Commit graph

767 commits

Author SHA1 Message Date
b211a372d9 fix(fork): base platform+test on upstream work 5f99533 + re-apply nigig BeforeStartup, NIGIG_TEST_MODE, touch protocol 2026-09-25 23:19:08 +03:00
8eaa075f1f fix(fork): refresh platform from upstream dev fda40f5 + re-apply nigig BeforeStartup, NIGIG_TEST_MODE, touch/long-press/paste/IME protocol 2026-09-25 22:55:32 +03:00
91b6267f84 fix(fork): restore upstream metal.rs - fix merge delimiter artifact 2026-09-25 21:11:01 +03:00
ce45048baf fix(fork): restore upstream blocking_http streaming API + add RemotePinch alongside nigig touch/joystick protocol 2026-09-25 20:47:20 +03:00
99ca24dbbc Merge upstream origin/work 5f99533 into nigig fork alongside dev 2026-09-25 17:32:26 +03:00
a0f46b7d83 Merge upstream origin/dev fda40f56 into nigig fork - preserve nigig hub/web_server, take upstream dev updates 2026-09-25 17:25:35 +03:00
Admin
5f99533505 Merge branch 'wm-fixes' into work 2026-09-25 11:20:28 +02:00
Admin
abcb4c3445 platform (windows): a texture pass drawn before its window has a size is skipped, not a crash -- a hosted child can draw before the host's first WindowGeomChange, at dpi 0, so a texture-cached view's pass had a NaN size: the viewport check (< 1) let NaN through, CreateTexture2D failed and the unwrap of the missing render target killed the child (calendar in wm on .100: 'Websocket closed', 3 of 4 launches). setup_pass_render_targets now says whether there is a target to draw into (refuses NaN and a render target the device could not create) and draw_pass_to_texture skips the pass
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 11:14:14 +02:00
Admin
b9882bff16 platform + wm: a hosted child redraws at its tile's new size -- two ways a geometry change was lost, measured on Windows (.100) with wm hosting clock and calendar: after a split or a resize the child kept drawing at its old size and the tile showed that frame stretched or squeezed into the new rect (child logs: the WindowGeomChange never arrived, painting stayed at 2268x1428 against a 560-wide tile)
- The child's Tick drains the network queue for HTTP and script sockets (dispatch_network_runtime_events), and that queue also carries the host socket its hosted loop reads. A host batch landing during a Tick went through dispatch_studio_msg, which drops the loop's own messages: WindowGeomChange, Swapchain, Tick. The drain now parks host-socket responses in Cx::studio_backlog once a loop owns the socket (its first read), and the loop's next read takes them first, in order. Before: 1 in 2-3 split runs lost the geometry; after: 6 of 6 runs delivered every geometry sent. Applies to the macOS and Linux X11 hosted loops too; Android hosted never drained the network in its Tick
- wm's run view cleared its bootstrap (the geometry resend) on any present, so a frame already in flight when the tile changed size cancelled the geometry before it was sent; a present settles it only after the first bootstrap beat has sent the messages

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 11:14:14 +02:00
Admin
3c56f0cf08 Merge branch 'd3d-first-draw' into work 2026-09-25 10:53:36 +02:00
Admin
d4f8533e42 platform (windows): a popup opened for the first time draws its rows -- AI provider dropdown, Styles menu and every other first open showed only the menu's background
Measured on .100 with apps/aichat and a draw-call log: the popup's rows use two
shaders created on its first draw (menu item background and text). D3D11
compiles them on the pool and skips their draw calls until they are installed;
the background's shader already existed, so the panel drew empty. The finished
compiles were only picked up inside a redraw (hlsl_compile_shaders ran under
need_redrawing), and a window at rest has none: the finished task raised the
internal signal, the loop woke and went back to sleep, and the rows stayed
missing until the next input. A startup shader that finished after the last
startup redraw waited 17 s for the click that opened the menu. Warm shader cache:
the same empty panel. Draw order is fine: the rows follow the background in the
popup's overlay list, above it in depth. Metal compiles inline and was correct.

- hlsl_adopt_shaders installs finished compiles; the Signal handler runs it
  when the internal signal is raised (one wake per finished task, no polling),
  and every paint tick runs it before it draws (and the stdin host's tick).
- Once the startup set is installed, new shaders compile on the UI thread
  before the frame renders, as Metal does, with a 1 s budget per frame and the
  rest on the pool. Startup keeps compiling on the pool. Measured first open
  with a cold cache: 26 ms + 19 ms, the menu complete in its first frame.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 02:03:03 +02:00
Admin
e831c4520f Merge branch 'mcp-reverse' into work 2026-09-25 01:39:16 +02:00
Admin
b6a99cb381 wm: starts on Windows -- the desk no longer overflows the 1 MB main stack
wm.exe died at startup with "thread 'main' has overflowed its stack"
(0xc00000fd) on Windows, where the main thread gets 1 MB against 8 MB on
macOS and Linux. The startup chain is shallow (~85 frames) but five of its
frames were huge: ShellIcons (41 DrawSvg, ~110 KB) sat by value in every
ShellDraw, PhoneSurface carries one ShellDraw and WmDesk carries a
PhoneSurface plus its own ShellDraw (286 KB). Each constructor layer
(WmDesk factory, WmDesk::script_new, PhoneSurface::script_new and
script_new_with_default, ShellDraw) held its whole value in its frame:
about 970 KB in five frames. Reproduced on macOS by linking wm with a
1 MB main stack (same overflow).

script gets a transparent Box<T> (ScriptNew/ScriptApply/ScriptHook forward
to T: same type id, proto, default and apply), and ShellDraw boxes its
icons. The same chain now takes ~305 KB (WmDesk 286 -> 69 KB, PhoneSurface
140 -> 30 KB, ShellDraw 117 -> 7 KB); the 1 MB-stack build starts and runs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 01:13:29 +02:00
Kevin Boos
03705413e7
Constrain Splash external I/O to the host service bridge (#1243)
* Constrain Splash external I/O to the host service bridge

* Validate untrusted Splash source with the host I/O restriction

* Give strict Splash validation a disposable storage jail

* Close the remaining ways out of the Splash host I/O restriction

- Keep CachedWidget singletons per heap, and don't register CachedWidget
  or WindowMenu in restricted isolates.
- Don't emit Html/Markdown link URLs as actions from a restricted isolate,
  and ignore its menu bar updates.
- Suppress clipboard copy/cut hits for any restricted isolate, not only
  within Splash.
- Give script calls made while an isolate is installed the same budget.
- On web, let package resource fetches skip the guest I/O guard.
- Name the validation jail without the wall clock, and skip it on wasm.
- Make the host I/O tests fail when their guards are removed.
2026-09-25 00:56:09 +02:00
Admin
0f39445982 ai: Claude Desktop drives any app with the F10 panel -- pick "Claude Desktop" in the panel's provider menu and the app serves its tools to it over MCP
- The loopback MCP server moves from Director into libs/ai/services (mcp::server); Director re-exports it, its lane tokens and tests unchanged. The dispatcher now names the server and its instructions; a TokenStore can live in memory only (ephemeral).
- mcp::host: while Claude Desktop is the provider the panel serves its registry's tools (service__tool names) on an ephemeral 127.0.0.1 port with a fresh bearer token, and writes ~/.makepad/mcp/<exe-stem>.json {pid, port, token, title} (0600 in a 0700 dir), removed when the provider changes or the panel goes. Calls queue to the UI thread and run through EngineCore::call_external: a card in the transcript, destructive calls held for the person's confirm (the pane opens for it), the result sent back when the card lands.
- mcp::mcpb: "Connect to Claude Desktop" writes <exe-stem>.mcpb (a stored zip, manifest_version 0.3, binary server = this executable with --mcp) and opens it so Claude Desktop shows its install dialog.
- platform mcp_relay: `<app> --mcp`, checked first in app_main before any Cx, window, GPU or audio, relays newline JSON-RPC on stdio to the running app's endpoint. It answers initialize/ping itself and tools/list from the app's last list while the app is down, starts the app (detached, MAKEPAD_AI_PROVIDER=claude-desktop, engine up with the pane closed) on the first call that needs it, waits up to 20 s for its file, and exits when stdin closes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 00:43:05 +02:00
Admin
ac1917d70c windows: desktop apps open no console window, and still speak through pipes -- the Builder links apps as windowed programs (/SUBSYSTEM:WINDOWS, mainCRTStartup), so starting one from Explorer or the Builder shows no cmd window; app_main joins the parent terminal's console only when the process has no stdout (started from a terminal), so a pipe (an MCP client starting --mcp) and console builds keep their stdin/stdout untouched
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 00:26:00 +02:00
Admin
fcdb8694d5 platform (macos): the display link is kept until it is invalidated -- the CADisplayLink from NSView displayLinkWithTarget: was stored without a reference of our own; closing the last window releases the view's link before the deferred WindowClosed retires the window, so invalidate hit a freed link and macOS 15.7 aborted on its unfair lock (EXC_BREAKPOINT in retire_cocoa_window) on every app exit. The link is retained when created and released after each invalidate.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 00:14:18 +02:00
Admin
79ea9dc876 platform (windows): half-float RGBA textures have four channels -- TexturePixel::RGBAf16 was created as DXGI R16_FLOAT, one red channel, so on D3D11 the relief buffer lost its green, blue and height (a green display lit its neighbours red) and the gauss chain's blur levels lost everything but red; it is R16G16B16A16_FLOAT, as on Metal and Vulkan
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 23:15:27 +02:00
Admin
6b6fbf003b platform, widgets, ai: a restyle recompiles nothing it already has, shows only complete frames, and a window can own its caption -- generated shader helpers were named after their module's heap position, which moves on every restyle, so the Metal source text changed and every style switch recompiled ~20 pipelines, even back to a loaded style; helpers are now numbered by first call order within the shader, so a warm switch compiles 0 and misses 0 draws (was 47 missing per frame for 0.5 s). A style switch holds the old frame until three frames in a row are complete (no draw skipped, no pipeline pending), then crossfades; cx.pipelines_pending() and per-reason skipped-draw counts back it. A window can hide its stock caption and name its own drag region (set_drag_region), enforced on every event and draw so no re-apply brings the stock bar back; app keys in that region answer the drag query as client. The audio analyzer keeps a stereo history (latest_stereo). The AI engine runs a CLI model's tool calls as they stream in and shows the text between them
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 18:47:36 +02:00
Admin
5986d4f8ee audio_route: one API on macOS, Windows and Linux, monitoring by default and processing only when asked, plus shaders that discard a value compile to WGSL
audio_route: the Core Audio process tap gains Windows (WASAPI process loopback; the source is ducked through its ISimpleAudioVolume) and Linux (the PulseAudio/PipeWire monitor of the source's sink; ducked through its stream volume) backends behind the same Route API. A route only monitors by default (copy for meters and visualisers; the app's own output is untouched). Route::set_processing turns processing on: the source is ducked to 2^-13 and boosted back by exactly 2^13 in float, so the processed signal is bit-exact. RouteConfig.state_dir keeps the duck state, so restore_after_crash puts a ducked volume back after a crash.

script/wgsl: an if/else whose branches end in a value nothing uses wrote that value as a bare statement (_phi_353;). Metal, GLSL and HLSL accept that, WGSL does not, so DrawMenuRow failed on Vulkan and menu rows lost their drawing (the theme chips on Linux). ShaderBackend::write_discarded_expr writes such values as `_ = expr;` for WGSL and keeps void calls as statements, in both places that emit leftovers. MAKEPAD_TRACE=shader.wgsl lifts the two-error log suppression.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 18:45:23 +02:00
Admin
27a2bd09fa platform (windows): every window keeps animating with several windows open -- the per-window frame beat held back a window that was keeping a spare DXGI credit (it never presented again, which is why things only moved during a window drag), stepped animations only on the first-registered window (a move re-registers it last), and always served the first ready window; the wait now serves the least recently served window first, the animation clock steps once per refresh on whichever beat arrives first (wall-clock fallback), only windows actually waiting for a beat are held back and a held pass keeps its previous paint state, and a finished move/resize drains the extra credits it created (Present had been blocking the UI thread a frame deep). An instance upload with zero instances no longer asks D3D11 for a zero-byte buffer. Amp with its pop-out: 32/32 presents per second on the 32 Hz remote display with one or two windows and after moving either.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 17:52:11 +02:00
Admin
3993ebb2f7 sheets, score, git, home: saves cannot cut a file short or overwrite another one, and checkouts cannot write outside the repository -- Sheets and Score save through a temp file renamed into place, refuse an empty path, and ask (a second Save) before replacing a file that is not the document's own; Sheets says when formulas were saved as values. The git library rejects tree entry names "", ".", "..", ".git" and any containing / \ or NUL, and refuses to write or remove through a symlinked parent folder. An empty MAKEPAD_HOME counts as unset everywhere it is read, so caches never land in the current folder.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 14:20:07 +02:00
Admin
90b6a05813 platform: the pipeline-skip repaint mark exists only on Apple, where Metal reads it -- it warned as never read on Android, Windows and Linux
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 13:53:23 +02:00
Admin
f0754226ec platform: Android builds without Vulkan compile again, and the font-selection test counts the hosted entry point -- android_hosted.rs used the Vulkan renderer unconditionally, so every default (OpenGL) Android check failed to compile; the Vulkan paths now build only with use_vulkan behind small helpers, and a hosted child in a GL build logs that it needs MAKEPAD=vulkan and exits. makepad_hosted_main is the fifth entry point calling new_cx_with_font_set
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 13:51:07 +02:00
Admin
e047d2a790 platform, widgets, audio_route, ai: window crossfades and whole-frame presents, caption controls that click, themed menus, a stereo-pair audio tap, and the AI chat on local Claude Code / Codex with images -- a window can snapshot its presented frame and crossfade it over the next one (0.25 s, Metal; other backends cut), and can hold a frame until everything in it is on the GPU so a relayout appears in one step; app controls in the caption bar answer the window's drag query as client so real clicks reach them; menus scroll within the window and keep a readable text/background contrast, drop-downs take their popup look from the host; relief surfaces gain a texture light knee, spill tint and screen colour maps. audio_route taps a player's output on the device's own stereo pair (no system downmix, device rate and channel order) and reports its format and permission without prompting. The AI chat can use a logged-in Claude Code or Codex CLI as its model (tools as tagged text blocks), attach dropped images, and pick its model; the speech lib gains opt-in GPU pacing, a shorter audio context and a token cap; audio tags expose bpm. The remote bridge gains window resize and drag-query probes
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 13:48:31 +02:00
Admin
149138afc7 widgets, platform: a texture can light the relief buffer, menus take colour chips, and a style reload recompiles changed shader functions -- relief_texture_light makes any texture a light source for neighbouring surfaces: the relief pass runs after the texture's producing pass in the same frame and repaints only when that producer painted, with a soft knee (and damping of near-white frames) so a flash does not flood every bevel; the buffer gained a fifth, widest blur level so spill washes the near half of a neighbouring face, surfaces take a style-wide spill tint and ceiling, and ReliefView caps can follow a held button. MenuRow::swatch(fill, dot) puts a colour chip before a row's label. A style reload re-evaluates Splash modules under the names they had, so the object- and function-address shader caches handed back the previous shader or another template's (changes landing a reload late, or on the wrong surface); a pending style reload now clears those two caches like a file-change live edit does, keeping the code-keyed cache so unchanged shaders do not recompile. examples/skeuomorph gains an animated plasma screen lighting the keys beside it. glass renders pixel-identical, hello_world differs only in its animated GIF
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 01:11:51 +02:00
Admin
d15996efd9 task, cargo-makepad, widgets, audio: the task manager chooses its columns, graphs every process' network and disk traffic and installs itself as a Dock app built by cargo makepad -- cargo makepad desktop bundle -p <crate> [--install[=DIR]] builds a self-contained, signed macOS .app (MAKEPAD_PACKAGE_DIR=resources in its own target dir, every dependency's resources plus only the fonts the binary's manifest names, icon from [package.metadata.makepad.desktop], per-app usage strings, signed with the Apple Development identity so privacy grants survive rebuilds) and installs it outside target/ (default ~/.makepad/apps), replacing the per-app package-macos.sh scripts
- task: a right-click column chooser (sections as flyouts, Default Columns), every figure and graph its own sortable column, dragged order and widths saved; per-process network bytes/packets from the kernel's ntstat control socket (matches nettop, no root), disk bytes, footprint and idle wake-ups every tick; history journal v4
- widgets: data_grid_columns, one column helper (chooser, reorder, resize, fit, sort cycle, layout text) that task uses and other tables can reuse; the menu engine refreshes marks inside an open flyout; the segmented control centres its labels on the line height and no longer glides after a moved row
- svg: a stroke join never connects to the previous subpath (the diagonal through outline icons)
- platform: home::app_data_dir; script: ScriptIp body ids widened to 14 bits (16384 bodies, was 4096) with an index of 26 bits, and a clear stop instead of aliasing past the limit
- audio_route (new): tap an app's audio output through the Core Audio process tap into a host processor (equalizer, gain, limiter, analyzer) and play it; audio_picture owns the one FFT; audio_decode probes tags and length from a file's head and tail; search::fold_words; zip_file reads archives with a trailing comment

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:45 +02:00
Admin
6907154d02 wm on Android: the look switcher stays put, the iOS dock shows its icons, background apps follow a look change -- the Light / Dark / iOS pill moved between skins and crowded the clock; it now sits at one spot in every look, centred above the page dots / All apps row. In the iOS skin the dock's glass bar was drawn over its icons; the glass draws first now. An idle background child applied a look change only after it next got input (the idle-wake work in b61ab763e left it without a tick); it applies it at once, and a tile-only app shows its current tile on its own ground in the new look
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:45 +02:00
Admin
5ac42f026d wm on Android: the shell follows the Pixel launcher's motion -- launching from an icon grows the window from an icon-sized circle over 500 ms on the emphasized curves while the icon crossfades out (25-75 ms) and home scales to 0.97; releasing an app to Home flies it into its icon or tile on Quickstep's three springs (dock-row circle fallback), gone by 85% while home reveals from 0.85 over 1 s; the lift subtracts the 11.3 dp slop, a motion pause opens Recents with a haptic click and neighbour cards sliding in over 300 ms, >= 36 dp goes Home; All Apps is a full-screen panel rising 300 dp with the launcher's fades, home at 0.97 and hidden at 40%, opening past 40% or on a > 1 dp/ms fling. Cx::haptic_feedback reaches the Activity's performHaptic. The status band keeps the app's last sampled colour while a Recents card opens. Latency: a finger move goes to a hosted child at once with its own tick and every batched MotionEvent sample reaches it (Mail scroll touch->present 22.1 -> 15.7 ms mean). Values from AOSP Launcher3/Quickstep
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
3e01d10828 android: hosted children hand frames over with GPU fences and draw only when they have work -- Mail as a WM child ran at 20-26 ms per frame (3% of frames at 120 Hz): the child CPU-waited its GPU before announcing each frame and the WM paced it one frame per WM frame on a fixed 125 Hz beat. The child now exports a SYNC_FD semaphore per frame over the socket that carries its AHardwareBuffers and the WM waits on it GPU-side; the WM returns a release semaphore so the child never renders into an image being sampled (VK_KHR_external_semaphore_fd; children announce that they fence, and anything else falls back to the CPU wait). The WM ticks a child on its display frame only when it has work (a requested frame, input, a due timer, startup, a bootstrap), and host messages handled outside a tick ask for a frame. Idle wakeups are gone: host messages no longer wake the child's UI loop, the 2 s heartbeat, the 125 Hz beat on empty views and the 20 Hz warm-pool timer are removed, the bar no longer redraws every second, and touch times are mapped to the app clock (the phone shell treated every touch as just now and never came to rest). Mail landscape fling: 20.5/29.2 ms -> 8.48/11.6 ms (p50/p95), 86% of frames at 120 Hz; the WM home at rest repaints once in 10 s instead of ~1220 times
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
801a07e884 vulkan (android): a window released on suspend is not released again -- switching away from a Makepad Android app and back crashed it (SIGSEGV in ANativeWindow_release from CxVulkan::update_surface): suspend_surface had already released the window and set it to NULL, and update_surface released it again. Only a non-null window is released now
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
dedc447e68 android: rotated Vulkan windows stop rebuilding their swapchain every frame, and hosted children get touch -- on the Pixel, Mail as a WM child process could not be scrolled in portrait and ran at about 40 fps in landscape. In landscape the WM's swapchain (IDENTITY pre-transform on a rotated display) reported VK_SUBOPTIMAL_KHR on every present and vulkan.rs rebuilt the whole swapchain each frame: present went from 34-35 ms to about 1 ms and repaint from 52-66 ms to 2-7 ms once that one known Android case (extent and transform unchanged since creation) no longer rebuilds; every other SUBOPTIMAL, and desktop Wayland/X11, rebuild as before. The WM forwards the finger to a child as mouse events, so a press on a row captured the mouse and the list refused to drag; an Android hosted child now dispatches it as one touch like the Activity build (Cx::dispatch_hosted_touch), cancels included, and reports its focused text field on a cancel. Mail's toolbar buttons are flat discs with hover/press states instead of glass (the child drew its window twice per frame: 12.8 -> 7.1 ms). The WM's bottom band draws a smooth app edge stretched (Weather's sky) and a busy one in its dominant colour, so text scrolling under it no longer smears into streaks
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
0c83b8c73f wm on Android: app transitions and gestures feel like the phone's -- on the Pixel, opening Clock from its live tile showed a streaked frame, the swipe up to Recents moved the app about 0.28 pt per pt of finger travel, the bottom gesture was hard to find, fading cards went grey and a closed app landed on a white card then "Loading". The WM now sizes a child's shared images for full screen before it opens (MpRunView::prepare_size), the child refuses to draw into a smaller image and the WM rejects such frames; the lifted card's centre follows the finger 1:1 while it shrinks and on release travels straight to its target; the WM draws its own 32 pt bottom-gesture strip and pill above the OS gesture band; rounded captures use fill_premul (opacity was applied twice); closing into a tile keeps the tile's last face until the child confirms a new one, holding the old capture so a live tile never draws over the foreground app. On Android a child renders one frame per WM frame into three shared images, with tick counters that resync on each acknowledgement; the warm pool is off there. Calculator's portrait toolbar uses a flat button (the glass one refracted its neighbour). A debug hook setprop debug.makepad.grab burst-<tag>-<n> saves a child's next frames
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
9baf6d6854 platform, wm: hosted apps ask the WM for what they cannot do themselves -- a hosted child has no OS window and, on Android, no JVM, so the clipboard menu, opening a URL, permission prompts, file pickers and HTTP were unavailable to it (Weather sat on "Loading" as a phone child process). AppToStudio::Relay / StudioToApp::Relay (appended, tags 26/27, existing ordinals pinned) carry these requests (platform/studio/src/relay.rs); the child side routes them automatically from the ordinary Cx APIs (platform/src/hosted_relay.rs), the WM executes them and answers by a host request id mapped back to the child's. HTTP for Android children is relayed through the WM's own Java HTTPS (NDK code has no TLS and the repo takes no external TLS crate), arriving as the NetworkResponses apps already handle; a relayed request fails after 60 s without an answer. The WM serves relays only to clients it holds a live connection to; open_url allows http, https, mailto, tel and geo; picked documents are copied on a worker into a per-pick cache folder (older than a day deleted); Android save/folder pickers answer cancelled until children can write through SAF. open_url, which was unimplemented on Android, now opens the URL. linux_direct gets a clipboard of its own (platform/src/direct_clipboard.rs): the WM owns it, Ctrl/Logo+C/X/V work as on X11, and children reach it through the existing copy/paste messages
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
a8bf0e4dcf wm on Android: every app is its own process -- the plain makepad-wm now ships as an Android APK (cargo makepad android ... proc-pack -p makepad-wm-android) whose phone apps run as real child processes instead of dylibs loaded into the WM. The interface between WM and app shrinks to what the desktop WM uses: shared GPU buffers and the StudioToApp/AppToStudio protocol. The WM allocates each app's swapchain as AHardwareBuffers and hands them over a unix socket (AHardwareBuffer_sendHandleToUnixSocket, API 26); the child, started through the libmakepad_launch.so launcher in nativeLibraryDir (W^X allows it there), imports them into a windowless Vulkan device and renders its window pass into them (android_hosted.rs). Each app library links the engine statically, so the engine-dylib identity handling of wm-dyn is not needed. Children have no JVM: assets are read from the APK file, audio device lookup no longer goes through Java, and the startup/resize extra draw of the Activity build is repeated so the first frame carries its text. On a phone the WM asks for the soft keyboard only while the child reports a focused text field. Proven on a Pixel 11 Pro XL: all twelve phone apps launch as processes (first frame 1.6-2.4 s cold), taps reach them. Not yet: HTTP in children (the Activity build borrows Java's), clipboard/permission/file-picker relays, idle-app reclaim, and on-device builds of app libraries
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:44 +02:00
Admin
6c6ebff2ec platform, widgets, wm: a touch that is taken away is cancelled, never released -- in the WM's phone skin the mouse now reaches the foreground app as a touch, and scrolling Mail then lifting opened the message under the finger: a list that took over a drag had no way to tell the pressed row it lost the press, and the same happened on real phones. Cancellation is now a contract. Event::FingerCancel and FingerUpEvent.cancelled carry it; was_tap() rejects it and no long press fires. claim_finger_gesture makes one owner per finger: PortalList and ScrollBar claim only with touch travel along their own axis (mouse drags scroll as before), and every loser, ancestors included, gets its terminal cancel in the same dispatch and never moves again. Pressed rows are cancelled before a list recycles them, cancels reach hidden widgets, and captures retire only after every consumer sharing the area has seen the cancel. iOS touchesCancelled and Android ACTION_CANCEL arrive as cancels and end an internal drag without a Drop. The WM relays StudioToApp::MouseCancel (appended, existing tags pinned) only to children that advertise it; inside a child it dispatches as FingerCancel. Widgets and apps that activated, committed, dropped, flung or resampled on any release now clear their state without acting (buttons, radios, menus, DataGrid, Kanban, Carousel, WheelPicker, RadialMenu, Modal, Dialog, Popover, colour controls, video hold-to-pause, maps, the Files treemap and tiles, Weather, Clock, AIChat, fab, flowgraph and more).
The WM phone shell rides on it: the simulated finger in the desktop skin, time-based release velocity (80 ms window, stale after a 120 ms rest), one critically damped spring (k 900, c 60) seeded with that velocity for paging, drawer, recents and app open/close, an 8 pt / 1.2x axis lock latched through release, a drawer that tracks the finger 1:1 and draws opaque over the home tiles, hold-to-Recents precedence, launches that zoom from the icon actually drawn with an opaque launch card, no ghost card on close, and one cancel/reset path for rotation, resize, focus loss, style switch and keyboard navigation.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 22:34:43 +02:00
Admin
6941c0e86b script: the Octoscript hardening keeps a Makepad host's semantics and its speed -- an uncaught error ends an evaluation only when the host sets bail_on_uncaught_error, so by default a module keeps evaluating past one bad statement and scripts can inspect returned error values; an error raised while no script ran is reported at the Rust->script boundary instead of ending, or being caught by, the next run; cross-call try unwinding stops at the nearest root frame, so an error inside a native's callback (array.retain) never pops frames an outer run_core still executes; the equality work ceiling applies to bounded evaluations only and a scalar == allocates nothing; run_core keeps its cached opcode pointer, invalidated by an epoch every bodies.borrow_mut() advances; take_allocation_error and charge_allocation are one flag read when nothing is limited, cast_to_f64 keeps its number path inlinable and checked_index is one round-trip compare
splash_bench geomean against work, best of alternating runs: +12.9% with the series as submitted (the per-instruction Option<String>::take in take_allocation_error alone was +9.8%), -1.1% with this commit.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-23 22:34:43 +02:00
ymote
a4c31be0b5 script: keep silenced streaming evals running past uncaught errors
The ws1 equality/fuel port made an uncaught script error Bail the whole
evaluation (vendor semantics). Splash's incremental eval_with_append_source
sets silence_errors because incomplete source inevitably raises errors that
are meaningless until the rest arrives, and its live widget tree relies on
evaluation continuing past them; with the Bail, `field := TextInput{...}`
never produced its child and
splash::style_tests::embedded_splash_restyles_its_isolate_without_replacing_edits
regressed (bisected to vm-port/ws1-equality-fuel alone).

Gate the Bail on !silence_errors: streaming evals keep drain-and-continue,
every other eval (including Octoscript's captured-sink evals) terminates on
the first uncaught error. Regression test added in vm.rs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JgSir4cQyaakzPju4h6smw
(cherry picked from commit a4347332b38d0d511287006dc19f0c079604f78a)
(cherry picked from commit 6ee2aecfcb7d9296b501be5ea481caef1a4d024a)
2026-09-23 22:34:43 +02:00
ymote
ba33084d9c script: port orphaned Octoscript VM hardening (execution caps, clear_type_methods, parser diagnostics)
Items no workstream branch owned, ported from the Octoscript vendor tree:

- Operand-stack and call-frame caps: ScriptVm::with_stack_value_limit,
  with_call_frame_limit, clear_execution_limit_failures; ScriptThread
  call_frame_limit / *_limit_exceeded flags, push_call_frame,
  has_execution_limit_exceeded; run_core, CALL_EXEC/RETURN/RETURN_IF_ERR
  and handle_return skip pop_to_me and raise an uncatchable
  "script operand stack limit exceeded" / "script call frame limit
  exceeded" bail. The root evaluation frame counts toward the cap.
- ScriptNative::clear_type_methods for restricted embeddings.
- ScriptParser structured diagnostics: ScriptParserDiagnostic,
  MAX_PARSER_DIAGNOSTICS, diagnostics()/diagnostics_truncated(),
  set_emit_errors(); the existing parse_errors sink is kept in lockstep.

Tests: tests/execution_limits.rs, vm.rs
return_does_not_pop_to_me_after_an_operand_stack_limit, parser.rs
diagnostics_* tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JgSir4cQyaakzPju4h6smw
(cherry picked from commit bfa4087b59abf64d30c385bea53120e0adf2f64b)
(cherry picked from commit 6a349506dd58b4f150dfa12f447385def3f1f469)
2026-09-23 22:34:43 +02:00
ymote
1f481016f4 script: port Octoscript heap/string/array/object hardening onto upstream's allocation budget
Workstream 3 of the Octoscript VM patch port (heap, strings, arrays, objects).

- Array opcode reads and writes validate the index (finite, non-negative,
  integral, representable) before touching storage: ScriptValue::checked_index
  and ScriptVm::checked_array_index, applied at every array/pod index site in
  opcodes_vars.rs and opcodes_assign.rs.
- Updating an existing untracked object field keeps its insertion order
  (ScriptObjectData::map_insert), matching the tracked path.
- Numeric string conversion handles inline and heap strings alike and yields
  a traced NaN for text that is not a number (ScriptHeap::cast_to_f64).
- Heap accounting: Octoscript's retained-heap cap is expressed over upstream's
  ScriptAllocationBudget instead of a second parallel accounting system. A
  persistent budget (heap_cap) is charged by the same charge_allocation calls
  as the scoped with_heap_allocation_limit budget, its headroom re-derived
  from a retained-capacity estimate by reconcile_heap_bytes (setup, GC sweep,
  shrink_to_fit, host boundaries). Public API preserved for octoscript-core:
  set_max_heap_bytes / max_heap_bytes / accounted_heap_bytes /
  reconcile_heap_bytes / take_heap_limit_exceeded. Refusals surface through
  take_allocation_error, so run_core bails uncatchably as before.
- Per-string ceiling: set_max_string_bytes / max_string_bytes /
  take_string_limit_exceeded, enforced on exact lengths at the store choke
  points (new_string_from_str, new_string_concat, intern_or_store_string and
  its preflighted variant, check_intern_string), plus ScriptStringSink,
  ScriptStringBuffer, new_bounded_string_with and temp_bounded_string_with
  (bounded by the string ceiling and the remaining allocation budget) for
  hosts that build strings incrementally. cast_to_string is generic over the
  sink. Byte-array parse_json builds its lossy text through the bounded buffer.
- Pod creation is charged; ValueMap/ScriptArrayStorage/ScriptObjectData expose
  retained_bytes for the estimate.

Retired in favor of upstream: per-path capacity preflights in array_heap.rs /
object_heap.rs (charge_allocation already meters sparse growth), the sink
generalization of to_json/percent/regex builders (upstream preflights exact
lengths), array_mut_with in vec_prims.rs (host conversions are covered by
reconcile_heap_bytes at the host boundary).

Tests: invalid index reads/writes leave storage untouched, numeric conversion
variants, insertion order, capped sparse growth (array, object vec, object
map) refused before mutation, string ceiling at the store paths and in the
bounded buffer, byte-array to_string/parse_json limits, lossy UTF-8 parity,
scoped budget nesting inside the cap.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JgSir4cQyaakzPju4h6smw
(cherry picked from commit ce4bbe5980f38fd0206f06fe27568528bd49a394)
(cherry picked from commit b21de9ff271d523f52b6154df3c7ef84048772d7)
2026-09-23 22:34:43 +02:00
ymote
2f9565e08a script: port Octoscript parser/tokenizer/control-flow VM patches (ws2)
Ports the parser, tokenizer and control-flow part of the Octoscript
makepad-script patch set (PATCHES.md, grammar v0.2) onto the September
`work` revision, by hand, area by area.

Decisions per PATCHES.md item:

1. Logical/comparison precedence, streaming, `!`: ADAPT. Upstream already
   patches a pending ShortCircuitEnd during auto-close but forgot the
   operator: ShortCircuitEnd now retains `what_op` so a tighter logical
   operator keeps a looser left jump open (`a || b && c`), the checkpoint
   restores the original TEST opcodes on continuation, comparisons (14)
   bind tighter than equality (15), and NOT always negates truth
   conversion instead of doing a bitwise NOT on f64-stored numbers.
   Upstream's `last_jump_target` bookkeeping is kept at every patch site.
2. Canonical `try protected catch fallback`: PORT. `catch` is a one-shot
   contextual separator carried in TryErrBlockOrExpr checkpoint state
   (allow_catch/canonical_catch/protected_was_block); block branches keep
   their tail value by removing the inherited pop-to-me marker before
   recomputing the jump; TRY_ERR now uses its encoded relative distance
   and the parser adds the extra TRY_OK skip only when legacy `ok`
   follows. Legacy catch-less `try a b [ok c]` still parses (the checker
   in Octoscript's own crates restricts it to the compatibility entry).
3. Cross-call unwinding: PORT. handle_errors searches all call frames
   (call_stack_has_try), pops younger script calls restoring slot_base
   and the return ip's body, then applies the try-frame cleanup/jump.
   Hard bails stay on ScriptTrapOn::Bail.
4. Loop back-edges: ADAPT onto upstream's reset_iteration_scope fast
   path: truncate_loop_iteration_bases discards iteration-local tries,
   operand values and mes before the scope reset; plain loop/while keep
   their iteration scope and free nested ones. Hard time-budget bails
   drain their diagnostic; OK_END with no try frame bails.
5. Field-assignment reverse-pair walk: PORT (stop at a 1-opcode chunk).
6. Prototype-field `:` rewrite: PORT (chain must begin with an id,
   paired insert through insert_code_with_source keeps opcode/source-map
   lockstep); unavailable rust-value index is a parse error.
7. Numeric-boundary tokenizer: PORT (`_` stays in the pending number
   instead of moving to Whitespace with stale text) plus the char-count
   token length so a multibyte identifier cannot underflow `pos`.

Tests: inline parser/tokenizer/vm regressions and tests/try_catch.rs
(legacy syntax, block/expression branches, nested and cross-function
recovery, contextual `catch`, checkpoint restoration, loop cleanup,
streaming appends, precedence and effects, tokenizer boundaries).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JgSir4cQyaakzPju4h6smw
(cherry picked from commit 8231a13906cfb339b496ff78b687e43a48e4e11b)
(cherry picked from commit a1f7afb543c8a737f9c56936bfcba605097f88df)
2026-09-23 22:34:43 +02:00
ymote
4a00885f26 script: port Octoscript WS1 — worklist equality with fuel/deadline/work bail, uncaught-error bail, allow_debug_output
Port of the equality / fuel / error-bail slice of Octoscript's makepad-script
patch set onto the September `work` base.

equality (PORT, string compare ADAPTED): `deep_eq` moves from heap.rs into
the new equality.rs as an iterative worklist that visits each container pair
once (cycles and shared DAGs terminate), keeps NaN unequal to itself, and
charges one work unit per processed pair, queued edge and typed-array
element, capped by MAX_EQUALITY_WORK = 65,536 per comparison. Upstream's
69d78873e string early-out is kept instead of the patch's chunked byte
compare: every heap string is interned (string_heap.rs) and short strings
are inline, so string equality is exactly bit equality and a string pair
costs one unit. The raw host `ScriptHeap::deep_eq` is iterative and
unbounded and consumes no VM fuel. The `==`/`!=` opcodes go through
`deep_eq_bounded`: each unit charges one instruction of
`instruction_limit_remaining`, the hard deadline (now an f64 on the
platform clock) is sampled every 256 units so trivial comparisons never
touch the clock, and exhaustion drains diagnostics and raises an
uncatchable Bail, like the instruction limit.

uncaught errors (PORT): `handle_errors` without an active try frame drains
the diagnostic once and sets `ScriptTrapOn::Bail(error)`, so no later
instruction or host effect runs and `eval` returns the error value; active
`try` handlers recover exactly as before. The hard time-budget bail drains
its diagnostic before unwinding, as the instruction-limit bail already did.

allow_debug_output (PORT): new host-controlled `ScriptVmBase` flag,
default true so raw makepad debugging is unchanged. When false the `~` LOG
opcode raises a catchable not-allowed error and `ScriptVm::log` is a no-op.
Incidental VM prints are removed: run_core's `log!` traces, the undefined
opcode `eprintln!` (now a bail) and the loop "unknown state" `println!`
(now a bail). mod_std.rs needs no change: std.log already routes through
the gated `ScriptVm::log`.

Tests: platform/script/tests/equality_fuel_bail.rs covers cycles, shared
DAGs, NaN, string/number semantics, the host deep_eq on typed arrays and
beyond the ceiling, instruction fuel charging, the work ceiling being
uncatchable, the in-comparison hard-deadline check, the hard-budget drain,
uncaught-error bail with try recovery, and the debug-output flag.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JgSir4cQyaakzPju4h6smw
(cherry picked from commit a44f8678ed68b20a0c413d607c07a37d55186fbe)
(cherry picked from commit 353fa369faa5672e075dd874a431dc928420bafb)
2026-09-23 22:34:43 +02:00
ymote
6c3414f087 script: re-entrant dispatch, thread index validation, Any-based handle downcasts, UTF-8 previews; regex: never_loop fix
Port of Octoscript's re-entrancy and hardening items onto the new VM host contract.

- vm.rs: run_core no longer caches a raw pointer into the active body's opcode
  vector across native calls. Each opcode is copied through a scoped
  `bodies.borrow()` that ends before dispatch, so a native handler that
  re-enters `eval` and replaces the body's parser cannot leave a dangling
  pointer. Regression: reentrant_reload_of_the_active_body_does_not_keep_an_opcode_pointer.
- thread.rs: ScriptThreads::set_current validates the index before updating
  the cached pointer (set_current_thread_id routes through it); update_ptr is
  bounds-checked via get_mut; cur/cur_ref/trap use release-mode assert!.
  Regressions: selecting_an_unknown_current_thread_panics_before_pointer_update,
  empty_threads_reject_current_access_in_release_builds.
- handle.rs: ScriptHandleGc: Any; is/downcast_ref/downcast_mut compare
  Any::type_id, removing the overridable ref_cast_type_id hook.
  Regression: handle_downcasts_use_the_concrete_any_type.
- suggest.rs: value previews truncate at character boundaries.
  Regression: preview_truncation_preserves_utf8_boundaries.
- libs/regex utf8.rs: iterator entry uses `self.range_stack.pop()?` instead of
  a never-advancing `while let`, replacing upstream's #[allow(clippy::never_loop)].

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JgSir4cQyaakzPju4h6smw
(cherry picked from commit ee7729e71c1408f61ec8f9083a79bdf9117d31a7)
(cherry picked from commit cdbc33e8ac1683fcdeb6e9dcb076e26ce5d23360)
2026-09-23 22:34:43 +02:00
Admin
76627b6f19 ci: a driven app takes every key once, and the storage module builds for the browser -- the mini's wm script went red one run in three at the browser launch, and the shell menu's new log lines said why: the filter read "bbrowser" and the menu had opened twice. The remote bridge applied every wait=1 input first and, when the frame after it could not be sealed (the window was busy presenting the warm browsers), answered "requested input frame could not be submitted; retry"; the CI driver took that at its word and sent the input again, so a busy app took the Cmd+Space and the first letter twice. The bridge now keeps the waiters of an applied input and asks for the frame on the next beat, as it already did for a drawable still being acquired; the driver never asks an input route twice, whatever the answer, and still retries a grab it could not place. The workspace row was orange and apps/scope red on wasm32 since 8d7246231: the public volume_available_bytes had been put between the not(wasm32) guard and the native module it guarded, so the module compiled in the browser with nothing using it (17 warnings) and the function it exported was missing there; the guard is back on the module, and the browser has a volume_available_bytes that says the free space is not known 2026-09-22 19:04:04 +02:00
Admin
2e926a70f4 platform: the storage module says how much a volume has free -- volume_available_bytes(path) was the private figure behind the storage estimate; an application that sizes a store by its disk has to ask the disk, not carry a figure of its own (Scope prepared into a fixed 32 GB per namespace and stopped at "disk capacity" on a volume with room to spare), so it is public now
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 17:11:05 +02:00
Admin
ab64a64e7e tools: makepad-screen is makepad-agents, and its binary is agents -- the crate is the agent session manager (start, attach, list, the TUI); "screen" was a nod to GNU screen, and its other job, the pty trampoline a terminal starts its shell through, does not need the old name either. The package is makepad-agents in tools/agents, the executable is agents, so it is the command on the PATH itself and the shell wrapper that existed only to give it that name is gone (the binary already resolves the workspace's session directory the wrapper used to export); the terminal's pty spawn looks for agents beside the app, Director looks for and pins the sibling agents with the makepad-agents-v1 record and the agents version line, the session environment is MAKEPAD_AGENTS_SESSION and MAKEPAD_AGENTS_STATE_DIR, the CI scripts build makepad-agents, and Director's notes say how to build and run it
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 09:36:13 +02:00
Kevin Boos
71f3b84a87
Linux: fix window chrome button hovers and how maximized/fullscreen windows work (#1255)
* Wayland: restore a maximized window maximized, not fullscreen

`configure_window`'s `is_fullscreen` is the legacy maximize-or-fullscreen
flag, and on Wayland the reporting side says so out loud: `wayland_state`
builds the geom with `is_fullscreen: is_fullscreen || is_maximized`. But
`WaylandWindow::new` took that same bool and called
`toplevel.set_fullscreen(None)`. So an app that persists `is_fullscreen()`
on exit and feeds it back through `configure_window` on the next launch --
Robrix does exactly this -- turns a window the user had merely maximized
into true compositor fullscreen, and the escalation sticks: the next save
records the monitor size rather than the work area.

Wayland was alone in reading the flag that way. x11 creates with
`self.maximize()` (`_NET_WM_STATE_MAXIMIZED_HORZ/VERT`) and reports
`get_is_maximized()` back; win32 creates with `ShowWindow(SW_MAXIMIZE)`
and reports the `WS_MAXIMIZE` style bit. Both round-trip. Only macOS takes
the flag literally, and AppKit keeps a menu bar and traffic lights there.

* Create with `set_maximized()`.
* Seed `is_maximized` from the request rather than `is_fullscreen`.
  `wayland_is_fullscreen` is copied out of that field before the first
  configure arrives, so the old seeding claimed fullscreen from frame one,
  before the compositor had confirmed anything, while `window_geom` still
  said `is_fullscreen: false`. The two signals no longer disagree.
* `should_show_csd_shadow` gets the request as `maximized`; same answer as
  before, now for the right reason.

An app that wants to come up genuinely fullscreen still can:
`WindowHandle::fullscreen()` during `Event::Startup` queues
`FullscreenWindow` behind `CreateWindow` in the same FIFO drain.

Also corrects the docs this contradicted. `configure_window` claimed
`inner_size` and `position` are ignored when fullscreen and that the
window is sized to the monitor, which is true on no backend now, and
`maximize()` claimed macOS zooms when it calls `toggleFullScreen:`.

* Wayland: keep our window chrome up in fullscreen

Under client-side decorations we draw the title bar and the min/max/close
cluster ourselves, and we were hiding both the moment the compositor put
the toplevel in fullscreen. The compositor draws nothing in their place,
so the window ends up with no chrome at all -- and the max button is the
only path to `RestoreWindow`, so there is no way back out. There is no
F11, no Escape, `Window::handle_event` has no `KeyDown` arm, and the View
menu is inert outside macOS. That leaves the compositor's own keybinding,
if the desktop happens to have one bound.

Hiding chrome in fullscreen is the right call when the OS supplies its own
-- macOS has an auto-hiding menu bar and traffic lights there, which is
why that arm stays as it is. Wayland supplies nothing, so ours stays up.

* `sync_caption_bar_state` drops the `wayland_fullscreen` terms: the
  caption bar and the buttons now follow `custom_chrome` alone.
* Fill `window_chrome_buttons` in the geom in fullscreen too. It is the
  transitional hit-test rect `WindowDragQuery` falls back on before the
  widget layout is known, so leaving it empty made the first clicks after
  entering fullscreen read as a caption drag instead of a button press.
* Let the caption's own gestures through in fullscreen -- they were gated
  behind `!is_fullscreen` on a bar that could not be visible then anyway.
  Double-click now unsets fullscreen first: `set_maximized` under it does
  nothing, so the bar would have looked dead.

`is_wayland_fullscreen()` loses its only caller but stays public: it is
the only way to tell true fullscreen from maximize, which the conflated
`is_fullscreen()` cannot. Say so on `WindowGeom::is_fullscreen` too, since
reading it as real fullscreen is what started this.

* Window: drop hide_caption_on_fullscreen, a dead trap

The `WindowGeomChange` arm hid the caption bar whenever the geom flipped
to `is_fullscreen`, on `Windows | Macos`. On Windows that flag is literally
`get_is_maximized()` (`win32_window.rs`: `is_fullscreen:
self.get_is_maximized()`), and Windows draws its own chrome, so this would
have stripped the close button on a plain maximize -- the same trap just
fixed on Wayland, one `#[live]` default away from firing.

It never fired, and could not have: `hide_caption_on_fullscreen` is set
nowhere in makepad or in any app (grep finds no other mention, DSL
included), and `sync_caption_bar_state` re-decides caption visibility on
every event through `ensure_initialized()`, so it overwrites whatever this
arm set. The macOS half it duplicated lives there already.

Deleted rather than repaired: the whole caption policy belongs in
`sync_caption_bar_state`, and a second copy that keys off a flag meaning
different things per platform is what produced the bug in the first place.

* macOS: restore() no longer enters fullscreen

`restore()` and `maximize()` were the same call, `toggleFullScreen:`, so
`CxOsOp::RestoreWindow` on a window that was not fullscreen put it *into*
fullscreen. The Window widget's max button hands `restore()` whatever
`is_fullscreen()` reports, which on macOS is the real NSWindow fullscreen
state -- so this only misfires when something else pushes `RestoreWindow`
on its own, but then it does the exact opposite of its name.

Guard on `is_fullscreen`, the field the fullscreen delegates maintain.

* x11: implement FullscreenWindow and NormalizeWindow

Both fell through to the catch-all `Not implemented on this platform`, so
`WindowRef::fullscreen()` and `disable_fullscreen()` silently did nothing
on x11. `_NET_WM_STATE_FULLSCREEN` was never even interned -- the atom
table only carried the two maximize atoms.

* Intern `_NET_WM_STATE_FULLSCREEN`, and split the `_NET_WM_STATE` client
  message out of `restore_or_maximize` so the fullscreen requests can
  reuse it instead of copying the send.
* `get_is_maximized` becomes a thin caller of `has_net_wm_state`, which
  `get_is_fullscreen` shares.
* `get_window_geom` reports `maximized || fullscreen`, the same union
  Wayland reports and the meaning the flag already had. Creation still
  maps the flag to `maximize()` alone, so a persisted `true` cannot come
  back as fullscreen -- the bug this branch opened with.
* `RestoreWindow` drops both states, matching the Wayland arm: a caller
  restoring off `is_fullscreen()` means "make it small again", and the
  union does not say which of the two is set.

* Wayland: go back to the floating size when leaving maximize

An xdg_toplevel configure of 0x0 means "pick your own size", which is what
the compositor sends on the way out of maximize or fullscreen. We fell back
to `window_geom.inner_size` -- the size we were maximized at -- so the
window came out of maximize still covering the work area, with nothing to
bring it back down. Creating a window maximized made it permanent: the
floating size was never recorded anywhere.

Track the last size the window actually floated at, and use that for the
0x0 case. `is_floating` excludes tiled as well as maximized and fullscreen,
so a half-snapped window does not get recorded as the floating size.

A configure that does carry a size is still obeyed exactly as before, which
is both what the protocol requires and what a user drag-resize produces.

Seen with a window created maximized and then normalized: 3383x1408 before,
the requested 900x600 after. Note this only covers the case where the
compositor defers to us -- GNOME sends a concrete size after unfullscreening
a window that was maximized first, and we honor it.

* Linux: tell the app when the pointer leaves the window

Neither Linux backend ever sent `Event::MouseLeave`. Windows has sent one
since forever, and `Hit` handles it -- `finger.rs` returns `FingerHoverOut`
for whatever area still holds the hover -- but on Wayland and x11 nothing
produced it, so the last hovered widget kept its hover the entire time the
pointer was outside the window.

That is what makes the window chrome buttons flicker. Hover close, move the
pointer off the top of the window, and the button stays lit; the hover only
clears on the first motion after the pointer comes back, so returning to the
window makes the button flash off. It is most obvious on the chrome buttons
because they sit against the window edge, where leaving the button and
leaving the window are the same gesture.

It also broke re-entry. `FingerHoverOut` does not clear the stored hover
area -- `cycle_hover_area` does, once per event -- so with no leave event
`hover_last` still named the button, and coming back over it returned
`FingerHoverOver` instead of `FingerHoverIn`. Widgets act on HoverIn, so a
button could fail to light up at all on the second hover.

* Wayland: emit it from `wl_pointer.leave`, guarded on `pointer_window`
  being set, which it is only for the toplevel surface -- leaving a CSD
  shadow gutter has no hover to drop.
* x11: finish the `LeaveNotify` TODO that has been commented out in
  `xlib_app`. The condition it had, `detail == 4`, would not have fired
  anyway: a real pointer-out-of-window here reports detail 3
  (NotifyNonlinear). Take any detail except NotifyInferior (the pointer
  only moved into a child), and only mode NotifyNormal, so a grab or
  ungrab does not drop the hover mid-drag.
* Both event loops then `cycle_hover_area` + `switch_captures`, the same
  pair the MouseMove arm uses and the same thing the Win32 arm does.

Verified on both backends with a probe on the hover in/out arms: before,
leaving the surface logged nothing; after, HoverOut fires on leave and a
fresh HoverIn on re-entry.

* DesktopButton: cross-fade the hover background premultiplied

The chrome buttons flash dark for an instant when the pointer leaves them.
Not a hover-state bug -- the `hover` instance really does fall 1.0 -> 0.0
monotonically over the 100ms fade. The dip is in the shader.

`bg_color` is `#00000000`: transparent BLACK. Mixing it toward an opaque
`bg_color_hover` in straight-alpha space ramps rgb up from black as well as
alpha, and `sdf.fill` then multiplies rgb by that same alpha again, so what
reaches the premultiplied blend is `rgb * h^2` against coverage `h`. Over a
caption bar of luminance C the composite is quadratic in h and sags well
below both endpoints in the middle.

Measured on a #F3F3F3 bar with the `#E9E9E9` hover face this file's callers
use (widgets/src/window.rs), sweeping hover across the button's width:

    hover    0%   30%   52%   80%  100%
    before  246   207   199   212   238
    after   246   244   242   240   239

The endpoints are 8 levels apart, so the intended highlight is nearly
invisible -- and the 47-level excursion between them is the only thing the
eye catches. It is symmetric, but on the way in it reads as arrival feedback
and on the way out it is a dark flash left behind where the pointer just
was, which is why it gets reported as flicker on hover-out.

Premultiply each face before mixing and fill with `fill_premul`, so the
cross-fade is linear in `hover` and anti-aliasing blends in premultiplied
space too. `DesktopButton` is the only widget with a fully transparent base
colour feeding this pattern.
2026-09-22 08:47:38 +02:00
Admin
86cd0604ef libs: no warnings in the workspace check on any row -- the CI box checks every package on every target, and the library crates, which have no tile of their own, warned on the rows nobody builds by hand. On wasm and mobile, things are gated with their users: the workspace document worker (its commands, payloads, retry constants and Drop are native; the wasm API stays, behind an uninhabited worker whose constructors answer that the browser has no document worker), the hub's unused non-Unix available_bytes and its ram facts parser, the loader's ArenaPtr, system_speech's bcp47. On the tvOS rows, the only ones built on nightly, the legacy numeric constants and functions become the associated constants they have been since Rust 1.43 (micro_serde, bytemuck, rustybuzz, unicode-script, smallvec, weezl); fetch_update keeps its name under allow(deprecated) in stitch, git and the map archive, since try_update does not exist on older stable toolchains; objc-sys declares free with the signature the standard library uses; rustybuzz calls its own method through a path that a future std method of the same name cannot shadow; and the Script derive's unused helper attribute splat, which nightly now reserves as a built-in, is spelled script_splat (nothing in makepad, Scope or Stage uses it)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 00:02:28 +02:00
Admin
661842f875 platform: a hidden window wears no hands-off frame -- the red frame a window wears for three seconds after the remote bridge injects input is for a person watching a scripted run; in a hidden window nobody watches, and there it only landed in the grabs, present in a capture taken right after a click and absent in the next one, which made the text atlas stress test see "changed text rows" and changes what any pixel test or vision check sees from one capture to the next
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 23:48:07 +02:00
Admin
9788b827eb tests: the workspace suite, run as a whole for the first time, passes outside the example UI tests -- each failure was settled from history as a stale test or a regression. Stale, expectation updated to the change that overtook it: draw's road pack tests fed a z-bias tick outside the exact f16 range; network no longer reserves Accept (906f94a94); the log ring test waits for the asynchronous sink (2e27ce2ff) and the audio tap test no longer assumes it owns the shared registry; xatlas compares the irregular oracle within the official tool's float precision instead of bit for bit; xr's four-wheel car exposes the chassis query plus one per wheel (080794781) and the depth mesh plan follows the 0.32 m chunk (ddec6fc60); score's DSL test sets up the OS context clock it reaches; hello_world's GIF test describes the fixture that is actually embedded. Regressions, code fixed: the tweaker could not print layout enums as whole values because the derive never emitted the __enum companion it looks up; the workspace style picker never learned about the Black orange style put at the front of DesktopStyle::ALL, and per the decision that Black orange is not offered in pickers it lists ALL without it, maps indices accordingly and loads a stored "blackorange" without a selection; xr's car controller no longer scales engine force by 1/dt a second time (same force at the fixed step) and a scaled vehicle's suspension is stiff enough to carry it at its shortened rest length. The two xr tests that need a local-only reference dump (xr/dump is git-ignored) say so and return
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 23:41:03 +02:00