Skip to content

feat(kanban): harden budget-aware execution recovery - #66965

Open
GravityTone wants to merge 1 commit into
NousResearch:mainfrom
GravityTone:feat/kanban-token-budget-optimizer
Open

GravityTone wants to merge 1 commit into
NousResearch:mainfrom
GravityTone:feat/kanban-token-budget-optimizer

Conversation

@GravityTone

@GravityTone GravityTone commented Jul 18, 2026 •

Copy link
Copy Markdown

Summary

This PR hardens Kanban execution so long-running work can use fewer context tokens and iterations without increasing max_turns.

  • adds durable iteration-budget checkpoints and exactly-once compression/repair behavior
  • makes compact Kanban context bounded to 48 KiB UTF-8 while reserving LATEST_HANDOFF and CONTEXT_REF
  • keeps handoffs reversible through hash-bound recovery of partial_summary_full
  • adds run CAS/ownership checks so stale workers cannot mutate a newer run
  • makes exact-review provenance durable and fail-closed across direct creation and decomposition
  • constrains decomposition to atomic 2–6 child fanout and blocks hidden activation/release work as PREPARE_ONLY
  • strips private Hermes metadata before provider sizing and wire serialization, while preserving repaired user input exactly once
  • documents configuration and ships a reproducible synthetic context benchmark

Builds on the timeout-salvage work in #52511 and implements the preventive budget-warning contract from #54153. The original contribution remains credited in the commit trailer.

Verification

Verification on the final integrated candidate:

  • Kanban matrix plus benchmark tests: 822 passed
  • agent/run-loop, 413 recovery, checkpoint, role-repair, compression, streaming, multimodal, and Bedrock tests: 782 passed
  • configuration matrix: 300 passed
  • combined canonical run: 1,904 passed, 0 failed, subprocess return code 0
  • Ruff, git diff --check, Python 3.11 compile, and focused Python 3.9 compile: PASS
  • YAML/JSON parsing, deterministic benchmark, and security/privacy scans: PASS

Synthetic benchmark:

  • full context: 340,866 bytes
  • compact context: 49,152 bytes
  • reduction: 85.58%
  • repeated and versioned artifacts: byte-identical

Review receipts

  • final candidate: efa7a991148be122e93f7c898f5adf98d4f55083
  • base reviewed for overlapping integration: c78aa0bad5dc96c8080b1d16def868f1ab039b0c
  • tree: b6b04c8eaa3be35c4a6d895d7d2e6f6b5dfefa33
  • binary diff SHA-256: 9f3dea8ac55998cf9302ccab61a55c3c5a47e4b9843de4e86095121ee2122d90
  • bundle SHA-256: 1cbf19e12bc68b1a515706ce9ae8f0883f5c05409c292666ae8447ede02fd55e
  • independent material controller: PASS
  • overlapping-integration controller: PASS
  • canonical PRE/POST interlock: PASS / NO_MUTATION
  • candidate history: one privacy-safe squash commit

After the frozen review, main advanced by four commits touching three paths. The intersection with the feature's 36 paths is empty; the reviewed base remains an ancestor, and git merge-tree reports a clean merge against current main.

Builds on timeout-salvage work from NousResearch#52511 and implements the preventive budget-warning contract from NousResearch#54153.

Co-authored-by: Daniel Maly <maly.daniel@protonmail.com>
@GravityTone
GravityTone marked this pull request as draft July 18, 2026 14:43
@alt-glitch alt-glitch added type/feature New feature or request comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cli CLI entry point, hermes_cli/, setup wizard comp/cron Cron scheduler and job management comp/gateway Gateway runner, session dispatch, delivery comp/plugins Plugin system and bundled plugins comp/tools Tool registry, model_tools, toolsets P3 Low — cosmetic, nice to have needs-decision Awaiting maintainer decision before any implementation sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades labels Jul 18, 2026
@GravityTone
GravityTone force-pushed the feat/kanban-token-budget-optimizer branch from 31a5333 to efa7a99 Compare July 18, 2026 14:59
@GravityTone
GravityTone marked this pull request as ready for review July 18, 2026 15:00

@teknium1 teknium1 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the substantial recovery and ownership hardening work. The current main path still lacks the run-id guard in agent/turn_finalizer.py:109-131, so the underlying Kanban recovery premise remains valid.

Problems

  • Blocking: agent/agent_runtime_helpers.py:422-425 now removes every underscore-prefixed message field before the provider path. The PR uses that copy for every request in agent/conversation_loop.py:979. This removes _anthropic_content_blocks, but current agent/anthropic_adapter.py:2069-2077 explicitly reads that field to preserve legacy stashed multimodal tool-result blocks. Anthropic requests are built from these transformed messages via agent/chat_completion_helpers.py:859-869, so the compatibility path loses its image/content blocks.

Suggested changes

  • Preserve _anthropic_content_blocks until Anthropic conversion, or restrict early stripping to known bookkeeping markers and retain generic transport sanitization afterward.
  • Add an Anthropic request-path regression test for a tool message containing _anthropic_content_blocks.

Automated hermes-sweeper review.

if content
else repaired_user_prefix
)
for internal_key in [

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: this blanket underscore-key removal also drops _anthropic_content_blocks. The Anthropic converter explicitly consumes that back-compat field in agent/anthropic_adapter.py:2069-2077, and this helper is now used before provider conversion at agent/conversation_loop.py:979. Preserve that field until Anthropic conversion (or narrow this filter) and add a request-path regression test.

@teknium1 teknium1 added sweeper:risk-caching Sweeper risk: may break/degrade prompt caching or cache-key stability (invariant) sweeper:blast-massive Sweeper blast radius: massive — everyone, every turn (invariant surface) labels Jul 19, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cli CLI entry point, hermes_cli/, setup wizard comp/cron Cron scheduler and job management comp/gateway Gateway runner, session dispatch, delivery comp/plugins Plugin system and bundled plugins comp/tools Tool registry, model_tools, toolsets needs-decision Awaiting maintainer decision before any implementation P3 Low — cosmetic, nice to have sweeper:blast-massive Sweeper blast radius: massive — everyone, every turn (invariant surface) sweeper:risk-caching Sweeper risk: may break/degrade prompt caching or cache-key stability (invariant) sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state type/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants