mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-10 20:50:08 +02:00
## Thinking Path > - Paperclip manages AI agents and their work. > - The experimental Runner owns provider processes and durable sessions. > - Pi needs working task execution and human controls. > - The five-PR stack must preserve changes already on master. > - Each layer now carries the complete integrated source for a safe sequential fallback. > - This PR belongs to native GitHub stack #15602, ending at #14956. ## Linked Issues or Issue Description Refs #14436, #14631, #14743 and #14956. Ship Pi 1.0 through the experimental Paperclip Runner. The five PRs are #14921, #14922, #14923, #14924 and #14956. The user authorized the complete merge after checks pass. Existing `pi_local` execution is unchanged. Accounting and wider provider/platform qualification remain deferred. ## What Changed - Recover missing final replies after workspace finalization changes owners, using accepted-turn evidence without rerunning work or granting external-chat publication. - Preserve the admitted Pi instruction root across warm runs, while retaining changed-root rejection. - Give Pi a bounded 15-second default shutdown grace so stop, drain acknowledgement and durable suspension can complete. Explicit deadlines and other providers retain their existing behavior. - Integrate the Pi 1.0 runtime and master contracts. - Use Pi profile 22. Preserve explicit caller-selected models and exact native thinking levels. Keep Pi's wrapper, helper, extension and question/control behavior unchanged from the qualified profile-19 runtime. - Preserve master's Dot lifecycle and consent fields, configured task environment, status guards and current Codex/Claude dependency versions. Cursor stays qualified. Copilot stays pending; profile 17 binds the changed shared protocol validation sources. - Exclude general AWS IAM credentials from Pi static/custom provider bindings and selected task projections; preserve the provider-scoped Bedrock bearer key. Profile 21 is retained as historical provenance. Rust and cloud install probes use the current declaration. - Patch bundled brace-expansion 5.0.9 to the exact official 5.0.12 payload. Pin the patch and complete runtime closures. Include the patch in normal installed setup tooling. Keep the upstream Pi shrinkwrap as provenance and permit only this exact security correction. - Include current attestation files in the Docker build context. Keep the repository lockfile unchanged from master. CI and private image builds resolve manifest changes before their frozen installation. ## Verification - Full local `pnpm -r typecheck` passes, including Runner Rust, server and UI. Focused integration checks pass: 194 Runner admission/environment tests, 63 profile/credential tests with one expected skip, 152 Dot/UI configuration tests, and Pi transcript/notice tests. - Full local `pnpm build` passes on the final source. - Fresh final-source checks pass: all 698 Rust workspace tests (32 binaries), 156 credential/profile/controller tests with one expected skip, Runner TypeScript typecheck, and 20 package/setup/sandbox tests. - The profile-21 Pi materializer passes on the native host with the official pinned Node 24.21.0 and its npm. It verifies all 150 locked packages, the patched dependency and the exact closure. Setup/package bundle tests and UI token gates pass. - The old hashes were reproduced for all three supported targets before calculating the patched graph. New closure hashes are darwin-arm64 `282022db10150c6632b3444df421342e7d534bdf5d5fb1097a2e79d0625a2bcf`, darwin-x64 `64e251e19009f755c0b04f73ce2138246faab71a961b0f13d75ebfcc34bef12e`, and linux-x64 `713b1fdff42fb56a1518bdc084f181d70bee8ebadc3e4b1d76321ed9108c8410`. Independent native platform execution is separate from graph identity reproduction. - Historical cloud qualification remains unchanged: all seven core cases pass on shipping source `10dc43c9ec65d88c2f782d62afb296d09494f215`, harness `1a4408a48cfb5a1f094a311141c257c92cd7a893`, image `sha256:5b3a775b383591bda1b0c1889e509acc70ce7f37c53f09733c81d59037f02280`, and accepted Sonnet 4.6/low fixture. All 215 canonical files and all seven cleanup checks pass independent verification. These are profile-19 results and are not relabeled as fresh profile-22 runs. - Current Pi digest: `sha256:e92078bee3c23bec4100aa589013a44613d054cd686826534025d8019e9f39a9`. [The readiness plan](https://github.com/paperclipai/paperclip/blob/codex/pi-production-readiness/doc/plans/2026-10-02-pi-production-readiness.md) preserves campaign and failed-attempt provenance. - Merge only after every PR's current-head CI and fresh review pass. Linux CI covers the full suites, build and browser tests. The local embedded Postgres API-authority suite cannot start on this macOS/Node 26 host, so Linux CI must confirm that suite. ### Fresh profile-22 core qualification — 2026-10-08 All seven accepted core cases pass canonically on Pi profile 22, with `openrouter/anthropic/claude-sonnet-4.6` and native-confirmed low thinking. This model is a fixture; production accepts the caller's explicit Pi provider/model. Runtime/install source: `3241a992f2a7703e59e97ed0fd3e5d6405de4401`. Frozen accepted harness: `1a4408a48cfb5a1f094a311141c257c92cd7a893`. Immutable cloud image: `ghcr.io/paperclipai/paperclip-daytona-runner@sha256:506f22db7edd78f37c0c40bec1cc084af1850455026dbf467194bfbb8fcef141`. Pi digest: `sha256:e92078bee3c23bec4100aa589013a44613d054cd686826534025d8019e9f39a9`. [Hosted Linux image and clean-install verification](https://github.com/paperclipai/paperclip/actions/runs/37868328023) passes, including all 20 source-bound archives, normal CLI/Pi setup, companion import and the production pack reader. This exact installation source includes the latest master integration and the corrected Pi warm instruction-root fence. Full local typecheck/build and current-head hosted CI verify the final stack. All 13 focused real-root regressions pass. The full local executor suite passed 662 tests; 15 database tests could not start the Mac embedded PostgreSQL service. Hosted Linux CI passes the full required verification and E2E checks. These fresh results keep their own source identity; profile-19 results remain historical. | Core path | Canonical campaign | Retained archive SHA-256 | | --- | --- | --- | | File edit, validation, download and Done | `pi-core22-replyfix-0-1791511228` | 23 files; `a473e8603a3dd4737863291f8d3d1e392391f0b16d433c3e0e0e9d8baf7a97b0` | | Pending question and controller restart | `pi-core22-replyfix-1-1791511376` | 33 files; `6b829c4eb74e1f32a89c692a4ae7130dbfc1c6d3cf13915effe2103d9e242c8e` | | Three-turn session/process/workspace continuity | `pi-core22-replyfix-2-1791511587` | 23 files; `7a87021f8f9a3fdd3c58bb4467f8d82c635e3ea4795d6e75f144d9aa14818df8` | | Four typed questions and browser reconnects | `pi-core22-replyfix-3-1791511881` | 42 files; `9e31755252be1f4f9cb0626c984c142d4d1ae5f5bee3a7af08444db8d12c280a` | | Plan approval and completion | `pi-core22-replyfix-4-1791512031` | 22 files; `a0383ce1aab38e7b5a25ce0e9dd3bebea5c037ebd96ae6b29dae19015da2ae2c` | | Same-turn steering and permission denial | `pi-core22-replyfix-5-1791512261` | 39 files; `c929b8c7070f0b66aedc17e65ca46e6beab1e363926ac9f7e2a75fb250f05949` | | Stop during pending permission | `pi-core22-replyfix-6-1791512390` | 33 files; `7f0a58ae0f4d5bfc76149435f4e322537089c5bd16e7ffe9b5ad71f10a621a07` | All 215 canonical files (28714587 bytes) are independently hash-verified. All seven cleanup grades pass, with no owned runtime process or temporary root after each case. Automatic retries are zero. The owned cloud host stopped normally after retention. The prior profile-22 warm attempt remains failed and separately retained: archive SHA-256 `1e54eba5ec72b50cee1534b23d1d1d4f21a090006b8a64501ba70db972abfde5`. Its original canonical classification is preserved. Diagnosis reproduced a product bug comparing an agent-files root against an unset checkpoint-only field. The fix stores the admitted physical root separately from the adopted per-run collection capability. The real-root regression fails before the fix and passes afterward, including rejection of a changed physical root. Fixture, grader, model and all seven accepted case IDs are unchanged; this fresh campaign tests final-reply publication after file registration first. The intermediate restart attempt also remains failed and retained: archive SHA-256 `5dcaefdf1d17cf4cd54fd4cf810f45e736667392339b8ce7caf08bb4e225277f`. Its original canonical classification is preserved. Pi resumed, wrote the verified answer and completed its task; exact runner suspension was proven, but idle stop consumed about 5.2s and left under 3s for the drain acknowledgement. The Pi-only default shutdown grace is now 15s, preserving a full 5s drain round trip and a finite suspension reserve. Explicit caller deadlines, other provider defaults, literal drain receipts and exact suspension identity checks remain unchanged. The timing regression fails before this correction and passes afterward; all 18 focused settlement tests and Runner typecheck pass. The final-source file attempt is also preserved as failed (`candidate_failure`), archive SHA-256 `db6767b6773ea618997927ac77bdb005a5ac81492c7b9c0ffbc900449f829bc9`. Native edit, validation, exact downloadable artifact and Done/succeeded all passed, and the exact final reply was durably recorded. A workspace recovery owner completed before the live heartbeat reached presentation, leaving that reply absent from task chat. Recovery now materializes only a completed final reply from the accepted turn of an ordinary internal Done task, preserving issue/run/contract binding, suppression, external-chat authorization and same-run deduplication. The database regression covers the generated file-preparation receipt, suppression, unapproved external continuation and replay. Server typecheck and all 49 response-selection tests pass; hosted Linux verifies the database regression because embedded PostgreSQL cannot start on this Mac. The delayed-final-answer database regression passes on [the final root-source Linux server shard](https://github.com/paperclipai/paperclip/actions/runs/37868262553/job/113628594152), alongside 1,108 passing tests. The first root Runner shard had one unchanged durable-resume test exceed its 5-second timeout; the identical top-source shard and the isolated exact test passed. One rerun of that failed job and its required aggregate passed without source or test changes. The original failed job log and the single-rerun receipt remain retained. ### October 9 merge verification Current merge head: `5a8fe63512a7166aaef5cf50065a25008aa8b44b`. All current-head checks pass, including `ci / verify` and `ci / e2e`; exact-head Greptile review is 5/5 with no unresolved threads. Current master conflicts are resolved. The user authorized the maintainer override of the code-owner review gate after these checks. The seven retained live core cases remain bound to source `3241a992f2a7703e59e97ed0fd3e5d6405de4401` and its recorded cloud image. ## Risks - The security correction changes the dependency closure and profile identity. Old sessions must reopen on the new profile. Exact identities and credential bindings fail closed. - The runner remains experimental and requires explicit selection. Legacy Pi Local is unchanged. Caller model IDs pass through; the E2E model is a fixture. - Accounting and the broad platform/provider matrix remain deferred. This merge does not publish a release or deploy a service. ## Model Used OpenAI GPT-6 through Codex assisted with reasoning, repository inspection, editing and tool use. The exact serving ID and context window are not exposed in this session. Final live qualification uses Pi 1.0.0 with `openrouter/anthropic/claude-sonnet-4.6` and native-confirmed low thinking. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
432 lines
27 KiB
TypeScript
432 lines
27 KiB
TypeScript
import { explicitlyRequestsFileOutput } from "../../server/src/services/native-runtime/native-deliverable-feedback.js";
|
|
import { copilotProtectionTasks } from "./copilot-protection-tasks.js";
|
|
import type { APIRequestContext, APIResponse } from "@playwright/test";
|
|
import { afterEach, expect, it, vi } from "vitest";
|
|
import { classifyFailure } from "./failure-classifier.js";
|
|
import { ObservedStateTimeout, RemoteAdmissionReadError, RunnerApi, RunnerApiHttpError } from "./api.js";
|
|
import { createRemoteNativeBootstrap } from "./remote-native-bootstrap.js";
|
|
import { REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS, type RemoteFixtureApi, type RemoteNativeFixture } from "./remote-native-fixtures.js";
|
|
|
|
afterEach(() => { vi.useRealTimers(); vi.unstubAllEnvs(); });
|
|
|
|
function harness(timeoutMs = REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 18_000) {
|
|
const order: string[] = [];
|
|
const issue = { id: "issue", companyId: "company", assigneeAgentId: "agent" };
|
|
const run = { id: "run", companyId: "company", agentId: "agent", status: "running", executionStage: "preparing", runtimeMode: "native", nativePhase: "provider_running" };
|
|
const leases = [{ id: "lease", heartbeatRunId: "run", issueId: "issue", status: "active", providerLeaseId: "sandbox" }];
|
|
const api = { get: vi.fn(async (path: string) => path === "/api/issues/issue" ? issue : path === "/api/heartbeat-runs/run" ? run : leases) };
|
|
const fixture = {
|
|
binding: { companyId: "company", environmentId: "env", runId: "run", leaseId: "lease", sandboxId: "sandbox", remoteCwd: "/workspace" },
|
|
baseline: { complete: true },
|
|
publishAction: vi.fn(async () => { order.push("publish"); }),
|
|
close: vi.fn(async () => { order.push("close"); }),
|
|
} as unknown as RemoteNativeFixture;
|
|
const bind = vi.fn(async () => { order.push("armed"); return fixture; });
|
|
const input = {
|
|
api: api as unknown as RemoteFixtureApi, daytona: { get: vi.fn() }, companyId: "company", environmentId: "env", agentId: "agent",
|
|
image: `image@sha256:${"a".repeat(64)}`, nodeSha256: `sha256:${"b".repeat(64)}`, runnerdSha256: `sha256:${"c".repeat(64)}`,
|
|
deadlineAt: Date.now() + timeoutMs, evidence: vi.fn(async (_name: string, _data: unknown) => { order.push("evidence"); }),
|
|
};
|
|
const bootstrap = createRemoteNativeBootstrap(input, bind);
|
|
const request = { issueId: "issue", runId: "run", targets: ["target.txt"], actionPrompt: async (actual: RemoteNativeFixture) => {
|
|
expect(actual).toBe(fixture); await Promise.resolve(); order.push("baseline"); return "PRIVATE ACTUAL ACTION";
|
|
} };
|
|
return { bootstrap, input, bind, api, issue, run, leases, fixture, request, order };
|
|
}
|
|
|
|
it("keeps negated bootstrap instructions out of the production file-delivery contract", () => {
|
|
const prompt = harness().bootstrap.prompt("nonce");
|
|
// Retained failed attempt: comma splitting detached this clause from “do not”.
|
|
const original = "Before reading those instructions, do not infer the task, run shell commands, create or modify any file, ask replacement questions, or mark work complete. Do not create the missing instruction file.";
|
|
expect(explicitlyRequestsFileOutput(original)).toBe(true);
|
|
expect(explicitlyRequestsFileOutput(prompt)).toBe(false);
|
|
expect(prompt).toContain("Do not create or modify any file.");
|
|
expect(prompt).toContain("Do not run shell commands.");
|
|
expect(prompt).toContain("Do not ask replacement questions.");
|
|
expect(prompt).toContain("Do not mark work complete.");
|
|
expect(prompt).toContain("Do not create the missing instruction file.");
|
|
// A real requested output still requires delivery; no production gate changes.
|
|
expect(explicitlyRequestsFileOutput(`${prompt}\nCreate a downloadable report.txt file.`)).toBe(true);
|
|
});
|
|
|
|
it("keeps async completion immediate with a private sentinel and no delivery wait", () => {
|
|
const task = copilotProtectionTasks.find(task => task.id === "attached-async-settlement")!;
|
|
const action = task.buildPrompt("nonce");
|
|
expect(explicitlyRequestsFileOutput(action)).toBe(false);
|
|
expect(explicitlyRequestsFileOutput(`${harness().bootstrap.prompt("nonce")}\n${action}`)).toBe(false);
|
|
expect(action).toContain("attempt to finish immediately without calling read_bash or another waiting tool");
|
|
expect(action).toContain("Do not modify fixture code, manufacture its result, or start another command.");
|
|
expect(action).toContain("private diagnostic sentinel, not a requested file deliverable");
|
|
expect(action).toContain("Do not publish it. Do not attach it.");
|
|
expect(explicitlyRequestsFileOutput(`${action}\nAttach a downloadable report.txt file.`)).toBe(true);
|
|
expect(action).toContain("evidence [], verification []");
|
|
expect(action).not.toContain("register_deliverable");
|
|
});
|
|
|
|
it("keeps the complete readiness/install reserve when a lease arrives at the admission boundary", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("late-lease");
|
|
const lease = h.leases.pop()!;
|
|
let remainingAtBind = 0;
|
|
h.bind.mockImplementation(async () => { remainingAtBind = h.input.deadlineAt - Date.now(); return h.fixture; });
|
|
const pending = h.bootstrap.bindAndRelease(h.request);
|
|
await vi.advanceTimersByTimeAsync(800);
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
h.leases.push(lease); await vi.advanceTimersByTimeAsync(100);
|
|
await expect(pending).resolves.toBe(h.fixture);
|
|
expect(remainingAtBind).toBeGreaterThanOrEqual(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS);
|
|
expect(h.bind).toHaveBeenCalledExactlyOnceWith(expect.objectContaining({ deadlineAt: h.input.deadlineAt }));
|
|
expect(h.order.indexOf("baseline")).toBeLessThan(h.order.indexOf("publish"));
|
|
});
|
|
|
|
it("withholds actual work until exact run admission, armed observer and awaited baseline", async () => {
|
|
const h = harness(); const prompt = h.bootstrap.prompt("nonce");
|
|
expect(prompt).not.toContain("PRIVATE ACTUAL ACTION");
|
|
expect(prompt).toContain("native file-read tool");
|
|
expect(h.bind).not.toHaveBeenCalled();
|
|
expect(await h.bootstrap.bindAndRelease(h.request)).toBe(h.fixture);
|
|
expect(h.order).toEqual(["armed", "baseline", "evidence", "publish"]);
|
|
expect(h.bind).toHaveBeenCalledWith(expect.objectContaining({
|
|
sdkVersion: "0.203.0", targets: ["target.txt"],
|
|
authority: { companyId: "company", environmentId: "env", runId: "run", leaseId: "lease", sandboxId: "sandbox", image: h.input.image },
|
|
}));
|
|
expect(h.fixture.publishAction).toHaveBeenCalledWith(expect.stringMatching(/^\.paperclip-eval-action-[a-f0-9]{36}\.txt$/u), "PRIVATE ACTUAL ACTION");
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).not.toContain("PRIVATE ACTUAL ACTION");
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("one unconsumed");
|
|
});
|
|
|
|
it.each(["issue-company", "issue-agent", "issue-id", "run-company", "run-agent", "run-id", "run-terminal", "ambiguous-lease"])("rejects %s before observer execution or action delivery", async variant => {
|
|
const h = harness(); h.bootstrap.prompt("nonce");
|
|
if (variant === "issue-company") h.issue.companyId = "other";
|
|
if (variant === "issue-agent") h.issue.assigneeAgentId = "other";
|
|
if (variant === "issue-id") h.issue.id = "other";
|
|
if (variant === "run-company") h.run.companyId = "other";
|
|
if (variant === "run-agent") h.run.agentId = "other";
|
|
if (variant === "run-id") h.run.id = "other";
|
|
if (variant === "run-terminal") h.run.status = "succeeded";
|
|
if (variant === "ambiguous-lease") h.leases.push({ ...h.leases[0]!, id: "second" });
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow();
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("waits through queued admission without publishing early", async () => {
|
|
const h = harness(); h.bootstrap.prompt("nonce"); h.run.status = "queued";
|
|
const original = h.api.get.getMockImplementation()!; let count = 0;
|
|
h.api.get.mockImplementation(async path => {
|
|
if (path === "/api/heartbeat-runs/run" && ++count === 2) h.run.status = "running";
|
|
return original(path);
|
|
});
|
|
await h.bootstrap.bindAndRelease(h.request);
|
|
expect(count).toBe(2); expect(h.fixture.publishAction).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it.each(["provider_running", "observed"])("admits a native %s run while its legacy stage stays preparing", async nativePhase => {
|
|
const h = harness(); h.bootstrap.prompt("native-ready"); h.run.nativePhase = nativePhase;
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).resolves.toBe(h.fixture);
|
|
expect(h.run.executionStage).toBe("preparing");
|
|
expect(h.bind).toHaveBeenCalledTimes(1); expect(h.fixture.publishAction).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it.each(["", "x".repeat(16385)])("rejects empty or over-bound action after closing only its observer", async action => {
|
|
const h = harness(); h.bootstrap.prompt("nonce");
|
|
await expect(h.bootstrap.bindAndRelease({ ...h.request, actionPrompt: () => action })).rejects.toThrow("empty or too large");
|
|
expect(h.fixture.publishAction).not.toHaveBeenCalled(); expect(h.fixture.close).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it("retains uncertain delivery and cleanup failure without retrying publication", async () => {
|
|
const h = harness(); h.bootstrap.prompt("nonce");
|
|
vi.mocked(h.fixture.publishAction).mockRejectedValue(new Error("uncertain delivery"));
|
|
vi.mocked(h.fixture.close).mockRejectedValue(new Error("cleanup failed"));
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("observer cleanup is unproven");
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("one unconsumed");
|
|
expect(h.fixture.publishAction).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it("rejects ambiguous bootstrap delivery and reused nonces", async () => {
|
|
const h = harness(); h.bootstrap.prompt("first");
|
|
expect(() => h.bootstrap.prompt("first")).toThrow("reused"); h.bootstrap.prompt("second");
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("one unconsumed");
|
|
expect(h.api.get).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it.each(["nodeSha256", "runnerdSha256", "image"])("requires immutable %s before any remote call", field => {
|
|
const h = harness();
|
|
expect(() => createRemoteNativeBootstrap({ ...h.input, [field]: "ambient-latest" }, h.bind)).toThrow("immutable");
|
|
expect(h.input.daytona.get).not.toHaveBeenCalled();
|
|
});
|
|
|
|
|
|
it("admits a cold building_snapshot lease after 20 seconds within the unchanged case deadline", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(90_000); h.bootstrap.prompt("cold");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
let sandboxState = "building_snapshot";
|
|
h.api.get.mockImplementation(async path => path.endsWith("/leases") && sandboxState === "building_snapshot" ? [] : original(path));
|
|
const delivery = h.bootstrap.bindAndRelease(h.request);
|
|
await vi.advanceTimersByTimeAsync(25_000);
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
sandboxState = "started";
|
|
await vi.advanceTimersByTimeAsync(100);
|
|
await expect(delivery).resolves.toBe(h.fixture);
|
|
expect(h.bind).toHaveBeenCalledWith(expect.objectContaining({ deadlineAt: 90_000 }));
|
|
expect(h.input.daytona.get).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it.each(["failed", "cancelled", "succeeded"])("stops waiting immediately when provisioning run becomes %s", async status => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 18_000); h.bootstrap.prompt("terminal"); h.leases.length = 0;
|
|
const delivery = expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("stopped before observer setup");
|
|
await vi.advanceTimersByTimeAsync(1000); h.run.status = status;
|
|
await vi.advanceTimersByTimeAsync(100); await delivery;
|
|
expect(Date.now()).toBeLessThan(h.input.deadlineAt);
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
expect(h.input.evidence).toHaveBeenCalledWith("remote-native-bootstrap-startup-run.json", expect.objectContaining({ runStatus: status, deadlineReached: false }));
|
|
});
|
|
|
|
it("rechecks run ownership while waiting for the lease", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(); h.bootstrap.prompt("owner"); h.leases.length = 0;
|
|
const delivery = expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("ownership is unproven");
|
|
await vi.advanceTimersByTimeAsync(100); h.run.companyId = "foreign";
|
|
await vi.advanceTimersByTimeAsync(100); await delivery;
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it.each(["foreign-run", "foreign-issue", "inactive", "missing-provider"])("never admits %s and reserves setup time within the authored deadline with bounded state", async variant => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("timeout");
|
|
if (variant === "foreign-run") h.leases[0]!.heartbeatRunId = "foreign";
|
|
if (variant === "foreign-issue") h.leases[0]!.issueId = "foreign";
|
|
if (variant === "inactive") h.leases[0]!.status = "released";
|
|
if (variant === "missing-provider") h.leases[0]!.providerLeaseId = "";
|
|
h.run.executionStage = "PRIVATE".repeat(10_000);
|
|
const delivery = expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("Timed out waiting for owned native qualification lease");
|
|
await vi.advanceTimersByTimeAsync(1000); await delivery;
|
|
expect(Date.now()).toBe(1000); expect(h.bind).not.toHaveBeenCalled();
|
|
expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
const state = h.input.evidence.mock.calls[0]![1];
|
|
expect(state).toMatchObject({ executionStage: "unknown", activeOwnedLeaseCount: 0, deadlineReached: false, admissionDeadlineReached: true });
|
|
expect(Buffer.byteLength(JSON.stringify(state))).toBeLessThan(512);
|
|
expect(JSON.stringify(state)).not.toContain("PRIVATE");
|
|
});
|
|
|
|
it("rejects a second same-run lease even if only one lease is active", async () => {
|
|
const h = harness(); h.bootstrap.prompt("ambiguous");
|
|
h.leases.push({ ...h.leases[0]!, id: "old", status: "released" });
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("Ambiguous native qualification lease");
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("does not start observation after the case deadline", async () => {
|
|
const h = harness(0); h.bootstrap.prompt("expired");
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("Timed out waiting");
|
|
expect(h.api.get).not.toHaveBeenCalled(); expect(h.bind).not.toHaveBeenCalled();
|
|
});
|
|
|
|
|
|
it.each(["terminal", "run-owner", "issue-owner"])("does not lose a successful %s read when the lease endpoint rejects", async variant => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(); h.bootstrap.prompt("read-error");
|
|
if (variant === "terminal") h.run.status = "failed";
|
|
if (variant === "run-owner") h.run.companyId = "foreign";
|
|
if (variant === "issue-owner") h.issue.companyId = "foreign";
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => {
|
|
if (path.endsWith("/leases") || (variant === "issue-owner" && path.endsWith("/run"))
|
|
|| (variant !== "issue-owner" && path.endsWith("/issue"))) throw new Error("PRIVATE API ERROR");
|
|
return original(path);
|
|
});
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow(variant === "terminal" ? "stopped before observer setup" : "ownership is unproven");
|
|
expect(Date.now()).toBe(0); expect(h.bind).not.toHaveBeenCalled();
|
|
expect(h.input.evidence.mock.calls[0]![1]).toMatchObject({ admissionDeadlineReached: false });
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).not.toContain("PRIVATE");
|
|
});
|
|
|
|
it.each(["/api/issues/issue", "/api/heartbeat-runs/run", "/api/environments/env/leases"])("never admits while %s cannot be read", async failedPath => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("missing-read");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => { if (path === failedPath) throw new Error("PRIVATE API ERROR"); return original(path); });
|
|
const delivery = expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("diagnostics withheld");
|
|
await vi.advanceTimersByTimeAsync(1000); await delivery;
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).not.toContain("PRIVATE");
|
|
});
|
|
|
|
it("allows a transient lease read failure to recover without losing the setup reserve", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(); h.bootstrap.prompt("recover-read");
|
|
const original = h.api.get.getMockImplementation()!; let failed = false;
|
|
h.api.get.mockImplementation(async path => { if (path.endsWith("/leases") && !failed) { failed = true; throw new Error("unavailable"); } return original(path); });
|
|
const delivery = h.bootstrap.bindAndRelease(h.request);
|
|
await vi.advanceTimersByTimeAsync(100); await expect(delivery).resolves.toBe(h.fixture);
|
|
expect(h.bind).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it("rejects a lease read completing inside the final setup reserve and saves startup evidence", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("late");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => {
|
|
if (path.endsWith("/leases")) await new Promise(resolve => setTimeout(resolve, 1100));
|
|
return original(path);
|
|
});
|
|
const delivery = expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("Timed out waiting");
|
|
await vi.advanceTimersByTimeAsync(1200); await delivery;
|
|
expect(h.bind).not.toHaveBeenCalled(); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
expect(h.input.evidence.mock.calls[0]![1]).toMatchObject({ phase: "lease_admission", leasesRead: "rejected", admissionDeadlineReached: true, deadlineReached: false });
|
|
expect(h.input.evidence.mock.calls[0]![1]).not.toHaveProperty("activeOwnedLeaseCount");
|
|
});
|
|
|
|
it("captures binder failure after admission without publishing or repeating setup", async () => {
|
|
const h = harness(); h.bootstrap.prompt("bind-failure");
|
|
h.bind.mockRejectedValue(new Error("remote_native_fixture:insufficient_setup_budget"));
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow("insufficient_setup_budget");
|
|
expect(h.input.evidence.mock.calls[0]![1]).toMatchObject({ phase: "observer_setup", activeOwnedLeaseCount: 1 });
|
|
expect(h.bind).toHaveBeenCalledTimes(1); expect(h.fixture.publishAction).not.toHaveBeenCalled();
|
|
});
|
|
|
|
|
|
it.each(["terminal", "run-owner", "issue-owner"])("rejects %s immediately with another failed read and a pending lease, and consumes its late rejection", async variant => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(); h.bootstrap.prompt("slow-lease");
|
|
if (variant === "terminal") h.run.status = "failed";
|
|
if (variant === "run-owner") h.run.companyId = "foreign";
|
|
if (variant === "issue-owner") h.issue.companyId = "foreign";
|
|
let rejectLease!: (error: Error) => void;
|
|
const leaseRead = new Promise<never>((_resolve, reject) => { rejectLease = reject; });
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => {
|
|
if (path.endsWith("/leases")) return leaseRead;
|
|
if (path === (variant === "issue-owner" ? "/api/heartbeat-runs/run" : "/api/issues/issue")) throw new Error("503 PRIVATE");
|
|
return original(path);
|
|
});
|
|
await expect(h.bootstrap.bindAndRelease(h.request)).rejects.toThrow(variant === "terminal" ? "stopped before observer setup" : "ownership is unproven");
|
|
expect(Date.now()).toBe(0); expect(h.api.get).toHaveBeenCalledTimes(3);
|
|
expect(h.api.get).toHaveBeenCalledWith("/api/environments/env/leases", { timeout: 18_000 });
|
|
const saved = JSON.stringify(h.input.evidence.mock.calls);
|
|
expect(saved).toContain('"leasesRead":"pending"'); expect(saved).not.toContain("PRIVATE");
|
|
rejectLease(new Error("late private rejection"));
|
|
await vi.advanceTimersByTimeAsync(60_000);
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).toBe(saved);
|
|
expect(h.api.get).toHaveBeenCalledTimes(3); expect(h.bind).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("retains persistent 503 classification without its raw cause", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("503");
|
|
const cause = new RunnerApiHttpError(503, "GET /api/environments/env/leases returned 503: PRIVATE BODY");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => { if (path.endsWith("/leases")) throw cause; return original(path); });
|
|
const delivery = h.bootstrap.bindAndRelease(h.request).catch(error => error);
|
|
await vi.advanceTimersByTimeAsync(1000); const error = await delivery;
|
|
expect(error).toBeInstanceOf(ObservedStateTimeout); expect(error.cause).toBeUndefined();
|
|
expect(classifyFailure(error)).toBe("transient_infrastructure");
|
|
expect(error.message).not.toContain("PRIVATE");
|
|
expect(h.input.evidence.mock.calls[0]![1]).toMatchObject({ readFailureClass: "transient_infrastructure" });
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).not.toContain("PRIVATE");
|
|
expect(h.bind).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it.each([true, false])("clears a recovered 503 cause before %s admission or observed-state timeout", async admits => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("503-recovery");
|
|
const original = h.api.get.getMockImplementation()!; let failed = false;
|
|
h.api.get.mockImplementation(async path => {
|
|
if (path.endsWith("/leases")) {
|
|
if (!failed) { failed = true; throw new RunnerApiHttpError(503, "PRIVATE BODY"); }
|
|
if (!admits) return [];
|
|
}
|
|
return original(path);
|
|
});
|
|
const delivery = h.bootstrap.bindAndRelease(h.request).catch(error => error);
|
|
await vi.advanceTimersByTimeAsync(1000); const result = await delivery;
|
|
if (admits) expect(result).toBe(h.fixture);
|
|
else { expect(classifyFailure(result)).toBe("candidate_failure"); expect(result.cause).toBeUndefined(); }
|
|
});
|
|
|
|
it("bounds an unresponsive read at admission without launching replacement reads", async () => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("hung");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => path.endsWith("/leases") ? new Promise<never>(() => {}) : original(path));
|
|
const delivery = h.bootstrap.bindAndRelease(h.request).catch(error => error);
|
|
await vi.advanceTimersByTimeAsync(1100); const error = await delivery;
|
|
expect(classifyFailure(error)).toBe("transient_infrastructure");
|
|
expect(h.api.get).toHaveBeenCalledTimes(3); expect(h.bind).not.toHaveBeenCalled();
|
|
});
|
|
|
|
|
|
it.each([
|
|
["Playwright TimeoutError", Object.assign(new Error("Timeout 1000ms exceeded. PRIVATE"), { name: "TimeoutError" }), "transient_infrastructure"],
|
|
["Playwright fetch timeout", new Error("apiRequestContext.get: Timeout 1000ms exceeded. PRIVATE"), "transient_infrastructure"],
|
|
["server fetch timeout", new Error("Timeout 1000ms exceeded PRIVATE"), "transient_infrastructure"],
|
|
["connection reset", new Error("apiRequestContext.get: read ECONNRESET PRIVATE"), "transient_infrastructure"],
|
|
["socket hang up", new Error("socket hang up"), "transient_infrastructure"],
|
|
["prefixed socket hang up", new Error("apiRequestContext.get: Socket Hang Up PRIVATE"), "transient_infrastructure"],
|
|
["undefined", undefined, "candidate_failure"],
|
|
["null", null, "candidate_failure"],
|
|
["private string", "PRIVATE 503 TimeoutError", "candidate_failure"],
|
|
["unknown object", { message: "PRIVATE", status: 503 }, "candidate_failure"],
|
|
])("normalizes %s rejection without exposing transport diagnostics", async (_label, rejected, failureClass) => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("safe-errors");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
h.api.get.mockImplementation(async path => { if (path.endsWith("/leases")) throw rejected; return original(path); });
|
|
const delivery = h.bootstrap.bindAndRelease(h.request).catch(error => error);
|
|
await vi.advanceTimersByTimeAsync(1000); const error = await delivery;
|
|
expect(classifyFailure(error)).toBe(failureClass);
|
|
expect(error.cause).toBeUndefined();
|
|
expect(error.message.length).toBeLessThan(1024);
|
|
expect(error.stack).not.toContain("PRIVATE");
|
|
expect(JSON.stringify(error)).not.toContain("PRIVATE");
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).not.toContain("PRIVATE");
|
|
expect(h.input.evidence.mock.calls[0]![1]).toMatchObject({ leasesRead: "rejected", readFailureClass: failureClass });
|
|
expect(h.bind).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it.each([[503, "transient_infrastructure"], [403, "permanent_infrastructure"], [400, "candidate_failure"]])(
|
|
"normalizes actual RunnerApi HTTP %s status independently of its private body", async (status, failureClass) => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
vi.stubEnv("PAPERCLIP_RUNNER_E2E_PORT", "3100");
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("actual-api");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
const secret = "PRIVATE body: forbidden secret plaintext 503 timeout socket hang up ".repeat(10_000);
|
|
const request = { get: vi.fn(async (path: string) => ({
|
|
ok: () => !path.endsWith("/leases"), status: () => status,
|
|
url: () => "http://PRIVATE.invalid/private", text: async () => secret,
|
|
json: async () => original(path),
|
|
} as APIResponse)) };
|
|
const actual = new RunnerApi(request as unknown as APIRequestContext);
|
|
h.api.get.mockImplementation(path => actual.get(path, { timeout: 1000 }));
|
|
const delivery = h.bootstrap.bindAndRelease(h.request).catch(error => error);
|
|
await vi.advanceTimersByTimeAsync(1000); const error = await delivery;
|
|
expect(classifyFailure(error)).toBe(failureClass);
|
|
expect(error.cause).toBeUndefined();
|
|
expect(error.message.length).toBeLessThan(1024);
|
|
expect(error.stack).not.toContain("PRIVATE");
|
|
expect(JSON.stringify(error)).not.toContain("PRIVATE");
|
|
expect(JSON.stringify(h.input.evidence.mock.calls)).not.toContain("PRIVATE");
|
|
if (status === 403) expect(error).toBeInstanceOf(RemoteAdmissionReadError);
|
|
expect(h.bind).not.toHaveBeenCalled();
|
|
vi.unstubAllEnvs();
|
|
},
|
|
);
|
|
|
|
it.each([
|
|
["issue", null], ["run", []], ["leases", {}], ["leases", [null]],
|
|
["leases", ["PRIVATE"]], ["leases", [[{}]]], ["leases", undefined],
|
|
])("rejects malformed successful %s JSON without an unhandled continuation", async (endpoint, value) => {
|
|
vi.useFakeTimers(); vi.setSystemTime(0);
|
|
const h = harness(REMOTE_FIXTURE_MIN_SETUP_BUDGET_MS + 1000); h.bootstrap.prompt("malformed");
|
|
const original = h.api.get.getMockImplementation()!;
|
|
const path = endpoint === "issue" ? "/api/issues/issue" : endpoint === "run" ? "/api/heartbeat-runs/run" : "/api/environments/env/leases";
|
|
h.api.get.mockImplementation(async requested => requested === path ? value as never : original(requested));
|
|
const delivery = h.bootstrap.bindAndRelease(h.request).catch(error => error);
|
|
await vi.advanceTimersByTimeAsync(1000); const error = await delivery;
|
|
expect(error).toBeInstanceOf(RemoteAdmissionReadError);
|
|
expect(classifyFailure(error)).toBe("candidate_failure");
|
|
expect(error.cause).toBeUndefined(); expect(error.stack).not.toContain("PRIVATE");
|
|
expect(h.bind).not.toHaveBeenCalled();
|
|
});
|