dtourolle 0ed38ada28 Adopt a peer's unmeasured faces instead of refusing them
The tablet showed a fraction of each person: 681 of the desktop's 3,851
confirmations, and none of Ian's 746, Catherine's 626 or my own 480.
Every face that existed on both devices agreed on who it was, and the
people rows were identical — the merge was fine. The missing 3,170
confirmations were on faces the tablet did not hold at all: the
desktop's 16,080 faces from the original detector, on 4,310 images,
detected before schema V14 kept the quality reading.

Those faces were in shards the tablet had already downloaded, in
August's export. `import_from_shards` looked at them on every sync pass
and declined each one, because a face without a quality reading was
"work this device cannot finish": adopting it would write the run
marker, and the marker was what stopped an image being looked at again.
That was true when it was written and has not been since the quality
repair existed — that pass lists its work by `f.quality IS NULL`, not by
the marker, exactly as the eye pass does, and faces without an eye
reading were already adopted on that reasoning.

The refusal had no exit. V14 had deleted the markers of every image
holding such faces so the quality pass would find them, and
`export_to_shards` walks the markers, so the desktop never re-exported
them either; the unmeasured August copies were the only ones there
would ever be. The tablet's answer was to queue all 17,727 images for a
re-detection of its own, a fetch of the whole library, while holding
the faces on disk.

Adopt them. The receiving device's quality pass measures them when it
reaches them, and the desktop's confirmations match onto them by box
overlap on the next catalog merge. The test that asserted the refusal
now asserts the adoption and that the image is still owed to the pass.
2026-09-20 12:58:41 +02:00
2026-09-20 11:06:54 +02:00
2026-08-26 10:08:51 +02:00
2026-09-20 11:06:54 +02:00
2026-09-20 11:06:54 +02:00

DarkRoom

A non-destructive RAW photo editor and library for Linux and Android, with a GPU develop pipeline, a catalog that syncs between devices, and no account, no telemetry and no cloud of its own.

The library: seventy frames, the timeline beside them, the filter bar above

The manual shows every feature, pictured from the application itself. This page says what it is, how to get it, and what is still missing.

What it does

A library. Point it at a folder — on this machine, on a network mount, or one a Nextcloud client keeps in virtual-files mode, where a placeholder is treated as the photograph rather than as a one-byte file — or at a Nextcloud account directly. The grid is virtualised, ordered by capture time with a timeline beside it, and filtered by rating, flag, person and whether the file is here. Ratings, keywords, collections and a trash that survives a crash mid-operation. Card ingest. Bursts fold. Face detection and identity, with the index syncing between devices.

Developing. Eighteen declared operations fused into one compute dispatch, plus the neighbourhood work that cannot be: clarity, texture, capture sharpening, noise reduction, lens correction, spectral film simulation. Crop and straighten, spot repair, and local adjustments over masks the model draws — click a subject or a category, then paint, subtract a gradient, grow or shrink the edge. Focus peaking and a raw histogram for judging what is recoverable. Named presets; XMP sidecars other editors read.

Segmenting an urban scene and choosing the sky as a mask

Panoramas. Select the frames, align, choose a projection, fill the ragged border rather than crop it, and the composite lands beside its sources as a DNG, with a sidecar recording what it was merged from.

Twelve hand-held frames aligned on a cylinder

Export. JPEG, PNG, AVIF, JPEG XL, 8- and 16-bit TIFF, with resize, output sharpening, a naming template and a colour space — to a folder here or back into the library.

On both platforms. The same core runs on a desktop and a 12-inch tablet; the interface is one layout, tuned for a wide viewport with touch targets throughout. On desktop the develop view draws the compute pass's texture directly — no readback between the GPU and the screen.

Getting it

Platform How State
Arch Linux packaging/PKGBUILD — makepkg -si Built from every release
Android The APK from each CI run, or ./docker/android/package.sh --install Runs on a tablet; F-Droid not yet submitted
Windows DarkRoom-<version>-x86_64-setup.exe, cross-built by CI (windows.md) Verified under Wine only; unsigned
Flatpak packaging/flatpak/ Manifest in tree; choosing a library does not yet work in the sandbox

Or build it. Git LFS is required for the model weights, and the toolchain pins itself to 1.92.0:

git lfs install && git lfs pull
cargo run --release -p darkroom-desktop

Android, through the containerised toolchain (docker/android):

./docker/android/build.sh cargo ndk -t arm64-v8a build --release

CONTRIBUTING.md has the system packages, the four commands CI runs against what you send, and the shortest useful contribution — a develop operation is one YAML file, and it arrives with its controls, its place in the chain and its tests.

Where it stands

0.13.2, sixteen tagged releases in. 184 numbered requirements in scope, 84% of them claimed by code and traced to it; the rest are written down rather than merely absent.

Not built: plugins (post-v1, D12), compare and survey culling, AI denoise, tiled and progressive rendering, HDR merge and focus stacking, most of the Android platform integration beyond running, and the Flatpak's library chooser. The performance targets are half verified: the per-commit benchmark suite §8 requires exists for everything that does not need a frame — the catalog, the scan, the thumbnails — and not yet for the render path, so a regression there fails nothing. outstanding.md is the list, with the reasoning for each.

The one deliberate compromise worth knowing about before reading anything else: the Android develop view reads its frame back through the CPU, because zero-copy there needs wgpu's Vulkan swapchain and that tears a portrait window on a tablet whose panel is mounted landscape. It is debt, not a revision of the rule — technical-debt.md TD-1 has the measurements and the three things any one of which would remove it.

Documentation

For someone using it:

manual Every feature, pictured
gestures.md How it is driven — generated from the code, so it cannot describe a gesture that does not exist

For someone changing it:

CONTRIBUTING.md How to land a first change without reading the rest
requirements.md What the software must do — the numbered register, and the decisions
architecture.md How it is built — crates, the GPU pipeline, the data model, sync
technical-debt.md Compromises taken deliberately, each with the condition that retires it
outstanding.md What is not built, and whether that is a decision or a gap
code-health.md What a contribution costs, per seam, measured
traceability.md Generated: which requirement is claimed by which file

Designs, one per subsystem: segmentation and mask editing · spot removal · panorama · faces · inference · storage and sync · catalog · display and extension · navigation · distribution · windows · benchmarks.

Licence

GPL-3.0-or-later. The photographs in the manual and the test fixtures are the author's and are there to show and test this project, nothing else. The model weights carry their own licences — models/LICENCE.md.

S
Description
No description provided
Readme GPL-3.0
1 GiB
2026-10-07 11:27:59 +00:00
Languages
Rust 86.1%
Slint 10.3%
Python 1.1%
Shell 1%
WGSL 0.9%
Other 0.6%