Skip to content

Port upstream 0.66.0: MiniMax browser storage discovery (stacked on #646) - #651

Closed
Finesssee wants to merge 112 commits into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.66.0-minimax-storage-discovery
Closed

Finesssee wants to merge 112 commits into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.66.0-minimax-storage-discovery

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #646 (shared Chromium LevelDB reader). Adds browser::storage_discovery, a shared, read-only locator for raw Chromium profile stores, and switches the MiniMax browser-storage importer to it.

  • storage_discovery::discover(StorageKind) walks every installed Chromium-family browser in the BrowserType catalog and returns candidate directories: Local Storage/leveldb, Session Storage, or IndexedDB/<origin>.indexeddb.leveldb filtered by origin prefixes. Profiles are Default, Profile *, and user-* (sorted; hidden entries, files, and guest/system profiles ignored). Nothing is opened, locked, or decrypted.
  • MiniMaxLocalStorageImporter::import_session previously looked only at the Default profile of Chrome, Edge, and Brave Local Storage (per-OS hard-coded paths). It now visits every catalog browser and profile, trying Local Storage first, then Session Storage, then MiniMax-origin IndexedDB only when earlier stores yield no session. source_label is now the candidate label (for example Google Chrome Profile 2 (Session Storage)).
  • MiniMax IndexedDB origin prefixes match upstream: https_platform.minimax.io_, https_www.minimax.io_, https_minimax.io_, https_platform.minimaxi.com_, https_minimaxi.com_, https_www.minimaxi.com_.

No user-visible change yet: MiniMaxLocalStorageImporter is still not called by the MiniMax fetch path (it uses API key or cookie header only), as noted in the 0.66.0 audit.

Upstream reference

  • Release bullet: "MiniMax: discover browser session storage across the shared Chromium catalog, including Comet and Yandex (fix(devin): share Chromium browser session discovery steipete/CodexBar#3883)", v0.66.0, commit 62cdd065.
  • Tag-pinned files: Sources/CodexBarCore/ChromiumLocalStorageDiscovery.swift (Storage enum, profileCandidates), Sources/CodexBarCore/Providers/MiniMax/MiniMaxLocalStorageImporter.swift (indexedDBStorage, storageCandidates, local, session, then IndexedDB order), Tests/CodexBarTests/MiniMaxLocalStorageImporterTests.swift (allowed and excluded IndexedDB fixture names, profile-name filter), docs/minimax.md.

Ported / Deferred

Ported: the three-storage discovery, profile filter, IndexedDB origin-prefix filter, and MiniMax fallback order.

Deferred:

  • Comet and Yandex: not in BrowserType, and upstream evidence gives macOS roots only, so their Windows User Data paths would be invented. Other upstream catalog members (Chrome Beta/Canary, Edge Beta/Canary, Brave Beta/Nightly, Vivaldi, Dia, Atlas, Helium) are likewise outside BrowserType; extending it belongs with the Chrome-channel work (feat(browser): support Chrome channels and Chromium profiles #614). Adding a browser there makes it visible to this discovery with no change here.
  • The MiniMax importer still string-scans .ldb/.log files rather than using the Port upstream 0.66.0: shared Chromium LevelDB + Snappy reader #646 LevelDB reader (Snappy-compressed tables are invisible to a raw scan). Switching the parse to the reader, and wiring the importer into the fetch path, are separate behavior changes.
  • Live-profile smoke check: not run (no real-browser data access in this task); coverage is fixture-based on temp directories.

Validation

Toolchain cargo +1.98.0, slot-4 target dir, E-core wrappers.

  • cargo +1.98.0 fmt --all: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar storage -- --test-threads=4: 14 passed, 0 failed (includes the 4 new discovery tests and 3 new importer tests)
  • cargo +1.98.0 test -p codexbar -- minimax browser:: --test-threads=4: 84 passed, 0 failed

New tests: per-kind path and label resolution, missing stores and missing user-data dir, profile-name filter and ordering (Default, Profile 2, user-work kept; Guest Profile, System Profile, Profile1, hidden, and file entries dropped), IndexedDB allow/exclude list from the upstream fixture (18 candidates across 3 profiles), and importer order (local beats session, session and IndexedDB fallback, no-browser vs no-session errors). Full cargo test -p codexbar not run (no shared core code touched).

Affected areas

  • Rust backend (rust/src/browser/, rust/src/providers/minimax/local_storage.rs)
  • Tauri shell
  • Frontend
  • Settings / bridge types
  • No new dependencies. No file over 1000 lines.

UI proof

Not applicable

Finesssee and others added 30 commits September 22, 2026 00:34
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

Thermo-nuclear review findings:

  • High: minimax/local_storage.rs scanned raw .ldb/.log files (missed Snappy-compressed tables, unbounded reads). Fixed: uses the existing LevelDB reader and origin-aware Local Storage decoder.
  • Medium: storage_discovery.rs kept its own profile filter beside the browser detector (drift risk). Fixed: uses canonical detected profiles; detection.rs handles ordering and user-* profiles.
  • Medium: minimax/local_storage.rs discarded read/parse errors and reported "storage not found". Fixed: keeps the last meaningful error while continuing.
  • Medium: JSON extraction treated braces inside quoted strings as boundaries. Fixed: scanner tracks strings and escapes.
  • Medium: importer has no caller in the MiniMax fetch path, so no runtime effect yet. Not fixed: the PR leaves wiring out and nothing establishes how a local storage token maps to the cookie-authenticated endpoints; guessing would change auth behavior without evidence.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at head f37043a: 4 of 5 findings fixed (wiring finding left, see above). Also fixed clippy cast lints in the new tests. Commands run: cargo +1.98.0 fmt --all, clippy -D warnings (rust crate, all targets), cargo test --lib browser (52 passed) and minimax (41 passed). Tauri crate clippy skipped: no changes outside the rust crate.

Port the remaining upstream 0.63.0 fd2414d conditions: the legacy weekly
counters must be reliable, counters are integers (an invalid used falls
back to a valid remaining balance), and the replacement window is built
from those counters. Translate the upstream KimiRatioPoolTests cases.
Make the new tray panel the default layout
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation (lane-A) at 084719a

Review verdict: the branch matches the 0.66.0 audit row-23 discovery spec: browser::storage_discovery::discover(StorageKind) walks every BrowserType catalog browser with profile candidates Default / Profile * / user-* (sorted; guest/system/hidden/file entries dropped), Local Storage first, then Session Storage, then MiniMax-origin IndexedDB (https_platform.minimax.io_, https_www.minimax.io_, https_minimax.io_, https_platform.minimaxi.com_, https_minimaxi.com_, https_www.minimaxi.com_) only when earlier stores yield nothing; source_label is the candidate label; read-only, nothing opened, locked, or decrypted. The importer no longer hard-codes Chrome/Edge/Brave Default paths.

Wiring note (the LANE-A "wire importer into fetch" item): the PR body itself scopes this as deliberate — MiniMaxLocalStorageImporter is still not called by the MiniMax fetch path (API key / cookie header only), matching the 0.66.0 audit's classification of the MiniMax browser-consumption wiring as a separate decision. The importer + discovery are production-ready and fully tested; no fetch-path change was attempted, which is the correct scoping for this PR. If the coordinator wants the fetch wired to browser storage, that belongs to a follow-up item, not this branch.

Merge outcome: the branch absorbed the finished #646 head (347faabf, which carries the #620 chain) and the thermo-review commit (f37043a3) (959a9cef, 084719a8). Zero conflicts, no code changes to the discovery/importer logic itself.

Checks at 084719a (CARGO_TARGET_DIR=W:\cargo-target\lane-a, jobs=4, RUST_TEST_THREADS=4):

  • cargo fmt --all --check: pass.
  • cargo clippy both manifests --all-targets -- -D warnings: only the 3 documented pre-existing main-drift findings; 0 in this PR's diff.
  • cargo test rust manifest: 2317 passed / 0 failed / 1 ignored (storage focused: 14/0; minimax focused: 41/0).
  • cargo test desktop manifest: 489 passed / 1 failed — bootstrap_payload_exposes_every_provider_variant, the documented Isolate bootstrap payload test from real settings #684 environment-dependent baseline on branches without Make the bootstrap catalog test hermetic (#684) #711 (expected; hermetic fix lives on release/v0.70.0).

Fast-forward pushed f37043a3..084719a8 (ls-remote verified).

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Shipped in v0.70.0: this PR's head is included in main via #735 (merge commit 9d0a37a). Closing as integrated.

@Finesssee Finesssee closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants