Build image / build-and-push (push) Successful in 6s
Gadfly findings on #94, the real ones: - scanSeedPacket extends only the READ deadline; a slow upload + a live vision call runs past the server's absolute 30s WriteTimeout and the successful response is silently dropped (the #78 failure mode). Extend the write deadline too (scanWriteTimeout). - An oversized upload tripping MaxBytesReader was mapped to 400; it's 413. Detect *http.MaxBytesError and report IMAGE_TOO_LARGE. - Split imagenorm error mapping: ErrTooLarge->413, ErrUnsupported->400, genuine read/encode faults (and a failed file.Open)->500, not 400. - CreateFromPacket discarded the plant it created when the lot then failed, contradicting its own doc. Roll the new plant back instead so the confirm is all-or-nothing (a fresh plant has no lots/plantings, so the delete is safe; log-and-continue on cleanup failure). - Dedup: packetLotRequest and seedLotCreateRequest shared every lot field. Extract a seedLotFields base both use. validCategory now reuses plantCategories. EffectiveConfig resolves agent+vision from one settings-row read instead of two. - capabilities swallowed an EffectiveVision error silently; log it. - vision test hand-copied Extract's body (drift risk). Split generate() out of Extract so the hermetic test drives the real request builder. Tests: rollback-on-lot-failure (service), oversized->413 (api). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
169 lines
5.9 KiB
Go
169 lines
5.9 KiB
Go
package service
|
|
|
|
import (
|
|
"context"
|
|
"strings"
|
|
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/agentmodel"
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/domain"
|
|
)
|
|
|
|
// Instance settings (#79): admin-editable, instance-wide configuration. The
|
|
// admin gate lives HERE, in the seam, not in the handler — the same rule every
|
|
// other permission follows. The API's requireAdmin middleware is a cheap early
|
|
// 403, not the authority.
|
|
|
|
// requireAdmin returns nil iff the actor is an admin, else ErrForbidden.
|
|
//
|
|
// ErrForbidden, not ErrNotFound: settings are not a resource whose existence is
|
|
// masked. A logged-in non-admin knows the instance has settings; they simply may
|
|
// not touch them. (Contrast objects/lots, where no-access masks existence.)
|
|
func (s *Service) requireAdmin(ctx context.Context, actorID int64) error {
|
|
u, err := s.store.GetUserByID(ctx, actorID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
if !u.IsAdmin {
|
|
return domain.ErrForbidden
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// GetInstanceSettings returns the instance settings for an admin.
|
|
func (s *Service) GetInstanceSettings(ctx context.Context, actorID int64) (*domain.InstanceSettings, error) {
|
|
if err := s.requireAdmin(ctx, actorID); err != nil {
|
|
return nil, err
|
|
}
|
|
return s.store.GetInstanceSettings(ctx)
|
|
}
|
|
|
|
// InstanceSettingsPatch is a full replacement of the editable fields plus the
|
|
// current version. Both agent fields carry their "inherit" sentinel: an empty
|
|
// AgentModel means fall back to env, a nil AgentEnabled means inherit.
|
|
type InstanceSettingsPatch struct {
|
|
AgentModel string
|
|
AgentEnabled *bool
|
|
VisionModel string
|
|
Version int64
|
|
}
|
|
|
|
// UpdateInstanceSettings applies an admin's change, version-guarded. It returns
|
|
// (current row, ErrVersionConflict) on a stale version, like every mutable
|
|
// resource. The model spec is validated before it is stored, so a typo is a 400
|
|
// now rather than a broken assistant on the next turn.
|
|
//
|
|
// It does NOT rebuild the running agent — that is the API layer's job, because
|
|
// the live Runner lives there. The caller rebuilds on success.
|
|
func (s *Service) UpdateInstanceSettings(ctx context.Context, actorID int64, patch InstanceSettingsPatch) (*domain.InstanceSettings, error) {
|
|
if err := s.requireAdmin(ctx, actorID); err != nil {
|
|
return nil, err
|
|
}
|
|
model := strings.TrimSpace(patch.AgentModel)
|
|
vision := strings.TrimSpace(patch.VisionModel)
|
|
// Validate non-empty specs up front. An empty one is the "inherit env"
|
|
// sentinel and needs no check — the env value was validated at boot.
|
|
for _, spec := range []string{model, vision} {
|
|
if spec != "" {
|
|
if err := agentmodel.Validate(s.cfg.Agent.OllamaCloudAPIKey, spec); err != nil {
|
|
return nil, domain.ErrInvalidInput
|
|
}
|
|
}
|
|
}
|
|
return s.store.UpdateInstanceSettings(ctx, &domain.InstanceSettings{
|
|
AgentModel: model,
|
|
AgentEnabled: patch.AgentEnabled,
|
|
VisionModel: vision,
|
|
Version: patch.Version,
|
|
})
|
|
}
|
|
|
|
// EffectiveAgent resolves the agent configuration actually in force: DB settings
|
|
// override the environment, and the API key always comes from the environment.
|
|
//
|
|
// This is internal plumbing (the API layer calls it to build the Runner), NOT an
|
|
// admin-gated operation — resolving what's configured is not the same as editing
|
|
// it, and the agent bootstrap must work before any user is even authenticated.
|
|
type EffectiveAgent struct {
|
|
Model string
|
|
Enabled bool
|
|
APIKey string
|
|
}
|
|
|
|
// Ready mirrors config.AgentConfig.Ready: enabled, with a key and a model.
|
|
func (e EffectiveAgent) Ready() bool {
|
|
return e.Enabled && e.APIKey != "" && e.Model != ""
|
|
}
|
|
|
|
// EffectiveAgent reads the settings row and layers it over the environment.
|
|
func (s *Service) EffectiveAgent(ctx context.Context) (EffectiveAgent, error) {
|
|
st, err := s.store.GetInstanceSettings(ctx)
|
|
if err != nil {
|
|
return EffectiveAgent{}, err
|
|
}
|
|
return s.agentOver(st), nil
|
|
}
|
|
|
|
// agentOver layers a settings row over the env-derived agent defaults. Split out
|
|
// so EffectiveConfig can resolve agent AND vision from a single row read instead
|
|
// of fetching the same one-row table twice.
|
|
func (s *Service) agentOver(st *domain.InstanceSettings) EffectiveAgent {
|
|
eff := EffectiveAgent{
|
|
Model: s.cfg.Agent.Model,
|
|
Enabled: s.cfg.Agent.Enabled,
|
|
APIKey: s.cfg.Agent.OllamaCloudAPIKey,
|
|
}
|
|
if st.AgentModel != "" {
|
|
eff.Model = st.AgentModel
|
|
}
|
|
if st.AgentEnabled != nil {
|
|
eff.Enabled = *st.AgentEnabled
|
|
}
|
|
return eff
|
|
}
|
|
|
|
// EffectiveVision resolves the vision configuration in force for seed-packet
|
|
// capture (#81): the model from DB-over-env, the key always from env.
|
|
type EffectiveVision struct {
|
|
Model string
|
|
APIKey string
|
|
}
|
|
|
|
// Ready reports whether packet capture can be offered: a key and a vision model.
|
|
// There's no separate enabled flag — configuring a vision model IS enabling it.
|
|
func (e EffectiveVision) Ready() bool {
|
|
return e.APIKey != "" && e.Model != ""
|
|
}
|
|
|
|
// EffectiveVision reads the settings row and layers it over the environment.
|
|
func (s *Service) EffectiveVision(ctx context.Context) (EffectiveVision, error) {
|
|
st, err := s.store.GetInstanceSettings(ctx)
|
|
if err != nil {
|
|
return EffectiveVision{}, err
|
|
}
|
|
return s.visionOver(st), nil
|
|
}
|
|
|
|
// visionOver layers a settings row over the env-derived vision defaults. See
|
|
// agentOver for why this is split from EffectiveVision.
|
|
func (s *Service) visionOver(st *domain.InstanceSettings) EffectiveVision {
|
|
eff := EffectiveVision{
|
|
Model: s.cfg.Agent.VisionModel,
|
|
APIKey: s.cfg.Agent.OllamaCloudAPIKey,
|
|
}
|
|
if st.VisionModel != "" {
|
|
eff.Model = st.VisionModel
|
|
}
|
|
return eff
|
|
}
|
|
|
|
// EffectiveConfig resolves the agent AND vision configuration from ONE settings
|
|
// read, for callers (the settings view) that need both — the single-row table
|
|
// would otherwise be fetched twice for one response.
|
|
func (s *Service) EffectiveConfig(ctx context.Context) (EffectiveAgent, EffectiveVision, error) {
|
|
st, err := s.store.GetInstanceSettings(ctx)
|
|
if err != nil {
|
|
return EffectiveAgent{}, EffectiveVision{}, err
|
|
}
|
|
return s.agentOver(st), s.visionOver(st), nil
|
|
}
|