2026-09-27 review, archives and interface improvements
Status: this batch’s repairs/local checks are complete. Scope: nine commits/444 changed files, 4ef354d42dac2ca9f86ae101f70908ff4cb2f7eb through ff1e458, range 4ef354d^..ff1e458. Initial workspace clean. Review covers design/version references/full change inventory/collection-to-UI data flow/tests/build/docs. Historical checks do not count as current passes. No commits, pushes, installation or deployment.
Repair requirements and results
Archives/active sessions share one source instance. Read only documented local formats; deduplicate by native identities without guessed association from nearby times/equal tokens. Unknowns remain unknown; messages/requests/cumulative values/quotas stay distinct. Model/Agent grouping/filtering is case-insensitive; event identity remains unchanged and display-name changes do not add events.
| Finding | Repair and regression coverage |
|---|---|
| Codex discovers sessions only, missing initial collection after archive | Discover archived_sessions too; archive-only/active-plus-archive/repeats count once |
| ZCode approximate time/token matching merges different calls; late JSONL duplicates | Native model_usage IDs; atomic source/day replacement, no guessed cross-format match |
| Deleting whole historical periods per dimension leaves only last dimension | Delete once per period; retain multiple sources/models; repeated cleanup changes nothing |
| Partial daily data overrides complete periods; summaries/groups select differently | Shared coverage selector; periods must fit fully within query range; preserve daily cutoff |
| Case handling differs across summaries/hours/details/charts | SQLite lowercase function matches Rust; consistent paths; different providers retain model rows |
| Hourly sessions use whole-day counts and add dimensions; cross-day duplicates | Deduplicate source/session within selected range; missing IDs/aggregate-only history unknown |
| Mean duration uses all calls as denominator | Weight by duration-bearing samples; add sample count; no zero for unknown samples |
| Hourly totals flatten quality/conflicts; cache ratios mix sample populations | Retain quality/conflicts; paired samples from retained details; unrecoverable old archives unknown |
| Empty user-source selection means every source | Distinguish unrestricted selection from explicit empty set; prevent cross-user statistics exposure |
| Export misses recent unsealed days/period history; import drops fields | Direct aggregate snapshot includes day/hour/period/coverage counts and original host; invalid import fully rolls back |
| Import overwrites partitions with live local details | Identical packages change nothing; reject different-content conflicts with active details; avoid sealing/overwriting live sources |
| Cursor commits before native summary failure lose retry data | Native summaries/events/cursors share transaction; Hermes failure injection checks rollback/failure state/complete retry |
| Interval zero still scans; concurrent trigger race | Zero stops interval collection; changed intervals/manual completion reset deadlines; atomic refresh coalescing |
| Second process opening DB recovers still-running jobs | OS file lock per DB; headless requests merge into owner; crashes release lock |
| Headless version mismatch opens delete-DB dialog | Windowless startup returns error/preserves DB; GUI handles interactive recovery explicitly |
| Returning to prior timezone omits later collected data | Rebuild daily/hourly partitions from retained details; no guessed conversion of cleaned history |
| Repeated page queries/stale responses/missed source reassignment refresh | Deduplicate requests/use sequence guards; separate filter catalog; force reassignment requery; idle polling leaves charts alone |
| Detail refresh resets page; cleanup leaves invalid page | Same-range refresh retains page; range changes reset; shrinking data returns to last valid page |
| Panel order lost on restart; unintuitive resize clicks | Restore saved order; insertion-sort dragging; keyboard resize; canceled drags do not save |
| Chinese user names produce identical IDs | Separate IDs/names; random unique IDs; test Chinese/duplicate names |
| GNU-only tar arguments break Windows script tests | Relative working-directory archives support BSDtar; repeated reports avoid repackaging |
Archive-source checks
Codex, Claude, OpenCode and Kilo
- Codex official App Server documentation describes thread/archive moving sessions to archives. Native event identity within a source remains unchanged by moves. Read-only local inventory: 306 active files/no archives; synthetic archives verify the path without claiming real local archive acceptance.
- Claude already discovers orphaned/superseded/subagents and tests native message identities; full suite rerun. No local Claude data for real archive comparison.
- OpenCode/Kilo DB queries retain archived sessions; added archive-marker before/after checks preserve totals. OpenCode fields reference official session source. Shared code families do not establish other products’ archive formats.
- Other capabilities follow the adapter matrix. Archives without verified format references are not parsed speculatively; limited products such as OpenClaw do not thereby become accepted.
ZCode: database collection and JSONL fallback
Read-only checks of installed resources/glm/zcode.cjs model_usage writing/cleanup, SHA-256 B1DF2EF3E5BD76C4AF3ECB296BC003A10D3F13191A26610BD0BA940FEADAD529. Native row identity includes assistantMessage/span/start/attempt source fields. JSONL network requestId is a different identity; traceId can span requests. Equal timestamps/tokens cannot establish the same call.
started_at cleanup removes records older than about 30 days: bounded local history, rather than permanent archives. Behavior:
- Normal discovery includes db/db.sqlite without a manual history button.
- Read-only consistent snapshots check fields/completion and use model_usage.id as source call key.
- Successful validation atomically replaces source/day events/daily/hourly rows and fingerprint; do not add turn_usage to per-call usage.
- Older saved app history remains. A possibly incomplete 30-day boundary preserves existing daily rows with diagnostics; expired daily-layer data is not split back into days.
- After a source uses DB data, missing/corrupt DBs preserve statistics/report errors; silently falling back to JSONL could double-count. Only sources that never used the DB may fall back.
- Missing per-record product-version references leave latest_fallback; valid amounts count, while version coverage remains unverified.
Real read-only command: cargo run –manifest-path desktop/src-tauri/Cargo.toml -p llm-usage-core –example real_verify_zcode – <local-ZCode-CLI-root> build/review-2026-09-27/real-zcode-final. Input is the local source; output is an independent task DB. Snapshot exited 0; permitted values:
| Metric | Compared result |
|---|---|
| Completed calls | 8,225 |
| Input tokens, including cache | 2,394,416,074 |
| Cache-read tokens | 2,360,503,168 |
| Cache-write tokens | 0 |
| Output tokens | 4,533,937 |
| Total tokens, input + output | 2,398,950,011 |
| Main / sub-Agent / auxiliary / unknown class | 5,949 / 2,257 / 18 / 1 |
| Added on repeat / revision changes | 0 / 0 |
The source was still running; later snapshots may change without historical recalculation errors. Per-call model_usage sums match application statistics. Of 506 turn_usage rows, 482 groups agree and 24 differ; cumulative total 2,389,951,339. This live snapshot cannot replace all completed calls with turn_usage. Compare both representations and retain differences without forcing equality. The checker outputs no prompts/bodies/session IDs/project paths.
Interface and performance
- Five pages share sidebar/hierarchy/spacing/cards/tables/forms; themes include chart text/axes/ tooltips. Narrow windows remain usable, with keyboard focus/reduced-motion preferences.
- Dashboard adds active days/known-usage-field ratio/duration samples/records requiring review/ historical coverage. Wording uses cache-read proportion so token proportions are not called request hit rates.
- Sources support search/user ownership/enabling and show compatibility/missing files/failures; remove the ZCode manual history entry replaced by automatic collection.
- Same-structure charts update incrementally; unknown usage remains blank; custom tooltips escape source labels. Today/details use statistics timezone, without OS-timezone or fixed 24-hour date offsets.
- Summaries reuse one coverage selection/detail scan instead of rescanning per period/dimension. Set-based period replacement avoids refiltering every daily row for each archive row. Aggregate export does not first load raw details. Unchanged scans/repeated imports/cleanup preserve revisions.
- Conclusions cover implementation/regressions only: million-row P95/idle memory/uniform source time limits were unmeasured. Fewer duplicate queries do not establish every M7 resource target.
Checks in this batch
Windows x64, Node.js 24.21.0, Rust 1.98.1; lockfile dependencies; cwd root. OS locks use File.try_lock, available since Rust 1.89. Desktop Cargo rust-version becomes 1.89; existing CI 1.98.0 satisfies it.
| Command / check | Exit | Result / log |
|---|---|---|
| npm run verify | 0 | 476 Rust/six frontend logic/three script tests; assets/Markdown/Svelte/workspace fmt/clippy/frontend build; verify-complete.log |
| npm run test:browser | 0 | Headless Edge, ten groups/zero runtime errors/seven screenshots; browser-final.log |
| npm run build:desktop | 0 | Windows release + NSIS; release-complete.log |
| real_verify_zcode | 0 | Per-call amounts above agree; repeat adds nothing; real-zcode-final.log |
| headless-schema-check.py | 0 | Child exits 1 as expected; no dialog/unchanged DB SHA-256; headless-schema.log |
| git diff –check | 0 | Final whitespace check passed |
Final NSIS candidate desktop/src-tauri/target/release/bundle/nsis/LLMUsage_0.1.0-dev_x64-setup.exe: 2,564,223 bytes, about 2.45 MiB; installer not run. Background failures use this release with isolated APPDATA, leaving the real user DB untouched. Logs/disposable probes: build/review-2026-09-27/.
Browser suite desktop/tests/browser-smoke.mjs runs via npm run test:browser with fixed time, OS Los Angeles/statistics Shanghai timezones/synthetic IPC. Checks five pages/light-dark themes/ 760px no horizontal overflow/two initial summary queries/no additional summary queries in 31 idle seconds/stale fast-filter responses/empty users/same-revision source reassignment/retained refresh page/cleanup page reduction. Results/screenshots: build/browser-smoke/. Six frontend logic cases cover timezone/DST/panel order/corrupt layouts/weighted duration/unknown chart values/ case-insensitive names/tooltip HTML escaping. Rust covers archive deduplication/equal-value distinct native requests/instance isolation/missing DB protection/NULL/cutoff boundaries/period retention/ user filters/exchange transactions/timezone rebuild/process locks.
The first full check found two outdated assertions: missing session IDs counted zero and ZCode identity was JSONL-only. Updated to unknown and separate native DB/JSONL identities, preserving business assertions; full rerun passed. Terminal sandbox access-denied/child EPERM failures were resolved through supported elevated execution, rather than counted as business failures or avoided by deleting tests. AI maintenance entry points/selective guidance reflect real commands/ collection regressions without duplicate Skills/empty rules. CI adds frontend regressions and workspace fmt/clippy; no push triggered CI in this batch.
Remaining acceptance and data limits
- No native GUI lifecycle/install/uninstall/Windows system-task registration/macOS/Linux/WSL acceptance here. Playwright simulated IPC does not verify native Tauri dialogs/IPC/system integration.
- Deleted source data never saved by the app cannot be recovered. Incomplete boundaries/unverified versions remain visible. Session counts/duration samples/cross-timezone hours cannot be inferred from sealed totals.
- Week/month/year-only history cannot prorate clipped periods into arbitrary ranges; weekday/hour heatmaps display only retained detail ranges.
- Exchange still imports aggregate snapshots; detail merging/deletion propagation/full Merge are later work. Aggregate snapshots cannot overwrite same-source partitions with continuing details.
- Per-source schedules/watchers/system-task desired/applied/uniform time limits remain M6/M7 work; static/unit passes do not complete those plans.
Additional archive and interface checks
Dark-heatmap black blocks were reproduced in browser screenshots: alternating axis backgrounds created gray-black checkerboards where calls were absent; low-value dark blue approached the panel background. Draw fixed 7×24 neutral base cells, overlay blue/cyan/gold intensity only with calls, and define base/gap colors per theme. New build/browser-smoke/trend-dark.png shows consistent no-call cells without alternating black blocks. Overview history/trend defaults are token usage, calls,sessions; saved layouts retain user ordering.
Qwen Code official archive behavior moves JSONL from chats to chats/archive and back on restore. Upstream active/archive coexistence issue rules out adding file counts. Settings documentation defines QWEN_RUNTIME_DIR/QWEN_HOME; new projects/old tmp layouts are discussed in session formats and daemon documentation. Enumerate only chats/archive in both layouts, keep one source instance/root, read active files first, deduplicate native uuid, import new active tails normally. Runtime override priority selects automatic environment roots; manual roots can retain old locations. Absolute/tilde-prefixed paths resolve; paths relative to Agent working directories cannot reliably be reconstructed by the desktop and require absolute manual roots. No local Qwen root was found: archive counts use synthetic samples without real Qwen archive acceptance.
Gemini session management describes regular automatic-session cleanup. Manual checkpoints save separate session state without verified per-call identities/formats enabling exact automatic- session deduplication; do not add them as independent calls. pi deletion may move sessions to the recycle bin: a deletion action, not independent native usage storage. Known Claude/Codex/Kilo/ OpenCode/ZCode archive behavior retains the preceding rules without expanding to other Agents by similar directory names.
Three new Qwen cases: archive-only imports; active tail plus retained archive gives three calls/ unchanged repeat revision; old tmp/new projects share two native calls/exclude side JSONL; runtime override selects only target root. Qwen regression/eight prior incremental cases passed. Browser adds two default-order checks/dark trend screenshot: 11 groups/eight screenshots/zero runtime errors. Full npm run verify exited 0: 479 Rust/six frontend logic/three script tests/Markdown/assets/ Svelte zero errors/warnings/fmt/clippy/build; build/review-2026-09-27/verify-archive-layout.log. npm run test:browser exited 0, browser-heatmap-final.log; npm run check after adding a legend exited 0, check-heatmap-legend.log. npm run build:desktop exited 0, release-archive-layout.log; same NSIS candidate path, 2,567,112 bytes, not installed. Synthetic browser IPC does not replace native GUI or real Qwen archive checks.
Source health and unknown versions
User reported Codex/ZCode both need checks. Read-only app DB: Codex 272 active/38 degraded files; ZCode two active/ten old new/one old unsupported. Latest seven tasks successful for both. Current program reading the same sources into an isolated root build/ DB still has 38 degraded Codex files; ZCode normal. Codex failures are not unknown versions: all 38 use registered versions. New DB diagnostics: 37 per-call/final-snapshot mismatches, four cumulative rollbacks, one malformed usage object. Complete calls cannot be verified, so partial-data review stays visible. Isolated and real app DBs remain separate; no writes to the real DB/Agent logs.
Old ZCode unsupported JSONL lacks sessionId but has requestId/usage. The DB is authoritative; current collection excludes JSONL to avoid cross-format double-counting. Read-only comparison finds no JSONL request-ID match in DB native/logical IDs; nearby same-day token values also differ. trace_id is not unique per call, so DB coverage of that call is unverified. A test-like filename cannot establish invalidity/safe exclusion. Retain warning/statistics without adding JSONL; source card shows one unidentified file. A fresh isolated DB is normal because authoritative DB reading skips side JSONL: it verifies the DB path, without establishing inclusion of side-file usage.
Unknown versions already try each Agent’s latest built-in parser; structurally valid data counts with latest_fallback references. Two shared fixes: incremental scans retain saved version references; bad records under compatible parsing show partial-data review even with valid calls, rather than active_compat hiding failures. Completely incompatible first reads still reject; successful zero cannot substitute for errors. Source cards distinguish compatible reading in normal information colors from degraded files. Added checks: unregistered valid calls count with normal source health; later invalid usage retains two prior calls and degrades file/source; successful ZCode DB reads preserve old unsupported/degraded JSONL warnings. Browser asserts source health/unidentified files/ compatibility notices.
Same Windows x64/Node.js 24.21.0/Rust 1.98.1; root commands, focused Rust from desktop/src-tauri. Logs: build/source-health-2026-09-27/.
| Command / check | Exit | Result |
|---|---|---|
| cargo test -p llm-usage-core –test zcode_gaps_synthetic –test zcode_db_backfill –test codex_gaps_synthetic –test codex_versions_v17 | 0 | Final 38 passed; initial new case exposed incremental bad records misclassified as wholly incompatible, corrected |
| npm run verify | 0 | 481 Rust/six frontend logic/three scripts; Markdown/Svelte zero errors or warnings/fmt/clippy/build |
| npm run test:browser | 0 | 12 groups/eight screenshots/zero runtime errors; synthetic IPC |
| npm run build:desktop | 0 | Windows release/NSIS, 2,568,281 bytes; not installed |
| git diff –check | 0 | No whitespace errors |
The real user DB was untouched. Automatic approval review rejected copying it into repository build/ because potentially sensitive usage/metadata exceeded read-only permission. Instead use fresh isolated source rescans/targeted read-only live SQL/synthetic old-state regressions. Whether the first refresh after upgrading the real app clears historical warnings remains to be observed using the new version.
Daily heatmaps and language expansion
User requested one day per heatmap cell/major languages. Previous weekday×hour folding merged the same hour across weeks and directly read events, losing usage retained in daily summaries after detail cleanup. Now return consecutive local dates in the selected IANA timezone; daily_usage aggregates calls/known tokens under overview daily filtering. Before daily-layer cutoff, a day without matching daily data is unavailable. Period archives are checked separately for imported DBs without local daily cutoffs. Partially retained days keep known values/partial coverage. Week/month/year materializations cannot be split into days: no zero filling/prorating/recalculation. Weekday distribution combines these date cells and reports incomplete coverage. Synthetic cases: same weekday across weeks/Shanghai crossing UTC dates/daily data retained after event deletion/ case-insensitive filters/empty users/period-only after daily cleanup/period import without cutoff/ partially retained days.
Calendar cells use theme base/intensity colors; cleaned dates have hatching distinct from zero calls, partial days dashed borders. Short ranges show known active days/longest active streak/ highest-call date without implying complete coverage. Light/dark screenshots show no old black blocks; date-cell count matches selected range.
Traditional Chinese/Japanese/Korean/Spanish/French/German/Brazilian Portuguese/Russian join Simplified Chinese/English for ten languages. All 292 UI keys exist per language; tests check key sets/nonempty text/interpolation parameters. Language persists/applies immediately; Intl formats dates/numbers/relative times in current locale. Translation does not change statistics timezone/ query values. Diagnostic originals/raw source names are excluded. Native-speaker review remains needed, particularly cleanup/import/export instructions with operational consequences.
Windows x64/Node.js 24.21.0/Rust 1.98.1. Synthetic browser IPC does not replace native GUI or installed acceptance after real daily cleanup.
| Check | Exit | Result |
|---|---|---|
| npm run verify | 0 | 483 Rust/eight frontend logic/three scripts; Markdown/assets/Svelte zero errors or warnings/Rust fmt/Clippy/build |
| npm run test:browser | 0 | 13 groups/nine screenshots/zero runtime errors; daily cells/themes/ten persisted languages/German-Russian narrow windows |
| npm run build:desktop | 0 | Windows x64 release/NSIS, 2,585,083 bytes; not installed |
| git diff –check | 0 | Tracked changes whitespace-clean; new files separately checked by formatting/types/tests |
Frontend JS gzip 287.14 KB/CSS gzip 7.27 KB remain below the designed 1 MiB gzip limit. First-screen P95 was not measured here. Native per-language desktop checks/native-speaker translation review remain for later manual acceptance.