xworkmate-app/scripts/ci/build_matrix_artifacts.sh
Haitao Pan c98bce9dde fix(ci): keep macos/ios build lanes running when Apple signing secrets are missing
The release preflight used to set should_build_platform=false whenever any
Apple signing secret was unset, which silently skipped the entire macos dmg
and ios ipa lanes (build + upload gated on that flag). Result: releases only
shipped linux, windows and android artifacts even when the iOS/macOS lanes
were otherwise healthy.

Make the preflight always release the lane, but emit a :⚠️: and
annotate the skip_reason when a secret is missing. The iOS branch in
build_matrix_artifacts.sh now picks the signed vs unsigned build path based
on actual secret availability instead of should_release alone, so it falls
back to flutter build ios --no-codesign + zip Runner.app whenever a secret
is absent. package-flutter-mac-app.sh already handled the no-secret case
locally (ad-hoc codesign --sign -) and needs no change.

Behavior matrix:
  macos: secret present -> signed DMG; secret missing -> unsigned DMG
  ios:   secret present + release -> signed IPA
         secret present + non-release -> unsigned zip
         secret missing (any) -> unsigned zip
2026-06-05 18:39:25 +08:00

77 lines
2.1 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
cd "$repo_root"
eval "$(python3 "$repo_root/scripts/ci/build_version.py" --format shell)"
platform="${1:?platform is required}"
arch="${2:?arch is required}"
should_release="${3:-false}"
flutter pub get
case "$platform" in
linux)
bash ./scripts/package-linux.sh
;;
macos)
bash ./scripts/package-flutter-mac-app.sh
mkdir -p dist/macos
find dist -maxdepth 1 -name '*.dmg' -exec mv {} dist/macos/ \;
;;
windows)
flutter build windows --release \
--build-name="$PLATFORM_RELEASE_VERSION" \
--build-number="$BUILD_NUMBER"
pwsh -File ./scripts/package-windows-msi.ps1 -Arch "$arch"
;;
ios)
ios_signing_secrets=(
APPLE_CERT_P12_BASE64
APPLE_CERT_PASSWORD
APPLE_PROVISION_PROFILE_BASE64
APPLE_KEYCHAIN_PASSWORD
)
ios_missing=()
for var_name in "${ios_signing_secrets[@]}"; do
if [[ -z "${!var_name:-}" ]]; then
ios_missing+=("$var_name")
fi
done
if [[ "${#ios_missing[@]}" -gt 0 ]]; then
echo "Apple signing secrets unavailable (missing: ${ios_missing[*]}); building unsigned iOS app bundle."
build_unsigned_ios_bundle=1
elif [[ "$should_release" == "true" ]]; then
build_unsigned_ios_bundle=0
else
echo "Release not requested; building unsigned iOS app bundle."
build_unsigned_ios_bundle=1
fi
if [[ "$build_unsigned_ios_bundle" -eq 1 ]]; then
flutter build ios --release --no-codesign \
--build-name="$PLATFORM_RELEASE_VERSION" \
--build-number="$BUILD_NUMBER" \
--dart-define="XWORKMATE_DISPLAY_VERSION=$DISPLAY_VERSION" \
--dart-define="XWORKMATE_BUILD_NUMBER=$BUILD_NUMBER"
mkdir -p dist/ios
(
cd build/ios/iphoneos
rm -f XWorkmate.app.zip
zip -qry XWorkmate.app.zip Runner.app
mv XWorkmate.app.zip ../../../dist/ios/
)
else
bash ./scripts/package-ios-ipa.sh
fi
;;
android)
bash ./scripts/package-android-apk.sh
;;
*)
echo "Unsupported platform: $platform" >&2
exit 1
;;
esac