mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-08 21:03:51 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Runner executes agents through native and managed provider drivers. > - The direct live eval layer had drifted from the current Runner contracts. > - The old local workflow did not provide a complete parallel campaign or durable report history. > - The Runner also needed current native OpenCode and OpenRouter qualification. > - This pull request restores the direct campaign, corrects the runtime gaps that the campaign found, and adds safe hosted Evalbook history. > - The benefit is repeatable model comparison against an immutable Runner and eval source revision. ## Linked Issues or Issue Description Refs #11297 Refs #11634 **What existing behavior does this improve?** This improves the direct live `paperclip-runner` eval workflow, provider execution contract, and static Evalbook reporting path. **Current behavior** The direct evals do not have one maintained full campaign on current `master`. OpenCode has no qualified multi-model OpenRouter roster. Parallel provider bursts can compact committed events before the transport observes them. Local reports do not have a separate safe S3 history index. **Proposed behavior** Run one immutable roster-plus-case matrix. Use the shared paid AWS runner fleet. Keep raw artifacts access-controlled. Publish a sanitized canonical Evalbook report under the separate `runner-protocol-evals` S3 prefix. Keep immutable campaign directories plus root history, latest, and latest-green pointers. **Reason and benefit** Maintainers can compare native Codex, native OpenCode, ACPX, Claude Managed, and AWS AgentCore behavior over time. They can inspect failures without mixing this direct protocol layer with browser full-stack E2E. **Breaking changes** None. The new workflow and S3 prefix are additive. The existing Runner full-stack E2E workflow and report remain separate. ## What Changed - Added a trusted two-shard direct live workflow for up to 393 roster-plus-case cells. - Reused the numeric actor allowlist, protected paid environment, and RunsOn fleet controls from Runner full-stack E2E. - Added immutable Runner and eval revision resolution, exact credential boundaries, bounded retries, and cost ceilings. - Added a public report projection that removes sessions, transcripts, tool payloads, state, traces, raw failures, remote profile identities, and credential-shaped values. - Added additive S3 history under `runner-protocol-evals`, with immutable campaigns and mutable root index pointers. - Added native OpenCode model injection and current OpenRouter pricing contracts. - Fixed direct eval completion, workflow execution, semantic discovery, warm-attach state reset, executable binding, and event-burst handling. - Kept Runner browser full-stack E2E behavior and publication separate. - Documented local and hosted direct eval operation. ## Verification - `pnpm --filter @paperclipai/paperclip-runner test:runner-protocol-eval-publish` — 15 passed. - `pnpm --filter @paperclipai/paperclip-runner build:typescript` — passed. - `actionlint .github/workflows/runner-protocol-live-evals.yml .github/workflows/runner-full-stack-e2e.yml` — passed. - Local current matrix at the revision in [paperclip-evals#17](https://github.com/paperclipai/paperclip-evals/pull/17) — 323 cells across 10 enabled configurations completed. - Final local current matrix — 269 passed, 11 behavior failures, and 43 expected macOS-only ACPX platform failures. - Targeted Runner checks — 13/13 eval-session tests, 15/15 publisher/security tests, and package typecheck passed; complete PR CI is green, including all browser E2E shards. ## Risks - Paid live campaigns can consume provider budget. Actor authorization, exact per-cell ceilings, protected environments, and explicit schedule enablement bound this risk. - Public reports can leak provider data. The workflow publishes only a separately projected report and validates every file before upload. - The new workflow cannot publish until it is present on the default branch. This pull request does not change the existing `runner-full-stack-e2e` publication path. - The campaign is large. It uses two GitHub matrices and caps combined concurrency at the shared fleet limit. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex on GPT-5. The exact deployment ID and context-window size are not exposed. The model used reasoning, code editing, browser inspection, repository tools, and live provider execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge
135 lines
4.0 KiB
JavaScript
135 lines
4.0 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import { mkdtemp, readFile, rm } from "node:fs/promises";
|
|
import { tmpdir } from "node:os";
|
|
import { resolve } from "node:path";
|
|
import test from "node:test";
|
|
|
|
import {
|
|
runnerWorkflowEvalbookAttempt,
|
|
writeRunnerWorkflowEvalbookAttempts,
|
|
} from "./render-runner-workflow-evalbook.mjs";
|
|
|
|
function fixture(overrides = {}) {
|
|
const report = {
|
|
generatedAt: "2026-09-05T16:30:00.000Z",
|
|
bundle: {
|
|
id: "runner-live-v2-test",
|
|
runnerVersion: "1.2.3",
|
|
runnerBuild: "abc123",
|
|
promptPolicyId: "runner-live-workflow-v1",
|
|
providerVersions: {
|
|
"codex-luna": "codex_app_server:gpt-5.6-luna",
|
|
},
|
|
},
|
|
results: [],
|
|
};
|
|
const result = {
|
|
scenarioId: "verification-policy",
|
|
candidateId: "codex-luna",
|
|
observation: {
|
|
classification: "completed",
|
|
provider: "codex",
|
|
base: {
|
|
controlPlaneOwned: false,
|
|
trace: { sessionId: "eval-session-1" },
|
|
},
|
|
lifecycle: {
|
|
checks: [{ id: "terminal-authority", passed: true }],
|
|
},
|
|
continuation: { checks: [] },
|
|
presentation: { checks: [] },
|
|
metrics: {
|
|
attempts: 1,
|
|
totalTokens: 1234,
|
|
costUsd: 0.0025,
|
|
},
|
|
...overrides.observation,
|
|
},
|
|
scorecard: {
|
|
dimensions: {
|
|
semantic_outcome: {
|
|
dimension: "semantic_outcome",
|
|
score: 1,
|
|
passed: true,
|
|
reasons: [],
|
|
},
|
|
},
|
|
overall: { score: 1, passed: true },
|
|
...overrides.scorecard,
|
|
},
|
|
};
|
|
report.results.push(result);
|
|
return { report, result };
|
|
}
|
|
|
|
test("maps a workflow result to the canonical immutable-attempt inputs", () => {
|
|
const { report, result } = fixture();
|
|
const attempt = runnerWorkflowEvalbookAttempt({
|
|
report,
|
|
result,
|
|
caseDefinition: {
|
|
title: "Verify before completion",
|
|
tags: ["verification"],
|
|
},
|
|
});
|
|
|
|
assert.match(attempt.attemptId, /verification-policy-codex-luna/);
|
|
assert.equal(attempt.artifact.requestedModel, "gpt-5.6-luna");
|
|
assert.equal(attempt.artifact.driver, "codex_app_server");
|
|
assert.equal(attempt.artifact.usage.estimatedCostNanodollars, 2_500_000);
|
|
assert.equal(attempt.score.disposition, "passed");
|
|
assert.equal(attempt.config.id, "codex-luna");
|
|
assert.equal(attempt.case.title, "Verify before completion");
|
|
assert.match(attempt.case.prompt, /Redacted/);
|
|
});
|
|
|
|
test("preserves unscored infrastructure semantics for the grid", () => {
|
|
const { report, result } = fixture({
|
|
observation: {
|
|
classification: "infrastructure_failure",
|
|
failure: {
|
|
code: "provider_timeout",
|
|
category: "provider",
|
|
retryable: true,
|
|
message: "provider timed out",
|
|
},
|
|
},
|
|
scorecard: {
|
|
overall: { score: null, passed: null },
|
|
},
|
|
});
|
|
const attempt = runnerWorkflowEvalbookAttempt({ report, result });
|
|
|
|
assert.equal(attempt.score.disposition, "infrastructure_failure");
|
|
assert.deepEqual(attempt.score.infrastructureErrors, ["provider timed out"]);
|
|
assert.deepEqual(attempt.artifact.infrastructureFailure, {
|
|
class: "provider_timeout",
|
|
category: "provider",
|
|
retryable: true,
|
|
});
|
|
});
|
|
|
|
test("writes idempotent attempt records without raw provider content", async () => {
|
|
const root = await mkdtemp(resolve(tmpdir(), "runner-workflow-evalbook-"));
|
|
try {
|
|
const { report } = fixture();
|
|
const options = {
|
|
report,
|
|
runsRoot: root,
|
|
caseForId: () => ({ title: "Verify", tags: ["verification"] }),
|
|
};
|
|
const first = await writeRunnerWorkflowEvalbookAttempts(options);
|
|
const second = await writeRunnerWorkflowEvalbookAttempts(options);
|
|
assert.deepEqual(second, first);
|
|
|
|
const artifact = JSON.parse(
|
|
await readFile(resolve(root, first[0], "artifact.json"), "utf8"),
|
|
);
|
|
assert.deepEqual(artifact.snapshot.transcript, []);
|
|
assert.deepEqual(artifact.snapshot.evidence, []);
|
|
assert.equal(artifact.workflow.observation.provider, "codex");
|
|
} finally {
|
|
await rm(root, { recursive: true, force: true });
|
|
}
|
|
});
|