-
code-index v0.26.0
StableAll checks were successfulCI / cargo fmt (push) Successful in 46sCI / OSS corpus tier-3 scale (weekly) (push) Has been skippedCI / Grammar rebuild from source (weekly) (push) Has been skippedCI / cargo test (abi, 32-bit + wasm32) (push) Successful in 4m21sCI / cargo doc (intra-doc links) (push) Successful in 4m26sCI / cargo deny (push) Successful in 5m26sCI / cargo check (MSRV 1.98) (push) Successful in 5m35sCI / cargo clippy (push) Successful in 5m51sCI / cargo check (windows-gnu) (push) Successful in 5m54sCI / OSS corpus (tier 1) (push) Successful in 15m50sCI / cargo test (push) Successful in 18m22sCI / cargo test (daemon transport) (push) Successful in 6m44sCI / Plugin path cost + pool throughput (weekly) (push) Has been skippedCI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 38m3sRelease Build / Generate Version (push) Successful in 19sRelease Build / Required CI green (push) Successful in 58sRelease Build / Build linux-aarch64 (push) Successful in 13m2sRelease Build / Build windows-x86_64 (push) Successful in 13m48sRelease Build / Build linux-x86_64 (push) Successful in 15m59sRelease Build / Build linux-x86_64-musl (push) Successful in 16m26sRelease Build / Pack the XAML reference package (push) Successful in 50sRelease Build / Create Forgejo Release (push) Successful in 2m56sreleased this
2026-09-04 08:43:11 +02:00 | 481 commits to master since this releasecode-index v0.26.0
Build: v0.26.0+571
Four-binary release:
code-index-mcp(MCP stdio bridge — the usual entry),code-index-daemon(long-lived watcher + RPC server, auto-spawned),code-index-plugin-host(sandboxed worker for plugin packages, spawned by the daemon), andcode-index(CLI: init, index, watch, doctor, link, plugin).Activation on demand
A project holds
.xamlfiles. You installed and enabled that package
for a DIFFERENT project last week. Until now this one handed you
text-only rows and said nothing about it.code-index now detects that case and tells you: a package in your store
whose manifest claims an extension this project actually holds files
for, and whose digest this project has not approved. The census is the
same populationsymbol_blind_extensionsreports, so the two cannot
disagree with each other.Where you have ALREADY approved that exact digest in another project,
the row is enabled without asking, and the grant written is the
INTERSECTION of what you granted there with what the package requests
here — never wider. Where there is no such basis it is OFFERED, not
enabled: the first grant of a package stays a human decision, on every
machine. A.cipfound inside the repository never auto-enables, because
cloning a repository must not activate code.A disable outranks the offer.
plugin disablenow writes a
tombstone, and nothing in the machinery above can clear it — so a
package you turned off here stays off, and theundo_commandthe
disclosure names actually holds. (Nothing re-granted a disabled row in
v0.25.0 either: there was no automatic enable at all. The tombstone is
what makes the new behaviour safe, not a repair to the old one.)The daemon leaves an account of itself
A daemon spawned by the MCP server runs with stdout and stderr on the
floor, so for the whole life of any startup defect there was nothing to
read. It now writesdaemon.logbeside its lockfile — bounded, with one
rotated backup — and the client's "did not become ready" error names the
path. The capability token is never written to it.Windows: your approval records move, by themselves
Read this if you run code-index on Windows. The key that names an
approval record was derived fromcanonicalize()'s output when the
project directory resolved, and from the raw path when it did not —
two different spellings of one project, because a record stores the
plain root whilecanonicalizereturns the\\?\form.That was not theoretical. The key IS the record's filename, so any
moment a project directory was not resolvable — a disconnected network
share, an unmounted volume, a detached disk — the lookup computed a
different key, found nothing, and every grant that project held appeared
to have vanished. They came back when the share reconnected.The key is corrected, and records already on your disk are MIGRATED to
it on the first read or write. Nothing is asked of you and no grant is
lost: if the store cannot be written to, the record is still read at its
old name. Other platforms are unaffected — their two spellings were
always identical, so no file moves there.For package authors
A guest can now map a kind NAME to a kind id without a new host call.
Guests run with an EMPTY IMPORT LIST — that emptiness is what makes
fork,openandconnectinexpressible — so a guest cannot ask "what
number isfunction_item?". It now asserts and the host checks: the
guest exports one immutablekind_table_digest, and the worker
enumerates the grammar it just loaded, in the same process that writes
those ids, refusing on mismatch with exit 24 and printing the number the
guest should have carried. The zero-import property is measured by
counting the module's imports, not asserted in prose.attr_start_linenow has a wire representation, andis_extensionis
deliberately still dropped: admitting it means authorising a package
into the C# extension-method binding pool, which is a capability
decision rather than a mapping one, and it is left as one.When a store holds more than one approved, resolvable digest of the same
package id, only one of them can be live. Which one that is, and which
digests it displaced, are now reported — previously the others simply
did not run and nothing said so.Also
read_codewith a mistyped range —path:60,200, a comma for the
hyphen — answeredinternal_errorand advised you to check whether
the daemon or index DB was down. It now answersinvalid_targetand
gives the syntax.
Upgrading
No action required, on any platform.
No index schema change — nothing is re-indexed and no migration runs
over your database;git diff v0.25.0..v0.26.0touches no migration.
The only thing that moves is the Windows approval record, on first use,
and that is idempotent.Downloads
Four platforms are built for every release. The table below says which ones THIS release published.
Platform Archive Linux x86_64 (glibc) code-index-v0.26.0-linux-x86_64.tar.gz Linux x86_64 (static/musl) code-index-v0.26.0-linux-x86_64-musl.tar.gz Linux ARM64 code-index-v0.26.0-linux-aarch64.tar.gz Windows x64 code-index-v0.26.0-windows-x86_64.zip XAML plugin package
de.h-dv.xaml-0.1.0.cipmakes.xamlfiles carry symbols and references instead of being text-only:x:ClassandClick=handlers bind into the paired C# code-behind,x:Namebecomes a searchable declaration, and{Binding …}stays unresolved because no bridge can reach it.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.xaml-0.1.0.cipstoo and keep the.cipsbeside the.cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody.code-index plugin trust listshows it, marked[BUILTIN], andcode-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cwithdraws it — see About that key.code-index plugin install de.h-dv.xaml-0.1.0.cip --sha256 sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd code-index plugin check sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd code-index plugin enable sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd \ --capabilities bridge_source \ --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.xaml-0.1.0.cip.digest.txtcarries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.Only
.xamlis claimed..datasetand other markup remain text-only (searchable, no symbols).About that key
sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cis a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works:
code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carryingdenied = true; the key stops verifying at the next load,plugin trust listshows it marked[DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and intests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.You may anchor it yourself instead —
code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', withcode-index-publisher.pubfrom this release's assets. Your file replaces the compiled-in entry, and the--nameis a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.macOS is not currently built. No
x86_64-apple-darwinoraarch64-apple-darwinarchive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.Wire into Claude Code
{ "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }SHA256 checksums (.sha256 files) available for every archive.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads