• v0.27.1 f9ddfaf776

    code-index v0.27.1
    Some checks failed
    CI / cargo fmt (push) Successful in 53s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / cargo doc (intra-doc links) (push) Successful in 4m49s
    CI / cargo check (MSRV 1.98) (push) Successful in 5m10s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 5m22s
    CI / cargo clippy (push) Successful in 5m32s
    CI / cargo check (windows-gnu) (push) Successful in 5m56s
    CI / cargo deny (push) Successful in 6m15s
    CI / OSS corpus (tier 1) (push) Successful in 24m9s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Failing after 34m10s
    CI / cargo test (push) Successful in 29m17s
    CI / cargo test (daemon transport) (push) Successful in 12m45s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 28s
    Release Build / Required CI green (push) Successful in 1m2s
    Release Build / Build linux-aarch64 (push) Successful in 12m20s
    Release Build / Build linux-x86_64 (push) Successful in 15m15s
    Release Build / Build linux-x86_64-musl (push) Successful in 15m50s
    Release Build / Pack the XAML reference package (push) Successful in 52s
    Release Build / Pack the TimeLine package (push) Successful in 1m3s
    Release Build / Build windows-x86_64 (push) Successful in 20m13s
    Release Build / Windows archive smoke (msvc) (push) Successful in 11s
    Release Build / Create Forgejo Release (push) Successful in 3m53s
    Stable

    buildagent released this 2026-09-09 09:26:47 +02:00 | 325 commits to master since this release

    code-index v0.27.1

    Build: v0.27.1+691

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    A patch release. Its headline is an asset that should have been in v0.27.0 and
    was not, and the gate that now makes that omission impossible to repeat.

    de.h-dv.timeline ships as a signed package

    de.h-dv.timeline is published as a signed .cip asset, pinned to

    sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    

    It teaches the index four TimeLine definition formats — .dataset, .xsql,
    .shd and .lgd — which stop being text-only and start carrying symbols and
    intra-file references: tables, columns, computed fields, arguments and their
    :name bindings for .dataset; display fields, XSQL tables and join structure
    for .shd and .lgd.

    Install it the way you install any package:

    code-index plugin install de.h-dv.timeline-0.1.0.cip \
      --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    

    Enabling it re-extracts its claim domain. extraction_identity is new, so
    every .dataset, .xsql, .shd and .lgd in a project is extracted on
    activation. Measured on the corpus it was built against: 1,323 files, 87,528
    symbols, 142,614 refs. That is a real indexing pass, not instant, and it is
    worth choosing when it happens.

    It is signed with the same first-party key as the XAML package, which means
    an operator who has anchored that fingerprint installs it with no new trust
    decision, and plugin trust list marks it [BUILTIN]. That is a deliberate
    choice rather than an inherited one: the package lives in this repository, goes
    through these gates, is conformance-checked here, and runs sandboxed behind an
    explicit capability grant.

    Reproducibility, stated precisely. Its extractor.wasm is rebuilt from
    source and byte-compared wherever the suite runs, CI included — an absent wasm32
    target is a failure there, not a skip. What is NOT measured is the
    across-directory leg: cargo derives -C metadata from an absolute path, so
    proving it needs a comparison between two checkouts that no single cargo test
    can perform. That state is "not measured", which is not the same as "measured
    and bad".

    Why it was not in v0.27.0, and what stops that happening again

    The pack job did not exist. Nothing failed, because an asset that was never
    declared cannot be reported absent
    — the release audit refuses a missing
    required
    asset, and the required list named only the XAML package.

    That is now a gate. Dropping a package from the audit's required list fails with
    the sentence the omission deserves:

    a package the audit does not name cannot be reported absent — the release
    publishes without it and every gate reads green.

    Proven the only way that means anything: deleting the pack job makes the new
    audit refuse and name it, while the audit shipped in v0.27.0 exits clean on the
    same artifacts.

    Three surfaces stop reporting states they did not measure

    • plugin check --repo reported a file whose extraction DIED as a successful
      extraction.
      The repo leg read symbols, refs and imports off the guest's
      reply and discarded its diagnostics — the failure arm of the guest's own
      report, dropped at the boundary. It now carries a diagnostic census in which
      the count and the basis it was measured against are a single value, so no
      surface can render one without the other. An empty census is emitted as a
      measurement rather than omitted, because "none reported" and "not looked at"
      are different answers.

    • A measured absence now names the tree it measured. A tool answering
      symbol_not_found with empty_population: {basis: "measured"} was making a
      claim about a specific indexed tree and not saying which — worst for anyone
      working in a git worktree, whose own edits are not indexed and who therefore
      received a confident measured absence about somebody else's checkout. Errors
      that carry a measurement now carry answer_provenance with it; errors that
      carry no measurement stay short, which is the distinction that keeps this from
      becoming noise on every reply.

    • The host's grammarless states now name what they are. Two enum variants
      and an ABI guarantee described a package state no manifest can produce.
      They describe the runtime state that every package actually traverses, and a
      new gate drives all five states from real packages and compares them for set
      equality — so a state nothing reaches fails, and a state that no longer exists
      fails too.

    Honest limits

    The plugin ABI and the .cip package format remain EXPERIMENTAL and may
    change incompatibly in any release. A package is pinned to one thing — the host
    fact-ABI major it brackets — and to nothing else.

    Two findings from this round are filed and NOT fixed here. plugin enable
    fails on a project holding only files a package claims; and the plugin-wpf
    payload ratchet has absorbed 549 tokens across 36 commits, leaving eight tokens
    of headroom, undiagnosed. Each is recorded with its measurement rather than left
    to be rediscovered.

    A third was filed and fixed inside this release. Three guest-rebuild tests read
    their artifact from a hard-coded path while an inherited CARGO_TARGET_DIR
    redirected the child build. That splits into two failures and only the first was
    reported: on a clean tree the artifact is absent and the read panics, but on a
    tree that has ever built that guest, the leftover is read instead
    — measured at
    a 19,765-byte artifact from an earlier run, compared and passed green. A
    reproducibility test that reads whatever is on disk is not binding the artifact
    to its source, which is the whole property it exists to establish. The fix
    clears the variable rather than teaching the paths to follow it, for that
    reason.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.27.1-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.27.1-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.27.1-linux-aarch64.tar.gz
    Windows x64 code-index-v0.27.1-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The five fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads