feat: implement issue #994 — [Phase 6] Weekly-budget glide-path breaker: pause at 100 − 2×days-until-reset of the 7-day Claude window - #1022
Conversation
…er: pause at 100 − 2×days-until-reset of the 7-day Claude window
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
Important Approval pendingCodeRabbit has no unresolved comments, but it has not reviewed the latest commit. Use the checkbox below to review the latest commit. CodeRabbit will approve the changes if it finds no blocking issues.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
There was a problem hiding this comment.
Code Review
This pull request implements a weekly-budget glide-path circuit breaker for the account-wide weekly_all window, introducing a time-varying threshold that rises as the weekly reset approaches. It adds several helper functions for config parsing, date arithmetic, and threshold calculation, integrates the new breaker into arl_admission_gate, and includes comprehensive BATS tests. Feedback on the changes suggests improving the robustness of arl_token_glide_enabled() by wrapping the nested jq path in a try operator to prevent fatal indexing errors if intermediate keys are missing, and initializing variables to avoid unbound-variable errors.
CodeAnt Nitpicks1 code suggestion1. The test name says 85% with five days left defers, but its comment and assertions correctly expect allow, making the test's stated boundary misleading.Inconsistent naming · |
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
|
CI checks on this PR are still running. Once they complete, re-mention Posted by the donpetry-bot PR-review cascade. |
1 similar comment
|
CI checks on this PR are still running. Once they complete, re-mention Posted by the donpetry-bot PR-review cascade. |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
|
|
CI checks on this PR are still running. Once they complete, re-mention Posted by the donpetry-bot PR-review cascade. |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 9c561cedd7602c357f6b6533b161a20bde96302b
Review mode: triage-approved (single reviewer)
Summary
Implements the Phase 6 weekly-budget glide-path breaker (#994): a time-varying threshold on the account-wide 7-day weekly_all window — clamp(ceiling_pct − reserve_pct_per_day × days_until_reset, floor_pct, ceiling_pct) — derived from telemetry resets_at with partial days rounded up. Reuses the Phase 5 telemetry adapter with a single shared fetch, extracts a shared transport-level 429/non-200 fail-safe (arl_token_transport_decision), and ships doubly inert (config weekly_all.enabled=false AND the AGENT_TOKEN_BUDGET_ENABLED env flag). 648 lines of new bats coverage plus config/docs updates. Triage cleared this as low-risk; on confirmation review the logic changes to the shared admission-gate library warrant MEDIUM, which still auto-approves.
Linked issue analysis
Closes #994. All acceptance criteria are substantively addressed: AC #1 (every schedule number read from config, degrades to allow when incomplete), AC #2 (days_until_reset from authoritative resets_at with ceiling division — verified for the 0..7 schedule and 12h/24h+1s partial-day boundaries), AC #3 (weekly_scoped at critical/100% cannot trip the fleet pause — pause_worthy scope guard tested), AC #4 (machine-readable trip reason JSON + shared arl_token_breaker_marker/needs-human-review label), AC #5 (fail-open on non-200, status 0, missing window, missing/unparseable resets_at; fresh 429 with future deadline blocks), AC #6/#7 (inert behind env flag + config arm; DRY_RUN reports the would-be defer but allows). The issue's motivating 85%-at-5-days probe scenario is asserted as a near-miss under the 90% Thursday threshold.
Findings
No blocking findings.
- Secret scan: the run_secret_scanning MCP tool is not available in this environment; the gitleaks CI check passed and no credential-like content appears in the diff.
- Behavior change (intentional, resolved thread): a 429 with retry_after but no deadline anchor (no retry_until/observed_at) now allows instead of deferring forever on a stale cached envelope — CodeAnt's critical finding, fixed with test coverage in both the session and glide suites.
- arl_token_budget_gate gained an optional envelope second parameter so the admission gate fetches telemetry exactly once for both breakers (asserted by a dedicated test); existing single-arg callers are unaffected.
- arl_token_iso_to_epoch rejects timezone-less timestamps and round-trips the date to reject normalised invalid calendar dates (Feb 30) — addresses the prior major finding.
- Non-blocking nit (already flagged by CodeAnt, not worth another cycle): the test name at tests/test_agent_rate_limit_weekly_glide.bats:298 says '85% with 5 days left defers' but the test correctly asserts allow; the in-test comment explains the near-miss intent.
- Workflow change is additive only (new test file in path filters and the bats invocation); no permission or action-pinning changes.
- All 4 inline review threads are resolved; gemini's jq-robustness feedback is addressed (guarded config path, try-style jq with defaults).
CI status
All checks green at 9c561ce: Agent Rate-Limits Tests (runs the new glide bats file), CI Lint/ShellCheck/Agent Security Scan/Secret scan (gitleaks), CodeQL (actions), SonarCloud quality gate passed (0 new issues, 0 hotspots), AgentShield, Compliance suites, dependency-audit (npm green, others skipped — no matching ecosystems), CodeRabbit status success. SKIPPED entries are conditional jobs (dependabot-automerge, ci-relay). 0.0% new-code coverage from Sonar is expected for shell/bats.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.



User description
Closes #994
Implemented by dev-lead agent. Please review.
CodeAnt-AI Description
Add a staged weekly budget glide-path breaker for agent dispatch
What Changed
weekly_all.enabledare enabled; dry-run mode reports a potential pause without blockingImpact
✅ Fewer weekly Claude budget overruns✅ Controlled agent dispatch near weekly reset✅ Safer rollout with fail-open telemetry degradation💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.