24 KiB
Iris extraction handoff
Operational handoff for pulling Iris out of ai-app into a standalone framework. Not a decisions log; delete it when the extraction is done.
Where things stand
Canonical main is ca2b4b2 (#17, the headless rig). Sixteen slices are
in.
#18 split/18-position-chain is open and finished apart from one decision:
worktree /home/bob/repos/iris-pr18, head 4178dfb, twelve commits, 49 tests
passing, fmt and clippy clean. It is LAYOUT.md §2's position chain, generalised
to boxes. /home/bob/repos/ai-app-2 is on rustify, worktree clean.
The one thing waiting on the owner. tabs at 1920x1200 is no longer
byte-identical to upstream/main: 1,283 pixels of 2.3M (0.06%), two
one-pixel-wide panel edges shifted by a pixel, at x=1056 and x=1337. view,
minimal and text are identical. Composing a position through the chain in
the shader associates the arithmetic differently from collapsing it on the CPU,
so a value that used to land exactly on an integer falls the other side of the
shader's floor. The CPU and the GPU still agree with each other -- both walk
the chain bottom-up -- so hit testing matches what is drawn; what changed is
only the comparison against the old code. Matching it exactly means composing
root-down in the shader, which needs the chain collected into an array first.
Byte-identical against upstream/main has been the bar for every slice, so
this is hers to accept or to spend a commit on.
Check for a review before starting anything, and read the newest submitted_at
rather than the first result:
TOKEN=$(cat ~/.config/gitea/token)
N=18
curl -s -H "Authorization: token $TOKEN" \
https://git.arirex.me/api/v1/repos/iris/iris/pulls/$N/reviews
curl -s -H "Authorization: token $TOKEN" \
https://git.arirex.me/api/v1/repos/iris/iris/pulls/$N/reviews/<id>/comments
curl -s -H "Authorization: token $TOKEN" \
https://git.arirex.me/api/v1/repos/iris/iris/issues/$N/comments
My replies are ordinary issue comments on the same PR and say what each change was for.
How a position resolves now
Invariants, not history. Everything in core/src/ui rests on them.
- A slot holds a box, in the coordinates of the slot it names. A primitive
instance and a mask each name one, and
prelude.wgslcomposes the chain withwithin. A translation is the special case where the box has its parent's relative extent. The identity isUiRegion::FULL, not zero -- a zeroed entry is a box of no extent and collapses its subtree to a point, whichMoveOffset's comment says beside theZeroablethatPodrequires. - A slot has to carry a whole box rather than a scale and an offset: a
pixel-space affine map scales everything under it, including a child that
must keep its pixel length, and the
rel/abspair is exactly what distinguishes the two. - Slots are opt-in.
Painter::placedraws a child whose box its parent decides and may decide again, and that child gets a slot;widgetandwidget_withindo not, and share the nearest ancestor's.Span,AlignedandScrollplace. This is what keeps the chain 2-4 deep rather than full tree depth, which is the difference between free and +42.6%. - A widget's region is held in the coordinates of the slot it draws in, so
a placed widget draws against
UiRegion::FULLand its box lives in its slot.ActiveData::regionis the box it was offered, in its parent's slot coordinates, andActiveData::parent_moveis the slot that is in;window_regioncomposes the one through the other, which is the walk the shader does. - Nothing inverts a lerp.
UiRegion::stretch,stretchableandUiScalar::stretchare gone. A box that changed length is written to its slot and the descendants recompose against it, which also covers the case the old guard refused outright: a fixed length has no fraction to recover, so a 40-tall row could not be stretched on its other axis at all. - Reuse is decided on the box a widget drew against, in pixels
(
ActiveData::px). A region is a fraction of a slot's box, so an unchanged region is not an unchanged box -- a child drawn atFULLof a slot that has since halved compares equal to itself. This is the check everything else rests on; do not weaken it back to comparing regions. - A size the parent learnt by drawing the child is an answer for that box
only.
redraws_underredraws a child whose size the widget read unless it declares an exactsize_hintfor the changed axis -- the one case the parent did not have to draw it to find out. The cost is that a size-reading container gives up its reuse when its box changes length, which is every span, soOnResize::Scaleearns its keep on moves and on subtrees whose sizes nobody read rather than on every stretch. redraws_underis a question asked before reusing, never a marking. Marking descendants for redraw instead does not terminate: the mark escalates to that descendant's size reader, which re-places the child, which marks it again. Asking first and giving up the whole reuse adds no marks and stops.- The walk stops where a length did not change. A part of a box with no relative extent on an axis is a fixed length held as offsets from that box's start, and composing anything into it leaves no relative extent either -- so a widget whose own box did not change length has no descendant whose box did. An 80-wide child of a widened row is never asked.
Span,Pad,Stack,Offset,Aligned,SetSizeandLayerOffsetsayScale; each places in fractions and offsets of its own box and none reads its pixel length.ScrollandMaxSizeread pixels and stayRedraw, which is the general rule:Scaleon an axis unless the draw reads the pixel length of its box on that axis. The default staysRedraw.OnResize::Scalekeeps its name. The owner rejectedStretchon 2026-09-14: stretch has an opposite and scale does not, and the answer is per axis, so the axis is already established where it is read.
Measured, so the next attempt is compared rather than argued
| rig | what it says |
|---|---|
tests/chain_cost.rs |
GPU pass time by chain depth at 200k instances. Translate slots: free to depth 8 (+5%), then ~3 us per level, +42.6% at 16 and +221% at 64. Each step is a storage load addressed by the previous one, so it is the chaining that costs, not the arithmetic at a level. A box slot (36 bytes) against a translate slot on the same binary: +0.6% at depth 1, +0.5% at 2, +0.8% at 4, then +9.6% at 8 and +32.2% at 64 -- free where opt-in slots put it, and dear only where the chain already was. |
tests/replace_cost.rs |
Instructions per frame re-placing 200 rows: 1.98M writing each row's slot, 2.38M rewriting its regions, 7.13M redrawing it. A load for perf, not a check. Five primitives per row; the regime that decides whether the chain is worth it is a transcript row of a few hundred glyphs, so re-run it with 200 characters of text per row before concluding anything from it. |
tests/draw_cost.rs |
What recording a frame costs on the CPU by layer count. Dispatch per list is 6 instructions, 0.1% of a frame at 256 and at 1024 layers. |
A chain is irrelevant at an example's couple of hundred primitives; a
transcript's glyphs are tens of thousands, which is the regime chain_cost
measures.
The random trees
iris::random grows a seeded tree -- spans in every direction holding two to
four children, stacks, padding with each of its four sides its own number,
rects with varying opacity, text both wrapping and overflowing, a declared size
over half of it, stopping at a depth. examples/random.rs draws one
(IRIS_SEED, IRIS_DEPTH). tests/generated.rs grows each seed twice -- once
and then changed, once with the change built in -- and compares every widget's
box across eight scenarios: a size change, a resize, both, and five ways of
changing what a span holds. a_long_run_of_seeds_agrees is the ignored sweep,
100 seeds across all eight, 800 comparisons, about four minutes.
The property is that laying a tree out again lands where growing it cold does,
which is the same thing as layout being a function of the state. It earned
itself immediately: it found the non-terminating marking, the pixel-box reuse
check and the measured-size rule above, none of which the hand-written tests
reached, and it says the result is better than what it started from -- 90 of 90
against 83 on db1751f.
Four things about it that are easy to get wrong:
- Both trees must make the same widgets in the same order. Comparison is index for index, so a tree that makes fewer widgets, or frees one whose id is then handed to the next, stops lining up at the first difference and every comparison after it is against the wrong widget. Hence three spare leaves grown beside every span whether they end up in it or not, and detached children held until the comparison is over.
- Attaching a spare moves it. A widget belongs to one parent;
WeakWidget::upgraderegisters an add and panics with "cannot add a widget twice", so it is for a handle that was never added, not a second share. - Each shuffle asserts the tree actually changed before comparing, or a case that quietly did nothing passes green.
- A failure prints the widget's ancestry, marking the ones that own a slot, because where two trees disagree is rarely where the cause is.
Verifying a slice
cd <iris-worktree>
cargo fmt --all --check
cargo clippy --workspace --all-targets -- -D warnings
cargo test --workspace
49 tests pass on #18's head. --workspace matters: rig-input is a crate of
its own.
Render checks are the last pass, not the iteration loop -- the owner asked for that on 2026-09-14, since the layout tests cover the CPU part and the shots cost real time:
./scripts/run-headless.sh tabs --mode 1920x1200@60Hz --shot /tmp/out.png
./scripts/run-headless.sh tabs --replay /tmp/taps.touch --shot /tmp/out.png
./scripts/run-headless.sh tabs --mode 1920x1200@60Hz --resize 900x1200@60Hz --shot /tmp/rs.png
- The reference shots are
tabs,view,minimalandtextat 1920x1200, plustabswith a replay that switches to the image tab and adds two images. A.touchline is<ms> down|move|up <x> <y>in the output's own pixels; the tab strip is at y=24 and the five tabs at x = 192, 576, 960, 1344 and 1728, with the image tab's add button near (1836, 1116). - A resize is its own case, and
--resizeis it: the output changes under the running app, and what it lands on must match a cold start at that size byte for byte. That caught both of #16's defects and nothing incargo testcan see it. - Run one at a time. The rig reuses a single compositor and a single output, so two invocations at once resize each other's window and quietly screenshot the wrong thing. Two sets of shots were thrown away learning that.
- Give a comparison worktree its own target dir. While one was shared between two checkouts I got results I could not reproduce afterwards; the mechanism was never pinned down, so re-run any cross-checkout comparison in isolation before believing it.
Two drawing paths still have no shot of their own, and each needs a ui the examples do not have, so both are throwaway examples written into the worktree and deleted after:
- An image alone in a layer, which is the case that failed GPU validation when every other test happened to have a rectangle in the same layer.
- Six lines of 400px text, which forces the atlas to four pages and proves the array grew and its group was rebuilt.
tabs with the image replay covers rects, glyphs and images together, so that
one is an ordinary check now.
How the work is sequenced
Most fundamental first, from the owner on 2026-09-13: "please do more
fundamental changes first, such as library updates and core framework changes,
so that code only has to be written once", and "should probably start adding
tests early on rather than later, so you don't have to make separate test
scripts and stuff." So slices are ordered by how much depends on them, not by
what is nearest ready, and a slice arrives with tests rather than with a script
in /tmp.
Agree a design before sending another variation of it. The owner stopped the fourth round of #11 with "we should probably agree on the design here rather than you keep submitting variations that I review". When a review comes back about the shape of something rather than a defect in it, put the options and a recommendation in front of her and implement what she picks.
Nothing is submitted without a separate review pass -- the installed
pre-submit-review skill: build clean, review the code, review the comments on
their own once the code has settled, then verify the claim by running it. The
fixes a review produces are themselves unreviewed code, so the passes repeat
until a round finds nothing. It has earned its place repeatedly: four defects
on #11 that format, clippy, tests and five headless renders had all passed, and
on #12 a regression introduced by the review's own first draft. audit.sh in
the skill directory prints every comment line a branch adds against a base ref;
the owner's standing complaint is verbose agent comments, and the default
verdict is delete. Machine-specific notes do not belong in the repository --
they live in ~/.claude/MACHINE.md or a this-machine-* skill.
Other standing instructions from the owner:
- Pull Iris out even if the Rust application switchover is not accepted. No
app, session, transcript, setup or server concepts in Iris; the dependency
runs one way from
app/to Iris. - Small, coherent PRs. The original extraction PR was too large to review.
A slice may be redone rather than transplanted, and need not remove every old
feature. Non-conflicting pull requests may be open at once -- disjoint path
sets, each branched from current
upstream/mainrather than stacked. She reviews small ones as they arrive and only avoids two large ones in flight. - Order by dependency, largest reach first. On 2026-09-13: "do the large reaching framework changes first so less has to be redone."
- Do not recreate an
aibranch in canonical Iris; the fork is the boundary. - Never rewrite a pushed branch. Follow review with additive commits, and
merge
upstream/mainin rather than rebasing when a branch falls behind. - Respond to each review finding with a fix or a concise explanation. Do not add a ceremonial comment when the changed code already answers it.
- A test has to guard something that could break again. She deleted #14's test as pointless: the rename it guarded cannot regress. When a fix is structural, the structure is the test.
- Say who decided a constraint. LAYOUT.md §2's "move slots carry translation only" was written by an agent on 2026-09-04, was never asked for, and read as settled until she said "I was not aware that an agent decided position slots should be translate only." Mark an agent's own choice as one.
What is left
Next, and small: LazySpan, the last of LAYOUT.md §2. set_child_offset
is no longer part of it -- a child offset is just placing the child, which
Painter::place now does.
Then, roughly in dependency order:
-
Built-in alignment, and probably size, which the owner moved ahead of the rest on 2026-09-14. Reproduced in the harness:
.width(rel(0.5))inside aDir::DOWNspan reports 200 of 400 and is handed the whole 400, and aPadin between does not change that. Do not "fix" it by reading the child's orthosize_hint-- aPadbetween theSetSizeand the span has no hint of its own, so the declared width silently goes back to filling. It works only when nothing is in the way. Alignment has to belong to the widget rather than be discovered through whatever happens to sit on top of it.Two things beyond the bug argue for it. Built-in size removes
SetSize, and with it a wrapper reporting one size while handing its child the whole box. And built-in alignment is what would letOnResize::Translateapply to centred content, which otherwise has to sayRedrawbecause only its own draw knows where the middle was. Size is the harder half: a declared size beside the onedrawreturns is two sources of truth for one thing, so settle what each means before building it. -
OnResize::Translate, which still does nothing. The chain removed half its obstacle: a placed widget's slot holds the box it was offered while its drawing is a set of fractions of that box, so the two are no longer one field. What is still missing is a widget saying where in a bigger box its unchanged drawing should sit, which is the alignment work above. -
UiRenderStatebehindRc<RefCell<..>>, queued by the owner on 2026-09-13 as fundamental, and especially so for text. -
Len,LayoutLenand dp. The archive splits the type so thatrestis unrepresentable where it is meaningless (a padding), and folds a density in at resolve time. 21 files mentionLen, so it is wide but shallow. -
The input restructure --
src/default/sense.rsbecomessrc/rsc/sense.rs(308 lines to 2313), pluscore/src/event/controller.rs,desktop/input.rs,android/input.rsandsense_tests.rs: pointer capture, drag slop and axis, platform cancellation, mask-aware hit testing, event timestamps. The archive's ownconsumesis what #12 landed, so that part transplants;tests/pointer_routing.rsis the acceptance criterion. -
Retained span, scrolling and layout placement.
-
Retained paints, selection, overlays and shared UI runtime state.
-
Generic desktop/Android framework hosts and reusable example/APK tooling.
-
Application-owned fonts and application-named font families.
-
Shared resource-handle bookkeeping and replaceable glyph-atlas buckets.
-
Positioned text overflow and cluster-safe ellipsis.
Dependencies are current apart from winit, which stays on 0.30.12 until 0.31
leaves prerelease. parley 0.11.1 and image 0.25.10 are latest.
The archive is a reference, not a patch to apply -- it writes Widget::draw
against painter.set_size, which #16 replaced with a returned Size, and
lengths against LayoutLen and density, which canonical does not have.
Recreate a change on today's types, leave app-specific behaviour out, and
verify it independently.
cd /home/bob/repos/iris && git fetch upstream
git diff --stat upstream/main..origin/archive/full-extraction
How the renderer works now
Current invariants, not history. Worth reading before touching core/render.
- A primitive registers itself by being drawn. The type carries its own
WGSL, and
PrimitiveRegistrykeys ids byTypeId, so the kind comes from the type and there are noRECT/GLYPH/TEXTUREconstants. Nothing is seeded, so an id depends on what a ui drew first and a ui pays only for the pipelines it uses. - Each primitive records its own draws.
Primitive::rendermakes aPrimitiveRenderthat states the layout its shader reads, uploads whatever it owns, and records its draws.GlyphRenderowns the atlas and binds it once per list;ImageRenderowns the images and binds one per instance; the default owns nothing and draws every instance in one call. The renderer sets the pipeline, the shared group, the list's data and its vertex buffer, and knows nothing else. - The shared bind group is the window, the masks and the move chain, given to every draw. A mask texture would go here too. What a primitive samples is its own group, and a primitive that samples nothing has no such group in its pipeline.
- Every binding size is stated. A
Noneminimum puts the binding on wgpu-core's late-sized list, whichis_readyscans on every draw. shader/prelude.wgslplus one file per primitive, because one module cannot declare two types at the same binding. The prelude carries only what every primitive uses -- window, masks, the chain walk, the vertex shader,masked()-- and its header is where binding numbers are written down.- A texture handle is drawn like anything else.
Painter::primitivetakesimpl PrimitiveLike: a primitive, or something that yields one and does whatever else drawing it needs -- a&TextureHandleretains its share on the way through, which aPodprimitive cannot. - Order within a layer means nothing, and the widgets do not rely on it:
Stackgives each child its own layer andTextEditdraws its view in a child layer above the selection rectangles. - Images are one texture and one bind group each, so each drawn image is a
draw call. The owner chose that on 2026-09-13 over packing images into arrays
like atlas pages; a bindless
binding_arraywas ruled out by Android support. Revisit only with her. - Layers are never freed (
TODOinprimitive/layer.rs), so every layer a session creates is walked every frame thereafter. Measured at ~2ns per empty layer per frame, which is why it is the TODO's problem and not a bug of its own.
Repository topology
ai-app checkout
/home/bob/repos/ai-app-2,origin = git@git.arirex.me:iris/ai-app.git, branchrustify.iris/is a submodule pinned at32f6ad8, the complete extracted snapshot, and.gitmodulespoints at the bot fork, not canonical Iris.- Do not change either casually: ai-app needs the complete snapshot while canonical Iris is only partly caught up. Reconcile when canonical contains what ai-app needs, or when the owner accepts a temporarily non-building pin.
standalone Iris checkout
/home/bob/repos/iris,origin= fork,upstream= canonical.- Fork
mainandorigin/archive/full-extractionboth name32f6ad8, the target snapshot.history/fullnames the source-history resulta615bcd. - Do not reset, overwrite or force-push fork
main: it is both the target reference and the commit ai-app pins. - Start each new branch from current
upstream/mainin its own worktree:
cd /home/bob/repos/iris && git fetch upstream
git worktree add -b split/19-name /home/bob/repos/iris-pr19 upstream/main
/home/bob/repos/iris-pr18 is the live one. Every other iris-pr* worktree
holds a merged branch; they are readable references, not places to build.
Cautions
- Read
/home/bob/repos/ai-app-2/AGENTS.mdand the machine-wide rules first. Anything about this machine -- the GPU that comes and goes, measuring a small performance difference, the emulator -- is in~/.claude/MACHINE.mdand thethis-machine-*skills, and belongs there rather than here. - Keep Iris generic: session drivers, transcripts, setup and server concepts, app icons and product fonts stay in ai-app. Android and desktop code is Iris work only when it is a generic host or platform integration.
- Preserve the dirty-worktree rule. All worktrees were clean at handoff; anything found later may be the owner's or another agent's.
- Do not delete the archived snapshot or the fork
mainai-app pins. - A complete target branch is not permission to recreate the giant PR.
- Another agent was freeing disk on this VM and removed
target/from theiris-pr*worktrees once. Sources and git state were untouched. Tell peers before changing shared machine tooling, and expect a cold rebuild sometimes.
Merged so far
| PR | On canonical main |
|---|---|
| #2 | Build on the current nightly (4275314) |
| #3 | Request a frame after resize (936fbdd) |
| #4 | Decouple iris-core from winit (465e430) |
| #5 | Use vsync by default (ec2b5d4) |
| #6 | Notify winit before presenting (db9b0f2) |
| #7 | Keep unsafe reference helpers internal (0191f20) |
| #8 | Initialize the window uniform from the surface (6e271e8) |
| #9 | Preserve primitive-count recursion (b90c855) |
| #10 | Text layout and rendering on Parley (0f6a28b) |
| #11 | Atlas as an array texture, and the primitive rendering overhaul (b234497) |
| #13 | Build on wgpu 30 (00d2230) |
| #14 | Rename the Sized widget to SetSize (32b1038) |
| #15 | Run a ui without a window, and test one (c8ac669) |
| #12 | Route pointer input per kind (43ce8c7) |
| #16 | Size a widget while drawing it, not in a pass of its own (f942385) |
| #17 | Bring the headless rig into the repository (ca2b4b2) |
URLs are https://git.arirex.me/iris/iris/pulls/{number}.