Files
codex/codex-rs/thread-store/src/error.rs
Owen Lin 5267e805fb feat(app-server): add history_mode to thread (#29927)
## Description

This PR adds a new `historyMode = "legacy" | "paginated"` to `Thread`.
This will be stored in `SessionMeta` in the JSONL rollout file and as a
new column in the SQLite thread_metadata table, and exposed on
`thread/start` and on the `Thread` object in app-server.

## What changed

- Added canonical `ThreadHistoryMode` with `legacy` and `paginated`,
defaulting old and new SessionMeta to `legacy`.
- Carried `history_mode` through core session config, ThreadStore stored
metadata, local/in-memory stores, rollout metadata extraction, and the
existing SQLite `threads` table.
- Added experimental `historyMode` to app-server v2 `Thread` and
`thread/start`.
- Made paginated stored threads metadata-discoverable but unsupported
for legacy full-history reads, `load_history`, live resume, and create
paths.
- Regenerated app-server schema fixtures and added
protocol/state/thread-store/app-server coverage for persistence and
fail-closed behavior.

## Compatibility floor
Because users may be running various versions of Codex binaries on the
same machine (TUI, Codex App, etc.), we will need to establish a
compatibility floor for upcoming paginated threads, which will change
how thread storage reads and writes work.

The overall plan here:
```
Release N:
- Add historyMode to SessionMeta / Thread / SQLite metadata.
- Teach binaries to understand paginated threads.
- If a binary sees `historyMode="paginated"` but does not support the paginated contract, it refuses to resume/mutate the thread.
- Default remains `"legacy"`.

Release N+1:
- First-party clients start opting into paginated threads where appropriate.
- Internal dogfood / staged rollout.
- Measure old-client usage and paginated-thread unsupported errors.

Release N+2:
- Only after Release N+ is overwhelmingly deployed, make paginated the default.
- Accept that a small tail of N-1-or-older binaries may not understand paginated threads.
```

The important behavior change is fail-closed handling for a binary that
encounters a persisted `paginated` thread before it knows how to fully
support paginated history. In app-server, if a thread is `paginated`, we
will:

- allow metadata-only discovery paths like `thread/list` and
`thread/read(includeTurns=false)`, so clients can still see the thread
and inspect its `historyMode`
- reject legacy full-history/live-thread paths like
`thread/read(includeTurns=true)` and `thread/resume` with an unsupported
JSON-RPC error
- avoid silently treating an unknown or future `historyMode` as `legacy`

Under the hood, the ThreadStore layer also rejects legacy operations
that would need to load or replay the full thread history for a
paginated thread. That gives us the behavior we want for Release N:
future paginated threads are visible, but this binary fails closed
instead of trying to operate on them as if they were legacy threads.
2026-06-26 09:12:42 -07:00

56 lines
1.7 KiB
Rust

use codex_protocol::ThreadId;
use codex_protocol::protocol::ThreadHistoryMode;
/// Result type returned by thread-store operations.
pub type ThreadStoreResult<T> = Result<T, ThreadStoreError>;
pub(crate) fn reject_paginated_history_mode(
history_mode: ThreadHistoryMode,
) -> ThreadStoreResult<()> {
if matches!(history_mode, ThreadHistoryMode::Paginated) {
return Err(ThreadStoreError::Unsupported {
operation: "paginated_threads",
});
}
Ok(())
}
/// Error type shared by thread-store implementations.
#[derive(Debug, thiserror::Error)]
pub enum ThreadStoreError {
/// The requested thread does not exist in this store.
#[error("thread {thread_id} not found")]
ThreadNotFound {
/// Thread id requested by the caller.
thread_id: ThreadId,
},
/// The caller supplied invalid request data.
#[error("invalid thread-store request: {message}")]
InvalidRequest {
/// User-facing explanation of the invalid request.
message: String,
},
/// The operation conflicted with current store state.
#[error("thread-store conflict: {message}")]
Conflict {
/// User-facing explanation of the conflict.
message: String,
},
/// The store implementation does not support this operation yet.
#[error("thread-store unsupported operation: {operation}")]
Unsupported {
/// Stable operation name for callers that need to map unsupported operations.
operation: &'static str,
},
/// Catch-all for implementation failures that do not fit a more specific category.
#[error("thread-store internal error: {message}")]
Internal {
/// User-facing explanation of the implementation failure.
message: String,
},
}