Keep runtime-owned command snapshots reusable until cleanup and observe optional prompt-start rejection without hiding it from callers.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Use the same controller-owned runner file for identity and remote staging, including packaged server vendor layouts.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Record controller-owned rotation events and require an exact run transition before accepting a new process fingerprint. Preserve stable sandbox, runner and provider-session checks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Expose the existing finalization timestamp through the scoped sync API and reject periodic-only or out-of-run saves.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Accept bounded Codex deprecation notices after a settled turn and require that capability before reusing a sandbox image runner. Stage replacement artifacts atomically so existing launchers and image symlink targets survive interrupted uploads.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bind validated OpenCode result notifications to the active provider process and turn, matching semantic tool responses. Reproduce the live shutdown failure and verify exact durable authority after interruption.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Mock the native shutdown boundary in the startup unit test and wait for the persisted process identity before allowing the runtime readiness fixture to listen.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Park idle native sandbox sessions before app shutdown, adopt retained legacy workspaces without restaging Git, and carry explicitly bound GitHub access through both OpenCode launch filters.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Validate paginated legacy lease candidates before choosing a workspace, preserving Postgres timestamp precision. Recover failed saves through a new authorized run and cover post-save finalization failures without replaying terminal cleanup.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bundle the task disposition helper with the installed Paperclip skill. Retry transient read-only file transfers within a fixed deadline and retain sandbox RPC caller provenance for staging failure diagnosis.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Recognize dispatched pre-folder runs and v1 leases while excluding new scoped preparation failures from the compatibility path.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Select Codex ACP's full-access initial mode only for host-validated external work-folder environments with approve-all authority. Keep local and restrictive permission modes unchanged. The regression failed before the fix; all 50 ACP environment and runtime tests pass.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep established tasks on their original filesystem and session layout. Recover version-1 lease identity from host run records, preserve configuration checks, and retain old work when ownership or resume cannot be verified.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reproduce Codex plugin-cache repositories with real Git and preserve private-runtime exclusions before validating directory entries.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep custom profile-provided runtimes available while restoring the projected Git launcher before agent startup.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
A failed final flush does not erase an earlier successful periodic checkpoint. Cover interrupted continuations and replacement sandboxes for both saved and failed prior runs.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Report incomplete terminal saves without hiding the latest successful checkpoint, including same-sandbox continuation and replacement failures.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Fail before editing repository state if the remote cannot be read, and reject credential or PATH workarounds during model-driven acceptance.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Align durable journal validation with the transport bound, preserve authorization on cached storage clients, and avoid Cloud session gates for native Git callbacks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>