fix: preserve Codex and Claude sessions during cleanup - #345
Draft
seonghobae wants to merge 268 commits into
Draft
fix: preserve Codex and Claude sessions during cleanup#345seonghobae wants to merge 268 commits into
seonghobae wants to merge 268 commits into
Conversation
…into HEAD # Conflicts: # src-tauri/src/cache_trash_reclaim.rs
…into HEAD # Conflicts: # src-tauri/src/cache_trash_reclaim.rs # src-tauri/tests/cache_trash_approval_snapshot_regression.rs
…into HEAD # Conflicts: # CHANGELOG.md # README.md # src/lib/Cleanup.svelte
…into HEAD # Conflicts: # docs/architecture/adr/0002-cache-cleanup-is-per-item-evidence-bound.md
…esearch' into codex/session-preservation-autoresearch
…esearch' into codex/session-preservation-autoresearch
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and behavior
DiskSage's shared deletion guard on protected
mainadmits recognized Codex and Claude conversation stores. Selecting a containing folder or misclassifying state as cache can therefore remove resumable work. This change retains recognized/configured agent state and containing trees before Trash, identity-bound Trash, moves, cloud eviction, native Git worktree removal, and cache-Trash classification. Incomplete metadata walks fail closed.Native recursive Git worktree removal is unavailable after a verified late-arrival session race. The retained staging/restoration path keeps Git registration intact. Rejection restores the original location if available; otherwise both the new original-path contents and retained worktree survive. Failed cloud Trash callbacks similarly restore the verified regular source without overwriting a reappeared path. Permanent cache Trash deletion remains unavailable under #263's fail-closed contract.
Current authority — 2026-09-06 KST
main:0e90f9cebadbd7f59606baaec4ca1d2f178c899a;d9b7fcf83bc0799fc9d53d0b739d87dfa42a54b6, still open/Draft with its own acceptance requirements;a9d2e77e750d1f621bef78e46c598ae9bd6ec289, open/Draft; current-head checks and independent approval remain required;e053ef7757bdc14a7ba8b39e8c9ee385a23cdfc4restoreddocs/product-technical-gap-baseline.mdto the protected-main blob, removing the competing canonical-doc writer from this runtime lane;f522ef955...records exact security: fail cache-trash permanent deletion closed #263 as a non-force second parent without changing fix: preserve Codex and Claude sessions during cleanup #345's preserved tree. This makes the cache-Trash predecessor explicit ancestry rather than an implicit mutable sibling dependency; security: fail cache-trash permanent deletion closed #263 is not closed or superseded;cbdc760c...restores.github/workflows/test.ymlto the protected-main blob, so this runtime PR no longer writes shared Test workflow source. The valid Windows agent-state regression was transferred test-first to canonical Test owner fix(ci): repair contract-doc path filtering #338 asfe205964...→29aaf64c.... fix: preserve Codex and Claude sessions during cleanup #345 must later adopt a terminal-GREEN canonical Test owner normally; no owner check is transferred.Validation
Review scope and limits
See
docs/doctoring/session-preservation/README.mdfor commands, commits, limits, and sources. Existing PRs retain their deltas and are not superseded or closed. Arbitrary renamed exports, custom roots invisible to DiskSage, other applications' retention, and arbitrary concurrent namespace mutations remain explicit limits. Trees exceeding 500,000 metadata entries are retained; the entire bounded tree must be inspected.A real Git/filesystem regression confirmed that a child retaining its working directory can create ignored agent state after the final staged scan and native removal then deletes it. Commit
06b55bcemakes recursive Git worktree removal unavailable and restores the retained worktree; both late-arriving Codex and Claude cases pass. The UI offers inspection only, and CLI help states the deletion hold. Re-enabling this boundary needs a verified late-arrival preservation contract.Capacity objective
The user requires at least 300 GiB of actual reclaimed capacity while preserving sessions. At 2026-09-06T15:20:09.211Z, available space was 296.262669 GiB, an increase of 287.559341 GiB over the 9,126,100 KiB baseline; 12.440659 GiB remains unmet. Completed external operations include 165 Cargo cleanups, selected BuildKit cache cleanup, three remotely verified unused Podman base images, five toolchains' documentation components, guest free-block return, and Trivy database-only cleanup. Five native pnpm cleanups retained manifest/lockfiles and reported sources but had a combined signed df change of -1.447853 GiB; further dependency cleanup was stopped. Directory sizes are not credited as physical recovery. UV, referenced Playwright revisions, missing-tag Cargo targets and remaining similar dependency directories are retained. Browser-native inspection could not proceed because the Mac was locked; no browser state changed. No cleanup runner remains active. These are operational records, not shipped product receipts.
A synthetic native pnpm experiment reproduced late nested-state deletion through a parent-directory descriptor missed by target-only probes. Full owning-Git-root probes then rejected existing and post-staging descriptor holders and preserved the synthetic session. Arbitrary arrivals after the final observation remain outside that evidence. PR295 now preserves original command-path association at 0b30fa2; 12 controlled module tests and a separate live native-helper experiment verify that focused repair. Owning-parent scope and atomic restoration remain canonical owner requirements. This lane records evidence without duplicating the implementation.
Keep Draft until current-head Test/security/SAST/CodeQL/review evidence is terminal, #345 has normally adopted a terminal-GREEN canonical Test owner, the late-session recursive-removal race remains repaired by deletion-unavailable or a stronger accepted contract, and protected-lineage prerequisites integrate normally. No self-approval, force-push, destructive rebase, gate weakening, administrative bypass, predecessor-evidence transfer, or premature merge/Close.
Recovery of omitted ancestor release changes
Commit
bdb42f90reconciles release/verifier changes already present in ancestor PR #264 but omitted by mergef522ef95. The selected changes preserve PR-only cancellation and existing session protections, restore stable artifact identities across retries, and run the canonical artifact verifier before SBOM generation. No review or protection gate was weakened.Local verification: all 37 frontend test files / 156 tests pass, actionlint passes, and the verifier passes shell syntax checking. Independent review found no introduced weakening of namespace, depth, file-type, checksum, or publication-order checks. It reproduced a pre-existing empty-payload admission gap in the canonical verifier; that remains owner follow-up, not a passing nonempty-artifact claim. New-head hosted tests, reviews, and protected merge remain outstanding.
Local session availability follow-up
The common iCloud local-copy admission path now reuses the shared session guard, retaining Codex and Claude local state before provider observation. Execution re-plans through that same boundary. This addresses local availability; no permanent cloud deletion was reproduced or performed.
RED dac63e2 reproduced synthetic Codex admission. Fix dd03c9c passed 21 actual-module unit tests, including three protected state paths and an ordinary control. The local harness excludes native/public entrypoints under coverage configuration; the checked-in public planner assertion requires the new head hosted run. The initial broader harness command failed doctest configuration and is not counted as a full application pass. Prior hosted Test success at bdb42f9 does not validate this new head. Full evidence and capacity limits remain in the doctoring report.
Hosted verification at 884840f
Test job 101574147853 completed successfully. Its log explicitly records
cloud_local_eviction::tests::session_state_is_retained_before_provider_observation ... okunder the normal Rust test build, including the public planner assertion omitted by the local coverage harness. All 37 frontend files / 156 tests passed. Native engine build and Windows home-resolution jobs also passed. No real cloud eviction was performed; required reviews/security checks and protected owner adoption remain outstanding. This supersedes the preceding pending-hosted-verification statement for this exact head only.