Root cause of the reported "edit tool silently reformats the whole file" corruption: fs/write_text_file has no verbatim guarantee. When an ACP client (e.g. Zed with format_on_save: on) reformats a buffer on save, routeWriteThroughBridge reported the pre-write content as successfully written, and Patcher.commit keyed the returned snapshot tag on that same pre-write text instead of what actually landed on disk. The next edit anchored on that tag then resolved hunks against a baseline the file had already drifted away from, which is what produced whole-file "corruption" from single-line hunks -- reproduced live in this session against real Swift/JSON/TypeScript files with Zed as the ACP client. - routeWriteThroughBridge reads the file back after the bridge write and returns the verified content plus a drift flag (best-effort: ACP defines no ordering between the client acking the write and its own async format-on-save settling, so this degrades gracefully to the old stale-tag-on-next-read failure mode, never to corruption). - HashlineFilesystem.writeText propagates that verified content in view-space (the same space readText returns -- e.g. a notebook's editable cell text, not its raw JSON), not storage-space, so tag validation on the next edit compares like with like. - Patcher.commit keys fileHash/header/snapshot on the verified post-write content (normalized, so BOM/line-ending restoration never produces a false "drift") when it diverges from what was sent, and appends a warning naming the drift -- but deliberately leaves the returned `after` (and therefore the model-visible diff) scoped to the intended hunk. Diffing against the full drifted file would balloon the tool response to span every reformatted line (measured ~6.8x inflation on a 245-line file with one touched line); the warning is the correct O(1) channel for "your editor reformatted this," not an O(file-size) diff. - write.ts keys its own snapshot header on the verified bridge content too (no diff-size concern there since write always replaces the whole file). Caught via code review (dispatched against the first pass of this fix): a naive "just use the verified content everywhere" fix broke .ipynb editing outright (write-space vs read-space content mismatch, tag invalid on every notebook edit) and would have inflated every drifted edit response by ~6.8x. Both are now covered by regression tests that fail against the pre-fix code and pass against this one. (cherry picked from commit 35ab80e43be5800b2f48728e4400eb9fd7f7f7d2)
@oh-my-pi/hashline
A compact, line-anchored patch language and applier.
Hashline is a diff format designed for LLM-driven file edits. It binds every hunk to a file-content hash so stale anchors are rejected before they corrupt code, and it abstracts over the filesystem so the same patcher works on disk, in memory, over the network, or against any custom backend.
Quick start
import {
Filesystem,
InMemoryFilesystem,
InMemorySnapshotStore,
Patcher,
Patch,
} from "@oh-my-pi/hashline";
const fs = new InMemoryFilesystem();
const snapshots = new InMemorySnapshotStore();
const before = `const greeting = "hi";\nexport { greeting };\n`;
await fs.writeText("hello.ts", before);
const tag = snapshots.record("hello.ts", before);
const patcher = new Patcher({ fs, snapshots });
const patch = Patch.parse(String.raw`[hello.ts#${tag}]
SWAP 1.=1:
+const greeting = "hello";`);
const result = await patcher.apply(patch);
console.log(result.sections[0].op); // "update"
console.log(await fs.readText("hello.ts"));
Format
See src/prompt.md for the user-facing description and
src/grammar.lark for the formal grammar.
Each file section starts with [PATH#TAG]. The tag is a 4-hex
content hash of the full normalized file text recorded by the
SnapshotStore, and it is not meaningful outside that store. The patcher
protects against stale anchors by resolving the tag, verifying the live file
still matches the recorded content hash, and refusing or attempting
session-aware recovery on mismatch.
Inside a section:
SWAP A.=B:— replace lines A.=B with following+TEXTbody rows.SWAP.BLK A:— replace the syntactic block beginning on line A.DEL A.=B/DEL.BLK A— delete concrete lines or a resolved block.INS.PRE A:/INS.POST A:/INS.HEAD:/INS.TAIL:— insert following body rows.INS.BLK.POST A:— insert following body rows after the resolved block's last line.REM— delete the whole file named by the section header.MV DEST— move/rename the section file toDEST(optionally after line edits).+TEXT— literal body row (use+alone for a blank line).
Abstractions
Filesystem
Read and write text by path. The default implementations:
InMemoryFilesystem— backed by aMap. Tests, sandboxes.NodeFilesystem— disk-backed viaBun.file/Bun.write. Default for CLIs.
Subclass Filesystem to wire hashline into any storage: VFS, S3, an LSP
text-document protocol, a Git tree, anything.
SnapshotStore
Required. Hashline tags are full-file content hashes recorded per path, so
Patcher must receive the store that observed them. Recovery replays edits
against the cached pre-edit snapshot and 3-way-merges onto current content
when the live file diverged.
Patcher
The orchestration class. Reads, normalizes line endings + BOM, applies edits,
restores line endings, and writes via the configured Filesystem. Multi-section
patches are preflighted up front so a partial batch never lands.