Skip to content

Release CodeStory 0.17.6 - #2403

Merged
TheGreenCedar merged 899 commits into
mainfrom
dev/codestory-next
Sep 27, 2026
Merged

TheGreenCedar merged 899 commits into
mainfrom
dev/codestory-next

Conversation

@TheGreenCedar

@TheGreenCedar TheGreenCedar commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Ready for combined promotion/publication approval. Candidate d4a112cfe9e7813856f1cadbbf279e53413e72f6, tree ad20a4fef1e65050feb200436c82dba1ced2523f, is the independently reviewed constants-only child of accepted source 912dfa06b4f0288476062e73843a78b2eedd8aa4. Source stabilization, Metal calibration, frozen acceptance, qualification, and pre-publish verification are authenticated. All ten pre-publish cells passed: source lineage, three archive identities, three accelerated runtime checks and three installed-candidate checks. None failed, were missing or were withheld. The macOS archive is signed and notarized. The controller adopted this existing PR as the concrete promotion; it remains draft and no approval is recorded. Publication, catalog delivery and post-publish verification follow the combined approval.

CodeStory 0.17.6 rebuilds the evidence engine behind repository search, source inspection and code navigation. Agents can search declaration comments, inspect verified source ranges and follow language relationships while index updates publish complete, immutable generations. The frozen candidate has completed qualification and pre-publish verification. This PR remains a draft promotion into main awaiting the combined maintainer approval.

The user-visible changes are consolidated in the changelog. Review three connected areas:

  • Evidence and navigation: search, context and packet responses carry evidence identities, status and explicit gaps. Scope, visibility, receiver bindings and source provenance constrain language relationships. Packets remain experimental, limited to sixteen evidence rows and a complete MCP result of 16 KiB, and make no answer-sufficiency claim.
  • Indexing and recovery: changed-file refresh remains incremental on supported filesystems without native cloning, using cancellable copies. Capacity checks report required and available bytes before full-size staging. Readers retain a complete generation through publication, and cleanup respects reader leases and retained rollback references. A successful upgrade retires the redundant standalone database; in-use or replaced files are deferred, and user annotations remain in their sidecar. This describes behavior, not a measured disk-saving or speed claim.
  • Runtime and delivery: requests select their project explicitly, status and plain readiness remain observational, and executable identity is checked at the plugin/runtime boundary. Cold tool calls retain their original request through preparation, reporting progress when requested and returning the requested evidence, a real error, cancellation or a bounded deadline. Ordinary preparation waits up to 120 seconds; packet keeps its existing spent latency budget. Deadline responses include exact-operation resume arguments. The shipping Cargo graph excludes proof-only support. Focused HTTP transport fixes preserve bounded responses when clients stall or keep sending data.

Breaking upgrade despite the patch version: publication schema 3 replaces the previous search hit, context and packet response shapes. MCP protocol negotiation does not translate schema 3 back to schema 2. Install matching CLI and plugin versions, start a fresh host session, and update custom response consumers. Removed MCP packet fields include task_class, extra_probes and include_evidence; obsolete inputs are rejected. --diagnostics-out replaces --step-trace-out, and search --why and --plan-details are retired. The global framework catalog is opt-in through include_framework_coverage or --include-framework-coverage; an omitted catalog does not mean no frameworks are supported. The upgrade guide gives the exact surface distinctions and migration examples.

The cache moves from schema 31's single database to schema 35's immutable core generations. Managed preparation upgrades or rebuilds derived state and preserves annotations. If rollback is required, stop clients and preserve a complete pre-upgrade cache, its annotation sidecar, and the authenticated 0.17.5 archive/checksum. Do not point 0.17.5 at an upgraded cache. Keep the upgraded cache separately: restoring a snapshot does not include annotations added afterward. A complete legacy rollback image is made through coherent SQLite backup, including committed WAL data; an interrupted incomplete legacy image is never offered as rollback.

All 66 retained review findings and 71 assertion records have resolved dispositions; #2404 is closed after the final independent six-flow review and accepted source stabilization. Final integration includes preparation waiting (#2516), preserving the underlying symbol-worker error (#2518), the changelog fold (#2520), equivalent lint corrections (#2522/#2524), cache retirement and migration-consumer repairs (#2527), and Python annotation/cache identity plus exact JavaScript assertion and snapshot corrections (#2528). Both final support merges have trees identical to their independently accepted candidates. Storage verification detected 13 production mutations plus two test-oracle perturbations, with 35 fixed/restored test executions passing. Language verification detected 11 meaningful production mutations plus one separate golden perturbation, with 36 fixed/restored executions passing; complete owning suites passed 410 distinct listed tests. Ineffective or surviving secondary mutation controls remain documented and are excluded from detection totals. The prior failed full source run is preserved. The generated constants-only child is now integrated as #2530.

Native staging and annotated-upgrade evidence retains source 048ea8c7fa99ec3340651edf3f1eb645e50f7a0a, tree 62e7f8555d44648fe3e6f9c811c922fd6f3892c4, on Mac and Windows. APFS clone/HFS+ copy and NTFS copy/ReFS clone staging, real Metal/Vulkan initial and edit indexing, and annotated legacy-upgrade cases passed within those receipts. The later Windows 363df800 build supplies the replay and full comparison results below, not a new execution of those staging and annotation probes. Windows uses its unchanged default 1 MiB executable stack. The WSL ext4 production-store probe passed copy, ownership and partial-cancellation cases; it does not establish Linux retrieval or accelerator execution. These are historical receipts, not new executions of 912dfa06; subsequent storage and language repairs have separate source evidence. Earlier rejected candidates and local macOS test failures remain recorded, without a claim that the full macOS workspace suite passed.

The descriptive disk comparison in #2507 completed initial indexing, five one-file edits and an authenticated legacy-cache upgrade on Mac HFS+ and Windows NTFS:

Host/filesystem Median edit seconds, 0.17.5 → candidate Final allocated GB, 0.17.5 → candidate Candidate upgrade seconds / final GB
Mac HFS+ 202.5 → 38.2 1.536 → 2.923 70.2 / 2.094
Windows NTFS 94.7 → 85.0 1.426 → 2.765 121.0 / 1.959

Sizes use decimal GB and count hard links once. Mac executable source is 048ea8c7; Windows executable source is 363df800973796b28b0e10a87bed74c7027824a3, tree 7d36fd82b59ef0dc80355a3583899c98418ba2a8; the measured integration snapshot 4ca7ae63 differed only in release notes, and historical a34b7040 added four equivalent test expressions. Current 912dfa06 also contains storage and language production repairs outside these measured executables. Each comparison used the same frozen 1,216-file corpus and cumulative edits. This is one ordered whole-version observation, not equal work: document/projection counts differ and both versions report the same unreadable binary fixture. Order was not randomized and OS caches were not flushed. Largest complete directory scans are non-atomic observations, not exact peaks or guaranteed lower bounds. No general performance, disk-saving or answer-quality claim is made.

The Mac cache contains an unreferenced 826.88 MB third core image consistent with best-effort cleanup lag, separate from selected rollback storage. Subtracting it is arithmetic, not an executed cleanup, and still leaves about 0.560 GB over baseline. Albert accepted keeping the current rollback policy for 0.17.6. A tighter cleanup policy is separate work. The Windows upgrade measurement had empty bookmark/category lists; nonempty preservation remains supported by the separate annotated native probe.

The earlier Windows candidate failed on edit 4. Its original cache and failure receipt are preserved, and the discarded staged database prevents a direct reconstruction. #2518 preserves the underlying error and makes failed symbol sessions terminal; independent controls detect four deliberate faults and restored behavior passes. One isolated edit-4 replay and the final full sequence passed, but the original cause remains unknown.

The 912dfa06 shipping build is installed through the canonical CodeStoryDev installer, with plugin data preserved. Staged and installed CLI SHA-256 is 61bb1005eb496cbd0af3f5e688ead3f4e895dc65b11eca2efa8d88547c4c6784. A fresh launcher authenticated matching 0.17.6 identities and 20 tools. One original cold ground call stayed pending for 40.6 seconds, emitted 35 increasing progress notifications and returned actual map evidence without caller retry, then shut down normally. It used isolated state and the frozen corpus. A single current-host ComiComic call now also succeeds and returns a map covering 529 files. That warm response includes no loaded executable identity; it does not establish worker reload or reproduce the historical cold preparation. No real project cache was reset or host reconnect forced. This is a development installation, not released-archive qualification.

The source jobs at 4ca7ae63 and 1f2e0755 compiled the workspace but failed test-only lint; both full test suites were skipped. The a34b7040 source run then passed compilation, lint and Windows contracts, but its full suite had 4,367 passed, 10 failed and 36 skipped tests. Those ten cases motivated the final support repairs. The new 912dfa06 source receipt is accepted: 4,381 passed, zero failed and 36 skipped tests; the doctest commands completed with zero doctest cases. Three fresh protected Metal calibration runs are authenticated, and their sole generated constant-set child d4a112cf is integrated. Frozen acceptance, qualification and all ten pre-publish cells are authenticated at that exact head. Qualification includes all three package/driver builds, the clean Linux shipping-build boundary, and protected Metal and Windows Vulkan execution. Pre-publish verification then installed each exact candidate archive and passed accelerated runtime checks on protected macOS, Windows and Linux hosts. The complete workspace source proof is retained from the parent and is not repeated on the generated child. PR #2403 remains draft. The standard release claim is exact archives installed on Apple Silicon macOS, Windows x64 and Linux x64, with one real project-scoped accelerated ground per platform and authenticated runtime/archive identity. Optional answer-accuracy and performance evaluation are outside that claim.

The previous qualification belongs only to historical candidate f26ab0d6106f5e9cc7fdbd4eea1b09a3253e19f1, tree 05277cd6374128ffdd8a055128b3b5360c7045da. Its pre-publish run did not publish a release or catalog. Later source changes invalidate it for the current candidate. Keep #2135 open: promotion and publication require the concrete qualified candidate and the repository's combined maintainer approval. The canonical workflow owns tagging, signing, checksums, catalog delivery and installed/live closeout.

The qualified frozen-candidate archives recorded with the combined approval are:

Target Archive SHA-256
linux-x64 codestory-cli-v0.17.6-linux-x64.tar.gz fb0278dfbfe23b9f144dab15a8fa42abfed6eee93f23708bac59203c5357a78f
macos-arm64 codestory-cli-v0.17.6-macos-arm64.tar.gz a79059f1072ac2f699945284d74f34ff3fffa6233b230ded8a094cea92d2cc75
windows-x64 codestory-cli-v0.17.6-windows-x64.zip b3b84acdad32c463887cbed0992a319039289818cb178555c3e69deb55ebdcee

The accepted pre-publish closeout is run 36310591825, attempt 1, artifact 10929264566, container digest sha256:dae53dc4dcdd5210b87c8d17872154c8bf79fd909a4474ecdaada70cf8ad5db7. Approval records these qualified frozen-candidate archive identities and source. The tree-preserving main promotion starts the automatic workflow, which builds fresh archives at the promotion commit, authenticates their own pre-publish package and installed/accelerator cells, and publishes only after that ledger is accepted. Published-download verification compares those published bytes with that same run’s accepted archive identities. Catalog delivery and installed/live closeout remain separate final steps.

Refs #2135. Refs #2404.

TheGreenCedar and others added 30 commits September 18, 2026 13:15
Co-authored-by: Cursor <cursoragent@cursor.com>
…ace-tests

[codex] clear Phase E source-stab workspace test failures
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…tion-status

[codex] clear Phase E stab residual: generation-only status readiness
Product deps for qualification only need proof-qualification-support;
moving benchmark-support to dev-deps stops Cargo feature-unification
from contaminating packaged CLI builds.

Co-authored-by: Cursor <cursoragent@cursor.com>
Live debian-security indexes publish superseded glibc .debs that 404;
use the rust bullseye image snapshot date so clang pins stay fetchable
without raising the glibc 2.31 floor.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Open the staged codestory.db with a write-capable handle before
FlushFileBuffers so core_freshness publish no longer fails os error 5.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Packaged Windows Vulkan qualification accepted crash_server then waited
75s for the PID to exit; CRT abort can stall under loaded accelerators,
so fail-stop now uses TerminateProcess and drains before terminating.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
* preserve declared Java type visibility

* keep Java reference visibility separate from declarations
TheGreenCedar and others added 13 commits September 26, 2026 10:51
[codex] restore permission fixtures for Clippy
[codex] separate shipping call path from qualification
* bound http response teardown

* prove bounded http drain

* cover queued http request bytes
* stage sealed files with bounded copy and space checks

* retain incremental retrieval work across filesystems

* surface disk refusals through runtime and cli

* document incremental disk behavior

* prove copied component refusal and cancellation

* describe immutable core publication

* preserve disk errors and file sync failures

* preflight native staging and prove sync boundaries

* preserve scip stage cleanup on error

* bound http response teardown

* prove bounded http drain

* cover queued http request bytes

* assert cancellable incremental snapshot staging
* stage sealed files with bounded copy and space checks

* retain incremental retrieval work across filesystems

* surface disk refusals through runtime and cli

* document incremental disk behavior

* prove copied component refusal and cancellation

* describe immutable core publication

* preserve disk errors and file sync failures

* preflight native staging and prove sync boundaries

* preserve scip stage cleanup on error

* bound http response teardown

* prove bounded http drain

* cover queued http request bytes

* assert cancellable incremental snapshot staging

* retire legacy core after immutable publication

* keep legacy sidecars when database deletion defers

* sync legacy parent before confirming retirement

* retire replaced incomplete legacy cores

* test uncommitted legacy retirement receipt

* update activation tests for retired legacy cores
* test sealed copy on a bounded stack

* move sealed copy buffer to heap

* make source drift tests observer independent

* test delayed source observer refusal

* test delayed same metadata source drift
* keep mcp calls pending through preparation

* fix preparation wait boundary regressions
@TheGreenCedar
TheGreenCedar deployed to macos-metal-release September 27, 2026 08:13 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to macos-metal-release September 27, 2026 09:21 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to windows-vulkan-proof September 27, 2026 09:21 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to macos-metal-release September 27, 2026 09:36 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to macos-release-signing September 27, 2026 09:54 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to macos-metal-release September 27, 2026 10:20 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to windows-vulkan-proof September 27, 2026 10:20 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar deployed to linux-vulkan-proof September 27, 2026 10:20 — with GitHub Actions Active
@TheGreenCedar
TheGreenCedar marked this pull request as ready for review September 27, 2026 11:16
@TheGreenCedar
TheGreenCedar merged commit f3966ca into main Sep 27, 2026
78 checks passed
@TheGreenCedar
TheGreenCedar deleted the dev/codestory-next branch September 27, 2026 11:16

This branch was successfully deployed

4 active deployments
linux-vulkan-proof — d4a112cf Deployed Sep 27, 2026 by TheGreenCedar via linux-vulkan-proof / Packaged Linux Vulkan engine #34
macos-metal-release — d4a112cf Deployed Sep 27, 2026 by TheGreenCedar via macos-metal-proof / Packaged Apple Silicon Metal engine #34
windows-vulkan-proof — d4a112cf Deployed Sep 27, 2026 by TheGreenCedar via windows-vulkan-proof / Packaged Windows Vulkan engine #34
macos-release-signing — d4a112cf Deployed Sep 27, 2026 by TheGreenCedar via packaged-proof / Build macos-arm64 #34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant