git.lucas.co / cce-ui
GPU-accelerated UI toolkit (Vulkan)
git clone https://git.lucas.co/cce-ui.git

commit60f62b257c6b1038e5cc30ce877f0f92475ce2c4
parent1b417ae7eb
authorLucas Galante <lsgalante12@gmail.com>
date2026-09-25 15:58
refactor(vk): remove the panicking VkRenderer::new; try_new is the constructor

`new` was try_new(..).unwrap_or_else(panic!) -- the variant that takes a
client down when its compositor goes away at logout. Its last callers
(cce-cloud, cce-lock, designer's vk-smoke) have moved to try_new, so
remove it rather than leave a new client able to pick it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

 CLAUDE.md          | 13 +++++++------
 src/vk/renderer.rs | 19 +------------------
 2 files changed, 8 insertions(+), 24 deletions(-)

diff --git a/CLAUDE.md b/CLAUDE.md
index b2ea686..bcba40a 100644
--- a/CLAUDE.md
+++ b/CLAUDE.md
@@ -109,12 +109,13 @@ so `vkGetPhysicalDeviceSurfaceFormatsKHR` is the first call to find out, with
 the compositor is still there, a clean exit if it is not. Mid-session, a swapchain
 rebuild, acquire or present that reports the surface lost latches `surface_lost()` and
 skips draws (one WARN) until the event loop sees the dead connection itself; the menu
-popup just closes. `VkRenderer::new` is the panicking wrapper, kept for tools that own
-their window outright (designer's `vk-smoke`) — **a client that can outlive its
-compositor calls `try_new`**. Found as cce-cloud's daemon panicking at logout on
-`No surface formats`: it had outlived a compositor and asked for a window over its
-connection. Reproduced by opening a `wl_surface`, killing the shadow compositor, then
-constructing: `new` panics, `try_new` returns the error.
+popup just closes. `try_new` is the ONLY constructor: the panicking `new` was removed
+once its last callers (cce-cloud, cce-lock, designer's `vk-smoke`) had moved over, so a
+new client cannot pick the one that takes the process down at logout. Found as
+cce-cloud's daemon panicking at logout on `No surface formats`: it had outlived a
+compositor and asked for a window over its connection. Reproduced by opening a
+`wl_surface`, killing the shadow compositor, then constructing: `try_new` returns the
+error where the old `new` panicked.
 
 ### `renderer_init` — GPU handles do not survive a reconnect
 
diff --git a/src/vk/renderer.rs b/src/vk/renderer.rs
index 219375a..d8fd773 100644
--- a/src/vk/renderer.rs
+++ b/src/vk/renderer.rs
@@ -446,23 +446,6 @@ pub(crate) fn flipped_viewport(extent: vk::Extent2D) -> vk::Viewport {
 
 
 impl VkRenderer {
-    /// [`try_new`](Self::try_new) for a caller that owns its window outright
-    /// and has no session to end — a smoke test. Panics on a lost surface;
-    /// a client that can outlive its compositor wants `try_new`.
-    ///
-    /// # Safety
-    /// Same contract as [`try_new`](Self::try_new).
-    pub unsafe fn new(
-        display_ptr: *mut c_void,
-        surface_ptr: *mut c_void,
-        width: u32,
-        height: u32,
-        corner_radius_px: f32,
-    ) -> Self {
-        Self::try_new(display_ptr, surface_ptr, width, height, corner_radius_px)
-            .unwrap_or_else(|e| panic!("{e}"))
-    }
-
     /// A renderer presenting to `surface_ptr`, or [`SurfaceLost`] when the
     /// display connection under it is already dead — which is what a window
     /// requested as the compositor goes away gets. The caller should treat
@@ -1539,7 +1522,7 @@ impl VkRenderer {
     /// renderer costs a device and every pipeline, this costs one swapchain.
     ///
     /// # Safety
-    /// Same contract as [`VkRenderer::new`]: live `wl_display` / `wl_surface`
+    /// Same contract as [`VkRenderer::try_new`]: live `wl_display` / `wl_surface`
     /// pointers that outlive the attachment.
     pub unsafe fn attach_surface(
         &mut self,