codeburn/app
Resham Joshi 8e1caae33a
Some checks are pending
CI / semgrep (push) Waiting to run
sessions: fold subagent runs into PR attribution (#791)
* sessions: fold subagent runs into PR attribution

Sidechain (subagent) session cost never reached the by-PR view, so a
session orchestrated on one model with subagent lanes on another showed
only the parent model on every PR row. Fold each sidechain's cost, calls,
models, and categories into the parent turn that spawned it, so it
inherits that turn's PR set under the existing turn-level state machine.

Linkage, in priority order: the spawn result's toolUseResult.agentId
pairs the child's agent id with the Agent/Task tool_use id that launched
it (recorded per turn), which is the true launch point and wins even when
the child's first activity landed during a later turn; else the child's
first-activity timestamp is bucketed into the containing turn span; else
the child folds into the parent's unattributed spend. Children of parents
that referenced no PR, and orphans whose parent is absent from the scan,
contribute nothing, unchanged.

Cache v6 to v7 (neither shipped, so one combined bump from v5): per-turn
spawnToolUseIds, per-file parentSessionId and agentSpawnLinks; the
validator and the append/compact paths thread them like prRefs. By-PR
footers now count parents plus folded subagent runs and the payload gains
an additive subagentSessions field. distinctCost now includes folded
subagent spend, documented in the payload comment.

* sessions: address adversarial review of subagent PR attribution

Rework child attribution to resolve each subagent to the PR its launching
turn was working on, using the parent's UNFILTERED turn data, and enforce
that every dollar is counted exactly once.

- Mutual exclusion: a child that referenced its own PR attributes
  standalone and is never folded; a child with no links is folded only.
  Fixes a double-charge where a self-linking child was both folded and
  self-attributed.
- Recursion: a fold aggregates a child plus its non-self-linking
  descendants (depth-first, cycle-guarded), so grandchildren spawned by
  subagents reach the PR report.
- Global linkage: the subagent index keys by parentSessionId alone
  (UUIDs are globally unique), so a child whose worktree resolves to a
  different project still links.
- Date-range correctness: spawn-to-PR sets are built at assembly from the
  full turn list, so a spawn in a pre-range turn attributes to the right
  PR; a PR-linked parent whose own turns fall out of range is kept as a
  0-cost fold anchor so its in-range child is not lost.
- Timestamp fallback compares epoch ms (mixed UTC offsets order right) and
  is end-bounded: a child active after the parent's last turn is unlinked
  (contributes nothing), matching orphan semantics.
- Cache adoption tries the newest prior versioned file (v6 then v5) so the
  preceding build's expired-PR history survives the v7 bump; an invariant
  note requires the list to cover every version that can exist on disk.
- Spawn-result pairing matches the tool_result block that carries the
  agentId, not the first block, when a record batches several results.
- resolveSubagentAttribution is computed once and shared by aggregateByPr
  and prLinkedTotals.

subagentSessions now counts folded subtrees (children plus descendants).
Verified on real data: attributed + unattributed reconciles to cost, and
parent-only cost plus folded-children cost equals the folded total to the
cent (no double-count).

* sessions: round-2 hardening of subagent PR attribution

Address a second adversarial review of the new machinery.

- ID collision: parents and a child's parent reference are keyed by
  provider + sessionId, not bare sessionId. When two distinct parents
  still share a key (true duplicate/imported data), the child folds into
  NEITHER (deterministic skip, stays standalone): correctness over
  coverage.
- Recursion dedup is global: one claimed-set spans all of a parent's
  direct children, so a descendant reachable through two paths (a diamond
  or duplicate id) folds exactly once and a parent-link cycle terminates.
- Cache adoption migrates every prior version oldest-to-newest and MERGES
  per source path (newer wins per entry), so a sparse or partial newer
  file no longer masks older-only expired-PR orphans.
- Fold anchors (0-cost PR-linked parents kept only for attribution) live
  in a new ProjectSummary.subagentAnchors, never in `sessions`, so they no
  longer contaminate session counts, averages, or any per-session report.
  Folded PR rows take their date span from the contributing child activity
  rather than the anchor's empty timestamps.
- One-pass buildPrAttribution computes rows and totals together; the
  payload builder and CLI call it once. Drops the identity-keyed
  memoization, which could return stale folds if the array was mutated.
- Ambiguous multi-block spawn-result pairing leaves the spawn link unset
  on purpose; the child then folds via the timestamp fallback rather than
  pairing with the wrong id or disappearing.

Every fix is mutation-verified. A fresh real-data drive re-proves the
no-double-count identity to the cent (parent-only cost plus folded cost
equals the folded total) and that the PR rows sum to attributedCost.

* sessions: round-3 hardening of subagent PR attribution

Third adversarial review pass.

- Ambiguity counts ALL candidate parents (and anchors) sharing a
  provider+sessionId key, not just PR-bearing ones, and uses a
  per-record fingerprint: a key carried by more than one DISTINCT record
  folds its child/subtree into NEITHER (identical duplicates still fold
  once). This unifies the parent-collision and duplicate-descendant rules
  and is deterministic across input order.
- Project-rebuilding filters (by day, by date range, by config source)
  now carry subagentAnchors through, and a date filter CONVERTS a spawn
  parent whose in-range turns are all filtered out into an anchor so a
  surviving in-range child still folds. Rebuilt sessions also keep their
  PR + subagent-linkage metadata (prLinks, parentSessionId, spawnPrSets,
  ...), which buildSessionSummary otherwise drops, so by-PR and folding
  work on a filtered slice (menubar/dashboard flow).
- Fold anchors leave ProjectSummary.sessions entirely and folded PR rows
  take their span from the child, so 0-cost anchors never touch session
  counts or averages.
- Ambiguous spawn pairing (parent named the agent but its exact launching
  tool_use could not be paired) is recorded per parent; a late child of
  such a pairing folds to the parent's last turn within a 30 minute grace
  window, else stays unlinked. A truly-absent pairing gets no grace.
- Row session key is NUL-delimited and provider-prefixed, so a project
  name or session id containing a space no longer collides and
  undercounts distinct sessions.

Every fix mutation-verified. A fresh real-data drive re-proves the
no-double-count identity to the cent, and a day-filtered drive proves the
filter fix end to end (anchors created, subagents fold, identity holds).

* sessions: round-4 hardening of subagent PR attribution

Fourth adversarial review pass.

- sessionFingerprint now covers the COMPLETE linkage-relevant payload,
  not just headline stats: a canonical (sorted-key) serialization of
  agentSpawnLinks, spawnPrSets, prRefsAtRangeStart, ambiguousSpawnAgentIds,
  parent/agent identity, and the per-turn prRefs timeline. Two records
  that share an id and headline stats but map the child to different
  spawns/PRs now fingerprint DISTINCT, so the ambiguity rule fires and
  they fold into neither, deterministically rather than order-dependent
  first-wins.
- A date/day filter recomputes prRefsAtRangeStart at the new slice
  boundary by replaying the original full turn sequence, instead of
  copying the wide range's value. A PR switch between the wide start and
  the slice start (July 1 A, July 10 B, slice July 20) now carries B, not
  a stale A; a turn exactly on the boundary stays in-slice and applies its
  own refs. The recompute selects by timestamp, so it is order-independent.
  Non-contiguous day selections are documented as treated contiguous from
  the earliest selected day (a single session-level seed cannot represent
  multiple segments; the menubar selection is a single day or a run).
- The anchor-carry path drops an anchor that duplicates a surviving
  session id, so malformed merged input cannot double-count.

Also: rebuilt filtered sessions were losing their PR/subagent-linkage
metadata (a child its parentSessionId, a parent its prLinks), which
carryLinkageFields now restores, so by-PR and folding work on any filtered
slice.

Every fix mutation-verified. A fresh real-data drive re-proves the
no-double-count identity and reconciliation to the cent for both a
lifetime scan and a day-filtered slice (anchors created, subagents fold
through the filter).

* sessions: round-5 hardening of subagent PR attribution

Fifth adversarial review pass; closed-form fixes.

- sessionFingerprint serializes the COMPLETE fold-determining state via a
  real recursive canonical encoder: session-level linkage AND, per turn in
  sequence, timestamp, prRefs, cost, calls, savings, and per-model cost.
  Object keys are sorted recursively and set-semantic arrays (PR-ref lists,
  ambiguous ids, spawnPrSets values) are sorted, while the turn list keeps
  order; the structure is emitted through JSON.stringify (no delimiter
  concatenation). Two same-id parents that differ only in a turn timestamp
  now fingerprint DISTINCT (fold neither), and records differing only in
  set-array order fingerprint EQUAL (no false ambiguity).
- recomputeRangeStartPrRefs breaks an exact-same-millisecond tie
  deterministically by the lexicographically-last sorted-ref key, so the
  recomputed seed is stable regardless of turn order.
- A day filter seeds EACH selected day's first ref-less turn by replaying
  the original full turn sequence up to that day's start (per-day seeding),
  so a PR switch on an UNSELECTED day between two selected days carries to
  the later day. Contiguous and non-contiguous selections are both correct.
- The anchor dedupe drops an anchor only when a surviving session shares
  the full provider-aware, fingerprint-qualified identity (a proven
  duplicate): a different-provider or different-record same-id session no
  longer wrongly drops the anchor.

Also fixed a double-count the fingerprint test exposed: two duplicate
parent sessions share a key and the SAME resolved children, so folding is
now done once per parent key.

Every fix mutation-verified. Fresh real-data drives (lifetime, single-day,
and a NON-CONTIGUOUS day selection) re-prove no-double-count and
reconciliation to the cent.

---------

Co-authored-by: reviewer <review@local>
2026-07-20 20:47:23 -07:00
..
build brand: restore binary 0101 flame across all surfaces 2026-07-17 14:14:40 -07:00
electron fix: Lifetime period end to end in the desktop app and menubar labels (#781) 2026-07-20 12:56:27 -07:00
renderer sessions: fold subagent runs into PR attribution (#791) 2026-07-20 20:47:23 -07:00
scripts fix(app): clean build stamp, splash without hash, About checks for updates 2026-07-17 14:30:00 -07:00
.gitignore feat(app): bundle the CLI inside the packaged app 2026-07-16 09:27:46 -07:00
DISTRIBUTION.md docs: desktop release flow + widened Linux build targets 2026-07-17 15:00:31 -07:00
package-lock.json release: 0.9.19 (#774) 2026-07-20 09:35:32 -07:00
package.json release: 0.9.19 (#774) 2026-07-20 09:35:32 -07:00
README.md feat(app): bundle the CLI inside the packaged app 2026-07-16 09:27:46 -07:00
tsconfig.electron.json feat(app): scaffold Electron+Vite package and codeburn CLI spawn 2026-07-10 15:16:55 -07:00
tsconfig.json fix(app): clean build stamp, splash without hash, About checks for updates 2026-07-17 14:30:00 -07:00
vite.config.ts fix(app): clean build stamp, splash without hash, About checks for updates 2026-07-17 14:30:00 -07:00
vitest.config.ts fix(app): clean build stamp, splash without hash, About checks for updates 2026-07-17 14:30:00 -07:00

CodeBurn Desktop

Electron desktop shell for CodeBurn's local-first usage views. M1 runs as a developer app and reads data by spawning the installed codeburn CLI; it does not run a daemon or HTTP server.

Development

npm --prefix app install
npm --prefix app run dev

Validation:

npm --prefix app run test
npm --prefix app run typecheck

CLI Dependency

Packaged builds ship their own version-matched copy of the codeburn CLI and require nothing installed — the app spawns the bundled CLI with Electron's own binary as Node (ELECTRON_RUN_AS_NODE). In development (Vite dev server) the app uses the repo's freshly-built CLI, and either can be overridden with CODEBURN_BIN or a persisted path file. See DISTRIBUTION.md for the bundling and resolution details. Electron resolves and spawns the CLI from the main process, then sends decoded JSON through the secure preload bridge into the renderer.

This follows the menubar pattern:

  • contextIsolation: true, nodeIntegration: false, and sandbox: true.
  • Renderer code calls window.codeburn only through app/renderer/lib/ipc.ts.
  • Main process handlers return JSON envelopes so structured CLI errors survive IPC.
  • Missing CLI, bad JSON, timeout, and nonzero exits are surfaced as honest UI states.
  • The renderer never imports CodeBurn engine code from src/; the data contract is spawn CLI, decode JSON, poll.

Data Contract

Current bridge calls:

  • Overview: codeburn status --format menubar-json --period <period> [--provider <provider>]
  • Plans: codeburn status --format json --period <period>
  • Models: codeburn models --format json --period <period> [--provider <provider>] [--by-task]
  • Optimize: codeburn yield --format json --period <period>
  • Spend flow: codeburn spend --format flow-json --period <period> [--provider <provider>]
  • Devices: codeburn devices --format json --period <period>
  • Device scan: codeburn devices scan --format json
  • Share status: codeburn share status --format json
  • Identity: codeburn identity --format json

Supported M1 periods are today, week, 30days, month, and all. Provider filtering is passed through where the CLI command supports it.

Sections

  • Overview: daily spend, spend stats, waste summary, and expensive sessions from menubar-json.
  • Spend: project/activity/tool/MCP/subagent lenses plus model-to-project flow.
  • Optimize: waste findings from menubar-json and reverted/abandoned yield data.
  • Models: model and task tables from models --format json.
  • Plans: plan pacing from status --format json.
  • Settings: device identity, nearby scan results, paired-device usage, and M2 visual affordances.

Packaging

npm run package produces an ad-hoc-signed macOS .dmg/.zip (arm64 and x64) via electron-builder, no paid Apple Developer account required. Packaging rebuilds the root CLI and bundles it into the app (Resources/cli), so installs need nothing on the target machine. See DISTRIBUTION.md for build instructions, the bundled-CLI mechanism, artifact locations, and the Gatekeeper first-open story.

M2 Backlog

  • Add Electron autoUpdater (the app already bundles its own version-matched CLI, so end-user installs need nothing on the machine; auto-update is the remaining piece).
  • Keep npm as a separate CLI-user channel at the same version as the desktop app.
  • Add macOS code signing with a paid Developer ID and notarization (ad-hoc packaging exists today; see DISTRIBUTION.md).
  • Add a codeburn desktop launcher subcommand.
  • Implement in-app pairing, approve, pull, and visibility mutations currently shown as M2 affordances.
  • Build the Models Compare sheet.
  • Add light theme support.
  • Expand codeburn optimize --format json with evidence and fix commands so Optimize can show richer actionable fixes.