paperclipai/paperclip · error

Local filesystem/network confinement requires the Codex CLI…

Error message

Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported.

What it means

Engine-capability guard for the Codex local adapter: local filesystem/network confinement is only implemented in the CLI engine, but the resolved run uses (or explicitly pins) ACP, which has no confinement support — so the run is rejected instead of running unconstrained by accident.

Solutions

  1. Use the Codex CLI engine for local filesystem/network confinement.
  2. Drop the confinement requirement when using ACP.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/adapters/codex-local/src/server/acp.ts:107 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of paperclipai/paperclip@3f1d897a7c (2026-08-18). Data as JSON: /api/errors/be77ca0957a651f0. Report an issue: GitHub.

Appendix: source

Thrown at packages/adapters/codex-local/src/server/acp.ts:107

  // Engine availability must never change the agent's execution or permission contract.
  if (selection.engine === "cli") return selection;
  const unavailable = (reason: string): CodexEngineSelection => ({
    ...selection,
    unavailableReason: `${reason} Repair the ACP setup, or explicitly set engine=cli to use the CLI engine.`,
  });
  const target = readAdapterExecutionTarget({
    executionTarget: input.executionTarget,
    legacyRemoteExecution: input.executionTransport?.remoteExecution,
  });
  if (target?.workspaceRealization?.mode === "in_place") {
    return unavailable("In-place workspace realization requires the Codex CLI engine; ACP archive staging is not supported.");
  }
  const filesystemScope = parseLocalProcessFilesystemScope(input.config.filesystemScope);
  const networkScope = parseLocalProcessNetworkScope(input.config.networkScope);
  if (filesystemScope || networkScope) {
    return unavailable("Local filesystem/network confinement requires the Codex CLI engine; ACP confinement is not supported.");
  }

  const reason = await codexAcpUnavailableReason(input);
  return reason ? unavailable(reason) : selection;
}

function firstNonEmptyString(...values: unknown[]): string | undefined {
  for (const value of values) {
    if (typeof value !== "string") continue;
    const trimmed = value.trim();
    if (trimmed.length > 0) return trimmed;
  }
  return undefined;
}

export function buildCodexAcpConfig(config: Record<string, unknown>): Record<string, unknown> {
  const agentCommand = firstNonEmptyString(config.agentCommand, config.acpAgentCommand);
  const stateDir = firstNonEmptyString(config.stateDir, config.acpStateDir);
  const mode = firstNonEmptyString(config.mode, config.acpMode) ?? DEFAULT_ACP_ENGINE_MODE;
  const permissionMode =

View on GitHub (pinned to 3f1d897a7c)