Repository navigation
fix(cost): enforce verifiable scan spending limits - #465
mldangelo-oai wants to merge 119 commits into
Conversation
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a147e46ca9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 95b3782aef
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
…/codex/portfolio-pr-465-20260815
|
@codex review Please review the current head, |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b9f37a9b17
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
zcrab-oai
left a comment
There was a problem hiding this comment.
Reviewed the diff and relevant callers at f8e5488, with an independent second pass. No actionable findings.
Focused validation: cost.test.ts:317 passed on initial run; one 5s timeout passed on isolated rerun with repository-required 30s timeout.
Validation limits: Full cross-platform and native live-model suites not rerun. Source review only; CI status remains separate.
CI still has failed, canceled, or unfinished checks. This source-review approval does not clear those checks.
Summary
Scans with a spending limit must verify usage from owned workers, including final records written during shutdown and logs moved into compressed archives. This change preserves observed overages and interrupts Deep Scan workers through their native lifecycle while retaining terminal accounting records. Cost reporting without a requested limit remains best effort.
Changes
Testing
The current integration (
aae8ccd6) passed both full SDK runs: seed12345and default-randomized seed989149221each completed with 4,950 tests passed, 68 skipped, zero failures, and 81,259 assertions. SDK/MCP type checking, formatting, and 603 focused cost and API tests (4 platform skips) also passed. The merge integration cleared three independent native reviews and fresh verification without findings. Hosted checks for this revision passed.The preceding
0654e53bintegration completed both full SDK runs: each passed 4,948 tests with 68 skips and no failures, plus type checking, formatting, the five portable plugin source checks, and fresh/resumed worker launch checks. Its hosted CI completed successfully. The current incremental change touches only the pricing table and two adjacent test files; worker runtime, plugin source, native code, dependencies, and workflows are unchanged from that tested revision.Previously completed behavior checks include Node archive accounting with native and portable decoders, installed SDK and standalone Deep Scan interruption/restart, ownership migrations, final accounting, and worker launch inheritance. Earlier failed or interrupted runs remain recorded separately and are not counted as passing validation.
Risk and rollout
Missing or unverifiable usage still fails a requested spending limit. Pricing remains estimated, and in-flight work may exceed the limit. The portable decoder is pinned for supported Node releases without native Zstandard support; both decoder paths preserve corruption errors and stop reading when a verified prefix is sufficient. Existing public commands, settings, and deadlines remain unchanged. All platform checks remain enabled.
Public disclosure review