gpui delivers DragMoveEvent to every drop target with a matching
payload type under the cursor, and every slider shared the SliderDrag
payload type — dragging one slider (e.g. an OFX panel parameter) also
moved every other slider the cursor passed over (timeline zoom, track
height). Tag the payload with the starting control and ignore drag
moves that are not ours.
Also finish the gesture on mouse-up (inside or outside the track)
instead of on_drop: gpui only delivers drop events to the hovered
target, so releasing outside the track used to leave the drag
unfinished and the final value/undo edit unemitted.
The Cmd+K split ran the plain per-block split for every selected clip,
so an originally linked audio/video pair came out with its front halves
linked but the two rear halves unlinked — dragging one rear clip left
its mate behind and Link/Relink could not repair it.
Split the whole target set as ONE BlockSplitPreservingLinksCommand (the
same command the multicam path uses): any pair of originally linked
blocks split at the same time gets its new halves linked too. Adds a
gpui test asserting front and rear halves of a dropped A/V clip stay
linked after split_at_playhead.
Real plugins (CImg ChromaKeyerOFX, AddOFX) failed the render action with
kOfxStatFailed / MissingHostFeature and painted the magenta failure frame:
- images lacked the mandatory ImageBase properties (OfxPropType,
PixelAspectRatio, PreMultiplication, Field, RenderScale); the ofxs
ImageBase constructor throws on the missing/invalid strong reads
- PreMultiplication used the made-up string "OfxImagePreMultiplied";
kOfxImagePreMultiplied is actually "OfxImageAlphaPremultiplied", the
only value mapStrToPreMultiplicationEnum accepts (lldb __cxa_throw
backtrace pinpointed this)
- RenderWindow is Int x4 per ofxsPropertyValidation, not Double x4
- field strings use the real constant "OfxFieldNone"
- clips define OfxImageClipPropConnected (isConnected is a strong read;
optional mask clips blew up without it)
- choice params predefine empty ChoiceEnum / ChoiceLabelOption arrays
- isIdentity failure is no longer fatal (the C++ plugin renderer never
calls it; plugins that error on it simply render normally)
- property suite coerces Int <-> Double on reads (the CImg framework
reads the render window with propGetIntN against a Double store)
- in-args carry NatronOfxPropNativeOverlays=0 for the Natron framework
- plugin jobs pass a GL-kind marker so GL-only plugins take the real
gl_bridge offscreen path instead of the CPU MissingHostFeature path
- trace-gated [ofx] diagnostics for property misses and suite calls
Verified with new smoke tests that render the real AddOFX and
ChromaKeyerOFX plugins through the executor and assert the output is
not the purple failure frame.
Adding an effect to a clip did nothing: the sequence render is
flattened into a montage (decode + composite), and MontageClip carried
no effect data at all.
- MontageClip gains an ordered effect stack (type id / enabled /
effect input / parameter values); protocol v2 carries it as an
additive wire field (older peers default to an empty stack).
- renderops::video_montage fills the stack from the effect chain
(the footage source node — the chain end without an effect input —
is dropped; the montage decodes the footage itself). Export
(oak-task) and the multicam single-track montage fill it too.
- The worker applies the stack between decode and composite: built-in
Opacity gets a CPU evaluator (C++ opacity.frag parity — whole vec4,
alpha included, unity pass-through); everything else dispatches as an
OFX plugin job through a new instance-factory slot (oak-plugin
lazily creates + caches one instance per identifier per render
process) with the montage's parameters injected. Disabled effects
bypass (the C++ traverser pushes the effect input through). Unknown
types warn once per type id and pass through — no silent no-ops.
Not covered (explicitly): Transform/Crop and the other ~30 built-in
effects have no CPU evaluator in oak-render (they pass through with a
warning), keyframed parameter animation, audio effect chains, and the
CLI's simplified montage.
Acceptance: a real 50% Opacity on real media quarters the rendered
pixels both in-process (renderops test) and through a real worker
process over IPC + shared memory (procpool_integration test);
disabling restores the plain render byte-for-byte.
Link toggle rule refinement (on top of 1ad2d71c8): the toggle now
unlinks only when the selection is FULLY linked internally — the C++
crude "any member has ANY link" check made split halves (which inherit
the original clip's A/V links via BlockSplitPreservingLinksCommand)
impossible to link to each other. Test: link_unlink_toggles_the_
selection_links covers toggle/undo/split-link.
Node editor: only stream inputs (texture/samples) become ports — OFX
plugins declare every parameter as an input, which buried the card
under internal params (the garbled NatronOfxParamProcess* wall). Secret
inputs stay hidden; port labels use the input's display name (the OFX
param label); edges resolve ports by input id, not by label.
编辑 > 链接/重新链接 (Cmd+L) was an unhandled stub
(PanelCommandHandler::toggle_links returned false), so linking clips
never created graph links and linked drags never happened.
- graphops::set_clips_linked: one undoable entry toggling every pair of
the selection; the undo restores the exact prior internal topology.
- RealEngine::toggle_clip_links: fully-linked selections unlink,
otherwise the selection links together (the C++ crude "any member has
ANY link" rule would have made split halves — which inherit the
original clip's A/V links — impossible to link to each other).
- TimelinePanel overrides toggle_links, routing the timeline selection.
- MockEngine stores demo link pairs.
- Test: link_unlink_toggles_the_selection_links — dropped A/V pair
toggles off/on with undo, and split halves link manually.
- docs/zh/plans: finished plans move to completed/ (the RIIR series, the
event-bridge and dependency plans, the v04 manual test plan).
- New design docs: the external (functional) plugin system
(process-isolated, JSON-RPC/shm) and its protocol.
- ai-agent-design refreshed; README pointers follow the moves.
Touchpad fixes from user testing:
- SpinBox: the wheel only steps a FOCUSED field — hover-wheel is inert,
so two-finger scrolling across a dialog no longer drifts values.
- SpinBox: direct numeric entry — double-click opens the editor (the
app's text input; commit on blur, Escape cancels), typing a digit on
the focused field starts editing with that character. Previously the
field accepted no text at all.
- ComboBox: a click anywhere outside closes the open popup
(on_mouse_down_out).
- gpui bump: the timeline header-occlusion fix.
- Help > About Oak… opens a real dialog (was a placeholder print): name
+ version, the GPL-3.0 line, the Olive fork notice and the thanks to
Enzo GD (Community Promoter).
- Modal (gpui_widgets, submodule bump): a title-row close button on
every dialog and opt-in backdrop dismissal (dismiss_on_mask) — Help >
Search Actions and About use it, so they close on an outside click
(previously a buttonless modal could only be closed with Escape).
- Preferences general tab grows two live settings: the cache-ahead
pre-render window (PlaybackPreRenderFrames, consumed by the preview
scheduler every playback tick) and the library storage backend
(Storage/Backend sqlite/pg + Storage/PgUrl connection string, read by
oak-storage's write-through when a project binds; the pg URL field
shows only for PostgreSQL and commits on dialog close). The C++
auto-recovery toggle is skipped on purpose: the Rust snapshot loop
has no disable semantic, so the switch would be dead.
i18n keys for all eight packs; new tests cover the about modal and the
preferences writes.
The popup was a plain absolute child: dialog rows after the combo drew
OVER it, making the list look transparent (its text overlapped the
content behind). deferred() paints it after all ancestors.
The menu item was a placeholder print; it now opens a real dialog (the
C++ ProjectPropertiesDialog):
- Per-project OCIO config override with a 浏览… picker: validated on OK
(an invalid config keeps the dialog open with the error shown, like
the C++ accept()), persisted in the project settings, applied to the
display color pipeline on accept and on project open, and reverted to
the app default when the project closes. oak-render gains
set_up_default_config_from for the explicit-path load.
- Disk-cache location (default / alongside the project / custom path):
persisted through the OVE serializer (cachesetting/customcachepath
round-trip the settings map, clamped on load) and honored by the
thumbnail writer — the first live consumer of Project::cache_path.
- PathField gains an enabled state (the custom path field follows the
combo selection).
The C++ color tab's Default Input Color Space and Reference Space
combos are intentionally absent: the Rust render pipeline has no
consumer for them today (decode performs no input transfer conversion),
so showing them would be dead settings.
Tests: dialog opens, OK applies the cache location, an invalid OCIO
config keeps the dialog open with the error row. i18n keys for all
eight packs.
convert_bgra8 applied packed u8 pixels to the default (F32-finalized)
OCIO CPU processor, which rejects them with a bit-depth mismatch; the
callers swallow the error, so the display-ICC transform was silently
inert on the shm preview path. ocio-rs exposes no Uint8-finalized CPU
processor, so the conversion now detours through F32. Verified against
the machine's actual display profile with the new
display_icc_bgra8_never_outputs_black test (OAK_DISPLAY_ICC).
Also:
- procpool_integration: audio tickets are Seek priority and claimable
by any worker now, so the shard-spread assertion goes (rendering on a
live worker is what matters).
- OAK_DEBUG_VIEWER=1: the program viewer logs frame pushes and dumps
the displayed frame to /tmp/oak_viewer_frame.ppm (the black-screen
investigation tooling).
RealEngine::set_track_height held the project graph lock while calling
graphops::set_track_height, which locks the same mutex — an instant
same-thread deadlock with any sequence open (sampled live: main thread
in nudge_track_height -> set_track_height -> Mutex::lock, no other
lock-holder thread). Collect the track ids under the lock, drop it,
then apply the heights.
Also:
- Regression test set_track_height_does_not_self_deadlock.
- save_load_roundtrips_a_timeline_clip: real footage through the OVE
serializer (also the fixture generator for viewer debugging).
Three compounding bugs froze the UI when dragging the playhead after
playback:
1. Self-deadlock on preview_windows: supply_preview_window /
cancel_preview_windows / cancel_preview_window called
cancel_preview_sequence / cancel_preview_frame while HOLDING the
preview_windows mutex; those calls fire completions synchronously and
the completion locks preview_windows again. Caught by sampling the
hung process: UI thread in cancel_preview_sequence -> TicketSlot::
finish -> completion -> Mutex::lock. Cancels/releases are now
collected under the lock and fired after it is dropped.
2. Seek starvation by shard pinning: a Seek request's scheduler frame
is its ticket id, pinning it to worker (id mod W). The playback
window fills every worker's slots (window slots are only released by
UI-thread consumption), so the seek's pinned worker could have zero
free slots while the UI thread blocked on the seek — permanent
starvation. Seeks (interactive frame / real-time audio) are now
claimable by ANY worker; the no-stealing shard rule stays for
Playback frames (adjacent frames finish together).
3. No per-worker reserve: the global preview_window_capacity reserve is
pool-wide accounting, but exhaustion happens per worker. Playback /
Background claims now leave one credit unused per worker; Seek
claims may use the last slot (they complete on the worker without
UI involvement).
Also: RealEngine::drop cancels the preview windows — ShmFrameRef has no
self-release, so every dropped engine leaked its window's slots from
the shared pool, starving later windows (surfaced as the full-suite
playback_window_supplies_playhead_frames failure once the new probe
test shifted the test schedule). new_sequence_has_default_two_video_
two_audio_tracks now takes the engine test lock (it asserts on the
global undo stack; running lock-free raced parallel undo histories).
New regression probe interactive_seek_renders_without_hanging: play 30
ticks (window fills and holds shm slots), pause, seek, synchronously
render — must not hang. Scheduler tests updated for the reserve and
seek-any-worker contract. OAK_DEBUG_DISPATCH=1 enables the dispatcher
starvation/pool diagnostics used to track this down.
Every test_project() node packs the same NodeId::identity (a fresh
graph's first node), so two tests running in parallel collide in the
process-wide registry and one resolves the other's live entry —
identity_project_dropped's dangling-upgrade assert then fails
intermittently on CI. Both identity tests now share a mutex.
The probe step pointed OAK_OFX_FIXTURE_DIR at .cache/ofx-fixtre, so the
ofx_roundtrip test found no fixture plugin and failed with "the fixture
plugin registered (got [])".
The background watchdog subshell inherited the step's stdout/stderr; when
cargo test finished, its lingering sleep child kept the pipes open and
the runner aborted the step with "exec: WaitDelay expired before I/O
complete". Redirect the watchdog to /dev/null and reap it after the
test so the step's I/O closes cleanly.
ci (Windows): the runner's msys2 shell starts as the base MSYS
environment (MSYSTEM=MSYS), which install-deps.sh rejects. Set the
job-level MSYSTEM=UCRT64 env and prepend /ucrt64/bin to PATH in every
Windows step, so pacman installs and the toolchain resolve against the
mingw-w64-ucrt-x86_64 packages.
fixtures: the restructured workspace moved the media fixtures into
crates/oak-app/tests; the remaining references pointed at the old
repo-root tests/ — oak-codec realmedia_tests + hwdecode, oak-node
serializer golden, oak-worker procpool integration. All point at
../oak-app/tests now (oak-app's own tests/demo.mp4 references were
already correct after the move).
The Gitea runner's msys2 shell does not start in the checkout
directory, so "bash ./tooling/install-deps.sh" reported the file
missing even though the checkout succeeded (the Linux steps were fine —
only the custom msys2 shell has the wrong CWD). Every Windows step now
begins with cd "$GITHUB_WORKSPACE" to make all relative file
references resolve.
A CRLF ci.yml turns every step command into "cmd\r", so bash fails to
find the referenced scripts on the Windows runner ("bash
./tooling/install-deps.sh: No such file or directory" — the file is
there, the command carries a trailing CR). Same class as the golden
JSON/OVE fix: pin *.yml/*.yaml to eol=lf.
Three real-engine throughput loops (thumbnail pipeline, full-res fill
behind the proxy, playback window supply) failed on machine slowness:
their pass/fail was a wall-clock Instant deadline, so a loaded machine
broke them for speed, not for a broken pipeline. Each loop now counts
engine pumps — machine-speed independent — and asserts the condition
within a bounded number of pumps. The two single-frame worker channel
receives keep a generous 60 s recv_timeout (a one-shot bounded
operation, not a throughput loop).
oak-cli: the integration fixtures moved with the app crate during the
workspace restructure; point the fixture helpers at
../oak-app/tests instead of the (now empty) repo-root tests/.
playback_display_tracks_the_playhead used a 30 s wall-clock deadline as
its pass/fail criterion, so a slow or loaded machine failed the test
for machine speed, not for a broken pipeline — spurious, unrelated to
any race. The loop now terminates on playback-clock progress (playhead
>= 120, ~5 s of playback; the transport advances independently of
render speed, so termination is guaranteed) and the only judgment is
the tracking invariant at that point. No Instant::now() remains.
Verified green on a heavily loaded machine in 84 s.
oakui/component/controls.rs owns the effect/editor controls instead of
reaching into gpui_widgets:
- Slider: horizontal 1:1-cursor drag (the gpui_widgets slider only
responded to vertical cursor movement, so horizontal drags did
nothing), wheel, middle-click reset, arrow keys (Shift = 1/10 step,
Home/End = range ends), and double-click numeric editing (app text
input; commit on blur, Escape cancels). A gesture emits
ValueChanged exactly once on drop — one undoable edit per drag, so
per-mouse-move edits + frame invalidation can no longer freeze the
UI thread.
- CheckBox: click / Space / Enter toggle, request-only contract
(Toggled + set_state), theme colors, optional label.
- ComboBox: click opens a popup list, Up/Down navigate (open) or
change the selection (closed), Enter commits/opens, Escape closes.
- SpinBox: wheel + Up/Down (Shift fine) + Home/End.
The params panel, timeline and dialogs import from the component
module. App-move fallout: i18n packs resolve from the repo-root
assets/i18n via CARGO_MANIFEST_DIR (crates/oak-app is not the repo
root anymore), and the render tests' worker-binary paths point at
../../target/debug/oak-worker.
All crates take the oak-* kebab-case naming (oak-audio, oak-codec,
oak-common, oak-core, oak-ffmpeg-link, oak-node, oak-otio, oak-plugin,
oak-render, oak-storage, oak-task, oak-timeline, oak-undo), with the
lib identifiers rewritten (oakrender:: -> oak_render::, oakcore_rs:: ->
oak_core::, ...) across all 226 referencing files.
The GUI application moves from the workspace root into
crates/oak-app/: src/, build.rs (paths fixed for the new location) and
tests/ travel with it, the root Cargo.toml becomes workspace-only
([workspace] + workspace.package + profiles), and the app package
inherits the workspace version. The screenshots example becomes a
standalone crate examples/simple_player/ with its own Cargo.toml.
Every crate now inherits the single workspace version
(version.workspace = true), and the workflows' crate paths and the
build docs follow the renames.
Validated with a clean cargo check --workspace.
oakui/component gains the two app-facing components:
text_input: the app's text field — the gpui_elements editing engine
(IME composition, caret, selection, undo) wrapped with the app theme's
colors (text via a text_color refinement on the wrapping div so the
engine's run layout picks it up; selection/caret/placeholder/IME-marked
directly) — and install_text_input_bindings(), which binds the
Backspace/Delete/arrow/Home/End/select-all editing keys into the app
keymap scoped to the EditableText context. The app never installed
them before, so every field accepted IME text but ignored its editing
keys; the bindings are now wired once at OakApp::new. All seven call
sites (ofx_params x2, effect_library, manager, dialogs x3) use the
component instead of gpui_elements directly.
menu: all app menu code consolidates here — the model types are
re-exported, the shared context-menu plumbing (ContextMenuHandle,
ContextMenuTriggered) and the shared segments (edit/clip-edit/in-out/
color-label/new, the viewer context menu, the dynamic language menu)
move in from src/menus, which is deleted; app.rs and every panel
import from the component. Inline fully-qualified crate paths in
non-use positions are replaced with use imports.
The single matrix job becomes two independent jobs on the oak Gitea
runners (oak-ubuntu-2404 / oak-windows-2025 — the user's labels, kept
as-is). Every runner.os conditional collapses into the owning job and
all macOS steps are removed. actionlint.yaml whitelists the two oak
runner labels (actionlint needs -config-file now that the config lives
under .gitea/ instead of the default .github/ path).
Gitea prep: .github becomes .gitea (the act runner looks there), and
every actions/cache + Swatinem/rust-cache step is commented out until
the self-hosted instance has a cache provisioned. The remaining
marketplace actions (checkout/upload-artifact are act-compatible;
msys2/setup-msys2, dtolnay/rust-toolchain and softprops/action-gh-release
need a runner test / replacement) are a follow-up.
tests: the two gpui keystroke tests that flaked on Windows CI (undo
pair, snapping toggle — each once, values identical to the pass state,
Global-route keys) now dispatch each key with a double park. The root
cause is not fully pinned: the loss happens inside gpui's synthetic
key dispatch on Windows (both tests hold every test lock; production
is unaffected). The CI retry-once remains the backstop. The earlier
idea of advancing the simulated clock to flush gpui's pending-input
timer is off the table: the mock engine's playback ticks with executor
time, so a clock advance moves the playhead out from under the
assertions (observed: playhead 14 vs expected 9).
Two different gpui keystroke tests flaked on Windows CI with the same
signature: a synthetic keystroke occasionally never reaches the action
(secondary-z lost while secondary-shift-z delivered; then a plain 's'
lost). Both passed every other run — a gpui test-harness delivery
flake, not an oak regression. A single retry pass absorbs it; a real
regression fails both passes.
edit_shortcuts_dispatch_to_the_engine dispatched secondary-z and
secondary-shift-z before a single run_until_parked; on Windows CI the
first key's binding hit was intermittently lost (undo 0, redo 1 —
twice, identically). Park after each key like every other assertion in
this test, and assert both reached the engine (>= 1) instead of the
exact pair count.
preview_window_capacity used the *configured* worker count, so a
window opened while workers were still handshaking (or after a crash)
could claim every slot of the smaller live pool — the synchronous
render ticket then never gets a free slot, and since the slot-releasing
cleanup runs on the same UI thread that is blocked in TicketArena::wait,
playback deadlocks permanently. Intermittent on Linux CI (the
playback_display_tracks_the_playhead hang, caught by the new test
watchdog): depends on how many workers had handshaken when playback
started. Count only Alive workers (fall back to the configured count
while none are alive, keeping the existing unit test semantics).
oakstorage: the sqlite URI parse tests used /tmp/lib.db, which is not
absolute on Windows, so parse_target's is_absolute check rejected it.
Pick the absolute path per platform (C:/tmp/lib.db on Windows).
ci (Linux): wrap the test step in a 1500 s watchdog — a deadlocked
test prints nothing and never fails; on timeout the watchdog dumps
every test/worker process's thread stacks with gdb and then kills the
suite. (One such hang already ate a run; the previous green run needed
~4 min.)
ci+cd: Swatinem/rust-cache gains cache-on-failure everywhere, so a
red run still saves its compile cache (the actions/cache FFmpeg cache
already saves in its post phase regardless of outcome).