paperclip/server/src/services
Dotta 0f94521017
fix(runner): restore local session and task integrity (#12721)
## Thinking Path

> - Paperclip is the control plane for agents that perform work.
> - Paperclip Runner connects durable provider sessions to individual
task runs through PRP.
> - Provider continuity and per-run authority are different lifetimes.
> - The existing implementation mixed those lifetimes and lost event
metadata between provider frames, runnerd, persistence, API
sanitization, and the task thread.
> - That caused failed continuation, missing progress and Plans,
duplicate replies, hidden failures, and unsafe recovery.
> - This repair gives every heartbeat fresh authority, preserves
qualified provider-session continuity, and restores one lossless
presentation path without changing direct adapters.

## Linked Issues or Issue Description

**What happened?**

A second native heartbeat could reuse tickets, leases, command receipts,
sequence state, and run identity from the first heartbeat. Provider
phase and item identity could be lost before the UI read them. Redaction
could corrupt protocol discriminators while still missing malformed
credential tails. The task thread could fold progress into the final
response, hide failures, or show more than one final answer. Native
Codex also exposed approval modes that do not yet have a durable
approval bridge.

**Expected behavior**

Each heartbeat uses a new PRP authority epoch. Codex and OpenCode
preserve exact qualified provider sessions; ACPX emits an explicit
continuity event when its qualified process-replacement policy is used.
Every accepted provider event is presented, classified as internal, or
surfaced as unsupported. The task page shows chronological progress,
reasoning summaries, activity, Plans, interactions, terminal failures,
and exactly one final reply. Direct adapters retain their existing path.

**Steps to reproduce**

1. Enable the unified experimental Paperclip Runner setting.
2. Create a local native Codex, OpenCode, ACPX Claude, or ACPX Codex
agent.
3. Run response, Plan, structured-question/resume, restart,
cancellation, and failure scenarios.
4. Reload the task while active, waiting, failed, and settled.
5. On the old implementation, observe stale run authority, missing
classifications, incomplete output, or duplicated/folded replies.

**Paperclip version or commit**

The repair is based directly on `master` at
`87d05e194b643810d16d20612115acd01d735d43`.

**Deployment mode**

Local development with the embedded database.

Related work: Refs #12616, #12646, #12666, #12685, and #12700.

## What Changed

- Rotates PRP control-plane, outbox, ticket, lease, command, receipt,
and sequence authority for each heartbeat while carrying forward only a
validated provider-session identity.
- Reads `control-plane-state.json`, validates both durable schemas and
lifecycle values, resumes coherent current runs, archives qualified
settled authority, and quarantines malformed or mismatched scoped state
without moving ambiguous live legacy state.
- Preserves Codex provider phase and stable item identities so
commentary remains progress and only `final_answer` becomes final.
- Adds raw OpenCode HTTP/SSE boundary coverage and canonical reasoning
lifecycle mapping.
- Makes ACPX normalization lossless for visible reasoning, tool
lifecycle metadata, stable bounded identities, Plan revisions,
structured requests, failures, and qualified process replacement. Only
the compatible terminal assistant message is promoted as final.
- Applies schema-aware redaction before generic JWT-shaped detection and
scans every diagnostic string leaf. Malformed raw/escaped quoted
credential tails are redacted in both server and durable Rust state.
- Restores snapshot-style chronological task presentation, expandable
tool activity, inline Plan cards, visible waiting/resume/cancel/failure
states, and exactly one final answer.
- Makes `never` the only qualified native Codex permission mode and
rejects unsupported persisted native modes with remediation. OpenCode
and ACPX policies remain intact.
- Keeps the unified experimental Runner setting as the only enablement
flag. Onboarding and direct Codex, Claude, and OpenCode stay on their
legacy execution/finalization paths.
- Adds cross-language goldens, authority/recovery/fault coverage, exact
response/count assertions, and native plus legacy acceptance scenarios.

## Verification

- Pull-request GitHub Actions run Rust formatting/tests, TypeScript
checks, server/UI tests, builds, protocol drift checks, browser E2E, and
security scans.
- A separate workflow-only validation ref is pinned directly on this PR
head and runs the 35-cell paid local matrix: three core scenarios plus
structured-question resume and restart/resume for native Codex, native
OpenCode, ACPX Claude, ACPX Codex, and direct Codex/Claude/OpenCode.
Run: https://github.com/paperclipai/paperclip/actions/runs/33682434315
- Acceptance requires exact single visible replies, monotonic sequences,
matching envelope discriminators, one semantic terminal, one run
terminal, no unresolved interaction, no duplicate mutation, no secret
leakage, provider continuity, and zero native rows for direct adapters.
- Per maintainer direction, tests are running in GitHub Actions rather
than on the slower local host. Only formatters and static diff checks
were run locally.

## Risks

- Recovery from old or partial filesystem state is sensitive. The repair
fails closed, preserves active or unverifiable authority, and
quarantines only state whose scoped ownership is safe to move.
- Provider event formats can change. Closed validators and boundary
goldens turn new or malformed events into visible diagnostics instead of
silent drops.
- Shared task presentation could affect direct adapters. Runtime-fact
gating plus the direct-adapter matrix protect the existing path.
- Managed and remote providers are not qualified here. Shared code
continues to compile and fail safely, but live qualification is
deferred.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex based on GPT-5. The exact deployed snapshot and
context-window size are not exposed to this task. It used agentic
reasoning, repository inspection, code editing, Git, parallel subagents,
and GitHub Actions.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id
- [ ] I have run tests locally and they pass (intentionally deferred to
GitHub Actions)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented risks above
- [ ] All Paperclip CI gates are green
- [ ] The paid local-provider matrix is green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-09-02 16:11:26 -05:00
..
native-runtime fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
recovery Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
runtime-exposure fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
scripts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
access.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
activity-log.ts feat(server): allow agents to resolve review confirmations (#10939) 2026-08-05 23:40:05 -05:00
activity.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
adapter-login-lease.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-login-lease.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-models-env.test.ts
…
adapter-models-env.ts
…
adapter-plugin-store.ts
…
adapter-registry-bootstrap.reconcile.test.ts
…
adapter-registry-bootstrap.test.ts
…
adapter-registry-bootstrap.ts
…
agent-action-audit.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
agent-assignability.ts
…
agent-instructions.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
agent-invokability.ts
…
agent-permissions.ts
…
agent-secret-bindings.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
agent-start-lock.ts
…
agents.ts fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
approvals.ts fix: prevent duplicate built-in agents and self-heal reconciliation (#10223) 2026-07-28 11:12:58 -07:00
approved-execution-wait.test.ts feat(apps): refine Postman and Shopify setup (#12357) 2026-08-29 12:08:35 -05:00
approved-execution-wait.ts feat(apps): refine Postman and Shopify setup (#12357) 2026-08-29 12:08:35 -05:00
artifact-review-documents.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
assets.ts
…
attention-resolver-audience.test.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
attention.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
authorization.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
batch-insert.ts Harden company import: durable UI, async jobs, integrity guard, batched inserts (#10523) 2026-07-30 16:52:58 -07:00
board-auth.test.ts perf(server): reduce issue detail request overhead (#10414) 2026-08-11 14:39:23 -04:00
board-auth.ts perf(server): reduce issue detail request overhead (#10414) 2026-08-11 14:39:23 -04:00
budgets.ts
…
built-in-agent-metadata.ts
…
built-in-agents.ts feat: make chat-style tasks the default experience (#11101) 2026-08-11 09:06:21 -07:00
bundled-plugins.ts feat: Claude login on the new-agent page before agent creation (#11347) 2026-08-17 13:42:51 -07:00
catalog-provenance.ts
…
change-consent-gate.ts
…
cloud-instance.ts feat: make in-app features cloud-aware (#10850) 2026-08-04 23:00:14 -05:00
codex-auth-reconciliation.ts
…
companies.ts Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
company-artifacts.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
company-export-readme.ts fix(security): route paperclipai CLI guidance through safe npx form (CWE-78) (#11400) 2026-08-14 22:11:16 -07:00
company-import-transfers.ts feat(server): chunked resumable company import transfers (#11223) 2026-08-11 15:25:07 -07:00
company-member-roles.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
company-portability.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
company-search-extract.ts
…
company-search-rate-limit.ts
…
company-search.ts
…
company-skill-policy.ts
…
company-skills.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
company-transfer-runs.ts feat(server): chunked resumable company import transfers (#11223) 2026-08-11 15:25:07 -07:00
composio-session-manager.ts feat(apps): add Composio and Gmail connectors (#12342) 2026-08-29 12:08:33 -05:00
composio.test.ts feat(apps): add Composio and Gmail connectors (#12342) 2026-08-29 12:08:33 -05:00
composio.ts feat(apps): add Composio and Gmail connectors (#12342) 2026-08-29 12:08:33 -05:00
connection-intents.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
costs.ts
…
cron.ts
…
cross-issue-influence-limit.ts fix(interactions): authorize resolvers consistently (#11376) 2026-08-16 13:46:50 -05:00
dashboard.ts perf(server): cut steady-state DB hot paths in dashboard, attention, and productivity sweeps (#10992) 2026-08-06 11:56:40 -05:00
database-backup-health.ts
…
decision-queues.ts feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
decision-retention.ts feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
decision-signing.ts fix(server): stop requiring PAPERCLIP_DECISION_SIGNING_SECRET at startup (#10594) 2026-07-31 22:48:32 -07:00
decision-training.ts feat: restore decision training library and inspector (#9779) 2026-07-17 13:27:32 -05:00
decision-wakeup.ts feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
decisions.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
default-agent-instructions.ts
…
device-login-credential-read.ts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
device-login-reaper.ts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
device-login-service.ts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
document-annotations.ts
…
documents.ts Harden company import: durable UI, async jobs, integrity guard, batched inserts (#10523) 2026-07-30 16:52:58 -07:00
duplex-observability-recorder.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
effective-run-config-fingerprints.ts
…
environment-config.ts feat(runner): add remote execution substrate (#12638) 2026-09-01 01:29:06 -05:00
environment-custom-image-runtime.ts feat(server): add a one-click relink action for detached custom-image templates (#11641) 2026-08-18 11:43:39 -07:00
environment-custom-image-setup-session-utils.ts
…
environment-custom-image-terminal-sessions.test.ts
…
environment-custom-image-terminal-sessions.ts
…
environment-custom-images.ts refactor(environment): classify environment capabilities from static driver definitions (#12045) 2026-08-23 21:24:59 -07:00
environment-driver-traits.ts feat(runner): add remote execution substrate (#12638) 2026-09-01 01:29:06 -05:00
environment-execution-target.ts feat(runner): add remote execution substrate (#12638) 2026-09-01 01:29:06 -05:00
environment-probe.ts
…
environment-run-orchestrator.ts feat(runner): add remote execution substrate (#12638) 2026-09-01 01:29:06 -05:00
environment-runtime.ts feat(runner): add remote execution substrate (#12638) 2026-09-01 01:29:06 -05:00
environments.ts feat: environment delete with agent reassignment and consented sandbox destroy (#12053) 2026-08-23 16:53:17 -07:00
execution-allowlist.test.ts Let tenants edit env vars on managed sandbox environments; add managed-sandbox-only mode (#11200) 2026-08-11 11:40:57 -07:00
execution-allowlist.ts Let tenants edit env vars on managed sandbox environments; add managed-sandbox-only mode (#11200) 2026-08-11 11:40:57 -07:00
execution-policy-bootstrap.test.ts
…
execution-policy-bootstrap.ts
…
execution-workspace-branch-ownership.ts fix(workspaces): attach PR preparation to existing branches (#11703) 2026-08-21 17:23:18 -05:00
execution-workspace-policy.ts fix(workspaces): attach PR preparation to existing branches (#11703) 2026-08-21 17:23:18 -05:00
execution-workspaces.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
export-fidelity.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
external-objects.ts fix(external-objects): refresh PR status labels (#10704) 2026-08-02 20:24:52 -07:00
feedback-redaction.ts
…
feedback-share-client.ts
…
feedback.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
finance.ts
…
folders.ts
…
git-credentials.ts fix(server): serialize managed-checkout materialization and stop misattributing clone failures (#10723) 2026-08-02 22:14:58 -07:00
github-commit-details.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
github-external-object-provider.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
github-fetch.ts feat(server): authenticate server-side git clone and fetch with a company-secret GitHub token (#10720) 2026-08-02 20:27:09 -07:00
github-pull-request-merge.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
gmail-tool-governance.test.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
goals.ts
…
heartbeat-policy.ts fix: preserve recovery retries across restarts (#11817) 2026-08-20 17:09:42 -05:00
heartbeat-run-events.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
heartbeat-run-runtime-status.test.ts feat(environments): refer to the managed default environment by name, not the sandbox driver key (#11838) 2026-08-21 12:51:22 -07:00
heartbeat-run-runtime-status.ts
…
heartbeat-run-summary.ts fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
heartbeat-runner-provider-config.test.ts fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
heartbeat-stop-metadata.test.ts
…
heartbeat-stop-metadata.ts
…
heartbeat.ts fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
hire-hook.ts
…
hot-restart.test.ts fix(server): preserve hot restart intent across path upgrade (#10593) 2026-07-31 21:55:59 -07:00
hot-restart.ts fix(server): preserve hot-restart shutdown snapshots (#10815) 2026-08-04 11:44:43 -05:00
import-write-types.ts feat(server): preserve task timestamps and hierarchy through company import/export (#11193) 2026-08-10 17:01:33 -07:00
inbox-agent-policy.ts feat(inbox): let agents safely tidy user inboxes (#9724) 2026-07-16 16:49:18 -05:00
inbox-dismissals.ts
…
index.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
instance-settings.ts Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
invite-grants.ts
…
invite-rate-limit.ts
…
issue-approvals.ts
…
issue-assignment-wakeup.ts feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
issue-change-receipt.ts feat: add authoritative issue PATCH receipts (#10478) 2026-07-31 18:52:59 -07:00
issue-continuation-summary.ts
…
issue-dependency-wakeups.test.ts fix(issues): cycle-aware issue_blockers_resolved after terminal reset (#11979) 2026-08-23 08:50:38 -07:00
issue-dependency-wakeups.ts fix(issues): cycle-aware issue_blockers_resolved after terminal reset (#11979) 2026-08-23 08:50:38 -07:00
issue-execution-policy.ts fix(server): let board users cancel issues with an active review stage (#10655) 2026-08-01 15:43:13 -07:00
issue-goal-fallback.ts
…
issue-liveness.ts
…
issue-prefix.test.ts feat(server): derive hosted-tenant issue prefixes from the company name and follow renames (#12292) 2026-08-27 11:34:42 -07:00
issue-prefix.ts feat(server): derive hosted-tenant issue prefixes from the company name and follow renames (#12292) 2026-08-27 11:34:42 -07:00
issue-queued-comment-queue.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
issue-recovery-actions.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
issue-references.ts
…
issue-review-policy.ts fix(interactions): authorize resolvers consistently (#11376) 2026-08-16 13:46:50 -05:00
issue-rewake-throttle.ts feat(issues): contain cross-issue agent side effects (#10837) 2026-08-04 13:17:49 -05:00
issue-thread-interaction-resolution.test.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
issue-thread-interaction-resolution.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
issue-thread-interactions.test.ts fix(interactions): deliver question answers durably (#12307) 2026-08-27 12:12:21 -05:00
issue-thread-interactions.ts fix: limit plan-to-auto transition to plan confirmation (#12695) 2026-09-01 17:18:42 -05:00
issue-tree-control.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
issue-visibility.ts
…
issues.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
json-schema-secret-refs.ts fix(server): accept secret_ref binding objects in sandbox provider environment config (#10355) 2026-07-28 10:50:13 -07:00
live-events.ts
…
local-service-supervisor.ts fix(workspaces): read process cwd on macOS so port-owner adoption works (#11763) 2026-08-21 16:03:43 -07:00
login-command.test.ts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
login-command.ts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
low-trust-runtime-containment.ts
…
managed-agent-profiles.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
managed-config.ts feat(server): computed owner instance-admin elevation for cloud-managed instances, behind platform floors (#10343) 2026-07-27 18:58:31 -07:00
managed-environments.test.ts Let tenants edit env vars on managed sandbox environments; add managed-sandbox-only mode (#11200) 2026-08-11 11:40:57 -07:00
managed-environments.ts Let tenants edit env vars on managed sandbox environments; add managed-sandbox-only mode (#11200) 2026-08-11 11:40:57 -07:00
managed-resource-drift.test.ts fix(server): preserve managed environment drift on boot (#10979) 2026-08-07 00:41:42 -05:00
managed-resource-drift.ts fix(server): preserve managed environment drift on boot (#10979) 2026-08-07 00:41:42 -05:00
managed-workspace-identity.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
mcp-http.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
onboarding-greeting.test.ts feat: make chat-style tasks the default experience (#11101) 2026-08-11 09:06:21 -07:00
onboarding-greeting.ts feat: make chat-style tasks the default experience (#11101) 2026-08-11 09:06:21 -07:00
onboarding-seed.ts Gate Paperclip Runner setup behind an experimental flag (#12656) 2026-09-01 05:57:40 -05:00
paperclip-cloud-connector-enrollment.test.ts fix(connector): isolate broker enrollment targets (#12609) 2026-08-31 16:43:46 -05:00
paperclip-cloud-connector-enrollment.ts Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
paperclip-cloud-connector-status.ts feat(apps): add Paperclip Cloud managed OAuth connector (#12600) 2026-08-31 14:34:46 -05:00
paperclip-cloud-connector.test.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
paperclip-cloud-connector.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
paperclip-id-gmail-connector.ts feat(apps): add Paperclip Cloud managed OAuth connector (#12600) 2026-08-31 14:34:46 -05:00
pipeline-case-outputs.ts
…
pipeline-conversation-context.ts
…
pipelines-aggregation.ts
…
pipelines.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
plan-review-context.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
plugin-capability-validator.ts feat(plugin-sdk): interactions/approvals respond + attachment read capabilities for the chat gateway (#10066) 2026-07-22 21:30:34 -07:00
plugin-config-validator.ts
…
plugin-database.ts
…
plugin-dev-watcher.ts
…
plugin-environment-driver.ts refactor(environment): classify environment capabilities from static driver definitions (#12045) 2026-08-23 21:24:59 -07:00
plugin-event-bus.ts
…
plugin-host-service-cleanup.ts
…
plugin-host-services.ts feat: parallelize sandbox file-sync behind a provider opt-in capability (#11736) 2026-08-19 12:34:11 -07:00
plugin-install-guard.ts feat: make in-app features cloud-aware (#10850) 2026-08-04 23:00:14 -05:00
plugin-job-coordinator.ts
…
plugin-job-scheduler.ts
…
plugin-job-store.ts
…
plugin-lifecycle.ts
…
plugin-loader.ts fix(plugins): retry errored plugins at boot instead of leaving them dead (#12054) 2026-08-23 16:52:42 -07:00
plugin-local-folders.ts
…
plugin-log-retention.ts
…
plugin-managed-agents.ts fix(server): authorize agent resume through direct grants (#12047) 2026-08-23 16:15:32 -05:00
plugin-managed-routines.ts feat(routines): expose activity gate API (#9438) 2026-07-24 16:47:24 -05:00
plugin-managed-skills.ts
…
plugin-manifest-validator.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
plugin-registry.ts fix(plugin-sdk): thread companyId through configChanged + fail-closed cross-tenant guard (LOOA-687) (#10096) 2026-07-23 09:50:48 -07:00
plugin-runtime-sandbox.ts
…
plugin-secrets-handler.ts
…
plugin-state-store.ts
…
plugin-stream-bus.ts
…
plugin-tool-dispatcher.ts
…
plugin-tool-registry.ts
…
plugin-worker-manager.ts feat(runner): integrate Codex native execution (#12616) 2026-08-31 22:51:17 -05:00
portable-path.ts
…
principal-access-compatibility.ts
…
productivity-review.ts Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
project-workspace-runtime-config.ts
…
projects.ts Exclude archived projects from the default project list route (#10146) 2026-07-24 07:19:58 -07:00
provider-profile-qualification.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
provider-trace-store.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
provider-trace-workspace-diff-reprojection.test.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
provider-trace-workspace-diff-reprojection.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
question-response-delivery.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
quota-windows.ts
…
recovery-observability.ts fix(recovery): stop automatic stranded-task takeovers (#11961) 2026-08-22 11:41:24 -05:00
remote-agent-profiles.test.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
remote-agent-profiles.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
remote-http-endpoint-guard.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
remote-http-fetch.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
remote-url-credentials.test.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
remote-url-credentials.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
resource-memberships.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
responsible-user-denial-run-outcomes.test.ts
…
responsible-user-denial-run-outcomes.ts
…
routable-blocked.ts Route blocked transitions to explicit unblock owners (#10112) 2026-07-23 15:49:28 -05:00
routines-formatter-cache.test.ts
…
routines.ts fix(routines): clear transient execution failures (#9689) 2026-08-19 15:43:26 -05:00
run-continuations.ts
…
run-liveness.ts
…
run-log-store.test.ts Add opt-in in-flight run-log mirroring with graceful-shutdown flush (#10512) 2026-07-30 14:01:02 -07:00
run-log-store.ts Add opt-in in-flight run-log mirroring with graceful-shutdown flush (#10512) 2026-07-30 14:01:02 -07:00
run-scratch.test.ts
…
run-scratch.ts
…
run-secret-redaction.ts fix(server): keep Date fields intact through secret redaction; harden chat notice timestamps (#10984) 2026-08-06 10:29:07 -05:00
runtime-skill-selections.ts feat(skills): add beta releases for the core Paperclip skill (#10228) 2026-07-27 19:45:59 -05:00
sandbox-orphan-cleanup-spool.ts feat: Claude login on the new-agent page before agent creation (#11347) 2026-08-17 13:42:51 -07:00
sandbox-provider-runtime.ts feat: Claude login on the new-agent page before agent creation (#11347) 2026-08-17 13:42:51 -07:00
secret-proposal-authorization.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
secret-proposal-notifications.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
secret-proposals.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
secrets.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
session-workspace-cwd.test.ts
…
session-workspace-cwd.ts
…
setting-defaults.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
settings-visibility.ts feat: operator-configurable settings visibility via PAPERCLIP_HIDDEN_SETTINGS (#11823) 2026-08-20 17:54:44 -07:00
setup-token-reaper.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
setup-token-reaper.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
setup-token-session.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
setup-token-session.ts fix(setup-token): pin the start guard to the served adapter (#12179) 2026-08-25 19:48:44 -07:00
setup-token-transport-binding.test.ts feat(login): use the login pseudo-terminal for Codex device login and de-Claude the shared channel (#12020) 2026-08-23 09:44:59 -07:00
setup-token-transport-binding.ts feat(login): use the login pseudo-terminal for Codex device login and de-Claude the shared channel (#12020) 2026-08-23 09:44:59 -07:00
sidebar-badges.ts
…
sidebar-preferences.ts
…
skills-catalog.ts
…
smoke-lab.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
source-trust.ts
…
stalled-review-decisions.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
status-card-finalization.ts feat(status-cards): add experimental status card update view (#10101) 2026-07-24 12:26:43 -05:00
status-card-update-engine.ts feat(status-cards): join summary-mentioned issues to watched set (#10205) 2026-07-24 16:44:56 -05:00
status-cards.ts feat(status-cards): join summary-mentioned issues to watched set (#10205) 2026-07-24 16:44:56 -05:00
successful-run-handoff-state.ts fix(issues): quiet missing-disposition warnings while a live continuation is running (#10899) 2026-08-05 15:59:01 -05:00
summary-slot-finalization.ts feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
summary-slots.ts fix: isolate execution workspace summaries (#10790) 2026-08-11 08:56:32 -04:00
systemd-notify.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
task-watchdog-scope.ts
…
task-watchdogs.ts fix(interactions): authorize resolvers consistently (#11376) 2026-08-16 13:46:50 -05:00
teams-catalog.ts
…
tool-access-policy.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
tool-access.ts Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
tool-connection-activity.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
tool-content-guards.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
tool-gateway.ts feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
tool-oauth-legacy-backfill.ts
…
tool-profile-binding-precedence.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
tool-profile-binding-precedence.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
tool-runtime-metrics.ts
…
tool-runtime-supervisor.ts
…
trust-preset-resolver.ts
…
vercel-connect.test.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
vercel-connect.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
work-products.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
work-timeline.ts fix(ui): load the full selected timeline window (#9576) 2026-07-30 21:40:57 -07:00
workspace-file-resources.ts fix: bound workspace Git scans (#11572) 2026-08-17 22:11:30 -05:00
workspace-git-operation-scheduler.test.ts fix(adapter-utils): harden the referenced-project ignore scan (#12214) 2026-08-26 08:30:42 -07:00
workspace-git-operation-scheduler.ts fix(adapter-utils): honor .gitignore for referenced-project staging (#12184) 2026-08-25 14:22:47 -07:00
workspace-instance-cleanup.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
workspace-login-handoff-issuer.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
workspace-operation-log-store.ts
…
workspace-operations.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
workspace-readiness.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
workspace-realization.ts refactor(environment): classify environment capabilities from static driver definitions (#12045) 2026-08-23 21:24:59 -07:00
workspace-runtime-exposure-backfill.test.ts feat(runtime): managed Tailscale HTTPS lifecycle, durable runtime leases, and bounded control recovery (#11525) 2026-08-17 06:23:33 -04:00
workspace-runtime-exposure.test.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-runtime-leases.ts feat(workspaces): sign the workspace login handoff and gate readiness (#11671) 2026-08-19 02:37:02 -05:00
workspace-runtime-read-model.test.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-runtime-read-model.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-runtime-ready-comment.test.ts fix(workspaces): attach PR preparation to existing branches (#11703) 2026-08-21 17:23:18 -05:00
workspace-runtime.ts fix(workspaces): enable UI hot reload by default (#12612) 2026-09-01 10:06:53 -05:00