Commit Graph
5091 Commits
Author SHA1 Message Date
Dotta 56d4ece67f ci: isolate pinned AJV npm packaging diagnosis 2026-09-30 16:37:12 -05:00
DottaandPaperclip 1cfb366607 ci(runner): run manual full verification on hosted Ubuntu
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 15:39:29 -05:00
Dotta 0f8fbd6fc3 ci(runner): add pinned full verification on the fleet 2026-09-30 13:50:10 -05:00
Dotta 45b977bca0 fix(server): admit correlated Stop for durable native retries
Check failed-run retry eligibility under the run and coordinator locks, fail closed on concurrent coordinator claims, and preserve same-caller recovery after the audited intent disables a retry. Keep terminal failures and foreign actors or intents rejected.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 79db1c2a6f)
2026-09-30 13:36:15 -05:00
DottaandPaperclip 647e4adf27 fix(native): bind operator Stop to caller cancellation intent
Reserve an optional board request UUID under the run lock and retain it
through default Stop joins and native dispatch. Reject prior or competing
intents and require the same actor for idempotent retries.

Bind the Copilot denial fixture to its exact request and audited intent,
with versioned causal receipts and negative controls for earlier Stop.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 12:03:34 -05:00
Dotta 22ded968dd docs(runner): correct denial settlement evidence limits 2026-09-30 11:33:55 -05:00
DottaandPaperclip 8040aa903c test(runner-e2e): reject coerced observation clock fields
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 11:33:41 -05:00
DottaandPaperclip eecd64509a fix(runner-e2e): require causal pre-Stop denial observations
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 11:33:41 -05:00
DottaandPaperclip 20154268be fix(runner-e2e): await durable denial evidence before Stop and sampling
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:58:35 -05:00
DottaandPaperclip 72cbc3503d fix(runner-e2e): distinguish Copilot denial settlement from Stop
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:58:35 -05:00
DottaandPaperclip 0499513435 fix(runner-e2e): bound inspection failure and graceful delivery races
Keep direct-child fallback bounded when process inspection fails, preserve incomplete cleanup evidence, and select graceful owners from the delivery snapshot without signaling already-covered descendants again.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:58:35 -05:00
DottaandPaperclip 0ad2173bc1 fix(runner-e2e): retain shutdown ownership across launcher cleanup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:58:35 -05:00
DottaandPaperclip a8ecf41cb1 fix(runner-e2e): preserve graceful server shutdown
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:58:35 -05:00
Dotta d8dfacff88 docs(runner): update qualification evidence and remaining gates 2026-09-30 10:57:10 -05:00
DottaandPaperclip adc049b904 fix(runner): preserve Cursor notice identities and settlement
Keep runnerd authority item IDs separate from native notice IDs. Retry optional diagnostic persistence on later state transitions without suppressing authoritative terminal save failures.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:35:36 -05:00
DottaandPaperclip 024776da24 docs(runner): clarify historical Cursor usage evidence limits
Avoid inferring that a captured paid attempt emitted the notice lost by the old recorder.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:35:36 -05:00
DottaandPaperclip 653bf7c37d fix(runner): retain bounded Cursor diagnostics in eval evidence
Validate the Cursor notice and active session/turn before retaining its closed observation fields. Preserve unknown token usage and cost, including malformed or stale diagnostics.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:35:36 -05:00
DottaandPaperclip a8df2064d6 fix(e2e): retain transient classification for admission socket drops
Recognize socket hang up only in transport errors. Test plain and prefixed drops plus HTTP bodies with misleading network text.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:56:23 -05:00
DottaandPaperclip 812b9e1a65 fix(e2e): normalize remote admission failures without private diagnostics
Preserve typed HTTP and transport timeout classification while removing raw response bodies and causes from admission reports. Reject unknown failures and malformed JSON without weakening ownership or deadline checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:48:21 -05:00
DottaandPaperclip 6ed490ee43 fix(e2e): reject stopped bootstrap runs without awaiting slow reads
Bound outstanding admission reads, preserve successful stop and ownership proof immediately, and retain API failure causes and classification at the existing deadline.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:23:19 -05:00
DottaandPaperclip 868c35e95c fix(e2e): preserve startup stop evidence and setup budget
Retain successful ownership and terminal reads when another endpoint fails. Reserve the existing fixture setup allowance inside the authored case deadline and capture binder failures with startup state.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:17:03 -05:00
DottaandPaperclip 1d3f237235 fix(e2e): bound remote bootstrap by the case deadline
Wait through cold snapshot provisioning while rechecking exact task/run ownership and active lease admission. Fail promptly on terminal runs and retain bounded startup state.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 07:58:24 -05:00
DottaandPaperclip 22721c1ab0 fix(server): serialize standalone agent directory probes
Include the production tsx name helper in generated Node programs so unchanged instruction copies remain warm. Exercise both generated programs through the actual tsx loader while retaining mutation and containment checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 07:55:15 -05:00
Dotta 5c69b69ef2 Integrate Cursor child counter provenance
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '986f8cc5344107cc199c69e0581cba5401c54282':
  Verify Cursor child usage lifecycle and fence profile v9

# Conflicts:
#	doc/architecture/runner-cursor-capabilities.md
2026-09-30 05:34:15 -05:00
DottaandPaperclip 986f8cc534 Verify Cursor child usage lifecycle and fence profile v9
Mark missing and invalid child run ordinals as partial observations. Exercise the pinned vendor child construction and reuse methods on all three platforms and regenerate the Cursor-only execution identity.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 05:33:44 -05:00
DottaandPaperclip 3518902733 Integrate bounded warm retirement recovery
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '84a50124a997f4256932eab15fe79dd9ce875940':
  fix(runner): bound instruction collection and preserve pending retirement
2026-09-30 05:29:03 -05:00
DottaandPaperclip 84a50124a9 fix(runner): bound instruction collection and preserve pending retirement
Stop immediate collection retries when ownership is deferred or attempts stop advancing. Keep unconfirmed agent-file retirement recoverable through generic cleanup, with later-owner and restart-proof regressions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 05:28:06 -05:00
DottaandPaperclip 6e0f54f565 Include the checked Cursor profile fixture in the combined candidate
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '4d6e2c00b88af9902facb20ad9177fb70a3a26e0':
  Keep the next Cursor profile fixture within the typed contract
2026-09-30 05:23:15 -05:00
DottaandPaperclip 4d6e2c00b8 Keep the next Cursor profile fixture within the typed contract
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 05:23:00 -05:00
DottaandPaperclip 34672c0c06 Combine reviewed remote observer fixture fixes
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit 'a1145db4d8dbde17e624f8a14ef2726b33d09083':
  test(runner-e2e): require observer startup readiness
  fix(runner-e2e): bound remote observer startup requests
2026-09-30 05:14:31 -05:00
DottaandPaperclip b09e0a1967 Combine warm recovery and versioned ACP usage candidates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 05:14:31 -05:00
DottaandPaperclip e95e28d9c8 Preserve partial Cursor native usage diagnostics and version ACP profiles
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 05:12:44 -05:00
DottaandPaperclip 3be4f778c6 fix(runner): fence warm directory successor ownership and recovery
Retain stable projectless scope, transfer collection to the exact successor lease, and preserve stopped remote files without restarting their sandbox. Validate complete remote directories and cover the composed DB/session lifecycle, retirement, and fresh preparation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 05:05:41 -05:00
DottaandPaperclip a1145db4d8 test(runner-e2e): require observer startup readiness
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:51:08 -05:00
DottaandPaperclip 5c98f04299 fix(runner-e2e): bound remote observer startup requests
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:33:09 -05:00
DottaandPaperclip 8d8e57a58f docs(runner): record corrected plan and current qualification evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:04:26 -05:00
DottaandPaperclip 5d4b3ac6c4 Finish stop-proved recovery of retained agent directories
Mark lost remote unchanged-turn copies unavailable only after exact termination proof, then perform owned cleanup. Preserve the live unchanged-turn guard and document warm ownership and crash preservation boundaries.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:03:03 -05:00
DottaandPaperclip 6c6c05dccb Retain unchanged agent files with their warm native owner
Probe complete materializations in bounded children, atomically transfer current-run collection authority, and preserve the exact agent home across warm turns. Retire before collecting changed or uncertain copies, fence stale claims and cleanup, and retain unresolved retirement ownership.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 03:59:20 -05:00
Dotta 3d21d375de Record current profile qualification and controller settlement fix 2026-09-30 02:56:03 -05:00
DottaandPaperclip 44e1b421cb Record Cursor plan correlation failure and reviewed profile7 candidates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip 654ec2a9cc Fix Copilot materialization rollback and cover replay identity
Roll back only files and directories created by a failed materialization. Cover partial writes, retry, foreign entries, and session replay isolation. Refresh the Copilot v7 source binding.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip 913f374191 Preserve native Copilot assistant message identities
Verify and extract the pinned Copilot distribution, preserve native message IDs on the ordered ACP stream, and bind the guarded distribution to profile v7. Keep interim messages separate from final output.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip c58a8881f2 fix: validate Cursor plan waits against canonical contract policy
Reuse the production completion-contract envelope hash and exercise real contract creation and reuse in accepted-plan persistence tests.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:54:16 -05:00
DottaandPaperclip b74ca5eb97 test(runner): dereference the owned Node fixture copy
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:24:13 -05:00
DottaandPaperclip 6fa2399392 test(runner): isolate the qualified OpenCode Node fixture
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:15:31 -05:00
DottaandPaperclip a2984a0a9d Preserve historical Cursor plan proof query bounds
Retain the original Cursor6 event filter when verifying an exact committed wait. Progress rows remain part of Cursor7 lifecycle proof without consuming the historical query budget.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:15:04 -05:00
DottaandPaperclip 770dc88a11 Bind Cursor plan waits to the native tool lifecycle
Carry the admitted native plan parent tool into canonical request identity and require its exact successful durable lifecycle before passive settlement. Preserve historical committed Cursor6 waits while versioning new admission to Cursor7.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip 4b94270a0b Await clean Stop continuation settlement in recovery test
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip ade7c83dbb Preserve committed Cursor plan waits across profile upgrades
Keep current profile qualification mandatory when first creating a wait. Recovery uses its scoped committed receipt to verify the entire original proof, so future catalog/settings changes cannot authorize task work. Cover actual persisted finalization, catalog drift, original-profile tampering, and document explicit user continuation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip 72a88e124d Keep accepted Cursor plans waiting for explicit continuation
Bind normal native plan acceptance to its durable request, delivered answer, admitted run and completion contract. Commit a passive in-progress result with a visible next-message summary, preserve semantic finish priority, and suppress recovery until task-specific continuation without changing modes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00