Files
Devin FoleyandPaperclip 7eadc714d2 Verify native semantic input against its raw wire digest (#15301)
## Thinking Path

> - Paperclip manages AI agents and their work.
> - Native runners send authenticated semantic tool inputs to the
control plane.
> - The runner hashes the complete input, but the receiver used a
redacted receipt hash.
> - Protected fields and credential-like document text can therefore
fail integrity validation even when the input is unchanged.
> - This pull request verifies the complete input with the existing
canonical hash function.
> - Receipt redaction and permanent rejection of altered input remain in
place.

## Linked Issues or Issue Description

**What happened?**

The Rust runner preserves tool arguments and hashes their canonical
JSON. The TypeScript receiver instead redacts the input before hashing.
A valid input such as a synthetic document containing `Bearer
fixture_token_123456` fails with `native_event_replay_conflict`. A
digest of redacted input can also pass without proving the original
protected values.

**Expected behavior**

Verify the complete transmitted input after authentication and exact
scope checks. Reject any incorrect digest before durable commit,
dispatch, or ACK.

**Steps to reproduce**

Run the new authenticated controller regressions against the prior
receiver. The protected-field and credential-like document cases fail,
and the redacted-digest rejection case receives an ACK. The same tests
pass with this change.

**Paperclip version or commit**

Reproduced from source at `858094ba8123c7edb56623597cd96f0391f7e2d4`
with synthetic fixtures. Applies to native runner deployments.

Related: #14937 preserves semantic input bytes for execution. GitHub
issue and PR searches found no duplicate fix; #14591 touches a separate
question-draft contract.

## What Changed

- Use the existing bounded raw canonical digest for incoming semantic
and MCP tool inputs.
- Keep receipt and diagnostic redaction unchanged.
- Share four digest fixtures between Rust and the authenticated
TypeScript controller, including protected fields, document text,
Unicode keys, and number boundaries.
- Test raw acceptance, altered protected values, forged and redacted
digests, canonicalization limits, permanent reconnect fences, and
authentication/scope rejection.
- Document the separate wire and receipt contracts and the unchanged
recovery fence.

## Verification

- Before the production fix, the new selected regressions produced three
expected failures and eight passes.
- Focused controller, receipt, and semantic-tool suites: 138 tests
passed.
- Rust shared digest fixture test: 1 test passed.
- Full workspace typecheck and build passed; the final receiver delta
also passed its TypeScript typecheck. Canonical Linux PR CI passed the
full aggregate test gate, runner checks, build, and canary dry run at
`efcd38e2d8a9fa6340db4f4e863b6febbe8ca32a`.
- Independent review passed, including 18 independently run
authenticated regressions and the Rust golden test, plus both
matching-digest size-limit cases after the test-only follow-up. Greptile
is 5/5 on the current head with no unresolved threads. Diff whitespace
and local secret/PII scan passed; fixtures are synthetic.

## Risks

The verifier remains strict: there is no redacted-digest fallback.
Existing authentication, scope, sequence, replay, settlement, and
authorization checks remain in force. Receipt storage and redaction
behavior are unchanged. This patch does not clear failed-run fences or
replay prior work. Synthetic tests prove the protocol mismatch; they do
not identify the contents of any historical rejected input.

## Model Used

OpenAI Codex (GPT-6), with reasoning, code execution, and independent
agent review. The exact serving model identifier and context-window size
are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 20:21:01 -07:00
..