Session management: xdg-session-management-v1 client, mandatory App::app_id / save_state / restore_state, runtime-managed state persistence and clean exit on signals (0.3.0)
Applications built on ltk had no way to come back where the user left them: the toolkit hardcoded `app_id = "ltk"` on every toplevel, never wrote anything to disk, and died on SIGTERM without a chance to save. This release gives the runtime the whole plumbing and asks each application only for the bytes worth keeping, in the spirit of Android's saved-instance state. The `App` trait gains three mandatory methods, deliberately without default bodies so every application states its position: `app_id()` (reverse-DNS, used for `xdg_toplevel.set_app_id`, the AccessKit application name and the state directory — the `app_id` element of the deprecated `window_config` tuple is now ignored and a one-time warning reports a mismatch), `save_state() -> Option<Vec<u8>>` and `restore_state(Vec<u8>)`. The bytes are opaque; the trait carries no serde bound. Their rustdoc is the contract: when the runtime saves, where the files live, when the bytes come back and when they do not, what must never go in them, and a worked serde_json example. The runtime persists under `$XDG_STATE_HOME/<app_id>/` (falling back to `~/.local/state`): `session.json` holds the compositor session id, a clean-exit marker and the writer's pid; `state.bin` holds the application bytes. Writes are atomic (temp file + rename, mode 0600, directory 0700) and best-effort. State is saved every 30 s when the bytes changed, once after the event loop exits (which covers `on_close_requested`, `requested_exit` and lost connections), and on SIGTERM/SIGINT — a calloop signal source, installed before any thread exists, now turns those into a clean exit of the loop instead of process death. `restore_state` runs synchronously in `try_run` before the window is created and before the first `view()`, and only when the process is relaunched as part of a session restore (`LTK_SESSION_RESTORE=1`, removed from the environment before the app can spawn children) or when the previous run left `clean_exit: false`; a plain launch starts fresh. A second concurrent instance detects the live pid and runs with persistence disabled rather than clobbering the first. The compositor side of geometry restore goes through `xdg-session-management-v1`. Neither wayland-protocols nor sctk ship generated code for it yet, so the XML is vendored under `protocols/` and `wayland-scanner` generates the client module in-tree (`src/protocol/`), resolving the crate names through sctk's reexports so the bindings stay on the crate instances sctk links. Before the first commit of a `ShellMode::Window` toplevel the runtime binds `xdg_session_manager_v1`, calls `get_session(reason, stored_id)` and `restore_toplevel(toplevel, "main")`; the three window-creation paths in `run.rs` are folded into one `make_window` helper so the attach always sits immediately before `commit()`. `created` persists the id, `replaced` destroys the objects and stops persisting. Compositors without the global lose only the geometry half. Layer-shell and session-lock surfaces skip the whole machinery. Every `App` implementor in the tree is updated: the twelve examples (`showcase`, `scroll` and `mini_shell` persist real state; the rest return `None`), both integration tests (`event_loop_flow` gains `save_restore_round_trip`), the in-source and markdown doctests, README, onboarding, cookbook (new recipe "Surviving relaunch: session state") and architecture docs, and the changelog. `src/session_state.rs` carries unit tests over a temporary state directory. `Makefile install` now copies `protocols/` into the cargo registry — without it downstream builds would fail inside the proc-macro — and `debian/copyright` covers the vendored XML. The trait change is breaking, hence 0.3.0. Also fixes the pre-existing `viewport_tests` module in `render/mod.rs`, which used `Length` without importing it and broke `cargo test`.
This commit is contained in:
@@ -149,6 +149,25 @@ impl App for CounterApp
|
||||
{
|
||||
type Message = Msg;
|
||||
|
||||
// Names the window for the compositor and the a11y tree, and the
|
||||
// `$XDG_STATE_HOME/<app_id>/` directory the runtime saves state in.
|
||||
fn app_id( &self ) -> &str { "net.example.Counter" }
|
||||
|
||||
// Opaque bytes ltk persists for you; handed back only on a session
|
||||
// restore or after a crash — a plain launch starts fresh.
|
||||
fn save_state( &self ) -> Option<Vec<u8>>
|
||||
{
|
||||
Some( self.value.to_string().into_bytes() )
|
||||
}
|
||||
|
||||
fn restore_state( &mut self, state: Vec<u8> )
|
||||
{
|
||||
if let Some( v ) = String::from_utf8( state ).ok().and_then( |s| s.parse().ok() )
|
||||
{
|
||||
self.value = v;
|
||||
}
|
||||
}
|
||||
|
||||
fn view( &self ) -> Element<Msg>
|
||||
{
|
||||
column::<Msg>()
|
||||
@@ -306,7 +325,7 @@ In practice, most first apps only need a small subset of the surface area.
|
||||
|
||||
Start here:
|
||||
|
||||
- `App`
|
||||
- `App` — `app_id`, `view`, `update`, `save_state` / `restore_state`
|
||||
- `Element<Msg>`
|
||||
- `button`, `text`, `text_edit`, `img_widget`
|
||||
- `column`, `row`, `stack`, `grid`, `spacer`
|
||||
@@ -418,6 +437,20 @@ Use `core::UiSurface` when you want `ltk`'s layout/drawing/hit-testing without
|
||||
|
||||
There is coverage for that path in `tests/core_surface.rs`.
|
||||
|
||||
## Session state
|
||||
|
||||
`ltk` owns the plumbing, you own the bytes. `save_state` returns whatever a
|
||||
relaunch needs (any encoding — the runtime never looks inside) and the
|
||||
runtime writes it to `$XDG_STATE_HOME/<app_id>/state.bin` every 30 s when it
|
||||
changed, when the window closes and on `SIGTERM` / `SIGINT`. `restore_state`
|
||||
gets those bytes back before the first frame — but only when the shell
|
||||
relaunches the app as part of a session restore (`LTK_SESSION_RESTORE=1`) or
|
||||
when the previous run did not exit cleanly. Opening the app from the launcher
|
||||
starts fresh; window size and position still come back on every launch
|
||||
because the compositor restores them through `xdg-session-management-v1`.
|
||||
Shell components (panels, lock screens) return `None` and no-op. See the
|
||||
cookbook recipe *Surviving relaunch: session state* for a worked example.
|
||||
|
||||
## Current assumptions and rough edges
|
||||
|
||||
This repo is usable, but a few current behaviours are worth knowing up front:
|
||||
|
||||
Reference in New Issue
Block a user