Keep raw invocation provenance separate from the validated proposal digest. Advance the semantic evidence contract to v2 and Copilot suite to 8; preserve denial and attached-operation invariants.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep bridge call identity separate from canonical result item identity. Require one complete shell-read lifecycle tied to the started command and reject extra or partial reads.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
State each bootstrap prohibition separately so the production file-delivery classifier does not treat an isolated clause as a requested output. Keep immediate completion stress, private marker evidence and all settlement assertions unchanged; version the authored Copilot protection definition.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Include lease revalidation and the readiness RPC in the existing setup reserve, so late lease admission cannot consume the observation window. Keep the authored outer deadline, single installation, armed baseline action gate, and teardown reserve unchanged.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Observe the pinned run process and runtime inode within the original deadline before one observer install. Revalidate identity at installation and baseline, and retain only closed RPC phase/error diagnostics. Preserve action, ownership and cleanup gates.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Distinguish live snapshots from the automatic owned-process retirement seal. Preserve local four-phase observation and separately revalidate remote UI/API cancellation state without claiming later filesystem reads. Version the suite and calibrate stale/replayed/foreign/lost-descendant evidence.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Observe the task In Progress header and native Run cancelled marker with loaded history before treating an absent Deny button as unanswerable. Bound all waits by the existing attempt deadline.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit fdfe9418c9)
Observe the isolated local-board session through the public API, retain it before Stop, and require its exact startup cancellation actor. Explicitly bind both closure and terminal envelopes to the observed turn, normalized session and source, including missing/null-turn negatives.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 3e04cf1461)
Wait for the exact turn reply and pending review card with enabled Continue work, In Review header and completed history loading before capturing intermediate warm screenshots. Reuse the existing turn deadline; preserve prior screenshots and result grades.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 11bc74b68d)
Add explicit Cursor and Copilot local/Daytona cells that retain an unanswered callback before a caller-correlated Stop, require cancelled provider settlement and stale-answer rejection, and independently verify no effects through owned retirement. Normal completion and provider death do not satisfy this active-work oracle.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit a6a5417cd9)
Recheck retry eligibility under the coordinator lock before creating a cancellation intent. Preserve later run and coordinator outcomes with a failed-only acknowledged-result CAS, while retaining same-intent recovery and NOWAIT conflict handling.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Check failed-run retry eligibility under the run and coordinator locks, fail closed on concurrent coordinator claims, and preserve same-caller recovery after the audited intent disables a retry. Keep terminal failures and foreign actors or intents rejected.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reserve an optional board request UUID under the run lock and retain it
through default Stop joins and native dispatch. Reject prior or competing
intents and require the same actor for idempotent retries.
Bind the Copilot denial fixture to its exact request and audited intent,
with versioned causal receipts and negative controls for earlier Stop.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Recognize socket hang up only in transport errors. Test plain and prefixed drops plus HTTP bodies with misleading network text.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Preserve typed HTTP and transport timeout classification while removing raw response bodies and causes from admission reports. Reject unknown failures and malformed JSON without weakening ownership or deadline checks.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bound outstanding admission reads, preserve successful stop and ownership proof immediately, and retain API failure causes and classification at the existing deadline.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Retain successful ownership and terminal reads when another endpoint fails. Reserve the existing fixture setup allowance inside the authored case deadline and capture binder failures with startup state.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Wait through cold snapshot provisioning while rechecking exact task/run ownership and active lease admission. Fail promptly on terminal runs and retain bounded startup state.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Roll back only files and directories created by a failed materialization. Cover partial writes, retry, foreign entries, and session replay isolation. Refresh the Copilot v7 source binding.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Verify and extract the pinned Copilot distribution, preserve native message IDs on the ordered ACP stream, and bind the guarded distribution to profile v7. Keep interim messages separate from final output.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Reuse the production completion-contract envelope hash and exercise real contract creation and reuse in accepted-plan persistence tests.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Retain the original Cursor6 event filter when verifying an exact committed wait. Progress rows remain part of Cursor7 lifecycle proof without consuming the historical query budget.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Carry the admitted native plan parent tool into canonical request identity and require its exact successful durable lifecycle before passive settlement. Preserve historical committed Cursor6 waits while versioning new admission to Cursor7.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep current profile qualification mandatory when first creating a wait. Recovery uses its scoped committed receipt to verify the entire original proof, so future catalog/settings changes cannot authorize task work. Cover actual persisted finalization, catalog drift, original-profile tampering, and document explicit user continuation.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Bind normal native plan acceptance to its durable request, delivered answer, admitted run and completion contract. Commit a passive in-progress result with a visible next-message summary, preserve semantic finish priority, and suppress recovery until task-specific continuation without changing modes.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep the failed full invocation and original paid cases explicit. Link the exact fixture corrections and independently reviewed v7 source proof.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Load route modules during fixture setup so cold transforms cannot leave a timed-out request running against the next test mock state. Dismiss delayed product announcements through the normal Board UI in the attachment receipt fixture.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Retain the failed paid case and original proof gaps. Document the verified private dependency-lock overlay and bot-owned tracked lock restoration.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep raw native command digests and exact execution origins while admitting at most eight leading ASCII space or tab bytes. Verify the relation in the settlement grader and retain independent local observations before a command mismatch aborts grading.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Separate source415 and source81 controller evidence from the unchanged e822 runtime. Retain failed attempts, scope the native denial pass, document pending plan settlement and exact command correlation, and distinguish implemented Pi notices from remaining rich-field gaps.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Regenerate pnpm 9.15.4 patch metadata without changing dependency versions or peer resolution. Bind both ACPX installations to their checked-in patches, including complete terminal diagnostics and rich protocol guards.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Keep authorized residue scrubbing and unsafe-path checks while leaving untouched workspaces unchanged when no wake attachments were selected.
Co-Authored-By: Paperclip <noreply@paperclip.ing>