file_hash salted the content digest with the resolved (symlink-collapsed) path, so a
symlink alias and its target hashed identically and one displaced the other from the
graph on a warm cache. Salt with the walked (lexical abspath) path relative to root
instead, giving aliases distinct keys; when the scan root itself is a symlink, derive
the leaf-relative salt from the lexical ancestor matching the resolved root. The
detect-layer containment guard (which resolves to block symlink escape) is untouched.
Converted Office/Google-Workspace sidecars were written to `root/GRAPHIFY_OUT/converted`,
always anchored to the scanned source tree, so `graphify extract --out <dir>` against a
read-only or pinned checkout polluted the source tree. Route sidecar writes through the
cache root while keeping the content hash anchored to the scan root, so sidecar filenames
stay stable across checkouts.
Fails on the current sanitizer in 4 of 5 cases: Korean/Japanese/accented labels
lose their letters, distinct communities collapse to the same tag, and the
graph-view colour group queries a tag no note carries.
_obsidian_tag stripped every non-ASCII character, so a Korean or Japanese community label collapsed to underscores and every note in that community carried the same tag. Python's \w is Unicode-aware, so switching the filter keeps letters from any script while still dropping spaces and punctuation.
Also route the .obsidian/graph.json colour-group query through the same sanitizer: it was built from the raw label, so on a non-ASCII label it queried a tag that no note carries.
The header logic is unit-tested, but only a real subprocess run proves the CLI
query command actually passes the resolved graph path through — the wiring that
was the point of #2789. Cover both the under-CWD relative form and an explicit
--graph outside the CWD shown in full. Plus 0.9.47 changelog entry.
The query header now leads with the graph file it opened and its node count,
shown relative to the CWD when the graph sits underneath it and absolute when it
does not — surfacing the case where a query run from a parent project silently
answers from the wrong corpus. graph_path is optional, so the header is
byte-identical for callers that do not pass it; the CLI query command and the MCP
query tool, which already resolve the path for querylog, now pass it.
The factory-object owner path emitted the `contains` edge inside the per-member
loop; add_node dedups on id but add_edge does not, so N methods assigned to one
object flooded the graph with N identical contains edges. Emit it once per owner.
Tests: assert a single contains edge across four methods, cover arrow-function
assignment (the dominant modern factory shape), and lock the negative case that a
non-object-literal receiver (`external.handler = fn`) is not captured.
Preserve callable members assigned to a local object-literal factory API
(`const api = {}; api.foo = fn`), modeling the API object beneath its factory
and attaching the assigned functions as methods. The lazy owner-node minting
(only for identifiers proven to be object-literal bindings in the enclosing
function) avoids the #1077 config-object flood.
Partially addresses #2524 (the object-literal-method shorthand form
`return { foo() {} }` remains out of scope).
Covers the ensure_ascii write path the field-order stabilization implicitly
relies on: a reordered node dict carrying escaped-unicode values must serialize
byte-identically across a read-rebuild.
node_link_data always appends the node key (id) last, so id sat mid-dict on a
cold build but last after a read-rebuild — churning graph.json key order with
no content change and defeating byte-stable caching. to_json now canonicalizes
each node/link dict (id / source,target,relation first, remaining keys sorted)
before serialization, so a load -> rebuild -> write round-trip is byte-identical.
Pure key permutation; values are untouched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the multiple-text-block test the deep-dive flagged: the helper must return
the FIRST text block (graphify's claude calls carry a single JSON payload, so
concatenating would corrupt it). Adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Extended thinking is on by default on current Claude models, so a response's
content[0] is a ThinkingBlock and the old content[0].text raised AttributeError
on the SDK claude backend. A shape-aware helper (mirroring the existing
_bedrock_response_text) skips leading non-text blocks and returns the first
text block; a thinking-only response falls back to the default. Only the two
SDK claude call sites are touched; the claude-cli JSON-envelope path is unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the two cases the deep-dive flagged: the kind='ast' path (the literal
graphify update scenario) stays byte-identical on a no-op and updates on a real
edit; and a corrupt/unparseable existing manifest still gets written (the
byte-equality skip's except must never silently drop a real update). Also adds
the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
save_manifest unconditionally stamped a fresh 'seen' timestamp for every file
on every run, so a no-op graphify update rewrote all manifest entries and left
graphify-out/ permanently dirty (a trailing graph commit on every push). Now
the per-file 'seen' is preserved for genuinely unchanged entries, and the disk
write is skipped entirely when the serialized manifest is byte-identical to
what is already on disk; a real change still refreshes and persists.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the two cases the deep-dive flagged: a built-in-typed primary-ctor param
(int count) must not fabricate a referenced node, and the branch's struct_declaration
claim is locked by a struct primary-ctor test. Also adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A C# 12 primary constructor puts its parameters on the class/record declaration
itself, which the extractor never walked: class Holder(IDep dep) emitted no
references edge Holder->IDep, and because dep was never registered in the class
receiver table, a dep.Method() call inside the class was dropped too. Scan the
declaration's parameter_list, register each param name->type, and emit the
param type reference — mirroring the field/property handlers. Built-in and
type-parameter types are not fabricated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AST-emitted INFERRED edges landed at the rubric-forbidden 0.5 (or a hardcoded
0.8). Each AST INFERRED emission site now sets a discrete rubric score keyed to
the relation (uses -> 0.95 direct structural evidence, indirect_call and
unresolved cross-file calls -> 0.85), and the INFERRED write-time default moves
0.5 -> 0.55 so any score-less INFERRED edge is on the rubric set. EXTRACTED /
AMBIGUOUS tiers are unchanged; uses stays INFERRED (not promoted to EXTRACTED)
to keep audit percentages honest.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the round-trip idempotency check the deep-dive flagged: after the first
load heals a legacy numeric confidence to INFERRED, reloading the persisted
graph stays silent with a stable score (the warning must not just move one run
later). Dates 0.9.46, opens 0.9.47.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A pre-enum graph.json stored a numeric edge confidence (a float) instead of a
string tag, which tripped the per-edge 'invalid confidence' validator warning on
every incremental reload. _fold_edge_aliases now moves a numeric confidence into
confidence_score (when none is present) and sets the tag to INFERRED — never
EXTRACTED, since a recovered legacy float is not structural provenance. Modern
string tags are untouched (no churn) and the raw float survives in
confidence_score.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
casefold and NFKC do not commute and neither is a fixpoint of the other, so a
single NFKC(casefold(...)) pass left normalize_id(s) != normalize_id(s.casefold())
for some combining-mark sequences (e.g. Greek ypogegrammeni U+0345 + a combining
accent): pre-casefolding turned U+0345 into iota, which NFKC then composed with
the accent into a form the single pass never saw. Iterate casefold-then-NFKC to
a bounded fixpoint (casefold first, on the raw input) so the result is stable
regardless of prior casefolds. No churn: letter/digit-bearing ids and every
CONTRACT_CASE are byte-identical; idempotency, word-only, and the Turkish (#2614)
cases still hold. Adds a deterministic regression pin so the fix does not rely on
hypothesis re-drawing the codepoints.
This was a pre-existing latent bug (present in released 0.9.45), surfaced by the
hypothesis property test; ids.py was untouched by the PRs landed alongside it.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The no-dup test asserted on _edge_labels (a set), so count()==1 was trivially
true whether or not the dedup ran. Count raw edge occurrences (normalized
labels) so a regressed dedup — @Uses({X, X}) emitting 2 edges — actually fails
the test. Adds a guard that string/enum annotation arguments (@RequestMapping(
"/x"), @Retention(RetentionPolicy.RUNTIME)) do not fabricate type refs. Adds
the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Java annotation extraction read only the annotation's name field, dropping
class-literal arguments (@Repeatable(RubricsFor.class), @Uses({A.class,B.class}))
and annotation-member return types (RubricFor[] value()), so a container
annotation became a disconnected island. Emit references edges for both, with
qualified-identity preservation; string/enum annotation arguments are not
treated as type refs, and JDK annotations resolve to sourceless stubs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The fix broadens seeding (splitting user_service into user + service), so add
the negative test the deep-dive flagged: an unrelated single-token node must not
out-rank the node matching the full multi-token query. (Note: _search_tokens
does not split camelCase, so the fix covers underscore/hyphen, not camelCase.)
Adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
_search_tokens split on \w+, which counts _ as a word char but not -, so a
query spelled with underscores stayed one un-matchable token while a hyphenated
label tokenized into parts. Splitting on [^\W_]+ makes both sides tokenize
consistently, so `graph_first_guard` matches `graph-first-guard`. Both query
and label route through _search_tokens, keeping the two sides symmetric.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The PR's test only asserted the guard line exists in the source — the exact
static-assertion anti-pattern #2126/#2641 removed for providing zero coverage.
Replace it with a runtime test that runs the real emitted post-checkout script
under sh up to the guard (with a sentinel, before the launch): same-head skips,
different-head falls through, file-checkout skips at the earlier guard. Adds the
CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
git checkout -b <new> reports a branch switch (flag=1) but passes the same SHA
for prev and new HEAD, so the post-checkout hook fired a full changed_paths-less
rebuild — the most expensive graphify op — on essentially every new branch. Add
a POSIX-sh guard that exits 0 when PREV_HEAD == NEW_HEAD; a real branch switch
(PREV != NEW) still rebuilds.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the two gaps the deep-dive flagged: a direct test of
_parse_frontmatter_fallback (the PyYAML-absent path, previously unexercised)
and an assertion that heading ids stay _make_id(stem, title) regardless of
frontmatter/node_kind (pins no id-churn). Also adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds an additive node_kind ("page"|"heading") attribute so a docs corpus can
distinguish the page node from its heading nodes, and parses leading YAML
frontmatter onto the page node via the bounded sanitize_metadata (values become
capped attributes, not graph nodes). Also fixes a leading YAML `#` comment in
frontmatter being extracted as an H1. Node ids/labels/file_type are unchanged,
so existing markdown graphs are not re-keyed.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The extractor emitted `imports` edges to _cl_id(mod_name) with no node created,
so a :use/require edge dangled (verified: sample.lisp left 'cl' and 'alexandria'
as edgeless targets) and never resolved to an in-corpus defpackage. Mint a
sourceless stub for each import target (the established cross-file pattern):
edges now have real targets, the corpus rewire collapses a stub onto a unique
in-corpus defpackage of the same name (:use :mylib -> the real package), and an
external one (cl) persists as a clean leaf. origin_file is stripped before
persist. Adds a no-dangling-edges regression test. Also adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
tree-sitter-commonlisp-backed extractor for packages, classes, functions,
methods, generics, macros, variable definers, and same-file calls. Handles the
grammar's dedicated defun node (defun/defmacro/defmethod/defgeneric via
defun_header) and the generic list_lit + leading-symbol forms (defvar/defclass/
defpackage), recurses into wrapper macros (eval-when/progn) and reader
conditionals, and maps CL operator chars (= < > ? ! + *) to readable id
suffixes. Wired into detect/extract dispatch, the extractor registry, a
[commonlisp] optional extra, and the README; ships a fixture and a 23-test suite
behind an importorskip guard.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The `if len(output) <= char_budget: return output` inside the cut_count==0
block sits within `if len(output) > char_budget`, so it can never be true.
Remove it and note why the branch is reached only when nodes fit but edges
overrun. Also adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
An unconditional early return once no whole node line was cut returned the full
edge section unchecked, so a query could emit ~6x the requested budget with no
indication — and the truncation banner advised raising the budget, the exact
trigger. When the node set fits but appending edges overruns the budget, prepend
an honest 'complete answer over budget' notice (real counts, estimated vs
requested tokens) without truncating edges, preserving the #2601 completeness
guarantee. The genuinely-fits case is byte-identical.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The #2799 fallback (utf-8 -> host codepage -> latin-1) turned a BOM'd UTF-16
ignore file (what PowerShell Set-Content / Notepad 'Unicode' write) into
NUL-laden mojibake via latin-1, so its rules matched nothing. Detect the
UTF-16 BOM and decode as utf-16 before the latin-1 fallback. Adds an
end-to-end UTF-16 exclusion test and a direct no-NUL-garbage test.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Ignore files were read with errors="ignore", so a mis-encoded byte in a rule
(e.g. a cp1252 accented directory name) was deleted, turning the pattern into
one that matches nothing — an exclusion that silently failed open. Both
rule-read sites now decode UTF-8-BOM first, then fall back to the host codepage
and latin-1 (never raising, never dropping bytes), with a one-time warning; the
rule survives intact instead of being truncated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the two cases the deep-dive flagged: a chained collapse (a_old, a_mid -> a)
lands directly on the final survivor (the whole fix rests on the union-find
remap being fully flattened), and a hyperedge collapsing to one distinct member
is kept, not dropped (pinning the deliberate sub-two-member policy). Adds the
CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Node dedup rewired edge endpoints to survivors but never remapped hyperedge
members, so a member naming a merged-away node silently vanished from the
rebuilt graph (the group shrank with no dangling reference). deduplicate_entities
now rewires hyperedge member ids through the same union-find survivor map the
edges use, de-duplicating members within each hyperedge; id-less/malformed
hyperedges pass through untouched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Documents the target-only invariant that makes a single sweep pass sufficient,
and adds two tests: the sweep does not trip the #479 shrink guard (swept
source-less orphans count as explained loss), and a stub still referenced by a
surviving file is not swept. Also adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
An external-import stub (source_file: "") is only ever an edge target of the
file that imported the symbol. When prune_sources removes that file, the stub
is stranded at degree 0 but no stale-node path reaches it (they all key on
source_file), so it accumulates in the node count, GRAPH_REPORT and exports.
build_merge now sweeps source-less degree-0 nodes that the prune just orphaned,
guarded against nodes that were already isolated beforehand so real content is
never touched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds a numeric-metadata-preserved test (surviving specific edge keeps its own
weight/confidence, not the demoted generic's) and an unknown-relation test
(a non-denylisted relation is treated as specific in either arrival order, so
the denylist can't drift into an ordering). Dates 0.9.45, opens 0.9.46.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
When two edges connect the same (source, target) pair with different relations,
the simple-graph collapse was last-write-wins by alphabetical relation, so a
specific `calls` was systematically overwritten by a generic `references`/
`uses` — and `references` is not in the callflow filter, so those call sites
dropped out of the call graph. A generic relation can no longer clobber a
stored non-generic one; the outcome is now order-independent and the edge count
is unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Ships: id-less hyperedge load tolerance (#2775), per-platform version stamp
completing #2694, Go case-only symbol collision (#2779), and .graphify_root
anchor validation (#2603).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Two small hardening tweaks on top of #2778: comment that in the hook path
Path.cwd() is the load-bearing anchor rescue (project_root == watch_root ==
the bad marker), and add hyperedges to the _anchors_stored_sources bucket
tuple to match the sibling loop. Adds a deletion-still-evicts test (the anchor
validation must not over-preserve) and an incremental==cold id-parity test.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A graph built on a subfolder stores source_file relative to the repo root but
the skill writes .graphify_root as the absolute subfolder, so an incremental
rebuild anchored stored paths under the wrong root, judged every unchanged
source deleted, and collapsed the graph. The anchor is now adopted only if the
stored sources actually resolve under it, falling back to the build root / cwd
otherwise, so a stale subfolder marker can no longer evict the whole corpus.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the two cases the deep-dive flagged as untested: a receiver-based method
collision (Get/get on the same type) and the all-salted branch where no member
is the unique exported one (Run/RUN). Also adds the CHANGELOG entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Node ids casefold (deliberately, for AST/LLM/builder parity), but Go is
case-sensitive and uses case for visibility: exported `Run` and unexported
`run` in one file collapsed to one id, so the second was dropped by add_node
and a local `run()` call phantomed to a same-named symbol in another package.
The Go extractor now salts the non-canonical half of a same-file case-only
collision (exported keeps the stable plain id), so both survive and the
in-file resolver binds the unexported call locally. ids.py / normalize_id are
untouched, so the id contract holds and non-Go corpora are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the end-to-end assertion the version-stamp fix was really about: after
installing one platform, a different stale platform actually emits the
staleness warning on stderr (the behavior the over-stamping suppressed). Adds
the CHANGELOG entry closing #2694.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
install() called _refresh_all_version_stamps(), which stamped every installed
platform's .graphify_version with the current version WITHOUT rewriting that
platform's skill content — so a genuinely stale platform was stamped current
and its staleness warning was suppressed. Removes that bogus refresh; each
platform's stamp now advances only when its own content is (re)written via
_copy_skill_file, so a not-reinstalled stale platform correctly still warns.
Completes #2694 (part 1 shipped in 0.9.44 via #2753).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>