Compare commits

...
Sign in to create a new pull request.

28 commits

Author SHA1 Message Date
Tald0r
38c74a968b
fix(regions): correct end Z coordinate assignment in InitRectangles (#2597)
The `ez` variable was incorrectly assigned `rect.End.X` instead of `rect.End.Z`, causing incorrect rectangle processing in region initialization.
2026-08-27 06:51:42 -07:00
Kamron Batman
e7f85d404d
feat: Adds independent think/move clocks for creature AI to fix speed (#2591)
Splits creature speed into two clocks so movement pace can be tuned without touching reaction time:

- **Think clock** — `ActiveSpeed`/`PassiveSpeed`/`CurrentSpeed`: seconds per AI decision. Unchanged in meaning, storage, and cadence.
- **Move clock** — `ActiveMoveSpeed`/`PassiveMoveSpeed` (+ resolved `CurrentMoveSpeed`): seconds per step. `0` = inherit the matching think value.

### How

- Move speeds come from optional `activeMove`/`passiveMove` in `npc-speeds.json`, are `[props`-tunable per instance (set `0` to re-inherit), and serialize (BaseCreature v22).
- `SetSpeed()` keeps its legacy one-clock semantics — sets the think clock **and clears move overrides** — so existing callers cannot half-configure a creature. `SetMoveSpeed()`/`ClearMoveSpeed()` configure movement explicitly; `ScaleMoveSpeed()` scales overrides for buffs.
- `CurrentMoveSpeed` is derived by classifying `CurrentSpeed`: a verbatim active/passive think value maps to the matching move value; a bespoke pace written directly (mount boosts, follow sprint) stays fused to both clocks. External `CurrentSpeed` writers need no changes.
- `AITimer` schedules the earlier of the two deadlines. Decisions run at the think cadence exactly as before; while a pursuit/investigation is live, the timer also wakes when the movement budget elapses and advances one step with no decisions. Steps no longer snap to the think grid, so any step delay paces smoothly on the 8ms wheel. A blocked creature schedules no move wakes.
- The movement budget is RunUO's `m_NextMove` accumulate-and-clamp at a full step, so long-run pacing averages `CurrentMoveSpeed` exactly.

### Behavior changes

- **`npc-speeds.json` buckets get RunUO `TransformMoveDelay`-parity move values**: creatures step at RunUO pace while thinking/reacting at current speed. The situational +0.1/+0.2 offsets are deliberately omitted.
- **Existing saves migrate on load**: a pre-v22 creature whose think speeds still match its npc-speeds entry (never hand-tuned) adopts the table's move values — worlds and pets pick up the new pacing without a respawn. Tuned creatures keep movement inheriting their think clock.
- **Paragons scale movement by `SpeedBuff` (1.2x)**: RunUO had no deliberate policy here — dividing by 1.2 knocked most speeds off `TransformMoveDelay`'s exact-equality table (raw pass-through, 2x+ faster), while 0.3/0.6 creatures landed back on it for ~1.33x. This applies the uniform 1.2x the buff always claimed. UnConvert snaps speeds back to exact table values within 1e-4 — /1.2 then ×1.2 drifts 0.45 and 0.9 by an ulp, which would read as hand-tuned (and defeat a future skip-table-conformant-values serialization pass); tuned speeds keep.
- **Herding paces the movement clock**: the old `CurrentSpeed` getter hack is gone. A herded creature walks at a fixed 0.3s/step — RunUO's forced pace, without its `TransformMoveDelay` inflation to 0.6 — so herding is never penalized by a slow creature. Thinking is untouched, and `CheckHerding` walks through `MoveToPoint`, so herded creatures path around obstacles.
- **Badly-hurt slowdown now inflates the step delay only** (RunUO parity), computed from the base each step. Previously it wrote `CurrentSpeed = CurrentSpeed + 0.05..0.15` back on every successful step — compounding unboundedly while hurt and slowing decisions too.
- Removes the vestigial `MoveSpeedMod` (never read, written, or serialized).
- With no bucket or per-instance move values, both clocks carry identical values and creatures pace as before.

### Testing

- Full suite passes (1557, including 12 new `MoveSpeedTests`: resolution classes, `SetSpeed` clearing, `0`-re-inherit, v22 round-trip with exact-consumption check, save migration adopt/skip, buff scale/snap, herding).
- In-game verified via local diagnostics build (per-step budget tracing): steady 700ms step cadence on a 0.3s think grid with one-step catch-up after idle, think grid unperturbed by move wakes.
2026-08-23 10:19:59 -07:00
Kamron Batman
8e39da2810
fix: creatures track and chase targets reliably around corners (#2590)
### Summary

Fixes the long-standing reports of monsters losing track of players who run around a corner ("Is monster AI not using pathfinding? It seems to be LOS blocked by statics"). Root-cause investigation compared current behavior against RunUO line-by-line and traced the regressions through the AI overhaul era (#2232, #2246, #2379, #2401, #2461).

### Root causes and fixes

1. **Movement contract** — `MoveTo`/`ApproachTarget` returned false on every healthy mid-chase tick (true only on arrival), so MeleeAI's RunUO-inherited *"move failed and beyond RangePerception+1 → Guard"* clause — which RunUO only evaluated on genuine blockage — fired **every tick of every chase**. A mounted player trivially opens 17 tiles at a corner, the monster guards, Guard nulls the combatant, and re-acquisition is LOS-gated — unrecoverable through a wall. Movement now reports failure only on genuine failure (no step taken with no working path, or approach give-up). ArcherAI's equivalent clause moves to the hard leash.

2. **Last-known-position pursuit** — while a combatant is in LOS its position is recorded each think tick. When the target vanishes (corner, hiding, recall), the creature walks to the last-seen spot, stands guard there ~10s (restoring RunUO's guard grace, which had decayed to a single tick since #2246), and **re-engages instantly** if the same target re-enters view — bypassing the 10s reacquire throttle.

3. **`ChaseLeashRange`** — new virtual on BaseCreature (default `RangePerception * 2` = 32 tiles) replaces the inline `RangePerception * 3` (48) in Melee/Mage/Archer AI. Per-creature tunable via `[props`.

4. **Group movement demoted to a crowding refinement** — previously any uncontrolled creature with one ally within 8 tiles on the same target used greedy ring-stepping for the *entire* chase, with wall-slides counted as success, never invoking the pathfinder — the "aggroed but won't come around the corner" symptom for spawn groups. It now engages only near the target when allies actually contest the ring, and blocked/wall-slid steps escalate to the pathfinding approach primitive.

5. **Mages close distance on broken LOS** — a mage within casting range but LOS-blocked by geometry stood at the wall holding a spell target until the 60s combatant expiry (ProcessTarget short-circuits Think and its RunTo stands off at RangeFight). Geometry-blocked mages now close in until LOS returns, both pre-cast and while holding a target. Hidden targets (CanSee) and poison-cure priority unchanged. The new movement contract also stops the constant spurious `OnFailedMove` teleport rolls mid-chase.

6. **Move budget: one actual step per AI tick** — nothing advanced `NextMove` on a normal step (RunUO's `m_NextMove` budget was lost), so code paths attempting several moves in one think tick could cross multiple tiles at once — visible as "warping" when crowded creatures jockey for position. A successful step now consumes a half-step budget (floor 50ms): blocks intra-tick double moves, stays safely below the timer interval so legitimate next-tick moves are never jitter-throttled, and does not reintroduce `TransformMoveDelay` inflation. Blocked attempts consume nothing, so retry ladders (repath-and-step, the collision fan) are unaffected. `CanMoveNow` is also wraparound-safe now.

### Reference behavior

RunUO requires LOS to *acquire* a target and to *land* a hit or spell — never to *continue* a chase (its MeleeAI LOS bail-out is literally commented out in stock code). Chases drop only on: target hidden, target dead/off-map, beyond `RangePerception * 3`, 60s without combat interaction, or blocked movement while far away. This PR restores those semantics while adding the last-known-position investigation on top. NPC run flags are untouched — pace is AI-timer-driven and most NPC art has no run animation.
2026-08-23 01:13:00 -07:00
Kamron Batman
2935eafe24
feat: convert all delta-time serialization to anchored time (#2589)
## Summary

Phase 3 of the anchored-time work: **every actively-written delta-time value in the engine now stores an anchored timestamp** — absolute on the wire, shifted forward by the downtime at load. Remaining time survives restarts (as delta did), and unlike delta, the bytes do not change on every save, so an idle world serializes identically save after save.

The answer to "is it possible everywhere": **yes** — including the one case that looked impossible.

## The GenericPersistence problem, solved

`GenericPersistence` bins (`Virtues.bin`, `StealableArtifacts.bin`, …) are raw payloads with no idx header, so they have no anchor of their own — anchored reads there would silently apply zero shift. But the anchor is a property of the **save**, not the file: every file in one save shares one `World.SaveStartTime`, and `Persistence.Load` reads **all** entity indexes (phase 1) before **any** persistence payload (phase 2). So the idx v5 header stamps a save-wide `World.LoadTimeShift`, and generic persistence readers inherit it. No file-format change, no per-bin header, old bins unaffected.

## Converted

- **Item v10 → v11**: `LastMoved` — previously whole-minute delta, rewritten every save for every item, the single largest source of idle-save churn — and `DecayResetTime` (retiring the TODO from #2583). **Mobile v37 → v38**: the three stat-gain stamps. **BaseCreature v20 → v21**: `SummonEnd`.
- **17 code-generated classes** (`[DeltaDateTime]` → `[AnchoredDateTime]`, version bump + `MigrateFrom` each): the five field spells, TransientItem, VirtueContext (×7 fields), PuzzleChestSolutionAndTime, BaseCamp, BaseBoat, RentedVendor, PlayerVendor, Ethics Player, Sheep, StarRoomGate, ChampionSpawn (×3), Corpse (`TimeOfDeath`, v19). The `MigrateFrom` bodies were generated from each class's current migration schema and are compiler-verified; VirtueContext's save-flagged nullables fall back to the same defaults the old deserialize left in place. Corpse's six migrations moved to a new `Corpse.Migrations.cs`.
- **Hand-written sites**: StealableArtifacts (v2), VendorInventory (v1), ML quest objectives (persistence v3) — each gated on its own version.

**Not converted, deliberately**: the ~25 read-only `ReadDeltaTime` sites in legacy version fallbacks and migration replays — they decode existing old bytes and must never change. `[DeltaDateTime]`/`WriteDeltaTime` remain available for them.

## Verification

- Build 0 errors / 0 warnings; **837 + 708 tests green**.
- Schema regeneration produced exactly the 17 expected new `vN.json` files (all `AnchoredTime` rule args), nothing else touched.
- **New acceptance tests** pin the point of the whole effort: serializing the same item at two save times **5 hours apart produces byte-identical output**, and `LastMoved`/`DecayResetTime` round-trip **exactly** at sub-minute precision (the old minutes encoding destroyed both properties).

## Notes for review

- `LastMoved` grows from a 1–3 byte encoded minutes value to 8-byte ticks per item — the price of byte-stability; it repays itself in incremental-save behavior since unchanged items now produce unchanged bytes.
- BaseEscortable-style semantics are unchanged: anchored shift preserves *remaining* time exactly, the same contract delta provided, so no gameplay-visible behavior changes — deadlines simply stop being consumed by downtime that delta already protected against, now with stable bytes.

## Enforcement

`WriteDeltaTime` is now `[Obsolete]` (interface + implementation). With the repo's warnings-as-errors, any new delta-time write — hand-written or emitted by a still-unconverted `[DeltaDateTime]` field — fails the build, with the migration instructions in the message. That the full solution still builds with **zero warnings** is itself the proof no active delta writer survived the conversion. `ReadDeltaTime` deliberately stays un-attributed: its remaining callers decode existing old bytes and are correct forever; its XML docs now state the legacy-decode-only contract.
2026-08-22 19:34:43 -07:00
Kamron Batman
b992c7b955
docs: update serialization docs and skills for generator v4 (#2588)
## Summary

Brings every serialization-related doc, skill, and the CLAUDE.md rule in line with generator **v4** (adopted in #2586/#2587). No code changes.

**Updated surface, everywhere it was referenced:**
- `[SerializableFieldSaveFlag(order)]` / `[SerializableFieldDefault(order)]` → `[SaveFlag(nameof(Should), nameof(Default))]` on the field (second method optional).
- `[TimerDrift]` + `[DeserializeTimerField(order)]` → `[DeserializeTimer(nameof(Method), wallClock)]` on the field, with the anchored-time semantics spelled out: drifting by default (downtime preserves the remaining delay, idle saves byte-stable), `wallClock: true` for absolute deadlines, restart method invoked **only when a timer was running** (no sentinel), and the timer `MigrateFrom` pattern (`XxxNext`/`XxxDelay`) for wire-format changes.
- New `[SerializableField]` documentation: the real signature (the documented `saveIf` parameter never existed) plus the setter hooks — `allowFieldChange` (`bool Method(ref T value)`: coerce/veto before assignment) and `fieldChanged` (`void Method(T oldValue, T newValue)` after) — with the generated pipeline and the SG3015/SG3018 guardrails.
- `[SerializableProperty]` guidance narrowed to its remaining purpose: custom getters and setter semantics the hooks cannot express.
- `[AnchoredDateTime]` documented alongside `[DeltaDateTime]` (now marked legacy, with the version-bump warning for converting between them).

**Files:** `dev-docs/serialization.md`, `dev-docs/timers.md`, `dev-docs/claude-skills/modernuo-serialization.md`, `dev-docs/claude-skills/modernuo-timers.md`, `dev-docs/runuo-migration-docs/02-serialization.md`, `dev-docs/runuo-migration-docs/03-timers.md`, and a condensed v4 addition to CLAUDE.md rule 9.

**Example refresh:** the skill's `BagOfSending` "custom properties" example was itself converted in #2587 — it is now quoted in its real post-conversion form as the canonical hooks example; the real-examples list points at `BaseWeapon.cs` for custom getters and `BaseLight.cs` for the drifting-timer + `MigrateFrom` pattern.

Verified by grep: zero references to the removed v3 attribute names remain anywhere in `dev-docs/` or `CLAUDE.md`.
2026-08-22 18:29:27 -07:00
Kamron Batman
b042edcf0b
refactor: fold hand-written serializable property setters into field hooks (#2587)
## Summary

Folds **113** hand-written `[SerializableProperty]` members into plain `[SerializableField]` declarations using the v4 setter hooks — value coercion/vetoes via `allowFieldChange`, post-change side effects via `fieldChanged` (whose `oldValue` parameter covers the old-house/old-sender unsubscribe patterns). Net **-450 lines** of setter boilerplate.

```cs
// before
[SerializableProperty(1)]
[CommandProperty(AccessLevel.GameMaster)]
public int Charges
{
    get => _charges;
    set
    {
        _charges = Math.Clamp(value, 0, MaxCharges);
        InvalidateProperties();
        this.MarkDirty();
    }
}

// after
[SerializableField(1, allowFieldChange: nameof(AllowChargesChange))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
[InvalidateProperties]
private int _charges;

private bool AllowChargesChange(ref int value)
{
    value = Math.Clamp(value, 0, MaxCharges);
    return true;
}
```

## How sites were selected

A classifier parsed all 204 `[SerializableProperty]` sites and converted only those matching strict shapes: getter is exactly `get => _field;`, the assignment comes first (after at most an equality guard), and relocated side effects contain no `return`, no `value` mutation, and no field re-assignment. Everything else was left alone deliberately:

- **~34 custom getters** (fallback defaults like `_x == -1 ? Default : _x`, self-healing refs) — no setter hook can express these.
- **~35 pre-assignment logic** (durability Unscale/Scale sandwiches, old-state captures like PotionKeg's pile weight).
- **virtual/override members, name-mismatched backing fields (`m_`), exotic semantics** (guards' `Focus` does work on *equal* assignment; `ChampionSpawn.Active` never assigns its field).

Five sites the classifier refused were converted by hand where the hooks fit cleanly: `ReceiverCrystal.Sender`, `PlayerVendor.House`, `PlayerBarkeeper.House` (old-value unsubscribe via `oldValue`), `BaseSuit.AccessLevel` (its existing virtual `OnAccessLevelChanged` already had the exact callback shape), and `DyeTub.DyedHue` (a true veto: `AllowDyedHueChange(ref int value) => _redyable`).

## Verification

- Build: **0 errors, 0 warnings**.
- **Schema regeneration produces zero Migrations changes** — the conversion is wire- and schema-neutral by construction (same orders, types, and property names), and CI's schema diff check enforces it.
- **835 + 708 tests green.**

## Behavioral notes (all strict improvements, called out for review)

- Generated setters skip everything when the incoming value equals the current one; a few converted setters previously re-ran side effects on equal assignment (redundant `Update()`-style refreshes).
- Generated setters always `MarkDirty()` on change; several converted setters never did (e.g. `DyeTub.DyedHue`, `MorphItem` ranges) — their changes only persisted if something else dirtied the entity. Those latent persistence bugs are fixed by construction.
2026-08-22 18:20:39 -07:00
Kamron Batman
73f9688083
feat: adopt serialization generator v4 (field-side linkage, anchored timers) (#2586)
## Summary

Adopts ModernUO.Serialization 4.0.0 across the engine. Three commits, reviewable independently:

1. **Package + tool bump to 4.0.0** (`Server.csproj`, `UOContent.csproj`, `dotnet-tools.json`).
2. **Timers → `[DeserializeTimer]`** — the 8 drifting timers (BaseLight, TreasureMapChest, MarkContainer, FillableContainer, DeathRobe, DecayedCorpse, Corpse, BaseEscortable) now store their next tick as **anchored time**: server downtime no longer consumes the remaining delay, and idle-world saves are byte-stable. This changes their wire format, so each class bumps its serialization version with a `MigrateFrom` that replays the old delta-time read through the migration schema (the new `vN.json` files carry `@AnchoredTimer`; the old ones keep `@TimerDrift`, which the generator reads forever). The 2 wall-clock timers (Aquarium, FountainOfLife) keep their exact format via `wallClock: true` — no bump. Restart methods drop their `TimeSpan.MinValue` sentinel checks: v4 invokes them **only when a timer was actually running at save**.
3. **Linkage → field-side declarations** — 175 conversions across 25 files: `[SerializableFieldSaveFlag(order)]`/`[SerializableFieldDefault(order)]` become `[SaveFlag(nameof(...), nameof(...))]` on the field, and `[SerializableFieldChanged(order)]` becomes the `fieldChanged:` argument of `[SerializableField]`. **Wire-neutral: zero migration schemas changed.**

## Verification

- Solution builds with **0 errors, 0 warnings**; all three 4.0.0 packages verified indexed on nuget.org (no local feed needed).
- **835 + 708 tests green.**
- Generated output inspected: old-version content structs replay `ReadDeltaTime` (e.g. `V3Content.DecayTimerNext = reader.ReadDeltaTime()`), current versions write/read anchored time with the gated restart, and the wall-clock classes emit byte-identical `Write`/`ReadDateTime` framing.
- Schema tool run is committed (CI's `git diff --exit-code` schema check passes): exactly the 8 expected new `vN.json` files, nothing else touched.
- The conversion was scripted with a class-scoped resolver (order → same-class `[SerializableField(order)]`/`[SerializableProperty(order)]`); it planned 175/175 with zero ambiguities before applying.

## Notes

- New `MigrateFrom`s use the content structs' provided `XxxDelay` property, matching the pre-existing idiom in Corpse's and TreasureMapChest's older migrations.
- Follow-up candidate (separate PR, wire-neutral, any time): fold the ~150 eligible hand-written `[SerializableProperty]` setters (clamps, post-change side effects) down to `[SerializableField]` with `allowFieldChange`/`fieldChanged` hooks.
2026-08-22 17:54:02 -07:00
Kamron Batman
126a10ce53
feat: anchored-time infrastructure with a save-start anchor in idx v5 (#2585)
## Summary

The save-stability infrastructure consumed by generator v3's `[AnchoredDateTime]`: anchored timestamps are written as **absolute values** and re-based once at load by the elapsed time since the save started — so downtime doesn't age them, and an unchanged entity serializes to identical bytes (the prerequisite for replacing delta-time encodings, which rewrite every entity on every save).

## Design

- **`WriteAnchoredTime` / `ReadAnchoredTime`** on `IGenericWriter`/`IGenericReader`. The read side applies the reader's `AnchoredTimeShift`; `Min/MaxValue` sentinels pass through unshifted, and shifts saturate instead of overflowing.
- **`World.SaveStartTime`** is stamped the moment the world freezes for a snapshot — one anchor for the entire save, no per-persistence skew.
- **idx v5**: the anchor ticks sit in the header right after the version. The anchor travels with the file it re-anchors, so a single idx+bin pair restored from a backup is self-describing, and anchor presence is guaranteed by the same version gate as the record format — there is no separate anchor file to lose.
- **The shift rides the reader instance** (`BufferReader`, `UnmanagedDataReader`, `BinaryFileReader` delegating), not a static — parallel per-persistence loads and ad-hoc restores each see their own file's anchor. idx v4 and older read with a zero shift.

## Scope

Behavior-neutral: nothing serializes anchored values yet (`Item.DecayResetTime` and the `[DeltaDateTime]` field migrations come separately, with their own version bumps). Saves written from this branch are idx v5; loading v4/v3 saves is unchanged and remains pinned by the existing hand-written-header tests.

## Testing

- Unit round-trips: exact with zero shift, shifted read, sentinel passthrough, saturation, Local→UTC normalization.
- End-to-end through the real worker/segment-log pipeline: an anchored timestamp re-bases across a simulated two-hour downtime via the idx v5 header.
- Full suites green: Server.Tests 835/835, UOContent.Tests 708/708 (including the existing v4/v3 idx loading tests).
2026-08-22 15:59:39 -07:00
Kamron Batman
541dbc5ac5
feat: Bumps dependencies. Introduces Serialization Generator v3 (#2584)
### Summary

* Upgrades Serialization Generator to v3. This contains numerous bug fixes and a significant performance improvement.
* Bumps other dependencies.
2026-08-22 15:48:53 -07:00
Kamron Batman
971d7b6a77
fix: stop items from insta-decaying when decay eligibility is restored without a move (#2583)
## Summary

A GM flipping `Movable` back on for a long-frozen item made it vanish within one scheduler tick. The setter registered the item with a deadline computed from its stale `LastMoved`, so `ProcessActiveQueue` deleted it almost immediately. The pre-#2311 save-time sweep had the same semantics, just hidden behind the save cadence. The same failure existed for `Visible` and `Spawner` transitions.

`LastMoved` is deliberately left meaning actual movement — it feeds vendor inventory expiry and house moving-crate checks — so the fix does not rewrite it for state changes.

## Changes

- **`DecayResetTime`** (CompactInfo-backed): the decay countdown runs from the later of `LastMoved` and this stamp. `RestartDecay()` stamps it only when the item can decay and the stamp extends the current deadline, so hot paths with a fresh `LastMoved` allocate nothing.
- **`Movable`/`Visible`/`Spawner` setters** call `RestartDecay()` instead of registering a stale deadline.
- **Region-refusal retry** in `DecayScheduler` uses `RestartDecay()` instead of rewriting `LastMoved`.
- **Persistence**: the stamp survives save/load as a `WriteDeltaTime` delta under `SaveFlag.DecayReset` (to become `WriteAnchoredTime` once the save-time anchor is ported) (Item serialization v10), so a restart mid-window no longer deletes the item.
- **`LastMoved` setter** drops a superseded stamp so the `CompactInfo` can collapse instead of being held (~40 bytes) forever.
- **Raw `Map` setter** now counts as a move for parentless items: it stamps `LastMoved` and updates decay registration, closing the gap where an item moved out of `Map.Internal` via the setter never decayed.
- **`LiftItemDupe`**: the remainder of a partially lifted *ground* stack was placed via raw `Location`/`Map` assignments and never enrolled for decay (lingering-trash leak since #2311) — now enrolled via the Map setter. Parented remainders get their map from `AddItem` (parent first, then map), so container splits never transit the scheduler.
2026-08-22 12:56:00 -07:00
Kamron Batman
fd27b7a3c9
chore: Simplify server requirements section in README (#2582)
Removed unnecessary details about game logic and server requirements.
2026-08-21 19:22:04 -07:00
Kamron Batman
be3a08513f
fix: Fixes PlayerConstructed stacking/BODs (#2579)
### Summary

* Removes player constructed as a requirement for BODs.
* When two items stack and they don't match player constructed flags, the resulting stack loses the flag.
2026-08-14 17:14:38 -07:00
Kamron Batman
2dbaa87377
feat: make the blocklist and manual allowlist opt-in; cut the ban subsystem's on-loop cost (#2577)
Two features ran on every shard out of the box, each polling on its own 60s timer for files most shards never generate, neither ever asked for. Fixing that turned into untangling why they shared a config file — and then into the on-loop cost of the three lists behind them.

## Before / after

Measured on the shipped defaults. On-loop numbers are what freezes the world; the tick budget is 8 ms.

| | before | after |
|---|---:|---:|
| Blocklist poll on a shard with no list | every 60s, forever | **none** (opt-in) |
| Manual allowlist poll on a shard with no carve-outs | every 60s, forever | **none** (opt-in) |
| Promote-guard sweep timer | leaked on `Stop()` | stopped, and only started when hits are reported |
| Login allowlist flush, on-loop | O(n) walk + 2 arrays **every 60s**, LOH past ~5,300 entries | reused buffers, **hourly**, zero steady-state allocation |
| Auto-denylist, accept path | 9.1 ns/call | **6.1 ns/call** |
| Auto-denylist, sustained flood at cap (60k rejected) | 26.7 ms | **9.3 ms** |
| Auto-denylist, flood end — **worst single call** | 9.49 ms | **0.05 ms** |
| Auto-denylist cap | 65,536 (stranding 9,895 slots) | **324,449** (exact `HashSet` capacity, ~19 MB) |

The auto-denylist row that matters is the third: the on-loop stall at flood end drops **190×**, because retiring lapsed holds is now the number expiring rather than the number held.

## Why this design

It is built for the shape of attack these shards actually see: **hundreds to a few thousand connections per second**, occasionally tens of thousands, sustained over minutes rather than delivered instantly. Against that shape the cap now covers the whole observed range (50k–250k distinct sources) in memory, and the work of expiring them spreads across the accept calls that were already happening.

There is one case this design is *worse* at than the old one: if every held entry lapses within the same millisecond, retiring them costs ~10.7 ms against the old ~8.9 ms, because the ring's random-access set removals lose to a sequential dictionary scan. Reaching it requires an entire flood to arrive inside one millisecond. **A shard absorbing 324,449 connections in a millisecond is finished at the accept path no matter what this list does** — that is the point where the answer is upstream security and scrubbing (an L4 proxy, edge filtering, a bouncer at the kernel), not a data structure in the game loop. We chose the design that fits the attacks we see and degrades honestly past them, rather than over-engineering for one we do not.

## Blocklist — now opt-in

`BlocklistFilter.Start` only bailed when `_path == null`, which needs `file` to be empty. The default is `"Configuration/ip-blocklist.txt"`, so on any default install both `Task.Run(PollLoop)` and a recurring `SweepGuard` timer started unconditionally, logging *"Blocklist inert: no list at …; polling every 60s"* and then doing exactly that forever.

Adds `"enabled"`, default `false`, using the `_enabled = s.Enabled && <preconditions>` idiom already in `LoginAllowlist` and `AutoDenylist`. **Upgrade is deliberately loud**: a missing key binds to the default, so `LogWhyDisabled()` splits three cases and a shard with a list on disk but no `enabled` key gets a **Warning**, not silence.

## `FileAllowlist` → `ManualAllowlist`, with its own config

Moves to `Configuration/ip-allowlist.json` (`enabled` default `false`, `files`, `reloadInterval`) and into `Network/ManualAllowlist/`, mirroring `Network/LoginAllowlist/`.

It was never a sub-feature of the blocklist. `ManualAllowlist.Contains` has two callers:

| Caller | Could anything else do it? |
|---|---|
| `BlocklistFilter.Evaluate` | **Yes** — the generator already subtracts these files at generation time |
| `BanExemptions.IsExempt` | **No** — sole mechanism for suppressing behavioural ban contributions |

The second reaches `BanChannel.IsExempt` with no blocklist in the path. A shard running **no blocklist** still needs this so the admin's own IP isn't auto-banned by rate-limit detection, so a shared flag couldn't express it — the implication is asymmetric. They still work together via a startup warning when the blocklist is on and the allowlist is not.

On the name: "File" described the storage. The distinction from `LoginAllowlist` is **provenance** — declared by an operator versus earned by authenticating — and "Manual" matches `BanReasons.Manual`. `allowlistFiles` is removed from `BlocklistSettings` outright; blocklists have not shipped long enough for anyone to have set it.

## Login allowlist flush

`Flush()` allocated two arrays sized to the live entry count and copied the whole dictionary into them **on the game loop**, every 60s. `UInt128` is 16 bytes, so past ~5,300 entries that first array was an LOH allocation once a minute, forever. The file write was already off-loop; the walk was not.

Static buffers grown geometrically; the writer owns them until it posts completion back through `Core.LoopContext`, so `_writing`/`_dirty` stay loop state (rule #10). Interval → 1 hour against a 90-day TTL. Clean shutdown writes synchronously via `EventSink.Shutdown`; `HandleClosed` skips `InvokeShutdown` when crashed, so the crash path subscribes separately and only writes when it is actually on the loop thread. Also fixes a pre-existing hole where `_dirty` was cleared *before* the write, so a failed write dropped entries despite the comment promising a retry.

## Auto-denylist: expiry ring

Reclaiming lapsed holds was O(entries held) — every cap-triggered reclaim during a flood walked the whole dictionary to find the few that expired, and `_warnedFull` suppressed the log, not the work.

A hold is **never refreshed** now: the first detection sets the expiry, later ones leave it. That makes insertion order equal to expiry order, so a ring of the same keys is sorted by construction and retiring stops at the first live record. Nothing is lost — the rate limiter runs *ahead* of the connection filters (`NetState.Network.cs`) and reports to the ban channel, so a flooder whose hold lapses is re-held on its next attempt.

Because the ring carries the expiry, the membership side only answers "present?", so it is a `HashSet` — measured at **36 B/slot against the dictionary's 52**. `HashSet` and `Dictionary` share `HashHelpers`, so the from-empty capacity progression is identical (36,353 → 75,431 → 156,437 → 324,449 → 672,827) and the cap still lands on one exactly. The ring is parallel `UInt128[]`/`long[]` rather than an array of structs — `UInt128` forces 16-byte alignment, so a packed pair costs 32 bytes where these cost 24, and the drain reads only the `long[]`.

Rejected after measuring: splitting the drain into a scan loop plus a removal loop (inside noise — both issue N hash removes, and the pointer math was never the bottleneck), and `Dictionary<UInt128,bool>` with tombstoning instead of removal (10% slower *and* unbounded, which breaks the cap).

## Testing

Build clean, 0 warnings. **1,530 tests pass** — 708 UOContent, 822 Server.

Tests were reworked rather than patched: the refresh test inverts to `Repeat_detection_does_not_extend_the_hold`, the obsolete sweep-throttle test is deleted along with the throttle, and four were added for the ring — set/ring parity, release-then-re-hold not being retired by the stale record, exact fill of a non-power-of-two cap, and the moved allowlist config's casing contract. The throttle test added mid-PR was verified to fail without its fix before being deleted.

One commit is comments only (verified: a diff filtered of `//` lines is empty), removing development narration — a `"(Task 2)"` plan reference, `"matching the per-feature JSON config pattern used by X"` across four loaders, a duplicated threading note — and repointing `Firewall` at `dev-docs/ip-bans-and-allowlists.md` instead of a "ban-channel design doc" that does not exist.

Note `Distribution/Configuration/blocklist.json` is gitignored (`.gitignore:14`) and generated from the record defaults on first boot, so the record default *is* the shipped default.
2026-08-13 23:22:35 -07:00
Kamron Batman
240118340e
fix: stop the idle-sleep backoff tripping on healthy hosts (#2572)
## Problem

The late-wake detector added in #2559 suspends idle sleeping on perfectly healthy hosts. The visible symptom is this Warning firing periodically on stable machines:

> This host returned a 2ms idle wait at least 8ms late 2 time(s) in the last second; idle sleeping suspended for 5000ms

Demoting it to Debug would hide the symptom but not the cost: every one of those lines means the shard dropped idle sleeping for 5s and burned a full core for no reason. The detector is what was mis-tuned.

## Cause 1 — lateness was a count, not a rate

An idle loop performs **~400–500 sleeps per second** (2ms each, bounded by the 8ms wheel tick). The trip condition was `late > 1` across two consecutive one-second samples — a **0.4% tail-outlier rate**. A co-tenant burst, a page fault, or another process changing the system timer resolution clears that bar on a healthy host.

A host that genuinely cannot schedule the process — throttled burstable vCPU — returns *most* of its waits late. Signal and noise were two orders of magnitude apart, and the check sat in the noise.

Now gated on the proportion, with the absolute count kept as a floor:

```csharp
if (late <= _lateWakeThreshold)             { _consecutiveBadSamples = 0; return; }  // floor
if (late * 100 < sleeps * _lateWakePercent) { _consecutiveBadSamples = 0; return; }  // rate
```

New `server.lateWakePercent` (default `10`). The floor is what keeps a window with only a handful of sleeps from tripping on a meaningless percentage; `server.lateWakeThreshold` keeps its existing meaning.

## Cause 2 — GC pauses were charged to the host

`dev-docs/debugging-event-loop.md` already documents that the GC collects preferentially **during idle sleeps** — that is the natural pause point it looks for. So the detector was systematically measuring the GC's chosen pause point and billing it to the host's scheduler. Not an occasional coincidence; a designed-in one.

```csharp
var collections = GC.CollectionCount(1);
NetState.WaitForCompletion(requested);
...
if (elapsed - requested >= Timer.TickRate && GC.CollectionCount(1) == collections)
```

Gen1 (which counts gen2 with it) rather than gen0 — gen0 pauses don't approach the 8ms `TickRate` bar anyway, and gating on them would discard useful samples. The second read short-circuits behind the overshoot test, so the common path costs **one** `GC.CollectionCount` per sleep: an internal counter read, single-digit nanoseconds, ~500/sec.

## Cause 3 — every backoff logged at Warning

Tiered to the escalation that already existed, since a single suspension is recoverable and not something an operator can act on:

| Backoff | Level |
|---|---|
| 1–2 | `Debug` |
| 3–5 | `Warning` (now includes the sleep count and "for the Nth time running") |
| ceiling | `Error`, unchanged |
| recovery | `Information` (new) |

Each backoff doubles the suspension, so every line is already a distinct escalation step — no further rate limiting needed.

## Drive-by

The `BackoffResetAfterCleanMs` reset only ran on the path to a *new* backoff, making it unreachable for a host that recovered for good — such a host never cleared its escalation or re-armed `_loggedBackoffCeiling`. It now runs on every health sample, which is also what makes the new recovery line reachable.

## Testing

Full solution builds clean, 0 warnings. No tests added: the state is private static in `Core` coupled to `_tickCount` with no injection point, and nothing covered it before — adding a seam purely to test it seemed worse than the gap. Happy to add one if reviewers disagree.
2026-08-13 19:58:03 -07:00
Kamron Batman
9b35b39d0d
fix: stop stack merges and splits from laundering PlayerConstructed (#2576)
## Why

`PlayerConstructed` is per-instance provenance, and #2574 put it on every crafted item — including potions, arrows and other stackables. Stack operations were written when no item carried provenance of any kind, so they treated two piles of the same graphic as interchangeable.

**Merging** keeps the receiving stack's value. Dropping bought potions onto a crafted stack made the whole pile count as crafted; the reverse order erased it. Which one happened was decided by drag direction alone.

**Splitting** rebuilds one half in `Mobile.LiftItemDupe`, which copies a fixed list of fields rather than going through `Dupe`/`CopyProperties`. `PlayerConstructed` was not on that list, so dragging part of a pile off stripped the new half. Worth calling out: `[IgnoreDupe]` does **not** govern this path — it only applies to `Dupe()`. Reasoning "the field isn't `[IgnoreDupe]`, so it copies" is wrong here.

## Changes

- `Item.CanStackWith` compares `PlayerConstructed`, so crafted and non-crafted never merge into one indistinguishable pile.
- `Mobile.LiftItemDupe` copies `PlayerConstructed` onto the remainder, so a split cannot produce halves that disagree about what they are.

Refusing to merge is the whole fix. A stack has nowhere to record provenance, so the only coherent behaviour is to keep the two piles apart rather than pick a winner.

## What this deliberately does not do

Paths that genuinely **virtualize** an item — pouring from a `PotionKeg`, for one — rebuild it without the flag, and the result is simply treated as not crafted. That is accepted rather than worked around; the alternative is threading provenance through every count-based container, which buys little. The keg stores a `Held` int rather than a stack, so nothing there depends on merging and nothing breaks.

`CommodityDeed` is unaffected — it holds the real `Commodity` item rather than a count, so the flag rides along.

## Player-visible effect

Crafted potions and arrows will no longer stack with bought or looted ones. That is the intended invariant, and it is the reason the flag can be trusted at all.

## Tests

7 new tests in `Server.Tests`: both merge directions, the matching-provenance case, split copying, and the split/re-merge round trip.

`Server.Tests` **822 passing**, `UOContent.Tests` **701 passing**, build clean with 0 warnings.
2026-08-13 19:18:06 -07:00
Kamron Batman
55ac2c3d98
refactor: Move legacy deserialization into the .Migrations.cs partials (#2575)
Follow-up to #2574, which added a `.Migrations.cs` partial to `BaseWeapon`. Pure relocation — no behaviour change.

## The inconsistency

`BaseArmor` and `BaseClothing` already kept their pre-codegen `Deserialize(reader, version)` in a `.Migrations.cs` partial, but left the `OldSaveFlag` enum and the `GetSaveFlag` helper behind in the main class file — even though every call site is in the partial:

| Class | `Deserialize` | `GetSaveFlag` / `OldSaveFlag` | Call sites outside the partial |
|---|---|---|---|
| `BaseArmor` | already in partial | in main file | 0 of 26 |
| `BaseClothing` | already in partial | in main file | 0 of 12 |
| `BaseWeapon` | in main file | in main file | — |

`BaseWeapon` had all three still inline, with its new `.Migrations.cs` holding only a `MigrateFrom`.

## After

All three follow the same layout: `MigrateFrom` newest to oldest, then the pre-codegen `Deserialize`, then `GetSaveFlag`, then `OldSaveFlag`. That moves ~290 lines of legacy read path out of `BaseWeapon.cs` — the file that needed it most at ~3,900 lines — and leaves the main class files describing only how the type behaves today.

## Reviewing this

The diff is large and almost entirely noise, so it is probably not worth reading line by line. Two checks are stronger:

- **Nothing was lost or altered.** Across each `.cs` / `.Migrations.cs` pair, the multiset of non-blank source lines is identical to `main` except for one added comment (below). The relocation was done mechanically and asserted against that invariant rather than by hand.
- **Nothing about serialization moved with the code.** Running `ModernUOSchemaGenerator` after the move emits no new migration files.

The complete set of intentional additions:

- `using System;` in each of the three partials, for the `[Flags]` attribute (implicit usings are not enabled here).
- `// Version 9 (pre-codegen)` above `BaseWeapon`'s moved `Deserialize`, matching the marker `BaseArmor` and `BaseClothing` already carry. Version 9 is correct because `BaseWeapon.v10.json` is its earliest migration schema, so codegen began at 10.

Everything else is blank-line placement.

## Verification

Full solution builds in Release with 0 errors and 0 warnings; 1516 tests pass (815 `Server.Tests`, 701 `UOContent.Tests`).
2026-08-13 18:43:53 -07:00
Kamron Batman
bd79cb7759
fix: Consolidate PlayerConstructed onto Item, stamped by the craft system (#2574)
Follow-up to #2573. That change made `SmallBOD.EndCombine` require a player-crafted item, but it could only read provenance off `BaseArmor`, `BaseWeapon` and `BaseClothing`, because those are the only three classes that track it — hence the hand-enumerated `armor?.PlayerConstructed ?? clothing?.PlayerConstructed ?? weapon?.PlayerConstructed ?? false`.

The gap is structural rather than cosmetic. `PlayerConstructed` is set inside each base's `OnCraft`, so it can only ever reach types implementing `ICraftable`. Most craftables do not — the tinkering catalogue alone is largely plain `Item` subclasses — so any rule keyed on "was this actually crafted" has nothing to key on for those types.

## What changed

Provenance moves to `Item` and is stamped centrally in `CraftItem`, immediately after the item is constructed and before the `ICraftable` dispatch, covering both the AOS and T2A craft paths. The three `OnCraft` overrides drop their now-redundant assignment and inherit `Item`'s property, so no call site outside them changes — `Resmelt` and `SalvageBag` still read `armor.PlayerConstructed` and still compile unchanged. `SmallBOD`'s three-way null-coalescing chain collapses to `item.PlayerConstructed`.

`OnCraft` is only ever invoked from `CraftItem` (the other three call sites are `base.OnCraft` chaining), so removing those assignments has no other reachable effect.

## Storage cost: none

`Item`'s `SaveFlag` word is written as a fixed-width `int`, not an encoded one, so occupying bit `0x08000000` changes no record lengths. Items that are not player-constructed serialize byte for byte as before, and crafted ones differ by a single bit in a field already being written.

`Item` itself needs no version bump: a bare `SaveFlag` bit is self-describing, so records written before it existed lack it and read `false`.

## Version bumps

The three content classes do need one, since removing a serialized field changes their layout:

| Class | Version | Field removed |
|---|---|---|
| `BaseArmor` | 9 → 10 | 24 (was last, nothing renumbered) |
| `BaseClothing` | 7 → 8 | 7 (fields 8–10 shift down) |
| `BaseWeapon` | 10 → 11 | 26 (fields 27–30 shift down) |

Each gets a `MigrateFrom` for its previous version that assigns the old bool to the inherited property, so existing crafted armour, weapons and clothing keep their provenance across the upgrade. `Item.Deserialize` runs first and reads the absent bit as `false`, then the migration overwrites it — the generated `Deserialize` calls `base.Deserialize` before dispatching, so the ordering holds. `BaseWeapon` had no migrations file and gains one.

The renumbering is not stylistic: the generator requires contiguous field ordering and rejects a hole with `SG3005: Expected field 'Crafter' with order 7 but found 8`.

New schema JSONs (`BaseArmor.v10`, `BaseClothing.v8`, `BaseWeapon.v11`) are generated by `ModernUOSchemaGenerator` and committed alongside.

## One thing worth a second opinion

The new property is a plain auto-property on `Item`, so it does not call `this.MarkDirty()` the way the codegen setters it replaces did. `MarkDirty` is currently a no-op (`// TODO: Add dirty tracking back`) and no property in `Item.cs` calls it, so this matches the file as it stands — but it is worth noting if dirty tracking comes back.

## Verification

Full solution builds in Release with 0 errors and 0 warnings; 1516 tests pass (815 `Server.Tests`, 701 `UOContent.Tests`).
2026-08-13 18:34:59 -07:00
Kamron Batman
5ce0f1e92b
fix: Require BOD combine items to be player-crafted (#2573)
## Problem

`SmallBOD.EndCombine` validates an item's **type**, **material** and **exceptional quality**, but never checks that the item was actually crafted by a player. Any item matching the request is accepted, including one bought straight from an NPC vendor.

https://github.com/modernuo/ModernUO/blob/main/Projects/UOContent/Engines/Bulk%20Orders/SmallBOD.cs#L117-L168

Where a vendor stocks a type a BOD can request, a player can fill the deed by buying the items instead of crafting them, and pocket the reward gold for the difference.

Tailoring is the clearest case. `SmallTailorBOD.CreateRandomFor` guarantees `Material = None` and `RequireExceptional = false` below 70.1 skill, so the rolled deed asks for plain cloth items — and tailor vendors stock several of those directly. A qty-20 Bandana BOD can be filled entirely from vendor stock for a small fraction of the reward gold, with no crafting and no material cost.

The same shape applies anywhere else a vendor-sold type overlaps a requestable BOD type; tailoring is simply where the low-skill deed generator and the vendor inventory overlap most.

## Fix

Add a `PlayerConstructed` check alongside the existing material and quality checks.

```csharp
var playerConstructed = armor?.PlayerConstructed ?? clothing?.PlayerConstructed ??
    weapon?.PlayerConstructed ?? false;

if (!playerConstructed)
{
    from.SendLocalizedMessage(1045169); // The item is not in the request.
}
```

This follows the pattern already used in `Engines/Craft/Core/Resmelt.cs` (L98-L100, L155-L160) to distinguish crafted from store-bought items, and reuses the same null-coalescing chain style as the adjacent `GetMaterial(armor?.Resource ?? clothing?.Resource ?? CraftResource.None)` line directly above it.

`PlayerConstructed` is already set in `OnCraft` and serialized on all three bases (`BaseArmor`, `BaseWeapon`, `BaseClothing`), so the flag survives restarts and no serialization change is needed.

## Open question — the message

There is no dedicated cliloc for "this item must be crafted", so I reused **1045169** (*"The item is not in the request."*). It is arguably accurate — a vendor-bought item genuinely is not what the deed asked for — but it is not precise, and a player who does not know the rule will find it confusing.

I would rather flag this than invent a string. If there is a better cliloc, I am happy to switch it.

## Testing

`dotnet build Projects/UOContent/UOContent.csproj` — **0 errors, 0 warnings**.

Not covered: I have not added an automated test, as I could not find existing coverage for `EndCombine` to extend. Happy to add one if you would like it, with a pointer to the preferred pattern.

## Compatibility note

Any *already-existing* vendor-bought item in a player's possession will now be rejected by a BOD. That is the intended behaviour, but it is a visible change for anyone mid-deed. Worth a line in release notes.
2026-08-12 20:12:54 -07:00
Kamron Batman
1bc83339bb
fix: Fixes guardian lazy check on Treasure Map Chests (#2569)
### Summary

Fixes a crash bug from the lazy check on treasure map chest guardians.
2026-08-10 09:06:43 -07:00
Kamron Batman
c1442aff3e
fix: Stop treasure chest guardian spawn farming via stack splits (#2568)
### Summary

Players reported an exploit: decipher a treasure map, then run a ClassicUO/Razor organizer agent that pulls the gold out of the chest in small amounts. Each pull spawned more monsters, turning one chest into an unbounded farmable spawn generator.

### Root cause

`TreasureMapChest.OnItemLifted` grants a 10% guardian spawn roll per first-time-lifted item, deduplicated by the instance-keyed `_lifted` set. But a partial lift goes through `Mobile.LiftItemDupe`, which re-adds the stack remainder to the chest as a **brand-new item instance** (engine-side `AddItem`, bypassing the `CheckHold` block on refilling). Every subsequent pull lifts an instance the `_lifted` set has never seen, so each one re-rolls the 10% spawn chance:

- A level 4 chest holds 4,000 gold → pulled coin by coin, ~400 spawned creatures (plus more from reagent stacks), hands-free, per chest.
- Spawns use `guardian: false`, so nothing tracks or caps them.
- Legit full-stack looting yields roughly 5–8 bonus spawns per chest for comparison.

The code is inherited from RunUO, so descendant shards likely share the hole.

### Fix

Mark every item that enters the chest **after the initial fill** as already lifted, via an `OnItemAdded` override gated by a non-serialized `_filled` flag (set at the end of the constructor and in `[AfterDeserialization]`). Ordering makes this exact: `LiftItemDupe` re-adds the remainder *before* the chest's `OnItemLifted` runs, so the lifted original still gets its one legitimate roll while the remainder is pre-marked.

This also covers packing items *into* the chest (e.g., merging gold back in to lift it out again) and bounce-backs — anything not part of the original loot can never grant a spawn roll.

### Tests

- `PartialLift_MarksSplitRemainderAsLifted` — drives the real `Mobile.Lift` path with a 1-coin pull and asserts the split remainder is marked (failed before the fix).
- `ItemAddedAfterFill_IsMarkedLifted` — post-fill additions are marked (failed before the fix).
- `OriginalFillLoot_IsNotMarkedLifted` — original loot keeps spawn-roll eligibility.

Full `UOContent.Tests` suite: 701 passed.
2026-08-10 09:01:29 -07:00
Kamron Batman
0628902644
fix: harden idle-sleep scheduling against bad config and misattributed saves (#2567)
Follow-ups to #2559, from a review of the ported idle-sleep/scheduler-health changes.

### Fixes

- **`NetState.IsIdle` omitted `_pendingDisconnects`** — `Slice()` drains five queues; the property checked four. The other deferred work (`_connectingQueue`, alive checks, movement throttle) is time-gated and correctly excluded; the disconnect queue was the only ready-work omission. Impact was bounded (≤ one idle wait of delay), but the property's contract is "sleeping cannot strand pending work".
- **Neither new setting was clamped** (`Main.cs`):
  - `server.lateWakeThreshold: -1` made `late <= threshold` false for every sample even at zero late wakes, so from the second sample on, sleeping was re-suspended every second, forever — a permanent full-core spin whose only trace was a nonsense warning ("… at least 8ms late 0 time(s)").
  - `server.eventLoopIdleWaitMs: -1` disabled sleeping while the admin gump reported **Healthy** (it tested `== 0`).
  - Both now clamp to `>= 0` and log a warning naming the configured value. `-1` is a natural thing to reach for given the sibling key's doc says "set very high to disable".
- **World snapshots were misattributed to `StolenMs`** — `World.Snapshot` ran outside all five profiler phases, so a 3-second save inside a sample read as ~75% stolen, and `debugging-event-loop.md` teaches stolen = "the host ran something else". The diagnostic pointed operators at buying dedicated CPU for their own largest loop-thread stall. Saves now land in a new `WorldSnapshot` phase; `[LoopStats` iterates `PhaseCount` generically, so the report and CSV pick it up with no changes.
- **Admin gump conflated host-forced spin with configured spin** — when the startup probe finds no high-resolution wait support it zeroes the idle wait, after which the gump said "Spinning (configured)" and the operator's config said 2. New `Core.IdleSleepUnsupported` property; the gump now shows "Spinning - host cannot honor short waits" as a distinct fourth verdict. A genuinely configured 0 still reads "configured" (the probe only runs when the configured value was > 0).
- **The backoff-ceiling `Error` logged once per process lifetime** — `_loggedBackoffCeiling` never reset, and at the ceiling the method returns before the `Warning`, so a host that recovered (>60s clean streak) and later degraded back to the ceiling never re-logged the one operator-actionable message. The flag now resets with the clean-streak escalation reset.
- **Removed the unreachable "already suspended, extend" branch** — no sleeps occur while suspended, so `_lateWakes` stays 0 and every suspended sample early-returns before reaching it; with the threshold clamped it can never fire. If sleep gating ever changes, the normal path handles the case by counting a fresh episode.

`dev-docs/debugging-event-loop.md` updated to match (phase list + gump verdict table).

### Verification

- `dotnet build` clean (0 warnings) both normally and with `-p:EventLoopProfiling=true` (the snapshot phase only becomes live IL under the profiling flag).
2026-08-09 22:05:18 -07:00
Kamron Batman
6d846b11e5
perf: Sleep the event loop when idle. Fixes networking micro-stalls. Adds event loop instrumentation. (#2559)
## Problem

`RunEventLoop` span through its body regardless of whether there was anything to do — ~10% of a desktop core for an empty shard, and ~70% of a core on a 3 vCPU VPS. A process that never idles is exactly what burstable vCPU plans throttle, which is how this surfaced: lag spikes that went away when the operator bought more cores. The spin also denied the GC its natural pause points, so memory climbed until a world save forced a collection — alarming in task manager, harmless in practice, and a recurring source of "is my server leaking?" reports.

## Result

Windows desktop, real world of **190,728 items / 33,158 mobiles**, no players, saves and prebake off, three consecutive runs:

| | Legacy spin | Idle sleeping |
|---|---|---|
| **CPU** | 10.42 – 10.50% of one core | **0.78 – 1.00%** |
| **Tick lag** (peak/15s) | 4–10 ms | 5–11 ms |

**~10× less CPU with tick lag unchanged** — the CPU came free rather than being traded for latency. Slower hosts gain proportionally more. Spin mode (`server.eventLoopIdleWaitMs=0`) independently gained **7× the iterations per core** (1.19M → 8.3M cycles/sec) from the ring's AcceptEx rework.

## How

The loop blocks in `NetState.WaitForCompletion` whenever every queue it drains is empty (all the drains are bounded, so leftovers keep it awake). Receive completions, new connections, and cross-thread `LoopContext.Post` (via the ring's sticky `Wake()`) are all in the wait set, so sleeping adds no latency to any of them. Only timer-driven logic sees wheel lag, bounded by the idle wait.

**Health is measured at the only place sleeping can cause harm.** A sleep is bounded by the time to the next wheel turn, so a correctly honoured sleep can never miss a deadline — the only failure mode is the host returning the wait late. That overshoot is measured on every sleep (one extra timestamp read; production's entire accounting cost), and an escalating backoff suspends sleeping when it persists. By construction, server work — saves, heavy staff commands, deep timer callbacks — cannot trip it, so the warning means exactly one thing: *the host is not scheduling the process promptly*, with two known remedies (dedicated CPU, or `=0`). Hosts with no high-resolution wait mechanism at all are detected once at startup and spin instead.

**CPS is removed.** `Core.CyclesPerSecond`/`AverageCPS` measured nothing actionable before and became actively misleading once the loop sleeps (the rate is set by the sleep, not by shard health). The admin gump's Performance page now shows the verdict instead: `Healthy` / `Sleep suspended (host)` / `Spinning (configured)`.

## Configuration

| Setting | Default | Meaning |
|---|---|---|
| `server.eventLoopIdleWaitMs` | `2` | Longest idle block. Measured across 1/2/4/8 ms, 2 is where the trade stops being free. `0` = never sleep: ~98% of a core, zero scheduling overhead — for large shards on dedicated CPU. |
| `server.lateWakeThreshold` | `1` | Idle waits the host may return a full tick late, per second, before sleeping backs off. Raise for jittery hosts; very high disables the backoff. |

## Diagnostics (compiled out by default)

`dotnet build -p:EventLoopProfiling=true` compiles in `EventLoopProfiler` — every hook is `[Conditional("EVENT_LOOP_PROFILING")]`, so normal builds contain zero profiling IL. The profiling build decomposes each second of wall time into **work (per loop phase) / sleep / GC pause / stolen residual**, keeps ~15 minutes of history in a ring buffer, and the `[LoopStats` command prints the last minute and dumps the full history to CSV. `dev-docs/debugging-event-loop.md` is the diagnosis guide (for humans and AI): what production already tells you, when to flip the profiling build, the signature table for host-steal vs deep-processing vs GC vs wake bugs, why dotnet-trace comes last, and the GC/RAM "leak" misconception.

## Verification

- 815 Server.Tests green; both build configurations compile.
- Docker echo harness green on epoll and io_uring (ping-pong mode); kqueue verified manually on an M1 Max.
- A/B measurements and per-change numbers: `measure/event-loop` branch.

## Notes

The full measurement harness and vendored ring sources used to develop this live on the [`measure/event-loop`](https://github.com/modernuo/ModernUO/tree/measure/event-loop) branch, kept for future loop work.
2026-08-09 13:24:59 -07:00
Kamron Batman
a7e65aab01
perf(login): run password hashing on a parked worker thread (#2566)
## Why

An Argon2 verify is **~8.9 ms of frozen world per login attempt** — more than half a 16 ms frame. Failed attempts cost exactly the same as successful ones, by design, so a credential-stuffing flood is a full-cost stall per packet without needing valid credentials. `SetPassword` derives a hash too, so `[password`, the admin gump and account creation each pay the same.

## What the measurement says

Off-loading does not delete the cost, it relocates it. Three things stay on the loop:

| Component | Measured |
|---|---:|
| Inline verify (today) | **8.92 ms** |
| Dispatch to the worker | 210 ns |
| Drain the continuation off `LoopContext` | 13 ns |
| Loop's own work slowed by shared-L3 eviction | **0.05 – 5.44 ms** |

Net gain **3.5 – 8.9 ms** of on-loop time per login. Harness in `ModernUO-Benchmarks` (`Benchmarks/Argon2OffLoop/`): it models the loop as a dependent-load pointer chase swept across working-set sizes, which is an upper bound on cache-latency sensitivity, and copies `EventLoopContext` so the hand-off cost is the real one.

Two results shaped the design:

- **The contention tax peaks in the middle of the working-set range**, not at the top — 5.44 ms at 8 MiB (a quarter of this chip's L3), but 0.76 ms at 30 MiB and 0.10 ms at 256 KiB. A tiny hot set has nothing in L3 to lose; a huge one is already DRAM-bound.
- **Per-login tax falls as concurrency rises** (5.44 → 2.56 → 1.60 ms at 1/2/4 hashers) while *total* loop damage rises. Contention is shared, not additive, so a login rush is not the disaster case — a single login is.

## Why exactly one worker

It is load-bearing three times over, which is also why it must not quietly become a pool:

- **Cost bound.** Off-loop loses to inline only if a hash steals ~82% of the loop's throughput. One hasher contending for one core leaves the loop ~50%. **A single background hasher cannot cost the loop more than the inline verify under any scheduling regime**, which is what lets the measurement hold on hardware we cannot inspect — AMD, VPS, oversubscribed VM. Four hashers drop the loop to ~20% and break it.
- **Memory.** Exactly one hashing arena is live at a time whatever the login volume.
- **Ordering.** Writes apply in dispatch order *only* because a single thread drains FIFO. A second worker would need ordering reintroduced; `WritesApplyInDispatchOrder` fails if that happens.

Throughput is ~110 verifies/sec. Only loop time matters, not login latency, so head-of-line blocking during a rush costs nothing.

## Making every protection safe off-thread

The worker was initially Argon2-only. That was the right call for the wrong reason — it was blamed on Argon2's salt RNG, which is a stateless syscall wrapper and was never a problem. The real blockers were elsewhere, and both are fixed at the source:

| Protection | Was | Now |
|---|---|---|
| MD5/SHA1/SHA2 | shared `HashAlgorithm.ComputeHash`, which carries the running digest across `HashCore`/`HashFinal` through process-wide singletons | static `HashData` into a `stackalloc` span — no state, no allocation, identical bytes |
| PBKDF2 | `Utility.RandomMinMax` → shared `System.Random`, thread-unsafe *and* game state | `RandomNumberGenerator.GetInt32`, matching the salt beside it |
| Argon2 | already safe (`Verify` is static + stackalloc) | unchanged, singleton reused |

Literal digests are pinned in a test **before** the change and still pass after it. These are compared as strings against every account database, so any casing or encoding drift would lock out every SHA and MD5 account at once.

With all three safe, the worker no longer knows which algorithm it runs and the dispatch conditions collapse to "is off-loop available".

## Correctness

- **Phrase derivation** moves to `AccountSecurity.DerivePhrase`, so verification (stored algorithm's rule) and rehash (target algorithm's rule) cannot disagree. Deriving with the wrong one is the shape of the lockout fixed in #2562.
- **Liveness** is checked at dequeue *and* at apply — a connection can drop while queued or while the result sits in the loop queue. A job with no connection attached, such as an admin password change, runs regardless.
- **Queue overflow rejects** a login rather than verifying inline; steering work back onto the loop is what a flood wants. A password change instead falls back to hashing inline, because unlike a login it must not be dropped.
- **Shutdown and crash** both just stop the thread, and pending jobs are dropped. No save is initiated once shutdown begins — saving is the operator's choice up front, via the admin gump's save/no-save variants, and `WaitForWriteCompletion` honours one already in flight — so a write applied during teardown would reach no disk. The crash path needs its own subscription because `HandleClosed` skips `InvokeShutdown` when crashed.

## Bounding

`MaxPending` is 4096 — a backstop, not a flood defense. `SentFirstPacket` holds a connection to one pending verify and the engine caps connections at 4096, so the queue is already bounded by construction and this can only trip if that invariant breaks. A cap low enough to blunt an attack would reject real players first; during a mass reconnect they *are* the queue. Flood defense belongs at the connection layer.

The real DoS improvement is elsewhere: today every attempt stalls the world, and after this a flood occupies one core while the loop keeps ticking.

## Gate

Release builds on 4+ cores. Below that there is no spare core to move work to, so off-loading buys nothing by construction; `DEBUG` is excluded because dev boxes and test shards have few logins. Both modes call the same code — the gate only chooses where it runs.

## Engine change

One property, `AccountLoginEventArgs.Deferred`, so a subscriber can say "no verdict yet". `EventSink.AccountLogin` is `Action<...>` with no continuation, and the packet handler replies in the same call. Approved separately since it touches `Projects/Server/`.

## Docs

`dev-docs/threading-model.md` and the threading skill gain a vetted-workers section. The forbidden-patterns table bans `new Thread`, `ConcurrentQueue<T>`, `Interlocked` and `volatile` in `UOContent`, and its exceptions covered only `Projects/Server/` — the existing Advanced Search fan-out already sat outside it. The new section leads with proving the need (measure on-loop time, not wall-clock; gate on core count; record the measurement), keeps game logic on the loop via chunking, and documents the hand-off protocol in both directions.

## Testing

698 UOContent tests, 810 Server tests, Release build clean.

Covered: verify and rehash outcomes, phrase rules for SHA1/SHA2 vs Argon2, stored-format stability for MD5/SHA1/SHA2, jobs with no connection attached, and dispatch ordering through the real queue. The liveness and ordering guards are mutation-verified.
2026-08-09 00:13:34 -07:00
Kamron Batman
cce035f1c3
fix: Removes unnecessary dictionary removal guards (#2565)
## What

`Dictionary<K,V>.Remove` and `HashSet<T>.Remove` do not bump the collection's version, so removing an entry during a `foreach` does not invalidate the enumerator. A number of loops were still paying for a `PooledRefQueue`/`PooledRefList` to collect keys and drain them in a second pass. This drops those guards.

## Why it's safe

Verified against .NET 10.0.10 rather than taken on trust, since the documented guarantee covers only `Dictionary<TKey,TValue>.Remove` while several of these call sites are `HashSet<T>` or enumerate `.Keys`/`.Values`:

| Case | Result |
|---|---|
| `Dictionary` foreach + `Remove` | safe, all entries visited |
| `Dictionary.Keys` / `.Values` foreach + `Remove` | safe, all entries visited |
| `HashSet` foreach + `Remove` | safe, all entries visited |
| `Dictionary` foreach + `Remove` **then `Add`** | throws `InvalidOperationException` |

Reflection on `_version` confirms the mechanism: neither `Dictionary.Remove` nor `HashSet.Remove` touches it. Because `Remove` never bumps the version, the `Keys` and `Values` enumerators are just as safe as the dictionary's own, even though only `Dictionary.Remove` documents the behaviour. No entries were skipped in any case.

The `HashSet` half is confirmed by [stephentoub on dotnet/dotnet-api-docs#8177](https://github.com/dotnet/dotnet-api-docs/issues/8177#issuecomment-1167251052): *"Both HashSet and Dictionary have been improved to support removal during enumeration. The docs may just benefit from updating."* The gap is in the documentation, not the runtime.

`Remove` followed by `Add` in the same enumeration still throws. That is the line this PR does not cross.

## Guards removed

`VisibilityList`, `ChampionTitleSystem`, `Channel`, `BombingRun`, `Ruleset`, `PuzzleChest`, `RaceChangeGump`, `StepCache`, `PlayerMurderSystem`, `VirtueSystem`, `ProjectedItem`, `StaminaSystem`, `AIGroupMovement`, `PromotedGuard`, `AutoDenylist`, `LoginAllowlist`, `AntiMacroSystem`, `DetectHidden`.

Both collection kinds are covered: `Dictionary` (including loops over `.Keys` and `.Values`) and `HashSet` (`ProjectedItem._active`, `PlayerMurderSystem._contextTerms`, `StaminaSystem._resetHash`). In `StaminaSystem.ResetTimer` the `Count == queue.Count → Clear()` branch goes away with the queue — it only existed to avoid paying for N individual removes.

Where the collection supports it, `Contains` + `Remove` and `TryGetValue` + `Remove` also collapse into a single lookup (`if (list.Remove(x))`, `if (m_Pending.Remove(ns, out var state))`).

`Utility.Tidy<K,V>` keeps its two branches: when `K` is serializable the value is not inspected, otherwise the value is. Only the serializable side may be cast, so `Dictionary<Mobile, int>` and `Dictionary<Mobile, string>` stay valid.

## Deliberately unchanged

**`BaseCreature.LoyaltyTimer.OnTick`** keeps its deferred-delete queue. Removing from `World.Mobiles` while enumerating it is safe, but `Mobile.Delete()` is not a `Remove` — it runs `OnDelete`/`OnAfterDelete`, the `OnParentDeleted` cascade over the creature's pack, `DropHolding()`, and region and guild callbacks. Anything in that surface that constructs a `Mobile` is an `Add` into the dictionary being enumerated, which does invalidate it. `BaseHire.PayTimer.OnTick` has the same shape and is likewise untouched.

**Spatial-query buffers** — `GuardedRegion.CallGuards`, `Thunderstorm`, `Exorcism`, `LeverPuzzleController`, `BaseCreature.TeleportPets` — are a different hazard. They buffer the result of a range query because the drain moves or harms mobiles, which mutates sectors mid-enumeration.

**Re-entrant drains.** The `_users` sets in `Firebomb` and the explosion, conflagration and confusion-blast potions look like this pattern but are not: the loop collects, `Clear()`s, and only then runs `Target.Cancel` on each, which can re-enter. `AnimalTrainer` enumerates `pm.Stabled` and drains through `RemoveStabled`, which nulls the `Stabled` field once it empties — safe for an in-flight enumerator, which holds the set reference rather than the field, but subtle enough not to be worth inlining on a cold path.

## Verification

`dotnet build` clean with 0 warnings; 810 Server and 684 UOContent tests pass.
2026-08-08 11:50:01 -07:00
Kamron Batman
f33bcd6006
fix: Bind the login auth id to its account and drop the redundant verify (#2564)
## What

- Bind the login auth id to the account **and** origin address that earned it, make it a CSPRNG draw, expire it after two minutes, and spend it only once its owner presents it.
- Skip the password verify on `GameLogin` (0x91) when the presented id vouches for the submitted username and address.

## Why

A full client login hashes the password twice — `AccountLogin` (0x80) and then `GameLogin` (0x91). At the current Argon2 parameters that is **most of a 16 ms frame each, on the single-threaded game loop**, for every login attempt.

The second verify is redundant. `GameLogin` already requires an id from `_authIDWindow`, and that window is only populated by `GenerateAuthID`, called from `PlayServer` — reachable only after 0x80 has already authenticated the account **in this same process**. ModernUO Gateway has its own auth-id passing mechanism and is out of scope here.

## Why the id needed hardening first

Skipping the verify promotes the id from a correlation token to a bearer token, and it was not one:

- drawn from `Utility.Random` → `BuiltInRng`, a non-cryptographic PRNG
- bound to nothing — `AuthIDPersistence` carried only `Age` and `Version`
- never expiring; `Age` was only read to pick an eviction victim

A guessed id got you nothing while the password was still checked. Without that check it would have been an account takeover, so the id is now a CSPRNG draw, single-use, two-minute TTL, and bound to both the account and the origin address.

What remains is observing a live id on the client's network or machine — which the server cannot defend against under any design, and which already yields the password itself, since the client transmits it in the same handshake.

Network switching mid-login is deliberately unsupported.

## Behaviour

A full verify was always required before this change, and ids never expired, so every "before" is a password check.

| Case | Before | After |
|---|---|---|
| Id absent | Disconnect | Disconnect |
| Address mismatch | Verify | **Disconnect** |
| Account mismatch | Verify | **Disconnect** |
| Expired | Verify | **Verify** |
| Id vouches | Verify | **Skip** |

No case grants access the previous code would have denied. Expiry deliberately falls back to the verify rather than disconnecting — a player can idle, and turning that into a lockout would be a regression for no gain.

## Look, then take

An id is not consumed until the presenter has shown it is theirs. Removing it first would let anyone who lands on a live id burn it, and its owner would arrive to `"Unable to find auth id."` and have to log in again over a packet they had no part in.

The **address is compared before the account**, so a guesser from anywhere else is rejected before a username is ever looked at. That is what makes it safe to leave the id in place on a mismatch: there is no username-enumeration risk to trade against, and the only presenter who could enumerate is already on the victim's own address.

## The window is not a cap

It was 128 entries with the oldest evicted to make room. That is a cap on *concurrent logins*, not a resource bound: 800 people picking a server at once would have live ids discarded and those clients would arrive to `"Unable to find auth id."` — a failed login caused by nothing except other people logging in.

Issuing now sweeps expired entries and lets the window grow if everything in it is still live. Unbounded is safe here: an entry costs a **successful** password verify to create and dies after two minutes, so its size tracks logins genuinely in flight.

Removing an id when its connection drops is not an option, and this was checked rather than assumed — `NetState.cs:787` disconnects the login connection *deliberately*, immediately after the id is issued, and that disconnect is never cancelled. Surviving it is the whole purpose of the id. Expiry is the only correct reclamation.

## Handshake hardening

Choosing a server queues a disconnect, but the queue drains on the *next* slice, so a client pipelining into the same recv buffer can reach the handshake handlers again. Two had no do-once guard:

- `LoginServerSeed` (0xEF) now rejects when `state.Seeded` is already set.
- `PlayServer` (0xA0) now rejects when `state.AuthId != 0` — otherwise a connection that had already spent its id would be handed the spent one back.

Issuing is also idempotent (`EnsureAuthId`), so a connection holds exactly one id by construction and an orphan is impossible rather than something to clean up. The login state machine itself is untouched.

Also fixes a fall-through: the "Unable to find auth id" branch disconnected without returning, then continued with a default entry and nulled `state.Version`.

## Testing

`ConsumeAuthId` is a seam with no `NetState` dependency, so the auth decision is tested directly: vouching, account mismatch, address mismatch, case-insensitive usernames, IPv4-mapped-IPv6, unknown ids, single-use by the owner, **a rejected attempt leaving the id redeemable**, expiry-into-verify, and an 800-id login rush that must evict nobody. Expiry is driven by moving `Core._now`, not by waiting. Every new clause was verified to discriminate by removing it and confirming only its own tests fail.

## Cost

Halves the per-login game-loop cost. This does not make hashing cheaper or move it off the loop — that is gated on a measurement described in `docs/handoffs/2026-08-07-off-loop-argon2-hashing.md`.
2026-08-08 09:25:42 -07:00
Guflly
64e6fe5da8
fix: Warn when sending empty gumps (#2563)
### Summary

Generates a console warning when users receive an empty gump. This will help prevent client side leaks.
2026-08-08 00:55:12 -07:00
Kamron Batman
b2c59191bd
fix: Fixes Argon2 verify correctness and the password upgrade lockout (#2562)
> ⚠️ **Rollback hazard — one-way door once logins are taken.** Serialization is unchanged, so a save
> written by this build still *loads* on the previous one. Its contents do not survive the trip: on
> its first successful login each account is rehashed to `$argon2id$`, and the previous build ships
> Argon2.Bindings 1.19.0, whose `Verify` is gated by the verifier's own configured type and answers
> `false` for an `$argon2id$` hash. **After a shard running this build has accepted logins, do not
> roll back past this commit** — every account that logged in is locked out on the older binary, and
> the only recovery is rolling forward again or resetting passwords by hand. Roll back only from a
> save taken before the first post-deploy login.

Requires [Argon2.Bindings 1.20.0](https://github.com/modernuo/Argon2.Bindings/pull/14), now published.

## What

- Consume `Argon2.Bindings` 1.20.0, which resolves the Argon2 type from the stored PHC string rather than from the verifier's own configuration.
- Default to **Argon2id, m=16384, t=1, p=1** — 8.51 ms against the old Argon2i 8 MiB t=3 at 10.11 ms. Cheaper *and* stronger.
- Rehash on a successful login whenever the stored parameters are stale, not only when the algorithm changes.
- Fix `SetPassword`, which derived the password phrase from the outgoing algorithm while storing it under the incoming one.

## Why

**Verification was gated by the verifier's configured type.** `Verify` passed the instance's own `ArgonType` to native `argon2_verify`, whose `decode_string` rejects a disagreeing `$argon2i$`/`$argon2id$` prefix and returns `DECODING_FAIL` — folded into `false`, the same answer as a wrong password. Switching the default type would have locked out every existing account, and `VerifyAndUpdate` could not have migrated them either: it delegates to the same type-fixed `Verify` and never compared `ArgonType`. Fixed upstream in 1.20.0. The pinned legacy-`$argon2i$` test here fails on 1.19.0 for exactly that reason, which is what makes the package bump load-bearing rather than incidental.

**Changing the defaults would otherwise have reached nobody.** Argon2's PHC string embeds `m`, `t` and `p`, so verification uses the parameters stored with each account, not the configured ones — and verification is the hot path. `CheckPassword` only rehashed when the *algorithm* changed, never when its cost parameters did, so on an established shard the new defaults would have applied to new accounts only. `IPasswordProtection.NeedsRehash` closes that: it defaults to `false`, so PBKDF2 and the `HashAlgorithm` protections are untouched — only Argon2 carries its cost inside the stored value.

**`SetPassword` picked the phrase rule from the wrong algorithm.** SHA1 and SHA2 salt the phrase with the username; Argon2 and PBKDF2 do not. It chose the rule from the *outgoing* algorithm while storing under the *incoming* one, so any algorithm change wrote a credential its own next verify could not reproduce. It now assigns `PasswordAlgorithm` first and derives the phrase from that. Note this ordering is load-bearing and invisible — `UpgradingAlgorithm_DoesNotLockTheAccountOut` is what pins it.

## Cost

Verification is re-derivation, so these are login numbers. A full login calls `CheckPassword` twice — `AccountLogin` (0x80) then `GameLogin` (0x91): **~20 ms before, ~17 ms after**, plus a one-time ~8.5 ms rehash on each account's migrating login.

That cost is still paid on the game loop. Moving hashing off-loop is deliberately **not** in this PR — it needs a pending-auth state in the login handlers, bounding of in-flight hashes, and login rate limiting.
2026-08-08 00:24:59 -07:00
Kamron Batman
23dc6649a0
fix: Require only runtime packages on Linux, and check ICU and tzdata the way the runtime does (#2561)
## Why

ModernUO mandated `-dev` packages on production servers for exactly one reason: `DllImport` never
asks for a versioned SONAME, so `libdeflate.so.0` and `libargon2.so.1` sitting in `/usr/lib` went
unfound, and the `-dev` package's unversioned symlink was the only thing making resolution work.
The `-dev` packages ship no library of their own — operators were installing headers and a static
lib on machines that compile nothing.

Fixed in the binding packages (modernuo/LibDeflate.Bindings#4, modernuo/Argon2.Bindings#13), so
this picks them up and stops asking.

```
LibDeflate.Bindings 1.0.3  -> 1.0.4
Argon2.Bindings     1.17.0 -> 1.19.0
```

## zstd is dropped too, on every platform

ZstdNet bundles `libzstd` for `linux-x64`, `linux-arm64`, `osx-x64`, `osx-arm64` and win, and
nothing shells out to the CLI. Verified: the 15 `ManagedArchive` round-trip tests pass in a
container with no `zstd` package installed and `which zstd` empty. Removed from the README, the
macOS `brew install`, and CI — so the macOS runners now prove it rather than us assuming it.

## NativeLibraryChecker asks a different question

It asked *"is package X installed"* via `dpkg -l` / `rpm -q`. That is what forced `-dev`, and no
hardcoded name works for ICU anyway — its apt package is release-specific (`libicu70` on Ubuntu
22.04, `libicu76` on Debian 13). It now asks *"will the loader find this"*: `NativeLibrary.TryLoad`
on the unversioned name, then `libfoo.so.N` descending through the range the runtime accepts.

It deliberately does not consult a package database or `ldconfig -p`. Both answer a different
question than "will `dlopen` succeed" — see the ICU section below for how that bit.

## What was wrong with the ICU check

`libicuuc` was **inherited, not derived**. It came from translating the old package-name check into
a library probe, without establishing which library that should be. Reviewing it turned up three
defects, all of which could report ICU present on a host where the runtime then refuses to start:

- **`libicui18n` was never probed.** The only ICU names in `libSystem.Globalization.Native.so` are
  `libicuuc` and `libicui18n`. `libicudata` arrives as a dependency of `libicuuc`, and
  `libicuio`/`libicutu`/`libicutest` are never referenced — so that is the complete list, and both
  are checked now.
- **No version floor.** The runtime's `MinICUVersion` is 60, but the probe accepted down to
  `.so.0`. RHEL/CentOS 7 ships ICU 50, which passed and then aborted at startup.
- **The `ldconfig` fast path bypassed the range.** A cache line for `libicuuc.so.50` still matches a
  `libicuuc.so` prefix test, so the floor was unenforceable through it. It also trusts a stale
  cache — observed reporting a deleted `libdeflate` as present. Removed in favour of asking the
  loader directly, which reads the same cache but answers the real question, and which also deletes
  the musl special-case (`ldconfig -p` exits 0 on musl while producing nothing usable).

Worth knowing when this goes wrong in the field: **missing ICU does not throw, it `FailFast`s** —
SIGABRT, exit 134, uncatchable. The process starts cleanly and dies later at whatever line first
touches a culture, so the stack rarely implicates ICU.

## tzdata is a separate prerequisite, and nothing was checking it

The event scheduler resolves configured zone IDs through `TimeZoneInfo`, which reads
`/usr/share/zoneinfo`. It is data rather than a library, so no loader probe finds it, and slim
container images routinely omit it. Without it every lookup except `UTC` throws
`TimeZoneNotFoundException` and `GetSystemTimeZones()` returns 1 entry instead of ~419.

There is no per-zone packaging to opt into — it is ~2 MB for the whole set. The one split that does
exist is a trap rather than an optimization: Debian 12 and Ubuntu 24.04 move the legacy aliases into
`tzdata-legacy`, so plain `tzdata` has `America/New_York` and `EST5EDT` but is **missing
`US/Eastern` and `Asia/Calcutta`**. A shard configured with a legacy alias throws even though tzdata
is installed. Documented, with both fixes.

## Why `InvariantGlobalization` stays false

Dropping ICU entirely by turning on invariant mode looks tempting and is not safe. Because
`Directory.Build.props` also sets `PredefinedCulturesOnly=false`, invariant mode does **not** throw
`CultureNotFoundException` — it silently hands back invariant data. Measured on .NET 10:

| Behaviour | With ICU | Invariant mode |
|---|---|---|
| `new CultureInfo("de-DE")` | real culture | succeeds, returns invariant data |
| de-DE decimal separator | `,` | `.` |
| `1234.5` as de-DE | `1.234,5` | `1,234.5` |
| `string.Compare("a", "B", InvariantCulture)` | `-1` (linguistic) | `31` (ordinal) |
| sort `[b, A, a, B]` | `a, A, b, B` | `A, B, a, b` |
| `FindSystemTimeZoneById("Eastern Standard Time")` on Linux | resolves | `TimeZoneNotFoundException` |
| UTF-8 round-trip of non-ASCII | unaffected | unaffected |

Number parsing and formatting produce wrong values with no error, and culture-sensitive sort order
silently becomes ordinal. Encoding is not the mechanism — UTF-8 round-trips fine either way.

## Documentation

The rationale now lives in `dev-docs/platform-prerequisites.md` rather than in comments, so it is
discoverable without reading the build tool: what each dependency is for, what breaks without it,
per-distro package names, the ICU floor, the `tzdata-legacy` split, and why the check asks the
loader instead of the package manager.

README drops `libicu-dev`. Matching the runtime package by pattern (`'^libicu[0-9]+$'`) is
version-independent without pulling in headers, so **no `-dev` package is required on any supported
distribution** — which was the point of the whole change.

## CI now proves the claim instead of contradicting it

The dnf job already installed runtime packages only. The apt job installed `libicu-dev`, which ships
the unversioned `libicuuc.so` symlink — so every probe succeeded on the first attempt and the
versioned-SONAME fallback this PR depends on was never exercised. Switched to the pattern match,
verified to resolve exactly one package on jammy (70), bookworm (72), noble (74) and trixie (76).

Added an assertion that the unversioned symlinks are absent. Without it the suite silently stops
testing anything the moment a base image starts shipping one. Verified against all eight matrix
distributions — none ship them — and confirmed the step fails as intended when a symlink is planted.

## Audit of every other native entry point

Checked whether anything else has the same hazard. It does not:

| Import | Verdict |
|---|---|
| `ws2_32.dll` — `SocketHelper` | Always present on Windows |
| `libc` — `SocketHelper` | **Verified safe**, see below |
| ZstdNet → `libzstd` | Bundled for every RID |
| IORingGroup | No native library; raw syscalls |
| ICU | Loaded by the .NET runtime itself, which probes versioned suffixes |

`libc` deserved a hard look, because `libc.so` *is* a `libc6-dev` linker script while the real
library is `libc.so.6` — the same shape as the bug being fixed. It is not affected. Measured in a
container with no `libc6-dev`:

```
/usr/lib/x86_64-linux-gnu/libc.so   ABSENT
/lib/x86_64-linux-gnu/libc.so.6     present
TryLoad("libc")     LOADED      <- resolves where "libdeflate" would not
TryLoad("libc.so")  not found
getpid() -> DllImport("libc") WORKS
```

Confirmed on Alpine/musl as well. No code in this repo registers a `DllImportResolver`, and nothing
else P/Invokes.

## `--check-prereqs`

New flag. `Program.cs` only ran the SDK check in non-interactive mode — `NativeLibraryChecker` was
reachable only through the Spectre-driven guided flow, so there was no way to verify a deployment
target from a script or a container. It is what made the container verification below possible, and
it prints the exact ICU package for the running release via `apt-cache`.

It renders through the same `PrerequisiteChecker` the guided menu uses, rather than a second
hand-rolled table that could drift from it. Spectre drops ANSI styling on its own when stdout is not
a terminal, so redirected output stays clean; the console width is widened in that case so the
install hints, which are shell commands meant to be copied, do not gain a newline mid-command.

```
╭───────────────────────────╮
│ Checking native libraries │
╰───────────────────────────╯

  ✔ libicuuc (Found)
  ✔ libicui18n (Found)
   libdeflate (Not found)
   tzdata (Not found — every zone except UTC will throw)

  ⚠️ Install the missing dependencies. The -dev/-devel packages are not required:
   sudo apt-get install -y libicu74 libdeflate0 tzdata
```

Exit code carries the machine-readable half: 0 when everything resolves, 1 when anything is missing.

## Verification

Against 1.0.4 and 1.19.0: build plus **810 Server.Tests and 642 UOContent.Tests**, on Windows and
on Linux with **only** `libdeflate0` and `libargon2-1` installed — with the absence of the
unversioned symlink asserted first so the run could not pass for the wrong reason.

`--check-prereqs` verified in containers on Debian and Alpine across every state that matters: all
present, each dependency removed individually, tzdata removed, a deliberately stale `ldconfig`
cache, and ICU downgraded to `.so.50` to confirm the floor rejects it. Package resolution and the
absence of unversioned symlinks checked on all eight CI distributions.
2026-08-07 15:03:08 -07:00
274 changed files with 10146 additions and 2951 deletions

View file

@ -3,7 +3,7 @@
"isRoot": true,
"tools": {
"modernuoschemagenerator": {
"version": "2.14.3",
"version": "4.0.0",
"commands": [
"ModernUOSchemaGenerator"
]

View file

@ -46,7 +46,7 @@ jobs:
- name: Install Prerequisites
run: |
brew update
brew install icu4c libdeflate zstd argon2
brew install icu4c libdeflate argon2
- name: Set Library Path
run: echo "DYLD_LIBRARY_PATH=/opt/homebrew/lib:$DYLD_LIBRARY_PATH" >> $GITHUB_ENV
- name: Build
@ -124,12 +124,36 @@ jobs:
dnf config-manager --set-enabled crb
dnf install -y epel-release
if: ${{ matrix.epel }}
# Runtime packages only, deliberately. Installing the -dev packages here would add the
# unversioned .so symlink and mask the very thing the binding packages now probe for, so a
# regression in versioned-SONAME resolution would sail through CI.
- name: Install Prerequisites using dnf
run: dnf makecache --refresh && dnf install -y findutils libicu libdeflate-devel zstd libargon2-devel
run: dnf makecache --refresh && dnf install -y findutils libicu libdeflate libargon2 tzdata
if: ${{ matrix.packageManager == 'dnf' }}
# ICU's runtime package carries the ABI version in its name (libicu70 on jammy, libicu76 on
# trixie) and has no stable alias, so match it by pattern. libicu-dev was the old way to stay
# version-independent, but it drags in the unversioned symlink and defeats the check below.
- name: Install Prerequisites using apt
run: apt-get update -y && apt-get install -y curl libicu-dev libdeflate-dev zstd libargon2-dev tzdata
run: apt-get update -y && apt-get install -y curl '^libicu[0-9]+$' libdeflate0 libargon2-1 tzdata
if: ${{ matrix.packageManager == 'apt' }}
# Versioned-SONAME resolution is only under test while the unversioned symlink is absent. If a
# base image or a package ever starts shipping it, every probe would succeed on the first try
# and a regression in the fallback would sail through CI, so fail loudly instead of silently
# testing nothing.
- name: Assert the unversioned .so symlinks are absent
run: |
found=""
for lib in libicuuc libicui18n libdeflate libargon2; do
hit=$(ls /usr/lib/*/"$lib".so /usr/lib64/"$lib".so 2>/dev/null || true)
if [ -n "$hit" ]; then
found="$found $hit"
fi
done
if [ -n "$found" ]; then
echo "::error::Unversioned symlinks present, so CI is no longer exercising versioned SONAME resolution:$found"
exit 1
fi
echo "No unversioned symlinks present; versioned SONAME resolution is under test."
- uses: actions/checkout@v7
with:
fetch-depth: 0 # avoid shallow clone so nbgv can do its work.

2
.gitignore vendored
View file

@ -14,6 +14,7 @@
/Distribution/Configuration/blocklist.json
/Distribution/Configuration/crowdsec.json
/Distribution/Configuration/expansion.json
/Distribution/Configuration/firewall.json
/Distribution/Configuration/ip-allowlist*.txt
/Distribution/Configuration/ip-allowlist*.txt.tmp
/Distribution/Configuration/ip-blocklist.txt
@ -25,6 +26,7 @@
/Distribution/Configuration/email-settings.json
/Distribution/Configuration/throttles.json
/Distribution/Configuration/tot.json
/Distribution/Data/Pathfinding
/Distribution/Logs
/Distribution/Archives
/Distribution/Backups

View file

@ -18,8 +18,8 @@ Apply these when writing or reviewing `.cs` files under `Projects/`.
6. **Cancel timers in `OnDelete()`/`OnAfterDelete()`** — call `_token.Cancel()` or `_timer?.Stop()`
7. **`STArrayPool<T>.Shared`** not `ArrayPool<T>.Shared` — single-threaded optimized, no locks
8. **`PooledRefList<T>`** not `new List<T>()` on hot paths — zero GC pressure, stack-allocated ref struct
9. **Serialization** — class must be `partial`, constructor needs `[Constructible]`, `TimerExecutionToken` must NOT have `[SerializableField]`. New classes: use `[SerializationGenerator(version)]` (omit `encoded`). When bumping versions, add `MigrateFrom(VXContent)` (X = previous version). Never modify `Deserialize(reader, version)` for version bumps — that method is only for pre-codegen legacy saves. When migrating from pre-codegen Serialize/Deserialize: pass `false` if old code used `reader.ReadInt()`, bump version +1, and keep old logic as `private void Deserialize(IGenericReader reader, int version)``dev-docs/runuo-migration-docs/02-serialization.md`
10. **No `Task.Run`/`new Thread()` for game logic** (tandem with rule #3) — game logic is the single-threaded event loop. Backgrounding is allowed only for work that does not itself touch game state (external service calls, large-file parse). When such work must *feed* game logic: run the heavy/I/O part off-loop and `ConfigureAwait(false)` its awaits so a continuation never resumes on the loop and silently foregrounds heavy work; then hand the result back **explicitly** — publish an immutable snapshot swapped via a `volatile` reference (the loop reads it lock-free), or marshal the apply step with `Core.LoopContext.Post(() => …)`. Never touch game state off-thread; never let the scheduler decide where the heavy work runs → `dev-docs/threading-model.md`
9. **Serialization** — class must be `partial`, constructor needs `[Constructible]`, `TimerExecutionToken` must NOT have `[SerializableField]`. New classes: use `[SerializationGenerator(version)]` (omit `encoded`). Setters that coerce/veto/run side effects: use `[SerializableField]` args `allowFieldChange: nameof(BoolRefMethod)` / `fieldChanged: nameof(OldNewMethod)` — reserve `[SerializableProperty]` for custom getters. Serializable `Timer` members declare `[DeserializeTimer(nameof(Method))]` on the field (anchored by default — downtime preserves remaining delay; `wallClock: true` = absolute; method runs only when a timer was running at save). Conditional writes: `[SaveFlag(nameof(Should), nameof(Default))]` on the field. When bumping versions, add `MigrateFrom(VXContent)` (X = previous version). Never modify `Deserialize(reader, version)` for version bumps — that method is only for pre-codegen legacy saves. When migrating from pre-codegen Serialize/Deserialize: pass `false` if old code used `reader.ReadInt()`, bump version +1, and keep old logic as `private void Deserialize(IGenericReader reader, int version)` `dev-docs/serialization.md`, `dev-docs/runuo-migration-docs/02-serialization.md`
10. **No `Task.Run`/`new Thread()` for game logic** (tandem with rule #3) — game logic is the single-threaded event loop. Backgrounding is allowed only for work that does not itself touch game state (external service calls, large-file parse). **Prove the need before adding a thread**: measure **on-loop** time, not wall-clock (frozen world is the cost, player latency is not), and gate on `Environment.ProcessorCount` — off-loading creates no CPU and buys nothing on 12 cores. New workers go in the vetted table in `dev-docs/threading-model.md` with their measurement. When such work must *feed* game logic: run the heavy/I/O part off-loop and `ConfigureAwait(false)` its awaits so a continuation never resumes on the loop and silently foregrounds heavy work; then hand the result back **explicitly** — publish an immutable snapshot swapped via a `volatile` reference (the loop reads it lock-free), or marshal the apply step with `Core.LoopContext.Post(() => …)`, re-validating in the continuation whatever may have changed while it ran. Never touch game state off-thread; never let the scheduler decide where the heavy work runs → `dev-docs/threading-model.md`
11. **Never assume era** — if code uses `Core.AOS`/`Core.SE`/etc., ask which expansion to target
12. **Naming**`_camelCase` private fields, `PascalCase` properties/methods/classes; don't flag legacy `m_` but use `_` for new code
13. **No empty gumps** — every gump must produce visual elements. An empty gump leaks on client+server (no way to close it). Use static `DisplayTo()` to validate before constructing → `dev-docs/gump-system.md`
@ -29,6 +29,7 @@ Apply these when writing or reviewing `.cs` files under `Projects/`.
17. **No `System.Text.StringBuilder`** — use `ValueStringBuilder` with `stackalloc` (bounded output) or `ValueStringBuilder.Create()` (unbounded). Supports `$"..."` interpolation directly. Always use `using var` for disposal. Use `Reset()` instead of reassigning → `dev-docs/string-handling.md`
18. **Interpolation anti-patterns on handler-aware APIs**`Send*`/`Say`/`Emote`/`PublicOverhead*`/`IPropertyList.Add`/gump `AddLabel`/`AddHtml`/`Html.Center`/`SpanWriter.Write*` all have `ref RawInterpolatedStringHandler` overloads that allocate zero strings, but only when the call-site argument is a `$"..."` literal directly. Avoid: ternaries with interpolated branches (`Send(c ? $"a" : $"b")`), switch expressions with interpolated arms, pre-built `var s = $"..."` locals (single-use), `.ToString()` / `.String()` / `string.Format` inside holes, string concat (`{a + b}`), LINQ string ops in holes. Use `:L` format spec for lowercase (`{rank:L}` not `rank.ToString().ToLowerInvariant()`) → `dev-docs/string-handling.md` § Interpolation Anti-Patterns
19. **No `InvalidateProperties()` from inside `GetProperties`** — every property a `GetProperties` override reads must be a pure read. `InvalidateProperties()` rebuilds the list in place (`Reset()` + rebuild), and `Reset()` returns the pooled interpolation buffer — which the compiler rents for the whole `$"..."` expression, so every hole is evaluated while it is live — and rewinds the packet cursor. A getter that invalidates therefore throws `ArgumentNullException` (parameter `"array"`) out of `GetProperties` from an unrelated-looking line, or silently corrupts the tooltip. The engine refuses and logs an error; `DEBUG` throws. Lazy recomputation in a getter is fine — the *notification* is not. Invalidate in the setter that changes the value, or defer with `Timer.DelayCall(InvalidateProperties)``dev-docs/property-lists.md` § Never Invalidate From Inside `GetProperties`
20. **Tick-count math must be wraparound-safe** — compare `Core.TickCount`/`GetTimestamp()` values only by subtraction (`a - b < 0`, never `a < b`), no zero/sign sentinels on tick fields, seed deadline fields from a real tick (never rely on the 0 default). Cloud hypervisors (GCP) pass through the host's never-resetting counter: ticks start enormous and can wrap negative. Linux affected in production; Windows not so far → `dev-docs/tick-counts.md`
## Dev-Docs Reference
@ -45,7 +46,11 @@ Apply these when writing or reviewing `.cs` files under `Projects/`.
| Commands & targeting | `dev-docs/commands-targeting.md` |
| Event system | `dev-docs/events.md` |
| Threading model | `dev-docs/threading-model.md` |
| Server hardware requirements | `dev-docs/server-requirements.md` |
| Debugging event-loop performance (profiling build, decomposition, GC/RAM) | `dev-docs/debugging-event-loop.md` |
| Tick-count overflow rules (subtraction comparisons; GCP pass-through counters) | `dev-docs/tick-counts.md` |
| Server lifecycle & bootstrap phases (Configure/ConfigurePrompts/Initialize) | `dev-docs/server-lifecycle.md` |
| Platform prerequisites (ICU, tzdata, native libs per distro) | `dev-docs/platform-prerequisites.md` |
| Configuration system | `dev-docs/configuration.md` |
| Networking & packets | `dev-docs/networking-packets.md` |
| IP bans, blocklists & allowlists (incl. unblocking a player) | `dev-docs/ip-bans-and-allowlists.md` |
@ -94,7 +99,18 @@ Then copy only the relevant skill files based on the task:
| Migrate persistence (WorldSave) | `migrate-from-runuo/migrate-persistence` |
| Migrate multi-file system | `migrate-from-runuo/migrate-systems` |
To enable a skill: `cp dev-docs/claude-skills/<name>.md .claude/skills/`
To enable a skill — Claude Code loads `.claude/skills/<name>/SKILL.md`; a bare `.md` dropped
directly into `.claude/skills/` is **not** picked up, and newly installed skills appear in the
*next* session:
```sh
# Standard skills (modernuo-*)
mkdir -p .claude/skills/<name> && cp dev-docs/claude-skills/<name>.md .claude/skills/<name>/SKILL.md
# Migration skills — sources live in the migrate-from-runuo/ subfolder, but install under the
# bare skill name (the table's "migrate-from-runuo/<name>" is the source path, not the name):
mkdir -p .claude/skills/<name> && cp dev-docs/claude-skills/migrate-from-runuo/<name>.md .claude/skills/<name>/SKILL.md
```
Migration skills reference the deep docs in `dev-docs/runuo-migration-docs/` and point to existing ModernUO skills for best practices.

View file

@ -63,8 +63,15 @@
<CodeAnalysisRuleSet>..\..\Rules.ruleset</CodeAnalysisRuleSet>
<AnalysisLevel>latest</AnalysisLevel>
</PropertyGroup>
<!-- Event-loop time accounting, compiled out unless requested:
dotnet build -p:EventLoopProfiling=true
See dev-docs/debugging-event-loop.md. Placed last so it appends to whatever the
configuration groups above set DefineConstants to. -->
<PropertyGroup Condition="'$(EventLoopProfiling)'=='true'">
<DefineConstants>$(DefineConstants);EVENT_LOOP_PROFILING</DefineConstants>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Serilog" Version="4.3.1" />
<PackageReference Include="Serilog" Version="4.4.0" />
<PackageReference Include="Serilog.Sinks.Async" Version="2.1.0" />
<PackageReference Include="Serilog.Sinks.Console" Version="6.1.1" />
<PackageReference Include="Nerdbank.GitVersioning" Condition="!Exists('packages.config')">

View file

@ -3,12 +3,16 @@
"level": "VerySlow",
"active": 0.4,
"passive": 0.8,
"activeMove": 0.9,
"passiveMove": 1.5,
"types": []
},
{
"level": "Slow",
"active": 0.3,
"passive": 0.6,
"activeMove": 0.6,
"passiveMove": 1.2,
"types": [
"AntLion", "ArcticOgreLord", "BogThing",
"Bogle", "BoneKnight", "EarthElemental",
@ -28,6 +32,8 @@
"level": "Medium",
"active": 0.25,
"passive": 0.5,
"activeMove": 0.45,
"passiveMove": 1.05,
"types": [
"AcidElemental", "AgapiteElemental", "Alligator",
"AncientLich", "Betrayer", "Bird",
@ -108,6 +114,8 @@
"level": "Fast",
"active": 0.2,
"passive": 0.4,
"activeMove": 0.3,
"passiveMove": 0.9,
"types": [
"LordOaks", "Silvani", "AirElemental",
"AncientWyrm", "Balron", "BladeSpirits",
@ -139,6 +147,8 @@
"level": "VeryFast",
"active": 0.125,
"passive": 0.30,
"activeMove": 0.125,
"passiveMove": 0.6,
"types": [
"Barracoon", "Mephitis", "Neira",
"Rikktor", "Semidar", "EnergyVortex",

View file

@ -14,4 +14,11 @@ public sealed class BuildOptions
public string? Arch { get; set; }
public bool SkipPrereqs { get; set; }
public bool Interactive { get; set; }
/// <summary>
/// Report the native library prerequisites and exit. The interactive flow is the only other
/// path that runs these checks, so without this there is no way to verify a deployment target
/// from a script or a container.
/// </summary>
public bool CheckPrereqsOnly { get; set; }
}

View file

@ -17,6 +17,5 @@
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Spectre.Console" Version="0.57.2" />
<PackageReference Update="Serilog" Version="4.4.0" />
</ItemGroup>
</Project>

View file

@ -1,3 +1,4 @@
using System.Runtime.InteropServices;
using BuildTool.Platform;
using BuildTool.Publishing;
@ -31,8 +32,10 @@ public static class NativeLibraryChecker
"Linux",
[
".NET 10 Runtime — https://dotnet.microsoft.com/download/dotnet/10.0",
"Debian/Ubuntu: sudo apt-get install -y libicu-dev libdeflate-dev zstd libargon2-dev",
"Fedora/RHEL: sudo dnf install -y libicu libdeflate-devel zstd libargon2-devel",
"Debian/Ubuntu: sudo apt-get install -y libdeflate0 libargon2-1 libicuNN tzdata",
" (libicuNN varies by release, e.g. libicu76 — run build-tool --check-prereqs there for the exact name)",
" (add tzdata-legacy if the shard is configured with an alias such as US/Eastern)",
"Fedora/RHEL: sudo dnf install -y libdeflate libargon2 libicu tzdata",
"CentOS: Also requires epel-release and CRB enabled"
]
),
@ -176,82 +179,59 @@ public static class NativeLibraryChecker
return results;
}
/// <summary>
/// Native libraries the server needs from the system on Linux, and the SONAME range to accept
/// for each. Rationale and per-distro package names: dev-docs/platform-prerequisites.md.
/// </summary>
private static readonly (string Name, int MinSoVersion, int MaxSoVersion)[] _linuxLibraries =
[
("libicuuc", 60, 120),
("libicui18n", 60, 120),
("libdeflate", 0, 9),
("libargon2", 0, 9)
];
private static List<PrerequisiteResult> CheckLinux(PlatformInfo platform)
{
return platform.PackageManager switch
{
PackageManager.Apt => CheckLinuxApt(),
PackageManager.Dnf => CheckLinuxDnf(platform),
_ => CheckLinuxGeneric(platform)
};
}
private static List<PrerequisiteResult> CheckLinuxApt()
{
var results = new List<PrerequisiteResult>();
var packages = new[] { "libicu-dev", "libdeflate-dev", "zstd", "libargon2-dev" };
var missing = new List<string>();
foreach (var package in packages)
foreach (var (name, minSoVersion, maxSoVersion) in _linuxLibraries)
{
var result = ProcessRunner.RunCaptured("dpkg", $"-l {package}");
var installed = result.Success && result.StandardOutput.Contains("ii");
var found = CanLoad(name, minSoVersion, maxSoVersion);
if (!installed)
if (!found)
{
missing.Add(package);
missing.Add(name);
}
results.Add(new PrerequisiteResult
{
Name = package,
Passed = installed,
Details = installed ? "Installed" : "Not installed"
Name = name,
Passed = found,
Details = found ? "Found" : "Not found"
});
}
if (missing.Count > 0)
var hasTimeZoneData = HasTimeZoneData();
if (!hasTimeZoneData)
{
results.Add(new PrerequisiteResult
{
Name = "Install all missing",
Passed = false,
IsWarning = true,
Details = "Run the following command to install all missing dependencies:",
InstallCommand = $"sudo apt-get install -y {string.Join(' ', missing)}"
});
missing.Add("tzdata");
}
return results;
}
private static List<PrerequisiteResult> CheckLinuxDnf(PlatformInfo platform)
{
var results = new List<PrerequisiteResult>();
var packages = new[] { "libicu", "libdeflate-devel", "zstd", "libargon2-devel" };
var missing = new List<string>();
foreach (var package in packages)
results.Add(new PrerequisiteResult
{
var result = ProcessRunner.RunCaptured("rpm", $"-q {package}");
var installed = result.Success;
Name = "tzdata",
Passed = hasTimeZoneData,
Details = hasTimeZoneData ? "Found" : "Not found — every zone except UTC will throw"
});
if (!installed)
{
missing.Add(package);
}
results.Add(new PrerequisiteResult
{
Name = package,
Passed = installed,
Details = installed ? "Installed" : "Not installed"
});
if (missing.Count == 0)
{
return results;
}
// Check if this is CentOS (needs EPEL)
var isCentOs = platform.DistroId?.Equals("centos", StringComparison.OrdinalIgnoreCase) == true;
if (isCentOs && missing.Count > 0)
if (platform.DistroId?.Equals("centos", StringComparison.OrdinalIgnoreCase) == true)
{
results.Add(new PrerequisiteResult
{
@ -263,48 +243,131 @@ public static class NativeLibraryChecker
});
}
if (missing.Count > 0)
results.Add(new PrerequisiteResult
{
results.Add(new PrerequisiteResult
{
Name = "Install all missing",
Passed = false,
IsWarning = true,
Details = "Run the following command to install all missing dependencies:",
InstallCommand = $"sudo dnf install -y {string.Join(' ', missing)}"
});
}
Name = "Install all missing",
Passed = false,
IsWarning = true,
Details = "Install the missing dependencies. The -dev/-devel packages are not required:",
InstallCommand = BuildInstallCommand(platform, missing)
});
return results;
}
private static List<PrerequisiteResult> CheckLinuxGeneric(PlatformInfo platform)
/// <summary>
/// tzdata is data, not a library, so no loader probe finds it. Asking the runtime rather than
/// stat'ing a path keeps TZDIR honoured, and the count is still accurate under
/// InvariantGlobalization, which this tool runs with — only display names degrade there.
/// </summary>
private static bool HasTimeZoneData()
{
var results = new List<PrerequisiteResult>();
// Use ldconfig to check for shared libraries
var ldResult = ProcessRunner.RunCaptured("ldconfig", "-p");
var ldOutput = ldResult.Success ? ldResult.StandardOutput : "";
var libraries = new Dictionary<string, string>
try
{
["libicu"] = "libicuuc",
["libdeflate"] = "libdeflate",
["zstd"] = "libzstd",
["libargon2"] = "libargon2"
};
foreach (var (name, soName) in libraries)
return TimeZoneInfo.GetSystemTimeZones().Count > 1;
}
catch
{
var found = ldOutput.Contains(soName, StringComparison.OrdinalIgnoreCase);
results.Add(new PrerequisiteResult
{
Name = name,
Passed = found,
Details = found ? "Found" : "Not found — install using your package manager"
});
return false;
}
}
/// <summary>
/// Asks the loader directly rather than querying a package database or scanning ldconfig's
/// cache, both of which answer a different question and can disagree with what dlopen will do.
/// Mirrors the binding packages' own probing: the unversioned name first, then libfoo.so.N
/// descending. Bare names go through the full loader search path, so LD_LIBRARY_PATH and
/// /etc/ld.so.conf.d still apply.
/// </summary>
private static bool CanLoad(string library, int minSoVersion, int maxSoVersion)
{
if (TryLoadAndFree($"{library}.so"))
{
return true;
}
return results;
for (var soVersion = maxSoVersion; soVersion >= minSoVersion; soVersion--)
{
if (TryLoadAndFree($"{library}.so.{soVersion}"))
{
return true;
}
}
return false;
}
private static bool TryLoadAndFree(string candidate)
{
if (!NativeLibrary.TryLoad(candidate, out var handle))
{
return false;
}
NativeLibrary.Free(handle);
return true;
}
private static string BuildInstallCommand(PlatformInfo platform, List<string> missing)
{
switch (platform.PackageManager)
{
case PackageManager.Apt:
{
// Distinct because the two ICU libraries resolve to the same package, and
// ResolveAptIcuPackage shells out, so it is memoized rather than called per name.
var packages = missing.Select(
library => library switch
{
"libdeflate" => "libdeflate0",
"libargon2" => "libargon2-1",
"tzdata" => "tzdata",
_ => _aptIcuPackage ??= ResolveAptIcuPackage()
}
).Distinct();
return $"sudo apt-get install -y {string.Join(' ', packages)}";
}
case PackageManager.Dnf:
{
var packages = missing.Select(
library => library switch
{
"libdeflate" => "libdeflate",
"libargon2" => "libargon2",
"tzdata" => "tzdata",
_ => "libicu"
}
).Distinct();
return $"sudo dnf install -y {string.Join(' ', packages)}";
}
default:
return $"Install your distribution's runtime packages for: {string.Join(", ", missing)}";
}
}
private static string _aptIcuPackage;
/// <summary>
/// ICU's apt package carries the ABI version in its name and there is no stable alias, so ask
/// apt which one this release actually ships instead of printing a name that rots.
/// </summary>
private static string ResolveAptIcuPackage()
{
var result = ProcessRunner.RunCaptured("apt-cache", "search --names-only ^libicu[0-9]+$");
if (!result.Success)
{
return "libicu";
}
var best = result.StandardOutput
.Split('\n', StringSplitOptions.RemoveEmptyEntries)
.Select(line => line.Split(' ', 2)[0].Trim())
.Where(name => name.StartsWith("libicu", StringComparison.Ordinal))
.OrderBy(name => int.TryParse(name.AsSpan(6), out var version) ? version : 0)
.LastOrDefault();
return best ?? "libicu";
}
}

View file

@ -4,6 +4,7 @@ using BuildTool.Interactive;
using BuildTool.Platform;
using BuildTool.Prerequisites;
using BuildTool.Publishing;
using Spectre.Console;
Console.OutputEncoding = Encoding.UTF8;
@ -36,6 +37,22 @@ options.Os ??= detectedPlatform.OsRid;
options.Arch ??= detectedPlatform.ArchRid;
var rid = $"{options.Os}-{options.Arch}";
if (options.CheckPrereqsOnly)
{
// Same renderer the guided menu uses, so the two cannot drift. Spectre drops ANSI styling by
// itself when stdout is not a terminal, which is the case this flag exists for, but it also
// falls back to an 80 column width and folds anything longer. The install hints we print are
// shell commands — the CentOS one is 95 characters — and a fold puts a newline in the middle of
// a command that someone is meant to copy. Widen the profile so they stay on one line.
if (Console.IsOutputRedirected)
{
AnsiConsole.Profile.Width = 200;
}
// Exit code is the machine-readable half: 0 when everything resolves, 1 when anything is missing.
return PrerequisiteChecker.CheckNativeLibraries(detectedPlatform, interactive: false) ? 0 : 1;
}
// Run prerequisite checks unless skipped
if (!options.SkipPrereqs)
{
@ -108,6 +125,12 @@ static BuildOptions ParseArguments(string[] args)
hasNamedArgs = true;
break;
}
case "--check-prereqs":
{
options.CheckPrereqsOnly = true;
hasNamedArgs = true;
break;
}
case "--interactive":
{
options.Interactive = true;

View file

@ -5,17 +5,16 @@
<RootNamespace>Server.Tests</RootNamespace>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.8.1" />
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.9.0" />
<PackageReference Include="xunit" Version="2.9.3" />
<PackageReference Include="xunit.SkippableFact" Version="1.5.61" />
<PackageReference Include="xunit.runner.visualstudio" Version="3.1.5">
<PackageReference Include="xunit.runner.visualstudio" Version="4.0.0">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
<ProjectReference Include="..\Application\Application.csproj" />
<DataFiles Include="$(SolutionDir)\Distribution\Data\**" />
<ProjectReference Include="..\UOContent\UOContent.csproj" />
<PackageReference Update="Serilog" Version="4.4.0" />
</ItemGroup>
<!-- Copy native ioring.dll for tests -->
<ItemGroup>

View file

@ -208,6 +208,272 @@ public class DecayRegistrationTests
item.Delete();
}
// Unfreezing an item with a stale LastMoved must grant a fresh decay window,
// not delete it on the next tick.
[Fact]
public void StaleImmovableItemMadeMovable_GetsAFreshDecayWindow()
{
var start = Core._now;
try
{
var item = new Item(0x1234);
item.MoveToWorld(new Point3D(107, 100, 0), Map.Felucca);
item.Movable = false;
Assert.False(DecayScheduler.IsRegistered(item), "A frozen item must not be tracked for decay.");
Core._now = start + TimeSpan.FromDays(30);
var flipped = Core._now;
item.Movable = true;
Assert.True(DecayScheduler.IsRegistered(item), "An unfrozen item must be tracked for decay.");
AdvanceDecay(flipped, item.DecayTime - TimeSpan.FromMinutes(2), item);
Assert.False(item.Deleted, "An unfrozen item must get a full decay window, not vanish immediately.");
AdvanceDecay(Core._now, TimeSpan.FromMinutes(4), item);
Assert.True(item.Deleted, "An unfrozen item must still decay once the fresh window elapses.");
}
finally
{
Core._now = start;
}
}
// Same transition through the Visible setter: unhiding a long-hidden item.
[Fact]
public void StaleHiddenItemMadeVisible_GetsAFreshDecayWindow()
{
var start = Core._now;
try
{
var item = new Item(0x1234);
item.MoveToWorld(new Point3D(109, 100, 0), Map.Felucca);
item.Visible = false;
Assert.False(DecayScheduler.IsRegistered(item), "A hidden item must not be tracked for decay.");
Core._now = start + TimeSpan.FromDays(30);
var flipped = Core._now;
item.Visible = true;
Assert.True(DecayScheduler.IsRegistered(item), "An unhidden item must be tracked for decay.");
AdvanceDecay(flipped, item.DecayTime - TimeSpan.FromMinutes(2), item);
Assert.False(item.Deleted, "An unhidden item must get a full decay window, not vanish immediately.");
AdvanceDecay(Core._now, TimeSpan.FromMinutes(4), item);
Assert.True(item.Deleted, "An unhidden item must still decay once the fresh window elapses.");
}
finally
{
Core._now = start;
}
}
// A refusal restarts the countdown without rewriting LastMoved.
[Fact]
public void RefusedDecay_DoesNotRewriteLastMoved()
{
var start = Core._now;
try
{
var item = new RefusesDecayItem();
item.MoveToWorld(new Point3D(110, 100, 0), Map.Felucca);
var lastMoved = item.LastMoved;
AdvanceDecay(start, item.DecayTime + TimeSpan.FromMinutes(2), item);
Assert.False(item.Deleted, "A refused decay must not delete the item.");
Assert.True(DecayScheduler.IsRegistered(item), "A refused decay must leave the item tracked.");
Assert.Equal(lastMoved, item.LastMoved);
item.Delete();
}
finally
{
Core._now = start;
}
}
// The fresh window must survive a save/load cycle, or a restart mid-window deletes the item.
[Fact]
public void FreshDecayWindow_SurvivesSerialization()
{
var start = Core._now;
try
{
var item = new Item(0x1234);
item.MoveToWorld(new Point3D(111, 100, 0), Map.Felucca);
item.Movable = false;
Core._now = start + TimeSpan.FromDays(30);
item.Movable = true;
var expected = item.ScheduledDecayTime;
var writer = new BufferWriter(new byte[512], true);
item.Serialize(writer);
var copy = new Item(item.Serial);
copy.Deserialize(new BufferReader(writer.Buffer));
// The stamp is stored as a delta, so it ages only by the real time between
// write and read - milliseconds here, the downtime in production.
Assert.True(
(copy.ScheduledDecayTime - expected).Duration() <= TimeSpan.FromSeconds(5),
"The restarted decay window must survive a save/load cycle."
);
item.Delete();
copy.Delete();
}
finally
{
Core._now = start;
}
}
// A real move supersedes the reset stamp; it must be dropped so the CompactInfo can collapse.
[Fact]
public void MovingAnItem_ClearsASupersededDecayResetStamp()
{
var start = Core._now;
try
{
var item = new Item(0x1234);
item.MoveToWorld(new Point3D(112, 100, 0), Map.Felucca);
item.Movable = false;
Core._now = start + TimeSpan.FromDays(30);
item.Movable = true;
Assert.NotEqual(default, item.DecayResetTime);
Core._now += TimeSpan.FromMinutes(1);
item.MoveToWorld(new Point3D(113, 100, 0), Map.Felucca);
Assert.Equal(default, item.DecayResetTime);
Assert.Equal(item.LastMoved + item.DecayTime, item.ScheduledDecayTime);
Assert.True(DecayScheduler.IsRegistered(item));
item.Delete();
}
finally
{
Core._now = start;
}
}
// Losing decay eligibility makes the stamp meaningless; it must be dropped so the
// CompactInfo is not held for as long as the item stays ineligible.
[Fact]
public void ItemBecomingIneligible_DropsTheDecayResetStamp()
{
var start = Core._now;
try
{
var item = new Item(0x1234);
item.MoveToWorld(new Point3D(115, 100, 0), Map.Felucca);
item.Movable = false;
Core._now = start + TimeSpan.FromDays(30);
item.Movable = true;
Assert.NotEqual(default, item.DecayResetTime);
item.Movable = false;
Assert.Equal(default, item.DecayResetTime);
item.Delete();
}
finally
{
Core._now = start;
}
}
// Moving a stamped item into a container programmatically (no drop, no SetLastMoved)
// must also drop the stamp.
[Fact]
public void StampedItemAddedToContainer_DropsTheDecayResetStamp()
{
var start = Core._now;
try
{
var pack = new Container(0xE75);
pack.MoveToWorld(new Point3D(116, 100, 0), Map.Felucca);
var item = new Item(0x1234);
item.MoveToWorld(new Point3D(117, 100, 0), Map.Felucca);
item.Movable = false;
Core._now = start + TimeSpan.FromDays(30);
item.Movable = true;
Assert.NotEqual(default, item.DecayResetTime);
pack.AddItem(item);
Assert.Equal(default, item.DecayResetTime);
pack.Delete();
}
finally
{
Core._now = start;
}
}
// A raw Map assignment (e.g. a GM changing Map through props) is a move: it must
// enroll an untracked item for decay.
[Fact]
public void ItemMovedToRealMapViaMapSetter_IsRegisteredForDecay()
{
var item = new Item(0x1234);
Assert.False(DecayScheduler.IsRegistered(item));
item.Map = Map.Felucca;
Assert.True(item.CanDecay());
Assert.True(DecayScheduler.IsRegistered(item), "Item placed on a map via the Map setter must be tracked.");
item.Delete();
}
// LiftItemDupe places the remainder of a partially lifted ground stack via raw
// Location/Map assignments, with no MoveToWorld fallback: it must still be tracked.
[Fact]
public void PartialLiftOfGroundStack_LeavesRemainderRegisteredForDecay()
{
var stack = new Item(0x1234) { Stackable = true, Amount = 10 };
stack.MoveToWorld(new Point3D(114, 100, 0), Map.Felucca);
var remainder = Mobile.LiftItemDupe(stack, 3);
Assert.NotNull(remainder);
Assert.Equal(7, remainder.Amount);
Assert.Null(remainder.Parent);
Assert.Equal(Map.Felucca, remainder.Map);
Assert.True(
DecayScheduler.IsRegistered(remainder),
"The remainder of a partially lifted ground stack must be tracked for decay."
);
stack.Delete();
remainder.Delete();
}
// Dropping into a container must untrack; taking it back out to the ground must re-track.
[Fact]
public void ItemMovedIntoContainerThenBackToGround_IsRegisteredForDecay()

View file

@ -0,0 +1,95 @@
using Xunit;
namespace Server.Tests;
[Collection("Sequential Server Tests")]
public class PlayerConstructedStackingTests
{
// PlayerConstructed is per-instance provenance, and stack operations were written when no
// item carried any. Merging keeps the receiver's copy of a field and splitting rebuilds one
// half from a fixed list of fields, so a flag that is not accounted for in both places is
// one that ordinary stacking can launder or erase.
// Stands in for a real stackable type. LiftItemDupe builds the remainder through the
// parameterless constructor and copies only a fixed list of fields onto it -- Stackable is
// not on that list -- so the remainder is only stackable if the type restores it the way
// every genuine stackable does.
private class StackableItem : Item
{
public StackableItem() => Stackable = true;
public StackableItem(Serial serial) : base(serial) => Stackable = true;
}
private static StackableItem MakeStack(Serial serial, int amount, bool playerConstructed) =>
new(serial) { Amount = amount, PlayerConstructed = playerConstructed };
[Theory]
[InlineData(false)]
[InlineData(true)]
public void CanStackWith_IsTrueWhenProvenanceMatches(bool playerConstructed)
{
var first = MakeStack((Serial)0x1, 5, playerConstructed);
var second = MakeStack((Serial)0x2, 7, playerConstructed);
try
{
Assert.True(first.CanStackWith(second));
}
finally
{
first.Delete();
second.Delete();
}
}
[Theory]
[InlineData(false)]
[InlineData(true)]
public void LiftItemDupe_CopiesPlayerConstructedToRemainder(bool playerConstructed)
{
var stack = MakeStack((Serial)0x1, 10, playerConstructed);
Item remainder = null;
try
{
remainder = Mobile.LiftItemDupe(stack, 4);
Assert.NotNull(remainder);
Assert.NotSame(stack, remainder);
Assert.Equal(4, stack.Amount);
Assert.Equal(6, remainder.Amount);
Assert.Equal(playerConstructed, remainder.PlayerConstructed);
}
finally
{
stack.Delete();
remainder?.Delete();
}
}
[Fact]
public void SplitHalvesRemainStackableWithEachOther()
{
// The two halves of a split must still be one pile's worth: if the split dropped the
// flag, the remainder would no longer stack back onto what it came from.
var stack = MakeStack((Serial)0x1, 10, true);
Item remainder = null;
try
{
remainder = Mobile.LiftItemDupe(stack, 4);
Assert.NotNull(remainder);
Assert.True(stack.CanStackWith(remainder));
Assert.True(stack.StackWith(null, remainder, false));
Assert.Equal(10, stack.Amount);
Assert.True(stack.PlayerConstructed);
}
finally
{
stack.Delete();
remainder?.Delete();
}
}
}

View file

@ -0,0 +1,69 @@
using Xunit;
namespace Server.Tests;
/// <summary>
/// The event loop only sleeps when every queue it drains is empty. These drains are deliberately
/// bounded -- ExecuteTasks stops at its per-frame cap -- so leftover work is normal and must keep
/// the loop awake. Getting this wrong strands queued work for the length of a sleep.
/// </summary>
[Collection("Sequential Server Tests")]
public class EventLoopIdleTests
{
[Fact]
public void FreshContextIsEmpty()
{
var context = new EventLoopContext();
Assert.True(context.IsEmpty);
}
[Fact]
public void PostedWorkMakesContextNonEmpty()
{
var context = new EventLoopContext();
context.Post(() => { });
Assert.False(context.IsEmpty);
}
[Fact]
public void PriorityWorkMakesContextNonEmpty()
{
var context = new EventLoopContext();
context.Post(() => { }, EventLoopContext.Priority.High);
Assert.False(context.IsEmpty);
}
[Fact]
public void ContextIsEmptyAgainOnceDrained()
{
var context = new EventLoopContext();
context.Post(() => { });
context.ExecuteTasks();
Assert.True(context.IsEmpty);
}
[Fact]
public void WorkBeyondThePerFrameCapKeepsContextNonEmpty()
{
// The cap is what makes IsEmpty necessary: a single ExecuteTasks pass cannot be assumed
// to have drained everything, so the loop must not treat "I just ran tasks" as "idle".
const int perFrameCap = 128;
var context = new EventLoopContext(perFrameCap);
for (var i = 0; i < perFrameCap + 10; i++)
{
context.Post(() => { });
}
context.ExecuteTasks();
Assert.False(context.IsEmpty);
}
}

View file

@ -0,0 +1,76 @@
using System;
using Xunit;
namespace Server.Tests;
[Collection("Sequential Server Tests")]
public class AnchoredItemSerializationTests
{
private static byte[] SerializeItem(Item item)
{
var writer = new BufferWriter(new byte[256], true);
item.Serialize(writer);
return writer.Buffer[..(int)writer.Position];
}
/// <summary>
/// Item v11 stores LastMoved and DecayResetTime as anchored time: the serialized bytes
/// are a function of item state only, not of when the save runs. Pre-v11 stored
/// minutes-since-moved and delta time, which rewrote the bytes on every save.
/// </summary>
[Fact]
public void ItemBytes_AreStable_AcrossSavesAtDifferentTimes()
{
var start = Core._now;
try
{
var item = new Item(0x1F13);
item.MoveToWorld(new Point3D(120, 100, 0), Map.Felucca);
item.RestartDecay();
var first = SerializeItem(item);
// A save hours later, with no state change, must produce identical bytes.
Core._now = start + TimeSpan.FromHours(5);
var second = SerializeItem(item);
Assert.Equal(first, second);
item.Delete();
}
finally
{
Core._now = start;
}
}
/// <summary>
/// Pre-v11 LastMoved was stored at whole-minute precision relative to the save time and
/// could never round-trip exactly. Anchored storage is absolute and exact.
/// </summary>
[Fact]
public void LastMovedAndDecayReset_RoundTripExactly()
{
var item = new Item(0x1F13);
item.MoveToWorld(new Point3D(121, 100, 0), Map.Felucca);
// Sub-minute precision that the old minutes encoding would have destroyed.
var moved = Core.Now - TimeSpan.FromSeconds(90.5) - TimeSpan.FromMilliseconds(123);
item.LastMoved = moved;
item.RestartDecay();
var decayReset = item.DecayResetTime;
Assert.NotEqual(default(DateTime), decayReset);
var bytes = SerializeItem(item);
var restored = new Item((Serial)0x7ffff123u);
restored.Deserialize(new BufferReader(bytes));
Assert.Equal(moved, restored.LastMoved);
Assert.Equal(decayReset, restored.DecayResetTime);
item.Delete();
}
}

View file

@ -0,0 +1,189 @@
using System;
using System.Collections.Generic;
using System.IO;
using Xunit;
namespace Server.Tests;
public class AnchoredTimeTests
{
private static (BufferWriter Writer, Func<TimeSpan, IGenericReader> Read) CreateRoundTrip()
{
var writer = new BufferWriter(new byte[64], true);
return (writer, shift => new BufferReader(writer.Buffer) { AnchoredTimeShift = shift });
}
[Fact]
public void AnchoredTime_RoundTripsExactly_WithZeroShift()
{
var (writer, read) = CreateRoundTrip();
var value = new DateTime(2026, 8, 22, 12, 30, 0, DateTimeKind.Utc);
writer.WriteAnchoredTime(value);
Assert.Equal(value, read(TimeSpan.Zero).ReadAnchoredTime());
}
[Fact]
public void AnchoredTime_AppliesShiftOnRead()
{
var (writer, read) = CreateRoundTrip();
var value = new DateTime(2026, 8, 22, 12, 30, 0, DateTimeKind.Utc);
var shift = TimeSpan.FromHours(3);
writer.WriteAnchoredTime(value);
Assert.Equal(value + shift, read(shift).ReadAnchoredTime());
}
[Fact]
public void AnchoredTime_SentinelsPassThroughUnshifted()
{
var (writer, read) = CreateRoundTrip();
writer.WriteAnchoredTime(DateTime.MinValue);
writer.WriteAnchoredTime(DateTime.MaxValue);
var reader = read(TimeSpan.FromDays(2));
Assert.Equal(DateTime.MinValue, reader.ReadAnchoredTime());
Assert.Equal(DateTime.MaxValue, reader.ReadAnchoredTime());
}
[Fact]
public void AnchoredTime_SaturatesInsteadOfOverflowing()
{
var (writer, read) = CreateRoundTrip();
writer.WriteAnchoredTime(DateTime.MaxValue - TimeSpan.FromMinutes(1));
Assert.Equal(DateTime.MaxValue, read(TimeSpan.FromDays(1)).ReadAnchoredTime());
}
[Fact]
public void AnchoredTime_NormalizesLocalKindOnWrite()
{
var (writer, read) = CreateRoundTrip();
var local = new DateTime(2026, 8, 22, 12, 30, 0, DateTimeKind.Local);
writer.WriteAnchoredTime(local);
Assert.Equal(local.ToUniversalTime(), read(TimeSpan.Zero).ReadAnchoredTime());
}
}
internal class AnchoredEntity : ISerializable
{
public AnchoredEntity(Serial serial) => Serial = serial;
public Serial Serial { get; }
public DateTime Created { get; set; } = DateTime.UtcNow;
public bool Deleted => false;
public DateTime LastRested { get; set; }
public void Delete()
{
}
public void Serialize(IGenericWriter writer) => writer.WriteAnchoredTime(LastRested);
public void Deserialize(IGenericReader reader) => LastRested = reader.ReadAnchoredTime();
}
[Collection("Sequential Server Tests")]
public class AnchoredTimePersistenceTests
{
private class AnchoredPersistence : GenericEntityPersistence<AnchoredEntity>
{
public AnchoredPersistence(int priority) : base("AnchoredTrip", priority, 1, 0x7FFFFFFF)
{
}
}
/// <summary>
/// The idx v5 header carries the save-start anchor; loading re-bases anchored timestamps
/// by the elapsed time since the save started, so downtime does not age them.
/// </summary>
[Fact]
public void SaveStartAnchor_RebasesAnchoredTimestampsAtLoad()
{
var previousAssemblies = AssemblyHandler.Assemblies;
AssemblyHandler.Assemblies = [.. previousAssemblies ?? [], typeof(AnchoredEntity).Assembly];
var source = new SerializationChunkSource();
var workers = new SerializationThreadWorker[2];
for (var i = 0; i < workers.Length; i++)
{
workers[i] = new SerializationThreadWorker(i, source);
workers[i].AllocateHeap();
}
var previousWorkers = World._threadWorkers;
World._threadWorkers = workers;
var previousSaveStart = World.SaveStartTime;
var persistence = new AnchoredPersistence(2100);
AnchoredPersistence loaded = null;
var dir = Path.Combine(Path.GetTempPath(), $"muo-anchored-{Guid.NewGuid():N}");
Directory.CreateDirectory(dir);
try
{
var lastRested = Core.Now - TimeSpan.FromMinutes(10);
var serial = (Serial)1u;
persistence.EntitiesBySerial[serial] = new AnchoredEntity(serial) { LastRested = lastRested };
persistence.RegisterType(typeof(AnchoredEntity));
// Pretend the save started two hours ago, as if the server had been down since.
var downtime = TimeSpan.FromHours(2);
World.SaveStartTime = Core.Now - downtime;
foreach (var worker in workers)
{
worker.Wake();
}
source.SetOwner(persistence);
Assert.True(persistence.TrySnapshotEntries(out var slotCount));
source.PushSlotRanges(persistence, slotCount);
source.Flush();
foreach (var worker in workers)
{
worker.Sleep();
}
persistence.WriteSnapshot(dir);
persistence.PostWorldSave();
loaded = new AnchoredPersistence(2101);
loaded.DeserializeIndexes(dir, null);
loaded.Deserialize(dir, null);
var entity = loaded.EntitiesBySerial[serial];
var expected = lastRested + downtime;
Assert.True(
(entity.LastRested - expected).Duration() <= TimeSpan.FromSeconds(30),
$"Anchored timestamp must re-base by the downtime; expected ~{expected}, got {entity.LastRested}."
);
}
finally
{
World.SaveStartTime = previousSaveStart;
persistence.Unregister();
loaded?.Unregister();
foreach (var worker in workers)
{
worker.Exit();
}
World._threadWorkers = previousWorkers;
AssemblyHandler.Assemblies = previousAssemblies;
Directory.Delete(dir, true);
}
}
}

View file

@ -0,0 +1,234 @@
/*************************************************************************
* ModernUO *
* Copyright 2019-2026 - ModernUO Development Team *
* Email: hi@modernuo.com *
* File: EventLoopProfiler.cs *
* *
* This program is free software: you can redistribute it and/or modify *
* it under the terms of the GNU General Public License as published by *
* the Free Software Foundation, either version 3 of the License, or *
* (at your option) any later version. *
* *
* You should have received a copy of the GNU General Public License *
* along with this program. If not, see <http://www.gnu.org/licenses/>. *
*************************************************************************/
using System;
using System.Diagnostics;
using System.Runtime.CompilerServices;
namespace Server;
public enum LoopPhase
{
MobileDeltas,
ItemDeltas,
TimerSlice,
NetworkSlice,
LoopTasks,
WorldSnapshot,
}
/// <summary>
/// Event-loop time accounting, compiled out of normal builds. Build with
/// <c>-p:EventLoopProfiling=true</c> to enable; every hook is
/// <c>[Conditional("EVENT_LOOP_PROFILING")]</c>, so without the flag the call sites do not exist
/// in the IL and this class is dormant. See dev-docs/debugging-event-loop.md for how to read it.
/// </summary>
/// <remarks>
/// Each one-second sample decomposes wall time into work (per <see cref="LoopPhase"/>), sleep,
/// GC pause, and a stolen residual (wall - work - sleep): time the host ran something else.
/// Samples land in a ring buffer (~15 minutes) so a lag episode can be compared against the good
/// minutes on the same box, build, and world — the baseline RunUO's profiler never had.
/// </remarks>
public static class EventLoopProfiler
{
public const int PhaseCount = 6;
private const int RingSize = 900;
private const long SampleIntervalMs = 1000;
public struct Sample
{
public long WallStart; // Core.TickCount at sample start
public long WallMs; // sample length
public long Iterations;
public long Sleeps;
public double SleepMs; // total time blocked in WaitForCompletion
public double SleepOvershootMaxMs; // worst (elapsed - requested) this sample
public long LateWakes; // overshoot >= Timer.TickRate
public long WheelLagMaxMs; // worst wheel lateness observed at Slice entry
public long WakesIssued;
public long WakesElided;
public double GcPauseMs; // GC.GetTotalPauseDuration delta
public int Gen0;
public int Gen1;
public int Gen2;
public PhaseTimes Phases;
// Work the phases did not account for and the loop did not spend sleeping: host
// scheduling steals, and anything between the bracketed phases. GC pauses inside a
// phase or sleep inflate those measurements instead, so GcPauseMs overlaps rather
// than subtracts.
public double StolenMs
{
get
{
var known = SleepMs + Phases.Total;
return WallMs > known ? WallMs - known : 0;
}
}
}
[InlineArray(PhaseCount)]
public struct PhaseTimes
{
private double _element0;
public double Total
{
get
{
double total = 0;
for (var i = 0; i < PhaseCount; i++)
{
total += this[i];
}
return total;
}
}
}
private static readonly double _msPerTick = 1000.0 / Stopwatch.Frequency;
private static Sample[] _ring;
private static int _ringCount;
private static int _ringHead;
private static Sample _current;
private static long _phaseStartTimestamp;
private static long _sampleStartedAt;
private static TimeSpan _lastGcPause;
private static int _lastGen0;
private static int _lastGen1;
private static int _lastGen2;
/// <summary>Number of samples recorded so far (capped at the ring size).</summary>
public static int SampleCount => _ringCount;
/// <summary>The sample currently being accumulated (not yet in the ring).</summary>
public static Sample Current => _current;
/// <summary>
/// Copies the newest <paramref name="count"/> completed samples, oldest first.
/// </summary>
public static Sample[] History(int count = RingSize)
{
count = Math.Min(count, _ringCount);
var result = new Sample[count];
for (var i = 0; i < count; i++)
{
result[i] = _ring[(_ringHead - count + i + RingSize) % RingSize];
}
return result;
}
[Conditional("EVENT_LOOP_PROFILING")]
public static void IterationStart(long tickCount)
{
if (_ring == null)
{
_ring = new Sample[RingSize];
_sampleStartedAt = tickCount;
_current.WallStart = tickCount;
_lastGcPause = GC.GetTotalPauseDuration();
_lastGen0 = GC.CollectionCount(0);
_lastGen1 = GC.CollectionCount(1);
_lastGen2 = GC.CollectionCount(2);
}
_current.Iterations++;
if (tickCount - _sampleStartedAt < SampleIntervalMs)
{
return;
}
_current.WallMs = tickCount - _sampleStartedAt;
var pause = GC.GetTotalPauseDuration();
_current.GcPauseMs = (pause - _lastGcPause).TotalMilliseconds;
_lastGcPause = pause;
var gen0 = GC.CollectionCount(0);
var gen1 = GC.CollectionCount(1);
var gen2 = GC.CollectionCount(2);
_current.Gen0 = gen0 - _lastGen0;
_current.Gen1 = gen1 - _lastGen1;
_current.Gen2 = gen2 - _lastGen2;
_lastGen0 = gen0;
_lastGen1 = gen1;
_lastGen2 = gen2;
_ring[_ringHead] = _current;
_ringHead = (_ringHead + 1) % RingSize;
if (_ringCount < RingSize)
{
_ringCount++;
}
_sampleStartedAt = tickCount;
_current = default;
_current.WallStart = tickCount;
}
[Conditional("EVENT_LOOP_PROFILING")]
public static void PhaseStart(LoopPhase phase) => _phaseStartTimestamp = Stopwatch.GetTimestamp();
[Conditional("EVENT_LOOP_PROFILING")]
public static void PhaseEnd(LoopPhase phase) =>
_current.Phases[(int)phase] += (Stopwatch.GetTimestamp() - _phaseStartTimestamp) * _msPerTick;
[Conditional("EVENT_LOOP_PROFILING")]
public static void SleepEnd(int requestedMs, long elapsedMs)
{
_current.Sleeps++;
_current.SleepMs += elapsedMs;
var overshoot = elapsedMs - requestedMs;
if (overshoot > _current.SleepOvershootMaxMs)
{
_current.SleepOvershootMaxMs = overshoot;
}
if (overshoot >= Timer.TickRate)
{
_current.LateWakes++;
}
}
[Conditional("EVENT_LOOP_PROFILING")]
public static void WheelSlice(long deltaSinceTurn)
{
var lag = deltaSinceTurn - Timer.TickRate;
if (lag > _current.WheelLagMaxMs)
{
_current.WheelLagMaxMs = lag;
}
}
// Cross-thread; approximate counts are fine for diagnosis, so no interlocked.
[Conditional("EVENT_LOOP_PROFILING")]
public static void WakeSignal(bool elided)
{
if (elided)
{
_current.WakesElided++;
}
else
{
_current.WakesIssued++;
}
}
}

View file

@ -42,10 +42,47 @@ public sealed class EventLoopContext : SynchronizationContext
public override SynchronizationContext CreateCopy() => new EventLoopContext();
public void Post(Action d, Priority priority = Priority.Normal) =>
(priority == Priority.High ? _priorityQueue : _queue).Enqueue(d);
/// <summary>
/// True when no callbacks are waiting to run.
/// </summary>
/// <remarks>
/// <see cref="ExecuteTasks"/> drains at most <c>_maxPerFrame</c> callbacks, so work can
/// legitimately be left over. The event loop checks this before sleeping so a backlog keeps
/// it running instead.
/// </remarks>
public bool IsEmpty => _queue.IsEmpty && _priorityQueue.IsEmpty;
public override void Post(SendOrPostCallback d, object state) => _queue.Enqueue(() => d(state));
public void Post(Action d, Priority priority = Priority.Normal)
{
(priority == Priority.High ? _priorityQueue : _queue).Enqueue(d);
WakeEventLoop();
}
public override void Post(SendOrPostCallback d, object state)
{
_queue.Enqueue(() => d(state));
WakeEventLoop();
}
/// <summary>
/// Nudges the game loop in case it is asleep: the loop blocks on network I/O, which a queue
/// push alone does not signal.
/// </summary>
private void WakeEventLoop()
{
// A post from the loop thread cannot need a wake -- the loop is executing this very call
// -- and the signal is a syscall on every backend.
if (Thread.CurrentThread == _mainThread)
{
EventLoopProfiler.WakeSignal(elided: true);
return;
}
EventLoopProfiler.WakeSignal(elided: false);
// Safe before networking is configured and after teardown; NetState.Wake does nothing.
Network.NetState.Wake();
}
public override void Send(SendOrPostCallback d, object state)
{
@ -63,6 +100,8 @@ public sealed class EventLoopContext : SynchronizationContext
evt.Set();
});
WakeEventLoop();
evt.WaitOne();
}

View file

@ -37,6 +37,13 @@ public class AccountLoginEventArgs
public bool Accepted { get; set; }
public ALRReason RejectReason { get; set; }
/// <summary>
/// No verdict yet: a subscriber moved the password check off the game loop and replies itself
/// once it lands. The packet handler must send neither accept nor reject while this is set, or
/// the client gets two answers to one login.
/// </summary>
public bool Deferred { get; set; }
}
public static partial class EventSink

View file

@ -44,10 +44,10 @@ public partial class Container : Item
internal int _version;
[SerializableField(3)]
[SaveFlag(nameof(ShouldSerializeLiftOverride))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private bool _liftOverride;
[SerializableFieldSaveFlag(3)]
private bool ShouldSerializeLiftOverride() => _liftOverride;
public Container(int itemID) : base(itemID)
@ -84,6 +84,7 @@ public partial class Container : Item
[EncodedInt]
[SerializableProperty(0)]
[SaveFlag(nameof(ShouldSerializeMaxItems), nameof(MaxItemsDefaultValue))]
[CommandProperty(AccessLevel.GameMaster)]
public int MaxItems
{
@ -96,14 +97,13 @@ public partial class Container : Item
}
}
[SerializableFieldSaveFlag(0)]
private bool ShouldSerializeMaxItems() => _maxItems != -1;
[SerializableFieldDefault(0)]
private int MaxItemsDefaultValue() => -1;
[EncodedInt]
[SerializableProperty(1)]
[SaveFlag(nameof(ShouldSerializeGumpId), nameof(GumpIDDefaultValue))]
[CommandProperty(AccessLevel.GameMaster)]
public int GumpID
{
@ -115,14 +115,13 @@ public partial class Container : Item
}
}
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializeGumpId() => _gumpID != -1;
[SerializableFieldDefault(1)]
private int GumpIDDefaultValue() => -1;
[EncodedInt]
[SerializableProperty(2)]
[SaveFlag(nameof(ShouldSerializeDropSound), nameof(DropSoundDefaultValue))]
[CommandProperty(AccessLevel.GameMaster)]
public int DropSound
{
@ -134,10 +133,8 @@ public partial class Container : Item
}
}
[SerializableFieldSaveFlag(2)]
private bool ShouldSerializeDropSound() => _dropSound != -1;
[SerializableFieldDefault(2)]
private int DropSoundDefaultValue() => -1;
[CommandProperty(AccessLevel.GameMaster)]

View file

@ -311,7 +311,7 @@ public class DecayScheduler : Timer
if (timeUntilDecay > _bucketInterval)
{
// Item was moved (SetLastMoved called) - re-bucket or move to overflow
// Deadline was pushed out (SetLastMoved/RestartDecay) - re-bucket or move to overflow
if (timeUntilDecay > _totalBucketSpan)
{
// Extended beyond total span - move to overflow
@ -429,7 +429,7 @@ public class DecayScheduler : Timer
{
// Refused by the region. Restart the clock rather than dropping the item, which has
// already left the queue; re-registering as-is would spin on a due time in the past.
item.SetLastMoved();
item.RestartDecay();
}
}
}

View file

@ -335,7 +335,25 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
[CommandProperty(AccessLevel.GameMaster)]
public virtual bool Decays => Movable && Visible && Spawner == null;
public DateTime LastMoved { get; set; }
private DateTime _lastMoved;
public DateTime LastMoved
{
get => _lastMoved;
set
{
_lastMoved = value;
// A move at or past the reset stamp supersedes it; drop it so the CompactInfo can collapse.
var info = LookupCompactInfo();
if (info != null && info.m_DecayReset != default && info.m_DecayReset <= value)
{
info.m_DecayReset = default;
VerifyCompactInfo();
}
}
}
[CommandProperty(AccessLevel.GameMaster)]
public bool Stackable
@ -373,7 +391,7 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
}
Delta(ItemDelta.Update);
UpdateDecayRegistration();
RestartDecay();
}
}
}
@ -389,7 +407,7 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
SetFlag(ImplFlag.Movable, value);
Delta(ItemDelta.Update);
UpdateDecayRegistration();
RestartDecay();
}
}
}
@ -749,6 +767,12 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
public static bool ScissorCopyLootType { get; set; }
/// <summary>
/// True when the item was produced by the crafting system rather than bought or looted.
/// </summary>
[CommandProperty(AccessLevel.GameMaster)]
public bool PlayerConstructed { get; set; }
[CommandProperty(AccessLevel.GameMaster)]
public bool QuestItem
{
@ -839,7 +863,7 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
public virtual void Serialize(IGenericWriter writer)
{
writer.Write(9); // version
writer.Write(11); // version
var flags = SaveFlag.None;
@ -949,6 +973,11 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
{
flags |= SaveFlag.SavedFlags;
}
if (info.m_DecayReset > LastMoved)
{
flags |= SaveFlag.DecayReset;
}
}
if (info == null || info.m_Weight < 0)
@ -979,16 +1008,21 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
flags |= SaveFlag.ImplFlags;
}
if (PlayerConstructed)
{
flags |= SaveFlag.PlayerConstructed;
}
writer.Write((int)flags);
/* begin last moved time optimization */
var ticks = LastMoved.Ticks;
var now = Core.Now.Ticks;
// Anchored: shifted by downtime at load, so time-since-moved is preserved and the
// bytes are stable across saves while the item does not move.
writer.WriteAnchoredTime(LastMoved);
var minutes = new TimeSpan(now - ticks).TotalMinutes;
writer.WriteEncodedInt((int)Math.Clamp(minutes, int.MinValue, int.MaxValue));
/* end */
if (GetSaveFlag(flags, SaveFlag.DecayReset))
{
writer.WriteAnchoredTime(info.m_DecayReset);
}
if (GetSaveFlag(flags, SaveFlag.Direction))
{
@ -1307,6 +1341,12 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
OnMapChange();
if (m_Parent == null)
{
// A map change is a move; nothing else updates decay registration for a raw Map change.
SetLastMoved();
}
if (old == null || old == Map.Internal)
{
InvalidateProperties();
@ -1537,7 +1577,7 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
if (oldValue != value)
{
UpdateDecayRegistration();
RestartDecay();
}
}
}
@ -1731,6 +1771,7 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
|| info.m_HeldBy != null
|| info.m_BlessedFor != null
|| info.m_Spawner != null
|| info.m_DecayReset != default
|| info.m_TempFlags != 0
|| info.m_SavedFlags != 0
|| info.m_Weight >= 0;
@ -2315,7 +2356,64 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
public virtual bool OnDecay() =>
CanDecay() && Region.Find(Location, Map).OnDecay(this);
public DateTime ScheduledDecayTime => LastMoved + DecayTime;
public DateTime ScheduledDecayTime
{
get
{
var reset = DecayResetTime;
var lastMoved = LastMoved;
return (reset > lastMoved ? reset : lastMoved) + DecayTime;
}
}
/// <summary>
/// When decay eligibility was last restored without the item moving, e.g. a GM unfreezing it.
/// The decay countdown runs from the later of this and <see cref="LastMoved" />.
/// </summary>
public DateTime DecayResetTime
{
get => LookupCompactInfo()?.m_DecayReset ?? default;
private set
{
if (value == default)
{
var info = LookupCompactInfo();
if (info != null && info.m_DecayReset != default)
{
info.m_DecayReset = default;
VerifyCompactInfo();
}
}
else
{
AcquireCompactInfo().m_DecayReset = value;
}
}
}
/// <summary>
/// Restarts the decay countdown without touching <see cref="LastMoved" />: call when decay
/// eligibility changes state (Movable/Visible/Spawner) or a region refuses a decay, where a
/// stale <see cref="LastMoved" /> would otherwise decay the item on the next tick.
/// Stamps <see cref="DecayResetTime" /> only when that extends the current deadline, then
/// updates the scheduler registration.
/// </summary>
public void RestartDecay()
{
if (CanDecay())
{
var now = Core.Now;
if (ScheduledDecayTime < now + DecayTime)
{
DecayResetTime = now;
}
}
UpdateDecayRegistration();
}
public void UpdateDecayRegistration()
{
@ -2325,6 +2423,12 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
{
DecayScheduler.Register(this);
}
else
{
// No countdown to anchor while ineligible; drop the stamp so the CompactInfo
// can collapse. Re-eligibility always re-anchors.
DecayResetTime = default;
}
}
public void SetLastMoved()
@ -2357,6 +2461,11 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
}
Amount += dropped.Amount;
if (PlayerConstructed != dropped.PlayerConstructed)
{
PlayerConstructed = false;
}
dropped.Delete();
if (playSound && from != null)
@ -2657,6 +2766,8 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
switch (version)
{
case 11:
case 10:
case 9:
case 8:
case 7:
@ -2664,7 +2775,11 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
{
var flags = (SaveFlag)reader.ReadInt();
if (version < 7)
if (version >= 11)
{
LastMoved = reader.ReadAnchoredTime();
}
else if (version < 7)
{
LastMoved = reader.ReadDeltaTime();
}
@ -2682,6 +2797,18 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
}
}
if (version >= 10 && GetSaveFlag(flags, SaveFlag.DecayReset))
{
var reset = version >= 11 ? reader.ReadAnchoredTime() : reader.ReadDeltaTime();
// Pre-v11 LastMoved was stored at whole-minute precision; keep the
// stamp only while it still extends the deadline.
if (reset > LastMoved)
{
DecayResetTime = reset;
}
}
if (GetSaveFlag(flags, SaveFlag.Direction))
{
m_Direction = (Direction)reader.ReadByte();
@ -2854,6 +2981,8 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
AcquireCompactInfo().m_SavedFlags = reader.ReadEncodedInt();
}
PlayerConstructed = GetSaveFlag(flags, SaveFlag.PlayerConstructed);
if (m_Map != null && m_Parent == null)
{
m_Map.OnEnter(this);
@ -3325,6 +3454,12 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
m_DeltaFlags &= ~flags;
}
/// <summary>
/// True when deltas remain queued after a <see cref="ProcessDeltaQueue"/> pass, which is
/// bounded by the count it saw on entry. The event loop consults this before sleeping.
/// </summary>
public static bool HasQueuedDeltas => m_DeltaQueue.Count > 0;
public static void ProcessDeltaQueue()
{
var limit = m_DeltaQueue.Count;
@ -3431,7 +3566,7 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
for (var i = 0; i < props.Length; i++)
{
var p = props[i];
if (p.GetCustomAttribute(typeof(IgnoreDupeAttribute), true) != null || !p.CanRead || !p.CanWrite)
if (p.GetCustomAttribute<IgnoreDupeAttribute>(true) != null || !p.CanRead || !p.CanWrite)
{
continue;
}
@ -4337,6 +4472,8 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
public ISpawner m_Spawner;
public DateTime m_DecayReset;
public int m_TempFlags;
public double m_Weight = -1;
@ -4374,6 +4511,8 @@ public partial class Item : IHued, IComparable<Item>, ISpawnable, IObjectPropert
HeldBy = 0x00800000,
IntWeight = 0x01000000,
SavedFlags = 0x02000000,
NullWeight = 0x04000000
NullWeight = 0x04000000,
PlayerConstructed = 0x08000000,
DecayReset = 0x10000000
}
}

View file

@ -39,10 +39,181 @@ public static class Core
{
private static readonly ILogger logger = LogFactory.GetLogger(typeof(Core));
private static bool _performProcessKill;
// Written off-loop (Kill, RequestSnapshot); volatile because the loop blocks between reads.
private static volatile bool _performProcessKill;
private static bool _restartOnKill;
private static bool _performSnapshot;
private static volatile bool _performSnapshot;
private static string _snapshotPath;
// A backstop, not a latency control: the wheel's tick rate already bounds the sleep.
// Measured across 1/2/4/8ms; 2 is optimal.
private static int _eventLoopIdleWaitMs = 2;
/// <summary>
/// Longest the loop will block while idle, in milliseconds. 0 spins instead; the backoff
/// does the same temporarily when the host keeps returning waits late.
/// </summary>
public static int EventLoopIdleWaitMs => _eventLoopIdleWaitMs;
/// <summary>
/// True when idle sleeping was disabled at startup because the host cannot honor short
/// waits, overriding whatever <c>server.eventLoopIdleWaitMs</c> was configured to.
/// </summary>
public static bool IdleSleepUnsupported { get; private set; }
/// <summary>
/// Whether idle sleeping is currently suspended because the host returned waits late.
/// </summary>
/// <remarks>
/// Compared by subtraction, never directly: tick counts can start enormous and wrap.
/// See dev-docs/tick-counts.md.
/// </remarks>
public static bool IdleSleepSuspended => _tickCount - _idleSleepSuspendedUntil < 0;
private const long HealthSampleIntervalMs = 1000;
// Doubling: a fixed suspension oscillates forever on a persistently bad host, while doubling
// converges on "stop sleeping" yet still recovers from a transient.
private const long BackoffBaseMs = 5000;
private const long BackoffMaxMs = 120_000;
private const int BackoffMaxShift = 5;
// Clean streak that clears the escalation.
private const long BackoffResetAfterCleanMs = 60_000;
// Below this a backoff is still recoverable and not actionable, so it only logs at Debug.
private const int WarnAfterConsecutiveBackoffs = 3;
// A sleep is bounded by the next wheel turn, so only a wait returning late can cost a deadline.
// Measured per sleep, which is why server work (saves, heavy commands) cannot trip the backoff.
private static int _lateWakes;
// Denominator for the late-wake rate.
private static int _sleepAttempts;
private static long _nextHealthSample;
private static long _idleSleepSuspendedUntil;
private static int _lateWakeThreshold = 1;
private static int _lateWakePercent = 10;
private static long _idleSleepBackoffs;
private static int _consecutiveBadSamples;
private static int _consecutiveBackoffs;
private static long _currentBackoffMs = BackoffBaseMs;
private static long _lastBackoffAt;
private static bool _loggedBackoffCeiling;
/// <summary>
/// Once a second, suspends idle sleeping (with escalating duration) if the host keeps
/// returning idle waits a full tick or more late.
/// </summary>
private static void CheckSchedulerHealth()
{
if (_tickCount - _nextHealthSample < 0)
{
return;
}
_nextHealthSample = _tickCount + HealthSampleIntervalMs;
var late = _lateWakes;
var sleeps = _sleepAttempts;
_lateWakes = 0;
_sleepAttempts = 0;
// A clean streak resets the escalation and re-arms the ceiling Error. Gated on the count
// rather than a "_lastBackoffAt > 0" sentinel because tick counts are not guaranteed positive.
if (_consecutiveBackoffs > 0 && _tickCount - _lastBackoffAt > BackoffResetAfterCleanMs)
{
if (_consecutiveBackoffs >= WarnAfterConsecutiveBackoffs)
{
logger.Information(
"This host has returned idle waits on time for {Duration}ms; idle sleeping is back to normal",
BackoffResetAfterCleanMs
);
}
_consecutiveBackoffs = 0;
_loggedBackoffCeiling = false;
}
if (late <= _lateWakeThreshold)
{
_consecutiveBadSamples = 0;
return;
}
// Lateness is a rate: an idle loop sleeps hundreds of times a second, so a few outliers are
// normal, while a host that cannot schedule the process returns most of its waits late. The
// threshold above is the floor for windows with too few sleeps for a proportion to mean anything.
if (late * 100 < sleeps * _lateWakePercent)
{
_consecutiveBadSamples = 0;
return;
}
// Require persistence: any host can drop one sample to unrelated load, but an oversubscribed
// one stays bad.
if (++_consecutiveBadSamples < 2)
{
return;
}
if (_eventLoopIdleWaitMs <= 0)
{
return;
}
_currentBackoffMs = Math.Min(BackoffBaseMs << Math.Min(_consecutiveBackoffs, BackoffMaxShift), BackoffMaxMs);
_consecutiveBackoffs++;
_lastBackoffAt = _tickCount;
_idleSleepSuspendedUntil = _tickCount + _currentBackoffMs;
_idleSleepBackoffs++;
if (_currentBackoffMs >= BackoffMaxMs)
{
// Escalation has run out of room; say so once.
if (!_loggedBackoffCeiling)
{
_loggedBackoffCeiling = true;
logger.Error(
"This host keeps returning idle waits late and sleeping has backed off {Count} times. " +
"The process is not being scheduled promptly, which is typical of shared or burstable vCPUs. " +
"Set server.eventLoopIdleWaitMs to 0 to disable sleeping permanently and trade a full core for latency.",
_idleSleepBackoffs
);
}
return;
}
// Each backoff doubles the suspension, so every line is a distinct escalation step and
// needs no further rate limiting.
if (_consecutiveBackoffs < WarnAfterConsecutiveBackoffs)
{
logger.Debug(
"This host returned a {Requested}ms idle wait at least {TickRate}ms late {Count} of {Sleeps} time(s) " +
"in the last second; idle sleeping suspended for {Duration}ms",
_eventLoopIdleWaitMs,
Timer.TickRate,
late,
sleeps,
_currentBackoffMs
);
return;
}
logger.Warning(
"This host returned a {Requested}ms idle wait at least {TickRate}ms late {Count} of {Sleeps} time(s) in " +
"the last second, for the {Backoffs}th time running; idle sleeping suspended for {Duration}ms",
_eventLoopIdleWaitMs,
Timer.TickRate,
late,
sleeps,
_consecutiveBackoffs,
_currentBackoffMs
);
}
private static bool _crashed;
private static string _baseDirectory;
@ -111,14 +282,6 @@ public static class Core
public static long Uptime => TickCount - _firstTick;
private static double _currentCPS;
private static double _averageCPS;
private static bool _cpsInitialized;
public static double CyclesPerSecond => _currentCPS;
public static double AverageCPS => _averageCPS;
public static string BaseDirectory
{
get
@ -235,6 +398,10 @@ public static class Core
{
_restartOnKill = restart;
_performProcessKill = true;
// Callers are usually off-loop (console input, signal handlers); wake so the request
// is noticed now rather than whenever the loop next surfaces.
NetState.Wake();
}
public static void CurrentDomain_UnhandledException(object sender, UnhandledExceptionEventArgs e)
@ -424,6 +591,45 @@ public static class Core
ServerConfiguration.Load();
// 0 disables idle sleeping entirely (full-core spin, zero scheduling overhead).
var idleWaitMs = ServerConfiguration.GetSetting("server.eventLoopIdleWaitMs", 2);
if (idleWaitMs < 0)
{
logger.Warning(
"server.eventLoopIdleWaitMs {Value} is negative; using 0 (idle sleeping disabled)",
idleWaitMs
);
}
_eventLoopIdleWaitMs = Math.Max(0, idleWaitMs);
// Floor for the backoff: idle waits per second the host may return a full tick late before
// the rate test below applies at all. Set very high to disable the backoff.
var lateWakeThreshold = ServerConfiguration.GetSetting("server.lateWakeThreshold", 1);
if (lateWakeThreshold < 0)
{
logger.Warning(
"server.lateWakeThreshold {Value} is negative; using 0",
lateWakeThreshold
);
}
_lateWakeThreshold = Math.Max(0, lateWakeThreshold);
// Share of a second's idle waits that must return late before the backoff trips. 0 leaves
// the threshold above in sole charge.
var lateWakePercent = ServerConfiguration.GetSetting("server.lateWakePercent", 10);
if (lateWakePercent is < 0 or > 100)
{
logger.Warning(
"server.lateWakePercent {Value} is outside 0-100; using {Clamped}",
lateWakePercent,
Math.Clamp(lateWakePercent, 0, 100)
);
}
_lateWakePercent = Math.Clamp(lateWakePercent, 0, 100);
var assemblyPath = Path.Join(BaseDirectory, AssembliesConfiguration);
// Load UOContent.dll
@ -440,10 +646,8 @@ public static class Core
AssemblyHandler.LoadAssemblies(assemblyFiles);
// First-boot interactive setup. Runs after assemblies are loaded (so content can
// register prompts) but before any Serilog output, so console prompts are not
// interleaved with the async console sink. Handlers self-gate on first-boot state
// (e.g. "is my setting already present?").
// First-boot interactive setup. After assemblies load so content can register prompts,
// before any Serilog output so prompts are not interleaved with the async console sink.
AssemblyHandler.Invoke("ConfigurePrompts");
logger.Information("Running on {Framework}", RuntimeInformation.FrameworkDescription);
@ -453,6 +657,11 @@ public static class Core
_now = DateTime.UtcNow;
_firstTick = _tickCount = GetTimestamp();
// Seed from a real tick: tick counts need not start near zero, so a zero-initialized
// deadline compares wrong. See dev-docs/tick-counts.md.
_nextHealthSample = _tickCount + HealthSampleIntervalMs;
_idleSleepSuspendedUntil = _tickCount;
Timer.Init(_tickCount);
AssemblyHandler.Invoke("Configure");
@ -469,41 +678,71 @@ public static class Core
NetState.Start();
PingServer.Start();
EventSink.InvokeServerStarted();
// Without a high-resolution wait a 2ms request quantises to 15.625ms and the loop runs a
// tick behind. Only fires when the high-res timer and the timeBeginPeriod fallback both failed.
if (_eventLoopIdleWaitMs > 0 && NetState.Ring?.SupportsHighResolutionWait == false)
{
logger.Error(
"This host cannot honor short waits (no high-resolution timer, and raising the system timer " +
"resolution failed). Idle sleeping is disabled. The loop will spin instead, using a full core."
);
IdleSleepUnsupported = true;
_eventLoopIdleWaitMs = 0;
}
RunEventLoop();
}
/// <summary>
/// True when every queue the loop drains is empty, so sleeping cannot strand pending work.
/// The drains are bounded, so leftovers are normal and must keep the loop awake.
/// </summary>
private static bool IsIdle() =>
!Mobile.HasQueuedDeltas && !Item.HasQueuedDeltas && LoopContext.IsEmpty && NetState.IsIdle;
public static void RunEventLoop()
{
try
{
var lastRaw = Stopwatch.GetTimestamp();
const int interval = 100;
double frequency = Stopwatch.Frequency * interval;
const double alpha = 2.0 / 129; // EMA smoothing (≈128-sample window)
var sample = 0;
while (!Closing)
{
_tickCount = GetTimestamp();
_now = DateTime.UtcNow;
EventLoopProfiler.IterationStart(_tickCount);
EventLoopProfiler.PhaseStart(LoopPhase.MobileDeltas);
Mobile.ProcessDeltaQueue();
EventLoopProfiler.PhaseEnd(LoopPhase.MobileDeltas);
EventLoopProfiler.PhaseStart(LoopPhase.ItemDeltas);
Item.ProcessDeltaQueue();
EventLoopProfiler.PhaseEnd(LoopPhase.ItemDeltas);
EventLoopProfiler.PhaseStart(LoopPhase.TimerSlice);
Timer.Slice(_tickCount);
EventLoopProfiler.PhaseEnd(LoopPhase.TimerSlice);
// Handle networking
EventLoopProfiler.PhaseStart(LoopPhase.NetworkSlice);
NetState.Slice();
EventLoopProfiler.PhaseEnd(LoopPhase.NetworkSlice);
// Execute captured post-await methods (like Timer.Pause)
EventLoopProfiler.PhaseStart(LoopPhase.LoopTasks);
LoopContext.ExecuteTasks();
EventLoopProfiler.PhaseEnd(LoopPhase.LoopTasks);
Timer.CheckTimerPool(); // Check for pool depletion so we can async refill it.
if (_performSnapshot)
{
EventLoopProfiler.PhaseStart(LoopPhase.WorldSnapshot);
// Return value is the offset that can be used to fix timers that should drift
World.Snapshot(_snapshotPath);
EventLoopProfiler.PhaseEnd(LoopPhase.WorldSnapshot);
_performSnapshot = false;
}
@ -513,29 +752,35 @@ public static class Core
break;
}
if (sample++ == interval)
CheckSchedulerHealth();
if (_eventLoopIdleWaitMs > 0 && _tickCount - _idleSleepSuspendedUntil >= 0 && IsIdle())
{
sample = 0;
var nowRaw = Stopwatch.GetTimestamp();
_currentCPS = frequency / (nowRaw - lastRaw);
if (!_cpsInitialized)
// Re-read the clock: a stale timestamp overstates the time to the next tick
// and sleeps straight past it.
var start = GetTimestamp();
var due = Timer.MillisecondsUntilNextTick(start);
if (due > 0)
{
_averageCPS = _currentCPS;
_cpsInitialized = true;
}
else
{
_averageCPS += alpha * (_currentCPS - _averageCPS);
}
var requested = (int)Math.Min(due, _eventLoopIdleWaitMs);
lastRaw = nowRaw;
// The GC prefers to collect during idle sleeps, so its pauses land here by
// design and are not the host's fault. Gen1 and above (what
// CollectionCount(1) counts) are the only pauses long enough to reach a tick.
var collections = GC.CollectionCount(1);
var sleepMs = (int)Timer.MillisecondsUntilNextTick(_tickCount);
if (sleepMs >= 2)
{
NetState.WaitForCompletion(sleepMs - 1);
NetState.WaitForCompletion(requested);
var elapsed = GetTimestamp() - start;
EventLoopProfiler.SleepEnd(requested, elapsed);
_sleepAttempts++;
// The second collection read sits behind the overshoot test, so the common
// path reads the counter once, not twice.
if (elapsed - requested >= Timer.TickRate && GC.CollectionCount(1) == collections)
{
_lateWakes++;
}
}
}
}
@ -553,6 +798,9 @@ public static class Core
{
_snapshotPath = snapshotPath;
_performSnapshot = true;
// Save requests arrive off-loop; wake so the snapshot starts now.
NetState.Wake();
}
public static void VerifySerialization()

View file

@ -2324,11 +2324,11 @@ public partial class Mobile : IHued, IComparable<Mobile>, ISpawnable, IObjectPro
public virtual void Serialize(IGenericWriter writer)
{
writer.Write(37); // version
writer.Write(38); // version
writer.WriteDeltaTime(LastStrGain);
writer.WriteDeltaTime(LastIntGain);
writer.WriteDeltaTime(LastDexGain);
writer.WriteAnchoredTime(LastStrGain);
writer.WriteAnchoredTime(LastIntGain);
writer.WriteAnchoredTime(LastDexGain);
byte hairflag = 0x00;
@ -5248,8 +5248,15 @@ public partial class Mobile : IHued, IComparable<Mobile>, ISpawnable, IObjectPro
item.Name = oldItem.Name;
item.Weight = oldItem.Weight;
item.PlayerConstructed = oldItem.PlayerConstructed;
item.Amount = oldAmount - amount;
item.Map = oldItem.Map;
// A parented remainder gets its map from AddItem (parent first, then map), keeping the
// split off the decay scheduler; a ground remainder is placed and enrolled here.
if (oldItem.Parent == null)
{
item.Map = oldItem.Map;
}
oldItem.OnAfterDuped(item);
@ -6143,6 +6150,7 @@ public partial class Mobile : IHued, IComparable<Mobile>, ISpawnable, IObjectPro
switch (version)
{
case 38: // Stat-gain stamps moved from delta time to anchored time
case 37: // Decomposed hair into inline item id/hue (dropped the VirtualHairInfo object)
case 36: // Moved virtues to VirtueSystem
case 35: // Moved short term murders to PlayerMurderSystem
@ -6151,9 +6159,18 @@ public partial class Mobile : IHued, IComparable<Mobile>, ISpawnable, IObjectPro
case 32: // Removed StuckMenu
case 31:
{
LastStrGain = reader.ReadDeltaTime();
LastIntGain = reader.ReadDeltaTime();
LastDexGain = reader.ReadDeltaTime();
if (version >= 38)
{
LastStrGain = reader.ReadAnchoredTime();
LastIntGain = reader.ReadAnchoredTime();
LastDexGain = reader.ReadAnchoredTime();
}
else
{
LastStrGain = reader.ReadDeltaTime();
LastIntGain = reader.ReadDeltaTime();
LastDexGain = reader.ReadDeltaTime();
}
goto case 30;
}
@ -7834,6 +7851,12 @@ public partial class Mobile : IHued, IComparable<Mobile>, ISpawnable, IObjectPro
}
}
/// <summary>
/// True when deltas remain queued after a <see cref="ProcessDeltaQueue"/> pass, which is
/// bounded by the count it saw on entry. The event loop consults this before sleeping.
/// </summary>
public static bool HasQueuedDeltas => m_DeltaQueue.Count > 0;
public static void ProcessDeltaQueue()
{
var limit = m_DeltaQueue.Count;

View file

@ -21,17 +21,15 @@ namespace Server;
[SerializationGenerator(0)]
public partial class ResistanceMod : MobileMod
{
[SerializableField(0)]
[SerializableField(0, fieldChanged: nameof(OnTypeChanged))]
private ResistanceType _type;
[SerializableFieldChanged(0)]
[MethodImpl(MethodImplOptions.AggressiveInlining)]
private void OnTypeChanged(ResistanceType oldValue, ResistanceType newValue) => Owner?.UpdateResistances();
[SerializableField(1)]
[SerializableField(1, fieldChanged: nameof(OnOffsetChanged))]
private int _offset;
[SerializableFieldChanged(1)]
[MethodImpl(MethodImplOptions.AggressiveInlining)]
private void OnOffsetChanged(int oldValue, int newValue) => Owner?.UpdateResistances();

View file

@ -21,33 +21,29 @@ namespace Server;
[SerializationGenerator(0)]
public abstract partial class SkillMod : MobileMod
{
[SerializableField(0)]
[SerializableField(0, fieldChanged: nameof(OnObeyCapChanged))]
private bool _obeyCap;
[SerializableFieldChanged(0)]
[MethodImpl(MethodImplOptions.AggressiveInlining)]
private void OnObeCapChanged(bool oldValue, bool newValue) => Owner?.Skills[_skill]?.Update();
private void OnObeyCapChanged(bool oldValue, bool newValue) => Owner?.Skills[_skill]?.Update();
[SerializableField(1)]
[SerializableField(1, fieldChanged: nameof(OnSkillChanged))]
private SkillName _skill;
[SerializableFieldChanged(1)]
private void OnSkillChanged(SkillName oldValue, SkillName newValue)
{
Owner?.Skills[newValue]?.Update();
Owner?.Skills[oldValue]?.Update();
}
[SerializableField(2)]
[SerializableField(2, fieldChanged: nameof(OnRelativeChanged))]
private bool _relative;
[SerializableFieldChanged(2)]
private void OnRelativeChanged(bool oldValue, bool newValue) => Owner?.Skills[_skill]?.Update();
[SerializableField(3)]
[SerializableField(3, fieldChanged: nameof(OnValueChanged))]
private double _value;
[SerializableFieldChanged(3)]
private void OnValueChanged(double oldValue, double newValue) => Owner?.Skills[_skill]?.Update();
public SkillMod(Mobile owner) : base(owner)

View file

@ -71,6 +71,24 @@ public partial class NetState
_socketManager?.WaitForCompletion(timeoutMs);
}
/// <summary>
/// Wakes the game loop if it is blocked in <see cref="WaitForCompletion"/>. Safe from any
/// thread; a no-op before networking is configured or after teardown. The signal is sticky,
/// so a wake racing the loop's decision to sleep is not lost.
/// </summary>
public static void Wake()
{
_socketManager?.Ring?.Wake();
}
/// <summary>
/// True when no queued network work remains for the loop to drain. <see cref="Slice"/> defers
/// work in several places, so an empty completion queue alone is not enough.
/// </summary>
internal static bool IsIdle =>
_throttled.Count == 0 && _throttledPending.Count == 0 &&
_flushPending.Count == 0 && _pendingDisconnects.Count == 0 && _disposed.Count == 0;
/// <summary>
/// Gets the listening addresses that the server is bound to.
/// </summary>

View file

@ -74,6 +74,12 @@ public sealed unsafe class BinaryFileReader : IDisposable, IGenericReader
/// </summary>
public long Position => _reader.Position;
public TimeSpan AnchoredTimeShift
{
get => _reader.AnchoredTimeShift;
set => _reader.AnchoredTimeShift = value;
}
public void Dispose()
{
_accessor?.SafeMemoryMappedViewHandle.ReleasePointer();

View file

@ -37,6 +37,8 @@ public class BufferReader : IGenericReader
public long Position => _position;
public long BufferSize => _buffer.Length;
public TimeSpan AnchoredTimeShift { get; set; }
public BufferReader(byte[] buffer, Dictionary<ulong, string> typesDb = null, Encoding encoding = null)
{
_buffer = buffer;

View file

@ -384,6 +384,7 @@ public class BufferWriter : IGenericWriter
}
[MethodImpl(MethodImplOptions.AggressiveInlining)]
[Obsolete("Delta time rewrites its bytes on every save. Write anchored time instead (WriteAnchoredTime, or [AnchoredDateTime] on generated fields); bump the containing type's version, as the wire format changes. Existing delta payloads remain readable through ReadDeltaTime in old-version fallbacks.")]
public void WriteDeltaTime(DateTime value)
{
if (value == DateTime.MinValue)
@ -407,6 +408,21 @@ public class BufferWriter : IGenericWriter
Write(value.Ticks - DateTime.UtcNow.Ticks);
}
/// <summary>
/// Writes the absolute value; <see cref="IGenericReader.ReadAnchoredTime" /> re-bases it
/// by the elapsed time since the save started, so downtime does not age it and an
/// unchanged value serializes to identical bytes.
/// </summary>
public void WriteAnchoredTime(DateTime value)
{
if (value.Kind == DateTimeKind.Local)
{
value = value.ToUniversalTime();
}
Write(value.Ticks);
}
[MethodImpl(MethodImplOptions.AggressiveInlining)]
public void Write(IPAddress value)
{

View file

@ -114,9 +114,10 @@ public class GenericEntityPersistence<T> : GenericPersistence, IGenericEntityPer
using var binFs = new FileStream(
Path.Combine(dir, $"{Name}.bin"), FileMode.Create, FileAccess.Write, FileShare.None, 1024 * 1024
);
// v4 records are fixed-width 26 bytes; the header carries the type table
// (name lengths vary — 64 bytes per entry is a staging hint, not a contract).
var expectedIdxSize = 12 + 26L * EntitiesBySerial.Count + 64L * _typeTable.Count;
// v4 records are fixed-width 26 bytes; the v5 header carries the save-start anchor
// and the type table (name lengths vary — 64 bytes per entry is a staging hint, not
// a contract).
var expectedIdxSize = 20 + 26L * EntitiesBySerial.Count + 64L * _typeTable.Count;
using var idx = new FileBufferWriter(Path.Combine(dir, $"{Name}.idx"), expectedIdxSize);
var binPosition = 0L;
@ -142,7 +143,10 @@ public class GenericEntityPersistence<T> : GenericPersistence, IGenericEntityPer
binPosition += _selfLength;
}
idx.Write(4); // Version
idx.Write(5); // Version
// One anchor for the whole save: the world is frozen from the moment it is stamped.
idx.Write(World.SaveStartTime.Ticks);
// The type table is fully known at freeze (AddEntity diverts to the pending
// queues while saving) and is written before the records so the loader can
@ -494,6 +498,18 @@ public class GenericEntityPersistence<T> : GenericPersistence, IGenericEntityPer
var version = dataReader.ReadInt();
if (version >= 5)
{
// Re-base anchored timestamps by the elapsed time since the save started.
var anchor = new DateTime(dataReader.ReadLong(), DateTimeKind.Utc);
var shift = Core.Now - anchor;
_anchoredTimeShift = anchor.Ticks > 0 && shift > TimeSpan.Zero ? shift : TimeSpan.Zero;
// The whole save shares one anchor. Publish it so payloads without their own
// (GenericPersistence bins) can shift too; indexes load before any of them.
World.LoadTimeShift = _anchoredTimeShift;
}
if (version >= 4)
{
DeserializeIndexesV4(dataReader, entities);
@ -660,6 +676,9 @@ public class GenericEntityPersistence<T> : GenericPersistence, IGenericEntityPer
private static List<T> _toDelete;
// From the loaded idx (v5+); zero when the save predates the anchor.
private TimeSpan _anchoredTimeShift;
private unsafe void InternalDeserialize(string filePath, int index, Dictionary<ulong, string> typesDb)
{
using var mmf = MemoryMappedFile.CreateFromFile(filePath, FileMode.Open);
@ -667,7 +686,10 @@ public class GenericEntityPersistence<T> : GenericPersistence, IGenericEntityPer
byte* ptr = null;
accessor.SafeMemoryMappedViewHandle.AcquirePointer(ref ptr);
var dataReader = new UnmanagedDataReader(ptr, accessor.Length, typesDb);
var dataReader = new UnmanagedDataReader(ptr, accessor.Length, typesDb)
{
AnchoredTimeShift = _anchoredTimeShift
};
Deserialize(dataReader);

View file

@ -98,7 +98,13 @@ public abstract class GenericPersistence : Persistence, IGenericSerializable
byte* ptr = null;
accessor.SafeMemoryMappedViewHandle.AcquirePointer(ref ptr);
var dataReader = new UnmanagedDataReader(ptr, accessor.Length, typesDb);
var dataReader = new UnmanagedDataReader(ptr, accessor.Length, typesDb)
{
// These payloads carry no anchor of their own; they inherit the save-wide
// shift stamped while the entity indexes were read (indexes always load
// before persistence payloads — see Persistence.Load).
AnchoredTimeShift = World.LoadTimeShift
};
Deserialize(dataReader);
error = dataReader.Position != fileLength

View file

@ -43,6 +43,12 @@ public interface IGenericReader
DateTime ReadDateTime() => new(ReadLong(), DateTimeKind.Utc);
TimeSpan ReadTimeSpan() => new(ReadLong());
/// <summary>
/// Decodes a legacy delta-time value. Only for reading old-version payloads (version
/// fallbacks and migration replays) — current formats store anchored time and read it
/// with <see cref="ReadAnchoredTime" />. <see cref="IGenericWriter.WriteDeltaTime" /> is
/// obsolete: no current-version format may write delta time.
/// </summary>
DateTime ReadDeltaTime()
{
return ReadLong() switch
@ -52,6 +58,37 @@ public interface IGenericReader
var delta => new DateTime(delta + DateTime.UtcNow.Ticks, DateTimeKind.Utc)
};
}
/// <summary>
/// Elapsed time between the loaded save starting and this load, applied by
/// <see cref="ReadAnchoredTime" />. Zero when the source carries no anchor.
/// </summary>
TimeSpan AnchoredTimeShift => TimeSpan.Zero;
DateTime ReadAnchoredTime()
{
var value = ReadDateTime();
if (value == DateTime.MinValue || value == DateTime.MaxValue)
{
return value;
}
var shift = AnchoredTimeShift;
if (shift == TimeSpan.Zero)
{
return value;
}
var ticks = value.Ticks + shift.Ticks;
if (ticks >= DateTime.MaxValue.Ticks)
{
return DateTime.MaxValue;
}
return ticks <= 0 ? DateTime.MinValue : new DateTime(ticks, DateTimeKind.Utc);
}
decimal ReadDecimal() => new([ReadInt(), ReadInt(), ReadInt(), ReadInt()]);
int ReadEncodedInt()
{

View file

@ -40,7 +40,11 @@ public interface IGenericWriter
void Write(decimal value);
void WriteEncodedInt(int value);
void Write(DateTime value);
[Obsolete("Delta time rewrites its bytes on every save. Write anchored time instead (WriteAnchoredTime, or [AnchoredDateTime] on generated fields); bump the containing type's version, as the wire format changes. Existing delta payloads remain readable through ReadDeltaTime in old-version fallbacks.")]
void WriteDeltaTime(DateTime value);
void WriteAnchoredTime(DateTime value);
void Write(IPAddress value);
void Write(TimeSpan value);
void Write(Point3D value);

View file

@ -43,6 +43,8 @@ public unsafe class UnmanagedDataReader : IGenericReader
/// </summary>
public long Position { get; private set; }
public TimeSpan AnchoredTimeShift { get; set; }
/// <summary>
/// Read bits of data raw from a serialized file using Little-endian.
/// </summary>

View file

@ -34,14 +34,13 @@
</Target>
<ItemGroup>
<ProjectReference Include="..\Logger\Logger.csproj" />
<PackageReference Include="IORingGroup" Version="1.0.9" />
<PackageReference Include="IORingGroup" Version="1.0.10" />
<PackageReference Include="CommunityToolkit.HighPerformance" Version="8.4.2" />
<PackageReference Include="LibDeflate.Bindings" Version="1.0.3" />
<PackageReference Include="System.IO.Hashing" Version="10.0.10" />
<PackageReference Include="LibDeflate.Bindings" Version="1.0.4" />
<PackageReference Include="System.IO.Hashing" Version="10.0.11" />
<PackageReference Include="ModernUO.Serialization.Annotations" Version="2.14.2" />
<PackageReference Include="ModernUO.Serialization.Generator" Version="2.14.3" />
<PackageReference Update="Serilog" Version="4.4.0" />
<PackageReference Include="ModernUO.Serialization.Annotations" Version="4.0.0" />
<PackageReference Include="ModernUO.Serialization.Generator" Version="4.0.0" PrivateAssets="all" />
</ItemGroup>
<ItemGroup>
<AdditionalFiles Include="Migrations/*.v*.json" />

View file

@ -51,8 +51,15 @@ public partial class Timer
}
}
/// <summary>
/// Milliseconds of simulated time one wheel turn advances.
/// </summary>
public static int TickRate => _tickRate;
public static void Slice(long tickCount)
{
EventLoopProfiler.WheelSlice(tickCount - _lastTickTurned);
var deltaSinceTurn = tickCount - _lastTickTurned;
while (deltaSinceTurn >= _tickRate)
{

View file

@ -1050,28 +1050,16 @@ public static partial class Utility
return;
}
using var queue = PooledRefQueue<K>.Create();
foreach (var (key, value) in dictionary)
{
if (serializableKey)
{
if (key == null || ((ISerializable)key).Deleted)
{
queue.Enqueue(key);
}
}
else
{
if (value == null || ((ISerializable)value).Deleted)
{
queue.Enqueue(key);
}
}
}
var deleted = serializableKey
? ((ISerializable)key).Deleted
: value == null || ((ISerializable)value).Deleted;
while (queue.Count > 0)
{
dictionary.Remove(queue.Dequeue());
if (deleted)
{
dictionary.Remove(key);
}
}
dictionary.TrimExcess();

View file

@ -93,6 +93,21 @@ public static class World
public static string SavePath { get; private set; }
public static WorldState WorldState { get; private set; }
public static bool Saving => WorldState == WorldState.Saving;
/// <summary>
/// UTC time the current or most recent world save started. Written into save indexes so
/// anchored timestamps can be re-based by the downtime at load.
/// </summary>
public static DateTime SaveStartTime { get; internal set; }
/// <summary>
/// The anchored-time shift for the save currently being loaded: the downtime between the
/// save's start and this load. Stamped while entity indexes are read (they all carry the
/// same anchor, since the whole save shares one <see cref="SaveStartTime" />) and applied
/// to every reader of that save's files — including <see cref="GenericPersistence" />
/// payloads, which carry no anchor of their own. Zero for saves that predate the anchor.
/// </summary>
public static TimeSpan LoadTimeShift { get; internal set; }
public static bool Running => WorldState is not WorldState.Loading and not WorldState.Initial;
public static bool Loading => WorldState == WorldState.Loading;
@ -287,6 +302,10 @@ public static class World
WorldState = WorldState.Saving;
// The world is frozen from here: one anchor for the whole save. Written into save
// indexes so anchored timestamps can be re-based by the downtime at load.
SaveStartTime = Core.Now;
Broadcast(0x35, true, "The world is saving, please wait.");
logger.Information("Saving world");

View file

@ -100,6 +100,8 @@ internal static class TestServerInitializer
}
World.Configure();
// Registers the Accounts entity persistence; without it no test can construct an Account.
Server.Accounting.Accounts.Configure();
RaceDefinitions.Configure();
MovementImpl.Configure();
PathFollower.Configure();

View file

@ -0,0 +1,74 @@
using System;
using Server.Accounting;
using Server.Accounting.Security;
using Xunit;
namespace Server.Tests.Accounting;
[Collection("Sequential UOContent Tests")]
public class AccountPasswordTests : IDisposable
{
private const string Password = "hunter2";
// CurrentAlgorithm is process-wide state shared with the rest of the collection.
private readonly PasswordProtectionAlgorithm _originalAlgorithm = AccountSecurity.CurrentAlgorithm;
public void Dispose() => AccountSecurity.CurrentAlgorithm = _originalAlgorithm;
[Theory]
[InlineData(PasswordProtectionAlgorithm.SHA1)]
[InlineData(PasswordProtectionAlgorithm.SHA2)]
[InlineData(PasswordProtectionAlgorithm.PBKDF2)]
[InlineData(PasswordProtectionAlgorithm.Argon2)]
public void NewAccount_CanLogIn(PasswordProtectionAlgorithm algorithm)
{
AccountSecurity.CurrentAlgorithm = algorithm;
var account = new Account($"new-{algorithm}-user", Password);
Assert.Equal(algorithm, account.PasswordAlgorithm);
Assert.True(account.CheckPassword(Password));
Assert.False(account.CheckPassword("wrong-password"));
}
// SetPassword assigns PasswordAlgorithm before deriving the phrase from it. Reversed, the hash
// is salted by the outgoing algorithm's rule but stored under the incoming one, which verifies
// once and then never again.
[Theory]
[InlineData(PasswordProtectionAlgorithm.SHA1)]
[InlineData(PasswordProtectionAlgorithm.SHA2)]
[InlineData(PasswordProtectionAlgorithm.PBKDF2)]
public void UpgradingAlgorithm_DoesNotLockTheAccountOut(PasswordProtectionAlgorithm from)
{
AccountSecurity.CurrentAlgorithm = from;
var account = new Account($"upgrade-{from}-user", Password);
Assert.True(account.CheckPassword(Password));
AccountSecurity.CurrentAlgorithm = PasswordProtectionAlgorithm.Argon2;
Assert.True(account.CheckPassword(Password));
Assert.Equal(PasswordProtectionAlgorithm.Argon2, account.PasswordAlgorithm);
// Must verify against what the rehash wrote.
Assert.True(account.CheckPassword(Password));
Assert.False(account.CheckPassword("wrong-password"));
}
[Fact]
public void StaleArgon2Parameters_AreRehashedOnLogin()
{
AccountSecurity.CurrentAlgorithm = PasswordProtectionAlgorithm.Argon2;
var account = new Account("stale-params-user", Password);
// The shipping default before this change: Argon2i, m=8192, t=3, p=1.
account.Password =
"$argon2i$v=19$m=8192,t=3,p=1$LD1XJz7P3wQmIJ+Tu6ScgA$NO5hBABsHQ172C5nDO2X4gWnB4jDef3x6WhLdVE2LFw";
Assert.True(account.CheckPassword(Password));
Assert.StartsWith("$argon2id$v=19$m=16384,t=1,p=1$", account.Password);
// Already current: verifying again must not rewrite the hash.
var afterFirst = account.Password;
Assert.True(account.CheckPassword(Password));
Assert.Equal(afterFirst, account.Password);
}
}

View file

@ -0,0 +1,229 @@
using System;
using System.Threading;
using Server.Accounting;
using Server.Accounting.Security;
using Xunit;
namespace Server.Tests.Accounting;
[Collection("Sequential UOContent Tests")]
public class PasswordWorkerTests : IDisposable
{
private const string Password = "hunter2";
private readonly PasswordProtectionAlgorithm _originalAlgorithm = AccountSecurity.CurrentAlgorithm;
public PasswordWorkerTests() => AccountSecurity.CurrentAlgorithm = PasswordProtectionAlgorithm.Argon2;
public void Dispose() => AccountSecurity.CurrentAlgorithm = _originalAlgorithm;
private static Account CreateAccount(string username) =>
Accounts.GetAccount(username) as Account ?? new Account(username, Password);
/// <summary>
/// Enqueues work, then pumps the loop context until <paramref name="complete"/> or the deadline.
///
/// The context pins itself to the thread that constructed it and refuses <c>ExecuteTasks</c>
/// from any other. The fixture's belongs to whichever thread built the fixture, and xUnit gives
/// no guarantee that a test method runs on that thread even inside a sequential collection --
/// so this owns one for the duration and puts the original back. Pumping the fixture's context
/// passed locally and failed on CI.
/// </summary>
private static void PumpUntil(Action enqueue, Func<bool> complete, int timeoutSeconds = 20)
{
var original = Core.LoopContext;
var owned = new EventLoopContext();
Core.LoopContext = owned;
try
{
enqueue();
var deadline = DateTime.UtcNow.AddSeconds(timeoutSeconds);
while (!complete() && DateTime.UtcNow < deadline)
{
owned.ExecuteTasks();
Thread.Sleep(5);
}
// Anything that landed between the last pump and the final check.
owned.ExecuteTasks();
}
finally
{
Core.LoopContext = original;
}
}
private static PasswordJob JobFor(Account account, string submitted) =>
new()
{
Account = account,
StoredHash = account.Password,
VerifyPhrase = account.GetVerifyPhrase(submitted),
HashPhrase = account.NeedsPasswordUpgrade() ? account.GetRehashPhrase(submitted) : null,
StoredAlgorithm = account.PasswordAlgorithm,
TargetAlgorithm = AccountSecurity.CurrentAlgorithm
};
/// <summary>
/// Drives the real queue rather than <c>ComputeInline</c>. A job with no NetState attached -- an
/// admin password change -- was being dropped by the liveness check, which read a null State as
/// a dead connection, so the change silently never happened and its callback never fired.
/// </summary>
[Fact]
public void RunsAJobThatHasNoConnectionAttached()
{
var account = CreateAccount("offloop-no-netstate-user");
var applied = false;
var job = new PasswordJob
{
Account = account,
HashPhrase = account.GetRehashPhrase("a-queued-password"),
TargetAlgorithm = AccountSecurity.CurrentAlgorithm,
OnComplete = (_, outcome) => applied = outcome.Hash != null
};
PumpUntil(() => Assert.True(PasswordWorker.TryEnqueue(job)), () => applied);
Assert.True(applied);
Assert.True(account.CheckPassword("a-queued-password"));
}
[Fact]
public void VerifiesTheCorrectPassword()
{
var account = CreateAccount("offloop-correct-user");
var outcome = PasswordWorker.ComputeInline(JobFor(account, Password));
Assert.True(outcome.Verified);
}
[Fact]
public void RejectsTheWrongPassword()
{
var account = CreateAccount("offloop-wrong-user");
var outcome = PasswordWorker.ComputeInline(JobFor(account, "not-the-password"));
Assert.False(outcome.Verified);
Assert.Null(outcome.Hash);
}
[Fact]
public void ProducesNoUpgradeWhenParametersAreCurrent()
{
var account = CreateAccount("offloop-current-user");
var outcome = PasswordWorker.ComputeInline(JobFor(account, Password));
Assert.True(outcome.Verified);
Assert.Null(outcome.Hash);
}
[Fact]
public void ProducesAnUpgradeWhenParametersAreStale()
{
var account = CreateAccount("offloop-stale-user");
// The shipping default before #2562: Argon2i, m=8192, t=3, p=1.
account.Password =
"$argon2i$v=19$m=8192,t=3,p=1$LD1XJz7P3wQmIJ+Tu6ScgA$NO5hBABsHQ172C5nDO2X4gWnB4jDef3x6WhLdVE2LFw";
var outcome = PasswordWorker.ComputeInline(JobFor(account, Password));
Assert.True(outcome.Verified);
Assert.StartsWith("$argon2id$v=19$m=16384,t=1,p=1$", outcome.Hash);
}
[Fact]
public void ProducesNoUpgradeWhenThePasswordIsWrong()
{
var account = CreateAccount("offloop-wrong-stale-user");
account.Password =
"$argon2i$v=19$m=8192,t=3,p=1$LD1XJz7P3wQmIJ+Tu6ScgA$NO5hBABsHQ172C5nDO2X4gWnB4jDef3x6WhLdVE2LFw";
var outcome = PasswordWorker.ComputeInline(JobFor(account, "not-the-password"));
Assert.False(outcome.Verified);
Assert.Null(outcome.Hash);
}
[Fact]
public void AppliesAWrite()
{
var account = CreateAccount("offloop-apply-user");
var upgraded = Argon2PasswordProtection.Instance.EncryptPassword(Password);
account.ApplyPasswordWrite(upgraded, PasswordProtectionAlgorithm.Argon2);
Assert.Equal(upgraded, account.Password);
Assert.True(account.CheckPassword(Password));
}
/// <summary>
/// Writes apply in dispatch order, which is what makes a guard unnecessary: dispatch is on the
/// loop, one worker drains FIFO, and results return through the loop context in that same order.
/// A second worker thread would break this and would need ordering reintroduced.
/// </summary>
[Fact]
public void WritesApplyInDispatchOrder()
{
var account = CreateAccount("offloop-two-writes-user");
var done = 0;
PumpUntil(
() =>
{
for (var i = 1; i <= 2; i++)
{
Assert.True(
PasswordWorker.TryEnqueue(
new PasswordJob
{
Account = account,
HashPhrase = account.GetRehashPhrase($"password-{i}"),
StoredAlgorithm = account.PasswordAlgorithm,
TargetAlgorithm = AccountSecurity.CurrentAlgorithm,
OnComplete = (_, _) => done++
}
)
);
}
},
() => done >= 2
);
Assert.Equal(2, done);
Assert.True(account.CheckPassword("password-2"));
Assert.False(account.CheckPassword("password-1"));
}
[Theory]
[InlineData(PasswordProtectionAlgorithm.SHA1)]
[InlineData(PasswordProtectionAlgorithm.SHA2)]
public void UsesTheUsernameSaltedPhraseForShaAccounts(PasswordProtectionAlgorithm algorithm)
{
AccountSecurity.CurrentAlgorithm = algorithm;
var account = CreateAccount($"offloop-phrase-{algorithm}-user");
// Verification must use the algorithm the hash was stored under...
Assert.Equal($"{account.Username}{Password}", account.GetVerifyPhrase(Password));
// ...and a rehash the one it is moving to. Swapping these is the #2562 lockout.
AccountSecurity.CurrentAlgorithm = PasswordProtectionAlgorithm.Argon2;
Assert.Equal(Password, account.GetRehashPhrase(Password));
}
[Fact]
public void UsesTheBarePasswordForArgon2Accounts()
{
var account = CreateAccount("offloop-phrase-argon2-user");
Assert.Equal(Password, account.GetVerifyPhrase(Password));
Assert.Equal(Password, account.GetRehashPhrase(Password));
}
}

View file

@ -74,4 +74,89 @@ public class PasswordProtectionTest
Assert.False(passwordProtection.ValidatePassword(encryptedPassword, "Not the same password"));
}
/// <summary>
/// Literal digests of <see cref="plainPassword"/>, so the stored format cannot drift. These are
/// compared as strings against what is already in every account database -- a casing or encoding
/// change would lock out every SHA and MD5 account on the shard at once.
/// </summary>
[Theory]
[InlineData("MD5", "52284053181040AC90DBDE74A0E7FF5E")]
[InlineData("SHA1", "9AC635509803AAE2D8312BA1879289259A50C5F0")]
[InlineData(
"SHA2",
"5A727BFF8F8E08A24BDF6B0CD5065F30A1F8E0060B857BB8AFD6955BE0ACBC489DA63F19B8F4CF08D73DE4069CF4B" +
"29D94B353F31513B2FB2D9382EFE15AE975"
)]
public void HashAlgorithm_StoredFormatIsStable(string algorithmType, string expected)
{
var protection = algorithmType switch
{
"SHA1" => HashAlgorithmPasswordProtection.SHA1Instance,
"SHA2" => HashAlgorithmPasswordProtection.SHA2Instance,
_ => HashAlgorithmPasswordProtection.MD5Instance,
};
Assert.Equal(expected, protection.EncryptPassword(plainPassword));
Assert.True(protection.ValidatePassword(expected, plainPassword));
}
// The shipping default before this change, as a literal so it cannot drift with the configured
// defaults. Password: "hunter2".
private const string LegacyArgon2iHash =
"$argon2i$v=19$m=8192,t=3,p=1$LD1XJz7P3wQmIJ+Tu6ScgA$NO5hBABsHQ172C5nDO2X4gWnB4jDef3x6WhLdVE2LFw";
[Fact]
public void Argon2_ValidatesLegacyArgon2iHash()
{
Assert.True(Argon2PasswordProtection.Instance.ValidatePassword(LegacyArgon2iHash, "hunter2"));
Assert.False(Argon2PasswordProtection.Instance.ValidatePassword(LegacyArgon2iHash, "wrong"));
}
[Theory]
// type, memory, time, parallelism -> expected NeedsRehash
[InlineData("argon2id", 16384, 1, 1, false)] // current defaults
[InlineData("argon2i", 8192, 3, 1, true)] // the old shipping default
[InlineData("argon2id", 8192, 1, 1, true)] // right type, stale memory
[InlineData("argon2id", 16384, 3, 1, true)] // right type, stale iterations
[InlineData("argon2id", 16384, 1, 2, true)] // right type, stale parallelism
[InlineData("argon2i", 16384, 1, 1, true)] // right cost, stale type
public void Argon2_NeedsRehash_ComparesTypeAndCost(
string type, int memory, int time, int parallelism, bool expected
)
{
var hash = $"${type}$v=19$m={memory},t={time},p={parallelism}$" +
"LD1XJz7P3wQmIJ+Tu6ScgA$NO5hBABsHQ172C5nDO2X4gWnB4jDef3x6WhLdVE2LFw";
Assert.Equal(expected, Argon2PasswordProtection.Instance.NeedsRehash(hash));
}
// Digest and salt lengths are decoded base64 sizes rather than parameter-list entries, so they
// need their own literals. Current type and cost throughout; only a length differs.
[Theory]
// 16-byte digest: 22 base64 chars instead of the 43 a 32-byte digest encodes to.
[InlineData("$argon2id$v=19$m=16384,t=1,p=1$LD1XJz7P3wQmIJ+Tu6ScgA$NO5hBABsHQ172C5nDO2X4g")]
// 8-byte salt: 11 base64 chars instead of the 22 a 16-byte salt encodes to.
[InlineData("$argon2id$v=19$m=16384,t=1,p=1$LD1XJz7P3wQ$NO5hBABsHQ172C5nDO2X4gWnB4jDef3x6WhLdVE2LFw")]
public void Argon2_NeedsRehash_ComparesSaltAndDigestLengths(string hash)
{
Assert.True(Argon2PasswordProtection.Instance.NeedsRehash(hash));
}
[Theory]
[InlineData("")]
[InlineData("not-a-hash")]
public void Argon2_NeedsRehash_IsTrueForUnparseableHashes(string hash)
{
Assert.True(Argon2PasswordProtection.Instance.NeedsRehash(hash));
}
[Fact]
public void NonArgon2Protections_NeverNeedRehash()
{
Assert.False(PBKDF2PasswordProtection.Instance.NeedsRehash("anything"));
Assert.False(HashAlgorithmPasswordProtection.SHA2Instance.NeedsRehash("anything"));
Assert.False(HashAlgorithmPasswordProtection.SHA1Instance.NeedsRehash("anything"));
Assert.False(HashAlgorithmPasswordProtection.MD5Instance.NeedsRehash("anything"));
}
}

View file

@ -6,6 +6,8 @@ public class DynamicTestGump : DynamicGump
{
private readonly string _petName;
public bool HasVisualElementsForTest => HasVisualElements;
public DynamicTestGump(string petName) : base(50, 50)
{
_petName = petName;

View file

@ -0,0 +1,40 @@
using Server.Gumps;
namespace Server.Tests.Gumps;
public sealed class EmptyLegacyTestGump : Gump
{
public bool HasVisualElementsForTest => HasVisualElements;
public EmptyLegacyTestGump() : base(0, 0)
{
}
}
public sealed class EmptyDynamicTestGump : DynamicGump
{
public bool HasVisualElementsForTest => HasVisualElements;
public EmptyDynamicTestGump() : base(0, 0)
{
}
protected override void BuildLayout(ref DynamicGumpBuilder builder)
{
builder.AddPage();
}
}
public sealed class EmptyStaticTestGump : StaticGump<EmptyStaticTestGump>
{
public bool HasVisualElementsForTest => HasVisualElements;
public EmptyStaticTestGump() : base(0, 0)
{
}
protected override void BuildLayout(ref StaticGumpBuilder builder)
{
builder.SetNoClose();
}
}

View file

@ -4,6 +4,8 @@ namespace Server.Tests.Gumps;
public sealed class LegacyTestGump : Gump
{
public bool HasVisualElementsForTest => HasVisualElements;
public LegacyTestGump(string petName) : base(50, 50)
{
Serial = (Serial)0x123;

View file

@ -4,6 +4,8 @@ namespace Server.Tests.Gumps;
public class StaticTestGump : StaticGump<StaticTestGump>
{
public bool HasVisualElementsForTest => HasVisualElements;
public StaticTestGump() : base(50, 50)
{
Serial = (Serial)0x123;

View file

@ -73,6 +73,32 @@ public class TestLayoutGumps
AssertThat.Equal(writer.Span, packet);
}
[Fact]
public void TestEmptyGumpsHaveNoVisualElements()
{
Assert.False(Compile(new EmptyLegacyTestGump()).HasVisualElementsForTest);
Assert.False(Compile(new EmptyDynamicTestGump()).HasVisualElementsForTest);
Assert.False(Compile(new EmptyStaticTestGump()).HasVisualElementsForTest);
Assert.False(Compile(new EmptyStaticTestGump()).HasVisualElementsForTest);
}
[Fact]
public void TestVisibleGumpsHaveVisualElements()
{
Assert.True(Compile(new LegacyTestGump("Test")).HasVisualElementsForTest);
Assert.True(Compile(new DynamicTestGump("Test")).HasVisualElementsForTest);
Assert.True(Compile(new StaticTestGump()).HasVisualElementsForTest);
Assert.True(Compile(new StaticTestGump()).HasVisualElementsForTest);
}
private static T Compile<T>(T gump) where T : BaseGump
{
var buffer = GC.AllocateUninitializedArray<byte>(512);
var writer = new SpanWriter(buffer);
gump.Compile(ref writer);
return gump;
}
private static void InternalTestStaticGump<T>(ReadOnlySpan<byte> expectedLayout, StaticGump<T> staticGump, string[] strings)
where T : StaticGump<T>
{

View file

@ -0,0 +1,111 @@
using Server;
using Server.Items;
using Server.Mobiles;
using Server.Tests;
using Xunit;
namespace UOContent.Tests;
[Collection("Sequential UOContent Tests")]
public class TreasureMapChestLiftTests
{
// Coordinates chosen to avoid overlap with Tracking (1000-4000, 1000-4000) and
// DetectHidden (1000-2400, 500) test areas.
[Fact]
public void PartialLift_MarksSplitRemainderAsLifted()
{
using var rng = new PredictableRandom(10); // RandomDouble() = 0.5, no spawn roll fires
var map = Map.Felucca;
var location = new Point3D(5000, 600, 0);
var player = CreatePlayerMobile(map, location);
var chest = new TreasureMapChest(1);
try
{
chest.MoveToWorld(location, map);
chest.Locked = false;
var gold = FindGold(chest, null);
Assert.NotNull(gold);
player.Lift(gold, 1, out var rejected, out _);
Assert.False(rejected);
// The stack split re-adds the remainder as a brand-new item. It must count as
// already lifted, otherwise every 1-coin pull grants a fresh guardian spawn roll.
var remainder = FindGold(chest, gold);
Assert.NotNull(remainder);
Assert.Contains(remainder, chest.Lifted);
Assert.Contains(gold, chest.Lifted);
}
finally
{
player.Holding?.Delete();
player.Delete();
chest.Delete();
}
}
[Fact]
public void ItemAddedAfterFill_IsMarkedLifted()
{
using var rng = new PredictableRandom(10);
var chest = new TreasureMapChest(1);
var packed = new Gold(500);
try
{
// Anything entering the chest after the initial fill (packed-back gold, split
// remainders, GM drops) was never part of the original loot and must not
// grant spawn rolls when lifted back out.
chest.DropItem(packed);
Assert.Contains(packed, chest.Lifted);
}
finally
{
chest.Delete();
}
}
[Fact]
public void OriginalFillLoot_IsNotMarkedLifted()
{
using var rng = new PredictableRandom(10);
var chest = new TreasureMapChest(1);
try
{
// The original loot must stay roll-eligible for its first lift.
Assert.True(chest.Lifted == null || chest.Lifted.Count == 0);
}
finally
{
chest.Delete();
}
}
private static Gold FindGold(TreasureMapChest chest, Gold except)
{
var items = chest.Items;
for (var i = 0; i < items.Count; i++)
{
if (items[i] is Gold gold && gold != except)
{
return gold;
}
}
return null;
}
private static PlayerMobile CreatePlayerMobile(Map map, Point3D location)
{
var mobile = new PlayerMobile(World.NewMobile);
mobile.DefaultMobileInit();
mobile.MoveToWorld(location, map);
return mobile;
}
}

View file

@ -0,0 +1,219 @@
using System;
using System.Collections.Generic;
using Server;
using Server.Mobiles;
using Xunit;
namespace UOContent.Tests.Mobiles.AI;
// Pins the CurrentMoveSpeed classification (verbatim active/passive maps to the matching
// move value; bespoke stays fused), SetSpeed's one-clock guarantee, and the v22 tail.
[Collection("Sequential UOContent Tests")]
public class MoveSpeedTests : IDisposable
{
// Delete spawned stubs so they don't linger in the shared static World.
private readonly List<Mobile> _created = new();
public void Dispose()
{
for (var i = 0; i < _created.Count; i++)
{
_created[i].Delete();
}
}
private sealed class SpeedStub : BaseCreature
{
// Stands in for the npc-speeds table (unconfigured in the test fixture).
public double TableActiveMove;
public double TablePassiveMove;
public SpeedStub() : base(AIType.AI_Animal) => Body = 0xC9;
public SpeedStub(Serial serial) : base(serial) => Body = 0xC9;
public override void GetSpeeds(out double activeSpeed, out double passiveSpeed)
{
activeSpeed = 0.3;
passiveSpeed = 0.6;
}
public override void GetMoveSpeeds(out double activeMoveSpeed, out double passiveMoveSpeed)
{
activeMoveSpeed = TableActiveMove;
passiveMoveSpeed = TablePassiveMove;
}
}
private SpeedStub NewCreature()
{
var bc = new SpeedStub();
_created.Add(bc);
return bc;
}
[Fact]
public void MoveSpeeds_InheritThinkValues_ByDefault()
{
var bc = NewCreature();
Assert.Equal(0.3, bc.ActiveMoveSpeed);
Assert.Equal(0.6, bc.PassiveMoveSpeed);
Assert.Equal(bc.CurrentSpeed, bc.CurrentMoveSpeed);
}
[Fact]
public void CurrentMoveSpeed_ResolvesPerMode_WhenOverridden()
{
var bc = NewCreature();
bc.SetMoveSpeed(0.45, 0.9);
// SetSpeed left the creature passive; the think clock is untouched.
Assert.Equal(0.6, bc.CurrentSpeed);
Assert.Equal(0.9, bc.CurrentMoveSpeed);
bc.SetCurrentSpeedToActive();
Assert.Equal(0.3, bc.CurrentSpeed);
Assert.Equal(0.45, bc.CurrentMoveSpeed);
}
[Fact]
public void CurrentMoveSpeed_BespokePace_StaysFused()
{
var bc = NewCreature();
bc.SetMoveSpeed(0.45, 0.9);
// Neither think value verbatim, so both clocks run it.
bc.CurrentSpeed = 0.11;
Assert.Equal(0.11, bc.CurrentMoveSpeed);
}
[Fact]
public void SetSpeed_ClearsMoveOverrides()
{
var bc = NewCreature();
bc.SetMoveSpeed(0.45, 0.9);
bc.SetSpeed(0.2, 0.4);
Assert.Equal(0.2, bc.ActiveMoveSpeed);
Assert.Equal(0.4, bc.PassiveMoveSpeed);
}
[Fact]
public void NonPositiveMoveSpeed_ClearsThatOverride()
{
var bc = NewCreature();
bc.SetMoveSpeed(0.45, 0.9);
bc.ActiveMoveSpeed = 0;
Assert.Equal(0.3, bc.ActiveMoveSpeed); // inheriting again
Assert.Equal(0.9, bc.PassiveMoveSpeed); // other override untouched
}
[Fact]
public void ScaleMoveSpeed_ScalesOverrides_LeavesInheritAlone()
{
var bc = NewCreature();
bc.ActiveMoveSpeed = 0.6; // passive left inheriting
bc.ScaleMoveSpeed(1.0 / 1.2);
Assert.Equal(0.5, bc.ActiveMoveSpeed);
Assert.Equal(bc.PassiveSpeed, bc.PassiveMoveSpeed); // still inheriting, not 0 * scalar
}
[Fact]
public void Herding_DrivesMoveClock_ThinkUntouched()
{
var bc = NewCreature(); // think 0.3/0.6, passive
bc.SetMoveSpeed(0.45, 1.05);
bc.TargetLocation = new Point2D(10, 10);
Assert.Equal(0.6, bc.CurrentSpeed); // think clock unaffected by herding
Assert.Equal(0.3, bc.CurrentMoveSpeed); // fixed herding pace, not 1.05
bc.TargetLocation = null;
Assert.Equal(1.05, bc.CurrentMoveSpeed);
}
[Fact]
public void SnapSpeedsToTable_UndoesScalingDrift_KeepsTunedValues()
{
var bc = NewCreature();
bc.TableActiveMove = 0.45;
bc.TablePassiveMove = 0.9;
bc.SetMoveSpeed(0.45, 0.9);
// 0.45 and 0.9 do not survive /1.2 then *1.2 bit-exactly.
bc.ScaleMoveSpeed(1.0 / 1.2);
bc.ScaleMoveSpeed(1.2);
Assert.NotEqual(0.45, bc.ActiveMoveSpeed);
bc.SnapSpeedsToTable();
Assert.Equal(0.45, bc.ActiveMoveSpeed);
Assert.Equal(0.9, bc.PassiveMoveSpeed);
// A hand-tuned value is nowhere near the epsilon and must keep.
bc.SetMoveSpeed(0.7, 0.9);
bc.SnapSpeedsToTable();
Assert.Equal(0.7, bc.ActiveMoveSpeed);
}
[Fact]
public void Migration_MatchingThinkSpeeds_AdoptTableMoveValues()
{
var bc = NewCreature(); // think 0.3/0.6, matching its table entry
bc.TableActiveMove = 0.45;
bc.TablePassiveMove = 0.9;
bc.MigrateMoveSpeeds();
Assert.Equal(0.45, bc.ActiveMoveSpeed);
Assert.Equal(0.9, bc.PassiveMoveSpeed);
}
[Fact]
public void Migration_TunedThinkSpeeds_KeepInheriting()
{
var bc = NewCreature();
bc.SetSpeed(0.35, 0.6); // hand-tuned: no longer matches the table entry
bc.TableActiveMove = 0.45;
bc.TablePassiveMove = 0.9;
bc.MigrateMoveSpeeds();
Assert.Equal(0.35, bc.ActiveMoveSpeed);
Assert.Equal(0.6, bc.PassiveMoveSpeed);
}
[Theory]
[InlineData(true)]
[InlineData(false)]
public void MoveSpeedOverrides_SurviveSerialization(bool overridden)
{
var bc = NewCreature();
if (overridden)
{
bc.SetMoveSpeed(0.45, 0.9);
}
var writer = new BufferWriter(true);
bc.Serialize(writer);
var buffer = new byte[writer.Position];
writer.Buffer.AsSpan(0, (int)writer.Position).CopyTo(buffer);
var copy = new SpeedStub(World.NewMobile);
_created.Add(copy);
var reader = new BufferReader(buffer);
copy.Deserialize(reader);
// The v22 tail is the last block; exact consumption catches any offset mistake.
Assert.Equal(buffer.Length, reader.Position);
Assert.Equal(overridden ? 0.45 : 0.3, copy.ActiveMoveSpeed);
Assert.Equal(overridden ? 0.9 : 0.6, copy.PassiveMoveSpeed);
}
}

View file

@ -20,8 +20,8 @@ using Xunit;
namespace Server.Tests.Network.AutoDenylists;
// Static store, so every test resets it first. Addresses come from TEST-NET-2 (198.51.100.0/24).
// Sequential: the cap tests reach Sweep, which rents from STArrayPool, which is not thread-safe.
// Static store, so every test resets it first and none may run alongside another.
// Addresses come from TEST-NET-2 (198.51.100.0/24).
[Collection("Sequential UOContent Tests")]
public class AutoDenylistTests
{
@ -62,8 +62,11 @@ public class AutoDenylistTests
Assert.Equal(0, AutoDenylist.Count);
}
// Not refreshed on purpose: it is what keeps insertion order equal to expiry order, so retiring lapsed
// entries costs the number expiring instead of the number held. A flooder whose hold lapses trips the
// rate limiter on its next attempt -- which runs ahead of the connection filters -- and is held again.
[Fact]
public void Repeat_detection_extends_the_hold()
public void Repeat_detection_does_not_extend_the_hold()
{
Reset();
var ip = IPAddress.Parse("198.51.100.13");
@ -71,8 +74,72 @@ public class AutoDenylistTests
AutoDenylist.Hold(ip, BanReasons.SilentConnect, Now);
AutoDenylist.Hold(ip, BanReasons.SilentConnect, Now + DurationMs - 1);
Assert.True(AutoDenylist.IsDenied(ip, Now + DurationMs + 1)); // would have lapsed without the second
Assert.Equal(1, AutoDenylist.Count); // and did not add a duplicate
Assert.Equal(1, AutoDenylist.Count); // no duplicate
Assert.True(AutoDenylist.IsDenied(ip, Now + DurationMs - 1));
Assert.False(AutoDenylist.IsDenied(ip, Now + DurationMs + 1)); // lapses from the FIRST detection
}
// The ring carries the expiry and the set carries membership; if they ever disagree, an address is
// either denied forever or retired early.
[Fact]
public void Ring_and_set_stay_in_step()
{
Reset(maxEntries: 4);
for (var i = 0; i < 8; i++)
{
AutoDenylist.Hold(IPAddress.Parse($"198.51.100.{70 + i}"), BanReasons.InvalidSeed, Now);
}
Assert.Equal(4, AutoDenylist.Count);
Assert.Equal(AutoDenylist.Count, AutoDenylist.RingCount);
AutoDenylist.Release(IPAddress.Parse("198.51.100.71"));
Assert.Equal(3, AutoDenylist.Count);
Assert.Equal(AutoDenylist.Count, AutoDenylist.RingCount);
AutoDenylist.Drain(Now + DurationMs + 1);
Assert.Equal(0, AutoDenylist.Count);
Assert.Equal(0, AutoDenylist.RingCount);
}
// The ring grows in doublings but is capped at maxEntries, which is not a power of two. Filling exactly
// to it must land on the last slot rather than off the end.
[Fact]
public void Ring_fills_exactly_to_a_non_power_of_two_cap()
{
Reset(maxEntries: 100);
for (var i = 0; i < 120; i++)
{
AutoDenylist.Hold(IPAddress.Parse($"198.51.100.{i}"), BanReasons.InvalidSeed, Now);
}
Assert.Equal(100, AutoDenylist.Count);
Assert.Equal(100, AutoDenylist.RingCount);
// And the whole ring still drains, so no slot was stranded by a wrapped write.
AutoDenylist.Drain(Now + DurationMs + 1);
Assert.Equal(0, AutoDenylist.Count);
Assert.Equal(0, AutoDenylist.RingCount);
}
// Releasing leaves no ring record behind, so a re-detection is not retired by the old one.
[Fact]
public void Release_then_re_hold_is_not_retired_by_the_stale_record()
{
Reset();
var ip = IPAddress.Parse("198.51.100.15");
AutoDenylist.Hold(ip, BanReasons.RateLimit, Now);
AutoDenylist.Release(ip);
var later = Now + DurationMs - 1;
AutoDenylist.Hold(ip, BanReasons.RateLimit, later);
// The first hold's expiry has passed; the second must survive it.
Assert.True(AutoDenylist.IsDenied(ip, Now + DurationMs + 1));
Assert.Equal(1, AutoDenylist.RingCount);
}
[Fact]

View file

@ -28,15 +28,15 @@ public class BanExemptionsTests
private static readonly IPAddress _listed = IPAddress.Parse("192.0.2.10");
private static readonly IPAddress _unlisted = IPAddress.Parse("192.0.2.11");
private static void WithFileAllowlist(string contents) =>
FileAllowlist.LoadForTesting(BlocklistSnapshot.Build(Encoding.ASCII.GetBytes(contents), out _, out _));
private static void WithManualAllowlist(string contents) =>
ManualAllowlist.LoadForTesting(BlocklistSnapshot.Build(Encoding.ASCII.GetBytes(contents), out _, out _));
private static void WithEmptyFileAllowlist() => FileAllowlist.LoadForTesting(BlocklistSnapshot.Empty);
private static void WithEmptyManualAllowlist() => ManualAllowlist.LoadForTesting(BlocklistSnapshot.Empty);
[Fact]
public void File_allowlist_exempts_behavioral_contributions()
public void Manual_allowlist_exempts_behavioral_contributions()
{
WithFileAllowlist("192.0.2.10");
WithManualAllowlist("192.0.2.10");
// Subtracting from the blocklist does nothing for behavioural detections, which never consult it.
Assert.True(BanExemptions.IsExempt(_listed, BanReasons.ForeignProtocol, NeverCalled));
@ -46,10 +46,10 @@ public class BanExemptionsTests
}
[Fact]
public void File_allowlist_covers_cidr_entries()
public void Manual_allowlist_covers_cidr_entries()
{
// Carve-outs are CIDRs, so a shared-CGNAT player is only covered if ranges work here.
WithFileAllowlist("192.0.2.0/24");
WithManualAllowlist("192.0.2.0/24");
Assert.True(BanExemptions.IsExempt(_listed, BanReasons.RateLimit, NeverCalled));
Assert.True(BanExemptions.IsExempt(IPAddress.Parse("192.0.2.254"), BanReasons.RateLimit, NeverCalled));
@ -57,9 +57,9 @@ public class BanExemptionsTests
}
[Fact]
public void Manual_bans_are_never_exempt_even_when_file_allowlisted()
public void Manual_bans_are_never_exempt_even_when_allowlisted()
{
WithFileAllowlist("192.0.2.10");
WithManualAllowlist("192.0.2.10");
// An explicit decision outranks the operator's own carve-out, and must not cost a strike.
Assert.False(BanExemptions.IsExempt(_listed, BanReasons.Manual, NeverCalled));
@ -68,16 +68,16 @@ public class BanExemptionsTests
[Fact]
public void Unopted_reasons_are_never_exempt()
{
WithFileAllowlist("192.0.2.10");
WithManualAllowlist("192.0.2.10");
Assert.False(BanExemptions.IsExempt(_listed, BanReasons.Blocklist, NeverCalled));
Assert.False(BanExemptions.IsExempt(_listed, "some-future-reason", NeverCalled));
}
[Fact]
public void File_allowlist_does_not_spend_the_earned_lists_strikes()
public void Manual_allowlist_does_not_spend_the_earned_lists_strikes()
{
WithFileAllowlist("192.0.2.10");
WithManualAllowlist("192.0.2.10");
// Unconditional, so the revocable list must not be consulted -- that would burn a strike.
Assert.True(BanExemptions.IsExempt(_listed, BanReasons.RateLimit, NeverCalled));
@ -86,7 +86,7 @@ public class BanExemptionsTests
[Fact]
public void Falls_through_to_the_login_allowlist_when_not_file_listed()
{
WithEmptyFileAllowlist();
WithEmptyManualAllowlist();
var consulted = 0;
@ -107,7 +107,7 @@ public class BanExemptionsTests
[Fact]
public void Null_address_is_never_exempt()
{
WithEmptyFileAllowlist();
WithEmptyManualAllowlist();
Assert.False(BanExemptions.IsExempt(null, BanReasons.RateLimit, NeverCalled));
}

View file

@ -30,6 +30,7 @@ public class BlocklistConfigurationTests
{
var original = new BlocklistSettings
{
Enabled = true,
File = "D:/shared/ip-blocklist.txt",
ReloadInterval = TimeSpan.FromMinutes(5),
ReportHits = false,
@ -39,6 +40,7 @@ public class BlocklistConfigurationTests
var json = JsonConfig.Serialize(original);
Assert.Contains("\"enabled\"", json);
Assert.Contains("\"file\"", json);
Assert.Contains("\"reloadInterval\"", json);
Assert.Contains("\"reportHits\"", json);
@ -48,6 +50,7 @@ public class BlocklistConfigurationTests
var restored = JsonSerializer.Deserialize<BlocklistSettings>(json, JsonConfig.DefaultOptions);
Assert.NotNull(restored);
Assert.Equal(original.Enabled, restored.Enabled);
Assert.Equal(original.File, restored.File);
Assert.Equal(original.ReloadInterval, restored.ReloadInterval);
Assert.Equal(original.ReportHits, restored.ReportHits);
@ -55,6 +58,13 @@ public class BlocklistConfigurationTests
Assert.Equal(original.PromoteSuppression, restored.PromoteSuppression);
}
// The point of the flag: a shard that never opts in must not start the reload poll.
[Fact]
public void Blocklist_is_off_by_default()
{
Assert.False(new BlocklistSettings().Enabled);
}
// The generator (tools/Export-IpBlocklist.ps1) writes to this path by default; if one side moves
// without the other, a shard silently enforces nothing.
[Fact]

View file

@ -0,0 +1,66 @@
/*************************************************************************
* ModernUO *
* Copyright 2019-2026 - ModernUO Development Team *
* Email: hi@modernuo.com *
* File: ManualAllowlistConfigurationTests.cs *
* *
* This program is free software: you can redistribute it and/or modify *
* it under the terms of the GNU General Public License as published by *
* the Free Software Foundation, either version 3 of the License, or *
* (at your option) any later version. *
* *
* You should have received a copy of the GNU General Public License *
* along with this program. If not, see <http://www.gnu.org/licenses/>. *
*************************************************************************/
using System;
using System.Text.Json;
using Server.Json;
using Server.Network.Bans;
using Xunit;
namespace Server.Tests.Network.ManualAllowlists;
public class ManualAllowlistConfigurationTests
{
// Locks the JsonConfig casing contract: JsonConfig's options are case-SENSITIVE, so every settings
// member must carry an explicit [JsonPropertyName("camelCase")] or it silently binds nothing.
[Fact]
public void ManualAllowlistSettings_RoundTripsThroughJsonConfig()
{
var original = new ManualAllowlistSettings
{
Enabled = true,
Files = ["D:/shared/ip-allowlist*.txt"],
ReloadInterval = TimeSpan.FromMinutes(5)
};
var json = JsonConfig.Serialize(original);
Assert.Contains("\"enabled\"", json);
Assert.Contains("\"files\"", json);
Assert.Contains("\"reloadInterval\"", json);
var restored = JsonSerializer.Deserialize<ManualAllowlistSettings>(json, JsonConfig.DefaultOptions);
Assert.NotNull(restored);
Assert.Equal(original.Enabled, restored.Enabled);
Assert.Equal(original.Files, restored.Files);
Assert.Equal(original.ReloadInterval, restored.ReloadInterval);
}
// The point of the flag: a shard that never opts in must not start the reload poll.
[Fact]
public void Manual_allowlist_is_off_by_default()
{
Assert.False(new ManualAllowlistSettings().Enabled);
}
// The generator creates ip-allowlist.txt beside the blocklist; the wildcard is what picks up a
// carve-out file (-RefreshCarveouts writes ip-allowlist-starlink.txt) with no config edit.
[Fact]
public void Default_pattern_matches_the_generator_output_path()
{
Assert.Equal(["Configuration/ip-allowlist*.txt"], new ManualAllowlistSettings().Files);
}
}

View file

@ -0,0 +1,382 @@
using System;
using System.Net;
using Server.Accounting;
using Server.Accounting.Security;
using Server.Network;
using Server.Tests.Network;
using Xunit;
namespace Server.Tests.Network.Packets;
[Collection("Sequential UOContent Tests")]
public class AuthIdTests : IDisposable
{
private static readonly IPAddress AddressX = IPAddress.Parse("203.0.113.10");
private static readonly IPAddress AddressY = IPAddress.Parse("203.0.113.11");
private readonly PasswordProtectionAlgorithm _originalAlgorithm = AccountSecurity.CurrentAlgorithm;
public AuthIdTests()
{
AccountSecurity.CurrentAlgorithm = PasswordProtectionAlgorithm.Argon2;
IncomingAccountPackets.ClearAuthIdWindow();
}
public void Dispose()
{
IncomingAccountPackets.ClearAuthIdWindow();
AccountSecurity.CurrentAlgorithm = _originalAlgorithm;
}
private static IAccount CreateAccount(string username) =>
Accounts.GetAccount(username) ?? new Account(username, "hunter2");
private static int Register(IAccount account, IPAddress address) =>
IncomingAccountPackets.RegisterAuthId(account, address, new ClientVersion(7, 0, 0, 0));
[Fact]
public void VouchesForTheAccountAndAddressItWasIssuedTo()
{
var account = CreateAccount("authid-match-user");
var authId = Register(account, AddressX);
var result = IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out var entry);
Assert.Equal(IncomingAccountPackets.AuthIdResult.Vouched, result);
Assert.Same(account, entry.Account);
}
[Fact]
public void RejectsADifferentAccount()
{
var issued = CreateAccount("authid-owner-user");
var other = CreateAccount("authid-other-user");
var authId = Register(issued, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId, other.Username, AddressX, out _)
);
}
[Fact]
public void RejectsADifferentAddress()
{
var account = CreateAccount("authid-switch-user");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressY, out _)
);
}
[Fact]
public void MatchesTheUsernameCaseInsensitively()
{
var account = CreateAccount("AuthId-Case-User");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(authId, "authid-case-user", AddressX, out _)
);
}
[Fact]
public void MatchesAnIPv4MappedIPv6Address()
{
var account = CreateAccount("authid-mapped-user");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX.MapToIPv6(), out _)
);
}
[Fact]
public void RejectsAnUnknownAuthId()
{
var account = CreateAccount("authid-unknown-user");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId + 1, account.Username, AddressX, out _)
);
}
[Fact]
public void IsSingleUseAfterASuccess()
{
var account = CreateAccount("authid-once-user");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out _)
);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out _)
);
}
// A rejected attempt must not consume the id, or anyone landing on a live one could burn it and
// force its owner to log in again.
[Fact]
public void SurvivesAnAttemptFromTheWrongAddress()
{
var account = CreateAccount("authid-not-burned-address-user");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressY, out _)
);
Assert.Equal(1, IncomingAccountPackets.AuthIdWindowCount);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out _)
);
}
[Fact]
public void SurvivesAnAttemptForTheWrongAccount()
{
var account = CreateAccount("authid-not-burned-account-user");
var authId = Register(account, AddressX);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId, "not-the-owner", AddressX, out _)
);
Assert.Equal(1, IncomingAccountPackets.AuthIdWindowCount);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out _)
);
}
[Fact]
public void ARejectedAttemptYieldsNoEntry()
{
var account = CreateAccount("authid-no-leak-user");
var authId = Register(account, AddressX);
IncomingAccountPackets.ConsumeAuthId(authId, "not-the-owner", AddressX, out var entry);
Assert.Null(entry.Account);
}
[Fact]
public void AnExpiredIdIsSpentByItsOwner()
{
var account = CreateAccount("authid-expired-spent-user");
var authId = Register(account, AddressX);
var now = Core._now;
try
{
Core._now = now + TimeSpan.FromMinutes(30.0);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Expired,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out _)
);
Assert.Equal(0, IncomingAccountPackets.AuthIdWindowCount);
}
finally
{
Core._now = now;
}
}
// Expiry is not a lockout. The game login always verified the password before any of this
// existed, so falling back to that verify is the behaviour we started from.
[Fact]
public void ExpiresIntoAPasswordVerifyRatherThanARejection()
{
var account = CreateAccount("authid-expired-user");
var authId = Register(account, AddressX);
var now = Core._now;
try
{
Core._now = now + TimeSpan.FromMinutes(30.0);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Expired,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressX, out var entry)
);
// Still carries the client version the game login needs.
Assert.Equal(new ClientVersion(7, 0, 0, 0), entry.Version);
}
finally
{
Core._now = now;
}
}
[Fact]
public void AnExpiredIdFromAnotherAddressIsStillRejected()
{
var account = CreateAccount("authid-expired-elsewhere-user");
var authId = Register(account, AddressX);
var now = Core._now;
try
{
Core._now = now + TimeSpan.FromMinutes(30.0);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Rejected,
IncomingAccountPackets.ConsumeAuthId(authId, account.Username, AddressY, out _)
);
}
finally
{
Core._now = now;
}
}
private static int Ensure(int existingAuthId, IAccount account, IPAddress address) =>
IncomingAccountPackets.EnsureAuthId(
existingAuthId,
account,
address,
new ClientVersion(7, 0, 0, 0)
);
[Fact]
public void IssuesAnIdWhenTheConnectionHasNone()
{
var account = CreateAccount("authid-first-select-user");
var authId = Ensure(0, account, AddressX);
Assert.NotEqual(0, authId);
Assert.Equal(1, IncomingAccountPackets.AuthIdWindowCount);
}
// Handing the same id back rather than minting another is what makes an orphan impossible,
// instead of something to clean up afterwards.
[Fact]
public void ReSelectingReturnsTheSameIdAndAddsNothingToTheWindow()
{
var account = CreateAccount("authid-reselect-user");
var first = Ensure(0, account, AddressX);
for (var i = 0; i < 10; i++)
{
Assert.Equal(first, Ensure(first, account, AddressX));
}
Assert.Equal(1, IncomingAccountPackets.AuthIdWindowCount);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(first, account.Username, AddressX, out _)
);
}
[Fact]
public void AbandonedIdsAreSweptWhenNewOnesAreIssued()
{
var abandoned = CreateAccount("authid-abandoned-user");
var live = CreateAccount("authid-live-user");
var now = Core._now;
try
{
for (var i = 0; i < 128; i++)
{
Register(abandoned, AddressX);
}
Assert.Equal(128, IncomingAccountPackets.AuthIdWindowCount);
Core._now = now + TimeSpan.FromMinutes(30.0);
var liveId = Register(live, AddressX);
Assert.Equal(1, IncomingAccountPackets.AuthIdWindowCount);
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(liveId, live.Username, AddressX, out _)
);
}
finally
{
Core._now = now;
}
}
// A login rush is not a backlog. Every id belongs to a client on its way to redeem it, so none
// may be discarded to hold the window at some arbitrary size.
[Fact]
public void ALoginRushDoesNotEvictAnyonesAuthId()
{
var account = CreateAccount("authid-rush-user");
var ids = new int[800];
for (var i = 0; i < ids.Length; i++)
{
ids[i] = Register(account, AddressX);
}
Assert.Equal(ids.Length, IncomingAccountPackets.AuthIdWindowCount);
// Every id issued during the rush is still redeemable, including the first one.
for (var i = 0; i < ids.Length; i++)
{
Assert.Equal(
IncomingAccountPackets.AuthIdResult.Vouched,
IncomingAccountPackets.ConsumeAuthId(ids[i], account.Username, AddressX, out _)
);
}
}
[Fact]
public void PreAuthenticatedGameLogin_SkipsThePasswordCheck()
{
var account = CreateAccount("authid-preauth-user");
using var ns = PacketTestUtilities.CreateTestNetState();
// A wrong password is accepted only because the auth id already vouched for the account.
var e = new GameServer.GameLoginEventArgs(ns, account.Username, "wrong-password", true);
GameServer.GameServerLoginEvent(e);
Assert.True(e.Accepted);
}
[Fact]
public void GameLoginWithoutPreAuthentication_StillChecksThePassword()
{
var account = CreateAccount("authid-nopreauth-user");
using var ns = PacketTestUtilities.CreateTestNetState();
var wrong = new GameServer.GameLoginEventArgs(ns, account.Username, "wrong-password", false);
GameServer.GameServerLoginEvent(wrong);
Assert.False(wrong.Accepted);
var right = new GameServer.GameLoginEventArgs(ns, account.Username, "hunter2", false);
GameServer.GameServerLoginEvent(right);
Assert.True(right.Accepted);
}
[Fact]
public void GeneratesDistinctAuthIds()
{
var account = CreateAccount("authid-distinct-user");
Assert.NotEqual(Register(account, AddressX), Register(account, AddressX));
}
}

View file

@ -4,9 +4,9 @@
<Configurations>Debug;Release;Analyze</Configurations>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.8.1" />
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.9.0" />
<PackageReference Include="xunit" Version="2.9.3" />
<PackageReference Include="xunit.runner.visualstudio" Version="3.1.5">
<PackageReference Include="xunit.runner.visualstudio" Version="4.0.0">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
@ -15,7 +15,6 @@
<ProjectReference Include="..\UOContent\UOContent.csproj" />
<ProjectReference Include="..\Server.Tests\Server.Tests.csproj" />
<DataFiles Include="$(SolutionDir)\Distribution\Data\**" />
<PackageReference Update="Serilog" Version="4.4.0" />
</ItemGroup>
<Target Name="CopyData" AfterTargets="AfterBuild">
<Copy SourceFiles="@(DataFiles)" DestinationFolder="$(OutDir)\Data\%(RecursiveDir)" />

View file

@ -378,28 +378,54 @@ public partial class Account : IAccount, IComparable<Account>
public void SetPassword(string plainPassword)
{
var phrase = _passwordAlgorithm is PasswordProtectionAlgorithm.SHA1 or PasswordProtectionAlgorithm.SHA2
? $"{_username}{plainPassword}"
: plainPassword;
Password = AccountSecurity.CurrentPasswordProtection.EncryptPassword(phrase);
PasswordAlgorithm = AccountSecurity.CurrentAlgorithm;
Password = AccountSecurity.CurrentPasswordProtection.EncryptPassword(
AccountSecurity.DerivePhrase(PasswordAlgorithm, _username, plainPassword)
);
}
/// <summary>The phrase that verifies against the currently stored hash.</summary>
internal string GetVerifyPhrase(string plainPassword) =>
AccountSecurity.DerivePhrase(_passwordAlgorithm, _username, plainPassword);
/// <summary>The phrase a rehash to the configured algorithm would be derived from.</summary>
internal string GetRehashPhrase(string plainPassword) =>
AccountSecurity.DerivePhrase(AccountSecurity.CurrentAlgorithm, _username, plainPassword);
/// <summary>
/// Whether a successful login should rewrite the stored hash, because the algorithm changed or
/// its cost parameters moved.
/// </summary>
internal bool NeedsPasswordUpgrade() =>
_passwordAlgorithm != AccountSecurity.CurrentAlgorithm ||
AccountSecurity.CurrentPasswordProtection.NeedsRehash(Password);
/// <summary>
/// Applies a hash derived off the game loop. Distinct from the private <c>UpgradePassword</c>
/// below, which adopts a legacy hash when loading pre-binary XML accounts.
///
/// Unguarded: dispatch is on the loop, one worker drains FIFO, and results return through the
/// loop context in that order, so last dispatched is last applied. A second worker would need
/// ordering reintroduced here.
/// </summary>
internal void ApplyPasswordWrite(string newEncrypted, PasswordProtectionAlgorithm algorithm)
{
PasswordAlgorithm = algorithm;
Password = newEncrypted;
}
public bool CheckPassword(string plainPassword)
{
var phrase = _passwordAlgorithm is PasswordProtectionAlgorithm.SHA1 or PasswordProtectionAlgorithm.SHA2
? $"{_username}{plainPassword}"
: plainPassword;
var ok = AccountSecurity.GetPasswordProtection(_passwordAlgorithm)
.ValidatePassword(Password, GetVerifyPhrase(plainPassword));
var ok = AccountSecurity.GetPasswordProtection(_passwordAlgorithm).ValidatePassword(Password, phrase);
if (!ok)
{
return false;
}
// Upgrade the password protection in case we change the algorithm
if (_passwordAlgorithm != AccountSecurity.CurrentAlgorithm)
if (NeedsPasswordUpgrade())
{
SetPassword(plainPassword);
}

View file

@ -5,6 +5,7 @@ using System.Net;
using System.Runtime.CompilerServices;
using ModernUO.CodeGeneratedEvents;
using Server.Accounting;
using Server.Accounting.Security;
using Server.Engines.CharacterCreation;
using Server.Engines.Help;
using Server.Logging;
@ -69,6 +70,9 @@ public static class AccountHandler
public static void Initialize()
{
EventSink.AccountLogin += EventSink_AccountLogin;
EventSink.Shutdown += PasswordWorker.Stop;
EventSink.ServerCrashed += PasswordWorker.OnCrashed;
}
[Usage("Password <newPassword> <repeatPassword>")]
@ -139,8 +143,12 @@ public static class AccountHandler
if (accessList[0].MatchClassC(ipAddress))
{
acct.SetPassword(pass);
from.SendMessage("The password to your account has changed.");
// Confirmed from the callback: off-loop the write has not landed yet here.
PasswordWorker.SetPassword(
acct,
pass,
_ => from.SendMessage("The password to your account has changed.")
);
}
else
{
@ -307,25 +315,129 @@ public static class AccountHandler
logger.Information("Login: {NetState} Access denied for '{Username}'", e.State, un);
e.RejectReason = LockdownLevel > AccessLevel.Player ? ALRReason.BadComm : ALRReason.BadPass;
}
else if (!acct.CheckPassword(pw))
else
{
logger.Information("Login: {NetState} Invalid password for '{Username}'", e.State, un);
e.RejectReason = ALRReason.BadPass;
HandlePasswordCheck(e, acct, pw);
}
else if (acct.Banned)
}
/// <summary>
/// Separate from the caller's else-if chain because two outcomes are not verdicts: the off-loop
/// path has none yet, and a full queue must reject rather than fall through and verify.
/// </summary>
private static void HandlePasswordCheck(AccountLoginEventArgs e, Account acct, string pw)
{
switch (DispatchPasswordCheck(e, acct, pw))
{
logger.Information("Login: {NetState} Banned account '{Username}'", e.State, un);
case PasswordCheckDispatch.Deferred:
{
e.Deferred = true;
return;
}
case PasswordCheckDispatch.Saturated:
{
// Reject rather than verify inline: steering work back onto the loop is what a
// flood wants.
logger.Warning(
"Login: {NetState} Password verification queue full, rejecting '{Username}'",
e.State,
acct.Username
);
e.RejectReason = ALRReason.BadComm;
return;
}
}
if (!acct.CheckPassword(pw))
{
logger.Information("Login: {NetState} Invalid password for '{Username}'", e.State, acct.Username);
e.RejectReason = ALRReason.BadPass;
return;
}
ApplyVerifiedLogin(e, acct);
}
/// <summary>Everything after the password is known good, shared so an off-loop verdict lands
/// in the same state as an inline one.</summary>
private static void ApplyVerifiedLogin(AccountLoginEventArgs e, Account acct)
{
if (acct.Banned)
{
logger.Information("Login: {NetState} Banned account '{Username}'", e.State, acct.Username);
e.RejectReason = ALRReason.Blocked;
return;
}
logger.Information("Login: {NetState} Valid credentials for '{Username}'", e.State, acct.Username);
e.State.Account = acct;
e.Accepted = true;
acct.LogAccess(e.State);
LoginAllowlist.RecordLogin(e.State?.Address);
}
private enum PasswordCheckDispatch
{
/// <summary>Verify on the loop.</summary>
Inline,
/// <summary>Handed to the worker; no verdict yet.</summary>
Deferred,
/// <summary>The queue is full.</summary>
Saturated
}
/// <summary>
/// Hands the password check to the worker, whatever algorithm it uses. Every protection is safe
/// off the loop, so there is no carve-out, and a cheap digest does not need one either:
/// <c>AccountSecurity.Configure</c> refuses anything below SHA2 as the configured algorithm, so
/// MD5 and SHA1 only appear as a stored hash awaiting migration. That makes
/// <c>NeedsPasswordUpgrade</c> true, and the upgrade hash dominates the job.
/// </summary>
private static PasswordCheckDispatch DispatchPasswordCheck(AccountLoginEventArgs e, Account acct, string pw)
{
if (!PasswordWorker.Enabled)
{
return PasswordCheckDispatch.Inline;
}
var job = new PasswordJob
{
Account = acct,
State = e.State,
StoredHash = acct.Password,
StoredAlgorithm = acct.PasswordAlgorithm,
VerifyPhrase = acct.GetVerifyPhrase(pw),
HashPhrase = acct.NeedsPasswordUpgrade() ? acct.GetRehashPhrase(pw) : null,
TargetAlgorithm = AccountSecurity.CurrentAlgorithm,
OnComplete = static (j, outcome) =>
CompleteDeferredAccountLogin(j.State, j.Account, outcome.Verified)
};
return PasswordWorker.TryEnqueue(job)
? PasswordCheckDispatch.Deferred
: PasswordCheckDispatch.Saturated;
}
/// <summary>Resumes a login whose password check ran on the verification thread.</summary>
internal static void CompleteDeferredAccountLogin(NetState state, Account acct, bool verified)
{
var e = new AccountLoginEventArgs(state, acct.Username, null);
if (verified)
{
ApplyVerifiedLogin(e, acct);
}
else
{
logger.Information("Login: {NetState} Valid credentials for '{Username}'", e.State, un);
e.State.Account = acct;
e.Accepted = true;
acct.LogAccess(e.State);
LoginAllowlist.RecordLogin(e.State?.Address);
logger.Information("Login: {NetState} Invalid password for '{Username}'", state, acct.Username);
e.RejectReason = ALRReason.BadPass;
}
IncomingAccountPackets.CompleteAccountLogin(state, e.Accepted, e.RejectReason);
}
[OnEvent(nameof(GameServer.GameServerLoginEvent))]
@ -343,7 +455,9 @@ public static class AccountHandler
logger.Information("Login: {NetState} Access denied for '{Username}'", e.State, un);
e.Accepted = false;
}
else if (!acct.CheckPassword(pw))
// The auth id was only issued after the account login packet verified this password, so
// re-deriving the hash costs a second Argon2 verify to answer the same question.
else if (!e.PreAuthenticated && !acct.CheckPassword(pw))
{
logger.Information("Login: {NetState} Invalid password for '{Username}'", e.State, un);
e.Accepted = false;

View file

@ -4,5 +4,12 @@ namespace Server.Accounting
{
string EncryptPassword(string plainPassword);
bool ValidatePassword(string encryptedPassword, string plainPassword);
/// <summary>
/// True when <paramref name="encryptedPassword"/> was produced with parameters that differ
/// from the ones this protection currently uses, so a successful login should rewrite it.
/// Algorithms whose cost is not embedded in the stored value never need this.
/// </summary>
bool NeedsRehash(string encryptedPassword) => false;
}
}

View file

@ -51,6 +51,17 @@ public static class AccountSecurity
}
}
/// <summary>
/// The string actually fed to the KDF. SHA1 and SHA2 salt by username; everything else hashes
/// the password alone. Verification must derive with the algorithm the stored hash was made
/// with, and a rehash with the one it is moving to -- deriving with the wrong one produces a
/// hash that verifies once and never again.
/// </summary>
public static string DerivePhrase(PasswordProtectionAlgorithm algorithm, string username, string plainPassword)
=> algorithm is PasswordProtectionAlgorithm.SHA1 or PasswordProtectionAlgorithm.SHA2
? $"{username}{plainPassword}"
: plainPassword;
public static IPasswordProtection GetPasswordProtection(PasswordProtectionAlgorithm algorithm)
{
var passwordProtection = algorithm switch

View file

@ -21,11 +21,37 @@ public class Argon2PasswordProtection : IPasswordProtection
{
public static IPasswordProtection Instance = new Argon2PasswordProtection();
private readonly Argon2PasswordHasher m_PasswordHasher = new(rng: RandomNumberGenerator.Create());
// 16 MiB at t=1 is cheaper than 8 MiB at t=3 (8.5 ms vs 10.1 ms) and twice as memory-hard, which
// is what resists GPU and ASIC cracking. p=1: native argon2 spawns a thread per lane.
private readonly Argon2PasswordHasher _passwordHasher = new(
time: 1,
memory: 16384,
parallel: 1,
type: Argon2Type.Argon2id,
rng: RandomNumberGenerator.Create()
);
public string EncryptPassword(string plainPassword) =>
m_PasswordHasher.Hash(plainPassword);
_passwordHasher.Hash(plainPassword);
public bool ValidatePassword(string encryptedPassword, string plainPassword) =>
m_PasswordHasher.Verify(encryptedPassword, plainPassword);
_passwordHasher.Verify(encryptedPassword, plainPassword);
// Verification uses the parameters embedded in the PHC string, not the configured ones, so
// comparing them is what lets a parameter change reach existing accounts.
public bool NeedsRehash(string encryptedPassword)
{
// Unparseable but verified: a format this build does not understand, so rewrite it.
if (!Argon2PasswordHasher.TryExtractMetadataValues(encryptedPassword, out var values))
{
return true;
}
return values.ArgonType != _passwordHasher.ArgonType
|| values.MemoryCost != _passwordHasher.MemoryCost
|| values.TimeCost != _passwordHasher.TimeCost
|| values.Parallelism != _passwordHasher.Parallelism
|| values.HashLength != (int)_passwordHasher.HashLength
|| values.SaltLength != (int)_passwordHasher.SaltLength;
}
}

View file

@ -19,19 +19,47 @@ using Server.Text;
namespace Server.Accounting.Security;
/// <summary>
/// The obsolete unsalted digests, kept only so imported accounts can log in once and be upgraded.
///
/// Hashing goes through the one-shot static APIs rather than a retained <see cref="HashAlgorithm"/>.
/// A <see cref="HashAlgorithm"/> instance carries the running digest across HashCore/HashFinal, so
/// two threads sharing one corrupt each other's result -- and these are process-wide singletons.
/// The static form has no such state, allocates nothing, and produces identical bytes.
/// </summary>
public class HashAlgorithmPasswordProtection : IPasswordProtection
{
public static IPasswordProtection MD5Instance = new HashAlgorithmPasswordProtection(MD5.Create());
public static IPasswordProtection SHA1Instance = new HashAlgorithmPasswordProtection(SHA1.Create());
public static IPasswordProtection SHA2Instance = new HashAlgorithmPasswordProtection(SHA512.Create());
private readonly HashAlgorithm _hashAlgorithm;
private enum Kind
{
MD5,
SHA1,
SHA512
}
public HashAlgorithmPasswordProtection(HashAlgorithm hashAlgorithm) => _hashAlgorithm = hashAlgorithm;
public static readonly IPasswordProtection MD5Instance = new HashAlgorithmPasswordProtection(Kind.MD5);
public static readonly IPasswordProtection SHA1Instance = new HashAlgorithmPasswordProtection(Kind.SHA1);
public static readonly IPasswordProtection SHA2Instance = new HashAlgorithmPasswordProtection(Kind.SHA512);
private const int MaxDigestLength = 64; // SHA512, the largest of the three.
private readonly Kind _kind;
private HashAlgorithmPasswordProtection(Kind kind) => _kind = kind;
public string EncryptPassword(string plainPassword)
{
var bytes = plainPassword.AsSpan(0, Math.Min(256, plainPassword.Length)).GetBytesAscii();
return _hashAlgorithm.ComputeHash(bytes).ToHexString();
Span<byte> digest = stackalloc byte[MaxDigestLength];
var written = _kind switch
{
Kind.MD5 => MD5.HashData(bytes, digest),
Kind.SHA1 => SHA1.HashData(bytes, digest),
_ => SHA512.HashData(bytes, digest)
};
return digest[..written].ToHexString();
}
public bool ValidatePassword(string encryptedPassword, string plainPassword) =>

View file

@ -22,23 +22,24 @@ namespace Server.Accounting.Security;
public class PBKDF2PasswordProtection : IPasswordProtection
{
private const ushort m_MinIterations = 1024;
private const ushort m_MaxIterations = 1536;
private const int m_SaltSize = 8;
private const int m_HashSize = 32;
private const int m_OutputSize = 2 + m_SaltSize + m_HashSize;
private const ushort MinIterations = 1024;
private const ushort MaxIterations = 1536;
private const int SaltSize = 8;
private const int HashSize = 32;
private const int OutputSize = 2 + SaltSize + HashSize;
public static readonly IPasswordProtection Instance = new PBKDF2PasswordProtection();
public string EncryptPassword(string plainPassword)
{
Span<byte> output = stackalloc byte[m_OutputSize];
var iterations = Utility.RandomMinMax(m_MinIterations, m_MaxIterations);
Span<byte> output = stackalloc byte[OutputSize];
var iterations = RandomNumberGenerator.GetInt32(MinIterations, MaxIterations + 1);
BinaryPrimitives.WriteUInt16LittleEndian(output[..2], (ushort)iterations);
var salt = output.Slice(2, m_SaltSize);
var salt = output.Slice(2, SaltSize);
RandomNumberGenerator.Fill(salt);
var hash = output.Slice(2 + m_SaltSize, m_HashSize);
var hash = output.Slice(2 + SaltSize, HashSize);
Rfc2898DeriveBytes.Pbkdf2(plainPassword, salt, hash, iterations, HashAlgorithmName.SHA256);
return output.ToHexString();
@ -46,15 +47,15 @@ public class PBKDF2PasswordProtection : IPasswordProtection
public bool ValidatePassword(string encryptedPassword, string plainPassword)
{
Span<byte> encryptedBytes = stackalloc byte[m_OutputSize];
Span<byte> encryptedBytes = stackalloc byte[OutputSize];
encryptedPassword.GetBytes(encryptedBytes);
var iterations = BinaryPrimitives.ReadUInt16LittleEndian(encryptedBytes[..2]);
var salt = encryptedBytes.Slice(2, m_SaltSize);
var salt = encryptedBytes.Slice(2, SaltSize);
Span<byte> hash = stackalloc byte[m_HashSize];
Span<byte> hash = stackalloc byte[HashSize];
Rfc2898DeriveBytes.Pbkdf2(plainPassword, salt, hash, iterations, HashAlgorithmName.SHA256);
return hash.SequenceEqual(encryptedBytes[(m_SaltSize + 2)..]);
return hash.SequenceEqual(encryptedBytes[(SaltSize + 2)..]);
}
}

View file

@ -0,0 +1,293 @@
/*************************************************************************
* ModernUO *
* Copyright 2019-2026 - ModernUO Development Team *
* Email: hi@modernuo.com *
* File: PasswordWorker.cs *
* *
* This program is free software: you can redistribute it and/or modify *
* it under the terms of the GNU General Public License as published by *
* the Free Software Foundation, either version 3 of the License, or *
* (at your option) any later version. *
* *
* You should have received a copy of the GNU General Public License *
* along with this program. If not, see <http://www.gnu.org/licenses/>. *
*************************************************************************/
using System;
using System.Collections.Concurrent;
using System.Threading;
using Server.Logging;
using Server.Network;
namespace Server.Accounting.Security;
/// <summary>
/// Work handed to the password thread, which reads no game state and writes none.
///
/// Verify and hash are independently optional: a login verifies and may rehash, an explicit change
/// only hashes.
/// </summary>
internal sealed class PasswordJob
{
public Account Account;
/// <summary>Ties the job to a connection. Null when the work is not gated on one, such as a
/// password change by an admin.</summary>
public NetState State;
/// <summary>Hash to verify against, with <see cref="VerifyPhrase"/>.</summary>
public string StoredHash;
/// <summary>Algorithm <see cref="StoredHash"/> was written with. Both algorithms are resolved on
/// the loop; <c>AccountSecurity.CurrentAlgorithm</c> is mutable state the worker must not read.</summary>
public PasswordProtectionAlgorithm StoredAlgorithm;
/// <summary>Phrase to verify, or null to skip verification.</summary>
public string VerifyPhrase;
/// <summary>Phrase to hash, or null when nothing needs writing.</summary>
public string HashPhrase;
public PasswordProtectionAlgorithm TargetAlgorithm;
/// <summary>Runs on the game loop with the result. Free to touch game state.</summary>
public Action<PasswordJob, PasswordOutcome> OnComplete;
}
internal readonly struct PasswordOutcome
{
/// <summary>True when no verification was asked for, or it succeeded.</summary>
public readonly bool Verified;
/// <summary>The derived hash, or null when nothing was hashed or verification failed.</summary>
public readonly string Hash;
public PasswordOutcome(bool verified, string hash)
{
Verified = verified;
Hash = hash;
}
}
/// <summary>
/// Runs password hashing off the game loop. An Argon2 verify costs ~8.9 ms of frozen world per
/// login attempt, successful or not.
///
/// Exactly one worker, and that is load-bearing three times over. It cannot cost the loop more than
/// an inline verify under any scheduling regime, because at worst it takes an equal share of one
/// core -- which is what lets the measurement hold on hardware we cannot inspect. It caps live
/// hashing arenas at one. And writes apply in dispatch order only because a single thread drains
/// FIFO, so a second would need ordering reintroduced.
///
/// ~110 verifies/sec, which is ample: only loop time matters, not login latency.
/// </summary>
internal sealed class PasswordWorker
{
private static readonly ILogger logger = LogFactory.GetLogger(typeof(PasswordWorker));
/// <summary>
/// Backstop, not a flood defense. <c>SentFirstPacket</c> holds a connection to one pending
/// verify and the engine caps connections at 4096 (<c>NetState.Network.cs</c>), so this matches
/// that bound and can only trip if that invariant breaks. A cap low enough to blunt an attack
/// would reject real players first; flood defense belongs at the connection layer.
/// </summary>
private const int MaxPending = 4096;
// Nothing signals the worker when a save freeze ends, so it re-checks on this interval -- but
// only while a save is in progress, never in steady state.
private const int SaveGatePollMs = 50;
private static PasswordWorker _instance;
// Needs a spare core to move work to, which a 1-2 core host does not have. Off in DEBUG, where
// logins are rare and the inline path is easier to follow.
internal static readonly bool Enabled =
#if DEBUG
false;
#else
Environment.ProcessorCount >= 4;
#endif
private readonly Thread _thread;
private readonly AutoResetEvent _work = new(false);
private readonly ConcurrentQueue<PasswordJob> _queue = [];
private int _pending;
private volatile bool _exit;
private PasswordWorker()
{
_thread = new Thread(Execute)
{
IsBackground = true,
Name = "Password Worker"
};
_thread.Start();
}
private static PasswordWorker Instance => _instance ??= new PasswordWorker();
/// <summary>Queues a job. False when full, and the caller must then reject without verifying.</summary>
internal static bool TryEnqueue(PasswordJob job) => Instance.TryEnqueueCore(job);
private bool TryEnqueueCore(PasswordJob job)
{
if (Volatile.Read(ref _pending) >= MaxPending)
{
return false;
}
Interlocked.Increment(ref _pending);
_queue.Enqueue(job);
_work.Set();
return true;
}
/// <summary>
/// Checked before each job, which bounds a save overlap to whichever hash was already running:
/// the freeze holds the loop, so nothing new can be queued during it. PendingSave counts too --
/// the serialization threads are already awake and spinning on an empty queue by then.
/// </summary>
private static bool CanRunNow() => World.WorldState is WorldState.Running or WorldState.WritingSave;
private void Execute()
{
while (!_exit)
{
if (_queue.IsEmpty)
{
// A kernel block at zero CPU. Set() during a hash leaves the event signalled, so a
// wake arriving mid-job is not lost.
_work.WaitOne();
continue;
}
if (!CanRunNow())
{
_work.WaitOne(SaveGatePollMs);
continue;
}
if (!_queue.TryDequeue(out var job))
{
continue;
}
Interlocked.Decrement(ref _pending);
// Gone while it waited: skip it rather than hash for a verdict nobody receives. Running
// only goes true -> false, so a stale read wastes a hash but never skips a live one. A
// null State is a job with no connection to lose, and still runs.
if (job.State?.Running == false)
{
continue;
}
PasswordOutcome outcome;
try
{
outcome = Compute(job);
}
catch (Exception ex)
{
// A verdict must still come back, or the connection never gets a reply.
logger.Error(ex, "Password work failed for {Username}", job.Account?.Username);
outcome = new PasswordOutcome(false, null);
}
Core.LoopContext.Post(() => Apply(job, outcome));
}
}
private static PasswordOutcome Compute(PasswordJob job)
{
if (job.VerifyPhrase != null &&
!AccountSecurity.GetPasswordProtection(job.StoredAlgorithm)
.ValidatePassword(job.StoredHash, job.VerifyPhrase))
{
return new PasswordOutcome(false, null);
}
return new PasswordOutcome(
true,
job.HashPhrase == null
? null : AccountSecurity.GetPasswordProtection(job.TargetAlgorithm).EncryptPassword(job.HashPhrase)
);
}
private static void Apply(PasswordJob job, PasswordOutcome outcome)
{
// Re-checked: a connection can drop while the result sits in the loop queue.
if (job.State?.Running == false)
{
return;
}
if (outcome.Verified && outcome.Hash != null)
{
job.Account.ApplyPasswordWrite(outcome.Hash, job.TargetAlgorithm);
}
job.OnComplete?.Invoke(job, outcome);
}
/// <summary>
/// Sets a password, off the loop where available and inline otherwise, invoking
/// <paramref name="onDone"/> on the loop either way.
///
/// Confirm from <paramref name="onDone"/>, not the call site: off-loop the write has not
/// happened when this returns.
/// </summary>
internal static void SetPassword(Account account, string plainPassword, Action<bool> onDone)
{
if (!Enabled)
{
account.SetPassword(plainPassword);
onDone?.Invoke(true);
return;
}
var job = new PasswordJob
{
Account = account,
HashPhrase = account.GetRehashPhrase(plainPassword),
TargetAlgorithm = AccountSecurity.CurrentAlgorithm,
OnComplete = (_, outcome) => onDone?.Invoke(outcome.Hash != null)
};
if (!TryEnqueue(job))
{
// Saturated. Unlike a login, a password change must not be dropped, so it pays the
// hash on the loop instead.
account.SetPassword(plainPassword);
onDone?.Invoke(true);
}
}
/// <summary>Runs a job on the calling thread. The seam the tests drive.</summary>
internal static PasswordOutcome ComputeInline(PasswordJob job) => Compute(job);
/// <summary>
/// Stops the worker on shutdown or crash. Pending jobs are dropped rather than finished:
/// nothing saves the world after this point, so a write applied here would reach no disk.
///
/// Draining the loop context is not this type's business either. That belongs in the core
/// shutdown path, before subscriber events run -- a subscriber pumping the shared context would
/// execute other subscribers' work at an arbitrary point in the event order.
/// </summary>
internal static void Stop() => _instance?.StopThread();
// HandleClosed skips InvokeShutdown when the server crashed, so the crash path needs its own
// subscription.
internal static void OnCrashed(ServerCrashedEventArgs e) => Stop();
private void StopThread()
{
_exit = true;
_work.Set();
_thread.Join(TimeSpan.FromSeconds(5));
}
}

View file

@ -0,0 +1,117 @@
#if EVENT_LOOP_PROFILING
using System;
using System.Globalization;
using System.IO;
using Server.Logging;
namespace Server.Commands;
/// <summary>
/// Reports the event-loop time decomposition recorded by <see cref="EventLoopProfiler"/>.
/// Only compiled when the server is built with -p:EventLoopProfiling=true.
/// See dev-docs/debugging-event-loop.md for how to read the output.
/// </summary>
public static class LoopStats
{
private static readonly ILogger logger = LogFactory.GetLogger(typeof(LoopStats));
public static void Configure()
{
CommandSystem.Register("LoopStats", AccessLevel.Administrator, LoopStats_OnCommand);
}
[Usage("LoopStats")]
[Description("Summarizes the last minute of event-loop time accounting and writes the full history to a CSV.")]
private static void LoopStats_OnCommand(CommandEventArgs e)
{
var history = EventLoopProfiler.History();
if (history.Length == 0)
{
e.Mobile.SendMessage("No samples recorded yet.");
return;
}
var window = Math.Min(60, history.Length);
double wall = 0, sleep = 0, gc = 0, stolen = 0, stolenMax = 0;
long iterations = 0, sleeps = 0, lateWakes = 0, wheelLagMax = 0;
Span<double> phases = stackalloc double[EventLoopProfiler.PhaseCount];
Span<double> phaseMax = stackalloc double[EventLoopProfiler.PhaseCount];
for (var i = history.Length - window; i < history.Length; i++)
{
ref var s = ref history[i];
wall += s.WallMs;
sleep += s.SleepMs;
gc += s.GcPauseMs;
stolen += s.StolenMs;
iterations += s.Iterations;
sleeps += s.Sleeps;
lateWakes += s.LateWakes;
if (s.StolenMs > stolenMax)
{
stolenMax = s.StolenMs;
}
if (s.WheelLagMaxMs > wheelLagMax)
{
wheelLagMax = s.WheelLagMaxMs;
}
for (var p = 0; p < EventLoopProfiler.PhaseCount; p++)
{
phases[p] += s.Phases[p];
if (s.Phases[p] > phaseMax[p])
{
phaseMax[p] = s.Phases[p];
}
}
}
e.Mobile.SendMessage($"Loop, last {window}s of wall time {wall:F0}ms:");
e.Mobile.SendMessage($" sleep {100 * sleep / wall:F1}%, gc {100 * gc / wall:F1}%, stolen {100 * stolen / wall:F1}% (worst {stolenMax:F0}ms/s)");
for (var p = 0; p < EventLoopProfiler.PhaseCount; p++)
{
e.Mobile.SendMessage($" {(LoopPhase)p}: {100 * phases[p] / wall:F1}% (worst {phaseMax[p]:F0}ms/s)");
}
e.Mobile.SendMessage($" {iterations} iterations, {sleeps} sleeps, {lateWakes} late wakes, worst wheel lag {wheelLagMax}ms");
var path = Path.Combine(Core.BaseDirectory, $"loopstats-{Core.Now:yyyyMMdd-HHmmss}.csv");
WriteCsv(path, history);
e.Mobile.SendMessage($"Full history ({history.Length} samples) written to {path}");
logger.Information("Loop stats dumped to {Path}", path);
}
private static void WriteCsv(string path, EventLoopProfiler.Sample[] history)
{
using var writer = new StreamWriter(path);
writer.Write("wallStart,wallMs,iterations,sleeps,sleepMs,sleepOvershootMaxMs,lateWakes,wheelLagMaxMs,wakesIssued,wakesElided,gcPauseMs,gen0,gen1,gen2,stolenMs");
for (var p = 0; p < EventLoopProfiler.PhaseCount; p++)
{
writer.Write(',');
writer.Write((LoopPhase)p);
}
writer.WriteLine();
for (var i = 0; i < history.Length; i++)
{
ref var s = ref history[i];
writer.Write(string.Create(
CultureInfo.InvariantCulture,
$"{s.WallStart},{s.WallMs},{s.Iterations},{s.Sleeps},{s.SleepMs:F2},{s.SleepOvershootMaxMs:F2},{s.LateWakes},{s.WheelLagMaxMs},{s.WakesIssued},{s.WakesElided},{s.GcPauseMs:F2},{s.Gen0},{s.Gen1},{s.Gen2},{s.StolenMs:F2}"
));
for (var p = 0; p < EventLoopProfiler.PhaseCount; p++)
{
writer.Write(',');
writer.Write(string.Create(CultureInfo.InvariantCulture, $"{s.Phases[p]:F2}"));
}
writer.WriteLine();
}
}
}
#endif

View file

@ -103,9 +103,8 @@ namespace Server.Commands
{
var list = pm.VisibilityList;
if (list.Contains(targ))
if (list.Remove(targ))
{
list.Remove(targ);
pm.SendMessage($"{targ.Name} has been removed from your visibility list.");
}
else

View file

@ -1,6 +1,5 @@
using System;
using System.Buffers;
using System.Collections.Generic;
using System.Globalization;
using System.Numerics;
using System.Runtime.CompilerServices;

View file

@ -6,27 +6,27 @@ namespace Server.Engines.BulkOrders;
public partial class BOBFilter
{
[SerializableField(0)]
[SaveFlag(nameof(ShouldSerializeType))]
private int _type;
[SerializableFieldSaveFlag(0)]
private bool ShouldSerializeType() => _type != 0;
[SerializableField(1)]
[SaveFlag(nameof(ShouldSerializeQuality))]
private int _quality;
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializeQuality() => _quality != 0;
[SerializableField(2)]
[SaveFlag(nameof(ShouldSerializeMaterial))]
private int _material;
[SerializableFieldSaveFlag(2)]
private bool ShouldSerializeMaterial() => _material != 0;
[SerializableField(3)]
[SaveFlag(nameof(ShouldSerializeQuantity))]
private int _quantity;
[SerializableFieldSaveFlag(3)]
private bool ShouldSerializeQuantity() => _quantity != 0;
private void Deserialize(IGenericReader reader, int version)

View file

@ -33,17 +33,13 @@ public partial class ChampionSkullBrazier : AddonComponent
[SerializedCommandProperty(AccessLevel.GameMaster)]
private ChampionSkullPlatform _platform;
[SerializableProperty(2)]
[CommandProperty(AccessLevel.GameMaster)]
public Item Skull
[SerializableField(2, fieldChanged: nameof(OnSkullChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private Item _skull;
private void OnSkullChanged(Item oldValue, Item newValue)
{
get => _skull;
set
{
_skull = value;
this.MarkDirty();
_platform?.Validate();
}
_platform?.Validate();
}
public override int LabelNumber => 1049489 + (int)_type;

View file

@ -27,16 +27,44 @@ using Server.Logging;
namespace Server.Engines.CannedEvil;
[SerializationGenerator(10, false)]
[SerializationGenerator(11, false)]
public partial class ChampionSpawn : Item
{
private void MigrateFrom(V10Content content)
{
_level = content.Level;
_activatedByProximity = content.ActivatedByProximity;
_nextProximityTime = content.NextProximityTime;
_maxLevel = content.MaxLevel;
_activatedByValor = content.ActivatedByValor;
_damageEntries = content.DamageEntries;
_confinedRoaming = content.ConfinedRoaming;
_idol = content.Idol;
_hasBeenAdvanced = content.HasBeenAdvanced;
_spawnArea = content.SpawnArea;
_randomizeType = content.RandomizeType;
_kills = content.Kills;
_active = content.Active;
_type = content.Type;
_creatures = content.Creatures;
_redSkulls = content.RedSkulls;
_whiteSkulls = content.WhiteSkulls;
_platform = content.Platform;
_altar = content.Altar;
_expireDelay = content.ExpireDelay;
_expireTime = content.ExpireTime;
_champion = content.Champion;
_restartDelay = content.RestartDelay;
_restartTime = content.RestartTime;
}
private static readonly ILogger logger = LogFactory.GetLogger(typeof(ChampionSpawn));
[SerializableField(1)]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private bool _activatedByProximity;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(2)]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private DateTime _nextProximityTime;
@ -96,7 +124,7 @@ public partial class ChampionSpawn : Item
[SerializedCommandProperty(AccessLevel.GameMaster)]
private TimeSpan _expireDelay;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(20)]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private DateTime _expireTime;
@ -109,7 +137,7 @@ public partial class ChampionSpawn : Item
[SerializedCommandProperty(AccessLevel.GameMaster)]
private TimeSpan _restartDelay;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(23, setter: "private")]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private DateTime _restartTime;
@ -203,47 +231,38 @@ public partial class ChampionSpawn : Item
}
}
[SerializableProperty(3)]
[CommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
public int MaxLevel
[SerializableField(3, allowFieldChange: nameof(AllowMaxLevelChange))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private int _maxLevel;
private bool AllowMaxLevelChange(ref int value)
{
get => _maxLevel;
set => _maxLevel = Math.Clamp(value, 0, 18);
value = Math.Clamp(value, 0, 18);
return true;
}
[SerializableProperty(9)]
[CommandProperty(AccessLevel.GameMaster)]
public Rectangle2D SpawnArea
[SerializableField(9, fieldChanged: nameof(OnSpawnAreaChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
[InvalidateProperties]
private Rectangle2D _spawnArea;
private void OnSpawnAreaChanged(Rectangle2D oldValue, Rectangle2D newValue)
{
get => _spawnArea;
set
{
_spawnArea = value;
this.MarkDirty();
InvalidateProperties();
UpdateRegion();
}
UpdateRegion();
}
[SerializableProperty(11)]
[CommandProperty(AccessLevel.GameMaster)]
public int Kills
[SerializableField(11, fieldChanged: nameof(OnKillsChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
[InvalidateProperties]
private int _kills;
private void OnKillsChanged(int oldValue, int newValue)
{
get => _kills;
set
var n = _kills / (double)MaxKills;
var p = (int)(n * 100);
if (p < 90)
{
_kills = value;
this.MarkDirty();
var n = _kills / (double)MaxKills;
var p = (int)(n * 100);
if (p < 90)
{
SetWhiteSkullCount(p / 20);
}
InvalidateProperties();
SetWhiteSkullCount(p / 20);
}
}

View file

@ -51,9 +51,9 @@ public partial class ChampionTitleContext
}
[SerializableField(1)]
[SaveFlag(nameof(ShouldSerializeAbyss))]
private ChampionTitle _abyss;
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializeAbyss() => _abyss != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -71,9 +71,9 @@ public partial class ChampionTitleContext
}
[SerializableField(2)]
[SaveFlag(nameof(ShouldSerializeArachnid))]
private ChampionTitle _arachnid;
[SerializableFieldSaveFlag(2)]
private bool ShouldSerializeArachnid() => _arachnid != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -91,9 +91,9 @@ public partial class ChampionTitleContext
}
[SerializableField(3)]
[SaveFlag(nameof(ShouldSerializeColdBlood))]
private ChampionTitle _coldBlood;
[SerializableFieldSaveFlag(3)]
private bool ShouldSerializeColdBlood() => _coldBlood != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -111,9 +111,9 @@ public partial class ChampionTitleContext
}
[SerializableField(4)]
[SaveFlag(nameof(ShouldSerializeForestLord))]
private ChampionTitle _forestLord;
[SerializableFieldSaveFlag(4)]
private bool ShouldSerializeForestLord() => _forestLord != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -131,9 +131,9 @@ public partial class ChampionTitleContext
}
[SerializableField(5)]
[SaveFlag(nameof(ShouldSerializeVerminHorde))]
private ChampionTitle _verminHorde;
[SerializableFieldSaveFlag(5)]
private bool ShouldSerializeVerminHorde() => _verminHorde != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -151,9 +151,9 @@ public partial class ChampionTitleContext
}
[SerializableField(6)]
[SaveFlag(nameof(ShouldSerializeUnholyTerror))]
private ChampionTitle _unholyTerror;
[SerializableFieldSaveFlag(6)]
private bool ShouldSerializeUnholyTerror() => _unholyTerror != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -171,9 +171,9 @@ public partial class ChampionTitleContext
}
[SerializableField(7)]
[SaveFlag(nameof(ShouldSerializeSleepingDragon))]
private ChampionTitle _sleepingDragon;
[SerializableFieldSaveFlag(7)]
private bool ShouldSerializeSleepingDragon() => _sleepingDragon != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -191,9 +191,9 @@ public partial class ChampionTitleContext
}
[SerializableField(8)]
[SaveFlag(nameof(ShouldSerializeCorrupt))]
private ChampionTitle _corrupt;
[SerializableFieldSaveFlag(8)]
private bool ShouldSerializeCorrupt() => _corrupt != null;
[CommandProperty(AccessLevel.GameMaster)]
@ -211,9 +211,9 @@ public partial class ChampionTitleContext
}
[SerializableField(9)]
[SaveFlag(nameof(ShouldSerializeGlade))]
private ChampionTitle _glade;
[SerializableFieldSaveFlag(9)]
private bool ShouldSerializeGlade() => _glade != null;
[CommandProperty(AccessLevel.GameMaster)]

View file

@ -167,20 +167,13 @@ public class ChampionTitleSystem : GenericPersistence
return;
}
using var queue = PooledRefQueue<Mobile>.Create();
foreach (var context in _championTitleContexts.Values)
{
if (!context.CheckAtrophy())
{
queue.Enqueue(context.Player);
_championTitleContexts.Remove(context.Player);
}
}
while (queue.Count > 0)
{
_championTitleContexts.Remove((PlayerMobile)queue.Dequeue());
}
}
}
}

View file

@ -3,15 +3,21 @@ using ModernUO.Serialization;
namespace Server.Items;
[SerializationGenerator(1, false)]
[SerializationGenerator(2, false)]
public partial class StarRoomGate : Moongate
{
private void MigrateFrom(V1Content content)
{
_decays = content.Decays;
_decayTime = content.DecayTime;
}
private static TimeSpan GateDuration = TimeSpan.FromMinutes(2.0);
[SerializableField(0)]
private bool _decays;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(1)]
private DateTime _decayTime;

View file

@ -146,15 +146,8 @@ namespace Server.Engines.Chat
m_Users.Remove(user);
user.CurrentChannel = null;
if (m_Moderators.Contains(user))
{
m_Moderators.Remove(user);
}
if (m_Voices.Contains(user))
{
m_Voices.Remove(user);
}
m_Moderators.Remove(user);
m_Voices.Remove(user);
SendCommand(ChatCommand.RemoveUserFromChannel, user, user.Username);
ChatSystem.SendCommandTo(user.Mobile, ChatCommand.LeaveChannel);
@ -183,10 +176,7 @@ namespace Server.Engines.Chat
public void RemoveBan(ChatUser user)
{
if (m_Banned.Contains(user))
{
m_Banned.Remove(user);
}
m_Banned.Remove(user);
}
public void Kick(ChatUser user, ChatUser moderator = null)

View file

@ -716,10 +716,7 @@ public partial class BRBomb : Item
m.Target = new BombTarget(this, m);
if (m_Helpers.Contains(m))
{
m_Helpers.Remove(m);
}
m_Helpers.Remove(m);
if (m_Helpers.Count > 0)
{
@ -833,10 +830,9 @@ public partial class BRBomb : Item
[SerializationGenerator(0, false)]
public partial class BRGoal : BaseAddon
{
[SerializableField(0)]
[SerializableField(0, fieldChanged: nameof(OnNorthChanged))]
private bool _north;
[SerializableFieldChanged(0)]
[MethodImpl(MethodImplOptions.AggressiveInlining)]
private void OnNorthChanged(bool oldValue, bool newValue) => Remake();

View file

@ -252,10 +252,9 @@ public partial class HillOfTheKing : Item
public partial class KHBoard : Item
{
[SerializedCommandProperty(AccessLevel.GameMaster)]
[SerializableField(0)]
[SerializableField(0, fieldChanged: nameof(OnControllerChanged))]
private KHController _controller;
[SerializableFieldChanged(0)]
private void OnControllerChanged(KHController oldValue, KHController newValue)
{
oldValue?.RemoveBoard(this);

View file

@ -56,12 +56,11 @@ namespace Server.Engines.ConPVP
public void RemoveFlavor(Ruleset flavor)
{
if (!Flavors.Contains(flavor))
if (!Flavors.Remove(flavor))
{
return;
}
Flavors.Remove(flavor);
Options.And(flavor.Options.Not());
flavor.Options.Not();
}

View file

@ -64,17 +64,13 @@ public partial class Trophy : Item
UpdateStyle();
}
[SerializableProperty(1)]
[CommandProperty(AccessLevel.GameMaster)]
public TrophyRank Rank
[SerializableField(1, fieldChanged: nameof(OnRankChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private TrophyRank _rank;
private void OnRankChanged(TrophyRank oldValue, TrophyRank newValue)
{
get => _rank;
set
{
_rank = value;
UpdateStyle();
this.MarkDirty();
}
UpdateStyle();
}
private void Deserialize(IGenericReader reader, int version)

View file

@ -1451,6 +1451,9 @@ namespace Server.Engines.Craft
if (item != null)
{
// Stamped here, not in OnCraft: most craftables do not implement ICraftable.
item.PlayerConstructed = true;
if (item is ICraftable craftable)
{
endquality = craftable.OnCraft(quality, makersMark, from, craftSystem, typeRes, tool, this, resHue);
@ -1742,6 +1745,9 @@ namespace Server.Engines.Craft
if (item != null)
{
// Stamped here, not in OnCraft: most craftables do not implement ICraftable.
item.PlayerConstructed = true;
if (item is ICraftable craftable)
{
endquality = craftable.OnCraft(quality, makersMark, from, craftSystem, typeRes, tool, this, resHue);

View file

@ -5,9 +5,20 @@ using Server.Mobiles;
namespace Server.Ethics;
[PropertyObject]
[SerializationGenerator(1)]
[SerializationGenerator(2)]
public partial class Player : EthicsEntity
{
private void MigrateFrom(V1Content content)
{
_mobile = content.Mobile;
_power = content.Power;
_history = content.History;
_steed = content.Steed;
_familiar = content.Familiar;
_shield = content.Shield;
_ethic = content.Ethic;
}
[SerializableField(0, setter: "private")]
private Mobile _mobile;
@ -27,7 +38,7 @@ public partial class Player : EthicsEntity
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private Mobile _familiar;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(5, setter: "private")]
private DateTime _shield;

View file

@ -162,10 +162,15 @@ namespace Server.Items
}
}
[SerializationGenerator(0)]
[SerializationGenerator(1)]
public partial class PuzzleChestSolutionAndTime : PuzzleChestSolution
{
[DeltaDateTime]
private void MigrateFrom(V0Content content)
{
_when = content.When;
}
[AnchoredDateTime]
[SerializableField(0)]
private DateTime _when;
@ -237,16 +242,12 @@ namespace Server.Items
}
}
[SerializableProperty(0)]
public PuzzleChestSolution Solution
[SerializableField(0, fieldChanged: nameof(OnSolutionChanged))]
private PuzzleChestSolution _solution;
private void OnSolutionChanged(PuzzleChestSolution oldValue, PuzzleChestSolution newValue)
{
get => _solution;
set
{
_solution = value;
InitHints();
this.MarkDirty();
}
InitHints();
}
public PuzzleChestCylinder FirstHint
@ -550,21 +551,14 @@ namespace Server.Items
return;
}
using var toDelete = PooledRefQueue<Mobile>.Create();
foreach (var (key, value) in _guesses)
{
if (Core.Now - value.When > CleanupTime)
{
toDelete.Enqueue(key);
_guesses.Remove(key);
}
}
while (toDelete.Count > 0)
{
_guesses.Remove(toDelete.Dequeue());
}
if (_guesses.Count == 0)
{
_guesses = null;

View file

@ -116,10 +116,9 @@ namespace Server.Engines.MLQuests.Gumps
private static void CloseCurrent(NetState ns)
{
if (m_Pending.TryGetValue(ns, out var state))
if (m_Pending.Remove(ns, out var state))
{
state._timeoutToken.Cancel();
m_Pending.Remove(ns);
}
ns.SendCloseRaceChanger();

View file

@ -19,7 +19,7 @@ namespace Server.Engines.MLQuests
{
base.Serialize(writer);
writer.Write(2); // version
writer.Write(3); // version
writer.Write(MLQuestSystem.Contexts.Count);
foreach (var context in MLQuestSystem.Contexts.Values)

View file

@ -119,7 +119,7 @@ namespace Server.Engines.MLQuests.Objectives
if (IsTimed)
{
writer.Write(true);
writer.WriteDeltaTime(EndTime);
writer.WriteAnchoredTime(EndTime);
}
else
{
@ -135,7 +135,7 @@ namespace Server.Engines.MLQuests.Objectives
{
if (reader.ReadBool())
{
var endTime = reader.ReadDeltaTime();
var endTime = version >= 3 ? reader.ReadAnchoredTime() : reader.ReadDeltaTime();
if (objInstance != null)
{

View file

@ -727,20 +727,14 @@ public sealed class StepCache
var window = MissPromotionWindowMs;
var beforeCount = _chunkMissTracker.Count;
using var toRemove = PooledRefQueue<long>.Create();
foreach (var kvp in _chunkMissTracker)
{
if (now - kvp.Value.LastMissTickStamp > window)
{
toRemove.Enqueue(kvp.Key);
_chunkMissTracker.Remove(kvp.Key);
}
}
while (toRemove.Count > 0)
{
_chunkMissTracker.Remove(toRemove.Dequeue());
}
if (_chunkMissTracker.Count == beforeCount)
{
_chunkMissTracker.Clear();

View file

@ -1,7 +1,5 @@
using System;
using System.Diagnostics;
using Server.Engines.Pathing;
using Server.Engines.Pathing.Cache;
using Server.Items;
using Server.PathAlgorithms;
using Server.Spells;

View file

@ -37,17 +37,17 @@ public partial class PlantItem : Item, ISecurable
[SerializedIgnoreDupe]
[SerializableField(0)]
[SaveFlag(nameof(ShouldSerializeSecureLevel))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private SecureLevel _level;
[SerializableFieldSaveFlag(0)]
private bool ShouldSerializeSecureLevel() => (int)_level != 0;
[SerializedIgnoreDupe]
[SerializableField(5, setter: "private")]
[SaveFlag(nameof(ShouldSerializePlantSystem))]
private PlantSystem _plantSystem;
[SerializableFieldSaveFlag(5)]
private bool ShouldSerializePlantSystem() => _plantStatus < PlantStatus.DecorativePlant;
// For clients older than 7.0.12.0
@ -82,6 +82,7 @@ public partial class PlantItem : Item, ISecurable
[CommandProperty(AccessLevel.GameMaster)]
[SerializableProperty(1)]
[SaveFlag(nameof(ShouldSerializePlantStatus))]
public PlantStatus PlantStatus
{
get => _plantStatus;
@ -120,53 +121,38 @@ public partial class PlantItem : Item, ISecurable
}
}
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializePlantStatus() => _plantStatus != PlantStatus.BowlOfDirt;
[SerializableProperty(2)]
[CommandProperty(AccessLevel.GameMaster)]
public PlantType PlantType
[SerializableField(2, fieldChanged: nameof(OnPlantTypeChanged))]
[SaveFlag(nameof(ShouldSerializePlantType))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private PlantType _plantType;
private void OnPlantTypeChanged(PlantType oldValue, PlantType newValue)
{
get => _plantType;
set
{
_plantType = value;
Update();
}
Update();
}
[SerializableFieldSaveFlag(2)]
private bool ShouldSerializePlantType() => (int)_plantType != 0;
[SerializableProperty(3)]
[CommandProperty(AccessLevel.GameMaster)]
public PlantHue PlantHue
[SerializableField(3, fieldChanged: nameof(OnPlantHueChanged))]
[SaveFlag(nameof(ShouldSerializePlantHue))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private PlantHue _plantHue;
private void OnPlantHueChanged(PlantHue oldValue, PlantHue newValue)
{
get => _plantHue;
set
{
_plantHue = value;
Update();
}
Update();
}
[SerializableFieldSaveFlag(3)]
private bool ShouldSerializePlantHue() => _plantHue != PlantHue.None;
[SerializableProperty(4)]
[CommandProperty(AccessLevel.GameMaster)]
public bool ShowType
{
get => _showType;
set
{
_showType = value;
InvalidateProperties();
this.MarkDirty();
}
}
[SerializableField(4)]
[SaveFlag(nameof(ShouldSerializeShowType))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
[InvalidateProperties]
private bool _showType;
[SerializableFieldSaveFlag(4)]
private bool ShouldSerializeShowType() => _showType;
[CommandProperty(AccessLevel.GameMaster)]

View file

@ -33,24 +33,24 @@ namespace Server.Engines.Plants
private PlantItem _plant;
[SerializableField(0)]
[SaveFlag(nameof(ShouldSerializeFertileDirt))]
private bool _fertileDirt;
[SerializableFieldSaveFlag(0)]
private bool ShouldSerializeFertileDirt() => _fertileDirt;
[SerializableField(1)]
private DateTime _nextGrowth;
[SerializableField(2, setter: "private")]
[SaveFlag(nameof(ShouldSerializeGrowthIndicator))]
private PlantGrowthIndicator _growthIndicator;
[SerializableFieldSaveFlag(2)]
private bool ShouldSerializeGrowthIndicator() => _growthIndicator != PlantGrowthIndicator.None;
[SerializableField(13)]
[SaveFlag(nameof(ShouldSerializePollinated))]
private bool _pollinated;
[SerializableFieldSaveFlag(13)]
private bool ShouldSerializePollinated() => _pollinated;
public PlantSystem(PlantItem plant)
@ -97,45 +97,42 @@ namespace Server.Engines.Plants
public bool IsFullWater => _water >= 4;
[SerializableProperty(3)]
public int Water
[SerializableField(3, fieldChanged: nameof(OnWaterChanged), allowFieldChange: nameof(AllowWaterChange))]
[SaveFlag(nameof(ShouldSerializeWater))]
private int _water;
private bool AllowWaterChange(ref int value)
{
get => _water;
set
{
_water = Math.Clamp(value, 0, 4);
Plant.InvalidateProperties();
MarkDirty();
}
value = Math.Clamp(value, 0, 4);
return true;
}
private void OnWaterChanged(int oldValue, int newValue)
{
Plant.InvalidateProperties();
}
[SerializableFieldSaveFlag(3)]
private bool ShouldSerializeWater() => _water != 0;
[SerializableProperty(4)]
public int Hits
[SerializableField(4, fieldChanged: nameof(OnHitsChanged), allowFieldChange: nameof(AllowHitsChange))]
[SaveFlag(nameof(ShouldSerializeHits))]
private int _hits;
private bool AllowHitsChange(ref int value)
{
get => _hits;
set
{
if (_hits == value)
{
return;
}
_hits = Math.Clamp(value, 0, MaxHits);
if (_hits == 0)
{
Plant.Die();
}
Plant.InvalidateProperties();
MarkDirty();
}
value = Math.Clamp(value, 0, MaxHits);
return true;
}
private void OnHitsChanged(int oldValue, int newValue)
{
if (_hits == 0)
{
Plant.Die();
}
Plant.InvalidateProperties();
}
[SerializableFieldSaveFlag(4)]
private bool ShouldSerializeHits() => _hits != 0;
public int MaxHits => 10 + (int)Plant.PlantStatus * 2;
@ -149,124 +146,108 @@ namespace Server.Engines.Plants
_ => PlantHealth.Vibrant
};
[SerializableProperty(5)]
public int Infestation
[SerializableField(5, allowFieldChange: nameof(AllowInfestationChange))]
[SaveFlag(nameof(ShouldSerializeInfestation))]
private int _infestation;
private bool AllowInfestationChange(ref int value)
{
get => _infestation;
set
{
_infestation = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(5)]
private bool ShouldSerializeInfestation() => _infestation != 0;
[SerializableProperty(6)]
public int Fungus
[SerializableField(6, allowFieldChange: nameof(AllowFungusChange))]
[SaveFlag(nameof(ShouldSerializeFungus))]
private int _fungus;
private bool AllowFungusChange(ref int value)
{
get => _fungus;
set
{
_fungus = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(6)]
private bool ShouldSerializeFungus() => _fungus != 0;
[SerializableProperty(7)]
public int Poison
[SerializableField(7, allowFieldChange: nameof(AllowPoisonChange))]
[SaveFlag(nameof(ShouldSerializePoison))]
private int _poison;
private bool AllowPoisonChange(ref int value)
{
get => _poison;
set
{
_poison = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(7)]
private bool ShouldSerializePoison() => _poison != 0;
[SerializableProperty(8)]
public int Disease
[SerializableField(8, allowFieldChange: nameof(AllowDiseaseChange))]
[SaveFlag(nameof(ShouldSerializeDisease))]
private int _disease;
private bool AllowDiseaseChange(ref int value)
{
get => _disease;
set
{
_disease = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(8)]
private bool ShouldSerializeDisease() => _disease != 0;
public bool IsFullPoisonPotion => _poisonPotion >= 2;
[SerializableProperty(9)]
public int PoisonPotion
[SerializableField(9, allowFieldChange: nameof(AllowPoisonPotionChange))]
[SaveFlag(nameof(ShouldSerializePoisonPotion))]
private int _poisonPotion;
private bool AllowPoisonPotionChange(ref int value)
{
get => _poisonPotion;
set
{
_poisonPotion = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(9)]
private bool ShouldSerializePoisonPotion() => _poisonPotion != 0;
public bool IsFullCurePotion => _curePotion >= 2;
[SerializableProperty(10)]
public int CurePotion
[SerializableField(10, allowFieldChange: nameof(AllowCurePotionChange))]
[SaveFlag(nameof(ShouldSerializeCurePotion))]
private int _curePotion;
private bool AllowCurePotionChange(ref int value)
{
get => _curePotion;
set
{
_curePotion = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(10)]
private bool ShouldSerializeCurePotion() => _curePotion != 0;
public bool IsFullHealPotion => _healPotion >= 2;
[SerializableProperty(11)]
public int HealPotion
[SerializableField(11, allowFieldChange: nameof(AllowHealPotionChange))]
[SaveFlag(nameof(ShouldSerializeHealPotion))]
private int _healPotion;
private bool AllowHealPotionChange(ref int value)
{
get => _healPotion;
set
{
_healPotion = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(11)]
private bool ShouldSerializeHealPotion() => _healPotion != 0;
public bool IsFullStrengthPotion => _strengthPotion >= 2;
[SerializableProperty(12)]
public int StrengthPotion
[SerializableField(12, allowFieldChange: nameof(AllowStrengthPotionChange))]
[SaveFlag(nameof(ShouldSerializeStrengthPotion))]
private int _strengthPotion;
private bool AllowStrengthPotionChange(ref int value)
{
get => _strengthPotion;
set
{
_strengthPotion = Math.Clamp(value, 0, 2);
MarkDirty();
}
value = Math.Clamp(value, 0, 2);
return true;
}
[SerializableFieldSaveFlag(12)]
private bool ShouldSerializeStrengthPotion() => _strengthPotion != 0;
public bool HasMaladies => Infestation > 0 || Fungus > 0 || Poison > 0 || Disease > 0 || Water != 2;
@ -274,6 +255,7 @@ namespace Server.Engines.Plants
public bool PollenProducing => Plant.IsCrossable && Plant.PlantStatus >= PlantStatus.FullGrownPlant;
[SerializableProperty(14)]
[SaveFlag(nameof(ShouldSerializeSeedType))]
public PlantType SeedType
{
get => Pollinated ? _seedType : Plant.PlantType;
@ -284,10 +266,10 @@ namespace Server.Engines.Plants
}
}
[SerializableFieldSaveFlag(14)]
private bool ShouldSerializeSeedType() => _pollinated;
[SerializableProperty(15)]
[SaveFlag(nameof(ShouldSerializeSeedHue))]
public PlantHue SeedHue
{
get => Pollinated ? _seedHue : Plant.PlantHue;
@ -298,53 +280,58 @@ namespace Server.Engines.Plants
}
}
[SerializableFieldSaveFlag(15)]
private bool ShouldSerializeSeedHue() => _pollinated;
[SerializableProperty(16)]
public int AvailableSeeds
[SerializableField(16, allowFieldChange: nameof(AllowAvailableSeedsChange))]
[SaveFlag(nameof(ShouldSerializeAvailableSeeds))]
private int _availableSeeds;
private bool AllowAvailableSeedsChange(ref int value)
{
get => _availableSeeds;
set => _availableSeeds = Math.Max(value, 0);
value = Math.Max(value, 0);
return true;
}
[SerializableFieldSaveFlag(16)]
private bool ShouldSerializeAvailableSeeds() => _availableSeeds != 0;
[SerializableProperty(17)]
public int LeftSeeds
[SerializableField(17, allowFieldChange: nameof(AllowLeftSeedsChange))]
[SaveFlag(nameof(ShouldSerializeLeftSeeds), nameof(LeftSeedsDefaultValue))]
private int _leftSeeds;
private bool AllowLeftSeedsChange(ref int value)
{
get => _leftSeeds;
set => _leftSeeds = Math.Max(value, 0);
value = Math.Max(value, 0);
return true;
}
[SerializableFieldSaveFlag(17)]
private bool ShouldSerializeLeftSeeds() => _leftSeeds != 8;
[SerializableFieldDefault(17)]
private int LeftSeedsDefaultValue() => 8;
[SerializableProperty(18)]
public int AvailableResources
[SerializableField(18, allowFieldChange: nameof(AllowAvailableResourcesChange))]
[SaveFlag(nameof(ShouldSerializeAvailableResources))]
private int _availableResources;
private bool AllowAvailableResourcesChange(ref int value)
{
get => _availableResources;
set => _availableResources = Math.Max(value, 0);
value = Math.Max(value, 0);
return true;
}
[SerializableFieldSaveFlag(18)]
private bool ShouldSerializeAvailableResources() => _availableResources != 0;
[SerializableProperty(19)]
public int LeftResources
[SerializableField(19, allowFieldChange: nameof(AllowLeftResourcesChange))]
[SaveFlag(nameof(ShouldSerializeLeftResources), nameof(LeftResourcesDefaultValue))]
private int _leftResources;
private bool AllowLeftResourcesChange(ref int value)
{
get => _leftResources;
set => _leftResources = Math.Max(value, 0);
value = Math.Max(value, 0);
return true;
}
[SerializableFieldSaveFlag(19)]
private bool ShouldSerializeLeftResources() => _leftResources != 8;
[SerializableFieldDefault(19)]
private int LeftResourcesDefaultValue() => 8;
public void Reset(bool potions)

View file

@ -35,18 +35,14 @@ public partial class Seed : Item
public override double DefaultWeight => 1.0;
[CommandProperty(AccessLevel.GameMaster)]
[SerializableProperty(1)]
public PlantHue PlantHue
[SerializableField(1, fieldChanged: nameof(OnPlantHueChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
[InvalidateProperties]
private PlantHue _plantHue;
private void OnPlantHueChanged(PlantHue oldValue, PlantHue newValue)
{
get => _plantHue;
set
{
_plantHue = value;
Hue = PlantHueInfo.GetInfo(value).Hue;
InvalidateProperties();
this.MarkDirty();
}
Hue = PlantHueInfo.GetInfo(newValue).Hue;
}
public override int LabelNumber => 1060810; // seed

View file

@ -16,12 +16,14 @@ public partial class MurderContext
[SerializedCommandProperty(AccessLevel.GameMaster)]
private TimeSpan _longTermElapse;
[SerializableProperty(2)]
[CommandProperty(AccessLevel.GameMaster)]
public int ShortTermMurders
[SerializableField(2, allowFieldChange: nameof(AllowShortTermMurdersChange))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private int _shortTermMurders;
private bool AllowShortTermMurdersChange(ref int value)
{
get => _shortTermMurders;
set => _shortTermMurders = Math.Max(value, 0);
value = Math.Max(value, 0);
return true;
}
[SerializableField(3)]

View file

@ -403,27 +403,20 @@ public class PlayerMurderSystem : GenericPersistence
return;
}
using var queue = PooledRefQueue<Mobile>.Create();
foreach (var context in _contextTerms)
{
context.DecayKills();
if (!context.CheckStart())
{
queue.Enqueue(context.Player);
}
}
while (queue.Count > 0)
{
var pm = (PlayerMobile)queue.Dequeue();
if (_murderContexts.TryGetValue(pm, out var ctx))
{
if (ctx.CanRemove())
var pm = context.Player;
if (_murderContexts.TryGetValue(pm, out var ctx))
{
_murderContexts.Remove(pm);
if (ctx.CanRemove())
{
_murderContexts.Remove(pm);
}
_contextTerms.Remove(ctx);
}
_contextTerms.Remove(ctx);
}
}
}

View file

@ -12,16 +12,12 @@ public partial class SummoningAltar : AbbatoirAddon
{
}
[SerializableProperty(0)]
public BoneDemon Daemon
[SerializableField(0, fieldChanged: nameof(OnDaemonChanged))]
private BoneDemon _daemon;
private void OnDaemonChanged(BoneDemon oldValue, BoneDemon newValue)
{
get => _daemon;
set
{
_daemon = value;
CheckDaemon();
this.MarkDirty();
}
CheckDaemon();
}
public void CheckDaemon()

View file

@ -54,10 +54,10 @@ public abstract partial class BaseSpawner : Item, ISpawner
[SerializedCommandProperty(AccessLevel.Developer)]
private Guid _guid;
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializeReturnOnDeactivate() => _returnOnDeactivate;
[SerializableField(1)]
[SaveFlag(nameof(ShouldSerializeReturnOnDeactivate))]
[SerializedCommandProperty(AccessLevel.Developer)]
private bool _returnOnDeactivate;
@ -67,48 +67,46 @@ public abstract partial class BaseSpawner : Item, ISpawner
private int _walkingRange = -1;
[SerializableFieldSaveFlag(4)]
private bool ShouldSerializeWayPoint() => _wayPoint != null;
[SerializableField(4)]
[SaveFlag(nameof(ShouldSerializeWayPoint))]
[SerializedCommandProperty(AccessLevel.Developer)]
private WayPoint _wayPoint;
[SerializableFieldSaveFlag(5)]
private bool ShouldSerializeGroup() => _group;
[InvalidateProperties]
[SerializableField(5)]
[SaveFlag(nameof(ShouldSerializeGroup))]
[SerializedCommandProperty(AccessLevel.Developer)]
private bool _group;
[SerializableFieldSaveFlag(6)]
private bool ShouldSerializeMinDelay() => _minDelay != DefaultMinDelay;
[SerializableFieldDefault(6)]
private TimeSpan MinDelayDefault() => DefaultMinDelay;
[InvalidateProperties]
[SerializableField(6)]
[SaveFlag(nameof(ShouldSerializeMinDelay), nameof(MinDelayDefault))]
[SerializedCommandProperty(AccessLevel.Developer)]
private TimeSpan _minDelay;
[SerializableFieldSaveFlag(7)]
private bool ShouldSerializeMaxDelay() => _maxDelay != DefaultMaxDelay;
[SerializableFieldDefault(7)]
private TimeSpan MaxDelayDefault() => DefaultMaxDelay;
[InvalidateProperties]
[SerializableField(7)]
[SaveFlag(nameof(ShouldSerializeMaxDelay), nameof(MaxDelayDefault))]
[SerializedCommandProperty(AccessLevel.Developer)]
private TimeSpan _maxDelay;
[SerializableFieldSaveFlag(9)]
private bool ShouldSerializeTeam() => _team != 0;
[InvalidateProperties]
[SerializableField(9)]
[SaveFlag(nameof(ShouldSerializeTeam))]
[SerializedCommandProperty(AccessLevel.Developer)]
private int _team;
@ -125,29 +123,29 @@ public abstract partial class BaseSpawner : Item, ISpawner
/// If true, the home location of the spawn is the location where it spawned
/// If false, the home location of the spawn is the location of the spawner
/// </summary>
[SerializableFieldSaveFlag(11)]
private bool ShouldSerializeSpawnLocationIsHome() => _spawnLocationIsHome;
[InvalidateProperties]
[SerializableField(11)]
[SaveFlag(nameof(ShouldSerializeSpawnLocationIsHome))]
[SerializedCommandProperty(AccessLevel.Developer)]
private bool _spawnLocationIsHome;
[SerializableFieldSaveFlag(12)]
private bool ShouldSerializeEnd() => _end != default;
[SerializableField(12)]
[SaveFlag(nameof(ShouldSerializeEnd))]
[SerializedCommandProperty(AccessLevel.Developer)]
private DateTime _end;
/// <summary>
/// Controls how spawn position optimization is handled.
/// </summary>
[SerializableFieldSaveFlag(13)]
private bool ShouldSerializeSpawnPositionMode() =>
_spawnPositionMode is not SpawnPositionMode.Automatic and not SpawnPositionMode.Abandoned;
[SerializableField(13)]
[SaveFlag(nameof(ShouldSerializeSpawnPositionMode))]
[SerializedCommandProperty(AccessLevel.Developer)]
private SpawnPositionMode _spawnPositionMode;
@ -156,13 +154,12 @@ public abstract partial class BaseSpawner : Item, ISpawner
/// <summary>
/// Maximum number of random position attempts before engaging optimization.
/// </summary>
[SerializableFieldSaveFlag(14)]
private bool ShouldSerializeMaxSpawnAttempts() => _maxSpawnAttempts != DefaultMaxSpawnAttempts;
[SerializableFieldDefault(14)]
private int MaxSpawnAttemptsDefault() => DefaultMaxSpawnAttempts;
[SerializableField(14)]
[SaveFlag(nameof(ShouldSerializeMaxSpawnAttempts), nameof(MaxSpawnAttemptsDefault))]
[SerializedCommandProperty(AccessLevel.Developer)]
private int _maxSpawnAttempts;
@ -314,26 +311,20 @@ public abstract partial class BaseSpawner : Item, ISpawner
}
}
[SerializableProperty(8)]
[CommandProperty(AccessLevel.Developer)]
public int Count
[SerializableField(8, fieldChanged: nameof(OnCountChanged))]
[SerializedCommandProperty(AccessLevel.Developer)]
[InvalidateProperties]
private int _count;
private void OnCountChanged(int oldValue, int newValue)
{
get => _count;
set
if (IsFull)
{
_count = value;
if (IsFull)
{
_timer?.Stop();
}
else if (_timer?.Running != true)
{
DoTimer();
}
InvalidateProperties();
this.MarkDirty();
_timer?.Stop();
}
else if (_timer?.Running != true)
{
DoTimer();
}
}

View file

@ -10,17 +10,17 @@ public partial class Spawner : BaseSpawner
/// When true, enables proactive spiral scanning to find valid spawn positions.
/// Only relevant when SpawnPositionMode is Automatic or Enabled.
/// </summary>
[SerializableFieldSaveFlag(0)]
private bool ShouldSerializeUseSpiralScan() => _useSpiralScan;
[SerializableField(0)]
[SaveFlag(nameof(ShouldSerializeUseSpiralScan))]
[SerializedCommandProperty(AccessLevel.Developer)]
private bool _useSpiralScan;
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializeSpawnBounds() => _spawnBounds != default;
[SerializableProperty(1)]
[SaveFlag(nameof(ShouldSerializeSpawnBounds))]
[CommandProperty(AccessLevel.Developer)]
public override Rectangle3D SpawnBounds
{

View file

@ -248,7 +248,7 @@ public class StealableArtifacts : GenericPersistence
public override void Serialize(IGenericWriter writer)
{
writer.WriteEncodedInt(1); // version
writer.WriteEncodedInt(2); // version
writer.Write(_enabled);
@ -261,7 +261,7 @@ public class StealableArtifacts : GenericPersistence
var si = _artifacts[i];
writer.Write(si.Item);
writer.WriteDeltaTime(si.NextRespawn);
writer.WriteAnchoredTime(si.NextRespawn);
}
}
}
@ -282,7 +282,7 @@ public class StealableArtifacts : GenericPersistence
for (var i = 0; i < length; i++)
{
var item = reader.ReadEntity<Item>();
var nextRespawn = reader.ReadDeltaTime();
var nextRespawn = version >= 2 ? reader.ReadAnchoredTime() : reader.ReadDeltaTime();
if (i < _artifacts.Length)
{

View file

@ -332,27 +332,22 @@ public partial class PigmentsOfTokuno : BasePigmentsOfTokuno
[Constructible]
public PigmentsOfTokuno(PigmentType type, int uses) : base(uses) => Type = type;
[SerializableProperty(0)]
[CommandProperty(AccessLevel.GameMaster)]
public PigmentType Type
[SerializableField(0, fieldChanged: nameof(OnTypeChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private PigmentType _type;
private void OnTypeChanged(PigmentType oldValue, PigmentType newValue)
{
get => _type;
set
var v = (int)_type;
if (v >= 0 && v < _table.Length)
{
_type = value;
var v = (int)_type;
if (v >= 0 && v < _table.Length)
{
Hue = _table[v][0];
Label = _table[v][1];
}
else
{
Hue = 0;
Label = -1;
}
Hue = _table[v][0];
Label = _table[v][1];
}
else
{
Hue = 0;
Label = -1;
}
}

View file

@ -617,27 +617,22 @@ public partial class LesserPigmentsOfTokuno : BasePigmentsOfTokuno
[Constructible]
public LesserPigmentsOfTokuno(LesserPigmentType type) : base(1) => Type = type;
[SerializableProperty(0)]
[CommandProperty(AccessLevel.GameMaster)]
public LesserPigmentType Type
[SerializableField(0, fieldChanged: nameof(OnTypeChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private LesserPigmentType _type;
private void OnTypeChanged(LesserPigmentType oldValue, LesserPigmentType newValue)
{
get => _type;
set
var v = (int)_type;
if (v >= 0 && v < _table.Length)
{
_type = value;
var v = (int)_type;
if (v >= 0 && v < _table.Length)
{
Hue = _table[v][0];
Label = _table[v][1];
}
else
{
Hue = 0;
Label = -1;
}
Hue = _table[v][0];
Label = _table[v][1];
}
else
{
Hue = 0;
Label = -1;
}
}

View file

@ -79,45 +79,33 @@ public partial class CharacterStatue : Mobile, IRewardItem
InvalidateHues();
}
[SerializableProperty(0)]
[CommandProperty(AccessLevel.GameMaster)]
public StatueType StatueType
[SerializableField(0, fieldChanged: nameof(OnStatueTypeChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private StatueType _statueType;
private void OnStatueTypeChanged(StatueType oldValue, StatueType newValue)
{
get => _statueType;
set
{
_statueType = value;
InvalidateHues();
InvalidatePose();
this.MarkDirty();
}
InvalidateHues();
InvalidatePose();
}
[SerializableProperty(1)]
[CommandProperty(AccessLevel.GameMaster)]
public StatuePose Pose
[SerializableField(1, fieldChanged: nameof(OnPoseChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private StatuePose _pose;
private void OnPoseChanged(StatuePose oldValue, StatuePose newValue)
{
get => _pose;
set
{
_pose = value;
InvalidatePose();
this.MarkDirty();
}
InvalidatePose();
}
[SerializableProperty(2)]
[CommandProperty(AccessLevel.GameMaster)]
public StatueMaterial Material
[SerializableField(2, fieldChanged: nameof(OnMaterialChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private StatueMaterial _material;
private void OnMaterialChanged(StatueMaterial oldValue, StatueMaterial newValue)
{
get => _material;
set
{
_material = value;
InvalidateHues();
InvalidatePose();
this.MarkDirty();
}
InvalidateHues();
InvalidatePose();
}
public override void OnDoubleClick(Mobile from)

View file

@ -25,17 +25,13 @@ public partial class CharacterStatueMaker : Item, IRewardItem
public override int LabelNumber => 1076173; // Character Statue Maker
[SerializableProperty(1)]
[CommandProperty(AccessLevel.GameMaster)]
public StatueType StatueType
[SerializableField(1, fieldChanged: nameof(OnStatueTypeChanged))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private StatueType _statueType;
private void OnStatueTypeChanged(StatueType oldValue, StatueType newValue)
{
get => _statueType;
set
{
_statueType = value;
InvalidateHue();
this.MarkDirty();
}
InvalidateHue();
}
public override void OnDoubleClick(Mobile from)

View file

@ -5,102 +5,121 @@ using Server.Mobiles;
namespace Server.Engines.Virtues;
[PropertyObject]
[SerializationGenerator(0)]
[SerializationGenerator(1)]
public partial class VirtueContext
{
[DeltaDateTime]
private void MigrateFrom(V0Content content)
{
// Save-flagged values arrive as nullables; unset flags fall back to the same
// defaults the old deserialize left in place.
_lastSacrificeGain = content.LastSacrificeGain ?? default;
_lastSacrificeLoss = content.LastSacrificeLoss ?? default;
_availableResurrects = content.AvailableResurrects ?? 0;
_lastJusticeLoss = content.LastJusticeLoss ?? default;
_lastCompassionLoss = content.LastCompassionLoss ?? default;
_nextCompassionDay = content.NextCompassionDay ?? default;
_compassionGains = content.CompassionGains ?? 0;
_lastValorLoss = content.LastValorLoss ?? default;
_lastHonorUse = content.LastHonorUse ?? default;
_honorActive = content.HonorActive;
_justiceProtection = content.JusticeProtection;
_justiceStatus = content.JusticeStatus ?? JusticeProtectorStatus.None;
_values = content.Values;
}
[AnchoredDateTime]
[SerializableField(0)]
[SaveFlag(nameof(ShouldSerializeLastSacrificeGain))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private DateTime _lastSacrificeGain;
[SerializableFieldSaveFlag(0)]
private bool ShouldSerializeLastSacrificeGain() => !SacrificeVirtue.CanGain(this);
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(1)]
[SaveFlag(nameof(ShouldSerializeLastSacrificeLoss))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private DateTime _lastSacrificeLoss;
[SerializableFieldSaveFlag(1)]
private bool ShouldSerializeLastSacrificeLoss() => !SacrificeVirtue.CanAtrophy(this);
[SerializableField(2)]
[SaveFlag(nameof(ShouldSerializeAvailableResurrects))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private int _availableResurrects;
[SerializableFieldSaveFlag(2)]
private bool ShouldSerializeAvailableResurrects() => _availableResurrects > 0;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(3)]
[SaveFlag(nameof(ShouldSerializeLastJusticeLoss))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private DateTime _lastJusticeLoss;
[SerializableFieldSaveFlag(3)]
private bool ShouldSerializeLastJusticeLoss() => !JusticeVirtue.CanAtrophy(this);
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(4)]
[SaveFlag(nameof(ShouldSerializeLastCompassionLoss))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private DateTime _lastCompassionLoss;
[SerializableFieldSaveFlag(4)]
private bool ShouldSerializeLastCompassionLoss() => !CompassionVirtue.CanAtrophy(this);
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(5)]
[SaveFlag(nameof(ShouldSerializeNextCompassionDay))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private DateTime _nextCompassionDay;
[SerializableFieldSaveFlag(5)]
private bool ShouldSerializeNextCompassionDay() => _nextCompassionDay > Core.Now;
[SerializableField(6)]
[SaveFlag(nameof(ShouldSerializeCompassionGains))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private int _compassionGains;
[SerializableFieldSaveFlag(6)]
private bool ShouldSerializeCompassionGains() => _compassionGains > 0;
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(7)]
[SaveFlag(nameof(ShouldSerializeValorLoss))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private DateTime _lastValorLoss;
[SerializableFieldSaveFlag(7)]
private bool ShouldSerializeValorLoss() => !ValorVirtue.CanAtrophy(this);
[DeltaDateTime]
[AnchoredDateTime]
[SerializableField(8)]
[SaveFlag(nameof(ShouldSerializeLastHonorUse))]
[SerializedCommandProperty(AccessLevel.GameMaster)]
private DateTime _lastHonorUse;
[SerializableFieldSaveFlag(8)]
private bool ShouldSerializeLastHonorUse() => !HonorVirtue.CanUse(this);
[SerializableField(9)]
[SaveFlag(nameof(ShouldSerializeHonorActive))]
[SerializedCommandProperty(AccessLevel.GameMaster, AccessLevel.Administrator)]
private bool _honorActive;
[SerializableFieldSaveFlag(9)]
private bool ShouldSerializeHonorActive() => _honorActive;
[SerializableField(10)]
[SaveFlag(nameof(ShouldSerializeJusticeProtection))]
private PlayerMobile _justiceProtection;
[SerializableFieldSaveFlag(10)]
private bool ShouldSerializeJusticeProtection() => _justiceProtection != null && _justiceStatus != JusticeProtectorStatus.None;
[SerializableField(11)]
[SaveFlag(nameof(ShouldSerializeJusticeStatus))]
private JusticeProtectorStatus _justiceStatus;
[SerializableFieldSaveFlag(11)]
private bool ShouldSerializeJusticeStatus() => _justiceProtection != null && _justiceStatus != JusticeProtectorStatus.None;
[SerializableField(12, setter: "private")]
[SaveFlag(nameof(ShouldSerializeValues))]
private int[] _values;
[SerializableFieldSaveFlag(12)]
private bool ShouldSerializeValues()
{
if (_values == null)

Some files were not shown because too many files have changed in this diff Show more