Files
LlamaCasty/HANDOFF.md
T
gramps e78c58fc28 docs: bank the Windows Store + signing research, and fix the dead EV-certificate line
The distribution answer existed only in conversation, so every session re-derived
it. It is now in the map, and the route decision is explicitly parked as the
creator's.

new TASKS/research-store-certification.md — Store Policies 7.20 + MSIX packaging:
which policies bind, which don't (and why), cert economics, camera/mic gating
layers, YouTube age + COPPA, the 11.12 UGC judgment call.

Two real defects surfaced, neither fixed (docs-only unit):
- FfmpegLocator downloads an unsigned exe from GitHub and runs it. That is
  policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of
  the 2026-09-01 404 — the pin aged out of BtbN's 14-day retention on the
  creator's first real recording attempt. -> TASK 48 item 1, not
  Store-conditional.
- Distribution.md:318 recommended a $400+/yr EV cert for a SmartScreen bypass
  Microsoft removed in March 2024. Fixed; had it shipped it would have cost
  $400+/yr to buy what $150 buys.

Also new: TASKS/task-48 (checklist, carved out of TASK 36 item 6) and
TASKS/task-49 (chat profanity filter, not blocked). ai.md gains the durable
invariants — full trust or recording breaks silently, chat is rendered never
stored — plus a correction to the FFmpeg locator section. MyMistakes.md records
the lesson: a policy citation is a claim about scope, not just text.

MARCOM.md got the privacy-copy guard but is gitignored by design, so that edit
stays local and did not travel here.
2026-09-27 14:17:13 -07:00

8.7 KiB
Raw Blame History

HANDOFF — current state

Branch: main (pre-1.0, no feature branches — creator ruling 2026-08-24). Last pushed: 938c5b3 (alert ticker). This unit (distribution/certification research) is docs-only — no code touched, no build, no tests run.

This unit: distribution & Store certification research is WRITTEN DOWN

The session's open question was "how do we get this in front of users without a SmartScreen scarewall" and it had been answered in conversation only — which meant the next session would re-derive it. It is now in the map, and the conversation can be dropped.

File What it is
TASKS/research-store-certification.md new — the authoritative research. Store Policies 7.20 (effective 2026-10-22, re-check the version), MSIX full-trust vs AppContainer, cert economics, a ⛔/✅ table of which policies bind and which don't, the camera/mic gating layers, the YouTube age + COPPA analysis, the 11.12 UGC judgment call, and the filter design constraints
TASKS/task-48-distribution-msix.md new — the executable checklist. Carved out of TASK 36 item 6 (code signing / installer / Velopack URL) so distribution has one owner
TASKS/task-49-chat-profanity-filter.md new — the chat filter checklist. Not blocked
Distribution.md §4.3 corrected — the EV recommendation was dead (§ below)
ai.md new "Windows packaging & distribution" section (durable invariants) + a correction on the FFmpeg locator
MyMistakes.md the policy-applicability lesson
TASKS.md rows 48/49, a research index, and the TASK 36 item 6 split
MARCOM.md ⛔ privacy-copy guard — gitignored, so this edit is local-only and did not travel with the push

Two real defects the research surfaced (both now recorded, neither fixed — no code this unit)

  1. ⛔ FfmpegLocator downloads an unsigned exe from GitHub and runs it. That is Store policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of the 2026-09-01 failure: the previous daily pin aged out of BtbN's 14-day retention and the download 404'd on the creator's first real recording attempt. FfmpegLocator.cs:30-35 records the incident but still reads like a design choice. → TASK 48 item 1. Not Store-conditional: bundling kills this whole class of cold-start failure and deletes the startup network dependency. This is the highest-value unblocked item in the repo.
  2. ⛔ Distribution.md:318 recommended a $400+/yr EV certificate for a benefit Microsoft deleted in March 2024. Fixed. Had it shipped, it would have cost $400+/yr to buy exactly what $150 buys. Lesson in MyMistakes.md — the recurring shape is citing a policy or a platform fact from memory instead of re-verifying it in the document itself.

⛔ The decision that is NOT made, and belongs to the creator

The distribution route. Research is done and MSIX is the front-runner (full trust is viable; we trip none of the four MSIX disqualifiers — no driver installed, no per-user service, no elevation, no shell extension). Four real combinations, costed in TASKS/research-store-certification.md §3:

# Route Cert/yr SmartScreen Notes
A Store MSIX + Store IAP $0 none Polar gets deleted; revenue cut; public listing
B Store MSIX + Polar $0 none free signing and keep 100% — two systems to maintain
C Polar file hosting + own cert $120–300 warning ramp the status quo already sketched in Distribution.md:14/:296
D Store EXE (policy 10.2.9) $120–300 warning ramp dominated — cert anyway, silent install, own URL

Nothing else was allowed to block on this — the user is right that most of the research is route-independent and worth banking regardless. So: research banked, dead line fixed, and only the packaging work is parked.

Also still open, deliberately: pricing (one-time vs one-time+monthly), the license provider, and therefore all licensing copy. OverlayHost.xaml still claims Polar unlocks alerts — wrong, alerts are not gated. Unresolved, queued, not to be papered over.

The two findings most likely to be forgotten

  • Distribution and licensing are independent. Policy 10.8.1 lets a Store-distributed app verify licenses with Polar. So "should we use the Store?" does not imply "drop Polar?" Only route A removes Polar, and that is a licensing decision riding on a distribution one.
  • ⛴ Two invariants that will break silently if touched:
    • Full trust, or recording breaks. DefaultRecordFolder() writes to Downloads/MyVideos; that passes through unvirtualized only at mediumIL. Flip the manifest to appContainer and output vanishes with no error. A comment is owed there when the manifest lands (TASK 48 item 6) — not before.
    • Chat is rendered, never stored. That non-persistence half is the load-bearing part of the 11.12 certification answer. No chat history, moderation log, analytics, or crash payload may be added without re-arguing 11.12 first.

Landmines

  • Stale fact inside TASKS.md (left alone, flagged here per the Scope Lock). The "1.0 gates" section asserts "TASK 36 is now shipped", but the catalog row 36 reads ☐ Queued and task-36-gold-pass.md still shows items 1–6 unchecked. The line most likely means item 2 (branding flash goes live) shipped at 9761b1d. Needs a one-line fix, not a code change — flagging rather than fixing because it is not this unit's job.
  • A stale ytLive.exe (PID 2544) locked bin/.../ytLive.exe and broke dotnet run with MSB3027. Killed. If the build fails to copy ytLive.exe, check for a running instance first.
  • LayerReorderPersistenceTests.RealMouseDrag_OnTheLayerList_PersistsTheReorder is flaky by environment (needs an interactive desktop session; 2 fail / 1 pass in isolation). Run the suite with ytLive CLOSED. Not a regression.
  • RealAppHost.RunAsync exists for a reason — a frame-pump test MUST await inside it. A blocking wait occupies the one shared STA thread and hangs the whole suite with no output. Always background a vstest run and poll the log; a foreground piped vstest returns nothing in this shell even on success.
  • GlobalHotkeys: two instances registering the SAME global hotkey — Windows refuses the second. Left alone deliberately.
  • MSIX writes under a real package identity are unverified. The docs say full trust passes user-profile writes through, but confirm on a real packaged build before trusting it with recordings (TASK 48 item 6).

Test state

367/367 as of 938c5b3. Not re-run for this unit — docs only, no code touched.

Uncommitted / untracked

  • MARCOM.md — the privacy-copy guard was added but the file is gitignored by design (confidential business file, .gitignore:11). It stays local, as intended. Same for MONETIZATION.md and CREDENTIALS.md — never commit those.

Next

  1. Bundle ffmpeg (TASK 48 item 1) — unblocked, recommended on every route, and it fixes a real user-facing failure. This is the next code unit.
  2. The route decision (creator) — A/B/C above, once the ffmpeg fix is out of the way.
  3. Vertical recording verification — the compositor tier is proven by Render_VerticalTier_Outputs_1080x1920_From_The_Center_Crop; the record path has never been run. FramePump.cs:645 flags off-size tiers as a known follow-up.
  4. Multi-instance — route FfmpegLocator._toolsDir through InstanceProfile (same shared extraction race as #1, and it becomes moot if ffmpeg is bundled). Confirm the launch method: $env:YTLIVE_INSTANCE=2 + dotnet run --no-build in a second shell is the known-good path.
  5. Post-session efficacy report — roll up CurrentHealth (dropped frames, duration, health message) when a stream or recording ends. SessionTeardownTests is the natural home.
  6. scripts/publish.sh + Debug-only InternalsVisibleTo + the LlamaCasty.exe rename — still queued from 2026-09-26; do NOT add -p:PublishTrimmed=true (WPF fails at runtime, not build time). See TASKS.md → "Shipping / release build".
  7. The alert-gating copy (OverlayHost.xaml) — fix the copy or gate the alerts; do not leave it lying. Blocked behind the pricing ruling.
  8. The camera-privacy measurement — does the Win11 desktop-app camera toggle actually gate a DShow webcam and a capture card? Gates all privacy-forward copy (MARCOM.md guard).
  9. TASK 36:212 stale "shipped" line — one-line fix, needs a hand.
  10. Ship-checklist items live in TASKS.md → "1.0 gates".