train: land 4088 4090 4095 - #4099
Conversation
…ce (#4088) Codex credential reads retry with a bounded reread when auth.json is missing, partial, incomplete, or expiring while the Codex CLI publishes fresh credentials mid-fetch, and a fresh plan change invalidates the old quota/reset evidence so usage from the new plan replaces the previous one. Fixes #3389; refs #3635 #3523. Thanks @theDanielJLewis and @coygeek!
Adaptive agent-aware refresh now recognizes the Codex app-server nested inside the ChatGPT app (both documented executable paths under /Applications/ChatGPT.app), after checking the running PID's kernel-reported path, OpenAI code signature, and symlink redirects on every scan; the outer bundle's Gatekeeper assessment is cached by bundle, Info.plist, executable, and CodeResources identity and retried on failure. Recent rollout activity stays authoritative. Fixes #4069. Thanks @jaychou0642-create!
Widget snapshots now retain each provider's last eligible reading with its original measurement time instead of an all-or-nothing guard, so a disabled, invalidated, or failing provider no longer blanks the others; an invalidated account stays retired until replacement usage is published. Refs #3500 #3627 #3339 #2838. Thanks @jaxleezhang!
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f317133e90
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| func isAvailable(_ context: ProviderFetchContext) async -> Bool { | ||
| (try? CodexOAuthCredentialsStore.loadForUsage( | ||
| env: context.env, | ||
| allowExternalSources: context.settings?.codex?.allowExternalOAuthSources == true)) != nil | ||
| await (try? Self.loadCredentials(context, retryStale: false)) != nil | ||
| } |
There was a problem hiding this comment.
Retry credential publication races during availability checks
When auth.json is briefly missing or partially written, the fetch pipeline calls isAvailable before it ever calls fetch. This passes retryStale: false, so the first read failure returns false and skips the OAuth strategy entirely; the retry-enabled load in fetch is never reached (leaving explicit OAuth with no available strategy and auto mode to fall back). This also makes the newly added availability-race test fail, since it expects the second read to observe the completed credential file.
Useful? React with 👍 / 👎.
|
Codex review: needs maintainer review before merge. Reviewed September 28, 2026, 5:35 AM ET / 09:35 UTC. ClawSweeper reviewWhat this changesCombines three commits that retry Codex credential reads and reset plan baselines, recognize ChatGPT’s nested Codex app-server for adaptive refresh, and retain eligible widget readings per provider. Merge readiness✅ Ready for maintainer review Keep open: current main lacks the addressed behavior, and this owner-authored PR is not eligible for cleanup closure. The existing availability-race review comment misreads the retry helper; read and decode failures still receive bounded retries. Priority: P2 Review scores
Verification
How this fits togetherCodexBar reads Codex credentials and local agent activity to produce usage readings and choose refresh timing. Its app store writes provider snapshots that widgets display. flowchart LR
A[Codex credentials] --> B[Usage fetch]
C[Running agent processes] --> D[Trusted session scan]
D --> E[Refresh timing]
E --> B
B --> F[Provider readings]
F --> G[Widget snapshot]
G --> H[Widget display]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep the existing fetch pipeline, consented session scanner, and widget snapshot writer as the ownership points, while preserving credential and account isolation. Do we have a high-confidence way to reproduce the issue? Yes: isolated credential-reader, nested-process, and widget-refresh fixtures give concrete paths through the reported failures. This read-only review did not execute them. Is this the best way to solve the issue? Yes: the changes use the existing fetch, scanner, and snapshot owners, with bounded credential retries and provider-specific widget retention. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against 03f4b6888193. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Merge train: one CI run for 3 green lane PRs, each kept as its own commit (rebase merge).