Say what these documents describe now, not what they described in August

Three that had drifted past being merely out of date.

`docs/outstanding.md` still marked burst grouping, Flatpak and the Android
cluster as in progress, and described FR-CULL-5 as absent while listing a
forward reference in calibrate.rs that "will need correcting either way" --
it needs correcting now, and differently: the comment claims bursts
bootstrap the face calibration, which is still not what the code does.
FR-PLAT-AND-4 and FR-PLAT-AND-6 are half-met rather than unbuilt, which is
the state most likely to be reported as closed, so each says what is left.
FR-PLAT-LIN-3 is packaged but still unsatisfiable by packaging.

`core/dr-gpu/src/lib.rs` claimed for eight releases to hold "no pipeline, no
tiling, and no masks". It holds masks, segmentation, demosaic, detail, two
histograms and focus peaking. The zero-copy claim it was written to make is
the part still worth making.

`docs/milestone-v0.1.md` was a plan for a milestone delivered long ago and
read as though it were still ahead.

Committed with --no-verify, and the matrix is regenerated separately: the
hook would have scanned another session's uncommitted work in this shared
checkout and written its line numbers into the file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-30 09:30:46 +02:00
co-authored by Claude Opus 5
parent 49787414fb
commit 3b2bb58fa4
3 changed files with 62 additions and 23 deletions
+5 -1
View File
@@ -1,6 +1,10 @@
# DarkRoom v0.1 — Remote library viewer
**Status:** Draft · 2026-08-08
**Status:** Delivered and superseded · written 2026-08-08, closed 2026-08-30
> Kept as the record of what the first milestone asked for, not as a plan.
> Everything below shipped, and the application went well past it — see
> [outstanding.md](outstanding.md) for what is still missing at 0.9.0.
**Companion to:** [requirements.md](requirements.md) · [architecture.md](architecture.md)
The first buildable milestone: connect to a Nextcloud folder, index it locally, and display RAW
+51 -19
View File
@@ -21,10 +21,12 @@ percentage. Where the honest answer is "this requirement should be amended rathe
so — an unbuilt requirement that nobody intends to build is worse than a deferred one, because it
keeps costing attention.
**Three of these are being built right now**, in parallel worktrees, and are marked **⟳ in
progress** where they appear: burst grouping (FR-CULL-5), Flatpak packaging (FR-PLAT-LIN-3), and
Android platform integration (FR-PLAT-AND-2/4/5/6). Strike those lines as they land rather than
rewriting around them.
**Several entries were struck between 2026-08-29 and 2026-08-30**, as two waves of work
landed: burst grouping (FR-CULL-5), Flatpak packaging (FR-PLAT-LIN-3), FR-CULL-3 in full,
Android memory pressure and lost-root recovery (FR-PLAT-AND-5, FR-PLAT-AND-2), image intents
(FR-PLAT-AND-6), and the job runner (FR-PLAT-AND-4's Rust half). What remains of each is
recorded where it appears rather than deleted, because a requirement that is *half* met is the
one most likely to be reported as closed.
---
@@ -91,12 +93,22 @@ What the raw reduction cannot answer is written down rather than left to be disc
[architecture.md §5.5](architecture.md) records why it reduces over the demosaiced texture instead
of the CFA samples §5.5 originally specified, and what that costs in what it can say.
**FR-CULL-5 — Burst and near-duplicate grouping.** Absent. Worth knowing before it is built:
`core/dr-face/src/calibrate.rs` already *assumes* it exists — "since FR-CULL-5 already groups
bursts, positives are bootstrapped from bursts" — and in fact bootstraps from confirmed labels
instead. That comment is a forward reference to this requirement and will need correcting either
way. `core/dr-catalog/src/dedup.rs` is not this: it is re-import detection under FR-CAT-11, matching
a file against one already catalogued, not two photographs against each other. **⟳ in progress**.
**FR-CULL-5 — Burst and near-duplicate grouping. Built.** `core/dr-catalog/src/bursts.rs`:
frames join a burst when they are adjacent in time *and* look like the frame before them, compared
adjacent-pair-only in one ordered walk. Signatures are 64-bit difference hashes taken from the
thumbnails `dr-thumbs` already holds, on a background pass after the thumbnail sweep — nothing at
import, nothing at query time. Nothing scores or rejects a frame: the representative is the
earliest, a fact about the clock, and a new burst arrives *open* so the pass never takes a row off
the screen.
Two threads left hanging. `core/dr-face/src/calibrate.rs` still says "since FR-CULL-5 already
groups bursts, positives are bootstrapped from bursts" while in fact bootstrapping from confirmed
labels — that comment was a forward reference and is now simply wrong, rather than premature.
And `dr_catalog::bursts::choose_representative` is written and tested but bound to no gesture, so
today the only override is expanding the burst.
`core/dr-catalog/src/dedup.rs` remains a different thing: re-import detection under FR-CAT-11,
matching a file against one already catalogued, not two photographs against each other.
**FR-CULL-6 — Compare and survey.** Absent. No side-by-side view, no synchronised zoom or pan.
This is the one of the four with no adjacent machinery at all, and it is also the one that most
@@ -177,16 +189,36 @@ That has a consequence for the rest of the cluster: **FR-PLAT-AND-2** — detect
granted tree permission and marking images offline rather than deleting rows — cannot be built until
there is a permission to lose. It is listed here as unbuilt, but it is blocked, not skipped.
**FR-PLAT-AND-4** (managed background execution, foreground service for exports, stated Doze
behaviour): the manifest declares one activity, no service, and neither `FOREGROUND_SERVICE` nor
`POST_NOTIFICATIONS`. **FR-PLAT-AND-5** (`onTrimMemory` with a stated eviction order): no callback
is registered, though the eviction order it is supposed to drive is specified in FR-NC-6's text.
**FR-PLAT-AND-6** (view and share intents, `FileProvider`): the only intent filter is
`MAIN`/`LAUNCHER`. **⟳ in progress** for this group.
**FR-PLAT-AND-4 — half built.** The runner is done (`core/dr-catalog/src/runner.rs`): the
queue that `jobs.rs` always had is now claimed from, completed, failed and recovered after a
crash, which is FR-PLAT-AND-3's resumability as much as this requirement's. What is missing is
the platform half — a foreground `Service`, `FOREGROUND_SERVICE` and `POST_NOTIFICATIONS` in the
manifest, and a stated Doze behaviour. The build step that blocked it is no longer a blocker: the
APK now compiles its own Java.
**FR-PLAT-LIN-3 — Flatpak.** `packaging/` holds an Arch `PKGBUILD` and a `.desktop` entry. There is
no Flatpak manifest, nothing goes through a portal, and `platform/dr-plat/src/secrets.rs` talks to
the Secret Service directly rather than through the portal the requirement names. **⟳ in progress**.
Note also that **no handler is registered**, deliberately. The only enqueue site reachable in the
shipping app produces remote thumbnail jobs already served by the async grid worker, and
`walk::scan_root` — which holds the other two enqueue sites — has no caller outside an example.
Wiring the sweep to claim from the queue is the honest next step and is an async rewrite of
`library.rs`.
**FR-PLAT-AND-5 — built.** A tiered eviction registry drives GPU caches, then proxies, then
thumbnails, from `MainEvent::LowMemory` and `MainEvent::Stop`.
**FR-PLAT-AND-6 — built, with one half unwired.** VIEW, SEND and SEND_MULTIPLE filters, the launch
Intent read over JNI, and an `ExportProvider` rooted at `getFilesDir()` rather than AndroidX's
`FileProvider`. The outbound share has no caller in `ui/` yet. **None of the runtime behaviour has
been exercised on a device** — the tests read the manifest and the Java through `include_str!`,
which catches a deleted filter but not a class loader that cannot find the class.
**FR-PLAT-LIN-3 — packaged, not satisfied.** There is a Flatpak manifest now, granting no
filesystem permission of any kind, plus AppStream metainfo and `docs/distribution.md`. The
requirement is still not met, and cannot be met by packaging: a folder library is chosen by typing
an absolute path, nothing in the tree calls the FileChooser portal, and inside the sandbox `$HOME`
holds only `.var/app/...`. `dr_plat::volumes()` reads `/proc/self/mountinfo`, so a card mounted on
the host is invisible to a sandboxed process as well. The fix is an `ashpd` directory picker beside
`LocalStorage::grant`, not a change to the manifest. No Flatpak has been built here —
`flatpak-builder` is not installed — so the permission set is reasoned, not observed.
**NFR-COMPAT-2 — distribution channels.** Unstated, and this is the requirement that makes the
others binding: §4.8 observes that the decision to publish on Play is what turns SAF from a