mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 16:11:46 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Sandbox adapters stage project files before an agent starts. > - Referenced projects ignored Git-ignored paths and copied large local directories. > - This behavior increased staging time and disk use, and it differed from anchor workspaces. > - This pull request resolves Git-ignored paths once and shares that result across all referenced-project consumers. > - The benefit is smaller, faster, and consistent project staging. ## Linked Issues or Issue Description No public GitHub issue exists for this bug. **What happened?** Referenced-project staging copied Git-ignored paths, except for a fixed list of heavy directory names. A large repository therefore used much more time and disk space than the same repository in an anchor workspace. **Expected behavior** Referenced-project staging should exclude the same Git-ignored paths that the workspace staging path excludes. **Steps to reproduce** 1. Create a referenced project with a large Git-ignored directory. 2. Start a sandbox or SSH run that stages the referenced project. 3. Observe that the ignored directory enters the staged content. **Paperclip version or commit** Commit `9964b034bbff24e700c8eccf5a8b1fc3daa44bf2`. **Deployment mode** Built from source. ## What Changed - Resolve each referenced project's Git-ignored paths once before staging. - Carry the resolved paths as a required field on `SandboxAdditionalSource`. - Reuse the resolved paths in sandbox staging, SSH staging, and content-signature code. - Harden the read-only Git helper with a bounded process, a reduced environment, and disabled system and global configuration. - Fail closed on Git errors, timeouts, and invalid path relations. - Escape tar glob metacharacters in ignore-derived exclude entries. - Add and update unit tests for the resolver and its three consumers. ## Verification - `pnpm vitest run --config packages/adapter-utils/vitest.config.ts` passes 266 tests locally. - `pnpm exec tsc --noEmit -p packages/adapter-utils/tsconfig.json` passes locally. - CI must pass on this pull request. - Greptile must report 5/5 with no unresolved comments before merge. ## Risks - A Git error or timeout now prevents staging for the affected referenced project. - The resolver uses a bounded read-only Git process and fails closed by design. - The change stays inside `packages/adapter-utils` and does not change the database schema. ## Model Used Claude Sonnet 5 (Anthropic) assisted the implementation with code execution and tool use. The exact context window and reasoning mode are not recorded. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
255 lines
8.6 KiB
TypeScript
255 lines
8.6 KiB
TypeScript
import path from "node:path";
|
|
import { GIT_ARCHIVE_EXCLUDES } from "./git-workspace-sync.js";
|
|
import {
|
|
type SshRemoteExecutionSpec,
|
|
prepareWorkspaceForSshExecution,
|
|
runSshCommand,
|
|
restoreWorkspaceFromSshExecution,
|
|
syncDirectoryToSsh,
|
|
} from "./ssh.js";
|
|
import {
|
|
mergeExcludes,
|
|
referencedSourceIgnoreExcludeEntries,
|
|
type SandboxAdditionalSource,
|
|
type SandboxManagedRuntimeAssetRestoreContext,
|
|
} from "./sandbox-managed-runtime.js";
|
|
import { captureDirectorySnapshot } from "./workspace-restore-merge.js";
|
|
import type { RuntimeProgressSink } from "./runtime-progress.js";
|
|
|
|
// The fixed heavy-directory excludes every referenced project drops,
|
|
// regardless of its ignore resolution. A `git`-resolved project additionally
|
|
// drops its own resolved ignored paths (see `referencedSourceIgnoreExcludeEntries`
|
|
// and the per-project merge below); an `other` project keeps only this set.
|
|
const REMOTE_ADDITIONAL_SOURCE_HEAVY_DIR_EXCLUDES = [
|
|
"node_modules",
|
|
"vendor",
|
|
"dist",
|
|
"build",
|
|
"out",
|
|
"coverage",
|
|
".next",
|
|
".turbo",
|
|
".cache",
|
|
".git",
|
|
].flatMap((entry) => [entry, `${entry}/*`, `*/${entry}`, `*/${entry}/*`]);
|
|
|
|
export interface RemoteManagedRuntimeAsset {
|
|
key: string;
|
|
localDir: string;
|
|
followSymlinks?: boolean;
|
|
exclude?: string[];
|
|
restore?: (ctx: SandboxManagedRuntimeAssetRestoreContext) => Promise<void>;
|
|
}
|
|
|
|
export interface PreparedRemoteManagedRuntime {
|
|
spec: SshRemoteExecutionSpec;
|
|
workspaceLocalDir: string;
|
|
workspaceRemoteDir: string;
|
|
runtimeRootDir: string;
|
|
assetDirs: Record<string, string>;
|
|
/**
|
|
* Remote directory of each additional (referenced) project that staged
|
|
* successfully, keyed by `projectId`. A project whose staging failed is
|
|
* absent (per-project failure isolation).
|
|
*/
|
|
additionalSourceDirs: Record<string, string>;
|
|
restoreWorkspace(onProgress?: RuntimeProgressSink): Promise<void>;
|
|
}
|
|
|
|
function asObject(value: unknown): Record<string, unknown> {
|
|
return value && typeof value === "object" && !Array.isArray(value)
|
|
? (value as Record<string, unknown>)
|
|
: {};
|
|
}
|
|
|
|
function asString(value: unknown): string {
|
|
return typeof value === "string" ? value : "";
|
|
}
|
|
|
|
function asNumber(value: unknown): number {
|
|
return typeof value === "number" ? value : Number(value);
|
|
}
|
|
|
|
function shellQuote(value: string): string {
|
|
return `'${value.replace(/'/g, `'"'"'`)}'`;
|
|
}
|
|
|
|
async function readRemoteFile(spec: SshRemoteExecutionSpec, remotePath: string): Promise<Buffer> {
|
|
const result = await runSshCommand(spec, `base64 < ${shellQuote(remotePath)}`, {
|
|
maxBuffer: 1024 * 1024,
|
|
});
|
|
return Buffer.from(result.stdout.replace(/\s+/g, ""), "base64");
|
|
}
|
|
|
|
export function buildRemoteExecutionSessionIdentity(spec: SshRemoteExecutionSpec | null) {
|
|
if (!spec) return null;
|
|
return {
|
|
transport: "ssh",
|
|
host: spec.host,
|
|
port: spec.port,
|
|
username: spec.username,
|
|
remoteCwd: spec.remoteCwd,
|
|
} as const;
|
|
}
|
|
|
|
export function remoteExecutionSessionMatches(saved: unknown, current: SshRemoteExecutionSpec | null): boolean {
|
|
const currentIdentity = buildRemoteExecutionSessionIdentity(current);
|
|
if (!currentIdentity) return false;
|
|
|
|
const parsedSaved = asObject(saved);
|
|
return (
|
|
asString(parsedSaved.transport) === currentIdentity.transport &&
|
|
asString(parsedSaved.host) === currentIdentity.host &&
|
|
asNumber(parsedSaved.port) === currentIdentity.port &&
|
|
asString(parsedSaved.username) === currentIdentity.username &&
|
|
asString(parsedSaved.remoteCwd) === currentIdentity.remoteCwd
|
|
);
|
|
}
|
|
|
|
export async function prepareRemoteManagedRuntime(input: {
|
|
spec: SshRemoteExecutionSpec;
|
|
runId: string;
|
|
adapterKey: string;
|
|
workspaceLocalDir: string;
|
|
workspaceRemoteDir?: string;
|
|
syncWorkspace?: boolean;
|
|
assets?: RemoteManagedRuntimeAsset[];
|
|
/** Referenced (additional) projects to stage as plain, read-only trees. */
|
|
additionalSources?: SandboxAdditionalSource[];
|
|
// Upload progress sink. Threaded for the byte-counting transport rewrite; the
|
|
// child task wires it into the workspace/asset transfers.
|
|
onProgress?: RuntimeProgressSink;
|
|
}): Promise<PreparedRemoteManagedRuntime> {
|
|
const baseWorkspaceRemoteDir = input.workspaceRemoteDir ?? input.spec.remoteCwd;
|
|
const syncWorkspace = input.syncWorkspace !== false;
|
|
const workspaceRemoteDir = syncWorkspace
|
|
? path.posix.join(
|
|
baseWorkspaceRemoteDir,
|
|
".paperclip-runtime",
|
|
"runs",
|
|
input.runId,
|
|
"workspace",
|
|
)
|
|
: baseWorkspaceRemoteDir;
|
|
const runtimeRootDir = path.posix.join(workspaceRemoteDir, ".paperclip-runtime", input.adapterKey);
|
|
|
|
const preparedWorkspace = syncWorkspace
|
|
? await prepareWorkspaceForSshExecution({
|
|
spec: input.spec,
|
|
localDir: input.workspaceLocalDir,
|
|
remoteDir: workspaceRemoteDir,
|
|
onProgress: input.onProgress,
|
|
})
|
|
: null;
|
|
const baselineSnapshot = preparedWorkspace
|
|
? await captureDirectorySnapshot(input.workspaceLocalDir, {
|
|
exclude: preparedWorkspace.gitBacked
|
|
? [...GIT_ARCHIVE_EXCLUDES, ".paperclip-runtime"]
|
|
: [".paperclip-runtime"],
|
|
})
|
|
: null;
|
|
|
|
const assetDirs: Record<string, string> = {};
|
|
try {
|
|
for (const asset of input.assets ?? []) {
|
|
const remoteDir = path.posix.join(runtimeRootDir, asset.key);
|
|
assetDirs[asset.key] = remoteDir;
|
|
await syncDirectoryToSsh({
|
|
spec: input.spec,
|
|
localDir: asset.localDir,
|
|
remoteDir,
|
|
followSymlinks: asset.followSymlinks,
|
|
exclude: asset.exclude,
|
|
onProgress: input.onProgress,
|
|
progressLabel: asset.key,
|
|
});
|
|
}
|
|
} catch (error) {
|
|
if (preparedWorkspace && baselineSnapshot) {
|
|
await restoreWorkspaceFromSshExecution({
|
|
spec: input.spec,
|
|
localDir: input.workspaceLocalDir,
|
|
remoteDir: workspaceRemoteDir,
|
|
baselineSnapshot,
|
|
restoreGitHistory: preparedWorkspace.gitBacked,
|
|
onProgress: input.onProgress,
|
|
});
|
|
}
|
|
throw error;
|
|
}
|
|
|
|
// Stage each referenced (additional) project as a plain, read-only tree in its
|
|
// OWN isolated remote directory (`project-<projectId>`). Additional sources
|
|
// never get the anchor's git-history/overlay semantics. Per-project failure
|
|
// isolation: one project's failure logs a warning and is skipped; the run and
|
|
// the other projects continue (no workspace restore, unlike an asset failure).
|
|
const additionalSourceDirs: Record<string, string> = {};
|
|
for (const source of input.additionalSources ?? []) {
|
|
const { localPath, projectId, ignoreResolution } = source;
|
|
try {
|
|
if (!path.posix.isAbsolute(localPath)) {
|
|
throw new Error(`additional source localPath is not an absolute path: ${localPath}`);
|
|
}
|
|
if (
|
|
projectId.length === 0 ||
|
|
projectId.includes("/") ||
|
|
projectId.includes("\\") ||
|
|
projectId.includes("..")
|
|
) {
|
|
throw new Error(`additional source projectId is not a simple path segment: ${projectId}`);
|
|
}
|
|
// Fail closed: a project whose ignore resolution failed is not staged at
|
|
// all — the existing per-project skip-and-warn path below handles it.
|
|
if (ignoreResolution.kind === "failed") {
|
|
throw new Error(`referenced project ignore resolution failed: ${ignoreResolution.reason}`);
|
|
}
|
|
const remoteDir = path.posix.join(runtimeRootDir, `project-${projectId}`);
|
|
const exclude = mergeExcludes(
|
|
REMOTE_ADDITIONAL_SOURCE_HEAVY_DIR_EXCLUDES,
|
|
referencedSourceIgnoreExcludeEntries(ignoreResolution),
|
|
);
|
|
await syncDirectoryToSsh({
|
|
spec: input.spec,
|
|
localDir: localPath,
|
|
remoteDir,
|
|
exclude,
|
|
onProgress: input.onProgress,
|
|
progressLabel: `project-${projectId}`,
|
|
});
|
|
additionalSourceDirs[projectId] = remoteDir;
|
|
} catch (error) {
|
|
console.warn(
|
|
`[paperclip] Failed to stage referenced project ${projectId}; skipping it. ${String(error)}`,
|
|
);
|
|
}
|
|
}
|
|
|
|
return {
|
|
spec: input.spec,
|
|
workspaceLocalDir: input.workspaceLocalDir,
|
|
workspaceRemoteDir,
|
|
runtimeRootDir,
|
|
assetDirs,
|
|
additionalSourceDirs,
|
|
restoreWorkspace: async (onProgress?: RuntimeProgressSink) => {
|
|
if (preparedWorkspace && baselineSnapshot) {
|
|
await restoreWorkspaceFromSshExecution({
|
|
spec: input.spec,
|
|
localDir: input.workspaceLocalDir,
|
|
remoteDir: workspaceRemoteDir,
|
|
baselineSnapshot,
|
|
restoreGitHistory: preparedWorkspace.gitBacked,
|
|
onProgress,
|
|
});
|
|
}
|
|
for (const asset of input.assets ?? []) {
|
|
if (!asset.restore) continue;
|
|
await asset.restore({
|
|
assetDir: path.posix.join(runtimeRootDir, asset.key),
|
|
readFile: (remotePath) => readRemoteFile(input.spec, remotePath),
|
|
});
|
|
}
|
|
},
|
|
};
|
|
}
|