Skip to content

fix(codex): keep spendable-credit accounts eligible at included usage limits - #6466

Closed
Hylouis233 wants to merge 2 commits into
lidge-jun:devfrom
Hylouis233:fix/consumable-codex-credits
Closed

Hylouis233 wants to merge 2 commits into
lidge-jun:devfrom
Hylouis233:fix/consumable-codex-credits

Conversation

@Hylouis233

@Hylouis233 Hylouis233 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

OpenAI Pool accounts at 100% included usage were classified as exhausted even when WHAM reported spendable purchased credits. This could pause the funded account, retire an existing conversation binding, and route the request to an empty account that returned 429.

Parse and cache spendable credits separately from reset tickets. Retain an independent five-minute observation clock, explicitly replace zero/null evidence, honor upstream refusal and overage flags, and use the same eligibility evidence for bulk pause, routing and complete-snapshot recovery. Preserve actual request cooldowns and the opt-in local main-account hard lock. A credits-only payload remains insufficient for cooldown recovery. Selection scores retain a funded account below the exhaustion boundary while preferring accounts with more included headroom.

Closes #6465.

Verification

On current upstream dev e0af52c (version 2.76.0):

bun scripts/test.ts tests/codex-integration/codex-{quota-parser-parity,routing,cooldown-recovery,auth-api,quota-auto-refresh}.test.ts tests/codex-integration/main-account-hard-lock-policy.test.ts tests/*/rate-limit-reset-credits.test.ts
bun run typecheck
bun run privacy:scan
bun run structure:check
(cd docs-site && bun run build)
  • Focused seven-file Bun wrapper run: 695 passed, 1 skipped, 0 failed. Covered quota parsing/merging, routing and affinity, real request cooldowns, bulk pause and account APIs, automatic refresh, local main hard-lock policy, and reset-ticket separation. The new cases include positive/unlimited credits, zero/invalid balances, upstream refusal, overage flags, expiry, partial headers, explicit null and missing governing windows.
  • bun run typecheck, bun run privacy:scan, bun run structure:check, and the file-size ratchet passed.
  • After relocating the new affinity/cooldown scenario into the existing smaller cooldown test file to meet the file-size gate, the two affected files passed again: 213 passed, 1 skipped, 0 failed. Runtime code is unchanged from the seven-file run.
  • cd docs-site && bun run build passed: 561 pages and 77,818 internal links checked.

A narrow local backport to installed 2.63.0 also passed the same seven focused files (683 passed, 1 skipped, 0 failed) and six operator-script policy scenarios. After its built-in drain restart, the live account read preserved the funded account and the empty main-account pause. A real request used the funded account and returned HTTP 200, upstream response.completed, and pong. Configuration stayed unchanged and the pre-existing SSE patch hashes matched. Current live included usage was below 100%; the at-100% behavior is covered by synthetic regression fixtures and the pre-reset historical observation, not by that live probe.

Broader validation remains incomplete. bun run test:changed on the 2.63.0 backport selected 1,077 files and reported 22,773 passed, 40 skipped, 90 failed. A service-restart test worker stalled for over five minutes with no CPU activity and was terminated, so that result is not claimed as a passing suite. A control run on the unmodified quota baseline reproduced the same ten provider-validation failures (127 passed, 10 failed); the other broad failures have not all been attributed. The core quota modules connect to a very large test graph, and this run also contended with active local services. This PR stays draft pending broader validation, current-head CI, and review; the full suite on 2.76.0 has not been run. No failing broad result is suppressed or represented as passing.

The private operator script is outside this repository and is not part of this PR. No credentials, account identities, private request logs or real balances are included; the reproduction balance is synthetic.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Review readiness

  • Required local validation passed with its scope documented; broad validation remains incomplete.
  • Branch is based on the latest observed dev commit e0af52c.
  • All correct Codex and CodeRabbit findings are fixed; review pending.
  • Ready for review confirmed.

Review readiness checklist

This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:

  • Required local validation passed; commands, results, and any full-suite exception are documented.

  • I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • review readiness checklist open (0/4 boxes ticked).

What to do

  • Tick all four boxes in the PR description once you're done (currently 0/4).

Review readiness checklist

  • ⬜ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ⬜ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ⬜ I resolved all correct Codex and CodeRabbit findings.
  • ⬜ My PR is ready for review.

0/4 boxes ticked.

This PR stays in draft until every box above is ticked.

Hygiene

✅ Deterministic PR hygiene checks passed.

@Ingwannu

Ingwannu commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Current-dev compatibility checkpoint: trusted dev 4b74668 now includes src/codex/account-credit-use.ts and the per-account creditCodexAccountIds opt-in from #6444. That state is later than the e0af52c baseline documented here. Spendable upstream capacity and local permission to spend are different predicates: a positive balance must not silently enable credits for an account whose switch is off. Please refresh onto current dev and add paired routing/affinity/bulk-pause regressions with the same 100%-plus-credits fixture and spending OFF versus explicitly ON, preserving upstream refusal, real cooldown and credential/observation expiry. Reconcile the owning docs with the new default rather than stating balance alone keeps an account eligible. I have not found a decisive opt-in bypass in the final union or approved this 15-file quota change; this is an integration/test request, and the disclosed incomplete broad validation remains a hold.

robin-bially pushed a commit to robin-bially/opencodex that referenced this pull request Oct 3, 2026
…e-jun#6466)

Keep fresh paid credit evidence separate from included usage and reset tickets.
Unlike the proposal, only creditCodexAccountIds opt-ins can override exhaustion; missing or stale balances cannot bypass the default hold.
Reuse the canonical credit parser, preserve real cooldowns and main hard-lock policy, and retract omitted balance evidence on explicit upstream refusal.

Reimplements lidge-jun#6466 by @Hylouis233.
Closes lidge-jun#6465
Co-authored-by: Hylouis233 <88263959+Hylouis233@users.noreply.github.com>
@lidge-jun

Copy link
Copy Markdown
Owner

Superseded by the integration in #6487, with reviewed follow-up fixes in #6490 and Windows validation repairs in #6494/#6495, all merged into dev.

Spendable-credit handling was reimplemented while preserving the explicit creditCodexAccountIds opt-in, fresh-evidence requirement and main-account hard lock. Automatic spending without opt-in was deliberately not adopted.

Original carry commit: 6ef255fd067342214ffd0518d11c8ecbe0cc894d. Attribution to @Hylouis233 is preserved in the integration history and merge trailers. The final integrated candidate passed the complete cross-platform CI run.

Closing this PR as superseded, not claiming that its original head was merged. Thank you for the contribution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working superseded

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants