholders for Phase 5. It is not 29 ordinary encounters plus four additional boss entries;
- ordinary-wave schema 1 defines bounded ordered packs, admission offsets, placement/domain seed salts, hostile-role quantities and formation offsets, declared threat/entity liabilities, and active threat/entity caps. Validation rejects top-level mini-splitters and accounts for Splitter descendant liability;
- the dependency-free product compiler preserves authored order, generates stable pack/token/target IDs, and terminates in the existing EncounterDefinition contract. Existing encounter validation remains the final runtime-compatibility authority;
- a separate Arena-owned YAML adapter decodes through the public engine serialization facade, produces field-path diagnostics, validates typed values before compilation, and follows the repository's forward-compatible unknown-field policy. Slice 1 initially supplied only test-owned fixtures; the later authored-content checkpoint adds product-owned runtime YAML without moving YAML or filesystem types into Arena core;
- canonical content hashes cover validated typed values in an explicit versioned domain and byte order. Raw YAML text, formatting, comments, key ordering, source path, object address, struct padding, native enum layout, and unordered-container iteration are not inputs; and
- focused proof covers partial and complete topology, invalid placement and capacity cases, deterministic compilation, semantic YAML equivalence, canonical hashing, and exact compilation of every current representative encounter pack/token/config field.
Slice 2, feat(arena): add ordered campaign progression, adds an explicit campaign session mode above that compiled-content boundary:
- immutable validated runtime data owns the canonical content marker and exact deterministic compiler output for all 27 ordinary positions. Each ordinary position derives a product-local wave seed from campaign seed and identity, position, authored wave salt, and ordered pack salts, then provisions the existing EncounterDirector; pack admission, token state, role authority, placement, activation, relevance, recycling, Splitter descendants, and legitimate completion remain unchanged;
- the bounded phase machine is WaveIntro → Combat (including director Active/Draining) → BoundaryResolution → Intermission. Boundary resolution first completes canonical combat and pickup processing, then purges projectiles, contacts, telegraphs, role state, pickups, placement, and encounter transients exactly once before explicit continuation;
- positions 10 and 20 are observable non-combat BossPlaceholder phases that require explicit acknowledgement and provision no fake token. Continuing from position 29 intermission enters AwaitingPhase5; positions 30 and 31 remain reserved and are not executed;
- versioned edge-triggered run-control commands, copied campaign observations, bounded per-position telemetry, reset/defeat handling, checksum coverage, and replayed headless control are product-local. Replay command-batch capacity is explicitly configured per position epoch, defaults to 4,096, is capped at 65,536, and rejects overflow rather than truncating. Complete campaign capture uses the bounded position-oriented archive described below; and
- authoritative tick order is fixed: validate both command vocabularies, digest gameplay commands, digest/apply at most one run-control edge, perform any intro-to-combat provisioning, run the existing encounter and combat authority, finish canonical damage/death/pickup and director resolution, then on the following boundary tick converge pickups, purge combat transients, capture telemetry, and enter intermission. Configuration mode/capacity, run-control transcript, campaign identity/content marker, phase/position state, wave seed/ticks, rejection state, and ordered bounded telemetry are checksum fields; derived act/milestone data is covered by the validated canonical content marker; and
- compiled test-only scenarios prove consecutive ordinary positions, milestone and act transitions, placeholders 10/20, the position-29 terminal boundary, canonical defeat/reset, origin rebasing, recycling, Splitter descendant drain, interactive/headless replay, and 30/60/144/165/irregular presentation schedules.
Slice 3, feat(arena): add typed perk builds and derived stats, adds only the Arena-private perk/build foundation:
- perk content schema 1 defines strong runtime and pool IDs, stable content keys, maximum ranks, prerequisites, exclusions, typed stat modifiers, typed behavioral classifications, support status, and immutable validated catalogs. Five pools match campaign positions 5/10/15/20/25 with sizes 3/6/3/3/3; position 10 carries the future three-distinct-selection rule;
- canonical FNV-1a domain hashing covers sorted typed definitions, effects, modifiers, relationships, pool metadata, selection counts, and offering order. YAML formatting, object addresses, padding, unordered iteration, and source paths are not inputs;
- build schema 1 stores at most 14 unique sorted (PerkId, rank) entries and a semantic revision. Pure selection first validates catalog, pool, milestone, perk identity/membership/support, distinct and pool limits, rank, prerequisites, exclusions, and capacity; rejection returns the original build without partial mutation. RunSession accepts only an explicit validated initial build; no fixed-tick or run-control selection command was added;
- derived-stat schema 1 rebuilds at construction/reset or after a successful build-revision change, never per simulation tick. Integer fixed point uses scale 1,000,000 and nearest rounding with ties away from zero. Expanded modifiers sort by target, operation, perk ID, rank, and effect index, then apply base → flat additions → summed additive percentage → ordered final multipliers → minimum/maximum clamps and system-safe bounds → one validated exclusive override. Checked arithmetic rejects overflow before authority continues;
- the derived cache is the read path for perk-modifiable resource initialization/caps, movement and dash tuning, and weapon/projectile tuning. Base configuration remains immutable input. An empty build reproduces the four existing tuning structures exactly;
- copied observation schema 1 records the content marker, canonical selected ranks, build/derived revisions, rebuild count, last rejection, bounded diagnostics, and final derived values. Replay owns the configuration and initial build. Checksum schema 21 appends, in order, enabled state, canonical content marker, initial-build schema/revision/count and sorted ID/rank entries, then the Arena-private authority fingerprint: initialized/enabled, content marker, live build schema/revision/count and entries, derived revision, and final resource, movement, dash, primary, and scatter values;
- the complete existing-system subset is Aegis Plating, Overcharged Ammunition, Vector Drive, Rapid Cycling, and Anti-Matter Chassis. The compiled test catalog uses explicit proof coefficients for these behaviors because the GDD specifies their direction and limits but does not yet author final production coefficients. It is test-only, not shipped tuning;
- deferred definitions are explicit rather than partially selectable: Magnet Field needs pickup attraction/smoothing; Scatter Pack and Hyper Scatter need an authored pattern package and preview; Vampire Circuit needs bounded healing authority; Twin Barrel needs stable multi-lane spawning and per-projectile coefficients; Stasis Field needs field/status authority; Orbital Drone needs companion, target, intercept, and budget authority; and Phoenix Protocol needs lethal-damage interception, charge, invulnerability, and purge policy; and
- perk_build_tests, run_session_perk_tests, session_execution_perk_tests, and arena_perk_integration_tests prove catalog/pool/build rejection, all modifier operations and rounding, the five stat-led perks and interactions, reset, collision damage, campaign initial builds, origin rebasing, three representative encounter builds, replay/checksum, direct headless equivalence, and 30/60/144/165/irregular presentation schedules.
Slice 4, feat(arena): add bounded combat perk effects, extends the existing Arena-private projectile, collision, damage, death, dash, perk-build, campaign, replay, and checksum authorities rather than adding a gameplay event bus:
- combat provenance schema 1 carries typed original/current source, direct or generated damage kind, eligible-kill policy, source perk, stable root event, generation, effect sequence/index, and generated status through canonical hit, damage, health-change, and death resolution. A target transitions alive to dead once; the first canonical lethal event in stable projectile/damage order owns the death, while later same-tick damage is ignored. Recycling, relevance removal, and target self-destruction are not eligible player kills;
- proc-context and area-effect schemas 1 use fixed-capacity ordered storage. Each root may emit at most 64 generated projectiles and 32 area effects. Default maximum proc depth is 2; depth 3 requires an explicitly validated typed definition. The non-recursive queue key is tick, root event ID, source/effect sequence, perk ID, effect index, then target ID. Limit rejection is diagnosed before partial health or projectile-pool mutation;
- Dash Ram reuses the existing logical swept-circle/broadphase and canonical damage paths, keeps a bounded target-ID history per dash, applies deterministic test-owned knockback only to survivors, and clears history at completion. Chain Burst consumes canonical eligible deaths, performs exact integer radial inclusion in target-ID order, permits generated eligible kills to chain through the validated depth, and enforces the per-root area cap without call-stack recursion;
- Atomic Dash emits one 12-member product-local radial pattern at the canonical dash-completion boundary. It preflights the complete player projectile-pool allocation, retains a single root across every member, and rejects the entire pattern when capacity is insufficient. Piercing Rounds snapshots three extra hits and 0.85 cumulative per-hit damage at spawn; impacts sort by time of impact then stable target ID and use an eight-entry fixed hit history. Vector Ricochet snapshots one continuation, selects the nearest bounded broadphase candidate within 4.5 WU with stable-ID tie-break, excludes dead/already-hit targets, preserves age/travel, and applies a 0.70 continuation multiplier;
- the five mechanically supported perks are Dash Ram, Chain Burst, Atomic Dash, Piercing Rounds, and Vector Ricochet. Their current coefficients are compiled test-owned proof values because final production tuning is not authored. They are selectable only in explicit test-owned initial builds; the executable still uses an explicitly disabled empty build;
- copied schema-1 effect observations expose roots, generation/budget use, dash history, area/pattern/pierce/ricochet outcomes, and bounded rejection diagnostics. Reset, replay reset, explicit purge, defeat, ordinary-wave boundary, and new-wave provisioning clear transient roots, queues, dash history, and observations. Canonical same-tick damage and generated effects resolve before an end-of-tick defeat purge; no later defeated tick produces effects; and
- run configuration schema 19, weapon/projectile schema 4, collision/damageable-target schemas 2, checksum schema 22, and replay schema 21 cover the new authority. Fixed gameplay commands remain schema 6; campaign run control/observation, campaign/wave content, perk content/build/derived-stat, and player-resource schemas do not advance. Checksum ordering appends combat-effect tuning after collision tuning; projectile behavior snapshots and each live projectile's provenance, remaining counts, multiplier, and ordered hit history; collision counters, root allocator, targets, broadphase, then hit/damage/health/death provenance; and finally initialized effect state, ordered roots, ordered queued areas, dash history, copied events, and diagnostics before the existing session transcript and remaining authorities; and
- combat_perk_effects_tests, the affected perk/collision/dash/projectile/ campaign/Splitter/relevance suites, and session_execution_perk_tests prove stable lethal attribution, duplicate-lethal suppression, direct/dash/area/ generated-projectile kills, cardinal and diagonal sweeps, rebase invariance, exact area inclusion, depth and area caps, Atomic allocation rejection, pierce order/history/reuse, ricochet target/no-target behavior, recycling exclusion, Splitter parent/child handling, defeat/reset/purge/wave-boundary cleanup, replay/checksum, direct headless equivalence, and 30/60/144/165/irregular schedule convergence.
Slice 5, feat(arena): add field drone and lethal perk effects, completes the mechanical baseline for the remaining eight typed perks:
- player-resource schema 3 is the sole health/armor owner and now resolves incoming damage in stable role order as validation, finite-invulnerability rejection, armor absorption and one positive-to-zero armor-break event, health mutation, one lethal-candidate decision, Phoenix interception or canonical death. Phoenix owns one run charge, restores a validated health fraction, starts a 72-tick test-owned invulnerability interval, and requests one bounded stable-ID hostile-projectile purge that grants no kill, reward, token, or encounter credit;
- Magnet Field moves only live uncollected pickups within its typed radius in stable pickup-ID order using integer direction, bounded acceleration, 60 Hz remainder integration, and canonical collection/cap handling. Scatter Pack, Twin Barrel, and Hyper Scatter compile to weapon-pattern schema 1: complete packages are capacity-checked before spawn, primary lanes have mirrored logical muzzle offsets, scatter members retain stable order, and projectile damage/pierce/ricochet behavior is snapshotted at spawn. Scatter Pack then Hyper Scatter compose additively for member count and multiplicatively for damage, with the resulting count hard-limited to 24;
- Vampire Circuit consumes canonical eligible DeathEvent order, heals once per death under validated per-event/per-tick and maximum-health caps, and ignores recycling, relevance removal, self-resolution, and defeated players. Stasis Field maintains one player-centered schema-1 field, slows eligible active hostile movement and hostile projectiles without permanent tuning mutation, excludes concealed/inactive targets, and leaves an already committed Charger at its sampled full-speed trajectory;
- Orbital Drone schema 1 uses one stable companion ID, an exact eight-step integer orbit, nearest visible active target selection with stable-ID tie-break, one shared bounded fire/intercept cooldown, the canonical player projectile pool and eligible generated-projectile provenance, and stable hostile-projectile retirement. Fields, target/fire transients, attraction motion, pattern observations, and drone combat behavior purge at combat and campaign boundaries; the configured drone and unconsumed Phoenix charge reconstruct on full reset; and
- run configuration schema 20, player-resource schema 3, weapon/projectile schema 5, checksum schema 23, replay schema 22, and the new schema-1 player-damage, pickup-attraction, weapon-pattern, field, drone, Phoenix, and remaining-perk observations cover the authority. Checksum order is existing combat effects; field and stable affected IDs; drone; ordered Vampire recoveries; Phoenix purges; session transcript; weapon pattern and projectile state; pickup attraction velocity/remainders; canonical damage/recovery and Phoenix state; then the existing role authorities.
All 18 baseline perks are now mechanically supported in typed test-owned definitions. Final production coefficients remain deferred wherever the GDD does not provide them. The executable remains SingleEncounter with an explicitly disabled empty perk build, so ordinary user-visible behavior and the Phase 3 representative encounter are unchanged.
Slice 6, feat(arena): add wave-boundary checkpoints and restart, establishes the checkpoint/restart foundation without exposing it in the executable:
- checkpoint schema 1 stores only persistent engine-independent authority needed to reconstruct a canonical campaign position start: typed campaign/perk compatibility markers, campaign seed and runtime identity, positions 1 through 29, completion count, command transcript state, player health/armor, sorted selected perk ranks, retained dash/weapon cooldowns, Phoenix charge/invulnerability state, ordered deterministic RNG streams, bounded completed-position telemetry, generation metadata, and a canonical payload digest;
- capture is valid only at a clean WaveIntro or BossPlaceholder after the previous position has converged. The shared position-start operation neutralizes movement/fire/dash/control edges, restores canonical player/origin state, rebuilds build-derived owners, and contains no live enemies, targets, projectiles, pickups, proc work, drone target/fire work, placement, avoidance, or copied combat events. Ordinary positions resume through WaveIntro; placeholders resume as placeholders. No checkpoint is created for AwaitingPhase5;
- one immutable in-memory checkpoint belongs to the current campaign position and survives defeat. Current-wave restart is accepted only for an ordinary WaveIntro, Combat, or Defeated position; full-run restart reconstructs position 1 from the original validated configuration. Both reuse the existing session/window and begin fresh bounded replay epochs;
- replay schema 23 records original-configuration, current-wave-checkpoint, or persisted-checkpoint initial authority, copied checkpoint identity, starting campaign position/checksum, epoch number, and ordered command batches. Run-control schema 2 adds the two restart edges. Campaign checksum schema 24 covers current checkpoint identity while SingleEncounter admits no checkpoint state;
- the separate Arena-private persistence target uses the public typed serialization facade. Codec schema 1 has required typed fields, bounded collections/input, forward-compatible unknown-field handling, path-aware diagnostics, semantic validation, and digest verification. The store writes checkpoint.0.yaml and checkpoint.1.yaml through a temporary sibling, re-reads before and after rename, retains the previous valid generation, and selects the newest valid compatible generation while reporting corruption or incompatibility fallback; and
- checkpoint observations are copied values only: availability and capture eligibility, resume position/schema/digest/compatibility, current-wave presence, typed result/diagnostics, loaded generation/fallback, and replay epoch kind/number. Filesystem paths, handles, YAML nodes, mutable session pointers, presentation, and HUD state are excluded.
Slice 7, feat(arena): add milestone draft authority and commands, adds the Arena-owned campaign draft lifecycle independently of presentation:
- campaign sessions opt in through an explicit schema-1 draft policy. SingleEncounter rejects enabled drafts, and enabled campaign drafts require the validated typed perk catalog. Campaign progression schema 2 adds the authoritative PerkDraft phase after canonical completion at positions 5, 10, 15, 20, and 25. Positions 5, 15, 20, and 25 require one selection; position 10 requires three sequential distinct selections from its six-entry pool. Boss-placeholder acknowledgement at positions 10 and 20 enters the draft instead of skipping it;
- pool projection preserves canonical definition order without random subsets or rerolls. Draft entry performs a bounded deterministic completion search: one-pick pools must admit a valid pick, and position 10 must admit a legal three-pick sequence from the current build. An impossible pool enters a typed blocked draft and cannot silently advance, select, skip, or weaken prerequisites;
- run-control schema 3 adds the edge-triggered SelectPerk command with stable draft serial, milestone, pool, and perk identities. Phase, blocking state, stale identity, milestone, pool, catalog support, pool membership, distinctness, rank, prerequisite, exclusion, capacity, build, and derived-stat rejections are ordered and atomic. Accepted selections use the existing pure perk-build operation and rebuild derived owners after every pick;
- schema-1 acquisition effects separate runtime health/armor/Phoenix grants from configured session-start statistics. Current health and armor always clamp to rebuilt maxima; maximum increases do not refill resources unless the selected definition has an explicit grant. Field and drone state rebuild from the committed build, Phoenix gains only its explicit bounded charge, and failed selections mutate no resources or persistent effects;
- the final required pick records the milestone once, emits bounded draft telemetry, and enters ordinary Intermission. It cannot also continue the intermission or provision the next position. The existing ContinueIntermission edge is required before the next position-start checkpoint is captured. Checkpoint schema 2 persists the enabled marker, canonical build, and ordered completed-draft telemetry, including the exact position-10 sequence; active drafts reject capture and current-wave restart; and the canonical commit order is selection validation, candidate canonical build, derived-stat rebuild, acquisition effects, draft selection sequence, final-pick milestone completion, Intermission, then next-position checkpoint state after explicit continuation; and
- run configuration schema 22, campaign observation schema 2, campaign checksum schema 26, replay schema 25, perk-content schema 2, and schema-1 draft state/observation/telemetry cover policy, offering order, selection sequence, canonical build, derived summary, eligibility, typed rejections, entry/first-pick/completion ticks, completed milestones, checkpoint identity, and fresh replay epochs. Fixed gameplay commands remain schema 6, and SingleEncounter retains its established checksum/replay behavior.
The replay-capacity reliability correction now participates in execution replay schema 25 and the established SingleEncounter byte stream while adding campaign replay epoch schema 1, archive schema 1, and copied archive-observation schema 1:
- an original-configuration, persisted-checkpoint, or restarted-current-wave epoch begins from its existing authority. Each ordinary next-position transition seals the completed position only after intermission and any milestone draft selections are committed, then begins the next epoch from the canonical position-start checkpoint. Positions 10 and 20 therefore keep placeholder acknowledgement, draft commands, and continuation in their position epochs. The AwaitingPhase5 transition seals position 29;
- restart-current-wave seals the failed attempt and begins a checkpoint-backed epoch; persisted continuation starts a new archive from the loaded checkpoint; restart-run discards the prior attempt archive and begins again from the original configuration. Checkpoint schema 2, payload compatibility, content hashes, and checkpoint files are unchanged;
- one archive retains at most 64 epochs, 65,536 command batches per epoch, 524,288 batches total, 96 MiB of estimated retained command/checkpoint storage, 64 KiB of estimated checkpoint initial state per epoch, and 4 MiB of estimated checkpoint initial state total. The shipped authored campaign keeps its 16,384-batch per-position limit. Boundary and batch preflight reject overflow atomically with typed diagnostics; sealed epochs are never silently discarded;
- archive checksum order is the archive schema and replay-configuration discriminator (configuration schema, campaign seed, mode, and per-epoch capacity), followed by epoch count and each epoch in order. An epoch hashes schema, initial-state kind, checkpoint payload digest, and the checksum of the replay-only campaign/draft, perk rebuild-count, and weapon-pattern boundary residue; then starting position/tick/checksum, epoch number, each batch tick and ordered fixed/run-control command field, ending position/phase/tick/checksum, seal reason, and sealed state. Replay startup separately proves the full configuration, checkpoint, and boundary residue against the recorded starting authoritative checksum;
- the live input adapter already omits empty frames, records held-state changes and action edges once, and replaces repeated presentation samples targeting the same next authoritative tick. Aim changes that reach distinct authoritative ticks remain timing-relevant, so this correction performs no command compaction; and
- copied F1-only diagnostics report current epoch position/start kind and command use, sealed/total archive use, estimated bytes and high-water, initial-state bytes, compaction count, overflow rejections, and the last seal reason. The normal campaign HUD is unchanged.
Slice 8, feat(arena): add campaign draft and run UI, originally exposed that authority behind the explicit compiled --campaign-showcase product mode:
- at that slice boundary, the no-argument executable remained the unchanged Phase 3 SingleEncounter, with its disabled empty perk build, representative five-pack encounter, existing HUD/replay flow, and no checkpoint I/O;
- product-private compiled provisional content supplies the complete 31-position topology, compact ordinary encounters for positions 1 through 29, placeholders at 10, 20, 30, and 31, all 18 mechanically supported perk definitions, and the milestone pools at 5, 10, 15, 20, and 25. It runs the real campaign, encounter, perk, draft, checkpoint, replay, and checksum owners, stops at AwaitingPhase5 after position 29, loads no YAML, and is proof content rather than final balance;
- one retained product RML/RCSS document consumes a bounded copied UI model for startup, campaign HUD, wave intro, intermission, boss placeholder, draft, pause/options, defeat, checkpoint state, terminal summary, compact build summary, accessibility, and off-screen threat indicators. No RmlUi type, mutable authority reference, pointer, file handle, or UI-only state enters Arena core, replay, checksum, or checkpoint authority;
- application command schema 1 routes stable draft identities and existing run-control edges through current authority. Pointer routing uses the public runtime-UI hit-test path without retained elements; keyboard navigation and activation are edge-triggered. Overlay transitions reset the existing input adapter so held movement, fire, scatter, dash, selection, acknowledgement, or continuation cannot leak across panels;
- pause remains application/execution control: fixed authority stops while presentation continues, resume rebases elapsed time rather than catching up, and mandatory drafts remain mandatory. Restart-current-wave and restart-run call their existing execution owners;
- the application selects a bounded checkpoint root, discovers compatible generations before authority begins, requires explicit continuation, and auto-saves only a newly authoritative clean position-start checkpoint. SingleEncounter never creates a store. Settings use a separate bounded Arena-private schema-1 store and affect only screen shake, cosmetic motion, hit/flash feedback, and high-contrast threat indicators; and
- the campaign HUD shows real phase/position/act, same-unit threat progress, resources, weapon/dash readiness, checkpoint state, and a bounded build. Draft cards preserve canonical offering order, exact proof coefficients, typed eligibility, authoritative ranks, and the position-10 three-distinct-pick progress. The terminal panel reports only copied real progress at AwaitingPhase5 and does not claim victory.
The authored-content technical checkpoint replaces the showcase's compiled provisional catalog with product-owned assets/content/campaign.yaml and assets/content/perks.yaml. Arena-private adapters decode required typed fields, reject invalid content with field-path diagnostics, validate the complete topology and all 18 mechanically supported perks, and compute canonical typed hashes that ignore source paths, comments, formatting, and key order. The authored campaign has 31 positions, 27 ordinary encounters, placeholders at 10, 20, 30, and 31, milestone pools at 5, 10, 15, 20, and 25, and execution ending after position 29 at AwaitingPhase5. Exhaustive milestone selection proves 9,720 legal paths, no blocked path, no mandatory perk, and maximum build occupancy 7 of 14. Checkpoint compatibility uses the authored campaign and perk markers and rejects the former compiled fixture markers.
The authored coefficients are current provisional product values, not final release balance. The no-argument executable now selects the runtime-authored campaign; --campaign-showcase is a compatibility alias for the same behavior, and --single-encounter explicitly selects the Phase 3 sandbox. The completed human Gate C scenarios establish structural and systems viability under ordinary product resources without claiming final intensity or presentation. Boss authority, positions 30/31 execution, rewards, audio, replay-file persistence, release packaging, final balance, and release hardening remain unimplemented.
Authored wave pressure continuity correction
The partial human Gate C run exposed a systemic relevance/activation defect, not an authored pack or role-speed defect. A player traveling away from an off-screen placement could move the spawn envelope faster than a concealed or pre-entry actor's ordinary approach. The token remained valid and in play, but never crossed its original activation deadline and therefore never became eligible for the existing active-hostile catch-up/recycle path. The former acceptance helper also treated concealed, pre-entry, catch-up, recycle-queued, and pending tokens as pressure, masking the loss of an actually visible arming/active hostile.
Authored campaign sessions now opt into schema-1 bounded visible-pressure continuity with a two-second deadline. Once pressure has begun, only alive visible-arming or active actors intersecting the actual spawn-view envelope, including committed mini-splitter descendants, count as effective visible pressure. Concealed, pre-entry, catch-up, recycle-queued, distant active, and pending actors do not. A missed approach deadline or loss of all effective visible pressure transitions eligible top-level actors into the existing inert catch-up lifecycle. Its deterministic per-entry speed is bounded to restore a safe visible-arming opportunity within the configured deadline while allowing for the player's maximum movement/dash speed and the actor's arming window; the actor remains non-attacking and non-targetable until safe re-entry, retains its token/actor identity and liability, and may still use the established bounded recycle path. No role's ordinary movement speed changed.
A related liability edge was exposed by the reproduction: Splitters are targetable during VisibleArming, but descendant scheduling formerly required the role to be armed. A Splitter killed in that interval could therefore be recorded as owing two descendants without committing them. Canonical parent death now commits exactly two stable children regardless of whether the targetable parent had finished arming; completion still requires both child deaths and recycling grants no defeat credit.
The product-authored campaign/perk YAML, topology, pack composition, role tuning, milestone pools, and canonical content hashes are unchanged. Focused sustained-travel proof for positions 6 and 7 and the all-27 ordinary-position scan require no post-start zero-visible-pressure interval above 120 fixed ticks, no hard stalls, finite canonical completion, and normal Splitter descendant drain. The later human Gate C pass accepted the corrected campaign flow while retaining late-Act-III density as a nonblocking balance follow-up.
The separate angle-dependent square/E-shaped artifact from the partial Gate C run was a presentation composite, not an origin-rebase or gameplay seam. The stable bracket marker at logical position (208, 56) used axis-aligned strokes on grid coordinates, while the minor layer also emitted the same geometry as the major grid at every major line. The correction emits each major line once and rotates the bracket motif 45 degrees without changing its stable identity or logical position. Focused proof covers signed grid phase, exact line uniqueness, the captured marker/camera pair, adjacent origin revisions, interpolation endpoints, shake ordering, bounded preparation, supported aspect ratios, content scale 1.0/1.5, and long positive/negative travel. No authority, content, pressure, checkpoint, replay, renderer API, or schema changed. The artifact did not recur as a blocking issue in the completed Gate C acceptance.
This authority addition advances run configuration to schema 22, the campaign checksum domain to 26, and execution replay to schema 25. The pressure policy is schema 1, and copied effective-visible/active counts join the existing encounter observation. Fixed gameplay commands, run control, campaign content, campaign observation, checkpoint, perk content/build, and the established SingleEncounter checksum domain do not advance.
Deterministic Core Guarantees And Deferrals
The stable facade //products/boundless_vector_arena:arena_core resolves to //products/boundless_vector_arena/core:arena_core. It has no engine, framework, presentation, editor, runner, shared-depot, or packaging dependency. Its public RunSession contract provides:
- explicit Uninitialized, Ready, Running, Defeated, and Stopped lifecycle states with actionable diagnostics for illegal transitions;
- configuration schema version 22, explicit single-encounter/campaign mode and explicit campaign-draft policy, campaign-seed ownership, versioned movement, dash, world-origin, weapon/projectile, collision/damage, player-resource, pickup, Runner, Shooter, Charger/Kamikaze, Splitter/mini-splitter, Tank, and local-avoidance, spawn-placement/envelope/sector-heat, hostile-relevance, authored-campaign pressure-continuity, and encounter/pack/token tuning plus versioned initial target, pickup, Runner, Shooter, Charger, Kamikaze, Splitter, reserved descendant, mini-splitter, and Tank records, and an invariant rational 1/60 authoritative fixed step with monotonically numbered ticks;
- fixed-tick command schema version 6 with stable ordered no-op, SetPlayerMove, SetPlayerAim, RequestPlayerDash, SetPrimaryFireHeld, RequestScatterFire, and PurgeCombatTransients records, addressed-tick application, atomic validation, and explicit malformed-payload rejection;
- integer-backed normalized logical coordinates, player position and velocity, persistent logical move input, deterministic logical aim, exact signed movement and dash integration remainders, fixed dash direction and active/cooldown counters, and a checksum-covered origin/local seam updated after movement;
- lazily derived, independently advancing product RNG streams using stable typed stream IDs plus a separate product-owned weapon-spread stream;
- checksum schema version 23 for unchanged SingleEncounter authority and campaign checksum schema version 26 over lifecycle, configuration, campaign progression/draft/checkpoint state, tick, committed command transcript, RNG states, complete player movement/aim state, and dash, world-origin, weapon cadence, bounded projectile pool, identity, lifecycle counters, spread state, bounded target health/alive state, broadphase diagnostics, collision/damage/death events, hit retirement, player health/armor/alive state, pickup pool/broadphase/events, Runner target mapping/position/velocity/integration/cooldown/active state, player-contact damage/resource/death events, Shooter mapping/movement/ telegraph/cadence state, hostile projectile/source/hit/player-damage/death events and capacity diagnostics, Charger/Kamikaze mappings, movement, velocities, fixed integration remainders, states, timers, sampled directions, pulse/resolution, contact/player-damage/self-resolution events, Splitter/mini-splitter mappings, pursuit state, integration remainders, active/armed/resolved flags, descendant reservations, pending requests, stable committed child identities/positions, capacity diagnostics, and purge/reset outcomes, Tank mapping/position/velocity/heading/integration/ cooldown/active/armed state and contact/player-resource/death events, plus local-avoidance tuning, ordered corrections, query/result high-water marks, coincident fallback, rejection/overflow diagnostics, and purge/reset outcomes, encounter schedule, token/pack identity and state, role mappings, admission/blocking counters, active threat/count accounting, Splitter descendant liability, director lifecycle, spawn placement stream, accepted placements, retry/blocking state, activation lifecycle/timers/first-visible tick, and placement/activation purge/reset diagnostics, target and player death outcomes, diagnostics, and purge state using defined byte ordering;
- deterministic reset to the configured Ready state and full teardown back to Uninitialized.
The session still deliberately owns no ECS. One player authority, a bounded player and hostile projectile partitions, bounded damageable targets, Runners, Shooters, Chargers, Kamikazes, Splitters, mini-splitters, Tanks, and pickups do not justify a generic entity/component system. Input, rendering, UI, and interactive diagnostics remain application-owned adapters outside the core. Checkpoint YAML and bounded two-generation I/O exist only in the Arena-private persistence adapter; the executable has no consumer. Replay-file persistence and audio remain deferred.
Headless Execution And Observability
The product-private facade //products/boundless_vector_arena:session_execution resolves to //products/boundless_vector_arena/execution:session_execution and depends only on //products/boundless_vector_arena:arena_core. It provides:
- integer fixed-step accumulation by adding elapsed_nanoseconds * 60 quanta and consuming exactly 1,000,000,000 quanta per authoritative tick, avoiding floating-point frame-schedule drift;
- presentation-frame input independent of authoritative simulation, deterministic dispatch of ordered tick-indexed command batches, and validated replacement of the pending next-tick batch for interactive sampling;
- a maximum accepted presentation-frame duration of 250 ms and at most eight catch-up ticks per presentation frame; elapsed time above 250 ms is explicitly discarded with a clamp diagnostic, while accepted whole ticks beyond the catch-up limit remain pending and are reported as deferred;
- explicit rejection and diagnostics for negative elapsed time and invalid command batches;
- initialization, start, reset, and shutdown ownership over RunSession;
- bounded recent diagnostics and per-tick checksum traces, plus frame, tick, pending-time, clamp, catch-up, rejection, reset, and lifecycle observations;
- schema-versioned in-memory replay records containing the configuration, campaign seed, and ordered movement/aim/dash command batches actually consumed. Replay schema version 15 records the complete movement, aim, dash, fire-intent, origin-tuning, weapon/projectile-tuning, initial target, collision/damage-tuning, player-resource tuning, initial pickups, pickup-tuning, Runner, Shooter, Charger/Kamikaze, and Splitter/mini-splitter tuning/target/reserved-descendant mappings, Tank tuning/target mappings, bounded local-avoidance tuning/capacities, and spawn-placement/envelope tuning and encounter/pack/token definitions, hostile-projectile definitions/capacity, purge commands, player alive/dead authority, and deterministic state contract.
//products/boundless_vector_arena/execution:session_execution_tests and :session_execution_dash_tests prove equivalent one-second movement and dash runs at 30 Hz, 60 Hz, 144 Hz, and an irregular uncapped presentation schedule all produce exactly 60 authoritative ticks, identical player position, velocity, aim, dash, and world origin, per-tick checksum traces, final checksums, RNG outcomes, command timing, and lifecycle state. The same surfaces prove movement, aim, and dash replay consumption in a fresh session, reset/repeated-run determinism, copied non-mutating observation, malformed-command rejection, and explicit catch-up/clamp behavior.
//products/boundless_vector_arena/execution:session_execution_collision_tests proves replay round trip and exact target, collision, damage, death, projectile retirement, pickup/resource/purge state, checksum-trace, and final-checksum equivalence at 30 Hz, 60 Hz, 144 Hz, and an irregular presentation schedule. The application Phase 2 integration proof runs the same physical fire capture through the interactive and headless adapters and compares the copied collision/damage observation. //products/boundless_vector_arena/execution:session_execution_runner_tests adds exact Runner/player-resource/event/checksum/replay comparisons across 30 Hz, 60 Hz, 144 Hz, and irregular presentation schedules, dead-player input suppression, origin rebasing, and unchanged independent RNG streams. //products/boundless_vector_arena/execution:session_execution_shooter_tests adds exact Shooter/hostile-projectile/player-resource/checksum/replay comparisons across the same schedules, direct headless tick equivalence, and unchanged independent RNG streams. //products/boundless_vector_arena/execution:session_execution_threat_tests adds exact Charger/Kamikaze target mapping, movement, state/timer, contact/self-resolution, player-resource, checksum, and replay comparisons across 30 Hz, 60 Hz, 144 Hz, and irregular schedules, direct headless equivalence, and unchanged unrelated RNG streams. //products/boundless_vector_arena/execution:session_execution_splitter_tests adds exact Splitter/mini-splitter target mapping, movement, descendant request/commit/capacity state, checksum, reset, teardown, and replay comparisons across 30 Hz, 60 Hz, 144 Hz, and irregular schedules, direct headless equivalence, and unchanged unrelated RNG streams. //products/boundless_vector_arena/execution:session_execution_tank_avoidance_tests adds exact Tank target mapping, movement/contact cooldown, avoidance corrections/diagnostics, reset/teardown, checksum, replay, and 30/60/144/ irregular schedule comparisons, direct headless equivalence, and unchanged unrelated RNG streams.
Interactive Composition And Presentation
The public target //products/boundless_vector_arena:boundless-vector-arena remains a genuine product composition root. Its product layer owns SessionExecution, samples a product-owned action-level input source, stages only addressed next-tick logical commands, publishes copied observations, and tears input, presentation, and session state down with the layer lifecycle. Focus loss or explicit reset suppresses held movement, dash, and fire until release, releases primary authority, and clears pending dash/scatter edges.
The centered camera model copies the authoritative player logical position as its camera position and places the player at the exact logical viewport center. There is no damping, dead zone, or look-ahead. A resolved form of the existing logical viewport maintains the 45 WU vertical span across supported aspects and live resize. Invalid/minimized extents produce no world preparation and cannot produce NaN aim or camera state. The interpolation alpha is derived only from pending fixed-step time and cannot feed authority. Sprite geometry stays camera-relative, so raw chunk coordinates never reach shaders.
The runtime presentation installs the existing renderer host binding and public scene-sprite subrender, draws a cyan body with a short aim stem, bounded gold primary and orange scatter projectile bodies/trails/current-position markers, plus a coordinate-stable bounded minor/major grid and deterministic sparse ambient markers using the existing flat-white texture, and retains the dark clear frame. While authoritative dash state is active, the copied model elongates and brightens the body and prepares at most three cyan/white afterimages; this presentation state cannot feed coordinates, checksums, or RNG. The presentation-only shake seam adds a bounded translation to the rendered world view after logical camera, grid, marker, and player preparation. It uses no RunSession RNG and leaves the HUD subrender unshifted. Positive impulses add and clamp at unit intensity; decay is elapsed-time based and schedule independent. Accepted shots add bounded presentation-only muzzle pulses and aim-stem recoil; they never mutate player or projectile authority. Neutral target rings, compact health indicators, magenta triangular Runners, lime square Shooters with heading/telegraph/release feedback, orange diamond Chargers with sampled-direction/telegraph/commit/recovery feedback, narrow yellow Kamikazes with heading/pulse/terminal feedback, compact crimson hostile projectiles, turquoise pentagonal Splitters, small cyan triangular mini-splitters, weighty violet hexagonal Tanks, impact/death/fracture/ materialization rings, and distinct health-plus/armor-diamond pickup geometry use the same flat-white support closure. Global rebase, resize, interpolation, and camera-shake transforms apply consistently, while bounded effect preparation remains read-only and cosmetic. The HUD remains a copied read-only RmlUi model and includes position, velocity, aim, dash, primary, scatter, player health/armor/alive state, active player/hostile projectile, target, pickup, active/alive Runner, and active/alive/armed/telegraphing Shooter counts, latest/total hit, active/alive/telegraphing/committing Charger counts, active/alive Kamikaze counts, Charger contacts, Kamikaze detonations, latest threat damage role, active/alive Splitter and mini-splitter counts, pending descendant requests, capacity rejections, committed child creation totals, active/alive Tank counts, Tank contact totals, avoidance query and candidate/result high-water counts, coincident fallbacks, and rejection/overflow diagnostics, target death, player-contact damage, and player-death counts, event capacities/overflows, collection totals, purge count, and capacity-rejection diagnostics. The product-authored runtime closure remains exactly the HUD RML and RCSS. The separate shared sprite-support closure is exactly the existing scene-sprite vertex shader, fragment shader, and flat-white texture; neither closure admits the broad shared depot.
//products/boundless_vector_arena/application:arena_input_tests, :arena_dash_input_tests, and :arena_fire_input_tests prove action mapping, opposite cancellation, fixed-tick command routing, focus behavior, cardinal/diagonal aim, dead-radius retention, invalid input handling, and viewport offset/resize behavior plus dash/scatter edge retention, primary held transitions, held-input non-retrigger, and focus/reset suppression. //products/boundless_vector_arena/application:arena_presentation_tests, :arena_dash_presentation_tests, and :arena_projectile_presentation_tests, and :arena_combat_presentation_tests, :arena_runner_presentation_tests, and :arena_shooter_presentation_tests, and :arena_threat_presentation_tests, and :arena_splitter_presentation_tests, and :arena_tank_avoidance_presentation_tests prove exact centering, no camera damping/look-ahead, read-only interpolation, and large-coordinate-independent geometry, bounded dash feedback, projectile identity/retirement, bounded trails, muzzle recoil, HUD diagnostics, and no camera/grid/marker/dash/projectile/target/pickup discontinuity across an origin revision. Combat presentation proof also covers exact target radius/alignment, event de-duplication, target death timing, effect overflow isolation, collection feedback, Runner/neutral distinction, authoritative Runner radius and heading, Shooter/neutral distinction, Shooter radius/aim/telegraph/release, hostile projectile interpolation and source identity, copied hit/death response, Charger/Kamikaze target separation, authoritative radius/heading/ telegraph/commit/pulse/terminal feedback, target slot reuse, resize, rebasing, interpolation, Splitter/mini-splitter target separation, authoritative radius/heading, fracture/materialization de-duplication, descendant slot reuse, Tank/neutral separation, authoritative Tank radius/heading/hit/death response, Tank slot reuse, avoidance HUD copying, and shake composition. //products/boundless_vector_arena/application:arena_world_presentation_tests proves backtracking stability, unique deterministic marker identities, bounded preparation/draw counts, and cosmetic RNG/checksum isolation. :arena_viewport_tests and :arena_camera_shake_tests prove supported aspect classification, stable vertical scale, exact centering, viewport-local aim, safe invalid/resume behavior, resize-stable grid phase and marker identity, zero/max/additive bounded shake, and frame-rate-independent decay. //products/boundless_vector_arena/application:arena_interactive_tests, :arena_dash_interactive_tests, :arena_phase_two_integration_tests, and :arena_phase_three_integration_tests capture synthetic interactive movement/aim commands and replays them through headless execution, requiring identical ticks, position, velocity, aim, dash, weapon state, projectile identity/position/age/travel/retirement, target/damage/resource/pickup/purge, Runner/contact/player-death, and Shooter/hostile-projectile/player-damage, and Charger/Kamikaze/contact/self-resolution/player-damage and Splitter/mini-splitter/descendant state, and Tank/local-avoidance state, checksum trace, final checksum, and RNG output at 30/60/144/irregular schedules. They also prove focus-loss/reset behavior, held-dash/fire behavior, first presentation with dash/projectile/collision/collection/Runner/contact/Shooter/hostile-release/ Charger/Kamikaze/Splitter/mini-splitter/Tank feedback, and repeated lifecycle teardown. Product build and startup smoke retain binary, asset loading, first-presentation, and teardown coverage. :arena_phase_one_integration_tests adds only the missing cross-surface proof: resize during movement/dash/rebase and maximum shake remain replay-, checksum-, RNG-, aim-, movement-, dash-, origin-, and interactive/headless-equivalent at 30, 60, and 144 Hz plus an irregular schedule; logical camera and HUD stay unshaken through startup and teardown.
Runtime And Authoring Distinctions
tools/scene_runner is a generic authored-scene tool and editor companion. It constructs ScenePlayLayer for a requested scene; it is not the Arena runtime or headless adapter. BulletSketch Run Standalone remains generic authored-scene execution. The Arena executable runs complete product sessions.
Arena assets remain editable and previewable in BulletSketch without requiring the editor to launch the full product. A future Run Product integration is optional and deferred.
Deferred Or Unrelated Debt
The three accepted repository-audit findings, provisional Material and Physics Gallery dispositions, gallery package absence, broad future graphics work, and other current repository debt do not block current Arena work unless a later slice produces direct measured evidence to the contrary.