Skip to content

fix(ci): ad-hoc sign the simulator e2e app - #44

Open
krassx wants to merge 1 commit into
mainfrom
fix/ios-sim-keychain-34018
Open

krassx wants to merge 1 commit into
mainfrom
fix/ios-sim-keychain-34018

Conversation

@krassx

@krassx krassx commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The iOS simulator e2e job built with CODE_SIGNING_ALLOWED=NO, which leaves a linker-signed app (flags=0x20002). On the failing main run the native SDK then logged Error saving key:bugseeDeviceId in keychain -34018 and launch() resolved without Status.Launched.
  • The e2e build now ad-hoc signs (CODE_SIGN_IDENTITY=-) and re-signs embedded frameworks and the app so the signature is flags=0x2. The example target sets the same simulator identity. The Status.Launched assertion and its 10s budget are unchanged.
  • A clean local simulator did not reproduce -34018 even with signing disabled. This CI run is the check that the signature change covers the runner that failed.

Test plan

  • ios e2e (simulator) on this PR reaches BUGSEE_E2E status=2 and does not log -34018
  • Local simulator: launch.test.ts passed on iPhone 17 Pro 6FA9B3E8-26C7-4232-AA2C-537D9DF32957 with status=2 in 110ms on the ad-hoc-signed build

Made with Cursor

CODE_SIGNING_ALLOWED=NO leaves a linker-signed slice the simulator keychain
rejects with errSecMissingEntitlement (-34018) when the SDK saves bugseeDeviceId;
capture then never reaches Launched while launch() still resolves true. Build
with ad-hoc signing instead and re-sign embedded frameworks before install.

Co-authored-by: Cursor <cursoragent@cursor.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deep code review — PR 44 (7c3b8a6)

Intent: Main’s ios e2e (simulator) (run 37102106116) built with CODE_SIGNING_ALLOWED=NO, left a linker-signed app, then logged Error saving key:bugseeDeviceId in keychain -34018. launch() resolved true and the suite never saw BUGSEE_E2E status=2. This PR ad-hoc signs the simulator build (CODE_SIGN_IDENTITY=-) and re-signs embedded frameworks plus the .app.

Reviewed against the surrounding CI job (erase + boot, Metro, launch.test.ts 10s Status.Launched budget), run-ios.sh / README device installs, and the example target (SUPPORTED_PLATFORMS = iphoneos iphonesimulator). I did not treat the diff in isolation.

What I actually checked

  • Main failure log: -34018 on bugseeDeviceId, then BUGSEE_E2E launch() resolved true, then never saw "Status.Launched".
  • This PR’s ios e2e (simulator) on run 37143953527: SUCCESS — Reach Status.Launched ran (placeholder-credentials step skipped, so the real token path ran) and went green. The signing change does fix the runner that failed.
  • BugseeModule.mm launch: still resolves from launchWithToken:andOptions: returning an instance; that matches the observed launch() true / never-Launched split. Unchanged here, and correct not to change it in a CI-signing PR.
  • The ios compile job still uses CODE_SIGNING_ALLOWED=NO for generic/platform=iOS. That job never runs the app; leaving it unsigned is fine.

Findings

P2 Medium — CODE_SIGNING_REQUIRED = NO is not SDK-qualified

  • Location: examples/bare/ios/BareExample.xcodeproj/project.pbxproj (Debug ~262, Release ~294)
  • Problem: The target is installed on a real iPhone (yarn device:ios, README SPM path). This setting is applied to every SDK, while CODE_SIGN_IDENTITY=- is correctly limited to sdk=iphonesimulator*.
  • Impact / scenario / fix: See the inline comment. The CI post-sign script does not run on the device path.

No P0/P1. I am not filing the post-link codesign --force --sign - as a defect: on this runner it produced a process that reached Status.Launched, so a flags-only ad-hoc signature is sufficient for bugseeDeviceId here. --preserve-metadata=entitlements,identifier would still be cheaper insurance if Xcode did embed __TEXT,__entitlements / __ents_der and a later re-sign should not drop them.


1. Overall risk: Low

The change that unblocks main is proven on the same job that failed. The remaining issue is a project-setting scope error that can hit local device installs, not the CI path this PR is about.

2. Merge recommendation

Request changes for the pbxproj scope (one-line). After that, merge is safe. Do not wait on a second e2e theory — this SHA already reached Status.Launched on Actions.

3. Most important to fix

Scope CODE_SIGNING_REQUIRED to the simulator SDK (or drop it from the target and keep it only on the CI xcodebuild invocation).

4. Positives

  • Diagnosis matches the failing main log exactly (-34018 → launch() true → no status=2).
  • Simulator erase-before-boot stays in place; this PR does not replace a state-flake fix with signing.
  • Nested re-sign is inside-out (find -depth on frameworks/dylibs, then the .app) and uses --timestamp=none, which is correct for ad-hoc.
  • Library / consumer signing is untouched; only the example and the simulator e2e job change.
Open in Web View Automation 

Sent by Cursor Automation: Bugsee code review

buildSettings = {
ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon;
CLANG_ENABLE_MODULES = YES;
CODE_SIGNING_REQUIRED = NO;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Medium — CODE_SIGNING_REQUIRED = NO applies to device builds too

Problem: This is set on the BareExample target for both Debug (here) and Release (line 294), with no sdk=iphonesimulator* condition. The same target has SUPPORTED_PLATFORMS = "iphoneos iphonesimulator". The simulator identity below is correctly qualified; this flag is not.

Impact: CODE_SIGNING_REQUIRED=NO is the setting whose purpose is to let the CodeSign phase skip. examples/bare/scripts/run-ios.sh and the README SPM device xcodebuild pass DEVELOPMENT_TEAM + CODE_SIGN_STYLE=Automatic but do not override CODE_SIGNING_REQUIRED. The CI post-sign (codesign --force --sign - on Debug-iphonesimulator/BareExample.app) never runs on those paths. An unsigned or linker-signed iphoneos .app is rejected by devicectl device install — the documented yarn device:ios / E2E_IOS_TARGET=device flow this example exists for.

Scenario: After this merges, yarn device:ios (or the README SPM xcodebuild -destination id=$IOS_DEVICE_ID ... CODE_SIGN_STYLE=Automatic) inherits CODE_SIGNING_REQUIRED=NO from the target. If the modern build system skips CodeSign because required is NO (or skips it when the generic project-level CODE_SIGN_IDENTITY[sdk=iphoneos*] = iPhone Developer does not resolve), install fails. Release is the same landmine for E2E_RELEASE=1.

Fix: Keep the simulator identity, drop the unscoped required flag from the target:

"CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-";

If a local no-team simulator build still needs it, qualify it the same way:

"CODE_SIGNING_REQUIRED[sdk=iphonesimulator*]" = NO;

The CI job can keep passing CODE_SIGNING_REQUIRED=NO on the xcodebuild command line; that does not change device installs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant