research(track-a): resolve P2 DualConnection egress boundary - #458
research(track-a): resolve P2 DualConnection egress boundary#458blakinio wants to merge 14 commits into
Conversation
|
Final researcher handoff / post-CI drift check Researcher package is Final validated state:
After those checks, Research result remains bounded negative evidence: No semantic claim in this Draft is canonical until coordinator disposition. |
blakinio
left a comment
There was a problem hiding this comment.
Coordinator-facing independent review checkpoint for OTCLIENT-TIBIA-RE-P2-NETWORK.
Disposition: ACCEPT_WITH_EDITS for the bounded negative result; NOT YET CANONICAL because PR #458 remains a researcher Draft and its evidence path is absent from current main.
Independently verified:
- source artifact 9283851546 ZIP sha256 = 7e03ed66bff463e288b5f2414bad8190a27bf421161ba1218c2a74d7342baeab;
- final artifact 9283858910 ZIP sha256 = 2df8405269431397f3da0601ef24d9a9a8787dc33f3b5fdd43774f1eca36922c;
- exact-client fence = 15.32.df7b29 / 51965216 / e6c244bd39fe2e0632f6f000efd3147164696efa8e901718668e0442325ff7fe;
- fresh independent objdump of the staged source bytes confirms b40370 returns by b40421 and b40630 is a distinct function entry;
- b40630 preserves original rsi in r12 and original this in rbx; b4066b calls 0x4de370 with rdi=rbx and rsi=r12;
- direct QTcpSocket sink at b4066b is disproven by receiver provenance;
- DualConnection +0x78/+0x80 staged windows contain no direct call to b40630;
- nested calls b56c93 and b57042 remain untyped by the available artifacts, therefore reachability to b40630 remains UNKNOWN;
- PR head c3a3d83 has Track A governance run 32018496831 SUCCESS and CI run 32018496866 SUCCESS; changed-file inventory is exactly the three declared P2 files; unresolved review threads = 0.
Required edits before promotion:
- Promote only the negative/corrective claims above; do not promote b40630 reachability, final egress, socket ownership, framing, sequence, compression, or encryption.
- Preserve the negative controls: b46bd0 non-gameplay QString/newline path, c33259 non-network, b5b880 superseded, quarantined run 31944051248 excluded.
- Next smallest falsifiable frontier: type the final nested receiver used by the b56c93/b57042 virtual +0x10 calls (including exact vtable identity/member provenance) and test whether its +0x10 target is b40630 or another concrete binary-write stage. Existing artifacts are insufficient for that edge, so absence of proof remains UNKNOWN rather than a replacement sink claim.
Terminal P2 state from this review: DUALCONNECTION_TO_BINARY_EGRESS=UNKNOWN; FINAL_BINARY_EGRESS=UNKNOWN; FINAL_SOCKET_OWNER=UNKNOWN; FRAMING=UNKNOWN; SEQUENCE=UNKNOWN; COMPRESSION=UNKNOWN; ENCRYPTION=UNKNOWN.
|
Coordinator disposition: ACCEPT_WITH_EDITS. Independent verification did not rely on the researcher summary. I checked the exact source/hosted evidence generation ( Accepted bounded result:
The original Canonical promotion is PR #481. It also assigns the next smallest frontier |
|
Coordinator promotion #481 merged as |
Draft-only Track A
P2-NETWORKresearcher forOTC-20260817-track-a-p2-dual-precondition-egress.Status:
DRAFT_NOT_PROMOTED / READY_FOR_COORDINATOR_REVIEW.Promotion authority: coordinator only — this PR intentionally remains Draft and must not self-merge.
Exact final state
main@8a52fe4af6a03fca29a831ae4fae4c3936cf025c;c3a3d8339a9fb769847011ffb76662688d91f06c;0 / 0;32018496831 = SUCCESS;32018496866 = SUCCESS;CI / Required: job95353000509 = SUCCESS.A flawed intermediate restack had retained stale copies of unrelated main paths. That was repaired before final validation: the branch tree was rebuilt from current main plus exactly the three P2 files and ancestry was bound to current main through
3600f6c8927484c30b4a7c97ef411ab0c0ce0fae. The final PR diff contains only:docs/agents/evidence/OTC-20260817-track-a-p2-dual-precondition-egress/20260817-dual-egress-discriminator.md;docs/agents/evidence/OTC-20260817-track-a-p2-dual-precondition-egress/result.json;docs/agents/tasks/active/OTC-20260817-track-a-p2-dual-precondition-egress.md.Objective
Test the historical
0xb4066bQIODevice::write(QByteArray const&)candidate as a concrete gameplay binary/socket egress boundary after the coordinator-promoted #450 same-message chain.Promoted input remains:
Evidence generation
Exactly one bounded generation ran on exact experiment head
37c455f2ab3170457a0d084a7745eaa42e28aff1:32016842999 = SUCCESS;95348018877 = SUCCESS;95348295109 = SUCCESS;9283851546, digestsha256:7e03ed66bff463e288b5f2414bad8190a27bf421161ba1218c2a74d7342baeab;9283858910, digestsha256:2df8405269431397f3da0601ef24d9a9a8787dc33f3b5fdd43774f1eca36922c;32016848906 = SUCCESS.Exact client fence:
15.32.df7b29;51965216;e6c244bd39fe2e0632f6f000efd3147164696efa8e901718668e0442325ff7fe.Source staging verified the exact regular file and copied only three bounded executable-file windows totalling 3616 bytes. It did no disassembly/semantic classification, accessed no client process/process memory/canonical state, executed no client and uploaded no raw executable/package. Semantic disassembly ran on GitHub-hosted Ubuntu.
runtime_access: none; physical E2E is not applicable.Accepted non-quarantined #310 artifact
9252025461was independently re-hashed to its canonical digestsha256:2a866247558b079944d81c9ad33bd4c5361c8144a7f367b273ab3bc19a080991and used only to cross-check exact-client PLT identities0x4dac00 = QBuffer::buffer()and0x4de370 = QIODevice::write(QByteArray const&). Quarantined run31944051248is not proof.Bounded result
Fresh exact bytes correct the historical broad-window interpretation:
0xb40370returns on visible paths by0xb40421;0xb40630is a distinct function entry;0xb4066bis not inside the0xb40370/TGameserverDualConnection +0x90function.At the distinct
0xb40630entry, exact SysV register dataflow establishes:Research classifications:
b4066b_inside_b40370_plus_0x90_function:DISPROVEN;b40630_distinct_function_entry:FACT;b4066b_qiodevice_write_callsite:FACT;FACT = b40630 this/rbx, structurally QBuffer/QIODevice-compatible; exact dynamic subtypeUNKNOWN;FACT = original b40630 second argument/rsi;QTcpSocket*sink at0xb4066b:DISPROVEN;UNKNOWN;+0x78/+0x80to0xb40630:UNKNOWN.Fresh
+0x78/+0x80windows contain no direct call to0xb40630. Nested indirect+0x10calls at0xb56c93and0xb57042remain untyped by this bounded evidence, so vtable adjacency/range proximity is not promoted as reachability.Initial H1 —
0xb4066bis the concrete binary gameplay egress candidate reachable after the promoted same-message handoff — isDISPROVEN_IN_STATED_FORM.Still UNKNOWN
No replacement sink is invented.
Negative controls remain:
0xb46bd0is a proven QString/local-8-bit newline write throughTGameserverTCPConnection::QTcpSocket*but not binary gameplay-frame proof;0xc33259is DISPROVEN QMatrix4x4/non-network;0xb5b880is SUPERSEDED.Cleanup / handover
The one-shot workflow and slicer ran exactly once and were removed after evidence consumption; they are absent from the final diff.
Researcher material findings open:
0.E2E:
NOT_APPLICABLE— static exact-file/disassembly research only, no live runtime/network observation or mutation.Next action: coordinator must independently inspect artifacts
9283851546/9283858910and the durable evidence, then classify this DraftACCEPT,ACCEPT_WITH_EDITS,RETURN_FOR_EVIDENCE, orREJECT/SUPERSEDE. No P2 semantic claim from this Draft is canonical until that coordinator promotion step.