Bisect identifies 5eaa6fed (#2034, #1820) as the first bad commit: its Python named-import fallback resolves task.delay() to the task function itself, hiding the queue effect in API steps. Require member resolution before returning a named Python import's target for attribute access.
Keep direct calls, callbacks, constructors, and known members working. Add absolute/relative aliased-import regression coverage without changing the existing steps assertions.
Validation: git bisect with preserved steps test, tsc and copy-assets at every step, CODEGRAPH_KERNEL=0 throughout bisect. 338 tests pass across ui-steps-api-servers, function-ref, rebuilt kernel-tsjs-parity, resolution, and ui-effects. Issue #1820 repro and tsc --noEmit pass.
Node runs a setTimeout delay above 2^31-1 ms after 1 ms instead, so a huge
CODEGRAPH_WATCHDOG_TIMEOUT_MS SIGKILLed a healthy server at once and a huge
CODEGRAPH_STARTUP_HANDSHAKE_TIMEOUT_MS abandoned the launch within
milliseconds. Both parsers now cap at 2147483647.
(cherry picked from commit a242f579ce)
Co-authored-by: Eric Minish <eric.minish@gmail.com>
* fix(db): guard synthesis metadata and migrate the expression index
Bisect identifies 2a2f71ec (#2033) as the malformed JSON regression. Guard index expressions, ownership predicates, wiring lookups, and the legacy Go backfill; schema v11 replaces existing v10 indexes. Cover malformed base edges, staged publication, upgrade replay, and indexed range lookup.
* fix(db): preserve call precedence in deterministic edge traversal
Independent bisect identifies 2a2f71ec (#2033): source-first ordering puts importing file IDs ahead of function callers and consumes the default caller limit. Restore kind-first incoming and outgoing traversal with deterministic endpoint/position ties. Keep both original regression tests unchanged and cover filtered, cached, and provenance-filtered queries across reverse insertion order.
Validation: 25 test files passed (564 tests, 3 skipped), including security, MCP caller truncation, sync, migration, graph, and DB/query coverage; npx tsc --noEmit passed. Both bisects rebuilt tsc and copied assets at every step with CODEGRAPH_KERNEL=0 to avoid using the HEAD kernel on historical extraction code. Final validation used the normal kernel setting.
* chore: no changelog entry for an unreleased regression
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(mcp): keep an explicit projectPath project in sync (#1835)
A project opened through a tool call's `projectPath` (a repository other
than the server's default — e.g. an indexed child of an un-indexed
workspace) was opened read-only: no catch-up sync on open and no file
watcher, so its answers went stale until someone ran `codegraph sync`.
The engine now owns the lifecycle of every project the ToolHandler opens
for an explicit path, mirroring the default project:
- the project's writer lock is acquired (#1740 single-writer rule); if
another live process holds it, that process keeps syncing and we only
read;
- a catch-up `sync()` runs on open and the first call against that
project awaits it, time-boxed like the default gate (#905);
- a file watcher runs for as long as the project stays cached.
Bounds: the cache is keyed by the canonical (realpath) root, so a
symlinked spelling shares one connection and one watcher; it is LRU with
`MAX_CACHED_PROJECTS = 8` — opening a ninth closes the least recently
used (watcher stopped, writer lock released, DB closed); `stop()` closes
them all. Un-indexed paths still get the success-shaped guidance.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(mcp): keep explicit projects synchronized (#1835)
Explicit projectPath connections bypassed catch-up and synchronization ownership.
Share canonical project leases and catch-up gates, retain daemon sessions, and retry ownership after a writer exits.
Advertise direct-writer readiness and drain active work before eviction or shutdown.
Add exact SQLite regressions for concurrent sessions, aliases, no-watch behavior, and teardown.
Co-authored-by: danusha2345 <danusha2345@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(mcp): retry catch-up quietly on sync lock contention
Handle LockUnavailableError without marking catch-up complete or logging an alarming failure, and verify timer-driven recovery against a real indexing lock.
Make the eviction regression deterministic by applying its short timeout only to the held catch-up. Other projects must finish reconciling before the test can assert that the oldest eligible graph was closed.
---------
Co-authored-by: danusha2345 <danusha2345@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* fix(cpp): macro invocations are not calls; local objects call their constructor
A function-like macro invocation (`TRACE_POINT(1)`) parses as a call, and
the resolver bound it to a same-named free function in another translation
unit — a caller and a callee that never existed (#1838). And local object
initialization (`Widget w;` / `Widget w(1);` / `Widget w{1};`) reached the
class node instead of a constructor, or nothing at all for the default
form (#1839).
Extraction (wasm walker and the Rust kernel, in parity):
- every `preproc_function_def` becomes a `constant` node whose signature
is the directive, so the index knows which names are macros;
- a C++ declaration emits one `calls` ref per constructed object, shaped
`ns::T::T/<arity>`; pointer, reference and function declarators,
`extern`, and array element braces construct nothing; the #1035
`instantiates` ref is unchanged;
- constructors carry their parameter list as the signature.
Resolution:
- `cpp-macro-visibility.ts` walks the translation unit (root file plus
in-repo includes, each file once) over per-file summaries of
function-like defines, undefs and includes, evaluating what each file
can decide itself (literals, its own defines, the include-guard idiom).
A call whose name is definitely a macro at that point, or a name that
only macros bear, resolves to nothing. A macro that exists in one build
configuration only (CMSIS's `__DSB()` under the ARM compilers, a
target's HAL compat header) keeps the call to the function the other
configuration compiles; a wrapper macro that calls its own name is how
that function gets called and hides nothing.
- `cpp-constructor.ts` resolves the constructor refs: the type in the
lexical namespaces of the call site, then the single overload whose
parameter count admits the arguments; two admitting overloads, an
initializer_list overload, or an aggregate yield no edge.
- a `#define` constant is never a `calls` target and does not count
toward the same-name ceiling.
Measured on a betaflight tree (4,017 files, wasm arm): 153 `calls` edges
lost — all fabricated (`MIN`/`MAX` bound to a CLI enum member, macros
misparsed as functions, a cross-vendor `SWAPBYTE`) — and 34 constructor
edges gained; indexing 34s vs 30s.
Fixes#1838Fixes#1839
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(cpp): resolve local constructors and macro visibility (#1839)
Local construction lacked constructor calls, while macro invocations could bind unrelated functions.
Resolve constructors using lexical types and overload signatures, preserving separately declared defaults and array element construction.
Evaluate macro directives in translation-unit order, respecting reinclusion, guards and pragma once.
Mirror extraction in Rust and WASM, preserve type dependencies, and distinguish them in CLI output.
Co-authored-by: danusha2345 <danusha2345@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <danusha2345@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* fix(extraction): record callers for methods passed as values (#1820)
pool.submit(obj.method), thread_pool_exec(self.store.fetch), and Go
Submit(c.store.Fetch) produced no callers/impact edge because only
obj.method(...) call expressions were captured. Member values are now
emitted as *.method function-refs and resolve unique-or-drop
(same-file first). Two methods of the same name still produce no edge.
Go go c.store.Fetch(ids) remains a calls edge (it is a call expression).
EXTRACTION_VERSION 27: MCP daemon catch-up rebuilds a stale index on
start so the watcher does not keep serving the hole after upgrade.
* fix(resolution): do not let test mocks veto #1820 method-value callers
A unique production method plus a unit-test double of the same name
was treated as ambiguous, so retrieve_vision_vectors still looked
callback-invisible on a real repo. Prefer the non-test file when
exactly one production target remains.
* fix(resolution): prefer a real override over a NotImplementedError base
#1820 unique-or-drop treated DocStoreConnection.delete_payload_fields
(the ABC stub) and QdrantConnection.delete_payload_fields as ambiguous,
so gc_stale_member_stamps stayed invisible. Skip short not-implemented
stubs when exactly one real implementation remains.
* fix(extraction): preserve receivers for method values (#1820)
Python attributes and Go selectors used as callback values were dropped or reduced to bare method names.
Preserve receiver paths in native and WASM extraction, resolve through type/import scope, and reject ambiguous or noncallable targets.
Cover callback, assignment, collection, and query behavior, with extraction version 27 signaling the required reindex.
Co-authored-by: Josh66 <info@aska-systems.de>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Josh66 <info@aska-systems.de>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(sync): refresh synthesized edges after incremental changes (#1988)
Scoped sync skipped synthesis and retained obsolete dispatch edges.
Refresh all synthesis passes after base resolution when dependencies or source patterns change.
Stage and atomically replace owned edges, preserve ordinary edges, and retry interrupted refreshes.
Stabilize traversal order and migrate existing indexes for rebuild convergence.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix: preserve structural Go containment during synthesis refresh
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(resolution): stop expression-receiver calls from binding to unrelated methods
A method called on an expression receiver reached the resolver as the bare
method name, and exact-match bound it to any project method of that name:
`(await list()).map(...)` in TypeScript onto a UI adapter class's `map`
(0.9), and `v.iter().map(...)` in Rust onto the same TypeScript method
across languages (0.5).
TS/JS extraction (mirrored in the kernel): look through receiver wrappers
that keep the same object — parentheses, `!`, `as`/`satisfies`, `<T>x`,
`await` (including the grammar's `(a && b)!` parse of `a && b!`) — so
`x!.m()` is `x.m` and `(await f()).m()` is `f().m`; any other receiver with
no static type (`(a ?? b).m()`, `f().list.m()`, `arr[0].m()`) emits nothing
instead of the bare name. `this`/`super` (and chains rooted at them),
`window.*` chains and `new C().m()` keep their existing bare form.
Resolution: a bare-named call may cross a language family only through the
C ABI (a C/C++ symbol, or a free function a C/Objective-C/Swift caller
reaches, e.g. a cgo `//export`). A class member of another family, or a
function/class/variable outside that pair, is rejected as the candidate a
strategy commits to (exact-match single/best and fuzzy), never filtered out
of the pool, so no lone survivor is manufactured.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(resolution): reject unrelated cross-language matches (#1986)
Name-based calls, constructors, and inheritance could select unrelated foreign-language symbols.
Apply a shared interoperability policy to selected results without manufacturing replacement matches, including JSX/Vue synthesis.
Preserve framework exports and ABI-backed calls, building on PR #1944's TS/Rust expression-receiver fixes.
Validate with both repro scripts, 529 targeted tests, kernel/wasm parity, and clean TypeScript checks.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(resolution): resolve same-file calls through object-literal aliases (#1932)
`api.getUser()` where `api` is `const api = { getUser }` (or
`{ getUser: fetchUser }`) and the function is declared outside the literal
resolved to nothing in the literal's own file: the #1573 containment lookup
only finds members defined inside the literal, and the binding-following
alias path existed only on the import side, so same-file callers were
missing from callers / impact / blast radius.
- Extract the member-binding read into `objectLiteralMemberBinding`, which
splits the literal into its own top-level members on comment- and
string-blanked source, so a nested object, a member body, a comment or a
string never donates a binding, and `{ fn: 1 }` names nothing. The import
path now uses it too.
- In the same-file object-literal receiver strategy, fall back to that
binding: a symbol of the file, else one of its imports, skipped when a
parameter or nested declaration shadows the name where the literal is
written.
Resolution-only change; extraction output (and kernel parity) unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* test(resolution): a literal wrapped in Object.freeze still names its members (#1932)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(resolution): resolve object-literal function references safely (#1932)
Same-file object-member calls only found functions defined inside the literal.
Share lexical binding resolution across same-file, import, and alias-forwarding paths.
Respect exact source columns, top-level membership, shadowing, and property overwrites while preserving wrappers and inline members.
Add JavaScript and TypeScript regressions and verify kernel/WASM parity.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Same-kind, same-name declarations on one line shared an ID and silently overwrote each other in SQLite.
Use per-extraction collision tracking to append a UTF-16 column only to later distinct declarations.
Apply the same rule across wasm, Rust language walkers, Liquid, and CFML while preserving file IDs and edge endpoints.
Add persistence, call-edge, identity-vector, and Unicode parity regressions.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(scala): resolve extends/with to the trait, not its companion object
The Scala trait + companion object idiom puts two same-named symbols in
one file. Both were indexed as kind 'class', so an 'extends X' reference
tied between the trait and its companion and the winner was arbitrary.
When the companion won, every subtype was detached from the trait's
inheritance chain, and impact analysis on a widely-used trait stopped at
depth 1.
- classify Scala object_definition as 'module' (a singleton value, not a
type - 'extends' can never target it)
- add 'module' to the classifyClassNode contract and handle it in the
extractor dispatch
- in name matching, bias extends/implements references toward actual
type definitions and penalize 'module' candidates, so the trait wins
the tie deterministically
Regression test: trait + companion in one file, subclass in another -
the extends edge must land on the trait and impact must reach the
subtype through it.
* fix(scala): resolve companion inheritance to type definitions (#1824)
Scala objects and their companion types could tie during inheritance resolution, disconnecting subtype impact paths.
Classify objects as modules in both extraction engines and reject Scala singleton inheritance targets across resolution strategies.
Preserve object method lookup and inherited receiver methods, with declaration-order, impact, and native/WASM parity regressions.
Co-authored-by: Hubert Tarnacki <hubert.tarnacki@comarch.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Hubert Tarnacki <hubert.tarnacki@comarch.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(resolution): resolve this.#field.method() on the field's type (#1987)
A call through an ES private field fell outside the `this.<field>` shape
(#1496): the extractor accepted only a property_identifier, so
`this.#items.add(x)` was emitted as the bare `add` and exact-matched
whichever project method shared the name, often the calling method itself.
The extractor and its kernel mirror now keep `this.#items.add`, and the
resolver matches that shape and reads the field's type off the class
declaration. The field regexes open with a lookbehind instead of `\b`,
which never matches before `#`. A builtin or external field type
(`new Set()`, a `Map`, an array) now yields no edge.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(resolution): require receiver evidence for built-in method calls (#1987)
Unknown JavaScript receivers could match unrelated methods by name or class-name similarity.
Require validated receiver evidence for built-in method names while retaining typed, imported, object-literal and class resolution.
Preserve private-field receivers in TypeScript and Rust extraction and keep public/private field declarations distinct.
Build on PR #1990 with regression coverage across all four JS/TS variants and kernel/WASM parity.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The #1465 change read the default project root on every tool call, before
checking whether a query worker would serve it. Resolve it only for a pooled
call; in-process dispatch no longer depends on it (restores the oversized-output
truncation test).
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Empty explore results returned no explanation or retry guidance.
Check FTS and live name segments with two bounded SQL queries to distinguish matched and unmatched words and suggest indexed names.
Preserve success-shaped responses, unresolved-path notes, ranking, and non-empty output; cap added diagnostics below 1.5K characters.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(watcher): auto-sync changes inside symlinked directories (#770)
The file watcher (Linux inotify strategy) did not follow directory
symlinks when building its watch set, so a project dir symlinked into
the workspace root was silently invisible to the watcher.
Changes:
1. watcher.ts: watchTree() now detects isSymbolicLink() entries,
resolves real targets with realpathSync(), and recursively watches
directory symlinks. Guards against cycles with a visitedRealDirs Set
— tracking regular dirs too so a symlink→already-visited-path is
also detected. Mirrors the indexer's walk() in extraction/index.ts.
2. utils.ts: Added allowSymlinkedDirs parameter to validatePathWithinRoot().
When true, skips the realpath check that would reject watched symlinks
whose targets live outside the lexical project root. All internal
sync/index paths pass true here; user-facing paths (MCP layer) keep
the existing strict validation.
3. extraction/index.ts: All internal sync/index paths now pass
allowSymlinkedDirs: true so the watcher can read files from
symlinked directories.
4. __tests__/watcher.test.ts: Added integration test for symlinked
directory auto-sync, plus a symlink-cycle detection test.
Signed-off-by: dengzhongyuan <dengzhongyuan@uniontech.com>
* fix(watcher): auto-sync symlinked directory changes across platforms (#770)
Directory indexing followed symlinks that native watchers did not cover.
Discover targets with realpath cycle guards, preserve logical paths, and install bounded supplemental watches.
Reconcile watches after topology and scope changes, and preserve changes arriving during a full sync.
Retain strict content-serving containment and cover lifecycle, resource limits, and cleanup.
Co-authored-by: dengzhongyuan <dengzhongyuan@uniontech.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(watcher): auto-sync symlinked directory changes across platforms (#770)
Directory indexing followed symlinks that native watchers did not cover.
Discover targets with realpath cycle guards, preserve logical paths, and install bounded supplemental watches.
Reconcile watches after topology and scope changes, and preserve changes arriving during a full sync.
Retain strict content-serving containment and cover lifecycle, resource limits, and cleanup.
Co-authored-by: dengzhongyuan <dengzhongyuan@uniontech.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(watcher): auto-sync symlinked directory changes across platforms (#770)
Directory indexing followed symlinks that native watchers did not cover.
Discover targets with realpath cycle guards, preserve logical paths, and install bounded supplemental watches.
Reconcile watches after topology and scope changes, and preserve changes arriving during a full sync.
Retain strict content-serving containment and cover lifecycle, resource limits, and cleanup.
Co-authored-by: dengzhongyuan <dengzhongyuan@uniontech.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Signed-off-by: dengzhongyuan <dengzhongyuan@uniontech.com>
Co-authored-by: dengzhongyuan <dengzhongyuan@uniontech.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The orphan sweep discarded resolver statistics, so unchanged files caused the CLI to report a no-op after recovery.
Carry processed, resolved, and unresolved sweep counts into SyncResult and report recovery without changing quiet mode.
Cover successful recovery, unresolved attempts, and genuine no-ops with real SQLite regression tests.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* test(mcp): reap the daemon-mode writer so the temp project can be removed
In daemon mode the writer is a third process spawned by the proxies and never recorded in children -- the test asserts its pid is neither child's. Killing only the proxies left it holding the index, so fs.rmSync failed and its catch swallowed the error: one temp directory and one live serve --mcp process leaked per run while both tests passed.
writer.pid already names the daemon and the test already parses it, so afterEach now reads it before killing the proxies and signals the writer too. The removal is no longer silenced, because the swallowed error is what made this invisible.
Measured on Windows 11 with TEMP redirected to a private directory: before, 1 leaked directory and 1 surviving process per run; after, 0 and 0, both tests still passing. Fixes#1782.
* fix(mcp): reap writer-lock test daemon and verify cleanup (#1782)
The writer-lock test stopped its proxies but left their daemon running, hiding directory removal failures.
Preserve the contributor fix and add verified daemon shutdown, bounded exit polling, and cleanup assertions.
Ensure the daemon test overrides inherited direct-mode configuration.
Co-authored-by: Aaron Queen <bompus@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Aaron Queen <bompus@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(mcp): enable query workers in direct mode (#1465)
Direct and proxy-fallback engines never enabled the query pool, serializing concurrent reads despite CODEGRAPH_QUERY_POOL_SIZE.
Enable bounded workers in both paths and support sessions without a default index, including indexes discovered later.
Preserve main-thread catch-up, staleness notices, and session accounting, with regression coverage for concurrency, parity, configuration, and teardown.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(mcp): enable query workers in direct mode (#1465)
Direct and proxy-fallback engines never enabled the query pool, serializing concurrent reads despite CODEGRAPH_QUERY_POOL_SIZE.
Enable bounded workers in both paths and support sessions without a default index, including indexes discovered later.
Preserve main-thread catch-up, staleness notices, and session accounting, with regression coverage for concurrency, parity, configuration, and teardown.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(mcp): enable query workers in direct mode (#1465)
Direct and proxy-fallback engines never enabled the query pool, serializing concurrent reads despite CODEGRAPH_QUERY_POOL_SIZE.
Enable bounded workers in both paths and support sessions without a default index, including indexes discovered later.
Preserve main-thread catch-up, staleness notices, and session accounting, with regression coverage for concurrency, parity, configuration, and teardown.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* test: build dist/ before the suite when it is missing or stale (#1879)
About thirty suites spawn dist/bin/codegraph.js, the parallel resolver loads
its worker from dist/, and the `codegraph ui` suites serve dist/viewer/. On a
fresh checkout `npm ci && npm test` failed them on spawn timeouts and a
missing-viewer error that never mentioned the build; after an edit without a
rebuild they quietly exercised the old code.
A Vitest globalSetup now rebuilds each half only when it is missing or older
than its sources: `tsc` + copy-assets when anything under src/ is newer than
dist/bin/codegraph.js, `build:ui` when ui/src/ is newer than
dist/viewer/index.html. A current dist/ costs one mtime walk.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(tests): build missing or stale test prerequisites (#1879)
Dist-dependent tests launched missing or stale compiled outputs without a build prerequisite.
Retain the contributor's shared setup and track build inputs and individual outputs for reliable invalidation.
Resolve TypeScript locally, preserve asset copying and engine/UI separation, and report build failures directly.
Add regression coverage for cold builds, warm runs, configuration changes, and missing assets.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(mcp): share one connection across two spellings of one root (#1057)
A symlinked checkout, or a case-variant of a root on a case-insensitive
mount (macOS, NTFS, WSL DrvFs), resolved to two path strings and opened two
connections to the same .codegraph/codegraph.db.
The connection cache stays keyed by path, so a root recreated at the same
path still heals in place (#925). On a miss, an open root that is the same
index NOW (both data directories stat to one dev:ino, read as bigints) is
reused and the new spelling filed as its alias. Comparing live identities
means a deleted root never matches, even if a new directory reuses its
inode. Windows has no usable inode, so it compares the case-folded
realpath.native instead. statInode moves to directory.ts so the DB layer
and the cache share one reading, and closeAll closes an aliased instance
once.
* fix(mcp): keep root aliases out of the connection cache (#1057)
A second spelling of an open root was filed in projectCache under its own key,
so one CodeGraph sat under two keys. Anything that drops one key and closes its
connection (a bounded cache's eviction, as proposed in #1929) then left the
other key holding a closed handle: every query on that spelling, and through
the alias scan on the original spelling too, failed with "database is not
open" until restart.
Aliases now live in their own map (spelling -> projectCache key). projectCache
is back to one key per instance, and an alias whose entry is gone is dropped
and re-resolved instead of served.
* fix(mcp): deduplicate equivalent project paths (#1057)
Equivalent project paths could open duplicate cached connections.
Compare current filesystem identities using bigint inodes and native Windows paths.
Revalidate aliases and pin cached connection owners to symlink targets.
Preserve recreation recovery and single-owner cleanup.
Co-authored-by: Eric Minish <eric.minish@gmail.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Eric Minish <eric.minish@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
MSVC COM interface declarations were parsed as functions, losing their owners and methods.
Normalize declaration-position interface keywords to padded struct keywords when alias or declaration evidence is present.
Preserve source offsets and protected text through the shared native/WASM preprocessing hook.
Cover real-file indexing, inheritance, source retrieval, and parser parity.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Rust command attributes were not retained as decorators, so runtime entry points could appear as dead code.
Preserve tauri::command metadata in both native and fallback extraction and reuse the existing decorated exclusion.
Add SQLite regression coverage and native/fallback parity checks, including negative cases.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Single-argument function macros were indexed under parentheses in C or the macro name in C++, breaking caller resolution.
Recover both parser shapes only when a preceding local macro definition establishes the function name, and mirror the recovery in the Rust kernel.
Preserve existing multi-argument recovery and ordinary declarations; add extraction, resolution, explore-flow, and parity regressions.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Path search marked nodes visited only on dequeue, allowing pending targets to be queued repeatedly with copied paths.
Track enqueued nodes from the starting node and exclude them from target lookups and subsequent pushes.
Add real-SQLite operation-count and path-correctness regression coverage.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Field-channel synthesis discarded receiver and binding identity when selecting handlers globally by name.
Reuse resolved function-reference edges at the registration site, retaining class, inheritance, and import resolution without global fallback.
Add regression coverage for target identity, unknown handlers, and explore registration metadata.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sync swallowed lock-acquisition failures and returned counters indistinguishable from a clean index.
Throw LockUnavailableError so the CLI reports failure and the watcher retains its retry behavior without inspecting counters.
Preserve quiet output and clean up resources when sync rejects.
Cover live locks, recovery, watcher retries, and CLI exit statuses.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(installer): resolve Antigravity codegraph command out of fnm's ephemeral per-shell dir
- resolveCodegraphCommand resolved `command -v codegraph`, which under fnm returns an ephemeral ~/.local/state/fnm_multishells/<pid>/bin path that fnm removes when the installing shell exits, leaving a dangling MCP command
- realpath the containing directory so the written command survives shell exit
- preserve the `codegraph` basename so agents that validate the command by basename still match
- fall back to the raw resolved path if realpath fails
* fix(installer): preserve Antigravity command after fnm shell exit (#1443)
Antigravity saved an ephemeral fnm shell path that disappeared after shell exit.
Canonicalize the containing directory while preserving the codegraph basename and existing fallbacks.
Add macOS regression coverage for symlink removal, stable paths, and lookup failures.
Co-authored-by: kevocodes <62626446+kevocodes@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: kevocodes <62626446+kevocodes@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Everyday uses of como and wie were treated as sufficient structural evidence for HIGH.
Remove these words from the unconditional keyword list so existing index verification determines HIGH, MEDIUM, or silence.
Add real-index CLI regressions while preserving existing English and multilingual structural tests.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(react-router): bound route scans to their declarations (#1348)
Fixed scan windows borrowed paths and components from neighboring or nested routes.
Scan JSX opening tags and data-router objects structurally, pairing only their own attributes and properties.
Add persisted-graph regressions across JavaScript and TypeScript route declarations.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(react-router): bound route scans to their declarations (#1348)
Fixed scan windows borrowed paths and components from neighboring or nested routes.
Scan JSX opening tags and data-router objects structurally, pairing only their own attributes and properties.
Add persisted-graph regressions across JavaScript and TypeScript route declarations.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
DFM/FMX component ranges stayed pinned to their declaration lines because closing blocks only popped IDs.
Store nodes in the component stack and update their ending positions at the matching end.
Cover persisted ranges and MCP source retrieval while preserving containment and event references.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(dead-code): treat an ancestor outside the index as opaque (#1973)
An override is excluded from the dead-code report when its ancestor is in
the graph, or is present but declares no members we can read. An ancestor
outside the project (React.Component, stream.Transform, a NestJS
interface) creates no edge at all, so a lifecycle method the framework
calls looked like it overrode nothing and was listed as unreferenced.
The resolver does record such an ancestor, as a failed extends /
implements row. A container with one, or a project ancestor of one that
has it, now counts as having an opaque ancestor, and its members are
excluded under "overriding".
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(dead-code): propagate external ancestor uncertainty to descendants (#1973)
External ancestors leave unresolved inheritance references rather than graph edges.
Treat those ancestors as opaque and propagate uncertainty through every descendant root.
Track visited ancestor/root pairs while preserving cycle protection and the depth bound.
Cover direct and three-level inheritance, unused controls, and batched query behavior.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Workspace imports could follow excluded dependency archives and decode them without a size guard.
Reuse extraction's 1 MiB limit, reject non-files before reading, and cache null results.
Add sparse-HAR and real ohpm indexing coverage while preserving legitimate import edges.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(explore): find files by exact Chinese filenames
Co-Authored-By: GPT-5 <noreply@openai.com>
* fix(explore): retrieve exact Han filenames (#1372)
ASCII-only query preparation discarded Han filename queries before retrieval.
Add exact basename/stem file lookup and prioritize matches before the entry-point cap while respecting node-kind filters.
Preserve shared tokenization and retrieval budgets; cover Lua, Svelte, and TypeScript retrieval.
Co-authored-by: 小为 <1053122090@qq.com>
Co-authored-by: GPT-5 <noreply@openai.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: 小为 <1053122090@qq.com>
Co-authored-by: GPT-5 <noreply@openai.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* feat(extraction): index Python docstrings, not just preceding comments (#1905)
getPrecedingDocstring only walks preceding comment siblings, so a Python
docstring — a bare string literal first in the body — never reached the
docstring column, never entered nodes_fts, and was never shown by
`codegraph node`. The identical sentence written as a leading `#` comment was
both. For a Python codebase that is most of the prose there is. (#1905)
Adds an optional getBodyDocstring() to LanguageExtractor, in the same shape as
getSignature(), and routes every docstring call site through one docstringFor()
helper that consults both sources. A node carrying a comment AND a docstring
keeps both, joined: they are two things the author wrote about the same symbol
and the column is free text.
The Python implementation reads the grammar`s string_content rather than
slicing quotes off the raw text, so r/u/b prefixes and both triple-quote forms
work without a regex per case; f-strings are skipped because an interpolated
string is code, not prose. Dedent follows PEP 257 (first line exempt).
Scoped to Python deliberately. Julia (a string sibling before the def) and
Elixir (@doc) fit the same hook and are left as follow-ups.
* fix(extraction): index Python body docstrings across backends (#1905)
Python extraction only consulted preceding comments, leaving body docstrings absent from search and rendered prose.
Extend the contributor's hook to module and definition docstrings, and mirror it in the native kernel.
Handle comments, concatenated literals, and indentation consistently while rejecting bytes, f-strings, and tuples.
Verify persistence, exact-name ranking, MCP/CLI rendering, and native/WASM parity.
Co-authored-by: Max Hsu <maxmilian@gmail.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Max Hsu <maxmilian@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The vendored grammar (master@0aca5d0a6f, in both the wasm and the kernel's C
sources) parsed `class A(x: X)(implicit y: Y) extends B(x)(y) with C with D`
with an ERROR and cut the extends clause after `B(x)(y)`, so `C` and `D` never
became inheritance edges. Both copies now come from the v0.26.2 release: the
wasm is the release asset, parser.c/scanner.c are the tag's generated sources.
The grammar change is additive over the old pin: no node type or field was
removed.
On two real repos the share of Scala files that fail to parse drops to zero
(lila 85/1565, playframework 83/846), with no file newly failing. Edges from
those files were built from error-recovered trees; playframework, for
example, nested top-level classes inside their neighbours and drew an
`extends` self-loop.
The kernel defer pins used inputs that the new grammar reads cleanly; they
now use inputs that still fail, and the old inputs pin that both paths
extract them in parity.
(cherry picked from commit 199bc8d8a0)
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(extraction): name a function bound through a curried wrapper (#1747)
reactHookBoundName already names an anonymous function after the
variable_declarator that binds it. The shape is general, but the method
is bounded to three React hooks, so `const run =
Effect.fn("Session.run")(function* () {…})` produced no function node at
all -- and its body's calls were attributed to the enclosing container,
so a file gained an outgoing edge belonging to a function and the
callee's caller list named the file instead.
Bound the new path by a different, equally decidable test: the callee is
itself a call, i.e. a factory returning the wrapper. That admits
Effect.fn(...)(fn), connect(mapState)(fn) and a project's own
wrap("n")(fn), and excludes the single-call forms whose argument is a
computation -- useMemo(() => …, []), arr.map(…) -- which stay anonymous
exactly as before. Widening to "any callee" would have given useMemo a
function node and reddened react-hook-handlers.test.ts.
Generators are admitted here and not in reactHookBoundName: a React
handler is never a generator, while function* is the common form in the
ecosystem this shape comes from, and it is what the report opens with --
broadening the callee test alone would not have fixed that repro.
Mirrored in the Rust kernel; kernel-parity.mjs reports byte-parity on
the new shape.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WgtWMywGTyu6twnk1Bu9nP
(cherry picked from commit 4f2b40080d)
* fix(extraction): name a curried-wrapper function that is an object member (#1747)
The curried-wrapper bound stopped at a variable_declarator parent, so
`return { getMode: Effect.fn("ACP.Session.getMode")(function* () {…}) }`
still produced no function node. An Effect service is usually an object a
factory returns, and on sst/opencode (df23b7f) these member positions were
the bulk of what the branch missed.
The member already has a name in the source: its property key. This repo
names `key: () => {}` pairs by that key (extractObjectLiteralFunctions /
objectKeyName), so a `pair` parent is now named the same way. The
callee-is-a-call rule is unchanged, so `key: useMemo(() => …, [])` and
`key: arr.map(…)` stay anonymous.
extractObjectLiteralFunctions also reaches such a member, because an
exported object with an inline function member is extracted member by member
and its initializer is never walked.
A wrapper passed as an argument to another call has no binding at all and is
left as it was.
Mirrored in the Rust kernel; kernel-parity.mjs reports byte-parity on the
new shapes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dfb3aazPY1ccmp5vam4k3L
(cherry picked from commit bbdef20542)
* chore: drop CHANGELOG entry (collected separately)
---------
Co-authored-by: Max Hsu <maxmilian@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
The trail store saves up to 64 hops, /api/flow read at most 24, the
in-memory trail had no limit, and /api/nodes answers 60 ids per request.
So "Read as flow" failed on any walk of 25 or more hops, including trails
the store had just saved, and a cold load of a 61-64 hop link never got its
names back.
/api/flow now reads up to the store's MAX_TRAIL_HOPS. The trail keeps the
same 64 hops, dropping the oldest on push and on hydrate. resolveTrailNames
asks /api/nodes in batches of 60 and merges the answers.
(cherry picked from commit 4da454022d)
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
buildRoutes looked up node ids only for the first 60 distinct handler
files, one getNodesInFile query each, so every later row went out with
handlerId null and the viewer called the handler "not in the index". Load
the nodes of every handler file in one chunked query instead
(getNodesInFiles), which also drops the per-file query the cap existed
to bound.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
getImpactRadius, getCallers and getCallees are depth-limited DFS walks
with one visited set. A node first reached through a longer path at the
depth limit was marked visited without being expanded, so when a shorter
path reached it later it was skipped and its own dependents within the
limit were lost. Record the shallowest depth each node was expanded at
and expand it again when a nearer path reaches it. Results and edges are
still reported once, and output order is unchanged where nothing was
missing.
(cherry picked from commit ec56377b37)
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
`readJsonFile` copied an unparseable file to `<path>.backup` and warned
that it was about to be overwritten. That is the right thing to do just
before a write, but every target's `detect()` reads its agent's config
through the same helper — and `install --refresh` detects every target
in order to skip the ones codegraph was never installed into.
So an empty `~/.gemini/config/mcp_config.json`, sitting beside an
Antigravity install codegraph does not manage, got a 0-byte
`mcp_config.json.backup` and a warning about an overwrite that never
came. Detection is meant to be read-only.
`readJsonFile` is now a pure read. Preserving an unparseable config
moves to `writeJsonFile`, the one place a target replaces a JSON config
— so the backup still happens wherever it mattered, and only there.
Reads that decide not to write (the legacy-entry cleanups, the uninstall
sweeps) no longer leave one behind either.
Unchanged on purpose: an install that really does overwrite an empty
config still backs it up. Skipping the copy when there is nothing to
preserve is a separate call.
A Go method is only reachable through a value or a method expression, so a
bare call such as `relogin(ctx)` on a func parameter was being bound to a
same-named method in its own package, or (when capitalised) to an exported
method of a package the file does not import. Extend the #1714 receiver-less
check to Go, reading the call site back from source so the
`pkg.Factory().Method()` chain that reaches the resolver as a bare `Method`
ref keeps its edge.
Claude-Session: https://claude.ai/code/session_01MuSia5rNjiWCqzqW9iTJGD
(cherry picked from commit 812cf0d45f)
Co-authored-by: Max Hsu <maxmilian@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
On Windows this file leaked 171 temp directories per run and failed 4 tests, both from the same cause: things that hold the SQLite database open outlive the code that removes their directory.
afterEach removed tempDir only in the else branch of \if (cg)\, and cg is describe-scoped and never reset, so from the first test that assigns it every later test kept its directory. destroy() is a deprecated alias for close(): it releases the database but does not remove the project, so removal cannot be its alternative -- uninitialize() is the method that removes. Removal is now unconditional.
That alone turns the silent leak into EPERM, because five DatabaseConnection.open calls were never closed and four nested tests removed their own tempProject while the outer cg still held it open. Each connection is now closed once its rows are materialised, and each nested finally closes the graph before removing its directory.
Measured on Windows 11 with TEMP redirected to a private directory: before, 171 leaked directories and 4 failed / 196 passed; after, 0 leaked directories and 200 passed. Fixes#1777.
`extension_type_declaration` appears in none of the three places Dart's other
type-like declarations do. `extension_declaration` — the older `extension` — is
in all three, and the two names are near neighbours.
That is why #1780's `isInsideClassLikeNode()` gate dropped these members and no
others: the gate asks whether a class-like node is on the stack, and an
`extension type` never put one there, while `extension`, `mixin` and `class`
all did. The gate surfaced the omission rather than causing it. Before it, the
members were still reached — but as top-level `function:km` rather than
`method:MetersT::km`, indexed and attributed to nothing.
The kernel omits the same node type, so it walks the members through its own
fallback and mints them as top-level functions with no `MetersT` to belong to.
`kernel-dart-parity.test.ts` fails four cases on `main` because of it; fixing
only the wasm side would leave those red.
Listing it alongside the others is the whole fix — `extraClassNodeTypes` and
`dartEnclosingTypeName` on the wasm side, the two `matches!` arms on the
kernel's. Both paths now give:
class:MetersT · method:MetersT::km · method:MetersT::report
with `report`'s span running to its closing brace rather than stopping at the
signature line, and an ordinary class untouched.
Claude Code's UserPromptSubmit hook also fires for the
`<task-notification>…</task-notification>` blocks the host injects as
`user` messages when a background agent finishes. Those blocks are long
machine text full of identifier-shaped tokens, so they pass the structural
gate and the whole blob is sent to codegraph_explore as the query — a
3.5s median (7.4s max) stall on the blocking path, on text the user never
typed.
Recognize a prompt that consists solely of one task-notification envelope
(leading/trailing whitespace allowed) and exit before any project lookup,
gate or explore work. A prompt that merely mentions the marker, or has
text around it, is still treated as a user prompt.
Fixes#1832
Co-authored-by: danusha2345 <danusha2345@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Two bugs in the MyBatis mapper extractor:
1. A close tag with trailing whitespace (`</select >`, legal XML) was not
matched by the statement regex, causing the non-greedy body to overshoot
to the next close tag — silently swallowing the statement in between.
Fix: add `\s*` before `>` in the close-tag pattern.
2. A fully-qualified `<include refid="com.example.M.base">` had every dot
replaced with `::`, producing `com::example::M::base` — which never
matched the fragment node's `qualifiedName` (`com.example.M::base`).
Fix: split on the last dot only, matching `qualifyStatement`'s logic.
Also fixes the include-offset calculation to derive from the opening tag
length rather than subtracting the close tag, so it stays correct when the
close tag carries trailing whitespace.
Closes#1209
A directory removal adds no pending file, only needsFullScan. The retry
after a failed sync (lock contention or a generic failure) was gated on
pending files alone, so the owed full reconcile was dropped and the
removed directory's files kept their nodes. Reschedule while needsFullScan
is set as well. A regression test also pins the mid-sync scope-change case,
which already follows a scoped pass with a full scan.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
In a polyglot repo the Spring resolver is detected globally (a sibling
Java module with spring-boot in its pom is enough), and its resolve()
then ran on references from every language. Pattern 4's bare-name
fallback ('any [A-Z][a-zA-Z]+ name, prefer /model/ dirs, else ANY
same-named class') could therefore hijack a Scala 'extends ExtCustomer'
to an unrelated same-named test class, corrupting the inheritance graph
that impact analysis walks.
Two gates in front of the DI/convention patterns (1-5):
- skip refs whose language is not java/kotlin - Spring DI conventions
say nothing about other languages
- skip extends/implements refs entirely - inheriting from a class is
never a DI injection point; those must resolve via imports/name
matching
The Spring config-key resolution above the gates is untouched (it
already gates itself). Regression tests cover the hijack case and the
still-working Java DI path.
Co-authored-by: Hubert Tarnacki <hubert.tarnacki@comarch.com>
* fix: index Java packages named build (#1642)
* fix(extraction): preserve Java packages named build (#1642)
The default build-directory exclusion hid legal Java package paths before extraction.
Retain the contributor's main/test Java source-root exceptions, restricted to directories so other default exclusions survive.
Cover filesystem and git enumeration, explicit ignores, indexed retrieval, and incremental sync.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(extraction): preserve Java packages named build (#1642)
The default build-directory exclusion hid legal Java package paths before extraction.
Retain the contributor's main/test Java source-root exceptions, restricted to directories so other default exclusions survive.
Cover filesystem and git enumeration, explicit ignores, indexed retrieval, and incremental sync.
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>