Repository navigation
feat(codex): quota-driven desktop-authless auto failover - #5879
MateuszJuszczyk wants to merge 1 commit into
Conversation
While the main Codex 5h quota reports exhausted, recent Desktop builds disable the composer account-wide, including for independently credentialed routed models. Opt-in 'codexDesktopAuthlessAuto' engages desktop-authless routing on exhaustion and releases it on forced- refresh-confirmed recovery, rewriting config.toml and restarting Codex clients per transition. Related lidge-jun#4878.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
⏳ DRAFT
What to do
Review readiness checklist
0/4 boxes ticked. This PR stays in draft until every box above is ticked. |
리뷰 · 우선순위 53 / 80Codex 데스크톱은 본 계정의 5시간 한도가 다 차면, 그 한도를 안 쓰는 다른 모델까지 보내기 버튼을 꺼 버립니다. 요청이 프록시까지 오지 않아서, 프록시 안에서 길을 바꿔도 늦습니다. 이 PR은 한도가 다 찬 동안만 데스크톱 로그인을 끄는 스위치( 기본은 꺼져 있습니다. 라인 - 라인 - 메인테이너의 판단이 필요한 지점 켜는 쪽은 캐시에 적힌 숫자를 그대로 믿습니다. 끄는 쪽만 서버에 다시 물어봅니다. 캐시가 옛 100이면, 한도가 이미 돌아와도 먼저 로그인을 끄고 재시작합니다. 그 방향을 유지할지 정해 주세요. 자동이 켜져 있는 동안, 사람이 준비 체크 네 칸은 비어 있습니다. 너의 추천 바탕 이 댓글은 grok-bot이 작성했습니다 |
|
Thanks for this, @MateuszJuszczyk. Release train 4 reviewed it against current The direction is reasonable: an opt-in, transition-only toggle on the existing minute sweep, with no quota spoofing. Before a carry it needs:
It is also conflicting with |
|
Status after #6361 (squash |
Summary
Recent Codex Desktop builds (observed with bundled codex-cli 0.158.x) disable the composer
account-wide while the ChatGPT 5h quota reports exhausted — including for independently
credentialed routed models that consume none of that quota. Because every ocx-routed model
reaches Desktop through the same provider, and a disabled Send button means no request ever
leaves the client, proxy-side routing cannot help once this state latches. The only working
lever is the provider form: with
requires_openai_auth = falseDesktop skips the ChatGPTlogin/account gate, the composer stays enabled, and routed models submit with their own
credentials.
This PR automates the manual workaround (
ocx system settings --desktop-authless on) behinda new opt-in setting,
codexDesktopAuthlessAuto(default off):authenticated routing is restored.
truesets the key,falsedeletesit), re-runs
applyCodexConfigInjectionto rewrite~/.codex/config.toml, and restartsCodex clients so the new routing takes effect.
every failure path returns for the next sweep instead of throwing.
Design notes:
registerStateSweepAfterTick), next to thequota-window worker — no new timers, no hooks on the request hot path, and the quota
boundary guards (
reset-observerlazy-import discipline) are untouched.would mask genuine exhaustion and mislead every other consumer of that snapshot.
while the manual switch already exists in the dashboard. CLI (
ocx system settings --desktop-authless-auto on),PUT /api/settings, andconfig.jsonall expose it.src/server/index.tsregistration is folded into a newregisterCodexSweepWorkershelper because that file sits exactly at its file-size cap (remedy by move, not by number).
Related #4878 (same Send-disabled family; this mitigates the observable state via failover
and does not change native quota accounting).
Verification
bun run typecheck— clean.tests/codex-integration/codex-desktop-authless-auto.test.ts— 7/7 pass (engage onexhaustion, no-op when already engaged, release on refresh-confirmed recovery, stay engaged
when refresh still reports exhausted, skip non-pool modes and client role, apply/restart
failures contained).
settings-desktop-switch-apply,codex-quota-auto-refresh,quota-reset-observation,quota-reset-notify,quota-reset-core-boundary,core-lab-boundary(25/25, including the updated
UNRESOLVED_CALLEESentry for the renamed cleanup binding),full
tests/cli(1278 pass),skill:surface:check,privacy:scan,structure:check.bun run test:changed(24,972 tests): 24,909 pass; 19 failures, all inservice/WSL/ownership/native-toggle areas that pass in isolation on this machine (live proxy
and installed service interfere with the parallel run) — none touch the changed behavior.
for every model, flipping desktop-authless on re-enabled submission for routed models, and
the natural reset restored normal mode. No GUI files changed, so no screenshot applies.
Checklist
docs-sitereference + guide,structure/config.md).Review readiness checklist
This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:
Required local validation passed; commands, results, and any full-suite exception are documented.
I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
I resolved all correct Codex and CodeRabbit findings.
My PR is ready for review.