Skip to content

Fix Iroh framework metadata for TestFlight - #8147

Merged
azooz2003-bit merged 4 commits into
mainfrom
feat-iroh-ffi-min-os
Jul 15, 2026
Merged

azooz2003-bit merged 4 commits into
mainfrom
feat-iroh-ffi-min-os

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 15, 2026 •

Copy link
Copy Markdown
Collaborator

Fix the App Store Connect 90530/90360 rejection caused by Iroh.framework missing MinimumOSVersion.

  • pin published iroh-ffi 1.0.2-cmux.2 in every SwiftPM lockfile
  • reject malformed embedded frameworks before uploading a signed IPA
  • keep the regression test and fix in separate commits

Verification:

  • published artifact attestation and SHA-256 verified
  • iOS device/simulator plists report MinimumOSVersion 17.5
  • macOS plist reports LSMinimumSystemVersion 14.0
  • python3 tests/test_ios_appstore_lane_identity.py
  • tagged macOS build irfin launched on Iroh 1.0.2-cmux.2

View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Summary by cubic

Fixes App Store Connect rejections (90530/90360) by ensuring embedded frameworks declare MinimumOSVersion and by pinning the Iroh FFI build. Prevents bad IPAs from being uploaded to TestFlight.

  • Bug Fixes

    • Add upload-time validation to ios/scripts/upload-testflight.sh to fail if any embedded .framework lacks a valid MinimumOSVersion (names the offending framework).
    • Add a regression test that simulates a missing MinimumOSVersion and verifies the script rejects the IPA.
  • Dependencies

    • Pin iroh-ffi to 1.0.2-cmux.2 across all SwiftPM lockfiles.

Written for commit 8a0ab61. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes

    • iOS TestFlight uploads now validate minimum OS version metadata for all bundled frameworks.
    • Uploads are rejected when framework metadata is missing, malformed, or specifies an unsupported OS version.
  • Tests

    • Added coverage confirming uploads fail when an embedded framework lacks minimum OS version metadata.
  • Chores

    • Updated the bundled transport dependency to a newer compatible release.

@vercel

vercel Bot commented Jul 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Building Building Preview, Comment Jul 15, 2026 6:03am
cmux-staging Building Building Preview, Comment Jul 15, 2026 6:03am

@coderabbitai

coderabbitai Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: d9f024d7-e0d8-49cb-a8d4-cb42183703ce

📥 Commits

Reviewing files that changed from the base of the PR and between 9b93e97 and 8a0ab61.

⛔ Files ignored due to path filters (3)
  • Packages/Shared/CmuxIrohTransport/Package.resolved is excluded by !**/Package.resolved
  • cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved is excluded by !**/Package.resolved
  • ios/cmuxPackage/Package.resolved is excluded by !**/Package.resolved
📒 Files selected for processing (3)
  • Packages/Shared/CmuxIrohTransport/Package.swift
  • ios/scripts/upload-testflight.sh
  • tests/test_ios_appstore_lane_identity.py

📝 Walkthrough

Walkthrough

The PR pins iroh-ffi to 1.0.2-cmux.2 and adds IPA validation for embedded framework MinimumOSVersion metadata, with a test covering rejection of frameworks missing that field.

Changes

iOS framework validation

Layer / File(s) Summary
iroh-ffi dependency pin
Packages/Shared/CmuxIrohTransport/Package.swift
Updates the exact iroh-ffi dependency from 1.0.2-cmux.1 to 1.0.2-cmux.2.
Framework metadata validation and rejection test
ios/scripts/upload-testflight.sh, tests/test_ios_appstore_lane_identity.py
Validates embedded framework Info.plist files for MinimumOSVersion, gates the upload flow on valid metadata, and tests rejection when Iroh.framework omits the field.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

  • manaflow-ai/cmux#8131: Adds related iOS upload-time MinimumOSVersion validation and corresponding exported IPA test coverage.

Suggested reviewers: lawrencecchen

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-iroh-ffi-min-os

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@azooz2003-bit
azooz2003-bit merged commit ee8da75 into main Jul 15, 2026
9 of 12 checks passed
@azooz2003-bit
azooz2003-bit deleted the feat-iroh-ffi-min-os branch July 15, 2026 06:04
@greptile-apps

greptile-apps Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR fixes App Store Connect rejection errors 90530/90360 by bumping iroh-ffi from 1.0.2-cmux.1 to 1.0.2-cmux.2 (which adds MinimumOSVersion to the embedded Iroh.xcframework metadata) and adding a pre-upload gate that validates every embedded framework's Info.plist before the IPA reaches App Store Connect.

  • All three cmux-owned Package.resolved lockfiles (CmuxIrohTransport, the Xcode workspace root, and ios/cmuxPackage) are updated in sync, satisfying the SwiftPM lockfile policy.
  • verify_ipa_framework_minimum_os_versions follows the same extract-inspect-cleanup pattern as the existing verify_ipa_aps_environment_production and runs before the EXPORT_ONLY early exit so the regression test can exercise it without a real upload.
  • The regression test correctly uses f-string {{...}} escaping to emit literal {...} in the generated fake xcodebuild binary, and checks both the exit code and the named-framework error message.

Confidence Score: 5/5

Safe to merge — the changes are narrowly scoped to bumping the iroh-ffi lockfiles and inserting a pre-upload validation gate that exits early on bad framework metadata.

All three cmux-owned Package.resolved files are updated together with the Package.swift constraint change. The new shell validation function follows the same extract-inspect-cleanup pattern as the existing verify_* functions, cleans up its temp directory in every branch, and is correctly placed before the EXPORT_ONLY early-exit so the regression test exercises it end-to-end. The test's {{...}} braces are correctly escaped inside an f-string and produce valid dict literals in the generated fake binary. No logic errors, no resource leaks, no lockfile drift.

No files require special attention.

Important Files Changed

Filename Overview
Packages/Shared/CmuxIrohTransport/Package.resolved Bumps iroh-ffi pin from 1.0.2-cmux.1 to 1.0.2-cmux.2 with the corresponding new revision hash; lockfile is consistent with Package.swift change
Packages/Shared/CmuxIrohTransport/Package.swift Updates exact version constraint from 1.0.2-cmux.1 to 1.0.2-cmux.2 to pull the MinimumOSVersion-bearing Iroh.xcframework
cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved Root Xcode workspace lockfile updated to iroh-ffi 1.0.2-cmux.2, keeping it in sync with the package-local lockfile
ios/cmuxPackage/Package.resolved iOS package lockfile updated to iroh-ffi 1.0.2-cmux.2; all three cmux-owned Package.resolved files now agree
ios/scripts/upload-testflight.sh Adds verify_ipa_framework_minimum_os_versions before the upload gate; correctly follows the existing verify_ipa_* pattern with proper workdir cleanup in every error path and runs before the EXPORT_ONLY early exit so the regression test exercises it
tests/test_ios_appstore_lane_identity.py Adds regression test for the missing-MinimumOSVersion rejection; the {{...}} syntax in the fake-xcodebuild f-string is correct escaped-brace syntax that produces literal dict literals in the generated script

Sequence Diagram

%%{init: {'theme': 'neutral'}}%%
sequenceDiagram
    participant Script as upload-testflight.sh
    participant XCB as xcodebuild (export)
    participant PB as PlistBuddy
    participant ASC as App Store Connect

    Script->>XCB: -exportArchive
    XCB-->>Script: IPA (with embedded frameworks)
    Script->>Script: verify_ipa_aps_environment_production (manual signing skips)
    Script->>Script: verify_ipa_framework_minimum_os_versions
    Note over Script: unzip IPA → find *.framework dirs
    Script->>PB: Print :MinimumOSVersion (per framework)
    alt MinimumOSVersion absent or malformed
        PB-->>Script: empty / error
        Script-->>Script: exit 1 (refuse upload)
    else MinimumOSVersion present and valid
        PB-->>Script: e.g. "17.5"
        Script->>Script: verify_ipa_bundle_identity
        Script->>ASC: altool / asc upload
    end
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
sequenceDiagram
    participant Script as upload-testflight.sh
    participant XCB as xcodebuild (export)
    participant PB as PlistBuddy
    participant ASC as App Store Connect

    Script->>XCB: -exportArchive
    XCB-->>Script: IPA (with embedded frameworks)
    Script->>Script: verify_ipa_aps_environment_production (manual signing skips)
    Script->>Script: verify_ipa_framework_minimum_os_versions
    Note over Script: unzip IPA → find *.framework dirs
    Script->>PB: Print :MinimumOSVersion (per framework)
    alt MinimumOSVersion absent or malformed
        PB-->>Script: empty / error
        Script-->>Script: exit 1 (refuse upload)
    else MinimumOSVersion present and valid
        PB-->>Script: e.g. "17.5"
        Script->>Script: verify_ipa_bundle_identity
        Script->>ASC: altool / asc upload
    end
Loading

Reviews (1): Last reviewed commit: "fix(ios): pin Iroh framework with deploy..." | Re-trigger Greptile

This branch was successfully deployed

1 active deployment
Preview – cmux — 8a0ab612 Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant