Skip to content

Conversation

@shai-almog
Copy link
Collaborator

Motivation

  • Ensure the app fails fast on compromised devices by performing jailbreak detection during app initialization.
  • Consolidate jailbreak detection logic into runtime startup instead of a standalone test to catch issues earlier.
  • Improve iOS native detection to catch modern dynamic-library injection and common bypass libraries.

Description

  • Enhanced Ports/iOSPort/nativeSources/CN1JailbreakDetector.m to import <unistd.h> and <stdlib.h>, check getenv("DYLD_INSERT_LIBRARIES"), scan loaded images via _dyld_image_count()/_dyld_get_image_name() for known bypass libraries, and exit when detected.
  • Updated restricted path checks and write-test behavior in CN1JailbreakDetector.m by moving MobileSubstrate entry, adding "/private/var/lib/apt/", using BOOL wroteFile = [@"Test" writeToFile:...] and removing the test file on success.
  • Kept additional runtime checks (fork() and process tracing via sysctl) to detect abnormal behavior and exit when bypass indications are found.
  • Removed the standalone JailbreakDetectionTest.java and added a startup assertion in scripts/hellocodenameone/common/src/main/kotlin/com/codenameone/examples/hellocodenameone/HelloCodenameOne.kt that calls Display.getInstance().isJailbrokenDevice() and uses check(!...) to fail initialization if the device is jailbroken.

Testing

  • No automated tests were executed for these changes.
  • The previous standalone test JailbreakDetectionTest.java was deleted and not run as part of CI.
  • No native compilation or runtime verification was performed automatically for the iOS detector changes.
  • The startup assertion was added to application initialization but was not executed in an automated test run.

Codex Task

@github-actions
Copy link

✅ Continuous Quality Report

Test & Coverage

Static Analysis

Generated automatically by the PR CI workflow.

@shai-almog
Copy link
Collaborator Author

shai-almog commented Jan 12, 2026

iOS screenshot updates

Compared 30 screenshots: 23 matched, 6 updated, 1 missing reference.

  • BrowserComponent — updated screenshot. Screenshot differs (1206x2622 px, bit depth 8).

    BrowserComponent
    Preview info: Preview provided by instrumentation.
    Full-resolution PNG saved as BrowserComponent.png in workflow artifacts.

  • graphics-draw-arc — updated screenshot. Screenshot differs (1206x2622 px, bit depth 8).

    graphics-draw-arc
    Preview info: JPEG preview quality 20; JPEG preview quality 20; downscaled to 603x1311.
    Full-resolution PNG saved as graphics-draw-arc.png in workflow artifacts.

  • graphics-draw-gradient — updated screenshot. Screenshot differs (1206x2622 px, bit depth 8).

    graphics-draw-gradient
    Preview info: JPEG preview quality 10; JPEG preview quality 10; downscaled to 844x1835.
    Full-resolution PNG saved as graphics-draw-gradient.png in workflow artifacts.

  • graphics-draw-round-rect — missing reference. Reference screenshot missing at /Users/runner/work/CodenameOne/CodenameOne/scripts/ios/screenshots/graphics-draw-round-rect.png.

    graphics-draw-round-rect
    Preview info: JPEG preview quality 10; JPEG preview quality 10; downscaled to 844x1835.
    Full-resolution PNG saved as graphics-draw-round-rect.png in workflow artifacts.

  • graphics-draw-string — updated screenshot. Screenshot differs (1206x2622 px, bit depth 8).

    graphics-draw-string
    Preview info: JPEG preview quality 10; JPEG preview quality 10; downscaled to 422x918.
    Full-resolution PNG saved as graphics-draw-string.png in workflow artifacts.

  • graphics-draw-string-decorated — updated screenshot. Screenshot differs (1206x2622 px, bit depth 8).

    graphics-draw-string-decorated
    Preview info: JPEG preview quality 10; JPEG preview quality 10; downscaled to 603x1311.
    Full-resolution PNG saved as graphics-draw-string-decorated.png in workflow artifacts.

  • kotlin — updated screenshot. Screenshot differs (1206x2622 px, bit depth 8).

    kotlin
    Preview info: Preview provided by instrumentation.
    Full-resolution PNG saved as kotlin.png in workflow artifacts.

Benchmark Results

  • VM Translation Time: 371 seconds
  • Compilation Time: 74 seconds

Detailed Performance Metrics

Metric Duration
Build Time Statistics
Setup & Unzip 32482 ms
Extract Extensions 20 ms
Google Services Setup 2 ms
Scan Classes 601 ms
Extract Libs 794 ms
Inject Build Hints 37 ms
Generate Unit Tests 1 ms
Generate Stubs 1705 ms
Compile Stubs 2114 ms
Generate Icons 990 ms
Prepare ParparVM 185 ms
ParparVM Execution 209785 ms
Post-VM Setup 134 ms
CocoaPods 4528 ms
Finalize 31 ms
Total Time 253412 msMaven Overhead : 118000 ms
CocoaPods Install (Script) 1000 ms
Simulator Boot (Run) 145000 ms
App Install 32000 ms
App Launch 6000 ms
Test Execution 191000 ms

@shai-almog
Copy link
Collaborator Author

shai-almog commented Jan 12, 2026

Compared 30 screenshots: 30 matched.

Native Android coverage

  • 📊 Line coverage: 24.83% (2661/10717 lines covered) [HTML preview] (artifact android-coverage-report, jacocoAndroidReport/html/index.html)
    • Other counters: instruction 24.45% (12352/50528), branch 15.30% (715/4672), complexity 17.52% (743/4241), method 33.08% (602/1820), class 34.98% (106/303)
    • Lowest covered classes
      • com.codename1.impl.android.com.codename1.impl.android.AndroidContactsManager – 0.00% (0/400 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidImplementation$Video – 0.00% (0/168 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.IntentIntegrator – 0.00% (0/139 lines covered)
      • com.codename1.impl.android.util.com.codename1.impl.android.util.Base64 – 0.00% (0/117 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidImplementation$SocketImpl – 0.00% (0/77 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidTextureView – 0.00% (0/76 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidSurfaceView – 0.00% (0/73 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.LocalNotificationPublisher – 0.00% (0/65 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.FridaDetectionUtil – 0.00% (0/64 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.PushNotificationService – 0.00% (0/59 lines covered)

✅ Native Android screenshot tests passed.

Native Android coverage

  • 📊 Line coverage: 24.83% (2661/10717 lines covered) [HTML preview] (artifact android-coverage-report, jacocoAndroidReport/html/index.html)
    • Other counters: instruction 24.45% (12352/50528), branch 15.30% (715/4672), complexity 17.52% (743/4241), method 33.08% (602/1820), class 34.98% (106/303)
    • Lowest covered classes
      • com.codename1.impl.android.com.codename1.impl.android.AndroidContactsManager – 0.00% (0/400 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidImplementation$Video – 0.00% (0/168 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.IntentIntegrator – 0.00% (0/139 lines covered)
      • com.codename1.impl.android.util.com.codename1.impl.android.util.Base64 – 0.00% (0/117 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidImplementation$SocketImpl – 0.00% (0/77 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidTextureView – 0.00% (0/76 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.AndroidSurfaceView – 0.00% (0/73 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.LocalNotificationPublisher – 0.00% (0/65 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.FridaDetectionUtil – 0.00% (0/64 lines covered)
      • com.codename1.impl.android.com.codename1.impl.android.PushNotificationService – 0.00% (0/59 lines covered)

@shai-almog shai-almog merged commit f6392da into master Jan 12, 2026
15 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants