Commit Graph

117 Commits

Author SHA1 Message Date
Chris Tate 8fc933b9db fix(windows): accelerate gpu surface presentation (#258)
* fix(windows): accelerate gpu surface presentation

- Render retained binary canvas packets through Direct2D and DirectWrite.
- Preserve dirty-region updates and GPU effects with a safe software fallback.
- Wire and validate the renderer across supported Windows build paths.

Co-authored-by: Omer Shatzberg <131801941+oshtz@users.noreply.github.com>

* fix(windows): harden Direct2D presentation

* fix(sdk): separate GPU backend request types

* fix(windows): honor GPU surface fallback contracts

* fix(windows): scale transformed blur kernels

* fix: harden Windows GPU surface presentation

* fix(windows): harden gpu blur and caption sampling

* fix(runtime): bypass packets for software surfaces

* fix(windows): preserve precise gpu surface updates

* fix(windows): reconcile GPU presenter state

* fix: preserve retained canvas resources

* fix: preserve Windows canvas packet fidelity

---------

Co-authored-by: Omer Shatzberg <131801941+oshtz@users.noreply.github.com>
2026-08-02 15:59:44 -05:00
Chris Tate 8600d7e5d5 fix: align Geist tabs with design system (#259)
* fix: align Geist tabs with design system

- Match Geist primary-tab sizing, spacing, icon treatment, and full-width rails while preserving default-theme pills.

- Add a scrollable component explorer with focused specimen views and a content-hugging default theme picker.

- Expand layout, rendering, semantics, interaction, and pixel-regression coverage for both themes.

* build: refresh docs WASM preview

- Recompile the checked-in component preview module against the updated Geist tab renderer.
- Verify the production docs build and live WASM scene instantiation.

* fix: extend Geist tab rails in flow layouts

- Let primary Geist tab lists claim available row and column width while preserving default-theme flex behavior.
- Add flow-layout regression coverage and refresh the docs WASM preview.

* docs: correct tabs markup example

- Compare the tab enum against quoted tag literals and show content for every tab.
- Use the cross-theme row and spacer composition for compact house tabs and full-width Geist rails.

* fix(canvas): correct tree, scroll, and tab layout

* fix(canvas): keep tree indentation author-owned

* fix(canvas): align Geist tab underlines with content

* fix(canvas): preserve wide Geist tab rails

* fix: preserve tab layout intent across themes

* fix(canvas): bound indented Geist tab rails

* fix: preserve Geist tab layout contracts
2026-08-02 12:22:58 -05:00
Chris Tate 19519dd5ea chore: prepare v0.7.1 (#247)
- Synchronize the CLI, core, platform, and example package versions.
- Merge pending changelog fragments into the marked v0.7.1 release notes.
- Credit release contributors and retire the v0.7.0 release markers.
2026-07-31 20:27:26 -05:00
Chris Tate 04b97cc2b7 feat: add native code editor example (#245)
* feat: add native code editor example

- Add an editable syntax-highlighted code surface with robust selection, large-file rendering, and expanded language coverage.
- Add the declarative Code Editor example with folder navigation, previews, permanent tabs, inline rename, save, and multi-window support.
- Extend tree interactions, macOS folder picking, component docs, tests, and live WASM previews.

* fix: address code editor review findings

* fix code editor large-file stability

* fix: harden large code editor state

* fix: polish code editor interactions

* fix: title empty code explorer windows

* fix: stabilize code editor rendering

* fix: harden code editor edge cases

* fix: address code editor review findings

* fix: resolve remaining code editor review findings

* fix: harden code editing and click handling

* fix: balance code editor tree spacing

* fix: load code editor folders on demand
2026-07-31 20:09:24 -05:00
Chris Tate ad6fa36f3e Compiled-core parity: fixture profiles declare and prove their integer slots (#241)
* test: declare i64 slots in the markup and host-fixture core profiles

- The shared wire codec, the markup adapter, and the markup frame channel prove decoded integer slots in place: bind the value, range-guard it with ordered comparisons, and state wholeness with Math.trunc at the write.
- Fixture counter bumps saturate at the i64 class's provable ceiling, ±(2^53 − 1), so range discharges.
- Model.pastBytes stays f64-classed: it holds 2^53 by design, past the provable window.

* test: declare i64 slots in the ai-chat core profile

- The text SDK gains one provable selection constructor: every editor-produced selection is range-guarded and stated whole with Math.trunc, keeping the proof local to the construction site.
- The ai-chat composer binds composition bounds and proves them at the write; -1 stays the no-composition sentinel.
- The chat_response status and nextId bumps prove in place with the same guard-and-trunc idiom.

* test: declare i64 slots in the system-monitor core profile

- Samples, probe results, and ps rows bind, range-guard, and Math.trunc their counts at each classed write; unprovable values keep the previous sample or skip the line like any other malformed row.
- The adapter proves dispatch values and classed helper returns in place with the same guard-and-trunc idiom.
- Structurally identical union arms lower to one record shape, so one code slot and one pid slot carry the class for their siblings (SC4009 keeps colliding declarations out).

* test: declare i64 slots in the soundboard core profile

- Catalog ids, playback clocks, and queue counters bind, range-guard, and Math.trunc at each classed write; the clock-tick cap comparison replaces Math.min so the proof stays in view.
- The adapter proves its ten classed helper returns in place with the same guard-and-trunc idiom.
- The id-carrying Msg arms share one lowered record shape with QueueEntry, which carries the class for all of them (SC4009 keeps colliding declarations out).

* test: carry i64-classed slots on the i64 wire encoding

- Snapshot, helper-result, record, and channel encoders write classed slots with wI64 (optionals via wOptionalI64), matching the contract each adapter now attests.
- Text-input decoding reads selection offsets and composition cursors as i64; selection offsets ride a saturating reader because select-all sends the maxInt to-the-end sentinel, which every consumer snaps to the text's length.
- Classed helper results route through their proven wrappers and encode with wI64.

* test: declare the coalesced arm slots and prove the decode ingress

- The ten same-shaped Msg arm slots join the soundboard and system-monitor profiles, so the declared set covers every provable reference slot and only the deliberate 2^53 boundary probe stays f64.
- Decode ingress proves in place where synthesized record slots carry write obligations: soundboard's id dispatches and audio clocks, and the shared composition-cursor decode, each range-guarded with wholeness stated by Math.trunc.
- The ai-chat and markup profiles drop a subscriptions_export naming a function their entry modules never exported; a dangling name refuses instead of resolving silently.

* test: preserve compiled-core numeric dispatch classes
2026-07-31 08:08:47 -05:00
Chris Tate 7636ec3686 chore: prepare v0.7.0 release (#239)
- Sync the CLI, core, examples, and platform packages to 0.7.0.
- Merge release notes and mark the v0.7.0 changelog entry.
2026-07-30 14:30:44 -05:00
Chris Tate bd3aab4b48 feat(canvas): add reusable code component (#235)
* feat(canvas): add reusable code component

- Add highlighted code surfaces with optional line numbers and horizontal scrolling.
- Route Markdown fences through Code while preserving indentation and first-line list alignment.
- Cover the markup API with tests, documentation, previews, and changelog fragments.

* fix(canvas): preserve multiline code rendering

* fix(canvas): bound code layout capacity

* fix(canvas): bound code span retention

* fix(canvas): address code component review feedback

* fix(canvas): polish code block rendering

* fix(canvas): address remaining code review feedback

* fix(canvas): preserve long code rendering

* fix(canvas): preserve numbered code selection

* fix(canvas): fold long span selections

* fix(canvas): preserve empty code and paged selection

* fix(canvas): address code rendering review findings

* fix(canvas): resolve remaining code review issues

* fix: bound transformed code rendering
2026-07-30 13:56:52 -05:00
Chris Tate c1bad63c5f chore: prepare v0.6.3 release (#233)
- Sync all CLI, core, platform, and example version references to 0.6.3.
- Merge the textarea fixes into the marked v0.6.3 changelog entry.
2026-07-29 13:45:49 -05:00
Chris Tate 3636af4b45 fix: improve textarea editing shortcuts (#231)
* fix: improve textarea editing shortcuts

- Align Command and vertical arrow navigation with native multiline behavior.
- Add bounded undo and redo while keeping controlled text buffers synchronized.
- Cover retained runtime and markdown-viewer editing paths.

* fix: harden textarea editing behavior

* fix: harden textarea editor lifetimes

* fix(canvas): harden textarea history and navigation

* fix textarea wrap navigation and macOS undo menu

* fix textarea navigation and history edge cases

* fix textarea reconciliation failure atomicity

* fix(runtime): make canvas text history replay transactional

* fix: preserve textarea indentation and shift-click selection

* fix: harden textarea navigation and selection

* fix: harden textarea caret boundaries

* fix: harden textarea history and CRLF editing

* fix(canvas): keep carets outside CRLF boundaries

* fix(core): keep CRLF edits atomic

* fix(canvas): preserve CRLF editing boundaries

* fix(canvas): match native selection navigation

* fix(runtime): reroute compound textarea history events

* fix(runtime): normalize reconciled CRLF selections

* fix textarea left navigation across soft wraps

* Fix IME history across CRLF boundaries
2026-07-29 13:06:47 -05:00
Chris Tate ef1f8d9cdd chore: prepare v0.6.2 release (#230)
- Bump CLI, core, and platform package versions to 0.6.2.
- Merge overlay and container background notes into the release changelog.
- Credit release contributors and rotate release markers.
2026-07-28 19:12:07 -05:00
Chris Tate a7509a7fa6 chore: prepare v0.6.1 release (#214)
- Sync CLI, core, platform, and example package versions to 0.6.1.
- Merge pending fixes into the marked v0.6.1 release notes and credit contributors.
2026-07-26 09:56:26 -05:00
Chris Tate ea98365a2d fix: sync pointer text selections to model (#213)
- Route pointer caret and selection changes through on-input.
- Cover workbench address deletion with an end-to-end regression.
- Update session replay expectations and changelog.
2026-07-26 01:33:26 -05:00
Chris Tate 514ce820da chore: prepare v0.6.0 release (#210)
- Sync CLI, core, platform, and example package versions to 0.6.0.
- Merge pending fragments into the marked v0.6.0 release notes.
- Credit release contributors and retire the v0.5.4 markers.
2026-07-25 14:55:29 -05:00
Chris Tate db34c23ea5 fix: sync webview focus with canvas panes (#209)
* fix: sync webview focus with canvas panes

- Report native webview focus changes across macOS, Linux, and Windows.
- Preserve and journal canvas focus state with a workbench pane regression.

* fix: sync CEF webview focus

- Report actual Chromium browser focus through the shared runtime event.
- Guard stale child generations and cover the CEF host seam.
2026-07-25 14:13:09 -05:00
Chris Tate daefe82106 fix terminal macOS shortcuts (#208)
* fix terminal macOS shortcuts

- Map Option/Cmd navigation and Cmd+Delete to shell-native sequences.

- Route Cmd+V through the bracketed-paste-aware terminal input path.

- Add runtime and example regressions for modified keys and paste.

* fix terminal key release handling on macOS
2026-07-25 13:18:51 -05:00
Chris Tate 4c3fb0bc30 fix: add terminal copy/paste context menu (#207)
* fix: add terminal copy/paste context menu

- Present standard Copy and Paste actions for terminal widgets.
- Route emulator selections to the clipboard and pasted text to PTY input.
- Add regression coverage and a changelog fragment.

* Fix terminal context menu paste handling
2026-07-25 12:09:40 -05:00
Chris Tate a43855001a fix: hide workbench terminal focus rule (#206)
* fix: hide workbench terminal focus rule

- Blend the full-bleed terminal focus ring into the pane while preserving autofocus.

- Pin the styling with a workbench regression and document the user-visible fix.

* fix: reflect terminal focus in cursor

* fix: complete terminal focus handling

* fix terminal cursor keyboard ownership

* fix: preserve terminal keyboard focus on Windows
2026-07-25 11:27:12 -05:00
Chris Tate a0947a227d fix: keep terminal Tab input in the PTY (#204)
* fix: keep terminal Tab input in the PTY

- Keep focus on active terminal components while routing Tab and Shift+Tab to the PTY.

- Prevent focus-entry keys from reaching the shell and add router plus live-session regressions.

* fix: preserve terminal Tab traversal boundaries

* docs: clarify terminal Tab gesture handling
2026-07-25 09:06:55 -05:00
Chris Tate beb1d8712a Compiled-core parity: every core fixture built externally and proven against the transpiler (#197)
* Add per-fixture compiled-core parity batteries and contract staging

- PairedCore lockstep module: a fixture's e2e battery runs over both lanes, byte-comparing commands, snapshots, subscriptions, channels, and helpers per cycle
- build.zig gains env-gated test-compiled-core-parity (per-fixture archive/sidecar pairs) and stage-core-contracts for external toolchains
- paired roots are generated from each transpiled module's own export surface, so channel detection never goes stale

* Compile the ai-chat core with an external toolchain and pass its battery

- adds a hand-authored adapter entry, core profile, shared wire codec, and a static restatement of the core module for library-mode compiles
- build_core.sh stages author sources with specifier resolution, readonly-array erasure, and byte-alias folding, then records cold and warm compile times
- ai-chat update always returns the [model, cmd] tuple and api.ts iterates bytes by index

* Compile the host fixture's core externally and pass its full battery

- hand-authored host-fixture adapter and profile: 53 arms, four record payloads, the boot command, and the model-gated timer subscription
- the fixture's update returns the [model, cmd] tuple on every arm
- staging drops any SDK type alias the author's own sources declare; the mirror conversion walk raises its comptime branch budget

* Corpus cores return the [model, cmd] pair on every update path

- soundboard and system-monitor update signatures drop the bare-model union arm; every return carries an explicit Cmd
- behavior is unchanged: the paths that produced no command now say Cmd.none

* Compile the soundboard core externally and pass its battery

- hand-authored soundboard adapter and profile: 19 arms, 35 model helpers, the chrome and env channels, and the frame/key channel ABI entries

- channel ABI entries take flat parameters and answer the contract's channel flags through their export suffixes, listed after the unconditional exports

- staging spells the SDK's event and text records as object-literal aliases so host-constructed channel arms carry value-stored records

* Compile the system-monitor core externally and pass its battery

- hand-authored system-monitor adapter and profile: 25 arms, 23 model helpers, the boot probe command, and the chrome channel

- the sample sorts are explicit stable insertion sorts and the byte scans index instead of iterating, both lanes over one source

* Compile the markup fixture's core externally and pass its battery

- Add the markup adapter, profile, and build_core.sh case: the corpus's
  first three-function-channel core (frame, key, and pinch).
- Add the markup compiled-core battery entry, the mirror image of the
  host one: the markup core pairs, the host fixture rides transpiler-only.
- Return the [model, cmd] pair on every markup update path so the
  contract's shape flags read from a declared return type.
2026-07-24 23:24:53 -05:00
Chris Tate 2209f022ee Live <terminal> sessions, and examples/workbench: a terminal beside a browser (#198)
* Bring libghostty-vt back behind a consumer-safe terminal_vt seam

- The framework module imports terminal_vt everywhere: a ghostty-vt wrapper where the dependency is safe to traverse, a stub (enabled=false) elsewhere
- Root builds resolve a lazy ghostty pin gated on being the build root, so consumers running this build script as a dependency never touch ghostty's graph
- Apps opt in via addAppArtifacts .ghostty_vt with their own pin; scaffolded builds keep the stub and stay free of harfbuzz/translate_c

* Live <terminal> sessions: the runtime-owned emulator behind a bound pty key

- terminal_session.zig: per-pty-key libghostty-vt sessions publishing resolved TerminalGrid snapshots, with the example tier's lossless outbound ring, query-answer write-back, key encoding, and theme-derived palette promoted into the runtime
- The effects engine grows a pty delivery tap (live drain and replay feed alike), so emulator state derives from exactly the journaled stream; outbound bytes ride the journaled ptyWrite verdict path
- The app loop installs the builder's terminal grid lookup, reconciles cols/rows from each element's laid-out frame into ptyResize, applies the scrollback source-wins echo, routes focused keys/IME text and wheel scrollback to the session, and dispatches on-terminal states

* Terminal session store tests: the element contract at the store seam

- Lookup-driven session creation, fed output as resolved cells, stdin-ordered write-back (keys, text, DSR answers), retained-ring flush, resize reconcile, scrollback source-wins, respawn reset, and wide-cell spacer backgrounds
- Fix the snapshot sizing multiply: @min against a comptime bound refines its result type, so the product needed explicit widening

* The terminal emulator is an app-owned pin, opted into per app

- Replace AppOptions.ghostty_vt with terminal_sessions: bool; the framework resolves the app's own lazy ghostty pin with the app module's target/optimize and the safe flags, so an app asks for live <terminal> sessions with one field instead of threading a module
- Drop the ghostty pin from this package's build.zig.zon: a pin here materializes into every consumer's package directory even when lazy and unused (measured 27 packages / 585 MB in a scaffolded app's package dir, now zero), so the toolkit's own builds always carry the terminal_vt stub
- Add src/terminal_session_tests_root.zig so an emulator-wired app build can run the session store's tests, which skip in this package's own suite

* examples/workbench: a live terminal beside a browser in one split

- Add the workbench example: a <split> with a <terminal pty={key}> pane and a browser pane (back, forward, reload, address bar), app-owned navigation history, and a hidden-inset titlebar with per-pane drag bands
- The app spawns a shell with fx.ptySpawn and binds the key in markup; no emulator wiring, key encoding, or grid plumbing lives in the app
- Register test-example-workbench, whose build also runs the runtime session store's tests since this build wires the emulator

* Document live terminal sessions and how a build opts in

- Terminal docs: the runtime owns the emulator behind a bound pty key, plus an "Enabling live sessions" section covering the app-owned lazy pin, terminal_sessions = true, and the terminal_sessions_enabled flag apps can gate tests on
- Add the changelog fragment for the live sessions, the opt-in emulator, and the workbench example

* Workbench: the shell owns the keyboard when the window opens

- Mark the terminal element autofocus, so typing lands in the live session without a click first — a terminal window's keyboard belongs to its shell

* Terminal runs measure the face they actually ink with

- Derive the cell width from a 16-glyph mono probe divided by its length — the advance a merged run walks — and leave it unrounded, so glyphs stay on the cells the painter's backgrounds, cursor, and selection draw from
- Carry the measurement seam on each run: a command's raster extent is its own declared bounds, and the estimator's 0.6 em mono pitch falls short of a wider host face (macOS resolves the mono id to the system monospaced face at 0.618 em when Geist Mono is absent), which sheared a full-width row's last cell to a two-pixel sliver
- Cover both with a painter test that paints a full-width row against a wide-pitch provider and asserts every run's bounds hold its ink

* Workbench README: what the divider drag does to focus

- `stty size` named as the visible proof that the pty re-grids with the pane

- the divider keeps the keyboard after a drag; clicking the terminal returns it
2026-07-24 23:17:56 -05:00
Chris Tate 3a188de6b7 Windows pty: ConPTY behind the shared transport seam (#193)
* Windows pty transport: ConPTY behind the shared seam

- pty_windows.zig: CreatePseudoConsole over an overlapped named-pipe pair, flags 0 (no inherit-cursor handshake), UTF-8/VT both directions per the pseudoconsole pipe contract; EOF manufactured by closing the console at the first quiet moment after the process handle signals
- pty.zig becomes the dispatch seam (one Pty shape, wait takes the transport); exit semantics are exit-code-only on Windows (signal always 0), kill is TerminateProcess plus console teardown, and handle-close discipline replaces the posix zombie table
- effects wiring: the io loop is unchanged, the env policy snapshots the live Windows environment through the same flatten seam, and the live suite gains ConPTY twins (containment assertions where conhost renders, byte-exact stays posix-gated)

* Terminal example: deterministic shell pick covers Windows

- cmd.exe joins the per-platform default-shell table (interactive by default, so the posix shells' -i rides a per-platform argv const)

* Docs: Windows pty moves from staged to supported

- platform matrix names the ConPTY backend and a Windows-semantics section states the differences plainly: exit codes only (signaled never occurs), rendered VT stream rather than raw child bytes, kill reach via console teardown, case-insensitive env names, no-CWD PATH resolution
- changelog fragment for the Windows transport; the terminal fragment stops calling Windows staged

* ConPTY: null std handles and an exit-quiet grace

- STARTF_USESTDHANDLES with null handles blocks CreateProcess's std-handle duplication from a console-less parent (sshd/CI pipes), so the child's stdio binds to the pseudoconsole instead of bypassing it
- the console close now waits out a 50ms quiet grace past the child's exit (short poll beat while it pends), so conhost's asynchronous final render is not cut off the frame it was painting
- transport tests: mode.com by full path (the minimal test env carries no PATH) and the quoting expectation pins the lone-backslash no-quote rule

* Fix the image-cache probe test's fake handle for Windows natives

- std.Io.File.Handle is pointer-shaped on Windows; the fake the noop close never dereferences now matches per platform, so the runtime-core test shard compiles on a Windows host

* ConPTY hardening: teardown reach, drain-before-close, env fidelity

- reapEnding now tears the console down on every path behind a bounded discard-drain, so a kill fells attached descendants at the reap (not a retire the host may never drain to) and ClosePseudoConsole can never meet the full pipe that wedges pre-rework conhosts
- State moves to process-lifetime backing (an abandoned io thread must outlive the caller's allocator), the exit quiet grace measures from the later of exit and last output, hidden =X:= drive-directory entries ride the env snapshot verbatim, and the no-PATH fallback derives the real Windows root
- docs state the 32767 console-geometry clamp, the Windows 10 1809 floor, and the direct-child session-lifetime policy (measured: the pipe never breaks on its own, so the manufactured EOF is the only ending)

* ConPTY: off-thread console close, batch-argument refusal, exact resolution

- ClosePseudoConsole moves to a detached helper so the reader thread keeps draining while conhost tears down (a client's CTRL_CLOSE handler can write past the pipe capacity; closing inline on the reader is the documented deadlock), and the teardown drain now runs behind the initiated close until EOF or its bound
- batch targets refuse argv bytes cmd.exe would reinterpret (a .cmd command line is reparsed by cmd's own grammar, which no CRT quoting neutralizes), extension probing appends suffixes only to extension-less names (a missing tool.cmd can never start a co-located tool.cmd.exe), and direct executables pass lpApplicationName so long paths start (batch keeps the null-application form that reroutes through cmd.exe)
- synchronous read completions stamp the exit quiet grace like event-delivered ones, and the environment block sorts names case-insensitively by code point through the OS BMP uppercase fold (raw WTF-8 bytes misorder folded non-ASCII names)

* ConPTY: safer failure-path closes, cmd-convention resolution, OS-order env block

- spawn-failure cleanup breaks the pipe before ClosePseudoConsole (a terminated child may have filled it; a blocked conhost would block the close), and the teardown drain runs quiet-first so the close's inline OOM fallback can only meet an emptied pipe
- extension-less names probe runnable suffixes before the bare spelling (a plain file named tool cannot mask tool.exe/tool.cmd), the probe's wide copy sizes to the candidate (long \\?\ PATH components resolve), direct executables keep the caller's argv[0] spelling in the command line (the module rides lpApplicationName), and a batch target's resolved path faces the same hostile-byte refusal as its arguments with plain space-guarding quotes (cmd reads backslashes literally, so CRT trailing-run doubling would corrupt them)
- the environment block sorts by uppercase-folded UTF-16 code units (surrogate halves order below private-use BMP, the OS's own comparison), pinned by test

* ConPTY: explicit cmd.exe for batch, deadlock-free close fallbacks, tighter quiet close

- batch targets launch through an explicitly resolved cmd.exe with /d /s /c (AutoRun cannot splice around the script), every batch argument is quoted (a bare closing parenthesis could join cmd's block grammar), and the refusal policy is stated in the docs
- the console-close fallback breaks the output pipe before closing inline (a reader that cannot spawn the detached closer never meets the blocked-conhost wait), spawn-failure cleanup closes on the same detached form, and retire guards the broken read handle
- the quiet close re-probes the read event after the pipe peek, so a completion landing between the two restarts the grace instead of racing the close

* ConPTY: pin the batch interpreter to the system cmd.exe

- the batch command processor now resolves as <windows root>\System32\cmd.exe (GetWindowsDirectoryW first, env root then literal as fallbacks) and is probed for existence - a PATH-planted cmd.exe can never answer for a trusted script, and a PATH without System32 no longer breaks batch spawns
- the no-PATH resolution fallback derives from the same shared windowsRoot helper
2026-07-24 17:26:04 -05:00
Chris Tate f8c14c59c7 Terminal: pty effects, libghostty-vt, and a replayable terminal example (#191)
* Add the POSIX pty primitive: openpty, controlling-terminal fork/exec, resize, reap

- One transport for terminal children: parent-built argv/envp (clean env plus TERM), async-signal-safe child path via login_tty/execve, group kill and waitpid decode
- macOS and Linux-with-libc report supported; every other target compiles to loud PtyUnsupported stubs
- Live tests prove the controlling terminal (test -t 0), exit codes, signal decode, and the env policy

* Pin libghostty-vt and stage the terminal example skeleton

- examples/terminal owns its build: ghostty pinned at 7aa9591 (the first upstream commit that builds under Zig 0.16.0; v1.3.1 still targets 0.15) with simd off so the vt module stays pure Zig
- The pin is proven in-tree: the example's test round-trips VT parsing through the pinned module
- zig-pkg/ (the project-local package store) joins .gitignore

* Add the pty effect vocabulary: spawn, coalesced output, write, resize, kill, replayable exits

- fx.ptySpawn/ptyWrite/ptyResize/ptyKill ride the keyed families' seams: one key space, the spawn argv budgets and env policy, exactly one exit per spawn, rejections staged loud and regenerating
- Output coalesces through a per-pty staging ring paced by the drain (lossless back-pressure: a full ring parks the reader, never drops), delivered as bounded batches journaled via the content-addressed blob store; replay never spawns a process
- The fake pty scripts the whole vocabulary headless (request/write/resize/kill mirrors plus output/exit feeds), and live POSIX tests pin coalescing, losslessness, controlling-terminal wiring, and teardown convergence

* Render the terminal example: libghostty-vt grid on the canvas, keyboard-first, replayable

- grid.zig wraps one emulator session (cell state, damage, scrollback, keyboard selection) and paints the viewport as real text: per-row background/text runs, theme-mapped ANSI-16 with exact 256-color and truecolor, wide CJK cells, a scrollback thumb
- main.zig drives it on the pty vocabulary: typing rides the IME-correct text channel and the emulator key encoder, selection/scroll/copy chords, a variable-length chrome prefix for the grid, and the frame pump resizes the grid and pty together
- UiApp gains on_text (the target-less committed-text seam) and a variable_prefix chrome mode; the gpu-surface layer routes unclaimed text_input to the app, the key_down fallback's twin
- Tests pin the emulator round trip, CJK width, scrollback, line/block selection, palette honesty, and a fake-pty session that replays byte-identical offline

* Document the terminal recipe, platform matrix, and replay story

- docs/terminal: the pty vocabulary, coalesced output, the exit taxonomy, grid rendering, and the byte-identical offline replay story, with the honest macOS/Linux/Windows-staged/null matrix
- Registered in the Core Concepts nav beside Dynamic Images
- Changelog fragments for the pty vocabulary, the terminal example, on_text, and the TS Cmd family

* Harden the pty transport: exec-failure detection, teardown, and write accounting

- pty spawn distinguishes a failed exec from a real 127 exit via a close-on-exec self-pipe (a bad shebang interpreter now reports spawn_failed, not exited), and rejects argv entries with embedded NULs instead of silently truncating them at the C boundary
- The io loop observes shutdown so a reader parked on a full staging ring exits promptly at teardown instead of forcing the abandon path
- dropped_writes now counts outbound bytes lost to a write failure or a child that exits with input still staged; a kill racing a natural exit rewrites the terminal to cancelled with the -1 sentinel code
- Bounded per-drain output: a delivered batch re-stamps the remaining backlog past the pass boundary, so a continuously writing child delivers one batch per drain instead of starving other events

* Harden pty fd hygiene, the kill/reap races, replay provenance, and grid fidelity

- pty spawn aborts if CLOEXEC on the exec self-pipe cannot be set (a leaked write end would hang the parent), and the wake pipe is now CLOEXEC so no descriptor leaks into the child; empty PATH components resolve as the current directory (POSIX)
- ptyKill no longer signals a reaped pid (the OS may have reused it) and the io loop winds down on kill even when an escaped descendant holds the pty open, so the exit always delivers; dropped_writes counts each lost payload, not one lumped event
- Platform-unsupported rejections are executor truth and feed under replay (a journal recorded where ptys are unsupported replays its rejection verbatim); the regenerating marker rides the record's truncated bit so a pty exit reason stays honest, with a replay damage gate for the pairing
- feedPtyOutput refuses an over-bound batch instead of truncating, and every fake pty (not just replay parks) refuses a second feed after its exit is queued
- Example: inverse-video cells paint text in the background color (not foreground-on-foreground), the grid self-limits to its chrome command budget so a pathological screen degrades to fewer rows, and the Linux default shell is /bin/sh (present on every install, unlike /bin/bash)

* Wire the pty command family into the TypeScript tier

- Cmd.ptySpawn/ptyWrite/ptyResize/ptyKill (wire opcodes 0x19-0x1C, additive over the current cmd format) expose the pty vocabulary to transpiled cores, with an event arm matched by field name (key/kind/bytes/code/reason/signal/droppedWrites)
- The rt kernel encodes the four ops; the emitter lowers and validates them (argv and grid bounds) with teaching diagnostics; the ts-core host decodes them into the runtime Effects pty calls and dispatches events back to the core's event arm
- Posting stays native-only (transpiled cores are single-threaded): the TS tier spawns, writes, resizes, kills, and receives. Covered by packages/core effects/conformance tests and the ts_core_host bridge tests, plus a cmdview decoder arm so the evals harness names the new commands

* Harden pty close-on-exec fds, the pid-reuse guard, exact write accounting, and NUL-safe TERM

- The pty parent end/child end (and the exec self-pipe read end) are close-on-exec, so a concurrent process or pty spawn on another thread cannot inherit another session's descriptors and hold its pty open; pipePair now aborts if either non-blocking fcntl fails instead of returning a pipe that could hang the UI thread in nudge
- Closed the pid-reuse window: the io thread publishes a reaping flag under the mutex before waitpid, and ptyKill and teardown decline to signal once it (or exit_staged/io_done) is set, so a reaped child's reused pid is never signalled
- dropped_writes now tracks per-payload boundaries: a fully-sent write pops as its bytes flush, so a discard counts only the writes that never reached the child, not already-delivered ones
- ptySpawn rejects argv or TERM containing an embedded NUL (validated at the effect boundary so the fake executor and replay agree), never a silently truncated value

* Bound the pty exec probe and reap, make kill signalling atomic, and cap the grid command budget

- The exec-status probe polls with a timeout instead of a blocking read: a real exec failure writes its byte instantly (always detected), success is EOF, and the timeout is the net for the residual CLOEXEC window so a concurrent fork inheriting the pipe writer can never hang the spawn. Pipes are created close-on-exec atomically on Linux (pipe2); Darwin keeps the immediate fcntl behind the same timeout net
- reapEnding replaces the unbounded reapBlocking after the stream ends: the normal case (child already exited) returns at once with no signal, and a child that closed its terminal but kept running is hung up and escalated to SIGKILL within a bounded window, so the exit always arrives and no kill is stranded
- ptyKill and teardown signal the child UNDER the shared mutex, atomic against the io thread's pre-waitpid reaping publish, so a reaped pid's reuse is never signalled
- dropped_writes stays exact: the outbound record ring is an admission bound (a write past it is refused and counted once, like a full byte buffer), so every accepted write owns a length record and none is folded
- Example: the grid's per-row command reserve accounts for background + text + underline per cell (3/column) so a pathological screen truncates safely under the chrome budget; a resize allocation failure leaves the model dimensions uncommitted so the emulator and pty never disagree and the frame pump retries

* Open the pty pair with an atomically close-on-exec child end, reset reused header flags

- Replace openpty with posix_openpt + grantpt + unlockpt and open the child end O_CLOEXEC atomically: the child end is the descriptor whose inheritance across a concurrent fork's exec would hold the pty open and starve the exit event, and an atomic open closes that window on both platforms (the parent end's Darwin sub-syscall window is benign — an inherited parent end does not hold the pty open)
- Reset every reused PtyShared flag on a new spawn (reaping, the outbound write records) so a prior session's state never steers the next: a stale reaping would make ptyKill skip its immediate SIGKILL
- Declare ioctl variadic to match the C ABI — a fixed-arg declaration mis-passed the winsize pointer on arm64, silently dropping the initial grid and every resize; the resize test now verifies the applied size, not just the call

* Handle already-reaped children, low child end fds, post-exit writes, and pre-output input

- reap reports ECHILD (a child reaped by an embedder's own SIGCHLD handling) as a gone child, never as still-running, so the escalation path cannot signal a reused pid
- Relocate a child end that lands on fd 0/1/2 to a high descriptor before login_tty: a same-fd dup2 does not clear close-on-exec, which would make the child's stdio vanish at execve when the host started with standard descriptors closed
- ptyWrite drops a write once the reaper has staged the exit: there is no io thread left to send it, and mutating the finalized exit's dropped_writes would race the drain
- The terminal example accepts input from spawn onward, not only after the first output batch — a shell with an empty prompt and no banner never flips to live, and gating input on it would strand every keystroke

* Relocate low pty fds, wind down orphaned ptys, commit-only text, IME preedit, guarded restart

- Relocate the child end AND the exec self-pipe write end above the standard descriptors before the fork: login_tty dup2's the child end onto 0/1/2, and a write end left on fd 1/2 would be clobbered, making an exec failure masquerade as a normal exit when the host began with stdio closed
- Bind-time services-snapshot failure now winds down already-running ptys (bounded), not just channels, so their exit still delivers instead of stranding with no wake services
- on_text delivers COMMITTED text only: an IME preedit (set_composition) or cancel routed through a focused non-text widget no longer types provisional bytes into a terminal
- The targetless text path tracks the IME preedit and delivers it on commit — hosts emit an empty commit for unchanged marked text, so the composed bytes come from the buffered preedit; only committed UTF-8 reaches on_text
- The terminal example restarts only a genuinely ended or failed session, never during starting/live, so a quiet shell is not duplicated onto its own occupied key

* Non-blocking pty parent end, detach at retire, UTF-8-safe preedit truncation

- The pty parent end is opened non-blocking and read/write surface WouldBlock: the sole io thread paces both directions through poll and never blocks inside a write when the child stops reading stdin while producing output, so stdout keeps draining and neither side deadlocks (ptyFlushOutbound writes at most one chunk per POLLOUT, leaving the rest staged)
- Retirement detaches the io thread instead of joining it: retirement runs at exit delivery, inside the very dispatch a synchronous-marshal wake hook may be waiting on, and the thread's last act is that host wake — joining would recreate the deadlock ChannelWake forbids. By retirement the thread has published io_done and is past all transport/staging/pipe access, so detaching and reclaiming its fds is safe (conforming enqueue-only wakes have already returned; a violating one lingers against the process-lived header)
- A truncated targetless IME preedit now cuts on a UTF-8 boundary, so an empty commit never forwards a split code point as committed text

* Quiesce every pty wake at teardown, route IME to editable widgets only, chunk input

- Teardown now quiesces the wake header of EVERY pty slot, idle included: the header is process-lifetime and reused, so a retired session's slow wake_fn can still be in flight when the services snapshot and platform are freed. A call still executing at the deadline is abandoned, counted, and the platform signalled to outlive it — the abandoned io-thread path accounts for its quiesce failure the same way, no longer silently
- Text and IME route to a focused widget only when it is an editable text-entry widget; a focused non-text widget (a button, a list row) lets committed text fall through to the target-less on_text seam instead of dropping it
- The targetless IME preedit buffer holds a full phrase-sized composition and the child's exec-failure report retries EINTR, so an interrupted one-byte report is never mistaken for a successful exec
- The terminal example chunks committed text into per-write-bound pieces, so a long paste or IME commit types every byte instead of being refused whole

* Free the pty header on clean teardown, honor emulator colors, bound the grid text store

- A cleanly quiesced pty header is now freed at teardown: unlike a channel header (which an app thread may post to forever), the pty io thread is the sole toucher and is gone once quiesce confirms no in-flight wake, so repeatedly creating and destroying runtimes that used a pty no longer leaks ~64 KiB each; an abandoned header still leaks deliberately
- The grid reads the emulator's resolved foreground, background, and cursor: the theme colors are pushed into the emulator's DEFAULTS so ghostty composes OSC 10/11/12 overrides and DECSCNM reverse-video itself, and the renderer honors an application's requested colors instead of forcing the theme
- The grid degrades by whole rows when the display-list text store nears its budget (an emoji-dense screen), never blanking cells mid-frame with a swallowed allocation failure
- Documented that an .exited pty terminal carries -1 only when the child was reaped outside the toolkit (an embedder installing SA_NOCLDWAIT / ignoring SIGCHLD / running its own reaper) — an already-broken parent/child contract where the real code is unrecoverable

* Keep the pty header process-lived, serialize ptsname, honor OSC 4 by mask

- Revert the teardown free of PtyShared: quiescing proves in_flight is zero, not that the io thread has RETURNED (it publishes its exit before calling requestHostWake, and a detached mid-life thread's late or violating wake still locks the header's mutex), so freeing risked a use-after-free. The header is now permanently retained like ChannelShared — a bounded per-slot leak that never grows during a runtime's life
- ptsname's shared static buffer is resolved and copied under a process-wide spinlock, so concurrent pty spawns from independent runtimes on different threads never open each other's child end
- The grid decides an ANSI slot is untouched by the emulator's override MASK, not RGB equality: a program that OSC-4-sets a slot to exactly the default RGB is honored instead of being replaced by the theme color

* Stop macOS Option double-input and stage heavy graphemes whole

- On macOS, Option is a compose key: Option+F commits the composed character through the text channel, so the key encoder no longer also treats Alt+printable as a chord there (which sent both the composed character and an Alt-escape to the child). Elsewhere Alt stays Meta
- The grid's run staging buffer holds a full row plus a heavy grapheme cluster (8 KiB), so a cell with hundreds of combining marks stages whole; the run-break splits long runs across draw commands rather than overflowing, and any residual cut lands between code points (valid UTF-8)

* Block for the exec verdict on Linux, refuse empty output records, make grid rows atomic

- The exec-status probe blocks for a reliable verdict on Linux, where the report pipe is atomically close-on-exec (pipe2): a slow execve (an interpreter on a sluggish filesystem) is now awaited and correctly reported as spawn_failed rather than assumed successful. Darwin keeps the bounded poll — it has no atomic-CLOEXEC pipe, so blocking could hang on the fork-inheritance window (the documented residual every macOS terminal shares)
- Replay refuses a .output pty record with a zero-length blob: the recorder journals output only for a non-empty batch, so a zero-length one is damage that would otherwise replay a synthetic empty event and diverge the fingerprint
- The grid measures each row's exact text bytes and skips the row WHOLE when the display-list text store cannot hold them, and breaks a run before a cell whose grapheme would overflow the run scratch — so a heavy-grapheme row is never torn mid-way and a large cluster landing near the buffer's end keeps all its marks
- The terminal-response staging buffer holds a large pipelined query burst (16 KiB); an overflowing reply is still dropped whole (never cut) and counted

* Zero the signal on a cancelled pty, chunk query replies, grow the IME preedit to fit

- A cancelled pty exit reports signal 0: the toolkit's own SIGKILL is what felled it, and the contract is "signal is nonzero only for a .signaled end", so the raw SIGKILL value no longer leaks into a cancelled terminal
- Terminal query replies (DSR/DA/XTVERSION) flush through the chunking write path, so a batch that pipelined more than one write's worth of replies delivers every byte instead of being refused whole and leaving the child waiting
- The targetless IME preedit buffer grows to fit the composition instead of truncating at a fixed size: each set_composition replaces it with the host's full string, reallocated only when a larger one arrives and freed at runtime deinit, so an unchanged commit of any length forwards the whole composition

* Ignore empty pty output, clear stale preedit on OOM, reset on restart, map function keys

- feedPtyOutput ignores an empty batch: the live drain only delivers non-empty output, so journaling a zero-length one would write a blob record replay refuses as damage
- A failed IME preedit grow clears the buffer instead of leaving the superseded composition, so a later empty commit never inserts stale text the user has replaced
- Restarting the terminal hard-resets the emulator (RIS + a fresh parser), so a shell that exited mid-escape or in a non-default mode does not corrupt the next session's key encoding or first output
- The key map covers Insert and F1-F12, which carry no committed text and would otherwise be dropped before reaching the child

* Bound the exec probe on both platforms, gate impossible exit records, clear selection on restart

- The exec-status probe blocks up to a generous bound on every platform rather than forever on Linux: O_CLOEXEC closes an inherited pipe copy on the concurrent forker's exec, not its fork, so a forker slow to exec would delay EOF and an unbounded wait could hang the spawn thread. The bound caps that pathological wait; a timeout means our own child exec'd (an inherited writer merely delayed EOF) and is success. A slow-failing exec under the bound is still awaited and reported; only one that both blocks and fails past it misclassifies (an extreme filesystem pathology) — a self-pipe cannot distinguish that from a delayed EOF without the bound
- Replay refuses a pty exit record whose code/signal contradict the delivered contract (signal nonzero iff .signaled; code -1 for every reason but .exited), so a hand-edited .cancelled with code 0 or signal 9 cannot dispatch a contract-violating event
- Restarting the terminal leaves selection mode, so a restart while a selection caret is armed does not reject the new shell's typed input

* Name the two ends of the pty pair parent and child

- The controlling side the toolkit keeps is the parent end; the process side the spawned program adopts as its controlling terminal is the child end. Rename the transport field, the spawn locals, and the poll helper to parent/child, and rephrase every comment to match.
- POSIX's own API names (posix_openpt, ptsname, grantpt/unlockpt) keep their C spellings at the call site; only the words the toolkit owns change.

* Carry the session key on pty events, normalize fake exits, keep query replies lossless, and shrink the pty leak

- The transpiled pty event arm now carries the app's own session key: two sessions routing one event arm were previously indistinguishable, so the arm gains a `key` field the host fills from the wire key (emitter, host bridge, and SDK type updated together).
- `feedPtyExit` clamps its tuple to the event contract the live io loop guarantees — a signal only after a signaled end, a code only after an exited one — so a fake or replay can never stage an exit the recorder journals but replay's damage gate then refuses.
- The terminal example feeds output in sub-slices and drains the emulator's query answers between them, so a burst of pipelined replies cannot outrun the write-back buffer and a child blocked on a DSR answer never hangs; a residual overflow surfaces on the status line instead of vanishing.
- A pty session's ~64 KiB outbound ring and its per-write length ring move into a heap block freed at retire, so only a small header joins the process-lifetime leak (the channel header invariant), not the buffers; a teardown that abandons a stuck io thread still leaks the block with the thread that can reach it.

* Make the pty rejection key self-contained and enforce the signaled-exit contract

- A staged spawn-rejection Msg is delivered a frame after it is issued, past a frame-arena reset, so it can no longer copy the wire key into that arena: it carries the empty key (the self-contained-Msg rule the bytes field already follows), leaving the durable engine-key routing for live events untouched.
- feedPtyExit now enforces the full exit contract as a biconditional — a signaled end REQUIRES a nonzero signal, not just a signal only on a signaled end — so a fake or replay feeding .signaled with signal 0 is refused loudly instead of journaling a record replay's damage gate would later reject.

* Give replayed pty output the -1 code, keep the rejection key, and bound the exec probe by deadline

- A replay-fed output batch now carries the -1 code sentinel the live drain delivers (the Entry default was 0), so an app that folds the event code into its model no longer diverges between a live run and its replay.
- A staged spawn-rejection keeps the app's requested key: it is copied into a process-static ring (durable across the frame reset the staged Msg outlives) and referenced directly, so a duplicate-key or table-full refusal is correlated with the command that caused it instead of arriving keyless.
- The exec-status probe bounds itself by a monotonic DEADLINE rather than a per-poll timeout, so signals interrupting poll (EINTR) can no longer each restart the full wait and defer the timeout indefinitely — the synchronous spawn stays bounded under a signal storm.

* Make staged rejection keys grow with the batch, pace pty input to the FIFO, and reserve grid widget text

- Staged spawn-rejection keys move from a fixed host ring to a growable engine store (stageLoopKey): each key gets its own stable heap buffer reclaimed when the staged stage next empties, so a Cmd.batch staging more rejections than any fixed ring holds can no longer overwrite a key still awaiting delivery and mis-correlate an exit.
- The terminal example buffers typed and pasted input and drains it against the pty stdin FIFO's free space (new ptyOutboundFree query), so a paste larger than the 64 KiB FIFO no longer loses its tail when the child is not reading; it paces out as the child reads, with a per-frame flush covering a child that reads without echoing. Query replies stay direct and the flush reserves FIFO headroom for them, so bulk input never starves an answer the child blocks on.
- Grid painting reserves display-list text bytes for the header and status widgets that share the per-view text store, so a grapheme-heavy viewport degrades to a few fewer rows instead of pushing the combined frame past the runtime limit and failing the whole update.
- Any residual dropped input surfaces on the status line beside the reply-drop count.

* Report pty write acceptance so the terminal never loses input or query replies

- ptyWrite now returns whether the whole payload was accepted, since it alone knows the byte-FIFO and 256-record admission limits; a byte-capacity query could report room the record ring would still refuse, misleading a caller into treating a rejected write as sent. The misleading ptyOutboundFree query is removed.
- The terminal example drains one stream-ordered outbound ring holding typed keys, pastes, AND emulator query replies, retrying any chunk ptyWrite refuses instead of dropping it. A paste larger than the FIFO paces out as the child reads; a reply refused by a full FIFO stays queued rather than being cleared, so a child blocking on a DSR answer is never stranded. A per-frame flush covers a child that reads without echoing, and a full-ring overflow is counted and shown, never silent.

* Journal pty write verdicts for replay and free pty buffers through their allocating seam

- A ptyWrite admission verdict is executor truth — whether the outbound FIFO and record ring had room depends on how fast the child was reading — so each one now journals (a .pty/.write record) and a replayed write returns the RECORDED verdict instead of recomputing optimistically against a fake with no child: an app that retains refused bytes takes the identical retain/remove path in both runs, pinned by a recorded session whose refused and accepted writes replay fingerprint-identical. The journal format fingerprint moves with the new record kind, refusing pre-verdict journals honestly.
- Pty staging rings and outbound blocks now free through the channel_storage_allocator seam that allocated them, so a swapped-in tracking or arena allocator sees its own frees instead of a mismatched destroy against the default backing.

* Scope target-less IME preedit per surface and gate command chords out of target-less text

- The target-less preedit buffer now tracks its originating surface (window + view label), matching how a focused widget's editor scopes composition to the widget: only the owning surface's commit consumes the buffered bytes and only its events clear them, so a second surface's empty commit can never insert a composition typed into the first.
- Target-less text_input now applies the same command-chord gate focused text widgets use (primary/command/control means shortcut, not typing; Alt stays out — Option and AltGr compose text), so Ctrl+C delivers the encoded chord alone and never a stray literal character; pinned at the runtime layer and against the terminal example's pty input.

* Deliver key-carried typing target-less, count post-exit write refusals, and complete the terminal key map

- Committed text carried on a key_down (hosts whose plain typing rides the key event, with no separate text event) now reaches the target-less on_text seam under the same command-chord gate the focused-widget path applies — ordinary typing was silently lost there, while specials carry no text on any host so nothing doubles with the key fallback.
- A ptyWrite refused in the staged-exit window now counts into dropped_writes (the exit reads the count under the mutex at drain delivery, which has not happened yet), closing the one silent-refusal gap; only a write after the exit delivers finds no slot, the documented cancel race.
- Every desktop platform now reports delete/home/end/pageup/pagedown/insert and f1-f12 as named keys (previously private-use strings or nothing), shortcuts and menu accelerators accept them, and the terminal example maps chorded punctuation and supplies the pressed character to the emulator's encoder — Ctrl+\ reaches the child as its C0 byte, Ctrl+[ as the encoder's fixterms CSI-u form, F1 as ESC O P.

* Reset OSC colors on shell restart and honor widget precedence in target-less text

- Session.reset now clears the palette and dynamic color overrides (OSC 4/10/11/12): the emulator's full reset leaves its color state alone, so a shell that tinted the palette and exited would otherwise color the next session; overrides drop while theme defaults stay.
- The target-less committed-text fallback now honors the widget-precedence contract's structural-claim step: a key the focused widget answers as a control intent (Space pressing a focused button) no longer ALSO types its literal character through on_text, on either committed-text carrier, while unclaimed characters keep flowing to a terminal that happens to share focus with a button.

* Wire the new named keys through every platform's menu accelerators

- GTK translates them to accelerator names (Page_Up, F1, ...) so gtk_application_set_accels_for_action actually binds them; AppKit converts named keys to their NSMenuItem key-equivalent characters (function-key unichars, control characters) instead of passing the canonical string through, which also repairs the pre-existing arrow/escape menu bindings.
- The Windows keydown path now dispatches menu-item accelerators alongside registered shortcuts — a menu item's key+modifiers emits its menu command exactly as if clicked; AppKit and GTK get this from their menu systems, and on Win32 the message loop is that system.

* Settle replay feeds at the journal's end and make pty record accounting exact

- Replay now verifies at the journal's end record that every journaled ptyWrite verdict was consumed and no write ran past them (the new .settle replay control): a write-count divergence changes no state when the caller is fire-and-forget, so fingerprint checkpoints alone could pass a diverged run — the settle check fails it loudly in both directions.
- Output records journal the canonical scalar shape from BOTH drain sites (-1 code sentinel, no signal, no drops) and the replay damage gate refuses records claiming anything else — previously replay silently delivered defaults that differed from a damaged record's journaled fields.
- A fed exit's dropped_writes now adds the refusals the fake itself counted (an oversized write against a scripted pty), so the counted-refusal contract holds without every script re-deriving the tally; under replay the slot count is always zero and the journaled count delivers verbatim.

* Keep an IME sequence with the consumer it started over

- A composition buffered by the target-less consumer continues target-less even when a text widget takes focus mid-sequence: routing its empty commit to the newly focused editor would resolve a composition that editor never saw and lose the composed text. Ownership ends with the sequence — the next composition belongs to the focused editor as usual.

* Admit outbound terminal payloads whole or not at all

- The pending-outbound ring's admission is now all-or-nothing: a payload it cannot hold whole is dropped whole and counted, never cut at the ring edge — a torn query reply or encoded key would feed the child a malformed escape sequence, which is worse than a counted loss. Reaching the drop at all means the child ignored 256 KiB of pending input, and the count stays on the status line.

* Key the replay write verdicts by pty and grow the queue with the recording

- The verdict queue now spills to the heap past its inline window (the pending-stage growth story): every verdict a dispatch recorded feeds before that dispatch replays, so a fixed bound would reject a valid recording whose one update wrote more times than the bound — a giant paste drained in per-write chunks is exactly that.
- Each verdict carries the pty key it was recorded against, and a replayed write consumes only a matching-key verdict: the same call count and acceptance results against a DIFFERENT session is still divergent input, which a global boolean sequence would silently pass; a mismatch counts as divergence, strands its verdict, and fails the end-of-journal settle on both signals.

* Canonicalize menu key case, teach the Chromium host the named keys, and state the reaping contract

- Menu-item keys canonicalize to lowercase at each host's storage boundary, matching the shortcut stores that already did: key names validate case-insensitively, so a mixed-case spelling must still translate to a valid GTK accelerator name and a correct AppKit key equivalent (single characters lowercase there too — uppercase implies Shift, which the modifier mask already expresses).
- The macOS Chromium host's key normalizer gains pageup/pagedown/insert and f1-f12, so shortcuts on those keys fire under that host exactly as under AppKit.
- The kill fence's ownership premise is now stated at the signal site and in the recipe: the toolkit forks each pty child, is its sole reaper, and never touches SIGCHLD disposition — an embedder must not either, because POSIX offers no portable way to signal a pid once a third party (including a kernel auto-reap) can free it first; inside the contract the reaping fence is exact.

* Settle the clock feed too, and retain query replies a full ring refuses

- settleReplayFeeds now holds the clock feed to the write-verdict rule: a wallMs read past the journaled values (answered 0 optimistically) or a journaled value never consumed is divergence no checkpoint need see, and either fails the end-of-journal settle loudly.
- A query reply the pending ring cannot take right now stays IN the emulator's buffer — uncleared, uncounted — and retries on the next output, resize, or frame nudge, so a child blocked on a DSR answer behind a full ring is never stranded by a discarded reply. Transient payloads (typed text, encoded keys) keep the counted-drop disposal since their bytes cannot outlive the dispatch; only a payload larger than the whole ring is impossible and counts immediately.

* Align start-failure write verdicts, grow the reply buffer, and strip the primary alias from encoder chords

- A write against a spawn whose transport failed synchronously now journals its refused verdict: the staged executor-truth terminal keeps the key occupied on the live side exactly as the parked slot does under replay, so the two verdict streams stay aligned where they previously diverged (live refused silently, replay consumed a verdict that was never recorded).
- The emulator's query-reply buffer is heap-grown to fit (up to the outbound ring's own capacity): replies retained behind a full ring keep accumulating while further output feeds, instead of overflowing a fixed buffer into counted drops that could strand a blocked child; past the ceiling a reply still drops whole and counted, never cut.
- The terminal encoder strips the runtime's primary-into-super fold when Ctrl raises it, so a bare Ctrl chord reaches the emulator clean and Ctrl+C delivers ETX — a stray super demoted it to a CSI-u chord no foreground shell treats as an interrupt. The GUI+Ctrl double chord encodes as plain Ctrl, the convention terminals follow.

* Hold stdin order across a retained reply

- A query reply retained behind a full outbound ring is older than any later keystroke, so transient input now gives the reply its retry first and refuses to jump the queue while it remains stuck (dropped counted, never reordered) — the child's stdin keeps the order a real terminal delivers: the answer it is parsing toward, then the typing.
- The output arm retries retained replies right after its flush frees ring room, so the oldest bytes take that room before anything a later dispatch could enqueue.

* Refuse and count fake writes after the staged exit, folding drops at delivery

- A fake pty now mirrors the live admission path's staged-exit rule: a write after feedPtyExit staged the terminal refuses and counts as dropped, never a silent acceptance into a session that is already over.
- The dropped tally folds the slot's count into the delivered exit AT DELIVERY (both the fed-exit queue drain and the start-failure stage), the same read-at-delivery rule the live staged-exit drain follows — so refusals landing between the feed and the drain still reach the delivered count; under replay the slot count is provably zero and the journaled count delivers verbatim.

* Land start-failure write refusals in the staged exit's tally

- A write refused in the synchronous start-failure window now counts onto the staged terminal entry itself: that terminal's slot was already released, so no slot tally could carry the drop to delivery, and the exit reported zero despite the refusal. The counting walk is the occupies-key predicate with the bump folded in, so the verdict journal and the delivered tally move together — the exit reports every refusal, never silence.

* Settle undelivered pty feeds, serialize the spawn's descriptor window, and state the process-group kill limit

- settleReplayFeeds now refuses fed pty results still queued at the journal's end: every result was journaled at its live delivery, inside an event that follows it in the stream, so a leftover means the journal was truncated past its consuming event — succeeding would silently omit a recorded delivery. Regenerating staged rejections stay exempt (the live run could end with one staged too).
- The pty spawn's whole descriptor-opening window — posix_openpt through fork — now runs under one process-wide lock, and the parent end's close-on-exec fcntl is verified: Darwin ignores O_CLOEXEC on posix_openpt, so a concurrent toolkit fork landing inside another spawn's flag gap would gift its exec'd child a copy of that pty's parent end for the child's whole life. Our own forks can no longer land there; an embedder fork keeps the documented residual window the exec probe's timeout nets, and the probe still polls outside the lock.
- The kill contract now states its real reach at every site: SIGKILL lands on the child's process group (the whole foreground job), and a descendant that re-grouped itself escapes — POSIX has no kill-whole-session primitive, the spawn family's documented limit.

* Cover every descriptor window with the spawn lock, bound the surrendered reap, and carry an unresolved exec probe to the reap

- Every toolkit fork and every Darwin flag gap now shares one lock: the wake pipe's creation and the job-spawn family's process start hold the pty spawn lock, so no toolkit child can inherit another spawn's not-yet-CLOEXEC parent end, pipe writer, or wake pipe across its exec — only embedder forks on threads the toolkit does not own keep the documented residual window.
- reapEnding's final wait is bounded: a SIGKILL'd child the kernel holds in uninterruptible I/O cannot be waited out by any signal, so past a further deadline the reap is surrendered and the kill reported as the ending — the exit always reaches the app, and the eventual zombie is the bounded, documented cost that beats an io thread wedged forever.
- An exec probe that times out no longer guesses success: the status pipe rides the transport (non-blocking) and is read at reap time, when a failing exec's byte — written before its _exit — is present by construction, so an executable that blocks past the bound and then fails still delivers spawn_failed, never a masqueraded normal exit.

* Intern staged rejection keys for the model's life, bound failure-path reaps, and free the spawn lock from job starts

- Staged rejection keys are now INTERNED and instance-lived: the TS commit walker shares non-frame pointers into the committed model rather than copying them, so a reducer that stored a rejection's key held memory the old reclaim could free mid-run. Interning bounds the storage by the app's distinct key vocabulary (repeat rejections of one key cost nothing) and the buffers outlive every model that references them.
- The pty thread-start and wake-snapshot failure paths use the escalate-then-surrender reap: a child wedged inside an exec on a stalled mount cannot be waited out, and an unbounded waitpid there froze the UI loop instead of delivering spawn_failed.
- The job-spawn process start no longer holds the pty spawn lock — it blocks on its own exec-status pipe, so a stalled execve would have wedged the lock and frozen the UI the moment a pty needed it. A job fork landing in a pty flag gap joins the documented bounded residual (inherited copies die at the job child's exec; a delayed exec-pipe EOF resolves through the carried reap-time verdict, never a guess).

* Pin compositions to their starting editor, shorten the exec probe, and re-poll surrendered reaps

- An IME sequence now routes its continuations to the text entry it STARTED in: a per-view owner is pinned when a set_composition routes and released when its commit, cancel, or a direct insertion closes the sequence — so a focus move mid-composition no longer strands the starting editor's marked text or leaks the commit through the target-less fallback, the mirror of the target-less ownership rule.
- The exec probe's deadline drops to half a second: the unresolved verdict carries to the reap where a late failure still reports spawn_failed exactly, so the synchronous wait buys only the instant-failure nicety and no longer holds the loop for seconds; the PATH walk's access() probes remain the documented stalled-mount residual of the spawn-position verdict the replay contract requires.
- A surrendered reap now parks its pid on a process-wide list re-polled (WNOHANG) at later spawns and at teardown, so a child that dies after its device or mount recovers is reaped then instead of zombieing for the process's life.

* Decide the text claim before app rebuilds, swallow orphaned compositions, and state the Darwin pipe residual

- The target-less committed-text claim is decided against the tree the input actually routed through, BEFORE the app dispatches that may rebuild it: a Space that pressed a focused button whose command removes that button still counts as claimed, so one physical keystroke can never double into a command and a literal space.
- A widget-owned composition whose editor vanished mid-sequence resolves nowhere: its commit or cancel is swallowed (the newly focused editor never saw the composition, and the target-less consumer never composed it) and the stale pin clears, so a fresh composition reopens cleanly at the focused editor.
- The Darwin pipe-then-fcntl window is stated fully at its site: pty forks are locked out, and the residual — a job or embedder fork landing inside it — is bounded on every axis (the copy dies at that child's exec, a wedged exec costs at most the half-second probe with the carried verdict keeping the outcome correct, a held wake pipe merely outlives its session's close until that exec).

* Route converted commits to the composing editor, latch orphaned sequences whole, and keep EINTR'd surrendered pids

- Every host encodes a converted commit (the composed result differs from the marked text) as cancel-then-text_input, so a cancel now holds the owner pin one event and arms a one-shot grace: the trailing text_input lands in the editor that composed it, never the newly focused one — while a plain cancel's own key_down disarms the grace before ordinary typing could inherit it.
- An orphaned sequence swallows EVERY continuation: the pin holds through preedit updates (the sequence is still open, and the focused editor must not inherit them) and releases only at its commit or cancel, with an orphaned cancel arming the swallow grace so the converted commit's trailing text vanishes with the sequence instead of typing into a stranger.
- reapSurrendered keeps a pid whose non-blocking poll was interrupted, rather than abandoning a live child to zombie unreaped; only a reap or ECHILD settles the entry.

* Give target-less compositions the converted-commit grace too

- A target-less composition's cancel now arms the same one-shot grace its widget twin got: the hosts encode a converted commit as cancel-then-text_input, so the trailing text still belongs to the surface that composed it — delivered target-less on that surface, never inserted into whichever text widget took focus mid-sequence. A plain cancel's own key_down disarms the grace before ordinary typing could inherit it.

* Retry the late-failure read, orphan-check the commit grace, and die with the view

- lateExecFailure retries an interrupted read instead of mistaking EINTR for success: the failure byte may be sitting right there, and reading past the signal is what keeps a delayed exec failure reporting spawn_failed.
- The route-to-owner grace re-checks its owner at consumption: the cancel's own app dispatch can rebuild the tree away from the composing editor, and a dead owner converts the grace to a swallow — the converted commit's text resolves nowhere, never in whichever editor holds focus by then.
- A target-less composition dies with its view: removing a surface clears any sequence it owned, so a later view reusing the same window and label never mistakes its first composition for a stale continuation that would bypass its own focused editor.

* Disarm IME graces on blur and view removal, and re-anchor selection across a resize

- A view losing focus disarms its cancel-to-commit grace (and the target-less twin) and releases the owner pin: hosts emit a standalone cancel when a composing view blurs, and after refocus an IM-consumed keystroke's text_input arrives before its key_down echo — a stale grace would route that fresh commit to the old editor or swallow it.
- Removing a view clears the target-less grace even when the preedit length is already zero (cancellation zeroes it before arming), so a converted commit's trailing text can never leak target-less into a surface recreated under the same label.
- Resizing the terminal re-anchors an armed selection at the clamped caret: reflow moves every cell, so coordinates into the old grid are dropped rather than copied, and Shift+Arrow keeps operating inside the new grid.

* Share the blur-side IME hygiene across every focus path, fix the backspace key equivalent, and range-gate exit records

- Every focus-mutation entry point — the pointer-driven focus move, the programmatic focusView, and the window-level clearFocusedView blur — now routes through one shared blur helper that disarms the cancel grace and releases its owner pin, closing the lifecycle class structurally instead of per path; audited all view-focus writers to exactly these three.
- The macOS "backspace" menu key equivalent maps to 0x7f, the byte the physical Delete/backspace key actually emits (and the key-event normalizer maps back to "backspace") — the nominal BS control 0x08 never fired; every other named key in the table was audited against the normalizer and matches.
- Pty exit records are range-gated to what waitpid's status word can produce — codes 0..255 plus the documented -1 externally-reaped sentinel, signals 1..127 — at both the replay damage gate and the feed boundary, refused as damaged rather than replayed into an event no live run can emit; pinned with hand-damaged records on both axes and both directions.

* Honor the requested TERM, AltGr text, IME resolutions past claims, flush-first admission, and a clipped grid

- The pty environment now replaces an inherited TERM with the spawn's requested value (the spawn declared what terminal the child is attached to; a stale TERM=dumb from the host would misdeclare it), pinned live; and the restart resets the previous session's copy feedback.
- AltGr input survives both layers: the text-chord gate exempts Ctrl+Alt together (hosts represent AltGr that way, so a text event carrying both is composed text, not a shortcut), and the terminal's key mapper stops encoding Ctrl+Alt printables as chords for the same reason — the composed character rides the text channel alone. An IME resolution (an owned empty commit, or a converted commit's grace-ridden text) also bypasses the structural-claim gate: it ends a sequence the focused widget never participated in, so a button's Space claim cannot eat it.
- Outbound admission flushes before refusing (stale occupancy must not drop a keystroke the drain would have made room for), with a fake full-FIFO test seam standing in for a child that stopped reading; and the grid paints under a clip to its frame with an exact bottom-row guard, so the one stale pre-resize frame degrades to a cropped grid instead of painting over the status bar and past the right edge.

* Deadline the reap graces, carry claims across split events, and finish the exit accounting

- reapEnding's grace windows are monotonic deadlines: usleep returns early on EINTR, so iteration counting let a signal-heavy embedder collapse the 500 ms hangup grace into an almost-immediate SIGKILL and shrink the surrender window; the surrendered list is also re-polled at every session end, so a recovered child is reaped at the next pty activity of any kind.
- The committed-text claim carries across the event split: hosts that deliver a claimed key_down and its committed character as separate events (unlike the key-with-text shape) would recompute the claim against a tree the activation already rebuilt — a one-shot per-view carry keeps one physical keystroke from doubling into a command and a literal character. View blur now clears the composition owner unconditionally too: an active sequence's pin surviving a blur would redirect post-refocus typing to the stale editor.
- The example's AltGr exemption narrows to the host that actually represents AltGr as Ctrl+Alt — elsewhere that combination is a genuine chord that must encode — and session end is accounted honestly: cleared outbound bytes count as dropped, retained replies drop with the dead key instead of retrying against it every frame, transport write refusals reach the status tally, and a signaled or cancelled end says so instead of rendering as exited (-1).

* Never strand a pre-bind pty exit, and die the claim carry at blur

- A failed bind-site snapshot publication now stages a live pty's cancelled terminal from the loop past the wind-down deadline, so the exit delivers instead of waiting on a wake that can never fire
- The split-event claim carry clears at blur with the IME grace: a claimed activation that moves focus no longer swallows the refocused surface's first commit
- A restarted shell starts its refused-write tally at zero instead of inheriting the dead session's drops

* Give the input method its keys, and make the grid preflight measure what paints

- A target-less composition now owns its surface's key_downs (candidate navigation, the trailing resolver key on hosts that run the IM filter first), so confirming a candidate with Enter never also sends CR; the buffered preedit and its graces die at the surface's blur
- The split-event claim carry is keyed to the armed activation key's own literal, so a different key's committed text arriving next flows instead of feeding a stale latch
- The grid's row preflight now counts only bytes painting emits (invisible cells suppress, clusters cap at the run scratch), a session exit counts retained reply bytes as loss, and each fix is pinned in both tiers

* Free pty staging only on the io thread's own completion proof

- Retirement defers the staging/outbound frees to the thread's io_done publish (same critical section as its staged exit) and leaks them past an abandon, so a detached thread can never observe freed blocks
- The outbound flush re-checks open/generation after its unlocked write before touching the block or folding drop counts, closing the one ungated deref
- A superseded thread (slot reused after an abandon) goes silent at its next loop head and never publishes reaping/io_done into the successor; pinned with a deadline-miss abandon carrying an in-flight write and a free-counting seam

* Suppress IM-consumed composition keys at the GTK source, and bound the grid by what the renderer can hold

- Replace the one-shot resolved-key grace with host-side suppression: GTK surfaces no key_down for a key its input method consumed while composing, so a mouse-committed candidate never costs the next genuine Enter or arrow
- A styled wide character's spacer tail extends the primary cell's background run, covering both cells for SGR backgrounds and inverse video
- Painting stops row-atomically before crossing a distinct-code-point budget (the glyph-atlas proxy), and the run scratch grows to the full text store so any cluster the emulator holds paints whole; each fix pinned

* Let compositions own their keys before widget routing, and put real cells in the terminal's semantic surface

- A live target-less composition suppresses unchorded key routing ahead of every widget pass (dismissal, focus moves, activation), so a confirming Enter never presses a freshly focused button; chorded shortcuts stay live
- hostRequest's inline pre-flight now rejects keys held by live or staged ptys, matching the shared keyed-effect namespace every other issuer enforces
- The grid's accessibility label is the viewport text, carrying real cell state into the session fingerprint (equal byte counters with different screens no longer verify), and a failed selection re-pin clears the emulator selection instead of leaving a stale copyable range

* Settle every fed family, refuse fed overflow loudly, and keep the semantic screen honest

- The end-of-journal settle now reports ANY fed result left undelivered (every family plus journaled env records), and a fed line against a full queue answers EffectQueueFull for the replay pump's drain-and-retry instead of silently converting a recorded delivery into a drop
- GTK swallows a suppressed composition key's release too (no orphan key_up), and Windows lets AltGr-composed WM_CHAR text through the chord gate it raises Ctrl+Alt for
- The terminal's semantic screen text is heap-exact (never truncated or cut mid-scalar), refreshes when a scroll moves the viewport, clears to unknown on a failed render instead of going stale, and a failed selection serialization surfaces as a failed copy with the selection kept

* Close the key-suppression edges and keep selection, scrollback, and copy coherent

- GTK dedupes suppressed composition keys under autorepeat and clears them at focus loss; Windows discards the WM_CHAR a dispatched shortcut already consumed (AltGr chords type only when no accelerator matched)
- The surrendered-reap table evicts round-robin on overflow, so every wedged child keeps a retry seat instead of all forgetting behind slot zero
- Scrollback chords pause while a keyboard selection is armed (viewport-relative caret vs absolute range), and a copy over a vanished emulator range reports failure instead of quietly keeping stale clipboard content

* Track suppressed keys by keycode, disarm graces the suppression starved, and confirm before clearing

- GTK tracks composition-suppressed keys by physical keycode (a lifted Shift cannot rename the release) and a plain cancel whose resolving key_down is suppressed emits a synthetic duplicate cancel, so the runtime's cancel-to-commit grace disarms instead of eating the next ordinary commit
- The Windows shortcut latch holds across the keystroke's whole translated burst (ligature layouts post several WM_CHARs), disarmed by the message sequence at the next key transition
- A terminal selection now anchors at the live cursor (never the last painted snapshot) and survives until the clipboard write CONFIRMS - a failed write keeps it standing for the retry the status promises

* Paint the terminal where the user can see it

- The grid region spacer is a stack, not a panel: the panel's surface chrome (fill, border, shadow, rounded corners) painted OVER the chrome-prefix grid, blanking the whole terminal
- Grid text anchors its BASELINE (origin is not the glyph top), so rows land in their cells instead of one line high with row zero swallowed by the clip
- The session-state indicator is a quiet muted label instead of a pill that read as a half-painted toggle, and a painted-output oracle now renders the retained frame to pixels headless and asserts the prompt's ink and the caret's cell

* Build the terminal example on hosts with only the command-line tools

- Disable ghostty's macOS app and xcframework artifacts in the dependency options: only the vt module is consumed, and their configure step resolves the iOS libc, which aborts without a full Xcode install

* Fall back to FIONBIO when Darwin's pty parent end rejects F_SETFL

- Some macOS releases return ENOTTY from fcntl(F_SETFL, O_NONBLOCK) on the posix_openpt fd while the FIONBIO ioctl succeeds; the shared setNonblock helper tries fcntl first and falls back, so a spawn no longer fails whole on those kernels

* Set the pty parent non-blocking only after the replica opens

- Some Darwin kernels answer ENOTTY to both fcntl(F_SETFL) and FIONBIO on a pty parent whose replica has never been opened, and accept the identical call once it has; the spawn now orders the non-blocking step after the child end opens

* Scope the AltGr chord exemption to Windows and keep an armed selection on its text

- Ctrl+Alt is a genuine command chord on Linux and macOS (AltGr rides its own level-3 shift there), so the text gate exempts the pair on Windows alone - a chorded key mid-composition now reaches the app instead of being swallowed
- Output that scrolls the live screen rebases the keyboard selection from the emulator's absolute pins: the caret follows the selected text, and a range that leaves the viewport clears selection mode instead of desynchronizing copy from the caret

* Arm the cancel-to-commit grace only while a composition owner is pinned

- A duplicate cancel (the hosts' synthetic disarm for a consumed cancelling key) arrives after the grace probe already released the owner; re-arming ownerless converted the next ordinary character into a dead-owner swallow, so the arm now requires a live owner

* Honor negotiated kitty modes for committed text and key releases, and admit one copy at a time

- Committed single-scalar text routes through the emulator's key encoder: byte-identical raw text under legacy modes, CSI-u under a TUI's report-all; multi-scalar IME commits stay raw per the protocol
- Key releases reach the encoder through an opt-in on_key phase (key_release_events), emitting kitty release events when negotiated and nothing under legacy; repeats stay presses, the one event type hosts do not distinguish
- A copy while the clipboard write is in flight is a no-op, so a duplicate-key rejection can never overwrite the first copy's success; the non-Latin Ctrl-chord gap is recorded as an accepted tail pending base-layout key data in the platform vocabulary

* Wheel scrollback, geometric box drawing, and a window that is just the terminal

- Trackpad and wheel scrolls over the grid ride a new on_wheel app channel (the pinch channel's sibling) into whole-row scrollback with fractional accumulation; inert while a selection is armed
- U+2500-259F render as geometry at exact cell bounds - lines, tees, crosses, doubles, quarter-arc rounded corners, diagonals, blocks, shades, and quadrants - with identical-piece runs merged into single bars, so borders join seamlessly where font glyphs showed seams
- The window is a standard titlebar plus the grid: header and status bar removed, size readout gone, keyboard hints moved to the README

* One seamless surface: hidden-inset chrome with the terminal running under the traffic lights

- The window drops its title and titlebar strip (hidden_inset): the theme background fills edge-to-edge including the titlebar band, the grid's text starts below the reported chrome inset, and only the traffic lights float over the terminal

* Shift the video tests' journal byte offsets past the appended pty trailer

- The pty record fields append 33 bytes after the video fields in every effect payload, so the hand-patching damage helpers now offset from the pty trailer

* Stitch the pty conformance fixtures after the video fixtures

- Two fixture-list merge points kept both families' cases in sequence; the video entries close before the pty entries begin
2026-07-24 07:57:38 -05:00
Chris Tate 501b59e490 Two-axis canvas scrolling with axis-aware routing (#190)
CI / Zig Core (push) Has been cancelled
CI / Linux Canvas Smoke (push) Has been cancelled
CI / Linux Dev Smoke (Debug scaffold) (push) Has been cancelled
CI / Windows Canvas Smoke (Wine) (push) Has been cancelled
CI / Windows Effects Smoke (Wine) (push) Has been cancelled
CI / Frontend Examples (push) Has been cancelled
CI / Mobile Examples (push) Has been cancelled
CI / Generated App Scaffolds (push) Has been cancelled
CI / macOS WebView (push) Has been cancelled
CI / macOS GPU Perf (push) Has been cancelled
CI / Linux WebKitGTK (push) Has been cancelled
CI / Windows WebView (push) Has been cancelled
CI / CEF Platform Tooling (push) Has been cancelled
CI / npm Package (push) Has been cancelled
CI / Native Examples (push) Has been cancelled
CI / Evals Typecheck (push) Has been cancelled
CI / Docs (push) Has been cancelled
Release / Check for new version (push) Has been cancelled
Release / Create GitHub Release (push) Has been cancelled
Release / Publish CLI to npm (push) Has been cancelled
* Make canvas scroll state and routing two-axis

- Widen ScrollState to eight per-axis fields (ScrollAxisState carries the physics), route each wheel axis independently to the nearest ancestor scrollable on that axis, and step kinetic motion per axis.
- Add the scroll axis declaration (attr 86 axis, attr 87 value-x, Widget.scroll_axes/value_x) through schema, markup validation, both engines, layout, clamping, reconcile, semantics, and the two-bar scrollbar renderer.
- Break the one-axis on-scroll record consciously: the reflect vocabulary, contract class, and both engines now teach the per-axis migration by field name, and the scroll-driver ABI/journal carry offset_x.

* Carry both scroll axes through hosts, docs, and the TS SDK

- Widen the macOS native scroll driver ABI to offset_x with a horizontal overlay scroller; GTK and Windows wheel handlers already forward delta_x.
- Update the TS SDK ScrollState to the eight per-axis fields and regenerate the markup vocabulary and scroll reference for axis/value-x.
- State the ScrollState break and its one-sentence migration in the changelog fragment.

* Pin two-axis scrolling with routing, driver, replay, and markup tests

- Cover the nested independent-axis routing case (dy to the vertical child, dx to the horizontal ancestor), the horizontal wheel/keymap/scrollbar paths, and per-axis driver sync with pinned ranges on ungranted axes.
- Ride a diagonal wheel through the reference record/replay session so a journaled two-axis scroll replays to identical per-axis offsets.
- Migrate the example apps to the two-axis ScrollState fields.

* Give the soundboard detail page a horizontal collection shelf

- Rail every other album under the track list on an axis="horizontal" scroll region: the grid's quiet-hover cover tiles, one press from record to record.
- Echo the shelf's offset_x into value_x (the controlled-scroll shape on the sideways axis) and reset the rail when an album opens.
- Teach the widget-wheel automation verb an optional delta-x token so drivers can scroll both axes like a real trackpad gesture.

* Harden two-axis scrolling per external review

- Keep the vertical scrollbar's thickness formula byte-identical (per-axis derivation), exclude anchored/clip-scope/concealed-disclosure subtrees from horizontal extents, and stop region-anchored surfaces riding scrolled content.
- Route macOS native wheel gestures by dominant-axis capability with an engine-wire fallback, and rewrite a queued driver report when a programmatic offset lands.
- Pick scroll semantics by live range on both-axes regions, page every granted axis on assistive steps, carry fling velocity per axis only while its offset survived, refine the axis/virtualized validation to the horizontal grant, and migrate bench_render.

* Split residual wheel axes on macOS and arm driver chrome per grant

- Forward the axis a locked native driver cannot travel to the wire, so one diagonal gesture scrolls a vertical list natively while its delta_x reaches the horizontal ancestor through per-axis routing.
- Carry the axis grants on the driver spec: elasticity and scroller chrome arm only on granted axes, so a horizontal-only region can never bounce vertically or report an offset the runtime would fight.
- Accept the optional delta-x token in the automation CLI, and warn at the builder seam when a DYNAMIC value pairs a horizontal grant with virtualization or value_x with a vertical-only region (both engines share the seam, so the diagnostic stays engine-uniform where validation cannot see the resolved value).

* Route every macOS wheel through the axis splitter and split set_offset per axis

- Stop the driver view claiming wheel events at hit test: the surface's dominant-axis selection, gesture lock, and residual-axis split now own all wheel routing, so a diagonal gesture over a nested vertical list cannot swallow the horizontal component its ancestor owns.
- Make the driver set-offset flag per axis end to end, so a programmatic vertical write can never push a stale horizontal offset over native motion whose coalesced report is still in flight.
- Teach the a11y focus-reachability audit the axis grants (offscreen-right tiles on a horizontal shelf are reachable, below-viewport content there is not) and bump the model-contract format to 2 - a format-1 artifact classified the retired one-axis scroll record as a scroll_state payload, which would be a false pass today.

* Pin the axis-aware focus-reachability audit

- A horizontal shelf's offscreen-right tile is reachable by design while a below-viewport button inside it stays a finding.

* Match native wheel routing to the engine walk and step the live axis

- Route each gesture axis to the deepest native driver that can consume its delta right now (direction-aware, so a saturated inner region hands an outward swipe to its ancestor), falling back to the outermost elastic region — rubber-band regions bounce even with short content — and reconcile the driver array in layout pre-order so keyed reorders keep the walk honest.
- Forward a residual axis only when the locked driver can neither move nor bounce on it.
- Assistive increment/decrement on a both-axes region whose only live axis is horizontal now step sideways instead of paging a zero-range vertical axis; pinned through the accessibility action path.

* Resolve wheel owners per axis with measured residuals and axis-keyed reach latches

- Replace the single-winner gesture lock with per-axis owner resolution at the gesture's anchor point, re-evaluated per event against live scroller offsets: saturation hands an axis to its ancestor (elastic-take never outranks a consumer), cross-owner diagonals whose native recipient would eat the other axis ride the wire whole, and the residual is MEASURED (delta minus what the scroller actually absorbed) so a nearly saturated region can never double-spend.
- Flush the coalesced driver report before any residual or cross-owner wire emission (offsets first, one clock), and route wheels over a visible overlay scroller through the same splitter instead of the knob.
- Key reach-end/reach-start hysteresis latches by (id, axis) so a region whose primary axis changes re-arms honestly.

* Flush driver offsets before the no-owner wire hand-off too

- Every wire emission now rides the offsets-first clock, including wheel events no native region owns.

* Size the collection shelf to actually overflow at desktop widths

- 168-point tiles keep seven sibling covers wider than the regular shell's content row, so the rail scrolls where it ships.

* Close the native-seam races and honesty gaps from the cycle-2 review

- Restrict wheel-owner resolution to the hit region's ancestor chain (parent driver ids through the ABI), anchor wire hand-offs at the gesture point, carry sub-half-point residuals across events, and wire-bind any region the engine scrolled this gesture so a later absolute native report can never erase relative wire motion.
- Skip subtrees anchored directly to the region in every VERTICAL extent walker (a stationary surface counted against a moving offset grew the range without bound), decide the assistive step axis from the semantics metrics (concealed-disclosure and anchored exclusions included), and page exactly one axis on widget-level semantic steps.
- Flag content stranded before a horizontal region's origin in both audits (offsets clamp at zero), double the reach-latch capacity for the (id, axis) key space, and fire reach signals only when the latch stores.

* Treat each discrete wheel as its own gesture

- Legacy (phase-less) events reset the wire bindings and residual carries per event, so a binding can never demote a region to the wire forever.

* Scope phase-less wheel gesture state to bursts, not events

- A quiet gap (250ms, well past the input queue's one-frame coalescing) is the gesture boundary for discrete streams: residual carries keep accumulating sub-half-point deltas and wire bindings outlive any in-flight relative hand-off, while a fresh burst still resets both so no binding lives forever.

* Honor overlays, phases, and revoked axes on the native wheel seam

- Push OCCLUDER rects (anchored floating surfaces at their frames, modal catchers as the whole view) with per-driver masks through the driver sync, so the host's geometric wheel routing declines exactly the points the engine's hit test would give to an overlay's branch; drivers inside the overlay stay exempt. Pinned through the null platform.
- Forward zero-delta phase events (begins, the terminal Ended/Cancelled) to the gesture's last native recipient so the scroller's overscroll bookkeeping always terminates, and scope residual carries to the hit region so fractional motion never leaks onto whatever chain the pointer wanders to next.
- Pin REVOKED axes home on native-driven regions too (the range clamp stays the OS scroller's), so an axis flip behaves identically on every host instead of resurrecting a stale echoed offset on re-grant.

* Make native wheel routing engine-exact: one owner or the wire

- One owner takes the WHOLE event natively and clamps at the edge exactly like the engine's consume-and-drop rule; split owners, dead axes, and wire-scrolled owners ride the wire whole — the residual measurement, fractional carries, and partial-clamp forwarding are gone, and consumption uses the engine's exact bounds.
- Zero-delta phase events forward only the gesture bookkeeping to the last native recipient; nonzero no-owner deltas go wire-only, so an overlay opening mid-momentum can no longer keep moving the obscured region.
- Fix the occluder model on every reported edge: view-local modal rects, tooltip passthrough, scrim=false previews, hidden/concealed surfaces, render transforms, self- and paint-order exemptions for anchored scroll regions, and a fail-safe whole-view occluder when surfaces outnumber the budget; both-axes semantic steps read child-frame range so the stepped axis matches the exposed semantics.

* Carry the two-axis scroll state through corewire's ABI seam

- dispatch_scroll_state now carries the eight per-axis scalars in declaration order; the retired one-axis quartet rides the generic record entry
- pin the new routing and the quartet's retirement in emit tests, and match the stub core's export to the widened symbol
2026-07-24 01:31:56 -05:00
Chris Tate 7563a4e61a Letterbox video to its stream aspect and anchor the example's status bar (#189)
* Letterbox the video surface: contain is its one fit mode

- The builder stamps contain fit and the LOADED report's stream dimensions on every media surface the video channel feeds; the emit computes the centered aspect-fitted quad over a black backdrop, so every host composites the same geometry with no fit math of its own
- Unknown dimensions pre-LOADED keep the full-frame placeholder draw (no guessed geometry, no divide-by-zero); a source replacement re-fits from the new report
- Paint-level pins: reference-rendered pillarbox/letterbox/exact-fit pixels and quads, the Ui stamp, and a null-platform end-to-end letterbox + re-fit test; the video doc states contain-by-default

* Anchor the video-player status bar full-bleed to the window edges

- The page padding wraps only the content column; the status bar is the root column's last child - flush left/right/bottom with its own padding and the token hairline separator, on both screens
- A layout test pins the full-bleed frame at the window edges

* Add the video contain-fit changelog fragment

- One fix fragment: contain-by-default letterboxing on the video surface, placeholder pre-LOADED, re-fit on replacement

* Scope stream geometry to the fed surface and keep the placeholder under the bars

- Stream dimensions ride a dedicated Widget.stream_size stamped only on the surface the active playback feeds - a source-less <video> beside a custom-surface load keeps its placeholder, and image_src keeps its source-crop meaning on every widget
- The letterbox paints black over exactly the remainder bars, leaving the deterministic id-derived placeholder under the picture quad for goldens and replay screenshots
- A bar-inset quad drops the radius mask (its corners sit in the bars) while each bar rounds only its outer corners, keeping a rounded surface's silhouette

* Harden the contain fit: diff coverage, seam-free quads, thin-bar masks, purge on video claims

- stream_size joins the widget diff's content comparison so a LOADED report alone invalidates retained paint, and the known-geometry draw stretches into the engine's quad - a decoder whose true dimensions round off the report can never open a host-side contain seam
- Bars thinner than the corner radius keep the frame's mask on the quad (a hairline bar cannot cover a rounded corner), pinned alongside the drop-the-mask case
- A video-channel claim purges the previous playback's retained texture (entry, host copy, repaint) so a replacement's new fit never composites the old stream's stale frame; generic producer re-claims keep the adoption-boundary dedup contract

* Draw the letterbox as a rounded black field with a tangent-masked quad

- The fitted shape is now three commands: black across the whole frame at the frame's radius (the silhouette, exact by construction - no per-bar corner approximation), the placeholder confined to the quad, and the picture quad
- The quad's mask is the tight inset radius max(0, corner - bar): internally tangent to the frame's corner circle, so hairline bars neither leak picture past the silhouette nor notch more corner than the silhouette demands
- A declared image_src crop drives the fitted quad's aspect - the crop is what draws, never flattened into the full stream's proportions

* Clamp the fit radius, clip crops to the stream, and end the picture on video release

- The tangent-mask math starts from the renderer-effective corner radius (clamped to half the frame's short side), so an unbounded style radius can no longer round a fitted quad into a circle
- A declared crop clips against the stream bounds before driving the quad's aspect, and the draw samples exactly the clipped region - an out-of-range crop never stretches its visible remainder
- The video-channel release purges the adopted frame: stop/replace/failure drop the surface's contain stamp on the next rebuild, and a retained freeze-frame would composite distorted under "no playback" chrome; pause and natural completion keep their claim and picture

* Keep crops off the fitted video draw and pin the binding's thread contract

- The fitted draw always samples the whole texture at the stream's aspect: DrawImage.src is adopted-texture pixel coordinates and the video texture's size is unknowable at emit (macOS budget-fits large decodes), so a stream-coordinate crop cannot be translated - crops stay a generic-producer facility in texture coordinates
- MediaSurfaceBinding is documented loop-thread-only on both halves: release purges loop-thread runtime texture state, matching its only callers (the video channel's update-dispatch paths); producer threads hold the sink, never the binding
2026-07-24 00:15:07 -05:00
Chris Tate dd9307656a Hover Msg bindings: on-hover-enter and on-hover-leave (#188)
* Add the hover-enter/hover-leave event pair to the markup vocabulary

- Registry events 11/12 (on-hover-enter / on-hover-leave): payloadless Msg bindings, legal on any element like the press family.
- Binding stamps Widget.hover_msgs — hover-hittable via the chart hover-details rule (no press claim, no wash, no a11y action) — and widgetHoverMsgChainFromNode collects nested listeners outermost-first for containment tracking.
- Both markup engines, the builder handler table (UiHandlerEvent.hover_enter/hover_leave), and parity/chain tests; the markdown arena canary's linear factor absorbs the larger Ui.Node.

* Track hover-Msg containment in the runtime and dispatch enter/leave

- Each view keeps a standing containment chain recomputed at exactly the wash-resolution seams (pointer phases, scroll re-hit-tests, layout adoption, rebuild and dismissal prunes), so hover Msgs and the wash never disagree; cancel is the window-leave edge and unbound apps keep an empty chain.
- UiApp diffs the chain against its delivered mirror at the tail of every runtime event — leaves innermost-first, enters outermost-first, leave Msgs captured at enter time so unmounted elements still deliver the pair; a pass cap bounds flapping apps.
- Tests pin nested containment, cancel, enter-that-unmounts, scroll-under-stationary-pointer, and record/replay determinism through the reference session's raw pointer moves.

* Prove the hover pair end to end over a transpiled TS core

- The markup fixture's task rows bind on-hover-enter/on-hover-leave with for-each payloads into a hoveredId mirror; payloadless events need no TS SDK type surface.
- The e2e test drives raw pointer moves through the null platform: enter with the row payload, row-to-row handoff, and the paired leave clearing the mirror.

* Document the hover pair and give notes a status-bar hover preview

- Markup reference, LSP/vocab doc tables, and the native-ui skill cover on-hover-enter/on-hover-leave: containment semantics, the pairing guarantee, wash separation, and the touch-honesty note.
- examples/notes: hovering a note row previews its title, age, and word count in the status bar without committing the selection, with a real-pointer test.
- Changelog fragment for the feature.

* Harden hover-Msg capture, delivery, and the touch-honesty gate

- Captured leave Msgs deep-copy their payload slices into slot-owned bytes (a standing hover outlives the build-arena pair), with live-tree fallback for payloads the budget cannot own; enters resolve from the live tree per edge.
- Containment advances only while a hover-capable pointer is live (a hover-phase move, which touch contact cannot produce), so taps, scrubs, and post-fling re-hit-tests never synthesize hover while mice keep full click/drag fidelity.
- Delivery degrades per edge (one failed dispatch no longer swallows sibling edges), the drain also runs on a handler's error path, and a transiently missing handler tree defers the transition instead of consuming enters as silence.

* Close the hover delivery seams: direct dispatches, pointer identity, and unbounded captures

- Public dispatch and drainEffects settle hover edges at their own tails (re-entrancy guarded), so direct dispatches deliver an unmounted element's leave without waiting for a platform event; drain passes degrade per pass and the flap cap is sized past any honest cascade.
- The hover-capable proof is scoped to the pointer identity that earned it, and a consumed secondary-stream cancel retires containment like the tooltip machine's pointer-left-view reading — a touch contact can never ride a mouse's proof on hosts that distinguish pointers.
- Leave captures are arena-backed (any payload size) and the standing view label is copied out of runtime storage before dispatches that can compact the view array.

* Anchor hover containment to the proven pointer and reserve a touch id bit

- A proven pointer's wheel refreshes the chain's re-hit anchor before the scroll reconcile, so a wheel arriving ahead of its coalesced motion event derives containment from where the pointer really is.
- platform.touch_pointer_id_bit rides the existing pointer_id field: hosts stamp touch-sourced events and the runtime refuses hover proof to stamped ids, so an OS-synthesized mouse-shaped float for a tap can never make touch hoverable; host-side stamping call sites are documented at the bit.
- Dismiss events drain hover edges at their tail (the automation dismiss verb dispatches one standalone), and the leave-capture copier handles error sets, error unions, and vectors.

* Make hover containment per-listener and its captures slot-owned

- The mirror diff is an id-set diff with capture slots decoupled from chain position: an outer listener unbinding (or binding) while an inner one stands dispatches edges for the changed id only — the retained entry never flickers and keeps its captured leave.
- Point-blind scroll re-hit-tests use the proven pointer's own anchor, so containment hands off correctly even after another device cleared the shared pointer position.
- Allocation failure while capturing a leave defers the enter (and the entering tail) to the next drain instead of dispatching an enter whose paired leave is already lost; the copier's non-transient refusal narrows to single-item pointers.

* Close the enter/leave pairing seams: platform window-leave and tree currency

- GTK connects the motion controller's leave signal and Windows arms TrackMouseEvent per hover session, both emitting the pointer cancel macOS already sends from mouseExited — window-leave retires hover state on all three desktop hosts (press-in-flight streams settle through their own release/capture change).
- Rebuild and slot-rebuild wrap in one currency invariant: a failed build or publication marks the handler trees stale, entering edges defer until a rebuild lands (never resolving through a tree the runtime refused, never consumed as absent), and captured leaves dispatch regardless — a broken destination cannot withhold them.
- Standing captures refresh whenever the build generation moves — a leave handler added mid-hover is captured before an unmount needs it, payloads deliver their latest binding, and unbinding retains the last capture; pinned by late-bind, failed-publication, and recovery tests.

* Refine hover currency to per-tree families and harden capture copies

- Tree currency splits per family: a main-only rebuild can never restore currency for a secondary-window tree whose publication failed — only a clean pass over the slots does — and every drain gate resolves the flag for its own destination.
- Capture refresh is copy-then-swap into a spare slot, so a failed allocation keeps the still-valid capture it was replacing.
- The slice copy preserves the payload type's own alignment and sentinel, pinned end to end by a builder-only app binding a 64-byte-aligned leave payload through capture, unmount, and delivery.

* Carry slot-rebuild bookkeeping everywhere and honor host pointer hand-offs

- Every slot rebuild path — the full pass and the direct resize/install sites — stamps the slot family stale on failure and ticks the build generation on success; only the clean full pass restores currency.
- The GTK click gesture wires cancel: a transferred or broken grab rolls a pipeline-visible press back with a pointer cancel (a drag-claimed press rolls back silently), so a stale pressed flag can never suppress later leaves.
- Windows WM_MOUSELEAVE skips the cancel while the cursor is still inside the client rect — the HTTRANSPARENT window-drag hand-off, not a real departure — so entering a hidden-titlebar drag header freezes hover instead of dispatching false leaves.

* Stamp hover currency at the install window itself, per tree

- Staleness marks exactly the window between publication and handler-tree adoption: a build or layout failure keeps the old, still-matching pair current (edges flow even when an idle app performs no further rebuild), and post-install follow-up failures never defer.
- Each window slot carries its own currency, so one window's failed publication never defers hover into its siblings, and that window's own next successful rebuild restores it wherever it was driven from.
- Capture-refresh allocation failures surface through the dispatch-error machinery instead of being swallowed; tests pin the enter-only deferral, leaves-never-wait, and build-failure-keeps-pair-live paths.

* Open the hover staleness window at adoption and bound capture indirection

- The currency stamps sit immediately after each setCanvasWidgetLayout: publication rejection is validated-then-atomic, so a refused chrome build, oversized-text rebuild, or slot budget overflow keeps the old still-matching pair current instead of deferring hover enters indefinitely.
- The leave-Msg copier bounds slice indirection (64 hops): a cyclic value graph refuses as unsupported instead of recursing toward allocator exhaustion or stack overflow.

* Track adoption exactly, drain standalone edits, and refresh captures per transition

- The currency stamp keys on a per-view adoption counter incremented the moment copyWidgetLayoutTree replaces the retained tree, so a failure in the publication pipeline's post-adoption steps still marks the pair stale while a validated-then-atomic rejection never does.
- Standalone keyboard events (accessibility selection edits, context-menu cut/paste/select-all) carry a flag the hover drain honors at their own tail — an edit that unmounts the hovered listener no longer waits for an input cycle that never comes.
- Leave captures refresh at every rebuild commit, not just at drain time, so two dispatches in one cycle (payload moved, then unmounted) deliver the latest binding; a proven pointer's consumed secondary release outside the view retires containment — the leave the frozen right-drag stream suppressed.

* Keep capture slots leak-free and refuse unownable hover pairs whole

- The enter loop and the unwind release any slot a mid-batch capture refresh installed before assigning or dropping a position, so repeated re-entry with rebuilding edge handlers can never exhaust the slot budget; pinned by a 40-cycle churn test asserting zero slots held after exit.
- An unownable leave payload (a single-item pointer) now refuses the PAIR: the enter never dispatches, the exit owes nothing, and the refusal settles with one warning instead of retrying every drain — no enter without a deliverable leave.
- Capture-refresh failures at rebuild commits land in the dispatch-error ring, so a stale payload delivered after a swallowed allocation failure can no longer hide behind rebuilds that reported success.

* Size the capture pool for both transition populations and stamp adoption at the tear

- The slot pool covers the departing chain's held captures plus a fully refreshed standing mirror plus one swap slot, and claiming degrades like allocation pressure instead of trapping if the accounting is ever wrong.
- The adoption witness moves inside copyWidgetLayoutTree at its destructive boundary, so a per-node failure mid-copy (an invalid command name escapes the pre-validation) counts as adopted-and-torn while up-front rejections leave it unmoved.
- A leave rebind no copy can own on a STANDING element warns once and degrades to live-tree resolution (a later ownable rebind upgrades), and sentinel-terminated array payloads capture with their sentinel stamped; both pinned by probe-app tests.

* Give hover containment its own hit-test policy and a half-open outside test

- Hover-Msg listeners are invisible to the interactive hit test (wash, cursor, press routing, text selection) and resolvable only through the new hover-containment policy, so binding hover provably never paints a wash or steals a click — even from an overlapping sibling; pinned by a probe asserting the interactive hit test finds nothing where the containment chain stands.
- The consumed-release outside test uses the engine's own half-open rectangle containment, so a release at exactly the right or bottom edge retires the chain like every hit test already treats that point.

* Resolve hover state by view identity and prune with the hover predicate

- Hover capture refresh and drain lookups key on window id plus canvas label, so a replacement window reusing a closed window's label (even with identical structural ids) can never answer for its predecessor's captures.
- Chain pruning uses a hover-specific survival predicate — a hover-only listener is never evicted into a false leave, and a widget whose hover bindings a rebuild removed stops standing — and a torn mid-copy failure prunes containment against the partial tree so owed leaves dispatch at that failure's own drain.
- Windows WM_MOUSELEAVE suppression requires the point's owner to be one of the child's own ancestors (the HTTRANSPARENT hand-off signature): an overlapping sibling pane taking the cursor is a genuine departure and cancels.

* Own the dispatch-error event name and bump the journal semantic epoch

- DispatchError keeps its event name in inline storage with an accessor (the detail pattern, 64-byte cap): records are copied by value into a ring that outlives every caller's buffer, so a name recorded through reusable storage can never dangle; pinned by a clobbered-buffer test and every consumer swept to the accessor.
- Reserving pointer-id bit 63 as the touch-source stamp changes a journaled field's meaning: the session journal's semantic epoch bumps 3 to 4, so older recordings refuse with the standard re-record teaching; the changelog states the conscious break.

* State the secondary-stream scope honestly in the input comments

- Only the secondary down/up/cancel stream is consumed: hosts report drag motion without a button, so containment follows a right-drag on the primary path (the mouseenter/mouseleave convention), exactly as the wash does — the comments now say so instead of claiming a freeze.
- The GTK leave handler's suppression comment scopes itself to click-gesture presses and names the settling paths (release, gesture cancel, the runtime's outside-release check).

* Teach the markup fixture sidecar the hover pair

- The hand-written contract sidecar (the schema's independent ground truth) gains the hoveredId model field and the hover_row/hover_off f64 arms in declaration order, so the corewire mirror stays fingerprint- and contract-byte-identical to the transpiled lane.
- The facade wire-tag pins move with the union: zoomed sits at tag 11 behind the hover pair.

* Retire containment when a proven primary release lands outside the view

- A captured drag's release beyond the surface clears the chain and the hover proof instead of re-hit-testing: hosts held a grab through the drag (no motion-leave fired) and send no later cancel, so an overflowing listener could stay entered off-view and a parked off-view anchor could re-enter one on a later rebuild.
- The primary rule mirrors the consumed secondary release; pinned by a down/drag-out/release-out test asserting the delivered leaves, the empty chain, and the retired proof.
2026-07-24 00:09:50 -05:00
Chris Tate 87fa3f92d0 Video playback: AVFoundation through the media surface, replayable end to end (#184)
* Add the video playback tier: platform seam, effects channel, journal v9

- One video channel mirroring audio end to end: loadVideo with the local-then-URL cascade and surface claim, transport verbs (play/pause/stop/seek/volume/mute/loop), key-stamped events, honest failed/rejected degrades, and automation-snapshot mirrors
- Pixels never enter the core: the platform decoder pushes RGBA8 through a copyable VideoFrameSink into the media-surface texture channel the load claimed
- Journal format v9: the .video effect-result kind (code 13) and platform-event tag (code 25) append the video fields after the v8 channel fields and journal every event verbatim for byte-identical replay with no producer attached

* Cover the video tier: lifecycle, frames, teardown, replay identity

- Fake and real executor batteries mirror the audio suite: request capture, event round trips, transport mirrors, rejection classes, cascade order, staged-host degrade, straggler swallowing, and the quit-while-playing stop hook
- Sink coverage proves decoded frames reach the claimed surface, replace/stop release the claim, and a stale sink push lands inert
- A recorded playback replays byte-identical into a decoder-less host with no producer attached, fingerprint and model equal; journal codecs round-trip the video event and effect shapes

* Export the video effect types and decline video on the embed host

- native_sdk.EffectVideo/EffectVideoEventKind/EffectVideoSource ride the SDK roots like their audio twins
- The mobile embed host declines video_playback until a shim registers a real decoder, the audio honesty rule

* Decode video on macOS with AVFoundation; teach on Windows and Linux

- One AVPlayer in the AppKit host: AVPlayerItemVideoOutput frames fitted to the sink's pixel budget, BGRA-to-RGBA vImage swizzle, a 1/60s run-loop frame pump plus the audio tier's 0.5s position clock, loop wraps without a completion, and paused seeks still paint their frame
- The frame sink crosses the C ABI as a callconv(.c) trampoline over the runtime's VideoFrameSink; a released claim answers 1 and the host stops its pump
- Windows and Linux stage the capability honestly: video_playback reports false and the load verbs answer a named teaching plus error.UnsupportedService; the CEF host stubs the video C ABI like audio

* Add Cmd.videoLoad and videoCtl to the TypeScript tier at opcodes 0x17/0x18

- videoLoad claims the named media-surface, resolves the local-then-URL cascade, and bakes autoplay/loop/muted into one flags byte; videoCtl drives play/pause/stop/seek/volume/muted/loop by verb ordinal with an f64 value
- The event arm is the seven-field record matched by NAME with the exact five-member state union both directions, the audio arm convention; refusals teach with the NS1027/NS1029/NS1030 vocabulary
- The host routes events on the TSVI key namespace, parks loads under the fake executor like audio, and covers the wire byte-for-byte in the package, host, and e2e suites

* Declare video from markup: the <video> element, house chrome, reconciler

- Element code 68 with flag attrs controls/autoplay/loop/muted at codes 82-85 (src rides the existing attr name; registry law keeps names unique); a leaf on all three surfaces — validator, interpreter, compiled engine — rejecting children like image
- ui.video composes the playback surface on the framework-owned surface id plus runtime-consumed transport chrome (ghost play/pause, proportional scrub slider, clipped time readouts in the built-in bar's register); presence IS playback: the ui-app reconciler loads on src change, applies loop/muted deltas, and stops when the element leaves the view
- Handler-less playback stays honest under replay: platform video events steer the channel mirrors while journaled effect records remain the only Msg source, so house-chrome sessions replay with live readouts and identical fingerprints

* Scope declarative video ownership to the playback it started

- The reconciler stops or retunes the channel only while the active key is the declaration's own: an update handler that loaded its own playback owns the single player, and a departing <video> element must not kill it

* Add the video-player example: house chrome and custom controls

- Player screen is one declarative ui.video with the house transport chrome; Custom screen composes its own bar (transport, +/-10s, proportional scrub, volume, mute, loop) from the command vocabulary over a bare media surface
- No bundled media: the launch argument or the source field names a local clip or http(s) URL, so a live macOS check is one command away
- Headless tests drive the whole transport with the fake executor's synthetic events, the automation widget path, and the null decoder behind the declarative screen

* Document the video element across the docs surfaces

- Components page, catalog entry, native-ui element table row, and the LSP/vocab doc strings for src/controls/autoplay/loop/muted
- Deterministic preview scenes render the placeholder with the house chrome (regenerated video webps only; the untouched catalog keeps its committed renders)
- Changelog fragment states the new element, the command vocabulary, the staged platforms, and the journal v9 break

* Resolve video attribute docs in the markup LSP hover path

- attributeDoc consults the video scoped table so controls/autoplay/loop/muted hover like every registry attribute; the coverage pin now names the video composite

* Make the video-player example's docs and status line honest

- README run instructions use the real CLI verbs: native dev for build-and-run, or native build plus the zig-out binary with the clip argument (the argument passthrough shape)
- The status line now matches each screen's ownership model: the declarative Player screen shows a static teaching (its transport state lives in the runtime-owned chrome, so an event-fed status there could only lie or stall), while the Custom screen keeps the event-fed loading/dimensions/finished/failed line it owns; tests pin both across load, playback, pause, and completion
- Direct-SDK examples handle the runtime's video event in their exhaustive event switches

* Stage video events non-lossily and deliver fed terminals under replay

- Video events leave the lossy pending ring for their own non-lossy stage (the image/channel discipline): a loop-side .rejected or .failed is its load call's only terminal and a fed event is one recorded delivery, so a burst past the ring's capacity must never evict one — pinned by a 40-rejection burst test
- Fed events capture the handler at feed time and deliver their journaled values verbatim when the channel no longer resolves them: under replay the platform .failed event that follows the record applies the channel reset first, and delivery-time resolution silently dropped the Msg the recording dispatched — pinned by a recorded mid-playback failure replaying fingerprint-identical
- loadVideo's deterministic refusal classes extract to the pure videoLoadRejected, one source of truth a caller-side validator can consult

* Refuse an invalid video_load before it re-routes the bridge entry

- The engine keeps the current playback when it rejects a load, but the bridge re-keyed its single routing entry optimistically first: a refused replacement left the surviving stream's events and transport verbs answering to the refused key and arm
- The bridge now consults the engine's own videoLoadRejected gate before committing the entry and stages the rejection Msg to the refused arm directly (stageLoopMsg, the channel-admission precedent), leaving the entry and the engine untouched
- Pinned: a rejected replacement delivers its rejection while the live stream keeps its events and its wire-key gate

* Drive the house video chrome from keys and rebuild it in every window

- Keyboard activation (Enter/Space) of the transport's play/pause control now drives the video channel exactly like the pointer release: the control advertises Play/Pause to focus and accessibility, so the intent must act instead of being consumed silently — pinned beside the pointer-toggle test
- Runtime-consumed control paths and handler-less video events rebuild through one helper that follows dispatch's discipline: the main canvas against ITS window (a control event from a secondary window used to target that window with the main canvas label and error) and the window slots after it, so a <video controls> declared in a secondary window's tree repaints from the moved mirrors

* Fail a macOS video load whose conversion buffer cannot allocate

- The frame tap's reusable BGRA-to-RGBA conversion buffer failing to allocate used to degrade to a silent zero-frame pump while the load still acknowledged LOADED: playback reported positions forever and could never deliver a pixel
- videoAttachOutputForItem now reports the failure and the status hop answers with the FAILED terminal instead of the acknowledgment - the honest degrade; an audio-only item (no video geometry) keeps its documented honest-absence path

* Journal handler-less video terminals and quarantine stale fed events

- Loop-side video terminals now stage and journal with no Msg handler bound (the image arm's rule): a declarative playback binds no handler, but its synchronous .failed is executor truth — the record is what replays the channel reset, and the staged delivery's wake re-renders the chrome
- A fed event whose staged key no longer names the live playback (replaced before its drain, or a replayed platform .failed already applied the terminal) delivers its staged values verbatim and leaves the live channel alone — applying a replaced stream's terminal would reset the replacement
- A journal-fed video record claiming a millisecond or dimension scalar at or past 2^53 refuses replay as a damaged record at the gate (no recorder writes one, and the TS tier's exact-integer widening would trap on it) — pinned by a hand-patched journal

* Route every video event by the key of the load that produced it

- The bridge's engine key now carries the issuing load's event-arm tag in its low byte (videoKeyForTag): a staged synchronous .failed that delivers AFTER a replacing load re-keyed the single entry still routes the arm of the load it answers, instead of handing the old stream's failure to the replacement's arm
- videoEventMsg routes by the event's own key tag, never the mutable entry's; the wire-key gate on transport verbs is unchanged
- Pinned: a replaced load's straggling terminal routes its own arm while the replacement's stream keeps its own; the request-key pins move to the tagged shape

* Reconcile <video src> from every window's tree and repaint Msg-less failures

- Secondary-window builds now feed the video reconciler: Ui.video promises that declaring the element IS the playback in every window's tree, but slot builds discarded the declaration — the main canvas wins when both declare (one player, one owner), the first declaring slot keeps ownership until it stops declaring or its window closes (reconcile-close included)
- The main build stamps the video mirrors it rendered; drainEffects compares that stamp after a Msg-less drain and re-renders the chrome when they moved — a handler-less declarative playback's synchronous failure no longer leaves controls advertising a playback that is gone

* Paint the poster frame for paused macOS video loads

- A load acknowledged while paused (autoplay = false, the documented poster-frame shape) ran no frame timer and never pumped its first decoded frame: the surface held the placeholder until the user played, paused, or seeked
- LOADED now arms a bounded first-frame hunt: the frame timer polls until the first frame pushes (a paused load then stops the timer; a playing one keeps it), surrendering honestly after ~3s if the output never yields one

* Restart the macOS frame timer when buffered playback actually begins

- The poster hunt could stop the pixel clock while AVPlayer was still waiting to play (a remote autoplay stream yielding its poster mid-buffer, or a hunt surrendering past its bound), and nothing restarted it when the waiting phase ended: audio played and positions ticked with no frames flowing
- The timeControlStatus hop now arms the frame timer whenever playback reports rolling (idempotent beside videoPlay's own arm), for local and remote sources alike

* Deliver a staged video terminal past stop instead of panicking

- A Cmd.batch([videoLoad, videoStop]) on a host whose load fails at once stages the .failed before stop retires the bridge entry; the drain then hit the entry gate's panic even though the terminal is the load call's only answer
- videoEventMsg drops the entry gate: every event reaching it was produced by a bridge-issued load and carries its arm tag in its own key (the engine swallows its post-stop stragglers itself), so routing needs no entry at all - pinned by the load-then-stop batch shape

* Retain every window's video declaration and promote on the owner's close

- The reconciler kept only the owning window's <video src>: closing that window (or its declaration vanishing) stopped playback and left another window's mounted video inactive until an unrelated rebuild
- Slot declarations now retain one entry per window (the table matches the window budget); when the owner closes or stops declaring, the next retained declaration promotes inside the same dispatch - pinned by a two-window close-promotes test with no on_close Msg and no rebuild

* Retry the frame wake for identical pushes still awaiting adoption

- A refused frame-wake request leaves pending clear so a retry can land, but the push-boundary fingerprint short-circuit returned before the wake: a static frame pushed again after a transient request_frame_fn refusal short-circuited forever and the staged bytes were never adopted
- An identical push now falls through to the wake while bytes are still staged; only an adopted frame's repeat stays a pure no-op

* Expose videoPlayback through the bridge alias and the TS feature type

- platformFeatureFromString gains the videoPlayback camel-case alias every other feature carries, so window.zero.platform.supports("videoPlayback") answers the platform truth instead of InvalidPlatformFeature
- NativeSdkPlatformFeature adds video_playback/videoPlayback so TS clients can compile the support query

* Stamp every platform video event with the load that produced it

- The engine mints a token per loadVideo, passes it through the load seam, and every host echoes it in each event: takeVideoMsg swallows an event whose token is not the current load's, so a replaced playback's queued terminal can neither reset the replacement, release its claim, nor route through its handler - pinned by a stale-failed-after-replace regression
- macOS hardening on the same theme: the item end/failure notification blocks re-check note.object against the current item (a removeObserver cannot recall a block already enqueued on the main queue), and the host carries the token across its terminal emits' teardown
- The journaled video platform event carries the token, so replay's mirror steering swallows stale recorded events exactly as live (the re-run loads mint the same deterministic sequence); the null platform echoes tokens like the real hosts and its fake position advance saturates instead of trapping on hostile deltas

* Pair replayed video deliveries with their events; token-gate fed entries; stop abandoned players

- A recorded video Msg dispatched synchronously inside its platform event's dispatch, but replay delivered the fed record at the NEXT drain: an update loading the next clip from its completion handler ran too late and the new clip's .loaded event was swallowed against the old load's token - takeVideoMsg under replay now pops the fed head (the journal's contiguity puts each event's record immediately before it) and dispatches it during the same event, pinned by a chained-load playlist session replaying byte-identical
- Pending video entries carry the load token that staged them, and delivery resolves against the live channel only while it still IS that load: the public key alone cannot tell two loads under one app key apart, and a stale fed terminal resolving against a same-key replacement would have reset it
- failVideoChannel silences the platform player it abandons (best effort): a load that succeeded before a later step refused kept its player decoding while the reset channel forgot it, and the inactive channel skipped it at teardown too

* Keep refused and uninstalled declarations out of the video reconciler

- A declared src the engine's own gates refuse (a malformed URL, say) no longer commits the reconciler's tracked ownership: the running playback keeps its identity - so removing the element later stops IT, instead of hashing the refused source and stranding the playback forever; the refused src is remembered separately and taught once, never re-attempted every rebuild - pinned by a refused-declaration ownership test
- A secondary window's declaration is captured only after its build pass and layout succeed and the tree installs: a build whose layout errors never displays, so its declaration never steers the playback either

* Link CoreVideo wherever appkit_host.m builds standalone

- The frame pump's CVPixelBuffer calls are real CoreVideo symbols: the central build gained the framework, but the generated-app template and the standalone example builds still linked only AVFoundation - a generated macOS project failed to link
- The template and every example build.zig that compiles the AppKit host now link CoreVideo beside AVFoundation

* Gate the poster hunt on a real push and clamp millisecond CMTimes

- videoPumpFrame initialized its push result to the success code, so a NULL base address or failed vImage permutation ended the poster hunt and stopped the frame timer with nothing on the surface; a sentinel now keeps the hunt alive until a push actually returns success
- NativeSdkCMTimeFromMs narrowed the u64 millisecond position straight into the signed CMTimeValue, turning absurd seeks negative; the value now clamps at INT64_MAX so AVFoundation clamps to the duration as documented

* Retire the null video player when a non-looping playback completes

- advanceVideo left the fake player loaded after its completion, so post-completion transport calls succeeded where a live host's torn-down player refuses them (and a replayed play could emit a second completion)
- the completion now unloads before the event returns, matching the live hosts' retire-before-emit order; tests pin the unload and the failed-play degrade path

* Stop the custom playback when an empty source commits

- loadCustom returned early on an empty committed source, leaving the previous video rolling under a status line that said "no source"
- an empty commit now stops the playback and resets the transport mirrors, with a test pinning the stopped channel and the honest status line

* Route replayed video records by the journaled load identity

- Every .video effect record now carries the producing load's token; replay feeds through feedVideoRecord, which resolves the token against the live channel or a retired-load park instead of binding the record to whatever the channel holds at feed time.
- loadVideo and stopVideo park the outgoing load's identity under replay, so a synchronous terminal staged inside the very dispatch that then replaced or stopped its playback still delivers the recorded Msg with the recorded identity - never EffectNotFound, never a reset of a same-key replacement the recording kept playing.
- The replay pairing in takeVideoMsg now token-gates fed entries against the platform event, and two session tests pin the batch shapes: load-then-stop and load-then-replace under one app key.

* Check the Core Video lock result before touching the pixel buffer

- A failed CVPixelBufferLockBaseAddress never maps the buffer, so reading the base address was undefined and the unconditional unlock unbalanced the lock count; the frame now drops with the buffer released.
- The poster hunt stays latched across the dropped frame - only an actual push verdict may end it, the converted-but-unpushed rule.

* Document why rate > 0 is transport intent at the playing derivations

- Per the AVPlayer.h contract, a playback waiting in AVPlayerTimeControlStatusWaitingToPlayAtSpecifiedRate keeps rate at the requested value ("not currently effective but instead indicates the rate at which playback will start or resume"), so a stalled-but-unpaused stream already reports playing=1 + buffering=1 and the transport control offers Pause.
- AVPlayer resets rate to 0.0 on its own only with waits-to-minimize-stalling disabled - the local-file configuration, where playback would not self-resume and offering Play is the honest affordance.

* Keep the controls-bearing video element zero-intrinsic

- The <video controls> wrap column now adopts the media sizing contract (WidgetLayoutStyle.zero_intrinsic): the transport bar's intrinsic size never leaks into the element, so an unsized element in a hug container measures zero like the bare surface instead of rendering a controls-only strip.
- The wrap clips its content, so chrome cannot paint past a box the layout granted nothing; declared width/height stay definite through the frame and min/max bounds.
- A ui test pins both shapes: zero in a hug container, surface-above-bar inside a declared 320x180 box.

* Bound video scalars at delivery, sweep replay parks, republish flag deltas

- Platform video events clamp position, duration, and dimensions into the exact-integer delivery window (max_effect_video_scalar_exclusive, 2^53) at takeVideoMsg, whatever a host or embedder reports - the engine-side guarantee behind replay's damage gate, so an honest recording can never be refused as damage; a past-window readout now records and replays clamped, pinned by test.
- Replay-side retired video identities release at the first drain-pass boundary after parking (any journaled record for them feeds before that pass's event dispatches), so a long replayed playlist parks and releases one entry per clip instead of accumulating them; pinned at the channel level.
- Same-src declarative loop/muted deltas republish the runtime mirror in the same reconcile, so an automation snapshot taken after the flip reports the new value instead of the one published before the rebuild.

* Journal the video cascade's resolved source for replay

- loadVideo now journals a Msg-less .video_load record (the .clock/.env discipline) carrying which source the recording host's cascade resolved - a missing local file that fell through to the url is filesystem truth the replayed fake load cannot re-probe.
- Replay queues each record and the replayed load consumes it by its deterministic token, so videoSnapshot() and the automation mirror report .stream with the optimistic buffering flag exactly as the recording did, handler-less declarative playbacks included.
- Pinned by a record/replay test on an assets-absent host; the handler-less house-chrome pin now expects exactly the one Msg-less record.

* Keep buffering honest across paused streams and widen the fake's loop wrap

- Buffering means an un-paused stream waiting for bytes: a fresh URL load now starts the flag from the autoplay intent (engine mirror and replayed cascade resolution alike), the macOS host derives it purely from timeControlStatus instead of presetting it, and pauseVideo clears it - a conforming host emits no pause acknowledgment that could.
- The macOS time-control observer stays silent when the transition lands on paused: pause emits nothing by contract and position reports are for playback in motion; waiting and playing transitions still emit.
- The null platform's advanceVideo runs its loop wrap in widened arithmetic so a past-u64 delta lands on the exact residue instead of a saturated one; pinned along with the paused-stream and pause-clears-buffering shapes.

* Spill the replayed cascade-resolution queue past its inline capacity

- Loads per dispatch are unbounded by contract and every .video_load record lands before the dispatch's event, so the replay-side queue now grows geometrically past its inline 64 (freed when it empties and at deinit) instead of refusing the 65th record as a false divergence - the pending stages' non-lossy discipline.
- Pinned by a record/replay burst one past the inline capacity on an assets-absent host.

* Cross-check the journaled key on every replayed video pairing

- Reminted tokens pair records with replayed loads by position; the journaled key now proves the load at that position is the one the recording issued - feedVideoRecord refuses a mismatch as divergence, and a cascade resolution consumed under a different key latches one for the finish check.
- Replay now ends with a consistency check (the .finish replay control): a structurally valid journal whose queued cascade resolutions the replayed timeline never claimed fails as ReplayEffectDivergence instead of reporting success.
- Pinned at the channel level: wrong-key feeds refuse, an unclaimed or misclaimed resolution fails finishReplay, and the honest pairing stays silent.

* Copy the captured video declaration and verify the load bijection under replay

- The main-canvas <video src> capture now copies the source out of the build arena into app-owned storage (the slot captures' rule): a later failed rebuild resets the arena the old capture borrowed, and a window-close reconcile could hash or load overwritten bytes.
- Every non-rejected real load now journals exactly one .video_load record - refused cascades included (failVideoLoad) - so the replayed loads and the journaled records form a bijection: a replayed load with no record at its position, and a record whose position was never issued, both latch divergence for the finish check.
- The journal semantic epoch bumps to 2: identical bytes, changed replay meaning - an earlier recording's failed loads would replay as false divergence, so old journals refuse with the re-record teaching. Pinned: the extra-load shape fails finishReplay and the captured src aliases the app-owned buffer.

* Run the replay finish check even when no records were fed

- A latched video-load divergence can exist with zero fed effect records (the recording journaled nothing; the replayed timeline loaded anyway), so the end-of-journal consistency check now runs unconditionally; hookless apps answer ReplayUnsupported, which is honestly nothing-to-check.
- Pinned: a zero-record recording replayed into a build that declares a video fails as ReplayEffectDivergence instead of reporting success.

* Refuse non-http(s) schemes at the videoLoadUrl seam

- The seam documents streaming-only and promises to reject bad arguments before the platform is asked, but forwarded any scheme - a direct caller could hand file:///... to a host whose media stack opens it (AVPlayer does); the scheme gate now holds at the seam for every caller, matching the engine's own load validation.
- Pinned: file:, ftp:, and unparseable URLs refuse as InvalidVideoOptions without reaching the platform; https passes.

* Retire the null platform's video player before the load probes refuse

- The macOS host stops the previous player before the file-existence probe, so a refused load leaves no playback behind; the null platform now models the same ordering in videoLoad and videoLoadUrl instead of returning early with the replaced player still emitting frames and events under its old token.
- Pinned: a VideoSourceNotFound load leaves nothing loaded, no pending acknowledgment, and no position ticks.

* Fail frame-less video loads and keep the seek mirror on platform truth

- An asset with no video geometry (an audio-only file loaded as video) now fails the load instead of acknowledging a playback that can never paint - sound over a permanently blank surface is the same broken promise as the conversion-buffer failure the attach path already refuses.
- seekVideo applies the platform seek before moving the mirror: a player the host already retired (a completed non-looping playback) refuses the call, and the snapshot and house slider must stay on the frame actually on the glass; pinned in the post-completion transport test.

* Refuse post-completion seeks on the fake video channel too

- A non-looping natural end retires the platform player (retire-before-emit), so a later seek refuses live and the mirror keeps the terminal position; the fake executor now latches the completion and refuses identically, so replayed chrome and snapshots land exactly where the recording left them instead of scrubbing a player that no longer exists.
- Pinned by a record/replay parity test: a scrub after the natural end keeps position at the duration on both sides, model and fingerprints identical.

* Pair replayed video deliveries from any stage position; stop cancels the TS stream

- The replay pairing in takeVideoMsg now scans the pending stage for the event's fed entry instead of checking only the head: a regenerated loop-side rejection staged earlier in the same dispatch keeps its own drain-time order and no longer reverses the recorded Msg order; pinned by a record/replay ordering test.
- VideoMsgFn may return null - the adapter tier's cancel gate - and the TS bridge uses it to honor Cmd.videoStop's wire contract (stop CLOSES the stream, no events for the key after this): a staged synchronous terminal from the very batch that stopped the stream drains through the engine but never reaches the app, and reopening the tag lifts the latch.
- The house videoMsg constructor never returns null, so Zig-native apps keep the one-terminal-per-load delivery whole; the bridge pin now asserts the swallow and the reopen.

* Cancel the key's staged video answers inside the engine at TS stop

- Cmd.videoStop's cancel now runs where the answers live: stopVideoCancel removes every staged-but-undrained entry for the key before the channel goes idle, so nothing for a stopped stream can reach the app - even the synchronous terminal of a load-fail-stop batch, and even when a later load reuses the same event tag before the drain (a bridge-side tag latch could not tell those generations apart).
- A cancelled answer never journals, so replay regenerates and cancels the same entries and the timelines stay identical with no extra machinery; the VideoMsgFn seam returns to plain Msg and the Zig-native stopVideo keeps its one-terminal-per-load delivery.
- The bridge pin now covers the same-tag reopen-before-drain shape.

* Mirror synchronous load refusals under replay; token-scope ownership and cancel

- The .video_load record's video_kind now carries the load's outcome: a refusal reset the live channel before loadVideo returned, so the replayed fake load resets at the same instant (parking its identity for the journaled terminal) and a snapshot an update reads inside the very dispatch matches the recording's; semantic epoch bumps to 3 (same bytes, the field gained meaning). Pinned by a record/replay probe test.
- Declarative video ownership now rides the load token the reconciler captured at its own load, never the derived key alone - the key is a pure function of the source string, and a manual load carrying it must survive declaration removal and flag deltas untouched; pinned.
- stopVideoCancel is token-scoped: the stopped stream is the latest accepted load, so a replaced predecessor sharing the arm's public key keeps its owed terminal - only stop cancels; pinned at the channel level.

* Refuse post-completion play on the fake video channel too

- A non-looping natural end retires the platform player, so play meets an absent player live: one .failed terminal and the channel resets before playVideo returns; the fake executor now models the same refusal (failVideoChannel on plain fake; under replay just the identity park and reset, because the journaled terminal delivers itself), so a snapshot an update reads right after its own play answers the same on every executor.
- Pinned by a record/replay probe test: the mid-dispatch snapshot reads inactive on both sides, the terminal delivers at its recorded wake, and models and fingerprints match.

* Break the video timer retain cycles and gate video-load outcomes at replay

- Both video timers (the 1/60 pixel clock and the 500ms readout) are now weak-host block timers that self-invalidate when the host is gone: a target-selector repeating timer retains its target through the run loop, so a host destroyed mid-playback without an orderly stop could never dealloc - leaving AVPlayer, the timers, and the conversion buffer permanently retained.
- Replay refuses a .video_load record whose video_kind is neither .loaded nor .failed as a damaged journal: the recorder writes exactly those two outcomes, and anything else would steer the replayed fake load into a state the recording never had; pinned by a hand-patched-journal test.

* Commit the video declaration at install; provenance-gate video rejections

- The main-canvas <video src> capture now stages during the build and commits only when the rebuild installs: a build that fails downstream never mounted, and the retained tree on the glass still shows the old declaration - a later reconcile acting on the unmounted capture would stop or replace a playback the presented tree still declares.
- Replay refuses a .video record whose kind and token are recorder-impossible: rejections stamp token 0 (a refused load never minted one) and every delivery carries its minted token, so a .rejected re-stamped onto a delivered record can no longer slip through the regeneration skip and silently omit the recorded Msg; pinned by a hand-patched-journal test.

* Fail the replay finish check on undelivered fed video results

- A fed record is one recorded delivery, and the event that consumed it live follows it in every honest journal - so a fed entry still staged when the journal ends means truncation or hand-editing, and finishReplay now refuses instead of reporting success; regenerated loop-side answers may honestly outlive the last drain on both timelines and stay exempt.
- Pinned: a fed-but-undelivered result fails the finish check and the same result delivered makes it silent again.

* Restart a finished playback from Play instead of failing it

- A non-looping natural end retires the player, so Play answered with one failed event and the seek was guaranteed to spring back - a broken response to a valid finished state. Effects.restartVideo is the resume path: a fresh load of the channel's own remembered source with autoplay, keeping key, surface, handler, and the loop and mute flags, journaling like any load.
- The house transport's toggle restarts when the completion latch is set and its scrub disables (Play is the live affordance); the snapshot and chrome state expose completed so custom players can do the same - the video-player example's Play now restarts its finished clip.
- Pinned: clicking the house toggle after the natural end issues a fresh platform load and the playback runs again.

* Validate replayed video payloads and source shapes; retire the example's dead seeks

- The replay pairing now requires the fed record's payload to equal what the platform event resolves to: the recorder journals every delivery verbatim from that event, so an altered kind or scalar around an intact identity refuses as divergence instead of handing the app a Msg the mirrors contradict; pinned by a hand-patched-journal test.
- A journaled cascade resolution must be one the load's request shape could select (.local needs a path, .stream needs a url); an impossible pairing latches divergence for the finish check, pinned at the channel level.
- The video-player example's seek-family controls (slider, back, forward) disable after a natural completion - a retired player refuses seeks and the thumb would spring back; Play stays live and restarts.

* Document the video output's vended-size contract at the frame tap

- The pixel-buffer width/height attributes are client requirements AVPlayerItemVideoOutput satisfies by scaling every vended frame, not hints: a 3840x2160 H.264 source tapped with fitted 1866x1050 attributes vends 1866x1050 buffers, so a 4K playback never hits the oversized-frame drop - that guard is defense in depth against a hypothetical non-conforming host, and the comment at the attributes site now says so.

* Keep declared ownership across restart; saturate past-window seeks

- The house transport's restart mints a fresh load identity, so the declarative reconciler re-captures its ownership token when the finished playback was its own - removal and same-source flag deltas keep working after a replay-from-end; pinned in the restart test.
- The TS bridge no longer rewinds a finite seek past the exact-integer window to zero: it saturates just below the window, where the engine's duration clamp lands it at the end - an oversized forward seek means the end, and only NaN and negatives (not millisecond offsets at all) seek to 0; pinned at the bridge level.

* Class non-finite seeks as invalid offsets, never oversized forward seeks

- Infinity reached the past-window saturation branch and sought an active video to its end, though the literal validation rejects non-finite offsets: the saturation now requires a FINITE value, so Infinity seeks to 0 like NaN and negatives - not millisecond offsets at all.
- Pinned at the bridge level beside the finite past-window seek.

* Keep the reserved video surface id inside the f64 exact window

- Surface ids ride the TS wire as f64, and a source-less <video> with custom controls is fed by the app's own Cmd.videoLoad naming exactly the reserved id - the old value sat near 2^63, so the bridge's exact-integer validation rejected it and the element could only ever show its placeholder from TypeScript.
- The id moves below 2^53 (mnemonic preserved, bit 63 clear, still a valid producer id reserved by convention); pinned: in the window, outside the derived-texture namespace, and round-trips the f64 wire unchanged.

* Deterministic seek mirror, journaled handler presence, and baked rotation

- The seek mirror now gates on the deterministic completion latch on every executor: a completed playback keeps its terminal position live and replayed alike (the platform is not even asked - the retired player could only refuse), and residual platform verdicts are fire-and-forget so an exotic host's answer can never diverge replay's mirrors from the recording's.
- Every .video record journals whether its delivery dispatched a Msg, and feedVideoRecord requires the replayed handler presence to agree - a record whose Msg silently vanished, or a Msg live never dispatched, refuses as divergence instead of a silent consume.
- Rotated media renders upright: a track with a non-identity preferredTransform gets a properties-of-asset video composition baked into the vended frames (verified against a portrait-flagged H.264 asset: the raw tap vends encoded orientation, the composition vends display orientation); identity-transform assets skip the render pass and track-less streams have no transform to bake.

* Repaint the chrome when the reconcile moves playback; seek on slider key steps

- A src change loading an autoplaying replacement reconciles after the build installs, so the just-installed chrome advertised the OLD transport state while its control acted on the new one - Play on the label, pause in effect. The rebuild now runs one guarded repass when the reconcile moved the mirrors the build rendered; the repass reconciles an unchanged declaration, so the mirrors are a fixed point. Pinned: the replacement's pause glyph shows in the same build.
- Keyboard and assistive steps on the house seek slider arrive as set_value intents with no widget change event behind them; they now map their fraction onto the duration and drive the channel like the pointer scrub instead of being consumed silently for the next tick to snap back. Pinned with a focused arrowright step.

* Repaint secondary-window chrome when its own reconcile moves playback

- The slot rebuild reconciles its captured declaration after the slot tree installs, so a first mount of an autoplaying <video controls> in a secondary window rendered its chrome from the still-inactive snapshot - disabled Play over a playing video - until some later platform event, seconds away on a slow stream. The slot path now runs the main rebuild's guarded repass when the reconcile moved the mirrors the build rendered; the repass reconciles an unchanged declaration, so the mirrors are a fixed point.
- Pinned: the slot's first installed build shows an enabled pause toggle.

* Latch missing video records; scope bridge verbs to their own stream

- A recorded video event arriving under replay with a handler bound and no fed record before it now latches divergence for the finish check: the recorder journals every handled delivery immediately before its event, so absence is truncation or hand-editing - never a Msg to drop silently; pinned at the channel level.
- Bridge video verbs now prove ownership with the load identity their own accepted load minted (Effects.videoMintedToken): a wire key whose stream was since replaced by a load the bridge never issued - a declarative element's - no-ops its transport verbs, and its stop cancels only its own stream's staged answers while the playback on the channel survives untouched; pinned at the bridge level.

* State the replace-is-not-stop rule at the videoLoad contract

- A replaced load still delivers the terminal it owes, routed to its own event arm - the never-silent promise applies to the replaced stream's failure exactly as to any other, and only Cmd.videoStop cancels undelivered answers. The wire contract now says so explicitly where the open-or-replace semantics are defined; the bridge's routing and the arm-separation pin already enforce it.

* Remember volume across a failed load; gate impossible terminal payloads

- Volume is a remembered preference the next load re-applies, so the bridge's ownership gate now lets videoSetVolume through when the channel is IDLE - a failed load's handler routinely sets it before retrying, and with nobody's playback on the channel there is nothing to protect; a foreign live playback still gates it. Pinned both ways.
- Replay refuses a .video record whose payload shape the recorder never writes for its kind: terminals deliver with playing and buffering false and no dimensions, and a completion pins position to the duration - a synchronously failed load's record has no platform event behind it to cross-check, so the gate is where a hand-set width refuses; pinned by a hand-patched-journal test.
2026-07-22 23:19:29 -05:00
Chris Tate 2eb9424c63 Native context menus on Windows and Linux; point-anchored fallback everywhere (#172)
* Anchor the context-menu fallback surface at the click point

- Thread the secondary click's pointer location through the fallback request into Ui.finalize, so the synthesized surface opens at the click like a native menu instead of the target row's bottom-left corner
- Give WidgetAnchor a point mode: a zero-size anchor rect at an explicit window-space point, reusing the existing flip-above and window-clamp edge rules
- Cover the point mode's placement, bottom-edge flip, and horizontal clamp at the geometry level, and the click-point mount end to end on a wide row

Co-authored-by: startewho <898009+startewho@users.noreply.github.com>

* Present native Windows context menus through TrackPopupMenu

- Mirror the tray popup discipline for the runtime's declared items: presentation defers to a fresh loop turn, TPM_RETURNCMD | TPM_NONOTIFY with SetForegroundWindow and the WM_NULL post, logical view-local request coordinates inverted through the presenting HWND's DPI scale and ClientToScreen
- Selection and dismissal emit the same journaled context_menu_action payload the macOS host produces (token echo, item id, 0 for dismissal), so session replay stays shape-identical across platforms
- Flip .context_menus to the tray's system-engine gate and unit-test the pure seam parts (item translation with separators and disabled flags, the action-event mapping); the TrackPopupMenu modal loop itself is only exercisable on a live Windows session

Co-authored-by: startewho <898009+startewho@users.noreply.github.com>

* Present native Linux context menus through GtkPopoverMenu

- Build a sectioned GMenu from the declared items (separators split sections, disabled items ride action enablement) wired to a per-invocation GSimpleActionGroup inserted on the presenting view widget, pointed at the click with a 1x1 rect in the widget's logical coordinates - the same space the inbound pointer path reports in
- Emit exactly one journaled context_menu_action per request (selection from the item action, dismissal from a one-turn-later teardown idle after the popover closes), the same token-echo payload the macOS and Windows hosts produce; refs stay balanced with weak pointers covering widgets that die while the menu is up
- Flip .context_menus to the system-engine gate, keep the new code outside the WebKitGTK stub fences, and update the docs, skill, and README claims that named native context menus macOS-only

Co-authored-by: startewho <898009+startewho@users.noreply.github.com>

* Gate context-menu resolution on per-request tokens

- Mint a fresh correlation token per presented (or automation-armed) request and check it before clearing the pending request, so a superseded menu's late dismissal can never resolve or clear its successor - even when both target the same widget.
- Give each GTK popover menu a per-invocation action-group namespace: the deferred teardown of a superseded menu now removes only its own group instead of the one the replacement just inserted on the same parent.
- Windows and macOS need no gate by construction (TrackPopupMenu blocks the loop thread and emits inline from a moved-out request; the macOS presentation block captures its token as a local while popUpMenuPositioningItem blocks the main queue) - noted at both fix sites.

* Add the native context-menus changelog fragment

- One feature fragment covering the Windows and Linux presenters, the .context_menus capability on both system-engine hosts, and the fallback surface's click-point anchoring.

* Cancel pending GTK context-menu teardown idles at host destroy

- Track every queued teardown idle on the host, linked through the menu states themselves: the popover's closed handler pushes the receipt the moment it exists, and native_sdk_context_menu_free unlinks on every exit path
- A superseded menu's deferred teardown captures its state and the host raw while host->context_menu tracks only the current menu, so destroy now removes each pending source and frees its captured state inline instead of letting the idle fire into a freed host
- The weak pointers keep covering widgets dying before the menu state; this covers the host dying, and cancelling deliberately drops the superseded request's owed dismissal since the runtime gating on that token is torn down with the host

* Re-point the notes context-menu token assertions at the recorded token

- Context-menu correlation tokens are minted per request and opaque, so the tests assert the null platform recorded a nonzero token instead of expecting the widget id

* Escape mnemonic ampersands in Windows context-menu and tray labels

- AppendMenuW treats & as a mnemonic marker, so an authored label like "R&D" rendered with the ampersand eaten and an accidental mnemonic armed; labels now cross the ABI with & doubled
- The escape lives in the shared translation helper covering both the app context-menu path and the tray path, whose labels are app-supplied too; a label the pool cannot hold passes through raw rather than truncated
- Pin the escaped output and the pool-exhaustion passthrough in the item-translation unit tests

* Escape mnemonic underscores in GTK context-menu labels

- GtkPopoverMenu treats _ in an item label as a mnemonic marker, so an authored label like "Save_As" rendered with the underscore eaten and an accidental mnemonic armed; labels now cross the ABI with _ doubled
- The escape lives in the context-menu translation helper (the GTK host strndup-copies every label before returning, so the caller stack pool is safe); a label the pool cannot hold passes through raw rather than truncated, and the menu bar keeps _ untouched as its intentional GTK mnemonic convention
- Pin the escaped output, the underscore-free pointer passthrough, and the pool-exhaustion passthrough in the item-translation unit tests

* Map GDK pointer buttons explicitly to the runtime's ordering

- GDK numbers secondary=3 and middle=2; the old subtract-one sent right
  clicks to the runtime as middle (never opening the menu) and middle
  clicks as secondary (opening it); press and release now share an
  explicit GDK-to-runtime switch, and the interactive-move stash keeps
  raw GDK numbering for gdk_toplevel_begin_move
- The Linux canvas smoke now owns its Xvfb display and drives a real
  xdotool right-click through a task row's declared context menu,
  asserting the selection's Msg dispatch ('1 done') in the snapshot
- ui-inbox task rows declare an honest one-item menu (Toggle done) so
  the smoke exercises an app-declared menu end to end

* Resolve context-menu selections from a present-time snapshot

- GTK popovers are asynchronous: a rebuild while the menu is open
  (timers or effects reordering conditional items) could redirect the
  visible selection through the live tree's handler table
- The runtime now emits canvas_widget_context_menu_shown after a native
  present; UiApp snapshots the shown items' dispatch Msgs keyed by the
  request token, and a token-matching selection resolves from that
  snapshot on every platform - never the rebuilt tree
- The automation verb and the fallback surface keep live-tree
  resolution: both validate against the tree they show

* Bump the automation protocol to v8 for per-request menu tokens

- Recorded context_menu_action tokens changed from widget ids to
  per-request generations; a v7 journal's selections would be silently
  swallowed by the token gate instead of refused
- The version handshake now turns that into the loud preamble mismatch,
  and the changelog fragment states the break deliberately

* Deep-copy context-menu snapshot slice payloads at present time

- The present-time selection snapshot copied MsgT by value, so a menu held open across two rebuilds dispatched slice payloads pointing into reset build-arena storage
- Snapshot Msgs now deep-copy every reachable slice into a token-scoped arena, released on resolve, supersession, and teardown
- Regression test presents a menu over an arena-derived payload, rebuilds twice with sentinel bytes, and asserts the dispatched Msg carries the bytes the user saw

* Drive the smoke's context-menu popover by pointer under Xvfb

- Xvfb has no window manager, so the GTK popover never receives keyboard focus and xdotool Down/Return died on the canvas beneath it; the menu's shown event fired but no selection ever dispatched
- Locate the popover's override-redirect X window by diffing the root's children across the right-click (topmost new viewable window) and click its center — the row declares exactly one arrowless item, so the center is the item
- Failure diagnostics now dump the X window list alongside the snapshot and app log; the workflow installs x11-utils for xwininfo

* Sharpen the snapshot copy: const slices only, exact types, loud OOM

- Mutable slice payloads pass by reference (update may write through app-owned storage; a copy would swallow the writes), while const slices copy with their declared alignment and sentinel and error unions recurse into successful payloads
- An out-of-memory copy now logs which item it disarmed instead of failing silently
- Direct unit test pins the copy semantics per shape; the integration test drives the error-union arm through the two-rebuild race

* Refuse un-copyable context-menu payload shapes with teaching errors

- A mutable slice's aliasing is unknowable to the deferred snapshot (arena bytes must be copied, model-owned storage must not be), so it is a compile-time teaching error instead of a silent guess either way
- Slice-bearing fixed arrays are refused too: an array's length says nothing about which elements are initialized, so walking a count-plus-buffer payload would interpret its undefined tail as slices; slice-free arrays and untagged unions still pass by value as plain bytes
- typeCanReachSlice gates the refusals so only genuinely un-copyable shapes are rejected; the unit test now covers the scalar count-plus-buffer shape with an undefined tail

* Scope the snapshot copy to const slices with a hop budget and a loud fallback

- The copier now walks only the blessed arena payload shape (const slices through structs, tagged unions, optionals, and error unions); mutable slices, fixed arrays, untagged unions, and non-slice pointers pass through under the deferred-Msg rule that their storage outlives the menu, so no payload shape is a compile error
- A slice-hop budget bounds the walk, turning cyclic or absurdly deep payload graphs into a handled error instead of unbounded recursion
- A failed copy (out of memory or over budget) keeps the visible item live: it dispatches the uncopied value with a warning naming the item, never a silent no-op

* Pin the presenting build's arena while its context menu is open

- Replace the snapshot payload copier outright: while a presented menu's token-keyed snapshot is armed, the arena generation that built the presented tree is exempt from the rebuild reset, so selection dispatches the ORIGINAL Msg value - same bytes and same pointer identity as the fallback surface and the automation verb, with no payload-shape restrictions, no copy allocation after present, and no recursive walk
- A new canvas_widget_context_menu_dismissed runtime notice releases the pin (and disarms the snapshot) when the menu closes without a selection; selection and supersession release it as before, and growth while a menu is open is bounded by its open span
- The regression test now also asserts pointer identity end to end and the pin's release on selection and dismissal

* Key the menu pin by window identity and double-buffer rebuilds under it

- The pin names its canvas by stable window identity, never slot index: removing a window swap-moves another slot into its place, and an index-keyed pin would protect the wrong arena; the pin-owning window's teardown now releases the snapshot and pin before its arenas deinit
- While pinned, every rebuild of that canvas routes through the partner arena on its normal reset cadence (the consecutive-build pattern the clearance retry already runs), so memory under an open menu holds at two trees regardless of rebuild count
- ANY superseding presentation or dispatch releases the previous app-menu request - a default edit/copy menu and the automation verb's direct dispatch now send the dismissed notice, not just app-over-app presentations
- Tests: pin follows its window across slot compaction (bytes and address), window removal releases, cross-kind and automation supersession release, and capacity stays flat across 14 rebuilds under an open menu

* Name the superseded menu's view in its dismissal and commit the successor first

- The pending request now carries a bounded copy of its view label, so the superseded-menu dismissal notice names the canvas it was presented on instead of an empty label (raw apps tracking per-canvas menu state need the correlation, and the view may already be gone)
- The replacement pending commits before the fallible dismissed-notice dispatch: if an app handler errors on the notice, the runtime's expected token still matches the menu the platform accepted, so the successor stays selectable
- Runtime-level test pins both: the notice carries the old token and the real view label, and the successor menu resolves after the supersession

* Keep the automation menu verb's synthetic selection ahead of a failing dismissal notice

- The widget-context-menu verb captures the superseded-menu dismissal notice's error and re-raises it only after the synthetic selection dispatches: unlike a presented menu, whose outcome the platform delivers later regardless, that dispatch is the armed request's only outcome, so no error path may leave a pending token with no presented menu and no delivered outcome
- The notice keeps its place in the event order (the old menu's dismissal before the successor's outcome), and its error still surfaces after the runtime's bookkeeping settles
- Test pins the supersession under an erroring dismissal handler: the selection still dispatches, the error still propagates, and no pending request survives

* Keep menu state sound when rebuilds fail or handlers close views

- A rebuild routed into the live tree's arena under an open menu's pin now drops the tree reference when the pass fails after its reset: handlers go quiet until the next successful rebuild instead of dangling into reset, partially rewritten storage, and the pinned snapshot still resolves the presented payload
- The superseded-menu dismissal notice runs arbitrary app code that can close views and compact their indices, so the shown event and the automation verb's synthetic selection now name their view from the committed request's own copy (showMenu returns it) instead of re-reading a cached index that a compaction can point at another view or another window's canvas
- Tests pin all three seams: the failed over-budget rebuild under a pin drops then restores the tree with the presented menu intact, and both supersession paths keep naming the presenting view after the dismissal handler closes a different one

* Restore a dropped tree on menu resolution and refuse a superseded automation verb

- A menu resolution that dispatches no Msg (dismissal, out-of-range or unmapped-item swallow) now restores a live tree the pinned-rebuild guard dropped: no Msg-driven rebuild is coming, and without a handler table every event silently no-ops until an unrelated resize or effect rebuilds
- The widget-context-menu verb now checks its freshly armed token survived the dismissal notice: a handler that synchronously presents a superseding menu replaces the pending request, so the verb refuses with ContextMenuSuperseded instead of reporting success while the token gate swallows its synthetic action
- Tests pin both: a dismissal after the failed over-budget rebuild rebuilds the tree once the model fits again, and the superseded verb errors by name while the handler's successor menu stays resolvable

* Announce nothing for a presentation superseded during its own notice

- showMenu now reports a three-way outcome: shown, refused, or superseded — the dismissal notice's app code can synchronously present a successor menu that replaces the freshly committed request, and a late shown event for it would overwrite the successor's snapshot with a token the action gate no longer accepts, stranding the stale pin
- A superseded presentation announces nothing and never falls back to the anchored surface, which would mount a second menu under the successor's native one
- Test pins the chain: menu A superseded by B whose notice presents C — three presentations, two announcements, the last carrying C's token, and C resolves normally

* Release the menu pin before its selection dispatches and refuse a closed-view verb

- A snapshot selection's Msg is stored by value and its pinned-arena payloads are consumed by update itself, so the pin now releases before the dispatch: the rebuild routes into the partner arena naturally, and a Msg whose update breaks a build budget fails the rebuild without resetting the live arena — input keeps working on the previous tree and the app's controls can recover the model
- The widget-context-menu verb revalidates its target view after the dismissal notice: a handler that closed it leaves a request that can never resolve, so the verb disarms it and refuses with ContextMenuViewClosed instead of reporting success while the action dispatch silently drops the selection
- Tests pin both: the poison selection leaves the tree live and a real click on the recovery control rebuilds in budget, and the closed-view verb errors by name with no orphaned token

* Disarm a presentation whose view died mid-notice and restore the tree before menu resolution

- showMenu now rechecks the presenting view after the dismissal notice: a handler that closed it leaves a request whose action can never deliver (or never arrive), so the request disarms with a view_closed outcome — never announced, never the anchored fallback on a dead view
- Arming a shown snapshot and resolving a snapshot-less selection both restore a live tree the pinned-rebuild guard dropped: a menu presented while the model was unbuildable still resolves once the model recovers, instead of falling through a null tree and dispatching nothing
- Tests pin both: the closed-view presentation stays silent, its token inert, a fresh present arms cleanly — and the snapshot-less selection dispatches the restored build's payload

---------

Co-authored-by: startewho <898009+startewho@users.noreply.github.com>
2026-07-22 00:52:30 -05:00
Chris Tate e67d3bd9c5 External-source channels: journaled events from app threads, sockets, and watchers (#165)
* Add the external-source channel effect family to the engine

- fx.openChannel/closeChannel with a generation-stamped thread-safe ChannelHandle.post that stages into a per-channel non-lossy FIFO, wakes the host, and reports back-pressure through per-channel drop counters
- channels share the keyed families' key space (occupied from open until the .closed terminal delivers) and deliver every event through the ordinary drain, journaled at the boundary
- journal format v8: the .channel effect-record kind with inline post bytes; replay feeds recorded events verbatim (no source thread), regenerates admission rejections, and damage-gates impossible records

* Cover the channel family: lifecycle, back-pressure, key space, replay

- direct-channel tests: open/post/deliver/close order, thread posting, duplicate-key and full-table rejects, drop accounting, post-after-close/teardown safety, shared key space with fetch and spawn
- record/replay acceptance: a session recorded with a live posting thread (one honest drop aboard) replays fingerprint-identical offline with no source thread; the duplicate open's rejection regenerates
- damage gates: over-bound post bytes and byte-carrying terminals refuse replay as damaged records

* Give transpiled cores the channel family: Cmd.channelOpen/channelClose

- wire opcodes 0x15/0x16 (additive within cmd_format_version 3) with rt builders, SDK types (ChannelState/ChannelEventArm/ChannelEventKind), and emitter lowering with the image-id literal gates
- ts_core_host routes every event through a five-field by-name arm (key/state/bytes/droppedPending/droppedTotal) on a non-retiring bridge entry; duplicate live keys reject at the post-cycle boundary echoing the key
- posting stays native-side API (Effects.channelHandle) - transpiled cores open, close, and receive; the bridge test drives a real handle post through the drain

* Add the channel-monitor example: a worker-thread source, zero polling

- an app-owned std.Thread samples its own process (uptime, peak RSS) and posts each reading through the channel handle; the UI updates only when events arrive
- Stop closes the channel and the detached worker winds down on the handle's false answer - safe past close and past teardown by the handle's construction
- tests swap the worker for a handle-capturing stub: posted samples land, no fx timer is ever armed, close kills the handle, a refused open reports rejected

* State the channel family and its journal v8 bump in the changelog

- one fragment covering the Zig surface, back-pressure contract, the conscious v8 format break, the TS tier, and the channel-monitor example

* Answer channel posts with a four-way PostResult instead of a bool

- ChannelHandle.post now returns PostResult { accepted, dropped_full, dropped_oversized, closed }: a producer can tell transient back-pressure (skip and continue) from closure (exit the loop) instead of guessing at a false; both drop answers keep the exact drop-counter semantics, and oversized gets its own member because its remedy differs (no retry of the same bytes can ever land)
- channel-monitor's worker now reads the answer honestly: dropped_full skips the sample and keeps sampling (the status line reports the delivered drop counters), closed winds the thread down - a transient 32-entry stall no longer stops monitoring forever while the UI says "monitoring"
- unmerged API, clean break: every post site, the SDK doc comment, the handle-lifetime docs, and the example's tests/README move to the enum

* Park replayed channel opens so a re-run source thread cannot diverge the stream

- under armReplay, openChannel registers the occupancy exactly as live (duplicate opens keep rejecting symmetrically, the shared key space holds) but allocates no staging and returns an INERT handle: every post answers .closed immediately, so app code following the documented open-and-spawn pattern sees its re-spawned worker exit on its first post instead of interleaving live posts with the journal-fed events
- closeChannel tolerates the parked occupancy's missing posting header; the fed .closed terminal retires the parked slot at its recorded position, the same causal instant live delivery frees the key
- new acceptance regression records the open-and-spawn pattern with a real posting thread and replays it offline fingerprint-identical (pre-fix the re-run worker's accepted posts diverged the checkpoints), plus direct coverage that inert-handle posts stage nothing and count no drops and that duplicate opens under replay still reject

* Teach the evals Cmd decoder the channel opcodes

- decode channel_open (0x15: key f64 LE + event_tag u8, exactly the bytes rt.zig's cmdChannelOpen builds - no max_pending rides the wire) and channel_close (0x16: key f64 LE) into new Op arms
- batch test pins both records' lengths so a trailing record still decodes; the unknown-op panic already names the offending byte and offset, so the next opcode gap stays a one-line diagnosis

* Never wake the host for a refused channel post

- A producer continuing through .dropped_full (the documented contract) enqueued one host wake per refusal, growing the main-loop queue without bound while the stage itself stayed bounded.
- The post site now documents the invariant: a wake is issued only when a post makes new work drainable - a full stage's entries already carry their accepted posts' wakes and the drop counters ride the next delivered event, an oversized post stages nothing, and a closed post stays a pure no-op.
- New regression test pins the pending-wake count flat across a 65-refusal storm and pins the accepted path's exactly-one-wake behavior before and after the stage refills.

* Document the channel family across the TS and skill surfaces

- The TypeScript-cores page gains Cmd.channelOpen/channelClose in the command table, a five-field event-arm example with the exact ChannelState union, and the channel stream in the Sub-vs-stream teaching.
- Both shipped skills now teach the family: native-ui gets the fx.openChannel section (verbs, event arm, back-pressure and replay contracts, test surface) and ts-core adds the channel ops to its streaming-ops set.
- A stale OpenChannelOptions comment still said overflow posts return false; it now states the .dropped_full PostResult, and the changelog names the refused-post-never-wakes contract.

* Never hold the channel staging mutex across the host wake

- Split the channel post's host wake out of ChannelShared.mutex into a ChannelWake half behind its own mutex, mirroring the media-surface producer's data/wake split: posts stage under the staging mutex, release, then wake, so drain, close, and teardown never contend with a slow or blocking platform wake hook.
- Arm the binding at openChannel and disarm it under the wake mutex on every close path (closeChannel, terminal retire, teardown) — the abandon fence: after a disarm returns, no post is inside the host call and none can start one.
- Document the lock-order invariant at ChannelShared.mutex (the staging mutex is never held across a host callback; the two locks never nest) and pin it with an injected wake hook that probes the poster's lock state.

* Coalesce channel post wakes behind one latched host wake

- Latch an atomic wake-pending flag in the channel's wake half on the first accepted post and ride it for the rest of the burst, following MediaSurfaceWake exactly: a fill/drain/refill producer now costs one host-queue entry per drain instead of a standing backlog of redundant wakes.
- Clear the latch at the drain pass boundary BEFORE snapshotting the post order (adoptMediaSurfaceFrames' clear-before-sample placement), so a post racing the drain either lands inside the pass's snapshot or observes the cleared latch and wakes afresh — nothing staged is ever left wakeless; the flag is per-channel, riding the generation-fenced binding the lock split introduced, and checked lock-free so a reentrant wake hook coalesces instead of deadlocking.
- Gate the contract in tests: a full-stage burst latches exactly one wake, a post after the pass boundary wakes afresh and delivers next pass, refused posts still never wake, and a wake hook posting back into its own channel completes instead of deadlocking.

* Surface a failed sampler start in the channel-monitor example

- Claim "monitoring" only after the source thread actually starts: the spawn reports failure through the start seam instead of silently returning with a live channel and no producer.
- On failure, close the just-opened channel (the .closed terminal frees the key for a retry) and render "sampler failed to start" in the status line.
- Exercise the failure branch through the injected-source seam the tests already use — std.Thread.spawn cannot be made to fail deterministically — including full recovery on a retry with a healthy source.

* Reserve channel-table capacity for an alloc-failed open until its rejection drains

- Live table admission now counts staged executor-truth channel rejections as occupied capacity, matching the slot replay parks for the same open until the journaled terminal feeds; regenerating refusals (occupied key, full table) deliberately never reserve, the same line the key window draws
- Route channel storage creation through a swappable allocator seam so tests can fail one open's start surgically
- Cover the reservation window, the table-limit record/replay boundary, regenerating no-reserve accounting, and teardown with a reservation pending

* Dispatch bridge-refused rejections in command-stream order across families

- Merge the TS core host's per-family rejection staging (spawn, image, channel) into one kind-tagged stage drained in wire order, so a mixed Cmd.batch's refusals reach update under the performed-in-order contract; a future family joins with one enum member and one switch arm
- Spawn rejections now share the spill discipline: a batch carrying more refused spawns than the effect table holds slots yields one rejection each instead of a panic
- Pin the order at both tiers: bridge tests drive mixed, reversed, and three-family refused batches, and the transpiled e2e fixture records a mixed-rejection session that replays with identical cross-family order

* Preserve mixed-provenance channel rejection order under replay

- A replay-parked open now reserves its pending-order slot at dispatch: the park consumes the pending_seq stamp a live executor-truth refusal would have staged at, and the fed park-retiring .rejected delivers through the pending stage at that stamp (ordered insert, slot retired at delivery) instead of trailing every younger regenerating refusal through the completion queue.
- Accepted opens stamp too - refusal-vs-accepted is only knowable at the first feed - but any non-.rejected feed vacates the stamp unused, so their fed streams keep riding the queue unchanged.
- Cover the mixed sessions end to end: alloc-fail-then-table-full replays in live order, the regenerating-first shape keeps its lead, and a rejection handler that opens a third channel sees the same table state on both sides.

* Publish the channel wake's services binding and sweep staged work at bind

- Posting threads now read the services binding through an atomically published mirror (release store at bind, acquire load under the wake mutex) instead of racing the loop thread's plain-field write; the release/acquire pair is the publication contract that makes the host state fully visible to the first cross-thread wake.
- bindServices sweeps: a post accepted before the binding could neither wake nor latch, so the bind issues one catch-up host wake when anything is staged - without it a one-shot producer that posted early stranded forever.
- Cover both shapes: the pre-bind post delivers off the bind sweep's wake with no further post, and an idle bind wakes nobody.

* Give channel occupancies a channel-owned u64 generation

- Channel handles now stamp from a dedicated monotonic u64 counter instead of the shared wrapping u32 effect counter: the permanent-closed guarantee is absolute, and a u32 wrap after 2^32 occupancies would let a long-lived stale handle match a reused slot and post into another producer's channel (the media-surface producer handle's width, mirrored).
- Fed channel entries carry the u64 generation on their own queue field; the slot families keep the shared u32 counter for their loop-internal gates.
- Pin the width, the counter's independence, and the wrap case itself: a seeded counter reproduces the exact u32 truncation collision and the stale handle still answers closed.

* Add ChannelHandle.live() and state the replay re-run honestly

- live() is the producer-launch check: false for parked replay handles, refused opens, closed or reused occupancies, and torn-down runtimes - advisory only, the post's own answer stays authoritative. The replayed open parks, but the opening update re-executes, so a producer launched unconditionally really starts (connects and blocking setup before its first post included) and is stopped only at that first post; gating the launch on live() keeps replay fully offline.
- The channel-monitor example consults live() before spawning the sampler - the Msg stream and model are identical either way because nothing model-visible branches on it - and its tests pin that a replay-armed start never invokes the source seam.
- Say it honestly everywhere it was claimed: the changelog fragment, the openChannel doc comment, the test-suite header, and both skill surfaces now state that replay never NEEDS the source rather than that no source thread runs, and one journal replays identically under both producer disciplines (acceptance-tested).

* Repair the bind/post wake handshake with a seq_cst store-buffer pairing

- bindServices' services publish, hasPending's mirror loads, the post's pending increment, and requestHostWake's services load all carry seq_cst: release/acquire never orders a store before the same thread's later load of another location, so both sides could read stale values and strand an accepted post with no wake
- Document the total-order argument at each of the four operations: whichever store lands later in the seq_cst order, that side's subsequent load sees the other's store, so the poster wakes or the binder sweeps
- Add a bounded concurrent regression (300 iterations, one post racing one bind) asserting a wake is always observed and the post drains, documented as probabilistic-but-real for this race class

* Deliver bridge refusals through the engine's one seq-ordered rejection stream

- A batch mixing an engine-refused record (cross-family occupied key, staged into the pending FIFOs for the next drain) with a bridge-refused one (host-side stage, dispatched at the cycle boundary) delivered the second rejection before the first, breaking Cmd.batch's performed-in-order contract across layers
- Add Effects.stageLoopMsg: a non-lossy caller-staged Msg stage sharing the pending seq stamp, never journaled and regenerating by contract; the TS bridge now stages its spawn/image/channel refusals there at refusal time and its finishCycle rejection stage retires, so one seq-ordered drain delivers every rejection in command order
- Pin the engine-then-bridge and bridge-then-engine compositions, the three-family mix, the journal provenance (bridge refusals journal nothing, engine refusals journal marked regenerable), and record/replay identity for mixed-authority rejection order

* Run the channel host wake with the wake mutex free

- An embedder wake_fn has no enqueue-only contract: holding wake.mutex through the call deadlocked against drainBoundary (and post's never-blocks contract) whenever a wake synchronously marshaled to the loop thread.
- Posts now mark an in-flight count under the mutex, release it for the host call, and re-acquire to clear; disarm clears the binding under the mutex and waits for in-flight to reach zero, so a returned disarm still means no producer is inside the host call.
- Gate the invariant with a wake hook that takes the drain's own pass boundary (deadlocked before, completes now) and asserts the wake mutex is free during the call.

* Refuse terminal feeds into a live channel occupancy

- feedChannelEvent is the replay/test seam and replay parks its opens with inert handles; feeding a terminal into a LIVE occupancy (open posting header, staged backlog, or armed close marker) raced the producer: the terminal's delivery destroyed the staging FIFO and stranded channel_pending_count, leaving hasPending() true forever.
- Feed answers error.ChannelLiveFeed for that shape instead; live occupancies end through closeChannel, and teardown already reconciles the count to zero when it discards staged entries.
- Tests pin the loud refusal (open and .closing shapes), the reconciled count after teardown-with-staged-entries, and the parked replay feeds staying green.

* State the bridge refusal timing break and align the TS replay claim

- The changelog names the rejection-timing change deliberately: bridge-produced refusals (duplicate-spawn keys, image validation, channel admission) moved from the command cycle's own boundary to the next host drain so every rejection arrives in one seq-ordered stream, and a frame may now render between the cycle and the rejection Msg.
- Cmd.channelOpen's doc drops the last 'no source thread at all' overclaim: replay never NEEDS the source, an unconditional producer is stopped at its first post, and a live()-gated one keeps replay fully offline.

* Reset the channel-monitor drop total on restart

- The start path reset samples and visible rows but not dropped_total, so a fresh run showed the previous run's drops until the first data event.
- The restart test now ends a run with a counted drop and pins a zeroed readout immediately after the fresh start.

* Split channel wake disarm into a non-blocking revoke and a teardown quiesce

- closeChannel and retireChannelSlot now revoke the wake binding without waiting out in-flight host calls: a supported wake hook that synchronously marshals to the loop deadlocked against the old spin-wait when the marshaled dispatch's handler closed the channel
- teardown keeps the blocking quiesce but bounds it (injectable deadline, abandoned-call counter): deinit runs as the loop stops servicing dispatches, so it cannot guarantee an in-flight marshal ever returns, and everything the abandoned call still touches lives in the process-lifetime header
- gate tests: the synchronous-marshal close completes with one .closed terminal, a stale in-flight call outliving close and reopen cannot unlatch the fresh occupancy, and teardown both waits out a slow hook and abandons a stuck one safely

* Release the wake coalescer latch when a takeMsg sweep observes an empty stage

- only drainBoundary cleared the latch, so a caller on the public bare-takeMsg drain stranded the next accepted post: it saw the stale latch and never woke the host
- the sweep clears the latch exactly when a channel's staged queue is observed empty, then re-checks the queue: a post racing the clear either re-latches a fresh wake or its entry is visible to the re-check and delivers — one redundant wake is acceptable, a stranded event is not
- gate tests: a bare-takeMsg drain to empty is followed by a fresh wake on the next accepted post, and an event-driven consumer that only drains on wake movement never strands a concurrent producer's accepted posts

* Condition the channel post never-blocks guarantee on an enqueue-only wake contract

- Document PlatformServices.wake_fn as bounded, non-blocking, and enqueue-only — the shape every first-party host already implements (macOS dispatch_async, GTK g_idle_add, Win32 PostMessageW) and the same contract the media-surface frame request documents — and condition ChannelHandle.post's never-blocks promise on it: the runtime holds no channel lock across the call, so a violating wake hangs only its own posting thread, never the runtime's lock graph.
- Reframe the loop-marshaling wake tests as violator-containment pins rather than supported-usage examples: the pinned behavior (no lock-cycle deadlock through drain, close, or reopen) stays, and the revoke/quiesce rationale now names the marshal shape as out of contract.
- Sweep the never-blocks wording in the TS SDK channel docs, the native-ui skill surface, and the changelog fragment's back-pressure bullet to carry the same conditioning.

* Leak the platform when teardown abandons a stuck channel wake call

- An abandoned in-flight wake_fn call still holds PlatformServices.context past Effects teardown, and the process-lived channel header only protects runtime bookkeeping after the call returns — so the quiesce-abandon path now reports the abandon to the platform through a new note_channel_wake_abandoned_fn services seam, synchronously, while the platform is still alive.
- Every first-party platform latches the report and gates its destruction on it: MacPlatform/LinuxPlatform/WindowsPlatform deinit (the app runner's and the generated runner's one destroy path), the null platform's reference-model deinit, and the mobile ui host's destroy all skip destruction and deliberately leak the host, process-lived, with one loud log — the abandoned-worker idiom, applied to the platform itself. A conforming enqueue-only wake never meets the teardown deadline, so the gate is violator containment only.
- Tests: the quiesce-abandon test now binds a real null platform behind the stuck hook and asserts the destroy path is suppressed (latch set, destruction skipped), and a new non-regression twin pins the healthy half — a conforming wake quiesces fast, nothing is abandoned, and the platform destroys normally.

* Make an abandoned channel wake call's whole dereference chain process-lived

- bindServices publishes an immutable process-allocator snapshot of the services table, so a poster suspended before its services.wake() dereference never reads Runtime-owned memory; a rebind swaps in a fresh snapshot and never writes the old one
- runners heap-allocate the desktop platform wrappers (createWithOptions/destroy) and gate the free on the abandon latch, extending the deinit gate to the wrapper storage the wake context actually points at
- new coverage: a stuck wake whose first context dereference happens only after teardown completes and the owning scopes die (poisoned), plus rebind-generation snapshot coverage

* Resolve a replay park's pending-order stamp exactly once

- A .rejected record targeting a park already vacated no longer reuses the stamp and appends a duplicate terminal to the one-entry-per-open pending ring; it refuses as journal damage (error.ReplayDamagedRecord) with a teaching that names the key and the one-terminal-per-open rule.
- Pins the refusal and the single delivered terminal in effects_channel_tests.

* Gate channel record provenance against recorder truth at replay

- A .data or .closed channel record stamped with .rejected provenance no longer slips into the regeneration skip and silently drops from the Msg stream; the damage gate refuses it, naming both fields.
- Channel records can only carry .exited or .rejected exit reasons (the two journal sites), so any other decoded value refuses as damage too; .rejected kind with .exited provenance stays the executor-truth feed path.
- Pins both mismatch directions, the out-of-range stamp, and the executor-truth positive path in effects_channel_tests.

* Materialize the services snapshot lazily and free it on clean teardown

- bindServices records the loop-thread services pointer only; the process-lived snapshot allocates at whichever comes last of the bind and the first live openChannel, so apps that never open a channel never allocate one, and the seq_cst publish-then-sweep Dekker pair holds at both sites.
- A clean teardown (every wake header quiesced, zero abandons this deinit) frees the snapshot through the channel-storage seam; it stays deliberately process-lived only past an abandon, and the ownership rule is documented at the new wake_snapshot field.
- Re-points the abandon and rebind coverage (an abandoned generation's snapshot stays intact for stale calls; a rebind's fresh snapshot never writes the old one) and adds laziness and clean-free pins in effects_channel_tests.

* Refuse any channel record fed past the open's terminal at replay

- A fed terminal now marks the park .terminated until its delivery retires the slot, so a damaged journal's post-terminal .data/.closed/.rejected records refuse as ReplayDamagedRecord instead of enqueueing events the retire would silently discard from an unverified replay's stream.
- A .rejected fed after the stream proved the open accepted live stays damage and leaves the park intact, so the real terminal still lands.
- Pins data-after-rejection, data-after-closed, and rejection-after-data in effects_channel_tests.

* Refuse an open that cannot publish the services snapshot

- openChannel pre-flights the snapshot before committing the occupancy and rejects as executor truth on allocation failure, so no live channel can exist whose accepted posts strand with producer wakes disarmed.
- The one remaining live-through-failure shape, a channel opened before bindServices whose bind-time publication failed, heals at every drain pass boundary: the retried publication's Dekker sweep un-strands posts accepted in the disarmed window.
- Pins the refusing open (with recovery on the next open) and the boundary heal in effects_channel_tests.

* Resolve a fed park only after its event actually enqueues

- A .closed refused by completion-queue back-pressure no longer marks the park .terminated first, so the replay pump's drain-and-feed-again retry of a valid journal lands instead of refusing as damage.
- The .data vacate moves behind the same commit point; the .rejected path stages through the pending ring, which never back-pressures, and keeps its transition.
- Pins the back-pressured terminal's clean retry in effects_channel_tests.

* Close open channels when the bind cannot publish the services snapshot

- A failed bind-site publication no longer leaves pre-bind channels accepting posts that may never deliver (the pass-boundary retry needed a loop event that idle apps never produce); the bind closes them, flushing backlogs and delivering .closed terminals through its own loop-side wake.
- Together with the open-site refusal this pins one invariant: no live channel ever runs with producer wakes disarmed while services are bound - so the now-unreachable drainBoundary heal is removed.
- Re-points the bind-failure test: pre-bind backlog flushes ahead of the terminal, the producer's next post answers .closed, and a later open republishes and wakes normally.
2026-07-21 20:41:47 -05:00
Chris Tate 349618a138 chore: prepare v0.5.4 release (#164)
- Synchronize CLI, core, platform, and example package versions to 0.5.4.

- Merge release notes and contributor credits from the pending changelog fragments.
2026-07-20 19:29:27 -05:00
Chris Tate 6f526a9c1e Menu-bar app lifecycle: close-to-hide windows and app show/quit verbs (#155)
* Track alive-but-hidden window state through frame events and the journal

- WindowState/WindowInfo gain a hidden flag: the window is alive and open but off the glass (the close_policy .hide shape), distinct from minimized and from closed
- window_frame_changed events carry it into the runtime window table, and the session journal round-trips it (format v6)

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Add the close_policy window declaration: .quit stays the default, .hide is the menu-bar shape

- Per-window close_policy threads app.zon (top-level and shell windows) through WindowOptions to the hosts, .quit by default so every existing app is unchanged
- macOS: windowShouldClose orders a .hide window out instead of closing (both hosts), the Dock reopen re-shows policy-hidden windows, runtime closes bypass the policy; Windows: WM_CLOSE hides via SW_HIDE and the tray stays the re-show affordance
- Linux GTK has no status item to bring a hidden window back, so .hide refuses loudly: a comptime teaching for manifest windows and error.UnsupportedWindowClosePolicy at runtime create, gated by the new window_hide_on_close platform feature

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Add the showWindow and quitApp effects verbs on the window-action seam

- fx.showWindow(label) un-hides and activates a window (deminiaturize + order front on macOS, SW_RESTORE + foreground on Windows, present on GTK) and fx.quitApp() terminates through the same shutdown event path a last-window close takes
- Both follow the existing verbs' shape exactly: mirror counts in windowActionState, fire-and-forget with no journaling of their own, honest no-ops for unknown labels, mirror-only under the fake executor
- Null platform models both with pinned seams (show counts, quit requests); a recorded hide/reopen/quit session replays its window states through the journal

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Mirror the window verbs into the TypeScript Cmd vocabulary

- Cmd.showWindow(label) and Cmd.quitApp() ride new additive wire records (window_show 0x10, quit_app 0x11; cmd_format_version 3) and decode onto the same fx.showWindow/fx.quitApp verbs the Zig tier calls
- The emitter lowers both with the string-literal label discipline effect keys use (window labels are declarations; a dynamic label is taught)
- Conformance pins the emitted shapes and the dynamic-label teaching; the effects gate asserts the exact wire bytes; the host-bridge suite pins the mirror counts

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Add the menu-bar example: the tray-player lifecycle in one small app

- Zero-config canvas app whose main window declares close_policy "hide"; the status item's Open/Quit rows map to fx.showWindow/fx.quitApp through the ordinary on_command path, with a model-driven title showing transport state while hidden
- Tests drive the real tray-selection-to-verb loop and pin the declaration, the mirror counts, and the exactly-once stop hook
- A purpose-built example keeps the pattern reference minimal instead of repurposing soundboard's close behavior

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Document the menu-bar lifecycle and make the tray quit example real

- The tray page's "app.quit" example now handles the command (runtime.quitApp) and a lifecycle recipe walks the whole pattern: close hides, tray Open/Quit drive showWindow/quitApp, the Dock reopen re-shows
- close_policy documented on the windows and app.zon pages, the new verbs on the runtime and TypeScript pages, and the platform matrix states the per-platform truth including Linux's loud refusal
- Changelog fragment for the feature (defaults unchanged, no breaks)

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Thread close_policy through the generated runner template

- The scaffolded runner's manifestWindow now mirrors the SDK runner: an app.zon window close_policy rides WindowOptions (.quit stays the default), instead of being silently dropped so a "hide" declaration kept quit-on-close
- The "hide" declaration is refused at comptime on linux with the same teaching as the SDK runner - nothing could bring the hidden window back
- The template test pins the field and the linux refusal, so dropping either fails the writeDefaultApp test again

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Expose alive-but-hidden in the JS bridge's window JSON

- writeWindowJsonToWriter emits "hidden" beside open/focused: a close_policy = "hide" window read open:true/focused:false over the bridge, indistinguishable from a visible unfocused one
- NativeSdkWindowInfo carries the field, the window bridge test drives a policy-hidden window through window.list, and the windows doc names the bridge JSON among the surfaces where hidden shows up
- The webview JSON twin stays untouched: policy-hidden is window state, webviews have none

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Stop listing hidden as persisted WindowState in the windows doc

- The type table said hidden persists while the close-policy prose and the implementation say the opposite; the row now marks it deliberately session-transient (never persisted, every launch starts shown) so nobody re-adds it to the store

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Thread shell-startup window state through the generated runner template

- The scaffold runner ignored every `.shell.windows` startup declaration that is host state fixed at create time: mirror the SDK runner's manifestShellStartupTitlebar/Resizable/ShowMode/MinSize/ClosePolicy threading (including the Linux comptime refusal of close_policy "hide") into the windows.len == 0 branch, so a scene-first app.zon no longer silently keeps quit-on-close, standard chrome, immediate show, and no min-size floor.
- Thread titlebar and min_width/min_height through the top-level manifestWindow too — the same silent-drop class close_policy shipped with once.
- Pin the shell-startup threading and the new window fields in the template test, so dropping any of them fails the scaffold contract loudly.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Route focus of a policy-hidden window through the show verb

- focusWindow on a window hidden by close_policy .hide left state inconsistent: the hosts' focus paths order a window forward without touching their policy-hidden bookkeeping (macOS reported hidden=true on a visible window; Windows never shows an SW_HIDE'd window at all), so the runtime now drives showWindow first — the seam that clears the hosts' policy-hidden sets, emits consistent state, and rolls back on platform failure — before focusing.
- One rule at the runtime seam covers every focus ingress: the app verb and the JS bridge's native-sdk.window.focus both resolve hidden-then-focus the same way.
- Tests pin the routing through the null platform's show count on both paths: the runtime seam (hidden clears, focus lands, no second show for a visible window) and the bridge twin (the focus response never reports a focused window that is still hidden).

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Queue the quit verb's stop so app_shutdown emits after the requesting dispatch

- fx.quitApp() lands mid dispatch (the tray/menu command's update returned it), and the macOS and GTK hosts emitted SHUTDOWN synchronously from the stop call: the shutdown dispatch nested inside the command's, the session recorder's nested commit + finish() sealed the journal, the outer commit no-oped, and the journal lost the very command (and model mutation) that quit the app — replay diverged. Both hosts (AppKit, macOS CEF, GTK) now queue the identical emitShutdown + stop onto their loop's next turn (dispatch_async onto the main queue / g_idle_add, the same seams the wake paths ride); Windows already posted. The pre-run-loop inline emit stays on macOS so a failed START handler's synchronous shutdown request keeps working, and stop's posted wake event still unwinds a loop whose quit was the last thing that ever happened.
- The null platform's quit seam models the queued shape: quitApp records the request and takeQueuedQuit() hands the test the deferred app_shutdown to dispatch as its own loop turn, exactly once — the userCloseWindow pattern.
- A recorded-session test drives the whole verb chain (menu command -> update -> fx.quitApp -> queued host echo) with a recorder attached and pins the contract: the journal is not sealed by the quit dispatch alone, contains BOTH the command and app_shutdown in order, and replays fingerprint-identical; a build check step pins the queued stop in all four host sources so reverting to the synchronous emit fails the suite.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Occlude policy-hidden windows in the Windows pacing and spectrum gates

- Both occlusion answers in the WebView2 host were IsIconic-keyed only, so a window hidden by close_policy .hide (the menu-bar shape — hidden for days behind its tray icon) kept its full-rate canvas frame loop and its 25 Hz spectrum emissions running for glass nobody can see: pure background CPU burn. gpuSurfaceOccludedPacingActive now answers occluded for a policy-hidden window's surfaces (the ~1 Hz heartbeat, same first-present and input exemptions), and audioAnyWindowReachesGlass stops counting policy-hidden windows as visible, so an app with every window minimized or hidden goes honestly quiet.
- Re-show restores full cadence without dropping a beat: SW_SHOW on a same-size window dispatches no WM_SIZE (the minimize path's restore re-arm), so the show verb itself supersedes a parked heartbeat emission at the frame-grid delay after clearing policy_hidden.
- This is C++ host logic the Zig suite cannot execute: the contract is pinned by the test-gpu-occluded-frame-heartbeat file-contains step (both policy_hidden gates plus the re-show re-arm), verified by cross-target -fsyntax-only compiles of both WebView2 configurations, and written into the windows and capabilities docs; the pacing comments now name both occlusion facts honestly.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Refuse a .hide main window at Linux platform init instead of silently quitting on close

- LinuxPlatform.initWithOptions creates the MAIN window before any runtime exists, so the runtime's create-time .hide gate (window_storage's error.UnsupportedWindowClosePolicy) and the generated runner's comptime refusal never covered a direct-SDK or custom-runner caller: a .hide declaration was silently dropped and the user got quit-on-close. The init now refuses with the same error and the same teaching text the comptime check prints — one message, all seams — through an extern-free gate that is unit-tested on every host, with a file-contains step pinning both its wiring into initWithOptions and the cross-seam message lockstep.
- Three-platform pre-created-window audit: macOS threads the declared policy into the host right after create (applyWindowClosePolicy -> windowShouldClose) and Windows does the same (applyWindowClosePolicy -> the WM_CLOSE hide hook), so neither drops it; Linux was the only silent seam and now refuses.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Park a pre-run quit verb and drain it after the boot dispatch returns

- A quit requested before [NSApp run] exists (App.start's update, a boot command during the synchronous first canvas frame) rode the failed-START inline emit on the macOS hosts, nesting app_shutdown inside the very dispatch that requested it — the session recorder sealed the journal before the boot turn committed and replay refused the recording.
- The seams are now split: native_sdk_appkit_request_stop (the quit verb, AppKit and CEF alike) parks pre-run quits in pendingPreRunStop and runWithCallback drains them at top level after the START dispatch and again after the remaining pre-run emits, while native_sdk_appkit_stop keeps the byte-for-byte inline pre-run emit for the host-side failed-START request.
- The recorded-quit session tier gains the quit-from-boot case (the journal carries the start event and app_shutdown in order, and replays fingerprint-identical through the modeled park-then-drain seam), and test-quit-pre-run-pending pins the host wiring so an inline pre-run revert fails the build.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Track, coalesce, and destroy-remove the GTK quit-stop idle source

- Every native_sdk_gtk_stop queued a bare untracked g_idle_add: a second stop requested while the first executed (the shutdown handler's error path can make one) left an idle source holding a freed host after the loop quit.
- The pending source id now lives on the host: stop coalesces while a turn is queued and skips entirely once did_shutdown is set, the idle clears the id as its first act, and native_sdk_gtk_destroy removes a still-pending turn before the host is freed.
- test-gtk-stop-idle-tracked pins the tracking, coalescing, and removal textually — this suite cannot run the GTK loop on macOS; the linux-dev-smoke CI job exercises the real path at runtime.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Clear hidden with open when the app closes a policy-hidden window

- closeWindow flipped open and focused optimistically but left hidden alone, so an app-driven close of a policy-hidden window parked {open=false, hidden=true} in the runtime table — visible through the JS bridge, which exposes hidden; a closed window is not hidden, it is gone.
- hidden now clears beside open/focused and restores on platform failure through the same rollback; the null platform gains a fail_next_close_window injection seam (error.CloseFailed, consumed on use) so rollback paths are drivable.
- The new ui_app_window test walks the whole arc: .hide close hides, a refused platform close rolls every flag back (still open, still hidden), and the successful close reads open=false and hidden=false — dropping the hidden clear fails it.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Clear policy-hidden membership on the CEF app-close exit that skips windowWillClose

- The CEF host's app-driven close of a browser-bearing window exits through orderOut + an open=false emit without ever reaching windowWillClose, so the window stayed in policyHiddenWindows: the frame encoder derives hidden from set membership, so app-closing a policy-hidden window emitted {open=false, hidden=true} (overwriting the runtime's optimistic hidden clear), and a later Dock reopen — which re-shows every set member — could resurrect the closed window.
- The branch now leaves the set before its emit; after this every close exit removes and only hideWindowWithId (the user close of a live window) adds, so set membership implies a live, policy-hidden window and the reopen handler cannot resurrect. The AppKit host needs no change: all of its close paths run windowWillClose, whose cleanup already precedes the emit.
- A file-contains gate pins both hosts' cleanup-before-emit ordering, including the CEF orderOut branch's own cleanup.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Mirror the close's hidden clear in the null platform and gate its reopen on liveness

- NullPlatform.closeWindow cleared open/focused but left hidden standing, and userReopenApp re-showed on the hidden flag alone — so the modeled host resurrected an app-closed policy-hidden window (hidden=false, focused=true, a frame event), the same hole the real macOS hosts' set hygiene closes.
- The close mirror now clears hidden with open (matching the runtime table's own close flip), and userReopenApp skips windows that are not open — a closed window keeps its slot in the mirror, so hidden alone is not liveness.
- The new test drives the whole arc through the runtime: close a policy-hidden window, reopen emits NO event and the runtime table is untouched, then force a stale hidden flag onto the closed slot to prove the liveness gate holds on its own — reverting either fix fails it, and the existing reopen re-shows test still passes for genuinely hidden-open windows.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Move runtime focus with a successful showWindow: the show verb activates

- The service contract is show AND activate — every host's show path makes the window key — but the runtime's showWindow flipped only hidden, so listWindows and the JS bridge reported the shown window unfocused while it stood frontmost on the glass.
- After the platform accepts the show, focus now moves through the same setFocusedIndex seam focusWindow uses (the dethroned window's key-loss consequence fires); a refused show still rolls hidden back and moves no focus, drivable through the null platform's new fail_next_show_window injection (error.ShowFailed, consumed on use).
- Tests pin both halves: show a hidden window and the runtime table reads it focused with every other window unfocused (the bridge's window.list JSON carries the same truth), the failure injection leaves hidden and focus untouched, and dropping the focus update fails both tests.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Teach the evals Cmd decoder the v3 window_show and quit_app records

- cmdview.zig self-identified as cmd_format_version 2 and panicked on op bytes past 0x0F, so any graded core returning Cmd.showWindow or Cmd.quitApp (alone or in a batch) crashed the ts-track behavioral harness mid-eval, reading as the graded app's failure.
- It now decodes window_show 0x10 ([op][label_len][label]) and quit_app 0x11 (bare op), mirroring the runtime decoder in src/runtime/ts_core_host.zig; a repo sweep found no other Cmd opcode table outside packages/core and src/runtime, both already v3.
- The decoder gains its first tests (round-trip of both records against the encoders' pinned bytes, plus batch adjacency), wired into `zig build test` as test-evals-cmdview since eval-time is too late to learn the decoder lags the format. The 0x10/0x11 overlap with feat/dynamic-images remains merge-order-reconciled.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Execute the CEF show and minimize verbs synchronously on the main thread

- native_sdk_appkit_show_window queued its work with dispatch_async and returned 1 immediately, while the close verb runs synchronously (direct on main, dispatch_sync hop otherwise): the runtime's post-success focus flip ran while the window was still in policyHiddenWindows, so frame emits in the gap carried {focused:true, hidden:true}, and a show-then-close in one dispatch re-ordered — the queued show landed AFTER the synchronous close and put a retained (ordered-out) closed window back on the glass. showWindowWithId: now owns closeWindowWithId:'s exact on-main/off-main split, with the window lookup inside the block so a window closed before an off-main hop lands is a no-op.
- The minimize sibling had the same queued shape and the same close race (a queued miniaturize captured past a synchronous close genies an app-closed window into the Dock); it moves into a miniaturizeWindowWithId: with the same discipline. Minimize mirrors no runtime window state, so it emits no frame event — the ordering race was its only exposure.
- The AppKit host's show and minimize were already synchronous direct calls; a file-contains gate pins the CEF block shapes, the shims' call-then-return-1 ordering, and the AppKit symmetry, so reverting any verb to a queued dispatch fails the suite.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Gate the runtime window verbs on slot liveness before the platform call

- Runtime.showWindow resolved the id and called the platform: a closed window keeps its table slot (ids and labels release lazily, at the next create), so a retained dead slot was accepted — the null platform reported {open:false, focused:true} and the CEF host, which retains browser-bearing windows past their close, would visibly re-order one onto the glass. Dead slots now answer error.WindowNotFound (the runtime's one answer for not-open slots) before any platform call, gating the resurrection race independent of host timing.
- focusWindow had the same hole (close clears hidden with open, so a dead slot skipped the hidden-routing and reached the platform's focus verb directly) and minimizeWindow too (the CEF host would genie the retained closed window into the Dock); both get the identical gate.
- The new test closes a window and drives all three verbs: each answers WindowNotFound, the null recorder counts stay 0, and the runtime table and platform mirror stay closed/unfocused/un-hidden — dropping the showWindow gate fails it (verified).

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Expose the full PlatformFeature cohort to the JS bridge and typings

- Backfill camelCase aliases in platformFeatureFromString for the seven members past gpuSurfaces: gpuSurfaceScrollDrivers, contextMenus, viewSurfaceAdoption, audioPlayback, audioStreaming, audioSpectrum, windowHideOnClose
- Extend NativeSdkPlatformFeature with both spellings of each and sync the builtin-commands feature enumeration
- Pin both window_hide_on_close spellings to the null platform seam (true by default, false when flipped) plus the audioSpectrum alias in the bridge test

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Teach check-runtime-types the PlatformFeature union and alias table

- Derive every expected union member (snake plus camel form) from the PlatformFeature enum in src/platform/types.zig and fail naming any missing or extra name in NativeSdkPlatformFeature
- Parse platformFeatureFromString's manual alias entries and fail on missing, extra, or mistargeted camelCase aliases
- Accept a newline after = when locating exported type unions, matching the multiline union layout

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Correct the quit_app_fn contract to the queued shutdown emit

- The doc comment mandated a synchronous app_shutdown emit — the exact shape that nests the shutdown inside the requesting dispatch and seals the recorder's journal before the triggering command commits; every shipped host defers, so the written contract now does too.
- States the queued shape (emit on the NEXT loop turn, after the requesting dispatch returns), the pre-run park-and-drain case, the exactly-once app.stop guarantee, and names the null platform's quit_pending/takeQueuedQuit seam as the reference model.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Bring every narrative command-set surface to v3 with the window verbs

- Four surfaces still said v2 after the window verbs landed: the rt.zig format heading, sdk/core.ts's command-set header, ts_core_host's command-walk doc, and the ts-core skill's command-set line — each now says v3 (the opcode tables and version-history prose beneath them were already v3-complete and unchanged).
- sdk/core.ts's header enumeration and the ts-core skill gain the window-verb pair in the set's voice: Cmd.showWindow(label) (un-hide + activate the declared label, the tray Open consequence) and Cmd.quitApp() (the graceful terminate through the last-window-close shutdown path).
- The typescript docs page already carried both verbs; version-cohort test names and the v1/v2-additivity history in rt.zig name past versions correctly and stay as they are.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Serialize the JS window-close response from the post-close table

- closeWindowFromJson answered from a pre-close snapshot with open and focused hand-cleared, so a policy-hidden window's close told JS {open:false, hidden:true}; the response now reads the table slot after closeWindow, which owns the full set of flags a close clears
- The slot index stays valid across the close: closed windows keep their table slot, and slots only compact inside window create when a dead id or label is re-used
- The bridge test now closes a policy-hidden palette window and pins "hidden":false in the response

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Gate secondary startup windows on the window_hide_on_close feature

- loadStartupWindows creates index > 0 windows through the platform services directly, bypassing the runtime create path's close-policy support check: a .hide declaration on a secondary startup window was silently accepted on hosts that cannot re-show a closed window, so the user's close really closed it
- The same loud error.UnsupportedWindowClosePolicy gate now rides that direct create; the host-created main window keeps its own init-time refusal
- New test drives the GTK-shaped null platform (window_hide_on_close=false) through a .quit main plus .hide secondary startup pair and pins the refusal at load; the supported host loads both windows

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Require the tray capability for .hide on Windows and downgrade tray-less hides

- close_policy "hide" on windows now requires the "tray" capability at every validation seam: the SDK runner and generated-template comptime checks refuse the declaration (SW_HIDE removes the taskbar entry and windows has no dock-reopen path, so the status item is the only re-show affordance; macos stays exempt via the Dock), and the runtime create gates inherit the refusal because the Windows host answers window_hide_on_close only when the manifest declares a tray (new AppInfo.declares_tray, threaded like has_web_content), with a Linux-style init refusal for the host-created main window
- Runtime backstop for a tray that validation accepted but creation lost: the WM_CLOSE hide hook consults the host's live tray_active state and downgrades a tray-less .hide close to a real close with a loud stderr line - a visible close beats a running, invisible, unreachable app
- Tests: pure-fn coverage for the conditional supports answer and the init refusal, generated-template text pins for the windows teaching and the declares_tray threading, and a textual pin holding the WM_CLOSE tray consult ahead of the SW_HIDE with the downgrade line present (the C++ branch itself is beyond the suite; both WebView2 configurations cross-compile clean to x86_64-windows-gnu)

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Count UTF-8 bytes in the emitter's literal length gates

- Cmd.showWindow's label gate (and every sibling string-literal gate: host/request names, cancel/delay/request/spawn/audioPlay/audio-verb/Sub.timer keys, and the asciiBytes literal bound) counted UTF-16 code units while teaching bytes, so a 200-character CJK label passed the gate and arrived as 600 UTF-8 bytes against the wire's 255-byte length prefix; every user-text gate now measures Buffer.byteLength (Cmd.fetch header names/values stay on .length - they are ASCII-enforced right above, where the counts agree)
- rt.cmdWindowShow's std.debug.assert compiles out of ReleaseFast, where the length-byte @intCast would then truncate and corrupt the wire record silently - it is now an explicit panic in every build mode, the loud backstop behind the emitter's build-time teaching
- Conformance pins both sides of the byte bound (100 CJK chars = 300 bytes teaches; an 84-char/250-byte multibyte label emits and compiles) and the effects harness pins the wire record for a CJK label carrying its 9-BYTE length prefix

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

* Document the Windows tray prerequisite for close_policy hide

- The windows, app.zon, and tray pages now state the tray-capability requirement and the runtime downgrade the round-10 guard introduced.

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>

---------

Co-authored-by: perminder-klair <3984412+perminder-klair@users.noreply.github.com>
2026-07-19 10:37:55 -05:00
Chris Tate e59091060f Fix the Linux Debug startup crash at the GTK create-view seam (#153)
* Fix the Linux Debug startup crash at the GTK create-view seam

- Force the LLVM backend for the app executable on x86_64 (and in the ejected template's build): zig 0.16.0's self-hosted backend shifts native_sdk_gtk_create_view's stack-passed arguments, so Debug `native dev` runs crashed reading a garbage role pointer.
- Cap the GTK host's view string lengths at the platform limits with a teaching refusal, so a corrupted C-ABI boundary fails loudly instead of faulting in strndup.

Co-authored-by: codehz <13158903+codehz@users.noreply.github.com>

* Add a Linux Debug-scaffold runtime smoke to CI

- linux-dev-smoke scaffolds the default ts-core template with the CLI, builds it -Doptimize=Debug with automation, and drives it under Xvfb to ready + first presented pixels.
- Pins the Debug half of the Linux runtime story: release-shaped lanes always use the LLVM backend and can never see a Debug-only x86_64 codegen fault.

Co-authored-by: codehz <13158903+codehz@users.noreply.github.com>

* Apply the x86_64 LLVM-backend workaround to the checked-in example builds

- The web-frontend examples own expanded build.zigs that created their exe without use_llvm, leaving Debug x86_64 runs exposed to the same self-hosted-backend C-ABI miscompile the app graph now guards against.

Co-authored-by: codehz <13158903+codehz@users.noreply.github.com>

* Restore the windows-canvas-smoke job key the dev-smoke insertion ate

- Duplicate name/runs-on/steps keys collapsed both jobs into one: the Wine smoke ran mislabeled and the new Debug scaffold smoke never executed.

Co-authored-by: codehz <13158903+codehz@users.noreply.github.com>

---------

Co-authored-by: codehz <13158903+codehz@users.noreply.github.com>
2026-07-18 12:14:13 -05:00
Chris Tate 57bf56bc58 Prepare v0.5.3 release (#145)
- Bump Native SDK package versions and platform pins to 0.5.3

- Merge pending changelog fragments into the marked 0.5.3 release notes

- Fold contributor credits for the v0.5.2..HEAD release range
2026-07-17 16:51:10 -05:00
Chris Tate 1e6b615674 Prepare v0.5.2 release (#138)
- Synchronize the CLI, core, platform packages, and examples at version 0.5.2.

- Merge pending fragments into the marked v0.5.2 release notes with contributor credits.
2026-07-16 22:39:42 -05:00
Chris Tate eefa3690c9 Polish the live-smoke ledger: grid slots, dark focus ring, system monitor states (#128)
* Keep declared grid column slots when children run short

- gridColumnCount no longer clamps the declared column count to the child count, so a filtered grid's children keep their column-slot width instead of stretching across the freed row
- pin the rule in the widget layout tests and in both soundboard e2e batteries (Zig example + TS port), which search the album grid down to one match and hold the tile at its natural width

* Desaturate the accent focus ring in dark appearance

- canvas.accentOverrides now takes the resolved scheme and derives the dark focus ring at half the accent's HSL saturation (canvas.accentFocusRing), matching the built-in packs' per-scheme ring moves
- the Zig soundboard theme states the same derivation so both authoring tiers land the identical ring; pins in the token tests and both soundboard suites

* Polish the system monitor footer and empty state in both tiers

- label the footer sample time UTC: local rendering would need a journaled tz channel to keep replay byte-identical, so the honest label wins for this sweep
- clear the transient 'terminate request delivered' notice on the next applied sample (failure notes still stick); pinned in both e2e batteries
- hint the top-128-by-CPU search scope in the no-match empty state, derived from the sampler cap

* Note the per-scheme accent ring in the soundboard-ts README

- the theme_accent bullet now names the dark scheme's desaturated focus-ring derivation

* Floor the dark accent ring at 3:1 and harden grid row math

- accentFocusRing's dark step now lifts the desaturated ring's HSL lightness until it holds 3:1 (WCAG non-text) against the default dark background whenever the accent itself cleared that bar, and never below the accent's own contrast when it did not — halving saturation alone dropped #008000 from 3.9:1 to ~2.6:1; a hue-sweep test pins the floor, and the changelog fragment now states the accentOverrides ColorScheme parameter as a deliberate pre-1.0 break with the .light migration line.
- gridRowCount ceil-divides as 1 + (count - 1) / columns so an unclamped huge declared column count no longer overflows the additive form in safe builds; both the layout and intrinsic-size paths already share the helper, and a unit test covers maxInt columns and zero children.

* Floor the accent ring on the lightest adjacent dark tone and finish the grid row sweep

- accentFocusRing's dark floor now measures against the lightest tone controls commonly sit on (house surface_subtle #262626) instead of the background, so rings drawn on cards and muted chrome clear 3:1 too — green's ring rises from ~2.72:1 to 3.49:1 on the dark surface, and the never-invent escape hatch caps at the accent's own contrast against that same reference
- Route intrinsicGridChildrenSize's row count through gridRowCount: the additive ceil-div still panicked when a parent intrinsically measured a nonempty grid with maxInt columns (the earlier fix only covered the placement path)
- Extend the hue sweep to assert 3:1 per adjacent tone across both packs and add the nested-grid intrinsic regression (verified to panic before the fix)

* Gate the transient-note clear on a sample launched after the kill

- A ps sample already in flight when the kill confirmed collected its rows before the signal, so its ps_done must not retire the delivered notice; both cores now bump a sample generation at launch and clear only when an applied sample's generation exceeds the kill_done stamp (pure Msg-driven state, replay-deterministic)
- Pin the race in both batteries: the stale in-flight sample applies with the notice surviving into the rendered footer (kill exit and stale ps exit drained in one batch), and the first sample launched after the kill retires it
- Rework the live kill-note pins to drive real launches through the cadence so delivered-clears and failure-persists keep their semantics under the generation gate
2026-07-16 11:01:50 -05:00
Chris Tate 4d83ce2f0d Derive every editor mutation through one seam so Escape reaches your core (#129)
* Derive every keyboard editor mutation through one stamped-edit seam

- updateCanvasWidgetTextFromKeyboard now stamps the edit it derives and applies onto the routed event, so the app dispatch hears exactly what the retained editor did — Escape's search-field clear, its composition cancel, and the single-line ArrowUp/Down caret jumps were runtime-only before and never reached the model.
- The app-side msgForKeyboard consumes the stamped edit first and keeps its own derivation only as the fallback for events that never crossed the runtime.
- The context-menu edit path routes through the same seam and dispatches the stamped event.

* Route automation composition verbs through the real ime input path

- widget-action set_composition/commit_composition/cancel_composition now dispatch the ime gpu input events a live IME session produces: journaled for replay, applied by the editor, and mirrored to the core's on_input — direct editor writes kept the model out of the loop.
- set_selection synthesizes the stamped keyboard event the clipboard edits use, so the core's selection mirror follows; it stays un-journaled (no selection input kind exists on the wire).
- The accessibility action dispatch and the mobile widget-action ABI funnel through the same verbs, so all three surfaces converge.

* Pin the edit-derivation seam across mirror, replay, and both tiers

- ui_app tests drive a search field through Escape, ArrowUp, ime cancel, and the automation composition/selection verbs, asserting the model mirror and the retained editor agree.
- The reference record/replay session types into a search field and Escape-clears it, so replay must re-derive the same clear from the raw journaled events.
- Soundboard e2e batteries (Zig live app and transpiled TS core) pin Escape clearing the query and unfiltering the library.

* Add changelog fragment for the Escape edit-derivation fix

- User-facing story: Escape in a search field now reaches your core, plus the automation composition verbs riding the real input path.

* Journal accessibility actions outer-wins so replay dispatches once

- Suppress event records staged while a journaled widget_accessibility_action dispatch is on the recorder's staging stack: the verb's synthesized key/text/drop children are deterministic derivations the replayed action re-runs, so recording both dispatched every child twice on replay.
- Effect results still write through mid-action in feed-then-dispatch order, and event_count/checkpoint ordinals stay coherent with the records a replay reader actually sees.
- Pin the class end to end: repeated AX press and set_text plus the composition verbs record and replay with exactly-once input counts and one journal record per action.

* Journal direct-surface accessibility verbs as outer-wins action records

- Stage a synthetic widget_accessibility_action inside dispatchCanvasWidgetAccessibilityAction when no platform tag-23 event is on the recorder's staging stack: the direct verb surfaces (embed widgetAction, automation widget_action — now delegated through the same dispatch) journaled only untargeted focus-routed children while the verb's focus write stayed unjournaled, so a first-in-session composition or set_text replayed against the wrong editor or none at all; nested inside a staged platform AX event the synthetic stage is a suppressed placeholder, keeping exactly one record.
- Add the composition kinds to the platform WidgetAccessibilityActionKind enum (values 11-13, additive) with both widget_bridge mappings, so the journal and replay's tag-23 arm carry every verb.
- Pin the class: composition first-in-session, composition while another field holds focus, and set_text first-in-session all record action-only journals and replay onto their target editor; a recorder mechanics test pins the nested placeholder.

* Suppress the open arrow's caret edit and bump the journal to v4

- A CLOSED combobox's ArrowUp/Down are its open keys: the app dispatch resolves the press before any stamped edit, so the caret derivation now yields no edit there and the retained editor agrees with the model mirror; an open picker's arrows already walk into the mounted menu, and an expanded trigger without one keeps the caret jump both sides hear.
- Bump the session journal format to v4: this branch serializes the composition action codes 11-13 into accessibility-action records, which a v3 reader would have called corrupt instead of refusing as version skew; the skew message now names the version this build reads, and the skew test pins refusal of older journals too.
- Rewrite the journal's stale coverage note: every automation verb journals now (direct-surface verbs as the outer-wins widget_accessibility_action record), so the v1 do-not-journal caveat is gone.
2026-07-16 10:00:35 -05:00
Chris Tate f7aa92af6d Prepare v0.5.1 release (#127)
- Bump CLI, core, platform, and example versions to 0.5.1
- Merge pending changelog fragments into the marked release entry
- Refresh exact package pins for reproducible publishing
2026-07-13 14:17:59 -05:00
Chris Tate e2627ee07f Prepare v0.5.0 release (#120)
- Bump the CLI, platform packages, @native-sdk/core, and runtime version to 0.5.0, and drop the private flag from @native-sdk/core — the release workflow publishes it from this version on.

- Fold the pending changelog fragments into the marked v0.5.0 entry: TypeScript authoring (#119) plus the signing (#118) and static-TLS (#117) fixes.

- Credit co-authors from the release range in the v0.5.0 contributor list.
2026-07-12 22:45:05 -05:00
Chris Tate 584dbbbaa9 TypeScript authoring: write app cores in TypeScript (#119)
* TypeScript authoring: write app cores in TypeScript

- App cores can be authored in TypeScript and compiled ahead of time to arena-backed native code: the complete language minus the ecosystem and purity violations, checked by tsc plus a teaching checker (NS1001-NS1060), emitting readable Zig with 83ns dispatch, no JS engine, and no GC
- The full platform surface reaches TS cores: the Cmd and Sub effects vocabulary bridged to the real engine, markup views binding the committed model, record and replay byte-identical to node semantics, stock-IDE support, multi-file cores with @native-sdk/core library modules, and native init scaffolding TypeScript by default with Zig first-class by choice
- Two showcase ports prove the bar with zero hand-written Zig: soundboard-ts at pixel parity with its Zig original and system-monitor-ts sampling the real OS, each with end-to-end batteries including replayed sessions with zero host calls
- Docs lead TypeScript-first with a segmented language toggle and a markup-first components reference; the eval suite gains dual-track realistic cases measuring both authoring tiers' health and efficiency

* Ship packages/core in the npm package and run its .ts modules from any layout

- copy-framework.js stages the @native-sdk/core closure (src/, sdk/, rt/, package.json + package-lock.json; test/ and scripts/ stay out), the sync check pins each staged entry plus the dep.path coverage, and package.json "files" covers the mirrored paths
- build/ts_run.mjs runs the transpiler tier's .ts modules on every layout: node refuses builtin type stripping under node_modules, so the runner strips those modules with the transpiler's own installed TypeScript and passes repo checkouts through untouched; build/app.zig, native check, and native dev --core all invoke through it
- the missing-dependency teaching now names the real dependency root (works verbatim on the npm-installed layout, where npm ci runs in the shipped packages/core against its shipped lockfile)

* TS scaffolds ship a CI workflow

- the --full ts-core template now writes the Zig full template's workflow (logic tests + Linux automation smoke, no WebKitGTK) with the node tier added to both jobs: setup-node and one npm ci in the fetched SDK's packages/core, the same install native build's teaching names
- slim scaffolds keep shipping no workflow (zero-config parity with the slim Zig template), now pinned by the ts slim template test

* Wire @native-sdk/core into the release automation

- sync-version.js stamps packages/core (manifest + lockfile own-package fields) and the committed TS examples' pins with the CLI release version, check-version-sync.js refuses a half-bumped tree, and the npm version script stages the stamped files; packages/core rides 0.4.4 from here on and scaffold pins follow the bundled manifest automatically
- the release publish step gains the packages/core publish gated on its "private" flag: private (until the 0.5.0 cut, by design) skips with a loud flip-requirement comment; dropping the flag is the publish switch, no workflow edit needed
- the TS scaffold README notes npm install is optional (the CLI materializes and refreshes the editor package itself), closing the pre-publish gap window honestly

* Provide node to the CI jobs that build TypeScript cores

- The Native Examples job panicked on the missing transpiler dependency, and the Zig Core and tooling jobs were silently skipping every node-gated ts-core suite; all three now set up node and npm ci packages/core
2026-07-12 21:37:07 -05:00
Chris Tate e71338f872 Blend geometry edge coverage in linear light (#89)
- Anti-aliased fringes of opaque geometry (rounded rects, path fills and strokes) now composite in linear light through a LUT, removing the dark rim sRGB-space blending grows on curved edges; interiors stay byte-identical via an opaque fast path
- Glyph coverage and translucent sources keep sRGB blending so text weight and overlay brightness are unchanged, and tests pin the split in both directions
2026-07-10 08:26:57 -05:00
Chris Tate 33da7101fa Stroke the checkbox mark through the vector core (#87)
* Stroke the checkbox mark through the vector core

- The check was two diagonal draw_line commands, and the line rasterizer's binary capsule test has no anti-aliasing, so the mark stair-stepped at every scale while the stroke icons around it rendered clean
- One stroked polyline with round caps and a round join now rasterizes the same shape with real coverage; a test pins the anti-aliased property so the mark can never regress to hard edges

* Own path elements in the builder and carry the stroke cap to the GPU host

- Path elements now live in builder-owned storage instead of threadlocal frame scratch, so commands from separately emitted trees can never alias each other's geometry; charts and the spinner adopt the same lifetime
- The stroke cap rides the packet command, both wire encodings (v4), and the fingerprint, and the AppKit host applies it plus the reference renderer's round join when stroking paths
2026-07-09 23:14:12 -05:00
Chris Tate 26df3687f4 Make the Windows embedded WebView layer real (#86)
* Make the Windows embedded WebView layer real

- Vendor the WebView2 SDK header and loader under third_party/webview2 (BSD-3-Clause, license preserved) so repo state alone compiles the embedded layer; a missing header is now a hard error instead of a silent stub
- Fix the conformance blockers behind the guard: a local WRL callback factory for mingw, the uncaptured bridge-handler variable, an EventToken shim, and STA COM initialization on the host thread
- Stage the arch-matched loader beside built, run, packaged, and scaffolded apps, mirror it into the npm payload, and pin the wiring with vendor and loader-layout tests

* Carry the SDK root through package shortcuts and generated builds

- packageShortcut and package-ios now pass the environ map into createPackage like the package verb, so NATIVE_SDK_PATH resolves the framework root for loader staging from standalone binaries
- Generated frontend builds export NATIVE_SDK_PATH on the package command and stage the loader dir on the dev command's PATH, mirroring the SDK-dependency graph
2026-07-09 21:48:41 -05:00
Chris Tate 512298b474 Anti-alias rounded primitives and adopt Per-Monitor V2 DPI on Windows (#81)
* Anti-alias rounded primitives and adopt Per-Monitor V2 DPI on Windows

- Rounded-rect fills and strokes render through one continuous signed-distance coverage field, so curved edges ramp smoothly with no silhouette drift; a supersampled ground-truth test pins shape fidelity and radius-0 rects stay bit-identical
- Hairline borders snap to whole device pixel columns at emit time and geometry snapping is on by default in the house and Geist packs, keeping 1px borders crisp while arcs stay smooth; pure-SDF geometry remains available by disabling pixel_snap.geometry
- Windows apps declare Per-Monitor V2 DPI awareness in the embedded manifest and the Win32 host sizes windows, child views, and surfaces in physical pixels with WM_DPICHANGED re-rasterization, so canvases render at device scale instead of being bitmap-stretched

* Re-pin example reference signatures for the snap default

- gpu-dashboard and gpu-components pin their reference-surface signatures inside the example suites, which only test-examples-native runs; the geometry-snap default changed those pixels

* Re-apply explicit webview frames on DPI change and stamp static tokens with surface scale

- WM_DPICHANGED now re-applies explicit child webview frames rooted at the message window, matching the native-view pass
- effectiveTokens stamps pixel_snap.scale onto a copy of static tokens and scale changes rebuild static-token apps, so hairline snapping stays on the device grid across monitor density changes

* Lay out the components scene with the tokens it renders with

- The catalog laid out under default tokens (geometry snapping off) and rendered under pack tokens (snapping on), so the ceil rule for label-exact widths no-oped and per-edge frame rounding elided the third theme tab
- Layout builders now take the token set, the live app lays out with its surface tokens, and a regression test asserts the theme strip never elides under snapping in either pack

* Snap hairline borders to the lighter whole-pixel width

- Within the existing snap-eligibility window, fractional hairline widths now floor to the lighter device-pixel count instead of rounding, so a 1px border at 1.5x covers one crisp device column instead of two
- Sub-half-pixel strokes still never snap and 1x, 1.25x, and 2x rendering is pinned byte-identical by the updated tests

* Adopt resize-carried density and give each window its own snap scale

- handleResize adopts the event's scale factor before rebuilding, so a DPI-only monitor move re-stamps tokens and re-emits even when the logical size is unchanged
- Window slots own a per-window pixel_snap_scale stamped into their token emission, so secondary windows on different-density monitors snap on their own device grid

* Round native view frames once from accumulated logical coordinates

- Native child view origins accumulate logical x/y through the parent chain and every physical edge rounds exactly once, so nested controls no longer drift a pixel at fractional scales and abutting frames share pixel columns
- The app manifest declares an ordered DPI awareness chain (PerMonitorV2, PerMonitor, legacy dpiAware) so pre-1607 systems degrade gracefully instead of losing awareness entirely

* Round hidden-titlebar content sizes like the standard path

- hiddenOuterSizeForContent rounds scaled content extents through a shared helper instead of truncating, so hidden-titlebar windows and min-size floors match the requested logical size at fractional scales
- check-framework-sync now explains that the package mirror is generated and points at copy-framework.js instead of implying the mirror should be committed

* Chain window DPI resolution through monitor and system fallbacks

- dpiForWindow now mirrors the manifest's awareness chain: GetDpiForWindow, then GetDpiForMonitor via shcore, then the system DPI, so pre-1607 systems that the manifest makes DPI-aware no longer render tiny 1x content
- gpuSurfaceScale delegates to the shared helper and the build pin asserts the chain alongside the manifest elements
2026-07-09 21:32:50 -05:00
Chris Tate c17c64e4c9 Align repository URLs with the renamed GitHub repo (#80)
* Align repository URLs with the renamed GitHub repo

- Point repository.url at vercel-labs/native in all eight platform packages so npm provenance validation passes (the v0.4.1 publish failed on the first package)
- Guard in check-version-sync.js: platform repository.url and homepage must match the main package
- Sweep remaining vercel-labs/zero-native links and zero-native.dev domains across docs, templates, and fixtures to the new canonical names

* Sync repository and homepage fields in sync-version.js

- version:sync now stamps repository and homepage from the main package into each platform package, making the check script's remediation hint accurate
2026-07-09 10:29:58 -05:00
Chris Tate b47111069c Native SDK: the complete toolkit for building native desktop apps (#67)
zero-native becomes the Native SDK. Apps are authored as native markup plus Zig on a deterministic runtime and rendered by the toolkit's own engine into real OS windows — no browser, no WebView, no interpreter in the binary.

- Desktop is complete on macOS, Windows, and Linux: native rendering with per-platform titlebar fidelity, audio playback with streaming, a verified track cache, and real spectrum analysis, native context menus, packaging with sealed code signing, and a deterministic automation and record-replay story.
- Experimental iOS and Android host tiers ship behind the same app manifest: simulator and emulator dev loops, archive-ready packaging, real platform tab bars and push navigation, with embedding over the C ABI underneath.
- The docs site, component catalog, theme packs, showcase apps, and CHANGELOG carry the full account.
2026-07-08 18:51:43 -05:00
Chris Tate 5b272a28e9 Fix Android mobile stop lifecycle 2026-06-26 21:54:21 -05:00
Chris Tate 2591284640 Fix generated manifest window options 2026-06-26 21:16:19 -05:00
Chris Tate 10cc3c24af Fix file drop paths and MIME validation 2026-06-25 13:03:44 -05:00
Chris Tate ab5a418b85 Fix native packaging review issues 2026-06-25 12:46:42 -05:00
Chris Tate 9af28f75d5 Fix Windows main WebView bridge and accessibility 2026-06-25 11:20:19 -05:00
Chris Tate 230fe3ff00 Fix chromium backend gating 2026-06-25 10:53:58 -05:00