Skip to content

feat: add first visible LLM invasion - #9

Merged
christopherjnelson merged 6 commits into
mainfrom
feat/0004-first-visible-llm-invasion
Aug 14, 2026
Merged

christopherjnelson merged 6 commits into
mainfrom
feat/0004-first-visible-llm-invasion

Conversation

@christopherjnelson

@christopherjnelson christopherjnelson commented Aug 14, 2026 •

Copy link
Copy Markdown
Member

What changed

Server-owned simulation

  • adds the deterministic 61-cell Toledo development world with six fixed named agents
  • runs one agent per turn in stable round-robin order with Start, Pause, Single Turn, and Reset controls
  • keeps a monotonic completed-turn count independent of the newest 120 retained turn records
  • retains only the newest 120 world events while preserving the newest eight relevant observation events in chronological order
  • validates complete accepted or rejected records before atomically committing world state, turn history, count, and cursor
  • records sanitized provider failures while allowing unexpected engine, schema, and internal failures to propagate without partial state changes

Visible World Lab

  • renders all 61 H3 cells through MapLibre with visible open, infected, border, and selected-cell styles
  • keeps all six agent markers visible, clickable, and above the H3 overlay
  • verifies readiness from unique MapLibre-rendered features instead of React source counts
  • exposes rendered cell and infection diagnostics for deterministic Playwright assertions
  • updates infection and reset data without recreating the map
  • configures a same-origin MapLibre worker path so GeoJSON processing works under Next.js

Real OpenRouter provider

  • targets google/gemini-3.7-flash with no fallback model
  • makes exactly one provider request per agent turn
  • uses max_tokens: 1024, low reasoning effort, and exclude: true
  • preserves provider.require_parameters: true and stream: false
  • uses a strict root-object response schema with a nested anyOf action union and single-value discriminator enums
  • leaves H3 formatting, summary bounds, action validation, adjacency, infection state, and consequences authoritative in Zod and the world engine
  • keeps the abort timeout active through body reading, decoding, extraction, and validation
  • reads non-success bodies only to a fixed bound and retains only sanitized status, code, message, request ID, and selected-model diagnostics for the opt-in CLI
  • keeps those diagnostics out of turn records, snapshots, browser responses, and normal logs

Environment and deterministic seams

  • loads provider configuration from the repository-root .env for both normal Game API startup and pnpm smoke:openrouter
  • makes .env provider values authoritative over stale exported values while loading only the provider variables in the shared override helper
  • keeps .env.example as the committed template and never exposes the API key to browser code
  • keeps the scripted provider explicit and limited to deterministic tests and Playwright; it is never an OpenRouter fallback

Why

This is Roadmap PR 2: the first browser-observable LLM invasion. It delivers a genuine model-backed vertical slice while keeping world authority deterministic and deferring persistence, autonomous scheduling, player systems, and later-roadmap social mechanics.

The correction passes also addressed retained-history turn-number reuse, non-atomic world mutation, unbounded world events, response-body timeout coverage, invisible H3 expressions, false overlay readiness, Next.js MapLibre worker loading, Gemini parameter/schema compatibility, safe provider diagnostics, and inconsistent root environment loading.

Validation

The repository owner reported the complete local validation sequence green, including formatting, lint, type checking, unit/integration tests, production build, and Playwright. The owner also ran the explicitly opted-in pnpm smoke:openrouter call successfully against google/gemini-3.7-flash and confirmed normal pnpm dev startup with repository-root .env configuration.

The real-provider smoke remains separate from default tests, Playwright, and CI because it incurs third-party cost.

Security and operating notes

  • OPENROUTER_API_KEY remains server-only.
  • Raw prompts, observations, request/response bodies, secrets, and private reasoning are not recorded or exposed.
  • Provider failures are public-safe; bounded detailed diagnostics are available only to the local opt-in smoke command.
  • The cost-incurring development API remains loopback-bound and is not suitable for unauthenticated public deployment.
  • API process restart resets the in-memory simulation.

@christopherjnelson
christopherjnelson marked this pull request as ready for review August 14, 2026 05:24
@christopherjnelson
christopherjnelson merged commit 36a3f41 into main Aug 14, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant