"""Publish fixed native failure evidence without moving private child output into annotations."""
import json
import sys

SIGNALS = {
    "pod_version_conflict": ("could not find compatible versions for pod", "Unable to satisfy the following requirements"),
    "pod_lock_drift": ("Podfile.lock", "deployment mode"),
    "ruby_version_incompatible": ("requires Ruby version", "Your Ruby version is"),
    "gem_missing": ("Could not find", "in locally installed gems"),
    "bundler_version_missing": ("Could not find 'bundler'",),
    "tls_verification": ("certificate verify failed", "CERTIFICATE_VERIFY_FAILED"),
    "connection_timeout": ("Connection timed out", "execution expired", "Read timed out"),
    # Distinct from tls_verification above: the peer never returned a verdict about its
    # certificate, the connection died mid-handshake. printer-ai run 34374868740
    # published signals=[] for `SSL_ERROR_SYSCALL in connection to github.com:443`
    # (2026-09-09), so the session read an unclassified failure and repaired the wrong
    # thing. Neither token appears in a certificate verdict.
    "tls_handshake_reset": ("SSL_ERROR_SYSCALL", "unexpected eof while reading"),
    "dns_resolution": ("Could not resolve host", "getaddrinfo"),
    "partial_transfer": ("curl 18", "curl: (18)"),
    "disk_full": ("No space left on device",),
}
ALL_REQUIRED = frozenset({"pod_lock_drift", "gem_missing"})
CODES = frozenset({
    "native_bundle_install_failed", "native_bundle_inputs_changed", "native_bundle_path_unverified",
    "native_bundle_operation_unverified", "native_configuration_failed", "native_google_proxy_required",
    "native_google_transport_helper_required", "native_pods_install_failed", "native_pods_operation_unverified",
    "native_pods_operation_interrupted", "native_pods_process_unverified", "native_podfile_lock_required",
    "native_podfile_lock_commit_required", "native_podfile_lock_changed", "native_gemfile_required",
    "native_gemfile_commit_required", "native_gemfile_lock_required", "native_gemfile_lock_commit_required",
    "native_workspace_reference_unverified", "native_project_generation_failed", "native_project_selection_required",
    "native_project_parse_unverified", "native_project_inventory_unverified", "native_project_inventory_missing",
    "native_package_proxy_transport_required", "native_initial_lock_phase_required",
})


def report(answer: dict, phase: str) -> None:
    if answer.get("ok"):
        return
    body = str(answer.get("diagnostic", ""))[-4000:]
    signals = sorted(name for name, patterns in SIGNALS.items()
                     if (all if name in ALL_REQUIRED else any)(part in body for part in patterns))
    code = answer.get("code")
    payload = {"schema": "gowalk-cicd/native-prepare-failed.v1",
               "phase": phase if phase in {"bundle", "pods"} else "unclassified",
               "code": code if code in CODES else "native_prepare_unclassified", "signals": signals}
    print("::error title=native_prepare_failed::" + json.dumps(payload, separators=(",", ":")),
          file=sys.stderr, flush=True)
