Optional DISPLAY → Gamepad mapping for sticks, triggers, and face buttons,
with altitude-scaled look sensitivity and a persisted on/off preference.
Co-authored-by: Cursor <cursoragent@cursor.com>
The proxy lists four mirrors and rotated on 5xx alone, so a 4xx ended the
fan-out. Measured against the live services: overpass-api.de and its lz4 alias
answer 406 to this proxy's User-Agent, while overpass.kumi.systems and
overpass.private.coffee answer 200 to the byte-identical request. Every
Overpass-backed feature — road geometry, annotation outlines, place lookup —
was failing on an Apache error page with two healthy mirrors untried.
The refusal was then cached. The cache guard read `status < 500`, so the error
page was written to memory and to disk, and the serve-stale guard used the same
threshold and declined to replace it. Boundary-class queries hold a month-long
TTL: four of twenty-three cached entries on this machine held that 406, dated
days after the mirror had stopped refusing.
Both decisions now go through one predicate. A payload is data only when it is
a 2xx that is neither rate-limited nor a body-level runtime error, so what may
be cached and what may be replaced by a stale entry cannot drift apart again.
A refusal every mirror agrees on is still reported with the first mirror's
status and body, so a malformed query says what upstream said — after every
mirror has had its chance, not instead of it. fetchOverpassPayload takes
injectable endpoints and fetch so the rotation is covered without a live
mirror; restoring either half of the old behaviour fails the new tests.
Expanding the empty KEY_SETUP_EXTERNAL_KEYS array under set -u is a fatal
'unbound variable' on bash 3.2, which macOS ships as /bin/bash — so a keyless
./scripts/dev-fresh.sh died at the provenance-marker line before doing
anything. The ${arr[*]:-} guard keeps 3.2 alive and leaves populated launches
byte-identical (same idiom the script already uses for DEV_UNSET).
Verified with /bin/bash 3.2.57: the extracted block runs clean under set -u
with no keys (empty CSV) and with keys (ordered comma-joined names); the full
launcher boots keyless to a live server, and exported keys still classify as
externally managed in Provider Settings. A behavioral guard now runs the real
block from the script both ways in the dev-fresh test surface, plus a textual
assertion pinning the 3.2-safe idiom.
The first formal release.
- One-click install via Pinokio; keyless boot lands on a live Esri World
Imagery satellite globe with keyless terrain, with automatic OSM fallback
and graceful degradation when terrain is unavailable.
- Provider Settings (the POWER UP panel): add, replace, or remove API keys
inside the app; credential files made owner-only before any secret is
written; external keys shown read-only; the panel refuses shared or proxied
servers.
- Keyless capability responses for the optional HUD summary and place search.
- Aircraft-identity voice answers cover operator, type, and route, and say so
plainly when enrichment is unavailable.
- README rewritten keyless-first; concise 0.1.0 changelog section; CI
workflow included.
Gates: 2,672 unit tests pass / 0 fail, build clean, tracking regression
108/108, map-source tray QA pass, setup doctor ready.
naturalEarthRegions.js and neighborhoodPolygons.js each carried an
isNode branch that dynamically imported node:fs to read their bundled JSON
packs, because a plain dynamic JSON import needs an import attribute in
Node. Vite only warns about externalizing node:fs for the browser, so both
warnings survived every production build and the runtime boundary rested on
an environment guard.
Give both loaders the import attribute instead. Vite bundles the JSON as a
module exactly as before (the emitted regions/marine/san-francisco chunks
are byte-identical), Node loads the same files under node:test, and the
isNode split disappears.
Add a source-boundary test so a node: import cannot silently return to a
browser-built module.
Closes#34