mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-09 06:15:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Runner executes agents through native and managed provider drivers. > - The direct live eval layer had drifted from the current Runner contracts. > - The old local workflow did not provide a complete parallel campaign or durable report history. > - The Runner also needed current native OpenCode and OpenRouter qualification. > - This pull request restores the direct campaign, corrects the runtime gaps that the campaign found, and adds safe hosted Evalbook history. > - The benefit is repeatable model comparison against an immutable Runner and eval source revision. ## Linked Issues or Issue Description Refs #11297 Refs #11634 **What existing behavior does this improve?** This improves the direct live `paperclip-runner` eval workflow, provider execution contract, and static Evalbook reporting path. **Current behavior** The direct evals do not have one maintained full campaign on current `master`. OpenCode has no qualified multi-model OpenRouter roster. Parallel provider bursts can compact committed events before the transport observes them. Local reports do not have a separate safe S3 history index. **Proposed behavior** Run one immutable roster-plus-case matrix. Use the shared paid AWS runner fleet. Keep raw artifacts access-controlled. Publish a sanitized canonical Evalbook report under the separate `runner-protocol-evals` S3 prefix. Keep immutable campaign directories plus root history, latest, and latest-green pointers. **Reason and benefit** Maintainers can compare native Codex, native OpenCode, ACPX, Claude Managed, and AWS AgentCore behavior over time. They can inspect failures without mixing this direct protocol layer with browser full-stack E2E. **Breaking changes** None. The new workflow and S3 prefix are additive. The existing Runner full-stack E2E workflow and report remain separate. ## What Changed - Added a trusted two-shard direct live workflow for up to 393 roster-plus-case cells. - Reused the numeric actor allowlist, protected paid environment, and RunsOn fleet controls from Runner full-stack E2E. - Added immutable Runner and eval revision resolution, exact credential boundaries, bounded retries, and cost ceilings. - Added a public report projection that removes sessions, transcripts, tool payloads, state, traces, raw failures, remote profile identities, and credential-shaped values. - Added additive S3 history under `runner-protocol-evals`, with immutable campaigns and mutable root index pointers. - Added native OpenCode model injection and current OpenRouter pricing contracts. - Fixed direct eval completion, workflow execution, semantic discovery, warm-attach state reset, executable binding, and event-burst handling. - Kept Runner browser full-stack E2E behavior and publication separate. - Documented local and hosted direct eval operation. ## Verification - `pnpm --filter @paperclipai/paperclip-runner test:runner-protocol-eval-publish` — 15 passed. - `pnpm --filter @paperclipai/paperclip-runner build:typescript` — passed. - `actionlint .github/workflows/runner-protocol-live-evals.yml .github/workflows/runner-full-stack-e2e.yml` — passed. - Local current matrix at the revision in [paperclip-evals#17](https://github.com/paperclipai/paperclip-evals/pull/17) — 323 cells across 10 enabled configurations completed. - Final local current matrix — 269 passed, 11 behavior failures, and 43 expected macOS-only ACPX platform failures. - Targeted Runner checks — 13/13 eval-session tests, 15/15 publisher/security tests, and package typecheck passed; complete PR CI is green, including all browser E2E shards. ## Risks - Paid live campaigns can consume provider budget. Actor authorization, exact per-cell ceilings, protected environments, and explicit schedule enablement bound this risk. - Public reports can leak provider data. The workflow publishes only a separately projected report and validates every file before upload. - The new workflow cannot publish until it is present on the default branch. This pull request does not change the existing `runner-full-stack-e2e` publication path. - The campaign is large. It uses two GitHub matrices and caps combined concurrency at the shared fleet limit. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex on GPT-5. The exact deployment ID and context-window size are not exposed. The model used reasoning, code editing, browser inspection, repository tools, and live provider execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge
314 lines
10 KiB
JavaScript
314 lines
10 KiB
JavaScript
import { createHash } from "node:crypto";
|
|
import {
|
|
mkdir,
|
|
readFile,
|
|
readdir,
|
|
rm,
|
|
stat,
|
|
writeFile,
|
|
} from "node:fs/promises";
|
|
import { resolve } from "node:path";
|
|
|
|
import { renderRunnerWorkflowWithCanonicalEvalbook } from "./render-runner-workflow-evalbook.mjs";
|
|
|
|
const packageRoot = resolve(import.meta.dirname, "..");
|
|
const evals = await import(resolve(packageRoot, "dist/eval/index.js"));
|
|
const packageManifest = JSON.parse(
|
|
await readFile(resolve(packageRoot, "package.json"), "utf8"),
|
|
);
|
|
const modeIndex = process.argv.indexOf("--mode");
|
|
const mode = modeIndex < 0 ? "nightly" : process.argv[modeIndex + 1];
|
|
const execute = process.argv.includes("--execute");
|
|
if (mode !== "nightly" && mode !== "chaos")
|
|
throw new Error(`unsupported workflow eval schedule mode: ${mode}`);
|
|
const now = process.env.PAPERCLIP_EVAL_GENERATED_AT ?? new Date().toISOString();
|
|
const rotationDay = Number(
|
|
process.env.PAPERCLIP_EVAL_ROTATION_DAY ?? evals.runnerLiveRotationWeek(now),
|
|
);
|
|
const seed =
|
|
process.env.PAPERCLIP_EVAL_SCHEDULE_SEED ?? "runner-live-seven-week-v1";
|
|
const outputDirectory = resolve(
|
|
packageRoot,
|
|
".paperclip-local/evals/workflows",
|
|
);
|
|
const historyDirectory = resolve(
|
|
process.env.PAPERCLIP_EVAL_HISTORY_DIR ?? resolve(outputDirectory, "history"),
|
|
);
|
|
await mkdir(outputDirectory, { recursive: true });
|
|
|
|
function selectorValues(flag, environmentName) {
|
|
const values = [];
|
|
for (let index = 0; index < process.argv.length; index += 1) {
|
|
if (process.argv[index] !== flag) continue;
|
|
const value = process.argv[index + 1];
|
|
if (!value || value.startsWith("--")) {
|
|
throw new Error(`${flag} requires a comma-separated value`);
|
|
}
|
|
values.push(value);
|
|
}
|
|
if (process.env[environmentName]) values.push(process.env[environmentName]);
|
|
return [
|
|
...new Set(
|
|
values.flatMap((value) =>
|
|
value
|
|
.split(",")
|
|
.map((entry) => entry.trim())
|
|
.filter(Boolean),
|
|
),
|
|
),
|
|
];
|
|
}
|
|
|
|
function selectionLimit() {
|
|
const index = process.argv.indexOf("--limit");
|
|
const raw =
|
|
index < 0 ? process.env.PAPERCLIP_EVAL_LIMIT : process.argv[index + 1];
|
|
if (raw === undefined || raw === "") return undefined;
|
|
const value = Number(raw);
|
|
if (!Number.isSafeInteger(value) || value <= 0) {
|
|
throw new Error("--limit must be a positive integer");
|
|
}
|
|
return value;
|
|
}
|
|
|
|
const selection = {
|
|
candidateIds: selectorValues("--candidate", "PAPERCLIP_EVAL_CANDIDATE"),
|
|
caseIds: selectorValues("--case", "PAPERCLIP_EVAL_CASE"),
|
|
limit: selectionLimit(),
|
|
};
|
|
const selectionActive =
|
|
selection.candidateIds.length > 0 ||
|
|
selection.caseIds.length > 0 ||
|
|
selection.limit !== undefined;
|
|
|
|
function safeBundleId(schedule) {
|
|
const runnerBuild =
|
|
process.env.PAPERCLIP_EVAL_RUNNER_BUILD ?? packageManifest.version;
|
|
const identity = JSON.stringify({
|
|
runnerVersion: packageManifest.version,
|
|
runnerBuild,
|
|
promptPolicyId: "runner-live-workflow-v1",
|
|
seed: schedule.seed,
|
|
candidates: schedule.candidates.map(
|
|
({ id, adapter, model, reasoningEffort }) => ({
|
|
id,
|
|
adapter,
|
|
model,
|
|
reasoningEffort,
|
|
}),
|
|
),
|
|
...(selectionActive
|
|
? {
|
|
selectedExecutions: schedule.entries.map(
|
|
(entry) => entry.executionId,
|
|
),
|
|
}
|
|
: {}),
|
|
});
|
|
return `runner-live-v2-${createHash("sha256").update(identity).digest("hex").slice(0, 16)}`;
|
|
}
|
|
|
|
function qualificationFailure(entry, candidate, evalCase) {
|
|
const missing = candidate.qualification.requiredEnvironment.filter(
|
|
(name) => !process.env[name],
|
|
);
|
|
if (missing.length === 0) return null;
|
|
return evals.unavailableLiveRunnerWorkflowObservation({
|
|
entry,
|
|
candidate,
|
|
evalCase,
|
|
classification: "skipped",
|
|
code: "qualification_environment_missing",
|
|
category: "qualification",
|
|
retryable: false,
|
|
message: `Required credential reference unavailable: ${missing.join(", ")}`,
|
|
});
|
|
}
|
|
|
|
async function readCompatibleHistory(bundleId) {
|
|
const names = await readdir(historyDirectory).catch(() => []);
|
|
const reports = [];
|
|
for (const name of names.filter((value) => value.endsWith(".json")).sort()) {
|
|
try {
|
|
const report = JSON.parse(
|
|
await readFile(resolve(historyDirectory, name), "utf8"),
|
|
);
|
|
if (
|
|
report?.schema === evals.RUNNER_WORKFLOW_REPORT_SCHEMA &&
|
|
report?.bundle?.id === bundleId
|
|
)
|
|
reports.push(report);
|
|
} catch {
|
|
// A malformed historical artifact is ignored; it cannot affect the current candidate score.
|
|
}
|
|
}
|
|
return reports.slice(-7);
|
|
}
|
|
|
|
async function retainHistory(report) {
|
|
await mkdir(historyDirectory, { recursive: true });
|
|
const stamp = report.generatedAt.replaceAll(/[^0-9A-Za-z.-]/g, "-");
|
|
await writeFile(
|
|
resolve(historyDirectory, `${stamp}-${report.bundle.id}.json`),
|
|
`${JSON.stringify(report, null, 2)}\n`,
|
|
);
|
|
// Candidate sets alternate, so seven compatible weekly baselines require
|
|
// roughly fourteen weeks of history. Keep a little extra scheduling margin.
|
|
const expiry = Date.now() - 120 * 24 * 60 * 60 * 1_000;
|
|
for (const name of await readdir(historyDirectory)) {
|
|
if (!name.endsWith(".json")) continue;
|
|
const metadata = await stat(resolve(historyDirectory, name));
|
|
if (metadata.mtimeMs < expiry) await rm(resolve(historyDirectory, name));
|
|
}
|
|
}
|
|
|
|
if (mode === "nightly") {
|
|
const fullSchedule = evals.buildRunnerLiveEvalSchedule({
|
|
seed,
|
|
rotationDay,
|
|
generatedAt: now,
|
|
});
|
|
const coverage = evals.runnerLiveScheduleCoverage(seed);
|
|
if (!Object.values(coverage).every(Boolean))
|
|
throw new Error(
|
|
`live schedule coverage failed: ${JSON.stringify(coverage)}`,
|
|
);
|
|
const schedule = selectionActive
|
|
? evals.selectRunnerLiveEvalSchedule(fullSchedule, selection)
|
|
: fullSchedule;
|
|
await writeFile(
|
|
resolve(outputDirectory, "nightly-schedule.json"),
|
|
`${JSON.stringify({ schedule, coverage, selection: selectionActive ? selection : null }, null, 2)}\n`,
|
|
);
|
|
if (!execute) {
|
|
process.stdout.write(
|
|
`Runner live eval schedule ready: ${schedule.expectedExecutions} executions, rotation week ${schedule.rotationDay}. Use --execute to run providers.\n`,
|
|
);
|
|
process.exit(0);
|
|
}
|
|
|
|
const campaignCostLimit = evals.parseRunnerLiveCampaignCostLimit(
|
|
process.env.PAPERCLIP_EVAL_MAX_CAMPAIGN_COST_USD,
|
|
);
|
|
let observedCampaignCost = 0;
|
|
const observations = await evals.executeRunnerLiveSchedule(
|
|
schedule,
|
|
async (entry, candidate) => {
|
|
const evalCase = evals.runnerWorkflowCase(entry.caseId);
|
|
const unavailable = qualificationFailure(entry, candidate, evalCase);
|
|
if (unavailable) return unavailable;
|
|
if (observedCampaignCost >= campaignCostLimit) {
|
|
return evals.unavailableLiveRunnerWorkflowObservation({
|
|
entry,
|
|
candidate,
|
|
evalCase,
|
|
classification: "skipped",
|
|
code: "campaign_cost_ceiling_reached",
|
|
category: "orchestration",
|
|
retryable: false,
|
|
message: `Campaign cost ceiling reached before this execution (${campaignCostLimit} USD)`,
|
|
});
|
|
}
|
|
const observation = await evals.executeLiveRunnerWorkflow({
|
|
entry,
|
|
candidate,
|
|
evalCase,
|
|
});
|
|
observedCampaignCost += observation.metrics.costUsd ?? 0;
|
|
return observation;
|
|
},
|
|
(entry, candidate, error) =>
|
|
evals.unavailableLiveRunnerWorkflowObservation({
|
|
entry,
|
|
candidate,
|
|
evalCase: evals.runnerWorkflowCase(entry.caseId),
|
|
classification: "infrastructure_failure",
|
|
code: error.code,
|
|
category: "provider",
|
|
retryable: error.retryable,
|
|
message: error.message,
|
|
}),
|
|
);
|
|
const bundleId = safeBundleId(schedule);
|
|
const results = observations.map((observation) => ({
|
|
scenarioId: observation.caseId,
|
|
candidateId: observation.candidateId,
|
|
observation,
|
|
scorecard: evals.scoreRunnerWorkflow(observation, { bundleId }),
|
|
}));
|
|
const providerVersions = Object.fromEntries(
|
|
schedule.candidates.map((candidate) => [
|
|
candidate.id,
|
|
`${candidate.adapter}:${candidate.model}`,
|
|
]),
|
|
);
|
|
const report = evals.buildRunnerWorkflowEvalReport({
|
|
source: "live",
|
|
bundle: {
|
|
id: bundleId,
|
|
runnerVersion: packageManifest.version,
|
|
runnerBuild:
|
|
process.env.PAPERCLIP_EVAL_RUNNER_BUILD ?? packageManifest.version,
|
|
promptPolicyId: "runner-live-workflow-v1",
|
|
providerVersions,
|
|
scheduleSeed: schedule.seed,
|
|
},
|
|
results,
|
|
generatedAt: now,
|
|
});
|
|
const history = await readCompatibleHistory(bundleId);
|
|
const comparison =
|
|
history.length === 0
|
|
? null
|
|
: evals.compareRunnerWorkflowReports(report, history.at(-1));
|
|
const alerts = evals.runnerWorkflowAlerts({
|
|
current: report,
|
|
history,
|
|
baselineReady:
|
|
process.env.PAPERCLIP_EVAL_BASELINE_READY === "true" &&
|
|
history.length >= 7,
|
|
});
|
|
await Promise.all([
|
|
writeFile(
|
|
resolve(outputDirectory, "live-report.json"),
|
|
`${JSON.stringify({ report, alerts, comparison }, null, 2)}\n`,
|
|
),
|
|
writeFile(
|
|
resolve(outputDirectory, "live-report.md"),
|
|
evals.renderRunnerWorkflowMarkdown(report),
|
|
),
|
|
writeFile(
|
|
resolve(outputDirectory, "live-report.junit.xml"),
|
|
evals.renderRunnerWorkflowJUnit(report),
|
|
),
|
|
writeFile(
|
|
resolve(outputDirectory, "github-live-summary.md"),
|
|
`${evals.renderRunnerWorkflowGitHubSummary(report, alerts)}\n## Previous compatible bundle\n\n${comparison === null ? "No compatible prior bundle is available." : `Pass-rate delta: ${comparison.passRateDelta}; overall delta: ${comparison.overallDelta}.`}\n`,
|
|
),
|
|
]);
|
|
await renderRunnerWorkflowWithCanonicalEvalbook({
|
|
packageRoot,
|
|
outputDirectory,
|
|
report,
|
|
caseForId: evals.runnerWorkflowCase,
|
|
});
|
|
await retainHistory(report);
|
|
process.stdout.write(
|
|
`Runner live evals complete: ${report.aggregate.passed}/${report.aggregate.scoreable} scoreable passed; ${report.aggregate.infrastructureFailures} infrastructure, ${report.aggregate.skipped} skipped, ${alerts.length} alert(s). Open ${resolve(outputDirectory, "index.html")}.\n`,
|
|
);
|
|
} else {
|
|
const payload = {
|
|
schema: "paperclip.runner.chaos-eval-schedule.v1",
|
|
generatedAt: now,
|
|
seed,
|
|
scenarios: evals.RUNNER_CHAOS_SCENARIOS,
|
|
};
|
|
await writeFile(
|
|
resolve(outputDirectory, "chaos-schedule.json"),
|
|
`${JSON.stringify(payload, null, 2)}\n`,
|
|
);
|
|
process.stdout.write(
|
|
`Runner chaos eval schedule ready: ${payload.scenarios.length} scenarios.\n`,
|
|
);
|
|
}
|