Add the two matrices whose absence hid the leaks: single-quoted and ANSI-C roots, full-header and value-only, with an adjacent serialized double-quoted segment at depths 0 to 3; and line continuations with LF and CRLF after an unquoted value, after each closed quoted argument, inside a double-quoted value, and on the value's first byte. Turn the permissive tables into transformation oracles. The truncated-tail, even-run space and line-end, and fixpoint tables now assert exact output where it is determinate. Rows stay on removal and stability only where the union makes the exact output a policy artifact rather than a fact about the credential: every serialized truncated row, which loses its outer delimiter, and the adjacent segment carrying an escaped quote, where scanning the tail at every layer runs a deeper reading to the line end. Each of those carries the reason inline. Claude-Session: https://claude.ai/code/session_01RYigf3eMFJjey9iKRApPGE |
||
|---|---|---|
| .. | ||
| src | ||
| CHANGELOG.md | ||
| README.md | ||
| package.json | ||
| tsconfig.json | ||
README.md
@paperclipai/adapter-utils
Shared utilities for Paperclip adapters: process spawning, environment injection, sandbox/SSH transport, workspace sync, and the round-trip helpers that move code between the local execution-workspace cwd and wherever the agent actually runs.
For the adapter-author guide see
docs/adapters/creating-an-adapter.md
and the in-repo notes at packages/adapters/AUTHORING.md.
No-remote-git contract
The local execution-workspace cwd is the only persistence boundary across runs. No adapter may depend on a git remote for cross-run state.
Adapters that run the agent on a different host should use the SSH round-trip
helpers in src/ssh.ts:
prepareWorkspaceForSshExecution({ spec, localDir, remoteDir })— bundles the local cwd (tracked files, dirty edits, untracked additions, and the git history needed to reconstruct it) toremoteDirbefore the run starts. Runs with nogit remoteconfigured.restoreWorkspaceFromSshExecution({ spec, localDir, remoteDir, ... })— syncs the remote cwd back intolocalDirafter the run, including any new commits the agent created. Also runs with nogit remoteconfigured.
prepareRemoteManagedRuntime in
src/remote-managed-runtime.ts wraps both
calls for adapters that want a per-run remote workspace and an automatic
restoreWorkspace() finally hook.
The invariant is pinned by the no-remote-git contract case in
src/ssh-fixture.test.ts, which asserts that a
remote-only commit propagates to the local worktree through the
prepare → restore round-trip with no git remote configured at any point. Do
not regress that test.