Squash of 38 work commits (Sep 2–6):
ed5b2fa web: wasm32 portability in libs and web startup geometry deferral
0ccd384 platform web: focus dispatch, window-zero geometry and generation-correct ids after the startup deferral
a7af3ea platform + mpfiles: platform clock instead of std::time on the web, unwind-safe event dispatch
52251b7 platform: a namespaced async key/value storage API on Cx — files natively, IndexedDB on the web
84b46c1 mbtile reader: file-backed readers are native-only so the map stack builds for wasm
6b661bf web: crashes report themselves — panic text, breadcrumbs, memory, workers; a dead instance stops pumping
372bfd7 asset-store: browser durability — generation extents over cx.storage, chunked CAS, quota and GC
0f967ce web path: the stream trace and the sqlite pager never wait on a clock the browser does not have
4e58ab9 vj: the output window exists only once opened — never on the web
93232a2 platform: two pool workers on wasm until the allocator is per-thread
c7fe851 vj: effect thumbnails render, encode and persist in browser storage on the web
5b33781 platform: thread-caching allocator for the threaded wasm build
463de64 web: shaders compile per draw list, link in parallel
e7be0e3 vj + platform: the browser UI thread never waits on a lock, and the web hot paths log only errors and summaries
7b33f7b vj + platform: a loaded deck actually plays on the web vj + platform: a loaded deck actually plays on the web
dc85eb0 web + vj: render-to-texture passes keep their 3D camera on WebGL, thumbnails wait for shader compile, bundled tiles re-ask — effect thumbnails match native
b39d301 web audio: the worklet links the whole module — every platform import the audio thread does not serve is stubbed, clocks and the UI wake are real
1e2dcd0 web: a pass without a draw list is skipped instead of taking the app down (F12 layers overlay)
0ef0311 web audio: a throw inside the worklet's process() is reported with its real text instead of a bare ErrorEvent
97e0701 vj + platform: the web audio thread never waits on a lock — a loaded deck plays
58d3fd5 web audio: the output is created inside the first gesture, and a stalled worklet module load is retried on a fresh context
410acd0 web + vj + route: the console carries failures and one-line summaries, nothing per request, per tile or per hiccup
a3248d1 web audio: the worklet gets the audio access pointer as its context — the thread-stack call gained a request id and the audio start was still passing the pointer in its place
9e2d65b pdf + photos + task + wm + video + automate + widgets: no per-job threads — pool jobs and start-up workers
639887d webgl: texture passes get their depth target — the tilted map (and every 3D scene drawn into a texture) was draw-order only: hollow buildings, no roofs, landmarks buried
2aa0780 webgl: BGRA uploads become RGBA at upload and sample_as_bgra is a plain sample on the web, as on every native backend — the tilt-shift's sharp band showed red/blue-swapped water
de9aba3 vj + web: the Layer button works on the web — a second Window is a queried capability (OsType::is_single_window; the web creates none and reports it once), so the output becomes an in-page full-canvas layer with browser fullscreen (Esc, the browser's own fullscreen exit, or a double-click leave it); a pass without a draw list settles its dirty flag instead of erroring every frame; exitFullscreen fixed; fullscreenchange feeds the window geometry
f615054 tweaker + webgl: click-to-climb continues only from the widget the climb started on, so a press on a sibling picks that sibling (the empty draw_bg was a bare View being pinned); the Shader tab says when a layer has no live draw call; the WebGL paint walk no longer resets every draw list's view_transform — the magnified material well drew at the window origin on the web
0d7ddee webgl: a uniform block is uploaded only when its generation moved — per draw call (uniforms_gen), per draw list (uniforms_gen, recording_gen), per pass (pass_uniforms_gen) and per shader scope block; the JS side caches (ptr, len, gen) per uniform buffer and re-records/recompiles reset it; direct camera writers (vj effects, render scene, the web flipped copy) bump the pass generation
e48b056 Revert "webgl: a uniform block is uploaded only when its generation moved — per draw call (uniforms_gen), per draw list (uniforms_gen, recording_gen), per pass (pass_uniforms_gen) and per shader scope block; the JS side caches (ptr, len, gen) per uniform buffer and re-records/recompiles reset it; direct camera writers (vj effects, render scene, the web flipped copy) bump the pass generation"
b043332 webgl: uniform blocks upload only when their generation moved — one global monotonic counter on Cx hands out every generation (draw call create/dirty/zbias, draw list allocate/transform/re-record, pass allocate/time/dpi/ortho/camera and the web flipped copy, shader scope writes), so a reused pool slot can never match a cached generation; clear_draw_items, pool reuse and VAO recreation reset the caches; the JS caches key on the generation alone. Proven on a local build: the pan screenshot keeps every tile, the settle tail drops 20.5 → 12.8 MiB/s
3c2530d web memory diet: the 805 MiB at load was the ocean-high archive's 13 M-entry leaf directory decoded to 407 MiB per lookup round and evicted at once — leaves now parse streaming into a window around the waiting tile ids (LeafParseLimits); a phone policy on the web (deviceMemory, UA, touch + short side) caps wasm at 512 MiB with a 320 MiB budget; archive leaf/range caches, reads and bakes in flight follow the budget; packed tile bytes stay packed until the bake decodes them; terrain scratch sized to the viewport and dropped with the layer; Cx::memory_report by owner. Phone viewport 1334 → 308 MiB after a minute of pans, desktop 1208 → 588
303458d webgl: a 2D texture pass builds its camera through set_ortho_matrix like every other backend, so the exploded z-layer view's camera reaches the GPU — the hand-built ortho branch uploaded an identity view and clipped every exploded draw, leaving the tweaker's layers view a bare window on the web; the Y flip for render-to-texture is one helper shared with the keep-camera branch
1801e38 Harden web renderer and make Route location opt-in
09fa1f0 Restore WebGL text with complete fallback samplers
9e61553 Keep Route 3D buildings under bounded web memory pressure
b005c6e Preserve complete Route geometry within measured web memory budgets
0832b35 platform: support float GI targets and retained mesh snapshots
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 10 work commits (Sep 2–11):
120b7e2 score view: the engraver as a shared library, with drum and pitched score builders
09b41a8 fonts: FontSet and FontPolicy — one application choice, selected-only loading, a font-assets manifest
6981e90 fonts: manifest generated from the chains, app-level font assets, a symbol fallback, deprecated i18n aliases
77d9138 wm: the module contract and the first in-process app — sheets in a tile, in an isolate of its own
55a3810 platform: typed compact vertex formats and u16 indices
83a8d4f fonts: the web demos start with the Latin set — CJK and emoji faces load on the first glyph that needs them
1980c24 platform: a draw call whose geometry id went stale is skipped, not drawn with whatever mesh now sits in the reused slot — the runaway triangle count that took a web map pan to 1 fps; reported with a power-of-ten backoff, never per frame
a75fe91 layout: extend turtle sizing and add Grid
4429551 draw, widgets: text clips by the list clip; GaussChain; map colour roles
6e02468 draw: restore Cx2d::set_current_pass_dpi_factor (raster density) beside the display-dpi setter
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Squash of 36 work commits (Sep 1–12):
176433a tweaker: click-again climbs the pick — the container under the children is reachable
97e9572 speech: one STT/TTS API on every platform, through the ai-hub
8ea3684 widgets: EventOrder reachable from the DSL; DataGrid hit-tests where it was drawn
0fd1ea2 route: demo profile — native/demo features, side-panel and provisioning seams, hosted tiles, HTTP nav client
cf4c84c keys: F10 is the assistant — the exploded-view debugger moves to Shift+F10, the screen recorder to Ctrl+F10
126d8c9 route: the demo profile runs in the browser — merged panel draw, platform clock, unavailable backends tolerated
e21db96 route: demo review fixes — route origin, rain lifecycle, hosted route validation, request context, provisioning
c24c206 aichat: the Window overlay — F10 in every standalone app, the in-process port, the /ai bridge routes, sheets as the pilot
dbe43bd wm + widgets: the AI panel on the left, pushing the body in
5184340 platform + vj + map + files + widgets + image_tiles: the runtime owns one warm two-lane task pool — jobs never spawn threads
697215e route + converse + example-map: every worker comes from the runtime pool or a start-up worker
862f3bd asset widgets + chat ui + render: fan-outs and jobs on the runtime pool, the transcript read without a lock on draw
976ea0e tweaker: Shift+F10 toggles it on every platform (KeyEvent::is_tweaker_toggle, one call site; the web page swallows exactly Shift+F10 so the browser never sees it); the exploded z-layer view has no keyboard shortcut any more — it is a button in the tweaker
4e8e4cd flow-ui: the design pass — menu bar and toolbar with the total run bar, continuous zoom through the draw-list view transform with pointer remapping, dark checker canvas with grid steps, shadowed cards with icon labels and port icons, glowing wires, per-node progress bars, full-bleed image cards, palette cards you drag out, the fab edit controls in the inspector, a template picker behind New, model pickers from the hub; MenuBar widget in the shared crate
075e1a7 flow-ui: pickers filled from the hub for image and text nodes, popups anchored through the canvas transform, labelled face controls, add_style explains itself, cards resize from a grip with size: vec2 kept in the file, full-bleed pictures, a click anywhere on a card selects it and still reaches the face, no remount on layout-only edits, panels float over the canvas
a50750f flow-ui: Flows, Running and Palette as their own rounded panels with splitters, the inspector and source pane likewise, columns resizable; gaussian frame shadows; keys and IME reach the focused face field through the canvas transform
43302a6 flow-ui: every card owns a draw list and draws in z order, selection brings it to the front; and the design review's findings — every event kind remapped through the camera, run events keyed by run id, no remount mid-run, an input journal that survives a failed PUT, terminal states reconciled, the total bar from the planned node set, isolate ownership on instance change, popups retired before an isolate is freed, the Ask face answers on a button, the menu bar navigates by keyboard, no per-frame allocation in the canvas draw
4ee4f4c flow-ui: the resize path sets walks and fits through typed setters, never a script apply from the main VM on an isolate's widget — a failed apply had left a freed script object behind and wedged every frame; a resized card fills its picture box, clips its face and lets the last flexible element take the height
cff15ac widgets: a fab number field drops a label that cannot fit instead of crushing it to a dot
24c927a flow-ui + widgets: every dropdown is the searchable ComboBox
a6c5f15 widgets: FabValueInput honours visible, so the seed picker's random mode hides the number field
1181a3b flow + flow-ui + widgets: every creator pipeline is a template — 55 templates in six groups (Image, Video, Audio, 3D, Vision & text, Utilities), all evaluated and engine-exercised in tests; the New picker, the flows.templates tool and the palette group the same way; the Templates menu shows them under group headings, and a menu taller than the window scrolls
f8b9a67 widgets: preserve numeric edit completion and menu focus
ed5f2e2 Add hotloadable OS themes and preserve widget state across style changes
f1d3b39 Center resized app recordings on a fixed black canvas
915fcae Remove icon rim highlights and align compact home tile contents
bfa7805 Keep terminal palettes theme-aware and resize above mobile keyboards
7535ce8 Fix workspace build regressions (#1220)
2233cbc Replace legacy Studio with docked and canvas agent workspace
708aa9f code_editor: range views, anchors, prepared documents, read-only, tab stops
0eae276 widgets: capture Studio evaluation feedback and recordings
487c602 widgets: let Studio pump dock bodies across presentations
c5adb93 Studio code atlas: settle-line diagnostics, index progress, chrome fades, exact search budget
ee9ab46 widgets: every screen capture lands in the repo's local/screencap, named by app
dcc9673 draw, widgets: the phone shell's glass, hosted-view and overlay support, app icons for the new apps
2fbc679 wm: preserve app caption controls and add Scope to the launcher
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* Event: trace cancel scopes, and gate StackNavigationView's Back on ownership
A scope held by a widget that has stopped being the active thing wedges
Escape and the back gesture for everything behind it, and the only symptom
is that the gesture silently stops working -- which is indistinguishable
from there being nothing to cancel. MAKEPAD_CANCEL_TRACE=1 now logs every
scope begun and ended, and which one each press was stamped to, each named
by the call site that began it.
That location comes from #[track_caller] on both Cx::begin_cancel_scope and
CxCancelScopes::begin: the attribute propagates through the chain, so
Location::caller() names the widget rather than either of makepad's own
frames. No signature changes, no caller passes anything new, and the
existing tests needed no edits. Releases are logged from Drop rather than
end(), so giving a scope up by dropping it -- including a widget being torn
down, the case most likely to leak -- is reported exactly once on either
route.
StackNavigationView called the consuming back_pressed() whenever it was
Active, with no ownership check. A modal or pane opened over a pushed stack
view owns that press, but the view could consume it first and pop: the
wrong thing acts and the owner is starved, on one gesture. It worked only
because children are dispatched before the closure request, which is
precedence by traversal order -- the thing cancel scopes exist to replace.
A pushed view genuinely is what Back should pop when nothing is in front,
so it now holds a scope while Active and acts only when it owns the press.
Its five state writes route through a single set_nav_state that moves the
state and the scope together, acquired at the transition because ownership
is stamped before dispatch. The left_button and mouse-back-button paths
stay ungated: those are unambiguous clicks on this view, matching Modal,
which gates only back_pressed().
* Fix Escape and Back ownership across widget lifecycles
Allow gesture-specific scopes, preserve held Escape ownership across Back and focus changes, and suppress repeated Android Back dispatch without invoking Activity fallback first.
Release popup, modal, drag, and navigation scopes on every exit; support suspended navigation, isolate Pop actions, and finalize wide-window hide animations. Add focused ownership and lifecycle regressions.
Validated with 14 platform cancellation tests, 14 widget cancellation tests, Android Rust and Java checks, and a release modal Escape smoke test.
* Resolve cancel ownership from the active widget hierarchy
Bind widget scopes to their owners and resolve visibility and descendant priority only when Escape or Back begins. Retained inactive pages, collapsed controls, and unfocused windows no longer require application activation callbacks.
Preserve press ownership through repeats and release, suppress scoped or repeated TextInput Escape actions, and remove the StackNavigation cancellation activation API. Cover hierarchy, container, wrapper, focus, and gesture ownership regressions.
* Simplify cancel traversal and remove unsafe root lookup
* Reuse validated widget paths for repeated activity queries
* Remove PR-added cancellation tests and tracing
* Arbitrate the mouse back button with cancel scopes
The mouse's back button is the same navigation gesture as Android Back, but it
never received a cancel owner: handle_event clears press_owner for every event
and only restores it for Escape and BackPressed. owns_cancel was therefore false
for every scope while a MouseUp was delivered, so a widget could not gate that
button on ownership at all. The ones that tried had to fall back on ad-hoc
conditions -- "is my tab the visible one" -- which cannot express the thing that
actually decides it, namely that something else is in front.
Stamp a Back press for Event::MouseUp with the back button: in
resolve_widget_owner so widget-bound scopes are resolved against the hierarchy,
and in handle_event so ownership is settled before dispatch, exactly as for the
gesture itself.
StackNavigationView's mouse-back path is gated on that ownership to match its
back_pressed(). A pane or modal opened over a pushed view now takes the first
click and the view stays put; the second pops it. The left_button path stays
ungated, being an explicit click on the view's own header rather than a gesture
something in front of it could have a better claim to.
* Close a Modal on the mouse's back button
The back button is the desktop equivalent of the back gesture, and is arbitrated
by the same cancel scope, but Modal acted only on Escape, BackPressed, and a
click on its backdrop. A back-click inside the content did nothing at all, and
one outside it closed the modal only incidentally, as a background click.
Gated on ownership like the other two, so a modal opened over another one keeps
its place, and left inside can_dismiss so a non-dismissible modal still ignores
it. This is what lets a full-screen modal's content -- an image viewer, say --
respond to the back button without handling the gesture itself.
* Fold Modal's Escape and mouse-back checks under one ownership test
Same behaviour with one ownership test instead of two, matching how the other
cancel-gesture handlers read. Back consumption stays outside can_dismiss, so a
non-dismissible modal still blocks back-navigation for the widgets behind it.
* Event: let the foreground widget own a cancel gesture
Several widgets act on Escape, and today more than one can act on a single
press: a modal closes and background dictation stops; a popup closes and the
microphone keeps recording. Dispatch order cannot arbitrate this. Siblings are
handled in reverse declaration order, a parent runs before its children, and
declaration order doubles as the z-order knob, so dispatch order is not
foreground order and cannot be made into it.
Add a stack of cancel scopes on Cx. A widget begins a scope when it becomes the
active thing -- a modal opens, a drag starts, a dictation session begins -- and
ends it when it stops being; the most recently begun live scope is in front. On
a fresh Escape key-down or a back gesture, call_event_handler records which
scope is in front, and that scope owns the whole press, its repeats and its
release included. A widget asks owns_cancel() and acts only if the press is its
own, so exclusivity needs no consumption primitive: only one scope is in front.
A scope that ends part-way through a press does not hand the rest of it to
whatever was behind, so an Escape that stops dictation cannot also close the
modal it was running in front of. Dropping a scope gives it up, so a widget torn
down without a tidy close cannot wedge the key for everything behind it.
Nothing changes for a widget that never begins a scope, so adoption is
incremental.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Widgets: adopt cancel scopes for Escape and the back gesture
Every widget that treats Escape or the back gesture as "cancel" now holds
a CancelScope while it is active, and acts on a press only when it owns
it. Foreground order decides who cancels, not dispatch order: a modal
opened in front of another modal takes the press, and nothing behind it
acts on the same one.
Widgets whose active state can end by several routes reconcile their
scope from that state on each event rather than trusting a single close
path. That also fixes the tweaker holding its drag state open after the
panel is toggled off with F12.
* Fix cancel-scope timing and Back gesture ownership
Acquire drag and color-popup scopes at activation and release them on each exit path, before the next cancel event chooses its owner. Gate Back consumption on scope ownership across modals and their popup/drag controls; non-dismissible foreground modals consume Back without closing.
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Admin <info@makepad.nl>
draw_scroll_bar passes the inner rect to ScrollBar, which places the bar
at `view_rect.size.x - bar_size` relative to the turtle's outer origin.
The bar therefore lands a right padding short of the edge, covering the
last few pixels of every wrapped line, and moves further into the text
the wider that padding is.
Draw it along the input's right edge instead, inside the padding. A text
input's visible area is not the area its bar runs along, so ScrollBar
gains draw_scroll_bar_along, which takes the track separately from the
visible size; draw_scroll_bar now delegates to it and every existing
caller keeps its geometry. TextInput also gains scroll_bar_inset, so an
app can keep the bar clear of anything it overlays on the input.
Sync the view total into the bar before the scroll position too:
clamping the position against the previous content height left the
handle a frame behind whenever the text grew and scrolled.
* Html: keep collapsed details with void tags from swallowing table closures
* Html: harden the parser, the walker and the widget against malformed input
Follows the void-tag fix in the `<details>` skip loop by auditing the rest of
the HTML code for the same class of defect. Robrix renders `formatted_body`
straight from Matrix events, so every parser crash here is reachable from a
message any stranger can send.
Crashes, all reachable from a chat message:
- Numeric character references were parsed as `i64` and cast to `u32`, then
handed to `char::from_u32(..).unwrap()`. `�`, `�`, `&#-1;`
and `�` aborted the process. They are validated now, and a
reference that names no scalar value stays literal text.
- An unterminated `&` stayed pending across a tag boundary or a closing
attribute quote, so a later `;` could fire `decoded.truncate()` and
retroactively invalidate byte ranges of nodes already emitted —
`<p>&am<b>p;</b></p>` produced out-of-bounds and mid-character ranges.
The pending entity is dropped at each of those boundaries.
- An unquoted attribute value beginning with a multi-byte character recorded
`decoded.len() - 1` as its start, splitting the character.
- `</summary>` with no `<summary>` popped an empty tracker stack, and stray
`</td>`, `</tr>`, `</li>` and friends reached `cx.end_turtle()` with nothing
to end. The widget now tracks what it opened and ignores unmatched closes.
- `('A' as u8 + count as u8 - 1)` overflowed on an attacker-controlled `start`
or `value`; alphabetic list markers now number a..z, aa, ab, ...
Content silently lost or mangled:
- `jump_to_close` counted every open tag toward depth, but a void element
written without a slash emits no close tag, so it overshot and swallowed the
rest of the document. `<a href=u>x<br>y</a>` hid everything after the link.
Only tags with the same id affect depth now, and an element with no close tag
leaves the walker where it is. `mod_html::find_close_tag` had it too.
- A `<` that cannot start a tag is literal text, the way a browser reads it.
`5<10 and 6<12` used to parse `<10` as an element and drop the rest.
- `?` mid-tag-name and `<!-->` / `<!--->` ran to end of input.
- `/` in an unquoted value ended it, truncating `href=http://host/path` at the
first slash; only a slash immediately before `>` closes the tag now.
- `<a href=>text</a>` took `>` as the value's first character, so the tag never
closed and its content leaked out as text.
- Unquoted values never decoded entities at all, unlike quoted ones.
- `<pre>`/`<code>` whitespace preservation was a single flag that any nested
tag cancelled, so a syntax-highlighted code block lost its indentation. It is
a depth counter now.
- HTML's whitespace set is five ASCII characters, not Unicode's;
`char::is_whitespace` collapsed ` ` runs and ate the full-width spaces
in CJK text.
- `find_text` returned the zero-length node the parser emits before every tag,
so `<a href=x><b>label</b></a>` rendered an empty link. `find_tag_text`
matched the case-sensitive id and missed any tag carrying an attribute.
- Duplicate `id` attributes bound two elements to one cached sub-widget, so a
second link could render its own text over the first link's href.
- `<li>a<li>b` and `<td>a<td>b` now implicitly close the previous item, and
anything a document leaves open is unwound before `TextFlow::end`.
Entity table, which had been generated by folding names case-insensitively:
- 146 names took their case-twin's code point. `é` rendered `É`,
`α` rendered `Α`, `→` rendered `⇒`, `𝕔` rendered `ℂ`.
- `Igrave`/`Icirc`/`Iuml` had been transcribed as `Lgrave`/`Lcirc`/`Luml`, and
`Iacute` was missing outright; the invented l-spellings are removed.
- `permil` mapped to the Windows-1252 byte 0x89 rather than U+2030, and an
empty-string key sat where it belonged, so `&;` decoded to `‰`.
- `tilde`, `lang` and `rang` were wrong.
The ALL-CAPS aliases the table also carries are left as they were.
Also: dropped the `unwrap` in `ElementSelfClose`, memoised table column counts
(quadratic in the number of `<table>` tags), and replaced the backward node
scan on every tag close with the depth counter.
Adds 18 tests covering each of the above. Verified by exhaustive enumeration of
all 12.2M inputs up to length 6 over a markup-heavy alphabet, and 6M randomized
structured cases, both checking that no input panics and that every node's byte
range is ordered, in bounds, on a character boundary, non-overlapping, and
agrees with its `all_ws` flag.
* Html: recover from malformed tags without leaking them into the text
A second pass over the same code, after the first round of fixes changed what
the edge cases look like.
- `</` followed by something that cannot name an element is literal text, the
rule `<` already follows. `i </3 u` used to emit a close tag named `3` and
drop the rest of the line.
- Junk inside a tag is discarded up to its `>` rather than resuming text in the
middle of it, which leaked the tag's own `>` into the output: `a</p x>b` and
`a<br/x>b` rendered `>b`.
- A custom widget with no close tag of its own is void, so it has no text.
Reading ahead picked up the *following* sibling's text, and now that
`jump_to_close` correctly stays put, the main loop drew that text a second
time: `<img src=x>caption` showed `caption` twice.
- `table_columns_cache` is keyed by node index, so it has to be cleared per
draw or a recycled widget lays a table out with a previous document's column
count.
- `<ol start="2147483647">` overflowed the item counter.
* Html: bound jump_to_close's scan and cut the measured hot spots
Benchmarked against the branch point (best-of-7, black_box'd, release).
- `jump_to_close` stops at the first close tag belonging to an enclosing
element instead of reading to the end of the node vector. It tracks the
elements opened inside this one so a descendant's close tag is still
matched correctly, and allocates nothing for the common case of an element
whose content is plain text.
- Numeric character references were compared against all ~1500 named-entity
arms before reaching the catch-all. Dispatching on the leading `#` first
makes them 2.9x faster (991us -> 342us for 3000 references).
- `process_entity` is `#[inline]`; it is called once per character.
- `decoded` is reserved up front, worth ~4% on text-heavy input. `nodes`
deliberately is not: its length tracks tag count rather than byte count, and
sizing it from `body.len()` cost a tag-sparse document a large pointless
allocation — that made the numeric-entity case 3x *slower* before it was
measured and removed.
- The widget rejects an unmatched close tag from a tally instead of scanning
the whole open-element stack, which was quadratic on a message combining
deep nesting with stray close tags.
- `align_keyword_to_x` compares in place rather than lowercasing into a fresh
String for every aligned cell on every draw.
Tag-heavy parsing is ~2-3% slower than the branch point, which is the standing
cost of the `<pre>` depth tracking, the literal-`<` guard and the entity state
carried across characters. Plain text is ~4% faster.
* Html: follow the tokenizer's recovery rules and resolve element ends at parse time
The parser's states now mirror the WHATWG tokenizer's, so malformed input
produces the tokens a browser would build from it rather than a guess:
- `</` followed by anything but a letter opens a bogus comment that runs to
the next `>`, `</>` is dropped, and `<?...>` is a bogus comment too. `<`
or `</` at the very end of input is text.
- `<a/b>` reads as `<a b>`: the slash was not a self-closing marker, so no
close tag is synthesized. `<x/>` still emits one — the SVG parser is built
on this walker and XML needs it — which is the one deliberate departure.
- In an unquoted attribute value a `/` is just another character, so
`href=http://host/path` keeps its path and `<img src=x/>` is `src="x/"`.
- `<!--x--!>` closes a comment, `<!-x>` is a bogus comment, and a tag cut
off by the end of input is dropped whole.
- Numeric character references follow the tokenizer's end state: zero, a
surrogate, or anything past U+10FFFF becomes U+FFFD, and the C1 range is
read as Windows-1252, so `—` is an em dash as legacy content intends.
Digits are accumulated with saturation so a forty-digit reference lands on
U+FFFD rather than an error. A decoded space collapses like a literal one.
- `<pre>`/`<code>` are tracked as a stack: a stray `</code>` cannot cancel an
enclosing `<pre>`, and `</pre>` closes a `<code>` left open inside it.
Every element's end is now resolved once at parse time (`HtmlDoc::closes`),
with the recovery a browser applies: a close tag ends the innermost open
element of its name and everything still open inside it, and a close tag
that matches nothing is ignored. `jump_to_close` and the new
`HtmlWalker::close_index` are lookups, which removes the last quadratic
case — a paragraph of thousands of `<img>` tags cost 3.4ms a frame — and a
stray `</span>` no longer stops a link's `</a>` from being found. The tally
that rejects stray close tags hashes `LiveId` through an identity hasher,
since it is already a 64-bit hash; with SipHash the pass cost 20%.
Widget:
- A `<summary>` left open is closed by `</details>` or the end of the
document, so its bold run and glyph tracker no longer leak into everything
drawn after it.
- Implicit closes follow the tree builder's scope rules — `<li>` closes an
open item up to its list, a cell up to its row, a row with its cells, a
heading directly following a heading, and any block element an open `<p>`
— rather than only the innermost element.
- A custom widget's label is all the text inside it, so
`<a href=x><b>Click</b> me</a>` reads "Click me", and a void one has none.
- Sub-widgets are keyed only by node index. Keying by the `id` attribute let
a document choose cache keys, and a repeated id bound two links to one
widget.
- `TrimWhitespaceInText`, `combine_spaces` and `ignore_newlines` are gone:
all three were written at every site and read at none.
- List markers are borrowed rather than allocated per item per draw, table
cell alignment compares in place, and link hit-testing no longer clones
its area list on every event.
Script module: `.html` printed raw hex for every tag and attribute name,
because the document was parsed without interning; it is interned now and
text and attribute values are escaped on the way out, so the output parses
back to the same document. `find_elements` counted every open tag toward
depth, the void-element bug again; it steps by resolved close index.
23 parser tests, exhaustive enumeration of all inputs up to length 6 over a
markup-heavy alphabet, and 6M randomized structured cases, checking that no
input panics and that every node range and close index is consistent.
* Html: resolve every element's end in the tokenizer, and close the review's findings
An adversarial review of the previous commit against the WHATWG tokenizer,
the branch point and a reference parser found the gaps below. All fixed.
The parser now keeps the open-element stack as tags stream past, so each
element's end is resolved in the same pass that tokenizes it — the recovery a
browser's tree builder applies: a close tag ends the innermost open element
of its name and everything still open inside it; a close tag that matches
nothing is ignored; the spec's void elements are whole at their open tag;
what is still open at end of input ends there. `HtmlDoc` records both the
element's own close tag (`close_index`) and where it ends (`end_index`).
That distinction was missing: an element ended by an ancestor looked the
same as a void one, so the script module gave `<li>a<li>b` items empty
ranges — no `.text`, no `.html`, children promoted to siblings — and the
widget dropped the label of a link ended by `</td>`. Both read correctly now.
Because the whitespace-preserving stack is the same stack, a `<pre>` ended
by an enclosing element's close tag stops preserving at that tag, which it
did not before.
Tokenizer fixes, each per the spec's state machine:
- `<!>` and `<!->` are complete bogus comments; they used to swallow text up
to the next `>`.
- A numeric character reference ends at the first non-digit whether or not
`;` follows (`& b` reads `& b`), and has no length limit: forty digits
saturate to U+FFFD as the previous commit claimed but did not do.
- An end tag followed by junk and then end of input is dropped like any
other tag cut off there; it used to emit its close tag anyway.
- `\r\n` and lone `\r` become `\n`, as the input stream preprocessing says.
- A repeated attribute name on one tag is dropped, so a consumer iterating
attributes sees the first `data-mx-color` rather than the last.
- A comment is not content, so `a <!-- c --> b` collapses to one space.
- `find_tag_text` answers for the first matching element and does not fall
through to a later one.
The maps that reject stray close tags and duplicate attributes are keyed
with a per-parse random seed and a multiply-fold hash: the previous identity
hasher let crafted tag names collide and made the pass quadratic, and the
standard SipHash cost a quarter of the parse time.
Widget:
- A `<summary>` is tied to the `<details>` that owns it. A `<details>` opened
inside a summary was taken for the owner, and `</details>` then popped an
empty tracker stack — a panic reachable from a chat message.
- `</summary>` and `</details>` end whatever was opened inside them, so an
`<li>` or a table cell opened in a summary no longer swallows the content
that follows.
- A collapsed body is skipped to the element's resolved end, so a
`<details>` ended by an ancestor no longer hides everything after it.
- `count_table_columns` ends the first row at the next `<tr>` as well as
`</tr>`; a table written without `</tr>` had every column halved.
- The `<p>` rule runs before the heading rule, as the tree builder orders
them, so `<h1><p>a<h2>` no longer nests the second heading in the first.
Script module: ranges are `(open, end)` with an exclusive end; `parse_query`
no longer panics on `a]b[`.
30 parser tests, exhaustive enumeration of all inputs up to length 6 over a
markup-heavy alphabet, and 6M randomized structured cases, checking every
node range, every `close_index`/`end_index`, nesting consistency, and
determinism.
* Html: build the tree builder's implicit closes into the parser, and end every element where it says
Two verification rounds against the previous commit — a spec-conformance
review, a stack-based reference for element ends, a simulation of the widget's
draw loop over exhaustive and random tag soups, and a round-trip check of the
script module — found the gaps below. All fixed.
The parser now applies the tree builder's implicit closes as it builds the
element stack: a block start tag closes an open `<p>`; a heading closes a
heading that is the current node; `<li>` closes an open item up to its list,
`<dd>`/`<dt>` likewise; a cell closes an open cell up to its row; `<tr>` closes
a row and its cells; a table section closes section, row and cells; a second
`<a>` closes the first. Every consumer therefore sees the tree a browser
builds: `<li>a<li>b` is two items, `<a href=1>x<a href=2>y</a>` two links,
and `<li><a href=u>one<li>two` gives the first link the label "one" rather
than "onetwo". The widget's own copy of these rules is gone; it closes each
element at the index the parser resolved, before that node is handled, and
`<details>`/`<summary>` without a close tag of their own are ended the same
way. Two bugs that fell out of them being special:
- a `<details>` ended by an enclosing close tag stayed on the stack, a later
`<summary>` bound to it, and the collapse-skip resumed *behind* the walker.
One stale level drew the text twice; N of them re-walked the document 2^N
times — a 380-byte message hung the UI. A resume is now never behind the
walker, and no level is left behind to be claimed.
- a `<summary>` ended by an enclosing close tag never popped its bold run and
glyph tracker, which leaked into everything drawn after it.
Per-name depth stacks replace the per-name counts, so finding the innermost
open element of a name, or the outermost one above a scope boundary, is a
lookup; scanning the stack made a document of nested `<div>`s quadratic.
A tag with thousands of attributes no longer makes every later tag pay to
clear the attribute-name set. Every nesting shape measured is linear.
Tokenizer and tree builder, per the spec: `</br>` is read as `<br>`, so
`x</br>y` breaks the line; the newline immediately after `<pre>` is not
content; NUL is dropped from text and replaced in attribute values.
Widget: a table whose first row is empty is sized by the first row that has
cells rather than falling back to 100px columns.
Script module: `.html` always writes `=""` and doubles a newline that starts
a `<pre>`, so its output parses back to the same document; `.text` is the
decoded text verbatim, no longer inventing a space inside a word split by a
comment or an inline tag; a query on a selection searches inside it, as
`querySelectorAll` does; descendant steps skip ranges already scanned, which
made `b b` on deeply nested `<b>` quadratic; `parse_query`'s grammar is
documented as implemented.
Deliberately unchanged: the entity table's omissions (`€`, ...), named
references without `;`, and an unquoted attribute value ending in `/` before
`>` (per the tokenizer the slash is part of the value; XML requires quotes).
33 parser tests; exhaustive enumeration of all inputs up to length 6 over a
markup-heavy alphabet and 6M randomized structured cases, checking every node
range, every `close_index`/`end_index`, nesting consistency, attribute
dedupe and determinism.
* cargo-makepad: declare native speech recognition metadata
* cargo-makepad: make Apple plist customization opt-in
* cargo-makepad: use macOS tools for plist overlays
* TextInput: add replace_range for edits that aren't typing
Anything that writes into a text field without being the keyboard —
dictation, autocomplete, a paste button — had only set_text and
restore_state to work with. Both clear the undo history, neither emits
Changed, and both end an IME composition that the platform keyboard still
thinks is in progress, so the next commit from the keyboard lands on text
the widget no longer agrees about.
replace_range(range, text, UndoGroup) goes through the same edit path as
typing: the input filter applies (text it rejects outright is refused
rather than deleting the range), the edit lands in the undo history,
Changed is emitted, and the selection is carried across it (anything that
was inside the range ends up after the replacement). UndoGroup::Extend
joins consecutive external edits into one undo step, so every revision of
a dictated phrase undoes together, while any typing in between splits
them. The IME composition belongs to the keyboard: an edit beside it moves
it and pushes the new text to the platform, and an edit overlapping it is
refused with ReplaceRangeError::Composing. is_composing() lets callers
wait for it to clear, and force_new_edit_group is now reachable from the
ref as well.
Undo and redo now end a composition, since the text the IME was composing
is gone with the rewind; the widget used to keep pointing at it, which
also stalled its IME syncing until focus was lost.
* ios: report the keyboard's marked text as the IME composition
The UITextView bridge forwarded marked text (kana awaiting conversion and
the like) to the widget as plain text with no composition range, so
TextInput never knew the keyboard was mid-composition on iOS:
is_composing() stayed false, replace_range's Composing refusal never
engaged, and the widget's next push did a whole-text setText: that
detached the keyboard's composition from the buffer.
forward_state_to_makepad now reads markedTextRange and carries it through
full_state_sync, so the widget records it exactly as it does for Android.
When the widget pushes text while it still holds a composition (an edit
beside it through replace_range), set_ime_text writes the text around the
composition and marks the composed part again with setMarkedText: instead
of committing it.
* macos: complete the handshake with a development launcher
`cargo run` starts a bare executable, which macOS gives no bundle identity.
Microphone, speech and location prompts are then attributed to the terminal
or editor that spawned it, and denied outright when that process has no
matching usage description, so a permission-using app cannot be developed
with plain `cargo run` at all. The way around it is a cargo runner that
launches a real .app through LaunchServices.
Three things are then lost, because LaunchServices forks the process itself
and starts it in `/`: the runner never learns the app's pid, so it has
nothing to forward a Ctrl-C to; it cannot pass on the terminal's working
directory; and it never sees the app's exit code, so `cargo run` always
reports success. All three are only knowable in-process.
The macOS event loop now reports them through the directory named by
MAKEPAD_DEV_LAUNCH_DIR, adopting MAKEPAD_DEV_WORKING_DIR before any
resource is loaded. Apps launched any other way see neither variable and
do nothing, so this replaces the same handshake being hand-written in every
app's main() that wants to develop against a permission-gated API.
* button: honour grab_key_focus on press
Button's FingerDown handling took keyboard focus twice: once guarded by
grab_key_focus, and again unconditionally at the end of the arm. That
second call is `self.set_key_focus(cx)`, which resolves through
WidgetNode to `cx.set_key_focus(self.area())` — and the derived `area()`
comes from the `#[redraw] draw_bg` field, so it is exactly the call the
guard above it wraps.
The upshot was that `grab_key_focus: false` did nothing on press, and a
button that deliberately opts out of focus still pulled it away from
whatever held it. Robrix's dictation hit this: tapping the microphone took
focus off the composer, hiding the caret the transcript is inserted at and
dismissing the soft keyboard on mobile, so it had to hand focus back by
hand afterwards.
Dropping the unconditional call leaves behaviour identical wherever the
flag is true, which is its default and every use in this repository.
* cargo-makepad: declare native speech recognition metadata
* cargo-makepad: make Apple plist customization opt-in
* cargo-makepad: use macOS tools for plist overlays
* TextInput: add replace_range for edits that aren't typing
Anything that writes into a text field without being the keyboard —
dictation, autocomplete, a paste button — had only set_text and
restore_state to work with. Both clear the undo history, neither emits
Changed, and both end an IME composition that the platform keyboard still
thinks is in progress, so the next commit from the keyboard lands on text
the widget no longer agrees about.
replace_range(range, text, UndoGroup) goes through the same edit path as
typing: the input filter applies (text it rejects outright is refused
rather than deleting the range), the edit lands in the undo history,
Changed is emitted, and the selection is carried across it (anything that
was inside the range ends up after the replacement). UndoGroup::Extend
joins consecutive external edits into one undo step, so every revision of
a dictated phrase undoes together, while any typing in between splits
them. The IME composition belongs to the keyboard: an edit beside it moves
it and pushes the new text to the platform, and an edit overlapping it is
refused with ReplaceRangeError::Composing. is_composing() lets callers
wait for it to clear, and force_new_edit_group is now reachable from the
ref as well.
Undo and redo now end a composition, since the text the IME was composing
is gone with the rewind; the widget used to keep pointing at it, which
also stalled its IME syncing until focus was lost.
* ios: report the keyboard's marked text as the IME composition
The UITextView bridge forwarded marked text (kana awaiting conversion and
the like) to the widget as plain text with no composition range, so
TextInput never knew the keyboard was mid-composition on iOS:
is_composing() stayed false, replace_range's Composing refusal never
engaged, and the widget's next push did a whole-text setText: that
detached the keyboard's composition from the buffer.
forward_state_to_makepad now reads markedTextRange and carries it through
full_state_sync, so the widget records it exactly as it does for Android.
When the widget pushes text while it still holds a composition (an edit
beside it through replace_range), set_ime_text writes the text around the
composition and marks the composed part again with setMarkedText: instead
of committing it.
The fe5b75d92 merge took upstream's widget_async.rs and dropped the
wm isolate-entry API (IsolateEntry, enter_isolate, leave_isolate)
while lib.rs and apps/flow-ui + apps/wm still use it, breaking
makepad-widgets. Restored verbatim from 77d91385f; structs unchanged
so the code applies as-is. makepad-widgets, makepad-app-flow-ui and
makepad-wm all check clean.
Bound drawable, geometry, texture, image, map and radar work; validate WebGL submissions and retire GPU resources safely. Treat context loss as terminal without re-entering Wasm after worker termination.
Add explicit Route location consent and regression coverage, including software-WebGL release probes for six deployed demos.
Reintroduce apps/arcade and the ten game crates that were ripped out of
the fork (assets, audio, blocks, coedit, gen, net, pkg, render, script,
session), from makepad-internal/dev. Reconcile against the fork's layout:
- makepad-game-sim/math come from the fork's existing libs/sim + sim/math;
the copied internal libs/game/{sim,math} are dropped and the kept game
crates plus arcade point at ../../sim and ../../sim/math.
- arcade AI is rewritten off the removed makepad-ai agent API onto the
makepad-ai-hub headless ChatProvider worker (example/cad pattern):
AiWorker{send,cancel,poll}, ai_worker_loop driving
ClaudeApiChatProvider(ClaudeCli), AiWorkerEvent availability/delta/
done/error mapped into the chat feed and authoring land_edit, with
main.rs send_message/cancel_request/event-drain rebuilt around it.
- the game-script sandbox is adapted to the fork's jailed splash storage:
every isolate gets mod.fs = splash_storage jail; splaes splash_storage
set_root_for_heap is now public so the ScriptHost (or Splash) can grant
a per-game jail root. ENT font: build.rs/dispatch.rs entities fill new
fork sim Entity/Part fields via ..Default::default(); world_raycast now
borrows mutably and returns the material id.
cargo check -p makepad-arcade and the game + arcade test suites pass.
Find numeric completion actions reliably and restore menu focus using tracked areas. Handle touch dismissal and focus changes without leaving menus open.
Makepad windows on Wayland had no drop shadow, which on GNOME reads as
broken next to everything else on the desktop. Mutter implements no
server-side decoration protocol at all -- it advertises neither
zxdg_decoration_manager_v1 nor any KDE equivalent, and its shadow code
(MetaShadowFactory) lives in src/x11/ and isn't even in the
introspection surface. Every shadow on that desktop is drawn by the app
that owns the window.
So draw one, out of eight wl_subsurfaces hung outside the toplevel: four
corner tiles and four edge strips, backed by one memfd wl_shm pool and
sized with wp_viewport, with xdg_surface.set_window_geometry keeping them
out of the window's logical bounds. GTK instead oversizes its own surface
and paints the shadow into a transparent margin. Subsurfaces keep the GL
surface exactly window-sized, so the shadow costs no per-frame GPU fill,
and no margin ever crosses the platform/widget boundary -- which is the
entire class of off-by-a-margin bugs the other approach invites.
The profile is libadwaita 1.9's, computed rather than sampled. A
rectangle's Gaussian shadow is separable, so each box-shadow layer's 2-D
coverage is the product of two 1-D normal CDFs, and evaluating that for a
*square* rectangle is what makes the corners hug the window: sampling a
rounded window's shadow gives 14/255 where a square corner needs 44/255,
and fades the edge out over the last 20px before every corner. The
straight-edge profile this produces matches a capture of the real
libadwaita output to within 1/255, which is what the test pins. Corner
tiles reach 16px along each edge, far enough that they join the strips
bit-identically at any scale.
Resizing happens in the gutter, the way it does for every native app.
The shadow surfaces carry input regions whose union is the window rect
grown by 12px -- the same halo libadwaita gives its toplevels -- and each
piece maps to exactly one edge, so landing on a surface is the hit test.
Window controls no longer compete with the corner grabs for the pointer,
which is what let the close button swallow the top-right corner.
Server-side decorations are requested wherever a compositor offers them,
overridable per process with --wayland-decoration= or
MAKEPAD_WAYLAND_DECORATION, and fall back to the frame above. KWin and
wlroots grant them; GNOME cannot.
Alongside, the caption bar gains double-click-to-maximize, a right-click
window menu, resize cursors keyed off the wl_pointer.enter serial the
protocol actually asks for, and tiled/constrained edges that suppress the
grabs they cannot service -- degrading a corner to its free axis rather
than dropping it.
Finally, declare the toplevel's opaque region, under the same
`!transparent && backdrop == None` condition macOS already uses for its
layer's opaque flag. The buffer is ARGB8888, so without that promise a
compositor cannot learn the alpha is uniformly solid short of reading
every pixel: it must blend the whole window, cannot cull what the window
covers, and cannot scan a fullscreen buffer out directly.
Verified against a WAYLAND_DEBUG trace: over 67 committed frames the
shadow issues no protocol traffic at all, and set_window_geometry,
set_opaque_region and the nine wl_regions are each sent and destroyed
exactly once.
The picker's own label counts the ready nodes, so the GPU list under a
chosen model was clutter; it stays only for a model no node can serve,
where it names why. A closed ComboBox reset its text field to the tail of
the label after set_text; the cursor now sits at the start.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Model and format pickers, the inspector's one-of rows, the Ask face's
choice and face-declared pickers all render as ComboBox; the popup and
its input map through the canvas zoom. ComboBoxRef gains changed_label
and set_selected_by_label so the bindings did not have to change shape.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A 54 px width chip left the "w" label one pixel column, which rendered
as a stray dot beside the number.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* View: an on_item_tap hook for script-rendered lists
Rows built by `on_render` can't carry `on_click` closures (they stop the
list re-rendering), so lists had no way to be tappable.
* `on_item_tap: |index|` on the container fires with the direct child
under a tap
* Runs after the scroll bars with capture overload, so a press still
starts a drag scroll and a Button child keeps its own click
* View: on_item_tap hit-tests rows with clipped_rect, so scrolled lists map to the right row
* View: a press that catches a fling never counts as an item tap
* an isolate's widget prelude snapshots `mod.theme` at boot, which was always the default dark theme even under a light host, so default labels and pressed buttons went light-on-light
* `set_splash_theme(SplashTheme)` names the theme applied between `theme_mod` and `widgets_mod` for every new isolate
`call_script_fn` looked names up in the module body scope, but a
`let`/`fn` that shadows a name already in scope opens a child scope,
and everything the script defines after it lands there, invisible from
the module scope. The Splash prefix's own `let fs` / `let host` can be
that shadow, so app hooks never resolved.
* The VM records the scope a root frame ended in (`ScriptBody::end_scope`)
* Splash looks hooks up there, falling back to the module scope