Skip to content

release: 2026-09-16 - #10134

Merged
anicalbano merged 15 commits into
mainfrom
release/2026-09-16
Sep 17, 2026
Merged

anicalbano merged 15 commits into
mainfrom
release/2026-09-16

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Automated release PR

lorux0 and others added 13 commits September 14, 2026 19:26
* fix: keep Jarvis security review label current

* chore: simplify security review classifier
* fix: bump rustls to 0.23.45 for RUSTSEC-2026-0285

TLS 1.3 handshake messages were accepted across encryption level
boundaries. rustls is transitive here, via segment's rustls-tls feature.
Single-package update; no other crate in the lock moved.

The shipped binaries still need the rebuild-and-relock round trip from
Explorer/Assets/Plugins/RustSegment/README.md: Cargo.lock is a hashed
build input, so the committed .dylib/.dll no longer match the lock.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore: relock RustSegment native binaries after the rustls bump

Cargo.lock is a hashed build input, so bumping rustls to 0.23.45 left the
committed .dylib/.dll describing a lock they were not built from.

Binaries are from rust-segment-native.yml run 34962852958, which passed
Gate A on both runners (byte-identical double build). Gate B failed there
by design: the toolchain matched the lock's pin and .native/src was
unchanged, so it demanded reproduction of binaries that Cargo.lock had
already invalidated. It becomes a real comparison on the next labelled run.

Toolchain pins and source_digest are unchanged - same runners, no src edit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Juan Molteni <juanignaciomolteni@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Ani <139157886+anicalbano@users.noreply.github.com>
…uild (#10110)

* fix: tolerate transient Unity Cloud API failures after a successful build

* fix: restore the build folder confirmation log in download_artifact
@github-actions

Copy link
Copy Markdown
Contributor Author

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor Author

🚦 CI Status

Build

Windows and Mac built successfully in Unity Cloud.

Name Links & timing
Build acc9c20 · Logs · built 2026-09-16T20:11:31Z
Windows GitHub job · Unity Cloud #74 · Unity log · ⏱ 24m 33s build + 9m 7s queue · Download .zip · .zip via S3
Mac GitHub job · Unity Cloud #75 · Unity log · ⏱ 27m 55s build + 5m 4s queue · Download .zip · .zip via S3

Lint

Warnings count reduced: 11902 => 11898

Warnings/errors in files changed by this PR (249)
Assets/DCL/Infrastructure/Utility/ExitUtils.cs:309  AssignNullToNotNullAttribute  Possible 'null' assignment to non-nullable entity
Assets/DCL/Passport/PassportController.cs:1061  CSharpWarnings::CS0618  CS0618: Method 'DCL.UI.ProfileElements.ProfilePictureView.Setup(ProfileRepositoryWrapper, in CompactInfo)' is obsolete: 'Use Bind instead.'
Assets/DCL/Chat/_Refactor/ChatTitleBar/ChatTitlebarPresenter.cs:314  CSharpWarnings::CS8601  Possible null reference assignment
Assets/DCL/InWorldCamera/InWorldCamera/ScreenshotMetadataBuilder.cs:68  CSharpWarnings::CS8601  Possible null reference assignment
Assets/DCL/InWorldCamera/InWorldCamera/ScreenshotMetadataBuilder.cs:115  CSharpWarnings::CS8601  Possible null reference assignment
Assets/DCL/InWorldCamera/InWorldCamera/ScreenshotMetadataBuilder.cs:117  CSharpWarnings::CS8601  Possible null reference assignment
Assets/DCL/InWorldCamera/InWorldCamera/ScreenshotMetadataBuilder.cs:129  CSharpWarnings::CS8601  Possible null reference assignment
Assets/DCL/InWorldCamera/InWorldCamera/ScreenshotMetadataBuilder.cs:131  CSharpWarnings::CS8601  Possible null reference assignment
Assets/DCL/Chat/_Refactor/ChatTitleBar/ChatTitlebarPresenter.cs:289  CSharpWarnings::CS8602  Dereference of a possibly null reference
Assets/DCL/Chat/_Refactor/ChatTitleBar/ChatTitlebarPresenter.cs:304  CSharpWarnings::CS8602  Dereference of a possibly null reference
Assets/DCL/InWorldCamera/InWorldCamera/ScreenshotMetadataBuilder.cs:46  CSharpWarnings::CS8603  Possible null reference return
Assets/DCL/WebRequests/Dumper/WebRequestsDumper.cs:112  CSharpWarnings::CS8603  Possible null reference return
Assets/DCL/Passport/PassportController.cs:872  CSharpWarnings::CS8604  Possible null reference argument for parameter 'arg1' in 'System.Action<in T1,in T2,in T3>.Invoke'
Assets/DCL/Infrastructure/ECS/Unity/StreamableLoading/GLTF/LoadGLTFSystem.cs:69  CSharpWarnings::CS8604  Possible null reference argument for parameter 'contentMappings' in 'ECS.StreamableLoading.GLTF.IGLTFastDisposableDownloadProvider.SetContentMappings'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:567  CSharpWarnings::CS8604  Possible null reference argument for parameter 'description' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.CreateOrUpdateCommunityAsync'
Assets/DCL/Infrastructure/SceneRuntime/Apis/Modules/SignedFetch/SignedFetchWrap.cs:241  CSharpWarnings::CS8604  Possible null reference argument for parameter 'headers' in 'SceneRuntime.Apis.Modules.SignedFetch.Messages.FlatFetchResponse.FlatFetchResponse'
Assets/DCL/Infrastructure/Global/Dynamic/BootstrapContainer.cs:210  CSharpWarnings::CS8604  Possible null reference argument for parameter 'identityCache' in 'DCL.PerformanceAndDiagnostics.Analytics.AnalyticsContainer.CreateAsync'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:567  CSharpWarnings::CS8604  Possible null reference argument for parameter 'lands' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.CreateOrUpdateCommunityAsync'
Assets/DCL/Chat/_Refactor/ChatTitleBar/ChatTitlebarPresenter.cs:395  CSharpWarnings::CS8604  Possible null reference argument for parameter 'model' in 'DCL.Chat.ChatViews.ChatDefaultTitlebarView.Setup'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:567  CSharpWarnings::CS8604  Possible null reference argument for parameter 'name' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.CreateOrUpdateCommunityAsync'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:286  CSharpWarnings::CS8604  Possible null reference argument for parameter 'ownerAddress' in 'DCL.PlacesAPIService.IPlacesAPIService.GetDestinationsByOwnerAsync'
Assets/DCL/Places/PlacesResultsController.cs:328  CSharpWarnings::CS8604  Possible null reference argument for parameter 'ownerAddress' in 'DCL.PlacesAPIService.IPlacesAPIService.GetDestinationsByOwnerAsync'
Assets/DCL/Passport/PassportController.cs:1012  CSharpWarnings::CS8604  Possible null reference argument for parameter 'reportedUserId' in 'DCL.UI.ConfirmationDialog.ReportUserHelper.ShowConfirmAndReportAsync'
Assets/DCL/Communities/CommunitiesBrowser/CommunitiesBrowserController.cs:576  CSharpWarnings::CS8604  Possible null reference argument for parameter 'targetedUserAddress' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.SendInviteOrRequestToJoinAsync'
Assets/DCL/Communities/CommunitiesCard/CommunityCardController.cs:689  CSharpWarnings::CS8604  Possible null reference argument for parameter 'targetedUserAddress' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.SendInviteOrRequestToJoinAsync'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:501  CSharpWarnings::CS8604  Possible null reference argument for parameter 'thumbnail' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.CreateOrUpdateCommunityAsync'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:567  CSharpWarnings::CS8604  Possible null reference argument for parameter 'thumbnail' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.CreateOrUpdateCommunityAsync'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:396  CSharpWarnings::CS8604  Possible null reference argument for parameter 'thumbnailLoader' in 'DCL.Communities.CommunityCreation.CommunityCreationEditionView.SetProfileSelectedImage'
Assets/DCL/Passport/PassportController.cs:989  CSharpWarnings::CS8604  Possible null reference argument for parameter 'userAddress' in 'DCL.Backpack.Gifting.Views.GiftSelectionParams.GiftSelectionParams'
Assets/DCL/MarketplaceCredits/MarketplaceCreditsMenuController.cs:338  CSharpWarnings::CS8604  Possible null reference argument for parameter 'userId' in 'DCL.MarketplaceCredits.MarketplaceCreditsUtils.IsUserAllowedToUseTheFeatureAsync'
Assets/DCL/Passport/PassportController.cs:873  CSharpWarnings::CS8604  Possible null reference argument for parameter 'userId' in 'DCL.Passport.PassportParams.PassportParams'
Assets/DCL/Communities/CommunityCreation/CommunityCreationEditionController.cs:567  CSharpWarnings::CS8604  Possible null reference argument for parameter 'worlds' in 'DCL.Communities.CommunitiesDataProvider.CommunitiesDataProvider.CreateOrUpdateCommunityAsync'
Assets/DCL/PluginSystem/Global/GenericPopupsPlugin.cs:103  CSharpWarnings::CS8618  Non-nullable field 'ChatEntryMenuPopupPrefab' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/PluginSystem/Global/GenericPopupsPlugin.cs:102  CSharpWarnings::CS8618  Non-nullable field 'PastePopupToastPrefab' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/Infrastructure/ECS/Unity/StreamableLoading/GLTF/GLTFData.cs:25  CSharpWarnings::CS8618  Non-nullable field 'Root' must contain a non-null value when exiting constructor. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/PluginSystem/Global/GenericPopupsPlugin.cs:104  CSharpWarnings::CS8618  Non-nullable field 'UpgradeGuestAccountPopupPrefab' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/Communities/CommunitiesCard/CommunityCardController.cs:113  CSharpWarnings::CS8618  Non-nullable field 'communityPlaceIds' must contain a non-null value when exiting constructor. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/Infrastructure/SceneRunner/Tests/SceneFacadeShould.cs:135  CSharpWarnings::CS8618  Non-nullable field 'engineFactory' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/UI/TextInputFields/EmailInputFieldView.cs:21  CSharpWarnings::CS8618  Non-nullable field 'errorContainer' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/PluginSystem/Global/LandscapeSettings.cs:16  CSharpWarnings::CS8618  Non-nullable field 'gpuiShaderBindings' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/UI/TextInputFields/EmailInputFieldView.cs:16  CSharpWarnings::CS8618  Non-nullable field 'inputField' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/PluginSystem/Global/LandscapeSettings.cs:15  CSharpWarnings::CS8618  Non-nullable field 'landscapeData' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/UI/TextInputFields/EmailInputFieldView.cs:22  CSharpWarnings::CS8618  Non-nullable field 'loadingSpinner' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/UI/TextInputFields/EmailInputFieldView.cs:25  CSharpWarnings::CS8618  Non-nullable field 'outline' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/Infrastructure/SceneRunner/Tests/SceneFacadeShould.cs:147  CSharpWarnings::CS8618  Non-nullable field 'path' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/Infrastructure/Utility/ExitUtils.cs:293  CSharpWarnings::CS8618  Non-nullable field 'quittingField' is uninitialized. Consider adding the 'required' modifier or declaring the field as nullable.
Assets/DCL/PluginSystem/Global/LandscapeSettings.cs:14  CSharpWarnings::CS8618  Non-nullable field 'realmPartitionS

…truncated; see the linked run for the full report.

Tests

All Unity tests passed ✅

TESTS SUITE Result Passed Failed Skipped Tests time Job time
EditMode ✅ Passed 25975 0 13 4m 40s 14m 58s
PlayMode ✅ Passed 248 0 37 38s 13m 3s

Tests time sums the test cases; Job time is the job's wall clock including checkout, licensing and asset import.

Slowest tests
  • [editmode] 16.5s DCL.AuthenticationScreenFlow.Tests.ProfileFetchingAuthStateShould.CancelStalledFetchOnTimeout
  • [editmode] 15.8s DCL.Tests.Editor.ValidationTests.CheckForDebugUsage
  • [editmode] 12.0s DCL.Tests.Editor.ValidationTests.CheckUnityObjectsForMissingReferences
  • [editmode] 10.0s DCL.Notifications.Tests.NotificationsRequestControllerShould.ReuseSingleListInstanceAcrossPollIterations
  • [editmode] 5.4s DCL.Tests.Editor.ValidationTests.SettingsAreValid
  • [editmode] 5.0s DCL.Friends.Tests.FriendsConnectivityStatusTrackerShould.RaiseOnlineEventWhenSameStatusIsRebroadcastAfterReset
  • [editmode] 5.0s CrdtEcsBridge.WorldSynchronizer.Tests.CrdtWorldSynchronizerShould.ThrowIfSyncBufferIsAlreadyRented
  • [editmode] 4.9s DCL.AvatarRendering.AvatarShape.Tests.FinishAvatarMatricesCalculationSystemShould.CullAnInWorldAvatarBehindTheCamera
  • [editmode] 4.4s DCL.AvatarRendering.AvatarShape.Tests.FinishAvatarMatricesCalculationSystemShould.KeepThePreviewAvatarLiveWhereverThePlayerCameraLooks
  • [editmode] 4.3s DCL.AvatarRendering.AvatarShape.Tests.FinishAvatarMatricesCalculationSystemShould.PlaceTheAvatarBoundsInTheWorldTheSameWayTheReferenceFormDoes
  • [playmode] 2.5s DCL.SDKComponents.Tween.Tests.TweenUpdaterSystemShould.ContinuousTweensRunIndefinitelyWhenDurationIsZero
  • [playmode] 2.5s Global.Tests.PlayMode.CubeWaveSceneShould.EmitECSComponents
  • [playmode] 2.3s DCL.SDKComponents.Tween.Tests.TweenSequenceSystemShould.TextureMoveSequenceUpdatesMaterial
  • [playmode] 2.1s DCL.SDKComponents.Tween.Tests.TweenSequenceSystemShould.TweenSequenceWithoutLoopCompletesOnce
  • [playmode] 2.0s DCL.SDKComponents.Tween.Tests.TweenUpdaterSystemShould.TextureMoveContinuousOffsetCompletesAndUpdatesMaterial
  • [playmode] 2.0s DCL.SDKComponents.Tween.Tests.TweenUpdaterSystemShould.RotateContinuousCompletesAfterDuration
  • [playmode] 1.9s DCL.SDKComponents.Tween.Tests.TweenUpdaterSystemShould.MoveContinuousMovesAndCompletesAfterDuration
  • [playmode] 1.7s DCL.SDKComponents.Tween.Tests.TweenSequenceSystemShould.TweenSequenceWithMoveRotateScaleWithOmittedScale_ResolvesScaleFromCurrentTransform
  • [playmode] 1.5s DCL.SDKComponents.Tween.Tests.TweenSequenceSystemShould.TweenSequenceWithMultipleTweens
  • [playmode] 1.4s DCL.SDKComponents.Tween.Tests.TweenSequenceSystemShould.TweenSequenceCompletesAllTweens

Full report: run summary · results + editor logs: editmode · playmode

Performance

🏁 Bare-metal benchmark finished — run #35145118714.

Full report

PR #10134, run #35145118714

Overall: ✅ no significant changes

Builds: Windows change, Windows baseline, macOS change, macOS baseline

How to read this table
  • Each build is measured 3 times, interleaved with the other build (change, baseline, change, baseline, ...) in the same session, so both see the same world content and machine state. The values are the median, and (min–max) is the lowest and highest of those runs.
  • Δ is Change minus Baseline (a negative Δ means Change is faster).
  • 🟢 faster / 🔴 slower — a difference that passed every check: the runs are fully separated (every run of one build faster than every run of the other), and the median difference is at least 3% and at least 0.5 ms.
  • ⚪ within noise — the builds' runs overlap, or the difference is tiny; it cannot be told apart from random variation. Treat it as no change.
  • — informational — the 0.1% worst metrics average only the few worst frames of a run, so a single OS hiccup swings them by a lot; they are shown for context and never earn a verdict.
  • ⚠️ no verdict — the two builds' sessions were not comparable (very different sample counts, or too few usable runs), so no conclusion is drawn from them.
  • Exceptions per run — the average number of exceptions in a run's log, not counting teardown ones logged while the app quits. Flagged only on a difference of at least 2 per run and 1.5× the other build; exception kinds the baseline never threw are called out under the table. The Exception breakdown groups all of them by the explorer's report category and exception type (as totals across the runs).
  • A run that logged unusually many exceptions (at least 10 and 5× the median of its build's runs — e.g. a service was down during it) is excluded from all numbers and called out under the table.
  • The Overall line at the top only reacts to a metric that moved on two or more machines, or by 10% or more on one — a single modest 🟢/🔴 cell can still be a statistical fluke.

Apple M1

Metric Baseline Change Δ Result
Samples 4083 (×3) 4124 (×3)
CPU average 21.9 ms (21.8–22.3) 21.7 ms (21.7–22.4) -0.2 ms ⚪ within noise
CPU 1% worst 219.5 ms (216.0–220.5) 219.0 ms (218.8–219.2) -0.5 ms ⚪ within noise
CPU 0.1% worst 224.6 ms (224.3–231.4) 225.5 ms (224.5–226.1) 0.9 ms — informational
GPU average 33.9 ms (33.8–36.2) 35.1 ms (33.3–36.5) 1.2 ms ⚪ within noise
GPU 1% worst 45.7 ms (44.3–46.2) 44.7 ms (43.8–46.1) -1.0 ms ⚪ within noise
GPU 0.1% worst 46.2 ms (45.1–47.4) 45.5 ms (44.6–47.0) -0.7 ms — informational
Exceptions per run 0 0 0 ⚪ no significant change

Intel Core i5

Metric Baseline Change Δ Result
Samples 4334 (×3) 4561 (×3)
CPU average 20.7 ms (18.1–21.3) 19.6 ms (16.7–22.2) -1.1 ms ⚪ within noise
CPU 1% worst 343.9 ms (315.6–383.9) 368.0 ms (245.9–420.0) 24.1 ms ⚪ within noise
CPU 0.1% worst 434.3 ms (390.2–448.0) 423.7 ms (289.8–453.3) -10.5 ms — informational
GPU average 13.4 ms (11.0–13.9) 12.5 ms (9.5–14.6) -0.9 ms ⚪ within noise
GPU 1% worst 196.4 ms (177.1–253.7) 255.8 ms (85.8–306.6) 59.4 ms ⚪ within noise
GPU 0.1% worst 432.8 ms (386.7–446.9) 423.1 ms (279.0–454.7) -9.7 ms — informational
Exceptions per run 0 0 0 ⚪ no significant change

Automation

On demand — comment /visual-tests on this PR to run the visual regression suite against its build.

InWorld

✅ InWorld suite passed on all 3 legs.

macOS Windows 1/2 Windows 2/2
Result ✅ passed ✅ passed ✅ passed
Tests 72 35 / 35 35 / 35
Duration 22m6s 15m54s 18m44s
Allure Open Open Open

Commit acc9c20 · branch release/2026-09-16 · filter Category=InWorld · run #35141144933

macOS on macos-14, Windows shards on win-gpu-t4-explorer. Updated on every run.

eordano and others added 2 commits September 16, 2026 19:25
SDK6 scenes are no longer pinned to their LOD representation. Near the
player they enter the normal distance-based scene lifecycle and run
their original JavaScript through the SDK6 compatibility adapter, which
now ships in StreamingAssets instead of being fetched from
renderer-artifacts.decentraland.org at runtime.

Adapter: decentraland/sdk6-adapter 0.4.3, commit f06e46e415e6e1ef692133eff198aa6bdea3ed4c
Build: https://github.com/decentraland/sdk6-adapter/actions/runs/34495065151
SHA-256: 733a108cd8bb667be75d6c76a3fe444f6ddcd481858af8d354dba25a29713b9a

* feat: provide ~system/AdaptationLayerHelper for SDK6 UI texture sizing

The SDK6 compatibility adapter uses the host-optional
~system/AdaptationLayerHelper.getTextureSize for UiImage sizeInPixels
sizing. Texture sources resolve through ISceneData.TryGetMediaUrl, the
same path SDK7 texture components use, and the original file is fetched
without the KTX variant so the reported size is the source image's.

Also clears the nullable compiler warnings in the files this branch
touches (LoadSceneDefinitionListSystem, VisualSceneStateResolverShould).

* chore: embed sdk6-adapter 5ae8391

The adapter now follows the legacy screen-space UI rules: pointer blocking
through the CanvasGroup chain, onClick on pointer down, image source-rect
cropping, stack sizing, text truncation and input placeholder, background
and submit semantics. It also moves esbuild past GHSA-67mh-4wv8-2f99.

Bundle and provenance are the subjects attested by
https://github.com/decentraland/sdk6-adapter/actions/runs/34679156027/attempts/1
(sha256 18e63cfc2a6913bbed658bde0bf4ca2af60336be2b4cd07806b00948662f12c9,
1132952 bytes). Bundled dependency licenses are unchanged.
* remove session-id override param & replace device id for a guid

* update comment

@DafGreco DafGreco left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✔️ PR reviewed and approved by QA on both platforms following instructions playing both happy and un-happy path

Regressions for this ticket had been performed in order to verify that the normal flow is working as expected:

Sanity check

@decentraland-bot decentraland-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release Review — release: 2026-09-16

Automated release PR merging 15 commits from release/2026-09-16 into main. QA has approved on both platforms.


STEP 1 — Scope

Commits in this release:

  1. fix: os font fallback anr (#10090) — ANR fix in MetricsRegistry
  2. fix: far-away scenes broken tick after teleport (#10089) — VisualSceneStateResolver SDK6 path removal
  3. fix: keep Jarvis security review label current (#10106) — CI workflow
  4. fix: crash when a deleted entity still lists destroyed children (#10067) — ParentingTransformSystem crash fix
  5. feat: guest login (#9888) — Major feature: full guest login flow, account upgrade, identity persistence
  6. chore: sync main to dev (#10108) — merge
  7. fix: tolerate transient Unity Cloud API failures (#10092) — build script resilience
  8. fix: editor start-position override (#10092) — TeleportStartupOperation simplification
  9. feat: _exit with 0 code on macOS (#10104) — ExitUtils: _exit(0) replaces kill(SIGKILL)
  10. chore: migrate to 'main' protocol (#10060) — protobuf updates, AvatarEmoteMask, comms protocol
  11. fix: remove the reflection scan behind web-request debug metrics (#10112) — MetricsRegistry ANR fix
  12. fix: reconcile the abgen server already on the port (#10113) — AbgenSidecar port reconciliation
  13. fix: stop GPU Instancer blocking the main thread on startup (#10111) — asset changes
  14. feat: run SDK6 scenes through an embedded adapter (#10057) — AdaptationLayerHelper, embedded JS adapter
  15. fix: guest session id random per install, no override (#10135) — GuestSessionIdProvider

138 C# files changed, plus assets, prefabs, textures, protocol files, CI scripts.


STEP 2 — Root-cause check

Each fix addresses its root cause:

  • #10067 (ParentingTransformSystem): The crash occurred because OrphanChildrenOfDeletedEntity called World.Get<TransformComponent>(childEntity) without validating whether the child entity was alive or still actually parented. The fix correctly adds World.IsAlive checks and validates transformComponent.Parent == entity before operating, plus a fallback to scene root when the requested parent is dead. ✅
  • #10090/#10112 (MetricsRegistry): Replaced a reflection scan over all loaded assemblies with an explicit type list — addresses the ANR at its source (slow reflection at startup). ✅
  • #10089 (VisualSceneStateResolver): Removed the early-return for SDK6 scenes that forced LOD display, now that SDK6 scenes run through the embedded adapter. ✅
  • #10104 (ExitUtils): Replaces kill(pid, SIGKILL) with _exit(0) on macOS — cleaner process termination. ✅
  • #10113 (AbgenSidecar): Instead of adopting any server on the port, reconciles version, realm, and status before adopting. ✅
  • #10135 (GuestSessionIdProvider): Generates a random GUID per install and persists it, removing any override path. ✅

STEP 3 — Design & integration

Guest login feature (#9888) — the largest change in this release. Design assessment:

  • Identity model: IWeb3Identity.Web3IdentitySource enum replaced with LoginMethod enum on IWeb3Authenticator. This is a clean refactor — the method is now persisted in the identity JSON and round-tripped correctly, with fallback to LoginMethod.ANY for legacy cached identities. Test coverage in IdentityMethodPersistenceShould confirms round-trip, fallback for absent/unrecognised method. ✅
  • IAccountLinkAuthenticator: New interface for email linking — implemented by ThirdWebAuthenticator, composed into ICompositeWeb3Provider. This earns its abstraction: it is consumed by both the UpgradeGuestAccountPopupController and the CompositeWeb3Provider facade. ✅
  • GuestAccountUpgradedException: Custom exception to signal that a guest wallet has been upgraded with an email. Caught at CompositeWeb3Provider.LoginAsync, TryAutoLoginAsync, and GuestOrSignUpAuthState. The exception propagation is consistent. ✅
  • UpgradeGuestAccountPopupController: New MVC controller for the upgrade popup. CTS lifecycle is correct (SafeRestart on close, SafeCancelAndDispose on dispose). Analytics events have symmetric subscribe/unsubscribe in UpgradeGuestAccountAnalytics. ✅
  • isGuest propagation through comms: The isGuest flag flows from identityCache.IsGuest() through MetaData, CommsHandshakeMetadata, SignedFetchWrap, and SceneRoomMetaDataSource. All call sites updated consistently. ✅
  • Feature gating: Guest login is behind FeatureId.GuestLogin (alfa-guest-login flag). Auto-login clears guest session when the flag is disabled. ✅

SDK6 adapter embedding (#10057):

  • AdaptationLayerHelperWrapper is a standard JsApiWrapper that fetches texture dimensions. It validates the URL through sceneData.TryGetMediaUrl before fetching. The texture is created and destroyed within the same flow (try/finally). ✅
  • The adapter JS is loaded from StreamingAssets instead of a remote URL. A SHA-256 and provenance file are committed alongside. ✅

AbgenSidecar reconciliation (#10113):

  • The ReconcileResidentServerAsync method probes /health and checks version, realm, and status before adopting. The adopted flag prevents killing a server this instance didn't launch. The AB panel is opened to explain why the port is blocked. ✅

STEP 4 — Member audit

  • ICompositeWeb3Provider.IsThirdWebAccount (renamed from IsThirdWebOTP): Used by CompositeWeb3Provider internally (3 call sites) and by external consumers. Rename correctly reflects that it now covers both guest and OTP flows. ✅
  • IWeb3IdentityCache.IsGuest() extension method: Used across 10+ call sites (comms metadata, voice chat, signed fetch, sidebar, passport, communities, chat, donations, places, profile name editor). Single-purpose utility that encapsulates the null-safe check. ✅
  • ProfileBuilder.WithGuestMode(bool): Used by UpgradeGuestAccountPopupController.PromoteProfileAsync and by ProfileFetchingAuthState. Delegates to hasConnectedWeb3 = !isGuest. ✅

STEP 5 — Line-level findings

No P0 or P1 issues found. The code is well-structured, follows project conventions, and each commit has been individually reviewed on dev.

Categories checked clean:

  • R1 (perf-alloc): No allocations introduced in hot paths. MetricsRegistry change explicitly removes a per-startup reflection scan. ✅
  • R2 (LINQ): No LINQ added in systems or hot paths. ✅
  • R4 (ECS lifecycle): ParentingTransformSystem changes are correct ECS query patterns with proper World.IsAlive and TryGetRef checks. ✅
  • R5 (entity by-ref): No structural changes over by-ref entities. The RemoveFromParent parameter change to in TransformComponent is read-only. ✅
  • R6 (acquire/release symmetry): UpgradeGuestAccountPopupController — linkCts is SafeRestarted on close and SafeCancelAndDisposed on Dispose. UpgradeGuestAccountAnalytics has symmetric subscribe/unsubscribe. ✅
  • R7 (nullability): Identity method fallback to LoginMethod.ANY for legacy data is correct. No null-forgiving operators added without justification. ✅
  • R8 (root cause): All fixes address root causes (see Step 2). ✅
  • R9 (logging): All logging uses ReportHub with explicit ReportCategory. ✅
  • R10 (catch-scope): ThirdWebLoginService.TryAutoLoginAsync uses catch (Exception e) when (e is not GuestAccountUpgradedException) — correct filtering. ✅
  • R11 (async/cancellation): CancellationTokens are threaded through all new async paths. ThrowIfCancellationRequested used in awaited flows (acceptable per CLAUDE.md §9). linkCts lifecycle in UpgradeGuestAccountPopupController is correct. ✅
  • R12 (abstraction justification): IAccountLinkAuthenticator has two consumers (UpgradeGuestAccountPopupController, CompositeWeb3Provider). ✅
  • R13 (reuse): GuestSessionIdProvider reuses DCLPlayerPrefs and DCLPrefKeys. BuildIdentityAsync extracts the common identity construction previously duplicated between login flows. ✅
  • R18 (magic numbers): SceneFacade.FROZEN_INTERVAL_MS = -1 is properly named. ✅
  • R20 (idiom cluster): No Concurrent* collections. String comparisons use StringComparison.OrdinalIgnoreCase in ContainsMessage. ✅
  • R22 (tests): IdentityMethodPersistenceShould (5 test cases), SceneFacadeShould (2 new tests for 0-FPS freeze/resume), TeleportStartupOperationShould (2 new tests), AvatarRandomizerShould, AdaptationLayerHelperWrapperShould, ParentingTransformSystemShould, MetricsRegistryShould — comprehensive coverage. ✅
  • R23 (AI comments): No AI-style narration comments detected. ✅
  • R24 (scope): Each commit is well-scoped to its stated purpose. ✅

STEP 6 — Complexity

COMPLEX — touches auth/identity infrastructure, ECS transform systems, comms metadata, scene runtime module registration, analytics, feature flags, and multiple plugin/container wiring points.


STEP 7 — QA

QA_REQUIRED: YES — runtime code is modified across authentication, scene loading, parenting, voice chat, and comms.

QA has already approved on both platforms (DafGreco).


STEP 8 — Warnings

No warnings. Main.unity is not in the changed files.


Merge gates

  • R25 (open threads): 0 open review threads. QA approved. ✅
  • R26 (QA sign-off): QA approved by DafGreco on both Windows and Mac. The PR carries the auto-pr label. ✅

CI Status

  • ✅ Build (Windows + macOS): PASS
  • ✅ Lint: PASS
  • ✅ Test (editmode + playmode): PASS
  • ✅ InWorld suite: PASS
  • ✅ Rust checks: PASS
  • ⚠️ request-security-review: FAIL (workflow infrastructure — does not indicate a code issue)
  • ⏳ Claude Review: Pending (this review)

REVIEW_RESULT: PASS ✅
COMPLEXITY: COMPLEX
COMPLEXITY_REASON: Touches auth/identity (guest login, account linking, identity persistence), ECS parenting, comms metadata, scene runtime (SDK6 adapter), analytics, and plugin wiring across 138 C# files.
QA_REQUIRED: YES


Reviewed by Jarvis 🤖 · Requested by Ani Albano (<@U05FQD5JWH2>) via Slack

@anicalbano
anicalbano self-requested a review September 17, 2026 15:07
@anicalbano
anicalbano added this pull request to the merge queue Sep 17, 2026
Merged via the queue into main with commit fe14de2 Sep 17, 2026
57 of 61 checks passed
@anicalbano
anicalbano deleted the release/2026-09-16 branch September 17, 2026 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.