fix(workspaces): make managed runtimes reliable across restarts (#11740)

## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Execution workspaces need isolated databases, ports, and runtime
services
> - Concurrent workspaces could reuse ports or lose service ownership
after a restart
> - A markerless worktree also needed seed recovery, but normal
markerless instances still needed to boot
> - This pull request makes seed, port, and service ownership state
explicit and recoverable
> - It also checks live process and listener identity before it reclaims
shared resources
> - The benefit is reliable workspace startup, restart, adoption, and
concurrent provisioning

## Linked Issues or Issue Description

**What happened?**

Managed workspaces could lose runtime service ownership after a
control-plane restart. Concurrent worktrees could also reuse a port when
their parent paths differed. A seed recovery change made every
markerless instance resolve a worktree seed source, so normal instances
without a source could not start.

**Expected behavior**

Paperclip must preserve healthy managed services across restarts. It
must reserve unique ports across worktree parents. It must provision a
registered markerless worktree, but it must skip seed work for a normal
markerless instance.

**Steps to reproduce**

1. Start two managed worktrees under different parent paths at the same
time.
2. Restart the control plane while a managed service stays alive.
3. Start Paperclip with a config that has no seed markers and no
registered worktree source.
4. Observe duplicate port selection, lost service adoption, or a
seed-source startup error.

**Paperclip version or commit**

Current `master` plus the workspace runtime reliability changes in this
pull request.

**Deployment mode**

Local development with managed execution workspaces and embedded
Postgres.

## What Changed

- Added a shared port registry with lease heartbeats, process identity
checks, and live listener probes.
- Reserved worktree ports across custom parent paths and repaired
duplicate legacy assignments.
- Preserved and adopted healthy managed services across control-plane
restarts.
- Reconciled guest bind modes and verified listener ownership before
termination or reuse.
- Provisioned registered markerless worktree databases and kept normal
markerless instance startup as a no-op.
- Added CLI, shared, server, and shell regression tests for seed, port,
listener, restart, and adoption behavior.
- Updated the worktree development documentation.

## Verification

- `pnpm exec vitest run cli/src/__tests__/worktree.test.ts
--reporter=verbose` — 63 tests passed.
- `pnpm exec vitest run
packages/shared/src/worktree-port-registry.test.ts --reporter=verbose` —
5 tests passed.
- Focused runtime Vitest set — 199 tests passed across 37 suites.
- `node --test scripts/__tests__/provision-worktree-self-heal.test.mjs`
— 10 tests passed.
- `git diff --check` passed.

## Risks

- Port reservation now depends on lease and process identity data. The
fallback listener probe prevents early reclamation when process metadata
is incomplete.
- Runtime adoption is stricter about bind and owner identity. The tests
cover healthy adoption, stale records, PID reuse, and unrelated
listeners.
- Markerless seed detection now separates registered worktrees from
normal instances. The tests cover both paths.
- There are no database schema migrations.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex with the `gpt-5` model family. The serving snapshot and
context-window size are not exposed. The agent used reasoning,
repository tools, code execution, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
Co-authored-by: Dev Agent <dev@paperclip.ing>
This commit is contained in:
authored and GitHub committed 2026-08-19 14:55:16 -05:00
1 parent 433b1eb099
commit bd059a073d
21 files changed
+2406 -345

No files matched your search

+51
View File
@@ -242,6 +242,51 @@ for (const rawValue of runtimePaths) {
EOF
}
reconcile_worktree_deployment_mode() {
SOURCE_CONFIG_PATH="$source_config_path" \
WORKTREE_CONFIG_PATH="$worktree_config_path" \
node <<'EOF'
const fs = require("node:fs");
const path = require("node:path");
const sourceConfigPath = path.resolve(process.env.SOURCE_CONFIG_PATH);
const worktreeConfigPath = path.resolve(process.env.WORKTREE_CONFIG_PATH);
const sourceConfig = JSON.parse(fs.readFileSync(sourceConfigPath, "utf8"));
const worktreeConfig = JSON.parse(fs.readFileSync(worktreeConfigPath, "utf8"));
const deploymentMode = sourceConfig?.server?.deploymentMode ?? "local_trusted";
if (deploymentMode !== "local_trusted" && deploymentMode !== "authenticated") {
throw new Error(`Registered source has unsupported server.deploymentMode: ${deploymentMode}`);
}
const exposure = deploymentMode === "local_trusted"
? "private"
: (sourceConfig?.server?.exposure ?? "private");
const currentServer = worktreeConfig?.server && typeof worktreeConfig.server === "object"
? worktreeConfig.server
: {};
if (currentServer.deploymentMode === deploymentMode && currentServer.exposure === exposure) {
process.exit(0);
}
worktreeConfig.server = {
...currentServer,
deploymentMode,
exposure,
};
if (worktreeConfig.$meta && typeof worktreeConfig.$meta === "object") {
worktreeConfig.$meta.updatedAt = new Date().toISOString();
}
const temporaryPath = `${worktreeConfigPath}.deployment-mode-${process.pid}`;
try {
fs.writeFileSync(temporaryPath, `${JSON.stringify(worktreeConfig, null, 2)}\n`, { mode: 0o600 });
fs.renameSync(temporaryPath, worktreeConfigPath);
} finally {
fs.rmSync(temporaryPath, { force: true });
}
console.error(`Reconciled isolated Paperclip worktree deployment mode from ${sourceConfigPath}: ${deploymentMode}/${exposure}`);
EOF
}
write_seed_pending_manifest() {
SEED_MANIFEST_PATH="$seed_manifest_path" \
SEED_PENDING_MARKER_PATH="$seed_pending_marker_path" \
@@ -579,6 +624,12 @@ else
created_worktree_config=1
fi
# The target config can predate a deployment-mode change on the registered
# source, and older/fallback CLI writers may default this field independently.
# Reconcile it after either create or reuse so the final guest config always
# carries the source's deployment/auth contract without replacing its database.
reconcile_worktree_deployment_mode
if [[ "$created_worktree_config" -eq 1 && ! -e "$seed_manifest_path" && ! -e "$seed_pending_marker_path" && ! -e "$seed_complete_marker_path" ]]; then
write_seed_pending_manifest
fi