Applied from a ce-code-review pass over this branch (run 20260911-053832-b49f88d6).
- `embeddings sync` now gates EVERY checkpoint kind on embedding identity.
`unverified-count` was exempted, but `decideEmbeddingResume` abandons that
kind before it compares identity, so the exemption was the only thing
keeping a foreign model from filling holes beside the old model's vectors —
two vector spaces in one CodeEmbedding table, reported healthy. The test
that asserted this run succeeds now asserts the refusal.
- `embeddings sync` refuses when the index's recorded vector width differs
from this run's. The column is FLOAT[N] fixed at build time and the pipeline
deletes each batch's stale rows immediately before inserting, so a width
change deleted rows it could not re-insert. `analyze` already forces a
rebuild on the same mismatch; only a rebuild can retype the column.
- `GITNEXUS_EMBEDDING_RETRY_TIMEOUTS` parses with the repo's truthy convention
(`1`/`true`/`yes`). The integer parser threw on `true`, so the conventional
spelling hard-failed every embedding call rather than enabling the flag or
leaving it off. README names the accepted spellings.
- One `persistMeta` write path replaces three inlined metadata
read-modify-writes; #2790 traced two production drifts to hand-copied
writers of these exact fields.
- Tests: the pipeline mock now invokes `onCheckpointWindowStart`/`onCheckpoint`,
so the resume contract actually executes under test. Added coverage for the
incomplete-index refusal, the partial-checkpoint branch, and the body-read
timeout retry site that the existing opt-in test never reached.
Verified: tsc --noEmit clean; 99 tests pass across the three affected suites;
prettier clean.
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Make long HTTP embedding jobs resumable
Retry endpoint timeouts when explicitly configured, creating a fresh abort signal for every attempt. Add gitnexus embeddings to fill an existing index in place: every successful batch is durable, and rerunning skips vectors whose content hash still matches instead of rebuilding the structural graph.
* Address PR review feedback (#3065)
Hold the per-index lock around embeddings sync, fail closed on a foreign-identity partial checkpoint, and refuse to create an empty DB from leftover metadata. Use the canonical embedding count, keep closeLbug from masking the real error, load hashes instead of full vectors, and document GITNEXUS_EMBEDDING_RETRY_TIMEOUTS.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Split embeddings sync off the install module so install no longer loads Ladybug.
Share the opt-in TimeoutError wrap between fetch-throw and .json(), and cover a non-file LadybugDB path.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Describe embeddings sync checkpoints as periodic and report cached node count.
Pipeline checkpoints every 5,000 nodes, and fetchExistingEmbeddingHashes is keyed by nodeId, not vector rows.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Leave an unverified-count checkpoint when embeddings sync cannot count rows.
A finished run must not keep an interrupted window marker; the next sync should re-derive the count instead of hitting the identity gate.
Co-authored-by: Cursor <cursoragent@cursor.com>
* chore(autofix): apply prettier + eslint fixes via /autofix command
---------
Co-authored-by: panbergco <panbergco@users.noreply.github.com>
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>