Skip to content

fix(cost): enforce verifiable scan spending limits - #465

Draft
mldangelo-oai wants to merge 119 commits into
mainfrom
mdangelo/codex/enforce-verifiable-scan-budgets
Draft

mldangelo-oai wants to merge 119 commits into
mainfrom
mdangelo/codex/enforce-verifiable-scan-budgets

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Aug 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Scans with a spending limit must verify usage from owned workers, including final records written during shutdown and logs moved into compressed archives. This change preserves observed overages and interrupts Deep Scan workers through their native lifecycle while retaining terminal accounting records. Cost reporting without a requested limit remains best effort.

Changes

  • Resolve authoritative ownership through the selected native SQLite state for fresh, resumed, archived, copied, and retried sessions. Preserve prior ownership migration receipts and worker IDs when upgrading to the current main schema.
  • Reconcile live and final usage without double charging copied sessions or clearing an observed overage. Stream compressed receipts through the already-open file handle, including concatenated archives and early prefix reads. Preserve checksum, truncation, and ownership errors on supported Node versions.
  • Use native stdio RPC for Deep workers. Register accepted turns, interrupt active work, and await terminal records and natural shutdown. Preserve authentication, provider settings, permissions, executable selection, and SQLite settings across fresh and resumed discovery and reducer workers.
  • Integrate current main and update synthetic launch, ownership-retry, package, and migration fixtures to exercise the actual runtime boundaries.

Testing

The current integration (aae8ccd6) passed both full SDK runs: seed 12345 and default-randomized seed 989149221 each completed with 4,950 tests passed, 68 skipped, zero failures, and 81,259 assertions. SDK/MCP type checking, formatting, and 603 focused cost and API tests (4 platform skips) also passed. The merge integration cleared three independent native reviews and fresh verification without findings. Hosted checks for this revision passed.

The preceding 0654e53b integration completed both full SDK runs: each passed 4,948 tests with 68 skips and no failures, plus type checking, formatting, the five portable plugin source checks, and fresh/resumed worker launch checks. Its hosted CI completed successfully. The current incremental change touches only the pricing table and two adjacent test files; worker runtime, plugin source, native code, dependencies, and workflows are unchanged from that tested revision.

Previously completed behavior checks include Node archive accounting with native and portable decoders, installed SDK and standalone Deep Scan interruption/restart, ownership migrations, final accounting, and worker launch inheritance. Earlier failed or interrupted runs remain recorded separately and are not counted as passing validation.

Risk and rollout

Missing or unverifiable usage still fails a requested spending limit. Pricing remains estimated, and in-flight work may exceed the limit. The portable decoder is pinned for supported Node releases without native Zstandard support; both decoder paths preserve corruption errors and stop reading when a verified prefix is sufficient. Existing public commands, settings, and deadlines remain unchanged. All platform checks remain enabled.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@github-actions github-actions Bot added the bug Something isn't working label Aug 15, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 15, 2026 •

Copy link
Copy Markdown

Security review completed. No security issues were found in this pull request.

Reviewed commit: a147e46ca9

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a147e46ca9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/tests-ts/cost.test.ts Outdated
Comment thread sdk/typescript/src/cost.ts Outdated
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 15, 2026 •

Copy link
Copy Markdown

Security review completed. No security issues were found in this pull request.

Reviewed commit: 95b3782aef

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 95b3782aef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cost.ts Outdated
Comment thread sdk/typescript/src/cost.ts Outdated
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: ce460fe36a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 15, 2026 •

Copy link
Copy Markdown

Security review completed. No security issues were found in this pull request.

Reviewed commit: ce460fe36a

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current head, b9f37a9b17ed5f3c9122b25c6316ba01cc2ffde0.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 16, 2026 •

Copy link
Copy Markdown

Security review completed. No security issues were found in this pull request.

Reviewed commit: b9f37a9b17

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b9f37a9b17

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cost.ts Outdated
Comment thread sdk/typescript/tests-ts/cost.test.ts
Comment thread sdk/typescript/src/cost.ts Outdated
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@mldangelo-oai mldangelo-oai added area:cost Token usage, cost estimates, spending limits, and quota visibility. area:deep-scan Deep Scan coordination, worker scheduling, coverage, convergence, and resume. labels Oct 8, 2026
@mldangelo-oai mldangelo-oai removed area:cost Token usage, cost estimates, spending limits, and quota visibility. area:deep-scan Deep Scan coordination, worker scheduling, coverage, convergence, and resume. labels Oct 8, 2026

@zcrab-oai zcrab-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the diff and relevant callers at f8e5488, with an independent second pass. No actionable findings.

Focused validation: cost.test.ts:317 passed on initial run; one 5s timeout passed on isolated rerun with repository-required 30s timeout.

Validation limits: Full cross-platform and native live-model suites not rerun. Source review only; CI status remains separate.

CI still has failed, canceled, or unfinished checks. This source-review approval does not clear those checks.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants