rdmodelrouter usage unification — build result
2026-09-27 11:56:57–12:17:48 EDT · rdmsm4x · codex@rdmsm4x/rmrnight.
FEAT-20260927-20; lead rdmodelrouter@rdmsm4x/rmr0926. Branch
rmr/usage-unify-20260927, base 231a300. Commit receipt
appended below.
Delivered
- Conditional direct ECSQuotaKit dependency, isolated by PublishedUsageReading. Pure shared parsing helpers used; no duplicate collector or native auth reads. Until shared package exposes a snapshot reader, versioned ~/.tyrell/usage.json is the canonical publication transport. Builds without the library too.
- Canonical schema-2 provider/account/window parser, state/freshness/provenance, measured credits without invented percentages, per-account expiry metadata. Fresh canonical data takes precedence over legacy vendor-gate. Missing/stale input has explicitly labelled degraded fallback. Existing quota errors still exhaust routes; unknown data never becomes zero.
- Both Codex emails mapped explicitly and independently. Gmail local selector points to ~/.codex-gmail with verified=false; missing directory is reported not signed in. No automatic login or account history/credential transfer.
- Status app shows shared provider meters and per-account sources. CLI quota JSON exposes publishedMeters. Canonical account coverage retires duplicate official-status subprocess polling. No inference/paid route enabled.
- INVENTORY.md plus docs/USAGE-CONTRACT.md and handoff copy. DEC-RMR-31 records ownership, parser reuse, degraded fallback and credential boundaries.
Reporting now
At final live CLI/window check around 12:16 EDT:
| Provider/account | Result |
|---|---|
| Claude | 51% worst canonical window, fresh |
| agy / Ultra | 33.2% worst canonical window, fresh; all four windows preserved |
| Codex iCloud | 46% weekly, fresh; email claim attribution works |
| Codex Gmail | Not signed in locally; no quota row; no number borrowed from iCloud |
| Copilot | 0.2% canonical monthly usage; disabled for automatic routing |
| OpenRouter | $0 key/account spend; key cap $100, account purchased credit $50; separate rows |
| Grok | Official CLI status available, weekly quota unmeasured |
| Hermes | Canonical unmeasured quota; independent official status confirmed Nous login |
| xAI API / ToshLLM | Keys named in inventory; no verified separate quota measurement |
| Firecrawl | Tool service, not inference-routing quota |
| Ollama / Goose / Cursor | Installed; no fabricated subscription allowance |
Quota freshness is NOT local CLI login verification. Today's publication lacks login_state for covered accounts, so accounts output truthfully says local sign-in unmeasured until the collector publishes it. A fresh meter never turns an unverified local selector into an authorized launch. This is an explicit remaining shared-contract field, not a failed vendor quota read.
Verification
- Baseline: 86 tests / 13 suites / 0 failures.
- Final default build: 96 tests / 14 suites / 0 failures, rc=0
(
tests-final.log). - Final RMR_DISABLE_QUOTA_KIT=1 build: 96 / 14 / 0, rc=0
(
tests-no-shared-lib-final.log). Initial disabled-library attempt exposed cached-module linkage; fixed via explicit manifest compile flag. Failed log retained for provenance, not counted as a final success. - Final
scripts/build-status-app.zsh: rc=0; CLI and status app both x86_64 + arm64, Intel minos 26.7. Worktree-only unsigned development bundle. - Six release acceptance checks passed (policy, two picks, SA-01 refusal, launch dry run, Gmail login plan); no apply. Receipt: release-acceptance.json.
- Final release CLI
quota --jsonandaccounts --json: rc=0;router-quota-live.json,router-accounts-live.json. - Official agy quota command returned zero turns/tokens. Official Codex stdio account/rateLimits/read returned iCloud identity/pro/45% at its earlier probe. gh read-only Copilot endpoint returned 99.8% remaining. No inference calls.
- Screenshot:
app-window-build.png, 1320x1480, SHA256 d5dbb633aea36729990bb4b7ce55e44b3ea0bea4c25eeeab059c867cf4e2e2c1. Captured the final rebuilt process/window (PID 70950, window 4189), visually inspected. Native CUA binding failed with native pipe closed; read-only window enumeration and screencapture captured the requested actual app. Installed app PID 51105 was not touched. Test process is terminated after capture. - Secret audit: 57 known credential candidates kept only in memory; regex and exact-value positive controls passed; working files, handoff logs, bundle and all reachable Git blobs and the current session transcript scanned. Initial hits were a public Xcode developer path stored under a misleading DEVELOPER_DIR_SECRET name. Equality to the known public path was proved; only that exact noncredential excluded. Final scan receipt appended after commit; no matched secret text is printed. A second regex hit was an official xAI documentation example returned by web search, allowlisted by its exact digest only; real known-value checks remain enabled.
- Independent OpenRouter no-prompt Keychain probe did not return within >90s; terminated. No successful direct Keychain or HTTP access claimed. Canonical OpenRouter readings are from the already-running shared collector.
Exact next actions for Tyrell owner
- Expose safe typed snapshot API in ECSQuotaKit; keep v2 published compatibility.
- Publish local login_state and explicit Gmail not-signed-in/unmeasured rows; keep fleet email identity separate from local selector evidence.
- Adopt verified official Codex stdio quota/identity recipe and agy /usage command; remove collector's need to inspect their auth files first.
- Grok: use approved shared OAuth credential access and TokenBar's overall weekly creditUsagePercent parser/reset guards. Current TokenBar credential read/refresh path is outside this builder's authorization. Until then unknown; if only web access is approved, explicit per-provider opt-in, cookies off.
- Copilot: publish token-based unit and preserve quota_remaining precision; refresh Pro+ plan/allowance from vendor on 2026-09-28, never hardcode.
- Hermes/ToshLLM: verify an account-usage endpoint before implementation. Keep API xAI usage separate from the shared SuperGrok subscription pool.
Full recipes, request/response shapes and official references are in the USAGE-CONTRACT. These asks are prepared as local artifacts; no outbound message or push was sent. Tyrell/shared-package source stayed read-only. No merge, install, signing, release, deletion or new sign-in occurred.
Apple Notes: pending because execution session is Background; changelog file copies under ~/dev/LLM/Claude/changelogs and ~/dev/LLM/Codex/changelogs.
Final commit and audit receipt
2026-09-27 12:21:05 EDT · rdmsm4x. Commit
7c5e194bbf103f703463aecaf6456fd57808ebee; Agent trailer
codex@rdmsm4x/rmrnight. Working tree clean, no merge/push.
Post-commit audit: 57 known credential candidates, 102 files, 235
reachable blobs, 1 current transcript, zero credential findings; pattern
and exact-match positive controls passed. Public documentation example
excluded only by exact digest. Native test app PID 70950 terminated;
installed app preserved. Notes helper rc=3 (Background).
Owner integration and additional shared collectors remain pending; this is a verified consumer branch and ready-to-implement collector handoff, not a claim that Grok/Hermes/Gmail now have measured quota.