At fit, every output pixel of the fused pass loads one texel from a source three or four times its width, on a stride. The memory system fetches the texels it skips along with the one it wanted, so on a 60 MP rgba16float source that gather was most of what the fused pass cost: 10.6 ms of a 2560x1600 frame against 3.8 ms for the same shader reading a contiguous window (the 1:1 view). At 3840x2160 it was 21.1 ms. Those are the laptop RTX 3050 with its clocks held at 420/810 MHz by the power cap; unthrottled the same frames were about 2.0 and 3.2 ms, and the gather is the same share of them. Which texel an output pixel reads depends only on the framing prologue, the framing and warp uniforms, the source and the render size. None of those move during a slider drag, so the gather is the same work every frame. The fused shader now takes a render-sized rgba16float cache of it (bindings 6 and 7, declared in every generated shader like the masks) and a pair of uniform flags: write what was gathered, or read it back at the pixel's own coordinate. AdjustPass keeps the cache and decides per dispatch. The composer supplies `ComposedShader::sample_key`, a hash of the prologue and those uniforms, and AdjustPass adds the image and the size; an image gets a process-unique id for this rather than being held alive by the key. The picture is bit-for-bit the same. The source is rgba16float and so is the cache, so the stored texel is the texel, and only the path that reads a texel whole takes part: an interpolated sample (straightening, lens warps, CA) is a blend that f16 could not hold exactly, so the composer gives it no key and it reads directly as before. The cache is written on the second frame with a given key, not the first: a crop or zoom drag changes the key every frame, and writing then would add a render-sized write to exactly the gestures that can afford it least. It is kept only up to 3840x2400, so an export never parks a full-frame copy on the device, and `release_caches` drops it. Measured with a scratch probe rendering the synthetic 60 MP frame from examples/frame_budget.rs, forty frames per run after six warm-up, five runs of each binary alternated, median of the per-run p50 (GPU idle apart from the power cap): scene before after neutral 2560x1600 fit 10.62 ms 3.88 ms exposure 2560x1600 fit 10.83 ms 3.87 ms nr chroma 2560x1600 fit 19.84 ms 12.69 ms neutral 3840x2160 fit 21.05 ms 7.11 ms exposure 3840x2160 fit 21.08 ms 6.94 ms clarity 3840x2160 fit 42.20 ms 27.88 ms neutral 2560x1600 1:1 3.83 ms 3.84 ms (control: nothing to gain) The rgba8 output of every scene hashed identically before and after, in isolated runs and across all 38 scene/size/view combinations of the probe. New tests walk a pass through direct, write and read frames, a slider move, a neighbourhood operation and a framing change, and compare every frame with a fresh pass that can only have read directly.
DarkRoom
A non-destructive RAW photo editor and library for Linux and Android, with a GPU develop pipeline, a catalog that syncs between devices, and no account, no telemetry and no cloud of its own.
The manual shows every feature, pictured from the application itself. This page says what it is, how to get it, and what is still missing.
What it does
A library. Point it at a folder — on this machine, on a network mount, or one a Nextcloud client keeps in virtual-files mode, where a placeholder is treated as the photograph rather than as a one-byte file — or at a Nextcloud account directly. The grid is virtualised, ordered by capture time with a timeline beside it, and filtered by rating, flag, person and whether the file is here. Ratings, keywords, collections and a trash that survives a crash mid-operation. Card ingest. Bursts fold. Face detection and identity, with the index syncing between devices.
Developing. Eighteen declared operations fused into one compute dispatch, plus the neighbourhood work that cannot be: clarity, texture, capture sharpening, noise reduction, lens correction, spectral film simulation. Crop and straighten, spot repair, and local adjustments over masks the model draws — click a subject or a category, then paint, subtract a gradient, grow or shrink the edge. Focus peaking and a raw histogram for judging what is recoverable. Named presets; XMP sidecars other editors read.
Panoramas. Select the frames, align, choose a projection, fill the ragged border rather than crop it, and the composite lands beside its sources as a DNG, with a sidecar recording what it was merged from.
Export. JPEG, PNG, AVIF, JPEG XL, 8- and 16-bit TIFF, with resize, output sharpening, a naming template and a colour space — to a folder here or back into the library.
On both platforms. The same core runs on a desktop and a 12-inch tablet; the interface is one layout, tuned for a wide viewport with touch targets throughout. On both, the develop view draws the compute pass's texture directly — no readback between the GPU and the screen.
Getting it
| Platform | How | State |
|---|---|---|
| Arch Linux | packaging/PKGBUILD — makepkg -si |
Built from every release |
| Android | The APK from each CI run, or ./docker/android/package.sh --install |
Runs on a tablet; F-Droid not yet submitted |
| Windows | DarkRoom-<version>-x86_64-setup.exe, cross-built by CI (windows.md) |
Verified under Wine only; unsigned |
| Flatpak | packaging/flatpak/ |
Manifest in tree; choosing a library does not yet work in the sandbox |
Or build it. Git LFS is required for the model weights, and the toolchain pins itself to 1.92.0:
git lfs install && git lfs pull
cargo run --release -p darkroom-desktop
Android, through the containerised toolchain (docker/android):
./docker/android/build.sh cargo ndk -t arm64-v8a build --release
CONTRIBUTING.md has the system packages, the four commands CI runs against what you send, and the shortest useful contribution — a develop operation is one YAML file, and it arrives with its controls, its place in the chain and its tests.
Where it stands
0.15.0, twenty-three tagged releases in. 190 numbered requirements in scope, 84% of them claimed by code and traced to it; the rest are written down rather than merely absent.
Not built: plugins (post-v1, D12), compare and survey culling, AI denoise, tiled rendering, HDR merge and focus stacking, most of the Android platform integration beyond running, and the Flatpak's library chooser. The performance targets are half verified: the per-commit benchmark suite §8 requires exists for everything that does not need a frame — the catalog, the scan, the thumbnails — and not yet for the render path, so a regression there fails nothing. outstanding.md is the list, with the reasoning for each.
Documentation
docs/README.md is the index. The short version, for someone using it:
| manual | Every feature, pictured |
| gestures.md | How it is driven — generated from the code, so it cannot describe a gesture that does not exist |
For someone changing it:
| CONTRIBUTING.md | How to land a first change without reading the rest |
| requirements.md | What the software must do — the numbered register, and the decisions |
| architecture.md | How it is built — crates, the GPU pipeline, the data model, sync |
| technical-debt.md | Compromises taken deliberately, each with the condition that retires it |
| outstanding.md | What is not built, and whether that is a decision or a gap |
| code-health.md | What a contribution costs, per seam, measured |
| traceability.md | Generated: which requirement is claimed by which file |
Designs, one per subsystem: segmentation and mask editing · spot removal · panorama · faces · inference · storage and sync · catalog · display and extension · navigation · distribution · windows · benchmarks.
Licence
GPL-3.0-or-later. The photographs in the manual and the test fixtures are the author's and are there to show and test this project, nothing else. The model weights carry their own licences — models/LICENCE.md.


