Keep authenticated verified OpenRouter usage frames in the known subtotal even when transport fails, without certifying complete cost or token totals. Cover the real pinned SDK interruption plus a successful retry and update both reviewed runtime closure pins.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Hash all three Hermes setup inputs. Keep the PR below the review limit by moving the unchanged public setup and account-cache test files to the stacked qualification follow-up.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Refresh both source-owned native parent pins for the sandbox payload change. Retain the prior reviewed interpreter and dependency entries; only tool_process.py changes.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Derive platform pins from previously verified manifests with only tool_process.py changed. Require fresh cloud materialization and retain the prior concurrent-write failure.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Provide the minimal bubblewrap device mount for native shell redirects and atomic writes, probe it before credential staging, and cover concurrent writes plus protected paths.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Preserve flat Runner acknowledgement receipts so native steering emits one
transcript item. Add a pinned Hermes regression across Rust PRP with distinct
durable and provider turn identities and stale-control rejection.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Cover native edit approval within the authorized invocation and record bounded,
versioned tool grants per conversation. Recheck policy and cancellation before
each operation. Restore named custom connections through their configured
identity and reject native route fallback. Bind assigned skill contents across
temporary lease replacements while preserving their write protection.
Qualify real native once/deny/session file effects, provider restart, distinct
same-name tool identities, conversation isolation and unanswered permission
cancellation with the credential-free production ACPX fixture. Update the
reviewed platform closure pins and document the remaining release gates.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bind usage to the admitted native session and turn before cancelled prompt settlement. Check its durable PRP carrier and harden qualification receipt identity and budget capture.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Use the canonical question converter for durable fallbacks. Retire pending native input only on its confirmed cancelled turn. Pass cancelled status to shared account and billing checks and retain the original browser acknowledgement before polling.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Build both native targets on standard cloud runners. Keep fixtures credential-free, validate host and binary architecture, and publish exact source, runtime, tool and binary provenance for acceptance without local Rust builds.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Extend the managed human-input boundary to confirmations and checkbox
confirmations. Preserve native receipts before controller parking and
cover immediate shutdown for all three canonical input kinds.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Return the committed question to Hermes before publishing the tool bridge's
own completion fact. Hold that fact until native terminal delivery, after
final prompt usage. Keep other harnesses on their existing order and treat a
typed already-terminal passive interrupt as settled cancellation.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Stop native Hermes at a committed assigned question. Preserve final prompt
usage before its completed tool result reaches the controller cancellation
boundary. Keep ordinary tools streaming and add an immediate-shutdown native
regression with pinned runtime closure updates.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Capture pinned SDK wire attempts, carry closed versioned receipts through ACPX and PRP, and bind reported subtotals to native turn accounting. Keep incomplete attempts unpriced and require settled cost plus budget health in the live OpenRouter oracle.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Give Hermes native session opening a 60-second bound for verified private
runtime copying and ACP initialization. Allow controller startup and per-turn
restoration overhead while preserving ordinary command and stop deadlines.
Add delayed-admission regressions and credential-free Linux native fixture CI.
Record the failed final-head paid campaign without promoting qualification.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Count serialized message, attachments, and metadata before turn admission. Keep TypeScript and Rust on a 7 MiB encoded content allowance within the existing encrypted frame bound. Validate before active-turn state changes, and prove accepted images and escaped documents traverse the secure PRP command frame.
Validation: 28 attachment/permission tests, two encrypted-frame regressions, the Rust encoded-admission regression, and Runner TypeScript compilation passed.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Qualification exposed denied plan workflows, missing structured tool output, and cancellation replay in subsequent turns. Admit assigned control-plane operations through their existing semantic authority, project denied native calls by identity, and keep managed history restoration separate from transcript replay.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Require the caller-verified target lock checksum instead of an incompatible checked-in default. Document lock-bot ownership and the companion browser qualification PR.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep history reconstruction without publishing restored text and tools as live output. Version the changed Cursor contract as profile 16 and retain replay compatibility.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reject replaced learned-state parents, include authenticated run attachment and the advertised native transport fixtures in this candidate. Keep paid browser campaign definitions in the qualification PR.
Co-Authored-By: Paperclip <noreply@paperclip.ing>