diff --git a/.github/workflows/runner-hermes-native.yml b/.github/workflows/runner-hermes-native.yml index 0eca7990d3..1f4f757ab4 100644 --- a/.github/workflows/runner-hermes-native.yml +++ b/.github/workflows/runner-hermes-native.yml @@ -4,13 +4,17 @@ on: pull_request: paths: - .github/workflows/runner-hermes-native.yml - - packages/paperclip-runner/src/providers/hermes/** - - packages/paperclip-runner/src/drivers/acpx/** - - packages/paperclip-runner/src/live/runnerd-*.ts - - packages/paperclip-runner/runner/crates/runner-core/src/acpx_*.rs - - packages/paperclip-runner/scripts/*hermes* - - packages/paperclip-runner/acpx-profiles.json + - packages/paperclip-runner/** + - packages/paperclip-eval-kernel/** + - packages/adapter-utils/** + - packages/shared/** + - patches/** + - package.json + - pnpm-lock.yaml + - pnpm-workspace.yaml + - tsconfig*.json - tests/runner-e2e/provision-hermes-linux.sh + - tests/runner-e2e/workflow-security.test.ts workflow_dispatch: permissions: diff --git a/doc/plans/2026-10-06-hermes-native-runner.md b/doc/plans/2026-10-06-hermes-native-runner.md index 4c65418aab..e2f5dbab2b 100644 --- a/doc/plans/2026-10-06-hermes-native-runner.md +++ b/doc/plans/2026-10-06-hermes-native-runner.md @@ -494,3 +494,17 @@ TypeScript attachment/permission tests, two encrypted-frame tests carrying accepted images and escaped documents, the Rust admission regression, and Runner TypeScript compilation. The stack still needs fresh CI and review on the resulting heads. No merge has occurred, and Hermes remains gated. + +The complete affected native tool-authority suite subsequently passed all 26 +tests with supported Node 24 and local PostgreSQL permissions. A negative proof +restored only the previous blocking lock temporarily: the concurrency regression +failed at its expected contention timeout. The committed NOWAIT fix was restored +with no remaining worktree changes. All 143 affected ACPX lifecycle tests and +the current generated profile, protocol, sidecar and surface checks also passed. + +The qualification review at `c99b2c86748e06600d853adaf5a7483aa16ed8ca` returned +5/5 but noted a native CI trigger coverage gap. The credential-free workflow +now covers shared Runner sources, Rust and build manifests, dependency patches, +and shared workspace inputs. A glob-matching regression verifies those changes +trigger the native fixture. Paid workflow authorization is unchanged. This +follow-up requires another exact-head review and CI run. diff --git a/tests/runner-e2e/workflow-security.test.ts b/tests/runner-e2e/workflow-security.test.ts index 2ae6310494..ce363aac65 100644 --- a/tests/runner-e2e/workflow-security.test.ts +++ b/tests/runner-e2e/workflow-security.test.ts @@ -15,6 +15,28 @@ const everydayOracleImage = "python@sha256:9d2e5553305c7c7b0097999bb17187c69b921ccd6bc9d40e4bb5ebe652c00285"; describe("public repository paid workflow security", () => { + it("runs native Hermes fixtures for shared sources, patches, and build inputs", async () => { + const workflow = await readFile(path.join(repositoryRoot, ".github/workflows/runner-hermes-native.yml"), "utf8"); + const filter = workflow.slice(workflow.indexOf(" paths:"), workflow.indexOf(" workflow_dispatch:")); + const patterns = [...filter.matchAll(/^ - (.+)$/gmu)].map(match => match[1]!); + const triggers = (file: string) => patterns.some(pattern => path.matchesGlob(file, pattern)); + for (const file of [ + "patches/acpx@0.13.1.patch", + "packages/paperclip-runner/src/contracts/user-attachments.ts", + "packages/paperclip-runner/src/backends/codex-native-backend.ts", + "packages/paperclip-runner/src/control-plane/durable-prp-control-plane.ts", + "packages/paperclip-runner/runner/crates/runner-core/src/durable/runner.rs", + "packages/paperclip-runner/runner/Cargo.lock", + "packages/paperclip-runner/package.json", + "packages/paperclip-runner/scripts/build-verified-provider-entrypoints.mjs", + "packages/paperclip-eval-kernel/src/index.ts", + "packages/adapter-utils/src/paperclip-runner-permissions.ts", + "packages/shared/src/ai-connections.ts", + "package.json", "pnpm-lock.yaml", "pnpm-workspace.yaml", "tsconfig.json", + "tests/runner-e2e/provision-hermes-linux.sh", + ]) expect(triggers(file), `Missing native fixture trigger: ${file}`).toBe(true); + expect(triggers("README.md")).toBe(false); + }); it("keeps native Hermes PR fixtures outside paid authority and strips their child environment", async () => { const workflow = await readFile(path.join(repositoryRoot, ".github/workflows/runner-hermes-native.yml"), "utf8"); expect(workflow).toContain("pull_request:");