Conversation
CODE_SIGNING_ALLOWED=NO leaves a linker-signed slice the simulator keychain rejects with errSecMissingEntitlement (-34018) when the SDK saves bugseeDeviceId; capture then never reaches Launched while launch() still resolves true. Build with ad-hoc signing instead and re-sign embedded frameworks before install. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Deep code review — PR 44 (7c3b8a6)
Intent: Main’s ios e2e (simulator) (run 37102106116) built with CODE_SIGNING_ALLOWED=NO, left a linker-signed app, then logged Error saving key:bugseeDeviceId in keychain -34018. launch() resolved true and the suite never saw BUGSEE_E2E status=2. This PR ad-hoc signs the simulator build (CODE_SIGN_IDENTITY=-) and re-signs embedded frameworks plus the .app.
Reviewed against the surrounding CI job (erase + boot, Metro, launch.test.ts 10s Status.Launched budget), run-ios.sh / README device installs, and the example target (SUPPORTED_PLATFORMS = iphoneos iphonesimulator). I did not treat the diff in isolation.
What I actually checked
- Main failure log:
-34018onbugseeDeviceId, thenBUGSEE_E2E launch() resolved true, thennever saw "Status.Launched". - This PR’s
ios e2e (simulator)on run 37143953527: SUCCESS —Reach Status.Launchedran (placeholder-credentials step skipped, so the real token path ran) and went green. The signing change does fix the runner that failed. BugseeModule.mmlaunch:still resolves fromlaunchWithToken:andOptions:returning an instance; that matches the observedlaunch() true/ never-Launched split. Unchanged here, and correct not to change it in a CI-signing PR.- The
ioscompile job still usesCODE_SIGNING_ALLOWED=NOforgeneric/platform=iOS. That job never runs the app; leaving it unsigned is fine.
Findings
P2 Medium — CODE_SIGNING_REQUIRED = NO is not SDK-qualified
- Location:
examples/bare/ios/BareExample.xcodeproj/project.pbxproj(Debug ~262, Release ~294) - Problem: The target is installed on a real iPhone (
yarn device:ios, README SPM path). This setting is applied to every SDK, whileCODE_SIGN_IDENTITY=-is correctly limited tosdk=iphonesimulator*. - Impact / scenario / fix: See the inline comment. The CI post-sign script does not run on the device path.
No P0/P1. I am not filing the post-link codesign --force --sign - as a defect: on this runner it produced a process that reached Status.Launched, so a flags-only ad-hoc signature is sufficient for bugseeDeviceId here. --preserve-metadata=entitlements,identifier would still be cheaper insurance if Xcode did embed __TEXT,__entitlements / __ents_der and a later re-sign should not drop them.
1. Overall risk: Low
The change that unblocks main is proven on the same job that failed. The remaining issue is a project-setting scope error that can hit local device installs, not the CI path this PR is about.
2. Merge recommendation
Request changes for the pbxproj scope (one-line). After that, merge is safe. Do not wait on a second e2e theory — this SHA already reached Status.Launched on Actions.
3. Most important to fix
Scope CODE_SIGNING_REQUIRED to the simulator SDK (or drop it from the target and keep it only on the CI xcodebuild invocation).
4. Positives
- Diagnosis matches the failing main log exactly (
-34018→launch() true→ nostatus=2). - Simulator erase-before-boot stays in place; this PR does not replace a state-flake fix with signing.
- Nested re-sign is inside-out (
find -depthon frameworks/dylibs, then the.app) and uses--timestamp=none, which is correct for ad-hoc. - Library / consumer signing is untouched; only the example and the simulator e2e job change.
Sent by Cursor Automation: Bugsee code review
| buildSettings = { | ||
| ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon; | ||
| CLANG_ENABLE_MODULES = YES; | ||
| CODE_SIGNING_REQUIRED = NO; |
There was a problem hiding this comment.
P2 Medium — CODE_SIGNING_REQUIRED = NO applies to device builds too
Problem: This is set on the BareExample target for both Debug (here) and Release (line 294), with no sdk=iphonesimulator* condition. The same target has SUPPORTED_PLATFORMS = "iphoneos iphonesimulator". The simulator identity below is correctly qualified; this flag is not.
Impact: CODE_SIGNING_REQUIRED=NO is the setting whose purpose is to let the CodeSign phase skip. examples/bare/scripts/run-ios.sh and the README SPM device xcodebuild pass DEVELOPMENT_TEAM + CODE_SIGN_STYLE=Automatic but do not override CODE_SIGNING_REQUIRED. The CI post-sign (codesign --force --sign - on Debug-iphonesimulator/BareExample.app) never runs on those paths. An unsigned or linker-signed iphoneos .app is rejected by devicectl device install — the documented yarn device:ios / E2E_IOS_TARGET=device flow this example exists for.
Scenario: After this merges, yarn device:ios (or the README SPM xcodebuild -destination id=$IOS_DEVICE_ID ... CODE_SIGN_STYLE=Automatic) inherits CODE_SIGNING_REQUIRED=NO from the target. If the modern build system skips CodeSign because required is NO (or skips it when the generic project-level CODE_SIGN_IDENTITY[sdk=iphoneos*] = iPhone Developer does not resolve), install fails. Release is the same landmine for E2E_RELEASE=1.
Fix: Keep the simulator identity, drop the unscoped required flag from the target:
"CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-";
If a local no-team simulator build still needs it, qualify it the same way:
"CODE_SIGNING_REQUIRED[sdk=iphonesimulator*]" = NO;
The CI job can keep passing CODE_SIGNING_REQUIRED=NO on the xcodebuild command line; that does not change device installs.


Summary
CODE_SIGNING_ALLOWED=NO, which leaves a linker-signed app (flags=0x20002). On the failing main run the native SDK then loggedError saving key:bugseeDeviceId in keychain -34018andlaunch()resolved withoutStatus.Launched.CODE_SIGN_IDENTITY=-) and re-signs embedded frameworks and the app so the signature isflags=0x2. The example target sets the same simulator identity. TheStatus.Launchedassertion and its 10s budget are unchanged.-34018even with signing disabled. This CI run is the check that the signature change covers the runner that failed.Test plan
ios e2e (simulator)on this PR reachesBUGSEE_E2E status=2and does not log-34018launch.test.tspassed on iPhone 17 Pro6FA9B3E8-26C7-4232-AA2C-537D9DF32957withstatus=2in 110ms on the ad-hoc-signed buildMade with Cursor