Skip to content

Harden SQLite fail-closed reads, model families, and audit overrides - #52

Merged
twidtwid merged 2 commits into
mainfrom
cursor/maintenance-sqlite-models-audit-887f
Oct 8, 2026
Merged

twidtwid merged 2 commits into
mainfrom
cursor/maintenance-sqlite-models-audit-887f

Conversation

@twidtwid

@twidtwid twidtwid commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

Maintenance work on main only (not the Claude/v0.3.0-beta provider work). No version bump, tag, or deploy.

  1. Audit release blocker. Bump the brace-expansion override to >=5.0.12 (resolves 5.0.12) and pin fast-uri to 3.1.8. Leave opentype.js at 1.3.4.
  2. SQLite fail-safe. #open() and queries now map missing DB, WAL/open failures, and schema mismatches to unsupported-schema (UNSUPPORTED) instead of throwing. Health and doctor surface a store component. Path discovery still prefers state_5.sqlite (CODEX_SQLITE_HOME / config.toml sqlite_home unchanged) and falls back to the highest-numbered state_*.sqlite when state_5 is absent.
  3. Model dial families. Families are derived from models_cache.json with the existing slug/reasoning allow-list (including stripping cache-only max), falling back to Luna/Terra/Sol/Astra when the cache is missing.
  4. Cleanup. Move test/astra-picker.fixture.test.ts into integrationTests so test:fast is native-free. Update MARKETPLACE.md (@elgato/streamdeck 3.0.1) and add a CHANGELOG Unreleased section (no version bump).

Merged origin/main at f0ed9f4 (#51 Guardian/subagent SQL filter). Conflict resolution keeps both: #51's schema-aware recentThreads/focusedThread SQL (thread_source, source.subagent, agent_path, spawn-edge exclusion, archived, DISTINCT/MAX(status), column detection) and this PR's fail-safe #open() wrapper plus state_*.sqlite fallback. Does not edit native/ComposerControls.swift. Native Targeting/Fixtures changes come from #51.

Validation

  • npm run check (macOS-14 CI on this PR, after merge)
  • npm audit --omit=dev --audit-level=high and npm run audit:full (0 vulnerabilities; brace-expansion@5.0.12, fast-uri@3.1.8, opentype.js@1.3.4)
  • Relevant connected-device checks, or an explanation of why they do not apply
  • No private data, credentials, proprietary Codex assets, or copied third-party source

Linux after the merge: public:check, generated:check, format:check, typecheck, docs:check, test:fast (323 passed, 1 skipped, including #51 subsession-filter and this PR's store/model tests), non-native integration (17 passed), build:bundle, validate. Connected-device checks do not apply.

User impact

  • Unreadable Codex state no longer blanks keys; Health and doctor surface UNSUPPORTED.
  • Model dial can pick up new cache families without a plugin code change.
  • Guardian reviewer sub-sessions stay excluded from Agent Status (Exclude Guardian reviewer sub-sessions from Agent Status #51).
  • No plugin version or Marketplace submission in this PR.
Open in Web Open in Cursor 

cursoragent and others added 2 commits October 8, 2026 13:09
Map unreadable Codex databases to the existing UNSUPPORTED health
state, fall back from state_5.sqlite to the newest state_*.sqlite,
and derive Model dial families from models_cache.json. Patch the
brace-expansion override and fast-uri so audits pass, and keep
test:fast free of native helper spawns.

Co-authored-by: Todd Dailey <twidtwid@users.noreply.github.com>
Keep Guardian sub-session SQL filtering from #51 together with the
read-only open/query fail-safe and state_*.sqlite fallback.

Co-authored-by: Todd Dailey <twidtwid@users.noreply.github.com>
@twidtwid
twidtwid marked this pull request as ready for review October 8, 2026 13:28
@twidtwid
twidtwid merged commit 42f8ffe into main Oct 8, 2026
1 check passed
@twidtwid
twidtwid deleted the cursor/maintenance-sqlite-models-audit-887f branch October 8, 2026 13:28
@twidtwid twidtwid mentioned this pull request Oct 8, 2026
4 of 5 tasks
twidtwid added a commit that referenced this pull request Oct 8, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

Prepare the v0.2.5 release from current `main` (`42f8ffe`), following
the v0.2.4 version-bump pattern. No feature work in this PR.

- Bump `0.2.4` → `0.2.5` in `package.json` and both top-level
`package-lock.json` version fields
- Bump plugin `manifest.json` `"Version"` to `"0.2.5.0"` (`SDKVersion`
3, Node.js 24, `MinimumVersion` 7.1 unchanged)
- Fold the Unreleased notes from #51 (Guardian/subagent session filter)
and #52 (SQLite fail-safe, model families, audit overrides) plus
Dependabot bumps including `@elgato/streamdeck` 3.0.1 into `## 0.2.5 —
2026-10-08`

This PR does not include Claude provider / draft PR #33 work. Do not
merge from that beta line. Do not tag or create a GitHub Release here;
tag after merge so `.github/workflows/release.yml` can pack and publish.

## Validation

- [x] Linux-allowed `release:verify` subset: `audit:full`,
`audit:production`, and `docs:check` (macOS-only native/`qa:design`
steps skipped on Linux)
- [x] `test:fast`, `build:bundle`, `streamdeck validate`,
`generated:check`
- [ ] Full `npm run check` on macOS CI
- [x] Relevant connected-device checks, or an explanation of why they do
not apply — version bump and changelog only; no device interaction
- [x] No private data, credentials, proprietary Codex assets, or copied
third-party source

## User impact

- Agent Status and the native helper no longer show or try to resume
Codex Guardian reviewer / subagent sub-sessions (reported by Paweł
Lipkowski; fixes "cannot resume a live Guardian reviewer"). A user chat
titled Guardian still shows.
- Unreadable Codex SQLite state fails closed; Health and doctor report
the store.
- Model dial families come from the Codex models cache.
- Stream Deck SDK 3.0.1 and security overrides (`brace-expansion`,
`fast-uri`) ship with this release.
- Install from the GitHub Release created when v0.2.5 is tagged after
merge.
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-c9c04dac-37cf-56af-9592-63ee0b0b2bbf?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-c9c04dac-37cf-56af-9592-63ee0b0b2bbf&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Todd Dailey <twidtwid@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants