Files
sanderling/cmd/sanderling/doctor.go
T
pj 90224dfd06 Physical-device iOS support (#64) (#66)
* feat(companion): add appState, eraseText, pressKey runner handlers

The Go runner transport already calls these methods; the in-device runner
implemented them only latently. They become load-bearing on the device
path, where the hybrid's legacy-companion fallback is absent. Backward
compatible: the simulator hybrid never calls them.

* feat(ios): resolve physical devices from devicectl

ResolveDevice parses xcrun devicectl list devices into Device{Name,
HardwareUDID, CoreDeviceID}: the hardware UDID feeds xcodebuild/iproxy
and the CoreDevice id feeds devicectl install. Matches by name or either
id; errors list candidates on none/ambiguous. Fixes the stale sidecar
comment on ResolveTarget.

* feat(ioscompanion): runner-only device driver mode

NewDevice reuses Driver with d.companion set to the runner dialed over an
iproxy usbmux tunnel, hybrid=false, runnerClient=nil. The existing accessor
seams then route launch/snapshot/text/gesture to the runner with no new
DeviceDriver methods. Device seams swap clear-state to a devicectl
reinstall, container reset to a warn-once no-op, and paste grant to a no-op.
realSpawnDeviceRunner builds and signs the runner at run time via the App
Store Connect API key (no Xcode UI), caching on a source hash.

* test(ioscompanion): cover device wiring, routing, and shell-out argv

Seam-driven NewDevice wiring + gesture/text routing (asserting no keyboard
HID), devicectl/build/test/iproxy argv builders, xctestrun test-target dict
name parsing, signing-credential env checks, and source-hash cache keying.

* feat(testrun): route physical-device iOS runs to the device driver

Execute resolves a non-simulator iOS target through ios.ResolveDevice into
its hardware UDID and CoreDevice id; buildDriver constructs NewDevice via a
seam instead of rejecting the device. Generalizes the --ios-device and
--ios-app-path help to cover the device path; signing stays env-read, never
a flag.

* feat(doctor): device prereqs replace java/sidecar for ios-device

iosDeviceChecks now verifies devicectl, iproxy on PATH, a connected+paired
device (via ios.ConnectedDevices), and App Store Connect signing creds (via
ioscompanion.VerifyDeviceSigning). The retired JVM sidecar checks stay only
under android.

* feat(conformance): device backend uses iphoneos app and tunnel orphan checks

The device backend now builds via just ios-device, points --ios-app-path at
the Debug-iphoneos bundle, and reinstalls each run for clear-state. The G5
orphan scan replaces the retired sidecar.jar check with lingering iproxy and
device test-without-building sessions (destination platform=iOS,id=).

* feat(folio): device build linking the iosArm64 framework

project.yml selects the Kotlin framework slice by SDK (iosArm64 for
iphoneos, iosSimulatorArm64 for simulator) and links via -framework Shared
on the SDK-conditional search path. New ios-device/test-ios-device recipes
mirror ios/test-ios, signing the Debug-iphoneos build with the .env API key.

* docs(cli): document ios-device doctor checks and the device flags

The --ios-device flag now also selects a connected device; --ios-app-path
covers the device install; the doctor gains an ios-device platform whose
checks are devicectl, iproxy, a paired device, and signing credentials.
Corrects the --clear-data default to true.

* fix(ioscompanion): resolve signing key path to absolute

xcodebuild's -authenticationKeyPath requires an absolute path, but .env
files commonly carry a repo-relative one. Resolve it against the working
directory before the stat so a relative ASC_API_KEY_PATH still signs.

* fix(ioscompanion): re-enable signing for the device runner build

companion/project.yml disables code signing for the simulator build, so
the device build inherited it and produced an unsigned runner that the
device rejected at install (0xe8008018). build-for-testing now forces
CODE_SIGNING_ALLOWED/REQUIRED=YES so automatic provisioning signs it.

* fix(ioscompanion): key the device build cache on signing identity

The cache marker hashed only sources, so switching signing team or key
reused a runner signed with the stale identity, which the device rejects at
install (0xe8008018). Fold team + key id into the cache key so a signing
change forces a rebuild.

* docs(getting-started): document physical iOS device setup

Lists the iproxy requirement and the App Store Connect signing env vars
(SANDERLING_IOS_TEAM, ASC_API_*) a device run needs, plus the
test-ios-device recipe and the doctor check.

* feat(ios): native usbmux client and in-process tunnel forwarder

Talk to macOS usbmuxd directly instead of shelling out to iproxy, so the
device path depends on nothing beyond macOS + Xcode.

* refactor(ios): drive device tunnel via io.Closer seam

Replace the tunnelChild *exec.Cmd and spawnTunnel seam with a tunnel
io.Closer and startTunnel seam backed by the in-process usbmux forwarder.

* refactor(ios): remove iproxy spawn from device runner

* test(ios): cover tunnel close via io.Closer not child process

* feat(doctor): check usbmuxd socket instead of iproxy on PATH

* chore(conformance): drop iproxy orphan check; tunnel is in-process

* docs(ios): device tunnel uses native usbmux, nothing to install

* chore: gitignore the signing keys directory

* feat(folio): add Android launcher icon (black bg, white dot)

* feat(folio): add iOS app icon (black bg, white dot)

* feat(folio): add web favicon (black bg, white dot)

* docs(ioscompanion): fix stale const comments

* refactor(ioscompanion): inline single-use devicectl argv builders

* refactor(ioscompanion): inline xcodegenArgs, drop tautological argv tests

* refactor(ioscompanion): inline firstNonEmpty

* refactor(doctor): dedup usbmuxd socket path via ioscompanion seam

* test(doctor): trim redundant signing-check test

* refactor(ioscompanion): deliver COMPANION_PORT via TEST_RUNNER_ env

* fix(testrun): seam preflight so iOS routing tests pass on CI without xcrun
2026-06-09 18:38:52 +05:30

302 lines
9.1 KiB
Go

package main
import (
"context"
"flag"
"fmt"
"io"
"os"
"os/exec"
"path/filepath"
"regexp"
"strconv"
"time"
"github.com/chromedp/chromedp"
"github.com/priyanshujain/sanderling/internal/driver/ioscompanion"
"github.com/priyanshujain/sanderling/internal/ios"
"github.com/priyanshujain/sanderling/internal/sidecarassets"
)
type doctorCheck struct {
Name string
Run func(ctx context.Context) error
}
// doctorChecksFor returns the host-readiness checks for a target platform.
// "all" returns the union (deduped by name) so the legacy zero-arg `doctor`
// behaviour keeps surfacing every platform's prerequisites.
func doctorChecksFor(platform string) []doctorCheck {
switch platform {
case "web":
return webChecks()
case "android":
return androidChecks()
case "ios":
return iosChecks()
case "ios-device":
return append(iosChecks(), iosDeviceChecks()...)
case "all":
return allChecks()
default:
return nil
}
}
func webChecks() []doctorCheck {
return []doctorCheck{
{Name: "headless chromium can launch", Run: checkChromiumLaunch},
}
}
func androidChecks() []doctorCheck {
return []doctorCheck{
{Name: "adb on PATH", Run: checkExecutableOnPath("adb")},
{Name: "emulator on PATH or under ANDROID_HOME", Run: checkEmulator},
{Name: "java 17+ on PATH", Run: checkJavaVersion},
{Name: "sidecar JAR is real (not placeholder)", Run: checkSidecarJAR},
}
}
// iosChecks covers the simulator path, which the native companion drives with
// no JVM. A simulator host with no Java still passes. Physical-device runs
// additionally need devicectl, the usbmuxd socket, a connected device, and
// signing credentials, covered by iosDeviceChecks and surfaced through the
// "all" union.
func iosChecks() []doctorCheck {
return []doctorCheck{
{Name: "xcrun on PATH (ios simulator)", Run: checkExecutableOnPath("xcrun")},
{Name: "simctl available (ios simulator)", Run: checkSimctl},
}
}
// iosDeviceChecks covers the prerequisites a physical iOS device needs: the
// runner is built and driven over a native usbmux tunnel, so devicectl installs
// the app, the macOS usbmuxd socket carries the tunnel, a device must be
// connected and paired, and App Store Connect signing credentials must be
// present for the no-UI build. Everything here is part of macOS + Xcode; nothing
// is installed.
func iosDeviceChecks() []doctorCheck {
return []doctorCheck{
{Name: "devicectl available (ios physical device)", Run: checkDevicectl},
{Name: "usbmuxd socket present (ios physical device)", Run: checkUsbmuxd},
{Name: "an iOS device is connected and paired", Run: checkDeviceConnected},
{Name: "App Store Connect signing credentials present", Run: checkDeviceSigning},
}
}
func allChecks() []doctorCheck {
seen := map[string]bool{}
var combined []doctorCheck
for _, group := range [][]doctorCheck{webChecks(), androidChecks(), iosChecks(), iosDeviceChecks()} {
for _, c := range group {
if seen[c.Name] {
continue
}
seen[c.Name] = true
combined = append(combined, c)
}
}
return combined
}
// checkChromiumLaunch boots a headless chromium under chromedp's default
// allocator, opens a blank tab, and tears down. Confirms the bundled CDP
// surface plus a working Chromium binary path.
func checkChromiumLaunch(ctx context.Context) error {
allocCtx, allocCancel := chromedp.NewExecAllocator(ctx,
append(chromedp.DefaultExecAllocatorOptions[:],
chromedp.Flag("headless", true),
chromedp.Flag("disable-gpu", true),
)...,
)
defer allocCancel()
tabCtx, tabCancel := chromedp.NewContext(allocCtx)
defer tabCancel()
if err := chromedp.Run(tabCtx, chromedp.Navigate("about:blank")); err != nil {
return fmt.Errorf("chromium launch: %w", err)
}
return nil
}
// checkSimctl exercises `xcrun simctl help`: simctl is an xcrun subcommand,
// not a standalone binary, so a PATH lookup can never find it.
func checkSimctl(ctx context.Context) error {
if err := exec.CommandContext(ctx, "xcrun", "simctl", "help").Run(); err != nil {
return fmt.Errorf("xcrun simctl help: %w", err)
}
return nil
}
// Device-check seams: package-level so the doctor's device checks run against
// canned results instead of a real device.
var (
doctorConnectedDevices = ios.ConnectedDevices
doctorVerifySigning = ioscompanion.VerifyDeviceSigning
doctorVerifyUsbmuxd = ioscompanion.VerifyUsbmuxdSocket
)
// checkDevicectl exercises `xcrun devicectl --version`: devicectl is an xcrun
// subcommand, so a PATH lookup cannot find it.
func checkDevicectl(ctx context.Context) error {
if err := exec.CommandContext(ctx, "xcrun", "devicectl", "--version").Run(); err != nil {
return fmt.Errorf("xcrun devicectl --version: %w", err)
}
return nil
}
// checkUsbmuxd confirms the macOS usbmuxd socket is present: the native device
// tunnel speaks to it directly instead of shelling out to a third-party client.
func checkUsbmuxd(_ context.Context) error {
return doctorVerifyUsbmuxd()
}
// checkDeviceConnected confirms at least one physical iOS device is connected
// and paired, the prerequisite for the tunnel and the install.
func checkDeviceConnected(ctx context.Context) error {
devices, err := doctorConnectedDevices(ctx)
if err != nil {
return err
}
if len(devices) == 0 {
return fmt.Errorf("no connected iOS device; connect and pair an iPhone")
}
return nil
}
// checkDeviceSigning confirms the App Store Connect signing environment is
// complete and the key file exists, so the no-UI device build can sign.
func checkDeviceSigning(_ context.Context) error {
return doctorVerifySigning()
}
func checkSidecarJAR(_ context.Context) error {
if sidecarassets.IsPlaceholder() {
return fmt.Errorf("placeholder JAR embedded; run `make sidecar && make sanderling` to embed the real fat JAR")
}
if sidecarassets.EmbeddedSize() == 0 {
return fmt.Errorf("embedded JAR is empty")
}
return nil
}
type doctorOptions struct {
platform string
}
func parseDoctorArgs(args []string, stderr io.Writer) (doctorOptions, error) {
flagSet := flag.NewFlagSet("doctor", flag.ContinueOnError)
flagSet.SetOutput(stderr)
var options doctorOptions
flagSet.StringVar(&options.platform, "platform", "all", "target platform: web, android, ios, ios-device, all")
if err := flagSet.Parse(args); err != nil {
return doctorOptions{}, err
}
switch options.platform {
case "web", "android", "ios", "ios-device", "all":
return options, nil
default:
return doctorOptions{}, fmt.Errorf("unsupported platform: %q (web, android, ios, ios-device, all)", options.platform)
}
}
// doctorCheckTimeout bounds a single host-readiness check. Most checks (exec
// lookups, file stats, java -version) finish in milliseconds, but
// checkChromiumLaunch boots a real browser and can exceed 5s on a cold CI
// host - 15s leaves headroom without making real failures feel hung.
const doctorCheckTimeout = 15 * time.Second
func runDoctorChecks(ctx context.Context, checks []doctorCheck, stdout io.Writer) error {
failures := 0
for _, check := range checks {
callCtx, cancel := context.WithTimeout(ctx, doctorCheckTimeout)
err := check.Run(callCtx)
cancel()
if err != nil {
fmt.Fprintf(stdout, "FAIL %s: %v\n", check.Name, err)
failures++
continue
}
fmt.Fprintf(stdout, "OK %s\n", check.Name)
}
if failures > 0 {
return fmt.Errorf("%d check(s) failed", failures)
}
return nil
}
func checkExecutableOnPath(name string) func(context.Context) error {
return func(_ context.Context) error {
if _, err := exec.LookPath(name); err != nil {
return fmt.Errorf("not found: %w", err)
}
return nil
}
}
func checkEmulator(_ context.Context) error {
if _, err := exec.LookPath("emulator"); err == nil {
return nil
}
androidHome := os.Getenv("ANDROID_HOME")
if androidHome == "" {
androidHome = os.Getenv("ANDROID_SDK_ROOT")
}
if androidHome == "" {
return fmt.Errorf("not on PATH and ANDROID_HOME is unset")
}
candidate := filepath.Join(androidHome, "emulator", "emulator")
if _, err := os.Stat(candidate); err != nil {
return fmt.Errorf("not found at %s", candidate)
}
return nil
}
var javaVersionPattern = regexp.MustCompile(`(?:java|openjdk)[^"]*"(\d+)(?:\.(\d+))?`)
func checkJavaVersion(ctx context.Context) error {
if _, err := exec.LookPath("java"); err != nil {
return fmt.Errorf("java not found: %w", err)
}
output, err := exec.CommandContext(ctx, "java", "-version").CombinedOutput()
if err != nil {
return fmt.Errorf("java -version: %w", err)
}
major, err := parseJavaMajor(string(output))
if err != nil {
return err
}
if major < 17 {
return fmt.Errorf("java major version %d is less than 17", major)
}
return nil
}
func parseJavaMajor(versionOutput string) (int, error) {
match := javaVersionPattern.FindStringSubmatch(versionOutput)
if match == nil {
return 0, fmt.Errorf("could not parse java version from %q", firstLine(versionOutput))
}
major, err := strconv.Atoi(match[1])
if err != nil {
return 0, fmt.Errorf("non-numeric major %q", match[1])
}
if major == 1 && len(match) >= 3 && match[2] != "" {
minor, err := strconv.Atoi(match[2])
if err == nil {
return minor, nil
}
}
return major, nil
}
func firstLine(text string) string {
for index := 0; index < len(text); index++ {
if text[index] == '\n' {
return text[:index]
}
}
return text
}