Pass the still sink's media type as a FourCC, not an object

On iOS 18, -[BWStillImageSampleBufferSinkNode initWithInputMediaType:sinkID:]
takes the media type as a uint32_t ('vide'). The hook typed it as id, so ARC
retained 0x76696465 and cameracaptured crashed on every launch. SpringBoard
waits synchronously for cameracaptured's flashlight service at startup, so
the guest never left the Apple logo (#541).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Lakr
2026-10-01 18:16:46 +09:00
co-authored by Claude Opus 5.5
parent 244c8853cc
commit 3a83bb5850
@@ -17,14 +17,16 @@
static IMP vcc_still_init_orig = NULL;
static IMP vcc_still_render_orig = NULL;
typedef id (*VccStillInitFn)(id self, SEL _cmd, id mediaType, id sinkID);
// mediaType is a FourCC ('vide'), not an object: typed as id, ARC retains it
// and cameracaptured crashes at 0x76696465 on iOS 18 (#541).
typedef id (*VccStillInitFn)(id self, SEL _cmd, uint32_t mediaType, id sinkID);
typedef void (*VccStillSetHandlerFn)(id self, SEL _cmd, id handler);
typedef void (*VccStillRenderFn)(id self, SEL _cmd, CMSampleBufferRef sb, id input);
static id vcc_still_init_hook(id self, SEL _cmd, id mediaType, id sinkID) {
static id vcc_still_init_hook(id self, SEL _cmd, uint32_t mediaType, id sinkID) {
VccStillInitFn orig = (VccStillInitFn)vcc_still_init_orig;
id ret = orig(self, _cmd, mediaType, sinkID);
vcc_log(@" [StillSink init] self=%p mediaType=%@ sinkID=%@",
vcc_log(@" [StillSink init] self=%p mediaType=0x%08x sinkID=%@",
ret, mediaType, sinkID);
if (ret) {
if (!vcc_still_sinks) vcc_still_sinks = [NSMutableArray new];