mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-09 06:15:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Paperclip Runner gives an agent a durable execution boundary. > - The Codex transport can now advertise a run-scoped semantic tool catalog. > - The durable backend did not yet persist tool calls or correlate their results. > - A restart could therefore lose the boundary between a provider call and a Paperclip action. > - This pull request binds authorized calls, durable events, results, replay, and cancellation. > - The benefit is safe semantic tool recovery without duplicate Paperclip actions. ## Linked Issues or Issue Description Refs #12382 **What existing behavior does this improve?** This improves the durable Codex provider backend in `@paperclipai/paperclip-runner`. **Current behavior** The Codex transport can project authorized dynamic tools. The durable backend rejects their calls because it cannot persist and recover their identities. **Proposed behavior** The durable backend records each authorized call before it emits the semantic input event. It records each result before it sends the result to Codex. It reconciles exact provider replays without another Paperclip action. **Reason and benefit** This order prevents duplicate semantic actions after a process restart. It also keeps unauthorized, changed, oversized, and late calls closed. **Breaking changes** None. A run without an authorized tool catalog still starts Codex with no dynamic tools. ## What Changed - Persist the authorized tool catalog with the Codex provider state. - Emit correlated and redacted semantic input, reconciliation, and result events. - Reconcile exact pending and completed calls after a provider restart. - Reject catalog drift, changed replay input, malformed results, and unauthorized operations. - Complete pending tool calls with a durable failure when a turn stops. - Bound retained tool values and validate recovered state before provider startup. - Bind production runner events to the active run, session, turn, and item identities. ## Verification - `cargo fmt --all -- --check` - `cargo test --workspace` - `pnpm -r typecheck` - `pnpm build` - Confirmed that the PR changes 9 files against `runner-codex-dynamic-tools`. - Confirmed that dependency installation did not change `pnpm-lock.yaml`. ## Risks The main risk is a mismatch between recovered provider state and the controller tool catalog. Recovery validates the complete catalog and its digest before Codex starts. The backend persists a call before it emits work and persists a result before it returns the result to Codex. This PR does not enable the server adapter or change any direct adapter path. ## Model Used OpenAI Codex with GPT-5 and repository tool use. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge