From 69b838ef3fb5bc02bdfb6c3ba887992c90c61e07 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Mon, 14 Sep 2026 13:39:36 +0000 Subject: [PATCH] Fix TestFlight archive signing and build numbers Ephemeral runners were minting Apple Development certs until the account hit the cap, so every archive since late July failed. Force Apple Distribution, and set CFBundleVersion to 1000+run_number so uploads beat TestFlight build 130. Co-authored-by: sanylax0 --- .github/workflows/testflight.yml | 42 ++++++++++++++++++++++++-------- project.yml | 8 ++++++ 2 files changed, 40 insertions(+), 10 deletions(-) diff --git a/.github/workflows/testflight.yml b/.github/workflows/testflight.yml index 8bca53a..ab982b6 100644 --- a/.github/workflows/testflight.yml +++ b/.github/workflows/testflight.yml @@ -10,9 +10,15 @@ # "App Manager" role) # base64 encode: base64 -i AuthKey_XXXXXXXXXX.p8 | pbcopy # -# The build number is the workflow run number (monotonic per repo), so TestFlight never -# rejects a duplicate CFBundleVersion. Uploads become available to INTERNAL testers -# automatically once App Store Connect finishes processing — no extra distribution step. +# Archive uses Apple Distribution (not Apple Development). Ephemeral GitHub runners have an +# empty keychain, so Automatic+Development minted a new development cert every run until +# the account hit Apple's cap and every archive died with "Choose a certificate to revoke" +# plus "No profiles for com.sanylax.continuity" (development profiles). +# +# CFBundleVersion is 1000 + github.run_number. TestFlight already has build 130 (Xcode Cloud, +# Jul 18) while run_number is still in the 30s — a raw run_number would be rejected as older. +# Uploads become available to INTERNAL testers automatically once App Store Connect finishes +# processing — no extra distribution step. name: TestFlight on: @@ -58,20 +64,34 @@ jobs: echo "$ASC_KEY_P8" | base64 --decode > "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" - name: Archive + env: + ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }} + ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }} run: | + set -eu + BUILD_NUMBER=$((1000 + ${{ github.run_number }})) + echo "CFBundleVersion=${BUILD_NUMBER}" xcodebuild archive \ -project Continuity.xcodeproj \ -scheme Continuity \ + -configuration Release \ -destination 'generic/platform=iOS' \ -archivePath build/Continuity.xcarchive \ - CURRENT_PROJECT_VERSION=${{ github.run_number }} \ + CURRENT_PROJECT_VERSION="$BUILD_NUMBER" \ + DEVELOPMENT_TEAM=KP832RV67A \ + CODE_SIGN_STYLE=Automatic \ + CODE_SIGN_IDENTITY="Apple Distribution" \ -allowProvisioningUpdates \ - -authenticationKeyPath "$HOME/private_keys/AuthKey_${{ secrets.ASC_KEY_ID }}.p8" \ - -authenticationKeyID "${{ secrets.ASC_KEY_ID }}" \ - -authenticationKeyIssuerID "${{ secrets.ASC_ISSUER_ID }}" + -authenticationKeyPath "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" \ + -authenticationKeyID "$ASC_KEY_ID" \ + -authenticationKeyIssuerID "$ASC_ISSUER_ID" - name: Upload to TestFlight + env: + ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }} + ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }} run: | + set -eu cat > ExportOptions.plist <<'EOF' @@ -83,6 +103,8 @@ jobs: upload signingStyle automatic + signingCertificate + Apple Distribution teamID KP832RV67A manageAppVersionAndBuildNumber @@ -95,6 +117,6 @@ jobs: -exportOptionsPlist ExportOptions.plist \ -exportPath build/export \ -allowProvisioningUpdates \ - -authenticationKeyPath "$HOME/private_keys/AuthKey_${{ secrets.ASC_KEY_ID }}.p8" \ - -authenticationKeyID "${{ secrets.ASC_KEY_ID }}" \ - -authenticationKeyIssuerID "${{ secrets.ASC_ISSUER_ID }}" + -authenticationKeyPath "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" \ + -authenticationKeyID "$ASC_KEY_ID" \ + -authenticationKeyIssuerID "$ASC_ISSUER_ID" diff --git a/project.yml b/project.yml index c4f791f..c18cb07 100644 --- a/project.yml +++ b/project.yml @@ -19,6 +19,12 @@ settings: CURRENT_PROJECT_VERSION: "2" DEVELOPMENT_TEAM: "KP832RV67A" CODE_SIGN_STYLE: Automatic + configs: + # Release archives must use Distribution. Automatic + Development on ephemeral + # CI runners minted a new Apple Development cert every TestFlight run until the + # account hit the cap ("Choose a certificate to revoke"). + Release: + CODE_SIGN_IDENTITY: Apple Distribution targets: Continuity: @@ -70,6 +76,8 @@ targets: # relying on Xcode's per-user scheme auto-creation (which xcodebuild does not perform). scheme: gatherCoverageData: false + archive: + config: Release settings: base: PRODUCT_BUNDLE_IDENTIFIER: com.sanylax.continuity