# Lemenzo Gallery

Privacy-first, local media gallery for LemenzoOS.

Implemented core features:
- Photos and videos from Android MediaStore
- Date-grouped gallery grid
- Albums
- Favorites
- Search
- Full-screen image/video viewer
- Pinch/double-tap zoom for images
- Sharing
- Favorite/unfavorite through MediaStore requests
- Trash / Restore / Permanent delete through MediaStore requests
- Media details and EXIF metadata
- MediaStore observer refresh
- Asynchronous thumbnail loading with LRU memory cache
- Runtime media permissions for modern Android
- Advanced local photo editor with rotate, flip, crop presets, draggable freeform crop, straighten, perspective, brightness, contrast, saturation, warmth, exposure, tint, highlights, shadows, sharpening, vignette, filters, drawing, text and privacy redaction
- Memory-budgeted high-quality Save copy generated from the original source rather than the preview bitmap
- JPEG/PNG/WebP output selection with alpha preservation where supported by Android Bitmap encoding
- Best-effort preservation of camera/date/lens/GPS EXIF metadata while normalizing orientation
- Android ACTION_EDIT image handler and Viewer Edit action
- Editor state restoration across Activity recreation

Privacy guarantees:
- No INTERNET permission
- No account requirement
- No cloud sync
- No analytics or advertising
- Backup and device-transfer extraction explicitly excluded
- Original media is not modified by the editor

Build module: `LemenzoGallery`
Package: `com.lemenzo.gallery`

Add `LemenzoGallery` to the relevant PRODUCT_PACKAGES list for LemenzoOS.

## v1.4 editor architecture

The editor uses a bounded preview (maximum 2048 px edge) only for UI responsiveness. Save copy decodes the original again and replays the edit state. Native resolution is preserved when the current heap budget can safely hold the source and output; exceptionally large images are adaptively decoded to a safe working resolution instead of risking process death or OOM. Geometry and color correction are rendered into one destination bitmap to reduce peak memory compared with chaining multiple full-resolution intermediate bitmaps.

Crop presets are state, not destructive button presses. Cycling None -> 1:1 -> 4:3 -> 16:9 -> None always recomputes from the same source state, so changing the crop ratio does not repeatedly remove pixels.

PNG output is used when alpha must be retained, WebP sources are written as lossless WebP, and other formats use high-quality JPEG when Android Bitmap does not expose a native encoder for that source format. The MIME type and file extension always match the actual encoded bytes.

The editor copies user-relevant EXIF metadata on a best-effort basis and forces output orientation to Normal because ImageDecoder has already applied source orientation to the decoded pixels. Stale width/height/orientation metadata is not copied.

Freeform crop, perspective, highlights/shadows/sharpening, drawing, text and flattened privacy redaction are implemented in v1.9. Encrypted Vault storage itself remains a separate app; Gallery now contains the stable import contract and only surfaces the handoff when Lemenzo Vault is installed.

## v1.5 advanced local capabilities
- Non-destructive full-resolution photo editing with undo/redo, rotate, flip, crop ratios, straighten, brightness, contrast, saturation, warmth, exposure, tint and local filter presets.
- Privacy share: images can be re-encoded to a short-lived app-cache copy without inherited EXIF/XMP/IPTC/location metadata before Android's share sheet opens.
- Video editing: trim and mute MP4-compatible videos without recompressing the video stream.
- Animated GIF/WebP playback in the full-screen viewer where Android ImageDecoder supports the source.
- Advanced offline search tokens for favorites, screenshots, camera/downloads, orientation, 4K, large files and common image formats.

### Production policy
Lemenzo Gallery has no INTERNET permission and must remain local-first. Features are only claimed when backed by a real implementation. Vault integration is intentionally deferred until the Lemenzo Vault import API/contract is finalized; a fake "hidden folder" is not considered a vault. HDR/Ultra HDR, RAW/DNG and Pixel Motion Photo behavior must be validated using real target-device media before release claims are made.

## v1.6 production hardening
- Main gallery loads MediaStore incrementally in 240-item pages using structured ContentResolver limit/offset query arguments, with a compatibility fallback.
- Search scans bounded MediaStore pages and retains only matching results instead of caching the full library.
- Viewer loads a bounded window around the requested item instead of retaining the entire library.
- Album summaries are aggregated page-by-page.
- Large photo export uses conservative runtime heap budgeting to prevent full-resolution bitmap OOM crashes while preserving native dimensions when safe.
- Metadata-free JPEG sharing is now a streaming operation: EXIF/XMP/IPTC/comment application segments are removed without decoding/recompressing the image, preserving resolution and compressed image quality while using very little memory.
- Non-JPEG privacy sharing uses a memory-budgeted fresh encode.
- Video trim UI resolves the selected start to the actual previous codec sync sample before export, so the displayed trim range matches the lossless mux result.

Production release still requires a successful `m LemenzoGallery` in the target Android 16 tree plus runtime/stress tests on supported Pixels.


## v1.7 hardening
- Viewer uses a MediaStore anchor offset to open deep-library items without hundreds of page queries.
- Favorites, Trash and individual albums use paged loading.
- Search explicitly surfaces the 2,000-result safety cap.
- Editor save-copy now actually applies BitmapBudget before decoding large originals.

## v1.8 media hardening

Lemenzo Gallery v1.8 adds platform-native Ultra HDR display, gainmap-aware geometry edits, DNG/RAW decode through Android ImageDecoder, verified Pixel/Google Motion Photo playback, video frame extraction and a non-destructive vignette control. All features remain local-only; the application has no INTERNET permission.

Ultra HDR color/tone/filter/vignette edits intentionally create an SDR edited copy unless the gainmap can be transformed correctly. The original is never modified. Geometry-only Ultra HDR edits preserve the gainmap on Android 16.


## v1.9 production candidate
- Draggable freeform crop and perspective correction.
- Highlights, shadows and sharpening.
- Non-destructive markup/text/redaction layers with undo/redo; redaction is flattened into the exported copy.
- Save private copy exports edited media without inherited EXIF/GPS metadata.
- Lossless MP4 orientation rotation in the local video editor.
- Stable, guarded Gallery -> Lemenzo Vault import contract.
- No INTERNET permission or cloud dependency.

Source-level review is not a substitute for the Android 16 build/runtime gate. Final production certification requires `m LemenzoGallery` plus Pixel regression/stress testing.


## v1.10 production-final candidate
Adds scoped-storage move/copy/rename, real folder creation through SAF, local Smart categories, accessibility actions for custom edit surfaces, LemenzoUI-facing resource cleanup, and an Android instrumentation test target. The shared legacy SecureLineUI Soong module remains a compatibility dependency until the OS-wide module is renamed; app resources and themes now use LemenzoUI aliases.

## v1.11 final hardening
Move/Copy can target existing MediaStore folders without broad filesystem permission. Smart Motion Photos use verified XMP + MP4-tail detection rather than filename guessing. Custom crop and annotation surfaces expose virtual accessibility nodes for assistive technologies. See LEMENZO_GALLERY_V1_11_RELEASE_NOTES.txt.

## LemenzoOS system integration (v1.14)

Lemenzo Gallery is prepared to ship as the built-in LemenzoOS gallery rather than as an isolated APK. The viewer handles standard Android `ACTION_VIEW` intents for `image/*` and `video/*`, while the editor handles `ACTION_EDIT` for `image/*`. The product integration snippet replaces legacy AOSP `Gallery2` with `LemenzoGallery`.

The app intentionally installs as a normal system app rather than a privileged app because it does not require signature|privileged permissions. On Android 16, the OEM-only `SYSTEM_GALLERY` role is the authority for gallery media access. The manifest requests image/video media access plus `ACCESS_MEDIA_LOCATION` for original EXIF/GPS access; no separate default-permissions exception is bundled. No `INTERNET` or `MANAGE_EXTERNAL_STORAGE` permission is used.

See `integration/SYSTEM_INTEGRATION.md` for product-build and Lemenzo Camera handoff details.

## Supported UI languages

Lemenzo Gallery ships with English as the canonical/default resources (`values/`) plus complete Danish (`values-da`), Swedish (`values-sv`), German (`values-de`) and Spanish (`values-es`) translations. Static validation enforces key and formatting-placeholder parity across all supported locales.
