ci: rework CI into a checks/iOS/macOS pipeline for all platforms - #4
Merged
Merged
Conversation
The workflow duplicated its setup four times, ran only on main, kept no diagnostics, and never verified the shipped Mac binary was universal. Structure: - New composite action .github/actions/setup replaces the Xcode-select, SDK-assert, XcodeGen and generate steps duplicated across both jobs. - A cheap `checks` job runs first. It asserts the deployment floor, App Group wiring and privacy-manifest reasons -- none of which any build catches, since every xcodebuild here passes CODE_SIGNING_ALLOWED=NO -- so a bad config fails in seconds instead of after twelve minutes of simulator work. - iOS and macOS both gate on it and run in parallel. Coverage: - Universal macOS Release build with an explicit lipo assertion on both the arm64 and x86_64 slices. Nothing previously proved the shipped Mac app carried both, and macOS still ships to Intel. Only the x86_64 *test* run needs Rosetta, which the arm64 runner does not document, so that half stays in Scripts/verify-macos.sh for local use. - iOS unit tests run once rather than on every matrix leg; they are pure logic and device-independent. - The UI step drops -only-testing. The UI target globs its whole source directory, so naming classes there silently skipped any newly added class. Operations: - concurrency cancels superseded runs, so a new push stops burning the macOS runners the previous one held. - permissions: contents: read. - Push now also builds `develop`, which was previously merged unverified. - Result bundles are written and uploaded on failure. UI tests attach screenshots with .keepAlways; those previously died with the runner and every failure had to be reproduced blind. iPad is intentionally not a matrix leg yet: the UI suite here has no iPad handling, so the leg would fail. The rationale and the one-word change to enable it are recorded inline. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reworks CI from two near-duplicate jobs into a
checks→iOS/macOSpipeline.What was wrong
maindevelopmerges were never verified.keepAlways) died with the runner; failures had to be reproduced blind-only-testingnamed UI classes explicitlyconcurrencyStructure
.github/actions/setup— Xcode select, SDK assert, XcodeGen, generate. One definition instead of four.checksjob runs first. It asserts the deployment floor, App Group wiring, and privacy-manifest reasons. None of those are caught by any build, because everyxcodebuildhere passesCODE_SIGNING_ALLOWED=NO— so entitlements are never applied. A bad config now fails in seconds rather than after 12 minutes of simulator work.Coverage added
lipoassertion on both slices. Nothing previously proved the shipped Mac app contained x86_64. Only the x86_64 test run needs Rosetta — which the arm64 runner doesn't document — so that half stays inScripts/verify-macos.shfor local use.iPad
Deliberately not a matrix leg yet. The UI suite on
develophas no iPad handling — no idiom checks, no sidebar/split-view paths — so the leg would fail on the first UI test. The iPad-capable suite arrives with the App Store screenshots branch (854b3da). Once that merges, addingipadto the matrix list is the only change needed; the rationale is recorded inline.Verification
Runner facts confirmed against the
actions/runner-imagesmanifest rather than assumed:macos-26is arm64 with Xcode 26.6 default and iOS 26.2/26.4/26.5 runtimes, each carrying both iPhone and iPad devices — so the resolver's 26.5 floor and its SDK-major ceiling both land on 26.5.Locally verified: YAML parses, composite action satisfies every rule (
using: composite,shell:on each step),checkssteps pass, thelipoassertion logic works against known-good output, and both resolver families return devices.An adversarial review raised 6 high/blocker issues; verification confirmed 2 and refuted 4. Both real ones are fixed here — the composite action was untracked (would have failed every job with "Can't find 'action.yml'"), and the iPad leg above.
🤖 Generated with Claude Code