paperclip/packages/shared/src
Dotta 018ca5daaf
fix: verify ACP Stop and preserve safe continuation (#13119)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Task controls coordinate provider execution and queued user
messages.
> - Stop could finish before an embedded ACP provider stopped its tools.
> - A later request could be held for reconciliation without a clear
task response.
> - A restored provider could also retain the stopped run's API
credential.
> - This pull request verifies provider termination and preserves safe
session continuation.
> - Operators can continue known-safe work and see why uncertain work
cannot start.

## Linked Issues or Issue Description

**What happened?**

Stop could leave an embedded ACP provider running. A queued follow-up
followed by “go” could fail before it reached the provider. Task chat
could show a generic missing-response message. Even a restored session
could use the previous run's credential and fail its task update.

**Expected behavior**

Stop waits for confirmed provider termination. A later explicit wake
continues the same compatible session only when recorded actions have
known outcomes. It carries pending comments and the current run's
environment. Uncertain actions retain a visible reconciliation hold.
Composer Stop preserves the existing pause rule: conversation can
continue while paused, but task work requires Resume.

**Steps to reproduce**

1. Start an embedded ACP task.
2. Send a second request while the provider is running.
3. Interrupt the run, then send “go”. Also test composer Stop followed
by Resume work.
4. Check that the request is delivered once and that the provider can
complete the task through the current run's API credential.
5. Repeat with an unfinished write. Confirm that the write stops and
that further execution stays blocked with a visible reason.

**Paperclip version or commit**

Built from source on master at `3bc60dd8b` plus this branch.

**Deployment mode**

Local source build with an isolated embedded PostgreSQL instance.

Refs #11183. Refs #12552. Those changes address recovery after operator
cancellation. This change also covers embedded ACP termination, session
proof, pending-comment delivery, and task feedback.

## What Changed

- Propagate Stop into embedded ACP and wait for bounded adapter cleanup
and provider exit. Retain the actual ChildProcess object for forced
termination on all platforms; never signal a recycled numeric PID.
- Preserve interrupted checkpoints only for acknowledged, local,
persistent sessions with settled reads or no tools. Keep writes,
incomplete actions, and forced termination blocked.
- Restore the same compatible provider session with the current run's
environment. Reject fresh-session fallback for an interrupted
checkpoint.
- Adopt pending comments on the next explicit wake. Stop alone does not
dispatch them.
- Share the execution-blocker rule across dispatch, Resume, and task
detail. Show Stopped or Couldn't start with the recorded reason. Resolve
the stopped agent for the run link, including reviewer runs.
- Keep execution reconciliation holds intact when generic recovery sees
queued comments or healthy child tasks.
- Add process, service, component, and browser regression coverage. Fix
disposable database cleanup and React test settling exposed by the full
suite.

## Verification

- Passed `pnpm -r typecheck`, `pnpm build`, and `pnpm
check:token-gates`.
- Passed all three `acp-stop-continuation.spec.ts` browser journeys.
They use an actual ACP child process and require task completion through
the agent API.
- Passed 165 adapter execution, operator-stop, and child-process control
tests, 17 queued-comment route tests, and 65 tests in the two adjusted
UI suites. Earlier focused recovery, heartbeat, and task-control tests
also passed.
- Manually used the browser to queue a request, Stop, send “go” while
paused, and Resume. The same session answered once and moved the task to
Done with the current run's credential.
- Manually interrupted an unfinished write. Its file size stayed fixed
for five seconds. “Go” showed the reconciliation reason and did not
start another provider prompt.
- Separate live Claude ACP smoke checks confirmed that Stop ended a
disposable local write and that a no-tool interruption could resume the
exact provider session. The browser fixture does not call Drive or
another external app.
- Passed all 5,615 UI tests and 3,090 other workspace tests. The CLI and
general server groups pass with targeted retries: two transient server
failures passed together on retry, and two embedded-database startup
failures passed after removing abandoned shared-memory segments from
this task's completed browser fixtures. All 144 serialized server suites
completed, with 2,189 tests passing after two transient HTTP socket
failures passed on retry.
- Passed all 135 heartbeat process/recovery tests, including a
deterministic regression that failed before the recovery-sweep fix.
- Passed 18 dispatch integration tests, including stopped-reviewer
links, company boundaries, and malformed run IDs.
- Greptile is 5/5 on `7dd170d83`, with zero unresolved review threads.
The security scan and all required CI gates pass for the same commit.

## Risks

- Safe continuation depends on complete tool reporting and a restorable
local provider session. Unknown outcomes remain blocked and require
reconciliation.
- Provider cleanup can take time. A timeout does not grant replay
permission.
- The change adds optional adapter context fields and an optional issue
projection. It does not change the database schema or require a
migration.
- Test cleanup truncates company data only in a disposable test
database.

## Model Used

OpenAI GPT-6, running as Codex with repository tools, code execution,
and browser interaction. The runtime does not expose a more specific
model deployment ID or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-09 22:06:06 -05:00
..
app-definitions feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
runtime-exposure fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
telemetry feat(telemetry): add the agent.task_run event and emit it at every terminal run transition (#12809) 2026-09-04 08:21:32 -07:00
types fix: verify ACP Stop and preserve safe continuation (#13119) 2026-09-09 22:06:06 -05:00
validators feat: add opt-in chat provider and data foundation (#13100) 2026-09-09 13:49:12 -05:00
account-handle.test.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
account-handle.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
adapter-agnostic-keys.test.ts fix: deduplicate adapter-agnostic config keys (#9058) 2026-07-05 21:47:38 -07:00
adapter-auth-check-code.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-auth-check-code.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-auth-session.ts Add sandbox device-login for the Codex adapter (#11237) 2026-08-12 08:58:25 -07:00
adapter-type.ts feat(adapters): external adapter plugin system with dynamic UI parser 2026-04-03 21:11:20 +01:00
adapter-types.test.ts [codex] Split backend control-plane QoL slice (#4700) 2026-04-28 16:46:45 -05:00
agent-eligibility.test.ts feat(agents): warn when an agent's escalation path routes to a paused manager (#10657) 2026-08-01 17:42:42 -07:00
agent-eligibility.ts feat(agents): warn when an agent's escalation path routes to a paused manager (#10657) 2026-08-01 17:42:42 -07:00
agent-url-key.ts feat: company portability — export/import companies and agents 2026-03-02 09:06:58 -06:00
api.ts feat: maintained in_review review-path contract + stalled-review actions (#10675) 2026-08-04 13:54:40 -05:00
app-definitions-url.test.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.generated.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.ingestion-report.json feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.test.ts feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
app-definitions.ts feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
company-import-transfer.test.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
company-import-transfer.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
config-schema.test.ts fix(config): preserve extensions and guard invalid repairs (#11005) 2026-08-07 00:41:19 -05:00
config-schema.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
connection-intent-guidance.test.ts feat(connections): connect services from native task feeds (#13058) 2026-09-08 15:55:26 -05:00
connection-intent-guidance.ts feat(connections): connect services from native task feeds (#13058) 2026-09-08 15:55:26 -05:00
constants.ts Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
decision.test.ts feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
document-anchors.test.ts [codex] Add document annotations and comments (#6733) 2026-05-26 06:41:23 -07:00
document-anchors.ts [codex] Add document annotations and comments (#6733) 2026-05-26 06:41:23 -07:00
env-file.test.ts fix(config): preserve env files during managed updates (#10980) 2026-08-07 00:54:43 -05:00
env-file.ts fix(config): preserve env files during managed updates (#10980) 2026-08-07 00:54:43 -05:00
environment-custom-images.test.ts Add browser SSH terminal for custom image setup (#8911) 2026-07-03 16:44:21 -07:00
environment-custom-images.ts Add browser SSH terminal for custom image setup (#8911) 2026-07-03 16:44:21 -07:00
environment-support.test.ts fix(runner): repair paid provider startup paths (#12769) 2026-09-04 07:58:44 -05:00
environment-support.ts fix(runner): repair paid provider startup paths (#12769) 2026-09-04 07:58:44 -05:00
execution-workspace-guards.ts Guard closed isolated workspaces on issues 2026-04-04 17:48:54 -05:00
external-objects-server.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
external-objects.test.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
external-objects.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
feature-catalog.test.ts Add a feature catalog build artifact derived from the experimental settings schema (#10055) 2026-07-22 18:12:56 -07:00
feature-catalog.ts feat(onboarding): first task opens as a chat with a chief of staff (#13068) 2026-09-08 20:19:14 -07:00
frontmatter.test.ts Skill Studio: three-pane skill IDE with sandboxed test runs (#9241) 2026-07-09 13:08:56 -05:00
frontmatter.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
github-connectors.ts feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
gitignore-runtime.test.ts chore: ignore materialized Paperclip runtime directory 2026-07-08 17:59:43 -07:00
google-workspace-connectors.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
home-paths.test.ts [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
home-paths.ts [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
humanize-connection.test.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
humanize-connection.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
index.ts fix: verify ACP Stop and preserve safe continuation (#13119) 2026-09-09 22:06:06 -05:00
issue-attribution.test.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
issue-attribution.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
issue-references.test.ts Fix Cloud tenant issue identifier routes (#5196) 2026-05-04 13:20:58 -05:00
issue-references.ts Fix Cloud tenant issue identifier routes (#5196) 2026-05-04 13:20:58 -05:00
issue-thread-interactions.test.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
issue-write-denial.test.ts feat(issues): explain cross-task agent writes with attribution, audit receipts, and actionable denials (#10843) 2026-08-04 23:02:51 -05:00
issue-write-denial.ts feat(issues): explain cross-task agent writes with attribution, audit receipts, and actionable denials (#10843) 2026-08-04 23:02:51 -05:00
markdown-work-products.test.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
markdown-work-products.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
mcp-config-help-prompt.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
mcp-remote-headers.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
mcp-remote-headers.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
network-bind.ts Introduce bind presets for deployment setup 2026-04-11 07:09:07 -05:00
node-version.ts fix(adapters): prevent engine fallback and preserve usable runtime defaults (#13105) 2026-09-09 13:27:24 -05:00
oauth-endpoint-url.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
oauth-endpoint-url.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
pipeline-case-type.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
pipeline-health.test.ts [codex] Deduplicate pipeline automation health warnings (#9090) 2026-07-06 12:12:18 -05:00
pipeline-health.ts [codex] Deduplicate pipeline automation health warnings (#9090) 2026-07-06 12:12:18 -05:00
portability-fidelity.test.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-fidelity.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-hash.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-zip.test.ts fix(server): raise company import zip upload limit to 1 GB and make it operator-configurable (#11184) 2026-08-10 12:47:03 -07:00
portability-zip.ts fix(server): raise company import zip upload limit to 1 GB and make it operator-configurable (#11184) 2026-08-10 12:47:03 -07:00
project-mentions.test.ts [codex] Roll up May 17 branch changes (#6210) 2026-05-17 17:15:06 -05:00
project-mentions.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
project-url-key.ts fix: append short UUID suffix to project slugs when non-ASCII characters are stripped to prevent slug collisions 2026-03-31 16:35:30 +00:00
resource-memberships.test.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
responsible-user-denial.test.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
responsible-user-denial.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
routine-variables.test.ts feat(routines): add date variable controls (#8655) 2026-06-26 12:00:16 -05:00
routine-variables.ts feat(routines): add date variable controls (#8655) 2026-06-26 12:00:16 -05:00
runner-goal.ts Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
self-serve-mcp-research.json feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
self-serve-mcp-research.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
setting-defaults.test.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
setting-defaults.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
settings-visibility.test.ts Let operators hide the Provider vaults and Proposals tabs (#12284) 2026-08-27 11:28:15 -07:00
settings-visibility.ts Remove the instance Heartbeats settings page (#12282) 2026-08-27 11:31:43 -07:00
summary-slot.test.ts fix: isolate execution workspace summaries (#10790) 2026-08-11 08:56:32 -04:00
trust-policy.ts fix(auth): clarify protected-agent assignment blocks (#10893) 2026-08-05 10:09:17 -05:00
work-product.test.ts Add workspace file viewer and artifact links (#7681) 2026-06-09 17:17:43 -05:00
workspace-commands.test.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-commands.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-file-resource.test.ts fix(files): only highlight accessible workspace file links (#11090) 2026-08-11 12:11:45 -04:00
worktree-port-registry.test.ts fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
worktree-port-registry.ts fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
worktree-seed-source.test.ts fix(workspaces): seed managed worktrees when the base checkout has no config (#11752) 2026-08-20 08:42:16 -07:00
worktree-seed-source.ts fix(workspaces): seed managed worktrees when the base checkout has no config (#11752) 2026-08-20 08:42:16 -07:00