The distribution answer existed only in conversation, so every session re-derived it. It is now in the map, and the route decision is explicitly parked as the creator's. new TASKS/research-store-certification.md — Store Policies 7.20 + MSIX packaging: which policies bind, which don't (and why), cert economics, camera/mic gating layers, YouTube age + COPPA, the 11.12 UGC judgment call. Two real defects surfaced, neither fixed (docs-only unit): - FfmpegLocator downloads an unsigned exe from GitHub and runs it. That is policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of the 2026-09-01 404 — the pin aged out of BtbN's 14-day retention on the creator's first real recording attempt. -> TASK 48 item 1, not Store-conditional. - Distribution.md:318 recommended a $400+/yr EV cert for a SmartScreen bypass Microsoft removed in March 2024. Fixed; had it shipped it would have cost $400+/yr to buy what $150 buys. Also new: TASKS/task-48 (checklist, carved out of TASK 36 item 6) and TASKS/task-49 (chat profanity filter, not blocked). ai.md gains the durable invariants — full trust or recording breaks silently, chat is rendered never stored — plus a correction to the FFmpeg locator section. MyMistakes.md records the lesson: a policy citation is a claim about scope, not just text. MARCOM.md got the privacy-copy guard but is gitignored by design, so that edit stays local and did not travel here.
8.7 KiB
HANDOFF — current state
Branch: main (pre-1.0, no feature branches — creator ruling 2026-08-24).
Last pushed: 938c5b3 (alert ticker). This unit (distribution/certification research) is
docs-only — no code touched, no build, no tests run.
This unit: distribution & Store certification research is WRITTEN DOWN
The session's open question was "how do we get this in front of users without a SmartScreen scarewall" and it had been answered in conversation only — which meant the next session would re-derive it. It is now in the map, and the conversation can be dropped.
| File | What it is |
|---|---|
TASKS/research-store-certification.md |
new — the authoritative research. Store Policies 7.20 (effective 2026-10-22, re-check the version), MSIX full-trust vs AppContainer, cert economics, a ⛔/✅ table of which policies bind and which don't, the camera/mic gating layers, the YouTube age + COPPA analysis, the 11.12 UGC judgment call, and the filter design constraints |
TASKS/task-48-distribution-msix.md |
new — the executable checklist. Carved out of TASK 36 item 6 (code signing / installer / Velopack URL) so distribution has one owner |
TASKS/task-49-chat-profanity-filter.md |
new — the chat filter checklist. Not blocked |
Distribution.md §4.3 |
corrected — the EV recommendation was dead (§ below) |
ai.md |
new "Windows packaging & distribution" section (durable invariants) + a correction on the FFmpeg locator |
MyMistakes.md |
the policy-applicability lesson |
TASKS.md |
rows 48/49, a research index, and the TASK 36 item 6 split |
MARCOM.md |
⛔ privacy-copy guard — gitignored, so this edit is local-only and did not travel with the push |
Two real defects the research surfaced (both now recorded, neither fixed — no code this unit)
- ⛔
FfmpegLocatordownloads an unsigned exe from GitHub and runs it. That is Store policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of the 2026-09-01 failure: the previous daily pin aged out of BtbN's 14-day retention and the download 404'd on the creator's first real recording attempt.FfmpegLocator.cs:30-35records the incident but still reads like a design choice. → TASK 48 item 1. Not Store-conditional: bundling kills this whole class of cold-start failure and deletes the startup network dependency. This is the highest-value unblocked item in the repo. - ⛔
Distribution.md:318recommended a $400+/yr EV certificate for a benefit Microsoft deleted in March 2024. Fixed. Had it shipped, it would have cost $400+/yr to buy exactly what $150 buys. Lesson inMyMistakes.md— the recurring shape is citing a policy or a platform fact from memory instead of re-verifying it in the document itself.
⛔ The decision that is NOT made, and belongs to the creator
The distribution route. Research is done and MSIX is the front-runner (full trust is viable;
we trip none of the four MSIX disqualifiers — no driver installed, no per-user service, no
elevation, no shell extension). Four real combinations, costed in
TASKS/research-store-certification.md §3:
| # | Route | Cert/yr | SmartScreen | Notes |
|---|---|---|---|---|
| A | Store MSIX + Store IAP | $0 | none | Polar gets deleted; revenue cut; public listing |
| B | Store MSIX + Polar | $0 | none | free signing and keep 100% — two systems to maintain |
| C | Polar file hosting + own cert | $120–300 | warning ramp | the status quo already sketched in Distribution.md:14/:296 |
| D | Store EXE (policy 10.2.9) | $120–300 | warning ramp | dominated — cert anyway, silent install, own URL |
Nothing else was allowed to block on this — the user is right that most of the research is route-independent and worth banking regardless. So: research banked, dead line fixed, and only the packaging work is parked.
Also still open, deliberately: pricing (one-time vs one-time+monthly), the license provider,
and therefore all licensing copy. OverlayHost.xaml still claims Polar unlocks alerts — wrong,
alerts are not gated. Unresolved, queued, not to be papered over.
The two findings most likely to be forgotten
- Distribution and licensing are independent. Policy 10.8.1 lets a Store-distributed app verify licenses with Polar. So "should we use the Store?" does not imply "drop Polar?" Only route A removes Polar, and that is a licensing decision riding on a distribution one.
- ⛴ Two invariants that will break silently if touched:
- Full trust, or recording breaks.
DefaultRecordFolder()writes to Downloads/MyVideos; that passes through unvirtualized only atmediumIL. Flip the manifest toappContainerand output vanishes with no error. A comment is owed there when the manifest lands (TASK 48 item 6) — not before. - Chat is rendered, never stored. That non-persistence half is the load-bearing part of the 11.12 certification answer. No chat history, moderation log, analytics, or crash payload may be added without re-arguing 11.12 first.
- Full trust, or recording breaks.
Landmines
- Stale fact inside
TASKS.md(left alone, flagged here per the Scope Lock). The "1.0 gates" section asserts "TASK 36 is now shipped", but the catalog row 36 reads ☐ Queued andtask-36-gold-pass.mdstill shows items 1–6 unchecked. The line most likely means item 2 (branding flash goes live) shipped at9761b1d. Needs a one-line fix, not a code change — flagging rather than fixing because it is not this unit's job. - A stale
ytLive.exe(PID 2544) lockedbin/.../ytLive.exeand brokedotnet runwith MSB3027. Killed. If the build fails to copyytLive.exe, check for a running instance first. LayerReorderPersistenceTests.RealMouseDrag_OnTheLayerList_PersistsTheReorderis flaky by environment (needs an interactive desktop session; 2 fail / 1 pass in isolation). Run the suite with ytLive CLOSED. Not a regression.RealAppHost.RunAsyncexists for a reason — a frame-pump test MUSTawaitinside it. A blocking wait occupies the one shared STA thread and hangs the whole suite with no output. Always background avstestrun and poll the log; a foreground pipedvstestreturns nothing in this shell even on success.GlobalHotkeys: two instances registering the SAME global hotkey — Windows refuses the second. Left alone deliberately.- MSIX writes under a real package identity are unverified. The docs say full trust passes user-profile writes through, but confirm on a real packaged build before trusting it with recordings (TASK 48 item 6).
Test state
367/367 as of 938c5b3. Not re-run for this unit — docs only, no code touched.
Uncommitted / untracked
MARCOM.md— the privacy-copy guard was added but the file is gitignored by design (confidential business file,.gitignore:11). It stays local, as intended. Same forMONETIZATION.mdandCREDENTIALS.md— never commit those.
Next
- Bundle ffmpeg (TASK 48 item 1) — unblocked, recommended on every route, and it fixes a real user-facing failure. This is the next code unit.
- The route decision (creator) — A/B/C above, once the ffmpeg fix is out of the way.
- Vertical recording verification — the compositor tier is proven by
Render_VerticalTier_Outputs_1080x1920_From_The_Center_Crop; the record path has never been run.FramePump.cs:645flags off-size tiers as a known follow-up. - Multi-instance — route
FfmpegLocator._toolsDirthroughInstanceProfile(same shared extraction race as #1, and it becomes moot if ffmpeg is bundled). Confirm the launch method:$env:YTLIVE_INSTANCE=2+dotnet run --no-buildin a second shell is the known-good path. - Post-session efficacy report — roll up
CurrentHealth(dropped frames, duration, health message) when a stream or recording ends.SessionTeardownTestsis the natural home. scripts/publish.sh+ Debug-onlyInternalsVisibleTo+ theLlamaCasty.exerename — still queued from 2026-09-26; do NOT add-p:PublishTrimmed=true(WPF fails at runtime, not build time). SeeTASKS.md→ "Shipping / release build".- The alert-gating copy (
OverlayHost.xaml) — fix the copy or gate the alerts; do not leave it lying. Blocked behind the pricing ruling. - The camera-privacy measurement — does the Win11 desktop-app camera toggle actually gate a
DShow webcam and a capture card? Gates all privacy-forward copy (
MARCOM.mdguard). - TASK 36:212 stale "shipped" line — one-line fix, needs a hand.
- Ship-checklist items live in
TASKS.md→ "1.0 gates".