From 1357a2b1ccfec6d6b4e7d8ba23ffa72513cc66b5 Mon Sep 17 00:00:00 2001 From: PJ Date: Mon, 8 Jun 2026 23:29:52 +0530 Subject: [PATCH] fix(ioscompanion): resolve signing key path to absolute xcodebuild's -authenticationKeyPath requires an absolute path, but .env files commonly carry a repo-relative one. Resolve it against the working directory before the stat so a relative ASC_API_KEY_PATH still signs. --- internal/driver/ioscompanion/devicerunner.go | 12 ++++++++---- .../driver/ioscompanion/devicerunner_test.go | 19 +++++++++++++++++++ 2 files changed, 27 insertions(+), 4 deletions(-) diff --git a/internal/driver/ioscompanion/devicerunner.go b/internal/driver/ioscompanion/devicerunner.go index 126a01e..67566a4 100644 --- a/internal/driver/ioscompanion/devicerunner.go +++ b/internal/driver/ioscompanion/devicerunner.go @@ -67,10 +67,14 @@ func readSigningCredentials() (signingCredentials, error) { if len(missing) > 0 { return creds, fmt.Errorf("device signing requires environment variables: %s", strings.Join(missing, ", ")) } - if creds.authKeyPath != "" { - if _, err := os.Stat(creds.authKeyPath); err != nil { - return creds, fmt.Errorf("App Store Connect key not found at %s: %w", creds.authKeyPath, err) - } + // xcodebuild's -authenticationKeyPath demands an absolute path, but .env + // files commonly carry a repo-relative one. Resolve it against the working + // directory before the stat so a relative key still works. + if absolute, err := filepath.Abs(creds.authKeyPath); err == nil { + creds.authKeyPath = absolute + } + if _, err := os.Stat(creds.authKeyPath); err != nil { + return creds, fmt.Errorf("App Store Connect key not found at %s: %w", creds.authKeyPath, err) } return creds, nil } diff --git a/internal/driver/ioscompanion/devicerunner_test.go b/internal/driver/ioscompanion/devicerunner_test.go index a780b85..1382243 100644 --- a/internal/driver/ioscompanion/devicerunner_test.go +++ b/internal/driver/ioscompanion/devicerunner_test.go @@ -147,6 +147,25 @@ func TestReadSigningCredentialsAcceptsPresentKey(t *testing.T) { } } +func TestReadSigningCredentialsResolvesRelativeKeyPath(t *testing.T) { + dir := t.TempDir() + t.Chdir(dir) + if err := os.WriteFile("AuthKey.p8", []byte("key"), 0o600); err != nil { + t.Fatal(err) + } + t.Setenv(envTeam, "TEAM1") + t.Setenv(envAuthKeyID, "KID") + t.Setenv(envAuthIssuer, "ISS") + t.Setenv(envAuthKeyPath, "AuthKey.p8") + creds, err := readSigningCredentials() + if err != nil { + t.Fatal(err) + } + if !filepath.IsAbs(creds.authKeyPath) { + t.Fatalf("authKeyPath = %q, want an absolute path for xcodebuild", creds.authKeyPath) + } +} + func TestSourceHashChangesWithSources(t *testing.T) { dir := t.TempDir() if err := os.MkdirAll(filepath.Join(dir, "Sources"), 0o755); err != nil {