Commit Graph
4783 Commits
Author SHA1 Message Date
DottaandPaperclip 9138f570c3 Align native qualification docs with the integrated 29-cell catalog
Record the two classic document repair cells and preserve the distinction between original native grades and analytical regrading.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:51 -05:00
DottaandPaperclip de487b20d3 Fix blocker browser grading and retain the complete native comparison
Accept the requested marker plus concrete blocker explanation, calibrate contradictory and future-condition replies, and clarify future fixture punctuation. Preserve every original paid failure and label retained-DOM replay separately from live qualification.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:51 -05:00
DottaandPaperclip be63fb52b3 docs(evals): publish first native completion result and pending matrix
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:51 -05:00
DottaandPaperclip c7a17d9396 test(evals): require a useful visible native blocker explanation
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:51 -05:00
DottaandPaperclip ec89bb5b17 test(evals): qualify native blocked reports with persisted outcomes
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:51 -05:00
DottaandPaperclip 3ab0178c34 Record native completion guidance verification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:22 -05:00
DottaandPaperclip d86953469a Clarify native Runner completion tool guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:08:22 -05:00
DottaandPaperclip 36aa4d81c4 docs: track merged hiring templates and frozen qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:06:50 -05:00
DottaandPaperclip a7d6aa682b Support unnumbered issues in the document link recipe
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip 2df0a03b20 Derive document handoff links from the current issue and saved key
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip c596787a98 Retain matched OpenCode routing results and original handoff defects
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip 5f868ab2f4 Route legacy task work to the operational skill and show clickable delivery
Use stock discovery metadata and an actual Markdown document-link example. Clarify the future explicit UI-link fixture and retain the original task request and all measured failures.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip 6c0e5cf47b Use one declared skill source list for both capability inventories
Include the issue-document reference in the normative inventory and calibrate coverage of every declared source without changing each inventory’s existing heading parsing scope.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip 2e50618b80 Fix skill capability metadata and publish the bounded repair comparison
Regenerate both capability inventories for the early issue-document recipe and reject stale derived manifests before stock-harness provider admission. Preserve the eight measured repair results, automatic recovery cost, and OpenCode delivery diagnosis.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip a1ee8832a9 Clarify legacy issue document delivery in the operational skill
Preserve the tiny hire manual and original assigned-skill case. Add a focused public document/revision/link oracle and explicit presence/absence provenance for a matched skill-only comparison.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:42 -05:00
DottaandPaperclip f6885253de docs(evals): keep timeout document outcomes unknown
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 9e0df9098c docs(evals): close the unchanged-source baseline recovery
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 1f54c3b75a docs(evals): retain matched stock-harness results and failures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip c08fcc157f fix(evals): retain prerequisites inside the campaign artifact root
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 2e26dbf732 fix(evals): use complete Rust protocol test preparation
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 6eb4e5a9e5 fix(evals): bind protocol evidence to the built daemon
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 782f66982a fix(evals): build the cold daemon before protocol prerequisites
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 4ffc55b90a fix(evals): prepare cold prerequisites and fingerprint connection guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 47bb034793 test(evals): enforce exact-source stock harness prerequisites
Run credential-free gates before live admission and verify retained evidence in direct browser execution. Include evaluated instruction sources in suite revisions and calibrate stale/missing evidence rejection.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 1f3c2efa98 test(evals): cover production default hires across stock harnesses
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:05:18 -05:00
DottaandPaperclip 8a5375520e fix(agents): reduce default manual and shared legacy guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 18:04:30 -05:00
DottaandPaperclip 862a5758ba fix(agents): reduce hiring templates to role descriptions (#14985)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for work.
> - New agents receive role instructions from onboarding, the hiring skill, or a team package.
> - These sources repeat harness procedures and impose generic work policies.
> - They can crowd out the task and the harness instructions.
> - This pull request reduces those sources to short role descriptions.
> - It preserves configuration, skills, authentication, reporting lines, and approval controls.
> - The benefit is less repeated instruction text with explicit coverage for the default hiring path.

## Linked Issues or Issue Description

Refs #3307. The CEO template can impose a fixed delegation route instead of letting the agent choose how to fulfill the request. This change removes that route. It does not implement autonomous goal selection.

Related work: #14920 preserves stock Codex base instructions. #14948 reduces the generic manual and shared runtime prompts. #14961 improves native completion-tool descriptions. This PR is separate from those changes.

## What Changed

- Select only the short CEO `AGENTS.md` for new default CEO bundles. Keep the three former companion files as compatibility assets.
- Reduce the first-agent chief-of-staff prompt and coder, QA, UX, and security role examples.
- Reduce seven bundled team role bodies. Preserve their role, reporting, and skill metadata. Regenerate the catalog.
- Make hiring examples optional. Replace the long generic role manual with short role drafting guidance. Preserve explicit requester instructions.
- Add configuration and import coverage for native and legacy managed bundles, custom instructions, first-agent rendering, and catalog contents.
- Add an explicit-only hiring eval that starts from the production CEO default and checks one coder hire, independently computed JSON output, saved instructions, and worker reuse.
- Include the full prompt comparison and a separate three-request drafting simulation. Neither is a live provider comparison.

Prompt differences: [before and after](doc/plans/2026-10-02-hiring-template-prompt-diff.md). The CEO default falls from 1,897 to 20 words. The coder example falls from 652 to 18 words. Word counts describe instruction size, not outcome quality or billing.

## Verification

- PASS: 99 focused server tests and eight shipped-catalog tests.
- PASS: catalog generation and validation for four shipped teams.
- PASS: hiring skill validation.
- PASS: `pnpm -r typecheck`.
- PASS: `pnpm build`.
- INCOMPLETE: the full local `pnpm test:run` was stopped before rebase. Its original log is retained. This is not a completed full-suite pass. The full current-head GitHub CI workflow passed: https://github.com/paperclipai/paperclip/actions/runs/37073372419.
- PASS: `pnpm test:e2e:runner:typecheck` and `pnpm test:e2e:runner:unit` (63 files / 843 tests).
- PASS: discovery for the two new hiring cells, 50 existing everyday cells, and the full 438-cell catalog.
- PASS after rebase: 99 server tests, 11 catalog tests, 62 selected E2E support tests, and the E2E typecheck.
- PASS: all current-head PR checks at `57dcee147ed0b2d2e3cc657cd9e50fb16bf9ec25`: 51 successful check runs, two intentional Storybook skips, and successful Snyk status. Fresh Greptile is 5/5 with zero unresolved threads.
- PENDING follow-up: matched live hiring runs on frozen integration refs. No live outcome-quality or non-regression result is claimed from the configuration checks or this merge.

The new suite has two local native cells: Codex and ACPX Claude. It expects five provider turns per cell. It compares source-derived bundles, so the historical long templates remain admissible. Missing successful source-read receipts make a pair uncomparable. They do not establish a behavior regression or equivalence.

## Risks

- New default roles have fewer prescribed procedures. Live checks must determine whether a removed instruction was needed for an outcome.
- Existing custom and saved bundles keep their contents. The retained companion assets avoid a source-file compatibility break.
- Specialized Summarizer, Reflection Coach, and Wiki Maintainer prompts remain unchanged. Their product contracts need separate review.
- The generic non-CEO fallback reduction is in #14948. This PR alone does not provide its eight-word fallback.
- Configuration tests and drafting simulations do not establish live outcome quality. QA, UX, security, and chief-of-staff hiring behavior remain outside the new two-cell comparison.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, based on GPT-6, with reasoning, code editing, shell tools, and delegated verification. The runtime does not expose the exact deployment model ID or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context to this change
- [x] I have specified the model used (with version and capability details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before requesting merge

Co-Authored-By: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.20
2026-10-02 17:56:42 -05:00
DottaandPaperclip 6eaf218924 chore: grant Storybook publishing access through CODEOWNERS (#14984)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Storybook previews help contributors review the board UI.
> - The publishing workflow uses the default branch CODEOWNERS file to
authorize users.
> - Tonio and Scott need access to this workflow.
> - This pull request adds both accounts as release documentation
owners.
> - The existing workflow can then authorize both accounts without a
separate user list in code.

## Linked Issues or Issue Description

**What existing behavior does this improve?**

Access to the Storybook build and publishing workflow.

**Subsystem affected**

Repository ownership and GitHub Actions authorization.

**Current behavior**

The workflow reads individual accounts from every CODEOWNERS rule on the
default branch. Neither `tonio-alucema` nor `scotttong` is in that file.
Both accounts already have repository admin access, but the workflow
authorization check denies them.

**Proposed behavior**

Add both accounts to the `doc/RELEASING.md` ownership rule. After merge,
both can start and rerun Storybook publishing workflows. A configured
`storybook-deploy` environment reviewer must still approve deployment.
CODEOWNERS membership does not add an account to the environment
reviewer settings.

**Reason and benefit**

Contributors can publish UI previews through the same CODEOWNERS policy
as other maintainers. The authorization code has no account-specific
exceptions.

**Breaking changes**

None. The existing authorization and deployment approval checks remain
in place.

**Additional context**

Related changes: #13226 added the publishing workflow. #13231 added
stable branch bookmarks. A search found no open PR for these permission
changes.

## What Changed

- Add `@tonio-alucema` and `@scotttong` only to the release
documentation ownership rule.
- Test that accounts listed for release documentation can start and
rerun publishing workflows.
- Test that removing an account from CODEOWNERS removes its publishing
access.
- Explain how CODEOWNERS entries and environment reviewers affect
publishing access.

## Verification

- `node --test scripts/__tests__/storybook-deploy.test.mjs`: all 25
tests pass.
- `actionlint .github/workflows/storybook-deploy.yml
.github/workflows/storybook-visual.yml`: passes.
- `git diff --check`: passes.
- GitHub API checks confirm that both accounts have repository admin
access. The deployment environment requires an existing reviewer and
disables administrator bypass.
- Repository-wide typecheck, tests, and build were attempted. They
cannot complete in this worktree because workspace dependencies are not
installed. Typecheck cannot find Node type definitions. Tests and build
cannot load the workspace `tsx` package.
- After merge, run `Storybook Deploy` from `master`, select a source
branch, obtain environment approval, and check the published URLs in the
run summary.

## Risks

Both accounts gain permission to start and rerun Storybook publishing.
Deployment still needs approval from a configured environment reviewer.
No AWS permissions or live GitHub settings change in this PR.

## Model Used

OpenAI GPT-6 through Codex. The exact backend model ID and context
window are not exposed in this session. The agent used reasoning,
repository inspection, code editing, shell execution, and GitHub API
tools.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.19
2026-10-02 17:34:37 -05:00
Devin FoleyandPaperclip 22cea6b2e6 fix: bound sandbox bridge waits and flag silent runs sooner (#14979)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Sandbox agents exchange input and output through bridge control
commands.
> - A provider can stop responding to a command even when it receives a
timeout.
> - These small commands can inherit a four-hour agent lifetime and
block input or teardown.
> - The board also calls a silent run healthy for the first hour.
> - This pull request bounds bridge control waits and surfaces silence
sooner.

## Linked Issues or Issue Description

**What happened?**

A sandbox run can remain active when a bridge control command never
returns. The shared helper passes a timeout to the provider but does not
enforce it on the host. It also accepts the agent's hours-long timeout.
Output silence remains `ok` for an hour and becomes `critical` only
after four hours.

**Expected behavior**

Bound short bridge operations even if the provider never settles. Report
failed input delivery through the existing shutdown path. Warn after
five silent minutes and escalate after fifteen. Keep normal agent
command limits and require verified termination before releasing
execution ownership.

**Steps to reproduce**

1. Use a sandbox runner whose bridge read or input-upload promise never
settles.
2. Set its configured timeout to four hours.
3. Observe that the old queue client never returns or rejects.
4. Inspect a running task with 35 minutes of output silence. The old
summary still reports `ok`.

**Paperclip version or commit**

Base commit `d6d88b9de2`.

**Deployment mode**

Self-hosted server with sandbox execution.

**Agent adapter(s) involved**

Shared command-managed sandbox bridge, including Codex ACP sessions. The
informational silence thresholds apply to active runs across adapters.

Related: #14889 recovers stalled Daytona output streams; #14485 retries
explicit gateway failures during input delivery. This change bounds
short control operations whose provider promises never settle. It does
not add tool replay or automatic cancellation for output silence. #6297
proposes configurable per-agent silence thresholds; this patch only
changes the existing defaults.

## What Changed

- Enforce at most 30 seconds per bridge control shell command on the
host and provider, including callback startup and shutdown,
process-session launch, and payload setup. Preserve shorter configured
deadlines and launch environments.
- Keep the long-lived agent command outside this deadline. Use a fixed
timeout diagnostic without command payloads.
- Surface suspicious output silence after five minutes and critical
silence after fifteen minutes.
- Decouple the shared-workspace holder cutoff from warning thresholds
and preserve its existing one-hour value.
- Add regressions for hung reads, a late upload response, failed input
delivery, exact warning boundaries, and fresh output clearing warnings.
- Update the adapter guide and execution contract.

## Verification

- The three new queue-client regressions fail on the unchanged base and
pass with this patch.
- Final callback bridge and sandbox session suites: 214 passed. These
cover hung reads, writes, startup, shutdown, process-session launch,
payload setup, and the separate long-running agent limit.
- Stdin ordering and shutdown suite: 56 passed after the lifecycle
change.
- Daytona and watchdog coverage passed in the earlier focused runs.
Across the focused suites, 602 distinct tests pass.
- `pnpm -r typecheck` and `pnpm build`: passed. Server and adapter
typecheck/build also passed after their respective follow-up changes.
- `pnpm test:run`: attempted and stopped after known local failures.
Four chat/email cases used an external ancestor skill path, three
skill-cache cases failed on macOS, and one wakeup case timed out. The
wakeup case passes alone (1 passed, 27 skipped). This run spanned the
workspace-cutoff follow-up and also failed its new holder case; a fresh
final-head workspace suite passes all 19 tests. The interrupted run is
not a full local-suite pass or final-head verification.
- A filesystem queue-drain test failed once during the lifecycle rerun
and passed on the complete two-suite rerun. It uses the filesystem
client, outside the changed command-runner path.
- Complete CI on `ff2212c235`: 53 successful checks and two expected
skips, including the full test suite and canary packaging dry run. No
failed or pending checks.
- Greptile reviewed `ff2212c235` at 5/5. All review findings are
addressed, no threads remain unresolved, and the branch has no merge
conflicts with `master`.
- `git diff --check` and a scan of added text for secrets and private
identifiers passed.

## Risks

- A bridge control operation that needs more than 30 seconds now fails,
even if the caller selected a longer run lifetime. Agent commands retain
their own limits.
- Timing out a provider promise does not cancel the remote operation or
prove it stopped. Existing execution settlement still owns termination
verification. No uncertain tool action is replayed.
- Quiet healthy runs display warnings sooner. Existing snooze, continue,
and false-positive dismissal controls still apply. Silence alone does
not cancel a run, create review work, or change assignments.
- No schema or API shape change.

## Model Used

OpenAI GPT-6 through Codex, with tool use and code execution. The exact
serving model ID and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run change-specific tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 15:29:41 -07:00
DottaandPaperclip d7bdfc422c fix(ui): show agent avatar and align chat header controls (#14726)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - Agent chat shows which agent receives each message.
> - The chat header used initials instead of the agent avatar.
> - The name and controls did not use the same center alignment.
> - This change uses the shared avatar and centers the header content.
> - Users can identify the agent and open its settings from the same
row.

## Linked Issues or Issue Description

**What happened?**
The agent chat header showed initials instead of the agent avatar. The
settings control did not align with the name and avatar.

**Expected behavior**
Show the agent avatar. Put the avatar, name, and settings control on the
same horizontal center line.

**Steps to reproduce**
1. Enable Agent Chat in Experimental settings.
2. Open a conversation with an agent that has an appearance set.
3. Check the avatar and settings control in the top bar.

Related navigation work: #14706.

## What Changed

- Use `AgentAvatar` in the conversation breadcrumb.
- Update the breadcrumb key when the agent appearance changes.
- Center breadcrumb labels that have an adjacent action. Keep task
identifier baseline alignment unchanged.
- Add regression checks for avatar props, appearance changes, and center
alignment.

## Verification

- PASS: affected Vitest suites, 129 tests.
- PASS: `pnpm check:token-gates`.
- PASS: `pnpm --filter @paperclipai/ui typecheck` on an isolated retry.
- PASS: `pnpm --filter @paperclipai/ui build`.
- PASS: browser checks at 1000 and 390 CSS pixels. Avatar, name, and
settings control all have center Y = 29.5 CSS pixels.
- Screenshots use the real header and avatar renderer with isolated
context fixtures. No screenshot or fixture is part of this diff.
- Full typecheck and build cannot complete because Cargo is not
installed.
- Full tests stopped with SIGKILL. The first UI typecheck also stopped
with exit 137. These runs do not prove full-suite success.

## Risks

- Low risk. The change only affects UI rendering. It changes no API or
database contract.
- Breadcrumbs with adjacent actions now use center alignment. Ordinary
task identifiers keep baseline alignment.

## Model Used

OpenAI Codex agent, with code editing, shell tools, and browser checks.
The runtime did not expose the exact model ID or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [ ] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

No behavior or command documentation needs an update for this rendering
fix. The execution environment requires the assigned branch name to stay
unchanged. Pending review gates are not marked complete.

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 22:06:50 +00:00
Devin FoleyandPaperclip 5b8b2b38ca feat(apps): add Neon connection (#14980)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents reach external services through the Apps catalog. Each
catalog entry is a reviewed `AppDefinition` that wires a provider's
hosted MCP server into Paperclip's shared vault, grants, policies,
gateway, and audit trail.
> - Neon is a widely used serverless Postgres provider with an official
hosted MCP server, but it is not in the catalog. Teams that run their
databases on Neon must use the generic "connect your own MCP server"
path, which has no branding, no guidance, and no project or read-only
controls.
> - The connector playbook requires a catalog entry for a provider like
this: the hosted server supports dynamic client registration and bearer
API keys, and the common definition fields can express every option
Paperclip can serialize.
> - This pull request adds the Neon definition, its official artwork,
the research and permission-review ledger rows, documentation, and
deterministic tests, without any provider-specific runtime code.
> - The benefit is a one-click, governed Neon connection with optional
project pinning and read-only mode, and a documented path to live
qualification.

## Linked Issues or Issue Description

**Problem or motivation**

Neon is a common Postgres host for the applications agents work on, but
Paperclip's Apps catalog has no Neon entry. Operators who want agents to
inspect schemas, run SQL, or manage branches must paste the MCP URL into
the generic remote-MCP flow, which gives no branding, no provider
guidance, no project boundary, and no read-only switch.

**Proposed solution**

Add a catalog-only Neon connection built from the connector playbook:
browser sign-in through Neon's dynamic client registration with the
reviewed `read` and `write` scopes, or a customer API key sent as an
Authorization bearer header. Both methods expose Neon's documented
`projectId` pin and `readonly` switch as optional Advanced fields. Every
discovered tool stays governed by the normal per-action policies.

**Alternatives considered**

A plugin was not needed because no custom UI, tables, workers, or
webhooks are involved. A separate read-only method was not added because
the playbook treats read-only switches as advanced fields rather than
methods. Neon's repeatable `category` query filter was left out because
tenant fields serialize lists as one comma-joined value, so it cannot be
sent correctly without new runtime code; per-action policies cover
catalog narrowing instead.

**Roadmap alignment**

This extends the existing self-serve remote-MCP connection catalog and
does not overlap planned core work.

## What Changed

- Added the `neon` provider to `scripts/ingest-app-definitions.mjs`
(category, API-key placement, methods, tenant fields, guidance,
warnings) and regenerated
`packages/shared/src/app-definitions/neon.json` plus the generated
registry.
- Added the Neon row to the self-serve MCP research ledger with
`dcr_or_api_key` auth and risk tier S4.
- Added permission reviews for `neon/mcp-oauth` (explicit scopes `read`,
`write`, taken from Neon's live authorization-server metadata) and
`neon/mcp-api-key` (provider key), with evidence links.
- Added Neon's official tile icon (`ui/public/brands/apps/neon.png`,
copied byte-for-byte from the icon linked by neon.com) and the brand
manifest entry.
- Added prosumer gallery copy for the Neon card.
- Added `doc/connections/NEON.md` (service involvement, endpoints,
administrator setup, capabilities and policy, manifest, brand
provenance, validation hook) and linked it from the connections README
and the permission audit.
- Tests: Neon definition shape, store visibility and artwork, URL
recognition, reviewed scopes with scope-widening rejection, URL
projection of the project pin and read-only flag, invalid project ID
rejection, the connect form's API-key gating, and the pinned catalog
counts.

## Verification

- `pnpm exec vitest run packages/shared/src/app-definitions.test.ts
packages/shared/src/app-definitions-url.test.ts` — 34 passed.
- `pnpm exec vitest run
server/src/__tests__/tool-access-service.test.ts` — 367 passed.
- `pnpm exec vitest run ui/src/pages/apps/AppsConnect.test.tsx
ui/src/pages/apps/Browse.test.tsx ui/src/lib/app-brand-assets.test.ts
ui/src/pages/apps/AppLogo.brand-assets.test.tsx` — all passed.
- `node scripts/check-app-brand-assets.mjs` and `node --test
scripts/app-brand-validation.test.mjs` — passed.
- `pnpm --filter @paperclipai/shared typecheck`, `pnpm --filter
@paperclipai/server typecheck`, `pnpm --filter @paperclipai/ui
typecheck`, `pnpm check:token-gates` — clean.
- Manual: in a local instance, open Apps → Browse, confirm the Neon card
and icon, open `/apps/connect?source=neon`, confirm both methods, the
Advanced project pin and read-only toggle, and that Connect enables
after an API key is entered. The operator completed a live connection
against a Neon account on this build.
- Live metadata probed on 2026-10-02: both `.well-known` documents at
`mcp.neon.tech` return the recorded endpoints and scopes; an
unauthenticated `initialize` returns 401 with `resource_metadata`.

## Risks

- Low risk to existing providers: the change is additive catalog data
plus tests. The generated registry only gains one import.
- Neon's hosted server grants broad project and database management. The
definition carries two warnings, recommends a development project, and
keeps every write under the normal action policies; the read-only switch
is enforced by Neon's server, not locally.
- The permission-review ledger records live proof for both methods as
not run; the full lifecycle checklist in `doc/connections/NEON.md` still
needs a documented pass before the entry is considered fully qualified.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- Claude Fable 5.1 (`claude-fable-5-1`) in Claude Code, with extended
thinking and tool use (shell, file editing, browser verification).

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.18
2026-10-02 15:04:52 -07:00
Devin FoleyandPaperclip d6d88b9de2 fix: preserve run outcomes when agent file cleanup is deferred (#14945)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The heartbeat service records each agent turn and releases its
working files.
> - A turn can save its work and finish before instruction-copy cleanup
runs.
> - A cleanup exception can replace that completed result with an
adapter failure.
> - This also loses result accounting and can prevent environment lease
release.
> - This pull request records a cleanup warning and keeps the original
run outcome.
> - The existing recovery sweep retries cleanup from the durable
working-copy record.

## Linked Issues or Issue Description

Related cleanup and lock work: #14866 and #14869. Related, distinct
work: #14695 retains warm-process files; #12021 handles provider-process
SIGTERM after a terminal result.

**What happened?**

An agent saved its plan, posted a comment, and requested approval. The
provider completed its turn. Instruction-copy cleanup then timed out on
a directory lock. Its exception escaped a `finally` block and replaced
the provider result, so the completed turn showed `Run failed`.

**Expected behavior**

Keep the provider outcome, usage, cost, saved work, and pending
approval. Record a cleanup warning and let the existing recovery sweep
retry. A real provider failure must keep its original error. A failed
file save must keep its failed-save receipt.

**Steps to reproduce**

1. Complete a legacy adapter turn that saves work and requests approval.
2. Make instruction-copy release throw a directory-lock timeout.
3. Read the run result. Before this change, the cleanup error replaces
the provider outcome.

The new heartbeat tests reproduce the failure without a live provider or
external service.

**Paperclip version or commit**

The regression reproduces on `c83df091b1a5207375eaf23466bb5c62e4e1518e`.
This branch is rebased onto `cf8ad63c80`.

**Deployment mode**

Server-managed agent execution with persistent instruction working
copies.

## What Changed

- Catch instruction-copy release failures in both heartbeat teardown
paths. Stop repeating a failed cleanup attempt within the same run.
- Write a sanitized `instruction_cleanup` warning. A warning-write
failure also preserves the run result.
- Test successful, failed, and throwing providers; both teardown paths;
warning-write failure; accounting; approval state; and execution-control
release.
- Extend the held-lock test to prove a fresh recovery worker removes the
deferred copy and preserves its failed-save receipt.
- Document deferred cleanup and the run-log event.

## Verification

- Red proof: all five new heartbeat regression cases fail with the
original release calls.
- At head `20bea4f431c916d2f5db1970213aab85f5daa34c`, all 417 tests
passed across heartbeat process recovery, agent directory working
copies, and directory merge locks.
- Full local `pnpm -r typecheck`, `pnpm build`, and `git diff --check`
passed.
- [GitHub
CI](https://github.com/paperclipai/paperclip/actions/runs/37031119795)
passed at this head. All 53 reported checks passed; the two Storybook
checks were correctly skipped. This includes general and serialized
tests, browser shards, runner verification, build, typecheck, and the
canary dry run.
- Greptile reviewed this head with 5/5, no code comments, and no
unresolved review threads. The branch has no merge conflicts.
- The local `pnpm test:run` attempt was stopped after it reported eight
failures in unchanged suites. Four Slack/AgentMail cases selected an
unrelated ancestor skills directory and failed with `ENOENT`; the two
Slack cases passed with a temporary local skill-root link, which was
then removed. Three company-skill cases reproduced macOS `EACCES` errors
when renaming read-only cache directories. One gateway case passed when
rerun alone. No full local-suite pass is claimed; the complete CI test
jobs passed.

## Risks

- Cleanup errors now leave recovery work pending. The durable
working-copy record remains available for the existing retry sweep.
- This change preserves provider failures and failed-save receipts. It
does not claim that unsaved file edits were saved.
- Native instruction reservation errors retain their existing behavior
because they guard process ownership.
- No schema, lockfile, workflow, API, or UI changes.

## Model Used

OpenAI Codex, based on GPT-6, with reasoning, repository tools, and code
execution. The exact backend model ID and context-window size are not
exposed by this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.17
2026-10-02 14:16:18 -07:00
abderrahmen bejaouiandabderbj d9b64ee28e fix(codex-local): order Codex models the way the ChatGPT app does (stacked on #14917) (#14918)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Each agent runs on an adapter, and the operator picks the agent's
model from the list the adapter advertises.
> - The `codex_local` adapter advertises a static, curated list. The
server returns that list as written, but the list itself is not in a
useful order: the default `gpt-5.6-sol` sits above the whole GPT-6
family (#14878).
> - This pull request orders the list the way the ChatGPT app orders
Codex models: newest model version first, then by decreasing capability
inside each version, with older models at the end.
> - It is stacked on #14917, which makes the model dropdown show a
hand-ordered list as the adapter advertises it. Without that change the
picker shows every list alphabetically.
> - The benefit is that a user who knows Codex finds the right model at
once, and older models sit at the end of the list.

## Linked Issues or Issue Description

Fixes #14878.

Related: #14917 (the Claude counterpart, #14877) carries the dropdown
change this PR relies on. This PR contains that commit until #14917
lands; after that it rebases to the Codex commit alone.

## What Changed

- `packages/adapters/codex-local/src/index.ts`: reorder the advertised
`models` list. GPT-6 (`astra`, `sol`, `luna`) first, then GPT-5.6
(`sol`, `terra`, `luna`), then `gpt-5.5`, `gpt-5.4`, `gpt-5.4-mini`,
`gpt-5`, `gpt-5-mini`, `gpt-5-nano`, then the o-series and
`codex-mini-latest` in their existing relative order.
`DEFAULT_CODEX_LOCAL_MODEL` is unchanged.
- `packages/adapters/codex-local/src/index.test.ts`: the metadata test
now asserts the full order of the GPT entries.

The ChatGPT app also lists GPT-6.1 Sol first. That model is not in
Paperclip's list today. Adding a model needs reasoning-effort and
fast-mode entries as well, so it is out of scope for an ordering fix.

## Verification

Run from the repository root:

```sh
pnpm exec vitest run packages/adapters/codex-local server/src/__tests__/adapter-models.test.ts
pnpm --filter @paperclipai/adapter-codex-local typecheck
```

Red on `master`, green here: the updated metadata test fails against the
unmodified list because `gpt-5.6-sol` comes first.

Manual check: open an agent that uses `codex_local` and open the model
dropdown. The list reads gpt-6-astra, gpt-6-sol, gpt-6-luna,
gpt-5.6-sol, gpt-5.6-terra, gpt-5.6-luna, gpt-5.5, gpt-5.4,
gpt-5.4-mini, gpt-5, gpt-5-mini, gpt-5-nano, o3, o4-mini, o3-mini, Codex
Mini.

## Risks

- Low risk. The list content and the default model do not change; only
the order does. The server returns this list as-is for the built-in
Codex adapter and the server test compares against the exported list, so
no server change is needed.
- The first entry is no longer the default model. Nothing reads the
first entry as a default: `DEFAULT_CODEX_LOCAL_MODEL` is resolved
separately.

## Model Used

Anthropic Claude Fable 5.1 (`claude-fable-5-1`) through Claude Code,
extended thinking on, with tool use for reading the repository, running
vitest and tsc, and editing files. The account holder reviewed the
change and owns the commit.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: abderbj <115119179+abderbj@users.noreply.github.com>
canary/v2026.1002.0-canary.16
2026-10-02 13:32:18 -07:00
abderrahmen bejaouiandabderbj 92ad158ce1 fix(claude-local): order Claude models the way the Claude app does (#14917)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Each agent runs on an adapter, and the operator picks the agent's
model from a list the adapter advertises.
> - The `claude_local` adapter advertises a static list and merges in
the models the Anthropic API returns. Neither list has a deliberate
order.
> - The model dropdown then sorts every list by id. For Claude this
shows "Fable 5", "Fable 5.1", "Haiku 4.5", "Mythos 5", "Opus 4.6" ...
which is not the order of capability, release, or version (#14877).
> - This pull request gives the adapter one defined order, the one the
Claude app uses: the newest release of each family first, by decreasing
capability, then older releases grouped by family. The server applies it
to discovered models, and the dropdown keeps the adapter's order instead
of re-sorting.
> - The benefit is that a user who knows the Claude app finds the right
model at once, and older models sit at the end of the list.

## Linked Issues or Issue Description

Fixes #14877.

Related: #14147 touches the same adapter's model list (the
`ANTHROPIC_MODEL` default label) and does not change ordering. #14878 is
the Codex counterpart and depends on the dropdown change in this PR.

## What Changed

- `packages/adapters/claude-local/src/server/model-order.ts` (new):
`sortClaudeModels()` and `parseClaudeModelId()`. The parser reads the
current scheme (`claude-opus-4-8`), the legacy scheme
(`claude-3-7-sonnet-20250219`), dated snapshots, `-latest` aliases, the
`[1m]` suffix, and Bedrock ids (`us.anthropic.…-v1`, `…-v2:0`). The sort
puts the newest release of each family first (Fable, Mythos, Opus,
Sonnet, Haiku), then older releases grouped by family with versions
descending. An alias sorts before its dated snapshots, and dated
snapshots of one release sort newest first. Ids that are not Claude
models keep their incoming order at the end.
- `packages/adapters/claude-local/src/server/models.ts`: apply the order
to the static fallback, to the merged API list, and to the Bedrock list.
Reorder `BEDROCK_MODELS` to match.
- `packages/adapters/claude-local/src/index.ts`: reorder the advertised
`models` list to the same order.
- `ui/src/components/AgentConfigForm.tsx`: `ModelDropdown` gets a
`preserveOrder` prop. With it the dropdown shows the list as the adapter
ordered it; without it the list is sorted by id as before.
`ui/src/lib/model-utils.ts` adds `adapterCuratesModelOrder()`, true for
the built-in adapters whose list arrives in a deliberate order
(`claude_local`, `codex_local`, `paperclip_runner`, `gemini_local`,
`grok_local`, `kimi_local`, `openclaw_gateway`, and `opencode_local` /
`pi_local`, which the server sorts when discovered and which lead with
the default model when it falls back to the declared list). Cursor is
not in the set because its list comes from `agent models` discovery, and
adapters not named there, including externally installed ones, keep the
alphabetical fallback. The three dropdown call sites (`AgentConfigForm`,
`ConfigureBuiltInAgentModal`, `NewAgentSetup`) pass it; `NewAgentSetup`
decides by the resolved brand type, because a `paperclip_runner` agent
fetches the Claude or Codex list for its brand. Grouped lists
(`opencode_local`, `pi_local`) are unchanged.
- Tests: `model-order.test.ts` (adapter, including the snapshot-date
tie-breaker), `ModelDropdown.test.tsx` (ui: preserved order with the
prop, alphabetical without it, provider groups unchanged),
`model-utils.test.ts` (which adapters opt in), and two updated
expectations plus one new order assertion in
`server/src/__tests__/adapter-models.test.ts`.

Mythos is not in the Claude app's list. This PR ranks it directly after
Fable, in the top capability tier. The rank table in `model-order.ts` is
one line to change if you prefer a different slot.

## Verification

Run from the repository root:

```sh
pnpm exec vitest run packages/adapters/claude-local server/src/__tests__/adapter-models.test.ts ui/src/lib/model-utils.test.ts ui/src/components/ModelDropdown.test.tsx ui/src/components/AgentConfigForm.render.test.tsx ui/src/components/ConfigureBuiltInAgentModal.test.tsx ui/src/pages/NewAgent.test.tsx
pnpm --filter @paperclipai/adapter-claude-local typecheck
pnpm --filter @paperclipai/ui typecheck
pnpm --filter @paperclipai/server typecheck
pnpm check:module-boundaries && pnpm check:token-gates && pnpm check:tokens
```

Red on `master`, green here:

- `ModelDropdown.test.tsx` fails against the unmodified dropdown because
the ids come back sorted alphabetically even with `preserveOrder`.
- `adapter-models.test.ts` fails against the unmodified adapter because
the first model is `claude-opus-4-8`, not `claude-fable-5-1`.

Manual check: open an agent that uses `claude_local`, open the model
dropdown. With no `ANTHROPIC_API_KEY` the list reads Fable 5.1, Mythos
5, Opus 5.5, Sonnet 5, Haiku 4.5, Fable 5, Opus 5, Opus 4.8, Opus 4.7,
Opus 4.6, Sonnet 4.6, Sonnet 4.5. With a key, the discovered models slot
into the same order.

## Risks

- The other built-in adapters in the set (Gemini with `Auto` first,
Grok, Kimi, OpenClaw, the runner's Codex list, and the OpenCode and Pi
lists in the built-in-agent modal) are now shown as their adapter
delivers them instead of alphabetized. Cursor's discovered list and
every adapter outside the set, including externally installed ones, keep
the alphabetical order they had, so no option moves between refreshes.
Grouped lists are unchanged.
- The first entry of the Claude list changes from Opus 4.8 to Fable 5.1.
Nothing reads the first entry as a default: `DEFAULT_CLAUDE_LOCAL_MODEL`
is `claude-opus-5` and is resolved separately.
- No API, schema, or migration change.

## Model Used

Anthropic Claude Fable 5.1 (`claude-fable-5-1`) through Claude Code,
extended thinking on, with tool use for reading the repository, running
vitest and tsc, and editing files. The account holder reviewed the
change and owns the commit.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: abderbj <115119179+abderbj@users.noreply.github.com>
canary/v2026.1002.0-canary.15
2026-10-02 13:24:04 -07:00
DottaandPaperclip 2ec82c5774 fix(runner): preserve task context when tool connections change (#14963)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents use tools through company-scoped connections and provider
sessions.
> - Resolving a tool connection currently forces a fresh session even
when the provider can load new tools into the existing conversation.
> - A fresh provider conversation can receive too little history to
continue the task.
> - This pull request adds explicit tool-refresh capabilities and uses
them in both runner paths.
> - Fresh attempts receive bounded task history with source IDs and
retrieval instructions.
> - The benefit is that agents can continue the same task after a
connection changes.

## Linked Issues or Issue Description

**What happened?**

A resolved tool connection forced a fresh provider conversation. The new
conversation could lose the original goal and prior answers. Claude also
rejected resume when only the MCP server set changed.

**Expected behavior**

Resume the provider conversation when its harness can refresh tools.
When a fresh session is required, supply enough bounded history to
continue the task. Preserve company, agent, task, workspace, model,
instruction, and skill checks.

**Steps to reproduce**

1. Start a conversation and agree on a task and its constraints.
2. Request and connect a tool needed for the task.
3. Continue the conversation after the connection resolves.
4. Check that the agent remembers the task and can use the new tool.

**Paperclip version or commit**

The bug was reproduced on master at `c46e41e81`. This branch is rebased
on current master.

**Deployment mode**

Self-hosted server. Both legacy adapters and the native runner are
affected.

Related public work: Refs #13282 for task-backed conversations. Refs
#13057 for the broader session-compaction proposal. Refs #14659 for
another report about local CLI session continuity. This change fixes
tool-connection continuation. Provider authentication repairs keep their
existing recovery behavior.

## What Changed

- Expose tool-refresh support in native harness descriptors and legacy
adapter metadata.
- Request tool refresh after connection resolution. Keep provider
authentication repair as a fresh-session wake.
- Reload current tools and credentials while retaining supported Claude,
Codex, Grok, and other provider conversations.
- Allow MCP-only changes during qualified native recovery. Keep all
other compatibility checks.
- Refresh managed-provider and ACPX tool bindings when attaching a new
run.
- Add a fresh-session handoff for both runner paths. Bound database
reads, excerpts, and the final packet to 24,000 bytes.
- Include the original request, recent messages, decisions, plans, prior
answers, and source IDs. Mark omitted content. Apply reset boundaries,
wake cutoffs, quarantine, and secret redaction.
- Add regression tests and document the capabilities and handoff
behavior.

## Verification

- `pnpm -r typecheck` and `pnpm build` passed. Rust formatting passed.
- Final review fixes passed 314 server tests, 333 adapter utility tests,
139 native-session runtime tests, and 12 managed-provider Rust tests.
They verify historical quarantine, raised budgets across attachment, no
history reads on successful resume, and handoff delivery on fresh retry.
- Broader branch verification also passed 1,401 adapter utility tests,
1,047 runner TypeScript tests, 43 Grok adapter tests, and 311 Rust core
tests.
- Live Claude CLI and Grok ACP probes preserved the provider session ID,
recalled a prior task constraint, and called a newly added read-only MCP
tool.
- GitHub CI passed on `b21486d18084a7aa4cafbe8e012f7cad6585d9cc`: 55
successful checks and 4 skipped checks. This includes all test shards,
all eight browser shards, runner checks, and the Grok clean public npm
install canary. [CI
run](https://github.com/paperclipai/paperclip/actions/runs/37057514976).
- A full local test attempt encountered a separate Git snapshot timeout.
All affected local suites passed after the final edits, and the full CI
test gates passed.
- Review the capability matrix in `packages/paperclip-runner/README.md`.
Repeat the four reproduction steps with a supported provider and with an
unsupported harness.

## Risks

- Provider tool refresh can fail. Existing recovery falls back to a
fresh conversation where policy permits it.
- A new transport can replace an old process while preserving the
provider conversation. Tests cover current credentials and unchanged
identity.
- Long history can omit older context. Explicit markers and source IDs
let the agent retrieve needed context within task scope.
- Unknown and unqualified harnesses use the fresh-session path. No
database migration is required.

## Model Used

OpenAI Codex, GPT-6, with reasoning, tool use, code execution, and live
provider testing. The exact model ID and context-window size are not
exposed in this session. Claude and Grok also ran as test subjects.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 15:11:44 -05:00
DottaandPaperclip 43f391e807 refactor(slack): clarify browser setup prompt from live testing (#14965)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Slack chat connections let people start and continue agent work from
Slack.
> - The setup prompt guides an agent through the Paperclip and Slack
browser interfaces.
> - A live setup completed, but several instructions did not match the
current interfaces.
> - Those gaps can send users to the wrong connection flow or leave them
waiting for controls that do not appear.
> - This pull request updates the prompt with the steps observed during
the live setup.
> - The benefit is a clearer path from a fresh instance to a verified
Slack conversation.

## Linked Issues or Issue Description

Refs: #13920 and #14862. The first added the Slack conversation flow.
The second updated the shared setup prompt control. A search found no
duplicate open PR or matching public issue.

**Issue type**

Outdated instructions and missing setup guidance.

**Where is the issue?**

`ui/src/pages/apps/chat/SlackSetupPrompt.tsx`

**What's wrong?**

The prompt omits the Chat connectors setting on fresh instances. It uses
an old navigation label. It assumes an avatar crop dialog and a Save
button always appear. It also assumes the suggested bot username matches
Slack and that the Slack reply contains a task link.

**Suggested fix**

Use the current labels. Explain the feature prerequisite, avatar save
behavior, real mention selection, clipboard recovery, and the path to
task and run evidence.

## What Changed

- Add the Chat connectors prerequisite and current Connectors, resume,
and identity-link labels.
- Explain Slack's combined Create and Install action and how to continue
from its success page.
- Handle avatar uploads that save immediately. Require a reload to
confirm the saved icon.
- Select the real bot from Slack's mention suggestions, including names
with punctuation.
- Recover from an empty or stale clipboard without exposing credentials.
- Find the linked task through Conversations and inspect the agent's
Runs page.

## Verification

- `pnpm exec vitest run
ui/src/pages/apps/chat/SlackSetupPrompt.test.tsx`: 10 tests passed after
rebasing onto current master.
- `git diff --check origin/master...HEAD`: passed.
- `pnpm build`: passed.
- `pnpm -r typecheck`: passed.
- `pnpm check:token-gates`: passed.
- Full Vitest suite: passed in CI for this commit, including all server,
chat, workspace, and serialized test shards. The duplicate local `pnpm
test:run` was stopped after CI finished; it did not complete locally.
- Current-commit CI: all checks passed, including build, typecheck, E2E,
Runner verification, and canary dry run. Greptile rated the change 5/5
with no findings or unresolved review threads.
- Live browser test before the wording update: created and installed a
new Slack app, verified the callback, uploaded and reopened the avatar,
linked the configuring user's identity, and enabled the selected test
channel. The first mention received a reply. A follow-up without another
mention recalled the first message. Both agent runs succeeded.
- The wording update does not repeat Slack app installation. Existing
tests verify the complete copied prompt, clipboard fallback, and
instance URL handling.
- This is a prompt-text refactor. No runtime behavior changes, so the
existing tests cover the copied result without a new test that repeats
the wording.

## Risks

- Low risk. This change updates prompt text in one file.
- Provider interfaces can change. The prompt tells the agent to inspect
the current page and handle optional controls.
- The prompt handles the observed mention mismatch. This change does not
alter the generated suggested username.

## Model Used

- OpenAI Codex, based on GPT-6, with reasoning, repository tools, code
execution, and browser automation. The session does not expose an exact
runtime model ID or context window size. The live test also used an
earlier model whose exact ID was not exposed.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 15:11:05 -05:00
Devin FoleyandPaperclip 144083fd48 fix(interactions): wait for workspace readiness before enabling approval (#14893)
## Thinking Path

> - Paperclip lets people manage AI agents and review their work.
> - Task confirmations must use the work produced by their source run.
> - The server blocks approval while that run still needs to sync its
workspace.
> - The card currently enables approval before that check can pass, so
an ordinary click produces an error.
> - This PR exposes the existing readiness check and shows “Preparing
approval…” with acceptance disabled.
> - The card refreshes itself and enables approval when the source
workspace settles.

## Linked Issues or Issue Description

**What happened?**

A confirmation appears while its source run is still preparing or
syncing its workspace. Its enabled approval button returns a conflict
asking the user to retry after syncing.

**Steps to reproduce**

1. Run an agent in an isolated workspace.
2. Have it create a confirmation before workspace finalization
completes.
3. Click the approval button while the source workspace is still active.

**Expected behavior**

The card explains that approval is preparing. Acceptance becomes
available automatically when the same server check permits it. Reject
and revise remain available.

Related work: #10770 handles this conflict after a click with retries.
#9520 proposes changing the workspace acceptance barrier. This PR
preserves that barrier and exposes readiness before the click, including
in compact task chat. It preserves the terminal-finalize behavior from
#10099.

## What Changed

- Add an optional, read-only `acceptanceBlocker` to interaction
responses. Readiness uses the existing source-run workspace predicate,
with one check per pending source run.
- Disable acceptance and show a shared preparation notice in classic and
compact confirmation cards, including checkbox and secret-binding
confirmations.
- Refresh preparing cards every two seconds in task detail, attention,
pipelines, and Skill Studio. Restore each surface's previous polling
cadence when preparation clears.
- Preserve live tool reviews, questions, rejection, revision, and the
server acceptance barrier. No automatic acceptance occurs.
- Document the preparation state and cover readiness, terminal sync
outcomes, unrelated runs, historical cards, and automatic refresh.

## Verification

- Focused service, card, query-refresh, and helper tests: 217 passed
across five files.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- `pnpm build-storybook`: passed.
- `pnpm check:token-gates`: passed.
- `pnpm test:run`: incomplete locally. Stopped after about 17 minutes
once it reproduced seven existing environment failures: two Slack tests
and two email tests lack ancestor-directory skill fixtures; three
company-skills tests fail on macOS runtime-cache staging permissions.
These are outside this change. The full CI test matrix passed.
- CI: all 53 checks passed; two optional Storybook jobs were skipped.
The branch has no conflicts with `master`.
- Greptile: 5/5 on commit `8a6f216d8d`, with no review threads.
- Reviewed added lines and new files for credentials, private URLs,
internal task references, user paths, and run artifacts. None found.

## Risks

- No database migration or change to acceptance authorization. Readiness
is advisory; the server still enforces its existing gate at acceptance.
- An open preparing card adds a read every two seconds. This cadence
stops after readiness clears; historical cards add no workspace checks.
- Failed or stale finalization retains the existing server behavior.
This PR does not change recovery policy.

## Model Used

OpenAI GPT-6 through Codex. The exact serving model ID and
context-window size are not exposed in this session. Used reasoning,
repository inspection, tool execution, and automated tests. No
sub-agents.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (217 focused tests; full
local-suite limitations are recorded above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 13:08:25 -07:00
806af230b6 docs(release): curate stable notes for the 2026.1002.0-beta.0 promotion (#14928)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The release pipeline publishes a beta, waits three days, and then
promotes it to stable.
> - The stable promotion reads `releases/beta/v<beta-version>.md` from
`master` and publishes it as the GitHub Release body.
> - Beta `2026.1002.0-beta.0` (source `467125fa`, 179 commits after
v2026.1001.0) is published and its soak has started. The planned stable
is around 2026-10-05.
> - The beta publish job pushed an auto-generated scaffold. The scaffold
lists raw commit subjects and PR bodies. It is not in release-notes
voice.
> - This pull request replaces the scaffold with curated stable notes.
> - The benefit is that the stable release ships with readable notes
that tell self-hosters what changed and what they must do.

## Linked Issues or Issue Description

**Issue type**

Docs: release notes.

**Where is the issue?**

`releases/beta/v2026.1002.0-beta.0.md` on branch
`release-notes/v2026.1002.0-beta.0`.

**What's wrong?**

The file is the auto-generated scaffold from the beta publish job. It
lists 170+ raw entries with no grouping, no breaking-changes section,
and no upgrade guide.

**Suggested fix**

Rewrite the file in the standard release-notes structure. The notes are
planned as `v2026.1005.0`. **If the promotion date moves past
2026-10-05, change the title and the Released date before you dispatch
stable.**

## What Changed

- Rewrote `releases/beta/v2026.1002.0-beta.0.md` into the standard
structure: overview, Breaking Changes, Highlights, Fixes, Improvements,
Upgrade Guide, and Contributors.
- Breaking Changes: operator UI snippet settings removed
([#13789](https://github.com/paperclipai/paperclip/pull/13789));
keyboard-shortcut settings and `/api/auth/preferences` removed
([#14141](https://github.com/paperclipai/paperclip/pull/14141),
[#14643](https://github.com/paperclipai/paperclip/pull/14643)); agent
@-mentions no longer start a run
([#14577](https://github.com/paperclipai/paperclip/pull/14577)).
- Highlights: Grok Build on the native runner, persistent agent files,
skills synced from GitHub, Browser Use Cloud, one-screen connector
setup, two-way Slack, Agent Chat navigation and handoffs, per-message
model and effort picker, governed API tools on by default.
- Upgrade Guide: migrations `0284`–`0293` with one-phrase descriptions,
new default for `PAPERCLIP_RUNNER_API_TOOLS_ENABLED`, and the new
optional variables `PAPERCLIP_RUNNER_API_COMPANY_CAPTURE_MAX_BYTES`,
`PAPERCLIP_WORKSPACE_GIT_SNAPSHOT_TIMEOUT_MS`, and
`PAPERCLIP_WORKSPACE_MANIFEST_MIN_FREE_BYTES` with their defaults.
- Removed release-infra noise: CI-only PRs, eval and test-only PRs,
lockfile refreshes, release-notes bookkeeping commits, and
cloud-control-plane-only changes.

## Verification

- Docs only. Each PR number and commit SHA in the notes is in `git log
v2026.1001.0..467125fafb47a8520856504fecc48d6e32055db1`.
- Migration range `0284`–`0293` checked against the
`packages/db/src/migrations` diff for that range.
- Environment variable defaults checked in the code, not in commit
subjects.
- Contributor count and external handles computed from `git shortlog`
over the same range.

## Risks

Low. Documentation only. The stable preflight only requires that the
file exists on `master`. The content can change during the soak.

## Model Used

Anthropic Claude Fable 5.1 (`claude-fable-5-1`) via Claude Code, with
tool use and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (docs only; no tests apply)
- [x] I have added or updated tests where applicable (none apply)
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green (pending on this fresh PR)
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(pending)
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: devinfoley <139239+devinfoley@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
canary/v2026.1002.0-canary.14
2026-10-02 12:39:47 -07:00
dependabot[bot] 0a2385eb31 build(deps): bump dompurify from 3.4.14 to 3.4.16 (#14783)
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.14 to
3.4.16.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/cure53/DOMPurify/releases">dompurify's
releases</a>.</em></p>
<blockquote>
<h2>DOMPurify 3.4.16</h2>
<ul>
<li>Fixed a problem with <code>IN_PLACE</code> node removal when working
with hooks, thanks <a
href="https://github.com/manus-pi"><code>@​manus-pi</code></a></li>
<li>Fixed a problem with <code>IN_PLACE</code> sanitization and raw-text
roots, thanks <a
href="https://github.com/h-t-m"><code>@​h-t-m</code></a></li>
<li>Fixed a problem with ESM default exports landing in CommonJS
declarations, thanks <a
href="https://github.com/ssi02014"><code>@​ssi02014</code></a></li>
<li>Migrated from <code>rollup</code> to <code>rolldown</code> because
performance, thanks <a
href="https://github.com/ssi02014"><code>@​ssi02014</code></a></li>
<li>Bumped several dependencies where possible</li>
</ul>
<h2>DOMPurify 3.4.15</h2>
<ul>
<li>Added better clobbering hardening when XML content is involved,
thanks <a
href="https://github.com/gnyselcuk"><code>@​gnyselcuk</code></a></li>
<li>Added several smaller hardening and edge-case improvements, thanks
<a
href="https://github.com/leechristensen"><code>@​leechristensen</code></a></li>
<li>Bumped several dependencies where possible</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/cure53/DOMPurify/commit/b9b9d80f7e401771c2ccaef5f45def7eec8f27d7"><code>b9b9d80</code></a>
release: 3.4.16 (<a
href="https://redirect.github.com/cure53/DOMPurify/issues/1636">#1636</a>)</li>
<li><a
href="https://github.com/cure53/DOMPurify/commit/1d7460c4f8a27be825c11b1c9d346d79db32c1e5"><code>1d7460c</code></a>
release: 3.4.15 (<a
href="https://redirect.github.com/cure53/DOMPurify/issues/1609">#1609</a>)</li>
<li>See full diff in <a
href="https://github.com/cure53/DOMPurify/compare/3.4.14...3.4.16">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=dompurify&package-manager=npm_and_yarn&previous-version=3.4.14&new-version=3.4.16)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/paperclipai/paperclip/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 12:37:46 -07:00
DottaandPaperclip d034ba7491 fix(interactions): derive question storage from canonical forms (#14946)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents request human input through durable issue interactions.
> - A question form has a canonical presentation and a compatibility
storage format.
> - The creation API required agents to write both formats.
> - Tool guidance told agents to split text and choice questions across
those formats.
> - This pull request accepts one complete canonical form and derives
storage fields on the server.
> - The benefit is a complete question card with stable answer and retry
behavior.

## Linked Issues or Issue Description

Related work: Refs #13630 and #14430. PR #13630 addresses the display of
historical partial forms. This change fixes creation and keeps the check
that rejects conflicting new forms.

**What happened?**

A question save supplied three compatibility questions and one canonical
text question. The API correctly rejected the incomplete canonical form.
The Runner's tool description encouraged this split. Sending only a
complete canonical form also failed because the API required
compatibility questions.

**Expected behavior**

An agent sends one complete `payload.questionSet` with every text and
choice question. Paperclip derives `payload.questions` for storage and
answer compatibility. Existing legacy requests remain valid. Explicitly
conflicting dual forms remain invalid.

**Steps to reproduce**

1. Call `paperclip_request_human_input` with `interactionKind:
"questions"`.
2. Send `payload: { version: 1, questionSet: ... }` with a required text
question and a required choice question.
3. The old API rejects the missing compatibility questions. With this
change, it stores both questions and preserves the canonical form.
4. Retry with the same idempotency key. Confirm that only one
interaction exists.
5. Submit both answers. Confirm that the normal resolver and
continuation rules apply.

**Paperclip version or commit**

The branch is based on `cf8ad63c8`. The problem affects the native
Runner and the interaction creation API.

**Deployment mode**

Server deployment with the native Paperclip Runner. Integration tests
use the real interaction service and an embedded test database.

## What Changed

- Add one shared canonical-to-storage projection. Reuse it for native
harness question requests.
- Accept canonical-only question creation at the shared validator and
server boundary.
- Export the input type and update the plugin SDK and its RPC contract.
- Advertise a typed, complete question form in the live and scenario
tool schemas.
- Enforce canonical text and custom-answer constraints before ordinary
or native resolution. Preserve harmless display whitespace.
- Run regex matching in isolated workers with a deadline and resource
limits. Both answer paths await the result before persistence. Saved
native delivery uses the validated answer without taking another worker
slot.
- Update agent guidance and generated Runner contracts.
- Test mixed forms, option-ID collisions, retries, answers, legacy
requests, and conflicting forms.

## Verification

- Interaction service, HTTP route, native bridge, and Runner authority
suites: 221 tests passed after correcting an obsolete tool-description
assertion.
- Shared validator, plugin SDK, CLI, and UI compatibility suites: 67
tests passed.
- Runner core tool-contract suite: 20 tests passed. AJV validates live
and scenario schemas.
- Final review regressions: 172 shared, service, native bridge, and
authority tests passed. These cover text length, pattern, numeric
limits, whitespace, custom option IDs, and historical pending cards.
- Runner session suites: 67 tests passed. Published example tests: 4
tests passed.
- Server typecheck and the shared/server builds passed after the
compatibility fixes.
- Final delivery verification: 35 response-delivery tests passed. The
native delivery regression proves saved answers do not enter pattern
workers; server typecheck and build passed.
- Pattern security and answer-flow verification: 205 tests passed after
repairing the child fixture loader. These cover pathological matching,
event-loop responsiveness, worker concurrency, slot cleanup, HTTP
routes, native delivery, and the full helper in a child process.
- `pnpm -r typecheck` passed on the bounded-worker revision.
- `pnpm build` passed on the bounded-worker revision.
- All 55 GitHub checks passed on `fe457af`; four optional jobs were
skipped. An unchanged Cursor adapter test timed out once in CI, passed
locally, and passed on one failed-job rerun.
- Reviewers can send the canonical-only mixed form above and verify that
the saved interaction contains both canonical and compatibility
questions.

## Risks

- The creation API accepts a new input shape. Stored rows and answer
contracts keep the existing shape.
- The shared projection must preserve synthetic free-text option IDs.
Collision and native round-trip tests cover this behavior.
- Historical partial rows remain readable. New conflicting dual forms,
including written-answer mismatches, remain rejected.
- Existing pending cards retain the written-answer paths offered by
their stored options. Canonical text constraints still apply.
- Ordinary answers now enforce declared canonical constraints before
persistence. Invalid answers leave the card pending.
- Regex validation has a one-second deadline and a four-worker capacity
limit. A complex pattern or capacity error leaves the card pending with
a validation error.
- No database migration or change to company authorization is required.

## Model Used

- OpenAI GPT-6 through Codex. The session exposes the GPT-6 model
family; its exact runtime model identifier and context window size are
not exposed. Used reasoning, tool use, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 14:21:11 -05:00
dependabot[bot] 8fd3cf74ea build(deps): bump @grpc/grpc-js from 1.14.4 to 1.14.5 (#14786)
Bumps [@grpc/grpc-js](https://github.com/grpc/grpc-node) from 1.14.4 to
1.14.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/grpc/grpc-node/releases">@​grpc/grpc-js's
releases</a>.</em></p>
<blockquote>
<h2><code>@​grpc/grpc-js</code> 1.14.5</h2>
<ul>
<li>Fix a bug that caused clients to automatically transmit excessive
error details to clients by default (<a
href="https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4">advisory
GHSA-f596-whhp-79r4</a>)</li>
<li>Fix a bug that caused <code>getAuthContext</code> to return
unverified certificates as though they were verified in some
configurations (<a
href="https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j">advisory
GHSA-m9gg-hp2v-232j</a>)</li>
<li>Fix a bug that could cause stale call data to accumulate if a
channel failed to connect for a long period of time (<a
href="https://redirect.github.com/grpc/grpc-node/issues/3078">#3078</a>)</li>
<li>Fix a bug that could cause call status to be reported with expected
fields missing (<a
href="https://redirect.github.com/grpc/grpc-node/issues/3079">#3079</a>)</li>
<li>Avoid redundant end() calls on completed HTTP/2 streams (<a
href="https://redirect.github.com/grpc/grpc-node/issues/3082">#3082</a>
contributed by <a
href="https://github.com/olavloite"><code>@​olavloite</code></a>)</li>
<li>Unify call numbers and avoid disabled trace allocations (<a
href="https://redirect.github.com/grpc/grpc-node/issues/3084">#3084</a>
contributed by <a
href="https://github.com/olavloite"><code>@​olavloite</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/grpc/grpc-node/commit/56567d9604b4e45cdca0d2e3c2a60ac227ee659d"><code>56567d9</code></a>
Merge pull request <a
href="https://redirect.github.com/grpc/grpc-node/issues/3086">#3086</a>
from murgatroid99/grpc-js_1.14.5</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/748ae86f7bb8af4a8d917d6fcf01c7a4c070f0a4"><code>748ae86</code></a>
Merge pull request <a
href="https://redirect.github.com/grpc/grpc-node/issues/3088">#3088</a>
from murgatroid99/grpc-js_perf_improvement_backport</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/526702d8ed335a99960878aea19cf6748f6d2314"><code>526702d</code></a>
test(grpc-js): fix type errors in client stream lifecycle tests</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/26a8d3d7d919098ded374b1c246d113161d69eb1"><code>26a8d3d</code></a>
fix(grpc-js): avoid redundant end() calls on completed HTTP/2
streams</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/152eebdcd5bbb1548b7779d14e0f5046784c21c1"><code>152eebd</code></a>
chore(grpc-js): unify call numbers and avoid disabled trace
allocations</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/c5ae75026d7f07d24ab1bbd76cb84d78ab3a4a8d"><code>c5ae750</code></a>
grpc-js(-xds): Increment version numbers (1.14.x)</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/735a09a4f967400667fbbeda54584437e1bcf721"><code>735a09a</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/af9b1401fbf72d7cbe8b569c8df45cb4d4905e24"><code>af9b140</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/45ac33e74312ccd34cd7015147b36ef21b12b6c3"><code>45ac33e</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/grpc/grpc-node/commit/9df49e3ca3ea20f8626f62339d703d7284ed13e9"><code>9df49e3</code></a>
Merge pull request <a
href="https://redirect.github.com/grpc/grpc-node/issues/3081">#3081</a>
from murgatroid99/grpc-js-xds_weighted_target_fix_ba...</li>
<li>Additional commits viewable in <a
href="https://github.com/grpc/grpc-node/compare/@grpc/grpc-js@1.14.4...@grpc/grpc-js@1.14.5">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 12:19:48 -07:00
DottaandPaperclip 9786f6df56 fix(runner): preserve credential content in document saves (#14937)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Runner sends authorized tool calls to the control plane.
> - Agents use these calls to save plans and instruction files.
> - The Runner used diagnostic secret detection to reject execution
arguments.
> - Ordinary credential-related prose could reject a document save
before persistence.
> - This pull request forwards the original arguments and leaves
credential policy to the provider harness.
> - The benefit is reliable saves with useful diagnostic records.

## Linked Issues or Issue Description

Related foundation: Refs #12415 and #14430. No duplicate save-policy fix
was found.

**What happened?**

A `write_document` call failed before the server saved its plan. The
Runner reported `semantic tool input contains credential material;
refusing to execute altered arguments`. The detector also masked
ordinary phrases such as `secret manager` and `credential handling` in
diagnostics. Both TypeScript dispatchers had equivalent execution gates.
One dispatcher also rewrote structured approval and question payloads
before execution.

**Expected behavior**

Paperclip forwards authorized arguments unchanged. The provider harness
decides credential-content policy. Log and audit redaction does not
reject or rewrite save input.

**Steps to reproduce**

1. Send an authorized `write_document` call with a plan that discusses
credential handling.
2. Include an intentional credential value in the body to exercise
harness-owned policy.
3. The old Runner rejects the call. With this change, the document
service stores the exact body.
4. Diagnostic records still mask explicit credential values. Qualified
credential fields, short bearer values, opaque diagnostic pairs, and
valid encoded JSON token headers have regression coverage.

**Paperclip version or commit**

Reproduced at `c46e41e81c03cd3c8b64cf993615b604d7fe8c62`. The branch is
based on current `master`.

**Deployment mode**

Server deployment with the native Paperclip Runner. Local regression
tests use the real document service and an embedded test database.

## What Changed

- Remove credential-content vetoes from Rust admission and both
TypeScript semantic dispatchers.
- Preserve original structured approval and question arguments during
execution.
- Keep transport bounds, schema checks, authorization, idempotency, and
audit masking.
- Require explicit credential syntax or recognized formats for
diagnostic masking. Preserve ordinary prose, metadata, and dotted
identifiers.
- Test exact document persistence, replay, nested argument identities,
and masked audit copies.
- Remove obsolete retry guidance and document harness-owned credential
policy.

## Verification

- `cargo test --manifest-path
packages/paperclip-runner/runner/Cargo.toml --locked -p
paperclip-runner-core --lib --test acpx_event_payload --test
acpx_provider_state --test acpx_provider_turns`: 355 tests passed.
- Focused server and adapter tests: 189 tests passed after rebase. These
include the real document save and the complete tool-gateway suite.
- Semantic dispatcher and conformance tests: 34 tests passed.
- Diagnostic redaction and MCP tests: 46 tests passed, including all six
review examples.
- `pnpm -r typecheck` and `pnpm build` passed on the repaired branch.
- The broad local root suite was interrupted after database fixture
setup failures. The focused database suites passed. CI runs the complete
configured test lanes.

## Risks

- Authorized tool arguments can intentionally contain credentials. The
harness must enforce its content policy.
- Diagnostic detection is narrower. Explicit assignments, credential
fields, and recognized credential formats remain masked.
- The change does not add a database migration or change company
authorization.

## Model Used

- OpenAI GPT-6 through Codex. The session exposes the GPT-6 model
family; its exact runtime model identifier and context window size are
not exposed. Used reasoning, tool use, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 14:19:41 -05:00
DottaandPaperclip 839cac1343 fix: request supported offline access for generic MCP OAuth (#14950)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents use external MCP tools through the governed gateway.
> - Remote MCP connections can use OAuth access tokens that expire.
> - Some providers issue refresh tokens only after an offline-access
request and consent.
> - Resource scopes hid that identity-provider capability in the generic
connection flow.
> - This pull request requests supported offline access and tests expiry
through a local MCP server.
> - The benefit is continued tool access without another sign-in when
the provider permits refresh.

## Linked Issues or Issue Description

Related PR: #13447 addresses the same OAuth symptom together with
managed Codex configuration. This PR focuses on generic MCP OAuth. It
also covers consent, explicit scope overrides, legacy reconnects, exact
scope persistence, and real HTTP expiry tests.

**What happened?**

A generic MCP resource can advertise only its tool scopes. Its OAuth
server can separately advertise `offline_access`. Paperclip selected the
resource scopes and omitted the offline-access request. A provider could
then issue an access token without a refresh token. Tool access stopped
after the access token expired.

**Expected behavior**

Paperclip adds advertised offline access to the selected tool scopes
when the OAuth server does not exclude refresh tokens. It requests
consent and stores the scopes sent in the authorization request.
Existing connections can discover this capability when the user
reconnects. Providers without this capability keep their existing scope
behavior.

**Steps to reproduce**

1. Run `node scripts/mcp-fixtures/servers/oauth-refresh-fixture.mjs`
from the repository root.
2. Add its MCP URL as a generic connection on a local Paperclip
instance.
3. Approve the test consent page and call `read_status`.
4. Let the two-minute access token expire and call the tool again.
5. Before this fix, the connection needs another sign-in. With this fix,
the call refreshes the token and succeeds.

**Paperclip version or commit**

The integration regression reproduced the missing-refresh-token failure
on the parent of this PR's fix. The same test passes with the fix.

**Deployment mode**

Local development. Automated tests use a loopback HTTP MCP/OAuth server
and a disposable PostgreSQL database.

## What Changed

- Track offline-access capability separately from MCP tool scopes.
- Add supported offline access and consent for generic connections.
- Preserve the actual requested scopes through callback completion and
reconnect.
- Discover the capability for older connections with cached OAuth
endpoints.
- Add a reusable MCP/OAuth fixture with PKCE, token expiry, resource
binding, and refresh-token rotation.
- Test shared and personal gateway calls through two refresh rotations.
Cover scope selection, unsupported refresh, and legacy reconnects.
- Document the behavior and local test commands.

## Verification

- The two real HTTP expiry tests failed before the fix with
`oauth_refresh_missing` after the first token expired.
- Tests passed on the current head: 76 generic MCP regressions, all 365
tool-access service tests, and 4 fixture controls.
- Full workspace `pnpm -r typecheck` and `pnpm build` passed. Server
TypeScript checks also passed after the review fixes.
- All remote checks passed on
`d22909bb34e9d54478c0002077c498ffe105932d`. Greptile gave 5/5 with both
previous findings resolved. The complete local `pnpm test:run` is still
running.
- Run `node --test
scripts/mcp-fixtures/servers/oauth-refresh-fixture.test.mjs` for the
standalone provider controls.
- Run `pnpm exec vitest run
server/src/__tests__/generic-mcp-connection.test.ts` for the Paperclip
integration tests.

## Risks

- Users can see a consent prompt when a generic provider supports
offline access.
- The provider can still decline to issue a refresh token. Access works
until expiry, then the user must reconnect.
- A provider that advertises offline access but rejects the scope
produces an OAuth error. This PR does not add an automatic retry without
that scope.
- Existing grants without refresh tokens need another sign-in. The fix
does not change them in place.
- Curated Apps keep their reviewed scope and authorization-parameter
allowlists. No database migration is required.
- This simulation verifies the suspected failure. The reported internal
MCP server has not been tested.

## Model Used

- OpenAI Codex, based on GPT-6, with reasoning, tool use, and code
execution. The runtime did not expose a more specific model ID or
context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 14:13:59 -05:00
DottaandPaperclip 7a52dcdc74 fix: repair MCP validation and cancelled execution recovery (#14951)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The tool gateway gives agents access to connected services. Recovery
controls what happens when a run stops.
> - Generated tool names can exceed the provider limit after the MCP
client adds its prefix.
> - The same invalid definition can fail each automatic retry. A
cancelled run can also hold saved messages without showing its cause.
> - This pull request bounds tool names, stops configuration retries,
and retains cancellation evidence.
> - It shows the stopped run and admits saved input only after the
existing safety checks pass.
> - The benefit is a clear recovery path that preserves operator Stop
and prevents duplicate message delivery.

## Linked Issues or Issue Description

**What happened?**

A long connected MCP tool name makes the provider reject the entire
request. Automatic recovery repeats the invalid request. Separately,
unexpected legacy cancellations can leave saved input behind a recovery
hold. The notice does not identify the stopped run or its cause.

**Expected behavior**

Complete MCP names fit the provider limit. Tool-definition errors
require configuration repair. Cancelled runs retain their source and
reason. The recovery notice shows the cause and saved-message count.
Verified unexpected cancellations can start a fresh turn through the
existing admission checks.

**Steps to reproduce**

1. Assign an App gallery connection with a long application key and tool
name to a Claude agent.
2. Start a run. The provider rejects a name over 128 characters,
including its MCP prefix.
3. For cancellation recovery, stop a legacy provider turn without an
operator Stop request and send a user message while the recovery hold is
active.
4. Inspect the recovery notice and the deferred message queue.

**Paperclip version or commit**

Rebased onto master at `cf8ad63c806685bfd7c48e3ed4a919d61a7c55f1`.

**Deployment mode**

Hosted or self-hosted server with legacy Claude or Codex execution.

Related public work:

- Refs #14017. That PR caps name segments. This PR preserves existing
short names and uses stable hash aliases for long complete names. It
also covers classification and recovery.
- Refs #4510. That PR adds a cancellation-source column. This PR records
bounded evidence in the existing run result, without a migration.
- Refs #12552 and #4506. Those PRs suppress recovery after operator
cancellation. This PR preserves operator intent and uses the existing
continuation gates.

## What Changed

- Bound gateway names with the full provider prefix in the 128-character
budget. Retain the original upstream tool name for dispatch and
permissions.
- Classify invalid tool definitions as configuration failures before
diagnostic redaction. Stop automatic retries and continuation attempts
for that error code.
- Persist cancellation source, expectedness, initiator, reason, and
time. Preserve recorded Stop intent when adapter results arrive. Report
unexpected started cancellations with closed diagnostic labels.
- Show the run cause, saved-message count, and Inspect run link. Offer
Continue for eligible unexpected cancellations. Require verified
provider stop, empty tool inventory, ownership, and the existing pause,
budget, approval, and dependency gates. Use the existing queue for
single delivery.
- Add regression coverage and update the execution, MCP gateway, and
run-log documentation.

## Verification

- `pnpm -r typecheck` and `pnpm build` passed.
- `pnpm check:token-gates` passed.
- Ran `pnpm test:run` and completed its workspace and serialized groups.
Initial resource and timing failures passed on isolated reruns. All 149
serialized route suites passed.
- Reran the changed server, adapter, and UI suites after the rebase.
Coverage includes long-name upstream dispatch, configuration retry
suppression, cancellation evidence retention, privacy labels, oversized
run projection, and concurrent saved-message delivery.
- `pnpm test:e2e tests/e2e/legacy-failure-continuation.spec.ts` passed
all six browser scenarios. The recovery notice shows the run cause and
inspection link, and each recovery entry point reaches one new response.
- Added database-backed checks for active, removed, paused, unavailable,
and disabled chat connections. The final continuation and
recovery-notice suites passed 167 tests. Externally bound chats hide
board Continue and show a usable next action.
- All 55 GitHub checks passed on
`42afbf1371dcaeb72646e3d8f65c19ff7cddf8de`. Two unrelated Storybook jobs
were skipped by their normal conditions. Greptile reviewed that commit
at 5/5 with no findings and no open review threads.

## Risks

- Long tool names change to aliases. Existing short names stay
compatible. The original connection and upstream name remain the
dispatch authority.
- Invalid tool definitions no longer get automatic retries. An operator
must repair the configuration before a new attempt.
- Continuation changes apply only to positively identified unexpected
legacy cancellations with complete empty tool inventory. Operator Stop,
unknown historical cancellations, outstanding tools, and unverified
provider termination keep their holds.
- No database migration. The added projection fields are optional.
Cancellation reason and initiator IDs remain local run evidence; Sentry
receives only closed source and initiator-type labels and expectedness.

## Model Used

- OpenAI GPT-6 through Codex, with reasoning, repository editing, shell
execution, and GitHub tool use. The runtime does not expose the exact
model variant or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.13
2026-10-02 13:47:59 -05:00
DottaandPaperclip 7d59de6113 feat(connections): probe provider usage limits on demand (#14936)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections store the AI accounts used by legacy and native runners.
> - Subscription accounts can reach session, weekly, model, or paid
usage limits.
> - Operators need to read these limits for a specific stored account
before making a routing decision.
> - This pull request adds an on-demand usage probe to the connection
service and account detail.
> - The result preserves provider limits, reset times, paid usage, and
unknown values for later consumers.

## Linked Issues or Issue Description

**Subsystem affected**

Shared contracts, the connection service and API, and the account detail
UI.

**Problem or motivation**

Managed AI accounts lack a common operation to read their current usage
limits. A local harness probe can read a different login from the
account selected for an agent.

**Proposed solution**

Add `aiConnectionService.probeUsage()` and a board-only connection usage
endpoint. Probe the selected credential grant on request. Support Codex,
Claude, and Grok subscriptions, plus OpenRouter API key limits.

**Alternatives considered**

Harness-specific automatic polling would couple the read to execution
and can read ambient credentials. This change uses the managed
connection credential and leaves scheduling and admission decisions to
later work.

**Roadmap alignment**

This extends the existing Personal & Shared AI Accounts capability. It
adds no routing or quota enforcement. Related: Refs #14459 for managed
OpenAI quota reads; Refs #14781 and Refs #13379 for downstream pacing
and budget work. This operation reads one requested account across all
three subscription providers.

## What Changed

- Add typed usage snapshots and a probe capability flag to managed AI
connections.
- Normalize Codex, Claude, Grok, and OpenRouter responses. Keep model
scopes, provider admission, reset periods, and paid allowances separate.
Preserve unknown values.
- Enforce company membership, credential audience, grant identity, and
connection lifecycle before reading the stored secret.
- Add a board-only `GET
/api/companies/:companyId/ai-connections/:connectionId/usage` endpoint
with `no-store` responses.
- Add manual **Check usage** and **Refresh** actions to account details.
Show compact usage bars, resets, admission and overage status; remove
repeated descriptions and account-default copy. Clear previous results
during a new request or error.
- Add Storybook previews using the production account components for all
four providers, initial checks, loading, and permission errors.
- Add provider, authorization, runner selection, API, and UI coverage.
Document provider sources and live qualification.

## Verification

- Initial provider, authorization, selection, API, and UI validation
passed (96 focused tests): `pnpm exec vitest run
server/src/services/ai-connection-usage.test.ts
server/src/__tests__/ai-connections.test.ts
ui/src/components/ai-connections/AiConnectionUsagePanel.test.tsx
server/src/__tests__/openapi-routes.test.ts`.
- `pnpm -r typecheck` passes for the initial implementation. After
simplifying the UI, 9 usage-panel and date-helper tests, UI typecheck,
token gates, and Storybook build pass. The initial feature module
boundary check also passed.
- Real Codex, Claude, and Grok credentials were saved to encrypted
disposable connections. The actual usage HTTP route returned 200 with
`status: ok`. Legacy and native runner selection checks passed. The
tests started no model turn and exchanged no refresh token. The
disposable databases and vaults were removed.
- Live Claude responses added structured scoped limits. Live Grok
responses omitted included-plan usage. Tests now cover both shapes and
preserve the Grok omission as unknown.
- The full workspace build passes. A full local test run hit a heartbeat
feedback timeout. That case passes in isolation. The duplicate local run
was stopped after all remote checks passed. The Slack ordering and
OpenCode transport CI flakes also pass in isolation and on the CI rerun.


- Current head: `ff3d479029a1c4248190323e221b2803cfb0d79d`. All 54
active checks pass. Two Storybook checks are intentionally skipped by
the workflow. Greptile is 5/5 with no unresolved review findings; the
branch is mergeable.

## Risks

- Subscription usage endpoints can change. Credentials can lack
usage-read permission. The probe returns explicit errors without fresh
limits in these cases.
- A successful probe can contain partial data. Missing utilization or
admission remains unknown. An enabled paid-usage switch does not prove a
funded balance.
- This change adds no migration. It does not change runner admission or
automatic provider selection. Provider requests use fixed endpoints,
disabled redirects, bounded response sizes, and a 15-second deadline.

## Model Used

OpenAI Codex, GPT-6, with reasoning, file editing, shell execution, and
HTTP tools. The session does not expose the exact runtime model variant
or context window size. Real provider credentials were used only for the
authorized live checks.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 11:47:14 -05:00
dependabot[bot] cf8ad63c80 build(deps-dev): bump tsx from 4.23.12 to 4.23.15 (#12965)
Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.12 to
4.23.15.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/privatenumber/tsx/releases">tsx's
releases</a>.</em></p>
<blockquote>
<h2>v4.23.15</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.14...v4.23.15">4.23.15</a>
(2026-09-20)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>exclude bare builtins from namespace inheritance (<a
href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a">38e1588</a>)</li>
<li>expose require.cache and require.extensions to tsImport CommonJS
modules (<a
href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a">2da3407</a>)</li>
<li>make namespaced register() overloads portable for declaration emit
(<a
href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15">562c434</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.15"><code>npm
package (@​latest dist-tag)</code></a></li>
</ul>
<h2>v4.23.14</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.13...v4.23.14">4.23.14</a>
(2026-09-20)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>restore the CJS bridge namespace for Node 24 require(esm) under
tsImport() (<a
href="https://redirect.github.com/privatenumber/tsx/issues/802">#802</a>)
(<a
href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f">6e5236b</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.14"><code>npm
package (@​latest dist-tag)</code></a></li>
</ul>
<h2>v4.23.13</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.13">4.23.13</a>
(2026-08-30)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>cache:</strong> bound shared transform cache memory (<a
href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>)
(<a
href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e">28e1f12</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.13"><code>npm
package (@​latest dist-tag)</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/privatenumber/tsx/commit/ca66105a17a2a4c6503fe3a12b5b9ec408286011"><code>ca66105</code></a>
test: fix drive-less file URLs in ESM resolver fixtures</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a"><code>2da3407</code></a>
fix: expose require.cache and require.extensions to tsImport CommonJS
modules</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a"><code>38e1588</code></a>
fix: exclude bare builtins from namespace inheritance</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15"><code>562c434</code></a>
fix: make namespaced register() overloads portable for declaration
emit</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/edfb1f05a3f40b879a41a03a0801c2abd3a3ecf9"><code>edfb1f0</code></a>
build: upgrade pkgroll and externalize CJS loader reference</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/70e78284837c859f09b96cd10cd71d007aa4b795"><code>70e7828</code></a>
test: upgrade tinyspy for disposable API</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/9ed2022dfa9ea1be9511fe6abcde8110c25055a7"><code>9ed2022</code></a>
ci: avoid duplicate release notifications</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/872e77ffc5e96ca5c4727e74c0694debcb26219b"><code>872e77f</code></a>
refactor: use disposables for cleanup</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f"><code>6e5236b</code></a>
fix: restore the CJS bridge namespace for Node 24 require(esm) under
tsImport...</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e"><code>28e1f12</code></a>
fix(cache): bound shared transform cache memory (<a
href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>)</li>
<li>See full diff in <a
href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.15">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.12
2026-10-02 08:39:37 -07:00
Nicky LeachandPaperclip b2c565038b test(shared): make the worktree port registry lock suite deterministic (#12798)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Shared worktree services use lock leases and worker-thread
heartbeats
> - The lock test suite measured wall-clock timing across two threads
> - Processor contention allowed a heartbeat tick to change the value
during an assertion
> - This pull request removes that timing race and restores a regression
guard
> - The benefit is a stable test suite that still detects slow
heartbeats

## Linked Issues or Issue Description

**What happened?** The worktree port registry lock suite failed at
random under continuous-integration processor contention. The failure
reported a fresh timestamp where the test expected an old timestamp.

**Expected behavior** The suite must pass when the heartbeat runs at its
supported interval. It must also fail when the heartbeat interval
regresses.

**Steps to reproduce**
1. Run `npx vitest run src/worktree-port-registry.test.ts` in
`packages/shared`.
2. Repeat the run under bounded processor contention.
3. Set the heartbeat interval to 3000 ms and run the asynchronous
critical-section test.

**Paperclip version or commit**
`a661caf74e704f7700a8b8a1e79b76ebd04e3483`

**Deployment mode** Built from source.

**Installation method** Built from source.

**Agent adapter(s) involved** Not adapter-specific (core test).

**Database mode** Not database-related.

**Additional context** Related open pull requests are #11994, #11985,
and #11922. This pull request keeps all five tests active and does not
use `skip`, `skipIf`, or `todo`.

## What Changed

- Build the fallback-probe lock state by hand so no live heartbeat
changes the timestamp during the assertion.
- Count distinct heartbeat refreshes in the asynchronous
critical-section test.
- Close the fake probe and settle the pending lock attempt in a
`finally` block.
- Keep production code unchanged.

## Verification

- `npx vitest run src/worktree-port-registry.test.ts` — 5 of 5 tests
pass.
- `npx vitest run` — 72 files and 704 tests pass at submit time.
- `npx tsc --noEmit` — exit code 0.
- Ten target-file runs pass under bounded processor contention.
- A 3000 ms heartbeat interval fails with `expected 2 to be greater than
or equal to 3`.
- An inverted cleanup assertion exits normally in 379 ms without a
leaked worker.

## Risks

Low risk. This pull request changes one test file. It changes test setup
and assertions only.

## Model Used

OpenAI GPT-5 through Codex. Exact model ID: GPT-5. The model used tool
calls and code execution. The context window is not disclosed by the
runtime.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` /
`Closes: #` / `Refs: #` OR (b) described the issue in-PR following the
relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:24:00 -07:00
Nicky LeachandPaperclip 9d0f7e2ddd fix(adapter-utils): make the directory merge lock crash test deterministic (#14881)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - A workspace restore merges a directory, and a cross-process lock
serializes that merge
> - The lock must recover after the process that holds it crashes
> - One test proves that recovery: it kills the holder process and then
acquires the lock
> - That test failed intermittently for two independent reasons, and
this pull request removes both
> - First, it spawned the holder through the tsx command-line entry
point, which re-spawns the evaluated code in a further child process, so
the kill signal reached only the wrapper and the real holder kept the
lock
> - Second, it replaced the global clock to force a timeout, which left
the acquisition with zero real retries, so a single transient busy
result failed the test
> - The benefit is a deterministic crash-recovery test and a reliable
continuous-integration signal

## Linked Issues or Issue Description

**What happened?**

The test `recovers a killed holder even when its recorded PID has been
reused` in `packages/adapter-utils/src/directory-merge-lock.test.ts`
failed intermittently in continuous integration. The failure reported
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` with `waitMs: 3` and
`knownLocalHolder: false`. A rerun of the same job on the same commit
passed.

**Expected behavior**

The test must pass every run. It must acquire the lock after the holder
process dies.

**Steps to reproduce**

1. Check out `master`.
2. Run `npx vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts`.
3. Repeat the run. The named test fails intermittently.

**Paperclip version or commit**

`32e9f3ba0ec000578936731990d23bb0e77493fa`

**Deployment mode**

Built from source. The failure appears in the general test job of
continuous integration.

**Agent adapter(s) involved**

Not adapter-specific (core bug).

**Relevant logs or output**

```
ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT
workspaceRestoreLock: { ownerState: 'alive', knownLocalHolder: false, waitMs: 3,
                        ownerSameProcess: true, ownerAgeMs: 60030, ownerPredatesProcess: true }
```

## What Changed

The test file had two independent defects. This pull request removes
both.

**1. The kill signal did not reach the real lock holder.**

The test spawned its holder through the tsx command-line entry point.
That entry point re-spawns the evaluated code in a further child
process. `SIGKILL` therefore killed only the wrapper, and the process
that had opened the lock database survived as an orphan that still held
the lock. The test now loads tsx as an `--import` hook, so the spawned
process is the real holder and the kill releases the lock at once. This
also stops the test from leaking an orphan process.

**2. The forced clock left the acquisition with zero retries.**

A test helper replaced `Date.now` to force a timeout. The implementation
reads `Date.now()` one time, to compute its deadline, so that single
read consumed the forced value and every later read returned a time
already past the deadline. The retry loop therefore got one attempt and
no retries. That is correct for a test that asserts a timeout, but the
crash-recovery test asserts a *successful* acquisition, so any transient
busy result on the first attempt failed it.

The fix removes the clock replacement from the whole file and gives each
test a real, short, explicit wait budget:

- `withDirectoryMergeLock` takes a new optional wait-budget parameter.
It threads through to the lock acquisition function. The production
default is the existing 30-second budget, and no production call site
changed.
- The five tests that assert a timeout pass a real 200-millisecond
budget. Each one still times out for the real reason, because the lock
is genuinely held or the legacy lock directory genuinely exists. Each
one now exercises at least four real retries of the 50-millisecond retry
interval.
- The crash-recovery test passes a real 5-second budget. A failure now
reports the structured `ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` diagnostic
well inside the test timeout, instead of a bare test timeout.

**No test timeout increased.** Every `it(..., N)` timeout in the file
equals its value on `master`.

## Verification

- Measured the first cause rather than assumed it: the spawned wrapper
process reported one process id, and the process that opened the lock
database reported a different process id and named the wrapper as its
parent. The real holder kept the lock for about 50 to 60 milliseconds
after the kill.
- Reproduced the failure deterministically before the change, with no
artificial processor load: 15 of 15 runs failed. Confirmed the fix: 15
of 15 runs passed.
- Ran the lock test file 15 times in series: 12 of 12 tests passed every
time.
- Confirmed the clock replacement is gone: a search for a `Date.now`
override in the file returns nothing.
- Confirmed the production default is unchanged at 30 seconds, and that
the diff touches no production call site.
- Proved the diagnostic still surfaces: with a temporary edit that held
the lock with a genuine live holder, the test failed with
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` and the full `workspaceRestoreLock`
block at about 5 seconds, inside the 15-second test timeout. The
temporary edit was reverted.
- `workspace-restore-merge.test.ts` passed 56 of 56. The adapter test
files that cover every production caller passed 116 of 116 and 52 of 52.
`agent-directory-working-copies.test.ts` passed 70 of 70.
- The `adapter-utils` and `server` type-checks passed with no error.
- Confirmed that no spawned process survives the test run.

## Risks

Low risk. The production change is one optional parameter with the
existing default, so every production caller keeps the real 30-second
budget and no production call site changed. The remaining change is
limited to one test file. The `--import` form of the tsx hook is already
used elsewhere in this repository, in the container image command and in
an end-to-end test configuration. Test coverage does not drop: the owner
record is diagnostic only, the SQLite reserved lock remains the
authority that the tests exercise, and the timeout-asserting tests now
exercise the real retry loop instead of a replaced clock. The file costs
about 0.5 to 0.9 seconds more wall clock than `master`, which is the
cost of the short real waits that replace the instant forced timeout.

## Model Used

Claude Sonnet 5 (`claude-sonnet-5`), used with extended thinking and
tool use for the diagnosis, the measurement, and the change.

## Checklist

Check every box that the state of the pull request satisfies. The local
test runs and the type checks are complete. Reconcile the
continuous-integration and review boxes after the checks reach their
terminal state.

## Test plan

- [x] Continuous integration is green on every check, including the
general test job.
- [x] The general test job passes the file
`packages/adapter-utils/src/directory-merge-lock.test.ts`.
- [x] Greptile returns 5 of 5 with no open item.
- [x] `mergeable: MERGEABLE` is terminal.

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:17:03 -07:00
DottaandPaperclip 6c1a75da49 feat(connections): make AgentMail a default connection with inline setup (#14772)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections give agents access to external services.
> - AgentMail needs both a saved key and an inbox assigned to the agent.
> - Chat requests offered a setup link instead of an inline card and
could treat a saved key as complete.
> - Inbox setup also hid address conflicts behind a generic server error
and a separate review step.
> - This pull request makes AgentMail a default connection, adds the
inline card, reduces setup to two steps, and shows conflicts beside the
address.
> - Shared native dropdown styles also give every caret a consistent
inset.

## Linked Issues or Issue Description

**What happened?**

AgentMail requests in chat did not show a usable inline connection card.
Manual setup required extra screens, ignored saved account keys, and
could trap new-address setup in a locked inbox dropdown. Agent selectors
omitted the avatar from the selected value. A taken address could
produce an HTTP 403 from AgentMail and appear as an internal server
error. Native dropdown arrows also touched the right edge of their
fields.

**Expected behavior**

Make AgentMail available as a default connection. Ask for the API key
inline, with a direct link to its provider page. Default human access to
the company and agent access to the requesting agent. Resume the agent
only after an assigned inbox is active. Manual setup should ask for an
agent and email address, then finish. Address checks should run as the
user types. Taken addresses should show clickable alternatives. A domain
dropdown beside the name should prefer a verified custom domain. Setup
should suggest authorized saved AgentMail keys and show agent avatars in
the picker and selected value.

**Steps to reproduce**

1. Ask an agent to connect AgentMail when it has no assigned inbox.
2. Check that an inline API-key card appears and links to the provider's
API-key page.
3. Open AgentMail setup, choose an agent, and request an address that is
already taken.
4. Correct the inline error, refresh, and finish setup with the same
request ID.
5. Inspect native dropdown carets in light, dark, disabled, and
right-to-left states.

Uses the bounded provider-error parser merged in #14768. Related work:
#13256 introduced AgentMail; #14725 expanded connection search.

## What Changed

- Stop recurring email queries for tasks that have no email thread.
Share the query between the thread provider and activity view. Keep
email-task updates and invalidation-based discovery.
- Make AgentMail available without the experimental chat setting. Keep
the catalog, setup and management routes, agent Channels tab, task email
feed, receiving worker, and agent tools available by default. Other
experimental chat providers stay gated.

- Make the email address and copy icon a single clickable action with
the shared Copied! confirmation. Add View inbox linking directly to the
matching AgentMail console inbox, with the address encoded as one URL
path segment.

- Reorganize inbox Settings around the copyable email address, usage
instructions, and receiving status. Move reconnect credentials into a
disclosure and separate the Disconnect action. Add production Settings
stories for active, paused, unassigned-address, revoked, webhook,
long-address, mobile, and reconnect states. Show repair controls when
the inbox has an error. Keep usage instructions tied to an active inbox
with an address.

- Add AgentMail channel intents and an inline key field with the direct
API-key URL.
- Keep setup and retry state tied to the interaction. Require an active
inbox for completion. Preserve company and agent access checks.
- Reduce manual setup to agent selection and email selection. Put the
domain dropdown beside the address and default to a verified custom
domain. Preserve explicit choices across reloads. Keep receiving
settings under Advanced options.
- Check the initial address and edits after a 350 ms pause. Abort
superseded requests and ignore stale responses. Show clickable
suggestions and retain known creation conflicts across reloads.
- Add a company-scoped, manager-only address check using the saved
credential. Search the visible inbox list instead of fetching an
uncreated inbox: live AgentMail retains negative lookups that can break
subsequent access-key creation. Unlisted addresses remain unknown;
creation is authoritative.
- Suggest labeled saved AgentMail keys in both manual setup and the
inline card. Filter by company, provider, active credential, and
current-user grants on the server. Prefer an account key and preserve
the selected key or an explicit new-key choice across refresh. Use
verified scope metadata and bounded concurrent checks for legacy keys.
Never return secret values.
- Catch an inbox-only key before the email step. Allow its existing
inbox only after an explicit choice. Recover old locked drafts at the
key picker. Save the replacement key before retiring an empty draft,
then use a new setup URL so refresh preserves the switched account; stop
if cleanup fails. Preserve already allocated addresses and their
original accounts.
- Use the shared AgentSelect in email setup. Show the canonical agent
avatar in each option and the selected value, including other consumers
of the shared component. Add regression coverage for legacy and current
Lucide agent-mention icon formats.
- Start each catalog Add connection with a fresh setup identity. Honor
Finish setup's exact draft/account/address instead of resuming an
unrelated browser draft. Return Cancel and Done to Connectors and Email
settings to the inbox. Group the task/thread explanation in a How it
Works card.
- Route AgentMail catalog removal through the email inbox control API,
including unfinished drafts. Refresh both the catalog and inbox views.
- Render each inbox management tab separately. Access uses the saved
account grants and agent controls; Conversations and Activity use the
shared persisted email feed. Activity lifecycle actions use the email
API. Reconnect returns to inbox Settings. Conversation failures show a
retry instead of a false empty state. Email delivery recovery stays in
the task.
- Map documented provider address conflicts to a field error. Preserve
actionable messages for other failures.
- Preserve non-secret draft fields across refresh, scoped to the
requested agent. Never save API keys in browser storage. Resume partial
inbox creation with the original agent, address, and request ID.
- Show an already-created address with explicit retry and new-address
recovery instead of locked inputs. Preserve the original inbox and
resumable draft when choosing another address. Distinguish runtime-key
404 errors and log safe provider status/operation/code.
- Apply final agent access once within email setup authorization for a
new account whose original installs are unchanged. Preserve later
permission edits and reused account installs. Support in-place retry of
progress loading.
- Let a failed inline setup change keys after retiring an empty draft.
Persist its replacement setup identity without storing secrets. Recover
a server-saved account when refresh interrupts the save response, while
preserving intentional account changes.
- Render the production setup in Storybook and add error, recovery, and
mobile states.
- Inset native select carets in shared CSS. Preserve custom icons,
listboxes, keyboard behavior, and forced-color controls.
- Add browser regression coverage and an AgentMail Product E2E case with
persisted-state and rendered-card evidence.

## Verification

- Full `pnpm -r typecheck`, `pnpm build`, `pnpm check:token-gates`, and
`git diff --check` passed after the default-availability change.
- All 485 focused tests passed. These cover setup, management, catalog
and route gates, connection intents, email authorization, Cursor
execution, and the OpenAPI contract. All 39 email integration tests run
with the experimental chat setting off.
- The shared polling change passed four behavioral tests, UI typecheck
and build, and token gates.
- `tests/e2e/agentmail.spec.ts` passed with the actual server setting
off. This full-stack browser test uses simulated provider responses. It
covers catalog entry, saved keys, editable address and domain controls,
creation, conflicts, retry, all management tabs, clipboard feedback, the
provider link, and task email rendering.
- In the live local browser, Add connection reached the editable email
step with the saved account key. The verified custom domain was selected
by default. Both domain choices worked. The existing inbox Settings page
remained available. Both active inboxes completed new mail checks with
the setting off. No new provider inbox or email message was created for
this pass.
- Earlier live provider acceptance covered creation on a verified custom
domain, Finish connecting on the reported draft, successful mail checks
after refresh, and catalog removal of disposable draft and active
connections. Clicking the email address copied the exact address and
showed Copied!. View inbox opened the same inbox in AgentMail’s console.
No email messages were sent.
- Production setup and Settings Storybook builds and interactions
passed. Settings states include active, paused, unassigned, revoked,
webhook, long-address, mobile, and reconnect. Receiving and
revoked-access stories had zero accessibility violations.
- Full local `pnpm test:run` on an earlier revision completed with
14,709 passing, 87 skipped, and four transient failures. All four failed
cases passed in focused reruns without product changes. That serial full
local command was not repeated after each follow-up. The latest-head
full CI suite is the final test gate.
- CI found an obsolete browser assertion that hid every channel when the
flag was off. Updated it to keep AgentMail and the Channels surface
visible while preserving the GitHub chat route gates. All 11 provider
browser tests passed locally after scoping the Channels selector to the
agent sidebar. Two initial local attempts stopped at temporary Postgres
initialization. The passing run used a separate disposable database on
the existing local Postgres server; it was removed after the test.
- Updated the remaining sidebar and aggregator discovery assertions for
default AgentMail availability. Ordinary task fixtures now return no
email thread. All 128 sidebar/task-page tests and all 42 aggregator
tests passed locally.
- Latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`: full CI
passed, with 54 successful checks including Snyk and two intentional
Storybook skips. The CI run is
https://github.com/paperclipai/paperclip/actions/runs/37020833647. A
fresh Greptile review scored 5/5 with no unresolved threads. Live model
evaluations and inbound/outbound email delivery were not run.

## Risks

- AgentMail no longer needs experimental opt-in. Setup still requires a
human to connect an account and assign an inbox. Inline setup creates an
inbox after a human submits a new or saved key. Company access, agent
access, inbox assignment, and completion checks remain enforced.
- AgentMail read APIs cannot prove global address availability. The
visible-list check is bounded to 100 entries and cannot see inboxes
outside the key’s scope. The UI reports this limitation, suggests
alternatives without claiming they are free, and keeps final creation
conflicts inline. Lookup outages show an error without preventing the
authoritative creation attempt.
- Native select CSS affects the whole app. Custom-icon selects and
multi-row lists are excluded. Forced-color mode keeps the browser caret.
- Saved-key discovery uses stored verified scope metadata and checks
authorized legacy credentials concurrently within a shared three-second
deadline. Provider outages mark legacy choices unavailable; users can
still enter another key. Final use rechecks authorization and provider
access.
- No database migration or transport default change. Live connection
remains the default.

## Model Used

OpenAI Codex, GPT-6, with reasoning, tool use, and code execution. The
exact served model ID and context-window size are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused suites; full-suite
limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green (latest head
`b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`)
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`)
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 10:01:15 -05:00
DottaandPaperclip ec3bacc9bd fix(chat): hide ignored provider information (#14929)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Task and agent chats show agent progress and problems that need
attention.
> - Codex also sends account, skill, and unrelated thread notifications.
> - The runner correctly ignores that information but reports it as a
warning.
> - Chat then shows an internal diagnostic as an actionable provider
notice.
> - This pull request keeps the diagnostic in run logs and removes it
from chat.
> - Real provider warnings, errors, and agent replies remain visible.

## Linked Issues or Issue Description

**What happened?**

Chat showed “Received a provider update” and a warning with the text
“ignored
unrelated provider information”. Its details said “User Actionable: Yes”
even
though no user action was needed. Saved conversations retained the same
noise.

**Expected behavior**

Keep ignored provider information in the run log. Do not show it as chat
activity
or a user warning. Preserve real warnings and errors.

**Steps to reproduce**

1. Start a conversation with the native Codex runner.
2. Have the provider send an account update, skill change, or unrelated
thread
   notification during the turn.
3. Inspect live chat and reload its saved history.

The regression tests also reproduce the old stored notice without a live
account.

**Paperclip version or commit**

Source implementation on master at `e00d10d5d`. The duplicate search
found no
open PR for this fix. Related prior work: #13109 improved
provider-notice
presentation. #12367 added Codex thread normalization. This change
addresses
the internal information that those paths still projected as chat
warnings.

**Deployment mode**

Native Paperclip Runner with the Codex app-server provider. The issue
was seen
in hosted chat and can be reproduced with local provider fixtures.

## What Changed

- Map ignored unrelated Codex information to `harness.diagnostic` in the
Rust
  and TypeScript normalizers.
- Retain a bounded allowlist of redacted provider method and thread/turn
identifiers.
- Use the same Unicode character limit and truncation marker in both
normalizers.
- Share the text redactor through a pure helper. Keep provider
connection code
  out of the standalone demo's source closure.
- Omit that diagnostic and the matching legacy notice from live chat.
- Omit the matching legacy notice from saved chat history.
- Test diagnostic retention, account-notification integration, live and
saved
  chat, and continued visibility of real warnings, errors, and replies.
- Document the local run-log event and historical display behavior.

## Verification

- Passed: 68 tests in the two affected UI transcript suites.
- Passed: 60 TypeScript tests across provider events, transport
behavior, and
  the standalone demo boundary.
- Passed: 13 Rust provider-event tests and the Codex
account-notification
  integration test.
- Passed: `pnpm check:token-gates` and Cargo formatting checks.
- Passed: full `pnpm build` and `pnpm -r typecheck`. After the review
fix,
the provider package build, typecheck, and both provider-event suites
passed again.
- Full local `pnpm test:run` failed: 608 files / 10,904 tests passed, 30
server
suites failed, and 104 files / 4,012 tests were skipped. Most failures
were
  embedded PostgreSQL startup errors. Two tests timed out in
`heartbeat-comment-wake-batching` and
`workspace-git-snapshot-streaming`.
  PostgreSQL startup also failed in `heartbeat-run-event-sequencing` and
`native-finalization-migration`. These server files are unchanged by
this PR.
Isolated heartbeat reruns were skipped locally. The stable test script
stopped
  after this general-server group, so later groups did not run locally.
- The original review thread is resolved. Greptile is 5/5 on current
head
  `683dab7cce57187c57e84c83f5e9da4ad75c9c04`.
- All current-head CI gates passed, including the full
server/chat/workspace
test matrix, Rust and TypeScript runner suites, browser E2E, build,
typecheck,
and release canary. [CI
run](https://github.com/paperclipai/paperclip/actions/runs/37021330663).
- Replay the exact old warning in either transcript adapter. It must
produce
no chat row. A genuine provider warning or error must still produce a
row.

## Risks

- Low risk. The display filter matches one diagnostic code or the
complete
  legacy warning shape. Other provider notices remain visible.
- New ignored-information events use the existing harness-diagnostic
event
type. They retain diagnostic evidence without original account payloads.
- No database migration, API permission, provider execution, or recovery
  behavior changes. This affects the local run log, not Telemetry or
  OpenTelemetry exports.

## Model Used

OpenAI Codex, GPT-6. The exact backend model ID and context-window size
are
not exposed in this session. Used reasoning, repository inspection, code
editing, tool use, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run the affected tests locally and they pass (the broad
local run has PostgreSQL startup errors and timeouts documented above;
the full CI matrix passed)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 09:59:34 -05:00