Skip to content

feat: land the post-v1.6 upstream sync with v1.6.1 corrections - #275

Merged
sunerpy merged 3 commits into
mainfrom
sync/product-integration
Sep 30, 2026
Merged

sunerpy merged 3 commits into
mainfrom
sync/product-integration

Conversation

@sunerpy

@sunerpy sunerpy commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

Second of two PRs landing the 2026-09-15 upstream sync (colby 3ed73bc audit) — the product changes on top of the engineering baseline in #271. Several ports were re-checked against the final forms upstream shipped in v1.6.1 (2026-09-29) and now follow them. Tracked upstream parity stays v1.6.0 in this PR; the v1.6.1 alignment continues in follow-up PRs and is closed in UPSTREAM.md only after a release.

Per-item evidence is in docs/upstream-sync/POST_V1_6_MAIN_2026-09-15.md → Implementation status.

Graph semantics — extraction version 12 → 13

  • TS/JS: generator callables, interface members, nested declarator handlers, CommonJS exports, React useCallback/useEffectEvent and curried wrappers (#1741 #1638 #1669 #1675 #1747).
  • C/C++: constructor resolution with namespace/arity proof, pure virtual methods, raw strings opaque to macro blanking, bounded designated-initializer macros (#1839 #1727 #1505 #1729).
  • Scala grammar =0.26.2, multi-parameter lists and mixins; companion objects are modules, never inheritance targets, and own their methods (#1823 #1824). Dart 3 extension types (#1784).
  • Method values passed as callbacks become References with fnRef (#1820), never fabricated Calls.

Resolution safety (upstream v1.6.1 forms)

  • Cross-file visibility for C statics, private JVM/Swift/Scala/Dart/PHP, Go package-locals and Rust module-private items (#1730/#1731); sealed JS modules read markers after blanking comments, strings and templates (#1719); calls to JSON require constants are rejected.
  • No receiver guesses: call results (#1683), receiver-less JS calls (#1714), receiver-less Go calls never bind methods (#1857), this.field needs a declared type (#1496), awaited receivers follow the #1885 inference (#1840); typed method lookup matches within a language family, so .tsx reaches .ts.
  • Rust self.method() binds to the impl owner and declines ambiguous same-named owners (#1861/#1882). Fuzzy matching judges its single survivor and keeps closures unreachable, while C/C++ nesting stays reachable (#1708).
  • Function-like macros and aggregates never fabricate calls (#1838); filesystem fallbacks prove containment (#1631).

CLI, MCP, installer, lifecycle

  • callers/callees/impact grouped by definition with truncation metadata (#1512 #1639 #1674); node file:42, :a-b, #L42-L80 (#1831); committed pending changes in status (#1829); unsupported-only and extensionless-path honesty (#1502 #1830); collapsed-parse warning (#1522).
  • Explicit projectPath projects are live-synced through the shared daemon and re-attached if the daemon exits or the index is re-created (#1835); one kernel-locked long-lived writer per project (#1740); atomic edge rebinding (#1833/#1849); explicit child index refuses an initialized ancestor (#1524).
  • Installer: CLAUDE_CONFIG_DIR/CODEX_HOME (#1627), native OpenCode 2 entries (#1698), Explore kept loaded (#1696); prompt hook capped at 9,000 bytes and skipping task-notification envelopes (#1694 #1832).

Resolution performance

A post-audit review found the new gates rescanned whole files per reference. Per-file source facts are now built once per resolution pass. init of generated single-file corpora (5,000 references each; one run, same host):

corpus v0.50.3 user s / RSS MB 2026-09-15 integration this PR
JS 5,000 distinct bare calls 11.45 / 53 34.17 / 121 11.62 / 56
JS 5,000 same-name bare calls 0.15 / 24 11.49 / 59 0.24 / 29
TS this.field + awaited receivers 24.63 / 100 26.53 / 99 27.16 / 106
Go / C / Rust within ±2% within ±2%

Verification

  • env -u RUSTUP_TOOLCHAIN make pre-ci: all checks passed; 3,704 tests, 0 failed; archive smoke codegraph 0.50.3.
  • Golden drift check: all 19 re-indexable corpora regenerated with this build are byte-identical to the committed goldens (TypeScript 14→16 and C-family 19→23 files, new Scala/Dart corpora; old rows unchanged).
  • cargo audit --no-yanked: no vulnerabilities.
  • This tree equals the integration branch except the CI fixes that landed in ci: harden CI and releases, refresh governance docs #271.

BEGIN_COMMIT_OVERRIDE
feat(extract): index generator callables, TypeScript interface members, nested handlers, CommonJS exports and React handler hooks
feat(extract): resolve C++ constructor calls and index pure virtual methods, Scala companions and Dart extension types
feat(resolve): record methods passed as callback values as function references
fix(resolve): enforce cross-file visibility for C statics, private JVM/Swift/Scala/Dart/PHP, Go package-local and Rust module-private definitions
fix(resolve): refuse unproven receivers for call results, bare JS and Go calls, this.field and awaited values
fix(resolve): bind Rust self.method() to its impl owner and keep sealed JS modules off cross-file targets
fix(resolve): stop function-like C/C++ macros and aggregates from fabricating calls
feat(cli): group callers, callees and impact by definition and report truncation
feat(cli): accept line-numbered file selectors in node
feat(cli): report committed but unindexed changes in status and warn on collapsed parses
feat(mcp): keep explicit projectPath projects live-synced through the shared daemon
feat(install): honor CLAUDE_CONFIG_DIR and CODEX_HOME, write native OpenCode 2 entries and keep Explore loaded
fix(prompt-hook): cap injections at 9,000 bytes and skip task-notification envelopes
fix(daemon): allow one long-lived writer per project with a kernel lock
fix(store): rebind edges atomically during incremental sync
fix(index): refuse to retarget an initialized ancestor from an explicit child path
perf(resolve): build per-file source facts once per pass instead of rescanning files per reference
END_COMMIT_OVERRIDE

🤖 Generated with Claude Code

Graph semantics (extraction version 13): generator callables, TypeScript
interface members, nested declarator handlers, CommonJS exports, React
handler hooks and curried wrappers; C++ constructor calls, pure virtual
methods, raw strings and designated-initializer macros; Scala multi-parameter
lists, mixins and companion objects; Dart extension types; method values
passed as callbacks as function references.

Resolution safety: cross-file visibility for C statics, private JVM/Swift/
Scala/Dart/PHP definitions, Go package-locals and Rust module-private items;
no receiver guesses for call results, bare JS calls, receiver-less Go calls,
unproven this.field or awaited receivers; Rust self.method() bound to its
impl owner; sealed JS modules; function-like C/C++ macros and aggregates
never fabricate calls. Gates follow upstream's v1.6.1 final forms and read
per-file source facts built once per resolution pass.

CLI/MCP/installer/lifecycle: callers/callees/impact grouped by definition,
line-numbered node selectors, committed pending changes in status,
unsupported-only and extensionless-path honesty, parse-collapse warnings,
live-synced explicit projectPath projects, a kernel writer lock, atomic
edge rebinding, explicit child-index safety, profile-directory, OpenCode 2
and Explore-loading installer support, and prompt-hook bounds.
@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 93.34959% with 409 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
crates/codegraph-cli/src/main.rs 86.64% 84 Missing ⚠️
crates/codegraph-resolve/src/resolver.rs 92.85% 47 Missing ⚠️
crates/codegraph-resolve/src/awaited.rs 94.70% 28 Missing ⚠️
crates/codegraph-resolve/src/name_matcher.rs 96.86% 28 Missing ⚠️
crates/codegraph-daemon/src/writer_lock.rs 89.18% 24 Missing ⚠️
crates/codegraph-mcp/src/rmcp_handler.rs 66.66% 24 Missing ⚠️
crates/codegraph-daemon/src/project_service.rs 84.09% 21 Missing ⚠️
crates/codegraph-extract/src/walker.rs 93.40% 19 Missing ⚠️
crates/codegraph-mcp/src/engine.rs 96.10% 19 Missing ⚠️
crates/codegraph-extract/src/lang/cpp.rs 92.03% 16 Missing ⚠️
... and 17 more

❌ Your patch check has failed because the patch coverage (93.34%) is below the target coverage (95.00%). You can increase the patch coverage or adjust the target coverage.

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #275      +/-   ##
==========================================
- Coverage   95.34%   95.22%   -0.12%     
==========================================
  Files         145      151       +6     
  Lines       85751    91465    +5714     
==========================================
+ Hits        81761    87100    +5339     
- Misses       3990     4365     +375     
Files with missing lines Coverage Δ
crates/codegraph-cli/src/installer/mod.rs 91.57% <100.00%> (+0.10%) ⬆️
crates/codegraph-cli/src/installer/registry.rs 98.63% <100.00%> (+0.01%) ⬆️
...codegraph-cli/src/installer/targets/antigravity.rs 96.18% <100.00%> (+0.03%) ⬆️
...ates/codegraph-cli/src/installer/targets/claude.rs 96.03% <100.00%> (+0.59%) ⬆️
...rates/codegraph-cli/src/installer/targets/codex.rs 97.48% <100.00%> (+0.31%) ⬆️
...tes/codegraph-cli/src/installer/targets/copilot.rs 99.00% <100.00%> (+0.01%) ⬆️
...ates/codegraph-cli/src/installer/targets/cursor.rs 98.58% <100.00%> (+0.01%) ⬆️
...ates/codegraph-cli/src/installer/targets/gemini.rs 98.88% <100.00%> (+0.01%) ⬆️
...ates/codegraph-cli/src/installer/targets/hermes.rs 98.13% <100.00%> (+0.01%) ⬆️
crates/codegraph-cli/src/installer/targets/kiro.rs 100.00% <100.00%> (ø)
... and 48 more
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3d891dc3ba

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +3837 to +3840
// A failed transport attach does not grant a second watcher. Keep the
// request path available as a read-only direct session while the live
// daemon retains the sole background-writer capability.
serve_direct_stdio(project, explicit_project_services(no_watch))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Recover live services after a failed daemon attach

When daemon_already_running is fooled by a reused PID, or the recorded daemon has a missing socket or incompatible hello, proxy_to_running_daemon returns None and this branch now starts a permanently read-only session without catch-up or a watcher. The previous fallback called serve_direct, so this change silently leaves the session serving a stale graph; attempt writer ownership and start direct services when no daemon actually owns them, or fail instead of silently disabling synchronization.

AGENTS.md reference: AGENTS.md:L56-L58

Useful? React with 👍 / 👎.

Comment on lines +194 to +198
let source: &str = &self.source;
LocalBindingSites {
var_decls: keyword_sites(source, &["const", "let", "var"]),
fn_decls: keyword_sites(source, &["function", "class"]),
arrows: source.match_indices("=>").map(|(at, _)| at).collect(),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Mask comments and strings before finding JS bindings

Because binding sites are collected from raw source, text such as // const run = mock or a string containing function run is treated as a real local binding. When the file later calls an imported/cross-file run(), is_locally_bound_js_name filters out the valid target and leaves the call unresolved; derive these offsets from the comment/string-blanked view instead.

Useful? React with 👍 / 👎.

Comment on lines +1165 to +1168
let line = facts.raw_line(index).unwrap_or("");
if impl_header.is_match(line) {
let code = line.split_once("//").map_or(line, |(code, _)| code);
return for_clause.is_match(code);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Accumulate multiline Rust impl headers before checking for

For a normally formatted multiline trait impl such as impl<T> followed by Trait for Type<T>, the upward scan reaches the impl line and immediately tests only that line for for. It therefore classifies the trait method as an ordinary private inherent method, and calls from outside the defining module are rejected by the new cross-file visibility gate. Join the impl header through its opening brace, or inspect the syntax tree, before deciding whether it is a trait impl.

Useful? React with 👍 / 👎.

Comment thread docs/cli.md
Comment on lines +158 to +163
> **Kiro global versus project-local.** A global Kiro install writes a bare
> `serve --mcp` entry with no `--path`. It can list tools and query any existing
> index when the agent supplies `projectPath` per call, but it does not own a
> project's live watcher. Run `codegraph init --target=kiro <project>` (or a
> local Kiro install from that project) to write a project-level entry with an
> absolute `--path` and enable live catch-up/watch. Kiro does not expand

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Describe global Kiro's actual live-sync behavior

This read-only claim is false after this commit: every non-opted-out MCP process installs explicit_project_services, and an explicit projectPath calls ProjectServiceBroker::ensure, which starts or attaches the project's daemon and performs catch-up. Global Kiro users can therefore trigger a watcher without a local install, contrary to both this canonical documentation and the installer notes; update those claims or explicitly disable the broker for this target.

AGENTS.md reference: docs/AGENTS.md:L5-L8

Useful? React with 👍 / 👎.

Comment thread docs/equivalence.md
`pure_virtual.cpp`, `raw_string.cpp`, `designated_macro.c`,
`template_method.cpp`, `templated_call.cpp`, `ue_actor.h`, `union_agg.c`,
`union_agg.cpp`, `union_agg.mm` — 19 files). The inheritance base
`union_agg.cpp`, `union_agg.mm` — 23 files). The inheritance base

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Derive or remove the hard-coded corpus size

The newly updated 23 files assertion is not derived or checked by scripts/docs-check.py or a product test, so the next corpus addition can leave this canonical regeneration guide stale while all validation still passes. Either remove the count or add a source-contract check that derives it; the same issue applies to the newly changed TypeScript count below.

AGENTS.md reference: docs/AGENTS.md:L12-L14

Useful? React with 👍 / 👎.

Windows LockFileEx locks are mandatory, so reading the holder's pid/mode
record from inside the kernel-locked writer.pid failed for every other handle
and the contention message could not name the owner. Publish the record in a
sibling writer.json (atomic rename) that is trusted only while the lock is
held; writer.pid itself is never written.
@sunerpy
sunerpy force-pushed the sync/product-integration branch from 19ca839 to 9600281 Compare September 30, 2026 14:15
Git exports GIT_DIR and the other repository-locating variables to hooks.
The committed-pending status test inherited them from pre-push and committed
its throwaway fixture into the branch being pushed. The test now strips the
variables for every git child, and the pre-push hook clears them before
running the gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant