Evidence record / paperclip
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-paperclip-v2026-824-0-sandbox-capability-contract-resolves-fail-closed-managed-previews-default-to
v2026.824.0: sandbox capability contract resolves fail-closed; managed previews default to Tailscale HTTPS. Providers declare capabilities, the live worker verifies them, and the server resolves the effective set as the intersection of declared, verified and configured, fail-closed. Three operator flags were deleted (streamAgentSessionOutput, Daytona useSessions, useLogStream); they load but are inert. Managed worktree runtimes now default to tailscale_https exposure when the host broker is present (PAPERCLIP_MANAGED_RUNTIME_HTTPS=off to opt out, force to fail closed). v2026.831.0 adds PAPERCLIP_HIDDEN_SETTINGS (hiding company.import also floors the API) and a managed-sandbox-only mode arrived in 824.0.
Channel: tagged-release. Half: both. Date: 2026-08-25.
Operator consequence: Delete the three inert keys; they no longer control anything and give a false reading on audit. If you run the Tailscale broker, agent branch previews are now reachable from the tailnet by default; set off if previews should stay loopback.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-paperclip-v2026-824-0-sandbox-capability-contract-resolves-fail-closed-managed-previews-default-to
Profile citations
- Paperclip / claim / sandbox-capabilities-fail-closed
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact