M9: a campaign you can actually get back

A campaign could already be exported and imported. What could not survive the
trip was everything that explains it: the state events behind the authoritative
document, the prompt each turn was actually given, the passages it was shown,
the summaries that carry long-story continuity, and which take belonged to which
turn. An imported campaign could be read and could no longer say why it was what
it was — and a manual correction, the one state change no narration explains,
was indistinguishable from something the story had established.

The bundle is now `ai-dnd-adventure-v3`, and the version is the design rather
than a side effect. Everything added here could have been another optional key,
the way persona, Save Points, narrative state and imported knowledge each were.
That mechanism stops working at exactly this addition: a v2 file with no prompt
provenance is ambiguous between "written before M9" and "written by M9 from a
campaign that has none", and those are different facts about a campaign. A
version number is how a recovery file states what it was capable of recording.
v1 and v2 still import, and every seam from pre-active-head onward is tested for
the rule that an older file is never reinterpreted under a newer assumption.

Two categories became three. "Chosen travels, derived is recomputed" was enough
until stored prompts had to be decided: they are derived, and they must travel
anyway. The test that separates evidence from cache is not "could this be
recomputed" but "would a recomputation answer the same question" — a rebuilt
search index answers the same question, a rebuilt prompt says what the turn
would be told *now*, which is the opposite of what the inspector is for.

Also here: a real SQLite backup, through the online backup API rather than a
file copy, taken while the application is running and verified before it is
kept; story cards settled as compatibility-only legacy data and taken out of the
narrator's prompt, because they were the untracked path around knowledge
authority that IMPORTED-KNOWLEDGE-DESIGN §73 already forbade; and no schema
change at all, proved against a database M8's own code wrote.

Three defects, found by running the milestone's own tests rather than by reading
them. Deleting a campaign leaked its FTS index rows, and SQLite then handed the
freed ids to the next source imported into any campaign, which failed with an
integrity error that Reindex could not repair — both ends are closed, and a
database already carrying the damage now repairs itself. An imported node with
no state snapshot was being stamped with the campaign's head state, so an Undo
to turn 2 showed what the story knew at turn 20. And the snapshot relink did not
persist at all, because it mutated a dict in place on a column SQLAlchemy tracks
by assignment: it looked correct in memory and wrote the wrong ids to disk.

Carrying per-turn prompts looked like it would halve the length of campaign that
can be restored. Measured — and after compressing them inside the file —
everything M9 added costs 12% of it: the import ceiling moves from about 318
turns to about 279, against a 100-turn certification target. The dominant cost
is not M9's at all. The per-position narrative state document is 74% of a
bundle, and v2 already carried it.

Backend 1,102 passed / 14 skipped / 0 failed. Frontend 145 passed. Lint,
production build and Docker build clean. Verified across two server processes
with two data directories, and in a real browser against a real narrator.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qyn3oRd4D6pi72nKBG725B
This commit is contained in:
JesseMarkowitz
2026-09-07 01:55:45 -04:00
co-authored by Claude Opus 5
parent 1ce9972760
commit 44edece67e
46 changed files with 9227 additions and 178 deletions
+38 -7
View File
@@ -1660,7 +1660,22 @@ def test_an_edited_content_hash_is_recomputed_and_reported(client):
def test_historical_prompt_evidence_survives_an_export_round_trip(client):
"""§33: the round trip does not turn provenance into dangling ids."""
"""§33: the round trip does not turn provenance into dangling ids.
Written in M7 and rewritten in M9, and the rewrite is the point of it.
In M7 the bundle carried no context snapshots at all, so this test pinned
the *absence*: there were no ids to dangle because there was no evidence,
and the imported campaign's turns simply had no snapshot. That was recorded
at the time as a limit owned by M9 rather than as a property worth keeping —
`V1-ACCEPTANCE-TESTS.md` I05 said so in as many words, and the M8 report
made it handoff question B.
M9 answered it: the evidence travels. So the assertion inverts, and what it
now pins is the thing M7 was worried about and could not check — that the
provenance arriving on the other side names *this* campaign's sources rather
than the ids it had on the machine that wrote the file.
"""
ids = import_fixture(client)
play(client, "Aldric asks about the Old Abbey and its broken-circle symbol.")
actions = client.get(f"/api/adventures/{client.adv_id}/actions").json()["actions"]
@@ -1673,17 +1688,33 @@ def test_historical_prompt_evidence_survives_an_export_round_trip(client):
bundle = client.get(f"/api/adventures/{client.adv_id}/export").json()
restored = client.post("/api/adventures/import", json=bundle).json()
# The bundle carries no context snapshots at all — it never has, by the rule
# at the top of `bundle.py` — so there are no ids to dangle. The imported
# campaign's turns simply have no snapshot, which is what a pre-M7 bundle
# already did for every other component of the inspector.
new_actions = client.get(
f"/api/adventures/{restored['id']}/actions"
).json()["actions"]
new_ai = next(a for a in reversed(new_actions) if a["type"] == "ai")
assert client.get(
moved = client.get(
f"/api/adventures/{restored['id']}/actions/{new_ai['id']}/context"
).status_code == 404
)
assert moved.status_code == 200, moved.text[:300]
moved = moved.json()
# The evidence itself is identical: the same passages, the same text, the
# same prompt the turn was actually assembled from.
assert [(r["title"], r["text"]) for r in moved["knowledge"]["used"]] == \
[(r["title"], r["text"]) for r in before["knowledge"]["used"]]
assert moved["prompt"] == before["prompt"]
# And the one pointer that is not evidence has been translated, so the
# inspector's "open this source" reaches the restored library rather than
# whatever holds that id here.
theirs = {
source["id"] for source in
client.get(f"/api/adventures/{restored['id']}/knowledge").json()
}
named = {r["source_id"] for r in moved["knowledge"]["used"]
if r["source_id"] is not None}
assert named and named <= theirs
# And the original campaign's evidence is untouched by having been exported.
after = client.get(
f"/api/adventures/{client.adv_id}/actions/{ai_action['id']}/context"