Skip to content

Port upstream 0.64.0: Helmcode reset fallback, tenant dashboard URL, optional endpoint tolerance - #723

Draft
Finesssee wants to merge 2 commits into
port/upstream-0.64.0from
port/micro-0.64.0-helmcode-parity
Draft

Finesssee wants to merge 2 commits into
port/upstream-0.64.0from
port/micro-0.64.0-helmcode-parity

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Brings the Helmcode provider to behavioral parity with upstream CodexBar v0.70.0 (helmcode.ts, HelmcodeProviderDescriptor.swift). Closes audit GAP-19.

  • Monthly reset fallback: when a model has no usable periodEnd, the reset falls back to 00:00 UTC on the first day of the month after periodStart (December rolls into January). periodStart is parsed with upstream's ^YYYY-MM-DD(T|$) rule, month 1..12, day 1..31, so date-only values such as 2026-09-01 now work. Before this change the fallback was the first of the same month and needed a full RFC 3339 string.
  • Optional endpoints: /api/billing and /api/billing/credits use a 2 s timeout and any failure (401/403/3xx/429/5xx, network error, timeout, bad or non-object JSON, oversized body) is treated as absent. They can no longer turn into AuthRequired or discard quota data. The quota endpoint is unchanged: 401/403/3xx still means AuthRequired. Redirects are not followed, matching upstream's 3xx handling.
  • Integer validation rejects values above 2^53-1; a negative safe-integer balanceMicros clamps to a zero balance instead of being rejected.
  • Dashboard URL per tenant: dashboard_url_for_organization returns https://cloud.nan.builders/dashboard for the "NaN Builders" organization and https://cloud.helmcode.com/dashboard otherwise. It is wired into open_provider_dashboard (new injected State parameter; the frontend invoke is unchanged) and get_provider_detail, using the cached snapshot organization. No frontend change.

Tests

New mockito HTTP tests cover optional endpoints returning 401/403/302/429/503, quota 401/403/302 still needing auth, the NaN tenant skipping credits, premium rolling windows, schema drift, and the monthly fallback cases (including 2026-12-15, 2026-13-01, garbage).

  • cargo +1.98.0 fmt --all --check: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: clean
  • cargo test -p codexbar: 2172 passed
  • cargo test -p codexbar-desktop-tauri: 461 passed, 1 failed. commands::tests::bootstrap_payload_exposes_every_provider_variant (catalog size 79 vs 78) fails identically on the unmodified base port/upstream-0.64.0, so it is not caused by this change.

UI proof

No visible UI change: only the URL opened by the existing "open dashboard" action for the NaN Builders tenant changes. No CUA run was needed.

Written by the codex-2 lane (Codex gpt-6-luna xhigh, reviewed by Claude).

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at 7fe1de4

Validator finding confirmed: premium_billing_reveals_rolling_windows_and_requires_boolean_true recomputed the premium predicate inline instead of exercising production code. It is now an async test that sends the billing bodies {}, {"subscription":{"premium":"true"}}, {"subscription":{"premium":1}} and {"subscription":{"premium":null}} through mock_fetch (the full fetch_usage path) and asserts 3 extra windows, all with window_minutes None, and primary window_minutes None. Mutation check: making production accept the string "true" makes the test fail. No production code changed.

Commands: cargo +1.98.0 fmt --all --check; cargo +1.98.0 clippy --workspace --all-targets -- -D warnings; cargo test -p codexbar (2172 passed, 0 failed); cargo test -p codexbar-desktop-tauri (461 passed, 1 failed: the existing base failure commands::tests::bootstrap_payload_exposes_every_provider_variant, unrelated).

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation (Claude Opus 5.5) passed at 7fe1de4

Scope: GAP-19, Helmcode reset fallback, tenant dashboard URL and optional-endpoint 401/403 (upstream aa32d41). The diff against port/upstream-0.64.0 (b585d48) touches rust/src/providers/helmcode.rs (940 lines), commands/system.rs and commands/provider_detail.rs.

What I checked against upstream v0.64.0 / v0.70.0 helmcode.ts, HelmcodeProviderDescriptor.swift and HelmcodePluginTests.swift:

  • Monthly reset fallback: a date-only periodStart (or one with T at index 10) gives the first day of the next month, December rolls into the next year, and invalid month/day values give no reset. This matches the plugin's Date.UTC(year, month, 1) with a 1-based month.
  • Optional endpoints (/api/billing, /api/billing/credits): any non-200 status, a transport error, an unreadable body, invalid JSON or a non-object body makes the value absent and never turns into an auth error. Quota 401/403 still requires sign-in. Redirects are not followed.
  • Credits: the balance must be a safe integer (|n| <= 2^53-1), the currency is 3 ASCII letters (null or missing means EUR), and a negative balance clamps to 0.
  • Premium windows are shown only for premium === true. The round-2 test sends {}, "true", 1 and null billing bodies through mock_fetch and the full fetch_usage path, and asserts 3 extra windows with no window_minutes. If production accepted a non-boolean value, parse_models(.., true) would give 6 models, so 5 extra windows, and the test would fail.
  • Dashboard URL: dashboard_url_for_organization matches HelmcodeProviderDescriptor.dashboardURL(snapshot:) ("NaN Builders" goes to cloud.nan.builders, everything else to cloud.helmcode.com). open_provider_dashboard reads account_organization from provider_cache (cli-name ids, with_organization(tenant.name())), and get_provider_detail sets the same URL. The managed Mutex<AppState> type matches the other commands.
  • No new dependency, logging, wire shape, frontend or locale change. All files are under 1000 lines.

Checks run at this SHA (toolchain 1.98.0, isolated target dir):

  • cargo +1.98.0 fmt --all --check: clean.
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: clean.
  • cargo +1.98.0 test -p codexbar: 2172 passed, 0 failed, 1 ignored. All 15 Helmcode tests pass.
  • cargo +1.98.0 test -p codexbar-desktop-tauri: 461 passed, 1 failed.
    • The failing test is commands::tests::bootstrap_payload_exposes_every_provider_variant (catalog 79 vs 78).
    • The same failure shows up on Port upstream 0.64.0: v0 billing dashboard URL #724, which does not touch the shell crate. It comes from the base and depends on the host (get_bootstrap_state() calls Settings::load()), so this PR does not cause it.

Finesssee added a commit that referenced this pull request Oct 2, 2026
…dashboard URL, optional endpoint tolerance
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at 38fb38c

Scope: Helmcode reset fallback, tenant dashboard URL, optional endpoint tolerance (#723, upstream 0.64.0), validated as merged into release/v0.70.0 (merge 38fb38c = merge of 7fe1de4 into 60255ea).

Attacks (highest-risk semantics, from the merged tree):

  • Monthly reset fallback is first-of-NEXT-month, not +30 days: monthly_reset_fallback parses periodStart's date fields with strict ASCII digit parsing and length guards, then computes the FIRST DAY OF THE NEXT MONTH (with the December→January year rollover via checked_add) at 00:00 UTC — the audit's "first of NEXT month, date-only periodStart" rule, not an approximate +30 days.
  • Optional endpoints never error: every optional-endpoint branch returns Ok(None) on transport error, non-2xx, and non-object body (Err(_) if optional => return Ok(None), optional && status != OK, optional && !value.is_object()), so a missing optional endpoint degrades gracefully instead of failing the whole fetch; the 2 s vs 8 s timeout split is keyed on optional.
  • Tenant dashboard URL: dashboard_url_for_organization maps the "NaN Builders" org to its own cloud dashboard and everything else to the Helmcode default — the tenant-specific URL the audit named.
  • Safe-integer bound + negative clamp: the ledger's "safe-integer bound, negative credits clamp" holds in the optional_nonnegative row parsing (creditTokens/windowHours default to 0.0 when absent).

No defects found. READY for the un-draft rule.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant