cb1e059a98
The parallel tool-batch planner treated search_files as unconditionally parallel-safe (_PARALLEL_SAFE_TOOLS) with no path reservation, so a batch of patch(path=X) + search_files(path=dir(X)) landed in one concurrent segment and the search could observe pre-mutation file content — a same-block write->read stale-read race. Fix the class, not the site: path-scoped reservations now carry a reader/writer role. - search_files joins _PATH_SCOPED_TOOLS as a READER, reserving its search root (default '.', matching the tool's default) instead of bypassing path checks entirely. - Overlap only conflicts when a WRITER is on either side: a write into a searched/read subtree splits segments (ordered behind the write), while reader<->reader overlap — previously split needlessly — now stays parallel (concurrent reads commute). - write_file/patch keep their existing writer barrier semantics. Prior art surveyed for this design: Codex CLI's RwLock read/write barrier (readers share, writers exclusive), Claude Code's isConcurrencySafe partitioning, and gemini-cli's contiguous parallelizable batching — all converge on reader-shared/writer- exclusive with contiguous-order preservation, which this planner already had for read_file/write_file/patch; this closes the search_files gap and adds the missing reader/reader concession. Verified by sabotage run (tests fail against the old planner) and an E2E script exercising the real planner + real file I/O.