Skip to content

Commit 34b7477

Browse files
committed
fix: distinguish owned host cache namespaces from task effects
1 parent 019ce4c commit 34b7477

2 files changed

Lines changed: 16 additions & 1 deletion

File tree

‎scripts/lib/real-codex-host-probe.js‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1009,6 +1009,7 @@ function partitionInstalledRuntimeEffects(effects, identity) {
10091009
for (const change of effects.unexpectedChanges || []) {
10101010
const name = change.path
10111011
const ordinaryFile = [change.before, change.after].every(value => !value || value.type === 'file')
1012+
const ordinaryDirectory = [change.before, change.after].every(value => !value || value.type === 'directory')
10121013
const createdDirectory = !change.before && change.after?.type === 'directory'
10131014
let owned = false
10141015
if (change.root === 'addDir') {
@@ -1020,8 +1021,15 @@ function partitionInstalledRuntimeEffects(effects, identity) {
10201021
}
10211022
} else if (change.root === 'globalHome') {
10221023
owned = createdDirectory && ['.codex/devcodex/.runtime-generation-leases', leaseRoot].includes(name)
1024+
// The host populates and refreshes these cache namespaces independently of
1025+
// task commands. Preserve their diffs without enumerating plugin versions
1026+
// or assets; config, credentials and the installed runtime stay protected.
1027+
const hostCachePath = ['.codex/cache', '.codex/plugins/cache'].some(root => name === root || name.startsWith(root + '/')) &&
1028+
!name.split('/').some(part => part === '.' || part === '..') && !name.includes('\\')
1029+
if ((hostCachePath && (ordinaryFile || ordinaryDirectory)) ||
1030+
(createdDirectory && name === '.codex/plugins')) owned = true
10231031
if (ordinaryFile) {
1024-
owned = name === '.codex/models_cache.json' ||
1032+
owned = owned || name === '.codex/models_cache.json' ||
10251033
/^\.codex\/(?:state|goals|logs|memories)_[0-9]+\.sqlite(?:-shm|-wal)?$/u.test(name) ||
10261034
/^AppData\/Local\/Microsoft\/PowerShell\/(?:ModuleAnalysisCache-[A-Fa-f0-9]+|StartupProfileData-NonInteractive)$/u.test(name) ||
10271035
(name.startsWith(leaseRoot + '/') && /^(?:memory|profile)-mcp-[a-f0-9]{8}-[0-9]+\.json$/u.test(name.slice(leaseRoot.length + 1)))

‎scripts/test-real-codex-host-probe.js‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -701,6 +701,9 @@ async function main() {
701701
[effectHome, '.codex/memories_1.sqlite'],
702702
[effectHome, '.codex/state_5.sqlite-wal'],
703703
[effectHome, '.codex/models_cache.json'],
704+
[effectHome, '.codex/cache/remote_plugin_catalog/catalog.json'],
705+
[effectHome, '.codex/plugins/cache/market/plugin/1.2.3/.codex-plugin/plugin.json'],
706+
[effectHome, '.codex/plugins/cache/market/plugin/1.2.3/assets/new-asset.txt'],
704707
[effectHome, '.codex/devcodex/.runtime-generation-leases/fixture-generation/memory-mcp-24efaa5d-12032.json'],
705708
[effectHome, 'AppData/Local/Microsoft/PowerShell/ModuleAnalysisCache-0C86AEE9'],
706709
[effectHome, 'AppData/Local/Microsoft/PowerShell/StartupProfileData-NonInteractive'],
@@ -740,6 +743,8 @@ async function main() {
740743
for (const [root, name] of [
741744
['globalHome', '.codex/config.toml'], ['globalHome', '.codex/auth.json'],
742745
['globalHome', '.codex/models_cache.json.backup'], ['addDir', '.codex/models_cache.json'],
746+
['globalHome', '.codex/plugins/config.toml'], ['globalHome', '.codex/plugins/cache-other/asset.txt'],
747+
['globalHome', '.codex/cache/../config.toml'], ['addDir', '.codex/plugins/cache/asset.txt'],
743748
['globalHome', '.codex/devcodex/runtime-fixture-generation/mcp/memory-server.js'],
744749
['globalHome', '.codex/devcodex/.runtime-generation-leases/other-generation/memory-mcp-24efaa5d-12032.json'],
745750
['addDir', '.memory/hooks/another-project/lifecycle-state.json'], ['addDir', 'unexpected.txt'],
@@ -752,6 +757,8 @@ async function main() {
752757
assert.deepStrictEqual(partitionInstalledRuntimeEffects({ ...rawEffects, unexpectedChanges: [linkEffect] }, effectIdentity).unexpectedChanges, [linkEffect])
753758
const cacheLinkEffect = { ...linkEffect, path: '.codex/models_cache.json' }
754759
assert.deepStrictEqual(partitionInstalledRuntimeEffects({ ...rawEffects, unexpectedChanges: [cacheLinkEffect] }, effectIdentity).unexpectedChanges, [cacheLinkEffect])
760+
const pluginCacheLink = { ...linkEffect, path: '.codex/plugins/cache/market/plugin/asset' }
761+
assert.deepStrictEqual(partitionInstalledRuntimeEffects({ ...rawEffects, unexpectedChanges: [pluginCacheLink] }, effectIdentity).unexpectedChanges, [pluginCacheLink])
755762
const independentLedger = initializeAttemptLedger({ evidenceRoot, identity: effectIdentity })
756763
const deniedAttempt = claimAttempt(independentLedger, 'H1')
757764
const deniedBytes = Buffer.from(JSON.stringify(deniedReceipt) + '\n')

0 commit comments

Comments
 (0)