{"record":{"id":"0d3f625f708922c0","repo":"paperclipai/paperclip","slug":"local-filesystem-network-confinement-requires-the","errorCode":null,"errorMessage":"Local filesystem/network confinement requires the Claude CLI engine; ACP confinement is not supported.","messagePattern":"Local filesystem/network confinement requires the Claude CLI engine; ACP confinement is not supported\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/adapters/claude-local/src/server/acp.ts","lineNumber":97,"sourceCode":"\ntype ClaudeAcpExecutor = (ctx: AdapterExecutionContext) => Promise<AdapterExecutionResult>;\n\nfunction normalizeEngine(value: unknown): ClaudeEngineSelection {\n  const raw = typeof value === \"string\" ? value.trim().toLowerCase() : \"\";\n  if (raw === \"acp\") return { engine: \"acp\", explicit: true };\n  if (raw === \"cli\") return { engine: \"cli\", explicit: true };\n  return { engine: \"acp\", explicit: false };\n}\n\nexport function resolveClaudeExecutionEngine(config: Record<string, unknown>): ClaudeEngineSelection {\n  return normalizeEngine(config.engine);\n}\n\nexport async function resolveClaudeExecutionEngineForRun(\n  input: ClaudeEngineResolutionInput,\n): Promise<ClaudeEngineSelection> {\n  const selection = normalizeEngine(input.config.engine);\n  // Engine availability must never change the agent's execution or permission contract.\n  if (selection.engine === \"cli\") return selection;\n  const unavailable = (reason: string): ClaudeEngineSelection => ({\n    ...selection,\n    unavailableReason: `${reason} Repair the ACP setup, or explicitly set engine=cli to use the CLI engine.`,\n  });\n  const filesystemScope = parseLocalProcessFilesystemScope(input.config.filesystemScope);\n  const networkScope = parseLocalProcessNetworkScope(input.config.networkScope);\n  if (filesystemScope || networkScope) {\n    return unavailable(\"Local filesystem/network confinement requires the Claude CLI engine; ACP confinement is not supported.\");\n  }\n\n  const reason = await claudeAcpUnavailableReason(input);\n  return reason ? unavailable(reason) : selection;\n}\n\nfunction firstNonEmptyString(...values: unknown[]): string | undefined {\n  for (const value of values) {\n    if (typeof value !== \"string\") continue;","sourceCodeStart":79,"sourceCodeEnd":115,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapters/claude-local/src/server/acp.ts#L79-L115","documentation":"Engine-capability guard for the Claude local adapter: local filesystem/network confinement is implemented only in the Claude CLI engine, but the run's configuration resolves to (or explicitly pins) the ACP engine, which has no confinement support — so the run is rejected instead of running unconstrained by accident.","triggerScenarios":"Thrown at packages/adapters/claude-local/src/server/acp.ts:96 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use the Claude CLI engine for local filesystem/network confinement.","Drop the confinement requirement when using ACP."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}