Skip to content

approve-ios: derive XcodeGen project.yml/Info.plist from .dag (launch screen, Face ID string, display name, Xcode 26) - #12244

Merged
gunbai-bot[bot] merged 7 commits into
mainfrom
session/still-lark-262
Sep 25, 2026
Merged

gunbai-bot[bot] merged 7 commits into
mainfrom
session/still-lark-262

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Supersedes the uncommitted hand edit in ~/gunbc-approve (DESIGN §6: a hand-authored projection the model should generate).

Upstream first

  • extdeps.xcodegen.project_spec — XcodeGen ProjectSpec pinned at 2.46.0 (options, configFiles, settings.base, targets, info/entitlements path+properties, xcodeVersion) and its YAML encoding, written by extdeps.languages.yaml.emit.
  • extdeps.apple.info_plist — UILaunchScreen, NSFaceIDUsageDescription, CFBundleDisplayName, UIBackgroundModes, each citing its Apple page.
  • extdeps.apple.build_settings — Apple build-settings reference; deliberately no INFOPLIST_KEY_* arm (ignored when XcodeGen writes Info.plist).
  • extdeps.apple.property_list — plist value shape.

Authority gunbc.approve_ios_project: required Info.plist keys are record fields (omission doesn't construct). xcodeVersion: 26.0 (LastUpgradeCheck 2600), ENABLE_USER_SCRIPT_SANDBOXING=YES, STRING_CATALOG_GENERATE_SYMBOLS=YES; deployment target kept at iOS 17.0 (the app's standing floor). Registered as ApproveIosProjectYmlArtifact (new consumer XcodeProjectGenerator), so the drift gate checks apps/approve-ios/project.yml.

Controls

  • Drift gate RED on hand edit: setting xcodeVersion: "16.0" by hand → tools.generated_artifact_gate main exit 1: apps/approve-ios/project.yml — committed content differs from authority.
  • test.claim.approve_ios_project_witness (7 PASS locally): the emitted+re-ingested bytes carry each required key at targets.Approve.info.properties, no INFOPLIST_KEY_*, xcodeVersion 26.0, both settings; reds for missing launch screen / Face ID string / display name, a dead INFOPLIST_KEY_ setting, and a stale xcodeVersion.

Note: the hand YAML comments are gone; their content lives in the .dag authority, and the file carries a generated header.

Operator verification requested (on the Mac): cd apps/approve-ios && xcodegen generate, build + install → full-screen (no letterbox), Face ID prompt shows the purpose string, and no "Update to recommended settings" prompt.

Round 2 (from the operator's Mac, Xcode 26.6)

  • LastUpgradeCheck: xcodeVersion: "26.6" from extdeps.apple.xcode xcode_26_6 (cited to Apple's release notes). XcodeGen derives LastUpgradeCheck 2660 via XCodeVersion.parse (2.46.0 Sources/XcodeGenKit/Version.swift), modeled as extdeps.xcodegen.project_spec xcodegen_last_upgrade_check; 26.0 → 2600 kept the prompt.
  • Warnings as errors: SWIFT_TREAT_WARNINGS_AS_ERRORS=YES, GCC_TREAT_WARNINGS_AS_ERRORS=YES. Language mode: Swift 5 (SWIFT_VERSION 5.10) with SWIFT_STRICT_CONCURRENCY=complete, so Swift 6's data-race checking runs as diagnostics and each one fails the build.
  • Info.plist: UISupportedInterfaceOrientations with all four orientations (cited to Apple).
  • ApproveTests: GENERATE_INFOPLIST_FILE=YES (it had no Info.plist; Cmd-U never built).
  • Swift (ApproveApp.swift, hand-written): both userNotificationCenter callbacks are nonisolated and hop to @MainActor private func refreshFromPush(); the UN* arguments are not Sendable and are not read.

What's derived and what's hand-authored

  • Derived, drift-gated: apps/approve-ios/project.yml (and so the Info.plist XcodeGen writes on the Mac) from gunbc.approve_ios_project; dag/test/fixture/approval_device_redemption/vectors.json from gunbc.auth.approval_device_redemption_fixtures.
  • Hand-authored realization: all Swift under Approve/ and ApproveTests/ (gunbc.approve_ios_app approve_ios_hand_authored_swift_frontier), and the operator-local Config/Team.xcconfig. ios_realization_frontier now names both of these and the gap below.

The iOS build's standing

  • Not executed by any required lane (Linux runners): gunbc.approve_ios_app approve_ios_build_unexecuted_frontier, trigger: a macOS runner executes the derived project build with warnings as errors on the required gate.
  • Evidence is operator-run receipts: ApproveIosBuildReceipt (Xcode release + build number, SDK, configuration, warnings, test outcome, device install, date, provenance: observer, built commit, xcresult sha256). approve_ios_build_receipts is empty on purpose: the Mac's 0-warnings / 18-of-18 result reached this lane as a relayed sentence without its result bundle, so it isn't entered. The first row goes in from the next run's artifacts.

Witness: 11/11 PASS (new reds: stale 26.0, missing test Info.plist, missing orientations).

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 4 commits September 24, 2026 18:08
…os_project

XcodeGen writes its own Info.plist, so INFOPLIST_KEY_* settings were ignored:
the app letterboxed (no UILaunchScreen) and would crash on first Face ID use
(no NSFaceIDUsageDescription). project.yml is now a generated artifact of a
.dag authority whose required Info.plist keys are record fields, and the
drift gate holds the committed file to it.

- extdeps.xcodegen.project_spec (XcodeGen 2.46.0 ProjectSpec) + YAML encoding
- extdeps.apple.{property_list, info_plist, build_settings} (cited Apple docs)
- gunbc.approve_ios_project: xcodeVersion 26.0, ENABLE_USER_SCRIPT_SANDBOXING
  and STRING_CATALOG_GENERATE_SYMBOLS=YES, iOS 17.0 kept; dead
  INFOPLIST_KEY_* removed; registered as ApproveIosProjectYmlArtifact
  (consumer XcodeProjectGenerator)
- test.claim.approve_ios_project_witness: the emitted bytes carry every
  required key/setting, with one red per failure seen on the Mac

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…errors, orientations, test Info.plist, nonisolated UN delegate; model the iOS build standing

- extdeps.apple.xcode XcodeRelease xcode_26_6 (release notes cited); XcodeGen's
  XCodeVersion.parse modeled as xcodegen_last_upgrade_check (26.6 -> 2660)
- SWIFT/GCC_TREAT_WARNINGS_AS_ERRORS=YES; Swift 5 mode + strict concurrency complete
- UISupportedInterfaceOrientations (all four); ApproveTests GENERATE_INFOPLIST_FILE=YES
- ApproveApp.swift: UN delegate callbacks nonisolated, hop to @mainactor refreshFromPush
- gunbc.approve_ios_app: derived vs hand-authored split, ApproveIosBuildReceipt
  carrier (empty until an observed run), approve_ios_build_unexecuted_frontier

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rain (emit refused an in-body //)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SOURCE HOLD at exact head 173db7804b701c0f6ca883d7c7cee528a3f703d5.

The Mac-driven repair round is accepted: Xcode 26.6/LastUpgradeCheck 2660, warnings-as-errors, Swift 5.10 with complete strict concurrency, all four orientations, the test target's generated Info.plist, the nonisolated notification callbacks hopping to a MainActor refresh, the derived-versus-hand-authored standing, and the deliberately empty provenance-bearing build-receipt roster are all sound. The five Linux checks are green and the PR is CLEAN, but they do not execute the iOS build, which the new frontier states honestly.

One prior evidence hold remains, and the expanded source claim adds one closely related seam. project_carries_required_content still does not read three settings that the authority calls load-bearing:

  1. targets.Approve.info.properties.ApproveApnsEnvironment == $(APNS_ENVIRONMENT);
  2. targets.Approve.settings.base.PRODUCT_BUNDLE_IDENTIFIER == ai.gunb.approve;
  3. settings.base.SWIFT_VERSION == 5.10.

The supplied “complete” document carries PRODUCT_BUNDLE_IDENTIFIER, but the predicate never checks it; it does not carry ApproveApnsEnvironment at all. The predicate checks SWIFT_STRICT_CONCURRENCY=complete but not the Swift 5.10 language mode that makes the PR's stated concurrency posture precise. Consequently, deleting or changing any of these three rows leaves the semantic witness green while the source still claims every required key and setting is proved.

Required repair: assert each exact path and value in the emitted-and-reingested document, and add supplied-document REDs for omission or substitution. This does not require a Mac build or a broader redesign; it is the missing discrimination at the existing YAML-byte witness seam.

No further objection remains to the XcodeGen model, generated-artifact registration, Swift callback repair, build-standing carrier, or the rest of the 11-cell witness.

…UNDLE_IDENTIFIER, SWIFT_VERSION at their paths, with omission and substitution reds

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE at exact head 525d340e4ff4bfa42315d851973ffefb58f0d730.

This supersedes my CHANGES_REQUESTED review 5311511132. The delta from held 173db7804b701c0f6ca883d7c7cee528a3f703d5 is exactly one commit and one file, dag/test/claim/approve_ios_project_witness_test.dag; it makes no implementation or authority change.

All three previously missing load-bearing rows are now read from the emitted-and-reingested YAML at their exact paths and exact values:

  • targets.Approve.info.properties.ApproveApnsEnvironment == $(APNS_ENVIRONMENT);
  • targets.Approve.settings.base.PRODUCT_BUNDLE_IDENTIFIER == ai.gunb.approve;
  • settings.base.SWIFT_VERSION == 5.10.

Each seam has both required supplied-document discriminators: omission and wrong-value substitution. The positive supplied document now contains all three, and the earlier controls were updated to preserve their own isolated subject rather than turning red accidentally from the newly required APNs row. The Swift helper also exposes the global settings list explicitly, so the missing and 6.0 substitutions exercise the exact path rather than a parallel fixture.

The accepted prior standing remains unchanged: the XcodeGen projection and generated-artifact drift wall are sound; Xcode 26.6/2660, warnings-as-errors, Swift 5.10 with complete strict concurrency, orientations, the ApproveTests generated Info.plist, and the nonisolated callback repair are accepted; the iOS build is still honestly NotExecutedByAnyRequiredLane, and no unproven operator result was entered into the empty provenance-bearing build receipt roster.

Run 36076623009 passes compiler, clippy, emit-build, floor, and witnesses at this exact SHA. GitHub reports the PR mergeable and CLEAN.

No source condition remains unless the head moves. The merge queue must still judge the composed landing revision; a queue red is a repair-and-requeue event, never grounds for bypass.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 25, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 25, 2026
gunbc-ci-auto-heal and others added 2 commits September 25, 2026 08:25
Resolves the project.yml conflict with #12000 by deriving its MARKETING_VERSION and
CURRENT_PROJECT_VERSION in gunbc.approve_ios_project (MARKETING_VERSION and
PRODUCT_BUNDLE_IDENTIFIER read from gunbc.auth.approval_app_attest_config); both
generated files regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… UnimportedBareProvider: 'append' resolves to another witness's declaration)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE rebind at exact head 5329a6fe323f91d18173ab0edf6be74ff2681ba5.

This carries forward the source approval at 525d340e4ff4bfa42315d851973ffefb58f0d730 (review 5312417028).

The dequeue was a merge-conflict event, and the resolution preserves the model’s authority direction rather than side-picking generated bytes:

  • apps/approve-ios/project.yml and .gitattributes are regenerated from their authorities. The exact-head floor’s generated-artifact step passes, so the committed projections equal the merged source authorities.
  • #12000’s MARKETING_VERSION and CURRENT_PROJECT_VERSION survive in the derived XcodeGen project. PRODUCT_BUNDLE_IDENTIFIER and MARKETING_VERSION now read gunbc.auth.approval_app_attest_config.approval_app_bundle_id and .approval_app_bundle_version, respectively. The build and the verifier therefore cannot carry independent literals for the App ID or CFBundleShortVersionString. CURRENT_PROJECT_VERSION remains the explicitly local build number, which the server does not check.
  • The resulting projection contains PRODUCT_BUNDLE_IDENTIFIER: ai.gunb.approve, MARKETING_VERSION: "1", and CURRENT_PROJECT_VERSION: "1" at the Approve target’s settings path.
  • The post-merge #12205 refusal is repaired at the witness source: path construction uses concat instead of bare append, avoiding the loader-selected declaration from another witness without changing the supplied-document population or any assertion.

No previously accepted source is weakened: the exact-path APNs, bundle-ID, and Swift-version assertions and their omission/substitution REDs remain; Xcode 26.6/2660, warnings-as-errors, Swift 5.10 plus complete strict concurrency, orientations, the test target Info.plist, nonisolated notification callbacks, generated-artifact registration, and the honest NotExecutedByAnyRequiredLane iOS-build standing remain intact.

Run 36114769484 passes compiler, clippy, emit-build, floor (including nominal witnesses, D0 publication/adjudication, and generated-artifact verification), and witnesses at this exact SHA. GitHub reports CLEAN and mergeable.

No source condition remains unless the head moves. The merge queue remains authoritative for the composed landing revision.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 25, 2026
Merged via the queue into main with commit d705250 Sep 25, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/still-lark-262 branch September 25, 2026 13:17
gunbai-bot Bot pushed a commit that referenced this pull request Sep 25, 2026
…12267): both RFM occurrence receipts kept

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls restored the session/still-lark-262 branch September 25, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant