fix: ship app store-safe apple artifacts - #265
Conversation
Build stable MAUI package artifacts with Xcode 26.6 and verify every embedded Apple slice before publication. Rebuild Godot's precompiled iOS frameworks with the accepted SDK, reject coverage-instrumented release binaries, and document the patch releases.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Warning Review limit reached
Next review available in: 33 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (11)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This pull request addresses App Store submission rejections caused by MAUI (and other framework) releases embedding Apple binaries built with a non–App Store accepted Xcode/SDK. It enforces a stable toolchain lane for producing distributable Apple artifacts while keeping an Xcode 27 compatibility lane for source validation, and updates documentation/release notes accordingly.
Changes:
- Split MAUI CI/release workflows to build App Store–safe XCFramework sidecars on
macos-26with pinned Xcode/SDK/LD versions, while retainingxcode-27validation lanes. - Add/extend toolchain provenance verification scripts to reject SDK drift, unexpected linker provenance, and coverage-instrumented binaries.
- Add documentation updates and a release-note entry for the patch releases.
Reviewed changes
Copilot reviewed 9 out of 12 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| scripts/audit-non-godot-parity.mjs | Adds parity/audit assertions ensuring MAUI/Godot pipelines pin the stable App Store toolchain and run provenance verification. |
| packages/docs/src/pages/docs/updates/releases.tsx | Adds a release-note entry and links for the App Store toolchain patch releases. |
| packages/apple/scripts/verify-app-store-xcframework.sh | New verifier script for MAUI-packaged XCFramework toolchain/SDK/linker provenance and coverage instrumentation. |
| libraries/maui-iap/README.md | Updates MAUI docs to describe the stable-toolchain policy and Xcode 27 being validation-only. |
| libraries/godot-iap/scripts/verify-ios-toolchain.sh | Updates Godot iOS framework provenance verification to enforce stable SDK/LD and reject coverage instrumentation. |
| libraries/godot-iap/README.md | Updates Godot docs to reflect stable App Store toolchain requirements and behavior differences. |
| libraries/godot-iap/Makefile | Disables Swift/Clang coverage instrumentation in release framework builds. |
| .github/workflows/release-maui.yml | Pins stable App Store toolchain for publish artifacts and adds provenance verification. |
| .github/workflows/ci-maui-iap.yml | Adds a dedicated stable App Store artifact job and broadens path filters to include new scripts. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 ESLint
ESLint install failed. For unrecoverable errors, disable the tool in CodeRabbit configuration. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 9 out of 12 changed files in this pull request and generated no new comments.
Suppressed comments (1)
libraries/godot-iap/scripts/verify-ios-toolchain.sh:22
- The SDK provenance check only verifies that some
sdkline matchesEXPECTED_SDK_VERSION. If thevtool -show-buildoutput contains multiple SDK entries (e.g., multiple LC_BUILD_VERSION blocks/slices) and any of them drift, this can still pass. It should fail if any recorded SDK differs, and also fail if no SDK entry exists (consistent with the XCFramework verifier).
if ! awk -v expected="$EXPECTED_SDK_VERSION" \
'$1 == "sdk" && $2 == expected { found = 1 } END { exit found ? 0 : 1 }' \
<<<"$build_info"; then
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Release and deployment verification is complete.
|
Summary
Closes #264.
Changes
MAUI release safety
macos-26with Xcode 26.6.Godot precompiled frameworks
Documentation
Test plan
bun run audit:paritybun run audit:docsand 38 docs audit testsbun run audit:release-stateand 18 release-policy testsgit diff --checkPreview
Watch the release-notes page preview. The primary behavior change is enforced in build and release pipelines; the test plan above records the artifact-level proof.