Skip to content

Stop a Codex card binding to a rollout that predates it - #66

Merged
psjamesh merged 2 commits into
mainfrom
fix/codex-resume-binds-old-rollout
Sep 7, 2026
Merged

psjamesh merged 2 commits into
mainfrom
fix/codex-resume-binds-old-rollout

Conversation

@jen-ps

@jen-ps jen-ps commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

A Codex card with no cached liveSessionId resolved one with launchedAt: 0, which disables the age bound in discoverCodexLiveId and matches on cwd alone — so the newest rollout a directory has ever hosted won, of any age. The result is persisted, so one bad guess bound the card to that conversation for good. The board-refresh path did it without any resume at all.

Bounding by mtime doesn't work: resuming an old conversation rewrites its rollout, so a superseded one can carry a newer mtime than the session that replaced it. This takes the minted time from the rollout's filename instead and skips anything minted before the card existed.

launchedAt semantics are untouched, so the launch-time probe is unchanged. Unparseable names aren't excluded, and entries predating createdAt keep the current behaviour rather than becoming unresumable.

The regression test fails on main.

The shared-cwd collision noted in the issue is not addressed here — two cards launched from one directory can still resolve to each other's conversation.

Fixes #63.

When a Codex entry has no cached live id, both the resume path and the board
refresh resolved one with `launchedAt: 0`, which disables the age bound in
discoverCodexLiveId and matches on cwd alone. The newest rollout the directory
has ever hosted wins, of any age, and the result is persisted — so a card could
be bound permanently to a months-old conversation in a since-reused directory,
and every later resume faithfully reopened it.

Bound those two lookups by when the card was created. mtime can't carry that
bound: resuming an old conversation rewrites its file, so a superseded rollout
can hold a newer mtime than the session that replaced it. Take the minted time
from the rollout's own filename instead, and skip anything minted before the
card existed. Unparseable names are not excluded, and entries predating
createdAt keep the old behaviour rather than becoming unresumable.

`launchedAt` semantics are untouched, so the launch-time probe still works off
mtime as before.
@jen-ps
jen-ps requested a review from psjamesh as a code owner August 25, 2026 08:36
@psjamesh
psjamesh merged commit f462046 into main Sep 7, 2026
2 checks passed
@psjamesh
psjamesh deleted the fix/codex-resume-binds-old-rollout branch September 7, 2026 16:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codex card can bind to a rollout that predates it, then resume it forever

2 participants