crates/tracedecay-sessions/src/runtime/hosts/codex/observation.rs still reads the retired Codex source identity, ObservationSourceIdentityV1::for_provider(codex, session), on every admission. When the v2 cursor from codex_observation_source_v2 lags, it replays current user messages into v2. The functions involved are legacy_cursor_matches_current_file, replay_advanced_current_user_messages, and CodexAdmissionMode::CurrentUserMessageReplay, all added 2026-09-04 in 9786266 ("make Codex prompt recovery durable").
This carries data from an old identity into the new one, which the product rules disallow: old on-disk shapes get a typed reset refusal or a rebuild, never a migration. Deleting the replay alone would re-admit v1-covered rollouts from byte 0 under v2 and could duplicate observations. The cutover therefore needs a decision first: either refuse stores that still hold v1 Codex source cursors with the scoped tracedecay wipe --stale --yes session-store reset, or prove that re-admission under v2 is idempotent. After that, delete the replay mode, the v1 cursor read, and their tests.
Found by the legacy-api-sweep sessions lane.
crates/tracedecay-sessions/src/runtime/hosts/codex/observation.rsstill reads the retired Codex source identity,ObservationSourceIdentityV1::for_provider(codex, session), on every admission. When the v2 cursor fromcodex_observation_source_v2lags, it replays current user messages into v2. The functions involved arelegacy_cursor_matches_current_file,replay_advanced_current_user_messages, andCodexAdmissionMode::CurrentUserMessageReplay, all added 2026-09-04 in 9786266 ("make Codex prompt recovery durable").This carries data from an old identity into the new one, which the product rules disallow: old on-disk shapes get a typed reset refusal or a rebuild, never a migration. Deleting the replay alone would re-admit v1-covered rollouts from byte 0 under v2 and could duplicate observations. The cutover therefore needs a decision first: either refuse stores that still hold v1 Codex source cursors with the scoped
tracedecay wipe --stale --yessession-store reset, or prove that re-admission under v2 is idempotent. After that, delete the replay mode, the v1 cursor read, and their tests.Found by the legacy-api-sweep sessions lane.