Official integration guide · 한국어 · Build a DDS plugin · Releases
The actual source of Digital Design Studio's optional KLayout 0.30.12 viewer integration, released under Apache-2.0. It installs a pinned official external viewer in DDS-owned user storage and opens a saved GDSII/OASIS file through a native picker. It does not qualify a layout producer, DRC/LVS flow or engine tool.
This is integration source, with a standalone package audit harness. KLayout itself is a separate GPL-3.0-or-later application. Its source and notices are available independently; this Git repository distributes no executable or icon.
The 11 files in source-inventory.json are byte-for-byte exports from the recorded DDS source commit:
src-tauri/src/native_klayout.rs: actual Tauri commands, workspace/window/session authorization, install reservations, cancellation, staging, status and launch.src-tauri/src/native_klayout_package.rs: actual fixed descriptor selection, bounded download, SHA-256 validation and Windows ZIP extraction/audit, including its five original Rust tests.src-tauri/src/native_klayout_linux.py: actual Ubuntu/WSL helper, Debian archive validation, user storage, dependency/version/display checks and fixed launch.scripts/klayout-linux-package.test.py: four original synthetic package tests.- The pinned descriptor, five KLayout-specific Tauri permission definitions and the TypeScript host/state wire contract, preserved at their DDS-relative paths.
src/lib.rs compiles the same unmodified package module using #[path].
It exposes archive verification, pinned download and Windows payload audit and
extraction for other native hosts. src/main.rs is a read-only audit CLI.
The standalone dependency lock contains only public crates and does not include
DDS host dependencies. The full Tauri adapter remains an integration module;
compiling that adapter requires the host interfaces described below.
Install Rust 1.91.1 with Cargo. Windows also needs the MSVC C/C++ build tools and CMake for the Rust TLS dependency; Linux needs a C/C++ toolchain and CMake. Python fixture tests require POSIX ownership and symlink semantics; use Python 3.12 on Linux or WSL. Nothing below installs or runs KLayout.
cargo test --locked
cargo run --locked -- descriptor
python scripts/verify-source.py
python scripts/klayout-linux-package.test.pyThe original Rust tests cover traversal/Windows aliases, integrity of changed, missing and added files, cancellation and stalled network futures. The Python tests cover Debian archive hashes, file/link inventory, path/link escapes and user-directory symlinks. CI uses public GitHub-hosted Ubuntu and Windows runners, commit-pinned actions and the checked-in Cargo lock.
To compare the published integration bytes to a DDS checkout:
python scripts/verify-source.py --dds-root /path/to/ddsTo audit an existing official archive without extracting or executing it:
cargo run --locked -- verify-archive windows-x86_64 /path/to/klayout-0.30.12-win64.zip
cargo run --locked -- verify-archive ubuntu24-x86_64 /path/to/klayout_0.30.12-1_amd64.deb
cargo run --locked -- verify-windows-payload /path/to/archive.zip /path/to/payloadUse the Rust library's pinned archive/payload functions when adapting package
management. They operate on explicit caller-owned paths and an AtomicBool
cancellation flag. The Python helper implements the existing inspect, stage,
commit, discard, uninstall and open protocol. Its command-line arguments are
action, opaque UUID ticket, saved layout path (only for open) and the exact
JSON descriptor; stage reads exactly the pinned archive bytes from stdin.
It prints one bounded JSON status and returns a nonzero exit on a JSON error.
Run it with isolated Python (python3 -I) and a fixed command, as the adapter does.
The original Tauri module assumes these host-owned interfaces:
native_console::WorkspaceLease: a retained workspace authority guard,environment()and, on Windows, selectedwsl()workspace information.native_console::Environment::OnPremisesandrequest_session(request): native environment and authenticated renderer session identity.desktop_runtime_security::sanitize_child_environment(command): child-process environment sanitization that must preserve the explicit fixed launch settings.- On Windows,
desktop_wsl_backend::transport: trusted system WSL command lookup,WslProject::newdistribution validation andWslProject::from_uncpath mapping. - Tauri application-local storage, dialog plugin, main window and native async runtime. Register the five commands and permit their matching exported permission identifiers only on the intended window. Use the exported TypeScript wire contract.
These interfaces are responsibilities of the embedding host. Their DDS implementations and the UI/catalog/application are outside this source export. Do not remove the authorization, session binding, distribution validation or environment sanitization when connecting the module to another host.
DDS uses Windows x64 app-local storage, or unprivileged Ubuntu 24.04 x64 storage
in the native-selected WSL distribution/Linux user account. Ubuntu dependencies
are recorded individually in the descriptor and must already be installed.
Cloud, other Linux releases and other architectures are unsupported. Linux GUI
launch requires a display or WSLg. Saved-layout launch uses fixed -nc -rx -ne
arguments; renderer-provided scripts, commands and environment are not accepted.
upstream-source.json records KLayout's immutable
v0.30.12 commit e71272c3b178105bd2a2f25af54673a7af7ed60d, the official
corresponding source URL, exact measured 104,078,293-byte size and SHA-256.
Retrieve the unchanged source into ignored dist/upstream/ with:
python scripts/fetch-upstream-source.pyThe same verified archive can be attached to this integration's source release
as klayout-0.30.12.tar.gz. Its SHA-256 is
fa747d9a4c216d0645587e05df365d5c22f73609ab98b34471372c711d8c2b75.
This archive contains KLayout's build scripts and original dependency notices.
For the upstream application build, use its included README.md, build.sh or
build.bat and official build instructions.
Its Windows build uses Qt, Ruby, Python, zlib, expat, curl and pthread-win; Linux
uses Qt with optional Ruby/Python support. Building that upstream application is
separate from building this integration harness.
Original GPL/MIT notices are retained under licenses/source/ and the
commit-specific upstream GPL/COPYRIGHT files under licenses/.
NOTICE specifies the selected DDS-original Apache-2.0 grant.
The descriptor's original Windows and Ubuntu download URLs, SHA-256 and sizes
remain unchanged. Windows notice inventory
records the ZIP directory, DLL names and 66 filename-selected notice entries
obtained by bounded HTTPS ranges and validated with ZIP entry CRCs; this audit
does not verify the full Windows ZIP SHA-256. Some selected entries are
upstream license templates; selection by filename is not a declaration
that every bundled DLL has a complete notice/source set. The
Ubuntu package audit records the complete verified
archive hash, actual control/dependency fields and packaged copyright notice.
Neither audit installs or executes the application. These inventories document
their method and limits and do not replace upstream distributors' obligations.
Local synthetic checks establish integration package behavior and exported source equality. They do not establish a clean-machine installation, installed GUI acceptance, an upstream application build or DDS host/UI acceptance.