Client Loader 1.0.0 - Windows x64

For users
  Extract the complete ZIP. Keep loader.ini beside ClientLoader.exe.
  Open ClientLoader.exe, start VRChat, and select its process.
  Click Download & load client. The loader gets the latest release from the
  configured Cloudflare HTTPS address, verifies its SHA-256, x64 DLL format,
  exported standalone client API, and embedded version, then loads it.
  Wait until the client reports ready. Open Quick Menu > Client.
  Check update checks release metadata without loading anything.
  Use local DLL selects an existing standalone client DLL for offline loading.
  Start VRChat opens Steam's normal VRChat launch link.
  Open logs opens %LOCALAPPDATA%\ClientLoader.

Updates and files
  Releases are cached by version and full SHA-256 under:
    %LOCALAPPDATA%\ClientLoader\releases
  Your update address is saved in that folder's settings.ini.
  Startup/progress/error logs are loader.log and loader.previous.log.
  Updates are downloaded into a staging file. A partial, corrupted, wrong-
  version or unsupported DLL never replaces the verified cached release.
  Restart VRChat before changing an already-loaded client release.
  The loader does not forcibly stop, replace or unload an active client.

Limits
  Windows 10/11 x64. Windows system APIs only; no Python, Node.js, UNIx or
  managed runtime is needed on users' computers.
  The process must permit normal Windows DLL loading. Access-denied errors
  are reported. No drivers, anti-cheat bypasses or security changes are used.
  Both apps should run under the same Windows account and elevation level.
  SHA-256 checks download integrity; release files are served using HTTPS.
  Client runtime ready is the DLL's own status, not a headset/UI verification.
  Loader and DLL code signing is not configured in this project.

For the owner
  This is an independent C++ project at VRCMOD\ClientLoader. It does not
  modify or build VRCMOD\test. Open ClientLoader.slnx, build Release x64.
  Visual Studio C++ toolset v145 and Windows SDK 10 are required to build.
  Alternatively run scripts\Build.ps1. It builds and runs loader checks.

  Prepare an updated release with PowerShell:
    .\scripts\Prepare-Release.ps1 -ClientDll 'PATH\TO\VERSIONED.dll' -BaseUrl 'https://test-client-loader.pages.dev'
  The DLL version comes from its embedded FileVersion. The script creates
  site\latest.ini, immutable version/hash release paths, chunks of at most
  20 MiB, and the loader-only ZIP. No user settings or credentials are copied.
  Each file fits Cloudflare Pages' 25 MiB static-file limit.

  Hosting setup uses Cloudflare Pages Direct Upload on the free pages.dev
  domain. Owner tooling only: install Node.js and pnpm, run pnpm install,
  pnpm run login (authenticate through your browser), then pnpm run deploy.
  Wrangler 4.149.0 is pinned in package.json. The deploy command explicitly
  uses Pages Direct Upload, because newer Wrangler can delegate to Workers.
  Upload the whole generated site folder for each release. Retain old chunks
  when preparing another release so in-flight downloads can finish.

Verification
  LoaderTests.exe uses inert test DLLs and its own LoaderTestHost.exe.
  It validates manifests, paths, PE bounds, download integrity, split files,
  existing-client detection, process identity, loading and failure states.
  It does not inject into VRChat. Production UI only accepts VRChat.exe.
  LoaderTests.exe --download HTTPS_MANIFEST_URL verifies real hosted downloads
  without loading them. See test-results and VALIDATION.md for current evidence.
