diff --git a/docker/daytona-runner/Dockerfile b/docker/daytona-runner/Dockerfile index 725892c40b..35a228d921 100644 --- a/docker/daytona-runner/Dockerfile +++ b/docker/daytona-runner/Dockerfile @@ -30,13 +30,14 @@ COPY packages ./packages COPY server/package.json ./server/package.json COPY ui/package.json ./ui/package.json COPY cli/package.json ./cli/package.json -# The complete resolved lock (including transitive integrity hashes) is reviewed. -# Reject registry-time drift BEFORE installing packages or running lifecycle code. -# Refresh this digest together with source/provider dependency changes. -ARG PAPERCLIP_RUNNER_LOCK_SHA256=f5ee14ee77b1dc7771fe455d619c880fc64b1e62e40a15704addc9f7430e5c50 +# The caller supplies the digest of its resolved, immutable target lockfile. +# The repository lock bot owns committed lock updates; branch workflows resolve +# and verify their target lock before copying it into this build context. +ARG PAPERCLIP_RUNNER_LOCK_SHA256 # pnpm 9 subtracts PNPM_WORKERS from available CPUs; it is not a worker count. # Subtract all available CPUs to select its minimum (one tarball worker). RUN export PNPM_WORKERS="$(node -p 'require("node:os").availableParallelism()')" \ + && test "${#PAPERCLIP_RUNNER_LOCK_SHA256}" = 64 \ && printf '%s pnpm-lock.yaml\n' "${PAPERCLIP_RUNNER_LOCK_SHA256}" > /tmp/provider-lock.sha256 \ && sha256sum -c /tmp/provider-lock.sha256 \ && pnpm install --frozen-lockfile --filter '@paperclipai/paperclip-runner...' diff --git a/docker/daytona-runner/README.md b/docker/daytona-runner/README.md index 1ba7800b59..449c0665c7 100644 --- a/docker/daytona-runner/README.md +++ b/docker/daytona-runner/README.md @@ -57,11 +57,15 @@ The fleet image is currently amd64-only because the pinned Cursor and GitHub CLI checksums cover amd64. ```bash +# Resolve the target manifest/patch changes without committing the bot-owned lock. +pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile +lock_sha="$(shasum -a 256 pnpm-lock.yaml | cut -d ' ' -f 1)" content_id="$(pnpm --silent test:e2e:runner:image-id)" docker buildx build \ --platform linux/amd64 \ --build-arg PAPERCLIP_RUNNER_CONTENT_ID="${content_id}" \ --build-arg PAPERCLIP_RUNNER_SOURCE_REVISION="$(git rev-parse HEAD)" \ + --build-arg PAPERCLIP_RUNNER_LOCK_SHA256="${lock_sha}" \ --tag "paperclip-daytona-runner:e2e-content-${content_id}" \ --load \ --file docker/daytona-runner/Dockerfile \ diff --git a/packages/paperclip-runner/docs/hermes.md b/packages/paperclip-runner/docs/hermes.md index 31771fe7bf..07f60f6e19 100644 --- a/packages/paperclip-runner/docs/hermes.md +++ b/packages/paperclip-runner/docs/hermes.md @@ -119,6 +119,13 @@ entry. The runner CLI accepts `--candidate-profile hermes`. ```sh pnpm --filter @paperclipai/paperclip-runner build:typescript pnpm --filter @paperclipai/paperclip-runner test:hermes:transport +``` + +The browser campaign definitions and implementation record are supplied by +[qualification PR #15436](https://github.com/paperclipai/paperclip/pull/15436). +Apply that companion PR before running its commands: + +```sh pnpm test:e2e:runner -- --list --suite extended-harnesses pnpm test:e2e:runner -- --id extended-harnesses.runner-acpx-hermes.local.hello-complete ``` @@ -127,8 +134,8 @@ The opt-in transport tests execute the pinned native process against a deterministic HTTP model fixture. It is not paid-model, browser or Daytona qualification. One test exercises the ACPX host directly; the other includes TypeScript, Rust PRP, the packaged sidecar, image delivery and semantic task -completion. The Product E2E catalog contains five local and five Daytona +completion. The companion Product E2E catalog contains five local and five Daytona Hermes cells using a managed OpenRouter connection. Each connection method, native control, attachment, persistence, remote restoration and permission mode must pass its release criterion with inspectable live evidence before promotion. -See the [implementation record](../../../doc/plans/2026-10-06-hermes-native-runner.md). +The implementation record is included in that qualification PR.