Skip to content

Port upstream 0.60.4: keep Chrome DeepSeek balance through same-session transport failures (stacked on #646) - #709

Draft
Finesssee wants to merge 1 commit into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.60.4-deepseek-chrome-balance
Draft

Finesssee wants to merge 1 commit into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.60.4-deepseek-chrome-balance

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Ports the behavior of upstream CodexBar 0.60.4 "keep Chrome DeepSeek balances visible through temporary connection failures for the same browser session, preserving the original measurement time".

When no DeepSeek API key is configured, Auto mode now reads the Platform balance through a signed-in Chrome session (token read with the LevelDB reader from #646). If a later refresh fails with a transport failure (timeout or connection refused), the cached balance stays visible with its original updated_at, but only when the failed request used the same Chrome profile and the same token that produced the cached balance. A rejected session, a different profile or token, a resolution deadline, or a balance with no session owner (for example an API-key balance) is never retained; the error is shown instead.

Found by the 0.60.4-0.69.0 port gap audit.

Upstream reference

  • steipete/CodexBar PR fix(deepseek): retain balances only for matching live sessions steipete/CodexBar#3680 "fix(deepseek): retain balances only for matching live sessions" (tag v0.60.4, head 82bfae5). Read-only, pinned to the tag.
  • Upstream ownership is a profile id plus a namespaced SHA-256 digest of the trimmed token, held in memory only. This port mirrors that: LastGoodOwner (rust/src/core/last_good_owner.rs), never serialized, Debug redacted.
  • Platform endpoint and auth-failure codes match upstream: GET https://platform.deepseek.com/api/v0/users/get_user_summary (Bearer, x-client-platform: web), 401/403 or envelope code/biz_code 40002/40003 mean the session is rejected.

Ported / Deferred

Ported:

  • Owner-checked retention: ProviderError::OwnedTransport wraps only transport failures; the shell (commands/providers.rs) records the owner of each fresh snapshot in AppState.last_good_owners and keeps the cached snapshot only when the failure's owner matches.
  • Fail-closed cases: resolution deadline (owner none), rejected session, unowned cached balance, unattributed transport failure for DeepSeek.
  • Platform balance parsing (wallets summed per currency; funded USD, then any funded, then USD, then first).
  • Chrome session import per profile (chrome:<dir> ids), 30-minute validation cache holding digests only, selected-profile balance always fetched live.
  • Other providers keep their existing last-good policy.

Deferred (not in this PR):

  • Profile picker UI. Until then, with several signed-in Chrome profiles the profile is chosen with env CODEXBAR_DEEPSEEK_PROFILE_ID (for example chrome:Profile 1); without it the user is told to set it.
  • DEEPSEEK_PLATFORM_TOKEN and other manual-token env support.
  • Detailed usage and cost rows for the Chrome lane (balance only here).
  • Background catalog validation of all profiles.
  • API-key balance with browser enrichment (upstream never lets it establish ownership; this port does not attempt it).
  • Chrome Local State profile display names (labels use the directory name).
  • Cancellation and stale-generation guards beyond what the shell refresh engine already does.

Validation

All with toolchain 1.98.0, slot-3 target dir, --test-threads=4.

  • cargo fmt --all: clean.
  • cargo clippy --workspace --all-targets -- -D warnings: pass.
  • cargo test -p codexbar deepseek: 42 passed, 0 failed.
  • cargo test -p codexbar (full): 2223 passed, 0 failed, 1 ignored.
  • cargo test -p codexbar-desktop-tauri last_good: 9 passed.
  • cargo test -p codexbar-desktop-tauri (full): 468 passed, 1 failed. The failure is the known bootstrap_payload_exposes_every_provider_variant (fixed by Isolate bootstrap payload test from real settings #684), unrelated.
  • No frontend files touched, so no vitest/lint/build run.

Affected areas

  • rust/src/core/ (owner type, ProviderError variant, ProviderFetchResult.last_good_owner)
  • rust/src/providers/deepseek/ (Chrome session lane, platform balance, resolver)
  • rust/src/cli/ (exhaustive ProviderError matches)
  • apps/desktop-tauri/src-tauri/src/ (state.rs, commands/providers.rs retention path)

No new dependencies (sha2 and futures already in rust/Cargo.toml). No secrets logged; only profile ids go to tracing::debug.

Stacked on #646 (base port/micro-0.66.0-browser-leveldb-reader).

UI proof

Pending: coordinator will capture CUA proof on a fresh build.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant