Skip to content

Build and verify every platform in one CI Verify job (PR 1/20) - #69

Merged
agoodkind merged 1 commit into
mainfrom
graphite-base/38
Jul 25, 2026
Merged

agoodkind merged 1 commit into
mainfrom
graphite-base/38

Conversation

@agoodkind

@agoodkind agoodkind commented Jul 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

CI builds every platform in one Verify job and verifies each product's signature, replacing the Mac-only Verify plus separate extra-target jobs.

Change

SWIFT_VERIFY_BUILD_CMD builds every platform through CellTunnelDev build all, so one Verify job compiles and signs the Mac agent and tunnel, the Catalyst app, the iPhone simulator app, the iPhone device app, and the daemon. The signing override signs every product, and the App Store Connect API key (already inherited) drives automatic signing for the iPhone and Catalyst products.

SWIFT_MK_VERIFY_SIGNING_ROOTS = Products makes the engine discover each runnable .app the build dropped under Products and verify its signature: a strict codesign --verify --deep on each app plus a team and non-ad-hoc check. The engine skips the iPhone simulator app, which is ad-hoc by design. The pre-build settings check confirms the signing identity. The build-catalyst, build-iphone-sim, and build-daemon extra-target jobs are removed because the one build produces them all.

Depends on the engine verify-signing products capability (swift-makefile #186).

Testing

  • make verify CONFIG=Debug builds every platform, signs each, and verifies each runnable product.
  • CI on this PR exercises the signed build and verification on the self-hosted pool.

agoodkind commented Jul 24, 2026 •

Copy link
Copy Markdown
Owner Author

@coderabbitai

coderabbitai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@agoodkind, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 53 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Pro Plus

Run ID: 2ac03ae9-2bb5-42bd-abdd-72fba0537a80

📥 Commits

Reviewing files that changed from the base of the PR and between db3e640 and 4d5656c.

⛔ Files ignored due to path filters (1)
  • Gemfile.lock is excluded by !**/*.lock
📒 Files selected for processing (10)
  • .github/workflows/ci.yml
  • .gitignore
  • AGENTS.md
  • Gemfile
  • Makefile
  • Project.swift
  • README.md
  • Tools/CellTunnelDev/ProcessSupport.swift
  • fastlane/Fastfile
  • fastlane/README.md
📝 Walkthrough

Walkthrough

The PR configures signed Mac verification and named CI build targets, updates build documentation, and renames EOF semaphore locals in PrefixedProcess while preserving their synchronization wiring.

Changes

Build verification and CI targets

Layer / File(s) Summary
Verify build and CI signing wiring
.github/workflows/ci.yml, Makefile, AGENTS.md, README.md
The Makefile adds Mac verification and signing settings; CI and documentation describe named platform targets and the updated signing flow.

Process output synchronization

Layer / File(s) Summary
EOF semaphore naming and storage
Tools/CellTunnelDev/ProcessSupport.swift
PrefixedProcess renames stdout/stderr EOF semaphore locals and preserves their callback and instance wiring.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: copilot

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title accurately summarizes the main change: consolidating platform builds and verification into one CI Verify job.
Description check ✅ Passed The description matches the changeset by explaining the unified Verify job, signing behavior, and removed extra-target jobs.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch graphite-base/38

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@agoodkind agoodkind changed the title Map Make targets and CI platform builds Map Make targets and CI platform builds (PR 1/20) Jul 24, 2026
@agoodkind
agoodkind marked this pull request as ready for review July 24, 2026 07:53
Copilot AI review requested due to automatic review settings July 24, 2026 07:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copilot AI review requested due to automatic review settings July 24, 2026 16:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@agoodkind agoodkind changed the title Map Make targets and CI platform builds (PR 1/20) Route CI through signed named platform builds (PR 1/20) Jul 24, 2026
Copilot AI review requested due to automatic review settings July 24, 2026 22:30

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@agoodkind agoodkind changed the title Route CI through signed named platform builds (PR 1/20) Build and verify every platform in one CI Verify job (PR 1/20) Jul 24, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@Makefile`:
- Line 41: Align the Verify configuration and documentation with the signed Mac
Verify contract: in Makefile lines 41 and 74-85, use the signed Mac product and
matching signing roots, product claims, and confirmed simulator handling instead
of build all. Update .github/workflows/ci.yml lines 54-62, AGENTS.md line 67,
and README.md lines 21-22 to document the same separate named-target invocations
for Catalyst, iPhone simulator, and daemon builds, including matching signing
checks.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Pro Plus

Run ID: b80d1236-1218-483c-8717-16c75d43441f

📥 Commits

Reviewing files that changed from the base of the PR and between 095f5d6 and db3e640.

📒 Files selected for processing (5)
  • .github/workflows/ci.yml
  • AGENTS.md
  • Makefile
  • README.md
  • Tools/CellTunnelDev/ProcessSupport.swift

Comment thread Makefile
Copilot AI review requested due to automatic review settings July 24, 2026 23:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copilot AI review requested due to automatic review settings July 24, 2026 23:47

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copilot AI review requested due to automatic review settings July 25, 2026 00:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copilot AI review requested due to automatic review settings July 25, 2026 05:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

SWIFT_VERIFY_BUILD_CMD builds every platform through CellTunnelDev `build all`, so
one Verify job compiles the Mac agent and tunnel, the Catalyst app, the iPhone
simulator app, the iPhone device app, and the daemon.

These targets carry App Groups and Network Extension entitlements, so each needs a
provisioning profile. CI runners are not registered devices, so development
provisioning cannot work there; only App Store distribution profiles, which carry no
device list, sign on an unregistered machine. The ci-provision setup step runs
fastlane before the build to create or renew one App Store profile per target through
the App Store Connect API key (fastlane/Fastfile), so profiles do not expire out from
under CI. Project.swift pins each profile by name and signs manually with the Apple
Distribution certificate when TUIST_DEVELOPER_ID_SIGNING is set; local builds keep
automatic development signing. ci.yml imports the distribution certificate and runs
ci-provision, and no longer installs static profiles. SWIFT_MK_VERIFY_SIGNING_ROOTS
verifies every runnable product is signed with the team and is not ad-hoc, skipping
the ad-hoc simulator product. The separate build-catalyst, build-iphone-sim, and
build-daemon extra-target jobs are removed because the one build produces them all.

Rename ProcessSupport EOF semaphore locals.

Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Claude <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 25, 2026 05:47

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@agoodkind

Copy link
Copy Markdown
Owner Author

nice

@agoodkind
agoodkind merged commit f6bbb91 into main Jul 25, 2026
16 checks passed
@agoodkind
agoodkind deleted the graphite-base/38 branch July 25, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants