-
code-index v0.32.2
StableSome checks failedCI / cargo fmt (pull_request) Successful in 48sCI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skippedCI / Grammar rebuild from source (nightly) (pull_request) Has been skippedCI / CI lane wall-clock headroom (pull_request) Successful in 50sCI / guest crates (fmt, clippy, doc) (pull_request) Successful in 1m16sCI / cargo doc (intra-doc links) (pull_request) Successful in 5m10sCI / cargo check (MSRV 1.98) (pull_request) Successful in 6m4sCI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 6m15sCI / cargo deny (pull_request) Successful in 6m28sCI / cargo clippy (pull_request) Successful in 6m31sCI / cargo check (windows-gnu) (pull_request) Successful in 6m38sCI / OSS corpus (tier 1) (pull_request) Successful in 27m30sCI / cargo test (pull_request) Successful in 31m20sCI / cargo test (daemon transport) (pull_request) Successful in 9m51sCI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skippedCI (Windows) / fmt + clippy + build + test (windows) (pull_request) Successful in 1h14m55sRelease Build / Generate Version (push) Successful in 29sCI / OSS corpus tier-3 scale (nightly) (push) Has been skippedCI / Grammar rebuild from source (nightly) (push) Has been skippedCI / cargo fmt (push) Successful in 49sCI / guest crates (fmt, clippy, doc) (push) Successful in 54sCI / CI lane wall-clock headroom (push) Successful in 1m8sCI / cargo doc (intra-doc links) (push) Successful in 5m24sCI / cargo clippy (push) Successful in 6m10sCI / cargo test (abi, 32-bit + wasm32) (push) Successful in 6m17sCI / cargo check (MSRV 1.98) (push) Successful in 6m28sCI / cargo deny (push) Successful in 6m35sCI / cargo check (windows-gnu) (push) Successful in 6m45sCI / OSS corpus (tier 1) (push) Successful in 31m9sRelease Build / Required CI green (push) Failing after 51m25sRelease Build / Build linux-aarch64 (push) Has been skippedRelease Build / Build linux-x86_64 (push) Has been skippedRelease Build / Build linux-x86_64-musl (push) Has been skippedRelease Build / Build windows-x86_64 (push) Has been skippedRelease Build / Pack the XAML reference package (push) Has been skippedRelease Build / Pack the TimeLine package (push) Has been skippedRelease Build / Pack the Ruby language package (push) Has been skippedRelease Build / Pack the Svelte language package (push) Has been skippedCI / cargo test (push) Successful in 50m27sCI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h10m17sRelease Build / Windows archive smoke (msvc) (push) Has been skippedRelease Build / Create Forgejo Release (push) Failing after 3m33sCI / cargo test (daemon transport) (push) Successful in 23m21sCI / Plugin path cost + pool throughput (nightly) (push) Has been skippedreleased this
2026-09-26 17:02:05 +02:00 | 60 commits to master since this releasecode-index v0.32.2
Build: v0.32.2+916
Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with
--tag v0.32.2.Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published
.sha256before unpacking, refuses hostile archive members (absolute paths,..escapes, symlinks and reparse points, whichExpand-Archivedoes not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project.-Helplists the flags;-Tag v0.32.2pins the binaries.Four-binary release:
code-index-mcp(MCP stdio bridge — the usual entry),code-index-daemon(long-lived watcher + RPC server, auto-spawned),code-index-plugin-host(bounded worker for plugin packages, spawned by the daemon), andcode-index(CLI: init, index, watch, doctor, link, plugin).Changes
This release fixes the mid-session disconnects two Windows users reported, and adds the tool improvements they asked for.
Daemon robustness
- Locked writes wait instead of crashing the daemon. The writer now waits out a write lock held by another process (
BEGIN IMMEDIATE, backing off from 25 ms to 1 s). Before, it gave up after five retries within about 7 ms and the whole daemon exited. A writer blocked by another process now says so, andSQLITE_LOCKEDis no longer retried. - Every daemon and MCP exit leaves a reason in
.code-index/daemon.exitanddaemon.log. Panics are logged with a backtrace. A panic on the MCP main thread now exits instead of leaving the server alive but unresponsive. - No more silent long hangs. Each tool call gets one shared daemon budget (default 180 s,
CODE_INDEX_TOOL_CALL_BUDGET_SECS), never lower than a raised per-call timeout, and at most one daemon respawn. The reply says when the daemon was replaced and why (daemon_restarted). - Plugin workers:
- They exit when their daemon dies.
- They retire after 60 s idle.
- On Linux they are the OOM killer's first choice.
- On Windows the daemon runs in its own hidden console and process group.
code-index indexnext to a running daemon now defers to it and exits 0 instead of refusing. It never becomes a second writer.- Maintenance and logging:
files_ftscompaction defers while the write lock is held. Undecodable text files warn once per content version instead of on every pass.
Tool improvements
find_callerson a type reportstarget_is_typewith a count of the type's members, or says when it cannot count them. This covers Rust impl blocks and C# partial classes.index_freshnessnames the lagging paths and says whether results for all other files are current.search_texttakesmax_lines_per_file(up to 1000) to list every matching line.read_codetakes a list of up to 8 targets in one call.envelope: "minimal"is available on every tool. It drops explanatory prose and provenance but keeps every verdict as a field, and saved about 17% on a representative call mix. The default reply is unchanged.- Diagnostics:
- A reason for a missing per-row field now compares the daemon's build with the server's instead of always blaming the daemon.
- A failing batch entry names its own query.
Upgrade
No schema change and no reparse. Replace the binaries. Running daemons are replaced on the next call, and the reply reports the replacement.
Known limits
These are tracked as follow-ups:
- The writer-blocked state is logged but not yet shown in
index_freshnessorproject_overview. - Panic-hook cost for plugin panics.
- The Windows parent-death check treats every error as the parent being gone.
- Exit codes on signals.
Validation
- CI: the release commit passed CI on Linux and on native Windows.
- Linux ran fmt, clippy, MSRV, the windows-gnu check, the 32-bit and wasm32 ABI tests, cargo deny, the guest crates, strict rustdoc, the workspace suite, the daemon-transport suite and the tier-1 OSS corpus job.
- Reviews: both halves of the change were independently reviewed. Each finding was fixed together with a test that fails when the fix is removed.
- Not covered: Linux ARM64 is cross-built and has no native runtime test. This release does not provide macOS or Windows ARM64 archives.
Downloads
Four platforms are built for every release. The table below says which ones THIS release published.
Platform Archive Linux x86_64 (glibc) code-index-v0.32.2-linux-x86_64.tar.gz Linux x86_64 (static/musl) code-index-v0.32.2-linux-x86_64-musl.tar.gz Linux ARM64 code-index-v0.32.2-linux-aarch64.tar.gz Windows x64 code-index-v0.32.2-windows-x86_64.zip XAML plugin package
de.h-dv.xaml-0.2.0.cipmakes.xamlfiles carry symbols and references instead of being text-only:x:ClassandClick=handlers bind into the paired C# code-behind,x:Namebecomes a searchable declaration, and{Binding …}stays unresolved because no bridge can reach it.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.xaml-0.2.0.cipstoo and keep the.cipsbeside the.cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody.code-index plugin trust listshows it, marked[BUILTIN], andcode-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cwithdraws it — see About that key.code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 code-index plugin check sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 code-index plugin enable sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \ --capabilities bridge_source \ --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.xaml-0.2.0.cip.digest.txtcarries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.Only
.xamlis claimed by this package. The TimeLine package below claims.dataset,.xsql,.shdand.lgd, and the Svelte package below claims.svelte; all other markup remains text-only (searchable, no symbols).TimeLine plugin package
de.h-dv.timeline-0.1.0.cipmakes the four TimeLine definition formats carry symbols and references instead of being text-only:.datasetand.xsqlthrough one language,.shdand.lgdthrough another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.timeline-0.1.0.cipstoo and keep the.cipsbeside the.cip. The same signature rules apply as for the XAML package above, and the same key signs both.code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f code-index plugin check sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f code-index plugin enable sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \ --capabilities same_file_candidate,exported_candidateNo
--bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what--sha256pins;de.h-dv.timeline-0.1.0.cip.digest.txtcarries it and the extraction identity.The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.
Ruby plugin package
de.h-dv.ruby-0.7.0.cipis the compiled-in Ruby extractor as an EXTERNAL, sandboxed package:tree-sitter-rubyloaded at runtime, the extractor compiled towasm32-unknown-unknownand byte-reproducible fromcrates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.It claims
.rbx, not.rb. The compiled-in Ruby plugin owns.rb,.rake,.gemspec,RakefileandGemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your.rbfiles are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.ruby-0.7.0.cipstoo and keep the.cipsbeside the.cip. The same signature rules apply as for the packages above, and one key signs every package in this release.code-index plugin install de.h-dv.ruby-0.7.0.cip --sha256 sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 code-index plugin check sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names code-index plugin enable sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names \ --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate--derived-namesis required oncheckas well as onenable, and without itcheckREPORTS FAILED. Rails'has_many :postsemits a type reference namedPostat the span of the literal:posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.No
--bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests andenablerefuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.ruby-0.7.0.cip.digest.txtcarries it and the extraction identity.The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and
plugin checkcompares the package's facts against them exhaustively.Svelte plugin package
de.h-dv.svelte-0.1.0.cipmakes.sveltefiles carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches,{#snippet}declarations and{@render}uses — out of one sandboxed extractor over thetree-sitter-svelte-nggrammar.It claims
.svelteand NOTHING ELSE..svelte.tsand.svelte.jsare deliberately not claimed and this package declares no[[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.svelte-0.1.0.cipstoo and keep the.cipsbeside the.cip. The same signature rules apply as for the packages above, and one key signs every package in this release.code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f code-index plugin check sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f code-index plugin enable sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \ --capabilities same_file_candidateOne capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a
{#snippet}, whose visibility isfile: reachable by name anywhere in its own component and nowhere else.exported_candidatewould admit an empty set, so it is not requested — andenablerefuses a grant wider than the manifest asks for, so the line above cannot be padded. No--bridges: this package declares none.The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.svelte-0.1.0.cip.digest.txtcarries it and the extraction identity.The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.
About that key
sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cis a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works:
code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carryingdenied = true; the key stops verifying at the next load,plugin trust listshows it marked[DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and intests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.You may anchor it yourself instead —
code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', withcode-index-publisher.pubfrom this release's assets. Your file replaces the compiled-in entry, and the--nameis a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.macOS is not currently built. No
x86_64-apple-darwinoraarch64-apple-darwinarchive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.Wire into Claude Code
{ "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }SHA256 checksums (.sha256 files) available for every archive.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Locked writes wait instead of crashing the daemon. The writer now waits out a write lock held by another process (