fix(simulation): PR #201 review round — wire extent clamp + coalescing tests

Hoshe finding 1: StepCanvasRequest.extent is no longer wire-trusted —
clamp_step_canvas_extent enforces the D-255(b) canvas budget at the
request boundary (per-axis cap 3840 defeating u32::MAX before any
multiplication, then an aspect-preserving total-cell ceiling at the
measured 3840x2160 = 8,294,400-cell workshop budget), mirroring the
legacy carrier's clamp_window_n_v2 discipline; the Global rung ignores
the wire extent entirely. StepCanvasResponse gains the extent echo
field so a client can detect the clamp (the DistrictWindowLayer.n
precedent — a pre-existing gap closed in passing, recorded on the
ticket for T-1182). Seven new tests including an end-to-end u32::MAX
request proving actual allocation respects the cap.

Hoshe finding 2: submit_step_canvas coalescing now has the same two
regression tests its submit_window sibling always had (same-key
collapses to one pending item, different-key does not), exercising
step_canvas_supersede_key.

Targeted suites green: 1928 lib, acceptance gate 5/5, bridge_tcp 22/22,
window_derivation_golden 6/6 byte-green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-25 03:34:09 +02:00
co-authored by Claude Fable 5
parent a64701645b
commit 8af28f317b
3 changed files with 462 additions and 13 deletions
+5
View File
@@ -282,6 +282,11 @@ fn serve_step_canvas_requests(
body_id: req.body_id.clone(),
rung: req.rung,
center: req.center,
// Nothing was derived — echo (0, 0) rather than the raw
// wire extent, matching serve_step_canvas_request's own
// Global-rung convention for "no meaningful extent to
// report" (PR #201 review, Hoshe finding 1).
extent: (0, 0),
min_wl_m: req.min_wl_m,
status: StepCanvasStatus::Error("no body source resolver".to_string()),
canvas: None,