Add a bounded native Intel ABBA diagnostic using the exact retained baseline and separately compiled unpublished streaming candidate. Keep full output integrity, process ownership, and diagnostic-only attribution.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Pin normal Intel verification to c9 and require the default Pi-only qualified provider pack. Preserve the historical baseline diagnostic and all startup deadlines.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Pin the final source and profile, restore fresh Rust compilation with SDK provenance, and keep manual immutable-source checks independent.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bind the existing bounded diagnostic to the exact failed W pack and add sparse native-manifest and layout timings without changing startup assertions, deadlines, or cleanup.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Admit complete source and Runner artifacts before upload, stage the exact Runner evidence closure without following directory symlinks, and audit immutable source and lock inputs after full source checks. Bind native Intel preparation to the reviewed W revision while preserving verification commands and deadlines.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Admit reviewed U source with the updated 26-cell catalog expectation in the existing hosted support mode.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Pin the existing hosted Linux E2E support mode to reviewed recovery harness 4c6adcad without changing runtime or verification behavior.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reduce diagnostic polling pressure while retaining fatal inspection failures and exact process cleanup. Keep shared inspection defaults and original startup assertions unchanged.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Build current TypeScript and provider pack while admitting the exact retained native daemon through source-input equality and original compiler provenance. Keep original startup assertions and evidence bounds.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep the rustup PATH alias instead of invoking its rustup-init target directly. Audit resolved target bytes and recheck them before invocation; add a regression reproducing symlink-based CLI dispatch.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Archive and verify the complete tested pack before startup checks. Make cleanup uncertainty sticky across test cases, retain scratch after interrupted launches, and enforce the reviewed 16 GiB seven-day artifact storage bound without truncation.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Add an exclusive manual no-provider lane that rebuilds the reviewed Pi 1.0 source and lock closure, checks native Intel execution, and retains unchanged startup/SDK test evidence with owned cleanup.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Increase only the pinned Rust/browser setup limit from eight to fifteen minutes after hosted dependency downloads exceeded the prior step limit before tests began.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Match the existing grouped CI prerequisite by compiling shared and plugin SDK exports before running the unfiltered root tests on a clean ignore-scripts install. Retain bounded prerequisite logs and exit status.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
The hosted source check interrupted a still-progressing root test suite after 15 minutes. Recorded server groups alone require roughly 85 serial minutes. Add a strictly guarded source-root-tests-only modifier and allow the unfiltered root test command up to 180 minutes, with retained timing and progress evidence.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Move the exclusive verify_source mode off the EC2 fleet and require immutable source and reviewed resolved-lock inputs. Retain per-command results and dependency evidence on failure.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Check failed-run retry eligibility under the run and coordinator locks, fail closed on concurrent coordinator claims, and preserve same-caller recovery after the audited intent disables a retry. Keep terminal failures and foreign actors or intents rejected.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 79db1c2a6f)
Reserve an optional board request UUID under the run lock and retain it
through default Stop joins and native dispatch. Reject prior or competing
intents and require the same actor for idempotent retries.
Bind the Copilot denial fixture to its exact request and audited intent,
with versioned causal receipts and negative controls for earlier Stop.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep direct-child fallback bounded when process inspection fails, preserve incomplete cleanup evidence, and select graceful owners from the delivery snapshot without signaling already-covered descendants again.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep runnerd authority item IDs separate from native notice IDs. Retry optional diagnostic persistence on later state transitions without suppressing authoritative terminal save failures.
Co-Authored-By: Paperclip <noreply@paperclip.ing>