Skip to content

feat(explore): find quoted prose in indexed source - #392

Merged
bompus merged 1 commit into
fork/consolidatedfrom
feat/explore-quoted-prose
Oct 5, 2026
Merged

bompus merged 1 commit into
fork/consolidatedfrom
feat/explore-quoted-prose

Conversation

@bompus

@bompus bompus commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Quoted UI sentences often have no literal-index entry, so an explore query such as Where is "Shipping updates are temporarily unavailable"? could return unrelated code or no source. Explore now scans indexed script and template source for quoted phrases of at least three words, ignoring case and punctuation. It returns the enclosing callable or matching template lines within existing output limits. No re-index is required.

The scan admits templates with no graph nodes, preserves numeric words such as protocol/2, and excludes configuration values before collecting matches. It reuses the native contained-source reader. Bounds are four phrases of at most 300 characters, 16 matches, 1 MiB per file and 64 MiB total, with a 300 ms budget checked between files. Ordinary symbol queries and two-word quotes skip the scan.

Validation: three public source-retrieval regressions fail on the base and pass here; a normalization mutation fails the numeric regression. All 83 focused tests and the full suite pass (7,377 passed, 39 skipped). Four Vite/Flask controls are byte-identical; the original failure in a private downstream project returns the sentence in three query variants, with every answer below 25,000 characters. The selected end-to-end correctness check passed: one Astra xhigh candidate run located the source and correctly explained the display condition, including its alternate-message exception. The parent checked the cited source. The run used three explore calls and two MCP resource-listing calls, made no command-execution calls, and both owned processes exited cleanly. Shell tools were disabled for this MCP-only check, so it does not measure unforced Read/Grep fallback. This single case establishes neither speed nor weaker-model sufficiency; the failed Sonnet attempt is retained separately. After static review, only test fixtures and assertions changed; no further review round ran.

README rows checked: quoted prose source, local callee bodies, requested tests and missing-name notes. README, MCP reference, server instructions and CHANGELOG describe the resulting behavior and limits. No quoted benchmark number changed.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 34e31a3e-7085-42d0-b086-b6701a4b94c9
📥 Commits

Reviewing files that changed from the base of the PR and between 3a6272b and 8918e3a.

📒 Files selected for processing (10)
  • CHANGELOG.md
  • README.md
  • __tests__/explore-quoted-prose.test.ts
  • __tests__/source-scan.test.ts
  • site/src/content/docs/reference/mcp-server.md
  • src/codegraph.ts
  • src/db/queries.ts
  • src/mcp/server-instructions.ts
  • src/mcp/source-scan.ts
  • src/mcp/tools.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Summary

Summary by CodeRabbit

  • New Features
    • codegraph_explore now finds quoted passages of three or more words in indexed source code, including script strings and template text. Matching ignores differences in case and punctuation and does not require re-indexing.
    • Results include matching files and line locations, subject to scan and output limits.
  • Documentation
    • Updated the README, changelog, and MCP server guidance with search behavior and scan limits.

Walkthrough

codegraph_explore now scans indexed source files for qualifying quoted query text. Matching files can contribute line anchors and callable or file seeds to exploration results. The scan applies limits for span length, file size, bytes read, elapsed time, and match count.

Changes

Quoted-prose search

Layer / File(s) Summary
Source scan and matching limits
src/db/queries.ts, src/codegraph.ts, src/mcp/source-scan.ts, __tests__/source-scan.test.ts, src/mcp/server-instructions.ts, site/src/content/docs/reference/mcp-server.md
The indexed-file query now returns language metadata. New scanning logic matches qualifying quoted spans and returns file and line ranges within the scan limits. Tests cover match caps, CRLF line coordinates, and oversized files.
Explore result integration
src/mcp/tools.ts, __tests__/explore-quoted-prose.test.ts, README.md, CHANGELOG.md
handleExplore adds prose matches to seeds and file selection, including files without graph nodes. Tests cover matching, output, and cases that do not trigger scanning. The README and changelog describe the feature.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 8918e

The quoted-prose search is ready for normal validation; complete the planned end-to-end comparison before merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8918e

Quoted searches can now bring additional source files into answers, sometimes as whole files within existing output limits. Project-path checks and configuration exclusions remain in place. No introduced security vulnerability was established, but consistency between matching and rendering during concurrent file changes is not guaranteed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A caller permitted to use Explore can cause quoted phrases to discover and return matching eligible indexed source within the selected project, including files without symbols. Per-call limits bound work and output, not cumulative project-source disclosure across repeated calls. No write, execution, credential, or infrastructure authority is added by the inspected scan path.

Security Findings and Attack Paths

  • observed — Prose-only admission expands Explore reachability, but the base already allowed indexed-file source retrieval without requiring graph nodes through handleFileView. Both paths retain the yaml/properties exclusion. This is counterevidence to treating newly discovered files as newly authorized assets; no authorization bypass was established.

Trust Boundaries and Controls

  • observed — The scanner checks the opened descriptor against the canonical project root, rejects traversal and non-regular files, and enforces byte limits. Final rendering separately validates lexical and resolved-path containment before reading current bytes. The scan and rendering reads are therefore not one descriptor-bound snapshot.

Resilience and Maintainability Implications

  • observed — Prose-only files use the existing session-emission pipeline: deduplication depends on current-content fingerprints, emitted ranges follow actual rendered sections, and final survivor filtering avoids recording removed sections. Session records remain scoped by project and session and commit after successful dispatch. Concurrent duplicate delivery is pre-existing, not a new prose-specific state transition.
  • inferred — A concurrent file mutation can invalidate scan-derived prose coordinates before rendering. The existing index-drift gate can omit stale slices or return bounded current whole-file content, but does not revalidate the phrase against the rendered bytes. This is a consistency limitation; unauthorized disclosure or another material security consequence was not demonstrated.

Hardening Proposals

  • proposed — Bind prose anchors to the rendered content using a content fingerprint or phrase revalidation. If concurrent filesystem mutation is within the threat model, consider using the descriptor-verified contained reader for final rendering as well. This would strengthen source identity and containment without implying that an exploit was verified.
🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Suppressions Explained ✅ Passed The pull request adds no lint, type-check, or compiler suppression directive. The changed-file diff contains no added eslint-disable, @ts-expect-error, @ts-ignore, or similar directive, and it c…
User-Visible Changes Documented ✅ Passed The diff adds quoted-prose source matching inside the existing codegraph_explore behavior. It does not add, remove, or rename a CLI command or flag, an MCP tool or argument, a supported language or …
Title check ✅ Passed The title clearly and concisely describes the main change: finding quoted prose in indexed source during explore.
Description check ✅ Passed The description explains the quoted-prose source scan, its behavior and limits, and reported validation. It is directly related to the changeset.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@bompus
bompus merged commit 47f7037 into fork/consolidated Oct 5, 2026
4 checks passed
@bompus
bompus deleted the feat/explore-quoted-prose branch October 5, 2026 07:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant