# store-ready: pickers and pre-flight detail

Read by `/multi-agent:store-ready` for Step 1 (branch fetch failure) and Step 2
(pre-flight checks and credential tiers). The command file keeps the rules; this
file holds the tables and commands they apply.

## Step 1: a failed `git fetch --prune`

Capture **stderr**. If the fetch fails, do not silently fall back to a cached ref,
and classify before naming a cause, the same rule as the pipeline's own remote gate:

| stderr contains | Cause | Remedy |
|---|---|---|
| `could not read Password`, `Authentication failed`, `403` | credential | store the PAT in the credential helper or switch the remote to SSH. **A VPN cannot fix this**, and the base ref being stale is unrelated to what broke  -  do not offer the cached-ref fallback. |
| `Could not resolve host`, `Operation timed out`, `Connection refused` | network | retry / continue on the cached ref with an explicit warning / switch remote / abort, per `$HOME/.claude/multi-agent-refs/rules.md` |
| `Repository not found`, `404` | wrong remote | show `git remote -v` and ask |

Always print the observed stderr line next to the classification. Asserting
`unreachable (VPN/DNS)` for a missing-credential error that returns in under a
second sends the user to fix something that was never broken.

## Step 2: iOS pre-flight

```bash
xcrun --find altool >/dev/null 2>&1 || echo "MISSING: altool (install Xcode)"
xcodebuild -version | head -1
```

Then resolve credentials, and **state which tier is active in the report**:

| Tier | Source | Effect |
|---|---|---|
| 1 | ASC API key  -  key id, issuer id and `.p8` in the Keychain (`appstore_connect_key_id`, `appstore_connect_issuer_id`, `appstore_connect_private_key`), read by the toolkit through the store reference file. `store_status` reports it as `appStoreConnect.configured` | Gate 2 runs; call `ios_testflight_validate` with neither `api_key_id` nor `apple_id` so it uses that key |
| 2 | Apple ID + app-specific password, referenced as a keychain item | Gate 2 runs |
| 3 | neither | **Gate 2 reports `SKIPPED`, and the run says so in the verdict line** |

Multi-provider accounts need `--provider-public-id`. When it is not in prefs, run
`ios_testflight_validate({list_providers: true})` once and ask which provider.

## Step 2: Android pre-flight

```bash
command -v bundletool >/dev/null || echo "MISSING: bundletool"
command -v aapt2      >/dev/null || echo "MISSING: aapt2 (Android SDK build-tools)"
command -v apksigner  >/dev/null || echo "MISSING: apksigner (Android SDK build-tools)"
```

The Gate 2 state table stays in the command file; say which state applies: a user
without the credential will go looking for one, and one with it needs to know why
Gate 2 did not run.
