{"record":{"id":"bc9c33aebac58d56","repo":"paperclipai/paperclip","slug":"sandbox-bridge-mode-requires-a-host-side-paperclip","errorCode":null,"errorMessage":"Sandbox bridge mode requires a host-side Paperclip API token.","messagePattern":"Sandbox bridge mode requires a host-side Paperclip API token\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/execution-target.ts","lineNumber":2511,"sourceCode":"      // only shorten this wait and suppress the warning below; it never\n      // gates, shortens, or replaces the unconditional removal further down.\n      // What actually makes the wrapper's own termination deterministic is\n      // the wrapper-side session-identity latch, not this event.\n      let acknowledgedInTime = false;\n      readShutdownAckUntil(Date.now() + DEFAULT_PROCESS_SESSION_SHUTDOWN_WAIT_MS);\n      await Promise.race([\n        shutdownAcknowledged.then(() => {\n          acknowledgedInTime = true;\n        }),\n        new Promise<void>((resolve) => {\n          const budgetTimer = setTimeout(resolve, DEFAULT_PROCESS_SESSION_SHUTDOWN_WAIT_MS);\n          budgetTimer.unref?.();\n        }),\n      ]);\n      stopReadingForShutdownAck = true;\n      if (!acknowledgedInTime) {\n        await onLog(\n          \"stderr\",\n          `[paperclip] ACP process session wrapper did not acknowledge shutdown within ${DEFAULT_PROCESS_SESSION_SHUTDOWN_WAIT_MS}ms; removing the session directory anyway.\\n`,\n        ).catch(() => undefined);\n      }\n      // Unconditional: this removal runs whether or not the wrapper\n      // acknowledged, and whether or not any event (real or forged) arrived\n      // under `sessionDir`. `stop()` runs during run teardown and must stay\n      // non-fatal, so every step above is best-effort and this step never\n      // throws.\n      await client.remove(sessionDir).catch(() => undefined);\n      await fs.rm(proxyDir, { recursive: true, force: true }).catch(() => undefined);\n    },\n  };\n}\n\nfunction getProcessSessionProxySource(input: { port: number; token: string }): string {\n  return `#!/usr/bin/env node\nimport net from \"node:net\";\n","sourceCodeStart":2493,"sourceCodeEnd":2529,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapter-utils/src/execution-target.ts#L2493-L2529","documentation":"Authentication precondition for sandbox bridge mode: the bridge relays sandbox callbacks to the host Paperclip API, which requires a host-side API token, and none was provided on the target configuration.","triggerScenarios":"Thrown at packages/adapter-utils/src/execution-target.ts:2215 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Provide a host-side Paperclip API token for sandbox bridge mode.","Use a non-bridge execution mode if no token is available."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}