<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<!--
    Distribution definition for the QNova Client installer.

    `3.0.0` and `QNovaClient-component.pkg` are substituted by scripts/build-pkg.sh.
    This file is a template on purpose: hard-coding the version here means it
    silently disagrees with Info.plist the first time someone bumps one and not
    the other, and the installer then reports a version it did not install.
-->
<installer-gui-script minSpecVersion="2">
    <title>QNova Client</title>
    <organization>com.quantumnova</organization>
    <!--
        System volume only. QNova installs a launchd daemon in
        /Library/LaunchDaemons and its app must live in /Applications for macOS
        to load the tunnel system extension at all, so a home-directory or
        alternate-volume install would produce something that appears to have
        installed and cannot connect.
    -->
    <domains enable_anywhere="false" enable_currentUserHome="false" enable_localSystem="true"/>
    <!--
        customize="never": there is one payload and it is not optional. Offering
        a customise pane whose only content is a checkbox the user must leave
        alone is friction that can only produce a broken install.

        hostArchitectures covers both slices so the same pkg installs on Apple
        Silicon and Intel.
    -->
    <options customize="never" require-scripts="true" hostArchitectures="arm64,x86_64"/>
    <!--
        Sidebar artwork: the QNova wordmark near the top, the app icon near the
        bottom, composited into one image by
        scripts/make-installer-background.swift.

        ONE image and not two, because a distribution package has exactly one
        <background> slot per appearance. The two marks want different positions,
        so they are one canvas the size of the sidebar with each element placed
        inside it — and `alignment="topleft"` anchors that canvas so the wordmark
        lands above Installer's step list and the icon below it.

        Two files, because the wordmark's lettering flips with the appearance:
        dark brand teal on the light sidebar, white on the dark one. The "Q" stays
        cyan in both. Using one file for both leaves the lettering nearly
        invisible in whichever mode it was not drawn for.

        `scaling="none"` means the pixel dimensions ARE the on-screen point size.
        There is no @2x mechanism for a distribution background.
    -->
    <background file="background.png" alignment="topleft" scaling="none"/>
    <background-darkAqua file="background-dark.png" alignment="topleft" scaling="none"/>
    <welcome file="welcome.html" mime-type="text/html"/>
    <conclusion file="conclusion.html" mime-type="text/html"/>
    <!--
        Refused on anything older than the deployment target rather than
        installed and broken. Package.swift declares .macOS(.v14).
    -->
    <volume-check>
        <allowed-os-versions>
            <os-version min="14.0"/>
        </allowed-os-versions>
    </volume-check>
    <choices-outline>
        <line choice="default">
            <line choice="com.quantumnova.vpn.client.pkg"/>
        </line>
    </choices-outline>
    <choice id="default"/>
    <choice id="com.quantumnova.vpn.client.pkg" visible="false">
        <pkg-ref id="com.quantumnova.vpn.client.pkg"/>
    </choice>
    <pkg-ref id="com.quantumnova.vpn.client.pkg" version="3.0.0" onConclusion="none" installKBytes="171672" updateKBytes="0">#QNovaClient-component.pkg</pkg-ref>
    <pkg-ref id="com.quantumnova.vpn.client.pkg">
        <bundle-version>
            <bundle CFBundleShortVersionString="3.0.0" CFBundleVersion="3.0.0" id="com.quantumnova.vpn.client" path="QNova Client.app"/>
            <bundle CFBundleShortVersionString="3.0.0" CFBundleVersion="3.0.0.20260902192913" id="com.quantumnova.vpn.client.tunnel" path="QNova Client.app/Contents/Library/SystemExtensions/com.quantumnova.vpn.client.tunnel.systemextension"/>
        </bundle-version>
    </pkg-ref>
</installer-gui-script>