Run failed at 'brew install xcodegen node' AFTER both formulae upgraded
successfully under ARM: brew's 'installed dependents check' then tried to
rebuild gemini-cli (0.40.1 -> 0.46.0, an unrelated dev tool on the runner
that depends on node) and exited 1.
Verified node is NOT used by any step in pr-iphone-deploy.yml — only
xcodegen is. The only node references in the repo are in
scripts/prepare-release.cjs and scripts/verify-admin-web-docker.sh,
neither of which runs in this workflow. Node was a historical leftover.
Drop node from the brew install. No node upgrade = no dependents check =
no gemini-cli rebuild. Also sync AGENTS.md §5 step 4.
Two related fixes to the Install tools / Deploy steps:
1. Rosetta/ARM-prefix conflict (unblocks run #142 failure)
Run #142 failed at 'brew install':
Cannot install under Rosetta 2 in ARM default prefix (/opt/homebrew)!
The act_runner shell runs under Rosetta 2 on Apple Silicon, but Homebrew
is installed natively in /opt/homebrew (ARM prefix). Brew refuses to mix
architectures and exits 1 — surfaced now because xcodegen/node registered
as outdated and brew tried to upgrade them.
Prefix the brew call with 'arch -arm64' (brew's own suggested workaround)
so the subprocess runs natively regardless of the parent shell's arch.
2. Drop ios-deploy, use xcrun devicectl only
The deploy step previously tried devicectl (WiFi) first, then fell back
to ios-deploy (USB). devicectl handles both network and wired discovery
natively, so the separate USB-fallback tool is unnecessary — removed
from the brew install and the deploy step.
Implication: a devicectl failure = deploy failure (no second tool to
fall back to). Acceptable: devicectl covers both transports.
Also updates workflow name/job labels and the 'Prêt à tester' comment to
drop 'WiFi/USB' wording, and aligns AGENTS.md §5 step 4 (arch -arm64 +
tool list) and step 7 (devicectl only).
Add a paths: filter to the pull_request trigger so the iOS build+deploy
only fires when the PR actually touches:
- tabatago-swift/** (the iOS/watchOS app source)
- .github/workflows/pr-iphone-deploy.yml (this workflow itself)
PRs touching only AGENTS.md, admin-web/, youtube-worker/, supabase/,
docs/, or root config no longer spin up the macOS runner — no point
rebuilding and deploying an unchanged .app.
Including the workflow file itself in paths: ensures a PR that only
edits the workflow logic still triggers it (so this branch's own PR
will run to validate the changes).
Rewrite AGENTS.md to match the corrected pr-iphone-deploy.yml:
§5 Workflow:
- Clean step: 'GARDE build/spm-cache' (not ../build/spm-cache), explicit
warning never to 'rm -rf build/', note that Xcode global cache is spared.
- New step 5: write Secrets.xcconfig from Gitea secrets before xcodegen.
- Scheme lists 4 targets (TabataGo, TabataGoWidget, TabataGoWatch,
TabataGoWatchWidget) — clarify TabataGoWidget is iOS, not watchOS.
- wait-approval: re-fetches all comments each cycle, regex \bLGTM\b/\bKO\b
anywhere in body, squash-merge.
- Document concurrency block and timeouts.
§5 Secrets table:
- Replace false 'Injectés via Config/Secrets.xcconfig → Info.plist' with
the real flow (CI writes file from secrets, Info.plist reads $(VAR)).
- Add historical-exposure warning: Secrets.xcconfig was committed before
the gitignore rule; key rotation recommended.
§5 Pitfalls + §8 anti-patterns:
- 'rm -rf build/' (not just 'rm -rf cache SPM').
- Don't nuke ~/Library/Caches/com.apple.dt.Xcode.
- permissions: block is intentionally absent (no-op under Gitea API).
- Don't remove concurrency block.
- Don't anchor LGTM grep to body start.
- {"Do":"squash"} not {"Do":"merge"}.
- Scheme must list all 4 targets.
§7 rule #9: expanded with the CI-writes-file flow.
The TabataGo scheme only listed TabataGo + TabataGoWidget (iOS), so
xcodebuild -scheme TabataGo never compiled the watchOS app in CI. Add
TabataGoWatch + TabataGoWatchWidget to the build targets so watch-side
breakage is caught before deploy.
Note: TabataGoWidget is a real iOS widget target (defined at project.yml
line 165, app-extension/iOS), NOT a phantom — the prior review was wrong
on that point. The real gap was the missing watch targets.
Embed deps were already correct (TabataGo embeds TabataGoWatch, which
embeds TabataGoWatchWidget). Verified locally with xcodegen 2.45.4:
the generated xcscheme now lists all 4 BlueprintNames.
⚠️ Risk: if the watch target has latent build issues (never compiled in
CI before), this will surface them on the next PR. Desirable — catch
before merge, not in the field.
10 fixes to .github/workflows/pr-iphone-deploy.yml:
Cache & build hygiene:
- Stop deleting build/spm-cache (was wiped by 'rm -rf build/'); clean only
build/derived. RevenueCat (~1.1 GiB) is finally actually preserved.
- Stop nuking ~/Library/Caches/com.apple.dt.Xcode (slows every next build).
- Drop '|| true' on brew install — fail loudly if brew is down.
- Bump build-deploy timeout 20m → 30m for cold builds.
Secrets:
- New step writes Config/Secrets.xcconfig from Gitea secrets (SUPABASE_URL,
SUPABASE_ANON_KEY, REVENUECAT_API_KEY, POSTHOG_API_KEY) before xcodegen.
Preflight fails loud if a required secret is missing. Heredoc body at
column 0 (xcconfig keys are whitespace-sensitive).
LGTM/KO handling:
- Regex now matches anywhere in body with word boundary: \bLGTM\b / \bKO\b.
'Tested, LGTM!' counts; 'KOM' / 'LGTMX' / 'OK' do not.
- Re-fetch ALL comments each poll (not since_id) to catch edits.
- Squash-merge ({"Do":"squash"}) instead of merge commit.
Workflow structure:
- Add concurrency block (per-PR, cancel-in-progress) — prevents double-merge
and stacked pipelines on successive pushes.
- Remove no-op 'permissions:' block (all mutations go via Gitea API with
PR_API_TOKEN, native GITHUB_TOKEN is never used).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.