The footer was rebuilt on a real ledger two commits ago. The rest of the shell
was never audited the same way, and a multi-agent pass over it found the same
class of defect everywhere else:
- A sidebar card reading "Buzz · lumbridgecode / connected · signed identity"
in the success colour. lumbridge-buzz is not a dependency of this binary.
- A saved host "amd-server", and a WORKTREES section with five entries and a
working selector, backed by a lumbridge-git crate that does not exist.
- A first-run workspace of six panes announcing "Codex · runtime / metal ·
Tailscale SSH", "Claude Code · UI / MacBook Air · local" and a Pi pane on a
saved host. Every one of them was a /bin/sh, and the machine names were this
developer's.
- A declared "Pi · spark-1 · laguna-s-2.1" usage profile with no probe of any
kind behind it. Declaring a profile promises the gap is real; that one could
never be filled.
- FOOTER_CENTER = "Codex · ChatGPT subscription · 62% window remaining",
rendered by the Floem shell. Decision 0013 names that exact form as the thing
that must never be shown.
- The header's PTY count painted green unconditionally, so "0/5 LIVE PTYS" read
as success. runtime_rows already had the right rule three hundred lines away.
- A browser panel describing itself as "An isolated system-web-engine surface"
on the chooser screen where you pick it. There is no web engine in this build.
First run is now three real local shells, and a pane claims a harness when one
has actually been launched into it. The seed mapping stays for when that is
possible.
Also removes the only unsafe block in the shell: a test set LUMBRIDGE_*_PROBE
through the environment, which needs unsafe under edition 2024 and silently
disabled both probes for every other test in the binary. Replaced with
UsageFeedOptions passed to start_with.
Clippy pedantic on the spike goes 79 -> 15 against root CI's -D warnings, so
graduating it into the workspace is not gated on a warning cleanup. The four
remaining too_many_lines are the render split, which the sidebar work needs to
do anyway.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The footer showed invented percentages. It now shows what two harnesses
actually report, or says it does not know.
lumbridge-core gains an append-only per-profile UsageLedger and a projection
that labels every derived value estimated, withholds a burn rate from a single
sample, withholds a window fraction with no reported ceiling, withholds an
exhaustion estimate that lands after the reset, and reports an expired window
as rolled over rather than freezing its last percentage. A missing fact renders
as missing, never as zero. (0012)
lumbridge-harness is the impure side: processes, clocks, and untrusted wire
text in, observations out. Three adapters:
- Codex's account/rateLimits/read over the app-server's JSON-RPC stdio. The
client cannot express a request outside a two-variant enum and answers every
server-to-client request with -32601, so a harness asking Lumbridge for a
credential is refused by construction. (0013)
- Claude Code's session transcripts, as a byte-offset tail follower that
reports nothing until the backlog is read to EOF — a partially-read backlog
is indistinguishable from a burst of spend, and the first run against 20 MB
reported forty-six billion tokens an hour. The parser models four counters,
so the conversations in those files are not representable. (0014)
- Claude Code's five-hour and seven-day subscription windows, via a bridge
installed as its statusLine command. 0014 had claimed no such surface
existed; it does, and the record is corrected in place rather than quietly
edited. Lumbridge does not read the OAuth credential to call the account
usage endpoint, which is what comparable tools do — AGENTS.md forbids it,
and 0015 says so rather than leaving the gap unexplained.
Also in here: a capability-check ordering fix in the workspace reducer, where
the applied-request replay table was consulted before the capability check and
so answered questions the caller had no right to ask; the GPUI spike wired to
the live probes with per-harness gauges and provenance chips; and a launcher
that matches its own window by PID, because GPUI sets WM_NAME but not
_NET_WM_NAME and a title match never succeeded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>