BUILD NOTES — 2026-10-05

Native C++17 Win32/GDI+ renderer. .scr modes /s, /c[:HWND], /p HWND.
No WebView, web server, network requests, embedded music, or personal data.
Uses normal Windows screensaver installation; no changes to secure resume
or display power policies. UI has import, previews, reduced motion, install.

Compiler: official llvm-mingw 20260922 UCRT macOS universal release
https://github.com/mstorsjo/llvm-mingw/releases/tag/20260922
Archive SHA-256:
52e5f5a7b131021d0c39a37a38fa380a1da7885cd04bd61afd0cd4ecfb8bc1f3
Verified against the release asset digest returned by the GitHub API.
JSON header: nlohmann/json v3.12.0
https://github.com/nlohmann/json/tree/v3.12.0
json.hpp SHA-256:
aaf127c04cb31c406e5b04a63f1ae89369fccde6d8fa7cdda1ed4f32dfc5de63

Build from this directory:
TOOLCHAIN=/absolute/path/to/llvm-mingw ./build.sh
Outputs dist/x64 and dist/ARM64. Statically linked C++ runtimes;
only Windows-provided system DLL imports. GUI subsystem, ASLR and DEP.
Embedded version, asInvoker and PerMonitorV2 DPI manifests.

Host core tests:
clang++ -std=c++17 -O1 -g -fsanitize=undefined tests/core.cpp -o build/core-tests
./build/core-tests
Result: PASS, no undefined-behavior reports.
AddressSanitizer did not initialize on this macOS host (Apple runtime
sanitizer_malloc_mac.inc assertion); no ASan result claimed.

Covered: supported schema, Unicode, inert HTML script extraction, BOM,
invalid/deep/oversized/duplicate input rejection, maximum text length,
complete group cycling, reduced-motion stability, bounded moving positions,
and Windows command parsing. Test fixtures use sample data only.

x64 and ARM64 executable headers/imports were inspected with llvm-readobj.
Native GDI+ rendering and Windows host lifecycle have NOT been run here.
Windows validation is required before public distribution; see checklist.

Sources:
https://learn.microsoft.com/en-us/windows/win32/devnotes/scrnsave-exe
https://learn.microsoft.com/en-us/windows/win32/lwef/screen-saver-library
