Files
PaperClipAI/scripts/tests/native-cleanup-paginated-codex.mjs
T
Devin FoleyandPaperclip be6f49a425 feat(runner): refresh shared coding harness runtimes (#13838)
## Thinking Path

> - Paperclip runs agents through local adapters and the native runner.
> - Both paths must use the same installed provider CLI.
> - New models require current harness releases.
> - The runner still pins Codex 0.153.4, Claude SDK 0.3.263, and
OpenCode 1.18.29.
> - Changing the image alone would fail the runner's exact version and
executable checks.
> - This pull request updates those dependencies, integrity checks,
controller checks, and image pins together.
> - Shared installations can then run the current models without a
task-time download.

## Linked Issues or Issue Description

Refs #13829, which updates model choices and reasoning controls.
Searches found no open PR that updates these runtime pins.

**Current behavior**

The shared provider pack ships old CLIs. Claude Code 2.1.263 cannot run
Opus 5.5, which requires 2.1.280. Remote controllers reject provider
packs whose versions differ from their declared pins.

**Proposed behavior**

Use Codex 0.156.0, Claude Agent SDK 0.3.280 / Claude Code 2.1.280, and
OpenCode 1.18.32 throughout the runner. Keep the reviewed ACP bridge
patches and one shared CLI installation per provider.

**Reason and benefit**

Current harnesses support the new model IDs while preserving executable
verification and remote provider-pack compatibility checks.

## What Changed

- Update dependency overrides, the Codex ACP package patch, runtime
profiles, and remote controller pins.
- Verify the new Claude Linux x64 and macOS arm64/x64 executables and
Codex Linux x64 executable against integrity-verified npm archives.
- Refresh OpenCode version checks, fixtures, and the runner
configuration label.
- Refresh the eval image's Grok, Gemini, Kimi, Cursor, and GitHub CLI
pins and archive hashes. Hermes remains current at 0.19.0.
- Refresh the build-time lock digest from clean pnpm 9.15.4 resolution.
Leave lockfile commits to repository automation.
- Document model compatibility and the separation between CLI runtimes
and patched ACP bridges.

## Verification

- `pnpm -r typecheck` and `pnpm build` passed.
- Rust workspace release tests passed.
- Package/patch and OpenCode binary-materialization contract tests: 11
passed.
- Real Codex 0.156.0 startup-ownership and paginated session-resume
probes passed with isolated synthetic homes and no model turn.
- Codex app-server `thread/start` preserved `gpt-6-sol` and
`gpt-6-luna`; no `turn/start` was sent. An unauthenticated built-in
catalog does not include those account-served entries.
- Installed Claude integrity probes passed for `claude-opus-5-5` and
`claude-fable-5-1`.
- `pnpm --filter @paperclipai/paperclip-runner
test:opencode:qualification` passed with the actual OpenCode 1.18.32
executable under Node 24 and Node 25. The loopback provider exercise
covers health/version, session creation/read/delete, SSE, and a
completed async prompt.
- `pnpm check:token-gates` passed.
- The targeted runner suite passed 130 tests. Three macOS failures in
snapshot module lookup and OpenCode final-message selection also
reproduce on the unchanged base; Linux CI will provide the platform
check.
- [Final Linux
CI](https://github.com/paperclipai/paperclip/actions/runs/35798076399):
all gates passed. Four jobs needed one retry after their CI workers
received shutdown signals. The PR has 55 successful checks, two skipped
checks, Greptile 5/5, and no unresolved review threads.
- Changed runner configuration UI tests: 5 passed.
- Full macOS `pnpm test:run` reached 13,094 passing server tests, 84
skipped, and 18 failures before the wrapper stopped. Failures involved
skill-cache publication permissions, missing bundled connector skills in
the worktree, and a conversation-reset timing case. The 10 cache
permission failures reproduce on the unchanged base; both
conversation-reset cases passed on a targeted retry. The wrapper did not
reach its later workspace/serialized groups locally; Linux CI covers
those groups.
- The local Docker daemon did not respond, so no local Docker build was
run. No billable model requests were made.

## Risks

- Deploy the matching controller and provider pack together. Older
controllers enforce their previous exact pins.
- Current upstream CLIs can change behavior. Existing protocol tests and
isolated real Codex probes cover the integration boundaries;
authenticated model inference is not part of these checks.
- ACP bridge package versions and executable digests stay unchanged
because their executable bytes are unchanged. Only the underlying
CLI/SDK dependencies move.
- No schema migration. Revert the runtime and image pins together to
roll back.

## Model Used

OpenAI GPT-6 via Codex, with repository tools, code execution, and web
research. The exact serving model ID and context window were not exposed
by this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass for the changed surfaces
and real-executable probes; full macOS-suite limitations are listed
above
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-22 17:02:29 -07:00

273 lines
8.2 KiB
JavaScript

// Opt-in real Codex qualification; no model turn or live account data.
// Run from the repository root:
// node --import ./server/node_modules/tsx/dist/loader.mjs scripts/tests/native-cleanup-paginated-codex.mjs
// PAPERCLIP_TEST_CODEX_BINARY may select the exact installed Codex 0.156.0 binary.
// Fresh synthetic fixture directories are retained for inspection; never reuse live homes.
import { spawn, execFileSync } from "node:child_process";
import {
mkdtemp,
readdir,
mkdir,
writeFile,
rename,
cp,
readFile,
readlink,
realpath,
} from "node:fs/promises";
import { tmpdir } from "node:os";
import { join, dirname, relative, isAbsolute } from "node:path";
import { createInterface } from "node:readline";
import { createHash } from "node:crypto";
import { rebaseRetainedNativeCleanupProviderHome } from "../../server/src/services/native-runtime/native-session-executor.ts";
const codexBinary = process.env.PAPERCLIP_TEST_CODEX_BINARY ?? "codex";
if (
execFileSync(codexBinary, ["--version"], {
encoding: "utf8",
timeout: 10000,
}).trim() !== "codex-cli 0.156.0"
) {
throw new Error(
"This opt-in qualification requires Codex CLI 0.156.0. Requalify deliberately before changing the pin.",
);
}
const home = await mkdtemp(join(tmpdir(), "paperclip-paginated-probe-"));
const methods = [];
async function withServer(home, callback) {
const child = spawn(codexBinary, ["app-server"], {
cwd: home,
env: {
PATH: process.env.PATH ?? "/usr/bin:/bin",
HOME: home,
CODEX_HOME: home,
},
stdio: ["pipe", "pipe", "pipe"],
});
const finished = new Promise((resolve) => {
child.once("exit", (code, signal) => resolve({ code, signal }));
child.once("error", (error) => resolve({ error }));
});
child.stderr.on("data", () => {});
const pending = new Map();
let next = 0;
createInterface({ input: child.stdout }).on("line", (line) => {
const frame = JSON.parse(line);
if (frame.id != null && pending.has(frame.id)) {
const { resolve, reject, timer } = pending.get(frame.id);
pending.delete(frame.id);
clearTimeout(timer);
frame.error
? reject(new Error(JSON.stringify(frame.error)))
: resolve(frame.result);
}
});
const rpc = (method, params) =>
new Promise((resolve, reject) => {
methods.push(method);
const id = ++next;
const timer = setTimeout(
() => reject(new Error("local_rpc_timeout")),
10000,
);
pending.set(id, { resolve, reject, timer });
child.stdin.write(JSON.stringify({ id, method, params }) + "\n");
});
try {
await rpc("initialize", {
clientInfo: { name: "paperclip-fixture", version: "1" },
capabilities: { experimentalApi: true },
});
child.stdin.write(JSON.stringify({ method: "initialized" }) + "\n");
return await callback(rpc);
} finally {
let killTimer;
let deadline;
try {
child.stdin.end();
child.kill("SIGTERM");
killTimer = setTimeout(() => child.kill("SIGKILL"), 2000);
const exit = await Promise.race([
finished,
new Promise((_, reject) => {
deadline = setTimeout(
() => reject(new Error("fixture_child_exit_unproven")),
5000,
);
}),
]);
if (exit.error) throw exit.error;
} finally {
clearTimeout(killTimer);
clearTimeout(deadline);
for (const { timer } of pending.values()) clearTimeout(timer);
}
}
}
const result = await withServer(home, (rpc) =>
rpc("thread/start", { cwd: home, model: "gpt-5.6-luna", ephemeral: false }),
);
const threadId = result.thread.id;
const canonicalHome = await realpath(home);
const rolloutRelative = relative(canonicalHome, result.thread.path);
if (
!/^[a-f0-9-]{36}$/.test(threadId) ||
isAbsolute(rolloutRelative) ||
!rolloutRelative.startsWith("sessions/") ||
rolloutRelative.split("/").includes("..") ||
!rolloutRelative.endsWith(`-${threadId}.jsonl`)
) {
throw new Error("Provider fixture path escaped the exact temporary home");
}
const timestamp = new Date().toISOString();
// Same minimal paginated fixture shape as the pinned provider's own
// app-server/tests/common/rollout.rs. No model call or turn/start is sent.
const lines =
[
{
type: "session_meta",
payload: {
id: threadId,
session_id: threadId,
timestamp,
cwd: home,
originator: "codex",
cli_version: "0.156.0",
source: "cli",
model_provider: "openai",
selected_capability_roots: [],
history_mode: "paginated",
},
},
{
type: "response_item",
payload: {
type: "message",
role: "user",
content: [
{
type: "input_text",
text: "Synthetic retained fixture. No action requested.",
},
],
},
},
{
type: "event_msg",
payload: {
type: "user_message",
message: "Synthetic retained fixture. No action requested.",
kind: "plain",
},
},
]
.map((v, ordinal) => JSON.stringify({ timestamp, ordinal, ...v }))
.join("\n") + "\n";
await mkdir(dirname(result.thread.path), { recursive: true });
await writeFile(result.thread.path, lines, { flag: "wx" });
// Materialize the synthetic persisted thread through the real provider so
// SQLite, paginated history and rollout selection use the producer schema.
await withServer(canonicalHome, (rpc) =>
rpc("thread/resume", {
threadId,
cwd: canonicalHome,
model: "gpt-5.6-luna",
excludeTurns: true,
}),
);
const original = `${canonicalHome}-archive`;
await rename(canonicalHome, original);
const fingerprint = async (root) => {
const files = [];
async function visit(relative) {
for (const entry of (
await readdir(join(root, relative), { withFileTypes: true })
).sort((a, b) => a.name.localeCompare(b.name))) {
const p = join(relative, entry.name);
if (entry.isDirectory()) await visit(p);
else if (entry.isFile())
files.push([
p,
createHash("sha256")
.update(await readFile(join(root, p)))
.digest("hex"),
]);
else if (entry.isSymbolicLink())
files.push([p, "symlink", await readlink(join(root, p))]);
else throw new Error("unsupported_synthetic_fixture_entry");
}
}
await visit("");
return createHash("sha256").update(JSON.stringify(files)).digest("hex");
};
const originalFingerprint = await fingerprint(original);
const copied = `${canonicalHome}-copy`;
await cp(original, copied, {
recursive: true,
filter: (source) => !["tmp", ".tmp"].includes(source.split("/").at(-1)),
});
const resume = (rpc) =>
rpc("thread/resume", {
threadId,
cwd: copied,
model: "gpt-5.6-luna",
excludeTurns: true,
});
let red;
try {
await withServer(copied, resume);
} catch (error) {
red = error.message;
}
if (!red?.includes(`no rollout found for thread id ${threadId}`)) {
console.log(JSON.stringify({ red, canonicalHome, copied, threadId }));
throw new Error("expected_exact_missing_paginated_path");
}
rebaseRetainedNativeCleanupProviderHome(
copied,
canonicalHome,
threadId,
"staging",
);
const green = await withServer(copied, resume);
if (green.thread.id !== threadId || green.thread.historyMode !== "paginated")
throw new Error("wrong_resumed_identity");
rebaseRetainedNativeCleanupProviderHome(
copied,
canonicalHome,
threadId,
"canonical",
);
await rename(copied, canonicalHome);
const activated = await withServer(canonicalHome, (rpc) =>
rpc("thread/resume", {
threadId,
cwd: canonicalHome,
model: "gpt-5.6-luna",
excludeTurns: true,
}),
);
if (
activated.thread.id !== threadId ||
activated.thread.historyMode !== "paginated"
)
throw new Error("wrong_activated_identity");
if (methods.some((method) => method === "turn/start"))
throw new Error("unexpected_provider_turn");
if (originalFingerprint !== (await fingerprint(original)))
throw new Error("original_fixture_changed");
console.log(
JSON.stringify({
red: "exact_paginated_path_missing",
green: true,
activatedResume: true,
threadId,
historyMode: green.thread.historyMode,
methods,
original,
canonicalHome,
originalFingerprint,
originalSnapshotPreserved: true,
}),
);