fix(workspaces): seed managed worktrees when the base checkout has no config (#11752)

## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Agents do that work in isolated git worktrees, and a managed
worktree runs its own Paperclip instance with a cloned database
> - That clone needs a seed source, and the source must come from
server-owned registration, never from state the workspace itself can
rewrite
> - The seed-source resolver requires the registered base project
workspace to hold its own `.paperclip/config.json`
> - A managed project workspace is a plain `git clone`, and no code
writes that file into it
> - Every isolated worktree provision, deferred seed, and workspace
repair therefore fails on a managed checkout
> - This pull request lets a named source supply the config when the
base checkout has none
> - The benefit is that managed worktrees provision again, and the seed
source stays server-owned

## Linked Issues or Issue Description

No public GitHub issue exists for this problem. It is described below.

**What happened?**

Agent runs that need an isolated worktree fail during provisioning. The
provision command exits with this error (paths redacted):

```
Execution workspace provision command "bash ./scripts/provision-worktree.sh" failed:
Registered base project workspace has no canonical Paperclip config:
<instance-home>/instances/default/projects/<company-id>/<project-id>/<repo>/.paperclip/config.json
```

`resolveRegisteredWorktreeSeedSource` sets `registeredConfigPath` to
`<baseCwd>/.paperclip/config.json` whenever the caller names a
registered base workspace. It then requires that file to exist.
`scripts/provision-worktree.sh` applies the same rule.

A managed project workspace never has that file.
`materializeManagedProjectWorkspace` creates it with `git clone` and a
rename, so the checkout holds repository content only. The control plane
keeps its config at `<home>/instances/<id>/config.json` instead.

The failure reaches three paths: worktree provisioning, deferred seeding
through `worktree ensure-seeded`, and workspace repair.

The behavior changed in #11671. That pull request replaced a fallback
chain with a single hard requirement. Fixture code in
`scripts/__tests__/provision-worktree-self-heal.test.mjs` writes a
config into the fake base workspace, so tests kept passing.

**Expected behavior**

A managed worktree provisions and seeds from the registered source. The
seed manifest still never selects that source.

**Steps to reproduce**

1. Register the Paperclip repository as a project with a `repoUrl`, so
the server materializes a managed checkout.
2. Assign an issue to an agent whose workspace strategy is
`git_worktree`.
3. Watch the workspace operation log for the provision command.
4. The command exits non-zero with the error above.

**Paperclip version or commit**

Reproduced on `master` at 01ddc26a3.

**Deployment mode**

`local_trusted`, single instance.

**Database mode**

Embedded PostgreSQL.

**Operating system**

Linux, Node.js 22.

**Related pull requests**

- Refs #11671 — introduced the requirement this pull request relaxes.
- Refs #11733 — open work on seed-source preflight. It reads the same
base-workspace config path and skips when the file is absent. It does
not change source selection.
- Refs #11735 — open work on provisioning reliability. It edits the same
four files and will need a rebase after either lands.

## What Changed

- `resolveRegisteredWorktreeSeedSource` sets the registered config path
only when `<baseCwd>/.paperclip/config.json` exists. This makes the
existing `registeredConfigPath ?? explicitSource` branch reachable for a
plain checkout.
- A base workspace that does hold its own config stays authoritative. A
mismatched explicit source is still rejected.
- The resolver throws a named error when the base workspace has no
config and no source is named.
- `readInstanceId` accepts an instance-root config at
`<home>/instances/<id>/config.json`. That layout names its instance by
directory and has no adjacent `.env`. Validation reuses
`resolvePaperclipInstanceId`.
- `scripts/provision-worktree.sh` and
`scripts/provision-worktree-runtime.sh` name the control plane's
instance config as the source when the base workspace has none. The
canonical-path and symlink checks stay.
- The workspace repair route supplies the same fallback, and only when
the base workspace has no config of its own.
- `doc/DEVELOPING.md` records the two source layouts.

## Verification

- `node --test scripts/__tests__/provision-worktree-self-heal.test.mjs`
— 10 tests pass. The fixture no longer writes a config into the base
workspace, so it models a real managed checkout. One test now creates
that config mid-test, which covers both layouts.
- `npx vitest run src/worktree-seed-source.test.ts` in `packages/shared`
— 4 tests pass. Two are new: one resolves an instance-root source, and
one still fails closed when no source exists.
- `npx vitest run src/__tests__/workspace-runtime.test.ts
src/__tests__/execution-workspaces-routes.test.ts
src/__tests__/execution-workspace-runtime-control-conflict.test.ts
src/__tests__/workspace-operations-reconciliation.test.ts
src/__tests__/worktree-seed-server-spawn.test.ts` in `server` — all
pass. Run them one file at a time. They share one test database, and
concurrent runs fail teardown.
- `npx vitest run src/__tests__/worktree.test.ts` in `cli` — 63 tests
pass.
- `pnpm --filter @paperclipai/shared typecheck` — clean.
- Manual check on a live instance: the resolver now returns the instance
config as the source for a managed checkout, with the source instance
`default` and a distinct target instance.

## Risks

Low to moderate.

- The relaxed rule applies only when the base workspace holds no config.
A base workspace that holds one keeps full authority, so the trust model
from #11671 is unchanged. The seed manifest still never selects the
source.
- The instance-id fallback reads a directory name. It applies only to
the `<home>/instances/<id>/config.json` layout, and
`resolvePaperclipInstanceId` rejects an unsafe segment.
- #11735 edits the same four files. Whichever pull request lands second
needs a rebase.
- `pnpm --filter @paperclipai/server typecheck` currently fails on this
checkout with duplicate `drizzle-orm` type instantiations. The failure
is present with and without this change, and the error count is
identical. It comes from an unrelated lockfile state, not from this pull
request.

## Model Used

Claude Opus 5 (`claude-opus-5`), by Anthropic, running in Claude Code.
Extended thinking was on. The model used file, search, and shell tools
to diagnose the failure on a live instance and to run the test suites.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Nicky LeachandClaude Opus 5 authored and GitHub committed 2026-08-20 08:42:16 -07:00
1 parent ed1db310a7
commit a9d1f740f0
7 files changed
+294 -26

No files matched your search

@@ -21,6 +21,17 @@ function makeTempDir(prefix) {
return dir;
}
/**
* A control plane's own instance home. A managed project checkout carries no
* instance config of its own, so this is the seed source the scripts fall back to.
*/
function makeInstanceHome() {
const home = makeTempDir("paperclip-provision-instance-home-");
fs.mkdirSync(path.join(home, "instances", "default"), { recursive: true });
fs.writeFileSync(path.join(home, "instances", "default", "config.json"), "{}\n");
return home;
}
test.after(() => {
for (const dir of cleanupDirs) {
fs.rmSync(dir, { recursive: true, force: true });
@@ -37,9 +48,6 @@ test.after(() => {
*/
function makeBaseWorkspace({ helpExit, initExit, ensureExit = 0 }) {
const baseCwd = makeTempDir("paperclip-provision-base-");
fs.mkdirSync(path.join(baseCwd, ".paperclip"), { recursive: true });
fs.writeFileSync(path.join(baseCwd, ".paperclip", "config.json"), "{}\n");
fs.writeFileSync(path.join(baseCwd, ".paperclip", ".env"), "PAPERCLIP_INSTANCE_ID=base-source\n");
const runnerPath = path.join(baseCwd, "cli", "node_modules", "tsx", "dist", "cli.mjs");
const entryPath = path.join(baseCwd, "cli", "src", "index.ts");
fs.mkdirSync(path.dirname(runnerPath), { recursive: true });
@@ -97,6 +105,7 @@ process.exit(0);
function runProvision(baseCwd, { pathPrefix } = {}) {
const worktreeCwd = makeTempDir("paperclip-provision-worktree-");
const worktreesHome = makeTempDir("paperclip-provision-home-");
const paperclipHome = makeInstanceHome();
const result = spawnSync("bash", [script], {
cwd: worktreeCwd,
encoding: "utf8",
@@ -107,16 +116,17 @@ function runProvision(baseCwd, { pathPrefix } = {}) {
PAPERCLIP_WORKSPACE_CWD: worktreeCwd,
PAPERCLIP_WORKSPACE_BRANCH: "feature/provision-test",
PAPERCLIP_WORKTREES_DIR: worktreesHome,
PAPERCLIP_HOME: path.join(worktreesHome, "no-such-instance-home"),
PAPERCLIP_HOME: paperclipHome,
PAPERCLIP_PROJECT_WORKSPACE_ID: "project-workspace-1",
PAPERCLIP_SEED_EXPECTED_COMPANY_ID: "company-1",
},
});
return { result, worktreeCwd, worktreesHome };
return { result, worktreeCwd, worktreesHome, paperclipHome };
}
function runRuntimeProvision(baseCwd, worktreeCwd) {
const worktreesHome = makeTempDir("paperclip-provision-runtime-home-");
const paperclipHome = makeInstanceHome();
return spawnSync("bash", [runtimeScript], {
cwd: worktreeCwd,
encoding: "utf8",
@@ -127,7 +137,7 @@ function runRuntimeProvision(baseCwd, worktreeCwd) {
PAPERCLIP_WORKSPACE_CWD: worktreeCwd,
PAPERCLIP_WORKSPACE_BRANCH: "feature/provision-runtime-test",
PAPERCLIP_WORKTREES_DIR: worktreesHome,
PAPERCLIP_HOME: path.join(worktreesHome, "no-such-instance-home"),
PAPERCLIP_HOME: paperclipHome,
PAPERCLIP_PROJECT_WORKSPACE_ID: "project-workspace-1",
PAPERCLIP_COMPANY_ID: "company-1",
},
@@ -171,6 +181,29 @@ test("uses the base CLI when its import graph boots", () => {
);
});
test("rejects a dangling base workspace config symlink instead of falling back", () => {
const baseCwd = makeBaseWorkspace({ helpExit: 0, initExit: 0 });
fs.mkdirSync(path.join(baseCwd, ".paperclip"), { recursive: true });
fs.symlinkSync(path.join(baseCwd, "absent.json"), path.join(baseCwd, ".paperclip", "config.json"));
const { result } = runProvision(baseCwd);
assert.notEqual(result.status, 0);
assert.match(result.stderr, /is missing or is not a canonical file/);
});
test("rejects a dangling base workspace .paperclip symlink instead of falling back", () => {
const baseCwd = makeBaseWorkspace({ helpExit: 0, initExit: 0 });
// `-e`/`-L` on the config resolve `.paperclip` first, so the config reads as absent
// here even though the workspace is malformed rather than a plain checkout.
fs.symlinkSync(path.join(baseCwd, "absent-dir"), path.join(baseCwd, ".paperclip"));
const { result } = runProvision(baseCwd);
assert.notEqual(result.status, 0);
assert.match(result.stderr, /\.paperclip is a broken symlink/);
});
test("falls back to an isolated config when the base CLI cannot boot", () => {
// Simulates the dangling pnpm symlink incident: the runner and entry files
// exist, but booting the CLI fails ESM resolution. The base has no
@@ -198,10 +231,12 @@ test("falls back to an isolated config when the base CLI cannot boot", () => {
test("reconciles deployment mode from the registered source when reusing a guest config", () => {
const baseCwd = makeBaseWorkspace({ helpExit: 1, initExit: 0 });
const { result: first, worktreeCwd, worktreesHome } = runProvision(baseCwd);
const { result: first, worktreeCwd, worktreesHome, paperclipHome } = runProvision(baseCwd);
assert.equal(first.status, 0, first.stderr);
assert.equal(readWorktreeConfig(worktreeCwd).server.deploymentMode, "local_trusted");
// A base workspace that does carry its own instance config outranks the fallback.
fs.mkdirSync(path.join(baseCwd, ".paperclip"), { recursive: true });
fs.writeFileSync(
path.join(baseCwd, ".paperclip", "config.json"),
`${JSON.stringify({
@@ -222,7 +257,7 @@ test("reconciles deployment mode from the registered source when reusing a guest
PAPERCLIP_WORKSPACE_CWD: worktreeCwd,
PAPERCLIP_WORKSPACE_BRANCH: "feature/provision-test",
PAPERCLIP_WORKTREES_DIR: worktreesHome,
PAPERCLIP_HOME: path.join(worktreesHome, "no-such-instance-home"),
PAPERCLIP_HOME: paperclipHome,
PAPERCLIP_PROJECT_WORKSPACE_ID: "project-workspace-1",
PAPERCLIP_SEED_EXPECTED_COMPANY_ID: "company-1",
},
@@ -247,9 +282,6 @@ test("repairs an unhealthy base install under the lock and then uses the CLI", (
// The CLI's health is controlled by a flag file, and a fake `pnpm install`
// creates that flag — modeling a forced reinstall that relinks the store.
const baseCwd = makeTempDir("paperclip-provision-repair-base-");
fs.mkdirSync(path.join(baseCwd, ".paperclip"), { recursive: true });
fs.writeFileSync(path.join(baseCwd, ".paperclip", "config.json"), "{}\n");
fs.writeFileSync(path.join(baseCwd, ".paperclip", ".env"), "PAPERCLIP_INSTANCE_ID=base-source\n");
const healthFlag = path.join(baseCwd, "cli-healthy.flag");
const runnerPath = path.join(baseCwd, "cli", "node_modules", "tsx", "dist", "cli.mjs");
const entryPath = path.join(baseCwd, "cli", "src", "index.ts");
@@ -339,7 +371,7 @@ test("runtime provisioning invokes ensure-seeded once and fast-exits after succe
.filter((args) => args[0] === "worktree" && args[1] === "ensure-seeded");
assert.equal(ensureCallsAfterFirst.length, 1);
assert.ok(ensureCallsAfterFirst[0].includes("--config"));
assert.ok(!ensureCallsAfterFirst[0].includes("--from-config"));
assert.ok(ensureCallsAfterFirst[0].includes("--from-config"));
const second = runRuntimeProvision(baseCwd, worktreeCwd);
assert.equal(second.status, 0, second.stderr);