The head-cursor model landed in 903fa7a and stopped there: the backend
moved the head instead of deleting turns, but a bundle still reopened at
its newest row, the browser had no way forward, and five inherited tests
still asserted the contract Undo had just stopped honouring. This is the
rest of the milestone, plus the one unsafe operation the review found.
Export now writes headDepth, and it belongs on the other side of the rule
app/bundle.py states about itself. The head depth used to be derived —
the tip of the head branch, a fact about the nodes that arrived with it —
and that was true while Undo deleted, because the newest row was the only
place a story could be read. It is a decision now: the same tree exports
identically whether the user undid three turns or none, so the file has
to say. An import that ignored it would silently Redo the story to its
newest retained turn, which is the Phase 0B export finding this milestone
exists to close. A file with no headDepth is opened at the tip, which is
not a fallback but the position such a file recorded; a file naming a
depth its own rows do not reach is refused in plan(), before a row is
written, for the reason that module gives about half-written trees.
Which branches the story has left goes into the file for the same reason.
Every row of an abandoned line arrives on an import either way, so the
disposition is the only thing telling it apart from an active one, and a
restored backup that had lost it would have nothing for the later cleanup
and recovery screens to select on. Both keys or neither: a time with no
depth cannot say what was displaced.
The browser gets a Redo button beside Undo, on Ctrl+Shift+Z, and both are
enabled from can_undo/can_redo rather than from the transcript. Neither
is derivable on the client — Undo stops at the campaign opening, which
may be off the top of the loaded window, and Redo depends on the retained
future, which the client is never sent — so the flags now ride on every
window the server hands back, including a scrolled-up page and the
response to an import. Moving the head also refreshes the state panels,
which undo never did: it has rolled the world state back since long
before M3 and the drawer kept showing the old numbers.
An in-place edit is now refused when story descends from the turn and is
not on screen. Editing rewrites one row and re-evaluates nothing, which
is what makes it a correction rather than a continuation, and that is
harmless while everything below the turn is visible — the reader can see
what their change has to agree with. It stops being harmless when the
continuation is undone, or was left behind by a divergence, because the
edit then silently changes the words an invisible stretch of story was
written from. That was the one way M3's retained history could be made to
contradict itself. Refusing is deliberately the whole of the fix: making
such an edit fork is STORY-BRANCH-SEMANTICS.md §14-15, and §15 wants the
state the edited prose implies re-evaluated, which is M5's extraction
pass. The requirement is not weakened, only deferred, and §14A now says
so.
The predicate asks one question rather than two. A descendant is
invisible either because it is past the head on this lineage or because
it is past a fork on a branch the story left, and both are "a live node,
deeper than this one, descending from it, off the path being read". A
first attempt scoped the search to branches other than the active one and
failed the divergence case, correctly: the departed branch is usually an
ancestor of the branch now being read. Only the deepest live node on each
descending branch is examined, because visibility is monotone in depth.
Five inherited tests are rewritten rather than deleted, because what they
were protecting is still worth protecting and only the mechanism changed.
The undo-state pair keeps its state assertions and swaps "the rows are
gone" for "the rows are all here and the story is read from earlier". The
memory test stops asserting that undo prunes memories and starts
asserting the property that replaced it: a memory past the head is
unreachable, still on disk, and retrievable again after Redo, with no
re-embedding. The attempt-group test still proves the group moves as one,
out of the story rather than out of the database. And the fork test
reverses: Undo used to refuse at a fork point because it deleted rows the
parent branch was also reading, and with nothing deleted there is nothing
to protect the parent from, so it now walks into the story the branch
inherits and stops at the campaign opening instead.
tests/test_head_cursor.py is the milestone's acceptance contract, named
by the items it discharges: D01-D10, E01-E04, I01-I03, I07, L01-L02, and
the invariant they all rest on — Undo deletes zero accepted turns,
asserted on row ids over the whole retained tree. E02 has both controls,
because a negative control alone would pass if memory retrieval were
simply broken. L01 records what it does not claim: the head does move by
one on a failed turn, onto the player's retained input, which is A05
rather than a gap. Two of the edit-guard tests exist to prove the guard
stays out of the way — a correction at the tip and a correction mid-story
with everything visible must both still work.
638 backend tests pass. Frontend lint is unchanged at seven pre-existing
warnings, none in the files touched; the bundle builds at 395.85 kB; the
production image builds.
Verified at runtime against the trusted-LAN Ollama over HTTPS: three
turns, two Undos, a Redo, a Retry, an Undo, a divergent continuation,
Redo correctly refused with 400, Undo back to the opening, export, a
process restart that reopened the campaign still undone, and an import
that opened at the same position with its retained future intact. The
browser click-through of that sequence has not been run — no session in
this milestone had a browser to drive — so the Redo control itself is
verified by its endpoint and its lint and build, not by a click.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QF5TcoB86QADgjHz1GZe8u
372 lines
16 KiB
Python
372 lines
16 KiB
Python
"""M3: where the story is being read, and what moving that point costs.
|
|
|
|
Undo used to delete. It removed the trailing nodes, let `tree.refresh_head`
|
|
recompute the tip from what survived, and the story was wherever the rows ended.
|
|
That made the head a derived value and made Redo impossible, because the turns it
|
|
would have moved forward into were gone.
|
|
|
|
The head is now a stored position that can sit behind the retained tip. Nothing
|
|
is deleted, so three things that used to be the same question are now three
|
|
different ones:
|
|
|
|
* **the active head** — `adventure.head_branch_id` and `adventure.head_depth`,
|
|
the end of the story being told. Every read of the story stops here, because
|
|
`lineage.Path` caps every entry at it.
|
|
* **the retained tip** — the deepest live node still on the lineage. Redo walks
|
|
toward it. It is read through `Path.uncapped()`, and only this module and the
|
|
divergence check may look at it.
|
|
* **the opening** — the shallowest node on the story, which is the floor Undo
|
|
may not pass.
|
|
|
|
Everything that moves the head or asks a question about it lives here, so the
|
|
turn engine, Retry, Add-take, Undo, Redo and Edit share one set of rules rather
|
|
than four similar ones. The Phase 0B spike put the fork check in the write path
|
|
and left Retry and Add-take on the old one, which is exactly the divergence this
|
|
module exists to prevent.
|
|
|
|
The state that belongs to a position is not recomputed. Every node carries the
|
|
world state it left behind (`attempts.snapshot_outcome`), so moving the head is a
|
|
row lookup plus `attempts.restore_state`, at any distance, in either direction.
|
|
"""
|
|
|
|
from sqlalchemy.orm import Session, undefer
|
|
|
|
from . import attempts, models, tree
|
|
from .context import lineage
|
|
|
|
# The kinds of node a player writes. An undo or a redo steps over a whole turn,
|
|
# which is one of these followed by the reply to it, so both ends need to agree
|
|
# on what "a player's half of a turn" is.
|
|
PLAYER_TYPES = ("do", "say", "story", "continue")
|
|
|
|
|
|
# ------------------------------------------------------------------ reading
|
|
|
|
def opening_depth(db: Session, adventure: models.Adventure) -> int | None:
|
|
"""Returns the depth of the first node of the story, or None if there is none.
|
|
|
|
This is Undo's floor. The Phase 0B spike moved the head to -1 and rendered an
|
|
empty transcript, because its guard tested for a node of type `start` and an
|
|
adventure opened with a player-written `story` action has none. Asking the
|
|
path for its shallowest node needs no such special case: whatever the opening
|
|
is called, it is the node with the smallest depth, and the story keeps it.
|
|
|
|
The read is uncapped. The opening does not move when the head does, and
|
|
capping would make the floor depend on where the head already is.
|
|
"""
|
|
return (
|
|
db.query(models.Action.depth)
|
|
.filter(
|
|
models.Action.adventure_id == adventure.id,
|
|
lineage.path_of(db, adventure).uncapped().clause(models.Action),
|
|
)
|
|
.order_by(models.Action.depth.asc(), models.Action.id.asc())
|
|
.limit(1)
|
|
.scalar()
|
|
)
|
|
|
|
|
|
def retained_tip(db: Session, adventure: models.Adventure) -> int | None:
|
|
"""Returns the depth of the deepest live node still retained on this lineage.
|
|
|
|
This is what the head would be if the story had never been undone, and it is
|
|
what Redo can reach. It is not the head, and no read of the story may use it.
|
|
"""
|
|
return (
|
|
db.query(models.Action.depth)
|
|
.filter(
|
|
models.Action.adventure_id == adventure.id,
|
|
lineage.path_of(db, adventure).uncapped().clause(models.Action),
|
|
)
|
|
.order_by(models.Action.depth.desc(), models.Action.id.desc())
|
|
.limit(1)
|
|
.scalar()
|
|
)
|
|
|
|
|
|
def behind_tip(db: Session, adventure: models.Adventure) -> bool:
|
|
"""Returns whether retained story sits past the head.
|
|
|
|
This one predicate answers every "does this write need to fork?" question in
|
|
the application. It is true exactly when the user has undone and not redone,
|
|
which is the only situation in which writing can displace an accepted future.
|
|
|
|
It is also what makes "is this turn the tip?" answerable again. Retry,
|
|
Add-take and `stand_on` each decide between amending a turn in place and
|
|
giving it a branch, and each used to ask `last_action`, which reads the
|
|
*capped* path and therefore reports the node at the head as the newest one.
|
|
Under a moved-back head that answer is wrong in the dangerous direction: it
|
|
says a turn with an accepted future is a leaf, and amending it in place would
|
|
leave that future descending from a take that is no longer live.
|
|
"""
|
|
tip = retained_tip(db, adventure)
|
|
return tip is not None and tip > adventure.head_depth
|
|
|
|
|
|
def node_at(
|
|
db: Session, adventure: models.Adventure, depth: int
|
|
) -> models.Action | None:
|
|
"""Returns the live node at `depth` on the retained lineage, outcome loaded.
|
|
|
|
The read is uncapped on purpose: Redo asks for a node it is about to move the
|
|
head onto, which is by definition past the head at the time of asking. The
|
|
outcome columns are undeferred because the only reason to fetch this row is
|
|
to restore the state it left behind.
|
|
"""
|
|
return (
|
|
db.query(models.Action)
|
|
.filter(
|
|
models.Action.adventure_id == adventure.id,
|
|
lineage.path_of(db, adventure).uncapped().clause(models.Action),
|
|
models.Action.depth == depth,
|
|
)
|
|
.options(
|
|
undefer(models.Action.state_after),
|
|
undefer(models.Action.world_state_after),
|
|
)
|
|
.order_by(models.Action.id)
|
|
.first()
|
|
)
|
|
|
|
|
|
def redo_target(db: Session, adventure: models.Adventure) -> int | None:
|
|
"""Returns the depth the head moves to on Redo, or None if there is nowhere.
|
|
|
|
Redo steps over a whole turn, the same unit Undo steps back over, so a
|
|
player's action and the reply to it move together. Landing between them would
|
|
show the story an input with no answer and would leave the next Undo undoing
|
|
half a turn.
|
|
|
|
The walk is along the retained lineage, which is what makes Redo follow the
|
|
continuation that was active rather than choosing among branches. After a
|
|
divergence the new branch *is* the lineage, and the displaced future is no
|
|
longer on it, so this returns None without having to know that a divergence
|
|
happened. That is `STORY-BRANCH-SEMANTICS.md` §8 falling out of the lineage
|
|
rather than being enforced by a flag.
|
|
"""
|
|
ahead = (
|
|
db.query(models.Action)
|
|
.filter(
|
|
models.Action.adventure_id == adventure.id,
|
|
lineage.path_of(db, adventure).uncapped().clause(models.Action),
|
|
models.Action.depth > adventure.head_depth,
|
|
)
|
|
.order_by(models.Action.depth.asc(), models.Action.id.asc())
|
|
.limit(2)
|
|
.all()
|
|
)
|
|
if not ahead:
|
|
return None
|
|
first = ahead[0]
|
|
if (
|
|
first.type in PLAYER_TYPES
|
|
and len(ahead) > 1
|
|
and ahead[1].type == "ai"
|
|
and ahead[1].depth == (first.depth or 0) + 1
|
|
):
|
|
return ahead[1].depth
|
|
return first.depth
|
|
|
|
|
|
def can_redo(db: Session, adventure: models.Adventure) -> bool:
|
|
"""Returns whether an ordinary Redo is available from where the head is."""
|
|
return redo_target(db, adventure) is not None
|
|
|
|
|
|
def undo_target(
|
|
db: Session, adventure: models.Adventure
|
|
) -> tuple[int, models.Action] | None:
|
|
"""Returns where Undo moves the head, and the first node it steps back over.
|
|
|
|
None means there is nothing to undo, which is either an empty story or a head
|
|
already resting on the opening. The caller turns that into a 400; this
|
|
function does not raise, so that the same question can be asked without
|
|
committing to undoing.
|
|
|
|
A turn is the player's node plus the reply to it, and both move together for
|
|
the reason given in `redo_target`. The player half is only claimed when it is
|
|
directly in front of the reply, so a bare `continue`, which writes no player
|
|
node, steps back over the reply alone.
|
|
"""
|
|
newest = (
|
|
db.query(models.Action)
|
|
.filter(
|
|
models.Action.adventure_id == adventure.id,
|
|
lineage.path_of(db, adventure).clause(models.Action),
|
|
)
|
|
.order_by(models.Action.depth.desc(), models.Action.id.desc())
|
|
.limit(2)
|
|
.all()
|
|
)
|
|
if not newest:
|
|
return None
|
|
last = newest[0]
|
|
first_stepped = last
|
|
before = newest[1] if len(newest) > 1 else None
|
|
if (
|
|
last.type == "ai"
|
|
and before is not None
|
|
and before.type in PLAYER_TYPES
|
|
and before.depth == (last.depth or 0) - 1
|
|
):
|
|
first_stepped = before
|
|
floor = opening_depth(db, adventure)
|
|
if first_stepped.depth is None or floor is None:
|
|
return None
|
|
if first_stepped.depth <= floor:
|
|
# Stepping back over this turn would hide the opening of the campaign,
|
|
# which is the pre-campaign state `STORY-BRANCH-SEMANTICS.md` §4 stops
|
|
# at. The floor is the opening node itself rather than depth -1, so an
|
|
# adventure that opens on a player-written `story` action stops in the
|
|
# same place as one that opens on a `start` node.
|
|
return None
|
|
return first_stepped.depth - 1, first_stepped
|
|
|
|
|
|
def can_undo(db: Session, adventure: models.Adventure) -> bool:
|
|
"""Returns whether an ordinary Undo is available from where the head is."""
|
|
return undo_target(db, adventure) is not None
|
|
|
|
|
|
def displaced_history_under(
|
|
db: Session, adventure: models.Adventure, node: models.Action
|
|
) -> bool:
|
|
"""Returns whether story the reader cannot see descends from `node`.
|
|
|
|
This is the question an in-place edit has to ask. Editing rewrites one row
|
|
and re-evaluates nothing, which is what makes it a correction rather than a
|
|
new continuation. That is harmless while everything descending from the row
|
|
is on screen: the reader can see what their correction has to stay
|
|
consistent with. It stops being harmless the moment a continuation descends
|
|
from the row and is *not* on screen, because the edit then silently changes
|
|
the words an invisible stretch of story was written from. That is the one
|
|
way M3's retained history can be made to contradict itself.
|
|
|
|
Refusing is deliberately the whole of the fix. Making such an edit fork, so
|
|
the original text and its future stay whole, is
|
|
`STORY-BRANCH-SEMANTICS.md` §14-15 — and §15 requires re-evaluating the
|
|
state the edited prose implies, which is M5's extraction pass. Neither is
|
|
started here.
|
|
|
|
The question is asked as one shape rather than two, because the two ways a
|
|
descendant becomes invisible turn out to be the same fact. An undone future
|
|
sits past the head on this very lineage; a displaced line sits past a fork
|
|
on a branch the story left. In both cases there is a live node, deeper than
|
|
this one, that descends from it and is not on the path being read — and the
|
|
departed branch is usually an *ancestor* of the branch now being read, which
|
|
is why "branches other than the active one" is the wrong set to look at.
|
|
|
|
Only the deepest live node on each descending branch is examined. Whether a
|
|
node is on the read path is monotone in depth: a branch is on the path with
|
|
a cap, and a node is visible when its depth is at or under that cap. So if
|
|
the deepest one is visible, every shallower one is too, and if it is not,
|
|
the answer is already yes.
|
|
|
|
A node that is not live has no descendants of its own — a take the story
|
|
moved past keeps a continuation only by being forked, and that fork is a
|
|
branch this loop asks about anyway — so editing one is always safe.
|
|
"""
|
|
if not node.live or node.depth is None:
|
|
return False
|
|
read = lineage.path_of(db, adventure)
|
|
branches = (
|
|
db.query(models.Branch)
|
|
.filter(models.Branch.adventure_id == adventure.id)
|
|
.all()
|
|
)
|
|
for branch in branches:
|
|
# Uncapped: the question is what this branch's story descends from, not
|
|
# how much of it the reader is currently being shown.
|
|
if not lineage.Path(lineage.entries_of(branch)).contains(node):
|
|
continue
|
|
deepest = (
|
|
db.query(models.Action)
|
|
.filter(
|
|
models.Action.adventure_id == adventure.id,
|
|
models.Action.branch_id == branch.id,
|
|
models.Action.live.is_(True),
|
|
models.Action.depth > node.depth,
|
|
)
|
|
.order_by(models.Action.depth.desc(), models.Action.id.desc())
|
|
.first()
|
|
)
|
|
if deepest is not None and not read.contains(deepest):
|
|
return True
|
|
return False
|
|
|
|
|
|
# ------------------------------------------------------------------ writing
|
|
|
|
def move_to(db: Session, adventure: models.Adventure, depth: int) -> None:
|
|
"""Moves the active head to `depth` and restores the state recorded there.
|
|
|
|
This is the whole of Undo and Redo. Nothing is deleted, nothing is
|
|
recomputed, and the direction of travel does not matter: the node at the
|
|
destination carries the world state it left behind, so arriving from in front
|
|
of it and arriving from behind it restore the same value.
|
|
|
|
A destination with no node — the head resting one step in front of the
|
|
opening — leaves the live state alone, which is `attempts.restore_state`'s
|
|
rule for a missing snapshot and the reason it is not this function's job to
|
|
invent an empty one.
|
|
"""
|
|
adventure.head_depth = depth
|
|
attempts.restore_state(adventure, node_at(db, adventure, depth))
|
|
|
|
|
|
def fork_if_behind_head(db: Session, adventure: models.Adventure) -> bool:
|
|
"""Gives the story a new branch when a write would displace a retained future.
|
|
|
|
Returns whether a branch was created, which is what a caller reports as a
|
|
divergence.
|
|
|
|
Called before every write that continues the story, and it does nothing on
|
|
the ordinary path where the head is already at the tip. That is the property
|
|
worth keeping: a story that is never undone forks exactly as often as it did
|
|
before M3, so the branch table does not fill up with one branch per turn.
|
|
|
|
Undo alone must not fork. Moving the head is not a decision to abandon
|
|
anything — the user may be reading, or about to Redo. Only the first write
|
|
below the head states which continuation they mean, which is
|
|
`STORY-BRANCH-SEMANTICS.md` §8 and §20 and what makes Redo survive an Undo.
|
|
|
|
`tree.branch_at` leaves the departed branch exactly as it is: its nodes stay
|
|
live, at their depths, on their branch. The new branch inherits the story up
|
|
to the head and owns everything written from here, so the displaced future
|
|
remains reachable through the branch it was written on.
|
|
"""
|
|
if not behind_tip(db, adventure):
|
|
return False
|
|
departed = lineage.branch_of(db, adventure)
|
|
at_depth = adventure.head_depth
|
|
tree.branch_at(db, adventure, at_depth)
|
|
if departed is not None:
|
|
mark_superseded(departed, at_depth)
|
|
return True
|
|
|
|
|
|
def mark_superseded(branch: models.Branch, depth: int) -> None:
|
|
"""Records that this branch's story past `depth` was displaced.
|
|
|
|
`DATA-MODEL.md` §5 gives a branch a disposition of active, retained or
|
|
disposable. This is that disposition, stored as the fact that produced it
|
|
rather than as a word: the depth the story left at, and when. A branch with
|
|
no `superseded_at` is active; one with a value has retained history past that
|
|
depth which no active head is reading.
|
|
|
|
Nothing in the application reads these columns to make a decision, and that
|
|
is deliberate. Redo is decided by the lineage, not by a flag, so a stale or
|
|
hand-edited value here cannot make the story wrong. They exist so that the
|
|
cleanup and discarded-history features `STORY-BRANCH-SEMANTICS.md` §28 and
|
|
§29 leave to a later version have something to select on, and so that a
|
|
divergence is observable in a test.
|
|
|
|
The shallowest departure wins. A branch left at depth 9 and later left again
|
|
at depth 4 has retained history from 4 onward, and recording the later, deeper
|
|
value would understate what was displaced.
|
|
"""
|
|
if branch.superseded_depth is None or depth < branch.superseded_depth:
|
|
branch.superseded_depth = depth
|
|
if branch.superseded_at is None:
|
|
branch.superseded_at = models.utcnow()
|