From 63bfd149dd04ffbe448f43004a17e371a514eb38 Mon Sep 17 00:00:00 2001 From: JUN Date: Wed, 19 Aug 2026 12:39:23 +0900 Subject: [PATCH 1/2] docs(governance): move @Wibias to former maintainers (#2098) @Wibias stepped down from developing opencodex, and repository permission was reduced to read access. Move him out of the current-maintainers table into a new Former maintainers section, drop him from the CODEOWNERS default-reviewer line and the four high-impact runtime paths, and record the change with the 2026-07-27 addition entry it closes. Nothing he authored is unwound: commits, merged pull requests, release-note attributions, and the code comments citing his reviews stay as they are. --- .github/CODEOWNERS | 10 +++++----- MAINTAINERS.md | 37 ++++++++++++++++++++++++++++++++----- 2 files changed, 37 insertions(+), 10 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 71f14c14a9..ae2c27bce7 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,11 +1,11 @@ # Default reviewers -* @lidge-jun @Ingwannu @Wibias +* @lidge-jun @Ingwannu # High-impact runtime behavior -/src/adapters/ @lidge-jun @Ingwannu @Wibias -/src/providers/ @lidge-jun @Ingwannu @Wibias -/src/codex/ @lidge-jun @Ingwannu @Wibias -/src/server/ @lidge-jun @Ingwannu @Wibias +/src/adapters/ @lidge-jun @Ingwannu +/src/providers/ @lidge-jun @Ingwannu +/src/codex/ @lidge-jun @Ingwannu +/src/server/ @lidge-jun @Ingwannu # Repository automation and release security /.github/ @lidge-jun @Ingwannu diff --git a/MAINTAINERS.md b/MAINTAINERS.md index 3214adfdf1..43377c093d 100644 --- a/MAINTAINERS.md +++ b/MAINTAINERS.md @@ -9,7 +9,6 @@ review and merge policy. | --- | --- | --- | | [@lidge-jun](https://github.com/lidge-jun) | Project owner | Project direction, releases, repository administration, and final governance decisions | | [@Ingwannu](https://github.com/Ingwannu) | Maintainer | Issue and pull-request triage, `dev` integration, security review, and repository maintenance | -| [@Wibias](https://github.com/Wibias) | Maintainer | Issue and pull-request triage, `dev` integration, and provider/CI maintenance | The table describes project responsibilities. Actual repository permissions remain controlled through GitHub repository settings. @@ -17,6 +16,16 @@ through GitHub repository settings. `dev` is the only integration line. The former `dev2-go` carry duty is retired; see [The retired `dev2-go` line](#the-retired-dev2-go-line). +## Former maintainers + +| GitHub account | Project role | Period | +| --- | --- | --- | +| [@Wibias](https://github.com/Wibias) | Maintainer | 2026-07-27 – 2026-08-19 | + +Former maintainers keep contributor standing and are welcome to open issues and pull requests like +anyone else. Authorship credit in git history, release notes, and code comments is not rewritten +when a maintainer steps down. + ## Review and merge policy - Pull requests target `dev`. It is the only integration line, and promotion to @@ -98,6 +107,24 @@ Adding or removing a maintainer requires: ### Change log +- 2026-08-19 — [@Wibias](https://github.com/Wibias) stepped down as a maintainer + and is now a contributor. This follows his own decision to stop developing + opencodex; it is not a disciplinary action, and it was made with the owner's + agreement (requirement 1). Requirement 2 does not apply to a maintainer's own + resignation, which needs no second maintainer to ratify it. Requirement 3 is + met by this file and `.github/CODEOWNERS`, where the default-reviewer line + and the four runtime paths that listed him (`/src/adapters/`, + `/src/providers/`, `/src/codex/`, `/src/server/`) drop back to the two + remaining maintainers. Repository permission was reduced to read access at + the same time, so the roster and the GitHub settings agree again. + + Nothing he authored is being unwound. His commits, the pull requests he + merged, the release-note attributions, and the code comments citing his + reviews stay exactly as they are, and the trust-lane gate derived from his + work in `.github/scripts/pr-sponsored-surface.cjs` keeps its attribution. + Returning to the maintainer table later would go through the same three + requirements that govern every addition. + - 2026-07-27 — [@Wibias](https://github.com/Wibias) added as a maintainer. Requirement 1 (agreement from the project owner) is met: the owner requested the addition. **Requirement 2 (review by another current maintainer) was @@ -105,10 +132,10 @@ Adding or removing a maintainer requires: carried the addition (`a2693c02`, `dc3a4ade`, `02bbd47a`) landed on `dev` as direct owner pushes with no associated pull request, so no second maintainer reviewed them. Requirement 3 is met by this file and `.github/CODEOWNERS`. - The addition is in effect regardless: @Wibias holds write access on the - repository and has been merging pull requests since 2026-07-26. This entry - records the gap rather than papering over it — a later maintainer change - should go through a reviewed pull request. + The addition took effect regardless: @Wibias held write access on the + repository and merged pull requests from 2026-07-26 until he stepped down on + 2026-08-19. This entry records the gap rather than papering over it — a later + maintainer change should go through a reviewed pull request. Scope covers issue and pull-request triage, `dev` integration, and provider/CI maintenance. (This entry originally also described carrying From ab1b383bc1bb79adb06edb858b4ff14af5d2c39b Mon Sep 17 00:00:00 2001 From: luvs01 Date: Fri, 14 Aug 2026 12:49:03 +0900 Subject: [PATCH 2/2] fix(usage): bound incremental append reads --- src/usage/log.ts | 4 ++++ tests/api-usage.test.ts | 29 +++++++++++++++++++++++++++++ 2 files changed, 33 insertions(+) diff --git a/src/usage/log.ts b/src/usage/log.ts index a526d8ddf5..dd1a31b4c6 100644 --- a/src/usage/log.ts +++ b/src/usage/log.ts @@ -921,6 +921,10 @@ async function readUsageEntriesIncrementally( // A shrink means truncation or replacement-in-place; the retained rows may no // longer correspond to file contents, so refuse to extend them. if (size < retained.coveredThroughBytes) return null; + // Extending retained state is only an optimization; never let a large burst turn + // the bounded management read into an unbounded read of everything appended since + // the previous poll. A full read below will load only the requested tail window. + if (size - retained.coveredThroughBytes > maxReadBytes) return null; // Verify the retained REGION is unchanged before anything is reused. Identity keeps // dev/ino/birthtime, and an append and an in-place rewrite both move mtime/ctime // forward, so only the bytes themselves settle it. diff --git a/tests/api-usage.test.ts b/tests/api-usage.test.ts index 58a38a232b..f6db775c6b 100644 --- a/tests/api-usage.test.ts +++ b/tests/api-usage.test.ts @@ -578,6 +578,35 @@ describe("GET /api/usage", () => { } }); + test("an append burst larger than the byte window falls back to a bounded full read", async () => { + const now = Date.now(); + const maxReadBytes = 512; + const row = (id: string): string => `${JSON.stringify({ + requestId: id, + timestamp: now, + provider: "openai", + model: "gpt-5.5", + status: 200, + durationMs: 1, + usageStatus: "reported", + usage: { inputTokens: 1, outputTokens: 1 }, + totalTokens: 2, + })}\n`; + const path = join(testDir, "usage.jsonl"); + writeFileSync(path, row("seed")); + + await usageLogModule.readUsageSnapshotForManagement(maxReadBytes); + const parsedBeforeBurst = usageReadCacheStatsForTests().parsedLines; + appendFileSync(path, Array.from({ length: 100 }, (_, index) => row(`burst-${index}`)).join("")); + + const snapshot = await usageLogModule.readUsageSnapshotForManagement(maxReadBytes); + const stats = usageReadCacheStatsForTests(); + expect(stats.fullReads).toBe(2); + expect(stats.tailReads).toBe(0); + expect(stats.parsedLines - parsedBeforeBurst).toBe(snapshot.entries.length); + expect(snapshot.entries.length).toBeLessThan(100); + }); + test("appends to an over-window ledger stay incremental and bounded", async () => { const now = Date.now(); writeFixture(now);