- Added the `enforceSeenLines` option to hashline `PatcherOptions` (defaults `true`); the seen-line guard in `Patcher` now runs only when enabled.
- Added the `edit.enforceSeenLines` coding-agent setting (default off) and wired it through `edit/hashline/execute.ts` into the `Patcher`.
- Stopped `file-snapshot-store` excluding column-clipped (>512-char) lines from a snapshot's seen set, so single-line edits on long lines apply without a full-width re-read.
- Updated `seen-line-guard` tests and the hashline/coding-agent changelogs.
- Added `tui.scrollbackRebuild` configuration with interactive startup/controller wiring to apply `setScrollbackRebuild`.
- Exposed prewalk session state in `SegmentContext` and rendered a dedicated prewalk segment/icon in the status line.
- Added divergence-aware TUI full-paint logic that enables scrollback erase-and-replay rebuilds for non-multiplexer divergence cases.
- Updated rendering and streaming tests to verify rebuild behavior (`3J`) and eliminate stale marker expectations under drift scenarios.
- Replaced 3-way-merge and session-chain replay strategies with a consistent anchor remapping flow for drift recovery.
- Removed legacy reconciliation logic and associated session-replay warning constants.
- Updated recovery flow to mandate anchor consistency and validate against duplicated context.
- Refined test suite to verify anchor mapping mechanics and explicit refusal of ambiguous remappings.
- Introduced strict validation for boundary repairs to prevent accidental code deletion when payload context is insufficient.
- Added `ambiguousBoundaryEchoMessage` to identify when a partial echo is too short to safely replace a range.
- Added `ambiguousCloserSpareMessage` to identify when a spare closer replacement lacks structural evidence (indentation or delimiter balance) for placement.
- Implemented rejection logic in `repairReplacementBoundaries` for ambiguous cases, forcing the user to provide explicit edits instead of guessing.
- Added test cases covering one-sided echo and ambiguous closer sparing to ensure errors trigger on unsafe edits.
- Simplified match logic to rely exclusively on content hash equality.
- Removed strict validation that rejected colliding snapshot tags.
- Updated recovery behavior to resolve collisions to the most-recently recorded snapshot.
- Refactored tests to expect successful preview and patching despite tag ambiguity.
Codex reviewer flagged that the per-reveal cap only limits the line
count, not each line's width. A minified-bundle-style wide line
(megabytes on one row) would be stored verbatim in the RevealedLine
and formatted straight into the thrown edit error — bypassing the
column-truncation read/search already apply to long lines and dumping
that much content into the tool result, TUI, and model context.
assertSeenLines now clips each revealed line at
SEEN_LINE_REVEAL_MAX_COLUMNS (512, matching search's DEFAULT_MAX_COLUMN)
with a trailing ellipsis marker and treats any clip as truncated. The
existing truncated-gated merge keeps the guard closed on clipped
reveals so the model cannot land an edit having only seen the first
512 chars of a wide line, and the message keeps the range-re-read
guidance.
Codex reviewer flagged that when an anchor range exceeds
`SEEN_LINE_REVEAL_CAP`, merging the revealed prefix into `seenLines`
lets a model split a blind over-cap edit into two <=cap-line retries
and slip past the range-re-read gate: attempt 1 reveals+merges lines
100-139, attempt 2 reveals+merges the 140-159 tail, attempt 3 applies
— all without a single range read.
The merge is now gated on `truncated === false`: only a reveal that
covered EVERY unseen anchor line joins `seenLines`. Truncated reveals
keep the range-re-read guidance and the reveal window stays anchored
at the head across retries, so the same over-cap patch keeps rejecting
until the model actually re-reads the range.
Structural-summary reads (default for parseable code >100 lines) mint a
`[path#tag]` that only marks declaration/boundary lines as displayed;
edits anchored inside an elided body then hit `#assertSeenLines` in
`packages/hashline/src/patcher.ts` and reject with "never displayed
(it showed a partial range, a search hit, or a folded summary)". The
existing message pointed at a range re-read, but that made every such
recovery a three-turn round-trip (edit-fail → range read → edit-retry)
and models frequently retried the same edit instead of following the
hint — 5-8 out of 10 edits failed for the reporter.
The rejection now:
- Inlines the actual file content at the unseen anchor lines, from
`matchedSnapshot.text` (which by definition equals the live normalized
content on the no-drift path), up to `SEEN_LINE_REVEAL_CAP` (40) lines.
- Merges the revealed lines into the snapshot's `seenLines` set, so a
straight retry with the same `[path#tag]` header succeeds without a
follow-up read. The content is inside the error the model receives,
which is the proof it has now seen those lines.
- For anchor ranges over the cap, only the revealed prefix is merged;
the message keeps the range-re-read guidance for the remainder so
runaway blind edits don't sneak past.
Fixes#4224
- Persist signed message blocks (`text`, `thinking`, `toolCall`) and encrypted reasoning payloads verbatim during session serialization instead of clearing or truncating them.
- Preserve signature keys instead of replacing them with empty strings when they exceed persistence size limits.
- Exempt official first-party OpenAI and Anthropic API endpoints from the leaked-thinking stream healing wrapper to prevent misfires on legitimate visible text fences.
- Added `byHashExact` to `SnapshotStore` to resolve historical versions only when a tag is unambiguous.
- Prevented recovery and edit-preview paths from incorrectly applying anchors against colliding tags.
- Implemented `InMemorySnapshotStore.byHashExact` returning null when multiple recorded versions share a tag.
- Added comprehensive unit tests validating single-match resolution and multi-collider rejection.
- Accelerates duplicate-line verification from quadratic $O(N^2)$ to linear $O(N \log N)$ by precomputing anchor neighbors in a single sorted pass.
- Optimizes duplicate checks to $O(1)$ by collecting line values into a pre-allocated Set instead of repeatedly searching arrays.
- Prevents silent content corruption by aborting recovery if multiple historical snapshots share the same 16-bit hash tag.
- Validates the optimized duplicate-line shifting behavior and collision rejection logic with new test coverage.
Clarified hashline minus-row errors and model-facing prompt examples so Markdown list rows use the + body-row prefix instead of triggering write fallbacks.
Fixes#4179