GEO-RUNTIME / SPRINT 1THE SLICE3 SEPT 20269 / 9 DONE-WHEN
Not a mesh, not a model file — a program. It declares its own ceiling in a 64-byte header, and a WebAssembly VM reads its bytes every frame to build 5,787 vertices straight into the layout the GPU wants. Ten times faster than the engine it was ported from, and vertex-for-vertex identical to it.
A depth-bounded program has a maximum cost you can compute without running it. That is the whole architecture in one sentence: known ceiling → arena sized before execution → no allocation, no memory growth → a typed-array view that can never detach. Bounded and zero-copy are the same constraint approached from opposite ends.
A fast engine that draws a different character is not a faster engine. So before any timing: the VM and GeoV's own gcBuildForm run in the same JavaScript context, on the same document, at fourteen times along the plan — every key, the mid-segments, the loop seam, past the end, and a negative time.
| compared | GeoV | the VM | result |
|---|---|---|---|
| vertices, every frame | 5,787 | 5,787 | identical |
| index buffer, element by element | 31,800 | 31,800 | 0 mismatches |
| group spans and colours | 11 | 11 | 0 mismatches |
| worst |Δvertex|, every float of every frame | 8.196 × 10⁻⁷ | 6.9 f32 ULP | |
The first run was 2.58 × 10⁻⁶. Widening the pose arithmetic from f32 to f64 cut it 3.1×; the ~6.4 × 10⁻⁷ that remains is the format storing pose values as f32, which is a stated cost rather than a bug. f32 in the file is a decision. f32 in the arithmetic is sloppiness.
The claim is narrow and total: for every input the VM accepts, execution fits the ceiling the header declared. Rejection is always allowed. What is never allowed is accepting a program and then exceeding the bound — because a clamped arena keeps rendering something plausible, so nobody would notice.
| mutation | accepted | tried | what it attacks |
|---|---|---|---|
| poisoned floats | 342 | 444 | NaN, ±∞ and 10³⁰ through real geometry |
| random byte flips | 294 | 445 | anything, anywhere |
| offset rewrites | 47 | 444 | sections pointing outside the file |
| 255× resolutions | 38 | 445 | the multiply that computes the ceiling |
| header scramble | 15 | 445 | every declared count at once |
| giant counts · lying ceiling · truncation · pure noise | 0 | 1,777 | all rejected, by design |
736 mutated programs were accepted and executed at eight times each. Zero traps. Zero ceiling violations. Zero arena overflows. Zero memory growth. The 3,264 rejections carry their reason: 1,601 for a section falling outside the binary, 1,260 for a ceiling that exceeds the arena or contradicts the header's own counts.
And the fuzz found a real hole. usize is 32-bit on wasm32, so a header claiming 65,535 solids at 255×255 wraps a plain multiply onto a small ceiling — which then passes the arena check. A bounded VM talked out of its bound by arithmetic. Fixed with saturating maths, and it was invisible until four thousand programs went looking.
⭐ The strongest line in that table is the first one. Poisoned floats are accepted and cannot move the bound, because the ceiling is derived from the header's counts — never from the data.
The existing .geo grammar is not bounded — it has subroutines, program-switching, neighbour propagation, and a tick that counts forever while depth stays capped. v0 does not adopt those and then guard against them. There is no encoding for them at all.
| absent from v0 | why it breaks the bound |
|---|---|
| CALL · PROG · PLURALITY | subroutines and program-switching are unbounded recursion |
| tick>=N · tick%P=R | depth is capped; time is not |
| EMIT · signal · neighbour reads | propagation has no static step bound |
| any jump, any backward branch | control flow is “walk the parts once, in order” |
The compiler refuses what the ISA cannot express, and names the key. A compiler that quietly drops a pose channel emits a binary that renders a different character and reports success — which is the exact fail-open shape this project keeps meeting. Restriction only means something if something enforces it at the boundary.
GeoV has a documented law: a control is not done until elementFromPoint at its own centre returns it. It exists because a depth slider shipped unclickable for months, visible and on screen the whole time, covered by the next panel — and every clipping test passed it, because nothing was clipped.
New repo. New HUD. A CSS comment citing the old failure by name, three lines above the controls that had it. “Covered by nothing” means the centre point is outside the viewport — the panel was one long scrolling column and the sliders sat below the fold at the default window size. The buttons above them passed.
Worse: the automation's drag helper scrolls the element into view before clicking, so one slider appeared to work. The drag test alone would have shipped it.
The fix is the layout, not the test. Readouts scroll; controls are pinned and cannot scroll out of reach at any height. And the harness now probes every control at three window sizes, because reachable at one size is not reachable. Writing a law down does not install it. Only the check does.
noodle_nv = 20 is still a number a person typed. Morton order as the program counter is not in v0..geoi and .geov do not appear here, deliberately — proving the dialect idea on one format is the point, and doing four at once is how this dies.