Skip to content

chore: land triage train 2026-09-21 (#3806 #3807 #3816 #3818 #3814 #3817 #3812 #3811 #3815 #3813) - #3823

Merged
steipete merged 19 commits into
mainfrom
triage/20260921-train
Sep 21, 2026
Merged

steipete merged 19 commits into
mainfrom
triage/20260921-train

Conversation

@steipete

@steipete steipete commented Sep 21, 2026

Copy link
Copy Markdown
Owner

Integrates eleven reviewed triage lanes in one branch so the saturated macOS runner queue validates the combined result and CHANGELOG entries do not repeatedly conflict across separate squash merges. Nineteen substantive commits are cherry-picked in the requested order with original authors, bodies, contributor trailers, and -x provenance; each subject carries its lane PR number. Two changelog-only relocation commits are folded into the conflict resolutions.

Lanes and verdicts

Lane PR Verdict summary from its report
#3806 — small-prs-b LAND #3721 (redundant accent swatch), partial LAND #3745 (chevron rotation; no child transitions/clipping), LAND #3695 (five update/version surfaces; no sidebar badge).
#3807 — claude-credentials Partial LAND #3390 for expired credentials with an already-observed Keychain fingerprint; keep the broader issue open. #3395 and #3663 need owner decisions about prompt policy and browser-session refresh. #3471 is already merged.
#3816 — keychain-preflight Bounded LAND #3249 for rejected CodexBar cache ACL recovery. Keep #3798 open: experimental-reader hardening is included, but recurring prompts under Always allow remain unproven.
#3818 — codex-cost-forks Reproduced inherited-fork accounting defects are fixed and locally reviewed. Keep #3524 open pending a completed current-version corpus result. The lane's original integration holds were stale-baseline accounting and unverified hosted CI; this train starts from current main.
#3814 — devin-stepfun Partial LAND candidate #3781 for setup guidance/error classes. Keep #3660 open for unreproduced macOS session loss and failures before profile discovery; keep #3762 open because no StepFun login defect was established.
#3817 — shared-usage-card LAND the credited #3747 rewrite; #3714 is fixed for shared images/copied text across unpriced, incomplete-request, and missing-model siblings. Contributor-thread closure remains for the coordinator after landing.
#3812 — small-prs-a LAND #3750 for bounded switch reconciliation and #3772 for Muse diagnostics/windowless identity. #3624 is superseded by main's TRY support; this lane adds converter cleanup/coverage. Keep #3736 open for remaining scope.
#3811 — js-cutover-b LAND LLM Proxy and LiteLLM plugin conversions with native fetch twins removed. Keep NeuralWatt native: the plugin bridges cannot yet preserve selective transport retry/cancellation semantics.
#3815 — helmcode LAND #3422 as a bundled TypeScript provider after domain-scoped cookie sessions and policy-only cookie availability prerequisites; contributor credit retained.
#3813 — claude-warnings LAND the verified-owner and unresolved-account warning revision. Keep #3450 open for unverified-owner continuity, #3746 for paired source captures, and #3734 for missing-credential/transport evidence.
#3819 — widgets Retain eligible last-known usage at its original age when failed refreshes empty every provider entry, while respecting provider/account invalidation; thanks @jaxleezhang preserved.

Integration resolutions

Preserved main and lane changelog bullets verbatim in their intended top Unreleased sections, including thanks. Kept both Claude credential-documentation changes, combined exact architecture anchors with Helmcode's provider references, and recounted the conversion matrix while retaining the NeuralWatt blocker. docs/ui.md merged with all main and lane bullets intact. All three regeneration scripts produced no tracked changes. The widgets fold-in retains both sides' catalog entries and corrects ten exact refresh line anchors without weakening gatekeeper rules.

Existing lane UI proof

These captures were inspected and published by the lane owners; they document the adopted lane changes, not a new live-app run of the train.

Surface Before After
Provider accent picker (contributor proof) Accent before Accent after
Shared usage card (synthetic) Sharing before Sharing after
Helmcode premium eligibility (synthetic; before reconstructs proposal) Helmcode before Helmcode after

Verification

  • swift build --jobs 4: passed (117.24 seconds).
  • make check: passed; zero SwiftLint violations across 2,532 files after the widgets fold-in.
  • Combined serial focused run: 1,810 Swift Testing tests plus 13 XCTest tests passed; seven opt-in native/screenshot proofs skipped; zero failures. The architecture gatekeeper passed with the combined exact anchors.
  • Plugin engine A/B selection: QuickJS covered by the combined run; JavaScriptCore passed 91 tests in six suites. Same selection as Scripts/test-plugin-engines.sh, with four jobs and explicit serial execution.
  • Regenerated plugin JavaScript, Codex parser hash, and provider manifests: no tracked changes.
  • Integration autoreview through P1: scoped-clean, zero findings across both review passes. Per-lane review results and remaining issue scope are summarized above.
  • Commit/changelog audit: exact requested order, original author/date/body/trailers preserved, production per-commit change counts match source commits, all main and lane changelog bullets retained in their intended sections, historical releases unchanged.
  • Widgets fold-in: 119 tests in seven suites passed with Keychain access suppressed, covering ProviderArchitectureGatekeeperTests|WidgetEmptyProjectionTests|UsageStoreWidgetSnapshot|CodexBarWidgetProviderTests; independent blocker review returned no findings.
  • Full make test with Keychain access suppressed: all 119 groups passed on the first attempt (1,304 selected test selections), zero failures/retries/timeouts; 1,217.1 seconds total.
  • git diff --check: passed. No live-account probes.
Combined focused test command
env -u LIVE_TEST -u CODEXBAR_ALLOW_TEST_KEYCHAIN_ACCESS -u CODEXBAR_PLUGIN_ENGINE \
  CODEXBAR_SUPPRESS_TEST_KEYCHAIN_ACCESS=1 \
  CODEXBAR_TEST_CODEX_FILE_ISOLATION=1 CODEXBAR_TEST_SESSION_FILE_ISOLATION=1 \
  swift test --jobs 4 --no-parallel --filter 'ProviderArchitectureGatekeeperTests|ProviderPluginParityTests|MenuDescriptorUpdateAndVersionTests|ClaudeOAuth|KeychainCache|CodexSubagent|CostUsageStoreTests|Devin|ShareStats|ClaudeSwap|Muse|LiteLLM|LLMProxy|Helmcode|ProviderPluginCookieBroker|ClaudeCredentialQuotaWarningTests|PredictivePaceWarningTests|ProviderAccentColorTests|ProviderAccentRefreshRevisionTests|CostHistoryChartMenuViewTests|AboutUpdateCommandTests|SparkleUpdaterControllerTests|ClaudeCredentialOwnershipBoundaryTests|ClaudeKeychainOverrideIsolationTests|ClaudeCLIBackgroundAvailabilityTests|ClaudeWebCookieRenewalTests|ClaudeWebRecoveryMenuTests|KeychainAccess|KeychainNoUI|KeychainPromptSafetyAudit|ClaudeSecurityCLI|CodexCompactSubagent|CodexForkAppendResumeTests|CostUsageScanner|StepFun(UsageFetcherParsing|SettingsReader|ProviderTokenResolver|TokenNormalizer)Tests|StepFunTokenRefreshTests.*password login matches web ID|ClaudeProviderRuntimeTests|BoundedTaskJoinTests|CodexBarPluginTests|UsageFormatterTests|SettingsStoreCoverageTests|NeuralWatt|ProviderCredentialCharacterizationTests|ProviderConfigEnvironmentTests|ProviderTokenResolverTests|ProviderPluginRuntimeTests|UserProviderPluginPortableTests|ProviderPluginExtensionParityTests|ProviderPluginDetailsParityTests|ProviderIconResourcesTests|ClaudeExtraWindowQuotaWarningTests|UsageStoreAccountQuotaWarningTests|QuotaWarningNotificationLogicTests|QuotaLowHookAccountScopingTests|ClaudeActiveAccountIdentityInvalidationTests|ClaudeResilienceTests|ClaudeCLIScopedWeeklyUsageTests|ClaudeUsageDetailNoteTests|Sub2APIPluginGoldenTests'

Closes #3806, Closes #3807, Closes #3816, Closes #3818, Closes #3814, Closes #3817, Closes #3812, Closes #3811, Closes #3815, Closes #3813, Closes #3819.

steipete and others added 18 commits September 21, 2026 01:47
Adopt #3721; the existing ColorPicker already previews the resolved accent color.

Co-authored-by: Elijah Friedman <efriedman810@gmail.com>
(cherry picked from commit 2ca4b1f)
Adopt the disclosure animation from #3745. Keep child rows and native menu resizing immediate, without clipping potentially taller content. Share leaf and group row styling.

Co-authored-by: Elijah Friedman <efriedman810@gmail.com>
(cherry picked from commit 2dad974)
Adopt the five scoped menu/settings surfaces from #3695. Keep staged
updates on their existing install route and omit the sidebar badge.
Consolidate About's Updates section, remove the unused email formatter,
and simplify provider version matching without changing its output.

Co-authored-by: Alec Gutman, Chip <44984861+Chipagosfinest@users.noreply.github.com>
(cherry picked from commit ecd7410)
…3816)

Replace rejected CodexBar cache items only when fresh data is available, and retain bounded repair state through delete/add failures and duplicate-item updates. Keep inconclusive no-UI delete failures retryable.

Enforce stored Claude prompt policy at the external security reader boundary. Document ACL replacement and signing identity limits without claiming the recurring prompt report is reproduced.

Refs #3249

Refs #3798

(cherry picked from commit a1dab45)
Infer owned component baselines without recounting copied token snapshots,
including advancing snapshots and inherited-only suffixes. Preserve child
model context, independent counters, and cumulative replay deduplication.
Reparse older native caches through parser revision 4 without rebuilding
compatible history stores.

Refs #3524.

(cherry picked from commit 67960cc)
Distinguish inaccessible discovered Chrome localStorage from missing sessions
and token rejection while preserving usable profiles and token/org priority.
Document app and CLI manual authentication with exact token/header steps.

Remove an unused importer wrapper and consolidate duplicate parsing so
production code remains smaller. Cover storage permissions, ignored hidden
files, session precedence, and CLI guidance with synthetic regression tests.

Refs #3660, #3781.

(cherry picked from commit 3e045d7)
Filter shared model rankings by provider and label omitted history as partial.
Keep day-scoped models out of full-window rankings, preserving unknown totals.
Reuse checked aggregation without changing missing-cost or overflow behavior.

Fixes #3714
Closes #3747

Co-authored-by: Alec Gutman <44984861+Chipagosfinest@users.noreply.github.com>
(cherry picked from commit a67c1e6)
Bound the ambient refresh wait without cancelling the provider request, and
refresh the adapter independently when a stalled predecessor delays that read.
Keep credential transactions serialized through the current adapter list.

Adopts #3750 with a bounded join instead of a task group that still waits for
its suspended child. Refs #3736.

Co-authored-by: keepitmello <keepitmello@users.noreply.github.com>
(cherry picked from commit b73c145)
Name the disabled Keychain setting without changing credential precedence or
prompt policy. Keep active subscription identity and an unavailable-quota
note when subs_usage is omitted or null, while rejecting malformed payloads.
Share snapshot fields and remove redundant credential checks.

Adopts #3772. Verified with synthetic credentials and both plugin engines.

Co-authored-by: oldcai <hi@oldcai.com>
(cherry picked from commit 4d8a9ab)
Route USD conversion through the existing pivot and remove one-use cache and
rate wrappers. Preserve public initialization, normalized currency codes,
cached-rate precedence, and locking. Use in-memory defaults for offline
fallback and cache coverage.

Follow-up cleanup for the converter reviewed in #3624, whose TRY support is
already on main. No currency behavior changes are intended.

Co-authored-by: aguvener <90110302+aguvener@users.noreply.github.com>
(cherry picked from commit f8052f9)
Keep key-bound user and team usage, private-network origins, budget labels, and identity-only snapshots. Delete the Swift fetch and parse twin. Record NeuralWatt’s remaining typed transport retry and cancellation blocker without changing its native implementation.

(cherry picked from commit 3a4e27a)
Read tenant dashboards through a bundled TypeScript plugin, confine manual
cookies to the selected tenant, and require explicit premium billing before
showing rolling tiers. Preserve per-model resets and Cloud-only prepaid balances.

Co-authored-by: luisgonzaleznf <luis@getduckbill.com>
(cherry picked from commit dc72e99)
Reuse verified account bindings for threshold notification state while preserving source-scoped hook and predictive histories. Defer unowned OAuth and CLI samples without retiring known warning episodes.

Refs #3450.

(cherry picked from commit 31d95f8)
@clawsweeper

clawsweeper Bot commented Sep 21, 2026

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 21, 2026
@clawsweeper

clawsweeper Bot commented Sep 21, 2026

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 21, 2026, 6:17 AM ET / 10:17 UTC (Revision 3).

ClawSweeper review

What this changes

Combines provider and credential repairs, corrected forked-session accounting, Helmcode support, plugin conversions, menu improvements, shared-statistics fixes, and preservation of eligible widget measurements after failed refreshes.

Merge readiness

Ready for maintainer review

Keep open: this owner-sponsored integration contains useful work absent from current main. No blocking introduced defect was established in the reviewed paths; repository policy also excludes automatic closure.

Priority: P2
Reviewed head: a06178c973307ba1958c46558e41a0bcdcc6e344

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A useful, owner-scoped integration with substantial regression and upgrade coverage and no established blocking finding.
Proof confidence 🌊 off-meta tidepool Not applicable: This owner-authored train is exempt from the ordinary contributor proof gate. Inspected images demonstrate accent and synthetic shared-card changes; reported isolated tests cover runtime boundaries, without claiming a live train run or broader native recovery proof.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: This owner-authored train is exempt from the ordinary contributor proof gate. Inspected images demonstrate accent and synthetic shared-card changes; reported isolated tests cover runtime boundaries, without claiming a live train run or broader native recovery proof.
Evidence reviewed 9 items Policy and review scope: Read the complete root AGENTS.md; no nested AGENTS.md or maintainer-note files were found. Applied credential isolation, provider ownership, bounded concurrency, and focused validation guidance. Builds, tests, live probes, and repository mutations were excluded by the read-only review contract.
Pinned introduction and merge identity: Inspected the introduced delta from d8d0f33 to a06178c. Raw test-merge parents are exactly main followed by the pinned head, and its tree matches the head. The original head separately records da29dfd as its parent.
Work remains unmerged: Current main retains the native proxy fetchers and parser revision 3; this branch introduces the conversions and revision 4. The latest supplied release, v0.63.0, also contains parser revision 3, and no local tag contains the pinned head. GitHub confirms the adopted plugin and widget lanes remain open, so they do not establish an already-merged replacement.
Findings None None.
Security None None.

How this fits together

CodexBar collects provider quotas and local usage history, associates measurements with accounts, and presents them in menus, shared cards, and widgets. This integration changes collection, credential handling, accounting, and presentation across those layers.

flowchart LR
  A[Provider settings and credentials] --> B[Credential and cookie checks]
  B --> C[Provider requests]
  D[Local session histories] --> E[Usage accounting]
  C --> F[Account scoped measurements]
  E --> F
  F --> G[Menus and shared cards]
  F --> H[Widget snapshots]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test delta Production +357 net (+2068/−1711); tests +2333 net (+2731/−398) Production growth includes generated JavaScript and the explicitly adopted Helmcode provider; focused regression coverage accompanies the integration.
Provider implementation changes 2 native fetchers replaced; 1 provider added Existing proxy configurations depend on parity across both JavaScript engines.

Technical review

Best possible solution:

Retain the integrated fixes with existing account and credential boundaries, bounded cache reparsing, and the documented limits on unresolved reporter scenarios.

Do we have a high-confidence way to reproduce the issue?

Yes, for the bounded repairs: unchanged-fingerprint expired credentials and inherited fork counters have concrete source triggers and regression fixtures. No live reproduction was performed, and the broader linked reports remain only partially addressed.

Is this the best way to solve the issue?

Yes: the adopted scope reuses existing plugin, credential, and snapshot owners, removes native fetch duplicates, and preserves upgrade behavior through focused compatibility tests.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against d8d0f3394989.

Labels

Label justifications:

  • P2: The train addresses bounded provider, accounting, credential, and presentation problems without evidence of an emergency regression.
  • merge-risk: 🚨 compatibility: Plugin browser APIs, proxy implementation cutovers, and persisted accounting upgrades are compatibility-sensitive; the owner explicitly adopts their scope and the inspected tests cover retained contracts.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This owner-authored train is exempt from the ordinary contributor proof gate. Inspected images demonstrate accent and synthetic shared-card changes; reported isolated tests cover runtime boundaries, without claiming a live train run or broader native recovery proof.
  • proof: 📸 screenshot: Contributor real behavior proof includes screenshot evidence. This owner-authored train is exempt from the ordinary contributor proof gate. Inspected images demonstrate accent and synthetic shared-card changes; reported isolated tests cover runtime boundaries, without claiming a live train run or broader native recovery proof.

Evidence

What I checked:

  • Policy and review scope: Read the complete root AGENTS.md; no nested AGENTS.md or maintainer-note files were found. Applied credential isolation, provider ownership, bounded concurrency, and focused validation guidance. Builds, tests, live probes, and repository mutations were excluded by the read-only review contract. (AGENTS.md:1, a06178c97330)
  • Pinned introduction and merge identity: Inspected the introduced delta from d8d0f33 to a06178c. Raw test-merge parents are exactly main followed by the pinned head, and its tree matches the head. The original head separately records da29dfd as its parent. (31f41c988fc9)
  • Work remains unmerged: Current main retains the native proxy fetchers and parser revision 3; this branch introduces the conversions and revision 4. The latest supplied release, v0.63.0, also contains parser revision 3, and no local tag contains the pinned head. GitHub confirms the adopted plugin and widget lanes remain open, so they do not establish an already-merged replacement. (Sources/CodexBarCore/Vendored/CostUsage/CostUsageCacheModels.swift:326, a06178c97330)
  • Cookie boundaries and accepted plugin scope: The broker validates declared domains, separates multi-domain caches, preserves single-domain cache keys, and conditionally evicts only the observed session. Helmcode manual mode selects one tenant. The owner-authored feat(helmcode): add Cloud and NaN dashboard quotas #3815 explicitly adopts the browser helpers and full tenant header without cURL capture or path filtering; this train adopts that scope. (Sources/CodexBarCore/Plugins/ProviderPluginCookieBroker.swift:44, a06178c97330)
  • Credential final-effect checks: Inspected cookie policy enforcement in both engines, request-origin validation and host-attached bearer credentials, same-origin redirect protection, and Keychain mutation queries. Cache repair targets CodexBar's own service with no-UI queries. The owner-authored fix(keychain): recover cache ACLs and respect Claude prompt policy #3816 explicitly retains consent and prompt policy and does not claim broader recurring-prompt reports fixed. (Sources/CodexBarCore/KeychainCacheStore.swift:207, a06178c97330)
  • Persisted accounting upgrade coverage: Revision-3 and older cache cases reparse inherited rows without changing source files or rebuilding the history store. Predecessor-hash tests preserve stored rows, metadata, and scan checkpoints, while the new fork fixtures cover cold, resumed, bounded, and forced scans. These tests were inspected, not executed. (Tests/CodexBarTests/CodexSubagentOrdinalBoundaryTests.swift:77, a06178c97330)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Rokas Tarasevičius: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (2 earlier review cycles)
  • reviewed 2026-09-21T09:14:29.865Z sha da29dfd :: needs maintainer review before merge. :: none
  • reviewed 2026-09-21T09:58:07.477Z sha a06178c :: needs maintainer review before merge. :: none

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. P2 Normal priority bug or improvement with limited blast radius. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant