NetKit
Shared Photon co-op transport layer for Outward BepInEx mods: channels over one relay, a hello/peer ledger, per-channel counters/heartbeat, PUN diagnostics, and a replicated-record store for consumer state mirroring.
CHANGELOG
NetKit changelog
0.2.10 — 2026-09-05
- ForgeKit 0.4.13 / DonorKit 0.1.9 / SpawnKit 0.6.1: session-3 fixes
- Fix release-blocking version skew: NetKit 0.2.10, Beastwhispering 0.2.17
- NetKit 0.2.10 loopback peers + GhostPeer GH16: the ghost answers kit hellos
- NetKit 0.2.9: Sim transport (VP1) + virtual-player spike report/education docs
- NetKit 0.2.8: MP-hardening sweep close-out (NK-F2b, A4-SIZEGUARD, C1)
- NetKit: A4-guard warn once when a payload nears PUN's 32717-byte practical ceiling
- merge NK-F2b: per-actor hello-refresh latch (same-tier reviewed, APPROVE)
- NetKit: NK-F2b per-actor hello-refresh latch so a targeted join-hello can't mask a payload change
- NetKit/SpawnKit: C1 loss-tolerance comments state the real reason (peer-state transitions, not transport loss)
- packaging: raise ForgeKit dep pins to 0.4.12 and StoryKit to 0.1.8 (fresh-install floor)
- Spawn gate abstraction: Lifecycle.IsGameplayLive, StoryKit SpawnPolicy + posture census, WalkSpeed default
- Beastwhispering 0.2.9: pet evade (hyena back-hop dodge) as the
evadespecies axis + ck.pet.cue MP cue
0.2.10 — 2026-09-03 (built, not live-verified)
- Loopback peers (GhostPeer GH16) —
Net.RegisterLoopbackPeer(actor)/UnregisterLoopbackPeer(actor), additive public API, DEV ONLY in intent. A registered fabricated actor answers as a same-bundle install: one hello delivered at registration and every outgoing hello echo-answered from it (the Sim transport's echo-hello behavior made transport-independent), so kit gates (SpawnKit room spawn gate, CompanionKit readiness) stop reading a ghost actor as UNMODDED and locking the room down. The registrant owns the lifecycle — unregister on leave.
0.2.9 — 2026-08-30 (built, not live-verified)
- Sim transport (VP1 of the virtual-player spike) —
[Net] Transport = Sim, DEV ONLY, never in a shipped profile. No Photon traffic at all: sends cross a seeded delay/jitter/drop wire (Core.SimLink, unit-tested; the seed pins the drop/jitter draw sequence — seed 0 derives one and logs it — though delivery interleaving still follows frame cadence) and are answered by ONE fabricated remote actor ([Net] SimActor, default 9). The sim peer answers annk.hellowith a same-bundle hello of its own, so every registered channel arms readiness toward it through the normal handshake — consumers exercise their real peer-facing paths on one box. Ordered mode (default) preserves Photon's reliable-ordered FIFO;SimOrdered=falseandSimDropPct>0are hostile-wire stress models Photon itself won't produce.SimEchoAllparrots every envelope back as the sim actor (handler idempotence/authorization fuzz). Newsimverb:status | join | leave | reset | send <channel> <verb> [payload…]. Scope: NetKit-layer traffic only — the sim actor has no PhotonView and no game character (that is VP3, the Ghost Peer —docs/virtual-player-spike.md).
0.2.8 — 2026-08-30 (built, not live-verified)
- The hello-refresh latch is PER RECIPIENT (NK-F2b). It used to be one global last-sent payload, so
a targeted join-hello — sent to a newly connected peer alone — advanced the refresh diff on behalf of
the peers that never received it. A mid-session payload change (a host-side taming retune, a late
channel registration) could therefore be masked for a pre-existing peer in a room of three or more
actors.
Core.HelloResendnow keeps a broadcast baseline (a send to Others reaches everyone, so it supersedes and clears the per-actor entries) plus a per-actor baseline for each targeted greeting; a refresh is owed while ANY recorded recipient is behind. Per-actor entries are dropped on peer loss and on room change, so they cannot leak or outlive an actor number (actor numbers restart per room). 2-actor behaviour is unchanged by construction, which is why this was unreachable in vanilla Outward's 2-player co-op and stood as an accepted risk until now. New Core tests cover the 3-actor masking scenario, broadcast supersession, host-alone → guest-joins baseline arming, peer-loss cleanup and room-change reset. Retest rowNK-F2b-FIXindocs/netkit-testplan.md. - A payload approaching PUN's practical ceiling warns once (A4-SIZEGUARD).
RpcRelayTransport.Sendmeasures the outgoing string and logs ONELogWarningper (channel, verb) per session when it crosses 80% of 32 717 bytes — vanilla's ownItemManager.CompressDataToSendchunk size, which is what puts the practical per-RPC limit there. Warn-only: nothing is chunked, nothing is refused, and the check itself can never throw a send. Threshold and UTF-8 sizing are pure (core/NetKit.Core/PayloadSizeGuard.cs); rowA4-SIZEGUARDindocs/netkit-testplan.md. - Comment-only (C1): the loss-tolerance notes on
ReplicatedStoreandStateMirrornow state the real reason the periodic re-announce exists. PUN RPCs are reliable, ordered per channel and deduped — the transport cannot lose messages, and loss means disconnection. The heartbeats are compensating for PEER-STATE transitions that produce the same missing-state symptom (late join, resync, room change, a peer not yet scene-ready), and they stay: they are load-bearing for late joiners. - Additive only;
COMPAT_SINCEunchanged at 0.2.4.
0.2.7 — 2026-08-29
FireAndForgetLadder.OnCastReceived(..., bool masterOriginated)overload: a MASTER-originated transient (the pet-evade cue — the host rolls a guest pet's dodge) applies on the owning guest instead of the own-echo skip, which would otherwise drop the one machine that moves the puppet. The 5-arg form is unchanged (delegates withfalse). Additive;COMPAT_SINCEunchanged.
0.2.6 — 2026-08-28
- Fix stale dependency pins across the fleet; DonorKit 0.1.7
- CompanionKit/NetKit: park+release the anchor's Photon view-ID
- AF1-3 review: keep void Flourish, add TryFlourish; sync the version quartets
- AF1-8: bound the NetCounters tables
- AF1-6: a PeerOwned store must clear on a room change
- AF1-4: a disabled master names the guest reports it swallows
Unreleased
NetCountersis bounded (AF1-8, theUnknownViewTablepattern): the per-verb table caps at 64 verbs and each verb's drop-reason set at 32, with refused events counted and named inSummary. Verbs and drop reasons are compile-time constants in every consumer, so a growing table means something is inventing them from the wire — and a diagnostic must never become the leak. A full table stops growing rather than evicting, and a capped reason tag still counts its drop.ReplicatedStorerefusesPeerOwned+ClearOnRoomChange = falseat construction (AF1-6), the sameArgumentExceptionshape as the existingResolveUidOwnerrefusal. A PeerOwned row key is derived from the sender's ACTOR NUMBER, and actor numbers are room-scoped — carrying rows across a room change leaves ghosts keyed to actors that mean someone else (or nobody) in the new room, and the presence reap compares actor numbers with no room identity so it cannot see them either. Latent today (both shipped consumers set it true); documented indocs/wiki/kits/netkit.md.- Fire-and-forget PROXY leg: a master with the feature disabled now DROPS a guest's report as
disabled-on-masterinstead of skipping it silently (AF1-4, ruling change). The old Skip blackholed every guest's transient — no apply, no relay, no drop count, no log — so nobody in the room ever saw that moment and no dump could name why. The CAST leg keeps its silent skip: a machine that renders nothing locally is not losing anyone else's moment.
0.2.4 — 2026-08-19
- Merge branch 'fix/sa-0815-mpnet' into feature/pet-self-feed
- SA 2026-08-15 lane F3: MP/net teardown, mirror-race + hello-warn fixes
- A10 verb re-homing: photondump body -> NetKit.ViewRegistryDump; waiver docs; V28-V31
- Forge shell fixes: SSH commands via bash -c (fish login shell); set/cfgdump on every channel mod
- Forge shell: catalog dump + response protocol + set/cfgdump in ForgeKit; forge CLI/REPL + completion packs; wiki-enriched name db
0.2.3 — 2026-08-11
- Phantom view-ID root cause + fixes: NetKit hb per-id attribution (top=[id×n]) + unknown-view RUNAWAY detector, DonorPhotonGuard duplicate-registration veto over live scene-baked views (DuplicateViewPolicy, unit-tested), V-PARKLEAK bounded-window acceptance + pt-stamped mute line; analysis doc + NK-PHANTOM1/2 retest rows — built, retest owed
- Fable-review fixes: viewID watermark reads outstanding ids (latched), corpse-release fallback never parks a neutralized view, FarCache InFlight can't leak, visual-pass retries count as busy, Notify header placement
- SpawnKit perf wave: hot-loop allocs removed, adaptive replica enforce, prune throttle, viewID watermark + opt-in corpse release, AI sleep radius, caps 8->12
- Merge fix/sa-0808-spawn: spawn recovery wave (SA 2026-08-08 §8)
- SA-0808 Wave C code half: spawn recovery — census, ghost fix-at-cause, quest-gate clear, TerrainManager guard, abandon quarantine
- NetKit hardening wave (static-analysis 2026-08-08 §7 items 1-7 + P1-6/P2-8)
- Fix duplicate field/const definitions in NetChannel.cs from the netkit-cloudward merge
- Merge branch 'cleanup/netkit-cloudward-2026-08-02'
- ck.proxy.pos: the guest's puppet becomes the pet's one position authority (MP-PETAIMDRIFT)
- Phase-2 view-lease migration: SpawnKit's view lifecycle moves into NetKit
- Solo-leg live results: core MP10 fix PASSES (zero refusals, clean census, viewID belt proven live); fix the caid false-positive TRIPWIRE it exposed
- Docs: MP10 fix wave 2 (root cause + NetKit.Views + contamination watchdog)
- Review fixes M1 + m1-m4: ghost bars-before-Character, per-view neutralize, self-contained disarm
- NetKit.Views clone hygiene: neutralize-first, honest tripwires, disarm-not-refuse
- W4: fixes for everything D1 found, plus the join-race P1
- MP fix waves W1/W2/W3, and what Block A found when we ran them
- Log levels: a per-mod [Diag] LogLevel, gating at the source
- NetKit + CompanionKit: GetComponent ?? AddComponent, without the eager trap (UNT0007)
- Cloudward + NetKit: say it when a decision was downgraded
- Cloudward + NetKit: five ways a quiet failure became a loud one
Unreleased
- New (built, NOT live-verified):
ChannelOptions.QuietVerbs— verbs a channel declares quiet skip the per-send/per-recvLogInfoline AND the 32-entryTraceRingwrite, while their COUNTERS still count (sends/recvs/drops stay innetdump). Built for streaming verbs (CompanionKit's ~5 Hzck.proxy.poswould wrap the whole trace ring in ~6 s and destroy the cross-verb forensic window, and would drown aVerboseNetlog). Pure membership decision isNetKit.Core.QuietVerbSet(ordinal, null/empty-tolerant, unit-tested). - New:
NetKit.Views— a shared clone/view-hygiene API, positioned as NetKit owning the Photon half of "clean up a live clone" so consumers stop hand-rolling their own tripwires against it.Neutralizeperforms the always-legalPhotonViewfield writes (removedFromLocalViewList,viewID=0, sync mode Off, send group 254) BEFORE any destroy is attempted, so even a refused destroy can no longer let a stray view evict the real replica underneath it.VerifyClean/CountNetwork/DisarmSurvivorsround out an honest report of what actually survived a strip, rather than assuming a logged destroy call succeeded. - New:
core/NetKit.Core/ViewHygiene.cs— the pure compute half (ViewFacts/SurvivorFacts/Describe/IsClean), including the one sharedRefusalNoteconst for "Unity silently refuses this class of destroy call here" so the explanation can't drift between call sites that quote it. - New:
NetKit.ViewLease— the view LIFECYCLE complement toViews(phase 2 of the hygiene migration; built, NOT live-verified):Mint/Bindallocate or adopt a viewID onto an inactive clone's ownPhotonView(single-view semantics; no-view is a returned fact, never a throw — the consumer owns the warn-vs-refuse policy),Release/DeferRelease/SweepPendingpark a minted id next to its body and hand it back only once the body is destroyed (PUN warns on a live-view release), andMuteView+MutedGroup(253) stop a registered view from streaming WITHOUT deregistering it — deliberately the opposite doctrine ofViews.Neutralize(254), the header explains why both groups coexist. One instance per consumer: the ledger, the log tag and the once-per-session latches are consumer-scoped, and every emitted line is byte-stable with the pre-migration SpawnKit implementation; consumer-dialect notices surface through callbacks. - New:
core/NetKit.Core/ViewLease.cs— the pure half of the lease (LeasePolicywith the 300s age-out rule and the aged-out re-check verdict,ViewLedger/LeaseEntrythe pending-release ledger,MuteResult), unit-tested for the first time incl. the byte-stable forensics dump format (ViewLeaseTests).
0.2.2 — 2026-08-02
- Cloudward + NetKit: say it when a decision was downgraded
- Cloudward + NetKit: five ways a quiet failure became a loud one
- Docs sweep: archive, condense, and validate the whole documentation tree
0.2.1 — 2026-07-30
- Session resilience:
unstickverb,[LOADGATE]watchdog, hardenedgoto - Hyena/Pearlbird tuning wave: HAO taunt, gifts, bone relic, feed rule