Build1 distinct publisher3 min readUpdated
RuntimeWire's reverse engineering of a production Codex build points to a separately metered reserve model for Plus and Pro. The wall may become a downgrade rather than a stop.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
The restore path carries more information than the fallback itself. According to RuntimeWire's reading of the client, the code holds on to whichever model you had selected, runs you on gpt-reserve, then puts your original selection back when the Reserve window closes [3]. A plain downgrade would not need to remember anything. Bookkeeping like that exists so the interruption reads as temporary, and a temporary interruption is the condition under which an offer to buy more premium capacity actually converts.
Compare the two failure modes. A hard limit ends the session and the developer goes to lunch. A metered fallback keeps them in the editor on a weaker model with a visible counter, and the client reportedly ships the string for exactly that counter: "Luna Reserve, {remaining}% remaining" [5]. RuntimeWire frames the intent as replacing the wall with a cheaper route that keeps developers active while turning premium capacity into an immediate upsell [15]. The mechanism in the binary is consistent with that framing, which is not the same as proving it.
The numbers in the sightings are the part worth putting in a spreadsheet. In the Plus screenshot RuntimeWire reviewed, the account had burned 49 percent of its weekly advanced allowance while the reserve pool sat untouched at 100 percent on a separate reset schedule [16][9]. Two allowances, two clocks. A second image from the Codex and Work Analytics view showed ordinary usage at 27 percent against gpt-reserve at 100 percent [10]. Once a second pool exists, the published weekly limit stops describing the moment work stops, and starts describing the moment quality drops.
The evidentiary limits are real and RuntimeWire states them. No server interaction or feature-flag bypass was attempted, and live reproduction of the interface still requires server-side eligibility and rate-limit state [12]. The gate itself is server-controlled, traced from the flag through eligibility, activation, model switching and restoration [11]. OpenAI had not responded to a request for comment by publication [13], and the tier does not appear in current official documentation [14]. So the client proves that separate metering, Plus and Pro eligibility checks and lifecycle analytics were built and shipped [2][1]. It does not disclose how large the reserve pool is, or what it costs.
The work is at least checkable, which is more than the screenshot circuit it started on: a named Store build, a named embedded version and production build number, an archive index of 8,461 entries, plus a published SHA-256 and reproduction steps [6][7]. The figure nobody has yet is the ratio of reserve allowance to primary allowance. Until that appears in documentation rather than in a renderer bundle, a Plus seat's effective throughput is whatever a server-side flag says it is this week.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Codex contains a feature-gated "Luna Reserve" allowance that appears to switch eligible Plus and Pro users to a Luna-class reserve model after advanced-model limits are reached.
Static analysis of the production-distributed Codex app.asar identified the model identifier gpt-reserve, feature gate reserve_enabled, luna_reserve banner logic, dedicated lifecycle analytics, eligibility checks for Plus/Pro accounts, and user-facing text describing a separate "Luna Reserve" allowance.
The client contains the user-facing string "Luna Reserve - {remaining}% remaining."
RuntimeWire calculated and published the archive's SHA-256 hash and reproduction steps, and independently reproduced the core finding.
RuntimeWire traced Luna Reserve from its server-controlled feature gate through account eligibility, rate-limit activation, model switching, UI presentation and restoration of the original model.
The code preserves the user's original model selection and restores it when Reserve ends.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Strong artifact-level evidence, one publisher, no vendor confirmation
The technical core is unusually well documented for a single-source story: a named production build, a published SHA-256 of the analysed app.asar, enumerated identifiers and strings, step-by-step reproduction instructions, an explicit statement of what was not attempted, and self-reproduction of the core finding. Screenshots of live accounts corroborate the code reading. What holds the score down is the absence of any second publisher, any OpenAI statement, and any documentation; server-side behaviour was deliberately not probed.
Shipped in production and visible to some accounts, scope undisclosed
Adoption is real but small and unquantified: the code is in a production-distributed build, and screenshots show gpt-reserve surfacing in at least a few live accounts, including in OpenAI's own Codex and Work Analytics view. However the feature sits behind two server-side flags plus plan and runtime-version checks, no user counts, regions or rollout percentage are disclosed, and workspace accounts are excluded.
Mildly overstated: mechanism is proven, commercial intent is inferred
The evidentiary sections are carefully hedged ("appears to switch", "shipped binaries suggest", explicit non-attempted steps), which keeps the gap small. The overshoot comes from framing: the headline's rebuilt-as-a-cheaper-tier claim and the "immediate upsell" thesis assert business intent that no OpenAI statement, pricing detail or documentation supports, and rollout breadth is implied by a handful of screenshots.
Self-originated scoop with disclosure offsetting promotional framing
The only publisher in the cluster is also the investigator, and the piece is explicitly branded as a RuntimeWire scoop with original reverse engineering, which creates an incentive to maximise the significance of its own finding — visible in the upsell framing and the emphatic "most consequential code" language. That incentive is partly counterbalanced by unusual transparency: published hash, tested versions, reproduction steps, a statement of what was not attempted, and a recorded no-response from the subject company. No sponsorship, vendor relationship or financial interest is disclosed or evident in the supplied material.
High confidence in the code facts, low confidence in intent and scope
Confidence is high that the described strings, gate, separate rate limit and model save/restore logic exist in the named production build, because the claim is reproducible from published steps and matches independent user screenshots. Confidence is materially lower on what OpenAI will do with Reserve, how broadly it will ship, and whether the pricing framing holds, given a single publisher, no vendor response and no server-side verification.
build
A coding orchestrator allowed to delegate chose zero workers, six times out of six1 distinct publisher
build
Codex can now ask and keep going, which deletes the only checkpoint you were getting for free1 distinct publisher
build
Codex learns to click: the coding agent stops typing patches and starts operating the machine1 distinct publisher
build
Developer habit, priced at $965B: what Anthropic's run actually proves1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 23, 2026