{
  "name": "VortX",
  "identifier": "tv.vortx.altstore",
  "subtitle": "Native streaming app for Apple, on stremio-core + libmpv.",
  "iconURL": "https://raw.githubusercontent.com/VortXTV/VortX/main/docs/logo.png",
  "website": "https://vortx.tv",
  "tintColor": "C8A24B",
  "apps": [
    {
      "name": "VortX",
      "bundleIdentifier": "com.stremiox.app.native",
      "developerName": "Mamaclapper",
      "subtitle": "Stream movies and shows on iPhone and iPad.",
      "localizedDescription": "VortX is a native, open-source streaming app for Apple devices, built on the official stremio-core engine and the libmpv player. Multi-profile, HDR and Dolby Vision, skip intro and outro, stream ranking, in-app add-ons and debrid keys, and more. Sideload-friendly: this source delivers one-tap updates so you never re-download an IPA by hand.",
      "iconURL": "https://raw.githubusercontent.com/VortXTV/VortX/main/docs/logo.png",
      "tintColor": "C8A24B",
      "category": "entertainment",
      "screenshotURLs": [],
      "versions": [
        {
          "version": "0.4.0",
          "buildVersion": "252",
          "date": "2026-09-27",
          "localizedDescription": "# 0.4.0 Beta 16 - Dolby Vision buffering, player switches, and next-episode recovery\n\n**Install this over any earlier Apple build.** Beta 16 focuses on playback failures reported in diagnostics 21-24: Dolby Vision production stopping, replacement sources opening on the wrong player surface, stalled next-episode recovery, and Apple TV going idle during a player handoff. Apple build **252**. All Beta 15 changes are retained; these packages are built afresh from the reviewed source, not an older beta executable.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages linked below.\n\n## What's fixed\n\n**Dolby Vision's local rolling buffer no longer gives the same capacity to both rewind history and forward loading.** Both sides previously budgeted against the entire publication allowance independently. Together with the still-advertised previous playlist, that could fill the physical spool and block the next segment from being published. The allocation is now shared, with room for a segment already being closed. Advertised video and subtitle resources keep their validity deadlines; the fix does not prematurely delete segments AVPlayer is still allowed to request.\n\n**AVPlayer's preferred buffer is coupled to what the DV producer can actually supply.** When bitrate is known, the target uses the forward allocation rather than the whole rolling window. Very high-bitrate sources no longer retain an unconditional minimum that can exceed the affordable lead. Unknown-bitrate sources retain their existing behavior until usable measurements arrive. This repairs an app-side producer/player mismatch, not a supposed TorBox outage.\n\n**Changing source or episode keeps the accepted player and the current stream.** A replacement accepted on VortX Player could previously clear fallback state and rebuild an AVPlayer surface using the original launch episode. Both Apple playback surfaces now retain the accepted engine. An explicit player switch uses the active URL, request headers and content hints, not stale launch values. The original source stays separate from any local proxy URL.\n\n**Apple TV stays awake through playback recovery and engine changes.** Idle prevention now follows your Play/Pause choice rather than temporary native pause notifications while buffering or falling back. An outgoing player view cannot release the incoming view's keep-awake ownership. Callbacks tagged for a retired load cannot overwrite the current load's pause or buffering state. An actual viewer pause still remains a pause.\n\n**An empty next-episode source gets one recovery owner instead of competing retry loops.** A prepared URL that produces no video packets is marked exhausted. Its exact load can accept a late-arriving alternative within the bounded settlement window, while conflicting startup and same-URL retry timers are retired. Duplicate errors or EOF callbacks cannot reopen that dead URL. Source changes, episode changes, cancellation and your pause choice still win. If no usable alternative arrives, the error replaces the reconnecting spinner rather than leaving it spinning indefinitely.\n\n**Resume recovery no longer fights itself or enters the manual-seek cache hold.** The ordinary stall watchdog waits while the exact deferred-resume recovery owns an unconfirmed resume. Recovery nudges use the resume-specific seek path and a confirmed position; they do not arm the separate manual-scrub refill watchdog. A valid Continue Watching persistence floor is retained. This targets the confirmed recovery conflict, not every possible late native seek callback.\n\n**Seek-preview contribution stops rechecking unchanged work on every playback tick.** The overnight diagnostic contained thousands of identical upload-admission checks without any new captured frames. An unchanged title now rechecks when duration first becomes known, when new coverage is captured, or during teardown. New titles keep their own initial check. This removes redundant work and keeps useful playback evidence from being buried in repeated preview messages; it does not claim every source now has previews available.\n\n**Diagnostics distinguish local spool capacity from a source-read stall.** A bounded receipt records physical storage accounting and companion-resource bytes when admission waits. It excludes source URLs, credentials and account identifiers. A read stall alone is not labeled as provider downtime.\n\n## Retained from Beta 15\n\nThe previous repairs remain: fresh-episode opening checks, larger next-episode warm-prefix acceptance, viewer-owned pause during source replacement, paused-DV playlist recovery, early-EOF protection, physical-item completion ownership, seek refill protection, exact Continue Watching detail targets, first-episode-to-season focus, supported native-text subtitle styling and redacted hardware-decoder diagnostics. See the [Beta 15 notes](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.15) for the full preceding change list.\n\n## Android\n\n**There is no new Android APK in Beta 16.** Full/MPV and Play/Media3 remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. This Apple cut does not claim new Android playback, sync or interface-parity work. The separately recorded rapid-title-selection and update-feed work remains open; use the matching signed Beta 14 APK directly.\n\n## Verification and remaining limits\n\nAll 18,757 lines of diagnostic 24 were read, alongside the previous diagnostics and a retrieved device log. The overnight capture includes roughly 55 minutes of healthy Debridio/VortX Player playback with hardware decoding and zero sampled output/decoder drops. It does not contain the initiating AIOStreams/AVPlayer failure, so it cannot establish that the two add-ons selected identical files or request paths.\n\nRegression checks cover the real spool and retained-resource deadlines, producer/buffer coupling, source and episode ownership, empty-source settlement, resume recovery, idle-owner replacement and preview admission. Independent reviewers inspected the actual changes. The release lane builds fresh packages and checks production engine provenance, simulator launch, package contents and update feeds before publishing.\n\n**These are concrete app-side repairs, not a declaration that every playback issue is gone.** Physical-TV testing of this build is still needed for long-running DV, AIOStreams player switches and next episodes. Unusually large segments can still encounter finite storage admission, and this release does not add an unbounded cache, force software decoding, replace DV with HDR10, or claim sustained NNTP throughput has been solved. The separate sync, phone/Mac redesign and Android parity backlog is not bundled into this playback release.\n\n## Please test\n\n- Play a DV title beyond several rolling-window advances, then pause, resume and seek backward and forward.\n- Switch between AVPlayer and VortX Player on an AIOStreams source. Confirm the same title, episode, position and your Play/Pause choice survive.\n- Start a series from Continue Watching and try both automatic advance and the next-episode button. Include a source that previously opened blank or remained reconnecting.\n- Leave playback running through an AVPlayer-to-VortX recovery beyond the TV's usual screensaver interval. Confirm the TV stays awake while video is playing.\n- If a failure remains, export the diagnostic shortly afterward so the initial cause is retained. Include the source/add-on and whether it followed pause, seek, an engine switch or an episode transition.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.16-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.16-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.16-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Use `VortX-macOS-v0.4.0-beta.16-ci.dmg`. This is the Apple Silicon package, ad-hoc signed rather than notarized. Follow the [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit and protected build provide provenance for these files. This beta is deliberately promoted to **Latest** with Apple update/install feeds verified during publication.\n\n<!-- vortx-build: 252 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.16/VortX-iOS-v0.4.0-beta.16-ci.ipa",
          "size": 65534888,
          "sha256": "5680d0212ac14392d25cd25cc829b6b622389432ac0ad30535402b730ad7300b",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "251",
          "date": "2026-09-12",
          "localizedDescription": "# 0.4.0 Beta 15 - Episode handoffs, paused Dolby Vision, and playback recovery\n\n**Install this over any earlier Apple build.** Beta 15 brings together the Apple playback work tested in local builds 248-250, plus a new guard for next episodes starting several seconds into the video. Apple build **251**. All Beta 14 changes are retained; no earlier executable or release package has been substituted.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages described below.\n\n## What's fixed\n\n**Next episodes no longer accept an unexpected multi-second opening as a normal start.** A device diagnostic showed a fresh episode committing at 4.046 seconds despite a zero resume point and auto-skip being off. The new check intercepts that first position before it can update the episode identity or watch progress, and makes one precise return to the opening on the already-running player. It does not restart the stream or change your pause state. Genuine resume points, live streams, and your own seeks stay in charge. If the correction cannot reach the opening, the app reports a source failure instead of quietly skipping ahead or repeatedly rewinding. This targets the observed next-episode handoff; the separate native decoder failure still needs device verification.\n\n**Next-episode preloading can retain the whole requested warm prefix.** The preloader requested the first 32 MiB but its response-size validator could reject that same valid response. The limit now matches the request. This removes a specific reason prepared streams were discarded and had to start cold; it is not a promise that every Usenet source can prepare instantly on every server.\n\n**Changing or recovering a source no longer introduces its own hidden Pause.** An implementation pause used while rejecting or retiring a source could survive an in-place player replacement, leaving the new source frozen despite having data. That synthetic pause is removed. An actual viewer pause is still preserved, but is bound only after the replacement is accepted. A failed retiring engine's paused flag does not get mistaken for your choice. Rejected replacements retain the current load's state.\n\n**A paused Dolby Vision stream can recover an expired local HLS playlist without skipping the episode or immediately falling back.** The device trace identified a real conflict: while paused, the bounded local producer stopped adding segments, and AVFoundation eventually rejected the unchanged growing playlist. One failure callback previously bypassed the existing paused-recovery path. It now keeps same-mount recovery evidence and waits for Play. Duplicate failure callbacks coalesce, and existing position, track-selection and DV restoration stay attached to the current item. No fake segments or unbounded producer buffer have been added.\n\n**A producer finishing while you are paused does not mean you finished watching.** Recovery now distinguishes the producer's final playlist from the viewer's actual position. A retained position inside that finished playlist can resume; a real end remains an end, and an invalid or evicted position remains a source error. Retry budgets only re-arm after sustained real playback, not seek jumps or paused ticks, preventing repeated item-replacement loops.\n\n**A stream ending early cannot casually mark the episode watched and play the next one.** Both Apple playback surfaces now compare a decoder's EOF against load-owned position and known duration. An EOF far before the ending enters same-episode source recovery instead of completion handling. Recovery uses observed playback position, not an optimistic scrub target or old resume floor. Duplicate EOF callbacks cannot spend the recovery budget twice. True endings, live playback, trailers and unknown-duration sources keep their existing semantics. This addresses the premature-completion code gap examined alongside issue #223.\n\n**Replacement items do not inherit the previous item's completion evidence.** AVPlayer can recover a physical item while retaining the logical playback request. Completion evidence now also follows the physical item generation, so an old early-EOF rejection cannot prevent the recovered item from genuinely finishing later. Retired callbacks cannot finish a newer episode.\n\n**Apple TV's short backward/forward seeks receive the same refill protection as a scrub.** A relative seek outside the buffered window previously missed the existing refill hold and bounded recovery watchdog. It now uses that protection while retaining relative seek semantics and your latest Pause/Play choice. In-buffer seeks do not unnecessarily invoke the cold-refill path.\n\n**Continue Watching keeps the episode you actually opened when it needs to show Details.** Local CW navigation on Apple TV and iPhone now carries the exact episode ID and resume point into the detail page. An episode with a zero resume point is still a valid selection; it does not fall back to an unwatched special such as S0E1. After you successfully play a newer episode, that newer local receipt supersedes the older navigation hint. If a partial episode list does not yet contain the exact target, the hero waits rather than inventing a different episode.\n\n**The phone's resume offset must belong to its selected episode.** The detail hero no longer applies an offset from one episode to a different selected episode. This matches the existing episode-identity check on Apple TV.\n\n**Up from the first episode returns to the selected season.** On Apple TV, that move now explicitly reveals and focuses the current season chip instead of jumping to the hero or making you navigate back down from Play. Down from the first episode still moves to the second; deeper episode rows retain their normal navigation.\n\n**Supported native AVPlayer WebVTT subtitles can follow the in-player appearance settings.** Their timed text can now use the existing VortX subtitle overlay, so outline, shaded and box styles are app-controlled. The native renderer is suppressed before supported text is displayed, and cues replace rather than accumulate. Seeks, subtitle changes, item replacements and close clear or fence stale cues. Unsupported or bitmap captions remain native; Picture in Picture and AirPlay retain native captions. This does not change the device's system caption settings or claim styling support for every subtitle format.\n\n**Diagnostics preserve useful decoder failure reasons without exporting raw decoder traffic.** Probe-enabled release builds now retain bounded, allowlisted VideoToolbox failure categories, including bad frame status, no-output callbacks, session/format failure and waiting for a keyframe. Signed stream links, request headers and arbitrary log text are excluded. This helps distinguish a native decoding failure from an output-frame drop or an empty network cache.\n\n## Android\n\n**There is no new Android APK in Beta 15.** The current Full/MPV and Play/Media3 packages remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. Their existing fixes are retained; this Apple release does not claim new Android playback or parity work.\n\nThe separately recorded Android rapid-title-selection race and Android update-feed correction remain open. Use the matching Beta 14 APK directly while that feed still serves the older entry.\n\n## Verification and remaining limits\n\nThe Apple completion, Continue Watching target, focus, resume/seek, source handoff, subtitle and diagnostic policies have executable regression coverage. Independent source review accompanies the changes; the release workflow builds and verifies fresh Apple packages, engine pins, signing/provenance and update feeds before publication.\n\nThe fresh-origin recovery was also exercised against the exact bundled GPL playback libraries with VideoToolbox, GPU-next/MoltenVK and AVFoundation audio. A controlled 4.046-second initial position returned to zero while playing and while paused, without changing the pause state. The matching source itself contains timestamps starting at zero.\n\n**These are specific repairs, not a claim that every playback problem is solved.** The physical Apple TV's initial hardware-decoder failure has not been reproduced on the Mac, and broader active-play DV stalls, provider-specific buffering and sustained NNTP throughput still need live-device testing. This release does not force software decoding, remove Dolby Vision, or disguise a failed source as a completed episode. The broader Android parity and phone/Mac redesign work is not bundled into this playback cut.\n\n## Please test\n\n- Let a series advance automatically and use the next-episode button. Confirm the opening is shown, the selected episode is correct, and watch progress belongs to that episode.\n- Pause a DV/AVPlayer title long enough for the local producer to stop filling, then resume. Confirm it stays paused until Play and recovers the same episode and selections.\n- Seek backward and forward both inside and outside the buffered window, including while paused.\n- Open Family Guy or another series from CW. If Details opens, confirm it targets the current episode instead of an unwatched special. From the first episode, press Up once to reach the season selector.\n- With supported built-in AVPlayer text subtitles, compare outline and box appearance. Include the subtitle format and a diagnostic if it remains native or ignores styling.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.15-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.15-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.15-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Download `VortX-macOS-v0.4.0-beta.15-ci.dmg`, drag VortX into Applications, and use **System Settings > Privacy & Security > Open Anyway** if needed. This is the Apple Silicon package, ad-hoc signed rather than notarized. [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit, and protected release workflow provide provenance for the published Apple files. This beta is deliberately promoted to **Latest**; Apple update and install feeds are verified as part of publication.\n\n<!-- vortx-build: 251 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.15/VortX-iOS-v0.4.0-beta.15-ci.ipa",
          "size": 65529125,
          "sha256": "7730fd8489c109e413bad11119f9f5b96ebee7b8bbb13b9f959d44c2b4e0c31d",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "247",
          "date": "2026-09-11",
          "localizedDescription": "Apple playback, source controls and episode artwork repairs; Android audio, remote, Discover and title-relation improvements; profile-specific collection visibility.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.14/VortX-iOS-v0.4.0-beta.14-ci.ipa",
          "size": 65500086,
          "sha256": "bc5d4af376778faea57e8d56983df7a1cd1954c00be0c2ea42af7fe1cc5d760b",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "245",
          "date": "2026-09-11",
          "localizedDescription": "Apple build 245: playback recovery, add-on order and sync, artwork, prioritized Usenet and NZB indexers.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.12/VortX-iOS-v0.4.0-beta.12-ci.ipa",
          "size": 65471776,
          "sha256": "bcb72cd2c722dad64b624e8bf03c22b9e363810a8953c612e3bec846c6291e2a",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "243",
          "date": "2026-09-06",
          "localizedDescription": "Apple Beta 10: Continue Watching episodes, pause and seek recovery, NNTP streaming repairs, and DV integrity checks.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.10/VortX-iOS-v0.4.0-beta.10-ci.ipa",
          "size": 65224079,
          "sha256": "4f8693b7bc4680a2b7777cfd6580bf89551774d9dbf4aa71835940720b09ab13",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "241",
          "date": "2026-09-05",
          "localizedDescription": "# 0.4.0 Beta 8 - Dolby Vision startup, Usenet playback, and safer episode recovery\n\n**Install this over any earlier Apple build.** Beta 8 focuses on the playback failures reported after Beta 2: Dolby Vision sources failing before the first picture, Usenet rows that would not start, and seek/recovery failures that could disrupt a binge session. This is an Apple-only beta, build 241. It retains Beta 2's fixes; Android and the broader sync and design work are reserved for the following beta.\n\n## What's fixed\n\nBetas 3-7 were held before publication for final integration, credential protection, and the last next-episode NNTP wiring correction. This is the next published Apple beta after Beta 2. They shipped no installable release assets. Beta 8 uses a new immutable tag for the combined source after Swift and security review.\n\n**A real cause of Dolby Vision startup failure is repaired.** Some HEVC files carry an incomplete container header and reveal their decoder setup inside the first video packet. VortX repaired that header but trusted the first provisional decode timestamp too early. The subsequent out-of-order timestamps made the MP4 writer reject the stream before it could publish a playable video segment. Startup now reads a bounded group of packets and repairs only the proven leading timestamp gap. Ordinary headers and established timestamps are left alone. This addresses the repeated remux failure captured in diagnostic 13 on Apple platforms.\n\n**The timestamp repair preserves the playable timeline.** Negative decode preroll remains in the muxed video where the decoder needs it, while the public HLS timeline starts at zero. A synthetic reproduction using the same shipped FFmpeg artifact now completes and decodes through Apple's video reader, with all 432 frames present in both the control and formerly failing cases. Audio and video retain their relative timing.\n\n**A dead remux no longer looks like healthy startup progress.** Once the current remux producer reports a terminal failure, its watchdog stops waiting on stale progress. Recovery acts on that exact item and source instead of spending another startup interval holding a stream that cannot produce a picture. This does not disable supported Dolby Vision or turn normal buffering into an automatic fallback.\n\n**A short placeholder cannot claim the next episode.** First-frame handling now checks the pending episode's stream evidence before committing its identity. An obviously mismatched short or undersized replacement is rejected before it can claim the requested episode. When incomplete evidence passes the existing bounded acceptance policy, the app consistently retires the old first-frame timeout instead of later abandoning a picture that already started.\n\n**Old recovery callbacks cannot take over a replacement player.** Delayed checks are fenced by the active controller, loaded item, and pending episode request on Apple TV and the shared iPhone, iPad, and Mac player. A callback belonging to a previous episode cannot finish or cancel the new episode's startup.\n\n**A seek-related false ending cannot silently become the next episode.** For the diagnosed mid-file EOF immediately following a seek, VortX Player now uses the duration captured before the seek and the current source's transport evidence. A qualifying single seek gets one bounded same-source reopen with its target retained. Missing or ambiguous evidence becomes a recoverable playback error, not a watched mark or an automatic episode change. Genuine near-end completion retains its normal path.\n\n**Rapid seeks fail safely instead of borrowing each other's callbacks.** When one seek supersedes another on the same source, untagged callbacks from the earlier seek cannot authorize a speculative reopen. The same protection covers a cache reanchor that replaces a pending viewer seek.\n\n**Play and Pause remain your decision during seek recovery.** A supported recovery preserves the latest explicit Play/Pause request, including a change made while the source is reopening. A new manual seek cancels the older recovery and releases its temporary forced pause rather than leaving the video parked.\n\n**Usenet playback reaches the correct embedded server.** Native NNTP playback now sends NZB control requests to the bundled Node server's actual discovered port, not the generic native media-server endpoint that does not implement that route. Explicit playback allows a short bounded startup wait while Node is becoming ready. Unsupported local-engine combinations no longer advertise a working local NZB route; TorBox's remote Usenet resolution remains available where configured.\n\n**Stremio-style NZB mirrors and server lists are retained.** Add-on responses can carry both `nzbUrl` and `nzbUrls`, plus an ordered `servers` list. These are preserved and validated before resolution. Add-on-provided NNTP servers keep their order. If their local setup fails, VortX tries the saved provider as a separate bounded attempt; it does not pool different accounts in parallel. Validated NZB mirrors also participate in cache lookup and source identity. This is compatibility for add-on-provided lists, not the separate multi-provider settings or NZB indexer feature.\n\n**NNTP now participates in Apple TV's next-episode preparation.** The TV preload gate previously skipped every raw NZB because it tested only for a cached torrent hash. It now admits NZBs into the same bounded local NNTP and TorBox resolver while keeping uncached torrents on their existing path. Next-episode preparation and cold advance on Apple TV, iPhone, iPad, and Mac also use the bounded Node readiness wait and the uncached Usenet preparation allowance, rather than treating every NZB like an instantly cached link. The overall preparation deadline and stale-episode cancellation remain in force.\n\n**Failed Usenet taps now explain themselves.** Explicit source selection distinguishes unavailable local support from an actual resolution failure, instead of silently returning without playing. Repeated Apple TV taps cannot launch overlapping NZB resolutions. A raw NZB descriptor is never handed to the video player as though it were media, and an unsupported NZB carrying torrent metadata cannot fall through into the torrent route.\n\n**The Node request contract is verified without exposing provider credentials.** The regression test exercises the real client's JSON POST, discovered port, returned key, and resulting stream URL through an injected session. Keys remain one opaque query value. Credential-bearing HTTP NZB descriptors are rejected before reaching Node, while NNTP credentials remain confined to the intended private local playback path. This test does not claim a live transfer from every Usenet provider.\n\n**TorBox Usenet requests now match its documented API.** NZB creation uses multipart form data rather than JSON. Both numeric and string download IDs are accepted. The download-link request supplies TorBox's documented, safely encoded token authentication; only the resulting validated playback URL reaches the player. Authenticated Usenet API calls now reject redirects entirely, preventing credentials from being forwarded to a redirect destination; ordinary media redirects are unchanged.\n\n**A failed local Usenet stream can try the next configured route for the same source.** The player retains whether a link came from the add-on's NNTP servers, your saved provider, or TorBox cloud. A later failure can move from add-on NNTP to the saved provider or cloud, or from saved NNTP to cloud, within the existing bounded recovery owner. It preserves the episode and resume/transport transaction, rejects stale callbacks, and does not loop back through routes already known to have failed.\n\n**Uncached NZB requests no longer use the cached-link five-second budget during a tap or episode transition.** User-selected NZBs and next-episode requests receive a bounded cloud preparation window matching the existing polling path; the next-episode pipeline still enforces its overall deadline. Cached-source fast paths retain their short budget. This does not turn an unavailable or still-downloading NZB into an instantly playable file.\n\n**NNTP hints are checked against the bundled downloader's actual parser.** Malformed server hints are rejected before they can throw inside Node. TLS schemes and credential delimiters are normalized without changing the credentials. Local requests are owned by the current account's cancellation/credential lease, so signing out cannot pass an old account's result into the new session.\n\n## Verification and please test\n\nThe targeted playback and episode-state tests, a real Apple TV simulator build, and the full existing remux/AVPlayer regression harness passed before release. The new empty-header reproduction was first observed failing in the production remux path, then passed after the timestamp repair and decoded all expected frames. The release is rebuilt from the exact tagged source by the protected Apple workflow; install feeds and artifact checksums are verified before publication.\n\n- Try the Dolby Vision title that failed in the previous beta, including starting from Continue Watching.\n- Pause, resume, seek backward, and use Next. A failed mid-file seek must not mark the episode finished or jump forward.\n- Try the Stremio NNTP/NZB source again, including an add-on-supplied server list. Full and Lite builds have different local-engine capabilities; an unsupported combination should now report that clearly.\n- Check long Dolby Vision playback and built-in subtitles. Beta 2's subtitle protections remain included, but diagnostic 13 did not establish a new duplicate-subtitle cause, and a synthetic decode test is not a physical Apple TV Dolby Vision continuity test.\n\nThis beta fixes the concrete failure mechanisms reproduced from the diagnostics and source audit. It is not a claim that every long-playback stall, provider failure, or display-specific HDR transition has been eliminated.\n\n## Android and the next beta\n\nAndroid is not attached to this Apple-only beta. Android playback and Apple-feature parity, cross-device sync and Stremio import, iPhone detail/source formatting, Mac redesign follow-up, and multi-server Usenet/NZB indexer settings remain on the follow-up plan. They are not being mixed into this playback hotfix.\n\n## Install\n\n**Mac (.dmg, easiest, never expires).** Download `VortX-macOS-v0.4.0-beta.8-ci.dmg` and drag VortX into Applications. For Apple's one-time quarantine prompt, open it once, click Done, then **System Settings > Privacy & Security > Open Anyway**. Full guide: **[Install on Mac](https://github.com/VortXTV/VortX/wiki/Install-on-Mac)**.\n\n**iPhone, iPad, Apple TV (sideload the IPA).** Download `VortX-iOS-v0.4.0-beta.8-ci.ipa`, `VortX-tvOS-v0.4.0-beta.8-ci.ipa`, or `VortX-tvOS-lite-v0.4.0-beta.8-ci.ipa`. The IPAs are unsigned and must be re-signed with Sideloadly, AltStore / SideStore, Signulous, or your preferred sideloading service. No jailbreak. Add the **[VortX AltStore / SideStore source](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json)** for updates. Full guide: **[Installing on iPhone, iPad, and Apple TV](https://github.com/VortXTV/VortX/wiki/Installing)**.\n\nThe release includes `SHA256SUMS-ci.txt` to verify the downloads produced by the public [GitHub Actions workflow](https://github.com/VortXTV/VortX/tree/main/.github/workflows). Android packages are intentionally not attached to this beta.\n\n<!-- vortx-build: 241 -->\n<!-- vortx-platforms: apple -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.8/VortX-iOS-v0.4.0-beta.8-ci.ipa",
          "size": 65196862,
          "sha256": "33c1a0558d0f39ae51e527d5cda3903114b8d36e3583344e3abf5aae4b823b2b",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "236",
          "date": "2026-09-05",
          "localizedDescription": "Apple Beta 2: pause/resume, Dolby Vision recovery, duplicate subtitles, source switching, Continue Watching and Mac settings.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.2/VortX-iOS-v0.4.0-beta.2-ci.ipa",
          "size": 65113674,
          "sha256": "f751a9c9a63e55e28e08a3304c4e8dcfb3e8cc0875fd676022661cb75d08c670",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "235",
          "date": "2026-09-03",
          "localizedDescription": "0.4 Beta 1: AVPlayer recovery and remux synchronization, episode focus, debrid refresh, update checks, subtitles and previews. Android TV parity is planned separately.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.1/VortX-iOS-v0.4.0-beta.1-ci.ipa",
          "size": 65011491,
          "sha256": "4133383241123add3ebe25cb94947326db1d18459edee7837c09275d4f186ffe",
          "minOSVersion": "16.0"
        }
      ]
    },
    {
      "name": "VortX (Apple TV)",
      "bundleIdentifier": "com.stremiox.tv",
      "developerName": "Mamaclapper",
      "subtitle": "Stream movies and shows on Apple TV.",
      "localizedDescription": "VortX for Apple TV: a native, open-source streaming app on the official stremio-core engine and the libmpv player, with an in-process streaming server for torrents. HDR and Dolby Vision, Dolby Atmos passthrough, stream ranking, in-app add-ons and debrid keys, Top Shelf, and more. This source delivers one-tap updates so you never sideload an IPA by hand.",
      "iconURL": "https://raw.githubusercontent.com/VortXTV/VortX/main/docs/logo.png",
      "tintColor": "C8A24B",
      "category": "entertainment",
      "screenshotURLs": [],
      "versions": [
        {
          "version": "0.4.0",
          "buildVersion": "252",
          "date": "2026-09-27",
          "localizedDescription": "# 0.4.0 Beta 16 - Dolby Vision buffering, player switches, and next-episode recovery\n\n**Install this over any earlier Apple build.** Beta 16 focuses on playback failures reported in diagnostics 21-24: Dolby Vision production stopping, replacement sources opening on the wrong player surface, stalled next-episode recovery, and Apple TV going idle during a player handoff. Apple build **252**. All Beta 15 changes are retained; these packages are built afresh from the reviewed source, not an older beta executable.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages linked below.\n\n## What's fixed\n\n**Dolby Vision's local rolling buffer no longer gives the same capacity to both rewind history and forward loading.** Both sides previously budgeted against the entire publication allowance independently. Together with the still-advertised previous playlist, that could fill the physical spool and block the next segment from being published. The allocation is now shared, with room for a segment already being closed. Advertised video and subtitle resources keep their validity deadlines; the fix does not prematurely delete segments AVPlayer is still allowed to request.\n\n**AVPlayer's preferred buffer is coupled to what the DV producer can actually supply.** When bitrate is known, the target uses the forward allocation rather than the whole rolling window. Very high-bitrate sources no longer retain an unconditional minimum that can exceed the affordable lead. Unknown-bitrate sources retain their existing behavior until usable measurements arrive. This repairs an app-side producer/player mismatch, not a supposed TorBox outage.\n\n**Changing source or episode keeps the accepted player and the current stream.** A replacement accepted on VortX Player could previously clear fallback state and rebuild an AVPlayer surface using the original launch episode. Both Apple playback surfaces now retain the accepted engine. An explicit player switch uses the active URL, request headers and content hints, not stale launch values. The original source stays separate from any local proxy URL.\n\n**Apple TV stays awake through playback recovery and engine changes.** Idle prevention now follows your Play/Pause choice rather than temporary native pause notifications while buffering or falling back. An outgoing player view cannot release the incoming view's keep-awake ownership. Callbacks tagged for a retired load cannot overwrite the current load's pause or buffering state. An actual viewer pause still remains a pause.\n\n**An empty next-episode source gets one recovery owner instead of competing retry loops.** A prepared URL that produces no video packets is marked exhausted. Its exact load can accept a late-arriving alternative within the bounded settlement window, while conflicting startup and same-URL retry timers are retired. Duplicate errors or EOF callbacks cannot reopen that dead URL. Source changes, episode changes, cancellation and your pause choice still win. If no usable alternative arrives, the error replaces the reconnecting spinner rather than leaving it spinning indefinitely.\n\n**Resume recovery no longer fights itself or enters the manual-seek cache hold.** The ordinary stall watchdog waits while the exact deferred-resume recovery owns an unconfirmed resume. Recovery nudges use the resume-specific seek path and a confirmed position; they do not arm the separate manual-scrub refill watchdog. A valid Continue Watching persistence floor is retained. This targets the confirmed recovery conflict, not every possible late native seek callback.\n\n**Seek-preview contribution stops rechecking unchanged work on every playback tick.** The overnight diagnostic contained thousands of identical upload-admission checks without any new captured frames. An unchanged title now rechecks when duration first becomes known, when new coverage is captured, or during teardown. New titles keep their own initial check. This removes redundant work and keeps useful playback evidence from being buried in repeated preview messages; it does not claim every source now has previews available.\n\n**Diagnostics distinguish local spool capacity from a source-read stall.** A bounded receipt records physical storage accounting and companion-resource bytes when admission waits. It excludes source URLs, credentials and account identifiers. A read stall alone is not labeled as provider downtime.\n\n## Retained from Beta 15\n\nThe previous repairs remain: fresh-episode opening checks, larger next-episode warm-prefix acceptance, viewer-owned pause during source replacement, paused-DV playlist recovery, early-EOF protection, physical-item completion ownership, seek refill protection, exact Continue Watching detail targets, first-episode-to-season focus, supported native-text subtitle styling and redacted hardware-decoder diagnostics. See the [Beta 15 notes](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.15) for the full preceding change list.\n\n## Android\n\n**There is no new Android APK in Beta 16.** Full/MPV and Play/Media3 remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. This Apple cut does not claim new Android playback, sync or interface-parity work. The separately recorded rapid-title-selection and update-feed work remains open; use the matching signed Beta 14 APK directly.\n\n## Verification and remaining limits\n\nAll 18,757 lines of diagnostic 24 were read, alongside the previous diagnostics and a retrieved device log. The overnight capture includes roughly 55 minutes of healthy Debridio/VortX Player playback with hardware decoding and zero sampled output/decoder drops. It does not contain the initiating AIOStreams/AVPlayer failure, so it cannot establish that the two add-ons selected identical files or request paths.\n\nRegression checks cover the real spool and retained-resource deadlines, producer/buffer coupling, source and episode ownership, empty-source settlement, resume recovery, idle-owner replacement and preview admission. Independent reviewers inspected the actual changes. The release lane builds fresh packages and checks production engine provenance, simulator launch, package contents and update feeds before publishing.\n\n**These are concrete app-side repairs, not a declaration that every playback issue is gone.** Physical-TV testing of this build is still needed for long-running DV, AIOStreams player switches and next episodes. Unusually large segments can still encounter finite storage admission, and this release does not add an unbounded cache, force software decoding, replace DV with HDR10, or claim sustained NNTP throughput has been solved. The separate sync, phone/Mac redesign and Android parity backlog is not bundled into this playback release.\n\n## Please test\n\n- Play a DV title beyond several rolling-window advances, then pause, resume and seek backward and forward.\n- Switch between AVPlayer and VortX Player on an AIOStreams source. Confirm the same title, episode, position and your Play/Pause choice survive.\n- Start a series from Continue Watching and try both automatic advance and the next-episode button. Include a source that previously opened blank or remained reconnecting.\n- Leave playback running through an AVPlayer-to-VortX recovery beyond the TV's usual screensaver interval. Confirm the TV stays awake while video is playing.\n- If a failure remains, export the diagnostic shortly afterward so the initial cause is retained. Include the source/add-on and whether it followed pause, seek, an engine switch or an episode transition.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.16-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.16-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.16-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Use `VortX-macOS-v0.4.0-beta.16-ci.dmg`. This is the Apple Silicon package, ad-hoc signed rather than notarized. Follow the [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit and protected build provide provenance for these files. This beta is deliberately promoted to **Latest** with Apple update/install feeds verified during publication.\n\n<!-- vortx-build: 252 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.16/VortX-tvOS-v0.4.0-beta.16-ci.ipa",
          "size": 65128621,
          "sha256": "4ede3e867cfbbe77cb42893966b4c894724c1655aeeee0775c253e13a2403938",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "251",
          "date": "2026-09-12",
          "localizedDescription": "# 0.4.0 Beta 15 - Episode handoffs, paused Dolby Vision, and playback recovery\n\n**Install this over any earlier Apple build.** Beta 15 brings together the Apple playback work tested in local builds 248-250, plus a new guard for next episodes starting several seconds into the video. Apple build **251**. All Beta 14 changes are retained; no earlier executable or release package has been substituted.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages described below.\n\n## What's fixed\n\n**Next episodes no longer accept an unexpected multi-second opening as a normal start.** A device diagnostic showed a fresh episode committing at 4.046 seconds despite a zero resume point and auto-skip being off. The new check intercepts that first position before it can update the episode identity or watch progress, and makes one precise return to the opening on the already-running player. It does not restart the stream or change your pause state. Genuine resume points, live streams, and your own seeks stay in charge. If the correction cannot reach the opening, the app reports a source failure instead of quietly skipping ahead or repeatedly rewinding. This targets the observed next-episode handoff; the separate native decoder failure still needs device verification.\n\n**Next-episode preloading can retain the whole requested warm prefix.** The preloader requested the first 32 MiB but its response-size validator could reject that same valid response. The limit now matches the request. This removes a specific reason prepared streams were discarded and had to start cold; it is not a promise that every Usenet source can prepare instantly on every server.\n\n**Changing or recovering a source no longer introduces its own hidden Pause.** An implementation pause used while rejecting or retiring a source could survive an in-place player replacement, leaving the new source frozen despite having data. That synthetic pause is removed. An actual viewer pause is still preserved, but is bound only after the replacement is accepted. A failed retiring engine's paused flag does not get mistaken for your choice. Rejected replacements retain the current load's state.\n\n**A paused Dolby Vision stream can recover an expired local HLS playlist without skipping the episode or immediately falling back.** The device trace identified a real conflict: while paused, the bounded local producer stopped adding segments, and AVFoundation eventually rejected the unchanged growing playlist. One failure callback previously bypassed the existing paused-recovery path. It now keeps same-mount recovery evidence and waits for Play. Duplicate failure callbacks coalesce, and existing position, track-selection and DV restoration stay attached to the current item. No fake segments or unbounded producer buffer have been added.\n\n**A producer finishing while you are paused does not mean you finished watching.** Recovery now distinguishes the producer's final playlist from the viewer's actual position. A retained position inside that finished playlist can resume; a real end remains an end, and an invalid or evicted position remains a source error. Retry budgets only re-arm after sustained real playback, not seek jumps or paused ticks, preventing repeated item-replacement loops.\n\n**A stream ending early cannot casually mark the episode watched and play the next one.** Both Apple playback surfaces now compare a decoder's EOF against load-owned position and known duration. An EOF far before the ending enters same-episode source recovery instead of completion handling. Recovery uses observed playback position, not an optimistic scrub target or old resume floor. Duplicate EOF callbacks cannot spend the recovery budget twice. True endings, live playback, trailers and unknown-duration sources keep their existing semantics. This addresses the premature-completion code gap examined alongside issue #223.\n\n**Replacement items do not inherit the previous item's completion evidence.** AVPlayer can recover a physical item while retaining the logical playback request. Completion evidence now also follows the physical item generation, so an old early-EOF rejection cannot prevent the recovered item from genuinely finishing later. Retired callbacks cannot finish a newer episode.\n\n**Apple TV's short backward/forward seeks receive the same refill protection as a scrub.** A relative seek outside the buffered window previously missed the existing refill hold and bounded recovery watchdog. It now uses that protection while retaining relative seek semantics and your latest Pause/Play choice. In-buffer seeks do not unnecessarily invoke the cold-refill path.\n\n**Continue Watching keeps the episode you actually opened when it needs to show Details.** Local CW navigation on Apple TV and iPhone now carries the exact episode ID and resume point into the detail page. An episode with a zero resume point is still a valid selection; it does not fall back to an unwatched special such as S0E1. After you successfully play a newer episode, that newer local receipt supersedes the older navigation hint. If a partial episode list does not yet contain the exact target, the hero waits rather than inventing a different episode.\n\n**The phone's resume offset must belong to its selected episode.** The detail hero no longer applies an offset from one episode to a different selected episode. This matches the existing episode-identity check on Apple TV.\n\n**Up from the first episode returns to the selected season.** On Apple TV, that move now explicitly reveals and focuses the current season chip instead of jumping to the hero or making you navigate back down from Play. Down from the first episode still moves to the second; deeper episode rows retain their normal navigation.\n\n**Supported native AVPlayer WebVTT subtitles can follow the in-player appearance settings.** Their timed text can now use the existing VortX subtitle overlay, so outline, shaded and box styles are app-controlled. The native renderer is suppressed before supported text is displayed, and cues replace rather than accumulate. Seeks, subtitle changes, item replacements and close clear or fence stale cues. Unsupported or bitmap captions remain native; Picture in Picture and AirPlay retain native captions. This does not change the device's system caption settings or claim styling support for every subtitle format.\n\n**Diagnostics preserve useful decoder failure reasons without exporting raw decoder traffic.** Probe-enabled release builds now retain bounded, allowlisted VideoToolbox failure categories, including bad frame status, no-output callbacks, session/format failure and waiting for a keyframe. Signed stream links, request headers and arbitrary log text are excluded. This helps distinguish a native decoding failure from an output-frame drop or an empty network cache.\n\n## Android\n\n**There is no new Android APK in Beta 15.** The current Full/MPV and Play/Media3 packages remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. Their existing fixes are retained; this Apple release does not claim new Android playback or parity work.\n\nThe separately recorded Android rapid-title-selection race and Android update-feed correction remain open. Use the matching Beta 14 APK directly while that feed still serves the older entry.\n\n## Verification and remaining limits\n\nThe Apple completion, Continue Watching target, focus, resume/seek, source handoff, subtitle and diagnostic policies have executable regression coverage. Independent source review accompanies the changes; the release workflow builds and verifies fresh Apple packages, engine pins, signing/provenance and update feeds before publication.\n\nThe fresh-origin recovery was also exercised against the exact bundled GPL playback libraries with VideoToolbox, GPU-next/MoltenVK and AVFoundation audio. A controlled 4.046-second initial position returned to zero while playing and while paused, without changing the pause state. The matching source itself contains timestamps starting at zero.\n\n**These are specific repairs, not a claim that every playback problem is solved.** The physical Apple TV's initial hardware-decoder failure has not been reproduced on the Mac, and broader active-play DV stalls, provider-specific buffering and sustained NNTP throughput still need live-device testing. This release does not force software decoding, remove Dolby Vision, or disguise a failed source as a completed episode. The broader Android parity and phone/Mac redesign work is not bundled into this playback cut.\n\n## Please test\n\n- Let a series advance automatically and use the next-episode button. Confirm the opening is shown, the selected episode is correct, and watch progress belongs to that episode.\n- Pause a DV/AVPlayer title long enough for the local producer to stop filling, then resume. Confirm it stays paused until Play and recovers the same episode and selections.\n- Seek backward and forward both inside and outside the buffered window, including while paused.\n- Open Family Guy or another series from CW. If Details opens, confirm it targets the current episode instead of an unwatched special. From the first episode, press Up once to reach the season selector.\n- With supported built-in AVPlayer text subtitles, compare outline and box appearance. Include the subtitle format and a diagnostic if it remains native or ignores styling.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.15-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.15-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.15-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Download `VortX-macOS-v0.4.0-beta.15-ci.dmg`, drag VortX into Applications, and use **System Settings > Privacy & Security > Open Anyway** if needed. This is the Apple Silicon package, ad-hoc signed rather than notarized. [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit, and protected release workflow provide provenance for the published Apple files. This beta is deliberately promoted to **Latest**; Apple update and install feeds are verified as part of publication.\n\n<!-- vortx-build: 251 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.15/VortX-tvOS-v0.4.0-beta.15-ci.ipa",
          "size": 65096502,
          "sha256": "8cd42c3b1f48290c42090e6b771712e30e97017b4374cb8cd6b6beeb7ac57585",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "247",
          "date": "2026-09-11",
          "localizedDescription": "Apple playback, source controls and episode artwork repairs; Android audio, remote, Discover and title-relation improvements; profile-specific collection visibility.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.14/VortX-tvOS-v0.4.0-beta.14-ci.ipa",
          "size": 65060961,
          "sha256": "bade529bf77d30b5dbf769680769a0c2925e5f9f1679d21fb8a0a9ec1128318c",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "245",
          "date": "2026-09-11",
          "localizedDescription": "Apple build 245: playback recovery, add-on order and sync, artwork, prioritized Usenet and NZB indexers.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.12/VortX-tvOS-v0.4.0-beta.12-ci.ipa",
          "size": 65031315,
          "sha256": "5d33893b6d6a839b52919fb7083516d53e4c51686a00c5c7c71c21cd0b4c8bcc",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "243",
          "date": "2026-09-06",
          "localizedDescription": "Apple Beta 10: Continue Watching episodes, pause and seek recovery, NNTP streaming repairs, and DV integrity checks.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.10/VortX-tvOS-v0.4.0-beta.10-ci.ipa",
          "size": 64777413,
          "sha256": "bd1679b990c729fb2570459fb0e05d2a07abf0892dd75237d7e4d8d81c05d7ad",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "241",
          "date": "2026-09-05",
          "localizedDescription": "# 0.4.0 Beta 8 - Dolby Vision startup, Usenet playback, and safer episode recovery\n\n**Install this over any earlier Apple build.** Beta 8 focuses on the playback failures reported after Beta 2: Dolby Vision sources failing before the first picture, Usenet rows that would not start, and seek/recovery failures that could disrupt a binge session. This is an Apple-only beta, build 241. It retains Beta 2's fixes; Android and the broader sync and design work are reserved for the following beta.\n\n## What's fixed\n\nBetas 3-7 were held before publication for final integration, credential protection, and the last next-episode NNTP wiring correction. This is the next published Apple beta after Beta 2. They shipped no installable release assets. Beta 8 uses a new immutable tag for the combined source after Swift and security review.\n\n**A real cause of Dolby Vision startup failure is repaired.** Some HEVC files carry an incomplete container header and reveal their decoder setup inside the first video packet. VortX repaired that header but trusted the first provisional decode timestamp too early. The subsequent out-of-order timestamps made the MP4 writer reject the stream before it could publish a playable video segment. Startup now reads a bounded group of packets and repairs only the proven leading timestamp gap. Ordinary headers and established timestamps are left alone. This addresses the repeated remux failure captured in diagnostic 13 on Apple platforms.\n\n**The timestamp repair preserves the playable timeline.** Negative decode preroll remains in the muxed video where the decoder needs it, while the public HLS timeline starts at zero. A synthetic reproduction using the same shipped FFmpeg artifact now completes and decodes through Apple's video reader, with all 432 frames present in both the control and formerly failing cases. Audio and video retain their relative timing.\n\n**A dead remux no longer looks like healthy startup progress.** Once the current remux producer reports a terminal failure, its watchdog stops waiting on stale progress. Recovery acts on that exact item and source instead of spending another startup interval holding a stream that cannot produce a picture. This does not disable supported Dolby Vision or turn normal buffering into an automatic fallback.\n\n**A short placeholder cannot claim the next episode.** First-frame handling now checks the pending episode's stream evidence before committing its identity. An obviously mismatched short or undersized replacement is rejected before it can claim the requested episode. When incomplete evidence passes the existing bounded acceptance policy, the app consistently retires the old first-frame timeout instead of later abandoning a picture that already started.\n\n**Old recovery callbacks cannot take over a replacement player.** Delayed checks are fenced by the active controller, loaded item, and pending episode request on Apple TV and the shared iPhone, iPad, and Mac player. A callback belonging to a previous episode cannot finish or cancel the new episode's startup.\n\n**A seek-related false ending cannot silently become the next episode.** For the diagnosed mid-file EOF immediately following a seek, VortX Player now uses the duration captured before the seek and the current source's transport evidence. A qualifying single seek gets one bounded same-source reopen with its target retained. Missing or ambiguous evidence becomes a recoverable playback error, not a watched mark or an automatic episode change. Genuine near-end completion retains its normal path.\n\n**Rapid seeks fail safely instead of borrowing each other's callbacks.** When one seek supersedes another on the same source, untagged callbacks from the earlier seek cannot authorize a speculative reopen. The same protection covers a cache reanchor that replaces a pending viewer seek.\n\n**Play and Pause remain your decision during seek recovery.** A supported recovery preserves the latest explicit Play/Pause request, including a change made while the source is reopening. A new manual seek cancels the older recovery and releases its temporary forced pause rather than leaving the video parked.\n\n**Usenet playback reaches the correct embedded server.** Native NNTP playback now sends NZB control requests to the bundled Node server's actual discovered port, not the generic native media-server endpoint that does not implement that route. Explicit playback allows a short bounded startup wait while Node is becoming ready. Unsupported local-engine combinations no longer advertise a working local NZB route; TorBox's remote Usenet resolution remains available where configured.\n\n**Stremio-style NZB mirrors and server lists are retained.** Add-on responses can carry both `nzbUrl` and `nzbUrls`, plus an ordered `servers` list. These are preserved and validated before resolution. Add-on-provided NNTP servers keep their order. If their local setup fails, VortX tries the saved provider as a separate bounded attempt; it does not pool different accounts in parallel. Validated NZB mirrors also participate in cache lookup and source identity. This is compatibility for add-on-provided lists, not the separate multi-provider settings or NZB indexer feature.\n\n**NNTP now participates in Apple TV's next-episode preparation.** The TV preload gate previously skipped every raw NZB because it tested only for a cached torrent hash. It now admits NZBs into the same bounded local NNTP and TorBox resolver while keeping uncached torrents on their existing path. Next-episode preparation and cold advance on Apple TV, iPhone, iPad, and Mac also use the bounded Node readiness wait and the uncached Usenet preparation allowance, rather than treating every NZB like an instantly cached link. The overall preparation deadline and stale-episode cancellation remain in force.\n\n**Failed Usenet taps now explain themselves.** Explicit source selection distinguishes unavailable local support from an actual resolution failure, instead of silently returning without playing. Repeated Apple TV taps cannot launch overlapping NZB resolutions. A raw NZB descriptor is never handed to the video player as though it were media, and an unsupported NZB carrying torrent metadata cannot fall through into the torrent route.\n\n**The Node request contract is verified without exposing provider credentials.** The regression test exercises the real client's JSON POST, discovered port, returned key, and resulting stream URL through an injected session. Keys remain one opaque query value. Credential-bearing HTTP NZB descriptors are rejected before reaching Node, while NNTP credentials remain confined to the intended private local playback path. This test does not claim a live transfer from every Usenet provider.\n\n**TorBox Usenet requests now match its documented API.** NZB creation uses multipart form data rather than JSON. Both numeric and string download IDs are accepted. The download-link request supplies TorBox's documented, safely encoded token authentication; only the resulting validated playback URL reaches the player. Authenticated Usenet API calls now reject redirects entirely, preventing credentials from being forwarded to a redirect destination; ordinary media redirects are unchanged.\n\n**A failed local Usenet stream can try the next configured route for the same source.** The player retains whether a link came from the add-on's NNTP servers, your saved provider, or TorBox cloud. A later failure can move from add-on NNTP to the saved provider or cloud, or from saved NNTP to cloud, within the existing bounded recovery owner. It preserves the episode and resume/transport transaction, rejects stale callbacks, and does not loop back through routes already known to have failed.\n\n**Uncached NZB requests no longer use the cached-link five-second budget during a tap or episode transition.** User-selected NZBs and next-episode requests receive a bounded cloud preparation window matching the existing polling path; the next-episode pipeline still enforces its overall deadline. Cached-source fast paths retain their short budget. This does not turn an unavailable or still-downloading NZB into an instantly playable file.\n\n**NNTP hints are checked against the bundled downloader's actual parser.** Malformed server hints are rejected before they can throw inside Node. TLS schemes and credential delimiters are normalized without changing the credentials. Local requests are owned by the current account's cancellation/credential lease, so signing out cannot pass an old account's result into the new session.\n\n## Verification and please test\n\nThe targeted playback and episode-state tests, a real Apple TV simulator build, and the full existing remux/AVPlayer regression harness passed before release. The new empty-header reproduction was first observed failing in the production remux path, then passed after the timestamp repair and decoded all expected frames. The release is rebuilt from the exact tagged source by the protected Apple workflow; install feeds and artifact checksums are verified before publication.\n\n- Try the Dolby Vision title that failed in the previous beta, including starting from Continue Watching.\n- Pause, resume, seek backward, and use Next. A failed mid-file seek must not mark the episode finished or jump forward.\n- Try the Stremio NNTP/NZB source again, including an add-on-supplied server list. Full and Lite builds have different local-engine capabilities; an unsupported combination should now report that clearly.\n- Check long Dolby Vision playback and built-in subtitles. Beta 2's subtitle protections remain included, but diagnostic 13 did not establish a new duplicate-subtitle cause, and a synthetic decode test is not a physical Apple TV Dolby Vision continuity test.\n\nThis beta fixes the concrete failure mechanisms reproduced from the diagnostics and source audit. It is not a claim that every long-playback stall, provider failure, or display-specific HDR transition has been eliminated.\n\n## Android and the next beta\n\nAndroid is not attached to this Apple-only beta. Android playback and Apple-feature parity, cross-device sync and Stremio import, iPhone detail/source formatting, Mac redesign follow-up, and multi-server Usenet/NZB indexer settings remain on the follow-up plan. They are not being mixed into this playback hotfix.\n\n## Install\n\n**Mac (.dmg, easiest, never expires).** Download `VortX-macOS-v0.4.0-beta.8-ci.dmg` and drag VortX into Applications. For Apple's one-time quarantine prompt, open it once, click Done, then **System Settings > Privacy & Security > Open Anyway**. Full guide: **[Install on Mac](https://github.com/VortXTV/VortX/wiki/Install-on-Mac)**.\n\n**iPhone, iPad, Apple TV (sideload the IPA).** Download `VortX-iOS-v0.4.0-beta.8-ci.ipa`, `VortX-tvOS-v0.4.0-beta.8-ci.ipa`, or `VortX-tvOS-lite-v0.4.0-beta.8-ci.ipa`. The IPAs are unsigned and must be re-signed with Sideloadly, AltStore / SideStore, Signulous, or your preferred sideloading service. No jailbreak. Add the **[VortX AltStore / SideStore source](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json)** for updates. Full guide: **[Installing on iPhone, iPad, and Apple TV](https://github.com/VortXTV/VortX/wiki/Installing)**.\n\nThe release includes `SHA256SUMS-ci.txt` to verify the downloads produced by the public [GitHub Actions workflow](https://github.com/VortXTV/VortX/tree/main/.github/workflows). Android packages are intentionally not attached to this beta.\n\n<!-- vortx-build: 241 -->\n<!-- vortx-platforms: apple -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.8/VortX-tvOS-v0.4.0-beta.8-ci.ipa",
          "size": 64758491,
          "sha256": "74f18bcb83a32d4652b46784b9608b084164bc90d82362f5a29ad64c74cdf9a5",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "236",
          "date": "2026-09-05",
          "localizedDescription": "Apple Beta 2: pause/resume, Dolby Vision recovery, duplicate subtitles, source switching, Continue Watching and Mac settings.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.2/VortX-tvOS-v0.4.0-beta.2-ci.ipa",
          "size": 64678475,
          "sha256": "b6b202bb2dbf9e29f856d126ee7372b8f591e6b8d2a520d8c57e9a57ee0d0c33",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "235",
          "date": "2026-09-03",
          "localizedDescription": "0.4 Beta 1: AVPlayer recovery and remux synchronization, episode focus, debrid refresh, update checks, subtitles and previews. Android TV parity is planned separately.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.1/VortX-tvOS-v0.4.0-beta.1-ci.ipa",
          "size": 64593483,
          "sha256": "82749f93f67210b96f0bb6ab8d4f7c3b09365c2148c6cc84333e059ed21e1dfb",
          "minOSVersion": "18.0"
        }
      ]
    }
  ],
  "news": []
}
