Skip to content

docs(track-a): promote conclusive XRes exact-client PID identity - #457

Merged
blakinio merged 11 commits into
mainfrom
diag/OTC-20260817-track-a-xres-raw-pid-identity-physical-authorized-v2
Aug 17, 2026
Merged

docs(track-a): promote conclusive XRes exact-client PID identity#457
blakinio merged 11 commits into
mainfrom
diag/OTC-20260817-track-a-xres-raw-pid-identity-physical-authorized-v2

Conversation

@blakinio

@blakinio blakinio commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Track A RUNTIME — conclusive raw XRes PID identity

Task: OTC-20260817-track-a-xres-raw-pid-identity
Base: trusted main@60ab740872d52f3f7c4802d49fd5275a9968d085

The one authorized v2 isolated physical launch is complete. The terminal PR no longer contains any one-shot runtime workflow or patcher; it contains only the durable physical evidence, independent final audit and terminal active-task checkpoint.

Physical result

Run 32015479835, physical job 95344000918, runner synology-otclient-01:

exact_client_pid: 13648
xres_version: 1.2
unique_viewable_1920x1080_xid: 0x00c00011
query_client_ids_reply_client_base: 0x00c00000
query_client_ids_mask: LocalClientPid
query_client_ids_value_length_bytes: 4
query_client_ids_pid: 13648
cleanup: COMPLETE
classification: XRES_PROVES_VIEWABLE_WINDOW_OWNED_BY_EXACT_CLIENT

The GitHub physical job is red only because the persistent helper still imposed an invalid requirement that the returned CLIENTIDVALUE.spec.client echo the exact queried resource ID. The raw reply was retained before helper interpretation. Primary XRes/X-server semantics show the server selects the owner from the queried resource and returns the owning client's resource-base; the returned LocalClientPid 13648 equals the exact launched/fenced process PID 13648.

Final audit: material_findings_open_for_this_task: 0. The remaining helper exact-echo assumption is LOW, nonblocking, hosted-fixable from the retained real reply, and requires no additional physical launch.

Safety: no canonical registration/lease/state, credentials, login, gameplay, process-memory access or client-byte mutation. Both v1 and v2 launch budgets are consumed; no further PID-identity launch is authorized.

Terminal changed paths are exactly:

  • docs/agents/tasks/active/OTC-20260817-track-a-xres-raw-pid-identity.md
  • docs/agents/evidence/OTC-20260817-track-a-xres-raw-pid-identity/20260817-v2-physical-pid-identity.md
  • docs/agents/evidence/OTC-20260817-track-a-xres-raw-pid-identity/20260817-v2-final-audit.md

After protected merge, a separate archive-only closeout will move the task active→archive and release ownership. Downstream RUNTIME work may consume the proven identity only under a fresh admission.

@blakinio blakinio changed the title diag(track-a): run raw XRes PID identity v2 docs(track-a): promote conclusive XRes exact-client PID identity Aug 17, 2026
@blakinio blakinio added the programme:client Oteryn client programme label Aug 17, 2026
@blakinio
blakinio marked this pull request as ready for review August 17, 2026 09:40
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@blakinio
blakinio enabled auto-merge (squash) August 17, 2026 09:40
@blakinio
blakinio merged commit 16c6fb6 into main Aug 17, 2026
11 checks passed
@blakinio
blakinio deleted the diag/OTC-20260817-track-a-xres-raw-pid-identity-physical-authorized-v2 branch August 17, 2026 09:41
blakinio added a commit that referenced this pull request Aug 17, 2026
Consume the promoted #457 XID-to-PID proof and #461 client-base semantics in the canonical worker window identity path. Add fail-closed raw-XRes ownership resolution, exact-anchor worker adaptation, deterministic regression coverage, and hosted validation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

programme:client Oteryn client programme

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant