Files
sanderling/internal/driver/sidecar/client_test.go
pj 6b0d6cb971 WIP: Drive physical Android devices over USB (#67)
* feat(sidecar): reach USB devices via the adb server by serial

* feat(test): add --device flag to target a specific Android device by serial

* feat(folio): select Android device via ANDROID_DEVICE in justfile

* feat(conformance): add android backend to the gate suite

* feat(android): keep device awake and unlocked so the app stays foreground

* feat(conformance): prep physical android device (autofill/verifier/stayon)

* fix(android): make device prep best-effort so OEM-blocked commands don't abort the run

* fix(verifier): require positive bounds for swipe candidates

A zero-bounds element centers at (0,0); a downward swipe from the
top-left corner is the system gesture that pulls down the notification
shade, dragging the fuzzer out of the app. Swipes now require positive
bounds like every other verb.

* fix(runner): harden app-scope guard against launcher and overlays

The per-step guard now relaunches and waits until the app window is
actually drawn before proceeding, so a slow physical-device relaunch no
longer lets an observe or action land on the launcher. It also detects a
system overlay (notification shade) stealing window focus while the app
stays resumed, and dismisses it with back.

* feat(android): harden physical-device runs in device prep

Device prep now disables the AOSP cached-app freezer, phantom-process
killer, and Doze (and exempts the driver) so OEM background management
stops suspending the driver mid-run. Adds ReinstallApp for clear-state on
ROMs that deny pm clear, and teaches focus detection to report the
notification shade as systemui so the scope guard can dismiss it.

* feat(driver): clear-state via APK reinstall when pm clear is blocked

When an APK path is set, Android clear-state resets the app by
uninstalling and reinstalling instead of asking the sidecar to pm clear,
which hardened OEM builds (ColorOS) deny even to the adb shell user.
Falls back to the sidecar clear path when no APK path is provided.

* feat(cli): add --android-app-path for clear-state reinstall

Wires the APK path from the test command through to the sidecar client so
Android clear-state can reset apps on OEM builds that deny pm clear.

* chore(folio): pass --android-app-path in just test

* fix(runner): clamp swipe/scroll origin out of edge gesture zones

A gesture starting in the top status-bar strip pulls down the
notification shade; the bottom and side strips are the home and back
gestures. Any of them drags the fuzzer out of the app. Swipe and scroll
origins are now clamped into a safe inner area sized from the maximum
element extent (the Android hierarchy root reports zero bounds, so the
extent is the reliable screen size). Calibrated on device: origins below
~7% of height no longer open the shade.

* perf(sidecar): faster Android text input and drop redundant settle poll

inputText now uses adb `input text` for short shell-safe ASCII (~5x
faster than the driver's per-character path) and falls back to the driver
for unicode, injection payloads, and overflow-length strings. waitForIdle
drops the structural-hash poll that followed waitForAppToSettle: each
hierarchy fetch is ~500ms on a physical device, so it cost ~2.8s per
mutating step for marginal benefit, and the runner already re-fetches
transitional frames. Cuts p95 step latency from ~6.5s to ~5.1s; G1-G4
still pass.

* fix(verifier): exclude soft-keyboard region from action candidates

The fuzzer was tapping Gboard's "Settings" key, navigating out of the
app. That key is a bare FrameLayout with a content-desc and no package or
resource-id, so the package-based scope filter missed it. Candidates whose
center falls in the keyboard region (derived from the IME elements' bounds)
are now dropped, so no tap or long-press lands on a key. Opt-in with app
scoping; unscoped runs keep every node.

* perf(runner): replace focus-tap settle with a brief wait

The full WaitForIdle after a field-focus tap cost ~0.5-1s per InputText
step on a physical device while the keyboard animated in. The tap registers
focus immediately and text is injected into the focused view, so a short
fixed wait suffices. Drops p95 step latency ~5.1s to ~4.0s; G1-G4 stay
green.

* chore(conformance): platform-aware G5 p95 budget for android

The 2500ms ceiling was calibrated on the iOS simulator. A physical Android
device drives every step over USB (snapshot + settle + adb round-trips), so
its per-step floor is several times higher; holding it to 2500ms would force
removing the settle/retry logic the correctness gates depend on. The android
backend now defaults to 4500ms (override with P95_LIMIT_MS); iOS stays 2500.

* fix(sidecar): retry maestro android driver startup

The maestro Android driver's dadb.open() occasionally misses its startup
deadline (its instrumentation host is slow to come up right after a reboot
or per-run reinstall), which aborted the whole run. Retry the open a few
times with a short backoff so a transient timeout recovers.

* chore(conformance): widen android G5 budget to 5500ms

Physical-device p95 swung 3209-4612ms across sessions (cold runs right
after a reboot are slower). 4500ms was too tight for that jitter; 5500ms
covers the observed ceiling with headroom.

* web replay fix

* feat(android): force 3-button nav during runs to prevent app drift

On gesture navigation a fuzzer swipe can trigger swipe-up-home or
edge-back and fling the app off screen. Device-prep now switches to
3-button navigation for the run (no edge gestures; the nav bar's buttons
are systemui-owned and already excluded from action candidates) and
restores the original navigation mode when the run ends. Best effort:
leaves nav untouched if the overlay command is unavailable.

* fix(android): target the selected device in adb reads; don't strand nav mode

Review fixes:
- ForegroundPackage/FocusedWindowPackage now take a serial and pass -s, so the
  foreground/scope guard works when several devices are attached (the --device
  path). Previously they ran bare `adb shell`, which errors with multiple
  devices, silently disabling app-scope enforcement. The sidecar client passes
  its serial through.
- Extract an adbArgs helper and route every adb call through it, removing four
  duplicated serial-arg builders.
- ForceThreeButtonNav now decides what to restore before changing anything: if
  the current mode is unknown or already 3-button it leaves nav untouched,
  instead of switching and then stranding the device in 3-button. Logic split
  into the pure navModeToRestore, now unit tested.

* fix(runner): restore scrollBounds doc; cover destination clamp and screenBounds

Review fixes: move the scrollBounds doc comment back onto scrollBounds (it was
stranded above screenBounds by an insertion). Extend the clamp test to assert an
off-screen destination is clamped onto the screen and that the origin lands
exactly on the margin.

* test(verifier): cover keyboardRegionTop, including the decor-view guard

The full-screen IME decor view rejection had no test; removing it left the
suite green. Add direct cases: no keyboard -> sentinel, decor view ignored in
favor of the real keyboard line, and decor-only -> sentinel.

* style(cli): gofmt testOptions field alignment

* fix(sidecar): keep a leading dash off the fast input path

A value starting with '-' could be read as an option by `adb input text`, so
the fast-path regex now requires a non-dash first character; such values fall
back to the driver. Also cover the dadb-target branch where a colon precedes a
non-numeric port (a USB serial, not host:port).

* refactor(verifier): scope action candidates by window ownership

Replaces the leaky per-element package check and the keyboard-region Y
heuristic with one rule: walk the window tree propagating each node's owning
package (empty and the neutral android framework package are transparent); a
node is in scope only when no concrete foreign package owns it (the app's own
window carries no package on Compose apps) or the owner is the app package.

This drops whole foreign windows (soft keyboard, system UI, launcher) AND
their empty-package child wrappers -- e.g. a keyboard's 'Settings' key, which
the old empty-package-is-in-scope rule admitted and which navigated out of the
app. Deletes keyboardRegionTop/isInputMethodElement.

* fix(runner): re-check foreground at apply time, skip stale actions

ensureForeground runs before observe, but the app can leave between observe and
apply (a prior gesture settling late); swipes/keys then fire stale coordinates
onto whatever screen is now up. Re-check foreground immediately before applying
and, when the app is gone, skip the action and log it (making the escape
visible) so the next step's guard relaunches instead.

* fix(android): type long ASCII via fast guarded path to stop keystroke escape

A 4096-char corpus string exceeded the fast input cap and fell to the
per-character driver path, which takes ~120s. During that uninterruptible
window focus could leave the app and the remaining keystrokes sprayed into
the launcher search box. Route shell-safe ASCII of any length through adb
input text, chunked, re-checking the foreground app between chunks and
stopping if it changed.

* chore: ignore gate artifacts and local scratch files

* refactor(runner): narrow gesture clamp to the top shade strip

3-button nav (forced for every run) disables the side back and bottom home
gestures at the OS level. On-device probing confirmed side and bottom swipe
origins no longer drift, leaving the notification shade as the only edge
gesture a swipe can trigger. Clamp only the top strip; keep origin and
destination on screen otherwise.

* chore(format): add .editorconfig enforcing 80-column limit

* chore(format): add prettier config with 80-char printWidth

* chore(deps): add prettier devDependency to replay-ui

* chore(deps): add prettier devDependency to folio-web

* chore(deps): add prettier devDependency to spec package

* chore(format): add swift-format config with 80-char lineLength

* feat(format): add make fmt targets for per-language 80-col formatting

* fix(runner): translate gesture to safe area so near-top scrolls keep direction

Clamping the swipe origin to the top margin while leaving the destination on the full screen used two reference frames: a scrollable container pinned in the top strip had its origin pushed past the destination, reversing the gesture. Translate the whole from->to segment down by the same delta so the origin clears the shade strip without flipping direction. Adds a scroll-near-top test that fails under the old origin-only clamp.

* fix(runner): apply-time guard consults focused window, not just resumed activity

ensureForeground detects a system overlay (notification shade) owning the focused window while the app stays the resumed activity, but appIsForeground only queried ForegroundApp. A swipe that pulls the shade over the app between observe and apply then fired onto the shade. Mirror the focus check at apply time so the action skips and the next step dismisses the overlay.

* test(runner): cover apply-time foreground skip and appIsForeground table

Adds a Run-level test asserting no tap reaches the driver while a system overlay holds focus (guards against the skip branch being dead-coded), plus a decision-table test for appIsForeground. Adds ForegroundErr/FocusedWindowErr to the mock driver so the guard's transient-read paths are exercised.

* fix(sidecar): harden android driver open, input guard, pressKey, foreground marker

- openWithRetry rebuilt a closed AndroidDriver, whose gRPC channel is final and shut down by close(); the retry then ran against a dead channel. Build a fresh driver per attempt and extract a unit-tested retryOpen helper (named DRIVER_OPEN_ATTEMPTS/BACKOFF).
- pressKey on the Maestro backend did KEY_MAP[key] (no lowercase, no throw), silently dropping unknown or wrong-case keys; route through a pure maestroKeyFor that lowercases and rejects unknown keys like the Stub contract.
- the mid-type foreground guard (typeShellSafe) was untested; extract a pure typeChunks and cover stop-on-foreground-change, always-send-first-chunk, and unknown-owner.
- foreground detection required the literal topResumedActivity=ActivityRecord; align parseResumedPackage to the same *ResumedActivity marker set Go reads so OEM wording does not disable the guard.

* fix(conformance): pin self-test p95 budget and score install failures as run failures

self_test reused the backend-dependent P95_LIMIT_MS, so under BACKEND=android the 4000ms slow fixture rated PASS and the offline analyzer check failed from an env var; pin it to 2500. A per-run adb install failure ran unguarded under set -e and aborted the whole harness; guard it, record the run as a G1 failure, and continue.

* fix(android): require --device when several devices are connected

With no serial requested and more than one device online, pickDevice silently returned connected[0], but that serial is never threaded into the per-step adb calls, so every later bare adb command failed with "more than one device". Error instead and ask for --device, mirroring pickAVD; a single device stays unambiguous.

* refactor(android): move PrepareDevice doc onto it; extract tested wakeCommands

The PrepareDevice doc block was stranded above adbArgs, leaving the exported function undocumented under godoc. Move it back and split the wake/keyguard tuples into wakeCommands so they have a unit test.

* perf(verifier): memoize scopedElements per tree

scopedElements rebuilt a full tree walk plus map on every candidatesForVerb call (~16 per step). Cache the result keyed on lastTree and invalidate it in PushSnapshot.

* fix(sidecar): default reinstallApp in SetClearStateReinstall; cover non-android clear

Only Dial set reinstallApp, so a Client built another way would nil-deref on Android clear-state. Default it in SetClearStateReinstall too. Add a non-android test so the platform guard has negative coverage: dropping the android check would now fail.

* test(runner): make focusTapSettle injectable so apply tests don't sleep 250ms

The focus-tap settle was a const, so five InputText apply tests each blocked the full 250ms. Make it a package var and shorten it per-test with cleanup.

* refactor(runner,android): drop unused bringToForeground return; grep no-match yields empty

bringToForeground's bool return was read by no caller. FocusedWindowPackage's on-device grep exited 1 on no match, surfacing as an error instead of the documented ""; add || true.

* perf(sidecar): reuse a single Jackson ObjectMapper

structuralHash, countRouteScreens, and hierarchy each built a fresh ObjectMapper per call inside the stability poll; the instance is thread-safe and meant to be reused. Hoist one shared val.

* refactor(android): remove unused AdbReverse/AdbReverseRemove

No callers anywhere in the tree; they were also the only adb calls bypassing adbArgs. Dead code, removed.

* style(runner): trim non-load-bearing comments from this PR's runner code and tests

* style(sidecar): trim non-load-bearing comments from this PR's driver code and tests
2026-06-11 10:10:05 +05:30

685 lines
21 KiB
Go

package sidecar
import (
"context"
"io"
"net"
"strings"
"sync"
"testing"
"time"
"google.golang.org/grpc"
"google.golang.org/grpc/codes"
"google.golang.org/grpc/status"
driverpb "github.com/priyanshujain/sanderling/proto/driverpb"
)
type fakeServer struct {
driverpb.UnimplementedDriverServer
mutex sync.Mutex
healthReady bool
healthCalls int
healthReadyAfterCall int
launchedBundleID string
clearState bool
terminateCalls int
taps []int32
tapSelectors []string
inputs []string
idleMillis []int64
hierarchy string
imagePNG []byte
imageWidth int32
imageHeight int32
longPresses []int32
doubleTaps []int32
swipes []*driverpb.SwipeRequest
erases []int32
pressedKeys []string
metricsBundles []string
logsRequests []*driverpb.RecentLogsRequest
logEntries []*driverpb.LogEntry
metrics *driverpb.MetricsResponse
healthError error
tapError error
}
func (s *fakeServer) Health(_ context.Context, _ *driverpb.Empty) (*driverpb.HealthStatus, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.healthCalls++
if s.healthError != nil {
return nil, s.healthError
}
ready := s.healthReady
if s.healthReadyAfterCall > 0 && s.healthCalls >= s.healthReadyAfterCall {
ready = true
}
return &driverpb.HealthStatus{Ready: ready, Version: "test", Platform: "android"}, nil
}
func (s *fakeServer) Launch(_ context.Context, request *driverpb.LaunchRequest) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.launchedBundleID = request.GetBundleId()
s.clearState = request.GetClearState()
return &driverpb.Empty{}, nil
}
func (s *fakeServer) Terminate(_ context.Context, _ *driverpb.Empty) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.terminateCalls++
return &driverpb.Empty{}, nil
}
func (s *fakeServer) Tap(_ context.Context, point *driverpb.Point) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
if s.tapError != nil {
return nil, s.tapError
}
s.taps = append(s.taps, point.GetX(), point.GetY())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) TapSelector(_ context.Context, selector *driverpb.Selector) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.tapSelectors = append(s.tapSelectors, selector.GetValue())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) InputText(_ context.Context, text *driverpb.Text) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.inputs = append(s.inputs, text.GetValue())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) WaitForIdle(_ context.Context, duration *driverpb.Duration) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.idleMillis = append(s.idleMillis, duration.GetMillis())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) LongPress(_ context.Context, point *driverpb.Point) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.longPresses = append(s.longPresses, point.GetX(), point.GetY())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) DoubleTap(_ context.Context, point *driverpb.Point) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.doubleTaps = append(s.doubleTaps, point.GetX(), point.GetY())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) Swipe(_ context.Context, request *driverpb.SwipeRequest) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.swipes = append(s.swipes, request)
return &driverpb.Empty{}, nil
}
func (s *fakeServer) EraseText(_ context.Context, request *driverpb.EraseTextRequest) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.erases = append(s.erases, request.GetCharacterCount())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) PressKey(_ context.Context, request *driverpb.PressKeyRequest) (*driverpb.Empty, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.pressedKeys = append(s.pressedKeys, request.GetKey())
return &driverpb.Empty{}, nil
}
func (s *fakeServer) RecentLogs(_ context.Context, request *driverpb.RecentLogsRequest) (*driverpb.LogEntries, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.logsRequests = append(s.logsRequests, request)
return &driverpb.LogEntries{Entries: s.logEntries}, nil
}
func (s *fakeServer) Metrics(_ context.Context, request *driverpb.MetricsRequest) (*driverpb.MetricsResponse, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
s.metricsBundles = append(s.metricsBundles, request.GetBundleId())
if s.metrics != nil {
return s.metrics, nil
}
return &driverpb.MetricsResponse{}, nil
}
func (s *fakeServer) Hierarchy(_ context.Context, _ *driverpb.Empty) (*driverpb.HierarchyJSON, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
return &driverpb.HierarchyJSON{Json: s.hierarchy}, nil
}
func (s *fakeServer) Screenshot(_ context.Context, _ *driverpb.Empty) (*driverpb.Image, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
return &driverpb.Image{Png: s.imagePNG, Width: s.imageWidth, Height: s.imageHeight}, nil
}
func (s *fakeServer) Snapshot(_ context.Context, _ *driverpb.Empty) (*driverpb.SnapshotResponse, error) {
s.mutex.Lock()
defer s.mutex.Unlock()
return &driverpb.SnapshotResponse{
Hierarchy: &driverpb.HierarchyJSON{Json: s.hierarchy},
Screenshot: &driverpb.Image{Png: s.imagePNG, Width: s.imageWidth, Height: s.imageHeight},
}, nil
}
type harness struct {
server *grpc.Server
fake *fakeServer
address string
}
func newHarness(t *testing.T) *harness {
t.Helper()
listener, err := net.Listen("tcp", "127.0.0.1:0")
if err != nil {
t.Fatal(err)
}
server := grpc.NewServer()
fake := &fakeServer{healthReady: true, hierarchy: `{"x":1}`, imagePNG: []byte{0xFF}, imageWidth: 1080, imageHeight: 2340}
driverpb.RegisterDriverServer(server, fake)
go func() { _ = server.Serve(listener) }()
t.Cleanup(func() {
server.Stop()
_ = listener.Close()
})
return &harness{server: server, fake: fake, address: listener.Addr().String()}
}
func TestClient_HealthRoundTrip(t *testing.T) {
state := newHarness(t)
client, err := Dial(state.address)
if err != nil {
t.Fatal(err)
}
defer client.Close()
got, err := client.Health(context.Background())
if err != nil {
t.Fatal(err)
}
if !got.Ready || got.Version != "test" || got.Platform != "android" {
t.Errorf("unexpected health: %+v", got)
}
}
func TestClient_WaitForHealth_PollsUntilReady(t *testing.T) {
state := newHarness(t)
state.fake.mutex.Lock()
state.fake.healthReady = false
state.fake.healthReadyAfterCall = 2
state.fake.mutex.Unlock()
client, err := Dial(state.address)
if err != nil {
t.Fatal(err)
}
defer client.Close()
ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)
defer cancel()
if err := client.WaitForHealth(ctx, 25*time.Millisecond); err != nil {
t.Fatalf("WaitForHealth: %v", err)
}
state.fake.mutex.Lock()
defer state.fake.mutex.Unlock()
if state.fake.healthCalls < 2 {
t.Errorf("expected at least 2 health polls, got %d", state.fake.healthCalls)
}
}
func TestClient_WaitForHealth_HonorsContext(t *testing.T) {
state := newHarness(t)
state.fake.mutex.Lock()
state.fake.healthReady = false
state.fake.mutex.Unlock()
client, err := Dial(state.address)
if err != nil {
t.Fatal(err)
}
defer client.Close()
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
defer cancel()
err = client.WaitForHealth(ctx, 25*time.Millisecond)
if err == nil || !strings.Contains(err.Error(), "context") {
t.Fatalf("expected context error, got %v", err)
}
}
func TestClient_Health_SurfacesRPCError(t *testing.T) {
state := newHarness(t)
state.fake.mutex.Lock()
state.fake.healthError = status.Error(codes.Unavailable, "boom")
state.fake.mutex.Unlock()
client, err := Dial(state.address)
if err != nil {
t.Fatal(err)
}
defer client.Close()
if _, err := client.Health(context.Background()); err == nil {
t.Fatal("expected Health to surface the RPC error, got nil")
}
}
func TestClient_LaunchAndTerminate(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
if err := client.Launch(context.Background(), "com.example", true, nil); err != nil {
t.Fatal(err)
}
if state.fake.launchedBundleID != "com.example" || !state.fake.clearState {
t.Errorf("launch payload wrong: %+v", state.fake)
}
if err := client.Terminate(context.Background()); err != nil {
t.Fatal(err)
}
if state.fake.terminateCalls != 1 {
t.Errorf("terminate calls: %d", state.fake.terminateCalls)
}
}
func TestClient_LaunchClearStateReinstallsOnAndroid(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
client.SetPlatform("android")
client.SetClearStateReinstall("serial123", "/tmp/app.apk", io.Discard)
var got struct {
serial, bundleID, apkPath string
}
called := 0
client.reinstallApp = func(_ context.Context, serial, bundleID, apkPath string, _ io.Writer) error {
called++
got.serial, got.bundleID, got.apkPath = serial, bundleID, apkPath
return nil
}
if err := client.Launch(context.Background(), "app.folio", true, nil); err != nil {
t.Fatal(err)
}
if called != 1 {
t.Fatalf("reinstall called %d times, want 1", called)
}
if got.serial != "serial123" || got.bundleID != "app.folio" || got.apkPath != "/tmp/app.apk" {
t.Errorf("reinstall args wrong: %+v", got)
}
// The sidecar must not also clear: the host reinstall already reset state.
if state.fake.clearState {
t.Error("sidecar clearState should be false after host reinstall")
}
if state.fake.launchedBundleID != "app.folio" {
t.Errorf("launched bundle wrong: %q", state.fake.launchedBundleID)
}
}
func TestClient_LaunchClearStateReinstallFailureAborts(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
client.SetPlatform("android")
client.SetClearStateReinstall("", "/tmp/app.apk", io.Discard)
client.reinstallApp = func(_ context.Context, _, _, _ string, _ io.Writer) error {
return context.DeadlineExceeded
}
if err := client.Launch(context.Background(), "app.folio", true, nil); err == nil {
t.Fatal("expected launch to fail when reinstall fails")
}
if state.fake.launchedBundleID == "app.folio" {
t.Error("sidecar launch should not be called after a failed reinstall")
}
}
func TestClient_LaunchClearStateWithoutApkPathUsesSidecarClear(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
client.SetPlatform("android")
client.reinstallApp = func(_ context.Context, _, _, _ string, _ io.Writer) error {
t.Fatal("reinstall should not run without an apk path")
return nil
}
if err := client.Launch(context.Background(), "app.folio", true, nil); err != nil {
t.Fatal(err)
}
if !state.fake.clearState {
t.Error("without an apk path the sidecar clearState path must remain")
}
}
func TestClient_LaunchClearStateNonAndroidUsesSidecarClear(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
client.SetPlatform("ios")
client.SetClearStateReinstall("", "/tmp/app.app", io.Discard)
client.reinstallApp = func(_ context.Context, _, _, _ string, _ io.Writer) error {
t.Fatal("reinstall must not run on a non-android platform")
return nil
}
if err := client.Launch(context.Background(), "app.folio", true, nil); err != nil {
t.Fatal(err)
}
if !state.fake.clearState {
t.Error("non-android clear-state must forward clearState to the sidecar")
}
}
func TestClient_TapAndTapSelector(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
if err := client.Tap(context.Background(), 100, 250); err != nil {
t.Fatal(err)
}
if len(state.fake.taps) != 2 || state.fake.taps[0] != 100 || state.fake.taps[1] != 250 {
t.Errorf("tap coordinates wrong: %v", state.fake.taps)
}
if err := client.TapSelector(context.Background(), "id:home"); err != nil {
t.Fatal(err)
}
if len(state.fake.tapSelectors) != 1 || state.fake.tapSelectors[0] != "id:home" {
t.Errorf("selectors wrong: %v", state.fake.tapSelectors)
}
}
// TestClient_ScalarForwardingRPCs pins that each single-payload RPC forwards
// its argument unchanged to the captured request: a dropped/mistyped text,
// idle duration, erase count, or logical key would change device behavior with
// no other field to disambiguate it.
func TestClient_ScalarForwardingRPCs(t *testing.T) {
tests := []struct {
name string
call func(c *Client) error
check func(t *testing.T, s *fakeServer)
}{
{"InputText", func(c *Client) error { return c.InputText(context.Background(), "hello world") }, func(t *testing.T, s *fakeServer) {
if len(s.inputs) != 1 || s.inputs[0] != "hello world" {
t.Errorf("inputs wrong: %v", s.inputs)
}
}},
{"WaitForIdle", func(c *Client) error { return c.WaitForIdle(context.Background(), 250*time.Millisecond) }, func(t *testing.T, s *fakeServer) {
if len(s.idleMillis) != 1 || s.idleMillis[0] != 250 {
t.Errorf("idleMillis wrong: %v", s.idleMillis)
}
}},
{"EraseText", func(c *Client) error { return c.EraseText(context.Background(), 7) }, func(t *testing.T, s *fakeServer) {
if len(s.erases) != 1 || s.erases[0] != 7 {
t.Errorf("erase count wrong: %v", s.erases)
}
}},
{"PressKey", func(c *Client) error { return c.PressKey(context.Background(), "back") }, func(t *testing.T, s *fakeServer) {
if len(s.pressedKeys) != 1 || s.pressedKeys[0] != "back" {
t.Errorf("pressed key wrong: %v", s.pressedKeys)
}
}},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
if err := tt.call(client); err != nil {
t.Fatal(err)
}
tt.check(t, state.fake)
})
}
}
func TestClient_HierarchyAndScreenshot(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
hierarchy, err := client.Hierarchy(context.Background())
if err != nil {
t.Fatal(err)
}
if hierarchy != `{"x":1}` {
t.Errorf("hierarchy wrong: %q", hierarchy)
}
image, err := client.Screenshot(context.Background())
if err != nil {
t.Fatal(err)
}
if image.Width != 1080 || image.Height != 2340 || len(image.PNG) != 1 {
t.Errorf("image wrong: %+v", image)
}
}
func TestClient_SnapshotPairsHierarchyAndScreenshot(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
hierarchyJSON, image, err := client.Snapshot(context.Background())
if err != nil {
t.Fatal(err)
}
if hierarchyJSON != `{"x":1}` {
t.Errorf("hierarchy wrong: %q", hierarchyJSON)
}
if image.Width != 1080 || image.Height != 2340 || len(image.PNG) != 1 {
t.Errorf("image wrong: %+v", image)
}
}
// TestClient_RPCErrorSurfaces is the representative check that a gRPC error
// status from the sidecar propagates out of an action RPC instead of being
// swallowed into a nil error. Per-method coverage of the sidecar-side status
// mapping lives in the sidecar server tests.
func TestClient_RPCErrorSurfaces(t *testing.T) {
state := newHarness(t)
state.fake.mutex.Lock()
state.fake.tapError = status.Error(codes.Internal, "device offline")
state.fake.mutex.Unlock()
client, _ := Dial(state.address)
defer client.Close()
err := client.Tap(context.Background(), 1, 2)
if err == nil {
t.Fatal("expected Tap to surface the gRPC error, got nil")
}
if status.Code(err) != codes.Internal {
t.Errorf("expected INTERNAL code, got %v", status.Code(err))
}
}
// TestClient_DoubleTapSelectorFiresTwice confirms the selector fallback
// composes exactly two taps; a broken composition would single-tap and the
// double-tap gesture would silently degrade.
func TestClient_DoubleTapSelectorFiresTwice(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
if err := client.DoubleTapSelector(context.Background(), "id:home"); err != nil {
t.Fatal(err)
}
state.fake.mutex.Lock()
defer state.fake.mutex.Unlock()
if len(state.fake.tapSelectors) != 2 || state.fake.tapSelectors[0] != "id:home" || state.fake.tapSelectors[1] != "id:home" {
t.Errorf("expected two taps on id:home, got %v", state.fake.tapSelectors)
}
}
// TestClient_DoubleTapSelectorCancelBetweenTaps confirms a context cancelled
// during the inter-tap gap fires exactly one tap and returns ctx.Err() - it
// must neither double-fire nor swallow the cancellation.
func TestClient_DoubleTapSelectorCancelBetweenTaps(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
ctx, cancel := context.WithCancel(context.Background())
go func() {
for {
state.fake.mutex.Lock()
n := len(state.fake.tapSelectors)
state.fake.mutex.Unlock()
if n >= 1 {
cancel()
return
}
}
}()
err := client.DoubleTapSelector(ctx, "id:home")
if err == nil || !strings.Contains(err.Error(), "context") {
t.Fatalf("expected context error, got %v", err)
}
state.fake.mutex.Lock()
defer state.fake.mutex.Unlock()
if len(state.fake.tapSelectors) != 1 {
t.Errorf("expected exactly one tap before cancellation, got %d", len(state.fake.tapSelectors))
}
}
// TestClient_SwipeForwardsEndpointsInOrder pins down that From keeps the start
// point and To the end point. A from/to transposition would send the swipe in
// the reverse direction on-device while every other assertion still passed.
func TestClient_SwipeForwardsEndpointsInOrder(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
if err := client.Swipe(context.Background(), 10, 20, 300, 400, 150*time.Millisecond); err != nil {
t.Fatal(err)
}
if len(state.fake.swipes) != 1 {
t.Fatalf("expected 1 swipe, got %d", len(state.fake.swipes))
}
got := state.fake.swipes[0]
if got.GetFrom().GetX() != 10 || got.GetFrom().GetY() != 20 {
t.Errorf("from wrong: %+v", got.GetFrom())
}
if got.GetTo().GetX() != 300 || got.GetTo().GetY() != 400 {
t.Errorf("to wrong: %+v", got.GetTo())
}
if got.GetDurationMillis() != 150 {
t.Errorf("duration wrong: %d", got.GetDurationMillis())
}
}
// TestClient_PointRPCsForwardCoordinates guards against x/y swaps in the point
// RPCs that have no other field to disambiguate which axis is which.
func TestClient_PointRPCsForwardCoordinates(t *testing.T) {
tests := []struct {
name string
call func(c *Client) error
got func(s *fakeServer) []int32
}{
{"LongPress", func(c *Client) error { return c.LongPress(context.Background(), 12, 34) }, func(s *fakeServer) []int32 { return s.longPresses }},
{"DoubleTap", func(c *Client) error { return c.DoubleTap(context.Background(), 12, 34) }, func(s *fakeServer) []int32 { return s.doubleTaps }},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
state := newHarness(t)
client, _ := Dial(state.address)
defer client.Close()
if err := tt.call(client); err != nil {
t.Fatal(err)
}
got := tt.got(state.fake)
if len(got) != 2 || got[0] != 12 || got[1] != 34 {
t.Errorf("coordinates wrong: %v", got)
}
})
}
}
// TestClient_MetricsMapsResponseFields catches CPU/heap/total being read off
// the wrong proto field, which would mislabel a memory regression as CPU.
func TestClient_MetricsMapsResponseFields(t *testing.T) {
state := newHarness(t)
state.fake.mutex.Lock()
state.fake.metrics = &driverpb.MetricsResponse{CpuPercent: 12.5, HeapBytes: 100, TotalMemoryBytes: 200}
state.fake.mutex.Unlock()
client, _ := Dial(state.address)
defer client.Close()
got, err := client.Metrics(context.Background(), "com.example")
if err != nil {
t.Fatal(err)
}
if got.CPUPercent != 12.5 || got.HeapBytes != 100 || got.TotalMemoryBytes != 200 {
t.Errorf("metrics mapping wrong: %+v", got)
}
if len(state.fake.metricsBundles) != 1 || state.fake.metricsBundles[0] != "com.example" {
t.Errorf("bundle id not forwarded: %v", state.fake.metricsBundles)
}
}
// TestClient_RecentLogsSinceBranches pins both arms of the zero-time guard: a
// zero time must send sinceMillis=0 (don't accidentally floor to epoch via
// UnixMilli of a zero Time, which is a huge negative number), a real time must
// forward its unix-millis. The response decode is checked alongside.
func TestClient_RecentLogsSinceBranches(t *testing.T) {
realTime := time.UnixMilli(1_700_000_000_000)
tests := []struct {
name string
since time.Time
wantMilli int64
}{
{"zero time forwards 0", time.Time{}, 0},
{"real time forwards unix millis", realTime, realTime.UnixMilli()},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
state := newHarness(t)
state.fake.mutex.Lock()
state.fake.logEntries = []*driverpb.LogEntry{{UnixMillis: 5, Level: "E", Tag: "t", Message: "boom"}}
state.fake.mutex.Unlock()
client, _ := Dial(state.address)
defer client.Close()
logs, err := client.RecentLogs(context.Background(), tt.since, "E")
if err != nil {
t.Fatal(err)
}
state.fake.mutex.Lock()
defer state.fake.mutex.Unlock()
req := state.fake.logsRequests[len(state.fake.logsRequests)-1]
if req.GetSinceUnixMillis() != tt.wantMilli {
t.Errorf("sinceUnixMillis = %d, want %d", req.GetSinceUnixMillis(), tt.wantMilli)
}
if req.GetLevelAtLeast() != "E" {
t.Errorf("levelAtLeast = %q, want E", req.GetLevelAtLeast())
}
if len(logs) != 1 || logs[0].Level != "E" || logs[0].Message != "boom" || logs[0].UnixMillis != 5 || logs[0].Tag != "t" {
t.Errorf("decoded logs wrong: %+v", logs)
}
})
}
}