Files
PaperClipAI/tests/runner-e2e/source.ts
Dotta 18ea965442 ci(runner): stamp paid target provenance (#12805)
## Thinking Path
Trusted workflow-dispatch runs execute an authorized target SHA, but
GitHub context still describes the default-branch workflow revision.
Retained paid results and artifact names were therefore labeling
target-branch executions as master. The workflow must explicitly pass
its authorized target coordinates to target code and trusted reporting.

## What Changed
- emit the canonical authorized target ref alongside the immutable
target SHA
- pass those coordinates to paid cells and the trusted report
- name shared build/provider artifacts with the target SHA rather than
workflow SHA
- add workflow-security coverage for all trusted provenance wiring

## Verification
- focused workflow-security tests: 6/6 passed
- Prettier and git diff checks passed
- run 33823252706 independently proved the pre-fix defect: functionally
green target cells were retained as master SHA 0ad180b85 instead of
feature SHA 33c7646d3

## Risks
The execution checkout and secret boundary were already pinned
correctly; this changes retained attribution and artifact labels only.
Target-side report code on PR #12769 consumes these trusted environment
values and overwrites untrusted cell metadata.

## Model Used
Codex (GPT-5)
2026-09-03 21:15:47 -05:00

36 lines
1.1 KiB
TypeScript

import type { RunnerE2EResult } from "./types.js";
type RunnerE2ESource = NonNullable<RunnerE2EResult["source"]>;
function nonEmpty(value: string | null | undefined) {
const normalized = value?.trim();
return normalized ? normalized : null;
}
function workflowRunUrl(environment: NodeJS.ProcessEnv) {
const serverUrl = nonEmpty(environment.GITHUB_SERVER_URL);
const repository = nonEmpty(environment.GITHUB_REPOSITORY);
const runId = nonEmpty(environment.GITHUB_RUN_ID);
return serverUrl && repository && runId
? `${serverUrl}/${repository}/actions/runs/${runId}`
: null;
}
export function resolveRunnerE2ESource(
existing?: RunnerE2ESource | null,
environment: NodeJS.ProcessEnv = process.env,
): RunnerE2ESource {
return {
sha:
nonEmpty(environment.PAPERCLIP_RUNNER_E2E_SOURCE_SHA) ??
nonEmpty(existing?.sha) ??
nonEmpty(environment.GITHUB_SHA),
ref:
nonEmpty(environment.PAPERCLIP_RUNNER_E2E_SOURCE_REF) ??
nonEmpty(existing?.ref) ??
nonEmpty(environment.GITHUB_REF),
workflowRunUrl:
workflowRunUrl(environment) ?? nonEmpty(existing?.workflowRunUrl),
};
}