Capacity clamping keeps only a PREFIX of the projected segment stream, so a
joint code emitted for the whole stream can name a partner that was never
written. Rewrite any such code to the free-end sentinel: the retained
endpoint then draws its soft cap instead of dereferencing a texel that holds
either nothing or a previous pool tenant's data.
This replaces a boundary-local heuristic that inferred the same situation
from matching endpoint POSITIONS on either side of the cut. The code makes it
exact and O(1) per segment inside the writer's existing single pass: a
partner is either in the written prefix or it is not. It also covers the case
the heuristic explicitly could not — arbitrary indexed neighbours anywhere in
the stream, not just the pair straddling the boundary.
It also enforces the encoding's REPRESENTABILITY bound — see
MAX_EXACT_JOINT_SLOT — and its WELL-FORMEDNESS: a code must decode to
a non-negative integer slot, so a hand-authored fractional value cannot reach
the shader and be truncated into a negative texelFetch.
Exported for tests: the two rules bind at wildly different scales (the prefix
rule at whatever the node was clamped to, the representability rule only past
2^24 segments), so driving them through writeLineTexels can only ever
exercise the first — the prefix check rejects any large slot before the
exactness check is reached. Asserting them separately is the only way to know
both are live.
Capacity clamping keeps only a PREFIX of the projected segment stream, so a joint code emitted for the whole stream can name a partner that was never written. Rewrite any such code to the free-end sentinel: the retained endpoint then draws its soft cap instead of dereferencing a texel that holds either nothing or a previous pool tenant's data.
This replaces a boundary-local heuristic that inferred the same situation from matching endpoint POSITIONS on either side of the cut. The code makes it exact and O(1) per segment inside the writer's existing single pass: a partner is either in the written prefix or it is not. It also covers the case the heuristic explicitly could not — arbitrary indexed neighbours anywhere in the stream, not just the pair straddling the boundary.
It also enforces the encoding's REPRESENTABILITY bound — see MAX_EXACT_JOINT_SLOT — and its WELL-FORMEDNESS: a code must decode to a non-negative integer slot, so a hand-authored fractional value cannot reach the shader and be truncated into a negative
texelFetch.Exported for tests: the two rules bind at wildly different scales (the prefix rule at whatever the node was clamped to, the representability rule only past 2^24 segments), so driving them through
writeLineTexelscan only ever exercise the first — the prefix check rejects any large slot before the exactness check is reached. Asserting them separately is the only way to know both are live.