paperclip/packages/adapter-utils/src
Dotta 68f69975a4
Harden control-plane safety and issue identifiers (#5292)
## Thinking Path

> - Paperclip relies on issue identifiers, execution policies, and agent
heartbeat rules to keep autonomous work auditable.
> - Safety checks need to reject ambiguous agent handoffs, and
identifier parsing needs to support Cloud tenant prefixes.
> - Agent instructions also need to make final-disposition rules
explicit so work does not stall in vague states.
> - This pull request isolates backend correctness and governance
hardening from the UI and recovery-system-notice branches.
> - The benefit is safer in-review transitions, better identifier
compatibility, and clearer agent operating contracts.

## What Changed

- Fixed run-aware confirmation ordering and interrupted-run state
cleanup.
- Added Cloud tenant identity bootstrap and alphanumeric issue
identifier support across shared parsing and server routes.
- Guarded agent-authored `in_review` updates unless a real review path
exists.
- Tightened heartbeat disposition instructions in adapter
utilities/default AGENTS/Paperclip skill.

## Verification

- `pnpm install --frozen-lockfile`
- `pnpm exec vitest run packages/shared/src/issue-references.test.ts
server/src/__tests__/issue-identifier-routes.test.ts
server/src/__tests__/issue-execution-policy-routes.test.ts
packages/adapter-utils/src/server-utils.test.ts` initially had the first
execution-policy test hit Vitest's 5s timeout under the parallel bundle
while the rest passed.
- `pnpm exec vitest run
server/src/__tests__/issue-execution-policy-routes.test.ts
--testTimeout=20000` passed with 10/10 tests.

- Follow-up: `pnpm run typecheck:build-gaps` passed.
- Follow-up: `pnpm --filter @paperclipai/ui typecheck` passed.
- Follow-up: `pnpm vitest run
server/src/__tests__/issue-comment-reopen-routes.test.ts
server/src/__tests__/company-portability.test.ts
server/src/__tests__/costs-service.test.ts` passed.
- Follow-up: `pnpm vitest run ui/src/context/LiveUpdatesProvider.test.ts
ui/src/lib/issue-chat-messages.test.ts
ui/src/lib/issue-reference.test.ts
ui/src/lib/issue-timeline-events.test.ts` passed.

## Risks

- Medium control-plane risk: in-review update validation changes agent
behavior. The error message is explicit and tests cover allowed review
paths.

## Model Used

- OpenAI GPT-5 Codex via Paperclip `codex_local` adapter, with
shell/git/GitHub CLI tool use.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-05-06 07:49:47 -05:00
..
billing.test.ts feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
billing.ts feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
command-managed-runtime.test.ts Let sandbox providers declare shell defaults (#5114) 2026-05-03 12:19:35 -07:00
command-managed-runtime.ts Wire per-adapter sandbox install commands through test and execute paths (#5280) 2026-05-05 08:29:28 -07:00
command-redaction.ts Add ACPX local adapter runtime (#4893) 2026-04-30 19:57:05 -05:00
execution-target-sandbox.test.ts Sanitize remote execution envs at the boundary (#5325) 2026-05-05 19:30:14 -07:00
execution-target.test.ts Sanitize remote execution envs at the boundary (#5325) 2026-05-05 19:30:14 -07:00
execution-target.ts Sanitize remote execution envs at the boundary (#5325) 2026-05-05 19:30:14 -07:00
index.ts Let adapters declare runtime command spec for remote provisioning (#5141) 2026-05-03 18:35:36 -07:00
log-redaction.ts fix(ui): external adapter selection, config field placement, and transcript parser freshness 2026-04-03 21:11:22 +01:00
remote-execution-env.ts Sanitize remote execution envs at the boundary (#5325) 2026-05-05 19:30:14 -07:00
remote-managed-runtime.ts Migrate SSH environment callback to bridge (#5116) 2026-05-03 12:43:52 -07:00
sandbox-callback-bridge.test.ts Serialize sandbox callback bridge against concurrent heartbeats (#5326) 2026-05-05 20:01:04 -07:00
sandbox-callback-bridge.ts Serialize sandbox callback bridge against concurrent heartbeats (#5326) 2026-05-05 20:01:04 -07:00
sandbox-managed-runtime.test.ts Add sandbox callback bridge for remote environment API access (#4801) 2026-04-29 16:37:34 -07:00
sandbox-managed-runtime.ts Migrate SSH environment callback to bridge (#5116) 2026-05-03 12:43:52 -07:00
sandbox-shell.ts Let sandbox providers declare shell defaults (#5114) 2026-05-03 12:19:35 -07:00
server-utils.test.ts Harden control-plane safety and issue identifiers (#5292) 2026-05-06 07:49:47 -05:00
server-utils.ts Harden control-plane safety and issue identifiers (#5292) 2026-05-06 07:49:47 -05:00
session-compaction.ts Add ACPX local adapter runtime (#4893) 2026-04-30 19:57:05 -05:00
ssh-fixture.test.ts Serialize sandbox callback bridge against concurrent heartbeats (#5326) 2026-05-05 20:01:04 -07:00
ssh.ts Serialize sandbox callback bridge against concurrent heartbeats (#5326) 2026-05-05 20:01:04 -07:00
types.ts Let adapters declare runtime command spec for remote provisioning (#5141) 2026-05-03 18:35:36 -07:00