Promote the round-eight review matrices into repository tables so the scanner's contract is checked here rather than in a harness under /tmp. Opener kind by value kind by suffix kind by serialization depth 0 to 3, including the adjacent double-quoted segment whose first byte is a space that leaked at depths 2 and 3. Truncated tails of each quote kind after each root kind, including the escaped-quote tail whose remainder leaked. Even backslash runs of 2, 4, 6 and 8 before a quote, a plain character, a space and a line end. Serialized rows assert the marker is gone, the output is stable, and the output still parses as the JSON string it arrived as and decodes to the redacted shell text. Truncated rows assert removal and stability only: a serialized string cut inside the header argument loses its outer delimiter, which is the contract's known over-redaction and never keeps a credential. Claude-Session: https://claude.ai/code/session_01RYigf3eMFJjey9iKRApPGE |
||
|---|---|---|
| .. | ||
| src | ||
| CHANGELOG.md | ||
| README.md | ||
| package.json | ||
| tsconfig.json | ||
README.md
@paperclipai/adapter-utils
Shared utilities for Paperclip adapters: process spawning, environment injection, sandbox/SSH transport, workspace sync, and the round-trip helpers that move code between the local execution-workspace cwd and wherever the agent actually runs.
For the adapter-author guide see
docs/adapters/creating-an-adapter.md
and the in-repo notes at packages/adapters/AUTHORING.md.
No-remote-git contract
The local execution-workspace cwd is the only persistence boundary across runs. No adapter may depend on a git remote for cross-run state.
Adapters that run the agent on a different host should use the SSH round-trip
helpers in src/ssh.ts:
prepareWorkspaceForSshExecution({ spec, localDir, remoteDir })— bundles the local cwd (tracked files, dirty edits, untracked additions, and the git history needed to reconstruct it) toremoteDirbefore the run starts. Runs with nogit remoteconfigured.restoreWorkspaceFromSshExecution({ spec, localDir, remoteDir, ... })— syncs the remote cwd back intolocalDirafter the run, including any new commits the agent created. Also runs with nogit remoteconfigured.
prepareRemoteManagedRuntime in
src/remote-managed-runtime.ts wraps both
calls for adapters that want a per-run remote workspace and an automatic
restoreWorkspace() finally hook.
The invariant is pinned by the no-remote-git contract case in
src/ssh-fixture.test.ts, which asserts that a
remote-only commit propagates to the local worktree through the
prepare → restore round-trip with no git remote configured at any point. Do
not regress that test.