fix(claude): migrate email-keyed iCloud snapshots to slot keys - #3111
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dc440cfdef
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex review: needs real behavior proof before merge. Reviewed August 21, 2026, 5:24 PM ET / 21:24 UTC. ClawSweeper reviewWhat this changesThis PR migrates Claude Swap CloudKit snapshots from email-derived record IDs to slot-derived IDs and removes a confirmed obsolete email-keyed predecessor. Regression provenancePossible regression — probable (reviewed change; known regression link). No predecessor PR is attributed. Merge readiness⛔ Blocked until real behavior proof is added - 7 items remain Keep open: the latest head still has two concrete CloudKit migration defects, and it lacks the required after-fix production CloudKit proof. The prior merged Claude Swap identity work is related but does not supersede this migration. Priority: P2 Review scores
Verification
How this fits togetherCodexBar converts provider account usage into local snapshots and optionally synchronizes them to CloudKit for fleet display. The migration path persists local sync state, waits for CloudKit save confirmation, then deletes an obsolete predecessor record. flowchart LR
A[Claude Swap account state] --> B[Local snapshot publication]
B --> C[Migration reconciliation]
C --> D[Persisted sync state]
D --> E[CloudKit save confirmation]
E --> F[Predecessor deletion]
F --> G[Fleet account display]
Before merge
Findings
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Treat the first empty snapshot publication as authoritative reconciliation, retry batch-rejected records with a bounded transient delay, add focused regressions, then capture a redacted production-signed CloudKit migration trace before merge. Do we have a high-confidence way to reproduce the issue? Yes for the two code paths: a restored mapping followed by Is this the best way to solve the issue? No. The replacement-then-delete design is appropriate, but it must reconcile an empty live set and classify batch rejections as recoverable before it is safe to merge. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against e85543ecf0f1. LabelsLabel changes:
Label justifications:
EvidenceAcceptance criteria:
What I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (10 earlier review cycles; latest 8 shown)
|
Terminal delete failures are reported once with delayed retries only for recoverable errors, and email-keyed leftovers wait until the replacement record is saved.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7080d1bdb8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Keep pending predecessor deletes in the persistence envelope before sleeping so a relaunch can finish the CloudKit migration if the retry task never ran. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5dc264d114
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Mark slot-keyed migration snapshots complete after permission, auth, or invalid-argument save failures so the 120s snapshot push does not keep requeueing the same record. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ec188c201b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Skip leftover-record retries after an account switch so a sleeping task cannot delete a same-named snapshot in a newly signed-in iCloud account. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eac53a8b5e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A later live email-keyed snapshot must not stay queued for delete just because an earlier slot-keyed save still has a pending predecessor set. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7f93015749
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A delayed CloudKit retry must not delete an email-keyed snapshot that was published again after a transient predecessor delete. Drop that name from the persisted retry set and the engine queue. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 290cfee9a2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A transient in-flight delete can land after the predecessor is live again. Skip persist-and-retry when the record is in the current live snapshot set so cancellation is not resurrected. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7e663aea7a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dbc3445215
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Skip retrying an unchanged terminal replacement without recording it in lastSnapshotHashes, so an unconfirmed slot cannot retire an email-keyed leftover.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aff7c1941e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…t saves Confirmed CloudKit saves now keep the in-flight payload hash, and terminal failures skip retrying that hash even when the snapshot has no predecessor.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9d6567f902
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…on stop A newer payload that arrives during an unconfirmed save stays pending and is flushed after that save completes, and toggling iCloud off no longer leaves in-flight hashes that skip every later publication.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4ee82a8f73
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…s on conflict accountTemporarilyUnavailable is treated as a transient CloudKit error, and a server-winning conflict no longer leaves pendingSaveHashes blocking later snapshot publications.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cd69625f2b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Fetched CloudKit snapshots no longer overwrite an in-flight local payload, and pending local updates win when merging unpublished fleet cache entries.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 78d553bd11
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Pending snapshot payloads from before disable are discarded so re-enabling sync cannot upload or delete against a stale account set.
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
Predecessor deletes must not run for other providers that move from email to a durable account ID. Drop the unreleased changelog line. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0e29fc9b57
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Turned on iCloud sync on this Mac to capture the CloudKit leftover ClawSweeper asked about. Secrets stay off. Live private zone after fetch (signed 0.54.0, this device only): one Claude Swap snapshot is still email-keyed ( Fleet currently has one Mac, so there is no second-Mac card screenshot. After-fix still needs an identity-signed build of this branch (this machine has no Developer ID). Details are in the PR body. |
…concile CKSyncEngine can confirm an in-flight slot save on relaunch before local snapshots publish. Wait until that set is applied so a leftover email-keyed record that became live again is not deleted. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Proof submission has hit its limit on this checkout. This machine can show the before leftover (one Mac, production It cannot show after-fix:
Parser tests are not a substitute for that after-fix / two-Mac capture. Next live proof needs CODEXBAR_SIGNING=identity \
APP_IDENTITY='Developer ID Application: Peter Steinberger (Y5PE65HELJ)' \
./Scripts/package_app.sh releasePushed |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3d0ffb1003
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| liveSnapshots: self.pendingSnapshots, | ||
| hashes: self.lastSnapshotHashes, | ||
| envelope: self.persistenceEnvelope) | ||
| if !self.pendingSnapshots.isEmpty { |
There was a problem hiding this comment.
Reconcile authoritative empty snapshot publications
When a relaunch restores pendingPredecessorDeletes and the replacement-save confirmation arrives before local usage, an authoritative queueSnapshots([]) never sets hasReconciledLiveSnapshots; if there is no persisted delete yet, the guard above also returns before reaching this branch. The confirmed slot-keyed record and its email-keyed predecessor can therefore remain duplicated indefinitely when this Mac currently has no snapshots. Fresh evidence beyond the prior startup comment is that the final fix marks reconciliation only inside the nonempty branch; retain the deferred confirmation and drain it after the first publication even when that publication is empty.
Useful? React with 👍 / 👎.
| default: | ||
| guard let retryAfter = error.retryAfterSeconds else { return nil } |
There was a problem hiding this comment.
Retry records rejected with their CloudKit batch
When CloudKit reports .batchRequestFailed for a record because another record in the same batch failed, that error normally has no retryAfterSeconds, so this fallback classifies it as terminal. Save handling then suppresses the snapshot payload for the rest of the process, while delete handling forgets the persisted delete intent; after the peer record's conflict or transient failure is resolved, the batch-rejected replacement or predecessor deletion is never retried. Treat batchRequestFailed as recoverable and requeue it after the causal batch failure is handled.
Useful? React with 👍 / 👎.
* Fix menu bar layout editor drag-and-drop Layout editor chips were Buttons with .draggable attached. On macOS the button's gesture recognizer claims the mouse-down, so no drag session ever starts: reordering and the trash drop zone were unreachable by mouse and the Delete key was the only way to remove a token. Moving .draggable onto the button label does not help, because the button still owns the gesture. Replace the chips with a plain draggable view that keeps click selection, keyboard activation, and accessibility, and make the trash zone a click target for the selected token as well. * Fix Codex CLI approval policy (#3118) * docs: credit #3118 changelog entry * fix(commandcode): Add support for individual-pro-v1 plan ($80/mo credits) (#3116) * fix(commandcode): Add support for individual-pro-v1 plan ($80/mo credits) Command Code's updated Pro tier ($20/mo → $80 credits) ships as individual-pro-v1 (legacy individual-pro remains $30). The new planId hit the hard unknownPlan throw in CommandCodeUsageFetcher, surfaced as 'Unknown Command Code plan: individual-pro-v1'. Add the versioned plan to CommandCodePlanCatalog (verified against live frontend bundle assets/constants-B6rERLKd.js and pricing docs). Pro pricing now: $20 → $80 (docs/resources/pricing-limits), legacy Pro kept for backwards compat. * test(commandcode): Cover individual-pro-v1 plan resolution Regression coverage for the $80 Pro v1 tier: an active subscription with planId individual-pro-v1 must resolve through CommandCodePlanCatalog instead of hitting the unknownPlan throw, and the catalog check now pins pro-v1 at 80 credits. * fix(alibaba): tolerate the Personal usage gateway's empty-Success responses (#3128) Mainland Personal/Solo Token Plan (cn-personal) intermittently shows "Could not parse Alibaba Token Plan usage: Missing Personal usage windows" even though auth succeeds. The `/tokenplan/personal/api/v2/usage` gateway sometimes answers with a 200 "Success" envelope (`code=SUCCESS`, `successResponse=true`, empty errorCode) whose payload omits the `per5HourPercentage`/`per1WeekPercentage` windows. The parser treated that absence as a hard parse failure. - Throw a distinct `.usageWindowsUnavailable` for a Success-with-no-windows body instead of `parseFailed("Missing Personal usage windows")`. - Retry the usage call a few times (the payload is usually populated on an immediate re-request) before surfacing it. - When it stays empty, surface the softer "temporarily unavailable; it will refresh automatically" message. CodexBar keeps the last-good card either way (a returned empty snapshot would blank it, so this stays a thrown error). Verified on a real cn-personal account: the fetch retries and, while the endpoint was returning empty, surfaced the transient message with the last-good card preserved. Adds AlibabaTokenPlanPersonalUsageRetryTests (recovers when a full response follows an empty one; throws .usageWindowsUnavailable when every attempt is empty). Refs #2500. Co-authored-by: LeoLin <leolin990405@gmail.com> * docs: credit #3116 and #3128 changelog entries * fix(claude): migrate email-keyed iCloud snapshots to slot keys (#3111) * fix(claude): migrate email-keyed iCloud snapshots to slot keys * fix(sync): confirm CloudKit snapshot saves before deleting predecessors Terminal delete failures are reported once with delayed retries only for recoverable errors, and email-keyed leftovers wait until the replacement record is saved. * fix(sync): persist leftover snapshot deletes across delayed retries Keep pending predecessor deletes in the persistence envelope before sleeping so a relaunch can finish the CloudKit migration if the retry task never ran. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): stop retrying terminal CloudKit replacement saves Mark slot-keyed migration snapshots complete after permission, auth, or invalid-argument save failures so the 120s snapshot push does not keep requeueing the same record. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): bind delayed CloudKit deletes to the originating engine Skip leftover-record retries after an account switch so a sleeping task cannot delete a same-named snapshot in a newly signed-in iCloud account. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): drop stale CloudKit predecessors that are live again A later live email-keyed snapshot must not stay queued for delete just because an earlier slot-keyed save still has a pending predecessor set. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): cancel leftover snapshot deletes when they become live A delayed CloudKit retry must not delete an email-keyed snapshot that was published again after a transient predecessor delete. Drop that name from the persisted retry set and the engine queue. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): do not retry CloudKit deletes for live snapshots A transient in-flight delete can land after the predecessor is live again. Skip persist-and-retry when the record is in the current live snapshot set so cancellation is not resurrected. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): isolate CloudKit migration state from the next iCloud account Clear predecessor maps and snapshot hashes when persistence is wiped, and requeue leftover deletes only after the current live snapshot set has been reconciled. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): persist predecessor deletes and requeue empty publications Keep the replacement-to-predecessor map in the persistence envelope across relaunch, and still requeue leftover snapshot deletes when the next publication is empty. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): wait for every shared-mailbox replacement before deleting Two Claude Swap slots can share one email-keyed predecessor. Delete that leftover only after no unsaved replacement still points at it. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): retry lost CloudKit responses and keep shared leftovers Treat serverResponseLost as a recoverable retry, and confirm saved replacements before abandoning failed siblings so a shared email-keyed record is not deleted early. * fix(sync): queue predecessor deletes for unchanged slot payloads When a slot snapshot is already published, newly obsolete email-keyed leftovers still need to be recorded and deleted instead of being skipped by the payload-hash shortcut. * fix(sync): confirm slot saves and ignore remote cache as live Predecessor deletes now wait for a confirmed replacement hash, and delete retries treat only local pending/confirmed snapshots as live so a fetched leftover cannot cancel its own removal. * fix(sync): do not treat terminal save failures as confirmed Skip retrying an unchanged terminal replacement without recording it in lastSnapshotHashes, so an unconfirmed slot cannot retire an email-keyed leftover. * fix(sync): record confirmed save hashes and skip all terminal snapshot saves Confirmed CloudKit saves now keep the in-flight payload hash, and terminal failures skip retrying that hash even when the snapshot has no predecessor. * fix(sync): requeue in-flight snapshot updates and clear save markers on stop A newer payload that arrives during an unconfirmed save stays pending and is flushed after that save completes, and toggling iCloud off no longer leaves in-flight hashes that skip every later publication. * fix(sync): retry unavailable iCloud accounts and drop in-flight hashes on conflict accountTemporarilyUnavailable is treated as a transient CloudKit error, and a server-winning conflict no longer leaves pendingSaveHashes blocking later snapshot publications. * fix(sync): do not requeue fetched snapshots over in-flight local saves Fetched CloudKit snapshots no longer overwrite an in-flight local payload, and pending local updates win when merging unpublished fleet cache entries. * fix(sync): drop retained snapshots when iCloud sync stops Pending snapshot payloads from before disable are discarded so re-enabling sync cannot upload or delete against a stale account set. * fix(sync): limit email-keyed snapshot cleanup to Claude Swap Predecessor deletes must not run for other providers that move from email to a durable account ID. Drop the unreleased changelog line. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): defer restored predecessor deletes until live snapshots reconcile CKSyncEngine can confirm an in-flight slot save on relaunch before local snapshots publish. Wait until that set is applied so a leftover email-keyed record that became live again is not deleted. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> * fix(codex): isolate profile-scoped token cost snapshots (#3132) * docs: credit #3111 changelog entry * perf(spend): parallelize loads and memoize model build (#3105) * perf(spend): parallelize loads and memoize model build - Parallelize independent provider refreshes in makeRequest via TaskGroup (was sequential 400ms-6s additive). - Parallelize Codex multi-account loads in SpendDashboardSource.load via ThrowingTaskGroup (was sequential 2s×N). - Memoize SpendDashboardModel: cache CurrencyExchange conversion per currency pair, hoist bounds once per build, and reuse static utcCalendar for Mistral/OpenRouter bucket (was new calendar per entry, 2920× per build). Evidence: - SpendDashboardController.swift:237 parallel baselines - SpendDashboardController.swift:433 parallel codex - SpendDashboardModel.swift:300 conversionCache + bounds hoist - SpendDashboardModel.swift:1069 utcCalendar reuse Before: 全部 3-10s empty → 2-3s; build 40ms → 8ms. After: TaskGroup wall-time = slowest provider, model build cached. * fix(spend): restore Codex account order after parallel load Task group completion order was appended directly to inputs, but providerRows uses input offset as tie-breaker for equal/unknown totals, so out-of-order completions reordered Codex · #1/#2 rows. Carry request index and sort results before appending, with compact formatting to keep file_length under warning. Fixes ClawSweeper P2 for #3105. * test(spend): add out-of-order Codex concurrent order regression Verifies that parallel Codex loads restore configured request order even when second account's snapshot completes first. Equal totals make completion order visible via providerRows tie-breaker, so without sorting the rows would reorder. Covers ClawSweeper P2 for #3105 and serves as needs-proof evidence. * test: update gatekeeper anchors after rebase to 54.0 * fix(spend): repair parallel load CI - file_length and escaping captures * fix(spend): debounce frequent refresh and throttle date window rebuilds - 250ms debounce for withObservationTracking and token publication bursts - 30s throttle for refreshDateWindow same-day revisits - display-only fast path to avoid Codex scan for filter/currency changes - update gatekeeper anchors for line shifts * Improve Antigravity retrieval: retired Flash alias and offline fallback - Map retired Flash wire ids (3.6/3.5/3-flash-agent) to 3.7-flash via canonicalModelID (opencodex RETIRED_FLASH_TIERS lesson), humanize via canonical, dedup collapsed windows by lowest remaining - Add AntigravityOfflineStore counting ~/.gemini/antigravity-cli/conversations/*.db (GEMINI_CLI_HOME override) with tokscale cache fallback, and AntigravityOfflineFetchStrategy as terminal offline probe in auto/cli pipelines - Cover with AntigravityModelLabelTests retired alias cases and AntigravityOfflineStoreTests (db/cache/count) * fix(gate): add missing provider-specific markers and sync anchors - add // Provider-specific by design for OpenCodex enrichment and token publication sync - sync gate anchors after debounce/throttle line shifts * fix(lint): wrap long provider-specific comment * Fix provider architecture gatekeeper for Antigravity offline and retired alias - Move CLI home marker to before gemini literal and update SpendDashboard marker to avoid flagging its own reason - Add marker before family() and update suppressed anchors to 748/751/754/757 - Allowlist offline gemini, family cluster, and UsageStore codex constructs * test: include offline strategy in antigravity pipeline expectations * fix(gate): sync remaining anchors and add missing markers * chore: trigger CI * fix(spend): make debounce instant for testing * fix(gate): update anchors after merge with main * fix(lint): break long delay line * fix(gate): drop stale codex anchor absorbed by sourceRevisions cluster * docs: credit #3105 changelog entry * style: swiftformat pass on layout editor chips --------- Co-authored-by: kiranmagic7 <kiranmagic@proton.me> Co-authored-by: Peter Steinberger <steipete@gmail.com> Co-authored-by: Sebastian Marines <18373185+sebastianmarines@users.noreply.github.com> Co-authored-by: Zhongyue Lin <101193087+LeoLin990405@users.noreply.github.com> Co-authored-by: LeoLin <leolin990405@gmail.com> Co-authored-by: sf-jin-ku <jin.ku@sendbird.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Yuxin Qiao <104957188+Yuxin-Qiao@users.noreply.github.com>
Summary
claude-swap:<slot>. CloudKit cannot rename record IDs, so this Mac now saves the slot-keyed record and deletes its leftover email-keyed record on the same device..claude,loginMethod == claude-swap, andaccountIDprefixedclaude-swap:. Live email-keyed snapshots (for example a still-present Claude identity that uses the mailbox) are left alone. Unknown CloudKit names are not deleted.Test plan
swift test --filter SyncModelTests(includes non-Claude / Claude-subscription predecessor regressions, and restored-mapping reconcile)make check/./Scripts/lint.sh lintProof limits (this checkout cannot go further)
This is as far as live CloudKit evidence can go here. Do not treat the leftover inventory as after-fix proof.
Captured
fleetDevices: 1)CodexBar 0.54.0with CloudKit entitlementsloginMethod: claude-swap, noaccountID, email-shaped identity,snap-claude-<64-hex>-<this-device>where<64-hex>is notsha256("claude-swap:N")for N in 0..31)snap-claude-default-<this-device>cardBlocked on this machine
security find-identity -p codesigning -v→ 0 identities).package_app.shonly embeds CloudKit entitlements +Scripts/profiles/CodexBar-DeveloperID.provisionprofileforDeveloper ID Application: Peter Steinberger (Y5PE65HELJ)+ release +com.steipete.codexbar. Ad-hoc /CodexBar Developmentcannot talk to ProductioniCloud.com.steipete.codexbar.Parser tests and the Claude Swap-only predecessor guard are not a substitute for two-Mac after-fix.
ClawSweeper P1 / P3
CHANGELOG.mdline for this migration removed (release-owned).Made with Cursor