Skip to content

Port upstream 0.69.0: reset Codex weekly baseline on plan change (stacked on #629) - #690

Open
Finesssee wants to merge 5 commits into
port/micro-0.65.0-codex-weekly-reset-rollingfrom
port/micro-0.69.0-codex-plan-change-baseline
Open

Finesssee wants to merge 5 commits into
port/micro-0.65.0-codex-weekly-reset-rollingfrom
port/micro-0.69.0-codex-plan-change-baseline

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

A Codex subscription change (for example Plus to Pro) now starts a new weekly-quota baseline instead of being judged against the previous plan's published weekly window.

  • initial_decision: when the source is exact OAuth, the observation is newer than the stored one, and both the stored and fresh plans are known and differ (trimmed, case-insensitive), the account state is reset (published weekly, pending candidate, credit inventory). preserve_weekly therefore no longer pins the previous plan's weekly window.
  • confirmation_decision: a near-zero weekly confirmation now requires the initial and confirmation plans to match (normalized; unknown vs known counts as different). A nonzero confirmation can still publish its own plan.
  • codex_reset_backfill (backfill_slot_window): skipped for Codex when both cached and fresh plan_name are known and differ, so the old plan's reset times are not copied onto the new plan.
  • Unknown or blank plans never reset the baseline.

Stacked on #629 (weekly_reset.rs and its tests).

Upstream reference

Ported / Deferred

  • Ported: the plan-change half of fix(codex): retry auth reads and reset quota baselines on plan changes steipete/CodexBar#4088 (item 6b): weekly-reset baseline, confirmation plan equality, and backfill guard.
  • Deferred to the separate PR port/micro-0.69.0-codex-auth-publication-retry: credential-file publication retry (item 6a).
  • Not applicable locally: upstream's UsageStore+TokenAccounts multi-snapshot backfill filter (no equivalent path in the Windows shell; the single cached-snapshot backfill guard covers it).
  • Windows difference: the reset baseline is the persisted per-account weekly-reset state (AccountState), so the whole state is reset rather than separate in-memory snapshots.

Validation

Cargo run with +1.98.0, target slot-4, E-core pinned.

  • cargo +1.98.0 fmt --all: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar weekly_reset -- --test-threads=4: 21 passed, 0 failed (7 new)
  • cargo +1.98.0 test -p codexbar providers::codex -- --test-threads=4: 61 passed, 0 failed
  • cargo +1.98.0 test -p codexbar-desktop-tauri backfill -- --test-threads=4: 8 passed, 0 failed (2 new)

New fixtures: Plus to Pro upgrade with an 80%-used published weekly (baseline reset, confirmation publishes); same-plan near-zero refresh (baseline kept); unknown/blank/stale/non-OAuth (baseline kept); pending candidate discarded on plan change; near-zero confirmation with a changed or unknown plan preserved; nonzero confirmation publishes its own plan; backfill skipped only when both plans known and differ.

Affected areas

  • Rust backend (rust/src/providers/codex)
  • Tauri shell (commands/providers.rs, values only)
  • Frontend, tray, settings, float bar (none)

Note: commands/providers.rs was already over 1000 lines (1429); this adds about 52 lines including tests.

UI proof

Not applicable (values only; no UI surface changed).

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d4dde836-fb34-41fd-b20a-b8060c200e17

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

Thermo-nuclear review of PR #690 (Codex weekly baseline reset on plan change): 1 finding.

  • Medium rust/src/providers/codex/weekly_reset.rs (commit_publication): publishing a snapshot with a missing or blank plan overwrote the stored plan with None, so a later Plus -> Pro change compared against an unknown plan and went undetected, leaving the old weekly window pinned. Unknown plans now keep the last known stored plan. Regression test unknown_plan_publication_preserves_the_last_known_plan covers None and blank plans followed by a plan change.

The rest of the diff (confirmation plan match, baseline reset on a known differing plan, backfill skip on differing known login methods, unknown plans never resetting) matches the spec. No UI change.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at current head 1864c84

The medium finding is fixed; nothing is left open.

Commands run: cargo +1.98.0 fmt --all --check, cargo +1.98.0 clippy --all-targets -- -D warnings on rust/ and apps/desktop-tauri/src-tauri, cargo +1.98.0 test --lib providers::codex (62 passed, including the new regression test).

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

Thermo-nuclear review of PR #690 (Codex plan-change baseline): 1 finding.

  • Medium apps/desktop-tauri/src-tauri/src/commands/providers.rs: the backfill policy and its tests grew an already 1,481-line refresh module. They now live in commands/providers/reset_backfill.rs (pure move, no behavior change); the refresh module delegates and drops to 1,229 lines.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Follow-up: the finding is fixed at the new head (pure move, no behavior change). Nothing left open.

Commands run: cargo +1.98.0 fmt --all --check, cargo +1.98.0 clippy --all-targets -- -D warnings on rust/ and apps/desktop-tauri/src-tauri, cargo +1.98.0 test reset_backfill on the Tauri crate (8 passed).

Move the plan-change weekly-reset tests into weekly_reset/tests/plan_change.rs
so tests.rs stays under 1000 lines after merging #629, and port the upstream
CodexPlanTransitionPublicationTests cases that were missing:

- a new plan without a weekly window cannot borrow the old plan's window;
- the new plan's own usage and reset become the stored baseline at 0 % and 5 %;
- same-plan (any case or spacing) or blank-plan near-zero readings keep the
  old evidence.
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Lane B review: fixes at 9ef221d

Reviewed the full diff against its base port/micro-0.65.0-codex-weekly-reset-rolling (#629) and against upstream steipete#4088 (in v0.69.0): CodexWeeklyResetConfirmation.swift, UsageStore+CodexResetBackfill.swift, UsageStore+CodexWeeklyResetConfirmation.swift and CodexPlanTransitionPublicationTests.

Base picked up (20eaf3a). I merged the reviewed #629 head (4a1674e) into this branch. The only conflict was weekly_reset/tests.rs, where both branches appended tests; I kept both sides. weekly_reset.rs now carries both #629's delayed_candidate_evaluation and this PR's plan-change baseline.

Logic: no defects found. The plan-change reset in initial_decision, the plan check in confirmation_decision, the sticky last-known plan in commit_publication, and the desktop reset-backfill guard (codex_plan_changed) match upstream.

These Windows differences are deliberate:

  • Last known plan is sticky. The stored plan is only overwritten by a known plan. Upstream compares against the previous snapshot, whose plan can be nil.
  • Diagnostic code. planChanged is a Windows-only log reason code, not a wire shape.
  • Plan reset with a failed or flipped confirmation. Windows shows the fresh unconfirmed reading, because the old baseline was reset. Upstream keeps the old snapshot.

Tests (9ef221d)

  • File split. Merging Port upstream 0.65.0: confirm unused rolling weekly Codex resets #629 pushed weekly_reset/tests.rs past the 1000-line limit, so the plan-change tests moved to weekly_reset/tests/plan_change.rs. tests.rs is now 785 lines.
  • Ported three CodexPlanTransitionPublicationTests cases that were missing:
    • new plan cannot borrow missing weekly usage from the old plan: a Pro reading without a weekly window publishes without the Plus window. The same plan still keeps it.
    • new token plan replaces previous plan quota baseline at 0 % and 5 %: the new plan's own usage and reset become the stored baseline, state.plan becomes the new plan, and no candidate survives.
    • same or unknown token plan cannot discard previous quota evidence for ChatGPT Plus, CHATGPT PLUS and a blank plan: a near-zero reading still needs confirmation, and the old 80 % stays shown.
  • Already covered by this PR's tests: near zero confirmation must retain the initial plan, fresh nonzero confirmation can publish its own plan, and older or incomplete new plan cannot discard previous quota evidence.

Not ported

  • Store-level subscription upgrade publishes new plan and quota without disabling Codex. On Windows it would have to run CodexApi::fetch_usage, which reads and writes the real %LOCALAPPDATA%\CodexBar\codex-weekly-reset-v1.json because there is no test override for that path. The pure decision tests above cover the same sequence.
  • The upstream docs/codex.md bullets. No Windows doc covers weekly-reset confirmation.

Validation (Windows, toolchain 1.98.0)

  • cargo fmt --all --check: pass
  • cargo clippy --workspace --all-targets -- -D warnings: pass
  • cargo test -p codexbar providers::codex::weekly_reset: 27 passed
  • cargo test -p codexbar: 2180 passed, 0 failed, 1 ignored. The run was after 01:00 local, so the known midnight flake on main passed.
  • cargo test -p codexbar-desktop-tauri: 463 passed, 1 failed. The failure is commands::tests::bootstrap_payload_exposes_every_provider_variant, which reads host settings where a deprecated provider is enabled. It fails the same way on main, and this PR does not touch it.

UI proof: not applicable. The change is backend decision logic plus a desktop cache guard with no visible surface of its own.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant