From 7b5bdc9d0bd5c5dcae2f336f071118dcfac697dc Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Thu, 2 Jul 2026 21:54:40 -0700 Subject: [PATCH 1/3] =?UTF-8?q?nvrsion:=20Add:=20Adjust=20Canary=20Build?= =?UTF-8?q?=20Auto-Update=20to=20run=20every=20hour,=20fix=20Keychain=20pe?= =?UTF-8?q?rmission=20audit=20by=20updating=20files:=20ControlAuth.swift,?= =?UTF-8?q?=20GitHubCredentials.swift,=20HeartbeatReporter.swift,=20Keycha?= =?UTF-8?q?inOwnedAccess.swift,=20HostIdentityStore.swift,=20PushRelayClie?= =?UTF-8?q?nt.swift,=20refactor=20Remote=20Build=20Icon=20to=20use=20?= =?UTF-8?q?=E2=80=9Cbell.and.waves.left.and.right.fill=E2=80=9D=20in=20ios?= =?UTF-8?q?/NucleicRemote/NucleicRemote/Views/BuildBanner.swift,=20add=20a?= =?UTF-8?q?=20Remote=20Release=20Channel=20Check=20in=20AppStore.swift,=20?= =?UTF-8?q?Sync/ConnectionHandler.swift,=20Sync/SyncHostBridge.swift,=20Sy?= =?UTF-8?q?nc/ReleaseChannel.swift,=20Sync/SyncClient.swift,=20Sync/WireMe?= =?UTF-8?q?ssages.swift,=20tests/SyncHostTests.swift,=20tests/SyncTestSupp?= =?UTF-8?q?ort.swift,=20and=20align=20build=20number=20hash=20in=20ios/Nuc?= =?UTF-8?q?leicRemote/NucleicRemote.xcodeproj/project.pbxproj,=20ios/Nucle?= =?UTF-8?q?icRemote/NucleicRemote/Info.plist,=20ios/NucleicRemote/NucleicR?= =?UTF-8?q?emote/Views/BuildBanner.swift.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nucleic-Promote: 1 Co-authored-by: Nucleic --- .../NucleicRemote.xcodeproj/project.pbxproj | 25 +++++++++++++ NucleicRemote/NucleicRemote/Info.plist | 5 +++ .../NucleicRemote/Models/RemoteStore.swift | 15 ++++++-- .../NucleicRemote/Views/BuildBanner.swift | 36 +++++++++++++++---- 4 files changed, 73 insertions(+), 8 deletions(-) diff --git a/NucleicRemote/NucleicRemote.xcodeproj/project.pbxproj b/NucleicRemote/NucleicRemote.xcodeproj/project.pbxproj index 48ce307..dcd9688 100644 --- a/NucleicRemote/NucleicRemote.xcodeproj/project.pbxproj +++ b/NucleicRemote/NucleicRemote.xcodeproj/project.pbxproj @@ -136,6 +136,7 @@ BP00000000000000000003 /* Frameworks */, BP00000000000000000004 /* Resources */, BP00000000000000000005 /* Embed Foundation Extensions */, + BP00000000000000000009 /* Stamp git commit into Info.plist */, ); buildRules = ( ); @@ -235,6 +236,24 @@ }; /* End PBXResourcesBuildPhase section */ +/* Begin PBXShellScriptBuildPhase section */ + BP00000000000000000009 /* Stamp git commit into Info.plist */ = { + isa = PBXShellScriptBuildPhase; + alwaysOutOfDate = 1; + buildActionMask = 2147483647; + files = ( + ); + inputPaths = ( + ); + name = "Stamp git commit into Info.plist"; + outputPaths = ( + ); + runOnlyForDeploymentPostprocessing = 0; + shellPath = /bin/sh; + shellScript = "# Stamp the short git commit into the built Info.plist (NucleicCommit key), the iOS\n# mirror of the Mac's EmbedGitCommit prebuild plugin. Runs before code signing so the\n# signature covers the stamped value; alwaysOutOfDate keeps it fresh on every build. A\n# trailing \"+\" marks a dirty tree; \"unknown\" (no git) makes the app fall back to the\n# bundle build number.\nset -e\nplist=\"${TARGET_BUILD_DIR}/${INFOPLIST_PATH}\"\n[ -f \"$plist\" ] || exit 0\nhash=$(git -C \"${SRCROOT}\" rev-parse --short HEAD 2>/dev/null || echo unknown)\nif [ \"$hash\" != unknown ] && [ -n \"$(git -C \"${SRCROOT}\" status --porcelain 2>/dev/null)\" ]; then\n hash=\"${hash}+\"\nfi\n/usr/libexec/PlistBuddy -c \"Set :NucleicCommit $hash\" \"$plist\" 2>/dev/null || /usr/libexec/PlistBuddy -c \"Add :NucleicCommit string $hash\" \"$plist\"\n"; + }; +/* End PBXShellScriptBuildPhase section */ + /* Begin PBXSourcesBuildPhase section */ BP00000000000000000002 /* Sources */ = { isa = PBXSourcesBuildPhase; @@ -305,6 +324,9 @@ CURRENT_PROJECT_VERSION = 1; DEVELOPMENT_TEAM = L7UDTQ6F5W; ENABLE_PREVIEWS = YES; + // The "Stamp git commit into Info.plist" phase shells out to git and rewrites the + // built Info.plist, both of which script sandboxing would block. + ENABLE_USER_SCRIPT_SANDBOXING = NO; GENERATE_INFOPLIST_FILE = YES; INFOPLIST_FILE = NucleicRemote/Info.plist; INFOPLIST_KEY_CFBundleDisplayName = "Nucleic$(NUCLEIC_NAME_SUFFIX)"; @@ -349,6 +371,9 @@ CURRENT_PROJECT_VERSION = 1; DEVELOPMENT_TEAM = L7UDTQ6F5W; ENABLE_PREVIEWS = YES; + // The "Stamp git commit into Info.plist" phase shells out to git and rewrites the + // built Info.plist, both of which script sandboxing would block. + ENABLE_USER_SCRIPT_SANDBOXING = NO; GENERATE_INFOPLIST_FILE = YES; INFOPLIST_FILE = NucleicRemote/Info.plist; INFOPLIST_KEY_CFBundleDisplayName = "Nucleic$(NUCLEIC_NAME_SUFFIX)"; diff --git a/NucleicRemote/NucleicRemote/Info.plist b/NucleicRemote/NucleicRemote/Info.plist index bb77515..6b1a38f 100644 --- a/NucleicRemote/NucleicRemote/Info.plist +++ b/NucleicRemote/NucleicRemote/Info.plist @@ -8,6 +8,11 @@ NucleicChannel $(NUCLEIC_CHANNEL) + + NucleicCommit + NSSupportsLiveActivities