- The child's Tick drains the network queue for HTTP and script sockets (dispatch_network_runtime_events), and that queue also carries the host socket its hosted loop reads. A host batch landing during a Tick went through dispatch_studio_msg, which drops the loop's own messages: WindowGeomChange, Swapchain, Tick. The drain now parks host-socket responses in Cx::studio_backlog once a loop owns the socket (its first read), and the loop's next read takes them first, in order. Before: 1 in 2-3 split runs lost the geometry; after: 6 of 6 runs delivered every geometry sent. Applies to the macOS and Linux X11 hosted loops too; Android hosted never drained the network in its Tick
- wm's run view cleared its bootstrap (the geometry resend) on any present, so a frame already in flight when the tile changed size cancelled the geometry before it was sent; a present settles it only after the first bootstrap beat has sent the messages
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
wm.exe died at startup with "thread 'main' has overflowed its stack"
(0xc00000fd) on Windows, where the main thread gets 1 MB against 8 MB on
macOS and Linux. The startup chain is shallow (~85 frames) but five of its
frames were huge: ShellIcons (41 DrawSvg, ~110 KB) sat by value in every
ShellDraw, PhoneSurface carries one ShellDraw and WmDesk carries a
PhoneSurface plus its own ShellDraw (286 KB). Each constructor layer
(WmDesk factory, WmDesk::script_new, PhoneSurface::script_new and
script_new_with_default, ShellDraw) held its whole value in its frame:
about 970 KB in five frames. Reproduced on macOS by linking wm with a
1 MB main stack (same overflow).
script gets a transparent Box<T> (ScriptNew/ScriptApply/ScriptHook forward
to T: same type id, proto, default and apply), and ShellDraw boxes its
icons. The same chain now takes ~305 KB (WmDesk 286 -> 69 KB, PhoneSurface
140 -> 30 KB, ShellDraw 117 -> 7 KB); the 1 MB-stack build starts and runs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The WM phone shell rides on it: the simulated finger in the desktop skin, time-based release velocity (80 ms window, stale after a 120 ms rest), one critically damped spring (k 900, c 60) seeded with that velocity for paging, drawer, recents and app open/close, an 8 pt / 1.2x axis lock latched through release, a drawer that tracks the finger 1:1 and draws opaque over the home tiles, hold-to-Recents precedence, launches that zoom from the icon actually drawn with an opaque launch card, no ghost card on close, and one cancel/reset path for rotation, resize, focus loss, style switch and keyboard navigation.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Remove the retired applications, asset-specific libraries and DJ pack tool
from Makepad, together with their workspace and launcher entries. All 981
removed source paths are accounted for in the private Stage repository.
Keep public AI chat generation through the AI Hub's generic job runner.
Extract shared SHA-256 and UDP binding into core_util so the public hub and
model crates no longer depend on the relocated asset libraries. Preserve
the retained public coverage in the split wasm validation script.
Validation on the exact cleanup tree in an isolated checkout:
- Release checks: core_util, model, aichat, WM and Builder.
- Release builds: aichat, WM and Builder.
- Existing tests: core_util 5, model 30, aichat 7, Builder 2 passed.
- Core/model checks: wasm32, Linux and Windows passed.
- No warnings in the successful checks, builds or tests.
Known baseline: WM library tests do not compile because the unchanged
style-transition assertion compares seven expected weights with eight.
The unrelated working-tree correction is intentionally outside this commit.
A test is a ci.splash beside what it tests; the script decides every input and the model only ever judges one picture against one acceptance text. mod.ci: launch (hidden, --remote, user_seq preserved), key, type_text, click, get, snap, wait_log (a * is a gap inside one line), no_errors, grab, quit; step, sleep, check, run; cargo, check_targets (the cargo makepad check matrix, check only for platforms we are not on, a test fails if the two tables drift), test, build, machine (another box over the makepad tunnel), exclusive; judge, accept, ask. The watcher polls git ls-remote once a minute for work and any extra branches, syncs a checkout the CI owns, runs the root script first and alone, then the rest up to a parallel limit behind one shared model judge. The window is a wall of squares, one per script: green passed, orange warnings, red failures, with a detail panel for the selected one.
Scripts: the root ci.splash (workspace check with core warnings denied, the tests), apps/wm (desktop up, switch to macOS by Cmd+Space / type / Return, launch the terminal and the browser, each waited for by the WM's own first-frame line), and one per main app in the default shape. Proven here: apps/wm/ci.splash green in 280 s, fifteen target checks and seven vision verdicts.
Models come from Hugging Face through the hub: registry entries qwen3.5-4b-vision and qwen3.5-9b-vision with exact revisions, sizes and digests, and hub-install, a command line over LocalModels::start_install. vlm-probe reads PNG.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
iOS: VideoFileDecoder::open_audio guarded its Apple path with macOS alone, so iOS fell through to UNSUPPORTED, a constant no Apple target has. It takes the same split as every other entry point in that file.
tvOS: libs/apple_sys opened with a crate guard of macOS or iOS, so on tvOS the crate compiled to nothing and every msg_send! user lost the macro; the crate guard and its 27 inner guards of that shape now name tvOS, and MTLCopyAllDevices is macOS only, which is where it exists. The platform's Apple video playback, player and YUV modules, the 17 guards of the Metal NV12 video path and the texture-pool imports follow, and the tvOS app gains try_metal_device, the lookup the texture adopt path already calls on iOS.
wasm: the window manager's dylib host needs a process, a linker and a loader, so it is native only; the web gets a stand-in with the same surface that refuses every compile through the queue the native host answers on, and libloading is a non-wasm dependency.
Windows: three Unix-only uses in apps/wm/src/clients.rs (Cx, CancellationToken, the grace argument) are guarded to match where they are used, tests included.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The child draws its frame through a texture pass, which on GL renders through an inverted projection, so its glReadPixels rows come in picture order already; the host keeps them as they are, and the two run views sample the texture as stored on every path. The old shader flip on the software path inverted it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 2D camera is GL-style: the top of a pass rect lands at clip y = +1 on every backend. Vulkan's clip space points down, so a pass drawn with that camera has to go through a negative-height viewport, window and capture alike; the window comes out upright and a capture's rows are stored top-left like Metal's. fbfec26ad made both viewports positive to cure an inverted phone desk, and every desktop Vulkan window stood on its head (the Scope report of 2026-09-20). The desk was inverted by its own OS-keyed consumer flips, not by the viewport, so those go: the gauss stack's per-OS flip and its callers, the phone shell's three Android flips and its y_flip shader term, the dock warp's capture_y_flip and its term. The direct display's letterbox blit keeps its positive viewport: its own vertex shader maps uv.y = 0 to clip -1.
Seen right side up by eye on the Arch RTX 5090 box: apps/wm as a Wayland client under sway, the hosted apps inside it, and the linux_direct WM on the panel; and on the Pixel 11 Pro XL the wm-dyn super-app (Vulkan, no GL fallback). Codex review in the session's notes endorses the restores and removals and leaves two flips for a later look: the SSAA resolve's 1.0 and the map shadow mask's Metal flip, both untouched here.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Every manifest `app_main!` emitted carried three fonts no theme role uses:
`NewCMMath-Regular.otf` for `MathView`, and `Inter.ttf` / `RobotoFlex.ttf` for the opt-in
iOS and Android platform styles. That was 3.6 MB in every package, and it only existed
because a font an app forgot to declare failed silently: `FontFamily::update_font_definitions`
skipped a member whose bytes never arrived, so the text showed as boxes with no log line.
* Drop the forced extras. The manifest is now the font set's fallback chain plus whatever
the app puts in `font_assets`, which is what makepad's own apps already did for `Inter`.
* `font_assets` takes expressions, and `INTER_FONT_ASSET` / `ROBOTO_FLEX_FONT_ASSET` join
`MATH_VIEW_FONT_ASSET`, so an app declares a font by name instead of by path.
* A font that never loads now logs one `error!` naming the path and the fix. A missing
member still degrades gracefully: the family keeps its remaining members.
* The apps that use those fonts declare them: the `wm` family binds both platform faces,
`clock`, `weather` and `director` draw with Inter and can select any style, `terminal`
and the builder use Inter for symbols, `splash` and `aichat` use `MathView`.
Measured on the Pixel 11 Pro XL (PowerVR): a pane swipe presented at
~84 fps on the 120 Hz panel, a vsync dropped every three to six frames.
simpleperf showed 22% of the CPU in the driver's shader compiler and 24%
in its render-target teardown: the Vulkan backend created a VkRenderPass
and a VkFramebuffer for every offscreen pass on every frame and destroyed
them after the fence, and on this driver each render pass compiles a
load-op shader. Offscreen draw render passes now live for the device
(keyed by formats and load/store ops) and framebuffers are cached per
render pass, attachment views and storage extent, invalidated through
texture retirement so they die after the frame that used them.
The app icons were re-tessellated from SVG every frame: one DrawSvg kept
one scale and the desk draws each icon at two or three sizes. A DrawSvg
keeps up to four meshes per device scale; the geometry pool defers frees
and releases them once per frame against the geometry ids the live draw
lists still name, so a retained draw call never sees its slot reused.
A font member whose resource can never load (the WM referenced Inter and
its other faces through `self:../../widgets/...`, unmapped in a package)
kept its family incomplete, and an incomplete family is redefined every
frame: the layout cache cleared, every label laid out again, the asset
reopened. Such a member drops out of its family once, logged, keyed on
the resource registry's generation so a resource that appears later is
asked for again. The WM names its fonts through `makepad_widgets:` and
reads the clock in-process on the UI thread instead of forking `date`
twice a second.
Android gains a `frame.cpu` trace (events, next-frame, draw and repaint
milliseconds per drawn frame) and a profileable manifest so simpleperf
can sample a release build. The dyn-pack tile proof tolerates the app's
own Dirty line after an engine rebuild.
After: SurfaceFlinger presents every swipe frame at 8.3 ms, the render
thread runs at ~45% instead of 85–97%, and the frame is paced by the GPU.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The contribution widened `StyleTween` to eight weights but left its two initialisers at
seven, so the window manager did not compile. It also declared `BlackOrange` second in
`DesktopStyle`, while the window manager reads the tween's weights by discriminant (1 is
macOS, 3 Windows 2000, 4 NeXTSTEP): every style after Omarchy would have driven the chrome
of the one before it. The new style is declared last, `ALL` keeps the order the sheets are
shown in, and `next()` walks `ALL` by place rather than by discriminant. An unused import
in a storybook story goes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squashed from vjroger/makepad `storybook-pr` at 086d25452 (1,332 commits on top of
6f1e44649; his last commit restored every path outside the contribution to upstream).
- apps/storybook: every component organised, documented and previewed live.
- widgets: about eighty new widgets (accordion, alert, avatar, badge, breadcrumb, calendar,
card, carousel, chat, chip, colour, command palette, date and time pickers, dialog,
dropzone, floating action and panel, form, hamburger, line and radial menus, kanban,
masonry, menu, nav list, pagination, pill nav, popover, progress, property inspector,
range slider, rich text, select, spinner, table, tabs, tag field, timeline, toast,
toolbar, tour, transfer, tree, waveform, wheel picker and more); theme tokens and a
theme store, themes mixed by weight with a legibility check, a twelfth style sheet in
black and orange; the data grid gains row selection, drag and reorder, heading tips and
alignment; the glass button is a water lens; the portal list keeps the wheel it uses,
stands down from a press another control holds, can keep a row on screen and rule the
gap under a short list.
- platform: sweep locks and scroll blocks nest, `is_mouse_held_outside`, per-axis
scroll-handled flags, `next_frame_is_pending`, owner-scoped scroll unblocking, a
hands-off marker for the remote bridge, exploded-view projection and focus.
- draw: the interior distance of square-cornered boxes, a pointer shape, and
`turtle_ancestor_clip`.
- wm: the style tween carries an eighth weight for the new sheet.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
`cargo makepad android dyn-pack` stages the relocatable checkout,
cross-builds host + engine from it through the ordinary Android build,
proves every tile's on-device command against that target/, packs the
APK with the phone toolchain, the checkout and target/ as streamed LZ4
tar parts, and rehearses the phone's first tile open from the packed
APK; `dyn-rehearse` runs that last gate alone. This replaces the
Python and shell pipeline that lived outside the tree. The stage
directory is tool-owned, every cargo phase runs under one controlled
environment recorded in the target's marker, rustc runs through
cargo-makepad itself as the remapping wrapper, and the APK is renamed
into place only after signing and the rehearsal. The host package
names its engine and tiles in [package.metadata.makepad.dyn]. Only the
three /system/bin/sh templates that run on the phone stay shell.
libs/rmeta is the rustc metadata header reader apps/wm used, now shared
with cargo-makepad; libs/tar gains a streaming ustar writer with GNU
long names; the zip writer streams to any sink so a 900 MB APK never
sits in memory.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The APK carries rustc, the checkout and a packed target tree as LZ4
frames. First compile streams them out of the asset manager into files/
and shows progress on the desk; later launches skip unpack when the
stamp matches. App crates keep a desktop Cargo.toml — dynamic-module is
empty — and rustc `--extern force:` binds makepad_wm_engine already in
the process so widgets stay the host dylib.
libs/lz4 grows a streaming frame codec and a makepad-lz4 CLI; libs/tar
unpacks those frames without buffering the archive. Android Vulkan
records two in-flight repaints instead of waiting every pass, and the
capture Y-flip applies only on the OpenGL fallback.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
apps/mail indexes local Apple Mail through the Envelope Index: Gmail
Inbox, Sent, Starred and Important are label rows, attachments open
from the message view, and a reimport button wipes the cache. apps/wm
hosts apps as on-demand dylibs on Android (apps/wm-dyn, with the module
apps' manifests and module.rs following). apps/terminal polls the child
with MpTerm::process_exited and resolves widget fonts through
makepad_widgets. Widgets: double-click selects a word in TextFlow,
links keep their hand cursor, and three stale tests follow the tree's
root rule and the mobile font policy.
Squashed from work (the apps and widgets parts of each):
- Index local Apple Mail with Gmail labels, attachments and reimport
- terminal: MpTerm::process_exited polls the child, and widget fonts resolve through makepad_widgets
- widgets: double-click selects a word in TextFlow; links keep their hand cursor
- wm: the Android super-app hosts apps as on-demand dylibs (apps/wm-dyn)
- widgets: three stale tests follow the tree's root rule and the mobile font policy
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 59 work commits (Sep 1–12):
b0380ba image-tiles: the picture-wall engine as a library — tape atlases, a baker CLI, and the TileGrid widget
83d8eac mpsheets: demo feature and the SheetDocs seam
daff390 finance: demo feature — generated ledger, SQLite target-gated, import hidden
13b4c48 mpfiles: demo build — procedural fake filesystem, still-image thumbnails, chat feature
58e1f72 mpsheets: review fixes for the demo seam
3203e32 finance: review fixes — id remapping on persist, structural determinism tests, one cfg seam
0537687 mpfiles: distinct repo-owned pictures for the demo thumbnail pool
fe920c8 files: review fixes — demo scan exclusions, Zipf sizes, trash root guarded, depth bound, tests
4144dc4 files: the spy test filesystem implements the clock
1940f3d fonts: leave apps/wm untouched — its font-set declaration waits for the aichat lane to land
b0e34c2 wm: the AI pane and its bus — the aichat child seated in the slot, F10, the os service with the typed open
de937ac route: the web build is a one-to-one recompile — native UI, service seams behind it
2f5a984 files: the file browser on the AI bus — four read-only tools through a correlated, cancellable runner
2b035ff route: the navigation session keeps time on the platform clock — the std clock traps on wasm
1b70899 files: the space view is where a tab starts
412b3c9 files: the space view rescans through the virtual filesystem — the web has no other disk
0105fa5 files: the space view opens in 2.5D
5d007e0 files: an unset projection preference means 2.5D
6857d86 files: the projected treemap clips boxes at the near plane and keeps the camera above them
d3cd233 wm: one desk for every target — the host seam, the assistant seated in-process, the web profile, and the assistant up at boot
6d47c3f wm: the omarchy themes moved to omacom/omarchy — the importer follows
82def6b wm: every app under the desk — the chat keeps the keyboard through an automatic refocus, a pool that gives up, polite closes for browser, sheets and aichat
6105b61 sheets + files: the assistant reads and writes cells, makes folders, renames and trashes
82ac768 photos: the picture wall as an app — the SMBC archive on the tile engine, a module from its first line; fabric in the launcher
190062e route: the maps app exposes its tool table to the desktop assistant
3768653 image_tiles: the wall is box-packed — justified rows keep every picture's own shape and fill the width
3691875 wm: launcher icons — a photo for Photos, a shirt for Fabric, a globe for Route, a play badge for Video, a pulse for the task manager
8625076 aichat + photos + image_tiles: make me a picture and it lands on the wall; the wall filters as you type, tiles flying to their places
1dcca41 wm: a theme with no wallpapers fetches them on its own
ff6cfec wm: minimise, maximise and close in the bar's top right on Windows and Linux
62f38a5 route: --hour=N pins the theme hour for harness grabs
362ac59 wm: the checkout is found from the working directory too, and a sibling binary is an .exe on Windows
0fdfba7 files: the web's makepad home is a fixed virtual path — std's temp_dir panics there
daf88e1 route demo: the tiles come from the repacked world archive at its own never-cached path
15c3b11 ai-services: what the pubsub review found — modules get a subscription seam and a publish sink through both WM paths, lease end flushes unsubscribes to hosted services, the subscription cap counts closing rows, an endpoint's queue is dropped after Unregister, the prompt drops a subscription on final
d852699 route: no tile-source dropdown — makepad.nl is the tile source through the local range cache; a world.mkmap in the saved maps folder is the only override; the stale preference file is removed on start
aa271c3 map + route + geodata: the Terrain layer through the archive plane — TerrainSource (hosted .mkmap elevation shards fetched by range through the shared reader, a local MBTiles only as a dev override), the hillshade rendered on the pool's heavy lane with reused TerrainScratch buffers (web capped at 2048×1536 at DPR 1, native DPR-aware), one request in flight; the demo checkbox now renders terrain like native
dbc7838 route: the maps-folder field and its save button are gone from the settings panel; the maps root is automatic
a53d9b6 route: no clock-driven night theme — the theme is the user's toggle, remembered in cx.storage, default day (the hour rule fired on the web for the first time once wasm had a clock and darkened the map after 19:00)
ca92ff9 route: the open sea on the web — the ocean-low/ocean-high overlays are an always-on group in the shared hosted overlay table, read through the archive plane (makepad.nl, cached); native keeps the local ocean files only as a dev override; the native-only OCEAN_MBTILES path is gone
4cd24c4 route demo: the first location fix flies the map to the user at zoom 14, as native does; Amsterdam stays the default until a fix arrives
2e869f8 route: the ocean-high overlay comes from the re-sharded archive (58 shards of at most 16 MB, one small leaf directory each) instead of two shards whose directories decoded to 407 MiB
8021bb0 Add Clock and Weather with shared mobile tile views and persistent alarms
77b8309 Make application layouts and custom widgets follow desktop and mobile themes
b357164 Add desktop and mobile compositor shells with OS switching and dock transitions
11dec2e Keep hosted app output readers off the shared task pool
c4002c5 Round complete desktop surfaces and add Windows snap layouts
a5f8dd8 Frame home photo tiles and clip the picture wall below app controls
678721d Give mobile app libraries real search focus and hosted keyboard input
4794cdf Keep window title fills opaque at the application surface join
2cc584e Match Windows 2000 and NeXTSTEP window chrome to original screenshots
4a876a8 Give Files navigation and storage tools a clearer hierarchy
7821c90 Keep prewarmed browsers in the active desktop appearance
5bfe694 Compact the Files toolbar and repair navigation and selection actions
44fef36 Preserve Photos subjects and zoom across host view and aspect changes
ae20efc Draw larger macOS traffic lights with centered hover symbols
2bc4d89 wm: the WM is a library plus a desktop binary, Linux controls, hosted tick pacing
d643eb4 apps: the in-process app wave — mail, notes, calendar, reminders, calculator; clock, weather, finance, photos and route as modules; civil time, read-only sqlite, Linux CEF
56c1dee wm: a timer beat missed while the child renders is serviced on its acknowledgement
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A wm started with cargo run from the repo root but with its target dir
elsewhere (CARGO_TARGET_DIR) found no checkout above its exe and fell
back to sibling binaries — which never exist as bare names on Windows —
so the launcher listed only the linked modules. The checkout is now
looked for above the exe and then above the current directory, and a
sibling binary carries the .exe extension on Windows. Every app is one
cargo run away again.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The omarchy bar is the caption strip and the frame is fully
client-sized there, so a WM window had no window controls at all. The
bar's right cluster now ends in three of our SVG buttons after the
status modules — minimise, maximise (restore once maximised), close —
wired to the window's own minimize, maximize, restore and close;
hover washes the slot, the close carries the accent, tooltips name
them, and the drag query answers Client over them. macOS keeps its
traffic lights on the left. The gallery shows them on every platform.
wm 155; the WM checks for windows-msvc, linux-gnu and wasm32. A real
click on Windows is the box's to prove.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The bundled default theme ships its colours, not its pictures, so a
fresh install had nothing behind the desk until someone ran the
importer. The desk now fetches the current theme's wallpapers from the
omarchy repo on a thread when its backgrounds folder is empty and shows
the first one the moment it lands; the importer shares the fetch. No
network or no pictures means nothing changes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Five 16 px icons in the set's own style (our SVGs, stroke 1.2,
currentColor), wired into the shell's icon set and the launcher map.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>