What version of the Codex App are you using (From “About Codex” dialog)?
Codex Desktop Windows app package:
OpenAI.Codex_26.602.4764.0_x64__2p2nqsd0c76g0
Version: 26.602.4764.0
The app was updated before filing this report.
Additional local CLI present on the same machine:
What subscription do you have?
ChatGPT Pro
What platform is your computer?
Microsoft Windows 11 Pro
Version: 10.0.26200
Build: 26200
Architecture: x64
Filesystem: NTFS
What issue are you seeing?
After power loss / abrupt shutdown, Codex Desktop local state is repeatedly coming back in a partially reset or internally inconsistent state.
The user-visible symptoms are:
- pinned chats disappear from the sidebar;
- saved projects/workspaces disappear or collapse to a single workspace;
- some project views show
No chats even though local conversations still exist;
- the TUI/skills refresh can fail because
config.toml regresses to an invalid service_tier = "default" value for this installed version;
- local metadata can get a far-future timestamp (
7026), making an old session look newer than real recent sessions.
This has happened multiple times after power loss. It looks like the local Desktop/profile state under %USERPROFILE%\.codex is not crash-safe across abrupt shutdowns. The underlying conversations are generally still recoverable from local SQLite/session files, but the UI state and indexes become misleading or broken.
Concrete local evidence
The affected local state directory is %USERPROFILE%\.codex.
1. .codex-global-state.json was rewritten to a minimal state
Before repair, the current .codex-global-state.json had effectively collapsed to one workspace:
file: %USERPROFILE%\.codex\.codex-global-state.pre-repair-20260606-070944.json
size: 2,053 bytes
pinned-thread-ids: 1
project-order: 1
electron-saved-workspace-roots: 1
thread-workspace-root-hints: 0
active-workspace-roots: [%USERPROFILE%]
After reconstructing from a known-good backup and state_5.sqlite, the repaired state contained:
file: %USERPROFILE%\.codex\.codex-global-state.backup-20260606-070944.repaired.json
size: 102,112 bytes
pinned-thread-ids: 11
project-order: 27
electron-saved-workspace-roots: 27
thread-workspace-root-hints: 675
Current post-repair state, after reopening the app, remains healthy:
pinned-thread-ids: 13
project-order: 28
electron-saved-workspace-roots: 27
thread-workspace-root-hints: 675
example project-specific hints: 3 for a project that previously showed `No chats`
The repaired JSON is UTF-8 without BOM. The first bytes are:
2. config.toml regressed to service_tier = "default"
The broken config contained this at the top:
model = "gpt-5.5"
model_reasoning_effort = "xhigh"
personality = "pragmatic"
sandbox_mode = "danger-full-access"
approval_policy = "never"
service_tier = "default"
The local error was:
failed to refresh skills: skills/list failed in TUI: skills/list failed: failed to reload config: C:\Users\<USER>\.codex\config.toml:6:16: unknown variant `default`, expected `fast` or `flex`
Restoring a previous fixed backup of config.toml removed the parse error. The current restored file no longer contains service_tier = "default".
3. A local thread and version cache jumped to year 7026
Before repair, one local thread had:
id: 911d47ec-a3a4-7503-b8ae-3f47cecabbd4
cwd: <redacted project path>
updated_utc: 7026-02-04 18:32:49
updated_ms: 159554946769000
rollout_path: %USERPROFILE%\.codex\sessions\7026\02\04\rollout-7026-02-04T15-32-49-911d47ec-a3a4-7503-b8ae-3f47cecabbd4.jsonl
version.json also had a last_checked_at timestamp in 7026:
{
"latest_version": "0.96.0",
"last_checked_at": "7026-02-04T18:32:48.404538600Z",
"dismissed_version": null
}
The 7026 session file contained only 4 metadata/instruction lines, not meaningful conversation content. After backing up the database and file, I moved it to the matching 2026 path and updated the SQLite row to a 2026 timestamp.
Post-repair validation:
future files under %USERPROFILE%\.codex: 0
future threads in state_5.sqlite: 0
4. Local conversation data was still present
The state database still contained many threads:
state_5.sqlite total threads: 791
active threads: 714
This looks like a local state/index/UI consistency problem rather than complete data deletion.
What steps can reproduce the bug?
This is tied to abrupt shutdown/power loss rather than a deterministic in-app action, but the observed sequence is:
- Use Codex Desktop on Windows with multiple saved workspaces/projects, pinned chats, and many local conversations.
- Leave Codex Desktop open with app-server/background processes active.
- Machine loses power or is abruptly shut down.
- Restart Windows and open Codex Desktop.
- Observe that the sidebar has lost pins and saved projects, or project views show
No chats.
- In some cases, launch TUI/CLI or trigger skills refresh and observe config parsing failure from
service_tier = "default".
- Inspect
%USERPROFILE%\.codex and compare:
.codex-global-state.json
state_5.sqlite
session_index.jsonl
sessions/**/rollout-*.jsonl
version.json
The conversations remain mostly recoverable locally, but the UI state and metadata can be corrupted or reset.
What is the expected behavior?
Codex Desktop should make local state persistence crash-safe across abrupt shutdowns.
Specifically:
.codex-global-state.json should not be replaced by a minimal state after a crash if recoverable state exists.
- Writes to local JSON state should be atomic, for example write temp file, fsync, then rename.
config.toml should not regress to a value that the installed parser rejects.
- Timestamps should be validated or clamped; a local session/version cache should not jump to year 7026.
- The app should detect drift between
.codex-global-state.json, state_5.sqlite, session_index.jsonl, and existing rollout files.
- If project state is incomplete, Codex should expose a supported local repair/reindex command rather than making users inspect and patch SQLite/JSON manually.
- Project views should not display
No chats when matching active local threads exist in state_5.sqlite and rollout files exist on disk.
Actual behavior
After power loss, Codex Desktop can reopen with:
- pins reduced from 11+ to 1;
- saved projects reduced from dozens to 1;
- workspace hints removed;
- project chat views empty despite active rows in
state_5.sqlite;
config.toml containing service_tier = "default", which this install rejects;
- local metadata containing future year
7026.
Workaround used locally
With Codex Desktop closed:
- Back up the broken files/databases.
- Restore a known-good
config.toml without service_tier = "default".
- Rebuild
.codex-global-state.json from a known-good backup and active rows in state_5.sqlite.
- Preserve and restore:
pinned-thread-ids
project-order
electron-saved-workspace-roots
active-workspace-roots
thread-workspace-root-hints
- Write JSON as UTF-8 without BOM.
- Move the
sessions\7026\... rollout to the equivalent sessions\2026\... path and update the corresponding SQLite row.
- Restart Codex Desktop.
After that, pins/projects/project hints were visible again.
Related issues
This overlaps with several existing local state/sidebar/path reports, but I did not find an exact duplicate for the power-loss/crash-safety combination:
The distinct parts here are:
- reproducible trigger is power loss / abrupt shutdown;
.codex-global-state.json collapses to a minimal state;
config.toml regresses to an invalid service_tier = "default" for this version;
- a local thread and version cache jumped to year
7026;
- the same local profile needed coordinated repair across global state JSON, config TOML, SQLite, session index, and session paths.
Additional information
No raw logs_2.sqlite, auth.json, full config.toml, or rollout content is attached publicly because those files may contain private prompts, local project names, tokens, URLs, or account data.
I can provide redacted diagnostics or specific SQL/query output if maintainers say which fields are useful and safe to share.
What version of the Codex App are you using (From “About Codex” dialog)?
Codex Desktop Windows app package:
The app was updated before filing this report.
Additional local CLI present on the same machine:
What subscription do you have?
ChatGPT Pro
What platform is your computer?
What issue are you seeing?
After power loss / abrupt shutdown, Codex Desktop local state is repeatedly coming back in a partially reset or internally inconsistent state.
The user-visible symptoms are:
No chatseven though local conversations still exist;config.tomlregresses to an invalidservice_tier = "default"value for this installed version;7026), making an old session look newer than real recent sessions.This has happened multiple times after power loss. It looks like the local Desktop/profile state under
%USERPROFILE%\.codexis not crash-safe across abrupt shutdowns. The underlying conversations are generally still recoverable from local SQLite/session files, but the UI state and indexes become misleading or broken.Concrete local evidence
The affected local state directory is
%USERPROFILE%\.codex.1.
.codex-global-state.jsonwas rewritten to a minimal stateBefore repair, the current
.codex-global-state.jsonhad effectively collapsed to one workspace:After reconstructing from a known-good backup and
state_5.sqlite, the repaired state contained:Current post-repair state, after reopening the app, remains healthy:
The repaired JSON is UTF-8 without BOM. The first bytes are:
2.
config.tomlregressed toservice_tier = "default"The broken config contained this at the top:
The local error was:
Restoring a previous fixed backup of
config.tomlremoved the parse error. The current restored file no longer containsservice_tier = "default".3. A local thread and version cache jumped to year 7026
Before repair, one local thread had:
version.jsonalso had alast_checked_attimestamp in 7026:{ "latest_version": "0.96.0", "last_checked_at": "7026-02-04T18:32:48.404538600Z", "dismissed_version": null }The
7026session file contained only 4 metadata/instruction lines, not meaningful conversation content. After backing up the database and file, I moved it to the matching 2026 path and updated the SQLite row to a 2026 timestamp.Post-repair validation:
4. Local conversation data was still present
The state database still contained many threads:
This looks like a local state/index/UI consistency problem rather than complete data deletion.
What steps can reproduce the bug?
This is tied to abrupt shutdown/power loss rather than a deterministic in-app action, but the observed sequence is:
No chats.service_tier = "default".%USERPROFILE%\.codexand compare:.codex-global-state.jsonstate_5.sqlitesession_index.jsonlsessions/**/rollout-*.jsonlversion.jsonThe conversations remain mostly recoverable locally, but the UI state and metadata can be corrupted or reset.
What is the expected behavior?
Codex Desktop should make local state persistence crash-safe across abrupt shutdowns.
Specifically:
.codex-global-state.jsonshould not be replaced by a minimal state after a crash if recoverable state exists.config.tomlshould not regress to a value that the installed parser rejects..codex-global-state.json,state_5.sqlite,session_index.jsonl, and existing rollout files.No chatswhen matching active local threads exist instate_5.sqliteand rollout files exist on disk.Actual behavior
After power loss, Codex Desktop can reopen with:
state_5.sqlite;config.tomlcontainingservice_tier = "default", which this install rejects;7026.Workaround used locally
With Codex Desktop closed:
config.tomlwithoutservice_tier = "default"..codex-global-state.jsonfrom a known-good backup and active rows instate_5.sqlite.pinned-thread-idsproject-orderelectron-saved-workspace-rootsactive-workspace-rootsthread-workspace-root-hintssessions\7026\...rollout to the equivalentsessions\2026\...path and update the corresponding SQLite row.After that, pins/projects/project hints were visible again.
Related issues
This overlaps with several existing local state/sidebar/path reports, but I did not find an exact duplicate for the power-loss/crash-safety combination:
C:\...vs\\?\C:\...stale path.No chatsfor projects with older non-archived conversations.state_5.sqliteandsession_index.jsonldrift.The distinct parts here are:
.codex-global-state.jsoncollapses to a minimal state;config.tomlregresses to an invalidservice_tier = "default"for this version;7026;Additional information
No raw
logs_2.sqlite,auth.json, fullconfig.toml, or rollout content is attached publicly because those files may contain private prompts, local project names, tokens, URLs, or account data.I can provide redacted diagnostics or specific SQL/query output if maintainers say which fields are useful and safe to share.