core/remote_kill_switch_controller library

Classes

KillSwitchState
One feature's current kill-switch decision — reason/version are the audit trail ("why was this killed, and which rollout"), populated from the remote payload when it's the richer {killed, reason, version} shape (a bare bool leaves them at their defaults, ''/0).
RemoteKillSwitchController
Emergency remote kill switch for a feature/event/shop/animation — built on top of RemoteConfigService (FEAT-39/ENH-58 already give it asset-fallback + partial-merge + last-known-good semantics at the config-value level; this controller adds the kill-switch-specific safety policy ON TOP: an invalid or missing remote value can never flip a feature from killed back to enabled — see KillSwitchSource for the exact resolution order).

Enums

KillSwitchSource
Where a KillSwitchState decision actually came from — surfaced so a debug overlay/health report can tell "ops explicitly killed this" apart from "we couldn't reach a fresh answer and fell back".