Skip to the write-up

The film's own car and showroom · loading

This is not a video.
It is the same car the film was shot with.

Every photograph below was path-traced from this exact mesh, in this exact room — the same surfaces, the same fourteen materials. Both download now and the car assembles in front of you; the circuit it was filmed on arrives when you press DRIVE.

model files
origins
KB total
The film below

The darkened showroom on the film's first frame: an empty lit turntable with the car's parts hanging exploded in the air around it.

Part two

One shot.
124 seconds.
No cuts.

The car you just drove is not a copy of the car in this film. It is the same export — the same mesh, the same fourteen materials — downloaded once at the top of this page and handed straight into the game without being fetched a second time. What cannot be handed over is the light: every frame below was path-traced in Cycles, and the car you steered was rasterised as you moved it, so the same surfaces do not read the same. The road under it is the film's as well — the circuit's own asphalt, kerbs, paint and landform, the 28,018 trees along it and the 34,899 barriers, tyre walls and grandstand seats beside it, exported from the same project and fetched by that same button; if it did not arrive, the game says so on screen and drives its own built-in circuit instead. The film was shot with that mesh, on that circuit — for two minutes and four seconds, in a single unbroken camera take, at 4K, with no edit point anywhere in it. This is that film, and the engineering log that came out of making it.

2,978frames delivered
3840×2160every one of them
124.08seconds, at 24 fps
0cuts
0downloaded assets

Behind: frame 1 of 2,978 — the film's first

The law the whole thing bends to

The brief has one absolute constraint and everything else is subordinate to it: the entire video — assembly, wall breach, drive to the track, the full lap, the ending — is a SINGLE unbroken camera take. Zero cuts. Zero crossfades. Zero hidden whip-pan cheats.

That is easy to write and it removes every escape hatch a film normally has. There is no cutaway to hide a sim that only works from one angle. There is no reverse shot to hide a building's unfinished side. The showroom is breached in the third movement and the hole is still there in the sixth, because the camera can come back and look at it. When the car drives from the showroom to the circuit, it drives — the road is real geometry the whole way.

It also means the film cannot be repaired in the edit, which is the reason the log below exists at the length it does.

And nothing in it was downloaded

No models. No HDRIs. No photo textures. No sample libraries. No stock footage. No sound effects. Nothing AI-generated, picture or audio. Every object in every frame was built from code or modelled for this film, and every sound in the mix was synthesised in numpy/scipy from the film's own telemetry — the engine note is a physical model driven by the car's speed, the shatter is read out of the rigid-body sim's actual collision events.

The page you are on keeps the same rule, and this round it stopped keeping it the easy way. The car above used to be a JavaScript reimplementation of those generators — no download, and also not the car. It is now the export itself, off this origin, which costs megabytes it did not cost before. The honest trade is written out at the bottom of this page, with the numbers.

Six movements, no edit points

What happens, and where

They are movements, not shots. Every boundary below is a place the camera keeps flying and the film changes what it is about — checked in pixels, not argued from the mechanism. The frame numbers are the delivered master's own.

The completed car standing on the lit showroom turntable at the end of the assembly. Beat 1

Assembly

The camera weaves through a field of exploded parts in a dark showroom, presenting fifteen clusters in the order they will seat — core first, aero late, the four corners together and last. The rule was that no part seats without having been seen, and the beat sheet records a violation count of zero against it.

frames 1–79233.0 s
The car leaving the turntable under power, wheels blurred, the showroom floor streaking past. Beat 2

Ignition and launch

A second of stillness, then wheelspin for about ten frames and a hard launch straight at the glass. The wheelspin is the only sanctioned violation of the rolling-contact rule in the entire film — everywhere else, wheel rotation is distance divided by radius, off the same telemetry that drives the sound.

frames 793–8643.0 s
The car out on the concrete apron beyond the breached wall, glass debris skittering across the ground behind it. Beat 3

The breach

Eight seconds of screen time covering 1.6 seconds of world time. The camera keeps flying in real time while the world eases down to a fifth of speed around it, arcs through the shard field, and lets time back up as the car clears the debris. The shutter angle scales with world time so the motion blur stays truthful at the bottom of the ramp.

frames 865–10568.0 s
High three-quarter view of the car accelerating away across the paddock apron in daylight, cyan livery lit. Beat 4

Transit

Out through the paddock and onto the pit straight, with the exposure animating from interior spill to full daylight over about fifteen frames — in the camera, not in the grade, because a grade that changes mid-film betrays the cut-free illusion. This beat is why the paddock had to be dressed at full fidelity: the camera crosses it once and never gets a second take.

frames 1057–11905.6 s
Kerb-height view alongside the car as it runs through a corner, red and white kerb streaking past. Beat 5

The lap

One flying lap, 63.5 seconds, with the camera morphing continuously between vantage points and never cutting between them — chase, kerb-height alongside, a helicopter arc through the esses, a near-static trackside pass, an onboard-like tuck down the straight. The trackside pass produces a textbook doppler sweep with no special-casing, because the spatialisation maths is always running.

frames 1191–271463.5 s
The closing wide: the circuit sweeping away below with pit buildings and treeline, late afternoon light. Beat 6

The ending

The camera decelerates, rises and pulls back into a closing wide over the circuit, then holds. It is also the beat with the most honest defect entry against it: the car is out of frame for the film's last 145 frames — six unbroken seconds — and two claims made to the client about this beat were withdrawn before that was found.

frames 2715–297811.0 s

The constraint

Every object in every frame was made here

The brief bans downloaded models, stock footage, photo textures and anything AI-generated, and it bans them for the world as much as for the car. That turns out to be the expensive half. A hero car is one object you can afford to build properly. A circuit is a landscape.

Close pass over the car's monocoque and floor as they hang in the exploded field, cyan trace livery visible along the flank.
Frame 49. The brief made close-up worthiness a defect gate: every hero part had to be test-rendered at the actual distance the beat sheet puts the camera at, and pixel-peeped, before the beat was animated. Anything that failed got rebuilt rather than shot from further away.
Near-camera view of the steering wheel and a front corner assembly hanging in the exploded field, brake and upright visible.
Frame 257. The steering wheel alone is 65 objects; the halo is 53. The assembly beat presents fifteen clusters in mechanically-derived seat order, and the order was derived from an inventory taken before any planning — because a spec written before the measurement is a hypothesis, which is the log's first entry.

The one rule the client stated in his own words was “i dont want repeat stuff aka one tree spammed 100 times” — and the gate written to enforce it could not see a single tree.

The terrain builder places trees as linked duplicate objects; the gate's walk skipped anything whose instance flag was false. The replacement measures the client's actual sentence — co-visible sharp copies of one source mesh — and its control watches the old code see 0 of 40 deliberately spammed trees while printing a spam verdict about the grass.

Helicopter view looking down on the car through a corner, kerbs, run-off, grass and treeline filling the frame.
Frame 1803. The vegetation library that dresses this shot carries 27,969 woody objects across 33.62 million triangles — and it was already shipping in the film on the day a scoping document declared that tier unbuildable. The number called impossible was the number the world already had. Elsewhere in the same landscape, a 16.5-hectare district drawn by hand had drifted 2.5× from the contract that was supposed to state its extents once, leaving 833 grass clumps standing on concrete.
The car mid-breach, seen through a full-frame fracture pattern as the showroom's glass wall comes apart around it.

The money moment

The wall is a real simulation, and it had to survive being circled

The glass is pre-fractured — small shards at the impact point, larger at the edges — and run as a rigid-body sim with the car as an animated passive of effectively infinite mass. Shards inherit contact velocity, tumble with spin, and catch the daylight coming in through the hole they are making.

Because there is no cut, the sim has to look correct from the entire camera arc rather than from one flattering angle, and the wound it leaves has to persist for the remaining eighty-eight seconds of film.

And this beat is where the audio was most wrong, for the longest

The showroom's glazing is laminated — a 5 mm / 1.5 mm PVB / 5 mm sandwich, declared in the fracture sim's own output — and no line of the audio had read that. A laminate is a constrained-layer damper; that is the entire acoustic reason it is specified. The mix was ringing every fragment of it at a Q of 800–1500, 995 contacts a second each ringing for 0.6 s, which is a wash and not a shatter.

It was also synthesising 351 fragments of median 321 mm while the picture's own fracture — the one these frames were rendered from — has 3,216 of median 21 mm. And underneath both, a world-time warp implemented as a varispeed resampler was transposing every world-attached source 6.51× down at the breach, which is why the glass had no glass in it.

Behind: frame 881 — beat 3, inside the speed ramp

The most publishable thing this project produced

Broken instruments

One failure, found twenty-six times, in subsystems that share no code and were written weeks apart by people solving unrelated problems:

A guard, gate, metric or report returned the same answer whether the defect it existed to catch was present or absent.

None of these were caught by review. They were caught by feeding the instruments deliberately stupid inputs and requiring a refusal, by running the fix's own test against the pre-fix tree first, and by a person listening to a mix that every gate had passed. A selection follows; the full catalogue is grouped by mechanism, because the mechanism is the part that transfers.

The instrument's own arithmetic destroyed the reading

A limiter reporting 0.124 dB while removing about 22

The build report said the loudness limiter had turned things down by at most 0.124 dB — the signature of a mix that needs no help. Recovering the true gain curve, by dividing the delivered file by the sum of its own fourteen component tracks, showed a 32.2 dB swing.

The cause is four lines: the limiter ran up to eight times in a loop and the variable holding “the worst we saw” was reassigned every pass rather than reduced with min. The per-pass reductions were −19.93, −3.89, −2.20, −1.13, −0.63, −0.40, −0.22, −0.12 dB. The report published the eighth. Every iterative refinement loop has this shape — the last iteration is by construction the one with the least left to do — and the direction of the bug is always flattering.

The most expensive consequence was not the audio. An earlier diagnosis read that −0.124, declared the limiter “REFUTED, clean”, and moved on. That refutation was carried forward into weeks of subsequent work before anyone retracted it.

BROKEN-INSTRUMENTS.md §IV.1 · R2-4031, R2-4037

The metric's best score was a degenerate case

A quality gate whose maximum score was silence

The gate asked “does this passage contain events, or is it a stationary wash?” Its statistic was the span between the loud moments and the quiet moments. Read that definition twice: the loud moments are the impacts, the quiet moments are whatever lies between them, so the cheapest way to maximise the score is to put nothing between them.

Same 777 impacts, only the material between them varied
the passage is impacts plus…gate scoreaudibility
nothing (what shipped)27.17 dB−140.71 dB
an audible machine-room ambience12.62 — FAIL+14.56 dB
a hair dryer5.48audible
a drone0.26audible

The bar was 13.7. Silence scored 27.17 — the best in the table — and a genuinely audible machine failed. A tuning loop had been walking a gain parameter downhill toward a better score, and it arrived: the delivered passage measured 26.4 dB SPL at domestic playback level, with 0 of 29 third-octave bands above the threshold of hearing. A living room's own noise floor is about 15 dB louder than the entire passage.

Every other gate in the file agreed it was fine, and the reason generalises past audio: every one of them was relative. Ratios, spans, correlations, fractions — not one absolute quantity anywhere. Digital silence has excellent ratios.

It was caught by a person, who wrote: “now beat 1 i dont hear anything until the tubes play.” The threshold was not moved. The honest finding was that trough depth is not eventfulness — the metric was right and the inference drawn from it was not.

BROKEN-INSTRUMENTS.md §II.1 · R2-4147

Calibrated against the artefact it judges

“The limit is the midpoint between what THIS master reads and what the adversary reads”

That rule set every threshold in the audio suite, and it is not lazy work — the adversary was a synthesised hair dryer plus two masters the client had already rejected, the placements were bootstrapped with real standard errors, and the resulting gate correctly failed both rejected masters and white noise on all ten limbs. It looks like a properly validated instrument.

It is still self-referential, and the consequence is exact: the pass mark is a function of the artefact under test, so a film can only fail by being worse than the film that calibrated the limits. What that gate could detect was regression. What everyone believed it detected was quality. Three rebuilds shipped and were rejected under it.

The fix is the most directly reusable thing in the corpus: every threshold is now a frozen record carrying a provenance tag — physics, published or control-derived — and an audit rejects source=artefact by name before any gate is allowed to run. A second rule fires alongside it: a threshold with no derivation note is itself a violation, because a bare number is not a threshold.

BROKEN-INSTRUMENTS.md §III.1 · R2-2222, banned at R2-4041

The instrument never opened the artefact

Eight gates, and a two-second tape loop passed all of them

Three successive soundtracks were rejected by the client. All three had passed all eight automated gates. So an audit took the delivered master, replaced the 33 seconds the client was complaining about with a single two-second block tiled 16.5 times, renormalised the loudness, and ran the suite unmodified. Eight green lights, ALL_PASS = True, exit 0.

The gate meant to judge tonal quality rated the tape loop 35.9 dB better than the film it had just passed. Three of the eight never opened the audio file at all — one was a static scan of the source tree, one re-synthesised a clean engine tone from telemetry and measured that, one root-solved constants out of a source file. All three pass on white noise. Of the remaining five, one judged 2 frames out of 2,978 and one judged 20 samples out of 5,956,000.

Count what fraction of the artefact your checks actually touch, in the artefact's own units. “Eight gates” sounds like coverage. And a check that reads the source tree is a provenance check, not a quality one.

BROKEN-INSTRUMENTS.md §I.1 · R2-4039

The instrument had no case to answer

A verification that could not fail

The shortest entry in the catalogue and the purest specimen in it:

(ob.matrix_world.translation − ob.matrix_world.translation).length > 1e9

A value minus itself — identically zero — compared against a number nothing reaches. It printed a reassuring 0 stragglers and proved precisely nothing. The author's own note records that two independent audits had, that same night, flagged “verification theatre” as a bug class in its own right. “I then wrote one.”

Its siblings: two gates printing green having tested zero of zero; a cache eviction bound that had never once executed in production; and a ship-or-don't-ship harness that claimed a long list of assertions and could act on 24 of them — the rest printed and were judged by nobody. Among the silent ones was the suite's only negative control, whose own header read “if this ever comes back PASS the instrument is broken and every PASS above it is vacuous — keep it”. It was kept. It was piped into tail -12 for four film generations and its verdict went in the bin. The ship candidate flipped from PASS to FAIL the moment they were counted.

BROKEN-INSTRUMENTS.md §V.1, §V.2, §V.3, §V.4 · R2-012, R2-018, R2-2824

The instrument measured the wrong quantity

A number that did not move when the thing it names was rebuilt twice

Someone claimed two sections of the film were defective, citing a harmonic quality metric. Every number in the claim was correct. The conclusion was not, and one table settles it — the same metric across four masters, with two complete rebuilds of the engine synthesiser in between:

Metric movement across two engine rebuilds
section2 Augrebuild 1rebuild 2nowmoved
flying lap−0.71−0.72+6.68+5.847.40
launch+1.36+1.27+5.63+8.066.79
transit−0.55−0.59+3.57+3.914.51
the ending+0.40+0.40+0.35+0.130.27
the glass breach+1.49+1.45+0.08+0.051.44

A number that does not respond to two rebuilds of the engine is not measuring the engine. Established independently afterwards: in the breach it was computing a ratio on 0.0183 % of the section's energy, because breaking glass is broadband on purpose; in the ending the band being scored was 86 % crowd noise and 0.93 % engine. It was measuring a grandstand, and measuring it correctly.

A time series of your metric across releases is a free and extremely strong test of whether it measures what you think.

BROKEN-INSTRUMENTS.md §VII.2 · R2-2223, R2-2224

The thread that does not hold

“They were sloppy” does not survive the evidence

The people who wrote these instruments also wrote the docstring naming the exact failure mode, the comment explaining precisely why the heavy step needed a lock, the header stating that a passing negative control invalidates every result above it, and the note that “a detection that does not reach an exit code is a rumour” — on the tool that had never once reached an exit code.

The knowledge was present and written down, adjacent to the defect, in the defect's own words. What was missing was a mechanism that could act on it. Prose is not a mechanism. The fixes that stuck all converted a written intention into something that executes: a provenance tag the build rejects, a third verdict value the aggregator counts as a failure, a self-test that perturbs each check and requires exactly one failure.

Which is why PASS/FAIL was replaced with three verdicts everywhere. Two-valued reporting has nowhere to put “I could not measure this”, and every project that lacks the third value discovers that unmeasured silently means fine. A check that cannot be evaluated must never be indistinguishable from one that passed.

BROKEN-INSTRUMENTS.md §Synthesis, §What actually caught these

The camera's closest pass of the whole film: the car nearly filling the frame from above, cyan trace livery and the driver's helmet legible.

Five rebuilds and one listener

Every rebuild measured better than the last. Every one was rejected by ear.

The soundtrack is one continuous synthesised mix with no samples in it anywhere. The listener is the camera: per audio block, the car-to-camera distance and radial velocity come out of the telemetry and the camera path, and doppler, inverse-square falloff, progressive air absorption and stereo position are applied continuously for the whole 124 seconds. The pass above produces its doppler sweep because the maths never stops running, not because that moment was special-cased.

And it was rejected, repeatedly, by someone with ears

AUDIO IS SHIT SOUNDS LIKE A HAIR BLOWER

the client

That turned out to be a precise physical diagnosis rather than a metaphor. The exhaust's mode series had been truncated at its fourth term, so the highest harmonic anywhere in the engine was 1,936 Hz; the turbo's three tones sat at 12.5, 25 and 37.5 kHz, two of them ultrasonic. Above 2.6 kHz the film measured −0.65 dB harmonic-to-noise. A hair dryer is a small compressor wheel making broadband noise in a volute. He had identified the component.

Successive rebuilds followed. One was “worse, sounds like a shitty musical” — caused by the gates pointing the wrong way, since the cheapest way to satisfy a periodicity bar and a non-flat-spectrum bar simultaneously is sustained pitched material, which is music. A machine is periodic in rhythm and never in pitch. The next was the one steered into silence. The last fixed the laminated glass.

Then the client heard them and chose the original

orginal audio was better go back to orgininal audio

2026-08-15

So the delivered film carries audio/out/master.wav — the audio that shipped with the render, verified by hashing the audio stream straight out of the delivery master and finding it byte-identical. Every rebuild and every measurement is kept, none is in the film, and the delivery index says so in the same table that names the file, because the last time that table and the decision disagreed it took an audit to notice.

Five successive rebuilds each measured better than the last, and the client rejected every one by ear. Any future pass should treat that as the primary evidence — not as a reason to try a sixth with the same instruments.

Behind: frame 2631 — the trackside pass, the film's closest look at the car

Four days on rented silicon

How 2,978 frames got made

Cycles at delivery quality, 512 samples a frame, on three rented RTX 5090s driven by a broker written for the job. It started on 2026-08-09 and the last frame landed on 2026-08-13 — 2,978 of 2,978 on disk, verified three independent ways.

512samples per frame
3rented RTX 5090s
~283 sper frame, measured
22 GBof delivered PNGs
0frames missing

What the campaign actually hit

Four bad hosts in nineteen rentals

A twelve-hour instance retirement that had never fired on this project in its life fired on all three cards at once, and the wake-ups were predicted before they happened and landed within 3, 9 and 9 seconds. A real five-minute network outage arrived and the middleware held — the best part being that a failed reconcile defaulted to safe: the broker could not reach the provider's API, logged “assuming it still exists”, and thereby did not destroy three healthy GPUs holding 7.7 hours of work.

One job failed with about 101 frames unrendered. It was escalated rather than worked around, and the re-submission was tested as a prediction — predicted 101, rendered 101 — before it was trusted.

R2-3860, R2-3861, R2-3907, R2-3925 → R2-3927

A number this page will not give you

What it cost is genuinely unsettled

The project's own pre-publication audit found five mutually inconsistent totals for the cost of this one render — $185, $131, ~$82, $112.88, and a commit message saying $80 — each presented as a current measured projection in its own file, none cross-referenced to the others. A sibling document had already adjudicated the anchor four of them were fitted to, and that adjudication never propagated.

The audit then declined to name a final figure, because isolating this render's own spend needs a join between job rows and instance lifetimes that nobody has done: “Do not publish $141.06 as the master's cost.” So this page does not publish a cost. That is the correct state of the evidence, and a confident number here would be the thirteenth entry in that audit.

DOC-ACCURACY-AUDIT.md §1.11, §U1

The car accelerating away across the apron in full daylight, glass debris scattered on the concrete behind it.
Frame 985. Each of these cost about 283 seconds of a 5090 to exist. A render farm that reports done is not the same as one that delivered a picture: this one shipped a structurally perfect PNG — right dimensions, valid signature, checksum matching what the remote worker computed — containing mean 0.0, standard deviation 0.0, an entirely black image. Every check it had verified that the file was intact. Nothing looked at the picture.
The closing wide: the circuit sweeping away through the landscape, pit buildings along the straight, late afternoon haze.

The last movement

The camera rises, and keeps rising

The ending is a deceleration into a closing wide over the circuit, held for about three seconds. It is also the part of the film with the most uncomfortable entry against it: two claims made to the client about this beat were both withdrawn — one came from reading past a sweep's own in-frame guard, one from a stale placement report — and what they had been concealing was larger than either. The car is out of frame for the film's last 145 frames. Six unbroken seconds.

It is on this page because it is in the log, and because a page that showed you the closing wide without saying what is missing from it would be doing exactly what the log exists to stop.

Behind: frame 2851 — beat 6, the closing wide

The engineering log

Written as the work happened, including the parts that were wrong

1,226 entries across 61,810 lines, appended chronologically, never edited to be right. When an entry turns out wrong a later entry corrects it and both stay — one of them retracts its own author's published finding in full, then carries an appended note saying the retraction's replacement number was also wrong. Follow the chain forward, not the first statement you find.

Read as a success story it is misleading. Read as a record of being wrong in public it is the most useful thing here.

  • BROKEN-INSTRUMENTS.md start here

    The essay. One failure catalogued twenty-six times across subsystems that share no code, grouped by mechanism rather than by subsystem, and written to need no knowledge of films, audio or render farms. Ends with the two claims that circulated as project folklore and did not survive contact with their own source entries — recorded as corrections rather than quietly dropped.

  • READING-LIST.md live

    Roughly sixty entries out of 1,226, chosen because they carry something transferable rather than because they were the biggest fixes. There is a ten-minute list at the top. Grouped into: instruments that could not detect what they existed for; claims made, tested and retracted; fixes built, measured and correctly not shipped; the world and its three constraints; the render campaign; a dozen agents sharing one box; the audio; and the laws the project generalised.

  • DEFECT-LOG-R2.md live

    The merged log itself — 1,226 entries, 61,810 lines, 3.2 MB, in merge order rather than numeric order. Plus 81 staging files holding the in-flight tail. The numbering conventions all exist because of specific incidents, including the rule that when two entries collide on a number, the one external code already cites keeps it.

  • DOC-ACCURACY-AUDIT.md read before quoting

    A pre-publication audit hunting exactly one class: a claim that was true when written and is false now, and a correction that never propagated to the other places the original claim lives. Twelve severity-1 findings. Every one was settled against something that is not a document — PCM hashes of the delivered films, PNG headers on the frames, read-only SQLite against twelve broker databases, --help against the live binary. It also states its own coverage honestly: about 6 % of the corpus, entry-point-down rather than log-up.

  • MASTER-RUNBOOK.md live banner, historical

    The 4K master: the spec, the seven un-waivable gates, and the measured per-beat cost. Its LIVE: THE MASTER IS RENDERING banner describes 2026-08-09 and the render finished on the 13th — read the gates and the cost tables, read the banner as history. The audit lists it as the most authoritative-looking file in the folder and therefore the most dangerous stale one.

  • THE-BRIEF-ROUND2.md the standard

    The client's brief, verbatim. The one-shot law, the ban on downloaded and AI-generated anything, the beat-by-beat shot description, the telemetry contract, and the audio spec down to the engine's harmonic model. The film is judged against this document and nothing else.

  • watch/INDEX.md which artefact is current

    The only place that says which artefact is current and which is stale. It exists because a client judgement was twice formed against an out-of-date file — both correctly labelled at the moment they were cut, and neither labelled at all afterwards. Every file in that folder is a claim about the film whether it was meant as one or not.

  • beat_sheet.json · circuit_spec.json generated

    The generated sources of truth for the camera and the circuit — regenerate rather than hand-edit. Note that the markdown rendering of the beat sheet and its JSON disagree about the film's last image, and a third beat table in circulation is wrong by 910 frames. Prefer the JSON.

Documents this index marks historical are kept rather than deleted, because the measurement behind a superseded decision is usually still the useful part. Several of them told a reader to redo work that had already been landed, measured and reverted; those lines are corrected in place with the correction stated, rather than quietly replaced.

The receipts

What 124 seconds cost

Two ledgers: what the model cost, and what the rented GPUs cost. The first is the client's own account report, pasted in unedited. The second is derived from twelve render-broker databases, and it disagrees with itself in one place — which is stated below rather than resolved by picking the nicer number.

Tokens through the model

26.0 billion

26,004,361,947 exactly

Almost none of it is writing. 96.2 % is the model re-reading its own context — 25,023,113,858 cache-read tokens — and only 94,473,381, or 0.36 %, are output: the work actually written. For every token produced, 275 were read back.

Model spend

$20,740.23

25 days of usage · 2026-07-23 → 2026-08-17

An average of $829.61 a day across four model versions. The busiest day by volume was 2026-07-29 — 2,998,959,667 tokens inside twenty-four hours, three billion in a day. The most expensive was a different one: 2026-07-25, at $2,162.00.

vast.ai — whole account

$229.76

2026-07-19 → 2026-08-18 · instances $229.76 · serverless $0.00 · storage $0.00

Every rented GPU on the account for the whole period. Path-tracing 2,978 frames of 4K was the cheap part: the model cost ninety times what the silicon did.

GPU-hours · summed per frame

336.2

per job 161.9 h · per frame 336.2 h · wall clock 472.5 h — three measurements, three questions

14.0 GPU-days of render time to make 124 seconds of film, summing the per-frame rows of all twelve broker databases. 231.7 h of that is the delivered film render itself. This number has no single correct definition and the page has now got it wrong twice by pretending it did: 161.9 h is the jobs column and is a floor; 472.5 h is the merged wall clock and is closest to what the money actually bought. Which one is right depends on the question, so all three are printed here and the method is on every one of them.

Frames delivered

2,978

3840 × 2160 · 24 fps · 124.083333 s · one camera · zero cuts

23,349,420,712 bytes of 8-bit PNG went in; an 880 MB HEVC file came out, a 26.5× reduction. Nothing in any of those frames was downloaded, photographed, or generated by a model.

Everything

$20,969.99

$20,740.23 model + $229.76 GPU

$169.00 for every second of finished film, or $7.04 a frame. It counts machines and nothing else: no human time is in this figure, because the record does not contain any.

The 2,978-frame 4K film was the cheap part. The expensive part was the thinking.

Model usage · 2026-07-23 to 2026-08-17 · the client's own account report, reproduced without recomputation
Token classTokens Share of all tokens
Input — what was typed to it 1,029,100 0.004 %
Output — the work actually written 94,473,381 0.363 %
Cache writes — context committed for re-use 885,745,608 3.406 %
Cache reads — context read back again 25,023,113,858 96.227 %
Total 26,004,361,947 100 %

Four model versions appear in that report — opus-5, fable-5, sonnet-5 and opus-4-8 — and the four token classes above are the whole of it: the report has no fifth column and this page has not added one. The bars are linear and share one scale, which means the top two are drawn at the chart's minimum width rather than at their true length: 0.004 % of a track that wide is a small fraction of one pixel. They are not equal to each other — output is ninety-two times input — and the figures beside them are the measurement. The bar is only there to show what 96 % looks like next to everything else.

Rented GPUs · twelve broker databases, plus the account's own billing total
MeasureValue How it was obtained
Billed to the account $229.76 2026-07-19 to 2026-08-18. Instances $229.76, serverless $0.00, storage $0.00. The account's own credit ledger reconciles against it to within one cent, so it is corroborated rather than merely quoted.
Render time — per job 161.9 h 582,907 s, summing one duration per job across all twelve databases. This is the figure in the cost file. It understates.
Render time — per frame 336.2 h 1,210,393.4 s, summing the per-frame rows in the same databases — 10,952 of the 10,954 records carry a time. Better supported; see below.
The delivered master alone 231.7 h 833,958.9 s of per-frame time over the three render blocks — 1‑993, 994‑1986, 1987‑2978.
Broker busy, wall clock 472.5 h Every job's start-to-finish interval, merged per broker, then summed. A third independent reading; it brackets the per-frame figure from above, as it should.
Jobs run 2,764 2,251 completed, 390 cancelled, 123 failed — an 81.4 % completion rate. 2,569 were renders and 195 were remote script runs.
Frame records 10,954 3.68 per delivered frame — but 7,609 of them are 720p or smaller rehearsals. At full delivery resolution it is 3,120 rendered against 2,978 shipped: 4.8 % more 4K frames than were used.
Instances rented 155 Distinct instance IDs in the broker logs. Thirty-nine of them were rented to render the one continuous shot.
Hosts blacklisted 11 + 18 Eleven machines and eighteen offers banned by the broker after failing to deploy or failing mid-render.
Effective rate — per GPU-hour of render $0.68/h $229.76 over 336.2 per-frame GPU-hours. Two earlier figures were published and both had the wrong denominator: $1.42/h divided by 161.9 h, the per-job floor; $0.58/h divided by 393.5 h, a total that added the master's frame-level time onto a jobs column that already contained the same master.
Effective rate — per rented hour $0.49/h $229.76 over the 472.5 h of merged wall clock above. This is the closer of the two to what vast.ai actually billed, because boot, image pull, scene upload, idle and teardown are all billed and none of them is render time. It is still not the invoice: the brokers stop recording when they stop, and an instance that was up but idle outside every job interval is in neither figure. Settling that needs a join between job rows and instance lifetimes that nobody has done.
What a single 4K frame cost to exist
Frame-level costValue Note
Average, across all 2,978 frames 280.0 s Four minutes and forty seconds of an RTX 5090, per frame, at 512 samples with adaptive sampling switched off.
Fastest frame194.7 s
Slowest frame445.1 s 2.3× the fastest.
Per render block: 1‑993 / 994‑1986 / 1987‑2978 243.7 / 311.2 / 285.2 s A 28 % spread between blocks of one continuous shot. That is host-to-host variation on rented hardware, not scene difficulty.
The frames on disk23.35 GB 2,978 PNGs at 3840 × 2160, 8-bit RGB, mean 7.84 MB each. The ProRes 422 HQ master off the back of them is 11.25 GB; the HEVC viewing copy is 880 MB.

The number that is a floor

161.9 GPU-hours is smaller than one of its own parts

The per-job sum of 161.9 hours reproduces to the second, and the arithmetic is right. The column is wrong. The jobs table stores one duration per job, and a job that rendered a 993-frame block stores a number that is not the sum of its frames: 1,080.2 seconds recorded against 242,034.1 seconds of its own frame rows, on a job whose clock ran for 262,607.4.

Summed per frame instead, the same twelve databases give 336.2 GPU-hours — and the delivered master on its own is 231.7, already more than the figure meant to cover the entire project. A total cannot be smaller than one of its parts.

So both readings are printed above, with the method beside each. The authoritative cost file was not quietly edited to the better number, because a page about measuring things honestly does not get to correct its own sources in silence.

project-cost.json gpu · project-facts.json corrections.gpu_hours_undercount

What the money still does not say

The account total is known. This render's share of it is not.

$229.76 is what the account was billed, and it reconciles against its own credit ledger to the cent. What it does not do is say how much of that belonged to the final master, because isolating one render's spend needs the same job-to-instance join that nobody has done.

The project's own pre-publication audit found five mutually inconsistent totals in circulation for that one render — $185, $131, about $82, $112.88 and $80 — each written as a current measured projection in its own file, none cross-referenced to the others. A sixth, $132.57, sits in another document for the same render. The audit declined to pick one, and so does this page.

That is the cleanest argument here for why a blank is better than a plausible number: six confident figures already exist for a quantity nobody measured.

DOC-ACCURACY-AUDIT.md §1.11, §U1 · project-facts.json infrastructure.spend_evidence_that_exists

Why any of this should be believed

The instruments lied twenty-six times, and each one is written down

Behind these figures sit 1,678 numbered log entries and 1,322 defect entries, appended in order and never edited to look better afterwards. A companion essay pulls twenty-six of them out and sets them side by side: twenty-six instruments that could not measure the thing they existed for, sorted into seven families by mechanism. A limiter reported 0.124 dB of gain reduction while removing about twenty-two. A quality gate's maximum possible score turned out to be silence. A winding test printed ALL PASS with twenty-four of forty-four surfaces deliberately reversed. A wheel gate reported a perfect 0.0 mm out of a loop whose body never executed. A treeline scored 99.24 % against a reference picture it shared nothing with. A structurally perfect PNG — right dimensions, valid signature, checksum agreeing with the remote worker — was delivered and counted with no picture in it at all.

None of the twenty-six was caught by code review. Three reviewers read one of the comments and all three agreed with it, because the comment described the intent correctly and was simply false about the order the code ran in. What caught them was cheaper and less flattering: controls fed a degenerate signal that had to fail, positive controls built from first principles that had to pass, mutation-testing the gates themselves, writing the predicted number down before measuring, and never moving a threshold to make something pass. Eight defects on this website were found by the client by hand, after every automated check had gone green.

A cost page is the easiest place in a portfolio to round in your own favour. The reason these figures carry their method, their limits and their disagreements is that this project has a documented history of numbers that were confident and wrong — and the only useful response was to publish the correction next to the claim.

BROKEN-INSTRUMENTS.md · DEFECT-LOG-R2.md · USER-DEFECTS.md

Every figure above is held in two data files that ship with this page, each value carrying its own source and status. Where a value is marked not measured it is blank on purpose and stays blank until something measures it. If one of these numbers turns out to be wrong, the useful artefact is the log entry that says so — not a quiet edit to this page.

Follow on X