Skip to content

feat(qwen): support Team Token Plan usage - #4338

Merged
steipete merged 2 commits into
mainfrom
triage/20260921-alibaba-zai
Oct 7, 2026
Merged

steipete merged 2 commits into
mainfrom
triage/20260921-alibaba-zai

Conversation

@steipete

@steipete steipete commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Qwen Cloud Team subscriptions were queried through the Individual-plan APIs and failed with “Missing token plan data.” The bundled Team plugin now reads the reported credit pool, remaining credits, seats, and NextCycleFlushTime reset.

The public Qwen console client supplies the previously missing billing-selector contract: ea-service / LoadHumanInfo in ap-southeast-1, followed by BssOpenAPI-V3 / GetSeatSubscriptionSummary in cn-hangzhou. The plugin reuses the native-selected dashboard session through the host’s opaque cookie and form-POST APIs. Valid Team usage takes precedence; Individual remains available when no active Team subscription is found. Team failures remain visible as diagnostics, and expired automatic sessions get one fresh-cookie attempt before fallback. Manual cookies stay strict.

This covers one active subscription group. Ambiguous multiple pools produce a diagnostic; existing endpoint overrides keep their Individual behavior. Provider registration/counts are unchanged. Thanks @tavioto for the sanitized Team capture.

Validation:

  • Scrubbed test environment via source Scripts/test_environment.sh; no live account probes. The installed signed CLI reports the relevant providers disabled.
  • swift test --build-system native --jobs 4 -Xswiftc -gnone --filter 'AlibabaTokenPlan|OneConsole|QwenCloud|TokenPlanMonthly|Zai|ProviderPluginDetailsParity|ProviderPluginConsoleCapabilities|ProviderArchitectureGatekeeper|ProviderSettingsDescriptor' — 336 tests / 35 suites passed.
  • After the authentication-recovery fix: swift test --build-system native --jobs 4 -Xswiftc -gnone --filter 'QwenCloud|TokenPlanMonthly|ProviderArchitectureGatekeeper|ProviderSettingsDescriptor' — 181 tests / 12 suites passed, including both plugin engines.
  • Red→green: the new Team fixture failed before the implementation; the stale-cookie and HTTP-200 login regressions failed before their fixes (3 issues), then passed.
  • make check — clean; SwiftLint reports 0 violations. The plugin test file also passed explicit SwiftFormat/SwiftLint checks.
  • Managed Codex review — clean through P2 after fixing its cookie-recovery finding.
  • Full suite on 8b52bf4400c9301870887f75b3839fd83273fd4d: ./Scripts/test.sh --swift-command /tmp/alibaba-zai-swift-native --direct-workers 4 — direct mode, 4 workers, 1,587 selections across 144 groups; all 144 groups passed on the first attempt; 0 failed groups, retries, or timeouts. The wrapper forwards test/build to Swift with --build-system native --jobs 4 -Xswiftc -gnone.

Synthetic before: the reported failure rendered through the menu model.

Synthetic Qwen Team failure

Synthetic after: the sanitized issue fixture parsed by the new plugin and rendered by the menu view.

Synthetic Qwen Team credit usage

Fixes #3711
Refs #2349, #2891, #2522, #3553

Hosted CI: run 37668430312 returned queued for this head in 12 scheduled status checks through 2026-10-07 19:38 UTC. The last response explicitly reported a shared-cache hit. Hosted completion is unverified; a fresh head-specific CI check is needed before merging.

Fetch Team credit pools through a bundled plugin using the console billing
selector, and keep Individual usage as the fallback. Preserve Team precedence
when cached automatic cookies expire, without replacing manual credentials.

Cover the reported summary, request regions, cycle resets, malformed quotas,
cancellation, cookie recovery, and synthetic menu presentation on both engines.

Fixes #3711
@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T18:41:44.545034Z 8b52bf4 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b52bf4400

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

private func fetch(
_ context: ProviderFetchContext, headers: QwenCloudCookieHeaders) async throws -> ProviderFetchResult
{
let runtime = try ProviderPluginRuntime(bundledPlugin: "qwencloud-team", transport: self.transport, timeout: 30)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Honor the configured web timeout for Team probes

When a caller selects a short --web-timeout, the new first-in-pipeline Team probe still uses a fixed 30-second runtime and three fixed 8-second requests; an authentication retry can repeat that entire budget before Individual fallback. This contradicts the CLI option’s documented “Web fetch timeout (seconds; source=auto or web)” semantics in Sources/CodexBarCLI/CLIOptions.swift:201-202, so Qwen requests can substantially exceed an explicit deadline. Derive both the runtime and request timeout from context.webTimeout instead.

Useful? React with 👍 / 👎.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Oct 7, 2026
@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex review: needs changes before merge. Reviewed October 7, 2026, 3:53 PM ET / 19:53 UTC (Revision 2).

ClawSweeper review

What this changes

Adds Qwen Cloud Team credit usage, remaining credits, seats, and cycle resets through a bundled provider script, with Individual usage retained as fallback.

Regression provenance

Possible regression — suspected (reviewed change). No predecessor PR is attributed.

Merge readiness

⛔ Needs changes before merge - 2 items remain

This PR remains useful because main and v0.73.0 cover Individual plans only. The previously reported timeout defect remains unfixed; repository policy and OWNER authorship also preclude automatic closure.

Priority: P2
Reviewed head: 8b52bf4400c9301870887f75b3839fd83273fd4d

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) Focused implementation and broad reported validation provide useful signal, but the existing timeout blocker remains.
Proof confidence 🌊 off-meta tidepool Not applicable: OWNER authorship exempts this PR from the ordinary contributor live-proof gate. The inspected synthetic screenshots demonstrate Team menu rendering through the real plugin and menu model with mocked HTTP responses; they do not establish live console compatibility. No stored-data contract changes require migration proof.
Patch quality 🦐 gold shrimp (3/6) 1 actionable review finding remain.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: OWNER authorship exempts this PR from the ordinary contributor live-proof gate. The inspected synthetic screenshots demonstrate Team menu rendering through the real plugin and menu model with mocked HTTP responses; they do not establish live console compatibility. No stored-data contract changes require migration proof.
Evidence reviewed 9 items Pinned introduced change: Read the introduced Swift strategy, TypeScript and generated JavaScript, both test files, descriptor changes, changelog, and documentation. The checkout equals the pinned original head; the verified test merge changes the same ten files.
Timeout defect remains: The Team strategy hardcodes a 30-second runtime, creates a fresh runtime for authentication recovery, and never reads context.webTimeout. The script independently hardcodes eight-second HTTP requests. The pipeline awaits strategies without enforcing an outer deadline.
Documented caller timeout: The CLI describes --web-timeout as the web fetch timeout for auto or web sources. The host copies script timeoutSeconds into URLRequest.timeoutInterval and bounds transport execution accordingly, so the fixed script value affects actual requests.
Findings 1 actionable finding [P2] Honor the configured web timeout in the Team probe
Security None None.

How this fits together

CodexBar’s Qwen provider turns an authenticated console session into usage displayed in the menu bar and CLI. The new Team probe runs before the existing Individual fetcher and maps the console’s subscription summary into the shared usage model.

flowchart TD
  A[Selected Qwen session] --> B[Team console requests]
  B --> C[Active Team credit pool]
  C -->|Valid| D[Shared usage model]
  C -->|Absent or failed| E[Individual fetcher]
  E --> D
  D --> F[Menu bar and CLI]
Loading

Before merge

  • Honor the configured web timeout in the Team probe (P2) - With a short --web-timeout, the new first-in-pipeline probe still receives a 30-second runtime and fixed eight-second HTTP requests. Authentication recovery creates another runtime with the same budget before Individual fallback, so the added path can substantially exceed the caller’s documented timeout. Derive the runtime and request budgets from context.webTimeout, accounting for recovery, and add short-timeout regression coverage. This previously reported finding remains unfixed at the same head.
  • Complete next step (P2) - Make Team runtime and HTTP budgets honor context.webTimeout, including authentication recovery, and cover short deadlines with regression tests.

Findings

  • [P2] Honor the configured web timeout in the Team probe — Sources/CodexBarCore/Providers/QwenCloud/QwenCloudTeamFetchStrategy.swift:40
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test growth production +401 net lines; tests +419 lines Production growth implements the new Team path and includes 181 lines of generated JavaScript; tests cover parsing, recovery, fallback, and presentation.

Root-cause cluster

Relationship: fixed_by_candidate
Canonical: #3711
Summary: This PR is the explicit implementation candidate for the Team Token Plan request.

Members:

Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything.

Technical review

Best possible solution:

Keep Team parsing within the existing Qwen provider while bounding its requests and authentication recovery by the caller’s configured timeout.

Do we have a high-confidence way to reproduce the issue?

Yes, source establishes that a short --web-timeout cannot constrain the new Team runtime or requests, including recovery. No execution was performed in this read-only review.

Is this the best way to solve the issue?

The bundled Team path fits the owner-approved direction and preserves Individual fetching, but the current implementation needs caller-derived timeout budgets.

Full review comments:

  • [P2] Honor the configured web timeout in the Team probe — Sources/CodexBarCore/Providers/QwenCloud/QwenCloudTeamFetchStrategy.swift:40
    With a short --web-timeout, the new first-in-pipeline probe still receives a 30-second runtime and fixed eight-second HTTP requests. Authentication recovery creates another runtime with the same budget before Individual fallback, so the added path can substantially exceed the caller’s documented timeout. Derive the runtime and request budgets from context.webTimeout, accounting for recovery, and add short-timeout regression coverage. This previously reported finding remains unfixed at the same head.
    Confidence: 0.99

Overall correctness: patch is incorrect
Overall confidence: 0.97

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 36bf01ace109.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is bounded provider coverage work with a concrete caller-timeout defect, without evidence of an urgent widespread regression.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🌊 off-meta tidepool and patch quality is 🦐 gold shrimp.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: OWNER authorship exempts this PR from the ordinary contributor live-proof gate. The inspected synthetic screenshots demonstrate Team menu rendering through the real plugin and menu model with mocked HTTP responses; they do not establish live console compatibility. No stored-data contract changes require migration proof.
  • proof: 📸 screenshot: Contributor real behavior proof includes screenshot evidence. OWNER authorship exempts this PR from the ordinary contributor live-proof gate. The inspected synthetic screenshots demonstrate Team menu rendering through the real plugin and menu model with mocked HTTP responses; they do not establish live console compatibility. No stored-data contract changes require migration proof.

Evidence

Acceptance criteria:

  • [P1] swift test --filter QwenCloud.
  • [P1] make test.
  • [P1] make check.

What I checked:

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • umutkeltek: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Apply the configured web timeout to Team fetching and add regression coverage for short deadlines and authentication recovery.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-10-07T19:23:25.736Z sha 8b52bf4 :: needs changes before merge. :: [P2] Honor the configured web timeout in the Team probe

@steipete
steipete merged commit 9fae8c8 into main Oct 7, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Qwen Cloud Team Token Plan support (GetSeatSubscriptionSummary)

1 participant