Skip to content

Open the attachments connection the way Madrid opened chat.db - #246

Merged
mattt merged 5 commits into
mainfrom
mattt/attachments-follow-access-mode
Sep 26, 2026
Merged

mattt merged 5 commits into
mainfrom
mattt/attachments-follow-access-mode

Conversation

@mattt

@mattt mattt commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

The attachments added in #244 are listed through a second SQLite connection, which assumed that the default database path and folder grants always open chat.db with its write-ahead log. When the log is unreadable, Madrid falls back to immutable=1, but the second connection still opened with mode=ro. macOS refused it, so messages_fetch with attachments: true failed with attachmentsQueryFailed("authorization denied").

This PR makes DatabaseAccess.immutable follow the database's accessMode, so both connections open the file the same way.

The second SQLite connection that reads attachments assumed that the
default database path and folder grants always open chat.db with its
write-ahead log. When Madrid falls back to immutable mode because the
log is unreadable, that connection still opened with mode=ro, and
macOS refused it, so messages_fetch with attachments failed with
"authorization denied". Take the mode from the database's accessMode.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Updates attachment database access to use the same resolved SQLite mode as the primary Messages connection, fixing reads when the WAL is inaccessible.

Changes:

  • Derives immutable from database.accessMode.
  • Removes duplicated access-mode state.
  • Aligns attachment queries with the primary connection.
File Description
App/​Services/​Messages.swift Synchronizes attachment database connections with the primary database mode.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

When chat.db is readable at its default path, for example through a
permission left over from an earlier grant on chat.db alone,
openDatabase used that path without the folder grant's security
scope, so reading an attachment failed with "Operation not
permitted". Use a folder grant first when one is stored. The
Messages toggle now also offers the folder when chat.db is readable
but the Attachments folder is not.
@mattt mattt changed the title Open the attachments connection the way Madrid opened chat.db Read Messages attachments through the folder grant Sep 25, 2026
@mattt
mattt requested a lite review from Copilot September 25, 2026 19:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Attachment-folder access can still bypass the required security-scope grant.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)

Comment thread App/Services/Messages.swift Outdated
// for example through a permission left over from an earlier grant on chat.db alone.
// The toggle then offers the folder; tool calls keep working with what is readable.
let canReadDefaultPath = canAccessDatabaseAtDefaultPath
if canReadDefaultPath, !offeringUpgrade || canAccessAttachmentsAtDefaultPath {
The menu toggle only runs activate() for a service that reports itself
as not activated. Messages reported activated whenever chat.db was
readable at its default path, so the toggle never offered the folder
when the Attachments folder was unreadable.
@mattt mattt changed the title Read Messages attachments through the folder grant Open the attachments connection the way Madrid opened chat.db Sep 26, 2026
@mattt
mattt requested a lite review from Copilot September 26, 2026 02:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved issues were identified, and all reviewed changes are aligned with the intended fix.

Review effort: Lite
Findings: 1 Medium severity

Open (1)

@mattt
mattt merged commit bceadf9 into main Sep 26, 2026
2 checks passed
@mattt
mattt deleted the mattt/attachments-follow-access-mode branch September 26, 2026 03:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants