Skip to content

Windows Desktop local state is not crash-safe after power loss: pins/projects reset, config regresses, future timestamps #26990

Description

@dudantas

What version of the Codex App are you using (From “About Codex” dialog)?

Codex Desktop Windows app package:

OpenAI.Codex_26.602.4764.0_x64__2p2nqsd0c76g0
Version: 26.602.4764.0

The app was updated before filing this report.

Additional local CLI present on the same machine:

codex-cli 0.125.0

What subscription do you have?

ChatGPT Pro

What platform is your computer?

Microsoft Windows 11 Pro
Version: 10.0.26200
Build: 26200
Architecture: x64
Filesystem: NTFS

What issue are you seeing?

After power loss / abrupt shutdown, Codex Desktop local state is repeatedly coming back in a partially reset or internally inconsistent state.

The user-visible symptoms are:

  • pinned chats disappear from the sidebar;
  • saved projects/workspaces disappear or collapse to a single workspace;
  • some project views show No chats even though local conversations still exist;
  • the TUI/skills refresh can fail because config.toml regresses to an invalid service_tier = "default" value for this installed version;
  • local metadata can get a far-future timestamp (7026), making an old session look newer than real recent sessions.

This has happened multiple times after power loss. It looks like the local Desktop/profile state under %USERPROFILE%\.codex is not crash-safe across abrupt shutdowns. The underlying conversations are generally still recoverable from local SQLite/session files, but the UI state and indexes become misleading or broken.

Concrete local evidence

The affected local state directory is %USERPROFILE%\.codex.

1. .codex-global-state.json was rewritten to a minimal state

Before repair, the current .codex-global-state.json had effectively collapsed to one workspace:

file: %USERPROFILE%\.codex\.codex-global-state.pre-repair-20260606-070944.json
size: 2,053 bytes
pinned-thread-ids: 1
project-order: 1
electron-saved-workspace-roots: 1
thread-workspace-root-hints: 0
active-workspace-roots: [%USERPROFILE%]

After reconstructing from a known-good backup and state_5.sqlite, the repaired state contained:

file: %USERPROFILE%\.codex\.codex-global-state.backup-20260606-070944.repaired.json
size: 102,112 bytes
pinned-thread-ids: 11
project-order: 27
electron-saved-workspace-roots: 27
thread-workspace-root-hints: 675

Current post-repair state, after reopening the app, remains healthy:

pinned-thread-ids: 13
project-order: 28
electron-saved-workspace-roots: 27
thread-workspace-root-hints: 675
example project-specific hints: 3 for a project that previously showed `No chats`

The repaired JSON is UTF-8 without BOM. The first bytes are:

123,13,10

2. config.toml regressed to service_tier = "default"

The broken config contained this at the top:

model = "gpt-5.5"
model_reasoning_effort = "xhigh"
personality = "pragmatic"
sandbox_mode = "danger-full-access"
approval_policy = "never"
service_tier = "default"

The local error was:

failed to refresh skills: skills/list failed in TUI: skills/list failed: failed to reload config: C:\Users\<USER>\.codex\config.toml:6:16: unknown variant `default`, expected `fast` or `flex`

Restoring a previous fixed backup of config.toml removed the parse error. The current restored file no longer contains service_tier = "default".

3. A local thread and version cache jumped to year 7026

Before repair, one local thread had:

id: 911d47ec-a3a4-7503-b8ae-3f47cecabbd4
cwd: <redacted project path>
updated_utc: 7026-02-04 18:32:49
updated_ms: 159554946769000
rollout_path: %USERPROFILE%\.codex\sessions\7026\02\04\rollout-7026-02-04T15-32-49-911d47ec-a3a4-7503-b8ae-3f47cecabbd4.jsonl

version.json also had a last_checked_at timestamp in 7026:

{
  "latest_version": "0.96.0",
  "last_checked_at": "7026-02-04T18:32:48.404538600Z",
  "dismissed_version": null
}

The 7026 session file contained only 4 metadata/instruction lines, not meaningful conversation content. After backing up the database and file, I moved it to the matching 2026 path and updated the SQLite row to a 2026 timestamp.

Post-repair validation:

future files under %USERPROFILE%\.codex: 0
future threads in state_5.sqlite: 0

4. Local conversation data was still present

The state database still contained many threads:

state_5.sqlite total threads: 791
active threads: 714

This looks like a local state/index/UI consistency problem rather than complete data deletion.

What steps can reproduce the bug?

This is tied to abrupt shutdown/power loss rather than a deterministic in-app action, but the observed sequence is:

  1. Use Codex Desktop on Windows with multiple saved workspaces/projects, pinned chats, and many local conversations.
  2. Leave Codex Desktop open with app-server/background processes active.
  3. Machine loses power or is abruptly shut down.
  4. Restart Windows and open Codex Desktop.
  5. Observe that the sidebar has lost pins and saved projects, or project views show No chats.
  6. In some cases, launch TUI/CLI or trigger skills refresh and observe config parsing failure from service_tier = "default".
  7. Inspect %USERPROFILE%\.codex and compare:
    • .codex-global-state.json
    • state_5.sqlite
    • session_index.jsonl
    • sessions/**/rollout-*.jsonl
    • version.json

The conversations remain mostly recoverable locally, but the UI state and metadata can be corrupted or reset.

What is the expected behavior?

Codex Desktop should make local state persistence crash-safe across abrupt shutdowns.

Specifically:

  • .codex-global-state.json should not be replaced by a minimal state after a crash if recoverable state exists.
  • Writes to local JSON state should be atomic, for example write temp file, fsync, then rename.
  • config.toml should not regress to a value that the installed parser rejects.
  • Timestamps should be validated or clamped; a local session/version cache should not jump to year 7026.
  • The app should detect drift between .codex-global-state.json, state_5.sqlite, session_index.jsonl, and existing rollout files.
  • If project state is incomplete, Codex should expose a supported local repair/reindex command rather than making users inspect and patch SQLite/JSON manually.
  • Project views should not display No chats when matching active local threads exist in state_5.sqlite and rollout files exist on disk.

Actual behavior

After power loss, Codex Desktop can reopen with:

  • pins reduced from 11+ to 1;
  • saved projects reduced from dozens to 1;
  • workspace hints removed;
  • project chat views empty despite active rows in state_5.sqlite;
  • config.toml containing service_tier = "default", which this install rejects;
  • local metadata containing future year 7026.

Workaround used locally

With Codex Desktop closed:

  1. Back up the broken files/databases.
  2. Restore a known-good config.toml without service_tier = "default".
  3. Rebuild .codex-global-state.json from a known-good backup and active rows in state_5.sqlite.
  4. Preserve and restore:
    • pinned-thread-ids
    • project-order
    • electron-saved-workspace-roots
    • active-workspace-roots
    • thread-workspace-root-hints
  5. Write JSON as UTF-8 without BOM.
  6. Move the sessions\7026\... rollout to the equivalent sessions\2026\... path and update the corresponding SQLite row.
  7. Restart Codex Desktop.

After that, pins/projects/project hints were visible again.

Related issues

This overlaps with several existing local state/sidebar/path reports, but I did not find an exact duplicate for the power-loss/crash-safety combination:

The distinct parts here are:

  • reproducible trigger is power loss / abrupt shutdown;
  • .codex-global-state.json collapses to a minimal state;
  • config.toml regresses to an invalid service_tier = "default" for this version;
  • a local thread and version cache jumped to year 7026;
  • the same local profile needed coordinated repair across global state JSON, config TOML, SQLite, session index, and session paths.

Additional information

No raw logs_2.sqlite, auth.json, full config.toml, or rollout content is attached publicly because those files may contain private prompts, local project names, tokens, URLs, or account data.

I can provide redacted diagnostics or specific SQL/query output if maintainers say which fields are useful and safe to share.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    appIssues related to the Codex desktop appbugSomething isn't workingconfigIssues involving config.toml, config keys, config merging, or config updatessessionIssues involving session (thread) management, resuming, forking, naming, archivingwindows-osIssues related to Codex on Windows systems

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions