Phase 3 of hydraheadquest #544. Bodies must serve THREE modes and switch gracefully per body request: Sunshine (flat), SteamVR+ALVR (Quest xr), Pico Business Streaming (Pico xr).
Prior art: fluffy already runs the Pico Business runtime co-located with hydrabody (hydrabody deploys the exe, PBS runs on the same machine). Formalize that into a role instead of hand setup. Chunky-turnip-23 is the reference body that must end up with all three (ALVR staged at C:\hydra\alvr from the 2026-08-26 validation; scheduled tasks hydra-alvr-{steam,dashboard,steamvr} exist; driver registration toggled via openvrpaths).
Role duties:
- alvr-steamvr role: supervise Steam (silent auto-login), ALVR dashboard, SteamVR; toggle driver registration ON only while an alvr session is active (while registered, ANY flat OpenXR launch grabs the virtual HMD - verified); restart vrserver when it dies (it did not survive overnight); trust clients ONLY via the dashboard API POST /api/dashboard-request with X-ALVR header (session.json hand-edits get reverted); auto-trust heads at enrollment.
- pbs role: supervise Pico Business Streaming, absorb the fluffy setup.
- Arbitration: exactly one active VR runtime; mode switch quiesces the others; flat mode = both XR stacks quiesced, Sunshine serves. Switching is driven by the stream request (driver field from hydracluster).
- Steam login flows: needs-steam-login body state; venue account provisioned once by operator scanning Steam's QR over a desktop stream; visitor_login sessions log out to the QR screen and guarantee logout + credential cache wipe at session end. No credential custody anywhere.
- Doff grace period: ALVR disconnects seconds after the headset is doffed and the experience exits; add a configurable grace window before teardown so an adjusted headset does not reset the visitor's session.
- gpu-mismatch watchdog needs an XR-aware exemption or it kills xr sessions exactly like #551.