e78c58fc28
The distribution answer existed only in conversation, so every session re-derived it. It is now in the map, and the route decision is explicitly parked as the creator's. new TASKS/research-store-certification.md — Store Policies 7.20 + MSIX packaging: which policies bind, which don't (and why), cert economics, camera/mic gating layers, YouTube age + COPPA, the 11.12 UGC judgment call. Two real defects surfaced, neither fixed (docs-only unit): - FfmpegLocator downloads an unsigned exe from GitHub and runs it. That is policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of the 2026-09-01 404 — the pin aged out of BtbN's 14-day retention on the creator's first real recording attempt. -> TASK 48 item 1, not Store-conditional. - Distribution.md:318 recommended a $400+/yr EV cert for a SmartScreen bypass Microsoft removed in March 2024. Fixed; had it shipped it would have cost $400+/yr to buy what $150 buys. Also new: TASKS/task-48 (checklist, carved out of TASK 36 item 6) and TASKS/task-49 (chat profanity filter, not blocked). ai.md gains the durable invariants — full trust or recording breaks silently, chat is rendered never stored — plus a correction to the FFmpeg locator section. MyMistakes.md records the lesson: a policy citation is a claim about scope, not just text. MARCOM.md got the privacy-copy guard but is gitignored by design, so that edit stays local and did not travel here.
128 lines
8.7 KiB
Markdown
128 lines
8.7 KiB
Markdown
# HANDOFF — current state
|
||
|
||
**Branch:** `main` (pre-1.0, no feature branches — creator ruling 2026-08-24).
|
||
**Last pushed:** `938c5b3` (alert ticker). This unit (distribution/certification research) is
|
||
**docs-only** — no code touched, no build, no tests run.
|
||
|
||
## This unit: distribution & Store certification research is WRITTEN DOWN
|
||
|
||
The session's open question was "how do we get this in front of users without a SmartScreen
|
||
scarewall" and it had been answered **in conversation only** — which meant the next session
|
||
would re-derive it. It is now in the map, and the conversation can be dropped.
|
||
|
||
| File | What it is |
|
||
|---|---|
|
||
| `TASKS/research-store-certification.md` | **new** — the authoritative research. Store Policies **7.20** (effective 2026-10-22, re-check the version), MSIX full-trust vs AppContainer, cert economics, a ⛔/✅ table of which policies bind and which don't, the camera/mic gating layers, the YouTube age + COPPA analysis, the 11.12 UGC judgment call, and the filter design constraints |
|
||
| `TASKS/task-48-distribution-msix.md` | **new** — the executable checklist. Carved out of TASK 36 item 6 (code signing / installer / Velopack URL) so distribution has one owner |
|
||
| `TASKS/task-49-chat-profanity-filter.md` | **new** — the chat filter checklist. Not blocked |
|
||
| `Distribution.md` §4.3 | **corrected** — the EV recommendation was dead (§ below) |
|
||
| `ai.md` | new "Windows packaging & distribution" section (durable invariants) + a correction on the FFmpeg locator |
|
||
| `MyMistakes.md` | the policy-applicability lesson |
|
||
| `TASKS.md` | rows 48/49, a research index, and the TASK 36 item 6 split |
|
||
| `MARCOM.md` | ⛔ **privacy-copy guard — gitignored, so this edit is local-only and did not travel with the push** |
|
||
|
||
### Two real defects the research surfaced (both now recorded, neither fixed — no code this unit)
|
||
|
||
1. **⛔ `FfmpegLocator` downloads an unsigned exe from GitHub and runs it.** That is Store
|
||
policy **10.2.2** (dynamic code inclusion) verbatim, *and* it is the root cause of the
|
||
2026-09-01 failure: the previous daily pin aged out of BtbN's 14-day retention and the
|
||
download **404'd on the creator's first real recording attempt**. `FfmpegLocator.cs:30-35`
|
||
records the incident but still reads like a design choice. → **TASK 48 item 1.** Not
|
||
Store-conditional: bundling kills this whole class of cold-start failure and deletes the
|
||
startup network dependency. **This is the highest-value unblocked item in the repo.**
|
||
2. **⛔ `Distribution.md:318` recommended a $400+/yr EV certificate for a benefit Microsoft
|
||
deleted in March 2024.** Fixed. Had it shipped, it would have cost $400+/yr to buy exactly
|
||
what $150 buys. Lesson in `MyMistakes.md` — the recurring shape is *citing a policy or a
|
||
platform fact from memory instead of re-verifying it in the document itself.*
|
||
|
||
### ⛔ The decision that is NOT made, and belongs to the creator
|
||
|
||
**The distribution route.** Research is done and MSIX is the front-runner (full trust is viable;
|
||
we trip **none** of the four MSIX disqualifiers — no driver installed, no per-user service, no
|
||
elevation, no shell extension). Four real combinations, costed in
|
||
`TASKS/research-store-certification.md` §3:
|
||
|
||
| # | Route | Cert/yr | SmartScreen | Notes |
|
||
|---|---|---|---|---|
|
||
| A | Store MSIX + Store IAP | **$0** | none | Polar gets deleted; revenue cut; public listing |
|
||
| B | Store MSIX + **Polar** | **$0** | none | free signing **and** keep 100% — two systems to maintain |
|
||
| C | **Polar file hosting** + own cert | $120–300 | warning ramp | **the status quo already sketched in `Distribution.md:14`/`:296`** |
|
||
| D | Store EXE (policy 10.2.9) | $120–300 | warning ramp | **dominated** — cert anyway, silent install, own URL |
|
||
|
||
**Nothing else was allowed to block on this** — the user is right that most of the research is
|
||
route-independent and worth banking regardless. So: research banked, dead line fixed, and only
|
||
the packaging work is parked.
|
||
|
||
**Also still open, deliberately:** pricing (one-time vs one-time+monthly), the license provider,
|
||
and therefore all licensing copy. `OverlayHost.xaml` still claims Polar unlocks alerts — wrong,
|
||
alerts are not gated. Unresolved, queued, **not** to be papered over.
|
||
|
||
### The two findings most likely to be forgotten
|
||
|
||
- **Distribution and licensing are independent.** Policy 10.8.1 lets a **Store-distributed**
|
||
app verify licenses with **Polar**. So "should we use the Store?" does not imply "drop Polar?"
|
||
Only route A removes Polar, and that is a licensing decision riding on a distribution one.
|
||
- **⛴ Two invariants that will break silently if touched:**
|
||
- **Full trust, or recording breaks.** `DefaultRecordFolder()` writes to Downloads/MyVideos;
|
||
that passes through unvirtualized **only** at `mediumIL`. Flip the manifest to
|
||
`appContainer` and output vanishes with no error. A comment is owed there **when the
|
||
manifest lands** (TASK 48 item 6) — not before.
|
||
- **Chat is rendered, never stored.** That non-persistence half is the load-bearing part of
|
||
the 11.12 certification answer. No chat history, moderation log, analytics, or crash payload
|
||
may be added without re-arguing 11.12 first.
|
||
|
||
## Landmines
|
||
|
||
- **Stale fact inside `TASKS.md` (left alone, flagged here per the Scope Lock).** The "1.0 gates"
|
||
section asserts "**TASK 36 is now shipped**", but the catalog row 36 reads **☐ Queued** and
|
||
`task-36-gold-pass.md` still shows items 1–6 unchecked. The line most likely means *item 2*
|
||
(branding flash goes live) shipped at `9761b1d`. **Needs a one-line fix, not a code change** —
|
||
flagging rather than fixing because it is not this unit's job.
|
||
- **A stale `ytLive.exe` (PID 2544) locked `bin/.../ytLive.exe`** and broke `dotnet run` with
|
||
MSB3027. Killed. **If the build fails to copy `ytLive.exe`, check for a running instance first.**
|
||
- **`LayerReorderPersistenceTests.RealMouseDrag_OnTheLayerList_PersistsTheReorder` is flaky by
|
||
environment** (needs an interactive desktop session; 2 fail / 1 pass in isolation). **Run the
|
||
suite with ytLive CLOSED.** Not a regression.
|
||
- **`RealAppHost.RunAsync` exists for a reason** — a frame-pump test MUST `await` inside it. A
|
||
blocking wait occupies the one shared STA thread and **hangs the whole suite with no output.**
|
||
Always background a `vstest` run and poll the log; a foreground piped `vstest` returns nothing
|
||
in this shell even on success.
|
||
- **`GlobalHotkeys`: two instances registering the SAME global hotkey** — Windows refuses the
|
||
second. Left alone deliberately.
|
||
- **MSIX writes under a real package identity are unverified.** The docs say full trust passes
|
||
user-profile writes through, but confirm on a real packaged build before trusting it with
|
||
recordings (TASK 48 item 6).
|
||
|
||
## Test state
|
||
|
||
**367/367 as of `938c5b3`.** Not re-run for this unit — docs only, no code touched.
|
||
|
||
## Uncommitted / untracked
|
||
|
||
- `MARCOM.md` — the privacy-copy guard was added but the file is **gitignored by design**
|
||
(confidential business file, `.gitignore:11`). It stays local, as intended. Same for
|
||
`MONETIZATION.md` and `CREDENTIALS.md` — **never commit those.**
|
||
|
||
## Next
|
||
|
||
1. **Bundle ffmpeg (TASK 48 item 1)** — unblocked, recommended on every route, and it fixes a
|
||
real user-facing failure. *This is the next code unit.*
|
||
2. **The route decision** (creator) — A/B/C above, once the ffmpeg fix is out of the way.
|
||
3. **Vertical recording verification** — the compositor tier is proven by
|
||
`Render_VerticalTier_Outputs_1080x1920_From_The_Center_Crop`; the *record* path has never
|
||
been run. `FramePump.cs:645` flags off-size tiers as a known follow-up.
|
||
4. **Multi-instance** — route `FfmpegLocator._toolsDir` through `InstanceProfile` (same shared
|
||
extraction race as #1, and it becomes moot if ffmpeg is bundled). Confirm the launch method:
|
||
`$env:YTLIVE_INSTANCE=2` + `dotnet run --no-build` in a second shell is the known-good path.
|
||
5. **Post-session efficacy report** — roll up `CurrentHealth` (dropped frames, duration, health
|
||
message) when a stream or recording ends. `SessionTeardownTests` is the natural home.
|
||
6. **`scripts/publish.sh` + Debug-only `InternalsVisibleTo` + the `LlamaCasty.exe` rename** —
|
||
still queued from 2026-09-26; do **NOT** add `-p:PublishTrimmed=true` (WPF fails at runtime,
|
||
not build time). See `TASKS.md` → "Shipping / release build".
|
||
7. **The alert-gating copy** (`OverlayHost.xaml`) — fix the copy or gate the alerts; do not leave
|
||
it lying. Blocked behind the pricing ruling.
|
||
8. **The camera-privacy measurement** — does the Win11 desktop-app camera toggle actually gate a
|
||
DShow webcam and a capture card? Gates all privacy-forward copy (`MARCOM.md` guard).
|
||
9. **TASK 36:212 stale "shipped" line** — one-line fix, needs a hand.
|
||
10. Ship-checklist items live in `TASKS.md` → "1.0 gates".
|