A fresh installation only provisioned Streamlink and FFmpeg when the
first download started, which delayed that download by the full tool
download and extraction time. Packaged builds now schedule a background
provisioning pass fifteen seconds after startup so the tools are
typically ready before the first download begins, reusing the existing
ensure functions with their in-flight deduplication so a download that
starts earlier simply joins the running installation. The timer is
tracked and cleared during shutdown, and development and test launches
keep the previous deferred behavior so isolated environments never
trigger network provisioning.
On a fresh installation the first download repairs the managed
Streamlink and FFmpeg copies, which downloads and extracts roughly two
hundred megabytes before the actual VOD transfer begins. The queue item
previously sat on a generic starting status for that entire window - the
old preparing hint only appeared when the streamlink command had not
been verified yet, and a prior System Check verifies the command without
making the managed repair any cheaper, so users saw no explanation for
delays of a minute or more. All three download paths - VOD, live
recording and merge groups - now report a dedicated localized
"Preparing download tools" status before the tool gates run, and the
misleading conditional hint was removed.
The installer staged downloaded tool archives as archiveName.uuid, so
the temporary file no longer ended in .zip. The Expand-Archive cmdlet
shipped with stock Windows PowerShell (Microsoft.PowerShell.Archive
1.0.1.0) rejects any archive whose extension is not .zip, which made
every managed streamlink and ffmpeg installation fail with
extract-failed on systems without an updated Archive module - including
plain end-user machines and the self-hosted CI runner. The unique
download path now uses the UUID as a prefix and keeps the manifest
archive name with its .zip extension intact.
recoverInterruptedMergeArtifacts resolved the artifact root through
fs.realpathSync.native but compared candidate artifact paths with
path.resolve only. On systems whose temporary or download directories
surface as Windows 8.3 short paths the queue-persisted artifact paths
never matched the canonical long root, so crash artifacts were treated
as outside the owned directory, nothing was removed and interrupted
merge items were incorrectly blocked. isInside now canonicalizes both
sides through the deepest existing path segment, keeping planned but
not yet created paths comparable, and a Windows ShortPath regression
test covers the recovery flow end to end.
ensureStreamlinkInstalled and ensureFfmpegInstalled forced a managed
reinstall whenever a bundled tool directory existed without passing
manifest verification. When that reinstall failed (offline, blocked
download, locked executable), both functions returned false without ever
probing the tool that was already present and runnable, so every
download path aborted with an auto-install error while the System Check
kept reporting the same tool as available. Both functions now fall back
to the same executability probe the System Check uses after a failed
managed repair, cache the verified command on success, and only report
failure when nothing runnable remains. The repair attempt itself is
preserved and retried on the next call.
The tool archive download also registered no error handler on the HTTP
response stream. A stream that failed mid-transfer settled neither the
writer finish nor the writer error path, leaving the install promise
pending forever and the download start hanging indefinitely. The
response stream now rejects the download on error and destroys the
writer.
Merge group downloads reported the bare "Streamlink is missing." text
while the VOD and live paths already explained the failed auto-install.
All three gates now share streamlinkAutoInstallFailed, ffmpeg gained the
matching ffmpegAutoInstallFailed message, and the now unused
streamlinkMissing and ffmpegMissing keys were removed.
The Managed tools panel showed "Missing / Unverified" with no hint that
downloads still work through a system-provided installation, which reads
like a hard failure on machines that never installed the managed copies.
getManagedToolStatuses now reports per tool whether a runnable
installation answers the version probe, and the panel appends a
localized "Downloads still available" note whenever an unverified state
is covered by a working tool.
Harden update, system-check, queue, cutter, streamer and shutdown state transitions.
Add multi-user installer recovery, secret-safe config migration, provider fallback handling, managed-tool validation and real media export coverage.
Refresh the English public documentation, release notes and 1.0.18 product screenshot.
Keep the loaded cutter layout stable across supported window sizes, preserve recovered encoder choices during capability discovery, and reject unsupported video selections without changing the active project.
Honor the Windows system theme, fully localize runtime metrics, invalidate imported System Check state safely, and bound child-process shutdown waits when close events never arrive.
Extend focused and Electron smoke coverage and prepare the v1.0.17 public release metadata.
Keep download progress inside the updater popover, slow changelog transitions, and improve dark-theme checkbox contrast. Expand diagnostics, prevent cleanup option clipping, improve navigation readability, and cover the affected states in Electron regression tests. Prepare version 1.0.15 release metadata.
Retry Electron binary provisioning before Windows smoke tests and retain bounded retries for package and installer builds. Bump release contracts to 1.0.14.
Retry the directory package once when Electron download transport is interrupted, keeping the Windows CI step bounded. Bump the release contracts to 1.0.12.
Mock Electron in the Node-only secure-storage unit test so its expected unavailable-path assertion never triggers Electron's binary bootstrap. Bump the patch release contracts to 1.0.11 after the 1.0.10 tag CI failure.
Ignore malformed update notifications that do not carry a version, preventing unusable release prompts in installed builds.
Keep the loaded cutter workspace free of the source selector and give cutter export selects an explicit non-repeating indicator after workspace styling.
Add regression coverage, bump the patch release to 1.0.10, and update public installation documentation.
Delay managed-tool installation promotion until checksum read streams have emitted close, preventing intermittent Windows rename failures caused by open file handles.
Add a deterministic end-before-close regression test and prepare the 1.0.9 patch release across package metadata, UI version text, README, changelog, and release contracts.
Stabilize Start menu and desktop shortcut migration with persistent versioned icon resources, stale-registration recovery, and explicit Windows shell notifications. Keep development, packaged, and shortcut identities aligned, and add regression coverage for orphaned per-user installs, reduced-motion changelog transitions, and update-popover pointer transit.
Provide a pure persisted policy contract for optional app-side throughput limits and local download windows. Cover overnight timing, local Date DST behavior, invalid values, and manual window overrides without creating Streamlink arguments.
Keep chat and event viewer focus on a listbox with an active descendant instead of creating row tab stops. Provide a full-text detail dialog for keyboard users with Escape focus restoration and production-path coverage for scrolling and selection.
Exercise delegated queue and VOD context menus plus chat and event viewer cancellation through compiled renderer code. Make truncated virtual rows keyboard-focusable with complete accessible labels and visible focus feedback.
Use cancellable, generation-aware reads and removable virtual scrolling for chat and event viewers. Constrain virtual rows to fixed single-line heights, clean busy state, stop Escape propagation, and cover dialog, menu, palette, and virtual list interactions.
Stream capability-authorized chat reads with cancellation, virtualize viewer rendering, centralize modal focus management, and add keyboard-accessible queue and VOD menus. Expose command palette combobox state and keep the document language synchronized with the selected locale.
Promote a verified staged first installation after interruption and clear stale first-install journals. Stream archive and managed executable hashes, make status recovery non-blocking, and await the propagated tool and IPC status contracts.
Persist atomic promotion state beside each managed tool, restore usable backups after interrupted renames, and retain precise recovery failures. Verify installed executable hashes from the staged manifest record and make cleanup diagnostics unable to strand repair single-flight state.
Pin Streamlink and FFmpeg archives to verified manifests, stage replacements before promotion, and expose managed tool status with repair and reset controls. Keep updater checks exclusive until their underlying operation settles and restore default electron-builder certificate environment support.
Track settings input generations so an older asynchronous secret save cannot mark a newer value durable. Commit queue snapshots before cancellation, cleanup, or pause effects so SQLite failures leave runtime processes and files unchanged.
Keep SQLite authoritative after completed migration even when legacy JSON is later invalid, reject non-object config documents before any migration state is written, and guard async secret masking by input generation. Persist renderer-facing config and queue mutations before updating memory so SQLite errors reject IPC calls and retain the last durable queue snapshot.
Store Twitch and Discord secrets as versioned safeStorage ciphertext behind explicit trusted IPC. Migrate legacy JSON transactionally into authoritative SQLite config and ordered queue repositories with rollback-safe markers and sanitized backups. Redact config exports and update renderer and release-harness contracts for secret-free config responses.
Reject renderer-owned queue internals before persistence and bind privileged handlers to trusted renderer events. Extend cutter session capabilities without weakening owner, purpose, path identity, or expiry checks. Migrate release harness contracts to opaque capabilities and add an invisible Node gate.