Skip to content

fix(antigravity): read usage from each instance data directory - #17769

Open
fixfon wants to merge 1 commit into
pingdotgg:mainfrom
fixfon:fix/antigravity-instance-usage-roots
Open

fixfon wants to merge 1 commit into
pingdotgg:mainfrom
fixfon:fix/antigravity-instance-usage-roots

Conversation

@fixfon

@fixfon fixfon commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Problem

Antigravity usage scans receive the configured provider instances but resolved ANTIGRAVITY_DATA_DIR from the host environment once. An Antigravity instance configured with its own ANTIGRAVITY_DATA_DIR had its history omitted.

Change

Resolve the data roots from each instance's already merged environment. The implicit default instance still carries the host environment, so the host override and the built-in defaults keep working. The existing canonical conversation-directory set still counts shared and aliased roots once. T3-managed profile directories are unchanged.

Refs #17631.

Scope and approval

#17631 was filed by maintainer Julius for the same gap in OpenCode and notes that "Antigravity and Cursor are worth checking for the same gap." The OpenCode fix is #17759. This PR is the Antigravity half only, kept separate under the one-problem rule.

Cursor is not included. Its usage reader reads one account per environment from the host's Cursor CLI login by design (packages/provider-cursor/src/server/driver.ts, "One account source per environment"), so per-instance accounts would be a product change rather than the same bug.

Verification

macOS, Node 25.9.0; temporary directories, no live provider history.

  • New regression in UsageService.test.ts: two configured Antigravity instances with distinct ANTIGRAVITY_DATA_DIR values (one with surrounding whitespace and an empty comma entry). Before the fix it fails: the scan reports three sources (host root plus two profile directories) and neither instance directory. After the fix both instance directories are scanned.
  • vp test run apps/server/src/usage/UsageService.test.ts apps/server/src/provider/Drivers/antigravityUsageReader.test.ts apps/server/src/provider/Drivers/AntigravityDriver.test.ts: 51 passed. The existing aliased-root test (ANTIGRAVITY_DATA_DIR on the host with two aliases) still counts one source.
  • tsc --noEmit -p apps/server/tsconfig.json: no errors. Scoped vp lint and vp fmt --check on the two changed files passed. git diff --check passed.

Windows was not executed.

Implemented with Claude Opus 5.5 through Claude Code in T3 Code.

🤖 Generated with Claude Code

Antigravity usage scans resolved ANTIGRAVITY_DATA_DIR from the host
environment only, so an instance configured with its own data directory
had its history omitted. Resolve the data roots from each instance's
merged environment; the existing canonical directory set still counts
shared and aliased roots once.

Refs pingdotgg#17631.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Oct 10, 2026
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 10, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This change alters production usage scanning by making per-instance data-directory configuration determine which history databases are traversed and aggregated. The scope is focused and tested, but the configuration-driven processing change warrants human review.

Notes:

  • Diff unchanged. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2e8c77f6-cdf2-4068-a27f-05f143ae727c

📥 Commits

Reviewing files that changed from the base of the PR and between bd2346e and a977b9e.


📒 Files selected for processing (2)
  • apps/server/src/provider/Drivers/AntigravityUsage.ts
  • apps/server/src/usage/UsageService.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 5 remain after this review.



📝 Walkthrough

Walkthrough

Antigravity scanning now derives data roots from each instance’s environment and combines those roots before adding profile roots. An integration test checks separate configured directories, including a value with surrounding whitespace and commas.

Changes

Antigravity data roots

Layer / File(s) Summary
Per-instance root collection
apps/server/src/provider/Drivers/AntigravityUsage.ts, apps/server/src/usage/UsageService.test.ts
dataRoots reads ANTIGRAVITY_DATA_DIR from each instance’s environment. scan collects roots for all supplied instances and continues to add profile roots. The integration test checks two resolved source directories, including a value padded with whitespace and commas.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: juliusmarminge


Merge Risk | ⚪ Minimal · up to a977b

Merge Risk: ⚪ Minimal · up to a977b

Antigravity scans now include configured instance data directories. No actionable merge-blocking risk is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a977b

Provider-instance settings can now select additional Antigravity history directories readable by the server. Existing authorization and read-only database access remain, and no security bypass was established. Directory ownership and isolation in shared deployments remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — A configured root is not restricted to an instance-owned profile directory. The reader recursively considers .db files beneath the selected conversation directory, subject to server filesystem permissions, skips nested symlinks, and opens databases read-only. Fixed queries decode Antigravity usage metadata rather than returning arbitrary database contents.

Trust Boundaries and Controls

  • observed — Provider-instance map updates and atomic mutations require providers:manage. Usage-summary reads require diagnostics:read. Environment names are validated, but values remain strings without directory-ownership validation; canonicalization is an identity control, not an access-control boundary.
  • observed — Configuration-selected filesystem history roots predate this PR: Codex accepts CODEX_HOME under its configuration conditions, and Claude accepts a configured home or CLAUDE_CONFIG_DIR. These unchanged paths are counterevidence against treating provider-manager path selection itself as a newly introduced privilege boundary failure.

Resilience and Maintainability Implications

  • observed — Concurrent identical requests share a scan keyed by settings and window. Scan enrollment is uninterruptible, departing callers do not cancel the detached scan, and terminal success or failure removes the in-flight entry and completes its waiters. Each response publishes the directories selected by its settings snapshot, limiting stale-source reuse across configuration changes.

Pre-merge checks | Passed 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description check Passed The description includes the required Problem, Change, Scope and approval, and Verification sections. It explains the bug, the implementation, the issue reference, test coverage, passed checks, and th…
Title check Passed The title clearly and concisely describes the primary change: reading Antigravity usage from each instance's data directory.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 11, 2026 — with ChatGPT Codex Connector
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 11, 2026 06:20

Dismissing prior approval to re-evaluate a977b9e

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants