Guard add_commit MCP partial edits against truncated large files
What does this MR do and why?
Hardens the add_commit MCP server tool's partial-edit feature (old_str/new_str) against silent data loss on files larger than 10 MB.
Related to #622860 (closed).
The bug
Partial edits read the target file's full content via rawTextBlob, which is capped at Gitlab::Git::Blob::MAX_DATA_DISPLAY_SIZE (10 MB). For a text file larger than 10 MB, rawTextBlob returns silently truncated content — no error, no nil. AddCommitService would then:
- Match
old_strwithin the truncated content. - Perform the substitution.
- Submit the truncated 10 MB blob as the file's full
contenttocommitCreate.
This silently deletes everything past the first 10 MB of the file while reporting a successful commit.
The fix
AddCommitService#read_blob_contents now rejects any partial-edit target whose blob size exceeds MAX_DATA_DISPLAY_SIZE, raising a PartialEditError instructing the caller to submit full file content instead.
size reflects the full blob size reported by Gitaly, not the (possibly truncated) loaded byte count, so it reliably detects truncation regardless of old_str/new_str content. The GraphQL query already selects size, so no query change was required.
Also corrected the user documentation, which incorrectly stated partial edits were "subject to the 20 MB GraphQL blob request limit." It now states partial edits are not supported for files over 10 MB.
Scope of changes
app/services/mcp/tools/repositories/add_commit_service.rb— truncation guard inread_blob_contentsdoc/user/model_context_protocol/mcp_server_tools.md— corrected size limit for partial editsspec/services/mcp/tools/repositories/add_commit_service_spec.rb— spec covering oversized-file rejection
Testing
spec/services/mcp/tools/repositories/add_commit_service_spec.rb passes (22 examples).