Skip to content

fix(ci): keep external TestFlight beta current - #12395

Open
brodynies wants to merge 3 commits into
mainfrom
issue-12366-ios-tailscale-pairing
Open

brodynies wants to merge 3 commits into
mainfrom
issue-12366-ios-tailscale-pairing

Conversation

@brodynies

@brodynies brodynies commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #12366.

The external TestFlight app was only updated through a manual marketing-version override, so external testers could remain on a build predating the Tailscale readiness fix from #10473.

This change adds an independent scheduled external beta lane and dispatch option. It resolves the beta bundle/profile, marks uploads external-eligible, assigns the Founder's Edition and cmux Pro groups, submits Beta App Review when Apple requires it, and keeps external metadata/history separate from the internal and demo lanes. Focused tests cover cron routing, artifact history, distribution resolution, group/review behavior, and external notes.

Validation:

  • python3 tests/test_ios_testflight_external_distribution.py
  • python3 tests/test_ios_testflight_notes.py
  • python3 tests/test_ios_testflight_main_push_filter.py
  • python3 tests/test_ios_testflight_pro_distribution.py
  • bash -n ios/scripts/upload-testflight.sh ios/scripts/cloud-testflight.sh
  • python3 -m py_compile ios/scripts/resolve_testflight_distribution.py
  • ./scripts/lint-pbxproj-test-wiring.sh
  • package resolved/workspace grouping checks

The tagged macOS build check was attempted but could not start because this checkout had uninitialized submodules; the documented setup then stopped at the machine disk limit while cloning them (100% full, about 530 MB free).

Changelog

Changed: Keeps the external TestFlight beta lane current.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Fixes #12366. The external TestFlight app previously only got updates through manual marketing-version overrides, so external testers could remain on builds missing the Tailscale readiness fix from #10473. This adds an independent hourly scheduled external beta lane plus a dispatch option so the external app tracks main automatically.

  • Resolves the dev.cmux.app.beta bundle and beta profile for external uploads.
  • Assigns external builds to the Founder's Edition and cmux Pro groups and submits Beta App Review when Apple requires it.
  • Keeps external metadata artifacts and notes history separate from the internal and demo lanes.
  • Allows the manual marketing_version_override dispatch on the external variant to reuse an approved marketing version as a recovery path; demo still rejects the override.

Written for commit df18d1a. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features

    • Added an external beta distribution lane for scheduled and manually triggered TestFlight uploads.
    • External uploads use dedicated build metadata, App Store Connect history, beta versioning, tester groups, and Beta App Review submission when needed.
    • Added recovery support for external uploads using an approved marketing version override.
  • Documentation

    • Updated iOS TestFlight documentation with external beta distribution details.
  • Tests

    • Added coverage for external routing, artifact selection, upload arguments, tester groups, and recovery scenarios.

@vercel

vercel Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cmux166 Ready Ready Preview Sep 12, 2026 6:32am UTC
cmux41 Ready Ready Preview Sep 12, 2026 6:32am UTC

@github-actions

Copy link
Copy Markdown
Contributor

Caution

Pull Request opener is not an author or co-author of any commit in this PR.

  • Opener: @brodynies
  • Author/co-author identities: austinywang

This check is blocked to guard against commits being submitted under a trusted identity the submitter does not control. If this PR is a legitimate cherry-pick, release-engineering submission, or mailing-list-style patch delivery, the repository maintainer can opt out of this check by setting require-opener-as-author: 'false' on the CLA-assistant step in the repository's workflow.


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document v2.2 and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f4a7d0da-e83c-4026-8992-a10d9bca201d

📥 Commits

Reviewing files that changed from the base of the PR and between 50b7f39 and df18d1a.

📒 Files selected for processing (2)
  • ios/scripts/resolve_testflight_distribution.py
  • tests/test_ios_testflight_pro_distribution.py

Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The iOS TestFlight workflow adds an external beta lane with hourly scheduling, manual dispatch, separate metadata artifacts, external upload arguments, dSYM handling, resolver support, and routing tests.

Changes

External TestFlight lane

Layer / File(s) Summary
External distribution decision
ios/scripts/resolve_testflight_distribution.py, tests/test_ios_testflight_pro_distribution.py
resolve_distribution accepts the external variant and returns the beta bundle, external assignment, dedicated metadata artifact, and checked_in_version mode. Tests cover automatic resolution, recovery overrides, rejected demo overrides, and workflow arguments.
External workflow scheduling and upload
.github/workflows/ios-testflight.yml, ios/README.md
The workflow adds an hourly external schedule, dispatch option, variant mapping, upload arguments, metadata output, dSYM gates, and Sentry upload handling. The README documents external beta uploads and override behavior.
External routing validation
tests/test_ios_testflight_main_push_filter.py
Routing tests use named schedules and verify external artifact selection, variant output, unchanged-upload filtering, and existing internal and demo routing.

Priority: ⬆️ High

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant decide
  participant resolve_distribution
  participant upload_testflight
  GitHubActions->>decide: select external schedule or dispatch variant
  decide->>resolve_distribution: resolve external distribution
  resolve_distribution-->>decide: return external metadata and upload mode
  decide->>upload_testflight: pass INPUT_VARIANT and --external
  upload_testflight-->>GitHubActions: upload external beta artifacts
Loading

Merge Risk: ⚪ Minimal · up to df18d

The external lane wiring and recovery override are consistent with the documented workflow, with no actionable merge-blocking risk identified.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #12366 requires an available external TestFlight build with the #10473 readiness fix and a clear update path. The workflow adds an independent hourly external lane and an external manual varia…
Out of Scope Changes check ✅ Passed The workflow, distribution resolver, documentation, and tests support the external beta release and recovery path required by #12366. Separate build history, dSYM handling, external group assignment, …
Cmux Swift Actor Isolation ✅ Passed PASS. The review-scoped diff changes only GitHub Actions YAML, Markdown, Python scripts, and Python tests. It contains no Swift files or Swift actor-isolation constructs. Therefore, the custom check h…
Cmux Swift Blocking Runtime ✅ Passed The authoritative pull-request diff changes only one YAML workflow, one Markdown file, three Python files, and no Swift or Objective-C source. The changed-file search found zero Swift paths, and the s…
Cmux Browser Automation Off-Main ✅ Passed PASS: The reviewed range changes only the iOS TestFlight workflow, documentation, Python distribution logic, and related tests. The rule's scoped files, Sources/TerminalController.swift and `Package…
Cmux Expensive Synchronous Load ✅ Passed The authoritative pull-request diff changes only a GitHub Actions workflow, iOS documentation, a Python distribution resolver, and Python tests. It contains no Swift, Objective-C, or Objective-C++ pro…
Cmux Cache Substitution Correctness ✅ Passed PASS. The pull request changes a GitHub Actions YAML workflow, Python scripts/tests, and documentation. It does not change production Swift, TypeScript, or JavaScript. The workflow's history lookup st…
Cmux No Hacky Sleeps ✅ Passed PASS. The PR adds an external cron route and distribution metadata, but it does not add a sleep, timer, polling loop, retry delay, or wall-clock wait in covered production scripts. The only existing `…
Cmux Algorithmic Complexity ✅ Passed No algorithmic-complexity failure is introduced. The production diff adds a constant-time variant mapping, a three-item variant membership check, external-lane conditions, and a constant-size distribu…
Cmux Swift Concurrency ✅ Passed The pull-request diff changes only one GitHub Actions workflow, documentation, Python distribution logic, and Python tests. The authoritative diff contains no Swift files or Swift concurrency construc…
Cmux Swift @Concurrent ✅ Passed PASS: The authoritative pull-request diff changes only GitHub Actions YAML, Markdown, Python, and Python tests. It contains no Swift source changes and no introduced @concurrent, nonisolated async…
Cmux Swift Package Boundaries ✅ Passed PASS: The authoritative review diff changes five files, all workflow, Markdown, or Python files. It contains no .swift files and introduces no Swift production logic or SwiftPM boundary changes. The…
Cmux Swiftpm Lockfiles ✅ Passed PASS. The PR changes only the TestFlight workflow, README, resolver script, and tests. The authoritative diff contains no Package.swift, package-local Package.resolved, .gitignore, Xcode project…
Cmux Swift Logging ✅ Passed PASS. The pull request changes only GitHub Actions YAML, Markdown, Python, and Python tests; git diff ... -- '*.swift' reports no changed Swift files. The added echo/print output is workflow or …
Cmux User-Facing Error Privacy ✅ Passed PASS. The authoritative diff changes only the TestFlight workflow, iOS operational documentation, a CI distribution resolver, and tests. The new resolver error remains CI validation output and exposes…
Cmux Full Internationalization ✅ Passed PASS. The authoritative diff changes only the TestFlight workflow, an iOS operational README, an automation resolver, and tests. It does not touch Swift UI, string catalogs, Info.plist localization, w…
Cmux Swiftui State Layout ✅ Passed PASS. The authoritative pull-request diff changes only workflow YAML, Markdown, Python, and Python test files. It contains no Swift or SwiftUI changes, so none of the state, layout, row-store, or rend…
Cmux Architecture Rethink ✅ Passed PASS: The pull request changes only GitHub Actions YAML, Markdown, Python, and Python test files. The authoritative diff contains no Swift, Objective-C, or Objective-C++ source changes. Therefore the …
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PASS: The authoritative PR diff changes only one GitHub Actions workflow, README, Python resolver, and Python tests. It contains no Swift changes and adds or modifies no NSWindow, NSPanel, NSWindowCon…
Cmux Source Artifacts ✅ Passed The authoritative diff changes only a GitHub Actions workflow, iOS documentation, a Python release-resolution script, and two Python test files. These are intentional config, source, documentation, an…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The reviewed diff changes only a GitHub Actions workflow, Markdown documentation, Python code, and Python tests. It contains no Swift file under a production Sources/ path, so the no-test-or-debug-s…
Cmux No Ambient Global State ✅ Passed PASS: The pull request changes only one YAML file, one Markdown file, and three Python files. The authoritative diff contains no .swift paths, so it introduces no production Swift global state cover…
Title check ✅ Passed The title clearly and concisely describes the main change: keeping the external TestFlight beta current.
Description check ✅ Passed The description explains the problem, resulting behavior, implementation scope, testing performed, changelog entry, and unverified macOS build check. It does not use the template's exact Summary and T…
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch issue-12366-ios-tailscale-pairing

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo teamleaderleo added S3: minor Wrong behavior with a workaround area: updates Install, Homebrew, updates, nightly and release builds, signing area: build-and-ci Build system, CI workflows, test infrastructure labels Sep 30, 2026
@teamleaderleo

Copy link
Copy Markdown
Collaborator

The scheduled external beta lane is still absent from current main; leaving this open for release review.

@teamleaderleo

teamleaderleo commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Thanks @brodynies, this is held for a design call on the TestFlight release policy. The CLA check and CI evidence also need to clear before that discussion :)

This branch was successfully deployed

2 active deployments
Preview – cmux166 — df18d1ae Deployed Sep 12, 2026 by vercel[bot]
Preview – cmux41 — df18d1ae Deployed Sep 12, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: build-and-ci Build system, CI workflows, test infrastructure area: updates Install, Homebrew, updates, nightly and release builds, signing S3: minor Wrong behavior with a workaround

Projects

None yet

Development

Successfully merging this pull request may close these issues.

iOS external beta: Tailscale QR pairing fails before ready; no update offered for #10473

3 participants