Implement Scheduler: stage execution, conflict batching, debug enforcement

Schedule gains real execution on top of the registration bookkeeping
from the PluginHost pass: RunStage(stage, world) runs every system
registered for a stage, and Reads<>/Writes<>() declarations are
enforced live via SystemAccessScope — a system touching a component it
didn't declare throws immediately, with a message naming the
violation, from GameWorld.Query<T>() and GameObject.GetComponent<T>()/
AddComponent<T>()/RemoveComponent<T>(). Outside of a running system
(editor code, tests, scene construction) nothing is enforced.

Scope cut made deliberately, not by accident: systems are grouped into
conflict-free batches by declared access (ComputeBatches, tested
directly), but batches run sequentially rather than on real threads.
Actually parallelizing them needs GameWorld's structural changes
(Create/Destroy/AddComponent/RemoveComponent) deferred to a command
buffer first — without that, two systems with disjoint *declared*
types can still race on shared storage, since AddComponent<T>() on a
GameObject mutates that object's own component list regardless of T.
Building real concurrency on top of a known thread-safety hole would
be worse than not building it yet. Noted as a TODO on RunStage.

Two real bugs found and fixed while wiring this up, not designed in
from the start:

- ISchedule.Add took `Delegate`, and a lambda passed there doesn't
  reliably compile down to `Action<IWorld>` at runtime — the
  compiler's natural-type inference for lambdas (as opposed to method
  groups, which do work this way) can synthesize a different, private
  delegate type instead, so `is Action<IWorld>` silently failed for
  every lambda-registered system. Changed Add's parameter type to
  Action<IWorld> directly, which sidesteps the inference question
  entirely — found by ScheduleTests actually using lambdas, which
  EchoPlugin's method-group-based Tick had been masking.
- AlcUnloadTests started failing intermittently ("ALC survived unload
  cycle 3") once PluginSystemTests existed alongside it — xUnit
  parallelizes across test classes by default, and ALC-unload tests
  are sensitive to any concurrent activity in the process. Added
  [CollectionBehavior(DisableTestParallelization = true)] to the
  harness assembly; stable across 5+ repeated runs since.

EchoPlugin.Tick is no longer a stub — it increments every Ping.Count
in World, which two new integration tests in
Engine.ConformanceHarness/PluginSystemTests.cs exercise end to end: a
plugin loaded from a real collectible ALC registers a system, Schedule
actually invokes that cross-ALC delegate, and it correctly mutates a
component owned by the Default-ALC World. This only works because
PluginLoadContext resolves Sandbox.Echo.Contracts to the copy this
test project references directly, rather than loading a second,
type-incompatible one — the harness's new normal ProjectReference to
Sandbox.Echo.Contracts.csproj makes that a live assertion, not just an
implementation detail no test would notice breaking.

27 tests total now (21 in Engine.Kernel.Tests, 6 in
Engine.ConformanceHarness), all green on a clean build, harness
verified stable across repeated runs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N1qPfzq8TDCUMFMV3UwV5N
This commit is contained in:
Emil
2026-09-02 00:59:02 +03:00
co-authored by Claude Sonnet 5
parent 978f34727f
commit 17f66c4de5
11 changed files with 376 additions and 16 deletions
+16
View File
@@ -1,4 +1,5 @@
using System.Numerics;
using Engine.Kernel.Scheduling;
namespace Engine.Kernel.World;
@@ -77,6 +78,8 @@ public sealed class GameObject
public T? GetComponent<T>() where T : Component
{
SystemAccessScope.CheckRead(typeof(T));
foreach (var component in _components)
{
if (component is T match)
@@ -86,8 +89,19 @@ public sealed class GameObject
return null;
}
/// <summary>
/// Adding a component requires <c>Writes&lt;T&gt;()</c> — checked here,
/// at the structural change. What isn't and can't be checked: mutating
/// a component's own fields after the fact, e.g.
/// <c>go.GetComponent&lt;T&gt;()!.Value = 5</c>. That's a plain field
/// write on a plain object, with nothing to intercept it — see
/// docs/kernel-contract.md §7's note on why components stay plain
/// classes rather than something that could enforce this fully.
/// </summary>
public T AddComponent<T>() where T : Component, new()
{
SystemAccessScope.CheckWrite(typeof(T));
var component = new T();
_components.Add(component);
Owner?.IndexComponentAdded(this, component);
@@ -96,6 +110,8 @@ public sealed class GameObject
public void RemoveComponent<T>() where T : Component
{
SystemAccessScope.CheckWrite(typeof(T));
for (var i = 0; i < _components.Count; i++)
{
if (_components[i] is not T match)