paperclip/packages/adapter-utils
Michel Tomas 831ff2036b
test(adapter-utils): exact oracles for the scanner's tables
Add the two matrices whose absence hid the leaks: single-quoted and ANSI-C
roots, full-header and value-only, with an adjacent serialized double-quoted
segment at depths 0 to 3; and line continuations with LF and CRLF after an
unquoted value, after each closed quoted argument, inside a double-quoted
value, and on the value's first byte.

Turn the permissive tables into transformation oracles. The truncated-tail,
even-run space and line-end, and fixpoint tables now assert exact output
where it is determinate. Rows stay on removal and stability only where the
union makes the exact output a policy artifact rather than a fact about the
credential: every serialized truncated row, which loses its outer delimiter,
and the adjacent segment carrying an escaped quote, where scanning the tail
at every layer runs a deeper reading to the line end. Each of those carries
the reason inline.

Claude-Session: https://claude.ai/code/session_01RYigf3eMFJjey9iKRApPGE
2026-09-06 02:45:31 +02:00
..
src test(adapter-utils): exact oracles for the scanner's tables 2026-09-06 02:45:31 +02:00
CHANGELOG.md fix: bound workspace Git scans (#11572) 2026-08-17 22:11:30 -05:00
README.md PAPA-430: workspace finalize gates + no-remote-git enforcement (#6969) 2026-05-29 08:25:29 -07:00
package.json feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
tsconfig.json Fix root TypeScript solution config 2026-03-09 14:09:30 -05:00

README.md

@paperclipai/adapter-utils

Shared utilities for Paperclip adapters: process spawning, environment injection, sandbox/SSH transport, workspace sync, and the round-trip helpers that move code between the local execution-workspace cwd and wherever the agent actually runs.

For the adapter-author guide see docs/adapters/creating-an-adapter.md and the in-repo notes at packages/adapters/AUTHORING.md.

No-remote-git contract

The local execution-workspace cwd is the only persistence boundary across runs. No adapter may depend on a git remote for cross-run state.

Adapters that run the agent on a different host should use the SSH round-trip helpers in src/ssh.ts:

  • prepareWorkspaceForSshExecution({ spec, localDir, remoteDir }) — bundles the local cwd (tracked files, dirty edits, untracked additions, and the git history needed to reconstruct it) to remoteDir before the run starts. Runs with no git remote configured.
  • restoreWorkspaceFromSshExecution({ spec, localDir, remoteDir, ... }) — syncs the remote cwd back into localDir after the run, including any new commits the agent created. Also runs with no git remote configured.

prepareRemoteManagedRuntime in src/remote-managed-runtime.ts wraps both calls for adapters that want a per-run remote workspace and an automatic restoreWorkspace() finally hook.

The invariant is pinned by the no-remote-git contract case in src/ssh-fixture.test.ts, which asserts that a remote-only commit propagates to the local worktree through the prepare → restore round-trip with no git remote configured at any point. Do not regress that test.