Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
56 commits
Select commit Hold shift + click to select a range
1a765e0
fix(pi): preserve directory marker when canonicalizing missing roots
Sogl Sep 27, 2026
ac80ba8
fix(app): drop isolated deinit from AgentSessionsStore
Sogl Sep 27, 2026
38d47ef
fix(mistral): price billing usage by event type, zone, and tier
T0mSIlver Sep 27, 2026
6fd10ec
docs(changelog): link Mistral pricing PR
T0mSIlver Sep 27, 2026
231bbef
Antigravity: reap MCP servers left behind by the usage probe
bcharleson Sep 27, 2026
190dbfc
Note the Antigravity reap fix in the changelog as #4077.
bcharleson Sep 27, 2026
6ae8c7c
Reap Antigravity leftovers only while the process identity still matches
bcharleson Sep 28, 2026
03a97bc
perf(codex): memoize Gatekeeper verdicts for standalone CLI binaries
dustball Sep 28, 2026
f6c6b86
fix(codex): bind memoized Gatekeeper verdicts to the executable assessed
dustball Sep 28, 2026
4b0736a
fix(codex): revalidate shared Gatekeeper verdicts per caller; 15-minu…
dustball Sep 28, 2026
bd39efc
fix(codex): bind memoized verdicts to the inode Gatekeeper assessed
dustball Sep 28, 2026
c9b0edd
fix(codex): five-minute verdict lifetime, and commit the native proof
dustball Sep 28, 2026
7ab7e56
fix(codex): revalidate the caller's path on a memo cache hit too
dustball Sep 28, 2026
a3a6f4d
ci: build tests with Xcode 26.3 and fix Swift 6.2 type-check timeouts…
steipete Sep 28, 2026
a5252e2
feat(plugins): host cookie jar and LongCat plugin cutover (#4059)
steipete Sep 28, 2026
610c391
fix(config): treat blank config files as absent (#4081)
steipete Sep 28, 2026
3dad9da
fix(menu-bar): validate preserved status item positions (#4082)
steipete Sep 28, 2026
2b455a5
fix(codex): refresh validated cost snapshots during catch-up (#4087)
steipete Sep 28, 2026
6600497
fix(keychain): bound validation stalls and recover Claude caches (#4089)
steipete Sep 28, 2026
62acfd8
fix(antigravity): group OAuth quotas and parse Starter weekly quotas …
steipete Sep 28, 2026
6dcac3d
fix(kimi): clarify stale CLI credential recovery (#4086)
steipete Sep 28, 2026
daffd77
fix(cost): compact and reuse Claude cache artifacts (#4092)
steipete Sep 28, 2026
e9b2823
fix(providers): clarify Kimi and z.ai quota availability (#4091)
steipete Sep 28, 2026
03f4b68
fix(grok): publish local token history when billing is unavailable (#…
steipete Sep 28, 2026
9013fd8
fix(codex): reread fresh credentials and invalidate stale plan eviden…
steipete Sep 28, 2026
1060f34
fix(refresh): detect the nested ChatGPT Codex app-server (#4090)
steipete Sep 28, 2026
c33760e
fix(widgets): retain eligible readings per provider (#4095)
steipete Sep 28, 2026
b32b2a5
chore: sync main for Mistral pricing review
steipete Sep 28, 2026
d58804f
fix(antigravity): reap probe descendants by inherited ownership
steipete Sep 28, 2026
fdf4115
refactor(pi): share root canonicalization and verify root identity
steipete Sep 28, 2026
40ecce6
fix(app): retain task isolation during session teardown
steipete Sep 28, 2026
7508e65
fix(mistral): verify billing price dimensions and share aggregation
steipete Sep 28, 2026
e45ea8f
fix(antigravity): verify portable probe ownership cleanup
steipete Sep 28, 2026
910f50d
Merge remote-tracking branch 'upstream/main' into fix/pi-canonical-di…
Sogl Sep 28, 2026
01bf722
Merge remote-tracking branch 'upstream/main' into fix/agent-sessions-…
Sogl Sep 28, 2026
c15a962
fix(security): redact fetcher environments and scrub test environment…
steipete Sep 28, 2026
14bdca1
feat(plugins): move Notion and ZoomMate to validated cookie sessions …
steipete Sep 28, 2026
c227f91
Merge remote-tracking branch 'origin/main' into pr-4067
steipete Sep 28, 2026
bf53c18
Merge #4067: preserve Pi directory marker for missing roots
steipete Sep 28, 2026
e77ce6f
Merge remote-tracking branch 'origin/main' into pr-4068
steipete Sep 28, 2026
a1d4f17
Merge remote-tracking branch 'upstream/main' into fix/codex-preflight…
dustball Sep 28, 2026
22fbf35
Merge #4068: nonisolated AgentSessionsStore teardown
steipete Sep 28, 2026
8fc5972
Merge remote-tracking branch 'origin/main' into pr-4077
steipete Sep 28, 2026
a866482
Merge #4077: reap Antigravity probe children by ownership marker
steipete Sep 28, 2026
b433575
chore(release): prepare 0.69.0
steipete Sep 28, 2026
48ded68
docs: update appcast for 0.69.0
steipete Sep 28, 2026
bd77ea6
chore: start 0.69.1 development
steipete Sep 28, 2026
c80b965
Merge remote-tracking branch 'upstream/main' into fix/codex-preflight…
dustball Sep 28, 2026
886b93c
chore: sync Mistral billing fixes with current main
steipete Sep 28, 2026
dd15792
proof: exact-head packaged-app before/after on the reporting Mac
dustball Sep 28, 2026
ee6a89d
fix(security): redact remaining stored process environments (#4106)
steipete Sep 28, 2026
1547a34
Merge remote-tracking branch 'origin/main' into pr-4076
steipete Sep 28, 2026
1784d44
Merge remote-tracking branch 'upstream/main' into fix/codex-preflight…
dustball Sep 28, 2026
b468e0d
Merge #4076: price Mistral billing by event type, zone, and tier
steipete Sep 28, 2026
2db68ee
fix(process): keep ownership cleanup responsive under load (#4108)
steipete Sep 28, 2026
f80ae03
Merge remote-tracking branch 'upstream/main' into fix/codex-preflight…
dustball Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
76 changes: 76 additions & 0 deletions .github/pr-proof/codex-gatekeeper-assessment-memo.log
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
CodexBar Codex launch preflight: Gatekeeper assessment memo, native proof (#4078)
Verified 2026-09-27 on macOS 15.7.7 (24G720), Intel Core i7-4790K, x86_64.
Codex CLI 0.145.0 standalone: ~/.local/bin/codex -> ~/.codex/packages/standalone/current/bin/codex
(Developer ID Application: OpenAI OpCo, LLC (2DC432GLL2), 281 MB x86_64, no quarantine xattr).
Private paths are shown relative to ~.

Cost of one assessment (spctl --assess --type execute --verbose=4, back to back, syspolicyd otherwise idle):
run 1 11.5 s wall 4.9 s syspolicyd CPU rejected (the code is valid but does not seem to be an app)
run 2 2.7 s wall 2.6 s syspolicyd CPU same verdict
run 3 2.6 s wall 2.5 s syspolicyd CPU same verdict
The same verdicts come back for /.vol/<device>/<inode> as for the path, for both the Developer ID codex
and an ad-hoc signed CLI ("rejected" / "source=no usable signature").

Before (official 0.57.0; unified log, process == "spctl", all parented by CodexBar):
16:50-17:10 5 refreshes 10 spctl runs, a pair on every 5-minute refresh (~1.7% of a core)
17:00-18:00 elevated lookup cadence, a pair every ~12 s: 494 spctl runs; syspolicyd 16.5 s CPU
per 30 s (~55% of a core). Quitting CodexBar: 0.00 s per 30 s.

After (this PR, packaged 0.68.1 build 160, launched with CODEX_CLI_PATH unset):
20:31:26, 20:31:31, 20:36:30 cold start: assessment > the existing 5 s spctl timeout, terminated,
not remembered (unchanged behaviour)
20:36:35 completed in 2.64 s, remembered
20:41:30, 20:46:31 refreshes codex launched, 0 spctl runs

Production-path harness: a throwaway local executable calling the public
CodexLaunchPreflight.isLaunchCandidateAllowed(path:) with the real spctl, on a symlink retargeted
between the Developer ID codex and an ad-hoc signed CLI.

codex (Developer ID), lookup 1 ALLOWED 2580 ms spctl on /.vol/<dev>/<inode>, remembered
codex, lookup 2 ALLOWED 0 ms memo
codex, lookup 3 ALLOWED 0 ms memo
link retargeted to ad-hoc binary BLOCKED 76 ms a different file, its own assessment
ad-hoc binary, lookup 2 BLOCKED 0 ms memo
link retargeted back to codex ALLOWED 0 ms the same file as lookup 1, its verdict
codex, lookup 5 ALLOWED 0 ms memo

Shared in-flight assessment (fresh process): the leader starts spctl on codex, a second lookup joins at
300 ms, and the link is retargeted to the ad-hoc binary at 1004 ms.

leader (starts spctl on codex) BLOCKED returned at 2637 ms
waiter (joins the same assessment) BLOCKED returned at 2637 ms

Unified log for that phase: one spctl on codex (2.47 s), then two short spctl runs on the ad-hoc binary,
one fresh assessment per caller. Neither caller was answered with the verdict for the file its path no
longer named.

Cache-hit window (review of revision 5): production decision function (the internal
isLaunchCandidateAllowed seam), production AssessmentMemo, a real spctl run with the production
arguments, and the memo's onCacheHit test hook retargeting the link to the ad-hoc binary after the
remembered entry is found and before it is returned.

codex (Developer ID), lookup 1 ALLOWED 9479 ms spctl runs: 1 (cold)
codex, lookup 2 (cache hit) ALLOWED 0 ms spctl runs: 0
cache hit; link -> ad-hoc inside the hit window BLOCKED 138 ms spctl runs: 1
ad-hoc binary, next lookup BLOCKED 137 ms spctl runs: 1

The remembered "allowed" for codex did not reach the decision for the ad-hoc binary: the path re-check
before answering saw a different file and ran a fresh, unshared assessment instead.

Exact-head packaged app, before and after (2026-09-28, 13:18-14:24, back to back, 30 minutes each).
Same Mac and codex binary. CODEX_CLI_PATH not in effect (pointed at a nonexistent file, which both
resolvers ignore, so the normal lookup and preflight run). CodexBar's child processes sampled every
second; syspolicyd CPU from ps; the spctl counts match the unified log (process == "spctl") exactly.

spctl runs at launch 5 refreshes after syspolicyd CPU
official 0.68.0 (Developer ID) 14 4 10, a pair on each 50.2 s
this PR (0.68.1 build 160, ad-hoc, 10 2 8, none on one 33.4 s
memo/preflight/test files as this head)

This Mac was under memory pressure (32 GB RAM, 8 GB of swap in use), so the 281 MB binary was
usually evicted between 5-minute refreshes. The first assessment of a refresh then ran into the
existing 5 s timeout (spctl killed at 5.0 s) and, as on main, was not remembered; the second, on a
warmer file, often finished in 3-4 s. On main that verdict is discarded. With the memo it is kept:
the refresh at +20:08 launched codex with no spctl at all. At launch, main ran three overlapping
assessments of the same file; with the memo, lookups that overlapped shared one assessment.
The saving here is in how many assessments run, not in what one costs.
42 changes: 40 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -203,13 +203,46 @@ jobs:
printf '| Runs lint-macos | `%s` |\n' "$RUNS_LINT_MACOS"
} >> "$GITHUB_STEP_SUMMARY"

swift-build-macos-compatibility:
needs: changes
if: ${{ needs.changes.outputs.macos-tests == 'true' }}
runs-on: macos-15
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Select Xcode 26.3
run: |
set -euo pipefail
sudo xcode-select -s /Applications/Xcode_26.3.app/Contents/Developer
echo "DEVELOPER_DIR=/Applications/Xcode_26.3.app/Contents/Developer" >> "$GITHUB_ENV"
[[ "$(/usr/bin/xcodebuild -version)" == Xcode\ 26.3* ]]
/usr/bin/xcodebuild -version

- name: Restore SwiftPM build cache
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
.build
~/Library/Caches/org.swift.swiftpm
key: swiftpm-macos15-xcode26.3-arm64-${{ hashFiles('Package.resolved', 'Package.swift') }}
restore-keys: |
swiftpm-macos15-xcode26.3-arm64-

- name: Build app, CLI, and tests with Swift 6.2
run: |
set -euo pipefail
swift --version
swift build --build-tests

lint-build-test:
runs-on: ubuntu-24.04
timeout-minutes: 5
needs:
- changes
- lint
- swift-test-macos
- swift-build-macos-compatibility
- build-linux-musl-cli
- build-linux-cli
if: ${{ always() && !cancelled() }}
Expand All @@ -226,7 +259,8 @@ jobs:
"${{ needs.changes.outputs.macos-tests-deferred }}" \
"${{ needs.changes.outputs.linux-musl-build }}" \
"${{ needs.build-linux-musl-cli.result }}" \
"${{ needs.build-linux-cli.result }}"
"${{ needs.build-linux-cli.result }}" \
"${{ needs.swift-build-macos-compatibility.result }}"

- name: Summarize aggregate CI gate
if: ${{ always() }}
Expand All @@ -238,6 +272,7 @@ jobs:
MACOS_TESTS_DEFERRED: ${{ needs.changes.outputs.macos-tests-deferred }}
MACOS_TESTS_REASON: ${{ needs.changes.outputs.macos-tests-reason }}
MACOS_RESULT: ${{ needs.swift-test-macos.result }}
MACOS_COMPATIBILITY_RESULT: ${{ needs.swift-build-macos-compatibility.result }}
LINUX_MUSL_BUILD: ${{ needs.changes.outputs.linux-musl-build }}
LINUX_MUSL_BUILD_REASON: ${{ needs.changes.outputs.linux-musl-build-reason }}
LINUX_MUSL_RESULT: ${{ needs.build-linux-musl-cli.result }}
Expand All @@ -258,6 +293,7 @@ jobs:
printf '| macOS Swift tests deferred | `%s` |\n' "${MACOS_TESTS_DEFERRED:-<unset>}"
printf '| macOS gate reason | %s |\n' "$reason"
printf '| swift-test-macos result | `%s` |\n' "$MACOS_RESULT"
printf '| Swift 6.2 build result | `%s` |\n' "$MACOS_COMPATIBILITY_RESULT"
printf '| Linux musl build required | `%s` |\n' "${LINUX_MUSL_BUILD:-<unset>}"
printf '| Linux musl gate reason | %s |\n' "$musl_reason"
printf '| build-linux-musl-cli result | `%s` |\n' "$LINUX_MUSL_RESULT"
Expand Down Expand Up @@ -522,7 +558,9 @@ jobs:
run: swift build -c release --product CodexBarCLI --static-swift-stdlib

- name: Swift Test (Linux only)
run: swift test --parallel
run: |
source Scripts/test_environment.sh
swift test --parallel

- name: Smoke test CodexBarCLI
shell: bash
Expand Down
72 changes: 58 additions & 14 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,26 +1,70 @@
# Changelog

## 0.68.1 — Unreleased
## 0.69.1 — Unreleased

### Added
### Fixed

- Claude: show saved usage-limit resets and their expiry from the Web source in the menu and `codexbar usage` details (#4048). Thanks @enieuwy!
- Mistral: price billing usage by event type, API zone, and service tier, so a per-second audio or priority price no longer inflates API spend and 30-day token cost (#4076). Thanks @T0mSIlver!
### Security

- Redact every remaining stored process environment in the app, CLI, provider contexts, and session scanners, and guard against new unredacted environment properties with a repository check (#4106).

### Fixed

- Token history: show observed model names when per-model totals are unavailable, including Grok local sessions (#4056). Fixes #4054. Thanks @BUKOWSKIREAL!
- TypeSafe: show the credit balance in the menu bar and layout preview instead of missing-value dashes, using shared balance-label metadata (#4050). Thanks @lg!
- Grok: retain the product usage breakdown on the grok.com billing fallback, with bounded shared protobuf decoding (#4041). Thanks @olddonkey!
### Changed
- Codex: remember Gatekeeper verdicts for unchanged standalone CLI binaries, bound to the file actually assessed, instead of running `spctl --assess` on every lookup, which kept `syspolicyd` busy in proportion to the refresh cadence (#4078, #4080). Thanks @dustball!
- CLI: keep probe timeout and cancellation cleanup responsive when other processes have large environments (#4077).

- Plugins: user plugins now get their own switcher tab by default when Merge Icons is on; set `topLevel: false` to keep the appended card.
- Menu bar: align the persistent Refresh row with other menu actions by removing its decorative icon, preserving the shortcut and accessibility action (#4057). Thanks @elijahfriedman!
### Fixed
## 0.69.0 — 2026-09-28

### Highlights

- Plugins feel native: user plugins now get their own switcher tab by default, and Notion AI, ZoomMate, and LongCat run as bundled plugins with browser sessions kept private to the host (#4074, #4098, #4059).
- Lighter on CPU and disk: Claude and Vertex cost history is reused instead of re-decoded on every scan, the history cache is about a quarter smaller, and cost scans no longer expand priority days back to year 1 (#4053, #4092, #4045). Thanks @djbclark for the CPU sample that pinned this down!
- Steadier refreshes: Codex rereads credentials while the CLI rewrites them and picks up plan upgrades right away, a stalled Keychain signature check can no longer freeze every provider, and Claude recovers from rejected cache writes on the next refresh (#4088, #4089). Thanks @lozcalver and @SilentKnight87!
- Widgets and the menu bar hold on to good data: each widget provider keeps its last good reading after failed refreshes, and corrupt saved menu bar positions are never restored (#4095, #4082).
- More accurate numbers: Grok token totals and model names survive billing outages, Claude shows saved limit resets from the Web source, Kimi marks windows blocked once the monthly pool is exhausted, Antigravity shows Starter quotas, and TypeSafe shows its balance in the menu bar (#4093, #4056, #4048, #4091, #4084, #4050).
- Leaner under the hood: the app ships with about 700 fewer lines of code than 0.68.0, even with the new plugin host capabilities.

- Claude: retain priced local spend as a partial estimate when an incomplete Pi or OMP mirror is included, across Usage & Spend, Overview, and sharing (#4052). Fixes #4051. Thanks @BUKOWSKIREAL!
- Claude and Vertex: reuse unchanged decoded cost-history caches across refreshes while preserving source, pricing, and time-zone validation (#4053). Thanks @djbclark!
- Costs: keep All history priority checks proportional to recorded days instead of generating centuries of empty days, while preserving older logs (#4045). Thanks @djbclark!
- CLI: macOS release builds compile again on the Xcode 26 release runners, so the 0.68 macOS CLI tarballs and the Homebrew `codexbar` formula ship alongside the app.
### Security

- Test and debug output no longer includes environment variable values: stored environments render only an entry count, and test runners scrub credential-shaped variables before running (#4097).

### Added

- Claude: show saved usage-limit resets and their expiry from the Web source in the menu and `codexbar usage` details (#4048). Thanks @enieuwy!

### Changed

- Plugins: user plugins now get their own switcher tab by default when Merge Icons is on; set `topLevel: false` to keep the appended card (#4074).
- Notion AI, ZoomMate, and LongCat: usage fetching runs through bundled plugins with host-owned cookie sessions, preserving browser-session reuse, validated cache migration, Notion over-quota values, ZoomMate credits history, and LongCat fuel-pack data (#4098, #4059).
- Menu bar: the persistent Refresh row drops its decorative icon to match other menu actions, keeping the shortcut and accessibility action (#4057). Thanks @elijahfriedman!

### Fixed

- Codex: retry brief credential-file publication races before reporting refresh errors, and discard the previous plan's quota baseline after a subscription change so fresh usage appears (#4088, #3635, #3389).
- Codex: publish newly validated token and cost totals after each catch-up pass, even while historical scanning is still pending (#4087, #3508). Thanks @kernnel!
- Claude: retain valid in-memory credentials after a rejected OAuth cache write once stale-cache cleanup succeeds, so the next automatic refresh recovers without a manual Refresh (#4089, #3395).
- Keychain: bound stalled code-signature validation so it cannot hold cache locks and freeze all provider refreshes (#4089, #3249).
- Claude: keep priced local spend as a partial estimate when an incomplete Pi or OMP mirror is included, across Usage & Spend, Overview, and sharing (#4052). Fixes #4051. Thanks @BUKOWSKIREAL!
- Claude and Vertex: reuse unchanged decoded cost-history caches, skip encoding unchanged caches, and compact retained row fields to cut CPU and disk writes during refreshes (#4053, #4092, #3882). Thanks @djbclark!
- Costs: keep All-history priority checks proportional to recorded days instead of generating centuries of empty days, preserving older logs (#4045). Thanks @djbclark!
- Configuration: treat empty or whitespace-only config files like missing files so usage keeps working; malformed non-empty files still report errors (#4081, #4071). Thanks @kvnloo!
- Menu bar: reject corrupt saved positions during status-item visibility changes and removal while preserving valid placement across restarts (#4082, #3355).
- Widgets: keep each eligible provider's last good reading and original age after failed refreshes, even when another provider is unavailable, disabled, or changes accounts (#4095, #3500).
- Adaptive refresh: recognize ChatGPT's nested Codex app-server with per-scan running-process validation and update-aware bundle assessment caching (#4090, #4069). Thanks @jaychou0642-create!
- Grok: keep local token totals visible in Usage & Spend and shared cards across wider history views and billing outages (#4093, #3716). Thanks @Chipagosfinest!
- Grok: keep the product usage breakdown on the grok.com billing fallback, with bounded shared protobuf decoding (#4041). Thanks @olddonkey!
- Token history: show observed model names when per-model totals are unavailable, including Grok local sessions (#4056). Fixes #4054. Thanks @BUKOWSKIREAL!
- Kimi: point stale CLI sessions to running `kimi` or adding an API key in Settings, keeping web fallback and leaving rotating CLI credentials read-only (#4086, #4063). Thanks @kid0114!
- Kimi Code: mark shorter windows as blocked when the monthly membership pool is exhausted, without fresh quota or pace forecasts (#4091, #3536).
- z.ai: explain unavailable Coding Plan usage for empty or unsupported quota shapes while keeping recognized quotas and analytics (#4091, #2522).
- Antigravity: preserve grouped OAuth quotas, including weekly-only Starter allowances, and honor explicit quota-window cadence (#4084, #2427, #3789).
- Antigravity: usage probes no longer leave MCP server processes behind; cleanup only touches processes carrying the probe's inherited ownership marker, so unrelated processes in the same directory are never killed (#4077). Thanks @bcharleson!
- TypeSafe: show the credit balance in the menu bar and layout preview instead of missing-value dashes (#4050). Thanks @lg!
- Pi: preserve the directory marker for session roots that do not exist yet (#4067). Thanks @Sogl!
- Agent Sessions: avoid the macOS 15 isolated-teardown crash while keeping task cancellation and Stay Awake cleanup (#4068). Thanks @Sogl!
- Browser sessions: keep distinct host-only and domain-scoped cookies when merging stores from the same profile, and preserve interactive cookie-refresh authorization across plugin engine callbacks (#4059, #4098).
- CLI and development: macOS CLI release builds and the test suite compile on Xcode 26.3 again, and CI now builds app, CLI, and tests on that toolchain (#4058, #4079, #4070). Thanks @RowboTony!

## 0.68.0 — 2026-09-27

Expand Down
4 changes: 2 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -44,10 +44,10 @@ test-skip-build:
./Scripts/test_fast.sh --skip-build $(test_filter_arg)

test-tty:
CODEXBAR_SUPPRESS_TEST_KEYCHAIN_ACCESS=1 swift test --filter TTYIntegrationTests
source ./Scripts/test_environment.sh && CODEXBAR_SUPPRESS_TEST_KEYCHAIN_ACCESS=1 swift test --filter TTYIntegrationTests

test-live:
LIVE_TEST=1 CODEXBAR_ALLOW_TEST_KEYCHAIN_ACCESS=1 swift test --filter LiveAccountTests
export CODEXBAR_ALLOW_TEST_KEYCHAIN_ACCESS=1 && source ./Scripts/test_environment.sh && LIVE_TEST=1 swift test --filter LiveAccountTests

release:
./Scripts/package_app.sh release
15 changes: 15 additions & 0 deletions Scripts/ci_verify_test_jobs.sh
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ macos_tests_deferred="${5:-}"
linux_musl_build_required="${6:-}"
linux_musl_build_result="${7:-}"
linux_build_result="${8-<missing>}"
macos_compatibility_result="${9-<missing>}"

if [[ "$lint_result" != "success" ]]; then
printf 'lint job finished with %s\n' "${lint_result:-<empty>}" >&2
Expand Down Expand Up @@ -45,6 +46,20 @@ case "${macos_tests_required}:${macos_tests_deferred}:${macos_test_result}" in
;;
esac

case "${macos_tests_required}:${macos_compatibility_result}" in
true:success)
printf 'Swift 6.2 compatibility build passed.\n'
;;
false:skipped)
printf 'Swift 6.2 compatibility build skipped by the macOS test gate.\n'
;;
*)
printf 'Swift 6.2 build gate/result mismatch: required=%s result=%s\n' \
"${macos_tests_required:-<empty>}" "${macos_compatibility_result:-<empty>}" >&2
exit 1
;;
esac

printf 'Linux glibc CLI matrix passed.\n'

case "${linux_musl_build_required}:${linux_musl_build_result}" in
Expand Down
5 changes: 3 additions & 2 deletions Scripts/test-plugin-engines.sh
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
#!/bin/sh
set -eu
#!/usr/bin/env bash
set -euo pipefail

ROOT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
cd "$ROOT_DIR"
source "$ROOT_DIR/Scripts/test_environment.sh"

FILTER='ProviderPluginRuntimeTests|ProviderPluginParityTests|ProviderPluginDetailsParityTests|ProviderPluginExtensionParityTests|Sub2APIPluginGoldenTests|UserProviderPluginPortableTests'

Expand Down
Loading