docs: bank the Windows Store + signing research, and fix the dead EV-certificate line

The distribution answer existed only in conversation, so every session re-derived
it. It is now in the map, and the route decision is explicitly parked as the
creator's.

new TASKS/research-store-certification.md — Store Policies 7.20 + MSIX packaging:
which policies bind, which don't (and why), cert economics, camera/mic gating
layers, YouTube age + COPPA, the 11.12 UGC judgment call.

Two real defects surfaced, neither fixed (docs-only unit):
- FfmpegLocator downloads an unsigned exe from GitHub and runs it. That is
  policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of
  the 2026-09-01 404 — the pin aged out of BtbN's 14-day retention on the
  creator's first real recording attempt. -> TASK 48 item 1, not
  Store-conditional.
- Distribution.md:318 recommended a $400+/yr EV cert for a SmartScreen bypass
  Microsoft removed in March 2024. Fixed; had it shipped it would have cost
  $400+/yr to buy what $150 buys.

Also new: TASKS/task-48 (checklist, carved out of TASK 36 item 6) and
TASKS/task-49 (chat profanity filter, not blocked). ai.md gains the durable
invariants — full trust or recording breaks silently, chat is rendered never
stored — plus a correction to the FFmpeg locator section. MyMistakes.md records
the lesson: a policy citation is a claim about scope, not just text.

MARCOM.md got the privacy-copy guard but is gitignored by design, so that edit
stays local and did not travel here.
This commit is contained in:
2026-09-27 14:17:13 -07:00
parent 938c5b3de4
commit e78c58fc28
8 changed files with 1044 additions and 128 deletions
+33 -1
View File
@@ -63,6 +63,17 @@
| 45 | TEST-tab chat fix #2: insert body must declare `snippet.type` (400 MISSING_REQUIRED_FIELD) | ✅ Done (2026-09-25) | [`TASKS/task-45-chat-insert-type.md`](TASKS/task-45-chat-insert-type.md) |
| 46 | Drawers: click outside the rail closes whichever is open — TEST added to the existing Stream Settings + YPP dismiss behavior | ✅ Done (2026-09-25) | [`TASKS/task-46-drawer-click-outside-close.md`](TASKS/task-46-drawer-click-outside-close.md) |
| 47 | Alert box video: built-in/custom alert clip (+ six-animation fallback) with read-time fade in/out + ticker (now in the preview too, 3 display methods) + alert volume in the live mix | ✅ Done (2026-09-26) | [`TASKS/task-47-alert-videos.md`](TASKS/task-47-alert-videos.md) |
| 48 | Distribution & packaging: route decision, bundled ffmpeg, MSIX + code signing | ⏳ Queued — **blocked on the creator's route decision**; bundled-ffmpeg half is unblocked and recommended | [`TASKS/task-48-distribution-msix.md`](TASKS/task-48-distribution-msix.md) |
| 49 | Chat profanity filter (local, opt-in, non-persistent, user word list) | ☐ Queued (2026-09-27) | [`TASKS/task-49-chat-profanity-filter.md`](TASKS/task-49-chat-profanity-filter.md) |
---
## Research index
| Research | Covers |
|---|---|
| [`TASKS/research-youtube-api.md`](TASKS/research-youtube-api.md) | YouTube Live Streaming API v3 — authoritative facts for the v3 build |
| [`TASKS/research-store-certification.md`](TASKS/research-store-certification.md) | **Windows Store policies 7.20 + MSIX packaging + code-signing economics** (2026-09-27). Feeds TASK 48. Records which policies bind, which don't, and why — read it before re-litigating distribution |
---
@@ -104,7 +115,7 @@ second encoder path needing a "redirect". Record+simulcast is one ffmpeg with tw
`DroppedFrames`/`StreamDuration`; `SessionTeardownTests` is the natural home for the roll-up.
- **TASK 3** — items 16 (Text source) + 20 (RewardEvent capture → SQLite, Alerts' persistence half) open; **17 (Alerts) is DONE via TASK 43 (2026-09-24) — native six-event alert box**
- **TASK 9** — item 5 open (webcam identity key reconciliation)
- **TASK 10** — Velopack update URL pending
- **TASK 10** — Velopack update URL pending → **now owned by TASK 48** (retires if the Store handles updates)
- **Shipping / release build (creator-queued 2026-09-26)** — no publish config exists yet:
the csproj has only `OutputType=WinExe` + `TargetFramework`, so a plain `dotnet publish`
is **framework-dependent** (customer needs the .NET 8 Desktop Runtime preinstalled).
@@ -198,6 +209,27 @@ second encoder path needing a "redirect". Record+simulcast is one ffmpeg with tw
**ticker** ("Funder — Super Chat · $10.00") scrolls along the very top of the frame
(never-baked dynamic overlay threaded through SceneCompositor + FramePump). Creator rulings:
custom + fallback (not either/or), ticker on top, no ducking.
- **TASK 36 item 6 (release engineering) is now TASK 48** (2026-09-27) — code signing, the
installer, and the Velopack update URL have one owner instead of three scattered mentions.
**EULA draft/review and the THIRD-PARTY-NOTICES license-texts gate stay in TASK 36 item 6**,
as does the agreed build-posture ceiling (HARDENED + MOCK_REWARDS, additive-only).
- **TASK 48 — distribution & packaging** — **⏳ the route decision belongs to the creator.**
Research is done and MSIX is the front-runner; the four real combinations (Store+Store IAP /
Store+Polar / Polar-hosted+own cert / dominated Store-EXE) and their cert costs are tabulated
in `TASKS/research-store-certification.md` §3. Two things are settled and unblocked:
**(a) bundle ffmpeg instead of downloading it** — `FfmpegLocator` currently downloads an
unsigned exe from GitHub and runs it, which is Store policy 10.2.2 (dynamic code inclusion)
*and* is the root cause of the 2026-09-01 expired-pin 404; **(b) the `Distribution.md` EV
claim is dead** — Microsoft removed the SmartScreen EV bypass in March 2024, so paying
$400+ buys what $150 buys. Full-trust MSIX is viable (mediumIL, not AppContainer, and the
three technical disqualifiers — drivers, per-user services, elevation — are all clear).
Packaging, Velopack removal, WACK, the demo account, the privacy policy and the IARC
questionnaire are all specified in the task file and waiting.
- **TASK 49 — chat profanity filter** — queued, not blocked, size S. Local, on-device,
**non-persistent**, opt-in, **user-supplied word list (never a hardcoded slur list)**, and it
must **never match the SuperChat amount or reward fields** (financial data, Store 10.5.5).
The non-persistence half is the same property that makes the 11.12 UGC certification answer
strong, so **no future chat-history/moderation-log/analytics feature may quietly break it.**
---