Skip to content

Glossary

SQLite WAL (write-ahead log)

SQLite write-ahead logging keeps recent changes in a -wal file until a checkpoint. For knowledgeC.db, the newest events often exist only there.

Write-ahead logging (WAL) is a SQLite journal mode. Instead of changing the main database file directly, SQLite appends changed pages as frames to a -wal file next to it, and a -shm file holds the shared-memory index that readers use to find them. Only frames of committed transactions count. A checkpoint later copies them back into the main file.

Both knowledgeC.db databases run in WAL mode, so the newest events often exist only in knowledgeC.db-wal. A copy of knowledgeC.db alone can suggest that activity stopped hours or days before collection. Comparing the database with and without its WAL shows rows that exist only in the WAL and rows the WAL removes.

Collect knowledgeC.db, knowledgeC.db-wal and knowledgeC.db-shm together, hash them, and open copies only: opening a WAL database in place can checkpoint it and change the evidence. The details are in recovering knowledgeC.db events from the WAL.