Files
oh-my-pi/packages/hashline
Márton Danóczy 7708f372b5 fix(hashline,coding-agent): key snapshot tag on actually-persisted content after ACP bridge writes
Root cause of the reported "edit tool silently reformats the whole
file" corruption: fs/write_text_file has no verbatim guarantee. When
an ACP client (e.g. Zed with format_on_save: on) reformats a buffer
on save, routeWriteThroughBridge reported the pre-write content as
successfully written, and Patcher.commit keyed the returned snapshot
tag on that same pre-write text instead of what actually landed on
disk. The next edit anchored on that tag then resolved hunks against
a baseline the file had already drifted away from, which is what
produced whole-file "corruption" from single-line hunks -- reproduced
live in this session against real Swift/JSON/TypeScript files with
Zed as the ACP client.

- routeWriteThroughBridge reads the file back after the bridge write
  and returns the verified content plus a drift flag (best-effort:
  ACP defines no ordering between the client acking the write and its
  own async format-on-save settling, so this degrades gracefully to
  the old stale-tag-on-next-read failure mode, never to corruption).
- HashlineFilesystem.writeText propagates that verified content in
  view-space (the same space readText returns -- e.g. a notebook's
  editable cell text, not its raw JSON), not storage-space, so tag
  validation on the next edit compares like with like.
- Patcher.commit keys fileHash/header/snapshot on the verified
  post-write content (normalized, so BOM/line-ending restoration never
  produces a false "drift") when it diverges from what was sent, and
  appends a warning naming the drift -- but deliberately leaves the
  returned `after` (and therefore the model-visible diff) scoped to
  the intended hunk. Diffing against the full drifted file would
  balloon the tool response to span every reformatted line (measured
  ~6.8x inflation on a 245-line file with one touched line); the
  warning is the correct O(1) channel for "your editor reformatted
  this," not an O(file-size) diff.
- write.ts keys its own snapshot header on the verified bridge content
  too (no diff-size concern there since write always replaces the
  whole file).

Caught via code review (dispatched against the first pass of this
fix): a naive "just use the verified content everywhere" fix broke
.ipynb editing outright (write-space vs read-space content mismatch,
tag invalid on every notebook edit) and would have inflated every
drifted edit response by ~6.8x. Both are now covered by regression
tests that fail against the pre-fix code and pass against this one.

(cherry picked from commit 35ab80e43be5800b2f48728e4400eb9fd7f7f7d2)
2026-07-29 23:08:38 +02:00
..
2026-07-28 14:10:19 +02:00

@oh-my-pi/hashline

A compact, line-anchored patch language and applier.

Hashline is a diff format designed for LLM-driven file edits. It binds every hunk to a file-content hash so stale anchors are rejected before they corrupt code, and it abstracts over the filesystem so the same patcher works on disk, in memory, over the network, or against any custom backend.

Quick start

import {
	Filesystem,
	InMemoryFilesystem,
	InMemorySnapshotStore,
	Patcher,
	Patch,
} from "@oh-my-pi/hashline";

const fs = new InMemoryFilesystem();
const snapshots = new InMemorySnapshotStore();
const before = `const greeting = "hi";\nexport { greeting };\n`;
await fs.writeText("hello.ts", before);

const tag = snapshots.record("hello.ts", before);
const patcher = new Patcher({ fs, snapshots });
const patch = Patch.parse(String.raw`[hello.ts#${tag}]
SWAP 1.=1:
+const greeting = "hello";`);
const result = await patcher.apply(patch);

console.log(result.sections[0].op); // "update"
console.log(await fs.readText("hello.ts"));

Format

See src/prompt.md for the user-facing description and src/grammar.lark for the formal grammar.

Each file section starts with [PATH#TAG]. The tag is a 4-hex content hash of the full normalized file text recorded by the SnapshotStore, and it is not meaningful outside that store. The patcher protects against stale anchors by resolving the tag, verifying the live file still matches the recorded content hash, and refusing or attempting session-aware recovery on mismatch.

Inside a section:

  • SWAP A.=B: — replace lines A.=B with following +TEXT body rows.
  • SWAP.BLK A: — replace the syntactic block beginning on line A.
  • DEL A.=B / DEL.BLK A — delete concrete lines or a resolved block.
  • INS.PRE A: / INS.POST A: / INS.HEAD: / INS.TAIL: — insert following body rows.
  • INS.BLK.POST A: — insert following body rows after the resolved block's last line.
  • REM — delete the whole file named by the section header.
  • MV DEST — move/rename the section file to DEST (optionally after line edits).
  • +TEXT — literal body row (use + alone for a blank line).

Abstractions

Filesystem

Read and write text by path. The default implementations:

  • InMemoryFilesystem — backed by a Map. Tests, sandboxes.
  • NodeFilesystem — disk-backed via Bun.file/Bun.write. Default for CLIs.

Subclass Filesystem to wire hashline into any storage: VFS, S3, an LSP text-document protocol, a Git tree, anything.

SnapshotStore

Required. Hashline tags are full-file content hashes recorded per path, so Patcher must receive the store that observed them. Recovery replays edits against the cached pre-edit snapshot and 3-way-merges onto current content when the live file diverged.

Patcher

The orchestration class. Reads, normalizes line endings + BOM, applies edits, restores line endings, and writes via the configured Filesystem. Multi-section patches are preflighted up front so a partial batch never lands.