Skip to content

research(track-a): recover native auth and session flow - #498

Closed
blakinio wants to merge 26 commits into
mainfrom
docs/OTC-20260817-track-a-auth-session-flow-static
Closed

research(track-a): recover native auth and session flow#498
blakinio wants to merge 26 commits into
mainfrom
docs/OTC-20260817-track-a-auth-session-flow-static

Conversation

@blakinio

@blakinio blakinio commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Terminal source disposition — superseded by clean coordinator promotion #585

Status: CLOSED UNMERGED AS SUPERSEDED. Source head 43438bb8ed42841c8a9f5bc2d0e76d05b466a958.

Coordinator review 4971599610 = ACCEPT_WITH_EDITS; zero material factual findings after repair. Accepted facts remain strictly historical exact-build evidence for 15.32.df7b29 / 51965216 / e6c244bd... and are not current-build addresses.

Source delivery governance 32058753745 failed because the source PR added a runtime-sensitive workflow without an active admission task. That workflow was deliberately not promoted. Clean promotion #585 carried only seven exact source evidence/research blobs plus coordinator audit/archive, passed generic CI 32248049388, zero threads, behind_by=0, review 4971626535, and squash-merged as 0130493ca364cd6eaf2637c1945c0f25ad2cf137.

Bounded conclusions remain: CAN_SKIP_LOGIN_FORM=PARTIAL, CAN_SKIP_PASSWORD_ENTRY=PARTIAL, architectural CAN_REUSE_SESSION=YES, PASSWORD_REQUIRED_FOR_GAME_LOGIN=UNKNOWN, direct character login conditional on valid retained state. No runtime/login/credentials were used for coordinator closeout.

@blakinio blakinio added the programme:client Oteryn client programme label Aug 17, 2026

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh coordinator audit: ACCEPT_WITH_EDITS.

The historical exact-build facts are accepted at source head 43438bb8ed42841c8a9f5bc2d0e76d05b466a958, fenced strictly to official Linux client 15.32.df7b29 / 51965216 / e6c244bd39fe2e0632f6f000efd3147164696efa8e901718668e0442325ff7fe.

Independent source-producer review confirms the exact packed/client hash gates, QMeta rows/targets, direct-to-character-selection state-machine route, loginSuccessful(TCharacterList,TWorldList,TPlaySessionData), existing-credentials game connection surface, selected-character handoff, corrected login-protocol queue receiver chain, reconnect/disconnect surface, and preserved UNKNOWNs. The source correctly fixes earlier false identifications (0xcf2ca0 is a QMeta static-metacall case rather than the implementation PMF; 0xbd36a0 is an adapter/delegator rather than a proven final serializer).

Required closeout edits:

  1. Historical-build fence: every address/offset/PMF/vtable claim remains historical exact-build evidence only. None is reusable as a current-build address on ed5469...; later #556/#528 corroborate architecture but do not rebase old offsets.
  2. Source delivery defect: exact source governance run 32058753745 failed because .github/workflows/tibia-official-client-re-auth-session-static.yml is a runtime-sensitive path without an active admission task bound to the PR branch. This is not a factual evidence failure, but the workflow must not be promoted. Clean promotion should contain durable evidence/research docs only plus coordinator audit/archive.
  3. Preserve the source's bounded conclusions: CAN_SKIP_LOGIN_FORM=PARTIAL, CAN_SKIP_PASSWORD_ENTRY=PARTIAL, CAN_REUSE_SESSION=YES only as an architectural/native-path statement, PASSWORD_REQUIRED_FOR_GAME_LOGIN=UNKNOWN, and persistence/expiry/refresh semantics UNKNOWN.

Source ancestry is stale (behind_by=50 against current main). Use clean current-main promotion; then close source unmerged as superseded. Open material factual findings after these edits: 0.

@blakinio blakinio closed this Aug 19, 2026
blakinio added a commit that referenced this pull request Aug 19, 2026
Finalize #498 historical auth-session evidence lifecycle and release ownership.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

programme:client Oteryn client programme

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant