Flip publish-win32-store back on (was a dummy skip), restore the store
variant build in build-win32, and wire the MSStore CLI submission:
- stable tags → production submission: msstore submission delete (clear
any pending, tolerant) then msstore publish <Store-*.msixbundle> -id.
- nightly tags → package flight ring: msstore flights submission delete
then msstore publish -f <flightId> -id. delete-then-replace so the
newest nightly always wins the single-slot submission queue (chosen
over skip-if-pending: always ship the newest, at the cost of cert
churn).
- Gate: runs for stable when MS_STORE_PRODUCT_ID is set; runs for
nightly only when MS_STORE_NIGHTLY_FLIGHT_ID is ALSO set, so the
flight ring stays off until the flight exists in Partner Center.
- The r2 staging loop archives the per-arch Store-*.msix again (and the
assembled universal bundle is archived by the store job).
Credentials (release-signing environment): MS_STORE_TENANT_ID,
MS_STORE_SELLER_ID, MS_STORE_CLIENT_ID, MS_STORE_CLIENT_SECRET
(secrets); MS_STORE_PRODUCT_ID, MS_STORE_NIGHTLY_FLIGHT_ID (vars).
Verified: yaml parses + needs graph resolves, store variant build
restored, bash branch harness (nightly→flight / stable→production)
executes the right msstore invocations, 215 js tests pass.