Commit Graph

4308 Commits

Author SHA1 Message Date
Dotta 8787dab6f3 Use the external sandbox for approved native Codex ACP runs
Select Codex ACP's full-access initial mode only for host-validated external work-folder environments with approve-all authority. Keep local and restrictive permission modes unchanged. The regression failed before the fix; all 50 ACP environment and runtime tests pass.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 19:28:06 -05:00
Dotta fbf2494104 Preserve existing sandbox workspaces across work-folder upgrades
Keep established tasks on their original filesystem and session layout. Recover version-1 lease identity from host run records, preserve configuration checks, and retain old work when ownership or resume cannot be verified.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 19:27:56 -05:00
Dotta 7fb72800ab fix: show loading while retrying cached file previews
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 18:58:02 -05:00
Dotta 14151ff69f fix: preserve sandbox tool environments and incoming file versions
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 18:02:00 -05:00
Dotta 97bf34eb60 Exclude private nested repositories before checkpoint path validation
Reproduce Codex plugin-cache repositories with real Git and preserve private-runtime exclusions before validating directory entries.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 17:24:04 -05:00
Dotta 36f8d69931 Restore managed Git PATH after remote login initialization
Keep custom profile-provided runtimes available while restoring the projected Git launcher before agent startup.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 17:22:37 -05:00
Dotta 0b9314cf3e Preserve managed Git launchers across legacy ACP startup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 17:14:18 -05:00
Dotta 22d61006b9 fix: retain periodic checkpoint timestamps after failed final saves
A failed final flush does not erase an earlier successful periodic checkpoint. Cover interrupted continuations and replacement sandboxes for both saved and failed prior runs.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:42:20 -05:00
Dotta b8d003baff fix: keep prior saves visible after interrupted sandbox runs
Report incomplete terminal saves without hiding the latest successful checkpoint, including same-sandbox continuation and replacement failures.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:41:32 -05:00
Dotta ffe3a32b2d test: require managed private repository access in staging acceptance
Fail before editing repository state if the remote cannot be read, and reject credential or PATH workarounds during model-driven acceptance.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:35:20 -05:00
Dotta 62096fd335 fix: preserve native sessions and route Git credentials internally
Align durable journal validation with the transport bound, preserve authorization on cached storage clients, and avoid Cloud session gates for native Git callbacks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:32:40 -05:00
Dotta 40619e2e23 fix: recognize wrapped document write conflicts
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 15:47:26 -05:00
Dotta 45eabf6563 fix(runner): carry Git credentials through the Rust ACP sidecar 2026-09-08 15:34:36 -05:00
Dotta 56daf4664d fix(runner): expose Pi semantic tools and preserve projected Git credentials 2026-09-08 15:05:28 -05:00
Dotta f50fa19eed fix: keep cache listing errors separate from save status 2026-09-08 14:18:55 -05:00
Dotta ebe1fc8b65 fix: show pending and unknown work folder save state
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 14:08:10 -05:00
Dotta 30ed3cbc99 fix: observe sandbox runner signal failures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:57:26 -05:00
Dotta 53e7067413 fix: preserve scoped sandbox home in legacy adapters
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:53:45 -05:00
Dotta 30b9cd8c00 fix: isolate GitHub launcher module format
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:40:19 -05:00
Dotta 1c48625115 fix: seed explicit Codex ACP sandbox credentials
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:35:39 -05:00
Dotta e5e54df884 fix: keep every failed shared-folder run accessible
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:06:36 -05:00
Dotta 0a9680a8b8 fix: preserve sandbox work folders through ACP launch boundaries
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:02:36 -05:00
Dotta cbdf95d053 fix(ui): identify failed sandbox saves in the cache inspector
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 12:53:29 -05:00
Dotta 0c4810ea7b test: verify staging actor and terminal run outcomes
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 12:20:08 -05:00
Dotta 56169f3e00 fix(storage): contain failed S3 checkpoint streams
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 12:10:32 -05:00
Dotta f3c67d50da fix(ui): label cached paths relative to sandbox home
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 10:03:29 -05:00
Dotta 630b002c75 fix(ui): select cached files and browse retained trash in tabs
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 10:01:39 -05:00
Dotta f65d0b841f fix(ui): keep cached file inspector expanded at a stable size
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 09:57:46 -05:00
Dotta 427678bb5a feat(ui): add experimental cached task file inspection
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 09:45:37 -05:00
Dotta 71774a29ca fix(ui): remove stored-file browsing entry points
Defer cached-file debugging and live sandbox inspection as separate features. Keep the saved-file browser only as an unshipped Storybook prototype.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 09:17:07 -05:00
Dotta bd4b566f96 fix(storybook): isolate project workspace queries
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 08:40:49 -05:00
Dotta 0bed8c643d test(storybook): verify isolated file lifecycle fixtures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 08:35:26 -05:00
Dotta 28858075ef docs(storybook): add work-folder components and page review gallery
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 08:30:28 -05:00
Dotta 5b12157460 fix(ci): verify staging dependency resolution before installation
Require a reviewed lock digest for staging migrator and app builds so registry drift fails before lifecycle-enabled installation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 20:55:25 -05:00
Dotta 3df487feb8 Update the Pi companion after core integration
Refresh the immutable provider lock fingerprint for the combined dependency graph.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 20:19:34 -05:00
Dotta 41f7b05157 Reconcile work folders with current schema and GitHub runtime
Preserve migration SQL hashes when renumbering and keep sandbox HOME with managed GitHub shell profiles.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 18:59:49 -05:00
Dotta f00d37da2a Bundle the verified remote provider pack in the Cloud app
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:18:55 -05:00
Dotta 5f58c6b4f2 Publish native resume identity only after durable file save
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:17:53 -05:00
Dotta 3094e1b31e Merge branch 'codex/work-folders' into codex/work-folders-pi
* codex/work-folders:
  Publish native resume identity only after durable file save
2026-09-07 16:17:53 -05:00
Dotta 2b1fa6982a Publish native resume identity only after durable file save
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:17:53 -05:00
Dotta 305390ebf3 Merge native sandbox finalization barrier
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/work-folders:
  Publish warm session before native sandbox completion
2026-09-07 16:07:53 -05:00
Dotta ea785c47aa Publish warm session before native sandbox completion
Wait for the final work-folder checkpoint before background reconciliation can finalize a sandbox run. Persist its resumable task identity before exposing completion, and avoid late cleanup overwriting a newer turn.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:07:51 -05:00
Dotta 5a2ed91963 Publish warm session before native sandbox completion
Wait for the final work-folder checkpoint before background reconciliation can finalize a sandbox run. Persist its resumable task identity before exposing completion, and avoid late cleanup overwriting a newer turn.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:07:46 -05:00
Dotta 1f06bfff29 Merge checkpoint cadence acceptance correction
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/work-folders:
  Measure live checkpoint cadence from persisted start events
2026-09-07 15:53:39 -05:00
Dotta 9c79481d65 Measure live checkpoint cadence from persisted start events
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:53:37 -05:00
Dotta 1928d4ba6e Identify native Pi sessions correctly
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:53:33 -05:00
Dotta 6f7125ecf2 Measure live checkpoint cadence from persisted start events
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:53:33 -05:00
Dotta 895a75ddfc Admit ACPX Pi through the verified native runner
Keep the unverified backend closed while allowing the descriptor-confined runner path, with regression coverage through the production session entry point.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:43:08 -05:00
Dotta 03d9234696 Preserve safe Codex shell variables alongside GitHub credentials
Codex filters explicit environment overrides through include_only. Retain the scoped home and standard executable path without allowing provider or host secrets into shell commands.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:36:03 -05:00
Dotta 39dffd70f4 Merge the Codex shell environment fix into the Pi companion
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/work-folders:
  Preserve safe Codex shell variables alongside GitHub credentials
2026-09-07 15:36:03 -05:00