mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-08-01 16:58:06 +00:00
* feat(layout): adaptive layout & font scaling system for plugins Add src/adaptive_layout.py — opt-in core helpers so plugins render legibly on any panel size without hand-tuned per-display layouts: - Region: integer rect algebra (bands/columns/weighted splits/centering) that partitions space so text bands can't overlap by construction - Font ladders: ordered (family, size) steps known to render crisply (LADDER_GRID: X11 BDFs at native sizes; LADDER_ARCADE: PressStart2P at 8px multiples) — fitting walks the ladder instead of scaling pixel fonts fractionally - LayoutContext: breakpoint tiers, geometry scale vs. a declared design size, and cached fit_text/fit_lines/font_for_rows queries Generalizes the three patterns proven in the field: f1-scoreboard's scale factor, masters-tournament's tiers, baseball-scoreboard's font fallback ladder. Wiring: BasePlugin gains a lazy .layout property and draw_fit(); FontManager gains get_native_bdf_size() and a cache_generation counter; manifest schema gains display.design_size and requires.display_size max_width/max_height; 96x48 joins DEFAULT_TEST_SIZES; the bounds-check harness records negative-coordinate draws; TextHelper's broken measurement helpers are fixed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(layout): adaptive image fitting + composite region helpers Add src/adaptive_images.py — the image counterpart to fit_text: - fit_image(img, box, mode=contain|cover|fill_height|stretch, crop_to_ink, anchor, resample, upscale) promoting the proven plugin patterns (football's crop-to-ink fill-height logos, masters' cover crop + NEAREST flags, static-image's letterbox). Upscales by default — thumbnail()'s downscale-only behavior is why imagery stays tiny on big panels. - draw_fitted_image() pastes aligned within a Region with alpha mask. - One central Pillow>=9.1 RESAMPLE shim replacing ~15 plugin copies. LayoutContext.fit_image() caches results per (identity, box size, options) with a 64-entry LRU; id()-keyed entries pin the source image. BasePlugin.draw_image() is the one-liner adoption path beside draw_fit. Composites in adaptive_layout.py: Region.offset() (user x/y-offset passthrough), scoreboard_regions() (the two-logos-plus-score card math duplicated across six sports plugins, logo_slot = min(H, W//2)), and media_row() (art-left/text-right). Fix LogoHelper's size-blind cache key (stale sizes on panel change); deprecation note on dead image_utils.py. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(harness): scale-up fill check, config variants, multi-size dev gallery Quality gates for adaptive layout: - fill_metrics()/check_scale_up() in the safety harness: overflow catches content too big for a panel, but nothing caught content that stays tiny on panels >= 2x the plugin's declared design size. The check measures lit-content extents and warns (or fails, when a plugin opts into "fill_check": "strict" in test/harness.json) below 50% coverage on the doubled axis. Warn-only by default so no existing plugin breaks. - harness.json "variants": extra runs with config overlays and their own golden dirs, so an opt-in mode (e.g. layout_mode: adaptive) is golden- tested beside the classic default. check_plugin.py loops base + variants and labels variant results mode@name. - Dev preview server: GET /api/sizes (harness size sample), POST /api/render-matrix (render at up to 12 sizes in one call), size-preset dropdown, and an "All Sizes" side-by-side gallery in the preview UI. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(plugins): adaptive-lib discoverability + advisory version compat warning Discoverability: re-export the adaptive layout/image API from src.common (the blessed-helpers package plugin authors already know) — canonical paths stay src.adaptive_layout / src.adaptive_images so nothing breaks. Document it in src/common/README.md and cross-link ADAPTIVE_LAYOUT.md from the developer docs authors actually read (quick reference, API reference, advanced dev, font manager, dev preview, plugin dev guide); ADAPTIVE_LAYOUT.md gains adaptive-images, composite-layouts and preserving-user-customization sections. Compat: PluginLoader now logs one advisory warning (never raises) when a plugin's manifest declares a min LEDMatrix version newer than the running core, checking the min_ledmatrix_version / requires.* / versions[] spellings found in the wild. Guarded against stale core version numbers. src/__init__.py __version__ bumped 1.0.0 -> 3.1.0 to match the latest release tag (v3.1.0) — it had never been updated and the compat check needs a truthful number. NOTE: verify this matches the intended release numbering before the next tag. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(layout): add measure_font_crispness — verify a ladder rung isn't blurry PIL antialiases TTF outlines by default; a 'pixel-style' font only rasterizes without antialiasing at specific sizes (for PressStart2P: exact multiples of its 8px design grid). A ladder rung at an unverified size silently renders blurry on an LED panel — this exact bug shipped in both text-display's and football-scoreboard's custom TTF ladders (non-8-multiple PressStart2P sizes, and '5by7.regular'/'4x6-font' at sizes that were never actually crisp). measure_font_crispness(font, sample_text) renders the sample and reports the fraction of ink-bbox pixels that are neither pure black nor pure white. BDF fonts (real bitmaps) always score 0.0; TTF ladders should be verified against this before shipping — see the new TestFontFitting::test_ladder_arcade_is_crisp pattern. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(layout): add fit_text_proportional — proportional sizing vs. always-maximize fit_text always picks the largest ladder rung that fits its box. That's right when an element owns dedicated space, but wrong when several independently-fitted elements need to stay visually harmonious as the panel grows: a score's box might have generous room while a neighboring logo scales by a fixed geometry factor via px() — fit_text lets the score balloon out of proportion (even overlapping the logo) even though its individual pick is technically correct. fit_text_proportional(text, box, base_size_px, ladder) instead targets base_size_px * self.scale (the same scale factor px() already uses), picking the nearest ladder rung at or below that target, still capped to what fits the box, floored at the smallest rung when the target is below every rung. Refactored the shared largest-that-fits/ellipsize walk into _walk_ladder() so fit_text and fit_text_proportional don't duplicate it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(layout): fit_text_proportional gains an axis-specific scale override self.scale (min(width_ratio, height_ratio)) is the right conservative default for anything whose aspect ratio matters, but a caller whose surrounding composition already scales along a single axis — e.g. football-scoreboard's logo_slot = min(height, width // 2), which tracks height alone — needs text sized the same way, or it reads as under-scaled next to logos that grew on a panel that only got taller (128x32 -> 128x64: self.scale stays 1.0 since width didn't grow, but logos still double). fit_text_proportional(..., scale=None) now accepts an explicit override; None keeps the existing self.scale default. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(layout): scoreboard_regions reserves real center space at 2:1 aspect ratios logo_slot = min(height, width // 2) has a blind spot: at exactly 2:1 aspect ratio (width == 2 * height -- a very common shape: two, four, or more square modules stacked into a taller panel) width // 2 and height are equal, so the two logo slots claim the ENTIRE width and leave zero pixels for a center column, no matter how large the panel gets. Not a 'small panel' problem -- 96x48, 128x64, and 256x128 (all exactly 2:1) hit it identically, while the 128x32 design baseline and panels like 192x48 or 256x32 never do, because height is already the tighter constraint there. Two new parameters fix it in the one shared helper every scoreboard-style plugin composes through: - min_center_fraction / min_center_design_px reserve at least max(width * fraction, design_px * ctx.scale) for the center column, capping logo_slot further when needed. The scaled design-px term matters on small panels where a flat fraction alone reserves too little absolute space. - score_bleed_fraction extends the score's own fit box (not the logo slots themselves) a controlled amount into each side -- the same way real broadcast scoreboards let a big score number's edges cross into the team marks flanking it. Without this the reserve alone can still be too narrow for a short score to render without truncating. score_area is now genuinely narrower than the full card width (previously identical to status_band/detail_band, which still span the full width and overlay the logos -- short text there was never the problem). Verified against the full harness size spread: a real game score like '17-21' never needs ellipsis at any tested 2:1-or-tighter aspect ratio (test_score_never_needs_ellipsis_for_a_short_score), and wide panels (128x32/192x48/256x32-style) are provably unaffected. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: document scoreboard_regions' center-reserve and score-bleed params Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: address CodeRabbit review on PR #393 - docs: scope the self.layout note to BasePlugin subclasses (others build a LayoutContext directly) and make explicit that adaptive layout is opt-in — classic rendering stays unless a plugin adopts the APIs. - dev_server: broaden the render-request catch (a bad manifest.json now returns a clean 400 instead of an unhandled 500) and stop echoing raw exception text in the loader-failure responses — full tracebacks go to the dev server's console log instead. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam * fix(dev-server): allowlist plugin_id before any path lookup CodeQL (py/path-injection): plugin_id arrives in request input and flows into filesystem paths via find_plugin_dir. Gate it with the same ^[a-zA-Z0-9_-]{1,64}$ allowlist the web UI's pages_v3 uses, at the single choke point every route resolves through. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam * fix(dev-server): lexical containment check on resolved plugin dirs CodeQL doesn't recognize the interprocedural allowlist as a path-injection barrier; add the canonical one — normalize (without following symlinks, since dev plugins are commonly symlinked into plugins/) and require the result to stay inside the search dir. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam * fix(dev-server): inline normpath containment barrier before render CodeQL doesn't credit the sanitization inside find_plugin_dir along this flow; apply its documented barrier (normpath + startswith against the allowed roots) inline in _parse_render_request, on the exact path that reaches the render/load sinks. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam * fix(dev-server): derive plugin dir from trusted directory listings CodeQL's barrier-guard recognition doesn't see a startswith check inside an any() comprehension, so the normalize-and-prefix approach still flagged. Break the taint outright instead: after lookup, re-derive the directory by enumerating the search dirs (iterdir) and matching by path equality — the Path used for all downstream file access is built solely from trusted listings, never from request input. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam * fix(dev-server): use os.scandir for path-injection barrier, redact stack traces from render responses CodeQL doesn't model Path.iterdir() as a taint-clearing enumeration the way it does os.scandir() -- _trusted_plugin_dir's iterdir-based rebuild still traced plugin_id through to the manifest.json open(). Switched to scandir, matching the pattern already verified clean on PR #396. Also stops surfacing raw exception text (update()/display() failures) in the JSON render response -- logs full detail server-side via exc_info instead, returning only the exception class name to the client. And drops path values from three plugin_loader debug/error logs that CodeQL flags as clear-text-logging of externally-influenced data, keeping plugin_id (not flagged) for context. * fix(dev-server): remove conditional-reassignment ambiguity in plugin_dir resolution CodeQL's path-injection flow still traced through _parse_render_request after the scandir fix -- the tainted find_plugin_dir() result and the scandir-derived _trusted_plugin_dir() result shared the same variable name (plugin_dir), reassigned only on the truthy branch. That merge point apparently isn't treated as a barrier by the flow analysis, so it kept tracing the pre-reassignment value through to the manifest open(). Split into two distinct names -- candidate_dir (tainted, used only to call _trusted_plugin_dir) and trusted_dir (the only name used for any downstream file access) -- so there's no reassigned variable for the flow to walk through. * fix: remove unused imports flagged by Codacy Union in adaptive_images.py and field in adaptive_layout.py are both imported but never used -- the last two Codacy findings on this PR, matching the same fix already applied on PR #396. * fix(layout): bound the fit cache; never alias the source image in fits Two latent issues found in a self-review pass: - LayoutContext._fit_cache was an unbounded dict (the image cache got an LRU cap, the text-fit cache didn't). Cache keys embed the fitted TEXT, so a plugin fitting changing strings — a live game clock, a ticker — on a 24/7 service grows it forever. Now LRU-bounded at 512 entries via the same pattern as the image cache. - fit_image returned the caller's ORIGINAL image object when the source was already RGBA at target size (contain/fill_height, no ink crop). ImageFitResult is documented as an independent copy, and LayoutContext caches results — an aliased image lets later mutations of the source corrupt cached fits (or vice versa). Copy in that branch. Both covered by new regression tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam --------- Co-authored-by: Chuck <chuck@example.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
148 lines
6.3 KiB
Python
148 lines
6.3 KiB
Python
"""
|
|
Bounds-checking display manager.
|
|
|
|
A VisualTestDisplayManager that draws onto an oversized canvas (the declared
|
|
panel size plus a right/bottom margin) while still reporting the declared size
|
|
to the plugin. Content that a plugin draws past the right or bottom edge lands
|
|
in the margin instead of being silently clipped by PIL, so the harness can
|
|
detect overflow — the classic symptom of hardcoded coordinates or fonts/icons
|
|
that don't scale down to a smaller panel.
|
|
|
|
Limitations (documented on purpose):
|
|
- Overflow past the LEFT or TOP edge (negative coordinates) is still clipped by
|
|
PIL and not detected pixel-wise here. The dominant real-world breakage is
|
|
content that is too wide/tall for a smaller panel, which this catches.
|
|
As a partial net, draw_text/draw_image calls made with negative coordinates
|
|
through this manager are recorded in `negative_coordinate_calls` — but draws
|
|
made directly on the raw PIL canvas remain uncovered.
|
|
- BDF text is clipped to the declared bounds by the parent's bitmap drawer, so
|
|
BDF overflow is not flagged. Golden-image regression covers those plugins.
|
|
- If a plugin replaces the canvas with its own image (display_manager.image = ...),
|
|
the margin can't be measured and overflow is reported as undetermined (None).
|
|
"""
|
|
|
|
from typing import Optional, Tuple
|
|
|
|
from .sizes import DEFAULT_TEST_SIZES
|
|
from .visual_display_manager import VisualTestDisplayManager, _MatrixProxy
|
|
|
|
# Smallest extra band kept on the right/bottom so a few pixels of overflow are
|
|
# still visible even on the largest panel in a run.
|
|
_BASE_MARGIN = 16
|
|
# Fallback overflow reference when a caller doesn't pass one: the largest shape
|
|
# in the default sample. We extend every (smaller) canvas out to at least this
|
|
# size so content drawn at a coordinate meant for a bigger build — e.g. x=200 on
|
|
# a 64-wide panel — lands in the padded region and is flagged, instead of being
|
|
# clipped off-canvas and read as a false pass.
|
|
_DEFAULT_EXTENT_WIDTH = max(w for w, _ in DEFAULT_TEST_SIZES)
|
|
_DEFAULT_EXTENT_HEIGHT = max(h for _, h in DEFAULT_TEST_SIZES)
|
|
|
|
|
|
class BoundsCheckingDisplayManager(VisualTestDisplayManager):
|
|
"""Detects drawing that overflows the declared panel size."""
|
|
|
|
# Kept for backwards compatibility; real padding is computed per-axis below.
|
|
MARGIN = _BASE_MARGIN
|
|
|
|
def __init__(self, width: int = 128, height: int = 32,
|
|
overflow_extent: Optional[Tuple[int, int]] = None):
|
|
self._declared_width = int(width)
|
|
self._declared_height = int(height)
|
|
# Pad the canvas out to at least `overflow_extent` (the largest panel
|
|
# this run cares about) plus a base margin, so coordinates meant for a
|
|
# bigger build are caught — not clipped — when rendering a smaller panel.
|
|
# Defaults to the largest shape in the sample when no run is known.
|
|
ext_w, ext_h = overflow_extent or (_DEFAULT_EXTENT_WIDTH, _DEFAULT_EXTENT_HEIGHT)
|
|
self._canvas_width = max(self._declared_width, int(ext_w)) + _BASE_MARGIN
|
|
self._canvas_height = max(self._declared_height, int(ext_h)) + _BASE_MARGIN
|
|
# Parent builds the (oversized) backing canvas + fonts.
|
|
super().__init__(self._canvas_width, self._canvas_height)
|
|
# Plugins must see the DECLARED size, not the padded canvas size.
|
|
self.matrix = _MatrixProxy(self._declared_width, self._declared_height)
|
|
# (text-or-'image', x, y) for every mediated draw call given a
|
|
# negative coordinate — PIL clips these silently, so record them.
|
|
self.negative_coordinate_calls: list = []
|
|
|
|
# -- negative-coordinate (left/top overflow) recording --
|
|
|
|
def draw_text(self, text, x=None, y=None, *args, **kwargs):
|
|
if (x is not None and x < 0) or (y is not None and y < 0):
|
|
self.negative_coordinate_calls.append((text, x, y))
|
|
return super().draw_text(text, x, y, *args, **kwargs)
|
|
|
|
def draw_image(self, image, x, y, *args, **kwargs):
|
|
if x < 0 or y < 0:
|
|
self.negative_coordinate_calls.append(('image', x, y))
|
|
return super().draw_image(image, x, y, *args, **kwargs)
|
|
|
|
# -- declared dimensions (override parent's image-derived properties) --
|
|
|
|
@property
|
|
def width(self) -> int:
|
|
return self._declared_width
|
|
|
|
@property
|
|
def height(self) -> int:
|
|
return self._declared_height
|
|
|
|
@property
|
|
def display_width(self) -> int:
|
|
return self._declared_width
|
|
|
|
@property
|
|
def display_height(self) -> int:
|
|
return self._declared_height
|
|
|
|
# -- overflow detection --
|
|
|
|
def _canvas_is_padded(self) -> bool:
|
|
return self.image.size == (self._canvas_width, self._canvas_height)
|
|
|
|
def check_overflow(self) -> Optional[Tuple[int, int, int, int]]:
|
|
"""Bounding box (in full-canvas coords) of any drawing beyond the
|
|
declared panel, or None if nothing overflowed / undetermined."""
|
|
if not self._canvas_is_padded():
|
|
return None
|
|
|
|
exp_w = self._canvas_width
|
|
exp_h = self._canvas_height
|
|
boxes = []
|
|
|
|
right = self.image.crop((self._declared_width, 0, exp_w, exp_h)).getbbox()
|
|
if right:
|
|
boxes.append((right[0] + self._declared_width, right[1],
|
|
right[2] + self._declared_width, right[3]))
|
|
|
|
bottom = self.image.crop((0, self._declared_height, exp_w, exp_h)).getbbox()
|
|
if bottom:
|
|
boxes.append((bottom[0], bottom[1] + self._declared_height,
|
|
bottom[2], bottom[3] + self._declared_height))
|
|
|
|
if not boxes:
|
|
return None
|
|
return (
|
|
min(b[0] for b in boxes), min(b[1] for b in boxes),
|
|
max(b[2] for b in boxes), max(b[3] for b in boxes),
|
|
)
|
|
|
|
# -- snapshot/image accessors return the cropped, true-panel image --
|
|
|
|
def declared_image(self):
|
|
"""The visible panel: the canvas cropped to the declared size."""
|
|
if self._canvas_is_padded():
|
|
return self.image.crop((0, 0, self._declared_width, self._declared_height))
|
|
return self.image
|
|
|
|
def save_snapshot(self, path: str) -> None:
|
|
self.declared_image().save(path, format='PNG')
|
|
|
|
def get_image(self):
|
|
return self.declared_image()
|
|
|
|
def get_image_base64(self) -> str:
|
|
import base64
|
|
import io
|
|
buffer = io.BytesIO()
|
|
self.declared_image().save(buffer, format='PNG')
|
|
return base64.b64encode(buffer.getvalue()).decode('utf-8')
|