Skip to content

Port upstream 0.66.0: MiniMax browser storage discovery (stacked on #646) - #651

Open
Finesssee wants to merge 2 commits into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.66.0-minimax-storage-discovery
Open

Finesssee wants to merge 2 commits into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.66.0-minimax-storage-discovery

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #646 (shared Chromium LevelDB reader). Adds browser::storage_discovery, a shared, read-only locator for raw Chromium profile stores, and switches the MiniMax browser-storage importer to it.

  • storage_discovery::discover(StorageKind) walks every installed Chromium-family browser in the BrowserType catalog and returns candidate directories: Local Storage/leveldb, Session Storage, or IndexedDB/<origin>.indexeddb.leveldb filtered by origin prefixes. Profiles are Default, Profile *, and user-* (sorted; hidden entries, files, and guest/system profiles ignored). Nothing is opened, locked, or decrypted.
  • MiniMaxLocalStorageImporter::import_session previously looked only at the Default profile of Chrome, Edge, and Brave Local Storage (per-OS hard-coded paths). It now visits every catalog browser and profile, trying Local Storage first, then Session Storage, then MiniMax-origin IndexedDB only when earlier stores yield no session. source_label is now the candidate label (for example Google Chrome Profile 2 (Session Storage)).
  • MiniMax IndexedDB origin prefixes match upstream: https_platform.minimax.io_, https_www.minimax.io_, https_minimax.io_, https_platform.minimaxi.com_, https_minimaxi.com_, https_www.minimaxi.com_.

No user-visible change yet: MiniMaxLocalStorageImporter is still not called by the MiniMax fetch path (it uses API key or cookie header only), as noted in the 0.66.0 audit.

Upstream reference

  • Release bullet: "MiniMax: discover browser session storage across the shared Chromium catalog, including Comet and Yandex (fix(devin): share Chromium browser session discovery steipete/CodexBar#3883)", v0.66.0, commit 62cdd065.
  • Tag-pinned files: Sources/CodexBarCore/ChromiumLocalStorageDiscovery.swift (Storage enum, profileCandidates), Sources/CodexBarCore/Providers/MiniMax/MiniMaxLocalStorageImporter.swift (indexedDBStorage, storageCandidates, local, session, then IndexedDB order), Tests/CodexBarTests/MiniMaxLocalStorageImporterTests.swift (allowed and excluded IndexedDB fixture names, profile-name filter), docs/minimax.md.

Ported / Deferred

Ported: the three-storage discovery, profile filter, IndexedDB origin-prefix filter, and MiniMax fallback order.

Deferred:

  • Comet and Yandex: not in BrowserType, and upstream evidence gives macOS roots only, so their Windows User Data paths would be invented. Other upstream catalog members (Chrome Beta/Canary, Edge Beta/Canary, Brave Beta/Nightly, Vivaldi, Dia, Atlas, Helium) are likewise outside BrowserType; extending it belongs with the Chrome-channel work (feat(browser): support Chrome channels and Chromium profiles #614). Adding a browser there makes it visible to this discovery with no change here.
  • The MiniMax importer still string-scans .ldb/.log files rather than using the Port upstream 0.66.0: shared Chromium LevelDB + Snappy reader #646 LevelDB reader (Snappy-compressed tables are invisible to a raw scan). Switching the parse to the reader, and wiring the importer into the fetch path, are separate behavior changes.
  • Live-profile smoke check: not run (no real-browser data access in this task); coverage is fixture-based on temp directories.

Validation

Toolchain cargo +1.98.0, slot-4 target dir, E-core wrappers.

  • cargo +1.98.0 fmt --all: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar storage -- --test-threads=4: 14 passed, 0 failed (includes the 4 new discovery tests and 3 new importer tests)
  • cargo +1.98.0 test -p codexbar -- minimax browser:: --test-threads=4: 84 passed, 0 failed

New tests: per-kind path and label resolution, missing stores and missing user-data dir, profile-name filter and ordering (Default, Profile 2, user-work kept; Guest Profile, System Profile, Profile1, hidden, and file entries dropped), IndexedDB allow/exclude list from the upstream fixture (18 candidates across 3 profiles), and importer order (local beats session, session and IndexedDB fallback, no-browser vs no-session errors). Full cargo test -p codexbar not run (no shared core code touched).

Affected areas

  • Rust backend (rust/src/browser/, rust/src/providers/minimax/local_storage.rs)
  • Tauri shell
  • Frontend
  • Settings / bridge types
  • No new dependencies. No file over 1000 lines.

UI proof

Not applicable

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 4d7cbf6a-ef50-4b53-9fa6-cdeb1de4bbf8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

Thermo-nuclear review findings:

  • High: minimax/local_storage.rs scanned raw .ldb/.log files (missed Snappy-compressed tables, unbounded reads). Fixed: uses the existing LevelDB reader and origin-aware Local Storage decoder.
  • Medium: storage_discovery.rs kept its own profile filter beside the browser detector (drift risk). Fixed: uses canonical detected profiles; detection.rs handles ordering and user-* profiles.
  • Medium: minimax/local_storage.rs discarded read/parse errors and reported "storage not found". Fixed: keeps the last meaningful error while continuing.
  • Medium: JSON extraction treated braces inside quoted strings as boundaries. Fixed: scanner tracks strings and escapes.
  • Medium: importer has no caller in the MiniMax fetch path, so no runtime effect yet. Not fixed: the PR leaves wiring out and nothing establishes how a local storage token maps to the cookie-authenticated endpoints; guessing would change auth behavior without evidence.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at head f37043a: 4 of 5 findings fixed (wiring finding left, see above). Also fixed clippy cast lints in the new tests. Commands run: cargo +1.98.0 fmt --all, clippy -D warnings (rust crate, all targets), cargo test --lib browser (52 passed) and minimax (41 passed). Tauri crate clippy skipped: no changes outside the rust crate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant