Change part of a file without rewriting it
file_write replaces a file entirely, so a model wanting to change one line either rewrote the whole thing from memory -- silently dropping everything it did not happen to recall -- or shelled out to sed. file_edit takes a unified diff instead, and services/agent/patch.py applies it. Four behaviours carry that module, and each exists because of how models actually write patches rather than how the format is specified. Fuzzy offset, exact content. A hunk header is a hint: models count from a truncated read or from the file as it was three edits ago and get the numbers wrong, and get the context lines right. So the hinted position is tried, then the file is scanned outward for an exact match of the context block. One match wins; more than one refuses, because guessing between two identical blocks is the one failure that silently corrupts a file. Line endings are normalised in and restored out, or every hunk on a CRLF file fails on context that looks identical in the error message. A blank context line that lost its leading space is read as blank, because trailing whitespace is stripped by half the things a model's output passes through. And nothing is written unless every hunk applies: a half-applied file is worse than a refused one, and the model cannot tell the difference without reading it again. It refuses a file this reply has not read, in those words. A patch written from memory either fails on context -- the good case -- or matches something it did not mean. AgentContext.read_paths records what was read; it lives there because runners never see a Generation and a read path is a fact about the machine, and it is shared with the approved copy because as_approved is dataclasses.replace, which copies field references. It resets each reply, and that is right rather than a limitation: tool_calls_json is never replayed, so on the next turn the model does not have the contents either. Writes and edits both render a git-style diff in the transcript now, escaped like everything else there and bounded at write time -- a generated file's diff can be larger than the file, and it sits on the row forever. That costs file_write one extra SFTP round trip to read the old contents, on the hottest agent operation, and it is a conscious trade: it is the difference between seeing what an agent did and having to go and look. It earns its keep twice, because that read also counts as having read the file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -58,6 +58,26 @@ class AgentContext:
|
||||
# this they would refuse the very thing that was approved -- the mode says
|
||||
# "ask", and asking is exactly what happened.
|
||||
approved: bool = False
|
||||
# Absolute paths this reply has read. `file_edit` refuses a file that is not
|
||||
# in here, because a patch written from memory against a file the model has
|
||||
# not looked at is how a rewrite silently loses somebody's work.
|
||||
#
|
||||
# Here rather than on `Generation` for two reasons. Runners never see a
|
||||
# Generation -- they get a `ToolContext`, which is a session-free snapshot
|
||||
# precisely so nothing in a tool holds live state -- and a read path is a
|
||||
# fact about the machine, which is what this class is.
|
||||
#
|
||||
# It is **shared with the approved copy**: `as_approved` is
|
||||
# `dataclasses.replace`, which copies field references, so a path read
|
||||
# through an approved call is visible here. That is wanted and is not
|
||||
# obvious, so there is a test for it.
|
||||
#
|
||||
# It resets each reply, and that is correct rather than a limitation.
|
||||
# `Message.tool_calls_json` is deliberately never replayed as context, so on
|
||||
# the next turn the model does not have the file's contents either --
|
||||
# requiring a re-read in the reply that edits is asking for something it
|
||||
# needs anyway.
|
||||
read_paths: set[str] = field(default_factory=set)
|
||||
|
||||
def executor(self) -> Executor:
|
||||
return ssh_service.SshExecutor(self.spec, self.project_dir)
|
||||
|
||||
Reference in New Issue
Block a user