Skip to content

Windows codex-cli 0.160.1: app-server exits during initialize with SQLite state-runtime/backfill symptoms #52229

Description

@aleg448

What version of Codex CLI is running?

codex-cli 0.160.1. The executable matched the previously recorded binary hash. No upgrade or replacement was used for this diagnosis.

What subscription do you have?

Not disclosed. The reproduction did not reach an account/read request.

Which model were you using?

None in the initialization-only probe. No thread/start, account/read, or turn/start request was sent.

What platform is your computer?

Windows, native Codex executable. The Windows build number is not included in the retained evidence.

What terminal emulator and version are you using (if applicable)?

Programmatic stdio subprocess. PowerShell was used for local diagnostics; an interactive terminal-emulator version was not collected.

Codex doctor report

Not collected. This report preserves a bounded initialization-only diagnostic scope; no new native CLI launch or raw diagnostic archive was collected for publication.

What issue are you seeing?

The native app-server exits before answering a valid initialize request. The latest retained initialization-only probe reached stdout EOF at 30.313 seconds and exited with code 1, before its 45-second watchdog. It sent only initialize; there was no valid initialization response and no initialized notification. Account, thread, and model setup were not reached by the client.

The complete stderr capture was 611 bytes and was not truncated. Its sanitized projection retained these ordered fragments; original line boundaries were flattened by the earlier local observer:

(os error 5) ... (os error 5)
state [REDACTED_VALUE] backfill is running at [REDACTED_PATH]
Error: failed to initialize sqlite state runtime [REDACTED_VALUE] [REDACTED_PATH]

The access-denied fragments came from temporary/PATH setup warnings. They do not establish the cause of the later fatal SQLite initialization error. The exact underlying SQLite cause and error code remain unknown. This report does not claim database corruption, a lock conflict, a stale backfill lease, or a confirmed backfill timeout.

A supported per-launch sqlite_home pointing to an owned workspace state directory was previously tested. It did not produce successful initialization. It was not promoted into a model runner.

What steps can reproduce the bug?

Observed workflow, rather than a separately validated portable minimal reproducer:

  1. Launch the installed native codex-cli 0.160.1 executable with the app-server subcommand, binary stdio pipes, the original working directory, and the existing restrictive tool/network/sandbox overrides.
  2. For the previously tested candidate, keep the original arguments and add only the supported per-launch sqlite_home location in an owned workspace directory. Do not redirect authentication or replace existing native state.
  3. Send exactly one schema-valid initialize request containing the required client metadata. Do not send account, thread, or turn methods.
  4. Read stdout/stderr with bounded capture and a 45-second watchdog.
  5. In the retained probe, observe stdout EOF and native exit 1 at 30.313 seconds without an initialization reply, accompanied by the sanitized backfill/SQLite symptoms above.

The private working directory and client identifiers are omitted. No new probe was run for this public report, and no independent clean-install reproduction is claimed.

What is the expected behavior?

The app-server should complete its initialization handshake under a supported execution policy, or return actionable startup diagnostics that preserve the underlying failure while protecting private values. A supported state-directory option should not be treated as a successful workaround until an initialization reply is verified.

Additional information

Local observer repair: the initial sanitizer overredacted the fatal wrapper failed to initialize sqlite state runtime under <path>: <cause>. Its unquoted Windows path pattern consumed the same-line cause as well as the path. This was a defect in our local observation code, not an asserted upstream Codex logging defect. An additive observer now preserves complete ordered sanitized lines, the exact wrapper boundary, and context-bound diagnostic codes while retaining secret/path redaction. Twelve focused offline tests passed with zero failures or errors; native process and socket dispatch were blocked. Those synthetic tests verify the observer, not the native startup bug. The discarded historical cause cannot be recovered from the old sanitized receipt.

Separate execution blocker: a later ordinary read-only request was refused during Windows sandbox preparation, before PowerShell or a native CLI child started:

windows unelevated restricted-token sandbox cannot enforce split writable root sets directly; refusing to run unsandboxed

This independently verified split-root preparation failure prevents another supported probe in that environment. It is not established as the cause of the earlier SQLite fatal error. No sandbox weakening, original-state database modification, credential change, or unsandboxed native retry was used to conceal it.

Related existing reports: #49653 describes a native Windows SQLite startup failure; #28087 concerns incomplete backfill state; #35864 covers the split-root sandbox family. Similar symptoms do not establish the same underlying cause here. The sandbox symptom is already reported and is included only as a limitation on further diagnosis. Please triage this evidence with the existing reports rather than treating it as proof of a distinct new defect.

Official references: sqlite_home configuration, app-server initialization lifecycle, and supported diagnostic environment variables. No diagnostic environment override was applied during report preparation.

Report author: Joan AK Wolf. Prepared with AI assistance for evidence inspection, local observer implementation, focused tests, and technical writing. This credit does not identify or rename the submitting GitHub account.

No raw logs, session dumps, conversation text, private paths, or credentials are attached. The native startup failure remains unresolved.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions