Unlock menu after failed join; remove contact damage; cover clean disconnects
ci / verify (push) Successful in 45s

A failed connection left the connect buttons disabled forever. _show_menu()
returned early when a menu already existed, so the set_busy(false) that
re-enables them never ran on the way back from _abort_connect -- the player was
locked out of both joining and hosting with no way out but a restart. Also
guards against a second attempt stacking on an in-flight one.

Contact damage is gone as a concept: nothing in this game hurts you by touching
it, because every threat should be a bullet you can see and dodge. The Stalker
walked at you and dealt contact damage and nothing else, so it now carries a
point-blank shotgun instead -- five pellets, 62 degrees, 18-tick lifetime for
about 78px of reach, so it still has to close and leaves nothing lingering.
tests/unit/test_content.gd asserts every hostile enemy has an emitter, so a new
enemy cannot quietly reintroduce the mechanic.

The menu's "Disconnect" DOES get the anti-cheese protection -- verified, not
assumed. It calls Net.shutdown(), the socket closes, and the server takes the
same linkdead path as a SIGKILL, because the channel is keyed on the socket
closing rather than on how it closed. Made permanent: a --leave-after bot flag
and two smoke assertions covering the polite exit alongside the hard kill, so a
future "clean leave" message that skipped the channel would fail a test. The
menu now says so out loud in a dungeon -- the mechanic only reads as fair if
the cost is known before clicking.

103 tests, 12 smoke assertions; check.sh, test.sh and smoke.sh all pass.
This commit is contained in:
2026-09-03 19:37:26 +02:00
parent f70de1b825
commit e1f9fa8096
17 changed files with 235 additions and 40 deletions
+14
View File
@@ -51,6 +51,17 @@ for n in 1 2; do
sleep 0.4
done
# A fourth bot that leaves *politely* -- the same Net.shutdown() the in-game
# menu's "Disconnect" button calls. The escape channel is keyed on the socket
# closing, not on how it closed, so a clean exit must be caught exactly like the
# SIGKILL below. If someone ever adds a "clean leave" message that bypasses the
# channel, this is what catches it.
"$GODOT" --headless --path . -- --bot --host 127.0.0.1 --port "$PORT" \
--name "leavebot" --leave-after 120 --autoquit "$CLIENT_TICKS" \
> "$OUT/leavebot.log" 2>&1 &
PIDS+=($!)
sleep 0.4
# A third bot that gets SIGKILLed the moment it is inside a dungeon. This is the
# anti-disconnect-cheese path: the server must keep its body in the world,
# channel it out over the same one second the escape button costs, and only then
@@ -104,6 +115,9 @@ check "bot1 returned to the lobby" "$OUT/bot1.log" "entered instance .*LOBBY
check "a hard drop is channelled, not instant" \
"$OUT/server.log" "dropped in instance [0-9]+, channelling out"
check "the dropped body is released" "$OUT/server.log" "released from instance [0-9]+ after drop"
check "a polite disconnect leaves too" "$OUT/leavebot.log" "BOT_GRACEFUL_LEAVE"
check "a polite disconnect is also channelled" \
"$OUT/server.log" "'leavebot' dropped in instance [0-9]+, channelling out"
refute "no server script errors" "$OUT/server.log" "SCRIPT ERROR|Parse Error|USER ERROR"
refute "no client script errors" "$OUT/bot1.log" "SCRIPT ERROR|Parse Error|USER ERROR"