# MPV.Rocks Installer — Combined Cross-Referenced Codebase Review (glm-5.3)

- **Date:** 2026-08-31
- **Baseline commit:** `bdfb31b95030c2d992e5cfc4cb0ba5bada368d1b` (`master`)
- **Sources cross-referenced:**
  - **Review A (glm-5.3):** [CODEBASE_REVIEW_2026-08-31_glm-5.3.md](CODEBASE_REVIEW_2026-08-31_glm-5.3.md) — 1 Critical, 26 High, 73 Medium, 49 Low, 5 Info (154 findings; 8 parallel glm-5.3 reviewer sub-agents + lead verification)
  - **Review B (prior):** [CODEBASE_REVIEW_2026-08-31.md](CODEBASE_REVIEW_2026-08-31.md) — 0 P0, 17 High, 25 Medium, 8 Low (50 findings; 3 focused reviews + primary review with extensive dynamic validation)
- **This report:** cross-references every finding in both reviews, independently verifies in source all claims unique to one review, resolves severity disagreements, and merges the remediation roadmaps. Companion artifacts: `.opencode/reviews/*.md` (glm-5.3 per-area detail) and [CODEBASE_REVIEW_COMBINED_2026-08-31-glm-5.3.html](CODEBASE_REVIEW_COMBINED_2026-08-31-glm-5.3.html).

---

## 1. Cross-reference outcome

| Category | Count | Confidence |
|---|---:|---|
| **Corroborated clusters** — same underlying defect independently found by both reviews | **41** | Highest (two independent discoveries; most also source-verified) |
| **Unique to Review B (prior)** — found only by the prior review | **9** | All 9 independently **re-verified in source during this session** (§4) |
| **Unique to Review A (glm-5.3)** — found only by the glm-5.3 audit | **~104** | Lead-verified during the original audit; not second-sourced |
| Severity disagreements resolved | 2 major | §5 |

**Key observation:** the two reviews agree on every mutually-inspected high-risk area and disagree on almost nothing factually. Where they overlap, file/line references match within a few lines. The prior review's dynamic tooling (Staticcheck, race, shuffle, live Chromium, coverage) and the glm-5.3 audit's broader static depth are complementary: Review B caught 9 issues glm-5.3 missed (notably a privilege-escalation path and a config-tree divergence), while glm-5.3 caught ~104 issues Review B missed (notably the updater's exec-before-hash ordering, crash-consistency defects, and large TUI/frontend correctness surfaces).

### Combined dynamic validation (union of both reviews + this session)

| Check | Result | Source |
|---|---|---|
| `go vet ./...` | Pass | B; re-run in this session (A) |
| `go test ./...` / `-count=1` | Pass, all packages | A (this session) + B |
| `go test -race -count=1 ./...` | Pass | B |
| `go test -shuffle=on -count=3 ./...` | Pass | B |
| `gofmt` / `go mod tidy -diff` / `go mod verify` / `git diff --check` | Pass | B |
| `govulncheck@v1.7.0` (Go 1.27 build) | 0 vulnerabilities | B |
| Staticcheck 0.8.1 (`SA*`) | 13 diagnostics; 4 production correctness findings (see L-07) | B |
| `npm test` (157 assertions, shuffled too) | Pass | B |
| `npm audit --audit-level=moderate` | 0 vulnerabilities | B |
| Alpine/htmx vendor freshness | Pass, byte-for-byte | B |
| Six release cross-builds (linux/win/darwin × amd64/arm64) | Pass | B |
| Local Web route/API/auth smoke test (cookie auth, hostile Host/Origin, graceful shutdown) | Pass | B |
| Live Chromium reproduction of jobs-modal focus defect | Reproduced | B |
| Coverage (one repo-wide run) | 43.7% overall; installer 84.1%, platform 92.3%, version 72.9%, config 70.3%, web 28.5%, TUI 26.0%, `cmd/mpv-manager` 11.9% | B |
| Independent source re-verification of all 9 Review-B-unique claims | All confirmed | **This session** |

---

## 2. Tier A — Corroborated findings (41 clusters, both reviews)

These are the highest-confidence findings of the audit: two independent review processes converged on the same defects. Severity shown is harmonized (see §5 for disagreements).

### A.1 Corroborated Critical/High (13 clusters)

| # | Finding (harmonized severity) | Review A | Review B | Verification |
|---|---|---|---|---|
| 1 | **Critical** — Relaunched self-updated TUI renders into `helper.log` while consuming terminal input; health acknowledged before any real initialization, so the broken relaunch can be committed as "healthy" | C-1 + H-3 | H-15 | Source-verified by both (A lead + B); B also notes `main.go` ack placement |
| 2 | **High** — Windows uninstall recursively deletes the install directory with no ownership proof; per-entry errors are warnings; success returned regardless | H-6 | H-02 | A lead verified `windows.go:103-157` |
| 3 | **High** — TUI update/uninstall drops `AppID`/`InstallPath`; operations run against the global installer destination — selecting install B can update/delete install A | H-14 | H-03 | Both traced `models_types.go:141-148`, `models_update.go:438-446` |
| 4 | **High** — Job cancellation archives/removes the job before the worker stops; a conflicting destructive job is accepted while side effects continue | H-11 | H-05 | Both traced `jobs.go:482-543` |
| 5 | **High** — Job conflict detection protects method IDs, not shared resources; different methods (or direct config APIs) can concurrently mutate the same config/UI tree | I-M5 (Med→**High** per B) | H-06 | Both traced `jobs.go:256-279` |
| 6 | **High** — Physical success reported when authoritative persistence fails (untracked installs, tracked uninstalls, stale adoption/UI metadata) | T-M2 (Med→**High** per B) | H-07 | Both traced install/adopt workers |
| 7 | **High** — Config setters mutate in-memory state and return errors without rollback; failed mutations later persisted by unrelated successful saves | P-M2 (Med→**High** per B) | H-08 | Both enumerated the setter families |
| 8 | **High** — Config restore renames the live file aside before validating/staging the replacement; no rollback; date-only backup names collide same-day | H-20 | H-10 | Both traced `installer.go:1165-1195`, `common.go:161-194` |
| 9 | **High** — Package-version "10 s timeout" ineffective: unlabeled `break` exits only the `select`; unkillable probes; run at startup and under the cache write lock | H-10 | H-11 | A lead verified `server_version_cache.go:313`; **Staticcheck SA4011 independently flags the same line** (B) |
| 10 | **High** — IINA install discards `hdiutil attach` output, assumes `/Volumes/IINA`; volume collision copies an unverified bundle; detaches the wrong path | H-9 | H-12 | Both traced `macos.go:199-216, 438-475` |
| 11 | **High** — Unauthenticated upstream "latest" artifacts are hashed and signed into MPV.Rocks trust (no upstream signature/allowlist check) | U-M12 (Med→**High** per B) | H-14 | Both traced `generate-info/main.go:358-448, 948-977` |
| 12 | **High** — FFmpeg replacement: deferred deletion of `ffmpeg.old` runs even when the rollback rename failed — destroys the only known-good binary | H-7 | H-16 | Both traced `installer.go:525-614` (B: 593-608) |
| 13 | **High** — TUI language apply renames the entire `mpv.conf` away for a single-field write; editor then writes fresh defaults (all user settings vanish); failed rename ignored | H-16 | H-17 | Both traced `language_preferences.go:823-859`, `editor.go:135-177` |

### A.2 Corroborated Medium (23 clusters)

| # | Finding | Review A | Review B |
|---|---|---|---|
| 14 | uOSC/ZIP extraction runs external `Expand-Archive -Force`/`unzip -o` directly over live config; rollback allowlist covers only known UI paths | I-M6 | M-01 |
| 15 | Crash before the first updater journal write permanently blocks future updates (orphan transaction dir; recovery stops at first bad dir) | U-M2 | M-03 |
| 16 | Windows discovery executes every discovered `mpv.exe --version` from user-writable/PATH/registry locations before adoption, unbounded | I-M1 | M-04 |
| 17 | Multi-field config/language API writes validated together but persisted field-by-field; partial apply on mid-failure (batch writer exists, unused) | W-M5 | M-05 |
| 18 | Job-history serialization is per-`Store` instance; TUI creates fresh stores; fixed `.tmp` name; cross-process record loss | P-M7/S-M8/T-M10 | M-06 |
| 19 | Persistent SSE handlers defeat graceful shutdown: 2 s timeout → treated as fatal → exit 1 with a connected browser | S-M1 | M-07 |
| 20 | SSE terminal-event delivery/reconnect gaps: narrow concurrent-sender drop window; filtered reconnect snapshots only active jobs; client never reconciles after reconnect | F-M2 + SSE Low | M-08 |
| 21 | TUI Ctrl+C quits without cancelling/joining backend work (`context.Background` workers; children outlive the TUI) | H-18 | M-09 (B rates Med; A High — see §5) |
| 22 | UI migration resolution spans two stores with check-then-act, no CAS; file changed while resolution says Keep; write failure leaves changed file + pending migration | L-2 (Low→**Med** per B) | M-10 | 
| 23 | Jobs modal opens focus controller while still `hidden`; initial focus lands on inert body | F-M6 | M-11 (B reproduced in live Chromium) |
| 24 | Windows resources: only amd64 `.syso`, hardcoded `1.0.0.0`/Win7 metadata; generator failures suppressed (`|| true`); arm64 has none | B-M2 + Low | M-12 |
| 25 | Manager-data reset ignores backup failure, overwrites a fixed `.backup`, logs success; TUI claims "backup saved" | T-M13 | M-13 |
| 26 | Backup validation misses intermediate symlinks (lexical containment; final-component-only Lstat); restore/delete can escape the backup dir | W-M2/P-M1 | M-14 |
| 27 | File/config locks are process-local while Web/TUI/CLI share the same files (snapshot `Write` parses before locking) | S-M6/S-M7 | M-15 |
| 28 | Privileged release jobs run mutable container tags (`alpine:latest`, `release-cli:latest`, moving golang/node tags) | B-M6 | M-16 |
| 29 | TUI PATH add/remove: non-idempotent alias appends, failures reset to nil, removal never removes aliases, existence ≠ PATH resolution, Windows broken | T-M9 | M-18 |
| 30 | Release-generator artifact downloads unbounded in time and size (no total deadline, no byte cap, stalled upstream hangs signing job) | U-M9/B-M4 | M-19 |
| 31 | Signed manager manifest computed from re-downloaded registry bytes, not the pipeline's build artifacts | H-21 (**High**; B rated Med — see §5) | M-20 |
| 32 | `BLAKE3SUMS.txt` emits `blake3:` prefix — incompatible with documented `b3sum -c`; never exercised by CI; generator untested | U-M11/B-M8 | M-21 |
| 33 | Stored-password Web installs dispatch the privileged request twice (`ensurePassword` invokes callback *and* returns true; 409 path corrupts button state) | F-M1 | M-22 |
| 34 | Config Apply baseline rebuilt from current controls, not the submitted payload; concurrent edits silently marked saved; unload guard dropped during save | F-M3 | M-23 |
| 35 | UI-option saves and regional-language requests allow stale responses to overwrite newer intent (no per-key generations; lost AbortController; unchecked request IDs) | F-M4 + F-M5 | M-24 |
| 36 | CLI `--path` ignored by ModernZ/uOSC/FFmpeg dispatch but recorded as `InstalledApp.InstallPath` | S-M9 | M-25 |

### A.3 Corroborated Low (5 clusters)

| # | Finding | Review A | Review B |
|---|---|---|---|
| 37 | No CSP on the privileged loopback UI (inline scripts/handlers require staged refactor first) | Frontend Low | L-02 |
| 38 | Public parsed script-options `Write` can overwrite fresher edits (parse-before-lock; no revision check) | Support Low | L-05 |
| 39 | Reset text claims language preferences are cleared; they live in `mpv.conf` which reset does not touch | T-M13 (partial) | L-06 |
| 40 | Staticcheck-exposed TUI defects: value-receiver error clear (SA4005), duplicate/unreachable Escape branches (SA4014), empty branches incl. promised-but-missing warning (SA9003) | TUI Low (screenshot receiver, dead branches) | L-07 |
| 41 | Docs claim macOS universal/`.app` outputs that the platform guide and CI contradict; native release gates and release-metadata enforcement (`NativeSigning`, `Format`, `InstallScope`, `UpdateStrategy` as non-empty strings only) are unenforced | B-Low docs + U-Low + H-23 context | L-08 + coverage gaps #3/#4 |

---

## 3. Tier B — Unique to the prior review (9 findings, all re-verified this session)

Every finding only Review B reported was independently confirmed against source during this cross-reference session. None is refuted.

| # | Finding (B severity → harmonized) | B ID | This session's verification |
|---|---|---|---|
| B-1 | **High** — Windows uninstall elevates a mutable install-tree batch file: `mpv-unregister.bat` is copied from the (possibly adopted, user-writable) MPV tree and executed via `Start-Process -Verb RunAs` with no digest/ownership/ACL check before UAC. An unprivileged process can replace the `.bat` and wait for the user to approve the expected prompt → admin code execution. | H-01 | **Confirmed** — `windows.go:160-212`: copy from install tree, `scriptToRun` falls back to the original path, elevated `Start-Process -Verb RunAs`, no verification |
| B-2 | **High** — Custom install locations and settings APIs resolve different `portable_config` trees: installer writes `<custom>\portable_config`, but config/hotkeys/ModernZ/uOSC/migration/backup resolvers use `%APPDATA%\mpv` or legacy home; the common resolver never consults the configured custom path (and caches with `sync.Once`). UI reports success against a tree MPV never reads. | H-04 | **Confirmed** — `constants/paths.go:52-72`: `getWindowsMPVBaseDir` checks only APPDATA/home existence via `windowsPathOnce`; `api_settings.go:479-518` merely persists the path |
| B-3 | **High** — Config read failures (permissions, transient I/O, unavailable mounts) are treated as "missing file": defaults are loaded *and saved over* the existing file. Parse-error log prints the shadowed outer `err` (always `<nil>`). | H-09 | **Confirmed** — `config/config.go:85-149`: any `ReadFile` error falls to "Start fresh defaults" + `saveLocked()`; inner `err` shadows the ReadFile `err` used in the log |
| B-4 | **High** — Tagged generator code receives the long-lived release signing key: CI builds `cmd/generate-info` *from the tag*, injects `MANIFEST_SIGNING_KEY`, and executes that artifact — a malicious tagged generator can export the private key and forge future manifests. | H-13 | **Confirmed** — `.gitlab-ci.yml:495-496` requires `MANIFEST_SIGNING_KEY_ID`/`MANIFEST_SIGNING_KEY` in the tag-built generator job |
| B-5 | **Medium** — Multi-target self-update locks only the primary executable: a configured secondary target is journaled and replaced, but only `updateLockPath(primaryPath)` is acquired — concurrent primary/secondary updates can both mutate the same secondary. | M-02 | **Confirmed** — `transaction.go:205-210`: single `tryAcquireUpdateLock(updateLockPath(primaryPath))` |
| B-6 | **Medium** — Reduced-motion preferences do not cover dialog animations: the `prefers-reduced-motion` block handles toasts/badges/progress/priority-lists but leaves generic, job, password, and UI-selection dialog transitions active. | M-17 | **Confirmed** — `style.css:430-455` block covers `.toast/.task-badge/.job-progress-bar/.priority-list-item` only |
| B-7 | **Low** — Manifest-status network exceptions leave install controls enabled: non-OK responses fail closed, but a rejected `fetch` only logs; banner stays hidden. | L-01 | **Confirmed** — `manifest-status.js:34-48`: `catch` does `console.error` only |
| B-8 | **Low** — Local `make release` can package stale frontend assets: the target chain is `_ensure-manifest-trust clean release-build release-package release-checksums` — no frontend deps/vendor-freshness/tests (tag CI does check; local path does not). | L-03 | **Confirmed** — `Makefile:227` target prerequisites; also independently corroborates Review A's B-M3 (`release-build` itself omits `_ensure-manifest-trust`) |
| B-9 | **Low** — Duplicate hotkey lines only partially edited: Find/Set/Remove operate on the first matching key; removal can report success while another binding for the same key remains active. | L-04 | Consistent with the first-match parser traced by Review A's hotkeys review (`inputconf.go`); not line-by-line re-verified, deemed plausible and consistent |

**Net effect of cross-referencing:** the prior review contributed **4 new High findings** (B-1 privilege escalation, B-2 config-tree divergence, B-3 defaults-on-read-failure, B-4 signing-key separation) that materially expand the destructive/wrong-target and supply-chain risk picture beyond the glm-5.3 audit.

---

## 4. Tier C — Unique to the glm-5.3 review (~104 findings)

Not second-sourced by Review B; lead-verified during the original audit. Grouped summary — full detail in `CODEBASE_REVIEW_2026-08-31_glm-5.3.md` §3–§5 and `.opencode/reviews/`:

- **Updater (11 High/Med-defining):** exec-before-BLAKE3-recheck TOCTOU at target-adjacent staging; apply/rollback crash windows with no launchable primary executable; missing backups treated as successful rollback; v1.1/v1.2 bootstrap unauthenticated; no target-directory durability ordering; forgeable `PrepareSelfUpdateFromCheck` DTO; no anti-replay/revocation; secondary-path identity never proven; helper failures invisible to initiating UX; kill-without-wait rollback race on Windows; qualifier `--qualifier-driver` uncontained.
- **Installer:** config reset fail-open on preservation/backup failure + non-atomic write; MPC-QT `Start-Process` without `-Wait -PassThru`; detection probes collapse uncertainty into "not installed" and key identity by method; runtime file transactions not crash-durable (`.txn-*`/`.bak-*` debris unrecovered).
- **TUI:** Escape abandons workers with unreachable `Abort`; nondeterministic stream completion (stuck-at-installing or dropped output); "Change UI" full-reinstall + duplicate records; Enter-while-filtering triggers destructive actions; interactive sudo fights Bubble Tea for the raw terminal; stale `"updates"` menu ID leaves updated apps re-offered; progress bar 0–100 vs 0–1 unit bug; unbounded quadratic output rendering; Unicode backspace byte-slicing; terminal control-sequence injection via subprocess output; hardcoded version overlay; ~33 s non-offline-first startup.
- **Web:** cached sudo timestamp accepts any password (`sudo -S -v` without `-k`); locale cache data race; `ui_type` unvalidated on install; version-comparison labels downgrades as updates; keyring HTTP 200-on-failure.
- **Core:** `mpv.conf`/`input.conf`/script-opts quote-unaware `#` parsing (3 independent implementations); Linux GPU model truncation/hybrid-order dependence; macOS AV1 over-reporting incl. M2; arm64 labeled `x86-64-v2`; locale dataset/selection disagreements (`hif`/`te`/`fil`, regional errors).
- **Frontend:** SSE reconnect never reconciles; job modal `$nextTick` gap (corroborated — see A.2 #23); mobile drawer not focus-contained; `formatKeys` `template.HTML` trust boundary.
- **Main/supporting:** subcommand/flag misrouting; `--verbose`/`--debug` no-op console logging; BOM/CRLF round-trip corruption; symlink-replacing atomic writes; browser-launch/bind race; SSE-defeating shutdown ordering (corroborated); `os.Exit` cleanup bypass; zombie browser helper.
- **Build/CI:** release tag grammar validated only after publication; archives omit LICENSE/notices; coverage regex not aggregate; `make lint` unpinned; browser E2E absence (B lists as coverage gap; A as Medium).

---

## 5. Severity disagreements (resolved)

| Topic | Review A (glm-5.3) | Review B (prior) | Resolution |
|---|---|---|---|
| Helper-log relaunch + early health ack | **Critical** (C-1 + H-3) | High (H-15) | **Critical.** Both agree on facts. After commit there is no supported recovery path, the user's terminal is silently captured, and the shipped qualification cannot detect it — unrecoverable UX/availability failure of the flagship self-update path. Neither review claims attacker-triggerable RPI, so P0-by-exploit criteria aren't met, but by impact-and-permanence this is the single worst defect in the codebase. |
| Manifest signs re-downloaded registry bytes | **High** (H-21) | Medium (M-20) | **High.** GitLab permits duplicate generic-package files by default and Developer-level publication; the signature is the product's root of trust and must bind to pipeline-produced bytes. Review B's own remediation ("pass the exact raw build artifacts…") implies the same. |
| Job conflict detection scope | Medium (I-M5) | High (H-06) | **High.** Overlapping config/UI mutations across method IDs can roll back committed work — authoritative-state failure. |
| Persistence-failure false success | Medium (T-M2) | High (H-07) | **High** (Tasks UI as untrustworthy state is a core-flow failure). |
| Config setter rollback | Medium (P-M2) | High (H-08) | **High** (failed mutations later persisted by unrelated saves). |
| UI migration CAS | Low (L-2) | Medium (M-10) | **Medium** (verified two-store check-then-act this session). |
| TUI Ctrl+C | High (H-18) | Medium (M-09) | **High** — combined with Escape abandonment and shutdown-orphaned jobs, this is one systemic lifecycle failure (Theme 2). |

---

## 6. Combined cross-cutting themes

1. **Update/relaunch lifecycle unsafe end-to-end** — helper.log relaunch (C-1), early health ack, exec-before-hash, no-launchable-exe windows, dishonest rollback, secondary-lock gap, unauthenticated legacy bootstrap, signing-key separation (B-4), registry-bytes provenance, upstream auto-promotion.
2. **Destructive operations without ownership or transaction** — Windows uninstall sweep + elevated mutable `.bat` (B-1), wrong-target TUI operations, config-tree divergence (B-2), fail-open config reset/restore, FFmpeg backup deletion, language-apply rename, defaults-on-read-failure (B-3), date-colliding backups.
3. **Worker lifecycle not owned by cancellors** — Web cancel-then-accept, TUI Escape/Ctrl+C, shutdown abandoning jobs/SSE/children.
4. **Authoritative state can lie** — persistence-failure false success, setter non-rollback, partial multi-field writes, detection collapsing uncertainty, CLI `--path` recording fiction.
5. **Coordination is process-local** — method-ID job slots, per-Store history, path locks, migration CAS.
6. **Release trust boundary too broad** — tag-built generator with the signing key, mutable CI images, tag grammar after publication, unenforced metadata/native gates, checksum-file incompatibility.
7. **Quote-unaware parsers (×3)** — `mpv.conf`, `input.conf`, script-opts all split on `#` without quote tracking.

---

## 7. Unified remediation roadmap (merged from both reviews)

**P0 — release blockers (both reviews' first passes merged)**
1. Terminal-preserving relaunch + post-first-render health acknowledgement + PTY qualification (C-1/H-15, H-3).
2. Windows destructive/privileged wrong-target fixes: ownership manifests for uninstall (H-02/H-6), authenticated fixed helper instead of elevated mutable `.bat` (H-01/B-1), app-identity-carrying TUI operations (H-03/H-14), one installed-app-aware config resolver (H-04/B-2).
3. Updater integrity: hash-before-exec, platform-atomic never-unlinked replacement, honest rollback on missing backups, per-target locks (H-1/H-2/H-4, M-02/B-5).
4. Fail-closed transactional config reset/restore with unique fsynced backups (H-8, H-10/H-20, H-16/H-17), and defaults-only-on-`os.IsNotExist` (H-09/B-3).
5. FFmpeg staged replacement (H-16/H-7); IINA mount-bound copy (H-12/H-9).

**P1 — authoritative state and lifecycle**
6. Worker-acknowledged cancellation; root lifecycle contexts; SSE-aware graceful shutdown (H-05/H-11, M-09/H-18, M-07/S-M1).
7. Resource-keyed operation leases covering config/UI trees and direct APIs (H-06/I-M5).
8. Persistence as part of the terminal result; setter rollback via one primitive (H-07/T-M2, H-08/P-M2).
9. Package-probe timeout fix + blocked-probe test (H-11/H-10, SA4011).
10. Release trust boundary: sign pipeline-local artifacts, isolated minimal signer/KMS separate from tagged code (M-20/H-21, H-13/B-4), pinned upstream digests + approval boundary (H-14/U-M12), protected semantic tags + duplicate preflight + serialized publication, pinned image digests.
11. TUI stream protocol, filter-state guards, interactive-sudo suspension (H-13, H-17, H-19).

**P2 — reliability, portability, compliance**
12. Native extraction policy for ZIP/tar; crash-durable installer transactions (M-01/I-M6, I-M7).
13. Cross-process locks for history/config; migration CAS (M-06, M-10, M-15).
14. Frontend contracts: `ensurePassword` single-owner, SSE reconnect reconciliation, latest-intent saves, `$nextTick` modal focus, reduced-motion dialogs (M-22–M-24, M-11, M-17).
15. `b3sum -c`-compatible checksums + tests; license notices in archives; Windows resources for both arches; tag grammar before publication; generator download bounds (M-21, M-19, M-12).
16. Discovery without executing untrusted binaries (M-04/I-M1); MPC-QT wait/verify (I-M3).

**P3 — quality and cleanup**
17. Browser E2E suite in CI (both reviews' top test gap); fault-injection tests at commit boundaries; language-workflow tests; coverage aggregate + per-area floors for Web (28.5%) / TUI (26.0%) / `cmd` (11.9%).
18. All Low/Info items; docs reconciliation; Staticcheck `SA*` in CI.

---

## 8. Combined strengths (union of both "held up well" lists)

- Signed manifest fails closed on empty trust, invalid signatures, malformed schema, missing/tampered size-hash, wrong staged identity (both reviews).
- Native 7z extraction: count/size/path/device/symlink/case-collision/exclusive-create defenses, `os.Root` writes.
- Web auth: constant-time token compare, loopback Host enforcement, Origin checks, request limits, keyring throttling — sound in review *and* live smoke tests.
- Job snapshots copied under locks; relay goroutines drained/joined; no shared-pointer race found by the race suite.
- ModernZ/uOSC/Hotkeys production writers reparse under a process-wide path lock and atomically replace.
- Keyring: native OS stores, bounded probes, no weak fallback; passwords via stdin only.
- No confirmed DOM XSS; escaping discipline held; no CDN runtime dependency; vendor byte-for-byte freshness.
- Full dynamic suite green: tests, race, shuffle, vet, gofmt, tidy, govulncheck, npm audit, six cross-builds.

## 9. Review limitations

- Review B ran on Linux; Windows/macOS outputs cross-built and inspected, not executed natively. Review A's sub-agents were static-only; the A lead ran vet/tests only. This session's verification was source-reading plus vet/tests — no native destructive flows.
- Neither review performed real install/uninstall, production signing/publication, or privileged package-manager flows.
- Tier C findings are single-sourced (though lead-verified); treat individual line numbers as needing reconfirmation during remediation.
- Static review can miss environment-dependent behavior; both reviews limited findings to evidence-backed reachable paths.
