Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 15 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -184,14 +184,28 @@ jobs:
- name: Build for the simulator
working-directory: examples/bare/ios
run: |
# CODE_SIGNING_ALLOWED=NO leaves a linker-signed slice the simulator
# keychain rejects with errSecMissingEntitlement (-34018) on
# bugseeDeviceId; capture then never reaches Launched. Ad-hoc sign
# instead: no Apple ID, but enough for SecItemAdd on the simulator.
xcodebuild \
-workspace BareExample.xcworkspace \
-scheme BareExample \
-destination "id=${{ steps.sim.outputs.udid }}" \
-configuration Debug \
-derivedDataPath build \
CODE_SIGNING_ALLOWED=NO \
CODE_SIGNING_ALLOWED=YES \
CODE_SIGN_IDENTITY=- \
CODE_SIGNING_REQUIRED=NO \
build
APP=build/Build/Products/Debug-iphonesimulator/BareExample.app
if [ -d "$APP/Frameworks" ]; then
find "$APP/Frameworks" -depth \( -name "*.framework" -o -name "*.dylib" \) -print0 \
| while IFS= read -r -d '' item; do
codesign --force --sign - --timestamp=none "$item"
done
fi
codesign --force --sign - --timestamp=none "$APP"

- name: Install the app
run: |
Expand Down
4 changes: 4 additions & 0 deletions examples/bare/ios/BareExample.xcodeproj/project.pbxproj
Original file line number Diff line number Diff line change
Expand Up @@ -259,6 +259,8 @@
buildSettings = {
ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon;
CLANG_ENABLE_MODULES = YES;
CODE_SIGNING_REQUIRED = NO;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Medium — CODE_SIGNING_REQUIRED = NO applies to device builds too

Problem: This is set on the BareExample target for both Debug (here) and Release (line 294), with no sdk=iphonesimulator* condition. The same target has SUPPORTED_PLATFORMS = "iphoneos iphonesimulator". The simulator identity below is correctly qualified; this flag is not.

Impact: CODE_SIGNING_REQUIRED=NO is the setting whose purpose is to let the CodeSign phase skip. examples/bare/scripts/run-ios.sh and the README SPM device xcodebuild pass DEVELOPMENT_TEAM + CODE_SIGN_STYLE=Automatic but do not override CODE_SIGNING_REQUIRED. The CI post-sign (codesign --force --sign - on Debug-iphonesimulator/BareExample.app) never runs on those paths. An unsigned or linker-signed iphoneos .app is rejected by devicectl device install — the documented yarn device:ios / E2E_IOS_TARGET=device flow this example exists for.

Scenario: After this merges, yarn device:ios (or the README SPM xcodebuild -destination id=$IOS_DEVICE_ID ... CODE_SIGN_STYLE=Automatic) inherits CODE_SIGNING_REQUIRED=NO from the target. If the modern build system skips CodeSign because required is NO (or skips it when the generic project-level CODE_SIGN_IDENTITY[sdk=iphoneos*] = iPhone Developer does not resolve), install fails. Release is the same landmine for E2E_RELEASE=1.

Fix: Keep the simulator identity, drop the unscoped required flag from the target:

"CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-";

If a local no-team simulator build still needs it, qualify it the same way:

"CODE_SIGNING_REQUIRED[sdk=iphonesimulator*]" = NO;

The CI job can keep passing CODE_SIGNING_REQUIRED=NO on the xcodebuild command line; that does not change device installs.

"CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-";
CURRENT_PROJECT_VERSION = 1;
ENABLE_BITCODE = NO;
INFOPLIST_FILE = BareExample/Info.plist;
Expand Down Expand Up @@ -289,6 +291,8 @@
buildSettings = {
ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon;
CLANG_ENABLE_MODULES = YES;
CODE_SIGNING_REQUIRED = NO;
"CODE_SIGN_IDENTITY[sdk=iphonesimulator*]" = "-";
CURRENT_PROJECT_VERSION = 1;
INFOPLIST_FILE = BareExample/Info.plist;
IPHONEOS_DEPLOYMENT_TARGET = 15.1;
Expand Down
Loading