Add opt-in bounded OpenTelemetry diagnostics across host preparation, scoped files, repository checkpoints, transport phases, and native execution. Preserve context parentage and stream cleanup, and retain diagnostic batches without per-file log writes.
Build qualification packs through the canonical frozen provider stage so lockfile, interpreter, and compiled bytes match the sandbox image. Keep ignored untracked repository files out of durable checkpoints.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Match the native runner's approved external-sandbox mode so Codex tools can reach the loopback API and Git credential bridge. Preserve local and restricted permission modes; verify the serialized launch environment.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Retry bounded read-only transport failures and resolve uncertain bulk writes through atomic signed receipts without replaying claimed batches.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Honor the native duplex opt-in and align repeat-safe credential acquisition with the file bridge response budget, without retrying Git commands.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Normalize the provider-pack layout independently of runnerd build order and compare verified content rather than revision provenance, avoiding unnecessary multi-gigabyte uploads.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep runtime-owned command snapshots reusable until cleanup and observe optional prompt-start rejection without hiding it from callers.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Use the same controller-owned runner file for identity and remote staging, including packaged server vendor layouts.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Record controller-owned rotation events and require an exact run transition before accepting a new process fingerprint. Preserve stable sandbox, runner and provider-session checks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Expose the existing finalization timestamp through the scoped sync API and reject periodic-only or out-of-run saves.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Accept bounded Codex deprecation notices after a settled turn and require that capability before reusing a sandbox image runner. Stage replacement artifacts atomically so existing launchers and image symlink targets survive interrupted uploads.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bind validated OpenCode result notifications to the active provider process and turn, matching semantic tool responses. Reproduce the live shutdown failure and verify exact durable authority after interruption.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Mock the native shutdown boundary in the startup unit test and wait for the persisted process identity before allowing the runtime readiness fixture to listen.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Park idle native sandbox sessions before app shutdown, adopt retained legacy workspaces without restaging Git, and carry explicitly bound GitHub access through both OpenCode launch filters.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Validate paginated legacy lease candidates before choosing a workspace, preserving Postgres timestamp precision. Recover failed saves through a new authorized run and cover post-save finalization failures without replaying terminal cleanup.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bundle the task disposition helper with the installed Paperclip skill. Retry transient read-only file transfers within a fixed deadline and retain sandbox RPC caller provenance for staging failure diagnosis.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Recognize dispatched pre-folder runs and v1 leases while excluding new scoped preparation failures from the compatibility path.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Select Codex ACP's full-access initial mode only for host-validated external work-folder environments with approve-all authority. Keep local and restrictive permission modes unchanged. The regression failed before the fix; all 50 ACP environment and runtime tests pass.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep established tasks on their original filesystem and session layout. Recover version-1 lease identity from host run records, preserve configuration checks, and retain old work when ownership or resume cannot be verified.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reproduce Codex plugin-cache repositories with real Git and preserve private-runtime exclusions before validating directory entries.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep custom profile-provided runtimes available while restoring the projected Git launcher before agent startup.
Co-Authored-By: Paperclip <noreply@paperclip.ing>