BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Hash-anchored edits turn a lost race into an error, and that contract outranks the tool count
Oh-My-Pi makes a write conditional on the target lines still hashing the same, so the loser of a race gets an error instead of a wrecked file. The guarantee is paid for in retries.
The Engineer · Build desk
What happened
- Oh-My-Pi, a fork of Mario Zechner's Pi, sends a hash of the targeted lines with each edit and applies the write only if those lines still match.
- A mismatch returns an error carrying the current file state, and the agent re-reads and retries rather than overwriting.
- The tool harness serializes writes from multiple agents or subagents against the same file and rejects any edit whose anchor has gone stale.
- Subagent recursion is capped at a default depth of 3, with a per-subagent token budget that ends in a kill and truncated output on overrun.
Why it matters
- capability Letting two writers work one file stops being a gamble, because the loser of the race receives something it can act on instead of a file it has already ruined.
- cost The bill moves off the human who debugs a clobbered file and onto whoever funds inference, one re-read and retry at a time.
- constraint The guarantee reaches exactly as far as the harness does, so throughput now depends on how narrowly the agent anchors and how often something rewrites a file wholesale.
- precedent A conditional write is a claim a buyer can test in an afternoon, which makes long operation counts a weaker argument than they were last quarter.
Compare-and-swap is the shape of this, with a range of lines standing in for the register, and the interesting part is where the check sits. It sits in the tool harness, which is also the component that orders writes [7], so the harness is the only thing in the system that can tell a losing writer why it lost. That placement has a price, and the write-up quotes only half of it: one hash comparison per edit, which it fairly calls negligible against the tokens burned re-reading a whole file after a bad write [2]. Those are two different ledgers. The comparison is charged on every edit that lands; the re-read is charged on every edit that is rejected, and rejection frequency depends on how wide the anchored range is and how many writers are aimed at the same file. The account reports no measured rate for that [15], which is the figure I would want in hand before pointing several subagents at one module.
A concrete anchor-killer sits in the same feature list. Among the 14 LSP operations exposed as agent tools is format [9], and a formatter rewrites lines nobody asked it to touch, so one format call can invalidate every outstanding anchor in that file. Nothing is corrupted; each pending edit simply fails and is retried against current bytes [6]. The behaviour being replaced, per the dev.to account, was a replace_file call that overwrote whatever had arrived since the agent's last read [14], with the failure case being two agents reading version N and the second write erasing the first [8]. Swapping silence for a retry loop is the right trade. It is still a trade, and it is denominated in tokens.
Add up the advertised surfaces and you get 73 agent-callable operations: 31 built-in tools, 14 LSP, 28 DAP [16]. Around them sit 60-plus provider integrations [9] and roughly 80k lines of Rust under a Bun runtime wrapping the TypeScript orchestration, with a TUI rather than Electron [10]. Those numbers travel well, as does the 26,497 stars the post attaches to the project's lineage [3], and none of them tell you whether a second writer can be trusted. The conditional write does. So does the LSP running out of process, where a crash returns a tool error and the agent can fall back to grep [13], and the default depth limit of 3 plus a per-subagent token budget that gets a runaway killed and truncated [11]. That is the concurrency contract. The rest of the sheet is inventory.
What to watch
- Whether anyone publishes a measured false-conflict rate under real subagent fan-out, which is the number that decides if this holds past two writers.
- Whether the harness special-cases wholesale rewrites such as an LSP format call, which invalidates every outstanding anchor in a file at once.
- Whether upstream Pi or other terminal agents still shipping whole-file replace adopt a conditional write of their own.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence26
- Adoption14
- Hype gap+34
- Incentives
- Insufficient
- Confidence31
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Oh-My-Pi is a fork of Pi by Mario Zechner.
- [2]
The stated cost is one extra hash comparison per edit, which the source calls negligible compared with the token budget of re-reading an entire file after a bad write.
- [3]
The post puts the project's star count at 26,497.
- [4]
Oh-My-Pi uses hash-anchored edits: the agent specifies a hash of the exact lines it wants to replace, and the edit only applies if those lines still match; if the file changed underneath, the edit fails cleanly instead of silently corrupting state.
- [5]
The sequence: the agent reads a file and hashes the lines it wants to modify, sends an edit request with the hash, line range and replacement text; the harness re-reads the file, hashes current content at that range and compares; matching hashes apply the edit, a mismatch returns an error with the current state.
- [6]
On a hash mismatch the agent sees the error, re-reads the file, and retries with updated context.
- [7]
Hash anchoring also enables concurrent edits: multiple agents, or one agent with subagents, can propose edits to different parts of the same file, and the tool harness serializes the writes and rejects any edit whose anchor hash is stale.
- [8]
The race condition being avoided is two agents both reading version N, both writing version N+1, with the second write silently clobbering the first.
- [9]
Oh-My-Pi ships 60+ provider integrations (Ollama, OpenAI, Anthropic, Gemini, DeepSeek), 31 built-in tools, 14 LSP operations and 28 DAP operations; the LSP operations exposed as agent tools include go-to-definition, find-references, hover, diagnostics, code actions, rename and format.
- [10]
The core is about 80k lines of Rust with a Bun runtime wrapping TypeScript orchestration; the architecture is terminal-native, with a TUI and no Electron or web UI.
- [11]
Subagents can spawn their own subagents; the harness enforces a depth limit, default 3, and each subagent gets a token budget, with the harness killing it and returning truncated output if the budget is exceeded.
- [12]
Inline execution covers file reads, LSP queries, shell commands under 5 seconds and Python REPL expressions; subagents are used for browser automation, long-running scripts and tasks needing their own context window.
- [13]
The LSP server runs in a separate process and the harness talks to it over JSON-RPC; if the LSP server crashes, the tool returns an error and the agent can retry or fall back to grep-based search.
- [14]
Traditional agents send a replace_file tool call with new content, so if the file changed between the agent's last read and the write, the agent overwrites everything.
- [15]
The account states the per-edit cost as one hash comparison but reports no measured rate of stale-anchor failures or retries.
- [16]
The listed operation counts sum to 73 agent-callable operations.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.