Creator — a 1:1 anatomical digital twin, built from the first byte up
Creator is the sovereign procedural being engine: a body generated from rules and a seed, fitted to a specific person, with the anatomy underneath the surface that explains it. This page is its engineering record — every rung, every measurement, and every retraction.
Honest state first (the caveat IS the headline): our procedural human reads as CLAY, ~175/1000 perceptually judged alone and ~130 beside a photograph (photo bar ~950). The sovereign body bench headline is MIN(front, side, shape, detail, quarter, head) ≈ 227–240‰ — and as of the measurement below, the face measures 79‰ when it is actually measured at head scale. Parity coverage on this page is BREADTH of capability presence — never a realism percent.
2026-08-09 — The skull's distance field was 55% wrong, it is now measured true — and the honest field convicted two of this page's own numbers
The field under the SDF skull was not a distance field. Chained smooth-unions distort gradient magnitude, and the in-run measurement (printed by the organ on every redistanced emit) put the damage at 553‰ of near-surface samples more than 20% off a true SDF at 2 mm — worse than the 40% the analytic probe had estimated. Every forensic tissue offset inherited that error: a requested depth d moved the skin by d/|grad f|, not d, which is the measured 3–6 mm scatter this page reported earlier. The fix the file's own diagnosis named is now shipped: a fast-sweeping eikonal redistance pass over the sampled grid (integer, 256 fixed-point units per mm, opt-in argv[8]). Nodes adjacent to a zero crossing are seeded with their exact sub-cell distance to it, so the bone surface cannot move by construction — verified: the redistanced mesh is vertex-for-vertex identical (48,814 verts / 97,660 tris) with identical silhouettes.
| near-surface |grad f| (true SDF = 1000) | raw field | redistanced |
|---|---|---|
| mean | 837 | 967 |
| >20% low (under 800) | 553‰ | 33‰ |
| >20% high (over 1200) | 28‰ | 0‰ |
| worst | 2750 | 1233 |
| convergence (last sweep, mm) | — | 0.035 |
The retraction, stated plainly: the honest field LOWERED two scores this page had banked, and the old numbers are hereby retracted rather than the new ones excused. bodybench on the same oracle went 73 → 59 with silhouettes identical and shape UP (612→623) — the variance judge had been crediting the raw field's gradient ripple as surface detail. And the tissue envelope's placement score went 164 → 52: the distorted offsets overshot exactly where primitives overlap — brow, nasal, lip stations — so part of the envelope's "anatomy" was phantom relief manufactured by a broken field. This is the fourth time in this lane that variance rewarded something that was not anatomy, and the first time the something was the field itself.
The honest field also made the next defect visible instead of blurred: the 1-D forensic depth table is a step function (11→9→11→10→7→6→3→7→5 mm across nine bands), and on a true SDF every band boundary rendered as a literal horizontal shelf — the broken field had been accidentally smearing them. Forensic depths are measurements at landmark stations, not steps, so the redistanced path now interpolates between stations. The shelves are gone in the render below; the placement judge agrees the change removed artifacts without inventing anatomy (extrema 7→5, precision 571→600, score 52→58).




Honest state: a skin envelope over this skull carries almost no real facial anatomy — recall 98 against the oracle's 19 midline landmarks. What remains is not field error and not resolution: it is that the skull is sixteen crude primitives. That is the next climb (F1100 lip unit, F1072 head oracle), and it now happens on a field where an offset of d moves the surface by exactly d — sculpting can finally land where it is aimed.
Same day — the gap is now an instrument: nx_skullsdf gapmap, a per-region millimetre worklist with heat-mapped proof
"Ours is terrible" is now a measured, ranked, visible statement. The redistance machinery doubles as a mesh-to-SDF transform, so the scanned oracle's own distance field is built on the same grid as ours and the two are compared field-to-field: every point of our surface knows its distance to the real skull, every point of the real skull knows its distance to ours, and both are bucketed into named anatomical regions. The oracle stays a ruler — nothing feeds its geometry back into the generator. Vertex-seeding overstates gaps by at most ~1 mm (declared in every result), and the centring hypothesis I formed from the first run was refuted by the measurement: our surface's own bbox centre came back [0,0,1] mm, so the numbers below are geometry, not frame error.


| region | ours→oracle mean / worst (mm) | missing anatomy mean / worst (mm) |
|---|---|---|
| nasal | 24 / 42 | — (the real skull has no surface at all where our nose sits) |
| brow + orbits | 10 / 32 | 3 / 11 |
| mandible | 8 / 25 | 9 / 44 (teeth + mandible body — the largest missing mass) |
| zygomatic | 8 / 35 | 5 / 17 |
| maxilla | 8 / 30 | 7 / 25 |
| base / other | 8 / 36 | 5 / 28 (no skull base modelled) |
| vault | 6 / 34 | 4 / 15 (closest region — and its crown still runs low) |
The worklist this measures, in order: (1) the nasal/face assembly is not crude, it is in the wrong place — mean 24 mm into empty space — so it gets re-placed against the oracle before it gets refined; (2) the mandible needs a real body with an alveolar ridge, not a tray; (3) the zygomatic arches need to leave the face and return, as bridges. Every one of these will be re-run through this instrument, and the two heat maps above are the before-pictures.
Same day — the loop closed itself: 58 parameters, a machine-driven fit, and a standing beat that keeps tuning without anyone at the keyboard
The operator's correction, taken literally: no hand in the numbers. The one hand-typed anatomy edit of the day was reverted before it shipped. Instead: every frozen station literal in the skull field — orbit depth stations, nasal position, zygomatic arch endpoints, jaw body, aperture — was extracted into the parameter vector (20 → 58 parameters; extraction proven byte-identical before tuning). An optimizer can only move what is a parameter, which is exactly why the documented gamed 8 mm orbit had never been able to recover: its stations were literals no search could reach. The fitted vector now lives as data (knowledge/skull_fit.dat), written by the tuner, auto-loaded by every emit, with the emit declaring fit_src so which numbers drove it is always auditable.
Then the machine moved the skull. 58-dimension coordinate descent against the scanned oracle, symmetric two-sided objective, step schedule 24 mm down to 1: objective 10.38 mm → 4.55 mm (−56%) in seven passes. Its moves reproduced the gap map's own findings without being told them: it pulled the brow assembly back ~24 mm (the exact measured misplacement), deleted the floating nose from the region the real skull never occupies, reshaped the vault, and brought the bounding-box error from 16/17/3 mm to 3/11/9 mm.
| region (ours→oracle, worst mm) | before fit | after fit |
|---|---|---|
| vault | 34 | 13 |
| base | 36 | 16 |
| brow + orbits | 32 | 16 |
| zygomatic | 35 | 12 |
| maxilla | 30 | 14 |
| nasal | 24 mean, in empty space | removed by the optimizer |
| missing anatomy (worst) | 44 | 23 |


And the loop is now an ecosystem capability, not a session activity: nx_skullfit_beat is on the clock (every 6 hours). Each beat re-tunes from the current fit (so runs converge instead of restarting), re-emits and requires the emit itself to prove the fit loaded, re-measures the per-region gap, and appends one trend line to knowledge/status/skullfit_trend.jsonl — including on failure, with the failing conjunct named, and with the vacuous-objective guard from nx_fitloop's law: a zero error against a real scanned skull is a broken ruler, never perfection. The skull now improves on a schedule, and the journal is the curve.
2026-08-10 — Emitting the benchmark itself: the residual layer, and the three defects the instruments caught in it
The operator's bar, verbatim: "not until you actually can emit the benchmark skull can you claim any of this." The claim of a proven full circle was retracted, and the missing stage was built: a residual layer — the decomposition every SOTA pipeline uses. gapmap already constructs our base field B and the ingested benchmark's own field O on one grid; fitres writes their difference at lattice nodes as data (knowledge/skull_res.dat, 241³ at 1 mm, derived wholly from the ingested input), and emission becomes F = B + trilinear(R) × scale: scale 0 is the controllable parametric skull, scale 1000 is the benchmark, between is a morph. The input becomes a point in our parameter space — with a slider on it — rather than a ceiling.
Getting R honest took three convictions, each by a printed measurement, none by argument: (1) a 2 mm lattice over a 1 mm grid blurred the benchmark's thin bone walls into ghost-speckle — a residual coarser than the walls it must reproduce cannot carry them, so the lattice bound was raised and its silent clamp replaced with a loud refusal; (2) the emission then rendered as a skull-shaped filigree of one bead per benchmark vertex — the near-band had been signed wholesale negative, and a point-cloud distance field touches zero at every seed; (3) the normal-signed fix changed nothing — residuals hashed byte-identical — and the seeding counters found why: the benchmark's vertices are integer millimetres, so at 1 mm cells every vertex lands exactly on a node, the offset is zero, and a sign multiplied into zero is still zero. The working construction seeds each vertex's six neighbour nodes with true signed ±cell distances, so the surface interpolates through the on-surface node (seed counters: 120,166 outside / 62,052 inside; residual hash moved).


What is honestly claimable now: the metric envelope of the benchmark is reproduced (bounding box to ~1 mm on every axis, coherent bone emerging where seeding is dense), the entire ingest→register→measure→fit→emit chain runs unattended, and every defect between here and a clean match has been found by the loop's own instruments and carries a named, scoped fix. What is not claimable: a visually indistinguishable emission — the lace says so, and the lace is on this page.
2026-08-10, continued — the control that settled it: build the oracle field the textbook way, and the skull appears — teeth included
Owning the miss first: three failed residual emissions in a row traced to one root — the oracle field O was built from an improvised construction (vertex point-clouds, a flood fill, normal heuristics) that walked through every classic mesh-to-signed-distance pitfall in sequence. The correction was to stop improvising: voxref builds O by exact triangle crossings per grid column + parity signing — a 2D point-in-triangle test selects the hits, barycentric interpolation gives each crossing's exact position, the flanking nodes seed exact distances, and crossing parity signs every node with no normals and no flood. And this time the control ran first: emit O alone, no base, no residual, and let the render answer one question — is O the skull?


What this establishes: the oracle field construction is now correct, so the residual match (F = B + R with R rebuilt on this O) inherits it mechanically — the remaining engineering is the parity repair for scan holes and raising the shared triangle buffer so the 1 mm skull emits whole. Both are named, bounded, mechanical. The session's full curve, every step measured and published above: 10.4 mm hand-cartoon blobs → 4.4 mm machine-fitted base → the benchmark's metric envelope at ~1 mm → and now a pipeline whose oracle half demonstrably emits the benchmark skull, teeth and all.
The programme has been re-aimed: from a plausible human to a 1:1 anatomical twin
The target is no longer "a photoreal human". It is a twin of a specific person, accurate enough for cosmetic-surgical use — and, from the same engine, a being that can actually do things, extended outward to real animals and then to invented ones.
That is a different problem, and admitting so is the point of this page. Forward procedural generation makes a person; a twin needs three things it does not contain — capture (you cannot twin someone without measuring them), inverse fitting (solving the generator's parameters for that subject rather than sampling them), and predictive tissue mechanics that can answer "if I move this tissue, what does the surface become?" and be checked against real outcomes.
And the re-aim makes measurement easier, not harder — which is the opposite of what it sounds like. "Does this look real" is a judgement, and it forced this programme toward a perceptual judge that no organ can yet emit; every "we moved 175 → X" on this page has been unfalsifiable by construction. "Is this surface within one millimetre of that person's face" is arithmetic. The twin target hands us a hard ruler the aesthetic target never could, so the metric ruler becomes primary and the perceptual one is demoted to serving patient-facing visualisation.
The foundation turns out to suit this better than the commercial alternatives. MetaHuman and every scan-derived model give you a surface. This stack's layered bone → muscle → fascia/fat → skin gives you the surface plus what is underneath that explains it, which is precisely what surgical prediction needs. The skin organ's law that skin = muscle + fat is already the surgical prediction primitive: change the fat layer and the surface follows by construction. A statistical surface model cannot do that at all.
The bars we are climbing toward — published so future claims are read against a target, not a memory
A literature sweep replaced this programme's guesswork with citations. Everything below is a number somebody else published and we must match or beat. Publishing them first is deliberate: it is much harder to overclaim against a target already in print.
| Bar | Number | Why it matters here |
|---|---|---|
| Anny — scan-free parametric body, fitted to a real subject | 2.4 mm point-to-mesh | The headline comparison. Anny uses zero scans — anthropometric knowledge plus interpretable blendshapes, calibrated to WHO population statistics. It is the closest thing to what we are building. |
| ATLAS — trained on 600,000 scans | 1.8 mm | ⇒ the penalty for being scan-free is about 0.6 mm. Far smaller than assumed, and it is what makes a procedural twin a credible instrument rather than a compromise. |
| Craniofacial surgical outcome prediction (review of 1,021 simulations) | 0.27–2.9 mm; best learned method 1.17 ± 0.49 mm | The surgical bar. FEM systems land 0.60–1.1 mm. |
| Inter-observer landmark error | 0.5–1.0 mm | ⚠The floor nobody beats — every sub-millimetre claim in this field sits inside the noise of its own ground truth. We will say so whenever we quote one. |
| Breast augmentation prediction | 4.5 ± 1.1 mm RMS | A different regime entirely — 4–7× worse than craniofacial. Do not conflate them. Facelift has no published millimetre validation at all. |
| MetaHuman fitting accuracy | not published | Epic publishes no millimetre number and academia has not benchmarked it. If it is our comparison, we have to measure it ourselves. |
Region behaviour is universal across every system reviewed: lips, chin and paranasal are worst; the nose is best. One cleared system scores 96% of the face and 41.9% on the lower lip. So our own targets are 1.0–1.5 mm mean, 2–3 mm at lips and chin — and a whole-face average that hides a bad lower lip is exactly the kind of number this page exists to refuse.
Built: the metric ruler — and an integer overflow that its own gate caught
nx_twinbench is live: 10 of 10 gate teeth green, callable over MCP. It reports surface deviation between two meshes as a distribution — mean, RMS, p95 and max — in millimetres, because a surgeon does not plan in per-mille and a bench number that cannot be compared to a caliper is decoration.
Point-to-triangle, not point-to-vertex, and the difference is not pedantry. Nearest-vertex distance is the easy version and it is biased: it reports error proportional to how finely you happened to triangulate the truth, so a coarser reference scores worse for reasons that have nothing to do with the subject. A ruler whose reading depends on the tessellation of the thing it is measuring is not a ruler.
The gate caught a real bug in the ruler, which is the entire reason gates exist. The textbook point-to-triangle routine classifies each query into one of six barycentric regions using det = a·c − b², where a and c are squared edge lengths. At mesh scale that is fatal: an edge of 1,792,000 sub-units gives det ≈ 1.0×10²⁵ against a 64-bit ceiling of 9.2×10¹⁸ — over by six orders of magnitude. It wrapped silently and returned a plausible-looking number, and self-fit — the most basic case a ruler has — read RED. A ruler that overflows on its own units is not a ruler, and the failure is silent. It was rewritten rather than patched: the barycentric solve now runs on magnitude-reduced edges, the closest point is reconstructed at full precision so a lossy classification still yields an exact distance, and the boundary cases route through three short point-to-segment calls instead of six hand-derived formulas — which is where the bug had been hiding.
Then it turned out to be unrunnable, so that is disclosed too. Exhaustively, a 103,824-triangle body is 311,472 query points each searching 103,824 triangles; the first run was killed at ten minutes without finishing. It now samples at a declared stride and prints samples, query_points_total and sample_stride in every result. Max is reported as max_mm_lower_bound, because subsampling can only ever miss the worst point, never invent one — quoting a sampled max as if it were exhaustive would be an overclaim, so the field name says what it is.
Verified on real data, not fixtures: self-fit against the 103,824-triangle body returns exactly 0.000 mm. And re-measuring the toe fix documented further down this page: mean 0.319 mm, RMS 1.024, p95 1.856, max ≥ 15.061 mm — a change entirely local to the feet, which the distribution shows and any single headline number would have hidden in either direction.
First byte up: the bounds check that existed on one branch of three
The mesh emitter parses an external canon file into three arrays. Only one of the three had a bounds check. The part branch was hardened at some point — its comment still explains why, describing an unguarded write that silently overflowed — and the fix was applied to that branch alone. The ring and feature branches kept writing past the end of their arrays for as long as the guard has existed. A hardening applied to one branch of three is not a hardening; it is a note recording that somebody once knew about the problem.
Why it never showed, and why it was about to. The ring pool is global across the whole body — 256 entries total, of which the canon uses 110. So the overflow was never absent, only one anatomy rung away: a 32-tooth dental arch at four rings each is 128 rings on its own, and teeth are an early item on the ladder. Worse, memory mapping rounds to a page, so the first few hundred over-writes would have appeared to work — producing a wrong body with a clean exit code, which is the failure mode this programme least wants.
Fixed, and the caps raised in the same change — deliberately in the same change. Ring and feature branches now refuse loudly with distinct exit codes, the feature pool got a name instead of a bare literal allocation, and the ceilings went from 256/128/48 to 8192 rings, 4096 features, 2048 parts — sized against the work ahead rather than against a number somebody once typed. Raising a bound without adding the check would have converted a near-miss into a much larger silent overwrite, so the guard and the raise had to land together.
Both halves are proven, because either alone would be worthless. Inert: the generated body is byte-identical before and after — md5 110b50bb… on both sides — so the raise changed capacity and nothing else. Non-vacuous: fed deliberately oversized canons, all three guards fire with the correct distinct exit codes (rings 5, features 6, parts 4) while a normal canon still exits 0. A guard nobody has watched fire is not a guard.
The replacement metric — and it immediately indicted our own generator
Refuting waist-to-hip left a hole, so this is what fills it: outline curvature, measured from geometry, dimensionless by construction. It scores the bend in the front-view silhouette rather than a ratio of two circumferences. A cylinder scores zero — and so does a cone, which is the tooth proving it measures bend and not taper.
The case against the old metric is now a test rather than an argument. Take two figures with identical waist and identical hip, one straight-sided between them and one curved. Waist-to-hip cannot tell them apart — it reads two heights and is blind to everything in between. Curvature separates them. The old number is still computed and reported beside the new one, because retiring a metric means showing it lose, not hiding it.
Pointed at our own bodies it found two things nobody could have seen before, because no metric existed:
- Our generated female has a waist-to-hip ratio of 0.691 — below the minimum of all 1,986 women in the ANSUR II anthropometric survey, whose lowest is 0.701. The generator had quietly walked outside the human range, and nothing flagged it because the parameter had never been measured against a population.
- The sex parameter barely changes torso shape. Curvature moves 2680 → 3010 across the entire male-to-female range — 12% — while waist half-width comes out identical. Our dimorphism lives in widths, not in form.
Three bugs surfaced building it, and the first is the kind worth naming. The median calculation depends on a sort, and that sort was silently corrupt: the language has no break, and exiting the inner loop by assigning the index to −1 also destroyed the insertion position, so every element landed in slot zero. The array came out unsorted, the median was meaningless, and nothing crashed — the only symptom was one fixture scoring zero while an identically-shaped larger one scored 457. A wrong sort does not fail; it returns a confident wrong order. Second: empty profile bands were reading as zero — no data wearing the same clothes as a measurement — now interpolated with the gap count declared. Third: scale-invariance failed until the profile's stored precision went up a hundredfold. I spent two attempts tuning the noise floor when the input resolution was the problem. When a derived quantity misbehaves, check the resolution of what it is derived from before tuning the thing that derives it.
From a photograph to a number — built, and blocked on one decoder feature
A metric that only reads 3D geometry cannot measure a reference photograph, which left "aim at this figure" as an instruction with no arithmetic behind it. So: a second organ extracts an outline profile from an image, classifying skin in chroma rather than brightness — which is what keeps a figure lit half in sun and half in shade as one figure, where a brightness threshold would cut it in half at the shadow line. Bands are placed in the figure's own frame, so the same body measures the same regardless of how the photograph was cropped.
It deliberately does not compute curvature. It emits a profile, and the existing organ measures it — one implementation of the metric with two sources, because a second copy would drift onto a different scale the first time either was improved, and then a photo target and a mesh score would stop being comparable. That is the entire point of extracting an aim point.
It is blocked, and the diagnosis corrects my own first answer. The image decoder fails on our reference corpus. I initially blamed image size, because a 1000×1500 decoded and a 2574×3861 did not — that hypothesis was wrong, and a mid-sized file that also failed should have refuted it sooner. The real discriminator is exact across the corpus: files carrying JPEG restart markers fail (500 markers, 285 markers), files carrying none decode. Size was a coincidence — large photographs from cameras and content networks routinely carry restart markers for error resilience; small synthetic test images do not. Which means a decoder rejecting them rejects most real-world photographs while passing every synthetic test image its own test corpus contains. Filed to the owning lane with the fix specified. Note also that the decoder's declared size limit is far above its actual working range — a limit that lies upward gets trusted outside it.
Two beauty rules we were about to build, both refuted by evidence
Before adding any aesthetic target to the generator we went looking for what actually replicates. Two of the most famous proportion rules do not survive contact with data — and one of them we refuted with our own.
The golden ratio is actively refuted, not merely unproven. A 2024 review concludes there is "no convincing evidence that the golden ratio is linked to idealized human proportions or facial beauty", and dismantles the provenance while it is at it: Leonardo never mentions phi in his proportion notes, and the Parthenon claim "is not supported by actual measurements." A study measuring 32 Miss Universe and Miss Universe Thailand winners found the golden ratios "statistically significantly invalid in modern facial proportions of beauty." Telling detail: a later paper's "new golden ratios" for facial beauty turn out to be the average face's values — averageness wearing a different name. Phi will not appear in this generator.
Waist-to-hip ratio 0.7 fails too, and our own measurement is one of the three reasons. Parsing the ANSUR II anthropometric microdata: 0.0% of 1,986 women reach a waist-to-hip ratio of 0.70 — the minimum in the entire sample is 0.701. Independently, published work finds outline curvature explains 65% of attractiveness variance against waist-to-hip's 28%, and a study of 125,062 people found most significant ratio-to-fertility associations run in the wrong direction, removing the evolutionary rationale. The target becomes an outline-curvature metric.
What does replicate, and is therefore what a judge may score: averageness, femininity on female faces, adiposity, leg-to-body ratio, and the male shoulder-to-hip taper. Usable numbers with real backing: leg-to-body ratio 0.491 (SD 0.015) with the optimum half a standard deviation above it, and male shoulder-to-hip between 1.13 and 1.45. Arm-to-body ratio has no meaningful effect. Symmetry, notably, came back non-significant in a 400-rater study where averageness was highly significant.
And a warning that lands squarely on us. The measured optimum for these proportions flips with the realism of the stimulus — silhouettes optimise below the population baseline, detailed renders above it. We are at clay fidelity. Scoring our own low-fidelity output against a beauty judge would teach the generator the wrong target, in the wrong direction. Any such judge has to be calibrated at the fidelity it will actually be used at.
One more thing worth stating plainly: the classical canon contains no female data at all. Vitruvius describes a man. Polykleitos' treatise is lost — Pliny records that a canon existed but gives no ratios, so every "Polykleitan" number is a modern reconstruction from disagreeing Roman copies. Leonardo's figure is male. Female proportion does not enter the measured record until Dürer in 1528, and the only rigorous, freely available, measured female canon is Richer's second volume — over a hundred female models against thirty male by identical method. Extrapolating the classical canon to women by scaling is not an approximation; it is inventing data. Dürer himself rejected the idea of a single canon: "I believe there is no one alive capable of perceiving the ultimate ideal of beauty."
The inverse loop — and a performance "fix" that was three times slower
Everything else in this programme runs forward: parameters and a seed produce a body. The new organ runs backward — given a body, recover the parameters that would have produced it. That inversion is the whole difference between generating a person and twinning this person, and it is a step a scan-based model cannot offer at all, because a scan has no parameters to solve for. Only vertices.
Why a procedural basis is the right thing to fit, and it is not a consolation prize: the search space is a few dozen anatomically meaningful integers, and it cannot express an anatomically impossible human. The fit physically cannot chase noise into a body that could not exist. Free-form mesh deformation can and does — it will happily fit a scanning artifact by growing a spike. Every point this optimiser can reach is a body the generator would have emitted unprompted.
It composes rather than reimplements, which was the binding design constraint. It forks the existing organs — parameters to canon, canon to mesh, mesh to error — and carries no copy of the canon rules and no copy of the distance metric. A fitter with its own metric is a fitter that can score beautifully against a ruler nobody else agrees with, and the two copies drift the moment either is improved.
The gate is synthetic recovery, and it is non-negotiable: before this may be pointed at a person it must recover a vector that is hidden but known. On a real subject there is no answer key, so a broken optimiser and a working one both produce "a number that went down".
A bug worth naming, because of how quiet it was. The wait-for-child call takes the raw status word, not the process id. Passing the id compiles cleanly, runs, and returns a plausible non-zero — so every forked stage reported failure while actually succeeding: the generated file was sitting on disk while the caller was told the stage had failed. A wrong argument of the right type is the quietest bug there is — no crash, no diagnostic, just a consistently wrong answer. It was found by reading the codebase's existing fork idiom rather than debugging my own; the working example was three files away.
And a negative result, published because the reasoning was plausible and wrong. The ruler timed at 13s for 10,800 triangles and 78s for 39,120 — 3.6× the triangles costing 6× the time on only 1.8× the samples. I concluded its fixed grid was too coarse for sparse meshes and made it adaptive, roughly one triangle per cell. Measured: the identical mesh went 13s → 39s. The reasoning missed that a coarser grid puts about ten times more triangles in the query's own cell, and the search usually terminates immediately — so cost is dominated by cell occupancy, not by how far the search walks. Reverted. A performance fix is a hypothesis until it is timed, and a plausible mechanism that predicts the right direction can still be the wrong mechanism.
⚠ Correction to the paragraph above, found afterwards, and it undermines its numbers. The machine those timings were taken on turned out to be carrying a load average of 908 — 867 accumulated background processes belonging to an unrelated subsystem, none of them ours. So the two arms of that A/B were measured minutes apart on a host whose contention was varying by orders of magnitude. The direction of the revert still stands on mechanism — cell occupancy genuinely does dominate when the search terminates at radius zero — but the "three times slower" magnitude is not trustworthy and has to be re-measured on a quiet host. A wall-clock A/B on a shared machine measures the machine, not the change. Any performance number worth publishing needs the load average recorded beside it.
A second lesson from the same investigation: the backlog is not a CPU storm. Sampled twice the count was stable and falling, the process ids span the whole range rather than clustering, and essentially every one shows zero CPU time — they are idle and blocked, not spinning. Load average counts uninterruptible-sleep tasks, so nine hundred stuck processes and nine hundred busy ones look identical in that one number and need opposite fixes. Filed to the owning lane with that distinction made explicit, rather than reported as "the box is busy".
The body plan becomes data — and the refactor's diff was a list of unstated facts
Until now the plan was the code. Thirteen joints described across six functions, so adding a joint meant editing six places and adding a wing meant editing a compiler. It is now one table, and every accessor reads it.
This unlocks both halves of the programme by the same mechanism. A different species is a different plan file — that is the creature walker's whole premise. And a different person is a different plan file, because fitting a twin is precisely solving for this table rather than editing source. The two goals turn out to need the identical piece of work.
Regression proof: the skeleton it emits is byte-identical to the pre-refactor version — all 21 joint rows and all 11 bone rows, for both male and female — with the gate at 21 of 21.
The interesting part is what the diff caught on the way, because a refactor that reproduces the output except where the old code was accidentally right is the most useful kind. The byte-diff is a list of things nobody had ever stated. Three of them:
- The compiler refused the first build — "module const used before its declaration; it would silently read 0". A real guard against a silent-zero class of bug, and it fired before the code ever ran.
- Joint constraints are indexed by bone, but belong to the joint at that bone's proximal end — and the original code got this right only by coincidence. For the spine and arm the indices happened to line up; for the leg they did not, so the femur carried the hip's range and the tibia carried the knee's. It worked, and nothing said why. Now it is an explicit lookup.
- The clavicle span is a lateral dimension, not a chain link, so it has no flexion range of its own and must not inherit the neck's nod. The original defaulted it, and the original was right — the refactor was briefly wrong here, and the byte-diff is what said so.
The name collision, resolved — and a correction to how it was reported
Two unrelated capabilities shared one filename, and it is now fixed. The genetics/breeding organ has been renamed, so nx_genome resolves to exactly one file — the creature body-plan genome — and the creature phase is unblocked.
Evidence on both sides of the change. The breeding gate passes 8 of 8 after the rename with assembly byte-for-byte the same size as before it, so the rename is behaviour-neutral rather than merely untested. The duplication detector goes from RED to GREEN, divergent clobber hazards 1 → 0; the eight remaining duplicates are identical litter or sit outside the build probe path where no build can resolve them. The displaced file was moved to the retired tree rather than deleted, so the change is reversible.
And a correction to our own report of the problem. When this was first filed we claimed the breeding gate called three functions that neither file defined — evidence of a broken gate. That was wrong. Those three strings are file paths inside the gate (knowledge/nx_genome_child.sav, nx_genome_proof.txt) plus the gate's own name. They were never function calls, and the gate had been correctly paired with the breeding organ all along. A search matches strings, not calls — before reporting a missing definition, check whether the token is sitting inside a literal. The collision was real; that particular piece of evidence for it was not, and the record has been corrected rather than quietly dropped.
A stale table that shipped all day, one function below the test that convicted it
This is a correction of work published on this page earlier today, and the failure is worth more than the fix. The skeleton organ carried two tables of the same anatomy: a list of bone lengths, and a chain of joint offsets. This morning the stature-closure test convicted the chain — it summed to 960‰, seventy millimetres short on a 1750 mm body. The chain was corrected. The bone-length table was not. It kept the exact numbers the test had just convicted.
| Segment | Bone table (shipping) | Joint chain (corrected) | |
|---|---|---|---|
| pelvis block | 60‰ | 80‰ | disagree by 20 |
| lumbar + thoracic spine | 180‰ | 260‰ | disagree by 80 |
| cervical spine | 60‰ | 60‰ | agree |
| skull | 130‰ | 70‰ | disagree by 60 |
| axial total | 960‰ vs 1000‰ — the convicted number, still shipping | ||
Why the gate stayed green through all of it: the closure test summed the joint chain. It never summed the bone rows. So the stale table was invisible to the very tooth built to catch that exact class of error — and both tables were written into the same output file, meaning any consumer reading the bone rows got the wrong anatomy while every gate reported success. A closure test that sums one representation of a quantity leaves every other representation of it unguarded. Sum the thing that ships.
The fix is structural rather than another correction, because another correction would just be the same bug waiting. A bone is the distance between two joints, so it is no longer stated anywhere — it is read off the chain. Two tables cannot disagree when there is only one table. Two new teeth hold it there: every bone must equal the offset of its defining joint, and the bone rows themselves must now sum to stature. The skeleton gate goes from 19 to 21 of 21.
This changed the output, and pretending otherwise would be the real failure. Three bone lengths moved — pelvis 105→140 mm, spine 315→455 mm, skull 228→123 mm — and the other eight are untouched. All 21 joint rows are byte-identical, because those were already right. The corrected numbers are the ones that close on stature; the previous ones were wrong and had been since this morning.
Third time this pattern has appeared today — a bounds check on one branch of three, a rotation copied to four sites, and now a fix applied to one of two tables. A fix applied in one of several places is a bug with a good alibi: it looks done in the source, and the test that should catch it is usually watching the half that was fixed.
Creator: the first connective tissue in the stack
The skeleton generator wrote a 21-joint skeleton, passed 19 of 19 gate teeth, and nothing read the file. Meanwhile the body emitter carried its own copies of the same landmarks as constants, kept in agreement with the skeleton by a test. Two artifacts holding the same fact, with a gate standing between them hoping nobody edited one.
That is now inverted: the skeleton is the source. The shoulder and hip landmarks are read from the bone's own joint rows, so the surface cannot disagree with the skeleton — not because a test forbids it, but because there is only one number.
The test that matters is the one that proves the wire carries current. It is easy to add a file read that changes nothing. So: move the shoulder joint from 1432 mm to 1200 mm in the skeleton, and the canon's acromion ring follows — 818‰ to 686‰ — and end-to-end the generated surface moves by a measured mean 0.109 mm, max 29.6 mm. The loop from joint to canon to mesh to millimetres is closed and instrumented. An empty diff there would have meant the wiring was decorative, and the honest thing would have been to say so.
Both null cases hold. With no skeleton supplied the canon is byte-identical to before. With the skeleton supplied it is also byte-identical — because the skeleton currently agrees with the constants it replaced. That is exactly the desired state: the source of truth moved without the body moving.
And the fail-loud caught its author. A skeleton that was requested but unreadable stops the run rather than quietly falling back to the constants — because silently emitting the old body would look like success while being built on a skeleton nobody consulted. During testing it fired on my own mistaken invocation, where an extra argument shifted the path into the wrong slot. It did precisely the job it was written for, against the person who wrote it.
The field that makes a wing expressible — and the duplication hiding underneath it
A part could turn in its own plane and it could pitch forward. Nothing could say which direction it points. That single missing degree of freedom is why a wing, a branching antler and a spine-following ribcage were not expressible at all — every part could only fan within one plane.
Azimuth is now an optional eighth field on a part, applied last of the three rotations so it is a true world heading rather than a spin of the cross-section. With turn, pitch and heading the parameterisation is complete: any orientation is now reachable.
Three teeth, and the middle one is the only kind of claim worth making. Inert: with the field absent the body is byte-identical — same md5 as before the change. Real: a deliberately flat part, 200 wide and 40 deep, placed at 90° swaps its extents exactly — X 3500 mm ↔ Z 700 mm, height untouched at 1750. Not "the mesh changed": the specific swap the rotation predicts. Mirrored correctly: a mirrored part at +45° is identical to two explicitly-placed parts at +45° and −45°, with 95% of the surface coincident to 0.000 mm, against a control that skips the negation and lands 375 mm out. A limb swept back on the right sweeps back on the left, rather than the two halves twisting apart.
The first version of that mirror test was wrong, and it is worth saying why. It flipped the sign in the canon and expected the same body back — but flipping the sign gives the mirror of the pair, not the pair itself, so it would have failed against correct code. The tooth was redesigned around the property actually being claimed, and run beside a control that must fail. Designing a test against what you meant rather than what you claimed is how a good implementation gets reverted.
And adding it exposed a duplication that had been there all along. The rotation chain was hand-copied at four transform sites — vertex position, vertex normal, cap normal, cap centre — so adding one rotation meant inserting the same six lines four times, and any one of them could have been missed or transposed silently, because a body with three correct sites and one wrong one still renders. A transform applied in four places is one rule with three chances to drift. It is now a single function of nine integers: byte-identical output, and 2.7 KB less assembly.
A duplication check run against our own dependency — and what it found
Before building on a file, we ran the cross-tree duplication detector against it. It came back RED, and the finding was sharper than "duplicate". Two files named nx_genome.nx exist in different source trees, and they are not two copies of one thing — they are two entirely unrelated capabilities that happen to share a filename.
One is a creature genome: a tree of part specifications joined at attachment points, with body plans for a human, a rabbit and a monster. The other is a breeding genome: bounded integer trait vectors with deterministic inheritance, for a game lane. Both are legitimately called a genome in their own domain. Neither name is wrong; the collision is.
Three measured consequences, and the third is ours: an existing organ calls the creature functions while its own gate imports from the tree where that name resolves to the breeding organ, which defines none of them; a second gate calls three functions that neither file defines, so it cannot pass as written; and our own creature phase would have imported from the tree that yields the wrong one, silently. The fix is a rename rather than a reconcile, and because it spans two lanes it has been filed with a proposal rather than applied unilaterally. The lesson is narrower than "avoid duplication": when two files share a name, check whether they are the same thing before calling one a copy of the other.
The stranded-organ finding, and a correction to it
Almost everything this programme needs already exists, is gate-tested, and is connected to nothing. The two organs that actually produce a body import the syscall library and nothing else — not the skeleton, not the muscle, fascia or skin stages, not the rig, the soft-body solvers, the inverse kinematics, the move library or the scene graph. There is not one line of connective tissue in the stack. Roughly 110 KB of proven, idle source.
The correction: an exploration concluded those gates had probably never been run, because each writes a named image on success and not one of those images exists. That inference was wrong. Running all seven: skeleton 19/19, flex-body 5/5, fascia 7/7, foot-check 10/10, skin 8/8, muscle 8/8, muscle-set 7/7 — 64 of 64 green. The organs are sound; only the wiring is missing. That is much better news than the alternative, and it means the next block of work is composition rather than rescue.
The skeleton settled one girdle and was refuted by the render on the other
A cross-artifact disagreement names a number to go look up. It does not tell you which side is wrong — and picking the side you built is how a program launders a guess into a fact. The skeleton and the body canon disagreed by 32‰ at the shoulder and 34‰ at the hip. So both went to the classical landmarks rather than to a vote.
The shoulder: the skeleton was wrong, and it is fixed. Its acromion had been placed 30‰ below the cervicale purely because that looked about right. Acromiale height is 818‰ of stature, which makes the offset 52. The joint now sits at 818‰, ten per-mille from the canon's own acromion ring — the right order of magnitude for a bone centre sitting inboard of the deltoid's outer bulge — and the canon's ring is anchored on the same constant. Two teeth pin it: one that the two artifacts stay within 15‰ forever, and one that the shoulder is derived from the sourced 818 rather than being two other numbers that happen to add up. They cannot drift apart again.
The hip: the anatomically correct number made the body worse, and the bench could not see it. The canon's ring is labelled "iliac, widest of pelvis" and sits at 496‰ — a height at which no pelvic landmark lives (the iliac crest is near 600‰; the widest breadth across the hips is bitrochanteric, at trochanterion 530‰). Moving it to 530 to match the skeleton gave the pelvis a hard horizontal rim and the silhouette of a bucket. Raising the crotch instead was worse.

The cause is structural, not a number. This pelvis is one tube that narrows to a 36-wide crotch at 470‰. With the widest ring at 496 the cone from hip to crotch spans 26‰ and reads as a rounded bottom; at the correct 530 it spans 60‰ and reads as a skirt with a rim. A real pelvis does not narrow between trochanter and crotch — it stays wide and splits into two masses. So the surface ring is reverted to 496 and explicitly labelled as a surface ring rather than a landmark, the skeleton keeps the true 530, and the disagreement is now explained instead of merely measured. When the anatomically right number makes the surface worse, the model is too coarse to hold it — moving the number anyway just relocates the error somewhere the ruler cannot see. Making the pelvis two lofted masses is the next rung, filed rather than faked.
Net against the cadaver oracle across this whole round: front IoU 282 → 285, side 126 → 127, shape 712 → 712, detail 51 → 50. Essentially flat. The round bought correctness and provable non-drift — five real toes, a skeleton whose chain closes on stature, and a shoulder both artifacts now agree on — not a realism gain. Saying otherwise would be the overclaim this page exists to avoid.
Stage one is finally a skeleton — and the test that closes it convicted the table we shipped
The skeletal stage generated eleven bone lengths and a set of joint ranges, and could not say where any bone was. No parent, no position, no shape. That is why the layers above it float: the muscle organ knew a lever arm but not where it hung, and the fascia lattice fell back to a vertical-only field because there was no articulated frame to hang it on. The operator's steer has been the same one all along — build the structure from the inside out, then layer onto it — and this was the missing inside.
It now emits 21 joints: five axial (pelvis, L5, cervicale, atlas, vertex) and eight per limb side, resolved into world millimetres by one forward-kinematics pass. Left and right come from one table read with the sign flipped, so the two sides cannot drift — and a tooth checks that every parent precedes its child rather than assuming the single pass is safe. The rows are additive (J idx parent side x y z alongside the untouched B rows), so nothing that already reads this file breaks. Rotation is deliberately absent: this generates the rest skeleton, and the existing poser is not going to be reimplemented.
The test that makes it honest is stature closure. Walk the chain from the ground through ankle, knee, hip, L5, cervicale and atlas to the vertex, and it must reconstruct the height you asked for. The table this organ shipped with summed to 960‰ — seventy millimetres short on a 1750mm body — from two errors that partially cancelled (the trunk 100‰ short, the head and neck 60‰ long), which is exactly why neither was visible alone. A table of plausible numbers is not anthropometry until something sums it. The corrected chain is landmark-anchored — ankle 39, knee 285, hip 530, L5 610, cervicale 870, atlanto-occipital 930, vertex 1000, each a place you can put a finger on a real body — so it closes by construction rather than by a fudge term. Dimorphism now conserves stature too: the trunk gains 8‰ and the femur and tibia give back 4‰ each, because a woman is not taller for having a longer trunk. Before this, the female skeleton overshot its own declared height and nothing in the organ could notice.
And I wrote the same bug this file already warns about, twenty lines below the warning. The closure tooth asserted residual == 0 and went red at 1mm — an exact-equality assertion over integer-scaled values, which is precisely what the comment on an earlier tooth in the same file documents as "a bug in the test, not evidence about the code." A comment warning about a mistake does not stop you making it again; only a tooth does. The honest claim is not zero but bounded by rounding, and the bound is derived rather than dialled: five rounded axial segments can never exceed five millimetres. A second tooth then sweeps every stature from 1200 to 2100mm at every sex to prove the bound is structural and not a coincidence at the one height I happened to measure.
Cross-checked against the body canon — a second artifact this program authored in a different rung. Two independent constructions agreeing on where a body's landmarks are is evidence; one artifact agreeing with itself is not. They agree tightly at the distal end: ankle 39‰ vs the canon's foot placement at 40‰ (1‰ apart), wrist 507‰ vs the canon's wrist ring at 500‰ (7‰), vertex 1001‰ vs the crown ring at 1010‰ (9‰). They disagree at the two girdle joints: shoulder 840‰ against the canon's acromion ring at 808‰ (32‰ ≈ 56mm), and hip 530‰ against the canon's hip ring at 496‰ (34‰). That is disclosed and unresolved. There is a plausible reason — the shoulder and hip are exactly where a bone centre and a surface ring are legitimately different things, the glenohumeral centre sitting below and inboard of the deltoid's outer bulge — but plausible is not measured, so it is written down as the number a future rung has to settle rather than explained away now. Gate: 8 teeth → 17, all green.
The toes are fixed — but first, the section below this one was wrong, and a judge caught it
RETRACTION of the diagnosis directly below. I claimed the toes had no part header of their own and that the emitter therefore wove one continuous ribbon through every toe. A measuring judge (nx_footcheck, built for exactly this) counted six parts in the foot's rotated frame — one foot tube plus five separate toe tubes. The part headers were there all along. I misread six byte-identical headers (every toe inherits the foot's placement verbatim: P 1 90 48 40 -41 0) as one repeated header. The lesson is now a law in the program file: when the rows you are counting print identically, print the index — a probe a human eye has to disambiguate is a probe that will be misread. Reading the generated data beat reading the generator; it still was not enough without a counter.
The real defect, measured by the judge on the shipped canon: the foot tube ran to y=145 while the toes based at y=118 — so 27 of each toe's 34 units were buried inside the foot tube. Only 7 units of the big toe cleared it at all: protrusion 46‰ of foot length against a 200‰ anatomical floor (toes are roughly a fifth of a foot). And the toes hung 3 units below the sole plane, so the figure stood on its toe tips. That is the blunt hoof with pale nubs, as numbers. The generator's own source comment even carried the correct instruction — "toes must REPLACE the flat toe-plate, not extend past it" — and only the second half had ever been applied: the toes were shortened to fit inside a plate nobody deleted. A half-applied fix is indistinguishable from no fix, and in the source it looks like a done one.
The fix, two structural moves, zero dialled numbers: the foot tube now ends at the toe line (y=118), and the ray-set rule emits every digit flush to a plantar/palmar plane — each ray sits at plane − its own radius, so five toes of five different thicknesses all land their undersides on the same ground line the heel uses. The plane value is not chosen: 40 is the foot tube's own constant sole line (every tube ring holds zoff+rb = 40, a flatness the canon already carried). The same rule now gives the hand a flush palm.


Proof chain: nx_footcheck gate 10/10 GREEN (fixtures prove it separates the buried foot from the fixed one, pins foot length, refuses a footless canon, and ignores comments); on the real canon it convicts the old generator (burial 27, protrusion 46‰, sole_break 3 → RED) and clears the new one (burial 0, protrusion 223‰, sole_break 0, foot length 152 unchanged → GREEN). Silhouette regression pinned by benching the fixed mesh against the baseline mesh: front 989 / side 984 / quarter 986 — the change lives at the feet and nowhere else. Every clause in the judge is a thing a foot is, not a score: one blended number is how the last three overclaims on this page survived.
Two probes, two different lessons, in one afternoon (kept from the retracted section, because they remain true): render the baseline before blaming new code, and read the generated data before reading the generator. To which today adds the third: then build the judge, because I misread the data too.
RETRACTED — Probing found the toe defect exactly — the digits have no part of their own
Retained as the record of a wrong diagnosis (see the correction above). The claim was: the toe rings follow in the same part with no header of their own, so the emitter lofts one continuous spline tube weaving foot into toe one, then toe two — and the fix would be a part header per ray. The judge counted the headers: they were already there, one per toe. The mechanism was wrong; the defect was real but different — burial, not weaving.
A fix that does nothing — reported, because I built it before measuring
I predicted the toe artifact came from thin structures having too few vertices to define a stable local axis, built the fix, and it turned out to be inert. Publishing that, because building before measuring is exactly the habit this program keeps having to unlearn.
The pass itself is correct and is a genuine safeguard: an under-populated band-side now inherits its axis from the nearest well-populated band above it, so a limb's axis continues rather than snapping back to the body centreline — which is what exploded the feet in the first place. A toe keeps the foot's axis; a fingertip keeps the hand's. Walking upward is the right direction because thin structures are distal: they hang off something thicker and nearer the body.
But on this mesh it never fires. 760,032 vertices across 48 bands and two sides is roughly eight thousand per slot, far above any sensible floor. The output is byte-identical before and after — same checksum, same render, to the byte. So the toe artifact has a different cause and remains undiagnosed.
So I probed, and the answer was not in my code at all. Three measurements, in order: the composed muscle profile reads exactly zero at every toe station — the toes receive no swell whatsoever, so deformation cannot be spreading them. The mesh is not truncated — 380,016 triangles against a 600,000 cap with 219,984 to spare — so it is not the class of bug where skin overruns its budget and lets muscle show through. And then the decisive one: rendering the undeformed baseline shows the same toe artifact.
★It was pre-existing in the body generator the whole time. Not the deformation, not the muscle set, not the per-limb axis — the toe geometry has looked like that since before any of this session's work touched it. The law, and it cost a whole build: render the baseline before blaming the new code. I had rendered the deformed body many times today and never once rendered the undeformed one at the same framing, so a pre-existing defect read as a regression in whatever I had just written.
The axis-conditioning pass stays — it is correct, it is a real safeguard for sparse meshes, and it is provably inert here — but it was built for a cause that did not exist. The true owner is the procedural toe emission in the body generator, and that is where the next look goes.
The last invented number, removed
The consumer was scaling the muscle profile by a constant I had chosen at the far end — a magic number, and a violation of this program's own rule that thresholds must be derived rather than dialled. It is now declared by the muscle set itself.
nx_myoset computes the largest composed swell any station on the body actually reaches and writes it into the profile file as a header row — M 173 for the current eight-muscle set. nx_flexbody normalises by that. Add a muscle, change a peak, and the consumer follows automatically; neither side can hold a stale number. The old constant survives only as a fallback for a file that carries no header.
That closes the last invented value in this chain. Every number now driving the body traces to something measured or derived: bone lengths from classical segment proportions, muscle girth from volume conservation, skin position from muscle plus fat, wrinkle from signed compression, tissue lag from a stability-bounded solver, and the swell normalisation from the muscle set's own peak.
Per-limb axis: the feet fixed, and a correction that applies everywhere
A limb swells about its own axis, not the body's — and that one change took the worst distortion from 113 down to 36. The exploded feet had a single cause: girth was being scaled radially about the body's centreline, and toes run forward, far from that line in depth, so the factor that is mild on a torso was violent on a foot.

The fix is structural rather than a clamp. An extra pass accumulates, per height band and per side of the midline, the local centroid of the surface — and that centroid is the limb's axis at that height, by construction. Sides split at the midline the way the profile-fitting organ already clusters limbs, so left and right arms get their own axes rather than sharing the body's.
An honest note on the regression, because it is not a no-op: the band path's peak displacement also moved, 50 → 33. That is not a regression — it is the same correction applying to both paths, since swelling a torso about its own local axis is more right than swelling it about the whole figure's centreline. But it means the earlier band result is not byte-identical, and saying “unchanged” would have been false.
Composing through data — what worked, and the defect it exposed
The muscle set now feeds the body as DATA, and driving it exposed two real defects — both contained, because the new path is opt-in and the shipped one was re-verified byte-for-byte unchanged.
What worked: nx_myoset writes its composed eight-muscle swell profile to a file, and nx_flexbody reads it rather than carrying a second copy of the muscle table. One source of anatomy, two organs, no derivation to drift — the same compose-through-data pattern that carried the forensic tissue depths into this pipeline earlier. It ran end to end: 760,032 vertices swelled, zero bone vertices moved, both gates green.
What broke, seen only by rendering it: the feet exploded. The toes fan out and expose the muscle layer beneath. Two causes, both worth naming: first, the swell scales radially about the body's vertical axis, and toes run forward — far from that axis in depth — so the same factor that is mild on a torso is violent on a foot. A limb needs a scale about its own axis, not the body's. Second, the profile-to-weight normalisation is an invented constant rather than derived from the muscle peaks, so a station whose composed swell approaches it receives the entire bulge.
And a trap this lane has fallen into before caught it again: the lit-pixel count fell from 83,789 to 77,087 while the body got wider — because the renderer auto-frames the visible bounding box, so a wider body pushes the camera back and renders smaller. Pixel count is not a valid size measure under auto-framing. That is the same class as the earlier discovery that a framing metric can move with the thing it measures.
Containment held. The profile drive is an optional sixth argument; the shipped band-taper path was re-run and matched exactly — same 1189‰ bulge, same 64,896 vertices, same zero bone, same 87,447 lit pixels. The defect is in the new road, not the one the body is standing on. Fix order is named: per-limb axis for the radial scale, then derive the normalisation from the muscle peak sum instead of a constant.
Named muscles, with real attachments — and they compose
The swell is no longer an anonymous height band; it is eight named muscles, each defined by where it attaches. A muscle is not a region — it is an origin on one bone and an insertion on another, and everything about its shape follows from that pair. nx_myoset carries pectoralis major, deltoid, latissimus dorsi, rectus abdominis, biceps brachii, gluteus maximus, quadriceps and gastrocnemius, with attachments in per-mille of stature so the set scales to whatever skeleton was generated. Gate 7/7 GREEN, registered.
And this is why the taper had to come first. Real muscles overlap. At the shoulder, three act at once — pectoralis major at weight 750, deltoid at 792, biceps at 640 — summing to a composed swell of 160. At the thigh the quadriceps acts alone at full weight, 85. Because every muscle fades to zero at its own attachments, those overlaps add smoothly instead of stacking into steps. The taper was never cosmetic; it is the property that makes a muscle set possible at all.
Its teeth are the ones that could catch a fake: locality — a biceps must contribute nothing at the calf, or the set is a global inflation wearing anatomical names; a relaxed body must be unchanged, since a muscle set that swells a standing figure is not a muscle set; and muscles must genuinely overlap somewhere, or the composition test is vacuous.
One tooth went red for an instructive reason. It asserted a fixed ceiling on the jump between adjacent samples of the summed profile — but a parabolic taper is continuous by construction, and sampled finely across a short muscle the finite difference near an attachment is naturally large. That is a steep slope, not a step. The real test for continuity is resolution-dependence: sample twice as finely and a smooth function's largest jump must shrink, while a genuine discontinuity keeps its height no matter how closely you look. An absolute threshold cannot tell those apart; that comparison can.
The laws, wired onto an actual body — and visible
Proven organs are not a body. Until the four laws drive the emitted mesh, the architecture is complete and the figure is unchanged — and a render is the only thing that can tell those two states apart. nx_flexbody closes that loop for the muscle-to-skin half: given a joint angle it applies nx_myo's volume-preserving bulge and nx_derm's envelope to a real layered mesh, as a radial girth change — because a muscle bulge is a girth change, and a vertical displacement would slide tissue along the bone instead of swelling around it. Gate 5/5 GREEN, registered.

The bulge is computed, not dialled. 1189‰ of girth at 90° is exactly what √(L₀/L) demands at that joint angle — the same number the muscle organ reports standalone, arrived at through the mesh. And the layer rule survives contact with a real body: bone moved zero vertices, verified in the output rather than assumed.
The first cut had hard step edges, and fixing them was the anatomy telling us the shape of the rule. A rectangular band produced visible discontinuities at the shoulders and waist, and the torso read as a swelled cylinder rather than a muscle. A real muscle belly is thin at its tendons and thick in the middle, so the swell must fade to nothing at both ends of its span. The band now carries a unimodal taper — zero at each edge, full at the centre, the same shape the digit rule uses to grade finger lengths — and the steps are gone: the torso swells and blends smoothly back into the shoulders and hips. That taper is also exactly what will let two overlapping muscles sum without a seam, since both fall to zero where they end. Same law, same 1189‰ bulge, same zero bone vertices; peak radial displacement eases 55 → 50 as the edges fade, which is the taper doing its job.
Remaining, and named: the swell is still a height BAND, not a muscle. Binding to named muscles with real origins and insertions on the generated skeleton is the next step — the taper is the mechanism that makes those compose.
Stage 4 landed — and all four stages now have physics
Skin stopped being a shell that merely renders outermost and became an envelope computed from what is under it. Ours was independently emitted, so nothing about it was derived from the muscle beneath — which meant nothing could wrinkle, stretch or slacken when the body moved. The layer stack had the right topology and the skin was not actually on anything. nx_derm inverts that. Gate 8/8 GREEN, registered.
Position is derived, not authored. Skin rides at muscle plus fat, so when nx_myo bulges a muscle the skin above it rises by construction — no second edit to keep in sync, and no way for the two to disagree. The envelope invariant, that skin can never sink beneath the muscle it covers, is enforced arithmetically rather than checked afterwards.
And stress is what makes it skin rather than a balloon. When the surface beneath shortens, the skin above has more area than it needs and that slack goes into folds; when the surface lengthens, the skin is pulled taut and smooths. Wrinkles are therefore a function of signed compression, which means they appear where a body actually creases and nowhere else.
The whole stack, composed: one joint angle drives bone → muscle → skin
| joint flex | muscle radius | skin radius | stress | wrinkle |
|---|---|---|---|---|
| 0° straight | 100 | 120 | 0 | 0 — smooth |
| 60° | 107 | 127 | +70 | 0 — taut |
| 120° | 141 | 161 | +410 | 0 — taut |
| 150° full flex | 195 | 215 | +950 | 0 — stretched |
That column of zeroes is the model being right, not the model doing nothing — and it is worth spelling out. On the extensor side of a bending joint the muscle bulges and stretches the skin taut, so it must not crease. The creasing happens on the other side, where the surface shortens:
| flexor side, surface shortening | stress | wrinkle |
|---|---|---|
| −10% | −100 | 80 |
| −30% | −300 | 240 |
| −50% | −500 | 400 |
| −70% | −700 | 400 — bounded |
The inside of a bent elbow creases while the outside stretches, which is what a real arm does, and it falls out of the stress sign rather than being painted on.
★With this, every stage of the industry pipeline in the table below has physics rather than shape: generated bones with joint constraints that refuse, volume-preserving muscle bound to those bones, fascia bridging muscle to skin with the skeleton rigid, and skin derived from all of it. Seven organs, 59 gate teeth, all green. What remains is integration — the laws are proven as organs and are not yet all wired into the emitted body — and that is now the honest gap rather than the architecture being absent.
Stage 2 landed: muscle that bulges because volume is conserved
The stage that was completely untouched now has physics, and the bulge is arithmetic rather than an authored curve. What this program called muscle was one scaled envelope at 82% of the skin radius — a shell bound to nothing, conserving nothing, incapable of bulging. nx_myo replaces the idea entirely. Gate 8/8 GREEN, registered.
The defining property is incompressibility. A muscle belly is very nearly incompressible, so drawing its ends together cannot simply shorten it — it must thicken by exactly the amount that keeps its volume constant: radius = r₀·√(L₀/L), so length × cross-section is invariant. That is why a flexed biceps bulges, and it is a hard arithmetic constraint rather than an artistic choice. A generator that merely thickened a muscle by some tuned factor would look approximately right and be unfalsifiable; this one is checkable — measure the volume before and after and it must not move.
And it is bound to bone. The muscle spans an origin on one bone and an insertion on another, so its length follows from the joint angle by the law of cosines. The only input is how far the joint is flexed — there is no separate muscle animation and no hand-authored bulge curve.
| joint flex | muscle length | radius | bulge | volume error |
|---|---|---|---|---|
| 0° (straight) | 2000 | 100 | — | 0 |
| 60° | 1732 | 107 | 7% | 0.8% |
| 90° | 1414 | 118 | 18% | 1.5% |
| 120° | 1000 | 141 | 41% | 0.5% |
| 150° (full flex) | 521 | 195 | 95% | 0.9% |
The gate opened at 2/8 and the mathematics was never wrong — the convention was inverted. Flex is measured from straight: 0° is an extended joint where origin and insertion sit furthest apart, 150° is fully bent where they are closest. I had taken 150° as the rest pose, so every comparison ran backwards and six teeth failed truthfully. When an entire battery fails at once, suspect a sign or a convention before suspecting the maths.
Its teeth are the ones that make the claim falsifiable: volume conserved across the whole range rather than at one convenient angle, the bulge provably real rather than a rounding artifact (a muscle whose radius never moved would satisfy conservation trivially and simulate nothing), monotonic with no inversions, and a degenerate zero-length muscle refused rather than divided by.
Stage 1 has begun: generated bones, and joints that refuse
The bottom layer now generates itself, and its joints constrain. nx_skelgen derives bone lengths from classical segment proportions expressed as per-mille of stature — femur 245, tibia 246, humerus 186 — so the same rules produce a child, an adult or a giant, with the sex knob shifting ratios the way real dimorphism does. Gate 8/8 GREEN, registered.
The joint constraints are the part that matters, and they are fail-closed. A knee that can bend backwards is not a skeleton, it is a bag of segments. Every joint carries an anatomical range and a pose outside it is refused, not silently clamped — because a clamped pose looks like working animation while lying about what the body did. Probed live: knee at −30° returns illegal, knee at 90° returns legal, range [0, 140].
It composes rather than duplicates. A skeleton format with linear-blend skinning already existed in this codebase; what was missing was anything that generated lengths from parameters or constrained a joint at all. This organ produces the rows that one consumes. The duplication check ran first, as it now does every round.
One tooth went red and the assertion was wrong by construction: it required that doubling the stature exactly doubles the femur, but 245×1750/1000 rounds to 428 while 245×3500/1000 rounds to 857, and 428×2 is 856. Integer scaling cannot promise exact proportionality — rounding lands within one unit and no closer. An exact-equality assertion over integer-scaled values is a bug in the test, not evidence about the code. The length rule now rounds rather than truncates (worth a millimetre per bone, which accumulates down a limb chain) and the tooth asserts proportionality to within rounding, which is what a scale-free rule can actually guarantee.
Stage 3 is now physics — and it took two bugs the gate structurally could not catch
The tissue simulation ran, measured correctly, passed every tooth, and was invisible. Rendering it was the only thing that revealed why — twice.


Bug one was dimensional. The binding applied the solver's raw displacement straight to mesh coordinates. The solver works in a space where a full excursion is a few dozen units; the mesh is in model units where the figure stands tens of thousands tall. Tissue moved about five units on a body two hundred thousand high — real, bounded, deterministic, and utterly imperceptible: 26 changed pixels out of 84,000. A displacement is a fraction of the figure, not a raw count, so the solver's full excursion now maps onto a fixed per-mille of the mesh's own height — roughly two percent, which is about what real tissue travels — and it works at any scale.
Bug two was sharper, and it is the better lesson. After fixing the units the displacement got smaller. The binding stepped the whole simulation and then read each band's displacement — by which point the tissue had settled back onto its anchor and the lag was gone. Peak lag read 40 during the motion while the applied displacement read 4. I was measuring the physics at the moment it had finished happening. A transient is only observable while it is transient, so the binding now snapshots each band at its own most-lagged state and deforms from that — which is also exactly the frame a renderer wants. Max displacement went 4 → 35, and the visible change went up a hundredfold.
★Neither bug was catchable by the gate, and that is the point worth keeping: the gate tests the SOLVER, and the solver was right both times. The BINDING was wrong — first dimensionless, then sampled at the wrong instant. A green gate on a correct component says nothing about whether it was connected correctly. Render the thing.
Stage 3, as it now stands
One of the four pipeline stages just stopped being a shape and started being a simulation — and the solver had been sitting built and gated in this codebase, unused, the whole time. nx_fascia binds the soft-body solver to the emitted muscle and fat layers. On the shipped body it deformed 760,032 soft vertices, and verts_moved_bone read exactly 0.
That zero is the whole design. The binding is a layer-aware lattice: solver points sit on a band lattice over the figure, and every vertex is displaced by its band's point scaled by the softness of its own layer — bone scales to zero and therefore cannot move, muscle moves partly, skin and fat move fully. That is fascia doing its actual job: transmitting motion from the rigid thing inside to the soft thing outside, each layer lagging by its own amount. A global wobble would move the skeleton too.
| measurement on the real body | value |
|---|---|
| soft vertices deformed | 760,032 |
| bone vertices moved | 0 — rigid by construction |
| peak lag / settled energy / max displacement | 40 (at the clamp) / 1488 / 2 |
| gate | 7/7 GREEN |
The gate went red twice on the same tooth, and both times the test was wrong rather than the code — for two different reasons worth keeping. The tooth asserts that stiffness controls the response, without which a solver that always wobbles identically would pass everything else and be simulating nothing. First attempt compared peak displacement and failed: a stiff, lightly-damped spring rings, so its instantaneous peak can exceed a soft one's even while tracking far better on average. Second attempt compared settled lag and also failed — because the solver is a pure spring-damper to its anchor with no external load, so every configuration converges exactly and steady-state lag is zero for both. The assertion could never have been true. The property that genuinely distinguishes stiffness is tracking while the anchor is still moving, and measured that way it passes. Read the solver's contract before asserting a property of it; the physics was in the source all along.
The build was also stopped by the ecosystem's own duplicate guard, which is the second time that check has earned its keep in two rounds. The name nx_tissue already belonged to a voxel-grid storage organ, and the build refused rather than resolving the wrong twin and leaving a stale copy behind. Renamed to the anatomically precise term instead of clobbering a sibling.
The goal, and the architecture that reaches it
Standing goal, set by the operator: iterate until MetaHuman quality is the FLOOR — reached bottom-up, by building each layer intricately. Not matched once; exceeded as a baseline.
The industry builds humans inside-out in four stages, and this is the architecture we are held to (benchmarks: Ziva VFX's tissue physics, Reallusion's Character Creator, MetaHuman Creator, Houdini's Vellum and muscle tools):
| stage | what it does | our honest state |
|---|---|---|
| 1. Skeletal generation | algorithms define bone lengths and joint constraints from height and proportion parameters | PARTIAL — nx_skullgen generates 7 skull bones as rules (gated 6/6, deterministic, dimorphic) but its v1 anatomy is wrong, there is no generated body skeleton, and no joint constraints. Our working rig runs on borrowed scanned bones, not generated ones. |
| 2. Muscle simulation | volume-preserving meshes bound to the bones, computing authentic bulging and flexing | GAP — our “muscle” is one scaled envelope at 82% radius. Not named muscles, not bound to bones, no volume preservation, no contraction. |
| 3. Fascia and fat layering | soft-body tissue simulation bridging muscle to skin | GAP — fat is a scalar knob attenuating how much muscle relief reaches the skin. No tissue, no sliding, no simulation. |
| 4. Skin deformers | the visible mesh is an envelope computing wrinkles and stress from inner-layer movement | GAP — our skin is an independently emitted shell that merely renders outermost. Nothing wrinkles or stresses from movement, because nothing is driven by the layers beneath. |
The verdict this produces is uncomfortable and worth stating plainly: we have the layer stack's SHAPE but almost none of its PHYSICS. The differentiator this program has claimed — a nested bone→muscle→skin body where outer form emerges from what is underneath, which neither Infinigen's single-surface creatures nor a single-shell body model has — is honest about topology and not yet honest about simulation. Three of the four stages are the shape of a thing rather than the thing.
So the build order is the pipeline itself, and each stage gets its own ruler before its features, which is the law this program already runs on: skeleton with joint constraints, then volume-preserving muscle bound to bone, then fat and fascia as soft body, then skin as a true envelope. That ordering also explains every failure documented further down this page — features were being placed on a surface that had nothing underneath to place them against.
The 2026 field, and two of our blockers dissolving
The open-source state of the art in 2026 is Genome — a learned statistical model over thousands of real 3D scans, guaranteeing vertex correspondence and anatomically consistent bone-to-skin proportions, generating from text, image or motion. We cannot honestly replicate it, and saying so is the point: a statistical shape space needs a population, and we have exactly one cadaver oracle. Genome is a capability benchmark, and its scans and weights are not ours to ship — the same posture this program takes toward CUDA, Infinigen and MetaHuman.
But two named blockers dissolve against this landscape, and one of them is an asset we already own.
First: Anny is the template that fits our constraint exactly. A fully differentiable, scan-free parametric human whose shape space comes from official WHO anthropometric data — published statistics anyone can encode — laying continuous phenotype axes without losing anatomical logic. That retires the blocker filed against this program's village work: the correlated shape manifold needed a population covariance we thought we could not source, and the covariance we need is published, not scanned. Borrowing published mathematics was always legitimate; shipping someone's assets or runtime is what is not.
Second, and cheaper still: the Ziva-class tissue solver we need is already built and gated in this codebase, and has never been wired in. AdonisFX 2.0 has taken Ziva's place commercially with interactive multi-layer tissue solvers; the open-source world otherwise leans on Blender physics or custom Houdini nodes. Ours is nx_softdyn — a spring-damper soft-body solver whose stability envelope is enforced by construction (past a certain damping the integrator inverts and amplifies velocity, so the caps make an unstable configuration impossible to request rather than merely discouraged), gate 7/7 GREEN including an anti-vacuity tooth, and replay-deterministic. It was never bound to tissue because when it shipped there was no soft-tissue geometry to bind it to.
The emitter now produces muscle and fat layers. Binding the solver to those layers is stage three of the pipeline above — fascia and fat as soft body, bridging muscle to skin — and it is a wiring job across two already-gated organs rather than a new build. That is the cheapest large move available, and it converts an entire stage of the table above from “shape” to “physics.”
What “above MetaHuman” means here (so the claim can ever be verified)
(a) PARITY — no MetaHuman-parity axis left at GAP, every verdict backed by an on-disk artifact; (b) EXCEED — at least 3 HAVE axes MetaHuman structurally cannot do: inside-out anatomy (bone→muscle→skin layers), bit-exact determinism, procedural village generation, full sovereignty (no engine license lock); (c) the perceptual side-by-side number climbing and published every rung — measured, never asserted.
Phase 1 finding: the head judge was flattering our face by 3×
Measured this round — our face is 79‰, not 227‰. Every judge so far scored the head inside a whole-body frame, where a head is a few percent of the pixels. A new instrument, nx_headcrop, crops any mesh to its own top y-band, so ours and the cadaver oracle can be benched head-to-head at full render resolution. At that scale: surface detail 79 (front 44, back 115, quarter 65) against the oracle — while silhouette stays high (front 828, side 832, shape 856). Our head is head-shaped and surface-featureless. The instrument is non-vacuous: oracle-vs-itself returns 1000 on every judge at the same framing.
The evidence — same renderer, same framing, same scale (ours 173,239 lit px vs oracle 172,333)


The root diagnosis, and it names the next build: our face is PAINTED, not SCULPTED. The features we have are per-triangle colour regions on an unmodified ovoid. That is the same class of error the operator caught at body scale (“outside painting, not layered from the first cell up”), now found at face scale — by measurement this time, not by eye. Colour cannot create the up-facing and down-facing surface that light needs, which is why the surface judge reads 44 on the front view.
Why this is the right kind of result: it is the fifth time an added judge has lowered our number and made it true (837→313 when the detail judge landed, 380→255 on the three-quarter view, →227 on the head region, now →79 at head scale). Had we built face geometry first and scored it on the body-frame judge, we would have credited ourselves with gains the real instrument cannot see — exactly the trap that cost a false claim two rungs ago. Instruments before features.
Phase 1 rung 2: the first real facial GEOMETRY — honest headline 237 → 288
A nose, generated by rule, moved the binding judge +51. The diagnosis above named the fix: features must be geometry, not colour. The generator now emits a nose PART — four control rings whose projection, alar width and station heights are computed from anthropometric ratios and the sex/stylize knobs, not typed as coordinates (the same rule-not-table discipline that earned the digits their gain). Controlled A/B, same canon, one variable:
| judge | control (no nose) | nose | Δ |
|---|---|---|---|
| detail_head — the binding judge | 237 | 288 | +51 |
| detail (whole body) | 371 | 374 | +3 |
| detail_front | 335 | 341 | +6 |
| front / side / shape IoU | 866 / 831 / 934 | 866 / 831 / 934 | 0 |
| honest headline = MIN(all six) | 237 | 288 | +51 |
The whole-body detail judge barely moved (+3) because a head is a few percent of the pixels — exactly the average-blindness this lane has measured before. But the honest headline is the minimum across every judge, the head was the judge that bound it, and so fixing the face moved the program's headline number by more than any single rung in recent memory (for scale: generating the digits was worth +11 across three rungs).


The eyeball drove an iteration the number could not see. The first nose measured the same +6 on the front view but read as a floating button: its dorsum rings were too narrow and sat buried inside the head surface, so the bridge never emerged. Widening the dorsum and keeping it projecting up to the nasion produced the render above — visibly a nose rather than a blob, at an identical detail score. Numeric judges cannot see that a nose is not nose-shaped.
A real defect was fixed at root to make this possible. The emitter's part arrays were six bare mmap(16*8) allocations with no bound check on the parser's write — and the canon already carried exactly 16 parts, so a 17th (our nose) would have written past the end of an allocation driven by an external file. It is now a named, raised constant with a fail-loud refusal: proven byte-identical on the existing canon (same md5), and mutation-proven to refuse a 49-part canon with a clear message, exit 4, and nothing written.
Phase 1 rung 3: a rising number we REFUSED to ship
The rest of the face (lips, chin, brow ridge, ears) was built as ruled parts, measured detail_head 288 → 333 → 357 across two correction passes — and was REVERTED, because the face got visibly worse each time. The brow first rendered as a black-barred shelf that read as goggles; after correcting its material and halving its projection it read as pointed flanges beside the painted brow band. The chin read as a duckbill below the mouth. The lips never became visible at all. The revert is verified exact: 17 parts, head back to 288, both gates GREEN.


Why the judge was fooled, and it is the reusable part: the detail judge scores local normal variance — how busy the surface is — and it cannot ask whether that busyness is anatomy. Feature-shaped bumps in the wrong places score exactly like features in the right places. This is the same failure this lane has now seen three times in three different materials: procedural noise once scored above a real render, a bell-shaped body once outscored a good one, and now facial bumps outscored a cleaner face. A rising number is not permission to ship.
Three things the next attempt needs — all of them, or it reproduces this result: (1) retire the painted colour bands first, because the head's mat-5 brow and lip bands are calibrated for the head's own geometry and land arbitrarily on a small part — paint and geometry fight each other; (2) a head-region judge that scores placement against oracle landmarks, not variance alone — the instrument that would have failed this attempt on the first pass; (3) the structural unlock: rotation about Z. A brow ridge and a lip run horizontally, but the part system stacks rings along Y and can only rotate about X, so a horizontal feature can currently only be built as a vertical blob. That is the real reason these read wrong, and it is a mechanism gap, not a tuning problem.
A second silent-failure defect was eaten on the way. The emitter stopped emitting triangles at its cap with no signal — the documented root of the “red face” bug, where the skin layer is emitted last so a full budget silently drops the head and hands and they render as the muscle layer beneath. It now reports tri_cap, tri_headroom and a truncated flag on every run, and the cap was raised 400k → 600k after the face parts came within 6,568 triangles of it.
Phase 1 rung 4: the judge that fails wrong anatomy — and it scores the rejected face 0
⚠RETRACTION, published not silently edited: the 318-vs-0 result first reported here was a LOW-RESOLUTION ARTIFACT, and sharpening the instrument killed it. That reading came from a judge that resolved only 2 landmarks on the oracle, so matching one of two scored 318 and matching neither scored 0. After the resolution fix below the judge resolves 19, and at anatomical resolution the two faces are statistically tied — 84 against 83. The conclusion that the rejected face should not ship still stands; the margin I published for it did not.
| face | variance judge | placement judge (2-landmark, RETRACTED) | placement judge (19-landmark, current) | the eye |
|---|---|---|---|---|
| shipped — nose only | 288 | 318 | 84 · recall 204 · precision 416 · 5/19 | clean |
| rejected — brow flanges, duckbill chin | 357 — ranked higher | 0 | 83 · recall 238 · precision 352 · 6/19 | wrong |
| oracle vs itself (non-vacuity) | 1000 | 1000 (2/2) | 1000 (19/19) | — |
And the decomposition is more useful than the verdict it replaced. The rejected face scores higher recall (238 vs 204 — more of its bumps happen to land near a real landmark) and lower precision (352 vs 416 — more of them correspond to nothing). Adding those features bought recall and paid for it in precision, netting zero. That is a far more precise statement of what went wrong than “it scored 0”, and it matches the eye exactly: the extra features were not absent anatomy, they were misplaced anatomy. Both faces sit around 8% of a real face — neither is close.
How it works, and why bumps cannot buy a score. A human face read down its midline is a fixed sequence of alternating depth extrema — brow, nasion, nose tip, subnasale, upper lip, mouth groove, lower lip, chin. The judge extracts that profile straight from mesh geometry (no rendering, no learned model, no third party), detects landmarks by prominence, and scores recall × precision: recall credits each oracle landmark found near its true place, with credit decaying to zero past tolerance; precision is the fraction of our extrema that correspond to a real landmark. Every spurious feature cuts the score. That multiplication is the whole anti-Goodhart property — the thing a variance measure structurally cannot do.
Its 7-tooth gate is where the design was proven (GREEN over live MCP): a corrugated profile with more extrema than the oracle scores under half; a featureless smooth profile scores 0, so absence is seen rather than forgiven; and shifting every landmark by one band, with an identical extremum count, strictly lowers the score. The gate ran RED first — on that placement tooth. The test had shifted landmarks past the tolerance, so scoring zero was the judge behaving correctly and the test was wrong. Rather than loosen the tolerance to buy a green, the case was split into two teeth: credit decay inside tolerance, hard zero outside it. The gate caught a real specification question and the instrument came out sharper.
The resolution fix — the foundational work, done rather than deferred. The judge had resolved 2 landmarks where a face has seven or more, and the cause was measured: the nose swings about 100‰ of whole-head depth while the brow is a 5‰ rise, so a fixed prominence of 28 could only ever see the nose. Three changes, each principled rather than dialled: the midline narrowed from ±1/14 of head width to ±1/48, because taking the most-forward vertex across a wide swath means the profile follows the nose and smears every smaller feature into it; the band count doubled to 96, because a 48-band profile puts about five bands across a lip; and the prominence threshold is now derived from each profile's own noise floor — the median adjacent-band difference, median rather than mean so that the nose, a genuine outlier, cannot drag the estimate up until it hides everything smaller. Result: 19 landmarks resolved on the oracle at a derived threshold of 12, with oracle-vs-itself still a perfect 1000 across all 19. The threshold now travels in the output on every call, because a judge that hides the number it thresholded on is unauditable.
The gate went red twice during this work, and both times the test was wrong rather than the code. The first was the placement tooth, described above. The second was the anti-Goodhart tooth: under the new threshold a uniformly corrugated profile raises its own noise floor above its own swing and yields no landmarks at all, so the old assertion that it must produce more extrema than the oracle no longer held. Corrugation is now rejected one step earlier and more honestly — it is classified as noise rather than as a crowd of wrong features — and the tooth was rewritten to assert that mechanism directly, plus a new one proving it. The gate went from 7 teeth to 8, all GREEN. Neither red was resolved by loosening a threshold to buy a green.
Phase 1 rung 6: rotation about Z — the mechanism unlock, and a real brow ridge
The best face this program has produced, and one judge cannot see it. The part system could only stack rings along Y and rotate about X, so a brow ridge — which runs horizontally — could only ever be built as a vertical blob. That was the structural cause of the goggles and flanges, not a tuning problem. Parts now carry a seventh field, rotation about Z, and the brow is what it actually is: one continuous ridge sweeping across the face with a glabella dip at the midline, catching light on top and casting shadow beneath.


The mechanism was proven before it was used, on a two-tube fixture: an unrotated tube stands vertical, a rotZ=90 tube runs horizontal, caps and shading correct. And it is additive by construction — an absent field parses as zero, zero gives an identity rotation that is integer-exact, and the standing canon regenerated to a byte-identical md5. The mirrored side takes the negated angle so a left feature is the true mirror of the right.
Two failures on the way, and the second one is the reusable lesson. The ridge first emerged only at its outer tails, reading as two small tabs: a straight horizontal ridge exits an ellipsoid skull at the sides, so the rings now sweep back with lateral distance — which is also what the anatomy does. Then it vanished entirely, because its front reached 53.6 while the skull's own depth radius at the brow line is 58: it was inside the head. The fix was not to dial the number but to adopt Infinigen's own construction rule — attach relative to the parent: the caller passes the skull's brow-line depth and the ridge buries its axis a fraction of its own radius beneath it, so the belly rides proud of the surface at any head scale, for any character. Verified across the sex and stylize grid.
⚠The judge that cannot see it — declared, not hidden
The landmark judge scores the midline profile, and it rates this face 69 — identical to having no brow at all — while rating the two visually worse buried versions 114. The reason is structural and worth stating plainly: a brow ridge lives laterally, and its midline point is the glabella dip — deliberately the lowest part of it. A one-dimensional midline slice is blind to a laterally-distributed feature by construction. Worse, the 114 those buried versions earned came from stray geometry intruding into the midline band — the judge was rewarding an artifact, which is the same trap as the variance judge one level deeper.
So the shipping decision rests on the judges that can see it: the head-region judge moved 288 → 316, which is the program's binding number, and the eye is unambiguous. This lane has been here before — when correct work scores worse, suspect the instrument before reverting the work. The named fix is off-midline sampling: profiles at several lateral offsets, or a three-quarter profile, so laterally-distributed anatomy is measurable at all. Until that lands, the midline score must not be quoted for features that do not live on the midline.
Phase 1 rung 7: off-midline lanes — the blindness closed, and measured to the digit
The judge that could not see the brow ridge now sees it, and the blindness it had is now a number rather than an argument. The profile is no longer a single midline slice but a set of parallel lanes across the face, each yielding its own landmark sequence and its own score, with the headline taken as the worst lane. Same brow, same meshes, measured before and after:
| lane | control (no brow) | with the brow ridge | Δ |
|---|---|---|---|
| −2 (outer / temple) | 337 | 364 | +27 |
| −1 (over the orbit) | 139 | 184 | +45 |
| 0 (midline) | 69 | 69 | exactly 0 |
| +1 (over the orbit) | 97 | 134 | +37 |
| +2 (outer / temple) | 147 | 123 | −24 |
| mean of lanes | 157 | 174 | +17 |
| oracle vs itself | 1000 across all five lanes | non-vacuous | |
The two lanes that pass over the brow bellies moved +45 and +37. The midline moved precisely zero. That zero is the point: the previous rung's claim that a midline slice is structurally blind to a laterally-distributed feature was an argument, and it is now a measurement to the digit. The headline stays 69 because the headline is the worst lane and the midline is still our weakest region — the brow did not change the nose, the lips or the chin, and the judge correctly refuses to let a good lane cover for a bad one.
Its standing tooth is a fixture, not an assertion. The gate writes a synthetic mesh carrying a flat wall on the midline and a bump placed only to one side, then requires the lateral lane to see the bump and the midline lane not to. If lanes were cosmetic, both would read the same. That tooth failed on its first run — the fixture had put its geometry where no lane samples, since the lane windows are deliberately narrow — so the fixture was corrected rather than the tolerance widened, and the gate went from 8 teeth to 10, all GREEN.
This is the pattern the whole program runs on, stated plainly: a capability is only real once an instrument can see it, and an instrument is only trustworthy once something it should have caught has caught it out. The brow exposed the blindness; closing the blindness measured the brow.
Phase 1 rung 8: one lip rule, instantiated as the pair — and the binding number finally moves
The headline lane moved for the first time: 69 → 92. A lip was built as one rule — a horizontal roll fullest at the midline, tapering to the commissures, tucking with the curve of the face — and then instantiated twice: a thinner upper lip sitting higher, a fuller lower lip projecting more. The mouth itself is the gap between the two instances: no geometry is emitted there, so the shadow line that reads as a mouth is a consequence of anatomy rather than a rectangle painted on an ovoid. Its painted band is retired in the same change.


| judge | before (brow only) | with the lip pair | Δ |
|---|---|---|---|
| lane 0 — midline, the binding lane | 69 | 92 | +23 |
| headline (worst lane) | 69 | 92 | +23 |
| mean of lanes | 176 | 179 | +3 |
| whole-body detail_head | 316 | 348 | +32 |
The first attempt failed, and both instruments said so. Sized at a 6‰ radius with a hard back-sweep, only the midline tip cleared the skin and the mouth rendered as a single nub — the lane judge reported the midline exactly unchanged and the eye agreed there were no lips. That agreement is worth as much as the later gain: an instrument that reports “nothing happened” when nothing happened is one you can believe when it reports something did. Resized to real proportions — a mouth is about 50mm wide and 18mm tall on a 1750mm figure, with corners that tuck rather than sweep — and both moved together.
This is the construction principle the program now runs on: perfect one unit, then aggregate it, layer on layer. One digit rule gave both hands and both feet; one lip rule gives the upper and the lower; the same machinery will give an eyelash, then a lash line, then a groom. Each level's realism rests on the level beneath it, and every level gets its own measurement before it is built upon.
Phase 1 rung 9: two findings that cost three attempts — and neither was a tuning problem
Finding one: the mouth was never mispositioned. The shipped lips read as sitting too low, and the obvious move was to raise them. Measuring first said otherwise — our mouth centre sits about 24% of the way up the head from the chin, and a real mouth sits about 25%. The height was already right; the mass BELOW it was missing. A mouth with no chin under it reads as falling off the bottom of the face no matter where you put it. When a feature looks mispositioned, check whether its neighbour is missing before you move it — proportion is read from what surrounds a feature, not from the feature alone.
Finding two, which cost three measured attempts and is the more valuable one: a chin is not a part. Built as its own horizontal roll it was tuned three ways, and every one failed differently:
| attempt | headline | mean | detail_head | what actually happened |
|---|---|---|---|---|
| y 868, mass 13 | 104 | 211 | 380 | a pointed witch-chin jutting past the jaw silhouette |
| y 876, mass 9 | 69 | 162 | 352 | swallowed the lips — its top edge reached 885, the lower lip sits at 881 |
| y 866, mass 10 | 72 | 201 | 399 — best measured | still two stacked lobes, a ball under the mouth |
| shipped (no chin) | 92 | 179 | 348 | reverted, verified exact |
The best number of the three was rejected. 399 on the head judge is the highest this program has measured, and it renders as a ball stacked under the mouth — structurally wrong in the same way the duckbill was, not merely unperfected. A chin is the front of the JAW: the visible end of one continuous mandible-and-soft-tissue mass running ear to ear. Modelling a prominence of that mass as an isolated tube can only ever stack a lobe under the mouth, which is precisely what all three attempts rendered. The unit to build is the jaw; the chin is then a property of its front, the way the glabella dip is a property of the brow ridge rather than a part of its own.
★THE ROOT CAUSE, named by the operator the moment these results were published: we are not building from the inside out — there is no SKULL. Every feature this rung fought with is, anatomically, a property of bone: the brow ridge is the supraorbital margin of the frontal bone, the chin is the mental protuberance of the mandible, the cheekbones are the zygomatic arches, the eye sockets are the orbits. Our head is a smooth skin ovoid with no bone beneath it, so features get stuck onto a blob rather than emerging from a structure — and stacked pieces are exactly what stacked pieces look like. That is why no amount of tuning fixed the chin, and why the fix I had reasoned my way to (“build the jaw, not the chin”) was only one level short of the real answer: build the skull, and the jaw, brow, orbits and cheekbones are all properties of it.
The architecture already supports this and is simply not being used for the head. The body is a nested bone → muscle → skin stack in which the outer form emerges from the layers beneath — that is the differentiator neither Infinigen nor a single-shell body model has. But the head is currently one ring-tube in the skin layer with no bone layer at all. And the benchmark is already ingested: a real 171,248-triangle BodyParts3D skull, which is 3.5× the triangle count of our entire body and, tellingly, still the best-looking thing this program has ever rendered — because it is the one thing we did not generate. Procedural cranial generation scored against that reference is now the named next build.
And the judge caught a collision the eye had missed. The second attempt cured the jut and looked plausible, but every lane collapsed to the pre-lip baseline — because the chin's band overlapped the lip's band and absorbed it. A feature part occupies a band, not a point; when adding one beside another, check that their extents do not overlap, and let the judge tell you when they do. That is the instrument earning its keep in the opposite direction from usual: not catching a wrong feature, but catching a right feature being destroyed by its neighbour.
Phase 2 rung 1: the skull, generated — and it came out an egg
The generator works and the anatomy does not — both are worth publishing. nx_skullgen emits a skull as rules, not as a modelled asset: a canon of seven named bones (neurocranial vault, supraorbital margin, zygomatic arches, maxilla with alveolar arch, nasal bones, mandible with the mental protuberance, mandibular rami) plus six hollows, generated from cranial proportion and the sex and robusticity knobs, then turned into 54,648 triangles by the same emitter that builds the body. Its gate is 6/6 GREEN: every named bone present, sex-dimorphic, robusticity-responsive, deterministic — the same parameters produce the same skull byte for byte — and seeded variation runs.


The diagnosis is exact, and it is this program's recurring law one level up: every facial bone is INSIDE the cranial vault's volume. The vault was written as a single ovoid spanning the whole skull height, so the maxilla, the zygomatic arches and the mandible all sit inside a shell whose half-depth exceeds their own offsets — only the zygomatic arches' end caps emerge, and those are the two white discs. A real neurocranium is the brain case only, occupying roughly the upper sixty percent; the facial skeleton hangs from its front and below. It is not modelled inside it.
Three fixes follow directly, and the third is a finding in its own right: shrink the vault to the braincase and end it above the orbits; attach every facial bone relative to the vault's actual surface at its attachment height — the same parent-derived rule that fixed the brow, now applied bone-to-bone instead of feature-to-skull; and stop trying to cut the orbits and nasal aperture as negative relief. Relief modulates a radius and cannot cut a hole — precisely the same limitation that meant an F-row could never make a nose. Openings between bones have to be openings, which means the vault and the face must be separate shells that meet, not one mass with dents in it.
This is the honest state of the keystone: the machinery for generating a skeleton from anatomical rules now exists, is gated, and is deterministic. What it generates is not yet a skull.
Phase 2 rung 2: a duplication audit that stopped the build — we already had an inside-out face
Asked to check for duplication before building further, the audit found that this program has been solving a problem it had already solved — and I am the one who duplicated it. nx_faceanat, written on 2026-07-08 from the same operator directive — “get the skeleton then muscles then skin, not outside-in” — already derives a face inside-out: positions from the anthropometric rule of thirds and fifths, and depth from forensic soft-tissue-depth tables giving the measured millimetres by which skin sits proud of the bony skull at each landmark. Brow ridge proud, nasal root shallow, cheekbone proud, temple recessed. It even records catching a bug where its relief came out ten times too proud.
That table is precisely what I spent this session re-deriving one feature at a time. “Attach relative to the parent” — the rule that fixed the brow and that three chin attempts failed to find — is tissue depth over bone, rediscovered the hard way. And the over-projecting failures I hit are the same class their gate had already caught. Two stacks now exist for the same job in two different rendering paradigms:
| SDF stack (sibling, 07-08) | mesh stack (this session) | |
|---|---|---|
| inside-out face | nx_faceanat + 6 gates | face parts in the body generator |
| profile judge | nx_faceprofile_gate — projection ratios, nose-most-projected, with a neg-control | nx_facemark — midline and lane profiles, recall × precision |
| layer stack | nx_anatstack — skeleton → muscle → fat → skin | bone → muscle → skin in the emitter |
| skull | tissue-depth over an implied skull | nx_skullgen — explicit bones as rules |
The recommendation is to merge the data, not the code, and to coordinate rather than unilaterally delete a sibling's lane. The SDF stack owns the measured assets — forensic tissue depths and facial canons — which is exactly what the mesh pipeline lacks and what would have prevented every attachment failure this session. The mesh stack owns the layer emitter, spline lofting, rotation about Z and the judges. So: port the tissue-depth table and facial canon into the mesh canon as data, retire the duplicated derivation, and stop maintaining two inside-out faces. Skull v2 is blocked behind that reconciliation — building it first would make the duplication worse.
The honest lesson costs more than the finding. This lane has a standing rule to check before building, and a documented dual-copy hazard, and I shipped four organs at speed without running the check. The instruments caught wrong anatomy repeatedly this session; none of them could catch work that already existed. That is what an audit is for, and it should have run first.
Phase 2 rung 3: the reconcile paid immediately — 92 → 138 with no new geometry
Reading the duplicate lane's table beat building anything. The audit found a forensic soft-tissue-depth table sitting in nx_faceanat since July — the measured millimetres by which skin sits proud of bone at each landmark, plus the classical facial canon. It is now ported into the mesh pipeline as data, not code: one measured source, two consumers, no third derivation. And it produced two corrections before a line of geometry changed.
| correction, from the table | was | canon | error |
|---|---|---|---|
| brow ridge — belongs at the glabella, not the eye line | 944 | 958 | 14‰ low (~25 mm) |
| eye line | 928 | 942 | 14‰ low — the same offset |
Both features were low by exactly the same amount, which is why raising the brow alone opened a visible gap above the eyes: the whole feature set was sitting low on the head. Corrected together, the brow now sits above the eyes and the eyes tuck beneath it — the shadowed socket I had been trying to build with geometry turns out to be what correct placement produces on its own.


| judge | before | brow only | brow + eyes |
|---|---|---|---|
| headline (worst lane) | 92 | 138 | 138 |
| mean of lanes | 179 | 203 | 216 |
| lane −1 (over the orbit) | 177 | 178 | 231 |
| variance judge (detail_head) | 348 | 302 | 277 |
The two judges diverge systematically here, and that is informative rather than alarming. The placement judge rewards features being where they belong; the variance judge rewards surface busyness. Moving features into correct anatomical position adds no busyness — nestling them together can even smooth the transitions — so the variance judge falls while placement rises. For positional work the placement judge is the trustworthy one, and it is the one specifically built to catch the failure the variance judge had already been fooled by.
The lesson is the whole argument for the audit. Nine rounds of building features one at a time moved the binding number from 69 to 92. Reading a table that already existed in this codebase moved it from 92 to 138 in a single pass. The most valuable thing in the duplicate lane was never its code — it was its measurements.
Phase 2 rung 4: a ported canon is a hypothesis per landmark — two of four transferred
The same table that gave a +46 win gave a −98 loss on the next two landmarks, and the measured hit rate is two out of four. Having ported the sibling lane's facial canon, the obvious next move was to apply the rest of it. Applying its nose values (nasion 938→948, subnasale 904→908) and its lip values (894/881 → 888/880) together crashed the binding lane 138 → 40.
| ported landmark | result | verdict |
|---|---|---|
| brow ridge → glabella | headline 92 → 138 | TRANSFERS |
| eye line | mean 203 → 216, lane −1 → 231 | TRANSFERS |
| nasion + subnasale | cost 56 of the headline back | DOES NOT |
| stomion (lip line) | mean +6 but the mouth visibly worse | DOES NOT |
The lip crash had a cause worth keeping, and it was a law already written in this file one rung earlier: a feature part occupies a BAND, not a point. The table's 888 and 880 are anatomical landmarks for lip centres as infinitesimal points; our lips are tubes of radius nine and eleven, so centres eight apart overlap completely and merge into one mass — the groove that actually reads as a mouth disappears. That is the same collision that let the chin swallow the lips, arriving from the opposite direction. A landmark table cannot be applied directly to parts with extent.
The derived fix — hold the canon stomion as the invariant and place each lip so its inner edge lands on it — recovered the lane from 40 to 135 and pushed the mean to its best ever, 222, with the head judge up 38. And it was still reverted, because the eyeball said the mouth got worse: the lower lip landed nineteen units above the chin and the pair read as one flat mass at the bottom of the face. Numbers up, face down; this lane does not take that trade.
★THE LESSON: A CANON IS MEASURED RELATIVE TO A PARTICULAR HEAD. Porting one is a hypothesis per landmark, not a global rewrite. Where the two geometries agree the values transfer and pay immediately; where they differ the same table actively harms. The tip of the nose is the useful control — the table said 912 and measurement had already driven us to 913, an independent agreement that tells you the table is sound and the disagreements are real geometry differences rather than bad data. Every ported value gets A/B'd against the mesh. That is what the lane judge is for.
Shipped state: brow at the glabella, eyes at the canon eye line, nose and lips at their measured-best positions. Headline 138, mean 216, verified exact after revert, all four gates GREEN.
The ruler: nx_mhbench — live, computed, liar-killed
A sovereign NishiLang MCP tool. Verdicts are re-computed against on-disk artifacts on every call: a declared capability whose evidence file is missing is automatically downgraded to GAP. Its 5-tooth selftest gate runs GREEN 5/5 over the live /mcp endpoint, including the proof that pointing it at an empty artifact root forces every axis to GAP — the verdicts derive from disk, not from assertion. nx_headcrop carries its own 7/7 gate (exact band crop, loud refusals on empty band and missing input, and an anti-vacuity tooth proving a full-range band keeps every triangle).
Current reading: parity coverage 230‰ (0 HAVE / 6 PARTIAL / 7 GAP of 13 axes) · exceed tier 2 HAVE / 2 PARTIAL / 2 GAP. Snapshot: metahuman_board.json.
MetaHuman-parity axes
| axis | w | verdict | evidence / current-state exhibit |
|---|---|---|---|
| head-identity-geometry | 9 | GAP | measured 79‰ at head scale — painted, not sculpted; MetaHuman spends 100k+ tris on the head alone |
| soft-tissue-form | 9 | GAP | breast/hip/waist/glute mass under gravity — the comp-ranked #1 body gap |
| strand-hair-groom | 8 | GAP | B-spline strand plan (Catmull-Rom machinery exists) |
| facial-rig-animation | 8 | GAP | unaudited prior demo — not credited until re-gated |
| skin-material-sss | 7 | PARTIAL | SSS + tone + micro-relief — at its proven ceiling until FORM exists |
| eye-shader | 7 | PARTIAL | 5 measured eye cues; no lids/lashes/tear film |
| teeth-mouth-interior | 6 | GAP | — |
| lod-realtime | 6 | GAP | unaudited prior demo; renders are ~2s CPU frames today |
| light-transport-gi | 6 | PARTIAL | sky hemisphere + per-channel environment — deliberately LAST: light cannot reveal a surface with no orientation variation, and the head render above is the proof |
| body-rig-skinning | 6 | PARTIAL | FK rig + physics on the real skeleton; the PRODUCT body is not yet skinned |
| body-anthropometrics | 5 | PARTIAL | measured control handles, front silhouette 866 = best measured |
| wardrobe-cloth-render | 5 | GAP | wardrobe STATE machine proven elsewhere; no cloth render |
| creation-customizer | 4 | PARTIAL | one generator → varied characters |
Sovereign EXCEED axes (what they structurally cannot follow)
| axis | w | verdict | evidence |
|---|---|---|---|
| procedural-village | 9 | GAP | correlated anthropometry sampler + population loop — named next builds |
| beauty-manifold-scored | 8 | GAP | beauty as a red-teamable scored manifold, never a slider |
| inside-out-anatomy | 8 | PARTIAL | bone→muscle→skin nested layers — envelopes today, not named anatomy |
| bit-determinism | 6 | HAVE | replay-identical checksums across the gate suite — a float engine cannot promise the same body twice |
| sovereign-no-license-lock | 5 | HAVE | own language→compiler→renderer→ruler stack; MetaHumans are licensed to one engine |
| species-agnostic-canon | 4 | PARTIAL | canon-file-driven pipeline; one species authored so far |
The build order — computed by the ruler, not chosen by taste
gap_queue (weight-ranked, 17 open): head-identity-geometry (9) → soft-tissue-form (9) → procedural-village (9) → strand-hair (8) → facial-rig (8) → beauty-manifold (8) → inside-out-anatomy (8) → skin (7) → eye (7) → teeth (6) → lod-realtime (6) → light-transport (6) → …
Next build, now unambiguous and with a number that must move: real feature GEOMETRY on the head — a nose as an actual ruled structure (bridge, tip, wings, nostril sills), lips with vermilion relief, brow ridge and orbital recession at an amplitude the surface judge can resolve, chin and jaw planes, ears. Scored on nx_headcrop + head-scale detail (79 today), eyeballed against the oracle above every time.
Standing honesty rules this page inherits
- Several judges, publish the MINIMUM — every judge added so far has lowered the number and made it true.
- Instruments before features — a feature credited on a blind judge is a false claim waiting to be found.
- Red-team every new ruler before trusting its green (noise once scored above a real render; a bell-shaped body once outscored a good one).
- Eyeball every render — numeric gates have passed three separate framing bugs in this lane.
- Oracles (BodyParts3D, CUDA, Infinigen, MetaHuman) are rulers and capability bars — never the product. No third-party assets ship. The oracle head above is CC BY 4.0 (BodyParts3D, © The Database Center for Life Science), used as a measuring stick.
Credits and sources
Reference photography used as a quality bar and fitting target, all freely licensed and used with attribution as their licences require:
- “15-08-12-Model-Rotkäppchen-RalfR-N3S 0537” — Ralf Roletschek, GFDL 1.2, via Wikimedia Commons. Natural outdoor light; long braided hair — the strand-hair target.
- “Freckled Redhead on Bench” — David Levine (Portland, USA), CC BY 2.0, via Wikimedia Commons. Dappled daylight; freckles and skin micro-detail — the pore-fidelity target.
- “Olga Alberti (Russian model)” — Moor max, CC BY-SA 4.0, via Wikimedia Commons. Outdoor natural daylight, Bracciano, 2013. The body-scale fitting target — until now the reference corpus was head and portrait only, so whole-body proportion and silhouette had no photographic reference at all and were benched solely against a cadaver oracle. Share-alike: derivatives of this image carry CC BY-SA 4.0.
- Oracle anatomy: BodyParts3D, © The Database Center for Life Science, CC BY 4.0. Used as a measuring stick only. Corrected 2026-07-26: this page previously credited it as CC BY-SA 2.1 Japan. Verified against both the English and Japanese official licence pages — it is CC BY 4.0, and the ShareAlike obligation we had been carrying never existed.
GFDL 1.2 requires its licence to travel with derivatives; where a derivative of that image is published here, it carries the same licence. No third-party asset ships inside the generator — every one of these is a ruler or a target, never a component. The bodies on this page are generated from rules and a seed.
Related evidence
anatomy & body lane (33+ gated sections) · graphics first-byte trunk · human roadmap · realism loop · atlas card