Skip to content

Recover automatically from a protected suite-cache folder (1.3.0-rc.4) - #19

Merged
oliverdougherC merged 1 commit into
mainfrom
codex/windows-exit4-20260922
Sep 22, 2026
Merged

oliverdougherC merged 1 commit into
mainfrom
codex/windows-exit4-20260922

Conversation

@oliverdougherC

Copy link
Copy Markdown
Owner

What changes

  • `client/suite.py`: when the primary `.suite-pack` extraction is unreadable/replace-blocked (ACL or lock), fully verified content installs into `.suite-pack-recovered/` under the same user-writable suite cache root; reused on later starts without re-extraction; blocked folders are never deleted, read, or trusted.
  • Recovery is announced as a `recovery` preparation event: GUI event log line + status line, CLI `Cache recovery: ...`.
  • If neither location is writable, the failure names the real permission error and the cache path (no invented attribution).
  • Regression tests: recovery on unreadable primary, recovery on locked swap, reuse-without-reextraction, protected-folder-bytes-untouched, clear error when nothing is writable.

Release metadata

Freeze `1.3.0-rc.4` / `client/0.3.3`; run-page model retargeted (Windows digest stays null/honest-pending until the stamped follow-up); superseded section documents the published rc.3 pair with its digests; changelog entry added. Protocol 7.1, admission minimum, suite bytes, frozen fingerprints, scientific settings and backend untouched.

An extraction folder left by an elevated or foreign-account run stays
unreadable and undeletable for the normal user, so rc.3 only failed faster
with instructions to delete it using administrator rights. Now the verified
bytes go one step further: after the full archive, manifest, notice and clip
verification passes, the client atomically installs the extraction into a
deterministic writable location beside the blocked ".suite-pack" subtree,
announces the recovery in the preparation event stream (GUI event log and CLI),
and reuses that copy byte-for-byte on later starts. Nothing protected is
deleted, taken over or trusted; when even the alternate location cannot be
written the error names the actual permission cause and both paths. Freeze
1.3.0-rc.4 / client/0.3.3; protocol 7.1, admission minimum, suite bytes,
frozen fingerprints and scientific settings unchanged.
@oliverdougherC
oliverdougherC merged commit f1c036a into main Sep 22, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant