• v0.24.0 4a72738211

    code-index v0.24.0
    Some checks failed
    CI / cargo fmt (push) Successful in 47s
    CI / OSS corpus tier-3 scale (weekly) (push) Has been skipped
    CI / Grammar rebuild from source (weekly) (push) Has been skipped
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 4m3s
    CI / cargo doc (intra-doc links) (push) Successful in 4m24s
    CI / cargo clippy (push) Successful in 5m11s
    CI / cargo check (MSRV 1.98) (push) Successful in 5m20s
    CI / cargo check (windows-gnu) (push) Successful in 5m46s
    CI / cargo deny (push) Successful in 5m57s
    CI / OSS corpus (tier 1) (push) Successful in 15m47s
    CI / cargo test (push) Successful in 16m55s
    CI / cargo test (daemon transport) (push) Successful in 5m20s
    CI / Plugin path cost + pool throughput (weekly) (push) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 35m5s
    Release Build / Generate Version (push) Successful in 26s
    Release Build / Required CI green (push) Successful in 47s
    Release Build / Build linux-x86_64-musl (push) Failing after 19s
    Release Build / Build linux-aarch64 (push) Successful in 11m18s
    Release Build / Build windows-x86_64 (push) Successful in 12m2s
    Release Build / Build linux-x86_64 (push) Successful in 14m7s
    Release Build / Pack the XAML reference package (push) Successful in 51s
    Release Build / Create Forgejo Release (push) Successful in 2m17s
    Stable

    buildagent released this 2026-09-02 09:33:19 +02:00 | 502 commits to master since this release

    code-index v0.24.0

    Build: v0.24.0+538

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (sandboxed worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Epic #75's runtime plugin architecture, phase 4 (#80), plus the review
    round that followed it and the fixes that round demanded.

    The customer-facing change is that the XAML plugin can now be
    obtained: the reference package is packed in CI by the shipped binary
    and published beside the archives with its digest. No release has ever
    carried one.

    Security, all of it found by asking what the shipped binary actually
    contains: eighteen debug_assert!s guarded invariants that do not
    exist under --release, and two of them mattered — the binary
    installed a seccomp filter that ALLOWED socket, and it minted
    builtin language ids that reach grant_all. derived_name is now an
    authority a project grants rather than one every package holds, with a
    detection bit so a fabricated edge can be enumerated after the fact.
    Three package-path guards became refusals.

    Honesty: plugin rollback refuses instead of exiting zero on a
    rollback it did not perform; context_pack's with_source is
    measured rather than derived behind an assertion release deletes;
    refs_resolved reports the rows the resolver actually changed.

    Gates the round added because it needed them: a rustdoc gate (backlog
    131 -> 0, five genuinely broken citations inside it), a README gate
    that caught this very version bump, a fork lock covering whole test
    targets, and three cost bounds on the plugin path — which nothing
    could see before, because the corpus ratchet counts SQLite opcodes and
    the corpus installs no packages.

    Measured, since the direction rests on it: a language plugin's wire
    cost is additive at ~3.5-4% of a real file, and a plugin fleet runs at
    0.97-1.09x of builtins at machine width.

    Verified: fmt, clippy (host + windows-gnu), rustdoc at zero warnings,
    cargo check --locked, MSRV 1.98, 2448 tests, daemon transport leg,
    precision_gate 7/7 phantom_count 0, release_gate, corpus ratchet with
    baseline.json unmoved at 534084b856c22566c48e386bc41ed67e and never
    blessed.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.24.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) not published for this release
    Linux ARM64 code-index-v0.24.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.24.0-windows-x86_64.zip

    No static (musl) archive was published for v0.24.0. That leg is best-effort: it either failed to build or its code-index-plugin-host failed the release plugin smoke/timeout/trap test, and an archive whose plugin host has not been proved on its own target is not one this project ships. Use the glibc archive.

    XAML plugin package

    de.h-dv.xaml-0.1.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant:

    code-index plugin install de.h-dv.xaml-0.1.0.cip --sha256 sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd
    code-index plugin check   sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd
    code-index plugin enable  sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd \n    --capabilities bridge_source \n    --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.1.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed. .dataset and other markup remain text-only (searchable, no symbols).

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads