Every face the user has ruled on entered the pass as an anchor, and the scan is exhaustive by design (`dr_face::neighbours`), so a person with 750 confirmed faces cost 750 comparisons against every other face in the library — and the cost of a library grew with how well it was named. Most of those comparisons said nothing new: thirty frames from one afternoon are one point of view, not thirty, and a face that matches one of them matches the rest. Each person now enters through at most 100 of their anchored faces (`dr_face::references`). Eligible are those whose raw embedding is at least 15 long — one above the gallery floor, since a reference speaks for someone rather than merely being admitted — with an unmeasured length admitted as it is everywhere else. From those, the set spanning the greatest volume is chosen greedily: the longest vector first, then at each step the face with the largest component orthogonal to the chosen so far. That is pivoted Gram–Schmidt, and the product of the residuals it picks is the Gram determinant, so the greedy step is the exact greedy on the objective. A near-duplicate of a chosen face has no residual and is passed over; the one profile shot among two hundred frontal frames is taken early; faces inside the span of the chosen add no volume and are not taken to fill the cap. The faces not chosen keep their confirmations and are not touched by the pass — they stay in the anchor map, so it never releases them — they are simply not compared. A person none of whose faces is long enough is still stood for, by their longest, rather than losing their anchor and having their next face filed as a stranger. Under the cap nothing changes: every eligible face stands, and the short ones stay in as the probes they were. At the reference library's 3,851 confirmations the scan shrinks by about a fifth; at 15,000 it is a fifth of what it was.
DarkRoom
A non-destructive RAW photo editor and library for Linux and Android, with a GPU develop pipeline, a catalog that syncs between devices, and no account, no telemetry and no cloud of its own.
The manual shows every feature, pictured from the application itself. This page says what it is, how to get it, and what is still missing.
What it does
A library. Point it at a folder — on this machine, on a network mount, or one a Nextcloud client keeps in virtual-files mode, where a placeholder is treated as the photograph rather than as a one-byte file — or at a Nextcloud account directly. The grid is virtualised, ordered by capture time with a timeline beside it, and filtered by rating, flag, person and whether the file is here. Ratings, keywords, collections and a trash that survives a crash mid-operation. Card ingest. Bursts fold. Face detection and identity, with the index syncing between devices.
Developing. Eighteen declared operations fused into one compute dispatch, plus the neighbourhood work that cannot be: clarity, texture, capture sharpening, noise reduction, lens correction, spectral film simulation. Crop and straighten, spot repair, and local adjustments over masks the model draws — click a subject or a category, then paint, subtract a gradient, grow or shrink the edge. Focus peaking and a raw histogram for judging what is recoverable. Named presets; XMP sidecars other editors read.
Panoramas. Select the frames, align, choose a projection, fill the ragged border rather than crop it, and the composite lands beside its sources as a DNG, with a sidecar recording what it was merged from.
Export. JPEG, PNG, AVIF, JPEG XL, 8- and 16-bit TIFF, with resize, output sharpening, a naming template and a colour space — to a folder here or back into the library.
On both platforms. The same core runs on a desktop and a 12-inch tablet; the interface is one layout, tuned for a wide viewport with touch targets throughout. On desktop the develop view draws the compute pass's texture directly — no readback between the GPU and the screen.
Getting it
| Platform | How | State |
|---|---|---|
| Arch Linux | packaging/PKGBUILD — makepkg -si |
Built from every release |
| Android | The APK from each CI run, or ./docker/android/package.sh --install |
Runs on a tablet; F-Droid not yet submitted |
| Windows | DarkRoom-<version>-x86_64-setup.exe, cross-built by CI (windows.md) |
Verified under Wine only; unsigned |
| Flatpak | packaging/flatpak/ |
Manifest in tree; choosing a library does not yet work in the sandbox |
Or build it. Git LFS is required for the model weights, and the toolchain pins itself to 1.92.0:
git lfs install && git lfs pull
cargo run --release -p darkroom-desktop
Android, through the containerised toolchain (docker/android):
./docker/android/build.sh cargo ndk -t arm64-v8a build --release
CONTRIBUTING.md has the system packages, the four commands CI runs against what you send, and the shortest useful contribution — a develop operation is one YAML file, and it arrives with its controls, its place in the chain and its tests.
Where it stands
0.13.3, seventeen tagged releases in. 184 numbered requirements in scope, 84% of them claimed by code and traced to it; the rest are written down rather than merely absent.
Not built: plugins (post-v1, D12), compare and survey culling, AI denoise, tiled and progressive rendering, HDR merge and focus stacking, most of the Android platform integration beyond running, and the Flatpak's library chooser. The performance targets are half verified: the per-commit benchmark suite §8 requires exists for everything that does not need a frame — the catalog, the scan, the thumbnails — and not yet for the render path, so a regression there fails nothing. outstanding.md is the list, with the reasoning for each.
The one deliberate compromise worth knowing about before reading anything else: the Android develop view reads its frame back through the CPU, because zero-copy there needs wgpu's Vulkan swapchain and that tears a portrait window on a tablet whose panel is mounted landscape. It is debt, not a revision of the rule — technical-debt.md TD-1 has the measurements and the three things any one of which would remove it.
Documentation
For someone using it:
| manual | Every feature, pictured |
| gestures.md | How it is driven — generated from the code, so it cannot describe a gesture that does not exist |
For someone changing it:
| CONTRIBUTING.md | How to land a first change without reading the rest |
| requirements.md | What the software must do — the numbered register, and the decisions |
| architecture.md | How it is built — crates, the GPU pipeline, the data model, sync |
| technical-debt.md | Compromises taken deliberately, each with the condition that retires it |
| outstanding.md | What is not built, and whether that is a decision or a gap |
| code-health.md | What a contribution costs, per seam, measured |
| traceability.md | Generated: which requirement is claimed by which file |
Designs, one per subsystem: segmentation and mask editing · spot removal · panorama · faces · inference · storage and sync · catalog · display and extension · navigation · distribution · windows · benchmarks.
Licence
GPL-3.0-or-later. The photographs in the manual and the test fixtures are the author's and are there to show and test this project, nothing else. The model weights carry their own licences — models/LICENCE.md.


