# Lemenzo Gallery production test plan

A release is not considered proven until the module builds inside the LemenzoOS Android 16 source tree and these runtime gates pass on target Pixel hardware.

1. `m LemenzoGallery` from a clean/enough Android 16 build environment with no compile/resource errors.
2. Launch with full photo/video access, selected-photo access, denied access and permission revocation while running.
3. MediaStore query with 0, 1, 1,000, 10,000 and 50,000 mixed image/video items.
4. Open JPEG, PNG with alpha, WebP, GIF, HEIF/HEIC, Ultra HDR where supported and DNG preview.
5. Open H.264/H.265 videos; rotate device; background/foreground; seek, pause and resume.
6. Favorite/unfavorite single and multi-item flows and verify MediaStore state.
7. Trash/restore/permanent-delete flows including user-cancel paths.
8. Editor rotate left/right and sequences such as rotate -> flip -> rotate; verify preview equals saved result.
9. Cycle crop None -> 1:1 -> 4:3 -> 16:9 -> None repeatedly and verify no cumulative pixel loss.
10. Exercise brightness, contrast, saturation and warmth at min/default/max values.
11. Rotate/recreate Editor Activity and verify every operation/crop/adjustment remains intact.
12. Save 48/50 MP JPEG and verify output pixel dimensions reflect crop/rotation but are not capped to preview size.
13. Save PNG with transparency and verify alpha remains present.
14. Save WebP and verify MIME/extension/content agree and output decodes normally.
15. Edit HEIF/HEIC and verify fallback JPEG is correctly named/mimetyped and full resolution is retained.
16. Verify original media checksum/content is unchanged after Save copy and after failed/cancelled edits.
17. Verify edited copy preserves applicable EXIF make/model/date/lens/exposure/ISO/focal/GPS and orientation reads Normal.
18. ACTION_EDIT from another app using content:// URI + temporary read grant.
19. Memory-pressure test with the largest supported camera images and repeated viewer/editor navigation.
20. Kill/restart during pending save and verify MediaStore does not expose a corrupt published item.
21. TalkBack/content-description pass, large-font pass and RTL smoke test.
22. Airplane/offline verification: gallery/editor remain functional with no network dependency.
23. Inspect final merged manifest: no INTERNET permission, telemetry SDK, account dependency or advertising SDK.
24. Verify cloud-backup/device-transfer extraction excludes Gallery app-private data.

## v1.5 advanced production gates
- Photo editor undo/redo across geometry, filter and adjustment changes.
- Straighten at -10°, 0°, +10° combined with rotate/flip and every crop ratio.
- Exposure/tint/filter preview must match full-resolution export.
- Metadata-free share: verify EXIF GPS, camera, timestamps, XMP/IPTC are absent in shared cache copy; original remains untouched.
- Private share provider must reject write modes, traversal paths and unknown files; grants must be read-only and temporary.
- Video editor: trim H.264/H.265 MP4 clips, with and without audio; mute output must contain no audio track.
- Video trim around non-keyframe selections must remain playable from first output frame.
- Test very large compressed video samples (>2 MiB/keyframe) to validate dynamic mux buffer growth.
- Animated GIF and animated WebP must animate in viewer, retain zoom/tap behavior, and stop when viewer is destroyed.
- Search tokens: favorites, screenshots, camera, downloads, portrait, landscape, square, 4k, large, gif, webp, raw/dng, heic/heif.
- No INTERNET permission; no network sockets; sanitized share data must live only in cache and expire automatically.

## v1.8 media capability gates
- Ultra HDR JPEG: viewer switches to HDR and back to default when swiping to SDR/video media.
- Ultra HDR rotate/crop/straighten: geometry-only Save Copy retains a gainmap.
- Ultra HDR tone/filter/vignette: edited copy is valid SDR and original remains Ultra HDR.
- DNG: open representative Pixel DNG files, zoom, details, close/reopen; corrupt DNG fails safely.
- Motion Photo 1.0: play modern Pixel Motion Photo using GContainer ItemLength; reject residual MotionPhoto=1 XMP when no valid appended MP4 exists.
- Legacy Motion Photo: MicroVideoOffset accepted only when appended bytes begin with a valid MP4 ftyp box.
- Motion Photo cache: extracted video stays under app cache and does not appear as a new MediaStore item.
- Video Save current frame: selected trim-start frame creates a readable MediaStore JPEG and survives Gallery refresh.
- Vignette: undo/redo, rotation recreation, reset and Save Copy match preview.

## v1.9 advanced editor regression
- Free crop: drag each corner and move the crop box; verify output matches preview framing and never modifies original.
- Free crop after an aspect preset: entering free crop returns to full-frame state before the free crop selection.
- Perspective X/Y: verify positive/negative corrections and combinations with rotate/straighten/crop.
- Highlights/shadows/sharpen: verify neutral position is pixel-neutral within encoder tolerance and extremes do not crash or overflow channels.
- Undo/redo: verify draw, redaction, text, free crop, perspective and tone controls restore exact editor state.
- Recreation: rotate/recreate the Activity and verify markup/text/redaction and all controls restore.
- Privacy redaction: export and inspect pixels to verify redacted regions are opaque black pixels, not a reversible overlay or retained annotation metadata.
- Ultra HDR: geometry-only edit retains HDR gainmap; tone/sharpen/vignette/markup edit intentionally exports SDR and never carries a stale gainmap.
- Video rotation: export 90/180/270 degree copies and verify orientation in platform players without video recompression.
- Vault handoff: action is hidden without Lemenzo Vault; when installed, URI read grant works and Gallery never deletes source media itself.
- Save private copy: verify edited pixels match normal save while EXIF/GPS/camera metadata is absent from the exported file.

## Automated regression targets (v1.10)

Build and run the device suite from the Android 16 tree:

```bash
m LemenzoGallery LemenzoGalleryTests
atest LemenzoGalleryTests
```

The suite enforces the no-INTERNET invariant, package identity, folder-name/path sanitization,
smart-category token stability, bitmap-budget safety, JPEG APP1 metadata stripping, and
accessibility actions on the custom crop/annotation surfaces. Manual Pixel stress cases below
remain release blockers because codec/HDR/MediaStore behavior must be validated on target hardware.
