Files
orca/src/main/codex/codex-path-observation.ts
T
Brennan Benson 0b80a773a4 fix(codex): stop overwriting and deleting Codex files that were merely unreadable (STA-4737) (#15287)
* fix(codex): stop overwriting and deleting Codex files that were merely unreadable (STA-4737)

Three modules shared by the host and WSL Codex lanes decided a file was absent
from a read that had only failed, and then wrote over it or removed it.

- `codex-config-mirror`: `existsSync` on the RUNTIME config.toml returned false
  for a locked file exactly as for an absent one, so the mirror took the
  "seed a fresh runtime config" branch and replaced the user's config wholesale.
- `config-settings-promotion`: an unreadable ~/.codex/config.toml counted as
  having no promoted settings, and the write path then rebuilt the user's
  canonical Codex config from Orca's runtime copy.
- `codex-home-paths`: both delete branches in `linkSystemCodexResource` remove
  Orca's mirrored copy because the system resource "is not there". `existsSync`
  and `systemResourceIsRegularFile`'s `catch { return false }` both reported
  that for a source nobody could read, so one denied read on ~/.codex/AGENTS.md
  removed the managed copy on the next launch.

`src/shared/definitive-filesystem-absence.ts` now owns the one errno allowlist —
ENOENT and ENOTDIR, with every other code including unrecognised ones treated as
indeterminate — and `host-codex-managed-home-ownership.ts` drops its private
copy rather than letting the two drift. `codex-path-observation.ts` builds the
three-valued observation on top of it.

The resource sync's two `existsSync`/`statSync` probes collapse into one
resolved stat, which answers reachability and regular-file-ness together and
closes the window between them.

`config-settings-promotion.ts` crossed its max-lines budget, so the write-target
resolution moves to its own module rather than taking a lint exemption.

Deliberately not here: the hook-service trust writes that run after a refused
mirror, and the promotion write target's own classification, which is
unreachable because it always resolves to the same file the read above already
refused. Both are noted in comments rather than half-built.

* fix(codex): preserve resource copies on indeterminate reads
2026-08-18 14:10:32 -07:00

44 lines
1.7 KiB
TypeScript

import { statSync, type Stats } from 'node:fs'
import { isDefinitiveAbsence } from '../../shared/definitive-filesystem-absence'
import { readAgentStateFileSync } from '../agent-state-file-reader'
/**
* A filesystem read either answered, definitively answered "not there", or
* failed to answer at all.
*
* `existsSync` collapses the last two into `false`, and a `catch` that returns a
* default collapses them into the default. That is how a held lock comes to
* authorise an overwrite or a delete: the caller reads "this file is not there"
* from evidence that says only "I could not look".
*/
export type CodexPathObservation<T> =
| { kind: 'present'; value: T }
| { kind: 'absent' }
| { kind: 'indeterminate'; error: unknown }
/**
* Classify any read. Only `ENOENT`/`ENOTDIR` are absence — every other errno,
* including unrecognised ones, is indeterminate. Mapping an unknown errno to a
* verdict is the category error this module exists to prevent.
*/
export function observe<T>(read: () => T): CodexPathObservation<T> {
try {
return { kind: 'present', value: read() }
} catch (error) {
return isDefinitiveAbsence(error) ? { kind: 'absent' } : { kind: 'indeterminate', error }
}
}
/** Why: one call replaces the `existsSync` + read pair, closing its TOCTOU window too. */
export function observeAgentStateFile(filePath: string): CodexPathObservation<string> {
return observe(() => readAgentStateFileSync(filePath))
}
/**
* `stat`, so a symlink resolves to its target — the same reachability question
* `existsSync` answers, but with the failure kept distinct from the absence.
*/
export function observeResolvedPathEntry(entryPath: string): CodexPathObservation<Stats> {
return observe(() => statSync(entryPath))
}