Skip to content

Port upstream 0.57.0: re-land stranded Codex scanner, OpenCodex numeric and reserve pricing (#488-#490) - #714

Open
Finesssee wants to merge 5 commits into
mainfrom
port/micro-0.57.0-reland-codex-opencodex
Open

Finesssee wants to merge 5 commits into
mainfrom
port/micro-0.57.0-reland-codex-opencodex

Conversation

@Finesssee

@Finesssee Finesssee commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Re-lands three upstream v0.57.0 ports that were merged on 2026-09-13 only into stacked port branches and never reached main (#488 into port/upstream-0.57.0; #489 and #490 into the #488/#489 head branches). git cherry against main @ 7695471b still reported all four patches as missing.

The original commits are cherry-picked with -x. One extra commit adapts the re-landed scanner tests to main's (CodexUsageRecord, i64) record tuples. There are no other changes.

Upstream reference

Ported / Deferred

Validation

The original PRs could not run tests (linker environment at the time). They now pass on this branch, run in the worker worktree on Rust 1.98.0:

Command Result
cargo +1.98.0 fmt --all --check pass
cargo +1.98.0 clippy --workspace --all-targets -- -D warnings pass. The first run failed on the re-landed tests (records[i].field against main's tuples); fixed in 195063e8
cargo +1.98.0 test -p codexbar 2164 passed, 0 failed, 1 ignored
cargo +1.98.0 test -p codexbar-desktop-tauri -- --skip bootstrap_payload_exposes_every_provider_variant 459 passed, 0 failed

The skipped desktop test is the non-hermetic #684 test, which reads the real %APPDATA%\CodexBar\settings.json on main. It is fixed separately by #711 and fails on main without this change too.

Affected areas

  • rust/src/core/jsonl_scanner/codex/helpers.rs, codex/parser.rs, jsonl_scanner/tests.rs
  • rust/src/spend_contract/opencodex.rs, spend_contract/opencodex/cache.rs
  • rust/src/core/cost_pricing.rs, cost_pricing_tests.rs

Integration note: #682 (port/micro-0.68.0-nous-opencodex-ledger) also edits opencodex/cache.rs (it bumps CACHE_SCHEMA_VERSION to 3). The two changes touch different lines.

UI proof

Not applicable. This is backend parsing and pricing only, with no UI surface changes.

Summary by CodeRabbit

  • Bug Fixes
    • Reserve model aliases now use the same pricing as GPT-5.6 Luna, including when the provider prefix or model name uses different capitalization.
    • Usage records are recognized across compact and whitespace-formatted logs, including records whose model name matches an event marker.
    • Log updates are reparsed when cached parsing information is missing or outdated, helping keep reported usage current.
    • Corrected handling of numeric values at the maximum integer boundary.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 2b1d33d8-5f45-4565-87b6-01fc6187b0db

📥 Commits

Reviewing files that changed from the base of the PR and between 7695471 and 195063e.

📒 Files selected for processing (8)
  • rust/src/core/cost_pricing.rs
  • rust/src/core/cost_pricing_tests.rs
  • rust/src/core/jsonl_scanner/codex.rs
  • rust/src/core/jsonl_scanner/codex/helpers.rs
  • rust/src/core/jsonl_scanner/codex/parser.rs
  • rust/src/core/jsonl_scanner/tests.rs
  • rust/src/spend_contract/opencodex.rs
  • rust/src/spend_contract/opencodex/cache.rs

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The changes update Codex model normalization and JSONL parsing. They also adjust OpenCodex numeric conversion and add parser-version checks to parse-cache cursors.

Changes

Codex model pricing

Layer / File(s) Summary
Normalize model aliases
rust/src/core/cost_pricing.rs, rust/src/core/cost_pricing_tests.rs
Normalization strips openai/ without case sensitivity and maps gpt-reserve to gpt-5.6-luna. Tests cover alias variants and compare their prices with gpt-5.6-luna.

Codex JSONL scanning

Layer / File(s) Summary
Detect and parse candidate records
rust/src/core/jsonl_scanner/codex/helpers.rs, rust/src/core/jsonl_scanner/codex/parser.rs, rust/src/core/jsonl_scanner/codex.rs, rust/src/core/jsonl_scanner/tests.rs
Candidate detection recognizes lines containing turn_context, including whitespace-formatted records. Bare-usage parsing can proceed when a line also matches an event marker. Tests cover compact and whitespace-formatted records, unrelated record rejection, and a usage row whose model is turn_context.

OpenCodex numeric conversion

Layer / File(s) Summary
Check the float conversion boundary
rust/src/spend_contract/opencodex.rs
Float conversion rejects the u64::MAX as f64 boundary. Tests verify that integer u64::MAX is accepted and its floating-point representation is rejected.

OpenCodex parse-cache versioning

Layer / File(s) Summary
Version parse cursors
rust/src/spend_contract/opencodex/cache.rs
Cursors include an optional parser version. Cache writes record the current version, and cursor reuse requires a match. Tests cover version serialization, mismatches, and reparsing legacy cursors.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 19506

The parsing, pricing-alias, numeric-boundary, and cache-version changes have no established merge-blocking issue. Mergeable subject to normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 19506

The changes tighten usage validation and require older cached results to be recalculated. No new security issue was identified in the reviewed paths, but broader exposure and failure scenarios were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated changed outcomes are usage records, pricing attribution and local cache reuse. Exploiting those inputs requires influence over supplied log content, model strings or cache state; effective filesystem permissions and broader downstream consumers were not independently established. No new credential, authorization or service-scope transition was identified in the changed functions.

Trust Boundaries and Controls

  • observed — The new parser-version condition supplements, rather than replaces, source identity and prefix verification. Parsed results are checked against the source snapshot before cache publication. These controls protect cache consistency; the evidence does not establish authenticity against an actor able to modify both source and cache.

Resilience and Maintainability Implications

  • observed — Existing scanner recovery retains source-offset ownership and validates cached prefixes before suffix parsing. Supporting tests compare appended parsing with a full parse and cover malformed lines and incomplete tails. The widened candidate gates do not introduce a new record-ownership mechanism.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 8 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically summarizes the three main changes: the Codex scanner, OpenCodex numeric safety, and reserve pricing ports.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant