feat(track-a): continue Surveyor next non-overlap typed reader - #658
Conversation
|
@codex review Fresh independent validator request for exact head |
Autonomous checkpoint — exact-head audit/CI gateInvocation result: WAITING under Exact final candidate head: Verified local/focused gates on this exact code state:
Exact-head GitHub checks observed within the two ordinary checks allowed for this head:
Fresh independent validator request:
Live overlap was refreshed: #475 and #593 remain open, so the explicit world/minimap exclusion remains valid; no competing open UI/settings PR appeared. No runtime/client observation, gameplay input, relogin, client restart, process-control action, process-memory write, credential access, or transaction/economy action was performed in this invocation.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e91504bb8d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
blakinio
left a comment
There was a problem hiding this comment.
Remediation checkpoint for the two findings from review PRR_kwDOTVmdjs8AAAABKddk8A on superseded head e91504bb8dcfcb7d582baf122710981e76c957e0. Current head is 782b5cff0cf5684f77a0c7fba74b308d0a7524c1. AUD-658-001 P1 is fixed by exact accepted key sets plus reconstruction of sanitized static/live dictionaries before telemetry. AUD-658-002 P2 is fixed by removing pre-open resolve() and walking the fixed settings path with directory FDs + O_NOFOLLOW, then validating a regular file owned by the target uid. New hostile extra-field tests plus path-source assertions were added. Post-remediation: focused 8/8 PASS, all Surveyor 59/59 PASS, compileall PASS, collect-all 169/12/7 with privacy PASS, Track A governance PASS, git diff --check PASS. Fresh exact-head independent re-audit remains required; this comment does not self-approve the remediation.
blakinio
left a comment
There was a problem hiding this comment.
Fresh exact-head validator request for 782b5cff0cf5684f77a0c7fba74b308d0a7524c1 after remediation of AUD-658-001 and AUD-658-002. Please independently falsify the full acceptance boundary, not the implementer summary. Recheck especially: exact probe-output allowlists/rebuilt dictionaries; secret/arbitrary-field non-retention; fixed-path no-follow directory-FD traversal and regular-file/uid validation; exact client fence; read-only/no-process-memory/no-GUI/no-login/no-restart scope; collect-all 169/12/7 accounting; tests/workflow assertions; task/governance lifecycle and non-overlap. Do not fetch or execute the proprietary official-client binary and do not access credentials/session material. Report any P0/P1 or other material finding with exact evidence; if none, state zero material findings on this exact head. Physical E2E remains post-merge and must not be claimed by this review.
blakinio
left a comment
There was a problem hiding this comment.
@codex review
Fresh independent validator on exact head 782b5cff0cf5684f77a0c7fba74b308d0a7524c1 only, after remediation of both prior findings. Attempt to falsify acceptance, with special attention to AUD-658-001 output allowlisting/rebuild and AUD-658-002 no-follow fixed-path opening, plus privacy, exact-fence, read-only authority and collect-all accounting. Do not access proprietary client binaries, credentials or session material. Report concrete material findings, or state zero material findings on this exact head. Do not claim post-merge physical E2E.
blakinio
left a comment
There was a problem hiding this comment.
Implementation/remediation is complete on 782b5cff0cf5684f77a0c7fba74b308d0a7524c1; PR is Ready. Awaiting only fresh independent exact-head review and exact-head GitHub checks before merge. No runtime access has occurred on this implementation head.
|
@codex review Fresh independent validator request for exact head |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Objective
Continue Surveyor v2 from current main after terminal
OTC-20260821-surveyor-action-protocol-reader, recompute the live repository/static typed-reader gaps, select the highest-value safe P0/P1 non-overlapping reader, and carry that one slice through full terminal closeout.Current authority
Track A discovery is admitted as
runtime_access:none. No official-client runtime observation or mutation is authorized by the current checkpoint. The owner explicitly forbids gameplay input, relogin, client restart and process-memory writes; credentials, character selection, process control, injection, network mutation and economy actions are likewise outside scope.Selection rule
world_minimap_typed_readeris excluded while live ownership overlap remains on PRs #475/#593 or successors. The selected reader will be recorded only after a fresh repository-only--collect-alland live overlap check.Planned terminal gates
Focused/static validation, exact-current-build resolver, collect-all/privacy, fresh independent audit, exact-head CI/governance, protected merge, trusted-main read-only physical E2E, durable evidence, related-PR cleanup, task archival and ownership release.
Task:
OTC-20260821-surveyor-next-nonoverlap-gap.