# v1.3.0 release readiness

Updated 2026-09-07. Atlas is the task-status authority; this document records
the release scope and acceptance checklist. Current implementation baseline:
`8a75f4e` for published RC9 applications; server tools `708bfc2`. **Release preparation is in progress; release approval is pending.**

## Owner scope decision

Microsoft Authenticode and Apple Developer ID signing/notarization move to
**v1.4.0** while identity verification completes (up to two weeks, per owner).
The Azure Artifact Signing account exists; both enrollments remain pending.
No platform signing integration or identity approval is claimed complete.

v1.3.0 will ship without these platform signatures/notarization. Manual QA
must record actual unsigned download/launch, SmartScreen/Gatekeeper/quarantine
and permission behavior, and release instructions must describe the supported
launch path. Passing verified-publisher/notarized policy checks is deferred.

The updater's **Ed25519 manifest authentication remains required for v1.3.0**.
It is independent of Microsoft/Apple identity verification. The repository
already enforces manifest trust and provenance; moving platform signing does
not disable or defer those controls.

## Completed implementation

- August remediation preserved and all R01–R22 September findings addressed.
- Native QA discoveries QA-01 (Windows journal sharing) and QA-02 (native
  config/TUI test isolation) fixed.
- Vitest upgraded to 5.0.0; automated and native implementation validation
  recorded in [audit remediation](AUDIT_REMEDIATION_2026-09-05.md) and
  [QA results](qa/2026-09-05/results.json).
- Known GPU alias/codec inaccuracies corrected in `981b14d`; full Go race,
  lint and six platform test-binary cross-builds passed for that follow-up.
  Physical GPU detection relies on user reports by owner decision. The Windows
  VM's Basic Display Adapter is not real vendor GPU qualification.
- Concrete regional locale corrections and drag/keyboard priority ordering
  are complete. On 2026-09-06, `go test ./pkg/locale/...` and the focused
  `languages-priority.test.js` Vitest suite passed. Future requested locales
  should be tracked with a concrete acceptance list.

Prior native results cover Windows 11 amd64, macOS arm64 and Linux amd64.
They validate the implementation, not the final protected-tag artifacts.
The September 6 RC smoke results below supplement that earlier evidence; owner
manual acceptance is still outstanding.

## Manual-QA candidate is available

Task `ec70121c` is complete. RC1 owner QA then found that fresh Windows installs
rejected the manager’s own lock files. Task `482298ce` fixes that interaction,
preserves those locks through install/uninstall, and adds actual default-path
Web install coverage. The earlier explicit-path smoke missed this behavior.
The owner confirmed the RC2 install fix, then reported progress-toast, switch and
Windows default-app discoverability issues. Task `ed5cc54b` addresses these in RC3;
seven real-browser regressions pass on Windows/macOS/Linux, and native registry
tests verify registration, cleanup and preservation of other defaults.
RC4 task `73c2ee5d` addresses another owner refusal: an old MPC-QT setup
executable remained in the MPV root. It is now preserved without MPV ownership;
future MPC-QT downloads use temporary staging. Native QA also discovered that an
upstream archive was replaced at the same URL. The original reviewed Windows
mpv/FFmpeg bytes now have immutable digest-addressed mirrors, with refreshed signed
metadata and unchanged hashes. Generator commit `708bfc2` adds reviewed mirror
support. RC5 task `027fa685` adds the owner-requested cleanup migration: old and
partial setup downloads are removed after guarded MPV installs/updates, with
locked-file warnings and directory/link preservation. RC6 application binaries
identify `59ab4c2`. The owner's known leftover setup file was also removed after
matching its SHA256 to the reviewed download.
Owner-authorized Linode publication now provides
`1.3.0-rc.9` with its matching signed [RC feed](https://mpv.rocks/api/releases/rc.json)
and six immutable executable/archive pairs. Existing `dist` application binaries
match that publication. The legacy v1.2 feed remains operational and unchanged
by RC publication; no final stable release was published.

Native Chromium/application checks passed on Windows 11 amd64, macOS arm64 and
Linux amd64: 22 route checks each, available authenticated RC metadata, no JS
errors and clean shutdown. The Windows default-path Web install of mpv + FFmpeg + ModernZ passed on RC5, including cleanup of the old setup on initial install and a
partial download on an existing-install update, followed by uninstall/reinstall
in the same directory with user config preserved;
macOS/Linux ModernZ installation was covered by RC1. All six public executable hashes/sizes
match the signed manifest and local builds. See
[current evidence](qa/2026-09-07/results-rc9.json) and
[RC6 evidence](qa/2026-09-06/results-rc6.json).
RC6 task `da602d16` fixes the owner's missing chooser entries. The archive's
`mpv-register.bat` calls `mpv.exe --register`; RC6 now runs that native operation
with config/scripts disabled, verifies executable/SupportedTypes/handler entries,
and cleans the old registration after success. Removal checks the active native
owner before invoking `--unregister`. Native registration/removal and migration
passed in a disposable Windows account. Actual `.mkv` and `.aac` Windows chooser
screenshots show mpv after the owner's installation was registered. File-type
default selection remains a user action. Earlier Settings-launch-only QA did not
prove chooser visibility. SSH/browser smoke does not establish quarantine or
interactive permission outcomes.

The September 7 [Windows RDP UX pass](qa/2026-09-07/WINDOWS_RDP_UX.md)
verified RC6 install, actual AAC/MKV default selection and shell playback,
registered uninstall, cancellation, navigation during reinstall, and config
preservation in a disposable standard account. Its four findings are addressed
by RC7–RC9: busy-file preflight before removal, cancellation toast cleanup,
completion-only 100%, and Cancel/Escape focus restoration. Decorative job-modal
icons no longer enter accessible button names. RC7 native QA exposed another
race when failure precedes the job-start response; RC8 recovers that result and
restores the retry button. RC8’s full Edge route sweep then exposed cached
pages retaining SSE connections and exhausting browser connections; RC9 closes
streams when pages leave and reconciles tasks on cached Back restoration. The
final 22-route Windows sweep and cached Back checks pass. Native verification is
recorded separately in
[RC9 Windows UX validation](qa/2026-09-07/WINDOWS_UX_RC9.md).
The owner designated `agent` on `win-dev` for this QA; its configuration was
snapshotted before managed installation/registration tests. Owner acceptance and
the separate final-release gates remain open.

Use the published archives or current `dist` files for owner QA. A later local
rebuild needs refreshed reviewed metadata because of the build-time freshness
check; changed binary bytes need a new candidate version. See
[release channels and deployment](RELEASE_CHANNELS.md).

## Remaining v1.3.0 acceptance

| Task | Work remaining | Completion evidence |
| --- | --- | --- |
| `8b25a11e` — final manual acceptance | Test the selected unsigned release candidate on disposable Windows/macOS installations and run Linux release smoke checks. Cover actual managed-app operations, config/language/UI flows, failures and recovery. | OS/architecture, commit, binary/archive hashes, checklist results and resolved blocking defects. |
| `75ddd84a` — updater trust and provenance | Manual offline RC signer, public trust and reviewed RC provenance are deployed. Complete production authorization/reviewer contracts, stable trust and real `release/provenance-v1.3.0.json`, immutable manifest storage and stable cutover. | Exact reviewed upstream pins/evidence, configured trust, successful authenticated manifest generation/verification and negative checks. |
| `22a13f11` — release infrastructure and evidence | Protect release tags/variables, configure trusted execution and package immutability, provide a native-evidence approval/attestation mechanism supported by this GitLab deployment. | Verified remote policy and an immutable tag/commit/digest-bound evidence record. |
| `b7ef5143` — final rehearsal and approval | Freeze candidate/version, run final checks and six builds, finish release notes, complete the protected release-chain rehearsal (manual RC publication passed) and historical bootstrap, then obtain owner publication approval. | Passing pipeline/rehearsal, exact artifact comparisons, manual acceptance, release notes and explicit approval. |

### Manual test scope

Use disposable installations/config homes; preserve real user installations.

- Fresh browser download/extraction and unsigned launch; Web, TUI and CLI.
- Install/update/uninstall mpv and applicable managed apps; existing-install
  detection, selected paths and shortcuts.
- Config save/reset/backup/restore; profile/comment preservation; ModernZ/uOSC;
  language selection, drag/keyboard priority ordering and persistence.
- Representative keyboard/modal navigation, cancellation, failure reporting,
  shutdown/relaunch, locked/read-only destinations, permission/UAC denial,
  rollback and retained recovery evidence.
- Actual unsigned quarantine/SmartScreen/Gatekeeper/antivirus outcomes. Record
  supported launch instructions without globally disabling OS protection.
- Historical v1.1/v1.2 bootstrap: supported Linux/macOS upgrade path and
  Windows one-time manual replacement. Test v1.3-origin helper updates
  separately; current-source synthetic versions do not prove old-client behavior.
- Record Windows arm64, macOS Intel and Linux arm64 coverage. If unavailable,
  qualify the architecture, narrow the release assets, or record an explicit
  owner exception before approval. Cross-compilation is not native evidence.

Run the required Go tests/race/lint, frontend tests/vendor freshness, relevant
real-browser checks and six release builds against the selected final candidate.
Bind manual QA to the exact artifacts consumed by publication. Fixes that change
those bytes require revalidation of the affected paths.

### Infrastructure observations

Read-only GitLab checks on 2026-09-06 found **zero protected tags, zero project
CI variables and one online runner (1321)**. The protected-environments endpoint
returned HTTP 404; a protected native approval mechanism has not been verified.
Package-setting endpoints attempted during this check did not expose the
duplicate-file policy, so server-side immutability remains unverified.

The current CI requires protected tag claims, manifest trust variables,
provenance and digest-bound native evidence. A manual job alone does not prove
the required approval isolation. Configure a supported equivalent where the
documented protected-environment feature is unavailable.

The rehearsal must not advance the stable channel. Before announcement,
verify final published downloads, checksums, manifest signatures/version and
legacy bootstrap behavior. Push, tag and stable publication still require owner
authorization; this task update grants none of those actions.

## Deferred and ongoing work

| Task | Milestone | Scope |
| --- | --- | --- |
| `7f9d5883` | v1.4.0 | Microsoft identity validation, Public Trust profile, scoped signing runner/identity, timestamped Windows signing and final signed-artifact QA. |
| `98152668` | v1.4.0 | Apple identity verification, Developer ID/notarization integration and final signed/quarantined macOS artifact QA. |
| `67ecfc8f` | maintenance | Newly reported GPU names/capabilities and ambiguous-device resolution; known inaccuracies already fixed. |
| `3d824d32` | maintenance | Concrete future accessibility reports beyond completed audit repairs. |

Wails/htmx roadmap tasks stay in v1.4.0; SQLite investigation stays in the
future milestone. Ongoing maintenance is not an undefined v1.3 release gate.
