BUILD-RESULT — independent rdmodelrouter usage collectors
2026-09-27 15:33:30 EDT → 2026-09-27 16:01:47 EDT · rdmsm4x. Builder codex@rdmsm4x/rmrcollectors; lead rdmodelrouter@rdmsm4x/rmr0926. FEAT-20260927-20; isolated execution lease TASK-20260927-63. Branch rmr/own-collectors-20260927; clean starting HEAD ee4524f9c64c8df022f56609b38d3229ffa9e61e. Worktree /Users/richh/dev/_worktrees/rdmodelrouter-collectors-20260927. Commit only; no merge, push, install, signing or fleet deployment.
Delivered
Independent Codex iCloud/Gmail, Claude, agy, Grok Build, Copilot, OpenRouter and Nous usage readers; Grok Bot explicitly unmeasured after bounded local-source inspection. Optional Tyrell fallback is per account and fresh-only, retains the original observedAt, and never overrides local signed-out state. XEntropy-first UsageCredentialSource and read-only native fallback; provider-bound fixed GET endpoints; no refresh, credential writes, cookies, proxy, listener or paid inference. Credentials never enter reports/cache. All four agy groups/windows are preserved and labelled. UI rows show source, freshness and live plan.
DEC-RMR-32 replaces Tyrell-canonical ownership. DEC-RMR-33 authorizes usage-only native credentials and records the 15:24 XEntropy contract. DEC-RMR-34 replaces restrictive personal-tool defaults. AGENTS.md, README, INTERFACES and docs/USAGE-CONTRACT.md updated; previous contract preserved in archive. No Tyrell, XEntropy, ~/dev/lib or mem0 source was edited.
Live per-account results
Final release CLI was run with --policy pointing explicitly at this branch's policy.v2.json, because the user's installed config still points at canonical main. Six acceptance commands passed. The table is a measured snapshot, not a projection of future plan changes. All observed times are retained.
| Provider/account | Window | Result | Plan | Source | Observation / state |
|---|---|---|---|---|---|
| anthropic / native | 5h | 6.00% | not returned | Tyrell fallback / Tyrell / vendor-api (own reader / XEntropy binary missing; direct saved sign-in expired; no refresh) | 15:54:46 EDT / fresh |
| anthropic / native | 7d | 51.00% | not returned | Tyrell fallback / Tyrell / vendor-api (own reader / XEntropy binary missing; direct saved sign-in expired; no refresh) | 15:54:46 EDT / fresh |
| copilot / native | monthly | 0.20%; limit 20000 | individual_max | own reader / GitHub usage / direct gh saved sign-in (XEntropy binary missing) | 15:53:29 EDT / fresh |
| google / agy / Third-party | 5h | 0.00% | not returned | own reader / agy /usage / official saved sign-in | 15:53:29 EDT / fresh |
| google / agy / Third-party | 7d | 20.29% | not returned | own reader / agy /usage / official saved sign-in | 15:53:29 EDT / fresh |
| google / agy / Gemini | 5h | 24.33% | not returned | own reader / agy /usage / official saved sign-in | 15:53:29 EDT / fresh |
| google / agy / Gemini | 7d | 34.95% | not returned | own reader / agy /usage / official saved sign-in | 15:53:29 EDT / fresh |
| grokbot / native | unknown | unmeasured | not returned | own reader / Grok Bot local stores expose no verified weekly usage schema; browser cookies off | 15:53:29 EDT / unmeasured |
| hermes / hermes | monthly | 32 credits remaining | Plus | own reader / Nous Portal account / direct saved sign-in (XEntropy binary missing) | 15:53:29 EDT / fresh |
| openai / [email protected] | unknown | not-signed-in | not returned | own reader / Codex home absent | 15:53:29 EDT / not-signed-in |
| openai / [email protected] | 7d | 62.00% | pro | own reader / Codex app-server / official saved sign-in | 15:53:29 EDT / fresh |
| openrouter / [email protected] | lifetime | 4.571e-06 usd; limit 50 | credits | Tyrell fallback / Tyrell / vendor-api (own reader / XEntropy binary missing; direct Keychain rdmodelrouter unavailable) | 15:54:46 EDT / fresh |
| openrouter / [email protected] | lifetime | 4.571e-06 usd; limit 100 | credits | Tyrell fallback / Tyrell / vendor-api (own reader / XEntropy binary missing; direct Keychain rdmodelrouter unavailable) | 15:54:46 EDT / fresh |
| xai / grok | unknown | unmeasured | not returned | own reader / Grok weekly creditUsagePercent absent or invalid / direct saved sign-in (XEntropy binary missing) | 15:53:29 EDT / unmeasured |
Official local account checks: iCloud, Claude, agy, Grok, Hermes and Copilot active; Gmail missing. Gmail ~/.codex-gmail was absent; no home/login was created or copied. The iCloud app-server supplied its own email and plan. Codex and agy use official usage protocols without exporting saved credentials.
Grok findings
The saved Grok Build sign-in successfully called the fixed weekly billing endpoint (HTTP 200), but its response omitted creditUsagePercent and productUsage. It returned currentPeriod.type WEEKLY, 2026-09-23T18:56:38.292181Z → 2026-09-30T18:56:38.292181Z. The monthly view also had no recognized used/monthlyLimit allowance. Therefore this is UNMEASURED, not 0% and not Rich's approximately 90%. A fixture proves that an explicit overall pool of 91% wins over a 10% GrokBuild product share. The inspected TokenBar source's missing-percent-to-zero behavior is deliberately not copied. The official explanation confirms the shared weekly pool: https://docs.x.ai/grok/faq .
Grok Bot: checked ~/.grokbot and its Application Support directory for named quota/usage/billing exports, and inspected packaged app.asar source. The app fetches its bar with getSandUsageStatus plus getCurrentPeriodUsage, maps usagePercent to percentUsed and nextResetTimestampUtc to nextResetMs. No verified exported local weekly measurement/schema was found. No Cookies, browser storage tokens, app authentication state, or new RPC authentication path was read/implemented. This finding is bounded local inspection, not a claim that the provider has no usage API. Grok Bot remains its own unmeasured row.
Claude's directly saved credential is expired; the native file's expiry is 2026-09-27T11:37:45.452Z. No refresh was attempted. Tyrell supplies the labelled 5-hour and weekly fallback readings. OpenRouter's own no-interaction Keychain read was unavailable; labelled Tyrell spend/credit rows fill it. These are actual remaining credential-access gaps, not claims of direct-reader success. Nous's official installed hermes_cli/nous_account.py established /api/oauth/account. Live returned Plus and 32 credits remaining; no monthly percentage is inferred from a balance that may include rollover.
XEntropy interface and integration status
Read main README and INTERFACES; the announced docs/cred-broker.md was absent, and xentropy was not on PATH. The old xentropyctl/MCP surfaces are metadata-only and are not used as token suppliers. No XEntropy edits. Needed request shape, already implemented:
xentropy creds get <provider> [--account <label>] --caller rdmodelrouter --purpose usage --json
Providers: claude, grok, copilot, openrouter, hermes. Response: provider/account/kind/token/expires_at, with token held transiently only for that provider's request. Supported access credential kinds include oauth, oauth_access_token, access_token, bearer, api_key, api-key; refresh credentials are not sent. Missing binary, 3 revoked, 4 missing, 5 expired, malformed response and subprocess failure all produce a labelled direct fallback. No refresh or credential alteration occurs. The 15:24 contract has no grant operation and no TTY guard. No grant command is required or run. Fake xentropy on a private PATH validates exact argv, pipe capture, successful broker priority, failure fallback and identity/expiry rejection. Actual broker integration remains unverified until its binary exists.
Every default changed or audited
| Setting | Before | This branch |
|---|---|---|
| Subscription launch | Dry-run unless --apply | Real launch; --dry-run explicitly suppresses apply |
| --apply | Required for launch | Compatibility alias; conflicts with --dry-run |
| Usage collection | Tyrell-primary | Every independent reader on; Tyrell fallback only |
| Credential lookup | No native usage reads | XEntropy first, direct read-only fallback, all on |
| Account checks | Existing official checks; Copilot skipped | On, with Copilot included; 7 policy accounts |
| Hermes | Manual-only account, omitted candidates | Automatic fallback using existing native login |
| Copilot | Disabled policy invariant | Enabled subscription fallback; plan from vendor |
| Local API eligibility | --allow-api required | Enabled by default; --allow-api compatible |
| Ollama configured model | Disabled | Enabled; installed glm-4.7-flash:q4_K_M verified by ollama list |
| Status auto-refresh | On, every 15 seconds | On, every 300 seconds; sanitized cache suppresses repeat reads |
| Login item | Enabled on first installed launch | Already correct, retained; respects an explicit later user choice |
| OpenRouter inference | Disabled plus paid opt-in | Retained; no paid default |
| xAI API inference | No implementation | Retained; no implicit paid route |
| MLX | Disabled placeholder model directory | Retained unavailable pending an actual model path; no model invented/downloaded |
| Login command | Explicit foreground --apply | Retained; usage never initiates a new login |
| Browser cookies / refresh | Off | Retained per Rich's explicit credential boundary |
| Missing Gmail / expiry / caps / SA-01 | Factual account and execution constraints | Retained; signed-out accounts are skipped, never guessed active |
| Error-log paths | Explicit source paths | Retained because no actual sanitized error feed is configured |
| Legacy policy.v1 | Compatibility policy | Retained as explicit historical choice; shipped default is v2 |
Verification and artifacts
- swift test: 110 tests / 15 suites / 0 failures, rc 0 (tests-final.log).
- RMR_DISABLE_QUOTA_KIT=1, isolated .build/noquota: 110 / 15 / 0, rc 0 (tests-noquota-final.log).
- Universal status build: rc 0; CLI and app x86_64 + arm64, Intel minos 26.7 (build-status-app-final.log).
- Six release checks: policy validation, pick, SA-01 rc 2, explicit launch dry-run applied=false, quota and all seven accounts. release-acceptance.json includes exact return codes.
- Actual default-launch versus --dry-run mutation behavior is proved with a fake runner; no real inference.
- Live interval: four credential files byte-identical before/after; immediate repeated quota reused disk cache byte-for-byte. Source observations stayed at their original time (release-acceptance.json).
- Secret scan before commit: 66 known values held only in memory, 242 reachable blobs, 100 files and current transcript, zero findings; exact and pattern positive controls passed. Final receipt follows commit.
- zsh syntax and git diff --check passed. No library modifications were needed.
- Initial failures were old credential-read bans, manual-only Hermes and six-account assertions; updated to the expressly superseding contract, retaining credential-boundary and paid-error controls.
Rebuilt development app process launched from the worktree. Native CUA app binding failed twice with "Sky Computer Use native pipe closed before response", including after reset. Screenshot NOT captured; app-window-build.png is not claimed. No visual UI acceptance is claimed. The test app process is cleaned up by exact PID/path; no installed app was replaced. Rebuilt bundle: .build/status-app/RDModelRouterStatus.app.
Ownership, durable output and resumption
Parent FEAT-20260927-20 still had a live usage-fix identity lease despite that completed handoff and merge. Preserved it; opened/claimed linked TASK-20260927-63 solely for this user-assigned collectors worktree. Preflight reported aged HIGH fleet mail. No outbound messages/acks, force-claim, workers or account migration were used. Lead remains rdmodelrouter@rdmsm4x/rmr0926. Commit only, no merge/push.
Apple Notes PENDING: launchctl managername is Background. fleet-notes-publish requires file copies and a pending report in this context. Copies retained in ~/dev/LLM/Claude/changelogs and ~/dev/LLM/Codex/changelogs. No GUI workaround or permission change attempted.
Resume: inspect this report, DEC-RMR-32..34, release-acceptance.json and the branch commit. Direct Grok percent requires a vendor response containing it; no inferred replacement is valid. Claude needs a non-expired existing credential; OpenRouter needs readable native Keychain or XEntropy delivery. The readers already fall back without blocking the rest. Broker and GUI screenshot remain external gaps. Undo source changes with a new revert commit; installed binaries and original credentials were untouched.
Final commit receipt — 2026-09-27 16:03:39 EDT · rdmsm4x
Commit 5179dff4a222ece55491786df0acd49ae82da655 on
rmr/own-collectors-20260927, Agent trailer present. 33 explicit files
committed; worktree clean. No merge or push. Postcommit scan: 66
in-memory known values, 274 reachable blobs, 116 files and current
transcript; zero findings, positive controls passed. Notes publisher
returned rc 3: Background session, not Aqua. File copies durable.
TASK-20260927-63 execution work resolved; parent feature remains for
lead integration.