# VPNCheap macOS Customer Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **93/100**. Treat green-without-internet and dual-egress identity as correctness work, not UI polish, while preserving core/OS authority. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Evidence and state

- **OBSERVED:** build 179 showed connected with no internet; later users reported TLS login failure, auto-selection mismatch, wrong displayed location, and apparent dual egress.
- **MEASURED:** TLS and dual-egress fixes exist with tests; no affected-machine or current-release receipt closes them.
- **MEASURED:** the routing fix predates the build-179 report, and current handoff still records no complete connected-state egress acceptance.
- **MEASURED:** build config says macOS 14 while portfolio documentation is inconsistent.

`△△△ ☐☐☐☐☐ | 0/3/5/0`

| State | IDs | Local obligation |
|---|---|---|
| `△` | VPN-12, VPN-14, VPN-15 | Node, TLS, and dual-egress fixes exist; real verification is missing. |
| `☐` | VPN-05, VPN-06, VPN-17, VPN-19, VPN-13 adoption | False-green, slowness, freshness, support policy, and signed capability remain open. |

```text
BEFORE  OS says connected -> UI green -> traffic may be dead or mismatched
AFTER   OS/core state + bounded acceptance -> safe advisory -> one verified egress
```

## Execution sequence

Order follows dependency and owner sequence, not numeric rank. Canonical fingerprint scores and program-value judgments are different decision ledgers and are not directly comparable.

Scores below are canonical registry references, not local rescores: items 1-7 -> VPN-05, VPN-15, VPN-17, VPN-06, VPN-14, VPN-19, and VPN-13 respectively.

### 1. Connected-but-no-internet acceptance: 75/100, P1

Breakdown: `30 + 3 + 12 + 10 + 10 + 10`.

**PROPOSED:** reproduce build 179 and current release on real devices, capture privacy-safe OS/core transitions and route/DNS outcome classes, and use a bounded connect-acceptance check. After the UI surfaces connected, any liveness probe is advisory only and cannot auto-teardown or reconnect.

### 2. One selected node equals one egress identity: 75/100, P1

Breakdown: `30 + 3 + 12 + 10 + 10 + 10`.

**PROPOSED:** verify first election, node switch, connection interruption, display reconciliation, IPv4/IPv6 leak surface, sleep/wake, and rapid reconnect. Verification may compare egress externally but never logs or displays network addresses.

### 3. Cross-client node and account freshness: 81/100, P1

Breakdown: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** adopt Xboard generation/revision, visible stale/pending states, pull-to-refresh, and account-switch invalidation; include the shared node release matrix.

### 4. Cross-desktop slowness attribution: 65/100, P2

Breakdown: `16 + 7 + 12 + 15 + 5 + 10`.

**PROPOSED:** correlate privacy-safe client phase timings with service/node metrics. Separate startup, selection, DNS, route, handshake, first-byte, and sustained-throughput classes before changing client or network policy.

Ownership: `vpncheap-app` is A for VPN-06; `vpncheap-macos`, `vpncheap-windows`, and VPNCheap node/service operations are R for their measured layer.

### 5. Affected-machine TLS login acceptance: 59/100, P2

Breakdown: `24 + 3 + 12 + 5 + 5 + 10`.

**PROPOSED:** retry the released TLS classifier/failover fix on an affected machine across certificate-date failure, generic handshake failure, endpoint failover, sleep/wake, and account switch; retain privacy-safe reason classes and a release receipt.

### 6. Support baseline: 53/100, P3

Breakdown: `8 + 3 + 20 + 10 + 5 + 7`.

**PROPOSED:** publish macOS 14 as current baseline, **88/100**, because it matches the project source of truth. Lowering the build target without compatibility and release proof scores **41/100**.

### 7. Signed client capability: 54/100, P3 evidence gate

Breakdown: `24 + 3 + 5 + 15 + 0 + 7`.

Inventory the current generic identifier/session flow and adopt the Xboard contract after it is frozen. UA-only authorization scores **18/100**.

## Phases

- **0-30:** real-device verification cards for VPN-05/12/14/15; freeze the P1 freshness envelope; baseline desktop performance; inventory current support declarations and client-identity adapters as evidence only. No P3 definition or publication occurs and no acceleration is claimed.
- **31-60:** fix only proven P1/P2 failing layers in an isolated branch; add sleep/wake, switch, dual-stack, stale account, and TLS tests.
- **61-90:** after scheduled P0-P2 gates close, define and publish the support baseline from one source, then define and adopt the signed-capability contract; canary release and observe false-green, connection identity mismatch, no-node, refresh, TLS, slowness, support-policy mismatch, and compatibility fingerprints.

### Phase gates

- **0-30:** evidence coverage reaches 100%.
- **31-60:** every scheduled P1/P2 acceptance is complete or explicitly approved `X`.
- **61-90:** two canary windows close without regression.
- Stop immediately on any listed guardrail.
- No P3 acceleration is claimed; support-baseline publication and signed-capability work start in 61-90 only after P0-P2 gates close.

## Acceptance and guardrails

- `○` requires real System Extension/NetworkExtension transition and changed public egress.
- `NEVPNStatus` and core events own connection state; supervisory checks never end a surfaced connected session.
- Never expose ingress address, protocol, raw configuration, subscription URL, or observed egress value.
- Preserve System Extension signing/notarization, list UI, Liquid Glass, and four-language errors.
- Stop on traffic leak, dual egress, stale-account overwrite, extension lifecycle regression, or sensitive logging.
