Skip to content

ci(track-a): complete contained runner toolroot with x11vnc - #384

Merged
blakinio merged 6 commits into
mainfrom
ci/OTC-20260816-track-a-runner-support-x11vnc-repair
Aug 16, 2026
Merged

ci(track-a): complete contained runner toolroot with x11vnc#384
blakinio merged 6 commits into
mainfrom
ci/OTC-20260816-track-a-runner-support-x11vnc-repair

Conversation

@blakinio

Copy link
Copy Markdown
Owner

Track A bounded runner-support repair

Task: OTC-20260816-track-a-runner-support-x11vnc-repair
Base: exact trusted main@c2e1466b4c0ac11deb96b104830f90aae9c35a97.
Execution: one bounded physical synology-otclient-01 support-filesystem repair; no official-client runtime access.

Read-only inventory #382/#383 proved the current contained /work/_otclient_tibia_re_state/toolroot has Xvfb, xdotool, XKB and libproxychains but lacks only x11vnc, while the runner has /usr/bin/x11vnc from installed package 0.9.16-10.

This task preserves the hardened one-root worker contract instead of weakening it:

  • verifies the source is exact /usr/bin/x11vnc, regular/executable, root-owned and non-group/world-writable;
  • verifies dpkg ownership, exact package version and package file verification;
  • re-verifies the existing contained root and its other required components;
  • refuses any unexpected different target;
  • atomically stages a bit-identical copy into /work/_otclient_tibia_re_state/toolroot/usr/bin/x11vnc;
  • verifies source/target SHA equality and then runs only the trusted worker's contract-test toolroot resolver;
  • removes the staged target automatically if any post-copy check fails.

No /proc inventory, canonical registration/lease/session state, client process/file, X11/VNC runtime, network/game/login state, credentials or Track B are observed or mutated. After one successful/terminal run the workflow will be removed before checkpoint updates.

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

COORDINATOR ACCEPT. Read-only inventory #382/#383 proved the persistent contained toolroot lacked only x11vnc. This repair preserved the hardened one-root/realpath-containment worker: first run 31954234775 failed before copy on an over-broad dpkg validator; the evidence-based repair allows only the four exact documentation/manpage omissions while still failing any executable/package payload mismatch. Second run 31954295453 / job 95182427755 = SUCCESS: target was absent, package-owned /usr/bin/x11vnc 0.9.16-10 was atomically copied, source/target SHA-256 both 4954921ae9c4e2bf7061603eb6a2d52c2292a0973eb2da5d6f48a9bd49570ffc, and trusted worker contract-test resolved /work/_otclient_tibia_re_state/toolroot. One-shot workflow is removed. Exact final head c069097 has Track A governance 31954434181 = SUCCESS and repository CI 31954434413 = SUCCESS; review threads/material findings = 0. No official-client/canonical runtime/login/credential surface was touched. Approved for protected ready-state promotion.

@blakinio
blakinio marked this pull request as ready for review August 16, 2026 15:02
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@blakinio
blakinio enabled auto-merge (squash) August 16, 2026 15:02
@blakinio
blakinio merged commit da790a9 into main Aug 16, 2026
17 checks passed
@blakinio
blakinio deleted the ci/OTC-20260816-track-a-runner-support-x11vnc-repair branch August 16, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant