Skip to content

diag(track-a): prove XRes window ownership on current main - #442

Closed
blakinio wants to merge 8 commits into
mainfrom
diag/OTC-20260816-track-a-xres-window-identity-v2
Closed

diag(track-a): prove XRes window ownership on current main#442
blakinio wants to merge 8 commits into
mainfrom
diag/OTC-20260816-track-a-xres-window-identity-v2

Conversation

@blakinio

@blakinio blakinio commented Aug 16, 2026

Copy link
Copy Markdown
Owner

Current-main replacement for XRes research Draft #440.

Task: OTC-20260816-track-a-xres-window-identity.
Base: exact trusted main@845adabba5f6d2bfecb6d54bc13834c47cc61c94 after unrelated World Observation/Atlas docs #439 and lifecycle #441.

Source #440 never launched the exact client: its accidental physical-job scheduling was stopped by the stale-base fence before runtime launch. Its corrected XRes observer then passed hosted preflight and Track A governance. GitHub computed a conflict-free merge ref against current main; that exact tree was replayed linearly and only task branch metadata changed.

Purpose is unchanged: rebuild the immutable #438 semantic startup script, add only an X-Resource 1.2 QueryClientIds/LocalClientPid observer for raw XIDs, and compare the returned PID directly with the exact fenced client PID.

Physical execution is disabled on this ...-v2 branch by branch-name gate. This PR is hosted-preflight only. Once hosted XRes preflight, Track A governance and required CI are green and main is reread stable, a separate ...-authorized branch/PR may be created for exactly one physical generation. No body-text token is used as authority.

No canonical state, credentials/login/gameplay, Track B/#303 surface, client backend change, explicit GLX flag, client-side DRI override, or global process inventory is allowed.

Copy link
Copy Markdown
Owner Author

RUNTIME TERMINAL HANDOVER — DRAFT_NOT_PROMOTED

Exact final head: 80bd75a1352ef1ffe84c3dcc34bf51a0cf0a7c54.

Bounded physical discriminator retained from run 31973388722, job 95229260820 on synology-otclient-01: same-job Track A admission/base/source/support fences passed, exact isolated client launched once, raw viewable X11 window was reproduced, and the XRes observer directly found libxcb=true, libxcb_res=false, libX11=true at t05/t15/t35. Therefore QueryClientIds(LocalClientPid) was not executed and exact PID ownership remains UNKNOWN. Generated classification: XRES_IDENTITY_UNRESOLVED; bounded classification: PROVEN_XRES_IDENTITY_UNRESOLVED_BECAUSE_LIBXCB_RES_HELPER_UNAVAILABLE_ON_RUNNER_FIXED_ALLOWLIST.

The discriminator reached PASS_DISCRIMINATOR_CAPTURED and CLEANUP=COMPLETE before a newer hardening generation cancelled the job during post-job handling. Source #440's stale-base physical scheduling did not launch the client: its base fence refused before generated-script execution. Hardened follow-up run 31973490169 passed hosted preflight and SKIPPED physical execution. The unsafe PR-body substring gate was replaced with an authorized-branch suffix gate; the one-shot workflow and both patchers are removed. Task is status: ready, mutation_authorized:false; no second client launch is authorized.

Durable evidence: docs/agents/evidence/OTC-20260816-track-a-xres-window-identity/20260816-xres-helper-unavailable.md.

Exact-final-head validation:

  • Track A governance 31973655155 = SUCCESS;
  • repository CI 31973655294 = SUCCESS;
  • CI / Required job 95229833967 = SUCCESS;
  • review threads = 0.

Next action is support-only and already separately executed by #443: fixed-path inventory for libxcb-res/libXRes/protocol basis. Do not retry client identity or change the canonical window contract from this Draft.

Copy link
Copy Markdown
Owner Author

Coordinator review disposition: ACCEPT / promotion staged in #444.

I independently re-read physical job 95229260820 from run 31973388722. Direct evidence confirms admission/base/source/support fences passed, the exact isolated client launched once, the raw full-display VIEWABLE XID was reproduced, and the observer reported libxcb=True, libxcb_res=False, libX11=True at t+05/t+15/t+35. Therefore QueryClientIds(LocalClientPid) did not execute and exact XID→PID ownership remains UNKNOWN. The discriminator reached PASS_DISCRIMINATOR_CAPTURED and CLEANUP=COMPLETE before later post-job cancellation from the hardening generation.

Accepted classification: PROVEN_XRES_IDENTITY_UNRESOLVED_BECAUSE_LIBXCB_RES_HELPER_UNAVAILABLE_ON_RUNNER_FIXED_ALLOWLIST.

Source #440's stale-base physical scheduling was separately refused before generated-script/client execution. No canonical identity relaxation or additional client launch is promoted from this result. This source Draft will be closed superseded only after #444 merges.

Copy link
Copy Markdown
Owner Author

Coordinator final disposition: ACCEPTED_AND_PROMOTED_BY_444 / CLOSE_SUPERSEDED_UNMERGED.

Canonical promotion #444 merged as 7540a679420689c388d9d11125c9fd8846956a10. The bounded helper-unavailable discriminator is now promoted on trusted main; exact viewable-XID PID ownership remains UNKNOWN and no second client launch is authorized from this task. This researcher Draft must not be merged from its source branch. The bounded child task will now be archived/released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

programme:client Oteryn client programme

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant