# HANDOFF — current state **Branch:** `main` (pre-1.0, no feature branches — creator ruling 2026-08-24). **Last pushed:** `938c5b3` (alert ticker). This unit (distribution/certification research) is **docs-only** — no code touched, no build, no tests run. ## This unit: distribution & Store certification research is WRITTEN DOWN The session's open question was "how do we get this in front of users without a SmartScreen scarewall" and it had been answered **in conversation only** — which meant the next session would re-derive it. It is now in the map, and the conversation can be dropped. | File | What it is | |---|---| | `TASKS/research-store-certification.md` | **new** — the authoritative research. Store Policies **7.20** (effective 2026-10-22, re-check the version), MSIX full-trust vs AppContainer, cert economics, a ⛔/✅ table of which policies bind and which don't, the camera/mic gating layers, the YouTube age + COPPA analysis, the 11.12 UGC judgment call, and the filter design constraints | | `TASKS/task-48-distribution-msix.md` | **new** — the executable checklist. Carved out of TASK 36 item 6 (code signing / installer / Velopack URL) so distribution has one owner | | `TASKS/task-49-chat-profanity-filter.md` | **new** — the chat filter checklist. Not blocked | | `Distribution.md` §4.3 | **corrected** — the EV recommendation was dead (§ below) | | `ai.md` | new "Windows packaging & distribution" section (durable invariants) + a correction on the FFmpeg locator | | `MyMistakes.md` | the policy-applicability lesson | | `TASKS.md` | rows 48/49, a research index, and the TASK 36 item 6 split | | `MARCOM.md` | ⛔ **privacy-copy guard — gitignored, so this edit is local-only and did not travel with the push** | ### Two real defects the research surfaced (both now recorded, neither fixed — no code this unit) 1. **⛔ `FfmpegLocator` downloads an unsigned exe from GitHub and runs it.** That is Store policy **10.2.2** (dynamic code inclusion) verbatim, *and* it is the root cause of the 2026-09-01 failure: the previous daily pin aged out of BtbN's 14-day retention and the download **404'd on the creator's first real recording attempt**. `FfmpegLocator.cs:30-35` records the incident but still reads like a design choice. → **TASK 48 item 1.** Not Store-conditional: bundling kills this whole class of cold-start failure and deletes the startup network dependency. **This is the highest-value unblocked item in the repo.** 2. **⛔ `Distribution.md:318` recommended a $400+/yr EV certificate for a benefit Microsoft deleted in March 2024.** Fixed. Had it shipped, it would have cost $400+/yr to buy exactly what $150 buys. Lesson in `MyMistakes.md` — the recurring shape is *citing a policy or a platform fact from memory instead of re-verifying it in the document itself.* ### ⛔ The decision that is NOT made, and belongs to the creator **The distribution route.** Research is done and MSIX is the front-runner (full trust is viable; we trip **none** of the four MSIX disqualifiers — no driver installed, no per-user service, no elevation, no shell extension). Four real combinations, costed in `TASKS/research-store-certification.md` §3: | # | Route | Cert/yr | SmartScreen | Notes | |---|---|---|---|---| | A | Store MSIX + Store IAP | **$0** | none | Polar gets deleted; revenue cut; public listing | | B | Store MSIX + **Polar** | **$0** | none | free signing **and** keep 100% — two systems to maintain | | C | **Polar file hosting** + own cert | $120–300 | warning ramp | **the status quo already sketched in `Distribution.md:14`/`:296`** | | D | Store EXE (policy 10.2.9) | $120–300 | warning ramp | **dominated** — cert anyway, silent install, own URL | **Nothing else was allowed to block on this** — the user is right that most of the research is route-independent and worth banking regardless. So: research banked, dead line fixed, and only the packaging work is parked. **Also still open, deliberately:** pricing (one-time vs one-time+monthly), the license provider, and therefore all licensing copy. `OverlayHost.xaml` still claims Polar unlocks alerts — wrong, alerts are not gated. Unresolved, queued, **not** to be papered over. ### The two findings most likely to be forgotten - **Distribution and licensing are independent.** Policy 10.8.1 lets a **Store-distributed** app verify licenses with **Polar**. So "should we use the Store?" does not imply "drop Polar?" Only route A removes Polar, and that is a licensing decision riding on a distribution one. - **⛴ Two invariants that will break silently if touched:** - **Full trust, or recording breaks.** `DefaultRecordFolder()` writes to Downloads/MyVideos; that passes through unvirtualized **only** at `mediumIL`. Flip the manifest to `appContainer` and output vanishes with no error. A comment is owed there **when the manifest lands** (TASK 48 item 6) — not before. - **Chat is rendered, never stored.** That non-persistence half is the load-bearing part of the 11.12 certification answer. No chat history, moderation log, analytics, or crash payload may be added without re-arguing 11.12 first. ## Landmines - **Stale fact inside `TASKS.md` (left alone, flagged here per the Scope Lock).** The "1.0 gates" section asserts "**TASK 36 is now shipped**", but the catalog row 36 reads **☐ Queued** and `task-36-gold-pass.md` still shows items 1–6 unchecked. The line most likely means *item 2* (branding flash goes live) shipped at `9761b1d`. **Needs a one-line fix, not a code change** — flagging rather than fixing because it is not this unit's job. - **A stale `ytLive.exe` (PID 2544) locked `bin/.../ytLive.exe`** and broke `dotnet run` with MSB3027. Killed. **If the build fails to copy `ytLive.exe`, check for a running instance first.** - **`LayerReorderPersistenceTests.RealMouseDrag_OnTheLayerList_PersistsTheReorder` is flaky by environment** (needs an interactive desktop session; 2 fail / 1 pass in isolation). **Run the suite with ytLive CLOSED.** Not a regression. - **`RealAppHost.RunAsync` exists for a reason** — a frame-pump test MUST `await` inside it. A blocking wait occupies the one shared STA thread and **hangs the whole suite with no output.** Always background a `vstest` run and poll the log; a foreground piped `vstest` returns nothing in this shell even on success. - **`GlobalHotkeys`: two instances registering the SAME global hotkey** — Windows refuses the second. Left alone deliberately. - **MSIX writes under a real package identity are unverified.** The docs say full trust passes user-profile writes through, but confirm on a real packaged build before trusting it with recordings (TASK 48 item 6). ## Test state **367/367 as of `938c5b3`.** Not re-run for this unit — docs only, no code touched. ## Uncommitted / untracked - `MARCOM.md` — the privacy-copy guard was added but the file is **gitignored by design** (confidential business file, `.gitignore:11`). It stays local, as intended. Same for `MONETIZATION.md` and `CREDENTIALS.md` — **never commit those.** ## Next 1. **Bundle ffmpeg (TASK 48 item 1)** — unblocked, recommended on every route, and it fixes a real user-facing failure. *This is the next code unit.* 2. **The route decision** (creator) — A/B/C above, once the ffmpeg fix is out of the way. 3. **Vertical recording verification** — the compositor tier is proven by `Render_VerticalTier_Outputs_1080x1920_From_The_Center_Crop`; the *record* path has never been run. `FramePump.cs:645` flags off-size tiers as a known follow-up. 4. **Multi-instance** — route `FfmpegLocator._toolsDir` through `InstanceProfile` (same shared extraction race as #1, and it becomes moot if ffmpeg is bundled). Confirm the launch method: `$env:YTLIVE_INSTANCE=2` + `dotnet run --no-build` in a second shell is the known-good path. 5. **Post-session efficacy report** — roll up `CurrentHealth` (dropped frames, duration, health message) when a stream or recording ends. `SessionTeardownTests` is the natural home. 6. **`scripts/publish.sh` + Debug-only `InternalsVisibleTo` + the `LlamaCasty.exe` rename** — still queued from 2026-09-26; do **NOT** add `-p:PublishTrimmed=true` (WPF fails at runtime, not build time). See `TASKS.md` → "Shipping / release build". 7. **The alert-gating copy** (`OverlayHost.xaml`) — fix the copy or gate the alerts; do not leave it lying. Blocked behind the pricing ruling. 8. **The camera-privacy measurement** — does the Win11 desktop-app camera toggle actually gate a DShow webcam and a capture card? Gates all privacy-forward copy (`MARCOM.md` guard). 9. **TASK 36:212 stale "shipped" line** — one-line fix, needs a hand. 10. Ship-checklist items live in `TASKS.md` → "1.0 gates".