Nothing from our own code reached logcat on the tablet: 284 lines from the app's PID during a launch, every one of them from Hwaps, BlockMonitor, InputEventReceiver or nativeloader, and not even the version banner android_main emits three statements in. I could not find the fault in our wiring, and this commit does not claim to fix it. What it does is make the next launch say which side is at fault, and close a hole that is real whatever the answer turns out to be. What reading rules out, so nobody repeats it: install does call log::set_max_level. The Config carries an explicit tag and an explicit max level, and its env_filter is None, so android_logger's enabled() and filter_matches() both pass an Info record. Tee::enabled delegates to the console and gates nothing else. set_boxed_logger cannot have failed — its Err path drops the Tee, taking the LogFile with it, and the file on the device has content. And Tee::log calls console.log() unconditionally *before* the file write, which is itself gated on console.enabled(), so every line that reached the file proves the AndroidLogger was handed the same record. Nothing else in the graph installs a logger; android-activity and Slint's backend do not. The diff that introduced this changed the level, the tag and the Config not at all — init_once and set_boxed_logger leave the same logger installed at the same level. That leaves below __android_log_write, which no amount of reading this file can reach. So: the console logger is now built first, and one line goes through it directly, before the state directory and before the log file. Two things follow. Everything between android_main's first statement and install returning — external_data_path, create_dir_all and an open on a FUSE volume the system may still be mounting — currently has no surface at all to fail on; that window is what logcat is for, and it now has a line in it. And when the log is silent, that line separates the two cases: present with the log::info! lines below it missing is the facade, absent along with them is liblog not delivering this process's records. It goes through Log::log rather than log::info!, which is not a style choice: the facade's maximum level is Off until install sets it, so a log::info! there compiles and emits nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
DarkRoom
A cross-platform, non-destructive RAW photo editor for Linux and Android.
Status: 0.9.0, and no longer a spike. A library opens, culls, develops and exports on both platforms, across eight tagged releases. What is not built is written down rather than merely absent — see docs/outstanding.md for the requirements that have no implementation and why, and docs/technical-debt.md for the compromises that were chosen.
Documentation
| Document | Contents |
|---|---|
| CONTRIBUTING.md | How to land a first change without reading the rest |
| requirements.md | What the software must do — 179 numbered requirements |
| architecture.md | How it is built — crates, GPU pipeline, data model, sync |
| technical-debt.md | Compromises taken deliberately, each with the condition that retires it |
| outstanding.md | What is not built, and whether that is a decision or a gap |
| code-health.md | What a contribution costs, per seam, measured |
| traceability.md | Generated: which requirement is claimed by which file |
| faces.md | Face detection and identity — the models, the licence problem, and what S14 measured |
Building
Desktop:
cargo run -p darkroom-desktop
Android (containerised toolchain, see docker/android):
./docker/android/build.sh cargo ndk -t arm64-v8a build --release
Git LFS is required for the model weights, and the toolchain pins itself. CONTRIBUTING.md has the details and the four commands CI will run against what you send.
Current state
Working. A catalog over a local folder, a Nextcloud account, or a folder a
sync client keeps in virtual-files mode — where a placeholder is treated as the
photograph rather than as a one-byte file. A virtualised library grid with a
capture-time timeline, ratings, labels, keywords, collections and a trash that
survives a crash mid-operation. Card ingest. Face detection and identity, with
the index syncing between devices. A develop pipeline of fifteen declared
operations fused into a single compute dispatch, plus the neighbourhood
operations that cannot be — clarity, texture, capture sharpening, noise
reduction, lens correction, spectral film simulation. Crop, straighten, spot
removal, gradient and subject-segmentation masks, named presets, and a
generated panel that no operation in ui/ is allowed to name. Export to JPEG,
PNG and 8- or 16-bit TIFF with resize and output sharpening.
The zero-copy display path works on desktop. The compute pass writes a texture that Slint composites directly, which is what ARCH §6.1 requires; the readback it forbids costs 96% of frame time at 4K, and
cargo run -p dr-gpu --example bench --features readback
still reproduces that measurement. The one exception is the Android develop view, which reads the frame back through the CPU because zero-copy there needs wgpu's Vulkan swapchain, and that tears a portrait window on a tablet whose panel is mounted landscape. It is debt, not a revision of the rule: the reasoning, the on-device measurements that forced it, and the three separate things any one of which would remove it are in technical-debt.md TD-1.
Not built. Plugins, compare and survey culling, focus peaking, burst grouping, AI denoise, tiled and progressive rendering, and most of the Android platform integration beyond running. The performance targets in §4.1 are unverified rather than unmet — the per-commit benchmark suite §8 requires does not exist, so nothing fails a build on a regression. docs/outstanding.md is the list, with the reasoning.
Licence
GPL-3.0-or-later.