# Native Windows installer portability follow-up

Date: 2026-10-03. Agent: /root/ui_audit. Parent evidence inspected: docs/qa/2026-10-03/remediation/native-windows-final.txt.

The reported installer failures were predominantly Unix-specific test fixtures. No package-wide Windows skip was introduced. The real transaction, copy, mount ownership, output and cancellation behavior continues to run on Windows.

| Native failure | Resolution |
| --- | --- |
| command_runner tests required sh, echo and false executable files | This installer test executable now serves as a controlled child producing exact stdout/stderr or exit 7. TestMain dispatches child mode before sandbox creation, so helper runs do not leak temporary profiles or add testing PASS output. Stream-once, exact captured stdout, error-channel and missing-binary behavior remain asserted on every OS. |
| supported RunShellCommand selected sh on Windows | Corrected the retained supported API to construct a native cmd.exe command. /D disables AutoRun, /S /C run the intended script, and an explicit raw Windows CmdLine wraps the script in one outer quote pair without Go's incompatible embedded-quote escaping. internal/process preserves the provided SysProcAttr and adds owned suspended/job execution. No current production installer calls this retained shell API; the native defect affected its supported behavior/test seam. Unix still prefers /bin/bash and falls back to sh. Real shell tests assert simple output, embedded quotes, execution of this test binary from a quoted path containing spaces, nonzero exit and stopping a command sequence before its final command. |
| TestCopyUIPath demanded Unix 0600 from Windows Stat | Compare the destination mode with the real source's observed native mode, preserving the copy contract. File content and interface routing assertions remain. |
| embedded_assets test demanded exact Unix 0644 | Content and regular-file publication checks run on every OS; Unix permission-bit assertions apply on Unix. This Lua asset test does not claim Windows DACL coverage; the explicit native owner/DACL gate is in fileops. |
| GetMPVConfigDirFromHome expected Unix home paths on Windows | Sandbox all native env vars and assert exact platform behavior: Windows per-user mpv/portable_config, Linux XDG_CONFIG_HOME/mpv, and Darwin/Unix caller-home .config/mpv (with empty home resolved to absolute cwd). |
| DMG selection/cleanup rejected valid /dev/disk7s1 on Windows | Device values originate from Darwin hdiutil, so normalize them with POSIX path.Clean, independent of the test host. Real filesystem mount roots/containment continue using host filepath. No Darwin mount test was disabled; owned-only selection, unrelated-mount exclusion, interruption cleanup, deduplication, ambiguity and symlink rejection still run. Darwin runtime semantics are unchanged. |
| regular-file transaction tests never reached the injected metadata/restore failure | Their fake staged data now uses nonempty-regular validation rather than irrelevant Unix executable bits. Both still run the real transaction and assert exact old live bytes, stage consumption or retained old backup when rollback fails. Executable/PE validation is independently tested at actual artifact boundaries. |
| injected FileSystem test map keys used slash literals while production joined native paths | CopyDir and file-helper fixtures now use sandboxed filepath.Join roots and compare the native keys. Exact content and error propagation remain asserted. |

Changed source: pkg/installer/command_runner.go, command_runner_shell_windows.go, command_runner_shell_other.go and dmg_mount.go. Remaining edits are installer tests: command_runner_test.go, testmain_test.go, common_fs_test.go, common_test.go, embedded_assets_test.go, file_transaction_test.go and installer_injection_test.go. Other agents own platform probe and logger corrections; this pass did not touch them.

Validation: focused Linux behavior tests passed, and the complete installer package passed with `go test -race ./pkg/installer -count=1 -timeout=3m`. Rebuilt binaries are `/tmp/mpv-october-final-windows/installer.test.exe` (windows/amd64, GOAMD64=v2, CGO_ENABLED=0) and `/tmp/mpv-october-final-darwin/installer.test` (darwin/arm64, CGO_ENABLED=0). Cross-build success is not native test acceptance. Parent will upload these final binaries and rerun native packages and the full combined repository gates before commit/push.
