Put the refinement on a slider, per layer
Benchmarks / CPU and I/O (per commit) (push) Successful in 3m27s
Benchmarks / Frame budget (on demand) (push) Skipped
🐳 Android image / Build and push (push) Successful in 3s
Build and test / android-image (push) Successful in 3s
Build and test / Desktop (Linux) (push) Failing after 1h14m30s
Build and test / Layer separation (push) Successful in 43s
Traceability / Requirement traces (push) Failing after 46s
Build and test / Android (aarch64) (push) Successful in 1h8m56s

The evidence was being gathered and spent immediately at one strictness
nobody could see or change. This makes it a control.

`MaskLayer::refine` is shaping, like the feather, and it lives on the layer
for the layer's reason: two layers may sit on the same category and want
different amounts of it, and the model ran once for both.

## What the segmentation now stores

`CategorySummary` keeps the **coarse** mask and the `Refinement` beside it,
rather than a refined mask. That is what gives the control an off position
that is bit-for-bit the model's own weighting, and what stops a strictness
change from needing the model again.

`category_mask_at` borrows at zero and wherever no refinement could be
fitted, so a layer nobody has touched costs nothing over the old path.

The fit moved to the far side of the orientation permutation. The verdict is
a per-pixel field over the same grid as the mask it gates, so fitting it
upright would mean permuting a proxy-sized buffer afterwards to match — a
second rotation, and a second chance to get one wrong. One logit cell is the
same number of pixels either way: the letterbox scales by the longer edge and
a permutation does not change which edge that is.

The two frames became a `Frames` struct rather than six parameters. This
function reads the picture twice for opposite purposes — the model needs it
upright or it recognises far less, the refinement needs the sensor's grid —
and a transposed pair produces a plausible mask over slightly the wrong
pixels, which is the failure this module is most prone to.

## It rebuilds the field, and the signature says so

`refine` is mixed into `subject_signature`. Unlike a feather, which is read
off a field that is already correct, this changes which pixels are in the
mask at all — so it changes the coverage the field is measured from. Omitting
it is the bug where the slider moves and nothing happens until some unrelated
control invalidates the cache.

That puts it in the same cost class as a close or an open, which is why the
row takes `SliderRow::changed` — already once-per-gesture, since that row
takes `SliderTrack`'s `committed` internally — rather than a live stream.

The slider is offered only where there is something to move: a category
source, *and* a refinement the frame actually gave enough to fit. A control
that moves and does nothing is worse than an absent one.

## Two defaults that are deliberately different

A layer added from the panel starts at 4.0, because a category's edges are
twenty proxy pixels wide before anything is done to them and a photographer
adding a sky mask wants the sky rather than the sky plus every chimney in it.

A layer read from a sidecar with no `refine` key starts at **zero**. A file
written before this control existed has to render as it did then, and a
default of 4 on absence would quietly re-grade every stored category mask in
the catalogue. `a_categorys_refine_strictness_survives_and_defaults_off`
holds both halves, and `an_out_of_range_refine_is_clamped` holds the file to
the scale — past the top of it every colour fails and the mask deletes
itself, which reads as lost work rather than as a bad file.

`MAX_REFINE` is dr-pipeline's own constant mirroring
`dr_segment::STRICTNESS_MAX`, following `Falloff` and `Morphology`: this
crate holds the description of an edit and must not depend on the crate that
runs a model. dr-ui is where the two meet, and the only place that converts.

Verified: fmt clean, clippy --workspace -D warnings clean, 488 dr-pipeline
and 60 dr-segment tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-30 18:30:40 +02:00
co-authored by Claude Opus 5
parent f87bf6ebc0
commit 4efab496c2
9 changed files with 413 additions and 47 deletions
+36
View File
@@ -49,6 +49,19 @@ use crate::ops;
/// be a literal in one.
pub const DEFAULT_FEATHER: f32 = 0.004;
/// The most a layer's [`MaskLayer::refine`] may be, in nats.
///
/// Mirrors `dr_segment::STRICTNESS_MAX`, and is a separate constant for the
/// same reason [`Falloff`] and [`Morphology`] are separate types from that
/// crate's: this one holds the *description* of an edit and must not depend on
/// the crate that runs a model. `dr-ui` is where the two meet, and it is the
/// only place that converts between them.
///
/// Used here to bound what a sidecar is allowed to claim. A file is not
/// trusted, and a strictness off the end of the scale would render as a
/// category that had silently deleted itself.
pub const MAX_REFINE: f32 = 8.0;
/// The most points one stroke keeps before a gesture continues as a new one.
///
/// This is a *cost* bound, not a storage one. Each stroke is drawn over its own
@@ -685,6 +698,23 @@ pub struct MaskLayer {
pub morphology: Morphology,
/// How far, in the same units as [`Self::feather`].
pub morph_radius: f32,
/// How strictly a category source is cut back to the pixels whose colour
/// agrees with it, in nats. Zero leaves the model's own weighting alone.
///
/// Only [`MaskSource::Category`] has anything to apply it to — the
/// evidence is fitted per category during segmentation — so it sits at
/// zero and out of the panel for every other source.
///
/// A *quantity*, not a 0-to-100: it is how much more plausible than the
/// alternatives a colour must be before its weight is kept, which is why
/// `dr_segment::refine` can state where a flag falls on it and where a
/// cloud does. Bounded by [`MAX_REFINE`].
///
/// This is shaping, like [`Self::feather`], and it lives on the layer for
/// the same reason: two layers may sit on the same category and want
/// different amounts of it, and the model ran once for both.
pub refine: f32,
/// This layer's adjustments.
///
/// A full chain, the same one [`crate::EditGraph`] holds. That is the
@@ -741,6 +771,7 @@ impl Clone for MaskLayer {
falloff: self.falloff,
morphology: self.morphology,
morph_radius: self.morph_radius,
refine: self.refine,
ops,
}
}
@@ -797,6 +828,11 @@ impl MaskLayer {
falloff: Falloff::default(),
morphology: Morphology::default(),
morph_radius: 0.0,
// Off, so a layer built here is the model's own weighting. The
// useful starting point for a *category* is not zero, but it is
// `dr_segment`'s number to state and this crate does not depend on
// it — `Session::add_category_mask` sets it on the way in.
refine: 0.0,
ops: layer_chain(),
}
}
+17
View File
@@ -1035,6 +1035,11 @@ fn write_mask(out: &mut String, version: &str, layer: &MaskLayer) {
let _ = writeln!(out, "morphology = {}", layer.morphology.name());
let _ = writeln!(out, "morph-radius = {}", format_value(layer.morph_radius));
}
// Absent means zero, which is the model's own weighting — so a file
// written before this control existed reads back looking exactly as it did.
if layer.refine != 0.0 {
let _ = writeln!(out, "refine = {}", format_value(layer.refine));
}
for (op, param, value) in layer.params() {
let _ = writeln!(out, "{op}.{param} = {}", format_value(value));
}
@@ -1144,6 +1149,7 @@ struct PartialMask {
falloff: Falloff,
morphology: Morphology,
morph_radius: f32,
refine: f32,
strokes: Vec<Stroke>,
params: Vec<(String, String, f32)>,
}
@@ -1174,6 +1180,7 @@ impl PartialMask {
falloff: Falloff::default(),
morphology: Morphology::default(),
morph_radius: 0.0,
refine: 0.0,
strokes: Vec::new(),
params: Vec::new(),
}
@@ -1227,6 +1234,15 @@ impl PartialMask {
"morph-radius" => {
self.morph_radius = value.parse::<f32>().unwrap_or(0.0).clamp(0.0, 1.0)
}
// Clamped for the same reason the feather is: a strictness off the
// end of the scale is a category that has deleted itself, and a
// file is not trusted to ask for that.
"refine" => {
self.refine = value
.parse::<f32>()
.unwrap_or(0.0)
.clamp(0.0, crate::mask::MAX_REFINE)
}
// An unrecognised name falls back to the default rather than
// dropping the layer. A newer build's falloff curve is a cosmetic
// difference in the edge; losing the selection under it would not
@@ -1304,6 +1320,7 @@ impl PartialMask {
layer.falloff = self.falloff;
layer.morphology = self.morphology;
layer.morph_radius = self.morph_radius;
layer.refine = self.refine;
for (op, param, value) in &self.params {
// `ParamId` holds a `&'static str` and this one came off disk, so
// it is matched against the descriptors and the *static* id is
+101
View File
@@ -660,6 +660,107 @@ fn category_masks_keep_their_name() {
assert!((layers[0].feather - 0.03).abs() < 1e-6);
}
/// The refine strictness survives, and its absence means zero.
///
/// Both halves matter and they are different claims. A dropped strictness
/// would reopen a sky the photographer had closed, silently, on the next
/// launch — the mask would still be there and would simply have got the
/// chimneys back.
///
/// And a *missing* key has to read as zero rather than as the default the
/// panel starts a new layer at, because that is what makes a file written
/// before this control existed render exactly as it did then. A default of 4
/// on absence would quietly re-grade every stored category mask in the
/// catalogue.
#[test]
fn a_categorys_refine_strictness_survives_and_defaults_off() {
let mut graph = EditGraph::default_chain();
let mut sky = MaskLayer::new(
"m1",
MaskSource::Category {
signature: 0x5EED_1234,
name: "sky".into(),
},
);
sky.refine = 3.7;
graph.masks_mut().push(sky);
// Left at zero, so the writer omits the key entirely — which is the case
// the second half of this test is really about.
let plain = MaskLayer::new(
"m2",
MaskSource::Category {
signature: 0x5EED_1234,
name: "water".into(),
},
);
graph.masks_mut().push(plain);
let text = {
let mut sidecar = Sidecar::new();
sidecar.put(Version::from_graph("default", "Default", &graph));
sidecar.to_text()
};
assert_eq!(
text.matches("refine =").count(),
1,
"only the layer that set one should write the key:\n{text}"
);
let layers = round_trip(&graph);
let layers = layers.masks().layers();
assert!(
(layers[0].refine - 3.7).abs() < 1e-6,
"got {}",
layers[0].refine
);
assert_eq!(
layers[1].refine, 0.0,
"an absent key is the model's own mask"
);
}
/// A file is not trusted to ask for a strictness off the end of the scale.
///
/// Past the top of the range every colour fails the test, so the mask deletes
/// itself — which reads as a lost edit rather than as a bad file.
#[test]
fn an_out_of_range_refine_is_clamped() {
let mut graph = EditGraph::default_chain();
let mut sky = MaskLayer::new(
"m1",
MaskSource::Category {
signature: 0x5EED_1234,
name: "sky".into(),
},
);
sky.refine = 3.0;
graph.masks_mut().push(sky);
// Edited in the written text rather than assembled by hand, so this test
// cannot drift out of step with the format the writer actually emits.
let mut sidecar = Sidecar::new();
sidecar.put(Version::from_graph("default", "Default", &graph));
let text = sidecar.to_text().replace("refine = 3", "refine = 900");
assert!(text.contains("refine = 900"), "the edit must have applied");
let parsed = Sidecar::parse(&text).expect("reparse");
let mut restored = EditGraph::default_chain();
parsed
.versions
.get("default")
.expect("version survived")
.apply(&mut restored)
.expect_no_film();
let refine = restored.masks().layers()[0].refine;
assert!(
refine <= dr_pipeline::mask::MAX_REFINE,
"a file asked for 900 and got {refine}"
);
}
/// A category is stale when its run is, exactly as a subject is.
///
/// The coverage buffer lives in the session, not the sidecar, so a layer whose