mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-10 12:07:09 +02:00
fix(hermes): require the resolved image lock digest
Require the caller-verified target lock checksum instead of an incompatible checked-in default. Document lock-bot ownership and the companion browser qualification PR. Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
1 parent
7d89e304f0
commit
63ec34ee79
3 files changed
+18
-6
No files matched your search
@@ -30,13 +30,14 @@ COPY packages ./packages
|
||||
COPY server/package.json ./server/package.json
|
||||
COPY ui/package.json ./ui/package.json
|
||||
COPY cli/package.json ./cli/package.json
|
||||
# The complete resolved lock (including transitive integrity hashes) is reviewed.
|
||||
# Reject registry-time drift BEFORE installing packages or running lifecycle code.
|
||||
# Refresh this digest together with source/provider dependency changes.
|
||||
ARG PAPERCLIP_RUNNER_LOCK_SHA256=f5ee14ee77b1dc7771fe455d619c880fc64b1e62e40a15704addc9f7430e5c50
|
||||
# The caller supplies the digest of its resolved, immutable target lockfile.
|
||||
# The repository lock bot owns committed lock updates; branch workflows resolve
|
||||
# and verify their target lock before copying it into this build context.
|
||||
ARG PAPERCLIP_RUNNER_LOCK_SHA256
|
||||
# pnpm 9 subtracts PNPM_WORKERS from available CPUs; it is not a worker count.
|
||||
# Subtract all available CPUs to select its minimum (one tarball worker).
|
||||
RUN export PNPM_WORKERS="$(node -p 'require("node:os").availableParallelism()')" \
|
||||
&& test "${#PAPERCLIP_RUNNER_LOCK_SHA256}" = 64 \
|
||||
&& printf '%s pnpm-lock.yaml\n' "${PAPERCLIP_RUNNER_LOCK_SHA256}" > /tmp/provider-lock.sha256 \
|
||||
&& sha256sum -c /tmp/provider-lock.sha256 \
|
||||
&& pnpm install --frozen-lockfile --filter '@paperclipai/paperclip-runner...'
|
||||
|
||||
@@ -57,11 +57,15 @@ The fleet image is currently amd64-only because the pinned Cursor and GitHub CLI
|
||||
checksums cover amd64.
|
||||
|
||||
```bash
|
||||
# Resolve the target manifest/patch changes without committing the bot-owned lock.
|
||||
pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile
|
||||
lock_sha="$(shasum -a 256 pnpm-lock.yaml | cut -d ' ' -f 1)"
|
||||
content_id="$(pnpm --silent test:e2e:runner:image-id)"
|
||||
docker buildx build \
|
||||
--platform linux/amd64 \
|
||||
--build-arg PAPERCLIP_RUNNER_CONTENT_ID="${content_id}" \
|
||||
--build-arg PAPERCLIP_RUNNER_SOURCE_REVISION="$(git rev-parse HEAD)" \
|
||||
--build-arg PAPERCLIP_RUNNER_LOCK_SHA256="${lock_sha}" \
|
||||
--tag "paperclip-daytona-runner:e2e-content-${content_id}" \
|
||||
--load \
|
||||
--file docker/daytona-runner/Dockerfile \
|
||||
|
||||
@@ -119,6 +119,13 @@ entry. The runner CLI accepts `--candidate-profile hermes`.
|
||||
```sh
|
||||
pnpm --filter @paperclipai/paperclip-runner build:typescript
|
||||
pnpm --filter @paperclipai/paperclip-runner test:hermes:transport
|
||||
```
|
||||
|
||||
The browser campaign definitions and implementation record are supplied by
|
||||
[qualification PR #15436](https://github.com/paperclipai/paperclip/pull/15436).
|
||||
Apply that companion PR before running its commands:
|
||||
|
||||
```sh
|
||||
pnpm test:e2e:runner -- --list --suite extended-harnesses
|
||||
pnpm test:e2e:runner -- --id extended-harnesses.runner-acpx-hermes.local.hello-complete
|
||||
```
|
||||
@@ -127,8 +134,8 @@ The opt-in transport tests execute the pinned native process against a
|
||||
deterministic HTTP model fixture. It is not paid-model, browser or Daytona
|
||||
qualification. One test exercises the ACPX host directly; the other includes
|
||||
TypeScript, Rust PRP, the packaged sidecar, image delivery and semantic task
|
||||
completion. The Product E2E catalog contains five local and five Daytona
|
||||
completion. The companion Product E2E catalog contains five local and five Daytona
|
||||
Hermes cells using a managed OpenRouter connection. Each connection method,
|
||||
native control, attachment, persistence, remote restoration and permission mode
|
||||
must pass its release criterion with inspectable live evidence before promotion.
|
||||
See the [implementation record](../../../doc/plans/2026-10-06-hermes-native-runner.md).
|
||||
The implementation record is included in that qualification PR.
|
||||
Reference in new issue
Block a user