train: land 4081 4082 4087 4089 4084 4086 4092 4091 4093 - #4096
Conversation
A zero-byte or whitespace-only config file now behaves like a missing one (defaults, usage keeps working, next save writes valid JSON with 0600 permissions) instead of failing closed and blanking usage; malformed non-empty JSON keeps its decode error and protected writes. Fixes #4071. Thanks @kvnloo!
Status-item position preservation now validates the saved position before and after hide/remove/visibility mutations: an invalid value written during the operation is not kept, a valid replacement is retained, and an already-corrupt snapshot is never restored (bound: widest attached display + 512 pt). Split-provider visibility uses the same helper. Refs #3355.
Codex cost catch-up now publishes each validated snapshot after every bounded pass instead of only the first, so a completed discovery replaces an older partial total before the next sleep (completeness, account/settings scope, cancellation, and freshness checks unchanged). Refs #3508. Thanks @kernnel!
Keychain signature validation runs on bounded utility workers with a two-second wait per caller, so a stalled native validation no longer blocks background quota refresh after app updates (late successes cannot authorize reads). Claude OAuth rechecks fresh, profile-scoped memory after stale-cache cleanup and persists it with its original owner binding. Fixes #3249; refs #3395 #3798. Thanks @lozcalver and @SilentKnight87!
Kimi CLI refresh tokens rotate and belong to the CLI, so CodexBar keeps CLI authentication read-only; when the CLI access token expires after the CLI quits, the error now says to run kimi or add a Kimi Code API key for unattended use, and configured web/API sources still take over. Fixes #4063. Thanks @kid0114!
Claude/Vertex cost caches keep the decoded value of each successful save under its committed file stamp, skip re-encoding unmodified values, and use compact row keys (a 24k-row history artifact shrinks from 9.3 MB to 6.9 MB). Schema 3 -> 4 rebuilds once from existing transcripts; Unicode text is preserved exactly. Refs #3882 #3247. Thanks @djbclark for the CPU sample that pinned this down!
Kimi: when the monthly membership is known to be exhausted, shorter windows show as blocked by the monthly limit instead of fresh capacity. z.ai: unsupported quota shapes explain that usage is unavailable instead of inventing numbers, while recognized limits stay visible. Refs #3536 #2522; closes #2871 (five-hour cadence already derived from API fields, now covered by the reported payload).
…4093) Grok local token history now reaches Usage & Spend and share output when x.ai billing is unavailable: wider dashboard requests keep the scan's actual 30-day coverage instead of an unknown horizon that the dashboard rejected, fresh local history publishes before retained-quota early returns, and the scanner clips files to its advertised calendar days so aggregates match daily buckets. Fixes #3716. Thanks @Chipagosfinest!
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 28, 2026, 3:40 AM ET / 07:40 UTC. ClawSweeper reviewWhat this changesCombines nine fixes for configuration, menu placement, provider quotas, credential recovery, and usage history into separate commits with tests and documentation. Merge readiness⛔ Blocked before merge - 1 item remains Keep open. Current main lacks the nine fixes carried by this owner-authored merge train. The reviewed source and regression coverage establish no concrete introduced blocker. Priority: P1 Review scores
Verification
How this fits togetherCodexBar reads configuration, credentials, provider responses, and local session files to build usage snapshots. Those snapshots feed the menu bar, widget, CLI, and Usage & Spend views. flowchart LR
A[Config and credentials] --> B[Provider probes]
C[Local session files] --> D[Cost scanner]
B --> E[Usage snapshots]
D --> E
E --> F[Menu, widget, CLI, and dashboard]
Before merge
Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Land the separately attributable fixes through the train after its ordinary exact-head checks, preserving the tested cache upgrade and credential guards. Do we have a high-confidence way to reproduce the issue? Not applicable as one issue: this train combines nine fixes with focused reproduction or regression evidence in their linked PRs. This read-only review did not execute those paths. Is this the best way to solve the issue? Yes. The train retains separate commits and uses existing snapshot, parser, and cache boundaries; no narrower repair is indicated by the reviewed diff. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against a5252e24c844. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Merge train: one CI run for 9 green lane PRs, each kept as its own commit (rebase merge).