Skip to content

fix(menu): avoid placeholder Dock promotion and show limiting quotas - #4335

Merged
steipete merged 2 commits into
mainfrom
triage/20260921-menu-appkit
Oct 7, 2026
Merged

steipete merged 2 commits into
mainfrom
triage/20260921-menu-appkit

Conversation

@steipete

@steipete steipete commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

CodexBar treated the empty SwiftUI Settings placeholder as a presented Settings window, promoting the app at launch. On the reported macOS 27 failure path, AppKit accepts promotion but refuses to restore accessory policy, leaving a Dock icon. Exclude the placeholder from promotion and regular-policy retention using the existing identifier/autosave-name rules, while preserving real Settings, minimized Settings, and Sparkle dialogs. Route the post-launch dismissal through the existing re-entry-safe guard and keep the placeholder out of restoration.

OpenCode Go's automatic menu-bar percentage and merged switcher now select the least remaining five-hour, weekly, or monthly quota before exhaustion. For a fixture with 20% rolling, 40% weekly, and 90% monthly usage, the switcher changes from 60% remaining to 10%. Explicit choices and other providers retain their existing rules. The UI guide also spells out the existing prefix-free weekly lane token for Codex and Claude.

Validation:

  • Red on unchanged production at 03a51bdcfc6: source Scripts/test_environment.sh; CODEXBAR_SWITCHER_QUOTA_PROOF_PATH=/tmp/menu-appkit-evidence/switcher-before.png swift test --build-system native --jobs 4 -Xswiftc -gnone --filter 'DockIconPolicyDecisionTests|SwitcherExhaustedQuotaTests' — 17 tests, 21 failed assertions (3 Dock, 18 quota).
  • Final-head focused proof: source Scripts/test_environment.sh; swift test --build-system native --jobs 4 -Xswiftc -gnone --filter 'DockIconPolicyDecisionTests|PlaceholderSettingsWindowGuardTests|AppDelegateTests|MenuBarMetricWindowResolverTests|SwitcherExhaustedQuotaTests|MenuBarLayoutRendererTests|MenuBarLayoutEditorTests|MenuBarLayoutTests|SparkleUpdaterControllerTests|OpenCodeGoProviderStrategyTests|ProviderArchitectureGatekeeperTests|ProviderPresentationPolicyCharacterizationTests|StatusItemBalanceDisplayTests|ClaudeDirectUsageFallbackTests|ClaudeSyntheticPlaceholder|ClaudeUsageInsightsTests|CompactOverviewTests' — 398 tests in 21 suites passed at de208143699.
  • Final-head full proof: CODEXBAR_TEST_SUITE_TIMEOUT=360 ./Scripts/test.sh --swift-command /tmp/menu-appkit-evidence/swift-native --direct-workers 4 — all 144 groups passed first try at de208143699, zero retries or timeouts; direct runtime verified 14,028 test methods. The wrapper forwards test/build to swift with --build-system native --jobs 4 -Xswiftc -gnone.
  • source Scripts/test_environment.sh; make check — passed on the final head; zero SwiftLint violations across 2,837 files.
  • Independent Codex review — no actionable P0–P2 findings, including after the single changelog-conflict rebase.

Earlier full-suite attempts caught two expectations for the previous OpenCode Go policy: the switcher-membership golden and a balance-display fixture expecting primary 12% instead of the limiting weekly 34%. Both are updated. An earlier check hit an unchanged process-cleanup timing test; serial reruns passed. An earlier full run recovered two unchanged Claude test groups on retry. The final-head full run above was clean without retries.

Dock validation uses deterministic descriptors without live NSApp activation; the reported macOS 27 LaunchServices failure was not exercised locally. Intentional Settings/update presentation still uses regular policy, so the OS can still refuse demotion after those real dialogs close. Opt-in live UI proofs and real account probes stayed disabled.

Production diff: 5 files, 26 insertions and 38 deletions (net -12). Tests: 6 files, 88 insertions and 15 deletions. The reduction removes the duplicate startup dismissal and a single-use quota wrapper while preserving its default ordering. The rebase preserved incoming Unreleased notes and left all source/test files owned by this PR unchanged.

Synthetic native rendering, identical fixture:

Before After
Before: OpenCode Go incorrectly shows 60 percent remaining After: OpenCode Go shows the limiting monthly 10 percent remaining

Exact-head CI run remains pending as of 2026-10-07 19:00 UTC, after the lane’s 12 permitted status polls: lint, change detection, Linux x64, Linux arm64, and Linux musl passed; macOS test shard 0 is running, shard 1 and macOS 15 compatibility are queued. No CI job has reported failure. Final job states were read through native REST using the authenticated personal writer; cached overall status was not treated as completion proof.

Fixes #4101
Fixes #3349
Refs #3671
Refs #4114

@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T18:01:22.730406Z de20814 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 7, 2026
@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed October 7, 2026, 3:13 PM ET / 19:13 UTC (Revision 3).

ClawSweeper review

What this changes

The branch prevents empty Settings placeholders from creating a Dock icon, makes OpenCode Go’s automatic quota displays show its tightest allowance, and documents prefix-free weekly percentages.

Merge readiness

✅ Ready for maintainer review

The PR remains useful: current main lacks both repairs, and no introduced correctness or security defect was found. The previous review's empty findings remain supported; no unresolved product decision or additional merge blocker was established.

Priority: P2
Reviewed head: de208143699c70273e610775ebb2db2cf556c06f

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, maintainable repair with useful native rendering evidence and reported full validation; the OS-specific activation path remains explicitly untested.
Proof confidence 🐚 platinum hermit (4/6) Not applicable: The OWNER-authored PR is exempt from the external-contributor proof gate. Inspected synthetic renders exercise the real quota helper and native switcher, showing 60% to 10% remaining; Dock coverage uses deterministic descriptors and does not prove macOS 27 LaunchServices recovery. No stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The OWNER-authored PR is exempt from the external-contributor proof gate. Inspected synthetic renders exercise the real quota helper and native switcher, showing 60% to 10% remaining; Dock coverage uses deterministic descriptors and does not prove macOS 27 LaunchServices recovery. No stored-data contract changes.
Evidence reviewed 9 items Pinned introduced change: Reviewed the complete introduced diff from the pinned main base to the original PR head: 14 files, with five production files and six test files. The supplied verified test merge has those same base and head parents.
Placeholder filtering preserves real dialogs: Window descriptors reuse the existing identifier/autosave-name decision, exclude placeholders from promotion and retention, and preserve registered Settings identities. Existing minimized Settings and Sparkle cases remain covered.
Shared dismissal and restoration behavior: The post-launch sweep now uses the existing guard, which records closure before synchronous notifications and disables restoration before closing. The removed startup implementation already disabled restoration, so this does not introduce a stored-data migration.
Findings None None.
Security None None.

How this fits together

CodexBar uses window notifications to manage temporary Dock presence and provider usage snapshots to render menu-bar percentages and switcher bars. These changes filter unwanted Settings windows and select the OpenCode Go quota that most limits remaining capacity.

flowchart TD
  A[Window notifications] --> B[Identify Settings placeholder]
  B --> C[Guarded dismissal]
  B --> D[Dock presence policy]
  E[Provider usage snapshot] --> F[Automatic quota selection]
  F --> G[Menu percentage and switcher bar]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test delta production +26/-38; tests +88/-15 Production shrinks through shared helpers while focused coverage expands around window eligibility and quota selection.

Technical review

Best possible solution:

Keep placeholder handling centralized and OpenCode Go quota ranking provider-scoped, preserving real-dialog behavior and explicit metric preferences.

Do we have a high-confidence way to reproduce the issue?

Yes from source for placeholder promotion and healthy-quota misselection on pinned main. The macOS 27 demotion failure is reporter-supported and was not independently executed.

Is this the best way to solve the issue?

Yes. The patch reuses established identity and presentation helpers, and the owner-authored change settles the broader OpenCode Go ranking choice without changing stored preferences.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 36bf01ace109.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: The PR addresses bounded Dock and quota-display defects without evidence of a blocked core workflow.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The OWNER-authored PR is exempt from the external-contributor proof gate. Inspected synthetic renders exercise the real quota helper and native switcher, showing 60% to 10% remaining; Dock coverage uses deterministic descriptors and does not prove macOS 27 LaunchServices recovery. No stored-data contract changes.
  • proof: 📸 screenshot: Contributor real behavior proof includes screenshot evidence. The OWNER-authored PR is exempt from the external-contributor proof gate. Inspected synthetic renders exercise the real quota helper and native switcher, showing 60% to 10% remaining; Dock coverage uses deterministic descriptors and does not prove macOS 27 LaunchServices recovery. No stored-data contract changes.

Evidence

What I checked:

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • harjothkhara: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (2 earlier review cycles)
  • reviewed 2026-10-07T18:05:14.161Z sha de20814 :: needs maintainer review before merge. :: none
  • reviewed 2026-10-07T18:32:24.003Z sha de20814 :: needs maintainer review before merge. :: none

@steipete
steipete merged commit c3c6ce0 into main Oct 7, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

1 participant