From f4bb181daeaa201c2528f774182cb5a25edfc4c6 Mon Sep 17 00:00:00 2001 From: Dotta Date: Wed, 7 Oct 2026 11:39:54 -0500 Subject: [PATCH] Keep release declarations in Docker build context Preserve the Pi and Copilot identity inputs required by generated profile validation and run that check against the cloud build context. Co-Authored-By: Paperclip --- .dockerignore | 12 ++++++++++++ .github/docker-context-checks.Dockerfile | 2 ++ tests/runner-e2e/daytona-image.test.ts | 8 ++++++++ 3 files changed, 22 insertions(+) diff --git a/.dockerignore b/.dockerignore index 7aaa533fe7..97575dc3cc 100644 --- a/.dockerignore +++ b/.dockerignore @@ -36,6 +36,18 @@ packages/paperclip-runner/scripts/*-smoke.mjs # on master failed its drift check — .github/docker-context-checks.Dockerfile # now guards this in PR CI. !packages/paperclip-runner/generated/** +# ACPX generation verifies these immutable release attestations as build inputs. +# Keep the two declarations while excluding other development fixtures. +!packages/paperclip-runner/test +packages/paperclip-runner/test/** +!packages/paperclip-runner/test/fixtures +packages/paperclip-runner/test/fixtures/** +!packages/paperclip-runner/test/fixtures/copilot-profile-v16-identity.json +!packages/paperclip-runner/test-fixtures +packages/paperclip-runner/test-fixtures/** +!packages/paperclip-runner/test-fixtures/pi-acp +packages/paperclip-runner/test-fixtures/pi-acp/** +!packages/paperclip-runner/test-fixtures/pi-acp/profile-v17-identity.json !packages/paperclip-runner/docs/capability-contract.md # check:runner-workflow-traceability access()es every regression test the # stress-traceability spec names — those are src/**/*.test.ts files, so diff --git a/.github/docker-context-checks.Dockerfile b/.github/docker-context-checks.Dockerfile index b259714bb7..4ceba5dd64 100644 --- a/.github/docker-context-checks.Dockerfile +++ b/.github/docker-context-checks.Dockerfile @@ -22,6 +22,8 @@ FROM node:24-slim@sha256:ba849c60be29959425b8734d57b8b4b7d56f98edd9504c9af091d5281095a71e WORKDIR /context COPY . . +# Verify ACPX release declarations against the exact Docker context. +RUN node packages/paperclip-runner/scripts/generate-acpx-profiles.mjs --check # Committed artifacts the image build reads whose drift checks cannot run # here (they need the locked dependency tree or compiled dist/). Existence # in the context is the property this probe guards; content correctness is diff --git a/tests/runner-e2e/daytona-image.test.ts b/tests/runner-e2e/daytona-image.test.ts index 9d273f7cef..cffe4380e0 100644 --- a/tests/runner-e2e/daytona-image.test.ts +++ b/tests/runner-e2e/daytona-image.test.ts @@ -88,6 +88,14 @@ describe("runner E2E Daytona image contract", () => { expect(dockerignore).toContain("**/node_modules"); expect(dockerignore).toContain("packages/paperclip-runner/dist"); expect(dockerignore).toContain("packages/paperclip-runner/runner/target"); + expect(await readFile(path.join(repositoryRoot, ".github/docker-context-checks.Dockerfile"), "utf8")).toContain("node packages/paperclip-runner/scripts/generate-acpx-profiles.mjs --check"); + for (const declaration of [ + "test-fixtures/pi-acp/profile-v17-identity.json", + "test/fixtures/copilot-profile-v16-identity.json", + ]) { + expect(dockerignore).toContain(`!packages/paperclip-runner/${declaration}`); + await expect(readFile(path.join(repositoryRoot, "packages/paperclip-runner", declaration), "utf8")).resolves.toBeTruthy(); + } for (const developmentOnlyInput of [ "packages/paperclip-runner/devtools", "packages/paperclip-runner/docs",