Planning: record M2 closeout decisions
M2's review reported six planning recommendations rather than applying them, three marked before M3. All six are applied here, plus three additions drawn from the same evidence. No implementation file is touched. The endpoint policy was the gap that mattered. It is the most consequential setting in the application — the storyteller sends the player's prose, the context, the memories and the embedding inputs to whatever address it names — and it existed only as a module docstring. It is now ADR 011 and a new §10A in the threat model, which also retires the assumption in §71A that the inherited guard was a starting point. It was not: AI-DnD's SSRF guard blocked private addresses to stop a hosted server reaching its own internal network, which is the exact opposite of what a local storyteller needs. It was removed, not adapted. Both documents state the rule as implemented — an allowlist of explicit local-network CIDRs, every resolved address checked, enforced on save and again before every outbound request, TLS never traded against it — and both state the two residual limits plainly rather than implying they are covered: a hostile host already on the trusted LAN is inside the permitted boundary, and a rebinding interval exists between the policy's resolution and the client's connection. Accepted risks, not M3 work. The CIDRs are spelled out rather than derived from is_private/is_reserved, and the ADR records why: is_private is true of the documentation ranges and 0.0.0.0/8, and is_reserved is true of IPv6 loopback, so a rule built on it refuses an ordinary same-host Ollama on [::1]. TECHNICAL-DESIGN §5.1 items 3 and 4 are marked done, closing all five hardening items. A new §5.2 records the M1/M2 architecture as fact rather than intention, so later milestones inherit what the code does. A new §18.1 carries the lesson of M2's two regressions: when removing a setting, test a real consumer construction path; when adding one, prove it reaches the component that uses it. Both defects hid behind a green suite because the tests at that boundary were mocks. BUILD-MILESTONES records M2 complete, with the capabilities later milestones inherit and the debt carried forward. Two notes go to milestones that would otherwise misread what M2 left them. M5 is told that eight rollback tests now use the world-state engine as instrumentation and not as endorsement — the instrumentation moves when the protocol does, and those tests are reworked rather than deleted. M6 is told that the memory bank died silently under a green suite, so background failure must be observable and at least one real provider-construction path must be tested. The security contract gains what M2 demonstrated. H10 now names the two conditions that were defects during M2: a wildcard origin must be refused at startup, and an unknown /api path must 404 rather than returning the SPA with 200. New H12 covers endpoint enforcement, and its fourth pass condition is the one that matters — a public endpoint written into the database behind the settings API must still be refused at the wire. A build passing the first three and failing that one has configuration validation only. SPECIFICATION.md is deliberately unchanged. M2 altered no product requirement; it removed capability the specification never asked for. The two M2 reports gain appended closeout notes rather than edits. Their original wording about an uncommitted working tree was true when written, and the note records what happened afterwards: the six-file correction is8652fe7,8c65ae9remains the implementation commit, and the two were never squashed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HsZBU8sWRuYTyLgWsu2oQ6
This commit is contained in:
co-authored by
Claude Opus 5
parent
8652fe7cd8
commit
2fdd2547f0
@@ -756,3 +756,95 @@ The three planning corrections marked *before M3* in §O — the threat model, t
|
||||
technical-design hardening list, and a new ADR for the endpoint policy — are
|
||||
documentation of decisions already made, not new work, and can be done alongside
|
||||
the M3 brief.
|
||||
|
||||
---
|
||||
|
||||
# S. Closeout note — appended 2026-09-03
|
||||
|
||||
**Appended after the fact.** Sections A-R above were written on 2026-09-02 and
|
||||
are left as they were, including §A.1's and §P's statements that the fixes were
|
||||
uncommitted at the time. Those statements were true when written and are the
|
||||
reason this note exists rather than an edit.
|
||||
|
||||
## The one thing §R said to do first
|
||||
|
||||
§R closed with: *"The one thing to do first is commit the six-file fix (§A.1).
|
||||
Until then the branch head contains a silently broken memory bank."*
|
||||
|
||||
Done:
|
||||
|
||||
```text
|
||||
8652fe7cd84bca5173abb03b2a692f15fea8a98c M2 review: two regressions the green suite hid, and the reports
|
||||
```
|
||||
|
||||
The commit carries the six implementation/test/lockfile files **and** these two
|
||||
reports. `8c65ae9` remains the M2 implementation commit and was not amended or
|
||||
squashed, so the provenance distinction §R wanted — original implementation
|
||||
versus review-discovered correction — survives in the history.
|
||||
|
||||
Confirmed present in that commit, against `8c65ae9`:
|
||||
|
||||
| Defect | Fix as committed |
|
||||
| --- | --- |
|
||||
| §9.1 dead memory bank | `memorybank.py` — both provider factories stop reading the removed `Settings.api_key_plain`; `summary_provider` now passes `model_timeout_seconds` |
|
||||
| §9.2 inert timeout | `turns.py`, `chat.py` and the summariser factory pass `settings.model_timeout_seconds` into the provider |
|
||||
| §9.3 stale lock | `requirements.lock` drops `quickjs`, `psycopg`, `psycopg-binary`, `cryptography`, and the transitive `cffi` and `pycparser` |
|
||||
| — | `test_local_only_surface.py` gains the two regression tests: every factory built from a real `Settings` row, and the configured timeout arriving at each generating client |
|
||||
|
||||
The separate short timeout classes were kept, as §9.2 required: `CONNECT_TIMEOUT`
|
||||
(10 s), `EMBED_READ_TIMEOUT` (60 s) and the connection-test/model-list path are
|
||||
unchanged, and only the generation read timeout became configurable.
|
||||
|
||||
## Verification at closeout
|
||||
|
||||
Re-run on 2026-09-03 against the **committed** tree, working tree clean:
|
||||
|
||||
```text
|
||||
backend pytest tests/ -q 606 passed in 133.26s
|
||||
tests/test_local_only_surface.py 32 passed
|
||||
test_endpoint_policy + test_tls_trust + test_offline_assets
|
||||
47 passed
|
||||
frontend npm run lint 7 warnings, 0 errors, exit 0
|
||||
frontend npm run build 395.41 kB, exit 0
|
||||
root docker build exit 0
|
||||
image quickjs/psycopg/cryptography/cffi/pycparser absent (32 packages)
|
||||
```
|
||||
|
||||
The packet-capture exercises were not repeated; the corrected files do not touch
|
||||
the network boundary. See §15 of the baseline report.
|
||||
|
||||
## Planning recommendations from §O
|
||||
|
||||
Three were marked *before M3* and are now applied, in commit
|
||||
`Planning: record M2 closeout decisions`:
|
||||
|
||||
- **§O.2** — `SECURITY-THREAT-MODEL.md` §10A records the endpoint policy as
|
||||
implemented, with both residual limits stated; §71A item 5 is marked resolved;
|
||||
§77 notes the required defaults are now met.
|
||||
- **§O.4** — `TECHNICAL-DESIGN.md` §5.1 items 3 and 4 are marked done, and a new
|
||||
§5.2 records the M1/M2 production architecture as fact rather than intention.
|
||||
- **§O.5** — **ADR 011, *Local Inference Endpoint Policy***, records the
|
||||
decision, including the `ipaddress`-classification finding from §K.1 as the
|
||||
reason the CIDRs are spelled out.
|
||||
|
||||
The remaining three are also applied, ahead of the *later* urgency §O gave them,
|
||||
since they are one-paragraph edits: **§O.1** as an M5 note in
|
||||
`BUILD-MILESTONES.md` about the world-state instrumentation, and **§O.3** as a
|
||||
strengthened H10 in `V1-ACCEPTANCE-TESTS.md`. **§O.6** correctly asked for no
|
||||
change to `SPECIFICATION.md`, and none was made.
|
||||
|
||||
Two additions beyond §O, both drawn from evidence in this report:
|
||||
|
||||
- an M6 note in `BUILD-MILESTONES.md` requiring background memory failure to be
|
||||
observable and at least one real provider-construction path to be tested —
|
||||
§A.1 and §9.1 are the argument for it;
|
||||
- **H12, *Inference Endpoint Enforcement***, in `V1-ACCEPTANCE-TESTS.md`, whose
|
||||
fourth pass condition is the database-edited-behind-the-API case this review
|
||||
demonstrated at runtime in §F.
|
||||
|
||||
`BUILD-MILESTONES.md` also gained M2's `## Status: COMPLETE` block, matching M1's.
|
||||
|
||||
## Not done in this closeout
|
||||
|
||||
M3 was not begun. Undo still deletes, and there is still no Redo. The debt table
|
||||
in §P is unchanged apart from its first row, which this note closes.
|
||||
|
||||
Reference in New Issue
Block a user