mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
9ae3d8db3dc930f316f29e6e83fe6c325ac8bc06
4764
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
9ae3d8db3d |
fix: keep pre-dispatch review waits out of execution recovery (#15024)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The queued-run gate can cancel a continuation that must wait for review. > - This cancellation happens before execution authority or a provider starts. > - Recovery currently treats the gate receipt as unknown provider execution. > - That mistake blocks a conversation after a successful reply and hides Retry. > - This pull request recognizes only the recorded, unclaimed review-wait state. > - Review waits keep their normal disposition path, and new user input can recover older false holds. ## Linked Issues or Issue Description Refs #15015, #15020, and #15022. Related #11614 narrows the review posture that causes cancellation; this change corrects recovery after a valid cancellation. **What happened?** After a successful agent reply, the queued-run gate cancelled an automatic continuation with `issue_continuation_waiting_on_review`. The gate retained `timeoutSource: stale_queued_run_gate` and a matching stop reason. No execution authority or provider started. Recovery still created an unknown-action hold, moved the task to Blocked, and hid Retry. **Expected behavior** Use normal review-wait disposition repair for this recorded state. Allow Retry, a new user message, or saved undelivered input to recover an older false hold after ordinary admission checks pass. Preserve the cancelled run and do not replay its input. **Steps to reproduce** 1. Finish an agent turn on an open task that has a real review target. 2. Let the automatic continuation reach the queued-run review gate. 3. Refresh after the cancelled run is checked by recovery. 4. Confirm a review wait is handled as a wait rather than unknown provider work. 5. Reproduce an older false hold for the same receipt, then request Retry or send a new message. 6. Confirm only one fresh turn starts, and contradictory execution or cleanup evidence retains the hold. **Paperclip version or commit** Reproduced on `215586d127`. **Deployment mode** Authenticated private self-hosted server, built from source. ## What Changed - Recognize the exact review-wait dispatch receipt only while all execution claims remain unset. - Exempt recovery only after checking retained launch and provider events, coordinators, and environment cleanup. Keep the synchronous classifier conservative without that database proof. - Apply the verified classification to automatic recovery, heartbeat retries, and stranded-queue release, so saved user input starts once. - Reuse guarded startup admission for Retry, new input, and saved input on older false holds. - Show a precise review-wait notice and keep continuation guidance consistent with Retry availability. - Verify provider events, launch events, coordinators, and cleanup before admission. - Add five initial red regressions, three additional red recovery evidence regressions, concurrent saved-input coverage, and negative evidence checks. - Document the review-wait contract. ## Verification - Red: five regressions fail on unchanged master. Existing review-wait and contradictory-evidence cases still pass. - Workspace `pnpm -r typecheck` passes. - All 752 affected recovery, continuation, queue, classification, and retry-scheduling tests pass. - Three additional review regressions failed before the database proof was added; all 12 focused review-wait cases then pass. - Workspace `pnpm build` passes. - Saved-input promotion and recovery notice regressions fail before their fixes and pass afterward. - Current-head CI has 54 passing checks and 2 skipped optional Storybook checks. Greptile reviewed `0bf1437110e1617ae4544afa41f4319eac763dba` at 5/5 with zero open findings. The complete suite runs in sharded CI. No complete local monolithic pass is claimed; an earlier long run was stopped, and its unrelated failing case passed in isolation. ## Risks The error code alone cannot establish that no provider started. This exception also requires the server gate receipt, matching stop reason, and null execution authority fields. User admission separately checks coordinator, launch and provider events, environment cleanup, pending decisions, ownership, task holds, budget, and active execution. No migration or dependency change. ## Model Used OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and context window are not exposed in this session. Used reasoning, repository tools, code execution, and browser inspection. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1003.0-canary.4 |
||
|
|
215586d127 |
fix: settle interrupted preparation with a retained cancellation fence (#15022)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - A cancelled preparation must preserve history while allowing a new user turn. > - Older preparation can retain its cancellation fence but omit the unwind marker. > - The controller from that older boot is gone, its lease expired, and no provider started. > - Use the same narrow preparation proof for this retained-fence state. > - The benefit is working Retry and saved-message recovery after interrupted startup. ## Linked Issues or Issue Description Refs #15020 and #15015. Related #13293 addresses post-launch recovery. **What happened?** A preparation interrupted before native selection retained `startupCancellation.beforeNativeSelection: true` but no preparation-settled marker. Its owner expired across restart and it had no environment leases. The missing-receipt compatibility rule did not recognize the retained fence, leaving Retry absent and saved messages deferred. **Expected behavior** Admit one new user turn when the preparation evidence agrees, the old controller expired, and cleanup is complete. Preserve previous results and do not replay the cancelled input. **Steps to reproduce** 1. Cancel Paperclip Runner preparation before runtime selection. 2. Retain the cancellation fence without an unwind marker or environment leases. 3. Restart after its old controller lease expires. 4. Send a new message, select Retry, or allow the saved-message worker to reconsider new input. 5. Confirm one successor receives only undelivered input. Repeat with live ownership, invocation evidence, or pending cleanup and confirm execution stays held. **Paperclip version or commit** Reproduced on `94f6f3eb4`. **Deployment mode** Authenticated private self-hosted server, built from source. ## What Changed - Accept a retained before-selection cancellation fence in the expired historical preparation proof. - Retain runtime, stage, adapter, ownership expiry, process, event, and cleanup requirements. - Extend Retry, fresh-message, partial-queue, concurrent-worker, and contradictory-evidence tests to both receipt states. - Document recovery when the preparation-settled marker was not retained. ## Verification - Red: five exact-state regressions fail on the parent commit. - Green: all 203 continuation tests pass, including the five new regressions and 13 additional negative evidence cases. Process recovery and queued-comment routes add 413 passing tests. - A read-only candidate service check against the retained live run returns Retry eligibility without changing any task state. - An unrelated containment assertion failed once in CI. All 85 tests in that route suite pass locally and the CI shard passes on rerun. - Workspace `pnpm -r typecheck` and `pnpm build` pass. - Final head `48240de3d`: all 54 CI checks pass, two optional Storybook checks skip, and Greptile is 5/5 with zero unresolved threads. The complete local monolithic suite is covered by sharded CI; the earlier local run was stopped after a workspace case failed, and that case passed in isolation. - After merge, deploy the exact merged commit and verify an actual agent reply through the task composer. ## Risks A cancellation receipt alone must not certify that provider execution stopped. This path still requires unresolved preparation, no native identity or coordinator, an expired controller from another boot, no launch or provider evidence, and completed environment cleanup. Current-boot preparation remains held until it settles. No schema or dependency change. ## Model Used OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and context window are not exposed in this session. Used reasoning, repository tools, code execution, and browser inspection. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1003.0-canary.3 |
||
|
|
94f6f3eb47 |
fix: recover historical interrupted native preparation (#15020)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - A task conversation must accept new user input after an interrupted startup. > - Native startup begins with a legacy preparation row before runtime selection. > - Older builds did not retain the startup cancellation receipt on that row. > - The immutable adapter claim and expired controller can still prove that no provider started. > - This pull request uses that narrow proof for explicit Retry and saved user input. > - The benefit is a conversation that recovers after an upgrade without repeating old work. ## Linked Issues or Issue Description Refs #15015. Related #13293 covers retained process evidence after provider startup. This change covers interrupted preparation before native runtime selection. **What happened?** After an upgrade, a task stopped during native preparation can still show automatic recovery stopped. A new user message saves but does not start. Retry is absent because the historical run has no cancellation receipt. **Expected behavior** Offer Retry and admit new user input when immutable run evidence proves that no provider started and cleanup is complete. Preserve incomplete or contradictory evidence as a recovery hold. **Steps to reproduce** 1. Retain a cancelled run with the Paperclip Runner adapter claim, an unresolved runtime, and the preparing stage. 2. Keep its old controller boot ID and expired lease. Retain no native identity, coordinator, result, process identity, or provider events. 3. Upgrade from a build that did not save the startup cancellation receipt. 4. Send a new user message or select Retry. Confirm that one fresh turn starts. 5. Repeat with an active controller, a provider launch, or unfinished cleanup. Confirm that execution stays held. **Paperclip version or commit** Reproduced on `cc67d4e1d` with a historical interrupted preparation row. **Deployment mode** Authenticated private self-hosted server, built from source. ## What Changed - Recognize historical interrupted native preparation from immutable run evidence and an expired controller from another server boot. - Reject adapter invocation evidence in the startup proof. Keep process and environment cleanup checks. - Apply the same proof to saved user messages in the bounded recovery worker. - Recheck saved-message eligibility under the existing task and run locks. Keep normal ownership, decision, pause, and budget gates. - Add regression tests for Retry, a new message, concurrent saved-message recovery, and contradictory evidence. Document the compatibility rule. ## Verification - Red: Retry, new-message recovery, and saved-message recovery fail on the parent commit. - Green: 185 continuation tests, 335 process-recovery tests, and 78 queued-comment route tests pass. Two additional red regressions cover partially delivered saved queues and pass after the admission fix. - Workspace `pnpm -r typecheck` and `pnpm build` pass. - Final head `48db53f4f`: all 54 CI checks pass; two optional Storybook checks skip. Greptile is 5/5 with zero unresolved threads. - The local monolithic `pnpm test:run` was stopped after CI passed. One unrelated workspace case failed in that long run; all three workspace reconciliation cases pass in isolation. No complete local monolithic pass is claimed. - After merge, deploy the exact merged commit and verify recovery through the normal task composer. ## Risks Historical compatibility could grant a new turn without enough startup evidence. The proof requires an immutable native adapter claim, an unresolved preparing stage, no result or native identity, an expired controller from another server boot, and no invocation or provider evidence. Environment cleanup remains mandatory. The fix does not replay old input or change historical run results. No schema or dependency change. ## Model Used OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and context window are not exposed in this session. Used reasoning, repository tools, code execution, and browser inspection. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1003.0-canary.2 |
||
|
|
cc67d4e1d8 |
fix: preserve steering and recover stopped task conversations (#15015)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - A task conversation must let a user guide a running agent and resume stopped work. > - The active run owns its input protocol, even when the user changes the next model or effort. > - Queue delivery waits for a provider receipt, which must be able to persist during the request. > - A stopped startup also needs a clear user action that passes normal task admission. > - This pull request fixes steering delivery, makes queue actions immediate, and restores explicit continuation. > - The benefit is a responsive conversation that can recover without losing saved input. ## Linked Issues or Issue Description **What happened?** A queued message could change from Steer to Interrupt while a native run prepared. A steer request could wait on its own database lock and fail to deliver. A stopped startup could then leave the conversation without a working Retry or message continuation. Interrupt also waited for the server and showed a toast. **Expected behavior** The active run keeps its input protocol. Steer delivers input to that run. Steer and Interrupt clear the submitted queue rows and show the input in the conversation immediately. Failed delivery restores the latest queue with an inline error. An eligible stopped run offers Retry, and authenticated user input can start a fresh turn through normal task admission. **Steps to reproduce** 1. Start a task with a native Paperclip Runner. 2. Change the selected model or effort while that run prepares. 3. Queue a message and press Steer. 4. Observe the provider receipt and queue state during the request. 5. Stop a startup before its provider process begins, then try Retry or send a new message. 6. Repeat queued delivery with a legacy runner and press Interrupt. **Paperclip version or commit** Reproduced on the parent of this branch, `59c07ede7`. **Deployment mode** Authenticated private deployment. The fixes also cover local task conversations. Related work: Refs #12834, Refs #13354, Refs #13275. The open refactor in #13160 moves the same queue route; it does not fix the receipt lock or stopped-run continuation addressed here. ## What Changed - Select queue behavior from the active run's immutable dispatch and runtime resolution. - Leave the run row unlocked during provider acknowledgement, then lock and read it before merging the receipt. - Retain queued input if the target run stops during that wait. Keep inline delivery errors visible after empty queue updates. - Permit exact Retry and authenticated continuation after verified native startup cancellation. Preserve pause, approval, budget, ownership, and process-stop gates. - Carry undelivered native queue input into a fresh turn once the old execution is confirmed stopped. - Show Steer and Interrupt input in the conversation and clear submitted composer rows immediately. Restore the latest queue inline on failure. Remove delivery toasts. - Keep optimistic delivery stable across stale polls, empty queues, and paginated history. Preserve classic Interrupt error handling. - Document recovery and optimistic delivery behavior. Add regression tests across server, shared queue projection, and UI boundaries. ## Verification - Red-green regression tests reproduced the queue protocol, receipt lock, stopped-startup continuation, and optimistic delivery failures. - The focused server route, continuation, queue, and runner boundary suites passed during implementation. - The queue-route suite passes with 78 tests. The three complete conversation UI suites pass with 347 tests. - UI typecheck, production build, and `pnpm check:token-gates` pass. - Workspace `pnpm -r typecheck` and `pnpm build` pass. The local monolithic `pnpm test:run` is still running; remote CI verifies the complete suite on the latest commit. - All CI gates pass on `bd9031ad56abfcde13d13a13488c1b9217c2fd3a`, including the full test shards, runner verification, browser E2E, typecheck, release registry, and canary dry run. - Greptile reports 5/5 for that commit. Both review threads are resolved. ## Risks This changes queue display and explicit continuation admission. The UI must restore rejected delivery without losing other-session edits. The server must preserve concurrent provider result updates and must not resume a process whose stop is uncertain. Focused tests cover these boundaries. This change has no database migration. ## Model Used OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and context window are not exposed in this session. Used reasoning, repository tools, code execution, and browser inspection. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1003.0-canary.1 |
||
|
|
59c07ede72 |
fix(ui): let a selected saved subscription be used without a tile click (#14996)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - A user creates an agent in the New Agent flow and connects a model provider in the model step. > - When a saved subscription exists, the step shows it as the selected default and labels the primary button "Use saved subscription". > - The button stays disabled until the user clicks the provider tile, which adds no auth step on this path. > - This extra click is a papercut: the visible choice looks ready but does not work. > - This pull request lets a selected saved subscription enable the button without the tile click. > - The benefit is one less confusing step, with no change to new sign-ins or API keys. ## Linked Issues or Issue Description No public issue exists. The description follows the bug template. **What happened** In New Agent > Connect model, choose a provider that has a saved subscription (for example OpenAI with a saved default). The saved subscription shows as selected and the primary button reads "Use saved subscription". The button stays disabled until you click the provider tile. **Expected behavior** The button is enabled when a saved subscription is selected. A click on it reuses that subscription. **Steps to reproduce** 1. Have a saved OpenAI subscription. 2. Open New Agent and go to the model connection step for a Codex agent. 3. Do not click the OpenAI Subscription tile. 4. See that "Use saved subscription" is disabled. **Paperclip version or commit** master at `4abff286c`. ## What Changed - `AgentProviderConnection.tsx`: the `!opened` gate on the footer primary button no longer applies when `method === "subscription"` and a saved subscription is selected. All other disabled conditions stay (pending auth, loading saved keys, login readiness, API key input). - `connect()` never reads `opened`, so no auth step is skipped. New sign-ins and API keys still require the user to open the provider tile. - `AgentProviderConnection.test.tsx`: a regression test that renders the initial state (tile not opened, saved subscription selected) and expects the button to be enabled and to connect with the saved subscription. A guard test checks that a new sign-in still requires opening the tile. ## Verification - `cd ui && npx vitest run src/components/new-agent src/components/ai-connections --no-file-parallelism`: 6 files, 64/64 tests pass. - The new regression test fails on master and passes with this change. - `pnpm --filter @paperclipai/ui typecheck`: 0 errors. - `node scripts/check-token-gates.mjs`: all gates clean. - Component QA in Storybook (real component, provider verification simulated): before, the button is disabled and skipped by Tab until the tile click. After, a direct click and Tab+Enter both connect, with exactly one verification callback. Selecting a new subscription still requires opening the tile. - Full-app before/after QA with a disposable empty backend and a simulated provider response: same result. - Not tested: a live OpenAI sign-in. Repo-wide `pnpm -r typecheck`, `pnpm test:run` and `pnpm build` are left to CI. Manual check: open New Agent with a saved subscription, go to the model step, and click "Use saved subscription" without clicking the tile. ## Risks - Low risk. The change is one condition in one component. - If a future change makes `connect()` depend on the tile being opened for saved subscriptions, this path would skip that work. The comment at the condition records why the gate is skipped. - Open PR #14698 edits nearby lines in the same component. A small merge conflict is possible. ## Model Used - Claude Opus 5.5 (`claude-opus-5-5`), Anthropic, via Claude Code with tool use (shell, file edit, browser automation). Extended reasoning on. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: scotttong <squadbot000@users.noreply.github.com> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
1815474597 |
fix: report pending execution phase at Stop timeout (#14990)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The server owns each adapter execution and waits for it to settle after Stop. > - A Stop timeout reports that termination remains unverified. > - Existing phase timings arrive only after their work completes, so a stalled await has no timing. > - This pull request samples the pending phase when the Stop timer expires. > - Operators can identify the pending operation without treating diagnostics as stop proof. ## Linked Issues or Issue Description **What existing behavior does this improve?** The opt-in Sentry context for an unconfirmed adapter Stop timeout. **Current behavior** The timeout includes execution identity but no pending phase. A session close, instruction collection, workspace restore, or diagnostic write can remain pending without producing its completion timing. **Proposed behavior** Add a closed-list phase and elapsed milliseconds from the exact live execution control. Sample them when the timeout fires. Report `unknown` and a null age when the control or attribution is unavailable. **Reason and benefit** The next timeout can identify which operation is still pending. It does not require task text, paths, provider output, or additional database writes. **Breaking changes** No API or execution behavior change. The existing opt-in error context gains two fields. Related public work: #14639 added Stop identity diagnostics; #14866 and #14945 cover instruction cleanup and teardown outcomes. This change adds pending attribution to those paths. The native Stop work in #14802 remains separate. ## What Changed - Add a bounded tracker per execution control. Token scopes support nested and overlapping awaits. A late release cannot clear a newer scope. - Track adapter execution, ACP cancellation and settlement, diagnostic writes, and host cleanup. Keep a coarse host scope until the executor finishes. - Sample only the matching current control and settlement promise at timeout. Freeze the sanitized result. Use a monotonic clock and cap elapsed time at one day. - Test stalled operations, repeated Stop calls, stale and wrong-run controls, callback failures, scope bounds, and the real Sentry SDK context. ## Verification - `pnpm -r typecheck` passed. - `pnpm build` passed. - Six focused suites passed: 79 tests. They cover pending scopes, Stop control ownership, real ACP settlement stalls, and Sentry context isolation. - The real Sentry SDK contract ran with the audited optional peer `@sentry/node@10.71.0` installed outside the workspace. Valid phase and elapsed values were exported; arbitrary labels and nonfinite elapsed values were rejected. - An independent agent reviewed the production diff and ran the focused tests without blockers. - `git diff --check` and a redacted Gitleaks scan passed. The local full `pnpm test:run` was stopped during its large serial server batch to avoid duplicating the sharded CI suite. No complete local broad-suite pass is claimed. - All CI gates passed on `c223237b58aa8d479d1c66d7d399de30270bac4f`: 54 successful checks and two expected Storybook skips. This includes the full sharded test suite, typecheck, build, real Sentry SDK isolation, browser tests, canary dry run, and the security scan after the PR became ready for review. - Greptile scored the same commit 5/5 with no actionable findings or unresolved review threads. ## Risks This is diagnostic instrumentation. Cancellation, deadlines, teardown order, termination proof, and file recovery proof remain unchanged. Unsupported or uninstrumented work uses a coarse phase. Tracker overflow fails closed to `unknown`. The tracker emits no new run-log or Telemetry event. The existing Sentry opt-in gate remains in place. ## Model Used OpenAI Codex, GPT-6. The agent used code inspection, local command execution, automated tests, and an independent agent review. The runtime did not expose a more specific model identifier or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1003.0-canary.0 |
||
|
|
4abff286c2 |
fix: retain resolved ACP execution timeout metadata (#14986)
## Thinking Path > - Paperclip manages agent work through adapters and heartbeat runs. > - ACP adapters resolve a timeout for the selected execution target. > - An untouched sandbox timeout uses a four-hour default. > - Heartbeat finalization rebuilt the metadata from the stored zero. > - This made a timed-out sandbox run report an effective timeout of zero. > - This change retains the adapter's resolved policy for accurate run diagnostics. ## Linked Issues or Issue Description **What happened?** ACP sandbox runs with `timeoutSec: 0` use the four-hour default. Their terminal metadata reports `effectiveTimeoutSec: 0` and `timeoutSource: config` because heartbeat finalization only reads the stored agent configuration. **Expected behavior** The result must report the policy the adapter used: `14400` and `sandbox_default`. Explicit limits, fractional limits, explicit unlimited overrides, and local defaults must keep their resolved values. **Steps to reproduce** Run an ACP adapter on a sandbox target with `timeoutSec: 0`. Compare the start log's four-hour policy with the terminal result's effective timeout. The new tests exercise the adapter result and the heartbeat metadata merge without waiting four hours. **Paperclip version or commit** Reproduced from `6eaf218924f0a89faf1c02eb0d6877a6c5c8a2cb`. **Deployment mode** Self-hosted server with an ACP sandbox execution target. Searched open timeout and metadata issues and PRs. Related #14804 exposes timeout configuration in forms; #14496 proposes a default policy; #14833 addresses CLI session retention. This PR changes only ACP result metadata. ## What Changed - Retain the resolved timeout in the ACP result after settlement. - Use validated adapter resolution when merging terminal timeout metadata. Preserve config fallbacks for older adapters and the HTTP millisecond policy. - Test sandbox defaults, explicit and fractional limits, explicit unlimited overrides, local defaults, malformed metadata, and unchanged cancellation fields. - Document the result fields and their meaning. ## Verification - `pnpm -r typecheck` passed. - `pnpm build` passed. - Stop metadata tests: 23 passed. - Reporter and diagnostic suites: 84 passed; two real-Sentry-SDK tests skipped because the optional SDK is not installed. - ACP engine suite: all 206 tests passed with a deterministic local `gemini --version` shim. Ambient host CLI probes made the existing Gemini session-resume fixture intermittent (one assertion failure in each of two broad runs); an isolated 15-case rerun and the clean-base 206-test suite also passed. No assertion or timeout was changed. - `pnpm test:run` is in progress. This PR does not claim a complete local suite pass. - Independent review found no blocking issues. The tests cover real adapter emission and the real metadata merge separately. ## Risks Low runtime risk: this changes result diagnostics. It does not change timeout values, cancellation acknowledgement, cleanup, checkpoint safety, retries, or provider operations. It does not fix the cause of a quiet or long-running tool. Older stored results are not rewritten. The new source values apply only when an adapter returns a valid resolution. ## Model Used OpenAI GPT-6 with reasoning, repository inspection, code editing, and test execution. The deployment-specific model ID and context-window size are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
862a5758ba |
fix(agents): reduce hiring templates to role descriptions (#14985)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - New agents receive role instructions from onboarding, the hiring skill, or a team package. > - These sources repeat harness procedures and impose generic work policies. > - They can crowd out the task and the harness instructions. > - This pull request reduces those sources to short role descriptions. > - It preserves configuration, skills, authentication, reporting lines, and approval controls. > - The benefit is less repeated instruction text with explicit coverage for the default hiring path. ## Linked Issues or Issue Description Refs #3307. The CEO template can impose a fixed delegation route instead of letting the agent choose how to fulfill the request. This change removes that route. It does not implement autonomous goal selection. Related work: #14920 preserves stock Codex base instructions. #14948 reduces the generic manual and shared runtime prompts. #14961 improves native completion-tool descriptions. This PR is separate from those changes. ## What Changed - Select only the short CEO `AGENTS.md` for new default CEO bundles. Keep the three former companion files as compatibility assets. - Reduce the first-agent chief-of-staff prompt and coder, QA, UX, and security role examples. - Reduce seven bundled team role bodies. Preserve their role, reporting, and skill metadata. Regenerate the catalog. - Make hiring examples optional. Replace the long generic role manual with short role drafting guidance. Preserve explicit requester instructions. - Add configuration and import coverage for native and legacy managed bundles, custom instructions, first-agent rendering, and catalog contents. - Add an explicit-only hiring eval that starts from the production CEO default and checks one coder hire, independently computed JSON output, saved instructions, and worker reuse. - Include the full prompt comparison and a separate three-request drafting simulation. Neither is a live provider comparison. Prompt differences: [before and after](doc/plans/2026-10-02-hiring-template-prompt-diff.md). The CEO default falls from 1,897 to 20 words. The coder example falls from 652 to 18 words. Word counts describe instruction size, not outcome quality or billing. ## Verification - PASS: 99 focused server tests and eight shipped-catalog tests. - PASS: catalog generation and validation for four shipped teams. - PASS: hiring skill validation. - PASS: `pnpm -r typecheck`. - PASS: `pnpm build`. - INCOMPLETE: the full local `pnpm test:run` was stopped before rebase. Its original log is retained. This is not a completed full-suite pass. The full current-head GitHub CI workflow passed: https://github.com/paperclipai/paperclip/actions/runs/37073372419. - PASS: `pnpm test:e2e:runner:typecheck` and `pnpm test:e2e:runner:unit` (63 files / 843 tests). - PASS: discovery for the two new hiring cells, 50 existing everyday cells, and the full 438-cell catalog. - PASS after rebase: 99 server tests, 11 catalog tests, 62 selected E2E support tests, and the E2E typecheck. - PASS: all current-head PR checks at `57dcee147ed0b2d2e3cc657cd9e50fb16bf9ec25`: 51 successful check runs, two intentional Storybook skips, and successful Snyk status. Fresh Greptile is 5/5 with zero unresolved threads. - PENDING follow-up: matched live hiring runs on frozen integration refs. No live outcome-quality or non-regression result is claimed from the configuration checks or this merge. The new suite has two local native cells: Codex and ACPX Claude. It expects five provider turns per cell. It compares source-derived bundles, so the historical long templates remain admissible. Missing successful source-read receipts make a pair uncomparable. They do not establish a behavior regression or equivalence. ## Risks - New default roles have fewer prescribed procedures. Live checks must determine whether a removed instruction was needed for an outcome. - Existing custom and saved bundles keep their contents. The retained companion assets avoid a source-file compatibility break. - Specialized Summarizer, Reflection Coach, and Wiki Maintainer prompts remain unchanged. Their product contracts need separate review. - The generic non-CEO fallback reduction is in #14948. This PR alone does not provide its eight-word fallback. - Configuration tests and drafting simulations do not establish live outcome quality. QA, UX, security, and chief-of-staff hiring behavior remain outside the new two-cell comparison. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, based on GPT-6, with reasoning, code editing, shell tools, and delegated verification. The runtime does not expose the exact deployment model ID or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-Authored-By: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.20 |
||
|
|
6eaf218924 |
chore: grant Storybook publishing access through CODEOWNERS (#14984)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Storybook previews help contributors review the board UI. > - The publishing workflow uses the default branch CODEOWNERS file to authorize users. > - Tonio and Scott need access to this workflow. > - This pull request adds both accounts as release documentation owners. > - The existing workflow can then authorize both accounts without a separate user list in code. ## Linked Issues or Issue Description **What existing behavior does this improve?** Access to the Storybook build and publishing workflow. **Subsystem affected** Repository ownership and GitHub Actions authorization. **Current behavior** The workflow reads individual accounts from every CODEOWNERS rule on the default branch. Neither `tonio-alucema` nor `scotttong` is in that file. Both accounts already have repository admin access, but the workflow authorization check denies them. **Proposed behavior** Add both accounts to the `doc/RELEASING.md` ownership rule. After merge, both can start and rerun Storybook publishing workflows. A configured `storybook-deploy` environment reviewer must still approve deployment. CODEOWNERS membership does not add an account to the environment reviewer settings. **Reason and benefit** Contributors can publish UI previews through the same CODEOWNERS policy as other maintainers. The authorization code has no account-specific exceptions. **Breaking changes** None. The existing authorization and deployment approval checks remain in place. **Additional context** Related changes: #13226 added the publishing workflow. #13231 added stable branch bookmarks. A search found no open PR for these permission changes. ## What Changed - Add `@tonio-alucema` and `@scotttong` only to the release documentation ownership rule. - Test that accounts listed for release documentation can start and rerun publishing workflows. - Test that removing an account from CODEOWNERS removes its publishing access. - Explain how CODEOWNERS entries and environment reviewers affect publishing access. ## Verification - `node --test scripts/__tests__/storybook-deploy.test.mjs`: all 25 tests pass. - `actionlint .github/workflows/storybook-deploy.yml .github/workflows/storybook-visual.yml`: passes. - `git diff --check`: passes. - GitHub API checks confirm that both accounts have repository admin access. The deployment environment requires an existing reviewer and disables administrator bypass. - Repository-wide typecheck, tests, and build were attempted. They cannot complete in this worktree because workspace dependencies are not installed. Typecheck cannot find Node type definitions. Tests and build cannot load the workspace `tsx` package. - After merge, run `Storybook Deploy` from `master`, select a source branch, obtain environment approval, and check the published URLs in the run summary. ## Risks Both accounts gain permission to start and rerun Storybook publishing. Deployment still needs approval from a configured environment reviewer. No AWS permissions or live GitHub settings change in this PR. ## Model Used OpenAI GPT-6 through Codex. The exact backend model ID and context window are not exposed in this session. The agent used reasoning, repository inspection, code editing, shell execution, and GitHub API tools. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.19 |
||
|
|
22cea6b2e6 |
fix: bound sandbox bridge waits and flag silent runs sooner (#14979)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Sandbox agents exchange input and output through bridge control commands. > - A provider can stop responding to a command even when it receives a timeout. > - These small commands can inherit a four-hour agent lifetime and block input or teardown. > - The board also calls a silent run healthy for the first hour. > - This pull request bounds bridge control waits and surfaces silence sooner. ## Linked Issues or Issue Description **What happened?** A sandbox run can remain active when a bridge control command never returns. The shared helper passes a timeout to the provider but does not enforce it on the host. It also accepts the agent's hours-long timeout. Output silence remains `ok` for an hour and becomes `critical` only after four hours. **Expected behavior** Bound short bridge operations even if the provider never settles. Report failed input delivery through the existing shutdown path. Warn after five silent minutes and escalate after fifteen. Keep normal agent command limits and require verified termination before releasing execution ownership. **Steps to reproduce** 1. Use a sandbox runner whose bridge read or input-upload promise never settles. 2. Set its configured timeout to four hours. 3. Observe that the old queue client never returns or rejects. 4. Inspect a running task with 35 minutes of output silence. The old summary still reports `ok`. **Paperclip version or commit** Base commit `d6d88b9de2`. **Deployment mode** Self-hosted server with sandbox execution. **Agent adapter(s) involved** Shared command-managed sandbox bridge, including Codex ACP sessions. The informational silence thresholds apply to active runs across adapters. Related: #14889 recovers stalled Daytona output streams; #14485 retries explicit gateway failures during input delivery. This change bounds short control operations whose provider promises never settle. It does not add tool replay or automatic cancellation for output silence. #6297 proposes configurable per-agent silence thresholds; this patch only changes the existing defaults. ## What Changed - Enforce at most 30 seconds per bridge control shell command on the host and provider, including callback startup and shutdown, process-session launch, and payload setup. Preserve shorter configured deadlines and launch environments. - Keep the long-lived agent command outside this deadline. Use a fixed timeout diagnostic without command payloads. - Surface suspicious output silence after five minutes and critical silence after fifteen minutes. - Decouple the shared-workspace holder cutoff from warning thresholds and preserve its existing one-hour value. - Add regressions for hung reads, a late upload response, failed input delivery, exact warning boundaries, and fresh output clearing warnings. - Update the adapter guide and execution contract. ## Verification - The three new queue-client regressions fail on the unchanged base and pass with this patch. - Final callback bridge and sandbox session suites: 214 passed. These cover hung reads, writes, startup, shutdown, process-session launch, payload setup, and the separate long-running agent limit. - Stdin ordering and shutdown suite: 56 passed after the lifecycle change. - Daytona and watchdog coverage passed in the earlier focused runs. Across the focused suites, 602 distinct tests pass. - `pnpm -r typecheck` and `pnpm build`: passed. Server and adapter typecheck/build also passed after their respective follow-up changes. - `pnpm test:run`: attempted and stopped after known local failures. Four chat/email cases used an external ancestor skill path, three skill-cache cases failed on macOS, and one wakeup case timed out. The wakeup case passes alone (1 passed, 27 skipped). This run spanned the workspace-cutoff follow-up and also failed its new holder case; a fresh final-head workspace suite passes all 19 tests. The interrupted run is not a full local-suite pass or final-head verification. - A filesystem queue-drain test failed once during the lifecycle rerun and passed on the complete two-suite rerun. It uses the filesystem client, outside the changed command-runner path. - Complete CI on `ff2212c235`: 53 successful checks and two expected skips, including the full test suite and canary packaging dry run. No failed or pending checks. - Greptile reviewed `ff2212c235` at 5/5. All review findings are addressed, no threads remain unresolved, and the branch has no merge conflicts with `master`. - `git diff --check` and a scan of added text for secrets and private identifiers passed. ## Risks - A bridge control operation that needs more than 30 seconds now fails, even if the caller selected a longer run lifetime. Agent commands retain their own limits. - Timing out a provider promise does not cancel the remote operation or prove it stopped. Existing execution settlement still owns termination verification. No uncertain tool action is replayed. - Quiet healthy runs display warnings sooner. Existing snooze, continue, and false-positive dismissal controls still apply. Silence alone does not cancel a run, create review work, or change assignments. - No schema or API shape change. ## Model Used OpenAI GPT-6 through Codex, with tool use and code execution. The exact serving model ID and context window are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run change-specific tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
d7bdfc422c |
fix(ui): show agent avatar and align chat header controls (#14726)
## Thinking Path > - Paperclip helps people manage AI agents and their work. > - Agent chat shows which agent receives each message. > - The chat header used initials instead of the agent avatar. > - The name and controls did not use the same center alignment. > - This change uses the shared avatar and centers the header content. > - Users can identify the agent and open its settings from the same row. ## Linked Issues or Issue Description **What happened?** The agent chat header showed initials instead of the agent avatar. The settings control did not align with the name and avatar. **Expected behavior** Show the agent avatar. Put the avatar, name, and settings control on the same horizontal center line. **Steps to reproduce** 1. Enable Agent Chat in Experimental settings. 2. Open a conversation with an agent that has an appearance set. 3. Check the avatar and settings control in the top bar. Related navigation work: #14706. ## What Changed - Use `AgentAvatar` in the conversation breadcrumb. - Update the breadcrumb key when the agent appearance changes. - Center breadcrumb labels that have an adjacent action. Keep task identifier baseline alignment unchanged. - Add regression checks for avatar props, appearance changes, and center alignment. ## Verification - PASS: affected Vitest suites, 129 tests. - PASS: `pnpm check:token-gates`. - PASS: `pnpm --filter @paperclipai/ui typecheck` on an isolated retry. - PASS: `pnpm --filter @paperclipai/ui build`. - PASS: browser checks at 1000 and 390 CSS pixels. Avatar, name, and settings control all have center Y = 29.5 CSS pixels. - Screenshots use the real header and avatar renderer with isolated context fixtures. No screenshot or fixture is part of this diff. - Full typecheck and build cannot complete because Cargo is not installed. - Full tests stopped with SIGKILL. The first UI typecheck also stopped with exit 137. These runs do not prove full-suite success. ## Risks - Low risk. The change only affects UI rendering. It changes no API or database contract. - Breadcrumbs with adjacent actions now use center alignment. Ordinary task identifiers keep baseline alignment. ## Model Used OpenAI Codex agent, with code editing, shell tools, and browser checks. The runtime did not expose the exact model ID or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [ ] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge No behavior or command documentation needs an update for this rendering fix. The execution environment requires the assigned branch name to stay unchanged. Pending review gates are not marked complete. Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
5b8b2b38ca |
feat(apps): add Neon connection (#14980)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents reach external services through the Apps catalog. Each catalog entry is a reviewed `AppDefinition` that wires a provider's hosted MCP server into Paperclip's shared vault, grants, policies, gateway, and audit trail. > - Neon is a widely used serverless Postgres provider with an official hosted MCP server, but it is not in the catalog. Teams that run their databases on Neon must use the generic "connect your own MCP server" path, which has no branding, no guidance, and no project or read-only controls. > - The connector playbook requires a catalog entry for a provider like this: the hosted server supports dynamic client registration and bearer API keys, and the common definition fields can express every option Paperclip can serialize. > - This pull request adds the Neon definition, its official artwork, the research and permission-review ledger rows, documentation, and deterministic tests, without any provider-specific runtime code. > - The benefit is a one-click, governed Neon connection with optional project pinning and read-only mode, and a documented path to live qualification. ## Linked Issues or Issue Description **Problem or motivation** Neon is a common Postgres host for the applications agents work on, but Paperclip's Apps catalog has no Neon entry. Operators who want agents to inspect schemas, run SQL, or manage branches must paste the MCP URL into the generic remote-MCP flow, which gives no branding, no provider guidance, no project boundary, and no read-only switch. **Proposed solution** Add a catalog-only Neon connection built from the connector playbook: browser sign-in through Neon's dynamic client registration with the reviewed `read` and `write` scopes, or a customer API key sent as an Authorization bearer header. Both methods expose Neon's documented `projectId` pin and `readonly` switch as optional Advanced fields. Every discovered tool stays governed by the normal per-action policies. **Alternatives considered** A plugin was not needed because no custom UI, tables, workers, or webhooks are involved. A separate read-only method was not added because the playbook treats read-only switches as advanced fields rather than methods. Neon's repeatable `category` query filter was left out because tenant fields serialize lists as one comma-joined value, so it cannot be sent correctly without new runtime code; per-action policies cover catalog narrowing instead. **Roadmap alignment** This extends the existing self-serve remote-MCP connection catalog and does not overlap planned core work. ## What Changed - Added the `neon` provider to `scripts/ingest-app-definitions.mjs` (category, API-key placement, methods, tenant fields, guidance, warnings) and regenerated `packages/shared/src/app-definitions/neon.json` plus the generated registry. - Added the Neon row to the self-serve MCP research ledger with `dcr_or_api_key` auth and risk tier S4. - Added permission reviews for `neon/mcp-oauth` (explicit scopes `read`, `write`, taken from Neon's live authorization-server metadata) and `neon/mcp-api-key` (provider key), with evidence links. - Added Neon's official tile icon (`ui/public/brands/apps/neon.png`, copied byte-for-byte from the icon linked by neon.com) and the brand manifest entry. - Added prosumer gallery copy for the Neon card. - Added `doc/connections/NEON.md` (service involvement, endpoints, administrator setup, capabilities and policy, manifest, brand provenance, validation hook) and linked it from the connections README and the permission audit. - Tests: Neon definition shape, store visibility and artwork, URL recognition, reviewed scopes with scope-widening rejection, URL projection of the project pin and read-only flag, invalid project ID rejection, the connect form's API-key gating, and the pinned catalog counts. ## Verification - `pnpm exec vitest run packages/shared/src/app-definitions.test.ts packages/shared/src/app-definitions-url.test.ts` — 34 passed. - `pnpm exec vitest run server/src/__tests__/tool-access-service.test.ts` — 367 passed. - `pnpm exec vitest run ui/src/pages/apps/AppsConnect.test.tsx ui/src/pages/apps/Browse.test.tsx ui/src/lib/app-brand-assets.test.ts ui/src/pages/apps/AppLogo.brand-assets.test.tsx` — all passed. - `node scripts/check-app-brand-assets.mjs` and `node --test scripts/app-brand-validation.test.mjs` — passed. - `pnpm --filter @paperclipai/shared typecheck`, `pnpm --filter @paperclipai/server typecheck`, `pnpm --filter @paperclipai/ui typecheck`, `pnpm check:token-gates` — clean. - Manual: in a local instance, open Apps → Browse, confirm the Neon card and icon, open `/apps/connect?source=neon`, confirm both methods, the Advanced project pin and read-only toggle, and that Connect enables after an API key is entered. The operator completed a live connection against a Neon account on this build. - Live metadata probed on 2026-10-02: both `.well-known` documents at `mcp.neon.tech` return the recorded endpoints and scopes; an unauthenticated `initialize` returns 401 with `resource_metadata`. ## Risks - Low risk to existing providers: the change is additive catalog data plus tests. The generated registry only gains one import. - Neon's hosted server grants broad project and database management. The definition carries two warnings, recommends a development project, and keeps every write under the normal action policies; the read-only switch is enforced by Neon's server, not locally. - The permission-review ledger records live proof for both methods as not run; the full lifecycle checklist in `doc/connections/NEON.md` still needs a documented pass before the entry is considered fully qualified. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - Claude Fable 5.1 (`claude-fable-5-1`) in Claude Code, with extended thinking and tool use (shell, file editing, browser verification). ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.18 |
||
|
|
d6d88b9de2 |
fix: preserve run outcomes when agent file cleanup is deferred (#14945)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The heartbeat service records each agent turn and releases its working files. > - A turn can save its work and finish before instruction-copy cleanup runs. > - A cleanup exception can replace that completed result with an adapter failure. > - This also loses result accounting and can prevent environment lease release. > - This pull request records a cleanup warning and keeps the original run outcome. > - The existing recovery sweep retries cleanup from the durable working-copy record. ## Linked Issues or Issue Description Related cleanup and lock work: #14866 and #14869. Related, distinct work: #14695 retains warm-process files; #12021 handles provider-process SIGTERM after a terminal result. **What happened?** An agent saved its plan, posted a comment, and requested approval. The provider completed its turn. Instruction-copy cleanup then timed out on a directory lock. Its exception escaped a `finally` block and replaced the provider result, so the completed turn showed `Run failed`. **Expected behavior** Keep the provider outcome, usage, cost, saved work, and pending approval. Record a cleanup warning and let the existing recovery sweep retry. A real provider failure must keep its original error. A failed file save must keep its failed-save receipt. **Steps to reproduce** 1. Complete a legacy adapter turn that saves work and requests approval. 2. Make instruction-copy release throw a directory-lock timeout. 3. Read the run result. Before this change, the cleanup error replaces the provider outcome. The new heartbeat tests reproduce the failure without a live provider or external service. **Paperclip version or commit** The regression reproduces on `c83df091b1a5207375eaf23466bb5c62e4e1518e`. This branch is rebased onto `cf8ad63c80`. **Deployment mode** Server-managed agent execution with persistent instruction working copies. ## What Changed - Catch instruction-copy release failures in both heartbeat teardown paths. Stop repeating a failed cleanup attempt within the same run. - Write a sanitized `instruction_cleanup` warning. A warning-write failure also preserves the run result. - Test successful, failed, and throwing providers; both teardown paths; warning-write failure; accounting; approval state; and execution-control release. - Extend the held-lock test to prove a fresh recovery worker removes the deferred copy and preserves its failed-save receipt. - Document deferred cleanup and the run-log event. ## Verification - Red proof: all five new heartbeat regression cases fail with the original release calls. - At head `20bea4f431c916d2f5db1970213aab85f5daa34c`, all 417 tests passed across heartbeat process recovery, agent directory working copies, and directory merge locks. - Full local `pnpm -r typecheck`, `pnpm build`, and `git diff --check` passed. - [GitHub CI](https://github.com/paperclipai/paperclip/actions/runs/37031119795) passed at this head. All 53 reported checks passed; the two Storybook checks were correctly skipped. This includes general and serialized tests, browser shards, runner verification, build, typecheck, and the canary dry run. - Greptile reviewed this head with 5/5, no code comments, and no unresolved review threads. The branch has no merge conflicts. - The local `pnpm test:run` attempt was stopped after it reported eight failures in unchanged suites. Four Slack/AgentMail cases selected an unrelated ancestor skills directory and failed with `ENOENT`; the two Slack cases passed with a temporary local skill-root link, which was then removed. Three company-skill cases reproduced macOS `EACCES` errors when renaming read-only cache directories. One gateway case passed when rerun alone. No full local-suite pass is claimed; the complete CI test jobs passed. ## Risks - Cleanup errors now leave recovery work pending. The durable working-copy record remains available for the existing retry sweep. - This change preserves provider failures and failed-save receipts. It does not claim that unsaved file edits were saved. - Native instruction reservation errors retain their existing behavior because they guard process ownership. - No schema, lockfile, workflow, API, or UI changes. ## Model Used OpenAI Codex, based on GPT-6, with reasoning, repository tools, and code execution. The exact backend model ID and context-window size are not exposed by this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.17 |
||
|
|
d9b64ee28e |
fix(codex-local): order Codex models the way the ChatGPT app does (stacked on #14917) (#14918)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Each agent runs on an adapter, and the operator picks the agent's model from the list the adapter advertises. > - The `codex_local` adapter advertises a static, curated list. The server returns that list as written, but the list itself is not in a useful order: the default `gpt-5.6-sol` sits above the whole GPT-6 family (#14878). > - This pull request orders the list the way the ChatGPT app orders Codex models: newest model version first, then by decreasing capability inside each version, with older models at the end. > - It is stacked on #14917, which makes the model dropdown show a hand-ordered list as the adapter advertises it. Without that change the picker shows every list alphabetically. > - The benefit is that a user who knows Codex finds the right model at once, and older models sit at the end of the list. ## Linked Issues or Issue Description Fixes #14878. Related: #14917 (the Claude counterpart, #14877) carries the dropdown change this PR relies on. This PR contains that commit until #14917 lands; after that it rebases to the Codex commit alone. ## What Changed - `packages/adapters/codex-local/src/index.ts`: reorder the advertised `models` list. GPT-6 (`astra`, `sol`, `luna`) first, then GPT-5.6 (`sol`, `terra`, `luna`), then `gpt-5.5`, `gpt-5.4`, `gpt-5.4-mini`, `gpt-5`, `gpt-5-mini`, `gpt-5-nano`, then the o-series and `codex-mini-latest` in their existing relative order. `DEFAULT_CODEX_LOCAL_MODEL` is unchanged. - `packages/adapters/codex-local/src/index.test.ts`: the metadata test now asserts the full order of the GPT entries. The ChatGPT app also lists GPT-6.1 Sol first. That model is not in Paperclip's list today. Adding a model needs reasoning-effort and fast-mode entries as well, so it is out of scope for an ordering fix. ## Verification Run from the repository root: ```sh pnpm exec vitest run packages/adapters/codex-local server/src/__tests__/adapter-models.test.ts pnpm --filter @paperclipai/adapter-codex-local typecheck ``` Red on `master`, green here: the updated metadata test fails against the unmodified list because `gpt-5.6-sol` comes first. Manual check: open an agent that uses `codex_local` and open the model dropdown. The list reads gpt-6-astra, gpt-6-sol, gpt-6-luna, gpt-5.6-sol, gpt-5.6-terra, gpt-5.6-luna, gpt-5.5, gpt-5.4, gpt-5.4-mini, gpt-5, gpt-5-mini, gpt-5-nano, o3, o4-mini, o3-mini, Codex Mini. ## Risks - Low risk. The list content and the default model do not change; only the order does. The server returns this list as-is for the built-in Codex adapter and the server test compares against the exported list, so no server change is needed. - The first entry is no longer the default model. Nothing reads the first entry as a default: `DEFAULT_CODEX_LOCAL_MODEL` is resolved separately. ## Model Used Anthropic Claude Fable 5.1 (`claude-fable-5-1`) through Claude Code, extended thinking on, with tool use for reading the repository, running vitest and tsc, and editing files. The account holder reviewed the change and owns the commit. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: abderbj <115119179+abderbj@users.noreply.github.com>canary/v2026.1002.0-canary.16 |
||
|
|
92ad158ce1 |
fix(claude-local): order Claude models the way the Claude app does (#14917)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Each agent runs on an adapter, and the operator picks the agent's model from a list the adapter advertises. > - The `claude_local` adapter advertises a static list and merges in the models the Anthropic API returns. Neither list has a deliberate order. > - The model dropdown then sorts every list by id. For Claude this shows "Fable 5", "Fable 5.1", "Haiku 4.5", "Mythos 5", "Opus 4.6" ... which is not the order of capability, release, or version (#14877). > - This pull request gives the adapter one defined order, the one the Claude app uses: the newest release of each family first, by decreasing capability, then older releases grouped by family. The server applies it to discovered models, and the dropdown keeps the adapter's order instead of re-sorting. > - The benefit is that a user who knows the Claude app finds the right model at once, and older models sit at the end of the list. ## Linked Issues or Issue Description Fixes #14877. Related: #14147 touches the same adapter's model list (the `ANTHROPIC_MODEL` default label) and does not change ordering. #14878 is the Codex counterpart and depends on the dropdown change in this PR. ## What Changed - `packages/adapters/claude-local/src/server/model-order.ts` (new): `sortClaudeModels()` and `parseClaudeModelId()`. The parser reads the current scheme (`claude-opus-4-8`), the legacy scheme (`claude-3-7-sonnet-20250219`), dated snapshots, `-latest` aliases, the `[1m]` suffix, and Bedrock ids (`us.anthropic.…-v1`, `…-v2:0`). The sort puts the newest release of each family first (Fable, Mythos, Opus, Sonnet, Haiku), then older releases grouped by family with versions descending. An alias sorts before its dated snapshots, and dated snapshots of one release sort newest first. Ids that are not Claude models keep their incoming order at the end. - `packages/adapters/claude-local/src/server/models.ts`: apply the order to the static fallback, to the merged API list, and to the Bedrock list. Reorder `BEDROCK_MODELS` to match. - `packages/adapters/claude-local/src/index.ts`: reorder the advertised `models` list to the same order. - `ui/src/components/AgentConfigForm.tsx`: `ModelDropdown` gets a `preserveOrder` prop. With it the dropdown shows the list as the adapter ordered it; without it the list is sorted by id as before. `ui/src/lib/model-utils.ts` adds `adapterCuratesModelOrder()`, true for the built-in adapters whose list arrives in a deliberate order (`claude_local`, `codex_local`, `paperclip_runner`, `gemini_local`, `grok_local`, `kimi_local`, `openclaw_gateway`, and `opencode_local` / `pi_local`, which the server sorts when discovered and which lead with the default model when it falls back to the declared list). Cursor is not in the set because its list comes from `agent models` discovery, and adapters not named there, including externally installed ones, keep the alphabetical fallback. The three dropdown call sites (`AgentConfigForm`, `ConfigureBuiltInAgentModal`, `NewAgentSetup`) pass it; `NewAgentSetup` decides by the resolved brand type, because a `paperclip_runner` agent fetches the Claude or Codex list for its brand. Grouped lists (`opencode_local`, `pi_local`) are unchanged. - Tests: `model-order.test.ts` (adapter, including the snapshot-date tie-breaker), `ModelDropdown.test.tsx` (ui: preserved order with the prop, alphabetical without it, provider groups unchanged), `model-utils.test.ts` (which adapters opt in), and two updated expectations plus one new order assertion in `server/src/__tests__/adapter-models.test.ts`. Mythos is not in the Claude app's list. This PR ranks it directly after Fable, in the top capability tier. The rank table in `model-order.ts` is one line to change if you prefer a different slot. ## Verification Run from the repository root: ```sh pnpm exec vitest run packages/adapters/claude-local server/src/__tests__/adapter-models.test.ts ui/src/lib/model-utils.test.ts ui/src/components/ModelDropdown.test.tsx ui/src/components/AgentConfigForm.render.test.tsx ui/src/components/ConfigureBuiltInAgentModal.test.tsx ui/src/pages/NewAgent.test.tsx pnpm --filter @paperclipai/adapter-claude-local typecheck pnpm --filter @paperclipai/ui typecheck pnpm --filter @paperclipai/server typecheck pnpm check:module-boundaries && pnpm check:token-gates && pnpm check:tokens ``` Red on `master`, green here: - `ModelDropdown.test.tsx` fails against the unmodified dropdown because the ids come back sorted alphabetically even with `preserveOrder`. - `adapter-models.test.ts` fails against the unmodified adapter because the first model is `claude-opus-4-8`, not `claude-fable-5-1`. Manual check: open an agent that uses `claude_local`, open the model dropdown. With no `ANTHROPIC_API_KEY` the list reads Fable 5.1, Mythos 5, Opus 5.5, Sonnet 5, Haiku 4.5, Fable 5, Opus 5, Opus 4.8, Opus 4.7, Opus 4.6, Sonnet 4.6, Sonnet 4.5. With a key, the discovered models slot into the same order. ## Risks - The other built-in adapters in the set (Gemini with `Auto` first, Grok, Kimi, OpenClaw, the runner's Codex list, and the OpenCode and Pi lists in the built-in-agent modal) are now shown as their adapter delivers them instead of alphabetized. Cursor's discovered list and every adapter outside the set, including externally installed ones, keep the alphabetical order they had, so no option moves between refreshes. Grouped lists are unchanged. - The first entry of the Claude list changes from Opus 4.8 to Fable 5.1. Nothing reads the first entry as a default: `DEFAULT_CLAUDE_LOCAL_MODEL` is `claude-opus-5` and is resolved separately. - No API, schema, or migration change. ## Model Used Anthropic Claude Fable 5.1 (`claude-fable-5-1`) through Claude Code, extended thinking on, with tool use for reading the repository, running vitest and tsc, and editing files. The account holder reviewed the change and owns the commit. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: abderbj <115119179+abderbj@users.noreply.github.com>canary/v2026.1002.0-canary.15 |
||
|
|
2ec82c5774 |
fix(runner): preserve task context when tool connections change (#14963)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents use tools through company-scoped connections and provider sessions. > - Resolving a tool connection currently forces a fresh session even when the provider can load new tools into the existing conversation. > - A fresh provider conversation can receive too little history to continue the task. > - This pull request adds explicit tool-refresh capabilities and uses them in both runner paths. > - Fresh attempts receive bounded task history with source IDs and retrieval instructions. > - The benefit is that agents can continue the same task after a connection changes. ## Linked Issues or Issue Description **What happened?** A resolved tool connection forced a fresh provider conversation. The new conversation could lose the original goal and prior answers. Claude also rejected resume when only the MCP server set changed. **Expected behavior** Resume the provider conversation when its harness can refresh tools. When a fresh session is required, supply enough bounded history to continue the task. Preserve company, agent, task, workspace, model, instruction, and skill checks. **Steps to reproduce** 1. Start a conversation and agree on a task and its constraints. 2. Request and connect a tool needed for the task. 3. Continue the conversation after the connection resolves. 4. Check that the agent remembers the task and can use the new tool. **Paperclip version or commit** The bug was reproduced on master at `c46e41e81`. This branch is rebased on current master. **Deployment mode** Self-hosted server. Both legacy adapters and the native runner are affected. Related public work: Refs #13282 for task-backed conversations. Refs #13057 for the broader session-compaction proposal. Refs #14659 for another report about local CLI session continuity. This change fixes tool-connection continuation. Provider authentication repairs keep their existing recovery behavior. ## What Changed - Expose tool-refresh support in native harness descriptors and legacy adapter metadata. - Request tool refresh after connection resolution. Keep provider authentication repair as a fresh-session wake. - Reload current tools and credentials while retaining supported Claude, Codex, Grok, and other provider conversations. - Allow MCP-only changes during qualified native recovery. Keep all other compatibility checks. - Refresh managed-provider and ACPX tool bindings when attaching a new run. - Add a fresh-session handoff for both runner paths. Bound database reads, excerpts, and the final packet to 24,000 bytes. - Include the original request, recent messages, decisions, plans, prior answers, and source IDs. Mark omitted content. Apply reset boundaries, wake cutoffs, quarantine, and secret redaction. - Add regression tests and document the capabilities and handoff behavior. ## Verification - `pnpm -r typecheck` and `pnpm build` passed. Rust formatting passed. - Final review fixes passed 314 server tests, 333 adapter utility tests, 139 native-session runtime tests, and 12 managed-provider Rust tests. They verify historical quarantine, raised budgets across attachment, no history reads on successful resume, and handoff delivery on fresh retry. - Broader branch verification also passed 1,401 adapter utility tests, 1,047 runner TypeScript tests, 43 Grok adapter tests, and 311 Rust core tests. - Live Claude CLI and Grok ACP probes preserved the provider session ID, recalled a prior task constraint, and called a newly added read-only MCP tool. - GitHub CI passed on `b21486d18084a7aa4cafbe8e012f7cad6585d9cc`: 55 successful checks and 4 skipped checks. This includes all test shards, all eight browser shards, runner checks, and the Grok clean public npm install canary. [CI run](https://github.com/paperclipai/paperclip/actions/runs/37057514976). - A full local test attempt encountered a separate Git snapshot timeout. All affected local suites passed after the final edits, and the full CI test gates passed. - Review the capability matrix in `packages/paperclip-runner/README.md`. Repeat the four reproduction steps with a supported provider and with an unsupported harness. ## Risks - Provider tool refresh can fail. Existing recovery falls back to a fresh conversation where policy permits it. - A new transport can replace an old process while preserving the provider conversation. Tests cover current credentials and unchanged identity. - Long history can omit older context. Explicit markers and source IDs let the agent retrieve needed context within task scope. - Unknown and unqualified harnesses use the fresh-session path. No database migration is required. ## Model Used OpenAI Codex, GPT-6, with reasoning, tool use, code execution, and live provider testing. The exact model ID and context-window size are not exposed in this session. Claude and Grok also ran as test subjects. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
43f391e807 |
refactor(slack): clarify browser setup prompt from live testing (#14965)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Slack chat connections let people start and continue agent work from Slack. > - The setup prompt guides an agent through the Paperclip and Slack browser interfaces. > - A live setup completed, but several instructions did not match the current interfaces. > - Those gaps can send users to the wrong connection flow or leave them waiting for controls that do not appear. > - This pull request updates the prompt with the steps observed during the live setup. > - The benefit is a clearer path from a fresh instance to a verified Slack conversation. ## Linked Issues or Issue Description Refs: #13920 and #14862. The first added the Slack conversation flow. The second updated the shared setup prompt control. A search found no duplicate open PR or matching public issue. **Issue type** Outdated instructions and missing setup guidance. **Where is the issue?** `ui/src/pages/apps/chat/SlackSetupPrompt.tsx` **What's wrong?** The prompt omits the Chat connectors setting on fresh instances. It uses an old navigation label. It assumes an avatar crop dialog and a Save button always appear. It also assumes the suggested bot username matches Slack and that the Slack reply contains a task link. **Suggested fix** Use the current labels. Explain the feature prerequisite, avatar save behavior, real mention selection, clipboard recovery, and the path to task and run evidence. ## What Changed - Add the Chat connectors prerequisite and current Connectors, resume, and identity-link labels. - Explain Slack's combined Create and Install action and how to continue from its success page. - Handle avatar uploads that save immediately. Require a reload to confirm the saved icon. - Select the real bot from Slack's mention suggestions, including names with punctuation. - Recover from an empty or stale clipboard without exposing credentials. - Find the linked task through Conversations and inspect the agent's Runs page. ## Verification - `pnpm exec vitest run ui/src/pages/apps/chat/SlackSetupPrompt.test.tsx`: 10 tests passed after rebasing onto current master. - `git diff --check origin/master...HEAD`: passed. - `pnpm build`: passed. - `pnpm -r typecheck`: passed. - `pnpm check:token-gates`: passed. - Full Vitest suite: passed in CI for this commit, including all server, chat, workspace, and serialized test shards. The duplicate local `pnpm test:run` was stopped after CI finished; it did not complete locally. - Current-commit CI: all checks passed, including build, typecheck, E2E, Runner verification, and canary dry run. Greptile rated the change 5/5 with no findings or unresolved review threads. - Live browser test before the wording update: created and installed a new Slack app, verified the callback, uploaded and reopened the avatar, linked the configuring user's identity, and enabled the selected test channel. The first mention received a reply. A follow-up without another mention recalled the first message. Both agent runs succeeded. - The wording update does not repeat Slack app installation. Existing tests verify the complete copied prompt, clipboard fallback, and instance URL handling. - This is a prompt-text refactor. No runtime behavior changes, so the existing tests cover the copied result without a new test that repeats the wording. ## Risks - Low risk. This change updates prompt text in one file. - Provider interfaces can change. The prompt tells the agent to inspect the current page and handle optional controls. - The prompt handles the observed mention mismatch. This change does not alter the generated suggested username. ## Model Used - OpenAI Codex, based on GPT-6, with reasoning, repository tools, code execution, and browser automation. The session does not expose an exact runtime model ID or context window size. The live test also used an earlier model whose exact ID was not exposed. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
144083fd48 |
fix(interactions): wait for workspace readiness before enabling approval (#14893)
## Thinking Path > - Paperclip lets people manage AI agents and review their work. > - Task confirmations must use the work produced by their source run. > - The server blocks approval while that run still needs to sync its workspace. > - The card currently enables approval before that check can pass, so an ordinary click produces an error. > - This PR exposes the existing readiness check and shows “Preparing approval…” with acceptance disabled. > - The card refreshes itself and enables approval when the source workspace settles. ## Linked Issues or Issue Description **What happened?** A confirmation appears while its source run is still preparing or syncing its workspace. Its enabled approval button returns a conflict asking the user to retry after syncing. **Steps to reproduce** 1. Run an agent in an isolated workspace. 2. Have it create a confirmation before workspace finalization completes. 3. Click the approval button while the source workspace is still active. **Expected behavior** The card explains that approval is preparing. Acceptance becomes available automatically when the same server check permits it. Reject and revise remain available. Related work: #10770 handles this conflict after a click with retries. #9520 proposes changing the workspace acceptance barrier. This PR preserves that barrier and exposes readiness before the click, including in compact task chat. It preserves the terminal-finalize behavior from #10099. ## What Changed - Add an optional, read-only `acceptanceBlocker` to interaction responses. Readiness uses the existing source-run workspace predicate, with one check per pending source run. - Disable acceptance and show a shared preparation notice in classic and compact confirmation cards, including checkbox and secret-binding confirmations. - Refresh preparing cards every two seconds in task detail, attention, pipelines, and Skill Studio. Restore each surface's previous polling cadence when preparation clears. - Preserve live tool reviews, questions, rejection, revision, and the server acceptance barrier. No automatic acceptance occurs. - Document the preparation state and cover readiness, terminal sync outcomes, unrelated runs, historical cards, and automatic refresh. ## Verification - Focused service, card, query-refresh, and helper tests: 217 passed across five files. - `pnpm -r typecheck`: passed. - `pnpm build`: passed. - `pnpm build-storybook`: passed. - `pnpm check:token-gates`: passed. - `pnpm test:run`: incomplete locally. Stopped after about 17 minutes once it reproduced seven existing environment failures: two Slack tests and two email tests lack ancestor-directory skill fixtures; three company-skills tests fail on macOS runtime-cache staging permissions. These are outside this change. The full CI test matrix passed. - CI: all 53 checks passed; two optional Storybook jobs were skipped. The branch has no conflicts with `master`. - Greptile: 5/5 on commit `8a6f216d8d`, with no review threads. - Reviewed added lines and new files for credentials, private URLs, internal task references, user paths, and run artifacts. None found. ## Risks - No database migration or change to acceptance authorization. Readiness is advisory; the server still enforces its existing gate at acceptance. - An open preparing card adds a read every two seconds. This cadence stops after readiness clears; historical cards add no workspace checks. - Failed or stale finalization retains the existing server behavior. This PR does not change recovery policy. ## Model Used OpenAI GPT-6 through Codex. The exact serving model ID and context-window size are not exposed in this session. Used reasoning, repository inspection, tool execution, and automated tests. No sub-agents. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (217 focused tests; full local-suite limitations are recorded above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
806af230b6 |
docs(release): curate stable notes for the 2026.1002.0-beta.0 promotion (#14928)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The release pipeline publishes a beta, waits three days, and then promotes it to stable. > - The stable promotion reads `releases/beta/v<beta-version>.md` from `master` and publishes it as the GitHub Release body. > - Beta `2026.1002.0-beta.0` (source `467125fa`, 179 commits after v2026.1001.0) is published and its soak has started. The planned stable is around 2026-10-05. > - The beta publish job pushed an auto-generated scaffold. The scaffold lists raw commit subjects and PR bodies. It is not in release-notes voice. > - This pull request replaces the scaffold with curated stable notes. > - The benefit is that the stable release ships with readable notes that tell self-hosters what changed and what they must do. ## Linked Issues or Issue Description **Issue type** Docs: release notes. **Where is the issue?** `releases/beta/v2026.1002.0-beta.0.md` on branch `release-notes/v2026.1002.0-beta.0`. **What's wrong?** The file is the auto-generated scaffold from the beta publish job. It lists 170+ raw entries with no grouping, no breaking-changes section, and no upgrade guide. **Suggested fix** Rewrite the file in the standard release-notes structure. The notes are planned as `v2026.1005.0`. **If the promotion date moves past 2026-10-05, change the title and the Released date before you dispatch stable.** ## What Changed - Rewrote `releases/beta/v2026.1002.0-beta.0.md` into the standard structure: overview, Breaking Changes, Highlights, Fixes, Improvements, Upgrade Guide, and Contributors. - Breaking Changes: operator UI snippet settings removed ([#13789](https://github.com/paperclipai/paperclip/pull/13789)); keyboard-shortcut settings and `/api/auth/preferences` removed ([#14141](https://github.com/paperclipai/paperclip/pull/14141), [#14643](https://github.com/paperclipai/paperclip/pull/14643)); agent @-mentions no longer start a run ([#14577](https://github.com/paperclipai/paperclip/pull/14577)). - Highlights: Grok Build on the native runner, persistent agent files, skills synced from GitHub, Browser Use Cloud, one-screen connector setup, two-way Slack, Agent Chat navigation and handoffs, per-message model and effort picker, governed API tools on by default. - Upgrade Guide: migrations `0284`–`0293` with one-phrase descriptions, new default for `PAPERCLIP_RUNNER_API_TOOLS_ENABLED`, and the new optional variables `PAPERCLIP_RUNNER_API_COMPANY_CAPTURE_MAX_BYTES`, `PAPERCLIP_WORKSPACE_GIT_SNAPSHOT_TIMEOUT_MS`, and `PAPERCLIP_WORKSPACE_MANIFEST_MIN_FREE_BYTES` with their defaults. - Removed release-infra noise: CI-only PRs, eval and test-only PRs, lockfile refreshes, release-notes bookkeeping commits, and cloud-control-plane-only changes. ## Verification - Docs only. Each PR number and commit SHA in the notes is in `git log v2026.1001.0..467125fafb47a8520856504fecc48d6e32055db1`. - Migration range `0284`–`0293` checked against the `packages/db/src/migrations` diff for that range. - Environment variable defaults checked in the code, not in commit subjects. - Contributor count and external handles computed from `git shortlog` over the same range. ## Risks Low. Documentation only. The stable preflight only requires that the file exists on `master`. The content can change during the soak. ## Model Used Anthropic Claude Fable 5.1 (`claude-fable-5-1`) via Claude Code, with tool use and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (docs only; no tests apply) - [x] I have added or updated tests where applicable (none apply) - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green (pending on this fresh PR) - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups (pending) - [x] I will address all Greptile and reviewer comments before requesting merge 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: devinfoley <139239+devinfoley@users.noreply.github.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>canary/v2026.1002.0-canary.14 |
||
|
|
0a2385eb31 |
build(deps): bump dompurify from 3.4.14 to 3.4.16 (#14783)
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.14 to 3.4.16. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/cure53/DOMPurify/releases">dompurify's releases</a>.</em></p> <blockquote> <h2>DOMPurify 3.4.16</h2> <ul> <li>Fixed a problem with <code>IN_PLACE</code> node removal when working with hooks, thanks <a href="https://github.com/manus-pi"><code>@manus-pi</code></a></li> <li>Fixed a problem with <code>IN_PLACE</code> sanitization and raw-text roots, thanks <a href="https://github.com/h-t-m"><code>@h-t-m</code></a></li> <li>Fixed a problem with ESM default exports landing in CommonJS declarations, thanks <a href="https://github.com/ssi02014"><code>@ssi02014</code></a></li> <li>Migrated from <code>rollup</code> to <code>rolldown</code> because performance, thanks <a href="https://github.com/ssi02014"><code>@ssi02014</code></a></li> <li>Bumped several dependencies where possible</li> </ul> <h2>DOMPurify 3.4.15</h2> <ul> <li>Added better clobbering hardening when XML content is involved, thanks <a href="https://github.com/gnyselcuk"><code>@gnyselcuk</code></a></li> <li>Added several smaller hardening and edge-case improvements, thanks <a href="https://github.com/leechristensen"><code>@leechristensen</code></a></li> <li>Bumped several dependencies where possible</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/cure53/DOMPurify/commit/b9b9d80f7e401771c2ccaef5f45def7eec8f27d7"><code>b9b9d80</code></a> release: 3.4.16 (<a href="https://redirect.github.com/cure53/DOMPurify/issues/1636">#1636</a>)</li> <li><a href="https://github.com/cure53/DOMPurify/commit/1d7460c4f8a27be825c11b1c9d346d79db32c1e5"><code>1d7460c</code></a> release: 3.4.15 (<a href="https://redirect.github.com/cure53/DOMPurify/issues/1609">#1609</a>)</li> <li>See full diff in <a href="https://github.com/cure53/DOMPurify/compare/3.4.14...3.4.16">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/paperclipai/paperclip/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d034ba7491 |
fix(interactions): derive question storage from canonical forms (#14946)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents request human input through durable issue interactions. > - A question form has a canonical presentation and a compatibility storage format. > - The creation API required agents to write both formats. > - Tool guidance told agents to split text and choice questions across those formats. > - This pull request accepts one complete canonical form and derives storage fields on the server. > - The benefit is a complete question card with stable answer and retry behavior. ## Linked Issues or Issue Description Related work: Refs #13630 and #14430. PR #13630 addresses the display of historical partial forms. This change fixes creation and keeps the check that rejects conflicting new forms. **What happened?** A question save supplied three compatibility questions and one canonical text question. The API correctly rejected the incomplete canonical form. The Runner's tool description encouraged this split. Sending only a complete canonical form also failed because the API required compatibility questions. **Expected behavior** An agent sends one complete `payload.questionSet` with every text and choice question. Paperclip derives `payload.questions` for storage and answer compatibility. Existing legacy requests remain valid. Explicitly conflicting dual forms remain invalid. **Steps to reproduce** 1. Call `paperclip_request_human_input` with `interactionKind: "questions"`. 2. Send `payload: { version: 1, questionSet: ... }` with a required text question and a required choice question. 3. The old API rejects the missing compatibility questions. With this change, it stores both questions and preserves the canonical form. 4. Retry with the same idempotency key. Confirm that only one interaction exists. 5. Submit both answers. Confirm that the normal resolver and continuation rules apply. **Paperclip version or commit** The branch is based on `cf8ad63c8`. The problem affects the native Runner and the interaction creation API. **Deployment mode** Server deployment with the native Paperclip Runner. Integration tests use the real interaction service and an embedded test database. ## What Changed - Add one shared canonical-to-storage projection. Reuse it for native harness question requests. - Accept canonical-only question creation at the shared validator and server boundary. - Export the input type and update the plugin SDK and its RPC contract. - Advertise a typed, complete question form in the live and scenario tool schemas. - Enforce canonical text and custom-answer constraints before ordinary or native resolution. Preserve harmless display whitespace. - Run regex matching in isolated workers with a deadline and resource limits. Both answer paths await the result before persistence. Saved native delivery uses the validated answer without taking another worker slot. - Update agent guidance and generated Runner contracts. - Test mixed forms, option-ID collisions, retries, answers, legacy requests, and conflicting forms. ## Verification - Interaction service, HTTP route, native bridge, and Runner authority suites: 221 tests passed after correcting an obsolete tool-description assertion. - Shared validator, plugin SDK, CLI, and UI compatibility suites: 67 tests passed. - Runner core tool-contract suite: 20 tests passed. AJV validates live and scenario schemas. - Final review regressions: 172 shared, service, native bridge, and authority tests passed. These cover text length, pattern, numeric limits, whitespace, custom option IDs, and historical pending cards. - Runner session suites: 67 tests passed. Published example tests: 4 tests passed. - Server typecheck and the shared/server builds passed after the compatibility fixes. - Final delivery verification: 35 response-delivery tests passed. The native delivery regression proves saved answers do not enter pattern workers; server typecheck and build passed. - Pattern security and answer-flow verification: 205 tests passed after repairing the child fixture loader. These cover pathological matching, event-loop responsiveness, worker concurrency, slot cleanup, HTTP routes, native delivery, and the full helper in a child process. - `pnpm -r typecheck` passed on the bounded-worker revision. - `pnpm build` passed on the bounded-worker revision. - All 55 GitHub checks passed on `fe457af`; four optional jobs were skipped. An unchanged Cursor adapter test timed out once in CI, passed locally, and passed on one failed-job rerun. - Reviewers can send the canonical-only mixed form above and verify that the saved interaction contains both canonical and compatibility questions. ## Risks - The creation API accepts a new input shape. Stored rows and answer contracts keep the existing shape. - The shared projection must preserve synthetic free-text option IDs. Collision and native round-trip tests cover this behavior. - Historical partial rows remain readable. New conflicting dual forms, including written-answer mismatches, remain rejected. - Existing pending cards retain the written-answer paths offered by their stored options. Canonical text constraints still apply. - Ordinary answers now enforce declared canonical constraints before persistence. Invalid answers leave the card pending. - Regex validation has a one-second deadline and a four-worker capacity limit. A complex pattern or capacity error leaves the card pending with a validation error. - No database migration or change to company authorization is required. ## Model Used - OpenAI GPT-6 through Codex. The session exposes the GPT-6 model family; its exact runtime model identifier and context window size are not exposed. Used reasoning, tool use, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
8fd3cf74ea |
build(deps): bump @grpc/grpc-js from 1.14.4 to 1.14.5 (#14786)
Bumps [@grpc/grpc-js](https://github.com/grpc/grpc-node) from 1.14.4 to 1.14.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/grpc/grpc-node/releases">@grpc/grpc-js's releases</a>.</em></p> <blockquote> <h2><code>@grpc/grpc-js</code> 1.14.5</h2> <ul> <li>Fix a bug that caused clients to automatically transmit excessive error details to clients by default (<a href="https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4">advisory GHSA-f596-whhp-79r4</a>)</li> <li>Fix a bug that caused <code>getAuthContext</code> to return unverified certificates as though they were verified in some configurations (<a href="https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j">advisory GHSA-m9gg-hp2v-232j</a>)</li> <li>Fix a bug that could cause stale call data to accumulate if a channel failed to connect for a long period of time (<a href="https://redirect.github.com/grpc/grpc-node/issues/3078">#3078</a>)</li> <li>Fix a bug that could cause call status to be reported with expected fields missing (<a href="https://redirect.github.com/grpc/grpc-node/issues/3079">#3079</a>)</li> <li>Avoid redundant end() calls on completed HTTP/2 streams (<a href="https://redirect.github.com/grpc/grpc-node/issues/3082">#3082</a> contributed by <a href="https://github.com/olavloite"><code>@olavloite</code></a>)</li> <li>Unify call numbers and avoid disabled trace allocations (<a href="https://redirect.github.com/grpc/grpc-node/issues/3084">#3084</a> contributed by <a href="https://github.com/olavloite"><code>@olavloite</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/grpc/grpc-node/commit/56567d9604b4e45cdca0d2e3c2a60ac227ee659d"><code>56567d9</code></a> Merge pull request <a href="https://redirect.github.com/grpc/grpc-node/issues/3086">#3086</a> from murgatroid99/grpc-js_1.14.5</li> <li><a href="https://github.com/grpc/grpc-node/commit/748ae86f7bb8af4a8d917d6fcf01c7a4c070f0a4"><code>748ae86</code></a> Merge pull request <a href="https://redirect.github.com/grpc/grpc-node/issues/3088">#3088</a> from murgatroid99/grpc-js_perf_improvement_backport</li> <li><a href="https://github.com/grpc/grpc-node/commit/526702d8ed335a99960878aea19cf6748f6d2314"><code>526702d</code></a> test(grpc-js): fix type errors in client stream lifecycle tests</li> <li><a href="https://github.com/grpc/grpc-node/commit/26a8d3d7d919098ded374b1c246d113161d69eb1"><code>26a8d3d</code></a> fix(grpc-js): avoid redundant end() calls on completed HTTP/2 streams</li> <li><a href="https://github.com/grpc/grpc-node/commit/152eebdcd5bbb1548b7779d14e0f5046784c21c1"><code>152eebd</code></a> chore(grpc-js): unify call numbers and avoid disabled trace allocations</li> <li><a href="https://github.com/grpc/grpc-node/commit/c5ae75026d7f07d24ab1bbd76cb84d78ab3a4a8d"><code>c5ae750</code></a> grpc-js(-xds): Increment version numbers (1.14.x)</li> <li><a href="https://github.com/grpc/grpc-node/commit/735a09a4f967400667fbbeda54584437e1bcf721"><code>735a09a</code></a> Merge commit from fork</li> <li><a href="https://github.com/grpc/grpc-node/commit/af9b1401fbf72d7cbe8b569c8df45cb4d4905e24"><code>af9b140</code></a> Merge commit from fork</li> <li><a href="https://github.com/grpc/grpc-node/commit/45ac33e74312ccd34cd7015147b36ef21b12b6c3"><code>45ac33e</code></a> Merge commit from fork</li> <li><a href="https://github.com/grpc/grpc-node/commit/9df49e3ca3ea20f8626f62339d703d7284ed13e9"><code>9df49e3</code></a> Merge pull request <a href="https://redirect.github.com/grpc/grpc-node/issues/3081">#3081</a> from murgatroid99/grpc-js-xds_weighted_target_fix_ba...</li> <li>Additional commits viewable in <a href="https://github.com/grpc/grpc-node/compare/@grpc/grpc-js@1.14.4...@grpc/grpc-js@1.14.5">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9786f6df56 |
fix(runner): preserve credential content in document saves (#14937)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Runner sends authorized tool calls to the control plane. > - Agents use these calls to save plans and instruction files. > - The Runner used diagnostic secret detection to reject execution arguments. > - Ordinary credential-related prose could reject a document save before persistence. > - This pull request forwards the original arguments and leaves credential policy to the provider harness. > - The benefit is reliable saves with useful diagnostic records. ## Linked Issues or Issue Description Related foundation: Refs #12415 and #14430. No duplicate save-policy fix was found. **What happened?** A `write_document` call failed before the server saved its plan. The Runner reported `semantic tool input contains credential material; refusing to execute altered arguments`. The detector also masked ordinary phrases such as `secret manager` and `credential handling` in diagnostics. Both TypeScript dispatchers had equivalent execution gates. One dispatcher also rewrote structured approval and question payloads before execution. **Expected behavior** Paperclip forwards authorized arguments unchanged. The provider harness decides credential-content policy. Log and audit redaction does not reject or rewrite save input. **Steps to reproduce** 1. Send an authorized `write_document` call with a plan that discusses credential handling. 2. Include an intentional credential value in the body to exercise harness-owned policy. 3. The old Runner rejects the call. With this change, the document service stores the exact body. 4. Diagnostic records still mask explicit credential values. Qualified credential fields, short bearer values, opaque diagnostic pairs, and valid encoded JSON token headers have regression coverage. **Paperclip version or commit** Reproduced at `c46e41e81c03cd3c8b64cf993615b604d7fe8c62`. The branch is based on current `master`. **Deployment mode** Server deployment with the native Paperclip Runner. Local regression tests use the real document service and an embedded test database. ## What Changed - Remove credential-content vetoes from Rust admission and both TypeScript semantic dispatchers. - Preserve original structured approval and question arguments during execution. - Keep transport bounds, schema checks, authorization, idempotency, and audit masking. - Require explicit credential syntax or recognized formats for diagnostic masking. Preserve ordinary prose, metadata, and dotted identifiers. - Test exact document persistence, replay, nested argument identities, and masked audit copies. - Remove obsolete retry guidance and document harness-owned credential policy. ## Verification - `cargo test --manifest-path packages/paperclip-runner/runner/Cargo.toml --locked -p paperclip-runner-core --lib --test acpx_event_payload --test acpx_provider_state --test acpx_provider_turns`: 355 tests passed. - Focused server and adapter tests: 189 tests passed after rebase. These include the real document save and the complete tool-gateway suite. - Semantic dispatcher and conformance tests: 34 tests passed. - Diagnostic redaction and MCP tests: 46 tests passed, including all six review examples. - `pnpm -r typecheck` and `pnpm build` passed on the repaired branch. - The broad local root suite was interrupted after database fixture setup failures. The focused database suites passed. CI runs the complete configured test lanes. ## Risks - Authorized tool arguments can intentionally contain credentials. The harness must enforce its content policy. - Diagnostic detection is narrower. Explicit assignments, credential fields, and recognized credential formats remain masked. - The change does not add a database migration or change company authorization. ## Model Used - OpenAI GPT-6 through Codex. The session exposes the GPT-6 model family; its exact runtime model identifier and context window size are not exposed. Used reasoning, tool use, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
839cac1343 |
fix: request supported offline access for generic MCP OAuth (#14950)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents use external MCP tools through the governed gateway. > - Remote MCP connections can use OAuth access tokens that expire. > - Some providers issue refresh tokens only after an offline-access request and consent. > - Resource scopes hid that identity-provider capability in the generic connection flow. > - This pull request requests supported offline access and tests expiry through a local MCP server. > - The benefit is continued tool access without another sign-in when the provider permits refresh. ## Linked Issues or Issue Description Related PR: #13447 addresses the same OAuth symptom together with managed Codex configuration. This PR focuses on generic MCP OAuth. It also covers consent, explicit scope overrides, legacy reconnects, exact scope persistence, and real HTTP expiry tests. **What happened?** A generic MCP resource can advertise only its tool scopes. Its OAuth server can separately advertise `offline_access`. Paperclip selected the resource scopes and omitted the offline-access request. A provider could then issue an access token without a refresh token. Tool access stopped after the access token expired. **Expected behavior** Paperclip adds advertised offline access to the selected tool scopes when the OAuth server does not exclude refresh tokens. It requests consent and stores the scopes sent in the authorization request. Existing connections can discover this capability when the user reconnects. Providers without this capability keep their existing scope behavior. **Steps to reproduce** 1. Run `node scripts/mcp-fixtures/servers/oauth-refresh-fixture.mjs` from the repository root. 2. Add its MCP URL as a generic connection on a local Paperclip instance. 3. Approve the test consent page and call `read_status`. 4. Let the two-minute access token expire and call the tool again. 5. Before this fix, the connection needs another sign-in. With this fix, the call refreshes the token and succeeds. **Paperclip version or commit** The integration regression reproduced the missing-refresh-token failure on the parent of this PR's fix. The same test passes with the fix. **Deployment mode** Local development. Automated tests use a loopback HTTP MCP/OAuth server and a disposable PostgreSQL database. ## What Changed - Track offline-access capability separately from MCP tool scopes. - Add supported offline access and consent for generic connections. - Preserve the actual requested scopes through callback completion and reconnect. - Discover the capability for older connections with cached OAuth endpoints. - Add a reusable MCP/OAuth fixture with PKCE, token expiry, resource binding, and refresh-token rotation. - Test shared and personal gateway calls through two refresh rotations. Cover scope selection, unsupported refresh, and legacy reconnects. - Document the behavior and local test commands. ## Verification - The two real HTTP expiry tests failed before the fix with `oauth_refresh_missing` after the first token expired. - Tests passed on the current head: 76 generic MCP regressions, all 365 tool-access service tests, and 4 fixture controls. - Full workspace `pnpm -r typecheck` and `pnpm build` passed. Server TypeScript checks also passed after the review fixes. - All remote checks passed on `d22909bb34e9d54478c0002077c498ffe105932d`. Greptile gave 5/5 with both previous findings resolved. The complete local `pnpm test:run` is still running. - Run `node --test scripts/mcp-fixtures/servers/oauth-refresh-fixture.test.mjs` for the standalone provider controls. - Run `pnpm exec vitest run server/src/__tests__/generic-mcp-connection.test.ts` for the Paperclip integration tests. ## Risks - Users can see a consent prompt when a generic provider supports offline access. - The provider can still decline to issue a refresh token. Access works until expiry, then the user must reconnect. - A provider that advertises offline access but rejects the scope produces an OAuth error. This PR does not add an automatic retry without that scope. - Existing grants without refresh tokens need another sign-in. The fix does not change them in place. - Curated Apps keep their reviewed scope and authorization-parameter allowlists. No database migration is required. - This simulation verifies the suspected failure. The reported internal MCP server has not been tested. ## Model Used - OpenAI Codex, based on GPT-6, with reasoning, tool use, and code execution. The runtime did not expose a more specific model ID or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
7a52dcdc74 |
fix: repair MCP validation and cancelled execution recovery (#14951)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The tool gateway gives agents access to connected services. Recovery controls what happens when a run stops. > - Generated tool names can exceed the provider limit after the MCP client adds its prefix. > - The same invalid definition can fail each automatic retry. A cancelled run can also hold saved messages without showing its cause. > - This pull request bounds tool names, stops configuration retries, and retains cancellation evidence. > - It shows the stopped run and admits saved input only after the existing safety checks pass. > - The benefit is a clear recovery path that preserves operator Stop and prevents duplicate message delivery. ## Linked Issues or Issue Description **What happened?** A long connected MCP tool name makes the provider reject the entire request. Automatic recovery repeats the invalid request. Separately, unexpected legacy cancellations can leave saved input behind a recovery hold. The notice does not identify the stopped run or its cause. **Expected behavior** Complete MCP names fit the provider limit. Tool-definition errors require configuration repair. Cancelled runs retain their source and reason. The recovery notice shows the cause and saved-message count. Verified unexpected cancellations can start a fresh turn through the existing admission checks. **Steps to reproduce** 1. Assign an App gallery connection with a long application key and tool name to a Claude agent. 2. Start a run. The provider rejects a name over 128 characters, including its MCP prefix. 3. For cancellation recovery, stop a legacy provider turn without an operator Stop request and send a user message while the recovery hold is active. 4. Inspect the recovery notice and the deferred message queue. **Paperclip version or commit** Rebased onto master at `cf8ad63c806685bfd7c48e3ed4a919d61a7c55f1`. **Deployment mode** Hosted or self-hosted server with legacy Claude or Codex execution. Related public work: - Refs #14017. That PR caps name segments. This PR preserves existing short names and uses stable hash aliases for long complete names. It also covers classification and recovery. - Refs #4510. That PR adds a cancellation-source column. This PR records bounded evidence in the existing run result, without a migration. - Refs #12552 and #4506. Those PRs suppress recovery after operator cancellation. This PR preserves operator intent and uses the existing continuation gates. ## What Changed - Bound gateway names with the full provider prefix in the 128-character budget. Retain the original upstream tool name for dispatch and permissions. - Classify invalid tool definitions as configuration failures before diagnostic redaction. Stop automatic retries and continuation attempts for that error code. - Persist cancellation source, expectedness, initiator, reason, and time. Preserve recorded Stop intent when adapter results arrive. Report unexpected started cancellations with closed diagnostic labels. - Show the run cause, saved-message count, and Inspect run link. Offer Continue for eligible unexpected cancellations. Require verified provider stop, empty tool inventory, ownership, and the existing pause, budget, approval, and dependency gates. Use the existing queue for single delivery. - Add regression coverage and update the execution, MCP gateway, and run-log documentation. ## Verification - `pnpm -r typecheck` and `pnpm build` passed. - `pnpm check:token-gates` passed. - Ran `pnpm test:run` and completed its workspace and serialized groups. Initial resource and timing failures passed on isolated reruns. All 149 serialized route suites passed. - Reran the changed server, adapter, and UI suites after the rebase. Coverage includes long-name upstream dispatch, configuration retry suppression, cancellation evidence retention, privacy labels, oversized run projection, and concurrent saved-message delivery. - `pnpm test:e2e tests/e2e/legacy-failure-continuation.spec.ts` passed all six browser scenarios. The recovery notice shows the run cause and inspection link, and each recovery entry point reaches one new response. - Added database-backed checks for active, removed, paused, unavailable, and disabled chat connections. The final continuation and recovery-notice suites passed 167 tests. Externally bound chats hide board Continue and show a usable next action. - All 55 GitHub checks passed on `42afbf1371dcaeb72646e3d8f65c19ff7cddf8de`. Two unrelated Storybook jobs were skipped by their normal conditions. Greptile reviewed that commit at 5/5 with no findings and no open review threads. ## Risks - Long tool names change to aliases. Existing short names stay compatible. The original connection and upstream name remain the dispatch authority. - Invalid tool definitions no longer get automatic retries. An operator must repair the configuration before a new attempt. - Continuation changes apply only to positively identified unexpected legacy cancellations with complete empty tool inventory. Operator Stop, unknown historical cancellations, outstanding tools, and unverified provider termination keep their holds. - No database migration. The added projection fields are optional. Cancellation reason and initiator IDs remain local run evidence; Sentry receives only closed source and initiator-type labels and expectedness. ## Model Used - OpenAI GPT-6 through Codex, with reasoning, repository editing, shell execution, and GitHub tool use. The runtime does not expose the exact model variant or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.13 |
||
|
|
7d59de6113 |
feat(connections): probe provider usage limits on demand (#14936)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Connections store the AI accounts used by legacy and native runners. > - Subscription accounts can reach session, weekly, model, or paid usage limits. > - Operators need to read these limits for a specific stored account before making a routing decision. > - This pull request adds an on-demand usage probe to the connection service and account detail. > - The result preserves provider limits, reset times, paid usage, and unknown values for later consumers. ## Linked Issues or Issue Description **Subsystem affected** Shared contracts, the connection service and API, and the account detail UI. **Problem or motivation** Managed AI accounts lack a common operation to read their current usage limits. A local harness probe can read a different login from the account selected for an agent. **Proposed solution** Add `aiConnectionService.probeUsage()` and a board-only connection usage endpoint. Probe the selected credential grant on request. Support Codex, Claude, and Grok subscriptions, plus OpenRouter API key limits. **Alternatives considered** Harness-specific automatic polling would couple the read to execution and can read ambient credentials. This change uses the managed connection credential and leaves scheduling and admission decisions to later work. **Roadmap alignment** This extends the existing Personal & Shared AI Accounts capability. It adds no routing or quota enforcement. Related: Refs #14459 for managed OpenAI quota reads; Refs #14781 and Refs #13379 for downstream pacing and budget work. This operation reads one requested account across all three subscription providers. ## What Changed - Add typed usage snapshots and a probe capability flag to managed AI connections. - Normalize Codex, Claude, Grok, and OpenRouter responses. Keep model scopes, provider admission, reset periods, and paid allowances separate. Preserve unknown values. - Enforce company membership, credential audience, grant identity, and connection lifecycle before reading the stored secret. - Add a board-only `GET /api/companies/:companyId/ai-connections/:connectionId/usage` endpoint with `no-store` responses. - Add manual **Check usage** and **Refresh** actions to account details. Show compact usage bars, resets, admission and overage status; remove repeated descriptions and account-default copy. Clear previous results during a new request or error. - Add Storybook previews using the production account components for all four providers, initial checks, loading, and permission errors. - Add provider, authorization, runner selection, API, and UI coverage. Document provider sources and live qualification. ## Verification - Initial provider, authorization, selection, API, and UI validation passed (96 focused tests): `pnpm exec vitest run server/src/services/ai-connection-usage.test.ts server/src/__tests__/ai-connections.test.ts ui/src/components/ai-connections/AiConnectionUsagePanel.test.tsx server/src/__tests__/openapi-routes.test.ts`. - `pnpm -r typecheck` passes for the initial implementation. After simplifying the UI, 9 usage-panel and date-helper tests, UI typecheck, token gates, and Storybook build pass. The initial feature module boundary check also passed. - Real Codex, Claude, and Grok credentials were saved to encrypted disposable connections. The actual usage HTTP route returned 200 with `status: ok`. Legacy and native runner selection checks passed. The tests started no model turn and exchanged no refresh token. The disposable databases and vaults were removed. - Live Claude responses added structured scoped limits. Live Grok responses omitted included-plan usage. Tests now cover both shapes and preserve the Grok omission as unknown. - The full workspace build passes. A full local test run hit a heartbeat feedback timeout. That case passes in isolation. The duplicate local run was stopped after all remote checks passed. The Slack ordering and OpenCode transport CI flakes also pass in isolation and on the CI rerun. - Current head: `ff3d479029a1c4248190323e221b2803cfb0d79d`. All 54 active checks pass. Two Storybook checks are intentionally skipped by the workflow. Greptile is 5/5 with no unresolved review findings; the branch is mergeable. ## Risks - Subscription usage endpoints can change. Credentials can lack usage-read permission. The probe returns explicit errors without fresh limits in these cases. - A successful probe can contain partial data. Missing utilization or admission remains unknown. An enabled paid-usage switch does not prove a funded balance. - This change adds no migration. It does not change runner admission or automatic provider selection. Provider requests use fixed endpoints, disabled redirects, bounded response sizes, and a 15-second deadline. ## Model Used OpenAI Codex, GPT-6, with reasoning, file editing, shell execution, and HTTP tools. The session does not expose the exact runtime model variant or context window size. Real provider credentials were used only for the authorized live checks. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
cf8ad63c80 |
build(deps-dev): bump tsx from 4.23.12 to 4.23.15 (#12965)
Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.12 to 4.23.15. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/privatenumber/tsx/releases">tsx's releases</a>.</em></p> <blockquote> <h2>v4.23.15</h2> <h2><a href="https://github.com/privatenumber/tsx/compare/v4.23.14...v4.23.15">4.23.15</a> (2026-09-20)</h2> <h3>Bug Fixes</h3> <ul> <li>exclude bare builtins from namespace inheritance (<a href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a">38e1588</a>)</li> <li>expose require.cache and require.extensions to tsImport CommonJS modules (<a href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a">2da3407</a>)</li> <li>make namespaced register() overloads portable for declaration emit (<a href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15">562c434</a>)</li> </ul> <hr /> <p>This release is also available on:</p> <ul> <li><a href="https://www.npmjs.com/package/tsx/v/4.23.15"><code>npm package (@latest dist-tag)</code></a></li> </ul> <h2>v4.23.14</h2> <h2><a href="https://github.com/privatenumber/tsx/compare/v4.23.13...v4.23.14">4.23.14</a> (2026-09-20)</h2> <h3>Bug Fixes</h3> <ul> <li>restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (<a href="https://redirect.github.com/privatenumber/tsx/issues/802">#802</a>) (<a href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f">6e5236b</a>)</li> </ul> <hr /> <p>This release is also available on:</p> <ul> <li><a href="https://www.npmjs.com/package/tsx/v/4.23.14"><code>npm package (@latest dist-tag)</code></a></li> </ul> <h2>v4.23.13</h2> <h2><a href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.13">4.23.13</a> (2026-08-30)</h2> <h3>Bug Fixes</h3> <ul> <li><strong>cache:</strong> bound shared transform cache memory (<a href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>) (<a href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e">28e1f12</a>)</li> </ul> <hr /> <p>This release is also available on:</p> <ul> <li><a href="https://www.npmjs.com/package/tsx/v/4.23.13"><code>npm package (@latest dist-tag)</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/privatenumber/tsx/commit/ca66105a17a2a4c6503fe3a12b5b9ec408286011"><code>ca66105</code></a> test: fix drive-less file URLs in ESM resolver fixtures</li> <li><a href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a"><code>2da3407</code></a> fix: expose require.cache and require.extensions to tsImport CommonJS modules</li> <li><a href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a"><code>38e1588</code></a> fix: exclude bare builtins from namespace inheritance</li> <li><a href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15"><code>562c434</code></a> fix: make namespaced register() overloads portable for declaration emit</li> <li><a href="https://github.com/privatenumber/tsx/commit/edfb1f05a3f40b879a41a03a0801c2abd3a3ecf9"><code>edfb1f0</code></a> build: upgrade pkgroll and externalize CJS loader reference</li> <li><a href="https://github.com/privatenumber/tsx/commit/70e78284837c859f09b96cd10cd71d007aa4b795"><code>70e7828</code></a> test: upgrade tinyspy for disposable API</li> <li><a href="https://github.com/privatenumber/tsx/commit/9ed2022dfa9ea1be9511fe6abcde8110c25055a7"><code>9ed2022</code></a> ci: avoid duplicate release notifications</li> <li><a href="https://github.com/privatenumber/tsx/commit/872e77ffc5e96ca5c4727e74c0694debcb26219b"><code>872e77f</code></a> refactor: use disposables for cleanup</li> <li><a href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f"><code>6e5236b</code></a> fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...</li> <li><a href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e"><code>28e1f12</code></a> fix(cache): bound shared transform cache memory (<a href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>)</li> <li>See full diff in <a href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.15">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.12 |
||
|
|
b2c565038b |
test(shared): make the worktree port registry lock suite deterministic (#12798)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Shared worktree services use lock leases and worker-thread heartbeats > - The lock test suite measured wall-clock timing across two threads > - Processor contention allowed a heartbeat tick to change the value during an assertion > - This pull request removes that timing race and restores a regression guard > - The benefit is a stable test suite that still detects slow heartbeats ## Linked Issues or Issue Description **What happened?** The worktree port registry lock suite failed at random under continuous-integration processor contention. The failure reported a fresh timestamp where the test expected an old timestamp. **Expected behavior** The suite must pass when the heartbeat runs at its supported interval. It must also fail when the heartbeat interval regresses. **Steps to reproduce** 1. Run `npx vitest run src/worktree-port-registry.test.ts` in `packages/shared`. 2. Repeat the run under bounded processor contention. 3. Set the heartbeat interval to 3000 ms and run the asynchronous critical-section test. **Paperclip version or commit** `a661caf74e704f7700a8b8a1e79b76ebd04e3483` **Deployment mode** Built from source. **Installation method** Built from source. **Agent adapter(s) involved** Not adapter-specific (core test). **Database mode** Not database-related. **Additional context** Related open pull requests are #11994, #11985, and #11922. This pull request keeps all five tests active and does not use `skip`, `skipIf`, or `todo`. ## What Changed - Build the fallback-probe lock state by hand so no live heartbeat changes the timestamp during the assertion. - Count distinct heartbeat refreshes in the asynchronous critical-section test. - Close the fake probe and settle the pending lock attempt in a `finally` block. - Keep production code unchanged. ## Verification - `npx vitest run src/worktree-port-registry.test.ts` — 5 of 5 tests pass. - `npx vitest run` — 72 files and 704 tests pass at submit time. - `npx tsc --noEmit` — exit code 0. - Ten target-file runs pass under bounded processor contention. - A 3000 ms heartbeat interval fails with `expected 2 to be greater than or equal to 3`. - An inverted cleanup assertion exits normally in 379 ms without a leaked worker. ## Risks Low risk. This pull request changes one test file. It changes test setup and assertions only. ## Model Used OpenAI GPT-5 through Codex. Exact model ID: GPT-5. The model used tool calls and code execution. The context window is not disclosed by the runtime. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
9d0f7e2ddd |
fix(adapter-utils): make the directory merge lock crash test deterministic (#14881)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - A workspace restore merges a directory, and a cross-process lock
serializes that merge
> - The lock must recover after the process that holds it crashes
> - One test proves that recovery: it kills the holder process and then
acquires the lock
> - That test failed intermittently for two independent reasons, and
this pull request removes both
> - First, it spawned the holder through the tsx command-line entry
point, which re-spawns the evaluated code in a further child process, so
the kill signal reached only the wrapper and the real holder kept the
lock
> - Second, it replaced the global clock to force a timeout, which left
the acquisition with zero real retries, so a single transient busy
result failed the test
> - The benefit is a deterministic crash-recovery test and a reliable
continuous-integration signal
## Linked Issues or Issue Description
**What happened?**
The test `recovers a killed holder even when its recorded PID has been
reused` in `packages/adapter-utils/src/directory-merge-lock.test.ts`
failed intermittently in continuous integration. The failure reported
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` with `waitMs: 3` and
`knownLocalHolder: false`. A rerun of the same job on the same commit
passed.
**Expected behavior**
The test must pass every run. It must acquire the lock after the holder
process dies.
**Steps to reproduce**
1. Check out `master`.
2. Run `npx vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts`.
3. Repeat the run. The named test fails intermittently.
**Paperclip version or commit**
`32e9f3ba0ec000578936731990d23bb0e77493fa`
**Deployment mode**
Built from source. The failure appears in the general test job of
continuous integration.
**Agent adapter(s) involved**
Not adapter-specific (core bug).
**Relevant logs or output**
```
ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT
workspaceRestoreLock: { ownerState: 'alive', knownLocalHolder: false, waitMs: 3,
ownerSameProcess: true, ownerAgeMs: 60030, ownerPredatesProcess: true }
```
## What Changed
The test file had two independent defects. This pull request removes
both.
**1. The kill signal did not reach the real lock holder.**
The test spawned its holder through the tsx command-line entry point.
That entry point re-spawns the evaluated code in a further child
process. `SIGKILL` therefore killed only the wrapper, and the process
that had opened the lock database survived as an orphan that still held
the lock. The test now loads tsx as an `--import` hook, so the spawned
process is the real holder and the kill releases the lock at once. This
also stops the test from leaking an orphan process.
**2. The forced clock left the acquisition with zero retries.**
A test helper replaced `Date.now` to force a timeout. The implementation
reads `Date.now()` one time, to compute its deadline, so that single
read consumed the forced value and every later read returned a time
already past the deadline. The retry loop therefore got one attempt and
no retries. That is correct for a test that asserts a timeout, but the
crash-recovery test asserts a *successful* acquisition, so any transient
busy result on the first attempt failed it.
The fix removes the clock replacement from the whole file and gives each
test a real, short, explicit wait budget:
- `withDirectoryMergeLock` takes a new optional wait-budget parameter.
It threads through to the lock acquisition function. The production
default is the existing 30-second budget, and no production call site
changed.
- The five tests that assert a timeout pass a real 200-millisecond
budget. Each one still times out for the real reason, because the lock
is genuinely held or the legacy lock directory genuinely exists. Each
one now exercises at least four real retries of the 50-millisecond retry
interval.
- The crash-recovery test passes a real 5-second budget. A failure now
reports the structured `ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` diagnostic
well inside the test timeout, instead of a bare test timeout.
**No test timeout increased.** Every `it(..., N)` timeout in the file
equals its value on `master`.
## Verification
- Measured the first cause rather than assumed it: the spawned wrapper
process reported one process id, and the process that opened the lock
database reported a different process id and named the wrapper as its
parent. The real holder kept the lock for about 50 to 60 milliseconds
after the kill.
- Reproduced the failure deterministically before the change, with no
artificial processor load: 15 of 15 runs failed. Confirmed the fix: 15
of 15 runs passed.
- Ran the lock test file 15 times in series: 12 of 12 tests passed every
time.
- Confirmed the clock replacement is gone: a search for a `Date.now`
override in the file returns nothing.
- Confirmed the production default is unchanged at 30 seconds, and that
the diff touches no production call site.
- Proved the diagnostic still surfaces: with a temporary edit that held
the lock with a genuine live holder, the test failed with
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` and the full `workspaceRestoreLock`
block at about 5 seconds, inside the 15-second test timeout. The
temporary edit was reverted.
- `workspace-restore-merge.test.ts` passed 56 of 56. The adapter test
files that cover every production caller passed 116 of 116 and 52 of 52.
`agent-directory-working-copies.test.ts` passed 70 of 70.
- The `adapter-utils` and `server` type-checks passed with no error.
- Confirmed that no spawned process survives the test run.
## Risks
Low risk. The production change is one optional parameter with the
existing default, so every production caller keeps the real 30-second
budget and no production call site changed. The remaining change is
limited to one test file. The `--import` form of the tsx hook is already
used elsewhere in this repository, in the container image command and in
an end-to-end test configuration. Test coverage does not drop: the owner
record is diagnostic only, the SQLite reserved lock remains the
authority that the tests exercise, and the timeout-asserting tests now
exercise the real retry loop instead of a replaced clock. The file costs
about 0.5 to 0.9 seconds more wall clock than `master`, which is the
cost of the short real waits that replace the instant forced timeout.
## Model Used
Claude Sonnet 5 (`claude-sonnet-5`), used with extended thinking and
tool use for the diagnosis, the measurement, and the change.
## Checklist
Check every box that the state of the pull request satisfies. The local
test runs and the type checks are complete. Reconcile the
continuous-integration and review boxes after the checks reach their
terminal state.
## Test plan
- [x] Continuous integration is green on every check, including the
general test job.
- [x] The general test job passes the file
`packages/adapter-utils/src/directory-merge-lock.test.ts`.
- [x] Greptile returns 5 of 5 with no open item.
- [x] `mergeable: MERGEABLE` is terminal.
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
|
||
|
|
6c1a75da49 |
feat(connections): make AgentMail a default connection with inline setup (#14772)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Connections give agents access to external services. > - AgentMail needs both a saved key and an inbox assigned to the agent. > - Chat requests offered a setup link instead of an inline card and could treat a saved key as complete. > - Inbox setup also hid address conflicts behind a generic server error and a separate review step. > - This pull request makes AgentMail a default connection, adds the inline card, reduces setup to two steps, and shows conflicts beside the address. > - Shared native dropdown styles also give every caret a consistent inset. ## Linked Issues or Issue Description **What happened?** AgentMail requests in chat did not show a usable inline connection card. Manual setup required extra screens, ignored saved account keys, and could trap new-address setup in a locked inbox dropdown. Agent selectors omitted the avatar from the selected value. A taken address could produce an HTTP 403 from AgentMail and appear as an internal server error. Native dropdown arrows also touched the right edge of their fields. **Expected behavior** Make AgentMail available as a default connection. Ask for the API key inline, with a direct link to its provider page. Default human access to the company and agent access to the requesting agent. Resume the agent only after an assigned inbox is active. Manual setup should ask for an agent and email address, then finish. Address checks should run as the user types. Taken addresses should show clickable alternatives. A domain dropdown beside the name should prefer a verified custom domain. Setup should suggest authorized saved AgentMail keys and show agent avatars in the picker and selected value. **Steps to reproduce** 1. Ask an agent to connect AgentMail when it has no assigned inbox. 2. Check that an inline API-key card appears and links to the provider's API-key page. 3. Open AgentMail setup, choose an agent, and request an address that is already taken. 4. Correct the inline error, refresh, and finish setup with the same request ID. 5. Inspect native dropdown carets in light, dark, disabled, and right-to-left states. Uses the bounded provider-error parser merged in #14768. Related work: #13256 introduced AgentMail; #14725 expanded connection search. ## What Changed - Stop recurring email queries for tasks that have no email thread. Share the query between the thread provider and activity view. Keep email-task updates and invalidation-based discovery. - Make AgentMail available without the experimental chat setting. Keep the catalog, setup and management routes, agent Channels tab, task email feed, receiving worker, and agent tools available by default. Other experimental chat providers stay gated. - Make the email address and copy icon a single clickable action with the shared Copied! confirmation. Add View inbox linking directly to the matching AgentMail console inbox, with the address encoded as one URL path segment. - Reorganize inbox Settings around the copyable email address, usage instructions, and receiving status. Move reconnect credentials into a disclosure and separate the Disconnect action. Add production Settings stories for active, paused, unassigned-address, revoked, webhook, long-address, mobile, and reconnect states. Show repair controls when the inbox has an error. Keep usage instructions tied to an active inbox with an address. - Add AgentMail channel intents and an inline key field with the direct API-key URL. - Keep setup and retry state tied to the interaction. Require an active inbox for completion. Preserve company and agent access checks. - Reduce manual setup to agent selection and email selection. Put the domain dropdown beside the address and default to a verified custom domain. Preserve explicit choices across reloads. Keep receiving settings under Advanced options. - Check the initial address and edits after a 350 ms pause. Abort superseded requests and ignore stale responses. Show clickable suggestions and retain known creation conflicts across reloads. - Add a company-scoped, manager-only address check using the saved credential. Search the visible inbox list instead of fetching an uncreated inbox: live AgentMail retains negative lookups that can break subsequent access-key creation. Unlisted addresses remain unknown; creation is authoritative. - Suggest labeled saved AgentMail keys in both manual setup and the inline card. Filter by company, provider, active credential, and current-user grants on the server. Prefer an account key and preserve the selected key or an explicit new-key choice across refresh. Use verified scope metadata and bounded concurrent checks for legacy keys. Never return secret values. - Catch an inbox-only key before the email step. Allow its existing inbox only after an explicit choice. Recover old locked drafts at the key picker. Save the replacement key before retiring an empty draft, then use a new setup URL so refresh preserves the switched account; stop if cleanup fails. Preserve already allocated addresses and their original accounts. - Use the shared AgentSelect in email setup. Show the canonical agent avatar in each option and the selected value, including other consumers of the shared component. Add regression coverage for legacy and current Lucide agent-mention icon formats. - Start each catalog Add connection with a fresh setup identity. Honor Finish setup's exact draft/account/address instead of resuming an unrelated browser draft. Return Cancel and Done to Connectors and Email settings to the inbox. Group the task/thread explanation in a How it Works card. - Route AgentMail catalog removal through the email inbox control API, including unfinished drafts. Refresh both the catalog and inbox views. - Render each inbox management tab separately. Access uses the saved account grants and agent controls; Conversations and Activity use the shared persisted email feed. Activity lifecycle actions use the email API. Reconnect returns to inbox Settings. Conversation failures show a retry instead of a false empty state. Email delivery recovery stays in the task. - Map documented provider address conflicts to a field error. Preserve actionable messages for other failures. - Preserve non-secret draft fields across refresh, scoped to the requested agent. Never save API keys in browser storage. Resume partial inbox creation with the original agent, address, and request ID. - Show an already-created address with explicit retry and new-address recovery instead of locked inputs. Preserve the original inbox and resumable draft when choosing another address. Distinguish runtime-key 404 errors and log safe provider status/operation/code. - Apply final agent access once within email setup authorization for a new account whose original installs are unchanged. Preserve later permission edits and reused account installs. Support in-place retry of progress loading. - Let a failed inline setup change keys after retiring an empty draft. Persist its replacement setup identity without storing secrets. Recover a server-saved account when refresh interrupts the save response, while preserving intentional account changes. - Render the production setup in Storybook and add error, recovery, and mobile states. - Inset native select carets in shared CSS. Preserve custom icons, listboxes, keyboard behavior, and forced-color controls. - Add browser regression coverage and an AgentMail Product E2E case with persisted-state and rendered-card evidence. ## Verification - Full `pnpm -r typecheck`, `pnpm build`, `pnpm check:token-gates`, and `git diff --check` passed after the default-availability change. - All 485 focused tests passed. These cover setup, management, catalog and route gates, connection intents, email authorization, Cursor execution, and the OpenAPI contract. All 39 email integration tests run with the experimental chat setting off. - The shared polling change passed four behavioral tests, UI typecheck and build, and token gates. - `tests/e2e/agentmail.spec.ts` passed with the actual server setting off. This full-stack browser test uses simulated provider responses. It covers catalog entry, saved keys, editable address and domain controls, creation, conflicts, retry, all management tabs, clipboard feedback, the provider link, and task email rendering. - In the live local browser, Add connection reached the editable email step with the saved account key. The verified custom domain was selected by default. Both domain choices worked. The existing inbox Settings page remained available. Both active inboxes completed new mail checks with the setting off. No new provider inbox or email message was created for this pass. - Earlier live provider acceptance covered creation on a verified custom domain, Finish connecting on the reported draft, successful mail checks after refresh, and catalog removal of disposable draft and active connections. Clicking the email address copied the exact address and showed Copied!. View inbox opened the same inbox in AgentMail’s console. No email messages were sent. - Production setup and Settings Storybook builds and interactions passed. Settings states include active, paused, unassigned, revoked, webhook, long-address, mobile, and reconnect. Receiving and revoked-access stories had zero accessibility violations. - Full local `pnpm test:run` on an earlier revision completed with 14,709 passing, 87 skipped, and four transient failures. All four failed cases passed in focused reruns without product changes. That serial full local command was not repeated after each follow-up. The latest-head full CI suite is the final test gate. - CI found an obsolete browser assertion that hid every channel when the flag was off. Updated it to keep AgentMail and the Channels surface visible while preserving the GitHub chat route gates. All 11 provider browser tests passed locally after scoping the Channels selector to the agent sidebar. Two initial local attempts stopped at temporary Postgres initialization. The passing run used a separate disposable database on the existing local Postgres server; it was removed after the test. - Updated the remaining sidebar and aggregator discovery assertions for default AgentMail availability. Ordinary task fixtures now return no email thread. All 128 sidebar/task-page tests and all 42 aggregator tests passed locally. - Latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`: full CI passed, with 54 successful checks including Snyk and two intentional Storybook skips. The CI run is https://github.com/paperclipai/paperclip/actions/runs/37020833647. A fresh Greptile review scored 5/5 with no unresolved threads. Live model evaluations and inbound/outbound email delivery were not run. ## Risks - AgentMail no longer needs experimental opt-in. Setup still requires a human to connect an account and assign an inbox. Inline setup creates an inbox after a human submits a new or saved key. Company access, agent access, inbox assignment, and completion checks remain enforced. - AgentMail read APIs cannot prove global address availability. The visible-list check is bounded to 100 entries and cannot see inboxes outside the key’s scope. The UI reports this limitation, suggests alternatives without claiming they are free, and keeps final creation conflicts inline. Lookup outages show an error without preventing the authoritative creation attempt. - Native select CSS affects the whole app. Custom-icon selects and multi-row lists are excluded. Forced-color mode keeps the browser caret. - Saved-key discovery uses stored verified scope metadata and checks authorized legacy credentials concurrently within a shared three-second deadline. Provider outages mark legacy choices unavailable; users can still enter another key. Final use rechecks authorization and provider access. - No database migration or transport default change. Live connection remains the default. ## Model Used OpenAI Codex, GPT-6, with reasoning, tool use, and code execution. The exact served model ID and context-window size are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (focused suites; full-suite limitation documented above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green (latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`) - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups (latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`) - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
ec3bacc9bd |
fix(chat): hide ignored provider information (#14929)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Task and agent chats show agent progress and problems that need attention. > - Codex also sends account, skill, and unrelated thread notifications. > - The runner correctly ignores that information but reports it as a warning. > - Chat then shows an internal diagnostic as an actionable provider notice. > - This pull request keeps the diagnostic in run logs and removes it from chat. > - Real provider warnings, errors, and agent replies remain visible. ## Linked Issues or Issue Description **What happened?** Chat showed “Received a provider update” and a warning with the text “ignored unrelated provider information”. Its details said “User Actionable: Yes” even though no user action was needed. Saved conversations retained the same noise. **Expected behavior** Keep ignored provider information in the run log. Do not show it as chat activity or a user warning. Preserve real warnings and errors. **Steps to reproduce** 1. Start a conversation with the native Codex runner. 2. Have the provider send an account update, skill change, or unrelated thread notification during the turn. 3. Inspect live chat and reload its saved history. The regression tests also reproduce the old stored notice without a live account. **Paperclip version or commit** Source implementation on master at `e00d10d5d`. The duplicate search found no open PR for this fix. Related prior work: #13109 improved provider-notice presentation. #12367 added Codex thread normalization. This change addresses the internal information that those paths still projected as chat warnings. **Deployment mode** Native Paperclip Runner with the Codex app-server provider. The issue was seen in hosted chat and can be reproduced with local provider fixtures. ## What Changed - Map ignored unrelated Codex information to `harness.diagnostic` in the Rust and TypeScript normalizers. - Retain a bounded allowlist of redacted provider method and thread/turn identifiers. - Use the same Unicode character limit and truncation marker in both normalizers. - Share the text redactor through a pure helper. Keep provider connection code out of the standalone demo's source closure. - Omit that diagnostic and the matching legacy notice from live chat. - Omit the matching legacy notice from saved chat history. - Test diagnostic retention, account-notification integration, live and saved chat, and continued visibility of real warnings, errors, and replies. - Document the local run-log event and historical display behavior. ## Verification - Passed: 68 tests in the two affected UI transcript suites. - Passed: 60 TypeScript tests across provider events, transport behavior, and the standalone demo boundary. - Passed: 13 Rust provider-event tests and the Codex account-notification integration test. - Passed: `pnpm check:token-gates` and Cargo formatting checks. - Passed: full `pnpm build` and `pnpm -r typecheck`. After the review fix, the provider package build, typecheck, and both provider-event suites passed again. - Full local `pnpm test:run` failed: 608 files / 10,904 tests passed, 30 server suites failed, and 104 files / 4,012 tests were skipped. Most failures were embedded PostgreSQL startup errors. Two tests timed out in `heartbeat-comment-wake-batching` and `workspace-git-snapshot-streaming`. PostgreSQL startup also failed in `heartbeat-run-event-sequencing` and `native-finalization-migration`. These server files are unchanged by this PR. Isolated heartbeat reruns were skipped locally. The stable test script stopped after this general-server group, so later groups did not run locally. - The original review thread is resolved. Greptile is 5/5 on current head `683dab7cce57187c57e84c83f5e9da4ad75c9c04`. - All current-head CI gates passed, including the full server/chat/workspace test matrix, Rust and TypeScript runner suites, browser E2E, build, typecheck, and release canary. [CI run](https://github.com/paperclipai/paperclip/actions/runs/37021330663). - Replay the exact old warning in either transcript adapter. It must produce no chat row. A genuine provider warning or error must still produce a row. ## Risks - Low risk. The display filter matches one diagnostic code or the complete legacy warning shape. Other provider notices remain visible. - New ignored-information events use the existing harness-diagnostic event type. They retain diagnostic evidence without original account payloads. - No database migration, API permission, provider execution, or recovery behavior changes. This affects the local run log, not Telemetry or OpenTelemetry exports. ## Model Used OpenAI Codex, GPT-6. The exact backend model ID and context-window size are not exposed in this session. Used reasoning, repository inspection, code editing, tool use, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run the affected tests locally and they pass (the broad local run has PostgreSQL startup errors and timeouts documented above; the full CI matrix passed) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
479debe9e3 |
build(deps): bump aws-actions/configure-aws-credentials from 6.2.3 to 6.3.0 (#12966)
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.3 to 6.3.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws-actions/configure-aws-credentials/releases">aws-actions/configure-aws-credentials's releases</a>.</em></p> <blockquote> <h2>v6.3.0</h2> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.4...v6.3.0">6.3.0</a> (2026-09-11)</h2> <h3>Features</h3> <ul> <li>add translate-env-variables option (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb">57b8365</a>)</li> </ul> <h2>v6.2.4</h2> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4">6.2.4</a> (2026-08-31)</h2> <h3>Bug Fixes</h3> <ul> <li>account-ids handling, mask proxy as secret in logs (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1943">#1943</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63">aa65264</a>)</li> <li>skip backoff sleep after the final retryAndBackoff attempt (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1937">#1937</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876">3852440</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md">aws-actions/configure-aws-credentials's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file. See <a href="https://github.com/conventional-changelog/standard-version">standard-version</a> for commit guidelines.</p> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.4...v6.3.0">6.3.0</a> (2026-09-11)</h2> <h3>Features</h3> <ul> <li>add translate-env-variables option (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb">57b8365</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4">6.2.4</a> (2026-08-31)</h2> <h3>Bug Fixes</h3> <ul> <li>account-ids handling, mask proxy as secret in logs (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1943">#1943</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63">aa65264</a>)</li> <li>skip backoff sleep after the final retryAndBackoff attempt (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1937">#1937</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876">3852440</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a> (2026-07-22)</h2> <h3>Bug Fixes</h3> <ul> <li>attach git credentials before Tag Major Version push (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li> <li>PackedPolicyTooLarge detection in STS tags (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a> (2026-07-07)</h2> <h3>Miscellaneous Chores</h3> <ul> <li>release 6.2.2 (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.0...v6.2.1">6.2.1</a> (2026-06-26)</h2> <h3>Bug Fixes</h3> <ul> <li>enforce allowed-account-ids on all auth paths (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1847">#1847</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/4d281fbc56a82e63c3fc14f2cc22361f34c97493">4d281fb</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0">6.2.0</a> (2026-06-01)</h2> <h3>Features</h3> <ul> <li>add additional session tags by default (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1775">#1775</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/e0ba7685077379a14a82d01fefd511490344ebfc">e0ba768</a>)</li> <li>add more retry logic and better logging (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1764">#1764</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/540d0c13aedb8d55501d220bd2f0b3cdedfe84e8">540d0c1</a>)</li> <li>add regex validation to role-session-name (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1765">#1765</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/e35449909c6ede5083a48ba4b8bbfaaa1cf09ba1">e354499</a>)</li> <li>Allow custom session tags to be passed when assuming a role (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1759">#1759</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/61f50f630f383628add73c1eab3f1935ba07da2b">61f50f6</a>)</li> <li>expose run id in STS client user-agent (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1774">#1774</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/29d1be30273e7ef371d59fccf6ec54572c64ec89">29d1be3</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/e1253824e5c10ff9df46874f81ed3ec929e19cfd"><code>e125382</code></a> chore(main): release 6.3.0 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1963">#1963</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/438100a0eb37d9180319c727b1e108d9a112a27a"><code>438100a</code></a> chore: add link to GH security docs (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1962">#1962</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/e92ebccf3986be80a7535da17f1ed57aec450139"><code>e92ebcc</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb"><code>57b8365</code></a> feat: add translate-env-variables option (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/cc49fa741eb53f7c83be6fce8f9b4df000cd3af7"><code>cc49fa7</code></a> chore(docs): README main branch guidance (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1960">#1960</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/866cb167f1d1a75ae9c75cdb39377cfd9c0f794e"><code>866cb16</code></a> chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1958">#1958</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/6782cb1b6df5d32e9354c1e6d6da4f956c0d61c4"><code>6782cb1</code></a> chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1951">#1951</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/c20509ac5cba30e782e34cf33a0067e67c746cf0"><code>c20509a</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/7a41fc6cd2b4970e71974e29fb3f0979f4eb20cb"><code>7a41fc6</code></a> chore(deps): bump <code>@aws-sdk/client-sts</code> from 3.1121.0 to 3.1127.0 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1954">#1954</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/726b71346f7761addb59879a6c73e0c64ec8f959"><code>726b713</code></a> chore(deps-dev): bump <code>@biomejs/biome</code> from 2.5.11 to 2.5.12 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1957">#1957</a>)</li> <li>Additional commits viewable in <a href="https://github.com/aws-actions/configure-aws-credentials/compare/e6de054238d6b7531b4efff3b6587d9aade6a06c...e1253824e5c10ff9df46874f81ed3ec929e19cfd">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.11 |
||
|
|
e00d10d5d5 |
fix(connections): repair stale AI defaults from agent settings (#14916)
## Thinking Path > - Paperclip manages AI agents and controls the credentials used for their work. > - Managed AI connections resolve each responsible user's provider default. > - Agent settings created another account but kept the old default selected. > - A rejected provider test left the old account marked as connected. > - Claude ACP reported a typed login failure as a generic terminal-access error. > - This pull request repairs the selected account or selects the new login explicitly. > - Agents can save and run with the repaired credential, and failed logins request sign-in. ## Linked Issues or Issue Description - Fixes #14831. - Refs #13867. Environment failures remain separate from credential-health failures. ## What Changed - Add an agent-settings action to reconnect an unavailable personal default in place. Keep its connection, grant, default, and agent access. - State that a new account becomes the user's provider default. Select its returned grant before changing the agent binding. Keep the actual sign-in method. - Show default-update errors and allow retry without another provider login. - Show the agent-access choice. Connection managers start with company-wide access for their own tasks. Other members start with access for the current agent. - Use the server's connection-manager permission in the shared list response. This includes members with a custom management grant. - Mark credentials as needing attention after an explicit login rejection in Test or Save. This includes API-key 401 and 403 responses. Network, quota, and server failures keep the credential health unchanged. - Reuse the credential-generation check so an old failure cannot invalidate a newer reconnect. - Route Claude's typed provider `access` failure to the existing login-recovery flow. Replace its generic terminal-access fallback with a sign-in message. - Add regression tests and update the AI Connections documentation. ## Verification - Red: the UI tests failed on the missing reconnect action, unused returned grant, missing access choice, and lost default-update error. The server tests failed because rejected credentials stayed connected. The real ACP fixture returned `acpx_turn_failed` for typed login failures. - Green: 156 tests passed across the AI connection, hiring, agent field, and New Agent suites. All 37 environment-route tests passed. The Claude ACP authentication fixtures also passed. - `pnpm check:token-gates` passed. - `pnpm -r typecheck` passed. - `pnpm build` passed. - The full local `pnpm test:run` passed 707 files and 14,503 tests, then exited with an agent-conversation timeout and embedded PostgreSQL startup failures in unchanged suites. The isolated conversation and migration tests passed on rerun. Later local test groups did not run after this failure. - [All CI gates passed](https://github.com/paperclipai/paperclip/actions/runs/37012669356) on commit `38513dfe2`. This includes the full test matrix, browser tests, typecheck, build, Runner checks, and canary dry run. - Greptile reviewed commit `38513dfe2` and returned 5/5 with no open findings. - The regression tests use a real embedded database and a real ACP fixture process. Live provider sign-in requires a valid account and was not run. ## Risks - Connecting a new account from agent settings changes the user's provider default. The dialog states this before sign-in. - The displayed access choice can allow all company agents to use the account for its owner's tasks. Reconnect keeps the existing access. Server permissions still control installs. - Claude's typed `access` category maps to the provider's `auth_required` signal. Tool and workspace request failures retain their existing classification. - No database migration or provider credential format changes are required. ## Model Used - OpenAI GPT-6 through Codex. The exact served model identifier and context window are not exposed in this session. Capabilities used: reasoning, repository tools, code editing, and command execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.10 |
||
|
|
408f70e69f |
fix(runner): preserve stock Codex base instructions (#14920)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The native Runner connects Paperclip tasks to Codex app-server. > - Paperclip passed its runtime context as `baseInstructions`. > - That field replaces the stock Codex base prompt. > - This pull request sends the same Paperclip context as additive developer instructions. > - Codex keeps its stock prompt and still receives Paperclip task instructions and tools. ## Linked Issues or Issue Description **What happened?** The native Codex driver and Rust provider sent Paperclip context through `baseInstructions` on thread start and resume. Codex used this text in place of its stock base instructions. Direct-chat resume also sent an empty replacement base. The Runner Lab session path used the same replacement field. **Expected behavior** Codex should retain its stock base prompt. Paperclip should add its runtime context through `developerInstructions`. Other provider facades should retain their current instruction handling. **Steps to reproduce** 1. Create a native Codex session through Paperclip Runner. 2. Inspect the `thread/start` request in the native provider trace. 3. Resume the session and inspect `thread/resume`. 4. Before this fix, these paths set `baseInstructions`. After this fix, the Codex paths set `developerInstructions` and omit `baseInstructions`. **Paperclip version or commit** Reproduced against master at `cad26c6bfb736039c8ed5743da650a44792a083c`. **Deployment mode** Built from source. Native Codex app-server and runnerd paths. A local protocol probe used codex-cli 0.153.4 and a localhost Responses stub. No duplicate fix or matching public issue was found in the GitHub search. ## What Changed - Send additive developer instructions on Codex start and resume in the TypeScript driver, Rust provider, and Runner Lab session path. - Carry the additive fragment through runnerd, including runtime asset path mapping. - Preserve existing instruction fields for other provider facades, including OpenCode. - Add start/resume/direct-chat regression coverage and check the actual Rust provider request. - Document the historical option and trace field names. Record progress and follow-ups in the working checklist. ## Verification - `pnpm -r typecheck` — passed. - `pnpm build` — passed. - Targeted Codex driver lifecycle, driver, and live-session Vitest suites — 139 tests passed. - `cargo test --manifest-path packages/paperclip-runner/runner/Cargo.toml --locked -p paperclip-runner-core --test codex_provider` — 91 passed, 2 ignored subprocess helpers. - Real app-server probe: a localhost Responses stub captured identical 14,732-character stock base instructions on fresh start and cold resume. Both requests retained the Paperclip marker in developer input. Both stub turns completed. No paid inference was used. - Runnerd transport Vitest suite — 182 tests passed. - The initial `pnpm test:run` attempt reported local dependency-loading, embedded PostgreSQL startup, and macOS `/var` versus `/private/var` path failures. It was stopped after those failures. Loading-suite reruns passed 1,428 tests after the build; native interaction/finalization reruns passed 38 tests. A seven-suite diagnostic rerun passed 463 tests and isolated the remaining path and PostgreSQL setup failures. - With `TMPDIR=/private/tmp`, workspace, gateway, interaction, and attachment suites passed all 356 tests. The remaining environment-image and native-session-resumption suites passed all 44 tests with the same canonical temp path. All affected suites passed on rerun. The original full local command was stopped after failures and is not claimed as passing. - All 55 PR checks passed at `83281439456181396f3707eecda5d2ebc90bd14d`. Greptile scored 5/5 with no open review threads. - No paid live campaign or Product E2E browser suite was run. This change has protocol and regression coverage; it does not claim improved task quality. ## Risks - Stock Codex behavior may differ from behavior under the previous Paperclip replacement prompt. Restoring that behavior is the intended change. - Existing Codex threads retain their saved replacement base prompt. They need a provider session reset to receive the stock base. This PR does not reset active sessions or alter recovery rules. - The legacy `baseInstructions` option and trace field names remain for compatibility. They now describe the additive Paperclip fragment for Codex. - The separate Codex-through-ACP dependency patch remains a follow-up in the harness coverage checklist. This PR covers native app-server execution. ## Model Used OpenAI Codex, GPT-6. The exact runtime model variant and context window are not exposed in this session. Used reasoning, repository inspection, code editing, shell execution, and test tools. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
c46e41e81c |
fix(heartbeat): validate native MCP gateway ownership (#14914)
## Thinking Path > - Paperclip lets people manage agents and govern their tool access. > - Native runs receive an immutable MCP tool assignment for one agent. > - The gateway must enforce that owner when it authenticates a run token. > - Older gateway rows stored the owner only in metadata. > - This change validates the gateway and profile, binds new rows, and repairs valid older rows on reuse. > - It also delivers each native assignment once. > - Other agents cannot use the assignment, and explicit shared gateways keep their configured scope. ## Linked Issues or Issue Description Builds on #14012 by @busla (Jón Levy). That PR adds agent binding and seven regressions. This PR carries that fix onto current master and adds legacy authentication, profile validation, and duplicate-delivery coverage. Related: #14864 improves discovery memory use. **What happened?** Native gateway creation stored an owner in metadata but left `agentId` null. Authentication could therefore accept another agent's run token. Managed discovery could also deliver historical native assignments again. **Expected behavior** A native assignment accepts only its owner's run token. The gateway and profile must refer to the same immutable assignment. The current assignment enters the run configuration once. **Steps to reproduce** 1. Run the database fixtures in `heartbeat-runtime-mcp-servers.test.ts` on the baseline. 2. Create a native assignment and inspect its stored gateway owner. 3. Authenticate with another agent's run token, then inspect legacy reuse and managed delivery. 4. The baseline fails six ownership and delivery cases. The fix passes all twelve cases. **Paperclip version or commit** The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which includes the merged discovery fix. **Deployment mode** Native Paperclip Runner execution and managed Codex MCP delivery. Reproduction uses isolated database and HTTP fixtures. ## What Changed - Store the agent owner and agent context on new native gateways. - Validate profile and gateway assignment metadata before reuse or token creation. - Bind valid legacy rows with a company-scoped, null-owner update and validate the result. - Reject mismatched run tokens before legacy repair. - Identify native assignments by gateway metadata, the reserved profile key, or profile source. Reject missing or malformed provenance, including JSON null. - Exclude historical native assignments from managed gateway delivery. Keep their rows for existing runs. - Add twelve database and HTTP regressions and document the runtime contract. ## Verification - Red baseline: six regressions fail and four controls pass before the initial fix. Two additional regressions reproduce metadata-loss admission and a JSON-null TypeError before the review fix. - All twelve ownership regressions pass on the final code, including owner admission, cross-agent rejection, metadata loss, JSON-null HTTP 401, and explicit shared-gateway admission. Policy, listing-memory, and discovery HTTP coverage also passes. - Full workspace typecheck and build pass locally. Server typecheck and compilation pass again after the review fix. The final ownership and grant patches pass 42 combined database and HTTP regressions. - [Full CI](https://github.com/paperclipai/paperclip/actions/runs/37011383657) passes for `626a08ae66361cf586105877e24d806b1a7a9c20`: all 54 checks succeed; two optional Storybook checks skip. This includes full typecheck, build, all test shards, all eight E2E shards, runner verification, and the canary dry run. - Greptile scores that exact head 5/5. No review threads remain unresolved. ## Risks Invalid historical native gateway or profile metadata now rejects authentication. Valid unbound rows are repaired only when their owner reuses the assignment. Conflicting owners are never overwritten. Historical rows are retained for existing runs. Explicit shared gateways use ordinary profiles and keep their configured scopes. The reserved native profile namespace remains agent-owned even when gateway metadata is cleared. No schema or dependency changes are included. ## Model Used Original fix and seven regressions in #14012: Anthropic Claude Opus 5.5, `claude-opus-5-5`, 1M context, as reported by @busla. Extensions and verification: OpenAI Codex (GPT-6), with reasoning, repository inspection, code execution, and tests. This session does not expose the exact serving model identifier or context window. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.9 |
||
|
|
483dbc8890 |
fix(tool-access): enforce stored grant restrictions (#14915)
## Thinking Path > - Paperclip governs the tools that agents can discover and call. > - Stored grants can limit access to a tool, connection, or application. > - The grant matcher must enforce every restriction in that scope. > - A nonmatching allow list fell through to a policy selector matcher that ignores allow. > - This change requires an explicit allow match and validates additional selectors. > - Malformed and unknown restrictions deny access. > - Discovery and execution now enforce the same stored grant limits. ## Linked Issues or Issue Description Related: #14864 adds the shared database and HTTP discovery fixture used here. Searched existing public PRs for tool grant scope fixes. No duplicate scope-validation fix was found. **What happened?** A stored grant with a nonmatching `scope.allow` could authorize a tool. Empty or malformed allow lists, unknown selectors, and combined mismatching selectors could also authorize access. The fallback policy matcher does not validate stored grant JSON. **Expected behavior** An explicit allow list must match the requested tool, connection, or application. Every additional selector must also match. Unknown or malformed restrictions must deny access. Existing null and empty-object scopes keep their broad grant behavior. **Steps to reproduce** 1. Run `tool-grant-scope.test.ts` on the baseline. 2. Create a deny profile and a grant that names another tool. 3. Attempt discovery or a call for the tool outside the grant. 4. The baseline authorizes access. The fix denies it. **Paperclip version or commit** The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which includes the merged discovery fix. **Deployment mode** The company-scoped MCP gateway. Reproduction uses isolated database fixtures and a deterministic HTTP provider. ## What Changed - Require an explicit allow entry to match the gateway or upstream tool name, connection, or application. - Apply all additional selectors after the allow match. - Reject unknown selectors, invalid value types, empty restrictions, and non-object scopes. - Preserve null and empty-object scope compatibility. - Add sixteen regressions, including discovery, successful execution, and revocation through the HTTP gateway. - Document stored grant scope behavior. ## Verification - Red baseline: seven restricted-scope cases and three malformed-root cases fail. HTTP discovery also exposes tools outside the grant. - All 16 grant regressions and 35 adjacent policy tests pass locally. The HTTP test excludes an ungranted tool from discovery, returns 403 for its call, and verifies that no provider call occurs. It also checks successful execution and later revocation. - Server typecheck passes. The final ownership and grant patches also pass 42 combined database and HTTP regressions. - [Full CI](https://github.com/paperclipai/paperclip/actions/runs/37011177989) passes for `803fa9440111742672c94c4471e5b98f15dd3b97`: all 54 checks succeed; two optional Storybook checks skip. This includes full typecheck, build, all test shards, all eight E2E shards, runner verification, and the canary dry run. - Greptile scores that exact head 5/5. No review threads remain unresolved. ## Risks Stored scopes with unknown keys or malformed restrictions now deny access. Operators must correct those grants before they can authorize tools. Null and empty-object scopes keep their previous broad behavior. There are no schema, dependency, or API changes. ## Model Used OpenAI Codex (GPT-6), with reasoning, repository inspection, code execution, database regressions, and HTTP tests. This session does not expose the exact serving model identifier or context window. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
cad26c6bfb |
fix(tool-gateway): bound MCP discovery memory and concurrency (#14864)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents discover governed tools through the MCP gateway. > - A listing repeated policy and full run-row reads for each catalog tool. > - Parallel listings multiplied those allocations during run startup. > - One 900-tool baseline listing used 11,489 queries and about 1.7 GiB of extra heap in a fixture. > - This pull request shares reads within a listing and bounds whole listings across the process. > - The benefit is lower discovery memory use while execution still checks current policy. ## Linked Issues or Issue Description Refs #13115. Its on-demand target change affects the same listing loop. **What happened?** MCP discovery repeated roughly 13 reads per tool. Full run snapshots and repeated connection configurations caused large allocations. Per-listing bounds alone did not limit concurrent listings across gateways. **Expected behavior** Discovery reads shared inputs once per listing. The process bounds active and queued listings. Catalog payload size and policy evaluation still grow with the catalog. Tool execution checks current access rules. **Steps to reproduce** Create a company with a remote MCP connection, 900 catalog tools, large schemas, and a large run snapshot. Send concurrent tools/list requests using a run-bound gateway token. Run the committed benchmark for a deterministic reproduction. **Paperclip version or commit** Baseline:canary/v2026.1002.0-canary.8 |
||
|
|
c83df091b1 |
build(deps): bump react-i18next from 17.0.12 to 17.0.15 (#12970)
Bumps [react-i18next](https://github.com/i18next/react-i18next) from 17.0.12 to 17.0.15. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md">react-i18next's changelog</a>.</em></p> <blockquote> <h2>17.0.15</h2> <ul> <li>fix(Trans): empty paired component tags now preserve a component's single valid React-element child, whether supplied through a named component map (<code><wrap></wrap></code>), a component array (<code><0></0></code>), or indexed JSX children (<code><1></1></code>). This matches the existing behavior for two or more children and self-closing tags. React represents one JSX child as an element and multiple children as an array; the previous array-only check silently rendered the one-child case empty. Compatibility note: when that sole element contains an interpolation object, the restored raw children can expose an existing React rendering limitation as an error instead of silently rendering empty; the same shape already errors with two children. Fixes <a href="https://redirect.github.com/i18next/react-i18next/issues/1932">#1932</a>.</li> </ul> <h2>17.0.14</h2> <ul> <li>fix: the <code>i18n</code> object returned by <code>useTranslation</code> was only refreshed when <code>i18n.language</code> changed, so a <code>resolvedLanguage</code> (or <code>languages</code>) change of its own kept handing components the previous snapshot. That happens whenever the translations for the current language arrive after the switch — i18next resolves to the fallback until its store has them — and components reading <code>i18n.resolvedLanguage</code> (language switchers, for example) then stayed one switch behind. The cached wrapper is now keyed on all three language fields, which are exactly the ones the surrounding <code>useMemo</code> already depends on; wrapper identity still only changes when the language state does, so the caching from <a href="https://redirect.github.com/i18next/react-i18next/issues/1885">#1885</a> is unaffected. Reported via <a href="https://redirect.github.com/i18next/next-i18next/issues/2348">next-i18next#2348</a>.</li> </ul> <h2>17.0.13</h2> <ul> <li>fix(types): the selector-form <code>keyPrefix</code> overload of <code>useTranslation()</code> is now available under <code>enableSelector: 'strict'</code>. <code>useTranslation</code> was gated on <code>true | 'optimize'</code> only, so under <code>'strict'</code> it resolved to the legacy signature and the selector overload disappeared entirely (<code>keyPrefix: ($) => $.ns.foo</code> failed with <code>Type '($: any) => any' is not assignable to type 'undefined'</code>). <code>Trans</code> already handled all three modes. Companion to the same fix for <code>getFixedT</code> in <a href="https://redirect.github.com/i18next/i18next/pull/2446">i18next#2446</a>. Thanks <a href="https://github.com/hovelopin"><code>@hovelopin</code></a> (<a href="https://redirect.github.com/i18next/react-i18next/pull/1930">#1930</a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/i18next/react-i18next/commit/7d38e0919507f0d339ac29b9fbd5f718eaadc829"><code>7d38e09</code></a> 17.0.15</li> <li><a href="https://github.com/i18next/react-i18next/commit/875b327d3515c781cd083dd77d3d8838dc1efc06"><code>875b327</code></a> fix(Trans): preserve single-element children in empty slots</li> <li><a href="https://github.com/i18next/react-i18next/commit/5f8c5f9e6c7cdabdc476111d0748c91e33bbaa30"><code>5f8c5f9</code></a> 17.0.14</li> <li><a href="https://github.com/i18next/react-i18next/commit/6def81a790ddc55cc6c09a9f306ea6c88e25867c"><code>6def81a</code></a> fix: refresh the returned i18n wrapper when resolvedLanguage changes</li> <li><a href="https://github.com/i18next/react-i18next/commit/f37ea872c74e74ca64a5b6652cc131893405770b"><code>f37ea87</code></a> docs: "For AI assistants" paragraph in the README</li> <li><a href="https://github.com/i18next/react-i18next/commit/e0592bafde1a904588c115f67b36cddf382e49c5"><code>e0592ba</code></a> chore: keep dev-only and local files out of the npm package</li> <li><a href="https://github.com/i18next/react-i18next/commit/addf646a37f5980af08814b5a2568def28e7e428"><code>addf646</code></a> 17.0.13</li> <li><a href="https://github.com/i18next/react-i18next/commit/7c634ee3f396af22ec7b5c3c647b8d5ab198b5ae"><code>7c634ee</code></a> changelog v17.0.13</li> <li><a href="https://github.com/i18next/react-i18next/commit/5ceefb0eff8bb430c658b21e5a08b457e78d87df"><code>5ceefb0</code></a> fix(types): allow selector keyPrefix in useTranslation under enableSelector '...</li> <li><a href="https://github.com/i18next/react-i18next/commit/aa7ba520255753c50d7fff9ab33ce0c7a60a45a2"><code>aa7ba52</code></a> chore(examples): require activesupport >= 7.2.3.1 in the RN Gemfiles</li> <li>Additional commits viewable in <a href="https://github.com/i18next/react-i18next/compare/v17.0.12...v17.0.15">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>nightly/v2026.1002.0-nightly.0 canary/v2026.1002.0-canary.7 |
||
|
|
f48bbba2ba |
build(deps): bump @assistant-ui/react from 0.15.21 to 0.15.22 (#12971)
Bumps [@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react) from 0.15.21 to 0.15.22. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/releases">@assistant-ui/react's releases</a>.</em></p> <blockquote> <h2><code>@assistant-ui/react</code><a href="https://github.com/0"><code>@0</code></a>.15.22</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a> - fix: type the assistant transport request body that <code>prepareSendCommandsRequest</code> receives; its fields are no longer <code>unknown</code> in <code>@assistant-ui/react</code>, and <code>threadId</code> is an optional <code>string</code>, absent when a resume has no remote id, instead of <code>string | null</code> (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a> - feat: <code>useAssistantTransportRuntime</code> accepts <code>cloud</code>: Assistant Cloud backs the thread list and every request carries the cloud thread id; without <code>cloud</code>, <code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as it does for <code>useLocalRuntime</code>. <code>adapters.history</code>, which this runtime never read, is deprecated (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a> - fix: lock the current scroll container after reasoning content or its ancestor chain changes (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a> - fix: prevent stale message hover updates after unmount (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a> - fix: scope selection toolbars to their owning thread (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a> - feat: <code>CloudRendererHost</code> draws a stored conversation in the Assistant Cloud dashboard's As shown view with the app's own components; a read only thread now reports itself disabled, so its composer renders disabled, and ignores composer input instead of throwing (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a> - feat: show a message with uploading attachments in the thread while it is being sent (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>MessagePrimitive.Attachments</code> now hands its render function <code>Attachment</code> rather than <code>CompleteAttachment</code>, because the row of a message that is still being sent shows attachments that are still uploading. a render function that reads <code>attachment.content</code> should check <code>attachment.status.type === "complete"</code> first.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a> - fix: honor registered data-part fallbacks on native MessageContent and grouped parts (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a> - fix: emit declarations from one TypeScript program so two builds of the same commit produce the same <code>.d.ts</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>aui-build</code> now emits the unbundled <code>.d.ts</code> output in one TypeScript pass over the whole package, so two builds of the same commit produce identical declarations; the per-module emit it replaced followed the bundler's load order and let union member order, alias visibility and import specifiers move between builds. Declarations import barrels as the source does and keep <code>import type</code>; the exported types are unchanged. A <code>/// <reference></code> directive that must reach the published declarations now carries <code>preserve="true"</code> in the source.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a> - fix: every distribution re-exports the same shared surface from <code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code> gains <code>ReadonlyThreadProvider</code>, <code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>, <code>GroupByContext</code>, <code>VoiceSessionState</code>, the external store runtime (<code>useExternalStoreRuntime</code>, <code>useExternalMessageConverter</code>, their adapters and options), the message queue, the tool approval types, the generative UI renderer and the cloud thread list hooks; <code>@assistant-ui/react-native</code> gains <code>VoiceSessionState</code>, the cloud thread list hooks, the generative UI renderer and the runtime state and adapter types the web package already carried; <code>@assistant-ui/react</code> gains <code>MessageRole</code>, <code>RunConfig</code>, <code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>, <code>ThreadsState</code>, <code>JoinStrategy</code>, <code>TitleGenerationAdapter</code>, <code>createSimpleTitleAdapter</code> and <code>ChainOfThoughtPartByIndexProvider</code>. (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a> - fix(react): attach the ExportMarkdown download anchor to the document so Firefox starts the download (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a> - fix: prevent disabled attachment dropzones from navigating to dropped files. (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a> - fix: clear attachment drag state when the dropzone is disabled (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a> - fix(react): stop a pending bottom scroll from hijacking keyboard-driven content growth (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a> - fix: resolve component registries by own keys only, so a component, tool or data part name that only <code>Object.prototype</code> has (<code>toString</code>, <code>constructor</code>, <code>__proto__</code>) takes the <code>Fallback</code> or <code>GenerativeUIRenderError</code> path instead of rendering the inherited built-in (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a> - fix: expose feedback submission state to assistive technology (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a> - feat: name the runtime state types <code>ThreadRuntimeState</code>, <code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>, <code>AttachmentRuntimeState</code> and <code>ThreadListItemRuntimeState</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>these are the states <code>ThreadRuntime</code>, <code>MessageRuntime</code>, <code>ComposerRuntime</code>, <code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code> return from <code>getState()</code>, now exported by all three distributions; <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code> had no name for them. in <code>@assistant-ui/react</code>, <code>ThreadState</code>, <code>MessageState</code>, <code>ComposerState</code>, <code>AttachmentState</code> and <code>ThreadListItemState</code> still name these runtime states but are deprecated: from 0.16 they name the store states <code>useAuiState</code> reads, as they already do in <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code>. code that annotates a runtime's <code>getState()</code> result should move to the new names.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a> - fix(react): keep the selection toolbar in sync after a right-click, so a context menu that swallows the mouseup no longer leaves it showing (and quoting) the previous selection (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a> - feat: a tool UI can record what the user did on its tool call with <code>unstable_recordInteraction</code>, kept on the part as <code>unstable_interactions</code> and stored in cloud history; the answer to a human input request is recorded once the runtime accepts it, the local runtime persists records and keeps them out of model input, external stores receive them through <code>unstable_onRecordToolInteraction</code>, and readonly threads ignore them (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a> - fix: Use successful Standard Schema output for tool execution and model output. Keep the original arguments for validation errors and stored tool calls. (<a href="https://github.com/ephraimduncan"><code>@ephraimduncan</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7777">#7777</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/c51ba8fb3014375ae62784084aaefe3ecc6d72fa"><code>c51ba8f</code></a> - feat(core): let typed text enter a connected voice session through <code>sendText</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@assistant-ui/react's changelog</a>.</em></p> <blockquote> <h2>0.15.22</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a> - fix: type the assistant transport request body that <code>prepareSendCommandsRequest</code> receives; its fields are no longer <code>unknown</code> in <code>@assistant-ui/react</code>, and <code>threadId</code> is an optional <code>string</code>, absent when a resume has no remote id, instead of <code>string | null</code> (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a> - feat: <code>useAssistantTransportRuntime</code> accepts <code>cloud</code>: Assistant Cloud backs the thread list and every request carries the cloud thread id; without <code>cloud</code>, <code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as it does for <code>useLocalRuntime</code>. <code>adapters.history</code>, which this runtime never read, is deprecated (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a> - fix: lock the current scroll container after reasoning content or its ancestor chain changes (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a> - fix: prevent stale message hover updates after unmount (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a> - fix: scope selection toolbars to their owning thread (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a> - feat: <code>CloudRendererHost</code> draws a stored conversation in the Assistant Cloud dashboard's As shown view with the app's own components; a read only thread now reports itself disabled, so its composer renders disabled, and ignores composer input instead of throwing (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a> - feat: show a message with uploading attachments in the thread while it is being sent (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>MessagePrimitive.Attachments</code> now hands its render function <code>Attachment</code> rather than <code>CompleteAttachment</code>, because the row of a message that is still being sent shows attachments that are still uploading. a render function that reads <code>attachment.content</code> should check <code>attachment.status.type === "complete"</code> first.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a> - fix: honor registered data-part fallbacks on native MessageContent and grouped parts (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a> - fix: emit declarations from one TypeScript program so two builds of the same commit produce the same <code>.d.ts</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>aui-build</code> now emits the unbundled <code>.d.ts</code> output in one TypeScript pass over the whole package, so two builds of the same commit produce identical declarations; the per-module emit it replaced followed the bundler's load order and let union member order, alias visibility and import specifiers move between builds. Declarations import barrels as the source does and keep <code>import type</code>; the exported types are unchanged. A <code>/// <reference></code> directive that must reach the published declarations now carries <code>preserve="true"</code> in the source.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a> - fix: every distribution re-exports the same shared surface from <code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code> gains <code>ReadonlyThreadProvider</code>, <code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>, <code>GroupByContext</code>, <code>VoiceSessionState</code>, the external store runtime (<code>useExternalStoreRuntime</code>, <code>useExternalMessageConverter</code>, their adapters and options), the message queue, the tool approval types, the generative UI renderer and the cloud thread list hooks; <code>@assistant-ui/react-native</code> gains <code>VoiceSessionState</code>, the cloud thread list hooks, the generative UI renderer and the runtime state and adapter types the web package already carried; <code>@assistant-ui/react</code> gains <code>MessageRole</code>, <code>RunConfig</code>, <code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>, <code>ThreadsState</code>, <code>JoinStrategy</code>, <code>TitleGenerationAdapter</code>, <code>createSimpleTitleAdapter</code> and <code>ChainOfThoughtPartByIndexProvider</code>. (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a> - fix(react): attach the ExportMarkdown download anchor to the document so Firefox starts the download (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a> - fix: prevent disabled attachment dropzones from navigating to dropped files. (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a> - fix: clear attachment drag state when the dropzone is disabled (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a> - fix(react): stop a pending bottom scroll from hijacking keyboard-driven content growth (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a> - fix: resolve component registries by own keys only, so a component, tool or data part name that only <code>Object.prototype</code> has (<code>toString</code>, <code>constructor</code>, <code>__proto__</code>) takes the <code>Fallback</code> or <code>GenerativeUIRenderError</code> path instead of rendering the inherited built-in (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a> - fix: expose feedback submission state to assistive technology (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a> - feat: name the runtime state types <code>ThreadRuntimeState</code>, <code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>, <code>AttachmentRuntimeState</code> and <code>ThreadListItemRuntimeState</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>these are the states <code>ThreadRuntime</code>, <code>MessageRuntime</code>, <code>ComposerRuntime</code>, <code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code> return from <code>getState()</code>, now exported by all three distributions; <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code> had no name for them. in <code>@assistant-ui/react</code>, <code>ThreadState</code>, <code>MessageState</code>, <code>ComposerState</code>, <code>AttachmentState</code> and <code>ThreadListItemState</code> still name these runtime states but are deprecated: from 0.16 they name the store states <code>useAuiState</code> reads, as they already do in <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code>. code that annotates a runtime's <code>getState()</code> result should move to the new names.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a> - fix(react): keep the selection toolbar in sync after a right-click, so a context menu that swallows the mouseup no longer leaves it showing (and quoting) the previous selection (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a> - feat: a tool UI can record what the user did on its tool call with <code>unstable_recordInteraction</code>, kept on the part as <code>unstable_interactions</code> and stored in cloud history; the answer to a human input request is recorded once the runtime accepts it, the local runtime persists records and keeps them out of model input, external stores receive them through <code>unstable_onRecordToolInteraction</code>, and readonly threads ignore them (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a> - fix: Use successful Standard Schema output for tool execution and model output. Keep the original arguments for validation errors and stored tool calls. (<a href="https://github.com/ephraimduncan"><code>@ephraimduncan</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/f008537f39f0936992b0f6d2433c092935df5faf"><code>f008537</code></a> chore: update versions (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7724">#7724</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a> feat(react): CloudRendererHost draws a stored conversation in the dashboard's...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a> fix(react): keep the selection toolbar quoting what is selected after a right...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a> feat(core): record the user's interactions with a tool ui on its tool call (#...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a> feat(core): show a message with uploading attachments while it is sent (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8030">#8030</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a> fix: type the assistant transport body that prepareSendCommandsRequest receiv...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a> fix(react): claim file drops when attachment dropzone is disabled (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8010">#8010</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a> feat: name the runtime state types and deprecate their old names (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7981">#7981</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/15937b8844db7757d3595d5644bc27196e742f4a"><code>15937b8</code></a> test(react): skip the initial viewport scroll in the MessageRoot hover test (...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a> fix(react): cancel pending bottom scroll on a keyboard gesture (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7897">#7897</a>)</li> <li>Additional commits viewable in <a href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.22/packages/react">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.6 |
||
|
|
3934fd14e5 |
build(deps-dev): bump @storybook/addon-docs from 10.5.10 to 10.6.0 (#12972)
Bumps [@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs) from 10.5.10 to 10.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-docs's releases</a>.</em></p> <blockquote> <h2>v10.6.0</h2> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the `@storybook/angular-vite` peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve `@angular/core` through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder `styles` the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-docs's changelog</a>.</em></p> <blockquote> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the <code>@storybook/angular-vite</code> peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve <code>@angular/core</code> through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder <code>styles</code> the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Stop marking a defaulted input as required in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a> Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a> Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a> Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a> Bump version from "10.6.0-beta.0" to "10.6.0-beta.1" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a> Bump version from "10.6.0-alpha.9" to "10.6.0-beta.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a> Bump version from "10.6.0-alpha.8" to "10.6.0-alpha.9" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a> Bump version from "10.6.0-alpha.7" to "10.6.0-alpha.8" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/3bf4afdce8aba47cc7960d3a3e09a3fd1ceb2baa"><code>3bf4afd</code></a> Merge branch 'next' into kasper/tools-cli-bootstrap-perf</li> <li><a href="https://github.com/storybookjs/storybook/commit/4ea0b1bc2c1a26ce061f5b44051e8f01273f27fa"><code>4ea0b1b</code></a> refactor(docs): move anchorBlockIdFromId into docs-tools</li> <li><a href="https://github.com/storybookjs/storybook/commit/5c80681f18d273461e1b15cb775a77347079b0b0"><code>5c80681</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35965">#35965</a> from storybookjs/valentin/sb-1804-surface-story-doc...</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/docs">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4e52463203 |
fix(daytona): recover output from stalled log streams (#14889)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Daytona driver streams sandbox command output to the host. > - A log socket can stop delivering bytes without closing or rejecting. > - Missing permission requests and cancellation results can leave a run active and block queued work. > - This pull request switches an idle log stream to saved-output polling for the same command. > - The host can receive the missing output without another command dispatch. ## Linked Issues or Issue Description **What happened?** The driver waits for the SDK log-stream promise before it can start recovery. If that promise never settles, the host can miss new output that is already in the provider's saved logs. A run can remain active after a watch completes. Interrupt can then time out with “Execution is still stopping; termination has not been verified.” **Expected behavior** Recover command observation when the live stream stalls. Forward new permission requests and cancellation results. Require a recorded command exit before reporting completion. Keep quiet commands running under the caller's existing lifetime controls. **Steps to reproduce** 1. Start a session command and leave the callback log promise pending. 2. Put new output in the snapshot API without invoking the stream callback. 3. Keep the command running until the host receives that output, then expose its cancellation output and exit code. 4. Verify that the host receives each byte once and dispatches the command once. **Paperclip version or commit** Base commit `479554120d`. **Agent adapter(s) involved** Daytona session commands, including sandbox ACP agent sessions. Related: #14799 handles closed streams; this change handles sockets that never close. #14485 handles input delivery retries. #13262 adds permission diagnostics. ## What Changed - After 15 seconds with no stdout or stderr, switch directly to the existing status and log-snapshot polling path. - Ignore callbacks and delayed failures from the abandoned stream. Clear its idle timer on every exit path. - Preserve byte-offset deduplication, one command dispatch, and independent timeouts for recovery reads. - Add regressions for an initial stream stall, a stall after UTF-8 output, cancellation output, late callbacks, hung recovery reads, and quiet commands that outlive an operation timeout. - Update the provider documentation and keep hour-long healthy-stream coverage active with periodic output. ## Verification - `pnpm vitest run packages/plugins/sandbox-providers/daytona/src/plugin.test.ts`: 245 passed. - `pnpm exec vitest run --project @paperclipai/plugin-daytona`: 339 passed; 14 gated live tests skipped. - Both new stalled-stream regressions fail on the unchanged base driver because it never starts snapshot recovery. Both pass with this change. - `pnpm -r typecheck`: passed. - `pnpm build`: passed. - `pnpm test:run`: the local run did not pass. It was stopped after confirmed local skill-path and macOS skill-cache failures, once complete PR CI was green. Four chat/email tests could not load connector skill files from an ancestor directory outside the checkout. Three company-skills tests hit macOS `EACCES` during cache publication. One unrelated wakeup test timed out in the full run and passed on a focused rerun (`1 passed`, `27 skipped`). No source or test assertions were changed for these failures. This is not a complete local-suite pass. - Complete PR CI on `11ac4e030b`: 53 successful checks, 2 expected skips, no pending or failed checks. The clean CI run includes the full test suite. - Greptile reviewed `11ac4e030b` at 5/5 with no findings or unresolved threads. The branch has no merge conflicts with `master`. - `git diff --check` and a local scan for secrets and private identifiers passed. ## Risks - Quiet healthy commands also switch to polling. Full snapshots can increase bandwidth as output grows; polling remains limited to one snapshot per second. - The SDK exposes no stream cancellation handle. The old socket remains owned by session teardown, and its callbacks cannot publish after fallback. - This change recovers a stalled output stream. It does not claim to identify every cause of an unanswered permission request or change the requirement to verify termination before releasing work. - No schema migration or command replay. ## Model Used OpenAI GPT-6 through Codex, with tool use and code execution. The exact serving model ID and context window are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run local change-specific tests; the full suite passes in CI, with local-suite limitations documented above - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.5 |
||
|
|
261c24ccf9 |
docs(release): canonicalize stable notes for v2026.1001.0 (#14890)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release process keeps stable notes under a beta-keyed path during the soak and renames them to the versioned path after the stable ships > - Stable v2026.1001.0 is published. The `canonicalize_stable_notes` job pushed the rename branch but it does not open a pull request > - The published notes also have no Contributors section. The previous stable notes (v2026.916.0) have one > - This pull request moves the notes to `releases/v2026.1001.0.md` and adds the Contributors section > - The benefit is that the repository returns to the canonical release-notes layout and the external contributors get credit ## Linked Issues or Issue Description **Issue type** Missing content **Where is the issue?** `releases/` — the stable notes for v2026.1001.0 still live at the beta-keyed path `releases/beta/v2026.921.0-beta.1.md`, and they have no Contributors section. **What's wrong?** The `canonicalize_stable_notes` job in the stable release run pushed branch `release-notes/v2026.1001.0-canonicalize` with the rename, but it does not open a pull request. The notes also do not credit the three external contributors in the release range. **Suggested fix** Merge the workflow's rename commit, plus one commit that appends a `## Contributors` section in the same format as `releases/v2026.916.0.md`. ## What Changed - Renamed `releases/beta/v2026.921.0-beta.1.md` to `releases/v2026.1001.0.md` (workflow commit, no content changes) - Appended a `## Contributors` section: 77 commits from 8 contributors, with credits to @austinpilz, @hawikk, and @mouse-value-add - No other content changed. The notes above the new section match the published GitHub Release body for v2026.1001.0 ## Verification - `git log --follow releases/v2026.1001.0.md` shows the rename commit followed by one commit that only appends the Contributors section - `git rev-list --count v2026.916.1..v2026.1001.0` returns 77 - The author list of that range, minus maintainers and bots, is @austinpilz, @hawikk, and @mouse-value-add - The GitHub Release body for v2026.1001.0 is identical to this file without the Contributors section ## Risks - Low risk: a documentation-only rename plus one appended section. ## Model Used - Claude (Anthropic), model ID `claude-fable-5-1` (Claude Fable 5.1), extended thinking enabled, tool use via Claude Code ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.4 |
||
|
|
479554120d |
build(deps): bump i18next from 26.4.0 to 26.4.2 (#12973)
Bumps [i18next](https://github.com/i18next/i18next) from 26.4.0 to 26.4.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/releases">i18next's releases</a>.</em></p> <blockquote> <h2>v26.4.2</h2> <ul> <li>fix: <code>$&</code>, <code>$`</code>, <code>$'</code> and <code>$$</code> inside a nested value (<code>$t(key)</code>) now stay literal. <code>nest()</code> handed the resolved value straight to <code>String.replace</code> as the replacement argument, so those sequences were read as replacement patterns: <code>$&</code> re-inserted the <code>$t(...)</code> match, <code>$`</code> / <code>$'</code> inserted the text before / after it, and <code>$$</code> collapsed to <code>$</code>. Through <code>t()</code> the <code>$&</code> case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted <code>$t(...)</code> was matched again on every pass and <code>t()</code> never returned — also under the default <code>escapeValue: true</code> when the value arrives via a variable forwarded through nesting options (<code>$t(key, { "name": "{{name}}" })</code> with a name containing <code>$&</code>). The value is now <code>$</code>-escaped at the <code>String.replace</code> call, the same guard <code>interpolate()</code> already has, and a non-string value returned by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is stringified before that. Nested values are still not HTML-escaped (<a href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>). Thanks <a href="https://github.com/mahirhir"><code>@mahirhir</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li> </ul> <h2>v26.4.1</h2> <ul> <li>fix(types): the selector-form <code>keyPrefix</code> overload of <code>getFixedT()</code> is now available under <code>enableSelector: 'strict'</code>. Its constraint was gated on <code>true | 'optimize'</code> only, so under <code>'strict'</code> it collapsed to <code>never</code>, the overload dropped out, and the returned <code>t</code> silently lost its <code>keyPrefix</code> scope (<code>t(($) => $.deep)</code> failed with <code>Property 'deep' does not exist on type '{}'</code>). The same call already typechecked under <code>true</code> and <code>'optimize'</code>. Thanks <a href="https://github.com/hovelopin"><code>@hovelopin</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's changelog</a>.</em></p> <blockquote> <h2>26.4.2</h2> <ul> <li>fix: <code>$&</code>, <code>$`</code>, <code>$'</code> and <code>$$</code> inside a nested value (<code>$t(key)</code>) now stay literal. <code>nest()</code> handed the resolved value straight to <code>String.replace</code> as the replacement argument, so those sequences were read as replacement patterns: <code>$&</code> re-inserted the <code>$t(...)</code> match, <code>$`</code> / <code>$'</code> inserted the text before / after it, and <code>$$</code> collapsed to <code>$</code>. Through <code>t()</code> the <code>$&</code> case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted <code>$t(...)</code> was matched again on every pass and <code>t()</code> never returned — also under the default <code>escapeValue: true</code> when the value arrives via a variable forwarded through nesting options (<code>$t(key, { "name": "{{name}}" })</code> with a name containing <code>$&</code>). The value is now <code>$</code>-escaped at the <code>String.replace</code> call, the same guard <code>interpolate()</code> already has, and a non-string value returned by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is stringified before that. Nested values are still not HTML-escaped (<a href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>). Thanks <a href="https://github.com/mahirhir"><code>@mahirhir</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li> </ul> <h2>26.4.1</h2> <ul> <li>fix(types): the selector-form <code>keyPrefix</code> overload of <code>getFixedT()</code> is now available under <code>enableSelector: 'strict'</code>. Its constraint was gated on <code>true | 'optimize'</code> only, so under <code>'strict'</code> it collapsed to <code>never</code>, the overload dropped out, and the returned <code>t</code> silently lost its <code>keyPrefix</code> scope (<code>t(($) => $.deep)</code> failed with <code>Property 'deep' does not exist on type '{}'</code>). The same call already typechecked under <code>true</code> and <code>'optimize'</code>. Thanks <a href="https://github.com/hovelopin"><code>@hovelopin</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da"><code>4dba50f</code></a> 26.4.2</li> <li><a href="https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009"><code>e436b62</code></a> build</li> <li><a href="https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92"><code>d955fb0</code></a> fix: stringify formatter results in nested values, changelog v26.4.2</li> <li><a href="https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425"><code>dfafa3c</code></a> fix: keep replacement patterns literal in nested values (<a href="https://redirect.github.com/i18next/i18next/issues/2447">#2447</a>)</li> <li><a href="https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a"><code>3c9981e</code></a> chore: keep dev-only and local files out of the npm package</li> <li><a href="https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8"><code>c057ee0</code></a> 26.4.1</li> <li><a href="https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2"><code>02e3e16</code></a> changelog v26.4.1</li> <li><a href="https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751"><code>6f198f2</code></a> fix(types): allow selector keyPrefix in getFixedT under enableSelector 'stric...</li> <li>See full diff in <a href="https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.3 |
||
|
|
b31ce54b81 |
build(deps): bump react-router-dom from 7.18.2 to 7.18.4 (#12974)
Bumps [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) from 7.18.2 to 7.18.4. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md">react-router-dom's changelog</a>.</em></p> <blockquote> <h2>v7.18.4</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies: <ul> <li><a href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.4"><code>react-router@7.18.4</code></a></li> </ul> </li> </ul> <h2>v7.18.3</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies: <ul> <li><a href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.3"><code>react-router@7.18.3</code></a></li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a> Release v7.18.4 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li> <li><a href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a> Release v7.18.3 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15424">#15424</a>)</li> <li>See full diff in <a href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4a999089ef |
Retry transient failures in dashboard reads (#14873)
## Thinking Path > - Paperclip shows company activity in the dashboard. > - The dashboard reads company, task, approval, and cost data. > - A pooled database connection can close during one of these reads. > - The driver must reject ambiguous statements because writes may have committed. > - These four dashboard queries are known to be read-only. > - This change retries only the failed read and preserves completed work. ## Linked Issues or Issue Description Refs #14773, which correctly removed automatic replay of ambiguous database statements. Searched existing database and dashboard PRs. Related #8780 changes pool recycling and logging; #13925 adds dashboard consistency coverage. Neither provides these per-query retries. **What happened?** A dashboard request returns a server error when its company lookup, task count, approval count, or monthly spend query loses its database connection. Drizzle wraps the driver's connection error in `cause`. **Expected behavior** A transient connection failure gets a bounded retry of the specific read. Completed reads and budget processing are not replayed. Persistent outages and non-connection errors still fail the request. **Steps to reproduce** Inject a typed `CONNECTION_CLOSED` error into one of these reads. Then allow the next query to succeed. Before this change, the dashboard request fails immediately. ## What Changed - Apply independent retries to the company lookup, task counts, pending approval count, and monthly spend query. Each callback rebuilds its own query with the same company scope. - Extract the existing authentication retry helper as `retryIdempotentDatabaseOperation`. Preserve authentication behavior and its existing exports. - Retain the existing limit of three total attempts with 50 ms and 100 ms pauses. Match typed connection codes through the error cause chain. - Test later-read failures, unchanged query parameters, retry exhaustion, missing companies, and errors that must not retry. Document the boundary. ## Verification - Final focused dashboard, authentication, and real database wire suites: 38 tests passed. Six initial recovery regressions failed before the implementation. - `pnpm -r typecheck`: passed on the final source. - Independent review: no actionable findings. The reviewer separately passed all 38 focused tests and checked the code allowlist, attempt bounds, pauses, and final error identity. - `pnpm test:run`: the general-server group completed with 14,738 tests passed, 13 failed, and 87 skipped. All 13 failures match the previously reproduced clean-base macOS skill-cache failures. The two test files and their implementations are unchanged from that baseline. The runner exited after this group, so the remaining local workspace and serialized groups did not run. All corresponding Linux CI groups passed on this commit. - `pnpm build`: passed on the final source. - Full CI: 53 successful checks and 2 skips on `6a113529c0`. Greptile: 5/5 on that commit, with no review threads or remaining findings. - Merge compatibility with master `f2e0f19630`, including #14866: no conflicts. The five reviewed files are unchanged in the resulting merge tree. ## Risks A persistent outage adds at most two retries per covered query. Each connection attempt retains the configured driver timeout. The change does not repair the underlying network or database failure. Agent counts, run-activity queries, and the budget workflow stay outside these retry boundaries. General database statements and disconnected transactions are not replayed. There is no schema or authorization change. ## Model Used OpenAI GPT-6 through Codex, with reasoning, repository inspection, code editing, and test execution. The runtime does not expose a more specific serving model identifier or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (38 focused tests; the full local run has the baseline limitation documented above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
40c8468e98 |
build(deps-dev): bump agentmail from 0.5.20 to 0.5.31 (#12975)
Bumps [agentmail](https://github.com/agentmail-to/agentmail-node) from 0.5.20 to 0.5.31. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/be477c3e9d07de608d94daa3f2235c46456758ad"><code>be477c3</code></a> Release 0.5.31</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/553d6a62e10a95c73a87d47b8b1125f716dfb1f2"><code>553d6a6</code></a> Release 0.5.30</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/a53948be57e396a8d08344e9d43ee191ae747fd9"><code>a53948b</code></a> Release 0.5.29</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/f2b4bb9a452a7343dc0eb6f20a07882d7364b211"><code>f2b4bb9</code></a> Release 0.5.28</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/d2c56f73735ed917961e1a16273a9320de6c21cd"><code>d2c56f7</code></a> Release 0.5.27</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/df2a12427b4e988024787167e6732bd1d1c5b9ff"><code>df2a124</code></a> Release 0.5.26</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/4ae0b9b2eeda5c65beb9fa4a3601a1a44f10947d"><code>4ae0b9b</code></a> Release 0.5.25</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/dc085581668947a177f5a087c4f78cf1b75dd2e8"><code>dc08558</code></a> Release 0.5.24</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/47210d91803f65b2ebf9ec8d1ae546a050e3d8bc"><code>47210d9</code></a> Release 0.5.23</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/0c5f98ff97a492ab77e9c688d3374548d9dd997a"><code>0c5f98f</code></a> Release 0.5.22</li> <li>Additional commits viewable in <a href="https://github.com/agentmail-to/agentmail-node/compare/0.5.20...0.5.31">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.2 |
||
|
|
427e048405 |
fix(company-skills): approve managed-checkout project dirs for local skill import (#10329)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Company skills can be imported into a company from a local folder;
`companySkillService.importFromSource` guards this with
`assertLocalImportSourceAllowed`, which only permits import sources
inside an approved set of roots (managed skills root + registered
project-workspace cwds), realpath-resolved and `${root}${sep}`-anchored
to prevent path traversal/escape
> - A project can exist as a `managed_checkout` (server-managed clone)
with **no registered `project_workspaces` row** — its `primaryWorkspace`
is `null` and `workspaces` is `[]`, so its only real on-disk location is
the server-derived `codebase.managedFolder`
> - Because `configuredRoots` was built solely from the managed skills
root and `workspaces[].cwd`, a `managed_checkout` project's
`managedFolder` was never an approved root, so importing a skill from
that project's own folder was rejected with
`skill_workspace_boundary_denied`
> - This PR adds each project's server-derived `codebase.managedFolder`
to `configuredRoots` so in-place skill imports from managed-checkout
projects are allowed
> - The benefit is that managed-checkout projects can re-import their
own skills in place, without weakening the traversal/escape protections
(the new roots are server-derived and matched exactly like the existing
ones)
## Linked Issues or Issue Description
No public GitHub issue. Describing in-PR (bug):
**What's wrong:** `assertLocalImportSourceAllowed` denies a legitimate
local skill import (`skill_workspace_boundary_denied`) for any project
that is a `managed_checkout` with no registered workspace row.
**Repro:** Create/import a company skill from a `managed_checkout`
project's own folder (`codebase.managedFolder/.agents/skills/<skill>`).
The import is rejected even though the source is inside the project's
server-managed checkout.
**Expected:** The import from a managed-checkout project's own
`managedFolder` subtree should be allowed, while paths outside that
subtree remain denied.
Related context (already merged): #9564 introduced the open-by-default
skill policy / this import boundary. This PR does not change that
boundary's matching logic — it only adds a missing, server-derived
approved root.
## What Changed
- `server/src/services/company-skills.ts`: add
`...projectRows.map((project) => project.codebase.managedFolder)` to
`configuredRoots` in `assertLocalImportSourceAllowed`. `managedFolder`
is server-derived (`resolveManagedProjectWorkspaceDir(companyId,
projectId)` → instance root + sanitized ids); it is
`fs.realpath`-resolved and `${root}${sep}`-prefix matched exactly like
every existing root. `managedFolder` is used rather than
`effectiveLocalFolder` because the latter can fall through to a
user-registered `localFolder`, which is already covered by the
registered workspace cwds.
- `server/src/__tests__/company-skill-import-boundary.test.ts`: add a
regression test — a managed-checkout project's `managedFolder/<skill>`
import is **allowed**, and a **prefix-adjacent sibling** (`managedFolder
+ "-evil"`) stays **denied**.
## Verification
- `cd server && ./node_modules/.bin/vitest run
src/__tests__/company-skill-import-boundary.test.ts` → **2/2 pass**
(embedded-Postgres suite). Covers both the new allow case and the
prefix-adjacent deny case, alongside the existing out-of-tree /
symlink-escape / non-file-scheme rejections.
## Risks
Low risk. The change only **adds** approved roots; it does not alter the
realpath + `${root}${sep}`-anchored matching that closes
traversal/prefix-adjacency escapes. The added roots are fully
server-derived from the instance root + sanitized company/project ids
(same trust class as the existing `resolveManagedSkillsRoot`) — no value
derived from the import `source` argument reaches them. Sanitization
(`[^a-zA-Z0-9._-]+ → -`) prevents separator/level injection, and the
only user-influenced segment (repo name) is normalized via `new
URL(...)`. The regression test's prefix-adjacent (`-evil`) case asserts
the escape class stays closed.
## Model Used
Claude Opus 4.8 (`claude-opus-4-8`), extended thinking + tool use (code
execution, git). Implementation and security review were produced with
Claude; this integration/PR was prepared with `claude-opus-4-8`.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes (N/A —
internal boundary fix, no user-facing docs)
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green (CI in progress)
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(pending review)
- [x] I will address all Greptile and reviewer comments before
requesting merge
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: brandonburr <brandonburr@gmail.com>
canary/v2026.1002.0-canary.1
|
||
|
|
5207c78f21 |
docs(release): align 2026.921.0-beta.1 stable notes header with v2026.1001.0 (#14882)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Releases are published by `release.yml`. A stable release promotes a soaked beta, and the stable notes live on master in `releases/beta/v<beta>.md` until the promotion runs. > - The curated notes for `2026.921.0-beta.1` have the title `Paperclip v2026.924.0` and the date `2026-09-24`. That stable did not ship. No `v2026.924.0` tag or release exists. > - The next promotion of this beta uses `stable_date=2026-10-01`. `scripts/release.sh stable --print-version --date 2026-10-01` resolves to `2026.1001.0`. > - `publish_stable` reads this file verbatim and uses it as the GitHub Release body. `canonicalize_stable_notes` copies it to `releases/v2026.1001.0.md`. Nothing rewrites the header. > - This pull request updates the title, the release date, and the intro sentence to `v2026.1001.0` and `2026-10-01`. > - The benefit is a GitHub Release page and a canonical notes file that show the correct version and date. ## Linked Issues or Issue Description **Describe the documentation problem** The stable notes file `releases/beta/v2026.921.0-beta.1.md` names a stable version and release date that do not match the version the release workflow will publish. **Where is the problem** `releases/beta/v2026.921.0-beta.1.md`, lines 1, 3, and 5. **Proposed fix** Change `v2026.924.0` to `v2026.1001.0` and `2026-09-24` to `2026-10-01` in the three places that name the version or date. Change nothing else in the file. ## What Changed - Title: `# Paperclip v2026.924.0` → `# Paperclip v2026.1001.0` - Release date: `> Released: 2026-09-24` → `> Released: 2026-10-01` - Intro sentence: `Paperclip v2026.924.0 carries 77 commits` → `Paperclip v2026.1001.0 carries 77 commits` ## Verification - `git diff master --stat` shows one file with 3 insertions and 3 deletions. - `grep -n '924' releases/beta/v2026.921.0-beta.1.md` returns no lines. - `git show master:scripts/release.sh > /tmp/r.sh && bash /tmp/r.sh stable --print-version --date 2026-10-01` prints `2026.1001.0`. - The rest of the file is byte-identical to master. ## Risks - Low risk. This is a documentation-only change to a release notes file. No code or workflow changes. - If the stable promotion is dispatched with a different `stable_date`, the header must be updated again to match. ## Model Used - Claude Fable 5.1 (model ID `claude-fable-5-1`), run as a Paperclip agent through the Claude Agent SDK, with tool use (shell, git, GitHub CLI). No extended thinking mode was configured beyond the default. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [ ] I have added or updated tests where applicable (not applicable: documentation-only change) - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Bender (Fable) <noreply@paperclip.ing> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>canary/v2026.1002.0-canary.0 |
||
|
|
f07f8d9599 |
build(deps-dev): bump @storybook/addon-a11y from 10.5.10 to 10.6.0 (#12976)
Bumps [@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y) from 10.5.10 to 10.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-a11y's releases</a>.</em></p> <blockquote> <h2>v10.6.0</h2> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the `@storybook/angular-vite` peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve `@angular/core` through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder `styles` the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-a11y's changelog</a>.</em></p> <blockquote> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the <code>@storybook/angular-vite</code> peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve <code>@angular/core</code> through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder <code>styles</code> the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Stop marking a defaulted input as required in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a> Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a> Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a> Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a> Bump version from "10.6.0-beta.0" to "10.6.0-beta.1" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a> Bump version from "10.6.0-alpha.9" to "10.6.0-beta.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a> Bump version from "10.6.0-alpha.8" to "10.6.0-alpha.9" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a> Bump version from "10.6.0-alpha.7" to "10.6.0-alpha.8" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/898f0ce828ec8bd00985934786724b94f8428c42"><code>898f0ce</code></a> Bump version from "10.6.0-alpha.6" to "10.6.0-alpha.7" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/cf97b46ca1a452f6f47206fd6ed7043a88e38a60"><code>cf97b46</code></a> Bump version from "10.6.0-alpha.5" to "10.6.0-alpha.6" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/2b7f6be9c96f72d6eca4b80af11db1a4ff380e8e"><code>2b7f6be</code></a> Bump version from "10.6.0-alpha.4" to "10.6.0-alpha.5" [skip ci]</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/a11y">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
41c18aa443 |
build(deps-dev): bump storybook from 10.5.10 to 10.6.0 (#12984)
Bumps [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) from 10.5.10 to 10.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">storybook's releases</a>.</em></p> <blockquote> <h2>v10.6.0</h2> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the `@storybook/angular-vite` peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve `@angular/core` through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder `styles` the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's changelog</a>.</em></p> <blockquote> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the <code>@storybook/angular-vite</code> peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve <code>@angular/core</code> through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder <code>styles</code> the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Stop marking a defaulted input as required in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a> Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a> Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/db38cb39d9be5609bba4ac3b861b2263c21ae1b6"><code>db38cb3</code></a> CLI: Serve skills through one path with a single expected-failure channel</li> <li><a href="https://github.com/storybookjs/storybook/commit/79bc6a63e0ecd6eb10baecb6302661da09eea1f7"><code>79bc6a6</code></a> CLI: Address review on skills reshape; credit skills --all in eval parser</li> <li><a href="https://github.com/storybookjs/storybook/commit/c11b0f2a6eb1e15b489a8c0bc17c5eace4c8a8b5"><code>c11b0f2</code></a> CLI: Drop per-skill --help; --help always prints the catalog</li> <li><a href="https://github.com/storybookjs/storybook/commit/c878263a6ced94ef30148b99758bea139122f5de"><code>c878263</code></a> CLI: Drop skills get/list, add skills --all</li> <li><a href="https://github.com/storybookjs/storybook/commit/c55462ef810dcf5641636a54021861f5d1d90222"><code>c55462e</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/36117">#36117</a> from storybookjs/kasper/tools-record-storybook-path</li> <li><a href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a> Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8ad41c80847390d53af17342e33c94d0f87bb368"><code>8ad41c8</code></a> CLI: Reject surplus skills arguments</li> <li><a href="https://github.com/storybookjs/storybook/commit/8d607e3b18731f63e09d23ad488623f0c01224bd"><code>8d607e3</code></a> Tools: Match Storybook installations correctly on Windows</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/core">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |