Repository navigation
fix(ios): scope TestFlight notification identity verification - #16510
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Merge receipt for
Labeled |
aa4d529 fix: drop the uncompilable CLI half of the Cloud link-failure copy test (manaflow-ai#16499) 0ce48f1 fix(ios): accept system extension in app store verification (manaflow-ai#16510) 12be747 fix(ios): expose cloud tab environment in release builds (manaflow-ai#16505) 920ff39 docs(cloud): cover advertised VM socket methods (manaflow-ai#16500) 6e34195 fix(socket): advertise dispatched Cloud methods (manaflow-ai#16460) # Conflicts: # .github/workflows/ci-guards.yml
Changelog
Fixed
Problem
The official
com.cmux.apparchive and export succeeded, but the TestFlight upload stopped in the post-sign verification because it applied NotificationService's application-identifier check toCloudVPN.appex. CloudVPN is a system-network extension with a different entitlement contract.Fix
Keep strict code-signature verification for the notification service extension, but scope its notification identity check to
NotificationService.appexand leave CloudVPN to its own signature contract.Validation
bash -n ios/scripts/upload-testflight.shpython3 -m unittest ios.tests.test_testflight_prepare_onlynode --test ios/tests/tagged-device-entitlements.test.mjsNeed help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes TestFlight uploads failing at post-sign verification by scoping the notification identity check to
NotificationService.appexonly.Previously the verifier applied the notification service's
application-identifier/team check to every.appex, includingCloudVPN.appex, which is a system-network extension with a different entitlement contract. Now onlyNotificationService.appexis identity-checked,CloudVPN.appexis left to its own signature contract, and a missingNotificationService.appexfails the upload.Written for commit a153d77. Summary will update on new commits.