Repository navigation
approve-ios: derive XcodeGen project.yml/Info.plist from .dag (launch screen, Face ID string, display name, Xcode 26) - #12244
Conversation
…os_project
XcodeGen writes its own Info.plist, so INFOPLIST_KEY_* settings were ignored:
the app letterboxed (no UILaunchScreen) and would crash on first Face ID use
(no NSFaceIDUsageDescription). project.yml is now a generated artifact of a
.dag authority whose required Info.plist keys are record fields, and the
drift gate holds the committed file to it.
- extdeps.xcodegen.project_spec (XcodeGen 2.46.0 ProjectSpec) + YAML encoding
- extdeps.apple.{property_list, info_plist, build_settings} (cited Apple docs)
- gunbc.approve_ios_project: xcodeVersion 26.0, ENABLE_USER_SCRIPT_SANDBOXING
and STRING_CATALOG_GENERATE_SYMBOLS=YES, iOS 17.0 kept; dead
INFOPLIST_KEY_* removed; registered as ApproveIosProjectYmlArtifact
(consumer XcodeProjectGenerator)
- test.claim.approve_ios_project_witness: the emitted bytes carry every
required key/setting, with one red per failure seen on the Mac
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…errors, orientations, test Info.plist, nonisolated UN delegate; model the iOS build standing - extdeps.apple.xcode XcodeRelease xcode_26_6 (release notes cited); XcodeGen's XCodeVersion.parse modeled as xcodegen_last_upgrade_check (26.6 -> 2660) - SWIFT/GCC_TREAT_WARNINGS_AS_ERRORS=YES; Swift 5 mode + strict concurrency complete - UISupportedInterfaceOrientations (all four); ApproveTests GENERATE_INFOPLIST_FILE=YES - ApproveApp.swift: UN delegate callbacks nonisolated, hop to @mainactor refreshFromPush - gunbc.approve_ios_app: derived vs hand-authored split, ApproveIosBuildReceipt carrier (empty until an observed run), approve_ios_build_unexecuted_frontier Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rain (emit refused an in-body //) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
SOURCE HOLD at exact head 173db7804b701c0f6ca883d7c7cee528a3f703d5.
The Mac-driven repair round is accepted: Xcode 26.6/LastUpgradeCheck 2660, warnings-as-errors, Swift 5.10 with complete strict concurrency, all four orientations, the test target's generated Info.plist, the nonisolated notification callbacks hopping to a MainActor refresh, the derived-versus-hand-authored standing, and the deliberately empty provenance-bearing build-receipt roster are all sound. The five Linux checks are green and the PR is CLEAN, but they do not execute the iOS build, which the new frontier states honestly.
One prior evidence hold remains, and the expanded source claim adds one closely related seam. project_carries_required_content still does not read three settings that the authority calls load-bearing:
targets.Approve.info.properties.ApproveApnsEnvironment == $(APNS_ENVIRONMENT);targets.Approve.settings.base.PRODUCT_BUNDLE_IDENTIFIER == ai.gunb.approve;settings.base.SWIFT_VERSION == 5.10.
The supplied “complete” document carries PRODUCT_BUNDLE_IDENTIFIER, but the predicate never checks it; it does not carry ApproveApnsEnvironment at all. The predicate checks SWIFT_STRICT_CONCURRENCY=complete but not the Swift 5.10 language mode that makes the PR's stated concurrency posture precise. Consequently, deleting or changing any of these three rows leaves the semantic witness green while the source still claims every required key and setting is proved.
Required repair: assert each exact path and value in the emitted-and-reingested document, and add supplied-document REDs for omission or substitution. This does not require a Mac build or a broader redesign; it is the missing discrimination at the existing YAML-byte witness seam.
No further objection remains to the XcodeGen model, generated-artifact registration, Swift callback repair, build-standing carrier, or the rest of the 11-cell witness.
…UNDLE_IDENTIFIER, SWIFT_VERSION at their paths, with omission and substitution reds Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE-MERGE at exact head 525d340e4ff4bfa42315d851973ffefb58f0d730.
This supersedes my CHANGES_REQUESTED review 5311511132. The delta from held 173db7804b701c0f6ca883d7c7cee528a3f703d5 is exactly one commit and one file, dag/test/claim/approve_ios_project_witness_test.dag; it makes no implementation or authority change.
All three previously missing load-bearing rows are now read from the emitted-and-reingested YAML at their exact paths and exact values:
targets.Approve.info.properties.ApproveApnsEnvironment == $(APNS_ENVIRONMENT);targets.Approve.settings.base.PRODUCT_BUNDLE_IDENTIFIER == ai.gunb.approve;settings.base.SWIFT_VERSION == 5.10.
Each seam has both required supplied-document discriminators: omission and wrong-value substitution. The positive supplied document now contains all three, and the earlier controls were updated to preserve their own isolated subject rather than turning red accidentally from the newly required APNs row. The Swift helper also exposes the global settings list explicitly, so the missing and 6.0 substitutions exercise the exact path rather than a parallel fixture.
The accepted prior standing remains unchanged: the XcodeGen projection and generated-artifact drift wall are sound; Xcode 26.6/2660, warnings-as-errors, Swift 5.10 with complete strict concurrency, orientations, the ApproveTests generated Info.plist, and the nonisolated callback repair are accepted; the iOS build is still honestly NotExecutedByAnyRequiredLane, and no unproven operator result was entered into the empty provenance-bearing build receipt roster.
Run 36076623009 passes compiler, clippy, emit-build, floor, and witnesses at this exact SHA. GitHub reports the PR mergeable and CLEAN.
No source condition remains unless the head moves. The merge queue must still judge the composed landing revision; a queue red is a repair-and-requeue event, never grounds for bypass.
Resolves the project.yml conflict with #12000 by deriving its MARKETING_VERSION and CURRENT_PROJECT_VERSION in gunbc.approve_ios_project (MARKETING_VERSION and PRODUCT_BUNDLE_IDENTIFIER read from gunbc.auth.approval_app_attest_config); both generated files regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… UnimportedBareProvider: 'append' resolves to another witness's declaration) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE-MERGE rebind at exact head 5329a6fe323f91d18173ab0edf6be74ff2681ba5.
This carries forward the source approval at 525d340e4ff4bfa42315d851973ffefb58f0d730 (review 5312417028).
The dequeue was a merge-conflict event, and the resolution preserves the model’s authority direction rather than side-picking generated bytes:
apps/approve-ios/project.ymland.gitattributesare regenerated from their authorities. The exact-head floor’s generated-artifact step passes, so the committed projections equal the merged source authorities.- #12000’s
MARKETING_VERSIONandCURRENT_PROJECT_VERSIONsurvive in the derived XcodeGen project.PRODUCT_BUNDLE_IDENTIFIERandMARKETING_VERSIONnow readgunbc.auth.approval_app_attest_config.approval_app_bundle_idand.approval_app_bundle_version, respectively. The build and the verifier therefore cannot carry independent literals for the App ID or CFBundleShortVersionString.CURRENT_PROJECT_VERSIONremains the explicitly local build number, which the server does not check. - The resulting projection contains
PRODUCT_BUNDLE_IDENTIFIER: ai.gunb.approve,MARKETING_VERSION: "1", andCURRENT_PROJECT_VERSION: "1"at the Approve target’s settings path. - The post-merge #12205 refusal is repaired at the witness source: path construction uses
concatinstead of bareappend, avoiding the loader-selected declaration from another witness without changing the supplied-document population or any assertion.
No previously accepted source is weakened: the exact-path APNs, bundle-ID, and Swift-version assertions and their omission/substitution REDs remain; Xcode 26.6/2660, warnings-as-errors, Swift 5.10 plus complete strict concurrency, orientations, the test target Info.plist, nonisolated notification callbacks, generated-artifact registration, and the honest NotExecutedByAnyRequiredLane iOS-build standing remain intact.
Run 36114769484 passes compiler, clippy, emit-build, floor (including nominal witnesses, D0 publication/adjudication, and generated-artifact verification), and witnesses at this exact SHA. GitHub reports CLEAN and mergeable.
No source condition remains unless the head moves. The merge queue remains authoritative for the composed landing revision.
Supersedes the uncommitted hand edit in ~/gunbc-approve (DESIGN §6: a hand-authored projection the model should generate).
Upstream first
extdeps.xcodegen.project_spec— XcodeGen ProjectSpec pinned at 2.46.0 (options, configFiles, settings.base, targets, info/entitlements path+properties, xcodeVersion) and its YAML encoding, written byextdeps.languages.yaml.emit.extdeps.apple.info_plist— UILaunchScreen, NSFaceIDUsageDescription, CFBundleDisplayName, UIBackgroundModes, each citing its Apple page.extdeps.apple.build_settings— Apple build-settings reference; deliberately noINFOPLIST_KEY_*arm (ignored when XcodeGen writes Info.plist).extdeps.apple.property_list— plist value shape.Authority
gunbc.approve_ios_project: required Info.plist keys are record fields (omission doesn't construct).xcodeVersion: 26.0(LastUpgradeCheck 2600),ENABLE_USER_SCRIPT_SANDBOXING=YES,STRING_CATALOG_GENERATE_SYMBOLS=YES; deployment target kept at iOS 17.0 (the app's standing floor). Registered asApproveIosProjectYmlArtifact(new consumerXcodeProjectGenerator), so the drift gate checksapps/approve-ios/project.yml.Controls
xcodeVersion: "16.0"by hand →tools.generated_artifact_gate mainexit 1:apps/approve-ios/project.yml — committed content differs from authority.test.claim.approve_ios_project_witness(7 PASS locally): the emitted+re-ingested bytes carry each required key attargets.Approve.info.properties, noINFOPLIST_KEY_*, xcodeVersion 26.0, both settings; reds for missing launch screen / Face ID string / display name, a dead INFOPLIST_KEY_ setting, and a stale xcodeVersion.Note: the hand YAML comments are gone; their content lives in the .dag authority, and the file carries a generated header.
Operator verification requested (on the Mac):
cd apps/approve-ios && xcodegen generate, build + install → full-screen (no letterbox), Face ID prompt shows the purpose string, and no "Update to recommended settings" prompt.Round 2 (from the operator's Mac, Xcode 26.6)
xcodeVersion: "26.6"fromextdeps.apple.xcode xcode_26_6(cited to Apple's release notes). XcodeGen derives LastUpgradeCheck 2660 viaXCodeVersion.parse(2.46.0Sources/XcodeGenKit/Version.swift), modeled asextdeps.xcodegen.project_spec xcodegen_last_upgrade_check; 26.0 → 2600 kept the prompt.SWIFT_TREAT_WARNINGS_AS_ERRORS=YES,GCC_TREAT_WARNINGS_AS_ERRORS=YES. Language mode: Swift 5 (SWIFT_VERSION 5.10) withSWIFT_STRICT_CONCURRENCY=complete, so Swift 6's data-race checking runs as diagnostics and each one fails the build.UISupportedInterfaceOrientationswith all four orientations (cited to Apple).GENERATE_INFOPLIST_FILE=YES(it had no Info.plist; Cmd-U never built).ApproveApp.swift, hand-written): bothuserNotificationCentercallbacks arenonisolatedand hop to@MainActor private func refreshFromPush(); the UN* arguments are not Sendable and are not read.What's derived and what's hand-authored
apps/approve-ios/project.yml(and so the Info.plist XcodeGen writes on the Mac) fromgunbc.approve_ios_project;dag/test/fixture/approval_device_redemption/vectors.jsonfromgunbc.auth.approval_device_redemption_fixtures.Approve/andApproveTests/(gunbc.approve_ios_app approve_ios_hand_authored_swift_frontier), and the operator-localConfig/Team.xcconfig.ios_realization_frontiernow names both of these and the gap below.The iOS build's standing
gunbc.approve_ios_app approve_ios_build_unexecuted_frontier, trigger: a macOS runner executes the derived project build with warnings as errors on the required gate.ApproveIosBuildReceipt(Xcode release + build number, SDK, configuration, warnings, test outcome, device install, date, provenance: observer, built commit, xcresult sha256).approve_ios_build_receiptsis empty on purpose: the Mac's 0-warnings / 18-of-18 result reached this lane as a relayed sentence without its result bundle, so it isn't entered. The first row goes in from the next run's artifacts.Witness: 11/11 PASS (new reds: stale 26.0, missing test Info.plist, missing orientations).
🤖 Generated with Claude Code