fix(ioscompanion): key the device build cache on signing identity

The cache marker hashed only sources, so switching signing team or key
reused a runner signed with the stale identity, which the device rejects at
install (0xe8008018). Fold team + key id into the cache key so a signing
change forces a rebuild.
This commit is contained in:
pj committed 2026-06-09 14:46:54 +05:30
1 parent 0a48502ab8
commit ac76fcca86
2 files changed
+47 -4

No files matched your search

@@ -168,6 +168,37 @@ func TestReadSigningCredentialsResolvesRelativeKeyPath(t *testing.T) {
}
}
func TestBuildCacheKeyChangesWithSigningIdentity(t *testing.T) {
dir := t.TempDir()
if err := os.MkdirAll(filepath.Join(dir, "Sources"), 0o755); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(dir, "Sources", "Server.swift"), []byte("v1"), 0o644); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(dir, "project.yml"), []byte("name: x"), 0o644); err != nil {
t.Fatal(err)
}
base, err := buildCacheKey(dir, signingCredentials{team: "TEAM1", authKeyID: "KID1"})
if err != nil {
t.Fatal(err)
}
otherTeam, err := buildCacheKey(dir, signingCredentials{team: "TEAM2", authKeyID: "KID1"})
if err != nil {
t.Fatal(err)
}
otherKey, err := buildCacheKey(dir, signingCredentials{team: "TEAM1", authKeyID: "KID2"})
if err != nil {
t.Fatal(err)
}
if base == otherTeam {
t.Fatal("a changed team must invalidate the cached build")
}
if base == otherKey {
t.Fatal("a changed signing key must invalidate the cached build")
}
}
func TestSourceHashChangesWithSources(t *testing.T) {
dir := t.TempDir()
if err := os.MkdirAll(filepath.Join(dir, "Sources"), 0o755); err != nil {