Skip to content

Repository files navigation

n42-dump-xcode-buildsettings

CLI tool to dump xcodebuild build settings, sanitize volatile values, and write one JSON file per target for stable Git diffs.

What it does

The tool runs:

xcrun xcodebuild -alltargets -showBuildSettings -json

It adds -clonedSourcePackagesDirPath and -packageAuthorizationProvider when needed (see below).

Then it:

  1. Sanitizes the full JSON dump in memory
  2. Splits by buildSettings.TARGET_NAME
  3. Writes one file per target: <output-dir>/<TARGET_NAME>.json

Default output dir: PersistedLogs/buildConfigs

Sanitization

The dump is normalized to reduce machine- and build-specific noise.

Regex-based replacements

  • Paths under /var/folders/.../.../ -> /var/folders/XX/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX/

Key-specific replacements

  • MAC_OS_X_PRODUCT_BUILD_VERSION -> XXXXXXXX
  • MAC_OS_X_VERSION_ACTUAL -> XXXX
  • MAC_OS_X_VERSION_MAJOR -> XX
  • MAC_OS_X_VERSION_MINOR -> XX
  • BUILD_VERSION -> XXXX.XX.XX.XX.XX
  • PATH -> REDACTED_PATH

Optional user-defined redactions

Use --redact-field <KEY> (repeatable) to redact additional keys with value REDACTED.

N42_GIT_COMMIT_HASH is not redacted by default; include it explicitly if needed:

swift run n42-dump-xcode-buildsettings --redact-field N42_GIT_COMMIT_HASH

Swift package clones

xcodebuild -showBuildSettings resolves the project's Swift packages. Without a clone directory they land in the default DerivedData, which on shared CI hosts means one multi-GB checkout per repository and runner slot that nothing removes. Pass --cloned-source-packages-dir-path <path>, or set N42_SPM_CLONE_DIR (the n42 runner slots export it), and the tool forwards it as -clonedSourcePackagesDirPath. (-derivedDataPath is not an option here: xcodebuild rejects it without a scheme.)

Package credentials on CI

When a package needs downloading, e.g. a binary target such as MSAL's XCFramework zip, xcodebuild looks up credentials for the download host and for the host the download redirects to. Its default store is the login keychain. On a headless CI runner that keychain is locked, so the lookup waits for an unlock dialog nobody answers and xcodebuild hangs without printing anything.

When CI is set (GitHub Actions sets it), the tool therefore passes -packageAuthorizationProvider netrc, so credentials come from ~/.netrc only. Override it with --package-authorization-provider keychain|netrc.

Timeout

The tool stops xcodebuild (and the git processes it started) after 1200 seconds (20 minutes) and fails with an error that includes xcodebuild's last output, rather than hanging until the CI job's own time limit. Change the limit with --timeout <seconds>. xcodebuild gets no stdin, so a prompt fails instead of waiting.

Usage

Swift Package Manager

swift run n42-dump-xcode-buildsettings

Run from another repo:

swift run --package-path /Users/admin/dev/work/Tools/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings

Custom output directory (derived from parent directory of the provided path):

swift run n42-dump-xcode-buildsettings --all-targets-output /tmp/allTargets.json

Note: the --all-targets-output filename is not written. Only its parent directory is used for per-target files.

With additional redacted fields:

swift run n42-dump-xcode-buildsettings --redact-field N42_GIT_COMMIT_HASH --redact-field CUSTOM_SECRET

With verbose logging:

swift run n42-dump-xcode-buildsettings --verbose

Short form:

swift run n42-dump-xcode-buildsettings -v

Mint

mint run <owner>/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings

With a tag:

mint run <owner>/n42-dump-xcode-buildsettings@<tag> n42-dump-xcode-buildsettings

Help:

mint run <owner>/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings --help

With custom output directory (derived from parent directory of the provided path):

mint run <owner>/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings --all-targets-output /tmp/allTargets.json

With additional redacted fields:

mint run <owner>/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings --redact-field N42_GIT_COMMIT_HASH --redact-field CUSTOM_SECRET

With verbose logging:

mint run <owner>/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings --verbose

Short form:

mint run <owner>/n42-dump-xcode-buildsettings n42-dump-xcode-buildsettings -v

Requirements

  • macOS with Xcode command line tools (xcodebuild and xcrun)
  • Run from an Xcode project/workspace context where xcodebuild -alltargets -showBuildSettings -json succeeds

Development

Build:

swift build

Test:

swift test

About

A Swift command line tool to dump the (redacted) buildsettings

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages