wl-pick 0.5.0

A live grid of window and display previews, for picking one
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
//! Capturing windows and displays.
//!
//! One session per tile, all opened before a single roundtrip so their buffer
//! constraints arrive together, and every first frame put in flight at once: the
//! compositor is bandwidth-bound reading pixels back, so serialising the
//! captures only adds latency.
//!
//! The pixels are never mapped into this process. A capture buffer goes straight
//! to a subsurface for display, so the compositor writes those pages and samples
//! them again itself. Nothing here interprets them, which leaves one thing that
//! must still be right: the stride declared with each buffer, since how wide a
//! row is depends on the format the session picked.

use std::error::Error;
use std::os::fd::AsFd;
use std::time::{Duration, Instant};

use wayland_client::protocol::{
    wl_buffer::{self, WlBuffer},
    wl_callback, wl_output, wl_shm,
    wl_subsurface::WlSubsurface,
    wl_surface::WlSurface,
};
use wayland_client::{Connection, Dispatch, QueueHandle, WEnum};
use wayland_protocols::ext::image_capture_source::v1::client::ext_image_capture_source_v1::ExtImageCaptureSourceV1;
use wayland_protocols::ext::image_copy_capture::v1::client::{
    ext_image_copy_capture_frame_v1::{self, ExtImageCopyCaptureFrameV1, FailureReason},
    ext_image_copy_capture_manager_v1,
    ext_image_copy_capture_session_v1::{self, ExtImageCopyCaptureSessionV1},
};
use wayland_protocols::wp::viewporter::client::wp_viewport::WpViewport;

use crate::app::App;
use crate::shm;
use crate::target::{Kind, Target};

/// Which tiles keep updating after the first frame.
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum Live {
    /// Every tile.
    All,
    /// Only the selected tile: much cheaper, and still reads as alive.
    Current,
    /// Nothing: one snapshot each, a picker rather than an expose.
    None,
}

impl Live {
    pub fn parse(s: &str) -> Result<Self, String> {
        match s.trim() {
            "all" => Ok(Live::All),
            "current" => Ok(Live::Current),
            "none" => Ok(Live::None),
            other => Err(format!("{other:?} is not all, current or none")),
        }
    }
}

/// One capture buffer. `busy` means the compositor still holds it — either it is
/// on screen or a capture is writing into it — so we must not scribble over it.
pub struct Slot {
    pub(crate) buffer: WlBuffer,
    pub(crate) busy: bool,
}

/// Pick a buffer format from what the capture session `offered`, and say how
/// many bytes one of its pixels takes.
///
/// Byte order is the compositor's business on both ends -- we never read these
/// pixels -- but the size of a pixel is ours, because the stride declared with
/// the buffer has to match the format. XRGB8888 and ARGB8888 are the two every
/// wl_shm supports, so they come first; otherwise take the first offer we can
/// both measure and hand back for display, since what a session can capture
/// into is not always what wl_shm can show.
fn choose_format(
    offered: &[wl_shm::Format],
    supported: &[wl_shm::Format],
) -> Option<(wl_shm::Format, i32)> {
    let sized = |format: &wl_shm::Format| Some((*format, bytes_per_pixel(*format)?));
    offered
        .iter()
        .filter(|f| matches!(f, wl_shm::Format::Xrgb8888 | wl_shm::Format::Argb8888))
        .find_map(sized)
        .or_else(|| {
            offered
                .iter()
                .filter(|f| supported.contains(f))
                .find_map(sized)
        })
}

/// How many bytes one pixel takes, for the formats a row of which is simply the
/// width times that.
///
/// These are the ones wlroots can hand us (its `pixel_formats` table), and a
/// capture session offers whatever it can capture into -- not only the two
/// wl_shm guarantees, and not all four bytes wide. Declaring a four-byte stride
/// for an eight-byte format is a protocol error that takes the connection with
/// it, so a format missing from here is one to decline rather than guess at.
///
/// Subsampled formats are absent deliberately. YUYV and friends do have a
/// constant block size, but a block covers two pixels, so their rows are
/// narrower than width times it and the arithmetic here would not hold.
fn bytes_per_pixel(format: wl_shm::Format) -> Option<i32> {
    use wl_shm::Format;
    Some(match format {
        Format::Rgb565 | Format::Bgr565 => 2,
        Format::Xrgb1555 | Format::Argb1555 => 2,
        Format::Rgbx4444 | Format::Rgba4444 | Format::Bgrx4444 | Format::Bgra4444 => 2,
        Format::Rgbx5551 | Format::Rgba5551 | Format::Bgrx5551 | Format::Bgra5551 => 2,
        Format::Rgb888 | Format::Bgr888 => 3,
        Format::Xrgb8888 | Format::Argb8888 | Format::Xbgr8888 | Format::Abgr8888 => 4,
        Format::Rgbx8888 | Format::Rgba8888 | Format::Bgrx8888 | Format::Bgra8888 => 4,
        Format::Xrgb2101010 | Format::Argb2101010 => 4,
        Format::Xbgr2101010 | Format::Abgr2101010 => 4,
        Format::Xbgr16161616 | Format::Abgr16161616 => 8,
        Format::Xbgr16161616f | Format::Abgr16161616f => 8,
        _ => return None,
    })
}

/// Where each tile's buffers go in the capture pool.
#[derive(Default)]
struct PoolPlan {
    total: usize,
    /// Tile index, and the pool offset of each of its slots.
    slots: Vec<(usize, Vec<usize>)>,
}

pub struct Tile {
    pub(crate) target: Target,

    pub(crate) session: Option<ExtImageCopyCaptureSessionV1>,
    /// A capture in flight, and which slot it is filling.
    pub(crate) frame: Option<ExtImageCopyCaptureFrameV1>,
    pub(crate) filling: Option<usize>,
    pub(crate) slots: Vec<Slot>,
    /// The slot that should be on screen, and the one the subsurface actually
    /// has attached. They differ while the tile is scrolled out of sight, and
    /// an attach only costs the compositor an upload when they do.
    pub(crate) showing: Option<usize>,
    pub(crate) attached: Option<usize>,
    pub(crate) formats: Vec<wl_shm::Format>,
    pub(crate) format: Option<wl_shm::Format>,
    /// Bytes per row of the capture buffer, which depends on the format: a
    /// stride that does not match is a protocol error, not a wrong picture.
    pub(crate) stride: i32,
    /// Buffer size the session required when the buffers were allocated: the
    /// window's full resolution at the time.
    pub(crate) size: (u32, u32),
    /// The source has changed size since. The buffers no longer fit it, so the
    /// tile keeps its last frame rather than asking for one it cannot hold.
    pub(crate) stale: bool,
    pub(crate) transform: wl_output::Transform,
    pub(crate) session_done: bool,
    pub(crate) ready: bool,
    pub(crate) settled: bool,
    /// When the last capture was asked for, for rate limiting, and how many
    /// frames this tile has produced.
    pub(crate) asked: Option<Instant>,
    pub(crate) frames: u32,

    pub(crate) surface: Option<WlSurface>,
    pub(crate) subsurface: Option<WlSubsurface>,
    pub(crate) viewport: Option<WpViewport>,
}

impl Tile {
    pub fn new(target: Target) -> Self {
        Self {
            target,
            session: None,
            frame: None,
            filling: None,
            slots: Vec::new(),
            showing: None,
            attached: None,
            formats: Vec::new(),
            format: None,
            stride: 0,
            size: (0, 0),
            stale: false,
            transform: wl_output::Transform::Normal,
            session_done: false,
            ready: false,
            settled: false,
            asked: None,
            frames: 0,
            surface: None,
            subsurface: None,
            viewport: None,
        }
    }

    pub fn bytes(&self) -> usize {
        self.stride as usize * self.size.1 as usize
    }

    /// Whether the buffer's contents are turned on their side relative to the
    /// window, which flips the aspect ratio we have to fit.
    pub fn rotated(&self) -> bool {
        use wl_output::Transform;
        matches!(
            self.transform,
            Transform::_90 | Transform::_270 | Transform::Flipped90 | Transform::Flipped270
        )
    }
}

impl App {
    /// Open one capture session per window whose toplevel we recognise. They are
    /// all opened before a single roundtrip, so every session's buffer
    /// constraints arrive together instead of costing a round trip each.
    pub fn open_sessions(&mut self, qh: &QueueHandle<Self>) {
        for (i, tile) in self.tiles.iter_mut().enumerate() {
            // A window's source comes from its toplevel handle, a display's from
            // its wl_output; everything after that is identical.
            let source: Option<ExtImageCaptureSourceV1> = match tile.target.kind {
                Kind::Window => self
                    .toplevels
                    .iter()
                    .find(|(_, id)| !id.is_empty() && *id == tile.target.ft_id)
                    .map(|(handle, _)| self.src_mgr.create_source(handle, qh, ())),
                Kind::Output => self
                    .outputs
                    .iter()
                    .find(|(_, n)| *n == tile.target.id)
                    .and_then(|(output, _)| {
                        self.output_src_mgr
                            .as_ref()
                            .map(|mgr| mgr.create_source(output, qh, ()))
                    }),
            };
            let Some(source) = source else {
                // Nothing to capture from: the tile stays label-only, and must
                // not be waited on.
                tile.settled = true;
                continue;
            };
            tile.session = Some(self.copy_mgr.create_session(
                &source,
                ext_image_copy_capture_manager_v1::Options::empty(),
                qh,
                i,
            ));
            source.destroy();
        }
    }

    /// Allocate the capture buffers in one pool and put every first frame in
    /// flight at once: the compositor is bandwidth-bound reading pixels back, so
    /// serialising the captures only adds latency.
    ///
    /// Live mode gets two buffers per window. A capture may not write into the
    /// buffer the compositor is currently displaying, so the two alternate:
    /// fill B while A is on screen, swap, and wait for A's release before
    /// touching it again.
    pub fn start_captures(&mut self, qh: &QueueHandle<Self>) -> Result<(), Box<dyn Error>> {
        // Cloned because the loop below borrows the tiles mutably; the list is
        // short and fixed once wl_shm has announced it.
        let shm_formats = self.shm_formats.clone();
        for tile in &mut self.tiles {
            if tile.session.is_none() {
                continue;
            }
            if !tile.session_done || tile.size.0 == 0 || tile.size.1 == 0 {
                tile.settled = true;
                continue;
            }
            let Some((format, bytes)) = choose_format(&tile.formats, &shm_formats) else {
                eprintln!(
                    "wl-pick: no usable buffer format for {:?} (offered {:?})",
                    tile.target.title, tile.formats
                );
                tile.settled = true;
                continue;
            };
            tile.format = Some(format);
            tile.stride = tile.size.0 as i32 * bytes;
        }

        // A live tile alternates between two buffers; anything else needs one,
        // and a display's is the size of the whole screen. A wl_shm pool is
        // limited to what fits in an i32, so if two each will not, fall back
        // to one each and say so.
        let live = self.live != Live::None;
        let mut plan = self.plan_pool(|t| {
            if live && t.target.kind != Kind::Output {
                2
            } else {
                1
            }
        });
        if plan.total > i32::MAX as usize {
            eprintln!(
                "wl-pick: {} MB of capture buffers is more than wl_shm allows; \
                 using one per window",
                plan.total >> 20
            );
            plan = self.plan_pool(|_| 1);
        }
        if plan.total > i32::MAX as usize {
            return Err(format!(
                "{} MB of capture buffers is more than wl_shm allows; try --no-outputs",
                plan.total >> 20
            )
            .into());
        }
        if plan.total == 0 {
            return Ok(());
        }

        self.stats.pool_bytes = plan.total;
        // Note: no mmap. The compositor writes these pages and samples them
        // again for display; mapping them here would only cost us the faults.
        let file = shm::memfd("wl-pick-capture", plan.total)?;
        let pool = self
            .shm
            .create_pool(file.as_fd(), plan.total as i32, qh, ());
        for (i, offsets) in plan.slots {
            let t = &self.tiles[i];
            let (w, h, stride) = (t.size.0 as i32, t.size.1 as i32, t.stride);
            let format = t.format.expect("planned tiles have a format");
            for offset in offsets {
                let slot = self.tiles[i].slots.len();
                let buffer = pool.create_buffer(offset as i32, w, h, stride, format, qh, (i, slot));
                self.tiles[i].slots.push(Slot {
                    buffer,
                    busy: false,
                });
            }
            self.request_capture(i, qh);
        }
        pool.destroy(); // the buffers keep the mapping alive
        Ok(())
    }

    /// Lay out one pool: which tiles get buffers, at what offsets, and how big
    /// the pool has to be. Only a tile that chose a format takes part.
    fn plan_pool(&self, slots_for: impl Fn(&Tile) -> usize) -> PoolPlan {
        const PAGE: usize = 4096;
        let mut plan = PoolPlan::default();
        for (i, tile) in self.tiles.iter().enumerate() {
            if tile.format.is_none() {
                continue;
            }
            let offsets = (0..slots_for(tile))
                .map(|_| {
                    let offset = plan.total;
                    plan.total += tile.bytes().div_ceil(PAGE) * PAGE;
                    offset
                })
                .collect();
            plan.slots.push((i, offsets));
        }
        plan
    }

    /// Ask the compositor for one frame of window `i`, into a free slot.
    ///
    /// After a session's first frame the compositor only answers once the window
    /// content changes, so a request left outstanding on an idle window costs
    /// nothing: this is damage-driven, and the rate limit only bites on windows
    /// that really are animating.
    fn request_capture(&mut self, i: usize, qh: &QueueHandle<Self>) {
        let t = &mut self.tiles[i];
        if t.frame.is_some() || t.session.is_none() {
            return; // already waiting on one
        }
        let Some(slot) = t.slots.iter().position(|s| !s.busy) else {
            self.stats.starved += 1;
            return; // both buffers still held by the compositor
        };
        let (w, h) = (t.size.0 as i32, t.size.1 as i32);
        let frame = t
            .session
            .as_ref()
            .expect("checked above")
            .create_frame(qh, i);
        frame.attach_buffer(&t.slots[slot].buffer);
        frame.damage_buffer(0, 0, w, h);
        frame.capture();
        t.frame = Some(frame);
        t.filling = Some(slot);
        t.asked = Some(Instant::now());
    }

    /// A capture landed: show it, and let go of the slot it replaced. Says
    /// whether the tile is still waiting for a subsurface, which only the
    /// overlay can give it.
    fn frame_ready(&mut self, i: usize) -> bool {
        // A tile scrolled out of sight was unmapped with a null buffer and
        // still carries the position it had when it was last visible, so
        // attaching here would put a stale thumbnail over whatever occupies
        // that cell now. sync_tiles hands it back when it scrolls into view.
        let visible = self.layout.tile(i as i32, self.scroll).is_some();
        let t = &mut self.tiles[i];
        let Some(slot) = t.filling.take() else {
            return false;
        };
        t.frames += 1;
        t.ready = true;
        t.settled = true;
        t.slots[slot].busy = true; // the compositor reads it until it releases it
        let previous = t.showing.replace(slot);
        match t.surface.clone() {
            Some(surface) if visible => {
                let (w, h) = (t.size.0 as i32, t.size.1 as i32);
                surface.attach(Some(&t.slots[slot].buffer), 0, 0);
                surface.damage_buffer(0, 0, w, h);
                surface.commit();
                t.attached = Some(slot);
            }
            // Nothing was attached, so the old slot was never actually read.
            _ => {
                if let Some(prev) = previous {
                    t.slots[prev].busy = false;
                }
            }
        }
        // Before the overlay is mapped there is nothing to attach to yet, and
        // sync_tiles picks up `showing` instead. A first frame landing after
        // that has to ask for a subsurface, or it is captured and never seen.
        t.surface.is_none()
    }

    /// Ask for the next frame callback. A commit is needed for the compositor to
    /// schedule one, and an empty commit is enough.
    pub fn arm_frame_callback(&mut self, qh: &QueueHandle<Self>) {
        if self.live == Live::None {
            return;
        }
        if let Some(surface) = self.surface.clone() {
            surface.frame(qh, ());
            surface.commit();
        }
    }

    /// Re-capture whatever is due. Driven by frame callbacks, so it stops when
    /// the overlay is not being presented.
    pub fn tick(&mut self, qh: &QueueHandle<Self>) {
        self.stats.ticks += 1;
        if self.live == Live::None {
            return;
        }
        let interval = Duration::from_secs_f64(1.0 / self.fps.max(1) as f64);
        let now = Instant::now();
        for i in 0..self.tiles.len() {
            if self.live == Live::Current && i != self.sel {
                continue;
            }
            // A display tile shows this overlay, which shows the display tile:
            // refreshing it never settles and costs a whole screen per frame.
            if self.tiles[i].target.kind == Kind::Output {
                continue;
            }
            // Nor is there any point refreshing a tile that is scrolled out of
            // sight — that is a readback for pixels nobody sees.
            if self.layout.tile(i as i32, self.scroll).is_none() {
                continue;
            }
            let t = &self.tiles[i];
            if t.session.is_none() || t.stale || t.slots.is_empty() || t.frame.is_some() {
                continue;
            }
            if t.asked.is_some_and(|a| now.duration_since(a) < interval) {
                continue;
            }
            self.request_capture(i, qh);
        }
    }
}

// --- event plumbing -------------------------------------------------------

impl Dispatch<ExtImageCopyCaptureSessionV1, usize> for App {
    fn event(
        app: &mut Self,
        _: &ExtImageCopyCaptureSessionV1,
        event: ext_image_copy_capture_session_v1::Event,
        &i: &usize,
        _: &Connection,
        _: &QueueHandle<Self>,
    ) {
        let Some(tile) = app.tiles.get_mut(i) else {
            return;
        };
        match event {
            // Constraints arrive once before the buffers are allocated, and
            // again whenever the source changes size. The buffers cannot
            // follow it, so after allocation a new size only marks the tile.
            ext_image_copy_capture_session_v1::Event::BufferSize { width, height } => {
                if tile.slots.is_empty() {
                    tile.size = (width, height);
                } else if tile.size != (width, height) {
                    tile.stale = true;
                }
            }
            ext_image_copy_capture_session_v1::Event::ShmFormat {
                format: WEnum::Value(f),
            } => {
                if !tile.formats.contains(&f) {
                    tile.formats.push(f);
                }
            }
            ext_image_copy_capture_session_v1::Event::Done => tile.session_done = true,
            // The source is gone. The protocol wants the session destroyed, and
            // a frame can no longer be asked of it; the last one stays on show.
            ext_image_copy_capture_session_v1::Event::Stopped => {
                if let Some(session) = tile.session.take() {
                    session.destroy();
                }
                tile.settled = true;
            }
            _ => {}
        }
    }
}

impl Dispatch<ExtImageCopyCaptureFrameV1, usize> for App {
    fn event(
        app: &mut Self,
        _: &ExtImageCopyCaptureFrameV1,
        event: ext_image_copy_capture_frame_v1::Event,
        &i: &usize,
        _: &Connection,
        qh: &QueueHandle<Self>,
    ) {
        let Some(tile) = app.tiles.get_mut(i) else {
            return;
        };
        match event {
            ext_image_copy_capture_frame_v1::Event::Transform {
                transform: WEnum::Value(t),
            } => tile.transform = t,
            ext_image_copy_capture_frame_v1::Event::Ready => {
                // The protocol wants the frame destroyed once ready; the buffer
                // stays ours to display.
                if let Some(frame) = tile.frame.take() {
                    frame.destroy();
                }
                // A tile whose first frame arrives after the overlay mapped has
                // no subsurface yet, and nothing else would ever give it one.
                if app.frame_ready(i) {
                    app.sync_tiles(qh);
                }
            }
            ext_image_copy_capture_frame_v1::Event::Failed { reason } => {
                // Live mode retries on the next tick, except that a buffer the
                // compositor has rejected for its size will be rejected again.
                // Only a failure with no frame yet leaves the tile without a
                // thumbnail.
                if matches!(reason, WEnum::Value(FailureReason::BufferConstraints)) {
                    tile.stale = true;
                }
                if tile.frames == 0 {
                    eprintln!(
                        "wl-pick: capture failed for {:?} ({reason:?})",
                        tile.target.title
                    );
                }
                tile.settled = true;
                if let Some(slot) = tile.filling.take() {
                    tile.slots[slot].busy = false;
                }
                if let Some(frame) = tile.frame.take() {
                    frame.destroy();
                }
            }
            _ => {}
        }
    }
}

/// A released capture buffer is a slot we may capture into again.
///
/// Release is the whole contract: with wl_shm the compositor copies the pixels
/// out at commit and hands the buffer straight back, so the slot currently on
/// screen is usually free too. (Waiting for it to stop being the displayed slot
/// instead would deadlock — that release never comes twice.)
impl Dispatch<WlBuffer, (usize, usize)> for App {
    fn event(
        app: &mut Self,
        _: &WlBuffer,
        event: wl_buffer::Event,
        &(tile, slot): &(usize, usize),
        _: &Connection,
        _: &QueueHandle<Self>,
    ) {
        if let wl_buffer::Event::Release = event
            && let Some(t) = app.tiles.get_mut(tile)
        {
            t.slots[slot].busy = false;
        }
    }
}

/// Frame callbacks are the clock for live updates: they arrive as the compositor
/// presents the overlay, so re-captures stop when it is not being shown.
impl Dispatch<wl_callback::WlCallback, ()> for App {
    fn event(
        app: &mut Self,
        _: &wl_callback::WlCallback,
        event: wl_callback::Event,
        _: &(),
        _: &Connection,
        qh: &QueueHandle<Self>,
    ) {
        if let wl_callback::Event::Done { .. } = event {
            app.tick(qh);
            app.arm_frame_callback(qh);
        }
    }
}

#[cfg(test)]
mod tests {
    use super::*;
    use wl_shm::Format;

    /// Everything wl_shm here advertises, plus the two it must.
    fn supported() -> Vec<Format> {
        vec![
            Format::Argb8888,
            Format::Xrgb8888,
            Format::Xbgr8888,
            Format::Bgr888,
            Format::Xrgb2101010,
            Format::Abgr16161616f,
            Format::Xbgr16161616f,
        ]
    }

    #[test]
    fn the_guaranteed_formats_win() {
        // Both are four bytes, and every wl_shm has them, so they are picked
        // over anything else on offer however the session orders them.
        let offered = [Format::Abgr16161616f, Format::Bgr888, Format::Xrgb8888];
        assert_eq!(
            choose_format(&offered, &supported()),
            Some((Format::Xrgb8888, 4))
        );
    }

    /// wlroots' own rule, from pixel_format_info_check_stride: a stride must
    /// be a whole number of pixels and cover the width.
    fn wlroots_accepts(stride: i32, width: i32, bytes: i32) -> bool {
        stride % bytes == 0 && stride >= width * bytes
    }

    #[test]
    fn the_declared_stride_matches_the_format() {
        // The reported bug: a session offering neither XRGB8888 nor ARGB8888
        // fell through to whatever came first, with a stride of four bytes a
        // pixel regardless. A 3830-wide window then declared 15320, which is
        // too small for an eight-byte format and not a whole number of
        // three-byte ones -- "Invalid stride (15320)", and the connection dies.
        let width = 3830;
        for (format, bytes) in [
            (Format::Bgr888, 3),
            (Format::Xbgr8888, 4),
            (Format::Abgr16161616f, 8),
        ] {
            let (chosen, chosen_bytes) =
                choose_format(&[format], &supported()).unwrap_or_else(|| panic!("{format:?}"));
            assert_eq!((chosen, chosen_bytes), (format, bytes));
            assert!(
                wlroots_accepts(width * chosen_bytes, width, bytes),
                "{format:?} stride {} rejected",
                width * chosen_bytes
            );
        }

        // And the old formula is what fails, for the formats that are not four
        // bytes wide.
        assert!(!wlroots_accepts(width * 4, width, 3), "15320 for BGR888");
        assert!(!wlroots_accepts(width * 4, width, 8), "15320 for ABGR16F");
        assert!(wlroots_accepts(width * 4, width, 4), "four bytes was fine");
    }

    #[test]
    fn formats_we_cannot_measure_are_declined() {
        // Multi-planar and subsampled rows are not width times a constant, and
        // a format wl_shm never advertised cannot be shown even if the session
        // can capture into it. Refusing costs one tile its thumbnail; guessing
        // costs the whole connection.
        assert_eq!(choose_format(&[Format::Nv12], &supported()), None);
        assert_eq!(choose_format(&[Format::Yuv420], &supported()), None);
        assert_eq!(choose_format(&[], &supported()), None);
        assert_eq!(
            choose_format(&[Format::Abgr16161616f], &[Format::Xrgb8888]),
            None,
            "offered but not displayable"
        );
    }

    #[test]
    fn pixel_sizes_match_the_names() {
        assert_eq!(bytes_per_pixel(Format::Rgb565), Some(2));
        assert_eq!(bytes_per_pixel(Format::Bgr888), Some(3));
        assert_eq!(bytes_per_pixel(Format::Xrgb2101010), Some(4));
        assert_eq!(bytes_per_pixel(Format::Xbgr16161616f), Some(8));
        // Subsampled: wlroots gives these a four-byte block too, but a block
        // is two pixels wide, so a row is not the width times it.
        assert_eq!(bytes_per_pixel(Format::Yuyv), None);
        // Not something a wlroots renderer offers, so not something to guess.
        assert_eq!(bytes_per_pixel(Format::Rgb332), None);
    }
}