# Verification record · 0.1.0-beta.4 source candidate The current source describes the cross-platform **0.1.0-beta.4 testing build**, not a stable or hardware-validated build. The website download update includes Windows portable and Linux packages; publication is separate from packaging. Historical beta.3 and beta.2 records below are retained and do not establish beta.4 results. ## Beta.4 candidate checks — September 28, 2026 - `npm test`: **95 passed, zero failures or skips**. Includes expiry boundaries, metadata/state rejection, fractional monotonic timestamps, clock rollback, randomized monitoring, stable-build exemption, IPC policy cleanup allowances, native enable/prompt races, and in-flight engine expiry. - Linux x64 AppImage and Debian packages built successfully. Checksums are in `release/SHA256SUMS.txt`. - Extracted the packaged `src/build-info.json` from Linux `app.asar` and verified it matches source metadata with an exact 30-day lifetime. - An unsigned Windows x64 runtime folder was cross-built successfully with executable resource editing/signing disabled, and its embedded version/expiry metadata verified. It is distributed as a complete portable-folder ZIP, not a standalone portable executable. NSIS installer packaging failed because Wine is unavailable; the incomplete installer output must not be distributed. - No native desktop GUI, macOS build, real administrative permission, actual sleep/wake or TV-hardware testing was performed for beta.4. Runtime GUI libraries are unavailable on this Linux host. No cryptographic tamper-resistance is claimed. ## Beta.3 candidate checks — September 28, 2026 (historical) These results apply to the cross-platform beta.3 source candidate only, not beta.4. - `npm test`: **74 passed, zero failures or skips** on the Linux build host. Includes TV protocol/engine regressions, local-time/DST boundaries, all three OS integration command plans, ownership isolation, rejected authorization, cleanup, and settings persistence/rollback. - Native integration tests inject command runners; they do **not** create real wake tasks, authorize administrative changes, or prove hardware wake behavior. - `npm run build:linux`: successfully generated x64 AppImage and Debian package. `npm run release:checksums` generated SHA-256 values in `release/SHA256SUMS.txt`. - The Linux GUI could not be launched on this build host because desktop runtime libraries (`libglib-2.0.so.0`) are unavailable. No Linux GUI or real sleep/resume result is claimed. - macOS DMG and updated Windows packages had native-runner CI build jobs configured but were not built here. The workflow was not run remotely. - Release gates remaining at the time included native packaged startup, save/authorize/decline, actual sleep/wake, selected weekdays and timezone changes, secure keyring/Keychain behavior, uninstall cleanup, and physical TV off tests. macOS signing/notarization was not configured. ## Prior beta.2 verification (historical) Built September 28, 2026 on Windows 11 x64. Electron 44.4.5, Node.js build host 22.17.0. The following records apply to beta.2 only and do not establish beta.3 results. ### Beta 2 layout correction Reproduced a Quiet hours page that was 1,850 pixels wide inside a 1,213-pixel viewport. Invisible weekday checkboxes inherited the full form-input width and extended beyond the window. They are now contained within their day labels. This removes the extra horizontal scroll area while preserving native checkbox and keyboard behavior. The targeted Electron regression checks every weekday by mouse and keyboard at window widths of 930, 1240, and 1600 pixels, with 100% and 125% app zoom. It verifies that page width never exceeds the viewport and focusing a weekday never scrolls sideways. No guard, pairing, or schedule-engine behavior changed in this patch. The checks below were completed for beta 1. ### Automated checks **36 passing tests; zero failures or skips.** - Overnight and daytime windows, exact start/end boundaries, selected-night rollover, spring/fall daylight-saving transitions, invalid schedule rejection. - Continuous overnight checks, 30-second minimum between repeated off attempts, pause/disable/unverified gates, no overlapping loops, late response crossing the end time, per-device failures, and off-test locks. - Unreachable and unknown states remain unconfirmed. Authentication/identity failures and registration timeouts disable the affected TV. - Samsung identity check, status check before connecting and again before sending, Frame hold/release sequence, dedicated standard-TV off key, no command after an off-state change. - LG registration permissions and dedicated off request; Sony PSK, identity/status and explicit false power state; Vizio PIN response, AUTH handling and dedicated off code. API error payloads tested. - Credential-store separation, encryption-unavailable rejection, unreadable-config fail-closed behavior, private-address validation, platform identification. - Real local TLS mock server confirms certificate mismatch is rejected before any authentication header reaches HTTP, first-pair certificate learning, and immediate WebSocket-message handling without an Origin header. Production dependency audit reported **zero known vulnerabilities** at build time (`npm audit --omit=dev`). This is a point-in-time dependency check, not a security certification. ### Electron UI and packaged application Automated Playwright walkthrough passed against both the development application and the packaged Windows executable: - Fresh install has zero devices, an 11 pm–6 am schedule, and enforcement disabled. - Renderer is sandboxed, context-isolated, and has no Node integration. Real Windows safeStorage encrypted/decrypted a synthetic test value. - Enforcement is blocked until pairing and the off-test gate are satisfied. - Schedule editing, simulated pairing, off-test success and failure, pause/resume, per-TV state, settings, activity, compatibility, and close-to-tray behavior. - Anonymous diagnostic export omits synthetic TV names, IP addresses, identities, and credentials. - No renderer exceptions during these walkthroughs. Setup and overview screenshots were visually inspected. Windows NSIS installer and portable executable built successfully. The embedded application archives passed 7-Zip integrity checks. Both self-extracting wrappers contain trailing installer data, which 7-Zip reports as a warning; embedded payload checks passed. Both executables are **unsigned**. The packaged files contain app source, runtime dependencies, icons, and documentation. A packaging audit found no household configuration, pairing state, logs, prototype device address, or unique TV identity. Source is distributed separately with synthetic test fixtures. ### Hardware and platform limits at beta.2 No real TV power command or pairing request was sent as part of this beta build or UI testing. The pre-existing personal Samsung guard was left running. Prior hardware evidence: the original Python prototype successfully paired and fully powered off a 2021 Samsung The Frame. This Electron version still needs its own physical off test. LG, Sony, Vizio, and other Samsung models have **not** been tested on physical hardware here. Windows login and wake options are implemented. Their UI was exercised in isolated preview mode; the build did not create a real wake task or startup entry on the development computer. Actual wake behavior, installation/uninstallation across clean Windows machines, and extended overnight use need beta testing. The packaged application was launched directly for its smoke test; the installer was built and its payload checked, without installing it over the user’s environment. macOS and Linux builds were not produced or tested for beta.2. For beta.3, the source and CI configuration target Windows x64 Setup/portable, macOS Intel and Apple Silicon DMGs built on native Mac runners, and Linux x64 AppImage/deb on native OS runners. CI is configured to run automated tests, build packages, calculate checksums, and upload CI artifacts only; it does not publish a release. CI builds do not validate physical TV behavior or hardware wake. Code signing, notarization, production updates, Store submission, account/payment systems, and a tamper-resistant background service are outside this candidate. No beta.3 physical-TV, clean-install/uninstall, startup, overnight, or hardware wake validation was claimed here. The only prior physical-TV evidence remains the original prototype's full-off sequence on a 2021 Samsung The Frame. Beta.4 testing remains pending as noted above.