Change part of a file without rewriting it

file_write replaces a file entirely, so a model wanting to change one line
either rewrote the whole thing from memory -- silently dropping everything it
did not happen to recall -- or shelled out to sed. file_edit takes a unified
diff instead, and services/agent/patch.py applies it.

Four behaviours carry that module, and each exists because of how models
actually write patches rather than how the format is specified.

Fuzzy offset, exact content. A hunk header is a hint: models count from a
truncated read or from the file as it was three edits ago and get the numbers
wrong, and get the context lines right. So the hinted position is tried, then
the file is scanned outward for an exact match of the context block. One match
wins; more than one refuses, because guessing between two identical blocks is
the one failure that silently corrupts a file.

Line endings are normalised in and restored out, or every hunk on a CRLF file
fails on context that looks identical in the error message. A blank context
line that lost its leading space is read as blank, because trailing whitespace
is stripped by half the things a model's output passes through. And nothing is
written unless every hunk applies: a half-applied file is worse than a refused
one, and the model cannot tell the difference without reading it again.

It refuses a file this reply has not read, in those words. A patch written from
memory either fails on context -- the good case -- or matches something it did
not mean. AgentContext.read_paths records what was read; it lives there because
runners never see a Generation and a read path is a fact about the machine, and
it is shared with the approved copy because as_approved is dataclasses.replace,
which copies field references. It resets each reply, and that is right rather
than a limitation: tool_calls_json is never replayed, so on the next turn the
model does not have the contents either.

Writes and edits both render a git-style diff in the transcript now, escaped
like everything else there and bounded at write time -- a generated file's diff
can be larger than the file, and it sits on the row forever. That costs
file_write one extra SFTP round trip to read the old contents, on the hottest
agent operation, and it is a conscious trade: it is the difference between
seeing what an agent did and having to go and look. It earns its keep twice,
because that read also counts as having read the file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jaroslav Beneš
2026-08-03 11:05:36 +02:00
parent 374982174f
commit 82a7ef5b58
8 changed files with 970 additions and 9 deletions
+57
View File
@@ -192,3 +192,60 @@ def test_an_unknown_tool_falls_back_to_its_name():
assert tool_labels.label_for({"name": "mcp_thing"}) == "mcp_thing"
assert tool_labels.icon_for({"name": "mcp_thing", "kind": "mcp"}) == "server"
assert tool_labels.icon_for({"name": "whatever"}) == tool_labels.FALLBACK_ICON
# --- Diffs -----------------------------------------------------------------------
def test_a_diff_renders_added_and_removed_lines():
html = _render(
{
"name": "file_edit",
"kind": "agent",
"query": "src/app.py",
"status": "ok",
"results": [],
"diff": "--- a/src/app.py\n+++ b/src/app.py\n@@ -1,2 +1,2 @@\n alpha\n-beta\n+BETA",
}
)
assert 'diff__line--del">-beta</span>' in html
assert 'diff__line--add">+BETA</span>' in html
assert 'diff__line--ctx"> alpha</span>' in html
assert 'diff__line--meta">@@ -1,2 +1,2 @@</span>' in html
def test_a_diff_header_is_not_an_addition():
"""`+++ b/x` at the top of every diff would otherwise render green, and
`--- a/x` red, which reads as the file being replaced by itself."""
html = _render(
{
"name": "file_edit",
"results": [],
"diff": "--- a/x.py\n+++ b/x.py\n@@ -1 +1 @@\n-a\n+b",
}
)
assert 'diff__line--meta">--- a/x.py</span>' in html
assert 'diff__line--meta">+++ b/x.py</span>' in html
def test_a_removed_line_of_dashes_is_still_a_removal():
"""A removed line whose own text begins with `--` produces exactly three
dashes, which is why the header test is against the a/ and b/ prefixes."""
html = _render({"name": "file_edit", "results": [], "diff": "@@ -1 +1 @@\n--- a dashed line"})
assert 'diff__line--del">--- a dashed line</span>' in html
def test_a_diff_line_is_escaped():
"""Hard rule 6. It is a file off somebody else's machine."""
html = _render(
{
"name": "file_edit",
"results": [],
"diff": "@@ -1 +1 @@\n+<script>alert(1)</script>",
}
)
assert "<script>" not in html
assert "&lt;script&gt;" in html
def test_an_event_with_no_diff_renders_none():
html = _render({"name": "file_read", "results": [], "text": "hello"})
assert "diff__line" not in html