Repository navigation
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This changes existing Codex auth-overlay behavior by redirecting SQLite state to a shared home and deleting stale shadow-home links during startup. Because it affects account/session isolation and authentication-related filesystem semantics, human review is warranted. Notes:
You can add or adjust custom eligibility rules. Learn more. |
1ba87ef to
b93ef8f
Compare
Dismissing prior approval to re-evaluate b93ef8f
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit b93ef8fc868b633428d2b675a03d2b72890bcb7d. Configure here.
b93ef8f to
bfeff66
Compare
8a9b251 to
2837c2c
Compare
|
Note 🤖 GPT-6 Astra (preview) responding on behalf of Theo This note is part of an automated cleanup pass. Preserve the repeat-pass cases from #7201 at head 979c4878. Set up the shadow home once, create a new SQLite database plus WAL/SHM files in both homes, then repeat setup twice. Both real file contents must survive and absent shadow sidecars must not become shared symlinks. Keep the unrelated |
2837c2c to
ed2d643
Compare
Dismissing prior approval to re-evaluate ed2d643
Preserves the regression coverage from pingdotgg#7201 against this PR's shared-home design: repeated materialization with a Codex-created database in both homes, the pingdotgg#5817 sidecar-only shape where the shadow home has no database of its own, and recovery after an unrelated config.toml conflict is cleared. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ed2d643 to
10a6f43
Compare
|
Carried over at Repeat-pass — #5817 sidecar-only —
Both new tests fail against the pre-fix
Separately re-verified the environment variable on Codex CLI 0.153.2 (the PR originally cited 0.152.1): with a shadow The branch is rebased onto Implemented with Claude Opus 5 using the Claude Code harness in T3 Code. |
Windows regression confirmation: regular sidecars still block startupThis reproduces the same sidecar-only shape described in #5817 after the provider had previously been recovered.
For immediate recovery, I am disabling only the affected provider instance. I am not deleting authentication or SQLite state. This is a temporary mitigation, not a fix. This is a useful end-to-end acceptance case for this PR: an existing sidecar-only shadow conflict must no longer disable the provider or cascade into a desktop-backend crash. The PR's |
|
Thanks for working on this. We merged the orchestrator V2 rewrite in #2829, and we are closing this PR as part of that transition. The patch conflicts with the rewrite in apps/server/src/provider/Drivers/CodexDriver.ts. Even where the conflict is small enough to rebase, we are asking for fresh PRs against the new base so we can review and verify the behavior in V2. Sorry for the extra work this creates. If the change is still needed on V2, please rebuild it on current main, verify it there, and open a new PR linking back here. We're closing the current implementation without assuming the underlying request is resolved. |

Problem
Codex auth overlays currently symlink SQLite databases and their WAL/SHM sidecars into each account-specific shadow home. On Windows, opening those databases through shadow symlink paths can repeatedly fail, and deleting the links does not stick because the next provider startup recreates them.
Fix
Set
CODEX_SQLITE_HOMEto the shared Codex home for auth-overlay instances, keep SQLite files out of shadow-home materialization, and remove stale SQLite symlinks left by earlier launches. Real shadow-local SQLite files are preserved.Materialization now also reads the shadow home so pre-existing SQLite symlinks are cleaned up; a failure to list it surfaces as
CodexShadowHomeFileSystemErrorrather than a raw platform error.Verification
pnpm exec vp test run apps/server/src/provider/Drivers/CodexHomeLayout.test.tspnpm exec vp run --filter t3 typecheckvp lintandvp fmt --checkdoctor --jsonwith disposable homes confirmed that a shadowCODEX_HOMEplus sharedCODEX_SQLITE_HOMEresolves every SQLite database path to the shared homeImplemented with GPT-5.6 Sol using the Codex harness in T3 Code.
Note
Medium Risk
Changes Codex auth-overlay filesystem layout and provider env for SQLite paths; existing shadow homes may lose stale SQLite symlinks on next startup.
Overview
Auth-overlay Codex instances now point SQLite at the shared home via
CODEX_SQLITE_HOME, while each instance still uses its shadowCODEX_HOMEfor per-account auth.Shadow-home materialization stops symlinking
.sqlitefiles (and journal/shm/wal sidecars) from shared into shadow, and on each run removes stale SQLite symlinks already in the shadow home without touching real shadow-local database files. Listing the shadow directory is now part of that pass, with failures wrapped asCodexShadowHomeFileSystemError.Tests cover no SQLite links after materialization, repeated materialization preserving separate shared/shadow DBs, stale-link cleanup, and conflict recovery after removing blocking files.
Reviewed by Cursor Bugbot for commit 10a6f43. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Keep Codex SQLite files in shared home for auth-overlay instances
CODEX_SQLITE_HOMEto the shared home path so SQLite state stays shared while account credentials remain private inCodexDriver.create(CodexDriver.ts).materializeCodexShadowHomein CodexHomeLayout.ts excludes.sqlitedatabases and their journal/WAL/shared-memory sidecars from the shared-entry symlink set, and removes stale matching shadow symlinks instead of replacing local files.SQLITE_ENTRY_NAME_PATTERNto classify SQLite filenames, and wraps shadow-directory read failures asCodexShadowHomeFileSystemError.CODEX_SQLITE_HOME; direct-home instances are unaffected. Reviewers should verifySQLITE_ENTRY_NAME_PATTERNcovers all expected sidecar suffixes and that consumers ofCODEX_SQLITE_HOMEhandle the shared path correctly.Macroscope summarized 10a6f43.