Skip to content

train: land 4081 4082 4087 4089 4084 4086 4092 4091 4093 - #4096

Merged
steipete merged 9 commits into
mainfrom
train/0928-0732
Sep 28, 2026
Merged

steipete merged 9 commits into
mainfrom
train/0928-0732

Conversation

A zero-byte or whitespace-only config file now behaves like a missing one (defaults, usage keeps working, next save writes valid JSON with 0600 permissions) instead of failing closed and blanking usage; malformed non-empty JSON keeps its decode error and protected writes. Fixes #4071.

Thanks @kvnloo!
Status-item position preservation now validates the saved position before and after hide/remove/visibility mutations: an invalid value written during the operation is not kept, a valid replacement is retained, and an already-corrupt snapshot is never restored (bound: widest attached display + 512 pt). Split-provider visibility uses the same helper. Refs #3355.
Codex cost catch-up now publishes each validated snapshot after every bounded pass instead of only the first, so a completed discovery replaces an older partial total before the next sleep (completeness, account/settings scope, cancellation, and freshness checks unchanged). Refs #3508.

Thanks @kernnel!
Keychain signature validation runs on bounded utility workers with a two-second wait per caller, so a stalled native validation no longer blocks background quota refresh after app updates (late successes cannot authorize reads). Claude OAuth rechecks fresh, profile-scoped memory after stale-cache cleanup and persists it with its original owner binding. Fixes #3249; refs #3395 #3798.

Thanks @lozcalver and @SilentKnight87!
…4084)

Antigravity: repair grouped model-family quotas on the OAuth path to match the agy CLI grouping, and parse weekly-only Starter (free-tier) quota fixtures with explicit cadence through the shared parser. Refs #2427 #3789.
Kimi CLI refresh tokens rotate and belong to the CLI, so CodexBar keeps CLI authentication read-only; when the CLI access token expires after the CLI quits, the error now says to run kimi or add a Kimi Code API key for unattended use, and configured web/API sources still take over. Fixes #4063.

Thanks @kid0114!
Claude/Vertex cost caches keep the decoded value of each successful save under its committed file stamp, skip re-encoding unmodified values, and use compact row keys (a 24k-row history artifact shrinks from 9.3 MB to 6.9 MB). Schema 3 -> 4 rebuilds once from existing transcripts; Unicode text is preserved exactly. Refs #3882 #3247.

Thanks @djbclark for the CPU sample that pinned this down!
Kimi: when the monthly membership is known to be exhausted, shorter windows show as blocked by the monthly limit instead of fresh capacity. z.ai: unsupported quota shapes explain that usage is unavailable instead of inventing numbers, while recognized limits stay visible. Refs #3536 #2522; closes #2871 (five-hour cadence already derived from API fields, now covered by the reported payload).
…4093)

Grok local token history now reaches Usage & Spend and share output when x.ai billing is unavailable: wider dashboard requests keep the scan's actual 30-day coverage instead of an unknown horizon that the dashboard rejected, fresh local history publishes before retained-quota early returns, and the scanner clips files to its advertised calendar days so aggregates match daily buckets. Fixes #3716.

Thanks @Chipagosfinest!
@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P1 Urgent regression or broken agent/channel workflow affecting real users now. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 28, 2026
@clawsweeper

clawsweeper Bot commented Sep 28, 2026

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 28, 2026, 3:40 AM ET / 07:40 UTC.

ClawSweeper review

What this changes

Combines nine fixes for configuration, menu placement, provider quotas, credential recovery, and usage history into separate commits with tests and documentation.

Merge readiness

⛔ Blocked before merge - 1 item remains

Keep open. Current main lacks the nine fixes carried by this owner-authored merge train. The reviewed source and regression coverage establish no concrete introduced blocker.

Priority: P1
Reviewed head: 58f3f0a899ade89c59f3a26f1f143e265b6c6a9c

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) Focused regression coverage, an upgrade fixture, and linked before/after evidence support a broad but reviewable train.
Proof confidence 🐚 platinum hermit (4/6) Not applicable: The owner-authored train is exempt from the external contributor proof gate. Linked PR evidence covers isolated CLI config behavior, native Kimi rendering, and a version-3 cache rebuild; Antigravity OAuth was exercised with a synthetic transport, and no separate integrated live run is claimed. The cache upgrade fixture supports existing-state compatibility.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The owner-authored train is exempt from the external contributor proof gate. Linked PR evidence covers isolated CLI config behavior, native Kimi rendering, and a version-3 cache rebuild; Antigravity OAuth was exercised with a synthetic transport, and no separate integrated live run is claimed. The cache upgrade fixture supports existing-state compatibility.
Evidence reviewed 7 items Introduced train: The pinned main-to-head diff contains nine commits and changes 67 files; the config loader, Grok publication, and Claude cache changes are absent from the pinned main.
Credential boundary: Timed-out signature validation returns an inconclusive result; the Claude recovery path checks profile-scoped, unexpired memory before persisting it with its recorded owner.
OAuth fallback: Antigravity tries measured grouped quotas with a two-second timeout and retains model-quota fallback, selected-account identity, cancellation, and authentication failure handling.
Findings None None.
Security None None.

How this fits together

CodexBar reads configuration, credentials, provider responses, and local session files to build usage snapshots. Those snapshots feed the menu bar, widget, CLI, and Usage & Spend views.

flowchart LR
 A[Config and credentials] --> B[Provider probes]
 C[Local session files] --> D[Cost scanner]
 B --> E[Usage snapshots]
 D --> E
 E --> F[Menu, widget, CLI, and dashboard]
Loading

Before merge

  • Resolve review confidence - ClawSweeper must reach high confidence before merge readiness is known.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Train scope 9 commits, 67 files The branch combines separately attributable fixes across several provider and app paths.
Production and test delta production +368/−394; tests +1602/−196 The fixes reduce net production lines while adding focused regression coverage.

Technical review

Best possible solution:

Land the separately attributable fixes through the train after its ordinary exact-head checks, preserving the tested cache upgrade and credential guards.

Do we have a high-confidence way to reproduce the issue?

Not applicable as one issue: this train combines nine fixes with focused reproduction or regression evidence in their linked PRs. This read-only review did not execute those paths.

Is this the best way to solve the issue?

Yes. The train retains separate commits and uses existing snapshot, parser, and cache boundaries; no narrower repair is indicated by the reviewed diff.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against a5252e24c844.

Labels

Label changes:

  • add P1: One included fix addresses native validation stalls that can block background provider refresh.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The owner-authored train is exempt from the external contributor proof gate. Linked PR evidence covers isolated CLI config behavior, native Kimi rendering, and a version-3 cache rebuild; Antigravity OAuth was exercised with a synthetic transport, and no separate integrated live run is claimed. The cache upgrade fixture supports existing-state compatibility.

Label justifications:

  • P1: One included fix addresses native validation stalls that can block background provider refresh.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The owner-authored train is exempt from the external contributor proof gate. Linked PR evidence covers isolated CLI config behavior, native Kimi rendering, and a version-3 cache rebuild; Antigravity OAuth was exercised with a synthetic transport, and no separate integrated live run is claimed. The cache upgrade fixture supports existing-state compatibility.

Evidence

What I checked:

Likely related people:

  • Peter Steinberger: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Daniel JB Clark: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Lam,Yiu Fung: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P1 Urgent regression or broken agent/channel workflow affecting real users now. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant