Launcher update manifest is a signed document
LNCH-0129 ○ Planned Lite and Pro Core Free (launcher)The update manifest (product id, channel, version, release date, notes, artifacts with name, url, sha256 and size, blocked versions) travels inside the signed-document envelope with an Ed25519 signature checked against embedded keys, expiry and a minimum document version; an unsigned manifest is never acted on
Depends on: LNCH-0001
Launcher manifest gate before any download
LNCH-0130 ○ Planned Lite and Pro Core Free (launcher)Product id must match, platform must match, the artifact must be a named file (never a folder URL), the version must not be blocked and must not be older than the installed one, all checked after the signature and before a download starts
Depends on: LNCH-0001
Launcher blocked versions list
LNCH-0131 ○ Planned Lite and Pro Core Free (launcher)The signed manifest lists versions that must never be offered or installed (known-bad releases); a blocked installed version is flagged for update or rollback
Depends on: LNCH-0001
Launcher checksum is mandatory (empty hash refused)
LNCH-0132 ○ Planned Lite and Pro Core Free (launcher)A missing or empty sha256 or size in the manifest fails the update; there is no skip-the-check path
Depends on: LNCH-0001
Launcher staging download with .partial then rename
LNCH-0133 ○ Planned Lite and Pro Core Free (launcher)The artifact is downloaded to a .partial file in the local staging folder, its sha256 and size are verified, and only then renamed to its final staged name
Depends on: LNCH-0001
Launcher stale partial and staging cleanup
LNCH-0134 ○ Planned Lite and Pro Standard Free (launcher)Leftover .partial files and abandoned staging entries from failed downloads are removed on the next start or update attempt
Depends on: LNCH-0001
Launcher staging in a local non-synced folder
LNCH-0135 ○ Planned Lite and Pro Standard Free (launcher)Staging lives under the local application-data folder, not in documents or a cloud-synced folder, to avoid sync and antivirus locks
Depends on: LNCH-0001
Launcher disk-space preflight before download
LNCH-0136 ○ Planned Lite and Pro Core Free (launcher)Check free space for the artifact and its staged copy before downloading and stop early with a plain message
Depends on: LNCH-0001
Launcher successor-file apply (never overwrite the running program)
LNCH-0137 ○ Planned Lite and Pro Core Free (launcher)The new version is copied to its own versioned file or folder and the old one is left in place; the running executable is never overwritten
Depends on: LNCH-0001
Launcher relaunch helper waits for the old process
LNCH-0138 ○ Planned Lite and Pro Core Free (launcher)A small helper waits for the old process to exit, starts the new version, and runs outside the old process tree; the launcher releases its single-instance lock before quitting
Depends on: LNCH-0001
Launcher resolves its real executable path
LNCH-0139 ○ Planned Lite and Pro Standard Free (launcher)The launcher finds the real path of its own file even when a portable build unpacks to a temp folder; updates never use the temp copy as the install slot
Depends on: LNCH-0001
Launcher real rollback to the previous generation
LNCH-0140 ○ Planned Lite and Pro Core Free (launcher)The previous generation is kept (hash recorded) and the user can switch back to it with one action; there is no downgrade through the manifest, only an explicit rollback to a retained, verified generation
Depends on: LNCH-0001
Launcher automatic rollback after a failed first start
LNCH-0141 ○ Planned Lite and Pro Core Free (launcher)A new generation that does not confirm a healthy start is rolled back to the previous generation on the next launcher open; the user is told why
Depends on: LNCH-0001
Launcher rollback never selects a blocked version
LNCH-0142 ○ Planned Lite and Pro Standard Free (launcher)Rollback and pinning refuse any generation that the current signed manifest lists as blocked
Depends on: LNCH-0001
Launcher keeps a bounded number of generations
LNCH-0143 ○ Planned Lite and Pro Standard Free (launcher)Keep the current and previous generation (a small fixed number of older ones) and delete the rest after a successful update
Depends on: LNCH-0001
Launcher full version comparison including prerelease
LNCH-0144 ○ Planned Lite and Pro Standard Free (launcher)Compare versions with full semantic-version rules including prerelease and build parts; a prerelease is never treated as equal to its release
Depends on: LNCH-0001
Launcher offline signed-file install uses the same checks
LNCH-0145 ○ Planned Lite and Pro Core Free (launcher)Installing an update from a file received by USB or messenger checks the same signature, expiry, blocked list, hash and size as an online update, with no network
Depends on: LNCH-0001
Launcher no fallback manifest sources
LNCH-0146 ○ Planned Lite and Pro Core Free (launcher)Only the configured manifest sources are read; no catalog fallback, no source-host (for example repository release) fallback and no access tokens from the environment
Depends on: LNCH-0001
Launcher fails open on any update error
LNCH-0147 ○ Planned Lite and Pro Core Free (launcher)Any failure to check or fetch leaves the installed version running and shows a plain reason; nothing is retried in the background
Depends on: LNCH-0001
Launcher remembers last check result without polling
LNCH-0148 ○ Planned Lite and Pro Standard Free (launcher)The last check time, result and seen manifest version are stored locally for display and rollback protection; they never trigger a check
Depends on: LNCH-0001
Launcher never applies an update at start
LNCH-0149 ○ Planned Lite and Pro Core Free (launcher)Opening the launcher may offer an update but never installs one; apply needs a user action every time
Depends on: LNCH-0001
Launcher carries no embedded demo or founder keys
LNCH-0150 ○ Planned Lite and Pro Core Free (launcher)No credential, key or launcher key is hard-coded in the launcher, the app or the updater
Depends on: LNCH-0001
Update artifact publish order and verification
LNCH-0151 ○ Planned Lite and Pro Standard Free (launcher)Publish the artifact first, then the signed manifest, then fetch both back and verify before announcing; purge cached not-found answers for new keys
Depends on: LNCH-0001
Update hosting prefixes per channel
LNCH-0152 ○ Planned Lite and Pro Standard Free (launcher)Static layout per product and channel (stable and dev) with an immutable artifact and a no-store manifest; the host is any static server or mirror
Depends on: LNCH-0001
Stock earlier launcher registry row for Simca (open)
LNCH-0153 ○ Planned Lite and Pro Optional Free (launcher)Registering Simca in the stock earlier launcher needs a registry row in its product list and a launcher release, with the artifact on the update host; the stock launcher does not verify the manifest hash before install, has no signing, and signs the user in to its seats service
Depends on: LNCH-0001
Simca-forked launcher that never calls seats (open)
LNCH-0154 ○ Planned Lite and Pro Optional Free (launcher)A Simca launcher forked from the earlier launcher without the tether, launcher keys, presence or seats calls; compare with registering Simca as a free offline SKU in the stock launcher (decision D27)
Depends on: LNCH-0001
Stock launcher as free offline SKU limits (open)
LNCH-0155 ○ Planned Lite and Pro Optional Free (launcher)If Simca is listed in the stock launcher as a free SKU, the user's launcher still signs in and talks to seats, which Simca cannot control; the no-account promise would then hold for Simca's own code only
Depends on: LNCH-0001
Launcher reuses signed install-from-file for stock-launcher users
LNCH-0156 ○ Planned Lite and Pro Standard Free (launcher)Whatever launcher is used, the app verifies the signature of its own update packages before use, because the stock launcher does not
Depends on: LNCH-0001