Guard add_commit MCP partial edits against truncated large files

What does this MR do and why?

Hardens the add_commit MCP server tool's partial-edit feature (old_str/new_str) against silent data loss on files larger than 10 MB.

Related to #622860 (closed).

The bug

Partial edits read the target file's full content via rawTextBlob, which is capped at Gitlab::Git::Blob::MAX_DATA_DISPLAY_SIZE (10 MB). For a text file larger than 10 MB, rawTextBlob returns silently truncated content — no error, no nil. AddCommitService would then:

  1. Match old_str within the truncated content.
  2. Perform the substitution.
  3. Submit the truncated 10 MB blob as the file's full content to commitCreate.

This silently deletes everything past the first 10 MB of the file while reporting a successful commit.

The fix

AddCommitService#read_blob_contents now rejects any partial-edit target whose blob size exceeds MAX_DATA_DISPLAY_SIZE, raising a PartialEditError instructing the caller to submit full file content instead.

size reflects the full blob size reported by Gitaly, not the (possibly truncated) loaded byte count, so it reliably detects truncation regardless of old_str/new_str content. The GraphQL query already selects size, so no query change was required.

Also corrected the user documentation, which incorrectly stated partial edits were "subject to the 20 MB GraphQL blob request limit." It now states partial edits are not supported for files over 10 MB.

Scope of changes

  • app/services/mcp/tools/repositories/add_commit_service.rb — truncation guard in read_blob_contents
  • doc/user/model_context_protocol/mcp_server_tools.md — corrected size limit for partial edits
  • spec/services/mcp/tools/repositories/add_commit_service_spec.rb — spec covering oversized-file rejection

Testing

spec/services/mcp/tools/repositories/add_commit_service_spec.rb passes (22 examples).

🤖 Generated with Claude Code

Edited by Jessie Young

Merge request reports

Loading
Loading