Planning: record M2 closeout decisions

M2's review reported six planning recommendations rather than applying them,
three marked before M3. All six are applied here, plus three additions drawn
from the same evidence. No implementation file is touched.

The endpoint policy was the gap that mattered. It is the most consequential
setting in the application — the storyteller sends the player's prose, the
context, the memories and the embedding inputs to whatever address it names —
and it existed only as a module docstring. It is now ADR 011 and a new §10A in
the threat model, which also retires the assumption in §71A that the inherited
guard was a starting point. It was not: AI-DnD's SSRF guard blocked private
addresses to stop a hosted server reaching its own internal network, which is
the exact opposite of what a local storyteller needs. It was removed, not
adapted.

Both documents state the rule as implemented — an allowlist of explicit
local-network CIDRs, every resolved address checked, enforced on save and again
before every outbound request, TLS never traded against it — and both state the
two residual limits plainly rather than implying they are covered: a hostile
host already on the trusted LAN is inside the permitted boundary, and a
rebinding interval exists between the policy's resolution and the client's
connection. Accepted risks, not M3 work.

The CIDRs are spelled out rather than derived from is_private/is_reserved, and
the ADR records why: is_private is true of the documentation ranges and
0.0.0.0/8, and is_reserved is true of IPv6 loopback, so a rule built on it
refuses an ordinary same-host Ollama on [::1].

TECHNICAL-DESIGN §5.1 items 3 and 4 are marked done, closing all five hardening
items. A new §5.2 records the M1/M2 architecture as fact rather than intention,
so later milestones inherit what the code does. A new §18.1 carries the lesson
of M2's two regressions: when removing a setting, test a real consumer
construction path; when adding one, prove it reaches the component that uses
it. Both defects hid behind a green suite because the tests at that boundary
were mocks.

BUILD-MILESTONES records M2 complete, with the capabilities later milestones
inherit and the debt carried forward. Two notes go to milestones that would
otherwise misread what M2 left them. M5 is told that eight rollback tests now
use the world-state engine as instrumentation and not as endorsement — the
instrumentation moves when the protocol does, and those tests are reworked
rather than deleted. M6 is told that the memory bank died silently under a
green suite, so background failure must be observable and at least one real
provider-construction path must be tested.

The security contract gains what M2 demonstrated. H10 now names the two
conditions that were defects during M2: a wildcard origin must be refused at
startup, and an unknown /api path must 404 rather than returning the SPA with
200. New H12 covers endpoint enforcement, and its fourth pass condition is the
one that matters — a public endpoint written into the database behind the
settings API must still be refused at the wire. A build passing the first three
and failing that one has configuration validation only.

SPECIFICATION.md is deliberately unchanged. M2 altered no product requirement;
it removed capability the specification never asked for.

The two M2 reports gain appended closeout notes rather than edits. Their
original wording about an uncommitted working tree was true when written, and
the note records what happened afterwards: the six-file correction is 8652fe7,
8c65ae9 remains the implementation commit, and the two were never squashed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HsZBU8sWRuYTyLgWsu2oQ6
This commit is contained in:
JesseMarkowitz
2026-09-03 01:52:03 -04:00
co-authored by Claude Opus 5
parent 8652fe7cd8
commit 2fdd2547f0
9 changed files with 659 additions and 26 deletions
+60
View File
@@ -866,3 +866,63 @@ Stated so the implementation report does not overclaim.
(§5.4). The individual capabilities — narration, streaming, embeddings,
memory writes, retry, fork, restart — were each measured separately.
3. **No load, soak or long-campaign testing.** Out of scope for M2.
---
# 15. Closeout note — appended 2026-09-03
**This section was appended after the fact and is not part of the original
evidence record.** Everything above was written on 2026-09-02 and describes the
repository as it stood then. Nothing above has been rewritten, including its
references to a working tree that was dirty at the time.
## What the original report correctly said
The report above correctly described commit `8c65ae9` — the M2 implementation
commit — as **not containing** the three fixes this review found. At the time it
was written, those fixes existed only in the working tree, six files ahead of
that commit. Every runtime measurement in this report was produced by an image
built from that fixed tree, which the report states plainly.
## What happened afterwards
The six-file correction was committed:
```text
8652fe7cd84bca5173abb03b2a692f15fea8a98c M2 review: two regressions the green suite hid, and the reports
```
That commit carries the six implementation/test/lockfile files **and** the two
M2 reports themselves, which is why this report's own history begins there. The
provenance distinction the review asked for is preserved regardless:
`8c65ae9` is the M2 implementation, `8652fe7` is the review correction, and the
two were never squashed.
## Verification at closeout
Re-run on 2026-09-03 against the committed tree — not the working tree — so that
what was verified is exactly what the repository contains:
```text
backend .venv/bin/python -m pytest tests/ -q 606 passed in 133.26s
frontend npm run lint 7 warnings, 0 errors, exit 0
frontend npm run build built in 932ms; index.js 395.41 kB
root docker build -t storyteller-m2-closeout . exit 0
git status --short clean
```
The 606 figure matches the count this report recorded, from the same tree.
Dependency removal was verified in the built image rather than only in the
lockfile:
```text
$ docker run --rm --entrypoint sh storyteller-m2-closeout -c "pip list | grep -iE 'quickjs|psycopg|cryptography|cffi|pycparser'"
ABSENT: none of quickjs/psycopg/cryptography/cffi/pycparser installed
32 packages total
```
The network measurements in §5, §6 and §10 were **not** re-run. The six
corrected files change provider construction and a timeout value; they do not
touch the endpoint policy, the TLS trust context, or the bind addresses, so the
captures above remain the evidence for the network boundary.