Skip to content

v0.7.6

Choose a tag to compare

@sdsrss sdsrss released this 22 Mar 12:06
· 1208 commits to main since this release

v0.7.6 — Code Review Fixes

Critical Fix

  • Non-ASCII panic in semantic search: Fixed str byte-index slice that crashed on multi-byte UTF-8 characters (Chinese comments, Unicode identifiers, etc.) — now uses floor_char_boundary

Security

  • SQL injection hardening: find_dead_code type filter now uses parameterized queries instead of string interpolation
  • NULL metadata handling: get_callers_with_route_info no longer errors on NULL edges.metadata

Robustness

  • Idempotent migrations: Schema migrations now use add_column_if_not_exists, preventing "duplicate column" errors on interrupted migration recovery
  • Reduced peak memory: Oversized stdin message handling now frees the buffer before draining, cutting peak allocation from 2x to 1x MAX_MESSAGE_SIZE
  • Removed redundant dependency: Eliminated explicit libsqlite3-sys from Cargo.toml (already provided by rusqlite bundled-full)

Tests

  • 4 new protocol error-path tests: malformed JSON, wrong JSON-RPC version, missing tool name, unknown method
  • Fixed flaky test_e2e_incremental_reindex (missing server initialization)
  • Fixed flaky test_watcher_detects_file_changes (replaced sleep(200ms) with recv_timeout(5s))
  • Corrected misleading concurrent test documentation

Cleanup

  • Removed dead #[cfg] branches in pid_is_alive (unreachable unix paths inside not(unix) gate)
  • Removed redundant fts5_triggers_sql() wrapper function
  • Improved unsafe block safety comment for SQLite extension registration
  • Added lock ordering documentation for drain_watcher_events