Commit Graph

1677 Commits

Author SHA1 Message Date
Dotta a72fd32191 test: isolate workspace eligibility fixtures from clock precision
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 05:19:03 -05:00
Dotta 17ddb89618 Preserve reusable sandboxes through failed resume and stop 2026-09-09 02:31:27 -05:00
Dotta 6fee0c3b4c fix: use the new run deadline while claiming a retained sandbox
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 01:47:49 -05:00
Dotta de60e9f6c2 fix: claim sandbox ownership before resume and preserve legacy launch profiles
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 01:44:00 -05:00
Dotta 6382f4e8fa fix: wait for task sandbox release before follow-up acquisition
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 01:35:25 -05:00
Dotta b820a6d884 fix: stage the resolved server runner artifact for sandbox upgrades
Use the same controller-owned runner file for identity and remote staging, including packaged server vendor layouts.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 00:50:36 -05:00
Dotta 1ca638736a test: verify explicit native credential process rotations
Record controller-owned rotation events and require an exact run transition before accepting a new process fingerprint. Preserve stable sandbox, runner and provider-session checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 00:23:55 -05:00
Dotta a24d331c41 test: require explicit final checkpoints in warm qualification
Expose the existing finalization timestamp through the scoped sync API and reject periodic-only or out-of-run saves.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-09 00:06:05 -05:00
Dotta 761ac12cc0 fix: preserve native warm attachment across runner upgrades
Accept bounded Codex deprecation notices after a settled turn and require that capability before reusing a sandbox image runner. Stage replacement artifacts atomically so existing launchers and image symlink targets survive interrupted uploads.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 23:20:23 -05:00
Dotta 777d891c25 test: stabilize startup checks and document shutdown drain requirements
Mock the native shutdown boundary in the startup unit test and wait for the persisted process identity before allowing the runtime readiness fixture to listen.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 22:02:28 -05:00
Dotta c7b68b52b0 fix: preserve sandbox credentials and Git state across restarts
Park idle native sandbox sessions before app shutdown, adopt retained legacy workspaces without restaging Git, and carry explicitly bound GitHub access through both OpenCode launch filters.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 21:49:19 -05:00
Dotta 816045d643 Keep finalization failures stable and recover valid older leases
Validate paginated legacy lease candidates before choosing a workspace, preserving Postgres timestamp precision. Recover failed saves through a new authorized run and cover post-save finalization failures without replaying terminal cleanup.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 20:25:41 -05:00
Dotta e60c6099c5 Preserve unbound legacy workspaces and contain failed final saves
Bundle the task disposition helper with the installed Paperclip skill. Retry transient read-only file transfers within a fixed deadline and retain sandbox RPC caller provenance for staging failure diagnosis.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 20:15:56 -05:00
Dotta f4a4916216 Preserve existing sandbox work after failed runs
Recognize dispatched pre-folder runs and v1 leases while excluding new scoped preparation failures from the compatibility path.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 19:32:16 -05:00
Dotta fbf2494104 Preserve existing sandbox workspaces across work-folder upgrades
Keep established tasks on their original filesystem and session layout. Recover version-1 lease identity from host run records, preserve configuration checks, and retain old work when ownership or resume cannot be verified.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 19:27:56 -05:00
Dotta 14151ff69f fix: preserve sandbox tool environments and incoming file versions
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 18:02:00 -05:00
Dotta 97bf34eb60 Exclude private nested repositories before checkpoint path validation
Reproduce Codex plugin-cache repositories with real Git and preserve private-runtime exclusions before validating directory entries.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 17:24:04 -05:00
Dotta 22d61006b9 fix: retain periodic checkpoint timestamps after failed final saves
A failed final flush does not erase an earlier successful periodic checkpoint. Cover interrupted continuations and replacement sandboxes for both saved and failed prior runs.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:42:20 -05:00
Dotta b8d003baff fix: keep prior saves visible after interrupted sandbox runs
Report incomplete terminal saves without hiding the latest successful checkpoint, including same-sandbox continuation and replacement failures.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:41:32 -05:00
Dotta 62096fd335 fix: preserve native sessions and route Git credentials internally
Align durable journal validation with the transport bound, preserve authorization on cached storage clients, and avoid Cloud session gates for native Git callbacks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 16:32:40 -05:00
Dotta 40619e2e23 fix: recognize wrapped document write conflicts
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 15:47:26 -05:00
Dotta 30ed3cbc99 fix: observe sandbox runner signal failures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 13:57:26 -05:00
Dotta cbdf95d053 fix(ui): identify failed sandbox saves in the cache inspector
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 12:53:29 -05:00
Dotta 56169f3e00 fix(storage): contain failed S3 checkpoint streams
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 12:10:32 -05:00
Dotta 427678bb5a feat(ui): add experimental cached task file inspection
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-08 09:45:37 -05:00
Dotta 5b12157460 fix(ci): verify staging dependency resolution before installation
Require a reviewed lock digest for staging migrator and app builds so registry drift fails before lifecycle-enabled installation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 20:55:25 -05:00
Dotta 3df487feb8 Update the Pi companion after core integration
Refresh the immutable provider lock fingerprint for the combined dependency graph.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 20:19:34 -05:00
Dotta 41f7b05157 Reconcile work folders with current schema and GitHub runtime
Preserve migration SQL hashes when renumbering and keep sandbox HOME with managed GitHub shell profiles.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 18:59:49 -05:00
Dotta 5f58c6b4f2 Publish native resume identity only after durable file save
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:17:53 -05:00
Dotta 2b1fa6982a Publish native resume identity only after durable file save
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:17:53 -05:00
Dotta ea785c47aa Publish warm session before native sandbox completion
Wait for the final work-folder checkpoint before background reconciliation can finalize a sandbox run. Persist its resumable task identity before exposing completion, and avoid late cleanup overwriting a newer turn.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:07:51 -05:00
Dotta 5a2ed91963 Publish warm session before native sandbox completion
Wait for the final work-folder checkpoint before background reconciliation can finalize a sandbox run. Persist its resumable task identity before exposing completion, and avoid late cleanup overwriting a newer turn.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 16:07:46 -05:00
Dotta 895a75ddfc Admit ACPX Pi through the verified native runner
Keep the unverified backend closed while allowing the descriptor-confined runner path, with regression coverage through the production session entry point.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:43:08 -05:00
Dotta aec14bbab8 fix: serialize warm binding validation with lifecycle transitions
Persist the validated workspace mode and run identical executable acceptance scripts across live engines.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:03:17 -05:00
Dotta c31eff6914 fix: serialize warm binding validation with lifecycle transitions
Persist the validated workspace mode and run identical executable acceptance scripts across live engines.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 15:03:16 -05:00
Dotta 850354d79c fix: retain warm sandbox bindings independently of worktree settings
Validate live engine coverage and physical sandbox reuse in deployed acceptance.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:56:37 -05:00
Dotta e8a6fb02bf fix: retain warm sandbox bindings independently of worktree settings
Validate live engine coverage and physical sandbox reuse in deployed acceptance.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:56:30 -05:00
Dotta fc05cd88a8 fix: preserve native target bindings and distinguish checkpoint status
Keep the execution target identity through workspace realization, restore its saved home for finalization, and distinguish warm setup reuse from replacement dependency recovery. Label direct file updates separately from agent checkpoints.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:38:35 -05:00
Dotta 2aed4261d0 fix: preserve native target bindings and distinguish checkpoint status
Keep the execution target identity through workspace realization, restore its saved home for finalization, and distinguish warm setup reuse from replacement dependency recovery. Label direct file updates separately from agent checkpoints.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:38:28 -05:00
Dotta 1cc45086d3
feat: use the responsible person's GitHub for shared agent operations (#13005)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Several people can send instructions to the same agent and task.
> - A fixed GitHub token in the provider process can keep the first
person's access after another person's message is accepted.
> - Task ownership cannot select credentials for each accepted
instruction or preserve the identity of an operation already in
progress.
> - This pull request records ordered execution identity contexts and
resolves credentials when managed Git, gh, or GitHub tools start.
> - The benefit is automatic personal GitHub access for shared agents,
with durable continuation rules and no teammate credential fallback.

## Linked Issues or Issue Description

**Subsystem affected**

Cross-cutting: orchestration, connection grants, database, runtime
adapters, native runners, and run details.

**Problem or motivation**

A shared agent must use the person whose instructions it has accepted. A
queued message must retain its author. A retry or approval without new
instructions must retain the originating identity. GitHub must remain
optional for ordinary work.

**Proposed solution**

Persist execution identity separately from task ownership. Give new
processes a run-scoped broker capability and token-free managed
launchers. Capture identity at operation start. Keep an explicit
dedicated-agent grant as an override. Show redacted diagnostics in run
details.

**Alternatives considered**

Per-task ownership, fixed provider tokens, and mutable repository author
configuration do not handle accepted steering or concurrent operations.
A manual account-selection action would add unnecessary setup to each
turn.

**Roadmap alignment**

This completes the existing Multiple Human Users, MCP Tool Gateway &
Apps, Secrets Manager, and Self-healing Runs capabilities. The
implementation follows the maintainer-approved plan.

Related work: Refs #12843, Refs #12907. Existing proposals #4618 and
#8945 cover per-agent or per-worktree author configuration. This change
instead follows the accepted human instruction across runtime types.
Refs #11831 for governed personal connection delegation; this change
preserves connection audience checks and does not use standing
delegation as a personal credential fallback.

## What Changed

- Add durable, ordered identity contexts and active run references.
Preserve message authors through consolidation, steering, retries,
delegation, approvals, routines, and restart.
- Add an authenticated operation-time GitHub credential broker and
local/remote managed git and gh launchers. Keep personal tokens out of
the long-lived provider process.
- Resolve GitHub gateway and server-side Git operations through the same
responsible-person or dedicated-grant selection rules.
- Make absent and unavailable GitHub credentials non-blocking at generic
startup. Clear host and prior-person credentials. Keep anonymous Git
access where supported.
- Add run-detail identity history and the dedicated-account warning.
Keep task ownership and queue-versus-steer decisions unchanged.
- Preserve personal OAuth declarations through connection edits. Retain
exact selected grants in the gateway.
- Fix continuation races found during real acceptance: verify a warm
owner before credential rotation, and wait for bounded durable runner
suspension before the next run starts.
- Make migrations replay-safe. Retain identity through agent/run
deletion, remove it with its company, and clean terminal launcher
directories before releasing execution environments. Document
coordinated release and rollback.

## Verification

- Full workspace typecheck, build, and token gates passed. The complete
local suite passed in its normal test groups: 17,120 passing tests,
including all 143 serialized server suites. After integrating the newly
merged runner API work, full local typecheck and build passed again,
along with 890 focused integration tests. All 31 checks on the
integrated revision passed, including build, browser E2E, release
registry, canary dry run, typecheck, security and all test suites.
Greptile is 5/5 with all review threads resolved.
- Current focused checks passed: 142 native executor tests, 67 runtime
lifecycle tests, 9 durable identity tests, 75 credential/routine tests,
19 low-trust/resumption tests, and the executable migration replay test.
- Authenticated browser acceptance with two Paperclip users and two
GitHub accounts on one shared native agent passed. Real commits and
pushes followed A → B accepted steering → queued A continuation in the
same saved conversation. GitHub commit author and committer identities
matched all three operations. Both runs succeeded and task ownership
stayed unchanged.
- Real GitHub MCP calls switched from A to B after accepted steering. A
delegated subtask retained its originating identity across a server
restart.
- Disabling B's GitHub connection left ordinary work successful. Managed
gh was unauthenticated and the provider had no inherited GH_TOKEN or
GITHUB_TOKEN.
- The browser displayed run-detail diagnostics and the exact
dedicated-account warning. A final controller-restart check followed by
another-person continuation retained the conversation, selected the
correct GitHub login and Git author, and removed each terminal launcher
directory.
- Company-lifetime migration and all five previously failing CI suites
passed locally (167 tests). Same-token gateway A → B → A and six
broker/launcher boundary tests passed.
- Remote callback, launcher, sandbox, and runtime contract tests passed.
Both native and legacy Codex completed actual Daytona executions on the
integrated revision ([campaign
results](https://github.com/paperclipai/paperclip/actions/runs/34155056509)).
The remote package-manager shim staging regression also passed locally.

## Risks

- Deploy the migrations, server broker, launchers, and runner artifacts
together. Existing processes finish with their original contract. New
managed processes need the broker endpoint for GitHub operations.
- Finish or stop new managed executions before rolling application code
back. Keep the additive schema and identity history during rollback.
- Scripts that require a persistent raw GH_TOKEN must use managed git,
gh, or GitHub gateway tools. Run capabilities authorize code executing
within that run to acquire its current identity; this is not
hostile-code isolation within one execution principal. Managed commands
prevent automatic credential carryover; arbitrary code deliberately
copying a credential is outside that boundary.
- Uncertain steering acknowledgement deliberately holds new credential
acquisition until reconciliation. Already-started operations retain
their captured identity.
- GitHub private access and provider outages can still fail the specific
operation that needs them. Dedicated grant failure does not fall back to
personal access.

## Model Used

OpenAI GPT-6 through Codex assisted implementation, review, shell
execution, and browser acceptance. The exact model variant and
context-window size are not exposed in this session. Tool use included
TypeScript and Rust tests, database integration tests, GitHub CLI, and
authenticated browser control.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-07 14:32:20 -05:00
Dotta 2e810127c4 fix: preserve restored setup and bind native sync to sandbox home
Record checkpoint intent before mutations and permit CI-owned lock resolution when building a staging migrator.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:26:10 -05:00
Dotta 82b19d5091 fix(work-folders): preserve save status when activity logging fails
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:26:10 -05:00
Dotta a4c655183d fix(adapters): leave sandbox work folders to the remote runner
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:26:10 -05:00
Dotta b2eb1bfd9a test: cover qualified Pi profiles and fenced runtime fixtures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:25:53 -05:00
Dotta 5f2b9742eb fix: preserve restored setup and bind native sync to sandbox home
Record checkpoint intent before mutations and permit CI-owned lock resolution when building a staging migrator.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 14:24:57 -05:00
Dotta 5bddff0920
feat(runner): add guarded API search and call fallback (#13003)
## Thinking Path

> - Paperclip manages AI agents and their work.
> - The new runner gives agents dedicated tools for common tasks.
> - Some API operations and parameters have no dedicated tool.
> - Agents need a controlled way to find and use those operations.
> - This pull request adds API search and calls through the real server
routes.
> - Existing tools remain the preferred path. The new tools are disabled
by default.
> - Paired tests measure correctness, tool choice, cost and time.

## Linked Issues or Issue Description

**Subsystem affected**

Paperclip Runner contracts, production tool authority and the server API
catalog.

**Problem or motivation**

The runner cannot use much of the API described by the old Paperclip
skill. A generic HTTP client would also let agents bypass runner control
rules.

**Proposed solution**

Add `search_api` and `call_api`. Resolve calls from the mounted API
catalog. Use server-held, run-bound credentials. Preserve route checks
and runner lifecycle rules. Keep the tools disabled until an operator
enables selected companies.

**Alternatives considered**

A dedicated tool for every endpoint would add a large initial prompt. An
unrestricted HTTP tool would weaken authorization and replay controls.

**Roadmap alignment**

This extends the native runner tooling. The repository owner requested
this design and implementation. The roadmap and related open PRs were
checked. No duplicate API escape-hatch PR was found.

## What Changed

- Register two compact fallback tools in canonical contracts and
provider projections.
- Build deterministic API discovery from OpenAPI, mounted experimental
routes and the old skill reference.
- Execute bounded JSON, text, file and download requests through
authenticated HTTP routes.
- Recheck active runs, company access and work modes. Block runner
lifecycle, scheduling, credential and approval bypasses. Keep routine
annotation collaboration available.
- Retain mutation receipts. Report uncertain outcomes without blindly
repeating writes.
- Add a company rollout gate and a durable eval worker with complete
cost accounting checks.
- Record child-task creation in the activity log with the agent and run.
- Add contract, authorization, file, replay and real runnerd/PRP/HTTP
tests.
- Document rollout gates and paid coverage limits. The companion eval
repository retains immutable attempts and reports.

## Verification

- Final app commit `da58370524c3626a744eec20164397c5fb6ba9ef`: all 32
checks passed; the unrelated Storybook visual check was skipped.
Greptile 5/5; no unresolved review threads.

- Full Linux build and recursive typecheck passed. Repository tests were
run by project and serialized shard; all 143 serialized server suites
passed.
- Runner TypeScript: 1,599 passed, two skipped. Rust release: 451
passing test reports. Conformance and replay parity passed. The required
API check passed 837 tests, including runnerd → PRP → authority → real
HTTP.
- Bindings cannot enable API tools without the explicit deployment flag.
Unit and real-authority tests prove the default-off boundary.
- The standalone API check builds and stages its own binary. It passed
after existing staged and debug binaries were removed from the test
container.
- UI and CLI tests passed. Initial environment failures (missing jq,
Docker overlay file identity, and parallel linker memory pressure) and
focused passing reruns are retained. The macOS full runner suite has
platform-specific failures; Linux is the qualified full-check platform.
- Eval harness: 27 tests passed; existing CI discovery ran 86 tests with
two unrelated skips. Credential export rejection is tested against the
actual report command.
- Luna and OpenRouter Sonnet each passed 60 common-workflow runs: ten
workflows, three repetitions per arm, zero unnecessary API fallback.
- Sonnet passed 11 selected capability/contract cases after fixes.
Gemini passed three smoke cases. DeepSeek exceeded the 120-second limit
and remains unqualified.
- Luna's two cost flags received focused follow-up. The original flags
and a later n=1 latency flag remain visible. Sonnet had no cost or
latency increase above 20%.
- The catalog contains 785 entries; 58 were exercised across all stages.
Most operation probes remain unrun and some need additional fixtures.
Authored probes do not establish successful coverage.
- Total conservative accounted cost: $9.875960. Active paid-campaign
time: 88.16/90 minutes. No missing accounting. Later security and
harness fixes have provider-free verification; no paid validation is
claimed for those revisions.
- Inspect the [qualification
report](https://github.com/paperclipai/paperclip-evals/blob/codex/seach-call-api-tools/evals/runner-api-tools/reports/2026-09-07-production/READINESS.md)
and [verification
record](https://github.com/paperclipai/paperclip-evals/blob/codex/seach-call-api-tools/evals/runner-api-tools/reports/2026-09-07-production/verification.json).

## Risks

- This is a broad authenticated API surface. Keep the default-off gate
until an operator selects initial rollout companies.
- Paid coverage is incomplete. Small regression samples do not prove all
workflows are unchanged.
- A timeout or server failure can follow a committed mutation. The
result reports an unknown outcome and requires state inspection.
- The new definitions add prompt tokens. The report retains cost flags
and cache variation.
- No database migration is required.
- Repository rules require code-owner approval before merge. Technical
CI and automated review are complete.

## Model Used

OpenAI Codex based on GPT-6 assisted with code, tests and review. The
exact serving model ID and context window are not exposed in this
session. It used reasoning, tool calls and code execution.

Eval models: `gpt-5.6-luna` with low reasoning,
`openrouter/anthropic/claude-sonnet-5`,
`openrouter/google/gemini-3.8-flash`, and
`openrouter/deepseek/deepseek-v4-flash-0731`. Attempts retain runtime
versions, model identity, usage and source provenance.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-07 14:14:43 -05:00
Dotta b5fca70b80 fix(work-folders): preserve save status when activity logging fails
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 13:53:39 -05:00
Dotta 2962ebfdb7 feat(runner): qualify pinned Pi runtime and linked provider launchers
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 13:47:34 -05:00
Dotta 368ebe76e7 fix(adapters): leave sandbox work folders to the remote runner
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 13:47:12 -05:00
Dotta b4c3bf6961 Fix browser file operations and persist visible save times
Preserve JSON Content-Type when custom idempotency headers are supplied. Expose the latest accepted folder operation timestamp so browser saves remain visible before an agent runs and after all files are deleted.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-07 13:31:59 -05:00