Safe editing and history
Use stale-change protection, version history and conservative undo behavior.
Guides follow the current project source. Check the release notes for your installed version.
Stale-change protection
Before applying prepared text changes, RepoTunnel fingerprints the relevant file state. If another editor changes the file before approval, the old change fails rather than overwriting newer content.
Undo coverage
- Created UTF-8 files when unchanged
- Full writes and targeted patches
- Created directories when safe non-recursive deletion remains possible
- Rename/move when the original path is still free
- Deleted accessible UTF-8 files when restoration is safe
Conservative failures
When RepoTunnel cannot confirm a safe rollback or history finalization, it reports failure/ambiguity and retains recovery evidence instead of claiming success.
A normal edit lifecycle
In AI Review, the model prepares a bounded mutation and RepoTunnel persists a diff/pending action. The human inspects and accepts or rejects it in the desktop UI; the remote MCP client cannot approve its own request.
In AI Auto, a compatible write is applied without an additional local confirmation and is recorded with history and recovery state when possible.
- Read the current file
- Prepare a bounded edit
- Revalidate the live file state before finalization
- Apply or queue according to policy
- Inspect history and verify final content
What Undo does not promise
Text edits have conservative recovery rules. RepoTunnel will not overwrite newer content when an earlier edit is undone. Binary deletion and recursive directory removal may be auditable without having a safe automatic undo point.
Always check the specific history record before assuming a destructive operation can be reversed.