Commit Graph
261 Commits
Author SHA1 Message Date
DottaandPaperclip a8df2064d6 fix(e2e): retain transient classification for admission socket drops
Recognize socket hang up only in transport errors. Test plain and prefixed drops plus HTTP bodies with misleading network text.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:56:23 -05:00
DottaandPaperclip 812b9e1a65 fix(e2e): normalize remote admission failures without private diagnostics
Preserve typed HTTP and transport timeout classification while removing raw response bodies and causes from admission reports. Reject unknown failures and malformed JSON without weakening ownership or deadline checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:48:21 -05:00
DottaandPaperclip 6ed490ee43 fix(e2e): reject stopped bootstrap runs without awaiting slow reads
Bound outstanding admission reads, preserve successful stop and ownership proof immediately, and retain API failure causes and classification at the existing deadline.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:23:19 -05:00
DottaandPaperclip 868c35e95c fix(e2e): preserve startup stop evidence and setup budget
Retain successful ownership and terminal reads when another endpoint fails. Reserve the existing fixture setup allowance inside the authored case deadline and capture binder failures with startup state.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:17:03 -05:00
DottaandPaperclip 1d3f237235 fix(e2e): bound remote bootstrap by the case deadline
Wait through cold snapshot provisioning while rechecking exact task/run ownership and active lease admission. Fail promptly on terminal runs and retain bounded startup state.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 07:58:24 -05:00
DottaandPaperclip a1145db4d8 test(runner-e2e): require observer startup readiness
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:51:08 -05:00
DottaandPaperclip 5c98f04299 fix(runner-e2e): bound remote observer startup requests
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:33:09 -05:00
DottaandPaperclip 72a88e124d Keep accepted Cursor plans waiting for explicit continuation
Bind normal native plan acceptance to its durable request, delivered answer, admitted run and completion contract. Commit a passive in-progress result with a visible next-message summary, preserve semantic finish priority, and suppress recovery until task-specific continuation without changing modes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip f401b831f2 Stabilize route setup and attachment announcement handling
Load route modules during fixture setup so cold transforms cannot leave a timed-out request running against the next test mock state. Dismiss delayed product announcements through the normal Board UI in the attachment receipt fixture.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:32:15 -05:00
DottaandPaperclip c9a0aaffa1 Bound Copilot fixture command prefix equivalence
Keep raw native command digests and exact execution origins while admitting at most eight leading ASCII space or tab bytes. Verify the relation in the settlement grader and retain independent local observations before a command mismatch aborts grading.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:58:04 -05:00
DottaandPaperclip 05d8b40a06 fix(evals): correlate denied Copilot tool target by origin
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 23:13:23 -05:00
DottaandPaperclip 951b06d08a fix(runner): fence warm ACPX owners on runtime contract changes
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 21:40:17 -05:00
DottaandPaperclip d6ff17fd0d test(runner-e2e): isolate denied-target watchers from startup churn
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 21:40:17 -05:00
DottaandPaperclip 4376dbe0be fix(evals): recognize native ACPX sidecar requests
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 21:40:17 -05:00
DottaandPaperclip a1ccf64737 test: clarify runnerd bootstrap ID correlation
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 19:13:40 -05:00
DottaandPaperclip 794e90a258 test: require exact attested bootstrap reads in native qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:54:12 -05:00
DottaandPaperclip 1597325184 test(runner): bound remote receipts by the cell deadline
Reserve 15 seconds for public teardown, share remaining time across SDK/socket/host waits, subtract setup time from observer TTL, and bound close independently without extending qualification.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:27:54 -05:00
DottaandPaperclip fe92554788 Wire native Daytona qualification and warm ACP journeys
Withhold native tasks until exact owned observers are armed, preserve sealed retirement proof before environment teardown, and register explicit local and Daytona warm continuity cases.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:26:29 -05:00
DottaandPaperclip 133793b419 test(runner): scope remote evidence around verified runtime state
Admit the actual staged runtime layout, retain sentinel and sibling mutation coverage, distinguish observed PRP identity from the sandbox lease, and bound setup readiness inside the caller deadline.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:22:19 -05:00
DottaandPaperclip 63eae696e7 test: bind Copilot remote protection to sealed sandbox evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:20:13 -05:00
DottaandPaperclip 522ab2d002 Fix canonical Cursor plan delivery expectations
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:18:14 -05:00
DottaandPaperclip 04e9e9aacc test: count all Copilot origins and verify marker after cleanup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:17:56 -05:00
DottaandPaperclip 9da7a7be62 test(runner): bind remote native evidence to exact run leases
Arm bounded filesystem and process observers before publishing native actions, retain sealed file and retirement receipts before ephemeral lease teardown, and provide an independent attached-command fixture.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:15:25 -05:00
DottaandPaperclip d1bb5729f9 Add Pi remote native evidence and browser denial fixtures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:13:41 -05:00
DottaandPaperclip fce6e109ad Prepare Cursor native Daytona flows with owned remote evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 17:13:41 -05:00
DottaandPaperclip 95faa1ee8b Prove Cursor native denial command and cancellation boundaries
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:45:15 -05:00
DottaandPaperclip c22526c266 test(runner): register native Cursor interactions and cleanup proof gates
Add four explicit candidate cells with mode-specific native callback evidence. Run independent cleanup assertions before grading and preserve failures while closing every observer.

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-29 16:41:43 -05:00
DottaandPaperclip 96ca6ce1e7 Clarify native fixture evidence requirements
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:41:43 -05:00
DottaandPaperclip 879eecdbb1 Prepare native Cursor callback and durable denial Product flows
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:41:43 -05:00
DottaandPaperclip 6ea2b49d88 fix(evals): bind interpreter build probe to Daytona image identity
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:06:39 -05:00
DottaandPaperclip 54dfc1bc8e fix(runner): preserve Copilot evidence in the direct driver
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:05:55 -05:00
DottaandPaperclip d3077a061f test(e2e): add Copilot denial and attached settlement cases
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 16:01:39 -05:00
DottaandPaperclip 76672efbeb test(runner-e2e): prepare Copilot denial and attached settlement oracles
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 15:56:52 -05:00
DottaandPaperclip a0d916a8c9 fix(evals): retain Pi native terminal API evidence
Capture the required final issue, runs, comments, interactions and paginated run events before native fixture success. Regress the real flow through evidence packaging and fail closed when terminal capture is unavailable.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 15:32:30 -05:00
DottaandPaperclip 23614d28c8 merge: integrate reviewed Copilot and Cursor runtime repairs into Pi
Preserve Pi v6 and bounded startup pools, admit current Cursor and Copilot v4 identities, and combine additive Product flows and catalog assertions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:33:28 -05:00
DottaandPaperclip 95dfde7c5c Merge current Cursor ACP runtime into Copilot v4
Preserve both profile-specific guards and complete terminal diagnostics; bind Copilot v4 to the regenerated ACPX patch.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 11:28:38 -05:00
DottaandPaperclip 3a08122558 Merge current master into Cursor ACP provider branch
Preserve upstream ACPX terminal diagnostics and rich extension delivery hooks.

Co-Authored-By: Paperclip <hello@paperclip.ing>
2026-09-29 10:36:20 -05:00
DottaandPaperclip 83076d7e7c feat: return completed handoffs to Agent Chat (#14408)
Return completed Agent Chat handoffs through a durable outbox and scope each generated update to its supplied tasks. Add recovery, browser delivery, result access, and calibrated quality coverage.

Validated with two consecutive ten-case Claude/Codex campaigns, all CI checks, and a 5/5 review.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 10:25:52 -05:00
Dotta 6766b9128e Merge branch 'codex/runner-copilot-acp' into codex/runner-pi-acp
* codex/runner-copilot-acp:
  Admit the verified Copilot v3 identity in Rust
  Admit the verified Cursor v3 identity in Rust
  Admit current ACP profiles and verify cross-language pin agreement
  Follow current Copilot profile identity in native installation admission
  Preserve authoritative Copilot guard errors for pending ACP requests
  Preserve Copilot policy rejection codes across sidecar transport
  Bind Copilot v3 identity to native detached-work admission
  Deny native Copilot detached work before permission dispatch
  Prove Cursor SDK interactions and retain profile v3 build evidence
  Bind Daytona image identity to Cursor isolation patch
  Retain Copilot detached-command early completion regression
  Prove Copilot permission recovery after provider death without replay

# Conflicts:
#	packages/paperclip-runner/src/drivers/acpx/qualified-profiles.ts
2026-09-29 10:10:17 -05:00
Dotta 304472946d Merge commit 'abad2bd0d' into codex/runner-copilot-acp
* commit 'abad2bd0d':
  Bind Daytona image identity to Cursor isolation patch
2026-09-29 09:58:05 -05:00
DottaandPaperclip 6f163033a4 test(runner): add explicit Pi native product boundaries
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 09:56:30 -05:00
DottaandPaperclip abad2bd0da Bind Daytona image identity to Cursor isolation patch
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 09:53:20 -05:00
DottaandPaperclip 3f4f8b37ba fix: grade Codex clarification and refusal outcomes from evidence (#14570)
Grade clarification lists, obsolete unstarted wakes, and refusal cancellation from persisted evidence. Preserve execution and ownership assertions, add boundary regressions, and version the affected eval definitions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 09:40:55 -05:00
DottaandPaperclip 5df684f182 Integrate final rich ACP foundation for production qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/runner-copilot-acp:
  fix(runner): stop settlement publication after persistence failure
  feat(agents): persist agent files across tasks without revision history (#14420)
  test(runner): synchronize recovered ACP fixture cleanup
  fix(runner): persist ACP response settlement across crashes
  feat(storage): add plain directory sync with conflict preflight (#14416)
  fix: retry sandbox ACP input delivery after gateway failures (#14485)
  fix: retain project defaults in partial workspace overrides (#14502)
  test: control Telegram subscription retry timing (#14501)
  fix: retain diagnostic reasons for native runner failures (#14481)
  fix: prevent run identity locks from blocking audit checks (#14478)
  fix: preserve company context across browser hot reload (#14482)
  feat(ui): improve task composer controls and pending input (#14322)
  Improve task artifacts with rich cards and editable stories (#14469)
2026-09-29 09:33:14 -05:00
DottaandPaperclip 55fa510d5e Integrate final rich ACP foundation for production qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/runner-cursor-acp:
  fix(runner): stop settlement publication after persistence failure
  feat(agents): persist agent files across tasks without revision history (#14420)
  test(runner): synchronize recovered ACP fixture cleanup
  fix(runner): persist ACP response settlement across crashes
  feat(storage): add plain directory sync with conflict preflight (#14416)
  fix: retry sandbox ACP input delivery after gateway failures (#14485)
  fix: retain project defaults in partial workspace overrides (#14502)
  test: control Telegram subscription retry timing (#14501)
  fix: retain diagnostic reasons for native runner failures (#14481)
  fix: prevent run identity locks from blocking audit checks (#14478)
  fix: preserve company context across browser hot reload (#14482)
  feat(ui): improve task composer controls and pending input (#14322)
  Improve task artifacts with rich cards and editable stories (#14469)
2026-09-29 09:33:14 -05:00
DottaandPaperclip 3d79b2b1f3 Integrate final rich ACP foundation for production qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/runner-rich-acp:
  fix(runner): stop settlement publication after persistence failure
  feat(agents): persist agent files across tasks without revision history (#14420)
  test(runner): synchronize recovered ACP fixture cleanup
  fix(runner): persist ACP response settlement across crashes
  feat(storage): add plain directory sync with conflict preflight (#14416)
  fix: retry sandbox ACP input delivery after gateway failures (#14485)
  fix: retain project defaults in partial workspace overrides (#14502)
  test: control Telegram subscription retry timing (#14501)
  fix: retain diagnostic reasons for native runner failures (#14481)
  fix: prevent run identity locks from blocking audit checks (#14478)
  fix: preserve company context across browser hot reload (#14482)
  feat(ui): improve task composer controls and pending input (#14322)
  Improve task artifacts with rich cards and editable stories (#14469)
2026-09-29 09:33:13 -05:00
DottaandPaperclip 24beb00575 feat(runner): add rich ACP transport and durable interaction foundation (#14430)
Add shared rich ACP transport, durable questions and permissions, verified provider packaging, and bounded activity and plan presentation. Keep Cursor, Copilot, and Pi pending their separate provider qualification.

Persist interaction settlement before publication, fence failed writes until fresh recovery, and preserve owned-process cleanup. Incorporate reviewed mainline integration with extended harness coverage.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 08:56:21 -05:00
DottaandPaperclip 8747917668 Merge master agent-file persistence into rich ACP foundation
Preserve the extended harness and instruction-persistence suites, generated
contracts, and cleanup/collection ordering. Record the unqualified ACPX
agent-directory capability without broadening environment or path policy.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 08:36:37 -05:00
DottaandFry 3ca196b0a6 feat(agents): persist agent files across tasks without revision history (#14420)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - An agent needs personal files across tasks and sessions.
> - AGENTS.md is one file in that directory. Supporting files need the
same persistence.
> - The Instructions Editor and agent runs must share one current
directory.
> - Concurrent runs should apply only the files they change. The last
sync of the same file wins.
> - This pull request uses existing file transport and removes temporary
copies after sync.
> - Old instruction-only sessions keep their restore contract. New saves
do not create revision history.

## Linked Issues or Issue Description

Refs #14325. This replaces its revision-oriented design with persistent
agent files. Keep #14325 unmerged.

Transport prerequisite #14416 merged first at
`d172197117a14b80a1eb2d2835a0e7cce2679656`. This PR now targets master
and remains below 100 changed files.

Related work: #4513 and #8798 cover instruction tooling. This change
handles run synchronization, cross-task personal files, browser editing,
and old-session restoration.

## What Changed

- Keep one current directory per company and agent. Point AGENT_HOME at
a temporary working copy for each active run. Keep task files and
provider HOME separate.
- Restore text, binary files, and nested folders through workspace
transport. Exclude remote agent files from task Git snapshots with a
self-ignoring file inside the reserved runtime directory; never write
through repository-controlled Git metadata.
- Collect after the provider and child processes have stopped. Keep
resumable conversation state.
- Apply changed and deleted files under the agent lock. The last sync
wins for the same file. Unrelated concurrent changes survive.
- Remove temporary copies after successful sync, rejected sync, and
staging failure. Register ownership before copying so restart recovery
can remove interrupted preparation. Retry transient synchronization up
to three times. Preserve the original remote lease reference until
deletion succeeds; restart cleanup never acquires a replacement sandbox.
Do not create captured directories or a conflict-review queue for new
runs.
- Keep browser editing, stale-draft protection, and streaming binary
downloads. Keep the instruction entry and text editor limited to 1 MiB.
- Keep historical agent-folder sync failures on their affected runs
instead of repeating them above current saved instructions. Preserve
legacy candidate review and current browser-save errors. Avoid duplicate
quota warnings while retaining separate sync failures when they describe
a different problem.
- Require target-scoped caller grants for peer instruction access, while
preserving self edits, responsible-user checks, and protected-change
consent.
- Treat full storage as a nonblocking run warning, never an agent pause
or run-admission failure. Restore already-over-quota saved folders so
ordinary agent cleanup can recover; warn on each run until cleanup. The
run detail view shows the warning.
- Allow 256 MiB per file, 2 GiB per directory, and 100,000 entries. Hash
large files as streams. Check editor-save quotas with metadata instead
of hashing unrelated files.
- Preserve old native inputs, instruction-only copies, paths, digests,
and pending legacy candidates. Adopt old revision heads once. New writes
do not append history rows.
- Add idempotent migration 0287 and verify upgrades from the preview
tables and receipts.
- Add nine interactive stories under **Agents / Persistent files**,
including automatic incoming edits, stale browser drafts, and
storage-limit diagnostics.

## Verification

- Merge candidate: `4f5390107ec6ffd80a76d1d2e85530e66f21d079`, after
merging current master and the landed transport prerequisite.
Integration required no manual conflict resolution; the feature remains
99 changed files. Full workspace typecheck, production build, token
gates, and 715 focused tests passed on this merge candidate. Fresh
Greptile review is 5/5 with no unresolved findings. All 55 checks
passed, with four conditional skips, including the build, typecheck,
browser E2E, and canary dry run. A single retry recovered four jobs
interrupted by runner shutdowns; no source changes were required.
- Historical-warning UI fix: all 6,834 UI tests across 640 files passed,
including regression coverage for three old failures, legacy preserved
edits, and warnings scoped to the affected run. Full workspace
typecheck, production build, Storybook build, and token gates passed.
Browser-verified Storybook playtests passed for Historical Failures
After Successful Save, Storage Limit, and Full Storage Run Warning.
- Review follow-ups at `4e20c9fb2`: all 18 focused tests passed,
including external Git directories, linked worktrees, symlinks,
hardlinks, and distinct I/O failures alongside storage warnings. Server
and UI typechecks, token gates, and the production build passed.
- Storage warning regressions at `0724f3012`: all 33 directory tests and
all five heartbeat-list tests passed, with no skips in their successful
runs. They cover repeated runs while full, an already-over-quota saved
folder, cleanup, warnings retained after unrelated save failures, and
bounded warnings in large result JSON. Server typecheck passed after the
final warning fixes.
- Full workspace typecheck, production build, and token gates passed
during this follow-up. Product E2E harness: 631 tests passed across 52
files; harness typecheck passed. Earlier native session/context and
directory/legacy collection suites passed 537 tests; Runner
unit/transport suites passed 329 tests.
- **Real E2E at `0724f3012` (before this follow-up):** legacy local
Codex and native Daytona Codex each passed six tasks, one server
restart, seven independent assertions, and cleanup verification. Both
prove browser-to-agent edits, agent-to-browser edits, nested/binary
restoration, per-file last-sync-wins, a successful run after an
oversized save rejection, and cleanup clearing the warning.
- Native local Codex also passed the six-task quota flow before the
final warning-retention fixes. That pass began at `918d1ed02` while the
bounded-result warning fix was being edited, so it is not claimed as
exact-final-head evidence. Its final-head rerun failed during embedded
PostgreSQL bootstrap before any provider run: the macOS host had 87,365
of 87,381 SysV semaphores occupied. No unrelated services or kernel
limits were changed.
- The final-source report intentionally records **2/3 cells passed**,
preserving the blocked native-local attempt:
`tests/runner-e2e/results/agent-files-quota-final-20260928-report/`.
Earlier failed attempts and provenance notes remain under
`tests/runner-e2e/results/agent-files-quota-final-20260928-input/` and
the original campaign directories.
- Daytona used immutable image
`ghcr.io/paperclipai/paperclip-daytona-runner@sha256:5643f0d801417cae3581833a1a3bc6715b325e028602738d2652c44cac5dc6bf`
and its exact Linux runner binary. Controller source is `0724f3012`;
image source is recorded separately.
- Legacy-session compatibility and all three ACP Stop/resume browser
regressions passed on the prior validated feature head
`169fab46d5af21caa2269b4c1b29b69c933a6951`. They assert the same
provider session is retained and interrupted writes are not replayed.
Migration upgrade tests also passed earlier.
- Nine interactive stories are under **Agents / Persistent files**,
including **Full Storage Run Warning**. Its playtest and visual browser
inspection passed; the warning states that runs continue and the editor
remains available.
- Prior-head checks on `4e20c9fb2`: 55 passed, two conditional jobs
skipped, no failures or pending checks. All eight browser E2E shards and
their aggregate passed. Fresh Greptile review is 5/5 with no findings;
all review threads are resolved, the security scan passed, and GitHub
reports no merge conflicts.
- The broad local follow-up test run was interrupted after host
semaphore exhaustion affected isolated PostgreSQL instances. It also
encountered the existing macOS long-path fixture failure and two timeout
failures. This is not a claim that the full local suite passed. Logs are
retained; focused storage/warning tests passed.

## Risks

- A later sync can overwrite an earlier edit to the same file, including
a saved browser edit. There is no text merge or retained version. This
is the intended last-sync-wins policy.
- A save that exceeds a storage limit is rejected and its temporary copy
is discarded. The run itself continues normally, and later runs restore
the last saved files with a warning until cleanup. Transient sync
failures get bounded retries. An I/O failure partway through a sync can
leave some files updated; a failed receipt does not claim whole-folder
success.
- Larger folders increase copy time, network traffic, and temporary disk
usage. Active runs still need working copies. Terminal runs do not
accumulate archives. Operators must provision disk for agents and
configured concurrency; these limits are not company-wide quotas.
- A restored old native session remains instruction-only until a fresh
session starts. Its original conflict fence and existing pending
candidates remain compatible.
- Provider processes close at the collection boundary. Conversation
resume remains available, but warm process reuse is lost.
- Backups must include the instance filesystem and database. External
bundles keep their existing behavior until explicitly moved to managed
storage.

## Model Used

OpenAI Codex, GPT-6 family. The session does not expose a more specific
model ID or context-window size. Reasoning, code execution, and browser
tools assisted this change. Real provider E2E uses `gpt-5.6-sol`.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Fry (Paperclip) <noreply@paperclip.ing>
2026-09-29 08:25:56 -05:00
DottaandPaperclip 9774086a73 Integrate current master before rich ACP foundation review
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* commit '53aad90b9':
  fix: retry sandbox ACP input delivery after gateway failures (#14485)
  fix: retain project defaults in partial workspace overrides (#14502)
  test: control Telegram subscription retry timing (#14501)
  fix: retain diagnostic reasons for native runner failures (#14481)
  fix: prevent run identity locks from blocking audit checks (#14478)
  fix: preserve company context across browser hot reload (#14482)
  feat(ui): improve task composer controls and pending input (#14322)
  Improve task artifacts with rich cards and editable stories (#14469)
2026-09-29 07:50:49 -05:00