1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
//! §11 rule 1b — **the control wins the row** (bl-bc06).
//!
//! Rule 1 (DESIGN §11) makes every label in a bounded panel truncate rather
//! than extend, so no row can ratchet its panel wider. Laid the obvious way —
//! text first, control after — that rule feeds the whole width to the greedy
//! text and hands the control whatever is left, which at the DEFAULT window
//! size is routinely one character: a button rendered as a bare `…` that says
//! neither what it is nor what it does. The Login pane's worst case was the
//! damaging one: `claude-session-direct` is the longest provider name in
//! brazen's table, so the one row where the operator actually needs the verb
//! was the one row whose verb vanished.
//!
//! The fix is an ordering, not a size. A row that pairs greedy text with a
//! trailing control lays the **control first**, at its own natural width, and
//! the text truncates into what is left. That is lawful in both directions:
//! a truncated *label* still names something (its head carries the verb glyph
//! and the id, and its hover carries the whole value — QUALITY G1), while a
//! truncated *control* is unusable at any length. Nothing extends past the
//! panel, so rule 1's own invariant is untouched.
/// §11 rule 1 — **a bounded panel truncates** — stated at the panel it is true
/// of (bl-5410).
///
/// It was written into the side panel's own body and read as if it were a
/// window rule; it is not, and egui's default everywhere else is `Extend`. So
/// the top bar, the centre and the activity accessory laid every horizontal
/// label at its natural width and the panel's clip rect sliced it mid-glyph —
/// with **no ellipsis**, because a galley that was never asked to truncate has
/// nothing to mark. That is QUALITY G1's defect in its silent form: the audit
/// measured `auth none…` laid 68 pt and shown 36, the `…` egui *had* added to
/// say the row was cut clipped off along with the rest.
///
/// One call per panel root rather than one ambient default: a `Ui` inherits its
/// parent's style, so the rule reaches every row inside without any of them
/// restating it, and a seat that must not truncate (a wrapped prose block) can
/// still say so locally. What it deliberately does **not** do is make a strip of
/// controls fit — a truncated control is unusable at any length ([`peers`] and
/// [`control_last`] are that half of the answer, rules 8 and 1b).
pub
/// §11 rule 1, the half a scroll area takes back (bl-7414): **a seat lays no
/// wider than it shows.**
///
/// [`bounded`] makes a row truncate, but truncate *to what*? To `max_rect`, and
/// a vertical `ScrollArea` whose content is wider than its viewport hands its
/// inner `Ui` a `max_rect` wider than its `clip_rect` — it must, to measure the
/// content it might have to scroll. With horizontal scrolling off there is
/// nothing to scroll to, so the surplus is pure fiction: every row truncates to
/// the fiction and the clip then cuts the result, **taking the ellipsis with
/// it**. Measured on the Config surface at 480x1400, a narrow-tall window: the
/// pane showed 224 pt and laid 388, so `the watcher-cycle cadence — worker
/// sweeps, debounce, and every …` was elided at 387 pt and hard-cut at 224 with
/// no mark on it at all. That is rule 1c's silent form, and it is the same
/// defect [`bounded`] was written for, one container further in.
///
/// So the rule is restated where it stopped being true. Clamping is one-way —
/// a seat whose clip is *wider* than its max rect (any ordinary row, whose
/// parent clips generously) keeps the narrower bound it already had, because
/// the fiction is only ever the surplus.
pub
/// §11 rule 1d at the moment an **optional trailing run** is about to be laid:
/// *an accessory the seat cannot pay does not paint* (bl-0424).
///
/// Rule 1 makes a run truncate; under a floor the truncation eats the run and
/// what lands is a bare `…`, which says strictly less than nothing and is
/// exactly what `legible/floor.rs` forbids. Worse on the width axis than on the
/// height one: a run laid at zero available width still allocates its ellipsis,
/// so three such runs after a greedy one push the seat's `min_rect` ~60 pt past
/// its `max_rect` — and in a side panel that rect **is** next frame's panel
/// width (rule 2's ratchet, measured again in bl-0424 at 319 pt of a 260 pt
/// column). So the answer is the same one `layout::share` gives on the other
/// axis: either the seat can pay a run or the run is not painted this frame.
///
/// The floor is [`crate::layout::ROW`] — *"the least an accessory can be and
/// still say anything"* — read on the width axis, which it generalizes to
/// without a second number: a run narrower than one line of text is one glyph
/// and an ellipsis.
pub
/// Lay `text` and a trailing `control` on one line, control first.
///
/// The control is allocated at its natural width against the row's full
/// extent, then `text` is laid left-to-right into the remainder and truncates
/// there. Both closures hand their value back, in painted order — the text's
/// (a widget response the caller seats a menu on) and the control's (typically
/// the button's `clicked()`).
///
/// **The truncation is set here, not inherited.** Rule 1 puts
/// `TextWrapMode::Truncate` at the *side panel's* root, so a row laid in that
/// panel elides for free — but the same rows paint in seats that set no such
/// mode (the Login rows render inline in the conversation's auth-failed banner,
/// in the centre, where the default is `Extend`). Pinning the control right
/// while the text beside it is free to extend does not make the text run off
/// the edge as it did before; it makes it run **through the control**, which is
/// worse than the defect being fixed — a real overlap, caught at 800×500 by
/// bl-9551's `acceptance::overlap` walk. So the helper states the whole rule
/// itself and depends on no ambient state: the control is pinned, and the text
/// beside it truncates wherever the row is seated.
pub
/// Lay a strip of **peer controls** — a tab bar, a verb row — so that every
/// one of them is laid out, wrapping to a second line rather than running off
/// the pane (§11 rule 8, bl-b531).
///
/// The failure a plain `ui.horizontal` has here is not elision, it is
/// **omission**: egui does not truncate a control that does not fit, it simply
/// never lays it out. Measured on the altitude-2 inspector strip in the 202 pt
/// centre a 420x320 window leaves — the documented `min_inner_size` — the row
/// painted `Transcript Steps Inbox Files` and `Config` and `Work` did not
/// exist. A label can lose its tail and still name itself; a control that was
/// never laid out has no seat to hover, no rect to click and no ellipsis to
/// warn you it is gone, which is the QUALITY G1 violation *"rendered
/// off-screen … the full value is reachable"* in its least recoverable form.
///
/// Rule 1b is the same question with a different answer, and the two are not
/// in tension: there the row pairs *greedy text* with a control, so the control
/// is pinned and the text truncates into the remainder; here every member is a
/// control of its own natural width and none may be dropped, so the row grows
/// a line instead. Wrapping costs a second row at the minimum size and nothing
/// at any other.
///
/// The centre's own tab strip (`shell::center::strip`) reached this answer
/// first, for exactly this reason, and stated it inline; this is that rule with
/// one home, so the next strip does not have to rediscover it.
pub