paperclipai/paperclip · error
Local filesystem/network confinement requires the Codex CLI…
Error message
Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported.
What it means
Engine-capability guard for the Codex local adapter: local filesystem/network confinement is only implemented in the CLI engine, but the resolved run uses (or explicitly pins) ACP, which has no confinement support — so the run is rejected instead of running unconstrained by accident.
Solutions
- Use the Codex CLI engine for local filesystem/network confinement.
- Drop the confinement requirement when using ACP.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/adapters/codex-local/src/server/acp.ts:107 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@3f1d897a7c (2026-08-18).
Data as JSON: /api/errors/be77ca0957a651f0.
Report an issue: GitHub.
Appendix: source
Thrown at packages/adapters/codex-local/src/server/acp.ts:107
// Engine availability must never change the agent's execution or permission contract.
if (selection.engine === "cli") return selection;
const unavailable = (reason: string): CodexEngineSelection => ({
...selection,
unavailableReason: `${reason} Repair the ACP setup, or explicitly set engine=cli to use the CLI engine.`,
});
const target = readAdapterExecutionTarget({
executionTarget: input.executionTarget,
legacyRemoteExecution: input.executionTransport?.remoteExecution,
});
if (target?.workspaceRealization?.mode === "in_place") {
return unavailable("In-place workspace realization requires the Codex CLI engine; ACP archive staging is not supported.");
}
const filesystemScope = parseLocalProcessFilesystemScope(input.config.filesystemScope);
const networkScope = parseLocalProcessNetworkScope(input.config.networkScope);
if (filesystemScope || networkScope) {
return unavailable("Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported.");
}
const reason = await codexAcpUnavailableReason(input);
return reason ? unavailable(reason) : selection;
}
function firstNonEmptyString(...values: unknown[]): string | undefined {
for (const value of values) {
if (typeof value !== "string") continue;
const trimmed = value.trim();
if (trimmed.length > 0) return trimmed;
}
return undefined;
}
export function buildCodexAcpConfig(config: Record<string, unknown>): Record<string, unknown> {
const agentCommand = firstNonEmptyString(config.agentCommand, config.acpAgentCommand);
const stateDir = firstNonEmptyString(config.stateDir, config.acpStateDir);
const mode = firstNonEmptyString(config.mode, config.acpMode) ?? DEFAULT_ACP_ENGINE_MODE;
const permissionMode =View on GitHub (pinned to 3f1d897a7c)