mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-10 20:50:08 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Sandboxed agents use provider capabilities to select safe execution paths > - Session output still depends on three operator flags that duplicate capability data > - Duplicate flags can drift from the verified sandbox capability snapshot > - This pull request makes the capability snapshot the only streaming decision and removes the obsolete flags > - The benefit is default streaming with a poll fallback when a capability or stream fails ## Linked Issues or Issue Description **What existing behavior does this improve?** ACP sandbox session-output streaming and sandbox execution configuration. **Subsystem affected** Cross-cutting (multiple of the above): server/, packages/shared/, packages/adapter-utils/, and packages/plugins/. **Current behavior** Session-output streaming requires operator flags in the server and Daytona plugin configuration. Saved configurations can retain a removed key. **Proposed behavior** The verified capability snapshot selects streaming. The Daytona plugin uses persistent sessions by default, keeps bypass commands one-shot, and falls back from the log stream to polling. Removed configuration keys become inert. **Reason and benefit** One capability source prevents configuration drift. The fallback keeps output available when capability resolution or log streaming fails. **Breaking changes** The three operator flags no longer control session-output streaming. Existing saved keys load but have no effect. ## What Changed - Remove `useSessions` and `useLogStream` from the Daytona plugin configuration and manifest. - Remove `streamAgentSessionOutput` from server configuration, shared types, and execution-target plumbing. - Select streaming from `persistentProcessSessions` and `independentControlCommands`. - Keep poll fallback on capability resolution failure and stream failure. - Strip removed keys from strict fake-sandbox and catchall plugin configuration. - Update the sandbox capability documentation and focused tests. ## Verification - `tsc --noEmit` passed in `packages/shared`, `packages/adapter-utils`, `server`, and the Daytona plugin. - Daytona `plugin.test.ts` passed 139 tests. - Server capability, configuration, route, and runtime suites passed 160 tests. - `packages/adapter-utils` `execution-target-sandbox.test.ts` passed 44 tests. - The capability matrix covers stream, poll, and resolution-failure paths. - Removed-key tests cover strict fake-sandbox and catchall plugin schemas. ## Risks - A capability snapshot that lacks either required session capability uses polling. - A log stream failure uses polling and can increase request count. - Existing removed configuration keys no longer change behavior. - The isolated-worktree Daytona Vitest run has a pre-existing missing `packages/adapters/droid-local` reference. CI and standard checkouts use the committed configuration. ## Model Used OpenAI Codex, GPT-5, tool use and code review assistance. The exact runtime context window is managed by the Codex platform. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
291 lines
7.8 KiB
TypeScript
291 lines
7.8 KiB
TypeScript
import { describe, expect, it } from "vitest";
|
|
import { HttpError } from "../errors.js";
|
|
import { normalizeEnvironmentConfig, parseEnvironmentDriverConfig } from "../services/environment-config.ts";
|
|
|
|
describe("environment config helpers", () => {
|
|
it("normalizes SSH config into its canonical stored shape", () => {
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "ssh",
|
|
config: {
|
|
host: "ssh.example.test",
|
|
port: "2222",
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "/srv/paperclip/workspace",
|
|
privateKeySecretRef: {
|
|
type: "secret_ref",
|
|
secretId: "11111111-1111-1111-1111-111111111111",
|
|
version: "latest",
|
|
},
|
|
knownHosts: "",
|
|
},
|
|
});
|
|
|
|
expect(config).toEqual({
|
|
host: "ssh.example.test",
|
|
port: 2222,
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "/srv/paperclip/workspace",
|
|
privateKey: null,
|
|
privateKeySecretRef: {
|
|
type: "secret_ref",
|
|
secretId: "11111111-1111-1111-1111-111111111111",
|
|
version: "latest",
|
|
},
|
|
knownHosts: null,
|
|
strictHostKeyChecking: true,
|
|
});
|
|
});
|
|
|
|
it("rejects raw SSH private keys in the stored config shape", () => {
|
|
expect(() =>
|
|
normalizeEnvironmentConfig({
|
|
driver: "ssh",
|
|
config: {
|
|
host: "ssh.example.test",
|
|
port: "2222",
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "/srv/paperclip/workspace",
|
|
privateKey: "PRIVATE KEY",
|
|
},
|
|
}),
|
|
).toThrow(HttpError);
|
|
});
|
|
|
|
it("rejects SSH config without an absolute remote workspace path", () => {
|
|
expect(() =>
|
|
normalizeEnvironmentConfig({
|
|
driver: "ssh",
|
|
config: {
|
|
host: "ssh.example.test",
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "workspace",
|
|
},
|
|
}),
|
|
).toThrow(HttpError);
|
|
|
|
expect(() =>
|
|
normalizeEnvironmentConfig({
|
|
driver: "ssh",
|
|
config: {
|
|
host: "ssh.example.test",
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "workspace",
|
|
},
|
|
}),
|
|
).toThrow("absolute");
|
|
});
|
|
|
|
it("parses a persisted SSH environment into a typed driver config", () => {
|
|
const parsed = parseEnvironmentDriverConfig({
|
|
driver: "ssh",
|
|
config: {
|
|
host: "ssh.example.test",
|
|
port: 22,
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "/srv/paperclip/workspace",
|
|
privateKey: null,
|
|
privateKeySecretRef: null,
|
|
knownHosts: null,
|
|
strictHostKeyChecking: false,
|
|
},
|
|
});
|
|
|
|
expect(parsed).toEqual({
|
|
driver: "ssh",
|
|
config: {
|
|
host: "ssh.example.test",
|
|
port: 22,
|
|
username: "ssh-user",
|
|
remoteWorkspacePath: "/srv/paperclip/workspace",
|
|
privateKey: null,
|
|
privateKeySecretRef: null,
|
|
knownHosts: null,
|
|
strictHostKeyChecking: false,
|
|
},
|
|
});
|
|
});
|
|
|
|
it("normalizes sandbox config into its canonical stored shape", () => {
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake",
|
|
image: " ubuntu:24.04 ",
|
|
},
|
|
});
|
|
|
|
expect(config).toEqual({
|
|
provider: "fake",
|
|
image: "ubuntu:24.04",
|
|
reuseLease: false,
|
|
});
|
|
});
|
|
|
|
it("loads a strict fake sandbox config that still carries the removed streamAgentSessionOutput key and drops it", () => {
|
|
// Session-output streaming moved from an operator flag to the capability
|
|
// snapshot. The fake sandbox schema is `.strict()`, so an undeclared key
|
|
// would fail validation. A saved config that still carries the removed key
|
|
// must load, and the removed key must not reach the stored config.
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake",
|
|
image: "ubuntu:24.04",
|
|
streamAgentSessionOutput: true,
|
|
},
|
|
});
|
|
|
|
expect(config).toEqual({
|
|
provider: "fake",
|
|
image: "ubuntu:24.04",
|
|
reuseLease: false,
|
|
});
|
|
expect(config).not.toHaveProperty("streamAgentSessionOutput");
|
|
});
|
|
|
|
it("loads a plugin sandbox config that still carries the removed streamAgentSessionOutput key and drops it", () => {
|
|
// The plugin sandbox schema uses `.catchall`, so an unknown key passes
|
|
// through. The removed key must still drop, so no consumer reads a stale
|
|
// operator flag.
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake-plugin",
|
|
image: "fake:test",
|
|
streamAgentSessionOutput: true,
|
|
},
|
|
});
|
|
|
|
expect(config).not.toHaveProperty("streamAgentSessionOutput");
|
|
expect(config).toMatchObject({ provider: "fake-plugin", image: "fake:test" });
|
|
});
|
|
|
|
it("parses a persisted sandbox environment into a typed driver config", () => {
|
|
const parsed = parseEnvironmentDriverConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake",
|
|
image: "ubuntu:24.04",
|
|
reuseLease: true,
|
|
},
|
|
});
|
|
|
|
expect(parsed).toEqual({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake",
|
|
image: "ubuntu:24.04",
|
|
reuseLease: true,
|
|
},
|
|
});
|
|
});
|
|
|
|
it("normalizes schema-driven sandbox config into the generic plugin-backed stored shape", () => {
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "secure-plugin",
|
|
template: " base ",
|
|
apiKey: "22222222-2222-2222-2222-222222222222",
|
|
timeoutMs: "450000",
|
|
},
|
|
});
|
|
|
|
expect(config).toEqual({
|
|
provider: "secure-plugin",
|
|
template: " base ",
|
|
apiKey: "22222222-2222-2222-2222-222222222222",
|
|
timeoutMs: 450000,
|
|
reuseLease: false,
|
|
});
|
|
});
|
|
|
|
it("normalizes plugin-backed sandbox provider config without server provider changes", () => {
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake-plugin",
|
|
image: " fake:test ",
|
|
timeoutMs: "120000",
|
|
reuseLease: true,
|
|
customFlag: "kept",
|
|
},
|
|
});
|
|
|
|
expect(config).toEqual({
|
|
provider: "fake-plugin",
|
|
image: " fake:test ",
|
|
timeoutMs: 120000,
|
|
reuseLease: true,
|
|
customFlag: "kept",
|
|
});
|
|
});
|
|
|
|
it("parses a persisted schema-driven sandbox environment into a typed driver config", () => {
|
|
const parsed = parseEnvironmentDriverConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "secure-plugin",
|
|
template: "base",
|
|
apiKey: "22222222-2222-2222-2222-222222222222",
|
|
timeoutMs: 300000,
|
|
reuseLease: true,
|
|
},
|
|
});
|
|
|
|
expect(parsed).toEqual({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "secure-plugin",
|
|
template: "base",
|
|
apiKey: "22222222-2222-2222-2222-222222222222",
|
|
timeoutMs: 300000,
|
|
reuseLease: true,
|
|
},
|
|
});
|
|
});
|
|
|
|
it("parses a persisted plugin-backed sandbox environment into a typed driver config", () => {
|
|
const parsed = parseEnvironmentDriverConfig({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake-plugin",
|
|
image: "fake:test",
|
|
timeoutMs: 300000,
|
|
reuseLease: true,
|
|
},
|
|
});
|
|
|
|
expect(parsed).toEqual({
|
|
driver: "sandbox",
|
|
config: {
|
|
provider: "fake-plugin",
|
|
image: "fake:test",
|
|
timeoutMs: 300000,
|
|
reuseLease: true,
|
|
},
|
|
});
|
|
});
|
|
|
|
it("normalizes plugin environment config into its canonical stored shape", () => {
|
|
const config = normalizeEnvironmentConfig({
|
|
driver: "plugin",
|
|
config: {
|
|
pluginKey: "acme.environments",
|
|
driverKey: "fake-plugin",
|
|
driverConfig: {
|
|
template: "base",
|
|
},
|
|
},
|
|
});
|
|
|
|
expect(config).toEqual({
|
|
pluginKey: "acme.environments",
|
|
driverKey: "fake-plugin",
|
|
driverConfig: {
|
|
template: "base",
|
|
},
|
|
});
|
|
});
|
|
});
|