01 / 08
A rule enforced in one place. Not the next one.
Found before a line of code was written. One feature, two screens and a button.
npx halfcycle Some documents can never be overwritten. That rule lived in the save path. Nobody copied it into the new restore path, so restore could quietly overwrite a document the product promises never to touch.
Would a code review have caught it?
No. Every test of the new code passes. Somebody has to notice a rule that is not there.
The feature was small: let somebody restore an earlier version of a document. The system already kept a copy of every version before overwriting it, and it already had a way to write a new body to a document. So the work came down to a list, a restore action and a button. No database change.
Some documents in this product are archival. They were imported from somewhere else, and the product promises it will never edit them. That promise was enforced on the save route, the endpoint people normally write through, rather than in the queue underneath it. The new restore endpoint wrote through the same queue and never repeated the rule.
Shipped, an automated process could have overwritten material the system defines as frozen. Quietly, with no error, in a product whose whole promise is that what you put in it is safe.
Every test written for the new route would have passed, because a test proves what the code does, not what it forgot to do. A reviewer reading the change would have had to notice something that was not in it.
It was found by somebody who had not written the design reading the code the design rested on. That is slower than reading a diff, and on this feature it is where nearly all of the value came from.
Read the other seven, or the same argument in general terms: why an agent reviewing its own work is not enough.