ColorSync suppression engine — six layers (#14) #45

Merged
gronod merged 1 commits from feat/14-colorsync into milestone/m3-printing 2026-09-09 00:19:31 +01:00
5 changed files with 473 additions and 6 deletions
@@ -0,0 +1,49 @@
import Foundation
/// Ordered private-SPI attempt table for the ColorSync suppression
/// engine (issue 14 layer , docs/11).
///
/// The ordering is data so the exact dlsym/mode sequence is unit-
/// testable without resolving any private symbols. The app layer walks
/// `attempts`, resolves each symbol via `dlsym(RTLD_DEFAULT,)`, and
/// calls the first `(symbol, mode)` that returns `0` verified on
/// macOS 14+ that all three symbols exist.
///
/// The SPI signature is `(PMPrintSession, CFStringRef) -> OSStatus`.
/// The second argument is the **mode string**, never integer `1`
/// (#188 a 3-arg call is a SIGSEGV). `AP_ColorSyncMatching` and
/// `AP_VendorColorMatching` are forbidden modes they re-enable
/// ColorSync/driver colour management.
public enum ColorMatchingAttempts {
/// dlsym order: `Lock` first (holds the print-session lock while
/// setting), then the plain setter, then `NoLock`.
public static let symbols: [String] = [
"PMSessionSetColorMatchingModeLock",
"PMSessionSetColorMatchingMode",
"PMSessionSetColorMatchingModeNoLock",
]
/// Mode strings tried per symbol, in order. `AP_` is the
/// documented mode; the unprefixed variant is the older alias.
public static let modes: [String] = [
"AP_ApplicationColorMatching",
"ApplicationColorMatching",
]
/// Symbol-outer, mode-inner the full attempt sequence; the app
/// stops at the first call that returns `0`.
public static var attempts: [(symbol: String, mode: String)] {
symbols.flatMap { symbol in
modes.map { (symbol: symbol, mode: $0) }
}
}
/// Layer : both spellings of the print-settings key are written
/// with `locked = true`. Written as `CFString` values.
public static let applicationMatchingValue = "AP_ApplicationColorMatching"
public static let printSettingsKeys: [String] = [
"AP_ColorMatchingMode",
"AP.ColorMatchingMode",
]
}
@@ -0,0 +1,59 @@
import Foundation
/// CUPS option filtering for `PMPrintSettingsToOptions` capture
/// (issue 14 layer , docs/11 §filter).
///
/// The captured `key=value` string is reduced to the options that
/// should be replayed on `lp`: `com.apple.*` ticket keys, job
/// bookkeeping (`collate`, `copies`, `pserrorhandler-requested`,
/// `job-sheets`), empty values, and **both** `AP_*ColorMatchingMode`
/// keys are dropped `build_lp_args` always re-adds those itself
/// (issue 15). Unknown non-`com.*` keys are kept (permissive vendor
/// driver keys survive).
public enum CupsOptionsFilter {
/// Option keys forwarded from the panel to `lp` (docs/11 roster).
public static let relevantKeys: Set<String> = [
// Media
"MediaType", "CNIJMediaType", "EPIJ_Medi", "StpMediaType",
// Tray
"InputSlot", "AP_D_InputSlot",
// Size
"PageSize",
// Colour bypass
"CNIJIntent2", "CNIJIntent", "EPIJ_CMat", "EPIJ_CCor",
"EPIJ_OSColMat", "ColorCorrection", "StpColorCorrection",
"EpsonColorMode", "ColorModel",
// Quality
"Resolution", "cupsPrintQuality", "Quality", "EPIJ_Quality",
"CNIJQuality", "StpQuality", "OutputMode",
// Duplex
"Duplex", "sides",
]
/// Keys we always drop regardless of the relevant list.
public static let alwaysDropped: Set<String> = [
"collate", "copies", "pserrorhandler-requested", "job-sheets",
"AP_ColorMatchingMode", "AP.ColorMatchingMode",
]
/// A `key=value` pair survives when the key is non-empty, the value
/// is non-empty, the key is not `com.apple.*`, not always-dropped,
/// and either relevant or an unknown non-`com.*` driver key.
public static func isRelevant(key: String, value: String) -> Bool {
guard !key.isEmpty, !value.isEmpty else { return false }
if key.hasPrefix("com.apple.") { return false }
if alwaysDropped.contains(key) { return false }
if relevantKeys.contains(key) { return true }
// Permissive: unknown vendor keys survive (non-com.*).
return !key.hasPrefix("com.")
}
/// `key=value key=value ` filtered string, order preserved.
public static func filter(_ options: String) -> String {
CupsParsers.lpoptions(options)
.filter { isRelevant(key: $0.key, value: $0.value) }
.map { "\($0.key)=\($0.value)" }
.joined(separator: " ")
}
}
@@ -0,0 +1,171 @@
import AppKit
import ApplicationServices
import ICCeryCore
/// Private Print Manager SPI: `(PMPrintSession, CFStringRef) -> OSStatus`.
/// The second argument is the mode string never integer `1` (#188).
typealias ColorMatchingModeFunction =
@convention(c) (PMPrintSession, CFString) -> OSStatus
/// `PMPrintSettingsToOptions` public symbol, resolved via dlsym so a
/// missing SDK declaration can't break the build.
typealias PrintSettingsToOptionsFunction =
@convention(c) (PMPrintSettings, UnsafeMutablePointer<UnsafeMutablePointer<CChar>?>) -> OSStatus
/// The six-layer unmanaged-printing engine (issue 14, docs/11):
///
/// session binding done by `PrintPanelService` before calling us.
/// private SPI `PMSessionSetColorMatchingMode{Lock,,NoLock}`
/// resolved by `dlsym(RTLD_DEFAULT,)`; first `(symbol, mode)`
/// returning `0` wins.
/// `PMPrintSettingsSetValue` both `AP_ColorMatchingMode` and
/// `AP.ColorMatchingMode` = `AP_ApplicationColorMatching`, locked.
/// driver "no colour adjustment" pre-select from `lpoptions -l`
/// keys, unlocked (`detectDriverColorBypass`).
/// mirror + into `NSPrintInfo.printSettings` so the PDE sees them.
/// after "Use Settings": `PMPrintSettingsToOptions`
/// `CupsOptionsFilter` captured `cupsOptions` + `mediaType`.
///
/// All layers degrade gracefully a missing symbol or non-zero status
/// is logged and the next layer still runs.
@MainActor
struct ColorSyncSuppressor {
/// Injected for tests: symbol function. Default resolves via
/// `dlsym(RTLD_DEFAULT, )`.
typealias ModeResolver = (String) -> ColorMatchingModeFunction?
typealias OptionsResolver = () -> PrintSettingsToOptionsFunction?
var modeResolver: ModeResolver = Self.dlsymMode
var optionsResolver: OptionsResolver = Self.dlsymOptions
var log: (String) -> Void = { AppLogger.shared.log(.info, $0) }
// MARK: - Layer SPI
/// Walk `ColorMatchingAttempts.attempts` (Lock plain NoLock ×
/// `AP_ApplicationColorMatching` `ApplicationColorMatching`); the
/// first call returning `0` wins. `false` when nothing worked.
@discardableResult
func applySPIMode(to session: PMPrintSession) -> Bool {
for attempt in ColorMatchingAttempts.attempts {
guard let function = modeResolver(attempt.symbol) else {
continue
}
let status = function(session, attempt.mode as CFString)
if status == 0 {
log("ColorSync: \(attempt.symbol) accepted "
+ "\(attempt.mode)")
return true
}
}
log("ColorSync: no PMSessionSetColorMatchingMode* accepted a "
+ "mode — falling back to PMPrintSettingsSetValue")
return false
}
// MARK: - Layer locked AP_* keys
/// `PMPrintSettingsSetValue` both key spellings, locked.
@discardableResult
func applyLockedKeys(to settings: PMPrintSettings) -> Int {
var applied = 0
for key in ColorMatchingAttempts.printSettingsKeys {
let status = PMPrintSettingsSetValue(
settings,
key as CFString,
ColorMatchingAttempts.applicationMatchingValue as CFString,
true)
if status == 0 { applied += 1 }
}
if applied == 0 {
log("ColorSync: PMPrintSettingsSetValue could not lock "
+ "AP_ColorMatchingMode")
}
return applied
}
// MARK: - Layer driver bypass
/// Pre-select the driver "no colour adjustment" option, unlocked
/// the PDE may override it. Returns the `(key, value)` applied.
@discardableResult
func applyDriverBypass(
to settings: PMPrintSettings,
optionKeys: Set<String>
) -> (key: String, value: String)? {
guard let bypass = CupsParsers.detectDriverColorBypass(
optionKeys: optionKeys)
else { return nil }
let status = PMPrintSettingsSetValue(
settings,
bypass.key as CFString,
bypass.value as CFString,
false)
if status != 0 {
log("ColorSync: driver bypass \(bypass.key)=\(bypass.value) "
+ "rejected (\(status))")
return nil
}
return bypass
}
// MARK: - Layer NSPrintInfo mirror
/// Mirror the applied keys into `printSettings` so the PDE pick
/// sees them.
func mirror(
into printInfo: NSPrintInfo,
driverBypass: (key: String, value: String)?
) {
let settings = printInfo.printSettings
for key in ColorMatchingAttempts.printSettingsKeys {
settings[key as NSString] = ColorMatchingAttempts.applicationMatchingValue as NSString
}
if let driverBypass {
settings[driverBypass.key as NSString] = driverBypass.value as NSString
}
}
// MARK: - Layer capture
/// `PMPrintSettingsToOptions` filter `(cupsOptions, mediaType)`.
/// The malloc'd C string is freed after copying.
func captureOptions(
from settings: PMPrintSettings
) -> (cupsOptions: String?, mediaType: String?) {
guard let toOptions = optionsResolver() else {
log("ColorSync: PMPrintSettingsToOptions unavailable — "
+ "panel options not captured")
return (nil, nil)
}
var raw: UnsafeMutablePointer<CChar>?
guard toOptions(settings, &raw) == 0, let raw else {
return (nil, nil)
}
defer { free(raw) }
let unfiltered = String(cString: raw)
let filtered = CupsOptionsFilter.filter(unfiltered)
return (
filtered.isEmpty ? nil : filtered,
CupsParsers.extractMediaType(fromOptionsString: unfiltered)
)
}
// MARK: - dlsym
private static func dlsymMode(_ name: String) -> ColorMatchingModeFunction? {
guard let symbol = dlsym(Self.rtldDefault, name) else { return nil }
return unsafeBitCast(symbol, to: ColorMatchingModeFunction.self)
}
private static func dlsymOptions() -> PrintSettingsToOptionsFunction? {
guard let symbol = dlsym(Self.rtldDefault, "PMPrintSettingsToOptions")
else { return nil }
return unsafeBitCast(symbol, to: PrintSettingsToOptionsFunction.self)
}
/// `RTLD_DEFAULT` `UnsafeMutableRawPointer(bitPattern: -2)`.
private static var rtldDefault: UnsafeMutableRawPointer? {
UnsafeMutableRawPointer(bitPattern: -2)
}
}
+43 -6
View File
@@ -33,6 +33,9 @@ enum PrintPanelError: LocalizedError {
@MainActor @MainActor
struct PrintPanelService { struct PrintPanelService {
/// The suppression engine injectable for tests.
var suppressor = ColorSyncSuppressor()
/// Resolves the display name (off-panel `lpoptions` fetch) and runs /// Resolves the display name (off-panel `lpoptions` fetch) and runs
/// the modal panel. Returns `nil` when the user cancels. /// the modal panel. Returns `nil` when the user cancels.
func showProperties( func showProperties(
@@ -47,14 +50,20 @@ struct PrintPanelService {
#endif #endif
let display = displayName let display = displayName
?? (try? await cupsService.displayName(for: queue)) ?? (try? await cupsService.displayName(for: queue))
return try runNativePanel(queue: queue, displayName: display) // Layer needs the queue's option keys (lpoptions -l) to pick
// the driver colour-bypass before the panel opens.
let optionKeys = (try? await cupsService.optionKeys(for: queue))
?? []
return try runNativePanel(
queue: queue, displayName: display, optionKeys: optionKeys)
} }
// MARK: - Panel // MARK: - Panel
private func runNativePanel( private func runNativePanel(
queue: String, queue: String,
displayName: String? displayName: String?,
optionKeys: Set<String>
) throws -> PrintPropertiesResult? { ) throws -> PrintPropertiesResult? {
let printInfo = NSPrintInfo() let printInfo = NSPrintInfo()
var pmPrinter: PMPrinter? var pmPrinter: PMPrinter?
@@ -97,8 +106,21 @@ struct PrintPanelService {
} }
} }
// Colour-suppression layers land in issue 14 here, between // ColourSync suppression only on the PM path: the SPI
// binding and runModal. // and PMPrintSettingsSetValue need a session with a current
// printer to attach to.
var settings = unsafeBitCast(
printInfo.pmPrintSettings(), to: PMPrintSettings.self)
var driverBypass: (key: String, value: String)?
if boundViaPM {
let session = unsafeBitCast(
printInfo.pmPrintSession(), to: PMPrintSession.self)
suppressor.applySPIMode(to: session) //
suppressor.applyLockedKeys(to: settings) //
driverBypass = suppressor.applyDriverBypass( //
to: settings, optionKeys: optionKeys)
suppressor.mirror(into: printInfo, driverBypass: driverBypass) //
}
let panel = NSPrintPanel() let panel = NSPrintPanel()
panel.options = [ panel.options = [
@@ -109,10 +131,22 @@ struct PrintPanelService {
panel.defaultButtonTitle = "Use Settings" panel.defaultButtonTitle = "Use Settings"
let response = panel.runModal(with: printInfo) let response = panel.runModal(with: printInfo)
// Layer capture (PMPrintSettingsToOptions) lands in issue 14.
guard response == NSApplication.ModalResponse.OK.rawValue else { guard response == NSApplication.ModalResponse.OK.rawValue else {
return nil return nil
} }
// Capture the user's choices filtered replay options plus
// the media type they picked. Re-fetch the settings handle so
// we read back what the modal wrote.
var cupsOptions: String?
var mediaType: String?
if boundViaPM {
settings = unsafeBitCast(
printInfo.pmPrintSettings(), to: PMPrintSettings.self)
let captured = suppressor.captureOptions(from: settings)
cupsOptions = captured.cupsOptions
mediaType = captured.mediaType
}
return PrintPropertiesResult( return PrintPropertiesResult(
selectedPrinter: boundViaPM selectedPrinter: boundViaPM
? Self.currentPrinterID( ? Self.currentPrinterID(
@@ -120,7 +154,10 @@ struct PrintPanelService {
printInfo.pmPrintSession(), to: PMPrintSession.self), printInfo.pmPrintSession(), to: PMPrintSession.self),
fallback: queue) fallback: queue)
: nil, : nil,
options: PrintOptions(ppdUncorrectedPassthrough: true)) options: PrintOptions(
mediaType: mediaType,
ppdUncorrectedPassthrough: true,
cupsOptions: cupsOptions))
} }
// MARK: - PM helpers // MARK: - PM helpers
@@ -0,0 +1,151 @@
import Testing
import Foundation
@testable import ICCeryCore
@testable import ICCery
import AppKit
import ApplicationServices
/// Issue 14 PMPrintSettingsToOptions capture filter (docs/11 layer ).
@Suite("CupsOptionsFilter")
struct CupsOptionsFilterTests {
@Test("Drops com.apple.*, collate, copies, job-sheets, AP_* keys")
func dropsReserved() {
let raw = "AP_ColorMatchingMode=AP_ApplicationColorMatching "
+ "AP.ColorMatchingMode=AP_ApplicationColorMatching "
+ "com.apple.print.JobTicket.PMTotalSidesImaged=0 "
+ "collate=true copies=1 job-sheets=none,none "
+ "pserrorhandler-requested=standard "
+ "MediaType=PhotographicGlossy"
#expect(CupsOptionsFilter.filter(raw) == "MediaType=PhotographicGlossy")
}
@Test("Keeps relevant driver keys, order preserved")
func keepsRelevant() {
let raw = "InputSlot=Rear PageSize=A4 CNIJIntent2=4 "
+ "Resolution=600x600dpi Duplex=None"
#expect(CupsOptionsFilter.filter(raw) == raw)
}
@Test("Permissive: unknown non-com.* keys survive")
func keepsUnknown() {
let raw = "VendorFooBar=baz MediaType=Plain"
#expect(CupsOptionsFilter.filter(raw) == raw)
}
@Test("Drops empty keys and values")
func dropsEmpty() {
let raw = "=noval MediaType= InputSlot=Rear"
// "MediaType=" has an empty value dropped; "=noval" empty key.
#expect(CupsOptionsFilter.filter(raw) == "InputSlot=Rear")
}
@Test("extractMediaType prefers MediaType then EPIJ_Medi")
func extractMedia() {
#expect(CupsParsers.extractMediaType(
fromOptionsString: "MediaType=Photo EPIJ_Medi=1") == "Photo")
#expect(CupsParsers.extractMediaType(
fromOptionsString: "EPIJ_Medi=7") == "7")
#expect(CupsParsers.extractMediaType(
fromOptionsString: "PageSize=A4") == nil)
}
}
/// Issue 14 the dlsym attempt order and first-success semantics.
/// A fake resolver records every call; no private symbols are touched.
@Suite("ColorSyncSuppressor")
@MainActor
struct ColorSyncSuppressorTests {
/// Fake PMPrintSession the injected resolver never dereferences it.
private var fakeSession: PMPrintSession {
unsafeBitCast(UnsafeMutableRawPointer(bitPattern: 0xdead)!, to: PMPrintSession.self)
}
private func suppressor(
succeeding symbol: String? = nil,
mode: String = "AP_ApplicationColorMatching",
calls: UnsafeMutablePointer<[(String, String)]>
) -> ColorSyncSuppressor {
var s = ColorSyncSuppressor()
s.log = { _ in }
s.modeResolver = { name in
// Missing symbol nil (older macOS path).
if name == "PMSessionSetColorMatchingModeLock" && symbol == nil {
return nil
}
return { _, modeArg in
calls.pointee.append((name, modeArg as String))
return (name == symbol && (modeArg as String) == mode) ? 0 : 1
}
}
return s
}
@Test("Attempt order: Lock → Mode → NoLock, AP_ prefix first")
func attemptOrder() {
let calls = UnsafeMutablePointer<[(String, String)]>.allocate(capacity: 1)
calls.initialize(to: [])
defer { calls.deallocate() }
let s = suppressor(succeeding: nil, calls: calls)
#expect(s.applySPIMode(to: fakeSession) == false)
#expect(calls.pointee == ColorMatchingAttempts.attempts
.map { ($0.symbol, $0.mode) }
.filter { $0.0 != "PMSessionSetColorMatchingModeLock" })
}
@Test("First zero wins — later symbols not called")
func firstZeroWins() {
let calls = UnsafeMutablePointer<[(String, String)]>.allocate(capacity: 1)
calls.initialize(to: [])
defer { calls.deallocate() }
let s = suppressor(
succeeding: "PMSessionSetColorMatchingMode", calls: calls)
#expect(s.applySPIMode(to: fakeSession))
// Lock symbol missing skipped; Mode tried AP_ then plain? No
// Mode succeeds on the first mode 2 calls total.
#expect(calls.pointee == [
("PMSessionSetColorMatchingMode", "AP_ApplicationColorMatching"),
])
// NoLock never attempted.
#expect(!calls.pointee.contains { $0.0 == "PMSessionSetColorMatchingModeNoLock" })
}
@Test("Mode fallback: AP_ rejected → ApplicationColorMatching tried")
func modeFallback() {
let calls = UnsafeMutablePointer<[(String, String)]>.allocate(capacity: 1)
calls.initialize(to: [])
defer { calls.deallocate() }
var s = suppressor(
succeeding: "PMSessionSetColorMatchingModeLock",
mode: "ApplicationColorMatching",
calls: calls)
// Make the Lock symbol resolvable this time.
let record: (String) -> ColorMatchingModeFunction? = { name in
{ _, modeArg in
calls.pointee.append((name, modeArg as String))
return (modeArg as String) == "ApplicationColorMatching" ? 0 : 1
}
}
s.modeResolver = record
#expect(s.applySPIMode(to: fakeSession))
#expect(calls.pointee.first
== ("PMSessionSetColorMatchingModeLock", "AP_ApplicationColorMatching"))
#expect(calls.pointee.last
== ("PMSessionSetColorMatchingModeLock", "ApplicationColorMatching"))
}
@Test("All symbols missing → false, no calls")
func allMissing() {
let calls = UnsafeMutablePointer<[(String, String)]>.allocate(capacity: 1)
calls.initialize(to: [])
defer { calls.deallocate() }
var s = suppressor(succeeding: nil, calls: calls)
s.modeResolver = { _ in nil }
#expect(s.applySPIMode(to: fakeSession) == false)
#expect(calls.pointee.isEmpty)
}
}