mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 16:11:46 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Isolated workspaces give each task a safe and reproducible checkout. > - The existing setup cloned the development database before an agent needed to run the app. > - This made worktree creation slower and heavier for tasks that never start a service. > - Runtime services already use one server start path for heartbeat, operator, and startup recovery flows. > - This pull request moves heavy setup to that start path and keeps worktree creation lean. > - The benefit is faster isolated workspace creation with the same reliable runtime setup when a service starts. ## Linked Issues or Issue Description Related pull request: #10652 covers the initial deferred database-seeding slice. This pull request supersedes it with end-to-end runtime provisioning and safe cleanup. **What existing behavior does this improve?** This improves isolated worktree creation, runtime service startup, and isolated instance cleanup. **Subsystem affected** Cross-cutting: CLI worktree setup, server runtime orchestration, shared workspace contracts, and development scripts. **Current behavior** Paperclip seeds an isolated development database during worktree creation. It can also leave an isolated instance directory after workspace teardown. This work happens even when no runtime service starts. **Proposed behavior** Paperclip creates the worktree with a lean eager setup. It runs an idempotent runtime provision command before the first managed service spawn. Concurrent starts share one provision attempt. Teardown removes the isolated instance safely. **Reason and benefit** Many agent tasks only edit and test code. They do not need a running Paperclip instance. Deferring the database seed reduces workspace startup cost while preserving automatic setup for tasks that start the app. **Breaking changes** None. The new runtime provision command is optional. Existing workspace behavior is unchanged when it is absent. ## What Changed - Split Paperclip worktree setup into a lean eager script and an idempotent runtime provision script. - Added `runtimeProvisionCommand` to project, issue, realized workspace, and persisted workspace contracts. - Added a per-workspace provision mutex before local service spawn for heartbeat, operator, and startup recovery flows. - Added a persisted `provisioning` service state and the `workspace_runtime_provision` operation phase. - Kept provision time outside the service readiness timeout and made failed attempts visible and retryable. - Reclaimed isolated instance data during safe workspace teardown. - Serialized deferred database seeding across processes and bound teardown to the instance root captured in persisted workspace metadata. - Added tests for config flow, concurrency, retry, no-op behavior, readiness timing, scripts, CLI commands, and cleanup. - Documented the eager and runtime provisioning contracts. ## Verification - `pnpm -r typecheck` - `pnpm build` - `pnpm test:run` (server: 3,201 passed; UI: 3,345 passed; the CLI phase exposed one environment-sensitive AWS doctor assertion because the agent runtime injects static AWS credentials) - `env -u AWS_ACCESS_KEY_ID -u AWS_SECRET_ACCESS_KEY pnpm exec vitest run cli/src/__tests__/secrets.test.ts -t 'passes AWS doctor checks when non-secret provider config is present'` - Focused runtime tests cover serialized provisioning, retry after stderr failure, absent-command no-op behavior, operation logging, persisted state order, and readiness timeout exclusion. - Focused CLI and cleanup tests cover concurrent seed serialization, stale-lock fail-closed behavior, persisted instance ownership, and rewritten sibling pointers. ## Risks - A faulty runtime provision script blocks service startup. Paperclip records stderr, marks the service failed, and retries on the next start. - Concurrent service requests share an in-process provision attempt, while the seed command uses an atomic filesystem lock across processes. A stale lock fails closed and requires an operator to verify no seed is running before removing it. - Isolated instance cleanup is destructive. The cleanup service validates ownership and path containment before removal. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, `gpt-5.6-sol`, with agentic reasoning, tool use, and code execution. The service does not expose the context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
138 lines
3.8 KiB
TypeScript
138 lines
3.8 KiB
TypeScript
import { existsSync, lstatSync, readFileSync } from "node:fs";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
|
|
function parseEnvFile(contents: string): Record<string, string> {
|
|
const entries: Record<string, string> = {};
|
|
|
|
for (const rawLine of contents.split(/\r?\n/)) {
|
|
const line = rawLine.trim();
|
|
if (!line || line.startsWith("#")) continue;
|
|
|
|
const match = rawLine.match(/^\s*(?:export\s+)?([A-Za-z_][A-Za-z0-9_]*)\s*=\s*(.*)\s*$/);
|
|
if (!match) continue;
|
|
|
|
const [, key, rawValue] = match;
|
|
const value = rawValue.trim();
|
|
if (!value) {
|
|
entries[key] = "";
|
|
continue;
|
|
}
|
|
if (value.startsWith("#")) {
|
|
entries[key] = "";
|
|
continue;
|
|
}
|
|
|
|
if (
|
|
(value.startsWith("\"") && value.endsWith("\"")) ||
|
|
(value.startsWith("'") && value.endsWith("'"))
|
|
) {
|
|
entries[key] = value.slice(1, -1);
|
|
continue;
|
|
}
|
|
|
|
entries[key] = value.replace(/\s+#.*$/, "").trim();
|
|
}
|
|
|
|
return entries;
|
|
}
|
|
|
|
type WorktreeEnvBootstrapResult =
|
|
| { envPath: null; missingEnv: false }
|
|
| { envPath: string; missingEnv: true }
|
|
| { envPath: string; missingEnv: false };
|
|
|
|
export function isLinkedGitWorktreeCheckout(rootDir: string): boolean {
|
|
const gitMetadataPath = path.join(rootDir, ".git");
|
|
if (!existsSync(gitMetadataPath)) return false;
|
|
|
|
const stat = lstatSync(gitMetadataPath);
|
|
if (!stat.isFile()) return false;
|
|
|
|
return readFileSync(gitMetadataPath, "utf8").trimStart().startsWith("gitdir:");
|
|
}
|
|
|
|
export function resolveWorktreeEnvFilePath(rootDir: string): string {
|
|
return path.resolve(rootDir, ".paperclip", ".env");
|
|
}
|
|
|
|
export function isWorktreeSeedPending(rootDir: string): boolean {
|
|
const markerDir = path.resolve(rootDir, ".paperclip");
|
|
return existsSync(path.resolve(markerDir, "seed-pending"))
|
|
&& !existsSync(path.resolve(markerDir, "seed-complete"));
|
|
}
|
|
|
|
function expandHomePrefix(value: string): string {
|
|
if (value === "~") return os.homedir();
|
|
if (value.startsWith("~/")) return path.resolve(os.homedir(), value.slice(2));
|
|
return value;
|
|
}
|
|
|
|
function resolveHomeAwarePath(value: string): string {
|
|
return path.resolve(expandHomePrefix(value));
|
|
}
|
|
|
|
function resolveDefaultWorktreeHome(env: NodeJS.ProcessEnv): string {
|
|
return path.resolve(expandHomePrefix(env.PAPERCLIP_WORKTREES_DIR?.trim() || "~/.paperclip-worktrees"));
|
|
}
|
|
|
|
function repairStaleMigratedWorktreeEnvEntries(
|
|
rootDir: string,
|
|
entries: Record<string, string>,
|
|
env: NodeJS.ProcessEnv,
|
|
): Record<string, string> {
|
|
const localConfigPath = path.resolve(rootDir, ".paperclip", "config.json");
|
|
const configuredPath = entries.PAPERCLIP_CONFIG?.trim();
|
|
if (!configuredPath) return entries;
|
|
|
|
const resolvedConfiguredPath = resolveHomeAwarePath(configuredPath);
|
|
const staleConfigPath =
|
|
resolvedConfiguredPath !== localConfigPath &&
|
|
!existsSync(resolvedConfiguredPath) &&
|
|
existsSync(localConfigPath);
|
|
if (!staleConfigPath) return entries;
|
|
|
|
const homeDir = resolveDefaultWorktreeHome(env);
|
|
return {
|
|
...entries,
|
|
PAPERCLIP_HOME: homeDir,
|
|
PAPERCLIP_CONFIG: localConfigPath,
|
|
PAPERCLIP_CONTEXT: path.resolve(homeDir, "context.json"),
|
|
};
|
|
}
|
|
|
|
export function bootstrapDevRunnerWorktreeEnv(
|
|
rootDir: string,
|
|
env: NodeJS.ProcessEnv = process.env,
|
|
): WorktreeEnvBootstrapResult {
|
|
if (!isLinkedGitWorktreeCheckout(rootDir)) {
|
|
return {
|
|
envPath: null,
|
|
missingEnv: false,
|
|
};
|
|
}
|
|
|
|
const envPath = resolveWorktreeEnvFilePath(rootDir);
|
|
if (!existsSync(envPath)) {
|
|
return {
|
|
envPath,
|
|
missingEnv: true,
|
|
};
|
|
}
|
|
|
|
const entries = repairStaleMigratedWorktreeEnvEntries(
|
|
rootDir,
|
|
parseEnvFile(readFileSync(envPath, "utf8")),
|
|
env,
|
|
);
|
|
for (const [key, value] of Object.entries(entries)) {
|
|
if (typeof env[key] === "string" && env[key]!.trim().length > 0) continue;
|
|
env[key] = value;
|
|
}
|
|
|
|
return {
|
|
envPath,
|
|
missingEnv: false,
|
|
};
|
|
}
|