Keep raw invocation provenance separate from the validated proposal digest. Advance the semantic evidence contract to v2 and Copilot suite to 8; preserve denial and attached-operation invariants.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Use session/request_permission for the native permission fixture and verify that the real pending-request mapper settles its callback exactly once with action cancel.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Require the normalized pending-request closure and cancelled terminal with the existing caller-owned Stop and native evidence guards. Exercise the real Product projection and version the changed settlement oracle.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
The Copilot shim test copies and hashes the complete host Node closure before launching the bootstrap and owned shim. Two CI runs stopped at Vitest's default 5s limit (jobs 110198660276 and 110200639147), while identical code passed in 1081ms in job 110197353844. Use the adjacent real-Node closure test's 30s envelope; preserve all assertions, product deadlines, and retry behavior.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep bridge call identity separate from canonical result item identity. Require one complete shell-read lifecycle tied to the started command and reject extra or partial reads.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Generate both input orders through the real Cursor and Copilot projectors. Preserve Cursor's deferred permission evidence invariant while allowing Copilot's immediate permission notice before its exact tool origin; retain all pre-Stop and settlement bindings.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Accept either canonical permission/tool arrival order while binding the exact native-origin and tool-start rows before Stop and through cancellation. Version the pending receipt and suite; retain strict identity, no-effects, unanswered-request, and settlement checks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Queue bounded internal request callbacks alongside notifications so the Codex driver maps earlier tool activity before exposing permission cards. Dispatch without awaiting human answers and discard stale callbacks after closure, replacement, or durable settlement.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reuse the existing provider tool identity transform across native evidence, permission details, and canonical activity without changing the provider request or option binding.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Apply the two provider evidence files from 2cbf72ec96 (#14802). The separate Product E2E changes remain on their existing branch.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
State each bootstrap prohibition separately so the production file-delivery classifier does not treat an isolated clause as a requested output. Keep immediate completion stress, private marker evidence and all settlement assertions unchanged; version the authored Copilot protection definition.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Preserve non-bundled package contents outside the pnpm tree before npm packs them. Keep bundled and root-package behavior and clean-consumer assertions unchanged.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Observe the retired authority at its durable prepared commit rather than the later attach observer. Add a forced post-activation lost-ACK observer regression while preserving event, ACK, identity, process, and cleanup assertions.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Include lease revalidation and the readiness RPC in the existing setup reserve, so late lease admission cannot consume the observation window. Keep the authored outer deadline, single installation, armed baseline action gate, and teardown reserve unchanged.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Observe the pinned run process and runtime inode within the original deadline before one observer install. Revalidate identity at installation and baseline, and retain only closed RPC phase/error diagnostics. Preserve action, ownership and cleanup gates.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Distinguish live snapshots from the automatic owned-process retirement seal. Preserve local four-phase observation and separately revalidate remote UI/API cancellation state without claiming later filesystem reads. Version the suite and calibrate stale/replayed/foreign/lost-descendant evidence.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Observe the task In Progress header and native Run cancelled marker with loaded history before treating an absent Deny button as unanswerable. Bound all waits by the existing attempt deadline.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Observe the isolated local-board session through the public API, retain it before Stop, and require its exact startup cancellation actor. Explicitly bind both closure and terminal envelopes to the observed turn, normalized session and source, including missing/null-turn negatives.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Wait for the exact turn reply and pending review card with enabled Continue work, In Review header and completed history loading before capturing intermediate warm screenshots. Reuse the existing turn deadline; preserve prior screenshots and result grades.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Add explicit Cursor and Copilot local/Daytona cells that retain an unanswered callback before a caller-correlated Stop, require cancelled provider settlement and stale-answer rejection, and independently verify no effects through owned retirement. Normal completion and provider death do not satisfy this active-work oracle.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Recheck retry eligibility under the coordinator lock before creating a cancellation intent. Preserve later run and coordinator outcomes with a failed-only acknowledged-result CAS, while retaining same-intent recovery and NOWAIT conflict handling.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 29230e2000)
Check failed-run retry eligibility under the run and coordinator locks, fail closed on concurrent coordinator claims, and preserve same-caller recovery after the audited intent disables a retry. Keep terminal failures and foreign actors or intents rejected.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 79db1c2a6f)
Reserve an optional board request UUID under the run lock and retain it
through default Stop joins and native dispatch. Reject prior or competing
intents and require the same actor for idempotent retries.
Bind the Copilot denial fixture to its exact request and audited intent,
with versioned causal receipts and negative controls for earlier Stop.
Co-Authored-By: Paperclip <noreply@paperclip.ing>