381cc65c78
Second job on the Windows E2E workflow covering the surfaces a user actually touches, per Teknium's requirement: * INSTALL: downloads the production Hermes-Setup.exe from hermes-assets.nousresearch.com, launches it HEADED, and AutoHotkey clicks Install -> waits -> clicks Launch (button templates + ImageSearch approach from @ethernet8023's #68183, retargeted by process name and extended to exercise the Launch hand-off). The real Electron Hermes.exe window must appear. * UPDATE x2: the installed Hermes.exe is launched under Playwright's Electron driver and the test CLICKS Settings -> About -> Update now. The production hand-off chain runs untouched: app quits, detached updater (repo script or staged binary) runs hermes update, rebuilds the desktop, relaunches Hermes.exe. Asserts: target sha, marker cleanup, result JSON when the script path wrote one, working hermes, and the RELAUNCHED app window. Leg 1 -> CURRENT, leg 2 -> synthetic NEXT. Proof artifacts: per-step renderer screenshots (booted app, settings, About panel, update-available, updating overlay), full-desktop frames every 3s across the whole run, ahk.log, bootstrap-installer.log, desktop-update-handoff.log — uploaded on success AND failure. The website exe runs exactly as shipped (its own pinned install.ps1, its baked release-pin commit); the only environmental deltas are the serve.git URL redirect, uploadpack.allowAnySHA1InWant for the commit pin fetch, and a placeholder provider key so the update legs meet the app shell instead of onboarding. The contract job from the previous commits is unchanged and independent — it remains the rollback position if the GUI job proves flaky.