• v0.26.0 e962b34b81

    code-index v0.26.0
    All checks were successful
    CI / cargo fmt (push) Successful in 46s
    CI / OSS corpus tier-3 scale (weekly) (push) Has been skipped
    CI / Grammar rebuild from source (weekly) (push) Has been skipped
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 4m21s
    CI / cargo doc (intra-doc links) (push) Successful in 4m26s
    CI / cargo deny (push) Successful in 5m26s
    CI / cargo check (MSRV 1.98) (push) Successful in 5m35s
    CI / cargo clippy (push) Successful in 5m51s
    CI / cargo check (windows-gnu) (push) Successful in 5m54s
    CI / OSS corpus (tier 1) (push) Successful in 15m50s
    CI / cargo test (push) Successful in 18m22s
    CI / cargo test (daemon transport) (push) Successful in 6m44s
    CI / Plugin path cost + pool throughput (weekly) (push) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 38m3s
    Release Build / Generate Version (push) Successful in 19s
    Release Build / Required CI green (push) Successful in 58s
    Release Build / Build linux-aarch64 (push) Successful in 13m2s
    Release Build / Build windows-x86_64 (push) Successful in 13m48s
    Release Build / Build linux-x86_64 (push) Successful in 15m59s
    Release Build / Build linux-x86_64-musl (push) Successful in 16m26s
    Release Build / Pack the XAML reference package (push) Successful in 50s
    Release Build / Create Forgejo Release (push) Successful in 2m56s
    Stable

    buildagent released this 2026-09-04 08:43:11 +02:00 | 481 commits to master since this release

    code-index v0.26.0

    Build: v0.26.0+571

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (sandboxed worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Activation on demand

    A project holds .xaml files. You installed and enabled that package
    for a DIFFERENT project last week. Until now this one handed you
    text-only rows and said nothing about it.

    code-index now detects that case and tells you: a package in your store
    whose manifest claims an extension this project actually holds files
    for, and whose digest this project has not approved. The census is the
    same population symbol_blind_extensions reports, so the two cannot
    disagree with each other.

    Where you have ALREADY approved that exact digest in another project,
    the row is enabled without asking, and the grant written is the
    INTERSECTION of what you granted there with what the package requests
    here — never wider. Where there is no such basis it is OFFERED, not
    enabled: the first grant of a package stays a human decision, on every
    machine. A .cip found inside the repository never auto-enables, because
    cloning a repository must not activate code.

    A disable outranks the offer. plugin disable now writes a
    tombstone, and nothing in the machinery above can clear it — so a
    package you turned off here stays off, and the undo_command the
    disclosure names actually holds. (Nothing re-granted a disabled row in
    v0.25.0 either: there was no automatic enable at all. The tombstone is
    what makes the new behaviour safe, not a repair to the old one.)

    The daemon leaves an account of itself

    A daemon spawned by the MCP server runs with stdout and stderr on the
    floor, so for the whole life of any startup defect there was nothing to
    read. It now writes daemon.log beside its lockfile — bounded, with one
    rotated backup — and the client's "did not become ready" error names the
    path. The capability token is never written to it.

    Windows: your approval records move, by themselves

    Read this if you run code-index on Windows. The key that names an
    approval record was derived from canonicalize()'s output when the
    project directory resolved, and from the raw path when it did not —
    two different spellings of one project, because a record stores the
    plain root while canonicalize returns the \\?\ form.

    That was not theoretical. The key IS the record's filename, so any
    moment a project directory was not resolvable — a disconnected network
    share, an unmounted volume, a detached disk — the lookup computed a
    different key, found nothing, and every grant that project held appeared
    to have vanished. They came back when the share reconnected.

    The key is corrected, and records already on your disk are MIGRATED to
    it on the first read or write. Nothing is asked of you and no grant is
    lost: if the store cannot be written to, the record is still read at its
    old name. Other platforms are unaffected — their two spellings were
    always identical, so no file moves there.

    For package authors

    A guest can now map a kind NAME to a kind id without a new host call.
    Guests run with an EMPTY IMPORT LIST — that emptiness is what makes
    fork, open and connect inexpressible — so a guest cannot ask "what
    number is function_item?". It now asserts and the host checks: the
    guest exports one immutable kind_table_digest, and the worker
    enumerates the grammar it just loaded, in the same process that writes
    those ids, refusing on mismatch with exit 24 and printing the number the
    guest should have carried. The zero-import property is measured by
    counting the module's imports, not asserted in prose.

    attr_start_line now has a wire representation, and is_extension is
    deliberately still dropped: admitting it means authorising a package
    into the C# extension-method binding pool, which is a capability
    decision rather than a mapping one, and it is left as one.

    When a store holds more than one approved, resolvable digest of the same
    package id, only one of them can be live. Which one that is, and which
    digests it displaced, are now reported — previously the others simply
    did not run and nothing said so.

    Also

    • read_code with a mistyped range — path:60,200, a comma for the
      hyphen — answered internal_error and advised you to check whether
      the daemon or index DB was down. It now answers invalid_target and
      gives the syntax.

    Upgrading

    No action required, on any platform.

    No index schema change — nothing is re-indexed and no migration runs
    over your database; git diff v0.25.0..v0.26.0 touches no migration.
    The only thing that moves is the Windows approval record, on first use,
    and that is idempotent.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.26.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.26.0-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.26.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.26.0-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.1.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.1.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.1.0.cip --sha256 sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd
    code-index plugin check   sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd
    code-index plugin enable  sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.1.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed. .dataset and other markup remain text-only (searchable, no symbols).

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads