Files
orca/src/shared/nested-worker-depth.ts
T
Brennan Benson 9135b6f004 feat(orchestration): surface nested worker depth and propagate it across hosts (#16669)
* feat(orchestration): surface nested worker depth and propagate it across hosts

Builds on the depth enforcement in the previous commit, which shipped with the
setting reachable only by editing settings.json and with workers never told they
could nest.

Adds the Settings -> Agents control (a 1/2/3 select rather than a free-form
number, which bounds the value without inventing a numeric input primitive). The
key stays absent from the SettingsUpdate RPC schema, matching agentSkillSharingEnabled:
settings.update is reachable from the CLI, so an RPC-writable depth would let a
worker raise its own cap.

Adds a SUB-DISPATCH block to the dispatch preamble, emitted only when the worker
actually has budget left. A worker told it "usually cannot" delegate still tries and
then reports the refusal as a blocker, so the section is omitted entirely rather
than softened.

Propagates depth to federated worker hosts. Previously the home side computed and
stored a depth the remote host never received, so a remote attachment always read
as depth 1. That is correct at the default cap and wrong as soon as the cap is
raised — precisely when someone starts relying on nesting. The field is optional,
so an older Run home simply omits it and the attachment's NOT NULL DEFAULT 1 keeps
the fail-closed behaviour. Enforcement still runs on the executing host against
that host's own cap, consistent with the SSH execution boundary.

* fix(orchestration): close nested depth readiness gaps

* fix(settings): defer nested depth translations

* fix(orchestration): drop federated depth keys that main already landed

The enforcement PR's review pass added the same federated depth propagation
before it merged, so replaying this branch onto main produced duplicate object
keys. Keep main's versions -- its schema entry validates an integer >= 1 rather
than any finite number.

* fix(settings): label nested worker depth select

* fix(settings): move nested depth to orchestration

* fix(settings): refine nested depth placement
2026-08-26 16:16:05 -07:00

43 lines
1.6 KiB
TypeScript

import type { GlobalSettings } from './global-settings-types'
/**
* How deep dispatched workers may nest. 1 means a coordinator dispatches
* workers and those workers may not dispatch further — the behaviour Orca
* documented but never actually enforced.
*/
export const NESTED_WORKER_MAX_DEPTH_DEFAULT = 1
/** Root coordinators are depth 0; the first generation of workers is depth 1. */
export const ROOT_DISPATCH_DEPTH = 0
export const NESTED_WORKER_DEPTH_EXCEEDED_CODE = 'nested_worker_depth_exceeded'
export function nestedWorkerDepthExceededMessage(childDepth: number, maxDepth: number): string {
// Why "complete this task yourself": a refusal alone leaves the worker looping
// on a capability it will never get.
return (
`Sub-worker dispatch is not permitted at depth ${childDepth} (max ${maxDepth}). ` +
'Complete this task yourself.'
)
}
export const NESTED_WORKER_DEPTH_EXCEEDED_NEXT_STEPS: readonly string[] = [
'Do the work in this terminal instead of dispatching a sub-worker.',
'To allow deeper nesting, open Settings → Orchestration in the Orca desktop app and raise "Nested worker depth".'
]
/**
* Clamp to a usable integer. Anything that is not a safe whole number >= 1 falls back
* to the default rather than disabling the fence: a malformed setting must not
* be a way to get unlimited nesting.
*/
export function resolveNestedWorkerMaxDepth(
settings: Pick<GlobalSettings, 'nestedWorkerMaxDepth'> | null | undefined
): number {
const raw = settings?.nestedWorkerMaxDepth
if (typeof raw !== 'number' || !Number.isSafeInteger(raw) || raw < 1) {
return NESTED_WORKER_MAX_DEPTH_DEFAULT
}
return raw
}