mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 16:11:46 +02:00
## Thinking Path > - The merged direct live eval workflow must read the private `paperclip-evals` repository at an exact commit. > - Its first hosted dispatch failed before provider execution because the GitHub App token was minted from the `paperclip` repository installation. > - GitHub returned 404 while resolving the private eval commit, proving that token did not have the required repository scope. > - Minting each short-lived token from the exact private eval repository installation supplies only the cross-repository read boundary the workflow needs. > - A workflow regression now verifies every eval-token block keeps that exact scope. ## Linked Issues or Issue Description The first default-branch run of Runner Direct Live Protocol Evals failed in its immutable eval-commit verification step with HTTP 404. No provider jobs ran and no provider spend occurred. **What existing behavior does this improve?** It allows the protected direct live eval workflow to verify and check out the private `paperclipai/paperclip-evals` repository. **Current behavior** All four eval-token blocks set `GH_REPO` to `paperclipai/paperclip`, selecting a token installation that cannot read the private eval repository. **Proposed behavior** Set `GH_REPO` to the exact `paperclipai/paperclip-evals` repository in authorization, catalog, matrix, and report jobs. **Reason and benefit** The app mints a short-lived token from the correct repository installation while the main repository continues to use its ordinary read-only workflow token. **Breaking changes** None. ## What Changed - Scoped all four private-eval installation tokens to `paperclipai/paperclip-evals`. - Added a regression requiring that exact scope in every token block. ## Verification - `pnpm --filter @paperclipai/paperclip-runner test:runner-protocol-eval-publish` — 15 passed. - `node --test .github/scripts/tests/get-bot-token.test.mjs` — 3 passed. - `actionlint .github/workflows/runner-protocol-live-evals.yml` — passed. - `git diff --check` — passed. ## Risks - The workflow reads a private repository. The token is still short-lived, repository-specific, masked immediately, and used only by the protected default-branch workflow. - This changes no provider execution, Runner behavior, report content, S3 publishing, or browser E2E behavior. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex on GPT-5. The exact deployment ID and context-window size are not exposed. The model used reasoning, repository inspection, code editing, GitHub Actions diagnostics, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change and contains no internal instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation where applicable - [x] I have considered and documented risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge
124 lines
4.6 KiB
JavaScript
124 lines
4.6 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import { readFile } from "node:fs/promises";
|
|
import { resolve } from "node:path";
|
|
import test from "node:test";
|
|
|
|
const repositoryRoot = resolve(import.meta.dirname, "../../..");
|
|
const workflowPath = resolve(
|
|
repositoryRoot,
|
|
".github/workflows/runner-protocol-live-evals.yml",
|
|
);
|
|
|
|
test("direct live eval workflow keeps paid execution behind stable actor authorization", async () => {
|
|
const workflow = await readFile(workflowPath, "utf8");
|
|
assert.match(workflow, /^\s{2}authorize:/mu);
|
|
assert.match(workflow, /RUNNER_E2E_ALLOWED_ACTOR_IDS/u);
|
|
assert.match(workflow, /github\.actor_id/u);
|
|
assert.match(workflow, /github\.triggering_actor/u);
|
|
assert.match(workflow, /refs\/heads\/\$DEFAULT_BRANCH/u);
|
|
assert.match(workflow, /Reauthorize paid execution before provider access/u);
|
|
assert.match(
|
|
workflow,
|
|
/Reauthorize paid execution before provider access[\s\S]*actions\/checkout@[0-9a-f]{40}[\s\S]*Run one immutable direct protocol cell/u,
|
|
);
|
|
assert.doesNotMatch(
|
|
workflow,
|
|
/^\s{2}(?:pull_request|pull_request_target|push|workflow_call|workflow_run):/mu,
|
|
);
|
|
const actions = [
|
|
...workflow.matchAll(/^\s*(?:-\s*)?uses:\s*([^\s#]+)/gmu),
|
|
].map((match) => match[1]);
|
|
assert.ok(actions.length > 0);
|
|
for (const action of actions) assert.match(action, /^[^@]+@[0-9a-f]{40}$/u);
|
|
});
|
|
|
|
test("resolves both repositories immutably and bounds total matrix concurrency", async () => {
|
|
const workflow = await readFile(workflowPath, "utf8");
|
|
const authorize = workflow.slice(
|
|
workflow.indexOf(" authorize:"),
|
|
workflow.indexOf(" catalog:"),
|
|
);
|
|
assert.match(authorize, /repos\/\$REPOSITORY\/branches\/\$encoded_branch/u);
|
|
assert.match(authorize, /\^\[0-9a-f\]\{40\}\$/u);
|
|
assert.match(
|
|
authorize,
|
|
/repos\/paperclipai\/paperclip-evals\/commits\/\$EVALS_SHA/u,
|
|
);
|
|
assert.match(authorize, /COMMITPERCLIP_KEY/u);
|
|
assert.match(authorize, /GH_REPO: paperclipai\/paperclip-evals/u);
|
|
assert.match(
|
|
authorize,
|
|
/GH_TOKEN: \$\{\{ steps\.evals_token\.outputs\.value \}\}/u,
|
|
);
|
|
assert.match(authorize, /test "\$resolved" = "\$EVALS_SHA"/u);
|
|
const catalog = workflow.slice(
|
|
workflow.indexOf(" catalog:"),
|
|
workflow.indexOf(" build_runner:"),
|
|
);
|
|
assert.match(
|
|
catalog,
|
|
/ref: \$\{\{ needs\.authorize\.outputs\.evals_sha \}\}/u,
|
|
);
|
|
assert.match(catalog, /RUNNER_E2E_MAX_PARALLEL/u);
|
|
assert.match(catalog, /max_parallel_per_shard/u);
|
|
const privateCheckouts = [
|
|
...workflow.matchAll(
|
|
/repository: paperclipai\/paperclip-evals[\s\S]*?persist-credentials: false/gmu,
|
|
),
|
|
];
|
|
assert.equal(privateCheckouts.length, 3);
|
|
const privateTokenSteps = [
|
|
...workflow.matchAll(
|
|
/^ - name: Generate private eval-repository token\n(?<body>(?:^ {8,}.*\n?)*)/gmu,
|
|
),
|
|
];
|
|
assert.equal(privateTokenSteps.length, 4);
|
|
for (const tokenStep of privateTokenSteps) {
|
|
assert.match(
|
|
tokenStep.groups.body,
|
|
/^ {10}GH_REPO: paperclipai\/paperclip-evals$/mu,
|
|
"every private-eval token must be minted from the eval repository installation",
|
|
);
|
|
}
|
|
for (const checkout of privateCheckouts) {
|
|
assert.match(
|
|
checkout[0],
|
|
/token: \$\{\{ steps\.evals_token\.outputs\.value \}\}/u,
|
|
);
|
|
}
|
|
assert.match(workflow, /matrix_0/u);
|
|
assert.match(workflow, /matrix_1/u);
|
|
});
|
|
|
|
test("publishes only the separately sanitized Evalbook through trusted OIDC code", async () => {
|
|
const workflow = await readFile(workflowPath, "utf8");
|
|
const report = workflow.slice(
|
|
workflow.indexOf(" report:"),
|
|
workflow.indexOf(" publish_history:"),
|
|
);
|
|
assert.match(
|
|
report,
|
|
/Render the access-controlled canonical Evalbook report/u,
|
|
);
|
|
assert.match(
|
|
report,
|
|
/--viewer-root runner-protocol-build\/extracted\/dist-issue-thread/u,
|
|
);
|
|
assert.match(report, /runner-protocol-eval-campaign\.mjs sanitize/u);
|
|
assert.match(
|
|
report,
|
|
/Upload access-controlled canonical Evalbook and raw attempts/u,
|
|
);
|
|
assert.match(report, /Upload publisher-only sanitized Evalbook/u);
|
|
|
|
const publisher = workflow.slice(workflow.indexOf(" publish_history:"));
|
|
assert.match(publisher, /ref: \$\{\{ github\.sha \}\}/u);
|
|
assert.match(publisher, /id-token: write/u);
|
|
assert.match(publisher, /runner-protocol-eval-public-/u);
|
|
assert.match(publisher, /publish-runner-protocol-eval-history\.mjs/u);
|
|
assert.match(publisher, /runner-protocol-evals/u);
|
|
assert.doesNotMatch(publisher, /(?:OPENAI|ANTHROPIC|OPENROUTER)_API_KEY/u);
|
|
assert.doesNotMatch(publisher, /paperclipai\/paperclip-evals/u);
|
|
assert.doesNotMatch(publisher, /downloaded-runner-protocol-evals/u);
|
|
});
|