Address Gadfly review on revision history
Build image / build-and-push (push) Successful in 5s

Six real bugs, three of which would have broken the feature's central promise.

The worst was that a failed operation threw away the history for changes that
had already committed. WithChangeSet buffers HISTORY, not data — the store
writes inside fn commit as they go — so discarding the buffer on error left real
mutations with no change set and no way to undo them. That is exactly the
situation undo exists for: an agent turn that did half a thing and then failed.
Now the buffer is written, the summary says the operation failed partway, and
the error is still returned. RevertChangeSet does the same for a revert that
fails mid-loop. The partial state is still partial, but it is visible and
undoable instead of orphaned.

versionGuard falsely conflicted whenever one change set held more than one
revision for the same entity — an agent turn that moves a bed and then renames
it. Each inverse bumps the row's version, so from the second one on the
snapshot's version no longer matched the live row and the revert flagged its own
work as somebody else's edit. RevertChangeSet now tracks what it has written and
the guard compares against that.

ListChangeSets found "was this reverted?" with a LEFT JOIN, which emits one
duplicate row per revert once a change set has been reverted more than once
(undo, redo, undo again). Now a scalar subquery.

Reverting an object creation cascade-deleted anything planted in that bed since,
quietly. The plops were snapshotted so it was recoverable, but deleting
someone's plants as a side effect of an unrelated undo should be reported. It
now conflicts and leaves the bed alone.

ClearObject cleared by predicate and snapshotted by a separate read, so a plop
created between the two was removed with no revision to undo it by. It now
clears exactly the ids it read. It also returned an error when only the
post-clear re-read failed, which told the caller a clear had failed after it had
already applied — inviting a retry of an applied operation. That path now logs
the history gap and reports success, matching how record() treats its own write
failures.

RestoreObject/RestorePlanting could lose the race between the existence check
and the insert and surface a raw constraint error. The revert now re-checks and
reports ConflictExists, which is what that condition means.

RevertChangeSet takes a source, so an agent undoing its own work is
distinguishable from a person clicking undo — the whole point of the badge.

Refactoring: the three revert bodies repeated a load/guard/unsnapshot/update
skeleton (flagged by 3 of 5 models). They are now one generic revertEntity over
a small per-type op table, so the ordering, guards and conflict reporting cannot
drift apart. The API's view structs duplicated domain types that already carried
every field, against the package's direct-JSON convention — dropped. intQuery
moved next to the other request helpers. planRevert's comment said three passes
where the code runs five. A revert where every revision is already a no-op now
answers 200 rather than 201 with a null change set.

Six new tests, one per bug.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
This commit is contained in:
2026-07-21 01:06:43 -04:00
co-authored by Claude Opus 4.8
parent b4f3181aef
commit 2dd9f2f04f
8 changed files with 543 additions and 280 deletions
+31 -91
View File
@@ -2,7 +2,6 @@ package api
import (
"net/http"
"strconv"
"github.com/gin-gonic/gin"
@@ -10,54 +9,26 @@ import (
)
// Change history and undo (#48). Two endpoints: read a garden's change sets, and
// revert one.
// revert one. Both encode domain types directly, like the rest of the package —
// domain.ChangeSet already carries the actor name, revert linkage and per-op
// counts the history list renders, and its Revisions field is omitempty so the
// JSON snapshots never ride along on a list response.
// historyResponse is the body of GET /gardens/:id/history. hasMore lets the
// client page without a separate count query — it asks for one row more than it
// shows and reports whether that row existed.
// client page without a separate count query over a table that only grows.
type historyResponse struct {
ChangeSets []changeSetView `json:"changeSets"`
HasMore bool `json:"hasMore"`
ChangeSets []domain.ChangeSet `json:"changeSets"`
HasMore bool `json:"hasMore"`
}
// changeSetView is one history entry. It deliberately omits the revisions
// themselves: the list renders counts, and nothing in the UI needs the JSON
// snapshots.
type changeSetView struct {
ID int64 `json:"id"`
GardenID int64 `json:"gardenId"`
ActorID int64 `json:"actorId"`
ActorName string `json:"actorName"`
Source string `json:"source"`
Summary string `json:"summary"`
AgentRunID *string `json:"agentRunId,omitempty"`
RevertsID *int64 `json:"revertsId,omitempty"`
RevertedByID *int64 `json:"revertedById,omitempty"`
Counts []countView `json:"counts"`
CreatedAt string `json:"createdAt"`
}
type countView struct {
EntityType string `json:"entityType"`
Op string `json:"op"`
N int `json:"n"`
}
// revertResponse is the body of POST /change-sets/:id/revert, on both the clean
// (201) and partial (409) paths. Carrying both fields either way is what lets the
// UI say "2 of 3 changes undone; the north bed was edited since and was left
// alone" instead of a generic failure — a partial revert really did change
// things, and pretending otherwise would be a lie.
// revertResponse is the body of POST /change-sets/:id/revert on every path.
// Carrying both fields regardless is what lets the UI say "2 of 3 changes undone;
// the north bed was edited since and was left alone" instead of a generic
// failure — a partial revert really did change things, and pretending otherwise
// would be a lie. ChangeSet is null when nothing needed reverting.
type revertResponse struct {
ChangeSet *changeSetView `json:"changeSet"`
Conflicts []conflictView `json:"conflicts"`
}
type conflictView struct {
EntityType string `json:"entityType"`
EntityID int64 `json:"entityId"`
Reason string `json:"reason"`
Name string `json:"name,omitempty"`
ChangeSet *domain.ChangeSet `json:"changeSet"`
Conflicts []domain.RevertConflict `json:"conflicts"`
}
func (h *handlers) getGardenHistory(c *gin.Context) {
@@ -74,11 +45,7 @@ func (h *handlers) getGardenHistory(c *gin.Context) {
writeServiceError(c, err)
return
}
views := make([]changeSetView, 0, len(sets))
for i := range sets {
views = append(views, *toChangeSetView(&sets[i]))
}
c.JSON(http.StatusOK, historyResponse{ChangeSets: views, HasMore: hasMore})
c.JSON(http.StatusOK, historyResponse{ChangeSets: sets, HasMore: hasMore})
}
func (h *handlers) revertChangeSet(c *gin.Context) {
@@ -86,55 +53,28 @@ func (h *handlers) revertChangeSet(c *gin.Context) {
if !ok {
return
}
cs, conflicts, err := h.svc.RevertChangeSet(c.Request.Context(), mustActor(c).ID, id)
// A revert through the REST API is a person clicking undo. The agent reverts
// its own work through the service directly and stamps SourceAgent, so the
// history badge can tell the two apart.
cs, conflicts, err := h.svc.RevertChangeSet(c.Request.Context(), mustActor(c).ID, id, domain.SourceUI)
if err != nil {
writeServiceError(c, err)
return
}
body := revertResponse{ChangeSet: toChangeSetView(cs), Conflicts: toConflictViews(conflicts)}
if len(conflicts) > 0 {
if conflicts == nil {
conflicts = []domain.RevertConflict{}
}
body := revertResponse{ChangeSet: cs, Conflicts: conflicts}
switch {
case len(conflicts) > 0:
// 409 even when part of the revert applied: something the caller asked for
// did not happen, and the body says exactly what.
c.JSON(http.StatusConflict, body)
return
}
c.JSON(http.StatusCreated, body)
}
func toChangeSetView(cs *domain.ChangeSet) *changeSetView {
if cs == nil {
return nil
}
counts := make([]countView, 0, len(cs.Counts))
for _, c := range cs.Counts {
counts = append(counts, countView{EntityType: c.EntityType, Op: c.Op, N: c.N})
}
return &changeSetView{
ID: cs.ID, GardenID: cs.GardenID, ActorID: cs.ActorID, ActorName: cs.ActorName,
Source: cs.Source, Summary: cs.Summary, AgentRunID: cs.AgentRunID,
RevertsID: cs.RevertsID, RevertedByID: cs.RevertedByID,
Counts: counts, CreatedAt: cs.CreatedAt,
case cs == nil:
// Every revision resolved to a no-op (already undone by hand, say). Nothing
// was created, so 200 rather than a 201 pointing at nothing.
c.JSON(http.StatusOK, body)
default:
c.JSON(http.StatusCreated, body)
}
}
func toConflictViews(cs []domain.RevertConflict) []conflictView {
views := make([]conflictView, 0, len(cs))
for _, c := range cs {
views = append(views, conflictView{EntityType: c.EntityType, EntityID: c.EntityID, Reason: c.Reason, Name: c.Name})
}
return views
}
// intQuery reads a non-negative integer query parameter, falling back to def on
// an absent or malformed value.
func intQuery(c *gin.Context, name string, def int) int {
raw := c.Query(name)
if raw == "" {
return def
}
v, err := strconv.Atoi(raw)
if err != nil || v < 0 {
return def
}
return v
}