Skip to content

feat(track-a): continue Surveyor next non-overlap typed reader - #658

Merged
blakinio merged 5 commits into
mainfrom
feat/OTC-20260821-surveyor-next-nonoverlap-gap
Aug 21, 2026
Merged

feat(track-a): continue Surveyor next non-overlap typed reader#658
blakinio merged 5 commits into
mainfrom
feat/OTC-20260821-surveyor-next-nonoverlap-gap

Conversation

@blakinio

Copy link
Copy Markdown
Owner

Objective

Continue Surveyor v2 from current main after terminal OTC-20260821-surveyor-action-protocol-reader, recompute the live repository/static typed-reader gaps, select the highest-value safe P0/P1 non-overlapping reader, and carry that one slice through full terminal closeout.

Current authority

Track A discovery is admitted as runtime_access:none. No official-client runtime observation or mutation is authorized by the current checkpoint. The owner explicitly forbids gameplay input, relogin, client restart and process-memory writes; credentials, character selection, process control, injection, network mutation and economy actions are likewise outside scope.

Selection rule

world_minimap_typed_reader is excluded while live ownership overlap remains on PRs #475/#593 or successors. The selected reader will be recorded only after a fresh repository-only --collect-all and live overlap check.

Planned terminal gates

Focused/static validation, exact-current-build resolver, collect-all/privacy, fresh independent audit, exact-head CI/governance, protected merge, trusted-main read-only physical E2E, durable evidence, related-PR cleanup, task archival and ownership release.

Task: OTC-20260821-surveyor-next-nonoverlap-gap.

@blakinio
blakinio marked this pull request as ready for review August 21, 2026 19:53

Copy link
Copy Markdown
Owner Author

@codex review

Fresh independent validator request for exact head e91504bb8dcfcb7d582baf122710981e76c957e0 only. Attempt to falsify the task acceptance rather than confirm the implementer narrative. Inspect the complete PR diff and repository contracts directly, with particular attention to: non-overlap selection, ui_settings_typed_reader fail-closed behavior, exact-build fences, fixed-path/read-only filesystem access, payload-shape validation, privacy/secret retention, absence of process-memory writes/gameplay/relogin/restart authority, collect-all gap accounting, tests/workflow assertions, and lifecycle/governance consistency. Do not fetch, upload, execute, or request the proprietary official-client binary or any credentials/session material. Report concrete P0/P1 or otherwise material findings with exact paths/lines; if none, state that no material findings were found on this exact head. This review is pre-merge only; it must not claim physical E2E PASS.

Copy link
Copy Markdown
Owner Author

Autonomous checkpoint — exact-head audit/CI gate

Invocation result: WAITING under ANTI_STALL_AND_EXECUTION_BUDGET.md; implementation remains active and no completion is claimed.

Exact final candidate head: e91504bb8dcfcb7d582baf122710981e76c957e0.

Verified local/focused gates on this exact code state:

  • ui_settings_typed_reader focused tests: 6/6 PASS;
  • all Surveyor tests: 57/57 PASS;
  • repository-only collect-all: 169 rows / 12 aliases / 7 missing readers / privacy PASS;
  • Track A runtime-governance local validator: PASS;
  • git diff --check: PASS;
  • worktree clean after removal of generated __pycache__.

Exact-head GitHub checks observed within the two ordinary checks allowed for this head:

  • Track A agent runtime governance 32520893047: SUCCESS;
  • Track A Surveyor tests 32520893148: SUCCESS;
  • repository CI 32520893379: still IN_PROGRESS at the second permitted ordinary state check.

Fresh independent validator request:

  • request comment 5374675708 targets exact head e91504bb8dcfcb7d582baf122710981e76c957e0 only;
  • chatgpt-codex-connector[bot] acknowledged it with eyes;
  • after the two permitted post-request external-state checks, no review submission exists yet, so audit PASS is not claimed.

Live overlap was refreshed: #475 and #593 remain open, so the explicit world/minimap exclusion remains valid; no competing open UI/settings PR appeared.

No runtime/client observation, gameplay input, relogin, client restart, process-control action, process-memory write, credential access, or transaction/economy action was performed in this invocation.

next_action: in a fresh continuation, first re-read #658 without trusting this checkpoint. If a Codex validator review now exists, require it to match exact head e91504bb8dcfcb7d582baf122710981e76c957e0 and resolve any material findings. Re-read exact-head CI 32520893379; if audit + all required checks + zero unresolved threads pass and main/head remain safe, merge #658. Then run the trusted-main Track A Surveyor v2 read-only physical acceptance, persist sanitized evidence, archive the task/release ownership, and merge the lifecycle closeout PR.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e91504bb8d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/tibia_re_surveyor/ui_settings.py
Comment thread tools/tibia_re_surveyor/ui_settings.py Outdated
@blakinio
blakinio marked this pull request as draft August 21, 2026 20:06

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation checkpoint for the two findings from review PRR_kwDOTVmdjs8AAAABKddk8A on superseded head e91504bb8dcfcb7d582baf122710981e76c957e0. Current head is 782b5cff0cf5684f77a0c7fba74b308d0a7524c1. AUD-658-001 P1 is fixed by exact accepted key sets plus reconstruction of sanitized static/live dictionaries before telemetry. AUD-658-002 P2 is fixed by removing pre-open resolve() and walking the fixed settings path with directory FDs + O_NOFOLLOW, then validating a regular file owned by the target uid. New hostile extra-field tests plus path-source assertions were added. Post-remediation: focused 8/8 PASS, all Surveyor 59/59 PASS, compileall PASS, collect-all 169/12/7 with privacy PASS, Track A governance PASS, git diff --check PASS. Fresh exact-head independent re-audit remains required; this comment does not self-approve the remediation.

@blakinio
blakinio marked this pull request as ready for review August 21, 2026 20:17

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh exact-head validator request for 782b5cff0cf5684f77a0c7fba74b308d0a7524c1 after remediation of AUD-658-001 and AUD-658-002. Please independently falsify the full acceptance boundary, not the implementer summary. Recheck especially: exact probe-output allowlists/rebuilt dictionaries; secret/arbitrary-field non-retention; fixed-path no-follow directory-FD traversal and regular-file/uid validation; exact client fence; read-only/no-process-memory/no-GUI/no-login/no-restart scope; collect-all 169/12/7 accounting; tests/workflow assertions; task/governance lifecycle and non-overlap. Do not fetch or execute the proprietary official-client binary and do not access credentials/session material. Report any P0/P1 or other material finding with exact evidence; if none, state zero material findings on this exact head. Physical E2E remains post-merge and must not be claimed by this review.

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@codex review

Fresh independent validator on exact head 782b5cff0cf5684f77a0c7fba74b308d0a7524c1 only, after remediation of both prior findings. Attempt to falsify acceptance, with special attention to AUD-658-001 output allowlisting/rebuild and AUD-658-002 no-follow fixed-path opening, plus privacy, exact-fence, read-only authority and collect-all accounting. Do not access proprietary client binaries, credentials or session material. Report concrete material findings, or state zero material findings on this exact head. Do not claim post-merge physical E2E.

@blakinio blakinio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implementation/remediation is complete on 782b5cff0cf5684f77a0c7fba74b308d0a7524c1; PR is Ready. Awaiting only fresh independent exact-head review and exact-head GitHub checks before merge. No runtime access has occurred on this implementation head.

Copy link
Copy Markdown
Owner Author

@codex review

Fresh independent validator request for exact head 782b5cff0cf5684f77a0c7fba74b308d0a7524c1 only, after remediation of both previous findings. Attempt to falsify acceptance. Recheck especially exact static/live probe-output allowlists and rebuilt dictionaries, secret/arbitrary-field non-retention, fixed-path directory-FD + O_NOFOLLOW opening and regular-file/uid validation, exact client fence, read-only/no-process-memory/no-GUI/no-login/no-restart scope, collect-all 169/12/7 accounting, tests/workflow assertions, non-overlap and lifecycle governance. Do not access proprietary client binaries, credentials or session material. Report concrete P0/P1/material findings, or state zero material findings on this exact head. Physical E2E remains post-merge and must not be claimed here.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 782b5cff0c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@blakinio
blakinio merged commit 1cb56f6 into main Aug 21, 2026
16 checks passed
@blakinio
blakinio deleted the feat/OTC-20260821-surveyor-next-nonoverlap-gap branch August 21, 2026 20:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant