Skip to content

feat(codex): opt in to using remaining included quota - #6629

Draft
Yuxin-Qiao wants to merge 1 commit into
lidge-jun:devfrom
Yuxin-Qiao:codex/use-remaining-quota
Draft

Yuxin-Qiao wants to merge 1 commit into
lidge-jun:devfrom
Yuxin-Qiao:codex/use-remaining-quota

Conversation

@Yuxin-Qiao

Copy link
Copy Markdown
Contributor

Summary

An explicitly selected Codex account can still be switched away or refused at a proactive quota threshold while included quota remains. Turning off auto-switch alone does not remove the main-account hard lock. This adds a persistent, default-off preference for using an individual account's remaining included quota.

  • Add ocx account use-remaining openai <id|alias|main> <on|off|status> [--json] and authenticated GET/PUT /api/codex-auth/accounts/use-remaining routes.
  • When enabled, disable proactive usage switching for that account. For the main login, move the effective short/long hard-lock thresholds to 100%, allowing a 95% reading to admit a request. Preserve the underlying thresholds so turning the preference off restores them.
  • Keep pause, reauthentication, entitlement, upstream cooldown, and paid-credit rules in force. This preference does not select an account, override round-robin scheduling or automatic pause, grant paid-credit permission, or redeem reset grants. The default-on main hard lock still refuses at 100%.
  • Validate loaded/write-time configuration, roll back the live preference if saving fails, remove it when an account is deleted, and update account DTOs, CLI capability references, English/Chinese documentation, and architecture contracts.

Example after enabling the preference:

ocx account use-remaining openai main on
ocx account use openai main
ocx account use-remaining openai main status --json

This control is exposed through the CLI and API. Explicit maintainer security review is pending for the account policy and management authentication boundary.

Verification

Validated locally against head 2a7add53ca, based on dev at 0511f458f1:

  • bun run typecheck — passed.
  • Focused eight-file run covering remaining quota, main authentication/hard lock, threshold routing, CLI policy/capabilities, file-size ratchet, test layout, and the core/Lab import boundary — 234 passed, 0 failed during implementation.
  • After the final test additions, bun test tests/codex-integration/codex-use-remaining-quota.test.ts tests/cli/cli-account-policy.test.ts tests/ci-workflows/file-size-ratchet.test.ts — 114 passed, 0 failed. Includes 95%/99.9% admission, 100% refusal, pause/429 cooldown, persistence, rollback, management credential checks, malformed configuration, and restoration of saved thresholds.
  • bun test tests/server/management-route-registry.test.ts tests/cli/cli-capability-account-workflows.test.ts — 38 passed, 0 failed.
  • bun run privacy:scan, bun run structure:check, bun run skill:surface:check, and git diff --check — passed.
  • cd docs-site && bun install --frozen-lockfile && bun run build — passed, including internal-link validation.
  • bun run test — not passed: the parallel lane was terminated by the repository's 900-second watchdog (exit 124), with failures before termination and incomplete full-suite coverage. On an unchanged 0511f458f1 baseline, the Anthropic Fast management test also fails (7 passed/1 failed), and provider management validation has 118 passed/19 failed. These reproduce specific baseline failures; other full-run failures and timeouts have not all been independently classified.

Regression evidence uses isolated fixtures. No real-account quota consumption or production runtime activation was performed. No remote CI result or approval is claimed.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults. Explicit maintainer security review remains pending; the privacy scan passed.

Review readiness

  • Required local validation passed; commands, results, and any full-suite exception are documented.

  • I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the intake: hygiene-blocked Deterministic PR hygiene checks failed label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

⚠️ Deterministic hygiene checks failed.

  • unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/codex/auth-context.ts.

@github-actions github-actions Bot added the enhancement New feature or request label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • hygiene: unsponsored_surface.

What to do

  • Fix unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/codex/auth-context.ts.
  • Tick all four boxes in the PR description once you're done (currently 1/4).

Review readiness checklist

  • ⬜ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ✅ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ⬜ I resolved all correct Codex and CodeRabbit findings.
  • ⬜ My PR is ready for review.

1/4 boxes ticked.

This pull request was already a draft. Its draft status will be preserved after every issue above is resolved.
@Yuxin-Qiao Tick the boxes once required local validation has passed with commands, results, and any full-suite exception documented, your branch is on the latest dev commit, and every correct Codex and CodeRabbit finding is resolved.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request intake: hygiene-blocked Deterministic PR hygiene checks failed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant