Open the attachments connection the way Madrid opened chat.db - #246
Merged
Merged
Conversation
The second SQLite connection that reads attachments assumed that the default database path and folder grants always open chat.db with its write-ahead log. When Madrid falls back to immutable mode because the log is unreadable, that connection still opened with mode=ro, and macOS refused it, so messages_fetch with attachments failed with "authorization denied". Take the mode from the database's accessMode.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved review issues were identified.
Review effort: Lite
Findings: None
What changed in this PR
Updates attachment database access to use the same resolved SQLite mode as the primary Messages connection, fixing reads when the WAL is inaccessible.
Changes:
- Derives
immutablefromdatabase.accessMode. - Removes duplicated access-mode state.
- Aligns attachment queries with the primary connection.
| File | Description |
|---|---|
App/Services/Messages.swift |
Synchronizes attachment database connections with the primary database mode. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
When chat.db is readable at its default path, for example through a permission left over from an earlier grant on chat.db alone, openDatabase used that path without the folder grant's security scope, so reading an attachment failed with "Operation not permitted". Use a folder grant first when one is stored. The Messages toggle now also offers the folder when chat.db is readable but the Attachments folder is not.
| // for example through a permission left over from an earlier grant on chat.db alone. | ||
| // The toggle then offers the folder; tool calls keep working with what is readable. | ||
| let canReadDefaultPath = canAccessDatabaseAtDefaultPath | ||
| if canReadDefaultPath, !offeringUpgrade || canAccessAttachmentsAtDefaultPath { |
The menu toggle only runs activate() for a service that reports itself as not activated. Messages reported activated whenever chat.db was readable at its default path, so the toggle never offered the folder when the Attachments folder was unreadable.
…able" This reverts commit 962e76e.
This reverts commit f809c18.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

The attachments added in #244 are listed through a second SQLite connection, which assumed that the default database path and folder grants always open
chat.dbwith its write-ahead log. When the log is unreadable, Madrid falls back toimmutable=1, but the second connection still opened withmode=ro. macOS refused it, somessages_fetchwithattachments: truefailed withattachmentsQueryFailed("authorization denied").This PR makes
DatabaseAccess.immutablefollow the database'saccessMode, so both connections open the file the same way.