Skip to content

fix(codex): resume archived native sessions - #15389

Merged
maria-rcks merged 1 commit into
pingdotgg:mainfrom
maria-rcks:fix/10481-codex-archive-resume
Oct 3, 2026
Merged

maria-rcks merged 1 commit into
pingdotgg:mainfrom
maria-rcks:fix/10481-codex-archive-resume

Conversation

@maria-rcks

@maria-rcks maria-rcks commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

archiving a codex session externally makes thread/resume fail. on current v2, the shared turn-start service silently starts a replacement native session and replays app history. this change catches the specific archived-session error in CodexAdapterV2, calls thread/unarchive for the same native id, and retries the identical resume once.

unrelated errors keep propagating. if unarchive or the retry fails, the existing global fallback may still start a fresh native session; this pr leaves that policy unchanged.

closes #10481. closes #10505. maintainer triage specifies this recovery. replaces the v1 implementation in #10505, closed during the v2 migration.

verification:

  • isolated blacksmith: vp test run apps/server/src/orchestration-v2/Adapters/CodexAdapterV2.test.ts passed 133 tests, including 11 recovery/failure cases in the existing file. targeted lint and formatting passed; server typecheck exited 0. lint reports two existing unused-variable warnings.
  • actual web client with codex 0.160.0, one new sandbox thread: after a completed turn, archive only its new native session, restart the sandbox backend to force resume, then send the same followup. baseline replaced native 01a1040d-2cf6-7ad0-ad78-caf497cc7511 with 01a1040f-3c59-7170-8190-8dd3580ce1d7. with only the adapter patch applied, repeating the archive/restart/followup kept 01a1040f-3c59-7170-8190-8dd3580ce1d7 and completed the turn without a new resume-failed warning.

the terminal in these captures runs a read-only query of the sandbox's actual persisted run-attempt.updated events. before: completed runs 1 and 2 have different native ids. after: runs 2 and 3 have the same native id. both versions recalled the token through conversation history, so token recall alone does not prove native-session continuity.

before: actual completed runs 1 and 2 show different native codex session ids

after: actual completed runs 2 and 3 retain the same native codex session id

after: real client followup completes with the original native session and read-only event proof.

after.mp4

desktop, mobile, remote/relay, tunnel, and live chatgpt archive were not independently exercised. the shared server adapter serves those clients; the real provider archive was exercised through codex's native rpc. no client ui or wire contracts change.

implemented by gpt-6.1-sol with xhigh reasoning through the codex harness in t3 code.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Oct 3, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 1b082c1

Macroscope's review found this PR approvable — This is a focused Codex adapter bug fix that restores archived sessions through an unarchive-and-resume sequence while preserving unrelated failures. Production behavior is confined to the existing resume path, with targeted tests covering recovery and error handling.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d9e693b8-55d2-4caf-b41b-4e6b9c76c5a4
📥 Commits

Reviewing files that changed from the base of the PR and between 243d1e7 and 1b082c1.

📒 Files selected for processing (2)
  • apps/server/src/orchestration-v2/Adapters/CodexAdapterV2.test.ts
  • apps/server/src/orchestration-v2/Adapters/CodexAdapterV2.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The Codex adapter now unarchives a thread and retries its resume request when Codex returns a matching archived-session error. Replay tests cover recovery, retry failures, and errors that should not trigger unarchiving.

Changes

Archived Codex thread recovery

Layer / File(s) Summary
Resume, unarchive, and retry
apps/server/src/orchestration-v2/Adapters/CodexAdapterV2.ts
resumeThread sends the raw resume request. For matching archived-session errors, it requests thread/unarchive and retries the same resume. Other request errors are rethrown.
Replay recovery and error cases
apps/server/src/orchestration-v2/Adapters/CodexAdapterV2.test.ts
Parameterized tests cover archived-session recovery, errors that do not trigger unarchiving, retry failures, and resumed thread state.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Low

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 1b082

The archived-session recovery appears ready to merge after normal checks. No concrete remaining issue is identified in the supplied change context.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1b082

Recovery targets the existing saved session and retries once without changing credentials or permissions. No introduced security vulnerability was established. The remaining uncertainty is how session state is reconciled when recovery fails or is interrupted after reactivation.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — Each recovery request targets the single native thread already referenced by the provider-thread object and uses the existing session client. This establishes the immediate operation scope, not the deployment’s full tenant or credential exposure.

Trust Boundaries and Controls

  • observed — Recovery requires a typed app-server request error with matching text. The tested authentication-failed, archived-workspace and archive-path permission-denied messages do not issue unarchive. The adapter retains the same provider authority; upstream ownership authorization was not established by this scope.

Resilience and Maintainability Implications

  • inferred — Successful unarchive followed by failed resume can leave the original native session unarchived while the existing fallback creates a replacement. The shown recovery and fallback paths contain no compensating rearchive. Whether this is intentionally retained state or reconciled elsewhere remains unresolved; unauthorized access was not demonstrated.

Hardening Proposals

  • proposed — Define and exercise native-session ownership semantics for interruption, retry failure and concurrent recovery after unarchive succeeds. Establish whether retaining the original unarchived session is intentional before adding reconciliation or compensation that could interfere with another successful caller.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #10481 requires a Codex thread to resume and accept a new message after ChatGPT archives its native session. CodexAdapterV2.resumeThread now catches archived-session or codex unarchive error…
Out of Scope Changes check ✅ Passed The changes are limited to archived-session recovery in CodexAdapterV2 and tests for that behavior. The added tests support issue #10481. No unrelated changes appear in the reviewed diff.
Title check ✅ Passed The title clearly and concisely identifies the fix: resuming archived native Codex sessions.
Description check ✅ Passed The description covers the problem, implementation, scope and maintainer triage, focused tests, real-client verification, and limitations. It meets the template requirements.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@maria-rcks

Copy link
Copy Markdown
Collaborator Author

Note

Written by gpt-6.1-sol on behalf of Maria

the docstring coverage warning does not require a change for this focused fix. the existing resumeThread contract is unchanged, and the recovery path has a local comment explaining why the unarchive response is ignored. the existing adapter test file covers recovery and failure behavior; adding documentation solely to reach the generic coverage percentage would not help explain this change.

@maria-rcks
maria-rcks merged commit 44bd4c9 into pingdotgg:main Oct 3, 2026
32 checks passed
github-actions Bot added a commit to davidvanderklay/t3code-flake that referenced this pull request Oct 4, 2026
## What's Changed
* feat(web): Nightly tells you to get the beta mobile app by @t3dotgg in pingdotgg/t3code#15070
* test(server): ACP adapter tests no longer race the prompt settle by @t3dotgg in pingdotgg/t3code#15330
* feat(usage): fold preview model IDs into the model they belong to by @t3dotgg in pingdotgg/t3code#15333
* refactor(server): check RPC scopes in group middleware by @juliusmarminge in pingdotgg/t3code#15324
* feat(mobile): beta Working section hides busy threads until they need you by @t3dotgg in pingdotgg/t3code#15346
* fix(settings): symlinked settings files stay linked when saved by @yordis in pingdotgg/t3code#15009
* fix(server): Stop ends a dev server left running before a provider switch by @t3dotgg in pingdotgg/t3code#15355
* fix(server): merged threads settle even after the agent wakes on its own by @t3dotgg in pingdotgg/t3code#15388
* fix(web): no-project drafts can switch machines by @maria-rcks in pingdotgg/t3code#15356
* fix(web): highlight tool inputs and remove nested work log indentation by @Yash-Singh1 in pingdotgg/t3code#15384
* fix(server): restarts keep delegated tasks, queued threads, and stops intact by @maria-rcks in pingdotgg/t3code#15323
* fix(web): sending past the resume banner compacts first by @maria-rcks in pingdotgg/t3code#15290
* fix(codex): resume archived native sessions by @maria-rcks in pingdotgg/t3code#15389
* feat(web): morph composer and panel action icons by @jakeleventhal in pingdotgg/t3code#14924
* fix(web): subagents sent a follow-up show as running in Lineage by @scratchyone in pingdotgg/t3code#15334
* fix(web): clear stale chat action shortcuts by @maria-rcks in pingdotgg/t3code#15394
* fix(orchestration-v2): restore earlier app agent transcript pages by @Bil0000 in pingdotgg/t3code#14104
* fix(web): remove the square thread info panel shadow by @PixPMusic in pingdotgg/t3code#15069
* fix(mobile): Android usage widget no longer sticks on "Loading widget" in release builds by @tris203 in pingdotgg/t3code#15142
* fix(web): size the model picker to its content by @saphid in pingdotgg/t3code#15152
* test(server): replay checks a Claude subagent's thread takes its reported model by @juliusmarminge in pingdotgg/t3code#15022
* fix(web): subagent finish notifications look like subagent cards by @flamboh in pingdotgg/t3code#15281
* fix(web): thread status dot has an accessible name by @ryanilano in pingdotgg/t3code#14587
* fix(web): legacy sidebar options button has a label by @ryanilano in pingdotgg/t3code#14602
* fix(web): imported themes keep switches and focus rings visible by @flamboh in pingdotgg/t3code#14498
* fix(web): links to issues no longer strand the pull request viewer by @flamboh in pingdotgg/t3code#14242
* fix(web): repo/task breadcrumb no longer bounces when the sidebar collapses by @flamboh in pingdotgg/t3code#15046
* fix(web): Pull request panel entry works for linked PRs by @flamboh in pingdotgg/t3code#15061
* fix(web): add context menu to draft threads in the sidebar by @flamboh in pingdotgg/t3code#10637
* fix(web): keep sidebar branding and build pills from clipping at varying font sizes and zoom levels by @flamboh in pingdotgg/t3code#12141
* fix(usage): model shares and order follow the selected metric by @flamboh in pingdotgg/t3code#11391
* feat(web): sweep sidebar buttons to settle, un-settle, and wake threads by @argofowl in pingdotgg/t3code#14768
* feat: retry a failed workspace preparation by @juliusmarminge in pingdotgg/t3code#15326

## New Contributors
* @argofowl made their first contribution in pingdotgg/t3code#14768

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261003.2638...v0.0.46-nightly.20261004.2644

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261004.2644
github-actions Bot added a commit to omarcresp/t3code-flake that referenced this pull request Oct 4, 2026
## What's Changed
* feat(web): Nightly tells you to get the beta mobile app by @t3dotgg in pingdotgg/t3code#15070
* test(server): ACP adapter tests no longer race the prompt settle by @t3dotgg in pingdotgg/t3code#15330
* feat(usage): fold preview model IDs into the model they belong to by @t3dotgg in pingdotgg/t3code#15333
* refactor(server): check RPC scopes in group middleware by @juliusmarminge in pingdotgg/t3code#15324
* feat(mobile): beta Working section hides busy threads until they need you by @t3dotgg in pingdotgg/t3code#15346
* fix(settings): symlinked settings files stay linked when saved by @yordis in pingdotgg/t3code#15009
* fix(server): Stop ends a dev server left running before a provider switch by @t3dotgg in pingdotgg/t3code#15355
* fix(server): merged threads settle even after the agent wakes on its own by @t3dotgg in pingdotgg/t3code#15388
* fix(web): no-project drafts can switch machines by @maria-rcks in pingdotgg/t3code#15356
* fix(web): highlight tool inputs and remove nested work log indentation by @Yash-Singh1 in pingdotgg/t3code#15384
* fix(server): restarts keep delegated tasks, queued threads, and stops intact by @maria-rcks in pingdotgg/t3code#15323
* fix(web): sending past the resume banner compacts first by @maria-rcks in pingdotgg/t3code#15290
* fix(codex): resume archived native sessions by @maria-rcks in pingdotgg/t3code#15389
* feat(web): morph composer and panel action icons by @jakeleventhal in pingdotgg/t3code#14924
* fix(web): subagents sent a follow-up show as running in Lineage by @scratchyone in pingdotgg/t3code#15334
* fix(web): clear stale chat action shortcuts by @maria-rcks in pingdotgg/t3code#15394
* fix(orchestration-v2): restore earlier app agent transcript pages by @Bil0000 in pingdotgg/t3code#14104
* fix(web): remove the square thread info panel shadow by @PixPMusic in pingdotgg/t3code#15069
* fix(mobile): Android usage widget no longer sticks on "Loading widget" in release builds by @tris203 in pingdotgg/t3code#15142
* fix(web): size the model picker to its content by @saphid in pingdotgg/t3code#15152
* test(server): replay checks a Claude subagent's thread takes its reported model by @juliusmarminge in pingdotgg/t3code#15022
* fix(web): subagent finish notifications look like subagent cards by @flamboh in pingdotgg/t3code#15281
* fix(web): thread status dot has an accessible name by @ryanilano in pingdotgg/t3code#14587
* fix(web): legacy sidebar options button has a label by @ryanilano in pingdotgg/t3code#14602
* fix(web): imported themes keep switches and focus rings visible by @flamboh in pingdotgg/t3code#14498
* fix(web): links to issues no longer strand the pull request viewer by @flamboh in pingdotgg/t3code#14242
* fix(web): repo/task breadcrumb no longer bounces when the sidebar collapses by @flamboh in pingdotgg/t3code#15046
* fix(web): Pull request panel entry works for linked PRs by @flamboh in pingdotgg/t3code#15061
* fix(web): add context menu to draft threads in the sidebar by @flamboh in pingdotgg/t3code#10637
* fix(web): keep sidebar branding and build pills from clipping at varying font sizes and zoom levels by @flamboh in pingdotgg/t3code#12141
* fix(usage): model shares and order follow the selected metric by @flamboh in pingdotgg/t3code#11391
* feat(web): sweep sidebar buttons to settle, un-settle, and wake threads by @argofowl in pingdotgg/t3code#14768
* feat: retry a failed workspace preparation by @juliusmarminge in pingdotgg/t3code#15326

## New Contributors
* @argofowl made their first contribution in pingdotgg/t3code#14768

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261003.2638...v0.0.46-nightly.20261004.2644

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261004.2644
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S 10-29 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

1 participant