The owner asked twice why there are still three separate boards. The honest answer, and what this round executes: **it feels like three boards, but not because the scale jumps 20x — because the three packs draw three different Californias, and the loudest difference is that the mountains are four times taller on one of them.** **THE 20x HORIZONTAL SCALE JUMP IS INVISIBLE**, and measuring that collapsed the cost of this whole round. `World.project` is a uniform scale in x/z with no vertical term, and a uniform scale leaves a perspective image identical — so a camera carried across the seam on matched true-metre offsets draws a pixel-identical horizontal frame. 1,919 -> 94 m/unit costs nothing to look at. Rescaling was never the problem. A boot card, a tab strip and a 4.17x vertical deflation were. **THE PAUSE WAS MOSTLY FAKE.** A switch covered the screen for 1,715 ms but only 608 ms blocked the main thread; the page drew 46 of 69 frames with nothing to show, because the outgoing board had already been disposed. `mountCity` now retains it: the incoming board builds BEHIND a live, interactive picture, and `stage.setScene` fires only on completion. Measured across all six directions, three runs each — boot card yes -> **no**, opaque cover 726-1,415 ms -> **0**, blank frames 21-46 -> **exactly 1**, wall clock down 12-29%, blocked main thread down 15-47%. A return to a board already seen links **zero** shader programs and blocks **zero** milliseconds: 298-312 ms of camera flight where it was ~1,600 ms behind a card. Disposal had been throwing away the shader cache too — linkProgram ran 38, 59, 78, 109, 127 across five mounts and never reused one. **The transition is a fog dip, not a crossfade**, through the `setAerialFog` seam built last round. Every both-boards-live crossfade breaks a budget — ca+sf is 2,640,307 triangles against bay-area's 2,600,000 cap — and a fade never lands inside the harness's sample window, which is the "a cap you do not measure is a cap you do not have" failure this repo already argues against. The dip costs zero triangles and zero draw calls, and it hides the 4.17x deflation, the 4,025 m projection disagreement and the vanishing 2 km freeway symbols at once, because all three happen at maximum obscuration. It is also diegetic: a descent through haze. The first dip was wrong and the photograph caught it: collapsing to 6% of board SPAN turned the whole night frame into one flat field — the exact "turns the map off" failure the risk list named. Re-anchored to 70% of camera STAND-OFF, so the coastline survives and only the relief melts. **One ladder, one places list.** 26 authored chapters become 24 rungs sorted descending by STAND-OFF, not altitude — by altitude they interleave badly and altitude cannot tell a low oblique from a high plan. The three-board tab strip is off by default; the left column is now one scrolling list of all 24 rungs under three region headings that does not change when the board does. Only which row is lit changes. Label collisions are resolved in the ladder and never in a pack, so the 29 index-aimed capture guards are untouched. The minimap stops turning through 90 degrees between boards: every board is pinned to a rectangle with California's proportions. **SF and SoCal are not regressed**, and that was the acceptance that mattered: 95.9-98.8% of board pixels are delta-0 against a baseline hash-verified identical to what the live site serves, and every one of the 34-70 surviving pixels per frame is an aircraft or a hull. **A real defect found only by photograph:** `minimap.setMarkers()` had zero call sites. Every marker on every board was gone — the LA studio's door dot, the Bay Area's eight company markers — dropped when the minimap went per-board. Typecheck, tests, budgets and the console were all green with that bug in. Also fixed: two capture presets that lied. `look.mjs`'s `glyph-la` and `glyph-sf` claimed California chapter closeups and returned SoCal and Bay Area frames, because they aimed by chapter index and the indices had moved. Aiming is now by identity, with a guard test. NOT SHIPPED, DELIBERATELY: the pack merge. At Bay density it is 34.04M triangles, 13x the highest budget — dead, not a trade. At SoCal density it is 1.99M and fits today, and the price is San Francisco rendering at 164 m lots instead of 40 m, i.e. SF looking the way SoCal looks now. SF and SoCal carry every marketing still on the site. That is the owner's decision and it is worthless as an argument and decisive as a photograph, so it ships as a measurement artifact with a side-by-side still and is wired into nothing. The four data reconciliations that would make one world honest — one exaggeration rule, roads in metres, one projection centre, one coastline convention — are behind TERA_RECONCILE, default OFF. Tests 1,570 -> 1,651, server 295. All ten budget cells pass, no cap raised. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Tera
The map view of Lumbridge Simulate — California from above, in three.js. Its other half, Spaces, is the offices you walk into: one engine and one asset library, seen from outside and from inside.
Apache 2.0. Runs at tera.lumbridgecorp.com.
What it is
An engine plus data packs. The default board joins Los Angeles and San Francisco with live deterministic traffic on US-101 and on the honest I-5 → I-580 → I-80 approach. Choose either route chapter to follow the procedural black Model X.
The engine renders terrain, coastline, built cities on authored street grids, bridges, roads, markers, road traffic and air traffic. A city pack is pure data — coastlines, hills, districts, landmarks, camera chapters — so adding a city is a data contribution anyone can review, not a fork.
California, the detailed Bay Area, and Los Angeles / Orange County / Riverside ship today. The corridor is intentionally sparse; detailed cities remain their own boards rather than forcing a 600 km world into one full-resolution mesh.
A plan view sits top right: the board drawn flat, with the footprint of the camera's own frustum on it, so you can see where you are looking from outside the shot. Click or drag it to move the camera; scroll it to dolly. It is a 2D canvas rather than a second WebGL context, drawn from the same city pack, and it follows the sun into the night along with everything else.
Who sees what
Three tiers, resolved once at boot by src/access.ts:
| anonymous | signed in | admin | |
|---|---|---|---|
| the map, the plan view, the named chapters | ✅ | ✅ | ✅ |
| observed weather and live aircraft | ✅ | ✅ | ✅ |
| the office | public depth — shell, furniture, viewpoints, nobody home | full depth, with presence | full depth |
| the marker feed | per TERA_MARKERS_ACCESS |
✅ | ✅ |
the godmode panel (G) — date, season, weather override, counters, pose editor |
— | — | ✅ |
The sky is public on purpose. Cloud cover over San Francisco is a government sensor reading, and the aircraft are broadcasting their positions unencrypted to anyone with a receiver; neither is something an account can grant you access to. Gating them cost the only moment that makes this project land — real fog rolling off the Pacific onto a city you recognise, at the real time of day, on a first visit.
The markers are the one feed that can carry something private, so the server
decides. TERA_MARKERS_ACCESS is members by default and an operator has to
say public out loud, which /api/v1/health then announces in degraded[].
The default is the safe answer rather than the common one, because the failure
mode is silent: nothing errors, nothing looks broken, the data is just readable
by the internet.
These are drawing decisions, not a security boundary, and src/access.ts
says so at length. Live data and office presence are withheld by the API, from
a caller it does not recognise; the client tier stops the app asking for
something it will not get. Admin is granted only by TERA_ADMIN_SUBJECTS on the
server — never inferred in the browser, and never from an API that failed to
answer. A deployment with no API at all is open, because "clone it and it works"
is the promise; it is not "clone it and you are an administrator".
Quick start
npm install
npm run dev
Play controls
The bottom mode dock is the local-player source of truth: View, Drive, Explore,
Fly, or office Walk. A transition clears stale held input and atomically hands
the follow camera to one subsystem. WASD is movement; Q/E is vertical or
yaw, I/K pitches the crow, Space is the primary action, G glides, P
resumes assistance, R resets, and C switches the driving camera. A standard
gamepad maps both sticks, triggers, shoulders, and rising-edge action buttons.
Touch play uses a pointer-ID analogue stick at lower left and only the actions that apply to the current mode at lower right. The Map button remains available during possession. Touch, keyboard, and gamepad state are independent, so a released or cancelled finger cannot clear another source that is still held. The UI and follow camera are presentation adapters only; they never enter Arena observations, rewards, snapshots, traces, or simulator hashes.
Headless RL environments
Tera also exports a versioned, renderer-independent Arena contract with five deterministic environments: US-101/I-5 driving, Frontier Valley office navigation, seeded SF/LA office robot jobs, crow waypoint flight, and California electric-aircraft flight. They share the client controllers and office plan, but require no canvas, DOM, Three.js scene, network service, or new runtime dependency.
Import them from @lumbridge/tera/arena. Seeded train/dev scenarios,
component rewards, safety terminals, maximum steps, snapshots, checksummed
traces, exact replay and executable inaction/scripted baseline proofs are
documented in ARENA.md.
The visible SF and LA office robots use that same fixed-step job state. Their patrol, parcel, inspection, and charging loops are authored demonstration scenarios—not presence, telemetry, or evidence of real company work—and the UI labels them as a seeded simulation.
Using the engine
import { createScene } from "@lumbridge/tera/engine/scene.ts";
import { createStage } from "@lumbridge/tera/engine/stage.ts";
import SAN_FRANCISCO from "@lumbridge/tera/cities/sf.ts";
// One stage per canvas, for the life of the page. Cities are put on it and
// taken off again; a renderer per city leaks its shadow map on every switch.
const stage = createStage(canvas);
const scene = await createScene(stage, {
city: SAN_FRANCISCO,
markerPalette: { hiring: 0x4ade80, closed: 0xef4444 },
});
scene?.setMarkers([
{ id: "1", lat: 37.7765, lng: -122.4241, label: "Somewhere", colorKey: "hiring" },
]);
createScene is async because the heightfield is built in a Worker — half a
million samples, about 730 ms on the Bay Area, and not on the main thread. It
resolves to null if the build was abandoned through options.signal, which is
what makes switching city mid-build cheap.
The engine renders Marker[] and looks colours up by colorKey in a palette
you supply. It does not know what your markers mean — that mapping lives in
your adapter. This is what lets one renderer serve a private map coloured by
one scheme and a public map coloured by another, without either being a fork.
Adding a city
Write src/cities/<id>.ts exporting a City. Trace the coastline and parks by
hand, place hills as radial peaks, and give each district its street bearing.
Two rules, and they are not stylistic:
- Do not import geometry from OpenStreetMap. OSM and Nominatim output is ODbL — share-alike, and incompatible with this repo's licence.
- Do not commit logos or brand assets. They are trademarks, not code.
See ARCHITECTURE.md §3 for the full reasoning, and
NOTICE for the attribution and data-provenance statement, and
PROVENANCE.json for the machine-checked shipped-artifact and
original procedural-lineage ledger. Run npm run provenance, npm run licenses,
and npm run sbom before accepting assets or dependencies.
Aircraft
The engine takes a FlightSource. Two ship here: SimulatedFlights (original,
flies real approach and departure corridors) and AdsbFlights (open community
ADS-B feeds such as adsb.lol).
FlightRadar24 is deliberately absent — their terms forbid scraping and forbid redistributing their data, so a client for it cannot live in an Apache-2.0 repository. Commercial sources belong in private deployments. The best long-term answer is an RTL-SDR receiver: first-party data with nothing to comply with.
Layout
src/engine/ renderer — terrain, blocks, structures, markers, flights, scene, minimap
src/cities/ data packs — pure geography, no code
src/transport/ serializable route packs and renderer-independent simulation
src/arena/ versioned headless RL contract, scenarios, traces and environments
src/assets/ original procedural asset library
src/adapters/ where outside data plugs in
src/tools/ instruments — god-only, dynamically imported, never statically
engine never imports cities; neither imports adapters.
Nothing under src/tools/ may be reached by a static import from the app. It is
loaded by one await import() behind access.can.debug, so a visitor who is
not an admin does not download the code at all — which is the strongest
available reading of "nothing here runs for a non-god visitor": not a hidden
panel, not a disabled panel, no panel. src/tools/index.ts states the rule and
what silently undoes it.
Licence
Apache License 2.0 — see LICENSE and NOTICE.
The ordered build plan and parallel work lanes live in BUILD_PLAN.md.
