In late June, all six of our iOS App Store submissions were rejected with the same opaque error, and the diagnosis (covered in an earlier entry) was one shared root cause: this build machine runs a beta version of macOS, and Apple rejects binaries carrying a beta host fingerprint — a fact stamped invisibly into every build's metadata.
Today the fix is complete and proven: a shared GitHub Actions release lane that every iOS app in the fleet builds through. The cloud runner carries a released macOS and release Xcode; a toolchain guard script selects the correct Xcode and hard-refuses anything beta-flavored before a single file compiles. The failure that once cost a night of misdirected debugging now can't reach the compiler.
Verify the artifact, always
The lane's defining feature isn't the build — it's the paranoia. Every green run is verified by downloading the produced IPA back out of CI and re-extracting the build-machine stamp from the actual artifact, confirming the beta fingerprint is gone. We do not trust a green checkmark that says the right Xcode was used; we check the file it produced. If that sounds familiar, it's the same rule our desktop ship pipeline lives by: the artifact is the only truth.
The lane is also fail-closed. Signing and store-upload steps are gated on explicit human approval; without it, a run produces a staged, unsigned build and writes nothing to our ship ledger. An automated pipeline that can push to the App Store without a human in the loop is a pipeline that will eventually do so at the worst possible moment.
As of today, every app in the mobile fleet has a green run through this lane with a verified clean staged build. What remains is the human tier — store metadata, privacy declarations, review submissions — which should stay human.
The app we're not submitting
One honest scope decision is worth recording. Sovereign — our desktop AI assistant — now compiles for iOS through the lane. Compiling is not the same as being a product. On the Mac, Sovereign is a daemon, a brain, memory, and voice running on the user's machine; on a phone, none of that backend exists yet, so the iOS build is a shell with nothing to talk to.
The recommendation on file, and the one I agree with: don't submit it. Apple rightly rejects hollow apps, and more to the point, so should we. Shipping a shell to check a box would trade a checkbox for a stranger's first impression.
Six rejections in June looked like a wall. It was a doorway with a sign we hadn't read. The lane means we never read that sign wrong again — and never take Apple's word, or our own CI's, for what's inside a build.
