Check failed-run retry eligibility under the run and coordinator locks, fail closed on concurrent coordinator claims, and preserve same-caller recovery after the audited intent disables a retry. Keep terminal failures and foreign actors or intents rejected.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 79db1c2a6f)
Reserve an optional board request UUID under the run lock and retain it
through default Stop joins and native dispatch. Reject prior or competing
intents and require the same actor for idempotent retries.
Bind the Copilot denial fixture to its exact request and audited intent,
with versioned causal receipts and negative controls for earlier Stop.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep direct-child fallback bounded when process inspection fails, preserve incomplete cleanup evidence, and select graceful owners from the delivery snapshot without signaling already-covered descendants again.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep runnerd authority item IDs separate from native notice IDs. Retry optional diagnostic persistence on later state transitions without suppressing authoritative terminal save failures.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Validate the Cursor notice and active session/turn before retaining its closed observation fields. Preserve unknown token usage and cost, including malformed or stale diagnostics.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Recognize socket hang up only in transport errors. Test plain and prefixed drops plus HTTP bodies with misleading network text.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Preserve typed HTTP and transport timeout classification while removing raw response bodies and causes from admission reports. Reject unknown failures and malformed JSON without weakening ownership or deadline checks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bound outstanding admission reads, preserve successful stop and ownership proof immediately, and retain API failure causes and classification at the existing deadline.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Retain successful ownership and terminal reads when another endpoint fails. Reserve the existing fixture setup allowance inside the authored case deadline and capture binder failures with startup state.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Wait through cold snapshot provisioning while rechecking exact task/run ownership and active lease admission. Fail promptly on terminal runs and retain bounded startup state.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Include the production tsx name helper in generated Node programs so unchanged instruction copies remain warm. Exercise both generated programs through the actual tsx loader while retaining mutation and containment checks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Mark missing and invalid child run ordinals as partial observations. Exercise the pinned vendor child construction and reuse methods on all three platforms and regenerate the Cursor-only execution identity.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Stop immediate collection retries when ownership is deferred or attempts stop advancing. Keep unconfirmed agent-file retirement recoverable through generic cleanup, with later-owner and restart-proof regressions.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
* commit '4d6e2c00b88af9902facb20ad9177fb70a3a26e0':
Keep the next Cursor profile fixture within the typed contract
Retain stable projectless scope, transfer collection to the exact successor lease, and preserve stopped remote files without restarting their sandbox. Validate complete remote directories and cover the composed DB/session lifecycle, retirement, and fresh preparation.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Mark lost remote unchanged-turn copies unavailable only after exact termination proof, then perform owned cleanup. Preserve the live unchanged-turn guard and document warm ownership and crash preservation boundaries.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Probe complete materializations in bounded children, atomically transfer current-run collection authority, and preserve the exact agent home across warm turns. Retire before collecting changed or uncertain copies, fence stale claims and cleanup, and retain unresolved retirement ownership.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Roll back only files and directories created by a failed materialization. Cover partial writes, retry, foreign entries, and session replay isolation. Refresh the Copilot v7 source binding.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Verify and extract the pinned Copilot distribution, preserve native message IDs on the ordered ACP stream, and bind the guarded distribution to profile v7. Keep interim messages separate from final output.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reuse the production completion-contract envelope hash and exercise real contract creation and reuse in accepted-plan persistence tests.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Retain the original Cursor6 event filter when verifying an exact committed wait. Progress rows remain part of Cursor7 lifecycle proof without consuming the historical query budget.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Carry the admitted native plan parent tool into canonical request identity and require its exact successful durable lifecycle before passive settlement. Preserve historical committed Cursor6 waits while versioning new admission to Cursor7.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep current profile qualification mandatory when first creating a wait. Recovery uses its scoped committed receipt to verify the entire original proof, so future catalog/settings changes cannot authorize task work. Cover actual persisted finalization, catalog drift, original-profile tampering, and document explicit user continuation.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bind normal native plan acceptance to its durable request, delivered answer, admitted run and completion contract. Commit a passive in-progress result with a visible next-message summary, preserve semantic finish priority, and suppress recovery until task-specific continuation without changing modes.
Co-Authored-By: Paperclip <noreply@paperclip.ing>