Skip to content

docs(track-a): promote historical auth-session static evidence - #585

Merged
blakinio merged 3 commits into
mainfrom
docs/OTC-20260817-auth-session-flow-promotion
Aug 19, 2026
Merged

docs(track-a): promote historical auth-session static evidence#585
blakinio merged 3 commits into
mainfrom
docs/OTC-20260817-auth-session-flow-promotion

Conversation

@blakinio

Copy link
Copy Markdown
Owner

Objective

Promote the independently audited historical exact-build auth/session static evidence from source Draft #498 without merging its stale history or its governance-invalid runtime-sensitive workflow.

Source audit

Source head: 43438bb8ed42841c8a9f5bc2d0e76d05b466a958
Coordinator review: 4971599610 = ACCEPT_WITH_EDITS.

Accepted evidence is strictly fenced to historical official Linux client:

15.32.df7b29
size 51965216
SHA256 e6c244bd39fe2e0632f6f000efd3147164696efa8e901718668e0442325ff7fe

Addresses/PMFs/vtables are not current-build addresses for later ed5469....

Clean promotion

Base: main@5a1c3f448b850fa388275f5b7af7be9218e132ff
Head: a125dfedc515d3c87499b3800a3c5704880b501e

ahead_by = 3
behind_by = 0
changed paths = exactly 9 docs/evidence/archive paths
runtime-sensitive workflow promoted = false

Seven accepted source phase/research documents are byte-identical source blobs. Coordinator-owned additions are the independent audit and archive checkpoint.

Bounded accepted result

CAN_SKIP_LOGIN_FORM: PARTIAL
CAN_SKIP_PASSWORD_ENTRY: PARTIAL
CAN_REUSE_SESSION: YES (architectural/native retained-state path only)
PASSWORD_REQUIRED_FOR_GAME_LOGIN: UNKNOWN
DIRECT_CHARACTER_LOGIN_POSSIBLE: YES, conditional on valid retained auth/play-session state

The static evidence establishes separation between initial credential submission, TPlaySessionData-bearing account-auth success, native retained-state character-selection routing, selected-character progression and later existing-credentials game connection. Persistence store, expiry/refresh, exact game-login credential fields and password presence/absence remain UNKNOWN.

The source's corrected receiver/producer identifications are preserved; no adapter/QMeta target is promoted as a final serializer.

Delivery repair

Source governance 32058753745 failed because the source PR itself added .github/workflows/tibia-official-client-re-auth-session-static.yml without an active admission task. This clean promotion excludes that workflow entirely rather than weakening governance or inventing runtime authority.

Safety

Repository/static only: runtime_access:none; no client execution, credentials, login, GUI input, gameplay, transaction, process-memory access or runtime mutation.

After promotion merge, source #498 will be closed unmerged as superseded and the archive finalized in a lifecycle-only closeout.

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Coordinator exact-head promotion review: PASS. Head a125dfedc515d3c87499b3800a3c5704880b501e; exactly 9 docs/evidence/archive paths; source evidence/research blobs preserved exactly; source workflow intentionally excluded; CI 32248049388 = SUCCESS; zero review threads; behind_by=0. Historical addresses remain fenced to e6c244bd...; all password/persistence/expiry UNKNOWNs preserved.

@blakinio
blakinio merged commit 0130493 into main Aug 19, 2026
8 checks passed
@blakinio
blakinio deleted the docs/OTC-20260817-auth-session-flow-promotion branch August 19, 2026 11:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant