branding credit: run in every scene and in recordings, not only while live

Creator 2026-09-26: "the made with llamacasty flash should appear in all scenes,
not just live" and "should also appear in recordings". The presenter was
Start()/Stop()-ed from UpdateLiveVisuals()'s IsLive branch, so a recording made
WITHOUT ever going live carried no credit at all -- the exact case the creator hit
while judging compositing from local recordings.

It is now Start()ed once in the MainViewModel ctor and never stopped on live-state
churn. One start covers every scene, the preview, the stream and the recording,
because go-live and local recording are the SAME FramePump: both
Streaming.Operations.cs:68 and :199 call StartAsync with the same brandFlash:
delegate. Verified by reading both call sites, not assumed -- there is no second
encoder path that needed a "redirect". The licence gate needs no live branch at
all: IsPremium's setter already pushes BrandFlashPresenter.Enabled from anywhere.

Fixed a trap that app-lifetime exposed: Enabled = false stops the presenter's
DispatcherTimer to cut the advertisement mid-credit. When Start() was per-go-live
the next go-live restarted it; with a single app-lifetime Start() nothing would,
so a key entered mid-session would leave the credit dead until the process was
restarted. The setter now restarts the timer when re-enabling while _running.

Tests (12 facts in BrandFlashOutputTests, +2):
  Credit_IsComposited_WithNoLiveSession_AndSoARecordingCarriesIt -- drives a real
    never-live VM past the 5s first-flash delay and asks the frame the pump would
    composite. Uses a new internal AdvanceBrandFlash seam; because Advance only
    advances the cadence while the presenter is running, a credit coming out
    proves Start() happened at construction.
  ADowngradeMidSession_RestartsTheCadenceTimer -- asserts the premium/downgrade
    edge decision directly (IsCadenceTimerEnabled) instead of sleeping through a
    30-60s interval, which a synchronous test body cannot observe.

Full suite 364/364.
This commit is contained in:
2026-09-27 09:33:30 -07:00
parent e3e69d941d
commit 9761b1d4be
8 changed files with 193 additions and 25 deletions
+18
View File
@@ -1480,6 +1480,24 @@ crooked.
**Escalation model (2026-09-01, creator decision):** the cadence is *obnoxiously* self-promoting.
License activation still flips exactly one bit: `IsPremium` → flash off. Nothing else changes
between free and paid, ever.
**Cadence is APP-LIFETIME, not go-live (creator ruling 2026-09-26):** the presenter is
`Start()`ed **once in the `MainViewModel` ctor**, not from `UpdateLiveVisuals()`. It used to be
gated on `IsLive`, which meant a recording made without ever going live carried no credit — the
creator's ruling: *"the made with llamacasty flash should appear in all scenes, not just live"*
and *"should also appear in recordings"*. One start now covers every scene, the preview, the
stream and the recording, because go-live and local recording are the **same `FramePump`**
(`Streaming.Operations.cs:68` and `:199` both call `StartAsync` with the same `brandFlash:`
delegate) — verified, not assumed; there is no second encoder path needing a "redirect". The
licence gate needs no live branch: `IsPremium`'s setter pushes `Enabled` from anywhere.
**Consequence of app-lifetime — the premium edge restarts the timer.** `Enabled = false` stops
the `DispatcherTimer` (cutting the advertisement mid-credit). Because `Start()` is no longer
called per go-live, nothing would ever restart it, so a key entered mid-session would leave the
credit dead until the process restarted. The setter therefore restarts it when re-enabling while
`_running` (`IsCadenceTimerEnabled` is the test seam).
**Test-arithmetic trap, hit again 2026-09-26:** `Advance(5.1)` in ONE call cannot observe a
credit — `Advance` both *opens* the presentation and *ages* it by the same delta, so a single
5.1s step blows clean through the 2s window. Always step in 1/30s increments like the real timer
(the `Step` helpers in `BrandFlashOutputTests`).
- **Paid (one-time perpetual license):** branding flash removed. `BrandFlashEnabled` is now a
**derived, non-assignable** `!IsPremium` and the presenter's own `Enabled` gate is re-checked on
every frame, so a key entered (or revoked) mid-credit cuts the advertisement on the next tick