mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Every change to Paperclip goes through the pull request CI workflow before it merges > - That workflow is split in two on purpose: `pr.yml` is the caller, and it pins `pr-trusted.yml` at an immutable SHA > - The pin means a change to `pr-trusted.yml` on master does nothing until someone advances the pin > - https://github.com/paperclipai/paperclip/pull/13457 added a read-only Rust dependency cache to the `Verify Paperclip Runner` lane, and it is inert for that reason > - This pull request advances the pin, which is the second step of that rollout > - The benefit is that the saving measured in #13457 starts to apply, about 3.9 minutes per run and about 4.7 compute-hours each day ## Linked Issues or Issue Description This pull request is the activation half of a two-step rollout. #13457 merged on 2026-09-15, so this pull request now targets master directly. - Refs https://github.com/paperclipai/paperclip/pull/13457 — added the cache step this pull request activates. Merged as `f97a3f886`. - Refs https://github.com/paperclipai/paperclip/pull/13302 — the previous activation, and the change that introduced the `# Pin:` comment convention this pull request follows - Refs https://github.com/paperclipai/paperclip/pull/13300 — the change #13302 activated, and the current pin target I searched this repository for other pull requests that move this pin. One is open: - Refs https://github.com/paperclipai/paperclip/pull/12968 — an automated bump of the same pin. See Risks. **What existing behavior does this improve?** The pull request CI lane still recompiles the full Rust dependency tree on every run, because the cache step added in #13457 is not yet part of the active CI definition. **Subsystem affected** Cross-cutting (multiple of the above). The change touches CI workflow configuration only. It does not change product code. **Current behavior** `.github/workflows/pr.yml` pins `pr-trusted.yml` at `44dde2de`, the squashed commit of #13300. GitHub reads `pr.yml` from the pull request and takes every job from `pr-trusted.yml` at that SHA. A change to `pr-trusted.yml` on master therefore has no effect on any pull request until the pin advances. #13457 is the only change to `pr-trusted.yml` since that pin, and it is currently inert. **Proposed behavior** Advance the pin to the commit that carries the cache step, and update the `# Pin:` comment to name the pull request it activates. **Reason and benefit** The saving measured in #13457 begins to apply. Master's own warm-cache lanes run the same checks in 3.4 minutes against 7.1 minutes cold. The net saving is about 3.9 minutes per run after the 20 second restore, across about 73 runs each day. **Breaking changes** None. The activated change only adds a cache restore. A cache miss reproduces today's behavior exactly. **Additional context** The last five activations all landed on the same day as the change they activated: #13302, #12860, #12810, #12509, and #12464. This pull request follows that convention. #13457 merged today. ## What Changed - Advanced the `uses:` pin in `.github/workflows/pr.yml` from `44dde2de` (#13300) to `f97a3f886`, the squashed merge of #13457. - Updated the `# Pin:` comment to name #13457 and the capability it activates, matching the convention #13302 introduced. The diff is the same two lines every previous activation changed. ## Verification Run the workflow and pin tests: ```bash node --test ./scripts/__tests__/e2e-shard.test.mjs ./scripts/__tests__/run-vitest-stable-shard.test.mjs ./scripts/__tests__/release-verify-workflow.test.mjs ./scripts/cloud-source-verification.test.mjs '.github/scripts/tests/*.test.mjs' ``` Result: 469 pass, 0 fail. This includes `pr.yml calls the trusted PR workflow at an immutable SHA`, which reads the pinned workflow out of git and asserts on its content. Confirm the pin resolves to a workflow that contains the cache step: ```bash git show $(grep -oE '[0-9a-f]{40}' .github/workflows/pr.yml):.github/workflows/pr-trusted.yml | grep -c "Restore Runner Rust dependencies (read only)" ``` This prints `1`. This pull request also verifies itself. GitHub uses the pull request's own `pr.yml` for `pull_request` events, so this run takes its jobs from the newly pinned workflow. The `Verify Paperclip Runner` job in this run is therefore the cached version, running the exact definition this pull request makes active. Check its log for `Cache restored from key: v0-rust-release-runner-v1-Linux-x64-...`, confirm cargo prints no `Compiling` lines for third-party crates, and compare the job duration against the 15.0 minute baseline recorded in #13457. ## Risks - **An automated pin bump is open and may race this.** #12968 moves the same pin. It is a no-op today, because `pr-trusted.yml` is identical between the two SHAs. If it rebases after #13457 lands, its target moves to a commit that contains the cache step, and merging it would activate the change with a stale `# Pin:` comment that still names #13300. Closing #12968 before merging this avoids the ambiguity. - **The activated change itself is low risk.** It only adds a read-only cache restore. A miss reproduces today's behavior. #13457 records the full risk list. - **The rollback is one commit.** Restoring the previous pin value returns CI to the current definition without touching `pr-trusted.yml`. ## Model Used Claude Opus 5, provider Anthropic, exact model ID `claude-opus-5`, 1M context window. Adaptive thinking was on. I used tool use throughout: `git` to confirm the merge strategy, the pin history, and the squashed merge SHA, the `gh` CLI and the GitHub API to read the repository merge settings and to find the open automated bump, and local `node --test` runs to verify the pin resolves and the guard tests pass. Run through Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Note on the unchecked boxes. The CI and Greptile boxes stay unchecked until those checks finish on this pull request. On tests: the existing pin guard in `scripts/__tests__/e2e-shard.test.mjs` already covers this change, so this pull request adds no new test. On documentation: no document describes the pull request CI pin, so there is nothing to update. 🤖 Generated with [Claude Code](https://claude.com/claude-code)