Describe the bug
The session_store_sql tool with source: "cloud" keeps returning sessions
after they have been deleted everywhere the user can reach:
SELECT COUNT(*) FROM sessions
→ 482, while GET /agents/tasks returns 0 tasks.
These rows are served by POST https://api.githubcopilot.com/agents/analytics/query
and written by chronicle reindex via PUT /agents/sessions/{id},
POST /agents/sessions/{id}/events, and PUT /agents/sessions/{id}/logs.
Every one of those write routes is an upsert or append. No route accepts
DELETE, and POST /agents/analytics/query rejects any non-SELECT
statement. Once a row exists in the sessions table behind
/agents/analytics/query, no client operation can remove it.
OPTIONS against every route the CLI uses for session data:
| Route |
Allow: |
/agents/analytics/query |
POST |
/agents/analytics |
GET, POST |
/agents/sessions |
GET, POST, PATCH |
/agents/sessions/{id} |
PUT, GET |
/agents/sessions/{id}/events |
GET, POST |
/agents/sessions/{id}/logs |
PUT, GET |
DELETE appears on none of them.
Affected version
Copilot CLI 1.0.87 (Linux x64)
Steps to reproduce the behavior
- Accumulate CLI sessions with
remoteExport enabled (the default).
- Delete the corresponding Mission Control tasks:
DELETE https://api.githubcopilot.com/agents/tasks/{id} (the call the CLI's
session picker makes), or via github.com/copilot/agent WebUI.
- Delete all local session state under
~/.copilot/session-state/.
- Set
remoteExport to false.
- Run
session_store_sql with source: "cloud":
SELECT COUNT(*) FROM sessions
Every previously-exported session is still returned. /chronicle and
cross-session search surface the same rows.
Expected behavior
Sessions deleted from github.com/copilot/tasks, from the CLI session picker,
and from ~/.copilot/session-state/ should stop being returned by
session_store_sql, /chronicle, and cross-session search.
Setting remoteExport: false should also provide some supported way to remove
data already exported — or the retention policy for that data should be
documented.
One of:
- A
DELETE route for rows in the sessions table — ideally bulk, e.g.
DELETE /agents/sessions/{id} plus a "delete all my cloud session history"
operation.
DELETE /agents/tasks/{id} cascading to the matching sessions row.
Additional context
Impact
- Deletion is not honored. Session metadata, titles, and summaries remain
queryable after deletion from every user-reachable surface.
remoteExport: false is not retroactive. It stops new writes but leaves
every prior row in place, with no documented retention period.
- No recourse exists through the CLI, the web UI, or the API.
Related issues
These look like the same gap — deletion never reaching the append-only
/agents/sessions/* → /agents/analytics/query pipeline:
| Issue |
Title |
Relationship |
| #3811 |
deleted sessions still in /chronicle insights |
Closest match — same symptom (local wipe + cloud delete + remoteExport off, yet /chronicle still surfaces deleted sessions); does not identify the route-level cause |
| #4094 |
Deleting a session doesn't remove it from session-store.db / VS Code Chat history |
Self-describes as the same root cause as #3811 |
| #4939 |
Unable to delete old remote sessions |
Same family; notes deletion worked in v1.0.55 |
| #3777 |
/chronicle reindex queues remote backfill despite local-only remote settings |
Shows remoteExport: false is not fully honored by the sync pipeline |
Adding a DELETE route would likely resolve #3811 and #4094 as well.
Describe the bug
The
session_store_sqltool withsource: "cloud"keeps returning sessionsafter they have been deleted everywhere the user can reach:
→ 482, while
GET /agents/tasksreturns 0 tasks.These rows are served by
POST https://api.githubcopilot.com/agents/analytics/queryand written by
chronicle reindexviaPUT /agents/sessions/{id},POST /agents/sessions/{id}/events, andPUT /agents/sessions/{id}/logs.Every one of those write routes is an upsert or append. No route accepts
DELETE, andPOST /agents/analytics/queryrejects any non-SELECTstatement. Once a row exists in the
sessionstable behind/agents/analytics/query, no client operation can remove it.OPTIONSagainst every route the CLI uses for session data:Allow:/agents/analytics/queryPOST/agents/analyticsGET, POST/agents/sessionsGET, POST, PATCH/agents/sessions/{id}PUT, GET/agents/sessions/{id}/eventsGET, POST/agents/sessions/{id}/logsPUT, GETDELETEappears on none of them.Affected version
Copilot CLI 1.0.87 (Linux x64)
Steps to reproduce the behavior
remoteExportenabled (the default).DELETE https://api.githubcopilot.com/agents/tasks/{id}(the call the CLI'ssession picker makes), or via github.com/copilot/agent WebUI.
~/.copilot/session-state/.remoteExporttofalse.session_store_sqlwithsource: "cloud":Every previously-exported session is still returned.
/chronicleandcross-session search surface the same rows.
Expected behavior
Sessions deleted from github.com/copilot/tasks, from the CLI session picker,
and from
~/.copilot/session-state/should stop being returned bysession_store_sql,/chronicle, and cross-session search.Setting
remoteExport: falseshould also provide some supported way to removedata already exported — or the retention policy for that data should be
documented.
One of:
DELETEroute for rows in thesessionstable — ideally bulk, e.g.DELETE /agents/sessions/{id}plus a "delete all my cloud session history"operation.
DELETE /agents/tasks/{id}cascading to the matchingsessionsrow.Additional context
Impact
queryable after deletion from every user-reachable surface.
remoteExport: falseis not retroactive. It stops new writes but leavesevery prior row in place, with no documented retention period.
Related issues
These look like the same gap — deletion never reaching the append-only
/agents/sessions/*→/agents/analytics/querypipeline:remoteExportoff, yet/chroniclestill surfaces deleted sessions); does not identify the route-level causeremoteExport: falseis not fully honored by the sync pipelineAdding a
DELETEroute would likely resolve #3811 and #4094 as well.