You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Track TokenBar's selective alignment with junhoyeo/tokscale without erasing TokenBar-specific streaming, cache, FFI, Swift, or Windows downstream semantics. This issue is the public exact ledger for the audited upstream range and the post-merge record for each selected milestone.
The goal is not a byte-for-byte re-vendor. An upstream behavior is aligned only when it survives TokenBar's actual scanner → parser → cache → streaming aggregation → FFI → Swift path, including every sibling-source, dedup, pre-aggregation, and stale-cache seam.
Audit boundary: The audited 111-row range is closed. No row in that historical ledger authorizes future runtime work. New upstream commits are reviewed in separately bounded ranges against the current public shared engine; a fresh audit does not select implementation or integration.
Outside the fixed 111-row audit; counts and cache format unchanged
Fresh upstream audit cutoff
e7293751 at 2026-08-11 04:29 UTC; latest release is v4.13.0, and the latest core-touching commit in this range is d8b23d1
Fresh bounded audit
Audited over 7e3552a7..e7293751: 175 upstream commits total, 76 touching crates/tokscale-core
Fresh audit scope
Existing-client correctness (Kimi, OpenCodeReview, Claude, Antigravity, Grok, and Copilot Desktop), pricing/reporting correctness, and Windows-native path handling require separately bounded review; new-client breadth and submit/CLI/CI/refactor-only work remain outside automatic adoption
Audit interpretation
The 175/76 counts measure upstream activity through the fixed cutoff, not a simple unported backlog: the public shared engine already selectively carries or adapts some post-range behavior, and no item is selected for implementation by this inventory update
Next pending graph
(none — the historical graph is closed; no runtime successor is implicitly authorized)
Preserved distinct embedded IDs and incompatible same-ID SQLite rows while collapsing only fingerprint-compatible forks.
Authority and dedup
One selection authority serves materialized, shipping-streaming, and count paths.
Logical payload identity excludes cost. A cost-only overlap promotes provider-reported cost over an estimate.
Legacy JSON authority uses message ID plus creation timestamp, replaces one exact deferred SQLite identity, and retains provider-reported cost precedence.
Rows without a v1 embedded ID retain the row/file fallback as an alternate key; alias authority expands across connected components before streaming, preventing database order from reopening a legacy fallback.
Cache and evidence
Schema 29 → 30: a same-fingerprint hybrid database may already contain a non-empty schema-29 v1-only cache entry.
Hermetic coverage rejects and rebuilds that entry to v1+v2, then proves warm materialized, shipping-streaming, count, model, monthly, hourly, and Agents parity.
Final review head: d3ffbb1559b21f3eb864d6e327cd79306fb10270.
M15-B — Kiro structured sessions
Selected scope
Ported upstream 405ded4a / PR #836, 315549b4 / PR #847, and only the Kiro start-anchor hunk of mixed b64d861e.
Discovery is limited to ~/.kiro/sessions/<workspace>/sess_*/session.json; sibling messages.jsonl is a parser dependency.
Parser behavior
Structured turns estimate input from contextUsage.usagePercentage × 200,000, estimate output from assistant text plus tool-call arguments, preserve duration/model/workspace, and back-anchor a missing prompt timestamp from turn_end - elapsedTime.
Older flat role/content JSONL remains an aggregated fallback.
New IDE rows fall back to model auto; existing Kiro CLI and SQLite rows retain unknown.
Cache and evidence
One kiro_related_messages_path() seam feeds specialized fingerprints, materialized and shipping-streaming cache lanes, latest-mtime observation, and sibling-aware fail-open pruning.
Schema remains 30.
Fixtures cover absent-to-created and sibling-only rewrites, warm rebuild, modified_after, M15-A/M15-B coexistence, and every report lane.
Final review head: 8001efb452d80fc74fad2f87ca1a2b0bd92a3eac.
M16 — existing-parser correctness
Selected scope
Ported 6899ea03 / PR #896, b59979c5 / PR #892, 9155018c / PR #890, 18cd13cc / PR #891, the provider-hardening hunks of mixed 34cfbb50 / PR #887, and the Jcode start-anchor hunk of mixed b64d861e / PR #898.
The 9Router bridge, scanner, registry, pricing, scripts, and service integration remain excluded.
Correctness changes
Codex keeps legacy UUID-v4 ancestor replays behind the child boundary, accepts numeric task_started.started_at, and start-anchors token snapshots.
Bare Claude transcript files suppress character-estimated tool-result usage while preserving explicit tokens and project-scoped estimation.
Claude and Copilot duplicate records retain per-field maxima, earliest start, and non-additive maximum duration; Copilot prefers OTEL startTime and back-anchors end-only records.
Jcode back-calculates explicit completion timestamps from positive tool_duration_ms.
Missing GJC/Pi providers are inferred from model identity; delimited Kimi/MiMo/GLM identities normalize to moonshotai / xiaomi / zai; Antigravity aliases reach priced canonical models without merging Low/Medium tiers.
Cache and evidence
Schema 30 → 31.
A same-fingerprint schema-30 Jcode fixture proves rejection, rebuilt anchoring, warm stability, all-lane parity, and report parity.
Final review head: 47a8491068fdc837fdd62364044ee1114cc66b97.
M19-A — Windows atomic replacement retry
Ported only the fs_atomic.rs Windows hunk from upstream a87f0ab6 / PR #906; upstream TUI signal and background-screen changes remain excluded.
MoveFileExW(MOVEFILE_REPLACE_EXISTING | MOVEFILE_WRITE_THROUGH) retries only ERROR_ACCESS_DENIED (5) and ERROR_SHARING_VIOLATION (32), stops after five total attempts, and uses 10/20/30/40 ms backoff.
Other Windows errors and non-Windows std::fs::rename remain single-attempt.
Five deterministic tests cover both retryable codes, success, terminal failure, immediate non-transient failure, and exact attempt/backoff order.
Schema remains 31. Final review head: 6b2fc0f01a85db99ff00b21e0b587ddfa70cfd1f.
M17 — Grok unified-log precedence
Source authority
Selectively ported non-main ed798642 / upstream issue #849 without replacing TokenBar's hardened legacy parser or report pipeline.
Discovery accepts only exact top-level logs/unified.jsonl sources beside primary and inferred Grok homes, canonical-deduplicates physical overlap, and excludes archive/backup copies.
Raw unified and legacy sources keep independent cache entries; one session authority selector suppresses only legacy rows covered by unified sessions before materialized, shipping-streaming, count, and report folds.
Legacy-only sessions remain available. Exact replays collapse without dropping distinct same-base token rows; model/workspace metadata is borrowed only when unique and non-conflicting.
Pricing occurs after selection so carried models cannot retain a pre-selection grok-unknown zero cost.
Cache and lifecycle
Schema remains 31.
Specialized identities include legacy signals.json, summary.json, and events.jsonl siblings.
A topology-sensitive source-change token invalidates graph and live-tail caches when unified sources are created, rewritten, or removed even if the maximum source mtime does not change.
Lifecycle fixtures cover source creation/removal, stale cache recovery, model switches, malformed tokens, PID reuse, zero-message tool loops, configured roots, cost parity, and every report lane.
Review closure
Corrected four integration defects from the first Codex pass; rejected within-session partial merging because cumulative legacy deltas and unified inference rows have no stable shared identity.
Corrected coarse replay identity, stale cache-hit dates, and lost parser message counts; fresh verification then exposed and closed an adjacent reasoning-token omission.
Added unique, consistent legacy-model carry-over while leaving conflicts fail-closed.
Moved pricing after model carry-over and expanded configured-root unified discovery.
Added terminal GPT identity, generic configured-root inference, and cache-read clamping.
Preserved explicit zero-message loops, handled missing loop indexes, and cleared PID authority at process restarts while retaining pidless session authority.
Final review head: d4e825bb33f14ed1522f70bc7380bf58f1f99c79. Live smoke exited 0; mutable-source drift diagnostics are not used as parity evidence, which comes from hermetic cold/warm fixtures.
M18 — Sakana/Fugu and routed pricing
Selected scope
Ported audited 959cce84 and 6c804711, plus request-level long-context semantics from non-main 548dc124 and routed prefix/suffix composition from non-main 6ea27ca1.
Verified LiteLLM GPT-5.4/GPT-5.5 identities use the same request-level threshold with their own catalog tiers.
Output and reasoning follow the selected tier; cache-write does not select the tier; bare fugu remains intentionally unpriced.
Routed lookup invariants
Preserve exact raw/custom and parenthesized first refusal, provider-scoped fail-closed behavior, bounded full-path before terminal fallback, case-insensitive forced-source isolation, provider ranking, cache-rate backfill, and one Claude never-degrade guard across every fallback.
Final review head: 41652249131d5569463e9f68ed741aa1e2d1d7b8.
M21 — Kimi Code, Junie, and OpenCodeReview
Selected scope
Client
Audited source
Kimi Code
839ce378, 052f43de
Junie
633ea946, 77948d9d, plus the Junie hunk of b64d861e
OpenCodeReview
302d39c3, plus the matching hunk of b64d861e
Integration behavior
Kimi Code reuses kimi, dispatches by agents/<agent>/wire.jsonl, honors KIMI_CODE_HOME only with environment roots, isolates legacy Kimi's config.json dependency, and collapses exact replays without dropping distinct turns.
Junie preserves finite non-negative provider-reported cost, consumes prompt ownership on the next response even when usage is missing, and start-anchors explicit duration.
OpenCodeReview carries workspace/duration metadata, includes recorded end timestamps in replay identity, and saturates oversized unsigned token values.
Materialized, shipping-streaming, count, and all report paths share parser dispatch and dedup semantics; raw source messages are cached before pricing.
Junie and OpenCodeReview append IDs 31 and 32; Swift uses verified display metadata and the existing initial-letter fallback.
Final review head: 9677224dee48fde428dbd0d8231043c3f63112fe.
M23 replacements — Hermes Windows and Copilot Desktop
Split decision
PR feat(vendor): add Copilot Desktop, VS Code chatSessions, and Hermes Windows roots #74 combined Hermes Windows roots, Copilot Desktop, and VS Code chatSessions across 18 commits and 14 review rounds. Continued review still exposed agent attribution, billed-credit, model-classification, ObjectMutationLog, and authority defects, while Copilot production drift reached about 3.1× the selected upstream implementation.
Rebuilt the fixed ~/.copilot/data.db token source from upstream f6f7eced + 0b454e60, preserving sessions.agent, input-minus-cache normalization, fractional timestamps, and event model/workspace enrichment while excluding AIU-only rows and provider-reported cost.
One raw UnifiedMessage selector gives OTEL whole-session authority before pricing, client/date filters, sessionization, and every report fold across materialized, shipping-streaming, and count consumers.
Strict DB, optional WAL, and sorted event dependencies drive raw-cache fingerprints, source change tokens, latest mtime, and fail-open modified-after pruning. Read or metadata failures bypass cache reuse and retain the Desktop source plus the full OTEL suppressor cohort.
AIU/credits, custom Copilot roots, extra VS Code families, ±2s matching, and a second authority engine are not part of the shipped replacements.
Counting rules
Each audited commit appears in exactly one category. The category represents the highest remaining action for the whole row; mixed commits stay one row while TokenBar selectively lands their approved hunks.
Classification
Meaning
ALREADY_VENDORED
The relevant behavior is present in TokenBar main, including verified selective ports or local equivalents
TAKE
At least one approved hunk remains to be implemented
ADAPT_FOR_STREAMING
The upstream behavior is required but still needs a separately classified streaming/cache adaptation
DEFER
Only product-deferred or intentionally postponed behavior remains
SKIP
No TokenBar implementation is intended for the audited scope
SUPERSEDED
A later design replaces the row while its regression semantics remain covered
The ledger must always satisfy all of the following: the audited range contains exactly 111 commits; every hash appears once; the duplicate set is empty; and both symmetric differences between the range and the classification union are empty.
Current inventory
Classification
Count
ALREADY_VENDORED
79
TAKE
0
ADAPT_FOR_STREAMING
0
DEFER
18
SKIP
13
SUPERSEDED
1
Total
111
The prior 50/0/0/35/13/1 99-commit checkpoint is retired. M21 merged at 74/13/0/10/13/1; the Zcode fidelity decision produced 74/8/0/15/13/1; M25 produced 75/7/0/15/13/1; M23-H and M23-D produced 78/3/0/16/13/1. M24 then moved 63a44d7c to DEFER without merging runtime code (78/2/0/17/13/1). M26-A moved ae36db5c to ALREADY_VENDORED (79/1/0/17/13/1), and M26-B moved the mixed cd07bf78 row to DEFER after taking only generic format-2 metadata (79/0/0/18/13/1). M19-BP, M19-BQ, PT0, and M19-B0 do not move audited rows.
Applied milestone
Ledger effect
M15-T
Established 59/29/0/9/13/1
M20
Moved 366ce643 from TAKE to ALREADY_VENDORED
M15-B
Moved 405ded4a and 315549b4 to ALREADY_VENDORED
M16
Moved 6899ea03 b59979c5 9155018c 18cd13cc to ALREADY_VENDORED; moved mixed 34cfbb50 to DEFER after taking only provider hardening
M19-A
Moved a87f0ab6 to ALREADY_VENDORED after taking only the Windows atomic-replacement hunk
M17
Used non-main ed798642 / upstream issue #849; counts unchanged
M18
Moved 959cce84 and 6c804711 to ALREADY_VENDORED; non-main semantic sources remain outside the ledger
M21
Moved 839ce378 052f43de 633ea946 77948d9d 302d39c3 to ALREADY_VENDORED
M25
Moved 9a5aeb65 to ALREADY_VENDORED
M22 evaluation
PR #72 closed unmerged; moved 640e97b9 f7a124da ed6f8b95 65f8f3e2 b64d861e from TAKE to DEFER as a product decision
M23-H
Moved c1aef5e9 to ALREADY_VENDORED; moved 074619f7 to DEFER after the PR #74 fidelity stop
M23-D
Moved f6f7eced 0b454e60 to ALREADY_VENDORED
M24 evaluation
PR #86 closed unmerged; moved 63a44d7c from TAKE to DEFER; no Warp runtime code landed
M26-A
Moved ae36db5c from TAKE to ALREADY_VENDORED
M26-B
Took generic format-2 metadata from cd07bf78; the remaining Devin scope moved the row from TAKE to DEFER
M19-BP / M19-BQ
Portable source-root and Claude version-probe canonicalization; counts unchanged
PT0
Provider transport, diagnostics, FFI publication ordering, and Swift scalar authority; outside the fixed 111-row audit
M19-B0
Native ownership of the cfg-gated Windows CNG/DACL/secure-open/identity/lock/replace/quarantine storage path; counts unchanged
Mixed b64d861e remains one DEFER row because only its Kiro, Jcode, Junie, and OpenCodeReview hunks are vendored while Zcode and Devin remain excluded.
The active source-message cache is format 2. Existing format-1 shards rebuild cold; the legacy schema-32 monolith remains unread, unmodified, and undeleted.
Product decision
The selected runtime cycle through M19-B0 is complete. The current product boundary is:
Group
Current decision
Existing parser correctness
OpenCode v2, Kiro structured sessions, Codex/Claude/Copilot/Jcode/provider/Antigravity fixes, Grok unified-log precedence, Hermes Windows discovery, and Copilot Desktop are merged
New local sources
Kimi Code, Junie, and OpenCodeReview are merged; Warp producer/local reporting is deferred after PR #86's fidelity stop
Money correctness
Sakana/Fugu pricing, request-level long-context evidence, and the routed-pricing precedence pipeline are merged with TokenBar-specific policy retained locally
Runtime configuration
Reloadable model aliases are merged for grouping only; raw model identity remains authoritative for pricing/cache/export
Cache architecture
Identity-aware format-2 shards are active; format-1 shards rebuild cold and the legacy schema-32 monolith remains inert
Provider transport
PT0 is merged outside the 111-row ledger: account-bound last-good, target-bound refresh write-back, bounded diagnostics, FFI publication generations, and shared Swift scalar/presentation authority
Windows parity
M19-BP, M19-BQ, M19-B0, M19-B1 exact Native-to-Windows sync, and D2 are complete. Native owns the cfg-gated Windows secure-storage implementation; there is no implicitly authorized runtime successor
The following feature groups remain DEFER: Zcode legacy/v2; Copilot VS Code chatSessions; Warp producer/local reporting; Command Code; CodeBuddy/WorkBuddy; Devin CLI/Desktop; and 9Router. Zcode and Warp each crossed the fidelity threshold in closed-unmerged runtime PRs. Copilot VS Code remains deferred until ObjectMutationLog replay plus model, agent, and cost authority have a reliable upstream format contract. Sakana subscription billing-console scraping (c634d1a5, #745) remains SKIP; selecting Fugu model pricing does not select the subscription usage provider.
Mixed-commit accounting
Commit
Selected work
Remaining work
Transition
34cfbb50
Provider hardening landed in M16
9Router
DEFER; only the excluded 9Router scope remains
b64d861e
Kiro landed in M15-B, Jcode in M16, and Junie/OpenCodeReview in M21
Zcode and Devin
DEFER; PR #72 closed unmerged and both remaining scopes wait for upstream convergence
c1aef5e9
Hermes Windows discovery landed in M23-H; macOS profile discovery was already present
Main shard architecture in M26; selected Claude dependency hunks are already present
None
TAKE → ALREADY_VENDORED after M26
cd07bf78
Generic CACHE_FORMAT_VERSION = 2 and related-file path/exists metadata in M26
Devin parser/discovery
TAKE → DEFER after M26
ae36db5c alone ends at cache format 1. The selected M26 format-2 contract therefore depends on the generic cache hunks from cd07bf78; the Devin-specific hunks remain excluded.
flowchart TD
H[M23-H Hermes Windows — PR #82] --> D[M23-D Copilot Desktop — PR #83]
D --> D0[D0 replacement checkpoint — PR #84]
D0 --> U1[U1 upstream contribution checkpoint — PR #85]
U1 --> F[M24 fidelity stop — PR #86 closed / PR #87 docs]
F --> A[M26-A format-1 shards — PR #90]
A --> B[M26-B format-2 metadata — PR #91]
B --> P[M19-BP portable roots — PR #92]
P --> Q[M19-BQ Claude probe — PR #93]
Q --> T[PT0 provider transport — PR #94]
T --> S[M19-B0 secure storage — PR #99]
S --> W[M19-B1 exact Windows sync — complete]
W --> Z[D2 final docs checkpoint — complete]
D -. fidelity defer .-> V[M23-V VS Code chatSessions]
D0 -. fidelity evidence .-> X[M22 Zcode — PR #72 closed]
F -. runtime deferred .-> R[M24 Warp]
Loading
M26-A, M26-B, M19-BP, M19-BQ, PT0, M19-B0, M19-B1, and D2 are complete. M24 is a completed fidelity stop, not a cache dependency and not a shipped runtime source. M22 Zcode, M23-V Copilot VS Code, and M24 Warp remain deferred. The exact ledger is terminal at 79/0/0/18/13/1; PT0, M19-B0, M19-B1, and D2 are outside that inventory. The historical execution graph is closed, and future upstream reviews start from separately declared bounded ranges against the current public shared engine rather than extending the 111-row denominator.
The terminal exact ledger is ALREADY_VENDORED 79, TAKE 0, ADAPT_FOR_STREAMING 0, DEFER 18, SKIP 13, and SUPERSEDED 1, total 111. Every future update must apply transitions to the actual previous six sets and regenerate the count, duplicate set, union, and both symmetric differences rather than trusting a planned intermediate value.
Fidelity audit
The audit separates upstream semantic fidelity from TokenBar's unavoidable streaming/cache/FFI integration. Churn ratio is a size signal, not a correctness score.
Milestone
Production size versus selected upstream
Assessment
M20 OpenCode v2
2.76x churn
High adaptation, but the parser port remains close to upstream; most growth is one TokenBar cross-store/streaming authority seam. Keep merged and freeze scope.
M15-B Kiro structured
0.76–0.86x
Faithful selective port that reuses existing TokenBar cache/scanner seams.
M16 parser correctness
About 1.06x parser additions overall
Faithful except for localized Copilot duplicate-span hardening; the narrow gaps were reported through upstream #938/#939 and #942/#943.
M17 Grok unified
4.26x churn
Grandfathered high-drift milestone. Keep issue #849 as evidence and do not expand locally without a new contract.
M18 routed pricing
2.78x churn
High local product-policy adaptation. Keep TokenBar's complete pricing precedence and safety rules local.
M21 new sources
1.056x production; 99.8% parser net parity
Faithful; added code is the bounded TokenBar streaming/cache/count/report seam.
M19-A Windows atomic retry
1.91x net production
Runtime behavior is faithful; extra code is deterministic testability and downstream portability.
M22 Zcode
2.1–2.5x production; 3.1–3.5x total
Failed the adoption threshold; PR #72 is closed unmerged and the scope is DEFER.
M25 aliases
Small upstream map + reloadable invalidation seam
Intentional TokenBar adaptation; raw model identity and pricing remain unchanged.
M23-H Hermes Windows
Discovery-only bounded residual
Faithful reuse of the existing parser, plural consumers, dedup, WAL, mtime, and pruning seams.
M23-D Copilot Desktop
285 local parser lines versus 261 selected upstream lines (+9.2%)
Faithful bounded port plus one TokenBar raw authority seam and strict DB/WAL/event freshness.
M23-V VS Code
No shipped implementation
Deferred after PR #74 reached about 3.1x Copilot production drift without a reliable ObjectMutationLog/model/agent/cost contract.
M24 Warp
No shipped implementation
PR #86 exposed repeated security/state-machine and cross-process ownership failures; the fidelity stop moved 63a44d7c to DEFER.
M26-A / M26-B
Selective format-1 then format-2 cache adoption
Upstream shard serialization and generic dependency metadata are retained; TokenBar-specific streaming lanes, parser dependencies, raw authority, and legacy-monolith isolation remain local adaptations.
M19-BP / M19-BQ
Outside the 111-row ledger
Portable FFI source-root and process-probe canonicalization required for the downstream Windows consumer.
PT0
Outside the 111-row ledger
TokenBar-owned provider transport, credential persistence, diagnostics, FFI publication ordering, and Swift scalar/presentation consistency; not an upstream tokscale bug claim.
M19-B0
Outside the 111-row ledger
TokenBar-owned cfg-gated Windows quota-storage security canonicalization; not an upstream tokscale bug claim.
Product quota meters and schema-32 turn_completed.usage; recorded separately from the audited range.
The adoption rule is explicit: preserve necessary TokenBar streaming/FFI seams, but stop when the core parser or authority requires repeated systemic repair, review keeps exposing new failure classes, or downstream invention exceeds the upstream feature. Do not continue because of sunk cost.
Current upstream reportability
The 2026-08-11 fresh upstream audit uses fixed cutoff e7293751 and covers 7e3552a7..e7293751: 175 upstream commits total, 76 touching crates/tokscale-core. Latest release at the cutoff is v4.13.0, and the latest core-touching commit is d8b23d1. Historical audit target 366ce643, range 0c820a5d..366ce643, and the fixed 111-row inventory remain unchanged. TokenBar main is 9e7741da, the reviewed shared-engine pin is 5b5f500d, and the exact ledger remains 79/0/0/18/13/1. The 175/76 counts measure upstream activity through this cutoff, not a simple unported backlog or implementation selection.
Classification
Candidate / outcome
Evidence and next action
FRESH_AUDIT
Existing-source candidates span Kimi, OpenCodeReview, Claude, Antigravity, Grok, Copilot Desktop, pricing/reporting, and Windows-native scan-root handling; new-source breadth includes Augment, Reasonix, Freebuff, Prime Agent, Senpi, and standalone Cline/Kimchi
Review each candidate family in a separately bounded range against shared-engine pin 5b5f500d. Submit-only, CLI, CI, docs, and refactor-only changes are not TokenBar runtime backlog; this row does not classify any commit as TAKE or authorize a pin advance
MERGED_UPSTREAM
Kimi #922 / #923 at 940c1cb5; Kimi #926 / #927 at 1c74ba4b; OpenCodeReview #928 / #929 at 8d0f887e; Copilot #938 / #939 at 1652852f; Copilot #942 / #943 at ff5e67ad
All are merged upstream. They remain outside the fixed 111-row audit unless an audited row already represents the same behavior; contributor merge was not performed locally.
Use issue-first for authority/identity contracts and narrow PRs only for isolated arithmetic or parsing defects. Deduplicate against already merged Kimi/OpenCodeReview work before filing.
Preserve closed-unmerged evidence and re-audit only after upstream or product contracts converge.
The canonical deduplicated reportability inventory is maintained in vendor/README.md; this issue mirrors its public status. A merged upstream PR is not automatically present in TokenBar's selected vendor tree, and an open upstream issue is not evidence that the corresponding TokenBar adaptation is upstream-ready.
Non-main semantic sources
The following sources are deliberately excluded from the 111-row count:
Never wholesale replace vendored files that contain TokenBar streaming, cache, FFI, pricing, or Windows adaptations.
A parser that reads a sibling, journal, history file, SQLite WAL, or metadata database must wire all four sites: fingerprint, active materialized/streaming lanes, latest-mtime probe, and sibling-aware pruning or fail-open behavior.
A serialized parser-output change requires an explicit TokenBar cache-schema decision and a same-fingerprint stale-cache regression.
Dedup and precedence must be selected once before report folds; do not stream one source and attempt to subtract it after pre-aggregation.
Raw model identity remains authoritative for pricing, cache, submit/export, and persistence; configurable aliases apply only at grouping surfaces.
New clients are incomplete until scanner, parser, cache identity, streaming/count/report lanes, FFI/Swift registry, settings, and UI identity agree.
Format-2 identity-aware shards own every active materialized, streaming, count, and report lane; no active lane writes the legacy monolith.
The final Windows sync starts from the merged Native source, classifies Windows-only residuals before copying, and stops if any residual is mixed or conflicting.
Verification and update protocol
Every selected runtime milestone must include an exact upstream diff review, hermetic old-fail/new-pass evidence, explicit cache/schema handling, materialized/streaming/count/report parity, applicable FFI/Swift checks, mandatory vendor/README.md and canonical-doc updates in the same PR, repository gates, fresh adversarial verification, clean GitHub review threads, and green CI.
After each milestone merges:
Record the actual PR and merge SHA.
Apply the exact ledger transition to the previous six sets.
Re-run the 111-row count, duplicate, union, and both symmetric-difference checks.
Record the active cache schema/format and the fixture/review evidence.
Update this issue with the actual next-ready dependencies; do not pre-label planned work as landed.
A milestone is complete only after both merge and this issue update succeed. The private Project tracks executable milestones only and must not duplicate the 111 commit rows. Tagging and release remain separate decisions.
Objective
Track TokenBar's selective alignment with
junhoyeo/tokscalewithout erasing TokenBar-specific streaming, cache, FFI, Swift, or Windows downstream semantics. This issue is the public exact ledger for the audited upstream range and the post-merge record for each selected milestone.Contents
Current checkpoint
9e7741da5b5f500d366ce6430c820a5d406241d85dc6c7fc65ac5a1ee026ccfd0c820a5d..366ce643 -- crates/tokscale-core79/0/0/18/13/1(empty)source-message-cache.binremains unread, unmodified, and undeleted1a8ee0c6; M23-D PR #83 merged atf99d9274; M23-V (074619f7) remainsDEFERe7293751at 2026-08-11 04:29 UTC; latest release isv4.13.0, and the latest core-touching commit in this range isd8b23d17e3552a7..e7293751: 175 upstream commits total, 76 touchingcrates/tokscale-core(none — the historical graph is closed; no runtime successor is implicitly authorized)Delivery history
a2f852ac59/29/0/9/13/11bc2fa7660/28/0/9/13/1CONFIRMED· CodexCLEAN· CI PASSf5773ea062/26/0/9/13/1CONFIRMED· CodexCLEAN· CI PASSaebbc37166/21/0/10/13/1CONFIRMED· CodexCLEAN· CI PASS11ae1bed67/20/0/10/13/1CONFIRMED· CodexCLEAN· CI PASSd4ff968b67/20/0/10/13/1CONFIRMED· CodexCLEAN· CI PASS0735fd2b69/18/0/10/13/1CONFIRMED· CodexCLEAN· CI PASS471a7f2374/13/0/10/13/1CONFIRMED· CodexCLEAN· CI PASSc41b864b74/8/0/15/13/1after the product reclassificationaa935d6e74/8/0/15/13/193d1583c75/7/0/15/13/1CONFIRMED· Codex+1· CI PASSturn_completed.usage(non-ledger)7b67bb20+1· CI PASS1a8ee0c676/5/0/16/13/1CONFIRMED· Codex+1· CI PASSf99d927478/3/0/16/13/1CONFIRMED· Codex+1· CI PASSchatSessions074619f7moved toDEFERfb3ecfeb15c0241b7dcb6985; docs PR #87 merged atee2946d978/2/0/17/13/195c819c779/1/0/17/13/1CONFIRMED· Codex+1· CI PASScc52c3b979/0/0/18/13/1CONFIRMED· Codex+1· CI PASS81d99ecdCONFIRMED· current-head review · CI PASSdf2fa096CONFIRMED· Codex+1· CI PASS346a58eeCONFIRMED· Codex+1· CI PASS · zero unresolved threadsf820b06fCONFIRMED· Codex+1· CI PASS · zero unresolved threads · equivalent Windows x64 runtime CI PASSM20 — OpenCode v2 SQLite
Selected scope
366ce643/ PR #920: v2session_messageassistant rows, nested model/provider resolution with v1 precedence, a shared v1/v2 accumulator, strict legacy JSON roles, workspace attribution, token clamps, and TokenBar cost/provider hardening.Authority and dedup
Cache and evidence
29 → 30: a same-fingerprint hybrid database may already contain a non-empty schema-29 v1-only cache entry.d3ffbb1559b21f3eb864d6e327cd79306fb10270.M15-B — Kiro structured sessions
Selected scope
405ded4a/ PR #836,315549b4/ PR #847, and only the Kiro start-anchor hunk of mixedb64d861e.~/.kiro/sessions/<workspace>/sess_*/session.json; siblingmessages.jsonlis a parser dependency.Parser behavior
contextUsage.usagePercentage × 200,000, estimate output from assistant text plus tool-call arguments, preserve duration/model/workspace, and back-anchor a missing prompt timestamp fromturn_end - elapsedTime.auto; existing Kiro CLI and SQLite rows retainunknown.Cache and evidence
kiro_related_messages_path()seam feeds specialized fingerprints, materialized and shipping-streaming cache lanes, latest-mtime observation, and sibling-aware fail-open pruning.modified_after, M15-A/M15-B coexistence, and every report lane.8001efb452d80fc74fad2f87ca1a2b0bd92a3eac.M16 — existing-parser correctness
Selected scope
6899ea03/ PR #896,b59979c5/ PR #892,9155018c/ PR #890,18cd13cc/ PR #891, the provider-hardening hunks of mixed34cfbb50/ PR #887, and the Jcode start-anchor hunk of mixedb64d861e/ PR #898.Correctness changes
task_started.started_at, and start-anchors token snapshots.startTimeand back-anchors end-only records.tool_duration_ms.moonshotai/xiaomi/zai; Antigravity aliases reach priced canonical models without merging Low/Medium tiers.Cache and evidence
30 → 31.47a8491068fdc837fdd62364044ee1114cc66b97.M19-A — Windows atomic replacement retry
fs_atomic.rsWindows hunk from upstreama87f0ab6/ PR #906; upstream TUI signal and background-screen changes remain excluded.MoveFileExW(MOVEFILE_REPLACE_EXISTING | MOVEFILE_WRITE_THROUGH)retries onlyERROR_ACCESS_DENIED(5) andERROR_SHARING_VIOLATION(32), stops after five total attempts, and uses 10/20/30/40 ms backoff.std::fs::renameremain single-attempt.6b2fc0f01a85db99ff00b21e0b587ddfa70cfd1f.M17 — Grok unified-log precedence
Source authority
ed798642/ upstream issue #849 without replacing TokenBar's hardened legacy parser or report pipeline.logs/unified.jsonlsources beside primary and inferred Grok homes, canonical-deduplicates physical overlap, and excludes archive/backup copies.grok-unknownzero cost.Cache and lifecycle
signals.json,summary.json, andevents.jsonlsiblings.Review closure
Final review head:
d4e825bb33f14ed1522f70bc7380bf58f1f99c79. Live smoke exited 0; mutable-source drift diagnostics are not used as parity evidence, which comes from hermetic cold/warm fixtures.M18 — Sakana/Fugu and routed pricing
Selected scope
959cce84and6c804711, plus request-level long-context semantics from non-main548dc124and routed prefix/suffix composition from non-main6ea27ca1.Pricing behavior
fugu-ultraregular rates: $5 input, $30 output, $0.50 cache-read per million tokens.fuguremains intentionally unpriced.Routed lookup invariants
41652249131d5569463e9f68ed741aa1e2d1d7b8.M21 — Kimi Code, Junie, and OpenCodeReview
Selected scope
839ce378,052f43de633ea946,77948d9d, plus the Junie hunk ofb64d861e302d39c3, plus the matching hunk ofb64d861eIntegration behavior
kimi, dispatches byagents/<agent>/wire.jsonl, honorsKIMI_CODE_HOMEonly with environment roots, isolates legacy Kimi'sconfig.jsondependency, and collapses exact replays without dropping distinct turns.Cache and evidence
9677224dee48fde428dbd0d8231043c3f63112fe.M23 replacements — Hermes Windows and Copilot Desktop
Split decision
chatSessionsacross 18 commits and 14 review rounds. Continued review still exposed agent attribution, billed-credit, model-classification, ObjectMutationLog, and authority defects, while Copilot production drift reached about 3.1× the selected upstream implementation.DEFERinstead of force-rewriting or cherry-picking the original branch.M23-H — PR #82
%LOCALAPPDATA%/hermesand supplied-homeAppData/Local/hermescandidates when explicitHERMES_HOMEis absent.c1aef5e9toALREADY_VENDORED; schema remained 32.M23-D — PR #83
~/.copilot/data.dbtoken source from upstreamf6f7eced + 0b454e60, preservingsessions.agent, input-minus-cache normalization, fractional timestamps, and event model/workspace enrichment while excluding AIU-only rows and provider-reported cost.UnifiedMessageselector gives OTEL whole-session authority before pricing, client/date filters, sessionization, and every report fold across materialized, shipping-streaming, and count consumers.0b454e60(+9.2%). Schema remains 32.Deferred scope
chatSessionscommit074619f7isDEFER: upstream and PR feat(vendor): add Copilot Desktop, VS Code chatSessions, and Hermes Windows roots #74 do not reliably replay ObjectMutationLogkind:2push/splice mutations, and bare-model, agent, and cost authority remain uncontracted.±2smatching, and a second authority engine are not part of the shipped replacements.Counting rules
Each audited commit appears in exactly one category. The category represents the highest remaining action for the whole row; mixed commits stay one row while TokenBar selectively lands their approved hunks.
ALREADY_VENDOREDTAKEADAPT_FOR_STREAMINGDEFERSKIPSUPERSEDEDThe ledger must always satisfy all of the following: the audited range contains exactly 111 commits; every hash appears once; the duplicate set is empty; and both symmetric differences between the range and the classification union are empty.
Current inventory
ALREADY_VENDOREDTAKEADAPT_FOR_STREAMINGDEFERSKIPSUPERSEDED59/29/0/9/13/1366ce643fromTAKEtoALREADY_VENDORED405ded4aand315549b4toALREADY_VENDORED6899ea03 b59979c5 9155018c 18cd13cctoALREADY_VENDORED; moved mixed34cfbb50toDEFERafter taking only provider hardeninga87f0ab6toALREADY_VENDOREDafter taking only the Windows atomic-replacement hunked798642/ upstream issue #849; counts unchanged959cce84and6c804711toALREADY_VENDORED; non-main semantic sources remain outside the ledger839ce378 052f43de 633ea946 77948d9d 302d39c3toALREADY_VENDORED9a5aeb65toALREADY_VENDORED640e97b9 f7a124da ed6f8b95 65f8f3e2 b64d861efromTAKEtoDEFERas a product decisionc1aef5e9toALREADY_VENDORED; moved074619f7toDEFERafter the PR #74 fidelity stopf6f7eced 0b454e60toALREADY_VENDORED63a44d7cfromTAKEtoDEFER; no Warp runtime code landedae36db5cfromTAKEtoALREADY_VENDOREDcd07bf78; the remaining Devin scope moved the row fromTAKEtoDEFERb64d861eremains oneDEFERrow because only its Kiro, Jcode, Junie, and OpenCodeReview hunks are vendored while Zcode and Devin remain excluded.Product decision
The selected runtime cycle through M19-B0 is complete. The current product boundary is:
The following feature groups remain
DEFER: Zcode legacy/v2; Copilot VS CodechatSessions; Warp producer/local reporting; Command Code; CodeBuddy/WorkBuddy; Devin CLI/Desktop; and 9Router. Zcode and Warp each crossed the fidelity threshold in closed-unmerged runtime PRs. Copilot VS Code remains deferred until ObjectMutationLog replay plus model, agent, and cost authority have a reliable upstream format contract. Sakana subscription billing-console scraping (c634d1a5, #745) remainsSKIP; selecting Fugu model pricing does not select the subscription usage provider.Mixed-commit accounting
34cfbb50DEFER; only the excluded 9Router scope remainsb64d861eDEFER; PR #72 closed unmerged and both remaining scopes wait for upstream convergencec1aef5e9TAKE → ALREADY_VENDOREDin PR #82ae36db5cTAKE → ALREADY_VENDOREDafter M26cd07bf78CACHE_FORMAT_VERSION = 2and related-filepath/existsmetadata in M26TAKE → DEFERafter M26ae36db5calone ends at cache format 1. The selected M26 format-2 contract therefore depends on the generic cache hunks fromcd07bf78; the Devin-specific hunks remain excluded.Exact 111-commit ledger
ALREADY_VENDORED — 79
TAKE — 0
ADAPT_FOR_STREAMING — 0
DEFER — 18
SKIP — 13
SUPERSEDED — 1
Execution graph
flowchart TD H[M23-H Hermes Windows — PR #82] --> D[M23-D Copilot Desktop — PR #83] D --> D0[D0 replacement checkpoint — PR #84] D0 --> U1[U1 upstream contribution checkpoint — PR #85] U1 --> F[M24 fidelity stop — PR #86 closed / PR #87 docs] F --> A[M26-A format-1 shards — PR #90] A --> B[M26-B format-2 metadata — PR #91] B --> P[M19-BP portable roots — PR #92] P --> Q[M19-BQ Claude probe — PR #93] Q --> T[PT0 provider transport — PR #94] T --> S[M19-B0 secure storage — PR #99] S --> W[M19-B1 exact Windows sync — complete] W --> Z[D2 final docs checkpoint — complete] D -. fidelity defer .-> V[M23-V VS Code chatSessions] D0 -. fidelity evidence .-> X[M22 Zcode — PR #72 closed] F -. runtime deferred .-> R[M24 Warp]M26-A, M26-B, M19-BP, M19-BQ, PT0, M19-B0, M19-B1, and D2 are complete. M24 is a completed fidelity stop, not a cache dependency and not a shipped runtime source. M22 Zcode, M23-V Copilot VS Code, and M24 Warp remain deferred. The exact ledger is terminal at
79/0/0/18/13/1; PT0, M19-B0, M19-B1, and D2 are outside that inventory. The historical execution graph is closed, and future upstream reviews start from separately declared bounded ranges against the current public shared engine rather than extending the 111-row denominator.Milestone transitions
366ce643: TAKE → ALREADY_VENDORED405ded4a 315549b4: TAKE → ALREADY_VENDORED; mixedb64d861eremainedTAKEat that checkpoint6899ea03 b59979c5 9155018c 18cd13cc: TAKE → ALREADY_VENDORED;34cfbb50: TAKE → DEFERed798642; counts unchanged839ce378 052f43de 633ea946 77948d9d 302d39c3: TAKE → ALREADY_VENDORED640e97b9 f7a124da ed6f8b95 65f8f3e2 b64d861e: TAKE → DEFER; no runtime mergec1aef5e9: TAKE → ALREADY_VENDORED;074619f7: TAKE → DEFERf6f7eced 0b454e60: TAKE → ALREADY_VENDOREDchatSessions— deferred074619f7remainsDEFER959cce84 6c804711: TAKE → ALREADY_VENDORED; non-main sources excluded from counts9a5aeb65: TAKE → ALREADY_VENDORED63a44d7c: TAKE → DEFER; no runtime code landeda87f0ab6: TAKE → ALREADY_VENDOREDae36db5c: TAKE → ALREADY_VENDOREDcd07bf78: TAKE → DEFERafter taking generic hunks and leaving Devin excludedf820b06fThe terminal exact ledger is
ALREADY_VENDORED 79,TAKE 0,ADAPT_FOR_STREAMING 0,DEFER 18,SKIP 13, andSUPERSEDED 1, total 111. Every future update must apply transitions to the actual previous six sets and regenerate the count, duplicate set, union, and both symmetric differences rather than trusting a planned intermediate value.Fidelity audit
The audit separates upstream semantic fidelity from TokenBar's unavoidable streaming/cache/FFI integration. Churn ratio is a size signal, not a correctness score.
2.76xchurn0.76–0.86x1.06xparser additions overall4.26xchurn2.78xchurn1.056xproduction;99.8%parser net parity1.91xnet production2.1–2.5xproduction;3.1–3.5xtotalDEFER.285local parser lines versus261selected upstream lines (+9.2%)3.1xCopilot production drift without a reliable ObjectMutationLog/model/agent/cost contract.63a44d7ctoDEFER.turn_completed.usage; recorded separately from the audited range.The adoption rule is explicit: preserve necessary TokenBar streaming/FFI seams, but stop when the core parser or authority requires repeated systemic repair, review keeps exposing new failure classes, or downstream invention exceeds the upstream feature. Do not continue because of sunk cost.
Current upstream reportability
The 2026-08-11 fresh upstream audit uses fixed cutoff
e7293751and covers7e3552a7..e7293751: 175 upstream commits total, 76 touchingcrates/tokscale-core. Latest release at the cutoff isv4.13.0, and the latest core-touching commit isd8b23d1. Historical audit target366ce643, range0c820a5d..366ce643, and the fixed 111-row inventory remain unchanged. TokenBar main is9e7741da, the reviewed shared-engine pin is5b5f500d, and the exact ledger remains79/0/0/18/13/1. The 175/76 counts measure upstream activity through this cutoff, not a simple unported backlog or implementation selection.FRESH_AUDIT5b5f500d. Submit-only, CLI, CI, docs, and refactor-only changes are not TokenBar runtime backlog; this row does not classify any commit asTAKEor authorize a pin advanceMERGED_UPSTREAM940c1cb5; Kimi #926 / #927 at1c74ba4b; OpenCodeReview #928 / #929 at8d0f887e; Copilot #938 / #939 at1652852f; Copilot #942 / #943 atff5e67adREPORTABLE_NOWu64clamp; OpenCode logical identity/reported-cost authority; optional long-lived pricing refresh TTLALREADY_REPORTED_OPENREVIVE_EXISTING<synthetic>share closed-unmerged upstream PR #708NEEDS_CONFIRMATIONsess_*topology and CLI/SQLiteautoversusunknown; Copilot VS Code ObjectMutationLog/model/agent/cost semanticsALREADY_FIXEDfs_atomicin current upstreamTOKENBAR_LOCALsimple_lane!arms, extra sibling folds, live-tail/FFI/cache/report seams, M18 complete pricing policy, reqwest TLS, M19-BP/BQ, PT0, and M19-B0DEFER-EVIDENCEThe canonical deduplicated reportability inventory is maintained in
vendor/README.md; this issue mirrors its public status. A merged upstream PR is not automatically present in TokenBar's selected vendor tree, and an open upstream issue is not evidence that the corresponding TokenBar adaptation is upstream-ready.Non-main semantic sources
The following sources are deliberately excluded from the 111-row count:
ed798642/ issue #849548dc124/ issue #8626ea27ca1/ issue #846d1cd03c2/ PR #636TokenBar adaptation rules
TokenBar's shipping path is not upstream's materialized CLI path:
Verification and update protocol
Every selected runtime milestone must include an exact upstream diff review, hermetic old-fail/new-pass evidence, explicit cache/schema handling, materialized/streaming/count/report parity, applicable FFI/Swift checks, mandatory
vendor/README.mdand canonical-doc updates in the same PR, repository gates, fresh adversarial verification, clean GitHub review threads, and green CI.After each milestone merges:
A milestone is complete only after both merge and this issue update succeed. The private Project tracks executable milestones only and must not duplicate the 111 commit rows. Tagging and release remain separate decisions.