Repository navigation
v0.22.1 — bounded shutdown, atomic embedding sidecars
Bound the graceful shutdown; stop trusting a stale embedding sidecar.
- serve --web now sets uvicorn timeout_graceful_shutdown=10. Unset it defaults
to None, and uvicorn drains open connections before running the ASGI lifespan
that closes the MCP session manager, so an open GET /mcp stream made shutdown
an unbounded wait. Half of recent stops hung the full systemd TimeoutStopSec
and ended in SIGKILL. - Embedding sidecars are written through a temp file + os.replace(). np.save()
opens its target O_TRUNC on the same inode, and the server keeps every sidecar
mmap'd, so indexing from a second process rewrote pages under the live map. - A sidecar whose metadata disagrees with its matrix is now refused at load
instead of returning a real-but-wrong symbol from an out-of-date symbol_ids. - Workspace mode compares sidecar version against index.db when the sidecar is
loaded and reports drift as stale_sidecars in /healthz degraded. Previously
semantic search could serve a subset of a repo while embedding_status, which
counts rows in the database, reported full coverage.