paperclip/packages/paperclip-runner/src
Dotta 3b550c80fa
fix(codex): correct startup trust, history reads, and resume usage (#13110)
## Thinking Path

> - Paperclip runs Codex locally and in remote sandboxes.
> - The runner must preserve startup configuration and session identity.
> - Missing project trust can disable repository configuration.
> - Full-history requests use deprecated provider fields.
> - Resume usage describes old work and must not become new run usage.
> - This change corrects startup trust, state reads, and usage
classification.

## Linked Issues or Issue Description

**What happened?**

Normal Codex runs could show repository-trust and history-deprecation
warnings.
Resume could report the preceding turn's token snapshot as a late-turn
warning.
The historical last-usage value could also be attributed to the new run.

**Expected behavior**

Trust the server-selected startup root in isolated configuration. Read
lightweight
provider state and paginated evidence. Use historical cumulative usage
as a
baseline without a new charge or user-facing warning.

**Steps to reproduce**

1. Start a native Codex task in a selected repository.
2. Finish the turn and resume the provider thread.
3. Inspect provider notices, history requests, and per-run usage.
4. Repeat startup and cold resume inside a Daytona sandbox.

**Paperclip version or commit**

Codex CLI 0.153.4 is the pinned runtime and reproduced baseline.
Replayed onto master at 6abeb6733. Related authority work: Refs #13092.
This PR retains its startup cleanup and protocol-integrity checks.

**Deployment mode**

Local source checkout and disposable Daytona sandbox.

## What Changed

- Classify the exact historical resume usage event before the generic
stale-turn warning.
- Persist cumulative usage baselines across recovery of the same run.
- Use excludeTurns on resume and lightweight thread reads.
- Page turn metadata and selected turn items with cursor and identity
validation.
- Reject unsupported or incomplete history instead of guessing that
execution is idle.
- Trust the startup execution root on its host, including Git worktree
trust keys.
- Start Codex in that root and retain the selected sandbox profile on
later turns.
- Keep unrelated isolated configuration and Codex's separate hook trust
policy.
- Add Rust, TypeScript, accounting, native integration, and local
run-log documentation.

## Verification

- Codex and native-transport TypeScript: 333 passed before PR replay.
- Adjacent OpenCode/ACPX driver and accounting tests: 49 passed.
- Rust library, serialized: 226 passed. Native Codex integration: 72
passed, 1 ignored, plus two pagination regressions.
- Repository typecheck and build passed. All repository test groups have
passing coverage after fixture and resource retests; the initial
monolithic command was not clean.
- Fresh real Codex native browser tasks returned correct answers without
the three targeted notices. Answers persisted after refresh and restart.
- Real same-thread TypeScript driver tests passed locally and in
Daytona, including cold resume, configuration, skills, and an approved
harmless hook.
- Local usage summed to 64,607 tokens. Daytona usage summed to 42,737
tokens. Each sum matched its final session total exactly.
- See doc/plans/2026-09-09-codex-integration-acceptance.md for the scope
and limits of the live tests.
- After replay onto current master and review fixes: 334 Codex, backend,
and live-session tests passed, including checkpoint serialization and
real-runner process restart. TypeScript checks passed.
- The native Codex integration run passed 83 tests; the large lineage
test passed separately with the release runner (its debug build exceeded
the test deadline).
- All GitHub checks passed on the final PR head. Greptile is 5/5 with no
unresolved review threads. CI regenerates the lockfile for the added
TOML dependency, per repository policy.
- The first server shard hit a timing-dependent duplicate-key failure in
the unchanged artifact-document concurrency test. Its focused 11-test
suite passed locally. One CI retry on the same head passed all 103 files
and 1,405 tests (2 skipped): [retry
result](https://github.com/paperclipai/paperclip/actions/runs/34398832930/job/102631274667).

## Risks

- Trust applies only to the server-selected startup root and isolated
configuration. Sandbox and tool permissions remain authoritative.
- Codex still requires approval of individual hook hashes. This change
does not bypass that policy.
- Providers without the required history APIs fail explicitly.
- Daytona acceptance used the production TypeScript driver. Remote
Paperclip UI and remote Rust execution were not tested.
- No new public API, database state, recovery policy, or UI control is
included.

## Model Used

OpenAI Codex, GPT-6 (`gpt-6-astra`). Used for reasoning, code edits,
tool use,
and test execution. The exact context-window limit is not exposed in
this
session. Real-provider acceptance used Codex CLI 0.153.4 with
`gpt-5.6-sol`.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-09 15:35:18 -05:00
..
backends fix(codex): correct startup trust, history reads, and resume usage (#13110) 2026-09-09 15:35:18 -05:00
browser feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
catalog feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
cli Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
conformance fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
contracts fix(codex): correct startup trust, history reads, and resume usage (#13110) 2026-09-09 15:35:18 -05:00
control-plane fix(runner): preserve durable native session authority across recovery (#13092) 2026-09-09 11:02:59 -05:00
devtools feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
drivers fix(codex): correct startup trust, history reads, and resume usage (#13110) 2026-09-09 15:35:18 -05:00
eval feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
evals Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
generated feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
issue-thread feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
live fix(codex): correct startup trust, history reads, and resume usage (#13110) 2026-09-09 15:35:18 -05:00
mock-core fix(runner): preserve durable native session authority across recovery (#13092) 2026-09-09 11:02:59 -05:00
protocol Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
protocol-actions feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
react feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
reducer Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
scenarios feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
semantic-tools feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
standalone feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
tools feat(runner): add authorized scenario tool runtime (#12361) 2026-08-29 23:50:11 -05:00
tracer feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
compatibility.test.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
compatibility.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
github-credential-environment.ts fix(runner): restore legacy Git access and independent networking (#13094) 2026-09-09 10:15:10 -05:00
index.ts fix(runner): preserve durable native session authority across recovery (#13092) 2026-09-09 11:02:59 -05:00
native-session-runtime.test.ts fix(runner): keep streaming after task completion tools (#13108) 2026-09-09 15:22:00 -05:00
native-session-runtime.ts fix(runner): keep streaming after task completion tools (#13108) 2026-09-09 15:22:00 -05:00
provider-events.test.ts fix(ui): simplify provider notices and hide completion calls (#13109) 2026-09-09 15:06:20 -05:00
provider-events.ts fix(ui): simplify provider notices and hide completion calls (#13109) 2026-09-09 15:06:20 -05:00
testing.ts feat(runner): integrate Codex native execution (#12616) 2026-08-31 22:51:17 -05:00