# VPNCheap Flutter Client Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **87/100**. Verify the macOS disconnect fix, then explicitly decide the Flutter repository's platform and support role before narrowing or retiring any ownership. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Scope and state

Current repository instructions identify this as the main Flutter client across iOS, Android, macOS, Windows, and Linux. The retained feedback assigned here is only the explicit Flutter macOS VPN-02 incident; broader platform ownership remains a proposal until the product owner approves the routing/support boundary. The filename describes this historical planning lane, not an approved legacy status.

- **OBSERVED:** Flutter macOS users repeatedly disconnected 2-8 seconds after connection.
- **MEASURED:** the post-connect reachability auto-recovery that tore down tunnels was removed on main; no released-build/device receipt closes adoption or recurrence.
- **MEASURED:** the current local diagnostic worktree is heavily dirty and is evidence-only for this plan.

`△ ☐☐☐ | 0/1/3/0`

| State | IDs or decision | Local obligation |
|---|---|---|
| `△` | VPN-02 | Exact fix exists; adoption and real-device recurrence proof are missing. |
| `☐` | client-role boundary, VPN-17 adoption, VPN-13 adoption | Support boundary and shared contracts are not decided end-to-end. |

## Execution sequence

Order follows dependency and owner sequence, not numeric rank. Canonical fingerprint scores and program-value judgments are different decision ledgers and are not directly comparable.

Canonical references, not local rescores: item 1 -> VPN-02; item 4 -> VPN-13. Items 2 and 3 are separate executive program judgments.

### 1. Verify the disconnect fix: 68/100, P2

Breakdown: `24 + 7 + 12 + 5 + 10 + 10`.

**PROPOSED:** identify the last shipped Flutter macOS build, adoption cohort, OS versions, and recurrence; run connect, long-RTT, blocked probe target, sleep/wake, reconnect, and user-disconnect tests on real devices.

### 2. Approve repository role and platform boundary: decision 88/100

Recommended proposal: **Linux active, Flutter macOS maintenance-only with a dated migration/retirement gate, 88/100**. Before approval, inventory current releases, active cohorts, native overlaps, and support promises; do not treat this proposal as current repository status.

Alternatives:

- Indefinite native/Flutter parity: **42/100**. High recurring cost and ambiguous support routing.
- Silent abandonment with no cohort inventory: **19/100**. Converts routing ambiguity into customer risk.

### 3. Privacy-safe support bundle, program value: 76/100

**PROPOSED:** include app/platform/build, state-transition timestamps, OS/core reason classes, cache/failover state, and consent. Exclude ingress, protocol, config, raw URL, credentials, and full user content.

### 4. Signed client capability contribution: 54/100, P3 evidence gate

Breakdown: `24 + 3 + 5 + 15 + 0 + 7`.

Adopt only for product-owner-approved Flutter cohorts after Xboard freezes the contracts. UA-only authorization scores **18/100**.

Shared account freshness follows canonical VPN-17 at `81/100, P1` in the portfolio registry; this component plan does not rescore it.

## Phases and acceptance

- **0-30:** inventory shipped cohorts; verify VPN-02; approve the Flutter platform/support boundary.
- **31-60:** fix only failed verification paths in a clean isolated worktree; publish migration/support copy only after boundary approval.
- **61-90:** observe recurrence and migration; remove ambiguous support routing only after the remaining cohort is measured.
- `○` requires real device tunnel transition plus changed public egress. Static tests never promote this item.

### Phase gates

- **0-30:** evidence coverage reaches 100%.
- **31-60:** every scheduled P1/P2 acceptance is complete or explicitly approved `X`.
- **61-90:** two canary windows close without regression.
- Stop immediately on any listed guardrail.
- P3 acceleration requires the governing-contract exception and never displaces P0-P2.

## Guardrails

- Data-plane health truth lives in the core. Host/Dart probes never auto-teardown a surfaced connected tunnel.
- Preserve unrelated dirty files; implementation later must use a clean worktree.
- Never expose ingress detail or protocol; keep node UI list-based and localized.
