v0.3.0: token savings (wait_task, brief view, auto-fix/escalation, usage report, opt-in savers) — stacked on #4 - #5
Merged
Conversation
- wait_task long-poll (single/many ids, any/all, capped at 55 s) and delegate_tasks batches - compact MCP JSON, task_result view brief|full, handoff context deduplicated in the full view - presets and size routing; auto_fix_rounds and escalate_to chains with hard caps and a trail - optional advisory auto_review on a cheap profile (transient status reviewing) - usage_report / workhorse stats with per-run tokens and a labelled supervisor ESTIMATE - opt-in worker token_savers: terse and minimal_code fragments, RTK rewrite in the guard plugin - approvals.require_operator with a separate operator token confirmed via the CLI - per-profile stall_minutes, audit.jsonl rotation - TEST-ONLY stub backend, registered only with WH_ENABLE_STUB_BACKEND=1
Runs approval, continue, retry/fallback, restart, handoff, auto-fix, escalation, auto-review, wait_task, delegate_tasks, presets, require_operator, token savers and usage_report against the real daemon with a scripted worker (git + python3 only).
… token-saver flags npm ci from scripts/pins/<cli> (integrity-checked) when the pinned version is requested, else fall back to npm install -g with a warning. New --token-savers and --rtk-bin options.
…fers wait_task docs/token-savings.md (features, RTK/Headroom/Caveman/Ponytail evaluation, benchmarks, usage estimate formula), configuration/handoff/architecture/security/troubleshooting updates, README, delegation skill draft, NOTICE attributions, CHANGELOG 0.3.0 (Unreleased), version 0.3.0.
…gets, auto-review children, rtk env - approvals.require_operator: a task that parks keeps a persistent operator_gate until the operator answers with the token; continue_task is refused on gated tasks whatever their status, closing via update_handoff/cancel_task/reject keeps the gate, reject with instructions needs the operator token - approval requests get an id; the operator CLI prints the pending request and sends back the displayed id; the daemon refuses the decision if the request changed - reviewVerdict reads the first line only, handles negations, else unclear - max_tokens/max_cost_usd 0 is an explicit zero budget (invalid values fail validate); auto-review child tokens/cost count against the parent budget; continue_task restarts run counters only - auto-review children: recover orphans after a crash, hidden from list_tasks unless include_auto_reviews, never needs_attention - full view keeps the complete handoff (backcompat); brief stays small - rtk rewrite: minimal env, 1 s timeout, falls back to the original command; bind only the rtk file - wait_task stops when the client disconnects; usage_report estimate counts worker output only - docs: operator gate is a parked-task flow gate, not a capability boundary; caps, trail, formula
… package.json bin opencode-ai@1.18.32 maps opencode to ./bin/opencode.exe; scripts/pin-bin.mjs reads the bin field and install.sh refuses a dangling link. CI: npm ci --ignore-scripts on each pin and assert the target exists.
…GELOG, recovery and budget tests - README: CI status badge; 'Measured savings' table, every figure labelled an estimate with how it was measured, linking docs/token-savings.md - CHANGELOG 0.3.0: operator gate and request ids, review verdict parsing, budgets (0 = explicit zero, reviews counted, per-run overshoot, continue semantics), rtk hardening, installer bin resolution, auto-review list/recovery, full view unchanged, conservative usage estimate - stub e2e: restart recovery re-links a review child and cancels an orphan review - unit: auto.max_tokens / max_cost_usd 0 kept as explicit zero budgets, invalid values reported
mrchatam
force-pushed
the
feat/v0.3-token-savings
branch
from
September 26, 2026 22:03
6890984 to
b18f9e0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Grok Workhorse exists to reduce supervisor (e.g. Grok) usage: smaller, user-chosen models do bounded tasks. v0.3.0 (Unreleased) cuts what the supervisor reads and how often it has to act, and adds opt-in token savers for workers. Details:
docs/token-savings.md.What's in it
wait_tasklong-poll: one id or many (any/all), capped at 55 s so each call stays under the MCP TS SDK's default 60 s request timeout. Alsoworkhorse wait. The delegation skill now prefers it.task_result view: "brief"(~0.5-1 KB).fullstays the default and is unchanged apart from compact JSON (the complete handoff is kept for compatibility).auto_fix_roundsplusescalatealong theescalate_tochains (cheap -> mid -> strong), with hard caps (fix rounds ≤ 3,max_auto_runs≤ 6, optionalmax_tokensandmax_cost_usd). Fix rounds count per profile; the total is capped bymax_auto_runs. Budgets include auto-review tasks,0= explicit zero budget, checked between runs. The trail is inresult.auto.auto_reviewon a cheap profile: advisory verdict, new transient statusreviewing;request_changessets the handoff toneeds_review. The verdict is read from the reviewer's first line (negations handled, otherwiseunclear). Review tasks are hidden fromlist_tasksby default and recovered/cancelled after a crash.usage_report(MCP/RPC) andworkhorse stats: by profile and by day, with per-run tokens. The supervisor number is labelled ESTIMATE and is conservative (only successful workers' output tokens minus the supervisor's own I/O; worker input not counted); the formula is documented.list_modelsshows them, new tiered example config, tightened skill draft.delegate_tasksbatch (≤ 10), thenwait_taskover many ids.WH_ENABLE_STUB_BACKEND=1in the daemon env and only runs its bundled script;workhorse healthwarns if the flag is on. It drives the approval, continue, retry/fallback, restart (SIGKILL and SIGTERM), handoff, auto-fix, escalation and review flows. CI now runsnpm run test:stub.approvals.require_operator: MCP approve only records a request (with an id). A human confirms withsudo workhorse approve, which prints the pending request and sends a separate operator token (only its SHA-256 is stored) plus the displayed request id; the daemon refuses if the request changed. A parked task keeps a persistent operator gate until the operator answers, also afterupdate_handoff state=closed,cancel_taskor reject; reject with instructions needs the operator. This gates the parked-task flow; it is not a capability boundary (a supervisor can still delegate a new task asking the same thing, visible in the audit log).stall_minutes, and the installer installs the pinned Kilo/OpenCode from committed lockfiles (npm ci), falling back tonpm install -g. The executable link comes from the package'sbinfield (opencode-ai 1.18.32 shipsbin/opencode.exe); a new CI job installs each pin withnpm ci --ignore-scriptsand checks the link target exists.Worker token savers (all opt-in,
token_saversin daemon.json or per profile,workhorse token-savers, installer--token-savers):terseandminimal_codefragments, in our own wording, inspired by Caveman and Ponytail (both MIT); attribution in NOTICE.rtk: the guard plugin rewrites worker bash commands viartk rewrite(RTK, Apache-2.0; Kilo/OpenCode only), with a minimal environment (no keys, telemetry disabled), a 1 s timeout and a fallback to the original command; only the rtk binary is bound into the sandbox.Benchmarks (small samples; token counts are estimates via the o200k tokenizer unless provider-reported)
Review fixes (independent review of #4 and #5)
All 13 findings addressed; #4's parts (restart socket race, closed-on-parked semantics, approval source attribution) are on
feat/task-handoff. README has a CI badge and a "Measured savings" section (all figures labelled estimates, with method).Tests
Local, on
b18f9e0:npm test) run twice: 114 tests, 112 pass, 0 fail, 2 skipped (the live test and the stub-prerequisites placeholder), both runs.npm run test:unit: 63/63. (The old handoff-dedupe test was removed because the full view keeps the complete handoff again.)npm run test:stubrun 10 times in a row: 10/10 green, each 20 pass + 1 placeholder skip. The restart tests run on their own: 4/4 green.