Commit Graph
5250 Commits
Author SHA1 Message Date
DottaandPaperclip cca38f29a4 Carry lowercase proxy settings through Pi installation
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'b7e692f48d8d98de32831d85cbd134eed95a26f6':
  Preserve lowercase proxies through explicit Pi downloads
2026-10-05 14:38:07 -05:00
DottaandPaperclip b7e692f48d Preserve lowercase proxies through explicit Pi downloads
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 14:37:29 -05:00
DottaandPaperclip 5aff21d776 Carry explicit Pi setup network and SDK fixture corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'fcef1eae9bc7e780732ab47fcbe71de1a8aa9714':
  Preserve explicit Pi setup network settings and current SDK fixtures
2026-10-05 14:28:02 -05:00
DottaandPaperclip fcef1eae9b Preserve explicit Pi setup network settings and current SDK fixtures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 14:27:02 -05:00
DottaandPaperclip 3250c3f685 Preserve complete prerequisite probe repair ancestry
These exports already exist here. Keep the tracked source tree identical while retaining the verified prerequisite repair.

Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'ec67ba1e05fff3eacc59139f6ded998a05a80fb9':
  Complete existing package-local Runner probe export boundary
2026-10-05 13:49:08 -05:00
DottaandPaperclip ec67ba1e05 Preserve complete prerequisite probe repair ancestry
These exports already exist here. Keep the tracked source tree identical while retaining the verified prerequisite repair.

Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '89f44485090f4c0181623e59ed2411044248c743':
  Complete existing package-local Runner probe export boundary
2026-10-05 13:49:06 -05:00
DottaandPaperclip 89f4448509 Complete existing package-local Runner probe export boundary
Carry the companion Runner and server shim exports with the already-forwarded import repair. Full Runner TypeScript typecheck passes, and the real shim resolves all three source function identities without mocks or probe calls. Final shipping source remains unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 13:47:26 -05:00
DottaandPaperclip 30410cf2ba Carry verified Pi prerequisite admission and probe corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '0a3f265c36bdcbda772db424ca4aa775ac110d42':
  Carry existing Pi admission assertions and package-local probe import
2026-10-05 13:38:30 -05:00
DottaandPaperclip 0a3f265c36 Carry verified Pi prerequisite admission and probe corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '32b5e275d56c5070de5a8ecdbec59c78b49a5f68':
  Carry existing Pi admission assertions and package-local probe import
2026-10-05 13:38:22 -05:00
DottaandPaperclip 32b5e275d5 Carry existing Pi admission assertions and package-local probe import
Keep Pi source assertions consistent with the held qualification candidate. Use the existing vendored runtime boundary for installed probes. All four changes already exist downstream; no final shipping input or profile pin changes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 13:37:35 -05:00
DottaandPaperclip 78b02e6baa Carry scoped prerequisite CI fixture corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'c057c574601d91fc9a0cba90f118756a58fc6912':
  test: carry verified Pi prerequisite CI corrections upstream
2026-10-05 13:23:18 -05:00
DottaandPaperclip c057c57460 Carry scoped prerequisite CI fixture corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'f8bbeeb4c38805d1ab44ad40dcbc562f3b581892':
  test: carry verified Pi prerequisite CI corrections upstream
2026-10-05 13:23:10 -05:00
DottaandPaperclip f8bbeeb4c3 test: carry verified Pi prerequisite CI corrections upstream
Align adapter-section admission expectations with the declared source. Preserve the deliberately killed attempt at 500 ms while giving the resumed successful fixture its existing downstream 5-second budget. Preserve the original CI failures and all state, usage and deduplication assertions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 13:21:49 -05:00
DottaandPaperclip 8b0911bdda Merge verified Pi prerequisite review corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'a23e607ecb7fd4d88f8999feb16f40011bb8f4a8':
  test(ui): align Pi admission assertion with prerequisite source
  fix(ui): coalesce bound duplicate Pi failure notices
  test(runner): align held Pi promotion assertions with profile 12
2026-10-05 13:06:14 -05:00
DottaandPaperclip a23e607ecb Keep Pi prerequisite review ancestry synchronized
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'a7b49fc14d67f2c3279ccac2d2506aa33554d017':
  test(ui): align Pi admission assertion with prerequisite source
2026-10-05 13:05:20 -05:00
DottaandPaperclip a7b49fc14d test(ui): align Pi admission assertion with prerequisite source
The shared adapter declaration already marks Pi qualified. Verify that source declaration rather than a stale linked build. Keep the separate production-qualification hold open.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 13:03:29 -05:00
DottaandPaperclip ef1558e027 Merge scoped Pi prerequisite review fixes
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '95a30b7ff':
  fix(ui): coalesce bound duplicate Pi failure notices
  test(runner): align held Pi promotion assertions with profile 12
2026-10-05 13:00:15 -05:00
DottaandPaperclip 95a30b7ffe fix(ui): coalesce bound duplicate Pi failure notices
Preserve the original run log while showing one consecutive failure row for the same run, turn, session, and notice payload. Different bindings, messages, and intervening activity remain distinct.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 12:58:32 -05:00
DottaandPaperclip 5c9ae3f856 test(runner): align held Pi promotion assertions with profile 12
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 12:58:15 -05:00
DottaandPaperclip eac5064321 fix(runner): refresh shared ACP identity and Pi mode fixtures
Preserve the historical Copilot declaration, version the pending identity for shared transport changes, and bind Pi admission fixtures to explicit reasoning mode.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 04:06:31 -05:00
DottaandPaperclip f5c5fde380 Bind Pi 1.0 reasoning modes through rich ACP and recovery
Require explicit native-effective thinking modes, reject drift across reconnects, and retain observed settings in qualification artifacts. Version the profile and pinned wrapper closure for the new contract.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 03:21:26 -05:00
DottaandPaperclip b70cf84ea6 test: align runtime readiness checks with qualified Pi
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 02:09:26 -05:00
DottaandPaperclip 30edeec300 test(runner): verify installed launch and published Daytona plugin
Invoke the public Playwright JavaScript entry directly for installed Pi tests so pnpm shim NODE_PATH injection cannot cross the closed controller boundary. Add a credential-free health/UI startup proof and a pinned published Daytona plugin fixture path without production runtime overrides.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 01:34:42 -05:00
DottaandPaperclip 4c58da84fd test(server): exclude companion fixtures from production compilation
Keep the remote companion tests in the canonical server test directory so Runner source fixtures do not enter the server rootDir.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 00:15:20 -05:00
DottaandPaperclip c3d4677807 docs: record Pi 1.0 installation and Intel qualification gates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 00:13:03 -05:00
DottaandPaperclip f96195a7a6 feat(runner): import verified Linux companions for normal Pi execution
Add explicit public CLI setup and full async source/profile/byte admission for an operator-pinned Linux companion. Preserve existing remote integrity checks and explicit overrides.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 00:09:04 -05:00
DottaandPaperclip 8ced6f9285 fix(runner): use pinned npm for explicit Pi setup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 23:52:29 -05:00
DottaandPaperclip c9de5292d6 test(runner): prove qualified Pi startup without candidate flag
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 23:24:31 -05:00
DottaandPaperclip d385c430bf test(runner): qualify Pi through installed public CLI
Verify installed CLI/server pins and default runtime resolution for explicit Pi Product cells. Keep Cursor and Copilot pending while qualified Pi runs without the candidate override.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:58:39 -05:00
DottaandPaperclip c27bbcee25 fix(runner): provision pinned Pi in published server installs
Add explicit host-only setup, verify the public server vendor layout, and route readiness through the packaged runner boundary. Preserve exact Pi closure and normal-mode admission checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:45:01 -05:00
DottaandPaperclip c806b94084 test(runner): align held Pi promotion assertions with profile 12
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:22:31 -05:00
DottaandPaperclip d40329a06b test(runner): align held Pi admission with qualified sidecar coverage
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:11:19 -05:00
DottaandPaperclip 2c4c6585db Merge Pi 1.0 profile 12 into held production admission
Prepare the reviewed candidate for normal-mode qualification. This branch remains held pending the full local and Daytona proof; no provider is enabled in the published default branch.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:07:08 -05:00
DottaandPaperclip b9e5d6ecdb perf(runner): keep verified snapshot copies progressing
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:03:21 -05:00
DottaandPaperclip 00462b048e fix(runner): preserve packaged daemon executability
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:03:21 -05:00
DottaandPaperclip 9d83e06b85 fix(runner): preserve Pi 1.0 serialized RPC events
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 22:03:21 -05:00
DottaandPaperclip efe019a79f fix(runner): preserve plain Node Pi materializer imports
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 20:14:01 -05:00
DottaandPaperclip 7b7fcbf96b perf(runner): verify Pi launch bytes once into the native snapshot
Cross-bind the Pi layout to its source-pinned native closure before structural discovery. Preserve full byte hashing in every immutable command snapshot and keep the independent generic verifier unchanged.

Add corruption, graph, link, repeated-open and runtime-boundary cleanup regressions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 19:53:47 -05:00
DottaandPaperclip 5a6a531575 test(runner-e2e): account for Pi provider-death catalog cell
Update the Pi candidate matrix assertion from 25 to 26 after adding the Daytona provider-death case. Runtime inputs and all other expectations are unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 19:39:40 -05:00
DottaandPaperclip 4c6adcadcb test(runner-e2e): verify pending Pi input after provider loss
Add one explicit Daytona Product cell that admits the exact Pi child before faulting it, then requires production expiry of the original native question, failed-run Blocked disposition, stale-answer rejection, distinct unanswered fallback, and no replay through owned retirement. Retain the existing local scope and pending qualification.

Calibrate public lifecycle evidence, generated observer one-shot dispatch, and candidate failure classification. Runtime, provider profile, dependency closure, deadlines, and lockfiles are unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 19:26:25 -05:00
DottaandPaperclip 30f5bc57b5 test(runner-e2e): calibrate exact Pi child fault ownership
Add closed Linux pidfd admission for the unique Pi child of a source-pinned wrapper, with full run ancestry and executable identity checks. Exercise title overwrite and ownership-safe cancellation in the standard E2E unit path; macOS explicitly skips the native Linux process calibration.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 19:17:32 -05:00
DottaandPaperclip 586af4d7f3 perf(runner): bound cold runtime directory work
Batch Pi inventory metadata checks while preserving depth-first ordering and revalidating directories immediately before descent. Deduplicate native snapshot parent creation and bound sealing work without changing the complete byte verification, private snapshot, or runtime deadlines.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 18:01:54 -05:00
Dotta 5cd6d3d523 test: strengthen Pi editing and pending native recovery qualification 2026-10-01 17:36:20 -05:00
DottaandPaperclip 89284e2905 feat(runner): prepare held Pi 1 production admission
Replay the inactive Pi-only admission patch on the frozen Pi 1.0.0 source, preserving profile 11, its exact digest and all native closure inputs. Cursor and Copilot remain gated. This local preparation requires complete qualification and rebuilt normal-mode acceptance before activation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 15:45:57 -05:00
DottaandPaperclip 5eba61ece9 Merge recorded master baseline into Pi 1 production candidate
Integrate 8ec4b84e1c before runtime qualification, preserving the new workspace restore lock, continuation and Docker packaging fixes. Pi profile 11 source and distribution inputs are unchanged by this merge.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 15:17:17 -05:00
DottaandPaperclip 2d60b454a7 feat(runner): upgrade closed Pi runtime to 1.0 profile 11
Preserve structural system messages without assistant attribution, disable native cache warming, and require queued continuation acknowledgements. Pin the complete upstream 1.0 dependency closure and retain historical profile evidence.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 15:16:41 -05:00
DottaandPaperclip 3ab022d7df test: align merged directory and continuation fixtures
Remove a duplicate service import, register the warm remote fixture leases required by the cleanup ownership guard, and assert the server-owned bounded continuation for an unauthorized unfinished response wait. Keep runtime implementation and qualified inputs unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 14:48:54 -05:00
DottaandPaperclip 8ec4b84e1c fix(chat): resume messages after failed runs without duplicate delivery (#14857)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - A user can send a new message after a native run fails.
> - The server checks that the old execution has stopped before it
starts a fresh turn.
> - A failed run can retain a result accepted before checkpoint or
cleanup failed.
> - The continuation gate treated that saved result as active recovery
and held the new message forever.
> - This pull request removes that false liveness signal while retaining
controller, process, environment, and authorization checks.
> - Live staging then exposed a second defect: chat admission created a
successor without consuming the original deferred receipt, so completion
delivered the message again.
> - Consume that exact receipt atomically with admission, while
preserving separate turns for later chat messages.

## Linked Issues or Issue Description

**What happened?**

A new user message stayed in the queue with `controller_settling` after
the previous run had reached `terminal_failure`. The old coordinator had
no lease owner but still had a `resultId`. Its remote environment had a
verified stop receipt.

**Expected behavior**

Start one fresh turn after execution has stopped and normal admission
checks pass. Preserve the failed run and its accepted result as history.

**Steps to reproduce**

1. Accept a native result, then fail checkpoint or cleanup and exhaust
recovery.
2. Retain the result ID on the terminal failure record and stop the
execution environment.
3. Send a new user message. Before this fix, it waits forever for the
finished controller.

**Paperclip version or commit**

Reproduced in a database-backed regression test on `26900655b`.

**Deployment mode**

Server with a native runner and remote sandbox. Local process stop
checks also apply.

Related: https://github.com/paperclipai/paperclip/pull/14775. Searched
existing PRs for retained-result continuation fixes; no duplicate found.

## What Changed

- Remove the retained-result veto for terminal failures.
- Keep controller ownership, successor, process, environment cleanup,
pending decision, and ordinary admission checks.
- Add regressions for retained results, active execution, missing stop
evidence, and delayed remote cleanup.
- Atomically consume the resumed receipt in agent chat, even though chat
does not coalesce other queued messages.
- Reproduce completion-time duplicate promotion, race cleanup against
periodic recovery, and prove a subsequent chat message keeps its own
turn.
- Document that a saved result does not make a terminal failure active.
- Keep exhausted workspace export on its separate repair path, tested
through the production finalizer.

## Verification

- Red: retained-result admission failed with `controller_settling`
before the original fix. The new chat-specific regression then
reproduced duplicate promotion when the first reply finished.
- Green: 406 tests across native continuation, workspace-export
recovery, and the wake-queue module passed on `cbc531cc0`.
- The chat regressions exercise real Postgres transactions, simultaneous
recovery callbacks, successful completion, the production queue-drain
use case, and repeated drain attempts. A distinct follow-up remains a
separate turn.
- `pnpm -r typecheck` and `pnpm build` passed on `cbc531cc0`.
- The earlier full local test run encountered a timeout and follow-on
failure in unchanged AI connection-adoption tests; all 50 tests passed
on isolated rerun. That local run was stopped after the full CI test
matrix passed on the earlier head.
- All 54 CI checks passed on `cbc531cc0` (2 skipped), including the full
test matrix and browser shards. One unchanged interaction-route test
returned HTTP 500 on its first CI attempt; its full 84-test file passed
locally, and the failed shard passed on one targeted rerun.
- Greptile reviewed `cbc531cc0`: 5/5, no unresolved findings.
- Live staging first verified that the original saved message resumes
and receives a successful response; that test exposed the duplicate now
covered above.
- Deployed exact commit `cbc531cc0410e1ef6e8811c6c5c014c3528351ed` to
the affected staging workspace; deployment verification, health,
authentication, and startup recovery passed.
- Submitted a fresh message through the browser. The agent replied in 39
seconds; server records show exactly one successful run, native phase
`committed`, no error, and an empty queue. A later check more than a
minute after completion found no duplicate run.

## Risks

The change affects admission after native execution failure and
consumption of a resumed deferred receipt. A fresh turn must never
overlap the prior execution, and consuming one chat receipt must not
absorb later messages. Tests retain the controller, process, and
remote-stop guards. This change does not migrate data, apply an old
result, or reset the old retry budget.

## Model Used

OpenAI Codex (GPT-6). The exact runtime model identifier and context
window are not exposed in this session. Used reasoning, repository
inspection, code execution, database-backed tests, and browser
inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.6
2026-10-01 14:43:02 -05:00
Devin FoleyandPaperclip dd9983b894 fix(adapter-utils): release restore locks when a process crashes (#14869)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agent runs restore workspace files and collect instruction-file
changes.
> - Writers to the same target directory must wait for each other.
> - The current lock records a PID, which a new process can reuse after
a crash.
> - A reused PID can keep an orphaned lock alive and make each later run
fail.
> - This pull request makes a SQLite file lock decide ownership. The OS
releases it when the process exits.
> - Later runs can proceed after a crash, and concurrent live writers
remain protected.

## Linked Issues or Issue Description

Refs #10914. This addresses crash recovery. It does not cancel a stalled
operation in a process that is still alive.

Related work: #9667, #14787, and #12187. The earlier attempt in #9667
assumes one live server per lock root. This implementation uses an
OS-backed lock to support concurrent writers without treating a
different process token or an old timestamp as proof of a dead owner. It
retains the private lock root and bounded timeout diagnostics from the
merged changes.

After a process dies while holding a restore lock, a replacement process
can reuse its PID. The existing `process.kill(pid, 0)` check then
reports a live owner forever. Later runs can complete their model turn
but fail during file collection or restore.

## What Changed

- Hold a SQLite `BEGIN IMMEDIATE` transaction for each directory write.
Use the existing built-in `node:sqlite` dependency.
- Keep each lock database on a stable inode. Keep PID and time metadata
only for diagnostics.
- Retain the 30-second asynchronous wait and existing timeout error code
and diagnostic fields.
- Fail closed when an old directory lock exists. Document a
stopped-writer upgrade and rollback procedure.
- Add real child-process tests for crashes, PID reuse, live owners, and
connection cleanup. Cover callback failures, independent targets, stable
inodes, invalid lock files, and ambiguous legacy records.

## Verification

- Before the fix, the crash/PID-reuse test and the live-owner test both
failed. Both pass with this change.
- `pnpm exec vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts
packages/adapter-utils/src/workspace-restore-merge.test.ts`: 56 tests
passed.
- Restore and agent-file working-copy integration tests: 118 tests
passed before the additional connection-cleanup test.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- Full GitHub CI: all checks passed, including Linux workspace tests,
server test shards, build, typecheck, and browser tests.
- Greptile: 5/5, with no review threads or unresolved comments.
- `pnpm test:run`: started locally, then stopped with SIGINT (exit 130)
after full CI passed. The local serial run did not complete and is not
counted as a full local pass. The completed CI shards provide the
full-suite result.

## Risks

- **Upgrade and rollback require a drain.** Stop every old writer that
shares an instance root before switching protocols. Old and new versions
must not write concurrently.
- Existing legacy `.lock/` directories remain blocking. After all
writers stop, preserve run evidence and move those directories to an
operator scratch directory. The new code does not infer that they are
abandoned from PID or age.
- Never delete or replace a `.lock.sqlite` file while writers can run.
These small files remain after release.
- The shared filesystem must support reliable SQLite locking. Broken
network-filesystem locking is unsupported.
- This change prevents new orphaned ownership. It does not recover file
changes lost during earlier failed collections, or interrupt a live
operation that stalls.
- No application database migration or new native dependency is
required. See `doc/workspace-restore-locks.md` for the procedure.

## Model Used

OpenAI Codex based on GPT-6, with code execution and repository tools.
The exact model variant and context window are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused regression and
integration suites; see the full-suite note above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.5
2026-10-01 12:14:48 -07:00
dependabot[bot] 8f7baf2f72 chore(deps): bump @aws-sdk/client-s3 from 3.1122.0 to 3.1141.0 (#13475)
Bumps
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3)
from 3.1122.0 to 3.1141.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/client-s3's
releases</a>.</em></p>
<blockquote>
<h2>v3.1141.0</h2>
<h4>3.1141.0(2026-09-25)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> smithy-aws-typescript-codegen 0.54.0 (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8314">#8314</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ad80ce3ebaf394679aabc6e26b2dcd023ce8e010">ad80ce3e</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-connect:</strong> Agent Privacy During Hold is a new
privacy capability for Amazon Connect Voice that prevents agent audio
from being captured in call recordings or Contact Lens conversational
analytics during hold. When enabled, agents are automatically muted on
entering hold and unmuted on resuming the contact (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/03527f9ea153365c1e3654ac6d3f3e064d06b5d0">03527f9e</a>)</li>
<li><strong>client-qconnect:</strong> Release shapes for the proactive
agentic recommendations and the multi-knowledge base search features.
Increases the maximum length of QuickResponseContent. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e008332b0b70c55d22dfca8a9c2317b67d06a5f3">e008332b</a>)</li>
<li><strong>client-bedrock-agent:</strong> Adds support for calling VPC
configuration API's in Bedrock. These configurations allow the use of On
Prem connectors in Bedrock Managed Knowledge bases (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/18524dc69cf36ebbb8bc7bc33e0bce6311dcdb23">18524dc6</a>)</li>
<li><strong>client-mediaconnect:</strong> This release adds support for
RTMP push router outputs in AWS Elemental MediaConnect. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5bd8d80bbca2c1c2545521b03d741b46fccd09b4">5bd8d80b</a>)</li>
<li><strong>client-securityagent:</strong> This release adds the
ListActorMessages operation, which returns the multi-factor
authentication messages received at an actor's server-generated email
address (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/10e53d506db74c48b09b94d9b9387b84dd40ed58">10e53d50</a>)</li>
<li><strong>client-arc-region-switch:</strong> Adds a service quota
checker to Region switch to verify quota parity between your primary and
standby Region, and automatically submit quota limit increases. Adds an
optional EC2 Auto Scaling and ECS setting that waits for instances or
tasks in the scaled-up Region to be healthy in target groups. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/cca33e380a8985e23a0e3fbb420577aab4b60ac7">cca33e38</a>)</li>
<li><strong>client-bedrock-agentcore-control:</strong> Amazon Bedrock
AgentCore Payments now supports credential rotation for payment
connectors, letting you rotate API and wallet secrets for Quick Create
payment auths from the console. This release also adds Type and Creation
type columns to the payment managers views. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/adca591f07c448603de2876faaf7914cad441436">adca591f</a>)</li>
<li><strong>client-neptune-graph:</strong> Add GraphIdentifier filter
for ListImportTasks (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/9b9aea9b553ba84f006f95da5d8ffd5381cc8a17">9b9aea9b</a>)</li>
<li><strong>client-rekognition:</strong> This release adds support for
Feedback and Metadata in the GetFaceLivenessSessionResults response.
Feedback returns codes explaining why a Face Liveness check produced its
result. Metadata includes the client SDK type. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0831c361bb69d44357ff57360db39afdbb149337">0831c361</a>)</li>
<li><strong>client-glue:</strong> add support for table level federation
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/a44458b77853cbb25a9fcb362b0a275d7dc1c69b">a44458b7</a>)</li>
<li><strong>client-wellarchitected:</strong> This change releases the
Well-Architected Agent, a generative AI service that analyzes a
customer's AWS environment and delivers personalized, prioritized
recommendations across cost, security, performance, and resilience. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/d0656586067f70b8d50000300f04512dd089df96">d0656586</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.1141.0.zip</strong></p>
<h2>v3.1140.0</h2>
<h4>3.1140.0(2026-09-24)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-route53resolver:</strong> Documentation updates for
Route 53 Resolver. Clarifies which Outpost Resolver operations apply to
first-generation AWS Outposts and that Resolver is managed automatically
on second-generation Outposts. Adds Local Network Interface subnet
compatibility notes for Resolver endpoints. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b4432abaaaf19bf4ac5d4d2b09bcc83e4d5440a0">b4432aba</a>)</li>
<li><strong>client-iot:</strong> Fixed ListV2LoggingLevels and
DeleteV2LoggingLevel documentation to include all supported target-types
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4dcf76d527e0c1fe76d64cb8ea444ce62d64135b">4dcf76d5</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2026-09-24
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/29a8566cb4c6eeb0cc554f4ae9bf985160556523">29a8566c</a>)</li>
<li><strong>client-eventbridgev2:</strong> Introducing Amazon
EventBridge enhanced Custom event bus, a new shareable event bus for
organizational-scale event-driven applications feature ordered delivery,
deduplication, open event formats, and cross-account bus sharing. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/69fbe6a22fd7810332b0b0356803a0eee3f563cf">69fbe6a2</a>)</li>
<li><strong>client-datazone:</strong> Amazon DataZone now supports the
TOOLING blueprint category on CreateEnvironmentBlueprint,
UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and
ListEnvironmentBlueprints, for custom tooling blueprints.
CreateConnection now accepts roleArn in iamProperties. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/591cd6f5a7b714427cbe87b36b13357d560d48ea">591cd6f5</a>)</li>
<li><strong>client-elasticache:</strong> Added tagging support for
ElastiCache Global DataStore. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0fa9da5946312f09942dad6f711885855f0d0b8e">0fa9da59</a>)</li>
<li><strong>client-marketplace-discovery:</strong> AWS Marketplace
Discovery API now supports localized responses and SigV4a request
signing. It returns new fulfillment details, including AMI architecture,
EBS volume and security group information, SaaS quick-launch status, and
SageMaker input and output MIME types. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/510673e376bbc578d318308136ecb5a841416bc3">510673e3</a>)</li>
<li><strong>client-redshift-data:</strong> Updates to the ListDatabases
and WorkgroupName validation (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/218c24e106efe1ad64658984123af6634fc7278d">218c24e1</a>)</li>
<li><strong>client-securityagent:</strong> Added support for Confluence
export, enabling customers to publish security findings to Confluence
pages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/81408527778af52f0c604a4eaca440f445082f78">81408527</a>)</li>
<li><strong>client-cloudwatch:</strong> This release adds Create, Get,
Update, and DeleteResourceMetricsConfiguration to enable detailed metric
collection for an AWS resource, and adds UpdateOTelEnrichment plus
include and exclude filters on StartOTelEnrichment so you can choose
which metric namespaces CloudWatch enriches. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/765cc1ce8f95a4f62d83dc07b81a927d74e09b52">765cc1ce</a>)</li>
<li><strong>client-eventbridge:</strong> Adds a ManagedBy field to the
DescribeEventBus and ListEventBuses responses, identifying the AWS
service that created an event bus on your behalf. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/28a639b27585c85376a4b5db528c31efb80e874d">28a639b2</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>undici-http-handler:</strong> update bidi stream e2e test to
nova-2-sonic model (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8313">#8313</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/d9a37d9d318f2ef7f5bcf6286bf3c7b475e4175b">d9a37d9d</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@​aws-sdk/client-s3's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1140.0...v3.1141.0">3.1141.0</a>
(2026-09-25)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1139.0...v3.1140.0">3.1140.0</a>
(2026-09-24)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1138.0...v3.1139.0">3.1139.0</a>
(2026-09-23)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1137.0...v3.1138.0">3.1138.0</a>
(2026-09-22)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1136.0...v3.1137.0">3.1137.0</a>
(2026-09-21)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1135.0...v3.1136.0">3.1136.0</a>
(2026-09-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1134.0...v3.1135.0">3.1135.0</a>
(2026-09-17)</h1>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/5bc8d9a96936723ac90d721e0c5a2bff7ee8520d"><code>5bc8d9a</code></a>
Publish v3.1141.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6050a3813c26795562b5ada8b0d9ea498eb9f8a1"><code>6050a38</code></a>
Publish v3.1140.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/03d54a858f80012bbc60046a77242223e8dfd9d9"><code>03d54a8</code></a>
Publish v3.1139.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/c68e50e4a6e0469a20c2894fe8a29c140553ebb8"><code>c68e50e</code></a>
Publish v3.1138.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/9a104768684e8f22d4373fcc5d910711e62676d6"><code>9a10476</code></a>
chore(codegen): sync for MetricsRecorder support and core error/retry
fixes (...</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6b432472f9bdf5437319b9186f706e3af5c9a748"><code>6b43247</code></a>
Publish v3.1137.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/d6b94db8f4a00cc452dbe0aacb247e8ece3897ea"><code>d6b94db</code></a>
Publish v3.1136.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2d5f18d08aa373d95692d83cb3d60a6a79248fae"><code>2d5f18d</code></a>
Publish v3.1135.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/0d6310bf6979ddbf737a7e15cfd8d0e7cec07063"><code>0d6310b</code></a>
Publish v3.1134.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/615a1ca4661ec0e4cb34b8da89fe60c2419b94d0"><code>615a1ca</code></a>
Publish v3.1133.0</li>
<li>Additional commits viewable in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.4
2026-10-01 11:13:22 -07:00