diff --git a/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md b/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md index 62bfad1..ec06b6c 100644 --- a/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md +++ b/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md @@ -79,6 +79,12 @@ The later continuation also hardened: linked protected/public notices plus corresponding-source references, and a protected release follow-through plus escalation surface that keeps entitlement, package, runtime, and rollout/compliance issues separated +- a later `2026-06-24` follow-up mirrored the same current Windows + packaged-validation proof from the main dashboard into + `/app/browser-access`, `/app/account`, and `/app/notices` so pairing, + entitlement review, and protected distribution/legal follow-through stay tied + to the real higher-dimensional desktop release evidence instead of only + mentioning validation abstractly This keeps the protected app shell aligned with the public manual packet so the operator surface remains honest and useful after sign-in rather than becoming a @@ -209,6 +215,21 @@ The next same-family protected-surface continuation then stayed green under: - `Quality: 6112` - `All rules pass` +Latest protected packaged-proof continuation on `2026-06-24` also stayed green +under: + +- `npm --prefix website run type-check` +- `npm --prefix website test -- --run src/__tests__/protected-app-pages.test.tsx src/__tests__/DashboardOverviewPage.test.tsx` + - `2` test files passed + - `9` tests passed +- `npm --prefix website run build` +- `npm --prefix website test -- --run` + - `41` test files passed + - `168` tests passed +- `scripts/run-hypertwist-sentrux-source-only.sh` + - `Quality: 6190` + - `All rules pass` + Latest same-family wording and truth-render follow-up on `2026-06-24`: - the public/manual XR and control-posture copy was tightened so it now states diff --git a/docs/ops/HYPERTWIST_REFACTORING_TOOLCHAIN_2026-06-22.md b/docs/ops/HYPERTWIST_REFACTORING_TOOLCHAIN_2026-06-22.md index 222a2fb..3fd0298 100644 --- a/docs/ops/HYPERTWIST_REFACTORING_TOOLCHAIN_2026-06-22.md +++ b/docs/ops/HYPERTWIST_REFACTORING_TOOLCHAIN_2026-06-22.md @@ -258,6 +258,25 @@ Additional follow-up after the protected website hardening continuation: than pretending the retained native payload was healthy here - `scripts/run-hypertwist-gitnexus-status.sh` then reported the bounded mirror `Status: up-to-date` + +Latest protected packaged-proof continuation refresh on `2026-06-24`: + +- `scripts/run-hypertwist-gitnexus-analyze.sh` again fell back cleanly from the + retained local CLI to `npx -y gitnexus@latest`, then indexed the bounded + source-only mirror successfully at: + - `16,201` nodes + - `37,889` edges + - `668` clusters + - `300` flows +- `scripts/run-hypertwist-gitnexus-status.sh` then reported: + - repository: `.gitnexus-source-only-root` + - indexed commit: `add7fd6` + - current commit: `add7fd6` + - status: `up-to-date` +- `scripts/run-hypertwist-sentrux-source-only.sh` had already stayed green on + the same website/protected-surface lane with: + - `Quality: 6190` + - `All rules pass` - `scripts/run-hypertwist-sentrux-source-only.sh` improved again to `Quality: 6131` with all `7` rules passing - the centralized website route-registry, sitemap renderer, and related diff --git a/website/src/__tests__/protected-app-pages.test.tsx b/website/src/__tests__/protected-app-pages.test.tsx index d84e987..92942ea 100644 --- a/website/src/__tests__/protected-app-pages.test.tsx +++ b/website/src/__tests__/protected-app-pages.test.tsx @@ -191,6 +191,9 @@ describe('protected app pages', () => { renderPage(, '/app/browser-access') expect(await screen.findByText('Current browser posture')).toBeTruthy() + expect(screen.getByText('Current packaged desktop proof')).toBeTruthy() + expect(screen.getByText('Packaged validation passed')).toBeTruthy() + expect(screen.getByText(/Magic120Cell dedicated-family training map: passed/i)).toBeTruthy() expect(screen.getByText('Native control and XR boundary')).toBeTruthy() expect(screen.getByText('Shipped classic control profile')).toBeTruthy() expect(await screen.findByText(byExactTextContent('Auth runtime mode: public', 'LI'))).toBeTruthy() @@ -206,6 +209,8 @@ describe('protected app pages', () => { renderPage(, '/app/account') expect(await screen.findByText('Session profile')).toBeTruthy() + expect(screen.getByText('Current packaged desktop proof')).toBeTruthy() + expect(screen.getByText('Packaged validation passed')).toBeTruthy() expect(screen.getByText('Current simulator control ownership')).toBeTruthy() expect(screen.getAllByText(/classic-wca-keyboard\/v1/i).length).toBeGreaterThan(0) expect(screen.getByText(byExactTextContent('Billing source: session', 'LI'))).toBeTruthy() @@ -221,6 +226,8 @@ describe('protected app pages', () => { renderPage(, '/app/notices') expect(await screen.findByText('Distribution notices')).toBeTruthy() + expect(screen.getByText('Current packaged release proof')).toBeTruthy() + expect(screen.getByText('Packaged validation passed')).toBeTruthy() expect(await screen.findAllByText(byExactTextContent('Configured release targets: 1/2', 'LI'))).toHaveLength(1) expect(screen.getByText(byExactTextContent('Public repository/notices URL: https://github.com/hypertwist/hypertwist', 'LI'))).toBeTruthy() expect(screen.getByText(byExactTextContent('Corresponding-source URL: https://hypertwist.app/open-source/source.zip', 'LI'))).toBeTruthy() diff --git a/website/src/pages/app-pages.tsx b/website/src/pages/app-pages.tsx index cdbc78f..dd1d974 100644 --- a/website/src/pages/app-pages.tsx +++ b/website/src/pages/app-pages.tsx @@ -201,6 +201,39 @@ function ReleaseAuthorityLinks({ ) } +function findWindowsManifestTarget(releaseManifest: ReleaseManifestView) { + return releaseManifest.platforms.find((platform) => platform.platform_key === 'windows') || null +} + +function PackagedValidationPanel({ + title, + kicker, + description, + emptyMessage, + releaseManifest, +}: { + title: string + kicker: string + description: string + emptyMessage: string + releaseManifest: ReleaseManifestView +}) { + const manifestWindowsTarget = findWindowsManifestTarget(releaseManifest) + + return ( + + {manifestWindowsTarget ? ( + <> +

{description}

+ + + ) : ( +

{emptyMessage}

+ )} +
+ ) +} + function DesktopFirstLaunchChecklist({ title, kicker }: { title: string; kicker: string }) { return ( @@ -335,11 +368,6 @@ export function DashboardOverviewPage() { ) ), [healthQuery.data, releaseManifestQuery.data?.manifest]) - const manifestWindowsTarget = useMemo( - () => releaseManifest.platforms.find((platform) => platform.platform_key === 'windows') || null, - [releaseManifest.platforms], - ) - const verifyUrl = useMemo(() => { const token = desktopLinkMutation.data?.token if (!token) return '' @@ -492,21 +520,13 @@ export function DashboardOverviewPage() { )} - - {manifestWindowsTarget ? ( - <> -

- This dashboard now surfaces the same server-backed Windows package proof that the public and protected release pages consume. - That keeps higher-dimensional desktop validation truth separate from launch-tier checkout or download configuration. -

- - - ) : ( -

- The live release manifest did not return a Windows platform entry, so packaged desktop validation proof is unavailable here right now. -

- )} -
+ + ) : null} + ) : null} +

Operators should keep public notices, protected notices, release notes, and corresponding source reachable from the same release story. diff --git a/website/src/site-data.ts b/website/src/site-data.ts index 2c8b2e3..454a588 100644 --- a/website/src/site-data.ts +++ b/website/src/site-data.ts @@ -715,6 +715,11 @@ export const resourceCollections = [ ] as const export const changelogEntries = [ + { + date: 'June 24, 2026', + title: 'Protected operator routes now mirror packaged release proof', + details: 'The signed-in browser-access, account, and notices routes now surface the same current Windows higher-dimensional packaged-validation proof as the main dashboard, keeping browser-to-desktop pairing, entitlement review, and distribution/legal follow-through anchored to real native release evidence.', + }, { date: 'June 24, 2026', title: 'XR host No-Go truth now renders end to end across native and public surfaces',