Skip to content

fix(layout): hand IntrinsicMeasure both sizes in the content box - #222

Closed
LeadcodeDev wants to merge 1 commit into
fix/em-font-sizefrom
fix/measure-fn-box-model
Closed

LeadcodeDev wants to merge 1 commit into
fix/em-font-sizefrom
fix/measure-fn-box-model

Conversation

@LeadcodeDev

Copy link
Copy Markdown
Owner

Severity Low, category correctness. Location: crates/rustmotion-core/src/engine/layout_pass.rs:97

Impact

taffy 0.10.1 (compute/leaf.rs) subtracts content_box_inset (padding+border) from available_space before calling the measure fn, but passes known_dimensions — the outer border-box size — untouched. The two arguments are therefore in different coordinate spaces, and neither IntrinsicMeasure's trait doc (box_tree.rs:114-122) nor this closure says so. TextIntrinsic::measure (rustmotion-components/src/intrinsic.rs:224) prefers known.0 as its wrap width, while Text::paint wraps at layout.content_box() width (legacy_dispatch.rs:145-155). A text with horizontal padding is therefore measured at a wider line width than it is painted at: fewer wrapped lines, a reserved box one line too short, and the text spills out of its own box. The geometry validator re-measures through the same intrinsic, so it signs the overflow off. intrinsic.rs:258-265 explicitly asserts the opposite ("taffy hands a leaf its own known/available height already padding/border-subtracted") — true for available, false for known.

Fix

Use the _style argument already handed to the closure to subtract resolved padding+border from known before calling intr.measure, so both arguments are content-box. Then state that invariant on IntrinsicMeasure::measure in box_tree.rs, and add a regression test for a padded text (measured height vs painted line count).

Evidence the audit read

|known, available, _node, ctx_data, _style| {
    let Some(ctx) = ctx_data else { return tf::Size::ZERO; };
    let Some(intr) = ctx.intrinsic.as_ref() else { return tf::Size::ZERO; };
    let (w, h) = intr.measure(
        (known.width, known.height),
        (available.width.into(), available.height.into()),
    );

Stacked on fix/em-font-size, which carries the previous finding of this workstream. GitHub shows only this finding's diff; merge in order.

Part of the September 2026 audit remediation chantier. Refs #220 (RM-27).

taffy 0.10.1 (compute/leaf.rs) subtracts content_box_inset (padding+border)
from available_space before calling the measure fn, but passes
known_dimensions — the outer border-box size — untouched. The two arguments
are therefore in different coordinate spaces, and neither IntrinsicMeasure's
trait doc (box_tree.rs:114-122) nor this closure says so.
TextIntrinsic::measure (rustmotion-components/src/intrinsic.rs:224) prefers
known.0 as its wrap width, while Text::paint wraps at layout.content_box()
width (legacy_dispatch.rs:145-155). A text with horizontal padding is
therefore measured at a wider line width than it is painted at: fewer
wrapped lines, a reserved box one line too short, and the text spills out of
its own box. The geometry validator re-measures through the same intrinsic,
so it signs the overflow off. intrinsic.rs:258-265 explicitly asserts the
opposite ("taffy hands a leaf its own known/available height already
padding/border-subtracted") — true for available, false for known.

Fix: Use the _style argument already handed to the closure to subtract
resolved padding+border from known before calling intr.measure, so both
arguments are content-box. Then state that invariant on
IntrinsicMeasure::measure in box_tree.rs, and add a regression test for a
padded text (measured height vs painted line count).

Refs #220
@LeadcodeDev
LeadcodeDev force-pushed the fix/measure-fn-box-model branch from e69bb81 to a3ca2f6 Compare September 22, 2026 08:46
@LeadcodeDev
LeadcodeDev deleted the branch fix/em-font-size September 22, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant