Skip to content

research(track-a): recover direct player position - #302

Draft
blakinio wants to merge 46 commits into
mainfrom
research/OTC-20260815-track-a-p0-direct-position
Draft

research(track-a): recover direct player position#302
blakinio wants to merge 46 commits into
mainfrom
research/OTC-20260815-track-a-p0-direct-position

Conversation

@blakinio

@blakinio blakinio commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Track A P0-STATE — direct player position (Draft only)

Task: OTC-20260815-track-a-p0-direct-position
Consumer PR: #302
Execution: github_hosted, runtime_access:none, persistent-session role: consumer_of_runtime_evidence.

Current terminal disposition

DIRECT_PLAYER_XYZ=INCONCLUSIVE
BLOCKED_NO_LEGAL_EXISTING_IN_GAME_LIFECYCLE
DRAFT_NOT_PROMOTED

Direct authoritative current player XYZ is not proven. The current blocker is no longer static evidence or XID→PID mechanics; it is the absence of a legal current canonical registered exact-client IN_GAME lifecycle under which the bounded semantic discriminator may execute.

Exact client fence

  • version: 15.32.df7b29
  • size: 51965216
  • SHA-256: e6c244bd39fe2e0632f6f000efd3147164696efa8e901718668e0442325ff7fe
  • platform: official native Linux only

Canonical structural input

Merged producer #435 remains accepted structural exact-client evidence. It establishes the bounded TCyclopediaMapStorage / TWorldMapCoordinate / player-position observer metadata neighborhood, including playerPositionChanged, onPlayerPositionWasUpdated, onPlayerCreatureAddedToGameSession, pPlayer, and weak_ptr<TCreature>. This evidence is structural only and does not itself identify authoritative player XYZ.

Durable producer evidence:

  • docs/agents/evidence/OTC-20260816-track-a-p0-cyclopedia-sanitized-bundle/p0-cyclopedia-sanitized-evidence.md
  • docs/agents/evidence/OTC-20260816-track-a-p0-cyclopedia-sanitized-bundle/evidence-data.json
  • docs/agents/evidence/OTC-20260816-track-a-p0-cyclopedia-sanitized-bundle/selected-code-windows.txt

Strongest direct XYZ-shaped static candidate

Exact-client disassembly gives the strongest current candidate on a TPlayerData-typed route:

0x83658a  rbx <- rsi
0x836659  movsxd ... DWORD PTR [rbx+0x78]
0x83667e  movsxd ... DWORD PTR [rbx+0x7c]
0x8366b3  movsxd ... DWORD PTR [rbx+0x80]
0x8367c1  exact `playerPosition` property literal reference

The associated exact-client structural work also identifies the TPlayerData primary vptr candidate 0x308ca70 at recovered target entries including 0x843e20 / 0x843f60.

Current classification of this candidate:

  • object identity: TPlayerData-typed/static route candidate; live authoritative instance identity UNKNOWN;
  • offsets: +0x78, +0x7c, +0x80;
  • representation: three signed 32-bit values (movsxd from DWORD);
  • stable live address derivation / pointer chain: UNKNOWN;
  • semantic classification: XYZ-shaped candidate only, not authoritative player position proof.

The static route does not exclude provider/status/render-owned copies or stale state. It therefore cannot be promoted without physical causal correlation.

Canonical X11/XRes identity chain

The former identity dependency is complete and must not be repeated:

Historical PID 13648 / XID 0x00c00011 from #457 are retained proof for that isolated run only and are not current runtime authority.

Fresh current RUNTIME admission

A new RUNTIME dependency was created solely to re-measure current canonical lifecycle availability; it was not a new P0 and did not investigate world-map behavior.

Promoted evidence:

  • task: OTC-20260817-track-a-p0-player-state-admission;
  • evidence PR runtime(track-a): refresh P0 player-state canonical admission #482 merge: a94e931cdc454e0e28c2ef628be23b926c4e3657;
  • physical admission run/job: 32033237388 / 95397745114;
  • runner: synology-otclient-01;
  • exact admitted head: 945d448f41332323bfb2d52fb498110a085b8f43;
  • governance: PASS;
  • canonical namespace: PRESENT;
  • lease: PRESENT, released, generation 8;
  • controller task/session: null / null;
  • authoritative runtime-registration.json: ABSENT;
  • control metadata unchanged: true;
  • process observation: false;
  • X11 observation: false;
  • process-memory access: false;
  • client mutation: false;
  • bootstrap/login: false / false.

The prior #467 snapshot was generation 7; fresh generation 8 proves the historical blocker was not blindly inherited. Current state changed, but authoritative registration is still absent.

Durable current evidence:

  • docs/agents/evidence/OTC-20260817-track-a-p0-player-state-admission/20260817-current-canonical-controller-inventory.md
  • archived runtime task: docs/agents/tasks/archive/OTC-20260817-track-a-p0-player-state-admission.md
  • archive/release PR docs(track-a): archive blocked P0 player-state admission #486 merge: 26c89a7d3b044acf88299f8d68eee4ac16b5d13c.

Semantic proof matrix

Because no legal current registered IN_GAME lifecycle exists, the live P0 discriminator was correctly not executed:

  • fresh exact-client PID/start identity: NOT AVAILABLE;
  • current X11/XRes ownership: NOT EXECUTED for P0 lifecycle;
  • structurally verified IN_GAME: NOT AVAILABLE;
  • direct XYZ observations: 0;
  • independent live structural world-coordinate observations: 0;
  • known movement delta correlation: NOT EXECUTED;
  • inverse control: NOT EXECUTED;
  • camera/viewport/map-origin/stale-copy negative controls: NOT EXECUTED;
  • repeatability: NOT VERIFIED;
  • restart/relogin stability: NOT VERIFIED.

No absence above is being converted into a negative semantic result. The candidate remains INCONCLUSIVE, not disproven.

Exactly one missing dependency

A separately legitimate canonical lifecycle, established for an independent authorized purpose, must first create a current authoritative registered exact-client runtime and reach structurally verified IN_GAME.

After that prerequisite exists, RUNTIME must perform a fresh admission and current Gate A / any required generation rebind / Gate B, then execute only the bounded read-only P0 semantic discriminator. P0 must not bootstrap/login solely to manufacture this evidence and must not create a second logged-in session.

Scope and promotion boundary

No world-map extent, world-map mutation, render extent or server map delivery was investigated by this P0 continuation. No client-byte mutation, process-memory write, credentials, owner-funded OpenAI API or direct Codex invocation was used.

This long-running Draft branch remains non-promotion-ready. Do not mark Ready or merge #302 unless the required causal semantic proof actually exists; any future promotion must first replay/refresh the consumer branch from then-current main.

@blakinio blakinio added the programme:client Oteryn client programme label Aug 15, 2026

Copy link
Copy Markdown
Owner Author

Coordinator disposition at current head e45b126923495b209c08a77e9a3db96b44ad71a4: RETURN_FOR_EVIDENCE.

The draft has a bounded, read-only, type-provenance-aware TPlayerData probe and a green standard PR CI checkpoint, but the material runtime discriminator has not executed. Coordinator recheck still shows run 31880617510 job 95002559098 in queued state; therefore there is no live direct-position semantic result, no negative-control result, no repeatability and no restart/relogin evidence to promote.

Required evidence before reconsideration:

  1. exact client SHA/size verified in the executing job;
  2. actual passive-probe logs/artifact from the assigned self-hosted runner;
  3. candidate provenance tied to the typed owner graph rather than a blind XYZ scan;
  4. discrimination against viewport/map-origin/camera/copy candidates;
  5. at least two observations and independent structural-world comparison;
  6. if one reversible step is needed, ownership recheck against research(track-a): prove runtime reacquisition stability #303 plus verified inverse restoration;
  7. terminal exact-head CI after the final evidence checkpoint.

Do not cancel/bypass the queued job or promote the existing DERIVED viewport-center coordinate as a direct player member.

Copy link
Copy Markdown
Owner Author

P0 PLAYER-STATE continuation — current trusted-base checkpoint

Verified trusted main@83034227280dc3bfdf589a991f0fdbbabab7dc87 (2026-08-17) and re-consumed the canonical chain without repeating XID→PID research:

The last fresh physical admission (32019313320 / 95355423148) proved: lease generation 7 released, controller task/session null, authoritative runtime-registration.json=ABSENT, no process/X11 observation, no bootstrap/login. Therefore it did not execute the P0 memory discriminator and did not establish IN_GAME.

I explicitly checked for newer Track A canonical-runtime work on current repository state rather than inheriting that blocker automatically. No newer open RUNTIME PR or durable main evidence establishes a current registered exact-client IN_GAME lifecycle. Repository state alone cannot prove that the external canonical runtime has not changed since #467, and the currently available GitHub connector exposes workflow/run inspection but no fresh workflow-dispatch/execution operation. I therefore cannot legally or verifiably claim a new physical admission from this session.

Terminal result

DIRECT_PLAYER_XYZ=INCONCLUSIVE

Candidate retained from exact-client structural evidence:

  • object class candidate: TPlayerData-typed owner path;
  • XYZ-shaped fields: +0x78 / +0x7c / +0x80;
  • representation: three signed 32-bit values (movsxd DWORD PTR [...] at exact-client code 0x836659, 0x83667e, 0x8366b3) immediately upstream of the playerPosition property literal;
  • direct authoritative semantics: NOT PROVEN;
  • lifecycle validity: NOT CURRENTLY ESTABLISHED;
  • causal delta correlation: NOT RUN;
  • independent world-coordinate correlation: NOT RUN;
  • camera/viewport/map-origin/stale-copy negatives: NOT RUN;
  • inverse control: NOT RUN;
  • restart/relogin stability: UNKNOWN.

Exactly one missing dependency remains: a fresh RUNTIME admission against an independently legitimate current canonical lifecycle that proves exact PID/start identity + XRes ownership + registration/lease/generation + structurally verified IN_GAME; only then run the bounded read-only P0 discriminator. Do not bootstrap/login solely for P0.

#302 remains Draft and must not be promoted on this evidence.

blakinio added a commit that referenced this pull request Aug 17, 2026
Promote the fresh generation-8 canonical controller-plane inventory for P0 #302. The authoritative runtime registration is absent and the lease is released, so direct player XYZ remains inconclusive without a separately legitimate registered IN_GAME lifecycle.
blakinio added a commit that referenced this pull request Aug 17, 2026
Archive the fresh generation-8 P0 runtime admission after #482 promoted its durable blocker evidence. Release RUNTIME ownership while leaving consumer #302 Draft and semantically inconclusive.

Copy link
Copy Markdown
Owner Author

Coordinator refresh after merged RUNTIME admission PR #482 (a94e931cdc454e0e28c2ef628be23b926c4e3657). Fresh physical controller-plane inventory 32033237388 / 95397745114 on synology-otclient-01 re-measured the canonical state at lease generation 8: lease released, controller task/session null, authoritative runtime-registration.json ABSENT; no process/X11 observation, bootstrap/login, gameplay, mutation or process-memory discriminator executed. This independently confirms the prior blocker rather than inheriting generation 7. P0 canonical disposition remains DIRECT_PLAYER_XYZ=INCONCLUSIVE / BLOCKED_NO_LEGAL_EXISTING_IN_GAME_LIFECYCLE. Do not repeat generic static analysis and do not bootstrap solely for P0. Resume the bounded semantic XYZ discriminator only after a separately legitimate authorized lifecycle creates a current registered exact-client runtime, reaches structurally verified IN_GAME, and a fresh RUNTIME admission passes current authority/identity gates.

Copy link
Copy Markdown
Owner Author

FINAL FRESH RUNTIME HANDOFF — GENERATION 8

Consumer: OTC-20260815-track-a-p0-direct-position / Draft PR #302

A fresh current-state RUNTIME dependency was executed rather than inheriting the historical #467 blocker:

  • task: OTC-20260817-track-a-p0-player-state-admission
  • physical admission run/job: 32033237388 / 95397745114
  • runner: synology-otclient-01
  • exact admitted head: 945d448f41332323bfb2d52fb498110a085b8f43
  • deterministic admission governance: PASS
  • canonical namespace: PRESENT
  • lease: PRESENT, status released, generation 8
  • controller task/session: null / null
  • authoritative runtime-registration.json: ABSENT
  • control metadata unchanged: true
  • process/X11 observation: false / false
  • process-memory access: false
  • client mutation: false
  • bootstrap/login: false / false

The previous #467 snapshot was generation 7; therefore the blocker was freshly re-measured, not blindly reused. Current state advanced to generation 8, but there is still no legal registered exact-client IN_GAME lifecycle that P0 may consume.

Canonical promotion and lifecycle closeout:

Terminal P0 classification under current authority:

DIRECT_PLAYER_XYZ=INCONCLUSIVE
BLOCKED_NO_LEGAL_EXISTING_IN_GAME_LIFECYCLE

Strongest exact-client static candidate remains the TPlayerData-typed route where rbx <- rsi at 0x83658a and signed DWORD values are read from +0x78/+0x7c/+0x80 at 0x836659/0x83667e/0x8366b3 immediately upstream of the exact playerPosition literal reference at 0x8367c1. Representation is three signed 32-bit values. The recovered TPlayerData primary-vptr candidate is 0x308ca70.

This is still only an XYZ-shaped static candidate. Exact live authoritative object identity, stable pointer chain/address derivation, causal movement correlation, independent live structural coordinate comparison, camera/viewport/map-origin/stale-copy negative controls, inverse control, repeatability and restart/relogin stability all remain UNKNOWN / not executed because the required legal current lifecycle does not exist.

Exactly one dependency remains: a separately legitimate canonical lifecycle, established for an independent authorized purpose, that creates a current authoritative registered exact-client runtime and reaches structurally verified IN_GAME. After that exists, RUNTIME must obtain a fresh admission and current Gate A / any required generation rebind / Gate B before executing the bounded read-only P0 semantic discriminator.

Do not bootstrap/login solely for P0, do not create a second logged-in session, and do not promote #302 until the causal semantic proof exists. No world-map extent/mutation/render/server-delivery work was performed by this continuation.

blakinio commented Aug 17, 2026

Copy link
Copy Markdown
Owner Author

P0 continuation checkpoint — read-only same-session RUNTIME package READY

DIRECT_PLAYER_XYZ=INCONCLUSIVE remains unchanged; #302 stays Draft and is not promotion-ready.

New bounded producer tooling

Final Draft head: 3924add0914b09f6c3dd2d131aa50b2b96df34fd.

Added a dedicated RUNTIME-side snapshot helper for the strongest exact-build candidate:

  • .github/scripts/tibia-official-client-re-p0-runtime-snapshot.py
  • helper blob: afd8cd7023ad667421eddce71dbc1575770e0f32
  • exact typed route: TPlayerData primary vptr offset 0x308ca70
  • direct fields: +0x78/+0x7c/+0x80, signed_i32_x3
  • exact client SHA/size + /proc/PID/exe fence
  • records PID, process-start ticks, boot-id hash, main base, all typed object addresses/private-data pointers, direct XYZ and wall/monotonic timestamps
  • /proc/PID/mem opened O_RDONLY only
  • no input/login/session action
  • output explicitly carries process_memory_writes=0 and semantic_player_xyz_proven=false.

Deterministic tests cover signed-i32 decode, /proc/PID/stat field-22 parsing, exact-vptr typed-object selection, direct offsets, invalid private-data rejection, read-only/nonsemantic payload, and source-level absence of write primitives.

Exact-head validation

  • dedicated helper run/job: 32036351518 / 95407516262 = SUCCESS
  • Track A runtime governance: 32036355515 = SUCCESS
  • repository CI: 32036355748
  • CI / Required: 95407800001 = SUCCESS
  • actionlint/yamllint: PASS
  • informational static-analysis jobs: PASS

An earlier CI attempt first hit external GitHub codeload HTTP 429 and then exposed SC2251 in the workflow write-surface guard. The guard was repaired to an explicit fail-closed if grep ...; then exit 1; fi; semantic/runtime behavior of the helper did not change.

Same-session RUNTIME handoff

Durable contract:
docs/agents/evidence/OTC-20260815-track-a-p0-direct-position/20260817-runtime-producer-handoff-v2.md

A bounded cross-consumer request was posted to active RUNTIME PR #475 as comment 5316768394. It requests no extra login and no extra movement: only before / stepped / restored read-only snapshots piggybacking on that task's independently authorized future Right -> Left lifecycle, if and only if its own RUNTIME owner reaches legal exact-client IN_GAME and accepts the sidecar under its current admission.

P0 does not own #475's runtime/branch and will not retry, attach to, or mutate it. The earlier physical attempt 32035722151 / 95405990902 failed before checkout on external HTTP 429, with client execution false. After this checkpoint was written, #475 advanced to head 1b1039ada5ff3fb7d8fd83cc012283b96951fd9f, whose latest change is explicitly a no-client static noise-mask focus-discriminator validation. Its task still reports workflow_mode: static_no_client_prelogin_validator, baseline login consumed 0, and no consumable IN_GAME lifecycle exists yet.

Remaining semantic gate

Still missing:

  • current exact PID/start + current XRes ownership for an actual IN_GAME lifecycle;
  • structurally verified IN_GAME;
  • before/stepped/restored direct observations;
  • independent structural world-coordinate comparison;
  • known-delta + inverse correlation;
  • camera/viewport/map-origin/stale-copy negative controls;
  • repeatability/relogin stability when available.

Exactly one external dependency remains: a RUNTIME owner must independently reach a legal exact-client IN_GAME lifecycle and accept the prepared same-session read-only handoff. No P0-only bootstrap/login or second session is authorized.

Copy link
Copy Markdown
Owner Author

Runtime handoff revalidation (2026-08-17): current producer PR #475 is still not consumable by P0. Its current head is 4a76bc6de5f164026d6fc77fdddbc5a5de4b534b; the Track A worldmap workflow run 32036904362 is queued as Normalized XRes worker binding diagnostic (no client), and the workflow on that exact head executes no client or secrets. The #475 task checkpoint remains runtime_access: ephemeral_isolated, phase baseline_ephemeral_behavioral_login_capture, with baseline_ephemeral_login_consumed: 0, and explicitly requires one later deliberate switch from static validation to the physical baseline before any exact-client IN_GAME lifecycle exists. Handoff comment 5316768394 remains compatible but conditional on that future legal IN_GAME lifecycle.

Therefore the bounded P0 sidecar cannot legally execute yet: there is no fresh exact-client PID/start identity, current XRes-owned IN_GAME process, or same-session Right→Left lifecycle from which S0/S1/S2 can be captured. No P0 login, second client, restart, movement, process-memory access, or world-map research was performed.

DIRECT_PLAYER_XYZ=INCONCLUSIVE

Exactly one missing dependency: #475 must independently reach its already-authorized exact-client structurally verified IN_GAME baseline and keep that same legal lifecycle alive through its existing reversible Right -> Left stimulus; only then may the read-only P0 helper capture S0/S1/S2 plus the already-produced independent structural coordinate control.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

programme:client Oteryn client programme state:stalled No meaningful update within the configured threshold

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant