{"record":{"id":"be77ca0957a651f0","repo":"paperclipai/paperclip","slug":"local-filesystem-network-confinement-requires-the-be77ca","errorCode":null,"errorMessage":"Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported.","messagePattern":"Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/adapters/codex-local/src/server/acp.ts","lineNumber":107,"sourceCode":"  // Engine availability must never change the agent's execution or permission contract.\n  if (selection.engine === \"cli\") return selection;\n  const unavailable = (reason: string): CodexEngineSelection => ({\n    ...selection,\n    unavailableReason: `${reason} Repair the ACP setup, or explicitly set engine=cli to use the CLI engine.`,\n  });\n  const target = readAdapterExecutionTarget({\n    executionTarget: input.executionTarget,\n    legacyRemoteExecution: input.executionTransport?.remoteExecution,\n  });\n  if (target?.workspaceRealization?.mode === \"in_place\") {\n    return unavailable(\"In-place workspace realization requires the Codex CLI engine; ACP archive staging is not supported.\");\n  }\n  const filesystemScope = parseLocalProcessFilesystemScope(input.config.filesystemScope);\n  const networkScope = parseLocalProcessNetworkScope(input.config.networkScope);\n  if (filesystemScope || networkScope) {\n    return unavailable(\"Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported.\");\n  }\n\n  const reason = await codexAcpUnavailableReason(input);\n  return reason ? unavailable(reason) : selection;\n}\n\nfunction firstNonEmptyString(...values: unknown[]): string | undefined {\n  for (const value of values) {\n    if (typeof value !== \"string\") continue;\n    const trimmed = value.trim();\n    if (trimmed.length > 0) return trimmed;\n  }\n  return undefined;\n}\n\nexport function buildCodexAcpConfig(config: Record<string, unknown>): Record<string, unknown> {\n  const agentCommand = firstNonEmptyString(config.agentCommand, config.acpAgentCommand);\n  const stateDir = firstNonEmptyString(config.stateDir, config.acpStateDir);\n  const mode = firstNonEmptyString(config.mode, config.acpMode) ?? DEFAULT_ACP_ENGINE_MODE;\n  const permissionMode =","sourceCodeStart":89,"sourceCodeEnd":125,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/adapters/codex-local/src/server/acp.ts#L89-L125","documentation":"Engine-capability guard for the Codex local adapter: local filesystem/network confinement is only implemented in the CLI engine, but the resolved run uses (or explicitly pins) ACP, which has no confinement support — so the run is rejected instead of running unconstrained by accident.","triggerScenarios":"Thrown at packages/adapters/codex-local/src/server/acp.ts:107 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use the Codex CLI engine for local filesystem/network confinement.","Drop the confinement requirement when using ACP."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}