Record ChatGPT's Pro reset times and meter Ego Chat's Pro usage #73

Merged
xicv merged 13 commits from feat/pro-limits-and-usage into main 2026-09-23 12:57:55 +00:00
xicv commented 2026-09-23 12:57:38 +00:00 (Migrated from github.com)

Summary

Two follow-ups to the "Pro only" policy from #70, plus the checkpoint schema rename planned in #71.

B. ChatGPT's own Pro reset times.

  • Under requirePro, the page reload before each Send makes ChatGPT fetch POST /backend-api/conversation/init. The driver drains the page's buffered events before the reload, reads the conversation/init response from the events after it, and fetches its body with Network.getResponseBody. It makes no request of its own.
  • It keeps only model_limits (slug and resets_after), the limit banner and blocked_features, validated in src/pro-limits.mjs. The result is recorded on the observation and persisted as the model-policy record's proLimits.
  • broker-status and ego-chat model-policy show proLimits. Each entry is marked expired once its time has passed.
  • The model_pro_fallback notification says when GPT-6 Pro returns. The pro_model_unavailable_before_send stop names the reset times.
  • The capture is bounded (1 s drain plus 4 s capture) and never stops a Send. A missing or unreadable response keeps the last known times.

C. An advisory Pro usage meter.

  • broker-status shows proUsage: Ego Chat's own answered Sends per answering-model family over rolling 24 hours and 7 days. The count comes from retained exchanges, so it is a lower bound; manual ChatGPT use is not counted.
  • One pro_usage_high notification (kind usage) fires when a counter crosses its warning threshold. The counters are GPT-6 Pro per week, GPT-5.6 Sol Pro per day and both together per day.
  • Defaults come from OpenAI's published Pro allowances: 200 per week, 170 per day and 200 per day, warning at 80%. model-policy.json can override them with allowances and usageWarningPercent. Nothing is enforced.
  • The warning fires from the exchange's completion commit, the commit that restart recovery re-drives. A broker stop between the answer and its completion therefore cannot lose it (Codex review finding, covered by a restart test).

D. Checkpoint schema. The broker publishes EgoSemanticCheckpoint.v1. Ego Monitor still reads the old EagleSemanticCheckpoint.v1.

Browser contract 33, runtime generation 2026-09-23.11.

Verification

  • npm test: 1408 tests, 1407 pass, 1 skipped. npm run test:ego-monitor: 148/148. Receipt suite 16/16. ESLint clean on the changed files. A3K fixture regenerated.
  • Codex review of the branch (read-only, --base 1e51747): one P2, the usage warning dispatched at the model-policy commit could be lost across a broker restart. Fixed by moving it to the completion commit, with a test that stops the store at that commit, restarts, and expects exactly one warning from the recovered exchange.
  • Codex review of the fix (read-only, --base b8c61bd): no actionable regression. Its sandbox could not create temporary directories, so it ran only the fixture checks; the suites above ran locally.
  • The capture technique was checked live and read-only on 2026-09-23 through the same runtime calls the driver uses. A same-URL reload produced exactly one conversation/init response, and its body held model_limits with GPT-6 Pro's reset time.

Known gaps

  • Adoption and restart recovery still repair without the Pro ladder.
  • The MCP tool descriptions do not mention proLimits or proUsage yet.
## Summary Two follow-ups to the "Pro only" policy from #70, plus the checkpoint schema rename planned in #71. **B. ChatGPT's own Pro reset times.** - Under `requirePro`, the page reload before each Send makes ChatGPT fetch `POST /backend-api/conversation/init`. The driver drains the page's buffered events before the reload, reads the `conversation/init` response from the events after it, and fetches its body with `Network.getResponseBody`. It makes no request of its own. - It keeps only `model_limits` (slug and `resets_after`), the limit banner and `blocked_features`, validated in `src/pro-limits.mjs`. The result is recorded on the observation and persisted as the model-policy record's `proLimits`. - `broker-status` and `ego-chat model-policy` show `proLimits`. Each entry is marked `expired` once its time has passed. - The `model_pro_fallback` notification says when GPT-6 Pro returns. The `pro_model_unavailable_before_send` stop names the reset times. - The capture is bounded (1 s drain plus 4 s capture) and never stops a Send. A missing or unreadable response keeps the last known times. **C. An advisory Pro usage meter.** - `broker-status` shows `proUsage`: Ego Chat's own answered Sends per answering-model family over rolling 24 hours and 7 days. The count comes from retained exchanges, so it is a lower bound; manual ChatGPT use is not counted. - One `pro_usage_high` notification (kind `usage`) fires when a counter crosses its warning threshold. The counters are GPT-6 Pro per week, GPT-5.6 Sol Pro per day and both together per day. - Defaults come from OpenAI's published Pro allowances: 200 per week, 170 per day and 200 per day, warning at 80%. `model-policy.json` can override them with `allowances` and `usageWarningPercent`. Nothing is enforced. - The warning fires from the exchange's completion commit, the commit that restart recovery re-drives. A broker stop between the answer and its completion therefore cannot lose it (Codex review finding, covered by a restart test). **D. Checkpoint schema.** The broker publishes `EgoSemanticCheckpoint.v1`. Ego Monitor still reads the old `EagleSemanticCheckpoint.v1`. Browser contract 33, runtime generation 2026-09-23.11. ## Verification - `npm test`: 1408 tests, 1407 pass, 1 skipped. `npm run test:ego-monitor`: 148/148. Receipt suite 16/16. ESLint clean on the changed files. A3K fixture regenerated. - Codex review of the branch (read-only, `--base 1e51747`): one P2, the usage warning dispatched at the model-policy commit could be lost across a broker restart. Fixed by moving it to the completion commit, with a test that stops the store at that commit, restarts, and expects exactly one warning from the recovered exchange. - Codex review of the fix (read-only, `--base b8c61bd`): no actionable regression. Its sandbox could not create temporary directories, so it ran only the fixture checks; the suites above ran locally. - The capture technique was checked live and read-only on 2026-09-23 through the same runtime calls the driver uses. A same-URL reload produced exactly one `conversation/init` response, and its body held `model_limits` with GPT-6 Pro's reset time. ## Known gaps - Adoption and restart recovery still repair without the Pro ladder. - The MCP tool descriptions do not mention `proLimits` or `proUsage` yet.
Sign in to join this conversation.
No description provided.