Commit Graph

4150 Commits

Author SHA1 Message Date
Dotta 5e3a9b50d9 test(runner): acknowledge terminal result delivery 2026-09-03 00:01:17 -05:00
Dotta 5835c98675 fix(runner): preserve ACPX command attestation 2026-09-02 23:57:10 -05:00
Dotta d2c9977065 fix(runner): acknowledge terminal transitions durably 2026-09-02 23:57:10 -05:00
Dotta a02087a5c1 fix(runner): project ACPX session identity 2026-09-02 23:46:08 -05:00
Dotta d582fbe1aa fix(runner): reconcile terminal result delivery 2026-09-02 23:38:26 -05:00
Dotta 76c82e642c fix(runner): project ACPX bridge tool catalog 2026-09-02 23:34:27 -05:00
Dotta a8ef9b8715 fix(runner): preserve trusted ACPX terminal catalog 2026-09-02 23:26:01 -05:00
Dotta 1b07b5a58b test(runner): wait for Codex tool completion 2026-09-02 23:18:25 -05:00
Dotta 32b1124242 fix(runner): stop after terminal result delivery failure 2026-09-02 23:06:59 -05:00
Dotta 156c913779 fix(runner): read ACPX output error codes 2026-09-02 23:00:28 -05:00
Dotta 534ce69adb fix(runner): stop after delivered terminal results 2026-09-02 22:59:09 -05:00
Dotta c8598416ef fix(runner): persist terminal lifecycle before delivery 2026-09-02 22:51:42 -05:00
Dotta b4e83ab3cc fix(runner): traverse ACPX error causes safely 2026-09-02 22:44:48 -05:00
Dotta 4ac656e8d4 fix(runner): preserve ACPX failure detail codes 2026-09-02 22:26:09 -05:00
Dotta f6f2d02b5d fix(runner): classify ACPX session ensure failures 2026-09-02 22:14:14 -05:00
Dotta 21bc0eba68 fix(runner): surface ACPX admission classifications 2026-09-02 21:48:45 -05:00
Dotta 6cba271e65 fix(runner): restore ACPX backend identity fallback 2026-09-02 21:37:34 -05:00
Dotta 9611da2b38 fix(runner): classify ACPX admission failures 2026-09-02 21:29:45 -05:00
Dotta d49c011403 fix(runner): verify ACPX model from durable state 2026-09-02 21:14:27 -05:00
Dotta d60306420d fix(runner): retain bounded ACPX startup diagnosis 2026-09-02 20:58:45 -05:00
Dotta e9998cbfdb fix(runner): preserve verified runtime across descendants 2026-09-02 20:50:25 -05:00
Dotta 492ba3a46b fix(runner): mirror Codex runtime profile in runnerd 2026-09-02 20:31:48 -05:00
Dotta 12fdb57ec8 fix(runner): qualify Codex ACP runtime executable 2026-09-02 20:23:30 -05:00
Dotta 805177f7d6 fix(runner): preserve provider startup classifications 2026-09-02 19:55:26 -05:00
Dotta ec9297bef7 Revert "fix(deps): lock Claude ACP 0.73 patch"
This reverts commit 1b8aa9765f.
2026-09-02 19:38:28 -05:00
Dotta 1b8aa9765f fix(deps): lock Claude ACP 0.73 patch 2026-09-02 19:35:13 -05:00
Dotta 2ffcc0104a Merge remote-tracking branch 'origin/master' into fix/runner-paid-matrix-integrity
* origin/master:
  fix(onboarding): preserve draft through company refetch (#12735)
  feat(codex-local): give each Codex account its own home and path secret (#12709)
  feat(claude-local): add Claude Fable 5.1 support (#12730)
2026-09-02 19:32:45 -05:00
Dotta 0d8accea8c fix(runner): classify bounded ACPX startup failures 2026-09-02 19:32:40 -05:00
Dotta 464bcfec26 fix(runner): scope verified runtime inheritance 2026-09-02 19:29:03 -05:00
Dotta cf8e7d475a test(runner): match macOS verified runtime snapshot 2026-09-02 19:13:40 -05:00
Dotta b8e26f101e fix(runner): preserve verified runtime for provider descendants 2026-09-02 19:12:41 -05:00
Dotta 325e1e813d fix(runner): load sealed CommonJS entrypoints by descriptor 2026-09-02 19:00:11 -05:00
Dotta 7c85257f66 fix(runner): track closed ACPX input portably 2026-09-02 18:48:04 -05:00
Dotta 476ca3d877 fix(runner): close ACPX sidecar stdin cleanly 2026-09-02 18:45:12 -05:00
Dotta 16e165d958 fix(runner): define descriptor bundle module URL 2026-09-02 18:40:38 -05:00
Dotta d414396011 fix(runner): compile descriptor bundles without import meta 2026-09-02 18:37:44 -05:00
Dotta 62b79deb20 fix(runner): restore verified JS provider startup 2026-09-02 18:32:59 -05:00
Dotta 96fcadeb51 fix(runner): load sealed Node entrypoints as ESM 2026-09-02 18:13:54 -05:00
Dotta 8d36deaa72 fix(runner): scope verified ESM mode to Node 2026-09-02 18:00:27 -05:00
Dotta 03bab72ee8 fix(runner): restore verified native provider startup 2026-09-02 17:23:10 -05:00
Dotta 910de2f2f1 test(runner-e2e): pin Plan terminal response 2026-09-02 17:06:56 -05:00
Dotta 0d1f36d493 ci(runner): qualify hosted Node interpreter 2026-09-02 17:05:44 -05:00
Dotta 4999e47762 test(runner-e2e): bind governed waits to interactions 2026-09-02 16:56:35 -05:00
Dotta 3e18f10060 fix(runner-e2e): honor governed wait boundaries 2026-09-02 16:55:16 -05:00
Dotta 84f1fa89b4 fix(runner): secure bundled provider entrypoints 2026-09-02 16:55:16 -05:00
Dotta 8c89340444
fix(onboarding): preserve draft through company refetch (#12735)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Onboarding creates an organization in the browser.
> - The browser keeps onboarding drafts for the same origin.
> - A new data directory does not clear that browser data.
> - The organization create request refreshes the company list.
> - The old gate unmounted the live wizard during that refresh.
> - This pull request keeps the wizard mounted after its first draft
check.
> - The customer can continue to the agent step after the organization
is created.

## Linked Issues or Issue Description

No matching public issue was found. Related earlier fix: Refs #12667.

**What happened?**

A local canary install could create an organization through the API and
then return the browser to an empty organization-name screen.

**Expected behavior**

The wizard must continue to the agent step after it creates the
organization.

**Steps to reproduce**

1. Keep a Paperclip onboarding draft in the browser.
2. Run npx paperclipai@canary onboard with a new data directory.
3. Open /onboarding.
4. Enter an organization name and select Continue.

**Paperclip version or commit**

2026.902.0-canary.7. The fix is based on current master.

**Deployment mode**

Local trusted mode through the Paperclip CLI.

**Install method**

npx package install.

**Agent adapter(s) involved**

Not adapter-specific.

**Database mode**

Embedded PostgreSQL.

## What Changed

- Keep the onboarding wizard mounted after its first successful draft
ownership check.
- Keep a failed ownership check retryable, so a later verified fetch
restores the saved draft.
- Add component, source E2E, and published-canary coverage for the
retained-draft refetch case.

## Verification

- Confirmed that the new canary scenario fails against
2026.902.0-canary.7 before this fix.
- pnpm exec vitest run ui/src/components/OnboardingWizard.test.tsx
- PAPERCLIP_E2E_PORT=3245 pnpm exec playwright test --config
tests/e2e/playwright.config.ts tests/e2e/onboarding.spec.ts
--reporter=line
- pnpm --filter @paperclipai/ui typecheck
- pnpm check:token-gates

## Risks

Low risk. The initial ownership check still waits for a fresh company
list. A later successful retry can restore a retained draft. Later
background refetches preserve live wizard state.

## Model Used

OpenAI Codex, GPT-5. Reasoning, tool use, code editing, terminal
execution, and browser testing were used. The execution environment does
not expose a context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used with version and capability
details
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have described the issue in-PR following the bug issue template
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-02 16:50:15 -05:00
Nicky Leach 9064cfd09e
feat(codex-local): give each Codex account its own home and path secret (#12709)
## Thinking Path

> - Paperclip is the control plane for companies that use AI agents for
work
> - Local adapters connect Paperclip agents to provider command line
tools
> - The Codex adapter stores login data in a shared company home
> - A shared home cannot keep credentials for more than one Codex
account
> - This pull request gives each account a safe home and a matching
company secret
> - The benefit is that one company can use multiple Codex accounts at
the same time

## Linked Issues or Issue Description

**Problem or motivation**

A company can hold only one Codex subscription credential because device
login uses one shared home. A second account cannot log in without
replacing or conflicting with the first credential.

**Proposed solution**

This change validates the vendor account identifier, stores each
credential in its own home, and creates a company secret that points to
that home. Repeat login calls return success when the matching secret
already exists.

**Roadmap alignment**

The change supports the roadmap goal for centrally managed secrets with
scoped access and audited resolution.

**Additional context**

The security review returned approve with no blocking finding. The
branch adds shared account-handle validation and tests for device login
and the Codex local adapter.

## What Changed

- Add strict allowlist validation for Codex account handles.
- Store each Codex account credential in a separate home under the Codex
cache root.
- Verify that the resolved account home stays inside the cache root.
- Create the `CODEX_HOME_<handle>` company secret for each account.
- Keep repeat and concurrent login calls safe and idempotent.
- Add shared helper and route, adapter, and validation tests.

## Verification

- `pnpm --filter @paperclipai/adapter-codex-local test` passes with 343
tests.
- `pnpm --filter @paperclipai/server test
src/__tests__/agent-device-login-routes.test.ts` passes with 25 tests.
- The adapter suite passes with 23 tests.
- The shared package and Codex adapter typechecks pass.
- Continuous integration must pass on every check before merge.

## Risks

The account handle becomes part of a directory path and secret name. The
strict allowlist and root containment check reduce path traversal risk.
Existing single-account homes remain unchanged unless a new device login
creates an account-specific home.

## Model Used

OpenAI GPT-5 (exact runtime model ID: gpt-5), with tool use and code
execution. The runtime context window is not exposed in this run.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-02 14:46:53 -07:00
Dotta e04611d65d fix(runner-e2e): align restart control directory 2026-09-02 16:39:56 -05:00
Dotta dfe7aaf26e fix(runner): stop after failed lifecycle commands 2026-09-02 16:34:24 -05:00
Michael Nguyen dfdfc8664e
feat(claude-local): add Claude Fable 5.1 support (#12730)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Claude local adapter lets operators select a Claude model for an
agent.
> - Claude Fable 5.1 was absent from the adapter model lists.
> - The adapter runtime also used a Claude Code build that rejected
Fable 5.1.
> - This pull request adds the direct Anthropic ID and the AWS Bedrock
inference profile ID.
> - It also updates the Claude ACP runtime and keeps the Paperclip usage
and isolation patches.
> - The benefit is that operators can select and run Claude Fable 5.1
through the Claude adapter.

## Linked Issues or Issue Description

Refs #8810. That issue covers related model ID handling. This change
does not change provider-prefixed model IDs.

**Agent or provider**

Claude Code through the built-in `claude_local` adapter. The requested
model is Claude Fable 5.1.

**Why this adapter is useful**

Operators can use Fable 5.1 without entering an undocumented model ID.
The configured model also reaches both supported Claude execution lanes.

**How the agent is invoked**

The CLI lane sends `--model claude-fable-5-1`. The ACP lane sends
`ANTHROPIC_MODEL=claude-fable-5-1` to
`@agentclientprotocol/claude-agent-acp`.

**Are you willing to implement it?**

Yes. This pull request includes the implementation and tests.

**Additional context**

Claude Code 2.1.232 rejected Fable 5.1 and required version 2.1.251 or
newer. ACP package 0.73.0 includes Claude Code 2.1.257. The update keeps
Paperclip's usage metadata and isolated-context behavior.

## What Changed

- Added `claude-fable-5-1` to the direct Claude fallback list.
- Added `us.anthropic.claude-fable-5-1` to the AWS Bedrock list.
- Kept the existing default model at the first position in each list.
- Updated the Claude ACP dependency from 0.70 to 0.73.
- Carried the Paperclip usage and isolated-context changes into the 0.73
patch.
- Added a Claude Code 2.1.251 minimum-version preflight for Fable 5.1
when using the standard `claude` executable, surfaced in both adapter
Test and execution. Explicit custom wrappers retain their existing
compatibility contract.
- Kept local adapter Tests from executing caller-selected binaries: when
runtime `PATH` selects a different Claude executable than the trusted
probe, the Test warns and defers the authoritative version check to
execution instead of approving or rejecting the alternate installation.
- Added tests for model listing, discovery deduplication, Bedrock
filtering, model pass-through in both execution lanes, old-CLI rejection
before launch, custom-wrapper compatibility, and local runtime-PATH
mismatch handling.

## Verification

- `pnpm --filter @paperclipai/adapter-claude-local typecheck`
- `pnpm exec vitest run
packages/adapters/claude-local/src/server/execute.remote.test.ts
packages/adapters/claude-local/src/server/test.remote.test.ts
packages/adapters/claude-local/src/server/test.probe.test.ts
packages/adapters/claude-local/src/server/acp.test.ts
server/src/__tests__/adapter-models.test.ts` (72 tests passed)
- `node --test scripts/acpx-patch-packaging.test.mjs` (13 tests passed)
- `pnpm -r typecheck`
- `pnpm build`
- A local Paperclip agent run completed with `usageJson.model` set to
`claude-fable-5-1` through ACP 0.73.0 and its bundled Claude Code
2.1.257.
- `pnpm test:run` completed 5,638 passing tests and 24 skipped tests. It
also found 24 failures in unrelated workspace-runtime,
path-canonicalization, and runtime-exposure tests on macOS with Node 26.
These failures do not touch this diff. Clean pull request CI is the
final full-suite gate.

## Risks

- The ACP dependency update can change Claude runtime behavior outside
model selection. Focused ACP tests, the full typecheck, the production
build, and a real local Fable run reduce this risk.
- The 0.73 patch must stay aligned with the installed ACP version.
Dependency-resolution CI verifies the manifest and patch pair.
- Fable 5.1 adds a short `claude --version` preflight to standard
CLI-lane Tests and runs. The result is intentionally not cached so an
in-place Claude Code upgrade takes effect without restarting Paperclip.
Explicit custom wrappers are not version-probed because their output and
compatibility contract can differ from the standard executable.
- Local Tests preserve the existing deny-by-default probe boundary and
do not execute a binary selected by caller-controlled `PATH`. A
mismatched runtime binary produces an explicit warning without blocking
an otherwise valid setup; execution independently validates the actual
runtime-selected CLI before launch.
- The AWS Bedrock identifier differs from earlier IDs because Fable 5.1
has no `-v1` suffix. The model-list test locks this exact value.
- There is no schema change or migration.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

Provider: OpenAI. Model: GPT-5 Codex. The host did not expose a more
specific model ID or context-window size. Capabilities used: agentic
reasoning, repository editing, shell execution, web research, and local
runtime verification.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-02 14:32:01 -07:00