A broken mobile release is already in production
“A severe bug shipped, but App Store and Play Store review may delay a replacement binary.”
THE PRINCIPLE
Recovery is a product capability. Ship kill switches, compatible runtime boundaries, staged rollouts, and rollback before the incident.
FIRST MOVES
- Disable the risky path with remote configuration if money or data is at risk.
- Determine whether the fix changes JavaScript/assets or native code.
- Test the exact OTA artifact against the production runtime and canary it.
- For native changes, submit a new binary and request expedited review while the mitigation remains active.
TOOLS: THEN → NOW
Microsoft App Center CodePushExpo EAS Update / expo-updates
Hard-coded feature availabilityRemote config and typed feature flags
PATTERN SNAPSHOT
// Runtime-compatible JS hotfix only.
await Updates.fetchUpdateAsync();
await Updates.reloadAsync();
// Native modules changed? Ship a new binary instead.CLOSE THE AI. EXPLAIN THIS.
Which kinds of fixes cannot safely be delivered as an OTA update, and why?Guide reviewed