Repository navigation
Releases: mastash3ff/taskspindle
Release list
TaskSpindle v0.4.0
-
Native extra usage. Exact-profile
provider_managedopt-in permits bounded native
OAuth extra usage under provider account controls;observe_onlyremains the default.
API-key authorization stays separate. No provider switching or billing-setting changes. -
Quota-failed continuation. Eligible tasks resume their original session, model and
retained work with atomic account-scoped admission, fresh authorization checks and durable
refusal evidence. Schema 9 preserves historical billing as unknown. -
Usage visibility. Workers and Usage expose policy, admission, native billing observations
and classification separately from estimated token costs. Live extra-usage billing remains
unqualified; seedocs/native-overage.mdfor activation and qualification guidance. -
Explicit model and effort selection. Built-in Claude and Grok task selections are
forwarded and confirmed after opening or restoring sessions, including bounded Grok
configuration transitions. -
Controlled worker recovery. Codex and the CLI can arm one explicit "Retry next task"
permit against the current account/model refusal evidence. Schema 7 records a single active
permit per shared provider availability key, with a 24-hour deadline, revocation, permanent
task association, and outcome history. Arming and revoking run no provider checks or prompts. -
Bounded initial attempts. Task creation validates grants, provider/model scope and review
independence before atomically consuming the permit. Preparation or startup failure consumes
it. Dispatch and initial prompt admission reject changed refusals and expired permits; future
quota restrictions with a reported future reset and fresh native exhaustion cannot be bypassed.
An explicitly authorized missing-reset throttle remains eligible for its one exact permit. A
successful turn clears only the evidence it tested. Existing continuations remain compatible;ignore_provider_statusis
recognized only to returnLEGACY_OVERRIDE_RETIRED. -
Durable quota windows and post-reset retries. Schema 8 retains every applicable quota window
with scope, model family, reset, source, observation and opaque fingerprint. Changed authentication
context invalidates recovery authorization without clearing restrictions. After reset, aliases of
a shared OAuth seat atomically claim one ordinary retry;QUOTA_RETRY_PENDINGprevents duplicates.
Unaffected model families retain their ordinary capacity and grant eligibility. -
Read-only recovery visibility. Cached capabilities, provider status and the Workers screen
expose evidence revisions, armed/pending recovery, deadlines, associated tasks and outcomes.
The dashboard supplies copyable CLI instructions and adds no recovery mutation endpoint.
Billing remains advisory and separate; scheduled collection stays opt-in and disabled. -
Isolated packaging smoke. MCP smoke tests now pass temporary XDG paths directly to the
child process, preventing a packaging check from opening the installed runtime's database.
TaskSpindle v0.3.0
- Operator console. The local dashboard now opens on a bounded Overview and navigates through
Overview, Tasks, Workers, Subscriptions, and Usage. It adds responsive keyboard-accessible
navigation, aCtrl+K/Cmd+Ktask finder, dark/light/system themes, and packaged local modules
without a CDN. The old#/providerslocation resolves to Workers. - Cached-only dashboard diagnostics.
GET /api/overviewreports global counts plus bounded
active and attention lists. Overview and Workers start no provider processes: Workers projects
cachednative_checkand doctor data, and an absent doctor cache is shown as not run. Explicit
/api/doctorand/api/doctor?live=1requests retain their existing diagnostic behavior. - Native Grok quota check.
capabilities(check_providers=["grok"])and
taskspindle providers --check --provider grokrun a session-free native ACP billing check and
cache its normalized result for five minutes. The installed Grok 1.0.13 path returned a valid
weekly quota/reset observation in live validation; private values stay in the local evidence
ledger. No inference, login, browser, direct HTTP, token read, or CLI upgrade is used. - Conservative quota gating. Only a fresh explicit exhausted native quota adds a temporary
new-task gate. Passed resets, stale observations, unsupported methods, and unknown quota permit
an ordinary attempt unless task-derived account/model evidence still refuses it. The check never
selects a provider, moves a task, clears a refusal, or enables a metered fallback. - Scoped Grok refusals. Grok account state now uses terminal structured provider HTTP status,
plus source-proven terminal xAI retry evidence. Incidental tool errors and unrelated 403 responses
stay unclassified; stored retry diagnostics exclude provider prose and URLs. - Honest MCP annotations. Default
capabilities()remains cached-only. The tool is no longer
marked read-only because its optional provider check writes only the bounded native diagnostic
cache; task records and provider refusal evidence are unchanged.
TaskSpindle v0.2.0
Adds subscription visibility, subscription-aware worker eligibility, native Antigravity support,
and broader task inspection while keeping provider choice and task ownership explicit.
-
Subscription tracking. The dashboard can connect a selected normal Chrome profile through
the Playwright extension and record normalized, account-bound billing observations for ChatGPT,
Claude, Grok, and Google AI. Credentials, payment details, raw provider payloads, and raw account
identities are not stored. Unsupported billing channels and unverified dates remain explicit. -
Lightweight billing follow-up. Scheduled collection is opt-in and disabled by default.
Manual Connect and Refresh remain available; fresh confirmed access-end observations expose
normalized seven-day and one-day warnings without changing worker routing. -
Subscription-aware worker eligibility. Account and model refusals, authentication expiry,
access denial, and elapsed quota resets are projected consistently for coordinators. Successful
use and stale evidence are recorded without clearing newer sibling failures. TaskSpindle does not
migrate an existing task or infer CLI eligibility from browser billing dates. -
Search and compare. Dashboard search matches literal task ID/prompt text, including
Unicode case folding. Candidate diffs sit alongside their reviews, finding links retain focus
through polling, and stale candidate requests are rejected rather than paired with a new diff. -
Repository labels. Usage summaries display registered paths while retaining stable IDs
in JSON and using an ID fallback when a path is unavailable. -
Discovery probes.
discover --probeoptionally initializes installed ACP agents without
authenticating or generating a turn. Per-agent results include useful timeout errors; a failed
probe does not prevent the remaining probes from running. -
Known limitation. Grok continuation succeeded with per-turn usage in the recorded
three-turn verification, but an intermittent direct ACP reload timeout remains unexplained. -
Grok read-only turns use the
read-onlysandbox.strictallowed writes inside the
worktree and, on WSL, denied the/etc/resolv.confsymlink target so the sandboxed agent's
DNS fell back to127.0.0.1: startup settings/catalog fetches always failed (about 45 s of
startup) and a resumed session's first model request failed about half the time with
TURN_TIMEOUT.read-onlyreads everywhere and kernel-denies every write outside~/.grok
and the temp dirs, the worktree included. -
Timed-out turns report transport retries. Grok's
retry_stateupdates are kept as a
bounded, sanitized summary; aTURN_TIMEOUTcarries the retry count and the last retry's
attempt, kind and reason so a transport stall is distinguishable from a slow model. -
Native Antigravity. Reserved OAuth provider
agyuses a separately pinned native CLI
1.1.26 and the existing personal Google login.setup --provider agyinstalls code only;
auth agychecks cached authentication without another ACP browser sign-in. Private CLI
state, masked inherited controls and filesystem isolation enforce consult/review read-only
access and declared implementation scopes. Shell commands run only through TaskSpindle's
external verification step. New tasks select the newest advertised Gemini release, preferring
Flash and Medium effort, and retain that exact selection and conversation on continuation.
Observed tool violations stop the worker; cancellation and failures retain partial results.
Native cumulative usage is converted to per-turn deltas without replaying prior charges. -
Review independence rechecked. Any different built-in provider can review a candidate;
aliases of the author's family are refused. Each new task records an immutable provider family.
Review, acceptance, manual integration and continuation compare that history with current
configuration. Old reserved Claude/Grok IDs remain usable; historical configured tasks with
unknown family fail closed instead of treating today's alias settings as historical evidence. -
Partial ACP failures retained. Cancellation, timeouts and failed turns retain partial
responses, usage and session identifiers. A failed continuation never creates a replacement
conversation. Database schema 3 adds resolved model, effort and provider family; retain a
consistent schema-2 backup before activating this code for rollback to an older runtime. -
Adapter-side delegation denial. Initial canonical delegation tool calls now produce
DELEGATION_ATTEMPTeven when the Claude adapter refuses them before requesting client
permission. A live Claude implement on adapter 0.70.0 attempted the disabledTasktool,
received its denial, and recorded the warning without creating a subagent; its small candidate
passed an independent Grok review and was accepted in a throwaway repository. -
Grok model attribution. New turns prefer the wire model ID, then the backend
modelUsage
key, then the profile model; attribution and usage agree while raw telemetry stays intact. -
Usage by repository.
repository_idgrouping is available in MCP, the CLI and dashboard,
including a null group for repository-free tasks; no migration is needed. -
Recovery choices.
continue_taskcan ask form-capable MCP clients to retry or cancel
ambiguous recovery, while preserving recovery and stale-version checks and the existing error fallback. -
Claude model metadata. Canonical model ids returned by ACP session creation or loading
are preferred over the session file. Aliases and display names retain the existing file fallback. -
Provider availability, reported rather than acted on. A turn a provider refuses for a
usage, rate, credit or login reason is classified (PROVIDER_THROTTLED,PROVIDER_AUTH_EXPIRED)
with the window and reset time the provider gave, recorded on the task, as aPROVIDER_LIMIT
event and in a newprovider_statustable, and surfaced incapabilities, in an advisory
doctorcheck, and as aPROVIDER_UNAVAILABLErefusal of the nextstart_taskon that
provider (ignore_provider_statusoverrides it). Nothing is retried elsewhere: the rule that a
provider is never substituted is unchanged. -
Usage. Token counts are captured per turn from the agents themselves — the Claude adapter's
prompt response and Grok'sturn_completedupdate — into a newturn_usagetable, with an
estimated cost at published rates that is labelled an estimate, and the usage windows the Claude
adapter reports intoprovider_windows. New read-only toolusage_report, new command
taskspindle usage, andtask_resultnow carriesusage,warningsand structured
quota_warnings. -
Dashboard.
taskspindle webserves a read-only page on localhost: tasks, timelines,
transcripts, diffs, reviews, provider availability and the usage report. The database is opened
read-only and there are no mutation endpoints. -
Attribution fixed.
reported_model,gateway_hostand the adapter'sagentname and
version are now filled in; they were always null before. -
task_diffdefaults to 16384 bytes (the maximum stays 262144), because an MCP client
truncates tool output at its own token limit and a receipt for a truncated page proved nothing. -
Orphans can be cleaned.
cleanup_taskwithforceremoves the worktree of a task whose
repository no longer exists, andrevoke_repositoryaccepts arepository_idfor a repository
that no longer has a path. -
Read-only turns are enforced by the agents themselves. A Claude worker is put in the
adapter'splansession mode for a consult or a review and indefaultmode for an implement,
so the permission gate is consulted instead of the operator's ownbypassPermissionssetting; a
Grok consult or review runs inside--sandbox strict, the one flag that makes its writes ask.
A request to switch mode is refused and recorded asMODE_SWITCH_ATTEMPT; an agent that refuses
the mode fails the turn withMODE_UNAVAILABLE. -
Reviewers are shown the diff. A review prompt carries the candidate's recorded diff (or the
snapshot'sgit diff), cut at 96 KiB, so a reviewer that cannot run git still sees the change. -
taskspindle discoverlists the ACP community registry's agents that are installed here and
prints a[providers.<id>]proposal for each; nothing is downloaded, run or written. -
Schema version 2. The migration is applied on the next open.
TaskSpindle v0.1.0
First release.
- MCP server (
taskspindle mcp): sixteen tools over stdio, one envelope for success and
failure alike, stable error codes, honestreadOnlyHintannotations, and tracebacks written to
the state directory rather than into the conversation. - Three modes:
consult,reviewandimplement, each in its own detached git worktree.
Candidate commits live underrefs/taskspindle/<task_id>/rev/<n>and never on a branch you use. - Two first-class providers, both OAuth-only:
claudethrough the pinned
@agentclientprotocol/claude-agent-acp0.70.0 adapter, andgrokthrough the native Grok CLI
1.0.13 ACP endpoint. Both are launched with delegation, MCP servers and external settings
disabled. - Second-class configured profiles from
config.toml: any ACP stdio agent, including an
API-key or LiteLLM-gateway harness. Never a default, never a fallback, gated behind
allow_metered, with attribution recorded on every task. - Acceptance you have to earn: the whole diff retrieved and receipted, an independent
reviewer's verdict on that exact candidate, an explicit override for every blocking or critical
finding, verification passing in the worktree and again in the root repository, and a
git merge-treeprobe before anything is applied. Every step is journalled, so an interrupted
acceptance is recognisable and reversible. - Durable workers: one turn per transient systemd user unit, heartbeats in SQLite,
SIGTERM
to ACPsession/cancelfor cancellation, and an explicitsession/loadfor every continuation. - Recovery that retains work: a vanished worker leaves an
INTERRUPTEDtask with its worktree,
session and candidate intact; a situation that cannot be settled becomesRECOVERY_AMBIGUOUS
and waits for a person rather than guessing. - Violation reporting:
SCOPE_VIOLATION,READ_ONLY_VIOLATION,ROOT_MUTATIONand
DELEGATION_ATTEMPTare recorded and block acceptance until resolved or acknowledged. taskspindle setupinstalls the pinned adapter from a shipped lock file with
npm ci --ignore-scripts, in an environment holding onlyPATH,HOMEandLANG. It never
logs in, never copies a credential and never edits Codex's configuration.taskspindle doctorchecks git, the systemd user manager, a transient unit, Node, the pinned
adapter, both provider logins, every profile's command and child environment, and the Codex
registration — one question at a time, so a fresh machine gets the whole list.- Documentation: install, Codex registration, the tool reference, configuration, platforms,
architecture, recovery and rollback.
Supported on Linux and WSL2 with a systemd user manager. Python 3.12+, Node 22+, git 2.38+.