Skip to content
5 changes: 4 additions & 1 deletion docs/remote-bridge/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,10 @@ backslashes, symlink escapes, unexpected fields, and host roots are rejected.
Workspace mutation remains disabled unless the operator starts the worker with
`--allow-workspace-writes` (or
`LIBRECHAT_CODE_ALLOW_WORKSPACE_WRITES=true`). That adds bounded `write_file`
and exact-match `edit_file` operations. Writes are limited to 1 MiB of UTF-8
and `edit_file` operations. `edit_file` matches exactly by default; the
negotiated `tolerant_match` and `replace_all` edit features add
whitespace-tolerant matching and multi-location replacement (see
`packages/code/README.md`). Writes are limited to 1 MiB of UTF-8
text, require an existing in-workspace parent directory, reject symlinks, and
commit atomically. The worker capability is an enforcement boundary; LibreChat
should still route every mutation through its configurable tool-approval hooks.
Expand Down
46 changes: 44 additions & 2 deletions packages/code/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -590,6 +590,46 @@ installed as one atomic mutation. Code API dispatches the batch form only after
the worker and server negotiate `batch` in `editFileModes`.
Revision-fenced edits likewise require the negotiated
`expected_base_sha256` entry in `editFileFeatures`.

Edits apply in order, each to the text the earlier ones produced. When any edit
fails, the worker still checks the rest and rejects the whole batch with one
`EDIT_CONFLICT` whose message lists every failing edit by position. A
missing edit names the nearest candidate line and flags elided (`...`) or
line-numbered `oldText`, a whitespace-only difference, or CRLF line endings.
An ambiguous edit gives its match count and line numbers. Overlapping
occurrences count as separate locations. Detailed source-line excerpts require
`read_file` or `preview_edit` on the same workspace; edit-only workers return a
generic failure and its error code without revealing file contents. A preview
itself exposes the resulting file text, so it is read-capable.

Two optional features change matching, each negotiated in `editFileFeatures`
before Code API dispatches it:

- `tolerant_match`: a request-level `matching: 'tolerant'` falls back from an
exact match to, in order, `line-trimmed` (ignores trailing whitespace and
CRLF), `indentation-flexible` (a uniformly shifted block, with `newText`
moved to the file's indentation) and `whitespace-normalized` (any whitespace
run between complete whitespace-delimited tokens, never a prefix or suffix
of another token). Without `replaceAll`, a match must still be unique;
replacements use the matched line's ending even in mixed-ending files. The
whitespace-normalized tier peels the complete shared newline-and-indentation
wrapper from `newText` even when CRLF/LF or nearby spaces differ, without
removing intentional extra line breaks or duplicating the source line ending.
Boundary whitespace claimed by `oldText`, including the number of line breaks,
must exist beside the matched tokens in the source; an attempt to remove it
with a token-only fallback fails rather than silently preserving it. Exact and
line-window matches can still replace terminators.
Excessively repetitive indentation candidates fail closed with a request
for more context rather than scanning every long window. Dense files reuse a
compact newline index for matching and diagnostics; overlapping exact matches
are counted without restarting a scan at each offset.
- `replace_all`: a batch edit's `replaceAll: true` replaces every
non-overlapping match instead of requiring exactly one, and still fails when
nothing matches.

A request that sets `matching` or any `replaceAll` receives `matches`, one
`{ strategy, occurrences }` entry per edit. Requests that set neither receive
exactly the legacy result.
Only IDs, names, protocol version, supported operations, and negotiated write
modes appear in worker capabilities; absolute host paths remain local to the
worker process.
Expand Down Expand Up @@ -655,8 +695,10 @@ non-regular files, and commit through an owner-only temporary file followed by
an atomic rename. The worker syncs the containing directory and verifies that
the installed inode still contains the requested bytes before reporting
success. Edits replace text only when the requested old text occurs exactly
once and reject if the file changes before commit. These operations do not
create directories or execute commands.
once (unless negotiated `replaceAll` selects every non-overlapping match) and
reject if the file changes before commit. Intermediate replacements are bounded
before construction, including `replaceAll`; these operations do not create
directories or execute commands.

Register one directory already present on the worker machine with the
worker-directory option:
Expand Down
Loading
Loading