Skip to content

research(track-a): stage missing P2 ClientMessageProcessor identity evidence - #449

Closed
blakinio wants to merge 12 commits into
mainfrom
research/OTC-20260817-track-a-p2-clientprocessor-sanitized-evidence
Closed

research(track-a): stage missing P2 ClientMessageProcessor identity evidence#449
blakinio wants to merge 12 commits into
mainfrom
research/OTC-20260817-track-a-p2-clientprocessor-sanitized-evidence

Conversation

@blakinio

@blakinio blakinio commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Draft-only bounded evidence producer for consumer #310. Coordinator disposition: ACCEPT / SOURCE_PR_CLOSE_UNMERGED_AFTER_FINAL_CI.

Task: OTC-20260817-track-a-p2-clientprocessor-sanitized-evidence
Base: main@8c9486e2c6109a7a39b564804c8acd707659b5e0
Execution class: github_hosted; runtime_access: none; physical E2E: false; mutation authorized: false.

Accepted evidence generation

Exactly one source/hosted evidence generation ran:

  • run 32005141186 = SUCCESS at exact evidence head 1b615736726049e70c902a88d0fde5004044e7e0;
  • source job 95312954329 = SUCCESS;
  • source artifact 9279753620, digest sha256:6c970c23aa95856698eb71024937ed847502fb1f040701ce04c632da32c38d32;
  • hosted job 95313213503 = SUCCESS;
  • final artifact 9279759553, digest sha256:8228d6c281cf99f45f5c880b76e7a2817130156fde4cc892a402eccf4af10528;
  • evidence-head Track A governance 32005159534 = SUCCESS;
  • evidence-head repository CI 32005159706 = SUCCESS.

The coordinator independently re-decoded the bounded source artifact rather than accepting generated result.json as proof. It closes #310 findings TACOORD-310-20260817-001 and TACOORD-310-20260817-002.

Accepted bounded result:

  • persistent QBuffer -> TProtocolClientMessageProcessor this+0x18: PROVEN;
  • processor +0x10@0xc2df80 direct QIODevice::readAll: PROVEN;
  • same stack message -> TGameserverNetworkPacketRawDataProcessor+0x10@0xb47130: PROVEN;
  • RawDataProcessor in-place QByteArray transform: PROVEN;
  • same message -> canonical TGameserverDualConnection +0x80/+0x78: PROVEN;
  • local protocol stage order: PROVEN_PARTIAL.

Remain UNKNOWN: framing, sequence, compression, encryption, final binary egress, final socket ownership.

Safety boundary

The Synology source stage did not perform static analysis/disassembly/semantic classification. It only exact-fenced the retained regular file and emitted bounded hex file windows. All disassembly/semantic analysis ran on ubuntu-latest. No client process, process memory, canonical state, X11/VNC, login/session, gameplay or raw client/package upload was used. Quarantined run 31944051248 was not evidence.

Closeout repair

A later task-only checkpoint accidentally omitted mandatory runtime_access:none admission fields; Track A governance correctly failed in run 32005722504. The checkpoint alone was repaired at head dbd75c152957ae945804f81313f485430b6cb768; evidence generation was not rerun. Fresh Track A governance 32006193081 is SUCCESS. Repository CI 32006193202 is the remaining final source-PR check generation.

Consumer #310 is intentionally closed unmerged as ACCEPT_WITH_EDITS; current-main coordinator promotion is PR #450. This producer workflow/script are one-shot evidence tooling and will not be merged to main.

E2E: NOT_APPLICABLE — static evidence producer only; no runtime behavior changed.

Copy link
Copy Markdown
Owner Author

Coordinator terminal producer disposition: ACCEPT / CLOSE_UNMERGED.

Final source-PR head dbd75c152957ae945804f81313f485430b6cb768 has Track A governance 32006193081 = SUCCESS and repository CI 32006193202 = SUCCESS; review threads = 0. The only evidence generation remained run 32005141186 at evidence head 1b615736726049e70c902a88d0fde5004044e7e0; no second source read/disassembly run occurred.

The source artifact was independently re-decoded and closes #310 findings TACOORD-310-20260817-001/-002. Durable accepted evidence is being integrated by current-main coordinator PR #450. This one-shot producer workflow/script are intentionally not merged.

E2E: NOT_APPLICABLE — static evidence staging only; no runtime behavior changed. Ownership is released to coordinator closeout #450.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant