Commit Graph
833 Commits
Author SHA1 Message Date
Dotta 3d21d375de Record current profile qualification and controller settlement fix 2026-09-30 02:56:03 -05:00
DottaandPaperclip 44e1b421cb Record Cursor plan correlation failure and reviewed profile7 candidates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip 913f374191 Preserve native Copilot assistant message identities
Verify and extract the pinned Copilot distribution, preserve native message IDs on the ordered ACP stream, and bind the guarded distribution to profile v7. Keep interim messages separate from final output.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip 770dc88a11 Bind Cursor plan waits to the native tool lifecycle
Carry the admitted native plan parent tool into canonical request identity and require its exact successful durable lifecycle before passive settlement. Preserve historical committed Cursor6 waits while versioning new admission to Cursor7.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip ade7c83dbb Preserve committed Cursor plan waits across profile upgrades
Keep current profile qualification mandatory when first creating a wait. Recovery uses its scoped committed receipt to verify the entire original proof, so future catalog/settings changes cannot authorize task work. Cover actual persisted finalization, catalog drift, original-profile tampering, and document explicit user continuation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip aec34c693f Record final local verification and Copilot message identity candidate
Keep the failed full invocation and original paid cases explicit. Link the exact fixture corrections and independently reviewed v7 source proof.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:34:21 -05:00
DottaandPaperclip 6b1e96af0f Record Copilot command and message-boundary qualification limits
Retain the failed paid case and original proof gaps. Document the verified private dependency-lock overlay and bot-owned tracked lock restoration.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:02:34 -05:00
DottaandPaperclip 672555ffbc Record current rich ACP qualification evidence and capability gaps
Separate source415 and source81 controller evidence from the unchanged e822 runtime. Retain failed attempts, scope the native denial pass, document pending plan settlement and exact command correlation, and distinguish implemented Pi notices from remaining rich-field gaps.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:48:33 -05:00
DottaandPaperclip 951b06d08a fix(runner): fence warm ACPX owners on runtime contract changes
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 21:40:17 -05:00
DottaandPaperclip 632e7c9802 docs(runner): record paid ACP qualification gaps
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 21:40:17 -05:00
DottaandPaperclip 5605c350b2 fix(runner): retain native Cursor mode in shared session checkpoints
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 19:59:27 -05:00
DottaandPaperclip a9e6757255 docs(runner): separate revised candidates from historical paid evidence
Record Cursor5, Copilot5 and Pi8 deterministic validation, retain all earlier failures and identify fresh qualification gates.

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-29 16:41:43 -05:00
DottaandPaperclip a97b626081 fix(runner): preserve Pi native assistant boundaries and notices
Pin Pi profile 8 to native message provenance, preserve explicit empty starts and ends, and keep replay/history and native notices out of final assistant aggregation. Validate fresh, warm and loaded SDK sessions and exact native closure bytes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:30:28 -05:00
DottaandPaperclip 4af314a055 Admit and bind Cursor native session modes in profile v5
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:23:41 -05:00
DottaandPaperclip c73e26107f fix(copilot): bind profile v5 to the final ACPX patch
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:13:35 -05:00
DottaandPaperclip 651110d3a5 docs: retain Cursor continuation qualification outcomes
Record three passing workflows and the exact-response failure without promoting partial file success to qualification.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:08:50 -05:00
DottaandPaperclip 54dfc1bc8e fix(runner): preserve Copilot evidence in the direct driver
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:05:55 -05:00
DottaandPaperclip d3077a061f test(e2e): add Copilot denial and attached settlement cases
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:01:39 -05:00
DottaandPaperclip 07369cc801 docs: record host recovery and authenticated ACP qualification
Retain failed attempts, new local and Daytona passes, current runtime identities, and remaining production gates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 15:58:36 -05:00
DottaandPaperclip 8193905d59 docs(runner): record completed validation and remaining host blockers
Preserve failed broad-suite results and identify successful Runner stages across targeted repairs without claiming an uninterrupted verification pass.

Paperclip-Task: rich-acp-production

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 13:52:19 -05:00
DottaandPaperclip ba21e6c0cf docs(runner): reconcile current paid qualification coverage
Keep historical proofs distinct while recording current Copilot local and Pi Daytona passes and the remaining qualification gates.

Paperclip-Task: rich-acp-production

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 13:45:16 -05:00
Dotta 0a987def5d docs(runner): align remote checkpoint with successful Pi run
Paperclip-Task: rich-acp-production
2026-09-29 13:29:45 -05:00
Dotta 7d59518e53 docs(runner): retain paid remote proof and qualification blockers
Paperclip-Task: rich-acp-production
2026-09-29 13:26:45 -05:00
Dotta bcd6572d60 docs(runner): record current local passes and first remote attempt
Paperclip-Task: rich-acp-production
2026-09-29 13:09:04 -05:00
DottaandPaperclip bd4cc29c30 docs(runner): record current paid qualification and shared recovery fix
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 12:40:38 -05:00
DottaandPaperclip c7869a980a Record current ACP review results and remaining capability gaps
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 12:16:14 -05:00
DottaandPaperclip 7bd453d33d Integrate Pi v7 native tool and input contracts
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '72ded1794':
  test(runner): distinguish Pi blank transport from form support
  fix(runner): admit Pi MCP names and bound native questions
2026-09-29 12:13:58 -05:00
DottaandPaperclip 72ded17946 test(runner): distinguish Pi blank transport from form support
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 12:05:52 -05:00
DottaandPaperclip bb00c85b69 fix(runner): admit Pi MCP names and bound native questions
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 12:00:42 -05:00
DottaandPaperclip 49ba2e61fb Integrate reviewed Cursor and Copilot event fixes
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '2042ca14c42c0112304328b8f059847be4370f6c':
  Keep Copilot notices session-scoped and close early smoke resources
  Bound Cursor child summaries without splitting Unicode characters
2026-09-29 11:50:29 -05:00
DottaandPaperclip 2042ca14c4 Keep Copilot notices session-scoped and close early smoke resources
Copilot passthrough does not identify the originating turn. Retain bounded session evidence and source identity without typed turn projection or invented turn provenance. Acquire smoke resource cleanup before every fallible setup operation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:49:53 -05:00
DottaandPaperclip fdcba3c877 Record current Pi paid proof and remaining qualification gates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:47:58 -05:00
DottaandPaperclip 97217c5313 Integrate reviewed rich ACP instruction and startup fixes
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/runner-pi-acp:
  Bind Cursor instructions to native rules and gate every ACP connection
  fix(copilot): refresh instructions under provider lifetime ownership
  fix(copilot): deliver native instructions with v4 session identity
  docs(runner): retain Pi native prompt delivery proof
  fix(runner): refresh trusted system instructions before ACPX restore
  fix(runner): refresh runtime context when restoring ACPX sessions
  test(copilot): record native system instruction delivery evidence
  fix(runner): refresh trusted system instructions before ACPX restore
  perf(runner): hash Pi runtime inventory with bounded workers
  perf(runner): bound native snapshot copy concurrency at 32
  perf(runner): bound native snapshot copy concurrency at 32
  test(copilot): preserve final question failure and offline recovery proof
  fix(runner): refresh runtime context when restoring ACPX sessions
  feat: return completed handoffs to Agent Chat (#14408)
  fix(adapters): preserve ACP terminal failure diagnostics (#14573)
  fix(runner): honor Codex effort selected in composer (#14568)
  fix: grade Codex clarification and refusal outcomes from evidence (#14570)
  fix(inbox): keep other users’ failed runs out of Mine (#14572)
2026-09-29 11:33:49 -05:00
DottaandPaperclip 23614d28c8 merge: integrate reviewed Copilot and Cursor runtime repairs into Pi
Preserve Pi v6 and bounded startup pools, admit current Cursor and Copilot v4 identities, and combine additive Product flows and catalog assertions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:33:28 -05:00
DottaandPaperclip 9ff6b04b46 docs(runner): record instruction delivery fixes and qualification gates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:33:17 -05:00
DottaandPaperclip 95dfde7c5c Merge current Cursor ACP runtime into Copilot v4
Preserve both profile-specific guards and complete terminal diagnostics; bind Copilot v4 to the regenerated ACPX patch.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:28:38 -05:00
DottaandPaperclip 62e642590f Bind Cursor instructions to native rules and gate every ACP connection
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:24:48 -05:00
DottaandPaperclip 2ff6a8efea fix(copilot): refresh instructions under provider lifetime ownership
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:17:22 -05:00
DottaandPaperclip 3ec07cc8fa docs(runner): distinguish implemented agent file binding from qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:16:58 -05:00
DottaandPaperclip 0f33a9080a fix(copilot): deliver native instructions with v4 session identity
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:12:26 -05:00
DottaandPaperclip f09813baec docs(runner): retain Pi native prompt delivery proof
Record sanitized actual SDK model-request assertions for fresh and loaded sessions, with exact runtime provenance and explicit qualification limits.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:11:36 -05:00
DottaandPaperclip 751f59f26c test(copilot): record native system instruction delivery evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:07:17 -05:00
DottaandPaperclip 42948b9d28 perf(runner): hash Pi runtime inventory with bounded workers
Retain exact checked file reads and traversal order, drain failed batches, and preserve the v6 closure identity. Add credential-free closed Runner startup regression and record both the paid timeout and diagnostic timings without claiming authenticated qualification.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 10:38:05 -05:00
DottaandPaperclip 3a08122558 Merge current master into Cursor ACP provider branch
Preserve upstream ACPX terminal diagnostics and rich extension delivery hooks.

Co-Authored-By: Paperclip <hello@paperclip.ing>
2026-09-29 10:36:20 -05:00
DottaandPaperclip 5630481a38 test(copilot): preserve final question failure and offline recovery proof
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 10:34:51 -05:00
DottaandPaperclip c4cc87fb38 docs(runner): record current paid qualification blockers
Co-Authored-By: Paperclip <hello@paperclip.ing>
2026-09-29 10:31:22 -05:00
DottaandPaperclip 83076d7e7c feat: return completed handoffs to Agent Chat (#14408)
Return completed Agent Chat handoffs through a durable outbox and scope each generated update to its supplied tasks. Add recovery, browser delivery, result access, and calibrated quality coverage.

Validated with two consecutive ten-case Claude/Codex campaigns, all CI checks, and a 5/5 review.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 10:25:52 -05:00
DottaandPaperclip 3b4b270650 fix(adapters): preserve ACP terminal failure diagnostics (#14573)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The shared ACP adapter engine records agent failures for operators.
> - ACP providers can report a failure category, title, and detailed
cause.
> - Our patch kept only the category in the saved error, so an operator
could not diagnose a failure when tracing was off.
> - This pull request preserves redacted provider diagnostics in the run
error, transcript, and structured run result.
> - Operators can now inspect the provider message and any supplied
request ID or stack trace after the run ends.

## Linked Issues or Issue Description

Refs #13889 (the diagnostic gap; this PR does not update the bundled
Claude version).
Refs #14484 (related model-refusal classification; this PR retains
diagnostics for all terminal failure categories).

**What happened?**
An ACP turn failed with only `ACP agent reported a terminal service
failure.` The provider's title and details were available in memory but
absent from the saved error and transcript.

**Expected behavior**
The run retains useful provider diagnostics even when raw tracing is
disabled. Credentials remain redacted. A size limit must report
truncation instead of silently removing the cause.

**Steps to reproduce**
1. Run an ACP agent that returns an error-severity typed session
failure.
2. Include an HTTP error, request ID, and stack text in its title and
details.
3. Inspect the failed run with tracing disabled. Before this change,
only the category survives.

## What Changed

- Both pinned ACPX patches pass complete error text to the in-memory
callback, so redaction happens before truncation.
- The shared engine retains the sanitized category, title, and details
in `resultJson.terminalSessionFailure` and includes the text in the run
error and error transcript.
- Diagnostics redact configured environment values even under arbitrary
names, unknown launch-environment values, connection URL passwords, run
credentials, and common credential syntax. Known boolean settings remain
readable, while credential values are redacted even when embedded in
other text. Diagnostics remove control characters and invalid Unicode.
- Title and detail limits keep escaped transcript JSON below the
server's chunk limit. Truncated fields include an omission count. The
safe run-result projection preserves a byte-bounded diagnostic preview
when the result exceeds its byte budget, with an explicit pointer to the
full adapter-bounded run error and transcript.
- The existing UI and CLI display the error. Diagnostics do not become
assistant output. Issue continuation summaries and session-compaction
prompts receive only the generic category, preventing provider text from
becoming handoff instructions. Existing quota classification, warnings,
timeout precedence, and control-channel failure precedence remain in
place.
- Regression tests cover real ACP child processes with both pinned
versions in one-shot and persistent modes, credential redaction, request
IDs after the old 4 KiB cutoff, transcript parsing, storage bounds, and
database retrieval of oversized multibyte diagnostics.

## Verification

- Full CI on `20ad4f5f1f66c46d2c260e6ad0339cbea607b4cf`: **54 passed, 2
intentionally skipped, no pending or failing checks**. Includes
typechecking, build, all Vitest shards, Runner checks, browser E2E, and
the canary packaging/public-install dry run.
- Greptile: **5/5** on this commit. Superagent security scan passes. All
review threads are resolved.
- Local verification passed: shared ACP engine suite (395 tests); real
Claude ACP child-process and diagnostic regressions across both pinned
runtimes and both execution modes; run retrieval and model-handoff
regressions (59 tests); ACPX patch packaging (16 tests); full typecheck
and build. Affected package typechecks and focused tests were rerun
after review fixes.
- The broad local `pnpm test:run` was stopped after review edits made
its cached imports stale. Fresh targeted runs pass, including both
affected server suites. Cold-build import failures were also rerun after
dependency builds: chat integration (1,063 tests) and tool access (351
tests) pass. The final commit's complete CI matrix is green.

## Risks

- Provider diagnostic text is untrusted. This change retains more of it
in company-scoped run records. Redaction and size bounds apply before
persistence.
- Diagnostics are limited to fields the provider supplies. Old runs
cannot recover discarded error text.
- No schema migration, recovery-policy change, or new Telemetry or
OpenTelemetry export.

## Model Used

- OpenAI GPT-6 through Codex, with reasoning, repository inspection,
code editing, and test execution. The exact serving model ID and
context-window size are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-29 10:18:30 -05:00
Dotta 6766b9128e Merge branch 'codex/runner-copilot-acp' into codex/runner-pi-acp
* codex/runner-copilot-acp:
  Admit the verified Copilot v3 identity in Rust
  Admit the verified Cursor v3 identity in Rust
  Admit current ACP profiles and verify cross-language pin agreement
  Follow current Copilot profile identity in native installation admission
  Preserve authoritative Copilot guard errors for pending ACP requests
  Preserve Copilot policy rejection codes across sidecar transport
  Bind Copilot v3 identity to native detached-work admission
  Deny native Copilot detached work before permission dispatch
  Prove Cursor SDK interactions and retain profile v3 build evidence
  Bind Daytona image identity to Cursor isolation patch
  Retain Copilot detached-command early completion regression
  Prove Copilot permission recovery after provider death without replay

# Conflicts:
#	packages/paperclip-runner/src/drivers/acpx/qualified-profiles.ts
2026-09-29 10:10:17 -05:00
Dotta 550801f956 Merge branch 'codex/runner-cursor-acp' into codex/runner-copilot-acp
* codex/runner-cursor-acp:
  Admit the verified Cursor v3 identity in Rust
  Admit current ACP profiles and verify cross-language pin agreement
  Prove Cursor SDK interactions and retain profile v3 build evidence
2026-09-29 10:08:55 -05:00