From 7c3b8a6f12694547b368c61e9dfc19a26af79d29 Mon Sep 17 00:00:00 2001 From: Alexey Karimov Date: Sat, 3 Oct 2026 23:20:18 +0500 Subject: [PATCH 1/2] fix(ci): ad-hoc sign the simulator e2e app so keychain writes succeed CODE_SIGNING_ALLOWED=NO leaves a linker-signed slice the simulator keychain rejects with errSecMissingEntitlement (-34018) when the SDK saves bugseeDeviceId; capture then never reaches Launched while launch() still resolves true. Build with ad-hoc signing instead and re-sign embedded frameworks before install. Co-authored-by: Cursor --- .github/workflows/ci.yml | 16 +++++++++++++++- .../ios/BareExample.xcodeproj/project.pbxproj | 4 ++++ 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8c888d7..5b0ec08 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -184,14 +184,28 @@ jobs: - name: Build for the simulator working-directory: examples/bare/ios run: | + # CODE_SIGNING_ALLOWED=NO leaves a linker-signed slice the simulator + # keychain rejects with errSecMissingEntitlement (-34018) on + # bugseeDeviceId; capture then never reaches Launched. Ad-hoc sign + # instead: no Apple ID, but enough for SecItemAdd on the simulator. xcodebuild \ -workspace BareExample.xcworkspace \ -scheme BareExample \ -destination "id=${{ steps.sim.outputs.udid }}" \ -configuration Debug \ -derivedDataPath build \ - CODE_SIGNING_ALLOWED=NO \ + CODE_SIGNING_ALLOWED=YES \ + CODE_SIGN_IDENTITY=- \ + CODE_SIGNING_REQUIRED=NO \ build + APP=build/Build/Products/Debug-iphonesimulator/BareExample.app + if [ -d "$APP/Frameworks" ]; then + find "$APP/Frameworks" -depth \( -name "*.framework" -o -name "*.dylib" \) -print0 \ + | while IFS= read -r -d '' item; do + codesign --force --sign - --timestamp=none "$item" + done + fi + codesign --force --sign - --timestamp=none "$APP" - name: Install the app run: | diff --git a/examples/bare/ios/BareExample.xcodeproj/project.pbxproj b/examples/bare/ios/BareExample.xcodeproj/project.pbxproj index decbca0..852ed23 100644 --- a/examples/bare/ios/BareExample.xcodeproj/project.pbxproj +++ b/examples/bare/ios/BareExample.xcodeproj/project.pbxproj @@ -259,6 +259,8 @@ buildSettings = { ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon; CLANG_ENABLE_MODULES = YES; + CODE_SIGNING_REQUIRED = NO; + "CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-"; CURRENT_PROJECT_VERSION = 1; ENABLE_BITCODE = NO; INFOPLIST_FILE = BareExample/Info.plist; @@ -289,6 +291,8 @@ buildSettings = { ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon; CLANG_ENABLE_MODULES = YES; + CODE_SIGNING_REQUIRED = NO; + "CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-"; CURRENT_PROJECT_VERSION = 1; INFOPLIST_FILE = BareExample/Info.plist; IPHONEOS_DEPLOYMENT_TARGET = 15.1; From 66a7dc2aa10437a4f58dcca66f6f34a91f88632d Mon Sep 17 00:00:00 2001 From: Alexey Karimov Date: Sun, 4 Oct 2026 10:43:24 +0500 Subject: [PATCH 2/2] fix(ios): drop unscoped CODE_SIGNING_REQUIRED from BareExample target Device installs must still require signing; keep the simulator-only ad-hoc identity and let CI pass CODE_SIGNING_REQUIRED=NO on the command line. Co-authored-by: Cursor --- examples/bare/ios/BareExample.xcodeproj/project.pbxproj | 2 -- 1 file changed, 2 deletions(-) diff --git a/examples/bare/ios/BareExample.xcodeproj/project.pbxproj b/examples/bare/ios/BareExample.xcodeproj/project.pbxproj index 852ed23..cae2685 100644 --- a/examples/bare/ios/BareExample.xcodeproj/project.pbxproj +++ b/examples/bare/ios/BareExample.xcodeproj/project.pbxproj @@ -259,7 +259,6 @@ buildSettings = { ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon; CLANG_ENABLE_MODULES = YES; - CODE_SIGNING_REQUIRED = NO; "CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-"; CURRENT_PROJECT_VERSION = 1; ENABLE_BITCODE = NO; @@ -291,7 +290,6 @@ buildSettings = { ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon; CLANG_ENABLE_MODULES = YES; - CODE_SIGNING_REQUIRED = NO; "CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-"; CURRENT_PROJECT_VERSION = 1; INFOPLIST_FILE = BareExample/Info.plist;