What happens
openIosSimulatorUrl (packages/platform-apple/src/core/app-launch.ts) runs xcrun simctl openurl <udid> <url> with no timeoutMs. When CoreSimulator is wedged (seen twice on 2026-10-01 under host load 215–691 while working #3096, and once on CI run 36843756495 step 87 where openurl answered NSPOSIXErrorDomain 60 only after its own long internal wait), the open holds until the daemon request timeout (450–630 s in those runs), and the simctl openurl child outlives the daemon's kill of the request.
Every other simctl call the open makes is bounded (listapps, plutil, the terminate calls at 2 s). openurl is the one that can take minutes.
Required behavior
simctl openurl runs under a bound of its own, shorter than the open's request budget, and takes the request signal so a cancel kills the child.
- A timed-out
openurl fails the open with a typed reason (dispatched: unknown: the URL may have been delivered) rather than letting the daemon request time out around it.
Completion conditions
- A unit test with a provider whose
openurl never returns: the open fails within the bound with the typed reason, and the child receives the kill.
- The bound and its reason are documented in the
open help where the other launch bounds are.
What happens
openIosSimulatorUrl(packages/platform-apple/src/core/app-launch.ts) runsxcrun simctl openurl <udid> <url>with notimeoutMs. When CoreSimulator is wedged (seen twice on 2026-10-01 under host load 215–691 while working #3096, and once on CI run 36843756495 step 87 whereopenurlansweredNSPOSIXErrorDomain 60only after its own long internal wait), the open holds until the daemon request timeout (450–630 s in those runs), and thesimctl openurlchild outlives the daemon's kill of the request.Every other simctl call the open makes is bounded (
listapps,plutil, the terminate calls at 2 s).openurlis the one that can take minutes.Required behavior
simctl openurlruns under a bound of its own, shorter than the open's request budget, and takes the request signal so a cancel kills the child.openurlfails the open with a typed reason (dispatched: unknown: the URL may have been delivered) rather than letting the daemon request time out around it.Completion conditions
openurlnever returns: the open fails within the bound with the typed reason, and the child receives the kill.openhelp where the other launch bounds are.