M8: the browser becomes the storyteller

The interface was AI-DnD's with this product's features bolted into it. The
navigation read Home · Adventures · Scenarios · Settings · AI Chat; starting a
story meant first picking a *world*, and making a world meant a JSON stat-schema
form, a story-card table and an art picker. The play screen had a Branches tab.
The input had three modes. Sixteen of the sixteen controls on a two-turn story
had no accessible name — they were single glyphs with a tooltip.

All of that was measured in a real browser before anything was changed, and the
measurements are in planning/reports/M8-IMPLEMENTATION-REPORT.md §C. Almost
nothing underneath was wrong: the play loop, the history controls, the takes,
the Save Points, the state correction and the knowledge library all worked. What
was wrong was what a reader was asked to understand in order to use them.

So the shape now is one entry point and one screen:

  Campaigns -> Campaign -> Story
                           State · Knowledge · Context · Save Points · Settings

Everything that is not the story lives in a panel that starts closed. The
top navigation bar is hidden on the story screen entirely, because on that one
screen the story is the interface.

Play is one natural-language field. An action and a piece of quoted dialogue are
both just what the reader wrote, and B01/B02 confirmed against a real narrator
that the model reads the quotes without being told which kind of turn it is.
What survives from the old Story mode is a Story direction toggle, which is not
a fourth mode: it changes who is being spoken to, not what kind of action is
taken, and the box is visibly marked while it is on.

Branch, fork, node, merge and head appear nowhere a reader can see them. The
branch panel and the tree overlay are gone from the browser. The mechanism is
untouched — takes, divergence, retained futures and Save Points all still work,
and their endpoints are still tested. This is a decision about what a reader is
asked to understand, not a reduction of what the product can do.

The two defects worth the space:

A player action is stored with AI Dungeon's "> You " prefix. That was right when
the Do mode asked for a bare verb phrase. With one field the spec tells the
reader to write "I enter the tavern", and the result was "> You I enter the
tavern." — in the transcript, in the replayed history, and therefore in the
narration, where a small model imitates it and writes "You I thank her". M8's
own design surfaced it, so M8 fixed it: the prefix is added only when the reader
has not already written a subject. The ">" marker, which is what actually
identifies a player turn in the prompt, is unchanged in every case.

And a stale `.input-bar { display: flex }` in play.css overrode the new
composer, because that sheet is imported after the new one. The direction row
and the input row laid out side by side and the box was unusably narrow. Found
by opening the product in a browser, not by reading the CSS — which is the
argument for having done that first.

Failures now have the taxonomy the spec asked for rather than one toast: model,
generation, state, knowledge, server, each with the thing to do about it. A
failed turn leaves the reader's words in the box and says so. The classification
reads backend strings, so it is a fallback ladder rather than a lookup — an
unrecognised message still classifies, still shows the server's own words and
still offers Retry.

`Settings.model` could be empty with nothing saying so until the first turn
failed with a provider error. The header now reports Ollama in five states, and
an unconfigured or missing model offers the models actually installed on the
endpoint, from the connection test that already knew them. Nothing is chosen
automatically: an endpoint's first model may be an embedding model, which cannot
narrate at all.

Narrator prose is rendered as safe Markdown — headings, emphasis, lists,
blockquotes, code. The safety is structural rather than filtered: every node is
a React element built from parsed text, and there is no dangerouslySetInnerHTML
in the file. A sanitizer is not needed to make markup safe if markup is never
produced from input. Link schemes are checked with the URL parser rather than a
pattern, because the bypasses are all in the parsing. A remote image is a
placeholder naming the blocked address; the knowledge and context panels
deliberately do not use this renderer at all, because they exist to show a
reader exactly what is in their file.

Backend, and only what the browser could not otherwise reach:

  AdventureCreate.opening   a start action could only come from a Scenario, so
                            every campaign made in the new setup flow opened on
                            a blank page. Same node, same code path.
  canon_rules               campaign_canon has been the highest authority in a
                            campaign since M5, read by the prompt builder and
                            the state validator, and had no API at all — a
                            fixture had to write it with SQL.
  a 401 and a 429 message   the last user-facing text describing a hosted
                            deployment. One told the reader to check an API key
                            that has not existed since M2.

No schema change and no migration: proved by building a database with a server
running the M7 commit's own code and opening it with this one.

The project had no frontend tests. It has 132 now, across ten files, running
in about six seconds — the enabled state of every history control, the take
selector, the confirmations, the panels, the five model states, the failure
taxonomy, the focus trap, accessibility, and that the reserved dictation control
never touches the microphone. Writing them found a real defect: the focus trap
filtered candidates with offsetParent, which is null inside the fixed-position
ancestor the dialog has and which jsdom never computes — it would have behaved
differently in the tests from the browser.

They do not replace the real-browser runs, and both kinds of evidence are in the
report. The browser suites drive the production build served by the real backend
with a real local narrator, including a genuine process restart.

A verification pass over all of it then found three more, each by driving the
product rather than reading it:

Stepping between alternate takes did nothing. The pager asked whether a take
lived on another line by comparing `target.branch_id !== action.branch_id`, and
`ActionOut` has never carried `branch_id` — so the comparison was permanently
`number !== undefined`, always true, and every step took the branch-switch path.
For two takes of an ordinary retry, which share a line until one is written
below, that meant switching to the line already being read: the same window came
back and nothing moved. D07 is a required v1 acceptance test. The fix needed no
new field — the variants list already carries every attempt's branch and marks
the live one.

The first regression test for that passed against the broken code, because its
fixture gave the action a `branch_id` the real payload never sends. That is the
exact failure M7's review was about, so the fixture was corrected, the tests were
re-run against the reverted code and failed for the right reason, and the
fixture now carries a docstring saying why the field must never come back.

And the knowledge panel pointed readers at an "embedding model" while the
setting is called "Model for meaning-based search" — a reader sent looking for a
field that does not exist by that name.

Campaign canon was measured rather than assumed. Editing it after play is a
configuration change: every turn already played keeps the canon it was actually
given, in its own context snapshot, and the accepted story, the state document
and the state audit log are byte-identical across an edit. It is not routed
through M5's state audit, because canon is not narrative state and doing so
would create the second representation the spec forbids. What the editor does
now is say so, once a campaign has moments.

`BROWSER-UX-SPEC.md` §38 asked for a "Show Hidden Story State" toggle. There is
no hidden story state — a secret lives in a narrator-only knowledge source and
never enters the state document. The section is rewritten to require what it
actually meant: ordinary surfaces must not carry narrator-only information,
advanced inspection must withhold it by default behind an explicit warned
choice, and no second store may be invented to give a toggle something to
reveal. The protection is stricter than before, not weaker.

Closeout. An independent review returned M8 IMPLEMENTATION: PASS subject to
evidence and documentation cleanup, and this commit carries that cleanup:

The report named two frontend bundles as the artifact behind its acceptance
evidence. The saved run logs settle it. index-Ii-lARp9.js, built at 18:53:02
from this tree, is the one final frozen artifact behind all 157 browser checks;
index-C6E5Uvtu.js is superseded — it predates the D09 fix and its acceptance
suite ended 54/55 on exactly that defect. No tracked file under backend/app or
frontend/src has a modification time after the freeze, so the whole final
campaign describes one build. §P sets the two side by side.

Finding 14 — the app budgets 16,384 prompt tokens while an Ollama that sees no
VRAM enforces 4,096 — is resolved operationally, with no application change.
The OpenAI-compatible endpoint this app speaks accepts num_ctx and ignores it,
and reloads the model at its own default, so a native call cannot prime it
either. A model derived with POST /api/create carries the parameter, is honoured
through the app's own OpenAI-compatible path, and appears in /v1/models — which
is the listing the Settings model picker already reads. Measured end to end.
The procedure is in DEVELOPMENT.md; nothing in the repository depends on any
particular derived model existing. Adding provider code to work around this was
declined deliberately: it would mean either a second native request path,
against ADR 011, or a parameter the endpoint provably ignores.

The §38 rewrite is ratified as a requirement clarification aligned with the
implemented architecture, and the spec gains the clause finding 3 was really
about: withheld material must be absent from the rendered DOM, not merely
collapsed in it.

The report's §U carries the M9 handoff — what a portable campaign has to include,
whether historical context snapshots belong in the bundle, what happens to
inherited story cards, and that a restored campaign may meet a different context
window than the one that wrote it. None of it is implemented here.

Final: backend 950 passed / 14 skipped; frontend 132 passed; lint, production
build and Docker build clean; 157 browser checks across six suites, zero
failures. M8 is implemented, verified, reviewed and accepted (2026-09-06).
M9 has not been started.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017HdaXiFbscatQaLS7dJk6b
This commit is contained in:
JesseMarkowitz
2026-09-06 23:31:45 -04:00
co-authored by Claude Opus 5
parent 480414efe0
commit 1ce9972760
89 changed files with 11985 additions and 6532 deletions
+85 -9
View File
@@ -184,6 +184,15 @@ unless inherited UI makes them useful without complexity.
Optional helpers may exist.
### As implemented in M8
One field. The inherited `Do` / `Say` / `Story` selector is gone: an action and
a piece of quoted dialogue are both just what the reader wrote, and B01/B02
confirmed against a real narrator that the model reads the quotes without being
told. What survived from `Story` mode is the direction toggle in §13, which is
deliberately not a fourth mode — it changes who is being spoken to, not what
kind of action is taken.
## 13. Out-of-Character Direction
The user should have a way to provide story-direction instructions.
@@ -468,6 +477,21 @@ Open Threads
Keep concise.
### As implemented in M8
The server groups the state and the panel renders the groups, so the section
headings are whatever the campaign has established rather than a fixed list —
a campaign with no items shows no Items heading. Nothing is rendered as JSON,
and each row offers **Correct** and, for a fact, **That's wrong**.
**There is no hidden dimension in the narrative state**, so there is nothing
here to reveal. A secret never enters authoritative state: it lives in a
knowledge source marked narrator-only, which the narrator is told not to
disclose. M7 verified against a real narrator that the secret stays out of the
state document. §38's requirement is met by this panel simply not containing
narrator-only information; the surface that must actively withhold it is the
context inspector — see §57.
## 32. Current Scene Section
Show:
@@ -544,19 +568,44 @@ Visual profile
Advanced data may be hidden behind expandable sections.
## 38. Hidden Narrator State
## 38. Hidden Narrator Information / Spoilers
Some campaigns may contain secrets.
Some campaigns contain secrets the narrator knows and the protagonist does not.
Normal player-facing state panel should not reveal narrator-only facts by default.
The requirement is:
Provide optional advanced mode:
- ordinary State and story surfaces must not expose narrator-only information;
- an advanced inspection surface that can contain hidden Canon or narrator-only
context must **withhold it by default**;
- revealing it requires an explicit, clearly labelled user action;
- the UI must warn that doing so may reveal campaign secrets;
- withheld material must be **absent from the rendered DOM**, not merely
visually collapsed — a closed `<details>`, a `hidden` attribute or a
`display: none` rule still leaves the text findable by browser search, by the
accessibility tree and by anyone reading the page source;
- **no second hidden-state store or duplicate representation** may be introduced
solely to give the UI something to toggle.
```text
Show Hidden Story State
```
### Where the secret actually lives (ratified at M8)
with clear warning.
This section originally described a `Show Hidden Story State` control on the
state panel. That named the wrong surface, and M8's review ratified the
correction.
Narrator-only material is not held in the narrative state. It is held in the
knowledge/canon system, as a source marked narrator-only, and the narrator is
instructed not to disclose it. A secret therefore never enters the state
document at all — M7 verified that against a real narrator — so a toggle on the
state panel would reveal nothing, and building a hidden-state dimension to give
it something to reveal would create exactly the duplicate representation the
requirement above forbids.
The surface that genuinely needs protecting is **advanced context inspection**,
because a retrieved narrator-only passage is reachable there. That is where the
default-withheld behaviour belongs, and where §57 records it as implemented.
The vocabulary for this is **hidden-information inspection** — not
"hidden-state", which implies a state subsystem that does not exist.
## 39. Campaign Sidebar / Menu
@@ -824,6 +873,14 @@ Optional advanced tab:
Rendered Prompt
```
### As implemented in M8
The M7 panel opened on 11,996 characters of assembled prompt. The M8 panel opens
on the same campaign at about 1,400: token usage, then what the narrator read,
what the story remembered, the summary, how much history was sent, and what
produced it — each collapsible. The assembled prompt is the last section and is
closed.
## 56. Retrieved Memory Row
Example:
@@ -864,6 +921,25 @@ answer rather than a silence.
Click-to-open-source is not implemented; the Knowledge panel is one click away
and lists the same file.
### As implemented in M8
Click-to-open-source **is** implemented: the row carries `source_id`, and the
filename is a button that opens the Knowledge panel on that source rather than
on the list.
The rows were also rewritten to read rather than to enumerate — `found by
hybrid · closeness 0.71 · 40 tokens` in place of a run of raw scores — and the
class tag is now the same component the Knowledge panel uses, so a class looks
the same wherever a reader meets it.
**Narrator-only passage text is withheld by default.** This is where §38's
hidden-information requirement actually lands: the only place a campaign's secrets are
reachable from an ordinary screen is a retrieved passage that was marked
narrator-only. The row shows the file, the class and the badge, and the text is
replaced by *"Hidden — this passage is narrator-only"* until the reader ticks a
control that says what it will reveal. Turning it on is a preference in that
component and nothing else: it changes no retrieval, no prompt and no state.
The passage text is rendered as a text node in a `<pre>`, never as markup. That
is where H06 and H07 are decided for imported content, and it is the reason a
Markdown renderer was not added here for appearance.
@@ -1432,7 +1508,7 @@ The final v1 browser interface must support:
- collapsible state panel,
- direct entity inspector,
- token usage display,
- hidden-state inspector,
- spoiler-aware advanced inspection of hidden narrator information,
- knowledge retrieval provenance,
- clear local-only status.
+109 -2
View File
@@ -1,6 +1,6 @@
# Adventure Storyteller — Production Build Milestones
**Status:** In implementation. M1-M7 complete and accepted (M1 and M2: 2026-09-02; M3 and M4: 2026-09-03; M5: 2026-09-04; M6 and M7: 2026-09-06, each of the last three after an independent review and a corrective pass); M8 — Finished v1 browser experience — next to brief
**Status:** In implementation. M1-M8 complete and accepted (M1 and M2: 2026-09-02; M3 and M4: 2026-09-03; M5: 2026-09-04; M6, M7 and M8: 2026-09-06, each of the last four after an independent review and a corrective pass). **M9 — Export, Backup, Recovery, and Migration Hardening — is next, and has not been started.**
**Base:** AI-DnD `d72f7c1bda0f34fccd84afb7a25c34eb01c901de`
## 1. Purpose
@@ -829,7 +829,7 @@ CORRECTIVE WORK REQUIRED*, a corrective pass that closed both blocking findings,
and a closeout verification that resolved the calibration boundary the
corrective pass had left as debt. Report, including the original findings, the
corrective closeout and the closeout verification, all preserved in sequence:
`reports/M7-IMPLEMENTATION-REPORT.md`.
`archive/milestone-reports/M7-IMPLEMENTATION-REPORT.md`.
**M8 is authorized.**
@@ -976,6 +976,113 @@ Turn the adapted AI-DnD interface into the focused interactive-story workspace d
Normal story creation and play feels like a focused local storyteller rather than an RPG or developer console.
## Status: COMPLETE / ACCEPTED — 2026-09-06
Implemented on `m8-browser-ux` from the signed M7 commit `480414e`, verified in
a real browser against a real local narrator, independently reviewed, and
accepted at closeout on 2026-09-06. The independent review returned
`M8 IMPLEMENTATION: PASS` subject to evidence and documentation cleanup, which
the closeout completed: the build-evidence classification in the report's §P and
finding 14's resolution.
`planning/reports/M8-IMPLEMENTATION-REPORT.md` records what was built, what was
measured and every finding, including the seven product defects verification
found, the five harness defects, and the evidence runs that were discarded.
**Closeout evidence**
- **Real-browser verification against a real local narrator** — 157 checks
across six suites, zero failures, all from one frozen production build
(`index-Ii-lARp9.js`): acceptance 57/57, hidden-information sentinel 21/21,
A05 failed generation 23/23, security/offline 27/27, genuine process restart
12/12, migration against an M7-built database 17/17.
- **A frontend test foundation, which the project had never had** — 132 tests
across 10 files, running in about six seconds. Backend: 950 passed, 14
skipped, 0 failed. Lint, production build and Docker build clean.
- **Reader-facing terminology audit: 0 hits** across 17 normal-play components
and both advanced surfaces.
- **No schema change and no migration.** Proved by building a database with a
server running the M7 commit's own code and opening it with M8's.
- **`BROWSER-UX-SPEC.md` §38 clarified and ratified** — hidden narrator
information is withheld at the surface that can actually expose it, and is
absent from the DOM rather than collapsed in it. No hidden-state subsystem was
invented, and none is required.
- **Carry-forward:** the four M9 handoff questions in the report's §U
(portability scope, historical context-snapshot provenance, legacy story
cards, context-window portability), and finding 14's context-window ceiling,
whose long-campaign release validation stays with **M11**.
**M9 is next and has not been started.**
**What M8 delivered, beyond the scope list above:**
- **One entry point, and everything else inside a campaign.** The navigation was
`Home · Adventures · Scenarios · Settings · AI Chat`; it is now the campaign
library and Settings, with State, Knowledge, Context, Save Points and campaign
Settings reachable from the story screen's own panel.
- **A campaign is created from a form, not from a template.** The scenario
gallery and its editor — a JSON stat-schema form, a story-card table and an
art picker — are gone from the browser. Setup asks for a name and offers
genre, tone, voice, length, protagonist, opening scene and canon, none of it
required and none of it genre-specific.
- **`campaign_canon` reached the browser.** It has been the highest authority in
a campaign since M5, read by the prompt builder and the state validator, and
had no API at all — a fixture had to write it with SQL.
- **A resolution path for a blank model.** `Settings.model` could be empty with
nothing saying so until a turn failed. The header now reports Ollama's state
in five cases, and an unconfigured or missing model offers the models actually
installed on the endpoint. Nothing is chosen automatically: an endpoint's
first model may be an embedding model, which cannot narrate.
- **Failures have §71's taxonomy** rather than one toast, and a failed turn
leaves the reader's words in the box (A05).
- **Safe Markdown for story prose.** Headings, emphasis, lists, blockquotes and
code, built as React elements from parsed text — no `dangerouslySetInnerHTML`
anywhere. A remote image is a placeholder, and a `javascript:` URL never
becomes an href.
- **A frontend test suite**, which the project had never had.
**Two defects found by driving the product, and fixed here:**
- **`> You I enter the tavern.`** AI Dungeon's player-input convention prefixes
`> You `, which was right for the Do mode's bare verb phrase and wrong for
§12's one natural-language field. It reached the transcript, the replayed
history and therefore the narration, where a small model imitated it. Now the
prefix is added only when the reader has not already written a subject.
- **A stale `.input-bar { display: flex }`** in `play.css` overrode the new
composer layout, because that sheet is imported after the new one. Found in
the first browser pass, not by reading the CSS.
**Debt carried forward, deliberately:**
- **A deployment's context ceiling may be far below the app's budget —
RESOLVED operationally, no code change.** Ollama defaults to a 4,096-token
input window when it sees no VRAM; `Settings.context_token_budget` defaults to
16,384. The OpenAI-compatible endpoint the app speaks accepts `num_ctx` and
silently ignores it, and reloads the model at its own default, so priming over
the native API does not help either. The remedy, verified end to end through
the app's own path, is a **derived model** carrying `PARAMETER num_ctx`,
created over `/api/create` and selected in Settings — no shell access on the
Ollama host, no application change, and it appears in the model picker
automatically. `DEVELOPMENT.md` carries the procedure under *"The context
window your Ollama actually enforces"*. **Nothing was truncated in M8** — the
largest assembled prompt across every suite was 2,498 tokens. This is now an
**operational/deployment note, not an open defect**: M11 should confirm the
window on the deployment it certifies against before its 100-turn run, and M9
should note that an imported long campaign reaches a small ceiling
immediately. A Settings-screen warning that reads the real window and compares
it to the budget remains an unowned usability improvement.
- **Story cards are no longer editable in the browser.** The backend keeps them
and the bundle still carries them; the M7 knowledge library supersedes them
for v1, and showing both would offer two unrelated systems for "things the
narrator should know".
- **The RPG world state is read-only.** It still appears in the context
inspector for a campaign that has one; the editing drawer is gone (§18).
- **Copy is per-message only.** §77's "copy the whole transcript" and §78's
story search are not built.
- **No discarded-history recovery screen** (§63) — explicitly future work.
- **Tablet is usable, not tuned.** Desktop was the target; the narrow-screen
sheet is inherited and was not redesigned.
---
# M9 — Export, Backup, Recovery, and Migration Hardening
+7 -7
View File
@@ -82,16 +82,16 @@ in `planning/archive/decisions/`.
One file, and it changes as development progresses:
```text
planning/reports/M7-IMPLEMENTATION-REPORT.md
planning/reports/M8-IMPLEMENTATION-REPORT.md
```
M4 is the most recently completed milestone, and M5 is the next to be briefed.
This report is M4's review *and* its closeout record: its §W holds the corrective
work, the process-boundary automation, and the real-browser verification that
closed the condition M3 and M4 both carried.
M8 is the most recently completed milestone, and M9 is the next to be briefed.
This report is M8's implementation account *and* its closeout record: its §P
classifies the browser evidence by build, its §S holds every finding, and its §V
records the acceptance.
**Replace it, do not accumulate.** When M5's report lands, remove this one from
the project Sources and upload M5's instead. The repository does the same thing:
**Replace it, do not accumulate.** When M9's report lands, remove this one from
the project Sources and upload M9's instead. The repository does the same thing:
`planning/reports/` holds the current milestone's report and
`planning/archive/milestone-reports/` holds the rest.
+55 -22
View File
@@ -9,9 +9,18 @@ independent review found a real defect and a corrective pass fixed it.
**M7 — First-Class Imported Knowledge Library — is complete** (2026-09-06),
after an independent review, a corrective pass and a closeout verification. Its
report keeps all three in sequence: `reports/M7-IMPLEMENTATION-REPORT.md`.
**Next: M8 — Browser UX Completion for v1 Story Operations.** Its brief has not
been written yet, and writing it is the current action.
report keeps all three in sequence, and is now in
`archive/milestone-reports/M7-IMPLEMENTATION-REPORT.md`.
**M8 — Browser UX Completion for v1 Story Operations — is complete and
accepted** (2026-09-06), after an independent review and a closeout pass.
`reports/M8-IMPLEMENTATION-REPORT.md` is the implementer's account and now
carries the closeout: the build-evidence classification in its §P, finding 14's
operational resolution, and the acceptance record in its §V. The M8 tree is
staged and awaits the repository owner's signed commit.
**Next: M9 — Export, Backup, Recovery, and Migration Hardening.** It has not
been started.
**Package version:** see `VERSION.md`, which records what each revision changed
and why.
@@ -101,8 +110,9 @@ Two standing qualifications:
10. `BROWSER-UX-SPEC.md`
11. `V1-ACCEPTANCE-TESTS.md`
12. `DECISIONS/` — all of them; they are short.
13. `reports/M7-IMPLEMENTATION-REPORT.md`, for what the last accepted milestone
actually left behind. Nothing in `planning/archive/` unless sent there.
13. `reports/M8-IMPLEMENTATION-REPORT.md`, for what the most recent milestone
actually left behind — reading it as a claim to check, not a record, until
it is reviewed. Nothing in `planning/archive/` unless sent there.
## Architectural decisions
@@ -133,15 +143,20 @@ work until Phase 0 closes — which Phase 0 satisfied on 2026-09-01. It is in
`reports/` holds the report for the milestone most recently completed, because
that is the one the next milestone's planning has to consult:
- `reports/M7-IMPLEMENTATION-REPORT.md` — M7's independent review, its
corrective closeout and its closeout verification, in that order and none
overwriting another. It is the longest report in the package because M7 is the
milestone whose first implementation was most wrong, and the sequence is the
point: what was claimed, what was measured, what that forced.
- `reports/M8-IMPLEMENTATION-REPORT.md` — the M8 implementation, its baseline
UX measurement, and the browser evidence for every acceptance test it claims.
Written by the implementer for an independent reviewer, and completed at
closeout after that review accepted the milestone: it is a set of claims with
the measurements attached **and** the record of the acceptance. Its §U carries
the M9 handoff — the four questions the next brief has to decide.
Completed earlier milestones are in `archive/milestone-reports/`, which M6's
report joined at M7's closeout: a milestone report is useful during the
immediate next milestone and historical afterwards. M1-M6 are all there,
**It stays here until M9's report replaces it.** A milestone report is useful
during the immediately following milestone; M8's is not archived merely
because M8 is accepted.
Completed earlier milestones are in `archive/milestone-reports/`, which M7's
report joined when M8's was written: a milestone report is useful during the
immediate next milestone and historical afterwards. M1-M7 are all there,
unedited.
## The decision this package rests on
@@ -258,24 +273,42 @@ Milestone M6 COMPLETE (2026-09-06)
|
v
Milestone M7 COMPLETE (2026-09-06)
first-class imported knowledge reports/M7-IMPLEMENTATION-REPORT.md
first-class imported knowledge archive/milestone-reports/M7-*.md
library review + corrective + closeout, in sequence
|
v
M8-M11, one at a time see BUILD-MILESTONES.md
Milestone M8 COMPLETE / ACCEPTED (2026-09-06)
browser UX completion for v1 reports/M8-IMPLEMENTATION-REPORT.md
story operations review + closeout, in sequence
|
v
Milestone M9 NEXT — not started
export, backup, recovery, see BUILD-MILESTONES.md
migration hardening
|
v
M10-M11, one at a time see BUILD-MILESTONES.md
```
## Stop Rule
**One milestone at a time. Do not begin a milestone before its brief exists.**
**No M8 brief has been prepared.** Writing one is the current action, informed by
the M7 report and by the debt `BUILD-MILESTONES.md` records against M7 — in
particular that the knowledge panel and the Insights knowledge rows are
functional rather than designed, that a "nothing was relevant enough" result and
an uncalibrated-embedding-model warning are both surfaced plainly and want a
considered treatment, and that `BROWSER-UX-SPEC.md` §47's import preview and
§52's retrieval-usage count are not built.
**No M9 brief has been prepared.** Writing one is the current action, informed
by the M8 report and by the debt `BUILD-MILESTONES.md` records against M8 — in
particular that the campaign bundle still carries no context snapshots, so an
imported campaign has no historical prompt provenance; that story cards survive
in the backend and the bundle with no browser surface, and M9 should decide
deliberately whether the bundle keeps carrying them; and that a deployment whose
Ollama enforces a small context window truncates an imported long campaign
immediately unless the `DEVELOPMENT.md` procedure or a matching
`context_token_budget` is applied.
**M8's own carried debt** is recorded under M8 in `BUILD-MILESTONES.md`: story
cards have no browser editor, the RPG world state is read-only, copy is
per-message only, there is no discarded-history recovery screen, and the tablet
layout is usable but untuned. Each names the milestone that owns it; none is an
open M8 condition.
The M6 retrieval debt this milestone was warned about is partly addressed and
partly still open. Imported material does **not** compete with story memory for
+77
View File
@@ -888,6 +888,83 @@ the source, because an imported file has no lineage: the query is built from
`adventures.narrative_state`, which head movement repoints. Nothing reads the
uncapped action table.
## 13.4 The browser is a presentation layer, and M8 kept it one
M8 rebuilt the interface without moving a decision into it. Three rules made
that hold, and each replaced a tempting shortcut:
- **Server-authoritative availability.** Whether Undo and Redo have anywhere to
go is the server's answer, carried on every window it returns. Neither is
derivable in the browser: Undo can reach past the top of the loaded page, and
Redo depends on a retained future the transcript is never sent. A React
component that computed either would be wrong exactly when it mattered.
- **Reading is not deciding.** Stepping between alternate takes tells the server
nothing. The decision is made by writing below one, and that is the only
moment `after_id` is sent. This is why the take pager can be offered on every
turn without any of them becoming a commitment.
- **UI state stays UI state** (§92 of `BROWSER-UX-SPEC.md`). Which panel is
open, whether narrator-only text is revealed, whether a source's detail is
expanded — none of it is written anywhere, and none of it changes what is
retrieved, what is prompted, or what the story believes.
### Failure has a taxonomy, not a toast
`frontend/src/errors.js` sorts a failure into the five kinds §71 names — model,
generation, state, knowledge, server — because each one has a different thing to
*do* about it. It reads the message the server actually sent, which is a
coupling to backend strings, so it is written as a fallback ladder rather than a
lookup: an unrecognised message still gets a kind, still shows the server's own
words, and still offers Retry. Nothing is hidden when the match misses.
### Markup is never produced from input
`frontend/src/markdown.jsx` renders narrator prose, and it is where H06 and H07
are decided for rendered text. The safety is structural rather than filtered:
every node it returns is a React element built from parsed text, the text only
ever becomes a React child, and there is no `dangerouslySetInnerHTML` in the
file. A sanitizer is not needed to make markup safe if markup is never produced.
Link schemes are checked with the URL parser rather than a pattern, because the
bypasses are all in the parsing — `java\tscript:`, `JaVaScript:` and
`%6a%61vascript:` are one URL to a browser and three strings to a regex.
The knowledge and context panels deliberately do **not** use this renderer.
They exist to show a reader exactly what is in their file, and rendering is the
opposite of that; imported text goes into a `<pre>` as a text node.
### Campaign canon is configuration, and its provenance is per turn
M8 gave `campaign_canon` an API for the first time (`canon_rules`), which raised
a question the column had never had to answer: what happens when a reader edits
the campaign's highest authority *after* a story exists?
Measured, against a real server with real turns:
- **Every turn already played keeps the canon it was actually given.** The canon
section is part of that turn's stored context snapshot, so a historical turn
inspected after the edit still shows the old rule and not the new one. This is
M7's principle — provenance is the rendered text, not a foreign key — doing
the work without being asked.
- **The next turn is told the new canon**, which is the point of editing it.
- **Nothing recorded is rewritten**: accepted story text, the narrative state
document and the state audit log are all byte-identical across the edit.
- **The edit itself is not audited**, because canon is *configuration*. It sits
with `ai_instructions` and the narrator prompt, none of which are audited
either, and unlike a manual state correction it asserts nothing about the
story — it changes what the narrator is told from that point on.
So M5's `StateEvent` log is deliberately **not** extended to cover it. That log
audits accepted changes to narrative state; canon is not narrative state, and
routing a configuration change through it would create a second representation
of canon — the same duplication `BROWSER-UX-SPEC.md` §38 forbids for hidden
information, arrived at from a different direction.
What M8 added instead is at the editing surface: once a campaign has moments,
the canon editor says that the change applies from here on, that everything
already written stays as it is, and where the per-turn record can be seen. The
guarantee is not "the edit is logged" but "the edit cannot be mistaken for a
retroactive one, and every turn can prove what it was told".
## 14. Prompt and Provenance Inspection
Preserve and extend AI-DnD's Insights/context-snapshot capability.
+25 -1
View File
@@ -18,7 +18,7 @@ I05, H06-H09)
> return nothing.** A query unrelated to every imported source must retrieve no
> chunks at all, and G05-G07 are only meaningful alongside that negative
> control — without it they can all pass while retrieval is unconditional.
> `planning/reports/M7-IMPLEMENTATION-REPORT.md` §I records how that was missed
> `archive/milestone-reports/M7-IMPLEMENTATION-REPORT.md` §I records how that was missed
> the first time.
> **Browser-level verification (M4 closeout, 2026-09-03).** The browser smoke
@@ -411,6 +411,19 @@ speaks plain HTTP, and it will hide exactly this class of defect.
# B. Basic Story Interaction
> **M8 — browser evidence.** B01-B04 were exercised through the production
> build in a real Firefox, against a real local narrator, with the Continuity
> Test fixture. The M8 implementation report records each narration and what was
> asserted about it. Two things are worth carrying here because they changed the
> product:
>
> - **B01/B02 no longer need a mode.** The Do/Say/Story selector is gone; both
> are typed into one field, and the narrator reads quoted text as speech
> without being told which kind of turn it is.
> - **B04 revealed a formatting defect.** AI Dungeon's `> You ` prefix, applied
> to §11's "I enter the tavern", produced `> You I enter the tavern.` in the
> transcript and in the replayed history. Corrected for first-person input.
## B01 — Natural Language Action
**Priority:** REQUIRED FOR V1
@@ -627,6 +640,17 @@ Catch semantically valid-looking state proposals that do not represent the accep
# D. Undo, Redo, Retry, and Checkpoints
> **M8 — browser evidence.** The D series was established at the API level in
> M3-M5. M8 owed the browser workflow, and D01-D14 were re-exercised end to end
> through the production build in a real Firefox: Undo and Redo from the story
> controls, alternate takes through the pager, editing through the transcript's
> own controls with the explanation dialogs, and Save Points through their panel
> — including a **genuine process restart** between creating a Save Point and
> restoring it. Per-test evidence is in the M8 implementation report.
>
> None of these is marked PASS because the underlying API passed earlier. The
> browser workflow is the thing M8 was asked to demonstrate.
## D01 — Undo One Turn
**Priority:** REQUIRED FOR V1
+143 -2
View File
@@ -1,8 +1,149 @@
# Planning Package Version
- **Package:** Adventure Storyteller Planning Package v3.0
- **Package:** Adventure Storyteller Planning Package v3.3
- **Revision date:** 2026-09-06
- **Status:** Phase 0 complete; architecture selected; **Milestones M1-M7 implemented and accepted**; M8 is next to brief.
- **Status:** Phase 0 complete; architecture selected; **Milestones M1-M8 implemented and accepted** (M8 closed out 2026-09-06). M9 is next and has not been started.
## v3.3 — M8 Closeout (2026-09-06)
M8 is **complete and accepted**. The independent review returned
`M8 IMPLEMENTATION: PASS` subject to evidence and documentation cleanup; this
revision is that cleanup. No product requirement changed and no application code
changed in it.
**What M8 leaves the package with**
- **The browser is now the intended v1 storyteller surface**, not an adapted
AI-DnD one. One entry point, one story screen, one natural-language field;
State, Knowledge, Context, Save Points and campaign Settings one layer deeper
behind panels that start closed. Branch, fork, node, head and depth appear
nowhere a reader can see them — audited in source and in the live DOM, 0 hits.
- **Automated frontend testing exists for the first time** — 132 tests across 10
files. The project had none before M8.
- **Hidden narrator information is withheld at the surface that can actually
expose it** — advanced context inspection — rather than through a fictitious
separate hidden-state subsystem. Withheld text is absent from the DOM, not
collapsed inside it.
- **Final acceptance evidence:** 950 backend passed / 14 skipped / 0 failed; 132
frontend passed; lint, production build and Docker build clean; **157 browser
checks across six suites, zero failures**, on one frozen build; no schema
change, proved against an M7-built database.
- **M9 — Export, Backup, Recovery, and Migration Hardening — is next.** Its four
handoff questions are in the M8 report's §U.
**What the closeout settled**
- **The build-evidence contradiction.** The M8 report named two different
frontend bundles as the artifact behind its acceptance evidence. The saved run
logs settle it: `index-Ii-lARp9.js`, built 18:53:02 from the staged tree, is
the one **final frozen** artifact behind all 157 browser checks.
`index-C6E5Uvtu.js` is **superseded** — it predates finding 7's fix and its
acceptance suite ended 54/55 on exactly that defect. The report's §P now sets
the two side by side, and §B, §Q and §S agree with it.
- **Finding 14 — resolved, operationally, with no application change.** Ollama's
OpenAI-compatible endpoint ignores `num_ctx` and reloads the model at its own
default, so the window cannot be set per request from where this application
stands. A **derived model** created over `/api/create` carries the parameter,
is honoured through the application's own OpenAI-compatible path, and appears
in `/v1/models` — so the existing Settings model picker finds it with no code
change. Measured end to end. It is now an operational note in
`DEVELOPMENT.md`, not an unresolved M11 blocker.
- **`BROWSER-UX-SPEC.md` §38 — ratified.** The change from *"Show Hidden Story
State"* to the requirement on **hidden narrator information / spoilers** is
accepted as a **requirement clarification aligned with the implemented
architecture**, not a weakening: ordinary Story and State surfaces expose no
narrator-only information; the advanced Context and Knowledge surfaces that
could withhold it by default; revealing it takes an explicit, warned action;
withheld material is **absent from the DOM**, not merely collapsed; and no
duplicate hidden-state subsystem is required to satisfy obsolete UI wording.
Verified by the sentinel suite, 21/21.
**Documents changed**
- `reports/M8-IMPLEMENTATION-REPORT.md` — §A, §B, §D, §P, §Q, §S (findings 13
and 14), §T, §U and §V. §U gains the **M9 handoff**: complete campaign
portability, historical prompt/context provenance in the bundle, legacy story
cards, and context-window portability. Verification figures unchanged.
- `BROWSER-UX-SPEC.md` §38 — one requirement added: withheld material must be
**absent from the rendered DOM**, not merely visually collapsed. A closed
`<details>` is still findable by browser search and by the accessibility tree,
which is how finding 3 leaked.
- `PROJECT-SOURCES.md`, `V1-ACCEPTANCE-TESTS.md` — three pointers still aimed at
`reports/M7-IMPLEMENTATION-REPORT.md`, which M8's rotation moved to the
archive.
- `BUILD-MILESTONES.md` — M8 marked **COMPLETE / ACCEPTED**, M9 marked next and
not started, finding 14's carried-forward entry reworded as resolved.
- `README.md` (planning) — M8 complete and accepted; next is M9.
- `VERSION.md` — this entry.
- `DEVELOPMENT.md` — the derived-model procedure (carried from the finding-14
investigation).
**Status discipline.** M8 is implemented, verified, reviewed and accepted. It is
**not committed**: the tree is staged for the repository owner's signature. M9
has not been started.
---
## v3.2 — M8 Final Verification Pass (2026-09-06)
The corrective, verification and reporting pass over M8. At the time of this
revision M8 was **implemented and verified, not accepted**; v3.3 records the
review outcome and the acceptance.
**Documents changed in this pass**
- `BROWSER-UX-SPEC.md` §38 — **requirement clarification.** Rewritten from
"Hidden Narrator State" with a `Show Hidden Story State` toggle to
"Hidden Narrator Information / Spoilers". The protection required is
unchanged and, if anything, stated more strictly; what changed is that it
no longer names a state subsystem that does not exist, and it now forbids
inventing one. §100's checklist entry follows it.
- `TECHNICAL-DESIGN.md` — **implementation fact.** Campaign canon is
configuration; its provenance is the per-turn context snapshot, measured
rather than assumed.
- `V1-ACCEPTANCE-TESTS.md`, `BUILD-MILESTONES.md`, `README.md`,
`DEVELOPMENT.md` — implementation facts and final counts.
**No product requirement was weakened.** The §38 change is the only one that
touches a requirement's wording, and it tightens it.
---
## v3.1 — M8 Implementation (2026-09-06)
M8 turned the adapted AI-DnD interface into the interactive-story workspace
`BROWSER-UX-SPEC.md` describes. Not yet accepted — the report is written for an
independent reviewer.
**Documents changed**
- `BROWSER-UX-SPEC.md` — four "As implemented in M8" notes (§12 one input, §31
the state panel and why there is no hidden-state toggle there, §55 the context
inspector's default view, §57 click-through and the narrator-only guard). No
requirement was altered.
- `TECHNICAL-DESIGN.md` — new §13.4, recording that the browser stayed a
presentation layer, the failure taxonomy, and why markup is never produced
from input.
- `BUILD-MILESTONES.md` — M8's outcome and the debt it carries forward.
- `V1-ACCEPTANCE-TESTS.md` — B01-B04 and D01-D14 recorded as browser evidence.
- `README.md`, `DEVELOPMENT.md` — one input rather than four modes, the context
inspector, the component test suite, and the removal of "no frontend tests"
from the inherited-debt list.
**What M8 established that the plan did not already say**
- The narrative state has **no hidden dimension**, so §38's `Show Hidden Story
State` has nothing to reveal there. A campaign's secrets live in narrator-only
knowledge sources, and the only ordinary screen that can surface one is the
context inspector — which is where the guard was built.
- `campaign_canon` had no API. It is the highest authority in a campaign, read
by both the prompt builder and the state validator since M5, and until M8 a
fixture had to write it with SQL.
- AI Dungeon's `> You {text}` player-input convention is incompatible with one
natural-language field: it produced `> You I enter the tavern.`, which a small
model then imitates. Corrected for first-person input.
---
## v3.0 — M7 Closeout (2026-09-06)
+6 -4
View File
@@ -12,9 +12,9 @@ document sends you here for a specific piece of historical evidence.
### `milestone-reports/` — the completed milestones
One report per milestone that has been accepted, unedited. M6's joined them at
M7's closeout, following the convention that a milestone report is useful during
the immediately following milestone and historical afterwards.
One report per milestone that has been accepted, unedited. M7's joined them
when M8's report was written, following the convention that a milestone report
is useful during the immediately following milestone and historical afterwards.
### `phase0/` — why AI-DnD was selected
@@ -48,7 +48,9 @@ Git history.
`M1-BASELINE-REPORT.md`, `M1-IMPLEMENTATION-REPORT.md`,
`M2-BASELINE-REPORT.md`, `M2-IMPLEMENTATION-REPORT.md`,
`M3-IMPLEMENTATION-REPORT.md`.
`M3-IMPLEMENTATION-REPORT.md`, `M4-IMPLEMENTATION-REPORT.md`,
`M5-IMPLEMENTATION-REPORT.md`, `M6-IMPLEMENTATION-REPORT.md`,
`M7-IMPLEMENTATION-REPORT.md`.
M3's report is both its review and its primary evidence record; no separate M3
baseline report was produced. It arrived here when M4's report landed.
File diff suppressed because it is too large Load Diff