ZHZN Android release verification
The published release is ZHZN 1.0.35 / code 36. Use Downloads for the cabinet APK and its verification details. The Flutter Operator X and native compact Operator apps belong on the operator's phone; they do not replace the cabinet controller.
- ZHZN Android release verification
- Published and verified 1.0.35
- Published and verified 1.0.34 (superseded)
- Historical verification: 1.0.33
- Historical verification: 1.0.32
- Historical verification: 1.0.31
- Historical verification: 1.0.30
- Historical verification: 1.0.29
- Retained installation and payment audit
- Retained remote access
- Updates and publication history
- Software validation and hardware scope
- Earlier published release and held candidate
- Install and accept the cabinet
Published and verified 1.0.35
Main release CI 34422912459 published the signed APK. An independent anonymous download on September 10, 2026 was inspected with androguard (manifest) and Android apksigner (signature); its bytes match the published CI digest and original fleet certificate.
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Version | 1.0.35, code 36 |
| Android | Minimum API 24; target API 34 |
| Size | 26,212,855 bytes |
| SHA-256 | 6efcbdecd439d1b74e55cd40fcc799910bf9c0453f261a6701d70a3b2fef4b71 |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Source commit | f66b4901a168fcff4ebdd5714abad9d74fcabb19 |
Not run for 1.0.35: emulator install/launch, physical cabinet acceptance, fleet OTA, server activation. The record is docs/reviews/zhzn-current-publication.json.
Published and verified 1.0.34 (superseded)
The published release was ZHZN 1.0.34 / code 35.
Main release CI 34384366809 published the signed APK after PR52 merged. An independent anonymous download on September 9, 2026 was inspected using Android aapt2 and apksigner; its bytes match the published CI digest and original fleet certificate.
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Version | 1.0.34, code 35 |
| Android | Minimum API 24; target API 34 |
| Size | 26,188,493 bytes |
| SHA-256 | 47c0133f806594da2c00773b6bf362a6ada917cfaf10f14f8d9213d0112c2540 |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Source commit | fb487e3b54fe706a6c9ea25bfc1a7c231b392fe3 |
The release adds an app-private, durable queue for unpaid merch, sticker and figurine requests. It retains each original request until the configured central service returns a committed receipt. Publication does not activate the API/Distribution receiver or establish payment, manufacturing acceptance, physical installation or an OTA offer. The release recorded 1,314 passed tests and 11 pre-existing skips, with zero failures. This version's independent verification did not install or launch the APK, operate a physical cabinet or initiate fleet OTA. Earlier emulator evidence below applies only to its named historical bytes; it is not inherited by this release. The current machine-readable publication record is docs/reviews/zhzn-current-publication.json.
Historical verification: 1.0.33
Main release CI 34304927376 published a fresh signed release. It retains the navigation functionality of 1.0.32 and advances the installable versionCode to 34. The full Android CI suite and publication guards passed. An independent anonymous download verified package, version, SHA-256 and fleet signer.
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Version | 1.0.33, code 34 |
| Size | 26,183,746 bytes |
| SHA-256 | 581f94e87582ea610185de02bc525dbaf3978edb202412a41f7652e6b3ab563d |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Source commit | 5f68f030cff6efe6d63669c57aa81bafe9e9d1b5 |
Device installation is recorded separately from publication. An offline device must reconnect; a device without unattended-install permission may require Android installation approval at the cabinet. Physical payment and dispensing acceptance remain outside navigation verification.
Historical verification: 1.0.32
Main release CI 34300722850 passed and published the signed APK on September 9, 2026. An independent anonymous download verified the manifest, SHA-256 and original fleet signer.
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Version | 1.0.32, code 33 |
| Size | 26,183,750 bytes |
| SHA-256 | e1c0726bfd6ee0b2c830981e5e86372e41d8dcc36429bbb7f9bba7766fe87c84 |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Source commit | b81625d5d71657504466488e86c19bf47d8c6d0b |
The invisible native admin touch area intercepted Back buttons in the upper-left corner during the physical 1.0.31 canary check. This release replaces it with passive gesture observation, preserving authenticated seven-tap service access and forwarding the complete touch to shopper controls. The full local suite passed 1,292 tests with 11 skips and no failures/errors; release guards passed. Physical payment and dispensing acceptance remain outside this navigation check.
Historical verification: 1.0.31
Main release CI 34295775960 passed the full Android suite, fleet signing, version-history guard, publication and anonymous-download verification on September 9, 2026.
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Version | 1.0.31, code 32 |
| Size | 26,167,362 bytes |
| SHA-256 | 769534d6634e0cb8e822a6a8fc95db808e2278ab105981f095d2db9a6d4d3d27 |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Source commit | 6e5c3a54d98357e6a617a2e6d22a350fac580194 |
This release adds touchscreen Back, Done, Retake, retry and recovery controls to native and offline screens, with camera lifecycle and payment safeguards. The integrated hosted storefront also restores QR exits, safe cancellation and product navigation. Browser flows passed at 1080×1920, 600×960 and 960×600 with no JavaScript errors. The local Android run passed 1,287 tests with 11 skips and no failures/errors. Publication is separate from device installation; physical payment and dispensing acceptance are outside this navigation check.
Historical verification: 1.0.30
The immutable 1.0.30 APK remains in the published-artifact ledger for this historical evidence.
Main release CI 34147341120 passed tests, release signing, publication-history checks and public-download verification on September 7, 2026. An independent anonymous download and Android signature check confirmed:
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Version | 1.0.30, code 31 |
| Android | Minimum API 24; the new experience player requires API 28 / Android 9 or later |
| Size | 26,166,562 bytes |
| SHA-256 | 9c52049c63730e6ef8fc25118cdf5141101efc99b11a84afa7ec0b3fc961235d |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Source commit | e0f32b27830ece1cb85019d33bf4eca4785928c5 |
The release adds an isolated HTTPS app/game player with a native exit, bounded sessions and an optional phone-controller QR. Use screen experience publishing with Operator X 3.2.6 or the SDK preview. The player has no vending, payment or reward privileges. Remote capture of this separate player is not supported in v1.
The local full suite completed 1,297 tests with zero failures/errors and 11 skips. A separately built debug Android 11 emulator run verified player rendering and timed return; it does not qualify the signed public APK on a physical cabinet. No physical-cabinet acceptance or OTA wave has been performed; validate the actual cabinet before enabling an experience. Publication does not prove installation or playback.
The exact public code 31 APK passed a fresh offline Android 14/API 34 ARM64 install and launcher check at 17:44:37 UTC on September 7, 2026. Camera remained ungranted; no default network was active; 60 seconds produced no app fatal exception, ANR or crash-buffer entry. Android first-run full-screen/pinning prompts appeared over the expected not-registered/not-enrolled identity screen. This checks launcher startup only, not device-owner lockdown, enrollment or the non-exported experience player.
Historical verification: 1.0.29
The following artifact evidence describes the earlier code 30 build. The subsequent code 31 retained these vending safeguards and added the isolated experience player.
Main CI run 34095479250 built, fleet-signed and published this release after PR 42 merged. Its anonymous public download, package and signing certificate were independently verified on September 7, 2026. The exact public APK also passed an isolated Android emulator install/launch check. Physical cabinet acceptance and a fleet OTA rollout were not performed.
| Check | Verified result |
|---|---|
| Application | ai.intelliverse.zhzn.kioskx |
| Android | Minimum Android 7.0 / API 24; target API 34 |
| Native architectures | armeabi-v7a, arm64-v8a |
| Version | 1.0.29, code 30 |
| Immutable filename | zhzn-kioskx-1.0.29-39da1f3548a1.apk |
| Size | 26,166,510 bytes |
| File SHA-256 | 39da1f3548a17fac5ebb202885b3e26b5a1196b69822cd21f2bb1dae279e1678 |
| Signing certificate SHA-256 | 818252217d466dfe89c5b932ba084e6a9dcecb84d99b7349369ae1623557c02d |
| Published source commit | 545de884956785510db12466508fd329b1415db9 |
Android build tools measured the package, version, Android requirements and signer from the downloaded APK. Signature verification passed with the existing fleet release key. Anonymous HTTP 200 download bytes match the digest published by CI. The machine-readable verification record keeps the artifact, CI, source comparison and emulator evidence together.
Retained installation and payment audit
This release combines the previously approved remote controls with the cabinet audit: durable card-session recovery, stock reservation before motor dispatch, quantity/currency/price checks before payment, guarded offline inventory reconciliation, stable enrollment identity, truthful factory evidence and linked manufacturer/operator/shopper procedures. Start with the visual installation atlas, then follow the instructions for the actual cabinet and APK role.
Native card remains a one-product, one-unit flow. A lost reply or missing drop is not proof that no charge occurred. Preserve the original order and pending reports; reconcile actual payment and physical stock before releasing held inventory. A signed APK does not replace that operational acceptance.
Retained remote access
Use a matching approved Operator app and gateway for private screenshots. Normalized coordinates address resized frames correctly. Inputs have an execution deadline and persistent duplicate suppression; native gestures cancel after interruption. Operator waits for a matching input result and its exact post-command screenshot before enabling another gesture. This establishes software sequencing, not a successful physical sale.
Native ZHZN capture/control covers the kiosk app's own foreground window. The optional Reyeah companion role requires its exact role and private credentials before first launch, plus working privileged/root firmware. It does not replace com.ruiye.jd, vend or install root. It checks actual capture dimensions/readiness, bounds shell execution, refuses credential redirects and preserves the returned device witness. Follow remote-access setup and qualification. An unidentified cabinet does not have verified device control merely because the app installs.
Updates and publication history
Previous public builds reused 1.0.26/code 27 for different files. A cabinet already on code 27 ignores an ordinary OTA offer with code 27 even when the file hash changes. Subsequent releases advanced to codes 28 and 29; the earlier 1.0.29 release advanced to 30, 1.0.30 advanced to 31, 1.0.31 advanced to 32, 1.0.32 advanced to 33, 1.0.33 advanced to 34, and current 1.0.34 advances to 35. Preserving the original signer satisfies Android's same-signer update requirement for an otherwise eligible installation.
For the historical 1.0.29 build, the publication guard inspected all 36 retained prior ZHZN APK objects from their actual manifests. Their highest versionCode was 29; this release's code 30 passed. The merged workflow checks publication history before upload, refuses equal/lower codes and reused version names, serializes publication jobs, and records package/version metadata measured from the built APK. This main CI run uploaded the release and verified its anonymous download before reporting success.
The check covers retained public artifacts. Cabinet identity, private builds, rollout selection, device-owner or ROM installation capability, busy/idle state and post-install health remain separate checks. A public download link does not create an OTA offer or prove silent installation support.
Software validation and hardware scope
The published CI build recorded 1,285 passed, 11 skipped, zero failures or errors across 111 suites. The 11 skips are gateway-only scenarios; their separate earlier gateway execution is recorded with the audited candidate and its exact backend source. Release and publication-history guards passed 31 checks. Signed assembly and certificate verification passed.
The exact published APK installed and launched on a fresh disposable ARM64 Android 14 / API 34 emulator. Networking was restricted, Wi-Fi and mobile data disabled, and no active default network was confirmed before installation and after observation. After denying camera permission, the activity stayed resumed for 60 seconds without an app fatal error, ANR or crash-buffer entry. Its screen truthfully showed registration retry and an unenrolled identity; Android's screen-pinning explanation remained visible. The emulator was stopped and its disposable data removed. This checks Android installation and launch, not device-owner lockdown, enrollment, USB/serial hardware, vending, payments, remote input or OTA recovery.
| Controller family in the APK | Required cabinet validation |
|---|---|
CSM spring/spiral (csm, SH) |
Correct board/firmware, serial transport, ten-column wire addressing, every fitted lane and drop sensor |
CSM Y-lift/elevator (csm, SH_YAxis) |
Exact board variant, calibration, travel, pickup-door timing and physical delivery |
Reyeah JD (reyeah_jd) |
Driver exists, but this audit did not certify it on a Reyeah cabinet; use the separately documented approved Reyeah APK procedure |
| Silkron/Vendron or TCN | No dedicated driver in this APK's protocol enum; establish controller/OS/API identity before choosing software |
“ZHZN” branding, an ARM processor or a working touchscreen does not establish compatibility with every model. Record the actual controller, Android ROM, serial adapter, payment reader and mechanism, then complete supervised acceptance on that combination before customer service.
Earlier published release and held candidate
The preceding public 1.0.28/code 29 remains a distinct historical artifact: zhzn-kioskx-1.0.28-40dc34d52767.apk, SHA-256 40dc34d52767ca4d31a1964cf5ec03d2b0c02c5929525f91db7d4d8b62aeab69, 26,131,674 bytes, source 4400f68833ebf715ee972dd1c3134777134a8fd7, CI run 34086554191. Its original evidence was 1,166 Android passes, 10 skips and 31 release-guard passes. It is retained in the published-artifact ledger.
The earlier held 1.0.29 candidate zhzn-kioskx-1.0.29-922ae8854f45.apk, SHA-256 922ae8854f454f59e541fa3822e843221ba01a4d002cb2b70197230f4199ae97, came from f4179b85b83b6ca4a958d56c5f5adf76da18b7b6. Its build, gateway and emulator records remain historical evidence for those exact bytes; they are not relabeled as the public file. The published merge has identical Android application and release-script source. Across 553 APK entries, DEX and other payloads match; the two native serial libraries differ only in two bytes each of compiler .comment metadata, with identical disassembly. The public artifact nevertheless has its own digest and its own install/launch verification above.
The original backend audit's 43/45 failures and 672 selected passes retain their original date and scope. Current backend validation belongs to the separate integrated backend release record; Android test counts do not establish a full backend pass or physical acceptance.
Install and accept the cabinet
Follow the ZHZN Android installation guide for identity, signer checks, an in-place update and preservation of settings. Do not uninstall or clear app data to bypass a signature or version error. Confirm the machine reconnects with its original identity, settings and pending reports, then complete lane, sensor, payment, failed-vend/refund and cold-boot checks in a service window.
For the photographed flickering cabinet, complete VC EL identification and flicker checks first. Its identity is not established as Silkron or ZHZN by the photographs, and an APK cannot fix a failing display cable or power supply.
Use the Operator and machine download guide to choose cabinet and phone apps separately. Return to Downloads for the exact public file.