[CP-beta]Remove Xcode environment when building swift tools in Xcode pre-action - #191585
Conversation
flutter#190848) By default, commands run within Xcode build scripts inherit the Xcode build environment. This conflicts with the `swift build` command for some reason with Xcode 27. To mitigate, we ignore the environment by prefixing with `env -i`. Fixes flutter#190846. ## Pre-launch Checklist - [x] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [x] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [x] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [x] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [x] I signed the [CLA]. - [x] I listed at least one issue that this PR fixes in the description above. - [x] I updated/added relevant documentation (doc comments with `///`). - [x] I added new tests to check the change I am making, or this PR is [test-exempt]. - [x] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [x] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md
|
@vashworth please fill out the PR description above, afterwards the release team will review this request. |
|
This pull request was opened from and to a release candidate branch. This should only be done as part of the official Flutter release process. If you are attempting to make a regular contribution to the Flutter project, please close this PR and follow the instructions at Tree Hygiene for detailed instructions on contributing to Flutter. Reviewers: Use caution before merging pull requests to release branches. Ensure the proper procedure has been followed. |
There was a problem hiding this comment.
Code Review
This pull request isolates the environment using env -i when running Swift Package Manager commands in flutter_integration.sh.tmpl and updates the integration tests to handle resulting Gatekeeper check failures. The review feedback points out that completely clearing the environment removes critical variables like HOME and TMPDIR, which are necessary for Gatekeeper verification, keychain access, and Swift Package Manager caching, and suggests preserving these variables.
| env -i PATH="$PATH" DEVELOPER_DIR="${DEVELOPER_DIR:-}" xcrun --sdk macosx swift package clean --build-path "$FLUTTER_TOOL_BUILD_PATH" | ||
| env -i PATH="$PATH" DEVELOPER_DIR="${DEVELOPER_DIR:-}" xcrun --sdk macosx swift build --product $FLUTTER_TOOL --build-path "$FLUTTER_TOOL_BUILD_PATH" -c $FLUTTER_TOOL_BUILD_MODE --disable-sandbox |
There was a problem hiding this comment.
Clearing the entire environment with env -i also removes HOME and TMPDIR. On macOS, code signing and Gatekeeper verification rely on accessing the user's keychain (typically located in ~/Library/Keychains under HOME). Without HOME, the build tool cannot access the user's keychain, which likely explains why the integration tests had to be updated to expect Gatekeeper check failed warnings.
Additionally, Swift Package Manager uses HOME to locate its shared cache (~/.swiftpm). Completely removing HOME can cause build failures or permission issues in restricted or CI environments.
Preserving HOME and TMPDIR in the environment should resolve these issues and potentially allow the Gatekeeper checks to succeed normally.
| env -i PATH="$PATH" DEVELOPER_DIR="${DEVELOPER_DIR:-}" xcrun --sdk macosx swift package clean --build-path "$FLUTTER_TOOL_BUILD_PATH" | |
| env -i PATH="$PATH" DEVELOPER_DIR="${DEVELOPER_DIR:-}" xcrun --sdk macosx swift build --product $FLUTTER_TOOL --build-path "$FLUTTER_TOOL_BUILD_PATH" -c $FLUTTER_TOOL_BUILD_MODE --disable-sandbox | |
| env -i PATH="$PATH" HOME="$HOME" TMPDIR="${TMPDIR:-}" DEVELOPER_DIR="${DEVELOPER_DIR:-}" xcrun --sdk macosx swift package clean --build-path "$FLUTTER_TOOL_BUILD_PATH" | |
| env -i PATH="$PATH" HOME="$HOME" TMPDIR="${TMPDIR:-}" DEVELOPER_DIR="${DEVELOPER_DIR:-}" xcrun --sdk macosx swift build --product $FLUTTER_TOOL --build-path "$FLUTTER_TOOL_BUILD_PATH" -c $FLUTTER_TOOL_BUILD_MODE --disable-sandbox |
da8023b
into
flutter:flutter-3.48-candidate.0
This pull request is created by automatic cherry pick workflow
Please fill in the form below, and a flutter domain expert will evaluate this cherry pick request.
Issue Link:
What is the link to the issue this cherry-pick is addressing?
#190846
Impact Description:
What is the impact (ex. visual jank on Samsung phones, app crash, cannot ship an iOS app)?
Does it impact development (ex. flutter doctor crashes when Android Studio is installed),
or the shipping of production apps (the app crashes on launch).
This information is for domain experts and release engineers to understand the consequences of saying yes or no to the cherry pick.
When integrating Flutter into a native iOS app (add-to-app) using SwiftPM, the build may fail due to
Changelog Description:
Explain this cherry pick:
See best practices for examples.
< Replace with changelog description here >
[flutter/190846] When building an existing native iOS app that's integrated with Flutter using SwiftPM on Xcode 27, it may fail to build Flutter's swift packages.
Workaround:
Is there a workaround for this issue?
No
Risk:
What is the risk level of this cherry-pick?
Test Coverage:
Are you confident that your fix is well-tested by automated tests?
Validation Steps:
What are the steps to validate that this fix works?
Run packages/flutter_tools/test/integration.shard/swift_package_manager_add2app_test.dart with Xcode 27