Files
interactive-story/planning
JesseMarkowitzandClaude Opus 5 c1a73b3d77 M1: make the first story turn work with no Internet
Phase 0B ran the upstream application on a network with no route out and
the first turn died in tiktoken, which downloads its BPE table the first
time anything counts a token. The browser separately fetched three font
families from Google on every page load. Neither is visible on a machine
that has been online once, which is why both now have tests.

The tokenizer table is vendored at
backend/app/context/vendor/cl100k_base.tiktoken and
backend/app/context/encoding.py builds the encoding from it directly,
verifying its SHA-256 against the digest tiktoken itself pins for that
URL. No code path in the tokenizer can reach the network any more —
not a warm cache, not an environment variable a deployment could forget.
The encoding was checked token for token against tiktoken's own.

The three font families are self-hosted as variable fonts under
frontend/public/fonts/ (343 KiB, Latin and Latin Extended), declared in
frontend/src/styles/fonts.css, and re-vendored by
frontend/tools/vendor_fonts.py. Their OFL licences ship beside them.
With no remote asset left, the CSP drops both Google hosts and gains
object-src, base-uri and form-action; woff2 also gets its real media
type, which Python's table lacks on a slim image.

A trusted-LAN Ollama turned out not to work at all over HTTPS. httpx
verifies against the certifi bundle, so an endpoint whose certificate
comes from a CA the user installed on their own machines — a StartOS
server's Ollama, for one — was refused with CERTIFICATE_VERIFY_FAILED
while curl and the browser on the same host accepted it.
app/tlstrust.py builds one context that unions the platform CA store
with certifi's, and all four outbound clients use it. A union rather
than a swap, so an image with an empty system store cannot start failing
on endpoints that worked before. Verification itself is untouched:
CERT_REQUIRED, hostname checking on, and no insecure escape hatch.

The storyteller listener is now loopback by explicit statement rather
than by inheriting uvicorn's default: start.sh, start.ps1, and
docker-compose.yml, which publishes to 127.0.0.1 rather than every
interface. Reaching an Ollama on another machine is outbound and needs
none of that inbound exposure.

backend/requirements.lock pins the exact tested closure;
requirements.txt keeps the ranges. DEVELOPMENT.md covers setup, the
same-host and trusted-LAN Ollama configurations, and how to re-run the
offline proof. PROVENANCE.md records the upstream commit, the MIT terms,
and both vendored assets.

Verified, not just compiled. On an --internal Docker network with
1.1.1.1 unreachable and no name resolving, a campaign was created and
played for six turns through same-host Ollama, restarted, and resumed.
A second run played ten turns through Ollama on a separate physical
machine on the LAN over verified HTTPS, summaries and embeddings
included, with the storyteller's default route deleted so the LAN was
reachable and the Internet was not. Its capture: 893 packets to the
approved host, 730 loopback, zero anywhere else, and zero DNS queries.
Two induced model failures left the accepted story bit-identical. The
inherited SPA was opened in a browser and a campaign read back from it.
Evidence is in planning/reports/M1-BASELINE-REPORT.md, along with the
findings that did not belong in this change.

648 backend tests pass, up from the inherited 632; frontend lint and
build are clean; the image builds. No M2 work is included: the hosted,
cloud, analytics, Postgres and scripting surfaces are untouched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017foPNqFjAJa2Ngebf5mEfL
2026-09-02 02:40:28 -04:00
..

Adventure Storyteller Planning Package

Status: Phase 0 complete; architecture selected; planning revision ready for review.
Production coding: Not yet authorized. Review this package before preparing the first implementation prompt.

This package contains the current product requirements, final Phase 0 architecture decisions, detailed subsystem designs, acceptance tests, research evidence, and the production milestone plan for the local-only interactive-story project.

Current Decision

Phase 0A static research and Phase 0B local validation are complete.

The production starting point is:

Fork AI-DnD at upstream commit d72f7c1bda0f34fccd84afb7a25c34eb01c901de.

The selection is based on measured Phase 0B behavior, not feature count. AI-DnD already contains the highest-value structural machinery: browser UI, FastAPI service boundary, SQLite persistence, parent-linked story history, alternate takes, branch-aware state snapshots, local Ollama operation, branch-scoped memory, prompt/context inspection, streaming, export/import, and a substantial automated test suite.

The selected composition of ideas is:

AI-DnD production base
  + ai-adventure state/event/commit/checkpoint/privacy patterns
  + Open Dungeon story-reading and future-media UX patterns
  + Chronicler memory-authority concepts
  + Interactive Fiction Framework canon/validation concepts
  + Gamentic provider-neutral media concepts

This is not a repository merge. AI-DnD is the ownership center. Other projects are implementation references only unless a later milestone explicitly reimplements a compatible idea.

Phase 0B Findings That Changed the Plan

Phase 0B confirmed the fork choice while correcting several Phase 0A assumptions:

  • AI-DnD's shipped Undo was destructive and had no Redo.
  • A disposable spike proved non-destructive head-cursor Undo/Redo in three backend files while preserving branch-scoped memory isolation.
  • A new continuation written after Undo can fork from the moved-back head while retaining the abandoned future.
  • AI-DnD's current relative-delta world-state protocol can produce semantically wrong state under realistic context even when the proposal is syntactically valid.
  • Production narrative state will therefore use explicit typed events/absolute assignments inspired by ai-adventure rather than AI-DnD's relative-delta protocol.
  • AI-DnD requires offline hardening: tiktoken attempts a first-use CDN fetch and the SPA requests Google Fonts at runtime.
  • AI-DnD's export format must preserve the active head position; otherwise export/import can silently redo an undone story.
  • AI-DnD Story Cards are not a sufficient imported-knowledge store because they are not designed for the required classification, provenance, chunking, and lineage semantics.
  • Open Dungeon remains useful for UX/media ideas but is no longer a serious production-fork candidate.
  • ai-adventure is not the production base but is the strongest implementation reference for authoritative typed state events, head movement, checkpoints, replay, and narrow local-only behavior.

See PHASE-0B-RECOMMENDATION.md for the coding agent's evidence. That report is retained as research evidence; the planning documents in this package record the decisions made after reviewing it.

Document Authority

Use the documents in this order when requirements appear to conflict:

  1. SPECIFICATION.md — product requirements and required behavior.
  2. Detailed behavior/design documents:
    • STORY-BRANCH-SEMANTICS.md
    • CONTEXT-AND-MEMORY.md
    • IMPORTED-KNOWLEDGE-DESIGN.md
    • SECURITY-THREAT-MODEL.md
    • MEDIA-EXTENSION-CONTRACT.md
    • BROWSER-UX-SPEC.md
    • DATA-MODEL.md
  3. V1-ACCEPTANCE-TESTS.md — observable pass/fail contract.
  4. TECHNICAL-DESIGN.md — selected implementation architecture.
  5. Foundational ADRs (001-...md through the current ADR set).
  6. BUILD-MILESTONES.md — implementation sequence; it does not override product behavior.
  7. Phase 0 research reports — evidence and historical findings.

Candidate repositories and research reports are not specifications. In particular, ai-adventure is an implementation reference for selected patterns; its behavior does not override this package.

Foundational Decisions

The following are settled for v1:

  • browser-first UI,
  • local-only runtime across user-controlled local infrastructure,
  • Ollama inference with same-host loopback as default and explicitly configured trusted-LAN inference supported,
  • single-user deployment,
  • AI-DnD production base at the pinned Phase 0B commit,
  • application-owned authoritative state,
  • complete retained transcript/history,
  • simple user-facing Undo/Redo/Retry/Save Point semantics,
  • non-destructive head-cursor history internally,
  • new write after moving backward creates a new continuation while retaining the old future,
  • abandoned history is retained and marked disposable; no automatic cleanup is required in v1,
  • named checkpoints remain until explicitly deleted,
  • genre-agnostic core state,
  • explicit typed narrative-state events/absolute assignments rather than ambiguous relative deltas,
  • hybrid state model: validated events plus state snapshots/cache,
  • branch/lineage-safe summaries and memories,
  • imported knowledge is a separate first-class subsystem rather than an extension of AI-DnD Story Cards,
  • knowledge classes: Canon / Reference / Inspiration,
  • local lexical retrieval plus local semantic retrieval where practical,
  • prompt/context provenance and inspection,
  • export/import must preserve active branch and active head position, including an undone position,
  • no cloud/Internet inference, telemetry, automatic web retrieval, remote runtime assets, shell/MCP/general plugin execution,
  • LAN inference is distinct from LAN exposure of the storyteller UI/API; the latter is not required for v1,
  • future local image/video/audio/TTS/STT support remains optional and decoupled from the story engine.

Phase 0 Status

Complete

  • candidate discovery and triage,
  • static architecture/privacy/licensing review,
  • local clone/build/test validation,
  • real Ollama testing,
  • offline/network observation,
  • AI-DnD strip-down/entanglement checks,
  • Open Dungeon history-retrofit analysis,
  • ai-adventure Ollama/service-boundary checks,
  • AI-DnD non-destructive Undo/Redo spike,
  • referee/state-protocol follow-up,
  • export/import head-position follow-up,
  • Story Card lineage review,
  • Postgres removability review,
  • production fork decision,
  • production architecture decision.

Deferred to implementation/release validation

These do not block the architecture decision:

  • comparative recommendation of narrator/state models for real users,
  • multi-hour/100-turn long-run behavior,
  • detailed concurrency behavior beyond the single-user turn lock,
  • actual future image/video/TTS/STT provider integration,
  • abandoned-history cleanup UI/policy (not required in v1).

Do not convert this into a coding prompt until the package review is approved.

When implementation planning resumes, read:

  1. SPECIFICATION.md
  2. TECHNICAL-DESIGN.md
  3. BUILD-MILESTONES.md
  4. STORY-BRANCH-SEMANTICS.md
  5. DATA-MODEL.md
  6. CONTEXT-AND-MEMORY.md
  7. IMPORTED-KNOWLEDGE-DESIGN.md
  8. SECURITY-THREAT-MODEL.md
  9. BROWSER-UX-SPEC.md
  10. V1-ACCEPTANCE-TESTS.md
  11. ADRs, especially the production-base and narrative-state-event decisions
  12. Phase 0B reports only as supporting evidence

Workflow From Here

Phase 0 research and spikes         COMPLETE
        |
        v
Architecture/fork decision         COMPLETE
        |
        v
Planning package revision          CURRENT REVIEW
        |
        v
Approve planning package
        |
        v
Prepare one implementation prompt
for Production Milestone 1
        |
        v
Implement and review milestone-by-milestone

Stop Rule

Do not begin production coding from this package yet.

The current action is to review the planning changes. No replacement Codex prompt has been prepared in this revision.