Ran real backends in isolated environments (real Postgres-backed gbrain,
live Sourcebot v6.5.0 with anonymous access, real graphify 0.9.23). All three
now index + search end-to-end. Fixes:
- gbrain: RESTORE `--strategy code` in refresh — round 1 removed it on a --help
misread, which silently stopped code from ever being indexed. refresh now runs
the verified two-pass (`sync`, then `sync --strategy code --full`). Pinned by a
new test so the regression can't return.
- sourcebot: an API key is NOT required for local use — anonymous access
(FORCE_ENABLE_ANONYMOUS_ACCESS=true) serves /api/search keyless (verified). Key
stays optional; only the messaging changed (anonymous-access first, key as
fallback) plus a note that a local repo needs remote.origin.url to index.
- graphify: correct the docstring — for CODE both `graphify <dir>` and
`graphify update` are AST-only (no LLM); the LLM only renames clusters and
ingests non-code, which our parser ignores. No LLM mode; local=true is correct.
Docs: capability matrix + "Verified against real environments" updated to record
all three proven end-to-end and to correct the two first-round mistakes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
search was running in cwd and missing the repo you indexed. Persist the indexed
path per provider in the selection store and resolve it back so `search` reads
the same graph `index` built. Graphify availability now checks `graphify --version`
(installed = selectable) instead of "a graph already exists here", and the CLI
keys Graphify sources on the repo path.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Parallel real-environment tests (graphify 0.9.23, Sourcebot v5 in Docker,
gbrain 0.42.56) surfaced real mismatches:
- graphify: build via `graphify update <dir>` (the local, no-LLM path) instead
of `graphify <dir>` (which runs an LLM backend needing a key + network, so the
old path wasn't actually local); query via `graphify query --graph <graph.json>`
so it reads the indexed graph regardless of cwd; parse the real NODE/EDGE output
(file lives at src=/at=) instead of an invented format.
- sourcebot: Sourcebot v5 gates /api/search behind auth — send
`Authorization: Bearer <SOURCEBOT_API_KEY>`; treat 401/403 as PROVIDER_UNAVAILABLE;
make status probe /api/search without following the login redirect.
- gbrain: degrade engine/DB init failures (e.g. pglite WASM, garrytan/gbrain#223)
to PROVIDER_UNAVAILABLE with a one-line message instead of PROVIDER_ERROR + a raw
stack dump; drop flags the real CLI doesn't define (`sync --strategy`,
`search --source`); align put/delete to stdin, export to brain-wide.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
contract.ts: repo-oriented interface (four required ops, three optional),
typed CodeProviderError, egress + capability consent guards.
Three real, runtime-drivable adapters:
- GbrainProvider: gbrain CLI (reuses lib/gbrain-exec + lib/gbrain-sources),
all seven capabilities.
- GraphifyProvider: graphify CLI — `graphify <dir>` builds the local graph,
`graphify query` searches it, export reads graphify-out/graph.json. Fully
local; never auto-installed.
- SourcebotProvider: self-hosted server over HTTP — register writes a local
git connection to config.json, search is POST /api/search, status is a
liveness probe. Loopback base URL = local (no egress); remote = consent.
selection.ts persists the chosen provider + per-repo indexing consent under
$GSTACK_HOME. picker.ts recommends GBrain first, resolves the selected
provider or null (provider-OFF), and probes live availability. Every adapter
degrades to PROVIDER_UNAVAILABLE when its tool/server is absent.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Design for the OPTIONAL code-intelligence provider contract that lets a
user pick how their codebase is indexed and searched, replacing gstack's
~17k LOC of bespoke GBrain glue. Repo-oriented ops (register_source/
refresh/search/status required; add/delete/export optional), a per-provider
capability matrix, GBrain-recommended-first selection, repo-scoped + install
consent, and a phased rollout that keeps gstack fully functional with no
provider selected. All three providers are driven from the runtime via CLI
or HTTP — no MCP client.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>