Skip to content

integration/consolidated-current — single-branch consolidation + Phase 2 (2A/2B) - #8

Draft
focusedbrain wants to merge 149 commits into
mainfrom
integration/consolidated-current
Draft

focusedbrain wants to merge 149 commits into
mainfrom
integration/consolidated-current

Conversation

@focusedbrain

@focusedbrain focusedbrain commented Aug 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

WR Code / Public Handshake — Email E2E slice, complete through Phase 5 on the single permanent development branch, now stamped for the final rig build.

Milestone Tag / commit Do-not-regress
Phase 2 phase-2-complete @ a310cb96 201 = 201
Consolidation-inherited remediation b46680a4 35 removed, 0 new
Phase 3 phase-3-complete @ 1c1cb3ef 166 = 166
Addendum 3G (contract v1.1) d8ac21b1 166 = 166
Pre-Phase-4 block 56dbf7c2 166 = 166
Phase 4 phase-4-complete @ 0a7ca3ae 166 = 166
Seal-key-source fix 6c758b80 0 new
Phase 5 phase-5-complete @ f12c6262 166 = 166
Rig stamp build047 21389e8e code unchanged (stamp only)

Rig build state

HOST_HASH = 21389e8ebe3936a573b292ad53c76a7ccd095f1b (short 21389e8), origin tip matches, tree clean, phase-5-complete is an ancestor. Expected [RUNTIME_IDENTITY]: commit == 21389e8e…, buildStamp == build047 (21389e8).

The stamp bump moves three literals together because three consumers read them: the extension outDir, VITE_EXT_BUILD_STAMP, and the Windows output-dir marker parsed by kill-wr-desk.cjs. The Electron stamp derives from the extension outDir by regex and appends the short HEAD at build time.

Slice content

Phases 2–5 delivered the provenance gate and fail-open closure, the unsuppressible rule-8 alert, CPR as a typed analysis input, the resolution infrastructure (hardened client, dual-channel validation, head/envelope/EVP verification, contract v1.1 embedded delegation), the A6 three-field status composition with resolution-bearing offers, and the email→offer path with EVP-first-render and manual entry.

E2E acceptance (a)–(d) met at logic level. UI rendering is unverified by design (no build, no app start in the agent session) — Phase-5 report §6 states exactly what that leaves for the rig. The integration-pending list is carried complete: nothing waived, no substitute trust path.

Details: code/docs/analysis/wr-code-email-e2e/ (reports + committed captures/) and code/docs/spec/.

Notes

  • main remains for author-designated document drops only.
Open in Web Open in Cursor 

Local Dev and others added 30 commits July 24, 2026 13:12
…trix, migration and risk, refactor plan)

Co-authored-by: Cursor <cursoragent@cursor.com>
…y, ingress admission, dead-path removal)

One shared full-claim identity guard (issuer+subject+email+wrdesk id, exact
match) replaces every partial comparison on ingest/ack/return paths; old
comparators deleted. Additive iss columns on coordination_handshake_registry
with lazy backfill (first write wins). New per-relationship ingress admission
filter is the first stage for all inbound deliveries incl. the BEAP inbox -
blocked transmissions die pre-visibility with an audit record. Removes dead
skipConsentForAutomation field, unused verifier, and no-op version step, with
structural-absence tests. Realm-distribution inventory + phase report in
docs/analysis/wr-handshake-gap/phase-1-report.md.

Co-authored-by: Cursor <cursoragent@cursor.com>
… frozen core record, key extraction, anti-rollback)

Canonicalization module with domain-separation tags; frozen signed core
record (wr_canonical_v3 envelope) carrying the complete capsule content as
a critical declaration, verified fail-closed on receive on top of legacy
rules; containers with preserve-unknown parsing and criticality refusal
naming the namespace; namespace registry (implemented + reserved-inert).

Dual-format emission: v2 surface stays byte-compatible for old peers; new
receivers verify the envelope and mark evidence wire_format canonical_v3 /
legacy_v2. Core nonce store rejects replayed cores; generic anti-rollback
high-water store lands with documented backup/restore semantics. Key
extraction migration (v73) moves private key material into a dedicated
handshake_key_store (copy-before-null, idempotent); reads overlay the store.

Acceptance tests 1-7 green (replay compat, container semantics, canonical
determinism, nonce replay, key extraction, anti-rollback, do-not-regress at
exact baseline parity). ingress_path log-only guard added. Phase report in
docs/analysis/wr-handshake-gap/phase-2-report.md.
…, ledger freeze

- Profile registry (packages/ingestion-core/profileRegistry.ts): five records
  (pbeap_publisher, private_personal, org_internal, org_cross, legacy_v0) fixing
  signature cardinality, attestation rules, role symmetry, permitted ingress
  paths. resolveProfile is fail-closed [VII.4.2]; no conversion path [VII.4.7].
- verifyCanonicalEnvelope dispatches on the registry: unknown profile/version
  refusal naming the profile, distinct-key signature cardinality [VII.3.2],
  schema-level attestation presence/absence [VII.4.5]. New reason codes
  UNKNOWN_PROFILE / PROFILE_SCHEMA_VIOLATION surfaced in denial audit entries.
- Core store split (v75): wr_handshake_core append-only (UPDATE/DELETE aborted
  by triggers, anti-rollback high-water gated) + wr_handshake_runtime mutable
  slice; legacy writers dual-write through coreStore adapter; legacy_v0
  backfill with null ingress_path, unknown_legacy provenance, empty signature
  list (never fabricated).
- Ledger freeze at v74 via freezeAtVersion option + persisted ledger_meta
  marker (closes the lazy-migration hole); one-time hygiene sweep copies out
  and drops undocumented tables, re-asserts row-level key hygiene; hygiene
  assertion on every ledger open.
- ingress_path registry with initial identifiers (Q4 groundwork; log-only).
- Fix: 64-char-hex seed keys signed with a RANDOM key because
  generateKeyPairSync('ed25519', {seed}) silently ignores the seed; now
  wrapped in PKCS#8 DER (canonicalCore.ts, signatureKeys.ts).
- 30 new acceptance tests (profile dispatch, migration parity, hash
  stability, ledger freeze/sweep); phase report with handshake_type inventory
  (249 occurrences / 78 files) and rollback plan.

Co-authored-by: Cursor <cursoragent@cursor.com>
…gate, handshake_type elimination, silent revocation, edge-agent retirement)

Single formation pipeline (V1): formationPipeline.ts dispatches on the
Phase-3 profile registry; the four dialects are deleted (initiatorPersist,
recipientPersist, inbound auto-insert, edge-agent pairing). handshake_type
branching is eliminated - the admission situation is the profile parameter
same_principal (Q9: internal_device, UI label "Cross-Device"); legacy wire
compat is confined to samePrincipalWire.ts, the frozen db column, and
declared envelope-parse boundaries.

Capture methods + Connect-offer staging (V2, C1-C3): capture-method and
invitation-class registries (scan/assisted_discovery fail-closed stubs,
targeted_bound refusal-only); inbound invitations land in connect-offers.db
(own SQLite file, outside both relationship handles) and only a consent
event forms a record. Failed verification suppresses the offer entirely -
structurally unreachable, no override. 7-day timeout (Q7). Capture
provenance is a signed contract declaration (optirando.decl.capture_provenance)
on new formations; consent records are Hash-Pinned (preview +
bound-definition + contract-state hashes) with tamper invalidation.

Silent revocation (V5): revoke-notify capsule removed - enforcement is
exclusively the Phase-1 ingress admission filter (zombie old-build peers'
sends die pre-visibility with a logged record, verified). Q8: revocation no
longer deletes context blocks/embeddings/audit rows; content deletion is
the separate explicit operator action deleteRevokedRelationshipContent
(handshake.deleteRevokedContent RPC).

Edge-agent fold-in (V8/I3): edge_ingestor dialect retired for new
formations (RETIRED_FORMATION_DIALECTS, fail-closed unknown_profile);
legacy pairings stay readable by the agent dist; lockstep upgrade
documented.

Acceptance tests 1-8 green (phase4OneFormationPipeline,
phase4SilentRevocation, phase4EdgeAgentFoldIn acceptance suites +
structural scans). Wide do-not-regress sweep: failure set byte-identical
to the Phase-3 baseline (0 new, 0 fixed). Sequencing evidence and
deviations in docs/analysis/wr-handshake-gap/phase-4-report.md.

Co-authored-by: Cursor <cursoragent@cursor.com>
…tap execution consent, Tier-L evidence chain, capability tokens)

Grant objects (E2-E4, E9) [VII.10.x]: wr_grants (migration v76, vault only)
with delivery/preparation rights and deliberately no execute variant; the
Phase-1 receiver-side ingress filter now consumes grant scopes (off-scope
blocked pre-visibility + logged + revoke offer after repetition); admitted
deliveries carry grant_ref provenance on email and P2P BEAP paths; legacy
relationships lazily backfilled from effective_policy (never a fabricated
consent); limit extensions parse-level critical.

Execution grants deleted + per-tap consent (V4) [VII.10.1, IX.19.2]:
GRANTED_TOOLS and ACTIVE-handshake blanket authorization removed; every
execution requires a fresh, single-use, Intent-Hash-bound human consent tap
(executionConsent.ts, wr_execution_consents); divergence from the presented
preview refuses execution and records a deviation PoAE; fail-closed kill
switch WRDESK_EXECUTION_CONSENT_TAP (never a consent-free path).

Evidence chain (H1-H4) [IX.19.1, X.10.1]: wr_evidence_chain - append-only by
trigger, per-contract monotonic sequence, SHA-256 prev-hash chaining,
explicit genesis at cutover; PoAC/PoAE writers on formation, grant
lifecycle, admission blocks, content deletion, and executions; BER schema
representable now (writers in Phase 6).

Ledger repurposing (Q10): handshake-ledger.db is the Tier-L evidence home
(ledger-native schema, hygiene-allowlisted); header docs state the actual
transitional dual role honestly.

Capability-token schema (T4/Q13) [XII.12.6 annex-number-provisional]:
carriage-only tokens with preserve-unknown-optional parsing (p2p_signal
pattern), optional context_scope/delegation_chain, delegable defaults false,
critical limit extensions.

Hygiene (H5): deleteHandshakeRecord no longer deletes audit rows; audit_log
frozen for mutation via triggers on both handles (INSERT stays open);
retention carve-out excludes wr_evidence_chain and audit_log. Pre-existing
purge losses are unrecoverable and the chain claims no pre-cutover
continuity.

Also fixes a Phase-4 latent bug: the default Connect-offer staging DB now
uses :memory: under vitest so test runs stop staging offers into the
developer-profile connect-offers.db (163 leaked fixture rows purged).

Acceptance tests 1-8 green (phase5GrantsEvidence.acceptance.test.ts et al);
do-not-regress verified against the Phase-4 baseline worktree - identical
pre-existing failure set, zero new regressions. Report:
docs/analysis/wr-handshake-gap/phase-5-report.md

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…sponsibility logging

EOF

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…json

Co-authored-by: Cursor <cursoragent@cursor.com>
…; stamp build046

Co-authored-by: Cursor <cursoragent@cursor.com>
…nce import depth

Channel provenance (SPF/DKIM/DMARC) and publisher resolution are mandatory
structural pipeline stages, not an opt-in trigger filter. A message failing
them yields no WR code and no affordance at all, so there is no class of
"WRCode-stamped email" a per-trigger checkbox could select. Disabling the
control left it naming a concept that does not exist.

Nothing ever produced the verdict it read: NormalizedEvent.wrcodeValid had no
writer, EventTagMatcher.evaluate has no production caller, and the router
behind the control is fed inline-chat and OCR text, never mail.

Removes the type, union member, evaluators, schema enum value, vestigial
wrcodeMatch field and the control itself; strips the condition from stored
agent configs at every read boundary. InputCoordinator's default: branch now
fails closed to match EventTagMatcher, which makes that stripping load-bearing
rather than cosmetic.

Also fixes email/providers/zoho.ts, which resolved aiProvenance five levels up
where its three peers in the same directory correctly use six - the cause of
both the blocked session:build and the 77 suite-load failures.

Co-authored-by: Cursor <cursoragent@cursor.com>
Brings main's document commits onto the branch so a fresh build covers the
complete state: WR Handshake Phases 1-5, art50 AI provenance, WR Code email
E2E Phase 1, and main. No code conflicts - main touched no source files.

Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
…II additions)

Additive delta to the v1.0 email E2E order: A-series decisions A1-A5,
Phase 3 additions 3D-3F (CatalogHead, DualAssuranceEnvelope, EVP), Phase 4
offer-schema and status additions, Phase 5 EVP-first-render, and acceptance
items (e)-(h).

Tracked rather than left in chat because the v1.0 order never was, which is
part of how the work lost its paper trail.

Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
…ug 2026)

Normative source for Delta v1.1 decisions A2 (EVP-first-render, XVII.4.4),
A4 (audit link, XVII.6) and A5 (platform suspension, XVII.3.3). Placed at
repository root alongside the other annexes.

Note: this annex depends throughout on Annex XIV 5.5 (Execution Authorization
Proof Chain and Catalog Commitment), which the Annex XIV copy in this repo
(v1.0, 26 July 2026) does not contain.

Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Author ruling on the collision named against Annex XVII XVII.3.2/XVII.3.3:
three orthogonal layers whose convergence is display-only. entry.status is
publisher-signed and platform suspension lives only in the envelope, so the
two cannot collide in data. Admission is conjunctive and fail-closed across
D4 status, entry.status and envelope.suspension; display keeps all three
distinct with headline precedence platform > entry > publisher-part.

Phase 4 bullet cross-references A6 for the composition rule.

Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Supersedes the A5 cross-reference wording with the authoritative statement:
the surface composes three orthogonal fields (D4 publisher-part status,
publisher-signed entry.status, platform envelope.suspension) under A6's
conjunctive fail-closed admission rule and headline precedence, with
distinct copy per layer. Offer-schema bullet unchanged.

Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Brings Refactor Order v1.0 (754e87e), the authoritative Annex XIV v1.1
carrying XIV.5.5, Annex XVII, and the updated Annexes IX/X/XI onto the
Phase-2 branch before order-02 work begins. Plain merge commit per the
author ruling: no cherry-picks, no rebase.

Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Local Dev and others added 29 commits August 31, 2026 03:55
…e security DB

Co-authored-by: Cursor <cursoragent@cursor.com>
… dispatcher) + anti-bypass proofs

Co-authored-by: Cursor <cursoragent@cursor.com>
…es, retention pruning, never touches floors/uses/devices)

Co-authored-by: Cursor <cursoragent@cursor.com>
…art/crash safety - after-capture identical failing set, +78 passing

Co-authored-by: Cursor <cursoragent@cursor.com>
…026-08-12)

Preserves uncommitted host-tree work found during the 2026-09 resync (A0/A6).
Removes the full disclosure mount and import from five surfaces:
EmailInboxBulkView, EmailInboxView, LetterComposerView, WRChatDashboardView,
DashboardAutomationHome. HybridSearch keeps its mount.

Committed as found; not reviewed, typechecked, or tested in this commit.
…8-12)

Preserves uncommitted host-tree work found during the 2026-09 resync (A0/A6).
User-facing copy WR Desk/WRDesk -> Optirando, APP_NAME, extension manifest
name/title and web-accessible assets, Optirando logo/symbol/wordmark assets,
BrandLogo component, wrdesk-logo.png replaced (legacy filename kept).

Also contains the uncommitted build-output change build007 -> build009
(electron-builder.config.cjs, extension vite.config.ts). Keep it off the
integration line unless intended.

Includes repo-root source assets (code/optirando-*.png) and
apps/extension-chromium/_symbol_raw.png as found; prune if not wanted.

Committed as found; not reviewed, typechecked, or tested in this commit.
…ce unverified)

Separate from Rebrand Wave 1 because the file's mtime is 2026-09-25 09:20,
six weeks after the rest of the wave. The Author made no edit that day; it is
probably left over from an interrupted earlier agent session. Two confirm-dialog
strings only.

Committed as found; not reviewed or tested.
Analysis-only run after the four-week pause. Resume point 8f0a564 (Run 5).
Runs 2-5 were complete on the host but unpushed; secured and pushed in this run
(integration fast-forward, wip/host-2026-08-12-art50-rebrand-w1, archive/*).

Before-captures at 8f0a564: failure identities (153 in both runs, 0 new /
0 repaired vs the a62d485 capture; testResults.length 589, numTotalTestSuites
2165) and normalized typecheck lists (extension 183 unchanged; workspace +16
since adcc99c, 14 from the stale ingestion-core dist, 2 genuine TS2322).

Findings: wrc.* has no production route (dispatcher forwards only vault./
handshake./beap./ingestion.; no UI caller), class register vs the
utility-model texts (SPEC-PENDING), ruling-2/3/4 conflicts, contract drift
(/v1/directory, entry_id semantics). No product code changed.
…packet, housekeeping

Part A: ruling 2 -> CONFORMANT (signed, status-bearing entries are addressable
sub-handshakes); ruling 1 -> SPEC-PENDING (committed XVI.13.2 governs); ruling 4
-> ANNEX NONCONFORMANCE (Run 1) per Annex XVI v1.95 XVI.3 and XVI.7.4a, fix
first (S1); ruling 3 split into the desktop route (S2b) and the resolver
response contract (S2).

Part B: Author decision packet (12 questions, 8 resolved by evidence), slice
plan with S2a acceptance review of Runs 3-5 before S2b, acceptance table, rig
checklist mapped to slices.

Part C: salvage branch bundled and verified outside OneDrive; stash@{1} and
stash@{2} archived as pushed branches (archive/stash-1-20260516,
archive/stash-2-20260516); ignored-items and absolute-path inventories. No
product code changed; nothing deleted.
…spawn

The validator-process lifecycle tests fork a tsx subprocess that resolves
@repo/ingestion-core through its package.json (dist/), and the
coordination-service startup test spawns dist/server.js. A fresh clone has
neither build output, so 11 tests fail there that pass on a tree with a
(possibly stale) dist. Run 'pnpm test:prepare' before the sanctioned runner.

Verified: fresh clone at C:\dev\optirando reproduces the 153-set after
test:prepare (one extra identity is the documented 5 s timing flake in
userDataBootstrapPersistence, green in isolation); host tree unchanged at 153.
… and Rebrand Wave 1

Brings the host-tree work of 2026-08-12 onto integration:
- 296123b Art. 50: remove the duplicate full disclosure mounts from five
  surfaces; HybridSearch and the extension popup keep theirs.
- 1702378, c67d14c Rebrand Wave 1: WR Desk -> Optirando copy, APP_NAME,
  manifest name/title, logo assets, BrandLogo.

The build007 -> build009 output-dir change in electron-builder.config.cjs and
extension vite.config.ts is deliberately NOT taken (integration keeps build007).

Verified: sanctioned runner 153-set unchanged (plus the documented
userDataBootstrapPersistence timing flake); typecheck extension 183 / workspace
430, sets identical to before the merge.
…VI 3, 7.4a)

Annex XVI v1.95 requires the signed WR script block for automatic detection
and auto-insertion from pages and e-mail; loose textual references are
captured only on explicit user request. Run 1 (d5e4db5) scanned every
channel-authenticated plain message at ingest and persisted the results into
the sealed metadata - an annex nonconformance.

- messageRouter: the ingest scan and the wr_code_detections metadata write
  are removed.
- wrCodeEmailDetection: reduced to the pure, explicit-trigger scanner.
- New local RPC wrc.detectReferences (no network) as the explicit trigger;
  candidates are still submitted through wrc.submitReference.
- Tests: source guard that the router never scans or writes detections;
  handler tests; the full-path capture-origin case now goes through the RPC.

Rows ingested since d5e4db5 may still carry a wr_code_detections key in
their sealed metadata; nothing reads it.
…sked TS2322

- tsconfig (electron app): map @repo/ingestion-core to its src, like
  @repo/shared-beap-ui. The headless typecheck no longer depends on a built
  (and possibly stale) packages/ingestion-core/dist: 26 ingestion-core files now
  resolve from src, 0 from dist.
- entryLifecycle: the transition table is built with a typed helper, so every
  target state is checked against WrEntryLifecycleStatus.
- useLimitStore (memory store): consume returns the settled state through a
  typed local; applyConsume never leaves a row claimed, so behaviour is
  unchanged.

Workspace typecheck 430 -> 428 (the two TS2322 gone; one pre-existing error in
ingestionPipeline.ts now reports its src path). Lifecycle, use-limit, pipeline,
acceptance, restart-matrix and pairing suites green.
- productionCompositionRoot.e2e: initWrcClient with no test seam builds every
  store on the durable security DB (redirected to a temp file) and an
  unconfigured deployment refuses a valid reference at Gate 2.
- connectOfferWrCodeSchema: pin the preview-hash key set (top level, entry,
  bound definition) and prove wr_code_class does not change the hash.
- provenanceGatesParsing.guard: pin the total of seven
  DepackageCutoverHeldError hold sites.
- relayRelease.e2e: source guard that the Gate-5 release chain carries one
  principal delegation, never a list.

Test-only change.
… SSO session (S2b, route)

Until now the WR Code RPCs existed only inside handleHandshakeRPC: the
renderer RPC dispatcher and the extension WebSocket forwarded vault.,
handshake., beap. and ingestion. only, so Runs 1-5 were reachable from tests
alone.

Both dispatchers now route wrc.* and refuse without an active SSO session
(getCurrentSession); unlike handshake.*, there is no skipVaultContext escape.
Submission and acceptance are therefore structurally account-bound (ruling 3).
The claimant party and keys still come from deployment config (Q19 default B).

Guard: productionRoute.guard.test.ts pins both routes, the session check,
the absent escape, and the five dispatcher targets.
153-set unchanged (plus the documented timing flake), +8 net tests, typecheck
extension 183 / workspace 428; fresh clone proven with test:prepare.
…ation (S2)

Agent draft under Q17 = A. Records what the client already expects (directory endpoint, per-class entry lookup keys, designation, closed signed objects, DNS and manifest formats), maps the wire shapes to Annex XVI v1.95 Appendix A.4, proposes public/account disclosure tiers (ruling 3, XVI.6.3), and leaves the relay/capsule wire legs open for S7. Lists client work C1-C8 and questions Q20-Q27. Not normative until ratified.
…-on domain by DNS (C1, C2)

C1 (XVI.6.5 entry assignment, XVI.16 entry substitution): deriveEntryDesignator refuses a P entry whose repository id differs from the reference's local block (designation_mismatch at Gate 3). Before, a registry could serve any other signed P entry of the same publisher under a local block and all six gates passed.

C2 (XVI.6.5 email-domain agreement): WrcDirectoryClient.dnsVerifiedDomains proves each registered domain live against its own _wr record. Gate 2 (acting principal) and Gate 6 (initiator SSO domain) accept only DNS-proven domains; before, only domains[0] was proven and any listed domain was accepted.

Tests: entryDesignator, fullChain (P substitution), directoryGate2 and capsuleAdmission (secondary domain with and without its own proof). Negative control: the 5 refusal tests fail without the fix. WRC contract v2.0 section 9.
…rt and captures

The Author accepted every recommended default on 2026-09-26. The delta loses its _DRAFT suffix, records the answers, and marks C1/C2 as implemented in fdf4a40. Before/after captures from the C:\\dev\\optirando checkout: 153-set unchanged, 0 regressions.
…ust pinned in source

pnpm run build:wrc-test compiles an in-process WR Code test registry behind the transport seam: six deterministic, seeded test publishers (catalogs, envelopes, Merkle proofs, dual-signed directory records, manifests, _wr answers) and 19 test codes covering every class and namespace status, through the real six gates. The signed-in SSO domain is registered live for the own test publisher. Test state lives in wrc-security.wrc-test.db and its own record cache; the app packages into build007-wrc-test beside the release build and shows a non-dismissible test-data banner; wrc.runtimeStatus reports the flavor.

Release builds alias the registry to an empty stub, scripts/verify-wrc-build-flavor.cjs fails any build chain whose bundle does not match its flavor, and WRC trust comes only from wrcTrustAnchors.ts (XVI.6.4 pinned; environment ignored; test- key ids refused). Only unbundled dev runs read WRDESK_WRC_* trust variables.

Tests: wrcTestRegistry (every code's gate outcome, one-time use, SSO domain, determinism, containment), wrcBuildFlavor.guard (alias, define, build chains, stub parity, pinned trust, output folder, code sheet), wrcTestRegistryRuntime.e2e (per-flavor composition root on a real security DB). Both builds verified. Code sheet: docs/operational/wrc-test-build.md.
…egistry, pinned release trust)

Records the reachability decision (built-in registry behind the transport seam, test builds only; no dev address allowance), what f8bf53f changed, and the verification: 153-set unchanged, 0 regressions, both build flavors verified.
A WR Code button in the message toolbar opens a panel: manual entry with a local format check, Find WR Codes in this message, Check through the six gates, then the offer with Accept/Decline or a status refusal. The surface renders main's view model (wrcSubmissionView.ts): offers are the EVP-first projection of offerPresentation.ts, statuses reuse the three-layer copy of entryStatusSurface.ts, every refusal has human copy and a tone, reason codes stay secondary.

Main decides the scan: wrc.scanMessage reads the sealed row and scans only when its Channel Provenance Record decodes with channel_pass (HC2, W5); manual entry is always available (HC3). wrc.declineReference releases the XVI.8.4 reservation at once; the panel declines an offer left open when the user checks another code, closes the panel or leaves the message.

Tests: wrcSubmissionView (every test code), wrcMessageScan (authenticated, unauthenticated, tampered, missing), runtime decline e2e, WrCodePanel (scan gating, offer render, decline on new check and on leave, none after accept; negative control verified). Route guard: eight wrc.* methods. docs/operational/wrc-test-build.md: where codes are entered.
…2b UI, first increment)

Maps the increment to HC2-HC4, HC6, W1, W2, W5; records what is not in it (HC5 connect-offer consent, S5, audit link, S7). Twelve review screenshots of the real panel with real pipeline outcomes. 153-set unchanged, 0 regressions.
…e rendered preview (HC5); directory C3/C4/C5/C8

The desktop handshake:accept answered HANDSHAKE_NOT_FOUND for every staged Connect offer, so no inbound request could be accepted in the app since Phase 4. It now resolves the staged offer, requires expected_preview_hash for it, and forwards the hash to consent. handshake.list carries connect_offer_preview; the accept dialog renders it and returns its hash.

WRC directory: the SC responder check uses the signed directory status (C3); the record carries a connector (C4); a grammar other than 2 is refused (C5); display_origin reaches the namespace verdict only after normalization and membership checks (C8).
…r channel (C6); account-tier credential and 401 (C7); HC5 in the extension and on every product route

S5: the WR Code offer shows the checked display_origin as the responsible domain, re-rendered from the verified directory record, never a link. C6: GET /v1/directory/operator-rollovers is decoded and folded from the pinned anchor when a record names an unknown operator key (at most once a minute, one shared fetch); the test registry's TEST03 verifies only through it. C7: the HTTP transport sends a bearer on entry and object reads only; 401 is entry_account_required with its own copy, not the capture error. The production credential source is not wired yet.

HC5: the extension renders the connect-offer preview and sends its hash; both product RPC dispatchers require the hash for a staged offer and for consentToOffer. The extension accept dialog no longer reports a refused accept as accepted. S4: stale interim comments in gatePipeline.ts updated.
@focusedbrain
focusedbrain force-pushed the integration/consolidated-current branch from 3a57dc6 to ad03c74 Compare September 26, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants