Apply post-M1 corrections to the planning package
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# ADR 002 — Ollama Is the v1 Model Backend
|
||||
|
||||
**Status:** Accepted
|
||||
**Status:** Accepted; transport/TLS consequence added after M1
|
||||
|
||||
## Decision
|
||||
|
||||
@@ -30,3 +30,31 @@ Ollama is already available locally, provides a simple local API, supports both
|
||||
- LAN inference does not imply LAN exposure of the storyteller UI/API; the storyteller should still bind to loopback by default,
|
||||
- arbitrary public Internet/cloud model endpoints remain outside normal v1 configuration,
|
||||
- future backend abstraction may be added, but v1 should not be delayed to support it.
|
||||
|
||||
## Transport for a Trusted-LAN Endpoint
|
||||
|
||||
Added after M1. Same-host Ollama speaks plain HTTP over loopback, and it was
|
||||
assumed a LAN endpoint would look the same. It does not have to.
|
||||
|
||||
A trusted-LAN Ollama may be served over **HTTPS with a certificate issued by a
|
||||
private or local CA** rather than a public one — a self-hosted server that
|
||||
terminates TLS for everything it exposes is the ordinary case, not an exotic
|
||||
one, and it may offer no cleartext port at all. A v1 client that trusts only a
|
||||
bundled public-CA list cannot talk to such a host, while `curl` and the user's
|
||||
browser on the same machine can.
|
||||
|
||||
Therefore:
|
||||
|
||||
- production clients must verify against the **operating system's trusted CA
|
||||
store** in addition to any bundled certificate list, so a CA the user has
|
||||
installed on their own machine is honoured by this application too;
|
||||
- certificate **and hostname** verification remain fully enabled;
|
||||
- there must be **no "ignore TLS errors" / "insecure" option**, in the UI,
|
||||
in configuration, or as an environment variable. A LAN endpoint the machine
|
||||
does not trust is a configuration problem to fix at the OS level, not a check
|
||||
to switch off;
|
||||
- the endpoint URL must therefore accept `https://` on any port, not only
|
||||
`http://…:11434`.
|
||||
|
||||
M1 implemented this (`backend/app/tlstrust.py`); see
|
||||
`planning/reports/M1-IMPLEMENTATION-REPORT.md` §G.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# ADR 004 — Local-Only Production Default
|
||||
|
||||
**Status:** Accepted; Phase 0B hardening requirements identified
|
||||
**Status:** Accepted; Phase 0B hardening requirements identified; testing consequence strengthened after M1
|
||||
|
||||
## Decision
|
||||
|
||||
@@ -31,6 +31,27 @@ The selected AI-DnD base does **not** satisfy this requirement unchanged:
|
||||
|
||||
These are bounded production-hardening tasks rather than reasons to reject the fork.
|
||||
|
||||
## Testing Consequence
|
||||
|
||||
Strengthened after M1, which confirmed the failure mode this rule exists to catch.
|
||||
|
||||
**Offline behavior must be tested with a fresh cache/data state on a machine
|
||||
with no route to the Internet.** Both inherited violations above were *first-use*
|
||||
downloads: `tiktoken` caches its encoding to a temp directory, and the browser
|
||||
caches Google's fonts. On any machine that had been online once, both were
|
||||
invisible — the application appeared to work offline while depending on an
|
||||
artifact an earlier online run had left behind. Neither was findable by static
|
||||
analysis; each took an actually isolated run to surface.
|
||||
|
||||
Therefore an offline claim is only evidence when the test:
|
||||
|
||||
- runs on a network with **no route out and no external DNS**, verified before
|
||||
the test rather than assumed,
|
||||
- starts from a **fresh application data directory and a fresh cache**, so
|
||||
nothing warmed by a previous run is available,
|
||||
- exercises the **first** story turn, which is when a first-use download fires,
|
||||
- observes actual network destinations rather than only the absence of an error.
|
||||
|
||||
## Consequences
|
||||
|
||||
The production application must avoid or remove:
|
||||
@@ -48,4 +69,11 @@ The production application must avoid or remove:
|
||||
|
||||
Production packaging must contain all runtime assets required for ordinary story use after the user has installed the intended local Ollama models.
|
||||
|
||||
Vendored runtime artifacts should be **integrity-verifiable where practical**: a
|
||||
recorded source and a digest the application checks when it loads them, rather
|
||||
than an opaque blob nobody can re-derive. A substituted or truncated artifact
|
||||
should then fail loudly instead of silently changing behavior — a corrupted
|
||||
tokenizer table, for instance, would quietly change every token count the
|
||||
context budget is computed from.
|
||||
|
||||
The storyteller application should bind to loopback by default. Ollama should default to same-host loopback but may be explicitly configured to an approved trusted-LAN endpoint for v1. This LAN inference path does not authorize LAN exposure of the storyteller UI/API. Arbitrary public/Internet inference endpoints remain prohibited in normal v1 configuration.
|
||||
|
||||
Reference in New Issue
Block a user