Files
orca/config/scripts/mobile-web-bundle-serializer-parity.test.mjs
Jinwoo Hong da1c322b00 feat(mobile): one build-time switch picks native or OTA, default native (OTA phase E1) (#22193)
* feat(mobile): one build-time constant decides native or OTA, default native

EXPO_PUBLIC_MOBILE_SHELL is read in exactly one place, mobileShellBuildKind in
preferences.ts. Expo's babel preset inlines a literal process.env member
expression at build time, so a release bundle carries the answer as a constant
and anything but the exact string 'ota' — unset, empty, a typo — is native.
Every default build is therefore the native app, unchanged.

mobileWebShellFlagCanBeOn now answers __DEV__ or an OTA build, so the ability to
mount the page comes from the build and never from storage: a native binary
installed over an OTA one, same bundle id and same data container, still refuses
a stored 'true' without reading the key. An unset key reads on only in an OTA
build; a development build keeps its opt-in, and a stored 'false' wins
everywhere so the Troubleshoot toggle can switch an OTA build back to native.

That toggle now mounts wherever the flag can be on, which is the only way back
to the native screens in an OTA build, and its label names the build kind rather
than saying "(dev)". The bundle probe row beside it stays development-only: it
fetches.

The flag census gains two rules — one module reads the switch, in the member
form Expo inlines and not the bracket form, and one named function answers the
build kind — and the build-kind fence now lists the Troubleshoot route that asks
it. Docblocks that said a store build can never mount the shell now say it
mounts only when built for OTA.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb

* ci(mobile): one workflow input picks the shell, and no input means native

Both release workflows gain a `shell` workflow_dispatch choice, options native
and ota, default native, and hand it to the step that bundles the JavaScript as
EXPO_PUBLIC_MOBILE_SHELL. That is the Gradle assembleRelease step on Android and
the fastlane build_and_upload step on iOS; nothing else in either file sets it.

A tag push and a schedule carry no inputs at all, so `inputs.shell || 'native'`
yields native for them — the first OTA release is a dispatch with one field
changed, and every other run is the app we ship today.

Each build step prints the value it is about to build with, read back from the
same variable rather than from a second copy of the expression, so a run's log
cannot claim a shell the build did not use.

The new contract test evaluates that expression rather than matching its text:
absent, empty and 'native' all resolve to native, 'ota' to ota, and any
expression shape it cannot evaluate is a failure rather than a pass.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb

* build: the desktop packages the real page, and the placeholder is retired

build:mobile-web now runs the app builder and app verifier, and both take their
output root from MOBILE_WEB_BUNDLE_DIR in the packaging guard rather than each
carrying a constant of their own — one definition of where the bundle lives, so
a drift cannot leave electron-builder's beforePack looking at an empty directory
while the builder reports a tree it wrote elsewhere. build:mobile-web:app is
gone; it was the same two commands.

src/mobile-web/ and its two scripts go with it. What the app builder shared with
them is split into three modules named for what they hold rather than for the
bundle that used to own them: mobile-web-bundle-manifest.mjs (content types, the
canonical asset serialization, buildId, hashed assets, the protocol window and
the manifest write), script-entry-detection.mjs (isDirectInvocation, whose two
failure modes are Windows paths and symlinked entries), and
mobile-web-source-line-endings.mjs (the CRLF guard, now with a required
directory rather than a default pointing at the deleted tree).

The two suites that only needed *a* valid tree on disk — the beforePack guard
and the packaged-bundle guard — build one from mobile-web-bundle-fixture-tree
instead of bundling the whole mobile graph. It goes through the same manifest
writer the page does, so a manifest shape change still reaches them.

Also retired: the placeholder's tsconfig project and its typecheck lane, its
knip entry, its electron-builder exclusion and .gitattributes pins, and the
app-bundle test that asserted the shims stayed out of a builder that no longer
exists. pr.yml's page job builds the same bundle the package job ships.

Inert for native phones: they never fetch it.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb

* style(config): one import of node:fs/promises in the entry-detection suite

The changed-code quality gate's focused plugins read the two as a duplicate
import; the readFile line was left over from the split.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb

* docs: the comments that still describe the retired placeholder bundle

The web entry said it was built by `build:mobile-web:app` into out/mobile-web-app
and shipped by nothing. That script, that directory and that fact are all gone:
it is built by `build:mobile-web` into the packaged bundle dir, and a phone
mounts it only when the binary was built with EXPO_PUBLIC_MOBILE_SHELL=ota.

Two Windows cache keys explained themselves by naming src/mobile-web and "the
two bundle builders"; config/** now covers the builder, the verifier and the
manifest writer, and the spike's key no longer waits on a Phase C flip that has
happened. The keys themselves are unchanged.

Three scratch directories in the app-bundle suites and one in the verifier still
spelled the retired output root. Renamed to mobile-web, which is what the build
writes; they are temp subdirectory names and nothing reads them.

Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb
2026-09-22 06:18:33 -04:00

122 lines
4.3 KiB
JavaScript

/**
* The canonical serialization that buildId hashes exists three times, because the two packaging
* scripts run on bare node before any build output exists and so cannot import the TypeScript
* contract. Three copies drift; this is what stops them. A divergence in any one of them would
* reject every honest bundle at packaging, or ship a bundle whose id the phone recomputes
* differently and re-downloads forever.
*/
import { createHash } from 'node:crypto'
import { createRequire } from 'node:module'
import { describe, expect, it } from 'vitest'
import {
computeMobileWebBundleBuildId,
serializeMobileWebBundleAssets as serializeInBuilder
} from './mobile-web-bundle-manifest.mjs'
import {
computeMobileWebBundleId,
MobileWebBundleManifestSchema,
serializeMobileWebBundleAssets as serializeInContract
} from '../../src/shared/mobile-web-bundle/manifest-contract'
const require = createRequire(import.meta.url)
const { serializeAssets: serializeInGuard } = require('./verify-packaged-mobile-web-bundle.cjs')
const digest = (hex) => `${hex}`.padStart(64, '0')
/**
* Mixed content types, a nested path, and an uppercase segment that sorts before a lowercase one
* only under code-unit order: `localeCompare` would put `assets/aQ.js` first, so any serializer
* that reached for it produces a different string here.
*/
const ASSETS = [
{
path: 'assets/Za.js',
sha256: digest('a1'),
byteLength: 2048,
contentType: 'text/javascript; charset=utf-8'
},
{ path: 'assets/aQ.css', sha256: digest('b2'), byteLength: 512, contentType: 'text/css' },
{
path: 'assets/nested/mark.png',
sha256: digest('c3'),
byteLength: 40_960,
contentType: 'image/png'
},
{
path: 'index.html',
sha256: digest('d4'),
byteLength: 640,
contentType: 'text/html; charset=utf-8'
}
]
const REORDERED = [ASSETS[3], ASSETS[1], ASSETS[0], ASSETS[2]]
const REVERSED = ASSETS.toReversed()
const sha256Hex = (value) => createHash('sha256').update(value, 'utf8').digest('hex')
describe('the three mobile web bundle serializers', () => {
it('produce one string for the builder, the packaging guard, and the shared contract', () => {
const fromContract = serializeInContract(ASSETS)
expect(serializeInBuilder(ASSETS)).toBe(fromContract)
expect(serializeInGuard(ASSETS)).toBe(fromContract)
})
it.each([
['reordered', REORDERED],
['reversed', REVERSED]
])('are order-independent, so %s input serializes identically', (_label, input) => {
const expected = serializeInContract(ASSETS)
expect(serializeInContract(input)).toBe(expected)
expect(serializeInBuilder(input)).toBe(expected)
expect(serializeInGuard(input)).toBe(expected)
})
it('leaves the caller-supplied array untouched, so a build cannot depend on the sort', () => {
const input = [...REORDERED]
serializeInContract(input)
serializeInBuilder(input)
serializeInGuard(input)
expect(input).toEqual(REORDERED)
})
it('emit exactly path, sha256, byteLength, contentType, in that order, and nothing else', () => {
const decorated = ASSETS.map((asset) => ({ ...asset, sourcePath: '/tmp/ignored', extra: 1 }))
expect(serializeInContract(decorated)).toBe(serializeInContract(ASSETS))
expect(serializeInBuilder(decorated)).toBe(serializeInContract(ASSETS))
expect(serializeInGuard(decorated)).toBe(serializeInContract(ASSETS))
expect(JSON.parse(serializeInContract(ASSETS))[0]).toEqual({
path: 'assets/Za.js',
sha256: digest('a1'),
byteLength: 2048,
contentType: 'text/javascript; charset=utf-8'
})
})
it('hash to one buildId, which the manifest schema then accepts', () => {
const buildId = computeMobileWebBundleId(REORDERED)
expect(computeMobileWebBundleBuildId(REORDERED)).toBe(buildId)
expect(sha256Hex(serializeInGuard(REORDERED))).toBe(buildId)
const manifest = {
schemaVersion: 1,
buildId,
desktopVersion: '1.4.200',
minCompatibleRuntimeProtocolVersion: 2,
runtimeProtocolVersion: 2,
entrypoint: 'index.html',
totalBytes: ASSETS.reduce((total, asset) => total + asset.byteLength, 0),
assets: [...ASSETS],
// Outside the hash on purpose, which the assertion below is what says.
routes: [{ pathname: '/h/[hostId]', grants: ['navigate'] }]
}
expect(MobileWebBundleManifestSchema.parse(manifest).buildId).toBe(buildId)
})
})