refactor(sessions)!: delete the Codex v1 source-cursor replay - #2730
Merged
Merged
Conversation
Codex admission read the retired per-session source cursor on every pass and, when the v2 cursor lagged it, replayed current user messages into the v2 source. That carried data from an old identity into the new one. Only binaries before the unified observation identity wrote that cursor, and a store holding observation rows without the unified-identity marker is already refused with the scoped `tracedecay wipe --stale --yes` reset. Admission now reads only the v2 source, and the replay-only JSONL admission plumbing (required start cursor, end-offset bound, existence precheck) and `HostAdmission::observation_receipt` are gone. BREAKING CHANGE: Codex admission ignores cursors of the retired per-session source identity; stores that still carry them beside observation rows must be reset with `tracedecay wipe --stale --yes`.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was wrong
Codex admission read the retired per-session source cursor (
ObservationSourceIdentityV1::for_provider(codex, session)) on every pass. When the v2 cursor fromcodex_observation_source_v2lagged it,legacy_cursor_matches_current_file+replay_advanced_current_user_messages(CodexAdmissionMode::CurrentUserMessageReplay) replayed current user messages into v2. That is a data migration from an old identity into the new one, which the product rules forbid.Why deleting it cannot duplicate observations
native_ingest_source_identity("codex", ..)already resolves to v2).tracedecay wipe --stale --yes, fix(sessions)!: scope stale session-store refusals and reset #2613/fix(sessions): scope every session-store refusal to sessions #2648) before admission runs.What changed
codex/observation.rs: admission reads only the v2 source. DeletedCodexAdmissionMode,replay_advanced_current_user_messages,legacy_cursor_matches_current_file, the v1 cursor read, and the replay-frame branches.jsonl_observation_admission.rs: deleted the replay-only plumbing:with_required_start_cursor,with_max_end_offset,JsonlFrameAdmission::durable_unless_observation_exists, and the per-frameskip_if_observation_existsprecheck path.HostAdmission::observation_receipt: removed along with its production (tracedecay-host-admission) and in-memory impls andHostAdmissionOutcome::observation_point_read_unavailable. Its only caller was the replay precheck.replay_boundary_tests,legacy_current_message_migration_records_receipted_duplicate_coverage, and the threeruntime_acceptance_suitelegacy-migration tests.Proof
Fail before / pass after.
retired_source_cursor_neither_gates_nor_narrows_canonical_admission(sessions lib) seeds a v1 Codex cursor covering the whole rollout into an admitted store. It then drives the production hook entrytry_admit_codex_jsonl_observations_for_project_with_admissiontwice and asserts literal counts: 3 frames persisted and 3 observations on the first pass, 0 persisted and still 3 observations on the second.origin/master: FAILED withassertion failed: !first.source_deferred, because the v1 cursor turned the pass into a deferred user-message replay.Typed operator state for a store carrying v1 cursor + rows.
retired_codex_source_cursor_store_refuses_sessions_with_scoped_reset(runtime_acceptance_suite) does the following:ResetRequired { authority: "observations", reason: "observation rows predate the unified observation identity and cannot be read; reset the profile so ingestion can rebuild them from host transcripts" }, with theobservationsrow count exactly 3 before and after.Suites:
cargo test -p tracedecay-sessions --lib-p tracedecay-host-admission --lib-p tracedecay --features test-helpers --test runtime_acceptance_suite -- codex--test transcript_ingest_suite -- codex(with the debug CLI built)cargo clippy -p tracedecay-sessions -p tracedecay-host-admission --all-targets -- -D warnings: clean.cargo clippy -p tracedecay --features test-helpers --test runtime_acceptance_suite -- -D warnings: clean.cargo fmt --all -- --check: clean.cfg(windows)code or Windows-only callers touched.Runtime journey. Debug CLI from this branch, isolated
HOME/TRACEDECAY_DATA_DIR, one daemon undersystemd-run --user --scope -p MemoryMax=6G -p MemorySwapMax=1G, synthetic Codex rollout plus Cursor transcript:Fixes #2700
BREAKING CHANGE: Codex admission ignores cursors of the retired per-session source identity; stores that still carry them beside observation rows must be reset with
tracedecay wipe --stale --yes.