Skip to content

Detect SQLite corruption during startup and preserve recovery backups - #49701

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/43e26328888e0301def642d69bd324acee867566
Sep 30, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/43e26328888e0301def642d69bd324acee867566

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Detect SQLite corruption during startup and preserve recovery backups

Why

A database can open successfully while containing corruption that startup previously missed. Detecting it before runtime initialization completes allows recoverable databases to be rebuilt while preserving the damaged files.

What changed

  • Run PRAGMA quick_check(1) when opening writable databases, with a 100 ms scan budget. Share attempts across cloned SqliteConfig instances by file identity so repeated opens skip validation and replacement files are checked again.
  • Back up and rebuild runtime databases that support recovery. Report corruption without rebuilding thread history or other databases without an automatic recovery policy. Treat interrupted or locked checks as incomplete rather than confirmed corruption.
  • Collect startup backups across recovery retries and include their locations in the app server warning. Explain that saved conversations can restore the thread list and history, while some database-only metadata may be unavailable.
  • Record confirmed corruption in codex.sqlite.corruption.count.

Testing

Add tests for recovery policies, backup preservation, validation caching and concurrency, cancelled and interrupted checks, and locked databases. Add app server coverage for recovery warnings and saved conversation restoration, a TUI warning snapshot, and message board post preservation.

…#49701)

## Why

A database can open successfully while containing corruption that startup previously missed. Detecting it before runtime initialization completes allows recoverable databases to be rebuilt while preserving the damaged files.

## What changed

- Run `PRAGMA quick_check(1)` when opening writable databases, with a 100 ms scan budget. Share attempts across cloned `SqliteConfig` instances by file identity so repeated opens skip validation and replacement files are checked again.
- Back up and rebuild runtime databases that support recovery. Report corruption without rebuilding thread history or other databases without an automatic recovery policy. Treat interrupted or locked checks as incomplete rather than confirmed corruption.
- Collect startup backups across recovery retries and include their locations in the app server warning. Explain that saved conversations can restore the thread list and history, while some database-only metadata may be unavailable.
- Record confirmed corruption in `codex.sqlite.corruption.count`.

## Testing

Add tests for recovery policies, backup preservation, validation caching and concurrency, cancelled and interrupted checks, and locked databases. Add app server coverage for recovery warnings and saved conversation restoration, a TUI warning snapshot, and message board post preservation.

GitOrigin-RevId: 43e26328888e0301def642d69bd324acee867566
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/43e26328888e0301def642d69bd324acee867566 branch from f0a252e to 3620b2c Compare September 30, 2026 18:30
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot merged commit 3620b2c into main Sep 30, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/43e26328888e0301def642d69bd324acee867566 branch September 30, 2026 18:30
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant