Wire native undo into menus, toolbar, and command validation

The command surface was already almost entirely platform machinery —
this card proves it and pins it. Headless probes established that
NSWindow.validateMenuItem answers enablement AND rewrites the row title
from the delegate-supplied manager, so 'Undo Move 3 Cards' flows step
phrase to Edit menu with no code of ours; under the lock the rows dim
and keep their names, the correct reading of the-stack-survives. The
toolbar twins validate through validateUserInterfaceItem, which never
touches labels — 03's static-label exception proven rather than
asserted — and their specs' enablement abstention is pinned so nobody
later adds a second, disagreeing answer. The one link a headless run
cannot close is the nil-target key-window resolution itself: standard
responder-chain behavior with none of our code in it, left as the
manual check. Base-edition 'disabled without undo' scaffolding is
reworded away — every base board has undo now. New suites cover the
trash's two doors (delete-then-undo byte-identical to Put Back's
effect), position-preserving restore of a middle card, and the
capstone: five gestures forward, five presses back to the origin
board, five forward again, the menu phrase asserted after every press.

Claude-Session: https://claude.ai/code/session_01SR4XGjmBE16ZUYWpfFHXwY
This commit is contained in:
2026-07-28 15:29:45 -04:00
parent 50669489cb
commit 96c4014fef
8 changed files with 531 additions and 19 deletions
+4 -3
View File
@@ -143,9 +143,10 @@ public struct HistoryStep {
/// "One stack per board, owned by the board session. Not per-window: every window over a board
/// (board window, its card windows) shares the store and shares the stack" (13-native-undo.md
/// Rules). `AppModel.BoardSession` is where that ownership lives, and the composition root binds
/// which implementation it gets: base binds `NativeHistoryProvider` (an `NSUndoManager` stack over
/// inverse `WriteOperation`s), Pro binds the git provider in pro-m1 (undo as forward restore commits
/// over HEAD's first-parent ancestry 06-history-undo.md), Teams inherits Pro's.
/// which implementation it gets: base binds `NativeHistoryProvider` (two step stacks over the
/// inverses registered at the Writer boundary), Pro binds the git provider in pro-m1 (undo as
/// forward restore commits over HEAD's first-parent ancestry 06-history-undo.md), Teams inherits
/// Pro's.
///
/// ### What this protocol deliberately does not say
///