Repository navigation
Releases: Guffawaffle/stfc-mod-bridge
Release list
STFC Mod Bridge 0.1.0-rc.21
Important
Public canary — qualification is still in progress.
This is a prerelease for voluntary testing. Wait for the post-publication update-hosting workflow to succeed before using the App Installer entry point.
Install
Install with STFCModBridge.appinstaller after the update-hosting workflow is green. It is the user-facing installation and update entry point.
The signed MSIX, release manifest, SBOMs, and attestation bundles are machine-consumed trust inputs. stfc-mod-bridge-win-x64.zip is a standalone fallback, not the primary installation path.
What this candidate adds
- Authorizes the exact NetniV
v1.1.6.0Windows release and configuration catalog while retainingv1.1.4solely as historical receipt-normalization evidence. - Supports canonical four-component upstream versions and preserves the monotonic release floor when an existing managed NetniV
v1.1.4installation updates tov1.1.6.0. - Keeps current install authority separate from historical evidence; historical artifacts cannot become fresh install candidates.
- Prevents Settings History from crashing when real history entries materialize.
- Keeps release-source metadata within the Settings viewport and exposes its full accessible value.
- Makes idle success and informational feedback dismissible and transient.
- Replaces unavailable exact-Repair dead ends with truthful Stop-managing handoffs to Install, preserving Install, Update, or source alignment.
- Adds a responsive configuration-cleanup review with selectable catalog-authorized alias operations, verified backup, stale-authority rejection, and atomic Apply.
- Preserves unknown settings, including NetniV 1.1.6.0 settings awaiting typed Bridge controls, byte-for-byte.
Qualification completed
- Protected merged-main CI plus build, test, Azure signing, SBOM, package inspection, Authenticode-policy, attestation, and draft-transfer gates passed.
- The signed annotated tag targets exact protected-main commit
346bc3e48c9446e829113d3ecf84f20562cb286e; its signature verifies with the reviewed maintainer key. - Protected release run 32367153099 produced and reverified exactly eight staged assets.
- The authenticated release manifest is bound to
v0.1.0-rc.21, the exact repository, and the exact source commit. - Package inspection verified the MSIX and fallback executable allowlists, package identity, content integrity, publisher/EKUs/timestamps, App Installer contract, and launcher/verifier pairing.
- Broad and manifest-only GitHub attestation bundles were created and verified against the exact repository, workflow, tag, commit, and GitHub-hosted runner.
- Release-source validation recorded 1,506 passes, 13 expected skips, and zero failures; focused release/deployment/coordinator validation and three independent review lanes were clear.
- Read-only local integration checks passed against the maintained
E:\devSTFC test installation without changing game files.
Full candidate history and remaining v1 gates are tracked in qualification issue #30. The rc.20 dogfood corrections landed in PR #215, and NetniV 1.1.6.0 support landed in PR #218.
Qualification still open
- Personal rc.20 → rc.21 App Installer update and state-retention checks.
- Packaged real-install NetniV 1.1.4 → 1.1.6.0 update, clean install, repair, removal, provider switching, Settings catalog, and recovery dogfood.
- Packaged validation of History, bounded release-source text, transient/dismissible feedback, repair handoffs, and configuration-cleanup review/Apply.
- Pristine-Windows install and remaining App Installer interruption, rollback, repair, reinstall, and OS-uninstall lifecycle.
- Manual 100%, 125%, and 150% DPI; light, dark, system, and high-contrast themes; minimum-width review; keyboard-only and screen-reader accessibility.
- Final screenshot set, idle/interaction resource observation, independent offline verification, and compromise-response tabletop.
- Typed Bridge controls for the eleven newly introduced NetniV settings remain deferred to issue #217; their TOML remains preserved in this candidate.
- Final issue #30 evidence closure and a separately signed final
v0.1.0release decision.
Signature, hash, and provenance verification establish artifact identity and origin; they do not prove that the source or dependencies are free of defects or malicious behavior.
STFC Mod Bridge 0.1.0-rc.20
Important
Public canary — qualification is still in progress.
This is a prerelease for voluntary testing. Wait for the post-publication update-hosting workflow to succeed before using the App Installer entry point.
Install
Install with STFCModBridge.appinstaller after the update-hosting workflow is green. It is the user-facing installation and update entry point.
The signed MSIX, release manifest, SBOMs, and attestation bundles are machine-consumed trust inputs. stfc-mod-bridge-win-x64.zip is a standalone fallback, not the primary installation path.
What this candidate adds
- Makes the ordinary mod journey direct: Check for updates, then one prominent Update mod action installs the latest eligible upstream DLL.
- Offers Manage mod when a manually installed DLL is already the exact current release, preserving it while creating Bridge ownership and recovery evidence.
- Treats runtime-ignored invalid TOML values as advisory: Bridge preserves them and continues to allow editing, saving, and provider switching.
- Allows known manual DLLs to change provider preference and compatible TOML behavior without forcing adoption or replacing the DLL.
- Replaces the disabled
ms-appinstallerlaunch with a supported HTTPS App Installer handoff while keeping Bridge open and providing browser guidance. - Routes incomplete provider-switch recovery through Home and Diagnostics with the exact transaction target, configuration-only versus artifact-aware copy, context locking, in-process recomposition, and durable success feedback.
- Hardens provider-switch journal validation and dependency preflight before mutation, including one-action recovery of coordinated outer and inner transactions and a narrowly bound schema-v1 upgrade path.
- Improves accessible action names, live announcements, and stable automation identity for dynamic install, manage, update, repair, and recovery controls.
Qualification completed
- Protected merged-main CI plus build, test, Azure signing, SBOM, package inspection, Authenticode-policy, attestation, and draft-transfer gates passed.
- The signed annotated tag targets exact protected-main commit
24e1272374c580048d2d02613576058333e7cfcc; GitHub verifies the tag signature. - Protected release run 32331783627 produced exactly eight staged assets; all were independently downloaded and matched GitHub's recorded sizes and SHA-256 digests.
- The authenticated release manifest is schema v2, preview sequence 21, active, and bound to
v0.1.0-rc.20, the exact repository, and the exact source commit. - Independent signed-package inspection verified the MSIX and fallback executable allowlists, package identity, content integrity, publisher/EKUs/timestamps, App Installer contract, and launcher/verifier pairing.
- Broad and manifest-only GitHub attestation bundles verified against the exact repository, workflow, tag, commit, and GitHub-hosted runner.
- The independently downloaded launcher, verifier, and updater passed the runtime Authenticode trust policy.
- Release-source tests recorded 1,477 passes, 10 expected skips, and zero failures.
Full receipts and candidate history are recorded in qualification issue #30. The rc.20 UX, upstream-mod update, App Installer handoff, and recovery corrections landed in PR #206.
Qualification still open
- Personal rc.19 → rc.20 update, quick upstream-mod update/adoption, provider switching with runtime-ignored invalid values, clean install, removal, multi-directory, Settings/Data Sync, launch, and game-running-lock checks.
- Pristine-Windows install and remaining App Installer interruption, rollback, repair, and OS-uninstall lifecycle.
- Manual 100%, 125%, and 150% DPI; light, dark, and system themes; minimum-width review; keyboard-only and screen-reader accessibility.
- Final screenshot set, idle/interaction resource observation, independent offline verification, and compromise-response tabletop.
- Final issue #30 evidence closure and a separately signed final
v0.1.0release decision.
Signature, hash, and provenance verification establish artifact identity and origin; they do not prove that the source or dependencies are free of defects or malicious behavior.
STFC Mod Bridge 0.1.0-rc.19
Important
Public canary — qualification is still in progress.
This is a prerelease for voluntary testing. Wait for the post-publication update-hosting workflow to succeed before using the App Installer entry point.
Install
Install with STFCModBridge.appinstaller after the update-hosting workflow is green. It is the user-facing installation and update entry point.
The signed MSIX, release manifest, SBOMs, and attestation bundles are machine-consumed trust inputs. stfc-mod-bridge-win-x64.zip is a standalone fallback, not the primary installation path.
What this candidate adds
- Presents first-class provider-aware Settings for NetniV while preserving unsupported or unknown configuration without guessing.
- Adds actionable, document-bound Save/Discard recovery for Settings and Data Sync, including selected-installation changes and credential-draft lifecycle safety.
- Makes provider switching configuration-aware, atomic, crash-recoverable, and immediately recomposed in-process without requiring a Bridge restart.
- Enforces one cross-process mutation boundary across install, update, repair, remove, provider switch, configuration restore, Settings, and Data Sync operations.
- Preserves manual/developer DLLs and independent runtime manifests through explicit adoption and exact restoration, with final residue auditing against a maintained installation.
- Retains per-installation, per-provider release high-water identities and blocks stale prepared downgrades, replayed releases, ambiguous release families, and same-version byte substitution.
- Accepts permissible signed Guffawaffle releases such as
v2.1.0-guffa.10through Authenticode plus signed ProductVersion rather than catalog-pinning every release. - Binds deployment, rollback, durable copies, and recovery to exact Windows file identities and schema-v2 journals so matching bytes alone never silently transfer Bridge ownership.
Qualification completed
- Protected merged-main CI plus build, test, Azure signing, SBOM, package inspection, Authenticode-policy, Battle named-pipe, attestation, and draft-transfer gates passed.
- The signed tag targets exact protected-main commit
1771e07250d3e88c1171abea7729cbe8a7d2f503; the authenticated release manifest is schema v2, preview sequence 20, active, and bound to that tag and commit. - All eight staged assets were independently downloaded and reproduced their GitHub digests.
- Independent signed-package inspection verified the MSIX and fallback executable allowlists, package identity, content integrity, publisher/EKUs/timestamps, App Installer contract, and launcher/verifier pairing.
- Broad and manifest-only GitHub attestation bundles verified against the exact repository, workflow, tag, commit, and GitHub-hosted runner.
- The independently downloaded payload passed the runtime Authenticode trust policy.
- Final source qualification recorded 1,458 passing solution tests with 13 expected opt-in/platform skips, 82 runtime-pair tests, 50 deterministic live-harness safety tests, installed-target and complementary clean-target receipts, and clear general/hostile/trust review gates.
Full receipts and candidate history are recorded in qualification issue #30. The final source hardening and real-install closeout landed in PR #204.
Qualification still open
- Tonight's personal rc.18 → rc.19 update, clean install, manual-adoption/removal, provider round-trip, multi-directory, Settings/Data Sync, launch/game-running lock, and health checks.
- Pristine-Windows install and remaining App Installer interruption, rollback, repair, and OS-uninstall lifecycle.
- Manual 100%, 125%, and 150% DPI; light, dark, and system themes; minimum-width review; keyboard-only and screen-reader accessibility.
- Final screenshot set, idle/interaction resource observation, independent offline verification, and compromise-response tabletop.
- Final issue #30 evidence closure and a separately signed final
v0.1.0release decision.
Signature, hash, and provenance verification establish artifact identity and origin; they do not prove that the source or dependencies are free of defects or malicious behavior.
STFC Mod Bridge 0.1.0-rc.18
Important
Public canary — qualification is still in progress.
This is a prerelease for voluntary testing. Wait for the post-publication update-hosting workflow to succeed before using the App Installer entry point.
Install
Install with STFCModBridge.appinstaller after the update-hosting workflow is green. It is the user-facing installation and update entry point.
The signed MSIX, release manifest, SBOMs, and attestation bundles are machine-consumed trust inputs. stfc-mod-bridge-win-x64.zip is a standalone fallback, not the primary installation path.
What this candidate adds
- Tracks an independent Bridge ownership receipt for every game installation Bridge has managed or adopted while keeping folder selection separate.
- Derives each selected installation's status from its live files and its own receipt, including managed, externally modified, manually installed, missing, and clean states.
- Allows a clean selected installation to be managed even when another installation has a separate Bridge receipt.
- Scopes repair, removal, recovery, migration, and Stop Managing to the exact canonical installation path.
- Refuses to remove live bytes that no longer match Bridge's receipt; Repair or Stop Managing remains available without deleting unrelated files.
- Preserves the current Guffawaffle v2.1.0-guffa.9 certification, latest .NET 8 servicing baseline, and user-initiated App Installer update policy.
Qualification completed
- Protected merged-main CI plus build, test, Azure signing, SBOM, package inspection, Authenticode-policy, Battle named-pipe, attestation, and draft-transfer gates passed.
- All eight staged assets and all nine final attested subjects were independently verified against signed tag v0.1.0-rc.18 and protected-main commit 506369d.
- The signed MSIX upgraded the installed package from rc.17 to rc.18 while preserving all 49 Bridge-state files, the separate personal-install receipt, the selected-folder record, and all six personal-install TOMLs byte-for-byte.
- Packaged UI Automation reproduced the former multi-install scenario and exposed an enabled Install action for the clean selected installation instead of the rc.17 cross-install blocker.
- Live Guffawaffle and NetniV install/remove plus Guffawaffle → NetniV → Guffawaffle switching passed with exact clean-target restoration.
Full receipts and candidate history are recorded in qualification issue #30. The per-installation ownership blocker was resolved by PR #182.
Qualification still open
- Pristine-Windows clean install and the remaining App Installer interruption, rollback, repair, and OS-uninstall lifecycle.
- Manual 100%, 125%, and 150% DPI; light, dark, and system themes; minimum-width review; keyboard-only and screen-reader accessibility.
- Final screenshot set and idle/interaction resource observation.
- Remaining manual real-action checks, compromise-response tabletop, and final issue #30 evidence closure.
Signature, hash, and provenance verification establish artifact identity and origin; they do not prove that the source or dependencies are free of defects or malicious behavior.
STFC Mod Bridge 0.1.0-rc.17
Important
Public canary — qualification is still in progress.
This is a prerelease for voluntary testing. Wait for the post-publication update-hosting workflow to succeed before using the App Installer entry point.
Install
Install with STFCModBridge.appinstaller after the update-hosting workflow is green. It is the user-facing installation and update entry point.
The signed MSIX, release manifest, SBOMs, and attestation bundles are machine-consumed trust inputs. stfc-mod-bridge-win-x64.zip is a standalone fallback, not the primary installation path.
What this candidate adds
- Certifies the current Guffawaffle
v2.1.0-guffa.9signed DLL and its exact runtime-manifest companion. - Supports the provider's exact two-file compatibility ZIP while rejecting missing, changed, nested, duplicate, or additional payloads.
- Preserves strict file-version verification by binding the signed DLL's actual
2.1.0.0version only to the exact reviewed repository, tag, source commit, DLL, and runtime-manifest identity. - Includes the latest .NET 8 servicing baseline and the corrected user-initiated App Installer update policy.
Qualification completed
- Protected build, test, Azure signing, SBOM, package inspection, Authenticode-policy, Battle named-pipe, attestation, and draft-transfer gates passed.
- All eight staged assets and all nine final attested subjects were independently verified against signed tag
v0.1.0-rc.17and protected-main commit12f3abefcd85c57d8cd5d5661a21d5a673aa4bf1. - The signed MSIX upgraded the installed package from rc.16 to rc.17 while preserving all Bridge state and production game TOMLs byte-for-byte.
- Packaged UI Automation passed.
- Live Guffawaffle and NetniV install/remove plus Guffawaffle → NetniV → Guffawaffle switching passed with exact clean-target restoration.
Full receipts and candidate history are recorded in qualification issue #30. The provider-certification blocker was resolved by PR #180.
Qualification still open
- Pristine-Windows clean install and the remaining App Installer interruption, rollback, repair, and OS-uninstall lifecycle.
- Manual 100%, 125%, and 150% DPI; light, dark, and system themes; minimum-width review; keyboard-only and screen-reader accessibility.
- Final screenshot set and idle/interaction resource observation.
- Remaining manual real-action checks, compromise-response tabletop, and final issue #30 evidence closure.
Signature, hash, and provenance verification establish artifact identity and origin; they do not prove that the source or dependencies are free of defects or malicious behavior.
STFC Mod Bridge 0.1.0-rc.9
Warning
Public canary — qualification is still in progress. This prerelease is available for voluntary testing, but it has not completed the full v1 clean-machine, game-integration, accessibility, and recovery matrix.
Install STFC Mod Bridge with STFCModBridge.appinstaller only after the published-release hosting workflow succeeds for this release. Windows App Installer owns installation, updates, and uninstall. Application state remains under %LOCALAPPDATA%\STFC Mod Bridge.
What changed
- Corrected the GCS publication check to compare the public App Installer descriptor as exact bytes instead of comparing incompatible PowerShell response types.
- Completed the first end-to-end keyless GitHub OIDC → Google Cloud publication boundary for the preview App Installer feed.
- Supersedes
v0.1.0-rc.8for new testing. The rc.8 signed bytes verified correctly, but its hosting workflow ended red on the false-negative descriptor assertion and its immutable notes retained draft wording.
Completed producer evidence
- Source: signed tag
v0.1.0-rc.9, exact commit1294d5a8ca07bc506846a4a6ec828f9655e3ca98, reachable from protectedmain. - Protected release workflow passed locked restore/tests, vulnerability and Defender gates, Azure OIDC signing, package inspection, runtime Authenticode policy, SBOM generation, and attestation verification.
STFCModBridge.exe,STFCModBridge.ReleaseVerifier.exe,STFCModBridge.Updater.exe, andSTFCModBridge.msixhave valid Joseph Gustavson Authenticode signatures and trusted RFC 3161 timestamps.- The MSIX contains only the reviewed launcher and release verifier, enforces package integrity, and matches the App Installer identity/version contract.
- Independent draft verification matched the authenticated manifest sizes and SHA-256 values and verified every broad attestation plus the dedicated single-subject manifest attestation.
Open public-canary checks
- Fresh-machine installation from the production App Installer URL and rc.8 → rc.9 version-to-version update with exact state retention.
- Interrupted update, repair, OS-owned uninstall, and uninstall/reinstall preservation behavior.
- Real STFC install/update/repair/remove and Guffawaffle ↔ NetniV provider round trips with the game-closed boundary.
- Final 100%/125%/150% scaling, minimum-width, light/dark/system theme, keyboard, UI Automation, and screenshot review.
- Clean-machine independent online/offline verification and compromise/revocation-response rehearsal.
- Native authenticated self-update shipping authorization remains fail-closed until the remaining v1 qualification work is accepted.
The MSIX, ZIP, manifest, SBOMs, and attestation bundles are machine-consumed trust/update inputs or a clearly labeled standalone fallback—not additional installation entry points. Signatures, hashes, and attestations establish publisher/build origin and byte integrity; they do not prove that the software or its dependencies are safe or free from malicious behavior.
STFC Mod Bridge 0.1.0-rc.8
Warning
Qualification draft. Do not publish or distribute this release until its canary evidence is complete.
Install STFC Mod Bridge with STFCModBridge.appinstaller after the published-release hosting check succeeds.
The MSIX, ZIP, manifest, SBOMs, and attestation bundles are machine-consumed trust/update inputs, not alternate installation entry points.
STFC Mod Bridge 0.1.0-rc.10
Warning
Public canary — qualification is still in progress. This prerelease is available for voluntary testing, but it has not completed the full v1 clean-machine, game-integration, accessibility, and recovery matrix.
Install STFC Mod Bridge with STFCModBridge.appinstaller only after the published-release hosting workflow succeeds for this release. Windows App Installer owns installation, updates, and uninstall. Application state remains under %LOCALAPPDATA%\STFC Mod Bridge.
What changed
- The Home window now opens at the intended content size and clamps safely to constrained displays instead of starting wider than its content.
- Settings can save valid edits to their intended TOML target without unrelated warnings elsewhere in the configuration blocking the save.
- Provider switching now uses a simpler, scrollable one-time review with retryable actions, persistent acknowledgement, and corrected accessibility labels and stale-preview handling.
- A running STFC process is reported as normal runtime state instead of degrading the installed mod's verified health; launch-process attribution is preserved.
- Supersedes
v0.1.0-rc.9for preview testing.
Completed producer evidence
- Source: signed tag
v0.1.0-rc.10, exact commita797254a54a82bfd1fe3f928820fd5290588284c, reachable from protectedmain. - Protected release workflow passed locked restore/tests, vulnerability and Defender gates, Azure OIDC signing, package inspection, runtime Authenticode policy, SBOM generation, and attestation verification.
- The local release suite passed 728 tests with 7 expected opt-in skips; the hosted build, signing, and draft-staging jobs all passed.
STFCModBridge.exe,STFCModBridge.ReleaseVerifier.exe,STFCModBridge.Updater.exe, andSTFCModBridge.msixhave valid Joseph Gustavson Authenticode signatures and trusted RFC 3161 timestamps.- The MSIX contains only the reviewed launcher and release verifier, enforces package integrity, and matches the App Installer identity/version contract.
- Independent verification of the exact draft assets matched the authenticated manifest sizes and SHA-256 values and verified all nine broad release attestations plus the dedicated single-subject manifest attestation against the reviewed workflow, tag, and commit.
Open public-canary checks
- Fresh-machine installation from the production App Installer URL and rc.9 → rc.10 version-to-version update with exact state retention.
- Interrupted update, repair, OS-owned uninstall, and uninstall/reinstall preservation behavior.
- Real STFC install/update/repair/remove and Guffawaffle ↔ NetniV provider round trips with the game-closed boundary.
- Final 100%/125%/150% scaling, minimum-width, light/dark/system theme, keyboard, UI Automation, and screenshot review.
- Clean-machine independent online/offline verification and compromise/revocation-response rehearsal.
- Native authenticated standalone self-update shipping authorization remains fail-closed until the remaining v1 qualification work is accepted.
The MSIX, ZIP, manifest, SBOMs, and attestation bundles are machine-consumed trust/update inputs or a clearly labeled standalone fallback—not additional installation entry points. Signatures, hashes, and attestations establish publisher/build origin and byte integrity; they do not prove that the software or its dependencies are safe or free from malicious behavior.
STFC Mod Bridge 0.1.0-rc.4 — Public canary
Warning
Public canary — qualification is still in progress. This is a prerelease for technically comfortable testers, not a stable release or a completed v1 security claim. Back up your Community Mod settings before provider changes.
Install STFC Mod Bridge with STFCModBridge.Setup.exe. The ZIP, manifest, SBOM, and attestation bundle are machine-consumed trust/update inputs, not alternate installation packages.
Validated on the maintainer's current Windows machine:
- signed Setup, launcher, and updater; exact release bytes independently matched the manifest and GitHub build-provenance attestation
- RC.3 → RC.4 replacement/self-update and state-preserving uninstall/reinstall
- Guffawaffle and NetniV install/remove plus Guffawaffle → NetniV → Guffawaffle restoration on a disposable game fixture
- game discovery and game-closed mutation boundary
- settings/UI smoke at 125% DPI and 960×620 minimum size
- redacted Diagnostics export matching its preview
Still intentionally open: a clean-VM/fresh-user pass, separately driven live repair/interruption cases, exact 100%/150% DPI checks, and a live Light/Dark/System visual pass. Track the qualification record in #84.
Report bugs with the repository's structured bug form, usability problems with the usability form, and security-sensitive findings through private vulnerability reporting.
Source commit: 37c61305a553ec155c05186a0e6549c70b4ed489
Release workflow: run 30985818161
Build provenance: attestation 38972993
STFC Mod Bridge 0.1.0-rc.3 — REJECTED
Caution
Rejected release candidate — do not install for closed-alpha testing.
This build has a provider-state projection regression. It is retained only as historical release evidence. Use only a later release whose notes explicitly say Closed-alpha approved.
Install STFC Mod Bridge with STFCModBridge.Setup.exe.
The ZIP and JSON assets are machine-consumed self-update inputs, not alternate installation packages.
Tracking: #84