TASKS: queue the shipping/release build (publish.sh + Debug-only InternalsVisibleTo)

Creator-queued 2026-09-26. Records that the csproj has no publish config, so publish
is currently framework-dependent while Distribution.md targets a self-contained
~80-120MB upload to Polar; and flags that InternalsVisibleTo(ytLive.Tests) ships in
Release. Notes that the compile side already excludes the tests (separate project,
one-way reference, explicit Compile Remove) so the real risk is packaging from
ytLive.Tests/bin, which contains a ytLive.exe next to the test DLLs.
This commit is contained in:
2026-09-27 07:53:52 -07:00
parent 7f14ffb11e
commit fae8ec5f32
+18
View File
@@ -71,6 +71,24 @@
- **TASK 3** — items 16 (Text source) + 20 (RewardEvent capture → SQLite, Alerts' persistence half) open; **17 (Alerts) is DONE via TASK 43 (2026-09-24) — native six-event alert box**
- **TASK 9** — item 5 open (webcam identity key reconciliation)
- **TASK 10** — Velopack update URL pending
- **Shipping / release build (creator-queued 2026-09-26)** — no publish config exists yet:
the csproj has only `OutputType=WinExe` + `TargetFramework`, so a plain `dotnet publish`
is **framework-dependent** (customer needs the .NET 8 Desktop Runtime preinstalled).
`Distribution.md` targets a self-contained ~80–120MB `LlamaCasty.exe` uploaded to Polar
as a File Download benefit. Two deliverables:
1. **`scripts/publish.sh`** wrapping
`dotnet publish ytLive.csproj -c Release -r win-x64 --self-contained true -o ./publish/win-x64`,
and **asserting the output contains no test/xunit artifacts**. (The compile side needs
nothing — the tests are a separate project with a one-way reference, plus explicit
`<Compile Remove="ytLive.Tests\**" />` in `ytLive.csproj`; the risk is *packaging*:
`ytLive.Tests/bin/.../ytLive.exe` exists and would ship a Debug build + test DLLs if
anyone ever zips a bin folder by hand. Never copy folders; always publish.)
2. **Condition `InternalsVisibleTo("ytLive.Tests")` to Debug only** (`ytLive.csproj:78-82`
is unconditional, so it ships in Release) — it hands the test assembly name to anyone
decompiling and advertises that `internal` members are externally reachable, which
conflicts with the obfuscation posture in `Distribution.md` §1.2.
Do **NOT** add `-p:PublishTrimmed=true`: WPF is not trim-compatible and it fails at
runtime (BAML/XAML resource resolution), not at build time. `PublishReadyToRun` is safe.
- **TASK 12** — queued future
- **TASK 13** — queued post-v1
- **TASK 14** — Branch 2 shipped; branch 3+ in progress