Files
PaperClipAI/doc
DottaandPaperclip 94f6f3eb47 fix: recover historical interrupted native preparation (#15020)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - A task conversation must accept new user input after an interrupted
startup.
> - Native startup begins with a legacy preparation row before runtime
selection.
> - Older builds did not retain the startup cancellation receipt on that
row.
> - The immutable adapter claim and expired controller can still prove
that no provider started.
> - This pull request uses that narrow proof for explicit Retry and
saved user input.
> - The benefit is a conversation that recovers after an upgrade without
repeating old work.

## Linked Issues or Issue Description

Refs #15015. Related #13293 covers retained process evidence after
provider startup. This change covers interrupted preparation before
native runtime selection.

**What happened?**

After an upgrade, a task stopped during native preparation can still
show automatic recovery stopped. A new user message saves but does not
start. Retry is absent because the historical run has no cancellation
receipt.

**Expected behavior**

Offer Retry and admit new user input when immutable run evidence proves
that no provider started and cleanup is complete. Preserve incomplete or
contradictory evidence as a recovery hold.

**Steps to reproduce**

1. Retain a cancelled run with the Paperclip Runner adapter claim, an
unresolved runtime, and the preparing stage.
2. Keep its old controller boot ID and expired lease. Retain no native
identity, coordinator, result, process identity, or provider events.
3. Upgrade from a build that did not save the startup cancellation
receipt.
4. Send a new user message or select Retry. Confirm that one fresh turn
starts.
5. Repeat with an active controller, a provider launch, or unfinished
cleanup. Confirm that execution stays held.

**Paperclip version or commit**

Reproduced on `cc67d4e1d` with a historical interrupted preparation row.

**Deployment mode**

Authenticated private self-hosted server, built from source.

## What Changed

- Recognize historical interrupted native preparation from immutable run
evidence and an expired controller from another server boot.
- Reject adapter invocation evidence in the startup proof. Keep process
and environment cleanup checks.
- Apply the same proof to saved user messages in the bounded recovery
worker.
- Recheck saved-message eligibility under the existing task and run
locks. Keep normal ownership, decision, pause, and budget gates.
- Add regression tests for Retry, a new message, concurrent
saved-message recovery, and contradictory evidence. Document the
compatibility rule.

## Verification

- Red: Retry, new-message recovery, and saved-message recovery fail on
the parent commit.
- Green: 185 continuation tests, 335 process-recovery tests, and 78
queued-comment route tests pass. Two additional red regressions cover
partially delivered saved queues and pass after the admission fix.
- Workspace `pnpm -r typecheck` and `pnpm build` pass.
- Final head `48db53f4f`: all 54 CI checks pass; two optional Storybook
checks skip. Greptile is 5/5 with zero unresolved threads.
- The local monolithic `pnpm test:run` was stopped after CI passed. One
unrelated workspace case failed in that long run; all three workspace
reconciliation cases pass in isolation. No complete local monolithic
pass is claimed.
- After merge, deploy the exact merged commit and verify recovery
through the normal task composer.

## Risks

Historical compatibility could grant a new turn without enough startup
evidence. The proof requires an immutable native adapter claim, an
unresolved preparing stage, no result or native identity, an expired
controller from another server boot, and no invocation or provider
evidence. Environment cleanup remains mandatory. The fix does not replay
old input or change historical run results. No schema or dependency
change.

## Model Used

OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and
context window are not exposed in this session. Used reasoning,
repository tools, code execution, and browser inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 23:08:05 -05:00
..
…