Files
interactive-story/planning
JesseMarkowitzandClaude Opus 5 c8755c21c2 Planning: close M3 and record active-head architecture
M3's review recommended planning changes and, following the M2 pattern,
reported rather than applied them. This applies them, and adds the ADR the
review asked for.

ADR 012 records the architecture rather than the requirement. ADR 005
already says that going backward must preserve abandoned history and that
the user sees Undo/Redo/Retry rather than branch management; it names a
movable active head as the direction and stops. What M3 settled is the
shape: the head is stored rather than derived, every read of the story is
capped at it in one place, one mechanism moves it, the state of a position
comes off the node rather than from a replay, the first write below a
moved-back head is the divergence, and whether Redo exists is decided by
the lineage rather than by a flag that could be stale. The last of those
is the property worth keeping — a flag can be wrong and make the story
wrong; a lineage cannot.

Two semantics are ratified in STORY-BRANCH-SEMANTICS.md, both of them
reversals or narrowings that a reader would otherwise take for bugs. Undo
now crosses fork points and continues to the campaign opening, because
refusing at the fork was a consequence of deleting rows the parent line
was also reading, and nothing is deleted any more. And the system refuses
to switch which take is live while a later story is off screen, because
doing it quietly would leave retained history continuing from words the
story no longer says.

A new §14A covers editing in place. §14-15 describe the finished
behaviour — the edit becomes authoritative, the state it implies is
re-evaluated, a new continuation is created, the original is retained —
and that requirement is intact and explicitly not weakened here. It is
also not built, because re-evaluating state from prose a user typed needs
M5's extraction pass. §14A says what exists in the meantime and why
refusing is the minimum that holds the invariant rather than the
destination.

TECHNICAL-DESIGN.md gains §8.7 and §9.1, recording the implemented model
and the bundle behaviour as fact in the way §5.2 records M1 and M2. §10.4
gains a constraint that is easy to lose: the snapshot half of the hybrid
state model is a requirement, not an optimization. Head movement is a row
lookup plus a restore, which is why Undo, Redo and Save Point restore cost
the same at any distance into a campaign; a state model recoverable only
by replaying from the opening would make all three proportional to
campaign length, on exactly the long campaigns this product is for.

DATA-MODEL.md records the head as stored on the campaign rather than
derived from its newest turn — two campaigns holding identical turns can
be read at different places, and nothing about the turns can tell them
apart — and the branch disposition as implemented: the depth a divergent
write left the branch at, deliberately advisory, and carried through
export because every row of an abandoned line is exported either way.

BUILD-MILESTONES.md marks M3 complete and states the one condition still
open. M4 is told a Save Point is a durable pointer and that restoring one
is head movement with a bounds check, not a restore system: a second
mover is the specific failure to avoid, because the two paths would
silently disagree about what restore means. M5 gets three constraints —
keep state efficiently recoverable, move the test instrumentation rather
than the assertions when the world-state protocol goes, and finish the
narrator edit §14A defers.

V1-ACCEPTANCE-TESTS.md clarifies ownership without lowering a bar. D10
keeps all three pass conditions and is explicitly recorded as *not*
satisfied at the end of M3; what changed is that the document now says
which milestone delivers which condition. D03's result is recorded as a
full pass rather than the partial the text allowed for, I07 gains the
pre-M3 bundle clause, and L01 gains the note that resolves its apparent
conflict with A05 — a failed turn does advance the head by one, onto the
player's retained input, and that is A05 working rather than L01 failing.

README.md described a different application: a hosted demo, guest
accounts, cloud providers, Postgres, a Render blueprint, an analytics
dashboard, a QuickJS scripting engine, and 549 tests. M2 removed all of
that and the README was never updated — a gap M2's own debt table missed.
It now describes what this fork is, including the endpoint policy and the
TLS behaviour, and the numbers in it are the current ones.

M3's report is included here as its own evidence record: no separate
baseline report was produced, so it carries the raw counts and runtime
observations as well as the review, and §W records this closeout.

SPECIFICATION.md and SECURITY-THREAT-MODEL.md are unchanged. M3 altered no
product requirement and touched no path in the threat model.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QF5TcoB86QADgjHz1GZe8u
2026-09-03 13:54:44 -04:00
..

Adventure Storyteller Planning Package

Status: Phase 0 complete; architecture selected; Milestones M1, M2 and M3 implemented and accepted (M3: 2026-09-03).
Production coding: Underway, milestone by milestone. M1, M2 and M3 are done; M4 is the next milestone to brief.

This package contains the current product requirements, final Phase 0 architecture decisions, detailed subsystem designs, acceptance tests, research evidence, and the production milestone plan for the local-only interactive-story project.

Current Decision

Phase 0A static research and Phase 0B local validation are complete.

The production starting point is:

Fork AI-DnD at upstream commit d72f7c1bda0f34fccd84afb7a25c34eb01c901de.

The selection is based on measured Phase 0B behavior, not feature count. AI-DnD already contains the highest-value structural machinery: browser UI, FastAPI service boundary, SQLite persistence, parent-linked story history, alternate takes, branch-aware state snapshots, local Ollama operation, branch-scoped memory, prompt/context inspection, streaming, export/import, and a substantial automated test suite.

The selected composition of ideas is:

AI-DnD production base
  + ai-adventure state/event/commit/checkpoint/privacy patterns
  + Open Dungeon story-reading and future-media UX patterns
  + Chronicler memory-authority concepts
  + Interactive Fiction Framework canon/validation concepts
  + Gamentic provider-neutral media concepts

This is not a repository merge. AI-DnD is the ownership center. Other projects are implementation references only unless a later milestone explicitly reimplements a compatible idea.

Phase 0B Findings That Changed the Plan

Phase 0B confirmed the fork choice while correcting several Phase 0A assumptions:

  • AI-DnD's shipped Undo was destructive and had no Redo.
  • A disposable spike proved non-destructive head-cursor Undo/Redo in three backend files while preserving branch-scoped memory isolation.
  • A new continuation written after Undo can fork from the moved-back head while retaining the abandoned future.
  • AI-DnD's current relative-delta world-state protocol can produce semantically wrong state under realistic context even when the proposal is syntactically valid.
  • Production narrative state will therefore use explicit typed events/absolute assignments inspired by ai-adventure rather than AI-DnD's relative-delta protocol.
  • AI-DnD requires offline hardening: tiktoken attempts a first-use CDN fetch and the SPA requests Google Fonts at runtime.
  • AI-DnD's export format must preserve the active head position; otherwise export/import can silently redo an undone story.
  • AI-DnD Story Cards are not a sufficient imported-knowledge store because they are not designed for the required classification, provenance, chunking, and lineage semantics.
  • Open Dungeon remains useful for UX/media ideas but is no longer a serious production-fork candidate.
  • ai-adventure is not the production base but is the strongest implementation reference for authoritative typed state events, head movement, checkpoints, replay, and narrow local-only behavior.

See PHASE-0B-RECOMMENDATION.md for the coding agent's evidence. That report is retained as research evidence; the planning documents in this package record the decisions made after reviewing it.

Document Authority

Use the documents in this order when requirements appear to conflict:

  1. SPECIFICATION.md — product requirements and required behavior.
  2. Detailed behavior/design documents:
    • STORY-BRANCH-SEMANTICS.md
    • CONTEXT-AND-MEMORY.md
    • IMPORTED-KNOWLEDGE-DESIGN.md
    • SECURITY-THREAT-MODEL.md
    • MEDIA-EXTENSION-CONTRACT.md
    • BROWSER-UX-SPEC.md
    • DATA-MODEL.md
  3. V1-ACCEPTANCE-TESTS.md — observable pass/fail contract.
  4. TECHNICAL-DESIGN.md — selected implementation architecture.
  5. Foundational ADRs (001-...md through the current ADR set).
  6. BUILD-MILESTONES.md — implementation sequence; it does not override product behavior.
  7. Phase 0 research reports — evidence and historical findings.

Candidate repositories and research reports are not specifications. In particular, ai-adventure is an implementation reference for selected patterns; its behavior does not override this package.

Foundational Decisions

The following are settled for v1:

  • browser-first UI,
  • local-only runtime across user-controlled local infrastructure,
  • Ollama inference with same-host loopback as default and explicitly configured trusted-LAN inference supported,
  • single-user deployment,
  • AI-DnD production base at the pinned Phase 0B commit,
  • application-owned authoritative state,
  • complete retained transcript/history,
  • simple user-facing Undo/Redo/Retry/Save Point semantics,
  • non-destructive head-cursor history internally,
  • new write after moving backward creates a new continuation while retaining the old future,
  • abandoned history is retained and marked disposable; no automatic cleanup is required in v1,
  • named checkpoints remain until explicitly deleted,
  • genre-agnostic core state,
  • explicit typed narrative-state events/absolute assignments rather than ambiguous relative deltas,
  • hybrid state model: validated events plus state snapshots/cache,
  • branch/lineage-safe summaries and memories,
  • imported knowledge is a separate first-class subsystem rather than an extension of AI-DnD Story Cards,
  • knowledge classes: Canon / Reference / Inspiration,
  • local lexical retrieval plus local semantic retrieval where practical,
  • prompt/context provenance and inspection,
  • export/import must preserve active branch and active head position, including an undone position,
  • no cloud/Internet inference, telemetry, automatic web retrieval, remote runtime assets, shell/MCP/general plugin execution,
  • LAN inference is distinct from LAN exposure of the storyteller UI/API; the latter is not required for v1,
  • future local image/video/audio/TTS/STT support remains optional and decoupled from the story engine.

Phase 0 Status

Complete

  • candidate discovery and triage,
  • static architecture/privacy/licensing review,
  • local clone/build/test validation,
  • real Ollama testing,
  • offline/network observation,
  • AI-DnD strip-down/entanglement checks,
  • Open Dungeon history-retrofit analysis,
  • ai-adventure Ollama/service-boundary checks,
  • AI-DnD non-destructive Undo/Redo spike,
  • referee/state-protocol follow-up,
  • export/import head-position follow-up,
  • Story Card lineage review,
  • Postgres removability review,
  • production fork decision,
  • production architecture decision.

Deferred to implementation/release validation

These do not block the architecture decision:

  • comparative recommendation of narrator/state models for real users,
  • multi-hour/100-turn long-run behavior,
  • detailed concurrency behavior beyond the single-user turn lock,
  • actual future image/video/TTS/STT provider integration,
  • abandoned-history cleanup UI/policy (not required in v1).

Do not convert this into a coding prompt until the package review is approved.

When implementation planning resumes, read:

  1. SPECIFICATION.md
  2. TECHNICAL-DESIGN.md
  3. BUILD-MILESTONES.md
  4. STORY-BRANCH-SEMANTICS.md
  5. DATA-MODEL.md
  6. CONTEXT-AND-MEMORY.md
  7. IMPORTED-KNOWLEDGE-DESIGN.md
  8. SECURITY-THREAT-MODEL.md
  9. BROWSER-UX-SPEC.md
  10. V1-ACCEPTANCE-TESTS.md
  11. ADRs, especially the production-base and narrative-state-event decisions
  12. Phase 0B reports only as supporting evidence

Workflow From Here

Phase 0 research and spikes         COMPLETE
        |
        v
Architecture/fork decision         COMPLETE
        |
        v
Planning package revision          COMPLETE
        |
        v
Approve planning package           COMPLETE
        |
        v
Milestone M1                       COMPLETE (2026-09-02)
  fork + offline baseline          see planning/reports/M1-*.md
        |
        v
Milestone M2                       COMPLETE (2026-09-02)
  local-only surface + endpoint    see planning/reports/M2-*.md
  policy
        |
        v
Milestone M3                       COMPLETE (2026-09-03)
  non-destructive undo/redo,       see planning/reports/M3-*.md and ADR 012
  active-head export               one open condition: the browser smoke test
        |
        v
Milestone M4                       NEXT — brief not yet prepared
  named Save Points
        |
        v
Implement and review milestone-by-milestone

Stop Rule

One milestone at a time. Do not begin a milestone before its brief exists.

M1, M2 and M3 are complete and accepted; the evidence is in reports/M1-*.md, reports/M2-*.md and reports/M3-IMPLEMENTATION-REPORT.md — the last of which is M3's primary evidence record as well as its review, since no separate M3 baseline report was produced. No M4 brief has been prepared. The current action is to write one, informed by the post-M3 corrections below, by the note BUILD-MILESTONES.md now attaches to M4, and by ADR 012, which records the head-movement mechanism M4 must reuse rather than reimplement.

One M3 condition remains open and is not a blocker for M4: the required browser smoke test has not been performed, because no session in which M3 was implemented or reviewed had a browser available. See reports/M3-IMPLEMENTATION-REPORT.md §M and §W.4.

Post-M3 corrections applied (2026-09-03)

M3's review recommended planning changes and, following the M2 pattern, reported rather than applied them. All are now applied, together with the closeout work the milestone itself required:

Document Correction
DECISIONS/012-active-head-non-destructive-history.md New ADR. The architecture selected to implement ADR 005: head stored not derived, one capped read path, one movement mechanism, state from the node, divergence on first write below the head, Redo decided by the lineage, advisory disposition metadata, and the head as an exported decision.
STORY-BRANCH-SEMANTICS.md §5 Undo crosses fork points and continues to the campaign opening. The old refusal was a consequence of destructive deletion, not a product decision.
STORY-BRANCH-SEMANTICS.md §10 Switching which take is live is refused while a later story is off screen, with the two resolutions the user has.
STORY-BRANCH-SEMANTICS.md §14A New. In-place editing before §14-15 exist: refuse when story descends from the turn and is not on screen. States explicitly that the full narrator-edit requirement stands and is completed in M5.
TECHNICAL-DESIGN.md §8.7, §9.1 New. The implemented active-head model and bundle behaviour, recorded as fact.
TECHNICAL-DESIGN.md §10.4 Constraint from M3: the snapshot half of the hybrid state model is a requirement, or head movement becomes proportional to campaign length.
DATA-MODEL.md §4, §5, §29 The head as campaign-stored rather than derived; the branch disposition as implemented and deliberately advisory; the export as carrying a chosen position.
BUILD-MILESTONES.md M3 Marked COMPLETE, with inherited capabilities, the open browser condition, and carried debt.
BUILD-MILESTONES.md M4 Note: a Save Point is a durable pointer; restore by reusing M3's head movement rather than building a second restore path.
BUILD-MILESTONES.md M5 Note: keep state efficiently recoverable at a position; move the test instrumentation rather than the assertions; complete the narrator edit.
V1-ACCEPTANCE-TESTS.md D03, D10, I07, L01 D03's result recorded as a full pass; D10's milestone ownership stated without weakening any pass condition; I07's pre-M3 bundle clause added; the apparent L01/A05 conflict resolved.
README.md Corrected to describe the current local-only single-user application. The scripting, accounts, analytics, hosted-demo, cloud-provider, Postgres and Render material described subsystems M2 removed.

SPECIFICATION.md and SECURITY-THREAT-MODEL.md were deliberately not changed. M3 altered no product requirement and touched no path in the threat model.

Post-M2 corrections applied (2026-09-03)

M2's review recommended six planning changes and reported rather than applied them. All six are now applied, plus three additions drawn from the same evidence:

Document Correction
SECURITY-THREAT-MODEL.md New §10A records the inference endpoint policy as implemented — address allowlist, enforced on save and before every request, TLS never traded against it — with both residual limits stated. §71A item 5 marked resolved; §77 notes the required defaults are now met.
TECHNICAL-DESIGN.md §5.1 Items 3 and 4 marked done; all five hardening items are now resolved.
TECHNICAL-DESIGN.md §5.2 New: the M1/M2 production architecture recorded as fact — SQLite, Ollama-only, loopback storyteller, trusted-LAN inference accepted, public endpoints refused.
TECHNICAL-DESIGN.md §18.1 New wiring rule from the M2 regressions: test a real consumer path when removing a setting, and prove a new setting reaches its component.
DECISIONS/011-local-inference-endpoint-policy.md New ADR. Address-based allowlist over hostname matching, deny by default, checked twice, mandatory TLS — with the ipaddress-classification finding as the reason the CIDRs are spelled out.
BUILD-MILESTONES.md M2 Marked COMPLETE with the capabilities it delivered and the debt it carried forward.
BUILD-MILESTONES.md M5 Note: eight rollback tests now use the world-state engine as instrumentation, not as endorsement; move the instrumentation when M5 replaces the protocol, and rework rather than delete those tests.
BUILD-MILESTONES.md M6 Note: background memory failure must be observable, at least one real provider-construction path must be tested, and derived-memory failure must not corrupt accepted story state.
V1-ACCEPTANCE-TESTS.md H10 Strengthened: a wildcard origin must be rejected at startup, and an unknown /api/... path must 404 rather than returning the SPA with HTTP 200.
V1-ACCEPTANCE-TESTS.md H12 New. Inference endpoint enforcement, including the defence-in-depth case: a public endpoint written into the database behind the settings API must still be refused at request time.

SPECIFICATION.md was deliberately not changed. M2 altered no product requirement; it removed capability the specification never asked for.

Post-M1 corrections applied (2026-09-02)

Implementation evidence contradicted or under-specified six places in this package, and a seventh was added on review. All seven are now corrected:

Document Correction
DECISIONS/002-ollama-only-v1.md New section: a trusted-LAN Ollama may be HTTPS with a private CA; verify against the OS trust store; full certificate and hostname checking; no bypass option.
DECISIONS/004-local-only-production.md New Testing Consequence: offline tests need a fresh cache and no route out. Vendored runtime artifacts should be integrity-verifiable.
V1-ACCEPTANCE-TESTS.md A05 Pass conditions reworded around accepted history; explicit note that the user's submitted text is deliberately retained.
V1-ACCEPTANCE-TESTS.md A06 Now requires a real second machine and an HTTPS endpoint with a locally issued certificate; a plain-HTTP LAN test is no longer sufficient evidence.
V1-ACCEPTANCE-TESTS.md §3 Record CPU/GPU/RAM: cold model load on a CPU-only host exceeded the inherited 120 s timeout.
BUILD-MILESTONES.md M1 marked COMPLETE with the capabilities it delivered; M2's endpoint-policy line reframed from inventing trusted-LAN support to narrowing it.
TECHNICAL-DESIGN.md §5 Runtime boundary restated: the storyteller is loopback-only, inference may be same-host or trusted-LAN, and the two are independent. Adds the TLS/private-CA rule.