paperclip/doc/plans
Dotta 3b550c80fa
fix(codex): correct startup trust, history reads, and resume usage (#13110)
## Thinking Path

> - Paperclip runs Codex locally and in remote sandboxes.
> - The runner must preserve startup configuration and session identity.
> - Missing project trust can disable repository configuration.
> - Full-history requests use deprecated provider fields.
> - Resume usage describes old work and must not become new run usage.
> - This change corrects startup trust, state reads, and usage
classification.

## Linked Issues or Issue Description

**What happened?**

Normal Codex runs could show repository-trust and history-deprecation
warnings.
Resume could report the preceding turn's token snapshot as a late-turn
warning.
The historical last-usage value could also be attributed to the new run.

**Expected behavior**

Trust the server-selected startup root in isolated configuration. Read
lightweight
provider state and paginated evidence. Use historical cumulative usage
as a
baseline without a new charge or user-facing warning.

**Steps to reproduce**

1. Start a native Codex task in a selected repository.
2. Finish the turn and resume the provider thread.
3. Inspect provider notices, history requests, and per-run usage.
4. Repeat startup and cold resume inside a Daytona sandbox.

**Paperclip version or commit**

Codex CLI 0.153.4 is the pinned runtime and reproduced baseline.
Replayed onto master at 6abeb6733. Related authority work: Refs #13092.
This PR retains its startup cleanup and protocol-integrity checks.

**Deployment mode**

Local source checkout and disposable Daytona sandbox.

## What Changed

- Classify the exact historical resume usage event before the generic
stale-turn warning.
- Persist cumulative usage baselines across recovery of the same run.
- Use excludeTurns on resume and lightweight thread reads.
- Page turn metadata and selected turn items with cursor and identity
validation.
- Reject unsupported or incomplete history instead of guessing that
execution is idle.
- Trust the startup execution root on its host, including Git worktree
trust keys.
- Start Codex in that root and retain the selected sandbox profile on
later turns.
- Keep unrelated isolated configuration and Codex's separate hook trust
policy.
- Add Rust, TypeScript, accounting, native integration, and local
run-log documentation.

## Verification

- Codex and native-transport TypeScript: 333 passed before PR replay.
- Adjacent OpenCode/ACPX driver and accounting tests: 49 passed.
- Rust library, serialized: 226 passed. Native Codex integration: 72
passed, 1 ignored, plus two pagination regressions.
- Repository typecheck and build passed. All repository test groups have
passing coverage after fixture and resource retests; the initial
monolithic command was not clean.
- Fresh real Codex native browser tasks returned correct answers without
the three targeted notices. Answers persisted after refresh and restart.
- Real same-thread TypeScript driver tests passed locally and in
Daytona, including cold resume, configuration, skills, and an approved
harmless hook.
- Local usage summed to 64,607 tokens. Daytona usage summed to 42,737
tokens. Each sum matched its final session total exactly.
- See doc/plans/2026-09-09-codex-integration-acceptance.md for the scope
and limits of the live tests.
- After replay onto current master and review fixes: 334 Codex, backend,
and live-session tests passed, including checkpoint serialization and
real-runner process restart. TypeScript checks passed.
- The native Codex integration run passed 83 tests; the large lineage
test passed separately with the release runner (its debug build exceeded
the test deadline).
- All GitHub checks passed on the final PR head. Greptile is 5/5 with no
unresolved review threads. CI regenerates the lockfile for the added
TOML dependency, per repository policy.
- The first server shard hit a timing-dependent duplicate-key failure in
the unchanged artifact-document concurrency test. Its focused 11-test
suite passed locally. One CI retry on the same head passed all 103 files
and 1,405 tests (2 skipped): [retry
result](https://github.com/paperclipai/paperclip/actions/runs/34398832930/job/102631274667).

## Risks

- Trust applies only to the server-selected startup root and isolated
configuration. Sandbox and tool permissions remain authoritative.
- Codex still requires approval of individual hook hashes. This change
does not bypass that policy.
- Providers without the required history APIs fail explicitly.
- Daytona acceptance used the production TypeScript driver. Remote
Paperclip UI and remote Rust execution were not tested.
- No new public API, database state, recovery policy, or UI control is
included.

## Model Used

OpenAI Codex, GPT-6 (`gpt-6-astra`). Used for reasoning, code edits,
tool use,
and test execution. The exact context-window limit is not exposed in
this
session. Real-provider acceptance used Codex CLI 0.153.4 with
`gpt-5.6-sol`.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-09 15:35:18 -05:00
..
2026-02-16-module-system.md Add company import export v2 plan 2026-03-13 21:10:45 -05:00
2026-02-18-agent-authentication-implementation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-18-agent-authentication.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-19-agent-mgmt-followup-plan.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-19-ceo-agent-creation-and-hiring.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-20-issue-run-orchestration-plan.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-20-storage-system-implementation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-21-humans-and-permissions-implementation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-21-humans-and-permissions.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-23-cursor-cloud-adapter.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-23-deployment-auth-mode-consolidation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-03-10-workspace-strategy-and-git-worktrees.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-03-11-agent-chat-ui-and-issue-backed-conversations.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-03-13-TOKEN-OPTIMIZATION-PLAN.md fix: isolate codex home in worktrees 2026-03-13 11:53:56 -05:00
2026-03-13-agent-evals-framework.md docs: add agent evals framework plan 2026-03-13 15:07:56 -05:00
2026-03-13-company-import-export-v2.md Use positional source arg for company import 2026-03-23 08:14:51 -05:00
2026-03-13-features.md docs: update PRODUCT.md and add 2026-03-13 features plan 2026-03-13 07:25:23 -05:00
2026-03-13-paperclip-skill-tightening-plan.md docs: add paperclip skill tightening plan 2026-03-13 14:37:44 -05:00
2026-03-13-plugin-kitchen-sink-example.md Add kitchen sink plugin example 2026-03-13 23:03:51 -05:00
2026-03-13-workspace-product-model-and-work-product.md docs: add dated plan naming rule and align workspace plan 2026-03-13 09:16:28 -05:00
2026-03-14-adapter-skill-sync-rollout.md [codex] Add skills CLI and catalog management (#6782) 2026-05-28 07:33:51 -10:00
2026-03-14-billing-ledger-and-reporting.md feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
2026-03-14-budget-policies-and-enforcement.md feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
2026-03-14-skills-ui-product-plan.md Refine portability export behavior and skill plans 2026-03-14 18:59:26 -05:00
2026-03-17-docker-release-browser-e2e.md feat: add release smoke workflow 2026-03-18 07:59:32 -05:00
2026-03-17-memory-service-surface-api.md chore: improve worktree tooling and security docs 2026-04-10 22:26:30 -05:00
2026-03-17-release-automation-and-versioning.md chore: switch release calver to mdd patch 2026-03-18 07:57:36 -05:00
2026-04-06-smart-model-routing.md docs: add smart model routing plan 2026-04-06 21:23:33 -05:00
2026-04-06-subissue-creation-on-issue-detail.md docs: add sub-issue issue detail plan 2026-04-06 21:24:22 -05:00
2026-04-07-issue-detail-speed-and-optimistic-inventory.md docs: add issue detail speed inventory plan 2026-04-09 06:14:12 -05:00
2026-04-07-pi-hooks-survey.md docs: survey pi and pi-mono hook surfaces 2026-04-09 06:14:12 -05:00
2026-04-08-agent-browser-process-cleanup-plan.md docs: add browser process cleanup plan 2026-04-09 06:14:12 -05:00
2026-04-08-agent-os-follow-up-plan.md docs: add agent-os follow-up plan 2026-04-09 06:14:12 -05:00
2026-04-08-agent-os-technical-report.md docs: add agent-os technical report 2026-04-09 06:14:12 -05:00
2026-04-12-vscode-task-interoperability-plan.md [codex] Harden execution reliability and heartbeat tooling (#3679) 2026-04-14 13:34:52 -05:00
2026-04-24-external-object-reference-backfill.md External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
2026-04-26-plugin-secret-ref-company-scope.md Add secrets provider vaults and remote import (#5429) 2026-05-09 18:22:17 -05:00
2026-05-05-scaled-kanban-board-design.md Scale issue kanban board for high-volume columns (#5309) 2026-05-15 10:53:09 -05:00
2026-05-05-scaled-kanban-board.md Scale issue kanban board for high-volume columns (#5309) 2026-05-15 10:53:09 -05:00
2026-05-06-llm-wiki-paperclip-asset-security-gate.md [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
2026-05-23-cli-api-parity-openapi-reference.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
2026-05-23-cli-api-parity.md Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
2026-05-26-skills-cli-catalog-contract.md [codex] Add skills CLI and catalog management (#6782) 2026-05-28 07:33:51 -10:00
2026-06-03-low-trust-review-contract.md Add low-trust review containment (#7530) 2026-06-05 16:48:02 -05:00
2026-06-05-agent-access-mcp-runtime-slots-adr.md feat(mcp) [split 8/8]: add e2e coverage and operator docs (#9563) 2026-07-14 15:48:57 -05:00
2026-08-26-self-serve-mcp-connections.md feat(apps): add Paperclip Cloud managed OAuth connector (#12600) 2026-08-31 14:34:46 -05:00
2026-09-07-runner-api-production-readiness.md feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
2026-09-08-reliable-execution-recovery.md fix: make task recovery durable and preserve current requests (#13075) 2026-09-09 09:14:25 -05:00
2026-09-09-chat-provider-foundation.md feat: add opt-in chat provider and data foundation (#13100) 2026-09-09 13:49:12 -05:00
2026-09-09-codex-integration-acceptance.md fix(codex): correct startup trust, history reads, and resume usage (#13110) 2026-09-09 15:35:18 -05:00
2026-09-09-codex-recurring-notices.md fix(codex): correct startup trust, history reads, and resume usage (#13110) 2026-09-09 15:35:18 -05:00
workspace-product-model-and-work-product.md Incorporate Worktrunk patterns into workspace plan 2026-03-13 09:41:12 -05:00
workspace-technical-implementation.md Add workspace technical implementation spec 2026-03-13 16:37:40 -05:00