mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
0a3f265c36bdcbda772db424ca4aa775ac110d42
5238
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
0a3f265c36 |
Carry verified Pi prerequisite admission and probe corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing> * commit '32b5e275d56c5070de5a8ecdbec59c78b49a5f68': Carry existing Pi admission assertions and package-local probe import |
||
|
|
32b5e275d5 |
Carry existing Pi admission assertions and package-local probe import
Keep Pi source assertions consistent with the held qualification candidate. Use the existing vendored runtime boundary for installed probes. All four changes already exist downstream; no final shipping input or profile pin changes. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
c057c57460 |
Carry scoped prerequisite CI fixture corrections
Co-Authored-By: Paperclip <noreply@paperclip.ing> * commit 'f8bbeeb4c38805d1ab44ad40dcbc562f3b581892': test: carry verified Pi prerequisite CI corrections upstream |
||
|
|
f8bbeeb4c3 |
test: carry verified Pi prerequisite CI corrections upstream
Align adapter-section admission expectations with the declared source. Preserve the deliberately killed attempt at 500 ms while giving the resumed successful fixture its existing downstream 5-second budget. Preserve the original CI failures and all state, usage and deduplication assertions. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
a23e607ecb |
Keep Pi prerequisite review ancestry synchronized
Co-Authored-By: Paperclip <noreply@paperclip.ing> * commit 'a7b49fc14d67f2c3279ccac2d2506aa33554d017': test(ui): align Pi admission assertion with prerequisite source |
||
|
|
a7b49fc14d |
test(ui): align Pi admission assertion with prerequisite source
The shared adapter declaration already marks Pi qualified. Verify that source declaration rather than a stale linked build. Keep the separate production-qualification hold open. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
ef1558e027 |
Merge scoped Pi prerequisite review fixes
Co-Authored-By: Paperclip <noreply@paperclip.ing> * commit '95a30b7ff': fix(ui): coalesce bound duplicate Pi failure notices test(runner): align held Pi promotion assertions with profile 12 |
||
|
|
95a30b7ffe |
fix(ui): coalesce bound duplicate Pi failure notices
Preserve the original run log while showing one consecutive failure row for the same run, turn, session, and notice payload. Different bindings, messages, and intervening activity remain distinct. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
5c9ae3f856 |
test(runner): align held Pi promotion assertions with profile 12
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
b70cf84ea6 |
test: align runtime readiness checks with qualified Pi
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
30edeec300 |
test(runner): verify installed launch and published Daytona plugin
Invoke the public Playwright JavaScript entry directly for installed Pi tests so pnpm shim NODE_PATH injection cannot cross the closed controller boundary. Add a credential-free health/UI startup proof and a pinned published Daytona plugin fixture path without production runtime overrides. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
4c58da84fd |
test(server): exclude companion fixtures from production compilation
Keep the remote companion tests in the canonical server test directory so Runner source fixtures do not enter the server rootDir. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
c3d4677807 |
docs: record Pi 1.0 installation and Intel qualification gates
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
f96195a7a6 |
feat(runner): import verified Linux companions for normal Pi execution
Add explicit public CLI setup and full async source/profile/byte admission for an operator-pinned Linux companion. Preserve existing remote integrity checks and explicit overrides. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
8ced6f9285 |
fix(runner): use pinned npm for explicit Pi setup
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
c9de5292d6 |
test(runner): prove qualified Pi startup without candidate flag
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
d385c430bf |
test(runner): qualify Pi through installed public CLI
Verify installed CLI/server pins and default runtime resolution for explicit Pi Product cells. Keep Cursor and Copilot pending while qualified Pi runs without the candidate override. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
c27bbcee25 |
fix(runner): provision pinned Pi in published server installs
Add explicit host-only setup, verify the public server vendor layout, and route readiness through the packaged runner boundary. Preserve exact Pi closure and normal-mode admission checks. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
c806b94084 |
test(runner): align held Pi promotion assertions with profile 12
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
d40329a06b |
test(runner): align held Pi admission with qualified sidecar coverage
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
2c4c6585db |
Merge Pi 1.0 profile 12 into held production admission
Prepare the reviewed candidate for normal-mode qualification. This branch remains held pending the full local and Daytona proof; no provider is enabled in the published default branch. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
b9e5d6ecdb |
perf(runner): keep verified snapshot copies progressing
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
00462b048e |
fix(runner): preserve packaged daemon executability
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
9d83e06b85 |
fix(runner): preserve Pi 1.0 serialized RPC events
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
efe019a79f |
fix(runner): preserve plain Node Pi materializer imports
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
7b7fcbf96b |
perf(runner): verify Pi launch bytes once into the native snapshot
Cross-bind the Pi layout to its source-pinned native closure before structural discovery. Preserve full byte hashing in every immutable command snapshot and keep the independent generic verifier unchanged. Add corruption, graph, link, repeated-open and runtime-boundary cleanup regressions. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
5a6a531575 |
test(runner-e2e): account for Pi provider-death catalog cell
Update the Pi candidate matrix assertion from 25 to 26 after adding the Daytona provider-death case. Runtime inputs and all other expectations are unchanged. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
4c6adcadcb |
test(runner-e2e): verify pending Pi input after provider loss
Add one explicit Daytona Product cell that admits the exact Pi child before faulting it, then requires production expiry of the original native question, failed-run Blocked disposition, stale-answer rejection, distinct unanswered fallback, and no replay through owned retirement. Retain the existing local scope and pending qualification. Calibrate public lifecycle evidence, generated observer one-shot dispatch, and candidate failure classification. Runtime, provider profile, dependency closure, deadlines, and lockfiles are unchanged. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
30f5bc57b5 |
test(runner-e2e): calibrate exact Pi child fault ownership
Add closed Linux pidfd admission for the unique Pi child of a source-pinned wrapper, with full run ancestry and executable identity checks. Exercise title overwrite and ownership-safe cancellation in the standard E2E unit path; macOS explicitly skips the native Linux process calibration. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
586af4d7f3 |
perf(runner): bound cold runtime directory work
Batch Pi inventory metadata checks while preserving depth-first ordering and revalidating directories immediately before descent. Deduplicate native snapshot parent creation and bound sealing work without changing the complete byte verification, private snapshot, or runtime deadlines. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
5cd6d3d523 | test: strengthen Pi editing and pending native recovery qualification | ||
|
|
89284e2905 |
feat(runner): prepare held Pi 1 production admission
Replay the inactive Pi-only admission patch on the frozen Pi 1.0.0 source, preserving profile 11, its exact digest and all native closure inputs. Cursor and Copilot remain gated. This local preparation requires complete qualification and rebuilt normal-mode acceptance before activation. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
5eba61ece9 |
Merge recorded master baseline into Pi 1 production candidate
Integrate
|
||
|
|
2d60b454a7 |
feat(runner): upgrade closed Pi runtime to 1.0 profile 11
Preserve structural system messages without assistant attribution, disable native cache warming, and require queued continuation acknowledgements. Pin the complete upstream 1.0 dependency closure and retain historical profile evidence. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
3ab022d7df |
test: align merged directory and continuation fixtures
Remove a duplicate service import, register the warm remote fixture leases required by the cleanup ownership guard, and assert the server-owned bounded continuation for an unauthorized unfinished response wait. Keep runtime implementation and qualified inputs unchanged. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
8ec4b84e1c |
fix(chat): resume messages after failed runs without duplicate delivery (#14857)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - A user can send a new message after a native run fails. > - The server checks that the old execution has stopped before it starts a fresh turn. > - A failed run can retain a result accepted before checkpoint or cleanup failed. > - The continuation gate treated that saved result as active recovery and held the new message forever. > - This pull request removes that false liveness signal while retaining controller, process, environment, and authorization checks. > - Live staging then exposed a second defect: chat admission created a successor without consuming the original deferred receipt, so completion delivered the message again. > - Consume that exact receipt atomically with admission, while preserving separate turns for later chat messages. ## Linked Issues or Issue Description **What happened?** A new user message stayed in the queue with `controller_settling` after the previous run had reached `terminal_failure`. The old coordinator had no lease owner but still had a `resultId`. Its remote environment had a verified stop receipt. **Expected behavior** Start one fresh turn after execution has stopped and normal admission checks pass. Preserve the failed run and its accepted result as history. **Steps to reproduce** 1. Accept a native result, then fail checkpoint or cleanup and exhaust recovery. 2. Retain the result ID on the terminal failure record and stop the execution environment. 3. Send a new user message. Before this fix, it waits forever for the finished controller. **Paperclip version or commit** Reproduced in a database-backed regression test on `26900655b`. **Deployment mode** Server with a native runner and remote sandbox. Local process stop checks also apply. Related: https://github.com/paperclipai/paperclip/pull/14775. Searched existing PRs for retained-result continuation fixes; no duplicate found. ## What Changed - Remove the retained-result veto for terminal failures. - Keep controller ownership, successor, process, environment cleanup, pending decision, and ordinary admission checks. - Add regressions for retained results, active execution, missing stop evidence, and delayed remote cleanup. - Atomically consume the resumed receipt in agent chat, even though chat does not coalesce other queued messages. - Reproduce completion-time duplicate promotion, race cleanup against periodic recovery, and prove a subsequent chat message keeps its own turn. - Document that a saved result does not make a terminal failure active. - Keep exhausted workspace export on its separate repair path, tested through the production finalizer. ## Verification - Red: retained-result admission failed with `controller_settling` before the original fix. The new chat-specific regression then reproduced duplicate promotion when the first reply finished. - Green: 406 tests across native continuation, workspace-export recovery, and the wake-queue module passed on `cbc531cc0`. - The chat regressions exercise real Postgres transactions, simultaneous recovery callbacks, successful completion, the production queue-drain use case, and repeated drain attempts. A distinct follow-up remains a separate turn. - `pnpm -r typecheck` and `pnpm build` passed on `cbc531cc0`. - The earlier full local test run encountered a timeout and follow-on failure in unchanged AI connection-adoption tests; all 50 tests passed on isolated rerun. That local run was stopped after the full CI test matrix passed on the earlier head. - All 54 CI checks passed on `cbc531cc0` (2 skipped), including the full test matrix and browser shards. One unchanged interaction-route test returned HTTP 500 on its first CI attempt; its full 84-test file passed locally, and the failed shard passed on one targeted rerun. - Greptile reviewed `cbc531cc0`: 5/5, no unresolved findings. - Live staging first verified that the original saved message resumes and receives a successful response; that test exposed the duplicate now covered above. - Deployed exact commit `cbc531cc0410e1ef6e8811c6c5c014c3528351ed` to the affected staging workspace; deployment verification, health, authentication, and startup recovery passed. - Submitted a fresh message through the browser. The agent replied in 39 seconds; server records show exactly one successful run, native phase `committed`, no error, and an empty queue. A later check more than a minute after completion found no duplicate run. ## Risks The change affects admission after native execution failure and consumption of a resumed deferred receipt. A fresh turn must never overlap the prior execution, and consuming one chat receipt must not absorb later messages. Tests retain the controller, process, and remote-stop guards. This change does not migrate data, apply an old result, or reset the old retry budget. ## Model Used OpenAI Codex (GPT-6). The exact runtime model identifier and context window are not exposed in this session. Used reasoning, repository inspection, code execution, database-backed tests, and browser inspection. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1001.0-canary.6 |
||
|
|
dd9983b894 |
fix(adapter-utils): release restore locks when a process crashes (#14869)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agent runs restore workspace files and collect instruction-file changes. > - Writers to the same target directory must wait for each other. > - The current lock records a PID, which a new process can reuse after a crash. > - A reused PID can keep an orphaned lock alive and make each later run fail. > - This pull request makes a SQLite file lock decide ownership. The OS releases it when the process exits. > - Later runs can proceed after a crash, and concurrent live writers remain protected. ## Linked Issues or Issue Description Refs #10914. This addresses crash recovery. It does not cancel a stalled operation in a process that is still alive. Related work: #9667, #14787, and #12187. The earlier attempt in #9667 assumes one live server per lock root. This implementation uses an OS-backed lock to support concurrent writers without treating a different process token or an old timestamp as proof of a dead owner. It retains the private lock root and bounded timeout diagnostics from the merged changes. After a process dies while holding a restore lock, a replacement process can reuse its PID. The existing `process.kill(pid, 0)` check then reports a live owner forever. Later runs can complete their model turn but fail during file collection or restore. ## What Changed - Hold a SQLite `BEGIN IMMEDIATE` transaction for each directory write. Use the existing built-in `node:sqlite` dependency. - Keep each lock database on a stable inode. Keep PID and time metadata only for diagnostics. - Retain the 30-second asynchronous wait and existing timeout error code and diagnostic fields. - Fail closed when an old directory lock exists. Document a stopped-writer upgrade and rollback procedure. - Add real child-process tests for crashes, PID reuse, live owners, and connection cleanup. Cover callback failures, independent targets, stable inodes, invalid lock files, and ambiguous legacy records. ## Verification - Before the fix, the crash/PID-reuse test and the live-owner test both failed. Both pass with this change. - `pnpm exec vitest run packages/adapter-utils/src/directory-merge-lock.test.ts packages/adapter-utils/src/workspace-restore-merge.test.ts`: 56 tests passed. - Restore and agent-file working-copy integration tests: 118 tests passed before the additional connection-cleanup test. - `pnpm -r typecheck`: passed. - `pnpm build`: passed. - Full GitHub CI: all checks passed, including Linux workspace tests, server test shards, build, typecheck, and browser tests. - Greptile: 5/5, with no review threads or unresolved comments. - `pnpm test:run`: started locally, then stopped with SIGINT (exit 130) after full CI passed. The local serial run did not complete and is not counted as a full local pass. The completed CI shards provide the full-suite result. ## Risks - **Upgrade and rollback require a drain.** Stop every old writer that shares an instance root before switching protocols. Old and new versions must not write concurrently. - Existing legacy `.lock/` directories remain blocking. After all writers stop, preserve run evidence and move those directories to an operator scratch directory. The new code does not infer that they are abandoned from PID or age. - Never delete or replace a `.lock.sqlite` file while writers can run. These small files remain after release. - The shared filesystem must support reliable SQLite locking. Broken network-filesystem locking is unsupported. - This change prevents new orphaned ownership. It does not recover file changes lost during earlier failed collections, or interrupt a live operation that stalls. - No application database migration or new native dependency is required. See `doc/workspace-restore-locks.md` for the procedure. ## Model Used OpenAI Codex based on GPT-6, with code execution and repository tools. The exact model variant and context window are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (focused regression and integration suites; see the full-suite note above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1001.0-canary.5 |
||
|
|
8f7baf2f72 |
chore(deps): bump @aws-sdk/client-s3 from 3.1122.0 to 3.1141.0 (#13475)
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1122.0 to 3.1141.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@aws-sdk/client-s3's releases</a>.</em></p> <blockquote> <h2>v3.1141.0</h2> <h4>3.1141.0(2026-09-25)</h4> <h5>Chores</h5> <ul> <li><strong>codegen:</strong> smithy-aws-typescript-codegen 0.54.0 (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8314">#8314</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ad80ce3ebaf394679aabc6e26b2dcd023ce8e010">ad80ce3e</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-connect:</strong> Agent Privacy During Hold is a new privacy capability for Amazon Connect Voice that prevents agent audio from being captured in call recordings or Contact Lens conversational analytics during hold. When enabled, agents are automatically muted on entering hold and unmuted on resuming the contact (<a href="https://github.com/aws/aws-sdk-js-v3/commit/03527f9ea153365c1e3654ac6d3f3e064d06b5d0">03527f9e</a>)</li> <li><strong>client-qconnect:</strong> Release shapes for the proactive agentic recommendations and the multi-knowledge base search features. Increases the maximum length of QuickResponseContent. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e008332b0b70c55d22dfca8a9c2317b67d06a5f3">e008332b</a>)</li> <li><strong>client-bedrock-agent:</strong> Adds support for calling VPC configuration API's in Bedrock. These configurations allow the use of On Prem connectors in Bedrock Managed Knowledge bases (<a href="https://github.com/aws/aws-sdk-js-v3/commit/18524dc69cf36ebbb8bc7bc33e0bce6311dcdb23">18524dc6</a>)</li> <li><strong>client-mediaconnect:</strong> This release adds support for RTMP push router outputs in AWS Elemental MediaConnect. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/5bd8d80bbca2c1c2545521b03d741b46fccd09b4">5bd8d80b</a>)</li> <li><strong>client-securityagent:</strong> This release adds the ListActorMessages operation, which returns the multi-factor authentication messages received at an actor's server-generated email address (<a href="https://github.com/aws/aws-sdk-js-v3/commit/10e53d506db74c48b09b94d9b9387b84dd40ed58">10e53d50</a>)</li> <li><strong>client-arc-region-switch:</strong> Adds a service quota checker to Region switch to verify quota parity between your primary and standby Region, and automatically submit quota limit increases. Adds an optional EC2 Auto Scaling and ECS setting that waits for instances or tasks in the scaled-up Region to be healthy in target groups. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/cca33e380a8985e23a0e3fbb420577aab4b60ac7">cca33e38</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> Amazon Bedrock AgentCore Payments now supports credential rotation for payment connectors, letting you rotate API and wallet secrets for Quick Create payment auths from the console. This release also adds Type and Creation type columns to the payment managers views. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/adca591f07c448603de2876faaf7914cad441436">adca591f</a>)</li> <li><strong>client-neptune-graph:</strong> Add GraphIdentifier filter for ListImportTasks (<a href="https://github.com/aws/aws-sdk-js-v3/commit/9b9aea9b553ba84f006f95da5d8ffd5381cc8a17">9b9aea9b</a>)</li> <li><strong>client-rekognition:</strong> This release adds support for Feedback and Metadata in the GetFaceLivenessSessionResults response. Feedback returns codes explaining why a Face Liveness check produced its result. Metadata includes the client SDK type. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0831c361bb69d44357ff57360db39afdbb149337">0831c361</a>)</li> <li><strong>client-glue:</strong> add support for table level federation (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a44458b77853cbb25a9fcb362b0a275d7dc1c69b">a44458b7</a>)</li> <li><strong>client-wellarchitected:</strong> This change releases the Well-Architected Agent, a generative AI service that analyzes a customer's AWS environment and delivers personalized, prioritized recommendations across cost, security, performance, and resilience. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/d0656586067f70b8d50000300f04512dd089df96">d0656586</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1141.0.zip</strong></p> <h2>v3.1140.0</h2> <h4>3.1140.0(2026-09-24)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-route53resolver:</strong> Documentation updates for Route 53 Resolver. Clarifies which Outpost Resolver operations apply to first-generation AWS Outposts and that Resolver is managed automatically on second-generation Outposts. Adds Local Network Interface subnet compatibility notes for Resolver endpoints. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b4432abaaaf19bf4ac5d4d2b09bcc83e4d5440a0">b4432aba</a>)</li> <li><strong>client-iot:</strong> Fixed ListV2LoggingLevels and DeleteV2LoggingLevel documentation to include all supported target-types (<a href="https://github.com/aws/aws-sdk-js-v3/commit/4dcf76d527e0c1fe76d64cb8ea444ce62d64135b">4dcf76d5</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>clients:</strong> update client endpoints as of 2026-09-24 (<a href="https://github.com/aws/aws-sdk-js-v3/commit/29a8566cb4c6eeb0cc554f4ae9bf985160556523">29a8566c</a>)</li> <li><strong>client-eventbridgev2:</strong> Introducing Amazon EventBridge enhanced Custom event bus, a new shareable event bus for organizational-scale event-driven applications feature ordered delivery, deduplication, open event formats, and cross-account bus sharing. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/69fbe6a22fd7810332b0b0356803a0eee3f563cf">69fbe6a2</a>)</li> <li><strong>client-datazone:</strong> Amazon DataZone now supports the TOOLING blueprint category on CreateEnvironmentBlueprint, UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and ListEnvironmentBlueprints, for custom tooling blueprints. CreateConnection now accepts roleArn in iamProperties. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/591cd6f5a7b714427cbe87b36b13357d560d48ea">591cd6f5</a>)</li> <li><strong>client-elasticache:</strong> Added tagging support for ElastiCache Global DataStore. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0fa9da5946312f09942dad6f711885855f0d0b8e">0fa9da59</a>)</li> <li><strong>client-marketplace-discovery:</strong> AWS Marketplace Discovery API now supports localized responses and SigV4a request signing. It returns new fulfillment details, including AMI architecture, EBS volume and security group information, SaaS quick-launch status, and SageMaker input and output MIME types. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/510673e376bbc578d318308136ecb5a841416bc3">510673e3</a>)</li> <li><strong>client-redshift-data:</strong> Updates to the ListDatabases and WorkgroupName validation (<a href="https://github.com/aws/aws-sdk-js-v3/commit/218c24e106efe1ad64658984123af6634fc7278d">218c24e1</a>)</li> <li><strong>client-securityagent:</strong> Added support for Confluence export, enabling customers to publish security findings to Confluence pages. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/81408527778af52f0c604a4eaca440f445082f78">81408527</a>)</li> <li><strong>client-cloudwatch:</strong> This release adds Create, Get, Update, and DeleteResourceMetricsConfiguration to enable detailed metric collection for an AWS resource, and adds UpdateOTelEnrichment plus include and exclude filters on StartOTelEnrichment so you can choose which metric namespaces CloudWatch enriches. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/765cc1ce8f95a4f62d83dc07b81a927d74e09b52">765cc1ce</a>)</li> <li><strong>client-eventbridge:</strong> Adds a ManagedBy field to the DescribeEventBus and ListEventBuses responses, identifying the AWS service that created an event bus on your behalf. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/28a639b27585c85376a4b5db528c31efb80e874d">28a639b2</a>)</li> </ul> <h5>Tests</h5> <ul> <li><strong>undici-http-handler:</strong> update bidi stream e2e test to nova-2-sonic model (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8313">#8313</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/d9a37d9d318f2ef7f5bcf6286bf3c7b475e4175b">d9a37d9d</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@aws-sdk/client-s3's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1140.0...v3.1141.0">3.1141.0</a> (2026-09-25)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1139.0...v3.1140.0">3.1140.0</a> (2026-09-24)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1138.0...v3.1139.0">3.1139.0</a> (2026-09-23)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1137.0...v3.1138.0">3.1138.0</a> (2026-09-22)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1136.0...v3.1137.0">3.1137.0</a> (2026-09-21)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1135.0...v3.1136.0">3.1136.0</a> (2026-09-18)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1134.0...v3.1135.0">3.1135.0</a> (2026-09-17)</h1> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/5bc8d9a96936723ac90d721e0c5a2bff7ee8520d"><code>5bc8d9a</code></a> Publish v3.1141.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/6050a3813c26795562b5ada8b0d9ea498eb9f8a1"><code>6050a38</code></a> Publish v3.1140.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/03d54a858f80012bbc60046a77242223e8dfd9d9"><code>03d54a8</code></a> Publish v3.1139.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/c68e50e4a6e0469a20c2894fe8a29c140553ebb8"><code>c68e50e</code></a> Publish v3.1138.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/9a104768684e8f22d4373fcc5d910711e62676d6"><code>9a10476</code></a> chore(codegen): sync for MetricsRecorder support and core error/retry fixes (...</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/6b432472f9bdf5437319b9186f706e3af5c9a748"><code>6b43247</code></a> Publish v3.1137.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/d6b94db8f4a00cc452dbe0aacb247e8ece3897ea"><code>d6b94db</code></a> Publish v3.1136.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/2d5f18d08aa373d95692d83cb3d60a6a79248fae"><code>2d5f18d</code></a> Publish v3.1135.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/0d6310bf6979ddbf737a7e15cfd8d0e7cec07063"><code>0d6310b</code></a> Publish v3.1134.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/615a1ca4661ec0e4cb34b8da89fe60c2419b94d0"><code>615a1ca</code></a> Publish v3.1133.0</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1001.0-canary.4 |
||
|
|
efc2e6810e |
fix: show each task once in dashboard agent cards (#14847)
## Thinking Path > - Paperclip helps people manage AI agents and their tasks. > - The dashboard shows recent agent activity in compact cards. > - Those cards use run records, so two runs for one task can create duplicate task cards. > - An operator needs to see each task once when scanning the dashboard. > - This pull request selects one run per linked task before it applies the card limit. > - The live runs page still shows each run for run inspection. ## Linked Issues or Issue Description **What happened?** The dashboard showed the same task in two agent cards when that task had both an active run and a completed run. **Expected behavior** The dashboard should show a linked task at most once. It should keep the active run card when one is present. **Steps to reproduce** 1. Start an agent run for a task that already has a completed run. 2. Open the company dashboard. 3. Observe two cards linked to the same task. **Paperclip version or commit** Reproduced on the pre-change master at `8b4aa0692`. **Deployment mode** Local dev, built from source. The bug is in the core dashboard UI and does not depend on an agent adapter or database mode. ## What Changed - Select distinct linked tasks from capped active and recent run samples before applying the dashboard card limit. - Keep separate cards for runs without a linked task. - Preserve the dashboard's count of additional distinct cards behind the live-runs link. - Add UI and embedded Postgres regression tests for duplicate runs and document the dashboard rule. - Give the existing multi-request cross-tenant authorization test enough time on loaded CI runners. ## Verification - `pnpm --filter @paperclipai/ui exec vitest run src/components/ActiveAgentsPanel.test.tsx` - `pnpm --filter @paperclipai/ui exec vitest run src/api/heartbeats.test.ts` - `pnpm exec vitest run server/src/__tests__/dashboard-service.test.ts server/src/__tests__/agent-live-run-routes.test.ts` - `pnpm exec vitest run server/src/__tests__/agent-cross-tenant-authz-routes.test.ts` - `pnpm --filter @paperclipai/ui typecheck` - `pnpm --filter @paperclipai/server typecheck` - `pnpm --filter @paperclipai/ui build` - `pnpm -r typecheck` - `pnpm build` - `pnpm check:token-gates` - Review the dashboard with an active and a completed run on the same task. Confirm that it shows one card. Open Live agent runs to inspect both run records. ## Risks - A very high volume of recent runs for one task can fill the capped sample and leave older tasks off the dashboard. The Live runs page remains available for full run inspection. - The dashboard may fetch up to 50 distinct run representatives to preserve its overflow count. The default run API response and persisted data are unchanged. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, GPT-6. The runtime does not expose the exact model ID or context window size to this task. The model used reasoning, tool calls, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
6f2ce27ca7 |
fix(workspaces): prepare checkouts without a local seed config (#14810)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Task preparation can create an isolated Git worktree and run its setup script. > - The Paperclip repository setup script also prepares a seeded development instance. > - A server configured through environment variables can have no local seed config. > - This stops ordinary task preparation before the agent starts. > - This pull request prepares checkout dependencies when no seed source exists, while preserving errors for invalid sources and existing development instances. > - Tasks can start without creating or claiming a seeded development runtime. ## Linked Issues or Issue Description **What happened?** A task with the Paperclip repository fails during setup when the host has no repository-local or default instance config. The automatic worktree provisioner requires a seed source even when the task only needs the checkout. **Expected behavior** A plain checkout should prepare its dependencies without a local development database. A missing custom source, invalid source path, or existing development instance with a missing source should still fail. Starting a seeded runtime must still require a valid source. **Steps to reproduce** 1. Run an environment-configured Paperclip server without a local instance config. 2. Add the Paperclip repository to a project. 3. Start a task that uses an isolated Git worktree without a custom provision command. 4. Observe the setup error before agent execution. **Paperclip version or commit** Reproduced against `0d3e7bf6ac` with a real script subprocess and workspace realization regression. **Deployment mode** Environment-configured server with external PostgreSQL. **Additional context** Searched open and closed GitHub PRs and issues. Related work: Refs #14795 (seed-source diagnostics) and Refs #11733 (source validation). This change keeps source validation and seed-readiness checks in place. ## What Changed - Permit dependency setup when the default seed config is absent (including the Docker image config path) and the worktree has no development-instance state. - Keep missing custom configs, invalid paths, and lost sources for existing instances as errors. - Create no config, environment file, or seed manifest for a plain checkout. - Keep dependency install failures visible and allow normal instance setup once a source becomes available. - Cover the setup script, seed-runtime refusal, and automatic server worktree realization. - Document the difference between checkout preparation and seeded-runtime readiness. ## Verification - Regression tests failed before the fix for absent-source checkout preparation and dependency setup. - `bash -n scripts/provision-worktree.sh` - `node --test scripts/__tests__/provision-worktree-self-heal.test.mjs` — 34 passed; 1 existing flock-dependent test skipped on macOS. - Server regression — 2 passed, covering an unset config and the Docker image default path. - `pnpm build` — passed. - `pnpm -r typecheck` — passed. - All CI checks passed, including the full test shards, build, typecheck, browser tests, and canary dry run. - The first local `pnpm test:run` encountered two chat-test failures because skill discovery selected an unrelated parent directory. Both tests pass at the PR commit in a clean temporary checkout. The full local run was not completed; the redundant clean run was stopped after the complete CI suite passed. - `git diff --check` and added-line secrets/PII scan passed. - Greptile: 5/5, no comments. The branch has no merge conflicts. - No live tenant deployment or task retry was performed. ## Risks - A new checkout with no implicit seed config now completes dependency setup. It has no seeded development instance. A runtime request still fails until a valid source exists. - Existing instances and custom source paths retain their failure behavior. The script does not synthesize a source from environment credentials or copy a live database. - No schema, API, or task-setting changes. Revert the commit to restore the previous setup behavior. ## Model Used OpenAI Codex (GPT-6), with tool-assisted analysis, code edits, and local tests. The runtime did not expose a verified model variant or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
6d654f63d1 |
feat(apps): make MCP action test results readable (#14859)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Connected Apps let an operator control which MCP actions an agent can use. > - The Permissions page lets the operator run a real action as an agent. > - The Test dialog displayed the nested MCP response as escaped JSON. > - A useful result was hard to read, even when the action worked. > - This pull request renders known MCP content as a readable preview and keeps the raw response available. > - The benefit is faster validation without losing the data needed to diagnose a failure. ## Linked Issues or Issue Description **What existing behavior does this improve?** The per-action Test dialog on a connection's Permissions page. **Subsystem affected** ui/ — React board UI. **Current behavior** The dialog shows the gateway response as an escaped JSON blob. Text content that contains JSON stays inside a string. The obsolete connection Test page also keeps a separate set of stories. **Proposed behavior** The dialog uses structured MCP content when present. It parses JSON text blocks when possible. It shows compact tables, cards, fields, or plain text. It keeps the full raw response behind a control and opens that view for errors or unknown block shapes. Stories exercise the Permissions page dialog, and the obsolete Test page and stories are removed. **Reason and benefit** An operator can inspect a successful action result at a glance and still inspect the exact gateway response when a call fails or looks wrong. **Breaking changes** No API or stored data changes. The Test dialog presentation changes. The raw response stays available. **Additional context** I tested a read-only Notion search through the real Permissions page. The dialog showed three result cards and the raw response control worked. Storybook uses invented example data. No directly matching public issue or open PR was found in the GitHub search. ## What Changed - Render structured MCP output and JSON text content in the action Test dialog. - Show wide rows as cards, keep short rows as tables, and retain the raw response for diagnosis. - Remove the obsolete connection Test page and its stories. - Add focused dialog tests and Permissions page Storybook cases for success, errors, mixed blocks, and malformed blocks. - Document the Test dialog result behavior in the connection playbook. - Keep agent mention icons visible when the Lucide icon node is unavailable in server rendering, which repaired a repeatable CI failure. ## Verification - `pnpm -r typecheck` — passed. - `pnpm exec vitest run --project @paperclipai/ui` — passed (7,111 tests). - `pnpm exec vitest run ui/src/pages/apps/app-detail/ActionTestDialog.test.tsx` — passed (11 tests). - `pnpm exec vitest run --project @paperclipai/ui ui/src/components/MarkdownBody.test.tsx` — passed (53 tests). - `pnpm test:run` — started, then stopped after the review fixes changed the head; the full sharded suite passed in CI. - `pnpm build` — passed. - `pnpm check:token-gates` — passed. - Use a connected MCP app. Open Permissions, select a read action, and run Test. Inspect the preview and the raw response control. ## Risks - MCP tools can return provider-specific block shapes. Unknown blocks open the raw response so the operator can inspect the exact result. - Row and field previews limit visible data. The raw response preserves the complete result. > This is a targeted improvement to the existing Connected Apps item in `ROADMAP.md`. ## Model Used OpenAI Codex, GPT-6. The session used tool access, code execution, and browser validation. The exact deployment ID and context window were not exposed to the session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
527e146980 |
feat(ui): share animated agent setup prompts (#14862)
Use the shared animated prompt-copy control across setup, invitations, webhooks, and task handoffs. Preserve first-click copying, clipboard recovery, and logo continuity. Add Storybook coverage and restore mention icon masks for the current Lucide data shape. Co-Authored-By: Paperclip <noreply@paperclip.ing>canary/v2026.1001.0-canary.3 |
||
|
|
9e0ede4cbe |
test(runner-e2e): retain Pi steering presentation evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
b97f3ce7c7 |
test(runner): preserve idempotent receiver result retries
Verify identical tool-result retries emit one sidecar resolution while changed payloads, operations, and error status remain rejected. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
6395cae072 |
fix(runner): ship provider pack in the standard Docker image (#14854)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Remote OpenCode and ACPX runs need a provider pack from the application build. > - Cloud now builds its application image from the standard production image. > - The provider pack was added only to the legacy cloud image target. > - The standard image therefore cannot supply the pack to downstream Cloud images. > - This pull request adds the pack to the production image and lets the cloud target inherit it. > - Remote runs can then use the pack that matches the application source commit. ## Linked Issues or Issue Description Refs #13827. Refs #14024. The standard production image does not include the remote provider pack. Downstream Cloud images inherit that omission. Remote OpenCode and ACPX runs fail with `runner_remote_provider_artifact_incompatible` and ask for `PAPERCLIP_RUNNER_REMOTE_PROVIDER_PACK_PATH`. ## What Changed - Build and copy the provider pack into the standard production image. - Set the pack path and check that an unprivileged user can read its artifacts and execute Node. - Let the legacy cloud target inherit the pack from production. - Add regression checks for production packaging and cloud inheritance. - Document stamped image behavior and the default pack path. ## Verification - The 12 focused Docker stamp and provider-pack reuse tests pass on commit `4a11f8d52aead55f85527c8e82c6d7f2644ce0da`. - The new packaging regression failed against the old Dockerfile and passed with the fix. - On the current commit, `pnpm build` and `pnpm -r typecheck` pass. All seven standard-image contract tests also pass. - The current-head CI build, typecheck, test, browser, and native Runner checks passed. The local full suite hit one chat-channel assertion failure; that exact test passed in isolation. The remaining local run was stopped after CI completed to avoid duplicating its full suite. An earlier run on the pre-rebase base had a heartbeat comment batching timeout; the external chat wait integration suite passed all 142 tests in isolation. - [The stamped preview image build passed](https://github.com/paperclipai/paperclip/actions/runs/36885002850/job/110446106393), including the production-stage provider pack build, copy, and unprivileged artifact readability/executable check. Publication, compatibility validation, and deployment of this exact commit to a staging QA instance passed. - Reproduced the exact missing-pack error on an existing staging image with Paperclip Runner, ACPX, and Claude in a remote Daytona computer. The legacy Claude adapter succeeds with the same account and computer. After deploying this commit, the same native task succeeded: it computed `5050` with a real remote shell command, wrote a proof file, read it back in a separate call, uploaded the file as a deliverable, and completed the task. The uploaded file contents and Done state persisted after a page reload. The run trace confirms Paperclip Runner, ACPX, and Claude. The first run took 2m 59s, including approximately 97s of remote artifact preparation. A second native run read the unchanged file from the prior run and completed successfully. Its startup took about 120s; this verifies repeated execution and file persistence, not fast provider-pack reuse. ## Risks - Stamped standard images now include the provider pack and its build cost. A pack build failure now fails the production image build. - Unstamped local builds still skip pack generation. Setting the path alone does not create a pack. - No database, provider authentication, or runner verification rules change. ## Model Used OpenAI Codex, GPT-6. The exact serving model identifier and context window are not exposed in this session. Capabilities used: repository inspection, code editing, shell verification, and browser testing. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
33a00d2f1e |
fix(ui): reopen last visited agent chat (#14848)
## Thinking Path > - Paperclip helps people manage AI agents and their work. > - Agent Chat keeps one conversation for each agent and board user. > - The Chat sidebar entry opens the agent chooser each time. > - A user must then find and reopen the chat they just used. > - The browser already records recent agent chat visits by company and user. > - This pull request uses that record to reopen the last available chat. > - The chooser still serves users who have no available saved chat. ## Linked Issues or Issue Description Related: #14706 added the secondary Agent Chat navigation. **What happened?** The Chat sidebar entry opened the agent chooser, even after a user opened an agent chat. **Expected behavior** The Chat entry should reopen the last agent chat visited by the current user in the current company. **Steps to reproduce** 1. Enable Agent Chat and open a chat with an agent. 2. Open another page. 3. Select Chat in the sidebar. 4. Observe the agent chooser instead of the chat. **Paperclip version or commit** Reproduced on master at `0829d94af`. **Deployment mode** Local development, browser UI. The change also uses the same browser storage path in authenticated mode. ## What Changed - Use the existing recent chat record when the Chat landing route opens. - Check saved agents against the current roster and chat history before redirecting. - Keep the chooser when no saved chat is available, and show a retry state for load errors. - Add route tests and update the Agent Chat implementation spec. ## Verification - `pnpm exec vitest run ui/src/pages/AgentChats.test.tsx ui/src/lib/recent-agent-chats.test.ts` — 16 tests passed. - `pnpm check:token-gates` — passed. - `pnpm exec playwright test --config tests/e2e/playwright.config.ts tests/e2e/agent-chat-sessions.spec.ts --grep 'secondary chat navigation preserves layout'` — passed. - `pnpm --filter @paperclipai/ui typecheck` — passed on the final commit. - `pnpm -r typecheck` and `pnpm build` — passed earlier in this branch; latest-head CI completed all 47 jobs successfully. - `pnpm test:run` reported an unrelated native runtime test failure before it was stopped. That test and an unrelated external object refresh test passed in isolation. CI runs the same suites on the PR. - To check in the UI: open an agent chat, leave it, and select Chat. The same chat should open. Clear the recent chat record or use another company to see the chooser. ## Risks - The recent order is stored in the browser. Clearing browser storage returns the user to the chooser. - An existing chat ID is stored with its visit. If the chat is removed, the landing route skips that visit when history loads. Cross-tab storage removal clears the identity; failed writes retain an in-tab fallback. - The landing route waits for the agent roster and validates saved issue IDs against chat history when available. If history fails, an active agent chat can still open; roster or session failures show a retry action. - No database or API contract changes are required. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, GPT-6 family. The runtime did not expose an exact API model ID or context window. It used reasoning, repository tools, shell commands, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
26900655b4 |
chore(deps): bump lucide-react from 1.38.0 to 1.45.0
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.38.0 to 1.45.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lucide-icons/lucide/releases">lucide-react's releases</a>.</em></p> <blockquote> <h2>Version 1.45.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added <code>calendar-chevrons-right</code> icon by <a href="https://github.com/AlexandrePhilibert"><code>@AlexandrePhilibert</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3565">lucide-icons/lucide#3565</a></li> <li>feat(icons): added <code>building-complex-plus</code> icon by <a href="https://github.com/tylerkade"><code>@tylerkade</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4758">lucide-icons/lucide#4758</a></li> <li>feat(icons): add hourglass-cog icon by <a href="https://github.com/lazerg"><code>@lazerg</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4635">lucide-icons/lucide#4635</a></li> <li>feat(icons): added <code>mouth</code> & <code>mouth-off</code> by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4787">lucide-icons/lucide#4787</a></li> <li>feat(icons): added <code>iv-bag</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4821">lucide-icons/lucide#4821</a></li> <li>fix(icons): changed <code>lectern</code> icon by <a href="https://github.com/UsamaKhan"><code>@UsamaKhan</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/2925">lucide-icons/lucide#2925</a></li> <li>feat(icons): add <code>layout-arrow-right</code> and <code>layout-arrow-down</code> by <a href="https://github.com/samuelalake"><code>@samuelalake</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4541">lucide-icons/lucide#4541</a></li> <li>feat(icons): added <code>park</code> icon by <a href="https://github.com/skajosborn"><code>@skajosborn</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3177">lucide-icons/lucide#3177</a></li> <li>fix(icons): changed <code>album</code>, <code>book-marked</code>, <code>folder-bookmark</code> icons by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3043">lucide-icons/lucide#3043</a></li> <li>fix(icons): correct misspelled tags by <a href="https://github.com/decknamec"><code>@decknamec</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4836">lucide-icons/lucide#4836</a></li> <li>feat(icons): added <code>houses</code> icon by <a href="https://github.com/danielbayley"><code>@danielbayley</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3241">lucide-icons/lucide#3241</a></li> <li>feat(icons): added <code>notebook-dot</code> icon by <a href="https://github.com/elenakovelskikh"><code>@elenakovelskikh</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3228">lucide-icons/lucide#3228</a></li> <li>feat(icons): add <code>messages-circle</code> icon by <a href="https://github.com/Mirazstudio-offical"><code>@Mirazstudio-offical</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4754">lucide-icons/lucide#4754</a></li> <li>feat(icons): added <code>plant-pot</code> icon by <a href="https://github.com/vqh2602"><code>@vqh2602</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3122">lucide-icons/lucide#3122</a></li> <li>fix(icons): changed <code>cookie</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4815">lucide-icons/lucide#4815</a></li> <li>fix(icons): remove duplicate use-cases prop from cookie.json by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4838">lucide-icons/lucide#4838</a></li> <li>fix(site): fix home card icons by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4839">lucide-icons/lucide#4839</a></li> <li>feat(docs): added "How to use Lucide icons" section to resources by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4829">lucide-icons/lucide#4829</a></li> <li>fix(packages/vue): fix generated icon declaration types for <code>@lucide/vue</code> by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4841">lucide-icons/lucide#4841</a></li> <li>chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4845">lucide-icons/lucide#4845</a></li> <li>chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 in /integrations/lucide-react/vite by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4844">lucide-icons/lucide#4844</a></li> <li>ci(ci.yml): Add dispatch post release by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4847">lucide-icons/lucide#4847</a></li> <li>feat(icons): added <code>globe-code</code> icon by <a href="https://github.com/AleksejDix"><code>@AleksejDix</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3722">lucide-icons/lucide#3722</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/tylerkade"><code>@tylerkade</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4758">lucide-icons/lucide#4758</a></li> <li><a href="https://github.com/alx-xo"><code>@alx-xo</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4115">lucide-icons/lucide#4115</a></li> <li><a href="https://github.com/skajosborn"><code>@skajosborn</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3177">lucide-icons/lucide#3177</a></li> <li><a href="https://github.com/elenakovelskikh"><code>@elenakovelskikh</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3228">lucide-icons/lucide#3228</a></li> <li><a href="https://github.com/Mirazstudio-offical"><code>@Mirazstudio-offical</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4754">lucide-icons/lucide#4754</a></li> <li><a href="https://github.com/AleksejDix"><code>@AleksejDix</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3722">lucide-icons/lucide#3722</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.44.0...1.45.0">https://github.com/lucide-icons/lucide/compare/1.44.0...1.45.0</a></p> <h2>Version 1.44.0</h2> <h2>What's Changed</h2> <ul> <li>feat(packages/icons): fixed <code>@lucide/icons</code> rollup config by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4824">lucide-icons/lucide#4824</a></li> <li>fix(icons): changed <code>door-open</code> by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4826">lucide-icons/lucide#4826</a></li> <li>fix(docs): replace missing LucideIcon icon names in guides by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4827">lucide-icons/lucide#4827</a></li> <li>feat(docs): fixed fuse js search by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4825">lucide-icons/lucide#4825</a></li> <li>fix(icons): changed <code>satellite-dish</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4813">lucide-icons/lucide#4813</a></li> <li>fix(icons): arcified flip icons & renamed them by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4833">lucide-icons/lucide#4833</a></li> <li>fix(icons): improve legibility of credit card icons by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4831">lucide-icons/lucide#4831</a></li> <li>feat(lab): add check-x icon by <a href="https://github.com/ishanbagra18"><code>@ishanbagra18</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4737">lucide-icons/lucide#4737</a></li> <li>fix(icons): correct compromised tags in shield icons by <a href="https://github.com/decknamec"><code>@decknamec</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4835">lucide-icons/lucide#4835</a></li> <li>feat(icons): added <code>toothbrush</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4755">lucide-icons/lucide#4755</a></li> </ul> <h2>New Contributors</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b"><code>94e4cb9</code></a> chore(dependencies): Update dependencies (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806">#4806</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2"><code>99d25bd</code></a> feat(packages): extract icon build logic into <code>@lucide/shared</code> (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409">#4409</a>)</li> <li>See full diff in <a href="https://github.com/lucide-icons/lucide/commits/1.45.0/packages/lucide-react">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e12b25f2b4 | test(runner-e2e): qualify Pi active Stop and steering | ||
|
|
f6406e7e55 |
Merge frozen master into the rich ACP production candidate
Preserve incremental Codex checkpoints and ACP unchanged-directory ownership as separate warm-session paths. Combine cancellation commit fencing, terminal outcome recovery, and both native fixture catalogs. Keep all candidate qualification states and provider profile identities unchanged. Validation: 629 controller unit checks, 5 heartbeat cancellation checks, 210 runner/profile/sidecar checks, 44 catalog checks; token gates, Rust source formatting, and generated protocol manifest pass. Database tests and builds intentionally deferred. Source-aliased no-emit checking is blocked only by the borrowed ACPX SessionRecord declaration lacking the already-patched cursor_prompt_usage field. |
||
|
|
4ac374103f |
fix(connections): repair Asana MCP and add shared-app sign-in (#14756)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections let agents use provider tools through the permission
gateway.
> - Asana provides an official remote MCP server, but its v2 server
requires a registered MCP OAuth app.
> - Setup can discover retired v1 endpoints and send a callback that
differs from the displayed URL.
> - This pull request repairs custom app setup and adds sign-in through
Paperclip's shared app.
> - Users can choose their own app without enrolling with Paperclip
Cloud.
> - Agents can use Asana tools after the user connects their account and
sets action permissions.
## Linked Issues or Issue Description
Related: #14739 supplies the personal credential repair used by resumed
Asana setup. No duplicate Asana authentication PR was found.
**What happened?**
Asana setup failed even with a user-created app. Root discovery metadata
still points at v1. MCP v2 uses the Asana OAuth issuer and requires an
MCP app with a client secret. Local setup also displayed a localhost
callback while an Origin header could make authorization use a numeric
loopback callback.
**Expected behavior**
Sign in with Paperclip's app when its broker profile is available. Keep
custom MCP app setup available without Cloud enrollment. Use the correct
issuer, callback, client credentials, and resource throughout setup.
**Steps to reproduce**
1. Open Asana in the connection catalog.
2. Supply an Asana MCP app's client ID and secret.
3. Start OAuth on a local instance opened with a numeric loopback
address, or resume a draft that cached v1 metadata.
4. Observe the wrong discovery endpoint or callback mismatch.
**Paperclip version or commit**
Reproduced from
|