A test is a ci.splash beside what it tests; the script decides every input and the model only ever judges one picture against one acceptance text. mod.ci: launch (hidden, --remote, user_seq preserved), key, type_text, click, get, snap, wait_log (a * is a gap inside one line), no_errors, grab, quit; step, sleep, check, run; cargo, check_targets (the cargo makepad check matrix, check only for platforms we are not on, a test fails if the two tables drift), test, build, machine (another box over the makepad tunnel), exclusive; judge, accept, ask. The watcher polls git ls-remote once a minute for work and any extra branches, syncs a checkout the CI owns, runs the root script first and alone, then the rest up to a parallel limit behind one shared model judge. The window is a wall of squares, one per script: green passed, orange warnings, red failures, with a detail panel for the selected one.
Scripts: the root ci.splash (workspace check with core warnings denied, the tests), apps/wm (desktop up, switch to macOS by Cmd+Space / type / Return, launch the terminal and the browser, each waited for by the WM's own first-frame line), and one per main app in the default shape. Proven here: apps/wm/ci.splash green in 280 s, fifteen target checks and seven vision verdicts.
Models come from Hugging Face through the hub: registry entries qwen3.5-4b-vision and qwen3.5-9b-vision with exact revisions, sizes and digests, and hub-install, a command line over LocalModels::start_install. vlm-probe reads PNG.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Every manifest `app_main!` emitted carried three fonts no theme role uses:
`NewCMMath-Regular.otf` for `MathView`, and `Inter.ttf` / `RobotoFlex.ttf` for the opt-in
iOS and Android platform styles. That was 3.6 MB in every package, and it only existed
because a font an app forgot to declare failed silently: `FontFamily::update_font_definitions`
skipped a member whose bytes never arrived, so the text showed as boxes with no log line.
* Drop the forced extras. The manifest is now the font set's fallback chain plus whatever
the app puts in `font_assets`, which is what makepad's own apps already did for `Inter`.
* `font_assets` takes expressions, and `INTER_FONT_ASSET` / `ROBOTO_FLEX_FONT_ASSET` join
`MATH_VIEW_FONT_ASSET`, so an app declares a font by name instead of by path.
* A font that never loads now logs one `error!` naming the path and the fix. A missing
member still degrades gracefully: the family keeps its remaining members.
* The apps that use those fonts declare them: the `wm` family binds both platform faces,
`clock`, `weather` and `director` draw with Inter and can select any style, `terminal`
and the builder use Inter for symbols, `splash` and `aichat` use `MathView`.
`cargo tree` only prints a directory for path dependencies, so for a git
dependency we fell back to the `<crate>.path` file its build script drops
in the target dir. Any tool that prunes the target dir deletes that file,
and a warm cache means the build script never re-runs to recreate it, so
`add_resources` silently found no `resources` dir for `makepad-widgets`
and packaging failed with "font assets declared by makepad.font-assets.v1
are missing on disk". Ask cargo for each package's `manifest_path`
instead, keeping the `.path` file as a last resort.
Measured on the Pixel 11 Pro XL (PowerVR): a pane swipe presented at
~84 fps on the 120 Hz panel, a vsync dropped every three to six frames.
simpleperf showed 22% of the CPU in the driver's shader compiler and 24%
in its render-target teardown: the Vulkan backend created a VkRenderPass
and a VkFramebuffer for every offscreen pass on every frame and destroyed
them after the fence, and on this driver each render pass compiles a
load-op shader. Offscreen draw render passes now live for the device
(keyed by formats and load/store ops) and framebuffers are cached per
render pass, attachment views and storage extent, invalidated through
texture retirement so they die after the frame that used them.
The app icons were re-tessellated from SVG every frame: one DrawSvg kept
one scale and the desk draws each icon at two or three sizes. A DrawSvg
keeps up to four meshes per device scale; the geometry pool defers frees
and releases them once per frame against the geometry ids the live draw
lists still name, so a retained draw call never sees its slot reused.
A font member whose resource can never load (the WM referenced Inter and
its other faces through `self:../../widgets/...`, unmapped in a package)
kept its family incomplete, and an incomplete family is redefined every
frame: the layout cache cleared, every label laid out again, the asset
reopened. Such a member drops out of its family once, logged, keyed on
the resource registry's generation so a resource that appears later is
asked for again. The WM names its fonts through `makepad_widgets:` and
reads the clock in-process on the UI thread instead of forking `date`
twice a second.
Android gains a `frame.cpu` trace (events, next-frame, draw and repaint
milliseconds per drawn frame) and a profileable manifest so simpleperf
can sample a release build. The dyn-pack tile proof tolerates the app's
own Dirty line after an engine rebuild.
After: SurfaceFlinger presents every swipe frame at 8.3 ms, the render
thread runs at ~45% instead of 85–97%, and the frame is paced by the GPU.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
`cargo makepad android dyn-pack` stages the relocatable checkout,
cross-builds host + engine from it through the ordinary Android build,
proves every tile's on-device command against that target/, packs the
APK with the phone toolchain, the checkout and target/ as streamed LZ4
tar parts, and rehearses the phone's first tile open from the packed
APK; `dyn-rehearse` runs that last gate alone. This replaces the
Python and shell pipeline that lived outside the tree. The stage
directory is tool-owned, every cargo phase runs under one controlled
environment recorded in the target's marker, rustc runs through
cargo-makepad itself as the remapping wrapper, and the APK is renamed
into place only after signing and the rehearsal. The host package
names its engine and tiles in [package.metadata.makepad.dyn]. Only the
three /system/bin/sh templates that run on the phone stay shell.
libs/rmeta is the rustc metadata header reader apps/wm used, now shared
with cargo-makepad; libs/tar gains a streaming ustar writer with GNU
long names; the zip writer streams to any sink so a 900 MB APK never
sits in memory.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The root menu names the two entries Makepad WM and Makepad Apps, in that
order, below Compile and run Scope. Every entry in Makepad Apps now does
what the WM entry already did: set up any missing compiler, download the
sources, compile and open the app, then return to the list with the
selection kept. The nested per-app checklist and its Back entries are
gone, so the menu has one shape. The Builder's runbook follows.
The platform reads --focus since this morning, not MAKEPAD_FOCUS; the
macOS launch of Scope passes the argument.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/makepad_builder replaces tools/makepad_loader: one build target
shared across app builds, workspace package selection, checkout
progress on the public Git API, detached built apps with a completion
state, waits for Windows security scans, manual retry after compiler
locks, dedicated-folder installer checks, catalog and runtime fixes.
tools/web_server and its scripts leave for github.com/makepad/webserver.
Arch USB clone/restore scripts, the qwen38 box scripts and the G-belt
serial test join tools/. docs/agents records the agent workflow and the
remote-control handoff protocol; AGENTS.md forbids vendored sources and
bulk imports. Cargo.toml lists apps/wm-dyn, libs/code_language,
libs/search, libs/tar, libs/loader_bundle and tools/makepad_builder,
and drops the two removed crates.
Squashed from work:
- Share Builder target across Makepad app builds
- Fix Builder workspace package selection
- Align Builder checkout progress with public Git API
- Detach built apps and show completion state
- Wait for Windows security scans
- Offer manual retry after Windows compiler locks
- docs: the agent workflow of record and the remote-control handoff protocol
- builder: dedicated-folder installer checks, catalog and runtime fixes; Windows job objects hold c_void handles
- tools: Arch USB clone/restore scripts, the qwen38 box scripts, and the G-belt serial test
- tools: the web server moves to makepad/webserver
- AGENTS.md: no vendored sources or bulk imports in the tree
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Retained renderer support is back for Scope on Metal, Vulkan, OpenGL,
WebGL and the simulated GPU. A `vulkan` cargo feature picks Vulkan on
desktop Linux, Cx::gpu_backend() names the compiled GPU API, and the
direct WM builds again. Settings.renderer in libs/workspace keeps the
saved GPU API choice (Vulkan | OpenGL) behind the --renderer-routed
argument. The Android build keeps the texture alloc types imported for
OES adoption, and that import stays off the web build. The simulated
GPU builds on Linux again.
Squashed from work, without the cargo vendor snapshot the retained
renderer commit carried there:
- platform: a `vulkan` cargo feature picks Vulkan on desktop Linux; Cx::gpu_backend() names the compiled GPU API; the direct WM builds again
- workspace: Settings.renderer — the saved GPU API choice (Vulkan | OpenGL) and the --renderer-routed argument
- Restore retained renderer support for Scope
- platform: Android builds again — the texture alloc types stay imported for OES adoption
- platform: the Android texture-adoption import stays off the web build
- platform: the simulated GPU builds on Linux again
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 55 work commits (Sep 1–12):
0fd356d windows: the vendored bindings are generated from a checked-in filter
79882b5 fabric: a photo or a live camera to a fitted sewing pattern
1e93309 AGENTS.md: designs stay local; no OS screenshots; focus and hidden-window laws
aa96dbd cargo-makepad wasm: package the bin target's wasm and create dirs before minifying
14d0723 cargo-makepad wasm: production packaging — strip, small profile LTO, optional binaryen, size report
79e7526 sqlite: a page-store seam — the file backend as before, an in-memory backend, and open_memory / open_with
60ee978 cargo-makepad: package artifacts carry a content hash so a re-upload is a new URL
611c9eb cargo-makepad: production packaging stays off fat LTO; script VM under LTO investigated
ab8febc cargo-makepad: fonts packaged from the app's font manifest
f6bbee9 wasm bridge: shared memory asks for the 4 GiB wasm32 ceiling and steps down where the engine refuses
fb1416d cargo-makepad: the threaded wasm module is linked with the 4 GiB wasm32 memory ceiling
fd5d70c cargo-makepad: the app's own resources are packaged under its bin name, which is how self:// resolves
f51ca07 workspace: the wasm interpreter's tests build at opt-level 1 — its own profile setting is ignored inside a workspace, and opt-level 0 overflowed the script eval stack
942ff86 sqlite: the browser store has one owner — its locks never wait on a clock
82d0cfa web path: the trace helper keeps its doc, the journal nonce steps a counter where there is no clock or pid
6f8c08f web-server: POST /api/crash stores crash reports in a rotating log on both servers
106b38c wasm bridge: the imported memory honours the module's declared limits
94b8726 dj-pack: tracks in, stems through the hub, a site store snapshot out
d9f04fc dj-pack: pack reads caches, never creates them; dry-run writes nothing
e6a305c ai-hub + dj-pack: a whole track fits a stems job; long tracks split into spans
d1910b8 web-server: a store snapshot's extensionless routes are served with the types the exporter recorded
c1f7b53 asset-client + dj-pack: a long description never rejects a snapshot; the packer writes one bounded line
453197d dj-pack: analyse produces the beat grid, overview and loop-splat caches the demo cache ships
9b4a3ca network: every completion raises the UI signal
fad1c49 web server: audio and text files are served, and models/ is immutable like maps/
569b4a7 dj-pack: every CC BY and CC BY-SA version and the public domain mark are redistributable licences
dc9cce6 workspace: no std clock on the web in any crate the web apps link — the last start-up worker death is gone
c7639f0 clippy: timed std waits (sleep, recv_timeout, wait_timeout, park_timeout) are disallowed — they read the std clock and panic on wasm workers
d748753 wasm bridge: the page environment carries js_worker_wait so the module links — the pool landing added the import for workers only
ec40fdb vj + widgets: double-click a knob or fader to reset it to its default — the Slider handles tap_count 2 and emits its normal Slide action; the deck controls carry their neutral defaults (pitch 0, gain/EQ/stems 1, filter centre, crossfader centre)
fe23e06 AGENTS.md: the execution policy — zero locking on the UI thread as one mechanism for native and wasm, no temporary threads (the pool), the standard operating flow (Codex codes, Fable designs and reviews, Grok tests), and the tweaker on Shift+F10
e689aea web_server + geodata + route: live radar, wind and weather on makepad.nl/api — one bounded poller per feed, hourly, disk-backed cache served from an Arc snapshot (a restart never re-polls early), 503 warming until the first result, health reports ok/warming/unavailable with timestamps; KNMI key from --knmi-key-file, the documented anonymous open-data key otherwise; libs/geodata fetches through the platform HTTP client instead of shelling out to curl; the client retries 503 after 30 s and disables a layer only on 404
cd33943 web_server: radar and weather run on KNMI's documented anonymous key when no --knmi-key-file is given; without --live-cache the pollers keep an in-memory cache and say so once
2f3e393 web_server: a directory path without its trailing slash (/score) redirects to /score/ instead of 404, query preserved
9a31d21 flow-ui + widgets: a chosen model shows no node list, and a closed ComboBox shows the start of a long label
22b2c78 docs: streamline agent runbook and extract reference guides
6058284 terminal: add hostable session multiplexing via tools/screen
8a9345b tools: migrate Cargo.toml lookups to segment-path keys
8749b91 counter: keep app state across Splash reloads
3ffd485 tools: add agent launcher and AIHub node update and smoke scripts
c33a9d3 screen: add bypass and resume menu options
c40d234 AGENTS.md: current delegation hierarchy (Grok mechanical, Codex hard, Fable manages)
4184455 Workspace: scope lives at apps/scope (clone of makepad/scope)
27844c9 makepad arch usb builder
dd967eb Workspace: drop nine members that are not in the repository
1961768 AGENTS.md: hierarchy 2026-09-11 — Fable builds, Codex reviews, Grok proves
9cd9f94 AGENTS.md: rendering is verified on the real GPU backend, headless is for logic tests only
5f53254 AGENTS.md: GPU proofs may run hidden; only the headless CPU backend is out
e950b08 docs: app-remote — hidden GPU runs vs the simulated-GPU backend, measured grab cadence, remote hazards
9c94a77 arch: the platform plan names the simulated-GPU backend gpusim
3009257 micro_serde: serde_json-style JsonValue accessors, pretty printer, depth limit and strict parse
134cd76 gitignore: alternate target directories, root scratch dirs and stray logs are never source
60ba86e arch: the render node refs name platform/src/os/gpusim/mod.rs
1dc571a tools/arch_usb: Wi-Fi, Intel GPU firmware, the AI hub service and game-hardware udev rules on the Arch image; the WM session script picks the saved compositor GPU
cc3b05a tools/arch_usb: a polkit rule lets the arch account start, stop and restart the WM service
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 7 work commits (Sep 1–12):
f7093bf map_nav: the search db's positioned read builds on Windows
3c03397 geodata: a data library keeps its own clock — the GUI platform is not a dependency
64d2d3a map-build: an unfinished bake resumes or restarts itself, and the maps root does not depend on the cwd
cb572ae map-tiles: makepad-map-repack rewrites an archive to what the renderer reads
30fc13b map-tiles: repack runs on all cores, resumes per shard, reports --status
2db9d48 mkmap: a root record may decode to 512 MiB — the densest world shards list over five million tiles
e8be900 deps: drop osmpbf and serde_json from the root workspace
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 3 work commits (Sep 2–6):
5c40761 cef: the build script downloads its CEF distribution itself, on every host, with no shell
eec516e cef: a Windows backend — the browser's page renders on Windows
3dce90e Propagate browser appearance changes to Chromium page media
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 8 work commits (Sep 2–10):
7b9ed2c aichat: the assistant as an app — the panel owns the engine, the bus client, settings with the local-only lock
e0c6e74 aichat: the progress bar and system lines use the theme's highlight colour
8b46ce0 aichat: the composer's hint is a dark grey Ask AI, not the typed colour
b99a631 toml_parser, rust_tokenizer: rewrite both for the code analyser
3bbcea2 aichat: add Studio evaluation-feedback widget
b61845f studio: Architecture view, the third workspace mode
d7a76cf studio: add bounded code context and source APIs
524142a Split Studio into makepad director (public) and makepad scope (private)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* Event: trace cancel scopes, and gate StackNavigationView's Back on ownership
A scope held by a widget that has stopped being the active thing wedges
Escape and the back gesture for everything behind it, and the only symptom
is that the gesture silently stops working -- which is indistinguishable
from there being nothing to cancel. MAKEPAD_CANCEL_TRACE=1 now logs every
scope begun and ended, and which one each press was stamped to, each named
by the call site that began it.
That location comes from #[track_caller] on both Cx::begin_cancel_scope and
CxCancelScopes::begin: the attribute propagates through the chain, so
Location::caller() names the widget rather than either of makepad's own
frames. No signature changes, no caller passes anything new, and the
existing tests needed no edits. Releases are logged from Drop rather than
end(), so giving a scope up by dropping it -- including a widget being torn
down, the case most likely to leak -- is reported exactly once on either
route.
StackNavigationView called the consuming back_pressed() whenever it was
Active, with no ownership check. A modal or pane opened over a pushed stack
view owns that press, but the view could consume it first and pop: the
wrong thing acts and the owner is starved, on one gesture. It worked only
because children are dispatched before the closure request, which is
precedence by traversal order -- the thing cancel scopes exist to replace.
A pushed view genuinely is what Back should pop when nothing is in front,
so it now holds a scope while Active and acts only when it owns the press.
Its five state writes route through a single set_nav_state that moves the
state and the scope together, acquired at the transition because ownership
is stamped before dispatch. The left_button and mouse-back-button paths
stay ungated: those are unambiguous clicks on this view, matching Modal,
which gates only back_pressed().
* Fix Escape and Back ownership across widget lifecycles
Allow gesture-specific scopes, preserve held Escape ownership across Back and focus changes, and suppress repeated Android Back dispatch without invoking Activity fallback first.
Release popup, modal, drag, and navigation scopes on every exit; support suspended navigation, isolate Pop actions, and finalize wide-window hide animations. Add focused ownership and lifecycle regressions.
Validated with 14 platform cancellation tests, 14 widget cancellation tests, Android Rust and Java checks, and a release modal Escape smoke test.
* Resolve cancel ownership from the active widget hierarchy
Bind widget scopes to their owners and resolve visibility and descendant priority only when Escape or Back begins. Retained inactive pages, collapsed controls, and unfocused windows no longer require application activation callbacks.
Preserve press ownership through repeats and release, suppress scoped or repeated TextInput Escape actions, and remove the StackNavigation cancellation activation API. Cover hierarchy, container, wrapper, focus, and gesture ownership regressions.
* Simplify cancel traversal and remove unsafe root lookup
* Reuse validated widget paths for repeated activity queries
* Remove PR-added cancellation tests and tracing
* Arbitrate the mouse back button with cancel scopes
The mouse's back button is the same navigation gesture as Android Back, but it
never received a cancel owner: handle_event clears press_owner for every event
and only restores it for Escape and BackPressed. owns_cancel was therefore false
for every scope while a MouseUp was delivered, so a widget could not gate that
button on ownership at all. The ones that tried had to fall back on ad-hoc
conditions -- "is my tab the visible one" -- which cannot express the thing that
actually decides it, namely that something else is in front.
Stamp a Back press for Event::MouseUp with the back button: in
resolve_widget_owner so widget-bound scopes are resolved against the hierarchy,
and in handle_event so ownership is settled before dispatch, exactly as for the
gesture itself.
StackNavigationView's mouse-back path is gated on that ownership to match its
back_pressed(). A pane or modal opened over a pushed view now takes the first
click and the view stays put; the second pops it. The left_button path stays
ungated, being an explicit click on the view's own header rather than a gesture
something in front of it could have a better claim to.
* Close a Modal on the mouse's back button
The back button is the desktop equivalent of the back gesture, and is arbitrated
by the same cancel scope, but Modal acted only on Escape, BackPressed, and a
click on its backdrop. A back-click inside the content did nothing at all, and
one outside it closed the modal only incidentally, as a background click.
Gated on ownership like the other two, so a modal opened over another one keeps
its place, and left inside can_dismiss so a non-dismissible modal still ignores
it. This is what lets a full-screen modal's content -- an image viewer, say --
respond to the back button without handling the gesture itself.
* Fold Modal's Escape and mouse-back checks under one ownership test
Same behaviour with one ownership test instead of two, matching how the other
cancel-gesture handlers read. Back consumption stays outside can_dismiss, so a
non-dismissible modal still blocks back-navigation for the widgets behind it.
- bundle_crate_secondary_dex: merge OUT_DIR/classes.dex from dependency
build scripts (robius-sms/trigger/ussd javac+d8 Java for manifest
receivers/services) into the APK as classesN.dex. Without it the
manifest declares BootReceiver/SmsReceiver/AccessibilityService that
are missing at runtime (ClassNotFoundException on boot).
- has_explicit_lib_target: a crate with src/main.rs containing app_main!
is an app, not a lib — generate the android wrapper ([lib] path =
src/main.rs) so the JNI entry (activityOnCreate) is linked. Fixes
UnsatisfiedLinkError for app crates that also ship src/lib.rs.
Use cached transparent 2D and cube textures for unallocated optional samplers without bypassing invalid-resource, target, or framebuffer-feedback guards.
Require actual glyph draws in release smoke tests and keep shader compilation asynchronous in probe instrumentation.
Bound drawable, geometry, texture, image, map and radar work; validate WebGL submissions and retire GPU resources safely. Treat context loss as terminal without re-entering Wasm after worker termination.
Add explicit Route location consent and regression coverage, including software-WebGL release probes for six deployed demos.
The generated android wrapper re-creates a standalone workspace and only
forwarded [patch.*] sections from the workspace root manifest, so deps
declared via [workspace.dependencies] + workspace = true failed to inherit
in wrapped crate builds. Extract the [workspace.dependencies] section the
same way patches are handled and inject it into the wrapper manifest.
- makepad_test/runtime.rs: forward NIGIG_TEST_MODE from host env to the
Android app via 'am start' intent extra; add wait_timeout (60s) used by
wait_visible/wait_hidden/wait_count; make query_widgets tolerant of
snapshot timeouts; grant READ_CONTACTS during adb setup
- makepad-platform android_jni.rs: read makepad.NIGIG_TEST_MODE intent
extra and surface it as the NIGIG_TEST_MODE env var via apply_studio_env
- cargo_makepad compile.rs: support verbatim custom AndroidManifest.xml in
addition to the templated variant
- makepad-xr xr_root.rs: add ortho camera controls (ortho, ortho_height,
min/max), derive Debug on XrCamera
- docs: ANDROID.md and DESKTOP_VISIBLE.md for makepad_test
Adds the Android test runtime to makepad_test: builds the APK with
cargo-makepad's standard Java path, installs and launches via adb with
makepad.STUDIO_* intent extras (incl. STUDIO_BUILD), connects the app to an
in-process hub over adb reverse, and waits for startup + responsiveness.
Adds clean in-process hub shutdown (HttpServerHandle + GatewayHandle Drop)
and the STUDIO_BUILD intent parsing on the app side. No native-activity or
NDK APK compilation code is included.
Mac-side only: no in-place rewrite, no push, no fallback source. Shards are
written atomically and skipped on resume; root.mkidx lands once at the end.
Ranged --verify streams the output back. 16 jobs: 4.2 tiles/s on the
500-tile sample (REPACK2b lane).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A new binary in tools/map_tiles streams an .mkmap shard by shard into a
new archive: every tile's protobuf is decoded, the osm_* tag tables are
rewritten to the reader's key whitelist, the field-101 shadow sections are
stubbed (regions and building groups stay byte-identical), field 100 is
kept, and the tile is re-brotli'd with the archive's own codec and
dictionary; leaf directories and root.mkidx are rebuilt, output is
deterministic and resumable per shard with a sidecar manifest, --tiles
limits a run to a Hilbert range or a z/x/y list, --dry-run reports and
--verify decodes both archives and checks the policy. On the 25 Amsterdam
start-view tiles: 95.1 -> 47.6 MB decoded, 30.6 -> 16.7 MB compressed.
A label sort tie-break makes the bake byte-deterministic for the parity
test.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The browser could not build from a clean clone on Windows: the fetch
was a bash script needing python3 and tar. It is Rust in build.rs now:
the spotify index is read by a strict scanner, the newest stable
standard build for the platform is picked (or MAKEPAD_CEF_VERSION pins
one), the archive is downloaded to a .part file with its size and sha1
checked, extracted beside it, and a current-<platform>.txt pointer file
names the dist — read before the old symlink, so the Mac keeps its
pinned 138 while a fresh box gets the current build; a platform that
already has a dist is never bumped. MAKEPAD_CEF_OFFLINE refuses with the
dir and pointer named; MAKEPAD_CEF_DRY_RUN prints the plan (with
MAKEPAD_CEF_PLATFORM to resolve another host's). Build-time deps only:
ureq (rustls), bzip2 (bundled), tar, sha1_smol. The shell script is gone.
Proven on this Mac: a pinned re-download of the 138 macosarm64 archive
(255 MB, sha1 verified) differs in nothing from the existing dist over
1,193 files; dry runs for linux64 and windows64 pick the archives already
on disk; the browser checks with no download; the cef crate's build deps
compile for the windows-msvc and linux-gnu hosts. Picker and pointer
tests 5. An actual download on Windows or Linux is not yet run.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>