Skip to main content

teksilo_core/
build_context.rs

1// SPDX-License-Identifier: MPL-2.0
2// SPDX-FileCopyrightText: 2026 FernTech
3
4//! BuildContext — context available during Widget::build().
5//!
6//! Provides Signal-based APIs for creating reactive state, registering
7//! effects, and adding child widgets during the build lifecycle.
8
9use crate::binding::BindingRegistry;
10use crate::event_source::{SubscriptionHandle, SubscriptionId};
11use crate::signal::{ObserverHandle, Signal};
12use crate::widget_id::WidgetId;
13
14/// Context available during Widget::build().
15pub struct BuildContext<'a> {
16    pub(crate) tree: &'a mut crate::widget_tree::WidgetTree,
17    pub(crate) composite_id: Option<WidgetId>,
18    /// RAII handles for effects registered during this build cycle.
19    /// Transferred to the arena node's `effect_handles` after build returns.
20    pub(crate) effect_handles: Vec<ObserverHandle>,
21    /// Backend-event subscription handles registered during this build
22    /// cycle via `subscribe_event`. Transferred to the arena node's
23    /// `subscription_handles` after build returns.
24    pub(crate) subscription_handles: Vec<(SubscriptionId, SubscriptionHandle)>,
25    /// The `SubscriptionId`s the **previous** build of this same widget used, in the
26    /// order it created them. Empty on a first mount.
27    ///
28    /// A subscription's id is what crosses the thread boundary: the publisher-side
29    /// wrapper captures it by value and posts it, and the UI thread looks it up some
30    /// frames later. Minting a fresh id on every rebuild therefore silently destroys
31    /// every event already in flight, because `rebuild_single_widget` removes the
32    /// previous build's callbacks before `build()` runs and the queued event then names
33    /// an id nothing answers to. Re-using the ids here makes a subscription's identity
34    /// span the rebuilds of one widget, so an event posted before a rebuild is delivered
35    /// to the closure the *new* build installed.
36    ///
37    /// Matched **by position**, which is what makes it cheap and predictable: the Nth
38    /// `subscribe_event`/`subscribe_event_with_ctx` call of this build re-uses the id of
39    /// the Nth call of the last one. A build that subscribes fewer times simply leaves
40    /// the surplus ids unclaimed and they stay torn down; one that subscribes more
41    /// allocates fresh ids for the extras.
42    pub(crate) reusable_sub_ids: Vec<SubscriptionId>,
43}
44
45impl<'a> BuildContext<'a> {
46    /// The WidgetId of the widget being built.
47    pub fn self_id(&self) -> WidgetId {
48        self.composite_id
49            .expect("self_id() called outside of build()")
50    }
51
52    /// Add a widget to the tree.
53    pub fn add(&mut self, widget: impl crate::widget::Widget + 'static) -> WidgetId {
54        self.tree.add(widget)
55    }
56
57    /// Add a pre-boxed widget to the tree.
58    pub fn add_boxed(&mut self, widget: Box<dyn crate::widget::Widget>) -> WidgetId {
59        self.tree.add_boxed(widget)
60    }
61
62    /// Add a **parentless** widget this one owns: pre-built overlay content
63    /// (a dropdown menu, a date picker's calendar, a tooltip's nested cascade
64    /// children) that must not be reached by the child walk.
65    ///
66    /// Use this — never a bare [`add`](Self::add) — for anything built ahead of
67    /// time and parked with [`set_dormant`](Self::set_dormant) to be shown later
68    /// through an overlay. The two differ only in bookkeeping: `add` hands back
69    /// a node nothing owns, so the builder's own teardown cannot reach it and
70    /// every rebuild strands another copy in the arena; this records the
71    /// ownership edge, so the node dies with its owner and the previous
72    /// generation dies with each rebuild.
73    ///
74    /// Content that *can* be a child should be returned from `build()` as one
75    /// instead. This exists for content that cannot: activation and the paint
76    /// walk both descend through `children`, so a dormant popup parked there
77    /// wakes with its host and paints inline at zero size.
78    pub fn add_detached(&mut self, widget: impl crate::widget::Widget + 'static) -> WidgetId {
79        self.add_detached_boxed(Box::new(widget))
80    }
81
82    /// Insert a child whose subtree is **not built until `reveal` first turns
83    /// true**, and is retained from then on. Returns the host's id immediately.
84    ///
85    /// The shape this replaces is `ctx.add(panel)` followed by
86    /// `ctx.set_dormant(id)` — correct, but it builds content the user may never
87    /// open, on every rebuild of the owner. In a virtualized collection the
88    /// owner is a per-row delegate, so that cost is multiplied by the row count:
89    /// on a 40-row table whose cells each carried a four-item menu, the eager
90    /// form cost 325–552 ms per rebuild against 42–46 ms without the column at
91    /// all, and ~85% of it was the `add` rather than constructing the widget
92    /// value. See [`DeferredSubtree`](crate::deferred_subtree::DeferredSubtree)
93    /// for the full contract.
94    ///
95    /// Pass the same signal the content's `visible_when` gate uses. Everything
96    /// downstream of the returned id — `set_dormant` / `activate`,
97    /// `visible_when`, `OverlayRequest::content_id`, descendant checks,
98    /// dismissal — is unchanged; only when the subtree below it exists moves.
99    pub fn add_deferred(
100        &mut self,
101        reveal: crate::signal::Signal<bool>,
102        widget: impl crate::widget::Widget + 'static,
103    ) -> WidgetId {
104        self.add_deferred_boxed(reveal, Box::new(widget))
105    }
106
107    /// [`add_deferred`](Self::add_deferred) for an already-boxed widget.
108    pub fn add_deferred_boxed(
109        &mut self,
110        reveal: crate::signal::Signal<bool>,
111        widget: Box<dyn crate::widget::Widget>,
112    ) -> WidgetId {
113        self.add(crate::deferred_subtree::DeferredSubtree::new(
114            Some(reveal),
115            widget,
116        ))
117    }
118
119    /// [`add_deferred`](Self::add_deferred) for content the **framework**
120    /// materializes, kept as a child of the builder.
121    ///
122    /// The parented twin of
123    /// [`add_detached_deferred_on_demand`](Self::add_detached_deferred_on_demand),
124    /// for the two rich-tooltip attach paths: they have always parented their
125    /// body on the anchor's owner, and reparenting them to `detached` would move
126    /// which teardown reaps them. Only *when* the body is built changes.
127    ///
128    /// Worth the separate entry point because a rich tooltip is not one widget:
129    /// `RichTooltipWidget::build` eagerly pre-creates a nested tooltip for every
130    /// `:key` link in its body, recursively, so one attached tip expands into a
131    /// cascade. Built eagerly on a data view's row delegate, 29 rows of
132    /// Skribisto's Overview carried 1,305 tooltip widgets inside a 22,737-node
133    /// subtree, and tearing that down cost 5.3 s per arrow-key press — the
134    /// destroy, not the build.
135    pub fn add_deferred_on_demand(
136        &mut self,
137        widget: impl crate::widget::Widget + 'static,
138    ) -> WidgetId {
139        self.add(crate::deferred_subtree::DeferredSubtree::new(
140            None,
141            Box::new(widget),
142        ))
143    }
144
145    /// [`add_deferred`](Self::add_deferred) for content the **framework**
146    /// materializes rather than a widget's own open signal.
147    ///
148    /// The tooltip case: a tooltip body has no open signal a widget could hand
149    /// over — the tree decides, when a dwell matures. `WidgetTree` forces such
150    /// a host just before it consults `Widget::tooltip_has_content`, so the
151    /// body exists by the time anything asks it a question.
152    pub fn add_detached_deferred_on_demand(
153        &mut self,
154        widget: impl crate::widget::Widget + 'static,
155    ) -> WidgetId {
156        self.add_detached(crate::deferred_subtree::DeferredSubtree::new(
157            None,
158            Box::new(widget),
159        ))
160    }
161
162    /// [`add_deferred`](Self::add_deferred), inserted detached — the shape
163    /// overlay content wants, so it is owned by the builder and dies with it
164    /// rather than outliving every menu the user ever opened.
165    pub fn add_detached_deferred_boxed(
166        &mut self,
167        reveal: crate::signal::Signal<bool>,
168        widget: Box<dyn crate::widget::Widget>,
169    ) -> WidgetId {
170        self.add_detached(crate::deferred_subtree::DeferredSubtree::new(
171            Some(reveal),
172            widget,
173        ))
174    }
175
176    /// [`add_detached_deferred_boxed`](Self::add_detached_deferred_boxed) for an
177    /// unboxed widget.
178    pub fn add_detached_deferred(
179        &mut self,
180        reveal: crate::signal::Signal<bool>,
181        widget: impl crate::widget::Widget + 'static,
182    ) -> WidgetId {
183        self.add_detached_deferred_boxed(reveal, Box::new(widget))
184    }
185
186    /// [`add_detached`](Self::add_detached) for an already-boxed widget.
187    pub fn add_detached_boxed(&mut self, widget: Box<dyn crate::widget::Widget>) -> WidgetId {
188        let id = self.tree.add_boxed(widget);
189        let owner = self.self_id();
190        self.tree.record_detached(owner, id);
191        id
192    }
193
194    /// Add a Level 2 widget as a child of another widget.
195    pub fn add_child(
196        &mut self,
197        parent: WidgetId,
198        widget: impl crate::widget::Widget + 'static,
199    ) -> WidgetId {
200        self.tree.add_child(parent, widget)
201    }
202
203    // --- Signal APIs ---
204
205    /// Create a new mutable signal.
206    pub fn signal<T: 'static>(&mut self, value: T) -> Signal<T> {
207        Signal::new(value)
208    }
209
210    /// Create a new `Signal<f32>` that supports `animate_to()`.
211    /// Registered with the animation scheduler automatically. The owning
212    /// widget (`self_id()`) is recorded so that the scheduler can pause
213    /// the animation when the widget is offscreen, dormant, or rebuilt.
214    pub fn animated_signal(&mut self, value: f32) -> Signal<f32> {
215        let signal = Signal::new_animated(value);
216        let owner = self.self_id();
217        self.tree.register_animated_signal(&signal, owner);
218        signal
219    }
220
221    /// Register a pre-existing `Signal<f32>` for animation support.
222    /// Use this when the signal was created outside of `build()` (e.g. in the
223    /// widget constructor) and needs to be registered with the animation scheduler.
224    pub fn register_animated_signal(&mut self, signal: &Signal<f32>) {
225        let owner = self.self_id();
226        self.tree.register_animated_signal(signal, owner);
227    }
228
229    /// Read the OS-level `prefers-reduced-motion` preference. Widgets
230    /// that use looping or decorative animations (spinners, sprite
231    /// icons, marquee text, etc.) should skip starting them when this
232    /// returns `true` so the UI respects accessibility settings and —
233    /// as a bonus — draws no CPU/GPU.
234    pub fn prefers_reduced_motion(&self) -> bool {
235        self.tree.prefers_reduced_motion()
236    }
237
238    /// Build an [`AnimationSpec`](crate::animation_builder::AnimationSpec)
239    /// — the fluent ergonomic façade over `Signal<f32>::animate_to`.
240    /// Captures the theme's `MotionTokens` and the platform
241    /// reduced-motion preference at build time, returns a clonable
242    /// spec that event-handler closures can drive without
243    /// re-threading durations and easing.
244    ///
245    /// ```ignore
246    /// let knob_anim = ctx.animate().fast().standard();
247    /// handlers = handlers.on_tap(move |_, _| {
248    ///     knob_anim.to_or_snap(&knob_position, target);
249    /// });
250    /// ```
251    pub fn animate(&self) -> crate::animation_builder::AnimationSpec {
252        crate::animation_builder::AnimationSpec::from_motion(
253            self.theme().motion.clone(),
254            self.prefers_reduced_motion(),
255        )
256    }
257
258    /// Opt into the shader-driven animated-quad pipeline. The widget
259    /// paint() emits ONE `canvas.draw_animated_quad(bounds, handle.slot(),
260    /// class)` call; the renderer samples per-slot state from its
261    /// uniform buffer each frame and the widget's paint() does not
262    /// re-run for animation ticks — only on layout changes. The
263    /// returned handle is stable for the widget-mount lifetime and
264    /// should be stashed on `self` to thread to `paint()`.
265    ///
266    /// For decorative motion that isn't a quad (scroll-offset tweens,
267    /// sidebar slide, toggle knob), keep using `ctx.animated_signal` +
268    /// `signal.animate_looping` — both paths coexist.
269    pub fn animated_quad(
270        &mut self,
271        kind: crate::animated_quad::AnimatedQuadKind,
272    ) -> crate::animated_quad::AnimatedQuadHandle {
273        let owner = self.self_id();
274        self.tree.register_animated_quad(owner, kind)
275    }
276
277    /// The per-frame delta-seconds signal. Observe it via
278    /// `ctx.effect(&ctx.frame_tick(), |delta| ...)` to run code once per
279    /// frame **the tree was explicitly asked to pump**. Merely observing
280    /// this signal does not keep the event loop awake — widgets must
281    /// call [`request_frame`](Self::request_frame) (typically from an
282    /// event handler or from inside the tick closure itself) to schedule
283    /// the next wake-up. This preserves Teksilo's draw-when-needed model.
284    pub fn frame_tick(&self) -> Signal<f32> {
285        self.tree.frame_tick()
286    }
287
288    /// Ask the tree to pump exactly one more frame. See
289    /// [`frame_tick`](Self::frame_tick) for the observer side.
290    pub fn request_frame(&self) {
291        self.tree.request_frame();
292    }
293
294    /// Request that the AccessKit tree be re-walked after this build pass.
295    /// Use when `build()` restructured its subtree in a way that changes the
296    /// accessibility tree (relayout alone no longer re-walks AT). `SceneView`
297    /// calls this each build, since it may have materialised or destroyed
298    /// scene widgets or applied a11y-only scene mutations.
299    pub fn request_accessibility_update(&self) {
300        self.tree.request_accessibility_update();
301    }
302
303    /// Speak `message` to the screen reader, politely.
304    ///
305    /// The build-time companion to
306    /// [`EventContext::announce`](crate::widget::EventContext::announce), for a
307    /// widget that discovers during `build()` that something needs saying — an
308    /// error surface appearing, a result count changing. Announcing from
309    /// `build()` announces once per *rebuild*, so guard it on a real change
310    /// rather than on the build itself.
311    pub fn announce(&mut self, message: impl Into<String>) {
312        self.tree.announce(message);
313    }
314
315    /// Speak `message` to the screen reader at the given urgency. See
316    /// [`EventContext::announce_with`](crate::widget::EventContext::announce_with).
317    pub fn announce_with(
318        &mut self,
319        message: impl Into<String>,
320        politeness: crate::announcer::Politeness,
321    ) {
322        self.tree.announce_with(message, politeness);
323    }
324
325    /// Clone the shared "frame requested" flag. Stash it on widget
326    /// state and call `.set(true)` from inside a frame-tick effect
327    /// closure to chain-request another frame without needing
328    /// mutable access to the tree. Used by widgets with continuous
329    /// frame needs (caret blink, drag auto-scroll, smooth
330    /// animations driven from a tick closure).
331    ///
332    /// **Prefer [`subscribe_frame_tick`](Self::subscribe_frame_tick)**
333    /// for visual-only continuous animations (Pulse, Cycle, …): the
334    /// scheduler-backed path automatically pauses the chain when the
335    /// owner widget is hidden, while this raw handle keeps the event
336    /// loop pumping at full frame rate regardless of visibility.
337    pub fn frame_request_handle(&self) -> std::rc::Rc<std::cell::Cell<bool>> {
338        self.tree.frame_request_handle()
339    }
340
341    /// Subscribe the widget being built to the per-frame-effect
342    /// scheduler. The returned RAII guard removes the subscription on
343    /// drop — store it on `self` so its lifetime tracks the widget's.
344    ///
345    /// While at least one subscriber's owner is visible, the framework
346    /// auto-arms `frame_tick_requested` after every render. When all
347    /// subscribers are hidden (e.g. parked inside a non-selected
348    /// `Switcher` branch), no re-arm happens and the chain dies, so
349    /// the event loop sleeps. On a hidden→visible transition the
350    /// `visible_when` binding's relayout dirty triggers a repaint that
351    /// paints the subscriber, which the post-render arm then detects
352    /// and resumes the chain.
353    ///
354    /// Replaces the widget-managed `frame_request.set(true)` re-arm
355    /// pattern for visual-only continuous animations. The widget's
356    /// `frame_tick` effect closure no longer needs to call
357    /// `frame_request.set(true)` itself — the scheduler handles it.
358    pub fn subscribe_frame_tick(&self) -> crate::frame_tick_scheduler::FrameTickSubscription {
359        let sub = self.tree.subscribe_frame_tick(self.self_id());
360        // Bootstrap: ensure at least one frame runs after registration
361        // so the first paint happens. The post-render re-arm takes over
362        // from there. This is also the resume nudge for the case where
363        // a widget rebuilds (e.g. due to a state change) while still
364        // hidden — the parent's relayout dirty will trigger paint, and
365        // post-render arm will pick up the chain.
366        self.tree.request_frame();
367        sub
368    }
369
370    /// Like [`subscribe_frame_tick`](Self::subscribe_frame_tick), but the
371    /// widget only needs to wake **at most once per `interval`** while
372    /// visible. Same visibility gate and RAII guard; between wakes the
373    /// event loop sleeps to the interval deadline rather than rendering
374    /// identical 60 fps frames. Use when the widget's visible output
375    /// changes far less often than 60 Hz — e.g. `Cycle`'s once-per-period
376    /// index advance, or a seconds-granular clock.
377    pub fn subscribe_frame_tick_throttled(
378        &self,
379        interval: std::time::Duration,
380    ) -> crate::frame_tick_scheduler::FrameTickSubscription {
381        let sub = self
382            .tree
383            .subscribe_frame_tick_throttled(self.self_id(), interval);
384        // Bootstrap the first frame after registration (see
385        // `subscribe_frame_tick`).
386        self.tree.request_frame();
387        sub
388    }
389
390    /// Clone the shared wake-at deadline cell. Stash it on widget
391    /// state and set `Some(instant)` from a frame-tick effect to
392    /// schedule a one-shot deadline wake-up without keeping the event
393    /// loop in `Poll` mode. See `WidgetTree::wake_at_handle` for
394    /// the underlying mechanism.
395    pub fn wake_at_handle(&self) -> std::rc::Rc<std::cell::Cell<Option<std::time::Instant>>> {
396        self.tree.wake_at_handle()
397    }
398
399    /// Register a scoped effect tied to this build cycle.
400    /// The effect fires whenever the signal changes. It is automatically
401    /// cleaned up on rebuild or widget destruction.
402    pub fn effect<T: Clone + 'static>(&mut self, signal: &Signal<T>, f: impl Fn(&T) + 'static) {
403        let handle = signal.observe(f);
404        self.effect_handles.push(handle);
405    }
406
407    /// Register a pre-existing observer handle for lifecycle management.
408    /// The handle will be dropped (and the observer removed) on rebuild
409    /// or widget destruction.
410    pub fn own_handle(&mut self, handle: ObserverHandle) {
411        self.effect_handles.push(handle);
412    }
413
414    /// Get the binding registry.
415    pub fn binding_registry(&self) -> &BindingRegistry {
416        self.tree.binding_registry()
417    }
418
419    /// Get the current theme.
420    pub fn theme(&self) -> &crate::styles::Theme {
421        self.tree.theme()
422    }
423
424    /// Reactive handle on the current theme. Fires observers when
425    /// `tree.set_theme(...)` is called. Build implementations that want
426    /// theme-driven values to update without a rebuild should use this
427    /// instead of cloning tokens from `self.theme()` — for example,
428    /// `ctx.theme_signal().map(|t| t.colors.primary)` or combining with
429    /// interaction state via `zip(...)`.
430    pub fn theme_signal(&self) -> crate::signal::Signal<crate::styles::Theme> {
431        self.tree.theme_signal().clone()
432    }
433
434    /// Current combined text-scale factor (`user × OS`, `1.0` = 100 %). One-shot
435    /// read for build-time sizing; for a value that updates without a rebuild,
436    /// bind [`text_scale_signal`](Self::text_scale_signal) instead.
437    pub fn text_scale(&self) -> f32 {
438        self.tree.effective_text_scale()
439    }
440
441    /// Reactive handle on the combined text-scale factor. Fires when the user
442    /// scale, theme, or OS text-scale preference changes. Build implementations
443    /// that derive a build-time dimension from the scale (e.g. `Calendar`'s
444    /// fixed cell sizes) bind this — typically at `Rebuild` level so the change
445    /// recomputes the constants — since a scale change relayouts but does not
446    /// rebuild on its own.
447    pub fn text_scale_signal(&self) -> crate::signal::Signal<f32> {
448        self.tree.text_scale_signal()
449    }
450
451    /// Whether the host window is currently active (`focused AND not
452    /// occluded`). One-shot read for build-time use; for a value that reacts
453    /// to focus changes, bind [`window_active_signal`](Self::window_active_signal).
454    pub fn window_active(&self) -> bool {
455        self.tree.is_window_active()
456    }
457
458    /// Reactive handle on window-active state. Fires when the host window gains
459    /// or loses active status (`focused AND not occluded`). Build
460    /// implementations that show/hide appearance with window focus — caret
461    /// effects, the selection-colour swap in text fields, `DimWhenInactive` —
462    /// bind this, typically at `RepaintOnly` level (an active-state flip never
463    /// affects geometry). Starts `true`.
464    pub fn window_active_signal(&self) -> crate::signal::Signal<bool> {
465        self.tree.window_active_signal()
466    }
467
468    /// Reactive handle on the current locale. Fires observers when
469    /// `tree.set_locale(...)` is called.
470    pub fn locale_signal(&self) -> crate::signal::Signal<Option<String>> {
471        self.tree.locale_signal().clone()
472    }
473
474    /// The [`WindowState`](crate::window::WindowState) for the window
475    /// hosting this tree. `None` only for trees built outside of an
476    /// app (tests, headless scenarios). Use this to bind widgets to
477    /// window-level signals like `placement`, `size`, `focused`.
478    pub fn window(&self) -> Option<&crate::window::WindowState> {
479        self.tree.window_state()
480    }
481
482    /// Retrieve an application-scoped value of type `T` registered via
483    /// `TeksiloAppBuilder::app_state`. Returns `None` if no value of
484    /// that type was registered. The returned reference borrows from
485    /// the framework for the duration of the build pass.
486    pub fn app_state<T: 'static>(&self) -> Option<&T> {
487        self.tree.app_context().app_state::<T>()
488    }
489
490    /// Borrow the [`AppEventPoster`](crate::AppEventPoster) installed by the
491    /// framework, if any. Mirrors [`EventContext::poster`](crate::widget::EventContext::poster).
492    /// Used by integrations that wire a platform callback (e.g. a native menu
493    /// item) to post a typed payload back to the UI loop. Returns `None` for
494    /// trees built outside an app (tests / headless).
495    pub fn poster(&self) -> Option<&std::sync::Arc<dyn crate::AppEventPoster>> {
496        self.tree.app_context().poster()
497    }
498
499    /// Bind a widget's visibility to a boolean prop or compatibility state binding.
500    pub fn visible_when(&mut self, id: WidgetId, state: impl Into<crate::signal::Prop<bool>>) {
501        self.tree.visible_when(id, state);
502    }
503
504    /// Enqueue a one-shot action to run shortly after this build, with a real
505    /// [`EventContext`](crate::widget::EventContext) — the only place a widget
506    /// can read the OS parent window handle (`ctx.parent_window_handle()`),
507    /// `app_state`, and `poster` *together*, after it is mounted under its
508    /// window. The action runs at most once per enqueue (the app loop drains
509    /// the queue each iteration); a widget that rebuilds must guard against
510    /// enqueuing twice. Built for widgets owning a native OS resource that
511    /// needs a window handle to initialise (a `WebView`'s engine subview);
512    /// ordinary widgets never need it.
513    pub fn run_after_mount(&mut self, f: impl FnOnce(&mut crate::widget::EventContext) + 'static) {
514        self.tree.queue_mount_action(Box::new(f));
515    }
516
517    /// Observe a node's framework activation as a `Signal<bool>` — `true`
518    /// while active, `false` while parked dormant by a `Switcher` /
519    /// `visible_when` gate. Initialised to the node's current state and
520    /// updated only on an actual Active↔Dormant transition.
521    ///
522    /// Ordinary widgets never need this: dormant subtrees are simply not
523    /// painted, so they vanish for free. It exists for the one case where
524    /// "not painted" ≠ "hidden" — a widget owning a native OS resource
525    /// that renders *outside* the wgpu pass (a `WebView`'s engine subview).
526    /// Such a widget does `ctx.effect(&ctx.activation_signal(id), move |a|
527    /// handle.set_visible(*a))` to hide/show the native surface in lockstep.
528    pub fn activation_signal(&mut self, id: WidgetId) -> Signal<bool> {
529        self.tree.activation_signal(id)
530    }
531
532    /// Reactive `Signal<bool>` that is `true` while the *focus scope* containing
533    /// the widget being built — its nearest focusable ancestor, e.g. the
534    /// enclosing `ListView` / `TreeView` — holds keyboard focus. Items outside
535    /// any focusable scope read a constant `true`.
536    ///
537    /// Drives **focus-aware selection**: a selected row renders with the active
538    /// `Selected` chrome while its view has focus and the muted
539    /// `SelectedInactive` chrome when focus moves elsewhere — the standard
540    /// desktop affordance (Qt `SH_ItemView_...`, macOS inactive selection) that
541    /// shows where the keyboard is. The scope is resolved at build time but the
542    /// signal stays live across focus changes.
543    pub fn view_focus_active(&mut self) -> Signal<bool> {
544        // Prefer the scope a containing data view explicitly established for its
545        // rows (deterministic, parenting-independent); else resolve by walking
546        // to the nearest focusable ancestor.
547        if let Some(scope) = self.tree.current_view_focus() {
548            return scope;
549        }
550        let id = self.self_id();
551        self.tree.view_focus_active_for(id)
552    }
553
554    /// Mark the widget being built as a **focus scope** for the rows/items it
555    /// builds next: any descendant's [`view_focus_active`](Self::view_focus_active)
556    /// (and `StandardItem`'s focus-aware selection / focus ring) reads *this*
557    /// widget's keyboard focus. A data view calls this around its row loop, then
558    /// [`end_view_focus`](Self::end_view_focus). Deterministic — unaffected by
559    /// arena parenting, which may not be wired while docked/virtualized rows build.
560    pub fn begin_view_focus(&mut self) -> Signal<bool> {
561        let id = self.self_id();
562        self.tree.begin_view_focus(id)
563    }
564
565    /// Like [`begin_view_focus`](Self::begin_view_focus) but keys the scope on
566    /// an explicit `node_id` rather than the widget being built. A view whose
567    /// rows are built by a **separate body-pane widget** (TableView /
568    /// TreeTableView / GridView) passes its own focusable root id so descendant
569    /// items resolve the *root's* keyboard focus — not the pane's, which is a
570    /// child of the root and so never holds focus itself.
571    pub fn begin_view_focus_for(&mut self, node_id: WidgetId) -> Signal<bool> {
572        self.tree.begin_view_focus(node_id)
573    }
574
575    /// End the focus scope opened by [`begin_view_focus`](Self::begin_view_focus).
576    pub fn end_view_focus(&mut self) {
577        self.tree.end_view_focus();
578    }
579
580    /// Input-modality "focus-visible" signal — `true` after keyboard input,
581    /// `false` after pointer input (the standard `:focus-visible` rule). Pair
582    /// with [`view_focus_active`](Self::view_focus_active) to draw a focus
583    /// ring only during keyboard navigation, not on mouse clicks.
584    pub fn focus_visible(&self) -> Signal<bool> {
585        self.tree.focus_visible_signal()
586    }
587
588    /// Bind an opacity multiplier (0..1) to a widget. The render walker
589    /// emits `SetOpacity(value)` before painting the widget's subtree
590    /// and `RestoreOpacity` afterwards, so the multiplier composes
591    /// correctly with ancestor opacity scopes. Bound at `RepaintOnly`:
592    /// opacity changes never trigger relayout. Used by the `Fade`
593    /// wrapper to animate a child between hidden and fully visible.
594    pub fn set_opacity(&mut self, id: WidgetId, opacity: impl Into<crate::signal::Prop<f32>>) {
595        self.tree.set_opacity(id, opacity);
596    }
597
598    /// Bind a 2D affine transform to a widget. The render walker emits
599    /// `PushTransform(value)` before painting the widget's subtree and
600    /// `PopTransform` afterwards, so the transform composes onto the
601    /// renderer's stack with any ancestor transform scopes and with
602    /// the widget's own canvas-level transforms. Bound at `RepaintOnly`:
603    /// visual-only transforms never trigger relayout. Used by `Scale`
604    /// and `Rotate`; reflow-driving wrappers (e.g. `Scale::reflow(true)`)
605    /// must additionally bind their driver signal to themselves at
606    /// `Relayout` to make layout track the value.
607    pub fn set_transform(
608        &mut self,
609        id: WidgetId,
610        transform: impl Into<crate::signal::Prop<teksilo_canvas::Transform2D>>,
611    ) {
612        self.tree.set_transform(id, transform);
613    }
614
615    /// Bind a 2D affine **content** transform to a widget — the transform
616    /// positions the widget's content within its fixed parent-space viewport
617    /// (its bounds) rather than transforming the widget itself. Renders the
618    /// same `PushTransform` / `PopTransform` scope as
619    /// [`set_transform`](Self::set_transform), but hit-testing treats the
620    /// bounds as a fixed viewport so the whole visible area stays interactive
621    /// at any pan / zoom. Used by `SceneView` for its pan/zoom view transform.
622    pub fn set_content_transform(
623        &mut self,
624        id: WidgetId,
625        transform: impl Into<crate::signal::Prop<teksilo_canvas::Transform2D>>,
626    ) {
627        self.tree.set_content_transform(id, transform);
628    }
629
630    /// Bind a Gaussian-equivalent blur radius to a widget. The render
631    /// walker emits `BeginBlurredSubtree { bounds, radius }` before
632    /// painting the widget's subtree and `EndBlurredSubtree` afterwards;
633    /// the renderer redirects drawing into an intermediate texture, runs
634    /// a dual-Kawase blur chain at the requested radius, and composites
635    /// the blurred result back into the parent pass at the widget's
636    /// bounds. Bound at `RepaintOnly`: blur radius changes never trigger
637    /// relayout. Sub-perceptual radii (< 0.5) skip the Begin/End pair
638    /// entirely so animated enable/disable patterns have zero per-frame
639    /// cost when fully off. Used by the `Blur` wrapper.
640    pub fn set_blur(&mut self, id: WidgetId, radius: impl Into<crate::signal::Prop<f32>>) {
641        self.tree.set_blur(id, radius);
642    }
643
644    /// Bind a widget's enabled state to a boolean prop or compatibility state binding.
645    pub fn enabled_when(&mut self, id: WidgetId, state: impl Into<crate::signal::Prop<bool>>) {
646        self.tree.enabled_when(id, state);
647    }
648
649    /// Reactive view of "is this widget effectively enabled?" — the AND
650    /// of the widget's own `enabled_state` and every ancestor's. The
651    /// arena's [`crate::arena::WidgetArena::is_enabled`] is the
652    /// non-reactive equivalent; this method gives composite widgets a
653    /// `Signal<bool>` they can `.map(...)` / `.zip(...)` against to
654    /// derive other reactive UI state (cursor, custom paint, helper
655    /// signals).
656    ///
657    /// Leaves like `IconWidget` / `TextWidget` / `RectWidget` do NOT
658    /// need this — they get the bool directly via
659    /// [`crate::widget::PaintContext::effective_enabled`] at paint time.
660    /// This method is for composites that need the value at build time
661    /// or want to chain signals.
662    ///
663    /// The signal is node-resident and framework-refreshed (install-or-reuse,
664    /// like [`Self::activation_signal`]), so it tracks ancestors correctly even
665    /// though a widget's parent is not yet wired while its own `build()` runs.
666    /// It is a *mutable* signal, so — unlike the old derived implementation —
667    /// it can be passed to [`Self::effect`].
668    ///
669    /// Returns a signal reading `true` for any node whose entire ancestor
670    /// chain (including itself) has no `enabled_state` bound.
671    pub fn effective_enabled_signal(&mut self, id: WidgetId) -> Signal<bool> {
672        self.tree.effective_enabled_signal(id)
673    }
674
675    /// Bind a widget's Tab-key participation to a boolean prop or
676    /// compatibility state binding. When false, the widget is removed
677    /// from Tab / Shift+Tab traversal but remains reachable via
678    /// `request_focus` and arrow-key navigation. Implements the ARIA
679    /// roving-tabindex pattern (HTML `tabindex="-1"` semantics).
680    pub fn set_tab_stop(&mut self, id: WidgetId, state: impl Into<crate::signal::Prop<bool>>) {
681        self.tree.set_tab_stop(id, state);
682    }
683
684    /// Declare the widget being built as a **traversal-scope boundary** for
685    /// Tab / Shift+Tab navigation. Descendants' `tab_index` values become
686    /// scoped to this node — they never collide with sibling scopes — and the
687    /// `policy` controls what happens at the scope's ends:
688    ///
689    /// - [`TraversalScopePolicy::Continue`](crate::focus::TraversalScopePolicy::Continue)
690    ///   — Tab flows out into the enclosing scope's next member (groups
691    ///   numbering only).
692    /// - [`TraversalScopePolicy::Cycle`](crate::focus::TraversalScopePolicy::Cycle)
693    ///   — Tab wraps within the scope, never exits. For **modal dialogs only**:
694    ///   a popover or menu is non-modal, and the framework closes one the
695    ///   keyboard walks out of rather than containing focus in it. Trapping such
696    ///   an overlay stops that dismissal from ever firing.
697    ///
698    /// This node is automatically excluded from being a Tab stop itself.
699    /// Prefer the `FocusScope` wrapper widget in `teksilo-widgets` over
700    /// calling this directly.
701    pub fn set_traversal_scope(&mut self, policy: crate::focus::TraversalScopePolicy) {
702        let id = self.self_id();
703        self.tree.set_traversal_scope(id, policy);
704    }
705
706    /// Attach a tooltip to a widget.
707    pub fn attach_tooltip(
708        &mut self,
709        anchor_id: WidgetId,
710        content_id: WidgetId,
711        delay: std::time::Duration,
712    ) {
713        self.tree.attach_tooltip(anchor_id, content_id, delay);
714        self.claim_tooltip_description(anchor_id);
715    }
716
717    /// Attach a tooltip with an explicit
718    /// [`TooltipPlacement`](crate::overlay::TooltipPlacement) — use `Side`
719    /// for anchors stacked vertically (menu items, a vertical tab strip,
720    /// list/tree rows) so the tooltip opens beside the anchor instead of
721    /// covering the next sibling.
722    pub fn attach_tooltip_with_placement(
723        &mut self,
724        anchor_id: WidgetId,
725        content_id: WidgetId,
726        delay: std::time::Duration,
727        placement: crate::overlay::TooltipPlacement,
728    ) {
729        self.tree
730            .attach_tooltip_with_placement(anchor_id, content_id, delay, placement);
731        self.claim_tooltip_description(anchor_id);
732    }
733
734    /// Attach a tooltip that auto-promotes to sticky after a dwell
735    /// timer. Non-None `sticky_after` enables the sticky-on-dwell UX:
736    /// once the tooltip has been shown for `sticky_after`, the tree
737    /// flags the entry sticky and swaps the overlay's dismiss
738    /// behavior to `EscapeOrClickOutside`.
739    pub fn attach_tooltip_with_sticky(
740        &mut self,
741        anchor_id: WidgetId,
742        content_id: WidgetId,
743        delay: std::time::Duration,
744        sticky_after: Option<std::time::Duration>,
745    ) {
746        self.tree
747            .attach_tooltip_with_sticky(anchor_id, content_id, delay, sticky_after);
748        self.claim_tooltip_description(anchor_id);
749    }
750
751    /// Variant of [`attach_tooltip_with_sticky`](Self::attach_tooltip_with_sticky)
752    /// that takes a shared `Rc<Cell<Option<Instant>>>` "sink" the
753    /// tree updates whenever the tooltip is shown / dismissed. The
754    /// tooltip widget reads from this sink to compute its own dwell
755    /// progress reliably, without needing a paint-gap heuristic.
756    pub fn attach_tooltip_with_sticky_sink(
757        &mut self,
758        anchor_id: WidgetId,
759        content_id: WidgetId,
760        delay: std::time::Duration,
761        sticky_after: Option<std::time::Duration>,
762        shown_at_sink: std::rc::Rc<std::cell::Cell<Option<std::time::Instant>>>,
763    ) {
764        self.tree.attach_tooltip_with_sticky_sink(
765            anchor_id,
766            content_id,
767            delay,
768            sticky_after,
769            shown_at_sink,
770        );
771        self.claim_tooltip_description(anchor_id);
772    }
773
774    /// Variant of [`attach_tooltip_with_sticky_sink`](Self::attach_tooltip_with_sticky_sink)
775    /// that also carries a [`TooltipPlacement`](crate::overlay::TooltipPlacement).
776    /// The full-featured path used by rich + composite tooltips that want
777    /// `Side` placement in a vertical context (menu items, list/tree rows).
778    pub fn attach_tooltip_with_sticky_sink_placement(
779        &mut self,
780        anchor_id: WidgetId,
781        content_id: WidgetId,
782        delay: std::time::Duration,
783        sticky_after: Option<std::time::Duration>,
784        shown_at_sink: std::rc::Rc<std::cell::Cell<Option<std::time::Instant>>>,
785        placement: crate::overlay::TooltipPlacement,
786    ) {
787        self.tree.attach_tooltip_with_sticky_sink_placement(
788            anchor_id,
789            content_id,
790            delay,
791            sticky_after,
792            shown_at_sink,
793            placement,
794        );
795        self.claim_tooltip_description(anchor_id);
796    }
797
798    /// Name this widget as the one the tooltip just attached describes.
799    ///
800    /// Every `attach_tooltip*` wrapper ends with this, so a composing control
801    /// gets it for free: `Button`, `Toggle` and the two dozen widgets shaped
802    /// like them hang the overlay off an inner chrome node -- the thing with
803    /// the right bounds to open against -- while their role, their name and
804    /// their focusability sit on their own outer node, which is the node an
805    /// assistive technology lands on and therefore the node a description has
806    /// to be on.
807    ///
808    /// A widget anchoring its tooltip on itself claims itself, which is what
809    /// it already had. A widget attaching *many* tooltips in one build -- a
810    /// list body pane, one per visible row -- claims itself for every one of
811    /// them, which is a claim that cannot be granted; the accessibility walk
812    /// is where that is noticed, because it is the only place the whole set
813    /// is visible at once.
814    fn claim_tooltip_description(&mut self, anchor_id: WidgetId) {
815        let owner = self.self_id();
816        self.tree.set_tooltip_description_owner(anchor_id, owner);
817    }
818
819    /// Promote a shown tooltip to "sticky": removes its auto-dismiss
820    /// on pointer-leave and swaps the overlay's dismiss behavior to
821    /// `EscapeOrClickOutside`. Used by rich tooltips that implement a
822    /// dwell timer.
823    pub fn promote_tooltip_to_sticky(&mut self, content_id: WidgetId) {
824        self.tree.promote_tooltip_to_sticky(content_id);
825    }
826
827    /// Set a widget as dormant (inactive). Used to pre-create overlay content
828    /// that will be activated later via `EventContext::activate()`.
829    pub fn set_dormant(&mut self, id: WidgetId) {
830        self.tree.set_dormant(id);
831    }
832
833    /// Destroy a widget and its entire subtree, removing them from the
834    /// arena and dropping any per-widget subscription / effect handles.
835    ///
836    /// Use this to clean up dormant subtrees that the current widget
837    /// created during a prior build and that live outside its regular
838    /// arena children — e.g., a pre-built popup panel inserted via
839    /// `ctx.add(..)` + `ctx.set_dormant(..)` that becomes stale after a
840    /// rebuild. Regular arena children of the composite (i.e. widgets
841    /// whose ids are returned from `build`) are destroyed automatically
842    /// by the framework's rebuild path and do not need this call.
843    ///
844    /// If an overlay currently references `id` as its content, the
845    /// overlay is dismissed first so the manager does not retain a
846    /// stale content reference.
847    pub fn destroy_subtree(&mut self, id: WidgetId) {
848        let overlay_id = self.tree.overlay_manager().find_by_content(id);
849        if let Some(overlay_id) = overlay_id {
850            self.tree.dismiss_overlay(overlay_id);
851        }
852        self.tree.destroy_subtree(id);
853    }
854
855    /// Apply a `HandlerSet` to the composite widget being built (self).
856    /// This transfers attached event handlers, focusable flag, cursor, etc.
857    /// to the widget's arena node, replacing `event()` and `is_focusable()` overrides.
858    pub fn apply_self_handlers(&mut self, handler_set: crate::widget_builder::HandlerSet) {
859        let id = self.self_id();
860        self.tree.apply_self_handler_set(id, handler_set);
861    }
862
863    /// Move keyboard focus to `id`. Mirrors
864    /// `EventContext::request_focus` for use during `build()` — e.g.
865    /// when a composing widget pre-builds an editor and needs focus to
866    /// land on it as soon as the subtree is wired in.
867    pub fn focus(&mut self, id: WidgetId) {
868        self.tree.focus(id);
869    }
870
871    /// Find the first focusable widget within the subtree rooted at
872    /// `root` in depth-first order. Returns `None` when the subtree has
873    /// no focusable descendant or `root` is not in the arena.
874    pub fn first_focusable_descendant(&self, root: WidgetId) -> Option<WidgetId> {
875        self.tree.first_focusable_descendant(root)
876    }
877
878    /// Move keyboard focus **into** the subtree rooted at `id`: its first
879    /// focusable descendant in tab order, or `id` itself when it is the only
880    /// focusable thing there. Returns whether focus ended up inside `id`.
881    ///
882    /// The build-time twin of
883    /// [`EventContext::request_focus_into`](crate::widget::EventContext::request_focus_into),
884    /// and safe here for the same reason [`focus`](Self::focus) is: `add` builds
885    /// a child's whole subtree synchronously, so by the time a composing widget
886    /// holds a child's id the focusable descendants of that child already exist.
887    ///
888    /// **Idempotent, and that is the point.** `build` runs again on every
889    /// rebuild, so a bare `focus` here would drag focus back into this subtree
890    /// every time the owner rebuilt for an unrelated reason — a table body pane
891    /// rebuilds on selection, on filtering and on scroll. This is a no-op while
892    /// focus already sits inside `id`, so it expresses "focus belongs in here"
893    /// rather than "focus here now".
894    ///
895    /// A subtree with nothing focusable leaves focus exactly where it was: an
896    /// empty region never traps it.
897    ///
898    /// ⚠ **Ancestor-chain side effects do not run**, and that is a property of
899    /// focusing from `build` at all, not of this method — [`focus`](Self::focus)
900    /// has it too. A node added during `build` is not parented until the build
901    /// that produced it *returns*, so at this moment `id`'s chain stops at
902    /// whatever the caller has already inserted: `focus_within` signals on
903    /// enclosing nodes never flip, and `scroll_focused_into_view` finds no
904    /// scroll container to reveal the target in. Everything **below** `id` is
905    /// linked (children are parented as each is inserted), so the walk that
906    /// picks the focusable descendant, and every later key dispatch — which
907    /// happens after the pass, on a whole tree — are unaffected.
908    ///
909    /// Reach for [`EventContext::request_focus_into`](crate::widget::EventContext::request_focus_into)
910    /// where the difference matters: it is queued and drained after dispatch,
911    /// against a complete tree.
912    pub fn focus_into(&mut self, id: WidgetId) -> bool {
913        if let Some(focused) = self.tree.focused()
914            && (focused == id || self.tree.is_descendant_of(focused, id))
915        {
916            return true;
917        }
918        match self.tree.first_focusable_descendant(id) {
919            Some(target) => {
920                self.tree.focus(target);
921                true
922            }
923            None => false,
924        }
925    }
926
927    // --- Actions & shortcuts ---
928
929    /// Attach an [`Action`](crate::action::Action) to the widget being
930    /// built. Actions are consulted during intent dispatch as the
931    /// framework walks source-widget → root; the first matching,
932    /// enabled action wins (subject to the `IntentResponse` returned
933    /// by its handler).
934    ///
935    /// Actions are cleared on rebuild, mirroring event handlers.
936    pub fn register_action(&mut self, action: crate::action::Action) {
937        let id = self.self_id();
938        self.tree.push_action(id, action);
939    }
940
941    /// Declare that the widget being built **edits text**.
942    ///
943    /// Every text widget should call this. It is what lets an application take
944    /// a text chord — `Ctrl+Z`, `Ctrl+C` — for itself without silently breaking
945    /// the widget it took it from: the host asks
946    /// [`focused_text_surface`](crate::widget_tree::WidgetTree::focused_text_surface)
947    /// and either drives this surface or steps aside so the widget keeps its own
948    /// keys. See [`crate::text_surface`] for the whole argument.
949    ///
950    /// Owned by the registering widget and torn down on its rebuild or destroy,
951    /// like [`register_action_global`](Self::register_action_global). Calling it
952    /// twice from one widget re-points rather than duplicating, so a rebuild
953    /// that hands over a fresh handle is correct.
954    pub fn register_text_surface(
955        &mut self,
956        surface: std::rc::Rc<dyn crate::text_surface::TextSurface>,
957    ) {
958        let id = self.self_id();
959        self.tree.push_text_surface(id, surface);
960    }
961
962    /// A cloneable view of this tree's registered text surfaces.
963    ///
964    /// Take it once, during `build`, and hold it: a view-model refreshed from a
965    /// frame tick has no `&WidgetTree` to consult, and that is exactly when it
966    /// needs to know whether the caret is in a text widget.
967    pub fn text_surfaces(&self) -> crate::text_surface::TextSurfaces {
968        self.tree.text_surfaces()
969    }
970
971    /// Register a **window-global** [`Action`](crate::action::Action), owned by
972    /// the widget being built. Unlike [`register_action`](Self::register_action)
973    /// — which only fires when this widget is on the intent's source→root walk —
974    /// a global action is consulted as a dispatch *fallback*, so it is reachable
975    /// no matter where the intent originated: a menu-bar dropdown (which renders
976    /// in an overlay, not under the registering widget), deep content, or a
977    /// global shortcut anchored at the root when nothing is focused.
978    ///
979    /// This is the action-side counterpart to
980    /// [`register_shortcut_global`](Self::register_shortcut_global): use it for
981    /// app-wide commands (`app.save`, `view.toggle_sidebar`) whose handler lives
982    /// at the app root but whose triggers (menu, toolbar, shortcut) are scattered
983    /// across the tree and chrome. Ownership applies: the action is torn down
984    /// when this widget rebuilds or is destroyed.
985    pub fn register_action_global(&mut self, action: crate::action::Action) {
986        let id = self.self_id();
987        self.tree.push_global_action(id, action);
988    }
989
990    /// Register a [`Shortcut`](crate::shortcut::Shortcut) in the
991    /// tree's registry, owned by the widget being built.
992    ///
993    /// If the shortcut builder left `scope` at the default
994    /// ([`ShortcutScope::Global`](crate::shortcut::ShortcutScope::Global)),
995    /// this method rewrites it to `Scoped(self_id)` so the shortcut
996    /// only fires when focus is inside the registering widget's
997    /// subtree — the ergonomic default for widget-declared shortcuts.
998    /// Callers that want an explicit global shortcut should use
999    /// [`BuildContext::register_shortcut_global`] instead; callers
1000    /// that want to scope to a specific child should set
1001    /// `.scope_to(child_id)` on the builder themselves.
1002    ///
1003    /// Ownership: the shortcut is removed from the registry when the
1004    /// widget is destroyed or rebuilt. User overrides survive across
1005    /// rebuilds (graveyard semantics).
1006    pub fn register_shortcut(&mut self, mut shortcut: crate::shortcut::Shortcut) {
1007        let id = self.self_id();
1008        if shortcut.scope == crate::shortcut::ShortcutScope::Global {
1009            shortcut.scope = crate::shortcut::ShortcutScope::Scoped(id);
1010        }
1011        self.tree
1012            .shortcut_registry_mut()
1013            .register_owned(shortcut, id);
1014    }
1015
1016    /// Register a [`Shortcut`](crate::shortcut::Shortcut) with
1017    /// explicit global scope, owned by the widget being built. Unlike
1018    /// [`BuildContext::register_shortcut`], this does not rewrite the
1019    /// scope — the shortcut fires regardless of focus position.
1020    ///
1021    /// Ownership still applies: the shortcut is torn down when this
1022    /// widget goes away.
1023    pub fn register_shortcut_global(&mut self, mut shortcut: crate::shortcut::Shortcut) {
1024        let id = self.self_id();
1025        shortcut.scope = crate::shortcut::ShortcutScope::Global;
1026        self.tree
1027            .shortcut_registry_mut()
1028            .register_owned(shortcut, id);
1029    }
1030
1031    /// Pre-declare shortcuts on behalf of a not-yet-mounted child
1032    /// (e.g. a `Switcher` walking its `Pending` slots' static
1033    /// declarations before they're inserted). Each shortcut is owned
1034    /// by the *calling* widget and its declared scope is preserved
1035    /// as-is — unlike [`register_shortcut`](Self::register_shortcut),
1036    /// no rewrite from `Global` to `Scoped(self)` happens, because
1037    /// the child intended its own scope.
1038    ///
1039    /// When the child is eventually mounted, the framework's
1040    /// insert-time walk of `Widget::declare_shortcuts` re-registers
1041    /// the same ids owned by the *child*; the registry's idempotent
1042    /// upsert moves ownership cleanly. If the child never mounts, the
1043    /// pre-declared entries stay alive (owned by the parent) so
1044    /// settings UIs still see them, and they get torn down when the
1045    /// parent goes away.
1046    pub fn register_pending_shortcuts(
1047        &mut self,
1048        shortcuts: impl IntoIterator<Item = crate::shortcut::Shortcut>,
1049    ) {
1050        let id = self.self_id();
1051        let registry = self.tree.shortcut_registry_mut();
1052        for shortcut in shortcuts {
1053            registry.register_owned(shortcut, id);
1054        }
1055    }
1056
1057    /// Read-through access to the tree's shortcut registry. Consumers
1058    /// (menus, tooltips) look up the effective keystroke for a given
1059    /// id here, and observe
1060    /// [`ShortcutRegistry::version`](crate::shortcut::ShortcutRegistry::version)
1061    /// to refresh when the user rebinds.
1062    pub fn shortcut_registry(&self) -> &crate::shortcut::ShortcutRegistry {
1063        self.tree.shortcut_registry()
1064    }
1065
1066    /// Effective view of a shortcut by id, merged with any user
1067    /// override. Returns `None` when no default has been registered
1068    /// for `id`. Typical caller pattern: call from `paint()` so
1069    /// late-registered shortcuts are still picked up without a
1070    /// dedicated build-phase query.
1071    pub fn effective_shortcut<'b>(
1072        &'b self,
1073        id: &str,
1074    ) -> Option<crate::shortcut::EffectiveShortcut<'b>> {
1075        self.shortcut_registry().effective(id)
1076    }
1077
1078    /// Convenience accessor for the reactive version signal. Widgets
1079    /// that render shortcut-derived state (menu labels, tooltips)
1080    /// observe this so the UI refreshes when the user rebinds or a
1081    /// new shortcut is registered.
1082    pub fn shortcut_version(&self) -> &Signal<u64> {
1083        self.shortcut_registry().version()
1084    }
1085
1086    /// A reactive, **per-id** handle to a shortcut's effective primary
1087    /// keystroke — the granular alternative to [`Self::shortcut_version`].
1088    /// Bind this to render one shortcut's accelerator as a *leaf* value
1089    /// (a menu item's trailing label, a tooltip) that refreshes in place
1090    /// when the user rebinds *that* id, without observing — and rebuilding
1091    /// on — every unrelated registry mutation. The signal is created on
1092    /// first request, seeded with the current value, and kept live by the
1093    /// registry across register / unregister / rebind of that id.
1094    pub fn effective_shortcut_signal(
1095        &mut self,
1096        id: &'static str,
1097    ) -> Signal<Option<crate::shortcut::KeyStroke>> {
1098        self.tree
1099            .shortcut_registry_mut()
1100            .effective_primary_signal(id)
1101    }
1102
1103    /// Apply a `HandlerSet` to a child widget created during this build.
1104    /// Use this to attach event handlers to children without wrapping them
1105    /// in `WidgetWithHandlers`.
1106    pub fn apply_handlers(
1107        &mut self,
1108        id: crate::widget_id::WidgetId,
1109        handler_set: crate::widget_builder::HandlerSet,
1110    ) {
1111        // A composing parent attaches handlers to a child — from the
1112        // child's perspective these are external and must survive the
1113        // child's own rebuilds.
1114        self.tree.apply_external_handler_set(id, handler_set);
1115    }
1116
1117    /// Wire an accessibility `labelled_by` relation from an already-mounted
1118    /// child (`id`) to its label (`label_id`), so assistive tech announces the
1119    /// field by its visible label (WCAG 3.3.2 / EN 301 549 11.5.2.7). Unlike
1120    /// the `.access_labelled_by(..)` builder method, this operates *after* the
1121    /// child is mounted (so a container like `FormLayout` can pair a label and
1122    /// a boxed field once both ids are resolved) and preserves any
1123    /// accessibility overrides the child already carries.
1124    pub fn access_labelled_by(
1125        &mut self,
1126        id: crate::widget_id::WidgetId,
1127        label_id: crate::widget_id::WidgetId,
1128    ) {
1129        self.tree.push_access_labelled_by(id, label_id);
1130    }
1131
1132    /// Wire an accessibility `described_by` relation from an already-mounted
1133    /// child (`id`) to a description/error node (`target_id`) — the
1134    /// post-mount, override-preserving counterpart of the
1135    /// `.access_described_by(..)` builder method (WCAG 3.3.1).
1136    pub fn access_described_by(
1137        &mut self,
1138        id: crate::widget_id::WidgetId,
1139        target_id: crate::widget_id::WidgetId,
1140    ) {
1141        self.tree.push_access_described_by(id, target_id);
1142    }
1143
1144    /// The id this subscription should carry: the one the previous build used at this
1145    /// same position, or a fresh one.
1146    ///
1147    /// ⚠ **Position is the whole matching rule**, and it is deliberate. The alternative
1148    /// — matching on the origin — cannot be written here: `origin` reaches the adapter
1149    /// as `Box<dyn Any>`, with no `Eq` and no `Hash` to compare it by, and requiring
1150    /// either would change every `EventSource` in existence. Position is stable for the
1151    /// shape widgets actually have, where `build()` runs the same subscribe calls in the
1152    /// same order every time.
1153    ///
1154    /// What a widget that subscribes *conditionally* gets: if the origin at position N
1155    /// differs between two builds, an event still in flight from the old origin is
1156    /// delivered to the new build's callback rather than being dropped. That is safe by
1157    /// construction rather than by luck — an app registers exactly one `EventSource`, so
1158    /// every subscription in the tree shares one origin type and one event type, and the
1159    /// payload downcast cannot mismatch. The callback receives the whole event and can
1160    /// read its origin, which is what `Origin::LongOperation(..)` handlers already do.
1161    fn next_subscription_id(
1162        &self,
1163        app_context: &crate::event_source::TreeAppContext,
1164    ) -> SubscriptionId {
1165        // `subscription_handles` is pushed to once per subscribe call and starts empty
1166        // for each build, so its length *is* this call's position within the build.
1167        self.reusable_sub_ids
1168            .get(self.subscription_handles.len())
1169            .copied()
1170            .unwrap_or_else(|| app_context.allocate_subscription_id())
1171    }
1172
1173    /// Subscribe to events from the registered application event source.
1174    /// The callback runs on the UI thread when the source publishes an
1175    /// event with a matching origin.
1176    ///
1177    /// The subscription is scoped to the current widget's lifetime: when
1178    /// the widget is rebuilt or destroyed, the framework drops the source
1179    /// handle (unregistering from the source) and removes the UI-side
1180    /// callback.
1181    ///
1182    /// It is scoped to the window it was registered from as well. A closing window's
1183    /// tree is dropped wholesale, with no per-widget destroy pass, so teksilo-app calls
1184    /// [`TreeAppContext::purge_subscriptions_for_window`](crate::event_source::TreeAppContext::purge_subscriptions_for_window)
1185    /// to drop the callbacks that window installed. A registration from a windowless
1186    /// tree (headless / tests) records no window, and only the per-widget path above
1187    /// removes such a callback.
1188    ///
1189    /// # Panics
1190    ///
1191    /// Panics if no event source has been registered on the
1192    /// `TeksiloAppBuilder`. In debug builds, also asserts that the `Origin`
1193    /// and `Event` types match the registered source.
1194    pub fn subscribe_event<O, E, F>(&mut self, origin: O, callback: F)
1195    where
1196        O: 'static,
1197        E: 'static,
1198        F: Fn(&E) + 'static,
1199    {
1200        use std::any::{Any, TypeId};
1201        use std::rc::Rc;
1202        use std::sync::Arc;
1203
1204        // Recorded so `TreeAppContext::purge_subscriptions_for_window` can drop this
1205        // entry when the window closes. A closing window's tree is dropped wholesale,
1206        // with no per-widget destroy pass, so nothing else ever reaches the entry and
1207        // the callback (plus everything it captured) would stay live for the rest of
1208        // the process. `None` from a windowless tree (headless / tests), which no
1209        // window purge touches. Mirrors `subscribe_event_with_ctx` below.
1210        let window_id = self.window().map(|w| w.id());
1211
1212        let app_context = self.tree.app_context.clone();
1213
1214        let adapter = app_context.event_source.as_ref().expect(
1215            "BuildContext::subscribe_event called but no event source was registered \
1216             on TeksiloAppBuilder. Call .event_source(source) on the builder first.",
1217        );
1218
1219        debug_assert_eq!(
1220            adapter.origin_type,
1221            TypeId::of::<O>(),
1222            "subscribe_event origin type mismatch: source uses {}, subscribe call used {}",
1223            adapter.origin_type_name,
1224            std::any::type_name::<O>(),
1225        );
1226        debug_assert_eq!(
1227            adapter.event_type,
1228            TypeId::of::<E>(),
1229            "subscribe_event event type mismatch: source uses {}, subscribe call used {}",
1230            adapter.event_type_name,
1231            std::any::type_name::<E>(),
1232        );
1233
1234        let sub_id = self.next_subscription_id(&app_context);
1235
1236        // The UI-side callback that runs after an event posted from the
1237        // source thread is delivered back to the UI thread. It downcasts
1238        // the type-erased payload back to `&E` and invokes the user's `F`.
1239        let stored_callback: Rc<dyn Fn(&dyn Any)> = Rc::new(move |event_any| {
1240            let event = event_any
1241                .downcast_ref::<E>()
1242                .expect("subscription event downcast failed — framework bug");
1243            callback(event);
1244        });
1245        app_context
1246            .subscription_callbacks
1247            .borrow_mut()
1248            .insert(sub_id, (window_id, stored_callback));
1249
1250        // Build the wrapper that the source will invoke from its
1251        // publisher thread. It carries only the sub_id (Copy) and an
1252        // Arc-clone of the poster (Send + Sync), boxes the typed event
1253        // as Any+Send, and posts an AppEvent::SubscriptionEvent through
1254        // the proxy. Tests that run without a registered poster post
1255        // events into a test queue and dispatch them back into the tree
1256        // via `tree.app_context().dispatch_subscription_event`.
1257        let poster = app_context
1258            .poster
1259            .as_ref()
1260            .expect(
1261                "BuildContext::subscribe_event called but no AppEventPoster \
1262                 is installed on the tree. teksilo-app installs one when an \
1263                 event source is registered on the builder; tests must \
1264                 supply a TestPoster via TreeAppContext::with_source_and_poster.",
1265            )
1266            .clone();
1267        let wrapper: Arc<dyn Fn(Box<dyn Any + Send>) + Send + Sync> =
1268            Arc::new(move |erased_event| {
1269                poster.post_subscription_event(sub_id, erased_event);
1270            });
1271
1272        let handle = (adapter.subscribe_fn)(Box::new(origin), wrapper);
1273        self.subscription_handles.push((sub_id, handle));
1274    }
1275
1276    /// Like [`subscribe_event`](Self::subscribe_event), but the UI-side
1277    /// callback additionally receives a fresh
1278    /// [`EventContext`](crate::widget::EventContext) bound to this widget's
1279    /// window. That lets it react to a backend event *imperatively* — update /
1280    /// replace / dismiss a toast, present a modal, `send_intent`, navigate —
1281    /// none of which a plain (context-free) `subscribe_event` callback can do
1282    /// (it can only poke `Signal`s).
1283    ///
1284    /// This is the supported bridge for **long-operation progress**: a Qleany
1285    /// `Origin::LongOperation(Progress | Completed | Cancelled | Failed)` event
1286    /// crosses from the operation's background thread to the UI thread and the
1287    /// callback drives an evolving progress toast (percentage in the body, a
1288    /// Cancel action, a success/error replacement on completion) — see the
1289    /// `toast_demo` example.
1290    ///
1291    /// The event is delivered on the UI thread through the same
1292    /// `AppEvent::SubscriptionEvent` path as `subscribe_event`; teksilo-app
1293    /// mints the `EventContext` from this widget's window tree just before the
1294    /// call (mirroring `teksilo-async`'s `spawn_local_with` completion path).
1295    /// The subscription is torn down with the widget, exactly like
1296    /// `subscribe_event`.
1297    ///
1298    /// The `<O, E>` type match against the registered event source is a
1299    /// `debug_assert` (as in [`subscribe_event`](Self::subscribe_event)); a
1300    /// mismatched call site in a release build is not caught here but panics
1301    /// later at the payload downcast.
1302    ///
1303    /// Registering from a windowless tree (headless / tests) is allowed but
1304    /// records `None` for the window — the app-side router then has no tree to
1305    /// mint an `EventContext` from and cannot deliver it, so such a subscription
1306    /// never fires in a running app. Ordinary application widgets always have a
1307    /// window; headless code that wants to observe events should use
1308    /// [`subscribe_event`](Self::subscribe_event) and drive `Signal`s instead.
1309    pub fn subscribe_event_with_ctx<O, E, F>(&mut self, origin: O, callback: F)
1310    where
1311        O: 'static,
1312        E: 'static,
1313        F: Fn(&E, &mut crate::widget::EventContext) + 'static,
1314    {
1315        use std::any::{Any, TypeId};
1316        use std::rc::Rc;
1317        use std::sync::Arc;
1318
1319        let window_id = self.window().map(|w| w.id());
1320
1321        let app_context = self.tree.app_context.clone();
1322
1323        let adapter = app_context.event_source.as_ref().expect(
1324            "BuildContext::subscribe_event_with_ctx called but no event source was registered \
1325             on TeksiloAppBuilder. Call .event_source(source) on the builder first.",
1326        );
1327
1328        debug_assert_eq!(
1329            adapter.origin_type,
1330            TypeId::of::<O>(),
1331            "subscribe_event_with_ctx origin type mismatch: source uses {}, subscribe call used {}",
1332            adapter.origin_type_name,
1333            std::any::type_name::<O>(),
1334        );
1335        debug_assert_eq!(
1336            adapter.event_type,
1337            TypeId::of::<E>(),
1338            "subscribe_event_with_ctx event type mismatch: source uses {}, subscribe call used {}",
1339            adapter.event_type_name,
1340            std::any::type_name::<E>(),
1341        );
1342
1343        // Re-used across this widget's rebuilds exactly as in `subscribe_event` — the
1344        // context-bearing path keeps its callbacks in a second map but crosses the very
1345        // same queue, so it loses in-flight events the very same way. See
1346        // [`Self::next_subscription_id`].
1347        let sub_id = self.next_subscription_id(&app_context);
1348
1349        // The UI-side callback, invoked after an event posted from the source
1350        // thread is delivered back to the UI thread and a fresh `EventContext`
1351        // has been minted. Downcasts the type-erased payload back to `&E` and
1352        // forwards it plus the context to the user's `F`. Stored behind `Rc` so
1353        // dispatch can drop the map borrow before invoking it (re-entrancy).
1354        let stored_callback: Rc<dyn Fn(&dyn Any, &mut crate::widget::EventContext)> =
1355            Rc::new(move |event_any, ctx| {
1356                let event = event_any
1357                    .downcast_ref::<E>()
1358                    .expect("subscription event downcast failed — framework bug");
1359                callback(event, ctx);
1360            });
1361        app_context
1362            .subscription_ctx_callbacks
1363            .borrow_mut()
1364            .insert(sub_id, (window_id, stored_callback));
1365
1366        // Same publisher-thread wrapper as `subscribe_event`: carry only the
1367        // sub_id (Copy) + an Arc-clone of the poster, box the typed event, and
1368        // post an `AppEvent::SubscriptionEvent`. The dispatch side (teksilo-app)
1369        // routes context-bearing sub_ids through the fresh-`EventContext` path.
1370        let poster = app_context
1371            .poster
1372            .as_ref()
1373            .expect(
1374                "BuildContext::subscribe_event_with_ctx called but no AppEventPoster \
1375                 is installed on the tree. teksilo-app installs one when an \
1376                 event source is registered on the builder.",
1377            )
1378            .clone();
1379        let wrapper: Arc<dyn Fn(Box<dyn Any + Send>) + Send + Sync> =
1380            Arc::new(move |erased_event| {
1381                poster.post_subscription_event(sub_id, erased_event);
1382            });
1383
1384        let handle = (adapter.subscribe_fn)(Box::new(origin), wrapper);
1385        self.subscription_handles.push((sub_id, handle));
1386    }
1387}
1388
1389#[cfg(test)]
1390mod effect_tests {
1391    use super::*;
1392    use crate::widget::{LayoutContext, Widget};
1393    use crate::widget_id::WidgetId;
1394    use crate::widget_tree::WidgetTree;
1395    use teksilo_canvas::SizeProposal;
1396
1397    /// A leaf widget that registers an effect on one signal to mirror its
1398    /// value into another. Produces no children.
1399    #[derive(Debug)]
1400    struct LeafWithEffect {
1401        source: Signal<i32>,
1402        mirror: Signal<i32>,
1403    }
1404
1405    impl Widget for LeafWithEffect {
1406        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1407            let mirror = self.mirror.clone();
1408            ctx.effect(&self.source, move |v| mirror.set(*v));
1409            Vec::new()
1410        }
1411
1412        fn layout_response(
1413            &self,
1414            proposal: SizeProposal,
1415            _ctx: &LayoutContext,
1416        ) -> crate::widget::LayoutResponse {
1417            proposal.resolve(0.0, 0.0).into()
1418        }
1419    }
1420
1421    /// A widget that observes the per-frame tick signal and accumulates the
1422    /// deltas it receives into a shared counter, so a test can verify both
1423    /// that the tick fires at all and that the delta value is non-zero.
1424    #[derive(Debug)]
1425    struct FrameTickListener {
1426        ticks: Signal<u32>,
1427        last_delta: Signal<f32>,
1428    }
1429
1430    impl Widget for FrameTickListener {
1431        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1432            let ticks = self.ticks.clone();
1433            let last_delta = self.last_delta.clone();
1434            let tick = ctx.frame_tick();
1435            ctx.effect(&tick, move |delta| {
1436                ticks.set(ticks.get() + 1);
1437                last_delta.set(*delta);
1438            });
1439            Vec::new()
1440        }
1441
1442        fn layout_response(
1443            &self,
1444            proposal: SizeProposal,
1445            _ctx: &LayoutContext,
1446        ) -> crate::widget::LayoutResponse {
1447            proposal.resolve(0.0, 0.0).into()
1448        }
1449    }
1450
1451    #[test]
1452    fn frame_tick_stays_silent_until_explicit_request() {
1453        // The draw-when-needed contract: a widget that merely observes
1454        // frame_tick must NOT keep the tree awake. Only an explicit
1455        // `request_frame()` call pumps a tick.
1456        let mut tree = WidgetTree::new();
1457        let ticks = Signal::new(0_u32);
1458        let last_delta = Signal::new(-1.0_f32);
1459        tree.add(FrameTickListener {
1460            ticks: ticks.clone(),
1461            last_delta: last_delta.clone(),
1462        });
1463
1464        // Flush the initial layout-dirty flag from widget insertion.
1465        tree.layout(teksilo_canvas::SizeProposal::exact(400.0, 300.0));
1466        assert!(
1467            !tree.frame_requested(),
1468            "observing frame_tick does not set the request flag"
1469        );
1470
1471        tree.tick_animations(std::time::Duration::from_millis(16));
1472        assert_eq!(
1473            ticks.get(),
1474            0,
1475            "an un-requested tick_animations must not fire frame_tick observers"
1476        );
1477        assert_eq!(last_delta.get(), -1.0);
1478    }
1479
1480    #[test]
1481    fn frame_tick_fires_once_per_request() {
1482        let mut tree = WidgetTree::new();
1483        let ticks = Signal::new(0_u32);
1484        let last_delta = Signal::new(-1.0_f32);
1485        let id = tree.add(FrameTickListener {
1486            ticks: ticks.clone(),
1487            last_delta: last_delta.clone(),
1488        });
1489
1490        // Flush initial layout-dirty flag so assertions reflect only
1491        // the frame-tick contract.
1492        tree.layout(teksilo_canvas::SizeProposal::exact(400.0, 300.0));
1493
1494        tree.request_frame();
1495        assert!(tree.needs_redraw(), "explicit request marks the tree dirty");
1496        assert!(tree.frame_requested());
1497
1498        tree.tick_animations(std::time::Duration::from_millis(16));
1499        assert_eq!(ticks.get(), 1);
1500        assert!((last_delta.get() - 0.016).abs() < 0.001);
1501        assert!(
1502            !tree.frame_requested(),
1503            "request flag must be cleared after the tick fired"
1504        );
1505
1506        // Second request fires exactly one more tick.
1507        tree.request_frame();
1508        tree.tick_animations(std::time::Duration::from_millis(16));
1509        assert_eq!(ticks.get(), 2);
1510
1511        // Without a request, further ticks silently advance time.
1512        tree.tick_animations(std::time::Duration::from_millis(16));
1513        assert_eq!(ticks.get(), 2);
1514
1515        tree.destroy_subtree(id);
1516        tree.request_frame();
1517        tree.tick_animations(std::time::Duration::from_millis(16));
1518        assert_eq!(
1519            ticks.get(),
1520            2,
1521            "destroyed widget's observer must not resurrect"
1522        );
1523    }
1524
1525    #[test]
1526    fn frame_tick_delta_clamped_against_huge_pauses() {
1527        let mut tree = WidgetTree::new();
1528        let ticks = Signal::new(0_u32);
1529        let last_delta = Signal::new(-1.0_f32);
1530        tree.add(FrameTickListener {
1531            ticks: ticks.clone(),
1532            last_delta: last_delta.clone(),
1533        });
1534
1535        tree.request_frame();
1536        tree.tick_animations(std::time::Duration::from_secs(5));
1537        assert_eq!(ticks.get(), 1);
1538        assert!(
1539            (last_delta.get() - 0.1).abs() < 1e-4,
1540            "frame delta must clamp at 0.1s even after a multi-second pause"
1541        );
1542    }
1543
1544    #[test]
1545    fn leaf_widget_effect_fires_and_is_cleaned_up_on_destroy() {
1546        // Regression guard: before the insert_widget / add_child fix,
1547        // effect_handles for a leaf widget (Vec::new() from build()) were
1548        // dropped the moment BuildContext went out of scope, silently
1549        // unregistering the observer. After the fix, the handle is
1550        // transferred to the arena node and the effect fires on signal
1551        // changes until the widget is destroyed.
1552        let mut tree = WidgetTree::new();
1553        let source = Signal::new(0_i32);
1554        let mirror = Signal::new(0_i32);
1555
1556        let id = tree.add(LeafWithEffect {
1557            source: source.clone(),
1558            mirror: mirror.clone(),
1559        });
1560
1561        // The effect should be live after insertion.
1562        source.set(42);
1563        assert_eq!(
1564            mirror.get(),
1565            42,
1566            "leaf widget effect must survive build() and fire on signal change"
1567        );
1568
1569        source.set(7);
1570        assert_eq!(mirror.get(), 7);
1571
1572        // Destroying the widget drops its effect_handles, which in turn
1573        // drops each ObserverHandle and unregisters the observer.
1574        tree.destroy_subtree(id);
1575        source.set(100);
1576        assert_eq!(
1577            mirror.get(),
1578            7,
1579            "effect must be unregistered after widget destruction"
1580        );
1581    }
1582}
1583
1584#[cfg(test)]
1585mod focus_into_tests {
1586    use super::*;
1587    use crate::widget::{LayoutContext, Widget};
1588    use crate::widget_builder::HandlerSet;
1589    use crate::widget_id::WidgetId;
1590    use crate::widget_tree::WidgetTree;
1591    use teksilo_canvas::SizeProposal;
1592
1593    /// A leaf that is focusable when asked, so the walk has something real to
1594    /// find — or nothing at all.
1595    #[derive(Debug)]
1596    struct Leaf {
1597        focusable: bool,
1598    }
1599
1600    impl Widget for Leaf {
1601        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1602            if self.focusable {
1603                ctx.apply_self_handlers(HandlerSet::new().focusable(true));
1604            }
1605            Vec::new()
1606        }
1607        fn layout_response(
1608            &self,
1609            proposal: SizeProposal,
1610            _ctx: &LayoutContext,
1611        ) -> crate::widget::LayoutResponse {
1612            proposal.resolve(10.0, 10.0).into()
1613        }
1614    }
1615
1616    /// Holds `focusable` focusable leaves and publishes their ids.
1617    #[derive(Debug)]
1618    struct Panel {
1619        focusable: usize,
1620        leaves: Signal<Vec<WidgetId>>,
1621    }
1622
1623    impl Widget for Panel {
1624        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1625            let kids: Vec<WidgetId> = (0..2)
1626                .map(|i| {
1627                    ctx.add(Leaf {
1628                        focusable: i < self.focusable,
1629                    })
1630                })
1631                .collect();
1632            self.leaves.set(kids.clone());
1633            kids
1634        }
1635        fn layout_response(
1636            &self,
1637            proposal: SizeProposal,
1638            _ctx: &LayoutContext,
1639        ) -> crate::widget::LayoutResponse {
1640            proposal.resolve(10.0, 10.0).into()
1641        }
1642    }
1643
1644    /// Calls `focus_into(panel)` on every one of *its own* builds, which is how
1645    /// a composing widget uses it. Rebuilt on demand through `tick` — and
1646    /// rebuilding it leaves the panel and its leaves alive, which is the whole
1647    /// point: that is the situation the idempotence has to survive.
1648    #[derive(Debug)]
1649    struct Driver {
1650        panel: Signal<Option<WidgetId>>,
1651        tick: Signal<u64>,
1652        moved: Signal<bool>,
1653    }
1654
1655    impl Widget for Driver {
1656        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1657            self.tick.bind_to(
1658                ctx.self_id(),
1659                ctx.binding_registry(),
1660                crate::binding::BindingLevel::Rebuild,
1661            );
1662            if let Some(panel) = self.panel.get() {
1663                let moved = ctx.focus_into(panel);
1664                self.moved.set(moved);
1665            }
1666            Vec::new()
1667        }
1668        fn layout_response(
1669            &self,
1670            proposal: SizeProposal,
1671            _ctx: &LayoutContext,
1672        ) -> crate::widget::LayoutResponse {
1673            proposal.resolve(0.0, 0.0).into()
1674        }
1675    }
1676
1677    struct Probe {
1678        tree: WidgetTree,
1679        leaves: Vec<WidgetId>,
1680        tick: Signal<u64>,
1681        moved: Signal<bool>,
1682    }
1683
1684    impl Probe {
1685        fn rebuild_driver(&mut self) {
1686            self.tick.set(self.tick.get() + 1);
1687            self.tree.layout(SizeProposal::exact(100.0, 100.0));
1688        }
1689    }
1690
1691    /// A panel with `focusable` focusable leaves, plus a sibling driver that
1692    /// calls `focus_into` on it from `build`. `outside` is focusable and lives
1693    /// outside the panel, so "focus did not move" is observable.
1694    fn probe(focusable: usize) -> (Probe, WidgetId) {
1695        let leaves = Signal::new(Vec::new());
1696        let panel_id = Signal::new(None);
1697        let tick = Signal::new(0_u64);
1698        let moved = Signal::new(false);
1699
1700        let mut tree = WidgetTree::new();
1701        let outside = tree.add(Leaf { focusable: true });
1702        let panel = tree.add(Panel {
1703            focusable,
1704            leaves: leaves.clone(),
1705        });
1706        panel_id.set(Some(panel));
1707        tree.add(Driver {
1708            panel: panel_id,
1709            tick: tick.clone(),
1710            moved: moved.clone(),
1711        });
1712        tree.layout(SizeProposal::exact(100.0, 100.0));
1713        (
1714            Probe {
1715                tree,
1716                leaves: leaves.get(),
1717                tick,
1718                moved,
1719            },
1720            outside,
1721        )
1722    }
1723
1724    /// It lands on the first focusable descendant, not on the container.
1725    #[test]
1726    fn focus_into_lands_on_the_first_focusable_descendant() {
1727        let (p, _) = probe(2);
1728        assert!(p.moved.get());
1729        assert_eq!(p.tree.focused(), Some(p.leaves[0]));
1730    }
1731
1732    /// **It is a no-op while focus is already inside** — the property that lets
1733    /// it be called from `build`, which re-runs on every rebuild. A bare
1734    /// `focus` on the first focusable descendant would drag focus back to the
1735    /// first field every time the caller rebuilt for an unrelated reason, which
1736    /// mid-edit is the caret jumping to the start of the line.
1737    #[test]
1738    fn focus_into_leaves_focus_alone_when_it_is_already_inside() {
1739        let (mut p, _) = probe(2);
1740        p.tree.focus(p.leaves[1]);
1741        p.rebuild_driver();
1742        assert!(p.moved.get(), "focus is inside, so the answer is still yes");
1743        assert_eq!(
1744            p.tree.focused(),
1745            Some(p.leaves[1]),
1746            "focus was dragged back to the first focusable child"
1747        );
1748    }
1749
1750    /// A subtree with nothing focusable leaves focus exactly where it was: an
1751    /// empty region never traps it, and the caller is told so.
1752    #[test]
1753    fn focus_into_an_unfocusable_subtree_moves_nothing() {
1754        let (mut p, outside) = probe(0);
1755        p.tree.focus(outside);
1756        p.rebuild_driver();
1757        assert!(!p.moved.get());
1758        assert_eq!(p.tree.focused(), Some(outside));
1759    }
1760}