The request was a mask's EXPOSURE losing hue, and the mask pass has not done that since6d60d45: measured today through a page the service worker controls, with an ellipse over the whole frame and +1 EV, the pixels inside move exactly as the frame's own knob moves them — identical to the byte (mask+1 vs frame+1 over four codes: 619 pixels of 1,709,450, all of them on the rim), and the hue each one leaves behind is the same distribution to a hundredth of a degree over the 370,606 pixels that carry a hue in both reads (mean 2.07°, p99 15.31° for the mask against 15.32° for the frame; on the vivid pixels, mean 0.83° at +1 EV). The one place that still says otherwise is a doc on the Android branch, whose §3.2 quotes the old line. But the symptom is real, and the build that produces it is the one from before that commit, where maskAdjust multiplied the three channels by the stop: c = c * half(pow(2.0, a.x)); Three channels clip by three different amounts, so the differences between them stop being scaled together and the hue goes with them. That bundle could still be what a visitor runs, because of two files the deploy never took away: - index.html was the only document the server handed over with no Cache-Control at all (the .mjs, /assets, /wasm and /models locations all name their policy, sw.js and the manifest both opted out). With no header the browser is free to guess a freshness window out of Last-Modified — a tenth of the file's age — and answer a navigation from its own cache for hours after a deploy. The page it answers with names the previous build's hashed bundle, so the previous shader is what runs, and a hard reload is the only way out. The SPA fallback lands on the same file (an internal redirect re-matches locations), so /app and /library were covered by the same guess. - sw.js is the second place the pin lived. Its navigations are network-first, but a plain fetch is not the network: it can be answered by the browser's cache, so the network never came first — and the old shell's hashed bundle, once fetched, is a STATIC path that the cache-first rule serves forever. So: nginx names the policy for the shell, with the isolation pair restated because an add_header in a location drops every inherited one and index.html is the document that needs them — the wasm renderer's SharedArrayBuffer is behind that pair. The worker reads its navigations past the browser's cache, precaches the shell the same way (a cache.add of '/' consults that cache like any other fetch, so a shell read inside a stale window would be stored as the offline shell of the build that replaced it), and VERSION goes to v2, whose activate drops the cache the old worker pinned — the old shell and the old bundle with it. The root fix is still6d60d45: this commit is what lets it reach the browser. Verified: nginx -t on the shipped config, and a container of this config against a copy of index.html hands / and /app `Cache-Control: no-cache` with all five original headers intact, while /assets/index-abc.js keeps `public, immutable` (30 days) — the exact location does not shadow the hashed bundle. node --check on sw.js. The measurements above come from the live 8090 build inside a persistent profile whose page is controlled by the worker (controlled true, crossOriginIsolated true, bundle index-CKOd57MG.js), the same session that pinned the build the fix is about. Co-authored-by: PenguinHarness <noreply@penguin.local>
RecipesCam web — self-contained stack
A Docker-hosted web build of RecipesCam. Everything it needs is in this folder: move it to another machine, run two commands, and the app is up. It does not need the React Native project around it.
cp .env.example .env
docker compose up -d --build
# → http://localhost:8090
What runs where
| Service | Image | Role |
|---|---|---|
frontend |
nginx:1.27-alpine (built by frontend/Dockerfile) |
Static SPA + /api/ reverse proxy |
api |
node:22-slim (built by backend/Dockerfile) |
Accounts + saved recipes, SQLite on ./data |
frontend resolves api through Docker's embedded DNS and proxies /api/* to
it — that is why the API container is named api and why it is not published on
the host. Only ${WEB_PORT:-8090} is exposed.
Photos never leave the browser. The CanvasKit render pipeline (grade, frame, watermarks, JPEG encode) runs in the visitor's tab; the API only stores recipes as JSON.
Layout
docker-compose.yml the stack
.env.example WEB_PORT
data/ SQLite (created on first run, gitignored)
backend/ Fastify + better-sqlite3 API, own Dockerfile
frontend/ Vite + React + CanvasKit SPA, own Dockerfile + nginx.conf
shared/ vendored copies of the app's types + utils (see below)
src/engine/ skiaShim.ts (CanvasKit) + exportEngine.ts (render pipeline)
+ session.ts (localStorage/IndexedDB studio persistence)
Vendored files
frontend/shared/{types/index.ts,utils/*.ts} are byte-identical copies of
src/types/index.ts and ten src/utils/*.ts files from the React Native
project (@shopify/react-native-skia is aliased to src/engine/skiaShim.ts in
vite.config.ts + tsconfig.json, so those files compile unchanged):
cinemaShader colorUtils defaultRecipes exifWrite frameUtils jpegDpi
paramDefs recipeShare skiaImage toneShader.
The landing page needs no CDN: frontend/public/assets/fonts/*.woff2 are the
seven self-hosted faces behind the three font groups the Themes menu offers
(Plus Jakarta Sans / Inter / JetBrains Mono, Fraunces / Be Vietnam Pro /
Courier Prime, Be Vietnam Pro / Space Mono — all SIL OFL, pulled from Google
Fonts, vietnamese + latin + latin-ext subsets), and
frontend/public/assets/samples/s*.jpg are the six placeholder negatives the
film strip, preset tester and QR card show (swap them for real graded stills
whenever we have them). Its one foreign request is the QR image from
api.qrserver.com, which degrades to an empty slot offline.
When the app changes one of them, copy it back in — the renderer is only "parity" for as long as these stay in sync:
cd <repo>/docker/frontend/shared/utils
cp <repo>/src/utils/<name>.ts .
Operations
docker compose logs -f api # API log
docker compose restart api # after backend/src changes (rebuild: --build)
docker compose down # stop; ./data survives
Backup is the ./data folder — that is the whole database.
Checks
curl -s http://localhost:8090/api/health # {"ok":true}
curl -sI http://localhost:8090/ # 200, index.html
Then open the UI, drop a photo in, and confirm the preview shows the picture and
EXPORT downloads a JPEG that opens. The preview going solid black while the
export still reports a plausible size is the one failure mode worth knowing: it
means the CanvasKit GPU surfaces lost their shared GrDirectContext (see
frontend/src/engine/skiaShim.ts), and with no GPU the raster fallback renders
the same pipeline correctly, just slower.