mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 07:23:08 +02:00
fix(workspaces): make managed runtimes reliable across restarts (#11740)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Execution workspaces need isolated databases, ports, and runtime services > - Concurrent workspaces could reuse ports or lose service ownership after a restart > - A markerless worktree also needed seed recovery, but normal markerless instances still needed to boot > - This pull request makes seed, port, and service ownership state explicit and recoverable > - It also checks live process and listener identity before it reclaims shared resources > - The benefit is reliable workspace startup, restart, adoption, and concurrent provisioning ## Linked Issues or Issue Description **What happened?** Managed workspaces could lose runtime service ownership after a control-plane restart. Concurrent worktrees could also reuse a port when their parent paths differed. A seed recovery change made every markerless instance resolve a worktree seed source, so normal instances without a source could not start. **Expected behavior** Paperclip must preserve healthy managed services across restarts. It must reserve unique ports across worktree parents. It must provision a registered markerless worktree, but it must skip seed work for a normal markerless instance. **Steps to reproduce** 1. Start two managed worktrees under different parent paths at the same time. 2. Restart the control plane while a managed service stays alive. 3. Start Paperclip with a config that has no seed markers and no registered worktree source. 4. Observe duplicate port selection, lost service adoption, or a seed-source startup error. **Paperclip version or commit** Current `master` plus the workspace runtime reliability changes in this pull request. **Deployment mode** Local development with managed execution workspaces and embedded Postgres. ## What Changed - Added a shared port registry with lease heartbeats, process identity checks, and live listener probes. - Reserved worktree ports across custom parent paths and repaired duplicate legacy assignments. - Preserved and adopted healthy managed services across control-plane restarts. - Reconciled guest bind modes and verified listener ownership before termination or reuse. - Provisioned registered markerless worktree databases and kept normal markerless instance startup as a no-op. - Added CLI, shared, server, and shell regression tests for seed, port, listener, restart, and adoption behavior. - Updated the worktree development documentation. ## Verification - `pnpm exec vitest run cli/src/__tests__/worktree.test.ts --reporter=verbose` — 63 tests passed. - `pnpm exec vitest run packages/shared/src/worktree-port-registry.test.ts --reporter=verbose` — 5 tests passed. - Focused runtime Vitest set — 199 tests passed across 37 suites. - `node --test scripts/__tests__/provision-worktree-self-heal.test.mjs` — 10 tests passed. - `git diff --check` passed. ## Risks - Port reservation now depends on lease and process identity data. The fallback listener probe prevents early reclamation when process metadata is incomplete. - Runtime adoption is stricter about bind and owner identity. The tests cover healthy adoption, stale records, PID reuse, and unrelated listeners. - Markerless seed detection now separates registered worktrees from normal instances. The tests cover both paths. - There are no database schema migrations. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex with the `gpt-5` model family. The serving snapshot and context-window size are not exposed. The agent used reasoning, repository tools, code execution, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Dev Agent <dev@paperclip.ing>
This commit is contained in:
21 files changed
+2406
-345
No files matched your search
@@ -71,7 +71,21 @@ if (cliArgs[0] === "worktree" && cliArgs[1] === "ensure-seeded") {
|
||||
process.exit(${ensureExit});
|
||||
}
|
||||
fs.rmSync(".paperclip/seed-pending", { force: true });
|
||||
fs.writeFileSync(".paperclip/seed-complete", "{}\\n");
|
||||
fs.rmSync(".paperclip/seed-complete", { force: true });
|
||||
fs.writeFileSync(".paperclip/seed-manifest.json", JSON.stringify({
|
||||
version: 2,
|
||||
source: { instanceId: "base-source", configPath: ${JSON.stringify(path.join(baseCwd, ".paperclip", "config.json"))} },
|
||||
snapshotAt: "2026-08-19T00:00:00.000Z",
|
||||
seedMode: "minimal",
|
||||
migrationRevision: "0142_test.sql",
|
||||
targetInstanceId: "target-test",
|
||||
phase: "complete",
|
||||
state: "verified",
|
||||
attemptId: "attempt-test",
|
||||
startedAt: "2026-08-19T00:00:00.000Z",
|
||||
finishedAt: "2026-08-19T00:01:00.000Z",
|
||||
diagnostics: [{ phase: "complete", status: "succeeded", at: "2026-08-19T00:01:00.000Z" }],
|
||||
}) + "\\n");
|
||||
process.exit(0);
|
||||
}
|
||||
process.exit(0);
|
||||
@@ -182,6 +196,45 @@ test("falls back to an isolated config when the base CLI cannot boot", () => {
|
||||
);
|
||||
});
|
||||
|
||||
test("reconciles deployment mode from the registered source when reusing a guest config", () => {
|
||||
const baseCwd = makeBaseWorkspace({ helpExit: 1, initExit: 0 });
|
||||
const { result: first, worktreeCwd, worktreesHome } = runProvision(baseCwd);
|
||||
assert.equal(first.status, 0, first.stderr);
|
||||
assert.equal(readWorktreeConfig(worktreeCwd).server.deploymentMode, "local_trusted");
|
||||
|
||||
fs.writeFileSync(
|
||||
path.join(baseCwd, ".paperclip", "config.json"),
|
||||
`${JSON.stringify({
|
||||
server: {
|
||||
deploymentMode: "authenticated",
|
||||
exposure: "private",
|
||||
},
|
||||
}, null, 2)}\n`,
|
||||
);
|
||||
|
||||
const second = spawnSync("bash", [script], {
|
||||
cwd: worktreeCwd,
|
||||
encoding: "utf8",
|
||||
env: {
|
||||
PATH: testPath,
|
||||
HOME: os.homedir(),
|
||||
PAPERCLIP_WORKSPACE_BASE_CWD: baseCwd,
|
||||
PAPERCLIP_WORKSPACE_CWD: worktreeCwd,
|
||||
PAPERCLIP_WORKSPACE_BRANCH: "feature/provision-test",
|
||||
PAPERCLIP_WORKTREES_DIR: worktreesHome,
|
||||
PAPERCLIP_HOME: path.join(worktreesHome, "no-such-instance-home"),
|
||||
PAPERCLIP_PROJECT_WORKSPACE_ID: "project-workspace-1",
|
||||
PAPERCLIP_SEED_EXPECTED_COMPANY_ID: "company-1",
|
||||
},
|
||||
});
|
||||
|
||||
assert.equal(second.status, 0, second.stderr);
|
||||
assert.match(second.stderr, /Reusing existing isolated Paperclip worktree config/);
|
||||
assert.match(second.stderr, /Reconciled isolated Paperclip worktree deployment mode/);
|
||||
assert.equal(readWorktreeConfig(worktreeCwd).server.deploymentMode, "authenticated");
|
||||
assert.equal(readWorktreeConfig(worktreeCwd).server.exposure, "private");
|
||||
});
|
||||
|
||||
test("repairs an unhealthy base install under the lock and then uses the CLI", (t) => {
|
||||
const hasTools = ["flock", "git"].every(
|
||||
(tool) => spawnSync("bash", ["-lc", `command -v ${tool}`], { env: { PATH: testPath } }).status === 0,
|
||||
@@ -276,7 +329,10 @@ test("runtime provisioning invokes ensure-seeded once and fast-exits after succe
|
||||
|
||||
const first = runRuntimeProvision(baseCwd, worktreeCwd);
|
||||
assert.equal(first.status, 0, first.stderr);
|
||||
assert.ok(fs.existsSync(path.join(worktreeCwd, ".paperclip", "seed-complete")));
|
||||
assert.equal(
|
||||
JSON.parse(fs.readFileSync(path.join(worktreeCwd, ".paperclip", "seed-manifest.json"), "utf8")).state,
|
||||
"verified",
|
||||
);
|
||||
assert.ok(!fs.existsSync(path.join(worktreeCwd, ".paperclip", "seed-pending")));
|
||||
|
||||
const ensureCallsAfterFirst = readCliInvocations(baseCwd)
|
||||
@@ -287,12 +343,58 @@ test("runtime provisioning invokes ensure-seeded once and fast-exits after succe
|
||||
|
||||
const second = runRuntimeProvision(baseCwd, worktreeCwd);
|
||||
assert.equal(second.status, 0, second.stderr);
|
||||
assert.match(second.stderr, /already seeded.*skipping/);
|
||||
assert.match(second.stderr, /verified seed manifest.*skipping/);
|
||||
const ensureCallsAfterSecond = readCliInvocations(baseCwd)
|
||||
.filter((args) => args[0] === "worktree" && args[1] === "ensure-seeded");
|
||||
assert.equal(ensureCallsAfterSecond.length, 1);
|
||||
});
|
||||
|
||||
test("runtime provisioning seeds a worktree config that has no seed markers", () => {
|
||||
const baseCwd = makeBaseWorkspace({ helpExit: 0, initExit: 0 });
|
||||
const worktreeCwd = makeTempDir("paperclip-provision-runtime-unmarked-config-");
|
||||
fs.mkdirSync(path.join(worktreeCwd, ".paperclip"), { recursive: true });
|
||||
fs.writeFileSync(path.join(worktreeCwd, ".paperclip", "config.json"), "{}\n");
|
||||
|
||||
const result = runRuntimeProvision(baseCwd, worktreeCwd);
|
||||
|
||||
assert.equal(result.status, 0, result.stderr);
|
||||
assert.equal(
|
||||
readCliInvocations(baseCwd)
|
||||
.filter((args) => args[0] === "worktree" && args[1] === "ensure-seeded").length,
|
||||
1,
|
||||
);
|
||||
assert.equal(
|
||||
JSON.parse(fs.readFileSync(path.join(worktreeCwd, ".paperclip", "seed-manifest.json"), "utf8")).state,
|
||||
"verified",
|
||||
);
|
||||
});
|
||||
|
||||
test("runtime provisioning bootstraps and seeds an empty .paperclip directory", () => {
|
||||
const baseCwd = makeBaseWorkspace({ helpExit: 0, initExit: 0 });
|
||||
fs.mkdirSync(path.join(baseCwd, "scripts"), { recursive: true });
|
||||
fs.copyFileSync(script, path.join(baseCwd, "scripts", "provision-worktree.sh"));
|
||||
const worktreeCwd = makeTempDir("paperclip-provision-runtime-empty-state-");
|
||||
fs.mkdirSync(path.join(worktreeCwd, ".paperclip"), { recursive: true });
|
||||
|
||||
const result = runRuntimeProvision(baseCwd, worktreeCwd);
|
||||
|
||||
assert.equal(result.status, 0, result.stderr);
|
||||
assert.match(result.stderr, /config is missing; running the built-in worktree provisioner/);
|
||||
const invocations = readCliInvocations(baseCwd);
|
||||
assert.equal(
|
||||
invocations.filter((args) => args[0] === "worktree" && args[1] === "init").length,
|
||||
1,
|
||||
);
|
||||
assert.equal(
|
||||
invocations.filter((args) => args[0] === "worktree" && args[1] === "ensure-seeded").length,
|
||||
1,
|
||||
);
|
||||
assert.equal(
|
||||
JSON.parse(fs.readFileSync(path.join(worktreeCwd, ".paperclip", "seed-manifest.json"), "utf8")).state,
|
||||
"verified",
|
||||
);
|
||||
});
|
||||
|
||||
test("runtime provisioning leaves seed-pending in place when ensure-seeded fails", () => {
|
||||
const baseCwd = makeBaseWorkspace({ helpExit: 0, initExit: 0, ensureExit: 4 });
|
||||
const worktreeCwd = makeTempDir("paperclip-provision-runtime-failure-");
|
||||
|
||||
@@ -6,8 +6,6 @@ worktree_cwd="${PAPERCLIP_WORKSPACE_CWD:?PAPERCLIP_WORKSPACE_CWD is required}"
|
||||
paperclip_dir="$worktree_cwd/.paperclip"
|
||||
worktree_config_path="$paperclip_dir/config.json"
|
||||
seed_manifest_path="$paperclip_dir/seed-manifest.json"
|
||||
seed_pending_marker_path="$paperclip_dir/seed-pending"
|
||||
seed_complete_marker_path="$paperclip_dir/seed-complete"
|
||||
|
||||
if [[ ! -d "$base_cwd" ]]; then
|
||||
echo "Base workspace does not exist: $base_cwd" >&2
|
||||
@@ -48,13 +46,23 @@ EOF
|
||||
echo "Worktree database has a verified seed manifest; skipping runtime provisioning." >&2
|
||||
exit 0
|
||||
fi
|
||||
elif [[ -e "$seed_complete_marker_path" || ! -e "$seed_pending_marker_path" ]]; then
|
||||
echo "Worktree database is already seeded by a legacy marker; skipping runtime provisioning." >&2
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if [[ ! -f "$worktree_config_path" ]]; then
|
||||
echo "Worktree config does not exist: $worktree_config_path" >&2
|
||||
initial_provision_script="$base_cwd/scripts/provision-worktree.sh"
|
||||
if [[ ! -f "$initial_provision_script" ]]; then
|
||||
echo "Worktree config does not exist and the built-in provision script is unavailable: $worktree_config_path" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "Worktree config is missing; running the built-in worktree provisioner before database seeding." >&2
|
||||
(
|
||||
cd "$worktree_cwd" &&
|
||||
bash "$initial_provision_script"
|
||||
)
|
||||
fi
|
||||
|
||||
if [[ ! -f "$worktree_config_path" ]]; then
|
||||
echo "Worktree config still does not exist after built-in provisioning: $worktree_config_path" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
||||
@@ -242,6 +242,51 @@ for (const rawValue of runtimePaths) {
|
||||
EOF
|
||||
}
|
||||
|
||||
reconcile_worktree_deployment_mode() {
|
||||
SOURCE_CONFIG_PATH="$source_config_path" \
|
||||
WORKTREE_CONFIG_PATH="$worktree_config_path" \
|
||||
node <<'EOF'
|
||||
const fs = require("node:fs");
|
||||
const path = require("node:path");
|
||||
|
||||
const sourceConfigPath = path.resolve(process.env.SOURCE_CONFIG_PATH);
|
||||
const worktreeConfigPath = path.resolve(process.env.WORKTREE_CONFIG_PATH);
|
||||
const sourceConfig = JSON.parse(fs.readFileSync(sourceConfigPath, "utf8"));
|
||||
const worktreeConfig = JSON.parse(fs.readFileSync(worktreeConfigPath, "utf8"));
|
||||
const deploymentMode = sourceConfig?.server?.deploymentMode ?? "local_trusted";
|
||||
if (deploymentMode !== "local_trusted" && deploymentMode !== "authenticated") {
|
||||
throw new Error(`Registered source has unsupported server.deploymentMode: ${deploymentMode}`);
|
||||
}
|
||||
const exposure = deploymentMode === "local_trusted"
|
||||
? "private"
|
||||
: (sourceConfig?.server?.exposure ?? "private");
|
||||
const currentServer = worktreeConfig?.server && typeof worktreeConfig.server === "object"
|
||||
? worktreeConfig.server
|
||||
: {};
|
||||
if (currentServer.deploymentMode === deploymentMode && currentServer.exposure === exposure) {
|
||||
process.exit(0);
|
||||
}
|
||||
|
||||
worktreeConfig.server = {
|
||||
...currentServer,
|
||||
deploymentMode,
|
||||
exposure,
|
||||
};
|
||||
if (worktreeConfig.$meta && typeof worktreeConfig.$meta === "object") {
|
||||
worktreeConfig.$meta.updatedAt = new Date().toISOString();
|
||||
}
|
||||
|
||||
const temporaryPath = `${worktreeConfigPath}.deployment-mode-${process.pid}`;
|
||||
try {
|
||||
fs.writeFileSync(temporaryPath, `${JSON.stringify(worktreeConfig, null, 2)}\n`, { mode: 0o600 });
|
||||
fs.renameSync(temporaryPath, worktreeConfigPath);
|
||||
} finally {
|
||||
fs.rmSync(temporaryPath, { force: true });
|
||||
}
|
||||
console.error(`Reconciled isolated Paperclip worktree deployment mode from ${sourceConfigPath}: ${deploymentMode}/${exposure}`);
|
||||
EOF
|
||||
}
|
||||
|
||||
write_seed_pending_manifest() {
|
||||
SEED_MANIFEST_PATH="$seed_manifest_path" \
|
||||
SEED_PENDING_MARKER_PATH="$seed_pending_marker_path" \
|
||||
@@ -579,6 +624,12 @@ else
|
||||
created_worktree_config=1
|
||||
fi
|
||||
|
||||
# The target config can predate a deployment-mode change on the registered
|
||||
# source, and older/fallback CLI writers may default this field independently.
|
||||
# Reconcile it after either create or reuse so the final guest config always
|
||||
# carries the source's deployment/auth contract without replacing its database.
|
||||
reconcile_worktree_deployment_mode
|
||||
|
||||
if [[ "$created_worktree_config" -eq 1 && ! -e "$seed_manifest_path" && ! -e "$seed_pending_marker_path" && ! -e "$seed_complete_marker_path" ]]; then
|
||||
write_seed_pending_manifest
|
||||
fi
|
||||
|
||||
Reference in new issue
Block a user