move-codex-session ignores databases and tables it does not know and still reports sourceRemoved: true #143
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
At
1a85c77, the script moves rows only out of the six database families it names. A move reportssourceRemoved: truewithout a word about any other database in the home.mainfindsstate,thread_history,logs,goals,memoriesandqueuethroughlatestDatabase, which matches^<prefix>_(\d+)\.sqlite$. Nothing scans the home for other databases. Codex 0.160.1 has two more that hold per-session rows:memories_v2_1.sqlite. Codex deletes a thread's rows from it next tomemories_1(delete_versioned_thread_memoryincodex-rs/state/src/runtime/memory_versions.rs). The pattern never matches it, becausev2_follows the prefix.agent_message_board_1.sqlite. Its boards are keyed by the session ID in aboardcolumn (codex-rs/ext/agent-message-board/src/local.rs).Tables inside the known databases get only a heuristic check.
requireNoUnknownThreadTablesrefuses a table whose name containsthread, that has athread_id,parent_thread_id,child_thread_idorsession_idcolumn, or that is linked by foreign key to a known table. It missedmemories_1.jobs, which keys its stage-1 rows by thread ID injob_key, so that table is now handled explicitly (lines 117-123). A table keyed any other way still passes.The move exits 0, the rows for the moved session stay in the source database, and the destination doesn't get them. Nothing is deleted. The session's v2 memories or board posts just don't follow it, and the output gives no hint.
Reproduced on fixtures, each with exit 0, empty stderr and
sourceRemoved: true, and the session's rows still in the source file:memories_v2_1.sqlitein both homes, and in the source only (the destination then has no such file).agent_message_board_1.sqlitein the source.notes(id, owner)added tomemories_1, holding the thread ID inowner. The same table with athread_idcolumn is refused.A possible fix keeps the heuristic and adds one refusal: when the source home holds a
<prefix>_<N>.sqlitewhose prefix is not one of the six, fail and name the file. Other versions of a known prefix, such as an oldstate_4.sqlite, stay ignored as today. Moves then fail onmemories_v2_1.sqliteuntil the script learns it. A strict allowlist of every table would catch more, but it would also refuse after any Codex upgrade that adds an unrelated table.Evidence: reproduced at
1a85c77with the fixtures above. The file names and their use come from reading Codex 0.160.1.