You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[P2.71] Daily spend limit reads tenant-writable data: move it to a server-side ledger #1344
Spun off from PR #1343 (issue #1303) during post-merge disposition.
Context
CODEFRAME_USER_DAILY_COST_LIMIT_USD (codeframe/core/spend_limit.py) sums today's token_usage from each workspace's .codeframe/state.db. Agent code running in that workspace can write the file, so a tenant can delete rows, or the DB, and lower its own meter. Three related approximations from the same design:
Attribution is by workspace (workspace_spend_users), not by caller, so a shared workspace counts in full toward each user who ran in it. This fails closed, but it is inexact.
Gated (needs-owner): this needs an OS-level isolation decision (bubblewrap vs. a separate uid vs. a container per run) that the owner chose to defer on 2026-10-02 in favour of the P1 launch blockers. Hosted execution is already refused (#1266), so this only matters once hosted mode launches.
Priority 7 of 7. Deferred, together with #1322: it needs the same isolation decision, so make that choice on #1322 and nothing more here, with one extra sub-decision.
When hosted mode is scheduled:
1. Make the #1322 decision (isolation model). See that issue's steps.
2. Decide how in-flight spend holds behave with several server workers.
Refuse to start multi-worker while CODEFRAME_USER_DAILY_COST_LIMIT_USD is set. Recommended: simplest, no new infrastructure.
3. The agent then moves spend to a server-side ledger in the control-plane DB, keyed by principal. Its acceptance test: deleting a workspace's state.db no longer lowers the meter. You approve the PR.
Relabelled needs-owner → Future (owner, 2026-10-06). It stays deferred until hosted mode is scheduled; hosted execution is refused until then (#1266). The isolation-model decision steps above still apply when it's picked up.
Spun off from PR #1343 (issue #1303) during post-merge disposition.
Context
CODEFRAME_USER_DAILY_COST_LIMIT_USD(codeframe/core/spend_limit.py) sums today'stoken_usagefrom each workspace's.codeframe/state.db. Agent code running in that workspace can write the file, so a tenant can delete rows, or the DB, and lower its own meter. Three related approximations from the same design:workspace_spend_users), not by caller, so a shared workspace counts in full toward each user who ran in it. This fails closed, but it is inexact.token_usage.Why it was not done in that PR
It needs its own design: a ledger the server owns and children cannot write. That is the same prerequisite as hosted execution (#1266, #1322).
Definition of done
spend_today_usdreads that ledger; deleting a workspace'sstate.dbno longer lowers the meter (test).