Planning: add the M4 implementation review report and rotate M3's

Reporting pass only. No application code, no test, and no product
requirement changes.

Result: PASS WITH CORRECTIVE WORK REQUIRED.

M4's Definition of Done is met and demonstrated at the API level, including
across a real two-process restart. The load-bearing constraint holds under
inspection rather than assertion: the only head-field assignment M4 added
anywhere in the backend is one line in head.py, and an exhaustive grep of the
diff finds no second mechanism that forks, prunes memories, reconstructs
state, filters the transcript or recomputes Redo.

Three corrective items, all M4's own, none in the head model:

- GET /checkpoints is an N+1 fetching whole Action rows including prose --
  measured at 53 SELECTs for 25 Save Points against 4 for the branch panel,
  in a codebase that keeps test_egress.py for this exact class of mistake;
- deleting a branch silently deletes Save Points naming it, and the branch
  panel's confirmation does not say so. M4 added the consequence to an
  existing destructive action without updating its warning;
- the shipped D11/L03 tests restart a client, not a process, so the suite is
  weaker than the acceptance items it is named for. Both pass here only
  because the report re-ran them across a real process boundary by hand.

The browser smoke test is NOT PERFORMED, for M4 and still for M3. Firefox is
a snap that hangs past 90s on a trivial headless screenshot; there is no
Xvfb, no display, no driver library. Two consecutive milestones now carry an
unperformed browser requirement, which the report raises as a standing
acceptance risk rather than a defect in either milestone's code.

Evidence recorded: 680 backend tests pass (42 M4, 130 M3 invariants, 93
security/local-only), frontend lint and build clean, Docker build clean,
migration 80 verified against a representative pre-M4 database with both
cascades and zero possible orphans, and I04 verified through a real round
trip with branch ids remapped 1->3 and 2->4.

M4 is NOT accepted by this report, and M5 is NOT authorized. That decision
belongs to whoever reviews this.

Rotation: planning/reports/M3-IMPLEMENTATION-REPORT.md moves to
planning/archive/milestone-reports/ as a pure rename, contents unedited
(git reports 100% similarity, 0 insertions, 0 deletions). Six path
references in five active documents are updated because the path changed
and for no other reason -- no status claim, no wording change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PWU4gTfLYY6Qq9U7aa9Qw2
This commit is contained in:
JesseMarkowitz
2026-09-03 19:15:53 -04:00
co-authored by Claude Opus 5
parent e08d49c3eb
commit 279a871a77
7 changed files with 1061 additions and 16 deletions
+1 -1
View File
@@ -250,7 +250,7 @@ History operations are non-destructive, Redo works, divergence preserves old fut
## Status: COMPLETE ## Status: COMPLETE
Accepted 2026-09-03. Evidence: `planning/reports/M3-IMPLEMENTATION-REPORT.md`, Accepted 2026-09-03. Evidence: `planning/archive/milestone-reports/M3-IMPLEMENTATION-REPORT.md`,
which is M3's primary evidence record — no separate baseline report was produced, which is M3's primary evidence record — no separate baseline report was produced,
so that document carries the raw counts and runtime observations as well as the so that document carries the raw counts and runtime observations as well as the
review. The architecture is recorded in **ADR 012**. review. The architecture is recorded in **ADR 012**.
+1 -1
View File
@@ -82,7 +82,7 @@ in `planning/archive/decisions/`.
One file, and it changes as development progresses: One file, and it changes as development progresses:
```text ```text
planning/reports/M3-IMPLEMENTATION-REPORT.md planning/reports/M4-IMPLEMENTATION-REPORT.md
``` ```
M3 is the most recently completed milestone, and M4 is the next to be briefed. M3 is the most recently completed milestone, and M4 is the next to be briefed.
+10 -12
View File
@@ -96,7 +96,7 @@ Two standing qualifications:
10. `BROWSER-UX-SPEC.md` 10. `BROWSER-UX-SPEC.md`
11. `V1-ACCEPTANCE-TESTS.md` 11. `V1-ACCEPTANCE-TESTS.md`
12. `DECISIONS/` — all of them; they are short. 12. `DECISIONS/` — all of them; they are short.
13. `reports/M3-IMPLEMENTATION-REPORT.md`, for what the last milestone actually 13. `reports/M4-IMPLEMENTATION-REPORT.md`, for what the last milestone actually
left behind. Nothing in `planning/archive/` unless sent there. left behind. Nothing in `planning/archive/` unless sent there.
## Architectural decisions ## Architectural decisions
@@ -127,15 +127,12 @@ work until Phase 0 closes — which Phase 0 satisfied on 2026-09-01. It is in
`reports/` holds the report for the milestone most recently completed, because `reports/` holds the report for the milestone most recently completed, because
that is the one the next milestone's planning has to consult: that is the one the next milestone's planning has to consult:
- `reports/M3-IMPLEMENTATION-REPORT.md` — M3's review **and** its primary - `reports/M4-IMPLEMENTATION-REPORT.md` — M4's review and its evidence record.
evidence record; no separate M3 baseline report was produced. M4 needs its
§W (closeout) and §M/§W.4 (the open browser smoke test).
Completed earlier milestones are in `archive/milestone-reports/`. When M4's Completed earlier milestones are in `archive/milestone-reports/`, which M3's
report lands, M3's moves there too: a milestone report is useful during the report joined when M4's landed: a milestone report is useful during the
immediate next milestone and historical afterwards. **M3's report has not moved immediate next milestone and historical afterwards. M3's is now at
yet**, because M4's does not exist — the rotation belongs to M4's closeout, not `archive/milestone-reports/M3-IMPLEMENTATION-REPORT.md`, unedited.
to its implementation.
## The decision this package rests on ## The decision this package rests on
@@ -233,7 +230,7 @@ Milestone M2 COMPLETE (2026-09-02)
| |
v v
Milestone M3 COMPLETE (2026-09-03) Milestone M3 COMPLETE (2026-09-03)
non-destructive undo/redo, reports/M3-IMPLEMENTATION-REPORT.md non-destructive undo/redo, archive/milestone-reports/M3-*.md
active-head export and ADR 012 active-head export and ADR 012
| |
v v
@@ -253,8 +250,9 @@ action; M5 does not begin before that report is written and accepted.
Two conditions remain open. The **browser smoke test has still not been Two conditions remain open. The **browser smoke test has still not been
performed** — now for M3 and for M4 — because no session so far has had a usable performed** — now for M3 and for M4 — because no session so far has had a usable
browser. See `reports/M3-IMPLEMENTATION-REPORT.md` §M and §W.4, and the M4 status browser. See `archive/milestone-reports/M3-IMPLEMENTATION-REPORT.md` §M and §W.4,
block in `BUILD-MILESTONES.md`. And **no M4 review exists**: the status block was `reports/M4-IMPLEMENTATION-REPORT.md` §M, and the M4 status block in
`BUILD-MILESTONES.md`. And **no M4 review exists**: the status block was
written by the implementation and records what it built, which is not the same as written by the implementation and records what it built, which is not the same as
a reviewer having read it. a reviewer having read it.
+1 -1
View File
@@ -77,7 +77,7 @@ tell authoritative material from evidence at a glance.
## v2.3 — Post-M3 Closeout (2026-09-03) ## v2.3 — Post-M3 Closeout (2026-09-03)
M3 replaced destructive Undo with a stored active head. Its review is M3 replaced destructive Undo with a stored active head. Its review is
`reports/M3-IMPLEMENTATION-REPORT.md`, which is also M3's primary evidence `archive/milestone-reports/M3-IMPLEMENTATION-REPORT.md`, which is also M3's primary evidence
record — no separate baseline report was produced — and whose §W records this record — no separate baseline report was produced — and whose §W records this
closeout. closeout.
+5 -1
View File
@@ -41,7 +41,11 @@ Git history.
### `milestone-reports/` — completed milestone evidence ### `milestone-reports/` — completed milestone evidence
`M1-BASELINE-REPORT.md`, `M1-IMPLEMENTATION-REPORT.md`, `M1-BASELINE-REPORT.md`, `M1-IMPLEMENTATION-REPORT.md`,
`M2-BASELINE-REPORT.md`, `M2-IMPLEMENTATION-REPORT.md`. `M2-BASELINE-REPORT.md`, `M2-IMPLEMENTATION-REPORT.md`,
`M3-IMPLEMENTATION-REPORT.md`.
M3's report is both its review and its primary evidence record; no separate M3
baseline report was produced. It arrived here when M4's report landed.
Every architectural conclusion these reports reached has already been applied to Every architectural conclusion these reports reached has already been applied to
the active planning documents and the ADRs — see `planning/VERSION.md`, which the active planning documents and the ADRs — see `planning/VERSION.md`, which
File diff suppressed because it is too large Load Diff