In a library's develop view the arrows, space, A and D opened `library-roll-pick(library-roll-current ± 1)`. `roll-current` is a row of the loaded window, set when a photograph was opened and never again. Two things followed on any library larger than one window: - Holding D stopped dead at the end of the loaded window: the pick of a row past `ctl.paths` found no path and did nothing, a few screenfuls into a library of thousands. A stopped at its start the same way. - Any reload of the window — a background sync, a judgement that drops the open frame out of a filter — left `roll-current` on a row that now held another photograph. The roll marked it, develop's rating keys judged it, and the next step walked on from it. The keys now call `library-roll-step(delta)`, and Rust steps as `move_cursor` does in the grid: from the open photograph's ordinal (`index`, which `report_position` already keeps), clamped to the library, loading the window around the target only when it lies outside. The window-bringing half of `place_cursor` is shared for this as `bring_window_to`, so the grid cursor and the roll move the window the same way. Catalog reads stay proportional to the window: one `load_window` per window crossed, none per step within it. The open photograph is also remembered by image id. Every `load_window` finds it again in the rows it just read (a scan of one window, no query), puts `roll-current` and `index` back on it, or takes the mark off when it is not there. When it is missing but its ordinal is still inside the window, it has left the grid and its successor moved up into its place, so the next step forward lands on that ordinal instead of skipping the successor. A click on the roll still reports a row; it is right because the cells it is drawn from and `ctl.paths` are replaced together, and it now goes through the same open path as a step. Fixes #64.
Documentation
Two audiences, two folders. Most people want the first table and never the second.
Using DarkRoom
| The manual | Every feature, pictured from the application itself — opening a library, rating and filing, developing, local masks, repair, film, panoramas, export |
| How it is driven | Every gesture and shortcut, by screen. Generated from the code, so it cannot describe one the application does not have |
The top-level README says what DarkRoom is, how to get it on each platform, and what is still missing.
Changing DarkRoom
Everything under dev/ is for someone working on the code. Start with
CONTRIBUTING.md, which says how to land a first change
without reading the rest.
The register and the record. What must be built, how it is built, and how far along it is.
| requirements.md | What the software must do — the numbered register, the decisions (D-numbers) and the spikes (S-numbers) |
| architecture.md | How it is built — crates, the GPU pipeline, the data model, sync |
| traceability.md | Generated: which requirement is claimed by which file. Never edited by hand |
| outstanding.md | What is specified and not built, and whether that is a decision or a gap |
| technical-debt.md | Compromises taken deliberately, each with the condition that retires it |
| code-health.md | What a contribution costs, per seam, measured |
Designs, one per subsystem. Each is the specification the code was built to, kept current as the code moved.
| catalog.md | The index, the library view, incremental scan, the job queue |
| storage.md | Storage backends: the seam a folder, a sync client and a Nextcloud account share |
| faces.md | Face detection, identity, clustering and the eye-state models |
| segmentation.md | How the application finds the regions a local mask snaps to |
| mask-editing.md | Painting, erasing and combining masks |
| spot-removal.md | Clone and heal as parameters in the edit graph |
| panorama.md | Alignment, projection, the chunked composite and the border fill |
| inference.md | The neural runtime and model chosen per device, with the measurements |
| display-and-extension.md | The display contract, and why the fused pipeline is already most of a plugin format |
| view-composition.md | A controller for the display layer |
| ui-navigation.md | Finding things in the interface once there are many |
Measurements. Numbers committed so a regression is a diff rather than a recollection.
| benchmarks.md | The per-commit suite: what it covers, what it does not, how to read a failure |
| bench-baseline.json | The committed numbers the suite checks against |
| frame-budget.md | What a frame costs on each device, and the decision those figures settled |
Platforms and distribution.
| distribution.md | Which channels v1 targets and what each one constrains |
| windows.md | The Windows installer, cross-built from the Linux CI |
| android-signing.md | Which key signs the APK, and keeping it |
Archive. Kept as the record of what was asked for, not as plans.
| milestone-v0.1.md | The first milestone, delivered 2026-08-30 and superseded |
| ui-refinement.md | How the interface should look; succeeded by ui-navigation.md |
Conventions
Two files here are generated and must not be edited by hand:
gestures.md and dev/traceability.md. Both come from
cargo run -p traceability and the pre-commit hook keeps them in step with
the tree. The manual's pictures are recorded by
tools/manual and live in LFS.
A design document links to the requirements it satisfies and to the code
that satisfies them. When the code moves, the link moves with it; a document
that has stopped being true goes to dev/archive/ with a note saying what
replaced it, rather than being deleted.