Collector 0.7.42: Codex responses counted once at the source, busy-session summaries keep progress, bounded maintenance timing
Collector 0.7.42 counts each Codex response once at the source, keeps busy-session summaries moving, and bounds maintenance timing.
- Codex responses count once (
.163.95). codex-app-server reports each response twice: acodex.sse_eventlog and ahandle_responsesspan. 0.7.42 pairs the two in the local ledger before usage upload, so a response counts once. The span stays in the ledger as raw evidence and no longer counts as usage.- Pairing needs three indexes, built in a stopped-service step:
plimsoll lifecycle pairing-indexes --apply, run while the collector is stopped. Without--applythe command only reports whether the indexes are ready. - A new ledger gets the indexes when it is created. On an existing ledger the collector runs unpaired, as 0.7.41 did, until the step has run.
- On a copy of the largest fleet ledger (73 GB), the step took about 24 seconds.
- After a rollback to 0.7.41 and a later update, run the step again to refresh its historical cursor and target.
- Pairing needs three indexes, built in a stopped-service step:
- Busy-session summaries keep their progress (
.163.87). A summary rebuild keeps its progress while unread rows in the session change. A terminal receipt retarget advances the old session revision, so a 0.7.41 worker rejects stale data after a downgrade. - Possible capture losses stay visible (
.163.81). When a JSON discriminator probe saturates, the Codex and Claude tailers keep the skipped usage visible as a possible loss. A revisit queue resumes partial files without losing the capture claim gap. - Coverage walks page their saved cursors (
.163.82). A walk records a gap when a known partial file vanishes before its directory entry is reached. A file created and removed entirely between walks remains outside this claim. - Observe-only budget sampling (
.164.3).- The collector samples ledger size, process memory and CPU, outbox age and summary lag.
plimsoll statusand the CSV export show advisory targets and local history. No capture budget is enforced.- Purging a stopped collector also removes the ledger's WAL and SHM files.
- Bounded HTTP deadlines and maintenance timing (
.163.83). Proofs now cover file-backed status probes, the maintenance deadline-to-reap and absolute hook latency. The runtime keeps its bounded HTTP request behavior.
Updating and rolling back:
- Rollback to 0.7.41 is supported. 0.7.41 runs on a ledger that 0.7.42 has used, including 0.7.42's replaced dashboard and session-summary triggers. An explicit rollback keeps the live ledger.
- Nothing is received while the collector is stopped. During an update, hook posts and OTLP exports are not recorded. Token usage in session files is captured again after the restart. In managed update windows the stop has lasted 1 to 7 seconds. The first 0.7.42 update also includes the one-time pairing index build, about 24 seconds on the largest ledger.
- Keep-all retention works as before. Updates and rollbacks with
--retention keep-allbehave as in earlier releases.
Runtime CLI SHA256: 9c80da7cc66570deef7706c75efbda0f7dbb27c09bdec5c89ebb2e5fcfb83229.
Qualification: typecheck, the proof suite and system end-to-end qualification ran on the merged commit. The published package is the qualified artifact from that run.