Commit Graph
5080 Commits
Author SHA1 Message Date
DottaandPaperclip f2da0ed5fc test(runner-e2e): join normalized Copilot completion receipts
Keep raw invocation provenance separate from the validated proposal digest. Advance the semantic evidence contract to v2 and Copilot suite to 8; preserve denial and attached-operation invariants.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 23:25:23 -05:00
DottaandPaperclip a1fa21c7b3 test(runner-e2e): bind semantic acceptance and complete shell reads
Keep bridge call identity separate from canonical result item identity. Require one complete shell-read lifecycle tied to the started command and reject extra or partial reads.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 22:14:30 -05:00
DottaandPaperclip 9fe177c848 test(runner-e2e): require correlated accepted Copilot completion
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 22:00:11 -05:00
DottaandPaperclip da1b5f7ffa fix(runner-e2e): preserve negation in async bootstrap task
State each bootstrap prohibition separately so the production file-delivery classifier does not treat an isolated clause as a requested output. Keep immediate completion stress, private marker evidence and all settlement assertions unchanged; version the authored Copilot protection definition.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 20:00:29 -05:00
DottaandPaperclip 727b979853 fix(runner-e2e): reserve remote runtime readiness budget
Include lease revalidation and the readiness RPC in the existing setup reserve, so late lease admission cannot consume the observation window. Keep the authored outer deadline, single installation, armed baseline action gate, and teardown reserve unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 16:50:51 -05:00
Dotta de7088afa7 docs(runner-e2e): describe remote runtime readiness evidence 2026-09-30 16:32:37 -05:00
DottaandPaperclip c9f29c5fe0 fix(runner-e2e): wait for exact remote runtime before native fixture install
Observe the pinned run process and runtime inode within the original deadline before one observer install. Revalidate identity at installation and baseline, and retain only closed RPC phase/error diagnostics. Preserve action, ownership and cleanup gates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 16:30:54 -05:00
DottaandPaperclip a31fc90b17 test(runner-e2e): bound remote Stop proof to process lifetime
Distinguish live snapshots from the automatic owned-process retirement seal. Preserve local four-phase observation and separately revalidate remote UI/API cancellation state without claiming later filesystem reads. Version the suite and calibrate stale/replayed/foreign/lost-descendant evidence.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 15:45:22 -05:00
Dotta 2467e24614 test(runner-e2e): require rendered cancelled Stop screenshot
Observe the task In Progress header and native Run cancelled marker with loaded history before treating an absent Deny button as unanswerable. Bound all waits by the existing attempt deadline.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit fdfe9418c9)
2026-09-30 14:51:25 -05:00
Dotta 4160912c1f test(runner-e2e): bind active Stop actor and terminal stream
Observe the isolated local-board session through the public API, retain it before Stop, and require its exact startup cancellation actor. Explicitly bind both closure and terminal envelopes to the observed turn, normalized session and source, including missing/null-turn negatives.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 3e04cf1461)
2026-09-30 14:51:25 -05:00
Dotta 14a5ac8927 test(runner-e2e): wait for rendered warm review screenshots
Wait for the exact turn reply and pending review card with enabled Continue work, In Review header and completed history loading before capturing intermediate warm screenshots. Reuse the existing turn deadline; preserve prior screenshots and result grades.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit 11bc74b68d)
2026-09-30 14:51:25 -05:00
Dotta 4c8d56466d test(runner-e2e): qualify Stop at pending native permission
Add explicit Cursor and Copilot local/Daytona cells that retain an unanswered callback before a caller-correlated Stop, require cancelled provider settlement and stale-answer rejection, and independently verify no effects through owned retirement. Normal completion and provider death do not satisfy this active-work oracle.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
(cherry picked from commit a6a5417cd9)
2026-09-30 14:51:25 -05:00
DottaandPaperclip 29230e2000 fix(server): fence native retry cancellation through final commit
Recheck retry eligibility under the coordinator lock before creating a cancellation intent. Preserve later run and coordinator outcomes with a failed-only acknowledged-result CAS, while retaining same-intent recovery and NOWAIT conflict handling.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 13:54:11 -05:00
DottaandPaperclip 79db1c2a6f fix(server): admit correlated Stop for durable native retries
Check failed-run retry eligibility under the run and coordinator locks, fail closed on concurrent coordinator claims, and preserve same-caller recovery after the audited intent disables a retry. Keep terminal failures and foreign actors or intents rejected.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 13:35:21 -05:00
Dotta 14c590371c docs(runner): correct local trusted Stop actor identity
Document the local-board user ID assigned by local trusted authentication and retained by correlated cancellation claims.
2026-09-30 12:25:37 -05:00
DottaandPaperclip 912dbfd54b fix(native): bind operator Stop to caller cancellation intent
Reserve an optional board request UUID under the run lock and retain it
through default Stop joins and native dispatch. Reject prior or competing
intents and require the same actor for idempotent retries.

Bind the Copilot denial fixture to its exact request and audited intent,
with versioned causal receipts and negative controls for earlier Stop.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 12:02:57 -05:00
DottaandPaperclip 1b47b30be9 test(runner-e2e): reject coerced observation clock fields
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 11:32:27 -05:00
DottaandPaperclip 6631d9e847 fix(runner-e2e): require causal pre-Stop denial observations
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 11:31:24 -05:00
DottaandPaperclip b5e3bccce6 fix(runner-e2e): await durable denial evidence before Stop and sampling
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:57:39 -05:00
DottaandPaperclip a14651998c fix(runner-e2e): distinguish Copilot denial settlement from Stop
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 10:43:26 -05:00
DottaandPaperclip 9dbf9ae0d0 fix(e2e): retain transient classification for admission socket drops
Recognize socket hang up only in transport errors. Test plain and prefixed drops plus HTTP bodies with misleading network text.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:55:00 -05:00
DottaandPaperclip a027895ea6 fix(e2e): normalize remote admission failures without private diagnostics
Preserve typed HTTP and transport timeout classification while removing raw response bodies and causes from admission reports. Reject unknown failures and malformed JSON without weakening ownership or deadline checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:44:44 -05:00
DottaandPaperclip 518423c092 fix(e2e): reject stopped bootstrap runs without awaiting slow reads
Bound outstanding admission reads, preserve successful stop and ownership proof immediately, and retain API failure causes and classification at the existing deadline.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:22:17 -05:00
DottaandPaperclip 9fb36831d4 fix(e2e): preserve startup stop evidence and setup budget
Retain successful ownership and terminal reads when another endpoint fails. Reserve the existing fixture setup allowance inside the authored case deadline and capture binder failures with startup state.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 08:07:27 -05:00
DottaandPaperclip 5483f15c88 fix(e2e): bound remote bootstrap by the case deadline
Wait through cold snapshot provisioning while rechecking exact task/run ownership and active lease admission. Fail promptly on terminal runs and retain bounded startup state.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 07:57:27 -05:00
DottaandPaperclip a1145db4d8 test(runner-e2e): require observer startup readiness
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:51:08 -05:00
DottaandPaperclip 5c98f04299 fix(runner-e2e): bound remote observer startup requests
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 04:33:09 -05:00
Dotta 3d21d375de Record current profile qualification and controller settlement fix 2026-09-30 02:56:03 -05:00
DottaandPaperclip 44e1b421cb Record Cursor plan correlation failure and reviewed profile7 candidates
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip 654ec2a9cc Fix Copilot materialization rollback and cover replay identity
Roll back only files and directories created by a failed materialization. Cover partial writes, retry, foreign entries, and session replay isolation. Refresh the Copilot v7 source binding.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip 913f374191 Preserve native Copilot assistant message identities
Verify and extract the pinned Copilot distribution, preserve native message IDs on the ordered ACP stream, and bind the guarded distribution to profile v7. Keep interim messages separate from final output.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:55:29 -05:00
DottaandPaperclip c58a8881f2 fix: validate Cursor plan waits against canonical contract policy
Reuse the production completion-contract envelope hash and exercise real contract creation and reuse in accepted-plan persistence tests.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:54:16 -05:00
DottaandPaperclip b74ca5eb97 test(runner): dereference the owned Node fixture copy
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:24:13 -05:00
DottaandPaperclip 6fa2399392 test(runner): isolate the qualified OpenCode Node fixture
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:15:31 -05:00
DottaandPaperclip a2984a0a9d Preserve historical Cursor plan proof query bounds
Retain the original Cursor6 event filter when verifying an exact committed wait. Progress rows remain part of Cursor7 lifecycle proof without consuming the historical query budget.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 02:15:04 -05:00
DottaandPaperclip 770dc88a11 Bind Cursor plan waits to the native tool lifecycle
Carry the admitted native plan parent tool into canonical request identity and require its exact successful durable lifecycle before passive settlement. Preserve historical committed Cursor6 waits while versioning new admission to Cursor7.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip 4b94270a0b Await clean Stop continuation settlement in recovery test
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip ade7c83dbb Preserve committed Cursor plan waits across profile upgrades
Keep current profile qualification mandatory when first creating a wait. Recovery uses its scoped committed receipt to verify the entire original proof, so future catalog/settings changes cannot authorize task work. Cover actual persisted finalization, catalog drift, original-profile tampering, and document explicit user continuation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip 72a88e124d Keep accepted Cursor plans waiting for explicit continuation
Bind normal native plan acceptance to its durable request, delivered answer, admitted run and completion contract. Commit a passive in-progress result with a visible next-message summary, preserve semantic finish priority, and suppress recovery until task-specific continuation without changing modes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:56:28 -05:00
DottaandPaperclip aec34c693f Record final local verification and Copilot message identity candidate
Keep the failed full invocation and original paid cases explicit. Link the exact fixture corrections and independently reviewed v7 source proof.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:34:21 -05:00
DottaandPaperclip f401b831f2 Stabilize route setup and attachment announcement handling
Load route modules during fixture setup so cold transforms cannot leave a timed-out request running against the next test mock state. Dismiss delayed product announcements through the normal Board UI in the attachment receipt fixture.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:32:15 -05:00
DottaandPaperclip 6b1e96af0f Record Copilot command and message-boundary qualification limits
Retain the failed paid case and original proof gaps. Document the verified private dependency-lock overlay and bot-owned tracked lock restoration.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 01:02:34 -05:00
DottaandPaperclip c9a0aaffa1 Bound Copilot fixture command prefix equivalence
Keep raw native command digests and exact execution origins while admitting at most eight leading ASCII space or tab bytes. Verify the relation in the settlement grader and retain independent local observations before a command mismatch aborts grading.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:58:04 -05:00
DottaandPaperclip 788e3b88ff Restore bot-owned lockfile bytes
Keep the private verified install overlay separate from the source lockfile.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:55:08 -05:00
DottaandPaperclip 672555ffbc Record current rich ACP qualification evidence and capability gaps
Separate source415 and source81 controller evidence from the unchanged e822 runtime. Retain failed attempts, scope the native denial pass, document pending plan settlement and exact command correlation, and distinguish implemented Pi notices from remaining rich-field gaps.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:48:33 -05:00
DottaandPaperclip 9d27311635 Refresh ACPX patch hashes in the frozen dependency lock
Regenerate pnpm 9.15.4 patch metadata without changing dependency versions or peer resolution. Bind both ACPX installations to their checked-in patches, including complete terminal diagnostics and rich protocol guards.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:44:30 -05:00
DottaandPaperclip 81c20ad227 fix: use non-secret text in the environment editor demo
Replace the static demo credential shape so bundled UI evidence does not trigger the secret scanner.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-30 00:07:46 -05:00
DottaandPaperclip 41503eb38f fix: avoid fresh attachment staging paths for empty wakes
Keep authorized residue scrubbing and unsafe-path checks while leaving untouched workspaces unchanged when no wake attachments were selected.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 23:16:23 -05:00
DottaandPaperclip 4597967f89 Handle durable cancellation before workspace failure recovery
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 23:15:13 -05:00
DottaandPaperclip 05d8b40a06 fix(evals): correlate denied Copilot tool target by origin
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-29 23:13:23 -05:00