# Patched upstream crates Each directory here is a crate exactly as crates.io publishes it, at the version `Cargo.lock` resolves, with a local patch on top. The root `Cargo.toml` routes the dependency here through `[patch.crates-io]`; the directory is excluded from the workspace, so `cargo test --workspace`, clippy and fmt leave it alone. The first commit that adds a directory is the pristine copy (from `~/.cargo/registry/src/*/-`, minus `.cargo-ok` and the crate's own `Cargo.lock`). Every later commit touching it is ours, so `git log -p -- third_party/` is the patch and nothing else. Each directory keeps the crate's own licence files, and the crate keeps its licence: wgpu-hal is MIT or Apache-2.0, i-slint-renderer-skia is Slint's GPL-3.0-only or royalty-free or commercial choice, and rawler is LGPL-2.1. ## Carrying a patch forward When Slint, wgpu or rawler is bumped, the version here stops matching and cargo warns that the patch is unused — the build then silently goes back to the unpatched crate. So a bump is: 1. Copy the new version in beside the old one, as its own commit. 2. Re-apply the diff from `git log -p` on the old directory. 3. Point `[patch.crates-io]` at the new directory and delete the old one. 4. Re-check what the patch was for. The wgpu-hal and Skia patches are behaviour that only a rotated Android display exercises (below); the rawler one is a linear DNG wider than 16 700 pixels, such as a panorama the merge writes. Drop a patch entirely once upstream has the fix; each section says what upstream change would make it unnecessary. ## wgpu-hal 29.0.4 — Vulkan pre-rotation on Android Upstream creates every Vulkan swapchain with `preTransform = IDENTITY` (`src/vulkan/swapchain/native.rs`, gfx-rs/wgpu#3345). On Android, a window whose orientation differs from the panel's is then rotated by the compositor on the GPU (`composition=CLIENT`), and on this tablet in portrait those frames tear. The patch adds two methods to `wgpu_hal::vulkan::Surface`: - `current_transform(&Adapter)` — the surface's `currentTransform`. - `set_pre_transform(transform)` — the `preTransform` for the next swapchain. Opt-in: nothing calls it but the Skia patch below, and the default is still `IDENTITY`, so desktop and every other caller behave exactly as upstream. Setting it is a promise that the caller draws rotated into a swapchain sized in the panel's orientation; wgpu itself rotates nothing. Unnecessary once wgpu exposes pre-rotation itself (#3345). ## i-slint-renderer-skia 1.17.1 — rotate the canvas to match `wgpu_29_surface.rs` keeps the promise the wgpu-hal patch lets it make. On Android it reads the surface's transform whenever it configures, sizes the swapchain in the panel's orientation (width and height swapped for a quarter turn), calls `set_pre_transform`, and concatenates the matching rotation onto the Skia canvas before Slint draws — so the whole UI, including an imported `wgpu::Texture`, is drawn pre-rotated. It checks the transform before every frame too, because a half turn (landscape to reverse landscape) changes it without resizing the window. Touch input is untouched: only drawing is rotated. `itemrenderer.rs` widens the pixel-alignment check from "pure translation" to "any right-angle rotation or flip without scaling". Without that, a rotated canvas silently loses pixel snapping everywhere. Off Android every path is upstream's: the rotation is always `None`. Unnecessary once Slint's Skia wgpu surface pre-rotates on its own — worth offering upstream, since the linuxkms backend already renders through the same rotate-and-translate in `render_to_canvas`. ## rawler 0.7.2 — the allocation guard counts samples, not pixels `alloc_image_plain!` and `alloc_image_f32_plain!` (`src/pixarray.rs`) panic on a buffer over 500 M elements or 50 000 along either axis. The width they are handed is `width × samples per pixel`. A linear DNG therefore hits the guard at about 16 700 pixels wide, and the 22927 × 8966 panorama Lightroom writes is refused as ">50000 px wide". The patch raises the guard to 1.5 G samples and 200 000 per axis. It is still a guard against a corrupt header, just no longer one that a real photograph trips. The copy leaves out `data/testdata`, 13 MB of sample files that only the crate's own tests read. Unnecessary once upstream sizes the guard in pixels, or drops it.