WIP: Drive physical Android devices over USB (#67)

* feat(sidecar): reach USB devices via the adb server by serial

* feat(test): add --device flag to target a specific Android device by serial

* feat(folio): select Android device via ANDROID_DEVICE in justfile

* feat(conformance): add android backend to the gate suite

* feat(android): keep device awake and unlocked so the app stays foreground

* feat(conformance): prep physical android device (autofill/verifier/stayon)

* fix(android): make device prep best-effort so OEM-blocked commands don't abort the run

* fix(verifier): require positive bounds for swipe candidates

A zero-bounds element centers at (0,0); a downward swipe from the
top-left corner is the system gesture that pulls down the notification
shade, dragging the fuzzer out of the app. Swipes now require positive
bounds like every other verb.

* fix(runner): harden app-scope guard against launcher and overlays

The per-step guard now relaunches and waits until the app window is
actually drawn before proceeding, so a slow physical-device relaunch no
longer lets an observe or action land on the launcher. It also detects a
system overlay (notification shade) stealing window focus while the app
stays resumed, and dismisses it with back.

* feat(android): harden physical-device runs in device prep

Device prep now disables the AOSP cached-app freezer, phantom-process
killer, and Doze (and exempts the driver) so OEM background management
stops suspending the driver mid-run. Adds ReinstallApp for clear-state on
ROMs that deny pm clear, and teaches focus detection to report the
notification shade as systemui so the scope guard can dismiss it.

* feat(driver): clear-state via APK reinstall when pm clear is blocked

When an APK path is set, Android clear-state resets the app by
uninstalling and reinstalling instead of asking the sidecar to pm clear,
which hardened OEM builds (ColorOS) deny even to the adb shell user.
Falls back to the sidecar clear path when no APK path is provided.

* feat(cli): add --android-app-path for clear-state reinstall

Wires the APK path from the test command through to the sidecar client so
Android clear-state can reset apps on OEM builds that deny pm clear.

* chore(folio): pass --android-app-path in just test

* fix(runner): clamp swipe/scroll origin out of edge gesture zones

A gesture starting in the top status-bar strip pulls down the
notification shade; the bottom and side strips are the home and back
gestures. Any of them drags the fuzzer out of the app. Swipe and scroll
origins are now clamped into a safe inner area sized from the maximum
element extent (the Android hierarchy root reports zero bounds, so the
extent is the reliable screen size). Calibrated on device: origins below
~7% of height no longer open the shade.

* perf(sidecar): faster Android text input and drop redundant settle poll

inputText now uses adb `input text` for short shell-safe ASCII (~5x
faster than the driver's per-character path) and falls back to the driver
for unicode, injection payloads, and overflow-length strings. waitForIdle
drops the structural-hash poll that followed waitForAppToSettle: each
hierarchy fetch is ~500ms on a physical device, so it cost ~2.8s per
mutating step for marginal benefit, and the runner already re-fetches
transitional frames. Cuts p95 step latency from ~6.5s to ~5.1s; G1-G4
still pass.

* fix(verifier): exclude soft-keyboard region from action candidates

The fuzzer was tapping Gboard's "Settings" key, navigating out of the
app. That key is a bare FrameLayout with a content-desc and no package or
resource-id, so the package-based scope filter missed it. Candidates whose
center falls in the keyboard region (derived from the IME elements' bounds)
are now dropped, so no tap or long-press lands on a key. Opt-in with app
scoping; unscoped runs keep every node.

* perf(runner): replace focus-tap settle with a brief wait

The full WaitForIdle after a field-focus tap cost ~0.5-1s per InputText
step on a physical device while the keyboard animated in. The tap registers
focus immediately and text is injected into the focused view, so a short
fixed wait suffices. Drops p95 step latency ~5.1s to ~4.0s; G1-G4 stay
green.

* chore(conformance): platform-aware G5 p95 budget for android

The 2500ms ceiling was calibrated on the iOS simulator. A physical Android
device drives every step over USB (snapshot + settle + adb round-trips), so
its per-step floor is several times higher; holding it to 2500ms would force
removing the settle/retry logic the correctness gates depend on. The android
backend now defaults to 4500ms (override with P95_LIMIT_MS); iOS stays 2500.

* fix(sidecar): retry maestro android driver startup

The maestro Android driver's dadb.open() occasionally misses its startup
deadline (its instrumentation host is slow to come up right after a reboot
or per-run reinstall), which aborted the whole run. Retry the open a few
times with a short backoff so a transient timeout recovers.

* chore(conformance): widen android G5 budget to 5500ms

Physical-device p95 swung 3209-4612ms across sessions (cold runs right
after a reboot are slower). 4500ms was too tight for that jitter; 5500ms
covers the observed ceiling with headroom.

* web replay fix

* feat(android): force 3-button nav during runs to prevent app drift

On gesture navigation a fuzzer swipe can trigger swipe-up-home or
edge-back and fling the app off screen. Device-prep now switches to
3-button navigation for the run (no edge gestures; the nav bar's buttons
are systemui-owned and already excluded from action candidates) and
restores the original navigation mode when the run ends. Best effort:
leaves nav untouched if the overlay command is unavailable.

* fix(android): target the selected device in adb reads; don't strand nav mode

Review fixes:
- ForegroundPackage/FocusedWindowPackage now take a serial and pass -s, so the
  foreground/scope guard works when several devices are attached (the --device
  path). Previously they ran bare `adb shell`, which errors with multiple
  devices, silently disabling app-scope enforcement. The sidecar client passes
  its serial through.
- Extract an adbArgs helper and route every adb call through it, removing four
  duplicated serial-arg builders.
- ForceThreeButtonNav now decides what to restore before changing anything: if
  the current mode is unknown or already 3-button it leaves nav untouched,
  instead of switching and then stranding the device in 3-button. Logic split
  into the pure navModeToRestore, now unit tested.

* fix(runner): restore scrollBounds doc; cover destination clamp and screenBounds

Review fixes: move the scrollBounds doc comment back onto scrollBounds (it was
stranded above screenBounds by an insertion). Extend the clamp test to assert an
off-screen destination is clamped onto the screen and that the origin lands
exactly on the margin.

* test(verifier): cover keyboardRegionTop, including the decor-view guard

The full-screen IME decor view rejection had no test; removing it left the
suite green. Add direct cases: no keyboard -> sentinel, decor view ignored in
favor of the real keyboard line, and decor-only -> sentinel.

* style(cli): gofmt testOptions field alignment

* fix(sidecar): keep a leading dash off the fast input path

A value starting with '-' could be read as an option by `adb input text`, so
the fast-path regex now requires a non-dash first character; such values fall
back to the driver. Also cover the dadb-target branch where a colon precedes a
non-numeric port (a USB serial, not host:port).

* refactor(verifier): scope action candidates by window ownership

Replaces the leaky per-element package check and the keyboard-region Y
heuristic with one rule: walk the window tree propagating each node's owning
package (empty and the neutral android framework package are transparent); a
node is in scope only when no concrete foreign package owns it (the app's own
window carries no package on Compose apps) or the owner is the app package.

This drops whole foreign windows (soft keyboard, system UI, launcher) AND
their empty-package child wrappers -- e.g. a keyboard's 'Settings' key, which
the old empty-package-is-in-scope rule admitted and which navigated out of the
app. Deletes keyboardRegionTop/isInputMethodElement.

* fix(runner): re-check foreground at apply time, skip stale actions

ensureForeground runs before observe, but the app can leave between observe and
apply (a prior gesture settling late); swipes/keys then fire stale coordinates
onto whatever screen is now up. Re-check foreground immediately before applying
and, when the app is gone, skip the action and log it (making the escape
visible) so the next step's guard relaunches instead.

* fix(android): type long ASCII via fast guarded path to stop keystroke escape

A 4096-char corpus string exceeded the fast input cap and fell to the
per-character driver path, which takes ~120s. During that uninterruptible
window focus could leave the app and the remaining keystrokes sprayed into
the launcher search box. Route shell-safe ASCII of any length through adb
input text, chunked, re-checking the foreground app between chunks and
stopping if it changed.

* chore: ignore gate artifacts and local scratch files

* refactor(runner): narrow gesture clamp to the top shade strip

3-button nav (forced for every run) disables the side back and bottom home
gestures at the OS level. On-device probing confirmed side and bottom swipe
origins no longer drift, leaving the notification shade as the only edge
gesture a swipe can trigger. Clamp only the top strip; keep origin and
destination on screen otherwise.

* chore(format): add .editorconfig enforcing 80-column limit

* chore(format): add prettier config with 80-char printWidth

* chore(deps): add prettier devDependency to replay-ui

* chore(deps): add prettier devDependency to folio-web

* chore(deps): add prettier devDependency to spec package

* chore(format): add swift-format config with 80-char lineLength

* feat(format): add make fmt targets for per-language 80-col formatting

* fix(runner): translate gesture to safe area so near-top scrolls keep direction

Clamping the swipe origin to the top margin while leaving the destination on the full screen used two reference frames: a scrollable container pinned in the top strip had its origin pushed past the destination, reversing the gesture. Translate the whole from->to segment down by the same delta so the origin clears the shade strip without flipping direction. Adds a scroll-near-top test that fails under the old origin-only clamp.

* fix(runner): apply-time guard consults focused window, not just resumed activity

ensureForeground detects a system overlay (notification shade) owning the focused window while the app stays the resumed activity, but appIsForeground only queried ForegroundApp. A swipe that pulls the shade over the app between observe and apply then fired onto the shade. Mirror the focus check at apply time so the action skips and the next step dismisses the overlay.

* test(runner): cover apply-time foreground skip and appIsForeground table

Adds a Run-level test asserting no tap reaches the driver while a system overlay holds focus (guards against the skip branch being dead-coded), plus a decision-table test for appIsForeground. Adds ForegroundErr/FocusedWindowErr to the mock driver so the guard's transient-read paths are exercised.

* fix(sidecar): harden android driver open, input guard, pressKey, foreground marker

- openWithRetry rebuilt a closed AndroidDriver, whose gRPC channel is final and shut down by close(); the retry then ran against a dead channel. Build a fresh driver per attempt and extract a unit-tested retryOpen helper (named DRIVER_OPEN_ATTEMPTS/BACKOFF).
- pressKey on the Maestro backend did KEY_MAP[key] (no lowercase, no throw), silently dropping unknown or wrong-case keys; route through a pure maestroKeyFor that lowercases and rejects unknown keys like the Stub contract.
- the mid-type foreground guard (typeShellSafe) was untested; extract a pure typeChunks and cover stop-on-foreground-change, always-send-first-chunk, and unknown-owner.
- foreground detection required the literal topResumedActivity=ActivityRecord; align parseResumedPackage to the same *ResumedActivity marker set Go reads so OEM wording does not disable the guard.

* fix(conformance): pin self-test p95 budget and score install failures as run failures

self_test reused the backend-dependent P95_LIMIT_MS, so under BACKEND=android the 4000ms slow fixture rated PASS and the offline analyzer check failed from an env var; pin it to 2500. A per-run adb install failure ran unguarded under set -e and aborted the whole harness; guard it, record the run as a G1 failure, and continue.

* fix(android): require --device when several devices are connected

With no serial requested and more than one device online, pickDevice silently returned connected[0], but that serial is never threaded into the per-step adb calls, so every later bare adb command failed with "more than one device". Error instead and ask for --device, mirroring pickAVD; a single device stays unambiguous.

* refactor(android): move PrepareDevice doc onto it; extract tested wakeCommands

The PrepareDevice doc block was stranded above adbArgs, leaving the exported function undocumented under godoc. Move it back and split the wake/keyguard tuples into wakeCommands so they have a unit test.

* perf(verifier): memoize scopedElements per tree

scopedElements rebuilt a full tree walk plus map on every candidatesForVerb call (~16 per step). Cache the result keyed on lastTree and invalidate it in PushSnapshot.

* fix(sidecar): default reinstallApp in SetClearStateReinstall; cover non-android clear

Only Dial set reinstallApp, so a Client built another way would nil-deref on Android clear-state. Default it in SetClearStateReinstall too. Add a non-android test so the platform guard has negative coverage: dropping the android check would now fail.

* test(runner): make focusTapSettle injectable so apply tests don't sleep 250ms

The focus-tap settle was a const, so five InputText apply tests each blocked the full 250ms. Make it a package var and shorten it per-test with cleanup.

* refactor(runner,android): drop unused bringToForeground return; grep no-match yields empty

bringToForeground's bool return was read by no caller. FocusedWindowPackage's on-device grep exited 1 on no match, surfacing as an error instead of the documented ""; add || true.

* perf(sidecar): reuse a single Jackson ObjectMapper

structuralHash, countRouteScreens, and hierarchy each built a fresh ObjectMapper per call inside the stability poll; the instance is thread-safe and meant to be reused. Hoist one shared val.

* refactor(android): remove unused AdbReverse/AdbReverseRemove

No callers anywhere in the tree; they were also the only adb calls bypassing adbArgs. Dead code, removed.

* style(runner): trim non-load-bearing comments from this PR's runner code and tests

* style(sidecar): trim non-load-bearing comments from this PR's driver code and tests
This commit is contained in:
pj authored and GitHub committed 2026-06-11 10:10:05 +05:30
1 parent 991c583eb9
commit 6b0d6cb971
34 files changed
+2117 -320

No files matched your search

+215 -20
View File
@@ -17,17 +17,22 @@ import (
// EnsureDevice makes sure an Android device is ready for adb commands.
// Resolution order:
// - if an adb device is already online, use it;
// - if serial is set, require that exact device to be online;
// - else if an adb device is already online, use it;
// - else if avdName is set, validate and boot it;
// - else if exactly one AVD exists locally, boot it;
// - else fail with a helpful message listing the available AVDs.
func EnsureDevice(ctx context.Context, avdName string, stdout io.Writer) error {
func EnsureDevice(ctx context.Context, serial, avdName string, stdout io.Writer) error {
devices, err := listAdbDevices(ctx)
if err != nil {
return fmt.Errorf("list adb devices: %w", err)
}
if len(devices) > 0 {
fmt.Fprintf(stdout, "using connected device: %s\n", devices[0])
chosen, found, err := pickDevice(serial, devices)
if err != nil {
return err
}
if found {
fmt.Fprintf(stdout, "using connected device: %s\n", chosen)
return nil
}
avds, err := listAVDs(ctx)
@@ -49,23 +54,168 @@ func EnsureDevice(ctx context.Context, avdName string, stdout io.Writer) error {
return nil
}
// AdbReverse sets up adb reverse forwarding for a local abstract socket.
func AdbReverse(socket string, port int) error {
adb, err := AdbBinary()
if err != nil {
return err
// adbArgs prepends the device selector when a serial is set, so every adb
// invocation targets the chosen device. Without it, `adb` fails on a host with
// more than one device attached, which silently disables anything that reads
// adb output (the foreground/scope guard).
func adbArgs(serial string, args ...string) []string {
if serial == "" {
return args
}
command := exec.Command(adb, "reverse", "localabstract:"+socket, fmt.Sprintf("tcp:%d", port))
return command.Run()
return append([]string{"-s", serial}, args...)
}
// AdbReverseRemove removes an adb reverse forwarding rule.
func AdbReverseRemove(socket string) error {
// wakeCommands keep the screen on and unlocked. A secure lock (PIN/password)
// cannot be dismissed here and must be unlocked out of band.
func wakeCommands() [][]string {
return [][]string{
{"svc", "power", "stayon", "true"},
{"input", "keyevent", "KEYCODE_WAKEUP"},
{"wm", "dismiss-keyguard"},
}
}
// PrepareDevice wakes and unlocks the device and disables the background
// freezers that would suspend the driver. Best effort: some OEM builds kill
// these commands (e.g. HyperOS SIGKILLs `svc power stayon`), so a failure is
// logged and skipped rather than aborting the run.
func PrepareDevice(ctx context.Context, serial string, stdout io.Writer) error {
adb, err := AdbBinary()
if err != nil {
return err
}
return exec.Command(adb, "reverse", "--remove", "localabstract:"+socket).Run()
for _, shellCommand := range append(wakeCommands(), antiFreezeCommands()...) {
args := adbArgs(serial, append([]string{"shell"}, shellCommand...)...)
if err := exec.CommandContext(ctx, adb, args...).Run(); err != nil {
fmt.Fprintf(stdout, "device prep: skipping `adb %s` (%v)\n", strings.Join(shellCommand, " "), err)
}
}
return nil
}
// driverPackages are the on-device native-driver instrumentation packages that
// the platform and OEM background freezers must not suspend mid-run.
var driverPackages = []string{"dev.mobile.maestro", "dev.mobile.maestro.test"}
// antiFreezeCommands turns off the background-process freezers that suspend the
// driver between actions. Android 12+ adds a cached-app freezer and a
// phantom-process killer; OEM builds (e.g. OnePlus/Oppo ColorOS OSense) add
// their own. Left on, they freeze the driver instrumentation while the app is
// foreground and the run stalls. set_sync_disabled_for_tests keeps the
// device_config writes from being reverted by server-side sync. All best effort:
// the caller skips and logs any command an OEM build rejects.
func antiFreezeCommands() [][]string {
commands := [][]string{
{"device_config", "set_sync_disabled_for_tests", "persistent"},
{"device_config", "put", "activity_manager_native_boot", "use_freezer", "false"},
{"device_config", "put", "activity_manager_native_boot", "freeze_exempt_inst_pkg", strings.Join(driverPackages, ",")},
{"settings", "put", "global", "settings_enable_monitor_phantom_procs", "false"},
{"device_config", "put", "activity_manager", "max_phantom_processes", "2147483647"},
{"dumpsys", "deviceidle", "disable"},
}
for _, pkg := range driverPackages {
commands = append(commands, []string{"dumpsys", "deviceidle", "whitelist", "+" + pkg})
}
return commands
}
// ReinstallApp resets an app to first-launch state by uninstalling and
// reinstalling it. This replaces `pm clear` for clear-state: ColorOS and other
// hardened OEM builds deny CLEAR_APP_USER_DATA even to the adb shell user, so a
// clear aborts the launch, whereas uninstall+install is always permitted.
// The uninstall is best effort so a not-installed app is not an error.
func ReinstallApp(ctx context.Context, serial, bundleID, apkPath string, stdout io.Writer) error {
adb, err := AdbBinary()
if err != nil {
return err
}
if output, err := exec.CommandContext(ctx, adb, adbArgs(serial, "uninstall", bundleID)...).CombinedOutput(); err != nil {
fmt.Fprintf(stdout, "clear-state: uninstall %s skipped (%v: %s)\n", bundleID, err, strings.TrimSpace(string(output)))
}
if output, err := exec.CommandContext(ctx, adb, adbArgs(serial, "install", "-r", apkPath)...).CombinedOutput(); err != nil {
return fmt.Errorf("install %s: %w: %s", apkPath, err, strings.TrimSpace(string(output)))
}
return nil
}
const threeButtonNavOverlay = "com.android.internal.systemui.navbar.threebutton"
// navModeOverlays are the system navigation-mode overlays. Only one is active at
// a time; the active one is restored after the run.
var navModeOverlays = []string{
"com.android.internal.systemui.navbar.gestural",
threeButtonNavOverlay,
"com.android.internal.systemui.navbar.twobutton",
}
// ForceThreeButtonNav switches the device to 3-button navigation for the run, so
// the fuzzer's swipes cannot trigger the gesture-nav home/back actions and fling
// the app off screen (the nav bar's own buttons are systemui-owned and already
// dropped from action candidates). It returns a function that restores the
// original navigation mode. Best effort: on any failure it leaves navigation
// untouched and returns a no-op restore.
func ForceThreeButtonNav(ctx context.Context, serial string, stdout io.Writer) func() {
adb, err := AdbBinary()
if err != nil {
return func() {}
}
// Decide before changing anything: if the current mode is unknown (an OEM
// overlay, or a parse failure) or already 3-button, there is nothing to
// restore, so leave navigation untouched rather than stranding the device in
// 3-button after the run.
restore := navModeToRestore(enabledNavOverlay(ctx, adb, serial))
if restore == "" {
return func() {}
}
if err := navOverlayCommand(ctx, adb, serial, threeButtonNavOverlay).Run(); err != nil {
fmt.Fprintf(stdout, "device prep: skipping 3-button nav (%v)\n", err)
return func() {}
}
return func() {
if err := navOverlayCommand(context.Background(), adb, serial, restore).Run(); err != nil {
fmt.Fprintf(stdout, "device prep: could not restore nav mode %s (%v)\n", restore, err)
}
}
}
// navModeToRestore returns the navigation overlay to restore after forcing
// 3-button nav, or "" when nothing should change: an unknown current mode (not
// restorable) or one that is already 3-button.
func navModeToRestore(original string) string {
if original == "" || original == threeButtonNavOverlay {
return ""
}
return original
}
// enabledNavOverlay returns the currently active navigation-mode overlay, or ""
// when it cannot be determined.
func enabledNavOverlay(ctx context.Context, adb, serial string) string {
output, err := exec.CommandContext(ctx, adb, adbArgs(serial, "shell", "cmd", "overlay", "list")...).Output()
if err != nil {
return ""
}
return parseEnabledNavOverlay(string(output))
}
// parseEnabledNavOverlay reads `cmd overlay list` output and returns the
// enabled ("[x]") navigation-mode overlay package.
func parseEnabledNavOverlay(overlayList string) string {
for line := range strings.SplitSeq(overlayList, "\n") {
trimmed := strings.TrimSpace(line)
if !strings.HasPrefix(trimmed, "[x]") {
continue
}
package_ := strings.TrimSpace(strings.TrimPrefix(trimmed, "[x]"))
if slices.Contains(navModeOverlays, package_) {
return package_
}
}
return ""
}
func navOverlayCommand(ctx context.Context, adb, serial, overlay string) *exec.Cmd {
return exec.CommandContext(ctx, adb, adbArgs(serial, "shell", "cmd", "overlay", "enable-exclusive", overlay)...)
}
// EnvWithAndroidPlatformTools returns env with the directory containing adb
@@ -191,6 +341,29 @@ func parseAVDList(output string) []string {
return avds
}
// pickDevice resolves which connected device to drive. A requested serial must
// be online. With no request: a single connected device is used; more than one
// is ambiguous and errors asking for --device, because the chosen serial is not
// threaded into the per-step adb calls, so silently picking one would leave
// every later bare `adb` command failing with "more than one device". No device
// connected returns found=false so the caller falls back to booting an AVD.
func pickDevice(requested string, connected []string) (serial string, found bool, err error) {
if requested != "" {
if !slices.Contains(connected, requested) {
return "", false, fmt.Errorf("device %q is not connected (online devices: %s)", requested, strings.Join(connected, ", "))
}
return requested, true, nil
}
switch len(connected) {
case 0:
return "", false, nil
case 1:
return connected[0], true, nil
default:
return "", false, fmt.Errorf("%d devices connected (%s); select one with --device", len(connected), strings.Join(connected, ", "))
}
}
func pickAVD(requested string, available []string) (string, error) {
if requested != "" {
if !slices.Contains(available, requested) {
@@ -239,13 +412,13 @@ func waitForBoot(ctx context.Context, timeout time.Duration) error {
}
// ForegroundPackage returns the package of the currently resumed activity on
// the connected device, or "" when it cannot be determined.
func ForegroundPackage(ctx context.Context) (string, error) {
// the given device, or "" when it cannot be determined.
func ForegroundPackage(ctx context.Context, serial string) (string, error) {
adb, err := AdbBinary()
if err != nil {
return "", err
}
output, err := exec.CommandContext(ctx, adb, "shell", "dumpsys", "activity", "activities").Output()
output, err := exec.CommandContext(ctx, adb, adbArgs(serial, "shell", "dumpsys", "activity", "activities")...).Output()
if err != nil {
return "", err
}
@@ -257,12 +430,16 @@ func ForegroundPackage(ctx context.Context) (string, error) {
// Unlike ForegroundPackage, this reflects what is actually on screen:
// ResumedActivity flips to a newly launched app before its first frame renders,
// while mCurrentFocus only names the app once its window is up.
func FocusedWindowPackage(ctx context.Context) (string, error) {
func FocusedWindowPackage(ctx context.Context, serial string) (string, error) {
adb, err := AdbBinary()
if err != nil {
return "", err
}
output, err := exec.CommandContext(ctx, adb, "shell", "dumpsys", "window").Output()
// Grep the focus line on-device: the full dumpsys window output is large and
// this runs on the per-step scope guard, so transferring it whole would add
// latency to every step. `|| true` keeps a no-match (grep exit 1) from
// surfacing as an error so it yields "" per the contract.
output, err := exec.CommandContext(ctx, adb, adbArgs(serial, "shell", "dumpsys window | grep mCurrentFocus || true")...).Output()
if err != nil {
return "", err
}
@@ -288,9 +465,22 @@ func parseForegroundPackage(dumpsys string) string {
return ""
}
// systemUIPackage is the owner reported for system overlays (notification
// shade, quick settings) that take window focus without a package/activity
// component name. The scope guard treats it as "not the app" and dismisses it.
const systemUIPackage = "com.android.systemui"
// systemOverlayWindowNames are the mCurrentFocus window names for the system
// panels a fuzzer gesture can pull over the app (a swipe from the status bar
// opens NotificationShade). They own focus while the app stays the resumed
// activity, so the resumed-activity signal alone misses them.
var systemOverlayWindowNames = []string{"NotificationShade", "ShadePanel", "QuickSettings", "VolumeUiDialog"}
// parseFocusedWindowPackage extracts the focused-window package from
// `dumpsys window` output by reading the mCurrentFocus component name. A
// "mCurrentFocus=null" line (no focused window) yields "".
// "mCurrentFocus=null" line (no focused window) yields "". A system overlay
// (e.g. the notification shade) yields systemUIPackage so callers can tell it
// apart from the app and from "no focus".
func parseFocusedWindowPackage(dumpsys string) string {
for line := range strings.SplitSeq(dumpsys, "\n") {
if !strings.Contains(line, "mCurrentFocus") {
@@ -299,6 +489,11 @@ func parseFocusedWindowPackage(dumpsys string) string {
if match := resumedActivityPackage.FindStringSubmatch(line); match != nil {
return match[1]
}
for _, overlay := range systemOverlayWindowNames {
if strings.Contains(line, overlay) {
return systemUIPackage
}
}
}
return ""
}
+168
View File
@@ -2,9 +2,22 @@ package android
import (
"reflect"
"slices"
"strings"
"testing"
)
func TestWakeCommands(t *testing.T) {
want := [][]string{
{"svc", "power", "stayon", "true"},
{"input", "keyevent", "KEYCODE_WAKEUP"},
{"wm", "dismiss-keyguard"},
}
if got := wakeCommands(); !reflect.DeepEqual(got, want) {
t.Errorf("wakeCommands() = %v, want %v", got, want)
}
}
func TestParseAdbDevices_OnlineOnly(t *testing.T) {
output := `List of devices attached
emulator-5554 device
@@ -28,6 +41,47 @@ func TestParseAdbDevices_Empty(t *testing.T) {
}
}
func TestPickDevice_RequestedOnline(t *testing.T) {
serial, found, err := pickDevice("physical-abc", []string{"emulator-5554", "physical-abc"})
if err != nil || !found || serial != "physical-abc" {
t.Fatalf("got (%q, %v, %v), want (physical-abc, true, nil)", serial, found, err)
}
}
func TestPickDevice_RequestedNotConnected(t *testing.T) {
_, found, err := pickDevice("physical-abc", []string{"emulator-5554"})
if err == nil {
t.Fatal("expected error for a serial that is not connected")
}
if found {
t.Fatal("found must be false when the requested device is absent")
}
}
func TestPickDevice_NoRequestSingleDeviceUsesIt(t *testing.T) {
serial, found, err := pickDevice("", []string{"emulator-5554"})
if err != nil || !found || serial != "emulator-5554" {
t.Fatalf("got (%q, %v, %v), want (emulator-5554, true, nil)", serial, found, err)
}
}
func TestPickDevice_NoRequestMultipleDevicesErrors(t *testing.T) {
serial, found, err := pickDevice("", []string{"emulator-5554", "physical-abc"})
if err == nil {
t.Fatal("expected an error asking for --device when several devices are connected")
}
if found || serial != "" {
t.Fatalf("ambiguous selection must not pick a device, got (%q, %v)", serial, found)
}
}
func TestPickDevice_NoneConnectedFallsBackToAVD(t *testing.T) {
serial, found, err := pickDevice("", nil)
if err != nil || found || serial != "" {
t.Fatalf("got (%q, %v, %v), want (\"\", false, nil)", serial, found, err)
}
}
func TestParseAVDList_DropsInfoLines(t *testing.T) {
output := `INFO | Storing crashdata in: /tmp/x
Medium_Phone_API_36.0
@@ -154,6 +208,21 @@ func TestParseFocusedWindowPackage(t *testing.T) {
dumpsys: " some unrelated dumpsys window output\n",
want: "",
},
{
name: "notification shade focused",
dumpsys: " mCurrentFocus=Window{885e289 u0 NotificationShade}",
want: "com.android.systemui",
},
{
name: "quick settings focused",
dumpsys: " mCurrentFocus=Window{abc u0 QuickSettings}",
want: "com.android.systemui",
},
{
name: "volume dialog focused",
dumpsys: " mCurrentFocus=Window{abc u0 VolumeUiDialog}",
want: "com.android.systemui",
},
}
for _, tc := range cases {
t.Run(tc.name, func(t *testing.T) {
@@ -163,3 +232,102 @@ func TestParseFocusedWindowPackage(t *testing.T) {
})
}
}
func TestParseEnabledNavOverlay(t *testing.T) {
cases := []struct {
name string
listing string
want string
}{
{
name: "gesture nav active",
listing: "[ ] com.android.internal.systemui.navbar.threebutton\n[x] com.android.internal.systemui.navbar.gestural\n[ ] com.android.internal.systemui.navbar.transparent",
want: "com.android.internal.systemui.navbar.gestural",
},
{
name: "three-button active",
listing: "[x] com.android.internal.systemui.navbar.threebutton\n[ ] com.android.internal.systemui.navbar.gestural",
want: "com.android.internal.systemui.navbar.threebutton",
},
{
name: "two-button active",
listing: "[x] com.android.internal.systemui.navbar.twobutton\n[ ] com.android.internal.systemui.navbar.gestural",
want: "com.android.internal.systemui.navbar.twobutton",
},
{
name: "ignores enabled non-nav overlays",
listing: "[x] com.some.other.overlay\n[ ] com.android.internal.systemui.navbar.gestural",
want: "",
},
{
name: "no overlay enabled",
listing: "[ ] com.android.internal.systemui.navbar.gestural\n[ ] com.android.internal.systemui.navbar.threebutton",
want: "",
},
}
for _, tc := range cases {
t.Run(tc.name, func(t *testing.T) {
if got := parseEnabledNavOverlay(tc.listing); got != tc.want {
t.Errorf("parseEnabledNavOverlay = %q, want %q", got, tc.want)
}
})
}
}
func TestAntiFreezeCommands_DisablesFreezersAndExemptsDriver(t *testing.T) {
commands := antiFreezeCommands()
has := func(want ...string) bool {
return slices.ContainsFunc(commands, func(c []string) bool { return slices.Equal(c, want) })
}
for _, want := range [][]string{
{"device_config", "set_sync_disabled_for_tests", "persistent"},
{"device_config", "put", "activity_manager_native_boot", "use_freezer", "false"},
{"settings", "put", "global", "settings_enable_monitor_phantom_procs", "false"},
{"dumpsys", "deviceidle", "disable"},
} {
if !has(want...) {
t.Errorf("anti-freeze commands missing exact command %v", want)
}
}
// The freezer exemption must be one device_config command whose final
// argument lists every driver package, not just the package string
// appearing somewhere among the commands.
exemption := findCommand(commands, "device_config", "put", "activity_manager_native_boot", "freeze_exempt_inst_pkg")
if exemption == nil {
t.Fatalf("no freeze_exempt_inst_pkg command found in %v", commands)
}
value := exemption[len(exemption)-1]
for _, pkg := range driverPackages {
if !strings.Contains(value, pkg) {
t.Errorf("freeze_exempt_inst_pkg value %q missing driver package %q", value, pkg)
}
if !has("dumpsys", "deviceidle", "whitelist", "+"+pkg) {
t.Errorf("driver package %q not whitelisted from doze", pkg)
}
}
}
// findCommand returns the first command whose leading tokens equal prefix.
func findCommand(commands [][]string, prefix ...string) []string {
for _, c := range commands {
if len(c) >= len(prefix) && slices.Equal(c[:len(prefix)], prefix) {
return c
}
}
return nil
}
func TestNavModeToRestore(t *testing.T) {
cases := map[string]string{
"com.android.internal.systemui.navbar.gestural": "com.android.internal.systemui.navbar.gestural",
"com.android.internal.systemui.navbar.twobutton": "com.android.internal.systemui.navbar.twobutton",
"com.android.internal.systemui.navbar.threebutton": "", // already 3-button: nothing to change
"": "", // unknown current mode: must not switch what cannot be restored
}
for original, want := range cases {
if got := navModeToRestore(original); got != want {
t.Errorf("navModeToRestore(%q) = %q, want %q", original, got, want)
}
}
}