[
  {
    "schema": "gowalk-cicd/apple-build-upload-failed.v2",
    "code": "processing_pending",
    "fixed_in": "1.0.164",
    "remedy": "Keep the original IPA and apple-build-upload receipt. If Apple later validates the exact upload, run reconcile_apple_upload.cjs in an authorized GitHub Actions recovery job with the original deployment, run, attempt and artifact receipt. It proves the failed owner, completed file, valid build and matching app before marking the deployment uploaded. Rerun the whole original deploy workflow after the readback; never upload a second binary or hand-edit the deployment receipt."
  },
  {
    "schema": "gowalk-cicd/mobile-release-refused.v1",
    "code": "mobile_release_phase_owner_mismatch",
    "fixed_in": "1.0.126",
    "remedy": "Inspect the release helper the workflow actually executes, including its immutable action snapshot. Before 1.0.126, a failed-jobs-only retry could retain an earlier admission attempt and refuse after rebuilding. If its receipt still says building, rerun the whole original workflow or adopt the released helper through a checked candidate. From 1.0.126 an earlier attempt of the same run, source and platform is supported, while begin-upload still requires building. A foreign run, source or platform remains refused. Preserve explicit task pins and app-specific inputs; never patch consumer ownership checks or relabel an ambiguous receipt."
  },
  {
    "schema": "gowalk-cicd/play-owner.v1",
    "code": "play_owner_busy",
    "fixed_in": "1.0.132",
    "remedy": "Read the package edit owner's current state through supported tooling and preserve unrelated work. The 1.0.132 package includes the 1.0.131 repair that records Android upload intent inside the acquired Play owner: adopt its action and workflow together, using mobileReleaseIntentScript instead of a separate Record Android upload intent step. A new owner refusal then leaves the release receipt building. Older workflows may already have marked uploading even though no provider call was attempted. That existing ambiguity still needs exact provider readback and supported recovery with the retained binary; neither elapsed time nor an owner refusal permits clearing the marker."
  },
  {
    "schema": "gowalk-cicd/mobile-release-refused.v1",
    "code": "mobile_release_upload_phase_unconfirmed",
    "fixed_in": "1.0.132",
    "remedy": "Read the original run, attempt and deployment receipt before retrying. A completed uploaded receipt is reused with its original evidence; finish its metadata and submission work. An uploading receipt is ambiguous even when a later owner refusal reports no provider attempt. Adopt the 1.0.132 action and workflow together to place future Android intent writes inside acquired Play ownership. For an existing receipt, prove the exact provider build/version or use supported retained-binary recovery; never relabel it building by hand or clear ownership on elapsed time."
  },
  {
    "schema": "gowalk-cicd/mobile-release-refused.v1",
    "code": "mobile_release_http_500",
    "fixed_in": "1.0.147",
    "remedy": "A GitHub receipt POST can persist uploading and still return HTTP 500 before the uploader executes; this proves neither an Apple upload nor a capacity limit. From 1.0.147 the helper reconciles its uniquely marked write by bounded readback without replaying the POST. Preserve the original run, attempt, binary and receipt if it still fails. recover_upload_intent.cjs owner/repo deployment-id plan|live restores an iOS intent only after fresh proof that its exact failed HTTP 500 intent step preceded an explicitly skipped uploader. Inspect the plan and live readback, then retry the original failed job. An executed uploader or uncertain evidence keeps the guard closed."
  },
  {
    "schema": "gowalk-cicd/mobile-release-refused.v1",
    "code": "mobile_release_intent_stale",
    "fixed_in": "1.0.160",
    "remedy": "From 1.0.160 a push changing .factory/releases/mobile.json admits the pushed tree for its declared platforms; upload and binary reuse keys come from the built tree and current build variables. Other events, including workflow_dispatch and newer-head retries, require the built tree to equal the last intent-changing commit's tree. Prepare and commit a new release intent on a task branch, land it through the required candidate checks, and follow that deployment. A dispatch of later source cannot substitute for the approved release. Legacy v1 intents are accepted; their stored source/configuration hashes no longer gate admission."
  }
]
