Let one mask be built from more than one selection, and paint into it

A mask the model draws arrives approximately right — stopping inside a
shoulder, leaking into the hair — and FR-DEV-3's edge controls move the
*whole* boundary, so no value of feather or dilation fixes two errors that
go opposite ways. What fixes them is a second selection joined to the first,
and a layer that held exactly one source had nowhere to put one. The brush
the core has had all along was reachable from no control in the application.

A layer is now an ordered list of parts. Each names a source and how it
joins the mask before it — added to it, or taken out of it — and carries its
own edge treatment, because a model's soft coverage and a stroke painted
where it stopped short do not want the same feather. Invert and opacity stay
on the layer, where the composed shader already reads them.

The sidecar grows `[part]` blocks and nothing else. A layer of one part
writes exactly the bytes it always did; a mask block with no part blocks
after it reads back as one part; and a stroke, a join or a source this build
cannot read costs that part rather than the layer. So every sidecar in every
library still parses to the edit it always was.

On the device the parts fold into the layer's one slice, so eight layers
still cost eight channels: union is a `max` blend and subtraction is the
erase blend the brush already used. A part is drawn into a scratch texture
before it is joined, and that is not incidental — an erase stroke means a
hole in *that part*, not a hole in the mask, and drawn straight onto the
accumulator it would punch through the subject underneath. A layer of one
part skips all of it and takes the path it always took.

In the interface: a part list under the selected layer with a chip saying
which way each joins, Add and Subtract beside it, a Select/Paint/Erase strip
with the brush's size, hardness and flow, and a drag on the photograph that
paints. Pressing Paint on a mask that cannot hold a stroke joins a part that
can, rather than explaining that a subject is not a brush. A whole stroke is
one step in the history.

The edge controls now shape the part that is selected rather than the layer,
which is the one behaviour change to an existing control: with a correction
selected, the feather slider softens the correction and leaves the model's
mask alone.
This commit is contained in:
2026-09-07 20:00:40 +02:00
parent 9ede23073d
commit df741a8a49
20 changed files with 2998 additions and 654 deletions
+29 -67
View File
@@ -5,7 +5,7 @@
Every entry here is extracted from the comment beside the code that implements it, so this file cannot describe a gesture the application does not have. Add one by writing a `GESTURE:` block next to the implementation; there is nowhere else to write it.
35 gestures, in 4 places.
31 gestures, in 3 places.
## Develop
@@ -25,7 +25,16 @@ Sampling a neutral is the first move of the tonal pass — every colour judgemen
Anchored on the fingers' midpoint, and on the pointer, so the gesture reads as magnifying the picture rather than sliding it about. Double-tap is the way to an exact 1:1; this is the way to everything in between.
<sub>`ui/dr-ui/ui/app.slint:2064`</sub>
<sub>`ui/dr-ui/ui/app.slint:2018`</sub>
### Paint a mask by hand
- **Touch** — Choose Paint or Erase, then drag on the photograph
- **Pointer** — Choose Paint or Erase, then drag
A model's mask stops inside a shoulder and leaks into the hair, and no single edge control fixes two errors that go opposite ways. The whole stroke is one step in the history, so taking a mark back costs one press however long it took to make.
<sub>`ui/dr-ui/ui/app.slint:2091`</sub>
### Move a magnified photograph about
@@ -34,7 +43,7 @@ Anchored on the fingers' midpoint, and on the pointer, so the gesture reads as m
Only once there is something outside the viewport to reach, which is why the cursor becomes a hand exactly then. The view is clamped to the frame: panning past the edge would show undefined area beside the photograph, and that reads as a rendering fault rather than as the end of the picture.
<sub>`ui/dr-ui/ui/app.slint:2217`</sub>
<sub>`ui/dr-ui/ui/app.slint:2224`</sub>
### Take back the last change
@@ -44,7 +53,7 @@ Only once there is something outside the viewport to reach, which is why the cur
A whole drag is one step, so undo takes back a decision rather than a frame of a gesture. The list is there because arriving six steps back costs what arriving from one does.
<sub>`ui/dr-ui/ui/app.slint:2384`</sub>
<sub>`ui/dr-ui/ui/app.slint:2391`</sub>
### Do it again after taking it back
@@ -52,7 +61,7 @@ A whole drag is one step, so undo takes back a decision rather than a frame of a
- **Pointer** — Click it, or press Redo in the History header
- **Keyboard** — Ctrl+Shift+Z
<sub>`ui/dr-ui/ui/app.slint:2397`</sub>
<sub>`ui/dr-ui/ui/app.slint:2404`</sub>
### Copy the settings from this photograph
@@ -62,7 +71,7 @@ A whole drag is one step, so undo takes back a decision rather than a frame of a
The panel is the copy that has to work: a tablet has no modifier key to hold and no menu bar to hang the action from. The shortcut is an accelerator for a control that is on screen either way.
<sub>`ui/dr-ui/ui/app.slint:2430`</sub>
<sub>`ui/dr-ui/ui/app.slint:2437`</sub>
### Paste the settings onto this photograph
@@ -72,7 +81,7 @@ The panel is the copy that has to work: a tablet has no modifier key to hold and
The button names what would be pasted — "3 adjustments", and whether the crop is coming with it — which the shortcut cannot say. Both paste the same scope.
<sub>`ui/dr-ui/ui/app.slint:2442`</sub>
<sub>`ui/dr-ui/ui/app.slint:2449`</sub>
### Change which group of adjustments is on screen
@@ -82,7 +91,7 @@ The button names what would be pasted — "3 adjustments", and whether the crop
The groups are whatever the operation set declares itself to be about, so there are as many as the pipeline has and no key can be assigned to one of them by name. Stepping is the binding that survives a node being added.
<sub>`ui/dr-ui/ui/app.slint:2470`</sub>
<sub>`ui/dr-ui/ui/app.slint:2477`</sub>
### Look at the photograph at 1:1
@@ -92,7 +101,7 @@ The groups are whatever the operation set declares itself to be about, so there
Noise reduction and capture sharpening are judgements about single pixels, and a fitted view averages several of the file's into each one on screen — so the frame looks softer than it is and the correction goes too far. The point and the magnification survive opening the next photograph, which is what makes checking the same eye across forty portraits forty keystrokes rather than forty pans.
<sub>`ui/dr-ui/ui/app.slint:2505`</sub>
<sub>`ui/dr-ui/ui/app.slint:2512`</sub>
### Move to the next or previous photograph
@@ -102,7 +111,7 @@ Noise reduction and capture sharpening are judgements about single pixels, and a
The edit on screen is saved on the way out, so stepping through a folder is as much a departure as going back to the grid and loses nothing.
<sub>`ui/dr-ui/ui/app.slint:2535`</sub>
<sub>`ui/dr-ui/ui/app.slint:2542`</sub>
### See the photograph before you edited it
@@ -112,7 +121,7 @@ The edit on screen is saved on the way out, so stepping through a folder is as m
Held rather than toggled, and no split screen: a split halves the working image on the tablet the column was sized for, and the comparison photographers describe making is a flick back and forth. It takes no history step, so checking whether a frame is overcooked costs nothing to undo afterwards.
<sub>`ui/dr-ui/ui/app.slint:2659`</sub>
<sub>`ui/dr-ui/ui/app.slint:2666`</sub>
### Put one control back to its default
@@ -130,45 +139,7 @@ The column is 280px wide and the colour mixer alone puts thirty-six of these in
Disabling a layer is the before-and-after a local edit constantly wants, so it is one press away rather than inside the row. It is an edit and does take a history step, unlike holding "Before" — the layer really is off until it is switched back on.
<sub>`ui/dr-ui/ui/masks.slint:163`</sub>
## Collections sidebar
### Pick a collection up to rearrange the tree
- **Touch** — Press and hold it until it lifts, then drag it
- **Pointer** — Drag it, or hold it until it lifts and then drag
The tree is inside a Flickable, which claims any drag beginning inside it — so with a finger a drag on a row is a scroll until something says otherwise. The hold is that something, and it is what every mobile list already uses to pick a row up. The row lifts the moment it fires, so the gesture says it has been understood before anything moves.
<sub>`ui/dr-ui/ui/collections.slint:335`</sub>
### Act on a collection — rename, nest, un-nest, delete
- **Touch** — Press and hold the collection, then let go without moving
- **Pointer** — Right-click it
The hold arms a drag and opens this menu, and which one you get is decided by whether you moved — the same fork the grid uses. One menu for everything done to a row, because there is one hold per row: while the hold opened the offline question by itself, nothing else the tree can do had a touch route.
<sub>`ui/dr-ui/ui/collections.slint:346`</sub>
### Take a collection back out of the one it is nested in
- **Touch** — Hold it, then drag it onto "All photographs" — or let go and choose "Move to top level"
- **Pointer** — Drag it onto "All photographs", or right-click it and choose "Move to top level"
Nesting is a drag of one row onto another, and its inverse had no gesture at all: "All photographs" refused every drop, which is right for a photograph — it is already in the library — and wrong for a collection, which has a top level to be returned to. Without it a collection dragged into another was in there permanently.
<sub>`ui/dr-ui/ui/collections.slint:356`</sub>
### Rename a collection
- **Touch** — Hold the collection, then "Rename"
- **Pointer** — Double-click its name, or right-click it and choose "Rename"
Double-click is what a file manager and a Lightroom panel use for the same thing, so it needs no discovering — but nothing on screen says so, which is what the menu item is for.
<sub>`ui/dr-ui/ui/collections.slint:369`</sub>
<sub>`ui/dr-ui/ui/masks.slint:195`</sub>
## People
@@ -261,7 +232,7 @@ This replaced a double tap, which had no visible state and could take forty phot
"Any of them" is a union and "all of them" is an intersection. The tray is where both terms and the choice between them live, because a filter belongs on the filter bar.
<sub>`ui/dr-ui/ui/library.slint:2102`</sub>
<sub>`ui/dr-ui/ui/library.slint:2096`</sub>
### Resize the thumbnails
@@ -270,7 +241,7 @@ This replaced a double tap, which had no visible state and could take forty phot
There is no wheel on a tablet, so without the pinch the cell size could only be changed by a control a finger cannot reach.
<sub>`ui/dr-ui/ui/library.slint:2755`</sub>
<sub>`ui/dr-ui/ui/library.slint:2749`</sub>
### File photographs in a collection
@@ -279,7 +250,7 @@ There is no wheel on a tablet, so without the pinch the cell size could only be
The selection is what the drag carries, which is why selecting several is worth the mode: forty photographs file in one gesture.
<sub>`ui/dr-ui/ui/library.slint:2952`</sub>
<sub>`ui/dr-ui/ui/library.slint:2946`</sub>
### Open a photograph
@@ -288,7 +259,7 @@ The selection is what the drag carries, which is why selecting several is worth
A tap opens; a tap that *moved* does not. Travel is what separates a deliberate tap from a hand brushing past, and it is the only thing that does: the two are the same length. An earlier version required the finger to dwell 120 ms instead, and that rejected ordinary taps — a real tap is often quicker than a brush.
<sub>`ui/dr-ui/ui/library.slint:3220`</sub>
<sub>`ui/dr-ui/ui/library.slint:3214`</sub>
### Rate a photograph without opening it
@@ -298,7 +269,7 @@ A tap opens; a tap that *moved* does not. Travel is what separates a deliberate
A star has to take the press without it also reaching the cell, or every rating throws the user into develop.
<sub>`ui/dr-ui/ui/library.slint:3340`</sub>
<sub>`ui/dr-ui/ui/library.slint:3334`</sub>
### Choose the frame a folded burst shows
@@ -307,7 +278,7 @@ A star has to take the press without it also reaching the cell, or every rating
A folded burst draws its earliest frame, which is a fact about the clock and not a judgement about the photograph — nothing in this application ranks a frame (FR-CULL-5). But the point of a burst is that one of the twelve is better than the other eleven, and the photographer is the only one who knows which. So the choice is offered on the frames themselves, while they are open and side by side, which is the one moment the alternatives are on screen to be compared.
<sub>`ui/dr-ui/ui/library.slint:3471`</sub>
<sub>`ui/dr-ui/ui/library.slint:3465`</sub>
### Drop the selection but keep selecting
@@ -316,7 +287,7 @@ A folded burst draws its earliest frame, which is a fact about the clock and not
Distinct from Done, which leaves the mode entirely. Clearing keeps it, so the next selection can start straight away.
<sub>`ui/dr-ui/ui/library.slint:4132`</sub>
<sub>`ui/dr-ui/ui/library.slint:4126`</sub>
### Select everything the grid is showing
@@ -325,13 +296,4 @@ Distinct from Done, which leaves the mode entirely. Clearing keeps it, so the ne
A scoped grid of two hundred frames is two hundred taps otherwise, and "all of them, except those three" is a far more common shape than the taps it took to say it.
<sub>`ui/dr-ui/ui/library.slint:4149`</sub>
### Take photographs out of a collection
- **Touch** — Select them, then "Collections…" in the selection bar
- **Pointer** — Select them, then "Collections…" in the selection bar
The badge on a cell says a photograph is filed in three collections and never which. This is the sheet that names them, and the only way out of one the grid is not currently scoped to.
<sub>`ui/dr-ui/ui/library.slint:4264`</sub>
<sub>`ui/dr-ui/ui/library.slint:4143`</sub>
+23 -7
View File
@@ -259,16 +259,32 @@ slice, so eight layers still cost eight channels.
The set operations are already expressible in fixed-function blending over
`r8unorm`, which is why this is the cheap half of the feature:
| Join | `src_factor`, `dst_factor`, op | Result |
|------|-------------------------------|--------|
| Union | `One`, `One`, `Max` | `max(dst, src)` |
| Subtract | `Zero`, `OneMinusSrc`, `Add` | `dst · (1 − src)` |
| Intersect | `Zero`, `Src`, `Add` | `dst · src` |
| Join | `src_factor`, `dst_factor`, op | Result | Built |
|------|-------------------------------|--------|-------|
| Union | `One`, `One`, `Max` | `max(dst, src)` | M1 |
| Subtract | `Zero`, `OneMinusSrc`, `Add` | `dst · (1 − src)` | M1 |
| Intersect | `Zero`, `Src`, `Add` | `dst · src` | M2 |
The middle row is `brush_erase`, already constructed in
[`MaskPass::new`](../core/dr-gpu/src/mask.rs). The other two are the same
pipeline with a different `BlendState` — three pipeline variants over one
shader, no new bind group layout, no new shader code, and nothing read back.
three vertices with a different `BlendState`, and nothing is read back.
**One correction to the first draft of this section, found in the building.**
It claimed no second texture was needed, because a part could be blended
straight onto the layer's slice. That is wrong, and the reason is the erase
stroke: an erase inside a part means *a hole in that part*, not a hole in the
mask. Drawn straight onto the accumulator it takes away whatever the parts
before it had put there — so tidying the edge of a correction punches through
the subject underneath, and the failure reads as the model's mask having holes
in it.
So a part is drawn into one scratch texture (proxy-sized, `r8unorm`, allocated
the first time any layer has more than one part) and blended from there. A
layer of one part still takes the old path exactly — straight into its slice,
no scratch, no combine pass — which is what keeps every existing mask
rendering as it did. `an_erase_stroke_holes_its_own_part_and_not_the_mask` in
[`local_adjustments.rs`](../core/dr-gpu/tests/local_adjustments.rs) is the test
that holds this in place.
`Max` blending on `r8unorm` is core WGPU and universally supported on the
desktop backends; **verify it on the Android adapter before M2 lands**, since
+22
View File
@@ -495,6 +495,28 @@ blend without a halo — the boundary is the picture's own, at whatever detail t
also the only route to selecting by skin tone, and the prerequisite for composing a selection from
several criteria at once.
**FR-DEV-19 — Mask editing.** A mask layer's coverage shall be editable by hand after it is
created: painted into, erased from, and built from more than one selection. Every edit is stored as
geometry and parameters in the edit graph; no rasterised mask is written to a file and none exists
in CPU memory (ARCH §5.4).
A model finds a subject in a second and, before this, the photographer could not then change it by a
single pixel. The coverage arrives approximately right — stopping inside a shoulder, leaking into
the hair — and FR-DEV-3's edge controls move the *whole* boundary, so no value of either fixes two
errors that go opposite ways. Every competing developer has had a brush over its selections for a
decade; a mask that cannot be corrected is the reason an edit leaves this application for a pixel
editor.
**FR-DEV-19a — Mask composition.** A layer's mask is an ordered list of parts, each naming a source
and how it joins the mask before it — added to it, or taken out of it. A layer of one part is
exactly the layer that existed before this, and reads and writes the same sidecar. The parts of a
layer merge under FR-NC-9 as the layer does, and each carries its own edge treatment.
**FR-DEV-19b — Hand correction.** A part may be painted, with add and erase strokes, at a radius,
hardness and flow the photographer sets. Strokes are stored as normalised source coordinates and
rasterised on the device, so a correction stays on what it was painted on through a crop, a zoom and
an export at any size. A whole stroke is one step in the history.
### 3.4 Display and interaction
**FR-DSP-1 — Proxy-resolution rendering.** The develop view renders at the resolution actually
+62 -59
View File
File diff suppressed because one or more lines are too long