fix: address codex review round 2

- edit tool: add the read-before-edit requirement to the model-facing prompt
  (with the just-created/edited-this-session exception), matching write's
  guidance so the model doesn't only learn it via a failed FS_NOT_OBSERVED call.
- fsspec-style-fs-seam RFC: correct the acceptance criteria that still claimed
  a ctx.fileContext service and a fileContext inject — the landed design is the
  fs/* event gate with the tool injecting fs.
- filesystem-tool-schemas RFC: replace the stale "prior full file state"
  edit requirement with version-freshness wording (any windowed read authorizes
  a fresh edit; no partial-view flag).
This commit is contained in:
Dudu-0223
2026-06-28 14:15:04 +08:00
parent f9f475cbea
commit 1059166cb1
3 changed files with 4 additions and 4 deletions
@@ -62,7 +62,7 @@ Arguments:
- `new_string: string` — required. Literal replacement text; an empty string deletes the match.
- `replace_all?: boolean` — optional. Defaults to false. When false, `old_string` must identify exactly one match.
`edit` requires prior full file state derived from a previous read in the same execution context. `ctx.fs` derives the file-state owner and uses the recorded version as the stale guard.
`edit` requires a prior observation of the file in the same execution context (any windowed read counts — authorization is version freshness, not a full-view requirement), or a prior write/edit by that context. The `dsh-file-context` policy plugin derives the owner and supplies the recorded version as the stale guard; the provider's mutation lock enforces it.
The first pass rejects Codex-style patch grammars and multi-mode edit APIs. It uses one strict literal replacement mode so the model-facing contract stays simple and the backend can own exact-match, duplicate-match, line-ending, and stale-version semantics.