Repository navigation
pkg: expose signing, asc, distribute, release and ipa as a library - #28
Merged
Merged
Conversation
Interlap01
force-pushed
the
signing-pkg
branch
from
September 20, 2026 10:45
5949078 to
c8a8ac9
Compare
Another program embedding Builder (mobai-dev) could already reach the build and config packages through pkg/, but not the App Store Connect flows: `signing setup` and on-demand provisioning lived in cmd/builder, so nothing outside this module could provision a signing set or release a build. Move the non-interactive core of `signing setup` and `ios build`'s on-demand provisioning into internal/signing/sets.go as Setup and EnsureSecrets. cmd/builder keeps everything a CLI owns -- the prompts, the plan, the confirmation and the summary -- and calls them; the JSON result is now signing.SetupResult, with the failed upload carried in UploadError instead of being recomputed by the caller. signing.Commands lets an embedding CLI name its own verbs where the error messages point at `builder auth apple` / `builder signing setup`. Add pkg/asc, pkg/distribute, pkg/release, pkg/ipa and pkg/signing as alias wrappers, so values pass between them without conversion, and release.Builder stays the one-method interface a foreign build backend implements. pkg/auth grows the App Store Connect key accessors and pkg/config the distributions, profiles and signing-set names those need; auth.AppleCredentialsFromEnv is exported for a program with its own credential store. No behaviour change to any command.
Interlap01
force-pushed
the
signing-pkg
branch
from
September 20, 2026 10:48
c8a8ac9 to
ed1c903
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
signing setupand the on-demand provisioning behindios build --profilelived incmd/builder, so nothing outside this module could provision a signing set or release a build. This moves their non-interactive core intointernal/signing/sets.go(Setup,EnsureSecrets) and adds the missingpkg/wrappers.internal/signing/sets.go— the signing-set core:Setup(provision + upload + write the builder.json profile),EnsureSecrets(on-demand provisioning before a dispatch),UploadSet/UploadSecrets/MissingSecretsand the key/path helpers. Nothing in it prompts or prints a summary.cmd/builderkeeps what a CLI owns: the plan, the confirmation, the password prompt and the summary. The JSON result is nowsigning.SetupResult, and the failed upload is read fromUploadErrorrather than recomputed.signing.Commandslets an embedding CLI name its own verbs where error messages point atbuilder auth apple/builder signing setup.pkg/asc,pkg/distribute,pkg/release,pkg/ipa,pkg/signing— alias wrappers, so values pass between them without conversion andrelease.Builderstays the one-method interface a foreign build backend implements.pkg/authgrows the App Store Connect key accessors,pkg/configthe distributions, profiles and signing-set names they need.auth.AppleCredentialsFromEnvis exported for a program with its own credential store.Review notes
The refactor left six wrappers in
cmd/builder/signing_auto.gowith no callers (missingSigningSecrets,findSigningKey,recordSigningDir,signingKeyDirs,certificateRefused,fileExists) and a verbatim second copy ofexpandPathincmd/builder/signing.go. Both are cleaned up here: the dead wrappers are gone andexpandPathdelegates tosigning.ExpandPath.Verification
go build ./...,go vet ./...,gofmt -l .clean.go test ./...passes, including the existingcmd/buildersigning tests that driveensureSigningSecretsandwriteSigningProfilethrough the new wrappers.signing.SecretStorewithpkg/github.PublicKeyand callingsigning.Setup/signing.EnsureSecretscompiles, so the exported surface is usable from outside the module.No behaviour change to any command.