# Hash-edit guide
Parse anchored patches, prepare against retained snapshots, then commit through tool filesystem policy.
## Where to look
| Envelope/syntax/tokens/model | `input.rs`, `parser.rs`, `tokenizer.rs`, `model.rs` |
| Line/block operations | `apply.rs`, `block.rs`, `normalize.rs` |
| Stale-tag recovery/snapshots | `recovery.rs`, `snapshots.rs` |
| Preparation/locking/commit/evidence | `tool.rs` |
| Diagnostics/success/diff bounds | `format.rs`, `tool/output.rs` |
## Local contracts
- Address every operation against original snapshot lines, not positions shifted by earlier operations; preserve overlap/range/block validation.
- Resolve/reject duplicate targets, acquire mutation/cross-process locks and prepare all sections before any commit. Preparation failure cannot write earlier sections.
- Multi-file commit is not atomic: later failure can leave earlier files written. Preserve per-file status, changed paths and partial-commit metadata even when overall result fails.
- Keep `committed_but_undurable` distinct from success and `destination_written_source_retained` for undurable move destinations. Move removal/rollback failures need truthful changed-path reporting.
- Stale recovery uses retained snapshots and checked remapping, never silent fuzzy matching. Keep bounded snapshots/diagnostics and explicit recovery warnings/metadata.
- Restore BOM/line-ending shape through `tool.rs`; normalized snapshot text is not persisted directly. Preserve parent filesystem policy on write/move/remove.
- Syntax/recovery-marker changes require matching parent schemas and provider guidance.