Files
LlamaCasty/HANDOFF.md
T
gramps e78c58fc28 docs: bank the Windows Store + signing research, and fix the dead EV-certificate line
The distribution answer existed only in conversation, so every session re-derived
it. It is now in the map, and the route decision is explicitly parked as the
creator's.

new TASKS/research-store-certification.md — Store Policies 7.20 + MSIX packaging:
which policies bind, which don't (and why), cert economics, camera/mic gating
layers, YouTube age + COPPA, the 11.12 UGC judgment call.

Two real defects surfaced, neither fixed (docs-only unit):
- FfmpegLocator downloads an unsigned exe from GitHub and runs it. That is
  policy 10.2.2 (dynamic code inclusion) verbatim, and it is the root cause of
  the 2026-09-01 404 — the pin aged out of BtbN's 14-day retention on the
  creator's first real recording attempt. -> TASK 48 item 1, not
  Store-conditional.
- Distribution.md:318 recommended a $400+/yr EV cert for a SmartScreen bypass
  Microsoft removed in March 2024. Fixed; had it shipped it would have cost
  $400+/yr to buy what $150 buys.

Also new: TASKS/task-48 (checklist, carved out of TASK 36 item 6) and
TASKS/task-49 (chat profanity filter, not blocked). ai.md gains the durable
invariants — full trust or recording breaks silently, chat is rendered never
stored — plus a correction to the FFmpeg locator section. MyMistakes.md records
the lesson: a policy citation is a claim about scope, not just text.

MARCOM.md got the privacy-copy guard but is gitignored by design, so that edit
stays local and did not travel here.
2026-09-27 14:17:13 -07:00

128 lines
8.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# HANDOFF — current state
**Branch:** `main` (pre-1.0, no feature branches — creator ruling 2026-08-24).
**Last pushed:** `938c5b3` (alert ticker). This unit (distribution/certification research) is
**docs-only** — no code touched, no build, no tests run.
## This unit: distribution & Store certification research is WRITTEN DOWN
The session's open question was "how do we get this in front of users without a SmartScreen
scarewall" and it had been answered **in conversation only** — which meant the next session
would re-derive it. It is now in the map, and the conversation can be dropped.
| File | What it is |
|---|---|
| `TASKS/research-store-certification.md` | **new** — the authoritative research. Store Policies **7.20** (effective 2026-10-22, re-check the version), MSIX full-trust vs AppContainer, cert economics, a ⛔/✅ table of which policies bind and which don't, the camera/mic gating layers, the YouTube age + COPPA analysis, the 11.12 UGC judgment call, and the filter design constraints |
| `TASKS/task-48-distribution-msix.md` | **new** — the executable checklist. Carved out of TASK 36 item 6 (code signing / installer / Velopack URL) so distribution has one owner |
| `TASKS/task-49-chat-profanity-filter.md` | **new** — the chat filter checklist. Not blocked |
| `Distribution.md` §4.3 | **corrected** — the EV recommendation was dead (§ below) |
| `ai.md` | new "Windows packaging & distribution" section (durable invariants) + a correction on the FFmpeg locator |
| `MyMistakes.md` | the policy-applicability lesson |
| `TASKS.md` | rows 48/49, a research index, and the TASK 36 item 6 split |
| `MARCOM.md` | ⛔ **privacy-copy guard — gitignored, so this edit is local-only and did not travel with the push** |
### Two real defects the research surfaced (both now recorded, neither fixed — no code this unit)
1. **⛔ `FfmpegLocator` downloads an unsigned exe from GitHub and runs it.** That is Store
policy **10.2.2** (dynamic code inclusion) verbatim, *and* it is the root cause of the
2026-09-01 failure: the previous daily pin aged out of BtbN's 14-day retention and the
download **404'd on the creator's first real recording attempt**. `FfmpegLocator.cs:30-35`
records the incident but still reads like a design choice. → **TASK 48 item 1.** Not
Store-conditional: bundling kills this whole class of cold-start failure and deletes the
startup network dependency. **This is the highest-value unblocked item in the repo.**
2. **⛔ `Distribution.md:318` recommended a $400+/yr EV certificate for a benefit Microsoft
deleted in March 2024.** Fixed. Had it shipped, it would have cost $400+/yr to buy exactly
what $150 buys. Lesson in `MyMistakes.md` — the recurring shape is *citing a policy or a
platform fact from memory instead of re-verifying it in the document itself.*
### ⛔ The decision that is NOT made, and belongs to the creator
**The distribution route.** Research is done and MSIX is the front-runner (full trust is viable;
we trip **none** of the four MSIX disqualifiers — no driver installed, no per-user service, no
elevation, no shell extension). Four real combinations, costed in
`TASKS/research-store-certification.md` §3:
| # | Route | Cert/yr | SmartScreen | Notes |
|---|---|---|---|---|
| A | Store MSIX + Store IAP | **$0** | none | Polar gets deleted; revenue cut; public listing |
| B | Store MSIX + **Polar** | **$0** | none | free signing **and** keep 100% — two systems to maintain |
| C | **Polar file hosting** + own cert | $120–300 | warning ramp | **the status quo already sketched in `Distribution.md:14`/`:296`** |
| D | Store EXE (policy 10.2.9) | $120–300 | warning ramp | **dominated** — cert anyway, silent install, own URL |
**Nothing else was allowed to block on this** — the user is right that most of the research is
route-independent and worth banking regardless. So: research banked, dead line fixed, and only
the packaging work is parked.
**Also still open, deliberately:** pricing (one-time vs one-time+monthly), the license provider,
and therefore all licensing copy. `OverlayHost.xaml` still claims Polar unlocks alerts — wrong,
alerts are not gated. Unresolved, queued, **not** to be papered over.
### The two findings most likely to be forgotten
- **Distribution and licensing are independent.** Policy 10.8.1 lets a **Store-distributed**
app verify licenses with **Polar**. So "should we use the Store?" does not imply "drop Polar?"
Only route A removes Polar, and that is a licensing decision riding on a distribution one.
- **⛴ Two invariants that will break silently if touched:**
- **Full trust, or recording breaks.** `DefaultRecordFolder()` writes to Downloads/MyVideos;
that passes through unvirtualized **only** at `mediumIL`. Flip the manifest to
`appContainer` and output vanishes with no error. A comment is owed there **when the
manifest lands** (TASK 48 item 6) — not before.
- **Chat is rendered, never stored.** That non-persistence half is the load-bearing part of
the 11.12 certification answer. No chat history, moderation log, analytics, or crash payload
may be added without re-arguing 11.12 first.
## Landmines
- **Stale fact inside `TASKS.md` (left alone, flagged here per the Scope Lock).** The "1.0 gates"
section asserts "**TASK 36 is now shipped**", but the catalog row 36 reads **☐ Queued** and
`task-36-gold-pass.md` still shows items 1–6 unchecked. The line most likely means *item 2*
(branding flash goes live) shipped at `9761b1d`. **Needs a one-line fix, not a code change** —
flagging rather than fixing because it is not this unit's job.
- **A stale `ytLive.exe` (PID 2544) locked `bin/.../ytLive.exe`** and broke `dotnet run` with
MSB3027. Killed. **If the build fails to copy `ytLive.exe`, check for a running instance first.**
- **`LayerReorderPersistenceTests.RealMouseDrag_OnTheLayerList_PersistsTheReorder` is flaky by
environment** (needs an interactive desktop session; 2 fail / 1 pass in isolation). **Run the
suite with ytLive CLOSED.** Not a regression.
- **`RealAppHost.RunAsync` exists for a reason** — a frame-pump test MUST `await` inside it. A
blocking wait occupies the one shared STA thread and **hangs the whole suite with no output.**
Always background a `vstest` run and poll the log; a foreground piped `vstest` returns nothing
in this shell even on success.
- **`GlobalHotkeys`: two instances registering the SAME global hotkey** — Windows refuses the
second. Left alone deliberately.
- **MSIX writes under a real package identity are unverified.** The docs say full trust passes
user-profile writes through, but confirm on a real packaged build before trusting it with
recordings (TASK 48 item 6).
## Test state
**367/367 as of `938c5b3`.** Not re-run for this unit — docs only, no code touched.
## Uncommitted / untracked
- `MARCOM.md` — the privacy-copy guard was added but the file is **gitignored by design**
(confidential business file, `.gitignore:11`). It stays local, as intended. Same for
`MONETIZATION.md` and `CREDENTIALS.md` — **never commit those.**
## Next
1. **Bundle ffmpeg (TASK 48 item 1)** — unblocked, recommended on every route, and it fixes a
real user-facing failure. *This is the next code unit.*
2. **The route decision** (creator) — A/B/C above, once the ffmpeg fix is out of the way.
3. **Vertical recording verification** — the compositor tier is proven by
`Render_VerticalTier_Outputs_1080x1920_From_The_Center_Crop`; the *record* path has never
been run. `FramePump.cs:645` flags off-size tiers as a known follow-up.
4. **Multi-instance** — route `FfmpegLocator._toolsDir` through `InstanceProfile` (same shared
extraction race as #1, and it becomes moot if ffmpeg is bundled). Confirm the launch method:
`$env:YTLIVE_INSTANCE=2` + `dotnet run --no-build` in a second shell is the known-good path.
5. **Post-session efficacy report** — roll up `CurrentHealth` (dropped frames, duration, health
message) when a stream or recording ends. `SessionTeardownTests` is the natural home.
6. **`scripts/publish.sh` + Debug-only `InternalsVisibleTo` + the `LlamaCasty.exe` rename** —
still queued from 2026-09-26; do **NOT** add `-p:PublishTrimmed=true` (WPF fails at runtime,
not build time). See `TASKS.md` → "Shipping / release build".
7. **The alert-gating copy** (`OverlayHost.xaml`) — fix the copy or gate the alerts; do not leave
it lying. Blocked behind the pricing ruling.
8. **The camera-privacy measurement** — does the Win11 desktop-app camera toggle actually gate a
DShow webcam and a capture card? Gates all privacy-forward copy (`MARCOM.md` guard).
9. **TASK 36:212 stale "shipped" line** — one-line fix, needs a hand.
10. Ship-checklist items live in `TASKS.md` → "1.0 gates".